# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=293

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 294

---

## [How to list out / export all the fields along with data types](https://discuss.elastic.co/t/how-to-list-out-export-all-the-fields-along-with-data-types/325975)

<div class="topic-metadata">

**Author:** [@RajuParipelly](https://discuss.elastic.co/u/RajuParipelly)\
**Replies:** 7\
**Last updated:** [February 28, 2023, 10:20am UTC](https://discuss.elastic.co/t/how-to-list-out-export-all-the-fields-along-with-data-types/325975 "2023-02-28T10:20:19Z")

</div>

I have an index with 25000 fields and wanted to export all the fields into a csv file along with data type? is there any way to do this?

---

## [Prevent setting minimum\_master\_nodes to more than the current node count](https://discuss.elastic.co/t/prevent-setting-minimum-master-nodes-to-more-than-the-current-node-count/326536)

<div class="topic-metadata">

**Author:** [@zhoumengbo](https://discuss.elastic.co/u/zhoumengbo)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 10:10am UTC](https://discuss.elastic.co/t/prevent-setting-minimum-master-nodes-to-more-than-the-current-node-count/326536 "2023-02-28T10:10:38Z")

</div>

Setting zen.discovery.minimum\_master\_nodes to a value higher than the current node count effectively leaves the cluster without a master and unable to process requests. The official website below has fixed this bug. ht…

---

## [Problem with adding node to elastic cluster](https://discuss.elastic.co/t/problem-with-adding-node-to-elastic-cluster/326671)

<div class="topic-metadata">

**Author:** [@reza\_setareh](https://discuss.elastic.co/u/reza_setareh)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 10:05am UTC](https://discuss.elastic.co/t/problem-with-adding-node-to-elastic-cluster/326671 "2023-02-28T10:05:12Z")

</div>

hi every one.i want to add new node to elastic cluster by enrollment token but i got the error below E:\\node-1\\bin\>elasticsearch-create-enrollment-token.bat -s node ERROR: \[xpack.security.enrollment.enabled\] must be se…

---

## [Transforming logs into geo\_point to draw them in kibana](https://discuss.elastic.co/t/transforming-logs-into-geo-point-to-draw-them-in-kibana/323053)

<div class="topic-metadata">

**Author:** [@grillo](https://discuss.elastic.co/u/grillo)\
**Replies:** 10\
**Last updated:** [February 28, 2023, 8:29am UTC](https://discuss.elastic.co/t/transforming-logs-into-geo-point-to-draw-them-in-kibana/323053 "2023-02-28T08:29:41Z")

</div>

My goal is to be able to geolocate on a kibana map the connections that interest me. The problem is that the generated indices do not create the correct type of data for kibana to draw. It would be Geopoints. The data …

---

## [Must and should match doesn't return should matches](https://discuss.elastic.co/t/must-and-should-match-doesnt-return-should-matches/326657)

<div class="topic-metadata">

**Author:** [@ksh117](https://discuss.elastic.co/u/ksh117)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 7:58am UTC](https://discuss.elastic.co/t/must-and-should-match-doesnt-return-should-matches/326657 "2023-02-28T07:58:12Z")

</div>

{ "track\_total\_hits": true, "from": 0, "size": 20, "query": { "bool": { "must": \[ { "term": { "item\_id": { "value": "item\_value\_1", "boost": 1 …

---

## [Elasticsearch ilm rollover NOT applied as it should on datastreams v8.5.2](https://discuss.elastic.co/t/elasticsearch-ilm-rollover-not-applied-as-it-should-on-datastreams-v8-5-2/326612)

<div class="topic-metadata">

**Author:** [@Gautier\_Franchini](https://discuss.elastic.co/u/Gautier_Franchini)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 7:45am UTC](https://discuss.elastic.co/t/elasticsearch-ilm-rollover-not-applied-as-it-should-on-datastreams-v8-5-2/326612 "2023-02-28T07:45:54Z")

</div>

Dear All, I'm currently using elasticsearch and kibana in 8.5.2 version; I used the stack as a centralized logging platform. Everything works fine, logstash is able to send me tousant of logs through elastic data stream …

---

## [Elastic search did not trust this server's certificate, closing connection](https://discuss.elastic.co/t/elastic-search-did-not-trust-this-servers-certificate-closing-connection/326663)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 7:35am UTC](https://discuss.elastic.co/t/elastic-search-did-not-trust-this-servers-certificate-closing-connection/326663 "2023-02-28T07:35:08Z")

