# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=4

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 5

---

## [    Switching Elasticsearch from HTTP to HTTPS with Active Fleet Agents](https://discuss.elastic.co/t/switching-elasticsearch-from-http-to-https-with-active-fleet-agents/386339)

<div class="topic-metadata">

**Author:** [@saeedelfiky](https://discuss.elastic.co/u/saeedelfiky)\
**Replies:** 0\
**Last updated:** [May 14, 2026, 3:08pm UTC](https://discuss.elastic.co/t/switching-elasticsearch-from-http-to-https-with-active-fleet-agents/386339 "2026-05-14T15:08:18Z")

</div>

Hey everyone, I currently have a self-managed Elastic Stack environment running over HTTP with: Elasticsearch Kibana Fleet Around 20 connected Elastic Agent instances I want to migrate Elasticsearch from …

---

## [Cluster name is logged as ${sys:es.logs.cluster\_name}](https://discuss.elastic.co/t/cluster-name-is-logged-as-sys-es-logs-cluster-name/385225)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 2\
**Last updated:** [May 14, 2026, 1:45pm UTC](https://discuss.elastic.co/t/cluster-name-is-logged-as-sys-es-logs-cluster-name/385225 "2026-05-14T13:45:35Z")

</div>

Hello we are upgrading our Elastic clusters to 9.2.5. I upgraded my monitoring cluster from 8.19.4 to 8.19.11, since this upgrade the cluster\_name in the elasticsearch server logs is logged as ${sys:es.logs.cluster\_nam…

---

## [Elasticsearch Serverless + Vector Search + Data Streams / Time Series Tradeoffs](https://discuss.elastic.co/t/elasticsearch-serverless-vector-search-data-streams-time-series-tradeoffs/386275)

<div class="topic-metadata">

**Author:** [@Januka\_Samaranayake](https://discuss.elastic.co/u/Januka_Samaranayake)\
**Replies:** 3\
**Last updated:** [May 12, 2026, 8:16am UTC](https://discuss.elastic.co/t/elasticsearch-serverless-vector-search-data-streams-time-series-tradeoffs/386275 "2026-05-12T08:16:25Z")

</div>

Hello everyone, I am trying to better understand the tradeoffs between Elasticsearch Serverless, Data Streams, TSDS (index.mode=time\_series), and future vector search workloads. Current Situation We currently have arou…

---

## [Unable to create snapshots with cifs share 9.4.0](https://discuss.elastic.co/t/unable-to-create-snapshots-with-cifs-share-9-4-0/386271)

<div class="topic-metadata">

**Author:** [@expErg](https://discuss.elastic.co/u/expErg)\
**Replies:** 4\
**Last updated:** [May 12, 2026, 7:19am UTC](https://discuss.elastic.co/t/unable-to-create-snapshots-with-cifs-share-9-4-0/386271 "2026-05-12T07:19:04Z")

</div>

Hello, Since upgrading to 9.4.0, we are experiencing snapshot failures on our CIFS-mounted shared repository. Timeline: Last successful snapshot: May 6, before the upgrade Upgrade to 9.4.0 performed: May 6 at 12:00 P…

---

## [Help in selecting the right Stack Monitoring Mode - Node vs Cluster?](https://discuss.elastic.co/t/help-in-selecting-the-right-stack-monitoring-mode-node-vs-cluster/386238)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 1\
**Last updated:** [May 11, 2026, 1:23pm UTC](https://discuss.elastic.co/t/help-in-selecting-the-right-stack-monitoring-mode-node-vs-cluster/386238 "2026-05-11T13:23:32Z")

</div>

Hey everyone, we are still on version 8.x, since we still have selfmonitoring enabled, but we want to move to version 9 as soon as possible. For now we want to switch to agent based monitoring (AutoOps is a possibility…

---

## [Elasticsearch reindex with ELSER pipeline succeeds but only generates embeddings for fraction of documents - no failures reported](https://discuss.elastic.co/t/elasticsearch-reindex-with-elser-pipeline-succeeds-but-only-generates-embeddings-for-fraction-of-documents-no-failures-reported/386228)

<div class="topic-metadata">

**Author:** [@Roland-02](https://discuss.elastic.co/u/Roland-02)\
**Replies:** 2\
**Last updated:** [May 8, 2026, 2:02pm UTC](https://discuss.elastic.co/t/elasticsearch-reindex-with-elser-pipeline-succeeds-but-only-generates-embeddings-for-fraction-of-documents-no-failures-reported/386228 "2026-05-08T14:02:16Z")

