# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=252

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 253

---

## [Elastic 8.8.0 - Current license is non-compliant for search application and behavioral analytics](https://discuss.elastic.co/t/elastic-8-8-0-current-license-is-non-compliant-for-search-application-and-behavioral-analytics/334712)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 6:22pm UTC](https://discuss.elastic.co/t/elastic-8-8-0-current-license-is-non-compliant-for-search-application-and-behavioral-analytics/334712 "2023-05-30T18:22:37Z")

</div>

Elasticsearch Log been polluted with following message Failed to get search application count to include in Enterprise Search usage java.util.concurrent.ExecutionException: org.elasticsearch.ElasticsearchSecurityExcepti…

---

## [Debian Package Upgrade to 8.8.0 - Multiple Errors](https://discuss.elastic.co/t/debian-package-upgrade-to-8-8-0-multiple-errors/334376)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 4\
**Last updated:** [May 30, 2023, 6:13pm UTC](https://discuss.elastic.co/t/debian-package-upgrade-to-8-8-0-multiple-errors/334376 "2023-05-30T18:13:54Z")

</div>

Hi Guys, Standard deb upgrade, getting a few errors in the Elasticsearch Log and when signing into Kibana UI.. \[2023-05-26T01:43:44,928\]\[WARN \]\[o.e.x.a.EnterpriseSearchUsageTransportAction\] \[IsaacAsimov\] Failed to get …

---

## [Reduce number of segments to speed up ANN search](https://discuss.elastic.co/t/reduce-number-of-segments-to-speed-up-ann-search/330584)

<div class="topic-metadata">

**Author:** [@Therese\_Persson](https://discuss.elastic.co/u/Therese_Persson)\
**Replies:** 8\
**Last updated:** [May 30, 2023, 5:43pm UTC](https://discuss.elastic.co/t/reduce-number-of-segments-to-speed-up-ann-search/330584 "2023-05-30T17:43:54Z")

</div>

Hi, We have an ES index with a dense\_vector field containing approx. 2.5 M documents which we use for ANN search. The embedding dimension is 512. We experience a very uneven search performance, it often takes \>20 s for …

---

## [When I try to import a model using eland, I get an error!](https://discuss.elastic.co/t/when-i-try-to-import-a-model-using-eland-i-get-an-error/334531)

<div class="topic-metadata">

**Author:** [@laoyang360](https://discuss.elastic.co/u/laoyang360)\
**Replies:** 3\
**Last updated:** [May 30, 2023, 4:44pm UTC](https://discuss.elastic.co/t/when-i-try-to-import-a-model-using-eland-i-get-an-error/334531 "2023-05-30T16:44:18Z")

</div>

\[root@-centos www\]# eland\_import\_hub\_model Traceback (most recent call last): File "/usr/local/bin/eland\_import\_hub\_model", line 34, in \<module\> from elastic\_transport.client\_utils import DEFAULT File "/usr/loca…

---

## [Migrate .security index for migrating users?](https://discuss.elastic.co/t/migrate-security-index-for-migrating-users/333917)

<div class="topic-metadata">

**Author:** [@termcap](https://discuss.elastic.co/u/termcap)\
**Replies:** 0\
**Last updated:** [May 20, 2023, 5:29pm UTC](https://discuss.elastic.co/t/migrate-security-index-for-migrating-users/333917 "2023-05-20T17:29:18Z")

</div>

Hi, I have setup a new cluster 8.7 and I want to migrate users from my old cluster 7.x into this cluster so that I do not have to re-create the users and setup new passwords. I did some looking around and it appears th…

---

## [How to write Kibana update query in java](https://discuss.elastic.co/t/how-to-write-kibana-update-query-in-java/333662)

<div class="topic-metadata">

**Author:** [@sarthik](https://discuss.elastic.co/u/sarthik)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 1:28pm UTC](https://discuss.elastic.co/t/how-to-write-kibana-update-query-in-java/333662 "2023-05-17T13:28:08Z")

</div>

Hi team, My requirement is to update a document for a particular index. I have constructed the query in Kibana using KQL, but I am unable to convert the same into java API client, so that I can call from my java code. …

