# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=48

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 49

---

## [Cisco switch integration](https://discuss.elastic.co/t/cisco-switch-integration/373440)

<div class="topic-metadata">

**Author:** [@amarasinghe.kaluarac](https://discuss.elastic.co/u/amarasinghe.kaluarac)\
**Replies:** 2\
**Last updated:** [February 3, 2025, 10:33am UTC](https://discuss.elastic.co/t/cisco-switch-integration/373440 "2025-02-03T10:33:05Z")

</div>

Hi, I have a need to integrate a Cisco Catalyst 3850 switch with my Elastic cluster, so as I was browsing through the integration, I didn't see any integration for a Catalyst switch. Could anyone help me with this? Tha…

---

## [Using reindex to generate embeddings from nested field](https://discuss.elastic.co/t/using-reindex-to-generate-embeddings-from-nested-field/373957)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [February 3, 2025, 10:03am UTC](https://discuss.elastic.co/t/using-reindex-to-generate-embeddings-from-nested-field/373957 "2025-02-03T10:03:41Z")

</div>

Hello! I was reading this: And I tried to apply the idea of using a reindex command together with an ingest pipeline to generate the embeddings of data already inside an elastic index. Now I defined the ingest pipeli…

---

## [Proxy in front of OIDC configuration Azure Entra App](https://discuss.elastic.co/t/proxy-in-front-of-oidc-configuration-azure-entra-app/373871)

<div class="topic-metadata">

**Author:** [@tdvo1996](https://discuss.elastic.co/u/tdvo1996)\
**Replies:** 1\
**Last updated:** [February 3, 2025, 4:39am UTC](https://discuss.elastic.co/t/proxy-in-front-of-oidc-configuration-azure-entra-app/373871 "2025-02-03T04:39:46Z")

</div>

Hi, We are running Elastic with an ECK Operator in Openshift. The namespace that Elastic is running on has strict network access in and out. Let's say we have an OIDC configuration with an Azure Entra App. Is it poss…

---

## [Huge segments (should I worry?)](https://discuss.elastic.co/t/huge-segments-should-i-worry/373879)

<div class="topic-metadata">

**Author:** [@teodor.zvezdov](https://discuss.elastic.co/u/teodor.zvezdov)\
**Replies:** 7\
**Last updated:** [February 2, 2025, 7:28pm UTC](https://discuss.elastic.co/t/huge-segments-should-i-worry/373879 "2025-02-02T19:28:45Z")

</div>

Hi, recently I have been tasked to maintain an existing ES cluster consisting of 3 nodes (3 data nodes). 12 GB heap per node. After observing the segments of the index "beneficiary2" I saw the following : 2 very big se…

---

## [Rate limit in elastic image pull?](https://discuss.elastic.co/t/rate-limit-in-elastic-image-pull/373733)

<div class="topic-metadata">

**Author:** [@Gopu](https://discuss.elastic.co/u/Gopu)\
**Replies:** 1\
**Last updated:** [February 1, 2025, 6:47pm UTC](https://discuss.elastic.co/t/rate-limit-in-elastic-image-pull/373733 "2025-02-01T18:47:29Z")

</div>

I am encountering an issue while trying to pull the docker.elastic.co/elasticsearch/elasticsearch:8.4.3 image in my Kubernetes cluster. The error I am seeing is: Failed to authorize: failed to fetch anonymous token: Get…

---

## [Counting agents in Dasboard](https://discuss.elastic.co/t/counting-agents-in-dasboard/373960)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 4\
**Last updated:** [January 31, 2025, 7:26pm UTC](https://discuss.elastic.co/t/counting-agents-in-dasboard/373960 "2025-01-31T19:26:36Z")

</div>

Hello everyone, I have a question, when I enter in the administration part in the “Fleet” option I get the list of agents and their status, in total it tells me that I have X amount of agents. I was asked to crea…

---

## [Using managed integration assets with different lifecycle policy/rollover alias](https://discuss.elastic.co/t/using-managed-integration-assets-with-different-lifecycle-policy-rollover-alias/373951)

