# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=42

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 43

---

## [Aggregation Group By With Total Count](https://discuss.elastic.co/t/aggregation-group-by-with-total-count/375057)

<div class="topic-metadata">

**Author:** [@hammadrasheed0](https://discuss.elastic.co/u/hammadrasheed0)\
**Replies:** 4\
**Last updated:** [March 5, 2025, 8:00pm UTC](https://discuss.elastic.co/t/aggregation-group-by-with-total-count/375057 "2025-03-05T20:00:55Z")

</div>

HI, I am stuck with a use case where I need to group N number of persons by company and get the total count of grouped persons across the pages. So far the query I have prepared is working fine up to the level where the…

---

## [Error Ingesting AWS Security Hub Data](https://discuss.elastic.co/t/error-ingesting-aws-security-hub-data/375013)

<div class="topic-metadata">

**Author:** [@Abhay\_Singh](https://discuss.elastic.co/u/Abhay_Singh)\
**Replies:** 4\
**Last updated:** [March 5, 2025, 5:35pm UTC](https://discuss.elastic.co/t/error-ingesting-aws-security-hub-data/375013 "2025-03-05T17:35:53Z")

</div>

Hello Team, I am trying to ingest data from AWS Security Hub into elastic using elastic agent and the integration available, however i am getting the below error. Could someone guide me how i can resolve this issue. Er…

---

## [Illegal\_argument\_exception Text Fields are not Optmised](https://discuss.elastic.co/t/illegal-argument-exception-text-fields-are-not-optmised/375386)

<div class="topic-metadata">

**Author:** [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Replies:** 2\
**Last updated:** [March 5, 2025, 4:40pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-text-fields-are-not-optmised/375386 "2025-03-05T16:40:25Z")

</div>

I have started getting this error when trying to run an average and median on a what certainly used to be mapped as a number. Type: illegal\_argument\_exception Reason: Text fields are not optimised for operations that r…

---

## [Error when restoring snapshot to a new stack](https://discuss.elastic.co/t/error-when-restoring-snapshot-to-a-new-stack/375461)

<div class="topic-metadata">

**Author:** [@koffe](https://discuss.elastic.co/u/koffe)\
**Replies:** 0\
**Last updated:** [March 5, 2025, 2:00pm UTC](https://discuss.elastic.co/t/error-when-restoring-snapshot-to-a-new-stack/375461 "2025-03-05T14:00:39Z")

</div>

Hi! I am trying to move my saved snapshots from my old stack to a new one. For some of my snapshots i get the following message: "searchable snapshots indices may be converted only within the same repository" What i h…

---

## [Which node has ML model deployed](https://discuss.elastic.co/t/which-node-has-ml-model-deployed/375447)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [March 5, 2025, 10:46am UTC](https://discuss.elastic.co/t/which-node-has-ml-model-deployed/375447 "2025-03-05T10:46:46Z")

</div>

Hi team! On my self managed elastic cluster, is it possible to check which node has the ML model deployed? I want to confirm that the ML node has it deployed and not in data node. Please help

---

## [How to ensure unique sorting with search\_after in Elasticsearch 8?](https://discuss.elastic.co/t/how-to-ensure-unique-sorting-with-search-after-in-elasticsearch-8/375233)

<div class="topic-metadata">

**Author:** [@jiel](https://discuss.elastic.co/u/jiel)\
**Replies:** 2\
**Last updated:** [March 5, 2025, 9:52am UTC](https://discuss.elastic.co/t/how-to-ensure-unique-sorting-with-search-after-in-elasticsearch-8/375233 "2025-03-05T09:52:29Z")

</div>

Hello, I am working on a tool that needs to retrieve large batches of records from an Elasticsearch index. The recommended method used to be the Scroll API, but it is now deprecated in favor of search\_after as stated in…

---

## [connect ElasticSearch script to Kibana dashboard](https://discuss.elastic.co/t/connect-elasticsearch-script-to-kibana-dashboard/375244)

