# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=34

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 35

---

## [Jdk is damaged when running elacticsearch in Mac](https://discuss.elastic.co/t/jdk-is-damaged-when-running-elacticsearch-in-mac/377582)

<div class="topic-metadata">

**Author:** [@Alakser](https://discuss.elastic.co/u/Alakser)\
**Replies:** 5\
**Last updated:** [May 3, 2025, 9:56pm UTC](https://discuss.elastic.co/t/jdk-is-damaged-when-running-elacticsearch-in-mac/377582 "2025-05-03T21:56:22Z")

</div>

Hello forum, I just recently installed elasticsearch on a MacBook. After a successfully unpacking and trying to run bin/elasticsearch I get the following popup message "idk is damaged". I have tried: xattr -d com.app…

---

## [Nodes regularly out of heap](https://discuss.elastic.co/t/nodes-regularly-out-of-heap/377704)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 1\
**Last updated:** [May 3, 2025, 4:05am UTC](https://discuss.elastic.co/t/nodes-regularly-out-of-heap/377704 "2025-05-03T04:05:51Z")

</div>

Hi, Recently we are experiencing unexpected elasticsearch node restarts with Terminating due to java.lang.OutOfMemoryError: Java heap space. We do not exactly know why this happens and what is causing it. We have been …

---

## [OOM since 8.16.1 with openjdk23](https://discuss.elastic.co/t/oom-since-8-16-1-with-openjdk23/371395)

<div class="topic-metadata">

**Author:** [@ALIT](https://discuss.elastic.co/u/ALIT)\
**Replies:** 32\
**Last updated:** [May 2, 2025, 7:14am UTC](https://discuss.elastic.co/t/oom-since-8-16-1-with-openjdk23/371395 "2025-05-02T07:14:30Z")

</div>

Hi, after upgrading from 8.15.1 to 8.16.1, all machines in two of our four ES clusters are running out of Memory after 7-12 hours. Our current setup for all clusters is: System: Ubuntu 22 3 master 3 data nodes (64GB…

---

## [Combining pinned and query rules in Elasticsearch DSL – is it possible?](https://discuss.elastic.co/t/combining-pinned-and-query-rules-in-elasticsearch-dsl-is-it-possible/377265)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 4\
**Last updated:** [May 2, 2025, 2:29am UTC](https://discuss.elastic.co/t/combining-pinned-and-query-rules-in-elasticsearch-dsl-is-it-possible/377265 "2025-05-02T02:29:06Z")

</div>

Is it possible to use both pinned query and query rules together in the same DSL request? I have a case where some documents need to be permanently pinned at the top (through rules), but there are dynamic situations wher…

---

## [Functional filter on ES v 9.0.0, not working on v 8.18.0](https://discuss.elastic.co/t/functional-filter-on-es-v-9-0-0-not-working-on-v-8-18-0/377692)

<div class="topic-metadata">

**Author:** [@dave\_espinosa\_qs](https://discuss.elastic.co/u/dave_espinosa_qs)\
**Replies:** 1\
**Last updated:** [April 30, 2025, 11:55pm UTC](https://discuss.elastic.co/t/functional-filter-on-es-v-9-0-0-not-working-on-v-8-18-0/377692 "2025-04-30T23:55:21Z")

</div>

Hello everyone, After checking this post, I implemented a filter (in a v 9.0.0 Elasticsearch infrastructure) which looks as follows: \[ { "bool": { "should": \[ {"term": {"metadata…

---

## [Renaming of indices during Elastic Search Upgrade](https://discuss.elastic.co/t/renaming-of-indices-during-elastic-search-upgrade/377680)

<div class="topic-metadata">

**Author:** [@Kavya\_2708](https://discuss.elastic.co/u/Kavya_2708)\
**Replies:** 4\
**Last updated:** [April 30, 2025, 3:53pm UTC](https://discuss.elastic.co/t/renaming-of-indices-during-elastic-search-upgrade/377680 "2025-04-30T15:53:54Z")

</div>

We are upgrading our elastic-search , kibana cluster from 7.17 to 8.17. As part of the upgrade, we are required to reindex the existing indices. During this process it is renaming the indices. ex. it is renaming aps to r…

