# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=51

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 52

---

## [Does searching through alias return data from all rolling index?](https://discuss.elastic.co/t/does-searching-through-alias-return-data-from-all-rolling-index/373292)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [January 16, 2025, 8:01pm UTC](https://discuss.elastic.co/t/does-searching-through-alias-return-data-from-all-rolling-index/373292 "2025-01-16T20:01:13Z")

</div>

Version 8.10.2 Is this new change comparing to version 7.x? What if I just want to search the latest rolling index pointed by the alias? Anybody knows why such behavior change?

---

## [Shard recovery in 8.10.2 seems to happen more often](https://discuss.elastic.co/t/shard-recovery-in-8-10-2-seems-to-happen-more-often/357024)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 14\
**Last updated:** [January 16, 2025, 7:59pm UTC](https://discuss.elastic.co/t/shard-recovery-in-8-10-2-seems-to-happen-more-often/357024 "2025-01-16T19:59:11Z")

</div>

I have noticed that in version 8.10.2, shard allocation seems to prioritize on storage space first then the shard delta. Which is fine. I don't really have a preference either way. But as the result, shard moving seem…

---

## [ERROR: Elasticsearch died while starting up, with exit code 78](https://discuss.elastic.co/t/error-elasticsearch-died-while-starting-up-with-exit-code-78/373287)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 6\
**Last updated:** [January 16, 2025, 7:39pm UTC](https://discuss.elastic.co/t/error-elasticsearch-died-while-starting-up-with-exit-code-78/373287 "2025-01-16T19:39:38Z")

</div>

Today I found some errors in kibana where dasboards were not loading. I have a cluster of 3 servers for elasticsearch, one for kibana, one for logstash and one for fleet server. When I checked each of the elasticsea…

---

## [Deletions failing until index is refreshed](https://discuss.elastic.co/t/deletions-failing-until-index-is-refreshed/373290)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 0\
**Last updated:** [January 16, 2025, 6:19pm UTC](https://discuss.elastic.co/t/deletions-failing-until-index-is-refreshed/373290 "2025-01-16T18:19:18Z")

</div>

For a very small number of my elasticsearch instances, deletions are failing due to timeout and not succeeding until a refresh is performed. Might this be expected? Do refreshes trigger merges or something that will imp…

---

## [ESQL pass a stats column to next stage](https://discuss.elastic.co/t/esql-pass-a-stats-column-to-next-stage/373276)

<div class="topic-metadata">

**Author:** [@mortenb123](https://discuss.elastic.co/u/mortenb123)\
**Replies:** 2\
**Last updated:** [January 16, 2025, 1:42pm UTC](https://discuss.elastic.co/t/esql-pass-a-stats-column-to-next-stage/373276 "2025-01-16T13:42:50Z")

</div>

I need to find the first and the last inserts of sources in events: FROM \*.events.\* | KEEP @timestamp,source | stats latest=max(@timestamp) by source FROM \*.events.\* | KEEP @timestamp,source | stats first=min(@timesta…

---

## [Track the user activity in an application using ElasticSearch](https://discuss.elastic.co/t/track-the-user-activity-in-an-application-using-elasticsearch/373278)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [January 16, 2025, 1:00pm UTC](https://discuss.elastic.co/t/track-the-user-activity-in-an-application-using-elasticsearch/373278 "2025-01-16T13:00:30Z")

</div>

Is there a way to track how much time a user is using a desktop application using Elasticsearch?

