# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=286

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 287

---

## [Elasticsearch 7.16.2 not getting started after upgrading Log4j to 2.20 version](https://discuss.elastic.co/t/elasticsearch-7-16-2-not-getting-started-after-upgrading-log4j-to-2-20-version/327799)

<div class="topic-metadata">

**Author:** [@kgpbharathi](https://discuss.elastic.co/u/kgpbharathi)\
**Replies:** 5\
**Last updated:** [March 17, 2023, 11:50pm UTC](https://discuss.elastic.co/t/elasticsearch-7-16-2-not-getting-started-after-upgrading-log4j-to-2-20-version/327799 "2023-03-17T23:50:25Z")

</div>

We are using elasticsearch with version": { "number": "7.16.2","build\_type": "rpm","lucene\_version": "8.10.1" } We have upgraded elasticsearch log4j files from 2.17 to 2.20 and elasticsearch is failing to start . Once…

---

## [Provide elastic password on debian installation](https://discuss.elastic.co/t/provide-elastic-password-on-debian-installation/327953)

<div class="topic-metadata">

**Author:** [@divadpoc](https://discuss.elastic.co/u/divadpoc)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 7:30pm UTC](https://discuss.elastic.co/t/provide-elastic-password-on-debian-installation/327953 "2023-03-17T19:30:59Z")

</div>

Hi, is it possible to provide the ELASTIC\_PASSWORD during startup so there's no auto-generated password? I see it's done w/ your provided compose examples, but can't find any information on bare-metal installations. Th…

---

## [What is the difference between xpack.security.http.ssl.verification\_mode and xpack.http.ssl.verification\_mode](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326537)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 11\
**Last updated:** [March 17, 2023, 6:59pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326537 "2023-03-17T18:59:40Z")

</div>

I want to know what is the difference between xpack.security.http.ssl.verification\_mode: certificate and xpack.http.ssl.verification\_mode: certificate Also, can I use both setting at same time...? Thank you..! Hiruni

---

## [Question about Opaque ID in index requests and Opaque ID restrictions/limitations](https://discuss.elastic.co/t/question-about-opaque-id-in-index-requests-and-opaque-id-restrictions-limitations/327963)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 6:22pm UTC](https://discuss.elastic.co/t/question-about-opaque-id-in-index-requests-and-opaque-id-restrictions-limitations/327963 "2023-03-17T18:22:07Z")

</div>

Hello Team, We are currently adding Opaque ID to our Elasticsearch calls to improve traceability in our system. We have also enabled slow logs for both indexing and searching, where Opaque ID is very helpful. So far, I…

---

## [Version\_conflict when trying to delete documents using \_delete\_by\_query API](https://discuss.elastic.co/t/version-conflict-when-trying-to-delete-documents-using-delete-by-query-api/327954)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/version-conflict-when-trying-to-delete-documents-using-delete-by-query-api/327954 "2023-03-17T15:58:41Z")

</div>

Hello, I'm using Elasticsearch 8.6. I loaded many documents to an index day by day. I made a mistake when uploading the data for one day, so I want to delete all data from that specific day and load the correct informat…

---

## [Elasticsearch search response pick(latency) occurs when \_refresh with G1GC](https://discuss.elastic.co/t/elasticsearch-search-response-pick-latency-occurs-when-refresh-with-g1gc/327612)

<div class="topic-metadata">

**Author:** [@doyle.min](https://discuss.elastic.co/u/doyle.min)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 3:18pm UTC](https://discuss.elastic.co/t/elasticsearch-search-response-pick-latency-occurs-when-refresh-with-g1gc/327612 "2023-03-17T15:18:03Z")

</div>

hello. Our elasticsearch cluster has 3 master nodes and 12 data nodes installed on 2 IDCs. In front of elasticsearch, there is search api server that multisearches three indexes. It shows an average response time of le…

---

## [Change the cloud provider of deployment in a elasticsearch](https://discuss.elastic.co/t/change-the-cloud-provider-of-deployment-in-a-elasticsearch/327784)

<div class="topic-metadata">

**Author:** [@Eduardo\_Maia](https://discuss.elastic.co/u/Eduardo_Maia)\
**Replies:** 2\
**Last updated:** [March 17, 2023, 3:25pm UTC](https://discuss.elastic.co/t/change-the-cloud-provider-of-deployment-in-a-elasticsearch/327784 "2023-03-17T15:25:07Z")

</div>

Hi, my deployment have only one provider cloud, this provider cloud is Azure, but i need to change this for Google. how can i do it?

