# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=30

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 31

---

## [unable to set up my lab in the Learner Dashboard](https://discuss.elastic.co/t/unable-to-set-up-my-lab-in-the-learner-dashboard/378880)

<div class="topic-metadata">

**Author:** [@Abebes](https://discuss.elastic.co/u/Abebes)\
**Replies:** 1\
**Last updated:** [June 4, 2025, 8:08pm UTC](https://discuss.elastic.co/t/unable-to-set-up-my-lab-in-the-learner-dashboard/378880 "2025-06-04T20:08:39Z")

</div>

I am unable to set up my lab in the Learner Dashboard. I have received the confirmation of enrollment and successfully logged in to the training portal; however, I do not see the class title under "My Enrollments" in the…

---

## [Alerts indices custom components template](https://discuss.elastic.co/t/alerts-indices-custom-components-template/378731)

<div class="topic-metadata">

**Author:** [@aptfinf](https://discuss.elastic.co/u/aptfinf)\
**Replies:** 9\
**Last updated:** [June 4, 2025, 1:20pm UTC](https://discuss.elastic.co/t/alerts-indices-custom-components-template/378731 "2025-06-04T13:20:38Z")

</div>

Hello everyone, I have a question: I know that for the "logs" indices templates exists the component template "@custom" that gets automatically mapped to the index templates. Does this same thing exist for the ".intern…

---

## [Understand fleet pipelines and reroute](https://discuss.elastic.co/t/understand-fleet-pipelines-and-reroute/378804)

<div class="topic-metadata">

**Author:** [@mistrhanky1](https://discuss.elastic.co/u/mistrhanky1)\
**Replies:** 2\
**Last updated:** [June 3, 2025, 7:59pm UTC](https://discuss.elastic.co/t/understand-fleet-pipelines-and-reroute/378804 "2025-06-03T19:59:29Z")

</div>

I need to, for a number of reasons, reroute the output of a fleet pipeline. To keep it very simple, lets use the fortigate integration as the example. I want my data to come in via elastic agent(working), be processed by…

---

## [Group/update events in Elastic](https://discuss.elastic.co/t/group-update-events-in-elastic/378600)

<div class="topic-metadata">

**Author:** [@miguel4](https://discuss.elastic.co/u/miguel4)\
**Replies:** 1\
**Last updated:** [June 3, 2025, 1:39pm UTC](https://discuss.elastic.co/t/group-update-events-in-elastic/378600 "2025-06-03T13:39:32Z")

</div>

Hello, I post a question about a use case we have on our ELK architecture. We are setting up an infrastructure with Logstash + Elasticsearch + Kibana. The same event (same value for a given ID field but another differen…

---

## [Planning 8 PB Elasticsearch Deployment – Is Free Tier Sufficient or Will Licensing Be a Limitation?](https://discuss.elastic.co/t/planning-8-pb-elasticsearch-deployment-is-free-tier-sufficient-or-will-licensing-be-a-limitation/378813)

<div class="topic-metadata">

**Author:** [@emad\_omara](https://discuss.elastic.co/u/emad_omara)\
**Replies:** 5\
**Last updated:** [June 3, 2025, 1:09pm UTC](https://discuss.elastic.co/t/planning-8-pb-elasticsearch-deployment-is-free-tier-sufficient-or-will-licensing-be-a-limitation/378813 "2025-06-03T13:09:03Z")

</div>

Hi all, I'm planning a large-scale self-managed Elasticsearch deployment for an application that will eventually handle around 8 petabytes (PB) of data I'm currently evaluating whether the Basic (free) license of Elast…

---

## [LDAP Connection Elastic](https://discuss.elastic.co/t/ldap-connection-elastic/377281)

<div class="topic-metadata">

**Author:** [@vahagg1](https://discuss.elastic.co/u/vahagg1)\
**Replies:** 9\
**Last updated:** [June 3, 2025, 11:27am UTC](https://discuss.elastic.co/t/ldap-connection-elastic/377281 "2025-06-03T11:27:48Z")

