# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=213

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 214

---

## [Custom TCP port numbers instead of 9200 for elasticsearch](https://discuss.elastic.co/t/custom-tcp-port-numbers-instead-of-9200-for-elasticsearch/341012)

<div class="topic-metadata">

**Author:** [@Penchala\_Abhilash\_Mu](https://discuss.elastic.co/u/Penchala_Abhilash_Mu)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 5:12am UTC](https://discuss.elastic.co/t/custom-tcp-port-numbers-instead-of-9200-for-elasticsearch/341012 "2023-08-18T05:12:06Z")

</div>

Hi Team, As a security best practices, i would like to change the http.port number from 9200 to custom tcp port number.?? Please share the some reference documents Best Reagards, Abhilash

---

## [Im installing elasticsearch 8.9x while inicialicing the nodes i received this error](https://discuss.elastic.co/t/im-installing-elasticsearch-8-9x-while-inicialicing-the-nodes-i-received-this-error/340786)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 4\
**Last updated:** [August 17, 2023, 9:10pm UTC](https://discuss.elastic.co/t/im-installing-elasticsearch-8-9x-while-inicialicing-the-nodes-i-received-this-error/340786 "2023-08-17T21:10:56Z")

</div>

im installing elasticsearch 8.9x but when im starting the nodes and change the password i receive this error the command i use to change is this sudo /usr/share/elasticsearch/bin/elasticsearch-reset-password --url "htt…

---

## [Filebeat failing to start due to YAML error, but which config file is it complaining about?](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 7\
**Last updated:** [August 17, 2023, 8:48pm UTC](https://discuss.elastic.co/t/filebeat-failing-to-start-due-to-yaml-error-but-which-config-file-is-it-complaining-about/341047 "2023-08-17T20:48:47Z")

</div>

I'm attempting to use Filebeat to ingest logs from Zeek, but I'm getting the following error when I start Filebeat: Here's my /etc/filebeat/filebeat.yml file: Yamllint tells me that there's an issue with this: "Map…

---

## [Platinum license with non-prod/prod](https://discuss.elastic.co/t/platinum-license-with-non-prod-prod/341048)

<div class="topic-metadata">

**Author:** [@Stevelee](https://discuss.elastic.co/u/Stevelee)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 7:06pm UTC](https://discuss.elastic.co/t/platinum-license-with-non-prod-prod/341048 "2023-08-17T19:06:10Z")

</div>

Let me explain our situation briefly. We already have contracted platinum version of ES with 3 nodes. And I got two license files for non-prod and prod. In this case, can I adopt license for 3 nodes in each environments…

---

## [ES 8.6.1 How to make the number result hits consistent when re-running the same query over and over](https://discuss.elastic.co/t/es-8-6-1-how-to-make-the-number-result-hits-consistent-when-re-running-the-same-query-over-and-over/341050)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 7:04pm UTC](https://discuss.elastic.co/t/es-8-6-1-how-to-make-the-number-result-hits-consistent-when-re-running-the-same-query-over-and-over/341050 "2023-08-17T19:04:39Z")

</div>

I have and index with 10 primaries and 10 replicas (number\_of\_replica is set to 1). Refresh interval is currently 5s. There is a lot writing activity happenning on that index. I have a query that queries for a specific…

---

## [Can we run bool query in constant\_score](https://discuss.elastic.co/t/can-we-run-bool-query-in-constant-score/341040)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 1\
**Last updated:** [August 17, 2023, 6:04pm UTC](https://discuss.elastic.co/t/can-we-run-bool-query-in-constant-score/341040 "2023-08-17T18:04:24Z")

</div>

can we run bool query in constant\_score sample query { "query": { "constant\_score": { "filter": { "bool": { "must": \[ { "term": { "account\_id": { …

---

## [javax.net.ssl.SSLHandshakeException: Empty client certificate chain](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-empty-client-certificate-chain/341024)

<div class="topic-metadata">

**Author:** [@nick\_harper1](https://discuss.elastic.co/u/nick_harper1)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 2:10pm UTC](https://discuss.elastic.co/t/javax-net-ssl-sslhandshakeexception-empty-client-certificate-chain/341024 "2023-08-17T14:10:54Z")

</div>

I have configured a cert that has both server and client enabled but when using this for transport on 9300 I get: exception caught on transport layer \[Netty4TcpChannel{localAddress=/10.15.4.16:9300, remoteAddress=/10.15…

---

## [Send a blocking bulk index request via the Elasticsearch Java client (8.9)](https://discuss.elastic.co/t/send-a-blocking-bulk-index-request-via-the-elasticsearch-java-client-8-9/341020)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 1:45pm UTC](https://discuss.elastic.co/t/send-a-blocking-bulk-index-request-via-the-elasticsearch-java-client-8-9/341020 "2023-08-17T13:45:06Z")