---

## [Converting 7x. into 8.x Java client code. Getting the counts of individual buckets](https://discuss.elastic.co/t/converting-7x-into-8-x-java-client-code-getting-the-counts-of-individual-buckets/373223)

<div class="topic-metadata">

**Author:** [@Hans\_Kruse](https://discuss.elastic.co/u/Hans_Kruse)\
**Replies:** 2\
**Last updated:** [January 16, 2025, 8:52am UTC](https://discuss.elastic.co/t/converting-7x-into-8-x-java-client-code-getting-the-counts-of-individual-buckets/373223 "2025-01-16T08:52:24Z")

</div>

In our journey of converting 7.x client code into 8.x code we ran into one more challenge. Observe the following code that converts aggregation data retrieved from the client into a list of our Agg dto objects. public …

---

## [What is the solution in order to search for the entire text accurately without increasing ignore\_above in order for the space to remain the same?](https://discuss.elastic.co/t/what-is-the-solution-in-order-to-search-for-the-entire-text-accurately-without-increasing-ignore-above-in-order-for-the-space-to-remain-the-same/372569)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 19\
**Last updated:** [January 16, 2025, 10:26am UTC](https://discuss.elastic.co/t/what-is-the-solution-in-order-to-search-for-the-entire-text-accurately-without-increasing-ignore-above-in-order-for-the-space-to-remain-the-same/372569 "2025-01-16T10:26:45Z")

</div>

Hi I have data that I store in elasticsearch and from these data there are long fields of up to 2000 characters and I want to search for them by term It is known in elasticsearch that the keyword field type reaches a le…

---

## [Selfhosted Sharepoint Connector and self-signed Certs](https://discuss.elastic.co/t/selfhosted-sharepoint-connector-and-self-signed-certs/371522)

<div class="topic-metadata">

**Author:** [@fal77](https://discuss.elastic.co/u/fal77)\
**Replies:** 5\
**Last updated:** [January 16, 2025, 8:08am UTC](https://discuss.elastic.co/t/selfhosted-sharepoint-connector-and-self-signed-certs/371522 "2025-01-16T08:08:48Z")

</div>

Hi everyone, I run ES 8.16.1 secured as to the documentation. Downloaded the source for the sharepoint connector and did a clean install. My config.yml looks like this: connectors: - connector\_id: "cLzelZMBUWuJQBqZq…

---

## [Elasticsearch backup on Object storage S3 Compatibility API](https://discuss.elastic.co/t/elasticsearch-backup-on-object-storage-s3-compatibility-api/373010)

<div class="topic-metadata">

**Author:** [@samozx](https://discuss.elastic.co/u/samozx)\
**Replies:** 3\
**Last updated:** [January 16, 2025, 6:56am UTC](https://discuss.elastic.co/t/elasticsearch-backup-on-object-storage-s3-compatibility-api/373010 "2025-01-16T06:56:16Z")

</div>

Hello everyone, I have Elasticsearch version 8.12.2 installed on Oracle OCI - OKE , I am trying to configure the snapshot to be uploaded to the Object Storage Amazon S3 Compatibility API (From oracle documentation). n…

---

## [Float value rendered incorrectly by elastic API](https://discuss.elastic.co/t/float-value-rendered-incorrectly-by-elastic-api/373180)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 3\
**Last updated:** [January 15, 2025, 11:55pm UTC](https://discuss.elastic.co/t/float-value-rendered-incorrectly-by-elastic-api/373180 "2025-01-15T23:55:36Z")

</div>

I have an index template which defines the data type for the field liableban as follows: "liableBan": { "meta": { "entity": "usageCharacteristic.liableBan" }, "null\_value": 0, "store": true, "type": "long"…

---

## [How do I query the full field value using match as if I am searching using term, but it is not case sensitive?](https://discuss.elastic.co/t/how-do-i-query-the-full-field-value-using-match-as-if-i-am-searching-using-term-but-it-is-not-case-sensitive/373240)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 6\
**Last updated:** [January 15, 2025, 6:10pm UTC](https://discuss.elastic.co/t/how-do-i-query-the-full-field-value-using-match-as-if-i-am-searching-using-term-but-it-is-not-case-sensitive/373240 "2025-01-15T18:10:24Z")

</div>

Hi I want to query a field of type text using match, but I want to query the full text and also be case-insensitive What I mean is I have a search I want to search as if I am searching using the term but not sensitive…

