# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=255

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 256

---

## [: max virtual memory areas vm.max\_map\_count \[65530\] is too low, increase to at least \[262144\]](https://discuss.elastic.co/t/max-virtual-memory-areas-vm-max-map-count-65530-is-too-low-increase-to-at-least-262144/334132)

<div class="topic-metadata">

**Author:** [@Ramon\_Moraga](https://discuss.elastic.co/u/Ramon_Moraga)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 2:16pm UTC](https://discuss.elastic.co/t/max-virtual-memory-areas-vm-max-map-count-65530-is-too-low-increase-to-at-least-262144/334132 "2023-05-23T14:16:10Z")

</div>

I'm trying to mount elk in an aws ecs fargate container but I can't put the vm.max\_map\_count on it. And I get this error (bootstrap check failure \[1\] of \[1\]: max virtual memory areas vm.max\_map\_count \[65530\] is too low ,…

---

## [ES Transactions](https://discuss.elastic.co/t/es-transactions/334093)

<div class="topic-metadata">

**Author:** [@sajeeda](https://discuss.elastic.co/u/sajeeda)\
**Replies:** 6\
**Last updated:** [May 23, 2023, 2:10pm UTC](https://discuss.elastic.co/t/es-transactions/334093 "2023-05-23T14:10:16Z")

</div>

Hi All, I am trying to do an partial update on the document for 7 different process. i have been getting version control conflict. Is there a way where ES supports transactions so that there is no data loss. I do not wa…

---

## [Authentication using apikey failed](https://discuss.elastic.co/t/authentication-using-apikey-failed/333244)

<div class="topic-metadata">

**Author:** [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 2:08pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed/333244 "2023-05-23T14:08:21Z")

</div>

Hi I have a cluster with 3 instances ( 1 Master 2 Data Nodes ) Recenty looking into my cluster, i found a lot of warnings about Authentication using apikey failed on specific apikey id EjkscocB14\*\*\*\*\*\*\*\* I try search…

---

## [How to manage array with dynamic\_templates](https://discuss.elastic.co/t/how-to-manage-array-with-dynamic-templates/334109)

<div class="topic-metadata">

**Author:** [@Julien\_Revol](https://discuss.elastic.co/u/Julien_Revol)\
**Replies:** 2\
**Last updated:** [May 23, 2023, 1:00pm UTC](https://discuss.elastic.co/t/how-to-manage-array-with-dynamic-templates/334109 "2023-05-23T13:00:42Z")

</div>

hello, i want to use dynamic mapping an manage array of object by making them defined as arrays. it works when i define the field directly: "tx.chargingSessionEvents": { "type": "nested" }, but i w…

---

## [Substring search NEST query](https://discuss.elastic.co/t/substring-search-nest-query/333980)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [May 23, 2023, 12:12pm UTC](https://discuss.elastic.co/t/substring-search-nest-query/333980 "2023-05-23T12:12:07Z")

</div>

Hello, I'm trying to search on an ID in my index with reservations for a test application. I can search on the full ID but when I search on the last part of the ID (something the PO requested), I don't get any results …

---

## [Help! Is it possible to make alarm like this?](https://discuss.elastic.co/t/help-is-it-possible-to-make-alarm-like-this/333827)

<div class="topic-metadata">

**Author:** [@Isaac\_Lee](https://discuss.elastic.co/u/Isaac_Lee)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 11:33am UTC](https://discuss.elastic.co/t/help-is-it-possible-to-make-alarm-like-this/333827 "2023-05-23T11:33:48Z")

</div>

Hi team, I am struggling to find whether Kibana is feasible to do this. Is it possible to make alarm like picture 2? If you know, would you guided me how I can do this? Thanks !

---

## [How to close HighLevelClient in thread pool](https://discuss.elastic.co/t/how-to-close-highlevelclient-in-thread-pool/334108)

<div class="topic-metadata">

**Author:** [@CatLoveFishma](https://discuss.elastic.co/u/CatLoveFishma)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 11:03am UTC](https://discuss.elastic.co/t/how-to-close-highlevelclient-in-thread-pool/334108 "2023-05-23T11:03:19Z")

</div>

Hi,I use the thread pool to batch query the data in the es cluster.It is performant and gives me good parallelization. However I am not able to figure out how to close the client. Actually, I do client.close() in child t…

---

## [Retrieve items sorted by mutual-terms match](https://discuss.elastic.co/t/retrieve-items-sorted-by-mutual-terms-match/333604)

<div class="topic-metadata">

**Author:** [@K\_K2](https://discuss.elastic.co/u/K_K2)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 12:06am UTC](https://discuss.elastic.co/t/retrieve-items-sorted-by-mutual-terms-match/333604 "2023-05-23T00:06:08Z")

