# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=194

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 195

---

## [Elasticsearch performance testing](https://discuss.elastic.co/t/elasticsearch-performance-testing/344335)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 6:10pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-testing/344335 "2023-10-03T18:10:58Z")

</div>

Hi all, We are trying to come up with performance tests, stress tests etc to calculate throughput and identify bottlenecks in our elasticsearch cluster. We are using elasticsearch exporter to export metrics from the clu…

---

## [Problem updating field via SDK GO](https://discuss.elastic.co/t/problem-updating-field-via-sdk-go/344326)

<div class="topic-metadata">

**Author:** [@Wiliam\_Joaquim](https://discuss.elastic.co/u/Wiliam_Joaquim)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 3:48pm UTC](https://discuss.elastic.co/t/problem-updating-field-via-sdk-go/344326 "2023-10-03T15:48:02Z")

</div>

I'm using the Go SDK to update data in Elasticsearch, but strangely, via the SDK it doesn't update a specific field, via the http client it works correctly sometimes: POST test/type1/123/\_update { "doc": { "asset…

---

## [Using script processor in elastic-agent integration](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632)

<div class="topic-metadata">

**Author:** [@aaszxc](https://discuss.elastic.co/u/aaszxc)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 3:44pm UTC](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632 "2023-10-03T15:44:52Z")

</div>

Need your help. I don't like that using kubernetes integration in elastic-agents we have one event\_dataset for all logs: kubernetes.container\_logs I would like to split it into several. In filebeat this can be done with…

---

## [Problem when create index template](https://discuss.elastic.co/t/problem-when-create-index-template/344302)

<div class="topic-metadata">

**Author:** [@Joker\_Thanh](https://discuss.elastic.co/u/Joker_Thanh)\
**Replies:** 5\
**Last updated:** [October 3, 2023, 2:04pm UTC](https://discuss.elastic.co/t/problem-when-create-index-template/344302 "2023-10-03T14:04:38Z")

</div>

i have seen problem when create index template based endpoint /\_index/c1s-template { "error" : { "root\_cause" : \[ { "type" : "illegal\_argument\_exception", "reason" : "IOException while readin…

---

## [Trying to query on length of the nested field](https://discuss.elastic.co/t/trying-to-query-on-length-of-the-nested-field/343853)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 1:41pm UTC](https://discuss.elastic.co/t/trying-to-query-on-length-of-the-nested-field/343853 "2023-10-03T13:41:07Z")

</div>

Hi, i have a mapping for an index of field resume.profile.locations, which is an nested field Here, I need to perform a scripting query... I am getting error call no mapping for that field but, I gave a mapping for …

---

## [Can't delete index template](https://discuss.elastic.co/t/cant-delete-index-template/344310)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 1:18pm UTC](https://discuss.elastic.co/t/cant-delete-index-template/344310 "2023-10-03T13:18:43Z")

</div>

Using Kibana 8.8.1 and ES 8.8.1 I deleted an index template as follows and it was acknowledged: DELETE /\_index\_template/my\_template However, when I run the following the template is still there: GET /\_cat/templates?v …

---

## [Getting No mapping Error](https://discuss.elastic.co/t/getting-no-mapping-error/344283)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 12:20pm UTC](https://discuss.elastic.co/t/getting-no-mapping-error/344283 "2023-10-03T12:20:26Z")

</div>

Hii, I tried a lot of queries.. but, Its not works.. It through an error.. Can anyone try this Here is my mapping, PUT array\_sort { "mappings": { "properties": { "Skills": { "type": "nested", …

---

## [AWS S3 repository for snapshot/restore in elasticsearch](https://discuss.elastic.co/t/aws-s3-repository-for-snapshot-restore-in-elasticsearch/342503)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 11:24am UTC](https://discuss.elastic.co/t/aws-s3-repository-for-snapshot-restore-in-elasticsearch/342503 "2023-10-03T11:24:49Z")

</div>

I want to use AWS S3 bucket for Elasticsearch snapshot/restore of indices. I have read the official doc but I am unable to understand what all properties will be needed in my elasticsearch.yml file to connect to my S3 b…

---

## [Change the location of an existing snapshot repository](https://discuss.elastic.co/t/change-the-location-of-an-existing-snapshot-repository/344200)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 7\
**Last updated:** [October 3, 2023, 9:40am UTC](https://discuss.elastic.co/t/change-the-location-of-an-existing-snapshot-repository/344200 "2023-10-03T09:40:45Z")

</div>

I need to change the location of the repository: but when I do I get this error: we had to move the mountpoint for the shared disk...