</div>

I'm reindexing documents with an ELSER inference pipeline to generate embeddings, but only a fraction of documents (usually around half) end up with embeddings despite the reindex completing successfully with no failures…

---

## [Request for product remediation guidance – bundled Apache Log4j vulnerabilities in Elasticsearch/Logstash](https://discuss.elastic.co/t/request-for-product-remediation-guidance-bundled-apache-log4j-vulnerabilities-in-elasticsearch-logstash/386221)

<div class="topic-metadata">

**Author:** [@sankalita](https://discuss.elastic.co/u/sankalita)\
**Replies:** 1\
**Last updated:** [May 7, 2026, 4:43pm UTC](https://discuss.elastic.co/t/request-for-product-remediation-guidance-bundled-apache-log4j-vulnerabilities-in-elasticsearch-logstash/386221 "2026-05-07T16:43:37Z")

</div>

Security scans have identified vulnerable Apache Log4j Core versions bundled with Elasticsearch 8.19.14 and Logstash on the host. Nessus reports CVE‑2026‑34477 and CVE‑2026‑34480, requiring Log4j 2.25.3/2.25.4 or later. …

---

## [After upgrade to 9.3.4 problem with version\_conflict\_engine\_exception](https://discuss.elastic.co/t/after-upgrade-to-9-3-4-problem-with-version-conflict-engine-exception/386162)

<div class="topic-metadata">

**Author:** [@Mario\_22](https://discuss.elastic.co/u/Mario_22)\
**Replies:** 4\
**Last updated:** [May 6, 2026, 7:53pm UTC](https://discuss.elastic.co/t/after-upgrade-to-9-3-4-problem-with-version-conflict-engine-exception/386162 "2026-05-06T19:53:38Z")

</div>

After upgrading the Elastic Stack, Fleet Server, and Elastic Agents to 9.3.4, and after re-enabling / upgrading integrations, we started seeing a very large number of errors in logs-elastic\_agent-\*. The errors look like…

---

## [AI assistant data access restrictions](https://discuss.elastic.co/t/ai-assistant-data-access-restrictions/386002)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 2\
**Last updated:** [May 6, 2026, 5:47am UTC](https://discuss.elastic.co/t/ai-assistant-data-access-restrictions/386002 "2026-05-06T05:47:33Z")

</div>

We are seeking clarification regarding data access restrictions when using the Elastic AI Assistant. We are planning to enable the Elastic AI Assistant feature for our users. Before proceeding, we would like to understa…

---

## [CEF processor](https://discuss.elastic.co/t/cef-processor/386165)

<div class="topic-metadata">

**Author:** [@Moe\_Hmaidan](https://discuss.elastic.co/u/Moe_Hmaidan)\
**Replies:** 4\
**Last updated:** [May 5, 2026, 3:42pm UTC](https://discuss.elastic.co/t/cef-processor/386165 "2026-05-05T15:42:35Z")

</div>

Does the newly introduced cef processor require license?

---

## [Filter for specific field values and create another index to store for longterm storage](https://discuss.elastic.co/t/filter-for-specific-field-values-and-create-another-index-to-store-for-longterm-storage/385273)

<div class="topic-metadata">

**Author:** [@C\_Shah](https://discuss.elastic.co/u/C_Shah)\
**Replies:** 3\
**Last updated:** [May 5, 2026, 3:34pm UTC](https://discuss.elastic.co/t/filter-for-specific-field-values-and-create-another-index-to-store-for-longterm-storage/385273 "2026-05-05T15:34:55Z")

</div>

I have filebeat sending logs from multiple files into an elasticseash index. What is the best way for me to filter on those logs and only store those filtered logs in an index for longer time (longer ILM policy)? k8s po…

---

## [Creating MSSP setup for lab (no license)](https://discuss.elastic.co/t/creating-mssp-setup-for-lab-no-license/386163)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 1\
**Last updated:** [May 5, 2026, 1:07pm UTC](https://discuss.elastic.co/t/creating-mssp-setup-for-lab-no-license/386163 "2026-05-05T13:07:07Z")

</div>

Hi There!! i was just tasked with making a lab of mssp setup without cluster (we will have 4 users ) Users:- CustA - windows logs and only alerts of windows (can only see this ) CustB - linux logs and its alerts sup…

