# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=295

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 296

---

## [Unable to change "elastic" user password](https://discuss.elastic.co/t/unable-to-change-elastic-user-password/326364)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 4\
**Last updated:** [February 24, 2023, 5:18am UTC](https://discuss.elastic.co/t/unable-to-change-elastic-user-password/326364 "2023-02-24T05:18:51Z")

</div>

Team, Can you please help to change \*\*elastic\*\* user password. root@elk:/usr/share/elasticsearch/bin# ls -lrt total 20812 -rwxr-xr-x 1 root root 21220982 Jan 13 2021 elasticsearch-sql-cli-7.10.2.jar -rwxr-xr-x 1 root …

---

## [Get the matched and unmatched result based on fields inside an index](https://discuss.elastic.co/t/get-the-matched-and-unmatched-result-based-on-fields-inside-an-index/326397)

<div class="topic-metadata">

**Author:** [@Prashant\_Pandey1](https://discuss.elastic.co/u/Prashant_Pandey1)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 4:06am UTC](https://discuss.elastic.co/t/get-the-matched-and-unmatched-result-based-on-fields-inside-an-index/326397 "2023-02-24T04:06:21Z")

</div>

Hi All , I'm new to Elasticsearch, please can someone help on this I want to matched and unmatched data based on fields from index. Sample of Data Schema of index : { "\_index": "comparebyid", "\_id": "MPGsra40AGzOIw1…

---

## [Autocomplete - Completion Suggester Or Search as you type filed type](https://discuss.elastic.co/t/autocomplete-completion-suggester-or-search-as-you-type-filed-type/326393)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 3:18am UTC](https://discuss.elastic.co/t/autocomplete-completion-suggester-or-search-as-you-type-filed-type/326393 "2023-02-24T03:18:02Z")

</div>

We need to create an autocomplete functionality so that as the user is typing suggestions are shown from the backend elasticsearch indices. Which is the better option for indiex that has 10 million plus records and the …

---

## [Get request taking much time in elasticsearch](https://discuss.elastic.co/t/get-request-taking-much-time-in-elasticsearch/326391)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 2:12am UTC](https://discuss.elastic.co/t/get-request-taking-much-time-in-elasticsearch/326391 "2023-02-24T02:12:59Z")

</div>

Hi Team, For elasticsearch using transport client 9kb record it takes to 3 seconds. sometimes it will take the 100 ms.

---

## [Storing only pointer to source field?](https://discuss.elastic.co/t/storing-only-pointer-to-source-field/326368)

<div class="topic-metadata">

**Author:** [@XD\_Captain](https://discuss.elastic.co/u/XD_Captain)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 12:21am UTC](https://discuss.elastic.co/t/storing-only-pointer-to-source-field/326368 "2023-02-24T00:21:19Z")

</div>

Hi, I'm new to Elasticsearch and am wondering about this: is there a handy way to not store the \_source field (original json file), but instead store just a pointer (ID) to the source field items? For instance if the …

---

## [Error running Repository Analysis API on AWS S3](https://discuss.elastic.co/t/error-running-repository-analysis-api-on-aws-s3/326381)

<div class="topic-metadata">

**Author:** [@ben.clifford](https://discuss.elastic.co/u/ben.clifford)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 11:24pm UTC](https://discuss.elastic.co/t/error-running-repository-analysis-api-on-aws-s3/326381 "2023-02-23T23:24:36Z")

</div>

I am running a 4 node cluster in AWS trying to use the Repository Analysis API to validate S3 compatible storage. The cluster is healthy and well provisioned, and doing nothing but running this API test. After continuous…

---

## [Upload of multiple CSV files into same index](https://discuss.elastic.co/t/upload-of-multiple-csv-files-into-same-index/326156)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 10:07pm UTC](https://discuss.elastic.co/t/upload-of-multiple-csv-files-into-same-index/326156 "2023-02-23T22:07:07Z")

</div>

Hi, Please advise me on the below. I want to upload CSV file into the same index name on daily basis and need to create Kibana dashboard. Is it possible for me to upload the CSV file directly into Elasticsearch autom…

---

## [Feature Request: minimum\_should\_match support for Terms Set query](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374)

<div class="topic-metadata">

**Author:** [@kulinsj](https://discuss.elastic.co/u/kulinsj)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 9:32pm UTC](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374 "2023-02-23T21:32:36Z")

