# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=40

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 41

---

## [How to monitor the size of elasticsearch index](https://discuss.elastic.co/t/how-to-monitor-the-size-of-elasticsearch-index/375986)

<div class="topic-metadata">

**Author:** [@jinfeng\_zhang](https://discuss.elastic.co/u/jinfeng_zhang)\
**Replies:** 1\
**Last updated:** [March 18, 2025, 11:26am UTC](https://discuss.elastic.co/t/how-to-monitor-the-size-of-elasticsearch-index/375986 "2025-03-18T11:26:47Z")

</div>

Do you have a solution for elasticsearch index size monitoring? For example, the index pit doesn't scroll according to the lifetime I set for various reasons, so it can get big. At this point, I would like to receive an…

---

## [Problem with logstash configuration](https://discuss.elastic.co/t/problem-with-logstash-configuration/376061)

<div class="topic-metadata">

**Author:** [@dante.tettamanti](https://discuss.elastic.co/u/dante.tettamanti)\
**Replies:** 0\
**Last updated:** [March 18, 2025, 11:08am UTC](https://discuss.elastic.co/t/problem-with-logstash-configuration/376061 "2025-03-18T11:08:19Z")

</div>

Hi guys, first , sorry for my bad english . I have problem with target in the input filter i tried to run the configuration and send a message, but il looks like that the "target" option of the jsoncodec isn't apply T…

---

## [Move existing index from hot node to cold node](https://discuss.elastic.co/t/move-existing-index-from-hot-node-to-cold-node/376037)

<div class="topic-metadata">

**Author:** [@Chaviru](https://discuss.elastic.co/u/Chaviru)\
**Replies:** 1\
**Last updated:** [March 18, 2025, 10:57am UTC](https://discuss.elastic.co/t/move-existing-index-from-hot-node-to-cold-node/376037 "2025-03-18T10:57:52Z")

</div>

Hello all, I currently have created an mapped a new ILM polciy for my indices right now. But there are some older indices which are mapped to the older ILM policy. This index size is very big and currently I need to mov…

---

## [Deletion of indices](https://discuss.elastic.co/t/deletion-of-indices/376002)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 2\
**Last updated:** [March 18, 2025, 9:59am UTC](https://discuss.elastic.co/t/deletion-of-indices/376002 "2025-03-18T09:59:58Z")

</div>

Getting FS utilization alert from elasticsearch node .On further checking I found some old indices /u01/app/elkprd/elasticsearch/var/lib/elasticsearch/nodes/0/indices/\_0IJAYgVTh2N1tHfmaxclQ/2/index/\_bs.fdt /u01/app/elk…

---

## [Node reduction - Should I use "primaries" or "none"](https://discuss.elastic.co/t/node-reduction-should-i-use-primaries-or-none/375983)

<div class="topic-metadata">

**Author:** [@Archie1](https://discuss.elastic.co/u/Archie1)\
**Replies:** 10\
**Last updated:** [March 17, 2025, 9:34pm UTC](https://discuss.elastic.co/t/node-reduction-should-i-use-primaries-or-none/375983 "2025-03-17T21:34:33Z")

</div>

Hi Everyone, I am reducing an Elasticsearch cluster from 6 nodes to 3. I have already started the process and can see shard draining from the nodes. Nodes were taken out of the pool with the correct command so that pa…

---

## [Running elastic search cluster with expired TLS ceritificate](https://discuss.elastic.co/t/running-elastic-search-cluster-with-expired-tls-ceritificate/375996)

<div class="topic-metadata">

**Author:** [@piyushgupta](https://discuss.elastic.co/u/piyushgupta)\
**Replies:** 3\
**Last updated:** [March 17, 2025, 2:16pm UTC](https://discuss.elastic.co/t/running-elastic-search-cluster-with-expired-tls-ceritificate/375996 "2025-03-17T14:16:21Z")

</div>

Hi , we are running 6 node cluster with 3 master and 3 data node in each node we are using letsencrypt certificate as below which expires every 3 month xpack.security.http.ssl.enabled: true xpack.security.http.ssl.ke…

