# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=242

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 243

---

## [Elasticsearch killed at time of start](https://discuss.elastic.co/t/elasticsearch-killed-at-time-of-start/336312)

<div class="topic-metadata">

**Author:** [@deepakmahajan00](https://discuss.elastic.co/u/deepakmahajan00)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 12:28pm UTC](https://discuss.elastic.co/t/elasticsearch-killed-at-time-of-start/336312 "2023-06-19T12:28:49Z")

</div>

Starting Elasticsearch Server …

---

## [Format version is not supported (resource BufferedChecksumIndexInput (SimpleFSIndexInput))](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336348)

<div class="topic-metadata">

**Author:** [@amal\_srivastava](https://discuss.elastic.co/u/amal_srivastava)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 11:14am UTC](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336348 "2023-06-19T11:14:44Z")

</div>

Hi, One of my elasticsearch index is red and when i dig this into deep i am getting this below error GET \_cluster/allocation/explain { "index" : "design", "shard" : 0, "primary" : true, "current\_state" : "unassign…

---

## [Issue with ingesting data and disk size](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 9:23am UTC](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087 "2023-06-19T09:23:29Z")

</div>

I am facing a very weird issue. I tried uploading 30 GB of csv data in Elasticsearch using python client. The below is the disk usage when I quit ingestion:- shards disk.indices disk.used disk.avail disk.total disk.pe…

---

## [Fleet: This output type currently does not support connectivity to a remote Elasticsearch cluster](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 8:15am UTC](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336 "2023-06-19T08:15:22Z")

</div>

I'm currently testing Fleet and added a dedicated fleet server and a dedicated "collector server" VM with elastic agent installed. Everything is now managed via Kibana and my goal is to collect stuff via the collector VM…

---

## [Getting unrelated data while searching with -\* in simple\_query\_string](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192)

<div class="topic-metadata">

**Author:** [@ms.t](https://discuss.elastic.co/u/ms.t)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 8:10am UTC](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192 "2023-06-19T08:10:50Z")

</div>

Hi I am using simple\_query\_string method with suffix \* (operator) for getting result But when i am searching with odd number of - getting unrelated data but with even number of - getting empty data.

---

## [Need help with Elasticsearch and Elastic agent](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502)

<div class="topic-metadata">

**Author:** [@SanketBaraiya](https://discuss.elastic.co/u/SanketBaraiya)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 7:20am UTC](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502 "2023-06-19T07:20:21Z")

</div>

I am facing the problem in my elk server. Whenever I start the elasticsearch service the outgoing traffic increases to \>10 MBps. This is what is shown in the processes. I also have stopped both filebeat and metricbea…

---

## [Upgrde 7.8 to 7](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 6:39am UTC](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264 "2023-06-19T06:39:42Z")

</div>

HI Team, Need help , we are facing issue after upgrade elasticseach from 7.8 to 7.17.10, Issue first it incresed respoonce time Chche value decresed drasticily from 7.8 to 7.17.10 on search . Please help Thanks Abh…

---

## [How to delete/clear an invalidated api key from '/\_security/api\_key' list?](https://discuss.elastic.co/t/how-to-delete-clear-an-invalidated-api-key-from-security-api-key-list/336069)

<div class="topic-metadata">

**Author:** [@ade.syseng](https://discuss.elastic.co/u/ade.syseng)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 4:30am UTC](https://discuss.elastic.co/t/how-to-delete-clear-an-invalidated-api-key-from-security-api-key-list/336069 "2023-06-19T04:30:27Z")

</div>

Hi, Is it possible to delete these invalidated api keys from '/\_security/api\_key'? I just want to keep the list clean from invalidated keys. Any suggestion or solution for this issue? Note: Elasticsearch and Kibana …

---

## [Index status red with reason failed engine (reason: \[merge failed\])](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249)

<div class="topic-metadata">

**Author:** [@Fajaruddin\_Shiddiq](https://discuss.elastic.co/u/Fajaruddin_Shiddiq)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 1:55am UTC](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249 "2023-06-19T01:55:47Z")

