# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=180

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 181

---

## [Data nodes removed from cluster one by one after indexing activity peak](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764)

<div class="topic-metadata">

**Author:** [@jalker](https://discuss.elastic.co/u/jalker)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 8:35am UTC](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764 "2023-11-09T08:35:12Z")

</div>

Elasticsearch 7.17, Debian, 12 data nodes, 5.5 Bi primary docs, 11.0 TB primary doc size. We have seen the following behavior twice now and we are clueless as to its root cause. We see an sudden increase of indexing a…

---

## [Update by query (async / task) - No failure info - Handling Conflicts](https://discuss.elastic.co/t/update-by-query-async-task-no-failure-info-handling-conflicts/346755)

<div class="topic-metadata">

**Author:** [@Irfanulla](https://discuss.elastic.co/u/Irfanulla)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 6:08am UTC](https://discuss.elastic.co/t/update-by-query-async-task-no-failure-info-handling-conflicts/346755 "2023-11-09T06:08:55Z")

</div>

I am running an update by query as a task (wait\_for\_completion=false), with 'conflicts=proceed'. I do expect version conflicts to happen sometimes and can see that info in get task response (/task/task-id). I plan to rep…

---

## [Why is a wildcard query string matching on stemmed terms?](https://discuss.elastic.co/t/why-is-a-wildcard-query-string-matching-on-stemmed-terms/346576)

<div class="topic-metadata">

**Author:** [@cphramington](https://discuss.elastic.co/u/cphramington)\
**Replies:** 4\
**Last updated:** [November 8, 2023, 10:54pm UTC](https://discuss.elastic.co/t/why-is-a-wildcard-query-string-matching-on-stemmed-terms/346576 "2023-11-08T22:54:52Z")

</div>

First, some background. I understand that the algorithmic stemmer is not perfect, e.g. "focused" is stemmed to "focus," while "focus" is stemmed to "focu," which I've validated by looking through the term vectors. Howev…

---

## [RHEL8 Upgrade](https://discuss.elastic.co/t/rhel8-upgrade/346738)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 7:14pm UTC](https://discuss.elastic.co/t/rhel8-upgrade/346738 "2023-11-08T19:14:43Z")

</div>

Is there anything special i need to do to upgrade from rhel7 to rhel8 running ELK8?

---

## [Loss of Elasticsearch Replicas/Shards After Node Failures](https://discuss.elastic.co/t/loss-of-elasticsearch-replicas-shards-after-node-failures/346664)

<div class="topic-metadata">

**Author:** [@Jeankininho](https://discuss.elastic.co/u/Jeankininho)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 6:00pm UTC](https://discuss.elastic.co/t/loss-of-elasticsearch-replicas-shards-after-node-failures/346664 "2023-11-08T18:00:09Z")

</div>

Hello, I'm facing an issue with my Elasticsearch cluster and I'm looking for some guidance or suggestions on what might be happening. I have an Elasticsearch cluster running version 6.5.1 with JVM 11.0.11. Recently, I'…

---

## [Failed after reindexing](https://discuss.elastic.co/t/failed-after-reindexing/346714)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 4\
**Last updated:** [November 8, 2023, 6:00pm UTC](https://discuss.elastic.co/t/failed-after-reindexing/346714 "2023-11-08T18:00:22Z")

</div>

Got this error after reindexing \[INIT\] Fail initialize schema, index already exists, previous initialization fail because you kill the platform before the end of the initialization. Please remove your elastic/opensearch…

---

## [Getting error when using variable\_width\_histogram aggregation 'Too many buckets'](https://discuss.elastic.co/t/getting-error-when-using-variable-width-histogram-aggregation-too-many-buckets/346695)

<div class="topic-metadata">

**Author:** [@Chandra\_Shekhar](https://discuss.elastic.co/u/Chandra_Shekhar)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 10:34am UTC](https://discuss.elastic.co/t/getting-error-when-using-variable-width-histogram-aggregation-too-many-buckets/346695 "2023-11-08T10:34:22Z")

