# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=227

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 228

---

## [ELSER deployments crash kibana and fail deployment](https://discuss.elastic.co/t/elser-deployments-crash-kibana-and-fail-deployment/337344)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 10:06am UTC](https://discuss.elastic.co/t/elser-deployments-crash-kibana-and-fail-deployment/337344 "2023-07-19T10:06:30Z")

</div>

Trying to test ELSER following this tutorial, but I cannot get past the very first step of deploying the ELSER model. I have a 4GB ML node, as specified. Every time I try to deploy the ELSER model, my Kibana node crashe…

---

## [Filter results by another query](https://discuss.elastic.co/t/filter-results-by-another-query/338763)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 10:01am UTC](https://discuss.elastic.co/t/filter-results-by-another-query/338763 "2023-07-19T10:01:07Z")

</div>

I have a usecase where I want to search for documents that do not have counterparts in the index. For example, consider the following: I have a document format like this: { "file": "myfile.ext", "classificatio…

---

## [Is it recommended to disable sniffer and always direct the requests to the k8s HTTP SVC instead?](https://discuss.elastic.co/t/is-it-recommended-to-disable-sniffer-and-always-direct-the-requests-to-the-k8s-http-svc-instead/338762)

<div class="topic-metadata">

**Author:** [@GustavoSantos](https://discuss.elastic.co/u/GustavoSantos)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:36am UTC](https://discuss.elastic.co/t/is-it-recommended-to-disable-sniffer-and-always-direct-the-requests-to-the-k8s-http-svc-instead/338762 "2023-07-19T09:36:04Z")

</div>

Hi all, Our ES clusters are deployed in k8s using the eck-operator and our application uses the Java client with sniffer enabled. We are currently struggling with an annoying issue when the cluster is restarted. By th…

---

## [Wrongly named the container of the master node](https://discuss.elastic.co/t/wrongly-named-the-container-of-the-master-node/338756)

<div class="topic-metadata">

**Author:** [@BogdanS](https://discuss.elastic.co/u/BogdanS)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:05am UTC](https://discuss.elastic.co/t/wrongly-named-the-container-of-the-master-node/338756 "2023-07-19T09:05:30Z")

</div>

Hi all. When I first created the Elasticsearch cluster in GKE with the ECK (1 master node, 32 data nodes), I gave a name to the container inside the master node - "elasticsearch-master". 6 months in, and 14 TB later, I …

---

## [ES node handshake failed](https://discuss.elastic.co/t/es-node-handshake-failed/338743)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 6:17am UTC](https://discuss.elastic.co/t/es-node-handshake-failed/338743 "2023-07-19T06:17:43Z")

</div>

Hi team, I am trying to start cluster on my MacBook. I got below error \[2023-07-19T14:16:03,014\]\[WARN \]\[o.e.d.HandshakingTransportAddressConnector\] \[node-2\] \[connectToRemoteMasterNode\[127.0.0.1:9301\]\] completed handsha…

---

## [Index rollover ealier than described in ILM index lifecycle management](https://discuss.elastic.co/t/index-rollover-ealier-than-described-in-ilm-index-lifecycle-management/337996)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 3:29am UTC](https://discuss.elastic.co/t/index-rollover-ealier-than-described-in-ilm-index-lifecycle-management/337996 "2023-07-19T03:29:22Z")

</div>

Hi everyone, I have setup a TSDS with following ILM in ES 8.8.2 GET .ds-micrometer-metrics-2023.07.08-000036/\_ilm/explain ".ds-micrometer-metrics-2023.07.08-000036": { "index": ".ds-micrometer-metrics-2023.07.0…

---

## [Add some default data to ES when docker first run](https://discuss.elastic.co/t/add-some-default-data-to-es-when-docker-first-run/338701)

<div class="topic-metadata">

**Author:** [@TranTruongMMCII](https://discuss.elastic.co/u/TranTruongMMCII)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 2:30am UTC](https://discuss.elastic.co/t/add-some-default-data-to-es-when-docker-first-run/338701 "2023-07-19T02:30:28Z")

</div>

Dear all, I am new to ES. Now I want to create a docker to run ES, but I faced some errors. Firstly, I can create a docker to run ES and can interact with it. But I want to add some default data to index when docker fir…

---

## [Set top\_hits size dynamically for each bucket based on its doc\_count with a script](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728)

<div class="topic-metadata">

**Author:** [@DMinovski](https://discuss.elastic.co/u/DMinovski)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 11:31pm UTC](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728 "2023-07-18T23:31:51Z")

</div>

I use a query to find the duplicates in an index based on a field. Some documents have the same value in this field and they are duplicates. { "size": 0, "aggs": { "duplicate\_terms": { "terms…

---

## [Data streams stuck in frozen searchable\_snapshot phase (wait state inconsistent with indices status)](https://discuss.elastic.co/t/data-streams-stuck-in-frozen-searchable-snapshot-phase-wait-state-inconsistent-with-indices-status/338727)