---

## [Data not showing for wazuh agents](https://discuss.elastic.co/t/data-not-showing-for-wazuh-agents/333448)

<div class="topic-metadata">

**Author:** [@uahmad](https://discuss.elastic.co/u/uahmad)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 12:48pm UTC](https://discuss.elastic.co/t/data-not-showing-for-wazuh-agents/333448 "2023-05-30T12:48:34Z")

</div>

Hello, I am facing issue where data for wazuh agents is not being shown. Elasticsearch throws the following error: \[2023-05-15T10:52:45,968\]\[WARN \]\[o.e.x.t.t.TransformIndexer\] \[elasticsearch\] \[endpoint.metadata\_united…

---

## [Monitoring indices configuration](https://discuss.elastic.co/t/monitoring-indices-configuration/334661)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 12:44pm UTC](https://discuss.elastic.co/t/monitoring-indices-configuration/334661 "2023-05-30T12:44:56Z")

</div>

Hi all! We are running ECK and we are trying to implement the best practices (metrics/metricbeat) and use a small dedicated cluster for monitoring. Before separation, with monitoring enabled, we had a 7 special indices…

---

## [Synonym order with unique filter breaks search](https://discuss.elastic.co/t/synonym-order-with-unique-filter-breaks-search/334647)

<div class="topic-metadata">

**Author:** [@kuseman](https://discuss.elastic.co/u/kuseman)\
**Replies:** 3\
**Last updated:** [May 30, 2023, 10:58am UTC](https://discuss.elastic.co/t/synonym-order-with-unique-filter-breaks-search/334647 "2023-05-30T10:58:28Z")

</div>

Hi, have a weird issue with synonyms along with a unique token filter that I cannot get my head around. MVP: Settings: { "settings": { "index": { …

---

## [Retrieve data directly from Elasticsearch index in React App](https://discuss.elastic.co/t/retrieve-data-directly-from-elasticsearch-index-in-react-app/334365)

<div class="topic-metadata">

**Author:** [@Thomas\_Makrigiannis](https://discuss.elastic.co/u/Thomas_Makrigiannis)\
**Replies:** 3\
**Last updated:** [May 30, 2023, 10:19am UTC](https://discuss.elastic.co/t/retrieve-data-directly-from-elasticsearch-index-in-react-app/334365 "2023-05-30T10:19:09Z")

</div>

Hi, everyone. I am new to elasticsearch and I really need your help. i have construced a react app that simulates a search engine. My app uses node.js and express. I have built both a server and a client. In the app I r…

---

## [Can we use Approximate kNN algorithm other than Hierarchical Navigable Small World Algorithm?](https://discuss.elastic.co/t/can-we-use-approximate-knn-algorithm-other-than-hierarchical-navigable-small-world-algorithm/333533)

<div class="topic-metadata">

**Author:** [@hikarut](https://discuss.elastic.co/u/hikarut)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 9:48am UTC](https://discuss.elastic.co/t/can-we-use-approximate-knn-algorithm-other-than-hierarchical-navigable-small-world-algorithm/333533 "2023-05-30T09:48:15Z")

</div>

Hi All, We have to construct a search system which contains 30 millions+ dense vectors. However, Naive kNN algorithm can not be applied to this scale of data. And, Hierarchical Navigable Small World Algorithm, which e…

---

## [Impact on cluster after expiration of Platinum license](https://discuss.elastic.co/t/impact-on-cluster-after-expiration-of-platinum-license/334656)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 1\
**Last updated:** [May 30, 2023, 9:30am UTC](https://discuss.elastic.co/t/impact-on-cluster-after-expiration-of-platinum-license/334656 "2023-05-30T09:30:33Z")

</div>

Hi, Currently we have a cluster of 3 Elasticsearch nodes with Platinum license, just I wanted to know if my platinum subscription expires and downgrade to basic version, what would be the impact in the Elasticsearch clu…

---

## [Elasticsearch not working after Upgrading from version 7.17 to 8.5.1 (Using Helm Chart)](https://discuss.elastic.co/t/elasticsearch-not-working-after-upgrading-from-version-7-17-to-8-5-1-using-helm-chart/334639)

