# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=219

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 220

---

## [Circuit\_breaking\_exception: \[script\] Too many dynamic script compilations within, max: \[1000/5m\]](https://discuss.elastic.co/t/circuit-breaking-exception-script-too-many-dynamic-script-compilations-within-max-1000-5m/340002)

<div class="topic-metadata">

**Author:** [@Zephery\_Wen](https://discuss.elastic.co/u/Zephery_Wen)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 2:25pm UTC](https://discuss.elastic.co/t/circuit-breaking-exception-script-too-many-dynamic-script-compilations-within-max-1000-5m/340002 "2023-08-03T14:25:38Z")

</div>

I created a stored script in elasticsearch GET \_scripts/xxx-script { "\_id": "xxx-script", "found": true, "script": { "lang": "painless", "source": "ctx.\_source.a = params.a;ctx.\_source.b = params.b;ctx.\_so…

---

## [Elasticsearch exited with code 1, docker elk stack](https://discuss.elastic.co/t/elasticsearch-exited-with-code-1-docker-elk-stack/340029)

<div class="topic-metadata">

**Author:** [@donglobal\_B](https://discuss.elastic.co/u/donglobal_B)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-exited-with-code-1-docker-elk-stack/340029 "2023-08-03T13:41:52Z")

</div>

I am using docker sebp/elk to build my elk environment. normally it runs well, but several days ago, the PC is restarted and when I want to restart the docker, it 99% fail and 1% run successfully. and after inspecting th…

---

## [Multi match query does not work for nested types](https://discuss.elastic.co/t/multi-match-query-does-not-work-for-nested-types/339936)

<div class="topic-metadata">

**Author:** [@Teqqan](https://discuss.elastic.co/u/Teqqan)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 12:26pm UTC](https://discuss.elastic.co/t/multi-match-query-does-not-work-for-nested-types/339936 "2023-08-03T12:26:30Z")

</div>

Hi, I'm trying to perform a multi match query on some data I have structured as nested types. When I search for something like "gadget plushy" I get no matches for a document with two nested fields "gadget" and "plushy"…

---

## [Unable to authenticate user](https://discuss.elastic.co/t/unable-to-authenticate-user/340001)

<div class="topic-metadata">

**Author:** [@Vamsi\_krishna\_Ramaya](https://discuss.elastic.co/u/Vamsi_krishna_Ramaya)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 9:06am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user/340001 "2023-08-03T09:06:16Z")

</div>

Hi, I have been facing some issues with Elasticsearch the error i am getting is “unable to authenticate user \[elastic\] for REST request \[/va\_vrm\_202308030888/\_doc\] Can anyone help to resolve this? Thanks in advance

---

## [Can't install a custom plugin even with a sufficient subscription level - Elastic Cloud](https://discuss.elastic.co/t/cant-install-a-custom-plugin-even-with-a-sufficient-subscription-level-elastic-cloud/339998)

<div class="topic-metadata">

**Author:** [@yechankim-paytalab](https://discuss.elastic.co/u/yechankim-paytalab)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 8:15am UTC](https://discuss.elastic.co/t/cant-install-a-custom-plugin-even-with-a-sufficient-subscription-level-elastic-cloud/339998 "2023-08-03T08:15:01Z")

</div>

Hi there. Somehow I can't install a custom plugin on my Elastic Cloud cluster, even though my subscription level is "Gold" right now. The Type - "An installable plugin (compiled, no source code)" is not clickable for m…

---

## [Search Applications with Search UI](https://discuss.elastic.co/t/search-applications-with-search-ui/340004)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 7:09am UTC](https://discuss.elastic.co/t/search-applications-with-search-ui/340004 "2023-08-03T07:09:41Z")

</div>

Hi, I tried to integrate Search Applications with Search UI as described in the Kibana frontend when I created a new Search Application sample-search-app. import EnginesAPIConnector from "@elastic/search-ui-engines-con…

---

## [Elasticsearch 7.4 query\_then\_fetch slow log](https://discuss.elastic.co/t/elasticsearch-7-4-query-then-fetch-slow-log/339780)

