# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=198

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 199

---

## [Do collapse keys benefit from document routing?](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 7:02pm UTC](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677 "2023-09-23T19:02:29Z")

</div>

I have an index with denormalized data that is almost exclusively used with collapse queries. If I configure index routing to use the collapse key, which would keep denormalized sibling documents on the same shard, would…

---

## [I have elk, logstash, kibana and filebeat version 7.10.1 and want upgarde to latest](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662)

<div class="topic-metadata">

**Author:** [@Mostafa\_Faridi](https://discuss.elastic.co/u/Mostafa_Faridi)\
**Replies:** 5\
**Last updated:** [September 23, 2023, 5:33pm UTC](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662 "2023-09-23T17:33:18Z")

</div>

I have install ELK stack with RPM on my Oracle Linux and its work and I have six Oracle Linux and install elasticserch and kibana and logstash on one server and install filebeat on other servers. I want right now upgrad…

---

## [Elasticsearch ILM Policies](https://discuss.elastic.co/t/elasticsearch-ilm-policies/343671)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 10:30am UTC](https://discuss.elastic.co/t/elasticsearch-ilm-policies/343671 "2023-09-23T10:30:52Z")

</div>

Hi All Currently we are sending logs to elasticsearch and it's configured in such a way that daily datastreams are created. For Eg: logs-app1-2023-09-23, logs-app1-2023-09-24 etc. Goal is to keep logs for 3 days. We hav…

---

## [DEMORA EN CARGAR INTERFAZ GRAFICA WAZUH](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 2:04am UTC](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653 "2023-09-23T02:04:04Z")

</div>

Tengo un problema al visualizar la interfaz grafica de Wazuh, he procedido a reinicar el servidor ubuntu y al momento de encender todos los servicios (filebeat, elasticsearch, kibana y wazuh-manager) están activos, pero …

---

## [Alter Index so every user can see it](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537)

<div class="topic-metadata">

**Author:** [@yogobah921](https://discuss.elastic.co/u/yogobah921)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 12:11am UTC](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537 "2023-09-23T00:11:33Z")

</div>

I have multiple accounts with different roles and now I created a new index. Now the roles can't access the new index because it is not listed in their indices configuration. how can I alter the index so every user can…

---

## [DEMORA EN CARGAR INTERFAZ GRAFICA WAZUH](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343654)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 8:24pm UTC](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343654 "2023-09-22T20:24:41Z")

</div>

Tengo un problema al visualizar la interfaz grafica de Wazuh, he procedido a reinicar el servidor ubuntu y al momento de encender todos los servicios (filebeat, elasticsearch, kibana y wazuh-manager) están activos, pero …

---

## [ElasticsearchSecurityException when security is enabled on master node but not the data nodes](https://discuss.elastic.co/t/elasticsearchsecurityexception-when-security-is-enabled-on-master-node-but-not-the-data-nodes/342076)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 6\
**Last updated:** [September 22, 2023, 7:44pm UTC](https://discuss.elastic.co/t/elasticsearchsecurityexception-when-security-is-enabled-on-master-node-but-not-the-data-nodes/342076 "2023-09-22T19:44:26Z")

</div>

I have an ES 7.16.2 cluster running with dedicated master nodes and separate data nodes. If/when - xpack.security.enabled is set to true on the master nodes some of the data nodes have xpack security disabled anonymou…

---

## [Analysis phoenitic plugin not found is server down?](https://discuss.elastic.co/t/analysis-phoenitic-plugin-not-found-is-server-down/343632)

<div class="topic-metadata">

**Author:** [@pc-magas](https://discuss.elastic.co/u/pc-magas)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 5:10pm UTC](https://discuss.elastic.co/t/analysis-phoenitic-plugin-not-found-is-server-down/343632 "2023-09-22T17:10:58Z")

</div>

I have this Dockerfile: FROM elasticsearch:7.7.0 RUN elasticsearch-plugin install analysis-phonetic &&\\ elasticsearch-plugin install analysis-icu &&\\ elasticsearch-plugin install gr.skroutz:elasticsearch-skrout…

---

## [Reindexing all data or Reindexing only changes](https://discuss.elastic.co/t/reindexing-all-data-or-reindexing-only-changes/343617)

<div class="topic-metadata">

**Author:** [@Julien\_Hac](https://discuss.elastic.co/u/Julien_Hac)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 3:53pm UTC](https://discuss.elastic.co/t/reindexing-all-data-or-reindexing-only-changes/343617 "2023-09-22T15:53:33Z")

