# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=19

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 20

---

## [Can i configure LDAP in BASIC License](https://discuss.elastic.co/t/can-i-configure-ldap-in-basic-license/381624)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 3\
**Last updated:** [September 6, 2025, 2:42am UTC](https://discuss.elastic.co/t/can-i-configure-ldap-in-basic-license/381624 "2025-09-06T02:42:51Z")

</div>

Hello We have Implemented , Elasticsearch version 7.8.0 cluster at our end. We are having this old version i understand and we are in process of upgrading same . Our Elasticsearch License TYPE is BASIC In mean while …

---

## [No id why I cannot access key "id"](https://discuss.elastic.co/t/no-id-why-i-cannot-access-key-id/381639)

<div class="topic-metadata">

**Author:** [@Salvatore\_Milano](https://discuss.elastic.co/u/Salvatore_Milano)\
**Replies:** 1\
**Last updated:** [September 5, 2025, 1:03pm UTC](https://discuss.elastic.co/t/no-id-why-i-cannot-access-key-id/381639 "2025-09-05T13:03:31Z")

</div>

Hello, sometimes it seems that Elasticsearch is not running as it should so I have tried to debug it using kibana. I cannot access the key “id” via: GET /trend\_meta/\_search { "query": { "co…

---

## [Alert throwing to fleet](https://discuss.elastic.co/t/alert-throwing-to-fleet/381637)

<div class="topic-metadata">

**Author:** [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Replies:** 1\
**Last updated:** [September 5, 2025, 12:57pm UTC](https://discuss.elastic.co/t/alert-throwing-to-fleet/381637 "2025-09-05T12:57:23Z")

</div>

Unable to initialize Fleet illegal\_argument\_exception Root causes: illegal\_argument\_exception: node \[\*\*\*\*\] does not have the \[remote\_cluster\_client\] role I have one cluster: 3 master+hot 1 frozen Why I need remote c…

---

## [Error when adding vector data with Elastic.Clients.Elasticsearch version 9.0.0](https://discuss.elastic.co/t/error-when-adding-vector-data-with-elastic-clients-elasticsearch-version-9-0-0/379388)

<div class="topic-metadata">

**Author:** [@ppworks](https://discuss.elastic.co/u/ppworks)\
**Replies:** 5\
**Last updated:** [September 4, 2025, 10:11pm UTC](https://discuss.elastic.co/t/error-when-adding-vector-data-with-elastic-clients-elasticsearch-version-9-0-0/379388 "2025-09-04T22:11:50Z")

</div>

The code is as follows: /// \<summary\> /// Create an index /// \</summary\> /// \<param name="sender"\>\</param\> /// \<param name="e"\>\</param\> protected async void Button1\_Click(object sender, EventArgs e) { // Connection …

---

## [Elastic Watcher migration to Rules Issue's](https://discuss.elastic.co/t/elastic-watcher-migration-to-rules-issues/381617)

<div class="topic-metadata">

**Author:** [@Sarada](https://discuss.elastic.co/u/Sarada)\
**Replies:** 1\
**Last updated:** [September 5, 2025, 5:41am UTC](https://discuss.elastic.co/t/elastic-watcher-migration-to-rules-issues/381617 "2025-09-05T05:41:53Z")

</div>

Hi All, I migrating watchers to Rules, I do have a watcher that compares previous value from last entry and alerts if not same. This works perfectly in watcher as we wrote aggs and painless script but as we are migratin…

---

## [Elasticsearch span\_near query in greek text](https://discuss.elastic.co/t/elasticsearch-span-near-query-in-greek-text/381608)

<div class="topic-metadata">

**Author:** [@epistola](https://discuss.elastic.co/u/epistola)\
**Replies:** 2\
**Last updated:** [September 5, 2025, 5:06am UTC](https://discuss.elastic.co/t/elasticsearch-span-near-query-in-greek-text/381608 "2025-09-05T05:06:13Z")

</div>

Hello everyone, I have a problem with the following query: { "query": { "span\_near": { "clauses": \[ { "span\_near": { "clauses": \[ { "span\_term": { "text1": "word…

