# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=291

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 292

---

## [All the shards are being assigned to a single node](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 11:27am UTC](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857 "2023-03-06T11:27:41Z")

</div>

Hi.. We have a 6 data node cluster and we have around 2000 indices with 9500 shards. We have the below cluster settings and have enabled all the shards to be re-balanced to distribute the shards across the cluster. { …

---

## [Elasticsearch deprecation issues](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 11:20am UTC](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543 "2023-03-06T11:20:40Z")

</div>

I can't upgrade to 8.6.1 due to a deprecation issue. I can't update the elasticsearch.yml, because I have a cloud solution. Problem: setting \[cluster.routing.allocation.disk.watermark.enable\_for\_single\_data\_node\] is dep…

---

## [Elastic ML Alert Mustache Syntax (Break Line)](https://discuss.elastic.co/t/elastic-ml-alert-mustache-syntax-break-line/327024)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 9:16am UTC](https://discuss.elastic.co/t/elastic-ml-alert-mustache-syntax-break-line/327024 "2023-03-06T09:16:18Z")

</div>

Hi, I would like to adjust my email alert to break to a new line. From above image, the upper context for (Environment Affected) is working as I used {{{foo}}} to break it. However, it does not work for the (Detect…

---

## [Searching non-indexed fields](https://discuss.elastic.co/t/searching-non-indexed-fields/327033)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:40am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033 "2023-03-06T08:40:00Z")

</div>

Hi everyone, Contrary to popular opinion, I'm able to search non-indexed fields in Elasticsearch. I'm wondering if this is is a bug or a newly introduced feature. I'm on Elasticsearch 8.6.2. The documentation says "Fie…

---

## [File Descriptors count](https://discuss.elastic.co/t/file-descriptors-count/327043)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 8:15am UTC](https://discuss.elastic.co/t/file-descriptors-count/327043 "2023-03-06T08:15:17Z")

</div>

Hi, According to docs it is recommended to set File Descriptors to 65535 (ulimit -n). How it effect my node? What will be the behavior if I will set higher value? for instance: 500000 Thanks

---

## [How to measure time it takes from elasticsearch pod to elasticsearch?](https://discuss.elastic.co/t/how-to-measure-time-it-takes-from-elasticsearch-pod-to-elasticsearch/327035)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 6:42am UTC](https://discuss.elastic.co/t/how-to-measure-time-it-takes-from-elasticsearch-pod-to-elasticsearch/327035 "2023-03-06T06:42:02Z")

</div>

We have a global search functionality that takes time to fetch data from Elasticsearch so we need to measure time it would take from elasticsearch pod to elasticsearch itself. Our technology uses java spring Elasticsearc…

---

## [Deleting \_recovery\_source](https://discuss.elastic.co/t/deleting-recovery-source/327028)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:32am UTC](https://discuss.elastic.co/t/deleting-recovery-source/327028 "2023-03-06T05:32:45Z")

</div>

Hi everyone, I'm on Elasticsearch 8.6.2. I wanted to reduce disk usage of my indices, and noticed that the \_recovery\_source takes up quite some space. I tried setting index.soft\_deletes.enabled to false, but index cr…

---

## [How to prevent RestHighLevelClient from blacklisting the Host in Elasticsearch 8.6.2?](https://discuss.elastic.co/t/how-to-prevent-resthighlevelclient-from-blacklisting-the-host-in-elasticsearch-8-6-2/327027)

<div class="topic-metadata">

**Author:** [@\_ite\_iew](https://discuss.elastic.co/u/_ite_iew)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-to-prevent-resthighlevelclient-from-blacklisting-the-host-in-elasticsearch-8-6-2/327027 "2023-03-06T05:27:35Z")

</div>

I am using Elasticsearch client version 8.6 we use Elasticsearch as a service and other companies provided us an IP/port to connect to it. we run heavy, numerous, automated queries against this Elasticsearch and someti…

---

## [Installed elastic search on Window 11. I hit localhost:9200 and Asking for Username and Password?](https://discuss.elastic.co/t/installed-elastic-search-on-window-11-i-hit-localhost-9200-and-asking-for-username-and-password/327022)

<div class="topic-metadata">

**Author:** [@wsdevprogrammer](https://discuss.elastic.co/u/wsdevprogrammer)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 3:50am UTC](https://discuss.elastic.co/t/installed-elastic-search-on-window-11-i-hit-localhost-9200-and-asking-for-username-and-password/327022 "2023-03-06T03:50:35Z")

</div>

I have installed Latest Elastic search setup on Window 11 , as i type lcoalhost:9200 as i hit enter it says user name and password. i don't know which type of pass and username need to enter.

