# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=206

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 207

---

## [Cleaning up of indexes](https://discuss.elastic.co/t/cleaning-up-of-indexes/340885)

<div class="topic-metadata">

**Author:** [@vishnu\_ishpujani](https://discuss.elastic.co/u/vishnu_ishpujani)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 3:32pm UTC](https://discuss.elastic.co/t/cleaning-up-of-indexes/340885 "2023-09-04T15:32:57Z")

</div>

Hi , I need to cleanup indexes data from Elastic cluster, what is the best way to perform the task as deleting from Dev tools is taking too much time and affecting cluster as well?

---

## [java.lang.IllegalArgumentException: Mapping file \_settings.json does not exist for elasticsearch version 8](https://discuss.elastic.co/t/java-lang-illegalargumentexception-mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8/340910)

<div class="topic-metadata">

**Author:** [@prashant\_chaturvedi](https://discuss.elastic.co/u/prashant_chaturvedi)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 11:41am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-mapping-file-settings-json-does-not-exist-for-elasticsearch-version-8/340910 "2023-08-16T11:41:01Z")

</div>

i have installed elasticsearch(8.9.0) and fscrawler (2.10) which shows that its been tested in document but still the fscrawaler is throwing the below error "java.lang.IllegalArgumentException: Mapping file \_settings.js…

---

## [Observing index of an Elastic node with Metricbeat not possible?](https://discuss.elastic.co/t/observing-index-of-an-elastic-node-with-metricbeat-not-possible/335791)

<div class="topic-metadata">

**Author:** [@Zaphod](https://discuss.elastic.co/u/Zaphod)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 12:35pm UTC](https://discuss.elastic.co/t/observing-index-of-an-elastic-node-with-metricbeat-not-possible/335791 "2023-09-04T12:35:34Z")

</div>

I would like to monitor an existing Elasticsearch node (ES A) (in Docker container) to control the performance concerning a distinct index, because the CPU of the node increases to 200%-500% intermittently for a few hour…

---

## [How to make map clustering through elastic search more flexible?](https://discuss.elastic.co/t/how-to-make-map-clustering-through-elastic-search-more-flexible/342266)

<div class="topic-metadata">

**Author:** [@Vladislav\_Kochurko](https://discuss.elastic.co/u/Vladislav_Kochurko)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 12:29pm UTC](https://discuss.elastic.co/t/how-to-make-map-clustering-through-elastic-search-more-flexible/342266 "2023-09-04T12:29:36Z")

</div>

I am developing an interactive map and my technology stack includes NodeJS, Angular, MapBox, and Elasticsearch. My application is a complex data aggregator, and I am trying to cluster my data on the map using Elasticsear…

---

## [Which index holds the fleet Healthy/Unhealthy status?](https://discuss.elastic.co/t/which-index-holds-the-fleet-healthy-unhealthy-status/341810)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 3\
**Last updated:** [September 4, 2023, 11:32am UTC](https://discuss.elastic.co/t/which-index-holds-the-fleet-healthy-unhealthy-status/341810 "2023-09-04T11:32:41Z")

</div>

Hi Guys, I need to fetch the data from elasticsearch indices using \_search API and need to know which indices hold the data for fleet and agent status? And how do I run the query using curl to get the Host name and IP …

---

## [Same index pattern but different index template](https://discuss.elastic.co/t/same-index-pattern-but-different-index-template/342018)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 5\
**Last updated:** [September 4, 2023, 11:24am UTC](https://discuss.elastic.co/t/same-index-pattern-but-different-index-template/342018 "2023-09-04T11:24:33Z")

</div>

Good day! I just have a question regarding on Index Template is it possible to create a different index template but same index pattern? What I am going to do is to create a index template but same name on the index p…

---

## [Help, make a selection by the field of the object](https://discuss.elastic.co/t/help-make-a-selection-by-the-field-of-the-object/342245)

<div class="topic-metadata">

**Author:** [@sitnik.ilya.93](https://discuss.elastic.co/u/sitnik.ilya.93)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 10:27am UTC](https://discuss.elastic.co/t/help-make-a-selection-by-the-field-of-the-object/342245 "2023-09-04T10:27:24Z")

</div>

you need to make a selection only by file type, the object was saved simply as Object.class try to choose by, searchResponse = osClient.search(new SearchRequest(eventIndex) .scroll(scroll) …

---

## [How it's posiible for query cache to be bigger than total heap?](https://discuss.elastic.co/t/how-its-posiible-for-query-cache-to-be-bigger-than-total-heap/342234)

<div class="topic-metadata">

**Author:** [@lifer](https://discuss.elastic.co/u/lifer)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-its-posiible-for-query-cache-to-be-bigger-than-total-heap/342234 "2023-09-04T09:57:38Z")

