# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=2

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 3

---

## [Elasticseach 9.4.0 Won't Start on Nehalem CPU "does not support all the following CPU features"](https://discuss.elastic.co/t/elasticseach-9-4-0-wont-start-on-nehalem-cpu-does-not-support-all-the-following-cpu-features/386216)

<div class="topic-metadata">

**Author:** [@amorrow](https://discuss.elastic.co/u/amorrow)\
**Replies:** 12\
**Last updated:** [July 8, 2026, 3:08pm UTC](https://discuss.elastic.co/t/elasticseach-9-4-0-wont-start-on-nehalem-cpu-does-not-support-all-the-following-cpu-features/386216 "2026-07-08T15:08:12Z")

</div>

I got an unexpected surprise today when I tried to upgrade my Elasticsearch cluster from 9.3.4 to 9.4.0 on Ubuntu 24.04 LTS using deb packages. The service won't start. May 07 08:33:52 elk3 systemd\[1\]: Starting elastics…

---

## [Elasticsearch Hardware Requirements](https://discuss.elastic.co/t/elasticsearch-hardware-requirements/387878)

<div class="topic-metadata">

**Author:** [@Sam11](https://discuss.elastic.co/u/Sam11)\
**Replies:** 5\
**Last updated:** [July 8, 2026, 2:45pm UTC](https://discuss.elastic.co/t/elasticsearch-hardware-requirements/387878 "2026-07-08T14:45:10Z")

</div>

Hi everyone, I am a bit confused about elasticsearch memory-to-storage ratio. And I would appreciate some clarifications. I know that for warm nodes the ratio is 1:160 and 1:30 for hot nodes. The offical Elasticsearch…

---

## [Can't deploy model on ML node due to insufficient memory](https://discuss.elastic.co/t/cant-deploy-model-on-ml-node-due-to-insufficient-memory/387871)

<div class="topic-metadata">

**Author:** [@Giorgi\_Jambazishvili](https://discuss.elastic.co/u/Giorgi_Jambazishvili)\
**Replies:** 0\
**Last updated:** [July 8, 2026, 11:23am UTC](https://discuss.elastic.co/t/cant-deploy-model-on-ml-node-due-to-insufficient-memory/387871 "2026-07-08T11:23:02Z")

</div>

I am using Elasticsearch cloud. I currently host the free-tier ML node, but the same behavior occurs on the next available tier (node w/ 2GB of memory). I am trying to deploy the E5 embedding model, preferably base, but…

---

## [The selected trace cannot be found](https://discuss.elastic.co/t/the-selected-trace-cannot-be-found/387491)

<div class="topic-metadata">

**Author:** [@hailinux](https://discuss.elastic.co/u/hailinux)\
**Replies:** 4\
**Last updated:** [July 8, 2026, 9:52am UTC](https://discuss.elastic.co/t/the-selected-trace-cannot-be-found/387491 "2026-07-08T09:52:17Z")

</div>

Help me solve the APM problem The selected trace cannot be found . Now I access the Kibana UI: Observability -\> APM-\>Services -\> name service . so this I see Transactions and error as pictured. Please help me quickl…

---

## [Compound sort with \`missing: "\_last"\` silently drops/substitutes hits when every document ties on the leading field](https://discuss.elastic.co/t/compound-sort-with-missing-last-silently-drops-substitutes-hits-when-every-document-ties-on-the-leading-field/387834)

<div class="topic-metadata">

**Author:** [@Kent-Kuan](https://discuss.elastic.co/u/Kent-Kuan)\
**Replies:** 0\
**Last updated:** [July 8, 2026, 3:26am UTC](https://discuss.elastic.co/t/compound-sort-with-missing-last-silently-drops-substitutes-hits-when-every-document-ties-on-the-leading-field/387834 "2026-07-08T03:26:18Z")

</div>

We found a correctness bug: sorting by two fields where the leading field is missing on every matching document returns a wrong, incomplete top-N — even though the result should be mathematically identical to sorting by …

---

## [Do i need to use the ingest node instead of hot nodes in logstash output](https://discuss.elastic.co/t/do-i-need-to-use-the-ingest-node-instead-of-hot-nodes-in-logstash-output/387607)

