# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=36

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 37

---

## [Paged Search Larger than 10,000 Records](https://discuss.elastic.co/t/paged-search-larger-than-10-000-records/376500)

<div class="topic-metadata">

**Author:** [@Devan](https://discuss.elastic.co/u/Devan)\
**Replies:** 4\
**Last updated:** [April 18, 2025, 3:36am UTC](https://discuss.elastic.co/t/paged-search-larger-than-10-000-records/376500 "2025-04-18T03:36:37Z")

</div>

We are currently using from and size pagination in our Elasticsearch results of ~1,000 records on average. We recently ran into some instances of ~15,000 records and expect some more of similar magnitude, resulting in th…

---

## [Ubuntu 24.04 Support](https://discuss.elastic.co/t/ubuntu-24-04-support/362337)

<div class="topic-metadata">

**Author:** [@jeff2](https://discuss.elastic.co/u/jeff2)\
**Replies:** 7\
**Last updated:** [April 16, 2025, 10:24am UTC](https://discuss.elastic.co/t/ubuntu-24-04-support/362337 "2025-04-16T10:24:59Z")

</div>

Ubuntu 24.04 LTS is now released but it is not mentioned in the elastic support matrix Are elasticsearch and logstash officially supported on Ubuntu 24.04? Also, does the Support matrix also act as a Compatibility matr…

---

## [Big drop in indexing rate when reindexing](https://discuss.elastic.co/t/big-drop-in-indexing-rate-when-reindexing/377310)

<div class="topic-metadata">

**Author:** [@parameter](https://discuss.elastic.co/u/parameter)\
**Replies:** 1\
**Last updated:** [April 19, 2025, 9:40am UTC](https://discuss.elastic.co/t/big-drop-in-indexing-rate-when-reindexing/377310 "2025-04-19T09:40:18Z")

</div>

I'm reindexing timeseries data into bigger indices. I have daily indices like logs-yyyy-MM-dd and I'm reindexing it to bigger indices using: POST \_reindex { "source": { "index": "logs-2024-08-\*" }, "dest": { …

---

## [Manual backup restore](https://discuss.elastic.co/t/manual-backup-restore/377270)

<div class="topic-metadata">

**Author:** [@iexpertini](https://discuss.elastic.co/u/iexpertini)\
**Replies:** 2\
**Last updated:** [April 18, 2025, 5:27pm UTC](https://discuss.elastic.co/t/manual-backup-restore/377270 "2025-04-18T17:27:32Z")

</div>

Greetings, We’re currently facing an issue with our Elasticsearch cluster, which consists of 8 nodes. Unfortunately, we accidentally “emptied” an index (my\_index) from the cluster. While we don’t have a snapshot, we do …

---

## [Differences between LOOKUP Index and Enrich Index](https://discuss.elastic.co/t/differences-between-lookup-index-and-enrich-index/377286)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [April 18, 2025, 4:53pm UTC](https://discuss.elastic.co/t/differences-between-lookup-index-and-enrich-index/377286 "2025-04-18T16:53:39Z")

</div>

Hello, Elastic recently announced LOOKUP JOINS. They specified that the lookup function in ES|QL only works if the index is a lookup index. I am bit confused on this implementation? It seems like both ENRICH and LOOKU…

---

## [Elasticsearch crashes with every update](https://discuss.elastic.co/t/elasticsearch-crashes-with-every-update/377276)

<div class="topic-metadata">

**Author:** [@Didier\_Bourgineau](https://discuss.elastic.co/u/Didier_Bourgineau)\
**Replies:** 3\
**Last updated:** [April 18, 2025, 3:21pm UTC](https://discuss.elastic.co/t/elasticsearch-crashes-with-every-update/377276 "2025-04-18T15:21:41Z")

</div>

Elasticsearch crashes with every update since 8.14.0 and again between 8.17.4 and 8.18.0 with the following error: java.util.ServiceConfigurationError: Error loading SPI class list from URL: jar:file:///usr/share/elast…

---

## [Service killing each week - Error loading SPI class list from URL - x-pack-security](https://discuss.elastic.co/t/service-killing-each-week-error-loading-spi-class-list-from-url-x-pack-security/363142)

