# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=289

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 290

---

## [Cannot add new CA to keystore](https://discuss.elastic.co/t/cannot-add-new-ca-to-keystore/326767)

<div class="topic-metadata">

**Author:** [@alrubaa](https://discuss.elastic.co/u/alrubaa)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 12:37am UTC](https://discuss.elastic.co/t/cannot-add-new-ca-to-keystore/326767 "2023-03-10T00:37:10Z")

</div>

Hi All, I have an ELasticsearch cluster of 12 nodes running 8.2 and the certificates have expired, just crossed 3 years which I did not realise. I have been trying to follow the instructions on Update security certifica…

---

## [Unassigned.reason CLUSTER\_RECOVERED](https://discuss.elastic.co/t/unassigned-reason-cluster-recovered/327370)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 8:05pm UTC](https://discuss.elastic.co/t/unassigned-reason-cluster-recovered/327370 "2023-03-09T20:05:34Z")

</div>

My health status is only yellow instead of green. { "cluster\_name" : "elasticsearch", "status" : "yellow", "timed\_out" : false, "number\_of\_nodes" : 1, "number\_of\_data\_nodes" : 1, "active\_primary\_shards" : 22…

---

## [Does this mean my "\_id" field is taking up GB of RAM?](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 6:39pm UTC](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128 "2023-03-09T18:39:27Z")

</div>

\[fielddata\] New used memory 13315258923 \[12.4gb\] for data of \[\_id\] would be larger than configured breaker: 13314398617 \[12.3gb\], breaking I'm getting the above warning and wondering why. Does it mean my "\_id" field (t…

---

## [\[HELP! ! \] About ILM (IndexLifecycleManagement) of ElasticSearch](https://discuss.elastic.co/t/help-about-ilm-indexlifecyclemanagement-of-elasticsearch/326813)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 10\
**Last updated:** [March 9, 2023, 4:38pm UTC](https://discuss.elastic.co/t/help-about-ilm-indexlifecyclemanagement-of-elasticsearch/326813 "2023-03-09T16:38:56Z")

</div>

Hello from Japan I have a question for you dear engineers I'm using Elasticsearch 7.6.2 and want to remove the accumulated indexes The created ILM policy rolls over at 50GB/30 days, and I created an ILM policy that de…

---

## [Disappearing Documents on Batch Upload with Enrich Policy](https://discuss.elastic.co/t/disappearing-documents-on-batch-upload-with-enrich-policy/327377)

<div class="topic-metadata">

**Author:** [@cj\_hillbrand](https://discuss.elastic.co/u/cj_hillbrand)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 4:12pm UTC](https://discuss.elastic.co/t/disappearing-documents-on-batch-upload-with-enrich-policy/327377 "2023-03-09T16:12:39Z")

</div>

Hey folks, My team and I are evaluating some interesting behavior when our system attempts to batch upload documents to our Elasticsearch store. We are noticing that occasionally a collection of documents that we expect…

---

## [Index sorting with two order values in the same field](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333)

<div class="topic-metadata">

**Author:** [@joaoantao](https://discuss.elastic.co/u/joaoantao)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:33am UTC](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333 "2023-03-09T08:33:53Z")

</div>

I am trying to improve queries in one index with ~ 125 million documents and 3 shards. Most of the queries hitting this index have a sort order for a given field with values ascending and descending. Currently the index…

---

## [Adding watcher condition](https://discuss.elastic.co/t/adding-watcher-condition/326763)

<div class="topic-metadata">

**Author:** [@alextg](https://discuss.elastic.co/u/alextg)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 2:23pm UTC](https://discuss.elastic.co/t/adding-watcher-condition/326763 "2023-03-09T14:23:10Z")

</div>

Hello, I'm looking to add a new condition to my working watcher. Currently, it alerts when the index doesn't received logs in the last 10 minutes (see below). The functionality I'm trying to add is to alert when the ind…

---

## [Meta data not written to logstash output file](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 2:02pm UTC](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366 "2023-03-09T14:02:14Z")

</div>

I am using the following logstash pipeline: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://elastic:80/elasticsearch/…

---

## [Get top 10 data for each group](https://discuss.elastic.co/t/get-top-10-data-for-each-group/327349)

<div class="topic-metadata">

**Author:** [@Shishir\_Kumar2](https://discuss.elastic.co/u/Shishir_Kumar2)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 11:25am UTC](https://discuss.elastic.co/t/get-top-10-data-for-each-group/327349 "2023-03-09T11:25:39Z")

</div>

Requirement is to get top 10 data for each group. I created below index and tried using few combination of aggregation query but it does not get desired result. Index Definition PUT /poc\_agg { "settings": { "numb…

---

## [Request body is required Error encountered while performing reindexing task](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327)

<div class="topic-metadata">

**Author:** [@Chandan1](https://discuss.elastic.co/u/Chandan1)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 7:58am UTC](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327 "2023-03-09T07:58:37Z")

