# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=45

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 46

---

## [Using retrievers in the open source version](https://discuss.elastic.co/t/using-retrievers-in-the-open-source-version/374706)

<div class="topic-metadata">

**Author:** [@Saleh\_AbuAli](https://discuss.elastic.co/u/Saleh_AbuAli)\
**Replies:** 3\
**Last updated:** [February 18, 2025, 9:26pm UTC](https://discuss.elastic.co/t/using-retrievers-in-the-open-source-version/374706 "2025-02-18T21:26:03Z")

</div>

Hi, I’m looking to implement a hybrid search combining kNN and BM25. Is it possible to use retrievers in the open-source version of Elasticsearch to perform this in a single search query instead of using multi-search?

---

## [Implementing Hybrid Search with k-NN and BM25 in Elasticsearch Open Source](https://discuss.elastic.co/t/implementing-hybrid-search-with-k-nn-and-bm25-in-elasticsearch-open-source/374680)

<div class="topic-metadata">

**Author:** [@Saleh\_AbuAli](https://discuss.elastic.co/u/Saleh_AbuAli)\
**Replies:** 2\
**Last updated:** [February 18, 2025, 1:12pm UTC](https://discuss.elastic.co/t/implementing-hybrid-search-with-k-nn-and-bm25-in-elasticsearch-open-source/374680 "2025-02-18T13:12:52Z")

</div>

Hi, I am currently using Elasticsearch version 8.16 and am looking to implement hybrid search that combines k-NN and BM25. Since I am using the open-source version, I am unable to utilize RRF. Is there a way to use retr…

---

## [Plug-in cannot read or write files](https://discuss.elastic.co/t/plug-in-cannot-read-or-write-files/374588)

<div class="topic-metadata">

**Author:** [@lgjut](https://discuss.elastic.co/u/lgjut)\
**Replies:** 3\
**Last updated:** [February 18, 2025, 12:33pm UTC](https://discuss.elastic.co/t/plug-in-cannot-read-or-write-files/374588 "2025-02-18T12:33:35Z")

</div>

When developing a text analysis plug-in, need to read and write dic directory: package com.lietu.bigramSeg; import org.apache.lucene.analysis.Tokenizer; import org.elasticsearch.plugin.analysis.TokenizerFactory; import…

---

## [Limit watcher\_admin role to certain watches](https://discuss.elastic.co/t/limit-watcher-admin-role-to-certain-watches/374635)

<div class="topic-metadata">

**Author:** [@Nicoletta](https://discuss.elastic.co/u/Nicoletta)\
**Replies:** 2\
**Last updated:** [February 18, 2025, 9:44am UTC](https://discuss.elastic.co/t/limit-watcher-admin-role-to-certain-watches/374635 "2025-02-18T09:44:03Z")

</div>

Hi, I was wondering if there's a way to give a user the possibility to create and manage only certain watches, for example all the watches that have a defined prefix. With the builtin role watcher\_admin (or the cluster…

---

## [How to Connect ODBC with Direct Query from Power BI with Elesticserach](https://discuss.elastic.co/t/how-to-connect-odbc-with-direct-query-from-power-bi-with-elesticserach/374637)

<div class="topic-metadata">

**Author:** [@venkat\_subbareddy](https://discuss.elastic.co/u/venkat_subbareddy)\
**Replies:** 1\
**Last updated:** [February 18, 2025, 9:38am UTC](https://discuss.elastic.co/t/how-to-connect-odbc-with-direct-query-from-power-bi-with-elesticserach/374637 "2025-02-18T09:38:33Z")

</div>

Hi Team, As you know ODBC connection don't have direct Query option and would like to connect through Power BI with Real time. Please help me on this.

