# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=193

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 194

---

## [Lot of delay in logs parsing at kibana GUI](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449)

<div class="topic-metadata">

**Author:** [@syedsyed](https://discuss.elastic.co/u/syedsyed)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:01am UTC](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449 "2023-10-05T07:01:33Z")

</div>

I have Elasticsearch and kibana installed and i have integrated the fleet server into it, enrolled the elastic agent with sonicwall integration into it, but i am facing lot of delay of about one and half day, mostly the …

---

## [Max items on runtime fields](https://discuss.elastic.co/t/max-items-on-runtime-fields/344307)

<div class="topic-metadata">

**Author:** [@lipig](https://discuss.elastic.co/u/lipig)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 6:16am UTC](https://discuss.elastic.co/t/max-items-on-runtime-fields/344307 "2023-10-05T06:16:31Z")

</div>

Hi Elastic people, A curiosity... I emit more than 100 values ​​in the runtime fields, and I saw in the forum that 100 was the maximum. I saw this thread from 2021 and wanted to ask if there have been any updates. Th…

---

## [Elastic system indices migration issue while upgrade](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 6:10am UTC](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434 "2023-10-05T06:10:48Z")

</div>

Hi, I am upgrading elastic from 6.8 to 7.17.0 and then 8.x.x. From version 6.8 to 7.17 migration was fine but while preparing to migrate from version 7.17 to 8.x.x upgrade assistant is not able to migrate this one(Task…

---

## [Master node in ECK with differente IP between pod and elasticsearch](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431)

<div class="topic-metadata">

**Author:** [@dudds22](https://discuss.elastic.co/u/dudds22)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 8:34pm UTC](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431 "2023-10-04T20:34:06Z")

</div>

Hi, Today we faced a strange situation and really want to share with you in order to try to obtain more infos about what can be happened. Context: We have a elasticsearch cluster and we need to send slowlogs to Datado…

---

## [Slef-host elasticsearch with azure ad sso SAML](https://discuss.elastic.co/t/slef-host-elasticsearch-with-azure-ad-sso-saml/344423)

<div class="topic-metadata">

**Author:** [@Yue\_CHEN](https://discuss.elastic.co/u/Yue_CHEN)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 9:09pm UTC](https://discuss.elastic.co/t/slef-host-elasticsearch-with-azure-ad-sso-saml/344423 "2023-10-04T21:09:38Z")

</div>

Hello, Recently created a self-host Elasticsearch and Kibana version 8.10 in Azure VM. Both working fine now. Like to get Azure AD SSO enable when user open kibana. But did not see a good document for how to set it up.…

---

## [Elastic query takes over 1 minute due to time spent in "HighlightPhase"](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344)

<div class="topic-metadata">

**Author:** [@David\_Avant](https://discuss.elastic.co/u/David_Avant)\
**Replies:** 5\
**Last updated:** [October 4, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344 "2023-10-04T19:26:59Z")

</div>

Some elastic queries are slow, taking more than a minute to execute. The query input is simple: just a single, numeric account identifier (i.e. "123456789"). The query takes 68 seconds to execute and returns 6 hits. T…

---

## [File not found when attempting to index](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353)

<div class="topic-metadata">

**Author:** [@Ahriss](https://discuss.elastic.co/u/Ahriss)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353 "2023-10-04T19:23:12Z")

</div>

Hello. I'm building a simple elasticsearch/PHP application, and I got a very weird error. I can search on it just fine, though I need to build pagination for it still, but when I attempt to index something, I simply get …

---

## [ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already be part of a cluster and this auto setup utility is designed to configure Security for new clusters only., with exit](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422)

<div class="topic-metadata">

**Author:** [@nav\_11](https://discuss.elastic.co/u/nav_11)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 6:29pm UTC](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422 "2023-10-04T18:29:24Z")

</div>

Getting below error while adding the node. I am following the MACOS setup guide below. Command: bin/elasticsearch --enrollment-token ERROR: Skipping security auto configuration because it appears that the node is no…

---

## [Getting index rate](https://discuss.elastic.co/t/getting-index-rate/344381)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 3:56pm UTC](https://discuss.elastic.co/t/getting-index-rate/344381 "2023-10-04T15:56:49Z")

</div>

Hi, I am looking a way to monitor index rate not through Kibana. Is there any RestAPI command that provide the current index rate? Is there alternative way? Thanks...

