# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=56

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 57

---

## [Search with multi-values](https://discuss.elastic.co/t/search-with-multi-values/372013)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [December 16, 2024, 9:58am UTC](https://discuss.elastic.co/t/search-with-multi-values/372013 "2024-12-16T09:58:17Z")

</div>

Hi, Is it possible to search with multiple values ? i have a list of words or group of words like \["John","command n345","Paris, France","Destination"\]. and I want to search an items contains with these values, not mu…

---

## [Unable to retrieve version information from Elasticsearch nodes. security\_exception](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/371950)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [December 16, 2024, 1:59am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/371950 "2024-12-16T01:59:39Z")

</div>

Hi all ! I just configuration elasticsearch & Kibana version 8.6.2 . However I don't access web interface Kibana: http://10.xx.xx.xx/app/home and here is the detailed log error Log Kibana: Dec 13 09:56:29 dc-uat-elk-lo…

---

## [Custom mapping in Trend Micro Vision One integration](https://discuss.elastic.co/t/custom-mapping-in-trend-micro-vision-one-integration/371983)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 3\
**Last updated:** [December 15, 2024, 2:23pm UTC](https://discuss.elastic.co/t/custom-mapping-in-trend-micro-vision-one-integration/371983 "2024-12-15T14:23:49Z")

</div>

Hi all, in Trend Micro Vision One integration, I added a custom pipeline: { "json": { "field": "event.original", "target\_field": "details", "if": "ctx?.trend\_micro\_vision\_one.detection.product.name == 'Vision One C…

---

## [Backward pagination with search\_after and PIT](https://discuss.elastic.co/t/backward-pagination-with-search-after-and-pit/371981)

<div class="topic-metadata">

**Author:** [@sandra\_a](https://discuss.elastic.co/u/sandra_a)\
**Replies:** 5\
**Last updated:** [December 15, 2024, 6:29am UTC](https://discuss.elastic.co/t/backward-pagination-with-search-after-and-pit/371981 "2024-12-15T06:29:20Z")

</div>

Hello; I used From and Size for pagination, but it doesn't retrieve more than 10,000 docs. I read Document about pagination and saw search\_after and PIT. I have a question about this. what if i want to see previous pa…

---

## [ECE - Searchable object storage](https://discuss.elastic.co/t/ece-searchable-object-storage/371861)

<div class="topic-metadata">

**Author:** [@Catalin1](https://discuss.elastic.co/u/Catalin1)\
**Replies:** 2\
**Last updated:** [December 12, 2024, 11:28am UTC](https://discuss.elastic.co/t/ece-searchable-object-storage/371861 "2024-12-12T11:28:58Z")

</div>

Hello, I'm using ECE, and trying to create a script that would give the "Searchable object storage" of a Frozen Instance, that is stored in S3. I have tried to get it through the API : /api/v1/deployments/{deployment\_id…

---

## [Using post filter to remove entries whereby collapsed inner hits total is less than X](https://discuss.elastic.co/t/using-post-filter-to-remove-entries-whereby-collapsed-inner-hits-total-is-less-than-x/371722)

<div class="topic-metadata">

**Author:** [@codeMonkey82](https://discuss.elastic.co/u/codeMonkey82)\
**Replies:** 9\
**Last updated:** [December 13, 2024, 12:24pm UTC](https://discuss.elastic.co/t/using-post-filter-to-remove-entries-whereby-collapsed-inner-hits-total-is-less-than-x/371722 "2024-12-13T12:24:24Z")

</div>

I have a query that collapses on a field representing a hash that can at most be shared between two entries. What I need to do is via a post filter (or alternative) remove the results from the final list whereby the inne…

---

## [Mocking the .NET Client for ExistsResponse in unit tests](https://discuss.elastic.co/t/mocking-the-net-client-for-existsresponse-in-unit-tests/371915)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 2\
**Last updated:** [December 13, 2024, 9:50am UTC](https://discuss.elastic.co/t/mocking-the-net-client-for-existsresponse-in-unit-tests/371915 "2024-12-13T09:50:43Z")

</div>

Hello Everyone, I am using .NET 8 and "Elastic.Clients.Elasticsearch" Version="8.15.6" (not NEST) For mocking we are using NSubstitute(not Moq) I tried to go through multiple blogs and even the github repo for .NET cl…

---

## [How to mock Elasticsearch ExistsAsync response](https://discuss.elastic.co/t/how-to-mock-elasticsearch-existsasync-response/371935)

<div class="topic-metadata">

**Author:** [@Guthula\_Baladitya](https://discuss.elastic.co/u/Guthula_Baladitya)\
**Replies:** 1\
**Last updated:** [December 13, 2024, 8:51am UTC](https://discuss.elastic.co/t/how-to-mock-elasticsearch-existsasync-response/371935 "2024-12-13T08:51:39Z")

