# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=37

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 38

---

## [Searchable Snapshot and HDD vs SSD/NVMe Performance](https://discuss.elastic.co/t/searchable-snapshot-and-hdd-vs-ssd-nvme-performance/377039)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [April 11, 2025, 2:05pm UTC](https://discuss.elastic.co/t/searchable-snapshot-and-hdd-vs-ssd-nvme-performance/377039 "2025-04-11T14:05:29Z")

</div>

Hi All, I have a question that I couldn't really find an answer to: When using searchable snapshots, is the data stored and read in a "sequential" order, in a way that would be ideal for using HDDs with, or is the "rec…

---

## [Running elasticsearch-users cashes the pod](https://discuss.elastic.co/t/running-elasticsearch-users-cashes-the-pod/377018)

<div class="topic-metadata">

**Author:** [@kam\_ka](https://discuss.elastic.co/u/kam_ka)\
**Replies:** 1\
**Last updated:** [April 11, 2025, 12:44pm UTC](https://discuss.elastic.co/t/running-elasticsearch-users-cashes-the-pod/377018 "2025-04-11T12:44:29Z")

</div>

I am not sure what is wrong: elasticsearch@elasticsearch-es-default-0:~$ bin/elasticsearch-users list command terminated with exit code 137 Any param I give to this cli command crashes the pod. it is running on t3.med…

---

## [Broken track\_total\_hits behaviour in aggregation](https://discuss.elastic.co/t/broken-track-total-hits-behaviour-in-aggregation/377008)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 4\
**Last updated:** [April 11, 2025, 8:55am UTC](https://discuss.elastic.co/t/broken-track-total-hits-behaviour-in-aggregation/377008 "2025-04-11T08:55:52Z")

</div>

Hey, I am running an aggregation only request, that looks like this: GET product\_data/\_search?request\_cache=false&terminate\_after=500000 { "timeout": "300ms", "track\_total\_hits": true, "size": 0, "query": {…

---

## [In Elasticsearch, data after a certain date is not coming through](https://discuss.elastic.co/t/in-elasticsearch-data-after-a-certain-date-is-not-coming-through/376075)

<div class="topic-metadata">

**Author:** [@aiagent\_ai](https://discuss.elastic.co/u/aiagent_ai)\
**Replies:** 12\
**Last updated:** [April 10, 2025, 3:06pm UTC](https://discuss.elastic.co/t/in-elasticsearch-data-after-a-certain-date-is-not-coming-through/376075 "2025-04-10T15:06:43Z")

</div>

Problem: My application is running on Docker, and I am using Elasticsearch. The index has been created. When I make a curl request, I get a response, but in my application, data after March 5th is not showing up. Howeve…

---

## [\_id not being set when I pass it in my actions setup](https://discuss.elastic.co/t/id-not-being-set-when-i-pass-it-in-my-actions-setup/376968)

<div class="topic-metadata">

**Author:** [@olaaustine](https://discuss.elastic.co/u/olaaustine)\
**Replies:** 4\
**Last updated:** [April 10, 2025, 7:42am UTC](https://discuss.elastic.co/t/id-not-being-set-when-i-pass-it-in-my-actions-setup/376968 "2025-04-10T07:42:31Z")

</div>

Not sure if I did it wrong or this is an issue, so i created one of my actions data\_index = { '\_op\_type': 'create', "\_index": index\_name, "\_id": code, "doc": \*\*\*\* …

---

## [Yml files content are not getting indexed](https://discuss.elastic.co/t/yml-files-content-are-not-getting-indexed/376964)

<div class="topic-metadata">

**Author:** [@Daivik](https://discuss.elastic.co/u/Daivik)\
**Replies:** 0\
**Last updated:** [April 9, 2025, 2:52pm UTC](https://discuss.elastic.co/t/yml-files-content-are-not-getting-indexed/376964 "2025-04-09T14:52:26Z")

</div>

Currently have connected azure blob storage and elasticsearch using the connector in UI and all the files are getting indexed but only the \*.yml files content is not getting indexed. There is no error also. Could anyone…