---

## [Elastic ILM](https://discuss.elastic.co/t/elastic-ilm/374670)

<div class="topic-metadata">

**Author:** [@amarasinghe.kaluarac](https://discuss.elastic.co/u/amarasinghe.kaluarac)\
**Replies:** 2\
**Last updated:** [February 18, 2025, 9:19am UTC](https://discuss.elastic.co/t/elastic-ilm/374670 "2025-02-18T09:19:11Z")

</div>

Hi all, I have a use case where my index should remain in the hot phase for 3 days, then move to the cold phase for 11 days, followed by the frozen phase for 90 days, after which the data should be deleted. My concern …

---

## [AlreadyClosedException error for a Elasticsearch image from \`docker commit\`](https://discuss.elastic.co/t/alreadyclosedexception-error-for-a-elasticsearch-image-from-docker-commit/374660)

<div class="topic-metadata">

**Author:** [@liu\_ben](https://discuss.elastic.co/u/liu_ben)\
**Replies:** 1\
**Last updated:** [February 18, 2025, 5:24am UTC](https://discuss.elastic.co/t/alreadyclosedexception-error-for-a-elasticsearch-image-from-docker-commit/374660 "2025-02-18T05:24:03Z")

</div>

We have a use case to preload some data (e.g. creating some indexes ) into a running Elasticsearch container and once finished, docker commit it to create a data-preloaded image that can be used later. Everything works …

---

## [Cannot update deprecated index setting mapping.source](https://discuss.elastic.co/t/cannot-update-deprecated-index-setting-mapping-source/374645)

<div class="topic-metadata">

**Author:** [@Matt\_Field](https://discuss.elastic.co/u/Matt_Field)\
**Replies:** 3\
**Last updated:** [February 17, 2025, 6:54pm UTC](https://discuss.elastic.co/t/cannot-update-deprecated-index-setting-mapping-source/374645 "2025-02-17T18:54:49Z")

</div>

Upon upgrading elasticsearch 8.17 a number of my indices have gone red. This is because they have the setting index.mapping.source.mode: "STORED" I have seen that this setting is now a premium feature as described her…

---

## [\[2025-02-11T15:35:06,661\]\[WARN \]\[o.e.h.AbstractHttpServerTransport\]](https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 3\
**Last updated:** [February 17, 2025, 5:21pm UTC](https://discuss.elastic.co/t/2025-02-11t1506-661-warn-o-e-h-abstracthttpservertransport/374371 "2025-02-17T17:21:39Z")

</div>

\[2025-02-11T15:35:06,661\]\[WARN \]\[o.e.h.AbstractHttpServerTransport\] \[timon\] caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=/ES-IP:9200, remoteAddress=/Elastalert-IP…

---

## [Login Issues](https://discuss.elastic.co/t/login-issues/374638)

<div class="topic-metadata">

**Author:** [@Steve\_Stefanovich](https://discuss.elastic.co/u/Steve_Stefanovich)\
**Replies:** 3\
**Last updated:** [February 17, 2025, 3:15pm UTC](https://discuss.elastic.co/t/login-issues/374638 "2025-02-17T15:15:24Z")

</div>

Anyone else unable to login via Elastic.co? Keep getting redirected to the serverless onboarding page with no way to cancel out.

---

## [Stale data bug in synthetic source loader on text fields](https://discuss.elastic.co/t/stale-data-bug-in-synthetic-source-loader-on-text-fields/374634)

<div class="topic-metadata">

**Author:** [@jeffgan96](https://discuss.elastic.co/u/jeffgan96)\
**Replies:** 0\
**Last updated:** [February 17, 2025, 2:29pm UTC](https://discuss.elastic.co/t/stale-data-bug-in-synthetic-source-loader-on-text-fields/374634 "2025-02-17T14:29:27Z")

</div>

\#112173 fixed an issue in synthetic source loader where stale data got loaded . this got reworked in #112480 but unfortunately looks like a bug got introduced where we dont reset values if values.size() is 1 . needed s…

---

## [Kaspersky Grok Pattern which is working fine at Grok Debugger is not parsing logs appropriately as expected](https://discuss.elastic.co/t/kaspersky-grok-pattern-which-is-working-fine-at-grok-debugger-is-not-parsing-logs-appropriately-as-expected/374498)

<div class="topic-metadata">

**Author:** [@Shreeraman](https://discuss.elastic.co/u/Shreeraman)\
**Replies:** 3\
**Last updated:** [February 17, 2025, 12:11pm UTC](https://discuss.elastic.co/t/kaspersky-grok-pattern-which-is-working-fine-at-grok-debugger-is-not-parsing-logs-appropriately-as-expected/374498 "2025-02-17T12:11:32Z")

</div>

I have created a Grok Pattern to parse Kaspersky logs. Kaspersky Grok Pattern which I've written is working fine at Grok Debugger In Dev Tools, but logs are not getting parsed in appropriate fields as expected and retu…

