# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=38

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 39

---

## [Fail to generate certs](https://discuss.elastic.co/t/fail-to-generate-certs/376625)

<div class="topic-metadata">

**Author:** [@zan135](https://discuss.elastic.co/u/zan135)\
**Replies:** 2\
**Last updated:** [April 2, 2025, 11:10am UTC](https://discuss.elastic.co/t/fail-to-generate-certs/376625 "2025-04-02T11:10:51Z")

</div>

Hello I'm trying to deploy elasticsearch and kibana using docker-compose but the elasticsearch container exited because the file usr/share/elasticsearch/config/certs/transport.p12 does not exists. Precision 1 : I want t…

---

## [Two simple and quite basic questions regarding search performance in elastichsearch](https://discuss.elastic.co/t/two-simple-and-quite-basic-questions-regarding-search-performance-in-elastichsearch/376662)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 7\
**Last updated:** [April 2, 2025, 11:07am UTC](https://discuss.elastic.co/t/two-simple-and-quite-basic-questions-regarding-search-performance-in-elastichsearch/376662 "2025-04-02T11:07:15Z")

</div>

Dear community I have two simple and quite basic questions regarding search performance in elastichsearch in general: If I am interested of doing searches in the documents / indicies in a time window of max. the latest …

---

## [Recurring searches with the same request for dense\_vector exhibit consistency issues in the results](https://discuss.elastic.co/t/recurring-searches-with-the-same-request-for-dense-vector-exhibit-consistency-issues-in-the-results/372347)

<div class="topic-metadata">

**Author:** [@Zona-hu](https://discuss.elastic.co/u/Zona-hu)\
**Replies:** 2\
**Last updated:** [April 2, 2025, 10:35am UTC](https://discuss.elastic.co/t/recurring-searches-with-the-same-request-for-dense-vector-exhibit-consistency-issues-in-the-results/372347 "2025-04-02T10:35:55Z")

</div>

In an index without replicas, with no data being written, some vector requests, when repeated, yield inconsistent results. This issue is reproducible in versions 8.13.4, 8.15.1, and 8.17.0, but cannot be reproduced in v…

---

## [Sharepoint](https://discuss.elastic.co/t/sharepoint/376424)

<div class="topic-metadata">

**Author:** [@volivares](https://discuss.elastic.co/u/volivares)\
**Replies:** 4\
**Last updated:** [April 2, 2025, 8:31am UTC](https://discuss.elastic.co/t/sharepoint/376424 "2025-04-02T08:31:18Z")

</div>

I'm having an issue with the SharePoint connector that isn't finishing its updates completely. It's throwing the following error: PermissionsMissing: Received Unauthorized response for https://xxxx.sharepoint.com/sites…

---

## [Restore snapshot checksum problem (Troubleshooting corruption)](https://discuss.elastic.co/t/restore-snapshot-checksum-problem-troubleshooting-corruption/369764)

<div class="topic-metadata">

**Author:** [@IgorSim](https://discuss.elastic.co/u/IgorSim)\
**Replies:** 22\
**Last updated:** [April 1, 2025, 5:05pm UTC](https://discuss.elastic.co/t/restore-snapshot-checksum-problem-troubleshooting-corruption/369764 "2025-04-01T17:05:55Z")

</div>

Hi, i'm encountering a problem when restoring ES snapshot into an empty cluster, some of the indices can't be restored due to org.apache.lucene.index.CorruptIndexException checksum failed (i'm using ES version 8.10) I'm…

---

## [Maximum characters limit text fields in elasticsearch](https://discuss.elastic.co/t/maximum-characters-limit-text-fields-in-elasticsearch/376616)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [April 1, 2025, 3:27pm UTC](https://discuss.elastic.co/t/maximum-characters-limit-text-fields-in-elasticsearch/376616 "2025-04-01T15:27:16Z")

</div>

Hi Team, We are using an API to get the data into elasticsearch and the API will give the entire documents in the response body which will be stored into elasticsearch into message or event.original. Could you please le…

---

## [Winlogbeat can't communicate with Elastic search Server](https://discuss.elastic.co/t/winlogbeat-cant-communicate-with-elastic-search-server/376650)

