# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=207

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 208

---

## [How to import iLO logs (Active health log, event log & Integrated Management log) to Elastic?](https://discuss.elastic.co/t/how-to-import-ilo-logs-active-health-log-event-log-integrated-management-log-to-elastic/342121)

<div class="topic-metadata">

**Author:** [@the4amfriend](https://discuss.elastic.co/u/the4amfriend)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 11:42am UTC](https://discuss.elastic.co/t/how-to-import-ilo-logs-active-health-log-event-log-integrated-management-log-to-elastic/342121 "2023-09-01T11:42:17Z")

</div>

Say I have an Elastic stack setup, is there a better way to export the logs other than using SNMP or syslog? For using SNMP, I couldn't get the MIBs and for syslog, the formats are usually crazy so worried I may not be …

---

## [Elastic.Apm.NetCoreAll with Serilog](https://discuss.elastic.co/t/elastic-apm-netcoreall-with-serilog/341991)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 10:01am UTC](https://discuss.elastic.co/t/elastic-apm-netcoreall-with-serilog/341991 "2023-09-01T10:01:06Z")

</div>

Good afternoon, I have services in .net6 and in this moment I'm using the next nugets: Elastic.Apm.NetCoreAll (1.20.0) Elastic.Apm.SerilogEnricher(1.5.3) I would like upgrade the packages but when I use the version 1…

---

## [Elasticsearch 2.2.4, issue with reindexing](https://discuss.elastic.co/t/elasticsearch-2-2-4-issue-with-reindexing/342089)

<div class="topic-metadata">

**Author:** [@Oeoeoey](https://discuss.elastic.co/u/Oeoeoey)\
**Replies:** 1\
**Last updated:** [September 1, 2023, 3:11am UTC](https://discuss.elastic.co/t/elasticsearch-2-2-4-issue-with-reindexing/342089 "2023-09-01T03:11:06Z")

</div>

I'm very new to elasticsearch and I just started working on some very old legacy code and the component I'm working on randomly stopped being able to reindex the indexes a couple of weeks ago. It used to be able to do a…

---

## [Is it possible to restore a single backing index for a data stream](https://discuss.elastic.co/t/is-it-possible-to-restore-a-single-backing-index-for-a-data-stream/341761)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 6\
**Last updated:** [August 31, 2023, 10:05pm UTC](https://discuss.elastic.co/t/is-it-possible-to-restore-a-single-backing-index-for-a-data-stream/341761 "2023-08-31T22:05:41Z")

</div>

we somehow lost both the a shard and its replica for the head of our datastream . I forced a rollover to get the datastream to accepting data again and removed the empty index (using api). I now want to restore that b…

---

## [Curator advancing ILM phase due to disk usage](https://discuss.elastic.co/t/curator-advancing-ilm-phase-due-to-disk-usage/342070)

<div class="topic-metadata">

**Author:** [@Pete\_Nelson](https://discuss.elastic.co/u/Pete_Nelson)\
**Replies:** 2\
**Last updated:** [August 31, 2023, 7:11pm UTC](https://discuss.elastic.co/t/curator-advancing-ilm-phase-due-to-disk-usage/342070 "2023-08-31T19:11:47Z")

</div>

This is a feature request for Curator. I know that Elastic's official stance is that clusters should be sized for retention time requirements, and I know the answer to exhausting disk space is to enable automatic scalin…

---

## [Reindex from AWS Opensearch to Elasticsearch 7.17](https://discuss.elastic.co/t/reindex-from-aws-opensearch-to-elasticsearch-7-17/342067)

<div class="topic-metadata">

**Author:** [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 4:00pm UTC](https://discuss.elastic.co/t/reindex-from-aws-opensearch-to-elasticsearch-7-17/342067 "2023-08-31T16:00:55Z")

</div>

I'm trying to reindex from AWS OPensearch to Elasticsearch 7.17 but I get the following error. { "error" : { "root\_cause" : \[ { "type" : "status\_exception", "reason" : "body={\\"error\\":{\\"roo…

---

## [Inconsistent behaviour of search\_after when used along with Point in time Id for large data sets](https://discuss.elastic.co/t/inconsistent-behaviour-of-search-after-when-used-along-with-point-in-time-id-for-large-data-sets/342074)

<div class="topic-metadata">

**Author:** [@Pravin\_Mourya](https://discuss.elastic.co/u/Pravin_Mourya)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 3:59pm UTC](https://discuss.elastic.co/t/inconsistent-behaviour-of-search-after-when-used-along-with-point-in-time-id-for-large-data-sets/342074 "2023-08-31T15:59:48Z")

