# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=301

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 302

---

## [Unable to update the password of elastic user](https://discuss.elastic.co/t/unable-to-update-the-password-of-elastic-user/325422)

<div class="topic-metadata">

**Author:** [@quynhdn](https://discuss.elastic.co/u/quynhdn)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 3:19am UTC](https://discuss.elastic.co/t/unable-to-update-the-password-of-elastic-user/325422 "2023-02-14T03:19:29Z")

</div>

I want to rotate the password of elastic user. I used this utility: bin/elasticsearch-users passwd elastic -p XXXXX It didn’t give any error, but when I tried to use the new password, it didn’t work. The old password co…

---

## [Default settings Xms and Xmx](https://discuss.elastic.co/t/default-settings-xms-and-xmx/324103)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 6:32pm UTC](https://discuss.elastic.co/t/default-settings-xms-and-xmx/324103 "2023-02-13T18:32:51Z")

</div>

Hi Whether elastic has set with default Xms and Xmx or should I always remember to set it it in environment per node? I'm asking because I'm observing some wire increase heap on nodes, and I think this graph should loo…

---

## [Runtime field not appearing in search results](https://discuss.elastic.co/t/runtime-field-not-appearing-in-search-results/325425)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 12:54am UTC](https://discuss.elastic.co/t/runtime-field-not-appearing-in-search-results/325425 "2023-02-14T00:54:00Z")

</div>

I'm trying to set up a run time field to calculate the total of an e-commerce purchase. But there is something wrong with the way I'm declaring run time field, and it might have something to do with nested objects. Fir…

---

## [Add Matches inside a loop](https://discuss.elastic.co/t/add-matches-inside-a-loop/325427)

<div class="topic-metadata">

**Author:** [@chachew](https://discuss.elastic.co/u/chachew)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 10:51pm UTC](https://discuss.elastic.co/t/add-matches-inside-a-loop/325427 "2023-02-13T22:51:22Z")

</div>

How can i add multiple Match clauses inside a loop? Currently when i do this, the only thing that gets added is the first item in the List and thats it. List\<string\> types = new(); b.Should(s =\> { types.ForEach(t =\>…

---

## [Script\_score behavior depends on number of requested documents](https://discuss.elastic.co/t/script-score-behavior-depends-on-number-of-requested-documents/324837)

<div class="topic-metadata">

**Author:** [@Gkleinereva](https://discuss.elastic.co/u/Gkleinereva)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 9:03pm UTC](https://discuss.elastic.co/t/script-score-behavior-depends-on-number-of-requested-documents/324837 "2023-02-13T21:03:11Z")

</div>

TL;DR - I encountered a problem with script\_score behavior. script\_score seems to calculate scores differently depending on the size parameter in the query. Can anyone help me understand what's going on here (and wheth…

---

## [With the removal of doc types, must I reindex all the indices that use a custom doc\_type?](https://discuss.elastic.co/t/with-the-removal-of-doc-types-must-i-reindex-all-the-indices-that-use-a-custom-doc-type/325419)

<div class="topic-metadata">

**Author:** [@kexin-zhai](https://discuss.elastic.co/u/kexin-zhai)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 8:36pm UTC](https://discuss.elastic.co/t/with-the-removal-of-doc-types-must-i-reindex-all-the-indices-that-use-a-custom-doc-type/325419 "2023-02-13T20:36:59Z")

</div>

I have a similar question regarding the removal of doc types as @smlbiobot 's post here With the removal of doc types, must I reindex all the indices that use a named type? . Do I have to reindex all the indices before …

---

## [Unified highlighter with function\_score](https://discuss.elastic.co/t/unified-highlighter-with-function-score/325281)

<div class="topic-metadata">

**Author:** [@Wonder\_Garance](https://discuss.elastic.co/u/Wonder_Garance)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 8:18pm UTC](https://discuss.elastic.co/t/unified-highlighter-with-function-score/325281 "2023-02-13T20:18:40Z")

</div>

Hello, I have a query to search for the acronym: pin and "Personal Identification Number", with "auto\_generate\_synonyms\_phrase\_query": true I don't want results with 3 words Personal, Identification, Number highlighted …

---

## [Update node roles with shards assigned](https://discuss.elastic.co/t/update-node-roles-with-shards-assigned/325344)

<div class="topic-metadata">

**Author:** [@sachiko](https://discuss.elastic.co/u/sachiko)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:54pm UTC](https://discuss.elastic.co/t/update-node-roles-with-shards-assigned/325344 "2023-02-13T19:54:41Z")

