# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=3

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 4

---

## [Elasticsearch coordinating node OOM/crash under sustained ingest (60k docs/min) with high shard count (~800)](https://discuss.elastic.co/t/elasticsearch-coordinating-node-oom-crash-under-sustained-ingest-60k-docs-min-with-high-shard-count-800/386708)

<div class="topic-metadata">

**Author:** [@Osmel\_Pillot\_Leyva](https://discuss.elastic.co/u/Osmel_Pillot_Leyva)\
**Replies:** 4\
**Last updated:** [June 9, 2026, 1:32pm UTC](https://discuss.elastic.co/t/elasticsearch-coordinating-node-oom-crash-under-sustained-ingest-60k-docs-min-with-high-shard-count-800/386708 "2026-06-09T13:32:50Z")

</div>

I have an Elasticsearch cluster with 3 master nodes, 1 data node, 1 ingest node, and 1 coordinating node. I also have 1 Kibana instance and 1 Fleet Server. Data ingestion is performed through approximately 12 Elastic Age…

---

## [Nest to the new API](https://discuss.elastic.co/t/nest-to-the-new-api/386742)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [June 6, 2026, 10:08pm UTC](https://discuss.elastic.co/t/nest-to-the-new-api/386742 "2026-06-06T22:08:30Z")

</div>

We used to be able to build filters incrementally as below. How do we do it in the new API. Thanks internal static List\<Func\<QueryContainerDescriptor, QueryContainer\>\> BuildFilter(SearchCriteria searchCriteria, string c…

---

## [Count of record drops on the hour](https://discuss.elastic.co/t/count-of-record-drops-on-the-hour/386676)

<div class="topic-metadata">

**Author:** [@HuwT](https://discuss.elastic.co/u/HuwT)\
**Replies:** 3\
**Last updated:** [June 5, 2026, 5:01pm UTC](https://discuss.elastic.co/t/count-of-record-drops-on-the-hour/386676 "2026-06-05T17:01:39Z")

</div>

Hello, I am running a single node ELK cluster including filebeat. My main pipeline involves Filebeat \> Logstash \> Elastic and I'm running no log mutations or alterations in logstash. I am seeing periodic drops, approxim…

---

## [Elasticsearch Indexing](https://discuss.elastic.co/t/elasticsearch-indexing/386724)

<div class="topic-metadata">

**Author:** [@akmoharana](https://discuss.elastic.co/u/akmoharana)\
**Replies:** 1\
**Last updated:** [June 5, 2026, 7:29am UTC](https://discuss.elastic.co/t/elasticsearch-indexing/386724 "2026-06-05T07:29:33Z")

</div>

Hi Team, I am using the ELK stack along with Filebeat for a monitoring project. Currently, Filebeat is collecting logs from a specific directory, and the log files follow a defined naming pattern. We also perform weekl…

---

## [Elastic search java client - co.elastic.clients:elasticsearch-java: and minimum target java road map](https://discuss.elastic.co/t/elastic-search-java-client-co-elastic-clients-and-minimum-target-java-road-map/386328)

<div class="topic-metadata">

**Author:** [@manick02](https://discuss.elastic.co/u/manick02)\
**Replies:** 2\
**Last updated:** [June 5, 2026, 6:08am UTC](https://discuss.elastic.co/t/elastic-search-java-client-co-elastic-clients-and-minimum-target-java-road-map/386328 "2026-06-05T06:08:03Z")

</div>

We use co.elastic.clients:elasticsearch-java in our application, which currently targets Java 17. We understand the 8.x client requires Java 17 as a minimum. Does Elastic have a published roadmap or policy for when the …

---

## [Elasticsearch Nodes Randomly Crashing Due to JVM Native Memory Allocation Failure on Windows Servers](https://discuss.elastic.co/t/elasticsearch-nodes-randomly-crashing-due-to-jvm-native-memory-allocation-failure-on-windows-servers/386422)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 5\
**Last updated:** [June 4, 2026, 9:50am UTC](https://discuss.elastic.co/t/elasticsearch-nodes-randomly-crashing-due-to-jvm-native-memory-allocation-failure-on-windows-servers/386422 "2026-06-04T09:50:01Z")

</div>

Hi Team, We are facing frequent Elasticsearch node crashes across all nodes in our cluster and need guidance on identifying the root cause and recommended tuning. Environment Details Elasticsearch Version: 9.1.3 OS…