</div>

I have a LDAP connection from a single Elastic to LDAP server which is Active Directory i use ldap not ldaps and get following error \[2025-04-18T11:59:27,596\]\[WARN \]\[o.e.x.s.a.l.s.LdapUtils \] \[elk\] Failed to obtain LD…

---

## [Issue when I am trying to upgraded Elasticsearch cluster from Elasticsearch 7.17.28 to 8.17.6,](https://discuss.elastic.co/t/issue-when-i-am-trying-to-upgraded-elasticsearch-cluster-from-elasticsearch-7-17-28-to-8-17-6/378807)

<div class="topic-metadata">

**Author:** [@kuroro](https://discuss.elastic.co/u/kuroro)\
**Replies:** 2\
**Last updated:** [June 3, 2025, 7:27am UTC](https://discuss.elastic.co/t/issue-when-i-am-trying-to-upgraded-elasticsearch-cluster-from-elasticsearch-7-17-28-to-8-17-6/378807 "2025-06-03T07:27:48Z")

</div>

Hi Everyone, I am trying to upgrade Elasticsearch cluster version from 7.17.28 to 8.17.6. I could see one node was successfully upgraded from 7.17.28 to 8.17.6, and it was automatically removed from the 7.x cluster aft…

---

## [Trying out ES 9 — any Java API changes?](https://discuss.elastic.co/t/trying-out-es-9-any-java-api-changes/376812)

<div class="topic-metadata">

**Author:** [@KajMagnus](https://discuss.elastic.co/u/KajMagnus)\
**Replies:** 16\
**Last updated:** [June 2, 2025, 9:38pm UTC](https://discuss.elastic.co/t/trying-out-es-9-any-java-api-changes/376812 "2025-06-02T21:38:34Z")

</div>

When upgrading from Elasticsearch 8 to 9, do I need to update my application server Java code? I use the ES 8 Java API to talk to an ES 8 (and 9?) server. Is there any ES Java client version 9, for talking with ES serve…

---

## [ES node enrolment error](https://discuss.elastic.co/t/es-node-enrolment-error/378788)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 1\
**Last updated:** [June 2, 2025, 8:49pm UTC](https://discuss.elastic.co/t/es-node-enrolment-error/378788 "2025-06-02T20:49:31Z")

</div>

While enrolling a node I am getting below error ERROR: Aborting enrolling to cluster. This node doesn't appear to be auto-configured for security. Expected configuration is missing from elasticsearch.yml., with exit cod…

---

## [Unable to use repository-azure plugin to connect to Azure storage account in Gov cloud](https://discuss.elastic.co/t/unable-to-use-repository-azure-plugin-to-connect-to-azure-storage-account-in-gov-cloud/378147)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 2\
**Last updated:** [June 2, 2025, 6:31pm UTC](https://discuss.elastic.co/t/unable-to-use-repository-azure-plugin-to-connect-to-azure-storage-account-in-gov-cloud/378147 "2025-06-02T18:31:52Z")

</div>

We successfully use the repository-azure plugin to use azure blob storage as a snapshot repo and have been doing this for quite a while in multiple elasticsearch clusters on Azure AKS in their commercial cloud. We have …

---

## [Understanding "id existence" check mechanism for custom ids](https://discuss.elastic.co/t/understanding-id-existence-check-mechanism-for-custom-ids/378795)

<div class="topic-metadata">

**Author:** [@danslapman](https://discuss.elastic.co/u/danslapman)\
**Replies:** 5\
**Last updated:** [June 2, 2025, 6:05pm UTC](https://discuss.elastic.co/t/understanding-id-existence-check-mechanism-for-custom-ids/378795 "2025-06-02T18:05:47Z")

</div>

Greetings! I'm seeking a way to verify/clarify my understanding on what's going on during indexing a document with custom \_id. I know that ES performs an existence check in such case, but I'm curious about details. For m…

---

## [How to get the \_id of a document easily? \[C#\]](https://discuss.elastic.co/t/how-to-get-the-id-of-a-document-easily-c/364260)

