# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=254

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 255

---

## [Failing to setup Elasticsearch dual node cluster](https://discuss.elastic.co/t/failing-to-setup-elasticsearch-dual-node-cluster/334298)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 9:15am UTC](https://discuss.elastic.co/t/failing-to-setup-elasticsearch-dual-node-cluster/334298 "2023-05-25T09:15:43Z")

</div>

I am trying to run a 2 node Elasticsearch cluster on different ec2 instances present in different regions. I using the following commands:- Command to run data node:- sudo docker run -it --pull=always --privileged --…

---

## [Taking snapshot of existing data and restore it after some disaster](https://discuss.elastic.co/t/taking-snapshot-of-existing-data-and-restore-it-after-some-disaster/334174)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 8:09am UTC](https://discuss.elastic.co/t/taking-snapshot-of-existing-data-and-restore-it-after-some-disaster/334174 "2023-05-25T08:09:26Z")

</div>

I am running one node which is a master node it receives data/logs from data nodes. This node has some indices that are created when I install this master node on a server. So the logs generated by master node and data …

---

## [Rolover policy for custom Index](https://discuss.elastic.co/t/rolover-policy-for-custom-index/333399)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 6:47am UTC](https://discuss.elastic.co/t/rolover-policy-for-custom-index/333399 "2023-05-25T06:47:08Z")

</div>

I got logs from winlogbeats, and i want to store them in custom indexes. So i need rollover policy for this indexes. here is part of logstash config file (output): output { if \[type\] == "winlogbeat" { elasticsearc…

---

## [Search\_phase\_execution\_exception error with all\_shared failes](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169)

<div class="topic-metadata">

**Author:** [@Kapildev](https://discuss.elastic.co/u/Kapildev)\
**Replies:** 15\
**Last updated:** [May 25, 2023, 6:18am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169 "2023-05-25T06:18:32Z")

</div>

hi team i am facing this search\_phase\_execution\_exception Please find the details. curl -X GET "localhost:9200/\_cluster/health?filter\_path=status,\*\_shards&pretty" { "status" : "red", "active\_primary\_shards" : 0, "…

---

## [elasticsearch build error](https://discuss.elastic.co/t/elasticsearch-build-error/334269)

<div class="topic-metadata">

**Author:** [@sand-hya](https://discuss.elastic.co/u/sand-hya)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 4:56am UTC](https://discuss.elastic.co/t/elasticsearch-build-error/334269 "2023-05-25T04:56:48Z")

</div>

Hello, I was running elasticsearch 7.6.0 version from source, and when I run ./gradlew assemble I am getting this error. Configure project :x-pack:qa:third-party:active-directory Tests for :x-pack:qa:third-party:acti…

---

## [I am getting the error in elasticsearch Rollup jobs](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262)

<div class="topic-metadata">

**Author:** [@daemon](https://discuss.elastic.co/u/daemon)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 12:32am UTC](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262 "2023-05-25T00:32:24Z")

</div>

I am getting the error in Kibana Rollup Jobs screen as shown in the image. Is there any solution?

---

## [Installing Elastic Cloud Enterprise Offline](https://discuss.elastic.co/t/installing-elastic-cloud-enterprise-offline/334240)

<div class="topic-metadata">

**Author:** [@geomandry](https://discuss.elastic.co/u/geomandry)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 4:25pm UTC](https://discuss.elastic.co/t/installing-elastic-cloud-enterprise-offline/334240 "2023-05-24T16:25:30Z")

</div>

There are too many documents! Can someone reply with the correct guides for installing Elastic Cloud Enterprise offline on a Linux box?

