# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=24

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 25

---

## [Use a static keystore in ansible for elsaticsarch deployment](https://discuss.elastic.co/t/use-a-static-keystore-in-ansible-for-elsaticsarch-deployment/380362)

<div class="topic-metadata">

**Author:** [@huanghaiqing1](https://discuss.elastic.co/u/huanghaiqing1)\
**Replies:** 1\
**Last updated:** [July 24, 2025, 3:16am UTC](https://discuss.elastic.co/t/use-a-static-keystore-in-ansible-for-elsaticsarch-deployment/380362 "2025-07-24T03:16:00Z")

</div>

Hello, here we want to deploy elasticsearch by ansible. We know there is a folder certs/\*, where stores key-pairs for nodes info transporation or access from kibana/logstash. My question is whether there is a way to prep…

---

## [Elastic cant find simple text](https://discuss.elastic.co/t/elastic-cant-find-simple-text/380347)

<div class="topic-metadata">

**Author:** [@nutmix](https://discuss.elastic.co/u/nutmix)\
**Replies:** 3\
**Last updated:** [July 23, 2025, 9:09pm UTC](https://discuss.elastic.co/t/elastic-cant-find-simple-text/380347 "2025-07-23T21:09:18Z")

</div>

if I search for "KCC", it doesnt find it, even though I'm looking right at entries with KCC in them. If we search with no search term specified, we see all our log lines, e.g. this one: 2025-07-22T13:38:33,460Z INFO ht…

---

## [Would int8\_hnsw slower than hnsw for vector search](https://discuss.elastic.co/t/would-int8-hnsw-slower-than-hnsw-for-vector-search/380290)

<div class="topic-metadata">

**Author:** [@wangbing993](https://discuss.elastic.co/u/wangbing993)\
**Replies:** 5\
**Last updated:** [July 23, 2025, 2:57pm UTC](https://discuss.elastic.co/t/would-int8-hnsw-slower-than-hnsw-for-vector-search/380290 "2025-07-23T14:57:53Z")

</div>

Data result by VectorDBBench: Elastic Search Version: 8.14.3 mappings config: {'\_source': {'excludes': \['vector'\]}, 'properties': {'id': {'type': 'integer', 'store': True}, 'vector': {'dims': 1024, 'type': 'dense\_ve…

---

## [Prod instance: Comms failing from remote and on-site- Error invoking remote method 'send-http-request': Error: connect ETIMEDOUT](https://discuss.elastic.co/t/prod-instance-comms-failing-from-remote-and-on-site-error-invoking-remote-method-send-http-request-error-connect-etimedout/380239)

<div class="topic-metadata">

**Author:** [@harryDHL](https://discuss.elastic.co/u/harryDHL)\
**Replies:** 6\
**Last updated:** [July 23, 2025, 12:13am UTC](https://discuss.elastic.co/t/prod-instance-comms-failing-from-remote-and-on-site-error-invoking-remote-method-send-http-request-error-connect-etimedout/380239 "2025-07-23T00:13:27Z")

</div>

Hi all, I wanted to reach out to see if anyone could help me with the following error I am getting while attempting to establish connection to Elastic PROD DB server. Error invoking remote method 'send-http-request': E…

---

## [High network usage by master node](https://discuss.elastic.co/t/high-network-usage-by-master-node/380102)

<div class="topic-metadata">

**Author:** [@rara01](https://discuss.elastic.co/u/rara01)\
**Replies:** 9\
**Last updated:** [July 22, 2025, 1:40pm UTC](https://discuss.elastic.co/t/high-network-usage-by-master-node/380102 "2025-07-22T13:40:19Z")

</div>

Hello, We have self-hosted Elasticsearch, used primarily for logs. Cluster is made of 3 nodes + one is only fleet-server. We have encountered very high network usage, now download is over 1 GiB/s, upload nearing tha…

---

## [Elasticsearch re-index not working correctly on Podman](https://discuss.elastic.co/t/elasticsearch-re-index-not-working-correctly-on-podman/380319)

<div class="topic-metadata">

**Author:** [@doomshallot](https://discuss.elastic.co/u/doomshallot)\
**Replies:** 0\
**Last updated:** [July 22, 2025, 2:19am UTC](https://discuss.elastic.co/t/elasticsearch-re-index-not-working-correctly-on-podman/380319 "2025-07-22T02:19:21Z")

