# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=18

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 19

---

## [Adding new Elastic Node to Cluster: Node stays undiscovered](https://discuss.elastic.co/t/adding-new-elastic-node-to-cluster-node-stays-undiscovered/382007)

<div class="topic-metadata">

**Author:** [@ElasticUser\_NextDoor](https://discuss.elastic.co/u/ElasticUser_NextDoor)\
**Replies:** 2\
**Last updated:** [September 17, 2025, 1:24pm UTC](https://discuss.elastic.co/t/adding-new-elastic-node-to-cluster-node-stays-undiscovered/382007 "2025-09-17T13:24:13Z")

</div>

Hi, I am trying to add a new node to an already existing cluster but it seems the discovery won’t do its job. Even after restarting the master node the discovery process won’t start or at least not detect the new node. …

---

## [Logstash initialization failed](https://discuss.elastic.co/t/logstash-initialization-failed/381933)

<div class="topic-metadata">

**Author:** [@piyush\_hn](https://discuss.elastic.co/u/piyush_hn)\
**Replies:** 2\
**Last updated:** [September 17, 2025, 5:05am UTC](https://discuss.elastic.co/t/logstash-initialization-failed/381933 "2025-09-17T05:05:53Z")

</div>

Anyone knows what the below error means please ? \[2025-09-14T16:24:11,750\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Failed to install template {:message=\>"Failed to load default template for Elasticsearch v9 with E…

---

## [How do you backup up a subset of system indices?](https://discuss.elastic.co/t/how-do-you-backup-up-a-subset-of-system-indices/381995)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 0\
**Last updated:** [September 16, 2025, 8:58pm UTC](https://discuss.elastic.co/t/how-do-you-backup-up-a-subset-of-system-indices/381995 "2025-09-16T20:58:24Z")

</div>

Per (elastic/elasticsearch#134769) There are bunch of old indices lying around I’d like clear out - for example .reporting-2023-07-23 and .kibana\_7.15.1\_001. Having looked at the aliases I’m pretty sure these are unuse…

---

## [Constant read timeout errors while indexing; non-master nodes are idle; shard sizes are mismatched?](https://discuss.elastic.co/t/constant-read-timeout-errors-while-indexing-non-master-nodes-are-idle-shard-sizes-are-mismatched/381994)

<div class="topic-metadata">

**Author:** [@dpitchford](https://discuss.elastic.co/u/dpitchford)\
**Replies:** 0\
**Last updated:** [September 16, 2025, 8:54pm UTC](https://discuss.elastic.co/t/constant-read-timeout-errors-while-indexing-non-master-nodes-are-idle-shard-sizes-are-mismatched/381994 "2025-09-16T20:54:28Z")

</div>

We are running an Elasticsearch 9.1.2 cluster with four nodes that is displaying some erratic behavior when under indexing load. Initially when we started indexing data, all four nodes (each a separate Kubernetes pod) we…

---

## [Build issue](https://discuss.elastic.co/t/build-issue/381992)

<div class="topic-metadata">

**Author:** [@Pedro\_Pacheco](https://discuss.elastic.co/u/Pedro_Pacheco)\
**Replies:** 0\
**Last updated:** [September 16, 2025, 6:57pm UTC](https://discuss.elastic.co/t/build-issue/381992 "2025-09-16T18:57:18Z")

</div>

Hello - I am trying to build elastic from source. I clone the repo, and as I am running ./gradlew clean build, it fails here: WARNING: module-info.class ignored in patch: /Users/pedropacheco/Projects/elasticsearch/libs/…

---

## [Change Elasticsearch password](https://discuss.elastic.co/t/change-elasticsearch-password/381983)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 6\
**Last updated:** [September 16, 2025, 3:40pm UTC](https://discuss.elastic.co/t/change-elasticsearch-password/381983 "2025-09-16T15:40:45Z")

</div>

Hi Understanding that Logstash uses .conf files to authenticate against Elasticsearch, I am here today to ask for your help in changing the current password I have configured in the .conf files from Logstash. elasticse…

---

## [Custom Threat Intelligence Error](https://discuss.elastic.co/t/custom-threat-intelligence-error/381975)

<div class="topic-metadata">

**Author:** [@kulisiber](https://discuss.elastic.co/u/kulisiber)\
**Replies:** 0\
**Last updated:** [September 16, 2025, 10:19am UTC](https://discuss.elastic.co/t/custom-threat-intelligence-error/381975 "2025-09-16T10:19:31Z")

