# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=309

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 310

---

## [On-premise pricing?](https://discuss.elastic.co/t/on-premise-pricing/324183)

<div class="topic-metadata">

**Author:** [@johber](https://discuss.elastic.co/u/johber)\
**Replies:** 6\
**Last updated:** [January 29, 2023, 8:28pm UTC](https://discuss.elastic.co/t/on-premise-pricing/324183 "2023-01-29T20:28:38Z")

</div>

Hello, I'm developing a public e-commerce site. Can it use a self hosted Elasticsearch instance for free, without violating the new license model?

---

## [Your trial license is expired help](https://discuss.elastic.co/t/your-trial-license-is-expired-help/324173)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 7\
**Last updated:** [January 29, 2023, 4:05pm UTC](https://discuss.elastic.co/t/your-trial-license-is-expired-help/324173 "2023-01-29T16:05:47Z")

</div>

Hi all, Please i use elasticsearch 8.0 version and i have my workspace so yesterday , kibana said Your trial license is expired Please your support i have all my dashbored I am afraid of losing my data and dashboard. …

---

## [How to add searched value with terms query results](https://discuss.elastic.co/t/how-to-add-searched-value-with-terms-query-results/324174)

<div class="topic-metadata">

**Author:** [@Nowrin\_Hossain](https://discuss.elastic.co/u/Nowrin_Hossain)\
**Replies:** 0\
**Last updated:** [January 29, 2023, 11:23am UTC](https://discuss.elastic.co/t/how-to-add-searched-value-with-terms-query-results/324174 "2023-01-29T11:23:39Z")

</div>

Hello, I want to do search an index with multiple values. I want to also know which search result comes for which searched value. Can I do this in case of terms query. e.g. GET /\_search { "query": { "terms": { …

---

## [2.4.1 groovy script aggregation make high cpu](https://discuss.elastic.co/t/2-4-1-groovy-script-aggregation-make-high-cpu/323107)

<div class="topic-metadata">

**Author:** [@huasheng\_zeng](https://discuss.elastic.co/u/huasheng_zeng)\
**Replies:** 2\
**Last updated:** [January 29, 2023, 4:04am UTC](https://discuss.elastic.co/t/2-4-1-groovy-script-aggregation-make-high-cpu/323107 "2023-01-29T04:04:25Z")

</div>

es version is 2.4.1 query request is {"aggregations":{"0-0":{"aggregations":{"0-1":{"aggregations":{"0-2":{"aggregations":{"1-0":{"aggregations":{"1-1":{"reverse\_nested":{}}},"filters":{"filters":\[{"script":{"script":{…

---

## [Transform not aligning checkpoints with date histogram](https://discuss.elastic.co/t/transform-not-aligning-checkpoints-with-date-histogram/324063)

<div class="topic-metadata">

**Author:** [@ddolcimascolo](https://discuss.elastic.co/u/ddolcimascolo)\
**Replies:** 6\
**Last updated:** [January 27, 2023, 9:41pm UTC](https://discuss.elastic.co/t/transform-not-aligning-checkpoints-with-date-histogram/324063 "2023-01-27T21:41:07Z")

</div>

Hi all. I'm using pivot transforms to group data by a date histogram and a few other terms dimensions. The transforms are running in continuous mode using the ingest timestamp as the sync.time.field but I'm grouping on …

---

## [ElasticSearch-8-5-2 ingest-pipeline issue](https://discuss.elastic.co/t/elasticsearch-8-5-2-ingest-pipeline-issue/324114)

<div class="topic-metadata">

**Author:** [@Pierre\_LANCASTRE](https://discuss.elastic.co/u/Pierre_LANCASTRE)\
**Replies:** 10\
**Last updated:** [January 27, 2023, 5:32pm UTC](https://discuss.elastic.co/t/elasticsearch-8-5-2-ingest-pipeline-issue/324114 "2023-01-27T17:32:26Z")

