# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=223

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 224

---

## [Can't start elastic elasticsearch-8.9.0](https://discuss.elastic.co/t/cant-start-elastic-elasticsearch-8-9-0/339299)

<div class="topic-metadata">

**Author:** [@choilee](https://discuss.elastic.co/u/choilee)\
**Replies:** 10\
**Last updated:** [July 27, 2023, 10:00am UTC](https://discuss.elastic.co/t/cant-start-elastic-elasticsearch-8-9-0/339299 "2023-07-27T10:00:10Z")

</div>

I installed elasticsearch-8.9.0 on root account in centos 7 But couldn't start. i use this command "systemctl start elasticsearch.service" And i couldn't find any wrong Permission....help please...ㅠㅠ Jul 26 20:06:43 S…

---

## [Elastic Agent error out with log\_group\_arn, log\_group\_name and log\_group\_name\_prefix config cannot all be empty](https://discuss.elastic.co/t/elastic-agent-error-out-with-log-group-arn-log-group-name-and-log-group-name-prefix-config-cannot-all-be-empty/339414)

<div class="topic-metadata">

**Author:** [@The2](https://discuss.elastic.co/u/The2)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 9:56am UTC](https://discuss.elastic.co/t/elastic-agent-error-out-with-log-group-arn-log-group-name-and-log-group-name-prefix-config-cannot-all-be-empty/339414 "2023-07-27T09:56:01Z")

</div>

Hello, I'm trying to use elastic-agent to integrate with AWS to fetch cloudwatch logs. However i'm facing this issue: Unit state changed aws-cloudwatch-default-aws-cloudwatch-cloudwatch-481de7b4-7c2d-4fbf-9156-3acdd53…

---

## [decayDateGauss gives different results depending on the amount of hits](https://discuss.elastic.co/t/decaydategauss-gives-different-results-depending-on-the-amount-of-hits/339415)

<div class="topic-metadata">

**Author:** [@Massimo\_Redaelli](https://discuss.elastic.co/u/Massimo_Redaelli)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 9:56am UTC](https://discuss.elastic.co/t/decaydategauss-gives-different-results-depending-on-the-amount-of-hits/339415 "2023-07-27T09:56:27Z")

</div>

I'm using a script\_score query where the score script is this: double decay = params.decays.getOrDefault(doc\['spider'\].value, 0.1); def ts = doc\['last\_update'\].size()!=0 ? doc\['last\_update'\].value : doc\['timestamp'\].va…

---

## [Elastic agent showing disable in windows services. How to resolved this issue](https://discuss.elastic.co/t/elastic-agent-showing-disable-in-windows-services-how-to-resolved-this-issue/339401)

<div class="topic-metadata">

**Author:** [@Tushar02](https://discuss.elastic.co/u/Tushar02)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 8:28am UTC](https://discuss.elastic.co/t/elastic-agent-showing-disable-in-windows-services-how-to-resolved-this-issue/339401 "2023-07-27T08:28:59Z")

</div>

elastic agent showing disable in windows services. How to resolved this issue

---

## [Char\_filter doesn't work properly](https://discuss.elastic.co/t/char-filter-doesnt-work-properly/339218)

<div class="topic-metadata">

**Author:** [@Vladimir\_Talabko](https://discuss.elastic.co/u/Vladimir_Talabko)\
**Replies:** 12\
**Last updated:** [July 27, 2023, 8:01am UTC](https://discuss.elastic.co/t/char-filter-doesnt-work-properly/339218 "2023-07-27T08:01:25Z")

</div>

Hello! I have an index with a char\_filter for avoiding special symbols like "-\_.": curl -X PUT "localhost:9200/test\_index?pretty" -H 'Content-Type: application/json' -d' { "settings": { "analysis": { …

---

## [Give wildcard for fieldname in emit() when creating Runtime field throws error](https://discuss.elastic.co/t/give-wildcard-for-fieldname-in-emit-when-creating-runtime-field-throws-error/339394)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 7:35am UTC](https://discuss.elastic.co/t/give-wildcard-for-fieldname-in-emit-when-creating-runtime-field-throws-error/339394 "2023-07-27T07:35:08Z")

</div>

Hi, I have a field, say macAddress in all my documents, but with different names. Like in some documents, it is host.macAddress, while in some it is machine.mac and so on. I want to create a runtime field called macAdd…