</div>

Hi Elastic Community, I have testing a new integration Custom Threat Intelligence into elastic and I found some error like below: I have configure the column of SSL Configuration like below: certificate: - | ----…

---

## [CVE-2025-58057 Netty Security Issue](https://discuss.elastic.co/t/cve-2025-58057-netty-security-issue/381815)

<div class="topic-metadata">

**Author:** [@sfarooqui](https://discuss.elastic.co/u/sfarooqui)\
**Replies:** 2\
**Last updated:** [September 15, 2025, 8:14pm UTC](https://discuss.elastic.co/t/cve-2025-58057-netty-security-issue/381815 "2025-09-15T20:14:16Z")

</div>

Hello! I hope you are well. My team recently ran AWS ECR Inspector on our elasticsearch docker image and Inspector stated our image contains this vulnerability: CVE-2025-58057 (can’t link to the host, but it is an issue …

---

## [Postgresql timezone and error message provided grok expressions do not match field value](https://discuss.elastic.co/t/postgresql-timezone-and-error-message-provided-grok-expressions-do-not-match-field-value/381946)

<div class="topic-metadata">

**Author:** [@VillsEK](https://discuss.elastic.co/u/VillsEK)\
**Replies:** 1\
**Last updated:** [September 15, 2025, 5:03pm UTC](https://discuss.elastic.co/t/postgresql-timezone-and-error-message-provided-grok-expressions-do-not-match-field-value/381946 "2025-09-15T17:03:02Z")

</div>

Helloy there, im new in elk. can someone tell me how to fix the error "error message provided grok expressions do not match field value". I found out that when the time zone is specified as an abbreviation in the postgr…

---

## [Elastic Search Web Crawler API question](https://discuss.elastic.co/t/elastic-search-web-crawler-api-question/381963)

<div class="topic-metadata">

**Author:** [@paul1000](https://discuss.elastic.co/u/paul1000)\
**Replies:** 0\
**Last updated:** [September 15, 2025, 4:51pm UTC](https://discuss.elastic.co/t/elastic-search-web-crawler-api-question/381963 "2025-09-15T16:51:29Z")

</div>

Hi, I have set up Elastic (Enterprise) Web Crawler indexes and would like to manage these via APIs. I am aware that the App Search Web Crawler can be managed via an API and also that open web crawler can be as well how…

---

## [Distance feature query that weights null values lower](https://discuss.elastic.co/t/distance-feature-query-that-weights-null-values-lower/381956)

<div class="topic-metadata">

**Author:** [@jorgenfu](https://discuss.elastic.co/u/jorgenfu)\
**Replies:** 0\
**Last updated:** [September 15, 2025, 2:18pm UTC](https://discuss.elastic.co/t/distance-feature-query-that-weights-null-values-lower/381956 "2025-09-15T14:18:57Z")

</div>

I’m looking for a way to weights documents higher based on a date field called publicationDate, but where the weight is lowest if the date field is null, instead of highest. The full query is a bool query with several s…

---

## [How to prevent default header parameter from being passed with webhook action in Watcher](https://discuss.elastic.co/t/how-to-prevent-default-header-parameter-from-being-passed-with-webhook-action-in-watcher/381544)

<div class="topic-metadata">

**Author:** [@adityabk](https://discuss.elastic.co/u/adityabk)\
**Replies:** 3\
**Last updated:** [September 15, 2025, 1:51pm UTC](https://discuss.elastic.co/t/how-to-prevent-default-header-parameter-from-being-passed-with-webhook-action-in-watcher/381544 "2025-09-15T13:51:00Z")

</div>

I have a Watcher watch that uses webhook action to send HTTPS request to a Mule API. It looks like this: \</\> ”webhook”: { ”scheme”: “XXXX“ ”host”: “XXXXX“ ”port”: 443 ”method”: “post“ ”path”: “xxx/yyy/zzz” ”param…

---

## [What are the best servers for storing Elasticsearch data?](https://discuss.elastic.co/t/what-are-the-best-servers-for-storing-elasticsearch-data/381754)

