# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=204

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 205

---

## [Has anyone come up with a maintainable way to set index.number\_of\_replicas cluster wide?](https://discuss.elastic.co/t/has-anyone-come-up-with-a-maintainable-way-to-set-index-number-of-replicas-cluster-wide/341288)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 7\
**Last updated:** [September 7, 2023, 11:09pm UTC](https://discuss.elastic.co/t/has-anyone-come-up-with-a-maintainable-way-to-set-index-number-of-replicas-cluster-wide/341288 "2023-09-07T23:09:03Z")

</div>

Thanks to budget issues, I'm trying to slim down the footprint of my Elastic stack. While not ideal, running in single-node mode would make things easier to manage. But, as far as I can tell, Elastic Agent creates ever…

---

## [Disable geo lookup in logstash](https://discuss.elastic.co/t/disable-geo-lookup-in-logstash/342557)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 10:57pm UTC](https://discuss.elastic.co/t/disable-geo-lookup-in-logstash/342557 "2023-09-07T22:57:39Z")

</div>

I am parsing firewall logs and I don't want logstash to try and do geo parsing. My firewall logs already have the geo information. How can I disable geo parsing so I stop getting \_geoip\_lookup\_failure?

---

## [Whats the difference between Tencent Elasticsearch Service and Elastic Cloud?](https://discuss.elastic.co/t/whats-the-difference-between-tencent-elasticsearch-service-and-elastic-cloud/342172)

<div class="topic-metadata">

**Author:** [@heermaas3](https://discuss.elastic.co/u/heermaas3)\
**Replies:** 5\
**Last updated:** [September 7, 2023, 8:20pm UTC](https://discuss.elastic.co/t/whats-the-difference-between-tencent-elasticsearch-service-and-elastic-cloud/342172 "2023-09-07T20:20:43Z")

</div>

I have seen there are 3 different cloud providers for the Elastic Cloud, but I have also seen Elasticsearch is available as a Service on Tencent and Alibaba too, which has nothing to do with the Elastic Cloud, right? Bu…

---

## [Ingest dns queries into elk from dozens of bind9 server](https://discuss.elastic.co/t/ingest-dns-queries-into-elk-from-dozens-of-bind9-server/342546)

<div class="topic-metadata">

**Author:** [@Poubelle\_Dirty](https://discuss.elastic.co/u/Poubelle_Dirty)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 7:20pm UTC](https://discuss.elastic.co/t/ingest-dns-queries-into-elk-from-dozens-of-bind9-server/342546 "2023-09-07T19:20:09Z")

</div>

Hello everyone. I'm looking for the best way (if there is !) for ingesting dns queries from bind9 servers. The environment is composed of about 15 "cluster" of dns servers (1 master and 3 slaves per cluster) that are a…

---

## [How to avoid field\_value\_factor on 'must' clause](https://discuss.elastic.co/t/how-to-avoid-field-value-factor-on-must-clause/342449)

<div class="topic-metadata">

**Author:** [@blinker1](https://discuss.elastic.co/u/blinker1)\
**Replies:** 5\
**Last updated:** [September 7, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-to-avoid-field-value-factor-on-must-clause/342449 "2023-09-07T18:28:26Z")

</div>

Hi, running the ELK stack on the Elastic cloud, I've defined a search template that has the following query: "query": { "function\_score": { "functions": \[ { "field\_value\_factor": { "field":…

---

## [Delete old back indexes from alias](https://discuss.elastic.co/t/delete-old-back-indexes-from-alias/342439)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 11\
**Last updated:** [September 7, 2023, 5:32pm UTC](https://discuss.elastic.co/t/delete-old-back-indexes-from-alias/342439 "2023-09-07T17:32:45Z")

</div>

Hello! I use data streams for store data. And I have data stream alias. How I can automatically delete back indexes older 7 days from alias?

---

## [Cannot reduce number of segments during indexing](https://discuss.elastic.co/t/cannot-reduce-number-of-segments-during-indexing/342199)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 2\
**Last updated:** [September 7, 2023, 4:15pm UTC](https://discuss.elastic.co/t/cannot-reduce-number-of-segments-during-indexing/342199 "2023-09-07T16:15:53Z")

</div>

I have followed the advice in the aKNN tuning guide: But no matter the settings, the indexing process still creates a huge tail of tiny segments. Setup: New dev deployment Zero search traffic 64GB, CPU optimized "in…

---

## [Limited score precision for a big score hierarchy](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759)

<div class="topic-metadata">

**Author:** [@Grisha](https://discuss.elastic.co/u/Grisha)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 3:02pm UTC](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759 "2023-09-07T15:02:20Z")

