# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=5

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 6

---

## [High sustained read traffic from Elasticsearch hot pods](https://discuss.elastic.co/t/high-sustained-read-traffic-from-elasticsearch-hot-pods/385508)

<div class="topic-metadata">

**Author:** [@cjpowers](https://discuss.elastic.co/u/cjpowers)\
**Replies:** 16\
**Last updated:** [April 14, 2026, 1:40pm UTC](https://discuss.elastic.co/t/high-sustained-read-traffic-from-elasticsearch-hot-pods/385508 "2026-04-14T13:40:32Z")

</div>

I’m running an EFK stack in an RKE2 cluster on RHEL 8.5. The VMs are hosted in vSphere and use centralized NetApp storage. Our Elasticsearch footprint currently looks like this: 2 master nodes 2 client nodes 2 hot da…

---

## [Advice on snapshot and restore setup for elasticsearch DR scenario](https://discuss.elastic.co/t/advice-on-snapshot-and-restore-setup-for-elasticsearch-dr-scenario/385873)

<div class="topic-metadata">

**Author:** [@fffasttFGHb3t](https://discuss.elastic.co/u/fffasttFGHb3t)\
**Replies:** 1\
**Last updated:** [April 13, 2026, 6:55pm UTC](https://discuss.elastic.co/t/advice-on-snapshot-and-restore-setup-for-elasticsearch-dr-scenario/385873 "2026-04-13T18:55:09Z")

</div>

We currently have an elasticsearch cluster deployed on-prem kubernetes with the elastic operator. Our main goals are exactly as described in the documentation: Regularly back up a cluster with no downtime Recover data…

---

## [Sythetics icmp down alert received but host and agent had been unenrolled!](https://discuss.elastic.co/t/sythetics-icmp-down-alert-received-but-host-and-agent-had-been-unenrolled/385866)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 6\
**Last updated:** [April 13, 2026, 9:20am UTC](https://discuss.elastic.co/t/sythetics-icmp-down-alert-received-but-host-and-agent-had-been-unenrolled/385866 "2026-04-13T09:20:44Z")

</div>

host had been decommissioned. agent had been unrolled weeks back BUT still getting sythetics icmp down alert today. Kindly assist!

---

## [Virtual Machines or Containers?](https://discuss.elastic.co/t/virtual-machines-or-containers/385765)

<div class="topic-metadata">

**Author:** [@saba\_kallel](https://discuss.elastic.co/u/saba_kallel)\
**Replies:** 4\
**Last updated:** [April 10, 2026, 1:13pm UTC](https://discuss.elastic.co/t/virtual-machines-or-containers/385765 "2026-04-10T13:13:29Z")

</div>

Hello everyone, I am currently working on my final-year project, which focuses on designing and automating the deployment of a highly available and fault-tolerant ELK stack (Elasticsearch, Logstash, Kibana). The goal o…

---

## [Unable to search data in fields](https://discuss.elastic.co/t/unable-to-search-data-in-fields/385824)

<div class="topic-metadata">

**Author:** [@s1ackspace](https://discuss.elastic.co/u/s1ackspace)\
**Replies:** 4\
**Last updated:** [April 9, 2026, 11:19am UTC](https://discuss.elastic.co/t/unable-to-search-data-in-fields/385824 "2026-04-09T11:19:08Z")

</div>

Hi, I have data in indice parsed with custom pipeline. After reindex that indice i can’t make aggregations (in discover module i see only empty fields) and visualizations from that data however data are still searchable…

---

## [GUI \>\> Cluster \>\> Logstash \>\> Nodes (no nodes displayed)](https://discuss.elastic.co/t/gui-cluster-logstash-nodes-no-nodes-displayed/385739)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 6\
**Last updated:** [April 9, 2026, 5:50am UTC](https://discuss.elastic.co/t/gui-cluster-logstash-nodes-no-nodes-displayed/385739 "2026-04-09T05:50:33Z")

</div>

When we click on Nodes under the Logstash section. Nothing is displayed!!

