# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=280

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 281

---

## [CircuitBreakingException: \[parent\] Data too large IN ES 7.3.2](https://discuss.elastic.co/t/circuitbreakingexception-parent-data-too-large-in-es-7-3-2/328788)

<div class="topic-metadata">

**Author:** [@Rahul\_Sen](https://discuss.elastic.co/u/Rahul_Sen)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 9:01am UTC](https://discuss.elastic.co/t/circuitbreakingexception-parent-data-too-large-in-es-7-3-2/328788 "2023-03-29T09:01:59Z")

</div>

Hi, We recently started to get multiple shards failures in one of our Kibana dashboards, and on checking the response it was found that we getting CircuitBreakingException: \[parent\] Data too large, exact error is given …

---

## [Elasticsearch doesn't see data](https://discuss.elastic.co/t/elasticsearch-doesnt-see-data/328702)

<div class="topic-metadata">

**Author:** [@freeman999](https://discuss.elastic.co/u/freeman999)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 8:49am UTC](https://discuss.elastic.co/t/elasticsearch-doesnt-see-data/328702 "2023-03-29T08:49:44Z")

</div>

hello everyone, I have running elasticsearch in docker container. Data stores like: "Mounts": \[ { "Type": "bind", "Source": "/opt/elasticsearch/data", "Destin…

---

## [Does es node prioritize local shard for searching?](https://discuss.elastic.co/t/does-es-node-prioritize-local-shard-for-searching/328790)

<div class="topic-metadata">

**Author:** [@clp991666](https://discuss.elastic.co/u/clp991666)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 8:19am UTC](https://discuss.elastic.co/t/does-es-node-prioritize-local-shard-for-searching/328790 "2023-03-29T08:19:24Z")

</div>

Hi, I use es cluster to serve a small index (\<1G) for searching and aggregation and so only 1 shard is assigned and 1 replica. As 1 node does not able to serve all the request fast enough so the cluster scale to 10 node…

---

## [Match with type phrase\_prefix doesn't work when words mix numbers and letters](https://discuss.elastic.co/t/match-with-type-phrase-prefix-doesnt-work-when-words-mix-numbers-and-letters/328743)

<div class="topic-metadata">

**Author:** [@Raphael\_Fidelis](https://discuss.elastic.co/u/Raphael_Fidelis)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 10:44pm UTC](https://discuss.elastic.co/t/match-with-type-phrase-prefix-doesnt-work-when-words-mix-numbers-and-letters/328743 "2023-03-28T22:44:17Z")

</div>

I'm trying to query as such: { "match": { "query": "100", "fields": "description", "type": "phrase\_prefix" } } However, if I search for "100" wanting to find, for example, a document with the "d…

---

## [Upgrade assistant](https://discuss.elastic.co/t/upgrade-assistant/328740)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 6:44pm UTC](https://discuss.elastic.co/t/upgrade-assistant/328740 "2023-03-28T18:44:21Z")

</div>

I have 8.5 and can't find upgrade assistant? where did it moved? I am logged in as user elastic

---

## [Document-level security on eleastic vs solr](https://discuss.elastic.co/t/document-level-security-on-eleastic-vs-solr/328488)

<div class="topic-metadata">

**Author:** [@SandraIsCool](https://discuss.elastic.co/u/SandraIsCool)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 6:32pm UTC](https://discuss.elastic.co/t/document-level-security-on-eleastic-vs-solr/328488 "2023-03-28T18:32:54Z")

</div>

We are using Solr now but perhaps elastic is a better choice for us. Looking to see if it makes sense to switch: Scenario I am working on a Customer Service Ticketing solution where we need to search ticket metadata, n…

---

## [Exaggerated consumption of ES instance](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 9\
**Last updated:** [March 28, 2023, 5:09pm UTC](https://discuss.elastic.co/t/exaggerated-consumption-of-es-instance/328616 "2023-03-28T17:09:54Z")

