# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=251

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 252

---

## [Throws ssl context error while trying to initialize RestHighLevelClient](https://discuss.elastic.co/t/throws-ssl-context-error-while-trying-to-initialize-resthighlevelclient/334796)

<div class="topic-metadata">

**Author:** [@Developer1318](https://discuss.elastic.co/u/Developer1318)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 8:17am UTC](https://discuss.elastic.co/t/throws-ssl-context-error-while-trying-to-initialize-resthighlevelclient/334796 "2023-06-01T08:17:53Z")

</div>

java.lang.IllegalStateException: could not create the default ssl context at org.elasticsearch.client.RestClientBuilder.createHttpClient(RestClientBuilder.java:222) at org.elasticsearch.client.RestClientBuilder.access$…

---

## [java.net.UnknownHostException/Name or service not known/failed to resolve host](https://discuss.elastic.co/t/java-net-unknownhostexception-name-or-service-not-known-failed-to-resolve-host/334920)

<div class="topic-metadata">

**Author:** [@Sundeep\_Teja\_Polina](https://discuss.elastic.co/u/Sundeep_Teja_Polina)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 7:59am UTC](https://discuss.elastic.co/t/java-net-unknownhostexception-name-or-service-not-known-failed-to-resolve-host/334920 "2023-06-01T07:59:11Z")

</div>

Hi I'm trying to deploy a self-managed containerized multinode Elasticsearch cluster in aws ecs. I was able to deploy and use a single node Elasticsearch cluster inside aws ecs. When I'm trying to host the same in multi…

---

## [Enterprise Search running on a docker container can't connect to Elasticsearch running as a service on windows](https://discuss.elastic.co/t/enterprise-search-running-on-a-docker-container-cant-connect-to-elasticsearch-running-as-a-service-on-windows/334761)

<div class="topic-metadata">

**Author:** [@Mtuni\_Globbal](https://discuss.elastic.co/u/Mtuni_Globbal)\
**Replies:** 6\
**Last updated:** [June 1, 2023, 7:31am UTC](https://discuss.elastic.co/t/enterprise-search-running-on-a-docker-container-cant-connect-to-elasticsearch-running-as-a-service-on-windows/334761 "2023-06-01T07:31:23Z")

</div>

Hi, I'm trying to connect Enterprise Search which I run as a docker container to connect to Elasticsearch and Kibana which are running as Windows service. However, every time I run Enterprise Search it exits, saying that…

---

## [Shards allocation method](https://discuss.elastic.co/t/shards-allocation-method/334900)

<div class="topic-metadata">

**Author:** [@saifulshihab](https://discuss.elastic.co/u/saifulshihab)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:43am UTC](https://discuss.elastic.co/t/shards-allocation-method/334900 "2023-06-01T06:43:27Z")

</div>

Hello how shards are allocated in cluster nodes? for the below scenario could anyone explain ? for 3node cluster 3primary shards and 2 replica shards configured. i have to configure my nodes with same storage ? how …

---

## [Query taking longer times than expected, possible ways of optimization at query level](https://discuss.elastic.co/t/query-taking-longer-times-than-expected-possible-ways-of-optimization-at-query-level/334221)

<div class="topic-metadata">

**Author:** [@nadeem.akhter](https://discuss.elastic.co/u/nadeem.akhter)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 4:14am UTC](https://discuss.elastic.co/t/query-taking-longer-times-than-expected-possible-ways-of-optimization-at-query-level/334221 "2023-06-01T04:14:47Z")

</div>

I have an Elasticsearch 8.6.0 instance with some data in it. I have been querying data off it using query string with 130 keywords in the following format: { "query": { "bool": { "should": \[ …

---

## [Ds-ilm-history index](https://discuss.elastic.co/t/ds-ilm-history-index/334716)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 3:27am UTC](https://discuss.elastic.co/t/ds-ilm-history-index/334716 "2023-06-01T03:27:32Z")

</div>

Hi guys, We have ds-ilm-history index, likely created by ES ilm automatically at some point. We don't use ILM, is it safe to delete this index and disable ILM using API or it can trigger anything which we need to be aw…