<div class="topic-metadata">

**Author:** [@Ella\_conan](https://discuss.elastic.co/u/Ella_conan)\
**Replies:** 17\
**Last updated:** [September 15, 2025, 6:09am UTC](https://discuss.elastic.co/t/what-are-the-best-servers-for-storing-elasticsearch-data/381754 "2025-09-15T06:09:13Z")

</div>

Hi I am storing events from devices in Elasticsearch, and the size of these events is very large. Therefore, I decided to purchase high-performance servers to make search as fast as possible, ideally around 1 second. I…

---

## [Influence master selection in elasticsearch](https://discuss.elastic.co/t/influence-master-selection-in-elasticsearch/381925)

<div class="topic-metadata">

**Author:** [@Phoenix2](https://discuss.elastic.co/u/Phoenix2)\
**Replies:** 5\
**Last updated:** [September 14, 2025, 11:07am UTC](https://discuss.elastic.co/t/influence-master-selection-in-elasticsearch/381925 "2025-09-14T11:07:07Z")

</div>

How can I influence the master selection, or how does Elasticsearch select the next master node? As far as I have discovered, it is not possible to influence this, but: Currently, it is always data node 01 for me, but …

---

## [Elasticsearch configuration](https://discuss.elastic.co/t/elasticsearch-configuration/381927)

<div class="topic-metadata">

**Author:** [@piyush\_hn](https://discuss.elastic.co/u/piyush_hn)\
**Replies:** 1\
**Last updated:** [September 14, 2025, 3:52am UTC](https://discuss.elastic.co/t/elasticsearch-configuration/381927 "2025-09-14T03:52:48Z")

</div>

Hi, Trying to run elasticsearch inside a docker container but getting below error. {"@timestamp":"2025-09-14T02:18:15.072Z", "log.level":"ERROR", "message":"node validation exception\\n\[2\] bootstrap checks failed. You …

---

## [Elasticsearch issue with migrate to 9.0.6](https://discuss.elastic.co/t/elasticsearch-issue-with-migrate-to-9-0-6/381926)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 1\
**Last updated:** [September 14, 2025, 2:58am UTC](https://discuss.elastic.co/t/elasticsearch-issue-with-migrate-to-9-0-6/381926 "2025-09-14T02:58:02Z")

</div>

Hello, I have issue with migrate from version 8.19.2 to 9.0.6 On version 8.19.2 from Stack Management/Upgrade assistant I migrated system indices Next I founded some critical old indexes - deleted them, And during u…

---

## [Best way to identify input error for multi\_match?](https://discuss.elastic.co/t/best-way-to-identify-input-error-for-multi-match/381889)

<div class="topic-metadata">

**Author:** [@nonword](https://discuss.elastic.co/u/nonword)\
**Replies:** 1\
**Last updated:** [September 13, 2025, 12:57am UTC](https://discuss.elastic.co/t/best-way-to-identify-input-error-for-multi-match/381889 "2025-09-13T00:57:51Z")

</div>

We’re passing user input into a multi\_match with minimal escaping. If the user searches ”something (unbalanced quotes), ES responds with a 400: { root\_cause: \[ { type: 'token\_mgr\_error', reason: 'token…

---

## [How to balance search relevance with lots of images in Elasticsearch?](https://discuss.elastic.co/t/how-to-balance-search-relevance-with-lots-of-images-in-elasticsearch/381905)

<div class="topic-metadata">

**Author:** [@jessicakaren907](https://discuss.elastic.co/u/jessicakaren907)\
**Replies:** 1\
**Last updated:** [September 13, 2025, 12:28am UTC](https://discuss.elastic.co/t/how-to-balance-search-relevance-with-lots-of-images-in-elasticsearch/381905 "2025-09-13T00:28:04Z")

</div>

Quick question for the community: has anyone here tried indexing pages that are heavy on visuals? I’ve seen cases where full-text search works fine for pure articles, but when the page has lots of images + short descrip…

---

## [Elasticsearch documents getting deleted](https://discuss.elastic.co/t/elasticsearch-documents-getting-deleted/381854)