---

## [Filebeat with fortinet module not dropping logs in elastic](https://discuss.elastic.co/t/filebeat-with-fortinet-module-not-dropping-logs-in-elastic/381580)

<div class="topic-metadata">

**Author:** [@gari](https://discuss.elastic.co/u/gari)\
**Replies:** 2\
**Last updated:** [September 4, 2025, 5:45pm UTC](https://discuss.elastic.co/t/filebeat-with-fortinet-module-not-dropping-logs-in-elastic/381580 "2025-09-04T17:45:02Z")

</div>

Hello i’m having problems dropping logs from filebeat to elastic using the fortinet module. This is the yml i have in filebeat but i does not seem to be dropping any logs since I still see traffic and notice and informat…

---

## [Consistently high CPU usage on hot nodes](https://discuss.elastic.co/t/consistently-high-cpu-usage-on-hot-nodes/379948)

<div class="topic-metadata">

**Author:** [@maario](https://discuss.elastic.co/u/maario)\
**Replies:** 12\
**Last updated:** [September 4, 2025, 3:47pm UTC](https://discuss.elastic.co/t/consistently-high-cpu-usage-on-hot-nodes/379948 "2025-09-04T15:47:04Z")

</div>

Hi all We are encountering a consistently high CPU usage (around 80% on average) on our hot nodes (2 hot, 2 warm, 4 cold) since around 3 weeks. The CPU usage roughly doubled one day and has since not gone down again. So…

---

## [Is there a way to determine what triggers shard movement?](https://discuss.elastic.co/t/is-there-a-way-to-determine-what-triggers-shard-movement/380047)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 10\
**Last updated:** [September 4, 2025, 2:47pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-determine-what-triggers-shard-movement/380047 "2025-09-04T14:47:57Z")

</div>

Our cluster all of a sudden starts to rebalance for no apparent reason. It's been going on for a day. I tweaked the setting "cluster.routing.allocation.balance.threshold" to 10 which means allow 10 shards difference be…

---

## [Custom analyzer synonym issue: Astoria → Queens also matches Queens Village](https://discuss.elastic.co/t/custom-analyzer-synonym-issue-astoria-queens-also-matches-queens-village/381543)

<div class="topic-metadata">

**Author:** [@william1349](https://discuss.elastic.co/u/william1349)\
**Replies:** 1\
**Last updated:** [September 4, 2025, 11:16am UTC](https://discuss.elastic.co/t/custom-analyzer-synonym-issue-astoria-queens-also-matches-queens-village/381543 "2025-09-04T11:16:31Z")

</div>

I am using a match search for a city called Astoria, and I am using a custom analyzer for cities. When I search for Astoria, the analyzer will return Queens. Queens is returning just fine. However, because it matches Que…

---

## [Elasticsearch-core plugin incompatibility](https://discuss.elastic.co/t/elasticsearch-core-plugin-incompatibility/381595)

<div class="topic-metadata">

**Author:** [@megha2](https://discuss.elastic.co/u/megha2)\
**Replies:** 0\
**Last updated:** [September 4, 2025, 2:06am UTC](https://discuss.elastic.co/t/elasticsearch-core-plugin-incompatibility/381595 "2025-09-04T02:06:40Z")

</div>

Using elasticseach bundled in arcgis, getting error below - where it fails as the elasticseach has no plugins. Has anyone seen or experienced this error before. CliToolLauncher.configureLoggingWithoutConfig(CliToolLaunc…

---

## [Salesforce Real time events Monitoring using Elasticsearch](https://discuss.elastic.co/t/salesforce-real-time-events-monitoring-using-elasticsearch/381587)

<div class="topic-metadata">

**Author:** [@mosaadshaikh1998](https://discuss.elastic.co/u/mosaadshaikh1998)\
**Replies:** 0\
**Last updated:** [September 4, 2025, 12:41am UTC](https://discuss.elastic.co/t/salesforce-real-time-events-monitoring-using-elasticsearch/381587 "2025-09-04T00:41:49Z")

</div>

Hello Team, Wanted to understand if Salesforce integration in Kibana can monitor real time events from salesforce (Not the EventLogFile object). I can see in “Kibana \> Integrations \> Salesforce \> Overview tab” that it i…

