# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=265

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 266

---

## [Reindex corrupted index into a new copy](https://discuss.elastic.co/t/reindex-corrupted-index-into-a-new-copy/330765)

<div class="topic-metadata">

**Author:** [@rivermigue](https://discuss.elastic.co/u/rivermigue)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 4:47pm UTC](https://discuss.elastic.co/t/reindex-corrupted-index-into-a-new-copy/330765 "2023-05-01T16:47:29Z")

</div>

Hello, Is it possible to reindex a corrupted index into a new copy accepting some data loss? I am trying to reindex a corrupted index with the following call: POST \_reindex { "source": { "index": "index001" }, "…

---

## [Elasticsearch binds to all interfaces even with network.host commented out](https://discuss.elastic.co/t/elasticsearch-binds-to-all-interfaces-even-with-network-host-commented-out/331159)

<div class="topic-metadata">

**Author:** [@alexl9](https://discuss.elastic.co/u/alexl9)\
**Replies:** 4\
**Last updated:** [May 1, 2023, 4:32pm UTC](https://discuss.elastic.co/t/elasticsearch-binds-to-all-interfaces-even-with-network-host-commented-out/331159 "2023-05-01T16:32:08Z")

</div>

I installed the latest Elasticsearch but it binds to all interfaces even with network.host commented out, is that expected behavior?

---

## [Moving all shards in an index to the same node](https://discuss.elastic.co/t/moving-all-shards-in-an-index-to-the-same-node/330956)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 3:43pm UTC](https://discuss.elastic.co/t/moving-all-shards-in-an-index-to-the-same-node/330956 "2023-05-01T15:43:18Z")

</div>

We want to implement the shrink index API on our cluster. A pre-requisite is that all shards in the to-be-shrunk index must reside on the same node. Currently, this is not the case. What is the simplest way to move all …

---

## [Extract all data from a composite aggregation in Power BI/Power Query using after\_key](https://discuss.elastic.co/t/extract-all-data-from-a-composite-aggregation-in-power-bi-power-query-using-after-key/331868)

<div class="topic-metadata">

**Author:** [@Felipe\_Moura\_da\_Silv](https://discuss.elastic.co/u/Felipe_Moura_da_Silv)\
**Replies:** 0\
**Last updated:** [May 1, 2023, 12:34pm UTC](https://discuss.elastic.co/t/extract-all-data-from-a-composite-aggregation-in-power-bi-power-query-using-after-key/331868 "2023-05-01T12:34:00Z")

</div>

Hey guys! I'm having a challenge importing data from an elasticsearch query into Power BI. I'm making the call and the results arrive, but only the limit of 16000 results that the API allows due to performance. I need …

---

## [Please tell me about the situation of es hardware resources](https://discuss.elastic.co/t/please-tell-me-about-the-situation-of-es-hardware-resources/330893)

<div class="topic-metadata">

**Author:** [@Astrid\_SRE](https://discuss.elastic.co/u/Astrid_SRE)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 10:18am UTC](https://discuss.elastic.co/t/please-tell-me-about-the-situation-of-es-hardware-resources/330893 "2023-05-01T10:18:13Z")

</div>

hi hello Can you help me analyze it, the current situation of our company is like this 20w logs per second 20T per day What kind of hardware configuration is required What is the configuration of the es cluster, net…

---

## [How to provide own API key in ELK version 8.0.0](https://discuss.elastic.co/t/how-to-provide-own-api-key-in-elk-version-8-0-0/330939)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 6\
**Last updated:** [May 1, 2023, 9:49am UTC](https://discuss.elastic.co/t/how-to-provide-own-api-key-in-elk-version-8-0-0/330939 "2023-05-01T09:49:29Z")

</div>

Hi Team, I want to know how i can provide my own API key in ELK version 8.0.0 I did try - "xpack.security.authc.api\_key.enabled=true" - "xpack.security.authc.api\_key.key=" but no luck getting xpack.security.authc…

