# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=218

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 219

---

## [Security autoconfiguration information](https://discuss.elastic.co/t/security-autoconfiguration-information/340100)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 6\
**Last updated:** [August 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/security-autoconfiguration-information/340100 "2023-08-07T13:33:15Z")

</div>

I have just installed the newest version of Elasticsearch using the official guide but did not come across 'Security autoconfiguration information' screen. Now when I try to start Elasticsearch using the following comman…

---

## [Unexpected HTTP Error (503) when running Elasticsearch tools](https://discuss.elastic.co/t/unexpected-http-error-503-when-running-elasticsearch-tools/340263)

<div class="topic-metadata">

**Author:** [@General-Trident](https://discuss.elastic.co/u/General-Trident)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 11:09am UTC](https://discuss.elastic.co/t/unexpected-http-error-503-when-running-elasticsearch-tools/340263 "2023-08-07T11:09:09Z")

</div>

Need help on how to resolve issue at Elasticsearch tools not working All permissions on $ES\_HOME using command ls -ltr : \[root@localhost bin\]# ls -ltr total 3204 -rwxr-xr-x. 1 root root 353 Jul 19 21:46 elasticsear…

---

## [Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create\<main\>, action\_result: false", :backtrace=\>nil](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/340116)

<div class="topic-metadata">

**Author:** [@ItsGautam](https://discuss.elastic.co/u/ItsGautam)\
**Replies:** 3\
**Last updated:** [August 7, 2023, 5:30am UTC](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/340116 "2023-08-07T05:30:44Z")

</div>

Hi, I am new to the elasticsearch. i ve tried to find the solution but ...... \[2023-08-04T13:09:08,778\]\[INFO \]\[logstash.javapipeline \]\[main\] Pipeline terminated {"pipeline.id"=\>"main"} \[2023-08-04T13:09:08,806\]\[ERR…

---

## [Logstash always queue in multiple pipeline](https://discuss.elastic.co/t/logstash-always-queue-in-multiple-pipeline/340131)

<div class="topic-metadata">

**Author:** [@jact](https://discuss.elastic.co/u/jact)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 3:13am UTC](https://discuss.elastic.co/t/logstash-always-queue-in-multiple-pipeline/340131 "2023-08-07T03:13:45Z")

</div>

Hi Master, i'm using logstash 8.8 i'm on stuck in this condtion. after i created multiple pipeline like this - pipeline.id: beats path.config: "/etc/logstash/conf.d/beats.conf" pipeline.workers: 3 - pipeline.id: …

---

## [Noop Query](https://discuss.elastic.co/t/noop-query/340208)

<div class="topic-metadata">

**Author:** [@yonzmeer](https://discuss.elastic.co/u/yonzmeer)\
**Replies:** 0\
**Last updated:** [August 6, 2023, 8:03pm UTC](https://discuss.elastic.co/t/noop-query/340208 "2023-08-06T20:03:11Z")

</div>

Hello, I'm building a some-what generic converter from an object that contains lists of values, to a search requests for elasticsearch, for example: { names: \["john", "bob"\], cities: \["boston", "moscow"\] } tur…

---

## [Did anything change concerning dashboards from version 6.3 to version 7.5?](https://discuss.elastic.co/t/did-anything-change-concerning-dashboards-from-version-6-3-to-version-7-5/338584)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 13\
**Last updated:** [August 6, 2023, 6:54pm UTC](https://discuss.elastic.co/t/did-anything-change-concerning-dashboards-from-version-6-3-to-version-7-5/338584 "2023-08-06T18:54:04Z")

</div>

Hello, Did anything change concerning dashboards from version 6.3 to version 7.5 ? I have a working dashboard in one environment with version 6.3, and the exactly same dashboard doesn't work from version 7.5. The dash…

---

## [Failure to elect master, v7.17](https://discuss.elastic.co/t/failure-to-elect-master-v7-17/340149)

<div class="topic-metadata">

**Author:** [@bobus](https://discuss.elastic.co/u/bobus)\
**Replies:** 19\
**Last updated:** [August 6, 2023, 3:28pm UTC](https://discuss.elastic.co/t/failure-to-elect-master-v7-17/340149 "2023-08-06T15:28:58Z")

</div>

I'm pulling my hair out trying to figure out why my three nodes, running as docker-compose containers on 3 separate Ubuntu 22.04LTS hosts, cannot start. The 3 nodes discover each other but fail to elect a master. When I…