---

## [ELK stack config on docker](https://discuss.elastic.co/t/elk-stack-config-on-docker/325941)

<div class="topic-metadata">

**Author:** [@samidha\_dubey](https://discuss.elastic.co/u/samidha_dubey)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 12:34am UTC](https://discuss.elastic.co/t/elk-stack-config-on-docker/325941 "2023-03-06T00:34:40Z")

</div>

Hello Team here i need some help in order to setup my ELK stack on docker, we laredy have cloud elk setup but now we decided to move from cloud to on prim setup which is weird though :stuck\_out\_tongue: as of now i have …

---

## [Elasticsearch error, after xpack authencation enabled](https://discuss.elastic.co/t/elasticsearch-error-after-xpack-authencation-enabled/326743)

<div class="topic-metadata">

**Author:** [@k\_noor](https://discuss.elastic.co/u/k_noor)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 11:32pm UTC](https://discuss.elastic.co/t/elasticsearch-error-after-xpack-authencation-enabled/326743 "2023-03-05T23:32:41Z")

</div>

HI All, I have enabled the pack for authentication purpose, but error has reported as below. Cloud you please help in this. at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:173) ~\[elasticsearch-7.…

---

## [SQL Query on ElasticSearch fails to parse a message, throws illegal\_argument\_exception](https://discuss.elastic.co/t/sql-query-on-elasticsearch-fails-to-parse-a-message-throws-illegal-argument-exception/326931)

<div class="topic-metadata">

**Author:** [@pedrodantas](https://discuss.elastic.co/u/pedrodantas)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 11:36am UTC](https://discuss.elastic.co/t/sql-query-on-elasticsearch-fails-to-parse-a-message-throws-illegal-argument-exception/326931 "2023-03-03T11:36:00Z")

</div>

Hello, I am trying to query my Elasticsearch environment using a Canvas dashboard on the Kibana App. I am getting a weird error when making a simple SQL query. The illegal\_argument\_exception says that it failed tryi…

---

## [SQL query on indices imported by OTEL Collector and Elastic APM](https://discuss.elastic.co/t/sql-query-on-indices-imported-by-otel-collector-and-elastic-apm/326711)

<div class="topic-metadata">

**Author:** [@ncvolt](https://discuss.elastic.co/u/ncvolt)\
**Replies:** 4\
**Last updated:** [March 5, 2023, 11:03pm UTC](https://discuss.elastic.co/t/sql-query-on-indices-imported-by-otel-collector-and-elastic-apm/326711 "2023-03-05T23:03:52Z")

</div>

When OTEL collector sends traces, logs and metrics to elastic APM It got stored with indices names like GET \_cat/indices yellow open .ds-logs-apm.app-default-2023.02.27-000001 ciiMrei8TLmJ1YilCaZy\_A 1 1 96 …

---

## [How to install Elastic stack (ELK) 8.6.2 in windows machine?](https://discuss.elastic.co/t/how-to-install-elastic-stack-elk-8-6-2-in-windows-machine/326933)

<div class="topic-metadata">

**Author:** [@sonu\_singh](https://discuss.elastic.co/u/sonu_singh)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 10:58pm UTC](https://discuss.elastic.co/t/how-to-install-elastic-stack-elk-8-6-2-in-windows-machine/326933 "2023-03-05T22:58:16Z")

</div>

Hi there, I am trying to install Elastic stack (ELK 8.6.2) in windows machine and Elasticsearch is not getting up. No luck on finding the Installation steps/tutorials/blogs online for Elastic stack 8.6.2. Any suggesti…

---

## [ELK Searches from Splunk](https://discuss.elastic.co/t/elk-searches-from-splunk/326887)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 3\
**Last updated:** [March 5, 2023, 10:38pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887 "2023-03-05T22:38:03Z")

</div>

Hello On a single server I have ELK(v 7.6.0) and Splunk. All sources that support syslog protocol are being ingested to ELK Taking advantage of some Splunk functionalities a query is made to ELK with this kind of code…