</div>

Hi, one of my index seems corrupt because of failed during merge process as below org.apache.lucene.index.MergePolicy$MergeException: org.apache.lucene.index.CorruptIndexException: docs out of order (594 \<= 594 ) (reso…

---

## [Unable to find in Java Client API ES 8.7 replacement of fieldsAndWeights in QueryStringQueryBuilder of earlier version](https://discuss.elastic.co/t/unable-to-find-in-java-client-api-es-8-7-replacement-of-fieldsandweights-in-querystringquerybuilder-of-earlier-version/336285)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 12:20am UTC](https://discuss.elastic.co/t/unable-to-find-in-java-client-api-es-8-7-replacement-of-fieldsandweights-in-querystringquerybuilder-of-earlier-version/336285 "2023-06-19T00:20:16Z")

</div>

Before ES 8 we were using below query. final BoolQueryBuilder expectedBooleanQuery = QueryBuilders.boolQuery(); expectedBooleanQuery.must( QueryBuilders.queryStringQuery("water") .defaultOperato…

---

## [Problems spinning up the docker compose example](https://discuss.elastic.co/t/problems-spinning-up-the-docker-compose-example/336268)

<div class="topic-metadata">

**Author:** [@Sasho](https://discuss.elastic.co/u/Sasho)\
**Replies:** 2\
**Last updated:** [June 18, 2023, 9:17pm UTC](https://discuss.elastic.co/t/problems-spinning-up-the-docker-compose-example/336268 "2023-06-18T21:17:06Z")

</div>

Hello, I'm following the instructions on Start a multi-node cluster with Docker Compose. I believe I have set up everything correctly. My .env file looks like this: # Password for the 'elastic' user (at least 6 chara…

---

## [Recent ecommerce requirement change ballooned our hosting costs x7. Need help with data model](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308)

<div class="topic-metadata">

**Author:** [@sdata47](https://discuss.elastic.co/u/sdata47)\
**Replies:** 0\
**Last updated:** [June 18, 2023, 6:14pm UTC](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308 "2023-06-18T18:14:54Z")

</div>

We're having a serious issue using Elasticsearch at work without large hosting costs. A recent requirement change bumped us up from $120 to $700 a month. Essentially, this is the issue. We have a catalog of products, …

---

## [Transform + Enrichment Policy](https://discuss.elastic.co/t/transform-enrichment-policy/334878)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 12\
**Last updated:** [June 18, 2023, 5:13pm UTC](https://discuss.elastic.co/t/transform-enrichment-policy/334878 "2023-06-18T17:13:47Z")

</div>

Hello, I had the idea to use the target index of a sum aggregation transform as the same target index for an enrichment policy. Essentially, I want to perform a join on the field being grouped on in the transform and en…

---

## [Little confuse about decay function source code](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296)

<div class="topic-metadata">

**Author:** [@RandalTeng](https://discuss.elastic.co/u/RandalTeng)\
**Replies:** 2\
**Last updated:** [June 18, 2023, 8:36am UTC](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296 "2023-06-18T08:36:15Z")

</div>

hi guys, I recently read some source code about the decay function. there is some code doc, I can't figure out why it should be. the code line is: https://github.com/elastic/elasticsearch/blob/13fb93511c23fe0d1a02de07…

---

## [Can you forward logs going into elasticsearch to a third party?](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 3\
**Last updated:** [June 17, 2023, 3:32pm UTC](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800 "2023-06-17T15:32:43Z")

</div>

I have a single instance of elasticsearch, kibana and i am getting the data in this via agents and filebeats. is there a way to "forward" the data that is ingested into elasticsearch to another device or instance?

