# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=229

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 230

---

## [Version conflict - no document found on update-by-query](https://discuss.elastic.co/t/version-conflict-no-document-found-on-update-by-query/338262)

<div class="topic-metadata">

**Author:** [@Balagopal\_Kanattil](https://discuss.elastic.co/u/Balagopal_Kanattil)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 3:40pm UTC](https://discuss.elastic.co/t/version-conflict-no-document-found-on-update-by-query/338262 "2023-07-14T15:40:24Z")

</div>

Hi, I am running a self hosted ES cluster with version 6.8.1. I am trying to update some docs using update-by-query API. It fails for some documents with following error: version\_conflict\_engine\_exception version con…

---

## [Phase out VM from cluster](https://discuss.elastic.co/t/phase-out-vm-from-cluster/338422)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 2\
**Last updated:** [July 14, 2023, 2:50pm UTC](https://discuss.elastic.co/t/phase-out-vm-from-cluster/338422 "2023-07-14T14:50:57Z")

</div>

Hi, I have an issue where one of my hot nodes has a larger disk than needed. Since I can't downsize the disk and due to the volume of data, I can't simply copy over to a smaller disk. So I thought it'd be the easiest (…

---

## [Facing java.io.EOFException: read past EOF exception and org.apache.lucene.index.CorruptIndexException: compound sub-files must have a valid codec header and footer: file is too small (0 bytes) in elastic 7.17.5](https://discuss.elastic.co/t/facing-java-io-eofexception-read-past-eof-exception-and-org-apache-lucene-index-corruptindexexception-compound-sub-files-must-have-a-valid-codec-header-and-footer-file-is-too-small-0-bytes-in-elastic-7-17-5/338370)

<div class="topic-metadata">

**Author:** [@Kesavan](https://discuss.elastic.co/u/Kesavan)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 10:34am UTC](https://discuss.elastic.co/t/facing-java-io-eofexception-read-past-eof-exception-and-org-apache-lucene-index-corruptindexexception-compound-sub-files-must-have-a-valid-codec-header-and-footer-file-is-too-small-0-bytes-in-elastic-7-17-5/338370 "2023-07-14T10:34:03Z")

</div>

In one our environment we are facing the "CorruptIndexException". While analyzing the elastic log we found the below are the list of exception details: infinity\_infinity-elasticsearch.1.862455ajz1ca@WorkerNode03Prod …

---

## [Eck stack helm install, expose ingress](https://discuss.elastic.co/t/eck-stack-helm-install-expose-ingress/338399)

<div class="topic-metadata">

**Author:** [@simonebenati](https://discuss.elastic.co/u/simonebenati)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 10:31am UTC](https://discuss.elastic.co/t/eck-stack-helm-install-expose-ingress/338399 "2023-07-14T10:31:30Z")

</div>

Hello, I installed eck operator via helm and then the eck stack via helm. Now I want to expose via ingress Elasticsearch but I am not able to find anywhere in the helm values or docs the value in order to expose an ingr…

---

## [Logstash grok pattern for apache error log](https://discuss.elastic.co/t/logstash-grok-pattern-for-apache-error-log/337676)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 4:59am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-for-apache-error-log/337676 "2023-07-14T04:59:24Z")

</div>

Hi experts, Can any one tell me that how to configure the logstash grok custom pattern for apache web server error log. below is my apache web server sample error log, \[Fri Jun 09 08:26:38.311375 2023\] \[proxy\_fcgi:err…

---

## [Snapshotter setup](https://discuss.elastic.co/t/snapshotter-setup/338365)

<div class="topic-metadata">

**Author:** [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 3:33am UTC](https://discuss.elastic.co/t/snapshotter-setup/338365 "2023-07-14T03:33:39Z")

</div>

Can I setup a new repository to take snapshots today onwards without having to restart the data and master nodes on the Elastic Search cluster ? I am currently using ES 7.16 . The old snapshots are not available and ther…

---

## [Kibana Watcher to trigger email by checking aggregation results with dynamic threshold value](https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357)

<div class="topic-metadata">

**Author:** [@Santosh1667](https://discuss.elastic.co/u/Santosh1667)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:30pm UTC](https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357 "2023-07-13T20:30:17Z")

</div>

Hi , I had a Kibana watcher which will give aggregation buckets in below format distinct\_error\_count:\[ { key:"Error 1 Occured", distinct\_count:6 }, { key:"Error 2 Occured", distinct\_count:4 }, { key:"Error 3 Occured", d…

---

## [Terms aggregation over section of a keyword](https://discuss.elastic.co/t/terms-aggregation-over-section-of-a-keyword/338351)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 5:55pm UTC](https://discuss.elastic.co/t/terms-aggregation-over-section-of-a-keyword/338351 "2023-07-13T17:55:59Z")

</div>

Hi, I have an index with a keyword field. The values are in the form '\<code\>\<numbers\>' where I know the code is a three figures number (e.g., in '123456789' the code is 123). I want to perform an aggregation like a term…

---

## [Elasticsearch creating different indices with identical data](https://discuss.elastic.co/t/elasticsearch-creating-different-indices-with-identical-data/338352)

