# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=6

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 7

---

## [Is APM required for Elasticsearch 8.19.8?](https://discuss.elastic.co/t/is-apm-required-for-elasticsearch-8-19-8/385522)

<div class="topic-metadata">

**Author:** [@winter\_crescents](https://discuss.elastic.co/u/winter_crescents)\
**Replies:** 3\
**Last updated:** [March 20, 2026, 9:59am UTC](https://discuss.elastic.co/t/is-apm-required-for-elasticsearch-8-19-8/385522 "2026-03-20T09:59:36Z")

</div>

I am trying to reduce the number of modules to the minimum number required. However, I find that when apm module is being removed, I get an error that says “ERROR: Expected to find \[apm\] module” and this got me confused,…

---

## [Azure Cloud collect k8s logs](https://discuss.elastic.co/t/azure-cloud-collect-k8s-logs/385512)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 2\
**Last updated:** [March 19, 2026, 10:23pm UTC](https://discuss.elastic.co/t/azure-cloud-collect-k8s-logs/385512 "2026-03-19T22:23:47Z")

</div>

Hey guys! What is the recommended way to collect logs from Azure Cloud AKS and deliver them to the desired Elastic instance deployed outside Azure Cloud? I have already checked this page: and corresponding integrati…

---

## [Understand the impact on the document writing process after setting index.translog.durability=true](https://discuss.elastic.co/t/understand-the-impact-on-the-document-writing-process-after-setting-index-translog-durability-true/385517)

<div class="topic-metadata">

**Author:** [@mloine](https://discuss.elastic.co/u/mloine)\
**Replies:** 1\
**Last updated:** [March 19, 2026, 6:17am UTC](https://discuss.elastic.co/t/understand-the-impact-on-the-document-writing-process-after-setting-index-translog-durability-true/385517 "2026-03-19T06:17:51Z")

</div>

After setting index.translog.durability=true, the time to successfully respond to the client is whether to respond to the client as long as the primary shard is successful without shutting down the replicas, or to respon…

---

## [How to use opentelemetry for search analytics](https://discuss.elastic.co/t/how-to-use-opentelemetry-for-search-analytics/385509)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 0\
**Last updated:** [March 18, 2026, 4:29pm UTC](https://discuss.elastic.co/t/how-to-use-opentelemetry-for-search-analytics/385509 "2026-03-18T16:29:48Z")

</div>

How to use opentelemetry for search analytics with java client

---

## [AI Assistant - Need to add a new LLM to Elastic](https://discuss.elastic.co/t/ai-assistant-need-to-add-a-new-llm-to-elastic/385506)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 0\
**Last updated:** [March 18, 2026, 1:02pm UTC](https://discuss.elastic.co/t/ai-assistant-need-to-add-a-new-llm-to-elastic/385506 "2026-03-18T13:02:47Z")

</div>

Hi Team, We are currently using Elasticsearch within our ELK platform to reconcile data received from multiple source systems. This is implemented using Elasticsearch transforms, where we compare data across multiple sy…

---

## [Anomaly Detection Jobs - Various warning messages](https://discuss.elastic.co/t/anomaly-detection-jobs-various-warning-messages/385501)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 3\
**Last updated:** [March 18, 2026, 9:49am UTC](https://discuss.elastic.co/t/anomaly-detection-jobs-various-warning-messages/385501 "2026-03-18T09:49:02Z")

</div>

We are seeing various warning message below. Is there a guide to kickstart how we can kick start our troubleshooting? Warning datafeed is encountering errors submitting data for analysis exception while flushing jobs …

---

## [Different responses for search with terms query and get document by id](https://discuss.elastic.co/t/different-responses-for-search-with-terms-query-and-get-document-by-id/385114)

<div class="topic-metadata">

**Author:** [@jprucia](https://discuss.elastic.co/u/jprucia)\
**Replies:** 5\
**Last updated:** [March 17, 2026, 12:42pm UTC](https://discuss.elastic.co/t/different-responses-for-search-with-terms-query-and-get-document-by-id/385114 "2026-03-17T12:42:25Z")