</div>

Cluster is having 6 nodes, having the default role: cdfhilmrstw How to update the node.roles from all to master only. Note: node has already a shards assigned, containing .security-7 index. IF I run elasticsearch-nod…

---

## [Empty snapshots](https://discuss.elastic.co/t/empty-snapshots/325194)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 17\
**Last updated:** [February 13, 2023, 7:46pm UTC](https://discuss.elastic.co/t/empty-snapshots/325194 "2023-02-13T19:46:42Z")

</div>

Hi, I have a problem when trying to create and restore a snapshot in Elasticsearch. The snapshots are blank. Some specifications: I'm using a Mac (MacOS Monterey 12.6.2) if relevant. I'm running Elasticsearch in it a…

---

## [Elasticsearch Memory Optimization?](https://discuss.elastic.co/t/elasticsearch-memory-optimization/325335)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 5\
**Last updated:** [February 13, 2023, 4:23pm UTC](https://discuss.elastic.co/t/elasticsearch-memory-optimization/325335 "2023-02-13T16:23:13Z")

</div>

Hello, I have 64GB of RAM on my machine. I am trying to optimize the elasticsearch's performance by utilizing maximum possible hardware. I noticed that the elasticsearch is not utilizing as much RAM as allocated to it …

---

## [Scroll vs search after](https://discuss.elastic.co/t/scroll-vs-search-after/325396)

<div class="topic-metadata">

**Author:** [@Prabu\_P](https://discuss.elastic.co/u/Prabu_P)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:40pm UTC](https://discuss.elastic.co/t/scroll-vs-search-after/325396 "2023-02-13T14:40:27Z")

</div>

in this thread it discussed about the performance issue of search after , is this issue still present in newer versions of ES ?

---

## [Monitoring cluster shows no data](https://discuss.elastic.co/t/monitoring-cluster-shows-no-data/325387)

<div class="topic-metadata">

**Author:** [@Fangy](https://discuss.elastic.co/u/Fangy)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 1:52pm UTC](https://discuss.elastic.co/t/monitoring-cluster-shows-no-data/325387 "2023-02-13T13:52:48Z")

</div>

Hello, I have a question about monitoring, my monitoring cluster shows no data. "No monitoring data found". The installation in a few nodes production cluster and one node monitoring cluster (both are 8.6.1 now). Monito…

---

## [How to find a term (title: req.query\['q\]) with geo\_distance with elasticsearch 8.6](https://discuss.elastic.co/t/how-to-find-a-term-title-req-query-q-with-geo-distance-with-elasticsearch-8-6/325330)

<div class="topic-metadata">

**Author:** [@teoman\_kirac](https://discuss.elastic.co/u/teoman_kirac)\
**Replies:** 20\
**Last updated:** [February 13, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-find-a-term-title-req-query-q-with-geo-distance-with-elasticsearch-8-6/325330 "2023-02-13T13:48:39Z")

</div>

Years ago I had this working with elasticsearch 16.x.x. It looked like this: let body = { size: 200, from: 0, query: { bool: { must: { term: { title : req.query\['q'\] } }, …

---

## ["Rejected execution of coordinating operation" exception after upgrade from 8.2.2 to 8.6.0?](https://discuss.elastic.co/t/rejected-execution-of-coordinating-operation-exception-after-upgrade-from-8-2-2-to-8-6-0/323430)

<div class="topic-metadata">

**Author:** [@mbooh](https://discuss.elastic.co/u/mbooh)\
**Replies:** 7\
**Last updated:** [February 13, 2023, 1:11pm UTC](https://discuss.elastic.co/t/rejected-execution-of-coordinating-operation-exception-after-upgrade-from-8-2-2-to-8-6-0/323430 "2023-02-13T13:11:15Z")

</div>

Hi! We just upgraded from 8.2.2 to 8.6.0 and suddenly our bulk inserts fails with this exception: es\_rejected\_execution\_exception Reason: "rejected execution of coordinating operation \[coordinating\_and\_primary\_bytes=20…

---

## [\[ES 6.7\] Multiple field terms aggregation using scripts](https://discuss.elastic.co/t/es-6-7-multiple-field-terms-aggregation-using-scripts/325383)

<div class="topic-metadata">

**Author:** [@Hi\_Jonk](https://discuss.elastic.co/u/Hi_Jonk)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 12:44pm UTC](https://discuss.elastic.co/t/es-6-7-multiple-field-terms-aggregation-using-scripts/325383 "2023-02-13T12:44:46Z")

</div>

In the 6.7 documentation for Terms aggregation, the section on multi field aggregation says that 6.7 does not support multiple field aggregation, and to use scripts instead: Terms Aggregation | Elasticsearch Guide \[6.7\] …