</div>

The Terms Set Query lets you match documents that have some minimum number of matches to a given array of input search terms. The minimum number of matches however can only be specified by referencing another field on th…

---

## [Elasticsearch 8.6 - enrich processor is not behaving as expected](https://discuss.elastic.co/t/elasticsearch-8-6-enrich-processor-is-not-behaving-as-expected/326371)

<div class="topic-metadata">

**Author:** [@BlueNoteBird](https://discuss.elastic.co/u/BlueNoteBird)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 7:44pm UTC](https://discuss.elastic.co/t/elasticsearch-8-6-enrich-processor-is-not-behaving-as-expected/326371 "2023-02-23T19:44:23Z")

</div>

Hello, I am new to Elasticsearch and I am probably missing something. It seems that enrich processor is not using custom normalizer. // My custom Normalizer PUT /\_component\_template/comptpl\_norm\_letters { "template"…

---

## [How to Set Default Integer Value in Search Template](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279)

<div class="topic-metadata">

**Author:** [@krmathieu](https://discuss.elastic.co/u/krmathieu)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:58pm UTC](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279 "2023-02-23T18:58:53Z")

</div>

I am getting a number\_format\_exception when trying to run a search against a search template containing this snippet of code. It defines a CityID variable and tries to set a wildcard default and the CityID field is defin…

---

## [Elasticsearch rolling restart without indexing down time](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358 "2023-02-23T18:50:06Z")

</div>

We run an elasticsearch cluster 7.17, with 3 data nodes and 3 master nodes. The use case is for monitoring with elasticAPM. We follow official documentation at Full cluster restart upgrade | Elasticsearch Guide \[7.17\] |…

---

## [Reindex w/ a regex](https://discuss.elastic.co/t/reindex-w-a-regex/326348)

<div class="topic-metadata">

**Author:** [@vfeydel](https://discuss.elastic.co/u/vfeydel)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 5:44pm UTC](https://discuss.elastic.co/t/reindex-w-a-regex/326348 "2023-02-23T17:44:51Z")

</div>

I have lot of indices with same prefix. In those indices, I need to keep only document that have for example the field "abc" with 7 numbers only. My indices are already index in Elastic. It is possible , with a query or…

---

## [How to grab the trace for bulkprocessor](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:19pm UTC](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149 "2023-02-23T14:19:41Z")

</div>

Hi I need to trace same stack for bulkprocessor for tracing the cause of the error on elastic, why does the application get a timeout ERROR e.i.u.r.i.BulkIndexingProcessorConfig - - Failed to execute bulk request. Reas…

---

## [Unable to search data containing math expression](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287)

<div class="topic-metadata">

**Author:** [@Hassan\_zaib\_Hayat](https://discuss.elastic.co/u/Hassan_zaib_Hayat)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287 "2023-02-23T13:39:14Z")

</div>

Hi ES folks, Hope everyone is doing fine. I am facing a problem when querying data containing mathematical expressions. For example I have following data indexed in my ES what is 3+4 what is 3-4 what is 3\*4 what is 3/…

---

## [Elastic Cloud SAML SSO in 'trial' environment](https://discuss.elastic.co/t/elastic-cloud-saml-sso-in-trial-environment/325509)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 14\
**Last updated:** [February 23, 2023, 1:07pm UTC](https://discuss.elastic.co/t/elastic-cloud-saml-sso-in-trial-environment/325509 "2023-02-23T13:07:40Z")

</div>

Hello, I'm looking for some insight with configuring SAML SSO in a trial Elastic Cloud environment. The deployment is on v8.6.1. Using Elasticsearch, Kibana, Enterprise Search. The idP provider is SAML 2.0. I have be…

---

## [Can we give more than 32GB Memory to dedicated Machine learning Node?](https://discuss.elastic.co/t/can-we-give-more-than-32gb-memory-to-dedicated-machine-learning-node/325159)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 12:05pm UTC](https://discuss.elastic.co/t/can-we-give-more-than-32gb-memory-to-dedicated-machine-learning-node/325159 "2023-02-23T12:05:39Z")

</div>

As per the documentation it is recommended by Elasticsearch Team that every Elasticsearch node should have the memory slightly less than 32GB. Now My question is that does this apply to a dedicated Machine learning Node …

