# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=52

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 53

---

## [Tips for managing spikes in data sources](https://discuss.elastic.co/t/tips-for-managing-spikes-in-data-sources/373143)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [January 13, 2025, 9:27pm UTC](https://discuss.elastic.co/t/tips-for-managing-spikes-in-data-sources/373143 "2025-01-13T21:27:12Z")

</div>

Hello, I was wondering what others do to manage a huge increase in events from a particular data source (spikes). I know there's a rate lime processor on elastic agent but is there other mechanisms used? I have heard o…

---

## [Filebeat8.12 cisco module for ise logs is supported or not?](https://discuss.elastic.co/t/filebeat8-12-cisco-module-for-ise-logs-is-supported-or-not/373043)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 4\
**Last updated:** [January 13, 2025, 8:28pm UTC](https://discuss.elastic.co/t/filebeat8-12-cisco-module-for-ise-logs-is-supported-or-not/373043 "2025-01-13T20:28:35Z")

</div>

I have setup filebeat 8.12 and set kafka input in filebeat input file , since cisco ise logs are coming at kafka topic , ingest pipeline is created for cisco module and filebeat index is created ,ise logs are coming in f…

---

## [Thread Pool Search Size and Query Cache](https://discuss.elastic.co/t/thread-pool-search-size-and-query-cache/373137)

<div class="topic-metadata">

**Author:** [@kdwolf](https://discuss.elastic.co/u/kdwolf)\
**Replies:** 0\
**Last updated:** [January 13, 2025, 4:57pm UTC](https://discuss.elastic.co/t/thread-pool-search-size-and-query-cache/373137 "2025-01-13T16:57:57Z")

</div>

We use default values for both search size and query cache. Providing we decide to increase the query cache looking to improve search experience, would one recommend to increase the search size of the thread pool as well…

---

## [Issue with \_prefer\_nodes behavior in Elasticsearch 8.15.1](https://discuss.elastic.co/t/issue-with-prefer-nodes-behavior-in-elasticsearch-8-15-1/373125)

<div class="topic-metadata">

**Author:** [@GabM](https://discuss.elastic.co/u/GabM)\
**Replies:** 0\
**Last updated:** [January 13, 2025, 1:49pm UTC](https://discuss.elastic.co/t/issue-with-prefer-nodes-behavior-in-elasticsearch-8-15-1/373125 "2025-01-13T13:49:24Z")

</div>

Hello, I am encountering what seems to be unexpected behavior with the preference option in the /\_search API when using the \_prefer\_nodes value. Here's the setup and the problem: Cluster Configuration: Elasticsearch v…

---

## [ILM Policy Reset for Indices Created by Kubernetes Integration](https://discuss.elastic.co/t/ilm-policy-reset-for-indices-created-by-kubernetes-integration/373119)

<div class="topic-metadata">

**Author:** [@KarimOthman](https://discuss.elastic.co/u/KarimOthman)\
**Replies:** 0\
**Last updated:** [January 13, 2025, 10:00am UTC](https://discuss.elastic.co/t/ilm-policy-reset-for-indices-created-by-kubernetes-integration/373119 "2025-01-13T10:00:12Z")

</div>

We are leveraging the Kubernetes integration in Elastic Agents to collect data from multiple Kubernetes clusters. By default, indices created by the Kubernetes integration are assigned the metrics@lifecycle ILM policy, w…

---

## [Restoring snapshot (filesystem) - empty](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987)

<div class="topic-metadata">

**Author:** [@e-lastic](https://discuss.elastic.co/u/e-lastic)\
**Replies:** 5\
**Last updated:** [January 12, 2025, 9:25am UTC](https://discuss.elastic.co/t/restoring-snapshot-filesystem-empty/372987 "2025-01-12T09:25:44Z")

</div>

Hi, TL;DR; Tried to restore a snapshot I did before re-installing the machine but ended up with elasticsearch complaining the snapshot is "empty" What happened: I had to set up a machine from scratch (single instance…

---

## [AttributeError: 'BM25RetrievalStrategy' object has no attribute 'query\_model\_id'](https://discuss.elastic.co/t/attributeerror-bm25retrievalstrategy-object-has-no-attribute-query-model-id/373085)