<div class="topic-metadata">

**Author:** [@smashley](https://discuss.elastic.co/u/smashley)\
**Replies:** 0\
**Last updated:** [January 31, 2025, 2:28pm UTC](https://discuss.elastic.co/t/using-managed-integration-assets-with-different-lifecycle-policy-rollover-alias/373951 "2025-01-31T14:28:05Z")

</div>

I'm running ES 8.17.0 on basic subscription, ingesting logs from Cloudwatch. Note we are not using the Agent to pull these logs, but rather send them to \_bulk with a lambda function. We had been ingesting these to an in…

---

## [LinkedTransferQueue is blocking threads i dont know why this issue occurs](https://discuss.elastic.co/t/linkedtransferqueue-is-blocking-threads-i-dont-know-why-this-issue-occurs/373691)

<div class="topic-metadata">

**Author:** [@Mani\_Kandan](https://discuss.elastic.co/u/Mani_Kandan)\
**Replies:** 3\
**Last updated:** [January 31, 2025, 1:02pm UTC](https://discuss.elastic.co/t/linkedtransferqueue-is-blocking-threads-i-dont-know-why-this-issue-occurs/373691 "2025-01-31T13:02:47Z")

</div>

As i am new to Elasticsearch.In my server elasticsearch datanode is running and this has a issue of JAVA\_TOO\_MANY\_THREADS so in stack trace Stack Trace at jdk.internal.misc.Unsafe.park(java.base@17.0.13/Native Method) …

---

## [Java Elastic query not returning results](https://discuss.elastic.co/t/java-elastic-query-not-returning-results/373933)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 4\
**Last updated:** [January 31, 2025, 12:10pm UTC](https://discuss.elastic.co/t/java-elastic-query-not-returning-results/373933 "2025-01-31T12:10:44Z")

</div>

I have an application which uses java HLRC client fetching results from Elasticsearch cluster. I am facing a peculiar problem in which I am not able to get certain results from Java client side. But the catch is when i a…

---

## [Apm server configuration](https://discuss.elastic.co/t/apm-server-configuration/373925)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [January 31, 2025, 9:14am UTC](https://discuss.elastic.co/t/apm-server-configuration/373925 "2025-01-31T09:14:18Z")

</div>

Hi Team! I understand apm server has to be private. I can place it behind a nginx load balancer. How do I ensure my apm server is secure. If I go to dev tools on my webpage, I can see the request to apm endpoint. what …

---

## [Elasticsearch build Unable to tunnel through proxy](https://discuss.elastic.co/t/elasticsearch-build-unable-to-tunnel-through-proxy/373844)

<div class="topic-metadata">

**Author:** [@Thomas\_Varley](https://discuss.elastic.co/u/Thomas_Varley)\
**Replies:** 1\
**Last updated:** [January 31, 2025, 8:07am UTC](https://discuss.elastic.co/t/elasticsearch-build-unable-to-tunnel-through-proxy/373844 "2025-01-31T08:07:55Z")

</div>

Hi, we are building elasticsearch v8.13.4 using an internal maven repository. During the build process we are seeing this error: java.io.IOException: Unable to tunnel through proxy. Proxy returns "HTTP/1.1 403 Forbidden …

---

## [\[8.x\] \[8.17.1\] Confidential Computing Elastic native system call filters](https://discuss.elastic.co/t/8-x-8-17-1-confidential-computing-elastic-native-system-call-filters/373924)

<div class="topic-metadata">

**Author:** [@nmwael](https://discuss.elastic.co/u/nmwael)\
**Replies:** 0\
**Last updated:** [January 31, 2025, 8:08am UTC](https://discuss.elastic.co/t/8-x-8-17-1-confidential-computing-elastic-native-system-call-filters/373924 "2025-01-31T08:08:46Z")

</div>

I am looking into securing and guarding Elastic search with Intel SGX hardware and a middleware called Gramine which are utilized as an libos. End goal are to protect Elastic against attackers that might do memory dumps,…

