# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=26

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 27

---

## [After upgrading from ES 7, it is easy for a node to be unable to join the cluster for a long time after leaving. Restart the problem node and join it immediately](https://discuss.elastic.co/t/after-upgrading-from-es-7-it-is-easy-for-a-node-to-be-unable-to-join-the-cluster-for-a-long-time-after-leaving-restart-the-problem-node-and-join-it-immediately/373546)

<div class="topic-metadata">

**Author:** [@zcola](https://discuss.elastic.co/u/zcola)\
**Replies:** 14\
**Last updated:** [July 7, 2025, 7:52am UTC](https://discuss.elastic.co/t/after-upgrading-from-es-7-it-is-easy-for-a-node-to-be-unable-to-join-the-cluster-for-a-long-time-after-leaving-restart-the-problem-node-and-join-it-immediately/373546 "2025-07-07T07:52:47Z")

</div>

Versions 8.8.2 or 8.13.2 have this problem. The cluster data size is usually 300-700 tb. The log will be stuck in waiting for local cluster applier for more than ten minutes or one or two minutes. When you restart the p…

---

## [Is data stream backing indices are explicitly created or auto created?](https://discuss.elastic.co/t/is-data-stream-backing-indices-are-explicitly-created-or-auto-created/373490)

<div class="topic-metadata">

**Author:** [@Richard\_Zhang](https://discuss.elastic.co/u/Richard_Zhang)\
**Replies:** 3\
**Last updated:** [July 7, 2025, 6:25am UTC](https://discuss.elastic.co/t/is-data-stream-backing-indices-are-explicitly-created-or-auto-created/373490 "2025-07-07T06:25:10Z")

</div>

Hi everyone, For example, elastic-cloud-logs-8 is a data stream and its underlying indices are like this .ds-elastic-cloud-logs-8-2025.01.22-016804. So question is: is data stream backing indices are explicitly created…

---

## [Enormous CPU usage spike on Hosts](https://discuss.elastic.co/t/enormous-cpu-usage-spike-on-hosts/379809)

<div class="topic-metadata">

**Author:** [@mertse](https://discuss.elastic.co/u/mertse)\
**Replies:** 2\
**Last updated:** [July 7, 2025, 6:18am UTC](https://discuss.elastic.co/t/enormous-cpu-usage-spike-on-hosts/379809 "2025-07-07T06:18:46Z")

</div>

Hello, we are finalizing our systems now and we're going to start the test license in August. Today after doing some more configurations inside Kibana, I've discovered the Host overview and Metrics overview which didn't…

---

## [Elasticsearch cluster keeps going yellow even with balanced nodes](https://discuss.elastic.co/t/elasticsearch-cluster-keeps-going-yellow-even-with-balanced-nodes/379845)

<div class="topic-metadata">

**Author:** [@Rovmenpaul](https://discuss.elastic.co/u/Rovmenpaul)\
**Replies:** 1\
**Last updated:** [July 7, 2025, 5:37am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-keeps-going-yellow-even-with-balanced-nodes/379845 "2025-07-07T05:37:55Z")

</div>

Hi Everyone, I'm running a small Elasticsearch cluster with three data nodes and one master. Everything was stable for a while, but lately the cluster keeps switching to yellow status randomly throughout the day. When I…

---

## [Elasticsearch index is deleted from application but not removed from disk](https://discuss.elastic.co/t/elasticsearch-index-is-deleted-from-application-but-not-removed-from-disk/379591)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 8\
**Last updated:** [July 6, 2025, 5:51pm UTC](https://discuss.elastic.co/t/elasticsearch-index-is-deleted-from-application-but-not-removed-from-disk/379591 "2025-07-06T17:51:05Z")

</div>

I am using elasticsearch version 8.12.0 i deleted some indices from my cluster, but when i checked node stats from stack monitoring tab from kibana what is found Free disk is 1TB and Data is 2.2TB but total disk size is …

---

## [Failed to determine the health of the cluster](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/379645)

<div class="topic-metadata">

**Author:** [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Replies:** 3\
**Last updated:** [July 5, 2025, 9:02am UTC](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/379645 "2025-07-05T09:02:11Z")