<div class="topic-metadata">

**Author:** [@IgorStan](https://discuss.elastic.co/u/IgorStan)\
**Replies:** 7\
**Last updated:** [March 5, 2025, 9:45am UTC](https://discuss.elastic.co/t/connect-elasticsearch-script-to-kibana-dashboard/375244 "2025-03-05T09:45:25Z")

</div>

I don't understand how to connect Elasticsearch Dev Tools scripts to Kibana dashboard. Say that we have a nice script: GET name\_of\_my\_index/\_search { "size": 0, "aggs": { "tags\_count": { "scripted\_metric"…

---

## [Elasticsearch service is not starting](https://discuss.elastic.co/t/elasticsearch-service-is-not-starting/375435)

<div class="topic-metadata">

**Author:** [@Temor\_Shah\_Waris](https://discuss.elastic.co/u/Temor_Shah_Waris)\
**Replies:** 4\
**Last updated:** [March 5, 2025, 9:27am UTC](https://discuss.elastic.co/t/elasticsearch-service-is-not-starting/375435 "2025-03-05T09:27:09Z")

</div>

Dear Friends, I configured SSL certificate on elasticsearch yml file after restart the service it is not running ( I do checked the yml file, SSL certificate CA, Key and CRT file ) also I checked the permissions which a…

---

## [Index rollover and ILM issue](https://discuss.elastic.co/t/index-rollover-and-ilm-issue/374824)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 12\
**Last updated:** [March 4, 2025, 4:43pm UTC](https://discuss.elastic.co/t/index-rollover-and-ilm-issue/374824 "2025-03-04T16:43:47Z")

</div>

Hello I hope my message finds the community & their loved ones safe and healthy. I have a 3-node cluster. 2 nodes store data and carry out processing 1 node is a voting only node. All the data to Elasticsear…

---

## [Elasticsearch cluster - container vs. native](https://discuss.elastic.co/t/elasticsearch-cluster-container-vs-native/375427)

<div class="topic-metadata">

**Author:** [@gruens](https://discuss.elastic.co/u/gruens)\
**Replies:** 1\
**Last updated:** [March 5, 2025, 6:56am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-container-vs-native/375427 "2025-03-05T06:56:02Z")

</div>

Hello Community, we already run two non-critical three node clusters on vsphere virtual machines (RHEL) with podman. The criticality will increase in the future, so we want to relaunch/improve our current instances. I…

---

## [Cold tier in self managed cluster](https://discuss.elastic.co/t/cold-tier-in-self-managed-cluster/375426)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [March 5, 2025, 6:29am UTC](https://discuss.elastic.co/t/cold-tier-in-self-managed-cluster/375426 "2025-03-05T06:29:47Z")

</div>

can someone please help me understand this: Data tiers | Elasticsearch Guide \[8.17\] | Elastic It says: 1/ cold tier uses searchable snapshots 2/ it can also be used with a replica How do I implement this in self mana…

---

## [I checked my elasticsearch.service and its running well, but i cant healthcheck it](https://discuss.elastic.co/t/i-checked-my-elasticsearch-service-and-its-running-well-but-i-cant-healthcheck-it/375419)

<div class="topic-metadata">

**Author:** [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Replies:** 0\
**Last updated:** [March 5, 2025, 3:36am UTC](https://discuss.elastic.co/t/i-checked-my-elasticsearch-service-and-its-running-well-but-i-cant-healthcheck-it/375419 "2025-03-05T03:36:01Z")

</div>

my service is running and actived but when i run \<curl --cacert/etc/elasticsearch/certs/http\_ca.crt -u elk https:/\_/localhost:9200\> it showed \<Curl 60\> and \<Curl 52\>

---

## [After edited the elasticsearch.yml file, my service turn into inactive](https://discuss.elastic.co/t/after-edited-the-elasticsearch-yml-file-my-service-turn-into-inactive/375338)

<div class="topic-metadata">

**Author:** [@Duong\_Hieu](https://discuss.elastic.co/u/Duong_Hieu)\
**Replies:** 7\
**Last updated:** [March 5, 2025, 3:32am UTC](https://discuss.elastic.co/t/after-edited-the-elasticsearch-yml-file-my-service-turn-into-inactive/375338 "2025-03-05T03:32:52Z")

