# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=273

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 274

---

## [Indices in red state. "cannot allocate because all found copies of the shard are either stale or corrupt"](https://discuss.elastic.co/t/indices-in-red-state-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/328871)

<div class="topic-metadata">

**Author:** [@Bhuvesh\_Seth](https://discuss.elastic.co/u/Bhuvesh_Seth)\
**Replies:** 10\
**Last updated:** [April 13, 2023, 6:20am UTC](https://discuss.elastic.co/t/indices-in-red-state-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/328871 "2023-04-13T06:20:08Z")

</div>

Hi, we are facing one issue where some of indices health not getting updated to yellow or green due to this error "cannot allocate because all found copies of the shard are either stale or corrupt". Can someone please gu…

---

## [MAX\_LOCKED\_MEMORY=unlimited setting in Elasticsearch 8.x](https://discuss.elastic.co/t/max-locked-memory-unlimited-setting-in-elasticsearch-8-x/329884)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 5:34am UTC](https://discuss.elastic.co/t/max-locked-memory-unlimited-setting-in-elasticsearch-8-x/329884 "2023-04-13T05:34:29Z")

</div>

Is MAX\_LOCKED\_MEMORY=unlimited settings in /etc/default/elasticsearch (on Ubuntu) still necessary in Elasticsearch 8.x? It looks like settings in /etc/default/elasticsearch system configuration file is quite simplified …

---

## [Removing one of the s3 snapshot repository causing connection pool shutdown](https://discuss.elastic.co/t/removing-one-of-the-s3-snapshot-repository-causing-connection-pool-shutdown/329857)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 2:31am UTC](https://discuss.elastic.co/t/removing-one-of-the-s3-snapshot-repository-causing-connection-pool-shutdown/329857 "2023-04-13T02:31:02Z")

</div>

Hello - When we configure single S3 bucket for backup, snapshot functionality is working as expected. But when we create a additional repository and remove it afterwards, elasticsearch snapshot functionality is failing t…

---

## [Date parse error](https://discuss.elastic.co/t/date-parse-error/329871)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 9:23pm UTC](https://discuss.elastic.co/t/date-parse-error/329871 "2023-04-12T21:23:30Z")

</div>

Hello, I have recently got this problem with parsing date of this format '2022-08-02T9:00:00 AMZ'. failed to parse field \[Date\] of type \[date\] in document with id 'uVxVd4cB4mQncJVwtSB8'. Preview of field's value: '2022-…

---

## [Disabling Hostname Verification on Elasticsearch 7.16 Outbound Connections](https://discuss.elastic.co/t/disabling-hostname-verification-on-elasticsearch-7-16-outbound-connections/329816)

<div class="topic-metadata">

**Author:** [@icey7z](https://discuss.elastic.co/u/icey7z)\
**Replies:** 4\
**Last updated:** [April 12, 2023, 8:01pm UTC](https://discuss.elastic.co/t/disabling-hostname-verification-on-elasticsearch-7-16-outbound-connections/329816 "2023-04-12T20:01:16Z")

</div>

I'm trying to do a remote reindexing from a 5.3 cluster to a 7.16 cluster, and need a way to disable hostname verification when communicating between them. The 5.3 cluster's certificate doesn't match the hostname, and I…

---

## [Remote cluster license with ECK operator](https://discuss.elastic.co/t/remote-cluster-license-with-eck-operator/329861)

<div class="topic-metadata">

**Author:** [@gidonshn](https://discuss.elastic.co/u/gidonshn)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:42pm UTC](https://discuss.elastic.co/t/remote-cluster-license-with-eck-operator/329861 "2023-04-12T17:42:50Z")

</div>

Hi all. I have an ECK operator and that manages two ES clusters in the same k8s namespace. I'm trying to configure one of them as a remote cluster in the other. looking at this doc: https://www.elastic.co/guide/en/cl…

---

## [Script access to nested field](https://discuss.elastic.co/t/script-access-to-nested-field/329860)

<div class="topic-metadata">

**Author:** [@GR8](https://discuss.elastic.co/u/GR8)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:42pm UTC](https://discuss.elastic.co/t/script-access-to-nested-field/329860 "2023-04-12T16:42:02Z")

</div>

Hello Elastic folks, I need to run a script that gets data from index\_a to index\_b with some basic ETL. This works well except I can't figure out the syntax for accessing a nested field like: "transitions": { "prope…