<div class="topic-metadata">

**Author:** [@kkumar123](https://discuss.elastic.co/u/kkumar123)\
**Replies:** 2\
**Last updated:** [July 7, 2026, 11:50am UTC](https://discuss.elastic.co/t/do-i-need-to-use-the-ingest-node-instead-of-hot-nodes-in-logstash-output/387607 "2026-07-07T11:50:33Z")

</div>

Hello i have dedicated nodes of ml,coordinate, and ml and hot currently i am using the hot nodes in the out put of the logstash but i want to know shouldn't i remove the ingest role from hot and use ingest node in out o…

---

## [ES client upgrade to 9.X](https://discuss.elastic.co/t/es-client-upgrade-to-9-x/387693)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 3\
**Last updated:** [July 7, 2026, 11:18am UTC](https://discuss.elastic.co/t/es-client-upgrade-to-9-x/387693 "2026-07-07T11:18:27Z")

</div>

Our product is currently with Current ES client version: 7.17.9 - co.elastic.clients:elasticsearch-java 7.17.9 with Java API Client Current ES server version: 8.14.3 for test automation Java:17 We are in process of a…

---

## [Node thread\_pools choked](https://discuss.elastic.co/t/node-thread-pools-choked/387466)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 2\
**Last updated:** [July 3, 2026, 7:15am UTC](https://discuss.elastic.co/t/node-thread-pools-choked/387466 "2026-07-03T07:15:44Z")

</div>

We are using elasticsearch 7.17.6 in one our cluster. Recently we saw that two of the hot nodes had their thread\_pools choked. Increased Queue and rejections. From jstack it seems that the node's CPU is occupied doi…

---

## [Timezone in watcher](https://discuss.elastic.co/t/timezone-in-watcher/387430)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [July 1, 2026, 1:40pm UTC](https://discuss.elastic.co/t/timezone-in-watcher/387430 "2026-07-01T13:40:47Z")

</div>

I have created a watcher to send business dashboards to clients . Elasticsearch watcher supports UTC and the requirement is reports should receive at 8 am first day of every month. I forgot about UTC when creating below …

---

## [Elastic certificate password](https://discuss.elastic.co/t/elastic-certificate-password/386883)

<div class="topic-metadata">

**Author:** [@Hamda\_A](https://discuss.elastic.co/u/Hamda_A)\
**Replies:** 3\
**Last updated:** [July 1, 2026, 1:29pm UTC](https://discuss.elastic.co/t/elastic-certificate-password/386883 "2026-07-01T13:29:07Z")

</div>

Hello, Our Elasticsearch cluster certificates have expired, and we generated a new certificate authority and elastic certificate without a password. After uploading the new certificate to the different nodes and trying …

---

## [Apm data timestamps wrong =\> high load and slow responses](https://discuss.elastic.co/t/apm-data-timestamps-wrong-high-load-and-slow-responses/387329)

<div class="topic-metadata">

**Author:** [@nb71](https://discuss.elastic.co/u/nb71)\
**Replies:** 13\
**Last updated:** [June 30, 2026, 2:41pm UTC](https://discuss.elastic.co/t/apm-data-timestamps-wrong-high-load-and-slow-responses/387329 "2026-06-30T14:41:12Z")

</div>

We have an Elastic Cloud installation running version 9.4.0. Overall, it is quite heavily loaded. We have multiple dashboards that use APM and RUM data. We started noticing that the dashboards were becoming slower and …

---

## [Optimizing Elasticsearch Indexing and Search Performance for a Growing Morse Code Website with High-Volume Translation and Analytics Data](https://discuss.elastic.co/t/optimizing-elasticsearch-indexing-and-search-performance-for-a-growing-morse-code-website-with-high-volume-translation-and-analytics-data/387398)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 1\
**Last updated:** [June 30, 2026, 6:51am UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-indexing-and-search-performance-for-a-growing-morse-code-website-with-high-volume-translation-and-analytics-data/387398 "2026-06-30T06:51:50Z")

</div>

I run a Morse Code translator website that allows users to convert plain text into Morse code, decode Morse messages, browse educational articles, and use interactive learning tools. As the website has grown, I have also…

---

## [How to upgrade from Elastic Stack 8 to 9.1?](https://discuss.elastic.co/t/how-to-upgrade-from-elastic-stack-8-to-9-1/378383)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 6\
**Last updated:** [June 29, 2026, 10:10am UTC](https://discuss.elastic.co/t/how-to-upgrade-from-elastic-stack-8-to-9-1/378383 "2026-06-29T10:10:24Z")

