# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=205

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 206

---

## [Not all fields are indexed](https://discuss.elastic.co/t/not-all-fields-are-indexed/342369)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 5:34am UTC](https://discuss.elastic.co/t/not-all-fields-are-indexed/342369 "2023-09-06T05:34:19Z")

</div>

I indexed several raw json documents using BulkRequest index BinaryData from json string. If I run a match all query, I am getting back all my documents. However only certain fields are searchable. Why aren't all field…

---

## [Block java.exe outbound in firewall](https://discuss.elastic.co/t/block-java-exe-outbound-in-firewall/342374)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:55pm UTC](https://discuss.elastic.co/t/block-java-exe-outbound-in-firewall/342374 "2023-09-05T19:55:19Z")

</div>

Hi. I have an Elastic cluster with 4 nodes, all on Windows Server. We are using Windows Defender Firewall to limit access to ports 9200 and 9300 between the nodes. We have now been asked if we can limit the OpenJDK java.…

---

## [ElasticSearch TASKS API - Task is given to a different client node after 1 minute of execution](https://discuss.elastic.co/t/elasticsearch-tasks-api-task-is-given-to-a-different-client-node-after-1-minute-of-execution/340801)

<div class="topic-metadata">

**Author:** [@es2learn](https://discuss.elastic.co/u/es2learn)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:41pm UTC](https://discuss.elastic.co/t/elasticsearch-tasks-api-task-is-given-to-a-different-client-node-after-1-minute-of-execution/340801 "2023-09-05T19:41:43Z")

</div>

Hi Team, I had a weird observation in our Elasticsearch Cluster. We have an ES Query that will be executed from a python script. When the Query is being fired from python, right away a task will get created under GET /…

---

## [Cisco filebeat module not listening on port as configured](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 18\
**Last updated:** [September 5, 2023, 7:26pm UTC](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988 "2023-09-05T19:26:40Z")

</div>

We have an existing functional Elastic instance running with Filebeat 8.9, running on Ubuntu 22.04. We're attempting to add Cisco logs using the Cisco filebeat module. However, we're not seeing any logs coming in. We hav…

---

## [Difficulty Making a REST API Call to ElasticSearch](https://discuss.elastic.co/t/difficulty-making-a-rest-api-call-to-elasticsearch/342296)

<div class="topic-metadata">

**Author:** [@Conrad414](https://discuss.elastic.co/u/Conrad414)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 6:51pm UTC](https://discuss.elastic.co/t/difficulty-making-a-rest-api-call-to-elasticsearch/342296 "2023-09-05T18:51:14Z")

</div>

Hello, I'm currently trying to follow the steps for installing Elasticsearch with Docker Install Elasticsearch with Docker | Elasticsearch Guide \[8.11\] | Elastic and I'm struggling with making a REST API call to Elastics…

---

## [Stored fields and SearchResponse](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 7\
**Last updated:** [September 5, 2023, 7:00pm UTC](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062 "2023-09-05T19:00:34Z")

</div>

Example: SearchResponse\<ObjectNode\> searchResponse = elasticsearchClient.search(searchRequest, ObjectNode.class); Hit\<ObjectNode\> hit = searchResponse.hits().hits().get(0); Map\<String, JsonData\> fields = hit.fields(); J…

---

## [Can't set a replication factor for some hidden indices](https://discuss.elastic.co/t/cant-set-a-replication-factor-for-some-hidden-indices/341839)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 4\
**Last updated:** [September 5, 2023, 6:26pm UTC](https://discuss.elastic.co/t/cant-set-a-replication-factor-for-some-hidden-indices/341839 "2023-09-05T18:26:52Z")

</div>

Hi, I can't seem to change a replication factor for some hidden indices: i.e. curl -X PUT "x.x.x.x:9200/.\*/\_settings" -H 'Content-Type: application/json' -d'{ "index" : { "number\_of\_replicas" : 2 } }' {"acknowledged":…

---

## [I don't understand why my bill is more than the cents per hour stated on the dashboard](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079)

<div class="topic-metadata">

**Author:** [@tonyfam](https://discuss.elastic.co/u/tonyfam)\
**Replies:** 5\
**Last updated:** [September 5, 2023, 6:05pm UTC](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079 "2023-09-05T18:05:29Z")

</div>

Hello, can someone please help me understand our bill? Budget crunch. On the dashboard, it says our one deployment is supposed to cost .0957 cents per hour. We have 2 x 45 GB. Enterprise search and Kibana is suppose…

---

## [Doubts about any field of wildcard](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365)

<div class="topic-metadata">

**Author:** [@caixukun](https://discuss.elastic.co/u/caixukun)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:21pm UTC](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365 "2023-09-05T17:21:34Z")

</div>

hello everyone I currently have a problem. I want to search exactly for field a and match the search for field b. this is my code GET /\_search { "query": { "bool": { "must": \[ { "multi\_match": { "q…

