# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=307

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 308

---

## [Unable to escape special character using Java REST API](https://discuss.elastic.co/t/unable-to-escape-special-character-using-java-rest-api/324456)

<div class="topic-metadata">

**Author:** [@Avi\_Buk](https://discuss.elastic.co/u/Avi_Buk)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 7:33pm UTC](https://discuss.elastic.co/t/unable-to-escape-special-character-using-java-rest-api/324456 "2023-02-01T19:33:54Z")

</div>

Hi, I'm using query\_string which is Lucene-based, and when I'm trying to send a query with "role" field contains the string "INFRA-Server", it cannot find any results because of the "-" sign. I tried to escape it, but …

---

## [OFFSET query \_sql is not recognizing](https://discuss.elastic.co/t/offset-query-sql-is-not-recognizing/324473)

<div class="topic-metadata">

**Author:** [@SergioFF](https://discuss.elastic.co/u/SergioFF)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 7:21pm UTC](https://discuss.elastic.co/t/offset-query-sql-is-not-recognizing/324473 "2023-02-01T19:21:58Z")

</div>

Hello, I have version 8.5.2 of Elasticsearch and I am trying to use the OFFSET clause within a query, but it is not recognizing it, can this clause be used in the version we have? The query I am sending is as follows: G…

---

## [Can't Configure or Enable Security Features in Elasticsearch 8.4](https://discuss.elastic.co/t/cant-configure-or-enable-security-features-in-elasticsearch-8-4/323971)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 5\
**Last updated:** [February 1, 2023, 4:15pm UTC](https://discuss.elastic.co/t/cant-configure-or-enable-security-features-in-elasticsearch-8-4/323971 "2023-02-01T16:15:59Z")

</div>

Hello dears, I'm having trouble I'm following the tutorial below, and when I finish the configuration, when starting Kibana I get an error: Toturial: https://www.elastic.co/guide/en/elasticsearch/reference/current/sec…

---

## [Any way to migrate Legacy templates to composable templates?](https://discuss.elastic.co/t/any-way-to-migrate-legacy-templates-to-composable-templates/324454)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 4:01pm UTC](https://discuss.elastic.co/t/any-way-to-migrate-legacy-templates-to-composable-templates/324454 "2023-02-01T16:01:25Z")

</div>

I have migrated to elasticsearch 7.8, I was reading that some of the changes include the replacement of Legacy index templates to composable index templates and I would like support to find a guide that can help me to mi…

---

## [Move config folder to another location on Window (v8.6.0)](https://discuss.elastic.co/t/move-config-folder-to-another-location-on-window-v8-6-0/324446)

<div class="topic-metadata">

**Author:** [@ykara84](https://discuss.elastic.co/u/ykara84)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 2:53pm UTC](https://discuss.elastic.co/t/move-config-folder-to-another-location-on-window-v8-6-0/324446 "2023-02-01T14:53:03Z")

</div>

Hi, I have ES 8.6.0 on Windows (single-node). I am looking to move the config folder to another location. I have I have added two new environment variables: C:\\Windows\\system32\>echo %ES\_HOME% E:\\elk\\elasticsearch\\8.6.…

---

## [Which certificate do I need for an external Java client linked to a self-hosted docker Elasticsearch 8.x, since the self-signed http\_ca.crt does not function unless the Java client is installed locally on the same server?](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159)

<div class="topic-metadata">

**Author:** [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 2:06pm UTC](https://discuss.elastic.co/t/which-certificate-do-i-need-for-an-external-java-client-linked-to-a-self-hosted-docker-elasticsearch-8-x-since-the-self-signed-http-ca-crt-does-not-function-unless-the-java-client-is-installed-locally-on-the-same-server/324159 "2023-02-01T14:06:41Z")

</div>

I understand that when I set up a docker image of elasticsearch version 8.x, the security is automatically activated, and three certificates are produced in the config/certs/ directory, which are: http\_ca.crt: The CA …

---

## [Combining fields into one for performance?](https://discuss.elastic.co/t/combining-fields-into-one-for-performance/324433)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 1:59pm UTC](https://discuss.elastic.co/t/combining-fields-into-one-for-performance/324433 "2023-02-01T13:59:10Z")

</div>

I currently have 140 fields in my Elasticsearch index-based App Search Engine. I realized that 40 of those fields contain data that does not need to be indexed (it's display only data), so I marked them index:false in t…

---

## [Watcher - Actions conditions in foreach](https://discuss.elastic.co/t/watcher-actions-conditions-in-foreach/324349)

<div class="topic-metadata">

**Author:** [@v\_watch](https://discuss.elastic.co/u/v_watch)\
**Replies:** 4\
**Last updated:** [February 1, 2023, 1:56pm UTC](https://discuss.elastic.co/t/watcher-actions-conditions-in-foreach/324349 "2023-02-01T13:56:41Z")