---

## [Elasticsearch coordinating node OOM/crash under sustained ingest (60k docs/min) with high shard count (~800)](https://discuss.elastic.co/t/elasticsearch-coordinating-node-oom-crash-under-sustained-ingest-60k-docs-min-with-high-shard-count-800/386710)

<div class="topic-metadata">

**Author:** [@Osmel\_Pillot](https://discuss.elastic.co/u/Osmel_Pillot)\
**Replies:** 1\
**Last updated:** [June 4, 2026, 3:53am UTC](https://discuss.elastic.co/t/elasticsearch-coordinating-node-oom-crash-under-sustained-ingest-60k-docs-min-with-high-shard-count-800/386710 "2026-06-04T03:53:49Z")

</div>

I have an Elasticsearch cluster with 3 master nodes (6 GB RAM each), 2 data nodes (16 GB RAM each), 1 ingest node (8 GB RAM), 1 coordinating node (16 GB RAM), and 1 transform node (6 GB RAM). Additionally, I have 1 Kiban…

---

## [Kaspersky Logs for SOC](https://discuss.elastic.co/t/kaspersky-logs-for-soc/386695)

<div class="topic-metadata">

**Author:** [@breno.bazaga](https://discuss.elastic.co/u/breno.bazaga)\
**Replies:** 0\
**Last updated:** [June 3, 2026, 1:49pm UTC](https://discuss.elastic.co/t/kaspersky-logs-for-soc/386695 "2026-06-03T13:49:51Z")

</div>

Hello everyone, I currently work in a SOC environment and I am working on a use case involving monitoring and ingestion of Kaspersky logs into Elastic for managed security services. During the integration process, I no…

---

## [Elastic POC Sizing & Architecture](https://discuss.elastic.co/t/elastic-poc-sizing-architecture/386669)

<div class="topic-metadata">

**Author:** [@Sharmon](https://discuss.elastic.co/u/Sharmon)\
**Replies:** 0\
**Last updated:** [June 3, 2026, 3:58am UTC](https://discuss.elastic.co/t/elastic-poc-sizing-architecture/386669 "2026-06-03T03:58:56Z")

</div>

Hello Everyone, I recently joined in a Distributor for elastic and now we have to do POC, I am fairly new to Elastic and my main concern is if we have an estimated ingest of around 400 GB/Day how do we design the archi…

---

## [How to ingest paginated API data into Elasticsearch?](https://discuss.elastic.co/t/how-to-ingest-paginated-api-data-into-elasticsearch/386648)

<div class="topic-metadata">

**Author:** [@1o1o](https://discuss.elastic.co/u/1o1o)\
**Replies:** 1\
**Last updated:** [June 2, 2026, 7:51pm UTC](https://discuss.elastic.co/t/how-to-ingest-paginated-api-data-into-elasticsearch/386648 "2026-06-02T19:51:25Z")

</div>

Hi everyone, I’m trying to ingest data from a web application API into an Elasticsearch index. Context: The API is HTTP-based and returns JSON data It supports pagination cursor-based I need to regularly fetch…

---

## [Elastic Architecture on Ex-Hypervisor servers](https://discuss.elastic.co/t/elastic-architecture-on-ex-hypervisor-servers/386605)

<div class="topic-metadata">

**Author:** [@othcher](https://discuss.elastic.co/u/othcher)\
**Replies:** 2\
**Last updated:** [June 2, 2026, 8:57am UTC](https://discuss.elastic.co/t/elastic-architecture-on-ex-hypervisor-servers/386605 "2026-06-02T08:57:59Z")

</div>

Hello ELK community, I'm currently implementing my first ELK infrastructure in production. The plan is to ingest S3 logs that are sent from 54 source servers where we installed filebeat. We have 3 physical servers ava…

---

## [LAG() LEAD() Functions in ES|QL](https://discuss.elastic.co/t/lag-lead-functions-in-es-ql/386589)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 0\
**Last updated:** [May 31, 2026, 12:27am UTC](https://discuss.elastic.co/t/lag-lead-functions-in-es-ql/386589 "2026-05-31T00:27:12Z")

</div>

Will there be an addition for LAG() or LEAD() functions that are in SQL added to ES|QL in the future?