<div class="topic-metadata">

**Author:** [@mfisher](https://discuss.elastic.co/u/mfisher)\
**Replies:** 5\
**Last updated:** [July 13, 2023, 6:30pm UTC](https://discuss.elastic.co/t/elasticsearch-creating-different-indices-with-identical-data/338352 "2023-07-13T18:30:00Z")

</div>

I recently moved from ELK stack 7.X to 8.8.2. I'm using my old Logstash pipline confs. For some reason Elasticsearch/Kibana is showing each individual index but each index as the same data. I don't think its a datavie…

---

## [Anomaly Detection Rule Won't Send Email](https://discuss.elastic.co/t/anomaly-detection-rule-wont-send-email/338244)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 6\
**Last updated:** [July 13, 2023, 2:02pm UTC](https://discuss.elastic.co/t/anomaly-detection-rule-wont-send-email/338244 "2023-07-13T14:02:45Z")

</div>

Hi all. I'm evaluating Anomaly alerting using a locally hosted Platinum trial. In short, the anomaly detection Job itself is working. I can see anomalies in the results. And I have set up a Rule with a Connector. I…

---

## [Elasticsearch Cluster Health watch Watcher](https://discuss.elastic.co/t/elasticsearch-cluster-health-watch-watcher/338321)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 8\
**Last updated:** [July 13, 2023, 1:36pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-watch-watcher/338321 "2023-07-13T13:36:55Z")

</div>

Hi Team, I am trying to create a watcher for cluster health check (Clluster is 3 master and 5 data node ) as per Elastic documentation In the input section it is referred to provide host as host:localhost "input" :…

---

## [ECE & Watcher: Trouble sending API key to ECE](https://discuss.elastic.co/t/ece-watcher-trouble-sending-api-key-to-ece/300980)

<div class="topic-metadata">

**Author:** [@Apprentice](https://discuss.elastic.co/u/Apprentice)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 1:05pm UTC](https://discuss.elastic.co/t/ece-watcher-trouble-sending-api-key-to-ece/300980 "2023-07-13T13:05:45Z")

</div>

I am trying to create a Watcher using information from the ECE API as input. However I am having trouble getting authenticated. This is the Input for the watcher: "input": { "http" : { "request" : { "s…

---

## [Controlled rotation of elasticsearch data nodes while enabling the shard allocation awareness](https://discuss.elastic.co/t/controlled-rotation-of-elasticsearch-data-nodes-while-enabling-the-shard-allocation-awareness/338269)

<div class="topic-metadata">

**Author:** [@veerachenna](https://discuss.elastic.co/u/veerachenna)\
**Replies:** 7\
**Last updated:** [July 13, 2023, 10:44am UTC](https://discuss.elastic.co/t/controlled-rotation-of-elasticsearch-data-nodes-while-enabling-the-shard-allocation-awareness/338269 "2023-07-13T10:44:16Z")

</div>

Hi All, We are trying to enable the shard allocation awareness on the elasticsearch cluster on "zone" attribute while rotating the data nodes one after the other. We wanted to achieve this in more controlled manner. Ini…

---

## [Reduce storage taken by specific index ? Freeze index ? Frozen tier ? Cold tier?](https://discuss.elastic.co/t/reduce-storage-taken-by-specific-index-freeze-index-frozen-tier-cold-tier/338311)

<div class="topic-metadata">

**Author:** [@mlng54](https://discuss.elastic.co/u/mlng54)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 9:53am UTC](https://discuss.elastic.co/t/reduce-storage-taken-by-specific-index-freeze-index-frozen-tier-cold-tier/338311 "2023-07-13T09:53:13Z")

</div>

Hi everyone, I recently experienced a DDoS attack on my Apache server. The logs are sent to Elasticsearch, so my last indices are around 70Gb/day. I have not configured ILM on my ELK stack yet but I would like to reduce…

---

## [How to support complex filters in nested aggregation?](https://discuss.elastic.co/t/how-to-support-complex-filters-in-nested-aggregation/337444)

<div class="topic-metadata">

**Author:** [@crowod](https://discuss.elastic.co/u/crowod)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 8:51am UTC](https://discuss.elastic.co/t/how-to-support-complex-filters-in-nested-aggregation/337444 "2023-07-13T08:51:56Z")

</div>

Here is my index mapping: { "mappings": { "properties": { "non\_nested\_field": { "type": "keyword" }, "nested\_field": { "type": "nested", "properties": { "subfiel…

---

## [My ELK CLuster health is showing yellow](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:39am UTC](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292 "2023-07-13T08:39:55Z")

</div>

My ELK Cluster health is showing yellow. Missing replica shards. i am creating index using python code es.index , in that where i have to define replica shard. image is attached.

---

## [Want to create technical support case in Elastic Search](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 7:02am UTC](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277 "2023-07-13T07:02:44Z")

</div>

I want access to the technical support in Elastic Search. I am Organisational owner but not able to access to the technical support. I have only access to account or billing.