---

## [ECK 2.6.1 node shutdown for invoice optimization](https://discuss.elastic.co/t/eck-2-6-1-node-shutdown-for-invoice-optimization/325374)

<div class="topic-metadata">

**Author:** [@screwyy](https://discuss.elastic.co/u/screwyy)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 12:33pm UTC](https://discuss.elastic.co/t/eck-2-6-1-node-shutdown-for-invoice-optimization/325374 "2023-02-13T12:33:43Z")

</div>

Hello, I'm running an ECK 2.6.1 elastic cluster in a non-prod k8s cluster which has a Horizontal Node Autoscale rule based on CPU+RAM metrics. Is it possible to shutdown elastic nodes on Friday night and start them bac…

---

## [Index not getting deleted as per ILM](https://discuss.elastic.co/t/index-not-getting-deleted-as-per-ilm/324700)

<div class="topic-metadata">

**Author:** [@RahulWagh](https://discuss.elastic.co/u/RahulWagh)\
**Replies:** 4\
**Last updated:** [February 13, 2023, 11:50am UTC](https://discuss.elastic.co/t/index-not-getting-deleted-as-per-ilm/324700 "2023-02-13T11:50:33Z")

</div>

Hi, We are using Elastic cloud version 7.17. We have created one index template and one ILM policy to delete indexes after 90 days. In th ILM we are not using rollover. Assigned this policy to index template. We hav…

---

## [If the file is deleted, delete from the ElasticSearch index](https://discuss.elastic.co/t/if-the-file-is-deleted-delete-from-the-elasticsearch-index/325314)

<div class="topic-metadata">

**Author:** [@SplendX](https://discuss.elastic.co/u/SplendX)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 11:43am UTC](https://discuss.elastic.co/t/if-the-file-is-deleted-delete-from-the-elasticsearch-index/325314 "2023-02-13T11:43:52Z")

</div>

I'm trying to make a piece of code that will be responsible for deleting an indexed file from the elasticsearch index, I pass with the indexed file md5(file name), to the id value. It is necessary to make sure that when …

---

## [Error 503 filebeat can not connect to elasticsearch](https://discuss.elastic.co/t/error-503-filebeat-can-not-connect-to-elasticsearch/325375)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 10:56am UTC](https://discuss.elastic.co/t/error-503-filebeat-can-not-connect-to-elasticsearch/325375 "2023-02-13T10:56:18Z")

</div>

Hi everyone I have up my ELK server working, and I put a filebeat in another machine with filebeat installed but filebeat can not send inputs to elasticsearch, the error says "Exiting: couldn't connect to any of the con…

---

## [Active alert from deleted rule](https://discuss.elastic.co/t/active-alert-from-deleted-rule/325270)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:53am UTC](https://discuss.elastic.co/t/active-alert-from-deleted-rule/325270 "2023-02-13T07:53:49Z")

</div>

Hi ! Using Elastic & kibana 8.6.1 with Elastic Agent. I'm trying to configure alerts and tried a few. I've been creating and deleting a dozen of alerts. Since two days, I'm still having an active alert from a deleted r…

---

## [Elasticsearch + Java - Can you further optimize this query?](https://discuss.elastic.co/t/elasticsearch-java-can-you-further-optimize-this-query/325357)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:15am UTC](https://discuss.elastic.co/t/elasticsearch-java-can-you-further-optimize-this-query/325357 "2023-02-13T07:15:28Z")

</div>

We have an elasticsearch that contains millions of records and we are using it for a global searching. However, our query takes 2-4 seconds to return result. Can somebody help or advice how to further optimize the follow…

---

## [Error code 429,Too Many Requests](https://discuss.elastic.co/t/error-code-429-too-many-requests/325332)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 4:37pm UTC](https://discuss.elastic.co/t/error-code-429-too-many-requests/325332 "2023-02-12T16:37:31Z")

</div>

Hi, What does error code 429,Too Many Requests actually means? Is the coordinator is fully loaded or the cluster is fully loaded? Thanks...

