# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=33

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 34

---

## [Transform script fails to index into destination data stream](https://discuss.elastic.co/t/transform-script-fails-to-index-into-destination-data-stream/378012)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [May 11, 2025, 11:52am UTC](https://discuss.elastic.co/t/transform-script-fails-to-index-into-destination-data-stream/378012 "2025-05-11T11:52:02Z")

</div>

I'm on v.8.18 and trying to make my first transform script which should correlate a start and end event from a source index and then calculate the process time in ms as the time difference between start and end events an…

---

## [Keyword or short type more perf for heavily used filter field?](https://discuss.elastic.co/t/keyword-or-short-type-more-perf-for-heavily-used-filter-field/376744)

<div class="topic-metadata">

**Author:** [@jmlucjav](https://discuss.elastic.co/u/jmlucjav)\
**Replies:** 7\
**Last updated:** [May 10, 2025, 7:47pm UTC](https://discuss.elastic.co/t/keyword-or-short-type-more-perf-for-heavily-used-filter-field/376744 "2025-05-10T19:47:34Z")

</div>

hi, I have a field (low cardinality enumeration), I know will be used in almost all queries as a filter. Usual pick is as a keyword of course. But then the query cache is not used. keyword are supposed to be so fast t…

---

## [Which 2 fields in Elastic Search can be made as time unsync comparsion?](https://discuss.elastic.co/t/which-2-fields-in-elastic-search-can-be-made-as-time-unsync-comparsion/378007)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 9\
**Last updated:** [May 10, 2025, 4:26pm UTC](https://discuss.elastic.co/t/which-2-fields-in-elastic-search-can-be-made-as-time-unsync-comparsion/378007 "2025-05-10T16:26:45Z")

</div>

{ "query": { "query\_string": { "query": "("NTP server status changes to unreachable" OR "Global time setting changed by NTP") AND devname:(ABC)", "default\_field": "logdesc" } } }

---

## [NTP server time sync issue - how to write alerts (Query DSL )](https://discuss.elastic.co/t/ntp-server-time-sync-issue-how-to-write-alerts-query-dsl/378006)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 3\
**Last updated:** [May 10, 2025, 3:14pm UTC](https://discuss.elastic.co/t/ntp-server-time-sync-issue-how-to-write-alerts-query-dsl/378006 "2025-05-10T15:14:12Z")

</div>

NTP server time sync issue

---

## [Creating vector index from SharePoint Online data](https://discuss.elastic.co/t/creating-vector-index-from-sharepoint-online-data/378000)

<div class="topic-metadata">

**Author:** [@UNNIE\_Ayilliath](https://discuss.elastic.co/u/UNNIE_Ayilliath)\
**Replies:** 0\
**Last updated:** [May 9, 2025, 9:35pm UTC](https://discuss.elastic.co/t/creating-vector-index-from-sharepoint-online-data/378000 "2025-05-09T21:35:46Z")

</div>

I am trying to implement a vector index using ELSER2. The data source is SharePoint Online and I have used the Elasticsearch SharePoint Online connector to ingest data into the index with DLS enabled. I followed this bl…

---

## [Clarification regarding java api](https://discuss.elastic.co/t/clarification-regarding-java-api/377957)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [May 9, 2025, 5:17pm UTC](https://discuss.elastic.co/t/clarification-regarding-java-api/377957 "2025-05-09T17:17:23Z")

</div>

Is this only applicable to java code? Python will still continue to use rest call? I am having a very difficult time to find a documentation with comprehensive examples of various calls using java api; therefore, it's …

---

## [Adaptive Replica Selection and knn load balancing](https://discuss.elastic.co/t/adaptive-replica-selection-and-knn-load-balancing/377991)

<div class="topic-metadata">

**Author:** [@peedeeboy](https://discuss.elastic.co/u/peedeeboy)\
**Replies:** 0\
**Last updated:** [May 9, 2025, 1:55pm UTC](https://discuss.elastic.co/t/adaptive-replica-selection-and-knn-load-balancing/377991 "2025-05-09T13:55:54Z")

</div>

hey friends :wave: I posted previously about our efforts on optimising our dedicated knn cluster. The latest thing we've been trying to understand / solve is why when we run load/stress testing, we often see 1 or 2 nod…

