# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=27

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 28

---

## [Warning: Connection refused on port 9304](https://discuss.elastic.co/t/warning-connection-refused-on-port-9304/379644)

<div class="topic-metadata">

**Author:** [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Replies:** 0\
**Last updated:** [June 30, 2025, 7:25pm UTC](https://discuss.elastic.co/t/warning-connection-refused-on-port-9304/379644 "2025-06-30T19:25:04Z")

</div>

I am running ES on a local computer. I am encountering this error: \[2025-06-30T15:06:05,304\]\[WARN \]\[o.e.d.PeerFinder \] \[localhost.localdomain\] address \[\[::1\]:9304\], node \[unknown\] discovery result: \[\]\[\[::1\]:9304…

---

## [After upgrade to latest version some of watchers missing](https://discuss.elastic.co/t/after-upgrade-to-latest-version-some-of-watchers-missing/378198)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 7\
**Last updated:** [June 30, 2025, 7:57am UTC](https://discuss.elastic.co/t/after-upgrade-to-latest-version-some-of-watchers-missing/378198 "2025-06-30T07:57:30Z")

</div>

Hello I have issue that after upgrade to latest elasticsearch version some of watchers in ELK are missing but working. Is it possible somehow to import them to be visible in Kibana ?

---

## [Elastic defend - network events - icmp traffic](https://discuss.elastic.co/t/elastic-defend-network-events-icmp-traffic/379599)

<div class="topic-metadata">

**Author:** [@Snow](https://discuss.elastic.co/u/Snow)\
**Replies:** 0\
**Last updated:** [June 30, 2025, 5:43am UTC](https://discuss.elastic.co/t/elastic-defend-network-events-icmp-traffic/379599 "2025-06-30T05:43:44Z")

</div>

Hi, I have installed only elastic defend. i similated few requests, under network events i could see logs ( connection attempted, connection accepted, disconnect received) but for icmp simulation like ping execution,…

---

## [Historical (Past) Data Ingestion in Time Series Data Stream](https://discuss.elastic.co/t/historical-past-data-ingestion-in-time-series-data-stream/379584)

<div class="topic-metadata">

**Author:** [@rubayetahmed314](https://discuss.elastic.co/u/rubayetahmed314)\
**Replies:** 14\
**Last updated:** [June 29, 2025, 6:04pm UTC](https://discuss.elastic.co/t/historical-past-data-ingestion-in-time-series-data-stream/379584 "2025-06-29T18:04:34Z")

</div>

Is it possible to insert historical (past) data into a Time Series Data Stream (TSDS) of Elasticsearch? To be more clear, suppose, I want to ingest NYC Taxi Trip Data from Year 2009 to 2024 in a time-series data stream. …

---

## [Spring Boot 3.4.5 with jdk 21, Elastic APM agent 1.54 is not working during startup](https://discuss.elastic.co/t/spring-boot-3-4-5-with-jdk-21-elastic-apm-agent-1-54-is-not-working-during-startup/379580)

<div class="topic-metadata">

**Author:** [@Sameer\_Hindurao](https://discuss.elastic.co/u/Sameer_Hindurao)\
**Replies:** 0\
**Last updated:** [June 28, 2025, 7:38am UTC](https://discuss.elastic.co/t/spring-boot-3-4-5-with-jdk-21-elastic-apm-agent-1-54-is-not-working-during-startup/379580 "2025-06-28T07:38:00Z")

</div>

We are Migrating SpringBoot 3.0.1 to SprintBoot 3.4.5 jdk 17 to jdk 21 APM agent 1.54 and we are getting below error during start up of application, Application is working fine but were are not able to push APM details…

---

## [Debug elasticsearch without basic auth (xpack.security.enabled=false)](https://discuss.elastic.co/t/debug-elasticsearch-without-basic-auth-xpack-security-enabled-false/379566)

<div class="topic-metadata">

**Author:** [@softwaredoug](https://discuss.elastic.co/u/softwaredoug)\
**Replies:** 2\
**Last updated:** [June 27, 2025, 2:27pm UTC](https://discuss.elastic.co/t/debug-elasticsearch-without-basic-auth-xpack-security-enabled-false/379566 "2025-06-27T14:27:34Z")

