# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=39

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 40

---

## [SAN storage - I/O values](https://discuss.elastic.co/t/san-storage-i-o-values/376474)

<div class="topic-metadata">

**Author:** [@stephanenm](https://discuss.elastic.co/u/stephanenm)\
**Replies:** 2\
**Last updated:** [March 27, 2025, 1:49pm UTC](https://discuss.elastic.co/t/san-storage-i-o-values/376474 "2025-03-27T13:49:45Z")

</div>

Hello all, I am currently in charge to about find a storage system than can works with Elastic solutions. I need to have this storage system on prem so any cloud services is forbiden. I have read that Objet storage or …

---

## [Automatic Rollover on Elastic Serverless deployment?](https://discuss.elastic.co/t/automatic-rollover-on-elastic-serverless-deployment/376406)

<div class="topic-metadata">

**Author:** [@Nicolo\_Boschi](https://discuss.elastic.co/u/Nicolo_Boschi)\
**Replies:** 3\
**Last updated:** [March 26, 2025, 1:19pm UTC](https://discuss.elastic.co/t/automatic-rollover-on-elastic-serverless-deployment/376406 "2025-03-26T13:19:13Z")

</div>

I wanted to configure automatic rollover for my index in a new Elastic Serverless deployment. From the docs, it looks like it should be managed automatically by the platform itself. Is it true? What is the threshold? I…

---

## [Need help setting up a second node](https://discuss.elastic.co/t/need-help-setting-up-a-second-node/375785)

<div class="topic-metadata">

**Author:** [@hairless\_mess](https://discuss.elastic.co/u/hairless_mess)\
**Replies:** 25\
**Last updated:** [March 26, 2025, 10:53am UTC](https://discuss.elastic.co/t/need-help-setting-up-a-second-node/375785 "2025-03-26T10:53:13Z")

</div>

Hello! I have a server with Elasticsearch, Kibana and a fleet-server agent installed. I use all the default certificates created in the beginning (automatic security configuration I believe it's called?). I would like…

---

## [Modifying StatefulSet updateStrategy in Elasticsearch k8s Operator from OnDelete to RollingUpdate](https://discuss.elastic.co/t/modifying-statefulset-updatestrategy-in-elasticsearch-k8s-operator-from-ondelete-to-rollingupdate/376397)

<div class="topic-metadata">

**Author:** [@Marian\_MIRON](https://discuss.elastic.co/u/Marian_MIRON)\
**Replies:** 0\
**Last updated:** [March 26, 2025, 2:49am UTC](https://discuss.elastic.co/t/modifying-statefulset-updatestrategy-in-elasticsearch-k8s-operator-from-ondelete-to-rollingupdate/376397 "2025-03-26T02:49:06Z")

</div>

Using the Elasticsearch k8s Operator, I need help changing the updateStrategy in a StatefulSet from type: OnDelete to type: RollingUpdate. I'm working with Helm templates to manage the CRDs. What's the best way to accomp…

---

## [ILM policy not triggering a new index](https://discuss.elastic.co/t/ilm-policy-not-triggering-a-new-index/376066)

<div class="topic-metadata">

**Author:** [@aravinds257](https://discuss.elastic.co/u/aravinds257)\
**Replies:** 1\
**Last updated:** [March 25, 2025, 3:25pm UTC](https://discuss.elastic.co/t/ilm-policy-not-triggering-a-new-index/376066 "2025-03-25T15:25:24Z")

</div>

I have index created on a weekly basis via a pipeline which creates a index ending with \_yyyymmddw, but was relying on ILM policy sharding based on if it reaches the 50gb limit. Even though the index action shows as roll…

---

## [Performance issue on 40TB index](https://discuss.elastic.co/t/performance-issue-on-40tb-index/376021)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 5\
**Last updated:** [March 25, 2025, 8:52am UTC](https://discuss.elastic.co/t/performance-issue-on-40tb-index/376021 "2025-03-25T08:52:33Z")

