# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=22

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 23

---

## [Sending Email to DL via Watcher](https://discuss.elastic.co/t/sending-email-to-dl-via-watcher/380937)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 1\
**Last updated:** [August 11, 2025, 3:28pm UTC](https://discuss.elastic.co/t/sending-email-to-dl-via-watcher/380937 "2025-08-11T15:28:49Z")

</div>

Hi Team, It is observed that individual Id's are receiving the email via Watcher without any issues but when a DL is added in “to”, the message/email does not arrive. Watcher executes & ends with success but message no…

---

## [This node is a fully-formed single-node cluster](https://discuss.elastic.co/t/this-node-is-a-fully-formed-single-node-cluster/380884)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 2\
**Last updated:** [August 10, 2025, 10:00pm UTC](https://discuss.elastic.co/t/this-node-is-a-fully-formed-single-node-cluster/380884 "2025-08-10T22:00:27Z")

</div>

Hey all I’m trying to set up a multi node cluster but this node was a single node cluster originally. I’ve deleted the /var/lib/elasticsearch/\* folder which should be the data folder on Ubuntu 24.04 but still getting t…

---

## [Elastic-agent output connection refuse error while setting up mutual TLS for fleet](https://discuss.elastic.co/t/elastic-agent-output-connection-refuse-error-while-setting-up-mutual-tls-for-fleet/380497)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 10\
**Last updated:** [August 9, 2025, 6:00am UTC](https://discuss.elastic.co/t/elastic-agent-output-connection-refuse-error-while-setting-up-mutual-tls-for-fleet/380497 "2025-08-09T06:00:21Z")

</div>

First let me start by explaining what i am trying to achieve. I have a cluster of 3 nodes (kibana is also installed on the same VM with one of the nodes) -each of 3 nodes have all the roles- with mutual TLS between clust…

---

## [Using dense\_vector with script params](https://discuss.elastic.co/t/using-dense-vector-with-script-params/380908)

<div class="topic-metadata">

**Author:** [@joellupfer](https://discuss.elastic.co/u/joellupfer)\
**Replies:** 1\
**Last updated:** [August 8, 2025, 3:07pm UTC](https://discuss.elastic.co/t/using-dense-vector-with-script-params/380908 "2025-08-08T15:07:46Z")

</div>

Hello! I am currently developing a script that utilizes text embedding vectors. The relevant portion of the mapping is shown below (please disregard the remaining parts, as this is intended solely for testing purposes). …

---

## [Failed to create repository](https://discuss.elastic.co/t/failed-to-create-repository/380705)

<div class="topic-metadata">

**Author:** [@deepakraja](https://discuss.elastic.co/u/deepakraja)\
**Replies:** 3\
**Last updated:** [August 8, 2025, 8:52am UTC](https://discuss.elastic.co/t/failed-to-create-repository/380705 "2025-08-08T08:52:25Z")

</div>

Hi, I was trying to create a repository on elasticsearch for camunda backup. On the documentation it mentioned to add local mounted path into the yaml using path.repo parameter. kindly guide how to refer this parameter i…

---

## [Indices with ILM policies are not included in Snapshot and Restore Operations](https://discuss.elastic.co/t/indices-with-ilm-policies-are-not-included-in-snapshot-and-restore-operations/380454)

<div class="topic-metadata">

**Author:** [@Rajesh\_Kannan](https://discuss.elastic.co/u/Rajesh_Kannan)\
**Replies:** 7\
**Last updated:** [August 8, 2025, 5:20am UTC](https://discuss.elastic.co/t/indices-with-ilm-policies-are-not-included-in-snapshot-and-restore-operations/380454 "2025-08-08T05:20:40Z")

</div>

There are approximately 4,000 indices in Elasticsearch, all of which are in an open state. However, during the scheduled backup, only 1,660 indices were successfully backed up, while the remaining ones were ignored. Upon…

---

## [Elastic webhook is showing ssl error](https://discuss.elastic.co/t/elastic-webhook-is-showing-ssl-error/380680)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 7\
**Last updated:** [August 7, 2025, 8:18pm UTC](https://discuss.elastic.co/t/elastic-webhook-is-showing-ssl-error/380680 "2025-08-07T20:18:41Z")

