# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=199

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 200

---

## [What's the equivalent of NEST's QueryBase.IsVerbatim property in Elastic.Clients.Elasticsearch (8.x)](https://discuss.elastic.co/t/whats-the-equivalent-of-nests-querybase-isverbatim-property-in-elastic-clients-elasticsearch-8-x/343455)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 1:26pm UTC](https://discuss.elastic.co/t/whats-the-equivalent-of-nests-querybase-isverbatim-property-in-elastic-clients-elasticsearch-8-x/343455 "2023-09-20T13:26:08Z")

</div>

NEST (7.x) client has QueryBase class, which in its turn has IsVerbatim boolean property. Hence, all derived query classes inherit it. However, query classes in Elastic.Clients.Elasticsearch (8.x) client don't inherit/de…

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - the truststore \[/usr/share/elasticsearch/ssl/qa.pfx\] does not contain any trusted certificate entries](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-usr-share-elasticsearch-ssl-qa-pfx-does-not-contain-any-trusted-certificate-entries/343138)

<div class="topic-metadata">

**Author:** [@Anushree](https://discuss.elastic.co/u/Anushree)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 12:10pm UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-usr-share-elasticsearch-ssl-qa-pfx-does-not-contain-any-trusted-certificate-entries/343138 "2023-09-20T12:10:08Z")

</div>

Hello, I encountered an SSL certificate trust issue when attempting to upgrade a single-node Elasticsearch instance from version 7.17 to 8.0, same certificate was working on 7.17. I am using a valid certificate chain pr…

---

## [jakarta.json.stream.JsonParsingException when deserializing data retrieved from Elasticsearch](https://discuss.elastic.co/t/jakarta-json-stream-jsonparsingexception-when-deserializing-data-retrieved-from-elasticsearch/343367)

<div class="topic-metadata">

**Author:** [@Georgi\_Nikolov](https://discuss.elastic.co/u/Georgi_Nikolov)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 11:44am UTC](https://discuss.elastic.co/t/jakarta-json-stream-jsonparsingexception-when-deserializing-data-retrieved-from-elasticsearch/343367 "2023-09-20T11:44:41Z")

</div>

for some time now I have been trying to incorporate the Elastic Java 8.10 client into my code, I have a big ELK stack with a lot of data. I am trying to fetch continuously data from it, but I am encountering some inconsi…

---

## [Time-based rule exclusions](https://discuss.elastic.co/t/time-based-rule-exclusions/343451)

<div class="topic-metadata">

**Author:** [@austinvdm](https://discuss.elastic.co/u/austinvdm)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 11:42am UTC](https://discuss.elastic.co/t/time-based-rule-exclusions/343451 "2023-09-20T11:42:44Z")

</div>

Hello, I am curious if there is a way to implement "time-based exclusions" for security rules? For example, we are trying to excluded specific endpoints from a rule on Saturday and Sundays when we run OS updates but stil…

---

## [Error while starting elasticsearch v8.9.1](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335)

<div class="topic-metadata">

**Author:** [@sanyam](https://discuss.elastic.co/u/sanyam)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 10:32am UTC](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335 "2023-09-20T10:32:21Z")

</div>

Whenever I start up ES by running ES .bat file on Windows, I receive this error: \[ERROR\]\[o.e.b.Elasticsearch \] \[node-1\] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: i…

---

## ["Failed to decode response" error from Java Client 8.8.0](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 10\
**Last updated:** [September 20, 2023, 9:12am UTC](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309 "2023-09-20T09:12:14Z")

</div>

Hello: I am trying to use Elastic Java Client 8.8.0 (also known low-level rest client) and getting the error: status: 200, \[es/search\] Failed to decode response I used the same library to create a new index and insert …

---

## [Semantic search on more than 10k documents](https://discuss.elastic.co/t/semantic-search-on-more-than-10k-documents/343362)

<div class="topic-metadata">

**Author:** [@Denis\_Stefan](https://discuss.elastic.co/u/Denis_Stefan)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 7:44am UTC](https://discuss.elastic.co/t/semantic-search-on-more-than-10k-documents/343362 "2023-09-20T07:44:47Z")