---

## [Add new master to the ES cluster](https://discuss.elastic.co/t/add-new-master-to-the-es-cluster/376000)

<div class="topic-metadata">

**Author:** [@piyushgupta](https://discuss.elastic.co/u/piyushgupta)\
**Replies:** 4\
**Last updated:** [March 17, 2025, 12:06pm UTC](https://discuss.elastic.co/t/add-new-master-to-the-es-cluster/376000 "2025-03-17T12:06:43Z")

</div>

Hi We are having ES cluster 7.10.0 with total 5 nodes 3 master node 3 data node 1 node serves as both data and master node i have plan to add 1 more master only node is any risk on adding new master only node to…

---

## [How to change a template of integration stream?](https://discuss.elastic.co/t/how-to-change-a-template-of-integration-stream/376005)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 0\
**Last updated:** [March 17, 2025, 11:19am UTC](https://discuss.elastic.co/t/how-to-change-a-template-of-integration-stream/376005 "2025-03-17T11:19:04Z")

</div>

Hi there. I use custom UDP integration. And it creates a datastream with seemingly hardcoded default "logs" template. Creating another one with a higher priority doesn't help. How the heck do I change it? Creating a…

---

## [Kibana has been in between availability and demotion, resulting in very slow queries](https://discuss.elastic.co/t/kibana-has-been-in-between-availability-and-demotion-resulting-in-very-slow-queries/375995)

<div class="topic-metadata">

**Author:** [@xialiang](https://discuss.elastic.co/u/xialiang)\
**Replies:** 2\
**Last updated:** [March 17, 2025, 10:17am UTC](https://discuss.elastic.co/t/kibana-has-been-in-between-availability-and-demotion-resulting-in-very-slow-queries/375995 "2025-03-17T10:17:25Z")

</div>

kibana's journal \[2025-03-17T09:44:49.334+00:00\]\[INFO \]\[status\] Kibana is now available (was degraded) \[2025-03-17T09:45:03.275+00:00\]\[INFO \]\[status\] Kibana is now degraded (was available) \[2025-03-17T09:45:18.038+00:00…

---

## [Podman compose for kibana+elasticsearch+logstash](https://discuss.elastic.co/t/podman-compose-for-kibana-elasticsearch-logstash/375592)

<div class="topic-metadata">

**Author:** [@Phoenix2](https://discuss.elastic.co/u/Phoenix2)\
**Replies:** 14\
**Last updated:** [March 16, 2025, 6:36pm UTC](https://discuss.elastic.co/t/podman-compose-for-kibana-elasticsearch-logstash/375592 "2025-03-16T18:36:32Z")

</div>

I am trying to create a podman compose file to create instant Elasticsearch, Kibana, Logstash. All data should be backed up via volumes. The problem seems to be transferring the Kibana API key from Elastic to Kibana. My…

---

## [Best way to delete old data from elastic search](https://discuss.elastic.co/t/best-way-to-delete-old-data-from-elastic-search/375958)

<div class="topic-metadata">

**Author:** [@prashanthtg](https://discuss.elastic.co/u/prashanthtg)\
**Replies:** 3\
**Last updated:** [March 16, 2025, 7:51am UTC](https://discuss.elastic.co/t/best-way-to-delete-old-data-from-elastic-search/375958 "2025-03-16T07:51:15Z")

</div>

I want to maintain the lifecycle management of an Elasticsearch doc over x days. \_delete\_by\_query api help with the job, however i understand this also comes with some performance impact on query/read on delete of large …

---

## [Autocomplete Strategy](https://discuss.elastic.co/t/autocomplete-strategy/375869)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 2\
**Last updated:** [March 14, 2025, 8:59pm UTC](https://discuss.elastic.co/t/autocomplete-strategy/375869 "2025-03-14T20:59:24Z")

</div>

We are new to Elasticsearch's options for autocomplete functionalities. Would apprciate if someone could advise us as to what is the best option for autocomplete such as Completion Suggesters, Search As You Type etc. T…