</div>

Hi! I'm trying to startup Elasticsearch in a debugger via: ./gradlew run --debug-jvm I'm trying to also pass -Dxpack.security.enabled=false and I've tried a few things, including: export ES\_JAVA\_OPTS="-Dxpack.securi…

---

## [Http client did not trust this server's certificate, closing connection Netty4HttpChannel](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-closing-connection-netty4httpchannel/379418)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [June 27, 2025, 2:01pm UTC](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-closing-connection-netty4httpchannel/379418 "2025-06-27T14:01:27Z")

</div>

Hi All, Suddenly I was unable to execute any GET command via DevTools as I started getting 502 Bad gateway error as follows: GET /\_ssl/certificates { "statusCode": 502, "error": "Bad Gateway", "message": "certifi…

---

## [File system repository returning error](https://discuss.elastic.co/t/file-system-repository-returning-error/379330)

<div class="topic-metadata">

**Author:** [@JSElasticDiscuss](https://discuss.elastic.co/u/JSElasticDiscuss)\
**Replies:** 3\
**Last updated:** [June 27, 2025, 8:57am UTC](https://discuss.elastic.co/t/file-system-repository-returning-error/379330 "2025-06-27T08:57:42Z")

</div>

Hello, I have confirmed a valid path in my path.repo setting, but now when I do a 'verify repository' it gives me an error: { "name": "ResponseError", "message": "repository\_verification\_exception\\n\\tCaused by:\\n\\t…

---

## [Enrich Logs Without Breaking ECS or Overriding Default Pipelines](https://discuss.elastic.co/t/enrich-logs-without-breaking-ecs-or-overriding-default-pipelines/379523)

<div class="topic-metadata">

**Author:** [@khaled7](https://discuss.elastic.co/u/khaled7)\
**Replies:** 1\
**Last updated:** [June 27, 2025, 4:15am UTC](https://discuss.elastic.co/t/enrich-logs-without-breaking-ecs-or-overriding-default-pipelines/379523 "2025-06-27T04:15:42Z")

</div>

Hi everyone, I'm using the free version tier Elastic Stack v9.0.1 with the following setup: Kibana v9.0.1 - Elastic Agent (enrolled via Fleet) - Sysmon integration - Managed data streams like logs-windows.sysmon\_operati…

---

## [DocumentSubsetReader is holding on to large number of objects](https://discuss.elastic.co/t/documentsubsetreader-is-holding-on-to-large-number-of-objects/379455)

<div class="topic-metadata">

**Author:** [@vjgorla](https://discuss.elastic.co/u/vjgorla)\
**Replies:** 3\
**Last updated:** [June 27, 2025, 3:11am UTC](https://discuss.elastic.co/t/documentsubsetreader-is-holding-on-to-large-number-of-objects/379455 "2025-06-27T03:11:16Z")

</div>

On one of our nodes, NUM\_DOCS\_CACHE in elasticsearch/x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/security/authz/accesscontrol/DocumentSubsetReader.java at v8.11.1 · elastic/elasticsearch is holding on …

---

## [Range based join between two indices?](https://discuss.elastic.co/t/range-based-join-between-two-indices/379545)

<div class="topic-metadata">

**Author:** [@echan23](https://discuss.elastic.co/u/echan23)\
**Replies:** 1\
**Last updated:** [June 26, 2025, 6:11pm UTC](https://discuss.elastic.co/t/range-based-join-between-two-indices/379545 "2025-06-26T18:11:35Z")

</div>

I have two indices: IndexA with field Date\_time Index B with fields MoveInDateTime and MoveOutDateTime I want to join them on MoveInDateTime \<= Date\_time \<= MoveOutDateTime. Is this possible in Elasticsearch? If not,…

---

## [Es Rejected Exception \[es\_rejected\_execution\_exception\]](https://discuss.elastic.co/t/es-rejected-exception-es-rejected-execution-exception/379530)

<div class="topic-metadata">

**Author:** [@Sathya\_R](https://discuss.elastic.co/u/Sathya_R)\
**Replies:** 2\
**Last updated:** [June 26, 2025, 1:28pm UTC](https://discuss.elastic.co/t/es-rejected-exception-es-rejected-execution-exception/379530 "2025-06-26T13:28:15Z")