</div>

Hi , I am trying to send health check up through watcher to splunk but getting ssl exception while executing watcher { "trigger": { "schedule": { "cron": "0 0 9 ? \* \*" } }, "input": { "http": { …

---

## [How to use Integrations on onenode ELK Instance](https://discuss.elastic.co/t/how-to-use-integrations-on-onenode-elk-instance/380699)

<div class="topic-metadata">

**Author:** [@Elasticisti](https://discuss.elastic.co/u/Elasticisti)\
**Replies:** 7\
**Last updated:** [August 7, 2025, 4:16pm UTC](https://discuss.elastic.co/t/how-to-use-integrations-on-onenode-elk-instance/380699 "2025-08-07T16:16:48Z")

</div>

Hi There, we have set up a small ELK instance with one Stand Alone Agent on a JIRA Testserver. The agent reports the logs of the hosts correctly, we would however need the JIRA Logs as well. We should use a JIRA Connec…

---

## [Title: Implementing S3 Buffer Layer for Elasticsearch - Looking for Community Feedback](https://discuss.elastic.co/t/title-implementing-s3-buffer-layer-for-elasticsearch-looking-for-community-feedback/380778)

<div class="topic-metadata">

**Author:** [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Replies:** 11\
**Last updated:** [August 7, 2025, 4:02pm UTC](https://discuss.elastic.co/t/title-implementing-s3-buffer-layer-for-elasticsearch-looking-for-community-feedback/380778 "2025-08-07T16:02:43Z")

</div>

Hi everyone, We're evaluating an S3-based buffer architecture to address circuit breaker issues and reduce costs in our ECK deployment. Would really appreciate insights from anyone who's implemented similar patterns. T…

---

## [CorruptIndexException after boot](https://discuss.elastic.co/t/corruptindexexception-after-boot/380805)

<div class="topic-metadata">

**Author:** [@Oozza](https://discuss.elastic.co/u/Oozza)\
**Replies:** 5\
**Last updated:** [August 7, 2025, 1:24pm UTC](https://discuss.elastic.co/t/corruptindexexception-after-boot/380805 "2025-08-07T13:24:23Z")

</div>

Hi, I should have done some snapshots, but I have to ask. Is it possible to recover from this error? ES doesn´t start. ES version is 7.17.24. One-node cluster. Thank you \[2025-08-06T10:25:59,213\]\[ERROR\]\[o.e.b.Bootstrap…

---

## [How do I migrate Elasticsearch Data Nodes by Moving Virtual Disks Between VMs](https://discuss.elastic.co/t/how-do-i-migrate-elasticsearch-data-nodes-by-moving-virtual-disks-between-vms/379539)

<div class="topic-metadata">

**Author:** [@KimuDesign](https://discuss.elastic.co/u/KimuDesign)\
**Replies:** 9\
**Last updated:** [August 7, 2025, 1:06pm UTC](https://discuss.elastic.co/t/how-do-i-migrate-elasticsearch-data-nodes-by-moving-virtual-disks-between-vms/379539 "2025-08-07T13:06:24Z")

</div>

Hi all, I have a production Elasticsearch cluster v 7.10.2 with 4 data nodes and 3 master nodes. Most of our indices have 4 shards and 1 replica. We perform a rollup of indices nightly at 3 AM. I’m planning to migrate …

---

## [Elastisearch Start : java.nio.file.AccessDeniedException: /etc/elasticsearch/elasticsearch.keystore](https://discuss.elastic.co/t/elastisearch-start-java-nio-file-accessdeniedexception-etc-elasticsearch-elasticsearch-keystore/380864)

<div class="topic-metadata">

**Author:** [@Elasticisti](https://discuss.elastic.co/u/Elasticisti)\
**Replies:** 1\
**Last updated:** [August 7, 2025, 11:56am UTC](https://discuss.elastic.co/t/elastisearch-start-java-nio-file-accessdeniedexception-etc-elasticsearch-elasticsearch-keystore/380864 "2025-08-07T11:56:47Z")

</div>

Just now I am resinstalling ELk with this If I would like to start Elasticsearch, I receives the follwing error: Aug 07 12:34:26 ESXELX1300 systemd-entrypoint\[6090\]: java.nio.file.AccessDeniedException: /etc/elastics…