---

## [How to migrate data from v5.4 to v8.x.x](https://discuss.elastic.co/t/how-to-migrate-data-from-v5-4-to-v8-x-x/329963)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 8:25am UTC](https://discuss.elastic.co/t/how-to-migrate-data-from-v5-4-to-v8-x-x/329963 "2023-05-01T08:25:25Z")

</div>

Hi ES Community, I have few question, i have to migrate ES v5.4 data into latest ES version(v8.x). What would be correct step for this kind data migration? Should i use elasticdump tool to migrate data from old cluster…

---

## [How to setup username and password in EFK in helm charts](https://discuss.elastic.co/t/how-to-setup-username-and-password-in-efk-in-helm-charts/331038)

<div class="topic-metadata">

**Author:** [@root\_linux](https://discuss.elastic.co/u/root_linux)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 4:18am UTC](https://discuss.elastic.co/t/how-to-setup-username-and-password-in-efk-in-helm-charts/331038 "2023-05-01T04:18:30Z")

</div>

Hi, I have configured EFK using helm charts. But it is not asking for username and password. Could anyone help me how can I configure username and password in EFK using helm charts?

---

## [After upgrading from 7.1 to 8.7, I lost my data](https://discuss.elastic.co/t/after-upgrading-from-7-1-to-8-7-i-lost-my-data/331126)

<div class="topic-metadata">

**Author:** [@toshihisa-nakamura](https://discuss.elastic.co/u/toshihisa-nakamura)\
**Replies:** 2\
**Last updated:** [May 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/after-upgrading-from-7-1-to-8-7-i-lost-my-data/331126 "2023-05-01T04:05:29Z")

</div>

After upgrading from 7.1 to 8.7, I lost my data. With Version 8.7, I want to be able to enter data into Elasticsearch and display graphs in Kibana as before. I've been using it for several years just to send weather da…

---

## [Remote clusters for basic/platinum , onprem/cloud license](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 10\
**Last updated:** [May 1, 2023, 12:43am UTC](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668 "2023-05-01T00:43:55Z")

</div>

Hi, We have several Elastic clusters on-premises and we plan to create a few new ones on Azure cloud. All of them are self-managed version 8.6. The purpose of all Elasticsearch clusters is data analysis in Kibana, so I…

---

## [Elasticsearch G1GC over CMS in resolving the GC overhead](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 3\
**Last updated:** [April 30, 2023, 11:21pm UTC](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744 "2023-04-30T23:21:48Z")

</div>

We are using the ES 7.3 with CMS GC and we are preparing for the rolling upgrade to 7.17 which supports G1GC only We are getting the GC overhead curently, \[2023-04-25T02:00:41,085\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[…

---

## [Move ilm based indices to new ILM policy](https://discuss.elastic.co/t/move-ilm-based-indices-to-new-ilm-policy/330793)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/move-ilm-based-indices-to-new-ilm-policy/330793 "2023-04-30T23:18:07Z")

</div>

Hi Team, Few months back we have created one ILM policy for all indices. It was working fine then now our business need to is to create different policy for different indices the idea is to rollover some indices in 3 da…

---

## [Mappings Issue](https://discuss.elastic.co/t/mappings-issue/330797)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:17pm UTC](https://discuss.elastic.co/t/mappings-issue/330797 "2023-04-30T23:17:15Z")

</div>

Hi, I have a field in my index with the mapping and custom analyzer has followed: Mapping: "BookingNo" : { "type" : "text", "fields" : { "lowercase\_keyword" : { "type" : "text", "analyzer" : "lowercase\_keyword\_an…

---

## [Elasticsearch 8.7.0 Installation issue: elasticsearch.bat cmd automatic closes without installation](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156)

<div class="topic-metadata">

**Author:** [@M4MURARI](https://discuss.elastic.co/u/M4MURARI)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 10:58pm UTC](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156 "2023-04-30T22:58:55Z")

