# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=275

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 276

---

## [Filebeat can not talk to ELK on AWS EKS](https://discuss.elastic.co/t/filebeat-can-not-talk-to-elk-on-aws-eks/329600)

<div class="topic-metadata">

**Author:** [@williamsun](https://discuss.elastic.co/u/williamsun)\
**Replies:** 2\
**Last updated:** [April 8, 2023, 9:49am UTC](https://discuss.elastic.co/t/filebeat-can-not-talk-to-elk-on-aws-eks/329600 "2023-04-08T09:49:31Z")

</div>

Hello Everyone, I am using the follow doc to setup the filebeat on EKS. curl -L -O https://raw.githubusercontent.com/elastic/beats/8.7/deploy/kubernetes/filebeat-kubernetes.yaml Default Setting does not work name: …

---

## [Logs in kibana are shown every hour, not during the hour](https://discuss.elastic.co/t/logs-in-kibana-are-shown-every-hour-not-during-the-hour/329607)

<div class="topic-metadata">

**Author:** [@habib\_huseyn](https://discuss.elastic.co/u/habib_huseyn)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 8:33am UTC](https://discuss.elastic.co/t/logs-in-kibana-are-shown-every-hour-not-during-the-hour/329607 "2023-04-08T08:33:44Z")

</div>

I send logs from palo alto to the syslog server using rsyslog. If from the syslog server, I send it to elasticsearch with the agent. but in kibana, the logs are shown in every hour, not during the hour

---

## [Design Index & Document](https://discuss.elastic.co/t/design-index-document/329596)

<div class="topic-metadata">

**Author:** [@YB\_Coding](https://discuss.elastic.co/u/YB_Coding)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:47pm UTC](https://discuss.elastic.co/t/design-index-document/329596 "2023-04-07T18:47:45Z")

</div>

Hello everyone I have a hard time designing my documents. I do not know if I need to create multiple indexes, use nested fieds or index multiple times my documents with a field with a "versionning filter". Below my analo…

---

## [Updating @elastic/elasticsearch version on npm](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595)

<div class="topic-metadata">

**Author:** [@Chukwuma\_Nwaugha](https://discuss.elastic.co/u/Chukwuma_Nwaugha)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595 "2023-04-07T18:01:27Z")

</div>

The latest version of @elastic/elasticsearch is 8.7.0 but the version on npm is still at 8.6.0. When should an update be expected? Thanks and best regards, Chukwuma.

---

## [Creating an indicator match Watcher Alert](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590)

<div class="topic-metadata">

**Author:** [@Banderson02](https://discuss.elastic.co/u/Banderson02)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 5:26pm UTC](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590 "2023-04-07T17:26:25Z")

</div>

Hello, Has anyone been able to replicate an indicator match alert like what is provided in Kibana security as an Elasticsearch Watcher alert? I have a deployment where we do not have access to Kibana Security, so I nee…

---

## [ES upgrade from 5.6 to 8.7](https://discuss.elastic.co/t/es-upgrade-from-5-6-to-8-7/329568)

<div class="topic-metadata">

**Author:** [@salimtb](https://discuss.elastic.co/u/salimtb)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 4:54am UTC](https://discuss.elastic.co/t/es-upgrade-from-5-6-to-8-7/329568 "2023-04-07T04:54:58Z")

</div>

Hi All, I am planning to upgrade the Elasticsearch from 5.6 to 8.7, I wanted to seek suggestions to see if it is a good idea to go directly from 5.6 to 8.7, or do a roll upgrade, application is built on Django and uses …

---

## [Elastic-operator version upgrade](https://discuss.elastic.co/t/elastic-operator-version-upgrade/329571)

<div class="topic-metadata">

**Author:** [@Satyajeet](https://discuss.elastic.co/u/Satyajeet)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:42am UTC](https://discuss.elastic.co/t/elastic-operator-version-upgrade/329571 "2023-04-07T06:42:33Z")

</div>

These are our existing environment parameters, GKE version 1.21.14-gke.14100 We had installed Elasticsearch with the following version previously, Elasticsearch version 7.9.2 Elastic Operator version 1.2.1 This is o…

---

## [Ingest pipeline gsub processor back reference not working](https://discuss.elastic.co/t/ingest-pipeline-gsub-processor-back-reference-not-working/329090)

