# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=187

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 188

---

## [Background Count (bg\_count) Remains Zero in Nested and Filtered significant\_terms Aggregation](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413)

<div class="topic-metadata">

**Author:** [@Emporea](https://discuss.elastic.co/u/Emporea)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 3:38pm UTC](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413 "2023-10-20T15:38:20Z")

</div>

Hi everyone, I've recently started using the significant\_terms aggregation with a nested field in my index, and I've noticed that the results are very similar to those of a standard terms aggregation. This leads me to b…

---

## [Cannot generate enrollment token](https://discuss.elastic.co/t/cannot-generate-enrollment-token/345465)

<div class="topic-metadata">

**Author:** [@Diego667](https://discuss.elastic.co/u/Diego667)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 2:25pm UTC](https://discuss.elastic.co/t/cannot-generate-enrollment-token/345465 "2023-10-20T14:25:03Z")

</div>

Hello, I'm using ELK 8.10. I have a working cluster composed by : 1 master + data node 1 data node Security layer has been configured manually using those documentation : TLS/SSL HTTP I did not entered any …

---

## [Java API for terms](https://discuss.elastic.co/t/java-api-for-terms/345461)

<div class="topic-metadata">

**Author:** [@mfrob](https://discuss.elastic.co/u/mfrob)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 1:34pm UTC](https://discuss.elastic.co/t/java-api-for-terms/345461 "2023-10-20T13:34:02Z")

</div>

Hi, I hope someone finds this. I am very new to elasticsearch. Currently I have this code snippet in my java file to search based on customer identification card (IC) number. I am able to fetch and search based off just…

---

## [Elastic APM server Elastic search connection not able to establish](https://discuss.elastic.co/t/elastic-apm-server-elastic-search-connection-not-able-to-establish/345459)

<div class="topic-metadata">

**Author:** [@Rajat\_Gupta1](https://discuss.elastic.co/u/Rajat_Gupta1)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 12:34pm UTC](https://discuss.elastic.co/t/elastic-apm-server-elastic-search-connection-not-able-to-establish/345459 "2023-10-20T12:34:21Z")

</div>

Hi All need Some help with existing elastic stack.I have used official helm charts for deployment of the elastic stack I have apm-server Elastic Search and Kibana to be deployed When I try to get health of Elastics…

---

## [Managing Real-time and Batch Processing in Elasticsearch to Prevent Document Resurrection](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452)

<div class="topic-metadata">

**Author:** [@taichi](https://discuss.elastic.co/u/taichi)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 10:17am UTC](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452 "2023-10-20T10:17:41Z")

</div>

Hello, I'm facing a challenge and need your expertise. In our system, we have a real-time process that adds or removes documents in an Elasticsearch index based on changes in an RDBMS. Alongside, we also have a batch pr…

---

## [Are comments supported in the synonyms file?](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442)

<div class="topic-metadata">

**Author:** [@peterge1998](https://discuss.elastic.co/u/peterge1998)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 8:08am UTC](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442 "2023-10-20T08:08:32Z")

</div>

We set up a new way to deploy the synonyms file to our elasticsearch hosts in our company using gitlab ci cd and ansible. Now we would like to include a comment into the synonyms file, some this like "Ansible managed, ed…

---

## [Is Elastic	Winlogbeat MSI still beta version?](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437)

<div class="topic-metadata">

**Author:** [@Metaad](https://discuss.elastic.co/u/Metaad)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 7:01am UTC](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437 "2023-10-20T07:01:15Z")

</div>

Am downloading ElasticWinlogbeat from Download Winlogbeat | Ship Windows Event Logs | Elastic | Elastic The name of the .msi shows beta. Can anyone please confirm if its still version or just the name itself is beta. A…

---

## [Deleting Events From Frozen Data Tier](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:50am UTC](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395 "2023-10-20T06:50:17Z")

</div>

Attempting to delete by query events in a frozen data tier index belonging to a data stream. I've tried targeting the specific index the events are in as well as the datastream name, but I get the following error: { …

---

## [What happens if index.store.type set as niofs when create index and change to default](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427)

<div class="topic-metadata">

**Author:** [@jonathanjxsq](https://discuss.elastic.co/u/jonathanjxsq)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 3:23am UTC](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427 "2023-10-20T03:23:07Z")

