# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=235

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 236

---

## [Boostrap Elasticsearch Index Template](https://discuss.elastic.co/t/boostrap-elasticsearch-index-template/337377)

<div class="topic-metadata">

**Author:** [@mibeyki](https://discuss.elastic.co/u/mibeyki)\
**Replies:** 2\
**Last updated:** [July 1, 2023, 3:35pm UTC](https://discuss.elastic.co/t/boostrap-elasticsearch-index-template/337377 "2023-07-01T15:35:56Z")

</div>

Hello, I am trying to configure Filebeat to write data to a custom index like my-index-{now/d}-000001 (using filebeat-8.8.1 and Elastcicsearch 8.8.1). I have followed this guide; But when i try to bootstrap the index u…

---

## [Netflow Mikrotik no data in elasticsearch](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692)

<div class="topic-metadata">

**Author:** [@sana1567](https://discuss.elastic.co/u/sana1567)\
**Replies:** 20\
**Last updated:** [July 1, 2023, 2:29pm UTC](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692 "2023-07-01T14:29:16Z")

</div>

hello please help, installed elastic 8.8 + kibana filebeat + netflow I don't see data in my Elasticsearch also when checking the netflow module - check data - No data has been received from this module yet /etc/filebe…

---

## [Create snapshot API not working](https://discuss.elastic.co/t/create-snapshot-api-not-working/337244)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:29pm UTC](https://discuss.elastic.co/t/create-snapshot-api-not-working/337244 "2023-06-30T18:29:42Z")

</div>

We are new to the snapshot-and-restore function of Elasticsearch. Following the example below, we are trying to create a snapshot repository with the Console of Dev Tools. The Elasticsearch server under test runs as a D…

---

## [Getting latest data per user\_id in time series data without latest transforms?](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329)

<div class="topic-metadata">

**Author:** [@MaterializedView](https://discuss.elastic.co/u/MaterializedView)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:21pm UTC](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329 "2023-06-30T18:21:00Z")

</div>

I have a users index. Users have various status "New", "Waiting", "Completed". A status can go from "Completed" to "New" again. So in time series it would look something like user\_id, status, timestamp 1 NEW…

---

## [Change destination datastream with Elasticsearch ingest pipeline](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 6:11pm UTC](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912 "2023-06-30T18:11:51Z")

</div>

We run Elastic stack in docker containers. The container logs are collected with Elastic Agent, using docker integration and datastreams. This means that the logs of elasticsearch container itself by default end up in l…

---

## [Elasticsearch 8.8 dynamic search request query](https://discuss.elastic.co/t/elasticsearch-8-8-dynamic-search-request-query/336994)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:42pm UTC](https://discuss.elastic.co/t/elasticsearch-8-8-dynamic-search-request-query/336994 "2023-06-30T17:42:55Z")

</div>

SearchResponse\<ObjectNode\> searchResponse = elasticsearchClient.search(req -\> req.index(index) .from((pageNumber - 1) \* pageSize) .size(pageSize) …

---

## [Elasticsearch-PHP \[8.8\] - Search for field in date-range, Client Helpers SearchResponseIterator & SearchHitIterator](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237)

<div class="topic-metadata">

**Author:** [@DavidDPD](https://discuss.elastic.co/u/DavidDPD)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 4:41pm UTC](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237 "2023-06-30T16:41:08Z")

</div>

The poor documentation of Elasticsearch continues to hamper expanding my usage, and even poorer vagueness in the PHP API documentation. This seems like a simple example. Search for field (it is a tag field, it can have…

---

## [Unable to run a benchmark on a 3 node Elastic-Search Cluster](https://discuss.elastic.co/t/unable-to-run-a-benchmark-on-a-3-node-elastic-search-cluster/337120)

<div class="topic-metadata">

**Author:** [@Kavya2708](https://discuss.elastic.co/u/Kavya2708)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-run-a-benchmark-on-a-3-node-elastic-search-cluster/337120 "2023-06-30T13:39:59Z")

</div>

When running a race on a 3 node Elasticsearch cluster we are getting the following error. We were able to run a benchmark on a single node cluster. The single node had a document count of 3,556,667 , whereas the 3 node …

---

## [Elasticsearch index migration](https://discuss.elastic.co/t/elasticsearch-index-migration/337314)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [June 30, 2023, 1:23pm UTC](https://discuss.elastic.co/t/elasticsearch-index-migration/337314 "2023-06-30T13:23:28Z")

