# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=44

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 45

---

## [Contact for solutions when index lifecycle policies are not reflected](https://discuss.elastic.co/t/contact-for-solutions-when-index-lifecycle-policies-are-not-reflected/374913)

<div class="topic-metadata">

**Author:** [@sjoh9163](https://discuss.elastic.co/u/sjoh9163)\
**Replies:** 3\
**Last updated:** [February 24, 2025, 3:08pm UTC](https://discuss.elastic.co/t/contact-for-solutions-when-index-lifecycle-policies-are-not-reflected/374913 "2025-02-24T15:08:38Z")

</div>

I am using ECK 8.14 and here is the reflected Index Lifecycle Policies(ILM) content: PUT \_ilm/policy/ECK-ILM { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { "set\_p…

---

## [Please help me with manual deletion of index](https://discuss.elastic.co/t/please-help-me-with-manual-deletion-of-index/374929)

<div class="topic-metadata">

**Author:** [@sjoh9163](https://discuss.elastic.co/u/sjoh9163)\
**Replies:** 1\
**Last updated:** [February 24, 2025, 1:28pm UTC](https://discuss.elastic.co/t/please-help-me-with-manual-deletion-of-index/374929 "2025-02-24T13:28:03Z")

</div>

Please help me organize INDEX manually I want to delete INDEX manually because ILM policy doesn't seem to reflect properly. For example, DELETE /.ds-logs-elastic\_agent-default-2025.01.06-000004 or POST /.ds-logs-e…

---

## [Having issues with low watermark / disk space](https://discuss.elastic.co/t/having-issues-with-low-watermark-disk-space/374934)

<div class="topic-metadata">

**Author:** [@cybertron](https://discuss.elastic.co/u/cybertron)\
**Replies:** 5\
**Last updated:** [February 24, 2025, 9:45am UTC](https://discuss.elastic.co/t/having-issues-with-low-watermark-disk-space/374934 "2025-02-24T09:45:24Z")

</div>

Hi I have been struggling with low watermark that keeps getting hit on some nodes in my cluster. I have a 6 node cluster, that unfortunatly have different diskspace. 3 nodes have 5 TB and 3 nodes have 10TB. The proble…

---

## [How to choose number of max threadpools for snapshots](https://discuss.elastic.co/t/how-to-choose-number-of-max-threadpools-for-snapshots/374922)

<div class="topic-metadata">

**Author:** [@Dharani\_Vattamwar](https://discuss.elastic.co/u/Dharani_Vattamwar)\
**Replies:** 1\
**Last updated:** [February 24, 2025, 7:56am UTC](https://discuss.elastic.co/t/how-to-choose-number-of-max-threadpools-for-snapshots/374922 "2025-02-24T07:56:54Z")

</div>

We have an elasticsearch cluster with 15 data nodes each with almost 9TB data to get snapshotted. Disk max\_snapshot\_Bytes\_per\_second is 250MB/sec. cpu -\> 4 cores ES\_JAVA\_OPTS -\> -Xms10240m -Xmx10240m

---

## [Adding Custom plugin on Elastic Cloud](https://discuss.elastic.co/t/adding-custom-plugin-on-elastic-cloud/374743)

<div class="topic-metadata">

**Author:** [@jaewon\_park](https://discuss.elastic.co/u/jaewon_park)\
**Replies:** 5\
**Last updated:** [February 24, 2025, 6:50am UTC](https://discuss.elastic.co/t/adding-custom-plugin-on-elastic-cloud/374743 "2025-02-24T06:50:27Z")

</div>

Trying to add plugin (.zip) through the Extensions tool. But I can't choose "installable plugin". Says it is not supported by my subscription. No additional information and nothing in the documentation. I am on Enterpri…

---

## [Azure Blob Storage Searchable Snapshot Repository Supported Storage Classes](https://discuss.elastic.co/t/azure-blob-storage-searchable-snapshot-repository-supported-storage-classes/374871)