</div>

Hello! I have an Elastic cloud cluster where I have 2 instances. Each instance is 120GB in size and works as replicas in different Availability Zones for redundancy. Something strange happened that I can't understand w…

---

## [Set Field Value in Painless Script by Field Name as String](https://discuss.elastic.co/t/set-field-value-in-painless-script-by-field-name-as-string/328719)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 2:25pm UTC](https://discuss.elastic.co/t/set-field-value-in-painless-script-by-field-name-as-string/328719 "2023-03-28T14:25:23Z")

</div>

TL;DR I'm trying to pass in a nested key to a Painless script as a string and set that key from the script, but it's not working. How do I do this?# Use Case Long Version Use Case As a user, I need to perform the same t…

---

## [Distributing load test driver, docker container limitation](https://discuss.elastic.co/t/distributing-load-test-driver-docker-container-limitation/328484)

<div class="topic-metadata">

**Author:** [@Rich2023](https://discuss.elastic.co/u/Rich2023)\
**Replies:** 4\
**Last updated:** [March 28, 2023, 2:13pm UTC](https://discuss.elastic.co/t/distributing-load-test-driver-docker-container-limitation/328484 "2023-03-28T14:13:11Z")

</div>

Preamble that I'm relatively new to Elasticsearch, load testing, and by no means a cloud infrastructure expert... I've had success with esrally and creating a new track to test a custom search query load, both against a…

---

## [Elasticsearch JMX Error](https://discuss.elastic.co/t/elasticsearch-jmx-error/328651)

<div class="topic-metadata">

**Author:** [@abrooky](https://discuss.elastic.co/u/abrooky)\
**Replies:** 4\
**Last updated:** [March 28, 2023, 2:12pm UTC](https://discuss.elastic.co/t/elasticsearch-jmx-error/328651 "2023-03-28T14:12:05Z")

</div>

On CentOS 7 I get this error with most Elasticsearch commands; Does anyone know how I can reslove it? I've spent ages on Google. TIA. :slight\_smile: # bin/elasticsearch-create-enrollment-token -s kibana 2023-03-27 21:0…

---

## [API or similar to get data from Elastic into Excel](https://discuss.elastic.co/t/api-or-similar-to-get-data-from-elastic-into-excel/328697)

<div class="topic-metadata">

**Author:** [@HenrikTide](https://discuss.elastic.co/u/HenrikTide)\
**Replies:** 4\
**Last updated:** [March 28, 2023, 12:29pm UTC](https://discuss.elastic.co/t/api-or-similar-to-get-data-from-elastic-into-excel/328697 "2023-03-28T12:29:52Z")

</div>

Is there an API or similar tool available to achieve the goal of getting live data from Elastic into Excel and updating it automatically? /Henrik

---

## [Not analyzed attribute in nest 7.17](https://discuss.elastic.co/t/not-analyzed-attribute-in-nest-7-17/328600)

<div class="topic-metadata">

**Author:** [@reza\_setareh](https://discuss.elastic.co/u/reza_setareh)\
**Replies:** 5\
**Last updated:** [March 28, 2023, 10:42am UTC](https://discuss.elastic.co/t/not-analyzed-attribute-in-nest-7-17/328600 "2023-03-28T10:42:29Z")

</div>

hi everyone i want to use not analyzed attribute in nest 7.17 but i cant find it it was in old versions with this code Index = FieldIndexOption.NotAnalyzed thank you

---

## [Get total number of matched nested objects present in a elastcsearch index](https://discuss.elastic.co/t/get-total-number-of-matched-nested-objects-present-in-a-elastcsearch-index/328418)

<div class="topic-metadata">

**Author:** [@sudheesh](https://discuss.elastic.co/u/sudheesh)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 6:13am UTC](https://discuss.elastic.co/t/get-total-number-of-matched-nested-objects-present-in-a-elastcsearch-index/328418 "2023-03-28T06:13:46Z")

