# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=290

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 291

---

## [Number of Zones for Zone awared Shard allocation](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169)

<div class="topic-metadata">

**Author:** [@Mani2](https://discuss.elastic.co/u/Mani2)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:20pm UTC](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169 "2023-03-07T22:20:37Z")

</div>

Hello, What can be the criteria of deciding the maximum number of zones within a data centre. For ex, If I have 30 Racks in a Data Centre, and if I have Primary and Secondary shards are 1,2 so minimum zones require will…

---

## [Getting authentication failure when logging into kibana](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:06pm UTC](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222 "2023-03-07T22:06:42Z")

</div>

I am trying to log into kibana as the elastic user to do some maintenance but the login fails -- server shows: Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\] I ca…

---

## [Configuracion del Node.Roles \[master\]](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098)

<div class="topic-metadata">

**Author:** [@LeonardoCord](https://discuss.elastic.co/u/LeonardoCord)\
**Replies:** 5\
**Last updated:** [March 7, 2023, 9:33pm UTC](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098 "2023-03-07T21:33:11Z")

</div>

Buenas Estoy tratando de configurar el Node.Roles \[master\] debido a que es una configuracion obsoleta en la version que tengo 7.17.6 y he configurado mi .YML pero a la hora de correrlo mi elastic no arranca.

---

## [Importing multiple large csv and json files into a single index](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738)

<div class="topic-metadata">

**Author:** [@mansi\_raval](https://discuss.elastic.co/u/mansi_raval)\
**Replies:** 10\
**Last updated:** [March 7, 2023, 9:29pm UTC](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738 "2023-03-07T21:29:17Z")

</div>

I have an folder containing data (20 GB) and this folder contains 26 subfolders that are sorted city-wise. Each of these subfolder contain many more subfolders comprising of csv and json files (The data that is stored in…

---

## [Disk size and performance optimization for Elasticsearch cluster](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:20pm UTC](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071 "2023-03-07T21:20:48Z")

</div>

Hi everyone, I'm currently running an Elasticsearch cluster with 6 nodes, and (for every node) the disk usage is around 5.5 TB out of a total disk size of 20 TB. I don't anticipate a significant increase in data storag…

---

## [Elasticsearch monitor with metricbeat](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223 "2023-03-07T19:26:47Z")

</div>

I am so crazy confuse on this setup. can't seems to make it work. this is my test setup that I am trying and getting more confuse every min. here is my configuration. monitor cluster:: elkdev11 monitoring cluster: …

---

## [Elasticsearch Cloud API Authentication](https://discuss.elastic.co/t/elasticsearch-cloud-api-authentication/327161)

<div class="topic-metadata">

**Author:** [@Mark\_Rodman](https://discuss.elastic.co/u/Mark_Rodman)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 4:28pm UTC](https://discuss.elastic.co/t/elasticsearch-cloud-api-authentication/327161 "2023-03-07T16:28:31Z")

</div>

Hi, I'm trying to figure how to authenticate REST API use against our Elasticsearch cloud instance. I understand how to use the cloud id etc when using a client library in a language such as Python however in my use ca…

---

## [Issue with RecyclerBytesStreamOutput](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996)

<div class="topic-metadata">

**Author:** [@aurelien.guillaume](https://discuss.elastic.co/u/aurelien.guillaume)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 4:03pm UTC](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996 "2023-03-07T16:03:26Z")

</div>

Hi, I'm new in the usage of Elasticsearch (integrated into a security onion appliance) I'm working to get a huge query (2.5M logs), and I'm stuck with this error message { "error": { "root\_cause": \[ { …

---

## [Filebeat: failed to parse field \[user\_agent.version\] of type \[date\]](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 12\
**Last updated:** [March 7, 2023, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124 "2023-03-07T14:43:29Z")

</div>

This begins as a filebeat issue but I think it's now a matter of elasticsearch index. I'm seeing repeated messages like this in our logging. I can see this is related to the nginx module but I'm unsure how to go about f…

---

## [Profiling kNN search](https://discuss.elastic.co/t/profiling-knn-search/327065)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/profiling-knn-search/327065 "2023-03-07T13:33:27Z")

</div>

I'm trying to profile slow kNN search as discussed here . So I read the documentation here and set up this query in Postman: { "profile": true, "knn": { "field": "title\_vector", "query\_vector": {{SEARCH\_TEX…

---

## [Falied to start Elasticsearch to my group volumes](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501)

<div class="topic-metadata">

**Author:** [@MonkeyD.J](https://discuss.elastic.co/u/MonkeyD.J)\
**Replies:** 9\
**Last updated:** [March 7, 2023, 12:17pm UTC](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501 "2023-03-07T12:17:15Z")

</div>

Hello, Mrs,Mr, I try to start Elasticsearch on my volum group. So I am on a debian 11.3 and I install java jre1.8.0\_121. I Install the version elastick 7.17.6 amd64.deb on my folder with this command dpkg -x /applis…