</div>

We are trying to execute a query to get variable\_width\_histogram aggregation results but getting an error 'Trying to create too many buckets'. However bucket size in query is 10. When trying to get bucket size 8, I am ab…

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232)

<div class="topic-metadata">

**Author:** [@Tybe\_sacha](https://discuss.elastic.co/u/Tybe_sacha)\
**Replies:** 27\
**Last updated:** [November 8, 2023, 2:23pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232 "2023-11-08T14:23:01Z")

</div>

Hi everyone, I'm new here ! :ok\_woman: I just finished set up basic security on my server (1VM with : Elasticsearch, 1 node, Kibana). I ran those commands : ./bin/elasticsearch-keystore add xpack.security.transport.ss…

---

## [{\\"error\\":{\\"root\_cause\\":\[{\\"type\\":\\"x\_content\_parse\_exception\\",\\"reason\\":\\"\[1:2\] Unexpected character ('\<' (code 60)):](https://discuss.elastic.co/t/error-root-cause-type-x-content-parse-exception-reason-1-2-unexpected-character-code-60/346704)

<div class="topic-metadata">

**Author:** [@sichuanmcl](https://discuss.elastic.co/u/sichuanmcl)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 12:21pm UTC](https://discuss.elastic.co/t/error-root-cause-type-x-content-parse-exception-reason-1-2-unexpected-character-code-60/346704 "2023-11-08T12:21:41Z")

</div>

Hi, I'm trying to send json string data using bulk update but the json string contain html component Is that possible? Because sometimes it's just okay, and sometimes it's error parsing. This is one of the body that …

---

## [Hybrid search by using knn and query in java client](https://discuss.elastic.co/t/hybrid-search-by-using-knn-and-query-in-java-client/346594)

<div class="topic-metadata">

**Author:** [@wshan13](https://discuss.elastic.co/u/wshan13)\
**Replies:** 1\
**Last updated:** [November 8, 2023, 12:18pm UTC](https://discuss.elastic.co/t/hybrid-search-by-using-knn-and-query-in-java-client/346594 "2023-11-08T12:18:50Z")

</div>

Hello. I want the hybrid search by using both the knn option and a query on the page below with java client. With spring-boot 3.1.5 and elasticsarch-java 8.7.1 environment, I made some codes as below, but seems like…

---

## [Elasticsearch Unable to access 'path.repo' shared folder](https://discuss.elastic.co/t/elasticsearch-unable-to-access-path-repo-shared-folder/346377)

<div class="topic-metadata">

**Author:** [@Aasif\_Ansari](https://discuss.elastic.co/u/Aasif_Ansari)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 10:23am UTC](https://discuss.elastic.co/t/elasticsearch-unable-to-access-path-repo-shared-folder/346377 "2023-11-08T10:23:36Z")

</div>

Hi Team, I have Elasticsearch installed to my windows server. And I have another windows server with file system shared with the first one. I have map network drive to "I" letter and path "I:\\Elasticsearch-Snapshot-v2" …

---

## [Indices got deleted anonymously](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641)

<div class="topic-metadata">

**Author:** [@aneesh](https://discuss.elastic.co/u/aneesh)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 10:15am UTC](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641 "2023-11-08T10:15:22Z")

</div>

Hi, some of the indices are deleted. Following is the log we have. Can you please let us know for the possibilities for same. \[2023-11-07T00:52:00,000\]\[INFO \]\[o.e.x.m.MlDailyMaintenanceService\] \[ServerName1\] triggerin…

---

## [Elasticsearch installation issues](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584)

<div class="topic-metadata">

**Author:** [@bosimaosh](https://discuss.elastic.co/u/bosimaosh)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584 "2023-11-08T10:10:57Z")

</div>

After installing Elasticsearch, when I try to start the elasticsearch.service service, it fails to start and I receive the following error. system is Ubuntu 20.04. Elasticsearch version is 7.17.14 sudo systemctl stat…

---

## [Understanding query difference](https://discuss.elastic.co/t/understanding-query-difference/346690)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 9:44am UTC](https://discuss.elastic.co/t/understanding-query-difference/346690 "2023-11-08T09:44:42Z")

