# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=256

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 257

---

## [Role Template with reference to metadata property from Open ID Realm](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869)

<div class="topic-metadata">

**Author:** [@Artem\_Ruzak](https://discuss.elastic.co/u/Artem_Ruzak)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 7:59pm UTC](https://discuss.elastic.co/t/role-template-with-reference-to-metadata-property-from-open-id-realm/333869 "2023-05-19T19:59:13Z")

</div>

Hello, we are having SSO solution implemented based with Keycloak and based on OpenID concept It is working well and we are able to assign roles by username or with reference to realm.name As a next step I want to imp…

---

## [Searching by ngrams](https://discuss.elastic.co/t/searching-by-ngrams/333872)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 9\
**Last updated:** [May 19, 2023, 4:57pm UTC](https://discuss.elastic.co/t/searching-by-ngrams/333872 "2023-05-19T16:57:33Z")

</div>

I use search with query string in index analyzed with ngrams. When I try to search doc with field\_1 = SU0001023277 it's ok. But when I try to use less letters, like SU0001023 the resultset is 0. Why it comes out like th…

---

## [Nested type is removed from the new index while reindexing](https://discuss.elastic.co/t/nested-type-is-removed-from-the-new-index-while-reindexing/333876)

<div class="topic-metadata">

**Author:** [@Maitri](https://discuss.elastic.co/u/Maitri)\
**Replies:** 4\
**Last updated:** [May 19, 2023, 4:14pm UTC](https://discuss.elastic.co/t/nested-type-is-removed-from-the-new-index-while-reindexing/333876 "2023-05-19T16:14:15Z")

</div>

I have an index which a property with nested type. I am reindexing the index into new index. But, in the destination index every mapping are same except the property which was having nested type in the source index. nest…

---

## [Reindex error : "type":"mapper\_parsing\_exception","reason":"failed to parse field \[date\] of type \[date\]](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 3:25pm UTC](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798 "2023-05-19T15:25:12Z")

</div>

Hello, While using the reindexing API, I am running into 4 indices that are giving me errors. It seems like the date in the document matches the template but I guess it is not. I don't really know how to tackle this. …

---

## [Knn vectors](https://discuss.elastic.co/t/knn-vectors/333199)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 12:41pm UTC](https://discuss.elastic.co/t/knn-vectors/333199 "2023-05-19T12:41:37Z")

</div>

Let us say I am building an ecommerce app and there are 2 users: user A : always searches for electronics (laptop, headphones, etc) user B: searches for snacks, beverages Is it possible to show a page with banner that…

---

## [Elasticsearch 8.7 2-node cluster](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 11:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772 "2023-05-19T11:22:54Z")

</div>

Hello, I want to create 2-node cluster and it doesn't work node-01: path.data: /bitnami/elasticsearch/data cluster.name: zephyr node.name: node-01 node.roles: \[ master, data \] http.port: 9200 transport.port: 9300 boot…

---

## [Elasticsearch monitoring using telegraf](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 10:58am UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862 "2023-05-19T10:58:07Z")

</div>

I am using telegraf to monitor elasticsearch. i am using below doc. i am not able to get the data elasticsearch\_network ' tcp\_in\_errs value=0 tcp\_passive\_opens value=16 tcp\_curr\_estab value=29 tcp\_in\_segs value=11…

---

## [Unassigned shards, with status "Elasticsearch can allocate the shard" for all of them](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 9:49am UTC](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806 "2023-05-19T09:49:27Z")

</div>

Can you help me to explain why I have for several days 25 unassigned replica shards wich can\_allocate status = yes and allocation\_explanation = Elasticsearch can allocate the shard. I supposed rebalancing job will alloc…

---

## [Elastic pipeline processors grok for question!](https://discuss.elastic.co/t/elastic-pipeline-processors-grok-for-question/333852)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 9:13am UTC](https://discuss.elastic.co/t/elastic-pipeline-processors-grok-for-question/333852 "2023-05-19T09:13:51Z")

