# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=214

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 215

---

## [Elasticsearch + filebeat + apache on docker environment](https://discuss.elastic.co/t/elasticsearch-filebeat-apache-on-docker-environment/340842)

<div class="topic-metadata">

**Author:** [@Jackson\_Luz](https://discuss.elastic.co/u/Jackson_Luz)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elasticsearch-filebeat-apache-on-docker-environment/340842 "2023-08-15T17:07:20Z")

</div>

Hello! Newbie here. Imagine the following scenario: a Docker environment where there are 3 containers. One is running Elasticsearch, another has Filebeat, and the third one contains Apache. All of them are on the same ne…

---

## [XContentBuilder](https://discuss.elastic.co/t/xcontentbuilder/340839)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 4:02pm UTC](https://discuss.elastic.co/t/xcontentbuilder/340839 "2023-08-15T16:02:02Z")

</div>

Referencing this post - Ways to build Json doc in ES8 Java API client Is it advised not to use XContentBuilder with the new Java API Client? Will that be deprecated? Thanks.

---

## [I have a problem with deployment of a dockerized Django/Elasticsearch website](https://discuss.elastic.co/t/i-have-a-problem-with-deployment-of-a-dockerized-django-elasticsearch-website/340828)

<div class="topic-metadata">

**Author:** [@Mostafa\_Mohamed](https://discuss.elastic.co/u/Mostafa_Mohamed)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 10:48am UTC](https://discuss.elastic.co/t/i-have-a-problem-with-deployment-of-a-dockerized-django-elasticsearch-website/340828 "2023-08-15T10:48:19Z")

</div>

I have a dockerized web application that contains 3 containers (Django/ PostgreSQL/Elasticsearch), The indices of the Elasticsearch are indexed depending on the Django database models using a library called Django-Elasti…

---

## [Can ILM policy be created on an existing set of indexes?](https://discuss.elastic.co/t/can-ilm-policy-be-created-on-an-existing-set-of-indexes/340809)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 1\
**Last updated:** [August 15, 2023, 12:42pm UTC](https://discuss.elastic.co/t/can-ilm-policy-be-created-on-an-existing-set-of-indexes/340809 "2023-08-15T12:42:39Z")

</div>

Currently, i am have a FluentD daemon writing app logs to Elasticsearch. The index names have the naming convention "logstash-(date)" e.g. logstash-2023-08-15. Is it possible to create an ILM policy that applies to thes…

---

## [\_source field storage (\_source Field Overview)](https://discuss.elastic.co/t/source-field-storage-source-field-overview/340729)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 8\
**Last updated:** [August 15, 2023, 11:47am UTC](https://discuss.elastic.co/t/source-field-storage-source-field-overview/340729 "2023-08-15T11:47:17Z")

</div>

Hello, We just want to have a clear understanding of the \_source field. Is it going to be indexed or stored? if it is stored where it is going to be stored. As an experiment, we disabled the \_source using PUT index\_nam…

---

## [How to automate search template creation?](https://discuss.elastic.co/t/how-to-automate-search-template-creation/338840)

<div class="topic-metadata">

**Author:** [@Prashant\_S](https://discuss.elastic.co/u/Prashant_S)\
**Replies:** 1\
**Last updated:** [August 15, 2023, 9:41am UTC](https://discuss.elastic.co/t/how-to-automate-search-template-creation/338840 "2023-08-15T09:41:18Z")

</div>

I am using search templates. How to manage the versioning of my templates and execute them . I am exposing search templates via microservice backed by springboot . Thanks

---

## [Cannot stop winlogbeat service](https://discuss.elastic.co/t/cannot-stop-winlogbeat-service/340653)

<div class="topic-metadata">

**Author:** [@Ptak](https://discuss.elastic.co/u/Ptak)\
**Replies:** 1\
**Last updated:** [August 15, 2023, 8:53am UTC](https://discuss.elastic.co/t/cannot-stop-winlogbeat-service/340653 "2023-08-15T08:53:01Z")

</div>

Hello all, I'm facing the following issue: I cannot stop the winlogbeat service either automatically or manually. The service can be stopped only after clicking "End Task" in the Task Manager. I did test the same Ansibl…

---

## [HIBP integration](https://discuss.elastic.co/t/hibp-integration/340815)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 7:32am UTC](https://discuss.elastic.co/t/hibp-integration/340815 "2023-08-15T07:32:45Z")

</div>

What’s the recommended way to integrate “have I been pwnd” API into elastic? The idea here is to have an index with email IDs in it and to generate alerts based on API calls to HIBP…real time breach monitoring. Search …