</div>

Below are two queries with their respective responses. I would like to understand the difference between the below queries from the point of aggregation. In Request 1 I filter docs based on "unique\_name" and then group t…

---

## [ElasticSearch cluster backup](https://discuss.elastic.co/t/elasticsearch-cluster-backup/346680)

<div class="topic-metadata">

**Author:** [@laurentiusoica](https://discuss.elastic.co/u/laurentiusoica)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 7:34am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-backup/346680 "2023-11-08T07:34:24Z")

</div>

Hi, For an Elasticsearch cluster, is it a supported way to backup the cluster by completely shutting it down and take data volumes snapshots?

---

## [Error "String length exceeds the maximum length (5000000)" when transferring a large document to the attachment pipeline](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687)

<div class="topic-metadata">

**Author:** [@Vlad\_I](https://discuss.elastic.co/u/Vlad_I)\
**Replies:** 5\
**Last updated:** [November 8, 2023, 3:25am UTC](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687 "2023-11-08T03:25:44Z")

</div>

I'm using Elasticsearch 8.9.1 Using python, I send an 8MB xlsx document to the Elasticsearch index via attachment pipeline. But the error "String length (5046272) exceeds the maximum length (5000000)" appears. For exam…

---

## [I have a question, can I take the ldap attribute to create a role map? and the following is the ldap configuration in elasticsearch.yml](https://discuss.elastic.co/t/i-have-a-question-can-i-take-the-ldap-attribute-to-create-a-role-map-and-the-following-is-the-ldap-configuration-in-elasticsearch-yml/346676)

<div class="topic-metadata">

**Author:** [@Tsabitul\_azmi1](https://discuss.elastic.co/u/Tsabitul_azmi1)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 3:04am UTC](https://discuss.elastic.co/t/i-have-a-question-can-i-take-the-ldap-attribute-to-create-a-role-map-and-the-following-is-the-ldap-configuration-in-elasticsearch-yml/346676 "2023-11-08T03:04:30Z")

</div>

xpack: security: authc: realms: ldap: ldap1: order: 0 url: "ldap://xxx.xxx.xxx.xxx:389" bind\_dn: "uid=xxxxx,ou=accounts,o=xxx,dc=xx,dc=xx" #user\_search.attribute: "branchalias" #user\_group\_attribute: "branchali…

---

## [ILM for new indices created via Logstash](https://discuss.elastic.co/t/ilm-for-new-indices-created-via-logstash/346621)

<div class="topic-metadata">

**Author:** [@tecbox41](https://discuss.elastic.co/u/tecbox41)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 1:40pm UTC](https://discuss.elastic.co/t/ilm-for-new-indices-created-via-logstash/346621 "2023-11-07T13:40:33Z")

</div>

I am trying to apply ILM to new indices created via Logstash, but it doesn't seem to show the new indices being managed by ILM. I am using the default index template and do not have streams configured for these indices. …

---

## [Aggregation of aggregation](https://discuss.elastic.co/t/aggregation-of-aggregation/346472)

<div class="topic-metadata">

**Author:** [@Hakan\_Kucuk](https://discuss.elastic.co/u/Hakan_Kucuk)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 1:37pm UTC](https://discuss.elastic.co/t/aggregation-of-aggregation/346472 "2023-11-07T13:37:39Z")

</div>

Hello, I’m struggling to create a query and dashboard for my specific scenario. I have a dataset of orders with the following structure: order\_id order\_status timestamp 1 started 01.01.2023 1 in\_progress 02.0…

---

## [Supporting Exact Search while obeying punctuations using ES](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604)

<div class="topic-metadata">

**Author:** [@prakharchaube](https://discuss.elastic.co/u/prakharchaube)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:22am UTC](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604 "2023-11-07T09:22:36Z")

</div>

Hi folks, I am new to ES and was stuck at something so seeking help! I have a search requirement where I need to get results for "Exact Matches". Consider it similar to Google's double quote search but only on content…