---

## [Elasticsearch update by query](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167)

<div class="topic-metadata">

**Author:** [@v-lixiubo](https://discuss.elastic.co/u/v-lixiubo)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 11:30am UTC](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167 "2023-03-07T11:30:14Z")

</div>

hi , I use the java client updateByQuery to update the data, and the returned result is successful, but the data has not actually changed

---

## [Cannot create elastic indexes after removing two nodes from cassandra](https://discuss.elastic.co/t/cannot-create-elastic-indexes-after-removing-two-nodes-from-cassandra/327151)

<div class="topic-metadata">

**Author:** [@Ram5](https://discuss.elastic.co/u/Ram5)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 9:24am UTC](https://discuss.elastic.co/t/cannot-create-elastic-indexes-after-removing-two-nodes-from-cassandra/327151 "2023-03-07T09:24:47Z")

</div>

I cannot create elastic index after removing two nodes from cassandra. We had two nodes earlier, but for some reason they were unable to communicate with each other. So we removed them and changed necessary configuration…

---

## ["Cannot write to a field alias \[...\]" on reindex](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-on-reindex/327162)

<div class="topic-metadata">

**Author:** [@Adrien](https://discuss.elastic.co/u/Adrien)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 9:14am UTC](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-on-reindex/327162 "2023-03-07T09:14:59Z")

</div>

Hi, I'm trying to migrate an Elasticsearch index from 6.8 to 7.10 using the \_reindex route API. Unfortunately during the index migration I get the error Cannot write to a field alias \[gl2\_message\_id\]. The mapping, cop…

---

## [Apply minimum score parameter for the child queries](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139)

<div class="topic-metadata">

**Author:** [@Rahul\_S1](https://discuss.elastic.co/u/Rahul_S1)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:42am UTC](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139 "2023-03-07T05:42:19Z")

</div>

I'm trying to apply some minimum score criteria for my has child queries, my data looks like this: {"Product Code": "A", "properties" :\[{"PROPERTY\_NAME":"density","PROPERTY\_NAME Encoded":\[0.22,0.432,.....\],"value":"low"…

---

## [Zone within data Centre](https://discuss.elastic.co/t/zone-within-data-centre/327141)

<div class="topic-metadata">

**Author:** [@Mani2](https://discuss.elastic.co/u/Mani2)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:54am UTC](https://discuss.elastic.co/t/zone-within-data-centre/327141 "2023-03-07T05:54:19Z")

</div>

What can be criteria of deciding the maximum number of zones within a data centre. For ex, If I have 30 Racks in a Data Centre, and if I have Primary and Secondary shards are 1,2 so minimum zones require will be 3. If ea…

---

## [Different Version Elasticsearch, Kibana, Metricbeat](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 5:47am UTC](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136 "2023-03-07T05:47:01Z")

</div>

is it ok if use Elasticsearch, Kibana, Metricbeat version 8.6.1 to connect to version 8.6.2?

---

## [How to write a collation rule for icu\_collation\_keyword field, with alphabets having atmost precedence?](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019 "2023-03-07T05:27:10Z")

</div>

Instead of using alternative locale option, I want to write a rules parameter to customise the sort behaviour with alphabets having atmost precedence. for the text values, $1232, Abi, £7232, 87343, Karthik I want the…

---

## [Is there query char length limit of a match query](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020)

<div class="topic-metadata">

**Author:** [@chenchuangc](https://discuss.elastic.co/u/chenchuangc)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 1:49am UTC](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020 "2023-03-07T01:49:34Z")

</div>

Thank you so much for having a look of my issue. ES Version 7.5.0 Query GET search\_vietnamese/\_search { "query": { "bool": { "should": \[ { "match": { "address": { …

---

## [Is it possible to ignore failure while using the Reindex API?](https://discuss.elastic.co/t/is-it-possible-to-ignore-failure-while-using-the-reindex-api/327120)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 10:01pm UTC](https://discuss.elastic.co/t/is-it-possible-to-ignore-failure-while-using-the-reindex-api/327120 "2023-03-06T22:01:40Z")

</div>

Hello, I'm trying to run some reindex on an index and got a failure related to a mapping parsing exception, which is kinda of expected as on this data the field can change from object to text. For this reason, the dest…

---

## [Reindex document count does not match the source](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116)

<div class="topic-metadata">

**Author:** [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:41pm UTC](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116 "2023-03-06T20:41:46Z")

</div>

I am reindexing an index from one cluster (elastic 6.8) to another cluster (elastic 7.17) Source: GET \<index\_name\>/\_count { "count" : 827908, "\_shards" : { "total" : 5, "successful" : 5, "skipped" : 0, "failed" …