---

## [High Latency on KNN Search](https://discuss.elastic.co/t/high-latency-on-knn-search/372828)

<div class="topic-metadata">

**Author:** [@Ahmad2356](https://discuss.elastic.co/u/Ahmad2356)\
**Replies:** 11\
**Last updated:** [January 15, 2025, 12:54pm UTC](https://discuss.elastic.co/t/high-latency-on-knn-search/372828 "2025-01-15T12:54:48Z")

</div>

Hi everyone, I’m running an Elasticsearch cluster (version 8.17) with the basic license. The cluster has 3 nodes, each on Linux servers with 62 GB RAM and 1 TB disk space. I’ve set up an index for vector search using th…

---

## [Authentication problem with Entra App OIDC on 8.13.4](https://discuss.elastic.co/t/authentication-problem-with-entra-app-oidc-on-8-13-4/373217)

<div class="topic-metadata">

**Author:** [@tdvo1996](https://discuss.elastic.co/u/tdvo1996)\
**Replies:** 0\
**Last updated:** [January 15, 2025, 6:33am UTC](https://discuss.elastic.co/t/authentication-problem-with-entra-app-oidc-on-8-13-4/373217 "2025-01-15T06:33:36Z")

</div>

Hi, we have configured Entra App for OIDC with the correct redirect uri, and correct group claim. I want the OIDC configuration to check the claim if I am a part of a specific AD group. Client secret is also stored in ke…

---

## [Does roles assigned to nodes affect the disk rebalancing?](https://discuss.elastic.co/t/does-roles-assigned-to-nodes-affect-the-disk-rebalancing/373215)

<div class="topic-metadata">

**Author:** [@mike123](https://discuss.elastic.co/u/mike123)\
**Replies:** 2\
**Last updated:** [January 15, 2025, 9:10am UTC](https://discuss.elastic.co/t/does-roles-assigned-to-nodes-affect-the-disk-rebalancing/373215 "2025-01-15T09:10:20Z")

</div>

I have 10 data nodes of which 3 have additional ML and transform role to it. I could observe that almost all the primary shards are assigned to nodes with ml role assigned to it. And replicas are distributed. This is ca…

---

## [What is the appropriate document size in Elasticsearch？](https://discuss.elastic.co/t/what-is-the-appropriate-document-size-in-elasticsearch/358191)

<div class="topic-metadata">

**Author:** [@jiankunking](https://discuss.elastic.co/u/jiankunking)\
**Replies:** 1\
**Last updated:** [January 15, 2025, 8:15am UTC](https://discuss.elastic.co/t/what-is-the-appropriate-document-size-in-elasticsearch/358191 "2025-01-15T08:15:26Z")

</div>

// Reduced irrelevant attributes { "code": "product code", "saleIncludeCustomers": \[ // Object { "code": "Customer code", "launchId": "la…

---

## [Elasticsearch Virtual Machine Requirement](https://discuss.elastic.co/t/elasticsearch-virtual-machine-requirement/371345)

<div class="topic-metadata">

**Author:** [@Hendrawns](https://discuss.elastic.co/u/Hendrawns)\
**Replies:** 2\
**Last updated:** [January 15, 2025, 8:13am UTC](https://discuss.elastic.co/t/elasticsearch-virtual-machine-requirement/371345 "2025-01-15T08:13:35Z")

</div>

Hello Everyone, I plan to move the Elasticsearch environment to a virtual machine because the bare metal server that I currently use is always full quickly, so my team decided to migrate to a virtual machine that is easy…

---

## [Finding number of hits for an index](https://discuss.elastic.co/t/finding-number-of-hits-for-an-index/373197)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [January 15, 2025, 2:26am UTC](https://discuss.elastic.co/t/finding-number-of-hits-for-an-index/373197 "2025-01-15T02:26:01Z")

</div>

Hi All, I am trying to determine number of hits that an index experiences in a 24 hours period. I see the number as 87,366,378 for a 24 hour period between Jan 6th and 7th as follows: How can I get this number 87,3…

