# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=226

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 227

---

## [Best disk modes for data nodes (VMVare ESX)](https://discuss.elastic.co/t/best-disk-modes-for-data-nodes-vmvare-esx/338898)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 3:57pm UTC](https://discuss.elastic.co/t/best-disk-modes-for-data-nodes-vmvare-esx/338898 "2023-07-20T15:57:44Z")

</div>

I need to create a cluster on vmware esx with 60 data nodes. Every node have 100GB disk for OS and 10TB disk (SSD) with for data fiber channel. I'm looking for best vmware disk mode option for data nodes. There are 3 o…

---

## [Streamingbulk vs parallel bulk](https://discuss.elastic.co/t/streamingbulk-vs-parallel-bulk/338895)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 3:02pm UTC](https://discuss.elastic.co/t/streamingbulk-vs-parallel-bulk/338895 "2023-07-20T15:02:44Z")

</div>

Hi, I've stumbled upon a case where I see one of my index goes to RED state and taking ES down with it. Here are the JVM options I've set it to. -Xms10g -Xmx10g In my case I need to migrate around 6lakh of data from …

---

## [Unable to login to kibana with valid elastic user credentials after few days](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-valid-elastic-user-credentials-after-few-days/338785)

<div class="topic-metadata">

**Author:** [@shiva\_ratnavarapu](https://discuss.elastic.co/u/shiva_ratnavarapu)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:50pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-valid-elastic-user-credentials-after-few-days/338785 "2023-07-20T14:50:50Z")

</div>

Kibana version: kibana:8.5.1 Elasticsearch version: elasticsearch:8.5.1 We have installed the elasticsearch and kibana using helm chart. Post installation able to access kibana with elasticsearch credentials user/pass…

---

## [Help with simple ILM rollover configuration for existing index](https://discuss.elastic.co/t/help-with-simple-ilm-rollover-configuration-for-existing-index/338843)

<div class="topic-metadata">

**Author:** [@Stephen\_Joiner](https://discuss.elastic.co/u/Stephen_Joiner)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:45pm UTC](https://discuss.elastic.co/t/help-with-simple-ilm-rollover-configuration-for-existing-index/338843 "2023-07-20T14:45:01Z")

</div>

Hey everyone! I have a super basic Elastic Stack set up in docker on my personal server. I am using Logstash to gather the logs of my non-elastic containers. The stack works great and has for years. The problem I'm runn…

---

## [Re-indexing ElasticSearch](https://discuss.elastic.co/t/re-indexing-elasticsearch/338816)

<div class="topic-metadata">

**Author:** [@randallkiddsr](https://discuss.elastic.co/u/randallkiddsr)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 2:38pm UTC](https://discuss.elastic.co/t/re-indexing-elasticsearch/338816 "2023-07-20T14:38:40Z")

</div>

I am trying to get clarity on the necessity and steps to re indexing Elasticsearch. After performing a search on one account, that account is coming up blank.

---

## [Backup and restore](https://discuss.elastic.co/t/backup-and-restore/338872)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:47pm UTC](https://discuss.elastic.co/t/backup-and-restore/338872 "2023-07-20T13:47:26Z")

</div>

Hi , I need to make a backup of elasticsearch data, due to maintenance, and restore it afterwards, My question is: Does elasticsearch save the configurations of each indices, I'm talking about the number of shards, th…

---

## ["\[my\_s3\_repo\] path is not accessible on master node](https://discuss.elastic.co/t/my-s3-repo-path-is-not-accessible-on-master-node/338885)

<div class="topic-metadata">

**Author:** [@Samuel\_Emmanuel](https://discuss.elastic.co/u/Samuel_Emmanuel)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:32pm UTC](https://discuss.elastic.co/t/my-s3-repo-path-is-not-accessible-on-master-node/338885 "2023-07-20T13:32:08Z")

</div>

I am trying to setup a repository using minIO s3 bucket to implement a snapshot for my Elasticsearch running in a kubernetes cluster, but I encountered the error as seen below on kibana dev too. { "error" : { "roo…

---

## [ILM rollover](https://discuss.elastic.co/t/ilm-rollover/338771)

<div class="topic-metadata">

**Author:** [@kruzadmn](https://discuss.elastic.co/u/kruzadmn)\
**Replies:** 12\
**Last updated:** [July 20, 2023, 1:20pm UTC](https://discuss.elastic.co/t/ilm-rollover/338771 "2023-07-20T13:20:51Z")