</div>

We migrated from RHEL 7 Linux servers to RHEL 8 Linux servers, which also forced us from using Docker to Podman. Everything else (as far as we can tell) is the exact same. We use postgresql on a separate Linux server (a…

---

## [When Elasticseach auto configs security, is there any way to inject SANs of my own choosing into the http\_ca.crt?](https://discuss.elastic.co/t/when-elasticseach-auto-configs-security-is-there-any-way-to-inject-sans-of-my-own-choosing-into-the-http-ca-crt/380176)

<div class="topic-metadata">

**Author:** [@chad.carson](https://discuss.elastic.co/u/chad.carson)\
**Replies:** 4\
**Last updated:** [July 22, 2025, 12:25am UTC](https://discuss.elastic.co/t/when-elasticseach-auto-configs-security-is-there-any-way-to-inject-sans-of-my-own-choosing-into-the-http-ca-crt/380176 "2025-07-22T00:25:51Z")

</div>

Hello, I am running Elasticsearch in Kubernetes, and everything is up and running well, but if I make any connections from other applications internally across Kubernetes to the exposed service on 9200, it fails the "hos…

---

## [Adjusting Search Filters for Swiftype](https://discuss.elastic.co/t/adjusting-search-filters-for-swiftype/379864)

<div class="topic-metadata">

**Author:** [@Yevhen\_Marynych](https://discuss.elastic.co/u/Yevhen_Marynych)\
**Replies:** 2\
**Last updated:** [July 21, 2025, 3:47pm UTC](https://discuss.elastic.co/t/adjusting-search-filters-for-swiftype/379864 "2025-07-21T15:47:29Z")

</div>

Hi! We're using Swiftype to search through our websites and I have several questions. Is there a way to adjust Weights in order to show recent pages on the site? Right now when you search (for Swarm, as an example), th…

---

## [Elasticsearch JDK version VA closure](https://discuss.elastic.co/t/elasticsearch-jdk-version-va-closure/380090)

<div class="topic-metadata">

**Author:** [@amjad](https://discuss.elastic.co/u/amjad)\
**Replies:** 3\
**Last updated:** [July 21, 2025, 9:05am UTC](https://discuss.elastic.co/t/elasticsearch-jdk-version-va-closure/380090 "2025-07-21T09:05:01Z")

</div>

Hi elastic community. Hope everyone is doing well. we are using Elasticsearch 7.11.1 version in which we are having jdk Installed version: 15.0.1 now we have received a security VA and suggested to Upgrade to a version…

---

## [Validating Incoming Http requests](https://discuss.elastic.co/t/validating-incoming-http-requests/380287)

<div class="topic-metadata">

**Author:** [@amjad](https://discuss.elastic.co/u/amjad)\
**Replies:** 1\
**Last updated:** [July 21, 2025, 8:08am UTC](https://discuss.elastic.co/t/validating-incoming-http-requests/380287 "2025-07-21T08:08:57Z")

</div>

Hi Elastic community, Hope everyone is doing well, and thank you for your support so far. We’ve encountered a vulnerability related to incoming HTTP requests. We're currently using cURL APIs to create users in Elastics…

---

## [Elasticsearch Pagination: Scroll API](https://discuss.elastic.co/t/elasticsearch-pagination-scroll-api/379852)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 4\
**Last updated:** [July 21, 2025, 6:44am UTC](https://discuss.elastic.co/t/elasticsearch-pagination-scroll-api/379852 "2025-07-21T06:44:31Z")

</div>

Hi, Noticed, that the following note has been added for Scroll Pagination. We no longer recommend using the scroll API for deep pagination. If you need to preserve the index state while paging through more than 10,000…

---

## [How to softly exclude ambiguous words?](https://discuss.elastic.co/t/how-to-softly-exclude-ambiguous-words/380249)

<div class="topic-metadata">

**Author:** [@S-Dragon0302](https://discuss.elastic.co/u/S-Dragon0302)\
**Replies:** 3\
**Last updated:** [July 20, 2025, 8:47am UTC](https://discuss.elastic.co/t/how-to-softly-exclude-ambiguous-words/380249 "2025-07-20T08:47:13Z")

</div>

Because "apple" is hit, not just "apple care".How to implement this query\_string?