---

## [Simple Query to search within log text (not keyword)](https://discuss.elastic.co/t/simple-query-to-search-within-log-text-not-keyword/327095)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 6:51pm UTC](https://discuss.elastic.co/t/simple-query-to-search-within-log-text-not-keyword/327095 "2023-03-06T18:51:30Z")

</div>

I am trying to search within text that originates from log files. Am I using the correct query? Any suggestions on how to restrict results only to the exact match? (eg show only results with higher score?) I am using e…

---

## [Will influencer change the way a model might detect and anomaly?](https://discuss.elastic.co/t/will-influencer-change-the-way-a-model-might-detect-and-anomaly/326908)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 5:29pm UTC](https://discuss.elastic.co/t/will-influencer-change-the-way-a-model-might-detect-and-anomaly/326908 "2023-03-06T17:29:15Z")

</div>

Hello Team, I am working with the machine learning tools provided by elastic. I am detecting certain rare events over time. But now I have certain fields that I want the model to take in consideration while detecting th…

---

## [Saving the content of a file in an elasticsearch index using springboot RESTAPI](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112)

<div class="topic-metadata">

**Author:** [@BEY\_MEHREZ](https://discuss.elastic.co/u/BEY_MEHREZ)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:14pm UTC](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112 "2023-03-06T17:14:53Z")

</div>

So I am building a Spring Boot rest api that it takes a file ( Multipart file ) ( and it is a log file ) as an argument and saves its content in a unique elasticsearch index ! Each line of the file will be in a document.…

---

## [Bufforing logs using ingest node](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 4:50pm UTC](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103 "2023-03-06T16:50:27Z")

</div>

Hi, I need to create an Elastic SIEM cluster in which logs will be buffered in the event of a data node failure. When the data node is brought back to life, the logs from the period when the node was not functioning wil…

---

## [Elasticsearch Compilation issues on Linux](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096)

<div class="topic-metadata">

**Author:** [@markchennai](https://discuss.elastic.co/u/markchennai)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 3:19pm UTC](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096 "2023-03-06T15:19:47Z")

</div>

Team, I am facing issues while compiling Elasticsearch 8.5.1, the source code is allowed to pull the files from the in-house repo, FAILURE: Build failed with an exception. What went wrong: A problem occurred configu…

---

## [java.lang.RuntimeException when using client in Java API in Kotlin](https://discuss.elastic.co/t/java-lang-runtimeexception-when-using-client-in-java-api-in-kotlin/327013)

<div class="topic-metadata">

**Author:** [@GAETANO\_SIMONELLI](https://discuss.elastic.co/u/GAETANO_SIMONELLI)\
**Replies:** 6\
**Last updated:** [March 6, 2023, 1:05pm UTC](https://discuss.elastic.co/t/java-lang-runtimeexception-when-using-client-in-java-api-in-kotlin/327013 "2023-03-06T13:05:38Z")

</div>

I am trying to use the Elasticsearch Java API in a Kotlin application, following the official tutorial page (Connecting | Elasticsearch Java API Client \[8.6\] | Elastic). However, I am encountering a java.lang.RuntimeExce…

---

## [Calculate MTTR for jenkins builds](https://discuss.elastic.co/t/calculate-mttr-for-jenkins-builds/327067)

<div class="topic-metadata">

**Author:** [@khuongdp](https://discuss.elastic.co/u/khuongdp)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 1:44pm UTC](https://discuss.elastic.co/t/calculate-mttr-for-jenkins-builds/327067 "2023-03-06T13:44:20Z")

</div>

Hi I would like to calculate MTTR for some jenkins builds. I have these fields in multiple documents: Using Elasticsearch 8.3.0 input : name, type \[type1|type2\], status \[failure|success\], buildDateTime Output (somet…

---

## [High CPU Utilization in Elasticsearch Nodes](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 1:12pm UTC](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078 "2023-03-06T13:12:26Z")

</div>

Hi, We have been experiencing HIGH CPU USAGE in elasticsearch nodes for the last couple of days causing timeout exceptions for most of the search queries. We have dedicated nodes for ES, however, there is no defined mas…

---

## [Setup Elastic Watcher Alert to match two message strings in a log](https://discuss.elastic.co/t/setup-elastic-watcher-alert-to-match-two-message-strings-in-a-log/326804)

<div class="topic-metadata">

**Author:** [@scott.godfrey](https://discuss.elastic.co/u/scott.godfrey)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 1:09pm UTC](https://discuss.elastic.co/t/setup-elastic-watcher-alert-to-match-two-message-strings-in-a-log/326804 "2023-03-06T13:09:34Z")

</div>

I'm trying to setup an Elastic Watcher Alert that will scan a logfile and match 2 different messages in the log and then send an alert. Sample Log \[2023-02-13 09:00:10.749 -05:00 INF\] This is test 1 \[2023-02-13 09:10…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=289)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=291)
