# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=258

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 259

---

## [No persistent volumes available for this claim on kubernetes](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:08pm UTC](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607 "2023-05-16T21:08:53Z")

</div>

I'm trying to set up elasticsearch on kubernetes with Helm(helm install elasticsearch elastic/elasticsearch -n efk). I get the error "no persistent volumes available for this claim and no storage class is set". In my ku…

---

## [Index Retention by Filesize](https://discuss.elastic.co/t/index-retention-by-filesize/333489)

<div class="topic-metadata">

**Author:** [@Chacko42](https://discuss.elastic.co/u/Chacko42)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 7:25pm UTC](https://discuss.elastic.co/t/index-retention-by-filesize/333489 "2023-05-16T19:25:39Z")

</div>

Hi Community, we are currently building up a logging infrastructure for our network stuff. The plan is like with switching or firewall logs, to let the logs rotate, as soon as the configured disk space is full. I had a …

---

## [How to create dynamic Query DSL for Includes](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581)

<div class="topic-metadata">

**Author:** [@Koi\_Kin](https://discuss.elastic.co/u/Koi_Kin)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 2:38pm UTC](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581 "2023-05-16T14:38:20Z")

</div>

I have this query: .Search\<Person\>("person", s =\> s .Index("person") .Source(s =\> s .Includes(i =\> i .Fields( f =\> f.Id, ) ) ) .Query(q =\> q …

---

## [Curator not can find indecies](https://discuss.elastic.co/t/curator-not-can-find-indecies/333465)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 12:28pm UTC](https://discuss.elastic.co/t/curator-not-can-find-indecies/333465 "2023-05-16T12:28:27Z")

</div>

I have an issue with deleting indexes! this is my Action file: actions: 1: action: delete\_indices description: \>- Delete indices. Find which to delete by first limiting the list to logstash- prefi…

---

## [Elastic search usermanagement with out using tls](https://discuss.elastic.co/t/elastic-search-usermanagement-with-out-using-tls/333550)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:36am UTC](https://discuss.elastic.co/t/elastic-search-usermanagement-with-out-using-tls/333550 "2023-05-16T09:36:25Z")

</div>

Hi Team, Currently i'm deploying elasticsearch 7.14 version , added usermangement with tls certs , its deploying but while accesing elasticsearch its not asking credentials , But i have added secrets for namespace. \< …

---

## [Aggregations: How to get number of combinations](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560)

<div class="topic-metadata">

**Author:** [@es\_make](https://discuss.elastic.co/u/es_make)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 11:24am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560 "2023-05-16T11:24:11Z")

</div>

Hello, Let's say we have a simple ES index having two fields: "name" (string) and "expired" (boolean) in one nested object "products" (array). Each product name can be mentioned only once in each document. Here's the e…

---

## [Storage polygon is judged to be self-intersecting](https://discuss.elastic.co/t/storage-polygon-is-judged-to-be-self-intersecting/333555)

<div class="topic-metadata">

**Author:** [@baiwenbo1997](https://discuss.elastic.co/u/baiwenbo1997)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 10:45am UTC](https://discuss.elastic.co/t/storage-polygon-is-judged-to-be-self-intersecting/333555 "2023-05-16T10:45:27Z")

</div>

I want to know the tolerance or precision of self-intersecting graphics when storing. error: Polygon self-intersection at lat=22.773210573949637 lon=113.95022321162234 Here is my figure： \[0\] 113.950224078 22.77320374…

---

## [Elasticsearch not showing correct count of documents in index](https://discuss.elastic.co/t/elasticsearch-not-showing-correct-count-of-documents-in-index/330986)

<div class="topic-metadata">

**Author:** [@Taby](https://discuss.elastic.co/u/Taby)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 10:08am UTC](https://discuss.elastic.co/t/elasticsearch-not-showing-correct-count-of-documents-in-index/330986 "2023-05-16T10:08:28Z")

</div>

Hi. Our Java 8 based application is sending an input data of total 17061816 documents to elasticsearch 7.17.4 to index these documents. However, after all indexing is completed, the curl \_count is showing a total of 168…

---

## [About using a two node cluster for data loss prevention](https://discuss.elastic.co/t/about-using-a-two-node-cluster-for-data-loss-prevention/333509)

<div class="topic-metadata">

**Author:** [@usaadi](https://discuss.elastic.co/u/usaadi)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 10:01am UTC](https://discuss.elastic.co/t/about-using-a-two-node-cluster-for-data-loss-prevention/333509 "2023-05-16T10:01:06Z")