<div class="topic-metadata">

**Author:** [@Alan\_Monteiro\_SW](https://discuss.elastic.co/u/Alan_Monteiro_SW)\
**Replies:** 2\
**Last updated:** [March 19, 2025, 2:14pm UTC](https://discuss.elastic.co/t/service-killing-each-week-error-loading-spi-class-list-from-url-x-pack-security/363142 "2025-03-19T14:14:25Z")

</div>

Hi :smiley: I was using Elastic Search 8.14.2, and the service would crash every week. The log output showed that x-pack-security-8.14.1 was not found, but the installed Elastic Search version was 8.14.2. I tried reinst…

---

## [Trouble implementing Elasticsearch BBQ](https://discuss.elastic.co/t/trouble-implementing-elasticsearch-bbq/377269)

<div class="topic-metadata">

**Author:** [@DylanWelzel](https://discuss.elastic.co/u/DylanWelzel)\
**Replies:** 1\
**Last updated:** [April 18, 2025, 5:46am UTC](https://discuss.elastic.co/t/trouble-implementing-elasticsearch-bbq/377269 "2025-04-18T05:46:02Z")

</div>

I am trying to integrate BBQ, specifically bbq\_hnsw into my existing index. However I'm not seeing the performance benefits I would expect. { "type": "dense\_vector", "dims": dims, "index": True, …

---

## [.monitoring-es-9-mb is missing](https://discuss.elastic.co/t/monitoring-es-9-mb-is-missing/377191)

<div class="topic-metadata">

**Author:** [@dramis](https://discuss.elastic.co/u/dramis)\
**Replies:** 2\
**Last updated:** [April 17, 2025, 9:24pm UTC](https://discuss.elastic.co/t/monitoring-es-9-mb-is-missing/377191 "2025-04-17T21:24:53Z")

</div>

Hi, i just migrate to elk 9, i just notice that .monitoring-es-mb System index template still using .monitoring-es-8-\* I also have these error in elk log: \[2025-04-16T07:57:24,226\]\[INFO \]\[o.e.x.i.a.TransportPutL…

---

## [Not entitled: component \[repository-s3\] after update from 8.17.4 to 8.18.0](https://discuss.elastic.co/t/not-entitled-component-repository-s3-after-update-from-8-17-4-to-8-18-0/377166)

<div class="topic-metadata">

**Author:** [@ATecha](https://discuss.elastic.co/u/ATecha)\
**Replies:** 11\
**Last updated:** [April 17, 2025, 10:54am UTC](https://discuss.elastic.co/t/not-entitled-component-repository-s3-after-update-from-8-17-4-to-8-18-0/377166 "2025-04-17T10:54:21Z")

</div>

Noticed this in the log after updating from 8.17.4 to the just-released 8.18.0. It occurred in the first startup, and any restart since. \[2025-04-15T14:44:04,795\]\[INFO \]\[o.e.n.Node \] \[node-0-dev\] Default …

---

## [TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block](https://discuss.elastic.co/t/too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/377233)

<div class="topic-metadata">

**Author:** [@Jackman](https://discuss.elastic.co/u/Jackman)\
**Replies:** 8\
**Last updated:** [April 17, 2025, 8:49am UTC](https://discuss.elastic.co/t/too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/377233 "2025-04-17T08:49:19Z")

</div>

Hey Guys im currently running an elastic-search container on my docker where im running a local development area, which all seemed fine at first but at one point i got the error in the title or to be exact: 2025-04-17 0…

---

## [High index size causing performance issue](https://discuss.elastic.co/t/high-index-size-causing-performance-issue/377213)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 5\
**Last updated:** [April 16, 2025, 9:24pm UTC](https://discuss.elastic.co/t/high-index-size-causing-performance-issue/377213 "2025-04-16T21:24:44Z")

</div>

Hello, I have a java application that is writting data directly to an Elasticsearch index named as candidate having 1 primary and 1replica and this is now causing issue.Need to increase no of primary shard. 300gb candi…

---

## [Elastic search .net client not removing field](https://discuss.elastic.co/t/elastic-search-net-client-not-removing-field/377184)

