# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=183

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 184

---

## [Elasticsearch Export Import](https://discuss.elastic.co/t/elasticsearch-export-import/346143)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 4:11pm UTC](https://discuss.elastic.co/t/elasticsearch-export-import/346143 "2023-10-31T16:11:44Z")

</div>

Hi Team, I had a requirement where I need export/ import one of the index data to a separate cluster. Is there any such tool which help me to achieve the same. Thanks, Debasis

---

## [Unbalanced CPU load when enabling vector search](https://discuss.elastic.co/t/unbalanced-cpu-load-when-enabling-vector-search/346150)

<div class="topic-metadata">

**Author:** [@FlorianL](https://discuss.elastic.co/u/FlorianL)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 4:06pm UTC](https://discuss.elastic.co/t/unbalanced-cpu-load-when-enabling-vector-search/346150 "2023-10-31T16:06:07Z")

</div>

Hello everyone, I have been trying to work with vector search at scale, but I ends up into a very awkward unstable state of my cluster. I have browse this forum but did not find someone sharing a similar problem to mine…

---

## [message":"error fetching EC2 Identity Document: operation error ec2imds: GetInstance Identity Document, exceeded maximum number of attempts, 3, request send failed, Get \\"http://169.254.169.254/latest/dynamic/instance-identity/document\\": dial tcp 169.254](https://discuss.elastic.co/t/message-error-fetching-ec2-identity-document-operation-error-ec2imds-getinstance-identity-document-exceeded-maximum-number-of-attempts-3-request-send-failed-get-http-169-254-169-254-latest-dynamic-instance-identity-document-dial-tcp-169-254/346140)

<div class="topic-metadata">

**Author:** [@pedada](https://discuss.elastic.co/u/pedada)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 2:13pm UTC](https://discuss.elastic.co/t/message-error-fetching-ec2-identity-document-operation-error-ec2imds-getinstance-identity-document-exceeded-maximum-number-of-attempts-3-request-send-failed-get-http-169-254-169-254-latest-dynamic-instance-identity-document-dial-tcp-169-254/346140 "2023-10-31T14:13:12Z")

</div>

message":"error fetching EC2 Identity Document: operation error ec2imds: GetInstance Identity Document, exceeded maximum number of attempts, 3, request send failed, Get "http://169.254.169.254/latest/dynamic/instance-ide…

---

## [Elasticsearch cluster configuration for intensive write](https://discuss.elastic.co/t/elasticsearch-cluster-configuration-for-intensive-write/346107)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 11:31am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-configuration-for-intensive-write/346107 "2023-10-31T11:31:25Z")

</div>

Hi, I need to index ~1TB data per day. I have the required HW and want to know which cluster should I raise, means How many nodes, How many shards, etc. Is there any formula for that? Thanks.

---

## [Object mapping for \[protoPayload.response.status\] tried to parse field \[status\] as object, but found a concrete value (document\_parsing\_exception)](https://discuss.elastic.co/t/object-mapping-for-protopayload-response-status-tried-to-parse-field-status-as-object-but-found-a-concrete-value-document-parsing-exception/346117)

<div class="topic-metadata">

**Author:** [@narrayana\_swamy](https://discuss.elastic.co/u/narrayana_swamy)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 10:38am UTC](https://discuss.elastic.co/t/object-mapping-for-protopayload-response-status-tried-to-parse-field-status-as-object-but-found-a-concrete-value-document-parsing-exception/346117 "2023-10-31T10:38:55Z")

</div>

Hi, I am trying to load the data via GCP dataflow to elasticsearch, but i am getting the below error. i am not using any agents. i have installed the GCP integrations. "Error message from worker: java.io.IOException: Er…

---

## [Elastic data large exception (Data too large, data for \[http\_request\])](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 12:25am UTC](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907 "2023-10-31T00:25:14Z")

</div>

Hello, Could you please help on below issue . we getting this issue on Elastic and kibana. \`1e9fa016\]\[trial #34\] null during Elasticsearch operation (ElasticsearchStatusException\[Elasticsearch exception \[type=circuit\_b…

---

## [Data too large for response \[parent\]](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048)

<div class="topic-metadata">

**Author:** [@uhlirradek95](https://discuss.elastic.co/u/uhlirradek95)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 12:22am UTC](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048 "2023-10-31T00:22:48Z")