---

## [EBS disk type for High traffic Elasticsearch Cluster](https://discuss.elastic.co/t/ebs-disk-type-for-high-traffic-elasticsearch-cluster/344244)

<div class="topic-metadata">

**Author:** [@SiorMeir](https://discuss.elastic.co/u/SiorMeir)\
**Replies:** 3\
**Last updated:** [October 3, 2023, 9:31am UTC](https://discuss.elastic.co/t/ebs-disk-type-for-high-traffic-elasticsearch-cluster/344244 "2023-10-03T09:31:15Z")

</div>

We encountered a dilemma during the setup of a new cluster of ES version 8 with Elastic Cloud for Kubernetes (EKS) operator on AWS with Elastic Block Storage (EBS) as the data hosting service. EBS offers different speci…

---

## [Setting min=max in ngram tokenizers](https://discuss.elastic.co/t/setting-min-max-in-ngram-tokenizers/344218)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 5\
**Last updated:** [October 3, 2023, 9:09am UTC](https://discuss.elastic.co/t/setting-min-max-in-ngram-tokenizers/344218 "2023-10-03T09:09:05Z")

</div>

The docs suggest setting min=max on ngrams - but this results in a very poor search experience. Assuming 3,3 and searching for "rough" you will never find "trough". Only if you search "tro", "rou" or any other 3 characte…

---

## [Elasticsearch span\_multi query rewrite parameter getting same result for top\_terms\_n top\_terms\_boost\_n and top\_terms\_blended\_freqs\_n?](https://discuss.elastic.co/t/elasticsearch-span-multi-query-rewrite-parameter-getting-same-result-for-top-terms-n-top-terms-boost-n-and-top-terms-blended-freqs-n/344295)

<div class="topic-metadata">

**Author:** [@Naman\_Mahor](https://discuss.elastic.co/u/Naman_Mahor)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-span-multi-query-rewrite-parameter-getting-same-result-for-top-terms-n-top-terms-boost-n-and-top-terms-blended-freqs-n/344295 "2023-10-03T08:34:01Z")

</div>

I m trying below query with "explain": true on million of articles. but top\_terms, top\_terms\_boost and top\_terms\_blended\_freqs returning me the same result. "query": { "span\_multi": { "match": { "pref…

---

## [Getting the facets info using search API facets](https://discuss.elastic.co/t/getting-the-facets-info-using-search-api-facets/344289)

<div class="topic-metadata">

**Author:** [@Aswanth\_Parambath](https://discuss.elastic.co/u/Aswanth_Parambath)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 7:35am UTC](https://discuss.elastic.co/t/getting-the-facets-info-using-search-api-facets/344289 "2023-10-03T07:35:41Z")

</div>

I have data in the format { field1:"data", field2 :{ innerField1 : "data2", innerField2: "data3" } } i want to implement the facets with search AP…

---

## [Can't create API role for Gitlab Advanced Search](https://discuss.elastic.co/t/cant-create-api-role-for-gitlab-advanced-search/344131)

<div class="topic-metadata">

**Author:** [@Oscar\_Yerpes](https://discuss.elastic.co/u/Oscar_Yerpes)\
**Replies:** 2\
**Last updated:** [October 3, 2023, 5:42am UTC](https://discuss.elastic.co/t/cant-create-api-role-for-gitlab-advanced-search/344131 "2023-10-03T05:42:54Z")

</div>

Hi all, As a part of enabling Gitlab Advanced Search using Elastic as a backend, I need to create a role in Elastic. Elastic API returns this error message when doing GET or POST actions: GET \_security/role { "error…

---

## [Little bit confused on min\_age parameter in ilm](https://discuss.elastic.co/t/little-bit-confused-on-min-age-parameter-in-ilm/299049)

<div class="topic-metadata">

**Author:** [@gokulnath112](https://discuss.elastic.co/u/gokulnath112)\
**Replies:** 4\
**Last updated:** [October 3, 2023, 4:12am UTC](https://discuss.elastic.co/t/little-bit-confused-on-min-age-parameter-in-ilm/299049 "2023-10-03T04:12:36Z")

</div>

Greetings...! Im currently using below ilm policy for my project. I just want to know the life span of an index. PUT \_ilm/policy/hot\_warm\_delete { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { "…

---

## [What are the use cases of EQL in elasticsearch?](https://discuss.elastic.co/t/what-are-the-use-cases-of-eql-in-elasticsearch/343554)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 9:56pm UTC](https://discuss.elastic.co/t/what-are-the-use-cases-of-eql-in-elasticsearch/343554 "2023-10-02T21:56:53Z")

</div>

What are the use cases of EQL in elasticsearch , Please explain with example ?