---

## [\[elasticsearch.server\]\[WARN\] caught exception while handling client http traffic, closing connection Netty4HttpChannel](https://discuss.elastic.co/t/elasticsearch-server-warn-caught-exception-while-handling-client-http-traffic-closing-connection-netty4httpchannel/365301)

<div class="topic-metadata">

**Author:** [@ETFJeff](https://discuss.elastic.co/u/ETFJeff)\
**Replies:** 4\
**Last updated:** [April 30, 2025, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-server-warn-caught-exception-while-handling-client-http-traffic-closing-connection-netty4httpchannel/365301 "2025-04-30T14:41:55Z")

</div>

Hi, I get the following error in the cluster log about every hour. \[elasticsearch.server\]\[WARN\] caught exception while handling client http traffic, closing connection Netty4HttpChannel Any suggestions on where to sta…

---

## [Enabling entitlements for my plugin using Elastic Search 8.18.0](https://discuss.elastic.co/t/enabling-entitlements-for-my-plugin-using-elastic-search-8-18-0/377624)

<div class="topic-metadata">

**Author:** [@eereiter](https://discuss.elastic.co/u/eereiter)\
**Replies:** 2\
**Last updated:** [April 30, 2025, 10:50am UTC](https://discuss.elastic.co/t/enabling-entitlements-for-my-plugin-using-elastic-search-8-18-0/377624 "2025-04-30T10:50:00Z")

</div>

I have a custom search plugin that I can install. I am getting an exception when the plugin gets called: Not entitled: component \[cmr\_spatial\], module \[ALL-UNNAMED\], class \[class clojure.lang.DynamicClassLoader\], entit…

---

## [Elastic Shard sizing](https://discuss.elastic.co/t/elastic-shard-sizing/377652)

<div class="topic-metadata">

**Author:** [@akmoharana](https://discuss.elastic.co/u/akmoharana)\
**Replies:** 0\
**Last updated:** [April 30, 2025, 6:49am UTC](https://discuss.elastic.co/t/elastic-shard-sizing/377652 "2025-04-30T06:49:08Z")

</div>

HI Team, I have deployed the ELK ion the bubernetes, the Shard size of the elasticsearch is reached to the max limit, which is affecting the performance of the ELK. Can anyone please let me know how to increase the siz…

---

## [How is decided if a certificate is valid in verificationMode: full mode](https://discuss.elastic.co/t/how-is-decided-if-a-certificate-is-valid-in-verificationmode-full-mode/377417)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 2\
**Last updated:** [April 30, 2025, 5:56am UTC](https://discuss.elastic.co/t/how-is-decided-if-a-certificate-is-valid-in-verificationmode-full-mode/377417 "2025-04-30T05:56:18Z")

</div>

Sorry if it is a simple question but, when i set verificationMode to full how is decided that certificate is valid or not? Which part of certificate is compared to what to check the certificate validation?

---

## [Best practices for continuous transform with fixed gte filter and tiered storage (hot/warm indices)](https://discuss.elastic.co/t/best-practices-for-continuous-transform-with-fixed-gte-filter-and-tiered-storage-hot-warm-indices/377604)

<div class="topic-metadata">

**Author:** [@ak84](https://discuss.elastic.co/u/ak84)\
**Replies:** 1\
**Last updated:** [April 29, 2025, 6:25pm UTC](https://discuss.elastic.co/t/best-practices-for-continuous-transform-with-fixed-gte-filter-and-tiered-storage-hot-warm-indices/377604 "2025-04-29T18:25:00Z")

</div>

I'm using an Elasticsearch continuous transform to aggregate data from time-based indices (These are daily indices which contain time sensitive documents). My goal is to have the transform only process data starting from…

---

## [Cannot create ES7 instances on Elastic Cloud](https://discuss.elastic.co/t/cannot-create-es7-instances-on-elastic-cloud/377616)

<div class="topic-metadata">

**Author:** [@PaulBonnel](https://discuss.elastic.co/u/PaulBonnel)\
**Replies:** 2\
**Last updated:** [April 29, 2025, 12:49pm UTC](https://discuss.elastic.co/t/cannot-create-es7-instances-on-elastic-cloud/377616 "2025-04-29T12:49:53Z")