---

## [Migration of ELK from on prem 7.17 to 8.x in OCI](https://discuss.elastic.co/t/migration-of-elk-from-on-prem-7-17-to-8-x-in-oci/376902)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 2\
**Last updated:** [April 9, 2025, 9:28am UTC](https://discuss.elastic.co/t/migration-of-elk-from-on-prem-7-17-to-8-x-in-oci/376902 "2025-04-09T09:28:46Z")

</div>

We have different versions in our ELK stack . Please suggest a plan for migration to 8.x . IAAS or SAAS ,which is recomended? Server 1 elasticsearch-7.17.8-1.x86\_64 elasticsearch-curator-5.7.6-1.x86\_64 apm-server-6.6.2…

---

## [Can users do a search and get all the details or is it only aggregated data that we can see from the cold tier](https://discuss.elastic.co/t/can-users-do-a-search-and-get-all-the-details-or-is-it-only-aggregated-data-that-we-can-see-from-the-cold-tier/376940)

<div class="topic-metadata">

**Author:** [@Farheen](https://discuss.elastic.co/u/Farheen)\
**Replies:** 4\
**Last updated:** [April 9, 2025, 7:26am UTC](https://discuss.elastic.co/t/can-users-do-a-search-and-get-all-the-details-or-is-it-only-aggregated-data-that-we-can-see-from-the-cold-tier/376940 "2025-04-09T07:26:26Z")

</div>

In the cold phase, are all fields searchable?

---

## [Filebeat unable to connect to azure storage account blob](https://discuss.elastic.co/t/filebeat-unable-to-connect-to-azure-storage-account-blob/376017)

<div class="topic-metadata">

**Author:** [@Sushmitha\_Shetty](https://discuss.elastic.co/u/Sushmitha_Shetty)\
**Replies:** 2\
**Last updated:** [April 9, 2025, 6:46am UTC](https://discuss.elastic.co/t/filebeat-unable-to-connect-to-azure-storage-account-blob/376017 "2025-04-09T06:46:21Z")

</div>

I have azure storage container blob in azure with .json file uploaded in it i want automatically json file should be fetched from the blob storage and pushed to elasticsearch using helm how can we acheive it using filebe…

---

## [Is my vector search quick enough](https://discuss.elastic.co/t/is-my-vector-search-quick-enough/376906)

<div class="topic-metadata">

**Author:** [@Capybara07](https://discuss.elastic.co/u/Capybara07)\
**Replies:** 5\
**Last updated:** [April 8, 2025, 12:50pm UTC](https://discuss.elastic.co/t/is-my-vector-search-quick-enough/376906 "2025-04-08T12:50:57Z")

</div>

I have 1536 dimension vectors, During benchmarking I am doing vector similarity search using script (not knn) by matching one vector agains 30k stored documents with vectors and getting response in about 4s The time i…

---

## [Iptables docker chain block](https://discuss.elastic.co/t/iptables-docker-chain-block/376898)

<div class="topic-metadata">

**Author:** [@felixwong](https://discuss.elastic.co/u/felixwong)\
**Replies:** 0\
**Last updated:** [April 8, 2025, 9:17am UTC](https://discuss.elastic.co/t/iptables-docker-chain-block/376898 "2025-04-08T09:17:25Z")

</div>

After installing Elasticsearch (port 8174) in Docker, I am experiencing packet drops in the Docker-related iptables chains, specifically: The DOCKER chain is dropping all traffic between non-bridge interfaces and Dock…

---

## [Request for Assistance in Extracting Fields and corresponding values from Elasticsearch](https://discuss.elastic.co/t/request-for-assistance-in-extracting-fields-and-corresponding-values-from-elasticsearch/376869)

<div class="topic-metadata">

**Author:** [@elastic\_interogation](https://discuss.elastic.co/u/elastic_interogation)\
**Replies:** 1\
**Last updated:** [April 8, 2025, 8:01am UTC](https://discuss.elastic.co/t/request-for-assistance-in-extracting-fields-and-corresponding-values-from-elasticsearch/376869 "2025-04-08T08:01:46Z")

</div>

Hi, I am looking to extract all available fields from my Elasticsearch index along with their possible values. I have more than 500 fields to extract. My goal is to create a comprehensive table where: Each column rep…

---

## [How to estimate the size of a snapshot for a single index or indices in Elasticsearch?](https://discuss.elastic.co/t/how-to-estimate-the-size-of-a-snapshot-for-a-single-index-or-indices-in-elasticsearch/376892)

