# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=189

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 190

---

## [Question About Snapshot and Restore](https://discuss.elastic.co/t/question-about-snapshot-and-restore/345058)

<div class="topic-metadata">

**Author:** [@Faker](https://discuss.elastic.co/u/Faker)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 2:23am UTC](https://discuss.elastic.co/t/question-about-snapshot-and-restore/345058 "2023-10-16T02:23:16Z")

</div>

Hello, I am struggling with Elasticsearch on Docker and have few questions. Even if you don't know the answers to all the questions, I'd appreciate it if you could answer them. Snapshot and Restore : Does Restoring P…

---

## [Duplicate Data](https://discuss.elastic.co/t/duplicate-data/345053)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 3:05pm UTC](https://discuss.elastic.co/t/duplicate-data/345053 "2023-10-15T15:05:10Z")

</div>

Hello, We have time series indexes created daily in Elasticsearch. We upgraded from version 7.10.2 to 8.10.2. While running our tests, we observed that the data coming with the creation of the first index is duplicate. …

---

## [Getting many more results than expected](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045)

<div class="topic-metadata">

**Author:** [@Shlomo\_Koppel](https://discuss.elastic.co/u/Shlomo_Koppel)\
**Replies:** 3\
**Last updated:** [October 15, 2023, 2:04pm UTC](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045 "2023-10-15T14:04:12Z")

</div>

Hi, I am making the following query: {'bool': {'must': \[{'terms': {'doc.attributes.type.keyword': \['Attachment', 'Document'\]}}, {'terms': {'doc.internal\_id': \['xxxx83a1c00f7004b52dxxxx'\]}}\], 'filter': \[{'range': {'doc.…

---

## [Reindexing a big index without down time](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 12:59pm UTC](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050 "2023-10-15T12:59:19Z")

</div>

Hi. I have a really big index with 100 millions of documents. I want to add some new fields, change existing ones and delete the redundant ones by applying explicit index. I will also use alias to switch the indiced. …

---

## [Using Fields in NEST client library](https://discuss.elastic.co/t/using-fields-in-nest-client-library/345033)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 6:15pm UTC](https://discuss.elastic.co/t/using-fields-in-nest-client-library/345033 "2023-10-14T18:15:05Z")

</div>

When using the Fieds options just to get a selection of fileds using the NEST client library and setting the Source(false), the Hits object's fields property is null. How are we supposed to get access to the values retu…

---

## [Wanted to have alerts in my email when a process goes down. Thanks](https://discuss.elastic.co/t/wanted-to-have-alerts-in-my-email-when-a-process-goes-down-thanks/345030)

<div class="topic-metadata">

**Author:** [@Abhiyash\_Agrawal](https://discuss.elastic.co/u/Abhiyash_Agrawal)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 3:06pm UTC](https://discuss.elastic.co/t/wanted-to-have-alerts-in-my-email-when-a-process-goes-down-thanks/345030 "2023-10-14T15:06:42Z")

</div>

Wants to have an alert in my email when data of pipelines goes down and is it possible to get screen shot of kibana dashboards in the same email. Thanks

---

## [2GB enough RAM for a 300MB dataset?](https://discuss.elastic.co/t/2gb-enough-ram-for-a-300mb-dataset/345021)

<div class="topic-metadata">

**Author:** [@kiko](https://discuss.elastic.co/u/kiko)\
**Replies:** 1\
**Last updated:** [October 14, 2023, 6:44am UTC](https://discuss.elastic.co/t/2gb-enough-ram-for-a-300mb-dataset/345021 "2023-10-14T06:44:56Z")

</div>

Hi, I'm having a hard time finding the required RAM for a dataset like mine: it's 300 MB in size, and has around 300 products and 250 product categories. Each product's JSON is around 10-15 KB in size.