</div>

Elasticsearch is running successfully but when iam checking the logs its says "http client did not trust this server's certificate, closing connection" find the log below : WARN", "message":"http client did not trust t…

---

## [Is it possible to integrated Elasticsearh with OBM Microfocus?](https://discuss.elastic.co/t/is-it-possible-to-integrated-elasticsearh-with-obm-microfocus/326645)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 6:57am UTC](https://discuss.elastic.co/t/is-it-possible-to-integrated-elasticsearh-with-obm-microfocus/326645 "2023-02-28T06:57:28Z")

</div>

I have question is it possible if elastic APM monitoring results be combined with other monitoring tools such as OBM from Microfocus? same thing as elasticsearch and splunk integration.

---

## [SSL communication issue for Elastic search and logstash](https://discuss.elastic.co/t/ssl-communication-issue-for-elastic-search-and-logstash/326644)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 5:08am UTC](https://discuss.elastic.co/t/ssl-communication-issue-for-elastic-search-and-logstash/326644 "2023-02-28T05:08:31Z")

</div>

Log stash not able comm with Elastic search pls find the below logs for Elasticsearch and Logstash Elastic search: dress=/10.244.0.53:9200, remoteAddress=/10.224.0.5:48848}", "ecs.version": "1.2.0","service.name":"ES\_E…

---

## [Apply new ILM to managed index template FAILED](https://discuss.elastic.co/t/apply-new-ilm-to-managed-index-template-failed/325789)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 7\
**Last updated:** [February 28, 2023, 2:02am UTC](https://discuss.elastic.co/t/apply-new-ilm-to-managed-index-template-failed/325789 "2023-02-28T02:02:45Z")

</div>

I have a time series data stream, it has a managed index template and it was configured to "logs ILM" by default. I want to use another ILM and I changed the index template configure by "Edit" in Index Management and ad…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[log-\*\*-au-uat-buyer-server\] does not point to index \[log-\*\*-au-uat-buyer-server-2022.11\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-log-au-uat-buyer-server-does-not-point-to-index-log-au-uat-buyer-server-2022-11/326636)

<div class="topic-metadata">

**Author:** [@deepthi.manam](https://discuss.elastic.co/u/deepthi.manam)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 12:05am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-log-au-uat-buyer-server-does-not-point-to-index-log-au-uat-buyer-server-2022-11/326636 "2023-02-28T00:05:46Z")

</div>

Hi there, I'm getting this exception on some of my indices "illegal\_argument\_exception: index.lifecycle.rollover\_alias \[log--au-uat-buyer-server\] does not point to index \[log--au-uat-buyer-server-2022.11\]. Can you please…

---

## [Is there any problem that set ES heap size to 64G?](https://discuss.elastic.co/t/is-there-any-problem-that-set-es-heap-size-to-64g/326546)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 10:46pm UTC](https://discuss.elastic.co/t/is-there-any-problem-that-set-es-heap-size-to-64g/326546 "2023-02-27T22:46:26Z")

</div>

My machine has 512G memory, and i only need 2 ES nodes( 2 shards is enough for my index). So, is there any problem that set ES heap size to 64G or more bigger?

---

## [Configuration to maximize resoration performance](https://discuss.elastic.co/t/configuration-to-maximize-resoration-performance/326610)

<div class="topic-metadata">

**Author:** [@kronx12](https://discuss.elastic.co/u/kronx12)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 3:17pm UTC](https://discuss.elastic.co/t/configuration-to-maximize-resoration-performance/326610 "2023-02-27T15:17:22Z")

</div>

Hi everyone, I have actually setup elasticsearch on an ec2 instance, I currently have 16 cores, 32GB of ram and for the storage I use an gp3 EBS volume of a 1TB but the problem is the next: I need to restore a massive …

---

## [Slow searches after changing daily to weekly indexes](https://discuss.elastic.co/t/slow-searches-after-changing-daily-to-weekly-indexes/326563)

<div class="topic-metadata">

**Author:** [@filipe-m-claudio](https://discuss.elastic.co/u/filipe-m-claudio)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 10:22pm UTC](https://discuss.elastic.co/t/slow-searches-after-changing-daily-to-weekly-indexes/326563 "2023-02-27T22:22:38Z")