<div class="topic-metadata">

**Author:** [@nguyenlethaihoang](https://discuss.elastic.co/u/nguyenlethaihoang)\
**Replies:** 2\
**Last updated:** [April 8, 2025, 7:01am UTC](https://discuss.elastic.co/t/how-to-estimate-the-size-of-a-snapshot-for-a-single-index-or-indices-in-elasticsearch/376892 "2025-04-08T07:01:07Z")

</div>

Hi everyone, I'm currently working with Elasticsearch snapshots and I need some clarification on how to estimate the size of a snapshot, especially for a specific index. For example: Let's say I have an index called l…

---

## [Failed to determine the health of cluster whats wrong with my configuration](https://discuss.elastic.co/t/failed-to-determine-the-health-of-cluster-whats-wrong-with-my-configuration/376888)

<div class="topic-metadata">

**Author:** [@Bonar\_Panjaitan](https://discuss.elastic.co/u/Bonar_Panjaitan)\
**Replies:** 0\
**Last updated:** [April 8, 2025, 4:46am UTC](https://discuss.elastic.co/t/failed-to-determine-the-health-of-cluster-whats-wrong-with-my-configuration/376888 "2025-04-08T04:46:09Z")

</div>

im running on single node elastic. failed when i try to reset the password. help me master. ======================== Elasticsearch Configuration ========================= NOTE: Elasticsearch comes with reasonable defau…

---

## [Logsdb will save about 65% disk spaces but i have received these results (Am I doing something wrong here)](https://discuss.elastic.co/t/logsdb-will-save-about-65-disk-spaces-but-i-have-received-these-results-am-i-doing-something-wrong-here/376883)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 3\
**Last updated:** [April 7, 2025, 11:43pm UTC](https://discuss.elastic.co/t/logsdb-will-save-about-65-disk-spaces-but-i-have-received-these-results-am-i-doing-something-wrong-here/376883 "2025-04-07T23:43:25Z")

</div>

I have tried uploading the simple logs data of windows from direct upload with about 279 KB file size that after ingestion into elastic was about 277.58kb. named windows\_2k\_simple that 277.58kb. same with logsdb setti…

---

## [Elasticsearch Not Logging Query Details Despite Enabling Audit Logs](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 10\
**Last updated:** [April 7, 2025, 6:59am UTC](https://discuss.elastic.co/t/elasticsearch-not-logging-query-details-despite-enabling-audit-logs/376790 "2025-04-07T06:59:17Z")

</div>

I have enabled the xpack.security.audit.enabled: true and also added xpack.security.audit.logfile.events.emit\_request\_body: true but when i query from postman but that does not seems to logging as i can only two streams …

---

## [Selective retnetion for an index](https://discuss.elastic.co/t/selective-retnetion-for-an-index/376720)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 8\
**Last updated:** [April 7, 2025, 5:55am UTC](https://discuss.elastic.co/t/selective-retnetion-for-an-index/376720 "2025-04-07T05:55:09Z")

</div>

We have a requirement in Elasticsearch where, for a single index, we need to store certain fields for one month and others for three months. Since there is no direct selective retention with ILM , we aim to achieve this…

---

## [How to optimize my ElasticSearch Query](https://discuss.elastic.co/t/how-to-optimize-my-elasticsearch-query/376531)

<div class="topic-metadata">

**Author:** [@simon\_Guille](https://discuss.elastic.co/u/simon_Guille)\
**Replies:** 22\
**Last updated:** [April 5, 2025, 11:30pm UTC](https://discuss.elastic.co/t/how-to-optimize-my-elasticsearch-query/376531 "2025-04-05T23:30:19Z")

</div>

Hello, I use a really strong request for my project. I tried to follow Elasticsearch tunes for search speed but it looks like its slower than before. Here you can find my request before I did the optimizations : { "qu…

---

## [Best Way to Convert Dynamic Frontend Filters to Elasticsearch Query DSL (Deeply Nested + AND/OR Support)](https://discuss.elastic.co/t/best-way-to-convert-dynamic-frontend-filters-to-elasticsearch-query-dsl-deeply-nested-and-or-support/376831)