</div>

Hello, I have a question about indexing strategy for my project. Iam a novice and elasticsearch and i need advice and help about my case. In the project, im using primary database postgres, and i have about 10 000 obje…

---

## [Can I limit the search on sub items based on other fields of subitems?](https://discuss.elastic.co/t/can-i-limit-the-search-on-sub-items-based-on-other-fields-of-subitems/343574)

<div class="topic-metadata">

**Author:** [@Carlos\_Barros](https://discuss.elastic.co/u/Carlos_Barros)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 2:51pm UTC](https://discuss.elastic.co/t/can-i-limit-the-search-on-sub-items-based-on-other-fields-of-subitems/343574 "2023-09-22T14:51:37Z")

</div>

Hello guys I'm new in elastic and here comes the doubt. When querying a json index, I need to find in an array of complex objects a string only in some array items. In example: considering the following info I need to…

---

## [Scroll documents with ElasticSearch 8.9 for dotnet](https://discuss.elastic.co/t/scroll-documents-with-elasticsearch-8-9-for-dotnet/343627)

<div class="topic-metadata">

**Author:** [@erhogaihe](https://discuss.elastic.co/u/erhogaihe)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 1:54pm UTC](https://discuss.elastic.co/t/scroll-documents-with-elasticsearch-8-9-for-dotnet/343627 "2023-09-22T13:54:12Z")

</div>

Hi, I am looking for some assisstance in getting scrolling working for ES client (Version 8.9) for .NET. I have tried a few things but cannot get them to work, I have tried as per example in documentation for v7.17 but …

---

## [Filebeat timestamp is shown with a 4hr offset](https://discuss.elastic.co/t/filebeat-timestamp-is-shown-with-a-4hr-offset/343575)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-is-shown-with-a-4hr-offset/343575 "2023-09-22T13:37:51Z")

</div>

We have a Filebeat server (8.9) that ingests Syslog logs. The timestamp shown in GUI is 4 hours earlier than it should be. The timezone is set correctly in Kibana. The timestamp is correct when viewing JSON; it looks lik…

---

## [Elk loses contact with the master every morning at 8am and the cluster turns red](https://discuss.elastic.co/t/elk-loses-contact-with-the-master-every-morning-at-8am-and-the-cluster-turns-red/343621)

<div class="topic-metadata">

**Author:** [@abcdbdocker](https://discuss.elastic.co/u/abcdbdocker)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 1:23pm UTC](https://discuss.elastic.co/t/elk-loses-contact-with-the-master-every-morning-at-8am-and-the-cluster-turns-red/343621 "2023-09-22T13:23:13Z")

</div>

重点词汇 690/5000 传统翻译模型 通用场景 hello Our cluster will turn red after 8 am every day. The cluster size is 6 hot data nodes 3 warm data nodes. The primary node is the same as the hot data node. Recently, we found a strange …

---

## [Elasticsearch Architecture nodes](https://discuss.elastic.co/t/elasticsearch-architecture-nodes/343435)

<div class="topic-metadata">

**Author:** [@Chloe\_Boissavy](https://discuss.elastic.co/u/Chloe_Boissavy)\
**Replies:** 2\
**Last updated:** [September 22, 2023, 11:58am UTC](https://discuss.elastic.co/t/elasticsearch-architecture-nodes/343435 "2023-09-22T11:58:11Z")

</div>

Hello, I have an ECK with 1 kibana + 4 nodes Elasticsearch + 1 Logstash. I am using hot warm cold rotation. I would like to change my design. I would like to change for 1 kibana + 3 nodes HOT + 3 nodes WARM + 3 nodes…

---

## [Create a max of 7 monitoring indices](https://discuss.elastic.co/t/create-a-max-of-7-monitoring-indices/343603)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 4\
**Last updated:** [September 22, 2023, 11:56am UTC](https://discuss.elastic.co/t/create-a-max-of-7-monitoring-indices/343603 "2023-09-22T11:56:24Z")

</div>

Hello, I want to configure monitoring setting as such that only 7 days monitoring indices is created in my cluster in order to monitor for only 7 days and not more.. Also Is there a way that only 1 elasticsearch monito…

