# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=211

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 212

---

## [Improve Snapshot/Backup capabilities for Air Gapped deployments via direct downloads or allowing individuals to push snapshots to repositories such as GitLab, Nexus or Artifactory](https://discuss.elastic.co/t/improve-snapshot-backup-capabilities-for-air-gapped-deployments-via-direct-downloads-or-allowing-individuals-to-push-snapshots-to-repositories-such-as-gitlab-nexus-or-artifactory/340599)

<div class="topic-metadata">

**Author:** [@sheldon.mcclung](https://discuss.elastic.co/u/sheldon.mcclung)\
**Replies:** 4\
**Last updated:** [August 23, 2023, 10:47am UTC](https://discuss.elastic.co/t/improve-snapshot-backup-capabilities-for-air-gapped-deployments-via-direct-downloads-or-allowing-individuals-to-push-snapshots-to-repositories-such-as-gitlab-nexus-or-artifactory/340599 "2023-08-23T10:47:09Z")

</div>

The below image shows the docs with the current snapshot repository options. For an environment that is air gapped, there are not many options available as far as registries to backup the elastic data. I propose that…

---

## [Nested Aggregation not returning document count](https://discuss.elastic.co/t/nested-aggregation-not-returning-document-count/341454)

<div class="topic-metadata">

**Author:** [@Raju\_Yadav](https://discuss.elastic.co/u/Raju_Yadav)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 9:49am UTC](https://discuss.elastic.co/t/nested-aggregation-not-returning-document-count/341454 "2023-08-23T09:49:56Z")

</div>

i have a product document and that product is published into various eCommerce website like amazon , flipkart as shown in location field. The product published is a nested field in Elasticsearch. now i want to aggregate …

---

## [Why is fast bulk than single indexing in elasticsearch](https://discuss.elastic.co/t/why-is-fast-bulk-than-single-indexing-in-elasticsearch/341339)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 11\
**Last updated:** [August 23, 2023, 9:42am UTC](https://discuss.elastic.co/t/why-is-fast-bulk-than-single-indexing-in-elasticsearch/341339 "2023-08-23T09:42:00Z")

</div>

I wonder why bulk indexing is faster than single indexing. I'm curious from the point of view of elasticsearch, other than being connected and closed and network communication problems. Based on the default refresh tim…

---

## [Runtime Fields](https://discuss.elastic.co/t/runtime-fields/341270)

<div class="topic-metadata">

**Author:** [@MOHIT\_SHARMA4](https://discuss.elastic.co/u/MOHIT_SHARMA4)\
**Replies:** 5\
**Last updated:** [August 23, 2023, 9:37am UTC](https://discuss.elastic.co/t/runtime-fields/341270 "2023-08-23T09:37:14Z")

</div>

Hey, I wanted to know what is the difference between defining runtime\_field in mapping v/s and doing so in the query itself. For this, I tried running the following requests to observe if there occurs any changes in int…

---

## [ROTATE ML INDEXES](https://discuss.elastic.co/t/rotate-ml-indexes/339286)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 7:02am UTC](https://discuss.elastic.co/t/rotate-ml-indexes/339286 "2023-08-23T07:02:43Z")

</div>

Hi to everyone! I was trying to apply an ILM to ML Job, but I couldn't found nothing related with ilm in machines learning job configuration Does someone how to do it?

---

## [Huge Segments filling up heap](https://discuss.elastic.co/t/huge-segments-filling-up-heap/341317)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 5:25am UTC](https://discuss.elastic.co/t/huge-segments-filling-up-heap/341317 "2023-08-23T05:25:34Z")

</div>

In our cluster, We have 6 node each with 30GB heap. We have around 30 indices each with few Millions of docs. Index structure is very very small with just 10 fileds. Each index size is hardly 5GB. Issue: After ingestin…

---

## [Elasticsearch Interface not loading](https://discuss.elastic.co/t/elasticsearch-interface-not-loading/341399)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 9:02pm UTC](https://discuss.elastic.co/t/elasticsearch-interface-not-loading/341399 "2023-08-22T21:02:31Z")

</div>

Cluster is green, all nodes are green but yet i cannot open up the interface, it stays as a blank screen, anyone ever run into this ? if I go to the monitoring node, and view the main cluster it loads fine , looks fine

---

## [Get most frequent combinations of nested docs](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397)

<div class="topic-metadata">

**Author:** [@JsRg](https://discuss.elastic.co/u/JsRg)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 4:41pm UTC](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397 "2023-08-22T16:41:46Z")

</div>

I have a elasticsearch index with nested documents (colors). I would like to have a query with an aggregation, which shows the most frequent combinations of colors. An example: I have three documents \[ { "name": "D…

---

## [Elasticsearch 8.9.1 - How to extract the self-signed CA and server cert](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304)

<div class="topic-metadata">

**Author:** [@saltspreader](https://discuss.elastic.co/u/saltspreader)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:06pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304 "2023-08-22T15:06:46Z")

</div>

Hi there, Elasticsearch v 8.9.1 installed via ES apt repo on ubuntu 22.04. I need to extract the self-signed CA and https cert from my elasticsearch 8.9.1 setup to copy to a gitlab instance for https connections. I've …

---

## [Upgrading elastic to 8.8 has resulted in a master node sending out 5 megabytes a second](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 2:19pm UTC](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299 "2023-08-22T14:19:08Z")

</div>

Usually elastic master nodes send out 100 kilobytes a second of data. But after upgrading the active master is sending out 5 megabytes. There's no known issue but this doesn't seem healthy. It's role is only master.