</div>

Hello. I am currently developing a semantic search solution and I have to work with more than 10k documents (more than the maximum number of candidates which is 10k for the kNN algorithm). I am trying to find a solution…

---

## [Hardware compability for elasticsearch](https://discuss.elastic.co/t/hardware-compability-for-elasticsearch/343405)

<div class="topic-metadata">

**Author:** [@Cino](https://discuss.elastic.co/u/Cino)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:24am UTC](https://discuss.elastic.co/t/hardware-compability-for-elasticsearch/343405 "2023-09-20T07:24:07Z")

</div>

hello team, I have a basic question about hardware compability or dependency with search engine. My hardware consists of NVMe direct attached disks( for better performance). Could we use such alternate raid options like…

---

## [ELK Pricing help for onprem cluster](https://discuss.elastic.co/t/elk-pricing-help-for-onprem-cluster/343322)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 5:14am UTC](https://discuss.elastic.co/t/elk-pricing-help-for-onprem-cluster/343322 "2023-09-20T05:14:22Z")

</div>

Hi team, Can you please help us to understand pricing for ELK onprem 4 node cluster with 128 GB of ram for each node and 12 TB harddisk or each node Please share for platinum and enterprise pricing comparision

---

## [Elastic Cloud: Defining roles to user in Okta using SAML](https://discuss.elastic.co/t/elastic-cloud-defining-roles-to-user-in-okta-using-saml/343153)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 1:59am UTC](https://discuss.elastic.co/t/elastic-cloud-defining-roles-to-user-in-okta-using-saml/343153 "2023-09-20T01:59:37Z")

</div>

Hello, Right now, I'm defining roles for user using the security api POST /\_security/role\_mapping/viewer\_mapping { "roles": \[ "custome\_role\_viewer"\], "enabled": true, "rules": { "field" : { "username" : \["us…

---

## [I got the exception when I added kerberos authentication to es](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116)

<div class="topic-metadata">

**Author:** [@zytine](https://discuss.elastic.co/u/zytine)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 1:53am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116 "2023-09-20T01:53:49Z")

</div>

Hello, My es was running fine, but when I added kerberos authentication and restarted，I got the following error \[2023-09-15T23:09:36,876\]\[WARN \]\[o.e.x.s.a.s.m.NativeRoleMappingStore\] \[bsa264\] Failed to clear cache for…

---

## [InferenceConfig doesn't support text\_expansion value when creating a pipeline from java](https://discuss.elastic.co/t/inferenceconfig-doesnt-support-text-expansion-value-when-creating-a-pipeline-from-java/342377)

<div class="topic-metadata">

**Author:** [@ajperez](https://discuss.elastic.co/u/ajperez)\
**Replies:** 6\
**Last updated:** [September 19, 2023, 9:04pm UTC](https://discuss.elastic.co/t/inferenceconfig-doesnt-support-text-expansion-value-when-creating-a-pipeline-from-java/342377 "2023-09-19T21:04:33Z")

</div>

When creating a PutPipelineRequest with the Java client version 8.9.1, InferenceConfig doesn’t support “text\_expansion” value, an error is thrown co.elastic.clients.json.JsonpMappingException: Error deserializing co.elas…

---

## [Cancel after time interval clarification](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401)

<div class="topic-metadata">

**Author:** [@maxfriz](https://discuss.elastic.co/u/maxfriz)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:48pm UTC](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401 "2023-09-19T20:48:29Z")

</div>

To ensure a clear understanding of our global search configuration for a given cluster, I would like to clarify the following as written: The search.cancel\_after\_time\_interval configures (at the data node level) the t…

---

## [What's the secret to fast recovery when adding a new node?](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:08pm UTC](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397 "2023-09-19T20:08:45Z")

</div>

We are on on version 7.15. Still experiencing issues during recovery. The cluster will often (very likely) move shards from new node back to old nodes even though the new node(s) are still have way fewer shards (and lo…