</div>

Hello! Our setup: ES 8.8.2, 6 nodes, self-hosted on AWS. I've noticed something strange in our kibana "stack monitoring" metrics for one of data nodes: query cache goes up to 14 GB: but total heap is set to 8GB: …

---

## [Index Lifecycle Policy does not work](https://discuss.elastic.co/t/index-lifecycle-policy-does-not-work/342231)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 9:52am UTC](https://discuss.elastic.co/t/index-lifecycle-policy-does-not-work/342231 "2023-09-04T09:52:52Z")

</div>

Hi, I am not sure if I understand the Index Lifecycle policy correctly Currently my index's size is over 20GB I have set the rollover to trigger as soon as the shard is greater than 15GB And move the index to de…

---

## [Getting error while trying to create knn index on elasticsearch version 8.7.1](https://discuss.elastic.co/t/getting-error-while-trying-to-create-knn-index-on-elasticsearch-version-8-7-1/342101)

<div class="topic-metadata">

**Author:** [@Sharad\_Nautiyal](https://discuss.elastic.co/u/Sharad_Nautiyal)\
**Replies:** 4\
**Last updated:** [September 4, 2023, 9:27am UTC](https://discuss.elastic.co/t/getting-error-while-trying-to-create-knn-index-on-elasticsearch-version-8-7-1/342101 "2023-09-04T09:27:08Z")

</div>

Below is the request I am sending while creating knn index: PUT posting { "settings": { "index": { "number\_of\_shards" :20, "number\_of\_replicas": 1, "knn":{ "algo\_param":{ "ef\_se…

---

## [Watcher email reports, getting resend while restarting elasticsearch](https://discuss.elastic.co/t/watcher-email-reports-getting-resend-while-restarting-elasticsearch/342230)

<div class="topic-metadata">

**Author:** [@forabraham1](https://discuss.elastic.co/u/forabraham1)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 8:59am UTC](https://discuss.elastic.co/t/watcher-email-reports-getting-resend-while-restarting-elasticsearch/342230 "2023-09-04T08:59:20Z")

</div>

Hi, Email alerts (reports as pdf of a dashboard) setup to trigger once per day early morning which are working fine. But during the day time if the elasticsearch is getting restarted, email reports alerts being resend. …

---

## [Error log curl: (52) Empty reply from server in v8.8.2](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-8-2/338981)

<div class="topic-metadata">

**Author:** [@Ridwan\_Satrio\_Hadiku](https://discuss.elastic.co/u/Ridwan_Satrio_Hadiku)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 8:39am UTC](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-8-2/338981 "2023-09-04T08:39:45Z")

</div>

Hello, can anyone help me? I found error log curl: (52) Empty reply from server when entering command curl -X GET Even though when referring to the problem of: I have followed the instructions and still get the sa…

---

## [Exact KNN queries not cached](https://discuss.elastic.co/t/exact-knn-queries-not-cached/342225)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 7:28am UTC](https://discuss.elastic.co/t/exact-knn-queries-not-cached/342225 "2023-09-04T07:28:34Z")

</div>

Hi Folks, I have a cluster with vectors indexed in a knn index and I'd like to find exact K-nearest neighbors for a given vector using score\_script. There are about 500K documents in total. I'm using the following quer…

---

## [DSL : Format avg result](https://discuss.elastic.co/t/dsl-format-avg-result/341692)

<div class="topic-metadata">

**Author:** [@RickT](https://discuss.elastic.co/u/RickT)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 7:53am UTC](https://discuss.elastic.co/t/dsl-format-avg-result/341692 "2023-09-04T07:53:51Z")

</div>

Hi, I'm using a DSL script to extract some datas. I use an aggregation with an average method. It's ok, but the end result does not suit me :confused: Indeed, the result format is like this 5133.076923076923 and I wou…

---

## [Elasticsearch resource calculation](https://discuss.elastic.co/t/elasticsearch-resource-calculation/341887)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Can\_Duran](https://discuss.elastic.co/u/Ibrahim_Can_Duran)\
**Replies:** 5\
**Last updated:** [September 4, 2023, 7:40am UTC](https://discuss.elastic.co/t/elasticsearch-resource-calculation/341887 "2023-09-04T07:40:02Z")

</div>

I am trying to calculate the Resource requirements for an ELK system which will be deployed on k8s. The total load will be 4 TB and i will use 1 replica. Is it possible to have equations for required number of shard and…

