# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=32

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 33

---

## [Elasticsearch TLS through Ansible](https://discuss.elastic.co/t/elasticsearch-tls-through-ansible/378302)

<div class="topic-metadata">

**Author:** [@H\_TS](https://discuss.elastic.co/u/H_TS)\
**Replies:** 0\
**Last updated:** [May 19, 2025, 2:31pm UTC](https://discuss.elastic.co/t/elasticsearch-tls-through-ansible/378302 "2025-05-19T14:31:45Z")

</div>

Hello everybody, I am starting to lose it. I would love some assistance in setting up TLS on my Elasticsearch node. I have come quite a way, but I get stuck on trying to change the elastic user password in my ansible fil…

---

## [Struggling with TLS on Elasticsearch \[Ansible\]](https://discuss.elastic.co/t/struggling-with-tls-on-elasticsearch-ansible/378297)

<div class="topic-metadata">

**Author:** [@H\_TS](https://discuss.elastic.co/u/H_TS)\
**Replies:** 1\
**Last updated:** [May 19, 2025, 12:47pm UTC](https://discuss.elastic.co/t/struggling-with-tls-on-elasticsearch-ansible/378297 "2025-05-19T12:47:06Z")

</div>

Hello everyone, I am currently deploying an Elastic Stack on Azure VM's using Ansible. The installation of the components was ofcourse a walk in the park, but I can't seem to get TLS to work properly. Whenever I try to …

---

## [File Descriptors leak on upgrade to 8.17.3](https://discuss.elastic.co/t/file-descriptors-leak-on-upgrade-to-8-17-3/376685)

<div class="topic-metadata">

**Author:** [@Ricardo\_Ferreira](https://discuss.elastic.co/u/Ricardo_Ferreira)\
**Replies:** 3\
**Last updated:** [May 19, 2025, 11:48am UTC](https://discuss.elastic.co/t/file-descriptors-leak-on-upgrade-to-8-17-3/376685 "2025-05-19T11:48:39Z")

</div>

Hello, I've tried searching around the forum for potential similar issues but couldn't find anything related so apologies in advance if this issue has been raised before. I've completed an upgrade of our Elasticsearch …

---

## [Unable to generate enrollment-token for new elasticsearch node](https://discuss.elastic.co/t/unable-to-generate-enrollment-token-for-new-elasticsearch-node/378234)

<div class="topic-metadata">

**Author:** [@fabio.virive](https://discuss.elastic.co/u/fabio.virive)\
**Replies:** 3\
**Last updated:** [May 19, 2025, 11:35am UTC](https://discuss.elastic.co/t/unable-to-generate-enrollment-token-for-new-elasticsearch-node/378234 "2025-05-19T11:35:06Z")

</div>

When I use elasticsearch-create-enrollment-token -s node, to generate the token for enrol a new elastic node, I have the following error message: Unable to create enrollment token for scope \[node\] ERROR: Unable to crea…

---

## [Data mismatches happening while sending data to Elastic Search index using pyspark](https://discuss.elastic.co/t/data-mismatches-happening-while-sending-data-to-elastic-search-index-using-pyspark/377188)

<div class="topic-metadata">

**Author:** [@yolo1](https://discuss.elastic.co/u/yolo1)\
**Replies:** 5\
**Last updated:** [May 19, 2025, 10:24am UTC](https://discuss.elastic.co/t/data-mismatches-happening-while-sending-data-to-elastic-search-index-using-pyspark/377188 "2025-05-19T10:24:40Z")

</div>

Any idea why data sent through df.write. in pyspark the data doesn't match correctly . in the backend the data is correct.