---

## [Elasticsearch on a single node docker container after mounting azure storage gives .es\_temp\_file file not found error](https://discuss.elastic.co/t/elasticsearch-on-a-single-node-docker-container-after-mounting-azure-storage-gives-es-temp-file-file-not-found-error/340174)

<div class="topic-metadata">

**Author:** [@sphnix](https://discuss.elastic.co/u/sphnix)\
**Replies:** 1\
**Last updated:** [August 5, 2023, 8:07pm UTC](https://discuss.elastic.co/t/elasticsearch-on-a-single-node-docker-container-after-mounting-azure-storage-gives-es-temp-file-file-not-found-error/340174 "2023-08-05T20:07:44Z")

</div>

Hi. I am running elasticsearch as single node. While starting the container it gives .es\_temp\_file not found error. Tried mounting blobfuse2 but didnot help. {"type": "server", "timestamp": "2023-08-05T08:53:25,540Z", …

---

## [Not able to install elastiKNN plugin in elastic search](https://discuss.elastic.co/t/not-able-to-install-elastiknn-plugin-in-elastic-search/339049)

<div class="topic-metadata">

**Author:** [@Shreeyash\_Pandey](https://discuss.elastic.co/u/Shreeyash_Pandey)\
**Replies:** 2\
**Last updated:** [August 5, 2023, 7:09pm UTC](https://discuss.elastic.co/t/not-able-to-install-elastiknn-plugin-in-elastic-search/339049 "2023-08-05T19:09:37Z")

</div>

I am getting this error during installation of my elsaticKNN plugin. Please let me know the compatible version for my elasticsearch(7.12.0) -\> Installing Release 7.12.0.5 · alexklibisz/elastiknn · GitHub -\> Downloading…

---

## [Stored fields getting deleted upon partial update of the document in elastic search](https://discuss.elastic.co/t/stored-fields-getting-deleted-upon-partial-update-of-the-document-in-elastic-search/340011)

<div class="topic-metadata">

**Author:** [@Jagadeesh12](https://discuss.elastic.co/u/Jagadeesh12)\
**Replies:** 4\
**Last updated:** [August 5, 2023, 1:12pm UTC](https://discuss.elastic.co/t/stored-fields-getting-deleted-upon-partial-update-of-the-document-in-elastic-search/340011 "2023-08-05T13:12:32Z")

</div>

Hi. I have an index which have stored fields in the documents. But, upon updating the document with new fields (partially update), the previously existing stored fields are getting deleted. Create the Index PUT itf\_t…

---

## [Elasticsearch search based on term position and fuzzy](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163)

<div class="topic-metadata">

**Author:** [@JohnsM](https://discuss.elastic.co/u/JohnsM)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 10:39pm UTC](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163 "2023-08-04T22:39:30Z")

</div>

I am a beginner in Elasticsearch and I try to combine a query with term position and fuzzy and the results are not what I expected. I tried this query { "query": { "bool": { "must": \[ …

---

## [Monitor users (requests, CPU usage, etc.)](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018 "2023-08-04T19:23:28Z")

</div>

Hello, I'd like to be able to find out what my users are doing, and more specifically list the users who are consuming CPU, consult the list of "big" requests and the linked user. Basically, I'd like to know if someone…

---

## [Wildcard query took 200 seconds with version 8.8 but only a few seconds with 6.3](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152)

<div class="topic-metadata">

**Author:** [@xluan](https://discuss.elastic.co/u/xluan)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152 "2023-08-04T16:53:49Z")

</div>

We are migrating Elastic from 6.3 to 8,8. But the wildcard queries (in query string) are excessively slow in 8,8 as compared with 6.3. For example, for query "abcddcba\*" that does not actually match anything, it takes 4 …

---

## [How we can remove deduplication event in logstash](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060)

<div class="topic-metadata">

**Author:** [@Sukhdeob\_95](https://discuss.elastic.co/u/Sukhdeob_95)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060 "2023-08-04T16:53:48Z")

</div>

I want to remove the duplicate event based on particular field of my input i wrote logic like following but i got an error aggregate { task\_id =\> "%{\[meta\]\[ingestionHash\]}" code =\> " map\['@metadata'\]\['keep'\] ||= ev…

---

## [Is there a way to have an aggregation bucket that delivery the sum of other values](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148)

<div class="topic-metadata">

**Author:** [@Fabio\_Batalha](https://discuss.elastic.co/u/Fabio_Batalha)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 3:35pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148 "2023-08-04T15:35:26Z")

</div>

I'm doing an aggregation, limiting the buckets size to 6, and I would have a bucket having the sum of the other values. I see Kibana deal with that in a hidden way. At Kibana we can configure an aggregation to delivery …