---

## [Elasticsearch 8.9.1 indexing bottleneck on i3.2xlarge and d3.2xlarge nodes in EKS using ECK](https://discuss.elastic.co/t/elasticsearch-8-9-1-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks-using-eck/342001)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 10\
**Last updated:** [October 2, 2023, 8:09pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks-using-eck/342001 "2023-10-02T20:09:08Z")

</div>

Last May I asked a similar question about performance in 7.17.10, but ran out of things to try and the discussion was auto-closed due to inactivity. I'll avoid repeating the same context info from that post (the initial …

---

## [Error adding a 4th node to existing ES cluster](https://discuss.elastic.co/t/error-adding-a-4th-node-to-existing-es-cluster/344252)

<div class="topic-metadata">

**Author:** [@Bolmar](https://discuss.elastic.co/u/Bolmar)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 6:02pm UTC](https://discuss.elastic.co/t/error-adding-a-4th-node-to-existing-es-cluster/344252 "2023-10-02T18:02:51Z")

</div>

ERROR: Skipping security auto configuration because this node is configured to bootstrap or to join a multi-node cluster, which is not supported. Steps for joining 4th node (First approach): Extract ES software (elast…

---

## [Connecting metricbeat to elasticsearch using ssl connection](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121)

<div class="topic-metadata">

**Author:** [@website](https://discuss.elastic.co/u/website)\
**Replies:** 5\
**Last updated:** [October 2, 2023, 2:42pm UTC](https://discuss.elastic.co/t/connecting-metricbeat-to-elasticsearch-using-ssl-connection/344121 "2023-10-02T14:42:36Z")

</div>

Good afternoon, can you help with connecting metricbeat to elasticsearch wazuh The file /etc/elasticsearch/elasticsearch.yml looks like this: network.host: 0.0.0.0 node.name: elasticsearch cluster.initial\_master\_nodes:…

---

## [Migrating HLRC IndexLifecycleClient to ES:8.8.1](https://discuss.elastic.co/t/migrating-hlrc-indexlifecycleclient-to-es-8-8-1/344236)

<div class="topic-metadata">

**Author:** [@UP2711](https://discuss.elastic.co/u/UP2711)\
**Replies:** 0\
**Last updated:** [October 2, 2023, 2:38pm UTC](https://discuss.elastic.co/t/migrating-hlrc-indexlifecycleclient-to-es-8-8-1/344236 "2023-10-02T14:38:31Z")

</div>

I'm in the process of migrating from Elasticsearch version 7.17.0 to version 8.8.1. In my existing code, I'm using the High-Level Rest Client (HLRC) to manage Index Lifecycle Policies. However, in Elasticsearch version 8…

---

## [Elastic search key, password encryption](https://discuss.elastic.co/t/elastic-search-key-password-encryption/344230)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 2:32pm UTC](https://discuss.elastic.co/t/elastic-search-key-password-encryption/344230 "2023-10-02T14:32:15Z")

</div>

is it possible to use a encrypted key between client and elasticsearch? i know the question is not very clear because i have little knowledge about the topic. What i need is a encryption system between the people who s…

---

## [Wildcard queries \_index field](https://discuss.elastic.co/t/wildcard-queries-index-field/344232)

<div class="topic-metadata">

**Author:** [@frens](https://discuss.elastic.co/u/frens)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 2:28pm UTC](https://discuss.elastic.co/t/wildcard-queries-index-field/344232 "2023-10-02T14:28:05Z")

</div>

We've just upgraded ES from 7.12.0 to 7.17.13 and since then we seem to be unable to run wildcard queries on the \_index field. Is this expected? Is this something we can work around? We have index patterns in Kibana wit…

---

## [Output syslog plugin](https://discuss.elastic.co/t/output-syslog-plugin/344219)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 12:35pm UTC](https://discuss.elastic.co/t/output-syslog-plugin/344219 "2023-10-02T12:35:09Z")

</div>

I'm trying to install output syslog plugin in my virtual machine where there is no network, i didn't find the package in the official elastic website to download it, i found this link to upload it : logstash-output-syslo…