</div>

Hi, I'm trying to implement a kind of score hierarchy using different boosts for different fields (there are multiple fields and type of search (full match, fuzzy, etc.)). Simplified example of boosts: field\_1 fuzzy b…

---

## [How does cluster.auto\_shrink\_voting\_configuration prevent split brain?](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418)

<div class="topic-metadata">

**Author:** [@etki](https://discuss.elastic.co/u/etki)\
**Replies:** 9\
**Last updated:** [September 7, 2023, 11:31am UTC](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418 "2023-09-07T11:31:15Z")

</div>

We have some docs telling that it's not possible, but they don't explain much, just stating some things. How is the following situation avoided? A cluster has voting configuration of 5 nodes. A network partition occurs…

---

## [Install Elastic Search](https://discuss.elastic.co/t/install-elastic-search/342320)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 11:39am UTC](https://discuss.elastic.co/t/install-elastic-search/342320 "2023-09-07T11:39:54Z")

</div>

Hi Team, I had a requirement to create elasticsearch cluster with three nodes . I had install the elasticsearch binaries on these three nodes individually and updated the elasticsearch.yml file with node information bu…

---

## [Hybrid Search aggregations count mismatch on filters](https://discuss.elastic.co/t/hybrid-search-aggregations-count-mismatch-on-filters/342496)

<div class="topic-metadata">

**Author:** [@Ramgopalbhat10](https://discuss.elastic.co/u/Ramgopalbhat10)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 11:23am UTC](https://discuss.elastic.co/t/hybrid-search-aggregations-count-mismatch-on-filters/342496 "2023-09-07T11:23:27Z")

</div>

I want to use aggregations on the hybrid search (query + knn), which will give me some facets that I can select in the UI and use as filters for subsequent queries. I'm using num\_candidates=100 and k=20. I read in the d…

---

## [Where are memories go?](https://discuss.elastic.co/t/where-are-memories-go/342338)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 3\
**Last updated:** [September 7, 2023, 9:42am UTC](https://discuss.elastic.co/t/where-are-memories-go/342338 "2023-09-07T09:42:44Z")

</div>

Our clients encountered errors below recently when performing index and query requests: org.elasticsearch.client.ResponseException: org.elasticsearch.client.ResponseException: method \[POST\], host \[http://192.168.12.171:…

---

## [Cannot configure grok pipeline to processors in the elastic agent](https://discuss.elastic.co/t/cannot-configure-grok-pipeline-to-processors-in-the-elastic-agent/341933)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 8\
**Last updated:** [September 7, 2023, 6:45am UTC](https://discuss.elastic.co/t/cannot-configure-grok-pipeline-to-processors-in-the-elastic-agent/341933 "2023-09-07T06:45:03Z")

</div>

Hi everyone! I completed and successful configure grok debuger log format of haproxy. And next I was added code grok pattens to pipeline Finally step I have added pipeline to processors in the elastic agent but …

---

## [I want to get the total number of keyword hits for each document in the query results](https://discuss.elastic.co/t/i-want-to-get-the-total-number-of-keyword-hits-for-each-document-in-the-query-results/342490)

<div class="topic-metadata">

**Author:** [@z\_Henry](https://discuss.elastic.co/u/z_Henry)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 2:12am UTC](https://discuss.elastic.co/t/i-want-to-get-the-total-number-of-keyword-hits-for-each-document-in-the-query-results/342490 "2023-09-07T02:12:11Z")

</div>

My field mapping settings are as follows "functionPoint": { "type": "text", "index": true, "analyzer": "ik\_smart", "search\_analyzer": "ik\_smart", "fielddata": true, "fielddata\_frequency\_filter": { "min":…

---

## [Please help me Install Elasticsearch in EC2](https://discuss.elastic.co/t/please-help-me-install-elasticsearch-in-ec2/342487)

<div class="topic-metadata">

**Author:** [@chobo](https://discuss.elastic.co/u/chobo)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:26am UTC](https://discuss.elastic.co/t/please-help-me-install-elasticsearch-in-ec2/342487 "2023-09-07T01:26:51Z")

</div>

Hello I'm installing Elasticsearch in EC2 environment and setting elasticsearch.yml file, but I keep getting the following error fatal exception while booting Elasticsearch org.elasticsearch.transport.BindTransportExce…

---

## [Does the Elasticsearch Ruby gem support both http and https hosts?](https://discuss.elastic.co/t/does-the-elasticsearch-ruby-gem-support-both-http-and-https-hosts/342477)

<div class="topic-metadata">

**Author:** [@ddzz](https://discuss.elastic.co/u/ddzz)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 9:38pm UTC](https://discuss.elastic.co/t/does-the-elasticsearch-ruby-gem-support-both-http-and-https-hosts/342477 "2023-09-06T21:38:57Z")