---

## [Elasticsearch Architecture](https://discuss.elastic.co/t/elasticsearch-architecture/373127)

<div class="topic-metadata">

**Author:** [@rolindroy](https://discuss.elastic.co/u/rolindroy)\
**Replies:** 3\
**Last updated:** [January 14, 2025, 11:32pm UTC](https://discuss.elastic.co/t/elasticsearch-architecture/373127 "2025-01-14T23:32:32Z")

</div>

I have set up an Elasticsearch cluster to handle logs from a Kubernetes (K8s) cluster hosting over 500 applications. Retention policies need to be configured per application, with a default retention of 20 days and exten…

---

## [Multiline config](https://discuss.elastic.co/t/multiline-config/373203)

<div class="topic-metadata">

**Author:** [@stecino](https://discuss.elastic.co/u/stecino)\
**Replies:** 0\
**Last updated:** [January 14, 2025, 8:48pm UTC](https://discuss.elastic.co/t/multiline-config/373203 "2025-01-14T20:48:28Z")

</div>

Trying to identify log events that start either with \<\<\< or \>\>\> or \[ Would this be correct? multiline.pattern: '^(\<\<\<\<|\>\>\>\>|\])'

---

## [Elastic search trained model inference not working](https://discuss.elastic.co/t/elastic-search-trained-model-inference-not-working/359649)

<div class="topic-metadata">

**Author:** [@likealam](https://discuss.elastic.co/u/likealam)\
**Replies:** 5\
**Last updated:** [January 14, 2025, 8:45pm UTC](https://discuss.elastic.co/t/elastic-search-trained-model-inference-not-working/359649 "2025-01-14T20:45:17Z")

</div>

After importing the text embedding sentence-transformers/msmarco-MiniLM-L12-cos-v5 model to elasticsearch using eland the model infering doesnt work. eland command: eland\_import\_hub\_model --url http://localhost:9200 --…

---

## [Filtering messages in Logstash](https://discuss.elastic.co/t/filtering-messages-in-logstash/373126)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [January 14, 2025, 7:49pm UTC](https://discuss.elastic.co/t/filtering-messages-in-logstash/373126 "2025-01-14T19:49:55Z")

</div>

Hi All, The incoming feed (log) to Logstash has parameters which are delimited by ~|~ These are being mutated and split in Logstash as follows. : if \[type\] == "tv\_dmz\_access" { mutate { …

---

## [Sizing a secondary Cluster with Frozen nodes and Searchable Snapshots](https://discuss.elastic.co/t/sizing-a-secondary-cluster-with-frozen-nodes-and-searchable-snapshots/373184)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [January 14, 2025, 6:53pm UTC](https://discuss.elastic.co/t/sizing-a-secondary-cluster-with-frozen-nodes-and-searchable-snapshots/373184 "2025-01-14T18:53:40Z")

</div>

Hi all, I’m working on a solution involving the use of searchable snapshots, and I need some clarification to properly size a second cluster. Here’s the context: I plan to use my production cluster (Platinum license) …

---

## [Elasticsearch Performance Issues on CapCut Resource Website](https://discuss.elastic.co/t/elasticsearch-performance-issues-on-capcut-resource-website/373130)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 2\
**Last updated:** [January 14, 2025, 4:46pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-issues-on-capcut-resource-website/373130 "2025-01-14T16:46:29Z")

</div>

Hi everyone, I’m running a website focused on CapCut tutorials and resources, and I’ve implemented Elasticsearch for powering the search functionality. However, I’m experiencing significant performance issues: Slow Se…

---

## [Snapshot Lifecycle Lifecyle and Managment Creating issue for rollover](https://discuss.elastic.co/t/snapshot-lifecycle-lifecyle-and-managment-creating-issue-for-rollover/373154)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 1\
**Last updated:** [January 14, 2025, 2:50pm UTC](https://discuss.elastic.co/t/snapshot-lifecycle-lifecyle-and-managment-creating-issue-for-rollover/373154 "2025-01-14T14:50:53Z")