---

## [How to know refresh interval of ES indexes?](https://discuss.elastic.co/t/how-to-know-refresh-interval-of-es-indexes/378282)

<div class="topic-metadata">

**Author:** [@philyeanaeknss](https://discuss.elastic.co/u/philyeanaeknss)\
**Replies:** 4\
**Last updated:** [May 19, 2025, 10:20am UTC](https://discuss.elastic.co/t/how-to-know-refresh-interval-of-es-indexes/378282 "2025-05-19T10:20:25Z")

</div>

I get ES indexes via /\_cat/indices endpoint. This tells me a number of documents for each index. I want to monitor such number and analyze it dynamic during three time intervals (minute/hour/day). But according inde…

---

## [How to get Elasticsearch index document count via HTTP request?](https://discuss.elastic.co/t/how-to-get-elasticsearch-index-document-count-via-http-request/378203)

<div class="topic-metadata">

**Author:** [@philyeanaeknss](https://discuss.elastic.co/u/philyeanaeknss)\
**Replies:** 2\
**Last updated:** [May 19, 2025, 9:07am UTC](https://discuss.elastic.co/t/how-to-get-elasticsearch-index-document-count-via-http-request/378203 "2025-05-19T09:07:27Z")

</div>

There's Elasticsearch Exporter and /metrics endpoint it returns es\_index\_document\_count fields. Is there an Elasticsearch API endpoint ables to return such data straight - without using exporters?

---

## [Location based recommendation](https://discuss.elastic.co/t/location-based-recommendation/374041)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 19, 2025, 6:29am UTC](https://discuss.elastic.co/t/location-based-recommendation/374041 "2025-05-19T06:29:17Z")

</div>

Hi team! I have a ecommerce usecase in which I want to show product recommendations based on user's geo location. eg) If they are from Chicago or somewhere cold (or even northern part of USA), as soon as the user logs i…

---

## [I want to use snapshot repositories to implement the archiving function of datastream streams](https://discuss.elastic.co/t/i-want-to-use-snapshot-repositories-to-implement-the-archiving-function-of-datastream-streams/378106)

<div class="topic-metadata">

**Author:** [@zhangzhihua](https://discuss.elastic.co/u/zhangzhihua)\
**Replies:** 1\
**Last updated:** [May 19, 2025, 6:04am UTC](https://discuss.elastic.co/t/i-want-to-use-snapshot-repositories-to-implement-the-archiving-function-of-datastream-streams/378106 "2025-05-19T06:04:29Z")

</div>

I want to leverage the snapshot repository in ES 8.18 to implement the archiving of the datastream. By saving the data to the object storage service, it enables restoration when needed. Suppose there are 10 indexes in a…

---

## [Unable to see logs in fleet integrations](https://discuss.elastic.co/t/unable-to-see-logs-in-fleet-integrations/378239)

<div class="topic-metadata">

**Author:** [@Ajeet](https://discuss.elastic.co/u/Ajeet)\
**Replies:** 1\
**Last updated:** [May 19, 2025, 5:23am UTC](https://discuss.elastic.co/t/unable-to-see-logs-in-fleet-integrations/378239 "2025-05-19T05:23:10Z")

</div>

I can see that the Fleet Agent is running, and the system-1 integration input shows as healthy, but I'm unable to see any logs. would someone assist on this, I installed fleet server on Master Elasticsearch node.

---

## [Best practices for ECK on EKS with multi-AZ nodegroups and EBS volumes during node upgrades](https://discuss.elastic.co/t/best-practices-for-eck-on-eks-with-multi-az-nodegroups-and-ebs-volumes-during-node-upgrades/378256)

<div class="topic-metadata">

**Author:** [@hormander](https://discuss.elastic.co/u/hormander)\
**Replies:** 0\
**Last updated:** [May 17, 2025, 10:49am UTC](https://discuss.elastic.co/t/best-practices-for-eck-on-eks-with-multi-az-nodegroups-and-ebs-volumes-during-node-upgrades/378256 "2025-05-17T10:49:52Z")

</div>

Hi all, I'm running an Elasticsearch cluster on EKS using the ECK operator and I'm trying to understand the best way to handle node upgrades in a multi-AZ setup, especially with EBS volumes involved. Here’s a simplifie…

---

## [Vector functions in script fields context](https://discuss.elastic.co/t/vector-functions-in-script-fields-context/378254)

<div class="topic-metadata">

**Author:** [@ksalomatin](https://discuss.elastic.co/u/ksalomatin)\
**Replies:** 0\
**Last updated:** [May 17, 2025, 12:02am UTC](https://discuss.elastic.co/t/vector-functions-in-script-fields-context/378254 "2025-05-17T00:02:18Z")