</div>

I want to transition a cluster of ES nodes from HTTP to HTTPS. When the list of hosts I pass in to the ES client is either all http or https, it works fine. But when it's a mix I run into a variety of errors. Does the ge…

---

## [What is actually causing these shard snapshot failures?](https://discuss.elastic.co/t/what-is-actually-causing-these-shard-snapshot-failures/342203)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 7\
**Last updated:** [September 6, 2023, 9:35pm UTC](https://discuss.elastic.co/t/what-is-actually-causing-these-shard-snapshot-failures/342203 "2023-09-06T21:35:59Z")

</div>

And how do I fix them ; ) I have 7 shards failing with a message of the form: INTERNAL\_SERVER\_ERROR: NoSuchFileException\[/data/elasticsearch/backups/daily/indices/L0OEoJ\_DSqOk8aNpntkxqQ/0/index-MD1wjtsmTBuEPMY\_zenaaQ\] I…

---

## [Detecting specific event sequences in data streams](https://discuss.elastic.co/t/detecting-specific-event-sequences-in-data-streams/342469)

<div class="topic-metadata">

**Author:** [@Kargo](https://discuss.elastic.co/u/Kargo)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 7:40pm UTC](https://discuss.elastic.co/t/detecting-specific-event-sequences-in-data-streams/342469 "2023-09-06T19:40:14Z")

</div>

Hey there. I have a datastream in Elasticsearch with mappings similar to this: { "mappings": { "properties": { "@timestamp": {"type": "date"}, "event-type": {"type": "keyword"}, "session": {"…

---

## [Anomaly Detection buckets over time?](https://discuss.elastic.co/t/anomaly-detection-buckets-over-time/340836)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/anomaly-detection-buckets-over-time/340836 "2023-09-06T17:50:52Z")

</div>

Hi all. I have an Anomaly Job running with hourly buckets. The values rise and fall once per day. It seems to work great in tracking that pattern, and learning about weekends. But I have a newbie question. When ML i…

---

## [Modify sort mechanism of elasticsearch by counting matched elements in array properties](https://discuss.elastic.co/t/modify-sort-mechanism-of-elasticsearch-by-counting-matched-elements-in-array-properties/342466)

<div class="topic-metadata">

**Author:** [@Ben\_Berizovsky](https://discuss.elastic.co/u/Ben_Berizovsky)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 5:22pm UTC](https://discuss.elastic.co/t/modify-sort-mechanism-of-elasticsearch-by-counting-matched-elements-in-array-properties/342466 "2023-09-06T17:22:56Z")

</div>

Hello, I am trying to achieve a "Best Match" strategy for the results in my platform that uses Elasticsearch 7.15. Basically, there are the rules on how it should work: Every property that you match with a query\_strin…

---

## [Rally race crushes right after start](https://discuss.elastic.co/t/rally-race-crushes-right-after-start/342254)

<div class="topic-metadata">

**Author:** [@lokinehn](https://discuss.elastic.co/u/lokinehn)\
**Replies:** 10\
**Last updated:** [September 6, 2023, 4:32pm UTC](https://discuss.elastic.co/t/rally-race-crushes-right-after-start/342254 "2023-09-06T16:32:09Z")

</div>

I want to run a benchmark for my existing 8.9.0 cluster (honestly I've already run tests on that cluster earlier, and everything was great) and i get error right after start. Command i execute: esrally race --track=sql…

---

## [\[DOCUMENTATION\] ElasticSearch and Kibana documentation in .pdf/.epub/.azw format?](https://discuss.elastic.co/t/documentation-elasticsearch-and-kibana-documentation-in-pdf-epub-azw-format/341584)

<div class="topic-metadata">

**Author:** [@CodeTradition](https://discuss.elastic.co/u/CodeTradition)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 4:08pm UTC](https://discuss.elastic.co/t/documentation-elasticsearch-and-kibana-documentation-in-pdf-epub-azw-format/341584 "2023-09-06T16:08:42Z")

</div>

Hello guys, This might be a strange request for you but I was wondering if there was a documentation of Elasticsearch and Kibana in .pdf/.epub/.azw format ? I have been using Elasticsearch and Kibana since approximatel…

---

## [I have different indexes that contain different fields I need to aggregate all of them, what i mean i have index1 and index2 in index1 I have ch and in index2 I have ch2 how can i add ch to ch2 with script or script field](https://discuss.elastic.co/t/i-have-different-indexes-that-contain-different-fields-i-need-to-aggregate-all-of-them-what-i-mean-i-have-index1-and-index2-in-index1-i-have-ch-and-in-index2-i-have-ch2-how-can-i-add-ch-to-ch2-with-script-or-script-field/341959)

