# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=192

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 193

---

## [Problem installation Elasticsearch - fatal exception while booting Elasticsearch java.lang.IllegalStateException: failed to obtain node locks](https://discuss.elastic.co/t/problem-installation-elasticsearch-fatal-exception-while-booting-elasticsearch-java-lang-illegalstateexception-failed-to-obtain-node-locks/344550)

<div class="topic-metadata">

**Author:** [@Andres\_Giraldo](https://discuss.elastic.co/u/Andres_Giraldo)\
**Replies:** 2\
**Last updated:** [October 8, 2023, 9:27am UTC](https://discuss.elastic.co/t/problem-installation-elasticsearch-fatal-exception-while-booting-elasticsearch-java-lang-illegalstateexception-failed-to-obtain-node-locks/344550 "2023-10-08T09:27:20Z")

</div>

Hi I am doing a new installation of elasticsearch, I have done it several times but I have changed to a server with nvme (I don't know if it is the problem) and I have not been able to do it, I am doing it through ssh, …

---

## [How to solve the hostname field missing in apm log?](https://discuss.elastic.co/t/how-to-solve-the-hostname-field-missing-in-apm-log/344589)

<div class="topic-metadata">

**Author:** [@TedMeng](https://discuss.elastic.co/u/TedMeng)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 6:39am UTC](https://discuss.elastic.co/t/how-to-solve-the-hostname-field-missing-in-apm-log/344589 "2023-10-08T06:39:21Z")

</div>

the same log, hostname shows in the jeager log but not in the APM log, Could you help me check what's wrong with it? Thanks very munch

---

## [Elasticsearch beats upgradations](https://discuss.elastic.co/t/elasticsearch-beats-upgradations/344586)

<div class="topic-metadata">

**Author:** [@rahul1989](https://discuss.elastic.co/u/rahul1989)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 5:26am UTC](https://discuss.elastic.co/t/elasticsearch-beats-upgradations/344586 "2023-10-08T05:26:40Z")

</div>

Hello, i have upgraded my elastic cloud from 7.x to 8.9.1 so, i have to upgrade the filebeat, logstash, metricbeats and heartbeat. this beats are running on "red hat enterprise linux" and this are the current beats ver…

---

## [Salesforce Integration with Elasticsearch cloud](https://discuss.elastic.co/t/salesforce-integration-with-elasticsearch-cloud/344585)

<div class="topic-metadata">

**Author:** [@rahul1989](https://discuss.elastic.co/u/rahul1989)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 5:11am UTC](https://discuss.elastic.co/t/salesforce-integration-with-elasticsearch-cloud/344585 "2023-10-08T05:11:48Z")

</div>

Hello, my query is i have to integrate salesforce application with Elasticsearch cloud to see the logs or data and i am using the architecture like this beats=\> logstash=\> elasticsearch \<= kibana. so, could you guide o…

---

## [Elasticsearch7 Not showing Filename /Folder name from Azure Blob Storage in Ubuntu OS](https://discuss.elastic.co/t/elasticsearch7-not-showing-filename-folder-name-from-azure-blob-storage-in-ubuntu-os/344582)

<div class="topic-metadata">

**Author:** [@muralif9](https://discuss.elastic.co/u/muralif9)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 4:07am UTC](https://discuss.elastic.co/t/elasticsearch7-not-showing-filename-folder-name-from-azure-blob-storage-in-ubuntu-os/344582 "2023-10-08T04:07:52Z")

</div>

Dear All, I have installed Elasticsearch 7 and Logstash7 in Ubuntu20.04 OS ,Logstash Data input is reading from Azure Blob Storage. The Setup is working fine but the Index in Elasticsearch not displaying the Foldernam…

---

## [Reindex in elasticsearch 7.17 as pre-upgrade to 8.x](https://discuss.elastic.co/t/reindex-in-elasticsearch-7-17-as-pre-upgrade-to-8-x/344575)

