# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=203

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 204

---

## [File /run/elastic-agent.sock no such file and directory when i finished installing the agent on linux](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775)

<div class="topic-metadata">

**Author:** [@Yanuar\_Ahmad\_Adhari](https://discuss.elastic.co/u/Yanuar_Ahmad_Adhari)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 3:15am UTC](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775 "2023-09-12T03:15:48Z")

</div>

Error: failed to communicate with Elastic Agent daemon: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial unix /run/elastic-agent.sock: connect: no such file or directory"…

---

## [Grok patterns for nginx](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 3:24am UTC](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692 "2023-09-11T03:24:40Z")

</div>

Today I have text log format about nginx\_access {"timestamp": "2023-09-07T03:03:33+00:00", "remote\_addr": "10.0.x.x", "remote\_user": "-", "request\_time": "0.002 s", "status\_request": "200", "request\_Size": "510", "requ…

---

## [GET api by doc\_id returns different result whenever i try](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293)

<div class="topic-metadata">

**Author:** [@ycice](https://discuss.elastic.co/u/ycice)\
**Replies:** 7\
**Last updated:** [September 12, 2023, 1:53am UTC](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293 "2023-09-12T01:53:49Z")

</div>

Hi, i manage more than 100 ES clusters in my company for 3 years But at last week, I faced very strange issue. I think it is not possible... Could you carefully check this? ES version : 6.8.2 Cluster health : Green G…

---

## [Failed to authenticate user 'elastic' against https://192.168.xx.xx:9200/\_security/\_authenticate?pretty](https://discuss.elastic.co/t/failed-to-authenticate-user-elastic-against-https-192-168-xx-xx-9200-security-authenticate-pretty/342654)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 3\
**Last updated:** [September 11, 2023, 2:00pm UTC](https://discuss.elastic.co/t/failed-to-authenticate-user-elastic-against-https-192-168-xx-xx-9200-security-authenticate-pretty/342654 "2023-09-11T14:00:33Z")

</div>

Hi fellows, your help is needed. I have installed elasticsearch for the first time on my Alma-Linux9. That worked so far elastisearch runs on port 9200 tcp6 0 0 :::9200 :::\* …

---

## [Bootstrap.password for first installation with scripting](https://discuss.elastic.co/t/bootstrap-password-for-first-installation-with-scripting/342611)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 5\
**Last updated:** [September 11, 2023, 1:32pm UTC](https://discuss.elastic.co/t/bootstrap-password-for-first-installation-with-scripting/342611 "2023-09-11T13:32:19Z")

</div>

Hi everybody, I need test for a script to change passwords of the built-in users. I test on a single-node cluster. I understand that i have to stop service on the node create bootstrap.password printf "tititi" …

---

## [Determining number of clients to achieve target-throughput](https://discuss.elastic.co/t/determining-number-of-clients-to-achieve-target-throughput/342634)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 2\
**Last updated:** [September 11, 2023, 12:50pm UTC](https://discuss.elastic.co/t/determining-number-of-clients-to-achieve-target-throughput/342634 "2023-09-11T12:50:16Z")

</div>

Continuing the discussion from The number of clients in search operation: Hi Folks, I found this thread on relationship between number of clients and target throughput. @dliappis Can you help me understand how did yo…

---

## [Transform script via Create Watcher API](https://discuss.elastic.co/t/transform-script-via-create-watcher-api/342608)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 12:07pm UTC](https://discuss.elastic.co/t/transform-script-via-create-watcher-api/342608 "2023-09-11T12:07:39Z")

</div>

Hi! I'm trying to put new watcher via Create Watcher API curl -X PUT "localhost:9200/\_watcher/watch/my-watch?pretty" -H 'Content-Type: application/json' -d' { ... "actions" { "problem": { "transform": { …