</div>

Hello, We cannot create ES7 instances on Elastic Cloud. Is this expected? We are quite surprised by this change since EOL of ES7 is scheduled for early 2026. Thanks

---

## [Elasticsearch trying to get access to old shards](https://discuss.elastic.co/t/elasticsearch-trying-to-get-access-to-old-shards/377421)

<div class="topic-metadata">

**Author:** [@TheJ](https://discuss.elastic.co/u/TheJ)\
**Replies:** 1\
**Last updated:** [April 29, 2025, 11:41am UTC](https://discuss.elastic.co/t/elasticsearch-trying-to-get-access-to-old-shards/377421 "2025-04-29T11:41:53Z")

</div>

Hi, I have hot nodes with weekly data retention and 3 warm nodes with yearly retention. When I try to run a query to get logs from the last 5 days, Elasticsearch is trying to access shards that were created a month ago …

---

## [Elastic PostgreSQL connector 8.12.2 with track\_commit\_timestamp off](https://discuss.elastic.co/t/elastic-postgresql-connector-8-12-2-with-track-commit-timestamp-off/377593)

<div class="topic-metadata">

**Author:** [@apostolos.e](https://discuss.elastic.co/u/apostolos.e)\
**Replies:** 2\
**Last updated:** [April 29, 2025, 7:15am UTC](https://discuss.elastic.co/t/elastic-postgresql-connector-8-12-2-with-track-commit-timestamp-off/377593 "2025-04-29T07:15:04Z")

</div>

Hi all, I am using ELK 8.12.2 along with Elastic PostgreSQL connector 8.12.2. Both have been setup on premises, in my infra. When track\_commit\_timestamp is off, the connector fails with: DBAPIError: (sqlalchemy.dialec…

---

## [Odd query help?](https://discuss.elastic.co/t/odd-query-help/377586)

<div class="topic-metadata">

**Author:** [@ChrisR](https://discuss.elastic.co/u/ChrisR)\
**Replies:** 2\
**Last updated:** [April 28, 2025, 7:23pm UTC](https://discuss.elastic.co/t/odd-query-help/377586 "2025-04-28T19:23:20Z")

</div>

Is there a way to query for docs that contain one and only one keyword value? For example, supposing these docs: {"id": 1, "keywd": \["A"\]} {"id": 2, "keywd": \["B"\]} {"id": 3, "keywd": \["A", "B"\]} Is there a way to que…

---

## [Elasticsearch node is offline on Stack Monitoring](https://discuss.elastic.co/t/elasticsearch-node-is-offline-on-stack-monitoring/377577)

<div class="topic-metadata">

**Author:** [@makinshin](https://discuss.elastic.co/u/makinshin)\
**Replies:** 0\
**Last updated:** [April 28, 2025, 1:02pm UTC](https://discuss.elastic.co/t/elasticsearch-node-is-offline-on-stack-monitoring/377577 "2025-04-28T13:02:17Z")

</div>

Hello everyone! My node dispalyed as offline, but it's working. How to fix this problem? Elk and metricbeat are installed on the same VM. GET / { "name" : "elk-0", "cluster\_name" : "elasticsearch", "cluster…

---

## [Performance Issue with KNN + Filter on Large Index (v8.12)](https://discuss.elastic.co/t/performance-issue-with-knn-filter-on-large-index-v8-12/377279)

<div class="topic-metadata">

**Author:** [@Saleh\_AbuAli](https://discuss.elastic.co/u/Saleh_AbuAli)\
**Replies:** 12\
**Last updated:** [April 28, 2025, 12:48pm UTC](https://discuss.elastic.co/t/performance-issue-with-knn-filter-on-large-index-v8-12/377279 "2025-04-28T12:48:33Z")

</div>

Hi, I’m currently using KNN search in Elasticsearch (version 8.12) with the following setup: Query vector dimension: 384 Index size: 200M+ documents k = 100, num\_candidates = 200 Quantized vectors using 'int8\_hnsw' in…

---

## [Missing index pattern](https://discuss.elastic.co/t/missing-index-pattern/377559)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [April 28, 2025, 12:27pm UTC](https://discuss.elastic.co/t/missing-index-pattern/377559 "2025-04-28T12:27:30Z")