</div>

Hi! Please help me. I have configured ILM to rollover the index when it reaches 120GB or 7 days. I have a problem that ILM does not rollover the index because it thinks that the index size is for example 117GB, when in …

---

## [Requirement for designing elastic search in aws](https://discuss.elastic.co/t/requirement-for-designing-elastic-search-in-aws/338879)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:35pm UTC](https://discuss.elastic.co/t/requirement-for-designing-elastic-search-in-aws/338879 "2023-07-20T12:35:23Z")

</div>

Hi All, I've asked to design a Elasticsearch for my project . I'm a new joiner to my project and new to Elasticsearch. I saw minimum requirement as such 8 GM Ram,4 CPU core, and 50 Gb disk space with 1 GBps network …

---

## [Painless script - percentage calculation - returns 0 always due to decimals](https://discuss.elastic.co/t/painless-script-percentage-calculation-returns-0-always-due-to-decimals/338875)

<div class="topic-metadata">

**Author:** [@Jayakrishna\_Manokara](https://discuss.elastic.co/u/Jayakrishna_Manokara)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:08pm UTC](https://discuss.elastic.co/t/painless-script-percentage-calculation-returns-0-always-due-to-decimals/338875 "2023-07-20T12:08:50Z")

</div>

Hi, I am trying to calculate percentage. "script": { "source": """ return \[ ctx.payload.first.aggregations.success\_count.doc\_count / (ctx.payload.first.aggregations.success\_count.doc\_count + ctx.payload.first.aggrega…

---

## [ElasticSearch Index Storage Optimization - Firewall Logs](https://discuss.elastic.co/t/elasticsearch-index-storage-optimization-firewall-logs/338410)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 9\
**Last updated:** [July 20, 2023, 11:51am UTC](https://discuss.elastic.co/t/elasticsearch-index-storage-optimization-firewall-logs/338410 "2023-07-20T11:51:59Z")

</div>

We are running a 3 node cluster to index logs from a firewall. The nodes are physical machines (20 Core CPUs, 16GB RAM, SSD Storage). Each days logs are stored in an individual index. The storage utilized per index wor…

---

## [Field loss occurs when making a runtime field](https://discuss.elastic.co/t/field-loss-occurs-when-making-a-runtime-field/338658)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 10:58am UTC](https://discuss.elastic.co/t/field-loss-occurs-when-making-a-runtime-field/338658 "2023-07-20T10:58:30Z")

</div>

IF agent(original) field exists, the copy field must also exist. However it often happens that there is an agent field but no copy field. Has anyone experienced the same problem?

---

## [Multi-cluster installation, cluster loss and recovery](https://discuss.elastic.co/t/multi-cluster-installation-cluster-loss-and-recovery/338858)

<div class="topic-metadata">

**Author:** [@Christophe\_DAME](https://discuss.elastic.co/u/Christophe_DAME)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 10:00am UTC](https://discuss.elastic.co/t/multi-cluster-installation-cluster-loss-and-recovery/338858 "2023-07-20T10:00:13Z")

</div>

Hi there, As I'm new, I'll introduce myself quickly : I'm Christophe Dame and I'm working for Camunda. Our solution embarks an Elasticsearch 7.17 and I'm currently experimenting a dual cluster setup. Ideally, my goal w…

---

## [How to check if the index was merged or not](https://discuss.elastic.co/t/how-to-check-if-the-index-was-merged-or-not/338866)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 9:33am UTC](https://discuss.elastic.co/t/how-to-check-if-the-index-was-merged-or-not/338866 "2023-07-20T09:33:27Z")

</div>

Hi there, from this discuss, i know that elastic will check continuously to see if the index needs merging or not. but what parameter i can check, so i can makesure that the index was merged. is that by using this API? …

---

## ["cluster.routing.allocation.enable": "primaries"](https://discuss.elastic.co/t/cluster-routing-allocation-enable-primaries/338855)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 7:58am UTC](https://discuss.elastic.co/t/cluster-routing-allocation-enable-primaries/338855 "2023-07-20T07:58:33Z")

</div>

Hi Team, "cluster.routing.allocation.enable": "primaries" In reality does it mean which ever primaries Node is unavailable the cluster will turn its related replica to become primary in that same replica node. There is…

---

## [Elasticsearch Cluster Yellow - Index Allocation "No Attempt"](https://discuss.elastic.co/t/elasticsearch-cluster-yellow-index-allocation-no-attempt/338492)