<div class="topic-metadata">

**Author:** [@yonglie](https://discuss.elastic.co/u/yonglie)\
**Replies:** 0\
**Last updated:** [January 11, 2025, 12:34am UTC](https://discuss.elastic.co/t/attributeerror-bm25retrievalstrategy-object-has-no-attribute-query-model-id/373085 "2025-01-11T00:34:39Z")

</div>

I want to run elasticsearch-lab examples chatbot-with-bm25-only-example.ipynb but i got the wrong info ,help me AttributeError: 'BM25RetrievalStrategy' object has no attribute 'query\_model\_id'

---

## [The documentation does not seem to document the minimum JDK runtime requirement for \`org.elasticsearch.plugin:x-pack-sql-jdbc\`](https://discuss.elastic.co/t/the-documentation-does-not-seem-to-document-the-minimum-jdk-runtime-requirement-for-org-elasticsearch-plugin-x-pack-sql-jdbc/372078)

<div class="topic-metadata">

**Author:** [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Replies:** 4\
**Last updated:** [January 10, 2025, 9:01pm UTC](https://discuss.elastic.co/t/the-documentation-does-not-seem-to-document-the-minimum-jdk-runtime-requirement-for-org-elasticsearch-plugin-x-pack-sql-jdbc/372078 "2025-01-10T21:01:21Z")

</div>

The documentation does not seem to document the minimum JDK runtime requirement for org.elasticsearch.plugin:x-pack-sql-jdbc. I am of course aware that using the JDBC driver requires a trial or paid license for the Elas…

---

## [Moving indices from Hot tier to Cold does not reduce hot tier size](https://discuss.elastic.co/t/moving-indices-from-hot-tier-to-cold-does-not-reduce-hot-tier-size/373001)

<div class="topic-metadata">

**Author:** [@Oolong](https://discuss.elastic.co/u/Oolong)\
**Replies:** 16\
**Last updated:** [January 10, 2025, 6:28pm UTC](https://discuss.elastic.co/t/moving-indices-from-hot-tier-to-cold-does-not-reduce-hot-tier-size/373001 "2025-01-10T18:28:47Z")

</div>

Hi Everyone, I have 200GB storage for HOT tier and 500GB for cold. I have so far used up 150GB on the HOT tier and have moved the indices that make up that 150 to Cold tier. My problem is that the Cold tier has increase…

---

## [Can I install license in a cluster that has no internet enabled](https://discuss.elastic.co/t/can-i-install-license-in-a-cluster-that-has-no-internet-enabled/373046)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [January 10, 2025, 5:22pm UTC](https://discuss.elastic.co/t/can-i-install-license-in-a-cluster-that-has-no-internet-enabled/373046 "2025-01-10T17:22:12Z")

</div>

Do I need internet to install a license in my ECK environment? there is no mentioned about this in the documentation: Manage licenses in ECK | Elastic Cloud on Kubernetes \[2.16\] | Elastic

---

## [How to monitor Elasticsearch snapshots](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/373069)

<div class="topic-metadata">

**Author:** [@Akinator](https://discuss.elastic.co/u/Akinator)\
**Replies:** 0\
**Last updated:** [January 10, 2025, 2:51pm UTC](https://discuss.elastic.co/t/how-to-monitor-elasticsearch-snapshots/373069 "2025-01-10T14:51:51Z")

</div>

Hello, I would like to use an alert to notify me of a snapshot failure. However, I quickly find myself limited because I am unable to define the type of monitor (Per query or per cluster metrics monitor). I need to retr…

---

## [Mocking SearchResponse in New .NET client](https://discuss.elastic.co/t/mocking-searchresponse-in-new-net-client/371925)

<div class="topic-metadata">

**Author:** [@imhoffdavid](https://discuss.elastic.co/u/imhoffdavid)\
**Replies:** 5\
**Last updated:** [January 10, 2025, 2:37pm UTC](https://discuss.elastic.co/t/mocking-searchresponse-in-new-net-client/371925 "2025-01-10T14:37:46Z")