---

## [Is there any way to update documents using the ingest pipeline?](https://discuss.elastic.co/t/is-there-any-way-to-update-documents-using-the-ingest-pipeline/381466)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 2\
**Last updated:** [September 3, 2025, 11:31pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-update-documents-using-the-ingest-pipeline/381466 "2025-09-03T23:31:59Z")

</div>

We are using NEST and using the Ingest Pipeline when indexing a new document as follows: await ElasticSearchConfig.GetClient().IndexAsync(o, idx =\> idx.Index($"{index}-{user.Country.ToLower()}").Pipeline("agent-pipeline…

---

## [Elasticsearch WARN message after upgrade 8.19.2 to 8.19.3](https://discuss.elastic.co/t/elasticsearch-warn-message-after-upgrade-8-19-2-to-8-19-3/381460)

<div class="topic-metadata">

**Author:** [@kalai](https://discuss.elastic.co/u/kalai)\
**Replies:** 6\
**Last updated:** [September 3, 2025, 5:33pm UTC](https://discuss.elastic.co/t/elasticsearch-warn-message-after-upgrade-8-19-2-to-8-19-3/381460 "2025-09-03T17:33:01Z")

</div>

After upgrade the Elasticsearch version 8.19.2 to 8.19.3 the below message is rollover Not entitled: component \[(unknown)\], module \[ALL-UNNAMED\], class \[class com.dynatrace.agent.casp.thirdparty.io.UrlUtils\], operation …

---

## [PostgreSQL Functionality Equivalent to Elasticsearch Painless Scripts](https://discuss.elastic.co/t/postgresql-functionality-equivalent-to-elasticsearch-painless-scripts/381559)

<div class="topic-metadata">

**Author:** [@samrinkomai](https://discuss.elastic.co/u/samrinkomai)\
**Replies:** 3\
**Last updated:** [September 3, 2025, 1:21pm UTC](https://discuss.elastic.co/t/postgresql-functionality-equivalent-to-elasticsearch-painless-scripts/381559 "2025-09-03T13:21:28Z")

</div>

In elasticsearch I often use painless script inside searches to calculate values dynamically ay query time, for example by manipulating a timestamp field or deriving custom numeric values. Now I am working on a project w…

---

## [Apt raises warning for repo on Debian 13](https://discuss.elastic.co/t/apt-raises-warning-for-repo-on-debian-13/381567)

<div class="topic-metadata">

**Author:** [@kcp](https://discuss.elastic.co/u/kcp)\
**Replies:** 0\
**Last updated:** [September 3, 2025, 12:20pm UTC](https://discuss.elastic.co/t/apt-raises-warning-for-repo-on-debian-13/381567 "2025-09-03T12:20:30Z")

</div>

The Elastic 8 repo causes apt to raise a warning on Debian 13 (aka Trixie). root@charly-dev13:~# apt-get update ... Get:9 https://artifacts.elastic.co/packages/oss-8.x/apt stable InRelease \[3248 B\] Get:10 https://artifa…

---

## [How to change ILM policy?](https://discuss.elastic.co/t/how-to-change-ilm-policy/381161)

<div class="topic-metadata">

**Author:** [@MagnusTHN](https://discuss.elastic.co/u/MagnusTHN)\
**Replies:** 3\
**Last updated:** [September 3, 2025, 12:15pm UTC](https://discuss.elastic.co/t/how-to-change-ilm-policy/381161 "2025-09-03T12:15:07Z")

</div>

Hi everyone, I’m using Elasticsearch (8.15.1) for logging in my server environment, and Fleet to distribute agents across the servers. The indices created are currently using the logs index lifecycle policy, which acco…

---

## [Restart Elastic search without data loss single node cluster](https://discuss.elastic.co/t/restart-elastic-search-without-data-loss-single-node-cluster/381540)

<div class="topic-metadata">

**Author:** [@Sudhir\_Takale1](https://discuss.elastic.co/u/Sudhir_Takale1)\
**Replies:** 5\
**Last updated:** [September 3, 2025, 11:29am UTC](https://discuss.elastic.co/t/restart-elastic-search-without-data-loss-single-node-cluster/381540 "2025-09-03T11:29:54Z")