</div>

Hello There isnt a clear guide (like other versions) on how to upgrade from Elastic Stack 8 (8.18) to Elastic Stack 9 (9.1). What is the best procedure on doing this? Im using Debian and I rather do it all thru apt-get …

---

## [Elasticsearch 8.17 → 8.19 upgrade: kNN now eagerly defaults "k = size", breaking aggregation-only queries](https://discuss.elastic.co/t/elasticsearch-8-17-8-19-upgrade-knn-now-eagerly-defaults-k-size-breaking-aggregation-only-queries/384628)

<div class="topic-metadata">

**Author:** [@shekhar\_k](https://discuss.elastic.co/u/shekhar_k)\
**Replies:** 5\
**Last updated:** [June 26, 2026, 7:11pm UTC](https://discuss.elastic.co/t/elasticsearch-8-17-8-19-upgrade-knn-now-eagerly-defaults-k-size-breaking-aggregation-only-queries/384628 "2026-06-26T19:11:15Z")

</div>

I’m upgrading Elasticsearch from 8.17.3 to 8.19.10 and ran into a behavioural change with kNN + aggregations that breaks an existing use case. What worked in 8.17.3: We use knn inside the query DSL (bool.must) together…

---

## [The proper way to reindex a data stream index](https://discuss.elastic.co/t/the-proper-way-to-reindex-a-data-stream-index/371102)

<div class="topic-metadata">

**Author:** [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)\
**Replies:** 2\
**Last updated:** [June 25, 2026, 2:03pm UTC](https://discuss.elastic.co/t/the-proper-way-to-reindex-a-data-stream-index/371102 "2026-06-25T14:03:56Z")

</div>

I have run into an issue with mappings in an data stream index. Can someone help me out? I am getting data type conflicts between the new mapping and old mapping of some fields. What I want to do is just remove the mappi…

---

## [Elastic OTP never comes](https://discuss.elastic.co/t/elastic-otp-never-comes/384319)

<div class="topic-metadata">

**Author:** [@Pegasus](https://discuss.elastic.co/u/Pegasus)\
**Replies:** 6\
**Last updated:** [June 25, 2026, 1:59am UTC](https://discuss.elastic.co/t/elastic-otp-never-comes/384319 "2026-06-25T01:59:46Z")

</div>

I signed up for Elastic Cloud (hosted) and was able to log in only during the initial signup. Since then, I have not been receiving the OTP, which is preventing me from logging in. This is extremely frustrating.

---

## [X-pack-security warnings after upgrading to 9.3.3](https://discuss.elastic.co/t/x-pack-security-warnings-after-upgrading-to-9-3-3/385852)

<div class="topic-metadata">

**Author:** [@Koirin](https://discuss.elastic.co/u/Koirin)\
**Replies:** 9\
**Last updated:** [June 23, 2026, 8:48am UTC](https://discuss.elastic.co/t/x-pack-security-warnings-after-upgrading-to-9-3-3/385852 "2026-06-23T08:48:42Z")

</div>

Hello - I just upgraded our node in our monitoring-cluster (single-node) from 9.2.4 to 9.3.3 and have started receiving warnings regarding the x-pack-security getting denied reading some internal files in the docker-cont…

---

## [Auto update GeoLite DB](https://discuss.elastic.co/t/auto-update-geolite-db/386728)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 2\
**Last updated:** [June 22, 2026, 1:49pm UTC](https://discuss.elastic.co/t/auto-update-geolite-db/386728 "2026-06-22T13:49:28Z")

</div>

Hello Logstash logs following warnings/errors related to GeoLite: failed to fetch ASN database {:exception=\>"503 Service Unavailable"} failed to fetch City database {:exception=\>"503 Service Unavailable"} The managed…

---

## [Can we send a report generated by AI assistance from AI chat](https://discuss.elastic.co/t/can-we-send-a-report-generated-by-ai-assistance-from-ai-chat/386896)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [June 18, 2026, 7:42pm UTC](https://discuss.elastic.co/t/can-we-send-a-report-generated-by-ai-assistance-from-ai-chat/386896 "2026-06-18T19:42:24Z")