---

## [Issue in restoring an Elastic Snapshot](https://discuss.elastic.co/t/issue-in-restoring-an-elastic-snapshot/343329)

<div class="topic-metadata">

**Author:** [@girolamo](https://discuss.elastic.co/u/girolamo)\
**Replies:** 7\
**Last updated:** [October 4, 2023, 3:08pm UTC](https://discuss.elastic.co/t/issue-in-restoring-an-elastic-snapshot/343329 "2023-10-04T15:08:18Z")

</div>

Hello there, I'm having issues restoring an elasticsearch snapshot. I've tried: POST \_snapshot/snapshot\_repo/snap-EIHidJXeQWuHpnGfzR04Uw/\_restore { "indices": "target\_indicies" } but I've got: { "error" : { "ro…

---

## [Could not communicate with the node on any of the addresses from the enrollment token. All of \[10.89.3.8:9200\] were attempted., with exit code 69](https://discuss.elastic.co/t/could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrollment-token-all-of-10-89-3-8-9200-were-attempted-with-exit-code-69/344398)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 2:06pm UTC](https://discuss.elastic.co/t/could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrollment-token-all-of-10-89-3-8-9200-were-attempted-with-exit-code-69/344398 "2023-10-04T14:06:41Z")

</div>

Hi fellows, I need our help. When I try to run my elasticsearch container like this: \`docker run -e "ENROLLMENT\_TOKEN= eyJ2ZXIiOiI4LjEwLjIiLCJhZHIiOlsiMTAuODkuMy44OjkyMDAiXSwiZmdyIjoiZjAwYjJjMjYyMmRiOTQ4NDU4ZmI3NjRhZ…

---

## [Elasticsearch spark runtime dependencies](https://discuss.elastic.co/t/elasticsearch-spark-runtime-dependencies/344341)

<div class="topic-metadata">

**Author:** [@krezno](https://discuss.elastic.co/u/krezno)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 1:00pm UTC](https://discuss.elastic.co/t/elasticsearch-spark-runtime-dependencies/344341 "2023-10-04T13:00:22Z")

</div>

Hello, I have sucessfuly managed to use elasticsearch-spark with both pyspark and scala spark by simply adding the jar to the classpath. I have noticed that the jar has some runtime dependencies such as protobuf-java an…

---

## [Auto deletion of all indices](https://discuss.elastic.co/t/auto-deletion-of-all-indices/344382)

<div class="topic-metadata">

**Author:** [@sujata\_g](https://discuss.elastic.co/u/sujata_g)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 12:36pm UTC](https://discuss.elastic.co/t/auto-deletion-of-all-indices/344382 "2023-10-04T12:36:01Z")

</div>

Hi, i am using Elasticsearch and kibana which are running on docker container(Elasticsearch version is 7.12.0) and all my indices are getting deleted automatically every month and i have not applied any policies and ever…

---

## [Knn versus match scores](https://discuss.elastic.co/t/knn-versus-match-scores/344386)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 12:22pm UTC](https://discuss.elastic.co/t/knn-versus-match-scores/344386 "2023-10-04T12:22:13Z")

</div>

When doing a hybrid search using a query and a knn clause using the \_search api, the combined document score is the sum of both scores. What I am unable to find in the docs is how the knn and match scores relate? Are the…

---

## [Elasticsearch on K8s VS Vm](https://discuss.elastic.co/t/elasticsearch-on-k8s-vs-vm/344384)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 12:09pm UTC](https://discuss.elastic.co/t/elasticsearch-on-k8s-vs-vm/344384 "2023-10-04T12:09:15Z")

</div>

Hi, On production which approach is preferred? Installing elastic on K8s or Vm? Is there any difference\\limitation? Thanks...

---

## [Move from High Level REST client to Java API Client](https://discuss.elastic.co/t/move-from-high-level-rest-client-to-java-api-client/344304)

<div class="topic-metadata">

**Author:** [@matt4589](https://discuss.elastic.co/u/matt4589)\
**Replies:** 4\
**Last updated:** [October 4, 2023, 12:03pm UTC](https://discuss.elastic.co/t/move-from-high-level-rest-client-to-java-api-client/344304 "2023-10-04T12:03:00Z")

</div>

I have to move from High Level REST client to Java API Client I would like to show one method I have to replace and learn from that . This is old method: public List\<Map\<String, Object\>\> getPublicFilters() { Search…

