# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=58

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 59

---

## [Date mapping issue](https://discuss.elastic.co/t/date-mapping-issue/371575)

<div class="topic-metadata">

**Author:** [@rmdevheart](https://discuss.elastic.co/u/rmdevheart)\
**Replies:** 3\
**Last updated:** [December 6, 2024, 11:12am UTC](https://discuss.elastic.co/t/date-mapping-issue/371575 "2024-12-06T11:12:26Z")

</div>

HI all, can't fight with it anymore, need help. I have an input 'localtime' field with text formatted as '2024-12-06 08:40:36.000404894'. Index mapping for this: "localtime": { "type": "date", "f…

---

## [What is the maximum allowed length for any search string with \* wildcard?](https://discuss.elastic.co/t/what-is-the-maximum-allowed-length-for-any-search-string-with-wildcard/371581)

<div class="topic-metadata">

**Author:** [@priyankaMS](https://discuss.elastic.co/u/priyankaMS)\
**Replies:** 1\
**Last updated:** [December 6, 2024, 10:03am UTC](https://discuss.elastic.co/t/what-is-the-maximum-allowed-length-for-any-search-string-with-wildcard/371581 "2024-12-06T10:03:20Z")

</div>

In my Elasticsearch environment, for different asterisk (\*) wildcard positions in string I am getting below error: ES Exception: \[HTTP Status Code: \[400\] ORIGINAL\_EXCEPTION: \[Elasticsearch.Net.ElasticsearchClientExcep…

---

## [How should I write this statement?](https://discuss.elastic.co/t/how-should-i-write-this-statement/371584)

<div class="topic-metadata">

**Author:** [@nIxedoahz](https://discuss.elastic.co/u/nIxedoahz)\
**Replies:** 5\
**Last updated:** [December 6, 2024, 9:56am UTC](https://discuss.elastic.co/t/how-should-i-write-this-statement/371584 "2024-12-06T09:56:48Z")

</div>

Create an index ··· PUT /new\_index { "mappings": { "properties": { "data": { "type": "keyword" }, "hash": { "type": "integer" }, "hash\_mapping": { "type": "keyword" }, "task\_id": { "type": "keyword" } } …

---

## [Need matching element from array objects in aggregation like below](https://discuss.elastic.co/t/need-matching-element-from-array-objects-in-aggregation-like-below/371444)

<div class="topic-metadata">

**Author:** [@krishna\_kishore](https://discuss.elastic.co/u/krishna_kishore)\
**Replies:** 1\
**Last updated:** [December 6, 2024, 8:23am UTC](https://discuss.elastic.co/t/need-matching-element-from-array-objects-in-aggregation-like-below/371444 "2024-12-06T08:23:32Z")

</div>

URL: /products/\_doc/\_search?routing=DEFAULT&filter\_path=took,hits.hits.\_id,aggregations.filters..buckets.key,aggregations.filters. .buckets.key\_as\_string,aggregations.filters..buckets.doc\_count,hits.hits.\_source,aggregat…

---

## [Elastic Agent in Fleet producing 1000s of log entries per hours about CA certs](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576)

<div class="topic-metadata">

**Author:** [@fstlouis](https://discuss.elastic.co/u/fstlouis)\
**Replies:** 4\
**Last updated:** [December 5, 2024, 9:38pm UTC](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576 "2024-12-05T21:38:15Z")

</div>

I'm starting an on premise Elastic 8.12 deployment. I'm using Fleet managed agents with my own certificates (Entrust). I currentely have about 10 agents enrolled. I've noticed that I'm getting a very high volume of th…

---

## [Variable Width Histogram not working with top hits subaggregation](https://discuss.elastic.co/t/variable-width-histogram-not-working-with-top-hits-subaggregation/370865)

<div class="topic-metadata">

**Author:** [@vijay267](https://discuss.elastic.co/u/vijay267)\
**Replies:** 2\
**Last updated:** [December 5, 2024, 8:43pm UTC](https://discuss.elastic.co/t/variable-width-histogram-not-working-with-top-hits-subaggregation/370865 "2024-12-05T20:43:57Z")

