# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=248

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 249

---

## [Show only results that are relevent to my shopping history](https://discuss.elastic.co/t/show-only-results-that-are-relevent-to-my-shopping-history/333149)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 11:05pm UTC](https://discuss.elastic.co/t/show-only-results-that-are-relevent-to-my-shopping-history/333149 "2023-06-06T23:05:38Z")

</div>

I want to understand if elasticsearch + knn could be used to accomplish this ask: a search on an item should only show relevent results with my shopping history. eg) search on dress should only show red or black or full…

---

## [How to "join" two different types of documents on the closest value of a common integer key](https://discuss.elastic.co/t/how-to-join-two-different-types-of-documents-on-the-closest-value-of-a-common-integer-key/333226)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 9:27pm UTC](https://discuss.elastic.co/t/how-to-join-two-different-types-of-documents-on-the-closest-value-of-a-common-integer-key/333226 "2023-06-06T21:27:32Z")

</div>

I have a problem. I've inherited legacy code for which ELK stack is now being used to capture and detect problems. Logstash + Filebeat are being used and an index template is being used to correctly map WGS84 points. I …

---

## [Returning count of buckets from aggregation terms search](https://discuss.elastic.co/t/returning-count-of-buckets-from-aggregation-terms-search/335373)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 6:48pm UTC](https://discuss.elastic.co/t/returning-count-of-buckets-from-aggregation-terms-search/335373 "2023-06-06T18:48:17Z")

</div>

Before anyone suggests it, I am trying to use the terms aggregation with a very large size value to get a more exact number as opposed to using cardinality. I realize it's less efficient but I'm only searching around 75k…

---

## [Cluster takes too long to apply cluster state](https://discuss.elastic.co/t/cluster-takes-too-long-to-apply-cluster-state/328407)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 26\
**Last updated:** [June 6, 2023, 6:14pm UTC](https://discuss.elastic.co/t/cluster-takes-too-long-to-apply-cluster-state/328407 "2023-06-06T18:14:51Z")

</div>

Hi guys, We have some 1Tb+ indices and it takes more than a minute to drop these indices when we rotate them. During the deletion cluster takes too long to apply cluster state and master nodes start to kick data nodes o…

---

## [How do you set up the user account to run Elasticsearch service on Linux?](https://discuss.elastic.co/t/how-do-you-set-up-the-user-account-to-run-elasticsearch-service-on-linux/335368)

<div class="topic-metadata">

**Author:** [@Latitude](https://discuss.elastic.co/u/Latitude)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 5:22pm UTC](https://discuss.elastic.co/t/how-do-you-set-up-the-user-account-to-run-elasticsearch-service-on-linux/335368 "2023-06-06T17:22:28Z")

</div>

Hello, I'm new to my organization and to Elasticsearch. I'm the new server administrator for Liferay 7.4 DXP which uses Elasticsearch 7.17.x. I'm developing our migration procedure as we're migrating to Liferay 7.4 DXP …

---

## [Docker-compose instructions lead to "unable to authenticate user \[elastic\]"](https://discuss.elastic.co/t/docker-compose-instructions-lead-to-unable-to-authenticate-user-elastic/333060)

<div class="topic-metadata">

**Author:** [@Pinch](https://discuss.elastic.co/u/Pinch)\
**Replies:** 27\
**Last updated:** [June 6, 2023, 1:09pm UTC](https://discuss.elastic.co/t/docker-compose-instructions-lead-to-unable-to-authenticate-user-elastic/333060 "2023-06-06T13:09:10Z")

</div>

Following these official instructions: Brings me to a state of "Kibana server is not ready yet." in the browser. Inspecting the logs I can see from the Kibana container that kibana\_system is not authenticated. Then c…

---

## [Rest API client](https://discuss.elastic.co/t/rest-api-client/335323)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 12:41pm UTC](https://discuss.elastic.co/t/rest-api-client/335323 "2023-06-06T12:41:42Z")

</div>

Do i need to upgrade REST API client version 7.2.1 also after ES up-gradation from version 7.8 to 7.17.

