# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=57

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 58

---

## [Frozen tier in self managed cluster](https://discuss.elastic.co/t/frozen-tier-in-self-managed-cluster/371825)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [December 11, 2024, 10:43am UTC](https://discuss.elastic.co/t/frozen-tier-in-self-managed-cluster/371825 "2024-12-11T10:43:39Z")

</div>

I understand elastic cloud enterprise subscription offers hot,warm,cold and frozen. What about a self managed deployment? Could I set up these tiers in my self managed cluster? DO I need enterprise subscription or is it…

---

## [Query elasticseatrch with pyspark and nested fields](https://discuss.elastic.co/t/query-elasticseatrch-with-pyspark-and-nested-fields/371745)

<div class="topic-metadata">

**Author:** [@xsa\_xsa](https://discuss.elastic.co/u/xsa_xsa)\
**Replies:** 0\
**Last updated:** [December 10, 2024, 9:58am UTC](https://discuss.elastic.co/t/query-elasticseatrch-with-pyspark-and-nested-fields/371745 "2024-12-10T09:58:45Z")

</div>

hello, I am trying to query with pyspark an index with documents: { "field1": "field1\_data", "field2": \[ { "field2\_1": "x1", "field2\_2": "x2" }, { "field2\_1": "x3", "field2\_2": "x4" } \] } if i query fr…

---

## [Hybrid search on managed elasticsearch instance](https://discuss.elastic.co/t/hybrid-search-on-managed-elasticsearch-instance/371807)

<div class="topic-metadata">

**Author:** [@aiexplorations](https://discuss.elastic.co/u/aiexplorations)\
**Replies:** 1\
**Last updated:** [December 11, 2024, 6:29am UTC](https://discuss.elastic.co/t/hybrid-search-on-managed-elasticsearch-instance/371807 "2024-12-11T06:29:56Z")

</div>

Hi all, I have a specific question on whether we need all the vectors to be persisted in memory on the Elasticsearch ML node (or in the other ES nodes) when running ML search. We're building an application at my end wh…

---

## [Kibana Login with Encrypt Username](https://discuss.elastic.co/t/kibana-login-with-encrypt-username/371756)

<div class="topic-metadata">

**Author:** [@amjad](https://discuss.elastic.co/u/amjad)\
**Replies:** 1\
**Last updated:** [December 10, 2024, 3:12pm UTC](https://discuss.elastic.co/t/kibana-login-with-encrypt-username/371756 "2024-12-10T15:12:29Z")

</div>

Hi All, Hope Everyone doing great. Please help me in what are the changes need to be done in both elastic.yml and kibana.yml for the logging of Kibana dashboards with the encrypt username in elastic version 7.16 having…

---

## [Elastic-Agent Upgradation](https://discuss.elastic.co/t/elastic-agent-upgradation/371749)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [December 10, 2024, 12:39pm UTC](https://discuss.elastic.co/t/elastic-agent-upgradation/371749 "2024-12-10T12:39:22Z")

</div>

Hi Team, We are running ELK cluster - 8.13.2 and we have installed elastic-agent -8.13.2 . We need to upgrade the cluster and elastic agent . I have a question that i can upgrade ELK cluster but don’t know how to upgrad…

---

## [ECK performance optimisation on Kubernetes](https://discuss.elastic.co/t/eck-performance-optimisation-on-kubernetes/371694)

<div class="topic-metadata">

**Author:** [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Replies:** 5\
**Last updated:** [December 10, 2024, 6:42am UTC](https://discuss.elastic.co/t/eck-performance-optimisation-on-kubernetes/371694 "2024-12-10T06:42:28Z")

</div>

Can you pass on some recommendation on optimising elasticsearch cluster on Kubernetes. Current Configuration : 3 different node groups hot-warm-cold ES Nodegroup - 4 CPU 8Gib Mem /node Kibana - 2 CPU 4 Gib Mem /node …

---

## [Data Migration from 2.3.3 to 8..9.0](https://discuss.elastic.co/t/data-migration-from-2-3-3-to-8-9-0/368589)

<div class="topic-metadata">

**Author:** [@utkarsh-007](https://discuss.elastic.co/u/utkarsh-007)\
**Replies:** 5\
**Last updated:** [December 10, 2024, 7:02am UTC](https://discuss.elastic.co/t/data-migration-from-2-3-3-to-8-9-0/368589 "2024-12-10T07:02:40Z")

