# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=297

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 298

---

## [How to collect log of NVR Hikvision (all camera's log) to Elastic?](https://discuss.elastic.co/t/how-to-collect-log-of-nvr-hikvision-all-cameras-log-to-elastic/326018)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 6:28am UTC](https://discuss.elastic.co/t/how-to-collect-log-of-nvr-hikvision-all-cameras-log-to-elastic/326018 "2023-02-21T06:28:18Z")

</div>

Hello everyone, I want to collect all logs (all type logs) of the cameras to my SIEM system. I have a NVR and it have function "Logs Server Configuration" but it always failed. ( UDP port use to collect logs on the linux…

---

## [Esrally benchmark takes longer time to run while the report service time doesn't change](https://discuss.elastic.co/t/esrally-benchmark-takes-longer-time-to-run-while-the-report-service-time-doesnt-change/324597)

<div class="topic-metadata">

**Author:** [@fatcloud](https://discuss.elastic.co/u/fatcloud)\
**Replies:** 9\
**Last updated:** [February 21, 2023, 5:34am UTC](https://discuss.elastic.co/t/esrally-benchmark-takes-longer-time-to-run-while-the-report-service-time-doesnt-change/324597 "2023-02-21T05:34:52Z")

</div>

Hi, I'm trying to run some test to see how the number of index affect the elasticsearch cluster performance. I tested from 1k indices to 8k indices, and ran some random requests against those indices. One weird thing …

---

## [Ingesting Delinea Audit/event Logs into Elasticsearch](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870)

<div class="topic-metadata">

**Author:** [@tthiry](https://discuss.elastic.co/u/tthiry)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 1:58am UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870 "2023-02-21T01:58:11Z")

</div>

Hello, I am wondering if anyone has tried ingesting Delinea Secret Server logs into Elasticsearch. I'm not quite sure where to start. We are using the cloud version of both Elastic and Delinea. Any helpful hints would …

---

## [High Vulnerabilities found in Elasticsearch docker image v7.17.9](https://discuss.elastic.co/t/high-vulnerabilities-found-in-elasticsearch-docker-image-v7-17-9/325976)

<div class="topic-metadata">

**Author:** [@hexer338](https://discuss.elastic.co/u/hexer338)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:58pm UTC](https://discuss.elastic.co/t/high-vulnerabilities-found-in-elasticsearch-docker-image-v7-17-9/325976 "2023-02-20T20:58:46Z")

</div>

Hi Elastic Team, We used aquasec's trivy scan(Trivy) to do vuln. scan on elasticsearch docker image: docker.elastic.co/elasticsearch/elasticsearch:7.17.9 We found 4 HIGH severity vulnerabilities below: CVE-2023-0286 …

---

## [Elasticsearch data nodes - disk usage optimisation](https://discuss.elastic.co/t/elasticsearch-data-nodes-disk-usage-optimisation/325544)

<div class="topic-metadata">

**Author:** [@chethan\_m](https://discuss.elastic.co/u/chethan_m)\
**Replies:** 5\
**Last updated:** [February 20, 2023, 5:36pm UTC](https://discuss.elastic.co/t/elasticsearch-data-nodes-disk-usage-optimisation/325544 "2023-02-20T17:36:15Z")

</div>

I have an elasticsearch deployed on kubenetes/aws platform. I'm observing that Disk Free Space is not equal in the data nodes. I have 4 data nodes out of which, Two data nodes have around 1 TB free disk space One …

---

## [Aliases API : error deleting index](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265)

<div class="topic-metadata">

**Author:** [@quentin.renoux](https://discuss.elastic.co/u/quentin.renoux)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 12:36pm UTC](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265 "2023-02-20T12:36:06Z")

</div>

Hi everyone, TL;DR : the \_aliases API throw error trying to remove index saying it doesn't exist but it does. I'm using the aliases API to swap two indices behind an alias in a single atomic operation. I'm following th…

---

## [Elasticsearch creates empty directories in /tmp, can I delete these empty directories](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887)

<div class="topic-metadata">

**Author:** [@eranga\_bandara](https://discuss.elastic.co/u/eranga_bandara)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887 "2023-02-20T08:59:47Z")

</div>

Elasticsearch creates directories inside /tmp. These directories used to execute native code by jna and libffi. Most of the time these directories are empty and have the name like elasticsearch.KNoHBn19. more info here. …

---

## [Two data folder present](https://discuss.elastic.co/t/two-data-folder-present/325834)

<div class="topic-metadata">

**Author:** [@dev\_sab](https://discuss.elastic.co/u/dev_sab)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/two-data-folder-present/325834 "2023-02-20T08:59:00Z")

