# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=237

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 238

---

## [How to Integration with Intersystems' IRIS database](https://discuss.elastic.co/t/how-to-integration-with-intersystems-iris-database/337025)

<div class="topic-metadata">

**Author:** [@tomming](https://discuss.elastic.co/u/tomming)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 1:26am UTC](https://discuss.elastic.co/t/how-to-integration-with-intersystems-iris-database/337025 "2023-06-28T01:26:58Z")

</div>

Need help Integration with Intersystems' IRIS database.

---

## [ES migration from 6.8 to 7.17. Data type change in template for "date" type](https://discuss.elastic.co/t/es-migration-from-6-8-to-7-17-data-type-change-in-template-for-date-type/337022)

<div class="topic-metadata">

**Author:** [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 11:19pm UTC](https://discuss.elastic.co/t/es-migration-from-6-8-to-7-17-data-type-change-in-template-for-date-type/337022 "2023-06-27T23:19:59Z")

</div>

Hi Team We are planning to move from ES 6.8 to 7.17 server migration . But in 7.17 -ve values are not supported for date field. So am thinking to change the index template for that specific field from date to long type …

---

## [Unable to access kibana despite creating azure elastic ISV service with owner subscription](https://discuss.elastic.co/t/unable-to-access-kibana-despite-creating-azure-elastic-isv-service-with-owner-subscription/336916)

<div class="topic-metadata">

**Author:** [@Francis\_Salvin](https://discuss.elastic.co/u/Francis_Salvin)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 8:14pm UTC](https://discuss.elastic.co/t/unable-to-access-kibana-despite-creating-azure-elastic-isv-service-with-owner-subscription/336916 "2023-06-27T20:14:04Z")

</div>

I am working on deploying azure elastic ISV service and using it with apps deployed in AKS cluster. Deployed successfully, but any elastic task I do after that is prompted for approval from admin (like accessing kibana) …

---

## [Gathering Top Values Through Elk API](https://discuss.elastic.co/t/gathering-top-values-through-elk-api/337019)

<div class="topic-metadata">

**Author:** [@hi\_xavier](https://discuss.elastic.co/u/hi_xavier)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 6:52pm UTC](https://discuss.elastic.co/t/gathering-top-values-through-elk-api/337019 "2023-06-27T18:52:15Z")

</div>

Hi, Is it possible, with the combination of Elk API and Aggregations , to gather top values. For example, the top 5 error messages from a set of results?

---

## [Configure limit.conf for ElasticSearch server](https://discuss.elastic.co/t/configure-limit-conf-for-elasticsearch-server/336930)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/configure-limit-conf-for-elasticsearch-server/336930 "2023-06-27T12:43:19Z")

</div>

The Elasticsearch documentation says that I should configure nofile and nproc for better performance. But the documentation is a bit confusing. First, do I set it to the "elastic" user that was created by Elasticsearch…

---

## [BACnet - ingest data from field devices](https://discuss.elastic.co/t/bacnet-ingest-data-from-field-devices/337015)

<div class="topic-metadata">

**Author:** [@Ostaseski](https://discuss.elastic.co/u/Ostaseski)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:46pm UTC](https://discuss.elastic.co/t/bacnet-ingest-data-from-field-devices/337015 "2023-06-27T15:46:00Z")

</div>

I cannot read the responses on how to ingest data from field devices that talk Modbus TCP and BACnet IP to Elastic Logstash. Were there any suggestions or perhaps an update? Any help would be appreciated. Thanks

---

## ["target\_prefix" equivalent for ingest pipeline?](https://discuss.elastic.co/t/target-prefix-equivalent-for-ingest-pipeline/337009)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 3:28pm UTC](https://discuss.elastic.co/t/target-prefix-equivalent-for-ingest-pipeline/337009 "2023-06-27T15:28:19Z")

</div>

The filebeat dissect processor has a handy "target\_prefix" option, which allows everything it extracts to be placed under a common prefix. Is there any equivalent for the dissect or grok processors in an ingest pipeline…

---

## [Enrich index with data found in another index](https://discuss.elastic.co/t/enrich-index-with-data-found-in-another-index/336966)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 2:50pm UTC](https://discuss.elastic.co/t/enrich-index-with-data-found-in-another-index/336966 "2023-06-27T14:50:29Z")

</div>

Hello, What is the best way to add a field to an existing indexm where the value is filled with data from an other index. E.g. most commont example you have an index with a name field amd you want to add an email addr…

---

## [Elastic search cluster red primary shards missing](https://discuss.elastic.co/t/elastic-search-cluster-red-primary-shards-missing/337004)

<div class="topic-metadata">

**Author:** [@Nilesh\_Jethwani](https://discuss.elastic.co/u/Nilesh_Jethwani)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-red-primary-shards-missing/337004 "2023-06-27T14:21:31Z")

</div>

Kibana is showing elastic health as red primary shards missing I have single node cluster. How can i fix this red status ?