---

## [Allocation Failed](https://discuss.elastic.co/t/allocation-failed/342167)

<div class="topic-metadata">

**Author:** [@njain213](https://discuss.elastic.co/u/njain213)\
**Replies:** 4\
**Last updated:** [September 4, 2023, 6:09am UTC](https://discuss.elastic.co/t/allocation-failed/342167 "2023-09-04T06:09:30Z")

</div>

Hello Team, One of my index is showing below error. I have created new shard where new data is going now but how to assign old index back to node. "unassigned\_info" : { "reason" : "ALLOCATION\_FAILED", "at" : "2023-09…

---

## [Filebeat setup for cakephp logs](https://discuss.elastic.co/t/filebeat-setup-for-cakephp-logs/339620)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 35\
**Last updated:** [September 4, 2023, 6:00am UTC](https://discuss.elastic.co/t/filebeat-setup-for-cakephp-logs/339620 "2023-09-04T06:00:58Z")

</div>

Hi, Can anyone advice how to configure the filebeat and logstash for cakephp logs. I need to configure filebeat for following cakephp logs, cake.log error.log Is do I need to enable any module in filebeat? Please c…

---

## ["node is locked into cluster" message](https://discuss.elastic.co/t/node-is-locked-into-cluster-message/342200)

<div class="topic-metadata">

**Author:** [@lifer](https://discuss.elastic.co/u/lifer)\
**Replies:** 1\
**Last updated:** [September 3, 2023, 6:41pm UTC](https://discuss.elastic.co/t/node-is-locked-into-cluster-message/342200 "2023-09-03T18:41:38Z")

</div>

Hi! We have a 6 nodes ES cluster, self-hosted on AWS. There are three dedicated master nodes, and three data nodes. Please help me to understand this message: \[2023-09-03T08:32:18,239\]\[WARN \]\[o.e.c.c.ClusterBootstrapS…

---

## [Elasticsearch remote cluster reindexing wildcard](https://discuss.elastic.co/t/elasticsearch-remote-cluster-reindexing-wildcard/342168)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [September 3, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elasticsearch-remote-cluster-reindexing-wildcard/342168 "2023-09-03T16:08:57Z")

</div>

Hi there, I am trying to use -e reindex.remote.whitelist="\*" in my docker run command to allow all domains in whitelist. But I am getting the following error when I try to run this:- Exception in thread "main" org.el…

---

## [What is the maximum dimensionality of a vector field?](https://discuss.elastic.co/t/what-is-the-maximum-dimensionality-of-a-vector-field/342159)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 1\
**Last updated:** [September 3, 2023, 3:16pm UTC](https://discuss.elastic.co/t/what-is-the-maximum-dimensionality-of-a-vector-field/342159 "2023-09-03T15:16:40Z")

</div>

What is the maximum dimensionality of a vector field ? I am using elastik version 8.9.1 The documentation says that the maximum vector size is 1000, but if you set the index: False property, the dimensionality can be u…

---

## [Elastic snapshot to azure blob not deleting data](https://discuss.elastic.co/t/elastic-snapshot-to-azure-blob-not-deleting-data/341103)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 8\
**Last updated:** [September 3, 2023, 2:53pm UTC](https://discuss.elastic.co/t/elastic-snapshot-to-azure-blob-not-deleting-data/341103 "2023-09-03T14:53:24Z")

</div>

I am running elastic 7.16.3 and snapshotting index's to azure blob storage for backup. The snapshot process is working, and after a couple of months we will go through and delete the snapshots. I have recently looked in …

---

## [Rust equivalent to simple requests.get for ES version 8?](https://discuss.elastic.co/t/rust-equivalent-to-simple-requests-get-for-es-version-8/342180)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [September 3, 2023, 8:48am UTC](https://discuss.elastic.co/t/rust-equivalent-to-simple-requests-get-for-es-version-8/342180 "2023-09-03T08:48:27Z")

</div>

I found the leap to version 8 big enough in Python, not least because I know nothing about authentication, certificates, proxies, etc.. I'm now trying to get the simplest possible response from a local server running ver…

---

## [Null\_pointer\_exception when trying to access any object type of field using ctx.\_source](https://discuss.elastic.co/t/null-pointer-exception-when-trying-to-access-any-object-type-of-field-using-ctx-source/342166)

<div class="topic-metadata">

**Author:** [@ankitpandoh](https://discuss.elastic.co/u/ankitpandoh)\
**Replies:** 3\
**Last updated:** [September 3, 2023, 3:59am UTC](https://discuss.elastic.co/t/null-pointer-exception-when-trying-to-access-any-object-type-of-field-using-ctx-source/342166 "2023-09-03T03:59:34Z")

</div>

I have a index mapping like below PUT /customer-index { "mappings":{ "properties":{ "customers.id": { "type": "long" }, "customers.name": { "type": "text", "norms": fals…