---

## [Rebalancing data between disks](https://discuss.elastic.co/t/rebalancing-data-between-disks/327927)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 12:13pm UTC](https://discuss.elastic.co/t/rebalancing-data-between-disks/327927 "2023-03-17T12:13:49Z")

</div>

Hi Can You give some tips how I can trigger rebalance for equal distribution of data depending on the size of the disk node shards disk.indices disk.used disk.avail disk.total disk.percent es\_data\_hdd\_1\_2 …

---

## [Unable to index into elasticsearch due to Byte range being out of range](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 9:44am UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857 "2023-03-17T09:44:05Z")

</div>

Hi, I have a log that shows the interface usage (eth0/eth1) at a particular time , it logs in bytes and while logstash is able to parse it , elasticsearch seems to be rejecting it . Any workaround for this ? , in the co…

---

## [Best Practices for Efficient and Effective Log Storage and Retrieval with Elasticsearch and Logstash?](https://discuss.elastic.co/t/best-practices-for-efficient-and-effective-log-storage-and-retrieval-with-elasticsearch-and-logstash/327904)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 6\
**Last updated:** [March 17, 2023, 9:28am UTC](https://discuss.elastic.co/t/best-practices-for-efficient-and-effective-log-storage-and-retrieval-with-elasticsearch-and-logstash/327904 "2023-03-17T09:28:48Z")

</div>

Hello, I am currently working with Elasticsearch to store our log files. I have followed all the necessary steps (Filebeat -\> Logstash -\> Elasticsearch) and I am ready to deploy the system for testing before deploying i…

---

## [Elastic SQL](https://discuss.elastic.co/t/elastic-sql/327525)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 6\
**Last updated:** [March 17, 2023, 8:41am UTC](https://discuss.elastic.co/t/elastic-sql/327525 "2023-03-17T08:41:00Z")

</div>

Hi, I'm not able to execute sql queries from kibana on AWS managed Elasticsearch, however I can execute it via REST call. Can someone help me identify what's the root cause of this? Query: POST /\_sql { "query": "SELE…

---

## [Allocation temporarily throttled issue](https://discuss.elastic.co/t/allocation-temporarily-throttled-issue/327629)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 1\
**Last updated:** [March 14, 2023, 6:52am UTC](https://discuss.elastic.co/t/allocation-temporarily-throttled-issue/327629 "2023-03-14T06:52:59Z")

</div>

One of my node down accidently, and it joined cluster few minutes later. After that To allocate shard faster, I changed 'cluster.routing.allocation.node\_concurrent\_incoming\_recoveries' 10 to 50 And below issue happene…

---

## [How to return more than 10k hits in spring boot without changing the index.max\_result\_window from elasticsearch 8.6](https://discuss.elastic.co/t/how-to-return-more-than-10k-hits-in-spring-boot-without-changing-the-index-max-result-window-from-elasticsearch-8-6/327888)

<div class="topic-metadata">

**Author:** [@BEY\_MEHREZ](https://discuss.elastic.co/u/BEY_MEHREZ)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 10:00pm UTC](https://discuss.elastic.co/t/how-to-return-more-than-10k-hits-in-spring-boot-without-changing-the-index-max-result-window-from-elasticsearch-8-6/327888 "2023-03-16T22:00:33Z")

</div>

Hello ! I want to return all the documents matching my query but the limit is set to 10k ? What can I do to return all the documents ( they are so much higher than 10k documents) without changing the index.max\_result\_wi…

---

## [Add field with same value for all docs in the index](https://discuss.elastic.co/t/add-field-with-same-value-for-all-docs-in-the-index/327880)

<div class="topic-metadata">

**Author:** [@fzar](https://discuss.elastic.co/u/fzar)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 8:25pm UTC](https://discuss.elastic.co/t/add-field-with-same-value-for-all-docs-in-the-index/327880 "2023-03-16T20:25:01Z")

</div>

Hello, I am writing to ask you about a question regarding the correct approach to take in these cases. We have reports that have a country by default (it is defined when the report is defined) and we have an index that …

---

## [Reindex API not distributing load when using slicing](https://discuss.elastic.co/t/reindex-api-not-distributing-load-when-using-slicing/325770)

<div class="topic-metadata">

**Author:** [@jmench](https://discuss.elastic.co/u/jmench)\
**Replies:** 3\
**Last updated:** [March 16, 2023, 5:25pm UTC](https://discuss.elastic.co/t/reindex-api-not-distributing-load-when-using-slicing/325770 "2023-03-16T17:25:29Z")

</div>

I have an index with 3 nodes running, each node having 1 primary and 1 replica shard: index shard prirep state node source-index 0 p STARTED eck-elasticsearch-es-default-2 source-index 0 r STA…

---

## [Elasticsearch getting failed to start the service](https://discuss.elastic.co/t/elasticsearch-getting-failed-to-start-the-service/327646)