---

## [I have a problem with EL and Xenforo](https://discuss.elastic.co/t/i-have-a-problem-with-el-and-xenforo/336872)

<div class="topic-metadata">

**Author:** [@Hi\_Welt](https://discuss.elastic.co/u/Hi_Welt)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 2:08pm UTC](https://discuss.elastic.co/t/i-have-a-problem-with-el-and-xenforo/336872 "2023-06-27T14:08:47Z")

</div>

HI I have been using EL in xenforo for a longtime but now I randomly starts shutingdown since updating from EL7 to EL8. cat /var/log/elasticsearch/elasticsearch.log \[2023-06-26T03:24:33,901\]\[INFO \]\[o.e.n.Node …

---

## [What are the ways to combine the scores of keyword search + vector search other than the RRF ranking recently used?](https://discuss.elastic.co/t/what-are-the-ways-to-combine-the-scores-of-keyword-search-vector-search-other-than-the-rrf-ranking-recently-used/336914)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 1:27pm UTC](https://discuss.elastic.co/t/what-are-the-ways-to-combine-the-scores-of-keyword-search-vector-search-other-than-the-rrf-ranking-recently-used/336914 "2023-06-27T13:27:31Z")

</div>

I want to combine the scores of knn search + normal keyword search. What are the ways of doing it other than the RRF ranking recently added?

---

## [8.1, some confusion about successfulShardExecution in AbstractSearchAsyncAction](https://discuss.elastic.co/t/8-1-some-confusion-about-successfulshardexecution-in-abstractsearchasyncaction/336987)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 12:32pm UTC](https://discuss.elastic.co/t/8-1-some-confusion-about-successfulshardexecution-in-abstractsearchasyncaction/336987 "2023-06-27T12:32:34Z")

</div>

"Every response of shard result will trigger the successfulShardExecution method of AbstractSearchAsyncAction. I am confused about why we use shardsIt.remaining() + 1 to calculate ops, shouldn't it be +1 for each shard?" …

---

## [Docs: reindex.remote.whitelist takes and array and not comma separated list](https://discuss.elastic.co/t/docs-reindex-remote-whitelist-takes-and-array-and-not-comma-separated-list/336976)

<div class="topic-metadata">

**Author:** [@adopauco](https://discuss.elastic.co/u/adopauco)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 10:49am UTC](https://discuss.elastic.co/t/docs-reindex-remote-whitelist-takes-and-array-and-not-comma-separated-list/336976 "2023-06-27T10:49:41Z")

</div>

According to this piece of documentation, I need to configure reindex.remote.whitelist to allow reindexing from a remote elastic cluster. It states that the value should be a string with comma separated list of allowed …

---

## [Elastic search upgrade from 7.16.2 to 7.17.7](https://discuss.elastic.co/t/elastic-search-upgrade-from-7-16-2-to-7-17-7/336579)

<div class="topic-metadata">

**Author:** [@Bibhutibhusan\_Sahoo](https://discuss.elastic.co/u/Bibhutibhusan_Sahoo)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 10:25am UTC](https://discuss.elastic.co/t/elastic-search-upgrade-from-7-16-2-to-7-17-7/336579 "2023-06-27T10:25:52Z")

</div>

Hi Team, we are trying to upgrade Elasticsearch from 7.16.2 to 7.17.7 through rpm package and getting following error One or more requisite failed: service.elastic.elasticsearch.service, Can someone help here? What is …

---

## [Unable to delete snapshot](https://discuss.elastic.co/t/unable-to-delete-snapshot/336952)

<div class="topic-metadata">

**Author:** [@rakesh08](https://discuss.elastic.co/u/rakesh08)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 8:31am UTC](https://discuss.elastic.co/t/unable-to-delete-snapshot/336952 "2023-06-27T08:31:12Z")

</div>

In our environment, having 2 different elasticsearch servers running on eks cluster and leveraging elasticsearch-curator tool to take periodic snapshot on AWS s3 bucket. On both the ES servers, the elasticsearch-curator…

---

## [Elasticsearch-create-enrollment-token is not possible without a keystore ( aka with PEM certificates)](https://discuss.elastic.co/t/elasticsearch-create-enrollment-token-is-not-possible-without-a-keystore-aka-with-pem-certificates/336136)