---

## [Cluster.initial\_master\_nodes and discovery.seed\_hosts](https://discuss.elastic.co/t/cluster-initial-master-nodes-and-discovery-seed-hosts/334588)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 10:49pm UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-and-discovery-seed-hosts/334588 "2023-05-31T22:49:21Z")

</div>

Hi, I have elasticsearch cluster (8.7.0) on Kubernetes. In the configmaps of the nodes (master,data,client) I had: ... discovery.seed\_hosts: ${NODE\_LIST} cluster.initial\_master\_nodes: ${MASTER\_NODES} ... In my deploym…

---

## [Can I still jump from 7.17 to the new 8.8?](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 8\
**Last updated:** [May 31, 2023, 7:16pm UTC](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616 "2023-05-31T19:16:57Z")

</div>

I'm at 7.16 right now. I know I need to update to 7.17 first, but I am wondering if right after that I can go directly to 8.8? I know I could jump to 8.7 from 7.17. Just wondering if it's still the case.

---

## [Take snapshot of a datastream](https://discuss.elastic.co/t/take-snapshot-of-a-datastream/334867)

<div class="topic-metadata">

**Author:** [@Abhilash\_B](https://discuss.elastic.co/u/Abhilash_B)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 7:13pm UTC](https://discuss.elastic.co/t/take-snapshot-of-a-datastream/334867 "2023-05-31T19:13:37Z")

</div>

I have scrambled through a lot of documentation on Snapshot and Restore. I was unable to find a specific example that show how to take a snapshot of a datastream and then restore it. Any help is highly appreciated.

---

## [Span\_Near and Span\_or query for two multiword match is not giving expected result](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862)

<div class="topic-metadata">

**Author:** [@chetab](https://discuss.elastic.co/u/chetab)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 5:27pm UTC](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862 "2023-05-31T17:27:55Z")

</div>

I need to write the query for below scenario: Ex: The car will be getting close to me but I am unable to stop it. or The car is too close to me but I am unable to stop it. like: Span\_near(span\_or("getting close", "is t…

---

## [Is it possible to use a runtime field in document based security query](https://discuss.elastic.co/t/is-it-possible-to-use-a-runtime-field-in-document-based-security-query/334730)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 4:06pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-a-runtime-field-in-document-based-security-query/334730 "2023-05-31T16:06:47Z")

</div>

If I wanted to setup a role that has document based security and uses runtime field in the query, would that be possible? I can use regular, already indexed fields to do that, but I don't know how to do that with a Runti…

---

## [Match query with operator "and", doesn't work when using synonyms analyzer](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821)

<div class="topic-metadata">

**Author:** [@Bage\_Atanasovska](https://discuss.elastic.co/u/Bage_Atanasovska)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 3:40pm UTC](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821 "2023-05-31T15:40:02Z")

</div>

I am creating an index using as a search analyzer, an alayzer that has a synonym filter. The query that creates the index is the following: { "settings": { "index": { "analysis": { …

---

## [Issue while running FSCrawler on WSL](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620)

<div class="topic-metadata">

**Author:** [@chloesun](https://discuss.elastic.co/u/chloesun)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:05pm UTC](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620 "2023-05-31T14:05:48Z")

</div>

I installed JAVA 11, Elastic Search 7, and Fscrawler2.8 on WSL on my Windows machine. Elastic search has no issue starting, and I already configured JAVA\_HOME in .bashrc export JAVA\_HOME="/usr/lib/jvm/java-11-openjdk-am…

---

## [Mapper\_parsing\_exception error](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:01pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447 "2023-05-31T14:01:26Z")

</div>

Hi all, I create indexes on a daily basis using fluentd in Elasticsearch. I don't do any mapping on elasticsearch side. After a while, the related index could not be created in Elasticsearch and I got the following erro…

---

## [Elastic Search 8.6.2 SSL enabled with 3rd party certificate](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 21\
**Last updated:** [May 31, 2023, 1:50pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713 "2023-05-31T13:50:36Z")

</div>

I have a single instance of Elastic Search 8.6.2 installed on a redhat server. No cloud, No docker and single node, very simple install. We need SSL enabled and configured to use a 3rd party certificate we can't use El…

---

## [Range queries with should clause not working](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 12:58pm UTC](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764 "2023-05-31T12:58:54Z")