---

## [Assume Role snapshot S3](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848)

<div class="topic-metadata">

**Author:** [@suarna](https://discuss.elastic.co/u/suarna)\
**Replies:** 7\
**Last updated:** [January 30, 2025, 4:47pm UTC](https://discuss.elastic.co/t/assume-role-snapshot-s3/373848 "2025-01-30T16:47:30Z")

</div>

Hi everybody, How is it going? Let's see if someone can help me with this. Sorry if the question is trivial (I am new in using elasticsearch) I have a question regarding the use of the s3 repository plugin in order to…

---

## [Master node recommendation](https://discuss.elastic.co/t/master-node-recommendation/373881)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [January 30, 2025, 4:36pm UTC](https://discuss.elastic.co/t/master-node-recommendation/373881 "2025-01-30T16:36:28Z")

</div>

If I configure 2 nodes as hot and 2 nodes as warm in my on prem deployment, can 3 out of 4 of these nodes be a master? (instead of having to configure separate master nodes?) If yes, is it okay 2 of the master nodes are…

---

## [Query\_string with wildcard not working as expected (or wrong understanging of analyze\_wildcard)](https://discuss.elastic.co/t/query-string-with-wildcard-not-working-as-expected-or-wrong-understanging-of-analyze-wildcard/371910)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 12\
**Last updated:** [January 30, 2025, 1:21pm UTC](https://discuss.elastic.co/t/query-string-with-wildcard-not-working-as-expected-or-wrong-understanging-of-analyze-wildcard/371910 "2025-01-30T13:21:03Z")

</div>

Hi I am wondering why the following query does not hit. Here is the reproducer: // put index PUT /test { "mappings" : { "properties" : { "title": { "type": "text", "analyzer": "german…

---

## [Storage to RAM](https://discuss.elastic.co/t/storage-to-ram/373888)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [January 30, 2025, 11:22am UTC](https://discuss.elastic.co/t/storage-to-ram/373888 "2025-01-30T11:22:33Z")

</div>

From the pricing calculator, I see elastic recommends 1 GB RAM for 30 GB storage (hot data). for my on prem set up, is it okay if I have 2 data nodes with 5 TB of data each? If I follow the 1:30 rule, number of data no…

---

## [Is it correct to response to HEAD req from elastic API with empty "transfer-encoding: chunked"?](https://discuss.elastic.co/t/is-it-correct-to-response-to-head-req-from-elastic-api-with-empty-transfer-encoding-chunked/372941)

<div class="topic-metadata">

**Author:** [@pencakj](https://discuss.elastic.co/u/pencakj)\
**Replies:** 14\
**Last updated:** [January 30, 2025, 8:07am UTC](https://discuss.elastic.co/t/is-it-correct-to-response-to-head-req-from-elastic-api-with-empty-transfer-encoding-chunked/372941 "2025-01-30T08:07:24Z")

</div>

Hello, we're troubleshooting issue in communication between client and elastic 8.13 in between with HAProxy. Is it correct to response to HEAD request with EMPTY "transfer-encoding: chunked"? In other words - to HEAD re…

---

## [Flattened fields and \`query\_string\` queries with leading wildcard](https://discuss.elastic.co/t/flattened-fields-and-query-string-queries-with-leading-wildcard/373576)

<div class="topic-metadata">

**Author:** [@ddittmar](https://discuss.elastic.co/u/ddittmar)\
**Replies:** 3\
**Last updated:** [January 30, 2025, 7:14am UTC](https://discuss.elastic.co/t/flattened-fields-and-query-string-queries-with-leading-wildcard/373576 "2025-01-30T07:14:03Z")

</div>

Hi, I'm seeing unexpected behaviors with flattened fields and query\_string queries with leading wildcard. I'm new to Elasticsearch so maybe someone could help me out. I'm using 8.15.2 but I see the same behavior on 8.17…