</div>

Hi, I have written a Spring Boot based integration test where I use the bulk api to index some documents. This is the main loop of the reindexAll() method: for (page in pageExports) { bulkRequest.operations…

---

## [Memory Pressure Getting Very High Very Quickly Due to Potentially Expensive Query](https://discuss.elastic.co/t/memory-pressure-getting-very-high-very-quickly-due-to-potentially-expensive-query/341021)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 1:34pm UTC](https://discuss.elastic.co/t/memory-pressure-getting-very-high-very-quickly-due-to-potentially-expensive-query/341021 "2023-08-17T13:34:20Z")

</div>

Hi, I'm running into a problem where memory pressure is getting very high very quickly when I make ES calls using a query with a lot of excludes. It seems to work fine for certain values of elastic\_tag\_subdomain but fo…

---

## [What is the inner workings of a GET operation?](https://discuss.elastic.co/t/what-is-the-inner-workings-of-a-get-operation/341018)

<div class="topic-metadata">

**Author:** [@jyaquinas](https://discuss.elastic.co/u/jyaquinas)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 1:09pm UTC](https://discuss.elastic.co/t/what-is-the-inner-workings-of-a-get-operation/341018 "2023-08-17T13:09:02Z")

</div>

I'm a little confused about the inner workings of GET in elasticsearch. The document states that the GET operation is realtime. I'm using version 6.8, and the documentation for this version also states the following: …

---

## [Issue with SSL when importing data but fine in browser](https://discuss.elastic.co/t/issue-with-ssl-when-importing-data-but-fine-in-browser/341008)

<div class="topic-metadata">

**Author:** [@nick\_harper1](https://discuss.elastic.co/u/nick_harper1)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 11:57am UTC](https://discuss.elastic.co/t/issue-with-ssl-when-importing-data-but-fine-in-browser/341008 "2023-08-17T11:57:05Z")

</div>

I have setup an SSL from a local CA which is working fine when I try to view in the browser from the server I am pushing data from but when trying to push data I get the following error on the server: \[2023-08-17T12:40:…

---

## [Repository-s3 is not compatible with AWS S3 on OUTPOSTS](https://discuss.elastic.co/t/repository-s3-is-not-compatible-with-aws-s3-on-outposts/340999)

<div class="topic-metadata">

**Author:** [@MatiF99](https://discuss.elastic.co/u/MatiF99)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 10:50am UTC](https://discuss.elastic.co/t/repository-s3-is-not-compatible-with-aws-s3-on-outposts/340999 "2023-08-17T10:50:23Z")

</div>

Hello! I am running Elasticsearch cluster on AWS EC2s in version 7.9.1 on AWS Outposts. I wanted to register snapshot repository on s3 bucket which is in this same Outposts, and I was not able to do it. S3 on outposts …

---

## [Simulate index results](https://discuss.elastic.co/t/simulate-index-results/340981)

<div class="topic-metadata">

**Author:** [@franck.valentin](https://discuss.elastic.co/u/franck.valentin)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 8:08am UTC](https://discuss.elastic.co/t/simulate-index-results/340981 "2023-08-17T08:08:24Z")

</div>

Hi, I was testing the Simulate index API on Elasticsearch 7.17 and didn't understand some of the results. The requests below create separate component templates for the mappings and settings and then index templates …

---

## [Example of error response for POST \_aliases API](https://discuss.elastic.co/t/example-of-error-response-for-post-aliases-api/340917)

<div class="topic-metadata">

**Author:** [@Tomas\_Hanus](https://discuss.elastic.co/u/Tomas_Hanus)\
**Replies:** 2\
**Last updated:** [August 17, 2023, 7:41am UTC](https://discuss.elastic.co/t/example-of-error-response-for-post-aliases-api/340917 "2023-08-17T07:41:14Z")

</div>

Hi, we are using 8.x JAVA client to communicate with Elasticsearch. In case of trying to handle unexpected error for updating aliases the documentation is saying nothing - Aliases API | Elasticsearch Guide \[8.11\] | Elas…

---

## [Simulate index API slow](https://discuss.elastic.co/t/simulate-index-api-slow/340973)

<div class="topic-metadata">

**Author:** [@franck.valentin](https://discuss.elastic.co/u/franck.valentin)\
**Replies:** 0\
**Last updated:** [August 17, 2023, 7:02am UTC](https://discuss.elastic.co/t/simulate-index-api-slow/340973 "2023-08-17T07:02:17Z")

</div>

Hi, I experience performance issues when calling the simulate index API on 7.17 (via the Java method SimulateIndexTemplateRequest() or /\_index\_template/\_simulate\_index/). Our ES installation runs on a Kubernetes cluste…

