# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=41

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 42

---

## [How to map memory size](https://discuss.elastic.co/t/how-to-map-memory-size/364296)

<div class="topic-metadata">

**Author:** [@mg77345](https://discuss.elastic.co/u/mg77345)\
**Replies:** 6\
**Last updated:** [March 11, 2025, 6:01pm UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296 "2025-03-11T18:01:17Z")

</div>

I have fields that are currently being ingested as resources\_used.vmem: 1028974kb resources\_requested.vmem: 2000000kb They are mapped as keyword, but i would like to have the "kb" (or file size denom.) stripped and to…

---

## [Cluster-health check with elasticsearch-java against 7.x cluster](https://discuss.elastic.co/t/cluster-health-check-with-elasticsearch-java-against-7-x-cluster/375724)

<div class="topic-metadata">

**Author:** [@Hans\_Kruse](https://discuss.elastic.co/u/Hans_Kruse)\
**Replies:** 1\
**Last updated:** [March 11, 2025, 5:15pm UTC](https://discuss.elastic.co/t/cluster-health-check-with-elasticsearch-java-against-7-x-cluster/375724 "2025-03-11T17:15:01Z")

</div>

Getting cluster health from an es-7 cluster using the elasticsearch-java (es8) language client does not work out of the box. How do I configure the client in a compatible way? We are finishing our migration from es7 c…

---

## [Inplace Mapping Update for Index](https://discuss.elastic.co/t/inplace-mapping-update-for-index/375712)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 2\
**Last updated:** [March 11, 2025, 3:46pm UTC](https://discuss.elastic.co/t/inplace-mapping-update-for-index/375712 "2025-03-11T15:46:33Z")

</div>

Hi Team, Wanted to understand, if there is any specific reason why Elasticsearch doesn't allow updating mapping of index in place for existing fields? Is this anti pattern? Or Is there any particular reason? Wasn't abl…

---

## [Best approach to make app logs queryable in ELK](https://discuss.elastic.co/t/best-approach-to-make-app-logs-queryable-in-elk/375710)

<div class="topic-metadata">

**Author:** [@siakc](https://discuss.elastic.co/u/siakc)\
**Replies:** 0\
**Last updated:** [March 11, 2025, 2:14pm UTC](https://discuss.elastic.co/t/best-approach-to-make-app-logs-queryable-in-elk/375710 "2025-03-11T14:14:04Z")

</div>

I have a nodejs app that currently uses bunyan logger to dump big amounts of logs in JSON format on the disk (one file a day). These logs have various nested fields, some about service requests and responses, and some ab…

---

## [Cluster vs. Index Segment Size Settings Precedence for max\_merged\_segment](https://discuss.elastic.co/t/cluster-vs-index-segment-size-settings-precedence-for-max-merged-segment/375694)

<div class="topic-metadata">

**Author:** [@Saleh\_AbuAli](https://discuss.elastic.co/u/Saleh_AbuAli)\
**Replies:** 0\
**Last updated:** [March 11, 2025, 10:31am UTC](https://discuss.elastic.co/t/cluster-vs-index-segment-size-settings-precedence-for-max-merged-segment/375694 "2025-03-11T10:31:30Z")

</div>

I've noticed what appears to be cluster settings taking precedence over index-specific settings for segment size limits, and I'm seeking clarification on how these settings interact. My index settings explicitly specify…

---

## [Save Index in specific Directory](https://discuss.elastic.co/t/save-index-in-specific-directory/375384)

<div class="topic-metadata">

**Author:** [@NikoCosmico01](https://discuss.elastic.co/u/NikoCosmico01)\
**Replies:** 7\
**Last updated:** [March 11, 2025, 8:50am UTC](https://discuss.elastic.co/t/save-index-in-specific-directory/375384 "2025-03-11T08:50:17Z")

</div>

Hi, I've the ELK stack installed via docker having in particular 3 ES nodes and 1 LogStash node. My question is if there is a way to have the data ingested from a specific LogStash pipeline saved in a specific director…

