# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=276

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 277

---

## [Index and search multiple indices and fields](https://discuss.elastic.co/t/index-and-search-multiple-indices-and-fields/329324)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 12:14pm UTC](https://discuss.elastic.co/t/index-and-search-multiple-indices-and-fields/329324 "2023-04-05T12:14:45Z")

</div>

I am new to elasticsearch I am using elasticsearch java-client library to in spring boot application for a global search functionality.I have 5 entity classes with multiple fileds to search for , how can I do that ? I …

---

## [How can I identify the root cause and fix a query in Elasticsearch cluster that never returns a response](https://discuss.elastic.co/t/how-can-i-identify-the-root-cause-and-fix-a-query-in-elasticsearch-cluster-that-never-returns-a-response/329424)

<div class="topic-metadata">

**Author:** [@Sagar\_Gulabani1](https://discuss.elastic.co/u/Sagar_Gulabani1)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 11:35am UTC](https://discuss.elastic.co/t/how-can-i-identify-the-root-cause-and-fix-a-query-in-elasticsearch-cluster-that-never-returns-a-response/329424 "2023-04-05T11:35:11Z")

</div>

How can I identify the root cause and fix a query in Elasticsearch cluster that never returns a response. I have an Elasticsearch cluster with Elasticsearch, Logstash, and Kibana running on the same machine using Docker…

---

## [How to transfer users from an Elastic Cluster to another one](https://discuss.elastic.co/t/how-to-transfer-users-from-an-elastic-cluster-to-another-one/329366)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 10:54am UTC](https://discuss.elastic.co/t/how-to-transfer-users-from-an-elastic-cluster-to-another-one/329366 "2023-04-05T10:54:54Z")

</div>

Hey everyone! I need to copy the users and roles from an Elastic cluster 7.9 to a new 8.3.2 cluster. Is there a way to do that? Recreating manually is not possible since we have hundreds of users configured and most of…

---

## [Problem with data streams date after rollover](https://discuss.elastic.co/t/problem-with-data-streams-date-after-rollover/329410)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 9:59am UTC](https://discuss.elastic.co/t/problem-with-data-streams-date-after-rollover/329410 "2023-04-05T09:59:27Z")

</div>

Hi. I configured ES to rollover my indexes every day. I noticed that today my index rolled at Current action time 2023-04-05 00:34:31. Despite that, the index name created was .ds-suricata-ids-8.6.2-2023.04.04-000010 w…

---

## [Ingest @timestamp](https://discuss.elastic.co/t/ingest-timestamp/329400)

<div class="topic-metadata">

**Author:** [@sta](https://discuss.elastic.co/u/sta)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 8:51am UTC](https://discuss.elastic.co/t/ingest-timestamp/329400 "2023-04-05T08:51:01Z")

</div>

Hello. I have a log file where timestamp is \[2023-04-05 07:42:35\]. I made a ingest pipeline PUT \_ingest/pipeline/fe-logs-json { "processors": \[ { "grok": { "field": "message", "patterns": \[ …

---

## [Latency reporting and rate limitting in logging-indexing-querying track](https://discuss.elastic.co/t/latency-reporting-and-rate-limitting-in-logging-indexing-querying-track/329135)

<div class="topic-metadata">

**Author:** [@Jiri\_Holusa](https://discuss.elastic.co/u/Jiri_Holusa)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 8:48am UTC](https://discuss.elastic.co/t/latency-reporting-and-rate-limitting-in-logging-indexing-querying-track/329135 "2023-04-05T08:48:02Z")

</div>

Hi, we're using rally for performance evaluation. In our case, it's about the effect of a JVM to Elasticsearch's performance (disclaimer: I work for Azul). We would like to use challenge "elastic/logs", track "logging-…

---

## [Script Exception on Elasticsearch function score script query](https://discuss.elastic.co/t/script-exception-on-elasticsearch-function-score-script-query/329387)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 8:07am UTC](https://discuss.elastic.co/t/script-exception-on-elasticsearch-function-score-script-query/329387 "2023-04-05T08:07:46Z")

</div>

Hello, I have used function score for a query and my script is: "doc\['Field1\_score'\].value != null && doc\['Field2\_score'\].value !=null ? (doc\['Field1\_score'\].value \* 100000) + (doc\['Field2\_score'\].value \* 100000) : 1", …

---

## [Rally eventdata-track & support for Elastic Stack 8.x](https://discuss.elastic.co/t/rally-eventdata-track-support-for-elastic-stack-8-x/329312)