</div>

Hi! I need to compute two vector similarities during search and return them as fields. Both fields are needed for downstream processing, so I cannot use scoring context that only returns a single combined score. This ol…

---

## [Log Restoration](https://discuss.elastic.co/t/log-restoration/378143)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 8\
**Last updated:** [May 16, 2025, 9:56pm UTC](https://discuss.elastic.co/t/log-restoration/378143 "2025-05-16T21:56:34Z")

</div>

Hi Team, Please advise , Long back we have ELK cluster running on 5.x after some months we have upgraded to 6.8. After a year we got VAs and we have decided to upgrade the cluster from 6.8.x to 7.17 . We are facing one …

---

## [How to Speed Up Elasticsearch bool.should Queries with Long Text Fields (Simulating max\_query\_terms in MLT)](https://discuss.elastic.co/t/how-to-speed-up-elasticsearch-bool-should-queries-with-long-text-fields-simulating-max-query-terms-in-mlt/378211)

<div class="topic-metadata">

**Author:** [@Saleh\_AbuAli](https://discuss.elastic.co/u/Saleh_AbuAli)\
**Replies:** 0\
**Last updated:** [May 16, 2025, 8:30am UTC](https://discuss.elastic.co/t/how-to-speed-up-elasticsearch-bool-should-queries-with-long-text-fields-simulating-max-query-terms-in-mlt/378211 "2025-05-16T08:30:59Z")

</div>

When dealing with large text fields like abstract (which may contain 500+ terms), using a bool.should query with multiple match or term clauses can significantly impact performance due to the sheer number of terms Elasti…

---

## [Shutdown Elastic through API](https://discuss.elastic.co/t/shutdown-elastic-through-api/378194)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [May 15, 2025, 5:29pm UTC](https://discuss.elastic.co/t/shutdown-elastic-through-api/378194 "2025-05-15T17:29:40Z")

</div>

Hi Team, We have Elastic cluster running(self-managed) . We wanted to shutdown or restart the service without going to server. I followed this documentation node-lifecycle but it didn't work for me.

---

## [OpenCTI Deployment and Integration with Elastic SIEM – Optimizing IOC Ingestion](https://discuss.elastic.co/t/opencti-deployment-and-integration-with-elastic-siem-optimizing-ioc-ingestion/378185)

<div class="topic-metadata">

**Author:** [@Vishag\_Learning](https://discuss.elastic.co/u/Vishag_Learning)\
**Replies:** 1\
**Last updated:** [May 15, 2025, 3:53pm UTC](https://discuss.elastic.co/t/opencti-deployment-and-integration-with-elastic-siem-optimizing-ioc-ingestion/378185 "2025-05-15T15:53:55Z")

</div>

Hi Team, I am currently working on the deployment of OpenCTI (On-Prem) and its integration with Elastic SIEM (hosted on AWS Cloud) to enable alerting based on IOC matches. To optimize storage consumption on AWS, I am co…

---

## [How to work Index Template?](https://discuss.elastic.co/t/how-to-work-index-template/378159)

<div class="topic-metadata">

**Author:** [@Subin\_Lee](https://discuss.elastic.co/u/Subin_Lee)\
**Replies:** 1\
**Last updated:** [May 15, 2025, 3:45am UTC](https://discuss.elastic.co/t/how-to-work-index-template/378159 "2025-05-15T03:45:54Z")

</div>

Hi there! I'm using AWS Managed OpenSearch 2.17. I'm just wondering how to work Index Templates of Elasticsearch. I want to make Index Template in Dashboard of AWS OpenSearch. If I only define 'Number of primary shar…

---

## [Scrolling API Seems Inconsistent](https://discuss.elastic.co/t/scrolling-api-seems-inconsistent/377763)

<div class="topic-metadata">

**Author:** [@Moose](https://discuss.elastic.co/u/Moose)\
**Replies:** 10\
**Last updated:** [May 14, 2025, 10:03pm UTC](https://discuss.elastic.co/t/scrolling-api-seems-inconsistent/377763 "2025-05-14T22:03:10Z")