---

## [Ambiguous reference configuring logging to ElasticCloud in Elastic.Serilog.Sinks](https://discuss.elastic.co/t/ambiguous-reference-configuring-logging-to-elasticcloud-in-elastic-serilog-sinks/368372)

<div class="topic-metadata">

**Author:** [@kabcampbell](https://discuss.elastic.co/u/kabcampbell)\
**Replies:** 2\
**Last updated:** [March 10, 2025, 7:12pm UTC](https://discuss.elastic.co/t/ambiguous-reference-configuring-logging-to-elasticcloud-in-elastic-serilog-sinks/368372 "2025-03-10T19:12:04Z")

</div>

I'm following the documentation for adding the logging configuration for writing to elastic using the Elastic.Serilog.Sinks and when I try to use the logging configuration extension method xxx.WriteTo.ElasticCloud(xxxx) …

---

## [Cross Cluster Search](https://discuss.elastic.co/t/cross-cluster-search/375665)

<div class="topic-metadata">

**Author:** [@jmello31](https://discuss.elastic.co/u/jmello31)\
**Replies:** 0\
**Last updated:** [March 10, 2025, 5:48pm UTC](https://discuss.elastic.co/t/cross-cluster-search/375665 "2025-03-10T17:48:00Z")

</div>

I am trying to configure cross cluster search within my ECK stack and I am having a hard time with the documentation. I am trying to configure with the API key related route and I am confused where to set the requisite …

---

## [Master\_not\_discovered\_exception after upgrade to Ubuntu Jammy and Docker 28.0.1](https://discuss.elastic.co/t/master-not-discovered-exception-after-upgrade-to-ubuntu-jammy-and-docker-28-0-1/375239)

<div class="topic-metadata">

**Author:** [@PMDubuc](https://discuss.elastic.co/u/PMDubuc)\
**Replies:** 17\
**Last updated:** [March 10, 2025, 5:17pm UTC](https://discuss.elastic.co/t/master-not-discovered-exception-after-upgrade-to-ubuntu-jammy-and-docker-28-0-1/375239 "2025-03-10T17:17:42Z")

</div>

We are trying to upgrade our Elastic Stack deployment to run on Ubuntu Jammy (22.04) (The docker is based on Ubuntu 20.04.6 this is 7.17.12 it also happens with the 7.17.28) and docker version 28.0.1. on the hosts. P…

---

## [MSSQL Connector not syncing](https://discuss.elastic.co/t/mssql-connector-not-syncing/375046)

<div class="topic-metadata">

**Author:** [@jjmcmullan](https://discuss.elastic.co/u/jjmcmullan)\
**Replies:** 5\
**Last updated:** [March 10, 2025, 5:02pm UTC](https://discuss.elastic.co/t/mssql-connector-not-syncing/375046 "2025-03-10T17:02:43Z")

</div>

Hi folks, I've got a docker install of elastic that I built using the blog posts "getting-started-with-the-elastic-stack-and-docker-compose-part\[1 and 2\]" and that all went very well. I have since decided to add the con…

---

## [Multi-node shrink prototype](https://discuss.elastic.co/t/multi-node-shrink-prototype/375652)

<div class="topic-metadata">

**Author:** [@tobyb121](https://discuss.elastic.co/u/tobyb121)\
**Replies:** 3\
**Last updated:** [March 10, 2025, 4:08pm UTC](https://discuss.elastic.co/t/multi-node-shrink-prototype/375652 "2025-03-10T16:08:56Z")

</div>

I've seen issues when running on larger clusters caused by index shrink. The root cause of these issues tends to be the requirement for all shards to be recovered on a single node, as this can cause significant hotspots …

---

## [Vulnerable Apache Lucene in ElasticSearch 7.17.28](https://discuss.elastic.co/t/vulnerable-apache-lucene-in-elasticsearch-7-17-28/375655)

<div class="topic-metadata">

**Author:** [@treektPL](https://discuss.elastic.co/u/treektPL)\
**Replies:** 4\
**Last updated:** [March 10, 2025, 2:10pm UTC](https://discuss.elastic.co/t/vulnerable-apache-lucene-in-elasticsearch-7-17-28/375655 "2025-03-10T14:10:57Z")