---

## [Issues upgrading Elasticsearch from 8 to 9 due to old 7.x indices and restricted Kibana indices](https://discuss.elastic.co/t/issues-upgrading-elasticsearch-from-8-to-9-due-to-old-7-x-indices-and-restricted-kibana-indices/379133)

<div class="topic-metadata">

**Author:** [@axvfvv79zcx57xv7k](https://discuss.elastic.co/u/axvfvv79zcx57xv7k)\
**Replies:** 17\
**Last updated:** [August 6, 2025, 6:29pm UTC](https://discuss.elastic.co/t/issues-upgrading-elasticsearch-from-8-to-9-due-to-old-7-x-indices-and-restricted-kibana-indices/379133 "2025-08-06T18:29:48Z")

</div>

Hello, I’m currently upgrading our Elasticsearch cluster from version 8 to 9. During the process, I still had some old indices created with version 7. Using the Upgrade Assistant, I marked all the old 7.x indices as re…

---

## [Shard Reallocation While Indexing](https://discuss.elastic.co/t/shard-reallocation-while-indexing/380779)

<div class="topic-metadata">

**Author:** [@nchalise](https://discuss.elastic.co/u/nchalise)\
**Replies:** 14\
**Last updated:** [August 6, 2025, 6:29pm UTC](https://discuss.elastic.co/t/shard-reallocation-while-indexing/380779 "2025-08-06T18:29:30Z")

</div>

We have 20 indexes with 490 shards. The shards size are vary from 35GB to 180GB and the ES cluster size is 35 data nodes. Each data node has 5 disk each disk has size 500GB. While indexing we noticed that shards are star…

---

## [Needed explanation for keystore's PrivateKey entries](https://discuss.elastic.co/t/needed-explanation-for-keystores-privatekey-entries/380600)

<div class="topic-metadata">

**Author:** [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Replies:** 7\
**Last updated:** [August 6, 2025, 3:45pm UTC](https://discuss.elastic.co/t/needed-explanation-for-keystores-privatekey-entries/380600 "2025-08-06T15:45:09Z")

</div>

I encountered the following issue when I try to enroll a token for Kibana: $ ./bin/elasticsearch-create-enrollment-token --scope kibana Unable to create enrollment token for scope \[kibana\] ERROR: Unable to create an en…

---

## [Different Cluster Behavior When Two Master-Eligible Nodes Are Stopped](https://discuss.elastic.co/t/different-cluster-behavior-when-two-master-eligible-nodes-are-stopped/380752)

<div class="topic-metadata">

**Author:** [@Farhad\_Salehi](https://discuss.elastic.co/u/Farhad_Salehi)\
**Replies:** 10\
**Last updated:** [August 5, 2025, 2:32pm UTC](https://discuss.elastic.co/t/different-cluster-behavior-when-two-master-eligible-nodes-are-stopped/380752 "2025-08-05T14:32:12Z")

</div>

I’m working with two different Elasticsearch clusters (version 8.17.5) and noticed different behavior when stopping master-eligible nodes. Here's the setup for both clusters: Cluster A: 3 dedicated master nodes 3 dedi…

---

## [Migrating from Elasticsearch helmchart to ECK](https://discuss.elastic.co/t/migrating-from-elasticsearch-helmchart-to-eck/380757)

<div class="topic-metadata">

**Author:** [@andrew-pickin-epi](https://discuss.elastic.co/u/andrew-pickin-epi)\
**Replies:** 0\
**Last updated:** [August 5, 2025, 12:04pm UTC](https://discuss.elastic.co/t/migrating-from-elasticsearch-helmchart-to-eck/380757 "2025-08-05T12:04:32Z")

</div>

Is there a documented migration plan to go from the now abandoned ES 8.5.1 helm charts at GitHub - elastic/helm-charts: You know, for Kubernetes to ECK Helm? I have several clusters in production and I can not find any …

---

## [Semantic Search Demo Fails on Some Machines But Not Others](https://discuss.elastic.co/t/semantic-search-demo-fails-on-some-machines-but-not-others/380743)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [August 5, 2025, 4:08am UTC](https://discuss.elastic.co/t/semantic-search-demo-fails-on-some-machines-but-not-others/380743 "2025-08-05T04:08:18Z")