---

## [Trial License ECK Issues](https://discuss.elastic.co/t/trial-license-eck-issues/341381)

<div class="topic-metadata">

**Author:** [@walberss](https://discuss.elastic.co/u/walberss)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 2:04pm UTC](https://discuss.elastic.co/t/trial-license-eck-issues/341381 "2023-08-22T14:04:16Z")

</div>

Hi guys I'm trying make tests with ldap integration on kubernetes eck and i can change de license from basic to trial, after few seconds the license come back to basic, Has anyone already caught this behavior? {"type":…

---

## [Connect Salesforce with Elastic](https://discuss.elastic.co/t/connect-salesforce-with-elastic/341255)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/connect-salesforce-with-elastic/341255 "2023-08-22T13:51:02Z")

</div>

Hi everyone, im using elastic cloud and i need to integrate Salesforce. What i need to do is analize logs coming from salesforce like SetupAuditTrail. I have found different solution for my problem: Using the Integra…

---

## [High latency issue with inner\_hits](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375)

<div class="topic-metadata">

**Author:** [@Gilat\_Naveh](https://discuss.elastic.co/u/Gilat_Naveh)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:46pm UTC](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375 "2023-08-22T13:46:56Z")

</div>

I’m trying to install a new cluster on ECK (version 8.8.1) and I’m having latency issues (~300ms). We already have a similar cluster working in version 6.5.3 (EC2) and for the same query timing is good (~20ms) The quer…

---

## [Search scroll](https://discuss.elastic.co/t/search-scroll/341283)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 1:25pm UTC](https://discuss.elastic.co/t/search-scroll/341283 "2023-08-22T13:25:36Z")

</div>

Can anyone point me to any documentation regarding search scroll for the new java api client? I'm talking about this from the HLRC - Search Scroll API | Java REST Client \[7.17\] | Elastic. Thanks.

---

## [Cant start kibana on docker any more](https://discuss.elastic.co/t/cant-start-kibana-on-docker-any-more/341108)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 1:20pm UTC](https://discuss.elastic.co/t/cant-start-kibana-on-docker-any-more/341108 "2023-08-22T13:20:16Z")

</div>

I am using this with docker image - and now , sundly I cant start the kibana any more . it showed this message - Kibana server is not ready yet. I runned the command - docker-compose logs , and shoed this message …

---

## [Elasticsearch docker cluster](https://discuss.elastic.co/t/elasticsearch-docker-cluster/341371)

<div class="topic-metadata">

**Author:** [@Swapnadeep\_Mondal](https://discuss.elastic.co/u/Swapnadeep_Mondal)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:18pm UTC](https://discuss.elastic.co/t/elasticsearch-docker-cluster/341371 "2023-08-22T13:18:33Z")

</div>

Hi, I am trying to create the Elasticsearch cluster in remote servers using the docker containers, one catch is that I am not using the docker-compose file. When I start the docker containers in different remote hosts …

---

## [Aggregations and sub-Aggregations in java API client](https://discuss.elastic.co/t/aggregations-and-sub-aggregations-in-java-api-client/341363)

<div class="topic-metadata">

**Author:** [@dt2244](https://discuss.elastic.co/u/dt2244)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 12:13pm UTC](https://discuss.elastic.co/t/aggregations-and-sub-aggregations-in-java-api-client/341363 "2023-08-22T12:13:22Z")

</div>

i am trying to rewrite my code from elasticsearch version 7.10.2 to latest version es 8.9 but i am having some problems: code version 7.10.2: FilterAggregationBuilder filteredAggs = AggregationBuilders …

---

## [Elaticsearch SQL CLI is not working](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 10\
**Last updated:** [August 22, 2023, 11:41am UTC](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615 "2023-08-22T11:41:02Z")

</div>

Hi Team, I am trying to execute some sql commands from SQL CLI in elasticsearch -8.8.2 but while executing below commands to open SQL CLI ./bin/elasticsearch-sql-cli I am getting below error ERROR: Cannot communicat…

---

## [Geo-distance query to match geo\_point within a given distance of a geopoint](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356)

<div class="topic-metadata">

**Author:** [@Allen\_Liang](https://discuss.elastic.co/u/Allen_Liang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 11:27am UTC](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356 "2023-08-22T11:27:27Z")

