# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=210

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 211

---

## [Compare 2 indices and find missing documents](https://discuss.elastic.co/t/compare-2-indices-and-find-missing-documents/341434)

<div class="topic-metadata">

**Author:** [@arks1](https://discuss.elastic.co/u/arks1)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 4:57pm UTC](https://discuss.elastic.co/t/compare-2-indices-and-find-missing-documents/341434 "2023-08-24T16:57:29Z")

</div>

I have 2 indices, index\_a and index\_b. The 2 indices have documents with the almost the exact same template. index\_b has some extra fields which was introduced as part of a new feature, but it also has all the fields al…

---

## [Retry on conflict](https://discuss.elastic.co/t/retry-on-conflict/341591)

<div class="topic-metadata">

**Author:** [@Vamsi\_krishna\_Ramaya](https://discuss.elastic.co/u/Vamsi_krishna_Ramaya)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:02pm UTC](https://discuss.elastic.co/t/retry-on-conflict/341591 "2023-08-24T16:02:20Z")

</div>

Hi I am working on a node ja project with elasticsearch so i am trying to create index with out replica even though i added that number\_of\_replicas 0 replica is generating and that gives me problem that document is geti…

---

## [Structured Data set in Elastic](https://discuss.elastic.co/t/structured-data-set-in-elastic/341379)

<div class="topic-metadata">

**Author:** [@ishani.sengupta](https://discuss.elastic.co/u/ishani.sengupta)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:44pm UTC](https://discuss.elastic.co/t/structured-data-set-in-elastic/341379 "2023-08-24T15:44:26Z")

</div>

Working on Analytics using ELK stack, the data being used is a structure data where we are facing issue with migration and correlation. Can elastic stack handle structure data within an index or any other ways to handle…

---

## [What is the proper way on migrating you elastic-stack environment?](https://discuss.elastic.co/t/what-is-the-proper-way-on-migrating-you-elastic-stack-environment/341517)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 3:40pm UTC](https://discuss.elastic.co/t/what-is-the-proper-way-on-migrating-you-elastic-stack-environment/341517 "2023-08-24T15:40:43Z")

</div>

Hello, So I have the Elasticsearch, Kibana, Logstash, Fleet-server, and the Package-registry all running on docker containers. I'm still testing things out, but I wanted to know what the proper way to migrate my docker …

---

## [Index is getting deleted automatically](https://discuss.elastic.co/t/index-is-getting-deleted-automatically/341578)

<div class="topic-metadata">

**Author:** [@HardikSCaypro](https://discuss.elastic.co/u/HardikSCaypro)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 1:58pm UTC](https://discuss.elastic.co/t/index-is-getting-deleted-automatically/341578 "2023-08-24T13:58:40Z")

</div>

Hello Team, We are using Elasticsearch from last few years. However recently we found that few of our indexes were getting deleted automatically, so we searched and found that we should reinstall it in different system. …

---

## [Wildcard search string in Discover](https://discuss.elastic.co/t/wildcard-search-string-in-discover/341575)

<div class="topic-metadata">

**Author:** [@wapevo5067](https://discuss.elastic.co/u/wapevo5067)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 12:30pm UTC](https://discuss.elastic.co/t/wildcard-search-string-in-discover/341575 "2023-08-24T12:30:38Z")

</div>

V 7.17 I am using Discover from Analytics section. I am just using the simple search box. Lets say I have lots of logs which are: "Connection Server\[N\] Started" I can use: "Connection" and "Started" But I wonder if …

---

## [Need to setup API Logging tool for our project](https://discuss.elastic.co/t/need-to-setup-api-logging-tool-for-our-project/341573)

<div class="topic-metadata">

**Author:** [@Uttam\_Jagwani](https://discuss.elastic.co/u/Uttam_Jagwani)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 12:05pm UTC](https://discuss.elastic.co/t/need-to-setup-api-logging-tool-for-our-project/341573 "2023-08-24T12:05:40Z")

</div>

Need to set up an API Logging tool for our project on the prod environment. Would like to know the details on the product stack, cluster setup, hardware & software specifications, storage requirements for logging, and a…