---

## [Failed to start the service winlogbeat](https://discuss.elastic.co/t/failed-to-start-the-service-winlogbeat/343289)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 7:26pm UTC](https://discuss.elastic.co/t/failed-to-start-the-service-winlogbeat/343289 "2023-09-19T19:26:24Z")

</div>

Hi everyone, I'm facing the issue to start the winlogbeat server on my windows servers " windows couldn't start the winlogbeat on your local computer. Error 1067 Please assist if anyone faced this issues and solved. Th…

---

## [Calculate percentage based on status of max per group in Elasticsearch](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 5\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171 "2023-09-19T16:27:48Z")

</div>

Given the dataset below, I'd like to calculate percentage of status over unique count of workflow. id,workflow,status 1,A,FAILURE 2,A,ABORTED 3,A,SUCCESS 4,A,SUCCESS 1,B,FAILURE 2,B,SUCCESS 3,B,FAILURE 1,C,FAILURE 2,C,F…

---

## [Cardinality problem](https://discuss.elastic.co/t/cardinality-problem/343387)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/cardinality-problem/343387 "2023-09-19T16:27:18Z")

</div>

Hi, I'm not sure if this can be done, but it's worth asking :slight\_smile: I would like to see a specific metric, but it'd need a lot of conditions and cardinality. Let's say I have an index where I have documents fro…

---

## [Transaction\_sample\_rate post 8 release versions](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 3:10pm UTC](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290 "2023-09-19T15:10:40Z")

</div>

We haev java agent 1.42 and Elasticsearch/APM servers are in 8.10 version. I haev tried with sampling rate of .2 and .5. Both values and 1 are getting response time/throughput for all samples. But document has change in…

---

## [What's the equivalent for NEST's MultiTermQueryRewrite class and/or RewriteMultiTerm enum in Elastic.Clients.Elasticsearch (8.x)](https://discuss.elastic.co/t/whats-the-equivalent-for-nests-multitermqueryrewrite-class-and-or-rewritemultiterm-enum-in-elastic-clients-elasticsearch-8-x/343379)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 2:45pm UTC](https://discuss.elastic.co/t/whats-the-equivalent-for-nests-multitermqueryrewrite-class-and-or-rewritemultiterm-enum-in-elastic-clients-elasticsearch-8-x/343379 "2023-09-19T14:45:41Z")

</div>

Basically, the title says it all. During migration from the NEST (7.x) client to Elastic.Clients.Elasticsearch (8.x) client I can't find the equivalent of MultiTermQueryRewrite class and/or RewriteMultiTerm enum. Could …

---

## [How to map ambiguous data](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 1:56pm UTC](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271 "2023-09-19T13:56:36Z")

</div>

There is a more practical way to map ambiguous data other than deleting and creating index, I need to make a query to the canvas but try to show a column with an error because the data cannot be ambiguous

---

## [Substituting Match Phrase Prefix Query with a MUST combination of Match Phrase and Prefix](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218)

<div class="topic-metadata">

**Author:** [@aliyanamu](https://discuss.elastic.co/u/aliyanamu)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 12:24pm UTC](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218 "2023-09-19T12:24:55Z")

</div>

Hi, I am using match phrase prefix for suggestion and querying search result. I'm using this for searching employee name, skill name, etc... basically name / title field which is not long. When I'm searching name like …

---

## [Unable to filter older indices](https://discuss.elastic.co/t/unable-to-filter-older-indices/343359)

<div class="topic-metadata">

**Author:** [@pbmamatha](https://discuss.elastic.co/u/pbmamatha)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 12:16pm UTC](https://discuss.elastic.co/t/unable-to-filter-older-indices/343359 "2023-09-19T12:16:04Z")

</div>

Hello, I am tasked to create an alert for indices older than 3 days, however, the filter query is not working. Could you please help me identify the issue. Have tried the below queries: 1. GET /\_search { "query":…

---

## [Which Node.js client should I use for Elastic search?](https://discuss.elastic.co/t/which-node-js-client-should-i-use-for-elastic-search/343115)