---

## [Extract specific log set from others indexed togheter](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262)

<div class="topic-metadata">

**Author:** [@necromancer](https://discuss.elastic.co/u/necromancer)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262 "2023-09-05T16:33:44Z")

</div>

I want to know ihow can I extract/separate my nginx logs from an index where they are saved along with systemd logs and others (cron, fail2ban, etc)? I have it indexed with the ident "nginx". My point with it is be abl…

---

## [Sort results by inner hits (min/max)](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359)

<div class="topic-metadata">

**Author:** [@LeoAdamek](https://discuss.elastic.co/u/LeoAdamek)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 4:11pm UTC](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359 "2023-09-05T16:11:18Z")

</div>

I'm using a join field and an has\_child filter in my search to join products with their various configuration permutations. There's a single level join from a product to a configuration. When a user searches for somethi…

---

## [Import trained model to ElastichSearch](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197 "2023-09-05T15:43:23Z")

</div>

hello everyone. I have a question about importing my model to Elasticsearch. When i imported the model for task text embedding and started deployment mode on Kibana web, i got an error message " Couldn't start trained …

---

## [Is rrf available in the free, self-hosted version of elastic search?](https://discuss.elastic.co/t/is-rrf-available-in-the-free-self-hosted-version-of-elastic-search/342354)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 3:39pm UTC](https://discuss.elastic.co/t/is-rrf-available-in-the-free-self-hosted-version-of-elastic-search/342354 "2023-09-05T15:39:40Z")

</div>

I am using Elasticsearch as self-hosted in docker container, 8.9.1. When I query with the parameter rrf Reciprocal rank fusion, I get this message elasticsearch.AuthorizationException: AuthorizationException(403, 'secur…

---

## [Query cache is getting cleared under heavy query load](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704)

<div class="topic-metadata">

**Author:** [@mahesh44](https://discuss.elastic.co/u/mahesh44)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:38pm UTC](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704 "2023-09-05T14:38:15Z")

</div>

We are seeing exact same issue mentioned in the below post after upgrading to ES 7.17.8. This issue still exists even in the ES 8.8.0. Can someone please help with the solution for this. ES 7.17 | Exponentially growing …

---

## [Filtered alias not working](https://discuss.elastic.co/t/filtered-alias-not-working/342139)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:01pm UTC](https://discuss.elastic.co/t/filtered-alias-not-working/342139 "2023-09-05T14:01:27Z")

</div>

Hi , I'm trying to create an alias filtered based on existing field but it seems not working Does anyone have any idea about this issue? POST /\_aliases { "actions" : \[ { "add" : { "index" : "myIndex", "alias" : …

---

## [How to filtering the data in api level while offloading in eastic search](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 2:00pm UTC](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315 "2023-09-05T14:00:39Z")

</div>

How to filtering the data in api level while offloading the data in eastic search ? Can any one help me here plz?

---

## [Elasticsearch Index is exist or not](https://discuss.elastic.co/t/elasticsearch-index-is-exist-or-not/342224)

<div class="topic-metadata">

**Author:** [@hld942614](https://discuss.elastic.co/u/hld942614)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elasticsearch-index-is-exist-or-not/342224 "2023-09-05T13:28:23Z")

</div>

How can I know if an index is exist or not? I am using co.elastic.clients 8.6.2 in Java below is my code String index = "test"+ date; try { ElasticsearchClient client = elasticsearchConfig.getClient(); SearchR…

---

## [Where the KNN index is stored?](https://discuss.elastic.co/t/where-the-knn-index-is-stored/342157)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 1:18pm UTC](https://discuss.elastic.co/t/where-the-knn-index-is-stored/342157 "2023-09-05T13:18:04Z")

</div>

Where is the KNN index stored, in RAM or disk memory ? I came across that I used to use ChromaDB to store vectors, I had about 1 million vectors and it stores them all in RAM, it took about 24gb. That's too much, and I'…

---

## [Offload apic analytics to elastic search, while offloading exclude one of the api](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 12:38pm UTC](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339 "2023-09-05T12:38:53Z")

</div>

we implemented the Elasticsearch and kibana, and we are able to see analytics data and all for all APIs which are running . But now i want to exclude ( remove) one api analytics from the index . How can we achieve this t…

---

## [Query latency spike when a node joins the cluster](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213)

<div class="topic-metadata">

**Author:** [@marinko](https://discuss.elastic.co/u/marinko)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 10:30am UTC](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213 "2023-09-05T10:30:11Z")

</div>

Hi, We have Elasticsearch 8.6.0 with ltr plugin running on AWS EC2. Each time a new instance (data node) joins the cluster, we see a short (\< 1 min) spike in latency. The maximum latency can rise to 4-5 seconds. This h…