---

## [Docker Compose ELK 8.10.2](https://discuss.elastic.co/t/docker-compose-elk-8-10-2/344770)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 8\
**Last updated:** [October 13, 2023, 2:07pm UTC](https://discuss.elastic.co/t/docker-compose-elk-8-10-2/344770 "2023-10-13T14:07:41Z")

</div>

Hi, I'm trying to create a docker-compose.yml file by following the instructions here. The only change I made to the docker-compose.yml file was to add the Logstash service. This is what I added to the docker-compose.…

---

## [Facing Issues while Installing Elastic-Search](https://discuss.elastic.co/t/facing-issues-while-installing-elastic-search/345006)

<div class="topic-metadata">

**Author:** [@Sadhwik\_Reddy](https://discuss.elastic.co/u/Sadhwik_Reddy)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/facing-issues-while-installing-elastic-search/345006 "2023-10-13T13:07:52Z")

</div>

:white\_check\_mark: Elasticsearch security features have been automatically configured! :white\_check\_mark: Authentication is enabled and cluster connections are encrypted. :x: Unable to auto-generate the password for th…

---

## [Snapshot, Hot/Warm Architecture and Upgrade](https://discuss.elastic.co/t/snapshot-hot-warm-architecture-and-upgrade/344887)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 11\
**Last updated:** [October 13, 2023, 11:25am UTC](https://discuss.elastic.co/t/snapshot-hot-warm-architecture-and-upgrade/344887 "2023-10-13T11:25:36Z")

</div>

Hi there, I have a few questions here: First, if I have an index of 4.5 TB, what is the best way to back up that much data? Second, my existing cluster has 25 data nodes in total, if I want to apply hot/warm architect…

---

## [Getting doc\_count for each type under each index in a cluster](https://discuss.elastic.co/t/getting-doc-count-for-each-type-under-each-index-in-a-cluster/344987)

<div class="topic-metadata">

**Author:** [@Darshan\_J](https://discuss.elastic.co/u/Darshan_J)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 10:39am UTC](https://discuss.elastic.co/t/getting-doc-count-for-each-type-under-each-index-in-a-cluster/344987 "2023-10-13T10:39:19Z")

</div>

Im using ES 5.6. Is there a way to get doc\_count of each type in each indices in a ES cluster.

---

## [Change the Account which is used to run the elastic stack (Windows Server)](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 5:39am UTC](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741 "2023-10-13T05:39:17Z")

</div>

Hi! I´m running the Elastic Stack onPrem with the latest version 8.10.2 (Elasticsearch - Kibana - WinlogBeat + Metricbeat). The Elastic stack was installed with my normal Windows account on a Windows Server 2016. Now …

---

## [Path of query](https://discuss.elastic.co/t/path-of-query/344958)

<div class="topic-metadata">

**Author:** [@Alan\_Hsiao](https://discuss.elastic.co/u/Alan_Hsiao)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 1:40am UTC](https://discuss.elastic.co/t/path-of-query/344958 "2023-10-13T01:40:17Z")

</div>

This is one of my filter in my watcher "filter": \[ { "range": { "@timestamp": { "gte": "now-30m" } } …

---

## [Elasticsearch data directory in S3 bucket](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [October 12, 2023, 8:04pm UTC](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945 "2023-10-12T20:04:55Z")

</div>

Hi All, Is it possible to have the data directory of a newly built ES 8 cluster hosted on a S3 bucket. Idea is for the data nodes to use S3 instead of local disk or NAS. Thanks

---

## [Elasticsearch api returning empty response (python)](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238)

<div class="topic-metadata">

**Author:** [@Aidan\_Campbell](https://discuss.elastic.co/u/Aidan_Campbell)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238 "2023-10-12T15:10:46Z")

</div>

I am trying to retrieve elasticsearch data in python using the elasticsearch rest api. When I attempt to call the search api using the requests python library, the elasticsearch python client, or directly from the comma…

---

## [Unable to connect one elasticsearch master pod to another pod to setup two node cluster](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915)

<div class="topic-metadata">

**Author:** [@Santhosh\_Sekar](https://discuss.elastic.co/u/Santhosh_Sekar)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 2:23pm UTC](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915 "2023-10-12T14:23:18Z")

</div>

Hello Team, I am trying to setup two node es cluster in k8s. Issue that i am facing is that es-1 could not elect that as master and could not connect to another pod es-2.yml file cluster.name: "elastic.cluster" …