</div>

Hi, im new to elasticsearch, i already install elasticsearch and kibana, they're running well but things have change when i edited the elastichsearch.yml file After i edited, the elasticsearch service turn to inactive s…

---

## [Upgrading from 8.x to 9.x with \_source disabled](https://discuss.elastic.co/t/upgrading-from-8-x-to-9-x-with-source-disabled/375388)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 5\
**Last updated:** [March 5, 2025, 3:23am UTC](https://discuss.elastic.co/t/upgrading-from-8-x-to-9-x-with-source-disabled/375388 "2025-03-05T03:23:28Z")

</div>

Hello, I am exploring disabling \_source for some of my indices. The documentation has warnings about doing that. One specific line in the warnings is not very clear to me: "The ability to reindex from one Elasticse…

---

## [Does Elastic Cloud Hosting Charge you for 24 hours in advance?](https://discuss.elastic.co/t/does-elastic-cloud-hosting-charge-you-for-24-hours-in-advance/375413)

<div class="topic-metadata">

**Author:** [@manpap11](https://discuss.elastic.co/u/manpap11)\
**Replies:** 0\
**Last updated:** [March 5, 2025, 12:22am UTC](https://discuss.elastic.co/t/does-elastic-cloud-hosting-charge-you-for-24-hours-in-advance/375413 "2025-03-05T00:22:13Z")

</div>

Hello everyone, I'm quite new to the ecosystem so thanks in advance for your patience! As the title of the post suggests I enabled the trial for the Elastic Cloud Hosting to see the features and capabilities, at first …

---

## [What is the meaning of the following acronyms? "o.e.a.a.i.m.p." and "o.e.c.s."](https://discuss.elastic.co/t/what-is-the-meaning-of-the-following-acronyms-o-e-a-a-i-m-p-and-o-e-c-s/375405)

<div class="topic-metadata">

**Author:** [@Chris\_McGrath](https://discuss.elastic.co/u/Chris_McGrath)\
**Replies:** 5\
**Last updated:** [March 4, 2025, 10:39pm UTC](https://discuss.elastic.co/t/what-is-the-meaning-of-the-following-acronyms-o-e-a-a-i-m-p-and-o-e-c-s/375405 "2025-03-04T22:39:05Z")

</div>

I saw in AWS OpenSearch logs a message very similar to a stack overflow post, The key part of which is: \[2020-03-17T09:13:08,964\]\[DEBUG\]\[o.e.c.s.MasterService \] \[prod-apm-elasticsearch103.example.com\] processing \[put…

---

## [Elasticsearch cluster with Docker vs Kubernetes](https://discuss.elastic.co/t/elasticsearch-cluster-with-docker-vs-kubernetes/375074)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 9\
**Last updated:** [March 4, 2025, 8:34pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-with-docker-vs-kubernetes/375074 "2025-03-04T20:34:48Z")

</div>

Question regarding the upgrade of an Elasticsearch cluster, which has over 50 nodes, to a new cluster running RedHat operating system. The question is: should we build the new cluster in a Docker environment or a Kub…

---

## [PDF content wrong sequence and space](https://discuss.elastic.co/t/pdf-content-wrong-sequence-and-space/375001)

<div class="topic-metadata">

**Author:** [@uniconfortced](https://discuss.elastic.co/u/uniconfortced)\
**Replies:** 2\
**Last updated:** [March 4, 2025, 3:32pm UTC](https://discuss.elastic.co/t/pdf-content-wrong-sequence-and-space/375001 "2025-03-04T15:32:48Z")

</div>

Good morning, I am new into Elasticsearch use. I install it to search information from content of PDF generated by my old ERP. Elastic extract correct text but into wrong sequence that depend from PDF read sequence or t…

---

## [Achieving a books dot google dot com workflow with Elasticsearch as search engine, any indexer and tesseract OCR tool?](https://discuss.elastic.co/t/achieving-a-books-dot-google-dot-com-workflow-with-elasticsearch-as-search-engine-any-indexer-and-tesseract-ocr-tool/375380)