<div class="topic-metadata">

**Author:** [@jan.stap](https://discuss.elastic.co/u/jan.stap)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:53am UTC](https://discuss.elastic.co/t/rally-eventdata-track-support-for-elastic-stack-8-x/329312 "2023-04-05T07:53:44Z")

</div>

Hi, In this post I read that the rally-eventdata-track is not supported for Elasticsearch 8.x, but I find no further info on that. The README.md says it is compatible with the latest development version of Elasticsearch…

---

## [High Number of indices affect on performance](https://discuss.elastic.co/t/high-number-of-indices-affect-on-performance/329355)

<div class="topic-metadata">

**Author:** [@sukur55](https://discuss.elastic.co/u/sukur55)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:46am UTC](https://discuss.elastic.co/t/high-number-of-indices-affect-on-performance/329355 "2023-04-05T07:46:24Z")

</div>

Does, number of indices has considerable affect on running/startup performance? like image having 100GB of data in 50 indices or having 100GB data on 300+ indices, how they differ from performance perspective? imagine I …

---

## [Several types as values to same key](https://discuss.elastic.co/t/several-types-as-values-to-same-key/329194)

<div class="topic-metadata">

**Author:** [@yael\_shifman](https://discuss.elastic.co/u/yael_shifman)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 7:34am UTC](https://discuss.elastic.co/t/several-types-as-values-to-same-key/329194 "2023-04-05T07:34:56Z")

</div>

I have jenkins logs in a json format. (taken with the API) the logs have different types of value to the same key: ''' { "\_class":"hudson.model.StringParameterValue", "name":"MANIFEST\_REVISION", "value":"master" }…

---

## [Monitor API URL with Elastic](https://discuss.elastic.co/t/monitor-api-url-with-elastic/329371)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 5:59am UTC](https://discuss.elastic.co/t/monitor-api-url-with-elastic/329371 "2023-04-05T05:59:40Z")

</div>

Hello, I would like to monitor the API URL in Azure with Elastic and the flow is like below image. My question is how do we grab the authentication token to monitor the API URL? And after grabbing the authenticatio…

---

## [Moving Index/shards from Hot Tier to Warm Tier using custom Attributes within zones using ILM](https://discuss.elastic.co/t/moving-index-shards-from-hot-tier-to-warm-tier-using-custom-attributes-within-zones-using-ilm/329277)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 5:09am UTC](https://discuss.elastic.co/t/moving-index-shards-from-hot-tier-to-warm-tier-using-custom-attributes-within-zones-using-ilm/329277 "2023-04-05T05:09:32Z")

</div>

I usually move an index to warm tier using ILM and the default \_tier\_preference if I have the nodes defined as data\_warm. Lets say I have multiple indices with varied number of shards. index1 with 5 shards and index 2 w…

---

## [Using Nested Field in Composite Aggregation](https://discuss.elastic.co/t/using-nested-field-in-composite-aggregation/329359)

<div class="topic-metadata">

**Author:** [@michael-jaxsta](https://discuss.elastic.co/u/michael-jaxsta)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 11:57pm UTC](https://discuss.elastic.co/t/using-nested-field-in-composite-aggregation/329359 "2023-04-04T23:57:01Z")

</div>

This question has been asked a few times in this community but have not got a response so hopefully someone reads this and helps me out! I'm trying to do a composite aggregation on documents which have nested fields. Sp…

---

## [How do index rollover and tier transition work when they overlap](https://discuss.elastic.co/t/how-do-index-rollover-and-tier-transition-work-when-they-overlap/329240)

<div class="topic-metadata">

**Author:** [@EyadArafat](https://discuss.elastic.co/u/EyadArafat)\
**Replies:** 4\
**Last updated:** [April 4, 2023, 9:51pm UTC](https://discuss.elastic.co/t/how-do-index-rollover-and-tier-transition-work-when-they-overlap/329240 "2023-04-04T21:51:07Z")

</div>

Hi, I'm a little confused on how transitioning a data stream's write index to the warm phase would work if it's still not supposed to be rolled-over yet. Here's an example. Let's say I have an ILM to rollover the data …

---

## [Elastic Cluster connection Issue](https://discuss.elastic.co/t/elastic-cluster-connection-issue/327593)

<div class="topic-metadata">

**Author:** [@Stalin](https://discuss.elastic.co/u/Stalin)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 7:49pm UTC](https://discuss.elastic.co/t/elastic-cluster-connection-issue/327593 "2023-04-04T19:49:02Z")

</div>

Hi, We have frequently faced the below issue " Can not connect to the Elastic Search Cluster See the Kibana logs for details and try to reload the page" Someone pls help me on this!!