---

## [ILM policies based on the age of records in an index](https://discuss.elastic.co/t/ilm-policies-based-on-the-age-of-records-in-an-index/340814)

<div class="topic-metadata">

**Author:** [@Zips6203](https://discuss.elastic.co/u/Zips6203)\
**Replies:** 1\
**Last updated:** [August 15, 2023, 7:34am UTC](https://discuss.elastic.co/t/ilm-policies-based-on-the-age-of-records-in-an-index/340814 "2023-08-15T07:34:01Z")

</div>

Hello everyone, I wanted to discuss the possibility of an implementation with the help of ILM policies. I am currently storing application metrices (flat JSON) into an Elasticsearch index. Only the records that have be…

---

## [Issues connecting to JIRA account after source configuration](https://discuss.elastic.co/t/issues-connecting-to-jira-account-after-source-configuration/340808)

<div class="topic-metadata">

**Author:** [@gggra](https://discuss.elastic.co/u/gggra)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 6:20am UTC](https://discuss.elastic.co/t/issues-connecting-to-jira-account-after-source-configuration/340808 "2023-08-15T06:20:58Z")

</div>

I am facing the setup issue in workplace search setup. JIRA is not letting log in when selecting "Connect JIRA". It always display the page "Hmm... We're having trouble logging you in." Can anyone advise ? Thanks.

---

## [How to know where the Elastic Search Hits are coming from](https://discuss.elastic.co/t/how-to-know-where-the-elastic-search-hits-are-coming-from/340800)

<div class="topic-metadata">

**Author:** [@es2learn](https://discuss.elastic.co/u/es2learn)\
**Replies:** 0\
**Last updated:** [August 15, 2023, 3:41am UTC](https://discuss.elastic.co/t/how-to-know-where-the-elastic-search-hits-are-coming-from/340800 "2023-08-15T03:41:16Z")

</div>

Is there any way to configure the Elasticsearch so that we get to know that the requests are coming from a service or kibana or external sources, API calls etc.,

---

## [Password reset require for elasticsearch 7.17.7](https://discuss.elastic.co/t/password-reset-require-for-elasticsearch-7-17-7/340780)

<div class="topic-metadata">

**Author:** [@sohag](https://discuss.elastic.co/u/sohag)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 10:19pm UTC](https://discuss.elastic.co/t/password-reset-require-for-elasticsearch-7-17-7/340780 "2023-08-14T22:19:39Z")

</div>

Hi Please help me to resolve the below issue. I lost my Elasticsearch password of user elastic . Now i am trying to reset the password but error is like below- curl -XPOST "http://localhost:9200/\_security/user/ela…

---

## [Painless Script runtime error: dynamic method \[java.util.ArrayList, entrySet/0\] not found](https://discuss.elastic.co/t/painless-script-runtime-error-dynamic-method-java-util-arraylist-entryset-0-not-found/340775)

<div class="topic-metadata">

**Author:** [@Anni](https://discuss.elastic.co/u/Anni)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 7:26pm UTC](https://discuss.elastic.co/t/painless-script-runtime-error-dynamic-method-java-util-arraylist-entryset-0-not-found/340775 "2023-08-14T19:26:45Z")

</div>

I am getting "dynamic method \[java.util.ArrayList, entrySet/0\] not found" error while running the painless script in watchers. Here is the simplified version of the code. I tried to recreate the issue in dev tools but I…

---

## [Using NGINX as a Load Balancer](https://discuss.elastic.co/t/using-nginx-as-a-load-balancer/340773)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 4:33pm UTC](https://discuss.elastic.co/t/using-nginx-as-a-load-balancer/340773 "2023-08-14T16:33:03Z")

</div>

I created an Elasticsearch Cluster with 3 Elasticsearch nodes. All nodes are of type master. They are configured to maintain high availability, one node receives data and replicates it to the other two. For load balanc…

---

## [Kibana map point-to-point connection](https://discuss.elastic.co/t/kibana-map-point-to-point-connection/340772)

<div class="topic-metadata">

**Author:** [@Hannah\_Zhang](https://discuss.elastic.co/u/Hannah_Zhang)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 4:30pm UTC](https://discuss.elastic.co/t/kibana-map-point-to-point-connection/340772 "2023-08-14T16:30:04Z")

</div>

Kibana guide states that "A point-to-point connection plots aggregated data paths between the source and the destination. Thicker, darker lines symbolize more connections between a source and destination, and thinner, li…