<div class="topic-metadata">

**Author:** [@cosieLq](https://discuss.elastic.co/u/cosieLq)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 9:40am UTC](https://discuss.elastic.co/t/which-node-js-client-should-i-use-for-elastic-search/343115 "2023-09-19T09:40:20Z")

</div>

Which package should I use as a Node.js client to connect to Elastic search? I've found this one: elasticsearch-js (GitHub - elastic/elasticsearch-js: Official Elasticsearch client library for Node.js) It seems to be r…

---

## [Installation Freeze (adding index template)](https://discuss.elastic.co/t/installation-freeze-adding-index-template/343324)

<div class="topic-metadata">

**Author:** [@fizzyBubblech](https://discuss.elastic.co/u/fizzyBubblech)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 8:56am UTC](https://discuss.elastic.co/t/installation-freeze-adding-index-template/343324 "2023-09-19T08:56:06Z")

</div>

Hello My Goal: Install Kibana and Elasticsearch on my Windows 11 VM. Our Infrastructure We run our VMs on ESXi and managed them in vCenter. I have Admin rights but just for my VM. Install processes 1.) Downloaded …

---

## [Error when converting Eland Dataframe to Pandas Dataframe using Eland on Jupyter](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:46am UTC](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331 "2023-09-19T08:46:50Z")

</div>

I currently have setup Eland to pull data from Elasticsearch and I am trying to rename some of the columns. However, I realised that to use the .rename() function, I would have to convert the data to Pandas Dataframe as …

---

## [Query\_string does not perform consistently in versions 6 and 7](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228)

<div class="topic-metadata">

**Author:** [@casterQ](https://discuss.elastic.co/u/casterQ)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 6:04am UTC](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228 "2023-09-19T06:04:55Z")

</div>

version: 6.7.0 and 7.17.6 mapping: { "t1": { "type": "text", "analyzer": "ik\_max\_word" }, "t2": { "type": "text", "analyzer": "ik\_max\_word" } } DSL: POST test1/\_search { "query": { "boo…

---

## [Install Elasticsearch with Docker](https://discuss.elastic.co/t/install-elasticsearch-with-docker/342271)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 26\
**Last updated:** [September 19, 2023, 2:35am UTC](https://discuss.elastic.co/t/install-elasticsearch-with-docker/342271 "2023-09-19T02:35:52Z")

</div>

Hello World! I'm trying to follow https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-compose-file, I copy .env file, change password, then copy and paste docker-compose.yml and then the …

---

## [Combine Elasticsearch/Enterprise Search Ingest Pipeline and Logstash Pipelines](https://discuss.elastic.co/t/combine-elasticsearch-enterprise-search-ingest-pipeline-and-logstash-pipelines/343280)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 10:22pm UTC](https://discuss.elastic.co/t/combine-elasticsearch-enterprise-search-ingest-pipeline-and-logstash-pipelines/343280 "2023-09-18T22:22:50Z")

</div>

Hi, does anybody know whether it is possible to call a Logstash pipeline from an Elasticsearch/Enterprise Search Ingest Pipeline ? Best regards Sebastian

---

## [Elastic Search on Rocky LInux 9](https://discuss.elastic.co/t/elastic-search-on-rocky-linux-9/343293)

<div class="topic-metadata">

**Author:** [@mcarifio](https://discuss.elastic.co/u/mcarifio)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 8:27pm UTC](https://discuss.elastic.co/t/elastic-search-on-rocky-linux-9/343293 "2023-09-18T20:27:06Z")

</div>

Does anyone have experience running Elastic Search on Rocky Linux 9? The Elastic Search support matrix indicates that RHEL 9 is a supported platform. What's the best way to add a Rocky Linux 9 column? Thanks.

---

## [Ingest Github Audit logs with Logstash](https://discuss.elastic.co/t/ingest-github-audit-logs-with-logstash/343266)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 1:57pm UTC](https://discuss.elastic.co/t/ingest-github-audit-logs-with-logstash/343266 "2023-09-18T13:57:45Z")

</div>

Has anyone created a successful grok pattern to ingest Github audit logs into ELK? Or does the Github plugin support formatting those logs into ELK?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=198)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=200)
