# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=277

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 278

---

## [Would be a good idea to turn all data nodes into non-eligible masters?](https://discuss.elastic.co/t/would-be-a-good-idea-to-turn-all-data-nodes-into-non-eligible-masters/329261)

<div class="topic-metadata">

**Author:** [@Bruno\_Arruda](https://discuss.elastic.co/u/Bruno_Arruda)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 3:57am UTC](https://discuss.elastic.co/t/would-be-a-good-idea-to-turn-all-data-nodes-into-non-eligible-masters/329261 "2023-04-04T03:57:08Z")

</div>

Hi, Actually I have a cluster with 4 master nodes and 10 data nodes on a Kubernetes Cluster. Basically, each node causes my cluster to scale new hosts because of the anti-affinity default behavior, so my k8s got 14 node…

---

## [How to set timezone when use python sdk?](https://discuss.elastic.co/t/how-to-set-timezone-when-use-python-sdk/329011)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 1:49am UTC](https://discuss.elastic.co/t/how-to-set-timezone-when-use-python-sdk/329011 "2023-04-04T01:49:09Z")

</div>

{ "\_index": "mysql\_backup\_stat", "\_type": "\_doc", "\_id": "addb-m15-2023-03-31T02:31:22.920268+08:00", "\_version": 1, "\_score": null, "\_source": { "timestamp": "2023-03-31T02:31:22.920268+08:00", "host…

---

## [Elasticsearch - getting Circuit breaker exception with sudden spike in Heap usage](https://discuss.elastic.co/t/elasticsearch-getting-circuit-breaker-exception-with-sudden-spike-in-heap-usage/329231)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 1:33am UTC](https://discuss.elastic.co/t/elasticsearch-getting-circuit-breaker-exception-with-sudden-spike-in-heap-usage/329231 "2023-04-04T01:33:07Z")

</div>

We are having ES 7.3.2 in production and we are getting circuit breaker exception when the heap usage increases suddenly, we have also tested for the same in es 7.17 and 8.x in local but is there any improvement in lates…

---

## [S3 Access Denied error while verifying repository for snapshot and restore](https://discuss.elastic.co/t/s3-access-denied-error-while-verifying-repository-for-snapshot-and-restore/329263)

<div class="topic-metadata">

**Author:** [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 1:17am UTC](https://discuss.elastic.co/t/s3-access-denied-error-while-verifying-repository-for-snapshot-and-restore/329263 "2023-04-04T01:17:27Z")

</div>

Hi, I am working on Snapshot and Restore to ensure that my Elasticsearch indices are securely backed-up and stored. I've set up an EFK stack on my AWS EKS cluster. I've deployed the stack using Helm in Bitnami chart. I a…

---

## [Fluentd configuration is not creating indexes in elasticsearch](https://discuss.elastic.co/t/fluentd-configuration-is-not-creating-indexes-in-elasticsearch/328876)

<div class="topic-metadata">

**Author:** [@sc9501](https://discuss.elastic.co/u/sc9501)\
**Replies:** 12\
**Last updated:** [April 3, 2023, 9:50pm UTC](https://discuss.elastic.co/t/fluentd-configuration-is-not-creating-indexes-in-elasticsearch/328876 "2023-04-03T21:50:33Z")

</div>

Hello everyone, I need some help with the EFK stack. I've already installed Elasticsearch, Kibana and Fluentd with their respective Helm charts in a k8s environment. Every pod is running fine but I'm my Fluentd configu…

---

## [Issues with snapshots](https://discuss.elastic.co/t/issues-with-snapshots/329142)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 7:30pm UTC](https://discuss.elastic.co/t/issues-with-snapshots/329142 "2023-04-03T19:30:06Z")

</div>

I am struggling to understand how one is expected to use the snapshot system to provide a reliable back up. I understand that individual snapshots are incremental, but presumably only within repositories? I have set up…

---

## [How to exclude attachment content and still searching inside it?](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191)

<div class="topic-metadata">

**Author:** [@aabdo](https://discuss.elastic.co/u/aabdo)\
**Replies:** 7\
**Last updated:** [April 3, 2023, 5:35pm UTC](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191 "2023-04-03T17:35:58Z")

</div>

hello, to optimize my disk space, i'm excluding my attachment content in the mapping of my index. but i can't no longer search inside it . i don't know what am i messing !! . is there any solution for this issue ??