---

## [Update field with new values is not possible using aggregate filter](https://discuss.elastic.co/t/update-field-with-new-values-is-not-possible-using-aggregate-filter/336266)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 0\
**Last updated:** [June 17, 2023, 10:27am UTC](https://discuss.elastic.co/t/update-field-with-new-values-is-not-possible-using-aggregate-filter/336266 "2023-06-17T10:27:51Z")

</div>

I am trying to update a JSON object called "attributes" inside aggregate filter. In some cases, I may or may not have attributes in Index, if it is not available means I will insert "attributes" as new JSON object field…

---

## [Reindex From json File only specific log file path docs](https://discuss.elastic.co/t/reindex-from-json-file-only-specific-log-file-path-docs/336195)

<div class="topic-metadata">

**Author:** [@bill210kouk](https://discuss.elastic.co/u/bill210kouk)\
**Replies:** 2\
**Last updated:** [June 17, 2023, 9:43am UTC](https://discuss.elastic.co/t/reindex-from-json-file-only-specific-log-file-path-docs/336195 "2023-06-17T09:43:18Z")

</div>

Good Morning I hope you're Alright. I'm a newbie and i would like to ask something. I've made an export process with elasticdump and it was a success. I would like to ask . My end goal is to keep only valuable documents…

---

## [Problems while using \_bulk api via camel rest route](https://discuss.elastic.co/t/problems-while-using-bulk-api-via-camel-rest-route/336238)

<div class="topic-metadata">

**Author:** [@markchennai](https://discuss.elastic.co/u/markchennai)\
**Replies:** 1\
**Last updated:** [June 17, 2023, 7:36am UTC](https://discuss.elastic.co/t/problems-while-using-bulk-api-via-camel-rest-route/336238 "2023-06-17T07:36:03Z")

</div>

Message History (source location and message history is disabled) Source ID Processor Elapsed (ms) route1/route1 …

---

## [Elasticsearch does not start](https://discuss.elastic.co/t/elasticsearch-does-not-start/336261)

<div class="topic-metadata">

**Author:** [@pan\_sjan](https://discuss.elastic.co/u/pan_sjan)\
**Replies:** 4\
**Last updated:** [June 17, 2023, 6:09am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start/336261 "2023-06-17T06:09:55Z")

</div>

I am using the es 7.17.10 tarball from https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.17.10-linux-x86\_64.tar.gz The Java version I have is JDK 18 # /usr/java/latest/bin/java -version openjdk vers…

---

## [Normalising scores?](https://discuss.elastic.co/t/normalising-scores/336149)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 8:49pm UTC](https://discuss.elastic.co/t/normalising-scores/336149 "2023-06-16T20:49:31Z")

</div>

I've been searching how to normalise the scores so we can display the score as a percentage to the end user - it seems that this is/was not possible? That seems incredible to me... Is there really no way to tell elastic…

---

## [How can I modify the path Elasticsearch 2.4.6 uses to run Java in Linux?](https://discuss.elastic.co/t/how-can-i-modify-the-path-elasticsearch-2-4-6-uses-to-run-java-in-linux/335893)

<div class="topic-metadata">

**Author:** [@Latitude](https://discuss.elastic.co/u/Latitude)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 7:59pm UTC](https://discuss.elastic.co/t/how-can-i-modify-the-path-elasticsearch-2-4-6-uses-to-run-java-in-linux/335893 "2023-06-16T19:59:31Z")

</div>

Brand new to Elasticsearch. Can anyone explain how how to modify the path Elasticsearch v2.4.6 uses for Java on Linux? There is a discrepancy between Test and Production and I need to change Test to match Production: Pr…

---

## [How to shutdown ES using API call](https://discuss.elastic.co/t/how-to-shutdown-es-using-api-call/336210)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 5\
**Last updated:** [June 16, 2023, 4:51pm UTC](https://discuss.elastic.co/t/how-to-shutdown-es-using-api-call/336210 "2023-06-16T16:51:54Z")

</div>

Hi, I am wondering if there is a way or an API using which I can shutdown my ES server?