---

## [Becoming ECS Compliant](https://discuss.elastic.co/t/becoming-ecs-compliant/340080)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 3:33pm UTC](https://discuss.elastic.co/t/becoming-ecs-compliant/340080 "2023-08-04T15:33:31Z")

</div>

I've been ingesting datasets from before ECS was a thing that now have an ECS mapping. What would be the most efficient means of ingesting data (moving forward) so that it is ECS compliant? Examples of datasets are For…

---

## [MD5 hash of fingerprint processor in ingest pipeline](https://discuss.elastic.co/t/md5-hash-of-fingerprint-processor-in-ingest-pipeline/340135)

<div class="topic-metadata">

**Author:** [@Zaid\_Raza](https://discuss.elastic.co/u/Zaid_Raza)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 1:39pm UTC](https://discuss.elastic.co/t/md5-hash-of-fingerprint-processor-in-ingest-pipeline/340135 "2023-08-04T13:39:48Z")

</div>

Hi, My elastic stack version is 8.5.3. I am using a fingerprint processor in ingest pipeline to create an MD5 hash. By default, it gives a hash in base64. I want a 128-bit MD5 hash. Is there any solution to this issue?

---

## [Elastic Serverless Forwarder for AWS adding reserved \_id field when sending to logstash](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084)

<div class="topic-metadata">

**Author:** [@stabbotco1](https://discuss.elastic.co/u/stabbotco1)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084 "2023-08-04T12:55:27Z")

</div>

Hi All! I am new to ES, so apologies in advance if I mis-state some things. We are looking to use the ES Serverless Forwarder for AWS (Elastic Serverless Forwarder for AWS | Elastic Serverless Forwarder Guide | Elastic)…

---

## [Sorting help with query](https://discuss.elastic.co/t/sorting-help-with-query/340128)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 11:58am UTC](https://discuss.elastic.co/t/sorting-help-with-query/340128 "2023-08-04T11:58:40Z")

</div>

{ "query": { "bool": { "must": \[ { "term": { "status": { "value": 1 } } } \], "should": \[ { "wildcard": {…

---

## [Elasticsearch not generating certificates and enrollment tokens when started from a DockerFile](https://discuss.elastic.co/t/elasticsearch-not-generating-certificates-and-enrollment-tokens-when-started-from-a-dockerfile/340119)

<div class="topic-metadata">

**Author:** [@Tanmay\_Sharma](https://discuss.elastic.co/u/Tanmay_Sharma)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 9:38am UTC](https://discuss.elastic.co/t/elasticsearch-not-generating-certificates-and-enrollment-tokens-when-started-from-a-dockerfile/340119 "2023-08-04T09:38:22Z")

</div>

Hello everyone, i'm trying to spin up a docker container for elasticsearch using the Dockerfile: FROM elasticsearch:8.8.1 # Set the environment variables for Elasticsearch. ENV discovery.type=single-node ENV xpack.secu…

---

## [Search slowlog in JSON format is truncating the query](https://discuss.elastic.co/t/search-slowlog-in-json-format-is-truncating-the-query/340095)

<div class="topic-metadata">

**Author:** [@gshankar-elastic](https://discuss.elastic.co/u/gshankar-elastic)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 7:53am UTC](https://discuss.elastic.co/t/search-slowlog-in-json-format-is-truncating-the-query/340095 "2023-08-04T07:53:46Z")

</div>

I am on Elasticsearch 7.10.0 and recently I have changed the slowlogs format from plaintext to json anticipating that large query truncation issue will be resolved automatically in the json format. But I am still seeing …

---

## [Help me to query this document](https://discuss.elastic.co/t/help-me-to-query-this-document/340110)

<div class="topic-metadata">

**Author:** [@marcin\_cron](https://discuss.elastic.co/u/marcin_cron)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 9:19am UTC](https://discuss.elastic.co/t/help-me-to-query-this-document/340110 "2023-08-04T09:19:02Z")

</div>

This is my documents: //document 1 { "place": "galaxy", "range": { "area": { "planet": "mars", "country": \[ -----------country 1------------------ …

---

## [Elasticsearch - Attempted to send a bulk request but Elasticsearch appears to be unreachable or down](https://discuss.elastic.co/t/elasticsearch-attempted-to-send-a-bulk-request-but-elasticsearch-appears-to-be-unreachable-or-down/340101)

<div class="topic-metadata">

**Author:** [@aswin\_parakkal](https://discuss.elastic.co/u/aswin_parakkal)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 6:39am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-send-a-bulk-request-but-elasticsearch-appears-to-be-unreachable-or-down/340101 "2023-08-04T06:39:27Z")