<div class="topic-metadata">

**Author:** [@Motsols](https://discuss.elastic.co/u/Motsols)\
**Replies:** 3\
**Last updated:** [June 2, 2025, 6:02pm UTC](https://discuss.elastic.co/t/how-to-get-the-id-of-a-document-easily-c/364260 "2025-06-02T18:02:41Z")

</div>

I'm indexing documents without an ID, letting ES set it by itself. How it is created nor the value is of any interest. How can I easily get this \_id in the response document? I'd very much love not to iterate over each…

---

## [esrally.exceptions.LaunchError: Daemon startup failed with exit code \[1\]](https://discuss.elastic.co/t/esrally-exceptions-launcherror-daemon-startup-failed-with-exit-code-1/378790)

<div class="topic-metadata">

**Author:** [@Zoree](https://discuss.elastic.co/u/Zoree)\
**Replies:** 1\
**Last updated:** [June 2, 2025, 11:39am UTC](https://discuss.elastic.co/t/esrally-exceptions-launcherror-daemon-startup-failed-with-exit-code-1/378790 "2025-06-02T11:39:14Z")

</div>

I trying start: esrally race --track-path=tracks/search\_all --distribution-version=7.11.2 --car="4gheap" --preserve-install But I got an error: esrally.exceptions.LaunchError: Daemon startup failed with exit code \[1\]. …

---

## [Elasticsearch 8. Refresh API](https://discuss.elastic.co/t/elasticsearch-8-refresh-api/378782)

<div class="topic-metadata">

**Author:** [@S\_R](https://discuss.elastic.co/u/S_R)\
**Replies:** 2\
**Last updated:** [June 2, 2025, 9:02am UTC](https://discuss.elastic.co/t/elasticsearch-8-refresh-api/378782 "2025-06-02T09:02:19Z")

</div>

Hi, I'm facing an probable issue in ES 8.x.x where the refresh operation has become significantly slower compared to versions 7.x.x ≤ 7.17. In our setup, each index is created with "refresh\_interval": "30s". In versio…

---

## [Enterprise Search - EOL](https://discuss.elastic.co/t/enterprise-search-eol/378706)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [May 30, 2025, 7:36pm UTC](https://discuss.elastic.co/t/enterprise-search-eol/378706 "2025-05-30T19:36:28Z")

</div>

Hello, I read this Enterprise Search FAQ | Elastic I am bit confused on what Elastic means they want to focus on "Elasticsearch" instead of Enterprise Search. We were looking into using Workplace Search but if its goi…

---

## [New cluster setup fails](https://discuss.elastic.co/t/new-cluster-setup-fails/378712)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [May 30, 2025, 5:38pm UTC](https://discuss.elastic.co/t/new-cluster-setup-fails/378712 "2025-05-30T17:38:42Z")

</div>

I have setup cluster in past without must problem. this time it is just failing don't understand why Node leaves and joins fine as I test it out. but can't run reset password command for elastic this is brand new clust…

---

## [Backup repository sizes - snapshot repository v. disk space use; why the difference?](https://discuss.elastic.co/t/backup-repository-sizes-snapshot-repository-v-disk-space-use-why-the-difference/378716)

<div class="topic-metadata">

**Author:** [@kmp](https://discuss.elastic.co/u/kmp)\
**Replies:** 3\
**Last updated:** [May 30, 2025, 3:57pm UTC](https://discuss.elastic.co/t/backup-repository-sizes-snapshot-repository-v-disk-space-use-why-the-difference/378716 "2025-05-30T15:57:18Z")

</div>

I'm curious whether anyone knows what the underlying mechanism is causing this... My (small) environment has replication across multiple nodes in the cluster, so snapshotting isn't something that's seemed important for …

---

## [Getting error in kibana.log](https://discuss.elastic.co/t/getting-error-in-kibana-log/378740)

<div class="topic-metadata">

**Author:** [@Deepraj\_Das](https://discuss.elastic.co/u/Deepraj_Das)\
**Replies:** 0\
**Last updated:** [May 30, 2025, 12:47pm UTC](https://discuss.elastic.co/t/getting-error-in-kibana-log/378740 "2025-05-30T12:47:05Z")

