# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=28

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 29

---

## [Elast alert substring](https://discuss.elastic.co/t/elast-alert-substring/379329)

<div class="topic-metadata">

**Author:** [@elastic\_interogation](https://discuss.elastic.co/u/elastic_interogation)\
**Replies:** 1\
**Last updated:** [June 19, 2025, 2:48pm UTC](https://discuss.elastic.co/t/elast-alert-substring/379329 "2025-06-19T14:48:04Z")

</div>

Hello, I am trying to parse my alerts, I want to get only a substring of a field (my field name is message). Let me give you an example, actually, I use: { "text": """ {{#context.hits}} - {{\_source.message}} {{/co…

---

## [How to Balance Shards When Routing by field in Elasticsearch?](https://discuss.elastic.co/t/how-to-balance-shards-when-routing-by-field-in-elasticsearch/379328)

<div class="topic-metadata">

**Author:** [@Dimitris\_Makris](https://discuss.elastic.co/u/Dimitris_Makris)\
**Replies:** 0\
**Last updated:** [June 19, 2025, 1:33pm UTC](https://discuss.elastic.co/t/how-to-balance-shards-when-routing-by-field-in-elasticsearch/379328 "2025-06-19T13:33:24Z")

</div>

Background & Setup I have an Elasticsearch index that stores information about users. Each user belongs to a group, and every user document contains a group\_id field. All queries to Elasticsearch are filtered by group\_id,…

---

## [Elasticsearch 8.17.3: Stuck "update\_tsdb\_data\_stream\_end\_times" Pending Task Blocking ILM Policy](https://discuss.elastic.co/t/elasticsearch-8-17-3-stuck-update-tsdb-data-stream-end-times-pending-task-blocking-ilm-policy/378224)

<div class="topic-metadata">

**Author:** [@bpaoli](https://discuss.elastic.co/u/bpaoli)\
**Replies:** 4\
**Last updated:** [June 19, 2025, 5:30am UTC](https://discuss.elastic.co/t/elasticsearch-8-17-3-stuck-update-tsdb-data-stream-end-times-pending-task-blocking-ilm-policy/378224 "2025-06-19T05:30:15Z")

</div>

Environment Elasticsearch 8.17.3 in a 3-node cluster SLES-OS 12 VMs JDK 21.0.5+11-JRE (issue also occurred with embedded JDK (java 23) and Java 17) 30GB partition for Elasticsearch data 64GB RAM per VM with JVM settings…

---

## [Allocation awarenes vs data tiering problems](https://discuss.elastic.co/t/allocation-awarenes-vs-data-tiering-problems/378820)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 16\
**Last updated:** [June 18, 2025, 3:03pm UTC](https://discuss.elastic.co/t/allocation-awarenes-vs-data-tiering-problems/378820 "2025-06-18T15:03:02Z")

</div>

Minimal setup is like this: Node Data tier Rack 1 data\_hot,data\_content A 2 data\_hot,data\_content B 3 data\_hot,data\_content B 4 data\_cold A 5 data\_cold B Node 1 failed. I expected elastic create new …

---

## [Elastic node get OOM(Out of memory) when make estimateCost](https://discuss.elastic.co/t/elastic-node-get-oom-out-of-memory-when-make-estimatecost/379291)

<div class="topic-metadata">

**Author:** [@Zoree](https://discuss.elastic.co/u/Zoree)\
**Replies:** 0\
**Last updated:** [June 18, 2025, 12:36pm UTC](https://discuss.elastic.co/t/elastic-node-get-oom-out-of-memory-when-make-estimatecost/379291 "2025-06-18T12:36:54Z")

</div>

We get OOM when function estimate Cost trying to complete. How i understand our query is too large? Stacktrace: Status: error. Problem Suspect 1 920 instances of org.elasticsearch.index.IndexService, loaded by jdk.int…

---

## [Flattened field contains one immense field whose keyed encoding is longer than the allowed max length of 32766 bytes](https://discuss.elastic.co/t/flattened-field-contains-one-immense-field-whose-keyed-encoding-is-longer-than-the-allowed-max-length-of-32766-bytes/376520)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 7\
**Last updated:** [June 18, 2025, 11:58am UTC](https://discuss.elastic.co/t/flattened-field-contains-one-immense-field-whose-keyed-encoding-is-longer-than-the-allowed-max-length-of-32766-bytes/376520 "2025-06-18T11:58:51Z")