</div>

consider the following example where I have an index with a nested field { "mappings": { "properties": { "class": { "type": "text" }, "subject": { "type": "nested", "prope…

---

## [Optimizing for reads with very small and stable index](https://discuss.elastic.co/t/optimizing-for-reads-with-very-small-and-stable-index/328442)

<div class="topic-metadata">

**Author:** [@Meisseli](https://discuss.elastic.co/u/Meisseli)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 9:41am UTC](https://discuss.elastic.co/t/optimizing-for-reads-with-very-small-and-stable-index/328442 "2023-03-28T09:41:57Z")

</div>

Hello! I'm working with a very small index. It is only 65000 documents and is about 50MB in size. Index is also very "stable" since it is only written once a day and does not receive any writes meanwhile. Because of tha…

---

## [ILM delete phase does not seem to do anything to index](https://discuss.elastic.co/t/ilm-delete-phase-does-not-seem-to-do-anything-to-index/328592)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 9:36am UTC](https://discuss.elastic.co/t/ilm-delete-phase-does-not-seem-to-do-anything-to-index/328592 "2023-03-28T09:36:44Z")

</div>

Hi I have a cloud Instance I use for a research project. It has 180gb disk space and it is almost full and causing problems to my stack. I want to free up some space so I looked at the indices that are using up all my s…

---

## [Sorting on the sub-aggregation fields and applying Pagination on the same](https://discuss.elastic.co/t/sorting-on-the-sub-aggregation-fields-and-applying-pagination-on-the-same/328693)

<div class="topic-metadata">

**Author:** [@Abhijeet\_Gosai](https://discuss.elastic.co/u/Abhijeet_Gosai)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 9:31am UTC](https://discuss.elastic.co/t/sorting-on-the-sub-aggregation-fields-and-applying-pagination-on-the-same/328693 "2023-03-28T09:31:00Z")

</div>

I need to sort the aggregation on the basis of sub-aggregation values and also apply pagination on the same . I found in documentation that we can do pagination with composite aggregation but can not sort on the basis o…

---

## [Explanation for potential security issue?](https://discuss.elastic.co/t/explanation-for-potential-security-issue/328680)

<div class="topic-metadata">

**Author:** [@amc1](https://discuss.elastic.co/u/amc1)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 8:19am UTC](https://discuss.elastic.co/t/explanation-for-potential-security-issue/328680 "2023-03-28T08:19:49Z")

</div>

Hi all, In this video- the video summary says that adding Letsencrypt certs means that other nodes with publicly signed certs can connect, so use a firewall. I am super confused about this - is it a secur…

---

## [Inaccuracy and noises in elastic search rollup data](https://discuss.elastic.co/t/inaccuracy-and-noises-in-elastic-search-rollup-data/328014)

<div class="topic-metadata">

**Author:** [@Mehrab\_Azad](https://discuss.elastic.co/u/Mehrab_Azad)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 7:13am UTC](https://discuss.elastic.co/t/inaccuracy-and-noises-in-elastic-search-rollup-data/328014 "2023-03-28T07:13:38Z")

</div>

I am new to the ELK stack and Elasticsearch. I am currently storing nginx logs in Elasticsearch and using Kibana to visualize the total bytes over time. The purpose of this is to monitor traffic. To reduce storage requir…

---

## [Restore the old behavior for SearchResponse in Elasticsearch 8](https://discuss.elastic.co/t/restore-the-old-behavior-for-searchresponse-in-elasticsearch-8/328678)

<div class="topic-metadata">

**Author:** [@Emanuel\_Zienecker](https://discuss.elastic.co/u/Emanuel_Zienecker)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 7:00am UTC](https://discuss.elastic.co/t/restore-the-old-behavior-for-searchresponse-in-elasticsearch-8/328678 "2023-03-28T07:00:21Z")