</div>

After unzipping the elasticsearch-8.7.0-windows-x86\_64.zip when I click on elasticsearch.bat of bin folder, It automatically closes without full installation. One solution I tried was xpack.security.transport.ssl.enable…

---

## [Issue with Elasticsearch indexes](https://discuss.elastic.co/t/issue-with-elasticsearch-indexes/331064)

<div class="topic-metadata">

**Author:** [@milank2](https://discuss.elastic.co/u/milank2)\
**Replies:** 9\
**Last updated:** [April 30, 2023, 10:56pm UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-indexes/331064 "2023-04-30T22:56:38Z")

</div>

Hello everyone, I am new to ELK and the issue I am experiencing is that indexes are after 3 days reduces to 25x bytes and 0 documents. We are viewing index patterns in Kibana but it will display the 3 days only. Nothing…

---

## [No incoming data to Logstash Output from Elastic Agents - Only Elasticsearch ouptut works](https://discuss.elastic.co/t/no-incoming-data-to-logstash-output-from-elastic-agents-only-elasticsearch-ouptut-works/331350)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 5\
**Last updated:** [April 30, 2023, 9:36pm UTC](https://discuss.elastic.co/t/no-incoming-data-to-logstash-output-from-elastic-agents-only-elasticsearch-ouptut-works/331350 "2023-04-30T21:36:01Z")

</div>

8.7 stack here After I setup a logstash output in Fleet, and set a policy to use that logstash ouptut for integrations, no data comes to it basically. When I switch the output for integrations to Elasticsearch instead …

---

## [Aggregate field with text type](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 5:37pm UTC](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119 "2023-04-30T17:37:31Z")

</div>

Hi i have two field in kibana "hostname" and "usage", when i add "usage" it will show area chart but when i add "hostname" as breakdown not show. FYI1: hostname type are text and not aggregatable! FYI2: these field cr…

---

## [How to avoid duplicate values being copied while using copy\_to?](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905)

<div class="topic-metadata">

**Author:** [@Srikrishna\_Raghupath](https://discuss.elastic.co/u/Srikrishna_Raghupath)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:22am UTC](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905 "2023-04-30T11:22:10Z")

</div>

My Index definition: PUT /test-index { "mappings": { "properties": { "category":{ "type": "text", "similarity": "boolean", "term\_vector": "with\_positions\_offsets", "fields":{…

---

## [Run time field generates error when trying tutorial](https://discuss.elastic.co/t/run-time-field-generates-error-when-trying-tutorial/330158)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [April 29, 2023, 9:38pm UTC](https://discuss.elastic.co/t/run-time-field-generates-error-when-trying-tutorial/330158 "2023-04-29T21:38:03Z")

</div>

I'm trying to learn how to create run time fields by following the instructions on this page: I tried my own variation with these queries: PUT rfield POST rfield/\_doc { "Favourite Food": "My fave food is" } GET r…

---

## [Can't write data to elasticsearch (cannot be changed from type \[date\] to \[text)](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 21\
**Last updated:** [April 29, 2023, 2:59pm UTC](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062 "2023-04-29T14:59:19Z")

</div>

Hi can't write data to elasticsearch vi logstash(http\_poller) here is the scenario: influxdb \> logstash(http\_poller) \> elasticsearch error that I get: "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "…

---

## [Limiting data integrity risks from compromised client](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086)

<div class="topic-metadata">

**Author:** [@nf4ray](https://discuss.elastic.co/u/nf4ray)\
**Replies:** 3\
**Last updated:** [April 29, 2023, 7:49am UTC](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086 "2023-04-29T07:49:16Z")

</div>

Let's say I want to monitor the system logs of a cluster of servers with filebeat. Because using one data stream per host doesn't scale well and the cluster is logically part of the same application, they all write to th…

---

## [Accessing Bucket aggregation in watcher condition. unexpected token was expecting one of \[{\<EOF\>, ';'}\]](https://discuss.elastic.co/t/accessing-bucket-aggregation-in-watcher-condition-unexpected-token-was-expecting-one-of-eof/331077)