---

## [Why do the docs.count and docs.deleted of the generated segments change](https://discuss.elastic.co/t/why-do-the-docs-count-and-docs-deleted-of-the-generated-segments-change/374611)

<div class="topic-metadata">

**Author:** [@cgejian](https://discuss.elastic.co/u/cgejian)\
**Replies:** 4\
**Last updated:** [February 17, 2025, 11:36am UTC](https://discuss.elastic.co/t/why-do-the-docs-count-and-docs-deleted-of-the-generated-segments-change/374611 "2025-02-17T11:36:32Z")

</div>

Background: In version 7.6.0 of ES, an external client is continuously executing update\_by\_query on an index. Phenomenon: At this time, I found through /\_cat/segments that the docs.count and docs.deleted of many existin…

---

## [One Application Migration from Splunk to Elastic search?](https://discuss.elastic.co/t/one-application-migration-from-splunk-to-elastic-search/374619)

<div class="topic-metadata">

**Author:** [@Kumar\_Dudekula](https://discuss.elastic.co/u/Kumar_Dudekula)\
**Replies:** 0\
**Last updated:** [February 17, 2025, 11:25am UTC](https://discuss.elastic.co/t/one-application-migration-from-splunk-to-elastic-search/374619 "2025-02-17T11:25:32Z")

</div>

What steps should we take to migrate an application from Splunk to Elastic Search? Process with Defined Steps

---

## [How to set up conversion tracking from query that's click through](https://discuss.elastic.co/t/how-to-set-up-conversion-tracking-from-query-thats-click-through/374601)

<div class="topic-metadata">

**Author:** [@DavidT\_Spark](https://discuss.elastic.co/u/DavidT_Spark)\
**Replies:** 0\
**Last updated:** [February 17, 2025, 4:46am UTC](https://discuss.elastic.co/t/how-to-set-up-conversion-tracking-from-query-thats-click-through/374601 "2025-02-17T04:46:40Z")

</div>

I'd like to know how or if its possible to track if a specific search query click led to a conversion in Elasticsearch?

---

## [Bug with displaying a NULL value in dense\_vector field in elasticsearch web UI](https://discuss.elastic.co/t/bug-with-displaying-a-null-value-in-dense-vector-field-in-elasticsearch-web-ui/374593)

<div class="topic-metadata">

**Author:** [@gennadii](https://discuss.elastic.co/u/gennadii)\
**Replies:** 0\
**Last updated:** [February 16, 2025, 2:20am UTC](https://discuss.elastic.co/t/bug-with-displaying-a-null-value-in-dense-vector-field-in-elasticsearch-web-ui/374593 "2025-02-16T02:20:21Z")

</div>

Hello! I noticed something that looks like a bug in elasticsearch web UI. When creating a document with dense\_vector field set to null, I cannot expand the document details at elasticsearch web UI documents page (vecto…

---

## ["Estimating Resources for an Elasticsearch Cluster with 10,000 EPS Log Ingestion"](https://discuss.elastic.co/t/estimating-resources-for-an-elasticsearch-cluster-with-10-000-eps-log-ingestion/374487)

<div class="topic-metadata">

**Author:** [@MH\_D](https://discuss.elastic.co/u/MH_D)\
**Replies:** 7\
**Last updated:** [February 15, 2025, 7:03pm UTC](https://discuss.elastic.co/t/estimating-resources-for-an-elasticsearch-cluster-with-10-000-eps-log-ingestion/374487 "2025-02-15T19:03:51Z")

</div>

I have a system that includes Elasticsearch, Logstash, and Kibana, with the following architecture: Logs are collected using Beats (Filebeat, Packetbeat, etc.) and sent to Elasticsearch via Logstash. I want to run Elast…

---

## [Clarification on vCPU Credit Calculation for Coordinating Node](https://discuss.elastic.co/t/clarification-on-vcpu-credit-calculation-for-coordinating-node/374583)

<div class="topic-metadata">

**Author:** [@Wallyson\_Silva](https://discuss.elastic.co/u/Wallyson_Silva)\
**Replies:** 1\
**Last updated:** [February 15, 2025, 2:49am UTC](https://discuss.elastic.co/t/clarification-on-vcpu-credit-calculation-for-coordinating-node/374583 "2025-02-15T02:49:36Z")