---

## [When 8.19.14 will be released? Being hitting hard by #144748](https://discuss.elastic.co/t/when-8-19-14-will-be-released-being-hitting-hard-by-144748/385798)

<div class="topic-metadata">

**Author:** [@carlosmg1](https://discuss.elastic.co/u/carlosmg1)\
**Replies:** 4\
**Last updated:** [April 8, 2026, 4:45pm UTC](https://discuss.elastic.co/t/when-8-19-14-will-be-released-being-hitting-hard-by-144748/385798 "2026-04-08T16:45:42Z")

</div>

Hi, we upgraded to 8.19.13, just to discover we’re having a lot of problems because mentioned issue related to percolate queries. i’ve seen the release note for the 8.19.14 is already up, but no release itself (btw, we …

---

## [I have ES on a 5 Windows machines](https://discuss.elastic.co/t/i-have-es-on-a-5-windows-machines/385781)

<div class="topic-metadata">

**Author:** [@stanimir\_kirilov](https://discuss.elastic.co/u/stanimir_kirilov)\
**Replies:** 1\
**Last updated:** [April 8, 2026, 4:07pm UTC](https://discuss.elastic.co/t/i-have-es-on-a-5-windows-machines/385781 "2026-04-08T16:07:42Z")

</div>

Hello, I’m running Elasticsearch on five Windows virtual machines, and applying Windows updates to them is extremely time‑consuming.Each time I have to stop the shard allocation then proceed with the Windows updates, mak…

---

## [Unable to register secondary azure snapshot repo. Elasticsearch says client not found](https://discuss.elastic.co/t/unable-to-register-secondary-azure-snapshot-repo-elasticsearch-says-client-not-found/385806)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 1\
**Last updated:** [April 7, 2026, 7:44pm UTC](https://discuss.elastic.co/t/unable-to-register-secondary-azure-snapshot-repo-elasticsearch-says-client-not-found/385806 "2026-04-07T19:44:04Z")

</div>

I’m trying to add a secondary snapshot repo repo to a cluster to migrate data. I’ve added the account info and key into the elasticsearch keystore, you can see them here: elasticsearch-keystore list azure.client.defau…

---

## [Real cluster state size](https://discuss.elastic.co/t/real-cluster-state-size/385796)

<div class="topic-metadata">

**Author:** [@Nicko](https://discuss.elastic.co/u/Nicko)\
**Replies:** 7\
**Last updated:** [April 7, 2026, 1:54pm UTC](https://discuss.elastic.co/t/real-cluster-state-size/385796 "2026-04-07T13:54:56Z")

</div>

When I try to get the cluster state size via GET \_nodes/stats in kibana dev tools it gives me this data from the node, which is holding cluster state now "serialized\_cluster\_states": { "full\_states": { "count": 77…

---

## [Is querying elasticsearch directly from NextJS server-side a bad pattern?](https://discuss.elastic.co/t/is-querying-elasticsearch-directly-from-nextjs-server-side-a-bad-pattern/385747)

<div class="topic-metadata">

**Author:** [@harwin36548](https://discuss.elastic.co/u/harwin36548)\
**Replies:** 1\
**Last updated:** [April 7, 2026, 1:44pm UTC](https://discuss.elastic.co/t/is-querying-elasticsearch-directly-from-nextjs-server-side-a-bad-pattern/385747 "2026-04-07T13:44:29Z")

</div>

Hi everyone, I’m building a Next.js app (App Router) and trying to decide on the right way to integrate Elasticsearch. I know Next.js allows direct server-side data access without needing an API layer, which makes this…

---

## [Cluster logs for errors in GUI (via filter) if not whatst the specific index to search](https://discuss.elastic.co/t/cluster-logs-for-errors-in-gui-via-filter-if-not-whatst-the-specific-index-to-search/385738)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 3\
**Last updated:** [April 7, 2026, 10:46am UTC](https://discuss.elastic.co/t/cluster-logs-for-errors-in-gui-via-filter-if-not-whatst-the-specific-index-to-search/385738 "2026-04-07T10:46:11Z")

</div>

This morning we were having slowness on our web console. From the cluster overview page. There were many high CPU for nodes. https://XXXXXXXXX.aws.found.io/app/monitoring#/overview? When we zoom it we found that they …