</div>

Hi Team, We are evaluating the Elastic AI Assistant capabilities and would like to understand its support for automated reporting. Could you please confirm whether the Elastic AI Assistant can: Automatically generat…

---

## [Best Practice for Keeping Separate DC and DR Elasticsearch Open-Source Clusters in Sync](https://discuss.elastic.co/t/best-practice-for-keeping-separate-dc-and-dr-elasticsearch-open-source-clusters-in-sync/386887)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 2\
**Last updated:** [June 17, 2026, 2:26pm UTC](https://discuss.elastic.co/t/best-practice-for-keeping-separate-dc-and-dr-elasticsearch-open-source-clusters-in-sync/386887 "2026-06-17T14:26:15Z")

</div>

Hi Team, We have two separate Elasticsearch Open-Source clusters running on Linux servers: DC Cluster 6 nodes 3 Dedicated Master nodes 3 Data nodes Active production cluster DR Cluster 6 nodes 3 Dedicated Master…

---

## [Cannot disable "xpack.monitoring.collection.enabled" setting](https://discuss.elastic.co/t/cannot-disable-xpack-monitoring-collection-enabled-setting/357358)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 6\
**Last updated:** [June 17, 2026, 7:50am UTC](https://discuss.elastic.co/t/cannot-disable-xpack-monitoring-collection-enabled-setting/357358 "2026-06-17T07:50:56Z")

</div>

Hello, I'm using Kibana upgrade assistant to fix a vulnerability issue, the problem is I need to resolve all warnings, one warning that i couldn't fix is this : the setting \[xpack.monitoring.collection.enabled\] is curr…

---

## [V8.17.3 ES Cloud: Random morning ConnectionTimeout to Elastic Cloud from Django/Kubernetes, same request succeeds seconds later](https://discuss.elastic.co/t/v8-17-3-es-cloud-random-morning-connectiontimeout-to-elastic-cloud-from-django-kubernetes-same-request-succeeds-seconds-later/386774)

<div class="topic-metadata">

**Author:** [@Husein\_Kantarci](https://discuss.elastic.co/u/Husein_Kantarci)\
**Replies:** 2\
**Last updated:** [June 16, 2026, 10:01am UTC](https://discuss.elastic.co/t/v8-17-3-es-cloud-random-morning-connectiontimeout-to-elastic-cloud-from-django-kubernetes-same-request-succeeds-seconds-later/386774 "2026-06-16T10:01:23Z")

</div>

Hi, We are seeing intermittent elastic\_transport.ConnectionTimeout: Connection timed out errors from our Django application to Elastic Cloud. Environment: Django app running on Kubernetes (EKS) uWSGI, 1 process per p…

---

## [Elasticsearch 9.2.1 snapshot visible in repository but restore fails with snapshot\_missing\_exception](https://discuss.elastic.co/t/elasticsearch-9-2-1-snapshot-visible-in-repository-but-restore-fails-with-snapshot-missing-exception/386829)

<div class="topic-metadata">

**Author:** [@shantia](https://discuss.elastic.co/u/shantia)\
**Replies:** 8\
**Last updated:** [June 15, 2026, 1:59pm UTC](https://discuss.elastic.co/t/elasticsearch-9-2-1-snapshot-visible-in-repository-but-restore-fails-with-snapshot-missing-exception/386829 "2026-06-15T13:59:41Z")

</div>

I have an Elasticsearch 9.2.1 cluster configured with Snapshot Lifecycle Management (SLM) that takes nightly snapshots to an S3 repository. The snapshots are successfully created, and I can see all snapshot metadata in t…

---

## [Courses on Elastic.Clients.Elasticsearch](https://discuss.elastic.co/t/courses-on-elastic-clients-elasticsearch/386125)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 12\
**Last updated:** [June 15, 2026, 1:27pm UTC](https://discuss.elastic.co/t/courses-on-elastic-clients-elasticsearch/386125 "2026-06-15T13:27:55Z")

</div>

We need to upgrade from NEST to the new API and are DESPARATELY looking for courses (paid or unpaid) to guide us through this process. Can anyone help? Thanks

---

## [Eland-imported naver/splade-v3 text\_expansion produces much smaller sparse vectors and worse ranking than local SentenceTransformers SparseEncoder](https://discuss.elastic.co/t/eland-imported-naver-splade-v3-text-expansion-produces-much-smaller-sparse-vectors-and-worse-ranking-than-local-sentencetransformers-sparseencoder/386819)