<div class="topic-metadata">

**Author:** [@ItsHoney](https://discuss.elastic.co/u/ItsHoney)\
**Replies:** 5\
**Last updated:** [September 11, 2025, 6:12pm UTC](https://discuss.elastic.co/t/elasticsearch-documents-getting-deleted/381854 "2025-09-11T18:12:05Z")

</div>

We’ve been experiencing an issue where certain documents in our Media index go missing. What’s unusual is that it’s often the same documents that disappear each time. Here’s what we’ve observed: We have a process tha…

---

## [Summary index transform reference](https://discuss.elastic.co/t/summary-index-transform-reference/381800)

<div class="topic-metadata">

**Author:** [@bigsby](https://discuss.elastic.co/u/bigsby)\
**Replies:** 1\
**Last updated:** [September 11, 2025, 12:45pm UTC](https://discuss.elastic.co/t/summary-index-transform-reference/381800 "2025-09-11T12:45:54Z")

</div>

I have a bunch of indices I’d like merge into a single summary index. From what I read, "Transforming data | Elastic Docs" is the way to go but I’m not find the way to do this. Here it goes. The indices I have are somet…

---

## [Search query in a list of texts](https://discuss.elastic.co/t/search-query-in-a-list-of-texts/381625)

<div class="topic-metadata">

**Author:** [@epistola](https://discuss.elastic.co/u/epistola)\
**Replies:** 7\
**Last updated:** [September 9, 2025, 5:34pm UTC](https://discuss.elastic.co/t/search-query-in-a-list-of-texts/381625 "2025-09-09T17:34:54Z")

</div>

Hello everyone, I have a search problem in ES. In the index i have a field that is a list of texts like the following: list\_field = \[text1, text2, text3, …\] I want to search for a number of terms that all belong to th…

---

## [Index template "logs-microsoft\_exchange\_server.httpproxy " Issue](https://discuss.elastic.co/t/index-template-logs-microsoft-exchange-server-httpproxy-issue/381790)

<div class="topic-metadata">

**Author:** [@aniskh](https://discuss.elastic.co/u/aniskh)\
**Replies:** 1\
**Last updated:** [September 9, 2025, 1:41pm UTC](https://discuss.elastic.co/t/index-template-logs-microsoft-exchange-server-httpproxy-issue/381790 "2025-09-09T13:41:29Z")

</div>

hello, i lost my index template “logs-microsoft\_exchange\_server.httpproxy logs-microsoft\_exchange\_server.httpproxy “ is theire any solution de restore it ?

---

## [Why doesn’t dense\_vector field show up in Spark schema when using Elasticsearch-Hadoop?](https://discuss.elastic.co/t/why-doesn-t-dense-vector-field-show-up-in-spark-schema-when-using-elasticsearch-hadoop/381715)

<div class="topic-metadata">

**Author:** [@dany\_fard](https://discuss.elastic.co/u/dany_fard)\
**Replies:** 2\
**Last updated:** [September 9, 2025, 1:03pm UTC](https://discuss.elastic.co/t/why-doesn-t-dense-vector-field-show-up-in-spark-schema-when-using-elasticsearch-hadoop/381715 "2025-09-09T13:03:46Z")

</div>

Hi everyone, I created an Elasticsearch index with a dense\_vector field, along with some text fields. The mapping looks like this (simplified): {"mappings": {"properties": {"embedding": {"type": "dense\_vector","dims": …

---

## [SSL issue when connecting MCP with elastic search for ibm cloud](https://discuss.elastic.co/t/ssl-issue-when-connecting-mcp-with-elastic-search-for-ibm-cloud/381794)

<div class="topic-metadata">

**Author:** [@ravitejavemula333](https://discuss.elastic.co/u/ravitejavemula333)\
**Replies:** 0\
**Last updated:** [September 9, 2025, 11:34am UTC](https://discuss.elastic.co/t/ssl-issue-when-connecting-mcp-with-elastic-search-for-ibm-cloud/381794 "2025-09-09T11:34:15Z")

</div>

Hi team, I am following below link to setup mcp server for Elasticsearch I use Databases for Elasticsearch from IBm cloud. i have given below code : client = AsyncElasticsearch( \[MCP\_ELASTIC\_URL\], ca\_cert…

---

## [Elasticsearch cannot access keys although they are available](https://discuss.elastic.co/t/elasticsearch-cannot-access-keys-although-they-are-available/381476)