</div>

Hello, I'm relatively new to .NET ecosystem and I'm trying to write some unit tests for the new elasticsearch .NET client (v 8.16.3) and I'm running into some issues. It seems in the past, (NEST client) you were able to…

---

## [Weird behavior of dot\_product similarity on dense\_vector field](https://discuss.elastic.co/t/weird-behavior-of-dot-product-similarity-on-dense-vector-field/373007)

<div class="topic-metadata">

**Author:** [@elaj](https://discuss.elastic.co/u/elaj)\
**Replies:** 3\
**Last updated:** [January 10, 2025, 1:10pm UTC](https://discuss.elastic.co/t/weird-behavior-of-dot-product-similarity-on-dense-vector-field/373007 "2025-01-10T13:10:36Z")

</div>

Hello, TLDR: What's the "indexation" difference between different similarities for dense\_vector field? I have an index with filed dense\_vector defined with similarity: cosine. Now, I want to experiment with similarity…

---

## [Are GET by ID requests impacted by index refresh?](https://discuss.elastic.co/t/are-get-by-id-requests-impacted-by-index-refresh/373042)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 1\
**Last updated:** [January 10, 2025, 5:59am UTC](https://discuss.elastic.co/t/are-get-by-id-requests-impacted-by-index-refresh/373042 "2025-01-10T05:59:43Z")

</div>

From what I understand, searches may be impacted by index refreshes in that the results may be based on a previous state of the index while the refresh is in progress. But how about get requests by the document ID? Can …

---

## [Multiline as single event](https://discuss.elastic.co/t/multiline-as-single-event/373040)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 0\
**Last updated:** [January 10, 2025, 3:11am UTC](https://discuss.elastic.co/t/multiline-as-single-event/373040 "2025-01-10T03:11:19Z")

</div>

I am trying to extract log line using custom log integration fleet agent, It's a single event but every event is seperate. \<SQL \> \<TrID: aergaerfertferfewrfwerwewf:0011064\> \<TID: 6546546464\> \<RPC ID: 0001135907\> \<Queue:…

---

## [Combine connect and disconnect documents with transform?](https://discuss.elastic.co/t/combine-connect-and-disconnect-documents-with-transform/372477)

<div class="topic-metadata">

**Author:** [@Jokke](https://discuss.elastic.co/u/Jokke)\
**Replies:** 3\
**Last updated:** [January 9, 2025, 1:29pm UTC](https://discuss.elastic.co/t/combine-connect-and-disconnect-documents-with-transform/372477 "2025-01-09T13:29:02Z")

</div>

Hello! I'm new to transforms so not really sure, but I think transforms is what I need here. Logs are pushed from web application to ES (fluentd) and there among connect and disconnect messages. What I would want is to…

---

## [Accidentally deleted synthetic browser data stream](https://discuss.elastic.co/t/accidentally-deleted-synthetic-browser-data-stream/372938)

<div class="topic-metadata">

**Author:** [@Emanuel](https://discuss.elastic.co/u/Emanuel)\
**Replies:** 1\
**Last updated:** [January 8, 2025, 3:57pm UTC](https://discuss.elastic.co/t/accidentally-deleted-synthetic-browser-data-stream/372938 "2025-01-08T15:57:58Z")

</div>

Hello, I accidentally deleted the datastream from synthetic browser via kibana UI, Stack management -\> index management -\> data stream This datastream was in a space so it had a namespace in its name synthetics-browse…

---

## [Performance: Adding multiple indexes in term query in a search request](https://discuss.elastic.co/t/performance-adding-multiple-indexes-in-term-query-in-a-search-request/372994)

<div class="topic-metadata">

**Author:** [@ajayraghav](https://discuss.elastic.co/u/ajayraghav)\
**Replies:** 0\
**Last updated:** [January 9, 2025, 11:47am UTC](https://discuss.elastic.co/t/performance-adding-multiple-indexes-in-term-query-in-a-search-request/372994 "2025-01-09T11:47:02Z")

</div>

I intend to use query\_string and term queries (across multiple indexes) on \_search. My combined query is this, "query": { "bool": { "must": \[ { "query\_string": { "fields": \[ "\*" \], "query": "tes" } } \], "sh…