</div>

Hello, I am trying to reindex the index with reindex api by providing a proper request body with the Source and Destination Index details and still iam receiving Request body is required Error. Please find below Reques…

---

## [\[plugin-development\] java.security.AccessControlException](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 7:10am UTC](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326 "2023-03-09T07:10:37Z")

</div>

Vesion: Elasticsearch 8.6.2 (My plugin is working on Elasticsearch7.6.0 ) I am developing a plugin to let ES filter through Redis data. So I import Jedis package in my code. But when ES starts, I get this error. Her…

---

## [Cannot use https on elasticsearch server](https://discuss.elastic.co/t/cannot-use-https-on-elasticsearch-server/327148)

<div class="topic-metadata">

**Author:** [@dityudha](https://discuss.elastic.co/u/dityudha)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 6:53am UTC](https://discuss.elastic.co/t/cannot-use-https-on-elasticsearch-server/327148 "2023-03-09T06:53:53Z")

</div>

Hello there, Right now i'm configuring elastic security with https based on article: I'm getting trouble after generate http.p12 certificate. Error like this: elastic server already up, but still not secured el…

---

## [\[esrally\] what cause difference of latency and service time?, what is proper way of custom parameter](https://discuss.elastic.co/t/esrally-what-cause-difference-of-latency-and-service-time-what-is-proper-way-of-custom-parameter/327317)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 6:15am UTC](https://discuss.elastic.co/t/esrally-what-cause-difference-of-latency-and-service-time-what-is-proper-way-of-custom-parameter/327317 "2023-03-09T06:15:47Z")

</div>

Hello. i just saw strange stuff when im trying to do single shard test. here is my metric it's error rate is 0.01% and its service time looks reasonable to service, but latency is really bad. the question is what ca…

---

## [Shards Rebalancing Issue Version 7](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 10:57pm UTC](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107 "2023-03-08T22:57:05Z")

</div>

ES version 7, Shards are not equally distributing, one data node has more shards, rest of the two data nodes are less number of shards and low disk used. Replication set to "1" on all indices Please let me know if any …

---

## [Is it possible to sort in a custom grouping manner with unicode collation algorithm in elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 5:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294 "2023-03-08T17:11:35Z")

</div>

I am working on a phonebook, where if the user does not provide Name but fills only email, I will show the email value in phonebook (as in mac contacts). And the priority is as follows Name (if not present) -\> Email (if…

---

## [Null\_pointer\_exception: Cannot invoke "String.equals(Object)" because the return value of "org.apache.lucene.search.SortField.getField()" is null](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 4:35pm UTC](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235 "2023-03-08T16:35:29Z")

</div>

This is on Elasticsearch 8.6.2. I have a pretty mundane query that I want to paginate via search\_after. The initial query looks like this: { "\_source": true, "collapse": { "field": "collapse\_col" }, "query…

---

## [Data nodes separation (via attributes) vs. clusters separation](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:33pm UTC](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216 "2023-03-08T16:33:45Z")

</div>

Hi, We are B2B that maintain one index per each one of our customers. Every index is being indexed every day from scratch and once it is ready, it replace the previous day index. Once the index is ready, it's in read-…

---

## [Unable to connect to Elasticsearch client running locally: receiving 'connection refused' on KOTLIN](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-client-running-locally-receiving-connection-refused-on-kotlin/327215)

<div class="topic-metadata">

**Author:** [@GAETANO\_SIMONELLI](https://discuss.elastic.co/u/GAETANO_SIMONELLI)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 4:05pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-client-running-locally-receiving-connection-refused-on-kotlin/327215 "2023-03-08T16:05:49Z")

</div>

I am experiencing connection issues with my Elasticsearch client running locally. Specifically, when I try to connect using localhost in the RestClient.builder, I receive a java.net.connectException: connection refused e…

---

## [Is there a quicker way to import data to Elastic?](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 5\
**Last updated:** [March 8, 2023, 3:49pm UTC](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275 "2023-03-08T15:49:54Z")

</div>

I have exported elastic indices using logstash with the following logstash configuration: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { …

---

## [Elastic Search Heap size](https://discuss.elastic.co/t/elastic-search-heap-size/327266)

<div class="topic-metadata">

**Author:** [@Jozelle\_Cinco](https://discuss.elastic.co/u/Jozelle_Cinco)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:38pm UTC](https://discuss.elastic.co/t/elastic-search-heap-size/327266 "2023-03-08T14:38:51Z")

</div>

Hi! We have a Headless Drupal 9 site (FE: Gatsby) with Elasticsearch that's currently encountering \[circuit\_breaking\_exception\] when doing a search. As per some discussions it is suggested we adjust the Heap size on Pro…

---

## [Shard allocation - strange behaviour of index tier preference](https://discuss.elastic.co/t/shard-allocation-strange-behaviour-of-index-tier-preference/326746)