</div>

Hi, I see that the latest update of Elasticsearch 7.17.28 have still vulnerability CVE-2024-45772 which affects Apache Lucene from 4.4.0 before 9.12.0. That mean's ES should update Lucene to 9.12.0 at least. Do we know…

---

## [Persistence of lifecycle policies accross container rebuild](https://discuss.elastic.co/t/persistence-of-lifecycle-policies-accross-container-rebuild/375464)

<div class="topic-metadata">

**Author:** [@Cyanat](https://discuss.elastic.co/u/Cyanat)\
**Replies:** 3\
**Last updated:** [March 10, 2025, 11:25am UTC](https://discuss.elastic.co/t/persistence-of-lifecycle-policies-accross-container-rebuild/375464 "2025-03-10T11:25:39Z")

</div>

Hi, I have an Elasticsearch server running on a Docker infrastructure with the following containers: Kibana Logstash Elasticsearch Once my server was set up, I used the Kibana interface to define Lifecycle policies t…

---

## [Shard rebalancing may temporarily unbalance cluster](https://discuss.elastic.co/t/shard-rebalancing-may-temporarily-unbalance-cluster/374911)

<div class="topic-metadata">

**Author:** [@Iron](https://discuss.elastic.co/u/Iron)\
**Replies:** 1\
**Last updated:** [March 10, 2025, 11:00am UTC](https://discuss.elastic.co/t/shard-rebalancing-may-temporarily-unbalance-cluster/374911 "2025-03-10T11:00:36Z")

</div>

Please let me know if the following issue can appear in the version below 8 points. issue : "Shard rebalancing may temporarily unbalance cluster" ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Shard reb…

---

## [Index Pre-Load for Vector Store](https://discuss.elastic.co/t/index-pre-load-for-vector-store/375564)

<div class="topic-metadata">

**Author:** [@peedeeboy](https://discuss.elastic.co/u/peedeeboy)\
**Replies:** 5\
**Last updated:** [March 10, 2025, 10:47am UTC](https://discuss.elastic.co/t/index-pre-load-for-vector-store/375564 "2025-03-10T10:47:42Z")

</div>

Hey all :waving\_hand: We have dedicated ES clusters we use for our vector database and approx kNN searching (single hnsw\_int8 dense vector) as part of our hybrid-search solution. We've started to push one cluster prett…

---

## [Unable to map prod production s3 repo on test cluster](https://discuss.elastic.co/t/unable-to-map-prod-production-s3-repo-on-test-cluster/375638)

<div class="topic-metadata">

**Author:** [@Suresh\_Hemke](https://discuss.elastic.co/u/Suresh_Hemke)\
**Replies:** 0\
**Last updated:** [March 10, 2025, 9:51am UTC](https://discuss.elastic.co/t/unable-to-map-prod-production-s3-repo-on-test-cluster/375638 "2025-03-10T09:51:11Z")

</div>

Hello Team, We have an AWS S3 repository configured on our production Elasticsearch cluster for backup snapshots, and this repository is successfully mapped to our PERF environment to restore snapshots without any issue…

---

## [Disable Internal shards](https://discuss.elastic.co/t/disable-internal-shards/374631)

<div class="topic-metadata">

**Author:** [@rihad](https://discuss.elastic.co/u/rihad)\
**Replies:** 0\
**Last updated:** [February 17, 2025, 2:12pm UTC](https://discuss.elastic.co/t/disable-internal-shards/374631 "2025-02-17T14:12:28Z")

</div>

Hi, after upgrading ES from 7.14 to 7.17.11 I started noticing these entries in \_cat/shards: index shard prirep state docs store .ds-.logs-deprecation.elasti…

---

## [Create data\_stream for container logs](https://discuss.elastic.co/t/create-data-stream-for-container-logs/374744)

<div class="topic-metadata">

**Author:** [@prakash85](https://discuss.elastic.co/u/prakash85)\
**Replies:** 0\
**Last updated:** [February 19, 2025, 9:28am UTC](https://discuss.elastic.co/t/create-data-stream-for-container-logs/374744 "2025-02-19T09:28:12Z")