<div class="topic-metadata">

**Author:** [@DavidDPD](https://discuss.elastic.co/u/DavidDPD)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 7:33am UTC](https://discuss.elastic.co/t/elasticsearch-create-enrollment-token-is-not-possible-without-a-keystore-aka-with-pem-certificates/336136 "2023-06-27T07:33:58Z")

</div>

This has been posted a few times, but threads have been auto-closed without an explicit explanation. I'm posting this as this really either needs to be changed/fixed in Elasticsearch, or DOCUMENTED. It does not seem to…

---

## [Attach two pipeline to a single index in kibana 6.7.0](https://discuss.elastic.co/t/attach-two-pipeline-to-a-single-index-in-kibana-6-7-0/336898)

<div class="topic-metadata">

**Author:** [@danialumer](https://discuss.elastic.co/u/danialumer)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 6:00am UTC](https://discuss.elastic.co/t/attach-two-pipeline-to-a-single-index-in-kibana-6-7-0/336898 "2023-06-27T06:00:15Z")

</div>

I have an issue that i have written two pipelines using devtools in v6.7.0, but do not know how to attach them with index, Can someone please assist on this?

---

## [Elasticsearch Index management strategy](https://discuss.elastic.co/t/elasticsearch-index-management-strategy/336833)

<div class="topic-metadata">

**Author:** [@Narcissus666](https://discuss.elastic.co/u/Narcissus666)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 5:28am UTC](https://discuss.elastic.co/t/elasticsearch-index-management-strategy/336833 "2023-06-27T05:28:10Z")

</div>

Does Elasticsearch have a mechanismr like docke for storing logs? Docker log management divides logs into many files, and during rolling updates, only the oldest log files are deleted, rather than deleting the entire in…

---

## [Nested queries that refer to an expression on the parent](https://discuss.elastic.co/t/nested-queries-that-refer-to-an-expression-on-the-parent/336938)

<div class="topic-metadata">

**Author:** [@DaveG](https://discuss.elastic.co/u/DaveG)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:11am UTC](https://discuss.elastic.co/t/nested-queries-that-refer-to-an-expression-on-the-parent/336938 "2023-06-27T03:11:20Z")

</div>

Hi All, I wish to write a query on nested data where there are expressions on the parent data as wells as expressions on the nested data all mixed together. For example, get me all the records that have id = 1 and exis…

---

## [.security-7 can't create replicas in elasticsearch 7.17.10](https://discuss.elastic.co/t/security-7-cant-create-replicas-in-elasticsearch-7-17-10/336936)

<div class="topic-metadata">

**Author:** [@Han2](https://discuss.elastic.co/u/Han2)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 2:06am UTC](https://discuss.elastic.co/t/security-7-cant-create-replicas-in-elasticsearch-7-17-10/336936 "2023-06-27T02:06:59Z")

</div>

My cluster statu is yellow ,When i add new node to my cluster I use this order \_cluster/allocation/explain to exlpian this error and i don't know how to do someone can help me? PLZ

---

## [Excluding all fields from object property except for one (4096 byte limit error for large URI)](https://discuss.elastic.co/t/excluding-all-fields-from-object-property-except-for-one-4096-byte-limit-error-for-large-uri/336934)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 4\
**Last updated:** [June 26, 2023, 11:37pm UTC](https://discuss.elastic.co/t/excluding-all-fields-from-object-property-except-for-one-4096-byte-limit-error-for-large-uri/336934 "2023-06-26T23:37:07Z")

</div>

Hi, I'm trying to get ES to return me only currency in the example below in a concise way. The currency field: hits.hits.\_source.attributes.currency For the sake of the example I also have properties like this: hits…

---

## [Enrich vs Transform with 2 source indices](https://discuss.elastic.co/t/enrich-vs-transform-with-2-source-indices/336344)

<div class="topic-metadata">

**Author:** [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 11:17pm UTC](https://discuss.elastic.co/t/enrich-vs-transform-with-2-source-indices/336344 "2023-06-26T23:17:05Z")

</div>

Hi! I am faced with a situation where I am not sure whether an enrich processor or a transform should be used. In my situation, I have sensors sending events in batch to Elastic. Each sensor has a sensor\_key and the eve…

---

## [Could not validate a connection to the.... No alive nodes found in your cluster](https://discuss.elastic.co/t/could-not-validate-a-connection-to-the-no-alive-nodes-found-in-your-cluster/336928)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 7:39pm UTC](https://discuss.elastic.co/t/could-not-validate-a-connection-to-the-no-alive-nodes-found-in-your-cluster/336928 "2023-06-26T19:39:17Z")