<div class="topic-metadata">

**Author:** [@ChestoOfGlen](https://discuss.elastic.co/u/ChestoOfGlen)\
**Replies:** 5\
**Last updated:** [July 20, 2023, 5:45am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-yellow-index-allocation-no-attempt/338492 "2023-07-20T05:45:49Z")

</div>

We are running several Elasticsearch clusters (v8.8.1) in Kubernetes (AWS EKS on v1.25) via Elastic Cloud on Kubernetes (ECK v2.8). We've had several of the clusters, after a high CPU load event on the K8s workers, not …

---

## [Regarding disk expansion for Elasticsearch Cluster](https://discuss.elastic.co/t/regarding-disk-expansion-for-elasticsearch-cluster/338838)

<div class="topic-metadata">

**Author:** [@klose.foot.baller](https://discuss.elastic.co/u/klose.foot.baller)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:30am UTC](https://discuss.elastic.co/t/regarding-disk-expansion-for-elasticsearch-cluster/338838 "2023-07-20T01:30:25Z")

</div>

Hi, We currently have an Elasticsearch (version 6.5) cluster with 3 Azure Virtual Machines. Disk space is getting tight and we would like to improve the situation, but we are wondering what is the best approach to take…

---

## [Size reduction after re-indexing from v7 to v8](https://discuss.elastic.co/t/size-reduction-after-re-indexing-from-v7-to-v8/338833)

<div class="topic-metadata">

**Author:** [@Ian\_Simpson](https://discuss.elastic.co/u/Ian_Simpson)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:24am UTC](https://discuss.elastic.co/t/size-reduction-after-re-indexing-from-v7-to-v8/338833 "2023-07-20T00:24:27Z")

</div>

I'm migrating from a v7.17.10 cluster to v8.8.2 using the reindex API. I'm seeing that some indices with data from ingested files (docx, pdf mostly) only take up 5% of the space that they used to. I've done a little spot…

---

## [Configurar 3 master nodos sin datos solo maestros? en la version 8.8?](https://discuss.elastic.co/t/configurar-3-master-nodos-sin-datos-solo-maestros-en-la-version-8-8/338829)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:36pm UTC](https://discuss.elastic.co/t/configurar-3-master-nodos-sin-datos-solo-maestros-en-la-version-8-8/338829 "2023-07-19T21:36:18Z")

</div>

estoy configurando un cluster con 3 nodos masestros la seguridad ya la tengo cubierta pero cuando inicializo me quedan 3 nodos master con data y 4 nodos de datos necesito que 3 sean dedicados master sin data y todos los…

---

## [Ingest Pipelines - illegal\_argument\_exception reason field not present as part of path](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267)

<div class="topic-metadata">

**Author:** [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Replies:** 3\
**Last updated:** [July 19, 2023, 8:23pm UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267 "2023-07-19T20:23:09Z")

</div>

Hi I trying apply a ingest pipeline into a datastream. I'm using logstash to send to datastream, this datastream has a mapping: { "template": { "mappings": { "properties": { "@…

---

## [Query indices on cold node?](https://discuss.elastic.co/t/query-indices-on-cold-node/338810)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 4:49pm UTC](https://discuss.elastic.co/t/query-indices-on-cold-node/338810 "2023-07-19T16:49:06Z")

</div>

I am trying to see if there is a straight forward way to query indices that are located on the "cold" node and to get a list of those indices, is there a straight forward way to do that in Elasticsearch? I presume I can …

---

## [Group data By 5 minutes using sql query in elastic](https://discuss.elastic.co/t/group-data-by-5-minutes-using-sql-query-in-elastic/338754)

<div class="topic-metadata">

**Author:** [@leonid\_fayngold](https://discuss.elastic.co/u/leonid_fayngold)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 4:03pm UTC](https://discuss.elastic.co/t/group-data-by-5-minutes-using-sql-query-in-elastic/338754 "2023-07-19T16:03:48Z")

</div>

how can I group data By 5 minutes using SQL query in elastic

---

## [Upgrade Query DSL version 7, a version 8](https://discuss.elastic.co/t/upgrade-query-dsl-version-7-a-version-8/338799)

<div class="topic-metadata">

**Author:** [@Miguel\_Martinez](https://discuss.elastic.co/u/Miguel_Martinez)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 3:58pm UTC](https://discuss.elastic.co/t/upgrade-query-dsl-version-7-a-version-8/338799 "2023-07-19T15:58:38Z")