---

## [After upgrade to 9.3.4 problem with system and windows integration](https://discuss.elastic.co/t/after-upgrade-to-9-3-4-problem-with-system-and-windows-integration/386156)

<div class="topic-metadata">

**Author:** [@Mario\_22](https://discuss.elastic.co/u/Mario_22)\
**Replies:** 2\
**Last updated:** [May 5, 2026, 5:49am UTC](https://discuss.elastic.co/t/after-upgrade-to-9-3-4-problem-with-system-and-windows-integration/386156 "2026-05-05T05:49:04Z")

</div>

Windows Event Logs stop indexing after upgrade to Elastic Agent 9.3.4 — system.application, system.system, Sysmon, PowerShell, and Custom Windows logs dropped with HTTP 400 Malformed content / dataset mapping conflict; p…

---

## [Clarification on shard allocation with 4 nodes across 3 zones using awareness](https://discuss.elastic.co/t/clarification-on-shard-allocation-with-4-nodes-across-3-zones-using-awareness/386077)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [April 29, 2026, 6:15am UTC](https://discuss.elastic.co/t/clarification-on-shard-allocation-with-4-nodes-across-3-zones-using-awareness/386077 "2026-04-29T06:15:10Z")

</div>

Hi, I’d like to clarify how shard allocation behaves in a specific setup using shard allocation awareness. Cluster setup: 4 data nodes 3 zones (AZ-A, AZ-B, AZ-C) AZ-A: 2 nodes AZ-B: 1 node AZ-C: 1 node …

---

## [Ingesting daily health data into Logstash pipeline for time-series monitoring](https://discuss.elastic.co/t/ingesting-daily-health-data-into-logstash-pipeline-for-time-series-monitoring/386059)

<div class="topic-metadata">

**Author:** [@jesscia](https://discuss.elastic.co/u/jesscia)\
**Replies:** 1\
**Last updated:** [April 28, 2026, 4:58am UTC](https://discuss.elastic.co/t/ingesting-daily-health-data-into-logstash-pipeline-for-time-series-monitoring/386059 "2026-04-28T04:58:50Z")

</div>

Hello everyone, I am working on a Logstash pipeline to ingest and process daily health monitoring data from a home BP device. The context of this data is post-operative recovery after a medical procedure (DIEP flap bre…

---

## [Does doing a POST query via the devtools alter any elastic data or database?](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-alter-any-elastic-data-or-database/385936)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 2\
**Last updated:** [April 28, 2026, 4:07am UTC](https://discuss.elastic.co/t/does-doing-a-post-query-via-the-devtools-alter-any-elastic-data-or-database/385936 "2026-04-28T04:07:00Z")

</div>

Its been brought to my attention that my post query is updating the database. I would like to seek clarification that such queries like below are purely querying instead of altering or updating any data in the elastics e…

---

## [A major issue with cluster state handling and persistent tasks cancellation](https://discuss.elastic.co/t/a-major-issue-with-cluster-state-handling-and-persistent-tasks-cancellation/386014)

<div class="topic-metadata">

**Author:** [@sherman81](https://discuss.elastic.co/u/sherman81)\
**Replies:** 7\
**Last updated:** [April 27, 2026, 8:15am UTC](https://discuss.elastic.co/t/a-major-issue-with-cluster-state-handling-and-persistent-tasks-cancellation/386014 "2026-04-27T08:15:53Z")

</div>

We are using ES 9.3.0. Our cluster has many data streams and indices. The cluster state is ~350 MB (compressed on disk) under normal conditions. I mistakenly scheduled a large number of downsampling tasks for historica…

---

## [Index lifecycle policy not being applied on indices after updating](https://discuss.elastic.co/t/index-lifecycle-policy-not-being-applied-on-indices-after-updating/386004)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 5\
**Last updated:** [April 23, 2026, 3:00pm UTC](https://discuss.elastic.co/t/index-lifecycle-policy-not-being-applied-on-indices-after-updating/386004 "2026-04-23T15:00:55Z")

</div>

As the title suggests, I have updated an index lifecycle policy, and the old indices are still stuck with the old settings. I have tried refreshing the index, clearing the cache, removing the ILM policy and adding it aga…

---

## [Elasticsearch Indexes are being created for Older dates](https://discuss.elastic.co/t/elasticsearch-indexes-are-being-created-for-older-dates/385959)