---

## [Wildcard query using NEST API](https://discuss.elastic.co/t/wildcard-query-using-nest-api/375867)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 2\
**Last updated:** [March 14, 2025, 8:57pm UTC](https://discuss.elastic.co/t/wildcard-query-using-nest-api/375867 "2025-03-14T20:57:25Z")

</div>

We have the following Wildcard query. What we want to do is if the query matches the beginning then it should be boosted to the top. All results should be in Ascending alphabetic order based on the field "Name" which i…

---

## [Why doesn't the index template created by .NET logger use logs@custom?](https://discuss.elastic.co/t/why-doesnt-the-index-template-created-by-net-logger-use-logs-custom/375953)

<div class="topic-metadata">

**Author:** [@tobiasly](https://discuss.elastic.co/u/tobiasly)\
**Replies:** 0\
**Last updated:** [March 14, 2025, 7:21pm UTC](https://discuss.elastic.co/t/why-doesnt-the-index-template-created-by-net-logger-use-logs-custom/375953 "2025-03-14T19:21:02Z")

</div>

I'm using the Elastic.Extensions.Logging library to ship logs from my .NET app. When I configured it to bootstrap the data stream, it created a corresponding index template named logs-dotnet-8.11.0 with a higher priority…

---

## [Handling multi word expressions in elastic](https://discuss.elastic.co/t/handling-multi-word-expressions-in-elastic/375950)

<div class="topic-metadata">

**Author:** [@Alireza\_Zamani](https://discuss.elastic.co/u/Alireza_Zamani)\
**Replies:** 0\
**Last updated:** [March 14, 2025, 6:14pm UTC](https://discuss.elastic.co/t/handling-multi-word-expressions-in-elastic/375950 "2025-03-14T18:14:47Z")

</div>

Hi, I want to be able to handle multi word expressions with fuzzy in elasticsearch. So for example i have two tokens in my field's value that have a unified meaning when they occur next to each other. Every query, must …

---

## [Is there any example of using bucketSelector in java client 8.14.1?](https://discuss.elastic.co/t/is-there-any-example-of-using-bucketselector-in-java-client-8-14-1/375924)

<div class="topic-metadata">

**Author:** [@TheXs](https://discuss.elastic.co/u/TheXs)\
**Replies:** 2\
**Last updated:** [March 14, 2025, 3:33pm UTC](https://discuss.elastic.co/t/is-there-any-example-of-using-bucketselector-in-java-client-8-14-1/375924 "2025-03-14T15:33:05Z")

</div>

Hi, there. I am currently using 8.14.1 rest client for java, by now, I want to use bucketSelector to filter the bucket. However, I can't find any example showing how to use that api and I tried a bit but still not able …

---

## [Is there any known issues for high shared and buff/cache usage with elasticsearch java client](https://discuss.elastic.co/t/is-there-any-known-issues-for-high-shared-and-buff-cache-usage-with-elasticsearch-java-client/374797)

<div class="topic-metadata">

**Author:** [@sibasish.palo](https://discuss.elastic.co/u/sibasish.palo)\
**Replies:** 16\
**Last updated:** [March 14, 2025, 11:05am UTC](https://discuss.elastic.co/t/is-there-any-known-issues-for-high-shared-and-buff-cache-usage-with-elasticsearch-java-client/374797 "2025-03-14T11:05:46Z")

</div>

i am using below Elasticsearch java client and see high shared and buff/cache memory usage with the application. \<dependency\> \<groupId\>co.elastic.clients\</groupId\> \<artifactId\>elasticsearch-java\</art…

---

## [Dense vector field in nested object](https://discuss.elastic.co/t/dense-vector-field-in-nested-object/375000)

<div class="topic-metadata">

**Author:** [@yli](https://discuss.elastic.co/u/yli)\
**Replies:** 7\
**Last updated:** [March 14, 2025, 8:45am UTC](https://discuss.elastic.co/t/dense-vector-field-in-nested-object/375000 "2025-03-14T08:45:31Z")