---

## [What's Python "best practice" for security certificates with ES8?](https://discuss.elastic.co/t/whats-python-best-practice-for-security-certificates-with-es8/327009)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 4:17pm UTC](https://discuss.elastic.co/t/whats-python-best-practice-for-security-certificates-with-es8/327009 "2023-03-05T16:17:08Z")

</div>

I just set up ES 8.6.2 on my machine. This is a single-machine setup. In fact I'm upgrading from 7.10.2, see previous question. I've managed to obtain a password for user "elastic"... this means I can get the "You know,…

---

## [How to customise ICU Collation Keyword Field for sorting digits, symbols at last after the alphabets?](https://discuss.elastic.co/t/how-to-customise-icu-collation-keyword-field-for-sorting-digits-symbols-at-last-after-the-alphabets/327000)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 11:32am UTC](https://discuss.elastic.co/t/how-to-customise-icu-collation-keyword-field-for-sorting-digits-symbols-at-last-after-the-alphabets/327000 "2023-03-05T11:32:01Z")

</div>

The phonebook fields sort the symbols, currency and digits at the top grouped. Instead i want to give the alphabets (a-z) the most precedence and appears first in the sorting and all the above 3 below it. for example In…

---

## [Struggling to get ES 8.6.2 to work (on W10)](https://discuss.elastic.co/t/struggling-to-get-es-8-6-2-to-work-on-w10/326998)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 11:16am UTC](https://discuss.elastic.co/t/struggling-to-get-es-8-6-2-to-work-on-w10/326998 "2023-03-05T11:16:17Z")

</div>

This follows on from this question. I deliberately configured 8.6.2 to use port 9500. I appear to have got 8.6.2 running on this W10 OS. When I enter "https://localhost:9500" in my browser I am asked for a username and…

---

## [Use terms\_set with nested array](https://discuss.elastic.co/t/use-terms-set-with-nested-array/326997)

<div class="topic-metadata">

**Author:** [@Ibrahem\_ismail](https://discuss.elastic.co/u/Ibrahem_ismail)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 9:08am UTC](https://discuss.elastic.co/t/use-terms-set-with-nested-array/326997 "2023-03-05T09:08:22Z")

</div>

Is there a way to use terms\_set with nested array { "from": 0, "size": 10, "query": { "bool": { "filter": \[ { "nested": { "path…

---

## [Run two versions of ES on machine](https://discuss.elastic.co/t/run-two-versions-of-es-on-machine/326985)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 5\
**Last updated:** [March 5, 2023, 9:49am UTC](https://discuss.elastic.co/t/run-two-versions-of-es-on-machine/326985 "2023-03-05T09:49:51Z")

</div>

This is on a W10 box. ES (7.10.2) is currently running on localhost:9200. I need to upgrade. When I attempted to upgrade to 7.16.3 some time ago a regression occurred, reported by me and acknowledged by Elasticsearch HQ,…

---

## [How to define "target-throughput" in cmd line of custom track](https://discuss.elastic.co/t/how-to-define-target-throughput-in-cmd-line-of-custom-track/326831)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 2\
**Last updated:** [March 5, 2023, 6:29am UTC](https://discuss.elastic.co/t/how-to-define-target-throughput-in-cmd-line-of-custom-track/326831 "2023-03-05T06:29:54Z")

</div>

hello i'm trying to make new custom track and just found how to write basic custom track and i have question that how can i pass params from command line for example, i want to set target-throuput on command line like …

---

## [Executing update by query for a array of arrays](https://discuss.elastic.co/t/executing-update-by-query-for-a-array-of-arrays/326993)

<div class="topic-metadata">

**Author:** [@otaviom\_30](https://discuss.elastic.co/u/otaviom_30)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 4:30am UTC](https://discuss.elastic.co/t/executing-update-by-query-for-a-array-of-arrays/326993 "2023-03-05T04:30:27Z")

</div>

Hello! So, one of the metadata I have indexed is a array of arrays. But, I'm having problems when I try to execute a update by query on it. Here is the sintax I'm using: "source":"ctx.\_source.Exemple ='\[\['foobar','10',…

---

## [Speed of elastic search](https://discuss.elastic.co/t/speed-of-elastic-search/326554)

<div class="topic-metadata">

**Author:** [@smitak](https://discuss.elastic.co/u/smitak)\
**Replies:** 15\
**Last updated:** [March 4, 2023, 8:41pm UTC](https://discuss.elastic.co/t/speed-of-elastic-search/326554 "2023-03-04T20:41:03Z")

</div>

How to increase Elasticsearch speed . I am uploading 75 files at a time and i want to add pdf file content into database.But it is taking 15-20 min. Any suggestions.