</div>

Hello All, I have 40 TB of index having about 6 Billion documents in single index. My ES query is Fetching 100000 unique values of uniqueId values (applying terms aggregations) from single ES query. Currently, we ini…

---

## [Node.js client uses master only nodes by default](https://discuss.elastic.co/t/node-js-client-uses-master-only-nodes-by-default/376162)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 6\
**Last updated:** [March 25, 2025, 10:13am UTC](https://discuss.elastic.co/t/node-js-client-uses-master-only-nodes-by-default/376162 "2025-03-25T10:13:55Z")

</div>

Hey, a couple of days ago I noticed that our node.js client by default seems to use master only nodes for queries, even though there are dedicated data nodes. The docs show this default node filter: function defaultNo…

---

## [Need help disabling field type casting for computer forensics logs](https://discuss.elastic.co/t/need-help-disabling-field-type-casting-for-computer-forensics-logs/376334)

<div class="topic-metadata">

**Author:** [@Hofmupy](https://discuss.elastic.co/u/Hofmupy)\
**Replies:** 1\
**Last updated:** [March 24, 2025, 5:54pm UTC](https://discuss.elastic.co/t/need-help-disabling-field-type-casting-for-computer-forensics-logs/376334 "2025-03-24T17:54:27Z")

</div>

Hi, While currently working on developing a tool for computer forensics relying on Elasticsearch, I am facing several issues related to field types. The tool is parsing data using Vector, and sends it directly to Elast…

---

## [KNN \_score not lining up with similarity filter](https://discuss.elastic.co/t/knn-score-not-lining-up-with-similarity-filter/376088)

<div class="topic-metadata">

**Author:** [@Yakob](https://discuss.elastic.co/u/Yakob)\
**Replies:** 4\
**Last updated:** [March 24, 2025, 4:03pm UTC](https://discuss.elastic.co/t/knn-score-not-lining-up-with-similarity-filter/376088 "2025-03-24T16:03:57Z")

</div>

Hi Elastic experts, I have the following elastic query, which returns 452 hits. { "explain": true, "knn": { "field": "derived.models.multilingualE5LargeInstruct", "query\_vector": \[{{1024 element …

---

## [How can i Disable SSL on Metricbeat?](https://discuss.elastic.co/t/how-can-i-disable-ssl-on-metricbeat/376226)

<div class="topic-metadata">

**Author:** [@Nooot\_VK](https://discuss.elastic.co/u/Nooot_VK)\
**Replies:** 3\
**Last updated:** [March 24, 2025, 2:02pm UTC](https://discuss.elastic.co/t/how-can-i-disable-ssl-on-metricbeat/376226 "2025-03-24T14:02:39Z")

</div>

Hey guys! I'm trying to temporarily disable SSL in Metricbeat due to a certificate issue, but I'm not getting it. Is there any way to disable it? I've tried this, but it doesn't work. ssl.verification\_mode: none ssl.ena…

---

## [Getting error while trying to connect a DB from ELK](https://discuss.elastic.co/t/getting-error-while-trying-to-connect-a-db-from-elk/376063)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 4\
**Last updated:** [March 24, 2025, 11:14am UTC](https://discuss.elastic.co/t/getting-error-while-trying-to-connect-a-db-from-elk/376063 "2025-03-24T11:14:59Z")

</div>

Getting connectivity error while trying to connect through default user and password for elasticsearch. "received plaintext http traffic on an https channel, closing connection Netty4HttpChannel{localAddress=/172.24.217…

---

## [Triggered esql alert rule does not expose document results](https://discuss.elastic.co/t/triggered-esql-alert-rule-does-not-expose-document-results/375907)

<div class="topic-metadata">

**Author:** [@FPTravStan](https://discuss.elastic.co/u/FPTravStan)\
**Replies:** 2\
**Last updated:** [March 24, 2025, 6:27am UTC](https://discuss.elastic.co/t/triggered-esql-alert-rule-does-not-expose-document-results/375907 "2025-03-24T06:27:05Z")