<div class="topic-metadata">

**Author:** [@lorimer](https://discuss.elastic.co/u/lorimer)\
**Replies:** 0\
**Last updated:** [April 1, 2025, 2:50pm UTC](https://discuss.elastic.co/t/winlogbeat-cant-communicate-with-elastic-search-server/376650 "2025-04-01T14:50:52Z")

</div>

Installed winlogbeat in 2 systems running Windows 2022 Server. None of them communicated it's log files to the Elastic Search server

---

## [Testing Custom Log Ingestion Issue: ECS Field](https://discuss.elastic.co/t/testing-custom-log-ingestion-issue-ecs-field/376603)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 3\
**Last updated:** [April 1, 2025, 2:36pm UTC](https://discuss.elastic.co/t/testing-custom-log-ingestion-issue-ecs-field/376603 "2025-04-01T14:36:48Z")

</div>

Hello, I am trying to test out parsing some new logs via Custom File stream Integration. I did an initial upload and then worked backwards by creating the ingest pipeline using the sample documents from the initial uplo…

---

## [Is setting up elk stack on docker intentionaly this complicated?](https://discuss.elastic.co/t/is-setting-up-elk-stack-on-docker-intentionaly-this-complicated/376622)

<div class="topic-metadata">

**Author:** [@batttererere](https://discuss.elastic.co/u/batttererere)\
**Replies:** 11\
**Last updated:** [April 1, 2025, 12:42pm UTC](https://discuss.elastic.co/t/is-setting-up-elk-stack-on-docker-intentionaly-this-complicated/376622 "2025-04-01T12:42:41Z")

</div>

I've been dealing with this for a couple hours now, followed half a dozen tutorials i am not a noob, i've set up a thousand servers, i run my own stack at home with a dozen containers. but this? impossible. does anyo…

---

## [Retrieve linked doc with images in a multimodal RAG app](https://discuss.elastic.co/t/retrieve-linked-doc-with-images-in-a-multimodal-rag-app/368287)

<div class="topic-metadata">

**Author:** [@zan135](https://discuss.elastic.co/u/zan135)\
**Replies:** 2\
**Last updated:** [April 1, 2025, 9:26am UTC](https://discuss.elastic.co/t/retrieve-linked-doc-with-images-in-a-multimodal-rag-app/368287 "2025-04-01T09:26:46Z")

</div>

Hello, I need to retrieve documents using a "join" property. Let's explain: I have 2 kind of documents in my index : "test" images and chunks, they are formatted like this { "type":"image" or "chunk", "content":"…

---

## [How can APM anomaly detection be fine-tuned or adjusted to effectively address periodic fluctuations in service metrics?](https://discuss.elastic.co/t/how-can-apm-anomaly-detection-be-fine-tuned-or-adjusted-to-effectively-address-periodic-fluctuations-in-service-metrics/376610)

<div class="topic-metadata">

**Author:** [@arT1](https://discuss.elastic.co/u/arT1)\
**Replies:** 2\
**Last updated:** [April 1, 2025, 8:49am UTC](https://discuss.elastic.co/t/how-can-apm-anomaly-detection-be-fine-tuned-or-adjusted-to-effectively-address-periodic-fluctuations-in-service-metrics/376610 "2025-04-01T08:49:21Z")

</div>

Elastic Stack v8.13.3 Use the Elastic APM monitoring service and enable APM Machine Learning (ML). My service metrics data exhibits a regular pattern, with a higher number of visits during weekdays and a significantly l…

---

## [Is it possible to create a new index (transform) by using a field of array type from another index?](https://discuss.elastic.co/t/is-it-possible-to-create-a-new-index-transform-by-using-a-field-of-array-type-from-another-index/376607)

<div class="topic-metadata">

**Author:** [@Nishanth\_Vimalesh](https://discuss.elastic.co/u/Nishanth_Vimalesh)\
**Replies:** 0\
**Last updated:** [April 1, 2025, 1:45am UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-new-index-transform-by-using-a-field-of-array-type-from-another-index/376607 "2025-04-01T01:45:08Z")