<div class="topic-metadata">

**Author:** [@Saikumar77](https://discuss.elastic.co/u/Saikumar77)\
**Replies:** 6\
**Last updated:** [April 22, 2026, 12:34pm UTC](https://discuss.elastic.co/t/elasticsearch-indexes-are-being-created-for-older-dates/385959 "2026-04-22T12:34:36Z")

</div>

Hi, We are hosting the ELK Stack on a VM and using Index Lifecycle Policies to manage log retention for different environments. However, we are currently facing an issue. We have configured a 4-day retention policy, an…

---

## [Elasticsearch API request](https://discuss.elastic.co/t/elasticsearch-api-request/385892)

<div class="topic-metadata">

**Author:** [@Cdotisp\_Delhi](https://discuss.elastic.co/u/Cdotisp_Delhi)\
**Replies:** 5\
**Last updated:** [April 22, 2026, 10:22am UTC](https://discuss.elastic.co/t/elasticsearch-api-request/385892 "2026-04-22T10:22:47Z")

</div>

GET /lb-2026.04/\_search { "size": 10000, "aggs": { "last\_entry": { "max": { "field": "@timestamp" } } } } I want to retrieve all latest timestamp documents from Index lb-2026.04 but number of documents are exc…

---

## [Using multiple path.data (local + NAS/SAN per node folders) to separate hot and old data – is this supported?](https://discuss.elastic.co/t/using-multiple-path-data-local-nas-san-per-node-folders-to-separate-hot-and-old-data-is-this-supported/385992)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 2\
**Last updated:** [April 22, 2026, 9:01am UTC](https://discuss.elastic.co/t/using-multiple-path-data-local-nas-san-per-node-folders-to-separate-hot-and-old-data-is-this-supported/385992 "2026-04-22T09:01:56Z")

</div>

Hi Team, I am working on a Elasticsearch cluster and need clarification on a storage architecture I am planning. My Architecture I have the following setup: 4 Elasticsearch data nodes Node1 → 1 TB Node2 → 1 TB Nod…

---

## [Cluster holds an odd number of shards](https://discuss.elastic.co/t/cluster-holds-an-odd-number-of-shards/385986)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [April 22, 2026, 7:29am UTC](https://discuss.elastic.co/t/cluster-holds-an-odd-number-of-shards/385986 "2026-04-22T07:29:39Z")

</div>

Hi Wondering about the number of shards in our v.8.19.9 cluster been odd like this when all shards ought to have exactly 1 replica: $ eshealth { "cluster\_name" : "pjp-es-epj", "status" : "green", "timed\_out" : fa…

---

## [Unified Multilingual search](https://discuss.elastic.co/t/unified-multilingual-search/385388)

<div class="topic-metadata">

**Author:** [@cptX](https://discuss.elastic.co/u/cptX)\
**Replies:** 1\
**Last updated:** [April 21, 2026, 2:28pm UTC](https://discuss.elastic.co/t/unified-multilingual-search/385388 "2026-04-21T14:28:16Z")

</div>

UPDATE: Sorry for posting it here, it was meant for magento 2, smile/elasticsuite. I’ll keep it here for reference if somebody wants to shed some light on my problems. Hi, several years now I’m facing the following prob…

---

## [ES|QL LOOKUP JOIN between fields containing a list of values](https://discuss.elastic.co/t/es-ql-lookup-join-between-fields-containing-a-list-of-values/385960)

<div class="topic-metadata">

**Author:** [@smyttie](https://discuss.elastic.co/u/smyttie)\
**Replies:** 2\
**Last updated:** [April 21, 2026, 4:58am UTC](https://discuss.elastic.co/t/es-ql-lookup-join-between-fields-containing-a-list-of-values/385960 "2026-04-21T04:58:54Z")

</div>

Hi all, creating a LOOKUP JOIN query is working fine, but I am not getting results when I have to do it between 2 fields containing a list of values. For example : main index field = "sizes" : \["S", "M"\] lookup index…

---

## [Improving ElasticSearch relevance with better normalization (beyond stemming)](https://discuss.elastic.co/t/improving-elasticsearch-relevance-with-better-normalization-beyond-stemming/385966)

<div class="topic-metadata">

**Author:** [@tonyj](https://discuss.elastic.co/u/tonyj)\
**Replies:** 0\
**Last updated:** [April 20, 2026, 4:11pm UTC](https://discuss.elastic.co/t/improving-elasticsearch-relevance-with-better-normalization-beyond-stemming/385966 "2026-04-20T16:11:20Z")