<div class="topic-metadata">

**Author:** [@kmfreder1](https://discuss.elastic.co/u/kmfreder1)\
**Replies:** 8\
**Last updated:** [April 7, 2023, 12:36am UTC](https://discuss.elastic.co/t/ingest-pipeline-gsub-processor-back-reference-not-working/329090 "2023-04-07T00:36:18Z")

</div>

I am having trouble getting a back reference to work using the gsub processor in the elasticsearch ingest node pipeline. I am trying to get just the TLD from a dns.question.name field and using very similar syntax to wh…

---

## [Azure Elastic Cloud - NEST Client - API call fails with Faulted](https://discuss.elastic.co/t/azure-elastic-cloud-nest-client-api-call-fails-with-faulted/329558)

<div class="topic-metadata">

**Author:** [@rahul-reveation](https://discuss.elastic.co/u/rahul-reveation)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 9:56pm UTC](https://discuss.elastic.co/t/azure-elastic-cloud-nest-client-api-call-fails-with-faulted/329558 "2023-04-06T21:56:28Z")

</div>

On Azure, we have a.Net Core App that connects to ES Cloud. The app makes use of the NEST client. We've recently noticed intermittent issues where the client call to ES would fail at random. Azure Insight reports that it…

---

## [Max limit for number of search results](https://discuss.elastic.co/t/max-limit-for-number-of-search-results/329544)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 7:29pm UTC](https://discuss.elastic.co/t/max-limit-for-number-of-search-results/329544 "2023-04-06T19:29:08Z")

</div>

What is the limit on number of search results by Elasticsearch? Is it 10,000? Which config parameter drives this count? Is it possible to export documents in terms of millions?

---

## [Desired Balance Allocator stuck - preventing assignment of new shards](https://discuss.elastic.co/t/desired-balance-allocator-stuck-preventing-assignment-of-new-shards/328633)

<div class="topic-metadata">

**Author:** [@itizir](https://discuss.elastic.co/u/itizir)\
**Replies:** 15\
**Last updated:** [April 6, 2023, 7:17pm UTC](https://discuss.elastic.co/t/desired-balance-allocator-stuck-preventing-assignment-of-new-shards/328633 "2023-04-06T19:17:54Z")

</div>

Hello, On one of our larger stacks, we have recently seen (twice last week) a problem seemingly related to the new 'desired balance allocator'. The documentation seems to imply this is purely a background operation so t…

---

## [Effects of changing ILM policy](https://discuss.elastic.co/t/effects-of-changing-ilm-policy/329516)

<div class="topic-metadata">

**Author:** [@india](https://discuss.elastic.co/u/india)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 3:54pm UTC](https://discuss.elastic.co/t/effects-of-changing-ilm-policy/329516 "2023-04-06T15:54:04Z")

</div>

I am using Elasticsearch 7.17.0. I have configured ILM policy in following way: "post\_policy" : { "version" : 1, "modified\_date" : "2021-07-26T19:20:56.981Z", "policy" : { "phases" : { "hot…

---

## [Express.js not sending compressed files to front-end after compression enabled](https://discuss.elastic.co/t/express-js-not-sending-compressed-files-to-front-end-after-compression-enabled/329532)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 3:49pm UTC](https://discuss.elastic.co/t/express-js-not-sending-compressed-files-to-front-end-after-compression-enabled/329532 "2023-04-06T15:49:47Z")

</div>

I have an express.js server that's pulling data from Elasticsearch and serving it to the browser. I was under the impression that all I needed to do for the express app to send compressed responses was activating compres…

---

## [Docker cluster](https://discuss.elastic.co/t/docker-cluster/329511)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 12:53pm UTC](https://discuss.elastic.co/t/docker-cluster/329511 "2023-04-06T12:53:21Z")

</div>

hi how to check the logs at /usr/share/elasticsearch/logs/docker-cluster.log

---

## [Post-installation warning message](https://discuss.elastic.co/t/post-installation-warning-message/329218)

<div class="topic-metadata">

**Author:** [@Ghepardo](https://discuss.elastic.co/u/Ghepardo)\
**Replies:** 7\
**Last updated:** [April 6, 2023, 10:02am UTC](https://discuss.elastic.co/t/post-installation-warning-message/329218 "2023-04-06T10:02:57Z")

</div>

I have installed Elasticsearch on an Ubuntu 22.04 system. When I start the service, I get a warning message like the following in the Elasticsearch log: \[2023-04-03T14:07:41,411\]\[WARN \]\[stderr \] \[\<\<ho…