---

## [The primary shard is unassigned](https://discuss.elastic.co/t/the-primary-shard-is-unassigned/342710)

<div class="topic-metadata">

**Author:** [@zytine](https://discuss.elastic.co/u/zytine)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 11:59am UTC](https://discuss.elastic.co/t/the-primary-shard-is-unassigned/342710 "2023-09-11T11:59:32Z")

</div>

Hello, My es cluster health status turned to be red because of two unsigined shards.One of them is the primary shard and I got the following error when I executed "/ cluster/allocation/explain",the other is the replicat…

---

## [Elasticsearch system indices](https://discuss.elastic.co/t/elasticsearch-system-indices/342737)

<div class="topic-metadata">

**Author:** [@Swapnadeep\_Mondal](https://discuss.elastic.co/u/Swapnadeep_Mondal)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 11:45am UTC](https://discuss.elastic.co/t/elasticsearch-system-indices/342737 "2023-09-11T11:45:11Z")

</div>

Hi team, we are using self self-managed Elasticsearch cluster. And we are using self-monitoring monitoring. So Elasticsearch creates monitoring logs named ".monitoring-es-7-" automatically and these indices are not ass…

---

## [Hi, I am trying to deploy the Elser (built-in) model, and all the configurations seems to be fine. But the deployment has started and it takes forever to complete the deployment](https://discuss.elastic.co/t/hi-i-am-trying-to-deploy-the-elser-built-in-model-and-all-the-configurations-seems-to-be-fine-but-the-deployment-has-started-and-it-takes-forever-to-complete-the-deployment/342350)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 9\
**Last updated:** [September 11, 2023, 9:16am UTC](https://discuss.elastic.co/t/hi-i-am-trying-to-deploy-the-elser-built-in-model-and-all-the-configurations-seems-to-be-fine-but-the-deployment-has-started-and-it-takes-forever-to-complete-the-deployment/342350 "2023-09-11T09:16:43Z")

</div>

In my case I have run the deployment at 11:27AM EST on 30th of August , but till 11:30 AM EST 31st of August, it still seems to be running. Also, tried increasing the RAM and space for Elastic search and also for the M…

---

## [How to get matched documents from ElasticSearch for a nested array fields matching specified values](https://discuss.elastic.co/t/how-to-get-matched-documents-from-elasticsearch-for-a-nested-array-fields-matching-specified-values/342724)

<div class="topic-metadata">

**Author:** [@Nid](https://discuss.elastic.co/u/Nid)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 9:12am UTC](https://discuss.elastic.co/t/how-to-get-matched-documents-from-elasticsearch-for-a-nested-array-fields-matching-specified-values/342724 "2023-09-11T09:12:04Z")

</div>

I am using elasticsearch-8.7.0. . I am a beginner, stuck on one thing. Please help. I have defined a mapping as below: mappings = { "properties": { "change\_id": {"type": "text", "analyzer": "english"}, "changes": { …

---

## [CompressingStoredFieldsReader instances take up a lot of memory](https://discuss.elastic.co/t/compressingstoredfieldsreader-instances-take-up-a-lot-of-memory/342717)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 8:17am UTC](https://discuss.elastic.co/t/compressingstoredfieldsreader-instances-take-up-a-lot-of-memory/342717 "2023-09-11T08:17:16Z")

</div>

Hello folks Our clients encountered errors below recently when performing index and query requests: TransportError(429, u'circuit\_breaking\_exception', {u'status': 429, u'error': {u'bytes\_wanted': 32385970160, u'durabil…

---

## [Merge two indexes to one](https://discuss.elastic.co/t/merge-two-indexes-to-one/342585)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 4\
**Last updated:** [September 11, 2023, 6:57am UTC](https://discuss.elastic.co/t/merge-two-indexes-to-one/342585 "2023-09-11T06:57:45Z")

</div>

Hi i would like to merge two indexes to one index, with same fields except for one field. i tried the reindex api but it is not working with regular expressions in the indexname. my index has timestamp attached to it. s…

