# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=196

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 197

---

## [Cannot create repository on a MinIO instance](https://discuss.elastic.co/t/cannot-create-repository-on-a-minio-instance/344055)

<div class="topic-metadata">

**Author:** [@astingengo](https://discuss.elastic.co/u/astingengo)\
**Replies:** 1\
**Last updated:** [September 28, 2023, 10:48am UTC](https://discuss.elastic.co/t/cannot-create-repository-on-a-minio-instance/344055 "2023-09-28T10:48:09Z")

</div>

ES version: 7.17.13 What I did: I installed s3-repository I created the generic keystore for access key and secret key and mounted as secret with secureSettings.secretName Installed on Kubernetes cluster \[so all chang…

---

## [Is RHEL9 supported on Elasticsearch 7.10.x or lower version](https://discuss.elastic.co/t/is-rhel9-supported-on-elasticsearch-7-10-x-or-lower-version/344031)

<div class="topic-metadata">

**Author:** [@ajay.bansal123](https://discuss.elastic.co/u/ajay.bansal123)\
**Replies:** 4\
**Last updated:** [September 28, 2023, 8:47am UTC](https://discuss.elastic.co/t/is-rhel9-supported-on-elasticsearch-7-10-x-or-lower-version/344031 "2023-09-28T08:47:56Z")

</div>

Hi Folks, Does Elasticsearch 7.10.x OR lower version supports RHEL 9.x OR Rocky Linux 9.x I did not find this info on support-matrix page BR, ajay

---

## [Retention policy characteristics](https://discuss.elastic.co/t/retention-policy-characteristics/343879)

<div class="topic-metadata">

**Author:** [@Tostis](https://discuss.elastic.co/u/Tostis)\
**Replies:** 6\
**Last updated:** [September 28, 2023, 8:23am UTC](https://discuss.elastic.co/t/retention-policy-characteristics/343879 "2023-09-28T08:23:30Z")

</div>

Hello, I am pretty new to Elasticsearch, but got some questions about retention policies. If I am implementing a retention policy for example to delete old data from a index if it is older then 5 days. How is this hand…

---

## [Sending Spring Boot logs directly to Elasticsearch](https://discuss.elastic.co/t/sending-spring-boot-logs-directly-to-elasticsearch/344045)

<div class="topic-metadata">

**Author:** [@tusharSuvarna](https://discuss.elastic.co/u/tusharSuvarna)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 8:12am UTC](https://discuss.elastic.co/t/sending-spring-boot-logs-directly-to-elasticsearch/344045 "2023-09-28T08:12:30Z")

</div>

Hi, I am running a spring boot application as a docker container. I want to send the logs of the application directly to Elasticsearch server without using Filebeats, Logstash or APM. Basically everything that is writt…

---

## [Suggestion in terms of RAM for 3 master nodes and 3 coordinating nodes with 9 data nodes](https://discuss.elastic.co/t/suggestion-in-terms-of-ram-for-3-master-nodes-and-3-coordinating-nodes-with-9-data-nodes/344040)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 7:28am UTC](https://discuss.elastic.co/t/suggestion-in-terms-of-ram-for-3-master-nodes-and-3-coordinating-nodes-with-9-data-nodes/344040 "2023-09-28T07:28:40Z")

</div>

Hello, Give me pls an optimal suggestion in terms of RAM for 3 master nodes and 3 coordinating nodes with 9 data nodes each having 64GB. I m using Elastic version 8.8.1

---

## [High CPU usage periodically](https://discuss.elastic.co/t/high-cpu-usage-periodically/343250)

<div class="topic-metadata">

**Author:** [@xCeLfr](https://discuss.elastic.co/u/xCeLfr)\
**Replies:** 8\
**Last updated:** [September 28, 2023, 7:47am UTC](https://discuss.elastic.co/t/high-cpu-usage-periodically/343250 "2023-09-28T07:47:33Z")

</div>

Hi, there are many topics about CPU load but I can't find an answer. Our standalone Elasticsearch 7.12.0 node runs on a 16 GB RAM Linux server. Every 10 minutes or so elasticsearch consumes 100% CPU and queries are ver…