</div>

We have index mapping like this: { "mappings": { "\_source": { "includes": \[ "uid" \] }, "properties": { "follow": { "doc\_values": true, …

---

## [Slow ES ingestion using Dataflow template with partialUpdates](https://discuss.elastic.co/t/slow-es-ingestion-using-dataflow-template-with-partialupdates/334039)

<div class="topic-metadata">

**Author:** [@julius11](https://discuss.elastic.co/u/julius11)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 5:14pm UTC](https://discuss.elastic.co/t/slow-es-ingestion-using-dataflow-template-with-partialupdates/334039 "2023-05-22T17:14:23Z")

</div>

We are using this template to ingest data once a day from BigQuery to Elastic Search. It creates a dataflow job using the following relevant parameters: "usePartialUpdate": "true", "batchSizeBytes": "5242880", …

---

## [How to configure Elastic Agent Policy in Fleet to Handle Long Key Values in JSON Logging](https://discuss.elastic.co/t/how-to-configure-elastic-agent-policy-in-fleet-to-handle-long-key-values-in-json-logging/334033)

<div class="topic-metadata">

**Author:** [@abhidwi27](https://discuss.elastic.co/u/abhidwi27)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 4:02pm UTC](https://discuss.elastic.co/t/how-to-configure-elastic-agent-policy-in-fleet-to-handle-long-key-values-in-json-logging/334033 "2023-05-22T16:02:07Z")

</div>

Hello, I have successfully set up an Elastic cluster by referring to the documentation provided by Elastic. I have configured the Elastic Stack version 8.7 in a self-managed manner. The following resources were particul…

---

## [Change ML instance configuration](https://discuss.elastic.co/t/change-ml-instance-configuration/333773)

<div class="topic-metadata">

**Author:** [@Elijah\_Adeoye](https://discuss.elastic.co/u/Elijah_Adeoye)\
**Replies:** 6\
**Last updated:** [May 22, 2023, 3:18pm UTC](https://discuss.elastic.co/t/change-ml-instance-configuration/333773 "2023-05-22T15:18:43Z")

</div>

Not sure if this can be routed to a more appropriate space but how do we change the ML instance for Elastic Cloud deployments? For my eland experiment, I am currently assigned "aws.es.ml.c5d" (costly) but I'd like to cha…

---

## [I want to sort items by the array of numbers](https://discuss.elastic.co/t/i-want-to-sort-items-by-the-array-of-numbers/333981)

<div class="topic-metadata">

**Author:** [@CookiesPrompt](https://discuss.elastic.co/u/CookiesPrompt)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 3:07pm UTC](https://discuss.elastic.co/t/i-want-to-sort-items-by-the-array-of-numbers/333981 "2023-05-22T15:07:50Z")

</div>

Hello! I am using elasticsearch version 7.11 and I want to sort items by the array of numbers: lucky\_numbers.number\_list A have a lot of elements like below and arrays have a dynamic length, example: \_source { "ga…

---

## [POSTGRESQL 9.6 Y ELASTICSEARCH 8.7.0](https://discuss.elastic.co/t/postgresql-9-6-y-elasticsearch-8-7-0/333711)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:54pm UTC](https://discuss.elastic.co/t/postgresql-9-6-y-elasticsearch-8-7-0/333711 "2023-05-22T13:54:15Z")

</div>

Hello everyone, I have a problem with the logs that I receive from postgresql version 9.6 to my elasticseach version 8.7.0. I have configured as instructed but I get the error shown in the image: I have another serv…

---

## [Elasticsearch is not working and gives " all shards not available" using the version 6.4.1](https://discuss.elastic.co/t/elasticsearch-is-not-working-and-gives-all-shards-not-available-using-the-version-6-4-1/334005)

<div class="topic-metadata">

**Author:** [@Shadi\_Almasri](https://discuss.elastic.co/u/Shadi_Almasri)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/elasticsearch-is-not-working-and-gives-all-shards-not-available-using-the-version-6-4-1/334005 "2023-05-22T13:51:34Z")

</div>

elasticsearch is not working and gives " all shards not available" using the version 6.4.1

---

## [Issues regarding the installation of ElasticSearch on a remote server](https://discuss.elastic.co/t/issues-regarding-the-installation-of-elasticsearch-on-a-remote-server/333860)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 12:48pm UTC](https://discuss.elastic.co/t/issues-regarding-the-installation-of-elasticsearch-on-a-remote-server/333860 "2023-05-22T12:48:07Z")

</div>

Good morning everyone. First thing first: I am a newbie on topics like servers, unix systems and CLIs. I am working on a Logs monitoring & analysis tool project using the ELK stack. I need to install elasticsearch on …

---

## [Regarding not using data streams for logs](https://discuss.elastic.co/t/regarding-not-using-data-streams-for-logs/334013)