</div>

Hi Team, We are using Elasticsearch with dotnet client version as PackageReference Include="Elastic.Clients.Elasticsearch" Version="8.17.1" We have an index in elastic where the mapping looks like below "mappings": {…

---

## [Reloading dictionary decompounder word\_list\_path](https://discuss.elastic.co/t/reloading-dictionary-decompounder-word-list-path/379206)

<div class="topic-metadata">

**Author:** [@cweiske](https://discuss.elastic.co/u/cweiske)\
**Replies:** 2\
**Last updated:** [June 18, 2025, 11:15am UTC](https://discuss.elastic.co/t/reloading-dictionary-decompounder-word-list-path/379206 "2025-06-18T11:15:33Z")

</div>

I've defined my own dictionary\_decompounder word list to cater for special words that are not matched by the German hyphenation\_decompounder: { "version": 3, "\_meta": { "description": "Default index sett…

---

## [ES\_PATH\_CONF ignored](https://discuss.elastic.co/t/es-path-conf-ignored/379262)

<div class="topic-metadata">

**Author:** [@h.koehler](https://discuss.elastic.co/u/h.koehler)\
**Replies:** 2\
**Last updated:** [June 18, 2025, 10:54am UTC](https://discuss.elastic.co/t/es-path-conf-ignored/379262 "2025-06-18T10:54:01Z")

</div>

What the title says. I already tried commenting out the source line in /usr/share/elasticsearch/bin/elasticsearch-env. My unit file: \[Unit\] Description=Elasticsearch %i Server Documentation=https://www.elastic.co Wants…

---

## [S3 Repo verification exception (Failed to connect to service endpoint)](https://discuss.elastic.co/t/s3-repo-verification-exception-failed-to-connect-to-service-endpoint/379244)

<div class="topic-metadata">

**Author:** [@staubt](https://discuss.elastic.co/u/staubt)\
**Replies:** 5\
**Last updated:** [June 18, 2025, 8:09am UTC](https://discuss.elastic.co/t/s3-repo-verification-exception-failed-to-connect-to-service-endpoint/379244 "2025-06-18T08:09:29Z")

</div>

Hello I'm using snapshotting for backup/restore. There I recreate each time the repository since the location in S3 can change. For the authentication I use two different clients "backup" and "restore". At the moment …

---

## [Elastic 30 day license renewal request](https://discuss.elastic.co/t/elastic-30-day-license-renewal-request/379264)

<div class="topic-metadata">

**Author:** [@jelliott1](https://discuss.elastic.co/u/jelliott1)\
**Replies:** 2\
**Last updated:** [June 17, 2025, 7:26pm UTC](https://discuss.elastic.co/t/elastic-30-day-license-renewal-request/379264 "2025-06-17T19:26:16Z")

</div>

Hello, my 30 day trial license for on-prem Elastic Stack expired before I could finish some validation tests. I filled out the renewal request form through Kibana a few weeks ago and have not heard anything. Assistance…

---

## [Index Automatically Deleted Every Few Days – ads\_index Disappears Without ILM Enabled](https://discuss.elastic.co/t/index-automatically-deleted-every-few-days-ads-index-disappears-without-ilm-enabled/379245)

<div class="topic-metadata">

**Author:** [@Developer\_G\_Design](https://discuss.elastic.co/u/Developer_G_Design)\
**Replies:** 8\
**Last updated:** [June 17, 2025, 2:41pm UTC](https://discuss.elastic.co/t/index-automatically-deleted-every-few-days-ads-index-disappears-without-ilm-enabled/379245 "2025-06-17T14:41:59Z")

</div>

Hello We’re encountering a critical issue where our custom index (ads\_index) is automatically deleted every 3–4 days without any manual action or lifecycle management policies in effect. Elasticsearch version: 8.18 Si…

---

## [Need Explanation ILM / DSL / closing indice and stuff](https://discuss.elastic.co/t/need-explanation-ilm-dsl-closing-indice-and-stuff/379232)