</div>

I’m reaching out to seek clarification on how vCPU credits are calculated in the Elastic Cloud UI. Specifically, we noticed that our coordinating node, which has 1GB of RAM, shows only 257 credits. Given the node size, w…

---

## [Strategy for rolling restart with ECK?](https://discuss.elastic.co/t/strategy-for-rolling-restart-with-eck/374576)

<div class="topic-metadata">

**Author:** [@blunckr](https://discuss.elastic.co/u/blunckr)\
**Replies:** 0\
**Last updated:** [February 14, 2025, 7:29pm UTC](https://discuss.elastic.co/t/strategy-for-rolling-restart-with-eck/374576 "2025-02-14T19:29:48Z")

</div>

Hello, I'm wondering what the proper strategy is for performing rolling restarts when running Elasticsearch in K8S with ECK? Before we ran in k8s, we followed this guide: Full-cluster restart and rolling restart | Elast…

---

## [How to run elasticsearch for local development after upgrading from 7.17 to 8.17](https://discuss.elastic.co/t/how-to-run-elasticsearch-for-local-development-after-upgrading-from-7-17-to-8-17/374562)

<div class="topic-metadata">

**Author:** [@mon4our](https://discuss.elastic.co/u/mon4our)\
**Replies:** 0\
**Last updated:** [February 14, 2025, 2:30pm UTC](https://discuss.elastic.co/t/how-to-run-elasticsearch-for-local-development-after-upgrading-from-7-17-to-8-17/374562 "2025-02-14T14:30:07Z")

</div>

I am currently upgrading my codebase from elasticsearch 7.17 to 8.17. I am using the elasticsearch python client. For 7.17 we used this code to create an elasticsearch instance: ES = elasticsearch.Elasticsearch( ('%…

---

## [JDBC for linux- adapter class not registered](https://discuss.elastic.co/t/jdbc-for-linux-adapter-class-not-registered/374430)

<div class="topic-metadata">

**Author:** [@JosephR](https://discuss.elastic.co/u/JosephR)\
**Replies:** 2\
**Last updated:** [February 14, 2025, 12:32pm UTC](https://discuss.elastic.co/t/jdbc-for-linux-adapter-class-not-registered/374430 "2025-02-14T12:32:57Z")

</div>

Hello I am having an issue when I go to run a conf file to connect to a mssql instance it is giving me the following error. {:message=\>"Could not load jdbc/mssql adapter: adapter class not registered in ADAPTER\_MAP", :e…

---

## [Elasticsearch license expired before the assigned expiry date](https://discuss.elastic.co/t/elasticsearch-license-expired-before-the-assigned-expiry-date/374548)

<div class="topic-metadata">

**Author:** [@ahsanraza](https://discuss.elastic.co/u/ahsanraza)\
**Replies:** 3\
**Last updated:** [February 14, 2025, 11:58am UTC](https://discuss.elastic.co/t/elasticsearch-license-expired-before-the-assigned-expiry-date/374548 "2025-02-14T11:58:35Z")

</div>

Hello, I had upgraded Elasticsearch license on 31st January 2025 through the end point POST /\_license/start\_trial?acknowledgement=true. With this, the license was upgraded from basic to trial. The validity of this licen…

---

## [Renew http\_ca.crt CA certificate of the elasticsearch cluster](https://discuss.elastic.co/t/renew-http-ca-crt-ca-certificate-of-the-elasticsearch-cluster/374526)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 1\
**Last updated:** [February 14, 2025, 11:30am UTC](https://discuss.elastic.co/t/renew-http-ca-crt-ca-certificate-of-the-elasticsearch-cluster/374526 "2025-02-14T11:30:41Z")

</div>

Hello, Can anyone help me understand on how to renew the http CA certificate for an autoconfigured on-prem cluster? This certificate was being used in the logstash's elasticsearch output section's cacert setting, howeve…

---

## [ES and LUN](https://discuss.elastic.co/t/es-and-lun/374544)

<div class="topic-metadata">

**Author:** [@Payal\_r](https://discuss.elastic.co/u/Payal_r)\
**Replies:** 3\
**Last updated:** [February 14, 2025, 9:45am UTC](https://discuss.elastic.co/t/es-and-lun/374544 "2025-02-14T09:45:56Z")