---

## [Need an example to to multi value search](https://discuss.elastic.co/t/need-an-example-to-to-multi-value-search/326971)

<div class="topic-metadata">

**Author:** [@vkrishna](https://discuss.elastic.co/u/vkrishna)\
**Replies:** 6\
**Last updated:** [March 4, 2023, 8:02pm UTC](https://discuss.elastic.co/t/need-an-example-to-to-multi-value-search/326971 "2023-03-04T20:02:40Z")

</div>

Hi Team, We need an example to to multi value search using co.elastic.clients.elasticsearch.\_types.query\_dsl.Query. Assume we have a field called "rating" in Elasticsearch. I want a JAVA Elasticsearch query written us…

---

## [Filtering by date field with DSL returning invalid results](https://discuss.elastic.co/t/filtering-by-date-field-with-dsl-returning-invalid-results/326969)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 7\
**Last updated:** [March 3, 2023, 8:18pm UTC](https://discuss.elastic.co/t/filtering-by-date-field-with-dsl-returning-invalid-results/326969 "2023-03-03T20:18:58Z")

</div>

I am trying to query one of my indexes for all records that have a date field (labels.expiresAt) set gte to now. In other words, the date field should be later than today. That seems super straightforward, but when I set…

---

## [Security Error while integrating SSO with elastic cloud cluster using Terraform](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967)

<div class="topic-metadata">

**Author:** [@Saicharan\_M](https://discuss.elastic.co/u/Saicharan_M)\
**Replies:** 1\
**Last updated:** [March 3, 2023, 7:08pm UTC](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967 "2023-03-03T19:08:16Z")

</div>

I've been trying to provision elastic cluster with SSO configured. As per the latest ec provider documentation we should be able to achieve this in a single workflow. But however, I do see below error while provisioning …

---

## [Nested aggregation](https://discuss.elastic.co/t/nested-aggregation/326949)

<div class="topic-metadata">

**Author:** [@Sneha\_Rose](https://discuss.elastic.co/u/Sneha_Rose)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 2:52pm UTC](https://discuss.elastic.co/t/nested-aggregation/326949 "2023-03-03T14:52:44Z")

</div>

I have an elastic index with authors field as array of objects: "authors" : \[ { "email" : "100@gmail.com", "authid" : "100", }, { "email" : "200@gmail.com", "authid" : "200", }, { "email" : "300@gmail.com", …

---

## [Multiple chain inputs and foreach](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882)

<div class="topic-metadata">

**Author:** [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 1:16pm UTC](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882 "2023-03-03T13:16:34Z")

</div>

I have following basic watcher. { "trigger": { "schedule": { "interval": "1m" } }, "input": { "chain": { "inputs": \[ { "first\_input": { "http": { …

---

## [Relevance tuning in platform search -scoring profile](https://discuss.elastic.co/t/relevance-tuning-in-platform-search-scoring-profile/326938)

<div class="topic-metadata">

**Author:** [@Arumugam](https://discuss.elastic.co/u/Arumugam)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 12:46pm UTC](https://discuss.elastic.co/t/relevance-tuning-in-platform-search-scoring-profile/326938 "2023-03-03T12:46:06Z")

</div>

We would like to define the weight by default for some fields and those weight criteria applied for search query. We want to same functionality that's available in App Search(Relevance tuning) in platform search. For ex…

---

## [Painlessly turning a string of multiple numbers into multiple fields of numbers](https://discuss.elastic.co/t/painlessly-turning-a-string-of-multiple-numbers-into-multiple-fields-of-numbers/326800)

<div class="topic-metadata">

**Author:** [@Mike\_Williams](https://discuss.elastic.co/u/Mike_Williams)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 10:38am UTC](https://discuss.elastic.co/t/painlessly-turning-a-string-of-multiple-numbers-into-multiple-fields-of-numbers/326800 "2023-03-03T10:38:24Z")

</div>

Hey all, I'm ingesting JSON formatted logs from nginx. The JSON is all ECS style nested fields. I've currently got a need to visualize the upstream response time, http.upstream.response.time. Fundamentally this is a fl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=290)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=292)