</div>

Hi all, I recently posted a problem on ingest-pipelines working in testing mode but finally not working. I have the same issue and i m still stuck while I ve tried many tricks (remove special characters from syslog stri…

---

## [How could i manage types in new versions ? another way?](https://discuss.elastic.co/t/how-could-i-manage-types-in-new-versions-another-way/324134)

<div class="topic-metadata">

**Author:** [@Anibal\_Ardid](https://discuss.elastic.co/u/Anibal_Ardid)\
**Replies:** 5\
**Last updated:** [January 27, 2023, 7:46pm UTC](https://discuss.elastic.co/t/how-could-i-manage-types-in-new-versions-another-way/324134 "2023-01-27T19:46:52Z")

</div>

Hi ! I'm new on elasticsearch indexing. And i'm trying to migrate from v5 to v8, i know this is a big change and challenge. I read about types are deprecated now. So , how could i manage my data ? Now I have 1 index…

---

## [Creating an index with existing index](https://discuss.elastic.co/t/creating-an-index-with-existing-index/323550)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 8:15pm UTC](https://discuss.elastic.co/t/creating-an-index-with-existing-index/323550 "2023-01-27T20:15:28Z")

</div>

Hello, I have many indexes named .ds-traces-apm-default-2022.12.12-000124 .ds-traces-apm-default-2022.12.17-000125 .ds-traces-apm-default-2022.12.20-000126 .ds-traces-apm-default-2022.12.22-000127 .ds-traces-apm-de…

---

## [Elastic search SaveJsontoEs Hadoop Libra dropping documents without throwing error or warning](https://discuss.elastic.co/t/elastic-search-savejsontoes-hadoop-libra-dropping-documents-without-throwing-error-or-warning/323384)

<div class="topic-metadata">

**Author:** [@Bhuvesh\_Seth](https://discuss.elastic.co/u/Bhuvesh_Seth)\
**Replies:** 8\
**Last updated:** [January 27, 2023, 7:51pm UTC](https://discuss.elastic.co/t/elastic-search-savejsontoes-hadoop-libra-dropping-documents-without-throwing-error-or-warning/323384 "2023-01-27T19:51:59Z")

</div>

Hi, we are using Elasticsearch Hadoop library to index the documents from Spark job. We are facing one weird issue where the documents are not getting indexed without throwing any error or exception. Method used: rdd.Sa…

---

## ["upgrade Assistant" is not visible under "management tab"](https://discuss.elastic.co/t/upgrade-assistant-is-not-visible-under-management-tab/324055)

<div class="topic-metadata">

**Author:** [@shahulyousuf](https://discuss.elastic.co/u/shahulyousuf)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 6:18pm UTC](https://discuss.elastic.co/t/upgrade-assistant-is-not-visible-under-management-tab/324055 "2023-01-27T18:18:38Z")

</div>

Hey, I'm new to elasticsearch, I have installed elasticsearch 8.5.2 in single node and configured Kibana. Now I'm trying to upgrade to 8.6.1 through upgrade assistant as elastic user but cant find the upgrade assistant…

---

## [Provided Grok expressions do not match field value](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/324133)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 6:04pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/324133 "2023-01-27T18:04:38Z")

</div>

Hi Team, I installed 7.12.1 filebeat and enabled apache module but I'm getting "error.message Provided Grok expressions do not match field value". I checked apache log format for my website.it seems like below; LogFo…

---

## [How to pass variable to the body section of script in webhook watcher?](https://discuss.elastic.co/t/how-to-pass-variable-to-the-body-section-of-script-in-webhook-watcher/324118)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 5:39pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-to-the-body-section-of-script-in-webhook-watcher/324118 "2023-01-27T17:39:48Z")

</div>

I have the following webhook watcher which creates OTRS ticket when there is a term "Error" in document. However right now the ticket body declared in script is a fixed string for now ( This is only a test). How to pa…

---

## [There is a way to use search\_after to restart an scroll?](https://discuss.elastic.co/t/there-is-a-way-to-use-search-after-to-restart-an-scroll/324128)