</div>

Hello, I'm looking for some help with getting an ESQL query based alert to expose the documents results so that it can be used in the customDetails of the pagerduty payload when triggered. Looking at the an example of …

---

## [Best practices for index needed for AI Analyst use cases](https://discuss.elastic.co/t/best-practices-for-index-needed-for-ai-analyst-use-cases/375964)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 3\
**Last updated:** [March 24, 2025, 5:53am UTC](https://discuss.elastic.co/t/best-practices-for-index-needed-for-ai-analyst-use-cases/375964 "2025-03-24T05:53:55Z")

</div>

Hi Team, Currently we have 2 indices for storing the raw datasets without doing any transformations. These datasets have very nested structure. This was fine for the current use cases where the only search pattern we h…

---

## [Unable to create Index in Elastic Search](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search/376256)

<div class="topic-metadata">

**Author:** [@pengdijie](https://discuss.elastic.co/u/pengdijie)\
**Replies:** 4\
**Last updated:** [March 23, 2025, 7:38pm UTC](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search/376256 "2025-03-23T19:38:46Z")

</div>

Hello, I'm trying to Use Elasticsearch to index the Wikipedia dump, but this error appears here elastic\_transport.ConnectionError: Connection error caused by: NewConnectionError(\<elastic\_transport.\_node.\_urllib3\_chain\_c…

---

## [Explode a document into multiple documents by delimited text field](https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 3\
**Last updated:** [March 21, 2025, 11:56pm UTC](https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141 "2025-03-21T23:56:10Z")

</div>

I have the following index. colors,value "blue,red", 10 "red", 20 "green", 5 "blue,red", 15 "blue,green", 5 I want to aggregate value by color like so. blue = 10, 15, 5 red = 10, 20, 15 green = 5, 5 The problem is th…

---

## [Case insensitive regex query with character range](https://discuss.elastic.co/t/case-insensitive-regex-query-with-character-range/376136)

<div class="topic-metadata">

**Author:** [@petrsimon](https://discuss.elastic.co/u/petrsimon)\
**Replies:** 10\
**Last updated:** [March 21, 2025, 3:07pm UTC](https://discuss.elastic.co/t/case-insensitive-regex-query-with-character-range/376136 "2025-03-21T15:07:26Z")

</div>

Hi, I'm implementing regex search on ES 8.16 (using java client) against fields of type keyword and I came across strange issue when sending the case\_insensitive: true option. "\[abc\]+" -\> "abc", "ABC" "\[ABC\]+" -\> "ab…

---

## [Bulk Ingester flush timing issues with wait\_for Refresh Policy](https://discuss.elastic.co/t/bulk-ingester-flush-timing-issues-with-wait-for-refresh-policy/376122)

<div class="topic-metadata">

**Author:** [@mattar](https://discuss.elastic.co/u/mattar)\
**Replies:** 5\
**Last updated:** [March 21, 2025, 9:47am UTC](https://discuss.elastic.co/t/bulk-ingester-flush-timing-issues-with-wait-for-refresh-policy/376122 "2025-03-21T09:47:24Z")

</div>

Hello everyone, I’m working with the bulk ingester in Elastic 8.15.3 and encountering some timing issues with flush. I configured the bulk ingester with a refresh policy set to wait\_for in the global settings, expecting…

---

## [Semantic search with the new semantic\_text field](https://discuss.elastic.co/t/semantic-search-with-the-new-semantic-text-field/367169)

<div class="topic-metadata">

**Author:** [@JdKock](https://discuss.elastic.co/u/JdKock)\
**Replies:** 12\
**Last updated:** [March 21, 2025, 8:39am UTC](https://discuss.elastic.co/t/semantic-search-with-the-new-semantic-text-field/367169 "2025-03-21T08:39:19Z")

</div>

I did some testing with Elser and after that I used the E5 model to play around with semantic search. I use the knn search to create a query on multiple embedding fields. I also looked at the retrievers to create a hybri…

---

## [ES|QL fails with 'Data too large message for a small dataset](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120)