---

## [Is Self Inner Join Supported in ES?](https://discuss.elastic.co/t/is-self-inner-join-supported-in-es/377906)

<div class="topic-metadata">

**Author:** [@sekarvicky73](https://discuss.elastic.co/u/sekarvicky73)\
**Replies:** 2\
**Last updated:** [May 9, 2025, 1:36pm UTC](https://discuss.elastic.co/t/is-self-inner-join-supported-in-es/377906 "2025-05-09T13:36:40Z")

</div>

is possible to the below DB in query in Elasticsearch in SIngle query. SELECT \* FROM ADSMFolderDetails a INNER JOIN ADSMFolderDetails b ON a.parent\_path = b.path AND a.perm = b.perm AND a.sid = b.sid

---

## [WP-CLI: Please complete the setup of your index options. There is no index configured for searching](https://discuss.elastic.co/t/wp-cli-please-complete-the-setup-of-your-index-options-there-is-no-index-configured-for-searching/377841)

<div class="topic-metadata">

**Author:** [@Flavius\_V](https://discuss.elastic.co/u/Flavius_V)\
**Replies:** 1\
**Last updated:** [May 9, 2025, 1:33pm UTC](https://discuss.elastic.co/t/wp-cli-please-complete-the-setup-of-your-index-options-there-is-no-index-configured-for-searching/377841 "2025-05-09T13:33:13Z")

</div>

Hi, we try running a wp-cli command to run a sync to index our existing content in Elasticsearch, using Elasticpress plugin. We are using the following WP-CLI command: wp elasticpress sync --force --setup --show-errors…

---

## [How to send raw JSON queries with Elasticsearch Java Client 8](https://discuss.elastic.co/t/how-to-send-raw-json-queries-with-elasticsearch-java-client-8/377922)

<div class="topic-metadata">

**Author:** [@Daniel\_Abadi](https://discuss.elastic.co/u/Daniel_Abadi)\
**Replies:** 2\
**Last updated:** [May 9, 2025, 10:48am UTC](https://discuss.elastic.co/t/how-to-send-raw-json-queries-with-elasticsearch-java-client-8/377922 "2025-05-09T10:48:42Z")

</div>

Hello, I’m currently migrating from Elasticsearch 7 to 8 in a Java application, and I’m running into issues when trying to perform searches using raw JSON queries. In Elasticsearch 7, I used the Low Level REST Client l…

---

## ["Start a multi-node cluster with Docker Compose" example does not work on 8.18.0](https://discuss.elastic.co/t/start-a-multi-node-cluster-with-docker-compose-example-does-not-work-on-8-18-0/377689)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 7\
**Last updated:** [May 8, 2025, 8:05pm UTC](https://discuss.elastic.co/t/start-a-multi-node-cluster-with-docker-compose-example-does-not-work-on-8-18-0/377689 "2025-05-08T20:05:32Z")

</div>

I followed the instructions in "Start a multi-node cluster with Docker Compose" to create a Elasticsearch/Kibana cluster on my machine. The Elasticsearch nodes start but cannot be connected to. My docker-compose.yml is …

---

## [Multi-Tenant](https://discuss.elastic.co/t/multi-tenant/377944)

<div class="topic-metadata">

**Author:** [@khaled7](https://discuss.elastic.co/u/khaled7)\
**Replies:** 3\
**Last updated:** [May 8, 2025, 2:11pm UTC](https://discuss.elastic.co/t/multi-tenant/377944 "2025-05-08T14:11:43Z")

</div>

hello Elastic Team I am detailing my scenario here. iam working with many customer wihth ELK and want a free open source solution to make multi-tenant monitor all those clients from one view internal in my company all…

---

## [S3 snapshot causing nodes to drop from cluster](https://discuss.elastic.co/t/s3-snapshot-causing-nodes-to-drop-from-cluster/377918)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 8\
**Last updated:** [May 8, 2025, 2:07pm UTC](https://discuss.elastic.co/t/s3-snapshot-causing-nodes-to-drop-from-cluster/377918 "2025-05-08T14:07:36Z")