</div>

When I run ./elasticsearch-reset-password -i -u elastic --url https://192.168.3.1:9200, it yields: ERROR: Failed to determine the health of the cluster., with exit code 69 But when I remove the --url flag, I get: ERRO…

---

## [Replica shards of newly created indices remain UNASSIGNED](https://discuss.elastic.co/t/replica-shards-of-newly-created-indices-remain-unassigned/379459)

<div class="topic-metadata">

**Author:** [@onel](https://discuss.elastic.co/u/onel)\
**Replies:** 12\
**Last updated:** [July 4, 2025, 7:44pm UTC](https://discuss.elastic.co/t/replica-shards-of-newly-created-indices-remain-unassigned/379459 "2025-07-04T19:44:16Z")

</div>

hello We haven’t experienced this issue before, but recently we noticed that the primary shards of rollover-created indices are allocated normally, while the replica shards always remain in an UNASSIGNED state. We creat…

---

## [The cluster never changes the assigned master node](https://discuss.elastic.co/t/the-cluster-never-changes-the-assigned-master-node/379777)

<div class="topic-metadata">

**Author:** [@Emiliano\_Baum](https://discuss.elastic.co/u/Emiliano_Baum)\
**Replies:** 12\
**Last updated:** [July 4, 2025, 6:30pm UTC](https://discuss.elastic.co/t/the-cluster-never-changes-the-assigned-master-node/379777 "2025-07-04T18:30:39Z")

</div>

The cluster never changes the assigned master node Elasticsearch version 6.8. I have a cluster with 6 data nodes, 3 ingest nodes, and 5 masters (masters only). Over the last few days, the master nodes have been cascadi…

---

## [How to Handle Selective Masking and Reversible Encryption for PII in Elasticsearch Ingestion](https://discuss.elastic.co/t/how-to-handle-selective-masking-and-reversible-encryption-for-pii-in-elasticsearch-ingestion/379807)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 1\
**Last updated:** [July 4, 2025, 2:18pm UTC](https://discuss.elastic.co/t/how-to-handle-selective-masking-and-reversible-encryption-for-pii-in-elasticsearch-ingestion/379807 "2025-07-04T14:18:47Z")

</div>

Hi Folks, I’m working on a use case where we ingest API response payloads into the Elastic Stack (Logstash → Elasticsearch). The payload contains JSON data with a mix of important application-level information (like res…

---

## [ELSER v2 model (version 12.0.0) inference fail for elasticsearch 9.0.3](https://discuss.elastic.co/t/elser-v2-model-version-12-0-0-inference-fail-for-elasticsearch-9-0-3/379776)

<div class="topic-metadata">

**Author:** [@chenlizhao](https://discuss.elastic.co/u/chenlizhao)\
**Replies:** 2\
**Last updated:** [July 4, 2025, 8:41am UTC](https://discuss.elastic.co/t/elser-v2-model-version-12-0-0-inference-fail-for-elasticsearch-9-0-3/379776 "2025-07-04T08:41:53Z")

</div>

I installed elasticsearch 9.0.3 with docker compose file, running on centos7, x86\_64 platform, when I call inference api with: POST \_inference/.elser-2-elasticsearch { "input": "What is Elastic?" } the elasticsearch …

---

## [ECK 8.17.3 can't set replication factor on system indices](https://discuss.elastic.co/t/eck-8-17-3-cant-set-replication-factor-on-system-indices/379697)

<div class="topic-metadata">

**Author:** [@DanielR1](https://discuss.elastic.co/u/DanielR1)\
**Replies:** 1\
**Last updated:** [July 4, 2025, 6:52am UTC](https://discuss.elastic.co/t/eck-8-17-3-cant-set-replication-factor-on-system-indices/379697 "2025-07-04T06:52:44Z")

</div>

Hello! I have deployed a cluster v 8.17.3 using the eck operator, I see all the indices have a replication factor of 0 by default. I have tried to change that using the PUT /.internal.alerts-default.alerts-default-0000…

---

## [The necessity of translog in the writing process of elasticSearch](https://discuss.elastic.co/t/the-necessity-of-translog-in-the-writing-process-of-elasticsearch/379769)