<div class="topic-metadata">

**Author:** [@Sebastien\_Tolron](https://discuss.elastic.co/u/Sebastien_Tolron)\
**Replies:** 0\
**Last updated:** [June 17, 2025, 8:56am UTC](https://discuss.elastic.co/t/need-explanation-ilm-dsl-closing-indice-and-stuff/379232 "2025-06-17T08:56:56Z")

</div>

Hi , Hi Everyone , I'm trying to understand what I've done with ILM and it looks messy :smiley: I need explanation and some help on good practices for that. The Setup : I have an Elasticsearch cluster with 10 Data …

---

## [Geo based pricing](https://discuss.elastic.co/t/geo-based-pricing/379199)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 16, 2025, 2:32pm UTC](https://discuss.elastic.co/t/geo-based-pricing/379199 "2025-06-16T14:32:34Z")

</div>

Is it possible to create a geo based pricing usecase with elasticsearch for retail index? Say, I search for a jacket from SFO, it should be $50 but from Denver, it should be $45. I see geo shape feature but how do you ap…

---

## [Question about Transport Client Compatibility with Elasticsearch 8.x](https://discuss.elastic.co/t/question-about-transport-client-compatibility-with-elasticsearch-8-x/379196)

<div class="topic-metadata">

**Author:** [@nickgarlis](https://discuss.elastic.co/u/nickgarlis)\
**Replies:** 2\
**Last updated:** [June 16, 2025, 10:53am UTC](https://discuss.elastic.co/t/question-about-transport-client-compatibility-with-elasticsearch-8-x/379196 "2025-06-16T10:53:58Z")

</div>

According to the Elasticsearch documentation, the Java client version 7.17 should be forward-compatible with 8.x clusters. We are currently using the Transport Client, not the High-Level REST Client. We’re aware that th…

---

## [.NET client Version 9.0.0 ElasticsearchClientProductRegistration ArgumentNullException](https://discuss.elastic.co/t/net-client-version-9-0-0-elasticsearchclientproductregistration-argumentnullexception/379174)

<div class="topic-metadata">

**Author:** [@Mahdi\_Abbasi](https://discuss.elastic.co/u/Mahdi_Abbasi)\
**Replies:** 1\
**Last updated:** [June 16, 2025, 7:42am UTC](https://discuss.elastic.co/t/net-client-version-9-0-0-elasticsearchclientproductregistration-argumentnullexception/379174 "2025-06-16T07:42:01Z")

</div>

Elastic.Clients.Elasticsearch version:9.0.0 Elasticsearch version:9.0.2 .NET runtime version:7.0.101 Operating system version:Windows 10.0.19045 Description of the problem: I am trying to connect to the elasticsearc…

---

## [Where is the release note of Go Client?](https://discuss.elastic.co/t/where-is-the-release-note-of-go-client/378882)

<div class="topic-metadata">

**Author:** [@johtani](https://discuss.elastic.co/u/johtani)\
**Replies:** 2\
**Last updated:** [June 16, 2025, 4:53am UTC](https://discuss.elastic.co/t/where-is-the-release-note-of-go-client/378882 "2025-06-16T04:53:30Z")

</div>

I can see some official clients release notes for Es 9 on Relase notes page. However , there is no Go Client. Does this mean there's nothing to be concerned about when upgrading to version 9? Or does it mean that Go C…

---

## [Installing Elasticsearch on Ubuntu 24](https://discuss.elastic.co/t/installing-elasticsearch-on-ubuntu-24/372215)

<div class="topic-metadata">

**Author:** [@Fredb69](https://discuss.elastic.co/u/Fredb69)\
**Replies:** 11\
**Last updated:** [June 15, 2025, 10:12pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-on-ubuntu-24/372215 "2025-06-15T22:12:06Z")

</div>

Hi I want installing Elasticsearch on Ubuntu 24 but I have a problem with the PGP Key. The message is : W: Erreur de GPG : https://artifacts.elastic.co/packages/8.x/apt stable InRelease : Les signatures suivantes n'on…

---

## [Service crashed | Disk Utilization was 100%](https://discuss.elastic.co/t/service-crashed-disk-utilization-was-100/379188)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [June 15, 2025, 10:03pm UTC](https://discuss.elastic.co/t/service-crashed-disk-utilization-was-100/379188 "2025-06-15T22:03:12Z")

