# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=270

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 271

---

## [Start Elasticsearch with preloaded index](https://discuss.elastic.co/t/start-elasticsearch-with-preloaded-index/330299)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 4:54pm UTC](https://discuss.elastic.co/t/start-elasticsearch-with-preloaded-index/330299 "2023-04-19T16:54:53Z")

</div>

Is there any way we can start the elasticsearch instance with a preloaded index data? Just like we do in postgres: Creating a Docker image with a preloaded database | Coding with Coffee

---

## [Anomaly Detection transactions financial data](https://discuss.elastic.co/t/anomaly-detection-transactions-financial-data/330207)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 7:57am UTC](https://discuss.elastic.co/t/anomaly-detection-transactions-financial-data/330207 "2023-04-19T07:57:05Z")

</div>

I have a data set that holds data like this: I want to create an anomaly detection job that alerts about suspicious large transactions but when I create a anomaly detection job it always looks at for example 1 day an…

---

## [Count number of times an index was searched](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 6:30am UTC](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260 "2023-04-19T06:30:58Z")

</div>

Hi team! Is there a way to find out how many times a particular index was searched/queries? If not a direct API in elastic, is there a workaround to get this metric?

---

## [AI-powered Elastic search alternative, for small project?](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261)

<div class="topic-metadata">

**Author:** [@c\_u\_be\_binh\_an](https://discuss.elastic.co/u/c_u_be_binh_an)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 4:51am UTC](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261 "2023-04-19T04:51:04Z")

</div>

I am developing a job board using NodeJs and it currently has around 1,000 items. However, I am facing an issue with deploying it on a 1GB RAM VPS as it cannot run Elastic Search on it. Therefore, I am searching for a li…

---

## [Mail enable smtp activity logs](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672 "2023-04-19T04:29:45Z")

</div>

Hello everyone I am trying to pars mail enable activity loga there are millions of logs in un even pattern I write some of the pattern and logs pars in well manner ans structured but now the issue is so many logs parsin…

---

## [How to monitor detail why elasstic data node is overloaded](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 4:25am UTC](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105 "2023-04-19T04:25:39Z")

</div>

our elastic is v8.6 3 master, 40x datanode (8core/32GB/2TB) , 2x loadbalancer node We ingest 100k-900K events/sec by few hundreds of different ingest pipelines, some of them creates small indices but there is about 5-…

---

## [Getting 403 denied to elastic.co (for anything: apt refresh, wget, etc)](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/329903)

<div class="topic-metadata">

**Author:** [@olegkrysinov](https://discuss.elastic.co/u/olegkrysinov)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:20am UTC](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/329903 "2023-04-19T02:20:28Z")

</div>

Hello! I\`ve a problem (( Error:1 https://artifacts.elastic.co:443/packages/8.x/apt stable InRelease 403 Forbidden \[IP: 34.120.127.130 443\] E: Failed to fetch http://artifacts.elastic.co/packages/8.x/apt/dists/stable/I…

---

## [Move all Indexes to new host](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:14am UTC](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825 "2023-04-19T02:14:39Z")

</div>

Hello, I have a host for Warm and another to Cold Phase without replicas configured. Now, I need to proceed to a maintenance on this Warm host, so i wanted to move all those Warm Indexes temporarily to Cold host (Added …

---

## [Error generating a custom certificate and private key for Fleet Server](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 12:57am UTC](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256 "2023-04-19T00:57:13Z")

</div>

Hi Elastic community I am generating my certificates to my Fleet Server Step1 ./bin/elasticsearch-certutil ca --pem i moved my CA.cert & ca.key to /path/to/ca Step2: ./bin/elasticsearch-certutil cert --name Flee…

---

## [Cluster health wrong yellow spikes (because new index ?)](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 7\
**Last updated:** [April 18, 2023, 10:53pm UTC](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124 "2023-04-18T22:53:25Z")

</div>

We are running elasticsearch on kubernetes, via the ECK operator. Every day we receive at least 4 alerts about elasticsearch cluster health go to yellow. Also, we use argocd to deploy it, the health check script here a…

---

## [Mapping Error with Run Time Field](https://discuss.elastic.co/t/mapping-error-with-run-time-field/330231)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 5:25pm UTC](https://discuss.elastic.co/t/mapping-error-with-run-time-field/330231 "2023-04-18T17:25:18Z")

</div>

Hello, I'm having issues with runtime fields with Elastic. I have this run time field working fine in Kibana, however, I need this field to be present in the database. I simplified the script, mostly to redact it's sen…

---

## [Ask For help](https://discuss.elastic.co/t/ask-for-help/330234)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:50pm UTC](https://discuss.elastic.co/t/ask-for-help/330234 "2023-04-18T15:50:11Z")

</div>

Good morning I'm doing an internship in Business intelligence working to collect data from odoo.sh to ELK Stack I'm working in odoo.sh. I want to ask you about the integration of the module in odoo.sh is possible or no…

