# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=283

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 284

---

## [co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/indices.create\] failed: \[resource\_already\_exists\_exception\] index \[\[test1111/OvwpReOdTNa-44HKedMUrw\]\]already exists](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-types-elasticsearchexception-es-indices-create-failed-resource-already-exists-exception-index-test1111-ovwpreodtna-44hkedmurw-already-exists/328321)

<div class="topic-metadata">

**Author:** [@chinaman](https://discuss.elastic.co/u/chinaman)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 8:25am UTC](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-types-elasticsearchexception-es-indices-create-failed-resource-already-exists-exception-index-test1111-ovwpreodtna-44hkedmurw-already-exists/328321 "2023-03-23T08:25:57Z")

</div>

Create index use elasticsearchClient.indices() , Executed Exception:co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/indices.create\] failed:\[resource\_already\_exists\_exception\] index \[test12345/OvwpReOd…

---

## [Snapshot Repository integration with GitHub](https://discuss.elastic.co/t/snapshot-repository-integration-with-github/328307)

<div class="topic-metadata">

**Author:** [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:17am UTC](https://discuss.elastic.co/t/snapshot-repository-integration-with-github/328307 "2023-03-23T08:17:12Z")

</div>

Hi, We've currently enabled Snapshots in our cluster with Amazon S3 buckets and everything it going great. I'm just exploring on new repository connections which can be applied with Elasticsearch Snapshots enablement. …

---

## [Too much network data out in 8.4.3 elasticsearch](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182)

<div class="topic-metadata">

**Author:** [@Dharampal\_Singh](https://discuss.elastic.co/u/Dharampal_Singh)\
**Replies:** 9\
**Last updated:** [March 23, 2023, 5:43am UTC](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182 "2023-03-23T05:43:09Z")

</div>

HI We have migrated from elasticsearch 6.2.3 to 8.4.3 and seeing huge network data transfer cost.is anyone else also facing this issue or its suppose to be happen. in my configuration only 3 node cluster all are mater …

---

## [Why is the length of keyword array always 1?](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164)

<div class="topic-metadata">

**Author:** [@lyq2333](https://discuss.elastic.co/u/lyq2333)\
**Replies:** 6\
**Last updated:** [March 23, 2023, 12:56am UTC](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164 "2023-03-23T00:56:28Z")

</div>

I create an index by PUT my-index-000002 { "mappings": { "properties": { "content":{ "type": "keyword", "index\_options": "freqs" }, "id":{ "type": "integer" } } …

---

## [ORing a text field with a unique identifier keyword field leading to increased next\_doc count and poor performance](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283)

<div class="topic-metadata">

**Author:** [@helderdias](https://discuss.elastic.co/u/helderdias)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 11:24pm UTC](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283 "2023-03-22T23:24:18Z")

</div>

TL;DR: I want to find documents that match a certain query (e.g. "my search") OR match the unique ID of a document. When I search for the text field alone, the search is super fast. However, when I or the text field wit…

---

## [Speed question between v5 and 7 and 8](https://discuss.elastic.co/t/speed-question-between-v5-and-7-and-8/328291)

<div class="topic-metadata">

**Author:** [@Ahmed\_Alsamarrai](https://discuss.elastic.co/u/Ahmed_Alsamarrai)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:56pm UTC](https://discuss.elastic.co/t/speed-question-between-v5-and-7-and-8/328291 "2023-03-22T19:56:37Z")

</div>

Hi, We are facing a situation which we would like to resolve. We have a server running Elastic version 5.6 (on Docker). We wanted to upgrade and tried 7.17, on the same network, on a machine which is identical and also…

---

## [Unable to PUT \_index\_template which was captured from GET \_index\_template](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 7:14pm UTC](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221 "2023-03-22T19:14:32Z")

</div>

I am getting an index template as follows: curl -X GET http://localhost:9200/\_index\_template/filebeat\* \> /var/tmp/filebeat-template.json Now I want to PUT the same template into another elastic instance: curl http://…

---

## [Snapshots and malicious deletion of backups](https://discuss.elastic.co/t/snapshots-and-malicious-deletion-of-backups/328191)

<div class="topic-metadata">

**Author:** [@jgimenez](https://discuss.elastic.co/u/jgimenez)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 7:07pm UTC](https://discuss.elastic.co/t/snapshots-and-malicious-deletion-of-backups/328191 "2023-03-22T19:07:10Z")

</div>

Hi there, I'm evaluating the options to protect against malicious deletion of backups. The recommendation is usually to keep some of the backups in offline storage and give the backup process the minimum permission poss…

---

## [{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340)

<div class="topic-metadata">

**Author:** [@nvelumani](https://discuss.elastic.co/u/nvelumani)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 6:43pm UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340 "2023-03-22T18:43:59Z")

</div>

Hello Team, I have installed elastic version 8.5.2 on three node cluster, it runs good. when I take down down node 2 (master -2), cluster is up and running with other two nodes. when I take down down node 3 (master -3…