---

## [How can I handle typos in synonyms?](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141)

<div class="topic-metadata">

**Author:** [@gennadii](https://discuss.elastic.co/u/gennadii)\
**Replies:** 12\
**Last updated:** [May 24, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141 "2023-05-24T14:54:38Z")

</div>

I have synonyms in synonyms.txt - "auto, vehicle =\> car". In index I have a document with string "car" and an analyzer to handle synonyms. When you use "auto", for example, it will also return you results for "car". B…

---

## [Date Range filter is not working ? NEST C# MVC.NET](https://discuss.elastic.co/t/date-range-filter-is-not-working-nest-c-mvc-net/334129)

<div class="topic-metadata">

**Author:** [@Samer\_Abdelwahed](https://discuss.elastic.co/u/Samer_Abdelwahed)\
**Replies:** 5\
**Last updated:** [May 24, 2023, 2:48pm UTC](https://discuss.elastic.co/t/date-range-filter-is-not-working-nest-c-mvc-net/334129 "2023-05-24T14:48:28Z")

</div>

hi every one Why date Range filter is not working in my code: public static DateRangeQuery GetSearchFromDate(int DayFrom, int DayTo, int MonthFrom, int MonthTo, int YearFrom, int YearTo, string fieldName) …

---

## [Not able to stop the tasks in devtool (Kibana)](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:36pm UTC](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857 "2023-05-24T14:36:43Z")

</div>

1.Firstly, "delete by query" was run. it exhausted 100 % of disk space, then I tried POST /\_forcemerge after adding more disk space but this space is also getting consumed rapidly can I cancel the tasks which are …

---

## [Elasticsearch Get All data which has specified value for some of the field](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:22pm UTC](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201 "2023-05-24T14:22:57Z")

</div>

Hello, I have a query which gets data with project\_id=1 and project\_user\_id=1: GET /tweet\_user\_id\_index/\_search { "query": { "bool": { "should": \[ { "term": { "project\_id": { …

---

## ['\_source' filtering is slower than query without '\_source' field](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556)

<div class="topic-metadata">

**Author:** [@nadeem.akhter](https://discuss.elastic.co/u/nadeem.akhter)\
**Replies:** 7\
**Last updated:** [May 24, 2023, 2:17pm UTC](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556 "2023-05-24T14:17:17Z")

</div>

I have an elasticsearch instance with some data on it, and when trying queries on the data, it is slower to filter '\_source' in query than not mentioning the '\_source' key at all. Is there any specific reason for this? P…

---

## [Writing PySpark dataframe to Elastic Cloud (Cannot detect ES version)](https://discuss.elastic.co/t/writing-pyspark-dataframe-to-elastic-cloud-cannot-detect-es-version/334176)

<div class="topic-metadata">

**Author:** [@Dmytro\_Ostapchuk](https://discuss.elastic.co/u/Dmytro_Ostapchuk)\
**Replies:** 6\
**Last updated:** [May 24, 2023, 2:06pm UTC](https://discuss.elastic.co/t/writing-pyspark-dataframe-to-elastic-cloud-cannot-detect-es-version/334176 "2023-05-24T14:06:12Z")

</div>

Hi there! My use case Run PySpark job on EMR Serverless that reads data from S3 and writes it into Elastic cloud. Errors Cannot detect ES version - typically this happens if the network/Elasticsearch cluster is not a…

---

## [Need Watcher configuration and settings ElasticSearch yml](https://discuss.elastic.co/t/need-watcher-configuration-and-settings-elasticsearch-yml/330291)

<div class="topic-metadata">

**Author:** [@Praveen\_kr](https://discuss.elastic.co/u/Praveen_kr)\
**Replies:** 20\
**Last updated:** [May 24, 2023, 1:11pm UTC](https://discuss.elastic.co/t/need-watcher-configuration-and-settings-elasticsearch-yml/330291 "2023-05-24T13:11:06Z")

</div>

Hi Team, , Anyone one Could you please help me with the watcher configuration elasticsearch yml setup as we have 13 nodes I need to add the watcher settings to send a mail alert (outlook). Challenges what am facing her…