---

## [I need help to undertand "GET \<target\>/\_ilm/explain" output for ILM policy phases moving](https://discuss.elastic.co/t/i-need-help-to-undertand-get-target-ilm-explain-output-for-ilm-policy-phases-moving/327912)

<div class="topic-metadata">

**Author:** [@LizardNerd](https://discuss.elastic.co/u/LizardNerd)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 9:22am UTC](https://discuss.elastic.co/t/i-need-help-to-undertand-get-target-ilm-explain-output-for-ilm-policy-phases-moving/327912 "2023-03-17T09:22:19Z")

</div>

Hi there, I'm fairly new to Elastic Stack. I created an ILM policy for my first data stream, then I ran: GET .ds-logs-pfsense.log-default-2023.01.26-000004/\_ilm/explain This is the output: { "indices": { ".ds-lo…

---

## [Elastic phrase suggester](https://discuss.elastic.co/t/elastic-phrase-suggester/329858)

<div class="topic-metadata">

**Author:** [@sujata1993](https://discuss.elastic.co/u/sujata1993)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:16pm UTC](https://discuss.elastic.co/t/elastic-phrase-suggester/329858 "2023-04-12T16:16:49Z")

</div>

Query: POST merchants\_phrase\_suggester\_29032023/\_search { "suggest": { "text" : "amazn,walmart", "simple\_phrase" : { "phrase" : { "field" : "mrch\_nm.trigram", "size" : 1, "confidence":0, "gram\_size":3, "max…

---

## [What triggers regular merges?](https://discuss.elastic.co/t/what-triggers-regular-merges/329773)

<div class="topic-metadata">

**Author:** [@Emma\_Vaiserfirov](https://discuss.elastic.co/u/Emma_Vaiserfirov)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 3:58pm UTC](https://discuss.elastic.co/t/what-triggers-regular-merges/329773 "2023-04-12T15:58:46Z")

</div>

Hi there, we're trying to decide if we need to trigger force merges on a regular basis. To do that, I was trying to understand how (and how often) merges are triggered by default. The piece of public documentation on mer…

---

## [Data view - number of Index timeout issue](https://discuss.elastic.co/t/data-view-number-of-index-timeout-issue/329769)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:58pm UTC](https://discuss.elastic.co/t/data-view-number-of-index-timeout-issue/329769 "2023-04-12T14:58:34Z")

</div>

I have large index with high volume of data. one shard is 20gig, Lets say two index per day from six month = 360 index with billions of record combine. when I run following it timesout select x,y,z from myidex-\* wh…

---

## [Elastic Aggregations query](https://discuss.elastic.co/t/elastic-aggregations-query/329807)

<div class="topic-metadata">

**Author:** [@math1](https://discuss.elastic.co/u/math1)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 2:33pm UTC](https://discuss.elastic.co/t/elastic-aggregations-query/329807 "2023-04-12T14:33:39Z")

</div>

POST test/\_doc/ { "food": \[ { "food1": { "type": "Western food", "name": "hamburger" }, "food2": { "type": "Japanese food", "name": "sushi" } } \] } POS…

---

## [Licence: install Elastic 7.16.2 Free or Platinum on Kubernetes](https://discuss.elastic.co/t/licence-install-elastic-7-16-2-free-or-platinum-on-kubernetes/329576)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 10\
**Last updated:** [April 12, 2023, 2:21pm UTC](https://discuss.elastic.co/t/licence-install-elastic-7-16-2-free-or-platinum-on-kubernetes/329576 "2023-04-12T14:21:31Z")

</div>

HI Guys, I would like to install all ELK stack (Elasticsearch, Logstash and Kibana) on Kubernets. I'm undecided if using the Free or Platinum version but before proceeding I would like to know if there are any limits on…

---

## [Search: Removing full stop if part of acronym / abbreviation with pattern\_replace character filter](https://discuss.elastic.co/t/search-removing-full-stop-if-part-of-acronym-abbreviation-with-pattern-replace-character-filter/329810)

<div class="topic-metadata">

**Author:** [@Marzipan](https://discuss.elastic.co/u/Marzipan)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:24am UTC](https://discuss.elastic.co/t/search-removing-full-stop-if-part-of-acronym-abbreviation-with-pattern-replace-character-filter/329810 "2023-04-12T08:24:05Z")