</div>

Hello. We are in the process of migrating from elasticsearch 7.6.2 to version 8.7.0 In our present set up the indices are stored on local disk of all nodes in the cluster and we do not have a shared storage (NAS). Is t…

---

## [Roles N/A in stack monitoring](https://discuss.elastic.co/t/roles-n-a-in-stack-monitoring/337251)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 7\
**Last updated:** [June 30, 2023, 1:15pm UTC](https://discuss.elastic.co/t/roles-n-a-in-stack-monitoring/337251 "2023-06-30T13:15:38Z")

</div>

Hi team, how can i resolve this problem the roles is showing N/A in stack monitoring i'm alreay specified the node.roles in elasticsearch.yml Thanks in advance

---

## [Reindex data stream](https://discuss.elastic.co/t/reindex-data-stream/337305)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 12:34pm UTC](https://discuss.elastic.co/t/reindex-data-stream/337305 "2023-06-30T12:34:56Z")

</div>

Hello, There is conflicts with fields in the data stream backing indices. I would like to know the correct way to resolve this issue. While reindexing data is possible with regular indexes, I am unsure how to proceed wi…

---

## [Cannot upgrade node because incompatible indices created with version \[6.2.3\] exist](https://discuss.elastic.co/t/cannot-upgrade-node-because-incompatible-indices-created-with-version-6-2-3-exist/337293)

<div class="topic-metadata">

**Author:** [@Achyut\_Muley](https://discuss.elastic.co/u/Achyut_Muley)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:52am UTC](https://discuss.elastic.co/t/cannot-upgrade-node-because-incompatible-indices-created-with-version-6-2-3-exist/337293 "2023-06-30T10:52:28Z")

</div>

I recently started using 8.5.3 version of Elasticsearch.I have some indices that were created in two earlier versions i.e. 7.17.0 and 6.2.3 Now when i while starting Elasticsearch for the version 8.5.3 i am getting the …

---

## [Elasticsearch query with multiple fuzziness and weights](https://discuss.elastic.co/t/elasticsearch-query-with-multiple-fuzziness-and-weights/336948)

<div class="topic-metadata">

**Author:** [@alex.shmukler](https://discuss.elastic.co/u/alex.shmukler)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:22am UTC](https://discuss.elastic.co/t/elasticsearch-query-with-multiple-fuzziness-and-weights/336948 "2023-06-30T10:22:18Z")

</div>

Hey Guys, I need to write query that will combine simple match and fuzziness together on different fields. At the beginning I need to normalize each field to characters and numbers only. Each field will have a differ…

---

## [How to configure the THESPIAN\_BASE\_IPADDR when encounter 'ActorAddr-(T|:1900) is not a valid ActorSystem admin'](https://discuss.elastic.co/t/how-to-configure-the-thespian-base-ipaddr-when-encounter-actoraddr-t-1900-is-not-a-valid-actorsystem-admin/336802)

<div class="topic-metadata">

**Author:** [@tengfei225](https://discuss.elastic.co/u/tengfei225)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 9:10am UTC](https://discuss.elastic.co/t/how-to-configure-the-thespian-base-ipaddr-when-encounter-actoraddr-t-1900-is-not-a-valid-actorsystem-admin/336802 "2023-06-30T09:10:48Z")

</div>

Hi I am a new user of Esrally, currently I have created my custom track in order to benchmark the elastic cloud in azure when I try the below command, the actor system can not be started esrally race --track=percolato…

---

## [ELK cluster issue after removing one of the master](https://discuss.elastic.co/t/elk-cluster-issue-after-removing-one-of-the-master/337267)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 5\
**Last updated:** [June 30, 2023, 8:00am UTC](https://discuss.elastic.co/t/elk-cluster-issue-after-removing-one-of-the-master/337267 "2023-06-30T08:00:06Z")

</div>

\[2023-06-30T13:43:27,396\]\[ERROR\]\[o.e.x.m.c.c.ClusterStatsCollector\] \[xxx-es-master-2.xxx.com\] collector \[cluster\_stats\] failed to collect data org.elasticsearch.action.search.SearchPhaseExecutionException: all shards fai…

---

## [ELK cluster issue failed after data node restart](https://discuss.elastic.co/t/elk-cluster-issue-failed-after-data-node-restart/337266)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 5:50am UTC](https://discuss.elastic.co/t/elk-cluster-issue-failed-after-data-node-restart/337266 "2023-06-30T05:50:52Z")