---

## [Need assistance for Uninstalling fleet agent on multiple workstation remotely](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 6:06am UTC](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282 "2023-07-13T06:06:24Z")

</div>

Hello, Recently we have deployed fleet agent on windows workstations remotely through GPO. Some of the workstations are facing high CPU usage issue. For That we need assistance for uninstalling the agents remotely. I ca…

---

## [Is leader sync cluster state to node when new node join cluster?](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 5:54am UTC](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185 "2023-07-13T05:54:58Z")

</div>

When a new node or a previously joined node that was later expelled joins a stable cluster, will the leader synchronize the latest cluster status with them? If so, who can tell me where to find this functionality? I have…

---

## [Action over webhook status](https://discuss.elastic.co/t/action-over-webhook-status/338278)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 5:45am UTC](https://discuss.elastic.co/t/action-over-webhook-status/338278 "2023-07-13T05:45:20Z")

</div>

Hi, I have a watcher with webhook action in it. Is it possible to make another action based on webhook response status? Something like that actions: { webhook\_action: { webhook: { scheme: host: …

---

## [LogStash::Json::ParserError: Unexpected character (':' (code 58))](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864 "2023-07-13T05:17:49Z")

</div>

i am facing the unexpected character error code 58 in my json data. even after validation of the data the logstash is reporting the errors . below is the sample data , can anyone help why logstash reporting an error here…

---

## [Elasticsearch 8.8: Master not discovered or elected yet, an election requires at least 2 nodes with ids from \[..\]](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034 "2023-07-13T05:17:48Z")

</div>

I am creating a multinode cluster (3 Master Nodes), having the configuration like xpack.ml.enabled: false xpack.security.enabled: false network.host: \[\_local\_, \_site\_\] path.data: /data/esdata path.logs: /data/logs xpack…

---

## [Is elastic Ingest pipelines resource intensive?](https://discuss.elastic.co/t/is-elastic-ingest-pipelines-resource-intensive/338049)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 7\
**Last updated:** [July 13, 2023, 4:30am UTC](https://discuss.elastic.co/t/is-elastic-ingest-pipelines-resource-intensive/338049 "2023-07-13T04:30:05Z")

</div>

Hi, I am currently using injest pipelines to enrich my document before it wrote into index. I am wondering if this process would have a potenial hugh resouce(heap ram or cpu) comsumed for my Elasticsearch node behind …

---

## [Index template failing with "reason": "unknown key \[index\_patterns\] for create index"](https://discuss.elastic.co/t/index-template-failing-with-reason-unknown-key-index-patterns-for-create-index/338270)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 3:04am UTC](https://discuss.elastic.co/t/index-template-failing-with-reason-unknown-key-index-patterns-for-create-index/338270 "2023-07-13T03:04:51Z")

</div>

I am facing the unknown key for my index template creation time, "reason": "unknown key \[index\_patterns\] for create index" below is the top heading of my template { "index\_patterns" : \[ "data\_center-…

---

## [Elastic Search / ILM / Snapshots S3/Minio](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:42pm UTC](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263 "2023-07-12T22:42:59Z")

</div>

I have been asked to do a POC to see how to properly configure our systems so that ILM will before it deletes an indice will take a snapshot of the indice and store it into S3/Minio. I have successfully updated the clust…

---

## [Node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258 "2023-07-12T20:12:31Z")

</div>

node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working. I am ok to loose the data but not able to start the cluster a fresh. Please suggest.

---

## [Sending request to one index, writing to multiple indices](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 23\
**Last updated:** [July 12, 2023, 7:19pm UTC](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079 "2023-07-12T19:19:13Z")

</div>

I have a index named index1. I want to configure it such that any write/update request that comes to index1 gets written to both index1 and index2 but any search request still uses index1. Is this possible with some exis…

---

## [Ingest error from one pipeline causing errors in other pipelines](https://discuss.elastic.co/t/ingest-error-from-one-pipeline-causing-errors-in-other-pipelines/338255)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 6:53pm UTC](https://discuss.elastic.co/t/ingest-error-from-one-pipeline-causing-errors-in-other-pipelines/338255 "2023-07-12T18:53:42Z")

</div>

The problem we are experiencing is that an ingest error from the Apache integration (agent) is causing an enrichment processor in a separate pipeline to fail with the same error the Apache processor failed with. This is…

---

## [Elasticsearch 7.17 suddenly prevents login](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249)

<div class="topic-metadata">

**Author:** [@eastdrive](https://discuss.elastic.co/u/eastdrive)\
**Replies:** 4\
**Last updated:** [July 12, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249 "2023-07-12T18:35:38Z")

</div>

I installed elasticsearch 7.17.11 from the artifacts.elastic.co repo with security, on a fresh Ubuntu 20.04.6 node a couple of days ago, for a Magento 2.4.5-p3 store. It worked fine, certainly allowed me to connect remot…

---

## [Version mismatch message even though versions match](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 15\
**Last updated:** [July 12, 2023, 3:49pm UTC](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819 "2023-07-12T15:49:08Z")

</div>

Hi all. I'm trying out ELK 8.8.2, and getting this message: Job creation error The client noticed that the server is not Elasticsearch and we do not support this unknown product. All explanations in various posts s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=228)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=230)