<div class="topic-metadata">

**Author:** [@ghramalhajyalhajy](https://discuss.elastic.co/u/ghramalhajyalhajy)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 9:05am UTC](https://discuss.elastic.co/t/i-have-different-indexes-that-contain-different-fields-i-need-to-aggregate-all-of-them-what-i-mean-i-have-index1-and-index2-in-index1-i-have-ch-and-in-index2-i-have-ch2-how-can-i-add-ch-to-ch2-with-script-or-script-field/341959 "2023-08-30T09:05:22Z")

</div>

search index PUT index1/\_doc/1 { "foo": "bar" } GET index2/\_search { "query": { "match": { "foo": "bar" } } }

---

## [Authentication Error setting up Eland on Jupyter Notebook](https://discuss.elastic.co/t/authentication-error-setting-up-eland-on-jupyter-notebook/342404)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 1:06pm UTC](https://discuss.elastic.co/t/authentication-error-setting-up-eland-on-jupyter-notebook/342404 "2023-09-06T13:06:56Z")

</div>

Hi, I am trying to use Eland on Jupyter Notebook. Here is what I wrote on Jupyter import eland as ed import pandas as pd import numpy as np from elasticsearch import Elasticsearch def json(x): import json print…

---

## [PDF document ingestion into elastic](https://discuss.elastic.co/t/pdf-document-ingestion-into-elastic/342443)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 12:44pm UTC](https://discuss.elastic.co/t/pdf-document-ingestion-into-elastic/342443 "2023-09-06T12:44:11Z")

</div>

Hello community How to import word, pdf documents into elastic??

---

## [Node connection to cluster is being refused (AWS ECS)](https://discuss.elastic.co/t/node-connection-to-cluster-is-being-refused-aws-ecs/341989)

<div class="topic-metadata">

**Author:** [@stanyzra](https://discuss.elastic.co/u/stanyzra)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 12:20pm UTC](https://discuss.elastic.co/t/node-connection-to-cluster-is-being-refused-aws-ecs/341989 "2023-09-06T12:20:18Z")

</div>

Hello, I'm trying to deploy a dockerized 3 node Elasticsearch (8.9.1) cluster in AWS ECS. The cluster's bootstraping seens to be okay, but when I try to join a node into it, I get a connection refused error. These are …

---

## [Mapping file \_settings.json does not exist for elasticsearch version 8 in](https://discuss.elastic.co/t/mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8-in/340908)

<div class="topic-metadata">

**Author:** [@prashant\_chaturvedi](https://discuss.elastic.co/u/prashant_chaturvedi)\
**Replies:** 5\
**Last updated:** [September 6, 2023, 12:00pm UTC](https://discuss.elastic.co/t/mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8-in/340908 "2023-09-06T12:00:25Z")

</div>

I have installed elasticsearch search 8.9.0 and fscrawaler 2.10 -SNAPSHOT which in the document page says that this is test but still i get the error java.lang.IllegalArgumentException: Mapping file \_settings.json does …

---

## [Elasticsearch storage on containers](https://discuss.elastic.co/t/elasticsearch-storage-on-containers/340829)

<div class="topic-metadata">

**Author:** [@anderstr1](https://discuss.elastic.co/u/anderstr1)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 11:33am UTC](https://discuss.elastic.co/t/elasticsearch-storage-on-containers/340829 "2023-09-06T11:33:40Z")

</div>

Our goal is to run Elasticsearch on docker containers. Until now we have only managed to run it properly on an Azure Virtual Machine. Our challenge is regarding storage. When using Elasticsearch, I understand that a typ…

---

## [Elasticsearch has accumulated a lot of pending tasks, and stop indexing](https://discuss.elastic.co/t/elasticsearch-has-accumulated-a-lot-of-pending-tasks-and-stop-indexing/341414)

<div class="topic-metadata">

**Author:** [@ShanYang](https://discuss.elastic.co/u/ShanYang)\
**Replies:** 12\
**Last updated:** [September 6, 2023, 9:16am UTC](https://discuss.elastic.co/t/elasticsearch-has-accumulated-a-lot-of-pending-tasks-and-stop-indexing/341414 "2023-09-06T09:16:53Z")

</div>

Phenomenon: When generating a new index across days, elasticsearch stop indexing. The cluster health show green but with many pending task. Used Get \_tasks?, I saw thousands transport task and hundreds direct task. Clu…

---

## [ES server specs for a good search performance](https://discuss.elastic.co/t/es-server-specs-for-a-good-search-performance/342355)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 7:39am UTC](https://discuss.elastic.co/t/es-server-specs-for-a-good-search-performance/342355 "2023-09-06T07:39:43Z")

</div>

So we have a situation where we want to make a mini-search engine for our project - the total volume of the data being 5 PB. We want to create a backup, so the total size to be needed overall is 10 PB, approximately. The…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=203)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=205)
