# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=202

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 203

---

## [How to ingest Squid proxy logs into elasticsearch and visualize on kibana?](https://discuss.elastic.co/t/how-to-ingest-squid-proxy-logs-into-elasticsearch-and-visualize-on-kibana/342906)

<div class="topic-metadata">

**Author:** [@irshadalam](https://discuss.elastic.co/u/irshadalam)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-to-ingest-squid-proxy-logs-into-elasticsearch-and-visualize-on-kibana/342906 "2023-09-13T11:49:07Z")

</div>

How to craete ingest-pipeline Squid proxy logs into elasticsearch and visualize on kibana ?

---

## [Elastic Security Issues](https://discuss.elastic.co/t/elastic-security-issues/342900)

<div class="topic-metadata">

**Author:** [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 11:18am UTC](https://discuss.elastic.co/t/elastic-security-issues/342900 "2023-09-13T11:18:03Z")

</div>

Hello, Firslty, sorry for my english. In my elastic panel, I see this error In your Elasticsearch configuration (elasticsearch.yml), enable: Elasticsearch security(opens in a new tab or window). Set xpack.security.ena…

---

## [Elasticsearch cluster status is yellow](https://discuss.elastic.co/t/elasticsearch-cluster-status-is-yellow/342911)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 4\
**Last updated:** [September 13, 2023, 10:44am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-status-is-yellow/342911 "2023-09-13T10:44:20Z")

</div>

Hi, I have created elasticsearch,kibana and apm in a single node and all is working properly ,kibana and apm is healthy but elasticsearch status is yellow.I also want to say elasticsearch status was green before,but afte…

---

## [Use fleet-server integration without authority certificates](https://discuss.elastic.co/t/use-fleet-server-integration-without-authority-certificates/342933)

<div class="topic-metadata">

**Author:** [@Guillaume\_Cotral](https://discuss.elastic.co/u/Guillaume_Cotral)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/use-fleet-server-integration-without-authority-certificates/342933 "2023-09-13T10:10:24Z")

</div>

Hello everybody, I set up an ELK server running Docker with Elasticsearch and Kibana within my company as a test. I would like to know if it is possible to delete the authentication certificates so that the integrations…

---

## [Elastic search queue choking](https://discuss.elastic.co/t/elastic-search-queue-choking/342904)

<div class="topic-metadata">

**Author:** [@cosmos\_roeba](https://discuss.elastic.co/u/cosmos_roeba)\
**Replies:** 5\
**Last updated:** [September 13, 2023, 9:52am UTC](https://discuss.elastic.co/t/elastic-search-queue-choking/342904 "2023-09-13T09:52:59Z")

</div>

I am running a 2 node cluster with 2 core cpus. I have 2 indices with about 1 million docs each. They are flat documents and I need to enable search on title key stored both as text and keyword. Search text is minimum 3…

---

## [I cannot search the file name from path in Elasticsearch](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812)

<div class="topic-metadata">

**Author:** [@Enes\_Can\_ISIK](https://discuss.elastic.co/u/Enes_Can_ISIK)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 9:48am UTC](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812 "2023-09-13T09:48:05Z")

</div>

I want to search filename from a path in Elasticsearch, but I cannot do it. I have documents consisting of "name" fields with paths. Example: Name "folder/folder1/test/folder2/folder/" "folder/folder1/test/folder2/f…

---

## [Doubt about cacerts file of Elasticsearch](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 9:18am UTC](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925 "2023-09-13T09:18:34Z")

</div>

Hi, everyone I would like to know the purpose of cacerts file of Elasticsearch (/usr/share/elasticsearch/jdk/lib/security/cacerts). It has some certificates into, are they important? they could be removed? Thanks in a…

---

## [Error: could not parse \[webhook\] action failed parsing http request template](https://discuss.elastic.co/t/error-could-not-parse-webhook-action-failed-parsing-http-request-template/342917)