</div>

Here is the scenario: app is running an integration test and is spinning up docker container using official docker image, version 8.7.0. When it’s up nd running, test doest its setup (it is using Spring Data Elasticsearc…

---

## [Upgrading from ES 7.17.8 to 8.19.8](https://discuss.elastic.co/t/upgrading-from-es-7-17-8-to-8-19-8/385475)

<div class="topic-metadata">

**Author:** [@winter\_crescents](https://discuss.elastic.co/u/winter_crescents)\
**Replies:** 1\
**Last updated:** [March 17, 2026, 8:08am UTC](https://discuss.elastic.co/t/upgrading-from-es-7-17-8-to-8-19-8/385475 "2026-03-17T08:08:36Z")

</div>

I have recently tried to upgrade Elasticsearch from version 7.17.8 to 8.19.8. However, I am facing this error: java.io.EOFException at org.elasticsearch.common.io.stream.InputStreamStreamInput.readByte(InputStreamStre…

---

## [Repository URL Changed: /packages/x.x/yum/ No Longer Working - Official Documentation Needed](https://discuss.elastic.co/t/repository-url-changed-packages-x-x-yum-no-longer-working-official-documentation-needed/385469)

<div class="topic-metadata">

**Author:** [@ven\_off](https://discuss.elastic.co/u/ven_off)\
**Replies:** 0\
**Last updated:** [March 16, 2026, 1:41pm UTC](https://discuss.elastic.co/t/repository-url-changed-packages-x-x-yum-no-longer-working-official-documentation-needed/385469 "2026-03-16T13:41:22Z")

</div>

Hello Elasticsearch Community, We're experiencing issues syncing Elasticsearch packages from the official repository and have discovered that the repository URL structure has changed Problem: Our mirrors server is con…

---

## [Generated reports no access for user with limited index patterns](https://discuss.elastic.co/t/generated-reports-no-access-for-user-with-limited-index-patterns/368092)

<div class="topic-metadata">

**Author:** [@tomaszde](https://discuss.elastic.co/u/tomaszde)\
**Replies:** 4\
**Last updated:** [March 16, 2026, 10:37am UTC](https://discuss.elastic.co/t/generated-reports-no-access-for-user-with-limited-index-patterns/368092 "2026-03-16T10:37:58Z")

</div>

Hi, I'm having issue with generated reports. When use the user with the role that have read access to \* index pattern, report is generated with data. But if a role only have access to specific index pattern eg. mylogs-…

---

## [Remove semantic duplicates in retrieval](https://discuss.elastic.co/t/remove-semantic-duplicates-in-retrieval/385456)

<div class="topic-metadata">

**Author:** [@alexander.korkhov](https://discuss.elastic.co/u/alexander.korkhov)\
**Replies:** 0\
**Last updated:** [March 15, 2026, 5:30pm UTC](https://discuss.elastic.co/t/remove-semantic-duplicates-in-retrieval/385456 "2026-03-15T17:30:22Z")

</div>

ElasticSeach indexes poster events retrieved from different sources. The same event (for example, a performance) can be retrieved from different sources. Is it possible to somehow organize the data retrieval so that only…

---

## [Get unique words (tokens ?) from all text fields from all documents in an Index](https://discuss.elastic.co/t/get-unique-words-tokens-from-all-text-fields-from-all-documents-in-an-index/385424)

<div class="topic-metadata">

**Author:** [@sivakumarp11](https://discuss.elastic.co/u/sivakumarp11)\
**Replies:** 3\
**Last updated:** [March 15, 2026, 5:26am UTC](https://discuss.elastic.co/t/get-unique-words-tokens-from-all-text-fields-from-all-documents-in-an-index/385424 "2026-03-15T05:26:40Z")

</div>

Is there a way to get list of ‘unique’ words Or terms used in a large text field in ALL the documents ? for ex. if the text field has content like ‘It is the most confidential because confidential or transcendental knowl…

