# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=29

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 30

---

## [Elasticsearch died while starting up](https://discuss.elastic.co/t/elasticsearch-died-while-starting-up/378287)

<div class="topic-metadata">

**Author:** [@shubhi-gupta5](https://discuss.elastic.co/u/shubhi-gupta5)\
**Replies:** 17\
**Last updated:** [June 12, 2025, 8:41am UTC](https://discuss.elastic.co/t/elasticsearch-died-while-starting-up/378287 "2025-06-12T08:41:22Z")

</div>

Hi All, Running into this error while I am trying to deploy Elasticsearch v8.17.1 on ppc64le machine Gradle Version : 8.13 OS Info : Linux 5.14.0-503.38.1.el9\_5.ppc64le (ppc64le) JD…

---

## [Field Exists like capability in ES|QL](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089)

<div class="topic-metadata">

**Author:** [@ashit\_pupu](https://discuss.elastic.co/u/ashit_pupu)\
**Replies:** 2\
**Last updated:** [June 12, 2025, 5:32am UTC](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089 "2025-06-12T05:32:27Z")

</div>

Hi Team Reaching out to understand if there is any functionality available in ES|QL which could handle if a field doesn't exist. Currently if a field has never been indexed we don't have the field name in index mapping …

---

## [Monitor rule to detect failed pods](https://discuss.elastic.co/t/monitor-rule-to-detect-failed-pods/379106)

<div class="topic-metadata">

**Author:** [@marcelpineda](https://discuss.elastic.co/u/marcelpineda)\
**Replies:** 1\
**Last updated:** [June 11, 2025, 8:14pm UTC](https://discuss.elastic.co/t/monitor-rule-to-detect-failed-pods/379106 "2025-06-11T20:14:32Z")

</div>

I am trying to define Monitoring rule to detect pod status=failed. I've used Discover and the parameters below: Data view: pod-status-ad-hoc Filter: metrics.k8s.pod.phase: exists Query: ( ( "failed": \* ) AND ( "resou…

---

## [How to search for job title synonyms like "Product Manager", "PM", "Product Lead", etc.?](https://discuss.elastic.co/t/how-to-search-for-job-title-synonyms-like-product-manager-pm-product-lead-etc/379072)

<div class="topic-metadata">

**Author:** [@Orel\_Sapir](https://discuss.elastic.co/u/Orel_Sapir)\
**Replies:** 2\
**Last updated:** [June 11, 2025, 6:37pm UTC](https://discuss.elastic.co/t/how-to-search-for-job-title-synonyms-like-product-manager-pm-product-lead-etc/379072 "2025-06-11T18:37:36Z")

</div>

Hi everyone, I'm working on querying a collection of CVs using Elasticsearch. I want to search for the job title "Product Manager", but also retrieve results that include synonyms such as "PM", "Product Lead", "Product …

---

## [Is it possible to setup 3 node elastic cluster without ca password](https://discuss.elastic.co/t/is-it-possible-to-setup-3-node-elastic-cluster-without-ca-password/379017)

<div class="topic-metadata">

**Author:** [@IamGuna](https://discuss.elastic.co/u/IamGuna)\
**Replies:** 2\
**Last updated:** [June 11, 2025, 9:20am UTC](https://discuss.elastic.co/t/is-it-possible-to-setup-3-node-elastic-cluster-without-ca-password/379017 "2025-06-11T09:20:58Z")

</div>

I was able to setup 3 node elastic cluster via elastic CA method - based on Setting up 3 node cluster for first time and getting errors - #2 by leandrojmp Now, the requirement is to use certs provided by org, certified …

---

## [ELK Stack and OS Upgrade Inquiry](https://discuss.elastic.co/t/elk-stack-and-os-upgrade-inquiry/379044)

<div class="topic-metadata">

**Author:** [@Wei\_Li](https://discuss.elastic.co/u/Wei_Li)\
**Replies:** 6\
**Last updated:** [June 10, 2025, 9:59am UTC](https://discuss.elastic.co/t/elk-stack-and-os-upgrade-inquiry/379044 "2025-06-10T09:59:25Z")

</div>

We currently have an Elasticsearch cluster with a valid license, consisting of 7 nodes deployed on VMs. The current version is 7.16.2. We are planning to upgrade both the ELK Stack and the underlying operating system. Ou…

---

## [Fleet indices prevent upgrade to Elasticsearch 9](https://discuss.elastic.co/t/fleet-indices-prevent-upgrade-to-elasticsearch-9/379006)