</div>

Hi, I'm trying below range query with must and should clause: Product id can range from 1 to 1000. I'm using below query to fetch product\_id between 1 to 99 or product\_id = 100. However I can only see the must clause…

---

## [Faceting, sorting, paginating within buckets](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:30pm UTC](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801 "2023-05-31T12:30:56Z")

</div>

Hi there, I have a question around Elasticsearch's aggregation functionality. We have a use case where we need to do search with a "search term" and then group results by a field in the document and read documents within…

---

## [Unable to form an ES cluster](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:31am UTC](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795 "2023-05-31T11:31:42Z")

</div>

I am having 2 nodes having elasticsearch installed. I am running first node as :- sudo docker run -it --pull=always --net elastic -p 9200:9200 -p 9300:9300 -e discovery.type=multi-node -e cluster.name="my-elasticsearch-…

---

## [Adding Custom Fields to an Elasticsearch Index](https://discuss.elastic.co/t/adding-custom-fields-to-an-elasticsearch-index/334794)

<div class="topic-metadata">

**Author:** [@Abeer\_Islam](https://discuss.elastic.co/u/Abeer_Islam)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:29am UTC](https://discuss.elastic.co/t/adding-custom-fields-to-an-elasticsearch-index/334794 "2023-05-31T11:29:10Z")

</div>

Hi, I want to add custom fields (Year, Yearly Week, Week, Month, Exist (a boolean value)) and their corresponding values into an ES index using API. SInce, I am running the OpenDistro for Elasticsearch version which doe…

---

## [Add query parameter "level" to the IndicesStatsRequest using the 7.17 transport client](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782)

<div class="topic-metadata">

**Author:** [@kley](https://discuss.elastic.co/u/kley)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 11:23am UTC](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782 "2023-05-31T11:23:38Z")

</div>

Hey! We are using Elasticsearch 7.17 + the corresponding transport client. I try to calculate the consumed disk space from Elasticsearch without the cat API and came up with this solution (documentation): curl -H 'Con…

---

## [DeflateCompressor threads causing memory leak in Tomcat](https://discuss.elastic.co/t/deflatecompressor-threads-causing-memory-leak-in-tomcat/334769)

<div class="topic-metadata">

**Author:** [@KristianJ](https://discuss.elastic.co/u/KristianJ)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 9:06am UTC](https://discuss.elastic.co/t/deflatecompressor-threads-causing-memory-leak-in-tomcat/334769 "2023-05-31T09:06:53Z")

</div>

Hi, using ES 7.17.10 in a Tomcat container (9.0.x). When the application is shutdown there are two threads that are not removed, causing memory leaks from the DeflateCompressor class. In particular it would seem that t…

---

## [Upgrading 7.17 to 8.7 query search query not working](https://discuss.elastic.co/t/upgrading-7-17-to-8-7-query-search-query-not-working/334645)

<div class="topic-metadata">

**Author:** [@ak01](https://discuss.elastic.co/u/ak01)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 8:48am UTC](https://discuss.elastic.co/t/upgrading-7-17-to-8-7-query-search-query-not-working/334645 "2023-05-31T08:48:32Z")

</div>

What will be the new query this I was using in old version for search: const { body } = await Client.search({ index: this.tableName, body: { sort: sortingData, from: skip, size: l…

---

## [Access Elasticsearch with public IP](https://discuss.elastic.co/t/access-elasticsearch-with-public-ip/334743)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 8:48am UTC](https://discuss.elastic.co/t/access-elasticsearch-with-public-ip/334743 "2023-05-31T08:48:26Z")

</div>

Hello, I have my Elasticsearch running on my windows 10 server. I want to access it with \< my static public ip address \>:9200 I can access my elasticsearch from the server with: localhost:9200 \<my ipv4 address from …

---

## [엘라스틱서치 shrink와 forcemerge 를 진행하는 node 선출 algorithm이나 문서](https://discuss.elastic.co/t/shrink-forcemerge-node-algorithm/334752)

<div class="topic-metadata">

**Author:** [@bxl0107](https://discuss.elastic.co/u/bxl0107)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 6:46am UTC](https://discuss.elastic.co/t/shrink-forcemerge-node-algorithm/334752 "2023-05-31T06:46:05Z")