---

## [Is it possible to Downsamp to a list of keyword values!](https://discuss.elastic.co/t/is-it-possible-to-downsamp-to-a-list-of-keyword-values/385393)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 1\
**Last updated:** [March 15, 2026, 3:37am UTC](https://discuss.elastic.co/t/is-it-possible-to-downsamp-to-a-list-of-keyword-values/385393 "2026-03-15T03:37:21Z")

</div>

Hello everyone, I have a time series data stream (TSDS) set up with downsampling configured via ILM (e.g. downsample to 1d intervals daily). The index template is correctly marked with time\_series\_dimension. My data in…

---

## [Using gMSA account to create API key for Elasticsearch ingestion](https://discuss.elastic.co/t/using-gmsa-account-to-create-api-key-for-elasticsearch-ingestion/385445)

<div class="topic-metadata">

**Author:** [@Vishal\_Reddy\_P](https://discuss.elastic.co/u/Vishal_Reddy_P)\
**Replies:** 1\
**Last updated:** [March 14, 2026, 12:49am UTC](https://discuss.elastic.co/t/using-gmsa-account-to-create-api-key-for-elasticsearch-ingestion/385445 "2026-03-14T00:49:50Z")

</div>

Earlier we used a service account to log into Kibana and create an API key for log ingestion or reading events. Now we are moving to a gMSA (Group Managed Service Account) which is passwordless and cannot log in interac…

---

## [Downsampling only works one time](https://discuss.elastic.co/t/downsampling-only-works-one-time/375708)

<div class="topic-metadata">

**Author:** [@bstinchcomb](https://discuss.elastic.co/u/bstinchcomb)\
**Replies:** 1\
**Last updated:** [March 13, 2026, 2:43pm UTC](https://discuss.elastic.co/t/downsampling-only-works-one-time/375708 "2026-03-13T14:43:22Z")

</div>

Hello, I am running into an issue with elasticsearch where downsampling will only run a single time, and then subsequent runs seems to just create an empty index. I have tried several different docker versions and still …

---

## [Does the .tasks index still exist in ES 8 and beyond?](https://discuss.elastic.co/t/does-the-tasks-index-still-exist-in-es-8-and-beyond/385426)

<div class="topic-metadata">

**Author:** [@davysteegen](https://discuss.elastic.co/u/davysteegen)\
**Replies:** 2\
**Last updated:** [March 12, 2026, 8:19pm UTC](https://discuss.elastic.co/t/does-the-tasks-index-still-exist-in-es-8-and-beyond/385426 "2026-03-12T20:19:49Z")

</div>

Hi, We are in the process of migrating our ES 7 to ES 8. The Java application that connects to the elasticsearch had a job that periodically removed all documents from the system .tasks index where the completed flag is…

---

## [Best way to store document chunks for vector search as production standard](https://discuss.elastic.co/t/best-way-to-store-document-chunks-for-vector-search-as-production-standard/385414)

<div class="topic-metadata">

**Author:** [@grunggy](https://discuss.elastic.co/u/grunggy)\
**Replies:** 2\
**Last updated:** [March 12, 2026, 5:43pm UTC](https://discuss.elastic.co/t/best-way-to-store-document-chunks-for-vector-search-as-production-standard/385414 "2026-03-12T17:43:33Z")

</div>

Hi, working on a RAG setup and trying to land on a sensible production architecture for chunk storage and retrieval. Curious what others are running at scale. Large documents get split into chunks at ingestion, each chu…

---

## [Wildcard phrases with slop using string query](https://discuss.elastic.co/t/wildcard-phrases-with-slop-using-string-query/385418)

<div class="topic-metadata">

**Author:** [@S-Dragon0302](https://discuss.elastic.co/u/S-Dragon0302)\
**Replies:** 1\
**Last updated:** [March 12, 2026, 8:29am UTC](https://discuss.elastic.co/t/wildcard-phrases-with-slop-using-string-query/385418 "2026-03-12T08:29:31Z")

</div>

Is this kind of query still not supported. This won't work. "query\_string": { "fields": \[ "nickname" \], "query": "content:\\"hello\\" AND \\"Rodan Fields?\\"", "default\_operator": "AND" } Writing "slop" like this w…