</div>

Hello everyone, I have a piece of code in my repository class where I'm checking whether a specific index exists or not. var IndexExists = await \_elasticClient.Indices.ExistsAsync(IndexName); if ((await \_el…

---

## [Remove system indices](https://discuss.elastic.co/t/remove-system-indices/371930)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [December 12, 2024, 9:49pm UTC](https://discuss.elastic.co/t/remove-system-indices/371930 "2024-12-12T21:49:07Z")

</div>

I am trying to remove old system indices from kibana but it gives me errro ".kibana\_7.12.0\_001" when I try to login as kibana\_system it does not allow me to login. How do I remove these old indices? Reason I want …

---

## [Enrichment Policy Execution getting stuck](https://discuss.elastic.co/t/enrichment-policy-execution-getting-stuck/371753)

<div class="topic-metadata">

**Author:** [@ankurl](https://discuss.elastic.co/u/ankurl)\
**Replies:** 0\
**Last updated:** [December 10, 2024, 11:54am UTC](https://discuss.elastic.co/t/enrichment-policy-execution-getting-stuck/371753 "2024-12-10T11:54:16Z")

</div>

Hi All, We are using enrichment policy to load data from one index to another and it works fine usually but some time our policy execution request is getting stuck without any response. Whenever it happens I check the …

---

## [Handling tags in elasticsearch documents and kibana visualisations](https://discuss.elastic.co/t/handling-tags-in-elasticsearch-documents-and-kibana-visualisations/371869)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 10\
**Last updated:** [December 12, 2024, 5:30pm UTC](https://discuss.elastic.co/t/handling-tags-in-elasticsearch-documents-and-kibana-visualisations/371869 "2024-12-12T17:30:22Z")

</div>

Hey folks I have been asked to determine how we can leverage a set of tags that will be added to all documents being indexed in future and I am looking for guidance on best practices. Our clusters are primarily used as…

---

## [Current doc is in 8.17, but no tag release](https://discuss.elastic.co/t/current-doc-is-in-8-17-but-no-tag-release/371922)

<div class="topic-metadata">

**Author:** [@decima](https://discuss.elastic.co/u/decima)\
**Replies:** 1\
**Last updated:** [December 12, 2024, 4:45pm UTC](https://discuss.elastic.co/t/current-doc-is-in-8-17-but-no-tag-release/371922 "2024-12-12T16:45:53Z")

</div>

I see that the "current" doc on elastic website is in 8.17 but can't see the release available on github

---

## [Roll over indices - mapping updates and reindexing requirements](https://discuss.elastic.co/t/roll-over-indices-mapping-updates-and-reindexing-requirements/371784)

<div class="topic-metadata">

**Author:** [@seshug](https://discuss.elastic.co/u/seshug)\
**Replies:** 1\
**Last updated:** [December 12, 2024, 2:16pm UTC](https://discuss.elastic.co/t/roll-over-indices-mapping-updates-and-reindexing-requirements/371784 "2024-12-12T14:16:08Z")

</div>

Question, how do we better handle the rollover indices along with rollover alias when there is a requirement to update the mappings on the indices. We have a scenario where we implemented a rollover indices for one of t…

---

## [Create an ILM policy on basis of volumes](https://discuss.elastic.co/t/create-an-ilm-policy-on-basis-of-volumes/371312)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 7\
**Last updated:** [December 12, 2024, 2:10pm UTC](https://discuss.elastic.co/t/create-an-ilm-policy-on-basis-of-volumes/371312 "2024-12-12T14:10:28Z")

</div>

I have implemented an ILM (Index Lifecycle Management) policy with a time-based strategy, where indices such as my-data-index-api-dev-\* are automatically deleted after 7 days. Currently, this setup deletes indices after …

---

## [Elastic Frozen Storage](https://discuss.elastic.co/t/elastic-frozen-storage/371903)

<div class="topic-metadata">

**Author:** [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Replies:** 2\
**Last updated:** [December 12, 2024, 2:07pm UTC](https://discuss.elastic.co/t/elastic-frozen-storage/371903 "2024-12-12T14:07:10Z")

</div>

Hello everyone, a question regarding elastic architecture; I have 100 GB per day ingestion. If I want to keep the data 300 days in a frozen node without any replication; how should I estimate the disk storage? I don't…

---

## [Pipeline error](https://discuss.elastic.co/t/pipeline-error/371916)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 0\
**Last updated:** [December 12, 2024, 1:19pm UTC](https://discuss.elastic.co/t/pipeline-error/371916 "2024-12-12T13:19:05Z")