</div>

Hi, I tried two different index mapping for my file content indexing with separate the file content into different text sections with corresponding text section embeddings. Flat file section index mapping In this case, …

---

## [Fuzzy matching multi term query problem](https://discuss.elastic.co/t/fuzzy-matching-multi-term-query-problem/375896)

<div class="topic-metadata">

**Author:** [@mateo80](https://discuss.elastic.co/u/mateo80)\
**Replies:** 0\
**Last updated:** [March 14, 2025, 7:38am UTC](https://discuss.elastic.co/t/fuzzy-matching-multi-term-query-problem/375896 "2025-03-14T07:38:46Z")

</div>

Hi guys Looks like I'm missing something obvious when trying to fuzzy match multi term query. What I'd like to achieve is to get only "Goleniow Helenow" result when providing "Goleniow Heleniow" query (city + district …

---

## [Loss power now my cluster will not connect](https://discuss.elastic.co/t/loss-power-now-my-cluster-will-not-connect/375539)

<div class="topic-metadata">

**Author:** [@Trent-alex](https://discuss.elastic.co/u/Trent-alex)\
**Replies:** 6\
**Last updated:** [March 13, 2025, 10:12pm UTC](https://discuss.elastic.co/t/loss-power-now-my-cluster-will-not-connect/375539 "2025-03-13T22:12:15Z")

</div>

So i lost power in the building. My servers came back up but... now my nodes dont communicate. Any help would be appreciated \[ERROR\]\[o.e.b.Elasticsearch \] \[herzai\] node validation exception \[1\] bootstrap checks f…

---

## [Filter out client.address in WHERE](https://discuss.elastic.co/t/filter-out-client-address-in-where/375727)

<div class="topic-metadata">

**Author:** [@JSElasticDiscuss](https://discuss.elastic.co/u/JSElasticDiscuss)\
**Replies:** 8\
**Last updated:** [March 13, 2025, 5:11pm UTC](https://discuss.elastic.co/t/filter-out-client-address-in-where/375727 "2025-03-13T17:11:02Z")

</div>

I am trying to write an ES|QL query that filters out client.address based with a WHERE clause, using wildcards to get rid of internal IP ranges. We are currently using the client.address field as a keyword, and trying to…

---

## [Mustache script result size limit exceeded](https://discuss.elastic.co/t/mustache-script-result-size-limit-exceeded/375818)

<div class="topic-metadata">

**Author:** [@Arun\_Kumar8](https://discuss.elastic.co/u/Arun_Kumar8)\
**Replies:** 1\
**Last updated:** [March 13, 2025, 3:26pm UTC](https://discuss.elastic.co/t/mustache-script-result-size-limit-exceeded/375818 "2025-03-13T15:26:55Z")

</div>

Hi Team, After upgrading the elastic version 7.17.11 to 7.17.27 we are getting the below error while searching in Elasticsearch. our request body size is less than 1 MB, even though we are getting the same exception. …

---

## [Azure Microsoft Entra Id integration with Elastic Fleet](https://discuss.elastic.co/t/azure-microsoft-entra-id-integration-with-elastic-fleet/373638)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [March 13, 2025, 9:26am UTC](https://discuss.elastic.co/t/azure-microsoft-entra-id-integration-with-elastic-fleet/373638 "2025-03-13T09:26:00Z")

</div>

Hi Team We need to fetch Microsoft Entra Id SignIn logs using integration with Elasticsearch fleet. We've added its respective integration under a policy and provided required values. The integration is shown as "Healt…

---

## [Do I need to upgrade?. Kibana 8.17.3 Security Update (ESA-2025-06)](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 5\
**Last updated:** [March 13, 2025, 3:54am UTC](https://discuss.elastic.co/t/do-i-need-to-upgrade-kibana-8-17-3-security-update-esa-2025-06/375756 "2025-03-13T03:54:59Z")

</div>

Hi Elastic Team Member, @ikakavas, I have read the information from Ikakavas, I am very concerned about my system. But I also want to ask you some questions. Please help me answer my questions. I am using ELK cluster…