</div>

Hello... I have a question about whether a two nodes cluster can be a sufficient setup in avoiding data loss in the event of the complete failure of one node. In other words, for a two nodes cluster, can it be set up s…

---

## [Pause a node of the cluster](https://discuss.elastic.co/t/pause-a-node-of-the-cluster/330964)

<div class="topic-metadata">

**Author:** [@Blacktek](https://discuss.elastic.co/u/Blacktek)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 9:34am UTC](https://discuss.elastic.co/t/pause-a-node-of-the-cluster/330964 "2023-05-16T09:34:15Z")

</div>

Hello, we've a three nodes cluster, and every once in a while we need to restart services or nodes to perform updates. We'd like to perform such activity in a graceful manner, waiting that current in-flight requests co…

---

## [I can't authenticate using 'elastic' , 'kibana\_system' in ELK version 8.5](https://discuss.elastic.co/t/i-cant-authenticate-using-elastic-kibana-system-in-elk-version-8-5/333455)

<div class="topic-metadata">

**Author:** [@linux\_admin](https://discuss.elastic.co/u/linux_admin)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 9:02am UTC](https://discuss.elastic.co/t/i-cant-authenticate-using-elastic-kibana-system-in-elk-version-8-5/333455 "2023-05-16T09:02:30Z")

</div>

I am using ELK cluster consists of three nodes. I can't access Kibana using its URL https://kibana\_IP:5601. When I checked the logs of /var/log/elasticsearch/elasticsearch.log I found these errors: Authentication of \[e…

---

## [Issues starting elastic search](https://discuss.elastic.co/t/issues-starting-elastic-search/333496)

<div class="topic-metadata">

**Author:** [@tanchev](https://discuss.elastic.co/u/tanchev)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 8:59am UTC](https://discuss.elastic.co/t/issues-starting-elastic-search/333496 "2023-05-16T08:59:29Z")

</div>

I'm currently attempting to install and run Elasticsearch on CloudLinux, but I'm encountering some difficulties. The main issue is the absence of a .log file in the directory: /var/log/elasticsearch Despite the log pat…

---

## [Installed elasticsearch and Kibana on my GCP Red Hat Linux 9 but its not working](https://discuss.elastic.co/t/installed-elasticsearch-and-kibana-on-my-gcp-red-hat-linux-9-but-its-not-working/333240)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 7:15am UTC](https://discuss.elastic.co/t/installed-elasticsearch-and-kibana-on-my-gcp-red-hat-linux-9-but-its-not-working/333240 "2023-05-16T07:15:06Z")

</div>

I installed elastic and kibana v.7.17.9 using rpm and was able to start the service with no issues. I don't see any errors in logs but when I try to access http://localhost:5601, it doesn't work and I get can't connect t…

---

## [How do I implement an alert for packet loss?](https://discuss.elastic.co/t/how-do-i-implement-an-alert-for-packet-loss/333425)

<div class="topic-metadata">

**Author:** [@Waruguru\_Joyce](https://discuss.elastic.co/u/Waruguru_Joyce)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-do-i-implement-an-alert-for-packet-loss/333425 "2023-05-16T05:27:31Z")

</div>

I need to implement an alert for packet loss. I have a dashboard in place and the remaining bit is coming up with a rule for checking on packets loss in and out..... Any leads on how to go about it.

---

## [Why my elk always report an error "{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}"](https://discuss.elastic.co/t/why-my-elk-always-report-an-error-statuscode-503-error-service-unavailable-message-license-is-not-available/332780)

<div class="topic-metadata">

**Author:** [@maf\_77](https://discuss.elastic.co/u/maf_77)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 4:59am UTC](https://discuss.elastic.co/t/why-my-elk-always-report-an-error-statuscode-503-error-service-unavailable-message-license-is-not-available/332780 "2023-05-16T04:59:39Z")

</div>

I made a ELK system,but there offen have a error,the kibana html report:{"statusCode":503,"error":"Service Unavailable","message":"License is not available."} I don't know how to find the reason,so i had restart the ser…

---

## [Custom label size issue in transaction metadata](https://discuss.elastic.co/t/custom-label-size-issue-in-transaction-metadata/333520)

<div class="topic-metadata">

**Author:** [@APandey](https://discuss.elastic.co/u/APandey)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 4:37am UTC](https://discuss.elastic.co/t/custom-label-size-issue-in-transaction-metadata/333520 "2023-05-16T04:37:25Z")

</div>

Hi team, We have modified the apm java agent code to add some metadata in transactions that is having dynamic length. One issue we are facing is that sometimes when the size of that metadata value is large let say more …