---

## [Elasticsearch - getting GC and the node reconnect from the cluster](https://discuss.elastic.co/t/elasticsearch-getting-gc-and-the-node-reconnect-from-the-cluster/329232)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-getting-gc-and-the-node-reconnect-from-the-cluster/329232 "2023-04-04T14:04:11Z")

</div>

we are getting GC and during that time heap usage is reducing and even sometimes the node reconnects from the cluster below are the params we are using and the GC -XX:+UseConcMarkSweepGC -XX:+UseParNewGC -XX:CMSIniti…

---

## [Indices Folder inside Backup not cleaning up](https://discuss.elastic.co/t/indices-folder-inside-backup-not-cleaning-up/328902)

<div class="topic-metadata">

**Author:** [@DVoss2](https://discuss.elastic.co/u/DVoss2)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 1:16pm UTC](https://discuss.elastic.co/t/indices-folder-inside-backup-not-cleaning-up/328902 "2023-04-04T13:16:49Z")

</div>

Hi! We are creating daily backups with: curl -u elastic: -X PUT 127.0.0.1:9200/\_snapshot/backup/snapshot-$snapdate?wait\_for\_completion=true and delete older ones with curl -u elastic: -X DELETE "127.0.0.1:9200/\_sna…

---

## [Elasticsearch mail Alerts via index Connector](https://discuss.elastic.co/t/elasticsearch-mail-alerts-via-index-connector/329287)

<div class="topic-metadata">

**Author:** [@Pawan\_kumar1](https://discuss.elastic.co/u/Pawan_kumar1)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 12:54pm UTC](https://discuss.elastic.co/t/elasticsearch-mail-alerts-via-index-connector/329287 "2023-04-04T12:54:25Z")

</div>

elasticsearch mail Alerts via index Connector

---

## [Curl -X GET 'http://localhost:9200' curl: (52) Empty reply from server](https://discuss.elastic.co/t/curl-x-get-http-localhost-9200-curl-52-empty-reply-from-server/329211)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 7\
**Last updated:** [April 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/curl-x-get-http-localhost-9200-curl-52-empty-reply-from-server/329211 "2023-04-04T12:49:59Z")

</div>

elasticsearch service is active and running but got this error while accessing 9200, elasticsearch.yml file is properly configuredcurl -X GET 'http://localhost:9200' curl: (52) Empty reply from server

---

## [Downsampling Documentation](https://discuss.elastic.co/t/downsampling-documentation/329105)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 12:18pm UTC](https://discuss.elastic.co/t/downsampling-documentation/329105 "2023-04-04T12:18:48Z")

</div>

Hi, I have the feeling this step is wrong: This query won't return an aggregation, only hits: Or could it be that the previous step is a post and not a get?

---

## [Issue using a sshfs docker mount as a snapshot repository](https://discuss.elastic.co/t/issue-using-a-sshfs-docker-mount-as-a-snapshot-repository/328822)

<div class="topic-metadata">

**Author:** [@Benjamin\_Goetz](https://discuss.elastic.co/u/Benjamin_Goetz)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 11:29am UTC](https://discuss.elastic.co/t/issue-using-a-sshfs-docker-mount-as-a-snapshot-repository/328822 "2023-04-04T11:29:13Z")

</div>

Hello, I'm having trouble trying to get Elasticsearch to register a docker mount as a snapshot repository. The situation I'm migrating indices from a server to another, let's call them "old host" and "new host". Both …

---

## [My filebeat is not able to talk with ealsticsearch](https://discuss.elastic.co/t/my-filebeat-is-not-able-to-talk-with-ealsticsearch/329304)

<div class="topic-metadata">

**Author:** [@madhav](https://discuss.elastic.co/u/madhav)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 11:01am UTC](https://discuss.elastic.co/t/my-filebeat-is-not-able-to-talk-with-ealsticsearch/329304 "2023-04-04T11:01:14Z")

</div>

I am getting below error while testing out put from filebeat. Let me know if anyone has any solution.

---

## [Elastic creating new Index on Bulk Api even though mapping is already provided](https://discuss.elastic.co/t/elastic-creating-new-index-on-bulk-api-even-though-mapping-is-already-provided/329294)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 10:39am UTC](https://discuss.elastic.co/t/elastic-creating-new-index-on-bulk-api-even-though-mapping-is-already-provided/329294 "2023-04-04T10:39:27Z")

</div>

Hi Community Members Using Elastic 8 with JAVA client.I first created template of mapping like below Index Name=A is created two in elastic 8 server instead of overwritingalready present mapping file { "settings": {…