</div>

I created index with index.store type as niofs. if I change the config to default, which type the system is really running with? Based on my test, it seems the system changed from niofs to default. I saw performance ben…

---

## [Shard numbers no longer equal (not even close) among cluster nodes](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342)

<div class="topic-metadata">

**Author:** [@Hao\_Yellow](https://discuss.elastic.co/u/Hao_Yellow)\
**Replies:** 6\
**Last updated:** [October 20, 2023, 1:58am UTC](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342 "2023-10-20T01:58:34Z")

</div>

Hello, I've been recently upgraded an Elasticsearch cluster, with 5 nodes, from version 7.3 to 7.17 then 8.9. As always, I've never disabled shard allocation and rebalancing, so until 7.17 it's observed, and as I unders…

---

## [Elasticsearch is returning less than the top K matches for a vector search](https://discuss.elastic.co/t/elasticsearch-is-returning-less-than-the-top-k-matches-for-a-vector-search/345207)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 8:19pm UTC](https://discuss.elastic.co/t/elasticsearch-is-returning-less-than-the-top-k-matches-for-a-vector-search/345207 "2023-10-19T20:19:40Z")

</div>

I have a problem where elasticsearch doesn't return k matches for a knn search. It used to work before so I think something has changed between version 8.8.3 to 8.10.3. Perhaps a minimum score? I could not find it in the…

---

## [Elasticsearch process ended by code 137](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399)

<div class="topic-metadata">

**Author:** [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Replies:** 7\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399 "2023-10-19T19:09:10Z")

</div>

Hi, When checking the error message for the termination of the Elasticsearch process, it was indicating that the process was terminated due to error 137, when consulting I saw that it indicates excessive memory consumpt…

---

## [Cluster to ingest 7TB of data daily](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 6:41pm UTC](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412 "2023-10-19T18:41:19Z")

</div>

The task at hand is to build a cluster that can ingest 7 terabytes daily, and Hold the data for 7 days in Hot phase, and 83 days in Cold phase, What is the best recommendation in a huge elasticsearch cluster? How many…

---

## [Unable to Start ES Cluster using docker-compose on M1 Mac](https://discuss.elastic.co/t/unable-to-start-es-cluster-using-docker-compose-on-m1-mac/345406)

<div class="topic-metadata">

**Author:** [@lance.zukel](https://discuss.elastic.co/u/lance.zukel)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 4:59pm UTC](https://discuss.elastic.co/t/unable-to-start-es-cluster-using-docker-compose-on-m1-mac/345406 "2023-10-19T16:59:03Z")

</div>

Need to set up a 3 node cluster using docker on my M1 Mac, using docker desktop/docker-compose. I am getting the following error: 2023-10-19 10:33:05 ERROR: \[1\] bootstrap checks failed. You must address the points desc…

---

## [Daily incoming data size calculation](https://discuss.elastic.co/t/daily-incoming-data-size-calculation/345105)

<div class="topic-metadata">

**Author:** [@nonameo](https://discuss.elastic.co/u/nonameo)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 2:09pm UTC](https://discuss.elastic.co/t/daily-incoming-data-size-calculation/345105 "2023-10-19T14:09:14Z")

</div>

Hi everyone, I need to know the daily incoming data size in GB. How can I calculate it? Could you please help with that?

---

## [Elasticsearch REST API Commands](https://discuss.elastic.co/t/elasticsearch-rest-api-commands/345168)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [October 19, 2023, 9:24am UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-commands/345168 "2023-10-19T09:24:24Z")

</div>

Hi Team, I need a help for understanding the O/P of REST API commands while running through Dev Console in Kibana Dashboard. While doing search of an item, apart from result the O/P shows so many other details. Is th…

---

## [Elasticsearch Next 7.x - ScriptQuery Id and Params Properties alternative to get Stored Script using its ID](https://discuss.elastic.co/t/elasticsearch-next-7-x-scriptquery-id-and-params-properties-alternative-to-get-stored-script-using-its-id/345351)

<div class="topic-metadata">

**Author:** [@Juan07](https://discuss.elastic.co/u/Juan07)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 3:59am UTC](https://discuss.elastic.co/t/elasticsearch-next-7-x-scriptquery-id-and-params-properties-alternative-to-get-stored-script-using-its-id/345351 "2023-10-19T03:59:47Z")