</div>

Hi Team, I have a set of documents in an index (index\_a) with fields that look like this: { \_id: \<\>, another\_id: \<\>, float\_field: \<\>, array: \[ {array\_1\_field\_1: \<\>, array\_1\_field\_2: \<\>}, {array\_2\_field\_1: \<\>, array\_2\_f…

---

## [Datastream : reindex an indice](https://discuss.elastic.co/t/datastream-reindex-an-indice/376571)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 3\
**Last updated:** [March 31, 2025, 9:04pm UTC](https://discuss.elastic.co/t/datastream-reindex-an-indice/376571 "2025-03-31T21:04:30Z")

</div>

Hi, I have a datastream named "logs-local1-default" that have 3 indices: .ds-logs-local1-default-2024.12.11-000001 .ds-logs-local1-default-2025.02.15-000002 .ds-logs-local1-default-2025.03.25-000003 One (the second o…

---

## [Filebeat io.pressure no such file or directory issue](https://discuss.elastic.co/t/filebeat-io-pressure-no-such-file-or-directory-issue/376579)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [March 31, 2025, 11:13am UTC](https://discuss.elastic.co/t/filebeat-io-pressure-no-such-file-or-directory-issue/376579 "2025-03-31T11:13:04Z")

</div>

I have multiple Linux servers and Filebeat 7.16.3. I get this log on all servers and it throws the log every 1-2 min. 2025-03-31T13:00:18.519+0200 ERROR metrics/metrics.go:380 error getting cgroup stats: error fe…

---

## [Kibana Shows Black Screen After Login Need Help](https://discuss.elastic.co/t/kibana-shows-black-screen-after-login-need-help/375155)

<div class="topic-metadata">

**Author:** [@xirawa](https://discuss.elastic.co/u/xirawa)\
**Replies:** 3\
**Last updated:** [March 2, 2025, 4:26am UTC](https://discuss.elastic.co/t/kibana-shows-black-screen-after-login-need-help/375155 "2025-03-02T04:26:47Z")

</div>

Hi Everyone, I recently upgraded my Elastic Stack version X.X and now when I try to access Kibana, all I see is a black screen after logging in. The browser loads the Kibana interface, but no content appears. Elasticse…

---

## [Unable to install elasticsearch on ubuntu](https://discuss.elastic.co/t/unable-to-install-elasticsearch-on-ubuntu/376565)

<div class="topic-metadata">

**Author:** [@remoteconn-7891](https://discuss.elastic.co/u/remoteconn-7891)\
**Replies:** 12\
**Last updated:** [March 31, 2025, 5:47am UTC](https://discuss.elastic.co/t/unable-to-install-elasticsearch-on-ubuntu/376565 "2025-03-31T05:47:06Z")

</div>

Hello, I'm back. So I'm on Ubuntu Desktop now and trying to install Elasticsearch on the local terminal. The problem, I get an error that says it can't find the package. Here is the error message I get (venv) corey-jam…

---

## [Disable entitlement by default in elastic 8.17](https://discuss.elastic.co/t/disable-entitlement-by-default-in-elastic-8-17/376509)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 3\
**Last updated:** [March 31, 2025, 1:27am UTC](https://discuss.elastic.co/t/disable-entitlement-by-default-in-elastic-8-17/376509 "2025-03-31T01:27:15Z")

</div>

I have a requirement to disable the checks for elasticsearch entitlement. Could you please let me know how is it possible

---

## [Data Node Offline on Kibana Dashboard](https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300)

<div class="topic-metadata">

**Author:** [@gardito-git](https://discuss.elastic.co/u/gardito-git)\
**Replies:** 3\
**Last updated:** [March 28, 2025, 11:28pm UTC](https://discuss.elastic.co/t/data-node-offline-on-kibana-dashboard/376300 "2025-03-28T23:28:59Z")

</div>

Greetings everyone, I'm sorry I'm newbie here I have a single master node, single data node and 1 kibana node in our Dev ENV I'm trying to monitoring our Elasticsearch Cluster with this guide when I click the red butto…