<div class="topic-metadata">

**Author:** [@taoyantu](https://discuss.elastic.co/u/taoyantu)\
**Replies:** 7\
**Last updated:** [August 3, 2023, 1:21am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-query-then-fetch-slow-log/339780 "2023-08-03T01:21:22Z")

</div>

A cluster of elasticsearch version 7.4 is deployed. There are about 20 servers in the cluster. Three nodes are started on each machine. The startup memory occupies 30G. The server is 88-core cpu and 256G memory. The ind…

---

## [Vaccum Deleted Documents](https://discuss.elastic.co/t/vaccum-deleted-documents/339974)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 9:13pm UTC](https://discuss.elastic.co/t/vaccum-deleted-documents/339974 "2023-08-02T21:13:53Z")

</div>

I learned that Elasticsearch does not update a document, but instead, deletes the current document and creates a new one with the updates. It happens that I have several documents that are updated several times during t…

---

## [Error displaying fleet agents -"Error fetching agents Cannot read properties of undefined (reading 'map')"](https://discuss.elastic.co/t/error-displaying-fleet-agents-error-fetching-agents-cannot-read-properties-of-undefined-reading-map/339840)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 3\
**Last updated:** [August 2, 2023, 8:09pm UTC](https://discuss.elastic.co/t/error-displaying-fleet-agents-error-fetching-agents-cannot-read-properties-of-undefined-reading-map/339840 "2023-08-02T20:09:56Z")

</div>

One fine morning, fleet section just decided not to show agents enrolled in a particular policy. I suspected two issues, @timestamp was not present in some of the fleet related indices, I added mapping for the same, seco…

---

## [\_template vs \_index\_template](https://discuss.elastic.co/t/template-vs-index-template/339969)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:13pm UTC](https://discuss.elastic.co/t/template-vs-index-template/339969 "2023-08-02T19:13:16Z")

</div>

I'm running ES 7.15. \_template seems to be legacy. \_index\_template is the one moving forward. I also noticed that there's no command to list all \_index\_templates. Is there a template migration guide somewhere?

---

## [Job for elasticsearch.service failed because the control process exited with error code.](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-the-control-process-exited-with-error-code/339884)

<div class="topic-metadata">

**Author:** [@Armel](https://discuss.elastic.co/u/Armel)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 6:13pm UTC](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-the-control-process-exited-with-error-code/339884 "2023-08-02T18:13:38Z")

</div>

---

## [How to filter out strings starting with any from a list of strings](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:18pm UTC](https://discuss.elastic.co/t/how-to-filter-out-strings-starting-with-any-from-a-list-of-strings/339948 "2023-08-02T14:18:33Z")

</div>

Hi, I'm wanting to filter out strings starting with a number of characters. I've been able to solve this using a DSL query. Let me provide the example first: # Cleanup DELETE discuss-338708 # Create an index PUT discus…

---

## [Remote Reindex from a datastream to another index](https://discuss.elastic.co/t/remote-reindex-from-a-datastream-to-another-index/339951)

<div class="topic-metadata">

**Author:** [@San72](https://discuss.elastic.co/u/San72)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 2:37pm UTC](https://discuss.elastic.co/t/remote-reindex-from-a-datastream-to-another-index/339951 "2023-08-02T14:37:59Z")

</div>

Hi Guys, we are trying to reindex some data (from another cluster) and ran into an issue. POST \_reindex { "source": { "remote": { "host": "https://COOL\_IP\_ADDRESS:9200", "username": "elastic", "passw…

---

## [Trying to delete documents in index older than XXX](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852)

<div class="topic-metadata">

**Author:** [@guy\_guy](https://discuss.elastic.co/u/guy_guy)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 7:45pm UTC](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852 "2023-08-01T19:45:00Z")

</div>

I need to delete some documents from indexes older than XXX days, but delete\_by\_query doesn't seem to be working for me. Here is an example query I'm trying to run POST shipment-log/\_delete\_by\_query { "query": { …