---

## [Wrong positionLength using output\_unigrams=false](https://discuss.elastic.co/t/wrong-positionlength-using-output-unigrams-false/373870)

<div class="topic-metadata">

**Author:** [@alexander.korkhov](https://discuss.elastic.co/u/alexander.korkhov)\
**Replies:** 0\
**Last updated:** [January 30, 2025, 6:23am UTC](https://discuss.elastic.co/t/wrong-positionlength-using-output-unigrams-false/373870 "2025-01-30T06:23:12Z")

</div>

For example, I have next settings: PUT test\_search\_05 { "settings": { "analysis": { "analyzer": { "shingle": { "tokenizer": "standard", "filter": \[ "my\_shingle\_filter" \] }…

---

## [\[elastic\_agent.metricbeat\]\[info\] CA certificate matching 'ca\_trusted\_fingerprint' found, adding it to 'certificate\_authorities'](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418)

<div class="topic-metadata">

**Author:** [@otortosa](https://discuss.elastic.co/u/otortosa)\
**Replies:** 7\
**Last updated:** [January 30, 2025, 12:49am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-info-ca-certificate-matching-ca-trusted-fingerprint-found-adding-it-to-certificate-authorities/358418 "2025-01-30T00:49:20Z")

</div>

Hello team! I receive from my Ubuntu host these logs all the time. \[elastic\_agent.metricbeat\]\[info\] CA certificate matching 'ca\_trusted\_fingerprint' found, adding it to 'certificate\_authorities' \[elastic\_agent.metricb…

---

## [Unable to delete index, unable to mark it as read-only false](https://discuss.elastic.co/t/unable-to-delete-index-unable-to-mark-it-as-read-only-false/373857)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [January 29, 2025, 10:12pm UTC](https://discuss.elastic.co/t/unable-to-delete-index-unable-to-mark-it-as-read-only-false/373857 "2025-01-29T22:12:31Z")

</div>

I tried following the solution here But in my case running PUT my\_index/\_settings { "settings": { "index.blocks.read-only": false } } yields FORBIDDEN/5/index read-only (api) So I am in a catch 22 situation wh…

---

## [WATCHER SCRIPTS](https://discuss.elastic.co/t/watcher-scripts/373850)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [January 29, 2025, 4:43pm UTC](https://discuss.elastic.co/t/watcher-scripts/373850 "2025-01-29T16:43:22Z")

</div>

TOMCAT ALERT COUNT PUT \_watcher/watch/tomcat\_error\_count\_alerts { "trigger": { "schedule": { "interval": "1h" } }, "input": { "search": { "request": { "search\_type": "query\_then\_fet…

---

## [Vectorised search in ES returning different result if i am changing the result size](https://discuss.elastic.co/t/vectorised-search-in-es-returning-different-result-if-i-am-changing-the-result-size/373715)

<div class="topic-metadata">

**Author:** [@Gaurav\_Duseja](https://discuss.elastic.co/u/Gaurav_Duseja)\
**Replies:** 5\
**Last updated:** [January 29, 2025, 4:04pm UTC](https://discuss.elastic.co/t/vectorised-search-in-es-returning-different-result-if-i-am-changing-the-result-size/373715 "2025-01-29T16:04:26Z")

</div>

my query looks like this - below i am passing the size as well and if i am changing the size from 30 to 300 i am seeing completely different results. { "query": { "bool": { …

---

## [Upgrading to 8.15 got Bad certificate error](https://discuss.elastic.co/t/upgrading-to-8-15-got-bad-certificate-error/373748)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 5\
**Last updated:** [January 29, 2025, 3:42pm UTC](https://discuss.elastic.co/t/upgrading-to-8-15-got-bad-certificate-error/373748 "2025-01-29T15:42:16Z")

</div>

I am tring to upgrade Elasticsearch from 7.17 to 8.15. I've got a bad certificate error . Caused by: javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate Here is my ssl setting in elasticsearch.ym…