</div>

I have an on-premise elastic cluster running on version 2.3.3. (aka old) I have another on-premise elastic cluster running on version 8.9.0 (aka new) I want to migrate data from one index of old cluster to new index o…

---

## [Having different passowrds for the pkcs12 keystore and the private key in the keystore](https://discuss.elastic.co/t/having-different-passowrds-for-the-pkcs12-keystore-and-the-private-key-in-the-keystore/371597)

<div class="topic-metadata">

**Author:** [@tom110](https://discuss.elastic.co/u/tom110)\
**Replies:** 1\
**Last updated:** [December 10, 2024, 3:39am UTC](https://discuss.elastic.co/t/having-different-passowrds-for-the-pkcs12-keystore-and-the-private-key-in-the-keystore/371597 "2024-12-10T03:39:37Z")

</div>

I am confused by how should i handle the passwords for the keystore and the private key inside the keystore. I used the following Openssl command to generate my own certificate using my own CA to secure http layer connec…

---

## [Issues with allocating kibana\_task\_manager index](https://discuss.elastic.co/t/issues-with-allocating-kibana-task-manager-index/371688)

<div class="topic-metadata">

**Author:** [@envycz](https://discuss.elastic.co/u/envycz)\
**Replies:** 1\
**Last updated:** [December 9, 2024, 9:57pm UTC](https://discuss.elastic.co/t/issues-with-allocating-kibana-task-manager-index/371688 "2024-12-09T21:57:46Z")

</div>

Hello, I have multiple ECK clusters (3 node) deployed the same way on different Azure AKS clusters. On all of them there a reoccurring events of failed allocation of one specific index .kibana\_task\_manager\_8.14.1\_001. It…

---

## [Slow log doesn't capture](https://discuss.elastic.co/t/slow-log-doesnt-capture/371715)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [December 9, 2024, 9:49pm UTC](https://discuss.elastic.co/t/slow-log-doesnt-capture/371715 "2024-12-09T21:49:23Z")

</div>

Hi I have noticed that most of the log words are not recorded despite the setting of precise parameters, have you met with such a situation. I need to know what type of request search takes more resources. PUT /prod\_in…

---

## [ML multimetric job](https://discuss.elastic.co/t/ml-multimetric-job/371387)

<div class="topic-metadata">

**Author:** [@Naina\_Sharma](https://discuss.elastic.co/u/Naina_Sharma)\
**Replies:** 1\
**Last updated:** [December 9, 2024, 6:54pm UTC](https://discuss.elastic.co/t/ml-multimetric-job/371387 "2024-12-09T18:54:03Z")

</div>

Hi, I am creating a multi metric job- because I want to check if there are no application data sent. We send the application directly to Elasticsearch in form of Datastreams. The logs have different fields like applicat…

---

## [The number of queries exceeds 10000](https://discuss.elastic.co/t/the-number-of-queries-exceeds-10000/371660)

<div class="topic-metadata">

**Author:** [@wender](https://discuss.elastic.co/u/wender)\
**Replies:** 3\
**Last updated:** [December 9, 2024, 6:37pm UTC](https://discuss.elastic.co/t/the-number-of-queries-exceeds-10000/371660 "2024-12-09T18:37:33Z")

</div>

Hi I have a question about search, how to query over 10000 item, I know some api about search after, scroll, from size, but I want to achieve the ability to select the page I want after querying 10000 items, like this …

---

## [How to migrate older logs stored in one elasticsearch cluster to another new one?](https://discuss.elastic.co/t/how-to-migrate-older-logs-stored-in-one-elasticsearch-cluster-to-another-new-one/360912)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 10\
**Last updated:** [December 9, 2024, 6:00pm UTC](https://discuss.elastic.co/t/how-to-migrate-older-logs-stored-in-one-elasticsearch-cluster-to-another-new-one/360912 "2024-12-09T18:00:14Z")

</div>

I don't have any paid features of elasticsearch. Older elasticsearch cluster version is 7.17 and the new one is 8.12.