<div class="topic-metadata">

**Author:** [@rahulkothanath](https://discuss.elastic.co/u/rahulkothanath)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 5:02pm UTC](https://discuss.elastic.co/t/accessing-bucket-aggregation-in-watcher-condition-unexpected-token-was-expecting-one-of-eof/331077 "2023-04-28T17:02:29Z")

</div>

I am executing the below watch and want to compare the values of bucket 1D from the aggregation in the watcher condition. However, I am getting errors while accessing the value. POST \_watcher/watch/\_execute { "watch"…

---

## [How to use SearchLookup getSource(LeafReaderContext ctx, int doc)](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072)

<div class="topic-metadata">

**Author:** [@p4paul](https://discuss.elastic.co/u/p4paul)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072 "2023-04-28T15:57:41Z")

</div>

In 8.7.0 the source() method was removed from SearchLookup: How do I use the new getSource method in SearchLookup for a FilterScript given the following use case... public class MyLeafFactory implements FilterScript.…

---

## [Remove random indexes](https://discuss.elastic.co/t/remove-random-indexes/331066)

<div class="topic-metadata">

**Author:** [@Marcelo\_Moro\_Brondan](https://discuss.elastic.co/u/Marcelo_Moro_Brondan)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 2:59pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066 "2023-04-28T14:59:17Z")

</div>

remove random indexesremove random indexesHello! I have an elasticsearch 5.6 in centOS 7 and it is behaving unexpectedly. Random indexes are being created. I am not able to identify the origin and apply a configuration …

---

## [Index template - exclude index seems not working](https://discuss.elastic.co/t/index-template-exclude-index-seems-not-working/331060)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 12:54pm UTC](https://discuss.elastic.co/t/index-template-exclude-index-seems-not-working/331060 "2023-04-28T12:54:14Z")

</div>

Hi everybody. I dont find the correct syntax to exclude one index of an index pattern in index template 2 index template :slight\_smile: 1st { "order": 0, "index\_patterns": \[ "\*\_\*","-tdir\_business\_prod-\*" \], …

---

## [Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028 "2023-04-28T08:28:14Z")

</div>

Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?

---

## [ILM policy created and applied but it's not deleting the data](https://discuss.elastic.co/t/ilm-policy-created-and-applied-but-its-not-deleting-the-data/330727)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 4\
**Last updated:** [April 28, 2023, 8:27am UTC](https://discuss.elastic.co/t/ilm-policy-created-and-applied-but-its-not-deleting-the-data/330727 "2023-04-28T08:27:45Z")

</div>

Hello Experts, I have created the ILM policy and applied to the index . but still it is not deleting the old file. is there anythin i miss or need to add. Please guide me. PUT \_ilm/policy/delete-old-indices { "policy…

---

## [How do I check why my search query takes too long? Is there something like Explain command in SQL databases?](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:26am UTC](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029 "2023-04-28T08:26:05Z")

</div>

How do I check why my search query takes too long? Is there something like Explain command in SQL databases?

---

## [Search after example in java8](https://discuss.elastic.co/t/search-after-example-in-java8/330969)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 8:07am UTC](https://discuss.elastic.co/t/search-after-example-in-java8/330969 "2023-04-28T08:07:34Z")

</div>

I cant follow example mentioned in rest api documentation.Elastic java client is really tough to understand. Can some one share how to use searchafter api with java tutorial. There is some sort field we need to share w…

---

## [Question around setting proper ds / index / ilm](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709)

<div class="topic-metadata">

**Author:** [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Replies:** 6\
**Last updated:** [April 28, 2023, 7:04am UTC](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709 "2023-04-28T07:04:14Z")

</div>

Hi new to ES, i have 12 node cluster and its purpose is to capture all of the logs from apps in our 14 env - lets call them dev1-14. each env has 6 apps server and 2 rp and 2 geodes and jmp box - so 11 servers. on the a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=264)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=266)