</div>

Hello, I am trying to create a watcher that must send a different slack message depending on the field "state" from each log in the hits.hits The slack message must have: "color" = "good" if the state is finished "col…

---

## [Passing dotnet APM Agent settings in Docker And Kubernetes](https://discuss.elastic.co/t/passing-dotnet-apm-agent-settings-in-docker-and-kubernetes/324427)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 1:03pm UTC](https://discuss.elastic.co/t/passing-dotnet-apm-agent-settings-in-docker-and-kubernetes/324427 "2023-02-01T13:03:08Z")

</div>

Hello I am trying to enable elastic APM with asp dotnet application but not able to find any reference document which says it is possible to enable apm & rum for containerized asp dotnet application Kindly suggest if i…

---

## [Shared solution with SQL Server](https://discuss.elastic.co/t/shared-solution-with-sql-server/324416)

<div class="topic-metadata">

**Author:** [@Chen\_Shacham](https://discuss.elastic.co/u/Chen_Shacham)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 11:27am UTC](https://discuss.elastic.co/t/shared-solution-with-sql-server/324416 "2023-02-01T11:27:54Z")

</div>

hello. I am trying to connect ELK search with my existing SQL Server ecosystem. I have created a CLR that calls Elastic index with search parameters (using native POST request) and then convert (deseriale) the results…

---

## [Error on running Elasticsearch from the command line](https://discuss.elastic.co/t/error-on-running-elasticsearch-from-the-command-line/324305)

<div class="topic-metadata">

**Author:** [@umairsaeed](https://discuss.elastic.co/u/umairsaeed)\
**Replies:** 9\
**Last updated:** [February 1, 2023, 11:09am UTC](https://discuss.elastic.co/t/error-on-running-elasticsearch-from-the-command-line/324305 "2023-02-01T11:09:12Z")

</div>

I downloaded, unzipped, and run Elasticsearch from the command line successfully. But after closing the command line, I am trying to run the Elasticsearch from the command line again, but it is giving me an error "localh…

---

## [How to change start of the week in date\_histogram based on 1w interval in group\_by transformof pivot](https://discuss.elastic.co/t/how-to-change-start-of-the-week-in-date-histogram-based-on-1w-interval-in-group-by-transformof-pivot/323675)

<div class="topic-metadata">

**Author:** [@sagarkhatri0605](https://discuss.elastic.co/u/sagarkhatri0605)\
**Replies:** 4\
**Last updated:** [February 1, 2023, 10:55am UTC](https://discuss.elastic.co/t/how-to-change-start-of-the-week-in-date-histogram-based-on-1w-interval-in-group-by-transformof-pivot/323675 "2023-02-01T10:55:09Z")

</div>

I am trying to create a transform with group\_by date\_histogram for interval of 1w (1 week), by default Elasticsearch considers week as Monday-Sunday and aggregates data accordingly, I want the week to start from Sunday i…

---

## [Search Match for all tokens from decompound filter](https://discuss.elastic.co/t/search-match-for-all-tokens-from-decompound-filter/322483)

<div class="topic-metadata">

**Author:** [@florin\_olah](https://discuss.elastic.co/u/florin_olah)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/search-match-for-all-tokens-from-decompound-filter/322483 "2023-02-01T10:03:47Z")

</div>

Hello, I am trying to do the same thing described in the topic here: German compound words in an e-commerce search simple example: searching for "sprachkurs" which is tokenized as "sprachkurs, sprach, kurs" Desired re…

---

## [Watcher Alert with multi match](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/watcher-alert-with-multi-match/323831 "2023-02-01T10:03:36Z")

</div>

Hi Team , I am New to community, I want to set up the watcher alert on the logs with messages like following "message: The user has selected account 84900-1 has no limit left" Where 84900 is account type and 1 is sub…

---

## [ElasticsearchException\[failed to bind service\]; nested: IndexFormatTooNewException\[Format version is not supported](https://discuss.elastic.co/t/elasticsearchexception-failed-to-bind-service-nested-indexformattoonewexception-format-version-is-not-supported/324353)

<div class="topic-metadata">

**Author:** [@Doums\_D](https://discuss.elastic.co/u/Doums_D)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 9:46am UTC](https://discuss.elastic.co/t/elasticsearchexception-failed-to-bind-service-nested-indexformattoonewexception-format-version-is-not-supported/324353 "2023-02-01T09:46:57Z")