---

## [Python Elasticsearch API: Error 'data too large' when iterating](https://discuss.elastic.co/t/python-elasticsearch-api-error-data-too-large-when-iterating/336234)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 2:15pm UTC](https://discuss.elastic.co/t/python-elasticsearch-api-error-data-too-large-when-iterating/336234 "2023-06-16T14:15:28Z")

</div>

I am using the Python Elasticsearch API to interact with my Elastic cluster. I'm getting an error when I try to perform several searches in a for loop. In synthesis, I'm doing the following: I iterate over a list of valu…

---

## [Allow Kibana role to access all indices EXCEPT FOR a specific one](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [June 16, 2023, 1:16pm UTC](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135 "2023-06-16T13:16:49Z")

</div>

TL;DR How do I grant access to all indices matching a pattern, but deny access to one specific index that also matches the pattern (e.g., how do I ALLOW access to all logs, including logs-myapp.log-\*, but specifically DE…

---

## [Drop docs if source.ip is on range os IPs](https://discuss.elastic.co/t/drop-docs-if-source-ip-is-on-range-os-ips/336229)

<div class="topic-metadata">

**Author:** [@Carlos\_Samuel](https://discuss.elastic.co/u/Carlos_Samuel)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 1:15pm UTC](https://discuss.elastic.co/t/drop-docs-if-source-ip-is-on-range-os-ips/336229 "2023-06-16T13:15:37Z")

</div>

Hi. I need to drop docs that is on range of IP "192.168.1.1" and "192.168.3.255". What I have tried on Ingest Pipelines: This example above is getting me "Compile Error".

---

## [Elastic "premium"](https://discuss.elastic.co/t/elastic-premium/336220)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 12:56pm UTC](https://discuss.elastic.co/t/elastic-premium/336220 "2023-06-16T12:56:21Z")

</div>

Hello everyone, I am potentially interested in a higher version of the Elastic suite, but I am not sure of is that the prices below are only for the cloud or not: Tarifs officiels Elasticsearch : Elastic Cloud, offre E…

---

## [Docker elasticsearch container : FileSystemException : Not a directory](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/336196)

<div class="topic-metadata">

**Author:** [@JulianMeister](https://discuss.elastic.co/u/JulianMeister)\
**Replies:** 3\
**Last updated:** [June 16, 2023, 9:27am UTC](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/336196 "2023-06-16T09:27:14Z")

</div>

I have the same issue as described in: I'm getting the error "java.nio.file.FileSystemException: /usr/share/elasticsearch/data/nodes/0: Not a directory" But if I change "/usr/share/elasticsearch/data" to "/usr/share/…

---

## [Rollover Index duplication data,data coming from logstash](https://discuss.elastic.co/t/rollover-index-duplication-data-data-coming-from-logstash/332726)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 18\
**Last updated:** [June 16, 2023, 9:26am UTC](https://discuss.elastic.co/t/rollover-index-duplication-data-data-coming-from-logstash/332726 "2023-06-16T09:26:14Z")

</div>

Hello , I'm facing one issue,to elaborate I've 40 elastic index and these are handled by ILM policy with rollover defined.The ilm policy is maintained to send data to new index each day(rollover) and delete after 5 days…

---

## [Docker elasticsearch container : FileSystemException : Not a directory](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/330204)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 8:33am UTC](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/330204 "2023-06-16T08:33:10Z")

</div>

I tried to modify the port the docker container of elasticsearch from 9200:9200 to 9201:9200 and since I did that I got this error in the docker container : "message": "uncaught exception in thread \[main\]", "stacktrace…

---

## [PKI Authentication query](https://discuss.elastic.co/t/pki-authentication-query/334121)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [June 16, 2023, 6:43am UTC](https://discuss.elastic.co/t/pki-authentication-query/334121 "2023-06-16T06:43:19Z")

</div>

Hello All, I'm using PKI based authentication for accessing kibana,The issue I'm facing is for the very first time using my PKI , I enter my password and it authenticates correctly. But now when I'm accessing the kiba…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=241)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=243)