</div>

Hi all, I've configured a custom pipeline. When the pipeline fails documents are not inserted in the data stream. No errors. No errors even though I have inserted a Failure processor that sets an 'error' field. Pipel…

---

## [Can't access Kibana from the broswer](https://discuss.elastic.co/t/cant-access-kibana-from-the-broswer/371914)

<div class="topic-metadata">

**Author:** [@khaled1](https://discuss.elastic.co/u/khaled1)\
**Replies:** 1\
**Last updated:** [December 12, 2024, 12:04pm UTC](https://discuss.elastic.co/t/cant-access-kibana-from-the-broswer/371914 "2024-12-12T12:04:31Z")

</div>

I installed the Elasticsearch and kibana on Ubuntu 20 on the same machine, at first everything was working very well but after restarting the Ubuntu cant open the Kibana from the broswers in the same time to services is …

---

## [Issue while starting elastic search service](https://discuss.elastic.co/t/issue-while-starting-elastic-search-service/371558)

<div class="topic-metadata">

**Author:** [@Mandara](https://discuss.elastic.co/u/Mandara)\
**Replies:** 4\
**Last updated:** [December 12, 2024, 10:25am UTC](https://discuss.elastic.co/t/issue-while-starting-elastic-search-service/371558 "2024-12-12T10:25:45Z")

</div>

Hi All , I am getting below error while starting up elastic service . May I know how to fix this issue as I am new to Elasticsearch . systemd-entrypoint\[62417\]: CompileCommand: dontinline java/lang/invoke/MethodHan…

---

## [Enrichement process not consistently enrching](https://discuss.elastic.co/t/enrichement-process-not-consistently-enrching/371270)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 16\
**Last updated:** [December 12, 2024, 7:04am UTC](https://discuss.elastic.co/t/enrichement-process-not-consistently-enrching/371270 "2024-12-12T07:04:04Z")

</div>

Enrichment is not consistent. I have source index from where i am enriching the a field on the basis of the destination ip. enrichemnt is working but sometime its not enriching the field even the same destination.ip is t…

---

## [Cost Optimization with Generative AI Using Elasticsearch](https://discuss.elastic.co/t/cost-optimization-with-generative-ai-using-elasticsearch/371890)

<div class="topic-metadata">

**Author:** [@yominosekai](https://discuss.elastic.co/u/yominosekai)\
**Replies:** 0\
**Last updated:** [December 12, 2024, 5:46am UTC](https://discuss.elastic.co/t/cost-optimization-with-generative-ai-using-elasticsearch/371890 "2024-12-12T05:46:04Z")

</div>

Hello Elastic Community, I am conducting research on cost optimization strategies for generative AI systems. Specifically, I am exploring how Elasticsearch can be used to store user queries, model responses, and their v…

---

## [We need to bring shards size in Grafana via exporter](https://discuss.elastic.co/t/we-need-to-bring-shards-size-in-grafana-via-exporter/371888)

<div class="topic-metadata">

**Author:** [@MaryES](https://discuss.elastic.co/u/MaryES)\
**Replies:** 0\
**Last updated:** [December 12, 2024, 5:27am UTC](https://discuss.elastic.co/t/we-need-to-bring-shards-size-in-grafana-via-exporter/371888 "2024-12-12T05:27:19Z")

</div>

Hi We need to check the size of shards from Grafana , we need to get the metrics via exporter. Is there any way to get the data?

---

## [Swapping out nodes in the cluster](https://discuss.elastic.co/t/swapping-out-nodes-in-the-cluster/371882)

<div class="topic-metadata">

**Author:** [@stecino](https://discuss.elastic.co/u/stecino)\
**Replies:** 1\
**Last updated:** [December 12, 2024, 4:49am UTC](https://discuss.elastic.co/t/swapping-out-nodes-in-the-cluster/371882 "2024-12-12T04:49:46Z")

</div>

Hello, I am swapping out some old nodes in Elasticsearch 5.6.3 cluster with new ones. I don’t have a lot of indices/shards in it at the moment. If were to stop the old node, and start the new node (provided I don’t hav…

---

## [Enrich Index Auto updation](https://discuss.elastic.co/t/enrich-index-auto-updation/371885)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 0\
**Last updated:** [December 12, 2024, 4:45am UTC](https://discuss.elastic.co/t/enrich-index-auto-updation/371885 "2024-12-12T04:45:50Z")

</div>

Hi Team, I am having two indexes one is orders index(Stores Orders information) and other one is items index(Store the information related to each order with list of items) and i wanted to enrich my orders index with th…

---

## [Elastic tools won't connect in simple docker-compose config](https://discuss.elastic.co/t/elastic-tools-wont-connect-in-simple-docker-compose-config/371783)

