# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=50

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 51

---

## [APP connect logs are not properly offload into elk](https://discuss.elastic.co/t/app-connect-logs-are-not-properly-offload-into-elk/372973)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 2\
**Last updated:** [January 23, 2025, 8:59am UTC](https://discuss.elastic.co/t/app-connect-logs-are-not-properly-offload-into-elk/372973 "2025-01-23T08:59:52Z")

</div>

We are encountering issues where response and outbound blocks are not being captured into ELK logs. Upon investigation, it appears that the root cause is related to heterogeneous data types in the adjacent structure. Spe…

---

## [Json Array Problem](https://discuss.elastic.co/t/json-array-problem/373561)

<div class="topic-metadata">

**Author:** [@pcglr](https://discuss.elastic.co/u/pcglr)\
**Replies:** 0\
**Last updated:** [January 23, 2025, 8:52am UTC](https://discuss.elastic.co/t/json-array-problem/373561 "2025-01-23T08:52:16Z")

</div>

Hi everyone, The sample log I sent to Elastic is below. Although the value of a ‘Statement’ field is null, when I assign ‘key’ as a row in the dashboard, it shows the value of another Statement field instead of showing…

---

## [How can i add count of no. of requests (Throughput) in kibana dashboard with count graph?](https://discuss.elastic.co/t/how-can-i-add-count-of-no-of-requests-throughput-in-kibana-dashboard-with-count-graph/373384)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 0\
**Last updated:** [January 20, 2025, 7:57am UTC](https://discuss.elastic.co/t/how-can-i-add-count-of-no-of-requests-throughput-in-kibana-dashboard-with-count-graph/373384 "2025-01-20T07:57:58Z")

</div>

Hi all, how can i add total count of no. of requests (Throughput) of http api in kibana(v 7.17.1) graph dashboard with count ? Obervability-\>APM-services-\>service\_name-\>transactions. currently i am using free version.…

---

## [Problem installing Elasticsearch](https://discuss.elastic.co/t/problem-installing-elasticsearch/373525)

<div class="topic-metadata">

**Author:** [@ktotsuka](https://discuss.elastic.co/u/ktotsuka)\
**Replies:** 6\
**Last updated:** [January 22, 2025, 8:59pm UTC](https://discuss.elastic.co/t/problem-installing-elasticsearch/373525 "2025-01-22T20:59:53Z")

</div>

I'm trying to install Elasticsearch, but the script is failing. I'm using Windows 11 Enterprise. Downloaded the installer (elasticsearch-8.17.1-windows-x86\_64.zip) from Download Elasticsearch | Elastic Unzip the zip f…

---

## [Aggregation with Concatenation](https://discuss.elastic.co/t/aggregation-with-concatenation/373526)

<div class="topic-metadata">

**Author:** [@kdwolf](https://discuss.elastic.co/u/kdwolf)\
**Replies:** 0\
**Last updated:** [January 22, 2025, 4:34pm UTC](https://discuss.elastic.co/t/aggregation-with-concatenation/373526 "2025-01-22T16:34:42Z")

</div>

I have an index (see below) which stores RTT (Realtime Text) - every time someone types a letter within a conversation, it is stored as a document as a "typed" event. If someone deletes the letter, it will be stored as a…

---

## [Issue with Elasticsearch Docker Deployment on Apple Silicon (M4 Processor, macOS 15.2)](https://discuss.elastic.co/t/issue-with-elasticsearch-docker-deployment-on-apple-silicon-m4-processor-macos-15-2/373214)

<div class="topic-metadata">

**Author:** [@deepflyz](https://discuss.elastic.co/u/deepflyz)\
**Replies:** 4\
**Last updated:** [January 22, 2025, 4:47am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-docker-deployment-on-apple-silicon-m4-processor-macos-15-2/373214 "2025-01-22T04:47:31Z")

</div>

There is a current issue with deploying Elasticsearch via Docker on Mac computers equipped with Apple silicon (M4 processor) and running macOS 15.2. Here is the error log: 2025-01-15 11:55:22 # 2025-01-15 11:55:22 # A …

---

## [Metricbeat.yml's keepfiles max value is 90?](https://discuss.elastic.co/t/metricbeat-ymls-keepfiles-max-value-is-90/373433)

<div class="topic-metadata">

**Author:** [@xiaotiger](https://discuss.elastic.co/u/xiaotiger)\
**Replies:** 1\
**Last updated:** [January 22, 2025, 2:00am UTC](https://discuss.elastic.co/t/metricbeat-ymls-keepfiles-max-value-is-90/373433 "2025-01-22T02:00:51Z")

</div>

What is the maximum value of metricbeat.yml's keepfiles?