---

## [Is reindex from remote included in Python client](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814)

<div class="topic-metadata">

**Author:** [@Shahab\_Malekzadeh](https://discuss.elastic.co/u/Shahab_Malekzadeh)\
**Replies:** 7\
**Last updated:** [October 12, 2023, 1:46pm UTC](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814 "2023-10-12T13:46:04Z")

</div>

The Elasticsearch documentation specify the ability to reindex from remote. Can this be done through Python client? I can't find any example. This is what I got which returns error: host = 'https://XXXXXXXXX' indexna…

---

## [Name resolution in hierarchical facets. How to do it better?](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719 "2023-10-12T13:33:52Z")

</div>

Hi, I have a question about how to model the following scenario in ES and if there is a better way for it than we already have. In our system there are documents and categories for these documents. The categories can be…

---

## [Is elasticsearch impacted by libwebp vulnerabilities](https://discuss.elastic.co/t/is-elasticsearch-impacted-by-libwebp-vulnerabilities/344910)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 12:03pm UTC](https://discuss.elastic.co/t/is-elasticsearch-impacted-by-libwebp-vulnerabilities/344910 "2023-10-12T12:03:38Z")

</div>

We have received information on vulnerabilities(CVE-2023-4863 / CVE-2023-5129) impacting libwebp packages as can be read below. Is elasticsearch or anything from the stack somehow impacted / depending on libwebp?

---

## [Elastic Search Next js 13 integration](https://discuss.elastic.co/t/elastic-search-next-js-13-integration/344905)

<div class="topic-metadata">

**Author:** [@Alex770](https://discuss.elastic.co/u/Alex770)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 11:14am UTC](https://discuss.elastic.co/t/elastic-search-next-js-13-integration/344905 "2023-10-12T11:14:19Z")

</div>

Need help to connect to my cluster using search-ui-elasticsearch-connector with my Next jx 13 app. The tls secure connection was established with elastic client. But I am unable to connect with search-ui library.

---

## [Filebeat is not writing log to Destination folder](https://discuss.elastic.co/t/filebeat-is-not-writing-log-to-destination-folder/344822)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 11:00am UTC](https://discuss.elastic.co/t/filebeat-is-not-writing-log-to-destination-folder/344822 "2023-10-12T11:00:49Z")

</div>

Hi Team, In my current project I am using filebeat to load csv files to Elasticsearch but filebeat is not writing the log files in to the destination folder instead it is writing /var/log/messages file. Could you please…

---

## [Ram usage problem](https://discuss.elastic.co/t/ram-usage-problem/344900)

<div class="topic-metadata">

**Author:** [@Mertozturkk](https://discuss.elastic.co/u/Mertozturkk)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 10:58am UTC](https://discuss.elastic.co/t/ram-usage-problem/344900 "2023-10-12T10:58:01Z")

</div>

All nodes in the cluster appear to be using approximately 99% of their RAM. What could be the reason for this? I took this image with the elasticvue plugin. This is one of the nodes

---

## [How to disable caching in ES?](https://discuss.elastic.co/t/how-to-disable-caching-in-es/344889)

<div class="topic-metadata">

**Author:** [@leslience](https://discuss.elastic.co/u/leslience)\
**Replies:** 1\
**Last updated:** [October 12, 2023, 10:33am UTC](https://discuss.elastic.co/t/how-to-disable-caching-in-es/344889 "2023-10-12T10:33:27Z")

</div>

I am currently facing a challenge where I want to disable the query cache in ES, so that every query request reads data from disk instead of directly accessing ES's JVM memory cache. Query requests include but are not li…

---

## [Performance tuning in elastic search in application level joins](https://discuss.elastic.co/t/performance-tuning-in-elastic-search-in-application-level-joins/344788)

<div class="topic-metadata">

**Author:** [@yash\_gehi](https://discuss.elastic.co/u/yash_gehi)\
**Replies:** 7\
**Last updated:** [October 12, 2023, 8:47am UTC](https://discuss.elastic.co/t/performance-tuning-in-elastic-search-in-application-level-joins/344788 "2023-10-12T08:47:04Z")