<div class="topic-metadata">

**Author:** [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Replies:** 5\
**Last updated:** [March 20, 2025, 5:24pm UTC](https://discuss.elastic.co/t/es-ql-fails-with-data-too-large-message-for-a-small-dataset/376120 "2025-03-20T17:24:33Z")

</div>

I am running the following ES|QL query against 192M documents from filebeat-audit-\* | where user.name is not null AND source.ip is not null and host.name is not null | where event.outcome == "success" and cidr\_match(s…

---

## [Discard empty/null values](https://discuss.elastic.co/t/discard-empty-null-values/376170)

<div class="topic-metadata">

**Author:** [@paddington1](https://discuss.elastic.co/u/paddington1)\
**Replies:** 1\
**Last updated:** [March 20, 2025, 3:33pm UTC](https://discuss.elastic.co/t/discard-empty-null-values/376170 "2025-03-20T15:33:06Z")

</div>

Hi, Is there a way to KEEP fields which are not null/empty with ES|QL? I do not want to manually write KEEP for all of the fields which are not empty.

---

## [When to index and when to data stream?](https://discuss.elastic.co/t/when-to-index-and-when-to-data-stream/374682)

<div class="topic-metadata">

**Author:** [@h.d.intodata](https://discuss.elastic.co/u/h.d.intodata)\
**Replies:** 2\
**Last updated:** [March 20, 2025, 12:44pm UTC](https://discuss.elastic.co/t/when-to-index-and-when-to-data-stream/374682 "2025-03-20T12:44:34Z")

</div>

Hi everyone, When is it best practise to use a data stream and when is it best practise to use an index? This would be from companies who are midsized to large enterprise. Best, H

---

## [Missing Data in Elasticsearch - Need Help Resolving](https://discuss.elastic.co/t/missing-data-in-elasticsearch-need-help-resolving/376166)

<div class="topic-metadata">

**Author:** [@SalehEska](https://discuss.elastic.co/u/SalehEska)\
**Replies:** 5\
**Last updated:** [March 20, 2025, 10:09am UTC](https://discuss.elastic.co/t/missing-data-in-elasticsearch-need-help-resolving/376166 "2025-03-20T10:09:26Z")

</div>

Hello Elasticsearch community, I'm currently facing an issue where I have missing data in my Elasticsearch index. I have been investigating the issue, but there have been no errors logged in Logstash itself. The cluster…

---

## [Intervals vs match\_phrase](https://discuss.elastic.co/t/intervals-vs-match-phrase/376163)

<div class="topic-metadata">

**Author:** [@moonrazer](https://discuss.elastic.co/u/moonrazer)\
**Replies:** 0\
**Last updated:** [March 20, 2025, 7:44am UTC](https://discuss.elastic.co/t/intervals-vs-match-phrase/376163 "2025-03-20T07:44:35Z")

</div>

I am trying to convince myself that I should be using a match\_phrase query instead of an intervals query for my use case. Are there any notable differences between the following two queries? { "\_source": { "includes":…

---

## [Finding the search as you type match for multi value fields](https://discuss.elastic.co/t/finding-the-search-as-you-type-match-for-multi-value-fields/375806)

<div class="topic-metadata">

**Author:** [@elasticfan1](https://discuss.elastic.co/u/elasticfan1)\
**Replies:** 7\
**Last updated:** [March 20, 2025, 12:26am UTC](https://discuss.elastic.co/t/finding-the-search-as-you-type-match-for-multi-value-fields/375806 "2025-03-20T00:26:04Z")

</div>

I have a multi value field called tags. Let's say my doc has the following values for the tags field: \["test trim", "yellow boat", "nice car"\] If I query for "boa", I want to get back "yellow boat". However result retu…

---

## [Time Out on @elastic/elasticsearch node js](https://discuss.elastic.co/t/time-out-on-elastic-elasticsearch-node-js/376144)

