# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=182

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 183

---

## [Coordinating Nodes High Circuit Breaker Tripped Counts](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 11\
**Last updated:** [November 3, 2023, 2:37am UTC](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161 "2023-11-03T02:37:24Z")

</div>

Hi All, I'm curious if anyone has any ideas on an issue I'm seeing. I have a cluster of 33 nodes, 3 of these nodes are coordinating only nodes that handle all requests. I've been noticing that these coordinating nodes…

---

## [Manually Add node to cluster Elasticsearch 8.6](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322)

<div class="topic-metadata">

**Author:** [@syifelastic](https://discuss.elastic.co/u/syifelastic)\
**Replies:** 4\
**Last updated:** [November 3, 2023, 1:52am UTC](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322 "2023-11-03T01:52:51Z")

</div>

Hello. I have a 3 node Elasticsearch cluster. I originally set up the 3 nodes with an enrollment token. However, I later changed from http keystore to a certificate/key configuration in the yml. This breaks the enrollme…

---

## [Http.p12 structure and use of keytool](https://discuss.elastic.co/t/http-p12-structure-and-use-of-keytool/346325)

<div class="topic-metadata">

**Author:** [@ken33](https://discuss.elastic.co/u/ken33)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 11:04pm UTC](https://discuss.elastic.co/t/http-p12-structure-and-use-of-keytool/346325 "2023-11-02T23:04:35Z")

</div>

Hi, In elasticsearch, I can execute : /usr/share/elasticsearch/jdk/bin/keytool -list -keystore http.p12.orig Enter keystore password: Keystore type: PKCS12 Keystore provider: SUN Your keystore contains 2 entries h…

---

## [Index Object structure](https://discuss.elastic.co/t/index-object-structure/346156)

<div class="topic-metadata">

**Author:** [@volkerfrank](https://discuss.elastic.co/u/volkerfrank)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 6:36pm UTC](https://discuss.elastic.co/t/index-object-structure/346156 "2023-11-02T18:36:29Z")

</div>

Hi, how can I index a document with this fields to an index? .. "gitlab": { "path": "/api/v4/jobs/request", "method": "POST", …

---

## [ElastiSearch consuming above 90% RAM memory continuously](https://discuss.elastic.co/t/elastisearch-consuming-above-90-ram-memory-continuously/345812)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 6:31pm UTC](https://discuss.elastic.co/t/elastisearch-consuming-above-90-ram-memory-continuously/345812 "2023-11-02T18:31:11Z")

</div>

Hello, Elastic Search continuously occupying above 90% . Total RAM : 108 GB JVM: 32 GB ( 28Gb used out of 32GB) Single Node Elastic search. Could you please suggest/help how to reduce the RAM usage. Thanks in adva…

---

## [If there is an error log in an application, how to send log files onto elastic search](https://discuss.elastic.co/t/if-there-is-an-error-log-in-an-application-how-to-send-log-files-onto-elastic-search/345906)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 21\
**Last updated:** [November 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/if-there-is-an-error-log-in-an-application-how-to-send-log-files-onto-elastic-search/345906 "2023-11-02T16:01:42Z")

</div>

if there is an error log in an application, how to send log files onto Elasticsearch

---

## [Elasticsearch vm.max\_map\_count error in docker image on MacOS 14](https://discuss.elastic.co/t/elasticsearch-vm-max-map-count-error-in-docker-image-on-macos-14/346285)

<div class="topic-metadata">

**Author:** [@timofeyp](https://discuss.elastic.co/u/timofeyp)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:54pm UTC](https://discuss.elastic.co/t/elasticsearch-vm-max-map-count-error-in-docker-image-on-macos-14/346285 "2023-11-02T15:54:29Z")

</div>

Hello! I have the "vm.max\_map\_count \[65530\] is too low, increase to at least \[262144\]" error while elastic container starting on Docker 4.25, MacOS 14 and ARM core. Here is my container props: image: elasticsearch…

---

## [Elastic Architecture review](https://discuss.elastic.co/t/elastic-architecture-review/345987)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 3:24pm UTC](https://discuss.elastic.co/t/elastic-architecture-review/345987 "2023-11-02T15:24:03Z")