</div>

I am getting Es rejected Exception. I am having Elasticsearch setup in a server of 188GB RAM,32 GB is assigned to JVM heap of Elastic search.Remaing is off heap memory. I am having ~1TB data space.and i am querying on …

---

## [How to display Kubernetes metadata (namespace, pod name) in Elastic APM UI for microservices?](https://discuss.elastic.co/t/how-to-display-kubernetes-metadata-namespace-pod-name-in-elastic-apm-ui-for-microservices/379450)

<div class="topic-metadata">

**Author:** [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Replies:** 0\
**Last updated:** [June 24, 2025, 7:18pm UTC](https://discuss.elastic.co/t/how-to-display-kubernetes-metadata-namespace-pod-name-in-elastic-apm-ui-for-microservices/379450 "2025-06-24T19:18:26Z")

</div>

Hi everyone, Eck-stack version: 8.14.3 I'm using Elastic APM with OpenTelemetry to monitor microservices deployed in Kubernetes. I have the OpenTelemetry Collector configured with the k8sattributes processor to enrich …

---

## [Params.\_source is always null in script query](https://discuss.elastic.co/t/params-source-is-always-null-in-script-query/379484)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 1\
**Last updated:** [June 26, 2025, 5:31am UTC](https://discuss.elastic.co/t/params-source-is-always-null-in-script-query/379484 "2025-06-26T05:31:44Z")

</div>

The following two queries should return the same results: GET iam-api-accounts/\_search { "query": { "bool": { "filter": { "script": { "script": """ return params.\_source?.roles?…

---

## [Cold tier node shows in overview, but not listed in cluster stats. Is it partially attached?](https://discuss.elastic.co/t/cold-tier-node-shows-in-overview-but-not-listed-in-cluster-stats-is-it-partially-attached/379453)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 5\
**Last updated:** [June 26, 2025, 12:07am UTC](https://discuss.elastic.co/t/cold-tier-node-shows-in-overview-but-not-listed-in-cluster-stats-is-it-partially-attached/379453 "2025-06-26T00:07:11Z")

</div>

I'm thinking I have a node in my cold tier that is "hung" or in a bad state (hereafter referred to as instance 15, see screenshots). Like it's in the cluster but it's not fully in the cluster. Long story on how we got in…

---

## ["\[s3-repository\] path is not accessible on master node" error in v9](https://discuss.elastic.co/t/s3-repository-path-is-not-accessible-on-master-node-error-in-v9/379476)

<div class="topic-metadata">

**Author:** [@ali.gunay](https://discuss.elastic.co/u/ali.gunay)\
**Replies:** 0\
**Last updated:** [June 25, 2025, 2:42pm UTC](https://discuss.elastic.co/t/s3-repository-path-is-not-accessible-on-master-node-error-in-v9/379476 "2025-06-25T14:42:14Z")

</div>

Hello, I could create a S3 repository and take snapshot in v8.18 but after updated elaticsearch version to v9 while we were trying to create a s3 repository we got above error. { "error": { "root\_cause": \[ …

---

## [Self-hosted ES startup fails after upgrading 8.18.0 -\> 8.18.2 due to changes in entitlements](https://discuss.elastic.co/t/self-hosted-es-startup-fails-after-upgrading-8-18-0-8-18-2-due-to-changes-in-entitlements/379440)

<div class="topic-metadata">

**Author:** [@fheinonen](https://discuss.elastic.co/u/fheinonen)\
**Replies:** 3\
**Last updated:** [June 25, 2025, 10:22am UTC](https://discuss.elastic.co/t/self-hosted-es-startup-fails-after-upgrading-8-18-0-8-18-2-due-to-changes-in-entitlements/379440 "2025-06-25T10:22:15Z")

</div>

In our self-hosted hardened RHEL 8 installed via RPM Elasticsearch 8.18.2 a node failed to start due to changes made here. What would be a sustainable way to fix this error? Just remove this addition from entitlement-pol…

---

## [Ingest pipeline pattern matching - much help needed](https://discuss.elastic.co/t/ingest-pipeline-pattern-matching-much-help-needed/379207)