</div>

When I parsed the nginx log using Filebeat pipeline, a user\_agent field in the log failed to be parsed. The following error is displayed. {"type":"mapper\_parsing\_exception","reason":"object mapping for \[user\_agent\] trie…

---

## [Ilm question/troubleshooting](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 8:25am UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676 "2023-05-19T08:25:20Z")

</div>

My ilm policy does not work, although I have created a similar one a couple of weeks before in another cluster and it is working just fine.. Here is what I did: I pointed Logstash towards ind\_alias Created index templ…

---

## [Disk space is 100% after running a "delete by query" in devtool in kibana](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 5:24am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647 "2023-05-19T05:24:34Z")

</div>

After running the query below, server space is getting full in all data nodes ( ELK cluster: 3 masters, 3 data, 1 kibana node). POST /apic\_sandbox/\_delete\_by\_query?wait\_for\_completion=false //change index here accordi…

---

## [How to add Sudachi NLP into Elastic Cloud?](https://discuss.elastic.co/t/how-to-add-sudachi-nlp-into-elastic-cloud/333838)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 4:23am UTC](https://discuss.elastic.co/t/how-to-add-sudachi-nlp-into-elastic-cloud/333838 "2023-05-19T04:23:53Z")

</div>

Hello. I want to use Japanese NLP Sudachi instead of the default library Kuromoji in Workplace Search in the deployment of Elastic Cloud. Is it possible to add Sudachi in the Elastic Cloud and install it to the specifi…

---

## [While accessing Kibana facing data view pulgin issue](https://discuss.elastic.co/t/while-accessing-kibana-facing-data-view-pulgin-issue/333834)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 3:42am UTC](https://discuss.elastic.co/t/while-accessing-kibana-facing-data-view-pulgin-issue/333834 "2023-05-19T03:42:00Z")

</div>

Hi Team, Deployed both V7.17 (kibana and elasticsearch ) through helm, While accessing kibana facing data view plugin issue some time, after refreshing its working \< 46635/bundles/plugin/dataViews/kibana/dataViews.…

---

## [Unable to authenticate with provided credentials and anonymous access is not allowed for this request](https://discuss.elastic.co/t/unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/333518)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 3\
**Last updated:** [May 19, 2023, 1:26am UTC](https://discuss.elastic.co/t/unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/333518 "2023-05-19T01:26:48Z")

</div>

I getting case errror when I configure Fleetserver with run file script ./elastic-agents install. . And now show detail log error "message":"Fleet Server - Error - info fail \[401 Unauthorized\] {"error":{"root\_cause":\[{…

---

## [GCP LOGGING TO ELASTIC | security](https://discuss.elastic.co/t/gcp-logging-to-elastic-security/332596)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 11\
**Last updated:** [May 19, 2023, 12:30am UTC](https://discuss.elastic.co/t/gcp-logging-to-elastic-security/332596 "2023-05-19T00:30:00Z")

</div>

Hi, We have elasticsearch running on VMs and we are trying to share the logs from GCP to local elastic cluster. Thing is, GCP uses service account and key. Is there a way where we can add GCP service account credential…

---

## [Warning: Body deprecated in hybrid search](https://discuss.elastic.co/t/warning-body-deprecated-in-hybrid-search/330613)

<div class="topic-metadata">

**Author:** [@Francisco\_Rocha](https://discuss.elastic.co/u/Francisco_Rocha)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 10:04pm UTC](https://discuss.elastic.co/t/warning-body-deprecated-in-hybrid-search/330613 "2023-05-18T22:04:29Z")

</div>

Hi there, don't know how to remove this warning: DeprecationWarning: The 'body' parameter is deprecated for the 'search' API and will be removed in a future version. Instead use API parameters directly. The following …

---

## [Having an empty hits and response from elasticsearch when trying to query them via an api](https://discuss.elastic.co/t/having-an-empty-hits-and-response-from-elasticsearch-when-trying-to-query-them-via-an-api/333698)

<div class="topic-metadata">

**Author:** [@Bettaieb\_Walid](https://discuss.elastic.co/u/Bettaieb_Walid)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 9:56pm UTC](https://discuss.elastic.co/t/having-an-empty-hits-and-response-from-elasticsearch-when-trying-to-query-them-via-an-api/333698 "2023-05-18T21:56:27Z")