---

## ["reset" ILM failed step](https://discuss.elastic.co/t/reset-ilm-failed-step/327754)

<div class="topic-metadata">

**Author:** [@pestevao](https://discuss.elastic.co/u/pestevao)\
**Replies:** 7\
**Last updated:** [April 18, 2023, 3:40pm UTC](https://discuss.elastic.co/t/reset-ilm-failed-step/327754 "2023-04-18T15:40:44Z")

</div>

Hello, I've some restricted indices stuck on ILM actions because of permissions. security\_exception: action \[indices:admin/delete\] is unauthorized for user \[xxx\] with roles \[superuser\] on restricted indices \[.ds-.fleet…

---

## [Filter result by collapsed date](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235)

<div class="topic-metadata">

**Author:** [@Mickael\_BARBIER](https://discuss.elastic.co/u/Mickael_BARBIER)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 3:35pm UTC](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235 "2023-04-18T15:35:32Z")

</div>

Hello, i have a topic/news system (a topic can have many news in different language) i want to get the oldest news of each topic. And i want the result sorted by the oldest news displayedAt column. ex: topic1 -News…

---

## [How to build query using elastic8 java client](https://discuss.elastic.co/t/how-to-build-query-using-elastic8-java-client/330194)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:14pm UTC](https://discuss.elastic.co/t/how-to-build-query-using-elastic8-java-client/330194 "2023-04-18T15:14:25Z")

</div>

I need one example where using elastic 8 dsl creates query which includes boolquery with should shouldnot must .query(q -\> q.bool( b -\> b.must(ListObj).should(listShould).mustNot(listMustNot)…

---

## [Sort document based on a field value](https://discuss.elastic.co/t/sort-document-based-on-a-field-value/330084)

<div class="topic-metadata">

**Author:** [@mohammedsajidkhaleel](https://discuss.elastic.co/u/mohammedsajidkhaleel)\
**Replies:** 8\
**Last updated:** [April 18, 2023, 2:41pm UTC](https://discuss.elastic.co/t/sort-document-based-on-a-field-value/330084 "2023-04-18T14:41:19Z")

</div>

Hi, Am having a real estate ads and I would like sort the document based on the users current city. All ads based on the current user city should be on top and other cities ads should be after this. What is the option t…

---

## [Significant terms aggregation returns incorrect bg\_count value when querying index with nested objects in version 8.3.3](https://discuss.elastic.co/t/significant-terms-aggregation-returns-incorrect-bg-count-value-when-querying-index-with-nested-objects-in-version-8-3-3/329466)

<div class="topic-metadata">

**Author:** [@shimpeko](https://discuss.elastic.co/u/shimpeko)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 1:51pm UTC](https://discuss.elastic.co/t/significant-terms-aggregation-returns-incorrect-bg-count-value-when-querying-index-with-nested-objects-in-version-8-3-3/329466 "2023-04-18T13:51:28Z")

</div>

Significant terms aggregation returns incorrect bg\_count value when querying index with nested objects. The value is the same as the document counts returned by \_cat/indices API (which returns Lucene-level doc count). I'…

---

## [How to set alert on total size of indices matching a pattern?](https://discuss.elastic.co/t/how-to-set-alert-on-total-size-of-indices-matching-a-pattern/330159)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 1:50pm UTC](https://discuss.elastic.co/t/how-to-set-alert-on-total-size-of-indices-matching-a-pattern/330159 "2023-04-18T13:50:14Z")

</div>

Hi! I've posted this question on SO: elastic stack - Elasticsearch how to set alert on total size of indices matching a pattern? - Stack Overflow but am re-posting it here in hopes to get a more focused audience …

---

## [Elasticsearch Down](https://discuss.elastic.co/t/elasticsearch-down/330175)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 12:48pm UTC](https://discuss.elastic.co/t/elasticsearch-down/330175 "2023-04-18T12:48:19Z")

</div>

hi community My elasticsearch Server is Down, ¿what could be happening? Elasticsearch 8.7 1) systemctl status elasticsearch elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.ser…

---

## [Elasticsearch 8: new OOM kills in comparison with ES7](https://discuss.elastic.co/t/elasticsearch-8-new-oom-kills-in-comparison-with-es7/330016)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 9\
**Last updated:** [April 18, 2023, 12:31pm UTC](https://discuss.elastic.co/t/elasticsearch-8-new-oom-kills-in-comparison-with-es7/330016 "2023-04-18T12:31:28Z")

</div>

We test Elasticsearch 8.7.0 cluster setup (to migrate from ES 7.17.9) and we face the problem that the voting-only node in the testing cluster is sometimes killed by OOM. We use almost identical setup like in our curr…

---

## [How to use Spark API to update and insert data in ES](https://discuss.elastic.co/t/how-to-use-spark-api-to-update-and-insert-data-in-es/330216)

<div class="topic-metadata">

**Author:** [@skyruan](https://discuss.elastic.co/u/skyruan)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 11:30am UTC](https://discuss.elastic.co/t/how-to-use-spark-api-to-update-and-insert-data-in-es/330216 "2023-04-18T11:30:29Z")