<div class="topic-metadata">

**Author:** [@Guillermo\_Garcia1](https://discuss.elastic.co/u/Guillermo_Garcia1)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 5:13pm UTC](https://discuss.elastic.co/t/there-is-a-way-to-use-search-after-to-restart-an-scroll/324128 "2023-01-27T17:13:45Z")

</div>

It is possible to start an scroll with search\_after ? The idea is to : Create an scroll with a good "sort" Iterate thanks to the scroll\_id and process each batch of docs If when asking for the next batch, a "search\_con…

---

## [java.lang.NullPointerException: Cannot invoke "java.util.List.stream()" because the return value of "org.elasticsearch.indices.NodeIndicesStats.getShardStats(org.elasticsearch.index.Index)" is null](https://discuss.elastic.co/t/java-lang-nullpointerexception-cannot-invoke-java-util-list-stream-because-the-return-value-of-org-elasticsearch-indices-nodeindicesstats-getshardstats-org-elasticsearch-index-index-is-null/324091)

<div class="topic-metadata">

**Author:** [@sasvmware](https://discuss.elastic.co/u/sasvmware)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 2:12pm UTC](https://discuss.elastic.co/t/java-lang-nullpointerexception-cannot-invoke-java-util-list-stream-because-the-return-value-of-org-elasticsearch-indices-nodeindicesstats-getshardstats-org-elasticsearch-index-index-is-null/324091 "2023-01-27T14:12:40Z")

</div>

Hi We are getting below in prod \[2023-01-26T23:55:54,079\]\[ERROR\]\[o.e.x.m.c.c.ClusterStatsCollector\] \[xxx-prd-elkmd1.xxxxxx.com\] collector \[cluster\_stats\] failed to collect data java.lang.NullPointerException: Cannot i…

---

## [Integración con Microsoft Exchange Online Message Trace](https://discuss.elastic.co/t/integracion-con-microsoft-exchange-online-message-trace/324111)

<div class="topic-metadata">

**Author:** [@Gonzalo\_Sandoval\_A](https://discuss.elastic.co/u/Gonzalo_Sandoval_A)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 1:29pm UTC](https://discuss.elastic.co/t/integracion-con-microsoft-exchange-online-message-trace/324111 "2023-01-27T13:29:49Z")

</div>

Hi, I need to integrate the Microsoft Exchange Online Message Trace, I am using the elastic agent integration and I don't know which url to put, please help as I think there is missing information and I am not very rela…

---

## [C# Elasticsearch 8.0.3+ 400 Bad Request media\_type\_header\_exception](https://discuss.elastic.co/t/c-elasticsearch-8-0-3-400-bad-request-media-type-header-exception/322816)

<div class="topic-metadata">

**Author:** [@KoalaBear](https://discuss.elastic.co/u/KoalaBear)\
**Replies:** 11\
**Last updated:** [January 27, 2023, 12:08pm UTC](https://discuss.elastic.co/t/c-elasticsearch-8-0-3-400-bad-request-media-type-header-exception/322816 "2023-01-27T12:08:39Z")

</div>

Just started with a new small project with Elasticsearch, while developing Elasticsearch it is currently running in Docker (docker-elk), with the added "http.cors" things: http.cors.enabled: true http.cors.allow-origin:…

---

## [Index changes notifications (document creation, update, deletion within the index / doc and more)](https://discuss.elastic.co/t/index-changes-notifications-document-creation-update-deletion-within-the-index-doc-and-more/324069)

<div class="topic-metadata">

**Author:** [@RAVI\_GOPALANI](https://discuss.elastic.co/u/RAVI_GOPALANI)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 10:11am UTC](https://discuss.elastic.co/t/index-changes-notifications-document-creation-update-deletion-within-the-index-doc-and-more/324069 "2023-01-27T10:11:09Z")