---

## [Practical issues related to disk usage](https://discuss.elastic.co/t/practical-issues-related-to-disk-usage/386568)

<div class="topic-metadata">

**Author:** [@mloine](https://discuss.elastic.co/u/mloine)\
**Replies:** 2\
**Last updated:** [May 30, 2026, 8:42am UTC](https://discuss.elastic.co/t/practical-issues-related-to-disk-usage/386568 "2026-05-30T08:42:34Z")

</div>

Hello, I am encountering a situation now: Version: 6.8.1 Number of nodes: 20, of which 15 nodes are 500G and 5 nodes are 2000G Now the 500G disk must be filled up to trigger the water level configuration of the disk. …

---

## [Version conflict, document already exists when putting new documents](https://discuss.elastic.co/t/version-conflict-document-already-exists-when-putting-new-documents/386577)

<div class="topic-metadata">

**Author:** [@scip](https://discuss.elastic.co/u/scip)\
**Replies:** 1\
**Last updated:** [May 29, 2026, 12:37pm UTC](https://discuss.elastic.co/t/version-conflict-document-already-exists-when-putting-new-documents/386577 "2026-05-29T12:37:52Z")

</div>

For testing+learning purposes I created a new index and add new docs in a loop. I am using a cli tool for this, which I call in a simple shell loop: while :; do ts=$(date --iso-8601=second) msg=$(dicepwgen -c 6) e…

---

## [How to apply logical operators to search query in golang?](https://discuss.elastic.co/t/how-to-apply-logical-operators-to-search-query-in-golang/386536)

<div class="topic-metadata">

**Author:** [@scip](https://discuss.elastic.co/u/scip)\
**Replies:** 2\
**Last updated:** [May 28, 2026, 12:57pm UTC](https://discuss.elastic.co/t/how-to-apply-logical-operators-to-search-query-in-golang/386536 "2026-05-28T12:57:13Z")

</div>

Hi, how can I specify if I want a query to use the AND or OR operator? For a SimpleQuery this is easy, just call DefaultOperator(operator.Operator{"AND"}). But how Do I specify this with a BoolQuery? What I found is, t…

---

## [Kibana Showing Only 5xx Errors for API Logs Despite of receving 200 Responses too in Analytics](https://discuss.elastic.co/t/kibana-showing-only-5xx-errors-for-api-logs-despite-of-receving-200-responses-too-in-analytics/386525)

<div class="topic-metadata">

**Author:** [@devapi](https://discuss.elastic.co/u/devapi)\
**Replies:** 1\
**Last updated:** [May 27, 2026, 6:46pm UTC](https://discuss.elastic.co/t/kibana-showing-only-5xx-errors-for-api-logs-despite-of-receving-200-responses-too-in-analytics/386525 "2026-05-27T18:46:40Z")

</div>

We have successfully set up and integrated Elasticsearch with the IBM Analytics subsystem to offload API logs into ELK. However, while applying a filter on the API-Name field in the Kibana UI for a specific valid timesta…

---

## [S3 compatible storage are not able to mounted for snapshot](https://discuss.elastic.co/t/s3-compatible-storage-are-not-able-to-mounted-for-snapshot/386444)

<div class="topic-metadata">

**Author:** [@Rajesh\_Kannan](https://discuss.elastic.co/u/Rajesh_Kannan)\
**Replies:** 11\
**Last updated:** [May 27, 2026, 11:05am UTC](https://discuss.elastic.co/t/s3-compatible-storage-are-not-able-to-mounted-for-snapshot/386444 "2026-05-27T11:05:50Z")

</div>

We are trying to mount the s3 storage( S3 compatible DataCore (caringo)) bucket on elastic 9.3.0 using the below command and we are getting "s3\_exception: A header you provided implies functionality that is not implement…

---

## [Unable to configure precision\_threshold for Unique Count in Kibana Lens (v9.3.3)](https://discuss.elastic.co/t/unable-to-configure-precision-threshold-for-unique-count-in-kibana-lens-v9-3-3/386505)

<div class="topic-metadata">

**Author:** [@Vignesh2](https://discuss.elastic.co/u/Vignesh2)\
**Replies:** 3\
**Last updated:** [May 27, 2026, 10:10am UTC](https://discuss.elastic.co/t/unable-to-configure-precision-threshold-for-unique-count-in-kibana-lens-v9-3-3/386505 "2026-05-27T10:10:34Z")

</div>

Hi team, I'm facing an accuracy issue with the Unique Count aggregation in Kibana Lens and could not find a way to configure precision\_threshold through the UI. Environment Kibana version: 9.3.3 Visualization: Lens (…

