# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=285

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 286

---

## [How can I restore logs from /usr/share/elasticsearch/data/nodes/0?](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822)

<div class="topic-metadata">

**Author:** [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 10:09am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822 "2023-03-20T10:09:19Z")

</div>

I am using Elasticsearch as a backend to save logs collected from Fluentd logging agent. Specifically, I've set up an EFK logging architecture in my Kubernetes cluster. (AWS EKS cluster to be specific) I've mounted the …

---

## [Error during startup](https://discuss.elastic.co/t/error-during-startup/327941)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 7\
**Last updated:** [March 20, 2023, 9:51am UTC](https://discuss.elastic.co/t/error-during-startup/327941 "2023-03-20T09:51:07Z")

</div>

Hi, I receive this error during startup: \[ERROR\]\[o.e.b.Elasticsearch \] \[s2ab00jb.be.srv.dev.sys\] fatal exception while booting Elasticsearch java.lang.IllegalArgumentException: Could not load codec 'Lucene94'. Di…

---

## [How to use Escape key value in query\_string](https://discuss.elastic.co/t/how-to-use-escape-key-value-in-query-string/327972)

<div class="topic-metadata">

**Author:** [@anon55421226](https://discuss.elastic.co/u/anon55421226)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 9:14am UTC](https://discuss.elastic.co/t/how-to-use-escape-key-value-in-query-string/327972 "2023-03-20T09:14:24Z")

</div>

So... according to the elasticsearch/QueryStringQueryBuilder.java at v7.16.3 · elastic/elasticsearch · GitHub code there should exists an escape parameter in the query\_string object, but how do i trigger it to escape my …

---

## [Is the basic free elasticsearch allows to send invitations and password reset mails?](https://discuss.elastic.co/t/is-the-basic-free-elasticsearch-allows-to-send-invitations-and-password-reset-mails/327938)

<div class="topic-metadata">

**Author:** [@coy\_aprieto](https://discuss.elastic.co/u/coy_aprieto)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/is-the-basic-free-elasticsearch-allows-to-send-invitations-and-password-reset-mails/327938 "2023-03-20T08:52:51Z")

</div>

Hi, I'm working on an elasticsearch platform for my company, and we are still using the free version for now. Is it possible to send invitations and password resets (i know alerts and generally mail stuff for kibana is…

---

## [Unable to create an enrollment token](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token/327917)

<div class="topic-metadata">

**Author:** [@geb](https://discuss.elastic.co/u/geb)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 8:47am UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token/327917 "2023-03-20T08:47:36Z")

</div>

Hi, i try to add a node at at new formed 8.6 cluster. As the first step i configured the ca, certificates and modified the elasticsearch.yml Cluster started -\> fine The error is also described in: This statement does…

---

## [How to add deletion policy in existing policy?](https://discuss.elastic.co/t/how-to-add-deletion-policy-in-existing-policy/328052)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 8:42am UTC](https://discuss.elastic.co/t/how-to-add-deletion-policy-in-existing-policy/328052 "2023-03-20T08:42:07Z")

</div>

I have a simple rotating policy and I want to add a deletion phase. This is not available in the UI, however I have done by creating a policy directly with PUT, including the delete section. My question is if it is poss…

---

## [Disable reads from few indices of an index pattern](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026)

<div class="topic-metadata">

**Author:** [@tarunpvss](https://discuss.elastic.co/u/tarunpvss)\
**Replies:** 7\
**Last updated:** [March 20, 2023, 7:06am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026 "2023-03-20T07:06:32Z")

</div>

Hi Team, I want to disable reads for few indices in an index pattern. I tried using index.blocks.read : true But due to this, when I am trying to query using index pattern, getting the below error { "error" : { …

---

## [Cannot suggest as I assume](https://discuss.elastic.co/t/cannot-suggest-as-i-assume/327604)

<div class="topic-metadata">

**Author:** [@Victor.Li](https://discuss.elastic.co/u/Victor.Li)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 7:19am UTC](https://discuss.elastic.co/t/cannot-suggest-as-i-assume/327604 "2023-03-14T07:19:27Z")

</div>

There's one field called 'table\_name' of which format is like 't\_data\_quality', 't\_data\_security'. Its mapping is "mappings": { "properties": { "table\_name": { "type": "text", "fields":{ "suggest":{ "type":"comp…