</div>

Hello All, I am having the scenario two data folder present. I have accidently changed the path.data in elasticsearch.yml file. So, Two data folder present, one with old data and another with new data. I need to merge …

---

## [How to find a missing word in elastic search query](https://discuss.elastic.co/t/how-to-find-a-missing-word-in-elastic-search-query/325351)

<div class="topic-metadata">

**Author:** [@Jude\_Jerome](https://discuss.elastic.co/u/Jude_Jerome)\
**Replies:** 7\
**Last updated:** [February 20, 2023, 7:06am UTC](https://discuss.elastic.co/t/how-to-find-a-missing-word-in-elastic-search-query/325351 "2023-02-20T07:06:39Z")

</div>

Hello Team, I have a 100 + applications which sending logs daily. I want to filter out the application which does not have a specific word. For example if a application log does not have success keyword then i need to f…

---

## [Elasticsearch error all shards failed on single node](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812)

<div class="topic-metadata">

**Author:** [@yc99](https://discuss.elastic.co/u/yc99)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 3:19am UTC](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812 "2023-02-20T03:19:13Z")

</div>

Caused by: org.elasticsearch.action.NoShardAvailableActionException: \[ip-13-35-23-200.ap-1.compute.internal\]\[13.35.23.200:9300\]\[indices:data/read/search\[phase/query\]\] \[2023-02-17T08:14:15,934\]\[WARN \]\[r.suppressed …

---

## [Beginner’s Crash Course to Elastic Stack - Part 4: Aggregations | Issues with data](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 3:13am UTC](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902 "2023-02-20T03:13:24Z")

</div>

After importing the data.csv file and running the STEP 1: Create a new index(ecommerce\_data) with the following mapping., I am getting an error: { "error": { "root\_cause": \[ { "type": "resource\_already\_exists\_except…

---

## [Watcher search on multiple terms and action depending on conditional result](https://discuss.elastic.co/t/watcher-search-on-multiple-terms-and-action-depending-on-conditional-result/325868)

<div class="topic-metadata">

**Author:** [@mape](https://discuss.elastic.co/u/mape)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 9:11pm UTC](https://discuss.elastic.co/t/watcher-search-on-multiple-terms-and-action-depending-on-conditional-result/325868 "2023-02-17T21:11:03Z")

</div>

Hi. What I am trying to achieve is: Use a search query to find all events where field status code = 400 OR 401 OR 403, AND field servicegroup is one of 6 options AND if the count of events is \> 300 if it occurs on any …

---

## [Elasticsearch data node out of memory](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866)

<div class="topic-metadata">

**Author:** [@sssamant](https://discuss.elastic.co/u/sssamant)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 2:26am UTC](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866 "2023-02-20T02:26:02Z")

</div>

Hello everyone, We are having out of memory issue for the elasticsearch data nodes? Can you please help me out to find the issue. Here is log from elasticsearch cluster. \[2023-02-17 10:02:47,551\]\[WARN \]\[netty.channel.…

---

## [Parsing Exception when using Bucket\_sort with org.elasticsearch.test.framework:8.6.2](https://discuss.elastic.co/t/parsing-exception-when-using-bucket-sort-with-org-elasticsearch-test-framework-8-6-2/325893)

<div class="topic-metadata">

**Author:** [@Neoministein](https://discuss.elastic.co/u/Neoministein)\
**Replies:** 0\
**Last updated:** [February 18, 2023, 5:00pm UTC](https://discuss.elastic.co/t/parsing-exception-when-using-bucket-sort-with-org-elasticsearch-test-framework-8-6-2/325893 "2023-02-18T17:00:39Z")

</div>

I am using org.elasticsearch.test.framework for Integration testing parts of my codebase. I am currently using the Elasticsearch Java API Client 8.7.0-SNAPSHOT to use the new BulkIngester. I've therefore bumped the ver…

---

## [Is there a recommendation on the number of Indices that can be created using ILM](https://discuss.elastic.co/t/is-there-a-recommendation-on-the-number-of-indices-that-can-be-created-using-ilm/325716)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 9\
**Last updated:** [February 20, 2023, 2:13am UTC](https://discuss.elastic.co/t/is-there-a-recommendation-on-the-number-of-indices-that-can-be-created-using-ilm/325716 "2023-02-20T02:13:19Z")

</div>

Hi Team, I am quite new to Elasticsearch. We are migrating Data from a Licensed Product to Elastic. But the amount of data is huge, its about 100 TB/month. And we have to index data for 10 years. So effectively 1 Pet…

---

## [Does Elastic Cloud service support SDK to access its APIs](https://discuss.elastic.co/t/does-elastic-cloud-service-support-sdk-to-access-its-apis/325719)