</div>

Hi Team, We have 14 nodes of elasticsearch(v8.17) cluster(3 master+6 hot+5 warm) running on prem. Today our cluster was on red state and i have observed that one of the warm nodes was stopped because of disk was 100% . …

---

## [ES|QL query message format](https://discuss.elastic.co/t/es-ql-query-message-format/379171)

<div class="topic-metadata">

**Author:** [@pruna](https://discuss.elastic.co/u/pruna)\
**Replies:** 7\
**Last updated:** [June 14, 2025, 4:19pm UTC](https://discuss.elastic.co/t/es-ql-query-message-format/379171 "2025-06-14T16:19:35Z")

</div>

Hi! I need to query elements for a specific month in a date field. For that, I'm trying my first ES|QL query, as follows: { "query": """ FROM facts | WHERE DATE\_PART('month', date\_start) = '06' """ } by doing …

---

## [Backup & Restore Scripts- Elasticsearch - 2.4.3](https://discuss.elastic.co/t/backup-restore-scripts-elasticsearch-2-4-3/379173)

<div class="topic-metadata">

**Author:** [@Akshay\_Kulkarni](https://discuss.elastic.co/u/Akshay_Kulkarni)\
**Replies:** 2\
**Last updated:** [June 14, 2025, 4:42pm UTC](https://discuss.elastic.co/t/backup-restore-scripts-elasticsearch-2-4-3/379173 "2025-06-14T16:42:08Z")

</div>

Posting For records. Note: These scripts tested against Elasticsearch 2.4.3 which is EOL. These scripts may or may not work with newer versions of elastic. 1\] Details: A\] Node1: 10.226.71.1 (Master + Data) B\] Node2:…

---

## [The maximum configured depth of 64 has been exceeded. Cannot read next JSON object](https://discuss.elastic.co/t/the-maximum-configured-depth-of-64-has-been-exceeded-cannot-read-next-json-object/378954)

<div class="topic-metadata">

**Author:** [@Nikos\_Levogiannis](https://discuss.elastic.co/u/Nikos_Levogiannis)\
**Replies:** 10\
**Last updated:** [June 14, 2025, 7:45am UTC](https://discuss.elastic.co/t/the-maximum-configured-depth-of-64-has-been-exceeded-cannot-read-next-json-object/378954 "2025-06-14T07:45:32Z")

</div>

I am trying to make a search request using the new ElasticsearchClient 8.18 (C# .net) with a high number of aggregations and I get the error : The maximum configured depth of 64 has been exceeded. Cannot read next JSON …

---

## [Elastic Common Schema For Network Devices/SNMP](https://discuss.elastic.co/t/elastic-common-schema-for-network-devices-snmp/379168)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [June 13, 2025, 4:41pm UTC](https://discuss.elastic.co/t/elastic-common-schema-for-network-devices-snmp/379168 "2025-06-13T16:41:31Z")

</div>

Hello, Does elastic have standardized fields for network devices? If not, is there plans for it? Thanks, E

---

## [Use of retrievers in the search api](https://discuss.elastic.co/t/use-of-retrievers-in-the-search-api/379145)

<div class="topic-metadata">

**Author:** [@aperez900907](https://discuss.elastic.co/u/aperez900907)\
**Replies:** 2\
**Last updated:** [June 13, 2025, 3:00pm UTC](https://discuss.elastic.co/t/use-of-retrievers-in-the-search-api/379145 "2025-06-13T15:00:14Z")

</div>

Hi, I'm getting this error below: { "error": { "root\_cause": \[ { "type": "security\_exception", "reason": "current license is non-compliant for \[linear retriever\]", "license.expired.fe…

---

## [.NET NEST 7.17.5 and Elastic Version 9.0.2](https://discuss.elastic.co/t/net-nest-7-17-5-and-elastic-version-9-0-2/379165)

<div class="topic-metadata">

**Author:** [@urbanjasmine](https://discuss.elastic.co/u/urbanjasmine)\
**Replies:** 1\
**Last updated:** [June 13, 2025, 12:58pm UTC](https://discuss.elastic.co/t/net-nest-7-17-5-and-elastic-version-9-0-2/379165 "2025-06-13T12:58:07Z")