---

## [Exception while attempting Migration from AWS OSS 1.3 to Elasticsearch 7.17](https://discuss.elastic.co/t/exception-while-attempting-migration-from-aws-oss-1-3-to-elasticsearch-7-17/337797)

<div class="topic-metadata">

**Author:** [@gaurav\_jain](https://discuss.elastic.co/u/gaurav_jain)\
**Replies:** 6\
**Last updated:** [July 25, 2023, 12:29pm UTC](https://discuss.elastic.co/t/exception-while-attempting-migration-from-aws-oss-1-3-to-elasticsearch-7-17/337797 "2023-07-25T12:29:12Z")

</div>

Hello. We are planning to migrate existing elastic cluster from AWS opensearch service 1.1 to Elastic Cloud: 7.17 with some indexes of ~50GB in size First, I launched an elastic cloud cluster : 7.17. Data migration e…

---

## [How to read indexed binary field data from doc values (in custom Query plugin)](https://discuss.elastic.co/t/how-to-read-indexed-binary-field-data-from-doc-values-in-custom-query-plugin/339387)

<div class="topic-metadata">

**Author:** [@Pyppe](https://discuss.elastic.co/u/Pyppe)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 6:19am UTC](https://discuss.elastic.co/t/how-to-read-indexed-binary-field-data-from-doc-values-in-custom-query-plugin/339387 "2023-07-27T06:19:40Z")

</div>

Hi! We're trying to write a custom query-plugin for Elasticsearch where we would use binary data for calculating scores (disclaimer: I've never written one before). Each document can have multiple vectors, so we cannot …

---

## [Hardware Requiremenr](https://discuss.elastic.co/t/hardware-requiremenr/339383)

<div class="topic-metadata">

**Author:** [@umangpatel](https://discuss.elastic.co/u/umangpatel)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 5:51am UTC](https://discuss.elastic.co/t/hardware-requiremenr/339383 "2023-07-27T05:51:06Z")

</div>

Hello There!!! I have one question about Elasticsearch hardware requiremnet. So let's say if i want to setup Elasticsearch cluster in on-premises data center and i have daily 20 TB of data is ingress or i would say inge…

---

## [Watcher alert status](https://discuss.elastic.co/t/watcher-alert-status/339374)

<div class="topic-metadata">

**Author:** [@jaja](https://discuss.elastic.co/u/jaja)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 5:16am UTC](https://discuss.elastic.co/t/watcher-alert-status/339374 "2023-07-27T05:16:10Z")

</div>

Hi Team, We have tried with the watcher it worked for us but we can't go as in watcher the alert status does not change like as in alert we have active , recover options we have. I tried with Index Threshold alert but …

---

## [Will the snapshot repository able to capture the changes in mappings?](https://discuss.elastic.co/t/will-the-snapshot-repository-able-to-capture-the-changes-in-mappings/339244)

<div class="topic-metadata">

**Author:** [@ian.chan](https://discuss.elastic.co/u/ian.chan)\
**Replies:** 6\
**Last updated:** [July 27, 2023, 5:19am UTC](https://discuss.elastic.co/t/will-the-snapshot-repository-able-to-capture-the-changes-in-mappings/339244 "2023-07-27T05:19:09Z")

</div>

Hi. Let's say I have registered a snapshot repository for an index A, with slm policy taking snapshot every hour. Then I add a new field in the mapping of the index A, and add some new documents with values in this new…

---

## [RefreshPolicy WAIT\_UNTIL does not work when using BulkProcessor in Java Client](https://discuss.elastic.co/t/refreshpolicy-wait-until-does-not-work-when-using-bulkprocessor-in-java-client/337857)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 5\
**Last updated:** [July 27, 2023, 4:53am UTC](https://discuss.elastic.co/t/refreshpolicy-wait-until-does-not-work-when-using-bulkprocessor-in-java-client/337857 "2023-07-27T04:53:47Z")

</div>

Hello everyone, I am a beginner, and my English is not very good. I am using ES 7.10 with the Java programming language, so I am using the Java High-Level REST Client. I want to be able to search for relevant content i…

---

## [The indexing or search request send to down node](https://discuss.elastic.co/t/the-indexing-or-search-request-send-to-down-node/339022)

<div class="topic-metadata">

**Author:** [@Chimu](https://discuss.elastic.co/u/Chimu)\
**Replies:** 10\
**Last updated:** [July 27, 2023, 3:35am UTC](https://discuss.elastic.co/t/the-indexing-or-search-request-send-to-down-node/339022 "2023-07-27T03:35:03Z")