</div>

I am trying to fetch the index in a specific dashboard however the index pattern goes missing For an Example:- In discover i can see 10 pattern but in dashboard in add filter section only limited index patterns are visi…

---

## [Ingest-data with problem in Kubernetes na GKE](https://discuss.elastic.co/t/ingest-data-with-problem-in-kubernetes-na-gke/377575)

<div class="topic-metadata">

**Author:** [@Renato\_Souza](https://discuss.elastic.co/u/Renato_Souza)\
**Replies:** 0\
**Last updated:** [April 28, 2025, 12:17pm UTC](https://discuss.elastic.co/t/ingest-data-with-problem-in-kubernetes-na-gke/377575 "2025-04-28T12:17:38Z")

</div>

I am implementing the stack below in my gke cluster version 1.30.10-gke.1022000 and I am getting an error in the ingest-data pod, it cannot start due to changes in the stateFulSet. apiVersion: argoproj.io/v1alpha1 kind:…

---

## [Index lifecycle policy](https://discuss.elastic.co/t/index-lifecycle-policy/377513)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 4\
**Last updated:** [April 28, 2025, 7:20am UTC](https://discuss.elastic.co/t/index-lifecycle-policy/377513 "2025-04-28T07:20:17Z")

</div>

I have two types of index in my system: Index\_A, where I store all documents, with '@timestamp' representing the log injection time to Elasticsearch, and '\_datetime' indicating the log's own timestamp. In order to minim…

---

## [Values less than -1 bytes are not supported when cat/indices](https://discuss.elastic.co/t/values-less-than-1-bytes-are-not-supported-when-cat-indices/377539)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 1\
**Last updated:** [April 27, 2025, 2:32am UTC](https://discuss.elastic.co/t/values-less-than-1-bytes-are-not-supported-when-cat-indices/377539 "2025-04-27T02:32:37Z")

</div>

My cluster is green. I saw Error from \_cat APIs: Values less than -1 bytes are not supported, but my cluster already is 7.10.2, and \_cat/indices may only involve store size?

---

## [ES Search tutorial :: 'no such index \[my\_documents\]',](https://discuss.elastic.co/t/es-search-tutorial-no-such-index-my-documents/377538)

<div class="topic-metadata">

**Author:** [@A\_ai](https://discuss.elastic.co/u/A_ai)\
**Replies:** 9\
**Last updated:** [April 26, 2025, 6:07pm UTC](https://discuss.elastic.co/t/es-search-tutorial-no-such-index-my-documents/377538 "2025-04-26T18:07:17Z")

</div>

Hi Total noob to ES. I am doing the Search tutorial here: Search Basics - Elasticsearch Labs So far so good, but when I run the sample search term 'policy', it gives me a elasticsearch.NotFoundError: NotFoundError(404…

---

## [How to improve log ingestion in multi-node cluster](https://discuss.elastic.co/t/how-to-improve-log-ingestion-in-multi-node-cluster/376679)

<div class="topic-metadata">

**Author:** [@Mohijeetsinh\_Jadeja](https://discuss.elastic.co/u/Mohijeetsinh_Jadeja)\
**Replies:** 12\
**Last updated:** [April 26, 2025, 8:19am UTC](https://discuss.elastic.co/t/how-to-improve-log-ingestion-in-multi-node-cluster/376679 "2025-04-26T08:19:18Z")

</div>

Hi Everyone, Recently we started using elasticsearch with multi-node architecture to handle heavy logs ingestion which is around 200K per second on an average during normal workload (not sure is this too much logs or no…

---

## [Way to diagnose "high watermark" or approaching high watermark?](https://discuss.elastic.co/t/way-to-diagnose-high-watermark-or-approaching-high-watermark/377536)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 5\
**Last updated:** [April 26, 2025, 7:50am UTC](https://discuss.elastic.co/t/way-to-diagnose-high-watermark-or-approaching-high-watermark/377536 "2025-04-26T07:50:16Z")

</div>

Near beginner/low-low intermediate here. A few months ago I spent a long time developing an app, in Python with a Rust module, to do automatic indexing of all the text documents under a particular directory in my system…