---

## [Checksum failed (hardware problem?)](https://discuss.elastic.co/t/checksum-failed-hardware-problem/341061)

<div class="topic-metadata">

**Author:** [@bigjohns97](https://discuss.elastic.co/u/bigjohns97)\
**Replies:** 6\
**Last updated:** [September 2, 2023, 2:07pm UTC](https://discuss.elastic.co/t/checksum-failed-hardware-problem/341061 "2023-09-02T14:07:09Z")

</div>

I am using a simple one node Elasticsearch instance on a Debian VM running on top of a Hyper-V Windows 11 system with an AMD 3950 CPU DDR4 RAM and SSD disk. Using elasticsearch as a index for a graylog instance and sendi…

---

## [How to get the complete pdf report of a kibana dashboard instead of snapshot pdf?](https://discuss.elastic.co/t/how-to-get-the-complete-pdf-report-of-a-kibana-dashboard-instead-of-snapshot-pdf/341023)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 3\
**Last updated:** [September 1, 2023, 11:21pm UTC](https://discuss.elastic.co/t/how-to-get-the-complete-pdf-report-of-a-kibana-dashboard-instead-of-snapshot-pdf/341023 "2023-09-01T23:21:22Z")

</div>

I have a bunch of kibana dashboards which gives very relevant data. My ELK stack is having a valid platinum license and when I generate a pdf report using the share button in dashboard section it gives me a snapshot and …

---

## [Sort documents based on matched inner nested objects](https://discuss.elastic.co/t/sort-documents-based-on-matched-inner-nested-objects/342150)

<div class="topic-metadata">

**Author:** [@akarsh\_cholaveti](https://discuss.elastic.co/u/akarsh_cholaveti)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 10:54pm UTC](https://discuss.elastic.co/t/sort-documents-based-on-matched-inner-nested-objects/342150 "2023-09-01T22:54:59Z")

</div>

Hello, I am working on a sort query for my documents in the index. Here are the documents look like: { "studentId": "123", "studentName": "Frodo", "year": "2023", "Scores": \[{ "subject": "Ph…

---

## [Why will writing to force merged indices make performance "much worse"?!](https://discuss.elastic.co/t/why-will-writing-to-force-merged-indices-make-performance-much-worse/342152)

<div class="topic-metadata">

**Author:** [@neo-anderson](https://discuss.elastic.co/u/neo-anderson)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 9:18pm UTC](https://discuss.elastic.co/t/why-will-writing-to-force-merged-indices-make-performance-much-worse/342152 "2023-09-01T21:18:49Z")

</div>

I have been following the changes to the documentation regarding force merge warning. I understand that force merging to an index that's actively being written to is a bad idea. However, if I use force merge to bring dow…

---

## [Metricbeat x509 Certificate error](https://discuss.elastic.co/t/metricbeat-x509-certificate-error/342072)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 4\
**Last updated:** [September 1, 2023, 7:52pm UTC](https://discuss.elastic.co/t/metricbeat-x509-certificate-error/342072 "2023-09-01T19:52:33Z")

</div>

I've got an Elasticsearch instance running nicely, and I'd like to use metricbeat to monitor system performance (running on the same host). I'm getting an x509 certificate error when I start metricbeat using metricbeat …

---

## [How are double-quotes put into a bulk string (for POSTing)?](https://discuss.elastic.co/t/how-are-double-quotes-put-into-a-bulk-string-for-posting/342064)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 5:27pm UTC](https://discuss.elastic.co/t/how-are-double-quotes-put-into-a-bulk-string-for-posting/342064 "2023-09-01T17:27:29Z")

</div>

I'm trying to populate an index with bulk data. In fact this data is being generated by a Rust crate, docx-rs, and this escapes double-quotes by putting a backslash in front of them. So, where one field of my (Lucene) d…

---

## [Agg query that retturns bucket ranges so that buckets have the same number of documents?](https://discuss.elastic.co/t/agg-query-that-retturns-bucket-ranges-so-that-buckets-have-the-same-number-of-documents/342005)

<div class="topic-metadata">

**Author:** [@ankh](https://discuss.elastic.co/u/ankh)\
**Replies:** 3\
**Last updated:** [September 1, 2023, 4:00pm UTC](https://discuss.elastic.co/t/agg-query-that-retturns-bucket-ranges-so-that-buckets-have-the-same-number-of-documents/342005 "2023-09-01T16:00:00Z")

</div>

In order to process a large number of documents from an index I have a number of instances of an app running in parallel, each processing a subset of the documents. Each subset is defined by a particular date range. The …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=205)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=207)
