# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=215

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 216

---

## [Query Precision/Recall vs Sort](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 7:59am UTC](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667 "2023-08-12T07:59:55Z")

</div>

I have a catalog of products and I'm facing some problems when I try to sort the results by other criteria than by relevance. Today I can sort the results in order: most recent and most rated. My query has the characte…

---

## [Log.file.path with grok condition issue with multiple log files](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 2\
**Last updated:** [August 12, 2023, 6:45am UTC](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600 "2023-08-12T06:45:48Z")

</div>

Hi Team, Am I trying to create the index using log.file.path field in the grok if condition. Actually am I including the multiple file path. so while doing this the index was not creating. but if I include only one, the…

---

## [Extract date from filename, time from log line](https://discuss.elastic.co/t/extract-date-from-filename-time-from-log-line/339251)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 3\
**Last updated:** [August 12, 2023, 6:00am UTC](https://discuss.elastic.co/t/extract-date-from-filename-time-from-log-line/339251 "2023-08-12T06:00:17Z")

</div>

Hi on logstash need to use file as input, output as http. here is the string must be send: mymeasure,tag=mytag field="myfield" 1689682934 this part "1689682934" is timestamp. now question is how can i extract date f…

---

## [Transport errors between elasticsearch nodes](https://discuss.elastic.co/t/transport-errors-between-elasticsearch-nodes/336685)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 10\
**Last updated:** [August 12, 2023, 5:38am UTC](https://discuss.elastic.co/t/transport-errors-between-elasticsearch-nodes/336685 "2023-08-12T05:38:57Z")

</div>

Hi ! I am creating this topic to seek help about a major issues on our Elasticsearch cluster. We have a cluster with nearly 150 nodes (quite a bit :wink: ) We are sometime encountering a big issues, some nodes start t…

---

## [Is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670)

<div class="topic-metadata">

**Author:** [@nfanh](https://discuss.elastic.co/u/nfanh)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 11:01pm UTC](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670 "2023-08-11T23:01:39Z")

</div>

is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?

---

## [Access Elasticsearch with HTTPs and HTTP](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 7:53pm UTC](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661 "2023-08-11T19:53:03Z")

</div>

I configured my Elasticsearch server to be secure, using a proprietary certificate. Similar to the configuration below: # security settings xpack.security.enabled: true xpack.security.autoconfiguration.enabled: false #…

---

## [Split One Lined "Message" field information](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:32pm UTC](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281 "2023-08-11T18:32:58Z")

</div>

Hi, In my dynamic syslogs in eleasticsearch, A fields called "messages" has over 7 lines of data, I need to split that single line into different field. I have a special character "\\r\\n" before required split informatio…

---

## [Script\_field](https://discuss.elastic.co/t/script-field/340660)

<div class="topic-metadata">

**Author:** [@poonamd](https://discuss.elastic.co/u/poonamd)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:21pm UTC](https://discuss.elastic.co/t/script-field/340660 "2023-08-11T17:21:16Z")

</div>

I am trying to return a date from a painless script and then use that date in the query -\> bool -\> filter range query. But this does not seem to work. How should I access the first element of the newVal array? Is the S…

---

## [Elasticsearch cluster search performance is bad after upgrade from 7.17 to 8.8](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592)

<div class="topic-metadata">

**Author:** [@chandra123](https://discuss.elastic.co/u/chandra123)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 5:12pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592 "2023-08-11T17:12:56Z")

</div>

Hello Elasticsearch Community, We recently did in-place upgrade from 7.17 to 8.8 and after which we started to see degraded search performance/latency. We have 150 data nodes and we observed that at most 10 data nodes a…

---

## [ELK Stack into AKS](https://discuss.elastic.co/t/elk-stack-into-aks/339086)

<div class="topic-metadata">

**Author:** [@izbant](https://discuss.elastic.co/u/izbant)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elk-stack-into-aks/339086 "2023-08-11T14:30:11Z")

</div>

Hello, I am trying to deploy ELK Stack with basic license into my AKS cluster, but i am unable to secure connection between logstash and elasticsearch. Is there any documentation for deploying ELK Stack into an AKS clu…

---

## [SAML - Migrate to new IDP](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534)

<div class="topic-metadata">

**Author:** [@heric](https://discuss.elastic.co/u/heric)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 2:29pm UTC](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534 "2023-08-11T14:29:14Z")

</div>

Hi All, I have 5 nodes cluster of elasticsearch integrated to SAML IDP. i want to migrate to new SAML IDP but i don't have working test environment to integrate to this new IDP. Below scenario that i can think of, do …