<div class="topic-metadata">

**Author:** [@sparkblaze](https://discuss.elastic.co/u/sparkblaze)\
**Replies:** 3\
**Last updated:** [June 10, 2025, 8:58am UTC](https://discuss.elastic.co/t/fleet-indices-prevent-upgrade-to-elasticsearch-9/379006 "2025-06-10T08:58:50Z")

</div>

I am trying to upgrade our test ELK stack from 8.x to 9.x. All of the components have been upgraded to 8.18.2 fine and have no issues. The Upgrade Assistant listed no critical issues and a handful of warnings (read-only…

---

## [Index management best practice in ES 8](https://discuss.elastic.co/t/index-management-best-practice-in-es-8/379039)

<div class="topic-metadata">

**Author:** [@Coral\_Hayoun](https://discuss.elastic.co/u/Coral_Hayoun)\
**Replies:** 0\
**Last updated:** [June 10, 2025, 5:14am UTC](https://discuss.elastic.co/t/index-management-best-practice-in-es-8/379039 "2025-06-10T05:14:08Z")

</div>

Hello everyone, I have a pipeline where I store two types of entities in Elasticsearch, providing fast search filters and aggregation searches for my users. Entity Type 1: Needs to be stored indefinitely. Entity Type …

---

## [ELK stack in docker](https://discuss.elastic.co/t/elk-stack-in-docker/378721)

<div class="topic-metadata">

**Author:** [@piyush\_hn](https://discuss.elastic.co/u/piyush_hn)\
**Replies:** 12\
**Last updated:** [June 10, 2025, 6:07am UTC](https://discuss.elastic.co/t/elk-stack-in-docker/378721 "2025-06-10T06:07:18Z")

</div>

Hi All, I am working on a project to spin up ELK stack inside docker container. I have containers for elasticsearch/kibana up and running but whenever I am trying to run logstash it gives me the below error, I replace…

---

## [Elasticsearch Integration for Stack Monitoring fails](https://discuss.elastic.co/t/elasticsearch-integration-for-stack-monitoring-fails/378947)

<div class="topic-metadata">

**Author:** [@g\_ourmet](https://discuss.elastic.co/u/g_ourmet)\
**Replies:** 2\
**Last updated:** [June 9, 2025, 10:02pm UTC](https://discuss.elastic.co/t/elasticsearch-integration-for-stack-monitoring-fails/378947 "2025-06-09T22:02:12Z")

</div>

Good day, im running an ELK Stack version 8.17.7 with several Elastic-Agents. Problem Since the update from 8.17.6 to 8.17.7, self monitoring is no longer functional. Hence the idea to feed the stack monitoring with th…

---

## [Kibana: Trying to create a scripted field, but cannot figure out how retrieve the value of field 'client.domain'](https://discuss.elastic.co/t/kibana-trying-to-create-a-scripted-field-but-cannot-figure-out-how-retrieve-the-value-of-field-client-domain/378909)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 2\
**Last updated:** [June 9, 2025, 8:30pm UTC](https://discuss.elastic.co/t/kibana-trying-to-create-a-scripted-field-but-cannot-figure-out-how-retrieve-the-value-of-field-client-domain/378909 "2025-06-09T20:30:08Z")

</div>

I have an index with data from our Bitbucket servers. The documents contains a lot of fields, but the one that is of interest to me is the keyword field client.domain (the FQDN of Jenkins servers). I want to create a scr…

---

## [How can i calculate cost of query?](https://discuss.elastic.co/t/how-can-i-calculate-cost-of-query/378995)

<div class="topic-metadata">

**Author:** [@Zoree](https://discuss.elastic.co/u/Zoree)\
**Replies:** 1\
**Last updated:** [June 9, 2025, 12:31pm UTC](https://discuss.elastic.co/t/how-can-i-calculate-cost-of-query/378995 "2025-06-09T12:31:06Z")

</div>

I want to create a functionality for calculating the cost of a query before it is launched, but I am interested in how to make very different queries. Suppose you think that 1 word = 1, operator "should" = 1,2, "mus"t = …

---

## [ECK Elasticsearch (9.0.1) Pod Stuck - 'Running' but Never 'Ready' (Local Storage)](https://discuss.elastic.co/t/eck-elasticsearch-9-0-1-pod-stuck-running-but-never-ready-local-storage/378900)