---

## [Error when starting Elasticsearch single node](https://discuss.elastic.co/t/error-when-starting-elasticsearch-single-node/328207)

<div class="topic-metadata">

**Author:** [@abctha1234](https://discuss.elastic.co/u/abctha1234)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 5:17pm UTC](https://discuss.elastic.co/t/error-when-starting-elasticsearch-single-node/328207 "2023-03-22T17:17:20Z")

</div>

My docker-compose.yaml elasticsearch: container\_name: elasticsearch image: docker.elastic.co/elasticsearch/elasticsearch:8.6.2 volumes: - elasticsearch\_data:/usr/share/elasticsearch/data - cert…

---

## [Elasticsearch endpoint giving http 504 error](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276)

<div class="topic-metadata">

**Author:** [@Raman\_Sawhney](https://discuss.elastic.co/u/Raman_Sawhney)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:58pm UTC](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276 "2023-03-22T16:58:16Z")

</div>

Hello Team, I am trying to install Elasticsearch on Kubernetes (1.24) version using the Elasticsearch(8.5.1) helm charts. I was able to install the charts and pods are in running status but when i tried to access the e…

---

## [Convert unix timestamp to epoch\_second and assign to @timestamp](https://discuss.elastic.co/t/convert-unix-timestamp-to-epoch-second-and-assign-to-timestamp/328133)

<div class="topic-metadata">

**Author:** [@nika](https://discuss.elastic.co/u/nika)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:54pm UTC](https://discuss.elastic.co/t/convert-unix-timestamp-to-epoch-second-and-assign-to-timestamp/328133 "2023-03-22T16:54:11Z")

</div>

I'm sorry if this is covered elsewhere, but I have been having trouble getting this to work. I have a field in a log being sent to elasticsearch from filebeat. The log is ndjson formatted. The field is called time and…

---

## [ES persistent outages](https://discuss.elastic.co/t/es-persistent-outages/327395)

<div class="topic-metadata">

**Author:** [@orthecreedence](https://discuss.elastic.co/u/orthecreedence)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 4:22pm UTC](https://discuss.elastic.co/t/es-persistent-outages/327395 "2023-03-22T16:22:35Z")

</div>

Hello. We recently upgraded to ES 7.17.9 (8.x is on the radar, but we have a lot of reindexing to do before then) and are having a lot of problems. We're using a fairly stock configuration on EC2. Our setup consists of …

---

## [Why I get after Client.Indices.Create() a second and unassigned index?](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 3:34pm UTC](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264 "2023-03-22T15:34:12Z")

</div>

I create a index on Elasticsearch with the C# code below. But instead of creating one assigned index I find a second unassigned index with the same name. I don't want and need this second (unassigned) index. My elasticse…

---

## [Increase doc\_count even if record is same in date\_histogram on Array field](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257)

<div class="topic-metadata">

**Author:** [@AbhimanyuSharma](https://discuss.elastic.co/u/AbhimanyuSharma)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 2:16pm UTC](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257 "2023-03-22T14:16:41Z")

</div>

I have an object / array field which contains date-time. This field contains every second of the duration between start and end time of some event. I am doing this because I want to see the running events on each second.…

---

## [Intermittent outbound connection issue to elastic cloud from azure app service](https://discuss.elastic.co/t/intermittent-outbound-connection-issue-to-elastic-cloud-from-azure-app-service/328181)

<div class="topic-metadata">

**Author:** [@chiragsharp](https://discuss.elastic.co/u/chiragsharp)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 1:36pm UTC](https://discuss.elastic.co/t/intermittent-outbound-connection-issue-to-elastic-cloud-from-azure-app-service/328181 "2023-03-22T13:36:47Z")

</div>

Hello Folks, I have a Virto Commerce deployed in azure app service. From app service intermittently, I am getting below error for connection to elastic cloud. Invalid NEST response built from a unsuccessful () low leve…

---

## [Elastic shards are not storing data equally](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235)

<div class="topic-metadata">

**Author:** [@Chanaka\_Liyanarachch](https://discuss.elastic.co/u/Chanaka_Liyanarachch)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:39pm UTC](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235 "2023-03-22T12:39:54Z")

</div>

elastic shards are not storing data equally,

---

## [Error al ejecutar docker compose](https://discuss.elastic.co/t/error-al-ejecutar-docker-compose/328239)

<div class="topic-metadata">

**Author:** [@karlosmartos](https://discuss.elastic.co/u/karlosmartos)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:37pm UTC](https://discuss.elastic.co/t/error-al-ejecutar-docker-compose/328239 "2023-03-22T12:37:18Z")

</div>

ERROR: \[1\] bootstrap checks failed. You must address the points described in the following \[1\] lines before starting Elasticsearch.