---

## [Double Terms aggregation with top\_hits sub-aggregation not working](https://discuss.elastic.co/t/double-terms-aggregation-with-top-hits-sub-aggregation-not-working/372668)

<div class="topic-metadata">

**Author:** [@Clement\_Naudet](https://discuss.elastic.co/u/Clement_Naudet)\
**Replies:** 5\
**Last updated:** [January 9, 2025, 11:36am UTC](https://discuss.elastic.co/t/double-terms-aggregation-with-top-hits-sub-aggregation-not-working/372668 "2025-01-09T11:36:18Z")

</div>

Hello everyone, Here is my mapping in my index "my-index-000001" { "mappings": { "properties": { "objectId": { "type": "keyword" }, "dateTime": { "type": "date" }, "status": { "type": "keyword" …

---

## [To big index for ML job - how to add ILM?](https://discuss.elastic.co/t/to-big-index-for-ml-job-how-to-add-ilm/357611)

<div class="topic-metadata">

**Author:** [@Wojciech\_Kwiecien](https://discuss.elastic.co/u/Wojciech_Kwiecien)\
**Replies:** 1\
**Last updated:** [January 9, 2025, 11:11am UTC](https://discuss.elastic.co/t/to-big-index-for-ml-job-how-to-add-ilm/357611 "2025-01-09T11:11:56Z")

</div>

Hello Everyone, I’ve encountered an issue while working with Machine Learning jobs in Elasticsearch, where the result indices aren't being properly managed post-rollover. I have to figured out something because index f…

---

## [What components come under Enterprise subscription?](https://discuss.elastic.co/t/what-components-come-under-enterprise-subscription/372968)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [January 9, 2025, 8:08am UTC](https://discuss.elastic.co/t/what-components-come-under-enterprise-subscription/372968 "2025-01-09T08:08:16Z")

</div>

Hi! If I put together an architecture with data nodes, master nodes, kibana, logstash, fleet nodes, ingest nodes - which of these are excluded during the RAM calculation to determine the number of licenses? Please help! …

---

## [Grok and special characters in field names](https://discuss.elastic.co/t/grok-and-special-characters-in-field-names/372971)

<div class="topic-metadata">

**Author:** [@Snow](https://discuss.elastic.co/u/Snow)\
**Replies:** 0\
**Last updated:** [January 9, 2025, 6:56am UTC](https://discuss.elastic.co/t/grok-and-special-characters-in-field-names/372971 "2025-01-09T06:56:07Z")

</div>

ES field names are like "dns.question, dns.question.type,dns.answers" (DNS Fields | Elastic Common Schema (ECS) Reference \[8.16\] | Elastic)|" (DNS Fields | Elastic Common Schema (ECS) Reference \[8.16\] | Elastic) but wh…

---

## [LogsDB Without Synthetic \_Source: Storage Savings and Upgrade Risks?](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 5\
**Last updated:** [January 8, 2025, 6:16pm UTC](https://discuss.elastic.co/t/logsdb-without-synthetic-source-storage-savings-and-upgrade-risks/372858 "2025-01-08T18:16:05Z")

</div>

I am currently on Elasticsearch version 8.16 and considering using the LogsDB index mode for its benefits, particularly the improved querying speed and reduced storage footprint with the new sorting feature (up to 20%, b…

---

## [How do i get AWS cloudwatch metrics to elastic for serverless](https://discuss.elastic.co/t/how-do-i-get-aws-cloudwatch-metrics-to-elastic-for-serverless/372669)

<div class="topic-metadata">

**Author:** [@rpeynado1](https://discuss.elastic.co/u/rpeynado1)\
**Replies:** 9\
**Last updated:** [January 8, 2025, 5:26pm UTC](https://discuss.elastic.co/t/how-do-i-get-aws-cloudwatch-metrics-to-elastic-for-serverless/372669 "2025-01-08T17:26:51Z")

</div>

Hello, I am trying to push cloudwatch metrics via sqs to elastic. How do i go about doing this? these are for multiple servers and serverless applications