</div>

Hyy👋, My Elasticsearch is running properly but sometimes it shows this error . Attempted to send a bulk request but there are no living connections in the pool (perhaps Elasticsearch is unreachable or down?) {:me…

---

## [Elasticsearch keep migrating shards out of one of my data node](https://discuss.elastic.co/t/elasticsearch-keep-migrating-shards-out-of-one-of-my-data-node/340041)

<div class="topic-metadata">

**Author:** [@Zeeshan\_Alam](https://discuss.elastic.co/u/Zeeshan_Alam)\
**Replies:** 4\
**Last updated:** [August 4, 2023, 3:48am UTC](https://discuss.elastic.co/t/elasticsearch-keep-migrating-shards-out-of-one-of-my-data-node/340041 "2023-08-04T03:48:27Z")

</div>

Elasticsearch keep migrating shards out of one of my data node data-mbesdrtp21. This cluster have mix of plain index and data streams. Around 10-15 shards get allocated to this node and then they are reallocated to othe…

---

## [Has anyone successfully stood up a multi-node elasticsearch cluster with kibana and logstash through docker images?](https://discuss.elastic.co/t/has-anyone-successfully-stood-up-a-multi-node-elasticsearch-cluster-with-kibana-and-logstash-through-docker-images/340082)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 9:30pm UTC](https://discuss.elastic.co/t/has-anyone-successfully-stood-up-a-multi-node-elasticsearch-cluster-with-kibana-and-logstash-through-docker-images/340082 "2023-08-03T21:30:52Z")

</div>

I've been on this project for while now and I not sure where I'm going wrong. My goal is to setup the ELK stack (elasticsearch, kibana, and logstash) on one host then a second elasticsearch node on a different host usin…

---

## [\`host.name\` and \`host.hostname\`](https://discuss.elastic.co/t/host-name-and-host-hostname/339742)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 9:24pm UTC](https://discuss.elastic.co/t/host-name-and-host-hostname/339742 "2023-08-03T21:24:27Z")

</div>

What kind of values are folks using for host.name and host.hostname? Basically I think ECS is encouraging FQDN in host.name and short name in host.hostname?

---

## [We can't find products matching the selection](https://discuss.elastic.co/t/we-cant-find-products-matching-the-selection/340075)

<div class="topic-metadata">

**Author:** [@Denis\_Belik](https://discuss.elastic.co/u/Denis_Belik)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 7:33pm UTC](https://discuss.elastic.co/t/we-cant-find-products-matching-the-selection/340075 "2023-08-03T19:33:06Z")

</div>

There is an online store on Magento 2.3.2 When you open a department , a blank page appears without product cards with an error "We can't find products matching the selection.". The hosting technical support said that…

---

## [Moving preconfigured Elasticsearch and kibana (with custom indexes and dashboards) to another server](https://discuss.elastic.co/t/moving-preconfigured-elasticsearch-and-kibana-with-custom-indexes-and-dashboards-to-another-server/340072)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 5:55pm UTC](https://discuss.elastic.co/t/moving-preconfigured-elasticsearch-and-kibana-with-custom-indexes-and-dashboards-to-another-server/340072 "2023-08-03T17:55:26Z")

</div>

Hello there, I am working on a large ec2 ubuntu instance where I manually downloaded and installed elasticsearch and kibana (I didn't use docker) . I connected my stack with external data sources and made a lot of cust…

---

## [Knn as percolator query](https://discuss.elastic.co/t/knn-as-percolator-query/340066)

<div class="topic-metadata">

**Author:** [@Matthew\_Pollard](https://discuss.elastic.co/u/Matthew_Pollard)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 4:37pm UTC](https://discuss.elastic.co/t/knn-as-percolator-query/340066 "2023-08-03T16:37:35Z")

</div>

Hi Just wondering whether it is currently possible to use a knn query as a percolater query - my feeling is that this is currently not possible but just checking? Thanks Matthew

---

## [Error while creating new Fields in Elastic Search](https://discuss.elastic.co/t/error-while-creating-new-fields-in-elastic-search/340064)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 3:35pm UTC](https://discuss.elastic.co/t/error-while-creating-new-fields-in-elastic-search/340064 "2023-08-03T15:35:55Z")

</div>

hello , Can anyone help, I'm new to elasticsearch Kibana but learnt in recent days to understand the usage. I have a Index name "logstash-\*" which receives logs constantly, my task is to filter from all logs in field "…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=217)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=219)