</div>

I want to restart my Elasticsearch service which is running on EC2, data stored on EFS mounted on EC2. As in current yml file there is no security related configurations present, I want add these and restart Elasticsearc…

---

## [Failure Store Released?](https://discuss.elastic.co/t/failure-store-released/362313)

<div class="topic-metadata">

**Author:** [@jsheely](https://discuss.elastic.co/u/jsheely)\
**Replies:** 2\
**Last updated:** [September 3, 2025, 1:52am UTC](https://discuss.elastic.co/t/failure-store-released/362313 "2025-09-03T01:52:02Z")

</div>

I have been seeing several commits, PR, and change log release notes, discussions around failure\_store. But I can't find anything in the documentation about it and when I try and utilize it based on the examples I am ge…

---

## [Vertex AI Gemini Embeddings Task Type Support in Inference API](https://discuss.elastic.co/t/vertex-ai-gemini-embeddings-task-type-support-in-inference-api/381533)

<div class="topic-metadata">

**Author:** [@Jared\_Gray](https://discuss.elastic.co/u/Jared_Gray)\
**Replies:** 0\
**Last updated:** [September 2, 2025, 8:32pm UTC](https://discuss.elastic.co/t/vertex-ai-gemini-embeddings-task-type-support-in-inference-api/381533 "2025-09-02T20:32:58Z")

</div>

I'm working on implementing semantic search using Vertex AI Gemini embedding models (gemini-embedding-001) through the Inference API. While the Create a Google Vertex AI inference endpoint | Elasticsearch API documentat…

---

## [Apply different ILM per namespace](https://discuss.elastic.co/t/apply-different-ilm-per-namespace/381523)

<div class="topic-metadata">

**Author:** [@djkprojects](https://discuss.elastic.co/u/djkprojects)\
**Replies:** 0\
**Last updated:** [September 2, 2025, 2:50pm UTC](https://discuss.elastic.co/t/apply-different-ilm-per-namespace/381523 "2025-09-02T14:50:01Z")

</div>

Hello, We have many Fleet policies (different data\_stream namespaces) with System integration which are currently using the default metrics ILM. We now want to tailor each policy and define dedicated ILM for each names…

---

## [Search in all attributes except one](https://discuss.elastic.co/t/search-in-all-attributes-except-one/381518)

<div class="topic-metadata">

**Author:** [@MatthiasKuehne](https://discuss.elastic.co/u/MatthiasKuehne)\
**Replies:** 0\
**Last updated:** [September 2, 2025, 12:25pm UTC](https://discuss.elastic.co/t/search-in-all-attributes-except-one/381518 "2025-09-02T12:25:45Z")

</div>

Hello lovely people, is there some way for a query\_string - Query to search in ALL attributes EXCEPT one? Or can I use another type of query to search for documents matching a search term in all attributes except one? I…

---

## [Fingerprint b64 not URL-friendly on pipelines](https://discuss.elastic.co/t/fingerprint-b64-not-url-friendly-on-pipelines/381515)

<div class="topic-metadata">

**Author:** [@Victor\_Monteagudo](https://discuss.elastic.co/u/Victor_Monteagudo)\
**Replies:** 0\
**Last updated:** [September 2, 2025, 10:48am UTC](https://discuss.elastic.co/t/fingerprint-b64-not-url-friendly-on-pipelines/381515 "2025-09-02T10:48:31Z")

</div>

Hello! In our ingestion pipeline, we use a field fingerprint as an ID. This ID is used in API paths for searches, such as /host/{id}. We are having problems with B64 due to Elastic transforming the fingerprint to B64 b…

---

## [After reading contributing guide, but still confused!](https://discuss.elastic.co/t/after-reading-contributing-guide-but-still-confused/381467)

<div class="topic-metadata">

**Author:** [@kush1](https://discuss.elastic.co/u/kush1)\
**Replies:** 2\
**Last updated:** [September 1, 2025, 5:30pm UTC](https://discuss.elastic.co/t/after-reading-contributing-guide-but-still-confused/381467 "2025-09-01T17:30:17Z")

</div>

Hi everyone I’m Kush, a recent graduate now working at a startup. In my free time I want to contribute meaningfully to Elasticsearch. I’ve read the contribution guide but still feel lost on where to begin — the ELK stac…