<div class="topic-metadata">

**Author:** [@rathasatekun](https://discuss.elastic.co/u/rathasatekun)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 7:38am UTC](https://discuss.elastic.co/t/error-could-not-parse-webhook-action-failed-parsing-http-request-template/342917 "2023-09-13T07:38:59Z")

</div>

I try to create Watcher , when i save it error could not parse \[webhook\] action \[42407423-32c4-4a72-aedf-03e31c4d6856/xxxx\_webhook\]. failed parsing http request template "actions": { "gosd\_webhook": { "transform": { …

---

## [Elastic search response parsing error](https://discuss.elastic.co/t/elastic-search-response-parsing-error/342909)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 6:59am UTC](https://discuss.elastic.co/t/elastic-search-response-parsing-error/342909 "2023-09-13T06:59:17Z")

</div>

I am using 7.4 El;asticSearchClient and querying to Elasticsearch. I am getting response in profile object like below "profile": { "shards": \[ { "id": "\[GArOi1iwQHGY2qpSalRgHw\]\[hbs-search-3\]\[0\]", "searches": \[ { …

---

## [How to get iml policy's use by in ES 7.10?](https://discuss.elastic.co/t/how-to-get-iml-policys-use-by-in-es-7-10/342776)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 6:20am UTC](https://discuss.elastic.co/t/how-to-get-iml-policys-use-by-in-es-7-10/342776 "2023-09-13T06:20:20Z")

</div>

The \_ilm/policy/my\_policy api can get which indices use this policy in current version, but in 7.10, the response does not contains in\_use\_by info. How to get the similar info(in\_use\_by) in ES 7.10? I noticed Kibana c…

---

## [What happens if my Elasticsearch cluster has only two nodes with a significant difference in disk storage space?](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 4:06am UTC](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895 "2023-09-13T04:06:24Z")

</div>

According to the official documentation, when the disk space reaches 85%, replica allocation becomes challenging, at 90% replicas start getting relocated to other nodes (but since I have only two nodes and the principle …

---

## [Identify what a ".save" file is and its purpose](https://discuss.elastic.co/t/identify-what-a-save-file-is-and-its-purpose/342750)

<div class="topic-metadata">

**Author:** [@sampad1](https://discuss.elastic.co/u/sampad1)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 1:22am UTC](https://discuss.elastic.co/t/identify-what-a-save-file-is-and-its-purpose/342750 "2023-09-13T01:22:38Z")

</div>

After deleting some documents from an index, I noticed a compound-file (.cfs) .save file extension as in \_01.cfs.save . I have looked for this file in open source docs/searches and within the community, but I have been u…

---

## [Filebeat processor not doing anything](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 11:11pm UTC](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890 "2023-09-12T23:11:49Z")

</div>

I'm trying to use a processor to split up syslog messages into separate fields (using the '=' character as a delimiter). Here's my processor: - type: syslog format: auto protocol.udp: host: "0.0.0.0:9002" tags…

---

## [Error: ElasticSearch won't start when downgraded from 8.9.2 to 8.4.1](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879)

<div class="topic-metadata">

**Author:** [@ujosyula](https://discuss.elastic.co/u/ujosyula)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 8:52pm UTC](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879 "2023-09-12T20:52:35Z")

</div>

I see this error when I try to downgrade. The version of elasticsearch is 8.4.1, but the service won't start. \[2023-09-12T09:52:39,253\]\[ERROR\]\[o.e.b.Elasticsearch \] fatal exception while booting Elasticsearch j…

---

## [Bulk import role mappings from one cluster to another via API](https://discuss.elastic.co/t/bulk-import-role-mappings-from-one-cluster-to-another-via-api/342869)

<div class="topic-metadata">

**Author:** [@AndrewDatTeranet](https://discuss.elastic.co/u/AndrewDatTeranet)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 4:16pm UTC](https://discuss.elastic.co/t/bulk-import-role-mappings-from-one-cluster-to-another-via-api/342869 "2023-09-12T16:16:29Z")

</div>

I am attempting to dump all role mappings out of one cluster into another by using the Role Mapping API. I use the generic: GET /\_security/role\_mapping to dump all the mappings but cannot find a way to easily bulk imp…