</div>

I have a 6 node cluster(6.8.5). I need to change the storage and therefore the LUN of my linux server for three nodes. I am thinking to follow the steps: 1- exclude these nodes and shift the shards to the other nodes. …

---

## [Problem installing the elasticsearch ingest processor plugin](https://discuss.elastic.co/t/problem-installing-the-elasticsearch-ingest-processor-plugin/374484)

<div class="topic-metadata">

**Author:** [@vsekap](https://discuss.elastic.co/u/vsekap)\
**Replies:** 1\
**Last updated:** [February 14, 2025, 2:44am UTC](https://discuss.elastic.co/t/problem-installing-the-elasticsearch-ingest-processor-plugin/374484 "2025-02-14T02:44:16Z")

</div>

Have a problem with plugin installation 8.14.3. Gradle Build tools used for compiling the java plugin project. Expected the output while installing the plugin: elasticsearch@9769694eb777:~$ bin/elasticsearch-plugin inst…

---

## [Curator 7.0.1 fails because of closed indices](https://discuss.elastic.co/t/curator-7-0-1-fails-because-of-closed-indices/373190)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 5\
**Last updated:** [February 14, 2025, 12:40am UTC](https://discuss.elastic.co/t/curator-7-0-1-fails-because-of-closed-indices/373190 "2025-02-14T00:40:30Z")

</div>

Elasticsearch version: 7.17.1 (yes, I know.) Curator version: 7.0.1 I find myself in the position of having to replace every server in our Elasticsearch cluster to replace them with ones running RHEL 9. As part of th…

---

## [Add nodes to a cluster ES 8.17.1; env RHEL 8.10](https://discuss.elastic.co/t/add-nodes-to-a-cluster-es-8-17-1-env-rhel-8-10/374529)

<div class="topic-metadata">

**Author:** [@latte123](https://discuss.elastic.co/u/latte123)\
**Replies:** 1\
**Last updated:** [February 14, 2025, 12:06am UTC](https://discuss.elastic.co/t/add-nodes-to-a-cluster-es-8-17-1-env-rhel-8-10/374529 "2025-02-14T00:06:15Z")

</div>

I built a cluster with two master nodes; two days later, the attempt to add another master node (all on different hosts) failed with error: ./elasticsearch-create-enrollment-token -s node Unable to create enrollment to…

---

## [Dealing with indexing large singular documents](https://discuss.elastic.co/t/dealing-with-indexing-large-singular-documents/374283)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 11\
**Last updated:** [February 13, 2025, 4:00pm UTC](https://discuss.elastic.co/t/dealing-with-indexing-large-singular-documents/374283 "2025-02-13T16:00:48Z")

</div>

Hello we are encountering issues with large documents in Elasticsearch, we index text extracted content from PDF/Word documents and then search on those in an enterprise search scenario. We are using Elastic Cloud which…

---

## [My Local machine does not recognize the elasticsearch certificate](https://discuss.elastic.co/t/my-local-machine-does-not-recognize-the-elasticsearch-certificate/374458)

<div class="topic-metadata">

**Author:** [@jeanne1](https://discuss.elastic.co/u/jeanne1)\
**Replies:** 2\
**Last updated:** [February 13, 2025, 3:18pm UTC](https://discuss.elastic.co/t/my-local-machine-does-not-recognize-the-elasticsearch-certificate/374458 "2025-02-13T15:18:17Z")

</div>

I setup an elasticsearch cluster on EC2 via docker. on EC2 terminal everything working well when I run: curl --cacert http\_ca.crt -u elastic:$Password https://localhost:9200 I got: { "name" : "21frt45422121f", "cluste…

---

## [Recommended version of Elasticsearch at this point](https://discuss.elastic.co/t/recommended-version-of-elasticsearch-at-this-point/374475)

<div class="topic-metadata">

**Author:** [@Iron](https://discuss.elastic.co/u/Iron)\
**Replies:** 4\
**Last updated:** [February 13, 2025, 1:46pm UTC](https://discuss.elastic.co/t/recommended-version-of-elasticsearch-at-this-point/374475 "2025-02-13T13:46:48Z")

</div>

I'm curious to know what the recommended version of Elasticsearch is at this point. And I want you to tell me why you recommend that version. Let's take a look at how to get an Elasticsearch update policy.

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=44)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=46)