<div class="topic-metadata">

**Author:** [@devbrat9415](https://discuss.elastic.co/u/devbrat9415)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 6:30am UTC](https://discuss.elastic.co/t/elasticsearch-not-working-after-upgrading-from-version-7-17-to-8-5-1-using-helm-chart/334639 "2023-05-30T06:30:46Z")

</div>

We are upgrading Elasticsearch version 7.17 to 8.5.1 to Kubernetes along with logstash and Kibana . We don't necessary want to remove PVC, because it will lead to a data loss. While upgrading we continuously getting ERRO…

---

## [{"statusCode":429,"message":"circuit\_breaking\_exception: \[circuit\_breaking\_exception\] Reason: \[parent\] Data too large, data for \[\<http\_request\>\] would be \[1052991986/1004.2mb\], which is larger than the limit of \[805306368/768mb\], real usage: \[1052991848/1](https://discuss.elastic.co/t/statuscode-429-message-circuit-breaking-exception-circuit-breaking-exception-reason-parent-data-too-large-data-for-http-request-would-be-1052991986-1004-2mb-which-is-larger-than-the-limit-of-805306368-768mb-real-usage-1052991848-1/334343)

<div class="topic-metadata">

**Author:** [@purna](https://discuss.elastic.co/u/purna)\
**Replies:** 10\
**Last updated:** [May 30, 2023, 6:05am UTC](https://discuss.elastic.co/t/statuscode-429-message-circuit-breaking-exception-circuit-breaking-exception-reason-parent-data-too-large-data-for-http-request-would-be-1052991986-1004-2mb-which-is-larger-than-the-limit-of-805306368-768mb-real-usage-1052991848-1/334343 "2023-05-30T06:05:12Z")

</div>

please help me , How to resloved this issue

---

## [Word\_delimiter hyphen remove but retain](https://discuss.elastic.co/t/word-delimiter-hyphen-remove-but-retain/333074)

<div class="topic-metadata">

**Author:** [@Damian](https://discuss.elastic.co/u/Damian)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 4:40am UTC](https://discuss.elastic.co/t/word-delimiter-hyphen-remove-but-retain/333074 "2023-05-30T04:40:40Z")

</div>

Hi I would like to retain the hyphen in between the words but remove at the beginning or at the end of the word. For word -ecigarette I would like the hyphen to be removed and search for "ecigarette" return a result, h…

---

## [What are least and most usage estimates](https://discuss.elastic.co/t/what-are-least-and-most-usage-estimates/334630)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 2\
**Last updated:** [May 30, 2023, 3:25am UTC](https://discuss.elastic.co/t/what-are-least-and-most-usage-estimates/334630 "2023-05-30T03:25:11Z")

</div>

Hello everyone, The node stats API returns least\_usage\_estimate and most\_usage\_estimate. What are these, and how are they different from total? Thank you

---

## [How to install X-PACK in elasticsearch-5.4.3 in windows](https://discuss.elastic.co/t/how-to-install-x-pack-in-elasticsearch-5-4-3-in-windows/334628)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 6\
**Last updated:** [May 30, 2023, 2:19am UTC](https://discuss.elastic.co/t/how-to-install-x-pack-in-elasticsearch-5-4-3-in-windows/334628 "2023-05-30T02:19:52Z")

</div>

how to install and configure x-pack in elasticsearch-5.4.3 ? os: widows server

---

## [Elastic Search - Limit of total fields \[1000\] - How to set in Docker compose file?](https://discuss.elastic.co/t/elastic-search-limit-of-total-fields-1000-how-to-set-in-docker-compose-file/334582)

<div class="topic-metadata">

**Author:** [@Eduardo\_Montes](https://discuss.elastic.co/u/Eduardo_Montes)\
**Replies:** 4\
**Last updated:** [May 30, 2023, 1:04am UTC](https://discuss.elastic.co/t/elastic-search-limit-of-total-fields-1000-how-to-set-in-docker-compose-file/334582 "2023-05-30T01:04:59Z")