</div>

Due to missing compatibility with the GeoBoundingBox query I am forced to use ad-hoc the new Elasticsearch 8 Java client. According to the documentation, when using the search, a document class must now be specified that…

---

## [Elastic Node.processors configuration](https://discuss.elastic.co/t/elastic-node-processors-configuration/328593)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 6:07am UTC](https://discuss.elastic.co/t/elastic-node-processors-configuration/328593 "2023-03-28T06:07:58Z")

</div>

Hi, I am running multiple instances (4 data nodes) on the same machine. When running load tests, I see the each node CPU is ~20-30% and Host CPU is ~92%. Elastic recommend to configure Node.processors in such case an…

---

## [Data is lost after elasticsearch restart](https://discuss.elastic.co/t/data-is-lost-after-elasticsearch-restart/328663)

<div class="topic-metadata">

**Author:** [@simplearebest](https://discuss.elastic.co/u/simplearebest)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 5:57am UTC](https://discuss.elastic.co/t/data-is-lost-after-elasticsearch-restart/328663 "2023-03-28T05:57:05Z")

</div>

The cluster(es 2.4.0) contains three nodes (node137,node138,node139) , create an index, 5 shards, and 1 replica. I follow these steps to test: the cluster status is green. shutdown node137. create large amount of data…

---

## [Does Rally support benchmark test to multi-instance elasticsearch in single node?](https://discuss.elastic.co/t/does-rally-support-benchmark-test-to-multi-instance-elasticsearch-in-single-node/328514)

<div class="topic-metadata">

**Author:** [@Qinghe12](https://discuss.elastic.co/u/Qinghe12)\
**Replies:** 5\
**Last updated:** [March 28, 2023, 5:37am UTC](https://discuss.elastic.co/t/does-rally-support-benchmark-test-to-multi-instance-elasticsearch-in-single-node/328514 "2023-03-28T05:37:06Z")

</div>

Hi,I want to start on 2 elasticseach instances（ES0 and ES1） in a single node with different port，and use 2 esrally ( esrally0 and esrally1) to benchmark these 2 elasticseach instances. But I find esrally1 cannot start …

---

## [Optimal size of shard: Is 80GB Per shard ok for this use case](https://discuss.elastic.co/t/optimal-size-of-shard-is-80gb-per-shard-ok-for-this-use-case/328668)

<div class="topic-metadata">

**Author:** [@hitesharyal](https://discuss.elastic.co/u/hitesharyal)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 5:30am UTC](https://discuss.elastic.co/t/optimal-size-of-shard-is-80gb-per-shard-ok-for-this-use-case/328668 "2023-03-28T05:30:51Z")

</div>

I am using version 5.5.2 of Elasticsearch( having 3 Nodes= 64 gb each ) with month wise index creation. Daily data insertion is 17 GB i.e 17 \* 30 = 510 GB/month. Right now i am having 6 shards(85gb/shard),1 replica in …

---

## [\[gc\]\[2661\] overhead, spent \[263ms\] collecting in the last \[1s\]](https://discuss.elastic.co/t/gc-2661-overhead-spent-263ms-collecting-in-the-last-1s/328660)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 4:02am UTC](https://discuss.elastic.co/t/gc-2661-overhead-spent-263ms-collecting-in-the-last-1s/328660 "2023-03-28T04:02:24Z")

</div>

ES Version: 6.3.0 OS Version: 7.4 Java Version: 1.8.0\_131 cpu cores: 20 memory: total 64g heap 32g There is nearly only the ES service on the server, I wonder should I decrease the heap size less than 32g? Or tot…

---

## [Inconsistent scoring starting w/ 7.0.0 (worse in 7.4.0)](https://discuss.elastic.co/t/inconsistent-scoring-starting-w-7-0-0-worse-in-7-4-0/328658)

<div class="topic-metadata">

**Author:** [@workmanw](https://discuss.elastic.co/u/workmanw)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 2:21am UTC](https://discuss.elastic.co/t/inconsistent-scoring-starting-w-7-0-0-worse-in-7-4-0/328658 "2023-03-28T02:21:36Z")