</div>

I have an Elasticsearch (v5.6.10) cluster with 3 nodes. Node A : Master Node B : Master + Data Node C : Master + Data There are 6 shards per data node with replication set as 1. All 6 primary nodes are in Node B and a…

---

## [How to test for indexes NOT being created?](https://discuss.elastic.co/t/how-to-test-for-indexes-not-being-created/339346)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 2:08am UTC](https://discuss.elastic.co/t/how-to-test-for-indexes-not-being-created/339346 "2023-07-27T02:08:27Z")

</div>

Hi all. My ELK should be receiving data regularly, and creating a new index daily. Is there any way to automatically test if either of those is NOT happening?

---

## [Physicals host with beats to server with ELK docker containers?](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352)

<div class="topic-metadata">

**Author:** [@rhyejam](https://discuss.elastic.co/u/rhyejam)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 1:48am UTC](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352 "2023-07-27T01:48:00Z")

</div>

So here’s my conundrum. Currently using a vm with a bunch of docker containers on it. Included in these is the ELK docker compose by deviantony on GitHub Now I have a few laptops that I want forwarding logs to the serve…

---

## [ELK storage on prem](https://discuss.elastic.co/t/elk-storage-on-prem/339348)

<div class="topic-metadata">

**Author:** [@carl56846453](https://discuss.elastic.co/u/carl56846453)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 9:03pm UTC](https://discuss.elastic.co/t/elk-storage-on-prem/339348 "2023-07-26T21:03:54Z")

</div>

ELK is not storing much log data. The log seem to keep turning over. ELK is consuming a lot of syslog data. how do I increase the storge of data.

---

## [Post data to elasticsearch sometimes throws error 429](https://discuss.elastic.co/t/post-data-to-elasticsearch-sometimes-throws-error-429/339345)

<div class="topic-metadata">

**Author:** [@111407](https://discuss.elastic.co/u/111407)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 7:37pm UTC](https://discuss.elastic.co/t/post-data-to-elasticsearch-sometimes-throws-error-429/339345 "2023-07-26T19:37:00Z")

</div>

command: curl -u username:pw -X POST 'http://sd-4531-6c55:9200/testindex/\_doc' -H 'Content-type: application/json' -d '{"test":11234}' response: {"error":{"root\_cause":\[{"type":"remote\_transport\_exception","reason":"\[…

---

## [Elasticsearch REST API Authorization](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 7:16pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332 "2023-07-26T19:16:26Z")

</div>

OK, so I tried using the Elastic.Client.Elasticsearch library to get an index template, but it had some JSON serialization issues that was causing an exception. Next up, I tried using just a regular REST call. I have cr…

---

## [GetIndexTemplate() call throws an exception](https://discuss.elastic.co/t/getindextemplate-call-throws-an-exception/339329)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 6:25pm UTC](https://discuss.elastic.co/t/getindextemplate-call-throws-an-exception/339329 "2023-07-26T18:25:47Z")

</div>

I am trying to get an index template using the .NET APIs via Elastic.Clients.Elasticsearch and Elastic.Transport libraries. I got my client setup like this: var credentials = new BasicAuthentication(elasticUsername, el…

---

## [How to view the backend log of the Python class \`Elasticsearch\`?](https://discuss.elastic.co/t/how-to-view-the-backend-log-of-the-python-class-elasticsearch/339133)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 6:21pm UTC](https://discuss.elastic.co/t/how-to-view-the-backend-log-of-the-python-class-elasticsearch/339133 "2023-07-26T18:21:22Z")

</div>

We are using an instance of the Python class Elasticsearch, e.g., by es = Elasticsearch(hosts="http://test-elastic-host:9200"). For example, when calling the search() method, we need to know what exactly the request is,…

---

## [I want to know why the indices.id\_field\_data.enabled configuration is turned off by default](https://discuss.elastic.co/t/i-want-to-know-why-the-indices-id-field-data-enabled-configuration-is-turned-off-by-default/339338)

<div class="topic-metadata">

**Author:** [@Kurt\_Rudolph](https://discuss.elastic.co/u/Kurt_Rudolph)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 5:50pm UTC](https://discuss.elastic.co/t/i-want-to-know-why-the-indices-id-field-data-enabled-configuration-is-turned-off-by-default/339338 "2023-07-26T17:50:36Z")