</div>

Hi! My input are author names and book titles. I try to delete full stops if they appear in acronyms and abbreviations. For example: S.O.S. should be replaced with SOS H.P. Lovecraft should be replaced with HP Lovec…

---

## [Can't create a cluster if node's domain points to the localhost in /etc/hosts](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738)

<div class="topic-metadata">

**Author:** [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Replies:** 8\
**Last updated:** [April 12, 2023, 2:06pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738 "2023-04-12T14:06:37Z")

</div>

Hi, if /etc/hosts/ is configured as follows: 127.0.0.1 node01.com 127.0.0.1 localhost and if you set elasticsearch.yml to: network.host: \["\_enp1s0\_", "\_local\_"\] …

---

## [Elasticsearch how to correctly calculate the number of shards](https://discuss.elastic.co/t/elasticsearch-how-to-correctly-calculate-the-number-of-shards/329834)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 12:47pm UTC](https://discuss.elastic.co/t/elasticsearch-how-to-correctly-calculate-the-number-of-shards/329834 "2023-04-12T12:47:56Z")

</div>

the question is about the intricacies of configuration. Situation - there is one physical server. Two CPUs. 20 cores in total. The task is to load there a lot of text - about 250 millions of records. Each of which a coup…

---

## [Multiple bulk actions on the same document](https://discuss.elastic.co/t/multiple-bulk-actions-on-the-same-document/329650)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/multiple-bulk-actions-on-the-same-document/329650 "2023-04-12T12:44:52Z")

</div>

Hi, To index data into Elasticsearch, we are using an Apache Flink pipeline that is consuming from Kafka topics. The index mapping looks something like below, a document with nested documents: { "name": "email documen…

---

## [Painless script to find the difference between two timestamp values](https://discuss.elastic.co/t/painless-script-to-find-the-difference-between-two-timestamp-values/329829)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 12:31pm UTC](https://discuss.elastic.co/t/painless-script-to-find-the-difference-between-two-timestamp-values/329829 "2023-04-12T12:31:31Z")

</div>

Hi All, I am trying to define a scripted field in ES 7.17 scope where the difference between two timestamp field values need to be defined. I did looked into the painless documentation, but could not exactly find some …

---

## [Query to Select Document based on only one object to be present under Node](https://discuss.elastic.co/t/query-to-select-document-based-on-only-one-object-to-be-present-under-node/329824)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 12:14pm UTC](https://discuss.elastic.co/t/query-to-select-document-based-on-only-one-object-to-be-present-under-node/329824 "2023-04-12T12:14:43Z")

</div>

Hi, We have data indexed as below { "tags": { "firstlevel": { "events": \[\], "promotions": \[\] } } } Data can be something like which has both events and promotions, just events or just promotion…

---

## [\[Elastic search\] wildcard (ignore case) query is not working](https://discuss.elastic.co/t/elastic-search-wildcard-ignore-case-query-is-not-working/329701)

<div class="topic-metadata">

**Author:** [@K\_Nam](https://discuss.elastic.co/u/K_Nam)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 11:37am UTC](https://discuss.elastic.co/t/elastic-search-wildcard-ignore-case-query-is-not-working/329701 "2023-04-12T11:37:01Z")

</div>

I have a problem when using wildcard (ignore case) query. I am using v7.10.2 Uppercase Lower case I have 2 query, the first is uppercase, the other is not. My expected output is both query will return the same r…

---

## [Esrally client option](https://discuss.elastic.co/t/esrally-client-option/329638)

<div class="topic-metadata">

**Author:** [@tmdgk490255](https://discuss.elastic.co/u/tmdgk490255)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 9:32am UTC](https://discuss.elastic.co/t/esrally-client-option/329638 "2023-04-12T09:32:40Z")

</div>

there is some options to specify the number of clients for certain operation in rally track "schedule": \[ { "operation": "force-merge", "clients": 1 // here }, { "operation": "match-all-qu…

---

## [Search: Filter data after an aggregation](https://discuss.elastic.co/t/search-filter-data-after-an-aggregation/329760)

<div class="topic-metadata">

**Author:** [@gutierrezfj](https://discuss.elastic.co/u/gutierrezfj)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 10:25am UTC](https://discuss.elastic.co/t/search-filter-data-after-an-aggregation/329760 "2023-04-12T10:25:17Z")

