# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=234

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 235

---

## [Increase the replica size for the index](https://discuss.elastic.co/t/increase-the-replica-size-for-the-index/337501)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 6\
**Last updated:** [July 4, 2023, 7:12am UTC](https://discuss.elastic.co/t/increase-the-replica-size-for-the-index/337501 "2023-07-04T07:12:02Z")

</div>

Hi Team, we are continously searching the records from the particular index approxmately 25,000 times per hour,so the heap usage is increasing regular period. we already set the replica value as 1. Now we planned to in…

---

## [Alert when data is not coming from last 5 minute](https://discuss.elastic.co/t/alert-when-data-is-not-coming-from-last-5-minute/337517)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 6:24am UTC](https://discuss.elastic.co/t/alert-when-data-is-not-coming-from-last-5-minute/337517 "2023-07-04T06:24:15Z")

</div>

We are monitoring multiple servers with metricbeat and we want to create an alert when no data is receiving from last 5 minutes. I have check Index Threshold type But how we will check for each source ? We need to crea…

---

## [Is it possible to store document versions in Elastic Search](https://discuss.elastic.co/t/is-it-possible-to-store-document-versions-in-elastic-search/337496)

<div class="topic-metadata">

**Author:** [@Dishatkr](https://discuss.elastic.co/u/Dishatkr)\
**Replies:** 1\
**Last updated:** [July 4, 2023, 6:22am UTC](https://discuss.elastic.co/t/is-it-possible-to-store-document-versions-in-elastic-search/337496 "2023-07-04T06:22:55Z")

</div>

I have a question on storing different versions of a document in Elasticsearch, i.e. on document update we have to store the old version. We might not want to store all older versions, but at least multiple active versio…

---

## [How to send Filebeat to a different and specific index](https://discuss.elastic.co/t/how-to-send-filebeat-to-a-different-and-specific-index/337502)

<div class="topic-metadata">

**Author:** [@Xenial](https://discuss.elastic.co/u/Xenial)\
**Replies:** 1\
**Last updated:** [July 4, 2023, 5:13am UTC](https://discuss.elastic.co/t/how-to-send-filebeat-to-a-different-and-specific-index/337502 "2023-07-04T05:13:29Z")

</div>

Hello Elastic Team, How to send filebeat log to a different and specifix index?? Thankyou

---

## [Cancellation of tasks](https://discuss.elastic.co/t/cancellation-of-tasks/337454)

<div class="topic-metadata">

**Author:** [@henrhoi](https://discuss.elastic.co/u/henrhoi)\
**Replies:** 10\
**Last updated:** [July 3, 2023, 6:48pm UTC](https://discuss.elastic.co/t/cancellation-of-tasks/337454 "2023-07-03T18:48:51Z")

</div>

Hello Elastic community! We have been encountering some difficulties with cancelling longer running tasks in our Elasticsearch cluster and could really use some guidance from the experts here. Our current approach invol…

---

## [Is there any similar functionality in ES like joinquery and custome function in SOLR](https://discuss.elastic.co/t/is-there-any-similar-functionality-in-es-like-joinquery-and-custome-function-in-solr/337347)

<div class="topic-metadata">

**Author:** [@tengfei225](https://discuss.elastic.co/u/tengfei225)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 6:39pm UTC](https://discuss.elastic.co/t/is-there-any-similar-functionality-in-es-like-joinquery-and-custome-function-in-solr/337347 "2023-07-03T18:39:39Z")

</div>

Hi Currently we have two indices , like below index A including fields with user, targetIds (list type) index B including fields with id, targetId And we want to query from indexB with permission applied, one login u…

---

## [Elasticsearch - Certificate Error](https://discuss.elastic.co/t/elasticsearch-certificate-error/337489)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 6:15pm UTC](https://discuss.elastic.co/t/elasticsearch-certificate-error/337489 "2023-07-03T18:15:10Z")

</div>

Failed to connect to backoff(elasticsearch(https://es:9200)): Get "https://e Jul 03 16:52:00 elasticsearch\_host metricbeat\[1700\]: 2023-07-03T16:52:00.717Z INFO \[publisher\_pipeline\_output\] pipeline/ou…

---

## [Why only 5 phases for Index Lifecycle Management?](https://discuss.elastic.co/t/why-only-5-phases-for-index-lifecycle-management/337483)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 4:08pm UTC](https://discuss.elastic.co/t/why-only-5-phases-for-index-lifecycle-management/337483 "2023-07-03T16:08:44Z")