---

## [Elasticsearch query timeouts on data stream (50M–170M docs, facets + NOT queries)](https://discuss.elastic.co/t/elasticsearch-query-timeouts-on-data-stream-50m-170m-docs-facets-not-queries/384646)

<div class="topic-metadata">

**Author:** [@Anup\_Kumar](https://discuss.elastic.co/u/Anup_Kumar)\
**Replies:** 4\
**Last updated:** [April 2, 2026, 10:04am UTC](https://discuss.elastic.co/t/elasticsearch-query-timeouts-on-data-stream-50m-170m-docs-facets-not-queries/384646 "2026-04-02T10:04:40Z")

</div>

Hi all, I’m facing Elasticsearch query timeouts for a search workload stored in a data stream (immutable data, bulk indexed historical data). We are using Point-in-Time (PIT) searches for query consistency/pagination. B…

---

## [Attempting to match or filter but still always return all values](https://discuss.elastic.co/t/attempting-to-match-or-filter-but-still-always-return-all-values/385708)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 8\
**Last updated:** [April 2, 2026, 9:13am UTC](https://discuss.elastic.co/t/attempting-to-match-or-filter-but-still-always-return-all-values/385708 "2026-04-02T09:13:12Z")

</div>

Can anyone share a working example of how to match or filter a field based on existing data? I have attempted the following query but it still returns all values. Also whats the difference between match and filter? Thank…

---

## [ILM Indices Blocking Master Queue - All Operations Timeout](https://discuss.elastic.co/t/ilm-indices-blocking-master-queue-all-operations-timeout/385725)

<div class="topic-metadata">

**Author:** [@Anup\_Kumar](https://discuss.elastic.co/u/Anup_Kumar)\
**Replies:** 5\
**Last updated:** [April 2, 2026, 8:40am UTC](https://discuss.elastic.co/t/ilm-indices-blocking-master-queue-all-operations-timeout/385725 "2026-04-02T08:40:02Z")

</div>

Our ES cluster has blocked master queue for 12+ days. All cluster state change operations timeout after 30s, including: Index open operations Index delete operations ILM move commands ILM stop/start commands …

---

## [Best practice for re-routed datastream and index template mappings](https://discuss.elastic.co/t/best-practice-for-re-routed-datastream-and-index-template-mappings/385729)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [April 1, 2026, 5:26pm UTC](https://discuss.elastic.co/t/best-practice-for-re-routed-datastream-and-index-template-mappings/385729 "2026-04-01T17:26:03Z")

</div>

Hi community, I'm wondering what is the best practice when it comes to rerouted datastreams from log integrations using fleet. For example default datastream is logs-docker.container\_logs-default and it's rerouted to lo…

---

## [Http port 9200 behind Citrix ADC loadbalancing](https://discuss.elastic.co/t/http-port-9200-behind-citrix-adc-loadbalancing/385721)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 12\
**Last updated:** [April 1, 2026, 5:18pm UTC](https://discuss.elastic.co/t/http-port-9200-behind-citrix-adc-loadbalancing/385721 "2026-04-01T17:18:34Z")

</div>

Trying desperately to avoid our Citrix ADC health monitoring of elasticsearch https port 9200 backend services from seeing LB monitoring traffic as plain text and thus avoid log error events like: received plaintext htt…

---

## [Unique vs Multiple dense vectors](https://discuss.elastic.co/t/unique-vs-multiple-dense-vectors/385710)

<div class="topic-metadata">

**Author:** [@cilasmarques](https://discuss.elastic.co/u/cilasmarques)\
**Replies:** 1\
**Last updated:** [April 1, 2026, 12:58am UTC](https://discuss.elastic.co/t/unique-vs-multiple-dense-vectors/385710 "2026-04-01T00:58:30Z")

</div>

Hi there! I'm adding semantic search to my site's search functionality. I use Elasticsearch and my index is structured as follows: "title":{ "type":"text", "analyzer":"general\_analyzer", "fields": { "spell"…