---

## [ECE Deployment issue on Centos 8](https://discuss.elastic.co/t/ece-deployment-issue-on-centos-8/326304)

<div class="topic-metadata">

**Author:** [@opensourcengineer](https://discuss.elastic.co/u/opensourcengineer)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 10:37am UTC](https://discuss.elastic.co/t/ece-deployment-issue-on-centos-8/326304 "2023-02-23T10:37:17Z")

</div>

I am trying to install the ECE using the ansible deployment git repo for the medium-size installation on centos 8 (https://github.com/elastic/ansible-elastic-cloud-enterprisehttps://github.com/elastic/ansible-elastic-clo…

---

## [GEOGRAPHY Elastic.Clients.Elasticsearch v8.x C# .NET](https://discuss.elastic.co/t/geography-elastic-clients-elasticsearch-v8-x-c-net/326282)

<div class="topic-metadata">

**Author:** [@IceF1reX](https://discuss.elastic.co/u/IceF1reX)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 9:49am UTC](https://discuss.elastic.co/t/geography-elastic-clients-elasticsearch-v8-x-c-net/326282 "2023-02-23T09:49:14Z")

</div>

How to use geo in Elastic.Clients.Elasticsearch v8.x C# .NET??

---

## [Replacing an Elasticsearch node](https://discuss.elastic.co/t/replacing-an-elasticsearch-node/326203)

<div class="topic-metadata">

**Author:** [@smutel](https://discuss.elastic.co/u/smutel)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 9:22am UTC](https://discuss.elastic.co/t/replacing-an-elasticsearch-node/326203 "2023-02-23T09:22:29Z")

</div>

Hello, I have a cluster with 5 nodes (3 master nodes and 2 data nodes) hosted on vms. I am using Elasticsearch version 7.17.8. I need to replace these VMs (to destroy them and to create new ones). I replaced the seco…

---

## [About fix log4j2 vulnerabilities, use the parameter -Dlog4j2.formatMsgNoLookups=true](https://discuss.elastic.co/t/about-fix-log4j2-vulnerabilities-use-the-parameter-dlog4j2-formatmsgnolookups-true/326271)

<div class="topic-metadata">

**Author:** [@qiuxb](https://discuss.elastic.co/u/qiuxb)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 7:17am UTC](https://discuss.elastic.co/t/about-fix-log4j2-vulnerabilities-use-the-parameter-dlog4j2-formatmsgnolookups-true/326271 "2023-02-23T07:17:28Z")

</div>

Currently, there are multiple ES versions in our online environment. To fix the logj2 vulnerability, we plan to add the parameter -Dlog4j2.formatMsgNoLookups=true to jvm.option. Do the following versions support this met…

---

## [Failed to obtain node locks, tried \[/usr/share/elasticsearch/data\]; maybe these locations are not writable or multiple nodes were started on the same data path?](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started-on-the-same-data-path/326264)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 7\
**Last updated:** [February 23, 2023, 7:15am UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started-on-the-same-data-path/326264 "2023-02-23T07:15:49Z")

</div>

I use k8s built a ela cluster, I in the yaml document data directory: / usr/share/elasticsearch/data local hostpath path is: / data/elasticsearch/data This is directory permission information: drwxr-xr-x. 3 1000 100…

---

## [Elasticsearch snapshot retention behavior](https://discuss.elastic.co/t/elasticsearch-snapshot-retention-behavior/326262)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 7:08am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-retention-behavior/326262 "2023-02-23T07:08:14Z")

</div>

Lets say we create daily indices with ILM policy that delete data after 1 year. And lets say we have SLM that have retention period of 30 days. So, eventually what will be the content of snapshot after 1 year. Is it one…

---

## [NativeSearchQuery exact match sort problems](https://discuss.elastic.co/t/nativesearchquery-exact-match-sort-problems/326256)

<div class="topic-metadata">

**Author:** [@iles983](https://discuss.elastic.co/u/iles983)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 4:46am UTC](https://discuss.elastic.co/t/nativesearchquery-exact-match-sort-problems/326256 "2023-02-23T04:46:57Z")

</div>

Hello everyone. I'm doing search using Java and elasticsearch 6.2.2 I'm having some troubles with sorting The way i need it to be: all exact match sorted by price, with fuzziness 1 sorted by price and then with fuzzine…