<div class="topic-metadata">

**Author:** [@Salvatore\_Milano](https://discuss.elastic.co/u/Salvatore_Milano)\
**Replies:** 10\
**Last updated:** [September 8, 2025, 11:07am UTC](https://discuss.elastic.co/t/elasticsearch-cannot-access-keys-although-they-are-available/381476 "2025-09-08T11:07:51Z")

</div>

Hello, recently I have been running into an issue with elastic. I have a single node Elasticsearch-Container running in Docker. Sometimes it seems that Elasticsearch is not running as it should so I have tried to debu…

---

## [Having issue to re run the snapshot](https://discuss.elastic.co/t/having-issue-to-re-run-the-snapshot/381723)

<div class="topic-metadata">

**Author:** [@Amirul\_Ento](https://discuss.elastic.co/u/Amirul_Ento)\
**Replies:** 1\
**Last updated:** [September 8, 2025, 9:09am UTC](https://discuss.elastic.co/t/having-issue-to-re-run-the-snapshot/381723 "2025-09-08T09:09:40Z")

</div>

Hi guys, I’m new to ELK. I got this issue recently. It actually is my mistake. I’m running a snapshot using elasticsearch curator where snapshot date based on range. Everything look normal since February until July. I…

---

## [io.netty.handler.codec.DecoderException: java.io.StreamCorruptedException](https://discuss.elastic.co/t/io-netty-handler-codec-decoderexception-java-io-streamcorruptedexception/381603)

<div class="topic-metadata">

**Author:** [@rajathgubbi](https://discuss.elastic.co/u/rajathgubbi)\
**Replies:** 3\
**Last updated:** [September 8, 2025, 7:19am UTC](https://discuss.elastic.co/t/io-netty-handler-codec-decoderexception-java-io-streamcorruptedexception/381603 "2025-09-08T07:19:11Z")

</div>

We are encountering the below exception in our environment, where we are running Elasticsearch version 6.8.12 with two Elasticsearch nodes communicating over stunnel. Please let me know the probable reason for below exc…

---

## [Parsing multiple similar exceptions to a single document in elasticsearch](https://discuss.elastic.co/t/parsing-multiple-similar-exceptions-to-a-single-document-in-elasticsearch/381748)

<div class="topic-metadata">

**Author:** [@radha16](https://discuss.elastic.co/u/radha16)\
**Replies:** 1\
**Last updated:** [September 8, 2025, 6:53am UTC](https://discuss.elastic.co/t/parsing-multiple-similar-exceptions-to-a-single-document-in-elasticsearch/381748 "2025-09-08T06:53:26Z")

</div>

Hi Team, I would like to customise the ES documents by passing the similar multiple exceptions from a log file to a single index instead of multiple indexes. If any good approach to test this, please let me know. Thanks…

---

## [Elasticsearch Cluster node migration from Old VM to New VM](https://discuss.elastic.co/t/elasticsearch-cluster-node-migration-from-old-vm-to-new-vm/381141)

<div class="topic-metadata">

**Author:** [@King\_storm](https://discuss.elastic.co/u/King_storm)\
**Replies:** 2\
**Last updated:** [September 7, 2025, 5:21am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-node-migration-from-old-vm-to-new-vm/381141 "2025-09-07T05:21:25Z")

</div>

I currently run a 3-node Elasticsearch cluster (v8.17.0) and need to migrate to a new set of VMs with larger partitions. My goal is to move nodes one by one (lift-and-shift) without downtime. Here’s the migration approac…

---

## [Readiness check issue with the eck-stack charts](https://discuss.elastic.co/t/readiness-check-issue-with-the-eck-stack-charts/381676)

<div class="topic-metadata">

**Author:** [@zlzzk](https://discuss.elastic.co/u/zlzzk)\
**Replies:** 0\
**Last updated:** [September 6, 2025, 4:16am UTC](https://discuss.elastic.co/t/readiness-check-issue-with-the-eck-stack-charts/381676 "2025-09-06T04:16:37Z")

</div>

I deployed eck-stack charts v0.16.0 but found the pod readiness check never succeed. I see it uses this command bash -c /mnt/elastic-internal/scripts/readiness-port-script.sh I tried inside the pod got Elasticsearch is…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=17)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=19)