---

## [Exception "aggregation\_execution\_exception" after issues with not enough shards](https://discuss.elastic.co/t/exception-aggregation-execution-exception-after-issues-with-not-enough-shards/327907)

<div class="topic-metadata">

**Author:** [@Filisimus](https://discuss.elastic.co/u/Filisimus)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 6:43am UTC](https://discuss.elastic.co/t/exception-aggregation-execution-exception-after-issues-with-not-enough-shards/327907 "2023-03-20T06:43:51Z")

</div>

Hi guys, so we are using Graylog with Elasticsearch and when I tried to create additional indices we ran out of shards. I fixed the shard issue, created the new indices but if I use the new indices with existing indices…

---

## [Calculate disk space requirement for increasing replicas](https://discuss.elastic.co/t/calculate-disk-space-requirement-for-increasing-replicas/327552)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 6:29am UTC](https://discuss.elastic.co/t/calculate-disk-space-requirement-for-increasing-replicas/327552 "2023-03-20T06:29:52Z")

</div>

Im planning to increase replication of some of our indices and trying to understand the additional disk required for this. Looking at the test index below(1p:2r, store.size = 45mb, pri.store.size=15mb) would it be accura…

---

## [How is this hardware selection for 3 node cluster](https://discuss.elastic.co/t/how-is-this-hardware-selection-for-3-node-cluster/327715)

<div class="topic-metadata">

**Author:** [@jbates5873](https://discuss.elastic.co/u/jbates5873)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 6:23am UTC](https://discuss.elastic.co/t/how-is-this-hardware-selection-for-3-node-cluster/327715 "2023-03-20T06:23:48Z")

</div>

Hi All, We currently run a production 3 node cluster internally at our company on a VERY resource constrained server. We run it under a docker swarm, and have all or our services etc.. also within the swarm, so the 3 ho…

---

## [Multi node cluster failing to connect](https://discuss.elastic.co/t/multi-node-cluster-failing-to-connect/326753)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 4:29am UTC](https://discuss.elastic.co/t/multi-node-cluster-failing-to-connect/326753 "2023-03-20T04:29:02Z")

</div>

Hi, I'm having an issue with a multi node elasticsearch cluster where the nodes are failing to join in a docker swarm. received join request from \[{es01}{SBn0YXX-RyuPcEsz3vgdjA}{0l0I2h0HRteijUgnwwmvqg}{es01}{10.0.0.69}…

---

## [Indices not getting an ILM policy applied after rollover](https://discuss.elastic.co/t/indices-not-getting-an-ilm-policy-applied-after-rollover/327997)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 5:46pm UTC](https://discuss.elastic.co/t/indices-not-getting-an-ilm-policy-applied-after-rollover/327997 "2023-03-19T17:46:22Z")

</div>

I have a problem with indices not getting an ILM policy applied after rollover on a cluster (Elasticsearch, Logstash, and Kibana) that have recently been upgraded from 7.17 to 8.4 and have had our old legacy templates co…

---

## [Sending HTTPS requests to es01 running on docker-compose](https://discuss.elastic.co/t/sending-https-requests-to-es01-running-on-docker-compose/327728)

<div class="topic-metadata">

**Author:** [@anjankow](https://discuss.elastic.co/u/anjankow)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 12:38am UTC](https://discuss.elastic.co/t/sending-https-requests-to-es01-running-on-docker-compose/327728 "2023-03-20T00:38:51Z")

</div>

I'm using docker-compose setup as described here: And I'm able to send requests to e01 using curl passing a certificate and username with password. Now I want to send requests from my application to e01 node. I tried …

---

## [While searching how do I exclude only one object and include other object inside a nested object](https://discuss.elastic.co/t/while-searching-how-do-i-exclude-only-one-object-and-include-other-object-inside-a-nested-object/327322)

<div class="topic-metadata">

**Author:** [@Nabin\_Upreti](https://discuss.elastic.co/u/Nabin_Upreti)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:51pm UTC](https://discuss.elastic.co/t/while-searching-how-do-i-exclude-only-one-object-and-include-other-object-inside-a-nested-object/327322 "2023-03-19T23:51:49Z")

</div>

I want to search minimum of the negotiated\_rate where negotiated type is not percentage. I used must not query to filter out percentage but this results to excluding the whole document. Here I expect the minimum negotia…

---

## [How to use Java api UpdateRequest for conditional write with optimistic locking control in place](https://discuss.elastic.co/t/how-to-use-java-api-updaterequest-for-conditional-write-with-optimistic-locking-control-in-place/327386)