---

## [Unable to get logs to elastalert with helk](https://discuss.elastic.co/t/unable-to-get-logs-to-elastalert-with-helk/339926)

<div class="topic-metadata">

**Author:** [@deloittepocra](https://discuss.elastic.co/u/deloittepocra)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 1:16pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-to-elastalert-with-helk/339926 "2023-08-02T13:16:59Z")

</div>

Hi Team, I have successfully set up helk by following the instructions provided in the GitHub repository. Additionally, I have configured winlogbeat to send my event/sysmon logs to Kibana through Kafka. Now, my goal is …

---

## [Unknown reason of All Elastic indices deletion repeatedly](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 6\
**Last updated:** [August 2, 2023, 12:25pm UTC](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934 "2023-08-02T12:25:49Z")

</div>

My elasticsearch instance is deployed in an EC2 instance and due to some reason, all my indices got deleted on 20th of July. After recovering the data on 30th, they got deleted again on 31st and then on 1st of August aga…

---

## [Filter vector search results to get only relevant documents?](https://discuss.elastic.co/t/filter-vector-search-results-to-get-only-relevant-documents/339543)

<div class="topic-metadata">

**Author:** [@john\_nicolas](https://discuss.elastic.co/u/john_nicolas)\
**Replies:** 10\
**Last updated:** [August 2, 2023, 12:15pm UTC](https://discuss.elastic.co/t/filter-vector-search-results-to-get-only-relevant-documents/339543 "2023-08-02T12:15:55Z")

</div>

I am not an expert in elastic queries, I have not found a solution to filter my results. My index contains 450,000 documents. The issue is that when I perform a search, it always returns all 450,000 documents, sorted by …

---

## [Caused by: java.lang.NoSuchMethodError: 'void co.elastic.clients.transport.rest\_client.RestClientTransport.\<init\>](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-void-co-elastic-clients-transport-rest-client-restclienttransport-init/339573)

<div class="topic-metadata">

**Author:** [@aph](https://discuss.elastic.co/u/aph)\
**Replies:** 8\
**Last updated:** [August 2, 2023, 12:04pm UTC](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-void-co-elastic-clients-transport-rest-client-restclienttransport-init/339573 "2023-08-02T12:04:08Z")

</div>

Maven build is failing with no method found error. Caused by: java.lang.NoSuchMethodError: 'void co.elastic.clients.transport.rest\_client.RestClientTransport.\<init\> Here is the pom.xml \<?xml version="1.0" encoding="UT…

---

## [Fail to start Elasticsearch in Linux](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920)

<div class="topic-metadata">

**Author:** [@Saeed\_Ramezani](https://discuss.elastic.co/u/Saeed_Ramezani)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 10:11am UTC](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920 "2023-08-02T10:11:49Z")

</div>

I'm just trying to install Elasticsearch on Linux(ubuntu 22) by this article All the following commands passed by but when I reach to command ./bin/elasticsearch this error accord: ERROR: Elasticsearch exited unexpecte…

---

## [Cannot use \_delete\_by\_query in ESSingleNodeTestCase tests with 8.X version.](https://discuss.elastic.co/t/cannot-use-delete-by-query-in-essinglenodetestcase-tests-with-8-x-version/338564)

<div class="topic-metadata">

**Author:** [@fusiasty](https://discuss.elastic.co/u/fusiasty)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 8:32am UTC](https://discuss.elastic.co/t/cannot-use-delete-by-query-in-essinglenodetestcase-tests-with-8-x-version/338564 "2023-08-02T08:32:12Z")

</div>

Hi, I'm just migrating my application from ES 7.17 to ES 8.8.2 and faced one issue. I'm using ESSingleNodeTestCase to check my implementation. My application uses Java API Client 8.8. I figured out how to run HTTP in…

---

## [How to wait for indexing to finish before closing bulkingester](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 8:15am UTC](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875 "2023-08-02T08:15:08Z")

</div>

how to wait for indexing to finish before closing bulkingester. previously we have awaitClose() for bulkprocessor. is is same for bulkingester? there is no awaitClose, but there is wait() in bulkIngester. I am not sur…

