# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=253

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 254

---

## [Disable \_source field from indexing](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 6\
**Last updated:** [May 29, 2023, 2:47am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486 "2023-05-29T02:47:27Z")

</div>

Hi, To reduce the size of an indice I decide not to store \_source field in elasticsearch, but I got this error when I try to diable it. PUT /myindice/\_mapping { "properties": { "\_source": { "enabled": fals…

---

## [Alert index is not getting generated](https://discuss.elastic.co/t/alert-index-is-not-getting-generated/333924)

<div class="topic-metadata">

**Author:** [@Ibraheem\_Alharbi](https://discuss.elastic.co/u/Ibraheem_Alharbi)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 1:11am UTC](https://discuss.elastic.co/t/alert-index-is-not-getting-generated/333924 "2023-05-29T01:11:25Z")

</div>

I didn't receive alert in elastic even agent is installed Please I need help just view little hours before delivering my project

---

## [java.lang.IllegalArgumentException: Setting \[xpack.security.transport.ssl.keystore.path\] is a non-secure setting and must be stored inside elasticsearch.yml, but was found inside the Elasticsearch keystore](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700)

<div class="topic-metadata">

**Author:** [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 12:38am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700 "2023-05-29T00:38:18Z")

</div>

Why after run: ./bin/elasticsearch-certutil http folder master: total 12 -rwxr-xr-x 1 root elasticsearch 3620 May 17 17:24 http.p12 -rwxr-xr-x 1 root elasticsearch 1365 May 17 17:24 README.txt -rwxr-xr-x 1 root elast…

---

## [Using Terms filter query API via elastic .net client](https://discuss.elastic.co/t/using-terms-filter-query-api-via-elastic-net-client/334439)

<div class="topic-metadata">

**Author:** [@Sagar\_Kayasth2](https://discuss.elastic.co/u/Sagar_Kayasth2)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 1:50pm UTC](https://discuss.elastic.co/t/using-terms-filter-query-api-via-elastic-net-client/334439 "2023-05-26T13:50:38Z")

</div>

Hi I am currently trying to write a Terms Query via the Elastic.Clients.Elasticsearch 8.1.1 .NET client. I have to apply dynamic terms query filter for filtered categories Ids. If any category id not selected then not …

---

## [Cannot run service elastic](https://discuss.elastic.co/t/cannot-run-service-elastic/334478)

<div class="topic-metadata">

**Author:** [@Wiwatsapon\_Lertworas](https://discuss.elastic.co/u/Wiwatsapon_Lertworas)\
**Replies:** 3\
**Last updated:** [May 28, 2023, 11:20pm UTC](https://discuss.elastic.co/t/cannot-run-service-elastic/334478 "2023-05-28T23:20:31Z")

</div>

This is my error on run sudo service elasticsearch start May 27 03:07:57 elk-stack systemd-entrypoint\[354840\]: Exception in thread "main" java.lang.NullPointerException: Cannot invoke "org.apache.logging.log4j.core.con…

---

## [Jaro Winkler algorithm in elasticsearch](https://discuss.elastic.co/t/jaro-winkler-algorithm-in-elasticsearch/334505)

<div class="topic-metadata">

**Author:** [@Bakhodur\_Karomatov](https://discuss.elastic.co/u/Bakhodur_Karomatov)\
**Replies:** 4\
**Last updated:** [May 28, 2023, 11:18pm UTC](https://discuss.elastic.co/t/jaro-winkler-algorithm-in-elasticsearch/334505 "2023-05-28T23:18:32Z")

</div>

can i use jaro winkler algorithm in elasticsearch?

---

## [Elasticsearch Kuromoji plugin](https://discuss.elastic.co/t/elasticsearch-kuromoji-plugin/334361)

<div class="topic-metadata">

**Author:** [@a4amann](https://discuss.elastic.co/u/a4amann)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 6:25pm UTC](https://discuss.elastic.co/t/elasticsearch-kuromoji-plugin/334361 "2023-05-25T18:25:40Z")

</div>

What is the expected output when we run : PUT test { "settings": { "index": { "analysis": { "filter": { "kuromoji\_number": { "type": "kuromoji\_number" }, "ku…