---

## [Integrate Elasticsearch with PostGres in nodejs app](https://discuss.elastic.co/t/integrate-elasticsearch-with-postgres-in-nodejs-app/359316)

<div class="topic-metadata">

**Author:** [@DubStep](https://discuss.elastic.co/u/DubStep)\
**Replies:** 5\
**Last updated:** [January 21, 2025, 6:23pm UTC](https://discuss.elastic.co/t/integrate-elasticsearch-with-postgres-in-nodejs-app/359316 "2025-01-21T18:23:31Z")

</div>

Hello! I'm kinda new to Elastic Search(I'm a noob in this particular technology) and I would like learn more about Elastic from the community. I'm building a nodejs app using PostGreSQL as the database and I want Elast…

---

## [Indices managed by Index Lifecycle Policy don't get deleted](https://discuss.elastic.co/t/indices-managed-by-index-lifecycle-policy-dont-get-deleted/373296)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 10\
**Last updated:** [January 21, 2025, 3:21pm UTC](https://discuss.elastic.co/t/indices-managed-by-index-lifecycle-policy-dont-get-deleted/373296 "2025-01-21T15:21:59Z")

</div>

I'm using Filebeat to ingest network logs. I have an Index Lifecycle Policy that applies to all Filebeat indices\*. I have set the Delete Phase to move data into the phase when it's 30 days old. However, indices don't see…

---

## [Troubleshooting 502 Errors During Elasticsearch Indexing](https://discuss.elastic.co/t/troubleshooting-502-errors-during-elasticsearch-indexing/373450)

<div class="topic-metadata">

**Author:** [@Rayliotta](https://discuss.elastic.co/u/Rayliotta)\
**Replies:** 1\
**Last updated:** [January 21, 2025, 1:39pm UTC](https://discuss.elastic.co/t/troubleshooting-502-errors-during-elasticsearch-indexing/373450 "2025-01-21T13:39:11Z")

</div>

Hi I've been encountering 502 errors when attempting to index large documents. Has anyone else faced similar issues, and how did you troubleshoot and resolve them? I'm particularly interested in understanding potential …

---

## [Activate sso with keyclock](https://discuss.elastic.co/t/activate-sso-with-keyclock/373436)

<div class="topic-metadata">

**Author:** [@rezgui](https://discuss.elastic.co/u/rezgui)\
**Replies:** 0\
**Last updated:** [January 21, 2025, 9:23am UTC](https://discuss.elastic.co/t/activate-sso-with-keyclock/373436 "2025-01-21T09:23:07Z")

</div>

hello, in kibana i have many spaces with custom rule for eatch user. each user can acced only on his space throw his rule. the problem after activate sso with rule mapping ,the user connecte to all space throw the rule…

---

## [502 error when indexing a large (?) document](https://discuss.elastic.co/t/502-error-when-indexing-a-large-document/373209)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 13\
**Last updated:** [January 21, 2025, 6:09am UTC](https://discuss.elastic.co/t/502-error-when-indexing-a-large-document/373209 "2025-01-21T06:09:03Z")

</div>

Hello I am having trouble diagnosing and resolving a large document upload issue... I'm using elasticsearch SaaS and there is a document which is approximately 42MB, when my software attempts to index it I get an error: …

---

## [Elastic Search Setup in Docker Swarm with xpack.security](https://discuss.elastic.co/t/elastic-search-setup-in-docker-swarm-with-xpack-security/373236)