</div>

Hi, could you please help me to understand following exception? Cluster configuration: 3 nodes each 6CPU, 32GB RAM, completely on SSD While making a search request, following exception occours: \[Invalid response ret…

---

## [MySQL Connector cannot connect to Elasticsearch Docker Instance](https://discuss.elastic.co/t/mysql-connector-cannot-connect-to-elasticsearch-docker-instance/346043)

<div class="topic-metadata">

**Author:** [@James\_Cook1](https://discuss.elastic.co/u/James_Cook1)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 3:38pm UTC](https://discuss.elastic.co/t/mysql-connector-cannot-connect-to-elasticsearch-docker-instance/346043 "2023-10-30T15:38:23Z")

</div>

Hello We are currently in the process of attempting to set up a locally running instance of Elasticsearch to connect to a MySQL database using Docker Containers but are unable to get this to work. We are following the …

---

## [Extract Exception Class](https://discuss.elastic.co/t/extract-exception-class/346046)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:21pm UTC](https://discuss.elastic.co/t/extract-exception-class/346046 "2023-10-30T14:21:54Z")

</div>

Hello, what is the best way to extract the exception from the following log? I only need the exception class NullpointerException e.g. My attempt: %{TIMESTAMP\_ISO8601:log\_timestamp}.%{LOGLEVEL:log\_level}.\[%{GREEDYDATA:…

---

## [search profile breakdown](https://discuss.elastic.co/t/search-profile-breakdown/346041)

<div class="topic-metadata">

**Author:** [@getsolaris](https://discuss.elastic.co/u/getsolaris)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:17pm UTC](https://discuss.elastic.co/t/search-profile-breakdown/346041 "2023-10-30T14:17:59Z")

</div>

hello, I'm using Elasticsearch's profile API to try and figure out what's taking so long. I currently have an index implemented with parent-child modeling. When I run a has\_child query, I am getting a high match in my…

---

## [How exlude particular index from ilm policy](https://discuss.elastic.co/t/how-exlude-particular-index-from-ilm-policy/345792)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 4\
**Last updated:** [October 30, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-exlude-particular-index-from-ilm-policy/345792 "2023-10-30T14:15:55Z")

</div>

Hi, OS : 22.04 linux ES version: 7.17.0 I have created ilm policy like delete all indexes after 45 days. I am using \* in policy. but I want to exclude particular index pattern which is not deleted or ilm policy is not…

---

## [Sync Postgresql and Elasticsearch using Filebeat](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 1:43pm UTC](https://discuss.elastic.co/t/sync-postgresql-and-elasticsearch-using-filebeat/345576 "2023-10-30T13:43:55Z")

</div>

Hi, I have a considerable amount of information in a Postgresql database. Registers are inserted on this database on demand. We are currently interested in syncronize this database and Elasticsearch in order to have the…

---

## [ELK | Logging | filter out specific ip's generated WARNs?](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040)

<div class="topic-metadata">

**Author:** [@LucGasper](https://discuss.elastic.co/u/LucGasper)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 1:33pm UTC](https://discuss.elastic.co/t/elk-logging-filter-out-specific-ips-generated-warns/346040 "2023-10-30T13:33:04Z")

</div>

Hi elk lovers, in our Company we are subjected daily to security penetration tests. All these tests are originated by a specific static ip. Our elasticsearch log is therefore filled up with WARNs, especially: ... \[2…

---

## [Elasticsearch node ram.percent at 100%](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022)

<div class="topic-metadata">

**Author:** [@rahmathm1](https://discuss.elastic.co/u/rahmathm1)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 10:57am UTC](https://discuss.elastic.co/t/elasticsearch-node-ram-percent-at-100/346022 "2023-10-30T10:57:33Z")

</div>

Hi, everyone, We have a 6x6 setup of ES deployed on Kubernetes. When we check node memory statistics, we can see that data nodes are using 100% of ram allocated to them. Below are the resource limits for data nodes: l…

---

## [Run painless script in cron like manner](https://discuss.elastic.co/t/run-painless-script-in-cron-like-manner/346017)

<div class="topic-metadata">

**Author:** [@Pawel\_Gorowicz](https://discuss.elastic.co/u/Pawel_Gorowicz)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 10:01am UTC](https://discuss.elastic.co/t/run-painless-script-in-cron-like-manner/346017 "2023-10-30T10:01:36Z")

</div>

Hi All, I'm searching for an options to run a script in cron like manner. I need to run "\_update\_by\_query" with tiny painless script every few hours to fix some data inside the index. Is there any option to do that ?