---

## [Elasticsearch 7.17 with G1GC and Java 17](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 5:14pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230 "2023-04-03T17:14:39Z")

</div>

Is it good to go with G1GC in Elasticsearch 7.17 With Java 17 and is there any drawback of having this config in production

---

## [Operations over indexed documents](https://discuss.elastic.co/t/operations-over-indexed-documents/329068)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 4:27pm UTC](https://discuss.elastic.co/t/operations-over-indexed-documents/329068 "2023-04-03T16:27:41Z")

</div>

Hi, Is it possible to compute variables taking the documents from an index as input? I will describe my current situation and my objective. I have data indexed on an Elasticsearch cluster. My data contains a timestamp …

---

## [Read from ES index fails without write permission with HEAD \[405|Method Not Allowed:\]](https://discuss.elastic.co/t/read-from-es-index-fails-without-write-permission-with-head-405-method-not-allowed/328176)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 10\
**Last updated:** [April 3, 2023, 3:03pm UTC](https://discuss.elastic.co/t/read-from-es-index-fails-without-write-permission-with-head-405-method-not-allowed/328176 "2023-04-03T15:03:29Z")

</div>

We're trying to connect to 2 different elastic instances and read data from databricks on indicies where a user has read permissions. For both instances we're seeing the following error EsHadoopInvalidRequest: \[HEAD\] o…

---

## [Problem with mapping](https://discuss.elastic.co/t/problem-with-mapping/329221)

<div class="topic-metadata">

**Author:** [@matheusgermano](https://discuss.elastic.co/u/matheusgermano)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 1:33pm UTC](https://discuss.elastic.co/t/problem-with-mapping/329221 "2023-04-03T13:33:57Z")

</div>

Hey, folks! How are you? I'm having some troubles with, I believe, mapping. I have a JsonElement field type that is not being saved in my elastic. I'm using C#, working with NEST client. Invalid NEST response built fro…

---

## [Loading BERT Model](https://discuss.elastic.co/t/loading-bert-model/327709)

<div class="topic-metadata">

**Author:** [@Cole\_Crawford](https://discuss.elastic.co/u/Cole_Crawford)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 1:11pm UTC](https://discuss.elastic.co/t/loading-bert-model/327709 "2023-04-03T13:11:18Z")

</div>

I am trying to add ANN semantic search to an Elasticsearch index of scientific documents. To that end, I am trying to set up an NLP pipeline on Elasticsearch to vectorize documents on ingest. I would like to test allenai…

---

## [Hybrid Retrieval with approximate KNN](https://discuss.elastic.co/t/hybrid-retrieval-with-approximate-knn/329196)

<div class="topic-metadata">

**Author:** [@jinmingteo](https://discuss.elastic.co/u/jinmingteo)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 12:50pm UTC](https://discuss.elastic.co/t/hybrid-retrieval-with-approximate-knn/329196 "2023-04-03T12:50:49Z")

</div>

Hi, I have read through the following documentation: k-nearest neighbor (kNN) search | Elasticsearch Guide \[master\] | Elastic I have also experimented with a small database and it seems that the results are skewed towa…

---

## [Enrich Processor missing documents](https://discuss.elastic.co/t/enrich-processor-missing-documents/328843)

<div class="topic-metadata">

**Author:** [@FKarraz](https://discuss.elastic.co/u/FKarraz)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 12:24pm UTC](https://discuss.elastic.co/t/enrich-processor-missing-documents/328843 "2023-04-03T12:24:30Z")

</div>

Hi, i have several ingest pipelines that has quite large processor configured in it. Each pipeline for each Data Stream. For example, pipeline "2g\_names" works with "raw\_kpi\_2g\_" (raw\_kpi\_2g\_1) Data Stream, "3g\_names" fo…