---

## [SOLR collection to Elasticsearch Indices data migration](https://discuss.elastic.co/t/solr-collection-to-elasticsearch-indices-data-migration/329364)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 5\
**Last updated:** [April 6, 2023, 9:25am UTC](https://discuss.elastic.co/t/solr-collection-to-elasticsearch-indices-data-migration/329364 "2023-04-06T09:25:06Z")

</div>

Is it possible to migrate the indexed data (collections) in SOLR to Elasticsearch (Indices)? Data volume will be around 100 million to 1 billion. If yes. What should be the approach? Is there any migration tool availabl…

---

## [Type of Long not valid in time series dimension](https://discuss.elastic.co/t/type-of-long-not-valid-in-time-series-dimension/329464)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 4\
**Last updated:** [April 6, 2023, 8:52am UTC](https://discuss.elastic.co/t/type-of-long-not-valid-in-time-series-dimension/329464 "2023-04-06T08:52:18Z")

</div>

Hi Is this a bug? I can't use a type long field for a time\_series\_dimension. this is a simple example: PUT /temperature01 { "settings": { "index": { "mode": "time\_series", "time\_seri…

---

## [How to count documents in Elasticsearch with exclusive name-value attribute filters of nested type?](https://discuss.elastic.co/t/how-to-count-documents-in-elasticsearch-with-exclusive-name-value-attribute-filters-of-nested-type/329491)

<div class="topic-metadata">

**Author:** [@AKSHAY\_AGARWAL1](https://discuss.elastic.co/u/AKSHAY_AGARWAL1)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 8:05am UTC](https://discuss.elastic.co/t/how-to-count-documents-in-elasticsearch-with-exclusive-name-value-attribute-filters-of-nested-type/329491 "2023-04-06T08:05:12Z")

</div>

\`Require a solution to count the number of documents in Elasticsearch that match a given set of exclusive name-value attribute pairs, where the attribute field is of nested type. The output should show the count of docum…

---

## [Logstash query against elastic returning unwanted field](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 5:05am UTC](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418 "2023-04-06T05:05:45Z")

</div>

I am exporting the metricbeat index from elastic using logstash. I would like to exclude the service.type term docker from the output. I am using the following query: query =\> '{ "query": { …

---

## [Can we use Scann for vector similarity in elasticsearch?](https://discuss.elastic.co/t/can-we-use-scann-for-vector-similarity-in-elasticsearch/328682)

<div class="topic-metadata">

**Author:** [@prakritidev](https://discuss.elastic.co/u/prakritidev)\
**Replies:** 2\
**Last updated:** [April 6, 2023, 4:58am UTC](https://discuss.elastic.co/t/can-we-use-scann-for-vector-similarity-in-elasticsearch/328682 "2023-04-06T04:58:34Z")

</div>

Hi, I am using es 7.14 and the cosine similairty function is not optimal as compare to other technologies. Can I use ScaNN somehow instead ? How will i integrate that library is thats possible. Thanks.

---

## [Silent setup](https://discuss.elastic.co/t/silent-setup/328972)

<div class="topic-metadata">

**Author:** [@geb](https://discuss.elastic.co/u/geb)\
**Replies:** 3\
**Last updated:** [April 6, 2023, 4:48am UTC](https://discuss.elastic.co/t/silent-setup/328972 "2023-04-06T04:48:57Z")

</div>

Is it possible to issue the command /usr/share/elasticsearch/bin/elasticsearch-certutil http in unattended mode? I automated the whole certificate generation stuff but couldnt solve this task.

---

## [Terraform Elastic Provider using the CA fingerprint](https://discuss.elastic.co/t/terraform-elastic-provider-using-the-ca-fingerprint/329115)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 7:25pm UTC](https://discuss.elastic.co/t/terraform-elastic-provider-using-the-ca-fingerprint/329115 "2023-04-05T19:25:56Z")

</div>

Would be great to incorporate the CA fingerprint into the Provider options, any timeline on this ?