<div class="topic-metadata">

**Author:** [@Sarathsoundar](https://discuss.elastic.co/u/Sarathsoundar)\
**Replies:** 6\
**Last updated:** [March 16, 2023, 4:19pm UTC](https://discuss.elastic.co/t/elasticsearch-getting-failed-to-start-the-service/327646 "2023-03-16T16:19:31Z")

</div>

Below i mentioned error log for elasticsearch. I don't know how to resolve this, Please anybody help me to resolve this ASAP. Because i want to start this in development server. \<The job identifier is 14563 and the …

---

## [How to map C# DateTime property to @timestamp field](https://discuss.elastic.co/t/how-to-map-c-datetime-property-to-timestamp-field/327866)

<div class="topic-metadata">

**Author:** [@shelby](https://discuss.elastic.co/u/shelby)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 3:14pm UTC](https://discuss.elastic.co/t/how-to-map-c-datetime-property-to-timestamp-field/327866 "2023-03-16T15:14:25Z")

</div>

I am trying unsuccessfully to se the c# client to bluk insert data into elasticsearch. the client connects successfully, however I now have an issue with the following code: var settings = client.ElasticsearchClientSe…

---

## [Analyze API in NodeJS](https://discuss.elastic.co/t/analyze-api-in-nodejs/327666)

<div class="topic-metadata">

**Author:** [@tirth\_pipalia](https://discuss.elastic.co/u/tirth_pipalia)\
**Replies:** 4\
**Last updated:** [March 16, 2023, 3:07pm UTC](https://discuss.elastic.co/t/analyze-api-in-nodejs/327666 "2023-03-16T15:07:17Z")

</div>

I added html\_strip ad analyzer in the settings of an index. const esObject = { analyzer: 'html\_analyzer', text: ' This is Bold , }; So as per documentation this work in my Kibana Console but I want to use GET \_index…

---

## [Snakeyaml vulnerability (CVE-2022-1471) on latest ES version](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854)

<div class="topic-metadata">

**Author:** [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 3:02pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854 "2023-03-16T15:02:50Z")

</div>

Hi Need help regarding CVE-2022-1471 (snakeyaml): Is there any fix for that in any ES version? AFAIK, in the latest version, this package hasn't been updated. Is there any plan to update the damaged package of snakey…

---

## [Fixing snakeyaml vulnerability (CVE-2022-1471) on older ES versions](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571)

<div class="topic-metadata">

**Author:** [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Replies:** 5\
**Last updated:** [March 16, 2023, 3:02pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571 "2023-03-16T15:02:45Z")

</div>

I'm using ES version 5.6.X, and I would like to change snakeyaml package version to the one with the fix to CVE-2022-1471 - Meaning, I need to change the package version from 1.33 (I guess..) to 2.0 . How can I do that? …

---

## [Using rank\_feature to achieve lower boosting the higher the value is](https://discuss.elastic.co/t/using-rank-feature-to-achieve-lower-boosting-the-higher-the-value-is/327860)

<div class="topic-metadata">

**Author:** [@Mustachipleb](https://discuss.elastic.co/u/Mustachipleb)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 2:16pm UTC](https://discuss.elastic.co/t/using-rank-feature-to-achieve-lower-boosting-the-higher-the-value-is/327860 "2023-03-16T14:16:44Z")

</div>

I have an index with a rank\_feature field that's either empty, or a positive integer. In my case, 1 represents the most relevant document within the rank's context, while higher numbers represent lower relevance. I'd lik…

---

## [Difference between HTTP and Transport certificates](https://discuss.elastic.co/t/difference-between-http-and-transport-certificates/327839)

<div class="topic-metadata">

**Author:** [@divadpoc](https://discuss.elastic.co/u/divadpoc)\
**Replies:** 2\
**Last updated:** [March 16, 2023, 1:53pm UTC](https://discuss.elastic.co/t/difference-between-http-and-transport-certificates/327839 "2023-03-16T13:53:25Z")

</div>

I've found this topic regarding automation of http certificate creation: generate http certificate non interactive, as I was wondering the same thing: why can't I use the same advanced feature of using a yaml file contai…

---

## [Adding a low configuration server as an additional node to elasticsearch cluster?](https://discuss.elastic.co/t/adding-a-low-configuration-server-as-an-additional-node-to-elasticsearch-cluster/327794)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 6\
**Last updated:** [March 16, 2023, 1:16pm UTC](https://discuss.elastic.co/t/adding-a-low-configuration-server-as-an-additional-node-to-elasticsearch-cluster/327794 "2023-03-16T13:16:14Z")

</div>

Hi , I have a single node elasticsearch cluster that may be having slow indexing performance (we have logstash's batch size about 2000 and workers at 40 pushing data to elasticsearch single node), so we were thinking to…

---

## [Error in running Detection Rules Indicator Match](https://discuss.elastic.co/t/error-in-running-detection-rules-indicator-match/327853)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 12:47pm UTC](https://discuss.elastic.co/t/error-in-running-detection-rules-indicator-match/327853 "2023-03-16T12:47:59Z")