</div>

Basically what the subject says. Why only 5 phases for ILM? I'm experimenting with some things and was just wanting to use more so I could be aggressive with down sampling. I want to start with every metrics every 10s,…

---

## [Inject data with Node.js on Elasticsearch service](https://discuss.elastic.co/t/inject-data-with-node-js-on-elasticsearch-service/337474)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 5\
**Last updated:** [July 3, 2023, 3:44pm UTC](https://discuss.elastic.co/t/inject-data-with-node-js-on-elasticsearch-service/337474 "2023-07-03T15:44:27Z")

</div>

Hi, I want to ingest data on Elasticsearch using a Node.js backend. The following link has instructions regarding how to the same on Elastic Cloud deployment (Ingest data with Node.js on Elasticsearch Service | Elastic…

---

## [Using prefix in must\_not](https://discuss.elastic.co/t/using-prefix-in-must-not/337480)

<div class="topic-metadata">

**Author:** [@breiter](https://discuss.elastic.co/u/breiter)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 3:37pm UTC](https://discuss.elastic.co/t/using-prefix-in-must-not/337480 "2023-07-03T15:37:15Z")

</div>

I am currently trying to query my data and exclude everything that begins with "EP". Am I able to use both prefix and must\_not to satisfy this? If not, what can I use?

---

## [Can we update node roles of elastic using API](https://discuss.elastic.co/t/can-we-update-node-roles-of-elastic-using-api/337469)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 3\
**Last updated:** [July 3, 2023, 3:33pm UTC](https://discuss.elastic.co/t/can-we-update-node-roles-of-elastic-using-api/337469 "2023-07-03T15:33:50Z")

</div>

I do not have access to elasticsearch.yaml , can i update node roles of elastic using any API. version - 7.17

---

## [ERROR \[ExceptionHandler\] Cannot read properties of undefined (reading 'cloud')](https://discuss.elastic.co/t/error-exceptionhandler-cannot-read-properties-of-undefined-reading-cloud/337436)

<div class="topic-metadata">

**Author:** [@mohamad\_khubayb](https://discuss.elastic.co/u/mohamad_khubayb)\
**Replies:** 3\
**Last updated:** [July 3, 2023, 3:09pm UTC](https://discuss.elastic.co/t/error-exceptionhandler-cannot-read-properties-of-undefined-reading-cloud/337436 "2023-07-03T15:09:09Z")

</div>

I'm trying to use ElasticSearch in a NestJs project. The problem is after setting up everything I getting this error:

---

## [Percolator on Elastic Search version 8 with JAVA API](https://discuss.elastic.co/t/percolator-on-elastic-search-version-8-with-java-api/337476)

<div class="topic-metadata">

**Author:** [@ulysse42](https://discuss.elastic.co/u/ulysse42)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 2:50pm UTC](https://discuss.elastic.co/t/percolator-on-elastic-search-version-8-with-java-api/337476 "2023-07-03T14:50:07Z")

</div>

Hello Elasticsearch community, Is there a way to use the percolator in the new version of Elasticsearch (8.6.2) with the Java API ? I am currently using the spring data Elasticsearch framework (5.1). But I can't find a…

---

## [Elastic server is not starting](https://discuss.elastic.co/t/elastic-server-is-not-starting/337460)

<div class="topic-metadata">

**Author:** [@Pooja\_Sharma](https://discuss.elastic.co/u/Pooja_Sharma)\
**Replies:** 2\
**Last updated:** [July 3, 2023, 1:39pm UTC](https://discuss.elastic.co/t/elastic-server-is-not-starting/337460 "2023-07-03T13:39:29Z")

</div>

Hi, We are using |MediaWiki|1.39.3| |\[PHP\] 8.1.20 | |\[MySQL 8.0.31| Elastic Search 7.10.2 Now when we are disabling this volumemount volumeMounts: - type: azure-blob name: storage storage: elasticsearch-data p…

---

## [Configure NGINX Proxy for Elastic](https://discuss.elastic.co/t/configure-nginx-proxy-for-elastic/337462)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 1:30pm UTC](https://discuss.elastic.co/t/configure-nginx-proxy-for-elastic/337462 "2023-07-03T13:30:52Z")

</div>

I configured three nodes as master. I created a certificate for each one, which is used in HTTP and Transport requests. There is also a username with a password to access the elasticsearch. Note: Since I created the c…