<div class="topic-metadata">

**Author:** [@pkmollman](https://discuss.elastic.co/u/pkmollman)\
**Replies:** 1\
**Last updated:** [February 22, 2025, 8:31am UTC](https://discuss.elastic.co/t/azure-blob-storage-searchable-snapshot-repository-supported-storage-classes/374871 "2025-02-22T08:31:03Z")

</div>

Does anyone know what storage classes are supported for Azure blob? There are docs that mention AWS S3 archive tiers aren't supported for snapshot repositories, but do hot, cool, cold, and archive all work for Azure blo…

---

## [Custom Connectors vs Integrations](https://discuss.elastic.co/t/custom-connectors-vs-integrations/374862)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [February 21, 2025, 10:57pm UTC](https://discuss.elastic.co/t/custom-connectors-vs-integrations/374862 "2025-02-21T22:57:31Z")

</div>

Hello, what is the difference between both?

---

## [Cleaning indexes or overwriting indexes automatically](https://discuss.elastic.co/t/cleaning-indexes-or-overwriting-indexes-automatically/374791)

<div class="topic-metadata">

**Author:** [@website](https://discuss.elastic.co/u/website)\
**Replies:** 1\
**Last updated:** [February 21, 2025, 8:17pm UTC](https://discuss.elastic.co/t/cleaning-indexes-or-overwriting-indexes-automatically/374791 "2025-02-21T20:17:06Z")

</div>

I deployed elasticsearch with suricata, now suricata has filled up the disk space, I wanted to increase the indexes with a period of more than 30 days or configure elasticsearch itself so that it overwrites the indexes a…

---

## [Elastic search scoring issue](https://discuss.elastic.co/t/elastic-search-scoring-issue/374694)

<div class="topic-metadata">

**Author:** [@Santanu112](https://discuss.elastic.co/u/Santanu112)\
**Replies:** 3\
**Last updated:** [February 21, 2025, 7:04pm UTC](https://discuss.elastic.co/t/elastic-search-scoring-issue/374694 "2025-02-21T19:04:47Z")

</div>

Hi All, I have implemented edge\_ngram. When i am searching "Santanu Prasad" I am getting 3 doc, "santanu", "santanu prasad" and "prasad" For the below query i am getting : "Prasad" with highest score then "Santanu P…

---

## [Expected configuration is missing from elasticsearch.yml](https://discuss.elastic.co/t/expected-configuration-is-missing-from-elasticsearch-yml/374861)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [February 21, 2025, 5:23pm UTC](https://discuss.elastic.co/t/expected-configuration-is-missing-from-elasticsearch-yml/374861 "2025-02-21T17:23:51Z")

</div>

Kindly help. While I am building a cluster with two nodes in version 8.15, I have started node1, and generated a token for node2 by command: /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node But…

---

## [Getting the count of documents in one index based on the ID on another index](https://discuss.elastic.co/t/getting-the-count-of-documents-in-one-index-based-on-the-id-on-another-index/374828)

<div class="topic-metadata">

**Author:** [@kko](https://discuss.elastic.co/u/kko)\
**Replies:** 4\
**Last updated:** [February 21, 2025, 2:13pm UTC](https://discuss.elastic.co/t/getting-the-count-of-documents-in-one-index-based-on-the-id-on-another-index/374828 "2025-02-21T14:13:56Z")

</div>

I have 2 indices, one contains all the courses and another index contains all the student registrations. Is there a way I can query the course index and get the count of registrations from the registration index in one q…

---

## [Slow bulk speed](https://discuss.elastic.co/t/slow-bulk-speed/373675)

<div class="topic-metadata">

**Author:** [@ronwilson](https://discuss.elastic.co/u/ronwilson)\
**Replies:** 61\
**Last updated:** [February 21, 2025, 10:47am UTC](https://discuss.elastic.co/t/slow-bulk-speed/373675 "2025-02-21T10:47:29Z")

</div>

Hi! We have performance issue with bulk operations in Elasticsearch 8.14.3. Bulks looks like this (tried from 1000 up to 25000 records - no changes): { "index": {"\_id" : "627", "\_index": "iv\_counter\_fd7bb2fd122ca9a08d40…