</div>

Since upgrading to 8.17.2, and even now on 8.18.0, snapshots to S3 are causing nodes to drop out of the cluster due to the 'followers check retry count exceeded' error. This seems to be happening only on cold data nodes…

---

## [Elastic refuses to balance disks, trying to send data to full cold disks, why?](https://discuss.elastic.co/t/elastic-refuses-to-balance-disks-trying-to-send-data-to-full-cold-disks-why/377923)

<div class="topic-metadata">

**Author:** [@Dave\_Houser](https://discuss.elastic.co/u/Dave_Houser)\
**Replies:** 4\
**Last updated:** [May 8, 2025, 12:56pm UTC](https://discuss.elastic.co/t/elastic-refuses-to-balance-disks-trying-to-send-data-to-full-cold-disks-why/377923 "2025-05-08T12:56:58Z")

</div>

We found a couple weeks ago that our 3 node cold storage was filling up. It got to ~90% full. We added 3 more cold nodes around this time before it got past ~90% full. After doing so elastic slowly started removing data …

---

## [Updating the license will clear the query cache](https://discuss.elastic.co/t/updating-the-license-will-clear-the-query-cache/377935)

<div class="topic-metadata">

**Author:** [@hanbj](https://discuss.elastic.co/u/hanbj)\
**Replies:** 0\
**Last updated:** [May 8, 2025, 11:15am UTC](https://discuss.elastic.co/t/updating-the-license-will-clear-the-query-cache/377935 "2025-05-08T11:15:01Z")

</div>

Due to the expiration of the license, a large number of clusters' licenses were updated at once today. Some clusters in the production environment experienced an increase in query time. Through monitoring, it was found t…

---

## [Prevent standard tokenizer from tokenizing \<IDEOGRAPHIC\> token per character](https://discuss.elastic.co/t/prevent-standard-tokenizer-from-tokenizing-ideographic-token-per-character/377797)

<div class="topic-metadata">

**Author:** [@yukha-dw](https://discuss.elastic.co/u/yukha-dw)\
**Replies:** 1\
**Last updated:** [May 8, 2025, 9:56am UTC](https://discuss.elastic.co/t/prevent-standard-tokenizer-from-tokenizing-ideographic-token-per-character/377797 "2025-05-08T09:56:32Z")

</div>

Hello, is it possible to use N-Gram Filter on each \<IDEOGRAPHIC\> phrase just like how it works on \<HANGUL\>? For example (min\_gram=max\_gram=2 & preserve\_original): Input: "我 爱 青苹果" Desired Output: "我", "爱", "青苹", "苹果",…

---

## [How does Elastic know that previous version is less than 8.18.0?](https://discuss.elastic.co/t/how-does-elastic-know-that-previous-version-is-less-than-8-18-0/377924)

<div class="topic-metadata">

**Author:** [@Andy\_Beckham](https://discuss.elastic.co/u/Andy_Beckham)\
**Replies:** 2\
**Last updated:** [May 7, 2025, 8:34pm UTC](https://discuss.elastic.co/t/how-does-elastic-know-that-previous-version-is-less-than-8-18-0/377924 "2025-05-07T20:34:48Z")

</div>

I'm upgrading Elasticsearch to the latest version 9.0.1. After installing I am getting an error saying I first need to upgrade to 8.18.0 before jump to 9.0.1. No problem if I'm upgrading manually, but I need this to wo…

---

## [Is it possible to search more than two occurrences](https://discuss.elastic.co/t/is-it-possible-to-search-more-than-two-occurrences/377837)

<div class="topic-metadata">

**Author:** [@shkhan](https://discuss.elastic.co/u/shkhan)\
**Replies:** 1\
**Last updated:** [May 7, 2025, 4:39pm UTC](https://discuss.elastic.co/t/is-it-possible-to-search-more-than-two-occurrences/377837 "2025-05-07T16:39:23Z")

</div>

I want to search keyword 'elastic' in a post which contains more than two occurrences.