</div>

Hi All, I'm new here and i have query creating data\_streams for container logs we have a common ELK without logstash for all - dev, stg,tst & prd and when we send logs from container to elasticsearch the dataset is pre…

---

## [How to generate reports or logs when deleting indices via ILM?](https://discuss.elastic.co/t/how-to-generate-reports-or-logs-when-deleting-indices-via-ilm/375633)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [March 10, 2025, 8:44am UTC](https://discuss.elastic.co/t/how-to-generate-reports-or-logs-when-deleting-indices-via-ilm/375633 "2025-03-10T08:44:33Z")

</div>

Hi everyone, I am looking for a way to generate reports or logs when indices are deleted as part of an Index Lifecycle Management (ILM) policy in Elasticsearch. Specifically: \*Does Elasticsearch provide built-in report…

---

## [Difference between (on status changes, recovered) and (on check interval, recovered) when defining alert](https://discuss.elastic.co/t/difference-between-on-status-changes-recovered-and-on-check-interval-recovered-when-defining-alert/375631)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 0\
**Last updated:** [March 10, 2025, 8:37am UTC](https://discuss.elastic.co/t/difference-between-on-status-changes-recovered-and-on-check-interval-recovered-when-defining-alert/375631 "2025-03-10T08:37:47Z")

</div>

I was trying to define a rule of type Elasticsearch query in observability, in action query section i can not understand the difference between these two. option 1 for each alert: on status changes run when: reovered …

---

## [Best practice to add more indices](https://discuss.elastic.co/t/best-practice-to-add-more-indices/375627)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 5\
**Last updated:** [March 10, 2025, 7:19am UTC](https://discuss.elastic.co/t/best-practice-to-add-more-indices/375627 "2025-03-10T07:19:59Z")

</div>

"error":"validation\_exception","reason":"Validation Failed: 1: this action would add \[2\] shards, but this cluster currently has \[999\]/\[1000\] maximum normal shards open;" Hi, I've a requirement where I need to add more i…

---

## [Cannot add runtime field to an existing index](https://discuss.elastic.co/t/cannot-add-runtime-field-to-an-existing-index/375577)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 1\
**Last updated:** [March 7, 2025, 11:15pm UTC](https://discuss.elastic.co/t/cannot-add-runtime-field-to-an-existing-index/375577 "2025-03-07T23:15:42Z")

</div>

I am trying to add a runtime field following the example from "Map a runtime field" in the documentation. PUT my-index-000001/ { "mappings": { "runtime": { "day\_of\_week": { "type": "keyword", …

---

## [I am not getting expected result using subquery in \_sql method of elasticsearch query DSL](https://discuss.elastic.co/t/i-am-not-getting-expected-result-using-subquery-in-sql-method-of-elasticsearch-query-dsl/375550)

<div class="topic-metadata">

**Author:** [@Sunil\_Jagtap](https://discuss.elastic.co/u/Sunil_Jagtap)\
**Replies:** 3\
**Last updated:** [March 7, 2025, 10:57am UTC](https://discuss.elastic.co/t/i-am-not-getting-expected-result-using-subquery-in-sql-method-of-elasticsearch-query-dsl/375550 "2025-03-07T10:57:38Z")

</div>

Below is the query & output, kindly suggest, GET \_sql?format=txt { "query": """ SELECT tenant\_id, (SELECT is\_vulnerability\_scan\_tool\_active from "index1") AS VST from "index2" where tenant\_id='ABCDEFHG' """ } …

---

## [Unable to setup connector in docker environment](https://discuss.elastic.co/t/unable-to-setup-connector-in-docker-environment/373315)

<div class="topic-metadata">

**Author:** [@Eshwar\_K](https://discuss.elastic.co/u/Eshwar_K)\
**Replies:** 7\
**Last updated:** [March 7, 2025, 9:10am UTC](https://discuss.elastic.co/t/unable-to-setup-connector-in-docker-environment/373315 "2025-03-07T09:10:30Z")

</div>

Hi Community, I am setting up a connector on top of docker but while running docker with provided configuration from Kibana UI, I am getting below errors. I am not sure why docker is giving permission denied error. Can…