---

## [Best Practice: Update metadata on larger documents](https://discuss.elastic.co/t/best-practice-update-metadata-on-larger-documents/335311)

<div class="topic-metadata">

**Author:** [@Hiketas](https://discuss.elastic.co/u/Hiketas)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 12:21pm UTC](https://discuss.elastic.co/t/best-practice-update-metadata-on-larger-documents/335311 "2023-06-06T12:21:51Z")

</div>

I have a question about best practice in the following scenario: I have documents with some meta fields among others with a full text field which can be up to 10 MB in size. We currently do not use parent/child relation…

---

## [Performance issue found : Upgade elasticsearch 7.8 to 7.17](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324 "2023-06-06T10:53:22Z")

</div>

Hi Team, We are facing major performance issue after upgrade elasticsearch from 7.8 to 7.17 by rolling method. Our Query hits elasticsearch using java rest api(7.2.1). Perfomance degrade form 20ms to 300ms. I need to…

---

## [Shuffle sorted documents](https://discuss.elastic.co/t/shuffle-sorted-documents/335255)

<div class="topic-metadata">

**Author:** [@Novel\_one](https://discuss.elastic.co/u/Novel_one)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/shuffle-sorted-documents/335255 "2023-06-06T10:10:22Z")

</div>

Hi, I want to create a promotional box in my marketplace, with the top rated articles. I dont want always to be the same articles, so i want them be shuffled a little by multiplying the article avg rate by a random num…

---

## [Running elastic search](https://discuss.elastic.co/t/running-elastic-search/335182)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:20am UTC](https://discuss.elastic.co/t/running-elastic-search/335182 "2023-06-06T09:20:34Z")

</div>

How can I run elasticsearch using python client on google colab. I have a python code which is running on my machine. I want to run it on google colab or other notebook online platform. What setup or instruction I need f…

---

## [Single node yellow](https://discuss.elastic.co/t/single-node-yellow/335249)

<div class="topic-metadata">

**Author:** [@decibel83](https://discuss.elastic.co/u/decibel83)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 8:38am UTC](https://discuss.elastic.co/t/single-node-yellow/335249 "2023-06-06T08:38:07Z")

</div>

Hi have a single node elastic cluster which is yellow: GET /\_cluster/health: { "cluster\_name": "log", "status": "yellow", "timed\_out": false, "number\_of\_nodes": 1, "number\_of\_data\_nodes": 1, "act…

---

## [Curator 7 is failing to delete indices](https://discuss.elastic.co/t/curator-7-is-failing-to-delete-indices/335287)

<div class="topic-metadata">

**Author:** [@chiranjeevirao](https://discuss.elastic.co/u/chiranjeevirao)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 8:35am UTC](https://discuss.elastic.co/t/curator-7-is-failing-to-delete-indices/335287 "2023-06-06T08:35:13Z")

</div>

Hi We are using opensearch 1.2.4 (derived from Elasticsearch 7.10.2). We could see in the curator release document that curator 7 will work with Elasticsearch 7.x and is functionally identical to 5.8.4 and uplifted cur…

---

## [Migration from HighRestLevelCLient to ElasticSearchClient](https://discuss.elastic.co/t/migration-from-highrestlevelclient-to-elasticsearchclient/335023)

<div class="topic-metadata">

**Author:** [@neodeveloper](https://discuss.elastic.co/u/neodeveloper)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 8:21am UTC](https://discuss.elastic.co/t/migration-from-highrestlevelclient-to-elasticsearchclient/335023 "2023-06-06T08:21:47Z")

</div>

Good morning, We are planning to upgrade to springboot3.0 and we are heavily using the deprecated client named HighRestLevelClient which is removed in springboot3 and replaced with the new java api client named ElasticS…

---

## [Log4j Vulnerability Elasticsearch 7.8.0](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035)

<div class="topic-metadata">

**Author:** [@Faisal\_Umer](https://discuss.elastic.co/u/Faisal_Umer)\
**Replies:** 7\
**Last updated:** [June 6, 2023, 8:08am UTC](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035 "2023-06-06T08:08:01Z")

</div>

We have Elasticsearch 7.8.0 cluster which has CVE-2021-44228. Can we somehow patch it without upgrading the Elasticsearch version? If yes, can you please share any relevant thread or documentation?