</div>

Hello, We have a requirement in our project to extract all the data from the Elasticsearch index and dump it into a relational DB. The volume of data in the index is quite high around 100 million. Also there are process…

---

## [How to use Machine Learning to track thousands of different error codes?](https://discuss.elastic.co/t/how-to-use-machine-learning-to-track-thousands-of-different-error-codes/342065)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 3:10pm UTC](https://discuss.elastic.co/t/how-to-use-machine-learning-to-track-thousands-of-different-error-codes/342065 "2023-08-31T15:10:58Z")

</div>

Hi all. I'm working with around 1,500 different types of error codes. I'd like to use ML to know when any of them individually goes way up. That's too many for Multi-Metric to handle. Could anyone advise how to work …

---

## [Elasticsearch Reindexing error during upgrade in upgrade assistant](https://discuss.elastic.co/t/elasticsearch-reindexing-error-during-upgrade-in-upgrade-assistant/342044)

<div class="topic-metadata">

**Author:** [@agent47](https://discuss.elastic.co/u/agent47)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 12:04pm UTC](https://discuss.elastic.co/t/elasticsearch-reindexing-error-during-upgrade-in-upgrade-assistant/342044 "2023-08-31T12:04:11Z")

</div>

I am currently trying to upgrade my elasticsearch stack from 7.17.7 to 8.9 but I run in the error in the upgrade assistant while trying to fix the deprecation issues, I get the following error {"error":{"root\_cause":\[{"…

---

## [Run arbitrary code at ingest that is too big for Painless script](https://discuss.elastic.co/t/run-arbitrary-code-at-ingest-that-is-too-big-for-painless-script/342032)

<div class="topic-metadata">

**Author:** [@jrihds](https://discuss.elastic.co/u/jrihds)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 10:08am UTC](https://discuss.elastic.co/t/run-arbitrary-code-at-ingest-that-is-too-big-for-painless-script/342032 "2023-08-31T10:08:16Z")

</div>

Hello, I have a simple algorithm I want to use as part of an ingest pipeline to derive a metric from a string field. For example: "this\_is\_my\_string" and from that we derive a new field for insertion into the index whic…

---

## [How to implement multi tenant environment in Elasticsearch](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 18\
**Last updated:** [August 31, 2023, 4:38am UTC](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606 "2023-08-31T04:38:05Z")

</div>

What is the approach the Elasticsearch community recommends to use in a multi-tenant environment? Is one index Approach good? what are the pros and cons? Thanks, Harshal

---

## [Geoip log file](https://discuss.elastic.co/t/geoip-log-file/341901)

<div class="topic-metadata">

**Author:** [@AndyB](https://discuss.elastic.co/u/AndyB)\
**Replies:** 8\
**Last updated:** [August 31, 2023, 2:10am UTC](https://discuss.elastic.co/t/geoip-log-file/341901 "2023-08-31T02:10:50Z")

</div>

I would like to see if the geoip database is being downloaded. Getting information from Bard, it tells me that I need to create a file on my server here: /var/log/geoip/geoip.log I have done this but the geoip.log file…

---

## [Indexing buffer settings](https://discuss.elastic.co/t/indexing-buffer-settings/342006)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 1:25am UTC](https://discuss.elastic.co/t/indexing-buffer-settings/342006 "2023-08-31T01:25:47Z")

</div>

Are there any metrics when this buffer (indices.memory.index\_buffer\_size) is filled up? The refresh interval for my index is 5 seconds, but I think that due to the volume + document size, the buffer is filled up earlier …

---

## [Index with different document types](https://discuss.elastic.co/t/index-with-different-document-types/341984)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 1:21am UTC](https://discuss.elastic.co/t/index-with-different-document-types/341984 "2023-08-31T01:21:16Z")

</div>

Hello, Suppose I have in total 3000 mappings (mix of text, date, numerics) for an index and have documents using a subset of those mappings like this: doc1 { field\_1 ... field\_2 ... field\_3 ... } doc2 { field\_…

---

## [Inconsistent definition of size field in ByteStreamOutput.java](https://discuss.elastic.co/t/inconsistent-definition-of-size-field-in-bytestreamoutput-java/341874)

<div class="topic-metadata">

**Author:** [@Paras\_Malik](https://discuss.elastic.co/u/Paras_Malik)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 8:19pm UTC](https://discuss.elastic.co/t/inconsistent-definition-of-size-field-in-bytestreamoutput-java/341874 "2023-08-30T20:19:06Z")

</div>

The definition of Size field in ByteStreamOutput changes from size of store data at the initialisation of BigByteArray to capacity of the BigByteArray at the time of growing the Array. What is the correct definition of …

---

## [Deleting Specific Fields From an Indexe](https://discuss.elastic.co/t/deleting-specific-fields-from-an-indexe/341430)

<div class="topic-metadata">

**Author:** [@Mohsin\_Ashraf](https://discuss.elastic.co/u/Mohsin_Ashraf)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 4:15pm UTC](https://discuss.elastic.co/t/deleting-specific-fields-from-an-indexe/341430 "2023-08-30T16:15:46Z")

</div>

Hi, is there any way to delete specific fields from and index pattern?