<div class="topic-metadata">

**Author:** [@csteffen](https://discuss.elastic.co/u/csteffen)\
**Replies:** 7\
**Last updated:** [December 12, 2024, 2:17am UTC](https://discuss.elastic.co/t/elastic-tools-wont-connect-in-simple-docker-compose-config/371783 "2024-12-12T02:17:07Z")

</div>

I'm using docker compose to put together some containers running code that my team has built, plus rabbitmq, and also an elk stack to monitor the rabbitmq logs and queues. I'm attempting to follow the configuration in: …

---

## [Using Relative Time in the rule to create alerts](https://discuss.elastic.co/t/using-relative-time-in-the-rule-to-create-alerts/371877)

<div class="topic-metadata">

**Author:** [@Aryaman\_Singh](https://discuss.elastic.co/u/Aryaman_Singh)\
**Replies:** 0\
**Last updated:** [December 12, 2024, 12:22am UTC](https://discuss.elastic.co/t/using-relative-time-in-the-rule-to-create-alerts/371877 "2024-12-12T00:22:03Z")

</div>

Hi, I wanted to understand a way where We can use relative timestamps inside a rule to generate alerts in respect to the time we have received a certain kind of log. Not generate an alert for the logs whose vulnerabil…

---

## [Nested Fields in an Index](https://discuss.elastic.co/t/nested-fields-in-an-index/371311)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 8\
**Last updated:** [December 11, 2024, 11:39pm UTC](https://discuss.elastic.co/t/nested-fields-in-an-index/371311 "2024-12-11T23:39:04Z")

</div>

We have an Index with a Nested field. Most of the documents will have their nested field null but some will have it populated. What would the most efficient way of querying such index so that if there are no docs with n…

---

## [Azure Load balancer not working with elasticsearch 8.16.1](https://discuss.elastic.co/t/azure-load-balancer-not-working-with-elasticsearch-8-16-1/371361)

<div class="topic-metadata">

**Author:** [@Wajahat\_Iqbal](https://discuss.elastic.co/u/Wajahat_Iqbal)\
**Replies:** 4\
**Last updated:** [December 11, 2024, 3:02pm UTC](https://discuss.elastic.co/t/azure-load-balancer-not-working-with-elasticsearch-8-16-1/371361 "2024-12-11T15:02:41Z")

</div>

I built Elasticsearch in my testing environment with the same configuration with a load balancer with Elasticsearch 7.10.0 and it was working fine. now I am using 8.16.1 I am having trouble connecting to it when I check…

---

## [What is the fastest storage type suitable for elasticsaerch than the HDD?](https://discuss.elastic.co/t/what-is-the-fastest-storage-type-suitable-for-elasticsaerch-than-the-hdd/371161)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 36\
**Last updated:** [December 11, 2024, 3:01pm UTC](https://discuss.elastic.co/t/what-is-the-fastest-storage-type-suitable-for-elasticsaerch-than-the-hdd/371161 "2024-12-11T15:01:24Z")

</div>

Hello can you help In order to store big data, what is the best type of HDD storage that is fast For example Qnap NAS is there a faster type than it?

---

## [\[BUG\] ECK 2.14/Eck-es 8.14.3: ILM Policy Rollover Settings (max\_docs, max\_primary\_shard\_docs) Incorrectly Merged with Cluster Defaults](https://discuss.elastic.co/t/bug-eck-2-14-eck-es-8-14-3-ilm-policy-rollover-settings-max-docs-max-primary-shard-docs-incorrectly-merged-with-cluster-defaults/371775)

<div class="topic-metadata">

**Author:** [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Replies:** 0\
**Last updated:** [December 10, 2024, 4:06pm UTC](https://discuss.elastic.co/t/bug-eck-2-14-eck-es-8-14-3-ilm-policy-rollover-settings-max-docs-max-primary-shard-docs-incorrectly-merged-with-cluster-defaults/371775 "2024-12-10T16:06:34Z")

</div>

Current Behavior Description We are experiencing unexpected behavior with ILM policy rollover settings in ECK 2.14 with Elasticsearch 8.14.3. Our custom ILM policy settings are being merged with cluster default rollover …

---

## [ElasticSearch taking too much ram](https://discuss.elastic.co/t/elasticsearch-taking-too-much-ram/371808)

<div class="topic-metadata">

**Author:** [@Wajahat\_Iqbal](https://discuss.elastic.co/u/Wajahat_Iqbal)\
**Replies:** 5\
**Last updated:** [December 11, 2024, 10:46am UTC](https://discuss.elastic.co/t/elasticsearch-taking-too-much-ram/371808 "2024-12-11T10:46:30Z")

</div>

I have 3 node setup, my CPU usage is very low, I have 4 cpu and 32 gb of ram. why its taking so much ram.

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=55)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=57)