---

## [Restore indices on snapshots based on their alias](https://discuss.elastic.co/t/restore-indices-on-snapshots-based-on-their-alias/328237)

<div class="topic-metadata">

**Author:** [@Nuno\_Santos1](https://discuss.elastic.co/u/Nuno_Santos1)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 11:23am UTC](https://discuss.elastic.co/t/restore-indices-on-snapshots-based-on-their-alias/328237 "2023-03-22T11:23:43Z")

</div>

When restoring indices from a snapshot, is there a way to get from the snapshot the aliases associated with an index before starting to restore the index? Through the REST API I can get information about the indices that…

---

## [Too many properties: should we increase the property limit or use a nested approach and increase that limit?](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179)

<div class="topic-metadata">

**Author:** [@obi-wan](https://discuss.elastic.co/u/obi-wan)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 11:19am UTC](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179 "2023-03-22T11:19:59Z")

</div>

Hi there, We have a situation with limits in the mapping, and I am not sure what is the way to go as there are multiple solutions. I will start by describing the use case: there are multiple tenants, which each have …

---

## [UPDATE existing index with reindex and pipeline](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227)

<div class="topic-metadata">

**Author:** [@hben](https://discuss.elastic.co/u/hben)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:51am UTC](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227 "2023-03-22T09:51:54Z")

</div>

Hi, I have an index that our application is working with like a Relational table, so we insert and update documents in it. now we want to make a structure change and add 3 fields and add data to those fields from a ta…

---

## [Convert string to ip in painless processor](https://discuss.elastic.co/t/convert-string-to-ip-in-painless-processor/328189)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:39am UTC](https://discuss.elastic.co/t/convert-string-to-ip-in-painless-processor/328189 "2023-03-22T09:39:15Z")

</div>

Hello, Is there a way to convert a string to an ip address in a painless processor? Regards Hans

---

## [Mailenable server smtp activity logs using filebeat to elasticsearch](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:08am UTC](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852 "2023-03-22T09:08:34Z")

</div>

Hello Every one I am using elasticsearch 7.10 and filebeat 7.10 I want to pars following logs using filebeat to direct elasticsearch I have no Idea how I can achive can you please suggest me from my sample logs. 03/15/…

---

## [Databricks Spark SQL and Elasticsearch](https://discuss.elastic.co/t/databricks-spark-sql-and-elasticsearch/328028)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 6:19am UTC](https://discuss.elastic.co/t/databricks-spark-sql-and-elasticsearch/328028 "2023-03-22T06:19:45Z")

</div>

Is there any documentation related to Databricks Spark/Spark SQL integration with elasticsearch?

---

## [Query to find all the users with one role](https://discuss.elastic.co/t/query-to-find-all-the-users-with-one-role/328156)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:09am UTC](https://discuss.elastic.co/t/query-to-find-all-the-users-with-one-role/328156 "2023-03-22T04:09:14Z")

</div>

Hi Team, How can I find the user in ELK with one particular role. I can get all the users with following query: GET /\_security/user but when I try to find user with a role GET /\_security/user/ { "query":"select …

---

## [Migrating 7.17 to 8.0 (With Frozen Indices and Searchable Snapshots)](https://discuss.elastic.co/t/migrating-7-17-to-8-0-with-frozen-indices-and-searchable-snapshots/328106)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 1:15am UTC](https://discuss.elastic.co/t/migrating-7-17-to-8-0-with-frozen-indices-and-searchable-snapshots/328106 "2023-03-22T01:15:23Z")

</div>

Hello, I'm migrating a cluster from 7.17 to 8.0 and I have frozen indices. I read in the documentation that the frozen action was removed or deprecated in version 8, so I wanted to know I can I safely migrate to version…

---

## [Semantic Search API](https://discuss.elastic.co/t/semantic-search-api/328113)

<div class="topic-metadata">

**Author:** [@rpmansion](https://discuss.elastic.co/u/rpmansion)\
**Replies:** 7\
**Last updated:** [March 21, 2023, 8:52pm UTC](https://discuss.elastic.co/t/semantic-search-api/328113 "2023-03-21T20:52:25Z")

</div>

There is a semantic search API endpoint (/index\_name/\_semantic-search) that was released in the documentation, what is the reason this was removed?

---

## [Conflict fluent bit and elasticsearch](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 7:54pm UTC](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198 "2023-03-21T19:54:54Z")

</div>

Hello everyone, I just migrated my cluster from version 7.9 to 8.5 everything went well but I have problems with fluent. For some reason Fluent is not able to ingest on ELK. Here are some data. \[SERVICE\] Flush …

---

## [Best approach to implement ILM on a large index and archive old data](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:43pm UTC](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045 "2023-03-21T16:43:16Z")

</div>

Hi, We have a single node cluster where one index unfortunately grew very big (261Gb) as we had no ILM on it. This is a production cluster. We understand that above 50Gb there is performance degradation and I think we …

---

## [Maximum allowed string Issue](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076 "2023-03-21T16:21:11Z")

</div>

I get this error: The content length (732630494) is bigger than the maximum allowed string (536870888) I added to kibana.yml: server.maxPayloadBytes: 888888888 savedObjects.maxImportPayloadBytes: 50485760 I added to…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=282)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=284)