</div>

ELK cluster issue failed after data node restart Tried restarting all nodes, after restart the index starts to restore but during restoring there is an error message: .text-only,.text-card-text{white-space: pre;}.rich-t…

---

## [Get the hit count in EQL](https://discuss.elastic.co/t/get-the-hit-count-in-eql/335529)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:42am UTC](https://discuss.elastic.co/t/get-the-hit-count-in-eql/335529 "2023-06-30T05:42:48Z")

</div>

Hi, I'm using the EQL queries for my search and want to get the hits.total.value . When I try the below query, i'm getting the hits.total.value as 10. But I'm not getting the total count of the hits for the search. G…

---

## [Is it possible to get http.max\_content\_length in AWS Elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-get-http-max-content-length-in-aws-elasticsearch/337223)

<div class="topic-metadata">

**Author:** [@a-moondance-94](https://discuss.elastic.co/u/a-moondance-94)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 3:40am UTC](https://discuss.elastic.co/t/is-it-possible-to-get-http-max-content-length-in-aws-elasticsearch/337223 "2023-06-30T03:40:45Z")

</div>

I need to get the max\_content\_length to limit the size of the bulk request I am sending to AWS Elasticsearch. In my local installation of Elasticsearch I am able to do this using GET \_cluster/settings?include\_defaults A…

---

## [Why count(distinct patient\_id) is larger than count(patient\_id)?](https://discuss.elastic.co/t/why-count-distinct-patient-id-is-larger-than-count-patient-id/337250)

<div class="topic-metadata">

**Author:** [@DongPoJuShi\_Dj](https://discuss.elastic.co/u/DongPoJuShi_Dj)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 1:24am UTC](https://discuss.elastic.co/t/why-count-distinct-patient-id-is-larger-than-count-patient-id/337250 "2023-06-30T01:24:29Z")

</div>

There is an index alias that includes two indexes, and the index structure is as follows: { "scientific\_data\_group1": { "aliases": { "scientific\_data\_group": {} }, "mappings": { "properties": {…

---

## [Elasticsearch Query cache shows no data](https://discuss.elastic.co/t/elasticsearch-query-cache-shows-no-data/336306)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 8\
**Last updated:** [June 30, 2023, 1:08am UTC](https://discuss.elastic.co/t/elasticsearch-query-cache-shows-no-data/336306 "2023-06-30T01:08:42Z")

</div>

The problem we are facing is that query cache is not being used at all in our ES cluster except version 7.8.1. We are using ES version 7.8.1 and we see data in Query Cache as show below. After upgrading to ES versio…

---

## [Authentication using apikey failed - unable to find apikey with id](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217)

<div class="topic-metadata">

**Author:** [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 9:58pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217 "2023-06-29T21:58:01Z")

</div>

Hello, We are running Elasticsearch 7.17.8 and have many error entries like this on in the elastic logs: \[WARN \]\[o.e.x.s.a.ApiKeyAuthenticator\] \[NODENAMEE\] Authentication using apikey failed - unable to find apikey wi…

---

## [Child document is occasionally not searchable](https://discuss.elastic.co/t/child-document-is-occasionally-not-searchable/337240)

<div class="topic-metadata">

**Author:** [@kved](https://discuss.elastic.co/u/kved)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 8:33pm UTC](https://discuss.elastic.co/t/child-document-is-occasionally-not-searchable/337240 "2023-06-29T20:33:36Z")

</div>

Child documents are sometimes not searchable. I have a parent-child relationship where the mapping looks like { "parent": { "id": "keyword", "name": "text" } "childId": "keyword", …

---

## [ElasticSearch does not start and not even cluster](https://discuss.elastic.co/t/elasticsearch-does-not-start-and-not-even-cluster/337017)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 10\
**Last updated:** [June 29, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-and-not-even-cluster/337017 "2023-06-29T18:29:46Z")

</div>

I'm trying to create an Elasticsearch cluster with 3 nodes, each node being eligible as a master, as stated in this doc. This cluster will be used by the end user only on our local network through an nginx proxy that wi…

---

## [JsonProviderImpl not found but only for UpdateByQuery responses](https://discuss.elastic.co/t/jsonproviderimpl-not-found-but-only-for-updatebyquery-responses/337051)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 6:00pm UTC](https://discuss.elastic.co/t/jsonproviderimpl-not-found-but-only-for-updatebyquery-responses/337051 "2023-06-29T18:00:42Z")