</div>

Currently the configuration is set to daily indices in a single-node, so we decided to move to weekly indices in order to reduce the number of shards in the cluster. Most of the time the client wants a 6 month history, …

---

## [Red Cluster Health - Unsure How to Fix](https://discuss.elastic.co/t/red-cluster-health-unsure-how-to-fix/326464)

<div class="topic-metadata">

**Author:** [@bcantrell](https://discuss.elastic.co/u/bcantrell)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 10:08pm UTC](https://discuss.elastic.co/t/red-cluster-health-unsure-how-to-fix/326464 "2023-02-27T22:08:28Z")

</div>

Hi all, I have been trying to figure out a problem where my Kibana is not able to keep connections alive with the Elasticsearch instance, and I think it is because of red cluster/index health. When Kibana is running, I …

---

## [Search as you type for documents with digits, unicode and special characters](https://discuss.elastic.co/t/search-as-you-type-for-documents-with-digits-unicode-and-special-characters/326005)

<div class="topic-metadata">

**Author:** [@zdebyman](https://discuss.elastic.co/u/zdebyman)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 9:46pm UTC](https://discuss.elastic.co/t/search-as-you-type-for-documents-with-digits-unicode-and-special-characters/326005 "2023-02-27T21:46:26Z")

</div>

Hi! Im very new to the ES and while learning and playing around with it, I got stuck with a problem that i'm not sure how to solve. REQUIREMENT I'm trying to build search-as-you-type autocomplete. I have a table with o…

---

## [Actual Size of a document - Mapper Size Plugin](https://discuss.elastic.co/t/actual-size-of-a-document-mapper-size-plugin/326631)

<div class="topic-metadata">

**Author:** [@prateek\_shekhar](https://discuss.elastic.co/u/prateek_shekhar)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:48pm UTC](https://discuss.elastic.co/t/actual-size-of-a-document-mapper-size-plugin/326631 "2023-02-27T20:48:37Z")

</div>

Hi All, Recently we have enabled the mapper-size plugin on our ES cluster. We have also added the index mapping \_size as per the recommendations at this link: Using the \_size field | Elasticsearch Plugins and Integratio…

---

## [Manual Alias vs ILM read performance](https://discuss.elastic.co/t/manual-alias-vs-ilm-read-performance/326627)

<div class="topic-metadata">

**Author:** [@Chirag\_Poddar](https://discuss.elastic.co/u/Chirag_Poddar)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 8:31pm UTC](https://discuss.elastic.co/t/manual-alias-vs-ilm-read-performance/326627 "2023-02-27T20:31:06Z")

</div>

I want to know about read performance between the following 2 Creating monthly indices on my own and pointing them to an alias Creating monthly indices using ILM Will they have any difference in search performance for…

---

## [Using ILM for huge size of indexes](https://discuss.elastic.co/t/using-ilm-for-huge-size-of-indexes/326496)

<div class="topic-metadata">

**Author:** [@Chirag\_Poddar](https://discuss.elastic.co/u/Chirag_Poddar)\
**Replies:** 16\
**Last updated:** [February 27, 2023, 8:11pm UTC](https://discuss.elastic.co/t/using-ilm-for-huge-size-of-indexes/326496 "2023-02-27T20:11:22Z")

</div>

Use case: We have a few indexes which have huge amounts of data and they are growing. We need to figure out a way to optimize the search time. We are thinking of using ILM to manage the indexes. But there are a few roadb…

---

## [Synonym graph token filter backed by Elastic index](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 4:35pm UTC](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616 "2023-02-27T16:35:20Z")

</div>

Hi, I want to use the synonym graph token filter but ideally have the data stored in an Elasticsearch index so that it can be easily updated and modified. My understanding of the code is that it reads the data from a f…

---

## [Start elasticsearch that used to be in a cluster as a single-node or in a different cluster](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 4:22pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568 "2023-02-27T16:22:24Z")

</div>

Hey Everyone, Due to some stuff that happened, I have an Elasticsearch node with a lot of data, that isn't up to date with the cluster. What I need to do is somehow start this node as a separate cluster, without it nee…

---

## [Elastic enrich data based on two matching fields](https://discuss.elastic.co/t/elastic-enrich-data-based-on-two-matching-fields/325561)