---

## [Elasticsearch input size not working](https://discuss.elastic.co/t/elasticsearch-input-size-not-working/373818)

<div class="topic-metadata">

**Author:** [@Amit\_Saini](https://discuss.elastic.co/u/Amit_Saini)\
**Replies:** 0\
**Last updated:** [January 29, 2025, 12:23pm UTC](https://discuss.elastic.co/t/elasticsearch-input-size-not-working/373818 "2025-01-29T12:23:48Z")

</div>

Hi Team, I'm working on an incremental data pipeline using Logstash. I'm using the Elasticsearch input plugin to retrieve the last processed document from an index. I intend to store the relevant field from this documen…

---

## [Need to send query in my data view on 2 separate document](https://discuss.elastic.co/t/need-to-send-query-in-my-data-view-on-2-separate-document/373792)

<div class="topic-metadata">

**Author:** [@ermisma](https://discuss.elastic.co/u/ermisma)\
**Replies:** 3\
**Last updated:** [January 29, 2025, 10:05am UTC](https://discuss.elastic.co/t/need-to-send-query-in-my-data-view-on-2-separate-document/373792 "2025-01-29T10:05:45Z")

</div>

Hi, I’m working with a Dataview where I’m querying to extract specific information from raw data for my use case. The issue I’m facing is that I have multiple documents, and some of the fields I need to query are not in…

---

## [Painless script outputs literal "key" field](https://discuss.elastic.co/t/painless-script-outputs-literal-key-field/373800)

<div class="topic-metadata">

**Author:** [@Henning\_Oden](https://discuss.elastic.co/u/Henning_Oden)\
**Replies:** 0\
**Last updated:** [January 29, 2025, 8:03am UTC](https://discuss.elastic.co/t/painless-script-outputs-literal-key-field/373800 "2025-01-29T08:03:48Z")

</div>

I have a Painless script I run in a Script processor in an Ingest Pipeline which moves fields from within a temporary jsonPayload field to the document root. The source looks like this (field names redacted for safety): …

---

## [If FSCrawler stops mid-scan, will it restart from scratch?](https://discuss.elastic.co/t/if-fscrawler-stops-mid-scan-will-it-restart-from-scratch/373787)

<div class="topic-metadata">

**Author:** [@syoo](https://discuss.elastic.co/u/syoo)\
**Replies:** 3\
**Last updated:** [January 29, 2025, 1:15am UTC](https://discuss.elastic.co/t/if-fscrawler-stops-mid-scan-will-it-restart-from-scratch/373787 "2025-01-29T01:15:27Z")

</div>

As a newcomer to Elasticsearch, I want to index a large filesystem (100TB) with FSCrawler. I’ve heard that if the initial scan is interrupted, FSCrawler might re-scan everything from the beginning. What’s the best stra…

---

## [Storage in Frozen nodes on Elastic Cloud](https://discuss.elastic.co/t/storage-in-frozen-nodes-on-elastic-cloud/373770)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [January 28, 2025, 3:22pm UTC](https://discuss.elastic.co/t/storage-in-frozen-nodes-on-elastic-cloud/373770 "2025-01-28T15:22:57Z")

</div>

Hi, Can anyone clarify what the storage of Frozen nodes on Elastic Cloud refers to? Is it the local storage of the node itself, or does it represent the storage used by the repository for searchable snapshots (e.g., S3)…

---

## [Webhook Body for Machine Learning Alerts](https://discuss.elastic.co/t/webhook-body-for-machine-learning-alerts/373416)

<div class="topic-metadata">

**Author:** [@catarina](https://discuss.elastic.co/u/catarina)\
**Replies:** 2\
**Last updated:** [January 28, 2025, 3:04pm UTC](https://discuss.elastic.co/t/webhook-body-for-machine-learning-alerts/373416 "2025-01-28T15:04:33Z")

</div>

Hello Elastic Community, I’ve set up an advanced Machine Learning job to detect anomalies in user logins, with 6 detectors focusing on unusual source.ip, country, hostname, hour, and time of the week per user. I create…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=47)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=49)