---

## [Heap Allocation Failures on 8.17](https://discuss.elastic.co/t/heap-allocation-failures-on-8-17/372211)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 9\
**Last updated:** [January 8, 2025, 3:20pm UTC](https://discuss.elastic.co/t/heap-allocation-failures-on-8-17/372211 "2025-01-08T15:20:15Z")

</div>

We've had 2 different 8.x clusters running for a number of years without issue however since upgrading to 8.17 (from 8.15.1) a couple of days ago we are seeing frequent heap allocation failures such as below: # # There …

---

## [What is .ent-search-\*-logs-\*,-.ent-search-\*? where is it from?](https://discuss.elastic.co/t/what-is-ent-search-logs-ent-search-where-is-it-from/372873)

<div class="topic-metadata">

**Author:** [@Richard\_Zhang](https://discuss.elastic.co/u/Richard_Zhang)\
**Replies:** 7\
**Last updated:** [January 8, 2025, 2:43pm UTC](https://discuss.elastic.co/t/what-is-ent-search-logs-ent-search-where-is-it-from/372873 "2025-01-08T14:43:52Z")

</div>

Hi everyone, In everyone of our Elasticsearch instances in Azure, there is a persistent setting entry like below: "action.auto\_create\_index": ".ent-search-\*-logs-\*,-.ent-search-\*,+\*" But nobody remembers/knows who a…

---

## [Heap filled up after upgrade to 8.17](https://discuss.elastic.co/t/heap-filled-up-after-upgrade-to-8-17/372932)

<div class="topic-metadata">

**Author:** [@cmoi](https://discuss.elastic.co/u/cmoi)\
**Replies:** 0\
**Last updated:** [January 8, 2025, 10:56am UTC](https://discuss.elastic.co/t/heap-filled-up-after-upgrade-to-8-17/372932 "2025-01-08T10:56:43Z")

</div>

Hi, I have upgraded my cluster from 8.11 to 8.17 and since it keeps crashing due to full heap used. I have upped the heap memory but it did not solve the issue. After some time with heap memory use steady, it starts gro…

---

## [ESQL - fieldnames with slash('/') not supported just removed in kibana](https://discuss.elastic.co/t/esql-fieldnames-with-slash-not-supported-just-removed-in-kibana/372935)

<div class="topic-metadata">

**Author:** [@mortenb123](https://discuss.elastic.co/u/mortenb123)\
**Replies:** 1\
**Last updated:** [January 8, 2025, 1:53pm UTC](https://discuss.elastic.co/t/esql-fieldnames-with-slash-not-supported-just-removed-in-kibana/372935 "2025-01-08T13:53:04Z")

</div>

I have the following fieldnames in index (verified in kibana): python .\\bin\\elkq2.py --getmapping --index='bps-trace-ttl\_7d-8.16.1-rancher2-2025.01.08' fields: @timestamp,@versi…

---

## [Elasticsearch: create a new field based on the value of other fields in a time range](https://discuss.elastic.co/t/elasticsearch-create-a-new-field-based-on-the-value-of-other-fields-in-a-time-range/372929)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 0\
**Last updated:** [January 8, 2025, 10:13am UTC](https://discuss.elastic.co/t/elasticsearch-create-a-new-field-based-on-the-value-of-other-fields-in-a-time-range/372929 "2025-01-08T10:13:17Z")

</div>

Hi all, I have some data in different timestamps as below image, imaging that the fields are "src label", "src value" "dst label" , "dst value" and timestamp. how can I define a new fields named as "In" based on th…

---

## [Async search performance on coplex aggregations](https://discuss.elastic.co/t/async-search-performance-on-coplex-aggregations/372922)

<div class="topic-metadata">

**Author:** [@Mahdi\_Moazami](https://discuss.elastic.co/u/Mahdi_Moazami)\
**Replies:** 0\
**Last updated:** [January 8, 2025, 8:53am UTC](https://discuss.elastic.co/t/async-search-performance-on-coplex-aggregations/372922 "2025-01-08T08:53:58Z")

</div>

Hello Elastic team, I recently got challenges on a complex aggregation search that when this aggregation is run sequentially by a python script, after some time goes on, it starts receiving circuit breaker errors on sea…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=51)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=53)