</div>

I use ES 6.24 what is running via Docker image configured in docker compose file. After some time I got error Limit of total fields \[1000\] in index my\_index has been exceeded. I tried to use set this limit in environme…

---

## [The security settings of 8+ versions is too too complicate](https://discuss.elastic.co/t/the-security-settings-of-8-versions-is-too-too-complicate/334546)

<div class="topic-metadata">

**Author:** [@Ansen\_J](https://discuss.elastic.co/u/Ansen_J)\
**Replies:** 4\
**Last updated:** [May 30, 2023, 12:55am UTC](https://discuss.elastic.co/t/the-security-settings-of-8-versions-is-too-too-complicate/334546 "2023-05-30T00:55:06Z")

</div>

I installed es and kibana through docker , after a period , the kibana cannot connect es , The security settings is too complicate , after weeks of reading docs and search from google, does not know what going wrong. t…

---

## [How do i get this product to integrate with Google Cloud?](https://discuss.elastic.co/t/how-do-i-get-this-product-to-integrate-with-google-cloud/334537)

<div class="topic-metadata">

**Author:** [@ezaidepc](https://discuss.elastic.co/u/ezaidepc)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 11:30pm UTC](https://discuss.elastic.co/t/how-do-i-get-this-product-to-integrate-with-google-cloud/334537 "2023-05-29T23:30:45Z")

</div>

I am trying to add the Elasticsearch Service to my Google Cloud product and it takes me to a page to set up an account but I already have an account, so I can't set up an account, however, there is not an option to simpl…

---

## [How to use Elasticsearch delete\_by\_query API's in watcher webhook. Its failing on Authentication](https://discuss.elastic.co/t/how-to-use-elasticsearch-delete-by-query-apis-in-watcher-webhook-its-failing-on-authentication/334415)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-to-use-elasticsearch-delete-by-query-apis-in-watcher-webhook-its-failing-on-authentication/334415 "2023-05-29T22:16:41Z")

</div>

Hi Team, I am using delete\_by\_query in elasticsearch watcher action as webhook as below. "actions": { "my\_api": { "webhook": { "scheme": "https", "host": "130.8.1.198", "port": 9200, …

---

## [Kubernetes deployment - 3rd Stateful set replica always fail with java.lang.ClassNotFoundException: com.fasterxml.jackson.core.io.JsonStringEncoder](https://discuss.elastic.co/t/kubernetes-deployment-3rd-stateful-set-replica-always-fail-with-java-lang-classnotfoundexception-com-fasterxml-jackson-core-io-jsonstringencoder/334613)

<div class="topic-metadata">

**Author:** [@kolslearningid](https://discuss.elastic.co/u/kolslearningid)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 6:37pm UTC](https://discuss.elastic.co/t/kubernetes-deployment-3rd-stateful-set-replica-always-fail-with-java-lang-classnotfoundexception-com-fasterxml-jackson-core-io-jsonstringencoder/334613 "2023-05-29T18:37:07Z")

</div>

I am trying to build a three replica stateful set Elasticsearch cluster in EKS using helm chart. When I deploy with one or two replicas the PODs are getting created and attached in the cluster mode. When I increase the r…

---

## [Elasticsearch Query: Array field length mismatch](https://discuss.elastic.co/t/elasticsearch-query-array-field-length-mismatch/334551)

<div class="topic-metadata">

**Author:** [@kusumakarb](https://discuss.elastic.co/u/kusumakarb)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-query-array-field-length-mismatch/334551 "2023-05-29T14:04:34Z")

</div>

Trying out the following query to get the values of 2 array fields and their corresponding lengths, the array values and the lengths don't match Query: GET my\_index/\_search { "\_source": \["file\_types", "link\_to\_file"\]…

---

## [It takes a long time to query the keyword field](https://discuss.elastic.co/t/it-takes-a-long-time-to-query-the-keyword-field/333297)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 3\
**Last updated:** [May 29, 2023, 1:03pm UTC](https://discuss.elastic.co/t/it-takes-a-long-time-to-query-the-keyword-field/333297 "2023-05-29T13:03:26Z")