</div>

Hi community. I have made a query to obtain the average number of bytes per browser type, but I require that only the data that has an average less than 5000 be displayed or retrieved. I have read a lot but nothing con…

---

## [How to create new field after subtracting 2 date time field](https://discuss.elastic.co/t/how-to-create-new-field-after-subtracting-2-date-time-field/329822)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 10:08am UTC](https://discuss.elastic.co/t/how-to-create-new-field-after-subtracting-2-date-time-field/329822 "2023-04-12T10:08:19Z")

</div>

I want to create one new field type String in existing index after subtracting two datetime (format - 2023-04-31 23:23:13). It should return 'Type-1' if seconds difference is more than or equal to 180 and should return '…

---

## [ELK on AWS](https://discuss.elastic.co/t/elk-on-aws/329819)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 9:25am UTC](https://discuss.elastic.co/t/elk-on-aws/329819 "2023-04-12T09:25:14Z")

</div>

Hi Team, We did install elk \[3 elastic nodes and 2 kibana nodes on us-east-1a,us-east-1b\] on AWS. We are trying to access Kibana dashboard via NLB with ACM\[AWS certificate Manager\] ,but somehow when I am starting kiba…

---

## [How elasticsearch distribute the requests from client](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815)

<div class="topic-metadata">

**Author:** [@qksjdhi1212](https://discuss.elastic.co/u/qksjdhi1212)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 8:53am UTC](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815 "2023-04-12T08:53:27Z")

</div>

I want to know the whole process where elasticsearch distribute the request received from client server (logstash, application, fluentd etc.) does the master node in cluster just assign the request to the most stable no…

---

## [Are there any guidelines to estimate how many snapshots can be handled by elasticsearch with specific amount of memory/cpu](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/are-there-any-guidelines-to-estimate-how-many-snapshots-can-be-handled-by-elasticsearch-with-specific-amount-of-memory-cpu/329811 "2023-04-12T08:29:34Z")

</div>

HI - I am looking for any data or estimates if we can derive about retaining the snapshots based on size of the cluster. E.g. If we have a smaller elastic cluster with 2G of memory allocation, and SLM with each 15 min s…

---

## [Elasticsearch 8.7, "master\_not\_discovered\_exception" error](https://discuss.elastic.co/t/elasticsearch-8-7-master-not-discovered-exception-error/329495)

<div class="topic-metadata">

**Author:** [@Jyotsna\_Bhati](https://discuss.elastic.co/u/Jyotsna_Bhati)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-master-not-discovered-exception-error/329495 "2023-04-12T06:32:54Z")

</div>

Upgraded elasticsearch from 7.17 to 8.7. Elasticsearch service is running but not able to discover other nodes. Ran: curl -XGET "localhost:9200/\_cluster/state?filter\_path=version,nodes,metadata.cluster\_coordination&p…

---

## [Cannt find dependency for CommonAnalysisPlugin](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798)

<div class="topic-metadata">

**Author:** [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 6:05am UTC](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798 "2023-04-12T06:05:08Z")

</div>

Hello everyone, I am currently trying to upgrade my Elasticsearch version from 7.8.1 to 7.17.4. However, after the upgrade, I encountered an error in my project: Cannot resolve symbol 'CommonAnalysisPlugin In Elastics…

---

## [ElasticSearch delete model with force does not work](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781)

<div class="topic-metadata">

**Author:** [@Diogo\_Moura](https://discuss.elastic.co/u/Diogo_Moura)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:23pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781 "2023-04-11T22:23:17Z")

</div>

According to the documentation here https://www.elastic.co/guide/en/elasticsearch/reference/8.6/delete-trained-models.html#ml-delete-trained-models-query-parms it is possible to use the parameter "force" to force the de…

---

## [How to properly add an ngram tokenizer via Nest](https://discuss.elastic.co/t/how-to-properly-add-an-ngram-tokenizer-via-nest/329777)

<div class="topic-metadata">

**Author:** [@jfavaro](https://discuss.elastic.co/u/jfavaro)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 9:05pm UTC](https://discuss.elastic.co/t/how-to-properly-add-an-ngram-tokenizer-via-nest/329777 "2023-04-11T21:05:22Z")

</div>

We have an existing Elastic version 8.3.3 with a .Net implementation using Nest 7.17.5. I've been trying to add a new field utitlizing an ngram tokenizer but whenever I add the code to my analyzers the existing full\_aut…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=272)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=274)