</div>

Hello everyone, I have a issue on my elasticsearch server. i extended the storage from 1To to 2To and after rebooting i never could restart my elasticsearch service. Here is what i have actually in my journalctl when i…

---

## [Runtime field kibana](https://discuss.elastic.co/t/runtime-field-kibana/324362)

<div class="topic-metadata">

**Author:** [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 9:45am UTC](https://discuss.elastic.co/t/runtime-field-kibana/324362 "2023-02-01T09:45:55Z")

</div>

hi, i want make three new field that capture alert, source address and destination address from message field. anyone can help me how to do it. i have try using runtime field, but i cannot extract the value from the mes…

---

## [Organisation of the document to index in the java API with a nested field](https://discuss.elastic.co/t/organisation-of-the-document-to-index-in-the-java-api-with-a-nested-field/324400)

<div class="topic-metadata">

**Author:** [@QuentinV](https://discuss.elastic.co/u/QuentinV)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 9:22am UTC](https://discuss.elastic.co/t/organisation-of-the-document-to-index-in-the-java-api-with-a-nested-field/324400 "2023-02-01T09:22:00Z")

</div>

Hello. In my project, I success to connect, create and index documents to an elasticsearch with the new java API but I want to index a file with an nested field and I don't find any information about it. Can you explai…

---

## [Error on disable data\_detection](https://discuss.elastic.co/t/error-on-disable-data-detection/324265)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 7:44am UTC](https://discuss.elastic.co/t/error-on-disable-data-detection/324265 "2023-02-01T07:44:27Z")

</div>

I'm trying to disable data\_detection via curl. I delete the shard curl -s -H 'Content-Type: application/json' -X DELETE 'http://localhost:9200/video?pretty' { "acknowledged" : true } then curl -H 'Content-Type: ap…

---

## [Upgrade Elasticsearch to 7.17.8](https://discuss.elastic.co/t/upgrade-elasticsearch-to-7-17-8/324391)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 7:27am UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-to-7-17-8/324391 "2023-02-01T07:27:09Z")

</div>

I'm trying to upgrade my elasticsearch to version 7.17.8 from version 7.14.0. I have a single instant with kibana and logstash included. Current version has quiet a lot of data so it's hard to back it up. When I upgr…

---

## [Pending\_tasks has millions of entries, many of with are exact duplicates of ilm-move-to-step](https://discuss.elastic.co/t/pending-tasks-has-millions-of-entries-many-of-with-are-exact-duplicates-of-ilm-move-to-step/324329)

<div class="topic-metadata">

**Author:** [@jmlucjav](https://discuss.elastic.co/u/jmlucjav)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 6:56pm UTC](https://discuss.elastic.co/t/pending-tasks-has-millions-of-entries-many-of-with-are-exact-duplicates-of-ilm-move-to-step/324329 "2023-01-31T18:56:58Z")

</div>

hi, I have a 7.10.2 cluster, quite large, with 10k indices, and we are having issues with millions of pending tasks being queued at some point. I managed to get a dump of them while they were just 2M, and I saw: 90% …

---

## [Runtime conditional](https://discuss.elastic.co/t/runtime-conditional/324210)

<div class="topic-metadata">

**Author:** [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Replies:** 7\
**Last updated:** [January 31, 2023, 6:39pm UTC](https://discuss.elastic.co/t/runtime-conditional/324210 "2023-01-31T18:39:59Z")

</div>

Hi, i get confuse how to set a new value for msg value from message field. i want set if message value == { "msg" : "ICMP flood" }, msg value will show only ICMP flood i have try this but getting error

---

## [Solving error 413 when using BulkAllObserver (NEST)](https://discuss.elastic.co/t/solving-error-413-when-using-bulkallobserver-nest/324356)

<div class="topic-metadata">

**Author:** [@Emil](https://discuss.elastic.co/u/Emil)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 4:03pm UTC](https://discuss.elastic.co/t/solving-error-413-when-using-bulkallobserver-nest/324356 "2023-01-31T16:03:51Z")

</div>

I'm using the C# NEST-api to index documents to elastic, with BulkAllObserver as described here: Indexing documents | Elasticsearch .NET Clients \[7.17\] | Elastic My documents are generally a few kB, but can sometimes be…

---

## [Data too large indices:data/read/search\[phase/query](https://discuss.elastic.co/t/data-too-large-indices-data-read-search-phase-query/323770)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 10\
**Last updated:** [January 31, 2023, 3:53pm UTC](https://discuss.elastic.co/t/data-too-large-indices-data-read-search-phase-query/323770 "2023-01-31T15:53:51Z")

</div>

Hi How I can increase such value ? for avoid any disturbance in read data over kibana \[parent\] Data too large, data for \[indices:data/read/search\[phase/query\]\] would be \[4093997030/3.8gb\], which is larger than the …