<div class="topic-metadata">

**Author:** [@ka\_ka](https://discuss.elastic.co/u/ka_ka)\
**Replies:** 1\
**Last updated:** [July 3, 2025, 2:11pm UTC](https://discuss.elastic.co/t/the-necessity-of-translog-in-the-writing-process-of-elasticsearch/379769 "2025-07-03T14:11:59Z")

</div>

What are the advantages of using the translog compared to simply setting a very low flush interval? If I set the flush interval to be very low, wouldn't that also achieve persistence? (I realize this might be a bit of a …

---

## [Time-based Phrase Search Without Doubling Transcript field storage – Any Better Way?](https://discuss.elastic.co/t/time-based-phrase-search-without-doubling-transcript-field-storage-any-better-way/379753)

<div class="topic-metadata">

**Author:** [@Andrii\_Tapuzov](https://discuss.elastic.co/u/Andrii_Tapuzov)\
**Replies:** 0\
**Last updated:** [July 3, 2025, 10:05am UTC](https://discuss.elastic.co/t/time-based-phrase-search-without-doubling-transcript-field-storage-any-better-way/379753 "2025-07-03T10:05:14Z")

</div>

Hi, We’re building a solution that allows time-based phrase search over audio transcripts in Elasticsearch. The goal is to find exact phrases that occur at a certain point in time, e.g., "may i help you" within the firs…

---

## [Scoring issue using "minmax" Normalizer in Linear Retriever](https://discuss.elastic.co/t/scoring-issue-using-minmax-normalizer-in-linear-retriever/379744)

<div class="topic-metadata">

**Author:** [@Saad\_Iqbal](https://discuss.elastic.co/u/Saad_Iqbal)\
**Replies:** 0\
**Last updated:** [July 3, 2025, 8:52am UTC](https://discuss.elastic.co/t/scoring-issue-using-minmax-normalizer-in-linear-retriever/379744 "2025-07-03T08:52:20Z")

</div>

If I have a keyword search query and I get 2 documents one with score 90 and other with 91 (and assuming that the best match we can get on the currently indexed data for any query is 100), using minmax normalizer gives t…

---

## [Deployment down because of an ml job](https://discuss.elastic.co/t/deployment-down-because-of-an-ml-job/379712)

<div class="topic-metadata">

**Author:** [@vmesis](https://discuss.elastic.co/u/vmesis)\
**Replies:** 4\
**Last updated:** [July 2, 2025, 8:37pm UTC](https://discuss.elastic.co/t/deployment-down-because-of-an-ml-job/379712 "2025-07-02T20:37:11Z")

</div>

Hello everyone, Recently, I had an issue with my deployment. I create an outliner detection jobs and it run out of memory. However, before I could stop it or reconfigure it the deployment went down. I already tried to …

---

## [Elasticsearch Snapshot](https://discuss.elastic.co/t/elasticsearch-snapshot/379323)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 26\
**Last updated:** [July 2, 2025, 12:43pm UTC](https://discuss.elastic.co/t/elasticsearch-snapshot/379323 "2025-07-02T12:43:36Z")

</div>

Hi Team, We are using Elasticsearch for the first time and are preparing to back up a cluster that is approximately 600 GB in size. Before we proceed with configuring the backup, we need to perform some calculations to …

---

## [ No Observable Difference Between BBQ and Default Configurations in Elasticsearch – Help with Index Size Comparison](https://discuss.elastic.co/t/no-observable-difference-between-bbq-and-default-configurations-in-elasticsearch-help-with-index-size-comparison/377817)

<div class="topic-metadata">

**Author:** [@mohab\_ghobashy](https://discuss.elastic.co/u/mohab_ghobashy)\
**Replies:** 15\
**Last updated:** [July 2, 2025, 3:03pm UTC](https://discuss.elastic.co/t/no-observable-difference-between-bbq-and-default-configurations-in-elasticsearch-help-with-index-size-comparison/377817 "2025-07-02T15:03:15Z")

</div>

I've been running some tests on Better Binary Quantization (BBQ) in Elasticsearch and comparing it with the default configuration for dense vectors, but I'm not observing the expected differences in disk size or search p…