---

## [Concurrent Enrich Policy Execution](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011)

<div class="topic-metadata">

**Author:** [@Akshey](https://discuss.elastic.co/u/Akshey)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 8:32am UTC](https://discuss.elastic.co/t/concurrent-enrich-policy-execution/346011 "2023-10-30T08:32:36Z")

</div>

Hi Team, We've added an enrichment policy to join data among two indexes. The indexes are dynamic, hence we are running the execute policy query whenever there's an update in the source index. The problem is when there …

---

## [Synonym search latency](https://discuss.elastic.co/t/synonym-search-latency/346001)

<div class="topic-metadata">

**Author:** [@vanduong](https://discuss.elastic.co/u/vanduong)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 3:51am UTC](https://discuss.elastic.co/t/synonym-search-latency/346001 "2023-10-30T03:51:00Z")

</div>

I recently utilized synonyms in an Elasticsearch context. After reading a blog that discusses the advantages of applying synonyms at search time as opposed to index time, I began to wonder if using synonyms at search tim…

---

## [Index data storage into a cluster](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298)

<div class="topic-metadata">

**Author:** [@MattzGB](https://discuss.elastic.co/u/MattzGB)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 11:07pm UTC](https://discuss.elastic.co/t/index-data-storage-into-a-cluster/344298 "2023-10-29T23:07:13Z")

</div>

I have an elasticsearch cluster with 3 nodes where the elasticsearch service is installed on each node. When I check the cluster health and the index on each node, I can see that the cluster is green and that the 25GB i…

---

## [Prioritizing Indices for Search Speed](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973)

<div class="topic-metadata">

**Author:** [@maorethians](https://discuss.elastic.co/u/maorethians)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 10:09pm UTC](https://discuss.elastic.co/t/prioritizing-indices-for-search-speed/345973 "2023-10-29T22:09:48Z")

</div>

We have an Elasticsearch instance, containing 100s of indices in it with different, statically-defined mappings. Is there a way to prioritize some of them for read/write operations not to be affected by low-priority ones…

---

## [Question about discuss.elastic.co](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 2\
**Last updated:** [October 29, 2023, 5:32pm UTC](https://discuss.elastic.co/t/question-about-discuss-elastic-co/345984 "2023-10-29T17:32:20Z")

</div>

Hello: I was trying to ask a question on discuss.elastic.co and I see that I cannot do that anymore. Not sure why. Maybe you could find out why I am blacklisted there.

---

## [HAYSTACK\_CONNECTIONS](https://discuss.elastic.co/t/haystack-connections/345829)

<div class="topic-metadata">

**Author:** [@sdarwin](https://discuss.elastic.co/u/sdarwin)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 11:49am UTC](https://discuss.elastic.co/t/haystack-connections/345829 "2023-10-29T11:49:29Z")

</div>

Hi, Not sure which category to post this in. Django Haystack GitHub - django-haystack/django-haystack: Modular search for Django supports Elasticsearch as a backend search engine. The connection is specified this way: H…

---

## [Elastic 8.10.3 failed to establish trust with server at \[\<unknown host\>\]; the server provided a certificate with subject name](https://discuss.elastic.co/t/elastic-8-10-3-failed-to-establish-trust-with-server-at-unknown-host-the-server-provided-a-certificate-with-subject-name/345656)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 8\
**Last updated:** [October 29, 2023, 11:21am UTC](https://discuss.elastic.co/t/elastic-8-10-3-failed-to-establish-trust-with-server-at-unknown-host-the-server-provided-a-certificate-with-subject-name/345656 "2023-10-29T11:21:41Z")

</div>

Hello good morning! I am trying to create an elastic cluster in version 8.10.3 but when starting the coordinator role I get the following error: \[ithrtc3aen1elk1-coordinator-1\] failed to establish trust with server at …

---

## [Can not connect Logstash to Elasticsearch](https://discuss.elastic.co/t/can-not-connect-logstash-to-elasticsearch/345867)