</div>

안녕하세요. elasticsearch 7.17.8을 사용 중입니다. ilm으로 hot-warm-cold index pahse도 함께 운영 중인데, forcemerge와 shink를 할 때, 용량이 부족한 node에서 진행하는 경우가 종종 있습니다. 용량은 wartermark로 설정해두었는데, shrink와 forcemerge를 진행하는 node를 선출하는 algorithm이나 문서가 있…

---

## [User needs to click 2 times for getting authenticated Azure OIDC](https://discuss.elastic.co/t/user-needs-to-click-2-times-for-getting-authenticated-azure-oidc/334748)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 6:34am UTC](https://discuss.elastic.co/t/user-needs-to-click-2-times-for-getting-authenticated-azure-oidc/334748 "2023-05-31T06:34:33Z")

</div>

Hi Team, We are running ELK stack version 7.17 with platinum license. We want to integrate Elasticsearch with Azure AD OIDC . We have done the configuration both at kibana and elasticsearch level. elasticsearch.yml xp…

---

## [Eland\_import\_hub\_model import error!](https://discuss.elastic.co/t/eland-import-hub-model-import-error/334701)

<div class="topic-metadata">

**Author:** [@laoyang360](https://discuss.elastic.co/u/laoyang360)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 11:51pm UTC](https://discuss.elastic.co/t/eland-import-hub-model-import-error/334701 "2023-05-30T23:51:48Z")

</div>

eland\_import\_hub\_model --url https://elastic:changeme@127.0.0.1:9200 --hub-model-id sentence-transformers/clip-ViT-B-32-multilingual-v1 --task-type text\_embedding --start --ca-certs /www/elasticsearch\_0806/elasticsearch-…

---

## [Usage pattern for ElasticsearchClient for multiple regions .NET](https://discuss.elastic.co/t/usage-pattern-for-elasticsearchclient-for-multiple-regions-net/334721)

<div class="topic-metadata">

**Author:** [@matthew\_gen](https://discuss.elastic.co/u/matthew_gen)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 11:47pm UTC](https://discuss.elastic.co/t/usage-pattern-for-elasticsearchclient-for-multiple-regions-net/334721 "2023-05-30T23:47:23Z")

</div>

I have two different elastic deployments that are in two different regions. Both clusters exist under the same elastic org account. Is the recommended usage pattern to create a singleton instance for each deployment? Or…

---

## [GROK Pattern syntax error, working in GROK debugger but not pipeline](https://discuss.elastic.co/t/grok-pattern-syntax-error-working-in-grok-debugger-but-not-pipeline/334707)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 7:51pm UTC](https://discuss.elastic.co/t/grok-pattern-syntax-error-working-in-grok-debugger-but-not-pipeline/334707 "2023-05-30T19:51:20Z")

</div>

Hey all. I'm trying to create a GROK pattern on a longer text message to break it into several fields. The error I'm having is when I try to make a field of a specific set of numbers from a larger set of numbers. For …

---

## [Elasticsearch exited unexpectedly](https://discuss.elastic.co/t/elasticsearch-exited-unexpectedly/334718)

<div class="topic-metadata">

**Author:** [@Long\_Nguyen](https://discuss.elastic.co/u/Long_Nguyen)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 7:32pm UTC](https://discuss.elastic.co/t/elasticsearch-exited-unexpectedly/334718 "2023-05-30T19:32:58Z")

</div>

Hello, I have a similar problem to this post. My problem is a bit different since I managed to start Elasticsearch the day before (before shutting it down). I have verified that all permission settings are correct. Her…

---

## [Keyword subfield mapping causes unexpected querying results](https://discuss.elastic.co/t/keyword-subfield-mapping-causes-unexpected-querying-results/334655)

<div class="topic-metadata">

**Author:** [@Hryhorii](https://discuss.elastic.co/u/Hryhorii)\
**Replies:** 6\
**Last updated:** [May 30, 2023, 6:38pm UTC](https://discuss.elastic.co/t/keyword-subfield-mapping-causes-unexpected-querying-results/334655 "2023-05-30T18:38:48Z")

</div>

We have an index mapping schema with a lot of text fields. To be able to sort and filter them we added keyword subfield mapping with lowercase normalizer. Here is a short part of our schema: { "mappings": { "dynam…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=250)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=252)