</div>

I'm trying to use variable width histogram to group results with similar relevance scores and then apply a secondary sort on them via a top hits aggregation. This is so that folks can sort on relevance and then also sort…

---

## [Purpose of "Data Retention" in index template](https://discuss.elastic.co/t/purpose-of-data-retention-in-index-template/371552)

<div class="topic-metadata">

**Author:** [@Stephen\_IAnson](https://discuss.elastic.co/u/Stephen_IAnson)\
**Replies:** 2\
**Last updated:** [December 5, 2024, 5:15pm UTC](https://discuss.elastic.co/t/purpose-of-data-retention-in-index-template/371552 "2024-12-05T17:15:02Z")

</div>

Hi, Can someone explain to me what the purpose of the data retention field is in an index template? My understanding is that the ILM is responsible for moving data between phases, rollover and optionally deletion. What…

---

## [ELK Replication- Doc count mismatch between the leader & follower](https://discuss.elastic.co/t/elk-replication-doc-count-mismatch-between-the-leader-follower/371546)

<div class="topic-metadata">

**Author:** [@sudhakartata](https://discuss.elastic.co/u/sudhakartata)\
**Replies:** 0\
**Last updated:** [December 5, 2024, 3:40pm UTC](https://discuss.elastic.co/t/elk-replication-doc-count-mismatch-between-the-leader-follower/371546 "2024-12-05T15:40:17Z")

</div>

The doc count in the follower is less than the count from leader. Is that normal? Or is that an issue that needs to be looked into? Was wondering it's a bug. Any help is appreciated

---

## [How to apply new ILM policy to existing datastream index](https://discuss.elastic.co/t/how-to-apply-new-ilm-policy-to-existing-datastream-index/371531)

<div class="topic-metadata">

**Author:** [@racitup](https://discuss.elastic.co/u/racitup)\
**Replies:** 1\
**Last updated:** [December 5, 2024, 11:55am UTC](https://discuss.elastic.co/t/how-to-apply-new-ilm-policy-to-existing-datastream-index/371531 "2024-12-05T11:55:37Z")

</div>

I found several posts about this topic but none gave the actual answer, so thought I would post: I had an existing index on a datastream (filebeat) which had the default 30d ILM policy assigned, but was growing large. I…

---

## [Kibana cannot reach the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-reach-the-elastic-package-registry-which-provides-elastic-agent-integrations/371515)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [December 5, 2024, 9:10am UTC](https://discuss.elastic.co/t/kibana-cannot-reach-the-elastic-package-registry-which-provides-elastic-agent-integrations/371515 "2024-12-05T09:10:56Z")

</div>

ever since I using configure own Elastic Package Registry I got issue relate to add integration from Agent policy I'am tries configure kibana.yml xpack.fleet.registryUrl: "http://10.0.xx.xx:8080" And log form…

---

## [Use plygon that is beyond the geographic scope to query](https://discuss.elastic.co/t/use-plygon-that-is-beyond-the-geographic-scope-to-query/371514)

<div class="topic-metadata">

**Author:** [@baiwenbo1997](https://discuss.elastic.co/u/baiwenbo1997)\
**Replies:** 0\
**Last updated:** [December 5, 2024, 8:29am UTC](https://discuss.elastic.co/t/use-plygon-that-is-beyond-the-geographic-scope-to-query/371514 "2024-12-05T08:29:37Z")

</div>

{"query":{"bool":{"filter":\[{"geo\_shape":{"GEOMETRY":{"shape":{"type":"Polygon","coordinates":\[\[\[-322.2866440677966,-206.98235202086046\],\[330.89735593220339,-206.98235202086046\],\[330.89735593220339,141.32567405475886\],\[-…

---

## [Only the number of containers are showing in the Metricbeat default dashboard, but no other metrics are appearing](https://discuss.elastic.co/t/only-the-number-of-containers-are-showing-in-the-metricbeat-default-dashboard-but-no-other-metrics-are-appearing/371512)