<div class="topic-metadata">

**Author:** [@Dror\_Roditti](https://discuss.elastic.co/u/Dror_Roditti)\
**Replies:** 1\
**Last updated:** [June 8, 2025, 7:01pm UTC](https://discuss.elastic.co/t/eck-elasticsearch-9-0-1-pod-stuck-running-but-never-ready-local-storage/378900 "2025-06-08T19:01:39Z")

</div>

ECK Elasticsearch (9.0.1) Pod Stuck - 'Running' but Never 'Ready' (Local Storage) Hello Elasticsearch Community, I'm facing a strange issue with a simple Elasticsearch deployment using ECK ( on my on-premise Kubernetes…

---

## [Elastic stack 10k EPS](https://discuss.elastic.co/t/elastic-stack-10k-eps/378903)

<div class="topic-metadata">

**Author:** [@adilraad2001](https://discuss.elastic.co/u/adilraad2001)\
**Replies:** 7\
**Last updated:** [June 7, 2025, 11:09pm UTC](https://discuss.elastic.co/t/elastic-stack-10k-eps/378903 "2025-06-07T23:09:49Z")

</div>

Hello guys i want to build my SIEM to handle at least 10000EPS what configuration should i do and what requirement need to use with what number of nodes and info i need

---

## [How to use Source in ElasticSearch Net](https://discuss.elastic.co/t/how-to-use-source-in-elasticsearch-net/366585)

<div class="topic-metadata">

**Author:** [@alikleitcr7](https://discuss.elastic.co/u/alikleitcr7)\
**Replies:** 2\
**Last updated:** [June 7, 2025, 5:05pm UTC](https://discuss.elastic.co/t/how-to-use-source-in-elasticsearch-net/366585 "2025-06-07T17:05:44Z")

</div>

How can I project fields in the Elasticsearch Net 8? I tried: SourceFilter filter = new SourceFilter(); filter.Includes = new List\<Field\>() .. hm not the way SourceConfig sourceConfig = new SourceConfig(filter); Se…

---

## [Recovered node’s translog usage after replica is promoted to primary due to node loss](https://discuss.elastic.co/t/recovered-node-s-translog-usage-after-replica-is-promoted-to-primary-due-to-node-loss/378941)

<div class="topic-metadata">

**Author:** [@hamakim](https://discuss.elastic.co/u/hamakim)\
**Replies:** 3\
**Last updated:** [June 7, 2025, 8:42am UTC](https://discuss.elastic.co/t/recovered-node-s-translog-usage-after-replica-is-promoted-to-primary-due-to-node-loss/378941 "2025-06-07T08:42:36Z")

</div>

Hi, I have a question regarding shard recovery and translog handling in Elasticsearch. Let’s say a primary shard goes offline due to a sudden node failure. One of the replica shards is promoted to be the new primary. La…

---

## [Unexpected High Disk Utilization on All Frozen Nodes After Adding New Node in Elastic Cloud](https://discuss.elastic.co/t/unexpected-high-disk-utilization-on-all-frozen-nodes-after-adding-new-node-in-elastic-cloud/378910)

<div class="topic-metadata">

**Author:** [@SourabhK1](https://discuss.elastic.co/u/SourabhK1)\
**Replies:** 2\
**Last updated:** [June 6, 2025, 5:06pm UTC](https://discuss.elastic.co/t/unexpected-high-disk-utilization-on-all-frozen-nodes-after-adding-new-node-in-elastic-cloud/378910 "2025-06-06T17:06:36Z")

</div>

We’re using frozen tier in Elastic Cloud with searchable snapshots (fully mounted). Initially had 3 frozen nodes (~99.4% used disk capacity), and hit the 9000 shard limit. Added a 4th frozen node to increase capacity (…

---

## [Seeking advice for multiple object searches in array](https://discuss.elastic.co/t/seeking-advice-for-multiple-object-searches-in-array/378709)

<div class="topic-metadata">

**Author:** [@Pavel\_Stoyanov](https://discuss.elastic.co/u/Pavel_Stoyanov)\
**Replies:** 1\
**Last updated:** [June 6, 2025, 1:50pm UTC](https://discuss.elastic.co/t/seeking-advice-for-multiple-object-searches-in-array/378709 "2025-06-06T13:50:56Z")

</div>

Hi everyone, Me and my team have similar properties in our documents(of course we have multiple of these array of objects that we would like to query by): { ... "example\_array": \[ { "type": "som…