---

## [Unable to Create Enrollment Token After http.p12 Certificate Renewal](https://discuss.elastic.co/t/unable-to-create-enrollment-token-after-http-p12-certificate-renewal/374842)

<div class="topic-metadata">

**Author:** [@Rushali](https://discuss.elastic.co/u/Rushali)\
**Replies:** 0\
**Last updated:** [February 21, 2025, 7:35am UTC](https://discuss.elastic.co/t/unable-to-create-enrollment-token-after-http-p12-certificate-renewal/374842 "2025-02-21T07:35:14Z")

</div>

I followed the official guide for the renewal of http.p12 cert for Elasticsearch: Basic Security Setup with HTTPS After renewing the http.p12 certificate, we are facing an issue where we cannot generate an enrollment t…

---

## [ElasticSearch self-signed Certificate error](https://discuss.elastic.co/t/elasticsearch-self-signed-certificate-error/374835)

<div class="topic-metadata">

**Author:** [@jeanne1](https://discuss.elastic.co/u/jeanne1)\
**Replies:** 0\
**Last updated:** [February 20, 2025, 9:18pm UTC](https://discuss.elastic.co/t/elasticsearch-self-signed-certificate-error/374835 "2025-02-20T21:18:33Z")

</div>

Hi, On my local ubuntu machine, I am running elasticsearch via docker container: docker run --name es01 --net elastic -p 9200:9200 -it -m 1GB \\ -e "discovery.type=single-node" \\ -e "network.host=0.0.0.0" \\ docker…

---

## [Datastreams are slower than normal indices?](https://discuss.elastic.co/t/datastreams-are-slower-than-normal-indices/374811)

<div class="topic-metadata">

**Author:** [@Victor\_Monteagudo](https://discuss.elastic.co/u/Victor_Monteagudo)\
**Replies:** 6\
**Last updated:** [February 20, 2025, 5:49pm UTC](https://discuss.elastic.co/t/datastreams-are-slower-than-normal-indices/374811 "2025-02-20T17:49:59Z")

</div>

Context: I have an Elasticsearch 7.17.10 running on a Docker machine. This Elasticsearch cluster has two nodes. We are ingesting DNS traffic using Packetbeat. We rotate indices daily: for example, dns-2025-02-20, dns…

---

## [Ingestion pipeline doesn't appear to be invoked](https://discuss.elastic.co/t/ingestion-pipeline-doesnt-appear-to-be-invoked/374816)

<div class="topic-metadata">

**Author:** [@wrh](https://discuss.elastic.co/u/wrh)\
**Replies:** 0\
**Last updated:** [February 20, 2025, 1:06pm UTC](https://discuss.elastic.co/t/ingestion-pipeline-doesnt-appear-to-be-invoked/374816 "2025-02-20T13:06:38Z")

</div>

I'm working on ingesting DB2 logs from db2diag.log into elastic. Here's the steps I have taken so far, and how much is working: Index Template - create an index template logs-db2.diag with index pattern logs-db2.diag-\* …

---

## [Parsing nested json](https://discuss.elastic.co/t/parsing-nested-json/374629)

<div class="topic-metadata">

**Author:** [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Replies:** 6\
**Last updated:** [February 20, 2025, 2:55pm UTC](https://discuss.elastic.co/t/parsing-nested-json/374629 "2025-02-20T14:55:43Z")

</div>

I am having issues with our AWS ecs -\> fluentbit -\> elasticsearch set up, specifically around nested json. For example, if the log message is: { "endpoint": "/process", "payload": { "body": { "success":…

---

## [Sorted pagination in terms aggregation search](https://discuss.elastic.co/t/sorted-pagination-in-terms-aggregation-search/374820)

<div class="topic-metadata">

**Author:** [@julian.dto](https://discuss.elastic.co/u/julian.dto)\
**Replies:** 0\
**Last updated:** [February 20, 2025, 1:46pm UTC](https://discuss.elastic.co/t/sorted-pagination-in-terms-aggregation-search/374820 "2025-02-20T13:46:58Z")

</div>

Hello! I am trying to run an aggregation search with pagination. The solutions I found were either partitioning or using search\_after. With partitioning the sorting will only be inside of the partition, not the overall…