</div>

Hello, I'm in the process of upgrading from 6.x to 7.x. Along the way I discovered an unexpected issue with document updates and relevancy scoring. In my application's integration test suite we have a series of very bas…

---

## [Is elasticsearch documents stored on file encrypted?](https://discuss.elastic.co/t/is-elasticsearch-documents-stored-on-file-encrypted/328652)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 12:50am UTC](https://discuss.elastic.co/t/is-elasticsearch-documents-stored-on-file-encrypted/328652 "2023-03-28T00:50:39Z")

</div>

Hi, We have a compliance audit coming up soon and one of the requirement is that the information stored in Elastic (as a SIEM) must be encrypted. Now, I understand that Elastic don't do encryption because these documen…

---

## [Error in the installation Elasticsearch process](https://discuss.elastic.co/t/error-in-the-installation-elasticsearch-process/328607)

<div class="topic-metadata">

**Author:** [@Hubert\_Homaei](https://discuss.elastic.co/u/Hubert_Homaei)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 10:28pm UTC](https://discuss.elastic.co/t/error-in-the-installation-elasticsearch-process/328607 "2023-03-27T22:28:48Z")

</div>

Hi, I wanted to install Elastic search on a local system; I checked all requirements, installed JDK, and set the variable path for java.exe. But when I execute elasticsearch.bat in CMD, I got this warning: warning: igno…

---

## [Metricbeat:action \[indices:admin/auto\_create\] is unauthorized for user \[metricbeat\] with effective roles \[ES\_metricbeat\] on indices \[metricbeat-8.6.2\], this action is granted by the index privileges](https://discuss.elastic.co/t/metricbeat-action-indices-admin-auto-create-is-unauthorized-for-user-metricbeat-with-effective-roles-es-metricbeat-on-indices-metricbeat-8-6-2-this-action-is-granted-by-the-index-privileges/328648)

<div class="topic-metadata">

**Author:** [@Tussingh](https://discuss.elastic.co/u/Tussingh)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 7:54pm UTC](https://discuss.elastic.co/t/metricbeat-action-indices-admin-auto-create-is-unauthorized-for-user-metricbeat-with-effective-roles-es-metricbeat-on-indices-metricbeat-8-6-2-this-action-is-granted-by-the-index-privileges/328648 "2023-03-27T19:54:33Z")

</div>

I am facing error in ingesting data from metricbeat to elastic. Please help {"log.level":"warn","@timestamp":"2023-03-28T01:22:21.499+0530","log.logger":"elasticsearch","log.origin":{"file.name":"elasticsearch/client.go…

---

## [Elastic Search First Query is always slow and shards not getting distributed properly](https://discuss.elastic.co/t/elastic-search-first-query-is-always-slow-and-shards-not-getting-distributed-properly/328639)

<div class="topic-metadata">

**Author:** [@Gaurav\_Sachdeva](https://discuss.elastic.co/u/Gaurav_Sachdeva)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-search-first-query-is-always-slow-and-shards-not-getting-distributed-properly/328639 "2023-03-27T18:29:39Z")

</div>

I am creating per day index in Elastic Search ( version: 7.5.1 ). I have 3 nodes in total and 2 shards with one replica each, total disk: 5.6 TB and JVM Heap: 95.8 GB per day index size is 40 GB with 110m documents. I …

---

## [Split data in painless](https://discuss.elastic.co/t/split-data-in-painless/327576)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 6:28pm UTC](https://discuss.elastic.co/t/split-data-in-painless/327576 "2023-03-27T18:28:52Z")

</div>

Hi team This is part of a watcher that i'm doing, but split part is nor working, this is my example String indices = "index1\\nindex2\\n"; String\[\] arr = indices.split('\\n'); return arr; But i g…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=279)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=281)