---

## [Moving index using custom attribute](https://discuss.elastic.co/t/moving-index-using-custom-attribute/386492)

<div class="topic-metadata">

**Author:** [@doniyey](https://discuss.elastic.co/u/doniyey)\
**Replies:** 3\
**Last updated:** [May 26, 2026, 7:59am UTC](https://discuss.elastic.co/t/moving-index-using-custom-attribute/386492 "2026-05-26T07:59:27Z")

</div>

Hello everyone, I am working on a project with elasticsearch 9.4.1, where the goal is to move a specific data stream (ds) to a dedicated cold node for that data stream. Here are the nodes I have prepared: ip …

---

## [Ingest pipeline doesnt work](https://discuss.elastic.co/t/ingest-pipeline-doesnt-work/386407)

<div class="topic-metadata">

**Author:** [@Shahar\_Argov](https://discuss.elastic.co/u/Shahar_Argov)\
**Replies:** 4\
**Last updated:** [May 21, 2026, 2:12pm UTC](https://discuss.elastic.co/t/ingest-pipeline-doesnt-work/386407 "2026-05-21T14:12:36Z")

</div>

hi, I want to send logs through ingest pipeline to rename them to a different name, now the pipeline does look like its running but the names arent changing. if i try it with a random file from the index it said it wor…

---

## [Does the restore function support incremental recovery?](https://discuss.elastic.co/t/does-the-restore-function-support-incremental-recovery/386434)

<div class="topic-metadata">

**Author:** [@mloine](https://discuss.elastic.co/u/mloine)\
**Replies:** 5\
**Last updated:** [May 21, 2026, 10:38am UTC](https://discuss.elastic.co/t/does-the-restore-function-support-incremental-recovery/386434 "2026-05-21T10:38:54Z")

</div>

Hello, we currently have a scenario where the new and old clusters are switched, and data will be restored to the new cluster using snapshots; I would like to ask if the restore method also supports incremental recovery…

---

## [Designing an Elasticsearch index for multiple domain models without field explosion](https://discuss.elastic.co/t/designing-an-elasticsearch-index-for-multiple-domain-models-without-field-explosion/386402)

<div class="topic-metadata">

**Author:** [@Mevevlin](https://discuss.elastic.co/u/Mevevlin)\
**Replies:** 2\
**Last updated:** [May 20, 2026, 4:16pm UTC](https://discuss.elastic.co/t/designing-an-elasticsearch-index-for-multiple-domain-models-without-field-explosion/386402 "2026-05-20T16:16:49Z")

</div>

I’m designing a search system where multiple SQL tables are synced into a single Elasticsearch index. The issue I’m running into is that the tables are not perfectly aligned in terms of contextual meaning. For example: …

---

## [Need Help: Date-wise Index Creation with Application Using Built-in Elasticsearch and Static Index Name](https://discuss.elastic.co/t/need-help-date-wise-index-creation-with-application-using-built-in-elasticsearch-and-static-index-name/386007)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 6\
**Last updated:** [May 20, 2026, 1:24pm UTC](https://discuss.elastic.co/t/need-help-date-wise-index-creation-with-application-using-built-in-elasticsearch-and-static-index-name/386007 "2026-05-20T13:24:00Z")

</div>

\## Environment Details ### Elasticsearch (self-managed cluster on AWS) 4 Data Nodes (1 TB each) 2 Master Nodes Daily data ingestion around 300 GB (without replica) and approximately 600 GB with 1 replica Data source is…

---

## [ECK AWS Pod Identity instead of iam user/secret key pair](https://discuss.elastic.co/t/eck-aws-pod-identity-instead-of-iam-user-secret-key-pair/386418)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 0\
**Last updated:** [May 20, 2026, 5:21am UTC](https://discuss.elastic.co/t/eck-aws-pod-identity-instead-of-iam-user-secret-key-pair/386418 "2026-05-20T05:21:57Z")

</div>

I used to add the AWS credentials into elasticsearch (ECK) keystore to backup to AWS S3. And then I was told that this is not a recommended good practice but should use pod identity or environment variables injected by i…

---

## [JSON Schema for DSL Query Language](https://discuss.elastic.co/t/json-schema-for-dsl-query-language/386415)

<div class="topic-metadata">

**Author:** [@aidin](https://discuss.elastic.co/u/aidin)\
**Replies:** 1\
**Last updated:** [May 20, 2026, 1:54am UTC](https://discuss.elastic.co/t/json-schema-for-dsl-query-language/386415 "2026-05-20T01:54:19Z")