---

## [ELSER - use the model outside of a pipeline](https://discuss.elastic.co/t/elser-use-the-model-outside-of-a-pipeline/341912)

<div class="topic-metadata">

**Author:** [@paulmaker](https://discuss.elastic.co/u/paulmaker)\
**Replies:** 3\
**Last updated:** [August 30, 2023, 2:31pm UTC](https://discuss.elastic.co/t/elser-use-the-model-outside-of-a-pipeline/341912 "2023-08-30T14:31:54Z")

</div>

Hi all, We are exploring the new ELSER features and how we integrate this into our application. We have a two stage ingestion approach that adds the text during the second phase. Therefore, using an ingestion pipeline i…

---

## [Elasticsearch search query with filter terms having more than 11 field names not returning proper result for 12th fieldname](https://discuss.elastic.co/t/elasticsearch-search-query-with-filter-terms-having-more-than-11-field-names-not-returning-proper-result-for-12th-fieldname/341828)

<div class="topic-metadata">

**Author:** [@ramanm](https://discuss.elastic.co/u/ramanm)\
**Replies:** 5\
**Last updated:** [August 30, 2023, 12:20pm UTC](https://discuss.elastic.co/t/elasticsearch-search-query-with-filter-terms-having-more-than-11-field-names-not-returning-proper-result-for-12th-fieldname/341828 "2023-08-30T12:20:12Z")

</div>

Elasticsearch search query with filter terms having more than 11 field names not returning proper result for 12th fieldname { "size":0, "aggs":{ "filtered\_data":{ "filter…

---

## [Large events don't reach elasticsearch](https://discuss.elastic.co/t/large-events-dont-reach-elasticsearch/341878)

<div class="topic-metadata">

**Author:** [@elade89](https://discuss.elastic.co/u/elade89)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 10:26am UTC](https://discuss.elastic.co/t/large-events-dont-reach-elasticsearch/341878 "2023-08-30T10:26:24Z")

</div>

Hello, We're using Filebeat -\> Kafka -\> Logstash -\> Elasticsearch (Kibana). for error messages we use multiline grouping from Filebeat - which obviously creates large events (around 50 lines, ~5000 characters). I can …

---

## [High Memory usage after migrating from Transport Client to Rest Client](https://discuss.elastic.co/t/high-memory-usage-after-migrating-from-transport-client-to-rest-client/341963)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 9:31am UTC](https://discuss.elastic.co/t/high-memory-usage-after-migrating-from-transport-client-to-rest-client/341963 "2023-08-30T09:31:09Z")

</div>

Hello, After migrating from Transport Client to Rest Client we discoverd some nodes in the Elasticsearch cluster had high memory usage and these nodes was not responding to cat/nodes request. I'm running Eclipse memory…

---

## [Elastic Stack Commercial License variants](https://discuss.elastic.co/t/elastic-stack-commercial-license-variants/340523)

<div class="topic-metadata">

**Author:** [@Mikele](https://discuss.elastic.co/u/Mikele)\
**Replies:** 4\
**Last updated:** [August 30, 2023, 10:23am UTC](https://discuss.elastic.co/t/elastic-stack-commercial-license-variants/340523 "2023-08-30T10:23:50Z")

</div>

Hi. I would like to receive information about the use of Elasticsearch, Kibana, Filebeat and APM (in versions above 8) for commercial purposes. In which version of the license it is possible to provide customers with a…

---

## [Change output for agent policies disabled in](https://discuss.elastic.co/t/change-output-for-agent-policies-disabled-in/341958)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 10:13am UTC](https://discuss.elastic.co/t/change-output-for-agent-policies-disabled-in/341958 "2023-08-30T10:13:06Z")

</div>

We are running 8.x fleet server and i am trying to change my output for agents based on different agent policies ( They correlate to different Data Centers ) The output does not allow me to change anything but default, …

---

## [Two words to act as one string in search](https://discuss.elastic.co/t/two-words-to-act-as-one-string-in-search/341954)

<div class="topic-metadata">

**Author:** [@vlovkis](https://discuss.elastic.co/u/vlovkis)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 8:31am UTC](https://discuss.elastic.co/t/two-words-to-act-as-one-string-in-search/341954 "2023-08-30T08:31:08Z")