---

## [elasticsearch.UnsupportedProductError: The client noticed that the server is not Elasticsearch and we do not support this unknown product](https://discuss.elastic.co/t/elasticsearch-unsupportedproducterror-the-client-noticed-that-the-server-is-not-elasticsearch-and-we-do-not-support-this-unknown-product/344379)

<div class="topic-metadata">

**Author:** [@Arshdeep\_Singh](https://discuss.elastic.co/u/Arshdeep_Singh)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 11:15am UTC](https://discuss.elastic.co/t/elasticsearch-unsupportedproducterror-the-client-noticed-that-the-server-is-not-elasticsearch-and-we-do-not-support-this-unknown-product/344379 "2023-10-04T11:15:22Z")

</div>

Here I'm trying to create a full sync between Django's database and Elastic Search. While running the command "python manage.py search\_index --create -f", I'm getting the error: ERROR: Traceback (most recent call last)…

---

## [Es/search\] Missing \[X-Elastic-Product\] header](https://discuss.elastic.co/t/es-search-missing-x-elastic-product-header/344366)

<div class="topic-metadata">

**Author:** [@matt4589](https://discuss.elastic.co/u/matt4589)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 9:56am UTC](https://discuss.elastic.co/t/es-search-missing-x-elastic-product-header/344366 "2023-10-04T09:56:24Z")

</div>

I'm using Java API Client 8.5.3 against elasticsearch 7.12.0 I'm gettinf this error when doing a search: co.elastic.clients.transport.TransportException: \[es/search\] Missing \[X-Elastic-Product\] header. Please check th…

---

## [Unexpected Behavior of OR Match Query With Synonym Graph](https://discuss.elastic.co/t/unexpected-behavior-of-or-match-query-with-synonym-graph/344320)

<div class="topic-metadata">

**Author:** [@MilanGatyas](https://discuss.elastic.co/u/MilanGatyas)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 9:45am UTC](https://discuss.elastic.co/t/unexpected-behavior-of-or-match-query-with-synonym-graph/344320 "2023-10-04T09:45:03Z")

</div>

I don't know if the following behavior is intended or not. See the following example of index definition and documents: PUT /test { "settings": { "analysis": { "filter": { "syn": { "syn…

---

## [The use of \`size\` and \`from\` parameter in a \`knn\` search](https://discuss.elastic.co/t/the-use-of-size-and-from-parameter-in-a-knn-search/343962)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 4\
**Last updated:** [October 4, 2023, 8:13am UTC](https://discuss.elastic.co/t/the-use-of-size-and-from-parameter-in-a-knn-search/343962 "2023-10-04T08:13:24Z")

</div>

When doing a knn search there is a parameter k which specifies the number of best matching documents to return (approximately). You can also use the size parameter to determine the number of documents to return. Is there…

---

## [Wildcard-like search on synonym authorizer](https://discuss.elastic.co/t/wildcard-like-search-on-synonym-authorizer/344363)

<div class="topic-metadata">

**Author:** [@mkalaaji](https://discuss.elastic.co/u/mkalaaji)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 7:44am UTC](https://discuss.elastic.co/t/wildcard-like-search-on-synonym-authorizer/344363 "2023-10-04T07:44:44Z")

</div>

Currently facing an issue with synonyms and using Elasticsearch managed service not self hosted elasticsearch I have created a synonym file and created an authorizer that utilizes this synonym file in a filter PUT /sto…

---

## [From Python to Rust](https://discuss.elastic.co/t/from-python-to-rust/344329)

<div class="topic-metadata">

**Author:** [@FrederickFrance](https://discuss.elastic.co/u/FrederickFrance)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:34am UTC](https://discuss.elastic.co/t/from-python-to-rust/344329 "2023-10-04T07:34:56Z")

</div>

Hi all, I'm a newbie with Python and Elasticsearch. I'm trying to create a client from host, username and password. With Python, the original code is: Elasticsearch( hosts=hosts, http\_auth=(es…

---

## [Fuzziness on multiple fields and match a particular field elastic search query](https://discuss.elastic.co/t/fuzziness-on-multiple-fields-and-match-a-particular-field-elastic-search-query/344361)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 7:32am UTC](https://discuss.elastic.co/t/fuzziness-on-multiple-fields-and-match-a-particular-field-elastic-search-query/344361 "2023-10-04T07:32:12Z")

</div>

Hi All, My requirement is to get the response for a specific word which can be appear anywhere in the document and it should belongs the user's account id. i've to use date range query like last 3 hours or 24 hours doc…