---

## [I am getting this error in fluentd pods , i have a efk setup in eks cluster , can someone help me with this please - error\_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="ku](https://discuss.elastic.co/t/i-am-getting-this-error-in-fluentd-pods-i-have-a-efk-setup-in-eks-cluster-can-someone-help-me-with-this-please-error-class-fluent-elasticsearcherror-error-400-rejected-by-elasticsearch-location-nil-tag-ku/333040)

<div class="topic-metadata">

**Author:** [@jatinarora0](https://discuss.elastic.co/u/jatinarora0)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 4:48am UTC](https://discuss.elastic.co/t/i-am-getting-this-error-in-fluentd-pods-i-have-a-efk-setup-in-eks-cluster-can-someone-help-me-with-this-please-error-class-fluent-elasticsearcherror-error-400-rejected-by-elasticsearch-location-nil-tag-ku/333040 "2023-05-16T04:48:24Z")

</div>

error\_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="kubernetes.var.log.containers.fluentd

---

## [Help me to solve this Grok error](https://discuss.elastic.co/t/help-me-to-solve-this-grok-error/333385)

<div class="topic-metadata">

**Author:** [@aaronlbk](https://discuss.elastic.co/u/aaronlbk)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 3:22am UTC](https://discuss.elastic.co/t/help-me-to-solve-this-grok-error/333385 "2023-05-16T03:22:22Z")

</div>

Hello, I created a pipeline in kibana # Click the Variables button, above, to create your own variable PUT \_ingest/pipeline/exemple-pipeline-apache { "description": "Mon premier pipeline pour appliquer un grok patter…

---

## [Triggering E-mail Alert (Conditional)](https://discuss.elastic.co/t/triggering-e-mail-alert-conditional/333415)

<div class="topic-metadata">

**Author:** [@Bong\_Fabian](https://discuss.elastic.co/u/Bong_Fabian)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/triggering-e-mail-alert-conditional/333415 "2023-05-15T07:57:22Z")

</div>

Hi All, How canI come out with an e-mail alert that is based on condition? Using Rules and Connectors For e.g Alert trigger by single IP\* group by specific API\*\* within 24 hours if the activities is more than 10 Indi…

---

## [Using certificate chain in Elasticsearch](https://discuss.elastic.co/t/using-certificate-chain-in-elasticsearch/333422)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 8:08am UTC](https://discuss.elastic.co/t/using-certificate-chain-in-elasticsearch/333422 "2023-05-15T08:08:06Z")

</div>

Hi, I want to configure security in elasticsearch using company signed CA certificate. The CA certificate provided is a cert chain. Now, when i I am trying to create certificates for elastic nodes, it is throwing err…

---

## [Add built-in normalizer to existing indices](https://discuss.elastic.co/t/add-built-in-normalizer-to-existing-indices/333360)

<div class="topic-metadata">

**Author:** [@NishuGoel](https://discuss.elastic.co/u/NishuGoel)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:52pm UTC](https://discuss.elastic.co/t/add-built-in-normalizer-to-existing-indices/333360 "2023-05-15T20:52:09Z")

</div>

Hi there, I was going through the documentation where it says for some mapping parameters, we CAN update the existing index using PUT index/\_mapping. "normalizer" being one of those parameters - Update mapping API | El…

---

## [JVM Heap size issue. ElasticSearch stops sometimes due to this error](https://discuss.elastic.co/t/jvm-heap-size-issue-elasticsearch-stops-sometimes-due-to-this-error/333157)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 10\
**Last updated:** [May 15, 2023, 7:55pm UTC](https://discuss.elastic.co/t/jvm-heap-size-issue-elasticsearch-stops-sometimes-due-to-this-error/333157 "2023-05-15T19:55:13Z")

</div>

Caused by: org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[preallocate\[aggregations\]\] would be \[4143070784/3.8gb\], which is larger than the limit of \[4080218931/3.7gb\], real …

---

## [Retrieving top N hits from nested documents across all matching documents](https://discuss.elastic.co/t/retrieving-top-n-hits-from-nested-documents-across-all-matching-documents/333485)

<div class="topic-metadata">

**Author:** [@Raja\_Sekhara\_Reddy\_K](https://discuss.elastic.co/u/Raja_Sekhara_Reddy_K)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 4:06pm UTC](https://discuss.elastic.co/t/retrieving-top-n-hits-from-nested-documents-across-all-matching-documents/333485 "2023-05-15T16:06:32Z")