---

## [ELASTIC\_PASSWORD and KIBANA\_PASSWORD in docker-compose seems to be ignored?](https://discuss.elastic.co/t/elastic-password-and-kibana-password-in-docker-compose-seems-to-be-ignored/375389)

<div class="topic-metadata">

**Author:** [@hairdo-wirier](https://discuss.elastic.co/u/hairdo-wirier)\
**Replies:** 3\
**Last updated:** [March 7, 2025, 4:57am UTC](https://discuss.elastic.co/t/elastic-password-and-kibana-password-in-docker-compose-seems-to-be-ignored/375389 "2025-03-07T04:57:45Z")

</div>

I am building out an automation project using ansible, docker and of course Elasticsearch. I have got SSL working, but I am really struggling with setting the passwords non-interactively. My understanding from the docs,…

---

## [Knn\_vectors field understanding](https://discuss.elastic.co/t/knn-vectors-field-understanding/374923)

<div class="topic-metadata">

**Author:** [@yli](https://discuss.elastic.co/u/yli)\
**Replies:** 23\
**Last updated:** [March 6, 2025, 11:13pm UTC](https://discuss.elastic.co/t/knn-vectors-field-understanding/374923 "2025-03-06T23:13:04Z")

</div>

Hi, I have defined one field, named "file\_section\_embedding", in my index mapping to be dense\_vector and enabled index for it. I also tested both including and excluding the dense vector field in/from the "\_source", and…

---

## [DWG - ElasticSearch - Tika](https://discuss.elastic.co/t/dwg-elasticsearch-tika/375383)

<div class="topic-metadata">

**Author:** [@uniconfortced](https://discuss.elastic.co/u/uniconfortced)\
**Replies:** 5\
**Last updated:** [March 6, 2025, 9:34pm UTC](https://discuss.elastic.co/t/dwg-elasticsearch-tika/375383 "2025-03-06T21:34:25Z")

</div>

I have a simple question. I read that Tika can extract information from CAD file as DWG format. There is a mode to improve this in Elastic? I put into modules\\ingest-attachment folder tika-parser-cad-module-2.9.2.jar b…

---

## [Which loggers does Elasticsearch have?](https://discuss.elastic.co/t/which-loggers-does-elasticsearch-have/375514)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 6\
**Last updated:** [March 6, 2025, 3:54pm UTC](https://discuss.elastic.co/t/which-loggers-does-elasticsearch-have/375514 "2025-03-06T15:54:51Z")

</div>

The doc says: Messages are logged by a hierarchy of loggers which matches the hierarchy of Java packages and classes in the Elasticsearch source code. And it gives an example: logger.org.elasticsearch.discovery: DEB…

---

## [Using the UpdateByQuery with InlineScript,100000+ items it is giving the max timeout exception](https://discuss.elastic.co/t/using-the-updatebyquery-with-inlinescript-100000-items-it-is-giving-the-max-timeout-exception/375434)

<div class="topic-metadata">

**Author:** [@rutuja](https://discuss.elastic.co/u/rutuja)\
**Replies:** 6\
**Last updated:** [March 6, 2025, 9:20am UTC](https://discuss.elastic.co/t/using-the-updatebyquery-with-inlinescript-100000-items-it-is-giving-the-max-timeout-exception/375434 "2025-03-06T09:20:53Z")

</div>

I am using the UpdateByQuery with InlineScript, but it is working for only 30000-40000 items while updating, and for 100000+ items it is giving the connection time out exception and only updating 14000 items. i want to …

---

## [Logstash single server](https://discuss.elastic.co/t/logstash-single-server/375493)

<div class="topic-metadata">

**Author:** [@Trent-alex](https://discuss.elastic.co/u/Trent-alex)\
**Replies:** 1\
**Last updated:** [March 6, 2025, 5:01am UTC](https://discuss.elastic.co/t/logstash-single-server/375493 "2025-03-06T05:01:16Z")

</div>

Hello I have the following configuration file reporting the below error. This is all running on a single machine. filter { csv { separator =\> "," columns =\> \["Day of Date Eastern", "Device Id", "Location", "T…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=40)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=42)