---

## [Restart Elasticsearch Instance one at a time](https://discuss.elastic.co/t/restart-elasticsearch-instance-one-at-a-time/376344)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [March 28, 2025, 11:24pm UTC](https://discuss.elastic.co/t/restart-elasticsearch-instance-one-at-a-time/376344 "2025-03-28T23:24:04Z")

</div>

Hi Team, I want to discuss one issue that Every month we have OS patching. The team will apply patches at server level and they asked application team to stop their application so that they can go for reboot activity on…

---

## [Elastic OpenAI Connector Local LLM](https://discuss.elastic.co/t/elastic-openai-connector-local-llm/375228)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 3\
**Last updated:** [March 28, 2025, 6:53pm UTC](https://discuss.elastic.co/t/elastic-openai-connector-local-llm/375228 "2025-03-28T18:53:58Z")

</div>

Hello everyone, i have an elastic instance where i try to set up a custom OpenAI connector to a machine with a locally hosted LLM to use within the AI Assistant. Since 8.17 it is possible to use an OpenAI compatible API…

---

## [Alert on no data per source?](https://discuss.elastic.co/t/alert-on-no-data-per-source/376425)

<div class="topic-metadata">

**Author:** [@Mike8](https://discuss.elastic.co/u/Mike8)\
**Replies:** 12\
**Last updated:** [March 28, 2025, 4:45pm UTC](https://discuss.elastic.co/t/alert-on-no-data-per-source/376425 "2025-03-28T16:45:37Z")

</div>

here @leandrojmp suggested a Log Threshold to get reported when no logs are added in the last 5 mins. This works but only if you add the specific source as a WITH condition. In my case I want to be reported on say 6 sour…

---

## [Unconfirmed Bug: q-Values in Accept-Language Header prevents search results](https://discuss.elastic.co/t/unconfirmed-bug-q-values-in-accept-language-header-prevents-search-results/376540)

<div class="topic-metadata">

**Author:** [@freezernick](https://discuss.elastic.co/u/freezernick)\
**Replies:** 0\
**Last updated:** [March 28, 2025, 4:35pm UTC](https://discuss.elastic.co/t/unconfirmed-bug-q-values-in-accept-language-header-prevents-search-results/376540 "2025-03-28T16:35:27Z")

</div>

I have a simple search query that works in all browsers except FF desktop. I could narrow it down to the q-Values of the Accept-Language Header from FF. de,en-US;q=0.7,en;q=0.3 -\> no results de,en-US; -\> results I'm …

---

## [Snapshot restore not restoring DataViews/Dashboard/Alerts](https://discuss.elastic.co/t/snapshot-restore-not-restoring-dataviews-dashboard-alerts/376536)

<div class="topic-metadata">

**Author:** [@optionalname1](https://discuss.elastic.co/u/optionalname1)\
**Replies:** 0\
**Last updated:** [March 28, 2025, 3:46pm UTC](https://discuss.elastic.co/t/snapshot-restore-not-restoring-dataviews-dashboard-alerts/376536 "2025-03-28T15:46:31Z")

</div>

Hey there, I was having some issues with my kibana logs/access and then I tried to restore using an old snapshot. But now all my views dashboard alerts are gone. Any chance I can get them back? Thank you in advance.

---

## [Bad version on master node](https://discuss.elastic.co/t/bad-version-on-master-node/376488)

<div class="topic-metadata">

**Author:** [@MaxiNimkus](https://discuss.elastic.co/u/MaxiNimkus)\
**Replies:** 8\
**Last updated:** [March 28, 2025, 2:23pm UTC](https://discuss.elastic.co/t/bad-version-on-master-node/376488 "2025-03-28T14:23:44Z")

</div>

Hi everyone, I have an ELASTIC cluster with 3 master nodes and 6 data nodes. I'm having a problem because one master node has upgraded to 8.17.3 while all the other nodes are running 8.17.0. I want to remove this mast…

---

## [Possible bug: Elasticsearch not honouring index.unassigned.node\_left.delayed\_timeout](https://discuss.elastic.co/t/possible-bug-elasticsearch-not-honouring-index-unassigned-node-left-delayed-timeout/376393)