<div class="topic-metadata">

**Author:** [@MarvinObert](https://discuss.elastic.co/u/MarvinObert)\
**Replies:** 1\
**Last updated:** [January 21, 2025, 2:42am UTC](https://discuss.elastic.co/t/elastic-search-setup-in-docker-swarm-with-xpack-security/373236 "2025-01-21T02:42:59Z")

</div>

Hi, I want to create an elastic with kibana and 3 nods. I have my docker compose which I use to setup the config in my docker swarm. On es01 I get the error: Caused by: org.elasticsearch.common.ssl.SslConfigException: …

---

## [Elasticsearch-Pyspark Problem](https://discuss.elastic.co/t/elasticsearch-pyspark-problem/372495)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [January 20, 2025, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-pyspark-problem/372495 "2025-01-20T18:48:52Z")

</div>

Hello, I'm trying to connect PySpark with Elasticsearch so that I can manipulate Elasticsearch docs using PySpark. However, I'm currently facing issues when trying to retrieve documents. I've tried different approaches,…

---

## [Bulk indexing using logstash jdbc plugin](https://discuss.elastic.co/t/bulk-indexing-using-logstash-jdbc-plugin/373418)

<div class="topic-metadata">

**Author:** [@sandhya\_revuri](https://discuss.elastic.co/u/sandhya_revuri)\
**Replies:** 0\
**Last updated:** [January 20, 2025, 6:31pm UTC](https://discuss.elastic.co/t/bulk-indexing-using-logstash-jdbc-plugin/373418 "2025-01-20T18:31:29Z")

</div>

Hello, I'm indexing five years of data from MySQL to Elasticsearch using the Logstash JDBC plugin. My SQL query joins around 15 tables, yielding separate rows for each order\_item of an order. Issue 1: Delayed Aggregati…

---

## [Python bulk index update not indexing all documents](https://discuss.elastic.co/t/python-bulk-index-update-not-indexing-all-documents/361345)

<div class="topic-metadata">

**Author:** [@Mario\_Betterplace](https://discuss.elastic.co/u/Mario_Betterplace)\
**Replies:** 5\
**Last updated:** [January 20, 2025, 5:39pm UTC](https://discuss.elastic.co/t/python-bulk-index-update-not-indexing-all-documents/361345 "2025-01-20T17:39:23Z")

</div>

We're bulk indexing documents with this function: async def bulk\_update\_index(index: str, docs: dict\[str, dict\]): actions = \[ { "\_index": index, "\_op\_type": "index", "\_i…

---

## [Applying ml jobs on raw data without installing network packet beats or other beats](https://discuss.elastic.co/t/applying-ml-jobs-on-raw-data-without-installing-network-packet-beats-or-other-beats/373402)

<div class="topic-metadata">

**Author:** [@Snow](https://discuss.elastic.co/u/Snow)\
**Replies:** 0\
**Last updated:** [January 20, 2025, 12:47pm UTC](https://discuss.elastic.co/t/applying-ml-jobs-on-raw-data-without-installing-network-packet-beats-or-other-beats/373402 "2025-01-20T12:47:21Z")

</div>

I have forwarded my raw log to elastic (custom udp integration), i have not installed beats(eg: packetbeat and other). I could see some of rules like below, DNS Tunneling "query": { "bool": { "filter": \[ { "term":…

---

## [Where can I find the traffic filtering rejection logs?](https://discuss.elastic.co/t/where-can-i-find-the-traffic-filtering-rejection-logs/373389)

<div class="topic-metadata">

**Author:** [@Richard\_Zhang](https://discuss.elastic.co/u/Richard_Zhang)\
**Replies:** 0\
**Last updated:** [January 20, 2025, 8:46am UTC](https://discuss.elastic.co/t/where-can-i-find-the-traffic-filtering-rejection-logs/373389 "2025-01-20T08:46:59Z")

</div>

Hi everyone, As per official document, if a request to ES is rejected by traffic filter rules, they will be included in proxy logs. Can anyone help guide me where I can find these logs? I'm not sure what the proxy logs …