<div class="topic-metadata">

**Author:** [@Jay\_Timbadia](https://discuss.elastic.co/u/Jay_Timbadia)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 12:26pm UTC](https://discuss.elastic.co/t/regarding-not-using-data-streams-for-logs/334013 "2023-05-22T12:26:40Z")

</div>

Hi, I am using latest version of Elastic Search. I am trying to Log my application logs to elasticsearch via logstash. It seems that its using data streams by default to create new indexes with weird index hidden name…

---

## [ILM on single-node?](https://discuss.elastic.co/t/ilm-on-single-node/333997)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 6\
**Last updated:** [May 22, 2023, 10:44am UTC](https://discuss.elastic.co/t/ilm-on-single-node/333997 "2023-05-22T10:44:37Z")

</div>

Hello everyone, I am currently on a single-node infrastructure and I would like to know if the implementation of ILM was useful, I assumed that putting an ILM with the different phases would allow me to keep my data lon…

---

## [Kuromoji\_number and kuromoji\_readingform filter issue](https://discuss.elastic.co/t/kuromoji-number-and-kuromoji-readingform-filter-issue/333999)

<div class="topic-metadata">

**Author:** [@kagnihotri](https://discuss.elastic.co/u/kagnihotri)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 9:02am UTC](https://discuss.elastic.co/t/kuromoji-number-and-kuromoji-readingform-filter-issue/333999 "2023-05-22T09:02:49Z")

</div>

Hi, I have added these two filters - kuromoji\_number, kuromoji\_readingform kuromoji\_readingform is dominating and it is not generating expected tokens from kuromoji\_number filter. Example - { "text": "一〇〇〇", "tok…

---

## [Cluster is not established](https://discuss.elastic.co/t/cluster-is-not-established/333671)

<div class="topic-metadata">

**Author:** [@apopap](https://discuss.elastic.co/u/apopap)\
**Replies:** 14\
**Last updated:** [May 22, 2023, 8:16am UTC](https://discuss.elastic.co/t/cluster-is-not-established/333671 "2023-05-22T08:16:28Z")

</div>

I have 2 EC2 instances one on private network 1 AZ1 and other on private network 2 AZ 2 and try to establish a cluster. The configuration is similar on both nodes, node.name changes # Add your configuration lines here …

---

## [How i can convert the given SQl query to dsl query?](https://discuss.elastic.co/t/how-i-can-convert-the-given-sql-query-to-dsl-query/333878)

<div class="topic-metadata">

**Author:** [@babu\_dev](https://discuss.elastic.co/u/babu_dev)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 7:58am UTC](https://discuss.elastic.co/t/how-i-can-convert-the-given-sql-query-to-dsl-query/333878 "2023-05-22T07:58:49Z")

</div>

Sql query SELECT \* FROM USER\_DB WHERE (NAME IN('BABU DEV', 'NIKHIL') OR AGE IN(23,45)) AND COUNTRY = 'INDIA' AND STATE ='DELHI';

---

## [ElasticSearch Version Upgrade in AWS EKS using Helm Charts \[7.17.3 -\> 8.5.1\]](https://discuss.elastic.co/t/elasticsearch-version-upgrade-in-aws-eks-using-helm-charts-7-17-3-8-5-1/333988)

<div class="topic-metadata">

**Author:** [@helloworld466](https://discuss.elastic.co/u/helloworld466)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 7:54am UTC](https://discuss.elastic.co/t/elasticsearch-version-upgrade-in-aws-eks-using-helm-charts-7-17-3-8-5-1/333988 "2023-05-22T07:54:51Z")

</div>

Have deployed Elasticsearch version 7.17.3 in AWS EKS using helm chart GitHub - elastic/helm-charts: You know, for Kubernetes. My goal is to upgrade my ES to the latest version 8.5.1 using helm chart. I followed the ste…

---

## [I have a ELK Cluster 7.17.3 and I have installed bundled JDK 18+36.. if i need to upgrade JDK to higher version is it compatible with my 7.17.3 version](https://discuss.elastic.co/t/i-have-a-elk-cluster-7-17-3-and-i-have-installed-bundled-jdk-18-36-if-i-need-to-upgrade-jdk-to-higher-version-is-it-compatible-with-my-7-17-3-version/333782)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:49am UTC](https://discuss.elastic.co/t/i-have-a-elk-cluster-7-17-3-and-i-have-installed-bundled-jdk-18-36-if-i-need-to-upgrade-jdk-to-higher-version-is-it-compatible-with-my-7-17-3-version/333782 "2023-05-22T01:49:25Z")

</div>

Hi All, I have a ELK Stack 7.17.3 installed on a Windows 2019 server with bundled JDK 18 +36 . Since there is a vulnerability in JDK 18, can i upgrade the jdk to open jdk 18.0.1 will this impact my ELK Stack . Thanks, …