---

## [Index template creation](https://discuss.elastic.co/t/index-template-creation/337049)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 6\
**Last updated:** [July 3, 2023, 12:48pm UTC](https://discuss.elastic.co/t/index-template-creation/337049 "2023-07-03T12:48:36Z")

</div>

during the template creation based on the json data , i am facing the issues for the data, even i have defined the nested type. please suggest . "type": "illegal\_argument\_exception", "reason": "composable template \[…

---

## [Slow log took time questions](https://discuss.elastic.co/t/slow-log-took-time-questions/337384)

<div class="topic-metadata">

**Author:** [@tengfei225](https://discuss.elastic.co/u/tengfei225)\
**Replies:** 3\
**Last updated:** [July 3, 2023, 12:25pm UTC](https://discuss.elastic.co/t/slow-log-took-time-questions/337384 "2023-07-03T12:25:44Z")

</div>

Hi I have some questions about the slow log took time I want to only get the process time in elasticsearch server using esrally to do the benchmark So I opened the slow log like below PUT /myIndex/\_settings { "i…

---

## [Elasticsearch es-client pods are down after master node reboot](https://discuss.elastic.co/t/elasticsearch-es-client-pods-are-down-after-master-node-reboot/337442)

<div class="topic-metadata">

**Author:** [@Shyamsundar\_Rajkumar](https://discuss.elastic.co/u/Shyamsundar_Rajkumar)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 10:34am UTC](https://discuss.elastic.co/t/elasticsearch-es-client-pods-are-down-after-master-node-reboot/337442 "2023-07-03T10:34:22Z")

</div>

I have deployed Elasticsearch 7 in our kubernetes cluster. The es-client-7 pods are going down when the master node is rebooted. When checking logs I found "master not discovered yet" . The statefulsets es-master and es…

---

## [ILM Policy getting stuck here](https://discuss.elastic.co/t/ilm-policy-getting-stuck-here/337383)

<div class="topic-metadata">

**Author:** [@dhawal](https://discuss.elastic.co/u/dhawal)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 10:16am UTC](https://discuss.elastic.co/t/ilm-policy-getting-stuck-here/337383 "2023-07-03T10:16:56Z")

</div>

I am getting below mentioned status here for most of the index i have. \[Index name\]lifecycle action \[migrate\] waiting for \[6\] shards to be moved to the \[data\_warm\] tier (tier migration preference configuration is \[data\_…

---

## [Track down responsible queries for deprecation warnings](https://discuss.elastic.co/t/track-down-responsible-queries-for-deprecation-warnings/337425)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 7:51am UTC](https://discuss.elastic.co/t/track-down-responsible-queries-for-deprecation-warnings/337425 "2023-07-03T07:51:31Z")

</div>

Hello, we want to finally upgrade our cluster to version 8. According to the Upgrade Assistant in Kibana, we only need to check the deprecation logs. In these I find something like this \[2023-06-30T14:36:47,251\]\[CRITI…

---

## [Transform nicing](https://discuss.elastic.co/t/transform-nicing/337277)

<div class="topic-metadata">

**Author:** [@ddolcimascolo](https://discuss.elastic.co/u/ddolcimascolo)\
**Replies:** 2\
**Last updated:** [July 3, 2023, 7:48am UTC](https://discuss.elastic.co/t/transform-nicing/337277 "2023-07-03T07:48:27Z")

</div>

Hi guys, We make use of transforms extensively in a production cluster (6 nodes of 20 CPU 32GB RAM, all nodes have all roles) with approximatively 250 transforms running in continuous mode. Some transforms have a freque…

---

## [Caused by: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate",](https://discuss.elastic.co/t/caused-by-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/337415)

<div class="topic-metadata">

**Author:** [@Khumendra](https://discuss.elastic.co/u/Khumendra)\
**Replies:** 0\
**Last updated:** [July 3, 2023, 5:46am UTC](https://discuss.elastic.co/t/caused-by-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/337415 "2023-07-03T05:46:30Z")

</div>

Hi Team, Please help me on this when I am trying to integrate apm-server I get this error. kubectl logs elasticsearch-master-0 -n \[namespace\] "stacktrace": \["io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHa…