</div>

We are planning to deploy elastic stack for logging and monitoring as SIEM, we want to start from open source version (community version) and if we see value we would upgrade to enterprise version with full security feat…

---

## [Elasticsearch 8.10.2 synonyms not working](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working/346303)

<div class="topic-metadata">

**Author:** [@smritibhandari91](https://discuss.elastic.co/u/smritibhandari91)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 3:16pm UTC](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working/346303 "2023-11-02T15:16:53Z")

</div>

We have deployed Elasticsearch 8.10.2 via ECK. The deployment is successful, however, we are facing below two issues: Index creation failing with IOException while reading synonyms\_path\_path. Synonym path has been succ…

---

## [Random access pagination with search\_after on Elasticsearch](https://discuss.elastic.co/t/random-access-pagination-with-search-after-on-elasticsearch/346203)

<div class="topic-metadata">

**Author:** [@cerenimo](https://discuss.elastic.co/u/cerenimo)\
**Replies:** 6\
**Last updated:** [November 2, 2023, 11:51am UTC](https://discuss.elastic.co/t/random-access-pagination-with-search-after-on-elasticsearch/346203 "2023-11-02T11:51:18Z")

</div>

There are more than 10 thousand documents in my index, but I cannot access all documents with search. I may also have performance problems with the scroll API. I found a method on how to overcome this with search\_after i…

---

## [How to modify index creation time on restored indices?](https://discuss.elastic.co/t/how-to-modify-index-creation-time-on-restored-indices/346284)

<div class="topic-metadata">

**Author:** [@Kavinkumar\_C](https://discuss.elastic.co/u/Kavinkumar_C)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 11:43am UTC](https://discuss.elastic.co/t/how-to-modify-index-creation-time-on-restored-indices/346284 "2023-11-02T11:43:54Z")

</div>

We have an ILM policy that deletes data after 7 days of index creation. We also take snapshots of the indices and store them for upto 30 days. Whenever we restore a backup, the ILM policy is executed, and the restored in…

---

## [Compare values across two indicies](https://discuss.elastic.co/t/compare-values-across-two-indicies/346279)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 10:31am UTC](https://discuss.elastic.co/t/compare-values-across-two-indicies/346279 "2023-11-02T10:31:21Z")

</div>

Hi, i want to compare two fields in two indexes in elasticsearch and return a hit if they match. For example: Index1: -hostname: "computer" Index2: -host\_name: "computer" If hostname value equals to host\_name value, I…

---

## [Is it possible to accelerating aggregations by using SIMD instructions?](https://discuss.elastic.co/t/is-it-possible-to-accelerating-aggregations-by-using-simd-instructions/346271)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 9:26am UTC](https://discuss.elastic.co/t/is-it-possible-to-accelerating-aggregations-by-using-simd-instructions/346271 "2023-11-02T09:26:23Z")

</div>

Is it possible to accelerating elasticsearch's aggregations by using SIMD instructions? OLAP databases like ClickHouse, TiDB, StarRocks use this way to achieve great performance.

---

## [Ingest: transforming multiple values in an array](https://discuss.elastic.co/t/ingest-transforming-multiple-values-in-an-array/346147)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 2\
**Last updated:** [November 2, 2023, 8:35am UTC](https://discuss.elastic.co/t/ingest-transforming-multiple-values-in-an-array/346147 "2023-11-02T08:35:42Z")

</div>

Hey, I'm looking for a way to transform { "related": { "user": \[ "user1@domain", "user2@anotherdomain" \] } } into { "related": { "user": \[ "user1@domain", "user1", "use…

---

## [Write bulk is stick for a long time](https://discuss.elastic.co/t/write-bulk-is-stick-for-a-long-time/346265)

<div class="topic-metadata">

**Author:** [@bxl](https://discuss.elastic.co/u/bxl)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 7:08am UTC](https://discuss.elastic.co/t/write-bulk-is-stick-for-a-long-time/346265 "2023-11-02T07:08:47Z")