<div class="topic-metadata">

**Author:** [@Michael\_Hyatt](https://discuss.elastic.co/u/Michael_Hyatt)\
**Replies:** 11\
**Last updated:** [March 8, 2023, 1:56pm UTC](https://discuss.elastic.co/t/shard-allocation-strange-behaviour-of-index-tier-preference/326746 "2023-03-08T13:56:43Z")

</div>

Hi there, I have a hot-warm cluster with 2 hot and 2 warm nodes (Elastic cloud v8.6.1). I also have an index that I want to distribute to both, hot and warm-tier nodes. To do that, I want to set up the number of replica…

---

## [Query index from within an AnalysisProvider?](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 12:38pm UTC](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191 "2023-03-08T12:38:38Z")

</div>

Hi, Here is the context of my question: Synonym graph token filter backed by Elastic index I am writing a custom AnalysisPlugin to generate a list of synonyms from an Elastic index instead of using a static file. A na…

---

## [Performance implications of \`index.max\_result\_window\` vs \`track\_total\_hits\`](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270)

<div class="topic-metadata">

**Author:** [@Cristian\_Calara](https://discuss.elastic.co/u/Cristian_Calara)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:21pm UTC](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270 "2023-03-08T12:21:15Z")

</div>

Hello, For example, if we would have 50.000 results for a search query. If we really need to return an exact total number of matches and we enabled track\_total\_hits to get it. Should we just as well increase the max\_res…

---

## [Elastic search container upgrade from 7.10.2 to 7.17.9](https://discuss.elastic.co/t/elastic-search-container-upgrade-from-7-10-2-to-7-17-9/327061)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 12:03pm UTC](https://discuss.elastic.co/t/elastic-search-container-upgrade-from-7-10-2-to-7-17-9/327061 "2023-03-08T12:03:11Z")

</div>

Hi, We are trying to upgrade from 7.10.2 Elasticsearch containers to 7.17.9. Can I ran my Elasticsearch container directly on the data node created/used by 7.10.2 containers ? Do I need to do additional steps to make s…

---

## [Elastic.Clients.Elasticsearch 8.x (custom) serialization](https://discuss.elastic.co/t/elastic-clients-elasticsearch-8-x-custom-serialization/324435)

<div class="topic-metadata">

**Author:** [@KoalaBear](https://discuss.elastic.co/u/KoalaBear)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 10:11am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-8-x-custom-serialization/324435 "2023-03-08T10:11:32Z")

</div>

I would like to do something like we have in Netwonsoft Json: options.SerializerSettings.ReferenceLoopHandling = Newtonsoft.Json.ReferenceLoopHandling.Ignore And also have in System.Text.Json: JsonSerializerOptions op…

---

## [How to filter date with optional keyword search](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260)

<div class="topic-metadata">

**Author:** [@gopikrish](https://discuss.elastic.co/u/gopikrish)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 10:08am UTC](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260 "2023-03-08T10:08:48Z")

</div>

Hi All , while retrieving data from ELK, I need to filter records between two date(mandatory) with keyword (optional) parameter. The searching keyword is only present in value format not in key value pair. For eg ; { …

---

## [Index.mapping.depth.limit not persistent after an index rollover](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 8:58am UTC](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182 "2023-03-08T08:58:52Z")

</div>

Hi everyone, I notice that when the current index is rollovered, the index.mapping.depth.limit is not take into account for the new created index. We are running an elasticsearch cluster and after we have created the f…

---

## [About elasticsearch and kibana snapshot and backup feature](https://discuss.elastic.co/t/about-elasticsearch-and-kibana-snapshot-and-backup-feature/327198)

<div class="topic-metadata">

**Author:** [@Rakesh\_Bare1](https://discuss.elastic.co/u/Rakesh_Bare1)\
**Replies:** 6\
**Last updated:** [March 8, 2023, 7:41am UTC](https://discuss.elastic.co/t/about-elasticsearch-and-kibana-snapshot-and-backup-feature/327198 "2023-03-08T07:41:10Z")

</div>

hey, i am used elasticsearch is cluster. i want to take snapshot of my es. i have create snapshot directory and mention in elasticsearch.yml in path.repo. after that elasticsearch docker not running. i have check logs …

---

## [What is the deciding factor for the number of coordinating only node in a cluster and how to route the requests?](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842)

<div class="topic-metadata">

**Author:** [@pruthvi](https://discuss.elastic.co/u/pruthvi)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:54am UTC](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842 "2023-03-08T00:54:28Z")

</div>

Hi, I have a requirement to index 100TB of data per month in ES with ILM. No. dedicated master nodes – 3 nodes. Total no. of hot nodes - 66 nodes. Total no. of warm nodes - 216 nodes. Above calculations are based on…

---

## [Create new field value is incorrect](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912)

<div class="topic-metadata">

**Author:** [@ikonrao](https://discuss.elastic.co/u/ikonrao)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:54pm UTC](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912 "2023-03-07T22:54:34Z")

</div>

Hi, I have a field which has value in seconds. I need to view it in hours. I used create new field and used script to convert it into hours. What i have observed is it is not able to take decimal values. For example, …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=288)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=290)