</div>

There is a issue: there are 4 fields named id,a,b,c if the id is same,i just want to use the latest data to update the value of a，and b,c not handle, if the id is different,adding the record in ES

---

## [How to read Data from ES response](https://discuss.elastic.co/t/how-to-read-data-from-es-response/330213)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 5\
**Last updated:** [April 18, 2023, 11:24am UTC](https://discuss.elastic.co/t/how-to-read-data-from-es-response/330213 "2023-04-18T11:24:21Z")

</div>

Hi, so I see the response of ES is tied to the kind of Query I write. I know Kibana is able to map it into charts so there must be a formal way of extracting information of BUCKETS property. Can I get info about it or is…

---

## [Cross-Cluster Prices](https://discuss.elastic.co/t/cross-cluster-prices/330210)

<div class="topic-metadata">

**Author:** [@Joelgoncalves3000](https://discuss.elastic.co/u/Joelgoncalves3000)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 10:18am UTC](https://discuss.elastic.co/t/cross-cluster-prices/330210 "2023-04-18T10:18:19Z")

</div>

If I have a cluster with 3 nodes what would be the price of an enterprise license? And if I have a cross-cluster with 2 clusters with 3 nodes each, what would be the price?

---

## [Kibana objects on elasticsearch container](https://discuss.elastic.co/t/kibana-objects-on-elasticsearch-container/329821)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 9:52am UTC](https://discuss.elastic.co/t/kibana-objects-on-elasticsearch-container/329821 "2023-04-18T09:52:40Z")

</div>

hello i want to mount volume of dashboards and visualizalisation in elasticsearch container how can i do it pleaze

---

## [Read data from influxdb from elasticsearch](https://discuss.elastic.co/t/read-data-from-influxdb-from-elasticsearch/329707)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 9:21am UTC](https://discuss.elastic.co/t/read-data-from-influxdb-from-elasticsearch/329707 "2023-04-18T09:21:31Z")

</div>

Hi need to read data from influxdb from elasticsearch and store on an index. I have two choice 1-telegraf 2-logstash need "input plugin for influx" and "output plugin for elastic". Any idea? Thanks

---

## [How to copy path to elastic cloud?](https://discuss.elastic.co/t/how-to-copy-path-to-elastic-cloud/330199)

<div class="topic-metadata">

**Author:** [@loong](https://discuss.elastic.co/u/loong)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 8:41am UTC](https://discuss.elastic.co/t/how-to-copy-path-to-elastic-cloud/330199 "2023-04-18T08:41:25Z")

</div>

Hi., I am new here. I would like to create hyphenation\_decompounder token filter on elastic cloud, but I should be able to copy the \*.xml file and the wordlist\_path. how can I copy it into? I got this error ApiError(5…

---

## [Elasticsearch 7.3.2 with java 8 and tcp client access from the java 17 running application](https://discuss.elastic.co/t/elasticsearch-7-3-2-with-java-8-and-tcp-client-access-from-the-java-17-running-application/330185)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 8:29am UTC](https://discuss.elastic.co/t/elasticsearch-7-3-2-with-java-8-and-tcp-client-access-from-the-java-17-running-application/330185 "2023-04-18T08:29:40Z")

</div>

Hi We are using elasticsearch 7.3.2 version with java 8 and with the tcp client we are accessing the cluster from the java application running with java 17 is there any issue in this

---

## [SSL Certificate problem : Unable to get local issuer certificate](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125)

<div class="topic-metadata">

**Author:** [@dinbabs](https://discuss.elastic.co/u/dinbabs)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125 "2023-04-18T01:18:21Z")

</div>

Hi, I have deployed standalone Elasticsearch in one of the VM instance of Google Cloud(GCP). The client(Manychat) which I use to connect to Elasticsearch only supports https, so I did the configurations to run Elastics…

---

## [Subject query data of restaurants by given location topic that we desire for a year](https://discuss.elastic.co/t/subject-query-data-of-restaurants-by-given-location-topic-that-we-desire-for-a-year/330167)

<div class="topic-metadata">

**Author:** [@Nonchaianon](https://discuss.elastic.co/u/Nonchaianon)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 10:15pm UTC](https://discuss.elastic.co/t/subject-query-data-of-restaurants-by-given-location-topic-that-we-desire-for-a-year/330167 "2023-04-17T22:15:42Z")

</div>

Dear elasticsearch technical I’am developer Food delivery platform We desire to improve performance query data of restaurants by given location Condition -50,000 restaurant -200 km^2 -queries 200,000 times per day …

---

## [Help with data management, I have an index with a size of 119GB, what can I do?](https://discuss.elastic.co/t/help-with-data-management-i-have-an-index-with-a-size-of-119gb-what-can-i-do/329866)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 10:00pm UTC](https://discuss.elastic.co/t/help-with-data-management-i-have-an-index-with-a-size-of-119gb-what-can-i-do/329866 "2023-04-17T22:00:36Z")

</div>

I have an index with a size of 119GB that is causing performance issues when search the data. My first thought was to use an index policy to expire old documents but soon I learned the lifecycle policy only works for t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=269)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=271)