---

## [Index 256 out of bounds for length 256](https://discuss.elastic.co/t/index-256-out-of-bounds-for-length-256/340710)

<div class="topic-metadata">

**Author:** [@1057888035](https://discuss.elastic.co/u/1057888035)\
**Replies:** 7\
**Last updated:** [August 17, 2023, 1:52am UTC](https://discuss.elastic.co/t/index-256-out-of-bounds-for-length-256/340710 "2023-08-17T01:52:57Z")

</div>

Hi Team, I am trying to execute api like this in elasticsearch GET /\_analyze { "tokenizer": "keyword", "char\_filter": \[ { "type": "mapping", "mappings": \["is a test data is a test data is a test da…

---

## [Java Api client documentation example seems to give JacksonParseException](https://discuss.elastic.co/t/java-api-client-documentation-example-seems-to-give-jacksonparseexception/340841)

<div class="topic-metadata">

**Author:** [@Migodden](https://discuss.elastic.co/u/Migodden)\
**Replies:** 5\
**Last updated:** [August 17, 2023, 1:11am UTC](https://discuss.elastic.co/t/java-api-client-documentation-example-seems-to-give-jacksonparseexception/340841 "2023-08-17T01:11:09Z")

</div>

I am attempting to query my elastic cluster using the Elasticsearch Java Api client documentation for my version of elastic, however, I am encountering an error. Is this error because of how I am formulating my query? Co…

---

## [Cluster.initial\_master\_nodes for ElasticSearch on EC2 with Auto Scaling](https://discuss.elastic.co/t/cluster-initial-master-nodes-for-elasticsearch-on-ec2-with-auto-scaling/340784)

<div class="topic-metadata">

**Author:** [@cockroachmondays](https://discuss.elastic.co/u/cockroachmondays)\
**Replies:** 6\
**Last updated:** [August 16, 2023, 10:56pm UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-for-elasticsearch-on-ec2-with-auto-scaling/340784 "2023-08-16T22:56:12Z")

</div>

Trying to upgrade ES from 6.8 to 8.9 for ES running on EC2 AWS instances. The issue is within cluster.initial\_master\_nodes. I see that I set fixed values for node.name. However, the instances are created by Auto Scaling…

---

## [New elasticsearch-client for termsuggest accuracy not available](https://discuss.elastic.co/t/new-elasticsearch-client-for-termsuggest-accuracy-not-available/340954)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 8:22pm UTC](https://discuss.elastic.co/t/new-elasticsearch-client-for-termsuggest-accuracy-not-available/340954 "2023-08-16T20:22:01Z")

</div>

We could not find any option to supply accuracy with term suggest. But Elasticsearch core lib provided that option. https://www.javadoc.io/doc/org.elasticsearch/elasticsearch/latest/org.elasticsearch.server/org/elastics…

---

## [Elastic JSON Processor Error: \`cannot add non-map fields to root of document\`](https://discuss.elastic.co/t/elastic-json-processor-error-cannot-add-non-map-fields-to-root-of-document/340845)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 5\
**Last updated:** [August 16, 2023, 5:39pm UTC](https://discuss.elastic.co/t/elastic-json-processor-error-cannot-add-non-map-fields-to-root-of-document/340845 "2023-08-16T17:39:56Z")

</div>

I am ingesting logs in the ECS format from the Elastic Serverless Forwarder into Elasticsearch. These logs are generated by the ECS Python logging library. Because they are being generated by ESF, I need to expand the nd…

---

## [Error when running snapshot using API and console](https://discuss.elastic.co/t/error-when-running-snapshot-using-api-and-console/340937)

<div class="topic-metadata">

**Author:** [@anfel](https://discuss.elastic.co/u/anfel)\
**Replies:** 0\
**Last updated:** [August 16, 2023, 2:45pm UTC](https://discuss.elastic.co/t/error-when-running-snapshot-using-api-and-console/340937 "2023-08-16T14:45:46Z")

</div>

Hi, we are running elastichsearch 7.17 , i have noticed that all the snapshots stored were delated without any indicator . when i tried running a new snapshot using API : PUT \_snapshot/synology/daily\_snapshot-15-08-23 …

---

## [Filebeat-Container neither sends data to elasticsearch nor writes output to console/file](https://discuss.elastic.co/t/filebeat-container-neither-sends-data-to-elasticsearch-nor-writes-output-to-console-file/340904)

<div class="topic-metadata">

**Author:** [@hmmh-sven-scheil](https://discuss.elastic.co/u/hmmh-sven-scheil)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/filebeat-container-neither-sends-data-to-elasticsearch-nor-writes-output-to-console-file/340904 "2023-08-16T14:08:31Z")

</div>

Hi there, I'am trying to setup a demo scenario, to demonstrate how to collect Tomcat log data from different containers and send it to an elastic stack for log aggregation and log analysis. I try to describe my setup, …