</div>

Hi, I am looking for alerting / notification for document creation, update, deletion within the index / doc. Does there any api available within the Elasticsearch / logstash for alerting the changes done at Index / Doc…

---

## [Single Server Single Node vs Single Server Multiple Node](https://discuss.elastic.co/t/single-server-single-node-vs-single-server-multiple-node/324081)

<div class="topic-metadata">

**Author:** [@sramana235](https://discuss.elastic.co/u/sramana235)\
**Replies:** 4\
**Last updated:** [January 27, 2023, 10:06am UTC](https://discuss.elastic.co/t/single-server-single-node-vs-single-server-multiple-node/324081 "2023-01-27T10:06:16Z")

</div>

As the title suggests, I wonder if it is better to configure a single node or multiple nodes when configuring a node on a single server. I understood that the reason for configuring multiple nodes can have the advantage…

---

## [Received plaintext http traffic on an https channel](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/324074)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 10:01am UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/324074 "2023-01-27T10:01:14Z")

</div>

Is it normal for this to appear as a warning in the elasticsearch logs? The first time I installed elasticsearch, this is what I saw in the elasticsearch logs. \[2023-01-27T06:18:35,815\]\[WARN \]\[o.e.x.s.t.n.SecurityNetty…

---

## [Query a field that has a colon](https://discuss.elastic.co/t/query-a-field-that-has-a-colon/323966)

<div class="topic-metadata">

**Author:** [@ilias\_ioannou](https://discuss.elastic.co/u/ilias_ioannou)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 9:34am UTC](https://discuss.elastic.co/t/query-a-field-that-has-a-colon/323966 "2023-01-27T09:34:21Z")

</div>

Hello, Is it possible to use elasticsearch dsl python client to implement a query that will run against a filed with colon? For example if a field is this properties.grid:code then a successfull query would be the foll…

---

## [Elastic cluster running out of space, can't get cluster health to green](https://discuss.elastic.co/t/elastic-cluster-running-out-of-space-cant-get-cluster-health-to-green/323906)

<div class="topic-metadata">

**Author:** [@lostsoul352](https://discuss.elastic.co/u/lostsoul352)\
**Replies:** 6\
**Last updated:** [January 27, 2023, 9:22am UTC](https://discuss.elastic.co/t/elastic-cluster-running-out-of-space-cant-get-cluster-health-to-green/323906 "2023-01-27T09:22:35Z")

</div>

I have a 2 node elastic cluster. I noticed that I was not able to add more data to it, and it turned out the filesystem space is over at the flood limit on both machines. So to try and recover from this I shut down the …

---

## [Java class ElasticsearchClient v. 7.17.8](https://discuss.elastic.co/t/java-class-elasticsearchclient-v-7-17-8/324041)

<div class="topic-metadata">

**Author:** [@habdank](https://discuss.elastic.co/u/habdank)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 7:43am UTC](https://discuss.elastic.co/t/java-class-elasticsearchclient-v-7-17-8/324041 "2023-01-27T07:43:26Z")

</div>

Hi, Java doc for ElasticsearchClient v. 7.17.8 ElasticsearchClient (java-client 7.17.8 API) states that ElasticsearchClient is java class. However using \<dependency\> \<groupId\>org.elasticsearch.clie…

---

## [Elasticsearch, Kibana does not work](https://discuss.elastic.co/t/elasticsearch-kibana-does-not-work/323472)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 16\
**Last updated:** [January 27, 2023, 6:45am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-does-not-work/323472 "2023-01-27T06:45:39Z")

</div>

I have an issue with Elasticsearch. After restarting ubuntu, Kibana does not show any logs.