<div class="topic-metadata">

**Author:** [@ted2349](https://discuss.elastic.co/u/ted2349)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-to-use-java-api-updaterequest-for-conditional-write-with-optimistic-locking-control-in-place/327386 "2023-03-09T18:28:38Z")

</div>

Hi, My scenario is upsert the whole document with optimistic locking control (seqno/ primary term) I also want to do some conditional update meaning I want to update only when current doc's updatedAt is earlier than w…

---

## [How to get the Elastic search data running on my docker in my host](https://discuss.elastic.co/t/how-to-get-the-elastic-search-data-running-on-my-docker-in-my-host/327402)

<div class="topic-metadata">

**Author:** [@Anubhavg](https://discuss.elastic.co/u/Anubhavg)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:15pm UTC](https://discuss.elastic.co/t/how-to-get-the-elastic-search-data-running-on-my-docker-in-my-host/327402 "2023-03-19T23:15:09Z")

</div>

I am running the docker image of Elasticsearch and not able to bind the volume (/usr/share/elasticsearch/data) to my host volume (/home). I am using the following command: sudo docker run --name els6 --net elasticsearc…

---

## [Getting the latest transform trigger time in a continuous transform](https://discuss.elastic.co/t/getting-the-latest-transform-trigger-time-in-a-continuous-transform/327420)

<div class="topic-metadata">

**Author:** [@cwwongaz](https://discuss.elastic.co/u/cwwongaz)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 7:49am UTC](https://discuss.elastic.co/t/getting-the-latest-transform-trigger-time-in-a-continuous-transform/327420 "2023-03-10T07:49:03Z")

</div>

Hi, I am running a continuous transform at a 15-minute frequency to transform the data from index\_A to index\_B. In the transform, I have set a 120s sync delay time to avoid missing the latest data. However, in the aggre…

---

## [Elasticsearch function\_score not working inside nested aggregations](https://discuss.elastic.co/t/elasticsearch-function-score-not-working-inside-nested-aggregations/327479)

<div class="topic-metadata">

**Author:** [@frarafra](https://discuss.elastic.co/u/frarafra)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 11:28pm UTC](https://discuss.elastic.co/t/elasticsearch-function-score-not-working-inside-nested-aggregations/327479 "2023-03-10T23:28:36Z")

</div>

I have an Elasticsearch query with nested aggregations. It was working as expected but when I added a function\_score query it seems to not take it into account. This is my query: GET reviews/\_search { "size": 0, "a…

---

## [Globalsearch: Resolving Logic From Person Type to Country Type](https://discuss.elastic.co/t/globalsearch-resolving-logic-from-person-type-to-country-type/327736)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:00pm UTC](https://discuss.elastic.co/t/globalsearch-resolving-logic-from-person-type-to-country-type/327736 "2023-03-19T23:00:46Z")

</div>

We have a "globalsearch" index that stores "person", "address", "country" information in one single index: { "id":"PER\_0001", "type":"person", "addressId":"ADDR\_001" }, { "id":"ADDR\_001", "type":"address", "countryId":"…

---

## [Formatting problems when I import a metricbeat index from one elastic instance to another](https://discuss.elastic.co/t/formatting-problems-when-i-import-a-metricbeat-index-from-one-elastic-instance-to-another/327808)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 10:21pm UTC](https://discuss.elastic.co/t/formatting-problems-when-i-import-a-metricbeat-index-from-one-elastic-instance-to-another/327808 "2023-03-19T22:21:30Z")

</div>

I am exporting a metricbeat index from elastic using logstash. I am using the following pipeline: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearc…

---

## [How do I output metadata when exporting data from elasticsearch with logstash?](https://discuss.elastic.co/t/how-do-i-output-metadata-when-exporting-data-from-elasticsearch-with-logstash/327684)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 3:15pm UTC](https://discuss.elastic.co/t/how-do-i-output-metadata-when-exporting-data-from-elasticsearch-with-logstash/327684 "2023-03-14T15:15:44Z")

</div>

I am using the following pipeline in logstash: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://localhost:9200" …

---

## [How to list CLOSED indices on 6.4.X?](https://discuss.elastic.co/t/how-to-list-closed-indices-on-6-4-x/327861)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 2\
**Last updated:** [March 19, 2023, 10:17pm UTC](https://discuss.elastic.co/t/how-to-list-closed-indices-on-6-4-x/327861 "2023-03-19T22:17:16Z")