<div class="topic-metadata">

**Author:** [@Vias\_Giraud](https://discuss.elastic.co/u/Vias_Giraud)\
**Replies:** 1\
**Last updated:** [April 16, 2025, 2:17pm UTC](https://discuss.elastic.co/t/elastic-search-net-client-not-removing-field/377184 "2025-04-16T14:17:29Z")

</div>

I have ingest pipeline , to remove field content to free up space like below : var pipeResponse = await \_client.Ingest.PutPipelineAsync\<Document\>("attachments", p =\> p .Description("Document attachme…

---

## [Some one provide EOL date of ELK components 7.9.x version](https://discuss.elastic.co/t/some-one-provide-eol-date-of-elk-components-7-9-x-version/377195)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 1\
**Last updated:** [April 16, 2025, 1:35pm UTC](https://discuss.elastic.co/t/some-one-provide-eol-date-of-elk-components-7-9-x-version/377195 "2025-04-16T13:35:43Z")

</div>

Hi Team, Could you please provide the EOL date of all ELK components of 7.9.x as I found like this. Shall we get release updates/patches for 7.x.x?

---

## [ESQL Get a specific field in the most recent document from a group of documents](https://discuss.elastic.co/t/esql-get-a-specific-field-in-the-most-recent-document-from-a-group-of-documents/377197)

<div class="topic-metadata">

**Author:** [@logalicious](https://discuss.elastic.co/u/logalicious)\
**Replies:** 0\
**Last updated:** [April 16, 2025, 1:19pm UTC](https://discuss.elastic.co/t/esql-get-a-specific-field-in-the-most-recent-document-from-a-group-of-documents/377197 "2025-04-16T13:19:45Z")

</div>

I have an index for purchases. In each document there is a customer.name and cashier.name field. I want to group the documents using ESQL based on customer.name and return the most recent value of cashier.name. This will…

---

## [What is the fix for CVE-2024-52980 in elasticsearch 7.x versions](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099)

<div class="topic-metadata">

**Author:** [@Amaresh\_Selva](https://discuss.elastic.co/u/Amaresh_Selva)\
**Replies:** 4\
**Last updated:** [April 16, 2025, 11:17am UTC](https://discuss.elastic.co/t/what-is-the-fix-for-cve-2024-52980-in-elasticsearch-7-x-versions/377099 "2025-04-16T11:17:09Z")

</div>

we are currently using elasticsearch 7.17.26 in our client side and 7.17.24 in servers . we received a notification about CVE-2024-52980 in elasticsearch what is the fix for this CVE for 7.x versions we only see that i…

---

## [Indexation stopped during indices rollover](https://discuss.elastic.co/t/indexation-stopped-during-indices-rollover/377180)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 3\
**Last updated:** [April 16, 2025, 9:10am UTC](https://discuss.elastic.co/t/indexation-stopped-during-indices-rollover/377180 "2025-04-16T09:10:35Z")

</div>

Hello, We have currently one big cluster (300+ nodes) with tiering. We are using Elasticsearch version 8.4.3 Since some months we are seeing issues during indices rollover, where the bulk index requests are delayed fo…

---

## [New logsdb format](https://discuss.elastic.co/t/new-logsdb-format/377101)

<div class="topic-metadata">

**Author:** [@skeyby](https://discuss.elastic.co/u/skeyby)\
**Replies:** 22\
**Last updated:** [April 16, 2025, 5:38am UTC](https://discuss.elastic.co/t/new-logsdb-format/377101 "2025-04-16T05:38:38Z")

</div>

Hello everybody. A few weeks ago I've set up a new Elasticsearch cluster to hold logs coming from our Kubernetes cluster. Since we installed a brand new 8.17 we decided to give the new logsdb format a go. We started w…

---

## [Should I publish multiple node HTTP ports when running all Elasticsearch nodes inside one Docker container?](https://discuss.elastic.co/t/should-i-publish-multiple-node-http-ports-when-running-all-elasticsearch-nodes-inside-one-docker-container/376972)