<div class="topic-metadata">

**Author:** [@SteveParker](https://discuss.elastic.co/u/SteveParker)\
**Replies:** 12\
**Last updated:** [June 24, 2025, 1:13pm UTC](https://discuss.elastic.co/t/ingest-pipeline-pattern-matching-much-help-needed/379207 "2025-06-24T13:13:43Z")

</div>

Hi all I am using the following ES|QL to pattern match a substring in a field from a filebeat index - FROM filebeat-\* | WHERE url.original LIKE "q=" It would make a lot of sense to drop any incoming documents that do…

---

## [Drop user IP from logs after x days](https://discuss.elastic.co/t/drop-user-ip-from-logs-after-x-days/379253)

<div class="topic-metadata">

**Author:** [@dklenke1](https://discuss.elastic.co/u/dklenke1)\
**Replies:** 6\
**Last updated:** [June 24, 2025, 12:37pm UTC](https://discuss.elastic.co/t/drop-user-ip-from-logs-after-x-days/379253 "2025-06-24T12:37:00Z")

</div>

Hi, I'm new to elasticsearch and running version 9.0.2 deployed with the elastic operator 3.0.0 to my kubernetes cluster. I ingest access logs from multiple web proxies into elasticsearch. These logs contain the IP of t…

---

## [Elastic search v8.18.2 fails to boot up in FIPS mode because of MD5 invocation in ESQL plugin](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118)

<div class="topic-metadata">

**Author:** [@k.rajendran](https://discuss.elastic.co/u/k.rajendran)\
**Replies:** 3\
**Last updated:** [June 24, 2025, 2:42am UTC](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118 "2025-06-24T02:42:22Z")

</div>

I am trying to upgrade our Elasticsearch FIPS enabled cluster from v8.17.4 to 8.18.2. When I tried doing this the initialization failed with this error: \[2025-06-09T20:46:40,119\]\[ERROR\]\[o.e.b.Elasticsearch \]\[elasticsear…

---

## [Optimizing Elasticsearch Indexing for Real-Time IoT Sensor Data Streams](https://discuss.elastic.co/t/optimizing-elasticsearch-indexing-for-real-time-iot-sensor-data-streams/379421)

<div class="topic-metadata">

**Author:** [@aria\_234](https://discuss.elastic.co/u/aria_234)\
**Replies:** 1\
**Last updated:** [June 24, 2025, 2:27am UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-indexing-for-real-time-iot-sensor-data-streams/379421 "2025-06-24T02:27:33Z")

</div>

Hi all, I'm currently setting up Elasticsearch to handle continuous, real-time IoT sensor data (temperature, humidity, motion, etc.). Essentially, multiple devices send small packets of data every few seconds, and I aim …

---

## [Wrong result by big index](https://discuss.elastic.co/t/wrong-result-by-big-index/378214)

<div class="topic-metadata">

**Author:** [@Alex\_Dgero](https://discuss.elastic.co/u/Alex_Dgero)\
**Replies:** 8\
**Last updated:** [June 23, 2025, 9:37pm UTC](https://discuss.elastic.co/t/wrong-result-by-big-index/378214 "2025-06-23T21:37:49Z")

</div>

Hello. I use elasticsearch v8.17.2. I need to do simple search by very big index 40M+ docs. But i works unexpected. My index have default analyzer without tokenization. So I can use only "phrase\_prefix" for search by sta…

---

## [Elasticsearch Machine Learning Architecture and Requirements](https://discuss.elastic.co/t/elasticsearch-machine-learning-architecture-and-requirements/379358)

<div class="topic-metadata">

**Author:** [@Wei\_Li](https://discuss.elastic.co/u/Wei_Li)\
**Replies:** 1\
**Last updated:** [June 23, 2025, 6:47pm UTC](https://discuss.elastic.co/t/elasticsearch-machine-learning-architecture-and-requirements/379358 "2025-06-23T18:47:10Z")

</div>

Hi, I'm looking into integrating machine learning capabilities with Elasticsearch and have a few questions regarding architectural considerations and prerequisites for ML features. 1.Architectural Placement of ML Compo…

---

## [Hyphen (dash) tokenizing](https://discuss.elastic.co/t/hyphen-dash-tokenizing/358226)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 1\
**Last updated:** [June 23, 2025, 3:22pm UTC](https://discuss.elastic.co/t/hyphen-dash-tokenizing/358226 "2025-06-23T15:22:21Z")