<div class="topic-metadata">

**Author:** [@abhishekacharya828](https://discuss.elastic.co/u/abhishekacharya828)\
**Replies:** 0\
**Last updated:** [December 5, 2024, 7:30am UTC](https://discuss.elastic.co/t/only-the-number-of-containers-are-showing-in-the-metricbeat-default-dashboard-but-no-other-metrics-are-appearing/371512 "2024-12-05T07:30:19Z")

</div>

Metricbeat Logs Dec 05 12:48:26 APMOSYSLT0817 metricbeat\[82993\]: strong text{"log.level":"warn","@timestamp":"2024-12-05T12:48:26.136+0530","log.logger":"elasticsearch","log.origin":{"function":"github.com/elastic/be…

---

## [ES snapshot restore from s3 bucket](https://discuss.elastic.co/t/es-snapshot-restore-from-s3-bucket/371507)

<div class="topic-metadata">

**Author:** [@ashadujjaman](https://discuss.elastic.co/u/ashadujjaman)\
**Replies:** 0\
**Last updated:** [December 5, 2024, 5:58am UTC](https://discuss.elastic.co/t/es-snapshot-restore-from-s3-bucket/371507 "2024-12-05T05:58:31Z")

</div>

Please let me know. My 15 Node ES cluster hosted in AWS ec2 instant, This snapshot save in s3 bucket regular basis a periodic time. Snapshot size more than 1 TB and every index size more than 20GB. I want to create anoth…

---

## [What is the key of elasticsearch Query Cache](https://discuss.elastic.co/t/what-is-the-key-of-elasticsearch-query-cache/371506)

<div class="topic-metadata">

**Author:** [@ChatLee](https://discuss.elastic.co/u/ChatLee)\
**Replies:** 0\
**Last updated:** [December 5, 2024, 5:44am UTC](https://discuss.elastic.co/t/what-is-the-key-of-elasticsearch-query-cache/371506 "2024-12-05T05:44:25Z")

</div>

Hi team, About the query cache, we want to the answers to the following questions: index.queries.cache.enabled=true would active all caches, right? like, node cache, shard cache and other stuff how to construct the ca…

---

## [Create Separate index for each logfile](https://discuss.elastic.co/t/create-separate-index-for-each-logfile/371493)

<div class="topic-metadata">

**Author:** [@nitesh.srivastava](https://discuss.elastic.co/u/nitesh.srivastava)\
**Replies:** 0\
**Last updated:** [December 4, 2024, 11:50pm UTC](https://discuss.elastic.co/t/create-separate-index-for-each-logfile/371493 "2024-12-04T23:50:39Z")

</div>

Hello ppl, I have a Filebeat \> Logstash \> Elasticsearch set up in my environment where we are collecting logs data by installing Filebeat and forwarding the data via logstash input. However, we have a peculiar situation…

---

## [Trying to use an alphabetical bucket sort within a terms aggregation](https://discuss.elastic.co/t/trying-to-use-an-alphabetical-bucket-sort-within-a-terms-aggregation/371490)

<div class="topic-metadata">

**Author:** [@JoshFarwig](https://discuss.elastic.co/u/JoshFarwig)\
**Replies:** 0\
**Last updated:** [December 4, 2024, 10:27pm UTC](https://discuss.elastic.co/t/trying-to-use-an-alphabetical-bucket-sort-within-a-terms-aggregation/371490 "2024-12-04T22:27:34Z")

</div>

Hey! I am currently using Elasticsearch 8.15. I am in a bit of a conundrum trying to achieve outer and inner bucket sorting for strings (sorted asc or desc alphabetically). My index, hazard, looks a little something like…

---

## [Time\_zone in sql query](https://discuss.elastic.co/t/time-zone-in-sql-query/371471)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [December 4, 2024, 10:02pm UTC](https://discuss.elastic.co/t/time-zone-in-sql-query/371471 "2024-12-04T22:02:47Z")

</div>

I have metricbeat time series data. time field is @timestamp due to BST and UTC time difference of one hour I can't get data GET \_sql?format=txt { "query": """ select host.name as host, from "my-metr…