---

## [Rollover alias \[xxxx\] can point to multiple indices, found duplicated alias \[\[xxxx\]\] in index template](https://discuss.elastic.co/t/rollover-alias-xxxx-can-point-to-multiple-indices-found-duplicated-alias-xxxx-in-index-template/324802)

<div class="topic-metadata">

**Author:** [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Replies:** 3\
**Last updated:** [February 12, 2023, 10:54am UTC](https://discuss.elastic.co/t/rollover-alias-xxxx-can-point-to-multiple-indices-found-duplicated-alias-xxxx-in-index-template/324802 "2023-02-12T10:54:14Z")

</div>

Hi everyone, I have a problem with rollover. I'm getting an error as described in the title: Rollover alias \[xxxx\] can point to multiple indices, found duplicated alias \[\[xxxx\]\] in index template The indice, for si…

---

## [Elasticsearch throwing invalid attributes in log](https://discuss.elastic.co/t/elasticsearch-throwing-invalid-attributes-in-log/323355)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:55am UTC](https://discuss.elastic.co/t/elasticsearch-throwing-invalid-attributes-in-log/323355 "2023-02-12T01:55:50Z")

</div>

Hi, Elasticsearch log is been written as below: 2023-01-16 19:02:31,790 main ERROR Filters contains invalid attributes "onMatch", "onMismatch" In our log4j2.properties, we have included onMatch and onMismatch, what is…

---

## [Background Update of Millions of Documenrs Using NEST API](https://discuss.elastic.co/t/background-update-of-millions-of-documenrs-using-nest-api/325196)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 11\
**Last updated:** [February 11, 2023, 6:18pm UTC](https://discuss.elastic.co/t/background-update-of-millions-of-documenrs-using-nest-api/325196 "2023-02-11T18:18:24Z")

</div>

What is the most efficient way of updating Millions of documents in the background so that it has little effect on foreground operations such as Autocomplete and user searches. Thanks

---

## [During the backup some indices fails giving me this error](https://discuss.elastic.co/t/during-the-backup-some-indices-fails-giving-me-this-error/325308)

<div class="topic-metadata">

**Author:** [@Amal\_Ranjan\_Misra](https://discuss.elastic.co/u/Amal_Ranjan_Misra)\
**Replies:** 2\
**Last updated:** [February 11, 2023, 10:12am UTC](https://discuss.elastic.co/t/during-the-backup-some-indices-fails-giving-me-this-error/325308 "2023-02-11T10:12:17Z")

</div>

I need help on this "stage" : "FAILURE", "stats" : { "number\_of\_files" : 0, "processed\_files" : 0, "total\_size\_in\_bytes" : 0, "…

---

## [Question about data stream rollover timings](https://discuss.elastic.co/t/question-about-data-stream-rollover-timings/325073)

<div class="topic-metadata">

**Author:** [@xnn](https://discuss.elastic.co/u/xnn)\
**Replies:** 5\
**Last updated:** [February 11, 2023, 3:35am UTC](https://discuss.elastic.co/t/question-about-data-stream-rollover-timings/325073 "2023-02-11T03:35:04Z")

</div>

We're considering moving some large ES clusters from time-based indices to data streams. One concern we have is that with time-based indices we notice a delay between when the first event arrives and when the shards are …

---

## [Wildcard matches are not highlighted in complex query containing field\_masking\_span](https://discuss.elastic.co/t/wildcard-matches-are-not-highlighted-in-complex-query-containing-field-masking-span/325301)

<div class="topic-metadata">

**Author:** [@claudinoac](https://discuss.elastic.co/u/claudinoac)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 9:42pm UTC](https://discuss.elastic.co/t/wildcard-matches-are-not-highlighted-in-complex-query-containing-field-masking-span/325301 "2023-02-10T21:42:05Z")

</div>

I'm applying the unified highlighter to the query below and the matched terms are being correctly highlighted, except by the ones matched by the wildcard term. That happens only when there is a field\_masking\_span term i…

---

## [Failed to determine the health of the cluster](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/325290)

<div class="topic-metadata">

**Author:** [@goodeejay](https://discuss.elastic.co/u/goodeejay)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 8:56pm UTC](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/325290 "2023-02-10T20:56:57Z")

</div>

Hello, I've been trying to generate enrollment token for kibana with: sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s "kibana" But I'm getting an error, the last line says: ERROR: Failed to …

---

## [Query response time when search query hits across HOT and WARM phase in ILM](https://discuss.elastic.co/t/query-response-time-when-search-query-hits-across-hot-and-warm-phase-in-ilm/324699)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 12\
**Last updated:** [February 10, 2023, 6:02pm UTC](https://discuss.elastic.co/t/query-response-time-when-search-query-hits-across-hot-and-warm-phase-in-ilm/324699 "2023-02-10T18:02:58Z")

</div>

Hi Team, We have to implement HOT, WARM and COLD phase with ILM implementation as a part of our requirement, wherein the HOT phase Nodes are in SSD and the WARM and COLD are not. Most of the searches will be fired for …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=300)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=302)