---

## [How to reset elasticsearch "elastic" user password?](https://discuss.elastic.co/t/how-to-reset-elasticsearch-elastic-user-password/371673)

<div class="topic-metadata">

**Author:** [@aalaskapedh](https://discuss.elastic.co/u/aalaskapedh)\
**Replies:** 5\
**Last updated:** [December 9, 2024, 3:52pm UTC](https://discuss.elastic.co/t/how-to-reset-elasticsearch-elastic-user-password/371673 "2024-12-09T15:52:57Z")

</div>

install-elasticsearch.sh sudo dnf install -y java-17-openjdk java-17-openjdk-devel sudo rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch cat \<\< EOF \> /etc/yum.repos.d/elasticsearch.repo \[elasticsearch\] na…

---

## [Does the combination of lambda with a builder have known name as a Design Pattern?](https://discuss.elastic.co/t/does-the-combination-of-lambda-with-a-builder-have-known-name-as-a-design-pattern/371710)

<div class="topic-metadata">

**Author:** [@Hans\_Kruse](https://discuss.elastic.co/u/Hans_Kruse)\
**Replies:** 1\
**Last updated:** [December 9, 2024, 3:28pm UTC](https://discuss.elastic.co/t/does-the-combination-of-lambda-with-a-builder-have-known-name-as-a-design-pattern/371710 "2024-12-09T15:28:50Z")

</div>

The elasticsearch-java client SDK uses the combination of a lambda with a builder a lot, e.g.: esClient.something(somethingBuilder -\> somethingBuilder .propertyA(valueA) .propertyB(valueB) )....; Is there an establish…

---

## [Correct way to search with a PIT using the elasticsearch-java](https://discuss.elastic.co/t/correct-way-to-search-with-a-pit-using-the-elasticsearch-java/371650)

<div class="topic-metadata">

**Author:** [@Hans\_Kruse](https://discuss.elastic.co/u/Hans_Kruse)\
**Replies:** 3\
**Last updated:** [December 9, 2024, 2:39pm UTC](https://discuss.elastic.co/t/correct-way-to-search-with-a-pit-using-the-elasticsearch-java/371650 "2024-12-09T14:39:27Z")

</div>

In the context of converting from the high level client to the newer elasticsearch-java SDK, how should I provide a PIT when searching with the elasticsearch-java client? I cannot find any guidance. I think I am doing it…

---

## [Elastic search nested aggrigation](https://discuss.elastic.co/t/elastic-search-nested-aggrigation/371709)

<div class="topic-metadata">

**Author:** [@Abhay\_Pratap\_Singh](https://discuss.elastic.co/u/Abhay_Pratap_Singh)\
**Replies:** 0\
**Last updated:** [December 9, 2024, 2:28pm UTC](https://discuss.elastic.co/t/elastic-search-nested-aggrigation/371709 "2024-12-09T14:28:23Z")

</div>

I am try to get final price of each product of orders bu not able to calculate. The Document sample : Order Index : ------------- { "order\_id": "123", "customer": "John Doe", "deliveryFee": 40, "items": \[ …

---

## [Unassigned shards node left no attempt](https://discuss.elastic.co/t/unassigned-shards-node-left-no-attempt/370423)

<div class="topic-metadata">

**Author:** [@elasticexpert2](https://discuss.elastic.co/u/elasticexpert2)\
**Replies:** 3\
**Last updated:** [December 9, 2024, 1:42pm UTC](https://discuss.elastic.co/t/unassigned-shards-node-left-no-attempt/370423 "2024-12-09T13:42:55Z")

</div>

Alot of times when node disconnect and reconnect, I left with 1 or 2 unassigned shards. When I use \_cluster/allocation/explain, I get reason: "NODE\_LEFT" and last\_allocation\_status: "no\_attempt". When doing GET \_interna…

---

## [Remove index from alias using elasticsearch-java client SDK](https://discuss.elastic.co/t/remove-index-from-alias-using-elasticsearch-java-client-sdk/371605)