</div>

{"type":"log","@timestamp":"2025-05-30T08:24:14-04:00","tags":\["info","plugins","taskManager"\],"pid":3396318,"message":"TaskManager is identified by the Kibana UUID: 197a9ff4-ceaa-474b-9ce0-c1f8b58fd3b8"} {"type":"log",…

---

## [ELK deployment in DC DR](https://discuss.elastic.co/t/elk-deployment-in-dc-dr/378722)

<div class="topic-metadata">

**Author:** [@sharathsurya](https://discuss.elastic.co/u/sharathsurya)\
**Replies:** 1\
**Last updated:** [May 30, 2025, 6:20am UTC](https://discuss.elastic.co/t/elk-deployment-in-dc-dr/378722 "2025-05-30T06:20:02Z")

</div>

Hi, I am looking for formation related to ELK deployment which support DC DR configuration. any guidance appreciated. Regards sharath

---

## [Dedicated ML node](https://discuss.elastic.co/t/dedicated-ml-node/378717)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 30, 2025, 3:04am UTC](https://discuss.elastic.co/t/dedicated-ml-node/378717 "2025-05-30T03:04:32Z")

</div>

Is a dedicated ML node needed when using ELSER? is a dedicated ML node needed when a third party ML model is used if I start using elastic cloud?

---

## [Datastream Index Rollover issue](https://discuss.elastic.co/t/datastream-index-rollover-issue/378689)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 2\
**Last updated:** [May 29, 2025, 12:42pm UTC](https://discuss.elastic.co/t/datastream-index-rollover-issue/378689 "2025-05-29T12:42:32Z")

</div>

Hi Team, I have this index as part of datastream which is still in HOT phase , with current step as ERROR { "failed\_step": "update-rollover-lifecycle-date", "step\_info": { "type": "illegal\_state\_exception", …

---

## [How to obtain mappings and ingest pipelines from Elastic integrations without using Fleet?](https://discuss.elastic.co/t/how-to-obtain-mappings-and-ingest-pipelines-from-elastic-integrations-without-using-fleet/378408)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 1\
**Last updated:** [May 29, 2025, 12:00pm UTC](https://discuss.elastic.co/t/how-to-obtain-mappings-and-ingest-pipelines-from-elastic-integrations-without-using-fleet/378408 "2025-05-29T12:00:01Z")

</div>

We’re working on ingesting logs from network devices (e.g., Cisco IOS) that send their logs via Syslog directly to Logstash, which then forwards the data to Elasticsearch. We manage all components through custom automati…

---

## [elasticsearch previous logs gone after adding ssl/https](https://discuss.elastic.co/t/elasticsearch-previous-logs-gone-after-adding-ssl-https/378609)

<div class="topic-metadata">

**Author:** [@yyhk123](https://discuss.elastic.co/u/yyhk123)\
**Replies:** 2\
**Last updated:** [May 29, 2025, 9:44am UTC](https://discuss.elastic.co/t/elasticsearch-previous-logs-gone-after-adding-ssl-https/378609 "2025-05-29T09:44:42Z")

</div>

I was using elasticsearch without ssl/https enabled, then when I enabled it, the previous logs were all gone, but still remains in the vm in /data/elasticsearch, whereas the original path was /home/user/elasticsearch i …

---

## [Failure in Writing Watcher History – Seeking Reliable Logging Mechanism](https://discuss.elastic.co/t/failure-in-writing-watcher-history-seeking-reliable-logging-mechanism/378645)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 2\
**Last updated:** [May 29, 2025, 8:11am UTC](https://discuss.elastic.co/t/failure-in-writing-watcher-history-seeking-reliable-logging-mechanism/378645 "2025-05-29T08:11:57Z")

</div>

Hi Folks! We are currently encountering challenges with debugging Watcher execution using the default .watcher-history-\* indices. Our production Elasticsearch cluster hosts over 200 complex Watcher definitions, and we a…