---

## [Setting up 3 node cluster for first time and getting errors](https://discuss.elastic.co/t/setting-up-3-node-cluster-for-first-time-and-getting-errors/378775)

<div class="topic-metadata">

**Author:** [@IamGuna](https://discuss.elastic.co/u/IamGuna)\
**Replies:** 12\
**Last updated:** [June 6, 2025, 1:24pm UTC](https://discuss.elastic.co/t/setting-up-3-node-cluster-for-first-time-and-getting-errors/378775 "2025-06-06T13:24:22Z")

</div>

I am trying to setup a 3 node cluster on RHEL 8.10 VMs with elasticsearch-8.18.1-linux-x86\_64.tar.gz. The ES\_JAVA\_HOME is configured with jdk-21.0.5 I have followed the steps from Set up HTTPS | Elastic Docs and generat…

---

## [Fetch top k frequent fields](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928)

<div class="topic-metadata">

**Author:** [@Parthpuri\_Goswami](https://discuss.elastic.co/u/Parthpuri_Goswami)\
**Replies:** 3\
**Last updated:** [June 6, 2025, 7:53am UTC](https://discuss.elastic.co/t/fetch-top-k-frequent-fields/378928 "2025-06-06T07:53:57Z")

</div>

Hi all, I want to fetch the top k fields that are most frequent in the last 5 minutes of documents or in whole index. I have tried some queries, as shown below, to get the desired output, but it's taking a long time. I …

---

## [Cannot run es with ERROR: Missing logging config file at xxx/log4j2.properties](https://discuss.elastic.co/t/cannot-run-es-with-error-missing-logging-config-file-at-xxx-log4j2-properties/378836)

<div class="topic-metadata">

**Author:** [@KevinFreeman](https://discuss.elastic.co/u/KevinFreeman)\
**Replies:** 3\
**Last updated:** [June 6, 2025, 6:09am UTC](https://discuss.elastic.co/t/cannot-run-es-with-error-missing-logging-config-file-at-xxx-log4j2-properties/378836 "2025-06-06T06:09:11Z")

</div>

es version: elasticsearch:8.18.0 yaml file. elastic: image: "${ELASTIC\_IMAGE}" container\_name: elastic read\_only: true user: "${UID:-1000}:${GID:-1000}" # Run as non-root user deploy: resou…

---

## [Sample notebook for merging hnsw graphs](https://discuss.elastic.co/t/sample-notebook-for-merging-hnsw-graphs/378834)

<div class="topic-metadata">

**Author:** [@Chenzhe\_Jin](https://discuss.elastic.co/u/Chenzhe_Jin)\
**Replies:** 5\
**Last updated:** [June 5, 2025, 4:01pm UTC](https://discuss.elastic.co/t/sample-notebook-for-merging-hnsw-graphs/378834 "2025-06-05T16:01:44Z")

</div>

I am wondering whether or where I can find the sample code for this blog Speeding up merging of HNSW graphs - Elasticsearch Labs?

---

## [Sync 2 indices in the same cluster](https://discuss.elastic.co/t/sync-2-indices-in-the-same-cluster/359926)

<div class="topic-metadata">

**Author:** [@DanielR1](https://discuss.elastic.co/u/DanielR1)\
**Replies:** 6\
**Last updated:** [June 5, 2025, 3:35pm UTC](https://discuss.elastic.co/t/sync-2-indices-in-the-same-cluster/359926 "2025-06-05T15:35:03Z")

</div>

Hello! Is there a way to keep in sync two elasticsearch indices? Whatever is written by the app in one index, to be copied in a second index. It is not a viable solution to make the app writing at the same time to bot…

---

## [Error while getting SLM Stats from the Java Client](https://discuss.elastic.co/t/error-while-getting-slm-stats-from-the-java-client/378919)

<div class="topic-metadata">

**Author:** [@BenjaminD](https://discuss.elastic.co/u/BenjaminD)\
**Replies:** 3\
**Last updated:** [June 5, 2025, 3:21pm UTC](https://discuss.elastic.co/t/error-while-getting-slm-stats-from-the-java-client/378919 "2025-06-05T15:21:45Z")

</div>

Hi everyone. I'm using the Java client to handle some functionalities in my cluster. With the ElasticsearchSlmClient, I can create a policy and run it. But when I try to run slmClient.getStats(); I have the followin…