</div>

I am trying out this guide on semantic search: My first attempt was a success (hooray!). I did it on a VM provider called linode.com, and I used a VM with 16GB memory, 6 CPUs, ubuntu 24.04 and elasticsearch 9.1. Then…

---

## [Issue Encountered during Microsoft 365 integration with Elastic cloud](https://discuss.elastic.co/t/issue-encountered-during-microsoft-365-integration-with-elastic-cloud/380738)

<div class="topic-metadata">

**Author:** [@Shre1](https://discuss.elastic.co/u/Shre1)\
**Replies:** 0\
**Last updated:** [August 4, 2025, 6:42pm UTC](https://discuss.elastic.co/t/issue-encountered-during-microsoft-365-integration-with-elastic-cloud/380738 "2025-08-04T18:42:10Z")

</div>

We are currently working on integrating Elastic Cloud with one of our cloud-hosted Microsoft 365 mailboxes (hosted on Azure). We have completed the following steps: • Created a new Azure AD App and gathered all require…

---

## [Elasticsearch cluster name in yml file](https://discuss.elastic.co/t/elasticsearch-cluster-name-in-yml-file/380643)

<div class="topic-metadata">

**Author:** [@King\_storm](https://discuss.elastic.co/u/King_storm)\
**Replies:** 7\
**Last updated:** [August 4, 2025, 3:21pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-name-in-yml-file/380643 "2025-08-04T15:21:42Z")

</div>

I have created a 3 node cluster. I have not mentioned cluster name or node name . It's using the default cluster name elasticsearch and node name of the Linux system. Initially I formed the cluster using the enrollment t…

---

## [Best Practices for Combining Fleet, Elastic Agent, Logstash, and Redis?](https://discuss.elastic.co/t/best-practices-for-combining-fleet-elastic-agent-logstash-and-redis/380419)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 6\
**Last updated:** [August 4, 2025, 1:20pm UTC](https://discuss.elastic.co/t/best-practices-for-combining-fleet-elastic-agent-logstash-and-redis/380419 "2025-08-04T13:20:42Z")

</div>

Hi everyone, I’ve been working with the Elastic Stack for several years and recently started exploring Fleet Server and Elastic Agent. While I appreciate the modern approach and prebuilt integrations, I’m struggling wit…

---

## [NET Client: Serialisation of descriptor objects (e.g. QueryDescriptor)](https://discuss.elastic.co/t/net-client-serialisation-of-descriptor-objects-e-g-querydescriptor/380257)

<div class="topic-metadata">

**Author:** [@JanSearch](https://discuss.elastic.co/u/JanSearch)\
**Replies:** 3\
**Last updated:** [August 4, 2025, 9:21am UTC](https://discuss.elastic.co/t/net-client-serialisation-of-descriptor-objects-e-g-querydescriptor/380257 "2025-08-04T09:21:50Z")

</div>

Dear Elastic forum, we used NEST so far and are going to switch to the new client. In NEST it is possible to serialise the descriptor objects, e.g. QueryContainerDescriptor or CreateIndexDescriptor. In the new NET cli…

---

## [How to monitor deleted document information](https://discuss.elastic.co/t/how-to-monitor-deleted-document-information/380241)

<div class="topic-metadata">

**Author:** [@double-7](https://discuss.elastic.co/u/double-7)\
**Replies:** 2\
**Last updated:** [August 4, 2025, 1:09am UTC](https://discuss.elastic.co/t/how-to-monitor-deleted-document-information/380241 "2025-08-04T01:09:11Z")

</div>

hello . I need everyone's help. Currently, I want to perform document monitoring on the ES server. I can accomplish this by using the \_seq\_no attribute to monitor the addition and modification of documents. However, whe…

---

## [Cant get Search to work with .NET 9 Client](https://discuss.elastic.co/t/cant-get-search-to-work-with-net-9-client/380688)

<div class="topic-metadata">

**Author:** [@c77m](https://discuss.elastic.co/u/c77m)\
**Replies:** 2\
**Last updated:** [August 3, 2025, 6:02pm UTC](https://discuss.elastic.co/t/cant-get-search-to-work-with-net-9-client/380688 "2025-08-03T18:02:48Z")

</div>

Hi, new to Elastic Search so I'm a bit stuck, I have indexed som documents and I can see mappings are created for all properties for my document. (might not be optimal right now but just testing this out right now) S…