---

## [Cannot get the name of indices using logstash](https://discuss.elastic.co/t/cannot-get-the-name-of-indices-using-logstash/343440)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 6\
**Last updated:** [September 22, 2023, 11:34am UTC](https://discuss.elastic.co/t/cannot-get-the-name-of-indices-using-logstash/343440 "2023-09-22T11:34:15Z")

</div>

Hello everyone, How can I get the name of indices using logstash? I have this indices which is from data stream called (backing indices if I correct) .ds-my-neoada-stream-2023.09.14-000001 .ds-my-neoada-stream-2023.09…

---

## [Exclude documents from Reindex](https://discuss.elastic.co/t/exclude-documents-from-reindex/343615)

<div class="topic-metadata">

**Author:** [@NekoNova](https://discuss.elastic.co/u/NekoNova)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 11:30am UTC](https://discuss.elastic.co/t/exclude-documents-from-reindex/343615 "2023-09-22T11:30:22Z")

</div>

Okay, I am using the C# NEST client to trigger a Reindex of documents between two indexes in our Elasticsearch. The problem is that the Elasticsearch cluster only moves around 888 documents of the million that is there …

---

## [ELK stack elasticsearch FIPS Keytool Certificates](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088)

<div class="topic-metadata">

**Author:** [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Replies:** 6\
**Last updated:** [September 21, 2023, 11:51pm UTC](https://discuss.elastic.co/t/elk-stack-elasticsearch-fips-keytool-certificates/343088 "2023-09-21T23:51:41Z")

</div>

I am setting up an ELK stack version 7.17.12. We have a separate instance for Elasticsearch, Kibana, and Logstash - but only one instance for each. We are using it with a Wazuh Manager instance as well with a Logstash an…

---

## [Msearch Java Elasticsearch 8.9](https://discuss.elastic.co/t/msearch-java-elasticsearch-8-9/343570)

<div class="topic-metadata">

**Author:** [@jfuehner](https://discuss.elastic.co/u/jfuehner)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 6:04pm UTC](https://discuss.elastic.co/t/msearch-java-elasticsearch-8-9/343570 "2023-09-21T18:04:42Z")

</div>

I am trying to use the Java 8.9 client to send multi-search requests (Multi search API | Elasticsearch Guide \[8.10\] | Elastic) but am getting a NullPointerException when waiting for the results to come back… Is there a …

---

## [Cannot start ES after upgrading from 7.x to 8.x](https://discuss.elastic.co/t/cannot-start-es-after-upgrading-from-7-x-to-8-x/343494)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 5:56pm UTC](https://discuss.elastic.co/t/cannot-start-es-after-upgrading-from-7-x-to-8-x/343494 "2023-09-21T17:56:57Z")

</div>

This is the error in my journalctl: Sep 20 11:39:43 ELK-Stack.uhtasi.local systemd\[1\]: Starting Elasticsearch... Sep 20 11:39:50 ELK-Stack.uhtasi.local systemd-entrypoint\[29322\]: Error occurred during initialization of…

---

## [Force starting Elasticsearch, even with incorrect index files](https://discuss.elastic.co/t/force-starting-elasticsearch-even-with-incorrect-index-files/343480)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 8\
**Last updated:** [September 21, 2023, 4:16pm UTC](https://discuss.elastic.co/t/force-starting-elasticsearch-even-with-incorrect-index-files/343480 "2023-09-21T16:16:07Z")

</div>

Hi there! I tried to start Elasticsearch 8.6 with loading data from index which was initially created by Elasticsearch 7.13. It fails to start with message \[2023-09-20T11:17:13,331\]\[ERROR\]\[o.e.b.Elasticsearch \] \[…

---

## [Assigning lifecycle policy to diffent indices](https://discuss.elastic.co/t/assigning-lifecycle-policy-to-diffent-indices/343527)

<div class="topic-metadata">

**Author:** [@DetlefG](https://discuss.elastic.co/u/DetlefG)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 12:36pm UTC](https://discuss.elastic.co/t/assigning-lifecycle-policy-to-diffent-indices/343527 "2023-09-21T12:36:07Z")

</div>

Hi all, in our installation filebeat is writing indices with different name depending on fields of the message which are sent to elasticsearch. For all these indices the same index template is used. Is it possible to a…

---

## [SQL Lite aggregare on non grouped Column](https://discuss.elastic.co/t/sql-lite-aggregare-on-non-grouped-column/343539)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 12:32pm UTC](https://discuss.elastic.co/t/sql-lite-aggregare-on-non-grouped-column/343539 "2023-09-21T12:32:23Z")