---

## [Persistent keystore errors - guidance for new install please](https://discuss.elastic.co/t/persistent-keystore-errors-guidance-for-new-install-please/378620)

<div class="topic-metadata">

**Author:** [@GuyMark](https://discuss.elastic.co/u/GuyMark)\
**Replies:** 18\
**Last updated:** [July 19, 2025, 5:18pm UTC](https://discuss.elastic.co/t/persistent-keystore-errors-guidance-for-new-install-please/378620 "2025-07-19T17:18:12Z")

</div>

I am trying to install elasticsearch both to learn how to use it - and as I need to try to make a working system too. I first tried installing with notes from here over a year ago, but right from the start I had issues …

---

## [org.apache.spark.SparkClassNotFoundException: \[DATA\_SOURCE\_NOT\_FOUND\] Failed to find the data source: org.elasticsearch.spark.sql. Make sure the provider name is correct and the package is properly registered and compatible with your Spark version](https://discuss.elastic.co/t/org-apache-spark-sparkclassnotfoundexception-data-source-not-found-failed-to-find-the-data-source-org-elasticsearch-spark-sql-make-sure-the-provider-name-is-correct-and-the-package-is-properly-registered-and-compatible-with-your-spark-version/380271)

<div class="topic-metadata">

**Author:** [@vsam](https://discuss.elastic.co/u/vsam)\
**Replies:** 0\
**Last updated:** [July 19, 2025, 1:06am UTC](https://discuss.elastic.co/t/org-apache-spark-sparkclassnotfoundexception-data-source-not-found-failed-to-find-the-data-source-org-elasticsearch-spark-sql-make-sure-the-provider-name-is-correct-and-the-package-is-properly-registered-and-compatible-with-your-spark-version/380271 "2025-07-19T01:06:01Z")

</div>

Hi Everyone, Currently I want to write pyspark dataframe to Elasticcloud index Below is the code, however pyspark is unable to find the org.elasticsearch.spark.sql. Environment - Databricks Databricks Run time - 1…

---

## [Adding additional aggregation causes 15x performance degradation despite small result set](https://discuss.elastic.co/t/adding-additional-aggregation-causes-15x-performance-degradation-despite-small-result-set/380132)

<div class="topic-metadata">

**Author:** [@mmiliauskas](https://discuss.elastic.co/u/mmiliauskas)\
**Replies:** 3\
**Last updated:** [July 18, 2025, 2:30pm UTC](https://discuss.elastic.co/t/adding-additional-aggregation-causes-15x-performance-degradation-despite-small-result-set/380132 "2025-07-18T14:30:37Z")

</div>

I have an Elasticsearch query that returns only 107 documents but takes 1.5 seconds to execute. When I remove one specific aggregation (values\_brand), the same query completes in 100ms. The brand field only contains 8 un…

---

## [Query regarding "cluster.initial\_master\_nodes"](https://discuss.elastic.co/t/query-regarding-cluster-initial-master-nodes/379318)

<div class="topic-metadata">

**Author:** [@mike123](https://discuss.elastic.co/u/mike123)\
**Replies:** 9\
**Last updated:** [July 18, 2025, 11:27am UTC](https://discuss.elastic.co/t/query-regarding-cluster-initial-master-nodes/379318 "2025-07-18T11:27:17Z")

</div>

i am having a cluster in which i have configured master node IPs in "cluster.initial\_master\_nodes" (ex: cluster.initial\_master\_nodes:\["172.12.12.2:9300","172.12.12.3:9300","172.12.12.4:9300"\]) and it worked perfectly. no…

---

## [Api key authentication on ElasticSearch 7.10.02 OSS](https://discuss.elastic.co/t/api-key-authentication-on-elasticsearch-7-10-02-oss/380164)

<div class="topic-metadata">

**Author:** [@qasidmubashir](https://discuss.elastic.co/u/qasidmubashir)\
**Replies:** 2\
**Last updated:** [July 18, 2025, 9:36am UTC](https://discuss.elastic.co/t/api-key-authentication-on-elasticsearch-7-10-02-oss/380164 "2025-07-18T09:36:53Z")

</div>

We are using Elasticsearch 7.10.02 OSS hosted on OpenSearch service on AWS Currently we are connecting our .net project to Elk using BasicAuthentication (Username Password), we are trying to switch to using apikey Nee…