</div>

Hello, I'm currently working with an Elasticsearch index where each document contains a nested field embedingContent representing "chunks" of the document. Each chunk has its own vector embedding, and I want to perform …

---

## [Append ingest processor stringifies arrays instead of processing the elements one by one](https://discuss.elastic.co/t/append-ingest-processor-stringifies-arrays-instead-of-processing-the-elements-one-by-one/333486)

<div class="topic-metadata">

**Author:** [@Technici4n](https://discuss.elastic.co/u/Technici4n)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 4:13pm UTC](https://discuss.elastic.co/t/append-ingest-processor-stringifies-arrays-instead-of-processing-the-elements-one-by-one/333486 "2023-05-15T16:13:30Z")

</div>

Hello, it seems that the append processor "stringifies" input arrays instead of processing the elements one by one. Could that be? (Using elasticsearch 8.6.2) Pipeline: "description": "testing issues with append", …

---

## [How to customize fleet agent policy integration](https://discuss.elastic.co/t/how-to-customize-fleet-agent-policy-integration/333478)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 3:13pm UTC](https://discuss.elastic.co/t/how-to-customize-fleet-agent-policy-integration/333478 "2023-05-15T15:13:29Z")

</div>

Hello, I am currently setting up an Elasticsearch cluster using the ECK operator, and I would like to know how I can customize the fleet integration configuration using the kibana.yml The problems I am facing. I can …

---

## [Unable to open index after config change while closed](https://discuss.elastic.co/t/unable-to-open-index-after-config-change-while-closed/333325)

<div class="topic-metadata">

**Author:** [@matt-monacelli](https://discuss.elastic.co/u/matt-monacelli)\
**Replies:** 5\
**Last updated:** [May 15, 2023, 2:26pm UTC](https://discuss.elastic.co/t/unable-to-open-index-after-config-change-while-closed/333325 "2023-05-15T14:26:13Z")

</div>

ES version: 7.10.2 (running in AWS) I mistakenly added a configuration that had been deprecated and is now preventing me from opening the index. To reproduce, close an index, set the index.mpper.dynamic setting to fals…

---

## [Elasticsearch 7.17.9 - current step is not recognized for shrink action, despite not having a shrink action defined](https://discuss.elastic.co/t/elasticsearch-7-17-9-current-step-is-not-recognized-for-shrink-action-despite-not-having-a-shrink-action-defined/330990)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 6\
**Last updated:** [May 15, 2023, 1:34pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-9-current-step-is-not-recognized-for-shrink-action-despite-not-having-a-shrink-action-defined/330990 "2023-05-15T13:34:20Z")

</div>

This is logged at the ERROR level and I'm not sure why. The ILM policy does not have a shrink action defined. Sample log, with the index name changed only to swap the account ID with 12345. current step \[{"phase":"warm…

---

## [Springboot maven project - RUM & APM Traces are not having same trace id](https://discuss.elastic.co/t/springboot-maven-project-rum-apm-traces-are-not-having-same-trace-id/332924)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 1:23pm UTC](https://discuss.elastic.co/t/springboot-maven-project-rum-apm-traces-are-not-having-same-trace-id/332924 "2023-05-15T13:23:56Z")

</div>

hello team, I came across the issue whee i am not getting same trace id for RUM & APM transaction. E.g. i initiate the transaction "login" and i get the transaction detail in APM (service - springboot-consumer) & RUM (…

---

## [Count distinct groups when using collapse](https://discuss.elastic.co/t/count-distinct-groups-when-using-collapse/333463)

<div class="topic-metadata">

**Author:** [@dorian-marchal](https://discuss.elastic.co/u/dorian-marchal)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 1:11pm UTC](https://discuss.elastic.co/t/count-distinct-groups-when-using-collapse/333463 "2023-05-15T13:11:29Z")

</div>

When collapsing results, the total number of hits (using track\_total\_hits) doesn't take collapsing into account, i.e. the total number of documents is returned, not the number of collapsed groups. E.g. if I index 150854…

---

## [High ram usage](https://discuss.elastic.co/t/high-ram-usage/333270)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 6\
**Last updated:** [May 15, 2023, 12:55pm UTC](https://discuss.elastic.co/t/high-ram-usage/333270 "2023-05-15T12:55:41Z")

</div>

Hello, after some posts and good answers we optimize our Elasticsearch. Actually we use: 6 x hot nodes a 32 gb ram / heap space a 16 gb 22 x cold nodes a 16 gb / 8 gb space We reduce 8 primaries shards to 6 shards A…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=257)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=259)