---

## [Slow Ingestion of Final Log Chunks (Filebeat + Logstash + Elasticsearch)](https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214)

<div class="topic-metadata">

**Author:** [@RafaelXokito](https://discuss.elastic.co/u/RafaelXokito)\
**Replies:** 22\
**Last updated:** [May 7, 2025, 1:08pm UTC](https://discuss.elastic.co/t/slow-ingestion-of-final-log-chunks-filebeat-logstash-elasticsearch/377214 "2025-05-07T13:08:54Z")

</div>

Setup We are using the ELK stack to ingest logs from a file share. The logs are pre-existing files, and ingestion starts from scratch when the stack is brought up. Our setup: Elasticsearch 6 GB heap 6 replicas L…

---

## [Disable ML](https://discuss.elastic.co/t/disable-ml/377891)

<div class="topic-metadata">

**Author:** [@divadpoc](https://discuss.elastic.co/u/divadpoc)\
**Replies:** 4\
**Last updated:** [May 7, 2025, 12:42pm UTC](https://discuss.elastic.co/t/disable-ml/377891 "2025-05-07T12:42:33Z")

</div>

Hi. I just want to use the Basic license. Is there any benefit when I enable ML? Or any disadvantage when disabling ML? I don't seem to be able to find any documentation what benefits I get when using just the basic lic…

---

## [:distribution:bwc:maintenance:createClone error during build](https://discuss.elastic.co/t/bwccreateclone-error-during-build/377815)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 1\
**Last updated:** [May 7, 2025, 8:28am UTC](https://discuss.elastic.co/t/bwccreateclone-error-during-build/377815 "2025-05-07T08:28:00Z")

</div>

while trying to go through the elasticsearch build process i am getting error related to task :distribution:bwc:maintenance:createClone, it seems to have something with backward compatibility check (just guessing) and i …

---

## [Wazuh Integration Issue: API Version & Alerts Index Pattern Failing in ELK Stack](https://discuss.elastic.co/t/wazuh-integration-issue-api-version-alerts-index-pattern-failing-in-elk-stack/377877)

<div class="topic-metadata">

**Author:** [@heli0s](https://discuss.elastic.co/u/heli0s)\
**Replies:** 1\
**Last updated:** [May 7, 2025, 1:43am UTC](https://discuss.elastic.co/t/wazuh-integration-issue-api-version-alerts-index-pattern-failing-in-elk-stack/377877 "2025-05-07T01:43:00Z")

</div>

Hi everyone, I am working on integrating Wazuh Manager (v4.10.1) with the ELK Stack (v7.10.2). Both are hosted on separate virtual machines: Wazuh Manager: Running on one VM (Wazuh GUI works fine). ELK Stack: Running …

---

## [Shrink of shard fails with error "source primary is allocated on another node"](https://discuss.elastic.co/t/shrink-of-shard-fails-with-error-source-primary-is-allocated-on-another-node/320360)

<div class="topic-metadata">

**Author:** [@Thomas\_Hasfjord](https://discuss.elastic.co/u/Thomas_Hasfjord)\
**Replies:** 7\
**Last updated:** [May 6, 2025, 6:25pm UTC](https://discuss.elastic.co/t/shrink-of-shard-fails-with-error-source-primary-is-allocated-on-another-node/320360 "2025-05-06T18:25:20Z")

</div>

We are running an ElasticCloud Cluster with 3 nodes and recently made a change to the lifecycle policy of one of our Data Streams: from: { "policy": { "phases": { "hot": { "actions": { "ro…

---

## [Enrich Processor Not Working with Ingest Pipeline + Fleet Data Streams](https://discuss.elastic.co/t/enrich-processor-not-working-with-ingest-pipeline-fleet-data-streams/377809)

<div class="topic-metadata">

**Author:** [@mehrad\_ghalibafi](https://discuss.elastic.co/u/mehrad_ghalibafi)\
**Replies:** 2\
**Last updated:** [May 6, 2025, 12:31pm UTC](https://discuss.elastic.co/t/enrich-processor-not-working-with-ingest-pipeline-fleet-data-streams/377809 "2025-05-06T12:31:12Z")

</div>

Hi everyone, I'm building a small CTI platform where threat intelligence feeds (containing file hashes, IPs, etc.) are indexed into a custom index called tip\_index. I want to correlate fields like threat.indicator.file.…

---

## [Docs for indexing a document leads to an error \[Elasticsearch.NET 8.13.12\]](https://discuss.elastic.co/t/docs-for-indexing-a-document-leads-to-an-error-elasticsearch-net-8-13-12/359842)