---

## [Inconsistency in data stream rollover](https://discuss.elastic.co/t/inconsistency-in-data-stream-rollover/323883)

<div class="topic-metadata">

**Author:** [@sagarkhatri0605](https://discuss.elastic.co/u/sagarkhatri0605)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 6:32am UTC](https://discuss.elastic.co/t/inconsistency-in-data-stream-rollover/323883 "2023-01-27T06:32:33Z")

</div>

We want hourly rollover of the index and then index should get deleted after 12 hour. To achieve this we have created data stream with a ILM policy which rollover index every 1hr and then the index goes into the warm ph…

---

## [Restricting Kibana access](https://discuss.elastic.co/t/restricting-kibana-access/324080)

<div class="topic-metadata">

**Author:** [@aneeshks1982](https://discuss.elastic.co/u/aneeshks1982)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 2:23am UTC](https://discuss.elastic.co/t/restricting-kibana-access/324080 "2023-01-27T02:23:53Z")

</div>

Hi, I'm using Elastic cloud and Elasticsearch version-8.6.0. Elastic cloud and Kibana are now accessible from anywhere. Can I restrict the access to Elastic/Kibana only from a specific IP source? because I like to restr…

---

## [How to create a GeoShape intersect query with elastic java client v8.6.0](https://discuss.elastic.co/t/how-to-create-a-geoshape-intersect-query-with-elastic-java-client-v8-6-0/324025)

<div class="topic-metadata">

**Author:** [@yusufozcan](https://discuss.elastic.co/u/yusufozcan)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 5:53pm UTC](https://discuss.elastic.co/t/how-to-create-a-geoshape-intersect-query-with-elastic-java-client-v8-6-0/324025 "2023-01-26T17:53:30Z")

</div>

Hi! We have a geo shape field which we store multi polygons and we want to filter it with a coordinate. Desired search request is: "geo\_shape": { "area": { "shape": { "type": "point", "coordinates": …

---

## [Completion-Suggester that respects the number of word occurences](https://discuss.elastic.co/t/completion-suggester-that-respects-the-number-of-word-occurences/324031)

<div class="topic-metadata">

**Author:** [@Andromeda](https://discuss.elastic.co/u/Andromeda)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 2:59pm UTC](https://discuss.elastic.co/t/completion-suggester-that-respects-the-number-of-word-occurences/324031 "2023-01-26T14:59:21Z")

</div>

Hello there, is there a way that Completion-Suggesters deliver suggests depending on how often matching words appear in the completion fields of all documents? For example, imagine "thinks" appears in completion fields…

---

## [Number of Nested objects](https://discuss.elastic.co/t/number-of-nested-objects/324050)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 5:18pm UTC](https://discuss.elastic.co/t/number-of-nested-objects/324050 "2023-01-26T17:18:41Z")

</div>

Hi, Looking for a way to get the number of nested objects, for querying, sorting etc. For example: PUT my-index-000001 { "mappings": { "properties": { "some\_id": {"type": "long"}, "user": { "…

---

## [Access global document count from inside bucket script](https://discuss.elastic.co/t/access-global-document-count-from-inside-bucket-script/324040)

<div class="topic-metadata">

**Author:** [@bpax51](https://discuss.elastic.co/u/bpax51)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 3:48pm UTC](https://discuss.elastic.co/t/access-global-document-count-from-inside-bucket-script/324040 "2023-01-26T15:48:42Z")

</div>

Hello guys, I'm new to Elasticsearch and already having fun with aggregations but I'm facing an issue that I couldn't figure out. I have the following query, that will search my index within a date range, give me a lis…

---

## [Migrating from ES 5 to ES 8, problems in index](https://discuss.elastic.co/t/migrating-from-es-5-to-es-8-problems-in-index/323454)

<div class="topic-metadata">

**Author:** [@Anibal\_Ardid](https://discuss.elastic.co/u/Anibal_Ardid)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 2:17pm UTC](https://discuss.elastic.co/t/migrating-from-es-5-to-es-8-problems-in-index/323454 "2023-01-26T14:17:51Z")

</div>

Hi ! I have this json that i use to index { "settings":{ "number\_of\_shards":1, "number\_of\_replicas":0, "index.mapping.total\_fields.limit":100000, "analysis":{ "filter":{ …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=308)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=310)