</div>

Hello, I'm seeking clarification regarding the distance utilised for filtering documents using the geo-distance query (Geo-distance query | Elasticsearch Guide \[8.9\] | Elastic). In each of my documents, there exists a …

---

## [How to perform with condition divide math operation in elasticsearch](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329)

<div class="topic-metadata">

**Author:** [@Huy\_Vu\_Quang](https://discuss.elastic.co/u/Huy_Vu_Quang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 6:54am UTC](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329 "2023-08-22T06:54:06Z")

</div>

I have a query like this how I perform a query in Elasticsearch with this condition if wager == 0 : payout/1 \>= multiplier else: payout/wager \>= multiplier filter multiplier according to this condition I wrote this …

---

## [Index creating through logstash and show on kibana index pattern](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 5\
**Last updated:** [August 22, 2023, 7:05am UTC](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972 "2023-08-22T07:05:35Z")

</div>

Hello , I need a help on configuration of logstash output section....i want to create an index and fetch some particular logs on that index...whenever am creating a new index it is not showing on kibana output { if "…

---

## [Failed to retrieve password hash for reserved user \[elastic\]](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 7:03am UTC](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330 "2023-08-22T07:03:20Z")

</div>

I upgraded elasticsearch cluster 7.17 to 8.9 version. I used "yum update elasticsearch" command to upgrade. It is upgraded successfully. But when i try to start elasticsearch, it couldn't start. How can i solve it? e…

---

## [Elasticsearch cluster certs configuration](https://discuss.elastic.co/t/elasticsearch-cluster-certs-configuration/341320)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 5:18am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-certs-configuration/341320 "2023-08-22T05:18:10Z")

</div>

Hey there, I am trying to run ES cluster of let's say 3 nodes. I am using volume mount in docker to mount my self signed certificates. And here is the command I am using:- sudo docker run -it --privileged -p 9200:92…

---

## [AFTER changed DATA STREAM INDEX template, index stay 225b,](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293)

<div class="topic-metadata">

**Author:** [@cLaYYs](https://discuss.elastic.co/u/cLaYYs)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 4:54am UTC](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293 "2023-08-22T04:54:20Z")

</div>

Hi All, We use custom UDP integration(fleet managed integration) to collect Linux auth logs. We set the default pipeline for auth logs which is \[logs-system.auth-default\]. We did parse the data as we expected. This dat…

---

## [Geo fields at root?](https://discuss.elastic.co/t/geo-fields-at-root/341307)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 12:58am UTC](https://discuss.elastic.co/t/geo-fields-at-root/341307 "2023-08-22T00:58:17Z")

</div>

ECS geo docs say: The geo fields are expected to be nested at: client.geo destination.geo host.geo server.geo ... Note also that the geo fields are not expected to be used directly at the root of the events. I was …

---

## [A good place for "state of being a canary" field](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 11:21pm UTC](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690 "2023-08-21T23:21:14Z")

</div>

Where do you think is a good place to indicate that a log message is from a canary? orchestration.\* doesn't seem appropriate. Maybe something in the upcoming node field set? (Where do I find information about that?) I…

---

## [Update indices replica set in Elasticsearch cluster](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 10:32pm UTC](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149 "2023-08-21T22:32:59Z")

</div>

Hello, I would like to update the number of replicas for newly creating indices to be 5 automatically, so i used the below curl curl -XPUT -k -u elastic:password 'https://192.168.x.x:9200/\_index\_template/my\_template' -…

---

## [Docker image "elastic-connectors:8.9.1.0" for ARM64 architecture?](https://discuss.elastic.co/t/docker-image-elastic-connectors-8-9-1-0-for-arm64-architecture/341302)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 9:16pm UTC](https://discuss.elastic.co/t/docker-image-elastic-connectors-8-9-1-0-for-arm64-architecture/341302 "2023-08-21T21:16:09Z")

</div>

Hello, I want to deploy the Enterprise Search MySQL connector docker image on an ARM64 architecture host. Is there a ARM64 docker image for: "enterprise-search/elastic-connectors:8.9.1.0" ? Best regards, Martin

---

## [Replica count 3 for .security-7](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:27pm UTC](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274 "2023-08-21T19:27:06Z")

</div>

I'm trying to set the replica count for .security-7 to 3 so that if 2 nodes go down it's still ok. But it seems superuser can't update it. What's the best path forward for this situation. The docs don't really answer …

---

## [Difference between Elasticsearch Security and Watcher Setting in Elasticsearch](https://discuss.elastic.co/t/difference-between-elasticsearch-security-and-watcher-setting-in-elasticsearch/341173)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 20\
**Last updated:** [August 21, 2023, 4:59pm UTC](https://discuss.elastic.co/t/difference-between-elasticsearch-security-and-watcher-setting-in-elasticsearch/341173 "2023-08-21T16:59:38Z")

</div>

Hi there, I am looking to set security on http and transport layer. But I am confused in what to use between the following: xpack.security.transport.ssl.verification\_mode=certificate xpack.transport.ssl.verification\_…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=210)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=212)