---

## [Elastic Search Crashing and corrupting the index data](https://discuss.elastic.co/t/elastic-search-crashing-and-corrupting-the-index-data/378604)

<div class="topic-metadata">

**Author:** [@rutuja](https://discuss.elastic.co/u/rutuja)\
**Replies:** 8\
**Last updated:** [May 28, 2025, 8:13pm UTC](https://discuss.elastic.co/t/elastic-search-crashing-and-corrupting-the-index-data/378604 "2025-05-28T20:13:27Z")

</div>

We are running a 1node Elasticsearch Cluster on Elastic stack version 7.17.9. The node are running on computer with SSD storage and 128GB RAM. But when I indexing some data on elastic-search getting stopped and as well a…

---

## [Data stream compatibility issues upgrading from 8.18 to 9](https://discuss.elastic.co/t/data-stream-compatibility-issues-upgrading-from-8-18-to-9/378652)

<div class="topic-metadata">

**Author:** [@mcflynnthm](https://discuss.elastic.co/u/mcflynnthm)\
**Replies:** 1\
**Last updated:** [May 28, 2025, 7:06pm UTC](https://discuss.elastic.co/t/data-stream-compatibility-issues-upgrading-from-8-18-to-9/378652 "2025-05-28T19:06:58Z")

</div>

Testing the upgrade of my cluster from 8.18 to 9.0, the Upgrade Assistant reports it cannot retrieve deprecation issues for Elasticsearch. Checked /\_migration/deprecations and among other things, get the following: "dat…

---

## [Cannot delete packetbeat index](https://discuss.elastic.co/t/cannot-delete-packetbeat-index/378629)

<div class="topic-metadata">

**Author:** [@albertino87](https://discuss.elastic.co/u/albertino87)\
**Replies:** 3\
**Last updated:** [May 28, 2025, 1:53pm UTC](https://discuss.elastic.co/t/cannot-delete-packetbeat-index/378629 "2025-05-28T13:53:47Z")

</div>

Hi I installed packetbeat because I wanted to check the traffic, now I don't need it anymore. I stopped the packetbeat service, disabled it and then uniinstalled the rpm package. Still there is a packetbeat index in ES b…

---

## [Elasticsearch URL unresponsive](https://discuss.elastic.co/t/elasticsearch-url-unresponsive/378625)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 4\
**Last updated:** [May 28, 2025, 12:07pm UTC](https://discuss.elastic.co/t/elasticsearch-url-unresponsive/378625 "2025-05-28T12:07:45Z")

</div>

Hi OS - Ubuntu 22.04 Elasticsearch - 7.17.27 we are getting continuous warnings in elasticsearch logs regarding \[WARN \]\[o.e.h.AbstractHttpServerTransport\] \[XXES12\] handling request \[null\]\[POST\]\[/index\]\[Netty4HttpChan…

---

## [GeoIP Procesor](https://discuss.elastic.co/t/geoip-procesor/378624)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 2\
**Last updated:** [May 28, 2025, 11:58am UTC](https://discuss.elastic.co/t/geoip-procesor/378624 "2025-05-28T11:58:37Z")

</div>

Hi All, I dont have direct internet on my elk cluster , But I want to use geoip processor through ingest pipeline using elastic agent . But in logs it is showing there is no database available. I have downloaded the max…

---

## [Not able to get more than top 4 result matches, regardless of configuration](https://discuss.elastic.co/t/not-able-to-get-more-than-top-4-result-matches-regardless-of-configuration/378546)

<div class="topic-metadata">

**Author:** [@dave\_espinosa\_qs](https://discuss.elastic.co/u/dave_espinosa_qs)\
**Replies:** 3\
**Last updated:** [May 28, 2025, 10:29am UTC](https://discuss.elastic.co/t/not-able-to-get-more-than-top-4-result-matches-regardless-of-configuration/378546 "2025-05-28T10:29:12Z")

</div>

Hello everyone, I am using ES Enterprise version 8.18.1 (I cannot change it for the time being BTW, as that is managed by other department). I created a Vector Database - like ES Vector Store, with the following Mapping…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=29)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=31)