<div class="topic-metadata">

**Author:** [@Adrien\_WATTEZ](https://discuss.elastic.co/u/Adrien_WATTEZ)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 10:51pm UTC](https://discuss.elastic.co/t/data-streams-stuck-in-frozen-searchable-snapshot-phase-wait-state-inconsistent-with-indices-status/338727 "2023-07-18T22:51:40Z")

</div>

This request follows a previous ticket that was never really answered. ES 8.8.2 - free trial in local - paid enterprise licence on other environment Same problem, I have created a data stream with ILM with phases rang…

---

## [Elasticsearch delete docs during the indexations](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674)

<div class="topic-metadata">

**Author:** [@atombrownbear](https://discuss.elastic.co/u/atombrownbear)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 9:53pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674 "2023-07-18T21:53:06Z")

</div>

Hi all! When im do indexation, my backend app sends 1234 pages (for example). if I call /stats? by curl I will see that 1234 pages have been indexed and 234 pages have been deleted, although they should not be deleted. w…

---

## [Custom analyser for numeric string](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 8:32pm UTC](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529 "2023-07-18T20:32:19Z")

</div>

Hi everyone. I have this kind of issue: I have a numeric string field, seperated with dots, like "1.1.2", "11.2.1", and the like. I have a requirement to do sorting by this field, and when I try to sort by that field, i…

---

## [Which configuration schemes are avaliable in 8.8 version of elastic clusterization?](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 20\
**Last updated:** [July 18, 2023, 7:57pm UTC](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137 "2023-07-18T19:57:03Z")

</div>

which configuration schemes are avaliable in 8.8 version of slatic clusterization?

---

## [Setup filebeat to send different logs to different indexes (to elasticsearch)](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 6:36pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709 "2023-07-18T18:36:10Z")

</div>

Hello, I setup a filebeat 8.8.2 on redhat host and configured my filebeat.yml like this, Im sending all my log data to ES directly, filebeat.inputs: - type: filestream id: my\_id enabled: true paths: - /home/cu…

---

## [Fast Vector Highlighting is not working stable on Synonym based fields](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673)

<div class="topic-metadata">

**Author:** [@Pavithra2014](https://discuss.elastic.co/u/Pavithra2014)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 4:05pm UTC](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673 "2023-07-18T16:05:20Z")

</div>

Here , we are using Fast Vector highlight on a field where it has the copy field for synonym . for some records FVH highlights properly but for some it is not. Field mapping: title: { type: "text", term\_vector: "with\_p…

---

## [Facing permission issues on running up \`elastic-package stack up\`](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 3:08pm UTC](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566 "2023-07-18T15:08:16Z")

</div>

Getting the below exception on running elastic-package stack up ERROR: Elasticsearch exited unexpectedly java.nio.file.AccessDeniedException: /usr/share/elasticsearch/config/certs at java.base/sun.nio.fs.UnixException.…

---

## [Configuration scheme issue](https://discuss.elastic.co/t/configuration-scheme-issue/338110)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/configuration-scheme-issue/338110 "2023-07-11T13:52:08Z")

</div>

i have to cofigure a clúster with 5Teras data ingest per day in 4 data nodes the thing is, if I installed elastisearch 8.8 which configuration is the best for these schema, single node configuration with the voting s…

---

## [Elasticsearch error when trying to run bin/elasticsearch-setup-passwords](https://discuss.elastic.co/t/elasticsearch-error-when-trying-to-run-bin-elasticsearch-setup-passwords/338625)

<div class="topic-metadata">

**Author:** [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/elasticsearch-error-when-trying-to-run-bin-elasticsearch-setup-passwords/338625 "2023-07-18T14:14:12Z")

</div>

I am setting up Elasticsearch version 7.17.11 on Ubuntu 20.04. It will be a single instance of Elasticsearch but I will have separate instances for Kibana and Logstash. I am trying to recreate our setup in another cloud …

---

## [How to create email alerts in kibana](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 11\
**Last updated:** [July 18, 2023, 9:37am UTC](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219 "2023-07-18T09:37:00Z")

</div>

how can i create email alert for logs in elasticsearch and how can i create connectors in kibana UI

---

## [Elasticsearch performance degrades after upgrading from 6.7 to 7.10](https://discuss.elastic.co/t/elasticsearch-performance-degrades-after-upgrading-from-6-7-to-7-10/338640)

<div class="topic-metadata">

**Author:** [@teanoon](https://discuss.elastic.co/u/teanoon)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-performance-degrades-after-upgrading-from-6-7-to-7-10/338640 "2023-07-18T09:28:59Z")

</div>

We are trying to migrate the elasticsearch from 6.7 to 7.10. The indices are reindexed in the new elasticsearch cluster. And did some comparisons. simple load test is slow A simple load test indicates that the same se…

---

## [I/O wait is increasing after many reindexing](https://discuss.elastic.co/t/i-o-wait-is-increasing-after-many-reindexing/337695)

<div class="topic-metadata">

**Author:** [@yannlef](https://discuss.elastic.co/u/yannlef)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 8:21am UTC](https://discuss.elastic.co/t/i-o-wait-is-increasing-after-many-reindexing/337695 "2023-07-18T08:21:13Z")