</div>

Hi, Is there a JSON Schema definition for the DSL Query language? I found some old topics here without an answer. I was wondering if a schema has been created since then. There are definitions for the entire API, but …

---

## [Stable analysis plugin with native library fails entitlements in Elasticsearch 8.19.12](https://discuss.elastic.co/t/stable-analysis-plugin-with-native-library-fails-entitlements-in-elasticsearch-8-19-12/386411)

<div class="topic-metadata">

**Author:** [@dbenito](https://discuss.elastic.co/u/dbenito)\
**Replies:** 0\
**Last updated:** [May 19, 2026, 3:34pm UTC](https://discuss.elastic.co/t/stable-analysis-plugin-with-native-library-fails-entitlements-in-elasticsearch-8-19-12/386411 "2026-05-19T15:34:36Z")

</div>

Stable analysis plugin with native library fails entitlements in Elasticsearch 8.19.12 We are building a stable-analysis plugin that registers a custom TokenFilter via the stable plugin API. The plugin needs to load a bu…

---

## [How to fetch data through multiple indexes](https://discuss.elastic.co/t/how-to-fetch-data-through-multiple-indexes/386380)

<div class="topic-metadata">

**Author:** [@Suiiinaldo](https://discuss.elastic.co/u/Suiiinaldo)\
**Replies:** 3\
**Last updated:** [May 19, 2026, 9:35am UTC](https://discuss.elastic.co/t/how-to-fetch-data-through-multiple-indexes/386380 "2026-05-19T09:35:26Z")

</div>

Problem: I need to fetch data through multiple indexes. Use Case: Currently I have an index "something-\*", and it stores data monthly (for example something-2026-05, something-2026-04). Now I need to fetch data for la…

---

## [Clarification on CVE / Vulnerability ID related to bundled commons-text-1.4.jar in Elasticsearch 8.19.x](https://discuss.elastic.co/t/clarification-on-cve-vulnerability-id-related-to-bundled-commons-text-1-4-jar-in-elasticsearch-8-19-x/386398)

<div class="topic-metadata">

**Author:** [@lukecw](https://discuss.elastic.co/u/lukecw)\
**Replies:** 2\
**Last updated:** [May 19, 2026, 9:19am UTC](https://discuss.elastic.co/t/clarification-on-cve-vulnerability-id-related-to-bundled-commons-text-1-4-jar-in-elasticsearch-8-19-x/386398 "2026-05-19T09:19:19Z")

</div>

Hello, we need clarification regarding a vulnerability finding raised by our security scanner on Elasticsearch. The scanner is reporting the following issue: CVE: CVE-2025-46295 Vulnerability ID: OO0TMV On our…

---

## [Updating xpack certificates to a new CA in an active Elasticsearch cluster without downtime](https://discuss.elastic.co/t/updating-xpack-certificates-to-a-new-ca-in-an-active-elasticsearch-cluster-without-downtime/385871)

<div class="topic-metadata">

**Author:** [@Anup\_Kumar](https://discuss.elastic.co/u/Anup_Kumar)\
**Replies:** 22\
**Last updated:** [May 15, 2026, 12:39pm UTC](https://discuss.elastic.co/t/updating-xpack-certificates-to-a-new-ca-in-an-active-elasticsearch-cluster-without-downtime/385871 "2026-05-15T12:39:34Z")

</div>

Hi, We have an active Elasticsearch cluster (large) with TLS/SSL enabled for inter-node communication (xpack.security.transport.ssl). We are planning to replace the existing node certificates with new ones issued by a d…

---

## [Migrating off ElasticSearch as sole primary database for a relational business domain — anyone done this?](https://discuss.elastic.co/t/migrating-off-elasticsearch-as-sole-primary-database-for-a-relational-business-domain-anyone-done-this/386137)

<div class="topic-metadata">

**Author:** [@lets\_get\_relational](https://discuss.elastic.co/u/lets_get_relational)\
**Replies:** 13\
**Last updated:** [May 15, 2026, 12:34pm UTC](https://discuss.elastic.co/t/migrating-off-elasticsearch-as-sole-primary-database-for-a-relational-business-domain-anyone-done-this/386137 "2026-05-15T12:34:16Z")

</div>

\# Migrating off Elasticsearch as sole primary database for a relational business domain — anyone done this? I've inherited a ~6 year old production Django application where Elasticsearch is the only data store. Not "ES …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=2)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=4)