---

## [Old Index is not deleted as per ILM](https://discuss.elastic.co/t/old-index-is-not-deleted-as-per-ilm/344036)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 6:59am UTC](https://discuss.elastic.co/t/old-index-is-not-deleted-as-per-ilm/344036 "2023-09-28T06:59:57Z")

</div>

Hello, I have created an ILM for my .monitoring-es-7-\* indices PUT \_ilm/policy/Elasticsearch\_monitoring\_test\_policy { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { …

---

## [What is the best aproach to add self-sign certificate to Elasticsearch Kubernetes](https://discuss.elastic.co/t/what-is-the-best-aproach-to-add-self-sign-certificate-to-elasticsearch-kubernetes/343760)

<div class="topic-metadata">

**Author:** [@astingengo](https://discuss.elastic.co/u/astingengo)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:59pm UTC](https://discuss.elastic.co/t/what-is-the-best-aproach-to-add-self-sign-certificate-to-elasticsearch-kubernetes/343760 "2023-09-25T12:59:32Z")

</div>

I deployed Elasticsearch in Kubernetes and I'm trying to backup it to an S3 Instance that has a self sign certificate. What would be the best approach to do so \[having Elasticsearch in Kubernetes\]? I tried to import th…

---

## [HIGH PRIORITY -\> how to add subaggregtion in terms aggregation for spring-data-elasticsearch 5.1](https://discuss.elastic.co/t/high-priority-how-to-add-subaggregtion-in-terms-aggregation-for-spring-data-elasticsearch-5-1/344015)

<div class="topic-metadata">

**Author:** [@Abhinav\_Tyagi](https://discuss.elastic.co/u/Abhinav_Tyagi)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:14pm UTC](https://discuss.elastic.co/t/high-priority-how-to-add-subaggregtion-in-terms-aggregation-for-spring-data-elasticsearch-5-1/344015 "2023-09-27T21:14:36Z")

</div>

i am rewriting my older verison elasticsearch implementations. I latest spring-data-elasticsearch 5.1, queryBuilders got removed due to whic i am not able to use/ add "AggregationBuilders" inside my native query. Can a…

---

## [Field \[field\] not present as part of path \[field.query\]](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008 "2023-09-27T18:45:20Z")

</div>

I'm creating a pipeline with a gsub processor and I keep getting this error when testing the pipeline on a document. I had to add a unique delimiter before ingesting to deal with a whitespace issue. I'm now trying to rep…

---

## [Elastic search mongo db (elastic-connectors) real-time sync configuration?](https://discuss.elastic.co/t/elastic-search-mongo-db-elastic-connectors-real-time-sync-configuration/343934)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 3:26pm UTC](https://discuss.elastic.co/t/elastic-search-mongo-db-elastic-connectors-real-time-sync-configuration/343934 "2023-09-27T15:26:59Z")

</div>

May I know how to configure Elasticsearch mongo db real-time sync config using elastic connector? Docker: container\_name: els\_connector image: docker.elastic.co/enterprise-search/elastic-connectors:8.10.2.0-SNAPSHOT Im…

---

## [Connecting to ELK from databricks](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998)

<div class="topic-metadata">

**Author:** [@ksasidhar1103](https://discuss.elastic.co/u/ksasidhar1103)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:35pm UTC](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998 "2023-09-27T14:35:10Z")

</div>

Hi, I'm trying to load data into databrciks from ELK with the help of API using python script. Can you suggest me the best option that I can read the huge data like 200 million in single shot. The method now I'm using i…

---

## [Breaklines character](https://discuss.elastic.co/t/breaklines-character/343840)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 11:50am UTC](https://discuss.elastic.co/t/breaklines-character/343840 "2023-09-27T11:50:31Z")

</div>

Good morning, I have an easy question about the text field when in the string I have breaklines. I have seen that in this moment when I read the index field I something like this: "enEN" : """- Characteristics of the g…