---

## [Can not find mongodb log in Discover](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202)

<div class="topic-metadata">

**Author:** [@miladghasemi](https://discuss.elastic.co/u/miladghasemi)\
**Replies:** 2\
**Last updated:** [May 27, 2023, 10:05pm UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202 "2023-05-27T22:05:43Z")

</div>

Hi (sorry for my bad english) I'm enabled mongodb module in filebeat to send mongodb log into elasticsearch. Filebeat created dashboard, my log show in discover but when i want to search in Dicover,it not show \[event.o…

---

## [Understanding filters cache for filters nested inside should clause of parent boolean query](https://discuss.elastic.co/t/understanding-filters-cache-for-filters-nested-inside-should-clause-of-parent-boolean-query/334511)

<div class="topic-metadata">

**Author:** [@Sarthak\_Madaan](https://discuss.elastic.co/u/Sarthak_Madaan)\
**Replies:** 0\
**Last updated:** [May 27, 2023, 8:52pm UTC](https://discuss.elastic.co/t/understanding-filters-cache-for-filters-nested-inside-should-clause-of-parent-boolean-query/334511 "2023-05-27T20:52:39Z")

</div>

{ "from": 0, "size": 2, "timeout": "10ms", "query": { "bool": { "should": \[ { "bool": { "filter": \[ …

---

## [Comparing and Unifying fields across documents](https://discuss.elastic.co/t/comparing-and-unifying-fields-across-documents/334355)

<div class="topic-metadata">

**Author:** [@obhive](https://discuss.elastic.co/u/obhive)\
**Replies:** 4\
**Last updated:** [May 26, 2023, 8:05pm UTC](https://discuss.elastic.co/t/comparing-and-unifying-fields-across-documents/334355 "2023-05-26T20:05:50Z")

</div>

Hello! I have an Elasticsearch Index, where a lot of request calls are being logged from our Company's API. So all the documents have "send" and "response" objects. The content of these objects changes based on the API …

---

## [Problem of connecting python client with elasticsearch](https://discuss.elastic.co/t/problem-of-connecting-python-client-with-elasticsearch/334437)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 12\
**Last updated:** [May 26, 2023, 2:10pm UTC](https://discuss.elastic.co/t/problem-of-connecting-python-client-with-elasticsearch/334437 "2023-05-26T14:10:12Z")

</div>

I am unable to connect with elastic using python client The code which run with no issue is from elasticsearch import Elasticsearch es = Elasticsearch(\['http://\<your\_ip\_address\>:\<your\_port\>'\]) (I use my ip and port w…

---

## [ILM keep rolling over empty indexes](https://discuss.elastic.co/t/ilm-keep-rolling-over-empty-indexes/332480)

<div class="topic-metadata">

**Author:** [@Adam\_Lin](https://discuss.elastic.co/u/Adam_Lin)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 1:52pm UTC](https://discuss.elastic.co/t/ilm-keep-rolling-over-empty-indexes/332480 "2023-05-26T13:52:39Z")

</div>

Hi according to the following release note, since 8.5.3, ILM won't rollover the empty index by default. I'm using the elk server v8.6.0, and with the ILM policy { "testpolicy" : { "version" : 2, "modified\_d…

---

## [Elasticsearch dynamic date field mapping](https://discuss.elastic.co/t/elasticsearch-dynamic-date-field-mapping/334436)

<div class="topic-metadata">

**Author:** [@riani.oussama](https://discuss.elastic.co/u/riani.oussama)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 1:25pm UTC](https://discuss.elastic.co/t/elasticsearch-dynamic-date-field-mapping/334436 "2023-05-26T13:25:26Z")

</div>

Hi, I have a problem in handling dates in my indexes. My indexes were created automatically from my application. In one index the field "CreationDate" is of type text (Tue May 23 10:55:12 CEST 2023), in another index …

---

## [I lose all my data when master node restarts](https://discuss.elastic.co/t/i-lose-all-my-data-when-master-node-restarts/334410)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 7\
**Last updated:** [May 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/i-lose-all-my-data-when-master-node-restarts/334410 "2023-05-26T12:54:45Z")

</div>

Hi, I have EKF stack on Kubernetes, now I have 1 client node, 1 master node and 3 data nodes. When my master node restarts I lose all the data and indices that I have and my master's UUID changes, so I need to restart a…

---

## [Mapping parser exception](https://discuss.elastic.co/t/mapping-parser-exception/334322)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 12:06pm UTC](https://discuss.elastic.co/t/mapping-parser-exception/334322 "2023-05-26T12:06:07Z")