---

## [The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510)

<div class="topic-metadata">

**Author:** [@Erdem\_Sekerci](https://discuss.elastic.co/u/Erdem_Sekerci)\
**Replies:** 7\
**Last updated:** [August 24, 2023, 10:51am UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/341510 "2023-08-24T10:51:22Z")

</div>

Hello. I see that similar issues have been reported before, but I cannot solve my problem using them. I'm using NEST 7.17.5 dotnet core client and with the following configurations. var elasticSettings = new Connectio…

---

## [Terms aggregation on raw field is returning Exception in thread "main" jakarta.json.stream.JsonParsingException: Property name 'doc\_count\_error\_upper\_bound' is not in the 'type#name' format. Make sure the request has 'typed\_keys' set](https://discuss.elastic.co/t/terms-aggregation-on-raw-field-is-returning-exception-in-thread-main-jakarta-json-stream-jsonparsingexception-property-name-doc-count-error-upper-bound-is-not-in-the-type-name-format-make-sure-the-request-has-typed-keys-set/341340)

<div class="topic-metadata">

**Author:** [@hr89](https://discuss.elastic.co/u/hr89)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 10:16am UTC](https://discuss.elastic.co/t/terms-aggregation-on-raw-field-is-returning-exception-in-thread-main-jakarta-json-stream-jsonparsingexception-property-name-doc-count-error-upper-bound-is-not-in-the-type-name-format-make-sure-the-request-has-typed-keys-set/341340 "2023-08-24T10:16:37Z")

</div>

Hi I have a simple index, index1 as below with mappings { "index1": { "mappings": { "properties": { "\_all": { "type": "text", "fields": { …

---

## [Security Privileges - Auto Expand Replicas](https://discuss.elastic.co/t/security-privileges-auto-expand-replicas/341555)

<div class="topic-metadata">

**Author:** [@tneto](https://discuss.elastic.co/u/tneto)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 9:09am UTC](https://discuss.elastic.co/t/security-privileges-auto-expand-replicas/341555 "2023-08-24T09:09:46Z")

</div>

Hello. I'm running ES version 8.1.3 and I'm facing some issues regarding "auto\_expand\_replicas" This is my command on the console over Dev Tools. PUT /.kibana/\_settings { "index" : { "number\_of\_replicas":0, "aut…

---

## [How can I change an existing node with both "master" and "data" roles to be a "master" role only, without any downtime?](https://discuss.elastic.co/t/how-can-i-change-an-existing-node-with-both-master-and-data-roles-to-be-a-master-role-only-without-any-downtime/340526)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 8:53am UTC](https://discuss.elastic.co/t/how-can-i-change-an-existing-node-with-both-master-and-data-roles-to-be-a-master-role-only-without-any-downtime/340526 "2023-08-24T08:53:16Z")

</div>

I have a cluster with multiple nodes. I intend to dynamically change an existing node that currently serves both the "master" and "data" roles to exclusively perform the "data" role, all without causing any downtime. Wha…

---

## [Audit log issue for Elasticsearch 7.15.2 with trail license](https://discuss.elastic.co/t/audit-log-issue-for-elasticsearch-7-15-2-with-trail-license/341551)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 8:30am UTC](https://discuss.elastic.co/t/audit-log-issue-for-elasticsearch-7-15-2-with-trail-license/341551 "2023-08-24T08:30:24Z")

</div>

Hi Team, I am using Elasticsearch 7.15.2 version with trail license on rpm machine(Red HAT). After enabling the audit log in elasticsearch.yml file , I am not getting audit log for the queries which I had executed. I…

---

## [Help for elk stack](https://discuss.elastic.co/t/help-for-elk-stack/341447)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 8:27am UTC](https://discuss.elastic.co/t/help-for-elk-stack/341447 "2023-08-24T08:27:13Z")

</div>

Can I make the datamart from elk stack . and How do I combine 2 index data in elasticsearch do-i-combine-2-index-data-in-elasticsearch/199044 .