</div>

We have updated to Nest 7 from Nest 6. We are getting compiler error with exception ScriptQuery does not contain a definition for Id and Params. Here, we are trying to get a stored script using its ID. But seems these p…

---

## [Elasticsearch Subscription for CCR](https://discuss.elastic.co/t/elasticsearch-subscription-for-ccr/345348)

<div class="topic-metadata">

**Author:** [@Leonadius](https://discuss.elastic.co/u/Leonadius)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 3:43am UTC](https://discuss.elastic.co/t/elasticsearch-subscription-for-ccr/345348 "2023-10-19T03:43:50Z")

</div>

Good day team, I want to ask about the subscriptions for CCR features. Currently we have 2 ELK clusters on DC and DRC, and we planning to replicate some of the indices from DC to DRC (one way). Both of the clusters have…

---

## [High Level Rest Client and SyncedFlushRequest](https://discuss.elastic.co/t/high-level-rest-client-and-syncedflushrequest/345330)

<div class="topic-metadata">

**Author:** [@Vlado](https://discuss.elastic.co/u/Vlado)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 9:18pm UTC](https://discuss.elastic.co/t/high-level-rest-client-and-syncedflushrequest/345330 "2023-10-18T21:18:19Z")

</div>

Hi folks, adding some signal here that I've run into the same issue as the below two RestHighLevelClient and SyncedFlushRequest. That is SyncedFlushRequest throws a java.lang.NoClassDefFoundError: org/elasticsearch/a…

---

## [REST API Connector to ingext REST API JSON Response in elastic Cloud Index](https://discuss.elastic.co/t/rest-api-connector-to-ingext-rest-api-json-response-in-elastic-cloud-index/345329)

<div class="topic-metadata">

**Author:** [@gupashis1978](https://discuss.elastic.co/u/gupashis1978)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 9:05pm UTC](https://discuss.elastic.co/t/rest-api-connector-to-ingext-rest-api-json-response-in-elastic-cloud-index/345329 "2023-10-18T21:05:34Z")

</div>

Using Elastic Cloud 8.9. Requirement is to index the JSON Data ( response) of REST API GET call. Not able to find any in built managed connector for this scenario. Looking for a connector where I can enter REST API Endpo…

---

## [Retrieving sorted results using a point-in-time search with slicing](https://discuss.elastic.co/t/retrieving-sorted-results-using-a-point-in-time-search-with-slicing/345328)

<div class="topic-metadata">

**Author:** [@valasatava](https://discuss.elastic.co/u/valasatava)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 8:58pm UTC](https://discuss.elastic.co/t/retrieving-sorted-results-using-a-point-in-time-search-with-slicing/345328 "2023-10-18T20:58:16Z")

</div>

Hi everyone, I'm running into issues with retrieving results using Paginate search results | Elasticsearch Guide \[8.10\] | Elastic and preserving the sorted order across the whole data set. I need to pull lots of docume…

---

## [Can number of shards per node be the bottleneck in a cluster?](https://discuss.elastic.co/t/can-number-of-shards-per-node-be-the-bottleneck-in-a-cluster/344970)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 15\
**Last updated:** [October 18, 2023, 4:23pm UTC](https://discuss.elastic.co/t/can-number-of-shards-per-node-be-the-bottleneck-in-a-cluster/344970 "2023-10-18T16:23:20Z")

</div>

Hi Folks, I have the following cluster. Nodes: 6 (48vCPUs and 384GB memory) Shards: 158 EBS volume: 24TB GP3 type (Provisioned IOPS: 50,000 and 1781 Mb/sec throughput per node) 0 replica. ~11B documents for ~10KB e…

---

## [How do I detect that a previous processor has succeeded in an ingest pipeline?](https://discuss.elastic.co/t/how-do-i-detect-that-a-previous-processor-has-succeeded-in-an-ingest-pipeline/345240)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 4:20pm UTC](https://discuss.elastic.co/t/how-do-i-detect-that-a-previous-processor-has-succeeded-in-an-ingest-pipeline/345240 "2023-10-18T16:20:47Z")

</div>

I'm using Filebeat, plus hints based auto discovery, to get my Docker Swarmt container Apache logs passed through the built in Apache logs ingest pipelines. The thing is, that several of my apache containers are also ou…