---

## [Elastic Platinum License Pricing](https://discuss.elastic.co/t/elastic-platinum-license-pricing/324317)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-platinum-license-pricing/324317 "2023-01-31T14:21:23Z")

</div>

Hello Can someone please help me with info on how to determine the pricing associated with the Platinum license using self-managed ELK instance and how that will vary with the volume of the data or the resources consump…

---

## [Best configuration for 3 Node Cluster](https://discuss.elastic.co/t/best-configuration-for-3-node-cluster/324318)

<div class="topic-metadata">

**Author:** [@sidchaug](https://discuss.elastic.co/u/sidchaug)\
**Replies:** 5\
**Last updated:** [January 31, 2023, 12:55pm UTC](https://discuss.elastic.co/t/best-configuration-for-3-node-cluster/324318 "2023-01-31T12:55:35Z")

</div>

HI There, Currently we having 3 ES nodes(node-1, node-2 and node-3 each of 3TB) , we are creating indexex on daily basic. When we run the command we note that we have 3 PRI & 3 Replicas, is this the best configuration? …

---

## [Elastic Search 8.3 integration Issue with Rest High Client 7.17.6](https://discuss.elastic.co/t/elastic-search-8-3-integration-issue-with-rest-high-client-7-17-6/323035)

<div class="topic-metadata">

**Author:** [@sidchaug](https://discuss.elastic.co/u/sidchaug)\
**Replies:** 6\
**Last updated:** [January 31, 2023, 9:34am UTC](https://discuss.elastic.co/t/elastic-search-8-3-integration-issue-with-rest-high-client-7-17-6/323035 "2023-01-31T09:34:08Z")

</div>

Hi Team, We are currently working on 6.3 Version of ES and 6.4v of RestHighLevelClient we are upgrading to ES 8.3v so the code written in earlier version of ES with RestHigh client we are facing challenges to upgrade. C…

---

## [Why does the query response time optimized significantly after disabling indices.queries.cache.size](https://discuss.elastic.co/t/why-does-the-query-response-time-optimized-significantly-after-disabling-indices-queries-cache-size/324204)

<div class="topic-metadata">

**Author:** [@xiaodid](https://discuss.elastic.co/u/xiaodid)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 8:18am UTC](https://discuss.elastic.co/t/why-does-the-query-response-time-optimized-significantly-after-disabling-indices-queries-cache-size/324204 "2023-01-31T08:18:17Z")

</div>

We have a ES 7.9.16 cluster which has 1 master node and 3 data nodes. Each data node has 31 Gb heap size. We created 2 indexes, each index contains 2.5 billion docs. The query response time is about 1 second while query…

---

## [What is the implication of making a large text field as keyword (using multi-fields)?](https://discuss.elastic.co/t/what-is-the-implication-of-making-a-large-text-field-as-keyword-using-multi-fields/324224)

<div class="topic-metadata">

**Author:** [@DarwinGoyal](https://discuss.elastic.co/u/DarwinGoyal)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 8:07am UTC](https://discuss.elastic.co/t/what-is-the-implication-of-making-a-large-text-field-as-keyword-using-multi-fields/324224 "2023-01-31T08:07:55Z")

</div>

What are the considerations that I should take into account while making a field as keyword? To provide some search capabilities I need to make a text field as keyword. I am not sure if there are any performance implica…

---

## [How to add password authorization](https://discuss.elastic.co/t/how-to-add-password-authorization/323713)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 14\
**Last updated:** [January 31, 2023, 7:52am UTC](https://discuss.elastic.co/t/how-to-add-password-authorization/323713 "2023-01-31T07:52:15Z")

</div>

Hi I've setup elk stack version 8.6.0. I've disabled authorization initially because ive installed it using a ansible playbook. by any way can i setup authorization from front end after i access kibana from front end?

---

## [Cluster\_block\_exception does not allow me to delete an index](https://discuss.elastic.co/t/cluster-block-exception-does-not-allow-me-to-delete-an-index/324218)

<div class="topic-metadata">

**Author:** [@DarwinGoyal](https://discuss.elastic.co/u/DarwinGoyal)\
**Replies:** 6\
**Last updated:** [January 31, 2023, 7:50am UTC](https://discuss.elastic.co/t/cluster-block-exception-does-not-allow-me-to-delete-an-index/324218 "2023-01-31T07:50:46Z")

</div>

I created one index with "blocks.metadata": true. PUT darwin-test-shard/\_settings { "blocks.metadata": true } Now whenever I try to access \_cat/indices, I get { "error" : { "root\_cause" : \[ { "ty…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=306)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=308)