<div class="topic-metadata">

**Author:** [@Hans\_Kruse](https://discuss.elastic.co/u/Hans_Kruse)\
**Replies:** 4\
**Last updated:** [December 9, 2024, 11:00am UTC](https://discuss.elastic.co/t/remove-index-from-alias-using-elasticsearch-java-client-sdk/371605 "2024-12-09T11:00:11Z")

</div>

How do I remove indices from an alias using the elasticsearch-java client? The API does not seem to have a method to specify the alias. I cannot find an examples nor documentation. I am busy converting code from the o…

---

## [How to Set Up Rules and Policies for Alerts in Wazuh with Elasticsearch Integration?](https://discuss.elastic.co/t/how-to-set-up-rules-and-policies-for-alerts-in-wazuh-with-elasticsearch-integration/371676)

<div class="topic-metadata">

**Author:** [@214\_7B11](https://discuss.elastic.co/u/214_7B11)\
**Replies:** 0\
**Last updated:** [December 9, 2024, 6:51am UTC](https://discuss.elastic.co/t/how-to-set-up-rules-and-policies-for-alerts-in-wazuh-with-elasticsearch-integration/371676 "2024-12-09T06:51:59Z")

</div>

Hello, I’ve integrated my Wazuh deployment with Elasticsearch, and I’m looking to configure custom rules and policies for managing alerts. Could someone guide me through the process or point me to relevant documentation…

---

## [How to set default lifecycle deletion phase for filebeat & metricbeat post installation of ES node?](https://discuss.elastic.co/t/how-to-set-default-lifecycle-deletion-phase-for-filebeat-metricbeat-post-installation-of-es-node/371600)

<div class="topic-metadata">

**Author:** [@Vijaykumar\_sanganala](https://discuss.elastic.co/u/Vijaykumar_sanganala)\
**Replies:** 3\
**Last updated:** [December 9, 2024, 5:53am UTC](https://discuss.elastic.co/t/how-to-set-default-lifecycle-deletion-phase-for-filebeat-metricbeat-post-installation-of-es-node/371600 "2024-12-09T05:53:16Z")

</div>

Hi, I am newbee to ES, I wanted to set default lifecycle deletion phase for filebeat and metricbeat lifecycle policy. I could see that by default the host phase already enabled in kibana. Same way i want delete phase a…

---

## [Point in time Expiry!](https://discuss.elastic.co/t/point-in-time-expiry/371670)

<div class="topic-metadata">

**Author:** [@Mohammad\_Saif](https://discuss.elastic.co/u/Mohammad_Saif)\
**Replies:** 0\
**Last updated:** [December 9, 2024, 6:07am UTC](https://discuss.elastic.co/t/point-in-time-expiry/371670 "2024-12-09T06:07:14Z")

</div>

I created a point in time with expiry set as 15 min, and i have observed that if the query(this query is not extending the pit ,i.e. keep-alive ) using the pit is running close to the expiry, then this pit is not getting…

---

## [Finding similiar products by name](https://discuss.elastic.co/t/finding-similiar-products-by-name/371656)

<div class="topic-metadata">

**Author:** [@chung](https://discuss.elastic.co/u/chung)\
**Replies:** 1\
**Last updated:** [December 9, 2024, 5:15am UTC](https://discuss.elastic.co/t/finding-similiar-products-by-name/371656 "2024-12-09T05:15:15Z")

</div>

Gven a list of products and each is assign to some categories( Mobile, Apple, iPhone) assigned to it. iPhone 16 Pro 6.3-inch display iPhone 16 Pro Max 6.9-inch display iPhone 16 6.1-inch display iPhone 16 Plus 6.7-inch …

---

## [Specify timezone when trigger watchers](https://discuss.elastic.co/t/specify-timezone-when-trigger-watchers/215222)

<div class="topic-metadata">

**Author:** [@robinmhj](https://discuss.elastic.co/u/robinmhj)\
**Replies:** 3\
**Last updated:** [December 9, 2024, 12:05am UTC](https://discuss.elastic.co/t/specify-timezone-when-trigger-watchers/215222 "2024-12-09T00:05:08Z")

</div>

Hi there, I am using watcher to aggregate data, our elasticsearch instance is using utc time zone. Is it possible to specify the time based on timezone, the reason I am asking it because that there are day light saving…