---

## [Report data from Splunk to Elastic](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:47am UTC](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975 "2023-09-27T10:47:47Z")

</div>

So, I have been sending log data to Splunk. And I want to "catch" the data that is sent to Splunk and forward it to Elastic. I tried with Integrations but that did not work. Does anybody have any ideas on how to solve th…

---

## [CircuitBreakingException when load huge data by bulk write](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410)

<div class="topic-metadata">

**Author:** [@ericsoul](https://discuss.elastic.co/u/ericsoul)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 9:24am UTC](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410 "2023-09-27T09:24:18Z")

</div>

I got many errors like Caused by: org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[indices:data/write/bulk\[s\]\] would be \[30897445494/28.7gb\], which is larger than the limit…

---

## [How to create finger print ingest pipeline for nested field?](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845)

<div class="topic-metadata">

**Author:** [@mhsankar](https://discuss.elastic.co/u/mhsankar)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845 "2023-09-27T09:23:58Z")

</div>

Hi every body. I have a mapping with nested field. I want to identify a finger print for every rows in nested field . how can create this ingest pipeline? I\`m using Elasticsearch v 7.17.7 my mapping: PUT test-neste…

---

## [Performance is low when using cluster mode](https://discuss.elastic.co/t/performance-is-low-when-using-cluster-mode/343964)

<div class="topic-metadata">

**Author:** [@AndreWanga](https://discuss.elastic.co/u/AndreWanga)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/performance-is-low-when-using-cluster-mode/343964 "2023-09-27T09:23:12Z")

</div>

Elasticsearch Version 7.4.0 Java Version from official docker image OS Version from official docker image Problem Description I have set up an Elasticsearch cluster using the official Elasticsearch image. I have confi…

---

## [ElasticSearch Cluster with two Nodes](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 8:37am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874 "2023-09-27T08:37:15Z")

</div>

I've always appreciated the support of this community, and I hope it can assist me once more. Here's the situation: I currently have Elasticsearch installed on my VM1, but I've encountered disk space issues, and the clus…

---

## [Getting one of index in red and did rolling restart of elastic cluster but still in red](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957)

<div class="topic-metadata">

**Author:** [@Jeet\_Lal\_Bhatrai](https://discuss.elastic.co/u/Jeet_Lal_Bhatrai)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 8:27am UTC](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957 "2023-09-27T08:27:54Z")

</div>

Getting one of index in red and did rolling restart of elastic cluster but still in red

---

## [How can I fix this to suggest phrases after say, three characters have been entered?](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 7\
**Last updated:** [September 27, 2023, 4:34am UTC](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755 "2023-09-27T04:34:30Z")

</div>

My query { "suggest": { "text" : "Tes", "simple\_phrase" : { "phrase" : { "field" : "Active\_Substance\_mstr.trigram", "size" : 1, "max\_errors" : 6, "direct\_generator" : \[ { "field" : "Active\_Substan…

---

## [Please suggest best mechanism to sync from Mongo db to elastic search in kubernetes (on prem)?](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 4:22am UTC](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937 "2023-09-27T04:22:33Z")

</div>

Please suggest best mechanism to sync from Mongo db to Elasticsearch in kubernetes (on prem)? Thank you

---

## [\[indices:admin/flush\[s\]\[r\]\] is unauthorized for user \[user\] with effective roles \[grant\_kibana\_system\_indices,superuser\] on restricted indices \[my-restricted-index\], this action is granted by the index privileges \[maintenance,manage,all\]](https://discuss.elastic.co/t/indices-admin-flush-s-r-is-unauthorized-for-user-user-with-effective-roles-grant-kibana-system-indices-superuser-on-restricted-indices-my-restricted-index-this-action-is-granted-by-the-index-privileges-maintenance-manage-all/343629)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 11:32pm UTC](https://discuss.elastic.co/t/indices-admin-flush-s-r-is-unauthorized-for-user-user-with-effective-roles-grant-kibana-system-indices-superuser-on-restricted-indices-my-restricted-index-this-action-is-granted-by-the-index-privileges-maintenance-manage-all/343629 "2023-09-26T23:32:53Z")