---

## [Error: entity content is too long \[105072697\] for the configured buffer limit \[104857600\]](https://discuss.elastic.co/t/error-entity-content-is-too-long-105072697-for-the-configured-buffer-limit-104857600/385636)

<div class="topic-metadata">

**Author:** [@Chen\_Wen](https://discuss.elastic.co/u/Chen_Wen)\
**Replies:** 16\
**Last updated:** [March 31, 2026, 8:49am UTC](https://discuss.elastic.co/t/error-entity-content-is-too-long-105072697-for-the-configured-buffer-limit-104857600/385636 "2026-03-31T08:49:15Z")

</div>

When I query data from ES8.2.3 with a big size in one req that the index docs are more than 10K and got en error Error: entity content is too long \[105072697\] for the configured buffer limit \[104857600\]. After search th…

---

## [Looking for Alert rule dataview and index](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 7\
**Last updated:** [March 30, 2026, 1:30pm UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650 "2026-03-30T13:30:39Z")

</div>

Using the API we can get the index of the alert that it is being used curl --request GET 'https://localhost:5601/api/alerting/rules/\_find' \\ If I want to use a query which default dataview or default index for all al…

---

## [ML jobs has no warnings or errors but message seems to be lagging](https://discuss.elastic.co/t/ml-jobs-has-no-warnings-or-errors-but-message-seems-to-be-lagging/385542)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 6\
**Last updated:** [March 30, 2026, 5:55am UTC](https://discuss.elastic.co/t/ml-jobs-has-no-warnings-or-errors-but-message-seems-to-be-lagging/385542 "2026-03-30T05:55:08Z")

</div>

In one of our ML jobs. There doesnt appears to be any errors or warning in the job message. However the latest\_record\_timestamp is lagging behind the current\_timestamp KIndly advice how we can further look into this. …

---

## [Query for top xx usage elasticsearch nodes](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 7\
**Last updated:** [March 29, 2026, 2:14pm UTC](https://discuss.elastic.co/t/query-for-top-xx-usage-elasticsearch-nodes/385581 "2026-03-29T14:14:30Z")

</div>

Trying to create a query for my cluster elasticsearch nodes. I want it to show nodes that is more than xx% of cpu or memory or JVM heap or free space left in % Not sure if I have selected the correct field for CPU , j…

---

## [Run Elasticsearch Docker 9.x on CPU without x86-64-v2 support?](https://discuss.elastic.co/t/run-elasticsearch-docker-9-x-on-cpu-without-x86-64-v2-support/385212)

<div class="topic-metadata">

**Author:** [@greenwoodma](https://discuss.elastic.co/u/greenwoodma)\
**Replies:** 1\
**Last updated:** [March 27, 2026, 2:32pm UTC](https://discuss.elastic.co/t/run-elasticsearch-docker-9-x-on-cpu-without-x86-64-v2-support/385212 "2026-03-27T14:32:01Z")

</div>

Is it at all possible to run the Elasticsearch 9.x docker containers on a machine with a CPU which doesn’t support x86-64-v2? The 8.x releases all ran fine on the machine but the new ones don’t start up as they just repo…

---

## [Architecture Validation: Backing up ES Clusters to Local Disk without NAS (using S3 Gateway sidecar)](https://discuss.elastic.co/t/architecture-validation-backing-up-es-clusters-to-local-disk-without-nas-using-s3-gateway-sidecar/384020)

<div class="topic-metadata">

**Author:** [@Maciek\_Pilawski](https://discuss.elastic.co/u/Maciek_Pilawski)\
**Replies:** 7\
**Last updated:** [March 27, 2026, 6:24am UTC](https://discuss.elastic.co/t/architecture-validation-backing-up-es-clusters-to-local-disk-without-nas-using-s3-gateway-sidecar/384020 "2026-03-27T06:24:48Z")

</div>

The Context I am a C++ developer working on an on-premise Visual Analytics application. Our service (DocumentStore) manages an Elasticsearch cluster (handling logs, events, configuration). We need to implement a Backup & …