---

## [Error Migration 8.19.12 -\> 9.1.3](https://discuss.elastic.co/t/error-migration-8-19-12-9-1-3/385410)

<div class="topic-metadata">

**Author:** [@M1ghty1](https://discuss.elastic.co/u/M1ghty1)\
**Replies:** 5\
**Last updated:** [March 11, 2026, 12:24pm UTC](https://discuss.elastic.co/t/error-migration-8-19-12-9-1-3/385410 "2026-03-11T12:24:55Z")

</div>

I am currently migrating from elasticsearch 8.19.12 to 9.1.3. I fixed the issues in upgrade assistant in 8.19.12, created a snapshot which is valid (status = SUCCESS). But when i try to import the snapshot in 9.1.3 i ge…

---

## [Limitations of ElasticSearch & Kibana Combination](https://discuss.elastic.co/t/limitations-of-elasticsearch-kibana-combination/382039)

<div class="topic-metadata">

**Author:** [@geoffrey](https://discuss.elastic.co/u/geoffrey)\
**Replies:** 14\
**Last updated:** [March 11, 2026, 7:19am UTC](https://discuss.elastic.co/t/limitations-of-elasticsearch-kibana-combination/382039 "2026-03-11T07:19:51Z")

</div>

Hi everyone, Im here as a 5 day old user of Elasticsearch + Kibana user and have given it a lot of time over this period. One thing which strikes me as a real limitation I am running into is that as a general rule of t…

---

## [Clarification about frozen data on k8s](https://discuss.elastic.co/t/clarification-about-frozen-data-on-k8s/385397)

<div class="topic-metadata">

**Author:** [@Cario](https://discuss.elastic.co/u/Cario)\
**Replies:** 0\
**Last updated:** [March 10, 2026, 3:51pm UTC](https://discuss.elastic.co/t/clarification-about-frozen-data-on-k8s/385397 "2026-03-10T15:51:13Z")

</div>

Hello everyone, I am new to the forum and basically self-taught, so I apologize in advance if I lack some basic knowledge. Thank you for your understanding. The elastic cluster works on a k8s cluster as pods, but readi…

---

## [Dynamic template mapping overridden by automatic \`dense\_vector\` inference for float arrays](https://discuss.elastic.co/t/dynamic-template-mapping-overridden-by-automatic-dense-vector-inference-for-float-arrays/385359)

<div class="topic-metadata">

**Author:** [@giga811](https://discuss.elastic.co/u/giga811)\
**Replies:** 3\
**Last updated:** [March 7, 2026, 6:16am UTC](https://discuss.elastic.co/t/dynamic-template-mapping-overridden-by-automatic-dense-vector-inference-for-float-arrays/385359 "2026-03-07T06:16:54Z")

</div>

I encountered a situation where a dynamic template specifying a field as float is overridden by automatic dense\_vector mapping when indexing a long float array in Elasticsearch. My intention is to store embeddings as a …

---

## [Lots of shards relocating post restore](https://discuss.elastic.co/t/lots-of-shards-relocating-post-restore/385356)

<div class="topic-metadata">

**Author:** [@ch4zzych4zz](https://discuss.elastic.co/u/ch4zzych4zz)\
**Replies:** 6\
**Last updated:** [March 6, 2026, 2:00pm UTC](https://discuss.elastic.co/t/lots-of-shards-relocating-post-restore/385356 "2026-03-06T14:00:37Z")

</div>

Hi, I’m struggling to repetitively backup and restore efficiently indices between two independent ES clusters as this is causing a lot of shards rebalancing. The setup is as follows: ES 8.19 cluster composed of 11 no…

---

## [POST /\_fleet/maintenance/cleanup?](https://discuss.elastic.co/t/post-fleet-maintenance-cleanup/385355)

<div class="topic-metadata">

**Author:** [@Juan\_de\_Dios\_Macias1](https://discuss.elastic.co/u/Juan_de_Dios_Macias1)\
**Replies:** 1\
**Last updated:** [March 6, 2026, 4:48am UTC](https://discuss.elastic.co/t/post-fleet-maintenance-cleanup/385355 "2026-03-06T04:48:58Z")