</div>

hello , I am developing backend using strapi , and i am going to store some data inside elasticsearch , and i would like to be able to consume the data, and fetch them. here is the different configuration files routes: …

---

## [Exclude a lost of mac addresses in alert with elasticsearch query](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590)

<div class="topic-metadata">

**Author:** [@odelacruzc93](https://discuss.elastic.co/u/odelacruzc93)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 9:40pm UTC](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590 "2023-05-18T21:40:25Z")

</div>

Hi There! Please I need your help, I am ingesting logs ARP and DHCP to find IPs outside my porganizatión, so I implemented an alarm but I must exclude 1650 MAC addresses, can I create a list with these MAC addresses to a…

---

## [Elasticsearch not able to form a cluster](https://discuss.elastic.co/t/elasticsearch-not-able-to-form-a-cluster/333817)

<div class="topic-metadata">

**Author:** [@neerajg](https://discuss.elastic.co/u/neerajg)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elasticsearch-not-able-to-form-a-cluster/333817 "2023-05-18T21:19:10Z")

</div>

Hi, We have 3 nodes (Linux Ubuntu 20.04) I have modified the /etc/hosts file to add node1 node2 and node3 as DNS with their IPs I have installed elasticsearch but for some reason elasticsearch is not able to form a cl…

---

## [I installed elasticsearch 8.7 but icant acess it through my browser down here is my yml file](https://discuss.elastic.co/t/i-installed-elasticsearch-8-7-but-icant-acess-it-through-my-browser-down-here-is-my-yml-file/333538)

<div class="topic-metadata">

**Author:** [@coolin\_dady](https://discuss.elastic.co/u/coolin_dady)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 9:04pm UTC](https://discuss.elastic.co/t/i-installed-elasticsearch-8-7-but-icant-acess-it-through-my-browser-down-here-is-my-yml-file/333538 "2023-05-18T21:04:55Z")

</div>

\# ======================== Elasticsearch Configuration ========================= # # NOTE: Elasticsearch comes with reasonable defaults for most settings. # Before you set out to tweak and tune the configuration, make…

---

## [Move shard to another node error](https://discuss.elastic.co/t/move-shard-to-another-node-error/333235)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 9:02pm UTC](https://discuss.elastic.co/t/move-shard-to-another-node-error/333235 "2023-05-18T21:02:02Z")

</div>

Hello, I need to move shards to another node. I get the following error. The command is first and the error after it: error to check post \_cluster/reroute { "commands": \[ { "move": { "index": "yeshut\_2022.03.31-0…

---

## [Elasticsearch "delete by query" not released disk space](https://discuss.elastic.co/t/elasticsearch-delete-by-query-not-released-disk-space/333768)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 8:35pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-by-query-not-released-disk-space/333768 "2023-05-18T20:35:10Z")

</div>

After running "delete by query ", disk space did not released. What should I do to make disk space release?

---

## [DSL compound Queries](https://discuss.elastic.co/t/dsl-compound-queries/330591)

<div class="topic-metadata">

**Author:** [@waitangi](https://discuss.elastic.co/u/waitangi)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 8:25pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591 "2023-05-18T20:25:11Z")

</div>

Hi everyone I have following DSL queries: GET eclaims-logs-2023.04.21/\_search { "query": { "bool": { "must": \[ { "match": { "thread\_name" : "http-nio-5050-exec-7" } …

---

## [Sorting by max value of property of nested object array](https://discuss.elastic.co/t/sorting-by-max-value-of-property-of-nested-object-array/333778)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 5:20pm UTC](https://discuss.elastic.co/t/sorting-by-max-value-of-property-of-nested-object-array/333778 "2023-05-18T17:20:01Z")

</div>

I have the following object model: { ... "classification": \[ { "label": "aaa", "probability": 0.9923 }, { "label": "bbb", "probability": 0.3452 }, { "label": "ccc", "probability": 0.0012 …

---

## [Change the index allocation requirement](https://discuss.elastic.co/t/change-the-index-allocation-requirement/333781)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 3:39pm UTC](https://discuss.elastic.co/t/change-the-index-allocation-requirement/333781 "2023-05-18T15:39:59Z")

</div>

How to change the index and remove the allocation requirement "cold" ?