---

## [Does synonym\_graph work on Percolator Query?](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331)

<div class="topic-metadata">

**Author:** [@jspark9812](https://discuss.elastic.co/u/jspark9812)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:16am UTC](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331 "2023-09-05T10:16:15Z")

</div>

Hello. There was a question from the percolator query, so I wrote it like this. The link below is a description of token-graphs. The description states that the positionLength of synonym\_graph is ignored in index time. …

---

## [logstash can no longer write to elasticsearch](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260)

<div class="topic-metadata">

**Author:** [@TaF](https://discuss.elastic.co/u/TaF)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 9:51am UTC](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260 "2023-09-05T09:51:40Z")

</div>

Hello, I'm new to this platform and I need your help for my ELK stack Indeed logstash has not been able to write to elasticsearch for a while below is my logstash/conf.d flow management configuration \< input { tcp …

---

## [Aggregate filter plugin - aggregation exception](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 8:15am UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314 "2023-09-05T08:15:44Z")

</div>

Hello, Logstash version: 7.17 Aggregate filter plugin: v2.10.0 I have the following input of logs: {"@timestamp": "2023-07-27T08:40:27.849Z", "message": "Activity Stream update entry for job", "host": "tower-host", "…

---

## [Bulk inserts more documents than given](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 6:30am UTC](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280 "2023-09-05T06:30:29Z")

</div>

Elasticsearched configured in single-node mode, I have ~1 million elements, but after bulk insert operation I see 10 million elements. I use this python code: def generate\_docs(data): for item in data: doc =…

---

## [Bulk API hangs forever python cloud function](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221)

<div class="topic-metadata">

**Author:** [@Thani\_Ath\_Nain\_Khurs](https://discuss.elastic.co/u/Thani_Ath_Nain_Khurs)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 6:25am UTC](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221 "2023-09-05T06:25:50Z")

</div>

I am new to Elasticsearch and this issue is driving me crazy. My use case involves getting all documents in elastic-search, min-max normalising some fields and then updating documents in bulk but my bulk call just hangs …

---

## [Elastic.Clients.Elasticsearch .NET client - calling Vector tile search API](https://discuss.elastic.co/t/elastic-clients-elasticsearch-net-client-calling-vector-tile-search-api/341422)

<div class="topic-metadata">

**Author:** [@Jarrod](https://discuss.elastic.co/u/Jarrod)\
**Replies:** 5\
**Last updated:** [September 5, 2023, 5:10am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-net-client-calling-vector-tile-search-api/341422 "2023-09-05T05:10:55Z")

</div>

I am trying to call the Vector tile search API using the new v8 .NET client but receiving an exception. Specifically 8.9.2 as of writing. I understand it doesn't have official support in the client, but it appears I sho…

---

## [What does it mean a shard executing a search locally?](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:31am UTC](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298 "2023-09-05T04:31:17Z")

</div>

Hi Folks, I need some help understanding Query phase of distributed search in ES better, step 2 specifically. Node 3 forwards the search request to a primary or replica copy of every shard in the index. Each shard ex…

---

## [Looking for developers for a UX Research study!](https://discuss.elastic.co/t/looking-for-developers-for-a-ux-research-study/342272)

<div class="topic-metadata">

**Author:** [@Gabriel\_Hughes](https://discuss.elastic.co/u/Gabriel_Hughes)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 8:24pm UTC](https://discuss.elastic.co/t/looking-for-developers-for-a-ux-research-study/342272 "2023-09-04T20:24:36Z")

</div>

Hi all, The Search product team at Elastic is looking for developers with experience building applications using Elasticsearch to participate in a study on the application development experience with Elastic. Our goal i…

---

## [Multi-node cluster across multiple virtual machines](https://discuss.elastic.co/t/multi-node-cluster-across-multiple-virtual-machines/341951)

<div class="topic-metadata">

**Author:** [@Cody](https://discuss.elastic.co/u/Cody)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 7:53am UTC](https://discuss.elastic.co/t/multi-node-cluster-across-multiple-virtual-machines/341951 "2023-08-30T07:53:09Z")

</div>

Hello, i am trying to run a 3 node cluster for Elasticsearch and kibana across 3 Virtual machines, each VM running 1 node each. I refer to the documentation " Start a multi-node cluster with Docker Compose" at https://ww…

---

## [Intermittent exception in index call](https://discuss.elastic.co/t/intermittent-exception-in-index-call/340903)

<div class="topic-metadata">

**Author:** [@Luiz\_Basile](https://discuss.elastic.co/u/Luiz_Basile)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 4:06pm UTC](https://discuss.elastic.co/t/intermittent-exception-in-index-call/340903 "2023-09-04T16:06:00Z")

</div>

We are using Elasticsearch java, in a lambda function. The below log is in lambda Apparently this exception is happening when you use the Elastic of other component and quickly trigger the lambda function. Any suggestio…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=204)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=206)