</div>

Hello, I'm trying to find some response here, since I think I exhausted all my solutions on that problem. I'm also totally new with this subject. I am working on an old ELK (5.5), hosted on a docker in a dedicated VM …

---

## [Can't send data to elastic after upgrade the version](https://discuss.elastic.co/t/cant-send-data-to-elastic-after-upgrade-the-version/338634)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 7:41am UTC](https://discuss.elastic.co/t/cant-send-data-to-elastic-after-upgrade-the-version/338634 "2023-07-18T07:41:36Z")

</div>

Hi, previously we used Elastic & Logstash version 7.15 to store data. But after we upgraded to version 8 the data could not be sent. We used the same Logstash configuration and added a few things that changed in version …

---

## [Elasticsearch failed to start 8.8](https://discuss.elastic.co/t/elasticsearch-failed-to-start-8-8/338616)

<div class="topic-metadata">

**Author:** [@Aditya\_Bollam](https://discuss.elastic.co/u/Aditya_Bollam)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 7:35am UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-start-8-8/338616 "2023-07-18T07:35:41Z")

</div>

I am not able to start the service

---

## [Can I find out why is my elastic node has a high read rate every 12 hours](https://discuss.elastic.co/t/can-i-find-out-why-is-my-elastic-node-has-a-high-read-rate-every-12-hours/338194)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 7:34am UTC](https://discuss.elastic.co/t/can-i-find-out-why-is-my-elastic-node-has-a-high-read-rate-every-12-hours/338194 "2023-07-18T07:34:08Z")

</div>

Hi, Above is my elastic 3 days IO rate chart, it does have a special pattern between every 12 hours, the read will reach to a peak, but I am not sure what is the thing that can potentially cause this happens... is there…

---

## [Rackaware good practises](https://discuss.elastic.co/t/rackaware-good-practises/338632)

<div class="topic-metadata">

**Author:** [@bombovy](https://discuss.elastic.co/u/bombovy)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 6:43am UTC](https://discuss.elastic.co/t/rackaware-good-practises/338632 "2023-07-18T06:43:44Z")

</div>

Hello, We have really big log elastic cluster hosted on EKS in AWS. We are generating 17TB of logs each day. Also we are using data tiers for savings. The big costs issue that we are struggling now is the Data Transfer …

---

## [ECK 8.8.0 error.message":"javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate](https://discuss.elastic.co/t/eck-8-8-0-error-message-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/338619)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 1:53am UTC](https://discuss.elastic.co/t/eck-8-8-0-error-message-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/338619 "2023-07-18T01:53:48Z")

</div>

\[my-es-master-0 elasticsearch\] {"@timestamp":"2023-07-18T01:52:00.183Z", "log.level": "WARN", "message":"caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=/10.0.81.0:9…

---

## [How to delete system indices?](https://discuss.elastic.co/t/how-to-delete-system-indices/338510)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 1:37am UTC](https://discuss.elastic.co/t/how-to-delete-system-indices/338510 "2023-07-18T01:37:09Z")

</div>

Hi all, My current cluster is an upgraded cluster from version 7.x to 8.x It has alot of system indices that nolonger require in the cluster but whenever i tried to delete it. I got this message { "error": { "ro…

---

## [Truststore does not contain any trusted certificate entries](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610)

<div class="topic-metadata">

**Author:** [@sslgeorge](https://discuss.elastic.co/u/sslgeorge)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 11:36pm UTC](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610 "2023-07-17T23:36:57Z")

</div>

I used openssl to generate self signed certs for elasticsearch, but I am unable to use this certs to start elasticsearch. I keep getting the below error \[2023-07-16T19:42:22,649\]\[ERROR\]\[o.e.b.Elasticsearch \] \[Mac…

---

## [Composite aggregation returns after\_key even when there are no more buckets](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606)

<div class="topic-metadata">

**Author:** [@cdhowie](https://discuss.elastic.co/u/cdhowie)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:00pm UTC](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606 "2023-07-17T22:00:35Z")

</div>

I've been working on a query that performs a composite aggregation with a large number of buckets. When I set the aggregation size to 50,000, all buckets fit in the response. However, after\_key is still present in the re…

---

## [Installer Claims Version is Already Installed](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603)

<div class="topic-metadata">

**Author:** [@mreeg](https://discuss.elastic.co/u/mreeg)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 7:21pm UTC](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603 "2023-07-17T19:21:45Z")

</div>

Hello, I'm trying to Install a piece of software that utilizes Elasticsearch, and includes the Elasticsearch install as part of the installation process. Due to other errors, I had to uninstall the software (includin…

---

## [Logstash HTTP code 400 {:response\_code=\>400}](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 7:19pm UTC](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501 "2023-07-17T19:19:13Z")

</div>

Hi when i try to send data with logstash to influxdb return this error: \[ERROR\] 2023-07-17 09:21:36.133 \[\[main\]\>worker1\] http - Encountered non-2xx HTTP code 400 {:response\_code=\>400, :url=\>"http://192.168.1.2:8086/api…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=226)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=228)