<div class="topic-metadata">

**Author:** [@Santos\_Cocom](https://discuss.elastic.co/u/Santos_Cocom)\
**Replies:** 0\
**Last updated:** [March 19, 2025, 10:12pm UTC](https://discuss.elastic.co/t/time-out-on-elastic-elasticsearch-node-js/376144 "2025-03-19T22:12:27Z")

</div>

I've set up a cluster, but I've created an index to perform semantic searches. When I try to send a request, I always get a timeout. I use @elastic/elasticsearch with NodeJS. const elastichSearchClient = new Client({ …

---

## [Partition and Index by Text Field Contents](https://discuss.elastic.co/t/partition-and-index-by-text-field-contents/376139)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 3\
**Last updated:** [March 19, 2025, 9:28pm UTC](https://discuss.elastic.co/t/partition-and-index-by-text-field-contents/376139 "2025-03-19T21:28:15Z")

</div>

I have an index with the following records. text The triangle is blue. The square is red. There are two red circles. The triangle is green. I want to partition them by mentions of color in the text field, meaning that …

---

## [Need advice on improving the performance of restoring large backup from GCS repository](https://discuss.elastic.co/t/need-advice-on-improving-the-performance-of-restoring-large-backup-from-gcs-repository/376097)

<div class="topic-metadata">

**Author:** [@lzz118](https://discuss.elastic.co/u/lzz118)\
**Replies:** 7\
**Last updated:** [March 19, 2025, 9:16pm UTC](https://discuss.elastic.co/t/need-advice-on-improving-the-performance-of-restoring-large-backup-from-gcs-repository/376097 "2025-03-19T21:16:46Z")

</div>

Hi there, I am looking for some advice on improving the performance of restoring large backup from GCS repository. In my test, I am restoring about 400TB data from the GCS bucket to the 50 nodes elasticsearch cluster r…

---

## [TooManyBucketsException in Transform with Continuous High Ingestion (100k documents/minute)](https://discuss.elastic.co/t/toomanybucketsexception-in-transform-with-continuous-high-ingestion-100k-documents-minute/375509)

<div class="topic-metadata">

**Author:** [@Lucas\_Pereira](https://discuss.elastic.co/u/Lucas_Pereira)\
**Replies:** 4\
**Last updated:** [March 19, 2025, 3:23pm UTC](https://discuss.elastic.co/t/toomanybucketsexception-in-transform-with-continuous-high-ingestion-100k-documents-minute/375509 "2025-03-19T15:23:35Z")

</div>

Hi, I'm facing an issue with an Elasticsearch transform that can't handle a continuous stream of high ingestion (~100k documents per minute) into the netflow-read-\* source index, as well as occasional backlogs (e.g. 10M …

---

## [Support for colpali and other late interaction based retrieval](https://discuss.elastic.co/t/support-for-colpali-and-other-late-interaction-based-retrieval/373864)

<div class="topic-metadata">

**Author:** [@dbasu](https://discuss.elastic.co/u/dbasu)\
**Replies:** 6\
**Last updated:** [March 18, 2025, 3:03pm UTC](https://discuss.elastic.co/t/support-for-colpali-and-other-late-interaction-based-retrieval/373864 "2025-03-18T15:03:24Z")

</div>

Does elasticsearch support search based on Embeddings from models like colqwen, colpali, etc.? If yes, where can I find supporting documentation?

---

## [High CPU usage: undertand events / traffic in discover view](https://discuss.elastic.co/t/high-cpu-usage-undertand-events-traffic-in-discover-view/376074)

<div class="topic-metadata">

**Author:** [@Gerardo\_Zenobi](https://discuss.elastic.co/u/Gerardo_Zenobi)\
**Replies:** 0\
**Last updated:** [March 18, 2025, 1:56pm UTC](https://discuss.elastic.co/t/high-cpu-usage-undertand-events-traffic-in-discover-view/376074 "2025-03-18T13:56:18Z")

</div>

Hello there, I am trying to understand why my cluster is currently being overloaded (high cpu, enterprise search instances rebooting) I stumbled upon the Discover view /app/discover view in Kibana: Our problems sta…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=38)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=40)