</div>

I'm getting the following error only when deserialising UpdateByQuery responses: 2023-06-27 18:00:18:193 +0000 \[http-nio-8080-exec-4\] ERROR Error: Provider org.glassfish.json.JsonProviderImpl not found jakarta.json.Json…

---

## [I can't filter nested](https://discuss.elastic.co/t/i-cant-filter-nested/337230)

<div class="topic-metadata">

**Author:** [@Vahid\_Hajiagazadeh](https://discuss.elastic.co/u/Vahid_Hajiagazadeh)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 5:06pm UTC](https://discuss.elastic.co/t/i-cant-filter-nested/337230 "2023-06-29T17:06:10Z")

</div>

I have a document that is in the form of nested data But I can't filter in a nested way and all the products return a category, while in the query I have only filtered products that have attribute\_id 40. my mapping { …

---

## [Problems connecting to ES Cross cluster search cluster indexes from Databricks using spark connector](https://discuss.elastic.co/t/problems-connecting-to-es-cross-cluster-search-cluster-indexes-from-databricks-using-spark-connector/335030)

<div class="topic-metadata">

**Author:** [@srinivas\_a1](https://discuss.elastic.co/u/srinivas_a1)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 4:56pm UTC](https://discuss.elastic.co/t/problems-connecting-to-es-cross-cluster-search-cluster-indexes-from-databricks-using-spark-connector/335030 "2023-06-29T16:56:32Z")

</div>

Hi All, I am trying to connect with ES from our Databricks cluster using elasticsearch\_spark\_30\_2\_12\_7\_16\_3.jar. I'm not able to read the data from cross cluster indexes which are starting with "\*:xxxxxxx", However able…

---

## [Elasticsearch Java API Client throwing error for empty fields](https://discuss.elastic.co/t/elasticsearch-java-api-client-throwing-error-for-empty-fields/337221)

<div class="topic-metadata">

**Author:** [@Shakhzod\_Khashimov](https://discuss.elastic.co/u/Shakhzod_Khashimov)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 2:50pm UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-throwing-error-for-empty-fields/337221 "2023-06-29T14:50:26Z")

</div>

Hi, we changed our elasticsearch from RestHighLevelClient to ElasticsearchClient, our document can have empty values, but in new Elasticsearch Java API Client it is throwing error saying: org.springframework.data.elasti…

---

## [Unable to access Elasticsearch connected to company server via Python](https://discuss.elastic.co/t/unable-to-access-elasticsearch-connected-to-company-server-via-python/335288)

<div class="topic-metadata">

**Author:** [@cyl](https://discuss.elastic.co/u/cyl)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 1:09pm UTC](https://discuss.elastic.co/t/unable-to-access-elasticsearch-connected-to-company-server-via-python/335288 "2023-06-29T13:09:01Z")

</div>

Hi Elastic community! :smiley: I have just started using Elastic and Kibana as my company has opted for this tech stack to store much of our data. To analyse the data, I would prefer the use of Python, and hence have b…

---

## [Documentation - Wildcard query DSL](https://discuss.elastic.co/t/documentation-wildcard-query-dsl/337182)

<div class="topic-metadata">

**Author:** [@Pawel123](https://discuss.elastic.co/u/Pawel123)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 11:32am UTC](https://discuss.elastic.co/t/documentation-wildcard-query-dsl/337182 "2023-06-29T11:32:08Z")

</div>

Running on ES 7.10.0. Sending a search query with "case\_insensitive" parameter: Getting response \[wildcard\] query does not support \[case\_insensitive\] as in documentation -\> Wildcard query | Elasticsearch Guide \[8.8\] |…

---

## [Simple search doesnt work](https://discuss.elastic.co/t/simple-search-doesnt-work/337092)

<div class="topic-metadata">

**Author:** [@Dach](https://discuss.elastic.co/u/Dach)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 11:21am UTC](https://discuss.elastic.co/t/simple-search-doesnt-work/337092 "2023-06-29T11:21:08Z")

</div>

When i do this search, my product is well find : { "query": { "bool": { "must": \[ { "match": { "pickRef": "630203" } }, { "match": { "id": 56139 } }, { "match": { "name.fr": "ENVELOPP…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=234)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=236)