---

## [Reusing certs b/w http & transport xpack security settings](https://discuss.elastic.co/t/reusing-certs-b-w-http-transport-xpack-security-settings/333691)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:13am UTC](https://discuss.elastic.co/t/reusing-certs-b-w-http-transport-xpack-security-settings/333691 "2023-05-22T01:13:00Z")

</div>

Hi - am trying to reuse the same certs for http & transport xpack security settings in elasticsearch.yml. Currently, http settings use company signed, transport xpack settings use elasticsearch signed certs. Tried to use…

---

## [Why Total from the Valid Nest Response is equals 2 and the Documents count equal 1. I'm not sure how that is possible.](https://discuss.elastic.co/t/why-total-from-the-valid-nest-response-is-equals-2-and-the-documents-count-equal-1-im-not-sure-how-that-is-possible/333919)

<div class="topic-metadata">

**Author:** [@Samer\_Abdelwahed](https://discuss.elastic.co/u/Samer_Abdelwahed)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 10:02pm UTC](https://discuss.elastic.co/t/why-total-from-the-valid-nest-response-is-equals-2-and-the-documents-count-equal-1-im-not-sure-how-that-is-possible/333919 "2023-05-21T22:02:35Z")

</div>

Why Total from the Valid Nest Response is equals 2 and the Documents count equal 1. I'm not sure how that is possible. Documents = Count = 1, Total = 2

---

## [Failed start elasticsearch after install](https://discuss.elastic.co/t/failed-start-elasticsearch-after-install/333959)

<div class="topic-metadata">

**Author:** [@Addr1](https://discuss.elastic.co/u/Addr1)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 6:50pm UTC](https://discuss.elastic.co/t/failed-start-elasticsearch-after-install/333959 "2023-05-21T18:50:25Z")

</div>

Hi, I've an error message after "sudo systemctl start elasticsearch" : Job for elasticsearch.service failed because the control process exited with error code. See "systemctl status elasticsearch.service" and "journalc…

---

## [ELK Indexing Strategy](https://discuss.elastic.co/t/elk-indexing-strategy/333663)

<div class="topic-metadata">

**Author:** [@ARDA\_ASLAN](https://discuss.elastic.co/u/ARDA_ASLAN)\
**Replies:** 11\
**Last updated:** [May 21, 2023, 6:46pm UTC](https://discuss.elastic.co/t/elk-indexing-strategy/333663 "2023-05-21T18:46:30Z")

</div>

Hello Elastic Community, I am quite new in ELK environment so trying to understand the concept and the best practices for a new project that i am responsible. Needing some advices and overview about the indexing strate…

---

## [Elasticsearch cluster replication](https://discuss.elastic.co/t/elasticsearch-cluster-replication/333752)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 4\
**Last updated:** [May 21, 2023, 10:56am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-replication/333752 "2023-05-21T10:56:59Z")

</div>

hello, if i have 2 nodes standalone elasticsearch working with scenario: node-1 : have elasticsearch and logstash and logstash send logs let's called it "index-1" node-2 : have elasticsearch and logstash and logstash …

---

## [Indexing speed single vs multiple clusters](https://discuss.elastic.co/t/indexing-speed-single-vs-multiple-clusters/333910)

<div class="topic-metadata">

**Author:** [@sliu](https://discuss.elastic.co/u/sliu)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 4:22am UTC](https://discuss.elastic.co/t/indexing-speed-single-vs-multiple-clusters/333910 "2023-05-21T04:22:14Z")

</div>

Here's my simplified use case: three indexes, each has 5 billion documents. No need to hit multiple indexes in search. The length of time to index the data is in concern here. With three server nodes, I can have: (1) si…

---

## [License - clarification](https://discuss.elastic.co/t/license-clarification/333925)

<div class="topic-metadata">

**Author:** [@A\_Thomas](https://discuss.elastic.co/u/A_Thomas)\
**Replies:** 1\
**Last updated:** [May 20, 2023, 7:57pm UTC](https://discuss.elastic.co/t/license-clarification/333925 "2023-05-20T19:57:03Z")

</div>

We are trying to use ES for a SaaS application and would like to understand the license required in case of below scenario. Probably this is a technical discussion forum, but couldn't find any other place where I can ask…

---

## [Referencing a weight value from array of match under score function](https://discuss.elastic.co/t/referencing-a-weight-value-from-array-of-match-under-score-function/333909)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 3\
**Last updated:** [May 20, 2023, 5:31pm UTC](https://discuss.elastic.co/t/referencing-a-weight-value-from-array-of-match-under-score-function/333909 "2023-05-20T17:31:16Z")

</div>

We have a requirement to override default elastic score mechanism and score two documents equally if they have equal number of matches ignoring tf and idf. Below is my sample index data PUT my\_index/\_doc/5 { "affinit…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=254)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=256)