---

## [I am sending 30 GB data from databricks to elasticsearch through the elasticsearch apache hadoop connector, It is taking around 2 hours for sending it. How to make it fast? How much time it should take ideally?](https://discuss.elastic.co/t/i-am-sending-30-gb-data-from-databricks-to-elasticsearch-through-the-elasticsearch-apache-hadoop-connector-it-is-taking-around-2-hours-for-sending-it-how-to-make-it-fast-how-much-time-it-should-take-ideally/333715)

<div class="topic-metadata">

**Author:** [@Sagnik\_Mandal](https://discuss.elastic.co/u/Sagnik_Mandal)\
**Replies:** 6\
**Last updated:** [May 18, 2023, 2:40pm UTC](https://discuss.elastic.co/t/i-am-sending-30-gb-data-from-databricks-to-elasticsearch-through-the-elasticsearch-apache-hadoop-connector-it-is-taking-around-2-hours-for-sending-it-how-to-make-it-fast-how-much-time-it-should-take-ideally/333715 "2023-05-18T14:40:17Z")

</div>

My elasticsearch connector configs are: .option("es.write.operation.parallelism", "4") .option("es.batch.size.bytes", "10mb") .option("es.batch.size.entries", "1000") .option("es.batch.write.retry.coun…

---

## [Reindex 1 index to multiple indexes](https://discuss.elastic.co/t/reindex-1-index-to-multiple-indexes/333667)

<div class="topic-metadata">

**Author:** [@elasticvakif](https://discuss.elastic.co/u/elasticvakif)\
**Replies:** 7\
**Last updated:** [May 18, 2023, 12:07pm UTC](https://discuss.elastic.co/t/reindex-1-index-to-multiple-indexes/333667 "2023-05-18T12:07:20Z")

</div>

We have an index which is around 120 gb. we want to split it multiple indices. Is there any way to do that ? I guess reindex supports 1 to 1. I need 1 to many. It doesn't matter which document is in which index. We can u…

---

## [Cross Cluster Replication - Dev Environment](https://discuss.elastic.co/t/cross-cluster-replication-dev-environment/333758)

<div class="topic-metadata">

**Author:** [@to185030](https://discuss.elastic.co/u/to185030)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 10:47am UTC](https://discuss.elastic.co/t/cross-cluster-replication-dev-environment/333758 "2023-05-18T10:47:43Z")

</div>

Can someone tell me if it is possible to setup CCR on Elasticsearch for my application in a Dev environment - for a very limited window of time, without having to bear the expenses for the licenses of all the Platinum li…

---

## [Frozen tier - Conenience in multiple zones](https://discuss.elastic.co/t/frozen-tier-conenience-in-multiple-zones/333475)

<div class="topic-metadata">

**Author:** [@Alberallo](https://discuss.elastic.co/u/Alberallo)\
**Replies:** 8\
**Last updated:** [May 18, 2023, 9:48am UTC](https://discuss.elastic.co/t/frozen-tier-conenience-in-multiple-zones/333475 "2023-05-18T09:48:42Z")

</div>

HI, since high availability is guaranteed by default for frozen nodes, why should there be any convenience in configuring a cluster with more than one zone for the frozen tier? In particular, during the execution of th…

---

## [Refresh API taking too long](https://discuss.elastic.co/t/refresh-api-taking-too-long/333562)

<div class="topic-metadata">

**Author:** [@blacar](https://discuss.elastic.co/u/blacar)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 8:56am UTC](https://discuss.elastic.co/t/refresh-api-taking-too-long/333562 "2023-05-18T08:56:24Z")

</div>

Hi folks, I am having some 409 - versioning conflict problems when using deleteByQuery so I decided to run a POST /\_refresh when I receive a 409 and just before trying again. The rate of operations recovery using this …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=255)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=257)