---

## [Java API enforces specifying both min and max in extended bounds unlike RHLC](https://discuss.elastic.co/t/java-api-enforces-specifying-both-min-and-max-in-extended-bounds-unlike-rhlc/329202)

<div class="topic-metadata">

**Author:** [@awojcik64](https://discuss.elastic.co/u/awojcik64)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 11:47am UTC](https://discuss.elastic.co/t/java-api-enforces-specifying-both-min-and-max-in-extended-bounds-unlike-rhlc/329202 "2023-04-03T11:47:20Z")

</div>

Hello, Edit: tested on dockerized Elasticsearch 7.17.7, 7.17.9, client version is 7.17.9 During migration to Java API client (from rest high level client) I've encountered an inconsistency regarding extended bounds in …

---

## [Old question but at a loss http\_request which is larger than the limit of \[\*\*\*\*\*/4.1gb\]](https://discuss.elastic.co/t/old-question-but-at-a-loss-http-request-which-is-larger-than-the-limit-of-4-1gb/329295)

<div class="topic-metadata">

**Author:** [@uschellh](https://discuss.elastic.co/u/uschellh)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 8:54am UTC](https://discuss.elastic.co/t/old-question-but-at-a-loss-http-request-which-is-larger-than-the-limit-of-4-1gb/329295 "2023-04-04T08:54:54Z")

</div>

Hello, i already increased Java Heap sizes for graylog-server which is 4.3.13 and elasticsearch . According to the nodes overview, my settings for graylog of 8/12 gb are not filled. Elasticsearch can do searches (someti…

---

## [\[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[node1\] master not discovered yet, this node has not previously joined a bootstrapped cluster](https://discuss.elastic.co/t/warn-o-e-c-c-clusterformationfailurehelper-node1-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster/329267)

<div class="topic-metadata">

**Author:** [@Raghulvishal](https://discuss.elastic.co/u/Raghulvishal)\
**Replies:** 9\
**Last updated:** [April 4, 2023, 7:56am UTC](https://discuss.elastic.co/t/warn-o-e-c-c-clusterformationfailurehelper-node1-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster/329267 "2023-04-04T07:56:16Z")

</div>

Hi Team, I am using ES 8.6 version and configured 3 nodes,while starting the node i'am getting master not discovered yet exception. This is my elastic .yml given below. cluster.name: es-8\_6 node.name: node1 path.dat…

---

## [Best method for calculating text embedding for a KNN search?](https://discuss.elastic.co/t/best-method-for-calculating-text-embedding-for-a-knn-search/329258)

<div class="topic-metadata">

**Author:** [@scott\_root](https://discuss.elastic.co/u/scott_root)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 7:50am UTC](https://discuss.elastic.co/t/best-method-for-calculating-text-embedding-for-a-knn-search/329258 "2023-04-04T07:50:15Z")

</div>

Hello, I am using Elastic Cloud and am using pre-trained ML models for text/semantic search and for image search. Currently, in order to do a text KNN search I have to make two API calls to ES, first to get the text em…

---

## [Failed to enable unit](https://discuss.elastic.co/t/failed-to-enable-unit/329289)

<div class="topic-metadata">

**Author:** [@bhargav.burugupalli](https://discuss.elastic.co/u/bhargav.burugupalli)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 7:45am UTC](https://discuss.elastic.co/t/failed-to-enable-unit/329289 "2023-04-04T07:45:37Z")

</div>

Hello everyone, Good day ! I was trying to setup Elastic search on a RHEL machine in our office network. And following through this link.Install Elasticsearch with RPM | Elasticsearch Guide \[8.7\] | Elastic When I am t…

---

## [Shield Licensing in 2023](https://discuss.elastic.co/t/shield-licensing-in-2023/329272)

<div class="topic-metadata">

**Author:** [@ovidiutirsa-en](https://discuss.elastic.co/u/ovidiutirsa-en)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 7:09am UTC](https://discuss.elastic.co/t/shield-licensing-in-2023/329272 "2023-04-04T07:09:41Z")

</div>

Hello, We are currently self hosting a very old version of Elasticsearch (2.0) and are in need of extending our Shield plugin license. Is there a way to contact someone from ES for pricing? Querying on emails did not h…

---

## [Setting up monitoring cluster](https://discuss.elastic.co/t/setting-up-monitoring-cluster/329106)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 4:11am UTC](https://discuss.elastic.co/t/setting-up-monitoring-cluster/329106 "2023-04-04T04:11:18Z")

</div>

I have cluster running 7.17 and want to setup monitoring cluster with 8.x version can I use metricbeat 8.x on elastic cluster running 7.17? they way I understand metricbeat is just going to pull data from cluster/node…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=275)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=277)