<div class="topic-metadata">

**Author:** [@Indu\_Nallithodi](https://discuss.elastic.co/u/Indu_Nallithodi)\
**Replies:** 0\
**Last updated:** [October 7, 2023, 11:48pm UTC](https://discuss.elastic.co/t/reindex-in-elasticsearch-7-17-as-pre-upgrade-to-8-x/344575 "2023-10-07T23:48:24Z")

</div>

Elasticsearch team: in need of a guidancee/help Now am in a upgrade from 6.8 to 8.x(latest) Progress: Have 6.8 server with 6.8 indices(created in 5.6 and upgraded to 6.8 few years back) with multi-type Reindexed to s…

---

## [Deleting Array Element USING NEST](https://discuss.elastic.co/t/deleting-array-element-using-nest/344573)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [October 7, 2023, 7:45pm UTC](https://discuss.elastic.co/t/deleting-array-element-using-nest/344573 "2023-10-07T19:45:40Z")

</div>

Can anyone assist us in how to delete an element of an array in Elasticsearch using NEST syntax. Thanks

---

## [How to calculate EPS-Events per second in Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 6:55pm UTC](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548 "2023-10-06T18:55:27Z")

</div>

Hi, I want to calculate the average and maximum EPS in my cluster. I'm using the ELK 8.1.2 version. Thank you..! Hiruni

---

## [Difference between number of fortigate firewall logs on Logstash and Elastic-agent managed by fleet](https://discuss.elastic.co/t/difference-between-number-of-fortigate-firewall-logs-on-logstash-and-elastic-agent-managed-by-fleet/344502)

<div class="topic-metadata">

**Author:** [@mrz](https://discuss.elastic.co/u/mrz)\
**Replies:** 4\
**Last updated:** [October 6, 2023, 4:00pm UTC](https://discuss.elastic.co/t/difference-between-number-of-fortigate-firewall-logs-on-logstash-and-elastic-agent-managed-by-fleet/344502 "2023-10-06T16:00:46Z")

</div>

Hi there, we have a cluster of Elasticsearch and have shipped firewall (FortiGate) logs to Logstash, everything is going well and we have a huge number of logs about 3.5M logs in 15 minutes, recently we decided to upgra…

---

## [Time\_zone in Lucence query](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534)

<div class="topic-metadata">

**Author:** [@Michael7](https://discuss.elastic.co/u/Michael7)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 2:17pm UTC](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534 "2023-10-06T14:17:34Z")

</div>

Hi, Im trying to realize how to specify time\_zone in URI query for elastic. ...&q=Mobile AND delivered\_at:\["now-30d" TO "now"\] How I can add time\_zone +03:00 to delivered\_at field?

---

## [Does elastic cloud provide any specific IP address for the deployment?](https://discuss.elastic.co/t/does-elastic-cloud-provide-any-specific-ip-address-for-the-deployment/344447)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 2:10pm UTC](https://discuss.elastic.co/t/does-elastic-cloud-provide-any-specific-ip-address-for-the-deployment/344447 "2023-10-06T14:10:33Z")

</div>

Hi Team, Does elastic cloud provide any specific IPs for the deployment that we create? If we have to whitelist the traffic into our office network we might need specific Ip address to configure. If elastic cloud is not…

---

## [ELS 8 Java Client performance issue](https://discuss.elastic.co/t/els-8-java-client-performance-issue/344465)

<div class="topic-metadata">

**Author:** [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:42am UTC](https://discuss.elastic.co/t/els-8-java-client-performance-issue/344465 "2023-10-05T09:42:50Z")

</div>

We have replaced the ELS 7 REST client with the ELS 8 Java client in our application and our soak/performance tests are showing a slight performance degradation. Is this expected ? I had thought the Java client would be…

---

## [Elasticsearch License](https://discuss.elastic.co/t/elasticsearch-license/344471)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [October 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-license/344471 "2023-10-06T10:10:36Z")

</div>

Hi Team, Could you please help me to understand the licensing part of Elasticsearch. Because I had installed Elasticsearch from below link and now while using Kibana dashboard today it is showing License related error.…

---

## [It's possible to encrypt Snapshots or ElasticSearch Snapshot repository?](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524)