---

## [Fleet searching on policy names](https://discuss.elastic.co/t/fleet-searching-on-policy-names/371489)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [December 4, 2024, 9:57pm UTC](https://discuss.elastic.co/t/fleet-searching-on-policy-names/371489 "2024-12-04T21:57:52Z")

</div>

Searching on policy names like ingest-agent-policies.name : name seems to be case sensitive, that finds nothing, but ingest-agent-policies.name : NAME Finds the policies. Searching in fleet seems clumsy, it see…

---

## [Finding out cause of circuit breaking exception (Data too large)](https://discuss.elastic.co/t/finding-out-cause-of-circuit-breaking-exception-data-too-large/351217)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 4\
**Last updated:** [December 4, 2024, 9:36pm UTC](https://discuss.elastic.co/t/finding-out-cause-of-circuit-breaking-exception-data-too-large/351217 "2024-12-04T21:36:25Z")

</div>

Hi, I'm getting the error below occasionally, and I'm trying to find the cause of it so I can try to resolve it. circuit\_breaking\_exception: \[parent\] Data too large, data for \[\<http\_request\>\] would be \[32620387928/30.3…

---

## [\[KNN\] Semantics Affected by Phrase Similarity](https://discuss.elastic.co/t/knn-semantics-affected-by-phrase-similarity/370180)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 5\
**Last updated:** [December 4, 2024, 1:11pm UTC](https://discuss.elastic.co/t/knn-semantics-affected-by-phrase-similarity/370180 "2024-12-04T13:11:50Z")

</div>

I'm implementing a semantic search for product names, aiming to allow searches based on user intent. However, I'm observing that semantically, it retrieves fragmented data within the text. For example, when searching for…

---

## [Could not index event to Elasticsearch](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/371385)

<div class="topic-metadata">

**Author:** [@deepika\_raghav](https://discuss.elastic.co/u/deepika_raghav)\
**Replies:** 2\
**Last updated:** [December 4, 2024, 11:52am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/371385 "2024-12-04T11:52:06Z")

</div>

hi I am facing issues while trying to create an index by querying microsoft sql server and the error I am facing as follows Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"…

---

## [Elasticsearch log show kibana\_version\_mismatch](https://discuss.elastic.co/t/elasticsearch-log-show-kibana-version-mismatch/371190)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 11\
**Last updated:** [December 4, 2024, 7:57am UTC](https://discuss.elastic.co/t/elasticsearch-log-show-kibana-version-mismatch/371190 "2024-12-04T07:57:54Z")

</div>

Dears, In elasticsearch log file there is many errors like this: \[2024-11-28T14:17:45,307\]\[ERROR\]\[o.e.x.w.i.s.ExecutableSearchInput\] \[elastic03\] failed to execute \[search\] input for watch \[kfkGWL45QVSehYfLGLGl8g\_kibana…

---

## [Converting Logstash Pipeline to Ingest Pipeline](https://discuss.elastic.co/t/converting-logstash-pipeline-to-ingest-pipeline/371416)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 8\
**Last updated:** [December 4, 2024, 6:53am UTC](https://discuss.elastic.co/t/converting-logstash-pipeline-to-ingest-pipeline/371416 "2024-12-04T06:53:13Z")

</div>

Hello, I have countless of logstash pipelines or logstash filter configs to be more exact. Is there a way to migrate these into ingest pipelines, quickly? I know they offer the same features but is it possible to do t…

---

## [Backup Old data Instead of Deleting](https://discuss.elastic.co/t/backup-old-data-instead-of-deleting/371438)

<div class="topic-metadata">

**Author:** [@Aswath\_Kumar](https://discuss.elastic.co/u/Aswath_Kumar)\
**Replies:** 0\
**Last updated:** [December 4, 2024, 6:31am UTC](https://discuss.elastic.co/t/backup-old-data-instead-of-deleting/371438 "2024-12-04T06:31:20Z")

</div>

Hi , We are having some important data in a particular index. But this index keep growing and Queries became slow. Is there anyway to keep only last 30 days of data and rest of the data move to snapshot in s3 This must…