---

## [I want to use spark to read data from es, but I don't know what es.net.ssl.keystore.pass is](https://discuss.elastic.co/t/i-want-to-use-spark-to-read-data-from-es-but-i-dont-know-what-es-net-ssl-keystore-pass-is/335210)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 7:58am UTC](https://discuss.elastic.co/t/i-want-to-use-spark-to-read-data-from-es-but-i-dont-know-what-es-net-ssl-keystore-pass-is/335210 "2023-06-06T07:58:51Z")

</div>

When I built the es cluster, I used bin/elasticsearch-certutil to generate the CA certificate and p12 certificate, but I did not enter the password, but chose to press Enter directly. When I want to use spark to connect…

---

## [Applying ILM on custom index](https://discuss.elastic.co/t/applying-ilm-on-custom-index/334924)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 7:53am UTC](https://discuss.elastic.co/t/applying-ilm-on-custom-index/334924 "2023-06-06T07:53:56Z")

</div>

Hi, I am using filebeat 8.3.3 with several inputs and writing them to the same ES 8.3.3. To separate the different inputs on ES, I have the following in my filebeat.yml. output.elasticsearch: indices: - index: "f…

---

## [How to get docs in aggregated format in ElasticSearch aggregation query?](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292 "2023-06-06T07:27:25Z")

</div>

My query { "aggs": { "distinct\_colours": { "terms": { "field": "colour" } } } } Required Result: { "took" : 2037, "timed\_out" : false, "\_shards" : { "total" : 1, "successf…

---

## [Indices in DR Cluster (CCR dest cluster) stuck on forcemerge causing the Space filled up](https://discuss.elastic.co/t/indices-in-dr-cluster-ccr-dest-cluster-stuck-on-forcemerge-causing-the-space-filled-up/335276)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 6:01am UTC](https://discuss.elastic.co/t/indices-in-dr-cluster-ccr-dest-cluster-stuck-on-forcemerge-causing-the-space-filled-up/335276 "2023-06-06T06:01:18Z")

</div>

I have 2 elasticsearch clusters deployed in 2 different regions in Amazon EKS. replicating data from east1 to east2 using CCR. I only keep the indices in east2 (dest cluster) for 2 days. 0 day after roller to warm (also…

---

## [How to calculate percentage of a field over all documents present in index](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544)

<div class="topic-metadata">

**Author:** [@Amit\_Charkha](https://discuss.elastic.co/u/Amit_Charkha)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:54am UTC](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544 "2023-06-06T04:54:48Z")

</div>

how to calculate percentage of a field log\_count over all documents present in index.

---

## [Why docker run elasticsearch working well and docker compose up stuck on starting, i am confused](https://discuss.elastic.co/t/why-docker-run-elasticsearch-working-well-and-docker-compose-up-stuck-on-starting-i-am-confused/335132)

<div class="topic-metadata">

**Author:** [@Wuxy-Bleu](https://discuss.elastic.co/u/Wuxy-Bleu)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 4:52am UTC](https://discuss.elastic.co/t/why-docker-run-elasticsearch-working-well-and-docker-compose-up-stuck-on-starting-i-am-confused/335132 "2023-06-06T04:52:05Z")

</div>

docker run -it -p 9201:9200 -p 9301:9300 --network elastic --name es2 -e discovery.type=single-node -e cluster.routing.allocation.disk.watermark.high=95% -e cluster.routing.allocation.disk.watermark.low=90% elasticsearch…

---

## [Single-node. Manage Lifecycle Policy](https://discuss.elastic.co/t/single-node-manage-lifecycle-policy/334347)

<div class="topic-metadata">

**Author:** [@Thales\_Eduardo](https://discuss.elastic.co/u/Thales_Eduardo)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:29am UTC](https://discuss.elastic.co/t/single-node-manage-lifecycle-policy/334347 "2023-06-06T04:29:14Z")