<div class="topic-metadata">

**Author:** [@maggo](https://discuss.elastic.co/u/maggo)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 2:35pm UTC](https://discuss.elastic.co/t/elastic-enrich-data-based-on-two-matching-fields/325561 "2023-02-27T14:35:42Z")

</div>

Hello guys, i'm pretty new to ELK and want to implement a vulnerability enrichment for incoming osquery data. I have one index with vulnerability data with fields like: "affected\_product": "chrome" "affected\_version":…

---

## [Trusting remote clusters' CA](https://discuss.elastic.co/t/trusting-remote-clusters-ca/326465)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 2:33pm UTC](https://discuss.elastic.co/t/trusting-remote-clusters-ca/326465 "2023-02-27T14:33:53Z")

</div>

Hi, I have two scenarios and would like a solution for both. I created a new cluster (8.6.X) with the self-generated certificates and enrolling new nodes. After that, I want to create a separate cluster, but I'd like …

---

## [Ingest issue during re-indexing/cloning?](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 2:17pm UTC](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466 "2023-02-27T14:17:29Z")

</div>

Hello ! I need to re-index multiple indices prior to an update of our stack. In order to test the reindexing process, I am cloning an index. However, the index needs to be read-only. My question is...what if data is in…

---

## [Elastic Search query](https://discuss.elastic.co/t/elastic-search-query/326430)

<div class="topic-metadata">

**Author:** [@ashish.akm](https://discuss.elastic.co/u/ashish.akm)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 1:39pm UTC](https://discuss.elastic.co/t/elastic-search-query/326430 "2023-02-27T13:39:06Z")

</div>

how to create one query with match sort by newer report date and martch\_phrase sort by newer report and combine both result

---

## [Only one of the data nodes has a significantly higher cpu usage than other data nodes](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589)

<div class="topic-metadata">

**Author:** [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 1:07pm UTC](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589 "2023-02-27T13:07:23Z")

</div>

ES version: elasticsearch-5.6.3-1.noarch OS version: CentOS Linux release 7.6.1810 (Core) Linux version 3.10.0-1160.31.1.el7.x86\_64 (mockbuild@kbuilder.bsys.centos.org) (gcc version 4.8.5 20150623 (Red Hat 4.8.5-44) (…

---

## [Two Node Cluster Failover did not work](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583)

<div class="topic-metadata">

**Author:** [@sven\_begis](https://discuss.elastic.co/u/sven_begis)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 12:32pm UTC](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583 "2023-02-27T12:32:26Z")

</div>

Two Node Cluster Failover did not work Hello, I'm trying to set up a two node cluster. VST-ELA01 -- RAM = 8 GB -- CPU = 8 -- HD = 100 GB -- OS = Ubuntu 22.04 LTS VST-ELA02 -- RAM = 8 GB -- CPU = 8 -- HD = 1…

---

## [Get sum of record count for inner bucket key in two level term aggregation](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575)

<div class="topic-metadata">

**Author:** [@Baekjun-Kim](https://discuss.elastic.co/u/Baekjun-Kim)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:01pm UTC](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575 "2023-02-27T12:01:45Z")

</div>

I have records with two keyword type field user\_id: String that identifies individual user, result: String such as "success", "failure" or "pending" etc. These are what I want to do: Get record count for each result…

---

## [Compare two indexes based on more than two fields](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464)

<div class="topic-metadata">

**Author:** [@Prashant\_Pandey1](https://discuss.elastic.co/u/Prashant_Pandey1)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 11:56am UTC](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464 "2023-02-27T11:56:24Z")

</div>

I have two Indexes. I want to get the list of matched and unmatched data based on field(s). I had tried to use Preview transform Api , but it's showing data only up to 100 records. Please let me know ,is there any oth…

---

## [Internal index process merging records into arrays of objects based on a parent common key](https://discuss.elastic.co/t/internal-index-process-merging-records-into-arrays-of-objects-based-on-a-parent-common-key/326451)

<div class="topic-metadata">

**Author:** [@MartinGarcia](https://discuss.elastic.co/u/MartinGarcia)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 10:59am UTC](https://discuss.elastic.co/t/internal-index-process-merging-records-into-arrays-of-objects-based-on-a-parent-common-key/326451 "2023-02-27T10:59:41Z")

</div>

Hi, I have a doubt about a feature. I'm trying to run an internal process in Elastic where I create superseed objects based on an index that contains more flat and granular objects. For example: The source index contai…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=292)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=294)