</div>

Continuing the discussion from Action \[indices:admin/flush\[s\]\] is unauthorized for user \[admin\] with roles \[superuser\] on restricted indices \[.kibana\_task\_manager\_7.17.5\_001\], this action is granted by the index privileg…

---

## [Elastic connectors release version download error](https://discuss.elastic.co/t/elastic-connectors-release-version-download-error/343933)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 9:45pm UTC](https://discuss.elastic.co/t/elastic-connectors-release-version-download-error/343933 "2023-09-26T21:45:42Z")

</div>

Hi, May I know how to get the elastic connector release version (I can successfully download and install snap shot version but getting an error during the release version) ? container\_name: els\_connector image: docker…

---

## [Term query by \_id very slow (30s+) occasionally](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305)

<div class="topic-metadata">

**Author:** [@May\_Zeng](https://discuss.elastic.co/u/May_Zeng)\
**Replies:** 20\
**Last updated:** [September 26, 2023, 8:10pm UTC](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305 "2023-09-26T20:10:48Z")

</div>

Mapping: { "dynamic": "strict", "\_source": { "enabled": false }, "properties": { "data": { "type": "binary", "doc\_values": false, "store": true } } } Query: {"query":{ "bool" …

---

## [Easy way to parse flattened data type?](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:59pm UTC](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926 "2023-09-26T19:59:21Z")

</div>

While I understand the reasoning behind the flattened data type, is there an easy way to split key value pairs out as their own field to use with dashboards / aggregations etc. IE - m365\_defender.event.activity.objects …

---

## [How to close co.elastic.clients.elasticsearch.ElasticsearchClient](https://discuss.elastic.co/t/how-to-close-co-elastic-clients-elasticsearch-elasticsearchclient/343922)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 7:55pm UTC](https://discuss.elastic.co/t/how-to-close-co-elastic-clients-elasticsearch-elasticsearchclient/343922 "2023-09-26T19:55:55Z")

</div>

The HLRC client had a .close() method. Can anyone tell me the correct way to close the new client? Thanks.

---

## [What field shows sign-in due to app or hardware token?](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925)

<div class="topic-metadata">

**Author:** [@BabyElkUser](https://discuss.elastic.co/u/BabyElkUser)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:49pm UTC](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925 "2023-09-26T19:49:16Z")

</div>

I'm in Filebeat and am hoping that someone can please help me find the field that holds the information as to whether someone is signing in with an app, like the MFA app, or with a hardware token. This is getting me all…

---

## [Elasticsearch index has multiple document ids](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 7:36pm UTC](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923 "2023-09-26T19:36:59Z")

</div>

Hi. I am using Logstash / Elasticsearch (8.5.3) and am indexing json data. In logstash I use http input plugin, filter plugins and elasticsearch output. Currently the auto generated @version field in logstash filter i…

---

## [Not eligible for data streams because config contains one or more settings that are not compatible with data streams: {"index"=\>"logstash-%{+YYYY.MM.dd}"}](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-logstash-yyyy-mm-dd/343803)

<div class="topic-metadata">

**Author:** [@Dinoo](https://discuss.elastic.co/u/Dinoo)\
**Replies:** 7\
**Last updated:** [September 26, 2023, 7:13pm UTC](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-logstash-yyyy-mm-dd/343803 "2023-09-26T19:13:13Z")

</div>

Hi, I am working on the ELK stack using Docker compose. I am following this tutorial: Getting started with the Elastic Stack and Docker-Compose | Elastic Blog. Everything works except Logstash. When I run docker-compose …

---

## [Downgrade from ES 8.10.1 TO 8.9.2](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 6:22pm UTC](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919 "2023-09-26T18:22:49Z")

</div>

I would like to upgrade my ES to 8.10.1, i want to have the option to downgrade if tests fails. i did my search and did not find any breaking change between 8.9 to 8.10, wanted to confirm is downgrade is possible. ex., …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=195)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=197)