---

## [Can't get licence trial extension and can't pay for subscription](https://discuss.elastic.co/t/cant-get-licence-trial-extension-and-cant-pay-for-subscription/369264)

<div class="topic-metadata">

**Author:** [@kingsley.ohia](https://discuss.elastic.co/u/kingsley.ohia)\
**Replies:** 10\
**Last updated:** [July 2, 2025, 12:21pm UTC](https://discuss.elastic.co/t/cant-get-licence-trial-extension-and-cant-pay-for-subscription/369264 "2025-07-02T12:21:59Z")

</div>

Hello everyone. I need some assistance with my licence, please. We are currently trialling the Platinum licence, which is due to expire in one hour. I have been trying to contact Elastic since last Thursday to request an…

---

## [Heap sudenly full on all voting-only master nodes (7.17.28)](https://discuss.elastic.co/t/heap-sudenly-full-on-all-voting-only-master-nodes-7-17-28/379485)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 19\
**Last updated:** [July 2, 2025, 11:50am UTC](https://discuss.elastic.co/t/heap-sudenly-full-on-all-voting-only-master-nodes-7-17-28/379485 "2025-07-02T11:50:23Z")

</div>

I have no idea what happened. No clue in node logs. These nodes are data\_cold,master,voting\_only and they are very idle, GC happening like every three hours. Suddenly heap on both nodes filled and they crashed. ▶ 2025-…

---

## [How to make Curator not exclude system indices?](https://discuss.elastic.co/t/how-to-make-curator-not-exclude-system-indices/379679)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 0\
**Last updated:** [July 1, 2025, 4:12pm UTC](https://discuss.elastic.co/t/how-to-make-curator-not-exclude-system-indices/379679 "2025-07-01T16:12:30Z")

</div>

I have an action kibana-snapshot: action: snapshot description: Backup the Kibana indicies, where all those lovely visualisations and index pattern settings and other good things are stored. options: …

---

## [Managing Multiple Elastic Cloud Organizations with a Single User](https://discuss.elastic.co/t/managing-multiple-elastic-cloud-organizations-with-a-single-user/367057)

<div class="topic-metadata">

**Author:** [@loml](https://discuss.elastic.co/u/loml)\
**Replies:** 1\
**Last updated:** [July 2, 2025, 4:52am UTC](https://discuss.elastic.co/t/managing-multiple-elastic-cloud-organizations-with-a-single-user/367057 "2025-07-02T04:52:03Z")

</div>

I understand that a user can only belong to one organization at a time based from this documentation. Is there a workaround for this limitation, or is it a current feature restriction?

---

## [Performance Issue During Ingestion](https://discuss.elastic.co/t/performance-issue-during-ingestion/379572)

<div class="topic-metadata">

**Author:** [@echan23](https://discuss.elastic.co/u/echan23)\
**Replies:** 2\
**Last updated:** [July 2, 2025, 4:22am UTC](https://discuss.elastic.co/t/performance-issue-during-ingestion/379572 "2025-07-02T04:22:52Z")

</div>

I currently ingest data into my Elasticsearch cluster from four sources in the first 15 minutes of each hour. During these 15 minutes, queries are slower and performance is impacted. Are there any alternatives that coul…

---

## [Best practice for adding additional fields to transform](https://discuss.elastic.co/t/best-practice-for-adding-additional-fields-to-transform/379665)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [July 1, 2025, 9:37pm UTC](https://discuss.elastic.co/t/best-practice-for-adding-additional-fields-to-transform/379665 "2025-07-01T21:37:53Z")

</div>

Hi community, I've created a custom transform job to extract Fortigate VPN events into custom index to get start / stop time. Sharing it below for reference. This is extracting data from fortigate integration so we alre…

---

## [Too Many Transforms Automatically Recreated](https://discuss.elastic.co/t/too-many-transforms-automatically-recreated/372899)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 1\
**Last updated:** [July 1, 2025, 8:03pm UTC](https://discuss.elastic.co/t/too-many-transforms-automatically-recreated/372899 "2025-07-01T20:03:39Z")