---

## [Rollup vs Transform](https://discuss.elastic.co/t/rollup-vs-transform/340537)

<div class="topic-metadata">

**Author:** [@ajitesh](https://discuss.elastic.co/u/ajitesh)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 3:23pm UTC](https://discuss.elastic.co/t/rollup-vs-transform/340537 "2023-08-14T15:23:09Z")

</div>

I have a use case where I have a nested aggregation query, now I want to ingest the data for all the aggregation results into a new index. I was going through the Elasticsearch documents and found out that Aggregation do…

---

## [Stability issues when uploading Databricks tables to Elasticsearch indices (circuit\_breaking\_exception)](https://discuss.elastic.co/t/stability-issues-when-uploading-databricks-tables-to-elasticsearch-indices-circuit-breaking-exception/340637)

<div class="topic-metadata">

**Author:** [@landlord\_matt](https://discuss.elastic.co/u/landlord_matt)\
**Replies:** 6\
**Last updated:** [August 14, 2023, 3:00pm UTC](https://discuss.elastic.co/t/stability-issues-when-uploading-databricks-tables-to-elasticsearch-indices-circuit-breaking-exception/340637 "2023-08-14T15:00:11Z")

</div>

Hi! We recently got switched from a large (8 node, 21 GB JVM heap memory) cluster to a smaller (3 node, 9 GB JVM heap memory) cluster and now we getting errors while trying to reupload our Elasticsearch indices. It occa…

---

## [Multi\_search with fuzziness](https://discuss.elastic.co/t/multi-search-with-fuzziness/340765)

<div class="topic-metadata">

**Author:** [@LUCAS\_CARVALHO\_GOMES](https://discuss.elastic.co/u/LUCAS_CARVALHO_GOMES)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 2:54pm UTC](https://discuss.elastic.co/t/multi-search-with-fuzziness/340765 "2023-08-14T14:54:31Z")

</div>

Hi guys. I'm new to Elastic, so my question may sound dull, but here we go. I'm trying to make a query that searches for a phrase in different fields. I'm aware that the fuzziness param doesn't work for phrases (test p…

---

## [Create Helmcharts for Metricbeats](https://discuss.elastic.co/t/create-helmcharts-for-metricbeats/340761)

<div class="topic-metadata">

**Author:** [@jhmcd2](https://discuss.elastic.co/u/jhmcd2)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 2:21pm UTC](https://discuss.elastic.co/t/create-helmcharts-for-metricbeats/340761 "2023-08-14T14:21:55Z")

</div>

Hello. I have a bit of a problem. I need to be able to create a set of Helm charts for Metricbeat and Packetbeat. Now, that is easy, I am mainly using Kompose to convert the docker-compose.yml file over. However, in b…

---

## [Aliases are lost after Elasticsearch Docker container recreate](https://discuss.elastic.co/t/aliases-are-lost-after-elasticsearch-docker-container-recreate/340743)

<div class="topic-metadata">

**Author:** [@Maxim\_Dubrovin](https://discuss.elastic.co/u/Maxim_Dubrovin)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 10:43am UTC](https://discuss.elastic.co/t/aliases-are-lost-after-elasticsearch-docker-container-recreate/340743 "2023-08-14T10:43:56Z")

</div>

Hello. Our project have Elasticsearch and Logstash running as Docker containers. Both started with one "docker-compose up" command. Containers config in "docker-compose.yaml" file. Elasticsearch successfully persists dat…

---

## [I want to Use Logstash Input Plugin for capturing the audit log of Elasticsearch. But not understood which one should be suitable for this](https://discuss.elastic.co/t/i-want-to-use-logstash-input-plugin-for-capturing-the-audit-log-of-elasticsearch-but-not-understood-which-one-should-be-suitable-for-this/340745)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 10:49am UTC](https://discuss.elastic.co/t/i-want-to-use-logstash-input-plugin-for-capturing-the-audit-log-of-elasticsearch-but-not-understood-which-one-should-be-suitable-for-this/340745 "2023-08-14T10:49:54Z")

</div>

I am trying to capture audit logs for all the executed query in Elasticsearch. i.e. DSL, EQL, SQL.