<div class="topic-metadata">

**Author:** [@liaotoca](https://discuss.elastic.co/u/liaotoca)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 11:15am UTC](https://discuss.elastic.co/t/can-not-connect-logstash-to-elasticsearch/345867 "2023-10-29T11:15:16Z")

</div>

I follow the instructions here Secure your connection to Elasticsearch | Logstash Reference \[8.10\] | Elastic but if I did not put the username/password, logstash reported 401, if I put in the user name /password, the sta…

---

## [Master Node cant connect](https://discuss.elastic.co/t/master-node-cant-connect/345899)

<div class="topic-metadata">

**Author:** [@Nerd0](https://discuss.elastic.co/u/Nerd0)\
**Replies:** 1\
**Last updated:** [October 29, 2023, 11:11am UTC](https://discuss.elastic.co/t/master-node-cant-connect/345899 "2023-10-29T11:11:27Z")

</div>

Hi, I have a problem caused by: sun.security.validator.ValidatorException: PKIX path validation failed: java.security.cert.CertPathValidatorException: Path does not chain with any of the trust anchors I configured 3 nod…

---

## [How to restore .security index from snapshot](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959)

<div class="topic-metadata">

**Author:** [@dna01](https://discuss.elastic.co/u/dna01)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/how-to-restore-security-index-from-snapshot/344959 "2023-10-29T11:06:56Z")

</div>

what is the recommended approach to restore .security index from snapshot? the index needs to be closed to be restored, but once it is closed, users cannot login anymore. and the whole database stuck since it cannot lo…

---

## [Logs don't show up on kibana](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930)

<div class="topic-metadata">

**Author:** [@yassinebad](https://discuss.elastic.co/u/yassinebad)\
**Replies:** 8\
**Last updated:** [October 29, 2023, 11:06am UTC](https://discuss.elastic.co/t/logs-dont-show-up-on-kibana/345930 "2023-10-29T11:06:23Z")

</div>

Hey I am using winlogbeat on my windows machine with sysmon64. my winlogbeat.yml file is configured correctly. I have checked with the config command. once I run ./winlogbeat.exe setup -e ! my index and dashboards get …

---

## [Restore snapshot with curl](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 5:49pm UTC](https://discuss.elastic.co/t/restore-snapshot-with-curl/345961 "2023-10-28T17:49:04Z")

</div>

Hi, I have snapshot of indexes pattern .\*, now after Kibana problems due power off I have to restore .kibana\* indexes to fix my problems. How can I do it with curl (as Kibana doesn't work)?

---

## [I have the same problem](https://discuss.elastic.co/t/i-have-the-same-problem/345963)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 2\
**Last updated:** [October 28, 2023, 1:54pm UTC](https://discuss.elastic.co/t/i-have-the-same-problem/345963 "2023-10-28T13:54:04Z")

</div>

Continuing the discussion from How to re-run cluster with different cluster uuid:

---

## [Get all ids with Python](https://discuss.elastic.co/t/get-all-ids-with-python/344689)

<div class="topic-metadata">

**Author:** [@marc.schwarzschild](https://discuss.elastic.co/u/marc.schwarzschild)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 9:51pm UTC](https://discuss.elastic.co/t/get-all-ids-with-python/344689 "2023-10-27T21:51:21Z")

</div>

Hi, I'd like to use the elastic\_enterprise\_search.AppSearch package to get all our document ids. I have tried many things and always hit the 10k result limit. I understand that "scrolling" may be the solution but have…

---

## [Why doesn't elser\_model\_1 generate the Vectors during index?](https://discuss.elastic.co/t/why-doesnt-elser-model-1-generate-the-vectors-during-index/345920)

<div class="topic-metadata">

**Author:** [@mbastarache](https://discuss.elastic.co/u/mbastarache)\
**Replies:** 3\
**Last updated:** [October 27, 2023, 8:29pm UTC](https://discuss.elastic.co/t/why-doesnt-elser-model-1-generate-the-vectors-during-index/345920 "2023-10-27T20:29:46Z")

</div>

No matter what I try, I don't get any errors during indexing, but when I search, the ml\_title and ml\_description fields are not in the results. When I look at the mappings, they are there with the correct configurations…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=182)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=184)