</div>

Hi, I have a question regarding query performance. What is the difference between querying the normal field and querying the keyword field? I did a test. The data types of the fields I am querying are as follows. …

---

## [JWT Realms not working using basic license](https://discuss.elastic.co/t/jwt-realms-not-working-using-basic-license/334580)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 11:04am UTC](https://discuss.elastic.co/t/jwt-realms-not-working-using-basic-license/334580 "2023-05-29T11:04:45Z")

</div>

We are using basic license of elasticsearch 8.7.1 and want to implement JWT authentication, but when we add Realm for JWT authentication using token type = access-token getting following warning in log file: \[WARN \]\[o.e…

---

## [The \[dot\_product\] similarity can only be used with unit-length vectors. Preview of invalid vector: \[-1.8447683, 0.20424768, 0.53359556, 1.1610416, 0.905799, ...\]](https://discuss.elastic.co/t/the-dot-product-similarity-can-only-be-used-with-unit-length-vectors-preview-of-invalid-vector-1-8447683-0-20424768-0-53359556-1-1610416-0-905799/334566)

<div class="topic-metadata">

**Author:** [@zheng\_zhiqiang](https://discuss.elastic.co/u/zheng_zhiqiang)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 9:13am UTC](https://discuss.elastic.co/t/the-dot-product-similarity-can-only-be-used-with-unit-length-vectors-preview-of-invalid-vector-1-8447683-0-20424768-0-53359556-1-1610416-0-905799/334566 "2023-05-29T09:13:20Z")

</div>

I create a deployment in elastic cloud with reference ChatGPT and Elasticsearch: OpenAI meets private data. The only difference is that I chose a Chinese model for machine learning. However, I encountered the following …

---

## [Converting epoch time format to datetime format using script](https://discuss.elastic.co/t/converting-epoch-time-format-to-datetime-format-using-script/334560)

<div class="topic-metadata">

**Author:** [@kashimmirza](https://discuss.elastic.co/u/kashimmirza)\
**Replies:** 2\
**Last updated:** [May 29, 2023, 8:33am UTC](https://discuss.elastic.co/t/converting-epoch-time-format-to-datetime-format-using-script/334560 "2023-05-29T08:33:24Z")

</div>

In elastic searach there is a index name personalprofile11 and there is a field named createdDate in epoch format , integer data type. but I want to make it datetime format query Datehistogramaggregation and using that …

---

## [Setting max\_analyzed\_offset permanently for an index](https://discuss.elastic.co/t/setting-max-analyzed-offset-permanently-for-an-index/334470)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [May 29, 2023, 7:48am UTC](https://discuss.elastic.co/t/setting-max-analyzed-offset-permanently-for-an-index/334470 "2023-05-29T07:48:56Z")

</div>

Hi All, We are using ELK stack 7.13.2 I came across an error while displaying an index in dashboard as follows: The length \[2134324\] of field \[additionalInfo\] in doc\[100496\]/index\[370844-2023.05.24\] exceeds the \[index…

---

## [How to make elasticdump faster](https://discuss.elastic.co/t/how-to-make-elasticdump-faster/334380)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-make-elasticdump-faster/334380 "2023-05-29T07:24:05Z")

</div>

Hi Elastic Community members, I would like to know, Is there any way to speed up the elastic-dump. I need to migrate data from one elasticsearch to another elasticsearch cluster. I noticed for 1GB of data is taking aro…

---

## [ElasticSearch - search\_after pagination sort](https://discuss.elastic.co/t/elasticsearch-search-after-pagination-sort/334502)

<div class="topic-metadata">

**Author:** [@VJ052023](https://discuss.elastic.co/u/VJ052023)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 4:52am UTC](https://discuss.elastic.co/t/elasticsearch-search-after-pagination-sort/334502 "2023-05-29T04:52:32Z")

</div>

I am trying to fetch results from Elasticsearch API using search\_after for pagination. However, in order to iterate to the subsequent data I am using a sort in the request Body of the API call as shown below "sort": \[ …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=251)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=253)