</div>

We are running Detection Rules to search for IOCs in firewall logs (using Indicator Matching). The firewall logs have a field named service. Every time there is a match the following error is seen: Bulk Indexing of sign…

---

## [Vectorizing documents - very slow](https://discuss.elastic.co/t/vectorizing-documents-very-slow/327710)

<div class="topic-metadata">

**Author:** [@Cole\_Crawford](https://discuss.elastic.co/u/Cole_Crawford)\
**Replies:** 4\
**Last updated:** [March 16, 2023, 12:07pm UTC](https://discuss.elastic.co/t/vectorizing-documents-very-slow/327710 "2023-03-16T12:07:36Z")

</div>

I am trying to create an NLP pipeline using Charangan/MedBERT · Hugging Face. Ingesting documents with this model and an ES ML pipeline is running very slowly: With a dockerized setup on my local machine with 10GB of RAM…

---

## [New build docker-compose multi-node cluster fails to retrieve password hash for reserved user \[elastic\] / at least one primary shard for the index \[.security-7\] is unavailable](https://discuss.elastic.co/t/new-build-docker-compose-multi-node-cluster-fails-to-retrieve-password-hash-for-reserved-user-elastic-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/326389)

<div class="topic-metadata">

**Author:** [@cookersjs](https://discuss.elastic.co/u/cookersjs)\
**Replies:** 3\
**Last updated:** [March 16, 2023, 11:07am UTC](https://discuss.elastic.co/t/new-build-docker-compose-multi-node-cluster-fails-to-retrieve-password-hash-for-reserved-user-elastic-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/326389 "2023-03-16T11:07:35Z")

</div>

Hi there, I've been following the instructions from Install Elasticsearch with Docker | Elasticsearch Guide \[8.6\] | Elastic (#docker-compose-file for multi-node cluster) and I keep running into an error that seems commo…

---

## [Upgrade to Java API Client](https://discuss.elastic.co/t/upgrade-to-java-api-client/327787)

<div class="topic-metadata">

**Author:** [@Michal\_Stefaniuk](https://discuss.elastic.co/u/Michal_Stefaniuk)\
**Replies:** 1\
**Last updated:** [March 16, 2023, 10:11am UTC](https://discuss.elastic.co/t/upgrade-to-java-api-client/327787 "2023-03-16T10:11:52Z")

</div>

Hey guys. We are currently upgrading our ES in production from 7.16.1 to 7.17.7. This is a must for us, client's requirement leaves us no option but to upgrade to this version. Now having moved to 7.17.7 we were wonderi…

---

## [How to create mass amounts of test data in elasticsearch / Kibana](https://discuss.elastic.co/t/how-to-create-mass-amounts-of-test-data-in-elasticsearch-kibana/327637)

<div class="topic-metadata">

**Author:** [@shelby](https://discuss.elastic.co/u/shelby)\
**Replies:** 5\
**Last updated:** [March 16, 2023, 8:35am UTC](https://discuss.elastic.co/t/how-to-create-mass-amounts-of-test-data-in-elasticsearch-kibana/327637 "2023-03-16T08:35:49Z")

</div>

0 I need to test some logic I have written in Kibana (Vega scripts). For this I require quite a bit of data to generate the graphs. I am currently doing this manually with statements such as: post /metrics-hardware-xx…

---

## [401 after updating API Key role descriptors](https://discuss.elastic.co/t/401-after-updating-api-key-role-descriptors/327756)

<div class="topic-metadata">

**Author:** [@Mateusz\_Migala](https://discuss.elastic.co/u/Mateusz_Migala)\
**Replies:** 8\
**Last updated:** [March 16, 2023, 8:16am UTC](https://discuss.elastic.co/t/401-after-updating-api-key-role-descriptors/327756 "2023-03-16T08:16:40Z")

</div>

Hello, I'm trying to limit default privileges of the API key when it's being created. By default it's created by terraform with superuser account which I feel has too much access. We want to use the API\_Key to connect …

---

## [我想在聚合汇总后，对聚合的bucket数据进行不响应，只是在响应时丢弃它](https://discuss.elastic.co/t/bucket/327818)

<div class="topic-metadata">

**Author:** [@lujiamingzZ](https://discuss.elastic.co/u/lujiamingzZ)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 7:37am UTC](https://discuss.elastic.co/t/bucket/327818 "2023-03-16T07:37:58Z")

</div>

只想要 sumtotal 结果，不想要bookingIdGroup.buckets结果，但是它对我汇总sumtotal有作用。 GET /booking\_order\_list\_v1/\_search { "from": 0, "size": 1, "aggs": { "bookingIdGroup": { "terms": { "field": "bookingId", …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=285)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=287)