---

## [About commercial use of the free version](https://discuss.elastic.co/t/about-commercial-use-of-the-free-version/337410)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 3:47am UTC](https://discuss.elastic.co/t/about-commercial-use-of-the-free-version/337410 "2023-07-03T03:47:09Z")

</div>

of the following sites Is "Wildcard field type" of "Free and open-Basic 1,2" available for commercial use free of charge? Is "Free and open -Basic 1, 2" already free for commercial use? I look forward to hearing fro…

---

## ["order" question](https://discuss.elastic.co/t/order-question/337153)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 6\
**Last updated:** [July 2, 2023, 11:54pm UTC](https://discuss.elastic.co/t/order-question/337153 "2023-07-02T23:54:09Z")

</div>

Hello. I would like to ask you something about the text on the official website below. GET /my-index-000001/\_search { "sort" : \[ { "post\_date" : {"order" : "asc", "format": "strict\_date\_optional\_time\_nanos"}}, …

---

## [Gork not work as excpected](https://discuss.elastic.co/t/gork-not-work-as-excpected/337389)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 2, 2023, 4:09pm UTC](https://discuss.elastic.co/t/gork-not-work-as-excpected/337389 "2023-07-02T16:09:51Z")

</div>

Hi Here is my gork filter: \\\[SqlExceptionHelper\\\] SQL (Error|Warning Code): %{NUMBER:error\_code}, SQLState: %{WORD:sql\_state} here is my log: 2023-06-30 01:54:38,867 WARN CUS.InEP-APPGW-121662220 \[SqlExceptionHelper…

---

## [How to receive logs from Kaspersky endpoint security to elasticsearch](https://discuss.elastic.co/t/how-to-receive-logs-from-kaspersky-endpoint-security-to-elasticsearch/336852)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 2\
**Last updated:** [July 2, 2023, 4:01pm UTC](https://discuss.elastic.co/t/how-to-receive-logs-from-kaspersky-endpoint-security-to-elasticsearch/336852 "2023-07-02T16:01:31Z")

</div>

Hi everyone, i am new in elasticsearch . I configured Fortinet, and it works fine. I want to know how I can retrieve logs and dates from the KES server and solarwinds."

---

## [Training elasticsearch](https://discuss.elastic.co/t/training-elasticsearch/336917)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 4\
**Last updated:** [July 2, 2023, 3:00pm UTC](https://discuss.elastic.co/t/training-elasticsearch/336917 "2023-07-02T15:00:55Z")

</div>

Hi all, As a beginner in elasticsearch and recent gratuate engineering id like to gain a better understanding of market requirements in order to better direct my carrer would you have any tasks or project that would ena…

---

## [Elasticsearch and VeloCloud / VMWare SDWAN](https://discuss.elastic.co/t/elasticsearch-and-velocloud-vmware-sdwan/335810)

<div class="topic-metadata">

**Author:** [@hogie365](https://discuss.elastic.co/u/hogie365)\
**Replies:** 4\
**Last updated:** [July 2, 2023, 8:50am UTC](https://discuss.elastic.co/t/elasticsearch-and-velocloud-vmware-sdwan/335810 "2023-07-02T08:50:39Z")

</div>

Afternoon - I'm new to Elasticsearch and want to see if it's possible to connect to a VeloCloud API to pull and analyze logs from the VeloCloud orchestrator. We've been struggling getting back any real content over SNMP…

---

## [How to detect status transition in ingested log data](https://discuss.elastic.co/t/how-to-detect-status-transition-in-ingested-log-data/337335)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 2\
**Last updated:** [July 2, 2023, 4:00am UTC](https://discuss.elastic.co/t/how-to-detect-status-transition-in-ingested-log-data/337335 "2023-07-02T04:00:52Z")

</div>

I would like to ask for a high-level advice how to approach the following problem (we have on-premise Elastic 8.8.0). Periodically every 30 seconds, the following data about status of a resource is ingested into Elastic…

---

## [Find unusual pattern](https://discuss.elastic.co/t/find-unusual-pattern/337145)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 4\
**Last updated:** [July 1, 2023, 4:26pm UTC](https://discuss.elastic.co/t/find-unusual-pattern/337145 "2023-07-01T16:26:41Z")

</div>

Need to find unusual send and receive patterns in huge log file, here is the example: 00:00:01.000 S-001 \< 00:00:01.000 S-002 \< 00:00:01.000 S-003 \< 00:00:01.000 S-004 \< 00:00:01.000 S-005 0…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=233)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=235)
