# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=60

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 61

---

## [ES|QL Grok parsing](https://discuss.elastic.co/t/es-ql-grok-parsing/371171)

<div class="topic-metadata">

**Author:** [@fitastronaut](https://discuss.elastic.co/u/fitastronaut)\
**Replies:** 1\
**Last updated:** [November 28, 2024, 10:42am UTC](https://discuss.elastic.co/t/es-ql-grok-parsing/371171 "2024-11-28T10:42:18Z")

</div>

Hello all, I have this raw log which I want to parse using GROK. I tried this but can't get it to parse. Appreciate any help I get :slight\_smile: Sample Data 2024-11-05 08:36:53 UTC:ip-10-0-1-111.ap-southeast-1.co…

---

## [OIDC Login Problem](https://discuss.elastic.co/t/oidc-login-problem/371063)

<div class="topic-metadata">

**Author:** [@cafuego](https://discuss.elastic.co/u/cafuego)\
**Replies:** 3\
**Last updated:** [November 28, 2024, 10:19am UTC](https://discuss.elastic.co/t/oidc-login-problem/371063 "2024-11-28T10:19:23Z")

</div>

After updating from 8.15.3 to 8.16.1 today, we found we were unable to login to Kibana via our SSO server. Instead we got the message "We hit an authentication error". After a bunch of digging, I eventually found an err…

---

## [Can I have 2 analyzer for the same field in the document?](https://discuss.elastic.co/t/can-i-have-2-analyzer-for-the-same-field-in-the-document/371165)

<div class="topic-metadata">

**Author:** [@Hooman\_Bahreini](https://discuss.elastic.co/u/Hooman_Bahreini)\
**Replies:** 0\
**Last updated:** [November 28, 2024, 5:17am UTC](https://discuss.elastic.co/t/can-i-have-2-analyzer-for-the-same-field-in-the-document/371165 "2024-11-28T05:17:35Z")

</div>

I am using Elasticsearch for a search jobs. Jobs have Title, Description, company and Location, as shown below: I am using english\_analyzer for Title and Description and keyword\_analizer for company and location, as sho…

---

## [Mongo db + elastic](https://discuss.elastic.co/t/mongo-db-elastic/371164)

<div class="topic-metadata">

**Author:** [@yahimin](https://discuss.elastic.co/u/yahimin)\
**Replies:** 0\
**Last updated:** [November 28, 2024, 5:09am UTC](https://discuss.elastic.co/t/mongo-db-elastic/371164 "2024-11-28T05:09:34Z")

</div>

I am trying to implement a search function using elastic. The general search filtering function and search function are functions found in shopping apps. What I'm curious about is whether it's the right choice to manag…

---

## [Resolving Message Queue Clogs in Elasticsearch with Informatica C360](https://discuss.elastic.co/t/resolving-message-queue-clogs-in-elasticsearch-with-informatica-c360/363014)

<div class="topic-metadata">

**Author:** [@SelvamaniTaurus](https://discuss.elastic.co/u/SelvamaniTaurus)\
**Replies:** 3\
**Last updated:** [November 27, 2024, 10:42pm UTC](https://discuss.elastic.co/t/resolving-message-queue-clogs-in-elasticsearch-with-informatica-c360/363014 "2024-11-27T22:42:38Z")

</div>

Hello Team, In our organization, we use Informatica C360 for Customer MDM, alongside Elastic Search to implement the Smart Search capability that Informatica provides. While we appreciate the optimized searching techniq…

---

## [Complex order on numerics and filtering](https://discuss.elastic.co/t/complex-order-on-numerics-and-filtering/371143)

<div class="topic-metadata">

**Author:** [@argy](https://discuss.elastic.co/u/argy)\
**Replies:** 0\
**Last updated:** [November 27, 2024, 2:36pm UTC](https://discuss.elastic.co/t/complex-order-on-numerics-and-filtering/371143 "2024-11-27T14:36:22Z")

</div>

Good day, I am developing a solution whereby I will have an index with below documents { "name" : "Powlowski, Schaden and Kuvalis", "financials" : \[ { "revenue\_value\_type" …

---

## [Elastic.Clients.Elasticsearch - Query list of codes](https://discuss.elastic.co/t/elastic-clients-elasticsearch-query-list-of-codes/371156)

<div class="topic-metadata">

**Author:** [@romatos](https://discuss.elastic.co/u/romatos)\
**Replies:** 0\
**Last updated:** [November 27, 2024, 5:20pm UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-query-list-of-codes/371156 "2024-11-27T17:20:54Z")

</div>

Hello, good afternoon, I am using Elastic.Clients.Elasticsearch, but I am unable to perform queries using a list of codes. Here is how I did it: var listaDeValores = new List\<int\> { 1, 2, 3, 4 }; var searchRequest = …

---

## [Need Taco connecter for Elasticsearch version 6.8.23](https://discuss.elastic.co/t/need-taco-connecter-for-elasticsearch-version-6-8-23/371033)

<div class="topic-metadata">

**Author:** [@Chinmay\_Bhusate](https://discuss.elastic.co/u/Chinmay_Bhusate)\
**Replies:** 2\
**Last updated:** [November 27, 2024, 4:22pm UTC](https://discuss.elastic.co/t/need-taco-connecter-for-elasticsearch-version-6-8-23/371033 "2024-11-27T16:22:26Z")