</div>

I have an elk siem (single node) version 8.7.1 in production. On it is a 5TB data partition with about 90% disk usage. I would like to allow lifecycle policies to rotate data every 180 days (6 months). It's possible? W…

---

## [Indexing requests and time goes high on 1 node in cluster](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491)

<div class="topic-metadata">

**Author:** [@tarund](https://discuss.elastic.co/u/tarund)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 4:28am UTC](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491 "2023-06-06T04:28:49Z")

</div>

Hi Team I am using ES 7.17.1. Pushing logs from Fluent to 5 node cluster. Enabled xpack monitoring on ES. we observe that sometime during the day the indexing requests & indexing time goes very high on a single node. So…

---

## [TLS error after fresh install of elastic search](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264)

<div class="topic-metadata">

**Author:** [@antarr](https://discuss.elastic.co/u/antarr)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 2:36am UTC](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264 "2023-06-06T02:36:34Z")

</div>

I'm trying to get Elasticsearch working on Ubuntu 22. I've uninstalled it a few times but keep getting an SSL error when testing using curl. I've tried 7.17, 7.10, and 8.8. uninstall sudo apt-get remove --purge elastic…

---

## [Push Logs from Elastic Search to Alien Vault USM Anywhere](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781)

<div class="topic-metadata">

**Author:** [@Zu\_kun](https://discuss.elastic.co/u/Zu_kun)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 2:16am UTC](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781 "2023-06-06T02:16:58Z")

</div>

Hi, I'm a legit noob when it comes to ELK so my questions might not make sense or will probably have some obvious answers to it. Getting straight to the point, I want to pull the logs from my on premises Elasticsearch …

---

## [Dynamic data (no code) scenario strategy](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870)

<div class="topic-metadata">

**Author:** [@Zak\_Sesti](https://discuss.elastic.co/u/Zak_Sesti)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:38am UTC](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870 "2023-06-06T01:38:52Z")

</div>

I use ES for searching of my basic CRUD constructs. But now we need to expand to help us search, sort, paginate our no-code constructs. These are json documents that have 100% dynamic fields. Some rough numbers: We …

---

## [Profile API](https://discuss.elastic.co/t/profile-api/335217)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:06am UTC](https://discuss.elastic.co/t/profile-api/335217 "2023-06-06T01:06:58Z")

</div>

I ran the profile API for my query that took 15s to run. I have a very big json as output. I am unable to determine why it is taking 15s. Can someone help me read or what to look for in the output of \_profile?

---

## [ILM not deleting data](https://discuss.elastic.co/t/ilm-not-deleting-data/335204)

<div class="topic-metadata">

**Author:** [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 10:11pm UTC](https://discuss.elastic.co/t/ilm-not-deleting-data/335204 "2023-06-05T22:11:26Z")

</div>

Hello, I'm trying to set a ILM to an index, but it's not deleting old data. This is my ILM: PUT \_ilm/policy/kong\_lifecycle { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { …

---

## [ES 8.6.2 - puzzling "Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]"?](https://discuss.elastic.co/t/es-8-6-2-puzzling-authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/335152)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 8:01pm UTC](https://discuss.elastic.co/t/es-8-6-2-puzzling-authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/335152 "2023-06-05T20:01:41Z")

</div>

I am aware this error has come up before, but please note the version, 8.6.2. Most of the others are about v7. So far I have found the whole configuration of 8.6.2. much more of a challenge (from the security PoV) than v…

---

## [Unable to apply memory lock to deploy elastic 8 on k8s](https://discuss.elastic.co/t/unable-to-apply-memory-lock-to-deploy-elastic-8-on-k8s/334897)

<div class="topic-metadata">

**Author:** [@rsingh\_2023](https://discuss.elastic.co/u/rsingh_2023)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 8:08pm UTC](https://discuss.elastic.co/t/unable-to-apply-memory-lock-to-deploy-elastic-8-on-k8s/334897 "2023-06-05T20:08:51Z")

</div>

I am running into issues with deploying elastic version 8.7 on kubernetes (k8s) I am using this docker image for elastic version 8.7 I have enabled bootstrap memory\_lock as "true" but I see these error logs in my elast…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=247)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=249)