---

## [Avoid duplicate insertions](https://discuss.elastic.co/t/avoid-duplicate-insertions/374809)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 3\
**Last updated:** [February 20, 2025, 1:58pm UTC](https://discuss.elastic.co/t/avoid-duplicate-insertions/374809 "2025-02-20T13:58:25Z")

</div>

Hi, What is the best method to avoid duplicate insertions (based on one or two fields) in an index? I am thinking of a mechanism like Primary Key of relational databases. Thanks for your suggestions. Cristina

---

## [Elasticsearch query | DSL Rules trigger count](https://discuss.elastic.co/t/elasticsearch-query-dsl-rules-trigger-count/374810)

<div class="topic-metadata">

**Author:** [@joaosf](https://discuss.elastic.co/u/joaosf)\
**Replies:** 0\
**Last updated:** [February 20, 2025, 11:47am UTC](https://discuss.elastic.co/t/elasticsearch-query-dsl-rules-trigger-count/374810 "2025-02-20T11:47:37Z")

</div>

Hi all, I created a script query and now I want to trigger an email if the count is more than 0. GET /xpto\_xpto/\_search { "\_source": false, "track\_total\_hits": false, "size": 0, "query": { "bool": { }…

---

## [Embedding generation using E5 failing for some records](https://discuss.elastic.co/t/embedding-generation-using-e5-failing-for-some-records/374090)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [February 20, 2025, 9:45am UTC](https://discuss.elastic.co/t/embedding-generation-using-e5-failing-for-some-records/374090 "2025-02-20T09:45:12Z")

</div>

I am trying to use the E5 model to generate embeddings for some documents. I used a reindex to generate the embeddings: POST \_reindex?wait\_for\_completion=false { "source": { "index": "source\_index", "size": 5…

---

## [Reindex stops stops after 1000 docs](https://discuss.elastic.co/t/reindex-stops-stops-after-1000-docs/374779)

<div class="topic-metadata">

**Author:** [@honungsburk](https://discuss.elastic.co/u/honungsburk)\
**Replies:** 3\
**Last updated:** [February 20, 2025, 7:30am UTC](https://discuss.elastic.co/t/reindex-stops-stops-after-1000-docs/374779 "2025-02-20T07:30:07Z")

</div>

Hello! I currently have 1 index filled with about 500k documents that I want to reindex into another index where I have added a semantic text search field. It is the most basic kind that uses the built in stuff in Elast…

---

## [Large log data indexing best practices (datastreams?)](https://discuss.elastic.co/t/large-log-data-indexing-best-practices-datastreams/374780)

<div class="topic-metadata">

**Author:** [@AnthonyKeydel](https://discuss.elastic.co/u/AnthonyKeydel)\
**Replies:** 2\
**Last updated:** [February 19, 2025, 8:59pm UTC](https://discuss.elastic.co/t/large-log-data-indexing-best-practices-datastreams/374780 "2025-02-19T20:59:38Z")

</div>

Hi there! I've been working to refine my Elastic instance for months now, and have gotten a bit tangled in the details. :face\_with\_spiral\_eyes: Before promoting the PoC into a live Production environment, I could use a…

---

## [How to save docker elastic search data permanently in azure storage](https://discuss.elastic.co/t/how-to-save-docker-elastic-search-data-permanently-in-azure-storage/374654)

<div class="topic-metadata">

**Author:** [@Constellation2025](https://discuss.elastic.co/u/Constellation2025)\
**Replies:** 5\
**Last updated:** [February 19, 2025, 3:19pm UTC](https://discuss.elastic.co/t/how-to-save-docker-elastic-search-data-permanently-in-azure-storage/374654 "2025-02-19T15:19:26Z")

</div>

How can I permanently save Elasticsearch data in Azure while using Docker, ensuring that the data remains intact even if the container is stopped or restarted?