<div class="topic-metadata">

**Author:** [@davecomputertips](https://discuss.elastic.co/u/davecomputertips)\
**Replies:** 1\
**Last updated:** [March 4, 2025, 3:26pm UTC](https://discuss.elastic.co/t/achieving-a-books-dot-google-dot-com-workflow-with-elasticsearch-as-search-engine-any-indexer-and-tesseract-ocr-tool/375380 "2025-03-04T15:26:37Z")

</div>

Chatgpt and deepseek hallucinated on this so asking here: 10s of pdfs is downloaded. I want to search for a particular topic inside the content of pdf. I search it. Then I want to read that pdf going to that exact page…

---

## [Shard best practices count vs stats for limit](https://discuss.elastic.co/t/shard-best-practices-count-vs-stats-for-limit/375377)

<div class="topic-metadata">

**Author:** [@zedEm](https://discuss.elastic.co/u/zedEm)\
**Replies:** 0\
**Last updated:** [March 4, 2025, 1:45pm UTC](https://discuss.elastic.co/t/shard-best-practices-count-vs-stats-for-limit/375377 "2025-03-04T13:45:37Z")

</div>

I have a question about ES best practices as written here Size your shards | Elasticsearch Guide \[8.17\] | Elastic. During inspections I have come across index size discrepancy with stats vs count. This is most likely du…

---

## [ERROR: \[1\] bootstrap checks failed. You must address the points described in the following \[1\] lines before starting Elasticsearch](https://discuss.elastic.co/t/error-1-bootstrap-checks-failed-you-must-address-the-points-described-in-the-following-1-lines-before-starting-elasticsearch/375358)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 4\
**Last updated:** [March 4, 2025, 12:01pm UTC](https://discuss.elastic.co/t/error-1-bootstrap-checks-failed-you-must-address-the-points-described-in-the-following-1-lines-before-starting-elasticsearch/375358 "2025-03-04T12:01:28Z")

</div>

I use the official docker image, version 8.6.0, encounter this error when starting up, but there is no info after this error message, so I don't know what to do.

---

## [Exception while emitting periodic batch from Serilog.Sinks](https://discuss.elastic.co/t/exception-while-emitting-periodic-batch-from-serilog-sinks/375371)

<div class="topic-metadata">

**Author:** [@Deekshi](https://discuss.elastic.co/u/Deekshi)\
**Replies:** 0\
**Last updated:** [March 4, 2025, 11:51am UTC](https://discuss.elastic.co/t/exception-while-emitting-periodic-batch-from-serilog-sinks/375371 "2025-03-04T11:51:38Z")

</div>

Facing below issue Exception while emitting periodic batch from Serilog.Sinks.Elasticsearch.Durable.ElasticsearchLogClient: Elasticsearch.Net.ElasticsearchClientException: The client is unable to verify that the server …

---

## [ransportException: Expecting JSON data but response content-type is application/octet-stream (Elastic Cloud 8.12)](https://discuss.elastic.co/t/ransportexception-expecting-json-data-but-response-content-type-is-application-octet-stream-elastic-cloud-8-12/375323)

<div class="topic-metadata">

**Author:** [@r3b1135h5](https://discuss.elastic.co/u/r3b1135h5)\
**Replies:** 1\
**Last updated:** [March 4, 2025, 8:22am UTC](https://discuss.elastic.co/t/ransportexception-expecting-json-data-but-response-content-type-is-application-octet-stream-elastic-cloud-8-12/375323 "2025-03-04T08:22:23Z")

</div>

Hello, I'm encountering a co.elastic.clients.transport.TransportException with the following error message: co.elastic.clients.transport.TransportException: node: http://my-elasticsearch-project-c2b746.es.ap-southeast-…

---

## [Documentation question](https://discuss.elastic.co/t/documentation-question/375319)

<div class="topic-metadata">

**Author:** [@alon\_hen](https://discuss.elastic.co/u/alon_hen)\
**Replies:** 4\
**Last updated:** [March 4, 2025, 7:44am UTC](https://discuss.elastic.co/t/documentation-question/375319 "2025-03-04T07:44:08Z")

</div>

Hey guys, im trying to read through the docs to understand what a production grade deployment needs , anyways I have reached the part where im reading about node roles Now - there is something rather confusing to me in…

---

## [Export ingest pipeline](https://discuss.elastic.co/t/export-ingest-pipeline/374994)

<div class="topic-metadata">

**Author:** [@poke1710](https://discuss.elastic.co/u/poke1710)\
**Replies:** 1\
**Last updated:** [March 3, 2025, 8:23pm UTC](https://discuss.elastic.co/t/export-ingest-pipeline/374994 "2025-03-03T20:23:31Z")

</div>

Hello, We are looking to export the ingest pipeline in elk to a file so we can import it into another ELK system. Is there a way to do that?