---

## [Minimal/optimal hardware setup for one node Elasticsearch stack with daily index 10GB to 20GB](https://discuss.elastic.co/t/minimal-optimal-hardware-setup-for-one-node-elasticsearch-stack-with-daily-index-10gb-to-20gb/328944)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 5:40pm UTC](https://discuss.elastic.co/t/minimal-optimal-hardware-setup-for-one-node-elasticsearch-stack-with-daily-index-10gb-to-20gb/328944 "2023-04-05T17:40:44Z")

</div>

Hello everybody. I'm new here, but very happy to join the community. Is there any official documentation regarding minimal / optimal hardware requirements for Elasticsearch ? Soon I will put in production single node …

---

## [Elasticsearch 8.2.0 doesn't start in centos 8](https://discuss.elastic.co/t/elasticsearch-8-2-0-doesnt-start-in-centos-8/329322)

<div class="topic-metadata">

**Author:** [@dhrchatt](https://discuss.elastic.co/u/dhrchatt)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elasticsearch-8-2-0-doesnt-start-in-centos-8/329322 "2023-04-05T15:30:53Z")

</div>

When I start elasticsearch-8.2.0 version in Linux Centos8, it is giving following error: 0.000s\]\[warning\]\[os,container\] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /scratch/chroot/OL\_7…

---

## [Cluster Redundancy](https://discuss.elastic.co/t/cluster-redundancy/329415)

<div class="topic-metadata">

**Author:** [@George\_Smith](https://discuss.elastic.co/u/George_Smith)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 3:00pm UTC](https://discuss.elastic.co/t/cluster-redundancy/329415 "2023-04-05T15:00:46Z")

</div>

Hi all, I have a question regarding network redundancy with an Elasticsearch Cluster. I am attempting to add redundancy to my cluster so that if a network adapter a node is using fails, it can use another network adapt…

---

## [Char\_Filter pattern replace is not behaving correctly](https://discuss.elastic.co/t/char-filter-pattern-replace-is-not-behaving-correctly/329445)

<div class="topic-metadata">

**Author:** [@ahiggins](https://discuss.elastic.co/u/ahiggins)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:44pm UTC](https://discuss.elastic.co/t/char-filter-pattern-replace-is-not-behaving-correctly/329445 "2023-04-05T14:44:42Z")

</div>

Elasticsearch Version 7.178 I am trying to work on a custom analyzer that would fix problematic texts in our database that contain unsearchable texts that are being obscured by existing '\\u200c' characters, or half-spac…

---

## [Bulk via Python to Kubernetes cluster](https://discuss.elastic.co/t/bulk-via-python-to-kubernetes-cluster/329065)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 1:46pm UTC](https://discuss.elastic.co/t/bulk-via-python-to-kubernetes-cluster/329065 "2023-04-05T13:46:38Z")

</div>

Hi! We are heavily indexing to Elasticsearch 8.6.1 via Python code using bulk API. Our cluster runs on Kubernetes with the elastic operator which creates the following services: my-cluster-es-data my-cluster-es-http m…

---

## [Kibana data](https://discuss.elastic.co/t/kibana-data/329329)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 1:19pm UTC](https://discuss.elastic.co/t/kibana-data/329329 "2023-04-05T13:19:42Z")

</div>

hello i use filebeat to load data from a virtual machine to Elasticsearch and i found it in discover as data stream i just have a question why the number of hits decrease everytime and not still the same thank u

---

## [Prevent filebeat-version-yyyy-mm-dd index from ingesting](https://discuss.elastic.co/t/prevent-filebeat-version-yyyy-mm-dd-index-from-ingesting/329152)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 5\
**Last updated:** [April 5, 2023, 12:37pm UTC](https://discuss.elastic.co/t/prevent-filebeat-version-yyyy-mm-dd-index-from-ingesting/329152 "2023-04-05T12:37:09Z")

</div>

On daily basis i am seeing indexes with name filebeat-7.17.7-yyyy-mm-dd are creating. This is eating lot of space i have to delete them manually. I Have seen options like to create entry in ES which will not allow aut…

---

## [What happened to composite runtime fields in Elasticsearch client?](https://discuss.elastic.co/t/what-happened-to-composite-runtime-fields-in-elasticsearch-client/329430)

<div class="topic-metadata">

**Author:** [@MichaelOpitz](https://discuss.elastic.co/u/MichaelOpitz)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 12:33pm UTC](https://discuss.elastic.co/t/what-happened-to-composite-runtime-fields-in-elasticsearch-client/329430 "2023-04-05T12:33:43Z")

</div>

Hi community, We used composite runtime fields in the Elasticsearch java client. But since we moved to the new Elasticsearch client, composite runtime fields are not longer supported. Are these runtime fields deprecate…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=274)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=276)