<div class="topic-metadata">

**Author:** [@alrolo3](https://discuss.elastic.co/u/alrolo3)\
**Replies:** 0\
**Last updated:** [June 11, 2026, 9:39pm UTC](https://discuss.elastic.co/t/eland-imported-naver-splade-v3-text-expansion-produces-much-smaller-sparse-vectors-and-worse-ranking-than-local-sentencetransformers-sparseencoder/386819 "2026-06-11T21:39:41Z")

</div>

Eland-imported naver/splade-v3 text\_expansion produces much smaller sparse vectors and worse ranking than local SentenceTransformers SparseEncoder Environment Elasticsearch version: 9.4.2 Eland Docker image used: docke…

---

## [Race between ThreadContext.close() and context access may throw IllegalStateException](https://discuss.elastic.co/t/race-between-threadcontext-close-and-context-access-may-throw-illegalstateexception/386792)

<div class="topic-metadata">

**Author:** [@denyjohn](https://discuss.elastic.co/u/denyjohn)\
**Replies:** 1\
**Last updated:** [June 11, 2026, 3:43pm UTC](https://discuss.elastic.co/t/race-between-threadcontext-close-and-context-access-may-throw-illegalstateexception/386792 "2026-06-11T15:43:39Z")

</div>

In v6.4.2, ThreadContext stores request-specific headers and transient values in the shared field threadLocal, whose concrete type is ThreadContext.ContextThreadLocal. There appears to be a race between ThreadContext.cl…

---

## [New .Net API](https://discuss.elastic.co/t/new-net-api/386806)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 10:51pm UTC](https://discuss.elastic.co/t/new-net-api/386806 "2026-06-10T22:51:48Z")

</div>

Thanks. Also we used to be able to build filters incrementally as below. How do we do it in the new API. Thanks internal static List\<Func\<QueryContainerDescriptor, QueryContainer\>\> BuildFilter(SearchCriteria searchCrite…

---

## [On-premise elasticsearch support for Windows Server 2025](https://discuss.elastic.co/t/on-premise-elasticsearch-support-for-windows-server-2025/379619)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 3\
**Last updated:** [June 10, 2026, 8:12am UTC](https://discuss.elastic.co/t/on-premise-elasticsearch-support-for-windows-server-2025/379619 "2026-06-10T08:12:34Z")

</div>

I have checked OS support matrix but didnt see anything mentioned about Windows Server 2025. Can someone please confirm when ELK will start supporting on-premise Elasticsearch and Kibana on Windows Server 2025?

---

## [Elasticsearch 9.1.3 - Unable to Recover or Delete Protected System Indices .secrets-inference and .security-7 After Multiple Recovery Attempts](https://discuss.elastic.co/t/elasticsearch-9-1-3-unable-to-recover-or-delete-protected-system-indices-secrets-inference-and-security-7-after-multiple-recovery-attempts/386751)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 8\
**Last updated:** [June 10, 2026, 7:11am UTC](https://discuss.elastic.co/t/elasticsearch-9-1-3-unable-to-recover-or-delete-protected-system-indices-secrets-inference-and-security-7-after-multiple-recovery-attempts/386751 "2026-06-10T07:11:51Z")

</div>

Hello Team, I am seeking assistance with an issue involving two protected system indices in our Elasticsearch 9.1.3 cluster: .secrets-inference .security-7 Environment Elasticsearch Version: 9.1.3 Installation Type…

---

## [High RAM usage with Active Directory Entity Analytics integration on a 4GB RAM server](https://discuss.elastic.co/t/high-ram-usage-with-active-directory-entity-analytics-integration-on-a-4gb-ram-server/386780)

<div class="topic-metadata">

**Author:** [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Replies:** 1\
**Last updated:** [June 10, 2026, 6:26am UTC](https://discuss.elastic.co/t/high-ram-usage-with-active-directory-entity-analytics-integration-on-a-4gb-ram-server/386780 "2026-06-10T06:26:11Z")

</div>

Hello everyone, I’ve run into an issue with excessive resource consumption by the Elastic Agent and am looking for advice on optimizing policies and limits. Context: A customer has a server with very modest hardware sp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=1)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=3)