---

## [Transforming (aggregating) network logs 14 million records every 5 min](https://discuss.elastic.co/t/transforming-aggregating-network-logs-14-million-records-every-5-min/371560)

<div class="topic-metadata">

**Author:** [@sid\_shah](https://discuss.elastic.co/u/sid_shah)\
**Replies:** 8\
**Last updated:** [December 7, 2024, 2:39pm UTC](https://discuss.elastic.co/t/transforming-aggregating-network-logs-14-million-records-every-5-min/371560 "2024-12-07T14:39:33Z")

</div>

I have 14 million records arriving every 5 minutes from Filebeat into a data stream (NetFlow data). My goal is to aggregate this data based on certain rules, such as summing source bytes and destination bytes for sp…

---

## [Elasticsearch ingestion : Geo point and numerical fields not recognize](https://discuss.elastic.co/t/elasticsearch-ingestion-geo-point-and-numerical-fields-not-recognize/371623)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 12\
**Last updated:** [December 7, 2024, 3:28am UTC](https://discuss.elastic.co/t/elasticsearch-ingestion-geo-point-and-numerical-fields-not-recognize/371623 "2024-12-07T03:28:30Z")

</div>

Hi all, I'm trying to ingest into an index my data (json) with a HTTP POST. Everything works fine but I have a geo point like this { "point\_location" : "11.0500,-0.2500" } which is not recognized as a geo point but like…

---

## [Searches never distribute across nodes in different AWS Availability Zones](https://discuss.elastic.co/t/searches-never-distribute-across-nodes-in-different-aws-availability-zones/371491)

<div class="topic-metadata">

**Author:** [@hatertot](https://discuss.elastic.co/u/hatertot)\
**Replies:** 1\
**Last updated:** [December 6, 2024, 11:01pm UTC](https://discuss.elastic.co/t/searches-never-distribute-across-nodes-in-different-aws-availability-zones/371491 "2024-12-06T23:01:41Z")

</div>

I have a cluster of about 19 nodes on ES 7.17.1. They are all definitely part of the same cluster. Each node has an entire copy of every index. 11 are in us-east-1f, 6 are in us-east-1d, 1 is in 1c and 1 is in 1b. …

---

## [Inference on an image](https://discuss.elastic.co/t/inference-on-an-image/368908)

<div class="topic-metadata">

**Author:** [@martin-k](https://discuss.elastic.co/u/martin-k)\
**Replies:** 3\
**Last updated:** [December 6, 2024, 10:51pm UTC](https://discuss.elastic.co/t/inference-on-an-image/368908 "2024-12-06T22:51:34Z")

</div>

Hello all, Is it possible to get a vector embedding for an image from an inference endpoint using the sentence-transformers\_\_clip-vit-b-32-multilingual-v1 model? And if so, what format should the input be? The document…

---

## [How can I compare similar indexes](https://discuss.elastic.co/t/how-can-i-compare-similar-indexes/370011)

<div class="topic-metadata">

**Author:** [@mortenb123](https://discuss.elastic.co/u/mortenb123)\
**Replies:** 3\
**Last updated:** [December 6, 2024, 4:06pm UTC](https://discuss.elastic.co/t/how-can-i-compare-similar-indexes/370011 "2024-12-06T16:06:51Z")

</div>

Events show up in kibana: but in Elastic dev console I cant see anything: if I just change the index it works for fido2.trk.events-test12\* but not fido2.demo.events-test12\* I've used stack management to check i…

---

## [Date mapping issue](https://discuss.elastic.co/t/date-mapping-issue/371575)

<div class="topic-metadata">

**Author:** [@rmdevheart](https://discuss.elastic.co/u/rmdevheart)\
**Replies:** 3\
**Last updated:** [December 6, 2024, 11:12am UTC](https://discuss.elastic.co/t/date-mapping-issue/371575 "2024-12-06T11:12:26Z")

</div>

HI all, can't fight with it anymore, need help. I have an input 'localtime' field with text formatted as '2024-12-06 08:40:36.000404894'. Index mapping for this: "localtime": { "type": "date", "f…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=56)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=58)