---

## [Painless Elasticsearch update do not handle big numbers](https://discuss.elastic.co/t/painless-elasticsearch-update-do-not-handle-big-numbers/342633)

<div class="topic-metadata">

**Author:** [@DidierB](https://discuss.elastic.co/u/DidierB)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 4:10pm UTC](https://discuss.elastic.co/t/painless-elasticsearch-update-do-not-handle-big-numbers/342633 "2023-09-12T16:10:37Z")

</div>

Hello, I'm using an index that contains big numbers (tracking data byte count per IP). Each time I see an IP in the log I extract the size of the request and add it to an index with the IP as a key. The index has a mapp…

---

## [Backup policy](https://discuss.elastic.co/t/backup-policy/342853)

<div class="topic-metadata">

**Author:** [@sravanth\_cabbu](https://discuss.elastic.co/u/sravanth_cabbu)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:39pm UTC](https://discuss.elastic.co/t/backup-policy/342853 "2023-09-12T14:39:34Z")

</div>

Hi Team, We are upgrading RHEL7 to 8 and installed ES. We have NAS mount in place and restored all indices. So in the process of cutover from rhel 7 to 8, we have to add the backup policy to rhel 8 for snapshot. we have…

---

## [Ingest Pipeline Dissect Pattern unable to match Append modifiers](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765 "2023-09-12T14:20:31Z")

</div>

This is is the dissect pattern %{+dateStr} %(+dateStr) %{logLevel} %{className} %{httpNio} %{+messageContent} %{+messageContent} %{+messageContent} %{} This is a sample line from the document that the dissect is failin…

---

## [Java api bulk opreration](https://discuss.elastic.co/t/java-api-bulk-opreration/342659)

<div class="topic-metadata">

**Author:** [@zgy](https://discuss.elastic.co/u/zgy)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 2:04pm UTC](https://discuss.elastic.co/t/java-api-bulk-opreration/342659 "2023-09-12T14:04:31Z")

</div>

hello,I'm a student , and learning elasticsearch recently. when I use the java bulk api follow the official guides as Bulk: indexing multiple documents | Elasticsearch Java API Client \[8.3\] | Elastic. but it's occured a…

---

## [Update By Query | Alias](https://discuss.elastic.co/t/update-by-query-alias/342834)

<div class="topic-metadata">

**Author:** [@ankitpandoh](https://discuss.elastic.co/u/ankitpandoh)\
**Replies:** 5\
**Last updated:** [September 12, 2023, 1:51pm UTC](https://discuss.elastic.co/t/update-by-query-alias/342834 "2023-09-12T13:51:26Z")

</div>

I am able to add a document to an index say my-main-index having some alias my-alias-index. When I did a search like below, I was able to get the documents. GET /my-main-index/\_search { "query":{ "match\_all": {} …

---

## [Feasibility to send alerts only if consecutive errors are occurred using elastalert](https://discuss.elastic.co/t/feasibility-to-send-alerts-only-if-consecutive-errors-are-occurred-using-elastalert/341485)

<div class="topic-metadata">

**Author:** [@prathameshdvk](https://discuss.elastic.co/u/prathameshdvk)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 1:34pm UTC](https://discuss.elastic.co/t/feasibility-to-send-alerts-only-if-consecutive-errors-are-occurred-using-elastalert/341485 "2023-09-12T13:34:38Z")

</div>

Hi All, I am trying to setup alerting using elastalert and I am trying to achieve below scenarios. scenario 1: Send alert if there are 3 consecutive 400 errors. (Which is working fine) scenario 2: Do not send alert if…

---

## [ElasticSearch v7 docker container not starting on RHEL 8.8](https://discuss.elastic.co/t/elasticsearch-v7-docker-container-not-starting-on-rhel-8-8/341913)