</div>

elasticsearch version: 7.16.2 os: rhel 7.9 es node load very high, write task execution 1-2 hours, help me, thanks hot\_threads 100.0% \[cpu=11.1%, other=88.9%\] (500ms out of 500ms) cpu usage by thread 'elasticsearch\[i…

---

## [Aborting enrolling to cluster. Could not communicate with the node on any of the addresses from the enrolment token](https://discuss.elastic.co/t/aborting-enrolling-to-cluster-could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrolment-token/346174)

<div class="topic-metadata">

**Author:** [@Vyshak\_Sekhar](https://discuss.elastic.co/u/Vyshak_Sekhar)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:47am UTC](https://discuss.elastic.co/t/aborting-enrolling-to-cluster-could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrolment-token/346174 "2023-11-02T03:47:16Z")

</div>

I am trying to install a 2 node Elasticsearch cluster , i installed and my Elasticsearch that node is running fine and while im trying to connect the next node to the using enrollment token im getting this borting enroll…

---

## [Date Range Search based on Oldest Document](https://discuss.elastic.co/t/date-range-search-based-on-oldest-document/346255)

<div class="topic-metadata">

**Author:** [@samjsem](https://discuss.elastic.co/u/samjsem)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:03am UTC](https://discuss.elastic.co/t/date-range-search-based-on-oldest-document/346255 "2023-11-02T03:03:48Z")

</div>

Hi team, I am writing to ask: What is the best way to construct a query to satisfy the following requirement: Date range specification in the filter clause of a boolean query so that gte is based on the oldest document …

---

## [How to convert field to Java properties](https://discuss.elastic.co/t/how-to-convert-field-to-java-properties/346104)

<div class="topic-metadata">

**Author:** [@Hsu\_Demon](https://discuss.elastic.co/u/Hsu_Demon)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:11am UTC](https://discuss.elastic.co/t/how-to-convert-field-to-java-properties/346104 "2023-11-02T02:11:09Z")

</div>

I use elasticsearch-java version 8.10.4 rather than spring-data-elasticsearch. In my elasticsearch index, the field is underline-word such as "user\_id". But in my Java Object, it is "userId". when i get the SearchRespo…

---

## [Supply ElasticSearch Keystore password to start ElasticSearch Service](https://discuss.elastic.co/t/supply-elasticsearch-keystore-password-to-start-elasticsearch-service/346160)

<div class="topic-metadata">

**Author:** [@ChrisMannix](https://discuss.elastic.co/u/ChrisMannix)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 6:38pm UTC](https://discuss.elastic.co/t/supply-elasticsearch-keystore-password-to-start-elasticsearch-service/346160 "2023-11-01T18:38:12Z")

</div>

Hi, I have been building my Elasticsearch cluster and I was playing around with the Elasticsearch keystore. If I change the Elasticsearch keystore password, the Elasticsearch service does not start anymore. This makes…

---

## [ELK in docker - fleet server on the host](https://discuss.elastic.co/t/elk-in-docker-fleet-server-on-the-host/346230)

<div class="topic-metadata">

**Author:** [@ken33](https://discuss.elastic.co/u/ken33)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 5:50pm UTC](https://discuss.elastic.co/t/elk-in-docker-fleet-server-on-the-host/346230 "2023-11-01T17:50:57Z")

</div>

Dear all, Sorry for asking a question allready seen question but not enough details to solve the pb. I install elk in docker according to the doc Docker is running on a host 192.168.50.3. Docker network is 172.19.0.0…

---

## [Splitting different usages in clusters?](https://discuss.elastic.co/t/splitting-different-usages-in-clusters/346215)

<div class="topic-metadata">

**Author:** [@grumpy](https://discuss.elastic.co/u/grumpy)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 4:41pm UTC](https://discuss.elastic.co/t/splitting-different-usages-in-clusters/346215 "2023-11-01T16:41:28Z")

</div>

We have multiple apps indexing their own data. We're setting up our new server and are thinking of optimizing our configurations. When does it make sense to have different clusters for the different apps? What are the …

---

## [Elastic Cross Cluster Replication of Data Stream](https://discuss.elastic.co/t/elastic-cross-cluster-replication-of-data-stream/346178)