---

## [NiFi flow not able to write into Elasticsearch because of exceeding maximum shards](https://discuss.elastic.co/t/nifi-flow-not-able-to-write-into-elasticsearch-because-of-exceeding-maximum-shards/334204)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 10:52am UTC](https://discuss.elastic.co/t/nifi-flow-not-able-to-write-into-elasticsearch-because-of-exceeding-maximum-shards/334204 "2023-05-24T10:52:49Z")

</div>

I have only one node elasticsearch at my cluster. I'm trying to write into elasticsearch using PutElasticsearchHttp control at my NiFi flow but I get an error: 2023-05-24 07:00:17,347 ERROR \[Timer-Driven Process Thread-…

---

## [Cluster State Yellow: 2 shards initializing with multiple failed attempts: IllegalArgumentException \[ReleasableBytesStreamOutput cannot hold more than 2GB of data](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 5\
**Last updated:** [May 24, 2023, 9:43am UTC](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008 "2023-05-24T09:43:51Z")

</div>

For about a week, we are seeing the following error and cluster state yellow. On checking the \_cluster/state we get this - Elastic Search Version - 7.17 (Please let me know if more data is needed) {"state":"INITIALIZIN…

---

## [Service unavailable error code 503 all shard failed](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 11\
**Last updated:** [May 24, 2023, 9:30am UTC](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976 "2023-05-24T09:30:24Z")

</div>

Hello all, I got this problem showing that service unavailable {"statusCode":503,"error":"Service Unavailable","message":"\[all shards failed: search\_phase\_execution\_exception\\n\\tRoot causes:\\n\\t\\tno\_shard\_available\_act…

---

## [Same Query different results in .NET client](https://discuss.elastic.co/t/same-query-different-results-in-net-client/334180)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 9:25am UTC](https://discuss.elastic.co/t/same-query-different-results-in-net-client/334180 "2023-05-24T09:25:01Z")

</div>

Hello, I've been working on a query that can search a Document from my reservation index, These Reservations has a "SequenceId" on which thesearch query works with. This is the format of the ID: LLL-0000-000000 Produ…

---

## [How to show several docs with the same field?](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198)

<div class="topic-metadata">

**Author:** [@asebalo98](https://discuss.elastic.co/u/asebalo98)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 9:20am UTC](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198 "2023-05-24T09:20:52Z")

</div>

I have documents that have a ”CompanyId” field that can be the same for multiple documents. I want Elasticsearch to take up to 3 documents with the same “CompanyId” and the highest score, and then rank them in the overa…

---

## [Warm tier shards being allocated to data nodes](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136)

<div class="topic-metadata">

**Author:** [@Mirko\_Katunar](https://discuss.elastic.co/u/Mirko_Katunar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:18am UTC](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136 "2023-05-24T08:18:29Z")

</div>

Hello, I have a hot, warm architecture and 3 master nodes that are also data nodes. At some point Elastic started to allocate data stream shards that are in warm tier to master/data nodes. As plain data node can fill a…

---

## [How to find openssl Version](https://discuss.elastic.co/t/how-to-find-openssl-version/334038)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:08am UTC](https://discuss.elastic.co/t/how-to-find-openssl-version/334038 "2023-05-24T08:08:43Z")

</div>

Hello Team, Does Elasticsearch use openssl when using the SSL / TLS protocol? If so, where can I find the version of openssl? Regards Kannan P

---

## [Pytorch\_inference silenty disappear during reindex using pretrained machine learning model](https://discuss.elastic.co/t/pytorch-inference-silenty-disappear-during-reindex-using-pretrained-machine-learning-model/330896)

<div class="topic-metadata">

**Author:** [@tomotaka](https://discuss.elastic.co/u/tomotaka)\
**Replies:** 4\
**Last updated:** [May 24, 2023, 8:05am UTC](https://discuss.elastic.co/t/pytorch-inference-silenty-disappear-during-reindex-using-pretrained-machine-learning-model/330896 "2023-05-24T08:05:57Z")

</div>

We are planning to build a vector-based search application with pretrained machine learning model which is based on mBERT model. So now I wrote some code to check how Elasticsearch works and I found that pytorch\_inferen…