---

## [Combining two fields from tow different documents within the same index based on conditions](https://discuss.elastic.co/t/combining-two-fields-from-tow-different-documents-within-the-same-index-based-on-conditions/342708)

<div class="topic-metadata">

**Author:** [@DivyaDileep](https://discuss.elastic.co/u/DivyaDileep)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 6:12am UTC](https://discuss.elastic.co/t/combining-two-fields-from-tow-different-documents-within-the-same-index-based-on-conditions/342708 "2023-09-11T06:12:56Z")

</div>

I am having data as below in one of the index @timestamp instance\_name dskIndex dskPercent dskPath Sep 8, 2023 @ 21:45:27.332 ssc-b 3 - …

---

## [Generate monthly report from elastic index](https://discuss.elastic.co/t/generate-monthly-report-from-elastic-index/342691)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 2:56am UTC](https://discuss.elastic.co/t/generate-monthly-report-from-elastic-index/342691 "2023-09-11T02:56:54Z")

</div>

Hi, I want to generate a monthly report from my elastic index Currently, I have an index which contains time series data from July to now(Sep) after September, I want to generate the summary report of July, Aug And Se…

---

## [How to Insert 50Million documents per 30sec in elasticsearch cluster?](https://discuss.elastic.co/t/how-to-insert-50million-documents-per-30sec-in-elasticsearch-cluster/342669)

<div class="topic-metadata">

**Author:** [@coldcoder8502](https://discuss.elastic.co/u/coldcoder8502)\
**Replies:** 6\
**Last updated:** [September 10, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-to-insert-50million-documents-per-30sec-in-elasticsearch-cluster/342669 "2023-09-10T15:52:11Z")

</div>

Hi all, Iam facing difficulty to insert 50million documents per 30 sec from source to Elasticsearch cluster. I have 7 sources so total = 350million documents per 30 sec. I have one machine with 500GB Ram, 500Tb storage …

---

## [Elasitc search date issue](https://discuss.elastic.co/t/elasitc-search-date-issue/342682)

<div class="topic-metadata">

**Author:** [@varun\_bisht](https://discuss.elastic.co/u/varun_bisht)\
**Replies:** 0\
**Last updated:** [September 10, 2023, 1:26pm UTC](https://discuss.elastic.co/t/elasitc-search-date-issue/342682 "2023-09-10T13:26:48Z")

</div>

Hi i am using this curl to create mapping - curl --cacert http\_ca.crt -u elastic:$ELASTIC\_PASSWORD -X PUT "https://DNS:9200/elasticdate-6?pretty=" -H 'content-type: application/json' -H 'user-agent: -lContent-Type: app…

---

## [Best way to write from Apache Spark to ECK](https://discuss.elastic.co/t/best-way-to-write-from-apache-spark-to-eck/342480)

<div class="topic-metadata">

**Author:** [@krezno](https://discuss.elastic.co/u/krezno)\
**Replies:** 2\
**Last updated:** [September 9, 2023, 9:26pm UTC](https://discuss.elastic.co/t/best-way-to-write-from-apache-spark-to-eck/342480 "2023-09-09T21:26:04Z")

</div>

Hello I have a lot of batch processes that write large batches of data to elastic in scheduled intervals. Currently we are writing to elastic using the es-hadoop library. From what I understand when writing to an ECK in…

---

## [Endpoint \_cat/indices doesn't work when "license expired"?](https://discuss.elastic.co/t/endpoint-cat-indices-doesnt-work-when-license-expired/342644)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 4\
**Last updated:** [September 9, 2023, 3:42pm UTC](https://discuss.elastic.co/t/endpoint-cat-indices-doesnt-work-when-license-expired/342644 "2023-09-09T15:42:32Z")

</div>

One day, no countdown, I was told after adding data to my ES server through kibana that I can't view indices. What do I have to do just to use the \_cat/indices endpoint? This is an incredible mess I'm in because of this…