<div class="topic-metadata">

**Author:** [@Hitanshi\_Mehta](https://discuss.elastic.co/u/Hitanshi_Mehta)\
**Replies:** 1\
**Last updated:** [April 5, 2025, 3:53pm UTC](https://discuss.elastic.co/t/best-way-to-convert-dynamic-frontend-filters-to-elasticsearch-query-dsl-deeply-nested-and-or-support/376831 "2025-04-05T15:53:51Z")

</div>

Hi everyone, I'm working on a frontend application that includes a flexible filter UI, allowing users to build complex search conditions using nested groups and logical operators (AND, OR). Each filter has a structure l…

---

## [Match against threat feed entries without Enterprise license](https://discuss.elastic.co/t/match-against-threat-feed-entries-without-enterprise-license/376771)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [April 4, 2025, 2:42pm UTC](https://discuss.elastic.co/t/match-against-threat-feed-entries-without-enterprise-license/376771 "2025-04-04T14:42:45Z")

</div>

We use Filebeat to ingest network logs. We're experimenting with threat feed ingestion, and would like to find matches between fields in our logs (say destination.ip) and entries in the threat feed. Is there a way to do …

---

## [Elastic pod is not Ready: Readiness probe failed: nc: connect to 127.0.0.1 port 8080 (tcp) failed: Connection refused](https://discuss.elastic.co/t/elastic-pod-is-not-ready-readiness-probe-failed-nc-connect-to-127-0-0-1-port-8080-tcp-failed-connection-refused/368853)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 4\
**Last updated:** [April 4, 2025, 8:15am UTC](https://discuss.elastic.co/t/elastic-pod-is-not-ready-readiness-probe-failed-nc-connect-to-127-0-0-1-port-8080-tcp-failed-connection-refused/368853 "2025-04-04T08:15:55Z")

</div>

Hello everyone, We had recently an upgrade of K8s nodes, during which one all pods were killed. Since the Elastic instances were deployed via ECK, the ECK operator automatically recreated the pods. However, the Elastic …

---

## [Seperate the elements into multiple documents using ingest pipeline](https://discuss.elastic.co/t/seperate-the-elements-into-multiple-documents-using-ingest-pipeline/376752)

<div class="topic-metadata">

**Author:** [@sai7276p](https://discuss.elastic.co/u/sai7276p)\
**Replies:** 3\
**Last updated:** [April 3, 2025, 8:00pm UTC](https://discuss.elastic.co/t/seperate-the-elements-into-multiple-documents-using-ingest-pipeline/376752 "2025-04-03T20:00:32Z")

</div>

Hi I want to create multiple documents/events based on the target field. Target field contains multiple elements and want to seperate it and create multiple documents using ingest pipeline. I tried with foreach and scri…

---

## [How to use the EVAL SPLIT command?](https://discuss.elastic.co/t/how-to-use-the-eval-split-command/376757)

<div class="topic-metadata">

**Author:** [@Piotr\_Lojowski](https://discuss.elastic.co/u/Piotr_Lojowski)\
**Replies:** 0\
**Last updated:** [April 3, 2025, 4:22pm UTC](https://discuss.elastic.co/t/how-to-use-the-eval-split-command/376757 "2025-04-03T16:22:23Z")

</div>

Hi! I'm just starting out with Elastic. How do I use the EVAL SPLIT command? I have a field that contains the following text: value1; value2; value3; I'd like to split them into separate columns.

---

## [Shards distribution implements after upgrade](https://discuss.elastic.co/t/shards-distribution-implements-after-upgrade/376747)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 7\
**Last updated:** [April 3, 2025, 5:21pm UTC](https://discuss.elastic.co/t/shards-distribution-implements-after-upgrade/376747 "2025-04-03T17:21:30Z")

</div>

Hello, I was informed that there was a vulnerability \[CVE-2025-25012\] in older versions of ELK so I set out to go through the whole process to upgrade to the latest version. It is the second time I do it and I am afraid…

---

## [Elasticsearch Engineer (On-Demand) lab expired](https://discuss.elastic.co/t/elasticsearch-engineer-on-demand-lab-expired/376726)