---

## [Elastic search refuses to start after update](https://discuss.elastic.co/t/elastic-search-refuses-to-start-after-update/373394)

<div class="topic-metadata">

**Author:** [@masara](https://discuss.elastic.co/u/masara)\
**Replies:** 1\
**Last updated:** [January 20, 2025, 10:28am UTC](https://discuss.elastic.co/t/elastic-search-refuses-to-start-after-update/373394 "2025-01-20T10:28:43Z")

</div>

So downgraded my Elasticsearch to 7.17 for me to achieve the all in one deployment with wazuh which was i have been using all along until someone updated the server and in then update the server. I then regenerated th…

---

## [Slowlog differences between 8.17 and 7.17](https://discuss.elastic.co/t/slowlog-differences-between-8-17-and-7-17/373379)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 1\
**Last updated:** [January 20, 2025, 8:52am UTC](https://discuss.elastic.co/t/slowlog-differences-between-8-17-and-7-17/373379 "2025-01-20T08:52:40Z")

</div>

Hello, The request shown below works fine on Elasticsearch 7.17 but fails on 8.17 (also on 8.10 that I tried) curl -X PUT "http://localhost:9200/my\_index3" -H 'Content-Type: application/json' -d' { "settings": { …

---

## [Cant Install Agent on Windows Machines But work on Linux](https://discuss.elastic.co/t/cant-install-agent-on-windows-machines-but-work-on-linux/373378)

<div class="topic-metadata">

**Author:** [@syed\_naqvi](https://discuss.elastic.co/u/syed_naqvi)\
**Replies:** 0\
**Last updated:** [January 20, 2025, 5:14am UTC](https://discuss.elastic.co/t/cant-install-agent-on-windows-machines-but-work-on-linux/373378 "2025-01-20T05:14:04Z")

</div>

Hi All ! I need help as tried many times and read blogs too. However facing an issue for installing Elastic agent though fleet on windows machines. It failes as log below . However same thing /policy worked on Linux mac…

---

## [Elasticsearch is very slow](https://discuss.elastic.co/t/elasticsearch-is-very-slow/373362)

<div class="topic-metadata">

**Author:** [@Unknown\_Device](https://discuss.elastic.co/u/Unknown_Device)\
**Replies:** 6\
**Last updated:** [January 20, 2025, 3:45am UTC](https://discuss.elastic.co/t/elasticsearch-is-very-slow/373362 "2025-01-20T03:45:54Z")

</div>

I set up Elastic Search about a month ago for my pet-project. Elastic Search is hosted locally on my machine on Windows. Everything was working fine. Now when I try to access it in any way it doesn't respond and I get an…

---

## [Problem using ES as a service on W10](https://discuss.elastic.co/t/problem-using-es-as-a-service-on-w10/373356)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 2\
**Last updated:** [January 19, 2025, 6:38pm UTC](https://discuss.elastic.co/t/problem-using-es-as-a-service-on-w10/373356 "2025-01-19T18:38:20Z")

</div>

I saw this question from 2021. But for one thing my system doesn't have an "elastic-agent.exe" file. I was using ES 7.10.2 up until about 3 years ago. Then I decided to upgrade to 8.x ... and eventually settled on 8.13.…

---

## [Deployment architecture of ELK stack in on premise Windows Server](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251)

<div class="topic-metadata">

**Author:** [@grootlin](https://discuss.elastic.co/u/grootlin)\
**Replies:** 6\
**Last updated:** [January 18, 2025, 12:33am UTC](https://discuss.elastic.co/t/deployment-architecture-of-elk-stack-in-on-premise-windows-server/373251 "2025-01-18T00:33:47Z")

</div>

I have found myself as an administrator in an environment where ELK stack is used for log aggregation. We need to be pulling in Syslog data from our Network devices, virtualization cluster, and logs from our Windows / Li…

---

## [ESQL - diff with NOW()](https://discuss.elastic.co/t/esql-diff-with-now/373321)

<div class="topic-metadata">

**Author:** [@mortenb123](https://discuss.elastic.co/u/mortenb123)\
**Replies:** 1\
**Last updated:** [January 17, 2025, 2:36pm UTC](https://discuss.elastic.co/t/esql-diff-with-now/373321 "2025-01-17T14:36:22Z")