---

## [Elastic Search - how to create index with mapping](https://discuss.elastic.co/t/elastic-search-how-to-create-index-with-mapping/340925)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/elastic-search-how-to-create-index-with-mapping/340925 "2023-08-16T14:08:09Z")

</div>

elasticsearch:8.7.1 I am creating index this way: return new CreateIndexRequest.Builder() .index(name) .aliases(alias, new Alias.Builder().build()) .settings(new Inde…

---

## [Elasticsearch query based on timestamp from kibana (dev tools)](https://discuss.elastic.co/t/elasticsearch-query-based-on-timestamp-from-kibana-dev-tools/340893)

<div class="topic-metadata">

**Author:** [@Mamta\_Bharadwaj](https://discuss.elastic.co/u/Mamta_Bharadwaj)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 12:40pm UTC](https://discuss.elastic.co/t/elasticsearch-query-based-on-timestamp-from-kibana-dev-tools/340893 "2023-08-16T12:40:15Z")

</div>

Hello All, I am using ELK 8.3.3 on Docker. When I am trying to fetch the data with any timestamp range, I am getting the correct output. But when I am trying to fetch the data based on the below, I am getting nothing. P…

---

## [ES S3 plugin](https://discuss.elastic.co/t/es-s3-plugin/340892)

<div class="topic-metadata">

**Author:** [@EshaSingh32000](https://discuss.elastic.co/u/EshaSingh32000)\
**Replies:** 4\
**Last updated:** [August 16, 2023, 10:44am UTC](https://discuss.elastic.co/t/es-s3-plugin/340892 "2023-08-16T10:44:23Z")

</div>

Currently my Es Version is 7.17.1, and i want to download s3 plugin for same, can anyone provide me link to download s3 plugin for es version 7.17.1

---

## [Changing password of elasticsearch user after expiration of x-pack](https://discuss.elastic.co/t/changing-password-of-elasticsearch-user-after-expiration-of-x-pack/340638)

<div class="topic-metadata">

**Author:** [@Kartik101](https://discuss.elastic.co/u/Kartik101)\
**Replies:** 2\
**Last updated:** [August 16, 2023, 9:53am UTC](https://discuss.elastic.co/t/changing-password-of-elasticsearch-user-after-expiration-of-x-pack/340638 "2023-08-16T09:53:52Z")

</div>

Can we change password of elasticsearch user after expiration of x-pack (installed using basic configuration) for Elasticsearch v5.6.2?

---

## [Java API Timeout connection](https://discuss.elastic.co/t/java-api-timeout-connection/340867)

<div class="topic-metadata">

**Author:** [@hld942614](https://discuss.elastic.co/u/hld942614)\
**Replies:** 3\
**Last updated:** [August 16, 2023, 9:39am UTC](https://discuss.elastic.co/t/java-api-timeout-connection/340867 "2023-08-16T09:39:59Z")

</div>

I am using Elastic Java API to write some data into elastic，but I occasionally get some error like this: "java.net.ConnectException: Timeout connecting to \[gt7-elk001.es.asia-east1.gcp.elastic-cloud.com/XX.XX.XXX.XXX:XX…

---

## [ES replica creation](https://discuss.elastic.co/t/es-replica-creation/340872)

<div class="topic-metadata">

**Author:** [@khubaibathar](https://discuss.elastic.co/u/khubaibathar)\
**Replies:** 1\
**Last updated:** [August 16, 2023, 7:07am UTC](https://discuss.elastic.co/t/es-replica-creation/340872 "2023-08-16T07:07:00Z")

</div>

Hi, Can someone tell me if ES is able to create a replica while still in use. Would it affect the performance of the cluster or does this mechanism run in the background. We have an ES cluster which has six nodes.

---

## [Filter combined\_fields result](https://discuss.elastic.co/t/filter-combined-fields-result/340812)

<div class="topic-metadata">

**Author:** [@Samuel\_Litvack](https://discuss.elastic.co/u/Samuel_Litvack)\
**Replies:** 3\
**Last updated:** [August 15, 2023, 5:13pm UTC](https://discuss.elastic.co/t/filter-combined-fields-result/340812 "2023-08-15T17:13:03Z")

</div>

Hi I'm working on a people search website. I already have my databases indexed and it is currently possible to search for a person by fullname using combined\_fields query like this. { "query":{ "combined\_field…

---

## [Attempting to create a Double Field, Changes to keyword when data is imported](https://discuss.elastic.co/t/attempting-to-create-a-double-field-changes-to-keyword-when-data-is-imported/340848)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 7:52pm UTC](https://discuss.elastic.co/t/attempting-to-create-a-double-field-changes-to-keyword-when-data-is-imported/340848 "2023-08-15T19:52:27Z")

</div>

Hello, I've got an empty dev index that I'm attempting to test some aggregations and a dashboard on. The problem I'm encountering is that when I push logs through to the index via a filebeat collector node the type for …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=212)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=214)