</div>

I have 2 tables which I have to join based on 3 common keys I'm trying for application level joins But it is getting more time in execution and dataset size is kind of large around 3-4 million Can you tell me how…

---

## [Replacing the IP address of two nodes in the elasticsearch cluster](https://discuss.elastic.co/t/replacing-the-ip-address-of-two-nodes-in-the-elasticsearch-cluster/344886)

<div class="topic-metadata">

**Author:** [@zmaxutbekov](https://discuss.elastic.co/u/zmaxutbekov)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 8:44am UTC](https://discuss.elastic.co/t/replacing-the-ip-address-of-two-nodes-in-the-elasticsearch-cluster/344886 "2023-10-12T08:44:19Z")

</div>

Hi, everyone! I have a cluster of 6 nodes. And I needed to change the IP addresses of two nodes. I have taken the following steps: I connected to the node where I need to change the IP address, performed a disable shar…

---

## [Manage heavy indexing in kNN indexes](https://discuss.elastic.co/t/manage-heavy-indexing-in-knn-indexes/344840)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 7:34am UTC](https://discuss.elastic.co/t/manage-heavy-indexing-in-knn-indexes/344840 "2023-10-12T07:34:24Z")

</div>

Hi everyone, I have performance issues with vector search. Can anyone please help! :slightly\_smiling\_face: I have the following setup: 5 node running on K8s Each node has 32vCPU, 128GB RAM Total index size ~6.5TB at t…

---

## [Would there be any CPU gains by disabling xpack-security and xpack.transport.ssl in Elasticsearch 7.17](https://discuss.elastic.co/t/would-there-be-any-cpu-gains-by-disabling-xpack-security-and-xpack-transport-ssl-in-elasticsearch-7-17/344878)

<div class="topic-metadata">

**Author:** [@Muthukumaran\_Kothand](https://discuss.elastic.co/u/Muthukumaran_Kothand)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 7:29am UTC](https://discuss.elastic.co/t/would-there-be-any-cpu-gains-by-disabling-xpack-security-and-xpack-transport-ssl-in-elasticsearch-7-17/344878 "2023-10-12T07:29:40Z")

</div>

Hi, We run our ES Cluster in a completely closed on-prem Kubernetes environment wherein we do not expose ES ports for any external access (hence no security-hazard) In this case, I wanted to understand if disabling xpa…

---

## [Elastic Stack Automated Event Correlation](https://discuss.elastic.co/t/elastic-stack-automated-event-correlation/344877)

<div class="topic-metadata">

**Author:** [@andresyahfahmi](https://discuss.elastic.co/u/andresyahfahmi)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 7:28am UTC](https://discuss.elastic.co/t/elastic-stack-automated-event-correlation/344877 "2023-10-12T07:28:56Z")

</div>

We currently have an Elastic Stack that is used to centralize logs and events in our IT environment. We collect logs using Elastic Agent/Filebeat, and we use an in-house application to collect third-party alert emails an…

---

## [Index name , doc say : Cannot be . or .. but run result](https://discuss.elastic.co/t/index-name-doc-say-cannot-be-or-but-run-result/344864)

<div class="topic-metadata">

**Author:** [@startjava](https://discuss.elastic.co/u/startjava)\
**Replies:** 6\
**Last updated:** [October 12, 2023, 6:34am UTC](https://discuss.elastic.co/t/index-name-doc-say-cannot-be-or-but-run-result/344864 "2023-10-12T06:34:05Z")

</div>

---

## [Nginx "502 Bad gateway"](https://discuss.elastic.co/t/nginx-502-bad-gateway/344855)

<div class="topic-metadata">

**Author:** [@Mohammad\_Ramadan\_Abd](https://discuss.elastic.co/u/Mohammad_Ramadan_Abd)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 2:04am UTC](https://discuss.elastic.co/t/nginx-502-bad-gateway/344855 "2023-10-12T02:04:01Z")

</div>

My stack is not working and when I login I receive this message nginx "502 Bad gateway". I have checked the kibana service and I found it continously restarting. tailing logs for kibana I found " di@dar-elk-7:~$ tail …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=188)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=190)