---

## [Creating an Index with .NET client](https://discuss.elastic.co/t/creating-an-index-with-net-client/340744)

<div class="topic-metadata">

**Author:** [@NekoNova](https://discuss.elastic.co/u/NekoNova)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 10:44am UTC](https://discuss.elastic.co/t/creating-an-index-with-net-client/340744 "2023-08-14T10:44:18Z")

</div>

Hello, I am currently working on a project in C#.NET and we gave created Poco objects for our documents. Can I do something same for creating the Index? We have an exported index in JSON that we want to represent in c…

---

## [JSON serialization differences from HLRC to new Java API Client](https://discuss.elastic.co/t/json-serialization-differences-from-hlrc-to-new-java-api-client/340651)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 10:20am UTC](https://discuss.elastic.co/t/json-serialization-differences-from-hlrc-to-new-java-api-client/340651 "2023-08-14T10:20:40Z")

</div>

With the HLRC, the timestamp field below is serialized as "2023-08-10T18:59:59.143Z". However, with the new Java API Client it is serialized as a long time. This is with the new BulkIngester. Is there a way to customize …

---

## [Object mapping for ... tried to parse field \[content\_range\] as object, but found a concrete value](https://discuss.elastic.co/t/object-mapping-for-tried-to-parse-field-content-range-as-object-but-found-a-concrete-value/340726)

<div class="topic-metadata">

**Author:** [@bohm](https://discuss.elastic.co/u/bohm)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 9:08am UTC](https://discuss.elastic.co/t/object-mapping-for-tried-to-parse-field-content-range-as-object-but-found-a-concrete-value/340726 "2023-08-14T09:08:23Z")

</div>

Hello, Found some informative posts already, but guess I misintepreted some info. This is logstash logging: :response=\>{"index"=\>{"\_index"=\>"logstash-http-2023.08.14", "\_type"=\>"\_doc", "\_id"=\>"BobW8okBwOC2FKopPOGW", "…

---

## [What is best node configuration in 5 node](https://discuss.elastic.co/t/what-is-best-node-configuration-in-5-node/340709)

<div class="topic-metadata">

**Author:** [@hyungsun\_lim](https://discuss.elastic.co/u/hyungsun_lim)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 9:08am UTC](https://discuss.elastic.co/t/what-is-best-node-configuration-in-5-node/340709 "2023-08-14T09:08:06Z")

</div>

I have 5 nodes for elasticsearch. When i use 3 nodes, i just use them as default mode. Is it okay to use default mode for 5 nodes? Or is there any good options to set role for 5 nodes?

---

## [Encryption in Elasticsearch](https://discuss.elastic.co/t/encryption-in-elasticsearch/340711)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 6:17am UTC](https://discuss.elastic.co/t/encryption-in-elasticsearch/340711 "2023-08-14T06:17:05Z")

</div>

Just wanted to get some idea from the folks here regarding Elasticsearch data encryption. So, I am aware about 2 ways we can get our data encrypt in Elasticsearch:- Using some encyption/tokenization on data before ing…

---

## [Ingest Pipeline Stats - Processor \`if\` (conditional) measurement](https://discuss.elastic.co/t/ingest-pipeline-stats-processor-if-conditional-measurement/340707)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [August 13, 2023, 8:18pm UTC](https://discuss.elastic.co/t/ingest-pipeline-stats-processor-if-conditional-measurement/340707 "2023-08-13T20:18:52Z")

</div>

Hi All, I have a question related to the Ingest Pipeline stats that are part of the node stats api. The API returns the time it takes to process a doc for a given processor, but what isn't clear to me is does the time …

---

## [Updating enrich index for pipeline](https://discuss.elastic.co/t/updating-enrich-index-for-pipeline/339732)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 7\
**Last updated:** [August 12, 2023, 7:50pm UTC](https://discuss.elastic.co/t/updating-enrich-index-for-pipeline/339732 "2023-08-12T19:50:27Z")

</div>

Hello, I have an 8.8.1 cluster, and am running documents through a series of ingest pipelines. One of these pipelines is an enrich stage. This data which is used to enrich the documents is sourced from an index via an…

---

## [How to query Elasticsearch datasource in Grafana?](https://discuss.elastic.co/t/how-to-query-elasticsearch-datasource-in-grafana/340682)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 0\
**Last updated:** [August 12, 2023, 10:49am UTC](https://discuss.elastic.co/t/how-to-query-elasticsearch-datasource-in-grafana/340682 "2023-08-12T10:49:39Z")

</div>

I want to use an index in Elasticsearch as a data source in Grafana. But I can't query it and extract a specific field from it. I want to have only the data of the fields I want as output from among several fields in thi…

---

## [Handle retries for bulk api](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 9:20am UTC](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640 "2023-08-12T09:20:51Z")

</div>

Hi, I am trying to make a bulk request using BulkRequest in java. I am not finding any documentation to retry the failed requests. Is there any inbuilt functionality in the java client api to handle retries or do I need…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=213)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=215)