---

## [Compatibility of Java Low Level REST Client 8.3.0 with ES 5.x and ES 7.x](https://discuss.elastic.co/t/compatibility-of-java-low-level-rest-client-8-3-0-with-es-5-x-and-es-7-x/385639)

<div class="topic-metadata">

**Author:** [@hxx](https://discuss.elastic.co/u/hxx)\
**Replies:** 0\
**Last updated:** [March 26, 2026, 4:28pm UTC](https://discuss.elastic.co/t/compatibility-of-java-low-level-rest-client-8-3-0-with-es-5-x-and-es-7-x/385639 "2026-03-26T16:28:30Z")

</div>

Hi, We're upgrading the Elasticsearch Java Low Level REST Client from 6.2.4 to 8.3.0, and we need to continue accessing both ES 5.x and ES 7.x clusters (cluster upgrades are not on the table for now). Since we're using…

---

## [Query DSL alert configuration](https://discuss.elastic.co/t/query-dsl-alert-configuration/385538)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 4\
**Last updated:** [March 26, 2026, 4:04am UTC](https://discuss.elastic.co/t/query-dsl-alert-configuration/385538 "2026-03-26T04:04:44Z")

</div>

I am trying to use the Elasticsearch Query DSL to create an alert The query consist of LIMIT 100 but the actual output is actually less than 10. When I did run the test query . Query matched 852597 documents in the las…

---

## [Elastic AI: Preconfigured LLM models data exposure](https://discuss.elastic.co/t/elastic-ai-preconfigured-llm-models-data-exposure/385605)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [March 25, 2026, 12:57pm UTC](https://discuss.elastic.co/t/elastic-ai-preconfigured-llm-models-data-exposure/385605 "2026-03-25T12:57:07Z")

</div>

Hi Team, We are currently exploring the AI Assistant feature in our ELK stack (version 9.3.1) and plan to use the preconfigured LLM model connectors. We would like to understand whether using these preconfigured LLM mo…

---

## [Backup deployment during upgrade](https://discuss.elastic.co/t/backup-deployment-during-upgrade/385591)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 0\
**Last updated:** [March 24, 2026, 10:33am UTC](https://discuss.elastic.co/t/backup-deployment-during-upgrade/385591 "2026-03-24T10:33:29Z")

</div>

We are using ech for ecommerce search application. We are planning to upgrade from 8.9.0 to 8.19.x. Before upgrading, should we already create the backup deployment with latest snapshot, or is it possible to create a ne…

---

## [Does .ml shared and custom falls under system indices](https://discuss.elastic.co/t/does-ml-shared-and-custom-falls-under-system-indices/385547)

<div class="topic-metadata">

**Author:** [@residual-07](https://discuss.elastic.co/u/residual-07)\
**Replies:** 1\
**Last updated:** [March 20, 2026, 1:08pm UTC](https://discuss.elastic.co/t/does-ml-shared-and-custom-falls-under-system-indices/385547 "2026-03-20T13:08:06Z")

</div>

Hi, I would like to get some help about understanding hidden and system indices. In our company we are using elasticsearch and kibana 8.19.9. We ended up in dilemma whether the .ml-anomalies-custom and .ml-anomalies-sh…

---

## [Cluster keeps getting into yellow state and hitting throttled for initializing shards (max rebalance)](https://discuss.elastic.co/t/cluster-keeps-getting-into-yellow-state-and-hitting-throttled-for-initializing-shards-max-rebalance/385392)

<div class="topic-metadata">

**Author:** [@carlosmg1](https://discuss.elastic.co/u/carlosmg1)\
**Replies:** 8\
**Last updated:** [March 20, 2026, 12:26pm UTC](https://discuss.elastic.co/t/cluster-keeps-getting-into-yellow-state-and-hitting-throttled-for-initializing-shards-max-rebalance/385392 "2026-03-20T12:26:40Z")

</div>

Hi, we have a cluster with this info: { "status": "yellow", "timed\_out": false, "number\_of\_nodes": 59, "number\_of\_data\_nodes": 54, "active\_primary\_shards": 6205, "active\_shards": 12409, "relocating\_shards": 7, …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=4)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=6)