---

## [Why are my indexes automatically removed?](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857)

<div class="topic-metadata">

**Author:** [@Miguel3](https://discuss.elastic.co/u/Miguel3)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 8:13am UTC](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857 "2023-08-02T08:13:59Z")

</div>

I have a problem with my elastic instance, after a few days of creating and uploading data to my indexes they are automatically deleted, I don't understand why it's happening and I don't see any message in the logs that …

---

## [Too\_many\_clauses: maxClauseCount is set to 1337](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894)

<div class="topic-metadata">

**Author:** [@drorp\_korra](https://discuss.elastic.co/u/drorp_korra)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:29am UTC](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894 "2023-08-02T07:29:16Z")

</div>

Hello, i'm getting the this error: ApiError(500, 'search\_phase\_execution\_exception', 'too\_many\_clauses: maxClauseCount is set to 1337') The query that is use is: { "bool": { "filter": \[ { "term": { "fi…

---

## [{“statusCode”:503,”error”:”Service Unavailable”,”message”:”License is not available.”}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:15am UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891 "2023-08-02T07:15:18Z")

</div>

Hello, Since a few days its starting again with the same error. Almost every morning when I check the machine its stopped with the following error when I open the URL. {"statusCode":503,"error":"Service Unavailable","m…

---

## [When I signed up for Elastic Cloud and clicked on "Create deployment," after logging in, the dashboard appears empty.](https://discuss.elastic.co/t/when-i-signed-up-for-elastic-cloud-and-clicked-on-create-deployment-after-logging-in-the-dashboard-appears-empty/339859)

<div class="topic-metadata">

**Author:** [@danbeeStudy](https://discuss.elastic.co/u/danbeeStudy)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 5:20am UTC](https://discuss.elastic.co/t/when-i-signed-up-for-elastic-cloud-and-clicked-on-create-deployment-after-logging-in-the-dashboard-appears-empty/339859 "2023-08-02T05:20:29Z")

</div>

When I signed up for Elastic Cloud and clicked on "Create deployment," after logging in, the dashboard appears empty. How can I proceed? By creating the "Create deployment," is it possible for the Elasticsearch Servic…

---

## [Field mapping \[field with constant name\]. --\> \[field with a changing/dynamic name\] --\> \[fields with constant names\]](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886 "2023-08-02T05:12:34Z")

</div>

hi.. i've run into a problem with elasticsearch mapping.. i'm sure there is a way to deal with it.. but i cant figure it out.. or even the terminology to use to search for a solution. i'm trying to import a json from sh…

---

## [Installing Elasticsearch 7.17](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887 "2023-08-02T05:12:10Z")

</div>

I am trying to reinstall the elasticsearch same version on ubuntu 20.04 but I am getting the below error again and again. I have tried almost all the solution given on google but the error was not resolved. Previously sa…

---

## [Using Maxmind databases without access to ES cluster](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 4:47am UTC](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736 "2023-08-02T04:47:38Z")

</div>

Hi, I'm using a ES cluster (v8.8.0) running on Kubenetes that is managed by someone else, and I was told by them that I would not be able to directly access the cluster. Previously, when I was managing my own cluster r…

---

## [ELK Update](https://discuss.elastic.co/t/elk-update/339880)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 3:19am UTC](https://discuss.elastic.co/t/elk-update/339880 "2023-08-02T03:19:27Z")

</div>

Hello everyone, I currently have an ELK version 7.6.0 implementation which I use hand in hand with Splunk version 8.0.1. I realize they are old versions, but it is working for what I need. The plugin I use from Splunk…

---

## [Multi-index query returning no results](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855)

<div class="topic-metadata">

**Author:** [@PedroD](https://discuss.elastic.co/u/PedroD)\
**Replies:** 4\
**Last updated:** [August 2, 2023, 12:01am UTC](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855 "2023-08-02T00:01:47Z")

</div>

Hey guys, I have 2 different indexes that store information about my users. Both use a hashed version of their id\_number as their doc\_id, I\`m trying to create a query that will look for different fields in both indexes …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=218)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=220)