---

## [What's the equivalent of NEST TermRangeQuery in the new ES 8.x client?](https://discuss.elastic.co/t/whats-the-equivalent-of-nest-termrangequery-in-the-new-es-8-x-client/346538)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 8:50am UTC](https://discuss.elastic.co/t/whats-the-equivalent-of-nest-termrangequery-in-the-new-es-8-x-client/346538 "2023-11-07T08:50:48Z")

</div>

The NEST client for ES 7 has TermRangeQuery class, which covers the case when the rage query is used with Text and Keyword fields. However, I can't find the equivalent in the new ES 8.x client. There's a class called Ra…

---

## [\_ingest.timestamp does not match my local time](https://discuss.elastic.co/t/ingest-timestamp-does-not-match-my-local-time/346600)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 8:15am UTC](https://discuss.elastic.co/t/ingest-timestamp-does-not-match-my-local-time/346600 "2023-11-07T08:15:47Z")

</div>

I am currently in GMT+8 time zone, I have created this pipeline so that when indexing new document, the new document is created with a timestamp PUT \_ingest/pipeline/add-current-time { "processors": \[ { "se…

---

## [Change path.data in elasticsearh cluster node](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:07am UTC](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596 "2023-11-07T07:07:26Z")

</div>

May I got 3 node elasticsearch cluster. Is it possible to change the path.data If yes. What is the recommended procedure?

---

## [Extend the size of ElasticSearch path.data](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:04am UTC](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595 "2023-11-07T07:04:00Z")

</div>

I got a elasticsearch cluster with 3 nodes. Each node got a path.data (size 5T) Which is a virtual harddisk. I would like to know is it possible to enlarge the disk storage by extend the virtual disk to 10T. If it is …

---

## [Curl ssl error to elasticsearch server via filebeat](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 4:52am UTC](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420 "2023-11-07T04:52:57Z")

</div>

This is my filebeat output test : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 172.10.110.29 dial up..…

---

## [How to catch an exception for "Authentication using apikey failed - api key is expired"](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 4:48am UTC](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158 "2023-11-07T04:48:54Z")

</div>

I am using client lib to perform a search operation. The API key used for constructing an ElasticsearchClient expired. How can I catch this specific type of "API Key expired" error, so that I can handle it, e.g. creating…

---

## [Elastic SQL CLI Error](https://discuss.elastic.co/t/elastic-sql-cli-error/345905)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 6\
**Last updated:** [November 7, 2023, 4:46am UTC](https://discuss.elastic.co/t/elastic-sql-cli-error/345905 "2023-11-07T04:46:29Z")

</div>

HI Team, I am able to connect to Elastic sql CLI but while querying the index data getting below error. Could you please help me on this. sql\> select \* from employee; Communication error \[Cannot POST address http://1…

---

## [Use search or scroll for large dataset which needs aggregations](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578)

<div class="topic-metadata">

**Author:** [@nboisnea1](https://discuss.elastic.co/u/nboisnea1)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:45pm UTC](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578 "2023-11-06T22:45:38Z")

</div>

Hi! I'm new to Elasticsearch and I have a particular use case for which I don't know if I should use a basic search or a scroll search. I have an index in which I periodically save a copy of JSON documents. Each JSON do…

---

## [Connection reset by peer](https://discuss.elastic.co/t/connection-reset-by-peer/346570)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:58pm UTC](https://discuss.elastic.co/t/connection-reset-by-peer/346570 "2023-11-06T20:58:22Z")

</div>

We are using Elasticsearch cloud version. We are connecting to Elasticsearch cloud using Elasticsearch java api client. However, we are getting "IOException : connection reset by peer" error randomly. It seems this error…

---

## [My Elasticsearch experiences freezing 3 to 4 times a day](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438)

<div class="topic-metadata">

**Author:** [@ihatecrypto](https://discuss.elastic.co/u/ihatecrypto)\
**Replies:** 9\
**Last updated:** [November 6, 2023, 8:39pm UTC](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438 "2023-11-06T20:39:49Z")

</div>

Hello everyone, I'm currently facing an issue that's not well defined. . The freezing periods last approximately 30 to 60 seconds. During these periods, I'm unable to query it using Kibana or the Nodejs client. I've…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=179)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=181)