---

## [io.netty.handler.ssl.SslHandshakeTimeoutException: handshake timed out after 10000ms](https://discuss.elastic.co/t/io-netty-handler-ssl-sslhandshaketimeoutexception-handshake-timed-out-after-10000ms/326117)

<div class="topic-metadata">

**Author:** [@Raghulvishal](https://discuss.elastic.co/u/Raghulvishal)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 3:25am UTC](https://discuss.elastic.co/t/io-netty-handler-ssl-sslhandshaketimeoutexception-handshake-timed-out-after-10000ms/326117 "2023-02-23T03:25:11Z")

</div>

Hi Team, We are getting this below exception daily. so, can you please give solution for this exception. we are using Elasticsearch 7.3.2, java version 1.8.0\_131 and tomcat version 9. 2023-02-19 18:55:20.683 \[elastic…

---

## [Elasticsearch getting killed by the oom killer because an out of memory](https://discuss.elastic.co/t/elasticsearch-getting-killed-by-the-oom-killer-because-an-out-of-memory/326218)

<div class="topic-metadata">

**Author:** [@noreddinelam](https://discuss.elastic.co/u/noreddinelam)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 3:03am UTC](https://discuss.elastic.co/t/elasticsearch-getting-killed-by-the-oom-killer-because-an-out-of-memory/326218 "2023-02-23T03:03:13Z")

</div>

Good morning, We are facing the problem "Out Of Memory" with elasticsearch. Our configuration : We are running on ec2 instance (tg4.micro) with 1gb ram and 1cpu. I know that perhaps it is not sufficient but i want to …

---

## [Can you query AD with Elastic to see Last Logon time?](https://discuss.elastic.co/t/can-you-query-ad-with-elastic-to-see-last-logon-time/326230)

<div class="topic-metadata">

**Author:** [@Mahigs](https://discuss.elastic.co/u/Mahigs)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:58pm UTC](https://discuss.elastic.co/t/can-you-query-ad-with-elastic-to-see-last-logon-time/326230 "2023-02-22T21:58:30Z")

</div>

Relatively new to Elastic and all that it can do. Our team is trying to query Active Directory with Elastic so that we can view user's last logon time. We're trying to satisfy DoD requirements relating to accounts needin…

---

## [String Replace in Painless](https://discuss.elastic.co/t/string-replace-in-painless/326231)

<div class="topic-metadata">

**Author:** [@John\_Warner](https://discuss.elastic.co/u/John_Warner)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 9:53pm UTC](https://discuss.elastic.co/t/string-replace-in-painless/326231 "2023-02-22T21:53:46Z")

</div>

I tried the following replace, and it did not work. Seems to be returning the empty string. Is this the correct way to do a string replace? Note that what I found on this thread does not seem to work for me. Replace stri…

---

## [ES custom ILM policy with cumulative index or disk size](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135 "2023-02-22T21:25:47Z")

</div>

We're trying to implement an ILM policy for moving indices between hot -\> warm -\> cold in out on-premise server. What we have is this: SSD for storing hot indices HDD for storing warm indices \> 7d NAS for storing cold…

---

## [Load different formats of data under the same index name](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:16pm UTC](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131 "2023-02-22T21:16:08Z")

</div>

Hello All, Is it possible to load different formats of data (from different sources) under the same index name in Elasticsearch? If yes, how can we do and what are the pros and cons. Please advise

---

## [Cannot use ElasticSearch IP Address as Node URI (does not trust server certificate)](https://discuss.elastic.co/t/cannot-use-elasticsearch-ip-address-as-node-uri-does-not-trust-server-certificate/326155)

<div class="topic-metadata">

**Author:** [@lemesios10](https://discuss.elastic.co/u/lemesios10)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 10:16am UTC](https://discuss.elastic.co/t/cannot-use-elasticsearch-ip-address-as-node-uri-does-not-trust-server-certificate/326155 "2023-02-22T10:16:18Z")

</div>

Hello all. This is my first post here, so please bear with me! Current setup: -Elasticsearch & Kibana hosted on an ubuntu server with docker (therefore the Elastics API URI is something like xxx.xxx.xxx.xxx:9200 for El…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=294)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=296)