---

## [How to make username case insensitive? (The default Basic Authentication via Internal Native Realm)](https://discuss.elastic.co/t/how-to-make-username-case-insensitive-the-default-basic-authentication-via-internal-native-realm/380175)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 2\
**Last updated:** [July 18, 2025, 5:49am UTC](https://discuss.elastic.co/t/how-to-make-username-case-insensitive-the-default-basic-authentication-via-internal-native-realm/380175 "2025-07-18T05:49:34Z")

</div>

Hi I would like to make my usernames case insensitive, but can't seem to find the config to achieve it. E.g. "Christof" is working, but "christof" is not (Difference: capital C) I found the documentation about authent…

---

## [Index sorting on boolean fields](https://discuss.elastic.co/t/index-sorting-on-boolean-fields/380181)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 1\
**Last updated:** [July 16, 2025, 8:38pm UTC](https://discuss.elastic.co/t/index-sorting-on-boolean-fields/380181 "2025-07-16T20:38:56Z")

</div>

Hey, quick question about index sorting on boolean fields. Basically we have an is\_active field in our data, and most of customer facing our queries have an is\_active: true filter applied. Am I right to assume that ind…

---

## [Need help with master nodes issue and UUID's](https://discuss.elastic.co/t/need-help-with-master-nodes-issue-and-uuids/380042)

<div class="topic-metadata">

**Author:** [@Alex\_Palacios](https://discuss.elastic.co/u/Alex_Palacios)\
**Replies:** 3\
**Last updated:** [July 17, 2025, 12:32pm UTC](https://discuss.elastic.co/t/need-help-with-master-nodes-issue-and-uuids/380042 "2025-07-17T12:32:43Z")

</div>

hi, We have a cluster with two master nodes and two data nodes, we had an issue where master pods show "master not discovered exception", so we deleted the PVC of master-1 and the master-1 pod, and re-created it, now ma…

---

## [Problem with 1 cluster](https://discuss.elastic.co/t/problem-with-1-cluster/380211)

<div class="topic-metadata">

**Author:** [@Usman\_Moavia](https://discuss.elastic.co/u/Usman_Moavia)\
**Replies:** 1\
**Last updated:** [July 17, 2025, 10:50am UTC](https://discuss.elastic.co/t/problem-with-1-cluster/380211 "2025-07-17T10:50:51Z")

</div>

When i try to search logs in "Discover" window i am seeing a warning against cluster, i think data might be not visible fully. when i open the warning it says 4 shards failed, failure type is " no\_shard\_available\_action…

---

## [Interested in Integrating with Elastic Stack](https://discuss.elastic.co/t/interested-in-integrating-with-elastic-stack/380201)

<div class="topic-metadata">

**Author:** [@naher64547](https://discuss.elastic.co/u/naher64547)\
**Replies:** 0\
**Last updated:** [July 17, 2025, 7:26am UTC](https://discuss.elastic.co/t/interested-in-integrating-with-elastic-stack/380201 "2025-07-17T07:26:08Z")

</div>

Hey guys... :waving\_hand: I recently completed my Spotfire course from igmGuru with some of the best trainers, and I’m eager to explore how Elastic Stack can complement my data visualization and analytics skills. Can a…

---

## [Vector search large dense vectors performance issues](https://discuss.elastic.co/t/vector-search-large-dense-vectors-performance-issues/380141)

<div class="topic-metadata">

**Author:** [@Pablo\_Delgado](https://discuss.elastic.co/u/Pablo_Delgado)\
**Replies:** 3\
**Last updated:** [July 16, 2025, 1:42pm UTC](https://discuss.elastic.co/t/vector-search-large-dense-vectors-performance-issues/380141 "2025-07-16T13:42:45Z")

</div>

I experience inconsistent (slow and fast results) on vector search. I currently have 50 million documents in an index, the vectors are stored in a filed with the current mapping: "large\_1536\_embedding": { "type": "de…

---

## [Elasticsearch Performance Issue After Adding Second Node](https://discuss.elastic.co/t/elasticsearch-performance-issue-after-adding-second-node/380138)