---

## [Fleet Agent Cannot Export to CSV](https://discuss.elastic.co/t/fleet-agent-cannot-export-to-csv/374752)

<div class="topic-metadata">

**Author:** [@kulisiber](https://discuss.elastic.co/u/kulisiber)\
**Replies:** 4\
**Last updated:** [February 19, 2025, 2:43pm UTC](https://discuss.elastic.co/t/fleet-agent-cannot-export-to-csv/374752 "2025-02-19T14:43:19Z")

</div>

I have a need to list all fleet agents with status and such for document purposes. I didn't find an export agent feature like on the Wazuh Dashboard. As a result, I tried to query Dev Tools but still didn't get the right…

---

## [.NET Client: Implementing Location Bias in a Query](https://discuss.elastic.co/t/net-client-implementing-location-bias-in-a-query/374685)

<div class="topic-metadata">

**Author:** [@Patricius](https://discuss.elastic.co/u/Patricius)\
**Replies:** 3\
**Last updated:** [February 19, 2025, 2:23pm UTC](https://discuss.elastic.co/t/net-client-implementing-location-bias-in-a-query/374685 "2025-02-19T14:23:41Z")

</div>

Hello, I'm working on a query with location bias with the new Elastic.Clients.Elasticsearch but I can't find any good documentation on how to do it. My EF-Core entity has those variables: public double Latitude { get;…

---

## [Cluster not forming](https://discuss.elastic.co/t/cluster-not-forming/374581)

<div class="topic-metadata">

**Author:** [@joelatgrayv](https://discuss.elastic.co/u/joelatgrayv)\
**Replies:** 14\
**Last updated:** [February 19, 2025, 12:10pm UTC](https://discuss.elastic.co/t/cluster-not-forming/374581 "2025-02-19T12:10:01Z")

</div>

I’m trying to get an ES cluster working with a cloud formation. I have it all up and running but the cluster is not forming correctly. This is the error that I’m getting: {"@timestamp":"2025-02-14T22:02:57.598Z", "log.…

---

## [Unable to set mustache.max\_output\_size\_bytes in elasticsearch.yml version 7.17.25](https://discuss.elastic.co/t/unable-to-set-mustache-max-output-size-bytes-in-elasticsearch-yml-version-7-17-25/372412)

<div class="topic-metadata">

**Author:** [@ManojKumarM](https://discuss.elastic.co/u/ManojKumarM)\
**Replies:** 17\
**Last updated:** [February 19, 2025, 12:18pm UTC](https://discuss.elastic.co/t/unable-to-set-mustache-max-output-size-bytes-in-elasticsearch-yml-version-7-17-25/372412 "2025-02-19T12:18:15Z")

</div>

Hi, We have recently upgraded to 7.17.25 and trying to set the below configuration in elasticsearch.yml as recommended in the release notes mustache.max\_output\_size\_bytes: 10485760 however we see that configuration is…

---

## [ES|QL and the \_size field](https://discuss.elastic.co/t/es-ql-and-the-size-field/374753)

<div class="topic-metadata">

**Author:** [@pilarjin](https://discuss.elastic.co/u/pilarjin)\
**Replies:** 1\
**Last updated:** [February 19, 2025, 11:13am UTC](https://discuss.elastic.co/t/es-ql-and-the-size-field/374753 "2025-02-19T11:13:13Z")

</div>

Hi, is it possible to use \_size field in ES|QL? I didn't find it mentioned in the limitations documentation. We are trying to identify traces that generate too much data as feedback for developers what to optimize. Ex…

---

## [How to specify index name in Elastic.Serilog.Sinks](https://discuss.elastic.co/t/how-to-specify-index-name-in-elastic-serilog-sinks/374741)

<div class="topic-metadata">

**Author:** [@Nick\_Farsi](https://discuss.elastic.co/u/Nick_Farsi)\
**Replies:** 0\
**Last updated:** [February 19, 2025, 9:13am UTC](https://discuss.elastic.co/t/how-to-specify-index-name-in-elastic-serilog-sinks/374741 "2025-02-19T09:13:36Z")

</div>

I have switched from Serilog.Sinks.Elasticsearch package to Elastic.Serilog.Sinks. Before I would specify target index name like this: string indexFormat = settings.IndexName.Replace("$ComponentID$", componentId.ToLowe…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=43)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=45)