<div class="topic-metadata">

**Author:** [@juan.domenech](https://discuss.elastic.co/u/juan.domenech)\
**Replies:** 5\
**Last updated:** [March 28, 2025, 1:16pm UTC](https://discuss.elastic.co/t/possible-bug-elasticsearch-not-honouring-index-unassigned-node-left-delayed-timeout/376393 "2025-03-28T13:16:20Z")

</div>

In Elasticsearch latest (8.17.3) running in Kubernetes ECK (2.16.0) will wait for 5 minutes to assign an Unassigned shard no matter the value of index.unassigned.node\_left.delayed\_timeout in the index configuration. Ple…

---

## [How does elastic compare to mongodb for vector search](https://discuss.elastic.co/t/how-does-elastic-compare-to-mongodb-for-vector-search/376467)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [March 28, 2025, 10:06am UTC](https://discuss.elastic.co/t/how-does-elastic-compare-to-mongodb-for-vector-search/376467 "2025-03-28T10:06:35Z")

</div>

we are evaluating elastic and mongodb for our vector search usecase. What are some advantages of elastic over mongodb?

---

## [No Role/User Admin - no reporting](https://discuss.elastic.co/t/no-role-user-admin-no-reporting/376514)

<div class="topic-metadata">

**Author:** [@Michael\_Jervis](https://discuss.elastic.co/u/Michael_Jervis)\
**Replies:** 1\
**Last updated:** [March 28, 2025, 9:16am UTC](https://discuss.elastic.co/t/no-role-user-admin-no-reporting/376514 "2025-03-28T09:16:57Z")

</div>

Hi, We set up ELK 7.17 some time ago following a digital ocean guide here: The login appears to just be set up via the NGINX basic auth. When I go into Stack Management there is no Roles or Users section, we don't ha…

---

## [Enabling Trace Logging for a shard/index](https://discuss.elastic.co/t/enabling-trace-logging-for-a-shard-index/376486)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 4\
**Last updated:** [March 28, 2025, 5:28am UTC](https://discuss.elastic.co/t/enabling-trace-logging-for-a-shard-index/376486 "2025-03-28T05:28:13Z")

</div>

Hi Team, Is there a way to enable trace logging for a particular shard or particular index in elasticsearch. I tried doing this but it didn't work PUT \_cluster/settings { "transient": { "logger.org.elasticsearch…

---

## [Java: java.lang.foreign.\* is a preview API and is disabled by default. (use --enable-preview to enable preview APIs)](https://discuss.elastic.co/t/java-java-lang-foreign-is-a-preview-api-and-is-disabled-by-default-use-enable-preview-to-enable-preview-apis/376442)

<div class="topic-metadata">

**Author:** [@Jo\_Vanmont](https://discuss.elastic.co/u/Jo_Vanmont)\
**Replies:** 5\
**Last updated:** [March 28, 2025, 3:10am UTC](https://discuss.elastic.co/t/java-java-lang-foreign-is-a-preview-api-and-is-disabled-by-default-use-enable-preview-to-enable-preview-apis/376442 "2025-03-28T03:10:10Z")

</div>

I'm trying to compile the elasticsearch-main source code with java version 21 in intellij idea but are getting this error. Tried already to add --enable-preview to the compiler vm options but no success.

---

## [Elasticsearch 8.17.2: Native memory allocation (mmap) failed](https://discuss.elastic.co/t/elasticsearch-8-17-2-native-memory-allocation-mmap-failed/376485)

<div class="topic-metadata">

**Author:** [@pavlodvornikov](https://discuss.elastic.co/u/pavlodvornikov)\
**Replies:** 2\
**Last updated:** [March 27, 2025, 4:08pm UTC](https://discuss.elastic.co/t/elasticsearch-8-17-2-native-memory-allocation-mmap-failed/376485 "2025-03-27T16:08:48Z")

</div>

Hello, I just recently upgraded my Elasticsearch cluster from 8.10.4 to 8.17.2. Prior to that I have not experienced memory issues with the same load. Data nodes run on i4i.2xlarge EC2 instances with 64G RAM and 8 vCPU…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=37)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=39)