---

## [EXCEPTION\_ACCESS\_VIOLATION (0xc0000005)](https://discuss.elastic.co/t/exception-access-violation-0xc0000005/373334)

<div class="topic-metadata">

**Author:** [@khaled-absalam](https://discuss.elastic.co/u/khaled-absalam)\
**Replies:** 1\
**Last updated:** [April 25, 2025, 5:08pm UTC](https://discuss.elastic.co/t/exception-access-violation-0xc0000005/373334 "2025-04-25T17:08:13Z")

</div>

I'm encountering error running Elasticsearch 8.17.0 on Windows 11 Pro version 24H2 with embedded Java 23.0+37, this error started occurring since I upgraded Elasticsearch to 8.16.1, I've got a memory of 128GB and I'm usi…

---

## [Availability of Older Elasticsearch Versions on Elastic Cloud (Below 8.17.5)](https://discuss.elastic.co/t/availability-of-older-elasticsearch-versions-on-elastic-cloud-below-8-17-5/377399)

<div class="topic-metadata">

**Author:** [@Aniket\_Dubey10](https://discuss.elastic.co/u/Aniket_Dubey10)\
**Replies:** 10\
**Last updated:** [April 25, 2025, 3:16pm UTC](https://discuss.elastic.co/t/availability-of-older-elasticsearch-versions-on-elastic-cloud-below-8-17-5/377399 "2025-04-25T15:16:27Z")

</div>

Is it possible to deploy an earlier version, such as 8.10.2, via Elastic Cloud — either through advanced settings or support request?

---

## [Dynamic watcher/alerting without creating multiple watches](https://discuss.elastic.co/t/dynamic-watcher-alerting-without-creating-multiple-watches/377432)

<div class="topic-metadata">

**Author:** [@Rukmangadha\_Ajay](https://discuss.elastic.co/u/Rukmangadha_Ajay)\
**Replies:** 0\
**Last updated:** [April 23, 2025, 11:47am UTC](https://discuss.elastic.co/t/dynamic-watcher-alerting-without-creating-multiple-watches/377432 "2025-04-23T11:47:18Z")

</div>

Hi all, I’m using Elasticsearch (with Kibana) to log IBM ACE message flow exceptions, and I’ve already built pipelines to successfully index logs. Now, I need to configure a Watcher to send email alerts based on specifi…

---

## [Problem with calculating flow with ELK with filebeat](https://discuss.elastic.co/t/problem-with-calculating-flow-with-elk-with-filebeat/377519)

<div class="topic-metadata">

**Author:** [@Komeyl\_Pouya](https://discuss.elastic.co/u/Komeyl_Pouya)\
**Replies:** 0\
**Last updated:** [April 25, 2025, 11:38am UTC](https://discuss.elastic.co/t/problem-with-calculating-flow-with-elk-with-filebeat/377519 "2025-04-25T11:38:07Z")

</div>

hi The problem I have with this service is that it does not calculate flow accurately. Flow is received, but filebeat and its dashboards show it extremely low and cannot be understood by any standard.

---

## [ElasticSearch indices](https://discuss.elastic.co/t/elasticsearch-indices/377506)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [April 25, 2025, 12:39am UTC](https://discuss.elastic.co/t/elasticsearch-indices/377506 "2025-04-25T00:39:40Z")

</div>

I checked the indices on a host that I have been given access too. There are only 2 indices I want to continue to use. Where did all these other indices come from, did ES install then as default clearly many dont have …

---

## [Duplicate indexing behavior without \_id](https://discuss.elastic.co/t/duplicate-indexing-behavior-without-id/377501)

<div class="topic-metadata">

**Author:** [@csanadpoda](https://discuss.elastic.co/u/csanadpoda)\
**Replies:** 1\
**Last updated:** [April 24, 2025, 9:07pm UTC](https://discuss.elastic.co/t/duplicate-indexing-behavior-without-id/377501 "2025-04-24T21:07:06Z")

</div>

If I were to index documents without specifying a fixed \_id, when duplicate documents appear, would they be created as duplicate entries in the index, or would ES recognize that there's already the same entry in the inde…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=33)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=35)