</div>

Hi everyone, In several Elasticsearch projects we’ve seen stemming introduce noise early in the analysis pipeline, especially in multilingual setups. For example: “organization” → “organ” “news” → “new” “united” → “u…

---

## [Elasticsearch data node instability and indexing failures when using NAS (shared storage) with separate folders per node](https://discuss.elastic.co/t/elasticsearch-data-node-instability-and-indexing-failures-when-using-nas-shared-storage-with-separate-folders-per-node/385952)

<div class="topic-metadata">

**Author:** [@Shubham\_Khodpe](https://discuss.elastic.co/u/Shubham_Khodpe)\
**Replies:** 3\
**Last updated:** [April 20, 2026, 12:41pm UTC](https://discuss.elastic.co/t/elasticsearch-data-node-instability-and-indexing-failures-when-using-nas-shared-storage-with-separate-folders-per-node/385952 "2026-04-20T12:41:48Z")

</div>

I am facing stability and performance issues in my Elasticsearch cluster and would like to understand if the storage architecture is the root cause. We have multiple Elasticsearch data nodes running on Windows servers. …

---

## [How to install the repository plug-in in a rolling upgrade to ensure that business reading and writing are not affected](https://discuss.elastic.co/t/how-to-install-the-repository-plug-in-in-a-rolling-upgrade-to-ensure-that-business-reading-and-writing-are-not-affected/385924)

<div class="topic-metadata">

**Author:** [@mloine](https://discuss.elastic.co/u/mloine)\
**Replies:** 4\
**Last updated:** [April 20, 2026, 9:43am UTC](https://discuss.elastic.co/t/how-to-install-the-repository-plug-in-in-a-rolling-upgrade-to-ensure-that-business-reading-and-writing-are-not-affected/385924 "2026-04-20T09:43:40Z")

</div>

Background: Because the business scenario does not allow downtime maintenance and there will be a large number of read and write operations during the period, only rolling installation of plug-ins can be considered The …

---

## [Upgrade 8.19.13 and errors starting regarding entitlement](https://discuss.elastic.co/t/upgrade-8-19-13-and-errors-starting-regarding-entitlement/385923)

<div class="topic-metadata">

**Author:** [@Juan\_Carlos\_Sanchez](https://discuss.elastic.co/u/Juan_Carlos_Sanchez)\
**Replies:** 2\
**Last updated:** [April 17, 2026, 7:37pm UTC](https://discuss.elastic.co/t/upgrade-8-19-13-and-errors-starting-regarding-entitlement/385923 "2026-04-17T19:37:07Z")

</div>

Hi, We are facing issue starting the elasticsearch with version 8.19.13 showing this error message: \[2026-04-16T15:15:34,195\]\[INFO \]\[o.e.n.NativeAccess \] Using native vector library; to disable start with -Dorg.…

---

## [Getting Session error on Kibana UI](https://discuss.elastic.co/t/getting-session-error-on-kibana-ui/385888)

<div class="topic-metadata">

**Author:** [@Cache\_Digitech](https://discuss.elastic.co/u/Cache_Digitech)\
**Replies:** 8\
**Last updated:** [April 17, 2026, 3:20pm UTC](https://discuss.elastic.co/t/getting-session-error-on-kibana-ui/385888 "2026-04-17T15:20:34Z")

</div>

As shown in the screenshot , I’m having this issue . I tried a fresh installation and again after running for few days , I got this error again. I did some research and found that the roles for the kibana\_system user …

---

## [Getting LAST record in aggr in ES|QL](https://discuss.elastic.co/t/getting-last-record-in-aggr-in-es-ql/372903)

<div class="topic-metadata">

**Author:** [@jfsardon](https://discuss.elastic.co/u/jfsardon)\
**Replies:** 11\
**Last updated:** [April 16, 2026, 6:33pm UTC](https://discuss.elastic.co/t/getting-last-record-in-aggr-in-es-ql/372903 "2026-04-16T18:33:40Z")

</div>

Is there an simple way to get the last value of a field (@timestamp sorted) for each customer, hostname, etc.. For example : select logs-myindex-xxx | SORT (@timestamp) | STATS LAST (maxsize) BY customer, hostname... b…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=3)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=5)