<div class="topic-metadata">

**Author:** [@hasham](https://discuss.elastic.co/u/hasham)\
**Replies:** 0\
**Last updated:** [April 3, 2025, 8:22am UTC](https://discuss.elastic.co/t/elasticsearch-engineer-on-demand-lab-expired/376726 "2025-04-03T08:22:07Z")

</div>

My Elasticsearch Engineer (On-demand) lab has expired after 90 days since I first accessed it. Is there a way it can be re-instated? Or at the minimum, can the lab guide be provided so that I can attempt the lab on a dif…

---

## [Huge amount of Space not released for \_recovery\_source](https://discuss.elastic.co/t/huge-amount-of-space-not-released-for-recovery-source/375477)

<div class="topic-metadata">

**Author:** [@Wei\_Chen](https://discuss.elastic.co/u/Wei_Chen)\
**Replies:** 10\
**Last updated:** [April 2, 2025, 9:14pm UTC](https://discuss.elastic.co/t/huge-amount-of-space-not-released-for-recovery-source/375477 "2025-04-02T21:14:39Z")

</div>

Hi, I am trying to optimize my dense vector space usage of the \_source field but haven't got any luck so far. I tried with turning on synthetic source, but then I observed that I now see a new \_recovery\_source field taki…

---

## [Indexing rate for data streams](https://discuss.elastic.co/t/indexing-rate-for-data-streams/376566)

<div class="topic-metadata">

**Author:** [@Dr00py](https://discuss.elastic.co/u/Dr00py)\
**Replies:** 3\
**Last updated:** [April 2, 2025, 4:50pm UTC](https://discuss.elastic.co/t/indexing-rate-for-data-streams/376566 "2025-04-02T16:50:17Z")

</div>

I want to calculate the indexing speed of documents in primary shards in my data streams. When monitoring is enabled, I can see the index rate for each index. But I can't do this for any data stream from my clusters. I …

---

## [Typesafety and ElasticSearch](https://discuss.elastic.co/t/typesafety-and-elasticsearch/376689)

<div class="topic-metadata">

**Author:** [@CLOVIS-AI](https://discuss.elastic.co/u/CLOVIS-AI)\
**Replies:** 0\
**Last updated:** [April 2, 2025, 1:41pm UTC](https://discuss.elastic.co/t/typesafety-and-elasticsearch/376689 "2025-04-02T13:41:46Z")

</div>

Hi! I'm the author of KtMongo, a Kotlin driver for MongoDB. One of the features of KtMongo is the ability to use Kotlin's DSLs to recreate typesafe requests within Kotlin itself. For example, a user could declare the s…

---

## [Elastic search 1000 req/s with max response time under 100 ms](https://discuss.elastic.co/t/elastic-search-1000-req-s-with-max-response-time-under-100-ms/376506)

<div class="topic-metadata">

**Author:** [@Majri\_Mohamed](https://discuss.elastic.co/u/Majri_Mohamed)\
**Replies:** 5\
**Last updated:** [April 2, 2025, 1:30pm UTC](https://discuss.elastic.co/t/elastic-search-1000-req-s-with-max-response-time-under-100-ms/376506 "2025-04-02T13:30:29Z")

</div>

my server is 85 vCPU with 200 gb ram i want to run 1000 req/s of medium search queries and aggregations with 100% success and max latency and response time under 100 ms I need help on the configuration please for Elast…

---

## [ES6 Cluster , with mult-NIC(Each node has more than two ips) bindip to 0.0.0.0 successfully . But Same with ES8 does not work](https://discuss.elastic.co/t/es6-cluster-with-mult-nic-each-node-has-more-than-two-ips-bindip-to-0-0-0-0-successfully-but-same-with-es8-does-not-work/376447)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 13\
**Last updated:** [April 2, 2025, 1:12pm UTC](https://discuss.elastic.co/t/es6-cluster-with-mult-nic-each-node-has-more-than-two-ips-bindip-to-0-0-0-0-successfully-but-same-with-es8-does-not-work/376447 "2025-04-02T13:12:48Z")

</div>

ES6 Cluster , with mult-NIC(Each node has more than two ips) bindip to 0.0.0.0 successfully . But Same with ES8 does not work. ES 8.15.2 Cluster throws and error in installation of two or more servers with (Each server…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=36)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=38)