---

## [Random function in Painless?](https://discuss.elastic.co/t/random-function-in-painless/70280)

<div class="topic-metadata">

**Author:** [@Dom-nik](https://discuss.elastic.co/u/Dom-nik)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 6:25am UTC](https://discuss.elastic.co/t/random-function-in-painless/70280 "2023-08-24T06:25:09Z")

</div>

Hello, What is the way to genereate a random value in Painless? Being able to draw one value from a set would be particularly great - I want to use it to add a new field to my mock data and I need a possibility to add…

---

## [ElasticSearch Service Startup Issue](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532)

<div class="topic-metadata">

**Author:** [@Jeevagan](https://discuss.elastic.co/u/Jeevagan)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:40am UTC](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532 "2023-08-24T04:40:06Z")

</div>

Hey everyone, I hope you're doing well. I've been working on setting up an Elasticsearch service using a systemd service file, but I'm encountering an issue when trying to start the application. I'm hoping someone here …

---

## [Name or service not known in java RestHighLevelClient](https://discuss.elastic.co/t/name-or-service-not-known-in-java-resthighlevelclient/341415)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:52am UTC](https://discuss.elastic.co/t/name-or-service-not-known-in-java-resthighlevelclient/341415 "2023-08-24T03:52:37Z")

</div>

Hi, everyone. I am using the Elasticsearch High Level REST client to access the service, but I am getting an error Name or service not known. However, I can successfully access the service using curl. Since I upgraded f…

---

## [Elasticsearch Aggregate Search Impact on Performance](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:45am UTC](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740 "2023-08-24T03:45:04Z")

</div>

Is there a leader in ES? For general product comprehensive search and display lists, it is recommended to use direct query or AGG aggregation form, as AGG has little impact on performance

---

## [When the number of documents exceeds 2 billion, the index status becomes RED](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461)

<div class="topic-metadata">

**Author:** [@im.jinxinwang](https://discuss.elastic.co/u/im.jinxinwang)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 3:24am UTC](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461 "2023-08-24T03:24:29Z")

</div>

Version: 7.8.1 Cause of failure: The number of important index documents in the 7.8.1 open source version of ES has reached the limit of 2147483519 in Lucene. The index status is red, and read and write operations canno…

---

## [Connectors-python mysql - selfsigned SSL can not verify](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 12:08am UTC](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512 "2023-08-24T00:08:55Z")

</div>

Hello, when I try to connect to our mysql / mariadb database instance using SSL and providing the CA-cert.pem file of the selfsigned certificate, the connectors-python connector outputs an error that the selfsigned SSL …

---

## [Optimizing ElasticSearch startup time for CI](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516)

<div class="topic-metadata">

**Author:** [@blindsnowmobile](https://discuss.elastic.co/u/blindsnowmobile)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 9:11pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516 "2023-08-23T21:11:20Z")

</div>

We use Elasticsearch in our integration tests, which run many times every day. Running ES in this way has a different set of requirements than in our production environment. We need ES to start as fast as possible with…

---

## [Can Rollover API / ILM be used to keep only x days data in an index at any point of time](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-x-days-data-in-an-index-at-any-point-of-time/341410)

<div class="topic-metadata">

**Author:** [@Aditya1996](https://discuss.elastic.co/u/Aditya1996)\
**Replies:** 14\
**Last updated:** [August 23, 2023, 6:44pm UTC](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-x-days-data-in-an-index-at-any-point-of-time/341410 "2023-08-23T18:44:02Z")

</div>

I have read a few threads regarding this question , Most of them suggest using DeleteBy Query as Rollover API seems to delete/move to other phase the indices and create the new ones based on given condition. I could not…

---

## [Stored fields](https://discuss.elastic.co/t/stored-fields/341503)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 5:02pm UTC](https://discuss.elastic.co/t/stored-fields/341503 "2023-08-23T17:02:30Z")

</div>

Looking for help interacting with stored fields returned from the search. Specifically hit.fields() returns a map of string and JsonData. How do you turn that JsonData into something you can manipulate? Thanks. SearchRe…

---

## [How to serialize/deserialize FieldValue object?](https://discuss.elastic.co/t/how-to-serialize-deserialize-fieldvalue-object/341498)

<div class="topic-metadata">

**Author:** [@icruces](https://discuss.elastic.co/u/icruces)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 3:40pm UTC](https://discuss.elastic.co/t/how-to-serialize-deserialize-fieldvalue-object/341498 "2023-08-23T15:40:24Z")