</div>

Hi, I have a cluster with a single node where I’m seeing some indices that I can’t delete because Elasticsearch tells me that my elastic user needs superuser permissions. I found the API request POST /\_fleet/maintenance/…

---

## [Parent data too large?](https://discuss.elastic.co/t/parent-data-too-large/385254)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 12\
**Last updated:** [March 5, 2026, 10:21am UTC](https://discuss.elastic.co/t/parent-data-too-large/385254 "2026-03-05T10:21:45Z")

</div>

I am getting the below error on a shard assignment. org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[internal:index/shard/recovery/translog\_ops\] would be \[28701173408/26.7gb\]…

---

## [Troubleshooting performance and load](https://discuss.elastic.co/t/troubleshooting-performance-and-load/385292)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 16\
**Last updated:** [March 5, 2026, 7:23am UTC](https://discuss.elastic.co/t/troubleshooting-performance-and-load/385292 "2026-03-05T07:23:57Z")

</div>

Is there a centralise repository or knowledge base that we can start for general troubelshooting. For scenrios not limiting to below. Elastic fleet server Health Check. What are the things to watch out for? Overlo…

---

## [Setting up self managed ELK stack with TLS/HTTPS issue](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102)

<div class="topic-metadata">

**Author:** [@BenNCSU](https://discuss.elastic.co/u/BenNCSU)\
**Replies:** 11\
**Last updated:** [March 5, 2026, 2:16am UTC](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102 "2026-03-05T02:16:44Z")

</div>

I’m trying to set up an ELK stack for SIEM doing a standard install. I installed Elasticsearch and Kibana, which worked fine using HTTP, but when I tried to set up TLS using a self-signed certificate from our CA, I can’…

---

## [Same \_id ends up duplicated across rollover indices behind a write alias — can this be prevented via template/ILM?](https://discuss.elastic.co/t/same-id-ends-up-duplicated-across-rollover-indices-behind-a-write-alias-can-this-be-prevented-via-template-ilm/385348)

<div class="topic-metadata">

**Author:** [@juan\_ma\_tejada](https://discuss.elastic.co/u/juan_ma_tejada)\
**Replies:** 1\
**Last updated:** [March 4, 2026, 7:34pm UTC](https://discuss.elastic.co/t/same-id-ends-up-duplicated-across-rollover-indices-behind-a-write-alias-can-this-be-prevented-via-template-ilm/385348 "2026-03-04T19:34:01Z")

</div>

Hi all, I’m indexing documents into Elasticsearch using a deterministic \_id (SHA1 of email + normalized\_context). I write to an alias that uses ILM rollover, so over time it creates backing indices like: data-000073 …

---

## [Dashboard anomaly score is not what we wanted](https://discuss.elastic.co/t/dashboard-anomaly-score-is-not-what-we-wanted/385336)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 1\
**Last updated:** [March 4, 2026, 5:38pm UTC](https://discuss.elastic.co/t/dashboard-anomaly-score-is-not-what-we-wanted/385336 "2026-03-04T17:38:49Z")

</div>

We create a dashboard which return a single column to show actual, typical, anomaly score Apparently, the actual is the highest(actual) the typical is the highest(typical) The anomaly score is calculated based on the t…

---

## [Anomoly detection jobs. latest timestamp is updating but more than 2 months back](https://discuss.elastic.co/t/anomoly-detection-jobs-latest-timestamp-is-updating-but-more-than-2-months-back/385311)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 3\
**Last updated:** [March 4, 2026, 5:15pm UTC](https://discuss.elastic.co/t/anomoly-detection-jobs-latest-timestamp-is-updating-but-more-than-2-months-back/385311 "2026-03-04T17:15:09Z")

</div>

Being a newbie to ML. Can anyone advice where I should start troubleshooting? job-name:noise-reduction-system-metrics-consolidated job state: opened. memory status: ok. latest timestamp is updating but more than 2 mo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=5)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=7)