</div>

I am using Elasticsearch 8.7.0....... While inserting any document I am getting this kind of error. In previously versions which includes the field path where got and error now It Shows only RequestError(400, 'mapper\_p…

---

## [Slower Perfomance with Elaticsearch cluster in kubernetes compared to Docker](https://discuss.elastic.co/t/slower-perfomance-with-elaticsearch-cluster-in-kubernetes-compared-to-docker/332395)

<div class="topic-metadata">

**Author:** [@samdevops](https://discuss.elastic.co/u/samdevops)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 9:23am UTC](https://discuss.elastic.co/t/slower-perfomance-with-elaticsearch-cluster-in-kubernetes-compared-to-docker/332395 "2023-05-26T09:23:27Z")

</div>

Hi All, I've had the same topic opened before but it seems like our issue has returned after implementing the feedback and testing once more. As mentioned in the title we seem to notice much slower performance when our …

---

## [Can I take backup of indices from one cluster and restore it to another cluster](https://discuss.elastic.co/t/can-i-take-backup-of-indices-from-one-cluster-and-restore-it-to-another-cluster/334387)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 14\
**Last updated:** [May 26, 2023, 8:55am UTC](https://discuss.elastic.co/t/can-i-take-backup-of-indices-from-one-cluster-and-restore-it-to-another-cluster/334387 "2023-05-26T08:55:37Z")

</div>

Can I take backup of indices from one cluster and restore it to another cluster by simply copying the snapshot/backup repository folder and sending it to another cluster and from there I will perform restore operation is…

---

## [Taking backup on one system and restoring it in another system](https://discuss.elastic.co/t/taking-backup-on-one-system-and-restoring-it-in-another-system/334392)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 6:22am UTC](https://discuss.elastic.co/t/taking-backup-on-one-system-and-restoring-it-in-another-system/334392 "2023-05-26T06:22:41Z")

</div>

I have Elasticsearch running on one system where I take backup of indices regularly into a snapshot, but these indices(snapshot) I want to restore to different system. How can I proceed. I am unable to find clear answer…

---

## [ELK version 8.7.0 with mysql using docker compose](https://discuss.elastic.co/t/elk-version-8-7-0-with-mysql-using-docker-compose/333871)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 13\
**Last updated:** [May 25, 2023, 6:36pm UTC](https://discuss.elastic.co/t/elk-version-8-7-0-with-mysql-using-docker-compose/333871 "2023-05-25T18:36:55Z")

</div>

hi every one I want to run elastic and kibana and logstash I use docker compose this is the docker compose file yml : version: '3' services: mysql: container\_name: mysql hostname: mysql image: 'mysql' …

---

## [Searching using query string with variable clauses](https://discuss.elastic.co/t/searching-using-query-string-with-variable-clauses/333756)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 7\
**Last updated:** [May 25, 2023, 4:48pm UTC](https://discuss.elastic.co/t/searching-using-query-string-with-variable-clauses/333756 "2023-05-25T16:48:06Z")

</div>

Hi everyone. I'm trying to make a template wich I can use to search through several fields by one word (using query string). But now I need to add a clause which will get a variable in a query (date). How can I combine …

---

## [How to list non empty field names based on search criteria on elasticsearch](https://discuss.elastic.co/t/how-to-list-non-empty-field-names-based-on-search-criteria-on-elasticsearch/334349)

<div class="topic-metadata">

**Author:** [@ehmd96](https://discuss.elastic.co/u/ehmd96)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:07pm UTC](https://discuss.elastic.co/t/how-to-list-non-empty-field-names-based-on-search-criteria-on-elasticsearch/334349 "2023-05-25T16:07:29Z")

</div>

we are encountering an issue on elasticsearch trying to display fields based on certain search criteria. We have an index with a "payload" field which has multiple properties What we are trying to do is to request t…

---

## [Documents being deleted after BulkRequest indexing](https://discuss.elastic.co/t/documents-being-deleted-after-bulkrequest-indexing/333674)

<div class="topic-metadata">

**Author:** [@vivss](https://discuss.elastic.co/u/vivss)\
**Replies:** 12\
**Last updated:** [May 25, 2023, 3:06pm UTC](https://discuss.elastic.co/t/documents-being-deleted-after-bulkrequest-indexing/333674 "2023-05-25T15:06:35Z")