---

## [Starting Fscrawler with SSL error](https://discuss.elastic.co/t/starting-fscrawler-with-ssl-error/375028)

<div class="topic-metadata">

**Author:** [@jimmorrison](https://discuss.elastic.co/u/jimmorrison)\
**Replies:** 52\
**Last updated:** [March 12, 2025, 10:52pm UTC](https://discuss.elastic.co/t/starting-fscrawler-with-ssl-error/375028 "2025-03-12T22:52:21Z")

</div>

Hi, Elasticsearch daemon is running and when I start Fscrawler I have this fatal error. Thanks 15:43:15,867 WARN \[f.p.e.c.f.c.ElasticsearchClient\] Failed to create elasticsearch client on Elasticsearch{nodes=\[https://1…

---

## [Watcher + PDF in email with filter last 24hours](https://discuss.elastic.co/t/watcher-pdf-in-email-with-filter-last-24hours/375792)

<div class="topic-metadata">

**Author:** [@Real\_Talk](https://discuss.elastic.co/u/Real_Talk)\
**Replies:** 0\
**Last updated:** [March 12, 2025, 4:16pm UTC](https://discuss.elastic.co/t/watcher-pdf-in-email-with-filter-last-24hours/375792 "2025-03-12T16:16:47Z")

</div>

Hello, Sorry, I am new to the ELK universe. I created an observer with a filter, and I configured it to add a PDF in a notification email. My filter is set to the last 24 hours (at the current time), I would like to mo…

---

## [Configure audit logging](https://discuss.elastic.co/t/configure-audit-logging/375772)

<div class="topic-metadata">

**Author:** [@danil.kalmikov1](https://discuss.elastic.co/u/danil.kalmikov1)\
**Replies:** 1\
**Last updated:** [March 12, 2025, 1:21pm UTC](https://discuss.elastic.co/t/configure-audit-logging/375772 "2025-03-12T13:21:17Z")

</div>

Hello, Community. I want to collect audit logs connected to user activity (like user create/delete, set/change password, create new role, delete role, change role, change user role, success/failed auth etc.) Is it poss…

---

## [Which index holds the fleet Healthy/Unhealthy status?](https://discuss.elastic.co/t/which-index-holds-the-fleet-healthy-unhealthy-status/374068)

<div class="topic-metadata">

**Author:** [@Kamal2](https://discuss.elastic.co/u/Kamal2)\
**Replies:** 1\
**Last updated:** [March 12, 2025, 12:42pm UTC](https://discuss.elastic.co/t/which-index-holds-the-fleet-healthy-unhealthy-status/374068 "2025-03-12T12:42:14Z")

</div>

Hi Team, I need to find which fleet agent is healthy or unhealthy but I am unable to find the index.

---

## [Add tag to queries for slowlog](https://discuss.elastic.co/t/add-tag-to-queries-for-slowlog/375777)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [March 12, 2025, 11:38am UTC](https://discuss.elastic.co/t/add-tag-to-queries-for-slowlog/375777 "2025-03-12T11:38:41Z")

</div>

Looking back to this thread I would like to know if there is any news about this topic. Is there a way to add a "tag" to queries which end up in the ES index\_search\_slowlogs? Generally, if I enable slowlog I have to lo…

---

## [Issues with @timestamp vs timestamp](https://discuss.elastic.co/t/issues-with-timestamp-vs-timestamp/375433)

<div class="topic-metadata">

**Author:** [@pix9](https://discuss.elastic.co/u/pix9)\
**Replies:** 12\
**Last updated:** [March 12, 2025, 8:36am UTC](https://discuss.elastic.co/t/issues-with-timestamp-vs-timestamp/375433 "2025-03-12T08:36:13Z")

</div>

Hey folks, Currently we are using following ELK Stack as per given below for managing access logs from our web-servers. Packages : elasticsearch-8.6.1-1 logstash-8.6.1-1 kibana-8.6.1-1 filebeat-8.6.1-1 Index size fo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=39)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=41)