---

## [Tabular form or report based on logs](https://discuss.elastic.co/t/tabular-form-or-report-based-on-logs/380684)

<div class="topic-metadata">

**Author:** [@dsrini-open](https://discuss.elastic.co/u/dsrini-open)\
**Replies:** 2\
**Last updated:** [August 3, 2025, 1:24am UTC](https://discuss.elastic.co/t/tabular-form-or-report-based-on-logs/380684 "2025-08-03T01:24:40Z")

</div>

I have the following logs - 20:00:00 Started processing 20:05:00 Successfully finished 20:05:03 Output file - /temp/file2 20:05:03 Started processing 20:10:10 Successfully finished 20:10:14 Output file - /temp/fil…

---

## [Version 9 Frozen Indices](https://discuss.elastic.co/t/version-9-frozen-indices/380691)

<div class="topic-metadata">

**Author:** [@Tal\_Hayun](https://discuss.elastic.co/u/Tal_Hayun)\
**Replies:** 2\
**Last updated:** [August 2, 2025, 1:54pm UTC](https://discuss.elastic.co/t/version-9-frozen-indices/380691 "2025-08-02T13:54:22Z")

</div>

In version 9.0 release notes it says - "Remove the ability to read frozen indices" Does that include indices in frozen ILM phase?

---

## [Activate "Fleet" and deploy agents - is a Fleet Server necessary?](https://discuss.elastic.co/t/activate-fleet-and-deploy-agents-is-a-fleet-server-necessary/380672)

<div class="topic-metadata">

**Author:** [@Elasticisti](https://discuss.elastic.co/u/Elasticisti)\
**Replies:** 1\
**Last updated:** [August 1, 2025, 9:16pm UTC](https://discuss.elastic.co/t/activate-fleet-and-deploy-agents-is-a-fleet-server-necessary/380672 "2025-08-01T21:16:59Z")

</div>

Hi there, I am new to ELK. It runs now in a small VM in our Testnetwork. Just for fun, I would like to ingest some jira logs to ELK as I see I should use "Fleet" to deploy the agents. As I have only one testnode, …

---

## [Deploy ELK on AlmaLinux 9.2 elasticsearch-create-enrollment-token Command not found](https://discuss.elastic.co/t/deploy-elk-on-almalinux-9-2-elasticsearch-create-enrollment-token-command-not-found/380664)

<div class="topic-metadata">

**Author:** [@Elasticisti](https://discuss.elastic.co/u/Elasticisti)\
**Replies:** 2\
**Last updated:** [August 1, 2025, 2:36pm UTC](https://discuss.elastic.co/t/deploy-elk-on-almalinux-9-2-elasticsearch-create-enrollment-token-command-not-found/380664 "2025-08-01T14:36:49Z")

</div>

Hi, I have an AlmaLinux Vm mit 4CPU und 4GB RAM where ELK should be deployed. I have used this tutorial to achieve this: "www.hostmycode.in/tutorials/install-and-configure-elk-stack-on-almalinux" I got to the point, …

---

## [Is it possible to delaying shrink and forcemerge lifecycle steps in hot tier](https://discuss.elastic.co/t/is-it-possible-to-delaying-shrink-and-forcemerge-lifecycle-steps-in-hot-tier/380634)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 3\
**Last updated:** [August 1, 2025, 12:32pm UTC](https://discuss.elastic.co/t/is-it-possible-to-delaying-shrink-and-forcemerge-lifecycle-steps-in-hot-tier/380634 "2025-08-01T12:32:01Z")

</div>

Hi All, Need some information about setting up ILM policy like below for time series data stream. "hot": { "min\_age": "0ms", "actions": { "rollover": { "max\_age": "10d", …

---

## [Openshift pod count into elastic](https://discuss.elastic.co/t/openshift-pod-count-into-elastic/380658)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 0\
**Last updated:** [August 1, 2025, 12:01pm UTC](https://discuss.elastic.co/t/openshift-pod-count-into-elastic/380658 "2025-08-01T12:01:06Z")

</div>

I have a number of projects in openshift, and each project can have multiple pods running. I'd like to visualise that data in kibana, but need it stored in elastic first. how do I get elastic to gather that data? It w…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=21)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=23)