<div class="topic-metadata">

**Author:** [@Alberto\_Roca](https://discuss.elastic.co/u/Alberto_Roca)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 7:37am UTC](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524 "2023-10-06T07:37:05Z")

</div>

Currently the structure I have is made up of a cluster with Elasticsearch nodes, which take snapshots and are saved in their corresponding repository. This data is later sent to an already encrypted Ceph bucket. Is there…

---

## [Using Elasticsearch Completion Suggester for large text search](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:55pm UTC](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507 "2023-10-05T19:55:52Z")

</div>

Is it possible to use the Completion Suggester feature for Elasticsearch to find content as text is typed, similar to Elasticsearch's Discuss? For example, I have articles in my knowledge base that have a title and cont…

---

## [Query an Elasticsearch index for one field, all documents in last 24 hours?](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 7:40pm UTC](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493 "2023-10-05T19:40:16Z")

</div>

Hi There. I'm trying to make a simple get request to my elk index. I have the right credentials, hostname, index name, etc. my ELK version is 6.8.6 But for what I'm trying to get I cannot figure out how to construct …

---

## [Elastic Common Schema support for Opensearch](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452)

<div class="topic-metadata">

**Author:** [@q3uxlyn](https://discuss.elastic.co/u/q3uxlyn)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:22pm UTC](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452 "2023-10-05T19:22:19Z")

</div>

Hello! Have you plans about adding OpenSearch support to Elastic Common Schema? Cause of OpenSearch has different field types than Elasticsearch we can't easily use ECS. I want to be able to keep the schemas up to date…

---

## [ABAC / Custom Realm / Extend JWT authentication](https://discuss.elastic.co/t/abac-custom-realm-extend-jwt-authentication/344500)

<div class="topic-metadata">

**Author:** [@SvenHa](https://discuss.elastic.co/u/SvenHa)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 3:36pm UTC](https://discuss.elastic.co/t/abac-custom-realm-extend-jwt-authentication/344500 "2023-10-05T15:36:34Z")

</div>

Hello, Currently, I'm trying to evaluate the best solution for a customer project. Some facts about the project environment: User authentication with OIDC/JWT is available. It is not possible to extend the JWT with c…

---

## [Kibana error: security\_exception: \[security\_exception\] Reason: unable to authenticate with provided credentials and anonymous access is not allowed for this request](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 3:26pm UTC](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243 "2023-10-05T15:26:00Z")

</div>

Hi. I upgraded the Kibana from 7.17 to 8.5.3 and got some corrupt indices. then I used these instructions and deleted .kibana and . monitoring indices. Resolve Migration Failures But I also deleted .security\_7. This …

---

## [Kibana Error - Error while updating search session x: Saved object x conflict](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:56pm UTC](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783 "2023-10-05T14:56:31Z")

</div>

Hello. I am using Kibana 8.5.3 and getting this error continuously. Error while updating search session b4100d1f-dfea-4ba9-8873-070219cbfe5f: Saved object \[search-session/b4100d1f-dfea-4ba9-8873-070219cbfe5f\] conflict…

---

## [Kibana fleet error - Failed to fetch latest version of synthetics from registry: Error connecting to package registry: request to URL failed, reason: connect ENETUNREACH xx.xxx.xxx.xxx:xxx - Local (0.0.0.0:0)](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498 "2023-10-05T14:43:55Z")

</div>

Hi. I am using Kibana 8.5.3 and everytime I start Kibana with "sudo systemctl start kibana" or restart, I get this error once. Failed to fetch latest version of synthetics from registry: Error connecting to package reg…

---

## [bulkIndex() or saveAll()?](https://discuss.elastic.co/t/bulkindex-or-saveall/344487)

<div class="topic-metadata">

**Author:** [@Cemre\_Senyuva](https://discuss.elastic.co/u/Cemre_Senyuva)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:24pm UTC](https://discuss.elastic.co/t/bulkindex-or-saveall/344487 "2023-10-05T13:24:19Z")

</div>

Which one is faster method to save/index in elasticsearch bulkIndex() or saveAll()?