<div class="topic-metadata">

**Author:** [@Motsols](https://discuss.elastic.co/u/Motsols)\
**Replies:** 3\
**Last updated:** [May 6, 2025, 12:28pm UTC](https://discuss.elastic.co/t/docs-for-indexing-a-document-leads-to-an-error-elasticsearch-net-8-13-12/359842 "2025-05-06T12:28:49Z")

</div>

I'm using the latest .NET client for elasticsearch. The docs shows this as an example of how to index documents: Getting started | Elasticsearch .NET Client \[8.9\] | Elastic When writing the same code in VS Community 20…

---

## [Migrate ElasticSearch Cluster to arm64](https://discuss.elastic.co/t/migrate-elasticsearch-cluster-to-arm64/377746)

<div class="topic-metadata">

**Author:** [@DanielR1](https://discuss.elastic.co/u/DanielR1)\
**Replies:** 8\
**Last updated:** [May 6, 2025, 8:45am UTC](https://discuss.elastic.co/t/migrate-elasticsearch-cluster-to-arm64/377746 "2025-05-06T08:45:56Z")

</div>

Hello! We have some big clusters installed on amd64 VMs. Given arm VMs are much cheaper we are considering moving these clusters to arm64. For example for 7.12.1 ES version, it would be possible to switch to arm64 VMs …

---

## [Can't execute the elasticsearch-reset-password script](https://discuss.elastic.co/t/cant-execute-the-elasticsearch-reset-password-script/377825)

<div class="topic-metadata">

**Author:** [@Khoa\_Bui](https://discuss.elastic.co/u/Khoa_Bui)\
**Replies:** 2\
**Last updated:** [May 5, 2025, 11:00pm UTC](https://discuss.elastic.co/t/cant-execute-the-elasticsearch-reset-password-script/377825 "2025-05-05T23:00:53Z")

</div>

Hi, I am starting a fresh installation of elasticsearch on RPM using the instruction here. I got to step 6, and it doesn't seem to work: \[root@es-hscore1 elasticsearch\]# curl --cacert /etc/elasticsearch/certs/http\_ca…

---

## [How to send proxy log to ELK? USE LOGSTASH?](https://discuss.elastic.co/t/how-to-send-proxy-log-to-elk-use-logstash/377774)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 3\
**Last updated:** [May 5, 2025, 5:03am UTC](https://discuss.elastic.co/t/how-to-send-proxy-log-to-elk-use-logstash/377774 "2025-05-05T05:03:38Z")

</div>

How to send proxy log to ELK ? may I have details sharing ? Thanks

---

## [Exclude symbol "-" does not work to filter out indices](https://discuss.elastic.co/t/exclude-symbol-does-not-work-to-filter-out-indices/377787)

<div class="topic-metadata">

**Author:** [@ChatLee](https://discuss.elastic.co/u/ChatLee)\
**Replies:** 0\
**Last updated:** [May 5, 2025, 2:01am UTC](https://discuss.elastic.co/t/exclude-symbol-does-not-work-to-filter-out-indices/377787 "2025-05-05T02:01:19Z")

</div>

Hi teams, I want to setup some snapshot settings, and I want to only back up indices those name start with non-dot, I tried with pattern " -.\* " and " \*, -.\* ", but found these patterns does not work. I tried to setup …

---

## [It's posible to create an Advanced Search page in WP powered by Elastic Search](https://discuss.elastic.co/t/its-posible-to-create-an-advanced-search-page-in-wp-powered-by-elastic-search/366788)

<div class="topic-metadata">

**Author:** [@Flavius\_V](https://discuss.elastic.co/u/Flavius_V)\
**Replies:** 1\
**Last updated:** [September 19, 2024, 5:38pm UTC](https://discuss.elastic.co/t/its-posible-to-create-an-advanced-search-page-in-wp-powered-by-elastic-search/366788 "2024-09-19T17:38:52Z")

</div>

Hi Team, I have no experience with Elastic Search, I have read a lot about it, and I found it awesome. I would like to adopt and integtate Elastic Search in a content website which is based on Wordpress. The website ru…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=32)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=34)