<div class="topic-metadata">

**Author:** [@SalehEska](https://discuss.elastic.co/u/SalehEska)\
**Replies:** 3\
**Last updated:** [July 16, 2025, 9:07am UTC](https://discuss.elastic.co/t/elasticsearch-performance-issue-after-adding-second-node/380138 "2025-07-16T09:07:38Z")

</div>

Hello everyone, I’m currently experiencing a performance issue with my Elasticsearch cluster. Previously, I was using a single-node setup, and all queries—especially \_count—were working quickly and reliably. Recently, …

---

## [Elasticsearch container as rootless Podman](https://discuss.elastic.co/t/elasticsearch-container-as-rootless-podman/380151)

<div class="topic-metadata">

**Author:** [@bbmcgee](https://discuss.elastic.co/u/bbmcgee)\
**Replies:** 0\
**Last updated:** [July 16, 2025, 1:51am UTC](https://discuss.elastic.co/t/elasticsearch-container-as-rootless-podman/380151 "2025-07-16T01:51:01Z")

</div>

I am using the elasticsearch 8.16.1 image, and get permissions error "java.nio.file.AccessDeniedException: /usr/share/elasticsearch/data" when I try to run it rootless with the command below with the mapped host volume /…

---

## [Identity-based authentication for automated pipeline deployments of Elastic Hosted and Serverless](https://discuss.elastic.co/t/identity-based-authentication-for-automated-pipeline-deployments-of-elastic-hosted-and-serverless/380148)

<div class="topic-metadata">

**Author:** [@alexyuwenaveva](https://discuss.elastic.co/u/alexyuwenaveva)\
**Replies:** 0\
**Last updated:** [July 15, 2025, 8:41pm UTC](https://discuss.elastic.co/t/identity-based-authentication-for-automated-pipeline-deployments-of-elastic-hosted-and-serverless/380148 "2025-07-15T20:41:17Z")

</div>

I would like to: set up automated pipeline deployments of both Elastic Hosted and Serverless avoid the inherent riskiness and fragility of API keys instead, use something like service principal or managed identity My …

---

## [Elk upgradation from 8.16.1 to 8.18.8 on docker](https://discuss.elastic.co/t/elk-upgradation-from-8-16-1-to-8-18-8-on-docker/380127)

<div class="topic-metadata">

**Author:** [@Sachin\_Chourasiya](https://discuss.elastic.co/u/Sachin_Chourasiya)\
**Replies:** 0\
**Last updated:** [July 15, 2025, 7:19am UTC](https://discuss.elastic.co/t/elk-upgradation-from-8-16-1-to-8-18-8-on-docker/380127 "2025-07-15T07:19:32Z")

</div>

Hi Team, Currently we are using 8.16.1 version of elk 3 node cluster on docker having components Elasticsearch, Kibana and fleet. we need to upgrade it to 8.18.8 version, so we have below queries: How to utilize upgra…

---

## [Watcher Email Output Not Preserving HTML Cell Colors](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 6\
**Last updated:** [July 15, 2025, 3:21am UTC](https://discuss.elastic.co/t/watcher-email-output-not-preserving-html-cell-colors/379939 "2025-07-15T03:21:00Z")

</div>

Hello Team, Could you please share if it is possible to have color coding while sending email via Watcher? Like if OK = the cell should be Green in the table which is sent via Watcher & for NOT OK = Red. I tried but i…

---

## [ELK 8.19.0](https://discuss.elastic.co/t/elk-8-19-0/380115)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [July 14, 2025, 6:51pm UTC](https://discuss.elastic.co/t/elk-8-19-0/380115 "2025-07-14T18:51:47Z")

</div>

Any news when ELK 8.19.0 may come out?

---

## [BulkProcessor insertions not happening in our environment](https://discuss.elastic.co/t/bulkprocessor-insertions-not-happening-in-our-environment/380028)

<div class="topic-metadata">

**Author:** [@rajathgubbi](https://discuss.elastic.co/u/rajathgubbi)\
**Replies:** 3\
**Last updated:** [July 14, 2025, 2:01pm UTC](https://discuss.elastic.co/t/bulkprocessor-insertions-not-happening-in-our-environment/380028 "2025-07-14T14:01:46Z")

</div>

We are creating the BulkProcessor object as shown below. While some upserts are processed successfully, subsequent upserts are not being completed. This issue is occurring in a high-scale environment where the upserts re…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=23)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=25)