<div class="topic-metadata">

**Author:** [@HorselessName](https://discuss.elastic.co/u/HorselessName)\
**Replies:** 8\
**Last updated:** [April 15, 2025, 3:12pm UTC](https://discuss.elastic.co/t/should-i-publish-multiple-node-http-ports-when-running-all-elasticsearch-nodes-inside-one-docker-container/376972 "2025-04-15T15:12:24Z")

</div>

Hi everyone, I'm building a multi-node Elasticsearch cluster inside a single Docker container for learning purposes. Instead of using the official Docker image, I’m going old-school: manually unpacking the .tar.gz binar…

---

## [Elasticsearch AWS Cognito OIDC issue](https://discuss.elastic.co/t/elasticsearch-aws-cognito-oidc-issue/377149)

<div class="topic-metadata">

**Author:** [@eugeniof](https://discuss.elastic.co/u/eugeniof)\
**Replies:** 3\
**Last updated:** [April 15, 2025, 1:34pm UTC](https://discuss.elastic.co/t/elasticsearch-aws-cognito-oidc-issue/377149 "2025-04-15T13:34:58Z")

</div>

Hello, I have a problem when I try to use JWT token provided by AWS Cognito. Specifically I add this configuration to my elasticsearch.yml, on elastic cloud: xpack: security: authc: realms: oidc: …

---

## [Implementing pinned queries in search-ui](https://discuss.elastic.co/t/implementing-pinned-queries-in-search-ui/377135)

<div class="topic-metadata">

**Author:** [@dabby](https://discuss.elastic.co/u/dabby)\
**Replies:** 0\
**Last updated:** [April 15, 2025, 8:16am UTC](https://discuss.elastic.co/t/implementing-pinned-queries-in-search-ui/377135 "2025-04-15T08:16:51Z")

</div>

Hello, I am currently using the search-ui library for a react website, using the elasticsearch connector. I would like to implement pinned queries, but I'm unsure of how to proceed. I have tried looking through the do…

---

## [Pre-filter points in geo(tile) aggregations](https://discuss.elastic.co/t/pre-filter-points-in-geo-tile-aggregations/377011)

<div class="topic-metadata">

**Author:** [@frens](https://discuss.elastic.co/u/frens)\
**Replies:** 9\
**Last updated:** [April 14, 2025, 3:29pm UTC](https://discuss.elastic.co/t/pre-filter-points-in-geo-tile-aggregations/377011 "2025-04-14T15:29:05Z")

</div>

Elasticsearch supports bounds for geo-tile aggregations. Is there any way to filter the points before the transformation to tiles? We're considering scripted fields, plugins, and other things. But it would be ideal if w…

---

## [Troubleshooting an unstable cluster](https://discuss.elastic.co/t/troubleshooting-an-unstable-cluster/377070)

<div class="topic-metadata">

**Author:** [@lwm2016](https://discuss.elastic.co/u/lwm2016)\
**Replies:** 19\
**Last updated:** [April 14, 2025, 12:23pm UTC](https://discuss.elastic.co/t/troubleshooting-an-unstable-cluster/377070 "2025-04-14T12:23:54Z")

</div>

Hi Team, We have deployed a cluster of across 9 physical machines, each hosting multiple instances. The hardware specifications per machine are: 112 CPU cores 503 GB memory Here's cluster and node info { "name" :…

---

## [Nested Query not working](https://discuss.elastic.co/t/nested-query-not-working/377093)

<div class="topic-metadata">

**Author:** [@I.am\_mohit](https://discuss.elastic.co/u/I.am_mohit)\
**Replies:** 1\
**Last updated:** [April 14, 2025, 9:11am UTC](https://discuss.elastic.co/t/nested-query-not-working/377093 "2025-04-14T09:11:00Z")

</div>

public class Calendars { public decimal? NightlyPrice { get; set; } public bool? Availability { get; set; } public List\<CalendarDates\> Dates{ get; set; } } public class CalendarDates { public DateT…

---

## [How to delete index template for data stream](https://discuss.elastic.co/t/how-to-delete-index-template-for-data-stream/363505)

<div class="topic-metadata">

**Author:** [@andre22](https://discuss.elastic.co/u/andre22)\
**Replies:** 2\
**Last updated:** [April 12, 2025, 8:17pm UTC](https://discuss.elastic.co/t/how-to-delete-index-template-for-data-stream/363505 "2025-04-12T20:17:20Z")