---

## [Why can't we make the leader index as the follower, on the primary cluster in uni-directional CCR?](https://discuss.elastic.co/t/why-cant-we-make-the-leader-index-as-the-follower-on-the-primary-cluster-in-uni-directional-ccr/360880)

<div class="topic-metadata">

**Author:** [@Paresh\_Kalinani](https://discuss.elastic.co/u/Paresh_Kalinani)\
**Replies:** 1\
**Last updated:** [June 5, 2025, 1:45pm UTC](https://discuss.elastic.co/t/why-cant-we-make-the-leader-index-as-the-follower-on-the-primary-cluster-in-uni-directional-ccr/360880 "2025-06-05T13:45:39Z")

</div>

I have two clusters, the primary is called A and the secondary is B. I have indices in A for which I created follower indices in B. Now, I could pause the following, close, unfollow and open the indices in B to make th…

---

## [Snapshot Restore to 9.0.1 Fails Despite Setting \`index.blocks.write=true\` on Source Index in 8.7.1](https://discuss.elastic.co/t/snapshot-restore-to-9-0-1-fails-despite-setting-index-blocks-write-true-on-source-index-in-8-7-1/378853)

<div class="topic-metadata">

**Author:** [@Bojan\_Komazec](https://discuss.elastic.co/u/Bojan_Komazec)\
**Replies:** 10\
**Last updated:** [June 5, 2025, 9:17am UTC](https://discuss.elastic.co/t/snapshot-restore-to-9-0-1-fails-despite-setting-index-blocks-write-true-on-source-index-in-8-7-1/378853 "2025-06-05T09:17:35Z")

</div>

Hi all, I'm attempting to restore a snapshot from an Elasticsearch 8.7.1 cluster into a 9.0.1 cluster running via ECK on AWS EKS. I have full access to both clusters. The snapshot was taken in 8.7.1 and includes some o…

---

## [Issue with Multi terms aggregation with Boolean field](https://discuss.elastic.co/t/issue-with-multi-terms-aggregation-with-boolean-field/378585)

<div class="topic-metadata">

**Author:** [@bsehra](https://discuss.elastic.co/u/bsehra)\
**Replies:** 15\
**Last updated:** [June 5, 2025, 9:04am UTC](https://discuss.elastic.co/t/issue-with-multi-terms-aggregation-with-boolean-field/378585 "2025-06-05T09:04:45Z")

</div>

I'm using Elasticsearch server 8.17.3 and Elasticsearch net Client 8.17.3. Looks like there is an issue with Elasticsearch resolving the multi terms aggregation involving a boolean field. I get below error where as I'm o…

---

## [SAN a valid option for an ELK stack?](https://discuss.elastic.co/t/san-a-valid-option-for-an-elk-stack/378888)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 4\
**Last updated:** [June 5, 2025, 8:44am UTC](https://discuss.elastic.co/t/san-a-valid-option-for-an-elk-stack/378888 "2025-06-05T08:44:27Z")

</div>

Dear community, a quick question: I need space for my indices. Is local storage the only best option for hot data or is SAN a valid option too? I am running a 8.17.x, single node, productive, dockerized all-in-one solu…

---

## [We are using Elasticsearch version 8.13, We have continuous heavy aggregation queries, it is making whole cluster unstable](https://discuss.elastic.co/t/we-are-using-elasticsearch-version-8-13-we-have-continuous-heavy-aggregation-queries-it-is-making-whole-cluster-unstable/378699)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 6\
**Last updated:** [June 5, 2025, 6:55am UTC](https://discuss.elastic.co/t/we-are-using-elasticsearch-version-8-13-we-have-continuous-heavy-aggregation-queries-it-is-making-whole-cluster-unstable/378699 "2025-06-05T06:55:59Z")

</div>

We have a heavy load aggregation , which cause circuit breaker quite often, I want to handle this before hand as the more ciicuit breakers are making our whole cluster unstable and many times it is making node with .secu…

---

## [Renew auto generated http certificates](https://discuss.elastic.co/t/renew-auto-generated-http-certificates/362929)

<div class="topic-metadata">

**Author:** [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Replies:** 6\
**Last updated:** [June 5, 2025, 4:23am UTC](https://discuss.elastic.co/t/renew-auto-generated-http-certificates/362929 "2025-06-05T04:23:18Z")

</div>

Hello, can anyone help me how to renew the http certificates of the elasticsearch nodes in a autoconfigured on-prem cluster? The current ones were generated automatically from the enrollment process / at startup of the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=28)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=30)