</div>

Overview i have elasticsearch 8.11 with no replicas right now, only 5 hot nodes and 2 frozen that's it. Here is index lifecycle policy is this PUT \_ilm/policy/ConrainerLogs { "policy": { "phases": { …

---

## [Hiding or Excluding Fields in Filebeat Data Ingestion via MQTT](https://discuss.elastic.co/t/hiding-or-excluding-fields-in-filebeat-data-ingestion-via-mqtt/373166)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 0\
**Last updated:** [January 14, 2025, 10:38am UTC](https://discuss.elastic.co/t/hiding-or-excluding-fields-in-filebeat-data-ingestion-via-mqtt/373166 "2025-01-14T10:38:26Z")

</div>

Hi, I'm encountering some challenges while ingesting data using Filebeat with MQTT. My setup involves ingesting data from multiple MQTT topics that follow this naming structure: \<ABBREVIATION\>/\<CITY\_NAME\>/\<SIGNAL\_CODE\> …

---

## [Startup failure - arch64 - crashes - arm64 - fedora, rocky9, centos9, macbook m4, docker](https://discuss.elastic.co/t/startup-failure-arch64-crashes-arm64-fedora-rocky9-centos9-macbook-m4-docker/371708)

<div class="topic-metadata">

**Author:** [@contactnkm](https://discuss.elastic.co/u/contactnkm)\
**Replies:** 7\
**Last updated:** [January 14, 2025, 10:35am UTC](https://discuss.elastic.co/t/startup-failure-arch64-crashes-arm64-fedora-rocky9-centos9-macbook-m4-docker/371708 "2025-01-14T10:35:49Z")

</div>

Get the following error whenever trying to install and run elasticsearch on aarch64 rocky9.5 or fedora 6.11.4 stdoout: # # A fatal error has been detected by the Java Runtime Environment: # # SIGILL (0x4) at pc=0x0000…

---

## [Nodes going down without any error logs](https://discuss.elastic.co/t/nodes-going-down-without-any-error-logs/373155)

<div class="topic-metadata">

**Author:** [@Naveen\_S1](https://discuss.elastic.co/u/Naveen_S1)\
**Replies:** 1\
**Last updated:** [January 14, 2025, 7:59am UTC](https://discuss.elastic.co/t/nodes-going-down-without-any-error-logs/373155 "2025-01-14T07:59:53Z")

</div>

I have an ES cluster hosted on-prem with around 110 nodes. Each node resides on a 2TB partition. I have to index around 5 set of 250 GB JSON data into the cluster. Each JSON file contains 10,000 docs. I am using a custo…

---

## [GET /\_security/api\_key does not show "role\_descriptors"](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029)

<div class="topic-metadata">

**Author:** [@Byungsoo\_Kim](https://discuss.elastic.co/u/Byungsoo_Kim)\
**Replies:** 8\
**Last updated:** [January 14, 2025, 12:52am UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029 "2025-01-14T00:52:48Z")

</div>

I am using ES cloud and create api\_key through "API Console" UI on ES cloud. The following is an example of the payload to create an api\_key POST /\_security/api\_key { "name": "midtier-2025", "role\_descriptors": { …

---

## [Index relocation failing at 100% bytes](https://discuss.elastic.co/t/index-relocation-failing-at-100-bytes/372934)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 5\
**Last updated:** [January 13, 2025, 11:09pm UTC](https://discuss.elastic.co/t/index-relocation-failing-at-100-bytes/372934 "2025-01-13T23:09:54Z")

</div>

After upgrade from 7.17.23 to 7.17.26 I started seeing patterns like this: ILM starts relocating from warm tier to cold in /\_cat/allocation transfer goes to 100% bp nothing in log of source node error in log of target …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=50)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=52)