---

## [\`.tasks\` index maintenance](https://discuss.elastic.co/t/tasks-index-maintenance/381487)

<div class="topic-metadata">

**Author:** [@taskstask](https://discuss.elastic.co/u/taskstask)\
**Replies:** 0\
**Last updated:** [September 1, 2025, 1:14pm UTC](https://discuss.elastic.co/t/tasks-index-maintenance/381487 "2025-09-01T13:14:59Z")

</div>

Our .tasks index grows quite large (about 250GB a month), and I’m seeking an alternative to us manually deleting it once in a while. I have two questions: Is it still true that it’s always safe to delete this index? (…

---

## [NET-Client 8.19: Serialisation of QueryDescriptor\<T\>](https://discuss.elastic.co/t/net-client-8-19-serialisation-of-querydescriptor-t/381456)

<div class="topic-metadata">

**Author:** [@JanSearch](https://discuss.elastic.co/u/JanSearch)\
**Replies:** 2\
**Last updated:** [September 1, 2025, 10:46am UTC](https://discuss.elastic.co/t/net-client-8-19-serialisation-of-querydescriptor-t/381456 "2025-09-01T10:46:58Z")

</div>

Hi there, I have another question regarding serialisation. After updating to version 8.19.4, serialisation of QueryDescriptor does not work as before. “Serialization in version 9.0 has been completely overhauled” which…

---

## [Elasticsearch9 compatible es\_client version](https://discuss.elastic.co/t/elasticsearch9-compatible-es-client-version/381479)

<div class="topic-metadata">

**Author:** [@schoekek](https://discuss.elastic.co/u/schoekek)\
**Replies:** 0\
**Last updated:** [September 1, 2025, 9:35am UTC](https://discuss.elastic.co/t/elasticsearch9-compatible-es-client-version/381479 "2025-09-01T09:35:02Z")

</div>

Hi, is untergeek (Aaron Mildenstein) · GitHub still active in the Elastic environment? He always responded very quickly to issues, but unfortunately, he hasn't responded for months... When will there be an elasticsear…

---

## [Issues regarding status code 429](https://discuss.elastic.co/t/issues-regarding-status-code-429/381440)

<div class="topic-metadata">

**Author:** [@Dipesh\_Manwani](https://discuss.elastic.co/u/Dipesh_Manwani)\
**Replies:** 4\
**Last updated:** [September 1, 2025, 6:46am UTC](https://discuss.elastic.co/t/issues-regarding-status-code-429/381440 "2025-09-01T06:46:44Z")

</div>

hey everyone i am facing an problem with the elastic serach service i am facing the problem that i am getting the data -1 ,but whenever i am trying it fetching it for 3 time or more than does anyone know help inform

---

## [Memory leak when creating snapshot with frequent repository change](https://discuss.elastic.co/t/memory-leak-when-creating-snapshot-with-frequent-repository-change/381429)

<div class="topic-metadata">

**Author:** [@lno](https://discuss.elastic.co/u/lno)\
**Replies:** 5\
**Last updated:** [September 1, 2025, 6:40am UTC](https://discuss.elastic.co/t/memory-leak-when-creating-snapshot-with-frequent-repository-change/381429 "2025-09-01T06:40:26Z")

</div>

Hi, When using the snapshot feature and creating many repositories, we can see that files are mapped in memory but never removed. For example, adding a repository, doing a snapshot and removing it multiple times result…

---

## [Connection to the internet with proxy](https://discuss.elastic.co/t/connection-to-the-internet-with-proxy/381457)

<div class="topic-metadata">

**Author:** [@GiorgioS13](https://discuss.elastic.co/u/GiorgioS13)\
**Replies:** 0\
**Last updated:** [August 29, 2025, 8:45pm UTC](https://discuss.elastic.co/t/connection-to-the-internet-with-proxy/381457 "2025-08-29T20:45:40Z")

</div>

Hello, I have a proxy server and I want all outbound internet traffic (required by Elastic for updates such as Fleet, Agent updates, etc.) to go through this proxy. The documentation on this is somewhat unclear. In the K…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=18)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=20)