<div class="topic-metadata">

**Author:** [@vaibhav\_b](https://discuss.elastic.co/u/vaibhav_b)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 1:15am UTC](https://discuss.elastic.co/t/does-elastic-cloud-service-support-sdk-to-access-its-apis/325719 "2023-02-20T01:15:49Z")

</div>

I have question related to SDK support to provision Elasticsearch service on elastic cloud. I am going through the documentation where I am seeing, "how can I consume the API", here I am not seeing anything mentioned r…

---

## [Easy way to monitor ElasticSearch](https://discuss.elastic.co/t/easy-way-to-monitor-elasticsearch/324404)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 1:08am UTC](https://discuss.elastic.co/t/easy-way-to-monitor-elasticsearch/324404 "2023-02-20T01:08:15Z")

</div>

I want a easy way to monitor Elasticsearch. What I found is Metricbeat. But it seems to be very extensive. For my purpose it is enough to see green, yellow, red and it would be nice to have if the administrator gets a …

---

## [Unassigned Shards - issue](https://discuss.elastic.co/t/unassigned-shards-issue/325692)

<div class="topic-metadata">

**Author:** [@azuramazda](https://discuss.elastic.co/u/azuramazda)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 9:00pm UTC](https://discuss.elastic.co/t/unassigned-shards-issue/325692 "2023-02-19T21:00:59Z")

</div>

I am facing an issue with ES where it shows 174 shards are unassigned. and allocate\_explanation is :"cannot allocate because all found copies of the shard are there stale or corrupt". This issue is arising since yesterd…

---

## [Systemctl reload elasticsearch.service or systemctl restart elasticsearch.service](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703)

<div class="topic-metadata">

**Author:** [@firdaussaad](https://discuss.elastic.co/u/firdaussaad)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:59pm UTC](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703 "2023-02-19T20:59:33Z")

</div>

Hi all, I am currently working on a bash script. Whenever i make changes to elasticsearch.yml file, should i perform systemctl reload elascticsearch.service or systemctl restart elasticsearch.service? Any difference be…

---

## [Is "http://localhost:9200/\_all/\_stats/\_all" an expensive call?](https://discuss.elastic.co/t/is-http-localhost-9200-all-stats-all-an-expensive-call/325907)

<div class="topic-metadata">

**Author:** [@junhuangli](https://discuss.elastic.co/u/junhuangli)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 8:43pm UTC](https://discuss.elastic.co/t/is-http-localhost-9200-all-stats-all-an-expensive-call/325907 "2023-02-19T20:43:02Z")

</div>

We are using open-telemetry to monitor the es cluster. And I found the open-telemetry receiver is sending request to "http://localhost:9200/\_all/\_stats/\_all" to pull the metrics. One issue I notice is if the receiver is …

---

## ["Elasticsearch Unreachable: \[http://localhost:9200/\]\[Manticore::ClientProtocolException\] localhost:9200 failed to respond"}](https://discuss.elastic.co/t/elasticsearch-unreachable-http-localhost-9200-manticore-clientprotocolexception-localhost-9200-failed-to-respond/325897)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 10\
**Last updated:** [February 19, 2023, 7:20pm UTC](https://discuss.elastic.co/t/elasticsearch-unreachable-http-localhost-9200-manticore-clientprotocolexception-localhost-9200-failed-to-respond/325897 "2023-02-19T19:20:51Z")

</div>

Hi. I'm trying to follow the "Parsing Logs with Logstash" (Tutorial), and I am having trouble when I try to connect my pipeline to Elasticsearch. My first-pipeline.conf file looks like this: input { beats { …

---

## [Closing node](https://discuss.elastic.co/t/closing-node/325913)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 7\
**Last updated:** [February 19, 2023, 3:53pm UTC](https://discuss.elastic.co/t/closing-node/325913 "2023-02-19T15:53:31Z")

</div>

Hi, I want to close node, and want elastic to move his to different node. What is the procedure for closing node? How it can be done automatically? Thanks.