---

## [Create repository with huawei hdfs](https://discuss.elastic.co/t/create-repository-with-huawei-hdfs/371435)

<div class="topic-metadata">

**Author:** [@carpeDiem](https://discuss.elastic.co/u/carpeDiem)\
**Replies:** 0\
**Last updated:** [December 4, 2024, 6:20am UTC](https://discuss.elastic.co/t/create-repository-with-huawei-hdfs/371435 "2024-12-04T06:20:41Z")

</div>

Hello experts,. I am using Huawei Cloud's MapReduce service, which includes a hadoop cluster with kerberos started. I downloaded the authentication credentials, including krb5.conf and krb5.keytab, and placed the files i…

---

## [LTR Plugin in Newer Versions of Elasticsearch](https://discuss.elastic.co/t/ltr-plugin-in-newer-versions-of-elasticsearch/370908)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 2\
**Last updated:** [December 3, 2024, 11:26pm UTC](https://discuss.elastic.co/t/ltr-plugin-in-newer-versions-of-elasticsearch/370908 "2024-12-03T23:26:14Z")

</div>

I am trying to implement LTR (Learning to Rank) with a machine learning model. However, for some reason, the training with the judgment list is not succeeding. The LTR is not respecting my judgment list configuration wit…

---

## [Elasticsearch 8.15.3 and Connectors 9.0.0 are incompatible: major versions are different](https://discuss.elastic.co/t/elasticsearch-8-15-3-and-connectors-9-0-0-are-incompatible-major-versions-are-different/371396)

<div class="topic-metadata">

**Author:** [@dev8100](https://discuss.elastic.co/u/dev8100)\
**Replies:** 2\
**Last updated:** [December 3, 2024, 9:14pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-3-and-connectors-9-0-0-are-incompatible-major-versions-are-different/371396 "2024-12-03T21:14:33Z")

</div>

I'm running into the issue below. I'm really not clear on how to modify the version of the connector service since I haven't built one before and can really use some help \[FMWK\]\[14:22:30\]\[INFO\] Running connector service…

---

## [Question on Date Processor](https://discuss.elastic.co/t/question-on-date-processor/371420)

<div class="topic-metadata">

**Author:** [@thejackal2020](https://discuss.elastic.co/u/thejackal2020)\
**Replies:** 0\
**Last updated:** [December 3, 2024, 8:43pm UTC](https://discuss.elastic.co/t/question-on-date-processor/371420 "2024-12-03T20:43:11Z")

</div>

I have a field that is currently set as 'keyword' and I want to convert it to be 'date'. I have added the Date processor in my ingest pipeline. I have set the formats to be "YYYY-MM-dd HH:mm:ss,SSS" I have the target …

---

## [Unable to get kubernetes metrics using metric beat in kibana](https://discuss.elastic.co/t/unable-to-get-kubernetes-metrics-using-metric-beat-in-kibana/371411)

<div class="topic-metadata">

**Author:** [@Sam96](https://discuss.elastic.co/u/Sam96)\
**Replies:** 1\
**Last updated:** [December 3, 2024, 7:44pm UTC](https://discuss.elastic.co/t/unable-to-get-kubernetes-metrics-using-metric-beat-in-kibana/371411 "2024-12-03T19:44:59Z")

</div>

I have installed the Elasticsearch(8.16) and kibana(8.16) using RPMs in Centos vm.Also installed Metricbeats (8.16) in the centos vm using RPMS. In the same vm i have kubernetes cluster and our application is running in…

---

## [Fleet error updating policy settings](https://discuss.elastic.co/t/fleet-error-updating-policy-settings/371332)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 1\
**Last updated:** [December 3, 2024, 11:50am UTC](https://discuss.elastic.co/t/fleet-error-updating-policy-settings/371332 "2024-12-03T11:50:17Z")

</div>

I'm getting this error after 8.16.0 in Fleet when changing anything on the Settings tab: \[request body.monitoring\_http.enabled\]: expected value of type \[boolean\] but got \[undefined\] It looks like "monitoring\_http" is…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=57)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=59)