---

## [Msearch with PHP](https://discuss.elastic.co/t/msearch-with-php/340585)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 1:56pm UTC](https://discuss.elastic.co/t/msearch-with-php/340585 "2023-08-11T13:56:44Z")

</div>

Hello , I am using msearch like this doc - well it is working in kibana . but when I try to do it , in php . does not work . this is my test code - $this-\>elasticSeacrh-\>msearch(\[ …

---

## [Backup Detection Rules and Exceptions](https://discuss.elastic.co/t/backup-detection-rules-and-exceptions/340639)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 12:48pm UTC](https://discuss.elastic.co/t/backup-detection-rules-and-exceptions/340639 "2023-08-11T12:48:29Z")

</div>

Hello everybody, I want to backup all security detection rules and the exceptions I defined for my Cluster. From the documentation I learned how to access rules via the kibana api but there must also be an elasticsearch…

---

## [Node roles impact on nodes](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 12:13pm UTC](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625 "2023-08-11T12:13:10Z")

</div>

Hi, We currently have a really big cluster with 150+ nodes. We are using node attributes to manage the data tiers and our ILM is based on it (node.attr.data). We are currently investigating the impact of migrating to …

---

## [Poll data ingestion to an index should trigger data ingestion to another index](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 10:25am UTC](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617 "2023-08-11T10:25:00Z")

</div>

Hi, Let's say I have to indices, index\_poll and index\_latest. Index\_poll gets metrics data from devices using logstash and beats. When data is ingested into index\_poll, I want this to trigger the data ingestion/updatio…

---

## [Metricbeat](https://discuss.elastic.co/t/metricbeat/340611)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:30am UTC](https://discuss.elastic.co/t/metricbeat/340611 "2023-08-11T05:30:23Z")

</div>

How to get the cpu and memory usage of each users in "CPU Usage \[Metricbeat System\] ECS in ELK" and "Memory Usage \[Metricbeat System\] ECS in ELK". Right now it is showing the metric of 'user' fields which contains all th…

---

## [Parse\_exception, status 400 while reindexing](https://discuss.elastic.co/t/parse-exception-status-400-while-reindexing/340610)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:20am UTC](https://discuss.elastic.co/t/parse-exception-status-400-while-reindexing/340610 "2023-08-11T05:20:00Z")

</div>

We are re-indexing some indices with an updated field mapping. The approach taken is to create a new index with the updated mapping, then copy the existing index into the new index using the Reindex API. Code #create e…

---

## [We have cluster of 4 nodes, where 2 nodes are master and data and other 2 nodes are data nodes, the configuration was working fine since 2 yrs, today we have to restart the cluster and since then we are getting master not discovered exception](https://discuss.elastic.co/t/we-have-cluster-of-4-nodes-where-2-nodes-are-master-and-data-and-other-2-nodes-are-data-nodes-the-configuration-was-working-fine-since-2-yrs-today-we-have-to-restart-the-cluster-and-since-then-we-are-getting-master-not-discovered-exception/340122)

<div class="topic-metadata">

**Author:** [@vishnu\_ishpujani](https://discuss.elastic.co/u/vishnu_ishpujani)\
**Replies:** 25\
**Last updated:** [August 11, 2023, 2:41am UTC](https://discuss.elastic.co/t/we-have-cluster-of-4-nodes-where-2-nodes-are-master-and-data-and-other-2-nodes-are-data-nodes-the-configuration-was-working-fine-since-2-yrs-today-we-have-to-restart-the-cluster-and-since-then-we-are-getting-master-not-discovered-exception/340122 "2023-08-11T02:41:53Z")

</div>

Please fine attached the logs for master 1 and master 2 \[2023-08-04T20:42:56,086\]\[WARN \]\[r.suppressed \] \[ES-Master-2\] path: /\_license, params: {human=false} org.elasticsearch.discovery.MasterNotDiscoveredExc…

---

## [Documentation for UpdateOperation](https://discuss.elastic.co/t/documentation-for-updateoperation/340566)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 7:02pm UTC](https://discuss.elastic.co/t/documentation-for-updateoperation/340566 "2023-08-10T19:02:48Z")

</div>

Is there any documentation for using UpdateOperation with the new Java API Client. I can't seem to find any. Some examples would be helpful. Thanks.