<div class="topic-metadata">

**Author:** [@adsandie](https://discuss.elastic.co/u/adsandie)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 3:05pm UTC](https://discuss.elastic.co/t/elastic-cross-cluster-replication-of-data-stream/346178 "2023-11-01T15:05:00Z")

</div>

Both Cluster are using v8.9.1 Hi, this is a new upgrade from 7.16.3 to 8.9.1 and we just reconfigured CCR. This is our first time using CCR on a data stream. We have been using CCR before on Index (metricbeat-, filebeat…

---

## [Azure Blob Storage to Elasticsearch - SaaS Elastic Cloud in Azure](https://discuss.elastic.co/t/azure-blob-storage-to-elasticsearch-saas-elastic-cloud-in-azure/346194)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 11:44am UTC](https://discuss.elastic.co/t/azure-blob-storage-to-elasticsearch-saas-elastic-cloud-in-azure/346194 "2023-11-01T11:44:52Z")

</div>

What are the options to load the JSON/CSV files from Azure Blob Storage to Elasticsearch (Elastic Cloud in Azure) I see the following filebeat module is in Beta.

---

## [Get records from index based on result from another search](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 5\
**Last updated:** [November 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074 "2023-11-01T10:41:01Z")

</div>

Hi, I have an index where we collect the requests to our api somthing like this : myindex: url: /some/path service: someservice uuid: xxx-yyy-zzz-uuu And I have a requirement to get or correlate all urls that…

---

## [Performance degrade after using Elastic 8](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 3\
**Last updated:** [November 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703 "2023-11-01T08:00:08Z")

</div>

We have been using elastic 7.17 Our application has load tests and we generally measure the performance After upgrading to elastic 8, we see lot of difference in the results we had when compared to elastic 7 We also n…

---

## [Best approach to combine two different ES instances in one instance](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 7:34am UTC](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177 "2023-11-01T07:34:05Z")

</div>

I have two instances running from two different drives. I would like to combine both. I have two approaches. Shutdown second node and use the data path of the second node in the first node as a multi-data path option c…

---

## [Consider comma separated values in a field as separate values while aggregating](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804)

<div class="topic-metadata">

**Author:** [@Gagan\_Saluja](https://discuss.elastic.co/u/Gagan_Saluja)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 4:26am UTC](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804 "2023-11-01T04:26:34Z")

</div>

Hi, i want to do aggregation on a field which has values like doc1\_field: "A" doc2\_field: "A, B" doc3\_field: "A, B, C" What mappings / settings I can use so that when I aggregate on this field I should get results l…

---

## [Ilm rollover error on datastream index](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 2:30am UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164 "2023-11-01T02:30:10Z")

</div>

I one index of a datastream showing an ILM error: java.lang.IllegalStateException: no rollover info found for \[.ds-sec-events-2023.08.12-000015\] with rollover target \[sec-events\], the index has not yet rolled over with …

---

## [Hardware Requirements - Self hosted in Cloud](https://discuss.elastic.co/t/hardware-requirements-self-hosted-in-cloud/346067)

<div class="topic-metadata">

**Author:** [@bEngineer](https://discuss.elastic.co/u/bEngineer)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 10:27pm UTC](https://discuss.elastic.co/t/hardware-requirements-self-hosted-in-cloud/346067 "2023-10-31T22:27:27Z")

</div>

Hi everyone, I'm researching scalability costs for an elasticsearch search engine project. I understand some hardware requirements on a small scale, large scale I'm having a hard time wrapping my head around it. I have…

---

## [Find transactions flow](https://discuss.elastic.co/t/find-transactions-flow/346059)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 5:39pm UTC](https://discuss.elastic.co/t/find-transactions-flow/346059 "2023-10-31T17:39:29Z")

</div>

Hi Is there anyway to find transaction flow like this i have log file contain 50 million transactions like this 16:30:53:002 moduleA:\[C1\]L\[143\]F\[10\]ID\[123456\] 16:30:54:002 moduleA:\[C2\]L\[143\]F\[20\]ID\[123456\] 16:30:55:00…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=181)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=183)
