# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=260

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 261

---

## [Collapse feature and total\_hist after collapse](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:12am UTC](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288 "2023-05-12T11:12:41Z")

</div>

As Elastisearch documantion said: The total number of hits in the response indicates the number of matching documents without collapsing. The total number of distinct group is unknown. I am using a search with paginatio…

---

## [Reasoning behind Geonames Rally Design](https://discuss.elastic.co/t/reasoning-behind-geonames-rally-design/333271)

<div class="topic-metadata">

**Author:** [@lquenti](https://discuss.elastic.co/u/lquenti)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:04am UTC](https://discuss.elastic.co/t/reasoning-behind-geonames-rally-design/333271 "2023-05-12T11:04:28Z")

</div>

Hi, I am currently evaluating Elasticsearch for a HPC related data lake infrastructure. For that, we are currently using rally benchmarker, especially with the geonames and nyc taxis. Since our HPC environment is batch…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[nginx\_uat\_test-frontend\_mobile-test\] does not point to index \[nginx\_uat\_test-frontend\_mobile\_2023.05.12\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 9:54am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276 "2023-05-12T09:54:03Z")

</div>

Rule： { "del-test" : { "version" : 1, "modified\_date" : "2023-05-11T09:30:54.350Z", "policy" : { "phases" : { "hot" : { "min\_age" : "0ms", "actions" : { "rollover" : { "max\_age" : "1d" }, "set\_priority" : { …

---

## [How works Allocation shards data tiers recommanded](https://discuss.elastic.co/t/how-works-allocation-shards-data-tiers-recommanded/333274)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 9:17am UTC](https://discuss.elastic.co/t/how-works-allocation-shards-data-tiers-recommanded/333274 "2023-05-12T09:17:14Z")

</div>

Hi everybody, Fine ? Questions about the allocation of the shards :wink: I have a big index that has his dedicated index template with 3 primary shards and 1 replica { "order": 1, "index\_patterns": \[ "tdir\_busin…

---

## [Index deletion error due to change from Gold to Basic license](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974)

<div class="topic-metadata">

**Author:** [@kazuo](https://discuss.elastic.co/u/kazuo)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 6:36am UTC](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974 "2023-05-12T06:36:32Z")

</div>

Hello, I was using a GOLD license, but did not renew my contract and I did not renew the contract and switched to the free version. One week after the switchover I received the following message ERROR Failed to compl…

---

## [Bug of /\_nlpcn/sql with subqueries](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243)

<div class="topic-metadata">

**Author:** [@liuchsh01](https://discuss.elastic.co/u/liuchsh01)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:51am UTC](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243 "2023-05-12T03:51:44Z")

</div>

After using the /\_nlpcn/sql interface to query the sql with subqueries, some subsequent queries will time out. sql sample: SELECT count(\*) FROM a\_index where someCode in (SELECT code FROM b\_index where someType ='ttt') …

---

## [Run elastic in docker](https://discuss.elastic.co/t/run-elastic-in-docker/332720)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 3:48am UTC](https://discuss.elastic.co/t/run-elastic-in-docker/332720 "2023-05-12T03:48:55Z")

</div>

HI i run my elastic in docker but when i tap this command curl --cacert http\_ca.crt -u elastic https://localhost:9200 Enter host password for user 'elastic': i have this problem: curl: (60) schannel: CertGetCertific…

---

## [Change HTTP SSL security without private key of CA](https://discuss.elastic.co/t/change-http-ssl-security-without-private-key-of-ca/331465)

<div class="topic-metadata">

**Author:** [@Alex\_Fan](https://discuss.elastic.co/u/Alex_Fan)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 2:31am UTC](https://discuss.elastic.co/t/change-http-ssl-security-without-private-key-of-ca/331465 "2023-05-12T02:31:28Z")

</div>

We just installed ELK stack v8.5.1 on RHEL linux server and the elasticsearch is using the generated certs and I can generate the enrollment token for my Kibana to connect. However, we want to use our corporate internal …

---

## [Create new fields in elasticsearch](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 7:19pm UTC](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659 "2023-05-11T19:19:15Z")

</div>

i want to calculate the difference in time between 2 logs different and add the value to a new field i search in google and i find that is possible with painless scripting but i dont know how to do it if there is anyon…

---

## [Change IP of single node instance](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133)

<div class="topic-metadata">

**Author:** [@Dusty\_Boley](https://discuss.elastic.co/u/Dusty_Boley)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133 "2023-05-11T19:12:05Z")

</div>

Hello all, if this info is somewhere and my search missed it I apologize. Also, I am an Elasticsearch noob so my apologies if I mix up terminology. I have a simple single node setup running version 8.7 to service a sma…

---

## [Deprecation Log Spam](https://discuss.elastic.co/t/deprecation-log-spam/332851)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 3:43pm UTC](https://discuss.elastic.co/t/deprecation-log-spam/332851 "2023-05-11T15:43:02Z")