---

## [Unexpected I/O error while de-serializing auth scheme](https://discuss.elastic.co/t/unexpected-i-o-error-while-de-serializing-auth-scheme/340078)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 7\
**Last updated:** [August 10, 2023, 6:40pm UTC](https://discuss.elastic.co/t/unexpected-i-o-error-while-de-serializing-auth-scheme/340078 "2023-08-10T18:40:14Z")

</div>

I have a simple Java Rest client making an index() call. I am getting warning messages: IndexRequest\<Node\> irequest = IndexRequest.of(i -\> i .index("index-b") .id("123") .document(node) ); …

---

## [Fuzzy search](https://discuss.elastic.co/t/fuzzy-search/340584)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 6:17pm UTC](https://discuss.elastic.co/t/fuzzy-search/340584 "2023-08-10T18:17:37Z")

</div>

Hey there, I take in to a project into elasticsearch. The task is a webshop. Right now the problem is, that its possible to search for foo 40 Liter but its not possible for search for foo 40L. My next step is, to use lo…

---

## [How to calculate number of licenses count for my Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 6:14pm UTC](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583 "2023-08-10T18:14:33Z")

</div>

Hi, I want to know what criteria are going to apply, when calculating the number of licenses for my Elastic cluster. Thank you..! Hiruni

---

## [Encryption at rest](https://discuss.elastic.co/t/encryption-at-rest/340580)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 6:02pm UTC](https://discuss.elastic.co/t/encryption-at-rest/340580 "2023-08-10T18:02:55Z")

</div>

Using the docker-compose.yml file found in the official Elastic documents: Install Elasticsearch with Docker | Elasticsearch Guide \[8.9\] | Elastic, is my data encryption at rest? Or do I need to add something to the env…

---

## [Bucket Script in Composite Aggregation using Java client 8.8.2](https://discuss.elastic.co/t/bucket-script-in-composite-aggregation-using-java-client-8-8-2/340569)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 2:08pm UTC](https://discuss.elastic.co/t/bucket-script-in-composite-aggregation-using-java-client-8-8-2/340569 "2023-08-10T14:08:39Z")

</div>

Java method should be written for the following ES query and I'm getting an error on script() function. "AVERAGE": { "bucket\_script": { "buckets\_path": { …

---

## [Updating every document to prepare for reindexing](https://discuss.elastic.co/t/updating-every-document-to-prepare-for-reindexing/340568)

<div class="topic-metadata">

**Author:** [@supernat10](https://discuss.elastic.co/u/supernat10)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:53pm UTC](https://discuss.elastic.co/t/updating-every-document-to-prepare-for-reindexing/340568 "2023-08-10T13:53:09Z")

</div>

Hi, I am in the process of upgrading to the latest version of Elasticsearch, and during our reindex testing from the old cluster to the new one (as we are jumping from 6.8 to 8.x), we ran into a couple of issues with th…

---

## [ElasticsearchException connection refused](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567)

<div class="topic-metadata">

**Author:** [@Hanane1](https://discuss.elastic.co/u/Hanane1)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567 "2023-08-10T13:42:10Z")

</div>

Hello, I have this error when I try to search for something using elasticsearch Caused by: org.springframework.data.elasticsearch.UncategorizedElasticsearchException: java.util.concurrent.ExecutionException: java.net.C…

---

## [Job fails injecting dataframe with variables in index name](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370)

<div class="topic-metadata">

**Author:** [@Joachim\_Rodrigues](https://discuss.elastic.co/u/Joachim_Rodrigues)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 1:08pm UTC](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370 "2023-08-10T13:08:57Z")

</div>

Hello I have this code that injects a dataframe to an elastic cluster 7.9.3 myDataframe.saveToEs("customer-{year}.{month}") But i'm getting this error : User class threw exception: java.lang.Exception: Error(s) durin…

---

## [Please share your wisdom: Passing Elastic key/value pairs instead of log statements?](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489 "2023-08-10T12:57:38Z")

</div>

Hi all. I'm looking for some very general advice. I know ELK started as a way to make sense of log statements, like: "We shipped 12 yellow rubber duckies to France". It will pick out "yellow", "rubber" and "duckies",…

---

## [Open Search Contexts Not Closed After Expiration](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557)

<div class="topic-metadata">

**Author:** [@Jaeger\_Jochimsen](https://discuss.elastic.co/u/Jaeger_Jochimsen)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 12:25pm UTC](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557 "2023-08-10T12:25:54Z")

</div>

We recently had a sudden surge in open search contexts as a result of initiating many scrolls without iterating on them or closing them explicitly. Even though scroll time to live was set to 2 min we continued to have to…

---

## [WARN messages in elsasticsearch.log CFF/OTF](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547)

<div class="topic-metadata">

**Author:** [@shayshy](https://discuss.elastic.co/u/shayshy)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 12:22pm UTC](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547 "2023-08-10T12:22:21Z")

</div>

I have lots of WARN Messages in elasticsearch.log org.apache.pdfbox.pdmodel.font.PDCIDFontType2 WARNING: Found CFF/OTF but expected embedded TTF fount Generic3-Regular and also POI does not currently support template…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=214)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=216)