---

## [Elasticsearch SCCM Windows deployment](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497)

<div class="topic-metadata">

**Author:** [@Waldfried](https://discuss.elastic.co/u/Waldfried)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:24pm UTC](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497 "2023-10-05T14:24:20Z")

</div>

Hi everyone, i'm having problems deploying Elasticsearch via SCCM. During execution the setup tries to create a symlink which is working as long as i install it with a administrative user account. As soon as the setup …

---

## [Kibana errors after changing encryptionKey - Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492 "2023-10-05T14:21:07Z")

</div>

I use elasticstack 8.5.3 and have 2 Logstash, 5 ELS and 1 Kibana nodes. I was cleaning the older kibana system indices ( upgraded from 7.17.7) and deleted .security\_7 index also and had to create all built in users agai…

---

## [Elasticsearch jvm memory outbursts above settings causing oom-kill](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490)

<div class="topic-metadata">

**Author:** [@Guillaume\_Soustrade](https://discuss.elastic.co/u/Guillaume_Soustrade)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490 "2023-10-05T13:49:55Z")

</div>

Dear Elasticsearch connoisseurs, We have a repeating issue in our clusters of nodes suddenly exiting due to the java process being oom-killed. Let's take the example of this falling node : 94.3 Go of RAM 8 CPUs SWAP …

---

## [Does Elastic accept combined JSON with flatten keys](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 12:06pm UTC](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373 "2023-10-04T12:06:17Z")

</div>

Hi, is it possible to send to ES messages in combined JSON format { "a": { "b": { "c.d.e.f": "value" } } } or it ends with error like can't merge a non object mapping with an object mapping?

---

## [Best practice for TDocument class reference to pass to Java's ElasticsearchClient methods?](https://discuss.elastic.co/t/best-practice-for-tdocument-class-reference-to-pass-to-javas-elasticsearchclient-methods/344473)

<div class="topic-metadata">

**Author:** [@ilgrosso](https://discuss.elastic.co/u/ilgrosso)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 12:14pm UTC](https://discuss.elastic.co/t/best-practice-for-tdocument-class-reference-to-pass-to-javas-elasticsearchclient-methods/344473 "2023-10-05T12:14:45Z")

</div>

Hi, I am using the latest Java REST API client and wondering what Class\<TDocument\> reference I should be passing to the search() method in case of no object domain model is being used. At present I am using a bare Map.…

---

## [How to change an index mapping in Elastic search](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456)

<div class="topic-metadata">

**Author:** [@Francesco66](https://discuss.elastic.co/u/Francesco66)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 11:47am UTC](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456 "2023-10-05T11:47:11Z")

</div>

Hello, I am ingesting the following document into Elasticsearch via Logstash: \[xxxx@yyyy ~\]# curl -k http://my\_es\_hostname:9200/cdp-zos-syslog-console-plex75-20231005/\_search?pretty { "took" : 564, "timed\_out" : fal…

---

## [Watcher filter Latency\_info](https://discuss.elastic.co/t/watcher-filter-latency-info/344458)

<div class="topic-metadata">

**Author:** [@Aitor\_MtzAm](https://discuss.elastic.co/u/Aitor_MtzAm)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 8:52am UTC](https://discuss.elastic.co/t/watcher-filter-latency-info/344458 "2023-10-05T08:52:34Z")

</div>

I need the watcher to differentiate between 2 values of the same field: Within the latency\_info field in the task "Integration" I need to differentiate whether the result field is "-" or "200". "latency\_info": \[ { "t…

---

## [Why does cluster.routing.allocation.exclude.\_ip only work as a transient, not persistent setting?](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419)

<div class="topic-metadata">

**Author:** [@Jamshid](https://discuss.elastic.co/u/Jamshid)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:12am UTC](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419 "2023-10-05T07:12:47Z")

</div>

Just a sanity check... trying to remove a node by setting cluster.routing.allocation.exclude.\_ip does not seem to have any effect if it's a persistent setting. Tested with elasticesarch 7.17.13 on a 3-node cluster. When …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=191)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=193)