</div>

This topic got automatically closed without an answer I want to know why the indices.id\_field\_data.enabled configuration is turned off by default I'm evaluating the impacts of upgrading from v7 -\> v8 and found an issue…

---

## [Pagination + Sorted Aggregations: Efficiently Retrieve Sorted List of Values?](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325)

<div class="topic-metadata">

**Author:** [@openelasticsearch](https://discuss.elastic.co/u/openelasticsearch)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 3:15pm UTC](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325 "2023-07-26T15:15:05Z")

</div>

Hi, I'm looking for some advice on the best way to implement an aggregation query that supports pagination and sorting. Quick Overview of My Documents & Desired Use Case: I have indexes that contain documents with a nu…

---

## [Installing Elasticsearch as an external service at OpenShift](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845 "2023-07-26T14:38:21Z")

</div>

We have OpenShift cluster and we want to install elasticsearch at ocp to serve both internal and external audit shipment. our design should be something like this: FileBeat (outside ocp) --\> Logstash (inside ocp) --\> El…

---

## [Which is the most stable version of elastic search in 8.x?](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314)

<div class="topic-metadata">

**Author:** [@Pankaj\_Goyal](https://discuss.elastic.co/u/Pankaj_Goyal)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 1:57pm UTC](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314 "2023-07-26T13:57:34Z")

</div>

We are working on a use case where we have to most rely on vector matching searched. Please suggest most stable version for elastic 8.x.

---

## [Install elasticsearch 8.8](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 11:54am UTC](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304 "2023-07-26T11:54:44Z")

</div>

Hello, I intend to install Elasticsearch 8.8 on an Ubuntu 22.04 server following the link below: Install Elasticsearch with Debian Package | Elasticsearch Guide \[8.9\] | Elastic The server has internet access, and the a…

---

## [Why comments field not being displayed](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 8\
**Last updated:** [July 26, 2023, 11:16am UTC](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228 "2023-07-26T11:16:40Z")

</div>

Why is the comment field not being displayed for some Affected Services field values (Memory, CPU) in the Dashboard when they are already being displayed in Discover? Is this an issue with the logstash? What should be d…

---

## [when bumped up beats version from 7.16 to 8.6.2, indices are not created](https://discuss.elastic.co/t/when-bumped-up-beats-version-from-7-16-to-8-6-2-indices-are-not-created/339282)

<div class="topic-metadata">

**Author:** [@skumarya](https://discuss.elastic.co/u/skumarya)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 9:20am UTC](https://discuss.elastic.co/t/when-bumped-up-beats-version-from-7-16-to-8-6-2-indices-are-not-created/339282 "2023-07-26T09:20:05Z")

</div>

we were using Elasticsearch version 7.16 earlier since we have bumped up the version to 8.6.2 for elasticsearch, kibana and filebeat indices are not created. we are using Helm version 3.12.2 Kubernetes version 1.25.4/1…

---

## [How to see audit log in for my deployment in elastic cloud](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 7:17am UTC](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257 "2023-07-26T07:17:42Z")

</div>

I have run the insert the data in Elasticsearch through rest call and once I went to Log and metrics inside the elastic cloud GUI ,I am unable to find audit logs , only I am getting server log, Please guide me regarding…

---

## [When using the index settings with auto\_expand\_replicas set to "0-all," an issue arises where primary shards are concentrated on specific nodes](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185)

<div class="topic-metadata">

**Author:** [@wedul\_chul](https://discuss.elastic.co/u/wedul_chul)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 4:31am UTC](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185 "2023-07-26T04:31:01Z")

</div>

Due to the service requirements, the setting "auto\_expand\_replicas" is configured as "0-all," enabling replica shards to be present on all nodes. However, there is an issue where primary shards are concentrated on a spec…

---

## [Search error rate 100](https://discuss.elastic.co/t/search-error-rate-100/339235)

<div class="topic-metadata">

**Author:** [@maximiliano\_carrasco](https://discuss.elastic.co/u/maximiliano_carrasco)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 12:41am UTC](https://discuss.elastic.co/t/search-error-rate-100/339235 "2023-07-26T00:41:48Z")

</div>

I am trying to run a simple track with search operation but I keep getting 100 error rate, This is my track {% import "rally.helpers" as rally with context %} { "version": 2, "description": "Tracker-generated track…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=222)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=224)