---

## [QueryBuilders.nested() in new Java REST Client works not as expected (no "nested" attribute generated), comparing to older (deprecated) HRC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099)

<div class="topic-metadata">

**Author:** [@Mattteo](https://discuss.elastic.co/u/Mattteo)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 11:31am UTC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099 "2023-04-03T11:31:51Z")

</div>

The problem: I am trying to upgrade from deprecated HRC (7.13) to new REST Client 8.6 in Java. We use nested queries, but although there is a special NestedQuery.Builder object in the new java client, its not possible t…

---

## [Experience with Large Memory Nodes (1TB, 2TB, and more)](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124)

<div class="topic-metadata">

**Author:** [@Michael\_Sander](https://discuss.elastic.co/u/Michael_Sander)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 10:53am UTC](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124 "2023-04-03T10:53:07Z")

</div>

Google Cloud, AWS, and others are now offering nodes with 2TB or more of memory. In the past, the conventional wisdom has been to not provide Elasticsearch with more than 32GB so it uses 32 bit pointers, but I wonder if …

---

## [Recommended configuration](https://discuss.elastic.co/t/recommended-configuration/329120)

<div class="topic-metadata">

**Author:** [@Noam\_Huri](https://discuss.elastic.co/u/Noam_Huri)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 9:48am UTC](https://discuss.elastic.co/t/recommended-configuration/329120 "2023-04-03T09:48:59Z")

</div>

Hi, could someone please help me and guide me on how to calculate the cost or the recommended configuration that would best suit my needs? unfortunately, I'm not an IT guy :slight\_smile: Our data set consists of approx…

---

## [Query template that will append to existing query for further filtering out results](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 8:23am UTC](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151 "2023-04-03T08:23:02Z")

</div>

We have an existing "person" index that has "status" field in it. We have several (around 6) existing queries for retrieving person document with different parameters and logic. However, we have a new requirement that o…

---

## [Elasticsearch Watcher Capabilities](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167)

<div class="topic-metadata">

**Author:** [@umityayla](https://discuss.elastic.co/u/umityayla)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:12am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-capabilities/329167 "2023-04-03T07:12:32Z")

</div>

Hello, We plan to implement such a watcher that will regex a field in the documents that are found and pass it to the clients. What I mean is; Let's assume there are 2 documents like below; { "\_type": "\_doc", "\_id…

---

## [About Elastalert errors](https://discuss.elastic.co/t/about-elastalert-errors/329138)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 5:57am UTC](https://discuss.elastic.co/t/about-elastalert-errors/329138 "2023-04-03T05:57:31Z")

</div>

We would like to use elasrticsearch and kibana to achieve the ability to email administrators about unusual events. We're using elastalert2 for this purpose but the filter is in error. We have spent a lot of time on th…

---

## [Timestamp search between two fields](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 4\
**Last updated:** [April 2, 2023, 11:32am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048 "2023-04-02T11:32:53Z")

</div>

In my use case, I created two fields for the values of start\_time and end\_time based on some indicators in the log lines with kibana discover , I want to search for all the log lines that their timestamp is between thes…

---

## [Watchers are not working after elasticsearch migration 7.16.1 to 8.5.1](https://discuss.elastic.co/t/watchers-are-not-working-after-elasticsearch-migration-7-16-1-to-8-5-1/328733)

<div class="topic-metadata">

**Author:** [@mkaymak](https://discuss.elastic.co/u/mkaymak)\
**Replies:** 1\
**Last updated:** [April 2, 2023, 2:57am UTC](https://discuss.elastic.co/t/watchers-are-not-working-after-elasticsearch-migration-7-16-1-to-8-5-1/328733 "2023-04-02T02:57:59Z")

</div>

After migrating Elasticsearch version 7.16.1 to 8.5.1 The watchers which basically find the error logs and send them to our messaging channel started to not working. When I simulate my watcher the error message is: "…

---

## [Master not discovered yet, this node has not previously joined a bootstrapped](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093)