</div>

Hello everyone, We have been using the NEST .NET package to connect to Elastic and make calls/searches. Current situation: .NET Nest 7.17.5 Elastic version 8.16.3. To maintain compatibility, we are using the followi…

---

## [CTFd access issues](https://discuss.elastic.co/t/ctfd-access-issues/379148)

<div class="topic-metadata">

**Author:** [@crash2025](https://discuss.elastic.co/u/crash2025)\
**Replies:** 0\
**Last updated:** [June 12, 2025, 7:17pm UTC](https://discuss.elastic.co/t/ctfd-access-issues/379148 "2025-06-12T19:17:38Z")

</div>

Signed up for a free class but cannot access the lab. On step 5 it says to register but I do not get the screen . ANy idea of what to do ??

---

## [Enrich IP address with custom mmdb database using ingest pipeline](https://discuss.elastic.co/t/enrich-ip-address-with-custom-mmdb-database-using-ingest-pipeline/379102)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 10\
**Last updated:** [June 12, 2025, 3:50pm UTC](https://discuss.elastic.co/t/enrich-ip-address-with-custom-mmdb-database-using-ingest-pipeline/379102 "2025-06-12T15:50:07Z")

</div>

I have below document in elasticsearch { "\_index": "test", "\_id": "guv6X5cBSvotes9C4gZS", "\_score": 1, "\_source": { "name": "Alice", "source.ip": "172.22.1.11" …

---

## [Ingest pipeline is not working for given document](https://discuss.elastic.co/t/ingest-pipeline-is-not-working-for-given-document/379099)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 6\
**Last updated:** [June 11, 2025, 5:02pm UTC](https://discuss.elastic.co/t/ingest-pipeline-is-not-working-for-given-document/379099 "2025-06-11T17:02:45Z")

</div>

i have below record which i want to process. \[ { "\_id": "GFk-X5cBY6REVzo7i86y", "\_index": "processor\_test", "\_source": { "event.original":"172.16.102.98 - - \[11/Jun/2025:19:05:43 +0530\] \\"POST /api/…

---

## [\[Docker\] Elasticsearch Docker container stuck on "loaded module \[...\]" logs and never fully starts](https://discuss.elastic.co/t/docker-elasticsearch-docker-container-stuck-on-loaded-module-logs-and-never-fully-starts/378991)

<div class="topic-metadata">

**Author:** [@manbra](https://discuss.elastic.co/u/manbra)\
**Replies:** 11\
**Last updated:** [June 12, 2025, 12:39pm UTC](https://discuss.elastic.co/t/docker-elasticsearch-docker-container-stuck-on-loaded-module-logs-and-never-fully-starts/378991 "2025-06-12T12:39:18Z")

</div>

Description While running the Elasticsearch container (tag: docker.elastic.co/elasticsearch/elasticsearch:8.13.4), the service fails to complete startup and gets stuck after logging multiple loaded module \[...\] messages…

---

## [Elastic stack license](https://discuss.elastic.co/t/elastic-stack-license/379134)

<div class="topic-metadata">

**Author:** [@adilraad2001](https://discuss.elastic.co/u/adilraad2001)\
**Replies:** 1\
**Last updated:** [June 12, 2025, 11:57am UTC](https://discuss.elastic.co/t/elastic-stack-license/379134 "2025-06-12T11:57:51Z")

</div>

Hello Guys I have an Elastic stack deployed in my VM(On Premise) and now i want to buy License to open features like Connectors and ML is there anyone knew where i can find the prices of license (Standrad , Gold , Pla…

---

## [Is it necessary to be running 7.17.28 before upgrade to 8?](https://discuss.elastic.co/t/is-it-necessary-to-be-running-7-17-28-before-upgrade-to-8/379129)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [June 12, 2025, 10:37am UTC](https://discuss.elastic.co/t/is-it-necessary-to-be-running-7-17-28-before-upgrade-to-8/379129 "2025-06-12T10:37:45Z")

</div>

Is it necessary to be running Elasticsearch 7.17.28 before upgrade to 8? An instance of Kibana upgrade assistant doesn't say anything about having to upgrade from 7.17.x that it's looking at. I can't find any documenta…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=27)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=29)