</div>

I have upgraded the Java API from 8.2 to the latest. The method Hit::sort now returns a List\<FieldValue\> instead of List\<String\>. I understand this is the correct way but it breaks my app as I was base64 encoding/decodin…

---

## [Postgresql to Elastic Search](https://discuss.elastic.co/t/postgresql-to-elastic-search/341319)

<div class="topic-metadata">

**Author:** [@oreobiskuit](https://discuss.elastic.co/u/oreobiskuit)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 2:51pm UTC](https://discuss.elastic.co/t/postgresql-to-elastic-search/341319 "2023-08-23T14:51:44Z")

</div>

Hi everyone, I'm new to Elasticsearch. Currently I'm trying to replicate my db from postgresql and transform it to Elasticsearch. I've tried using google datastream (since my db is deployed in cloudSql) to cloud storage…

---

## [Cross Cluster Search - 7.17 on EC2 to 8.8 on Kubernetes](https://discuss.elastic.co/t/cross-cluster-search-7-17-on-ec2-to-8-8-on-kubernetes/341391)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 1:59pm UTC](https://discuss.elastic.co/t/cross-cluster-search-7-17-on-ec2-to-8-8-on-kubernetes/341391 "2023-08-23T13:59:10Z")

</div>

I have a 7.17 cluster running on EC2 nodes in AWS. No security enabled. I'm trying to connect it to an 8.8 cluster on K8s with security enabled. Is this even possible? Having no issues connecting to other 7.17 clusters …

---

## [Is reading elastic logs from a node directly possible?](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473)

<div class="topic-metadata">

**Author:** [@mscch](https://discuss.elastic.co/u/mscch)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 1:41pm UTC](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473 "2023-08-23T13:41:19Z")

</div>

Hi all Is there a way to read logs (sent to elastic by Logstash) directly from an Elasticsearch node? Our Elasticsearch version is 8.30. Because of a Ransomware attack, we currently do not have access to the Kibana VM.…

---

## [Logs Pulling Architecture](https://discuss.elastic.co/t/logs-pulling-architecture/341438)

<div class="topic-metadata">

**Author:** [@Raz\_Maabari](https://discuss.elastic.co/u/Raz_Maabari)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 1:10pm UTC](https://discuss.elastic.co/t/logs-pulling-architecture/341438 "2023-08-23T13:10:00Z")

</div>

Filebeat uses a "push" architecture, sending logs to logstash or elastic. Is there a feature or product that would enable elastic to receive hosts' logs using a "pull" architecture? In my setup, I have network connectiv…

---

## [Security exception for remote cluster calls](https://discuss.elastic.co/t/security-exception-for-remote-cluster-calls/341395)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 12:07pm UTC](https://discuss.elastic.co/t/security-exception-for-remote-cluster-calls/341395 "2023-08-23T12:07:41Z")

</div>

I have a local & a remote cluster running on the same host (localhost) to be used by the integration tests. It is basically a sidecar container running ES. These tests were passing for ES version 7.16.2, but when I tried…

---

## [Insert data into a field where data contains some text between dollar and flower brackets](https://discuss.elastic.co/t/insert-data-into-a-field-where-data-contains-some-text-between-dollar-and-flower-brackets/341444)

<div class="topic-metadata">

**Author:** [@Madhuri\_Desai](https://discuss.elastic.co/u/Madhuri_Desai)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 10:57am UTC](https://discuss.elastic.co/t/insert-data-into-a-field-where-data-contains-some-text-between-dollar-and-flower-brackets/341444 "2023-08-23T10:57:11Z")

</div>

I need help with an issue that I am facing while inserting data into one of elastic index. Im trying to insert data from a log file into elastic and that file contains some text within dollar and flower brackets. Examp…

---

## [How to disable client certificate checks?](https://discuss.elastic.co/t/how-to-disable-client-certificate-checks/341365)

<div class="topic-metadata">

**Author:** [@nick\_harper1](https://discuss.elastic.co/u/nick_harper1)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 10:54am UTC](https://discuss.elastic.co/t/how-to-disable-client-certificate-checks/341365 "2023-08-23T10:54:39Z")

</div>

Is it possible to disable the server from checking the clients? Even when I have this set: xpack.security.http.ssl.client\_authentication: none When I try to import anything using a script I get this: at java.lang.Thr…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=209)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=211)