---

## [HDR percentile aggregation memory footprint](https://discuss.elastic.co/t/hdr-percentile-aggregation-memory-footprint/375297)

<div class="topic-metadata">

**Author:** [@mike123](https://discuss.elastic.co/u/mike123)\
**Replies:** 0\
**Last updated:** [March 3, 2025, 7:23am UTC](https://discuss.elastic.co/t/hdr-percentile-aggregation-memory-footprint/375297 "2025-03-03T07:23:33Z")

</div>

Hi, I was facing huge latency in t-digest percentile aggregations, So tried out HDR percentile aggregation. it was fast but in the documentation it is mentioned that "HDR Percentile aggregation has a larger memory foo…

---

## [How to make Elasticsearch REST calls with Postman given nothing but a Cloud ID and API Key?](https://discuss.elastic.co/t/how-to-make-elasticsearch-rest-calls-with-postman-given-nothing-but-a-cloud-id-and-api-key/375295)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 3\
**Last updated:** [March 3, 2025, 4:00am UTC](https://discuss.elastic.co/t/how-to-make-elasticsearch-rest-calls-with-postman-given-nothing-but-a-cloud-id-and-api-key/375295 "2025-03-03T04:00:03Z")

</div>

Hello, if I use the Elasticsearch SDK I can make API calls using nothing but a Cloud ID and API Key - how can I do the same with Postman, which requires a URL? Presumeably the SDK is converting the Cloud ID to a URL, bu…

---

## [Any update to snapshot repositoruy requires to restart ES cluster](https://discuss.elastic.co/t/any-update-to-snapshot-repositoruy-requires-to-restart-es-cluster/375182)

<div class="topic-metadata">

**Author:** [@Dharani\_Vattamwar](https://discuss.elastic.co/u/Dharani_Vattamwar)\
**Replies:** 1\
**Last updated:** [March 2, 2025, 5:43am UTC](https://discuss.elastic.co/t/any-update-to-snapshot-repositoruy-requires-to-restart-es-cluster/375182 "2025-03-02T05:43:05Z")

</div>

We have observer that if we perform any change to snapshot repository or even hit a simple update repository API with exactly same setting we observe connection pool shutdown error or repository inaccessible error which …

---

## [Stack monitoring Ingest Pipeline dashboard 404](https://discuss.elastic.co/t/stack-monitoring-ingest-pipeline-dashboard-404/370846)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 3\
**Last updated:** [March 2, 2025, 5:19am UTC](https://discuss.elastic.co/t/stack-monitoring-ingest-pipeline-dashboard-404/370846 "2025-03-02T05:19:07Z")

</div>

I'm ECE 8.16.0, in the Stack Monitoring section, after going to Nodes, there is a tab for Ingest Pipelines, but it gets a 404 error. Does it work for anyone? Thanks

---

## [How to make Permanent data view of custom indexes](https://discuss.elastic.co/t/how-to-make-permanent-data-view-of-custom-indexes/374795)

<div class="topic-metadata">

**Author:** [@Eshwar\_K](https://discuss.elastic.co/u/Eshwar_K)\
**Replies:** 3\
**Last updated:** [March 1, 2025, 5:04pm UTC](https://discuss.elastic.co/t/how-to-make-permanent-data-view-of-custom-indexes/374795 "2025-03-01T17:04:34Z")

</div>

Hi Community, We had created a customer index for one of our requirement and ingesting the data to the custom index. hence, we can see data is ingesting into custom index whenever we are running the script. However, we …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=41)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=43)