</div>

Hi I'm trying to get a list of closed indices on ES 6.4.2.... This /\_cluster/state/blocks?pretty this returns { "cluster\_name" : "XXXXXX", "compressed\_size\_in\_bytes" : 961428, "cluster\_uuid" : "XXXXXX", "blocks"…

---

## [Elastic and Kibana](https://discuss.elastic.co/t/elastic-and-kibana/327548)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 5\
**Last updated:** [March 19, 2023, 8:45pm UTC](https://discuss.elastic.co/t/elastic-and-kibana/327548 "2023-03-19T20:45:59Z")

</div>

Hi Team, I have installed the elasticsearch(8.5.3) and kibana throgh eck , its working I can able to login If we login first time i'm getting issue like \< elastic did not load properly check the server output for infor…

---

## [Error Add New Node Elasticsearch](https://discuss.elastic.co/t/error-add-new-node-elasticsearch/327814)

<div class="topic-metadata">

**Author:** [@ilham\_bahrul](https://discuss.elastic.co/u/ilham_bahrul)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:40pm UTC](https://discuss.elastic.co/t/error-add-new-node-elasticsearch/327814 "2023-03-19T20:40:39Z")

</div>

I want to add new nodes in my cluster from 3 nodes to 4 nodes. The condition of port 9300 and 9200 is already open on each node. However, I encountered a problem when adding a new node. the following is the error that oc…

---

## [How big should the disk of each node usually be configured reasonably?](https://discuss.elastic.co/t/how-big-should-the-disk-of-each-node-usually-be-configured-reasonably/327897)

<div class="topic-metadata">

**Author:** [@jaryzhong](https://discuss.elastic.co/u/jaryzhong)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:40pm UTC](https://discuss.elastic.co/t/how-big-should-the-disk-of-each-node-usually-be-configured-reasonably/327897 "2023-03-19T20:40:06Z")

</div>

We have 10TB of data and this 10TB of data already contains all replicas, we have 5 data nodes, each node will store 2TB of data, how big should the disk of each node usually be configured reasonably?

---

## [Solr to Elasticsearch Migration](https://discuss.elastic.co/t/solr-to-elasticsearch-migration/327981)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 5:51pm UTC](https://discuss.elastic.co/t/solr-to-elasticsearch-migration/327981 "2023-03-19T17:51:49Z")

</div>

Is there any migration guidelines for migration from Apache Solr to Elasticsearch?

---

## [Help in Export Elasticsearch data](https://discuss.elastic.co/t/help-in-export-elasticsearch-data/326823)

<div class="topic-metadata">

**Author:** [@sameer\_khamkar](https://discuss.elastic.co/u/sameer_khamkar)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 1:29pm UTC](https://discuss.elastic.co/t/help-in-export-elasticsearch-data/326823 "2023-03-19T13:29:12Z")

</div>

Hello Team, I am new to Elasticsearch I have an situation where I want to reindex data from elasticsearch to opensearch I dont have any cluster so its a single node I wan some clarity on my below queries How to exp…

---

## [Drop docs that meet certain Grok pattern](https://discuss.elastic.co/t/drop-docs-that-meet-certain-grok-pattern/327889)

<div class="topic-metadata">

**Author:** [@demonsquatch](https://discuss.elastic.co/u/demonsquatch)\
**Replies:** 6\
**Last updated:** [March 18, 2023, 6:41pm UTC](https://discuss.elastic.co/t/drop-docs-that-meet-certain-grok-pattern/327889 "2023-03-18T18:41:25Z")

</div>

Hi all, Currently looking to drop any documents that meet a certain Grok pattern, but am not having much luck on finding anything. In this scenario, I would like do drop anything that matches the pattern of EVENT1 in th…

---

## [Field\_value\_factor use max of score](https://discuss.elastic.co/t/field-value-factor-use-max-of-score/327971)

<div class="topic-metadata">

**Author:** [@Alexander\_Engel](https://discuss.elastic.co/u/Alexander_Engel)\
**Replies:** 3\
**Last updated:** [March 18, 2023, 3:31pm UTC](https://discuss.elastic.co/t/field-value-factor-use-max-of-score/327971 "2023-03-18T15:31:09Z")

</div>

I have the following query: { "query": { "function\_score": { "boost\_mode": "multiply", "functions": \[ { "field\_value\_factor": { "factor": 0.5, "field": "albums…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=284)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=286)