---

## [Estimating max. search throughput that can be achieved from a cluster](https://discuss.elastic.co/t/estimating-max-search-throughput-that-can-be-achieved-from-a-cluster/342661)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 0\
**Last updated:** [September 9, 2023, 3:25pm UTC](https://discuss.elastic.co/t/estimating-max-search-throughput-that-can-be-achieved-from-a-cluster/342661 "2023-09-09T15:25:55Z")

</div>

Hello Folks, I'm trying to compute the max. search throughput I can achieve from a given cluster. Following is my cluster settings 27 data nodes(Mem:384GB and 48 vCPUs) each having 17 shards with 0 replica attached t…

---

## [BadRequestError(400, 'search\_phase\_execution\_exception', 'runtime error') when trying to do l2 similarity search](https://discuss.elastic.co/t/badrequesterror-400-search-phase-execution-exception-runtime-error-when-trying-to-do-l2-similarity-search/342649)

<div class="topic-metadata">

**Author:** [@longlegs](https://discuss.elastic.co/u/longlegs)\
**Replies:** 0\
**Last updated:** [September 9, 2023, 8:25am UTC](https://discuss.elastic.co/t/badrequesterror-400-search-phase-execution-exception-runtime-error-when-trying-to-do-l2-similarity-search/342649 "2023-09-09T08:25:15Z")

</div>

Hello, Im trying to implement a vector similarity search for face recognition using Elasticsearch in python. This is my mapping for creating an index: mapping = { "mappings": { "properties": { "…

---

## [Filebeat filtering incoming syslogs?](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 5\
**Last updated:** [September 8, 2023, 7:16pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458 "2023-09-08T19:16:01Z")

</div>

I'm setting up Filebeat (8.9) on an Elasticsearch (8.9) instance, and it looks like Filebeat is filtering logs from external hosts. Here's the relevant section from my Filebeat config: - type: syslog format: auto p…

---

## [EsHadoopIllegalArgumentException: Cannot detect ES version](https://discuss.elastic.co/t/eshadoopillegalargumentexception-cannot-detect-es-version/342593)

<div class="topic-metadata">

**Author:** [@Piyush\_Jain](https://discuss.elastic.co/u/Piyush_Jain)\
**Replies:** 1\
**Last updated:** [September 8, 2023, 1:33pm UTC](https://discuss.elastic.co/t/eshadoopillegalargumentexception-cannot-detect-es-version/342593 "2023-09-08T13:33:00Z")

</div>

I'm getting error "EsHadoopIllegalArgumentException: Cannot detect ES version-typically this happens if the network/Elasticsearch cluster is not accessible or when targeting a WAN/Cloud instance without the proper setti…

---

## [S3 Intelligent-Tiering class with Deep Archive Access tier for snapshots is working?](https://discuss.elastic.co/t/s3-intelligent-tiering-class-with-deep-archive-access-tier-for-snapshots-is-working/342122)

<div class="topic-metadata">

**Author:** [@mihai1](https://discuss.elastic.co/u/mihai1)\
**Replies:** 6\
**Last updated:** [September 8, 2023, 12:41pm UTC](https://discuss.elastic.co/t/s3-intelligent-tiering-class-with-deep-archive-access-tier-for-snapshots-is-working/342122 "2023-09-08T12:41:56Z")

</div>

We're currently utilizing Elasticsearch version 8.8.1 and storing our daily snapshots in S3 using the 'Intelligent\_Tiering' storage class. In an effort to optimize costs, based on AWS's documentation on Intelligent Tieri…

---

## [Connecting to Tableau: Tableau could not generate a query to perform this operation](https://discuss.elastic.co/t/connecting-to-tableau-tableau-could-not-generate-a-query-to-perform-this-operation/342517)

<div class="topic-metadata">

**Author:** [@Krikkits](https://discuss.elastic.co/u/Krikkits)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 10:17am UTC](https://discuss.elastic.co/t/connecting-to-tableau-tableau-could-not-generate-a-query-to-perform-this-operation/342517 "2023-09-08T10:17:06Z")