</div>

Hi, I have created an index template which creates a data stream for testing purposes and would like to get rid of it. I cannot delete the index template: OK, there is still an exisitng data stream. I cannot delete t…

---

## [Elasticsearch server is not starting](https://discuss.elastic.co/t/elasticsearch-server-is-not-starting/377051)

<div class="topic-metadata">

**Author:** [@mithun321](https://discuss.elastic.co/u/mithun321)\
**Replies:** 5\
**Last updated:** [April 12, 2025, 12:22pm UTC](https://discuss.elastic.co/t/elasticsearch-server-is-not-starting/377051 "2025-04-12T12:22:32Z")

</div>

I'm getting this error I'm starting Elasticsearch server Job for elasticsearch.service failed because the control process exited with error code. See "systemctl status elasticsearch.service" and "journalctl -xeu elasti…

---

## [Does setting a high size in terms aggregation affect memory usage if the actual bucket count is low?](https://discuss.elastic.co/t/does-setting-a-high-size-in-terms-aggregation-affect-memory-usage-if-the-actual-bucket-count-is-low/377060)

<div class="topic-metadata">

**Author:** [@lostpeacock](https://discuss.elastic.co/u/lostpeacock)\
**Replies:** 1\
**Last updated:** [April 12, 2025, 8:30am UTC](https://discuss.elastic.co/t/does-setting-a-high-size-in-terms-aggregation-affect-memory-usage-if-the-actual-bucket-count-is-low/377060 "2025-04-12T08:30:14Z")

</div>

I'm using a terms aggregation in Elasticsearch and have a question about the size parameter. Let's say I set size: 1000, but in reality, the number of buckets generated is always much lower—around 150 at most. My questi…

---

## [In version 8.17.3, some default pipelines are automatically created after being deleted using DELETE \_ingest/pipeline/\*](https://discuss.elastic.co/t/in-version-8-17-3-some-default-pipelines-are-automatically-created-after-being-deleted-using-delete-ingest-pipeline/376945)

<div class="topic-metadata">

**Author:** [@AdolphGai](https://discuss.elastic.co/u/AdolphGai)\
**Replies:** 5\
**Last updated:** [April 11, 2025, 6:28pm UTC](https://discuss.elastic.co/t/in-version-8-17-3-some-default-pipelines-are-automatically-created-after-being-deleted-using-delete-ingest-pipeline/376945 "2025-04-11T18:28:25Z")

</div>

Install elasticsearch 8.17.3 and find that there are many default pipelines Run the DELETE \_ingest/pipeline/\* and \_ingest/pipeline/pipeline\_id command. The command output is deleted successfully But with get, the discov…

---

## [Search timeout doesn't work](https://discuss.elastic.co/t/search-timeout-doesnt-work/376809)

<div class="topic-metadata">

**Author:** [@swami\_dtex](https://discuss.elastic.co/u/swami_dtex)\
**Replies:** 4\
**Last updated:** [April 11, 2025, 5:04pm UTC](https://discuss.elastic.co/t/search-timeout-doesnt-work/376809 "2025-04-11T17:04:26Z")

</div>

In our testing, we are observing that the following timeout settings aren't honored. This is in Elasticsearch 6.8.23. escurl -XPUT //\_cluster/settings -d '{"persistent": {"search.default\_search\_timeout": "5m"}}' escurl …

---

## [Can a Platinum-Licensed Cluster's watcher query Basic-Licensed Clusters?](https://discuss.elastic.co/t/can-a-platinum-licensed-clusters-watcher-query-basic-licensed-clusters/377044)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [April 11, 2025, 2:27pm UTC](https://discuss.elastic.co/t/can-a-platinum-licensed-clusters-watcher-query-basic-licensed-clusters/377044 "2025-04-11T14:27:00Z")

</div>

Hello Elastic community,​ I'm exploring the possibility of setting up Watcher alerts on a Platinum-licensed Elasticsearch cluster that would query data from other Elasticsearch clusters operating under the Basic license…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=35)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=37)