</div>

How can I create a nowdiff: FROM \*.events.\* | limit 1 | EVAL mynow=now() | KEEP time,mynow time mynow 2023-05-20T03:22:16.976Z 2025-01-17T10:07:54.328Z But: FROM \*.events.\* | li…

---

## [Combination of faceted and full-text query](https://discuss.elastic.co/t/combination-of-faceted-and-full-text-query/373310)

<div class="topic-metadata">

**Author:** [@SLEZ\_DOM](https://discuss.elastic.co/u/SLEZ_DOM)\
**Replies:** 1\
**Last updated:** [January 17, 2025, 7:54am UTC](https://discuss.elastic.co/t/combination-of-faceted-and-full-text-query/373310 "2025-01-17T07:54:58Z")

</div>

Task: I am using full-text search and faceted search in a single query. However, I encountered an issue: if the search by query (e.g., brand or product name) yields no results, it returns all products that match the fil…

---

## [ILM action - lifecycle action \[migrate\] waiting for \[3\] shards to be moved to the \[data\_warm\] tier](https://discuss.elastic.co/t/ilm-action-lifecycle-action-migrate-waiting-for-3-shards-to-be-moved-to-the-data-warm-tier/373179)

<div class="topic-metadata">

**Author:** [@NikolaySh1](https://discuss.elastic.co/u/NikolaySh1)\
**Replies:** 2\
**Last updated:** [January 17, 2025, 7:52am UTC](https://discuss.elastic.co/t/ilm-action-lifecycle-action-migrate-waiting-for-3-shards-to-be-moved-to-the-data-warm-tier/373179 "2025-01-17T07:52:59Z")

</div>

Hello everyone! I have ILM configured: "filebeat-prod": { "version": 5, "modified\_date": "2025-01-13T15:41:59.287Z", "policy": { "phases": { "warm": { "min\_age": "1d", "actions": { …

---

## [Difference between \`terms\` and \`term\` query for a single term?](https://discuss.elastic.co/t/difference-between-terms-and-term-query-for-a-single-term/373248)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 5\
**Last updated:** [January 17, 2025, 5:00am UTC](https://discuss.elastic.co/t/difference-between-terms-and-term-query-for-a-single-term/373248 "2025-01-17T05:00:39Z")

</div>

Is there any significant implementation difference between terms and term query when there is a single term to search? In a situation where I know the number of terms in advance, is it worth it to implement them separat…

---

## [Elasticsearch 8.17.0 failing to start in minikube with older manifests (used to work with 7.12.1)](https://discuss.elastic.co/t/elasticsearch-8-17-0-failing-to-start-in-minikube-with-older-manifests-used-to-work-with-7-12-1/373299)

<div class="topic-metadata">

**Author:** [@dangerouspython](https://discuss.elastic.co/u/dangerouspython)\
**Replies:** 0\
**Last updated:** [January 16, 2025, 9:53pm UTC](https://discuss.elastic.co/t/elasticsearch-8-17-0-failing-to-start-in-minikube-with-older-manifests-used-to-work-with-7-12-1/373299 "2025-01-16T21:53:33Z")

</div>

Elasticsearch Version 8.17.0 Installed Plugins kibana, istio Java Version bundled OS Version Darwin GGN-MAC-10089 24.2.0 Darwin Kernel Version 24.2.0: Fri Dec 6 18:41:43 PST 2024; root:xnu-11215.61.5~2/RELEASE\_X86\_64…

---

## [Index breaking for a few seconds/minutes](https://discuss.elastic.co/t/index-breaking-for-a-few-seconds-minutes/370901)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 7\
**Last updated:** [January 16, 2025, 9:31pm UTC](https://discuss.elastic.co/t/index-breaking-for-a-few-seconds-minutes/370901 "2025-01-16T21:31:36Z")

</div>

Started to notice that my indexing rate has some breaks which leads delay in the indexing of the documents. What can be the cause of this?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=49)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=51)