</div>

Hello. I'm trying to make it so queries for "Tiger's-Eye" and "Tiger's Eye" and "Tiger Eye" and "Tiger-Eye" (without quotes) all return the same results WITHOUT USING SYNONYMS. I can do this part with my tokenizer and …

---

## [Ingest Processor for array object data using script](https://discuss.elastic.co/t/ingest-processor-for-array-object-data-using-script/379375)

<div class="topic-metadata">

**Author:** [@adude946](https://discuss.elastic.co/u/adude946)\
**Replies:** 2\
**Last updated:** [June 20, 2025, 7:14pm UTC](https://discuss.elastic.co/t/ingest-processor-for-array-object-data-using-script/379375 "2025-06-20T19:14:23Z")

</div>

Need assist to get the Ingest pipeline processors to work correctly for my sample data. Its an array of objects, trying to create individual objects from each array object using a value data + prefix names based on these…

---

## [Top-Level knn with collapse: Accuracy-Performance Trade-off & Filter Behavior](https://discuss.elastic.co/t/top-level-knn-with-collapse-accuracy-performance-trade-off-filter-behavior/379349)

<div class="topic-metadata">

**Author:** [@Rami\_Salman](https://discuss.elastic.co/u/Rami_Salman)\
**Replies:** 1\
**Last updated:** [June 20, 2025, 7:36am UTC](https://discuss.elastic.co/t/top-level-knn-with-collapse-accuracy-performance-trade-off-filter-behavior/379349 "2025-06-20T07:36:50Z")

</div>

Hello Elasticsearch Community, I'm facing a critical challenge trying to balance search accuracy and performance when combining kNN queries with collapse and inner\_hits in Elasticsearch 8.17. I'm seeing a puzzling filte…

---

## [Mapping: Allowing to load booleans eagerly as global ordinals like keyword](https://discuss.elastic.co/t/mapping-allowing-to-load-booleans-eagerly-as-global-ordinals-like-keyword/375723)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 3\
**Last updated:** [June 20, 2025, 7:32am UTC](https://discuss.elastic.co/t/mapping-allowing-to-load-booleans-eagerly-as-global-ordinals-like-keyword/375723 "2025-06-20T07:32:19Z")

</div>

Hey, keywords can be configured to be loaded eagerly as global ordinals in the mapping. This is important to not run into delays if a query hits a segment for first time. I've been wondering if such an option should al…

---

## [Unable to delete documents from full index](https://discuss.elastic.co/t/unable-to-delete-documents-from-full-index/379266)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 17\
**Last updated:** [June 20, 2025, 5:37am UTC](https://discuss.elastic.co/t/unable-to-delete-documents-from-full-index/379266 "2025-06-20T05:37:42Z")

</div>

Hi; I have an application with one build-in Elasticsearch node used for collecting log events into 3 indices. The application is deployed at several sites. At some point in the future the implementation is going to be …

---

## [Difference between regular induces and logsdb (datastreams)](https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324)

<div class="topic-metadata">

**Author:** [@roman.stupko](https://discuss.elastic.co/u/roman.stupko)\
**Replies:** 3\
**Last updated:** [June 19, 2025, 8:21pm UTC](https://discuss.elastic.co/t/difference-between-regular-induces-and-logsdb-datastreams/379324 "2025-06-19T20:21:16Z")

</div>

Hi, I recently decided to move my k8s cluster logs from regular induces to logsdb type of datastreams. For my induces now i use: dynamic mapping for all string fields to keyword (except message field, which i use for…

---

## [Why i got different result of aggregation?](https://discuss.elastic.co/t/why-i-got-different-result-of-aggregation/379289)

<div class="topic-metadata">

**Author:** [@Zoree](https://discuss.elastic.co/u/Zoree)\
**Replies:** 1\
**Last updated:** [June 19, 2025, 4:56pm UTC](https://discuss.elastic.co/t/why-i-got-different-result-of-aggregation/379289 "2025-06-19T16:56:33Z")

</div>

I have queries with aggregation, the query section is the same for both, but the aggregation section is a little different and I don't understand why the different results are coming. agg1: { "aggs": { "Met…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=26)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=28)