</div>

Elasticsearch cluster (version 8.17.0) I see numerous transforms are being created automatically. Even when I delete these transforms, they are recreated immediately. The transforms follow a naming pattern like: en…

---

## [Search nested fields](https://discuss.elastic.co/t/search-nested-fields/379672)

<div class="topic-metadata">

**Author:** [@sa.moskalenko](https://discuss.elastic.co/u/sa.moskalenko)\
**Replies:** 3\
**Last updated:** [July 1, 2025, 2:32pm UTC](https://discuss.elastic.co/t/search-nested-fields/379672 "2025-07-01T14:32:50Z")

</div>

I create index with nested field { "chat": { "aliases": {}, "mappings": { "properties": { "dataset\_id": { "type": "text", "fields":…

---

## [Understanding ES812Postings Codec Vs Lucene99 Codec](https://discuss.elastic.co/t/understanding-es812postings-codec-vs-lucene99-codec/379659)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 0\
**Last updated:** [July 1, 2025, 9:09am UTC](https://discuss.elastic.co/t/understanding-es812postings-codec-vs-lucene99-codec/379659 "2025-07-01T09:09:19Z")

</div>

Hi Everyone, I was going through the changes made in elasticsearch to tackle lucene's new posting format that uses FOR instead of PFOR and got to know that elasticsearch made its own PFOR codec ES812Postings. My doubt …

---

## [Reindex error from strict mapping to dynamic on sub-field](https://discuss.elastic.co/t/reindex-error-from-strict-mapping-to-dynamic-on-sub-field/379536)

<div class="topic-metadata">

**Author:** [@ugur-kurnaz](https://discuss.elastic.co/u/ugur-kurnaz)\
**Replies:** 2\
**Last updated:** [July 1, 2025, 8:08am UTC](https://discuss.elastic.co/t/reindex-error-from-strict-mapping-to-dynamic-on-sub-field/379536 "2025-07-01T08:08:24Z")

</div>

Hello Elastic Community, I'm struggling with a mapping evolution on an index used to backend messages dropped in DLQ in rabbitmq. We have until now a strict and restricted mapping (as the properties and properties.head…

---

## [SearchRequest.toString() is truncated because of exceed the MAX\_LENGTH 10000](https://discuss.elastic.co/t/searchrequest-tostring-is-truncated-because-of-exceed-the-max-length-10000/379656)

<div class="topic-metadata">

**Author:** [@ChatLee](https://discuss.elastic.co/u/ChatLee)\
**Replies:** 0\
**Last updated:** [July 1, 2025, 5:17am UTC](https://discuss.elastic.co/t/searchrequest-tostring-is-truncated-because-of-exceed-the-max-length-10000/379656 "2025-07-01T05:17:31Z")

</div>

Hi teams, We use the elasticsearch=8.13.2 in our code, when we try to log the query before the requests send to ES, we suffer the incomplete log be printed when we use searchRequest.toString() method, we found that if t…

---

## [Highlighter is using unified or fvh, fields are configured with term\_vector:with\_positions\_offsets](https://discuss.elastic.co/t/highlighter-is-using-unified-or-fvh-fields-are-configured-with-term-vector-with-positions-offsets/379653)

<div class="topic-metadata">

**Author:** [@min\_liu](https://discuss.elastic.co/u/min_liu)\
**Replies:** 0\
**Last updated:** [July 1, 2025, 3:07am UTC](https://discuss.elastic.co/t/highlighter-is-using-unified-or-fvh-fields-are-configured-with-term-vector-with-positions-offsets/379653 "2025-07-01T03:07:08Z")

</div>

My version is 7.10, before highlighter use default value, there will be the following problem: index has exceeded \[1000000\] - maximum allowed to be analyzed for highlighting. This maximum can be set by changing the \[ind…

---

## [Movie Example SearchUI Not Working](https://discuss.elastic.co/t/movie-example-searchui-not-working/379643)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [June 30, 2025, 6:24pm UTC](https://discuss.elastic.co/t/movie-example-searchui-not-working/379643 "2025-06-30T18:24:48Z")

</div>

The Movie Search Example in the Demos does not work. It keeps giving messages of downloading this and that (we waited for 20 minutes) and still is processing. Is this normal?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=25)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=27)