<div class="topic-metadata">

**Author:** [@williamsun](https://discuss.elastic.co/u/williamsun)\
**Replies:** 1\
**Last updated:** [April 1, 2023, 6:20am UTC](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093 "2023-04-01T06:20:37Z")

</div>

My issue is related to the last post. Master not discovered yet, this node has not previously joined a bootstrapped ====== I installed Elasticsearch 8.7.0 on AWS EKS 1.23 with three master Pods, three Data Pods and tw…

---

## [Data stream rollover & writing documents at pre-rollover date](https://discuss.elastic.co/t/data-stream-rollover-writing-documents-at-pre-rollover-date/329086)

<div class="topic-metadata">

**Author:** [@nouknouk](https://discuss.elastic.co/u/nouknouk)\
**Replies:** 2\
**Last updated:** [April 1, 2023, 12:14am UTC](https://discuss.elastic.co/t/data-stream-rollover-writing-documents-at-pre-rollover-date/329086 "2023-04-01T00:14:58Z")

</div>

Hi, I brand new to the concept of data streams, and I'm trying to understand the concepts & limits behind them. So sorry in advance if my question is a dumb one. Let's say: I configure a data stream "foo" with rollo…

---

## [Keytool error: java.io.IOException: Invalid keystore format](https://discuss.elastic.co/t/keytool-error-java-io-ioexception-invalid-keystore-format/328939)

<div class="topic-metadata">

**Author:** [@dr01](https://discuss.elastic.co/u/dr01)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/keytool-error-java-io-ioexception-invalid-keystore-format/328939 "2023-03-31T20:40:24Z")

</div>

I have Elasticsearch 7.17. Following the generation of new SSL certificates, I have created a new keystore via the command /usr/share/elasticsearch/bin/elasticsearch-keystore create and I'm trying to add the CA cert…

---

## [Data stream timestamp in the name of index](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 8:25pm UTC](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080 "2023-03-31T20:25:48Z")

</div>

Hi Is it possible to achieve name with timestamp from ingest data to elasticsearch in the index name like .ds-\<data-stream\>-\<yyyy.MM.dd\>-\<generation\> .ds-\<data-stream\>\<mytimestamp\_from\_log\>-\<generation\> I've tried to…

---

## [Elasticsearch Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 7:33pm UTC](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072 "2023-03-31T19:33:54Z")

</div>

Hello, I am trying to run reindex with query but getting the error Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]. { "source": { "index": "index-\*", "\_source" : \[ "@timestamp", "message"\], …

---

## [S3 API Costs are extraordinary expensive for snapshots](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 7:04pm UTC](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071 "2023-03-31T19:04:45Z")

</div>

To store 5TB of data, we are paying about $1,200 in storage fees per month and $10,000 in API calls Is there a way to fix this? During a snapshot we are seeing upwards of 120k s3 api calls/minute SLM: PUT \_slm/policy/…

---

## [Elastic Search Api with Python](https://discuss.elastic.co/t/elastic-search-api-with-python/329009)

<div class="topic-metadata">

**Author:** [@Sharath\_B.S](https://discuss.elastic.co/u/Sharath_B.S)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 6:45pm UTC](https://discuss.elastic.co/t/elastic-search-api-with-python/329009 "2023-03-31T18:45:31Z")

</div>

Im trying to sort the search results according to the date in ascending order. it would be helpful if i could get to know how to sort the results according to the date.

---

## [Elasticsearch 8.4.3 - security rules dashboard cannot be accessed - Privileges required](https://discuss.elastic.co/t/elasticsearch-8-4-3-security-rules-dashboard-cannot-be-accessed-privileges-required/329074)

<div class="topic-metadata">

**Author:** [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 6:21pm UTC](https://discuss.elastic.co/t/elasticsearch-8-4-3-security-rules-dashboard-cannot-be-accessed-privileges-required/329074 "2023-03-31T18:21:41Z")

</div>

Hi there, I created a rule in elastic and followed this document for allowing access for a user to all security features including alerts. The role has all indices access including metioned in the above document: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=276)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=278)