---

## [Very slow on-prem Elasticsearch 8.6.0 cluster](https://discuss.elastic.co/t/very-slow-on-prem-elasticsearch-8-6-0-cluster/325307)

<div class="topic-metadata">

**Author:** [@tibbers38](https://discuss.elastic.co/u/tibbers38)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 3:29pm UTC](https://discuss.elastic.co/t/very-slow-on-prem-elasticsearch-8-6-0-cluster/325307 "2023-02-19T15:29:37Z")

</div>

Hi everyone, I'm having a very slow ES cluster despite I'm not making any change with data volume or number of shards. Our ES cluster is version 8.6.0 with these node: es01: "data\_content","data\_hot","ingest","master…

---

## [Elasticsearch production deployment to docker keeps exiting without any indication to why](https://discuss.elastic.co/t/elasticsearch-production-deployment-to-docker-keeps-exiting-without-any-indication-to-why/325916)

<div class="topic-metadata">

**Author:** [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 2:59pm UTC](https://discuss.elastic.co/t/elasticsearch-production-deployment-to-docker-keeps-exiting-without-any-indication-to-why/325916 "2023-02-19T14:59:48Z")

</div>

After tinkering with elasticsearch in development, I am now ready to deploy it to production on docker on my own server, so, I was reading what practices should be followed, this documentation: Install Elasticsearch with…

---

## [Beat-exporter sending the metrics of filebeat to prometheus even pod gets deleted](https://discuss.elastic.co/t/beat-exporter-sending-the-metrics-of-filebeat-to-prometheus-even-pod-gets-deleted/325914)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 2:10pm UTC](https://discuss.elastic.co/t/beat-exporter-sending-the-metrics-of-filebeat-to-prometheus-even-pod-gets-deleted/325914 "2023-02-19T14:10:56Z")

</div>

Hi Team, I am running filebeat as a deamonset in k8s also running beat-exporter as a side car container. one weird thing i am observing is after pod get's deleted \[ pod deleted almost 1 week ago \] still i am getting th…

---

## [Improve search performance beyond 2x](https://discuss.elastic.co/t/improve-search-performance-beyond-2x/325537)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 3\
**Last updated:** [February 19, 2023, 10:15am UTC](https://discuss.elastic.co/t/improve-search-performance-beyond-2x/325537 "2023-02-19T10:15:22Z")

</div>

Question on replica shard: Node1 P0 Node2 P1 Node3 R0 Node4 R1 So, overall search performance can get 2x as Primary and Replica shards will share the search load. But what is next if search load increases to 5 f…

---

## [ICU Tokenizer to keep tags and hashtags in token](https://discuss.elastic.co/t/icu-tokenizer-to-keep-tags-and-hashtags-in-token/325909)

<div class="topic-metadata">

**Author:** [@kaanebv](https://discuss.elastic.co/u/kaanebv)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 9:07am UTC](https://discuss.elastic.co/t/icu-tokenizer-to-keep-tags-and-hashtags-in-token/325909 "2023-02-19T09:07:56Z")

</div>

I'm using ICU tokenizer with a custom analyzer but it doesn't keep hashtag in token. I have tried word\_delimiter and icu\_normalizer but they didn't work. Is there any solution to this?

---

## [Restoring Dashboards](https://discuss.elastic.co/t/restoring-dashboards/325738)

<div class="topic-metadata">

**Author:** [@Faisaljodayn](https://discuss.elastic.co/u/Faisaljodayn)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 5:39am UTC](https://discuss.elastic.co/t/restoring-dashboards/325738 "2023-02-19T05:39:17Z")

</div>

Hi everyone, Today while we were working on dashboards. We deleted a model package by mistake and it affected all the dashboards. Basically, all the indices are present but with no data. All the configurations and every…

---

## [Can elasticsearch/kibana/... export trace/span log as datasets?](https://discuss.elastic.co/t/can-elasticsearch-kibana-export-trace-span-log-as-datasets/325855)

<div class="topic-metadata">

**Author:** [@elkLearner](https://discuss.elastic.co/u/elkLearner)\
**Replies:** 3\
**Last updated:** [February 19, 2023, 4:07am UTC](https://discuss.elastic.co/t/can-elasticsearch-kibana-export-trace-span-log-as-datasets/325855 "2023-02-19T04:07:09Z")

</div>

I'm a freshman here. I'm using skywalking+elasticsearch monitoring a microservice application in k8s. l know skywalking can collect trace/span logs from microservice and store the data in elasticsearch, and then display …

---

## [How to use mutli\_match with same value](https://discuss.elastic.co/t/how-to-use-mutli-match-with-same-value/325882)

<div class="topic-metadata">

**Author:** [@anhhungxdieu](https://discuss.elastic.co/u/anhhungxdieu)\
**Replies:** 4\
**Last updated:** [February 19, 2023, 2:49am UTC](https://discuss.elastic.co/t/how-to-use-mutli-match-with-same-value/325882 "2023-02-19T02:49:35Z")

</div>

I'm using elastic ver7.17 My sample documents : { "title" : "Firmly stepping forward under the glorious banner of the Party", "intro": "In celebration of the Party’s founding anniversary and the new spring, we proudl…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=296)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=298)