</div>

Estou tendo fazer uma instalação do magento 2.4.6, mas estou recebendo esse erro na instalação. ● elasticsearch.service - Elasticsearch Loaded: loaded (/etc/systemd/system/elasticsearch.service; enabled; vendor preset…

---

## [Elasticsearch query to match all tokens inside a specific field](https://discuss.elastic.co/t/elasticsearch-query-to-match-all-tokens-inside-a-specific-field/336927)

<div class="topic-metadata">

**Author:** [@vsha041](https://discuss.elastic.co/u/vsha041)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 7:17pm UTC](https://discuss.elastic.co/t/elasticsearch-query-to-match-all-tokens-inside-a-specific-field/336927 "2023-06-26T19:17:21Z")

</div>

We have a scenario where for one of the fields of the index should contain all the words in order for that field to be treated as a match. Whereas other fields can contain the rest of search query. Here are few examples.…

---

## [Re-index using a Machine Learning with custom Trained Models](https://discuss.elastic.co/t/re-index-using-a-machine-learning-with-custom-trained-models/336711)

<div class="topic-metadata">

**Author:** [@Lone\_Eagle](https://discuss.elastic.co/u/Lone_Eagle)\
**Replies:** 5\
**Last updated:** [June 26, 2023, 5:14pm UTC](https://discuss.elastic.co/t/re-index-using-a-machine-learning-with-custom-trained-models/336711 "2023-06-26T17:14:19Z")

</div>

We have currently a Production Elasticsearch using Elastic Cloud and want to experiment vectors using a Machine Learning with a custom trained model. Machine Learning Configuration: 32 GB RAM | 16.9 vCPU As a pipeline…

---

## [Need to use java jdk 11 on elasticsearch 7](https://discuss.elastic.co/t/need-to-use-java-jdk-11-on-elasticsearch-7/336923)

<div class="topic-metadata">

**Author:** [@adevbrought](https://discuss.elastic.co/u/adevbrought)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 5:31pm UTC](https://discuss.elastic.co/t/need-to-use-java-jdk-11-on-elasticsearch-7/336923 "2023-06-26T17:31:20Z")

</div>

What is the best way to setup install elasticsearch 7 on ec2 with jdk 11 in ansible playbook?

---

## [Index not creating for filebeat](https://discuss.elastic.co/t/index-not-creating-for-filebeat/336908)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 1:28pm UTC](https://discuss.elastic.co/t/index-not-creating-for-filebeat/336908 "2023-06-26T13:28:41Z")

</div>

not able to create index in kibana getting below error {"log.level":"info","@timestamp":"2023-06-26T18:43:27.607+0530","log.logger":"monitoring","log.origin":{"file.name":"log/log.go","file.line":187},"message":"Non-zer…

---

## [Giving ES big amount of heap space](https://discuss.elastic.co/t/giving-es-big-amount-of-heap-space/336877)

<div class="topic-metadata">

**Author:** [@mzhaqs](https://discuss.elastic.co/u/mzhaqs)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 1:21pm UTC](https://discuss.elastic.co/t/giving-es-big-amount-of-heap-space/336877 "2023-06-26T13:21:31Z")

</div>

We have a pod with ES 5.6.16 container running in Kubernetes cluster. Only one instance running. Can not update the version or horizontally scale. This poor instance needs to deal with significant amount of load. Gave it…

---

## [Discover bar chart not showing](https://discuss.elastic.co/t/discover-bar-chart-not-showing/336900)

<div class="topic-metadata">

**Author:** [@balupad14](https://discuss.elastic.co/u/balupad14)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 1:22pm UTC](https://discuss.elastic.co/t/discover-bar-chart-not-showing/336900 "2023-06-26T13:22:34Z")

</div>

I have an Index called "DemoIndex". I am inserting the below index post /DemoIndex/\_doc { "processCode": "ADPROJ", "processName": "Admin process", "manualDuration": 0, "tableName": "tblProcess", "timestamp": "2023…

---

## [Curl -X GET 'https://localhost:9200'](https://discuss.elastic.co/t/curl-x-get-https-localhost-9200/336624)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 16\
**Last updated:** [June 26, 2023, 1:07pm UTC](https://discuss.elastic.co/t/curl-x-get-https-localhost-9200/336624 "2023-06-26T13:07:25Z")

</div>

curl -X GET 'https://localhost:9200' curl: (60) Peer's certificate issuer has been marked as not trusted by the user. More details here: http://curl.haxx.se/docs/sslcerts.html curl performs SSL certificate verification…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=236)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=238)