---

## [Distinguishing hybrid search results](https://discuss.elastic.co/t/distinguishing-hybrid-search-results/344086)

<div class="topic-metadata">

**Author:** [@Gabor\_Gergely](https://discuss.elastic.co/u/Gabor_Gergely)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 12:14pm UTC](https://discuss.elastic.co/t/distinguishing-hybrid-search-results/344086 "2023-10-02T12:14:18Z")

</div>

Hi Folks, I perform hybrid search by providing both the knn and a query, like the example in the Elasticsearch Guide: POST image-index/\_search { "query": { "match": { "title": { "query": "mountain l…

---

## [How can I disable stored fields (i.e. set "stored\_fields" to "\_none\_") using the Java API Client?](https://discuss.elastic.co/t/how-can-i-disable-stored-fields-i-e-set-stored-fields-to-none-using-the-java-api-client/344079)

<div class="topic-metadata">

**Author:** [@dsc](https://discuss.elastic.co/u/dsc)\
**Replies:** 1\
**Last updated:** [October 2, 2023, 11:54am UTC](https://discuss.elastic.co/t/how-can-i-disable-stored-fields-i-e-set-stored-fields-to-none-using-the-java-api-client/344079 "2023-10-02T11:54:09Z")

</div>

The SearchRequest builder only lets me specify a list of stored fields (or an empty list), but no way to set it to the string \_none\_. If I leave this as the default, or set it to an empty list, I don't get the desired b…

---

## [IP address component search](https://discuss.elastic.co/t/ip-address-component-search/344132)

<div class="topic-metadata">

**Author:** [@cesar.hernandez.a3se](https://discuss.elastic.co/u/cesar.hernandez.a3se)\
**Replies:** 6\
**Last updated:** [October 2, 2023, 6:05am UTC](https://discuss.elastic.co/t/ip-address-component-search/344132 "2023-10-02T06:05:55Z")

</div>

Hi there. I have a elasticsearch index with a ip address field in the mapping: "address" : { "type" : "ip" }, I need to know if I can search for any ip byte component, for example, having a document with…

---

## [How does the Elasticsearch work internally?](https://discuss.elastic.co/t/how-does-the-elasticsearch-work-internally/342631)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 1\
**Last updated:** [October 1, 2023, 7:40pm UTC](https://discuss.elastic.co/t/how-does-the-elasticsearch-work-internally/342631 "2023-10-01T19:40:12Z")

</div>

Hi, I am trying to understand how the core Elasticsearch algorithm works, especially how the inverted indexes and other data representations are created and how they are searched on query time. I was unable to find any …

---

## [How to get Cloudtrail data from S3 bucket to elasticsearch](https://discuss.elastic.co/t/how-to-get-cloudtrail-data-from-s3-bucket-to-elasticsearch/344140)

<div class="topic-metadata">

**Author:** [@Dilpreet](https://discuss.elastic.co/u/Dilpreet)\
**Replies:** 1\
**Last updated:** [October 1, 2023, 6:41pm UTC](https://discuss.elastic.co/t/how-to-get-cloudtrail-data-from-s3-bucket-to-elasticsearch/344140 "2023-10-01T18:41:56Z")

</div>

Greeting, My usecase to fetch cloudtrail logs which are in a S3 bucket to Elasticsearch and build kibana dashboard. Need some guidance on what are some possible ways this can be achieved. Thanks

---

## [Indices Not Creating after 48 indices created](https://discuss.elastic.co/t/indices-not-creating-after-48-indices-created/344180)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 8\
**Last updated:** [October 1, 2023, 5:13pm UTC](https://discuss.elastic.co/t/indices-not-creating-after-48-indices-created/344180 "2023-10-01T17:13:03Z")

</div>

Hi Am I facing the issues related to index creation recently. I'm running the ELK stack in AWS ubuntu EC2 instance. I configured the Elasticsearch to create the index daily basis like this ( orchid-cakelog-pos-2023.09.…

---

## [Why might I be getting 400 on this request?](https://discuss.elastic.co/t/why-might-i-be-getting-400-on-this-request/344172)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 3\
**Last updated:** [October 1, 2023, 7:29am UTC](https://discuss.elastic.co/t/why-might-i-be-getting-400-on-this-request/344172 "2023-10-01T07:29:17Z")

</div>

ES 8.6.2. Low-level user here. I'm trying to clone and then delete in order to rename an index. Before cloning I'm told (here) I should execute this "index.blocks.write" command. This is my attempt (Python): …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=193)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=195)