</div>

I'm using the .NET NEST client in my Azure function to retrieve data from our Elastic account. Some of the SearchAsync requests I make exceed the 10,000 search result limit and as such I have to use the ScrollAsync reque…

---

## [Cannot synchronize elasticsearch repo in TheForeman](https://discuss.elastic.co/t/cannot-synchronize-elasticsearch-repo-in-theforeman/377553)

<div class="topic-metadata">

**Author:** [@tiga](https://discuss.elastic.co/u/tiga)\
**Replies:** 2\
**Last updated:** [May 14, 2025, 11:48am UTC](https://discuss.elastic.co/t/cannot-synchronize-elasticsearch-repo-in-theforeman/377553 "2025-05-14T11:48:03Z")

</div>

I cannot synchronize Elasticsearch 8.x yum repository under https://artifacts.elastic.co/packages/8.x/yum The issue I got is: HTTP status code: 502 Response headers: {"Date"=\>"Sun, 27 Apr 2025 16:30:38 GMT", "Server"=\>"…

---

## [Please teach me search substrings in Elasticsearch query](https://discuss.elastic.co/t/please-teach-me-search-substrings-in-elasticsearch-query/378115)

<div class="topic-metadata">

**Author:** [@t\_rin](https://discuss.elastic.co/u/t_rin)\
**Replies:** 2\
**Last updated:** [May 14, 2025, 5:59am UTC](https://discuss.elastic.co/t/please-teach-me-search-substrings-in-elasticsearch-query/378115 "2025-05-14T05:59:52Z")

</div>

DELETE content-search-test PUT content-search-test { "mappings": { "properties": { "content": { "type": "text", "analyzer": "kuromoji\_analyzer", "f…

---

## [Migration to V8: kibana reporting-user depreciated](https://discuss.elastic.co/t/migration-to-v8-kibana-reporting-user-depreciated/378100)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [May 13, 2025, 9:03pm UTC](https://discuss.elastic.co/t/migration-to-v8-kibana-reporting-user-depreciated/378100 "2025-05-13T21:03:47Z")

</div>

basic license on version 7.17... I spent hours on this yesterday and failed to figure out how to use "kibana privileges" to allow reporting for users. the screenshot in the documentation do not match what I see. I res…

---

## [Custom mapping types in index templates are deprecated --](https://discuss.elastic.co/t/custom-mapping-types-in-index-templates-are-deprecated/378068)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [May 13, 2025, 1:58am UTC](https://discuss.elastic.co/t/custom-mapping-types-in-index-templates-are-deprecated/378068 "2025-05-13T01:58:19Z")

</div>

I am getting ready to move to version 8 (at last)... Under " deprecation issues" I get Custom mapping types in index templates are deprecated. I have never knowing used anything except \_type: doc and have never set up…

---

## [Need help with getting task list on a particular node](https://discuss.elastic.co/t/need-help-with-getting-task-list-on-a-particular-node/378096)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 1\
**Last updated:** [May 13, 2025, 6:25pm UTC](https://discuss.elastic.co/t/need-help-with-getting-task-list-on-a-particular-node/378096 "2025-05-13T18:25:58Z")

</div>

Sorry to post such simple request, but the new online documentation is really useless. The reference site to old doc is also useless because the searching feature is broken. I need to list all the tasks on a particular…

---

## [Migrate Elastic indexes betwewn v6 and v8](https://discuss.elastic.co/t/migrate-elastic-indexes-betwewn-v6-and-v8/377943)

<div class="topic-metadata">

**Author:** [@miguel4](https://discuss.elastic.co/u/miguel4)\
**Replies:** 6\
**Last updated:** [May 13, 2025, 12:23pm UTC](https://discuss.elastic.co/t/migrate-elastic-indexes-betwewn-v6-and-v8/377943 "2025-05-13T12:23:26Z")

</div>

Hello, I currently have a Stack ELK with version 6.x of Elastic whose data we want I have to migrate to v8.x. I want to migrate only the indexes. With dumps I have seen that it is impossible to do it directly without go…