</div>

Hello, I have several DSL queries in version 7 of elasticsearch but I updated to version 8 but the queries are not working for me, I was looking at a query and in version 7 the eventtime is written like this but in versi…

---

## [Error while using ./elasticsearch-node repurpose tool](https://discuss.elastic.co/t/error-while-using-elasticsearch-node-repurpose-tool/338807)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 3:43pm UTC](https://discuss.elastic.co/t/error-while-using-elasticsearch-node-repurpose-tool/338807 "2023-07-19T15:43:23Z")

</div>

i got this error while using /usr/share/elasticsearch/elasticsearch-node repurpose to set my master node only for master { "error" : { "root\_cause" : \[ { "type" : "security\_exception", "reas…

---

## [Improve performance for update\_by\_query relational updates](https://discuss.elastic.co/t/improve-performance-for-update-by-query-relational-updates/338415)

<div class="topic-metadata">

**Author:** [@rolfschmidt](https://discuss.elastic.co/u/rolfschmidt)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 3:30pm UTC](https://discuss.elastic.co/t/improve-performance-for-update-by-query-relational-updates/338415 "2023-07-19T15:30:24Z")

</div>

Hi, I would like to ask for advice because I'm not sure how to optimize my data structures or requests to get more performance out of my system. I have a Elasticsearch with 1.000.000 objects stored in it. Let's say I h…

---

## [Unassigned shards - cannot allocate because all found copies of the shard are either stale or corrupt](https://discuss.elastic.co/t/unassigned-shards-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/338804)

<div class="topic-metadata">

**Author:** [@karsai1993](https://discuss.elastic.co/u/karsai1993)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 3:11pm UTC](https://discuss.elastic.co/t/unassigned-shards-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/338804 "2023-07-19T15:11:55Z")

</div>

Hello there, We are facing a RED cluster. GET \_cluster/health { "cluster\_name": "my\_cluster", "status": "red", "timed\_out": false, "number\_of\_nodes": 20, "number\_of\_data\_nodes": 13, "active\_primary\_shards"…

---

## [BulkIngester index operation does not propagate pipeline if defined](https://discuss.elastic.co/t/bulkingester-index-operation-does-not-propagate-pipeline-if-defined/338781)

<div class="topic-metadata">

**Author:** [@ng.software.dev](https://discuss.elastic.co/u/ng.software.dev)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 2:22pm UTC](https://discuss.elastic.co/t/bulkingester-index-operation-does-not-propagate-pipeline-if-defined/338781 "2023-07-19T14:22:59Z")

</div>

I am using the BulkIngester utility in the Java API to stream index request to Elasticsearch. Consider the following snippet of code: bulkIngester.add(o -\> o.index(i -\> i .pipeline(pipeline) .index(index) .…

---

## [Pros and Cons of using Elastic as a vector database?](https://discuss.elastic.co/t/pros-and-cons-of-using-elastic-as-a-vector-database/338733)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 1:47pm UTC](https://discuss.elastic.co/t/pros-and-cons-of-using-elastic-as-a-vector-database/338733 "2023-07-19T13:47:28Z")

</div>

I'm comparing Elastic vs other pure vector databases vs Mongodb/redis offerings. Is anything wrong or supplemental? Thank you! Pros: It's an Elastic product, meaning high SLA and needless to buy other products when do…

---

## [How to send logs from IBM DataPower to logstash](https://discuss.elastic.co/t/how-to-send-logs-from-ibm-datapower-to-logstash/338715)

<div class="topic-metadata">

**Author:** [@ram\_mq](https://discuss.elastic.co/u/ram_mq)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 12:34pm UTC](https://discuss.elastic.co/t/how-to-send-logs-from-ibm-datapower-to-logstash/338715 "2023-07-19T12:34:08Z")

</div>

I would like to send logs from IBM DataPower to Logstash. Please advise how to send the logs?

---

## [How to fetch Ids from more than 10k records in single response](https://discuss.elastic.co/t/how-to-fetch-ids-from-more-than-10k-records-in-single-response/338749)

<div class="topic-metadata">

**Author:** [@Paras\_Rangani](https://discuss.elastic.co/u/Paras_Rangani)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-to-fetch-ids-from-more-than-10k-records-in-single-response/338749 "2023-07-19T11:21:20Z")

</div>

I have around 1 million documents , after applying the filters I get more than 10k records, but I do not want whole documents , instead I want the IDS of that records in a single call.How can I do that ?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=225)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=227)