---

## [How to get list of documents created by reindex API in destination index](https://discuss.elastic.co/t/how-to-get-list-of-documents-created-by-reindex-api-in-destination-index/333540)

<div class="topic-metadata">

**Author:** [@Sumeet\_Koli](https://discuss.elastic.co/u/Sumeet_Koli)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 6:44am UTC](https://discuss.elastic.co/t/how-to-get-list-of-documents-created-by-reindex-api-in-destination-index/333540 "2023-05-24T06:44:27Z")

</div>

I have a query around the reindex API . Is there a way to get a list of all the documents created by the reindex API in the destination index? Context: I am using the reindex API to migrate a few indices from a remote …

---

## [Should clause within nested query not giving results](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167)

<div class="topic-metadata">

**Author:** [@discuss\_lipak](https://discuss.elastic.co/u/discuss_lipak)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 5:07am UTC](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167 "2023-05-24T05:07:40Z")

</div>

I am trying to retrieve a specific document with nested query on the identityLinks element. My requirement: either identityLinks.userId should match specific userid when identityLinks.type is "assignee" OR identityLin…

---

## [Using value from the returned documents and recalculating the score of the documents](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 4:10am UTC](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154 "2023-05-24T04:10:01Z")

</div>

Hi, I have a use case where I need to perform a search request, then use a value from the returned documents in recalculating the score. Below is the example of returned documents for my search request { \_score: 1.7, \_…

---

## [How to resolve failed requests to ES database after rebuilding the site](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365)

<div class="topic-metadata">

**Author:** [@stan4o](https://discuss.elastic.co/u/stan4o)\
**Replies:** 4\
**Last updated:** [May 24, 2023, 1:54am UTC](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365 "2023-05-24T01:54:11Z")

</div>

After our website (system) was rebuilt on a new server (Digital Ocean) all the requests to the Elastic search are failing = we cannot access the Elastic search. How to resolve this issue? I am not a programmer. This is w…

---

## [Elasticsearch memory data ratio recommendations for logging use case](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 6:15am UTC](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076 "2023-05-23T06:15:43Z")

</div>

Hello , I am planning to create an Elasticsearch Cluster for logging and metrics purpose I am using time-based indexes I want to calculate the optimal data nodes and shards this cluster requires The logs reach a maxi…

---

## [ElasticSearch NEST - Search Query Not Returning Expected Results](https://discuss.elastic.co/t/elasticsearch-nest-search-query-not-returning-expected-results/334160)

<div class="topic-metadata">

**Author:** [@mmobley](https://discuss.elastic.co/u/mmobley)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 10:12pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-search-query-not-returning-expected-results/334160 "2023-05-23T22:12:41Z")

</div>

I'm working on a project that searches parts using Elasticsearch and NEST (7.x). Here's my Model (adjusted for simplicity): \[ElasticsearchType\] public class PartInfo { public string Make { get; set; } public str…

---

## [How to increase queue capacity from 200 to 400?](https://discuss.elastic.co/t/how-to-increase-queue-capacity-from-200-to-400/333947)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 11\
**Last updated:** [May 23, 2023, 5:40pm UTC](https://discuss.elastic.co/t/how-to-increase-queue-capacity-from-200-to-400/333947 "2023-05-23T17:40:44Z")

</div>

How to increase queue capacity from 200 to 400?

---

## [Find 2 following ES entry](https://discuss.elastic.co/t/find-2-following-es-entry/334137)

<div class="topic-metadata">

**Author:** [@Kim2000](https://discuss.elastic.co/u/Kim2000)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 2:57pm UTC](https://discuss.elastic.co/t/find-2-following-es-entry/334137 "2023-05-23T14:57:02Z")

</div>

Hi, i have seen some info online about this and search about entity centric event but I can't figure out how to implement all of this. I am a newbie in the field. I am working with logstash and winlogbeat. I want to se…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=253)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=255)