---

## [Can we resue serialized ShardSearchRequest in coordinator? And reuse it among channels?](https://discuss.elastic.co/t/can-we-resue-serialized-shardsearchrequest-in-coordinator-and-reuse-it-among-channels/378067)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 2\
**Last updated:** [May 13, 2025, 9:56am UTC](https://discuss.elastic.co/t/can-we-resue-serialized-shardsearchrequest-in-coordinator-and-reuse-it-among-channels/378067 "2025-05-13T09:56:23Z")

</div>

When coordinator send ShardSearchRequest to data nodes, it need serialize this shard request many times for every shard, even these request are all the same. Can we just serialize it one time, and send it to different s…

---

## [Why is the file scanned as a non secure file?](https://discuss.elastic.co/t/why-is-the-file-scanned-as-a-non-secure-file/378018)

<div class="topic-metadata">

**Author:** [@matianyang1203](https://discuss.elastic.co/u/matianyang1203)\
**Replies:** 2\
**Last updated:** [May 13, 2025, 1:09am UTC](https://discuss.elastic.co/t/why-is-the-file-scanned-as-a-non-secure-file/378018 "2025-05-13T01:09:49Z")

</div>

c:/program files/elk/elasticsearch-8.15.0/data/indices/tdnqopoytdeizxdumput4w/0/index/\_dx.cfs, \_7t.cfs, \_6z.cfs. These files are scanned as suspicious Trojan files!

---

## [How to Elasticsearch Backup/Restore (User, Role, and Repository Settings)](https://discuss.elastic.co/t/how-to-elasticsearch-backup-restore-user-role-and-repository-settings/377995)

<div class="topic-metadata">

**Author:** [@Jinhee\_Jeong](https://discuss.elastic.co/u/Jinhee_Jeong)\
**Replies:** 3\
**Last updated:** [May 12, 2025, 11:59am UTC](https://discuss.elastic.co/t/how-to-elasticsearch-backup-restore-user-role-and-repository-settings/377995 "2025-05-12T11:59:20Z")

</div>

Hi there, I’ve set up an Elasticsearch cluster using Docker Compose with 3 Elasticsearch nodes and 1 Kibana — so a total of 4 Docker containers. I’m currently working on testing backup and restore functionality. First…

---

## [How can i generate UUID in nodejs](https://discuss.elastic.co/t/how-can-i-generate-uuid-in-nodejs/377231)

<div class="topic-metadata">

**Author:** [@parsamoloudi](https://discuss.elastic.co/u/parsamoloudi)\
**Replies:** 2\
**Last updated:** [May 12, 2025, 5:03am UTC](https://discuss.elastic.co/t/how-can-i-generate-uuid-in-nodejs/377231 "2025-05-12T05:03:31Z")

</div>

i want to generate unique id in my each document in NodeJS

---

## [Rollover Alternatives for Updating?](https://discuss.elastic.co/t/rollover-alternatives-for-updating/378013)

<div class="topic-metadata">

**Author:** [@mvkfg](https://discuss.elastic.co/u/mvkfg)\
**Replies:** 4\
**Last updated:** [May 11, 2025, 3:38pm UTC](https://discuss.elastic.co/t/rollover-alternatives-for-updating/378013 "2025-05-11T15:38:28Z")

</div>

Hi, I have an Elasticsearch setup which is running version 8.18.1, which is used for bulk data logging and searching. Initially, I was using the default settings, but once my index became larger than 20GB, I decided to …

---

## [How to remove filter alias from backing index of a data stream?](https://discuss.elastic.co/t/how-to-remove-filter-alias-from-backing-index-of-a-data-stream/378011)

<div class="topic-metadata">

**Author:** [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Replies:** 3\
**Last updated:** [May 11, 2025, 2:22pm UTC](https://discuss.elastic.co/t/how-to-remove-filter-alias-from-backing-index-of-a-data-stream/378011 "2025-05-11T14:22:10Z")

</div>

Hi, I have an alias in my index template for test data stream to let me query for data in the last few days like the following: { "recent": { "filter": { "range": { "@timestamp": { "gte": "…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=31)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=33)