</div>

I have Elasticsearch 7.17.3 and the latest Tableau Desktop (trial version). I followed the documentation (v. 7.17.3 connectors as well) on how to connect them and it works. However, even though the tables are shown withi…

---

## [The principle of sorting queries](https://discuss.elastic.co/t/the-principle-of-sorting-queries/342508)

<div class="topic-metadata">

**Author:** [@Ceilzcx](https://discuss.elastic.co/u/Ceilzcx)\
**Replies:** 6\
**Last updated:** [September 8, 2023, 9:27am UTC](https://discuss.elastic.co/t/the-principle-of-sorting-queries/342508 "2023-09-08T09:27:03Z")

</div>

I simulated some discrete queries using esrally，and found something that confused me. the first picture is not use sort, and the second use sort. search qps is same. 【99.9th percentile service time】not use sort is smal…

---

## [ELK index being deleted for a certain period without index lifecycle](https://discuss.elastic.co/t/elk-index-being-deleted-for-a-certain-period-without-index-lifecycle/342189)

<div class="topic-metadata">

**Author:** [@Juan\_Paulo\_Serrano1](https://discuss.elastic.co/u/Juan_Paulo_Serrano1)\
**Replies:** 8\
**Last updated:** [September 8, 2023, 8:38am UTC](https://discuss.elastic.co/t/elk-index-being-deleted-for-a-certain-period-without-index-lifecycle/342189 "2023-09-08T08:38:18Z")

</div>

Hi, I'm having an issue where certain index is being deleted after 28 days, I already removed the lifecycle policy which has 60 days delete phase and it is still being deleted after 28 days. Does anyone has experience on…

---

## [Esrally queries guesses of bottlenecks during pressure measurements](https://discuss.elastic.co/t/esrally-queries-guesses-of-bottlenecks-during-pressure-measurements/342584)

<div class="topic-metadata">

**Author:** [@Ceilzcx](https://discuss.elastic.co/u/Ceilzcx)\
**Replies:** 2\
**Last updated:** [September 8, 2023, 8:07am UTC](https://discuss.elastic.co/t/esrally-queries-guesses-of-bottlenecks-during-pressure-measurements/342584 "2023-09-08T08:07:26Z")

</div>

I use esrally. when i setting throughout to 100 or 200, the Median Throughput are about 100 or 200. but i setting throughout parm more, the mediam throughput still about 240. when i watch the monitor, the load less than …

---

## [Can synonym analyzer or Fuzzy queries return the token that it got matched to from document?](https://discuss.elastic.co/t/can-synonym-analyzer-or-fuzzy-queries-return-the-token-that-it-got-matched-to-from-document/342575)

<div class="topic-metadata">

**Author:** [@aashini](https://discuss.elastic.co/u/aashini)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 6:22am UTC](https://discuss.elastic.co/t/can-synonym-analyzer-or-fuzzy-queries-return-the-token-that-it-got-matched-to-from-document/342575 "2023-09-08T06:22:38Z")

</div>

I am using search-time synonyms in my Index. I am also using fuzzy queries to correct the spelling mistakes of user input in making search. For example, My Index has a field named Trade which can have value "Plumbing". …

---

## [Outputing Logstash logs to Elastic Index fails](https://discuss.elastic.co/t/outputing-logstash-logs-to-elastic-index-fails/341774)

<div class="topic-metadata">

**Author:** [@aashini](https://discuss.elastic.co/u/aashini)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 5:41am UTC](https://discuss.elastic.co/t/outputing-logstash-logs-to-elastic-index-fails/341774 "2023-09-08T05:41:55Z")

</div>

I am using Logstash version 7.11 and and trying to output logs from logstash pipeline to Elastic version 8.\*. I am using hosts, index, api\_key, ssl and action params with ssl =\> true and action =\> "create" . output { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=202)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=204)