---

## [Is BulkIngester (replacement of 'Bulk Processor') in elasticsearch java api thread safe?](https://discuss.elastic.co/t/is-bulkingester-replacement-of-bulk-processor-in-elasticsearch-java-api-thread-safe/344285)

<div class="topic-metadata">

**Author:** [@Irfanulla](https://discuss.elastic.co/u/Irfanulla)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:12am UTC](https://discuss.elastic.co/t/is-bulkingester-replacement-of-bulk-processor-in-elasticsearch-java-api-thread-safe/344285 "2023-10-04T07:12:35Z")

</div>

Use case: I have multiple kafka listeners for various topics. Each topic Listener will run in multiple threads (using spring's 'ConcurrentKafkaListenerContainer'). Listeners will be performing Update/Insert operations on…

---

## [Logs are not ingesting to elasticsearch](https://discuss.elastic.co/t/logs-are-not-ingesting-to-elasticsearch/344355)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 4:40am UTC](https://discuss.elastic.co/t/logs-are-not-ingesting-to-elasticsearch/344355 "2023-10-04T04:40:27Z")

</div>

This was my set up earlier. filebeat =\> logstash (SQS-PUSH) =\> logstash (SQS-PULL) =\> elasticsearch. The above approach seems very costlier to us because of (SQS API) calls. Hence we replaced kafka (standalone). fileb…

---

## [Elastic dev tool has different total hits number than discover query search](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 9\
**Last updated:** [October 4, 2023, 2:22am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275 "2023-10-04T02:22:53Z")

</div>

Hi, I have the same query and with the same filter. But the dev tool and discover give me different total hit counts ..I wonder what is the reason to that? and which is the accurate one

---

## [Restoring indexes that have missing shards from snapshot](https://discuss.elastic.co/t/restoring-indexes-that-have-missing-shards-from-snapshot/344265)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 2:11am UTC](https://discuss.elastic.co/t/restoring-indexes-that-have-missing-shards-from-snapshot/344265 "2023-10-04T02:11:43Z")

</div>

I had a cluster node restart while another the cluster was still recovering from another node crashing which resulted in some indexes with missing shards. None of the affected indexes are currently being written and I h…

---

## [I want to have date filter in my embed kibana dashbard which i have one external web page](https://discuss.elastic.co/t/i-want-to-have-date-filter-in-my-embed-kibana-dashbard-which-i-have-one-external-web-page/344171)

<div class="topic-metadata">

**Author:** [@Jyoti\_Pandey](https://discuss.elastic.co/u/Jyoti_Pandey)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 11:44pm UTC](https://discuss.elastic.co/t/i-want-to-have-date-filter-in-my-embed-kibana-dashbard-which-i-have-one-external-web-page/344171 "2023-10-03T23:44:01Z")

</div>

i am using the library for the date filter which is already present on my web page I want my date filter date should have to reflect to result of the Kibana dashboard as per the date range

---

## [Do Time series data streams (TSDS) store non-numeric/non-dimension logs efficiently?](https://discuss.elastic.co/t/do-time-series-data-streams-tsds-store-non-numeric-non-dimension-logs-efficiently/344352)

<div class="topic-metadata">

**Author:** [@micheal\_riff](https://discuss.elastic.co/u/micheal_riff)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 10:40pm UTC](https://discuss.elastic.co/t/do-time-series-data-streams-tsds-store-non-numeric-non-dimension-logs-efficiently/344352 "2023-10-03T22:40:07Z")

</div>

Hi, I have a few questions about time series data streams (TSDS). I've tried looking through the documentation but am still confused on a few small things :slightly\_smiling\_face: I was wondering if fields that are not …

---

## [Using an index per Board in my application (need help with the Architeture of my elastic search cluster)](https://discuss.elastic.co/t/using-an-index-per-board-in-my-application-need-help-with-the-architeture-of-my-elastic-search-cluster/344340)

<div class="topic-metadata">

**Author:** [@Goalfy\_Services](https://discuss.elastic.co/u/Goalfy_Services)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 7:14pm UTC](https://discuss.elastic.co/t/using-an-index-per-board-in-my-application-need-help-with-the-architeture-of-my-elastic-search-cluster/344340 "2023-10-03T19:14:48Z")

</div>

Good evening, I'm been using Elastic Search for a while and I need some help with my arch design, basically I'm using Elasticsearch for storgin dynamic forms which can have an (n) amount of fields, these forms are stored…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=192)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=194)