<div class="topic-metadata">

**Author:** [@hakakuma](https://discuss.elastic.co/u/hakakuma)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:31pm UTC](https://discuss.elastic.co/t/elasticsearch-v7-docker-container-not-starting-on-rhel-8-8/341913 "2023-09-12T13:31:07Z")

</div>

When we try to run elasticsearch v7.17.0 or v7.17.12, we are facing an error to start the container. It fails with "2023-08-29T12:34:54.499254418+05:30 stderr F chroot: cannot change root directory to '/': Operation not …

---

## [Help me: Unable to parse response body for Bulk Request posted](https://discuss.elastic.co/t/help-me-unable-to-parse-response-body-for-bulk-request-posted/342793)

<div class="topic-metadata">

**Author:** [@adibas](https://discuss.elastic.co/u/adibas)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:09pm UTC](https://discuss.elastic.co/t/help-me-unable-to-parse-response-body-for-bulk-request-posted/342793 "2023-09-12T13:09:33Z")

</div>

Error Details: java.io.IOException: Unable to parse response body for Response{requestLine=POST /\_bulk?timeout=1m HTTP/1.1, host=eu-west-1.es.amazonaws.com, response=HTTP/1.1 200 OK} Tried to investigate and I see the …

---

## [Elasticsearch using bundled JDK instead of the one at JAVA\_HOME](https://discuss.elastic.co/t/elasticsearch-using-bundled-jdk-instead-of-the-one-at-java-home/342797)

<div class="topic-metadata">

**Author:** [@martha889](https://discuss.elastic.co/u/martha889)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:06pm UTC](https://discuss.elastic.co/t/elasticsearch-using-bundled-jdk-instead-of-the-one-at-java-home/342797 "2023-09-12T13:06:30Z")

</div>

Seeing this error while trying to run elasticsearch on redhat docker container. Any idea why elasticserach is not using the JDK present in JAVA\_HOME or how to fix this error? root@5196a84b088b:/var/lib/avi/logs# JAVA\_HO…

---

## [Rolling restart triggers primary-replica resync leading to write unavailability](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301)

<div class="topic-metadata">

**Author:** [@devoxel](https://discuss.elastic.co/u/devoxel)\
**Replies:** 10\
**Last updated:** [September 12, 2023, 10:54am UTC](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301 "2023-09-12T10:54:13Z")

</div>

When a node is shutdown during a normal rolling restart, we end up in a loss of write availability for a period of 10 mins. We're using ECK operator to manage the cluster. It's 7.17 and the operator is the latest versio…

---

## [Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\]](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442)

<div class="topic-metadata">

**Author:** [@Andi0r](https://discuss.elastic.co/u/Andi0r)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 9:35am UTC](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442 "2023-09-12T09:35:06Z")

</div>

Hi, i am trying to install Elastic Search but i am getting the error: Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\] Could it be that y…

---

## [Is Is watcher is free in elastic search? if paid than what is the cost?](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 9:05am UTC](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785 "2023-09-12T09:05:03Z")

</div>

Is watcher is free in Elasticsearch? if paid than what is the cost?

---

## [I need to use search\_after sort by \_score and \_id in a rescore query](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789 "2023-09-12T08:20:03Z")

</div>

I want to implement the search\_after pagination technique, I want to sort out the data using \_score and \_id. The problem I am facing is that I have built my query using rescore and you can't use the sort and rescore at t…

---

## [Generating term vectors on the fly](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784)

<div class="topic-metadata">

**Author:** [@d\_u](https://discuss.elastic.co/u/d_u)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 6:47am UTC](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784 "2023-09-12T06:47:54Z")

</div>

Suppose, I have more than 1mil documents where I have a text field lets say "Contents". We have not enabled termvector for the index. Now when we want to find count of occurrence of a word lets say "data" in "Contents" …

---

## [Change text mapping from text to integer](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 3:21am UTC](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484 "2023-09-12T03:21:08Z")

</div>

Good day! Im creating new index, when I add this to "data views", it was tagged as TEXT type. I need it to be integer. do you have step by step guide for this case? my temporary solution is this command -\> emit (Intege…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=201)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=203)