</div>

Hello dear Elastic fellas, I'm new to Elasticsearch and already have some questions to which I don't know the answers fully. So question is what setting or filter I could use in order to make my search query act as one s…

---

## [Watcher Alert based on Status down for tomcat and not trigger based on time interval](https://discuss.elastic.co/t/watcher-alert-based-on-status-down-for-tomcat-and-not-trigger-based-on-time-interval/341944)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 7:16am UTC](https://discuss.elastic.co/t/watcher-alert-based-on-status-down-for-tomcat-and-not-trigger-based-on-time-interval/341944 "2023-08-30T07:16:03Z")

</div>

Hello All, I have a requirement where in watcher should trigger on the basis of status down and not based on time interval settings. Below is my working watcher script that triggers every 15 min or 8hrs accordingly se…

---

## [Elasticsearch node down after run kibana in same host ubuntu](https://discuss.elastic.co/t/elasticsearch-node-down-after-run-kibana-in-same-host-ubuntu/341767)

<div class="topic-metadata">

**Author:** [@phu\_phat](https://discuss.elastic.co/u/phu_phat)\
**Replies:** 4\
**Last updated:** [August 30, 2023, 6:25am UTC](https://discuss.elastic.co/t/elasticsearch-node-down-after-run-kibana-in-same-host-ubuntu/341767 "2023-08-30T06:25:57Z")

</div>

After upgrade elasticsearch and kibana from 6.x to 8.9 when start kibana my elasticsearch node in that host down but if i change config kibana to not connect with elasticsearch cluster, elasticsearch can run normally \[…

---

## [Elasticsearch java API client trackTotalHits](https://discuss.elastic.co/t/elasticsearch-java-api-client-tracktotalhits/341935)

<div class="topic-metadata">

**Author:** [@hld942614](https://discuss.elastic.co/u/hld942614)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 5:46am UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-tracktotalhits/341935 "2023-08-30T05:46:06Z")

</div>

I am trying to search my data and expect to get all data，but I can't get more than 10000 result，so I try to use trackTotalHits ，can someone tell me how to use it? try { ElasticsearchClient client = elasticsearchConfi…

---

## [Using ECK, Elastic search does not start up after enabling SAML](https://discuss.elastic.co/t/using-eck-elastic-search-does-not-start-up-after-enabling-saml/341864)

<div class="topic-metadata">

**Author:** [@johanw](https://discuss.elastic.co/u/johanw)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 3:17am UTC](https://discuss.elastic.co/t/using-eck-elastic-search-does-not-start-up-after-enabling-saml/341864 "2023-08-30T03:17:03Z")

</div>

We are trying to enable SAML on our ELK stack on Kubernetes. We are using ECK and custom resource definitions to manage and run our Elastic cluster. Instructions followed: Set up SAML with Azure Active Directory | Elast…

---

## [Building a Basic Query That Orders Results](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906)

<div class="topic-metadata">

**Author:** [@kocakserdar](https://discuss.elastic.co/u/kocakserdar)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 3:37pm UTC](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906 "2023-08-29T15:37:50Z")

</div>

Hello, As a newbie, I'm trying to build a compound query for my NodeJS/Express web app. All I need is to give priority to phrases first in the search results if they exist... For example let's search for "customers are"…

---

## [\[Elasticsearch Client .Net\] need help Create Index mapping Nested field type](https://discuss.elastic.co/t/elasticsearch-client-net-need-help-create-index-mapping-nested-field-type/341786)

<div class="topic-metadata">

**Author:** [@Steven\_Vo](https://discuss.elastic.co/u/Steven_Vo)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-client-net-need-help-create-index-mapping-nested-field-type/341786 "2023-08-29T15:10:13Z")

</div>

public class EsProductEto { public Guid Id { get; set; } ..... public List\<EsAttributeEto\> Items { get; set; } } ----- public class EsAttributeEto { public Guid Id { get; set; …

---

## [Semantic search with search correlation between fields](https://discuss.elastic.co/t/semantic-search-with-search-correlation-between-fields/341564)

<div class="topic-metadata">

**Author:** [@sivagurlinka](https://discuss.elastic.co/u/sivagurlinka)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 2:49pm UTC](https://discuss.elastic.co/t/semantic-search-with-search-correlation-between-fields/341564 "2023-08-29T14:49:14Z")

</div>

Can semantic search with correlation between fields can be implemented with Elasticsearch ? I have ecommerce data indexed to Elasticsearch with below fields and description is vector text embedded. Name : product name(…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=206)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=208)