</div>

The below line is blowing up my log files. What is it and what do I need to do to get it to stop? \[2023-05-03T22:10:15,259\]\[WARN \]\[o.e.d.c.m.IndexNameExpressionResolver\] \[elastic.contoso.net\] data\_stream.dataset="depre…

---

## [UpdateByQueryRequest.setMaxRetries does not seems available in ElasticSearch version 8 Java Client](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222)

<div class="topic-metadata">

**Author:** [@csplrj](https://discuss.elastic.co/u/csplrj)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 3:41pm UTC](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222 "2023-05-11T15:41:42Z")

</div>

Below code is for Elasticsearch Client version 7.17. Can't find equivalent code in Elasticsearch Client version 8.7 Script storedScript = new Script(ScriptType.STORED, null, script.getScriptId(), (Map\<String, Object\>) s…

---

## [Ingest data with Node.js on Elastic Search service](https://discuss.elastic.co/t/ingest-data-with-node-js-on-elastic-search-service/333082)

<div class="topic-metadata">

**Author:** [@newbie\_coder](https://discuss.elastic.co/u/newbie_coder)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 2:58pm UTC](https://discuss.elastic.co/t/ingest-data-with-node-js-on-elastic-search-service/333082 "2023-05-11T14:58:03Z")

</div>

I have a simple app and I want to ingest data from my app to Elastic Search sevice. I followed the steps from this tutorial which seem pretty straightforward - get a free trial, create a deployment, then install with np…

---

## [Joining Two Indexes with common field values](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 8\
**Last updated:** [May 11, 2023, 2:22pm UTC](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861 "2023-05-11T14:22:30Z")

</div>

Hi, I am trying to join two indexes with common field values. Can someone please help me. Here is the example: Index\_1 =\> A column\_1 =\> value\_1 Index\_2 =\> B column\_2 =\> value\_1 How can i join both indexes on the…

---

## [Elasticsearch too\_many\_requests disk usage exceeded flood-stage watermark](https://discuss.elastic.co/t/elasticsearch-too-many-requests-disk-usage-exceeded-flood-stage-watermark/333111)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-requests-disk-usage-exceeded-flood-stage-watermark/333111 "2023-05-11T14:20:49Z")

</div>

Hello, I've installed elasticsearch and kibana on a virtual Ubuntu Server and I'm pretty sure I do not have enough space on my virtual disk. I'm running on VSphere and I tried to add disk space but it doesn't extend el…

---

## [Using a Terms Query via Elastic.Clients.Elasticsearch 8.1.1 .NET](https://discuss.elastic.co/t/using-a-terms-query-via-elastic-clients-elasticsearch-8-1-1-net/332817)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/using-a-terms-query-via-elastic-clients-elasticsearch-8-1-1-net/332817 "2023-05-11T14:20:16Z")

</div>

I am currently trying to write a Terms Query via the Elastic.Clients.Elasticsearch 8.1.1 .NET client. To be more precise, I want to write following query in C#: GET persons/\_search { "query": { "bool": { "mu…

---

## [Elasticsearch in Docker : WARN "this node is locked into cluster UUID" on container restart](https://discuss.elastic.co/t/elasticsearch-in-docker-warn-this-node-is-locked-into-cluster-uuid-on-container-restart/333105)

<div class="topic-metadata">

**Author:** [@Bruno44](https://discuss.elastic.co/u/Bruno44)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-in-docker-warn-this-node-is-locked-into-cluster-uuid-on-container-restart/333105 "2023-05-11T13:41:05Z")

</div>

Hello, I use Elasticsearch 8.7.1 in an official Docker container. I export the data (/usr/share/elasticsearch/data/) to the host to keep indexing data. If I delete the container (for update for example), when I recrea…

---

## [NEST equivalent code for an ML infer query](https://discuss.elastic.co/t/nest-equivalent-code-for-an-ml-infer-query/333007)

<div class="topic-metadata">

**Author:** [@virtualaidev](https://discuss.elastic.co/u/virtualaidev)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/nest-equivalent-code-for-an-ml-infer-query/333007 "2023-05-11T13:21:55Z")

</div>

Hi there, any NEST library documentation on how to infer query in ML? For instance I want to do the below: POST /\_ml/trained\_models/sentence-transformers\_\_all-minilm-l12-v2/\_infer { "docs": { "text\_field": "simil…

---

## [Unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\]](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202)

<div class="topic-metadata">

**Author:** [@fmkaiser](https://discuss.elastic.co/u/fmkaiser)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 11:35am UTC](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202 "2023-05-11T11:35:23Z")

</div>

Hello, when trying to migrate system indices to ES 8.x, I get the following error: unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\] full output We are cu…

---

## [ Index not moving to delete phase](https://discuss.elastic.co/t/index-not-moving-to-delete-phase/333026)

<div class="topic-metadata">

**Author:** [@tirelibirefe](https://discuss.elastic.co/u/tirelibirefe)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 11:06am UTC](https://discuss.elastic.co/t/index-not-moving-to-delete-phase/333026 "2023-05-11T11:06:21Z")