---

## [Multi-get vs Terms query performance](https://discuss.elastic.co/t/multi-get-vs-terms-query-performance/345241)

<div class="topic-metadata">

**Author:** [@CletusTSJY](https://discuss.elastic.co/u/CletusTSJY)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 3:55pm UTC](https://discuss.elastic.co/t/multi-get-vs-terms-query-performance/345241 "2023-10-18T15:55:45Z")

</div>

I'm using Elasticsearch 7.16.2 and for one of my use-cases I need to fetch documents out of my Elasticsearch index in batches of 200 to 400 at a time. Each document is around 40k on disk but I only fetch certain fields, …

---

## [ILM and alias error](https://discuss.elastic.co/t/ilm-and-alias-error/345230)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 2:37pm UTC](https://discuss.elastic.co/t/ilm-and-alias-error/345230 "2023-10-18T14:37:19Z")

</div>

Hi, i've followed the ILM setup guide and came accross this error "illegal\_argument\_exception: index.lifecycle.rollover\_alias \[test-alias\] does not point to index x" Now i understand that you should create the index …

---

## [Elastic Stack with security enabled automatically not working for multiple node](https://discuss.elastic.co/t/elastic-stack-with-security-enabled-automatically-not-working-for-multiple-node/345296)

<div class="topic-metadata">

**Author:** [@Ramakrishna\_M](https://discuss.elastic.co/u/Ramakrishna_M)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 2:04pm UTC](https://discuss.elastic.co/t/elastic-stack-with-security-enabled-automatically-not-working-for-multiple-node/345296 "2023-10-18T14:04:05Z")

</div>

Error:- \[2023-10-18T19:09:36,604\]\[WARN \]\[o.e.x.c.s.t.n.SecurityNetty4Transport\] \[node-1\] client did not trust this server's certificate, closing connection Netty4TcpChannel{localAddress=/0.0.0.29:9300, remoteAddress=/0.…

---

## [Is point in time ID considered sensitive information?](https://discuss.elastic.co/t/is-point-in-time-id-considered-sensitive-information/345292)

<div class="topic-metadata">

**Author:** [@matheisco](https://discuss.elastic.co/u/matheisco)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 1:47pm UTC](https://discuss.elastic.co/t/is-point-in-time-id-considered-sensitive-information/345292 "2023-10-18T13:47:31Z")

</div>

Hi! I'm implementing pagination using search\_after and the PIT API and am wondering if it's safe to propagate the PIT ID to an end user device. Am I exposing internal information to end users this way? Thank you!

---

## [TTL Value for Documents Under the Indices](https://discuss.elastic.co/t/ttl-value-for-documents-under-the-indices/345194)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 8\
**Last updated:** [October 18, 2023, 11:54am UTC](https://discuss.elastic.co/t/ttl-value-for-documents-under-the-indices/345194 "2023-10-18T11:54:09Z")

</div>

Hi Team, We had one requirement to set the TTL value for the documents present in a index. Could you please help me how to achieve the same. Thanks, Debasis

---

## [Elastic Translog corrupted error (Unassigned shards)](https://discuss.elastic.co/t/elastic-translog-corrupted-error-unassigned-shards/345255)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 11:39am UTC](https://discuss.elastic.co/t/elastic-translog-corrupted-error-unassigned-shards/345255 "2023-10-18T11:39:18Z")

</div>

Hello Friends, Can you suggest below error related translog corrupted .100+ shards are red (unassigned state) due disk failure and most of the shards recover but few shards not getting recovery. tried below option to r…

---

## [Creating a "join" mapping between two indexes using lookup](https://discuss.elastic.co/t/creating-a-join-mapping-between-two-indexes-using-lookup/345204)

<div class="topic-metadata">

**Author:** [@ugurcandede](https://discuss.elastic.co/u/ugurcandede)\
**Replies:** 4\
**Last updated:** [October 18, 2023, 11:22am UTC](https://discuss.elastic.co/t/creating-a-join-mapping-between-two-indexes-using-lookup/345204 "2023-10-18T11:22:48Z")

</div>

when I make following request. I got the following error. PUT /develop\_tickets\_dev/\_mapping { "properties": { "fieldMap": { "type": "nested", "properties": { "ts.requester": { "type":…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=186)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=188)