</div>

Hi all, We are using Elasticsearch 7.17.7 and indexing documents via BulkRequest in Java API Client, and we noticed that many documents are being deleted after indexing. We retrieve the records from a Postgresql databas…

---

## [API Key delete by mistake in stack Management](https://discuss.elastic.co/t/api-key-delete-by-mistake-in-stack-management/334304)

<div class="topic-metadata">

**Author:** [@maniacci](https://discuss.elastic.co/u/maniacci)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 1:04pm UTC](https://discuss.elastic.co/t/api-key-delete-by-mistake-in-stack-management/334304 "2023-05-25T13:04:11Z")

</div>

Hi , I have by mistake deleted API keys (while doing some manipulations following a test to add a Linux server on the SIEM). I would like to know if it is possible to restore his keys? I have Veeam backups . I would …

---

## [Elasticsearch 7.17.10 indexing bottleneck on i3.2xlarge and d3.2xlarge nodes in EKS](https://discuss.elastic.co/t/elasticsearch-7-17-10-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks/333503)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 52\
**Last updated:** [May 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-10-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks/333503 "2023-05-25T13:03:25Z")

</div>

My 7.17.10 cluster is hosted in AWS EKS and is managed by ECK. It appears to top out at around 90k documents indexed per second (including replicas) per second and I haven't been able to identify the bottleneck. Adding m…

---

## [Pass raw search object to \`SearchAsync\` Elastic.Clients.Elasticsearch 8.1.1 .NET](https://discuss.elastic.co/t/pass-raw-search-object-to-searchasync-elastic-clients-elasticsearch-8-1-1-net/334311)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:10am UTC](https://discuss.elastic.co/t/pass-raw-search-object-to-searchasync-elastic-clients-elasticsearch-8-1-1-net/334311 "2023-05-25T11:10:55Z")

</div>

I am trying to implement an API, which allows users to dynamically query an Elasticsearch index. The API should therefore act like a "proxy" between the user and Elasticsearch (the API performs additional operations alon…

---

## [Can U help with optimal search method?](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:03am UTC](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310 "2023-05-25T11:03:43Z")

</div>

Can you guys show the best way to find users by first and last name or by full name. Also, when the user enters a name, I want to search for that name in both Cyrillic and Latin. Any links, ideas? Client could enter N…

---

## [Polygon Self-Intersecting when there is minimal wrapping at -180/180 failing](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065)

<div class="topic-metadata">

**Author:** [@Craig\_Roush](https://discuss.elastic.co/u/Craig_Roush)\
**Replies:** 13\
**Last updated:** [May 25, 2023, 10:05am UTC](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065 "2023-05-25T10:05:31Z")

</div>

I am receiving a polygon-self intersecting error when I have a polygon that barely wraps across 180 to -180: I have a simple mapping for a index setup as: index\_mapping = { "time": { "type": "da…

---

## [How to extract all log sources in ELK?](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 6\
**Last updated:** [May 25, 2023, 9:45am UTC](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188 "2023-05-25T09:45:41Z")

</div>

Hi team, I'm new in elastic stack , please i need a procedure how to extract all the source logs IP and status if possible, for example i have 10 servers linux redhat integrated in elastic with auditbeat and i have 10 w…

---

## [The analyser in mapping is not getting applied to field](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 9:38am UTC](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286 "2023-05-25T09:38:44Z")

</div>

This is the mapping and settings { "blogs\_fixed2": { "aliases": {}, "mappings": { "\_meta": { "created\_by": "Sheereen Hamza KV" }, "properties": { "@timestamp": { "t…

---

## [Elastic search Client API](https://discuss.elastic.co/t/elastic-search-client-api/334288)

<div class="topic-metadata">

**Author:** [@Gururaj\_Shivananda](https://discuss.elastic.co/u/Gururaj_Shivananda)\
**Replies:** 7\
**Last updated:** [May 25, 2023, 9:16am UTC](https://discuss.elastic.co/t/elastic-search-client-api/334288 "2023-05-25T09:16:26Z")

</div>

Hi we are using Elastic Search client API to read/write from OpenSearch. This is part of commercial service provided to customer. How would SSPL license Apply here.

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=252)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=254)