</div>

Hi @leandrojmp , I have a requirement where I need to apply order on a filed in Elasticsearch which is formed dynamically on the fly and it is not part of original index. My Sample document looks like { "deviceType"…

---

## [Implement Search After in Java](https://discuss.elastic.co/t/implement-search-after-in-java/343512)

<div class="topic-metadata">

**Author:** [@Kumar25](https://discuss.elastic.co/u/Kumar25)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 9:46am UTC](https://discuss.elastic.co/t/implement-search-after-in-java/343512 "2023-09-21T09:46:42Z")

</div>

Hi All, I just migrated Elastic search from 7.17 to 8.2 in Java, but my code is breaking because many libraries are deprecated now, previously we used scroll but now I need to use search after, can you please help me on…

---

## [Elastic license](https://discuss.elastic.co/t/elastic-license/343515)

<div class="topic-metadata">

**Author:** [@DVCS](https://discuss.elastic.co/u/DVCS)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 9:46am UTC](https://discuss.elastic.co/t/elastic-license/343515 "2023-09-21T09:46:01Z")

</div>

Hi all, I have elastic cloud istance with Enterprise license. I opened a ticket to get information about ingest pipline. Support give me same info about it but also tell me that my current subscription level is outside…

---

## [Ingesting Strange Behavior](https://discuss.elastic.co/t/ingesting-strange-behavior/343520)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 9:32am UTC](https://discuss.elastic.co/t/ingesting-strange-behavior/343520 "2023-09-21T09:32:26Z")

</div>

Hi there, I have trouble with ingesting from one of our logs. let me tell you the conditions first: we have been ingesting our logs from OCP4 to Elastic through Logstash and generally, we have 2 sites of the Elastic …

---

## [Data is not saved in Elasticsearch](https://discuss.elastic.co/t/data-is-not-saved-in-elasticsearch/343506)

<div class="topic-metadata">

**Author:** [@gwa99a9](https://discuss.elastic.co/u/gwa99a9)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 7:46am UTC](https://discuss.elastic.co/t/data-is-not-saved-in-elasticsearch/343506 "2023-09-21T07:46:28Z")

</div>

Hi All, My ELK setup is, Logstash running in k8s, version 7.16.2 Elasticsearch in vm with cluster of 4 data nodes and 2 coordinators all running version 7.16.2 Issue: Data is not saved into Elasticsearch and there ar…

---

## [class RestHighLevelClient in package client is deprecated](https://discuss.elastic.co/t/class-resthighlevelclient-in-package-client-is-deprecated/343399)

<div class="topic-metadata">

**Author:** [@Nassereddine](https://discuss.elastic.co/u/Nassereddine)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 9:23pm UTC](https://discuss.elastic.co/t/class-resthighlevelclient-in-package-client-is-deprecated/343399 "2023-09-20T21:23:14Z")

</div>

I am upgrading Elasticsearch from 7.9.2 to 7.17.6 and then to 8.4.2, in the first step i am upgrading the es cluster to the 7.17.6 version , and compiling all other ES clients, the compilation is good for all the other …

---

## [Restore request has no response and doesnt execute](https://discuss.elastic.co/t/restore-request-has-no-response-and-doesnt-execute/343476)

<div class="topic-metadata">

**Author:** [@Chris\_Brown](https://discuss.elastic.co/u/Chris_Brown)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 4:09pm UTC](https://discuss.elastic.co/t/restore-request-has-no-response-and-doesnt-execute/343476 "2023-09-20T16:09:44Z")

</div>

Hello. I've successfully created a snapshot in s3 and it appears to be fine when calling \_snapshot/name/\_all. When trying to restore it with a POST to \_snapshot/name/snapshot/\_restore the request hangs indefinitely, nev…

---

## [Multi-level nested query structure — bug or feature](https://discuss.elastic.co/t/multi-level-nested-query-structure-bug-or-feature/343475)

<div class="topic-metadata">

**Author:** [@jonnyeom](https://discuss.elastic.co/u/jonnyeom)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 3:42pm UTC](https://discuss.elastic.co/t/multi-level-nested-query-structure-bug-or-feature/343475 "2023-09-20T15:42:00Z")

</div>

Hello, Im working with multi-level nested query filters. Documentation in Nested query | Elasticsearch Guide \[8.10\] | Elastic shows an example where each level is nested as part of the search query. i.e. Query Example…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=197)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=199)