</div>

Hello, I have Elasticsearch 8 on K8s. Fluentbit sends logs to ES8. Everyday new indexes are created based on date; likes this: backend-app-2023.05.09 backend-app-2023.05.10 backend-app-2023.05.11 ... I would like e…

---

## ["\_cat/nodes" API reports "transport" IP instead of "http" IP](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166)

<div class="topic-metadata">

**Author:** [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 10:40am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166 "2023-05-11T10:40:38Z")

</div>

Hi, I have a 2-nodes cluster with this setup for the networking configuration : http.host: \[\_local\_,\_ens192\_\] http.port: 9200 transport.host: \[\_ens161\_\] transport.port: 9300 And here is my network setup : # ip -br a…

---

## [Multiple Elasticsearch instances architecture](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187)

<div class="topic-metadata">

**Author:** [@jabulon](https://discuss.elastic.co/u/jabulon)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 10:18am UTC](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187 "2023-05-11T10:18:53Z")

</div>

I am designing a solution based on many smaller Elasticsearch engines scattered around the world, and a single instance containing all of the data from all of the instances combined. I do not need the data to be up to da…

---

## [Elasticsearch - get logs from DMZ](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901)

<div class="topic-metadata">

**Author:** [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901 "2023-05-11T09:28:48Z")

</div>

Hi , we have Elasticsearch cluster and now we want to stream logs from DMZ environment to there which isn't allowed by InfoSec purpose. Only allowed method of pull from the DMZ. What's the preferred option in such cas…

---

## [ElasticSearch does not see indices](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 6\
**Last updated:** [May 11, 2023, 9:23am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960 "2023-05-11T09:23:11Z")

</div>

Hi, I had to reboot EC2 instances that hosts 5-node cluster. The data stored on corresponding EBS volumes. Once I have rebooted the instance and started the Elasticsearch my cluster got into status red. \_cat/indices m…

---

## [My index write api request blocked by status 403 after adding index lifecycle policy](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174)

<div class="topic-metadata">

**Author:** [@jeyong.oh](https://discuss.elastic.co/u/jeyong.oh)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 9:01am UTC](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174 "2023-05-11T09:01:46Z")

</div>

This is what happened today. I'm using index without life cycle management. The index name is "vehicle-iot-coordinate", it's size is about 280GB and it grow with rate of 1GB/day. I'm adding lifecycle management. (disab…

---

## [Logstash , multiple indexs using same ILM and index template and alias error](https://discuss.elastic.co/t/logstash-multiple-indexs-using-same-ilm-and-index-template-and-alias-error/333092)

<div class="topic-metadata">

**Author:** [@sankrithi43](https://discuss.elastic.co/u/sankrithi43)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 8:38am UTC](https://discuss.elastic.co/t/logstash-multiple-indexs-using-same-ilm-and-index-template-and-alias-error/333092 "2023-05-11T08:38:49Z")

</div>

Hi , below is my task to setup and struggling with ILM issue and looking forward if any help here. i setup and configured filebeat and logstash on kubernetes cluster successfully. since we had multiple application…

---

## [Elasticsearch high latency](https://discuss.elastic.co/t/elasticsearch-high-latency/328911)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 15\
**Last updated:** [May 11, 2023, 7:49am UTC](https://discuss.elastic.co/t/elasticsearch-high-latency/328911 "2023-05-11T07:49:47Z")

</div>

Hi all, We noticed some high request latency for searches on our elasticsearch cluster(7.17) and while checking the metrics, it was seen that there was spike in search\_fetch\_time for many indices which were configured 1…

---

## [Curriculum Vitae using ES](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 6:15am UTC](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108 "2023-05-11T06:15:57Z")

</div>

Good morning, I would like use elastic to search in CV perfect matchings and I have this question. Is it possible that with the text of CV get a list of tags? Like a tag cloud. My idea is get this tags and simply sav…

---

## [Fetching filtered and unfiltered count in a single request](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 6:11am UTC](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160 "2023-05-11T06:11:51Z")

</div>

Hi, I have a use case where a user\_id has multiple records in Elasticsearch. I'm using a bool query on user\_id and additional filters on top of it. I'm able to fetch the count of filtered records using track\_total\_hits…

---

## [Timestamp attribute mapping as text(this existing mapping not working for newly created indices )](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156)

<div class="topic-metadata">

**Author:** [@Dnyaneshwar\_Chavan](https://discuss.elastic.co/u/Dnyaneshwar_Chavan)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:46am UTC](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156 "2023-05-11T05:46:36Z")

</div>

I am using dynamic indices creation with template { "base\_index\_dev" : { "order" : 0, "index\_patterns" : \[ "dev\_shipments", "dev\_shipment\_legs\_", "dev\_transport\_orders\_\*" \], "settings" : { "index" : { "default…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=259)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=261)