</div>

We are trying to connect tableau with elasticsearch v 6.8.23. But on official website we are only able to see Tableau connecter for Elasticsearch until version 7.9.0. Need to know if elasticsearch provides taco connecte…

---

## [Ingest pipeline (attachment) unable to find base64 encoded field](https://discuss.elastic.co/t/ingest-pipeline-attachment-unable-to-find-base64-encoded-field/371140)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 0\
**Last updated:** [November 27, 2024, 1:44pm UTC](https://discuss.elastic.co/t/ingest-pipeline-attachment-unable-to-find-base64-encoded-field/371140 "2024-11-27T13:44:24Z")

</div>

Hi! I have a very basic ingest pipeline case where I'd like to call an attachment processor. A simple curl -X PUT with provided Json-data works perfectly but when I do the following from my c# code: var response = awai…

---

## [Remove double quotation (") from all fields values](https://discuss.elastic.co/t/remove-double-quotation-from-all-fields-values/371025)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [November 27, 2024, 2:28pm UTC](https://discuss.elastic.co/t/remove-double-quotation-from-all-fields-values/371025 "2024-11-27T14:28:32Z")

</div>

I'm having some issues with normalizing my CEF logs coming over Elastic Agent's CEF integration. To be precise, they're logs from Silverfort, and there's no way to configure detailed logging options on it to remove the …

---

## [When I query 15 minutes of data, it takes 7 seconds, but when I adjust the query time range to 7 days, the query times out. How can I improve the efficiency of the query? The query size=10 is all used. Why does the commissioning time range affect the quer](https://discuss.elastic.co/t/when-i-query-15-minutes-of-data-it-takes-7-seconds-but-when-i-adjust-the-query-time-range-to-7-days-the-query-times-out-how-can-i-improve-the-efficiency-of-the-query-the-query-size-10-is-all-used-why-does-the-commissioning-time-range-affect-the-quer/371108)

<div class="topic-metadata">

**Author:** [@canli12138](https://discuss.elastic.co/u/canli12138)\
**Replies:** 1\
**Last updated:** [November 27, 2024, 11:25am UTC](https://discuss.elastic.co/t/when-i-query-15-minutes-of-data-it-takes-7-seconds-but-when-i-adjust-the-query-time-range-to-7-days-the-query-times-out-how-can-i-improve-the-efficiency-of-the-query-the-query-size-10-is-all-used-why-does-the-commissioning-time-range-affect-the-quer/371108 "2024-11-27T11:25:17Z")

</div>

{ "highlight": { "fields": { "\*": { "pre\_tags": " \[\\"\<span\>\\"\],", "post\_tags": "\[\\"\<\\/span\>\\"\]" } }, "fragment\_size": 2147483647 }, …

---

## [Elastic auto-complete vs normal querying](https://discuss.elastic.co/t/elastic-auto-complete-vs-normal-querying/371119)

<div class="topic-metadata">

**Author:** [@prempatell](https://discuss.elastic.co/u/prempatell)\
**Replies:** 0\
**Last updated:** [November 27, 2024, 7:16am UTC](https://discuss.elastic.co/t/elastic-auto-complete-vs-normal-querying/371119 "2024-11-27T07:16:44Z")

</div>

Hi, I am maintaining a separate index for auto-complete suggestions, while using type "completion" of Elasticsearch I faced certain limitations like it only worked for prefix, I tried tokenizing input by n-gram analyze…

---

## [Manually specifing java heap size breaks elasticsearch service](https://discuss.elastic.co/t/manually-specifing-java-heap-size-breaks-elasticsearch-service/371101)

<div class="topic-metadata">

**Author:** [@ahsan0331](https://discuss.elastic.co/u/ahsan0331)\
**Replies:** 1\
**Last updated:** [November 26, 2024, 8:53pm UTC](https://discuss.elastic.co/t/manually-specifing-java-heap-size-breaks-elasticsearch-service/371101 "2024-11-26T20:53:11Z")

</div>

hi I have a vm wiht 16gb. i need to reduce its memory consumption. for some reasons manually specifying Xmx1g and Xms1g (or any other value) breaks the elasticsearch. the service wont start. commenting this setting in /…

---

## [GeoIP stopped working after upgrade](https://discuss.elastic.co/t/geoip-stopped-working-after-upgrade/371046)

<div class="topic-metadata">

**Author:** [@Leb\_Cryptos](https://discuss.elastic.co/u/Leb_Cryptos)\
**Replies:** 7\
**Last updated:** [November 26, 2024, 7:17pm UTC](https://discuss.elastic.co/t/geoip-stopped-working-after-upgrade/371046 "2024-11-26T19:17:06Z")

</div>

After Upgrading my elasticsearch and kibana to the latest version, geoip stopped working, everything else is working.

---

## [Ctrl+F search behavior in elastic](https://discuss.elastic.co/t/ctrl-f-search-behavior-in-elastic/371028)

<div class="topic-metadata">

**Author:** [@Arie\_Youlus](https://discuss.elastic.co/u/Arie_Youlus)\
**Replies:** 17\
**Last updated:** [November 26, 2024, 5:24pm UTC](https://discuss.elastic.co/t/ctrl-f-search-behavior-in-elastic/371028 "2024-11-26T17:24:55Z")

</div>

We are aiming to implement a naive search in Elasticsearch that functions exactly like a Ctrl+F search. Specifically, a query like "rd1 wo" should match "word1 word2" because it is a partial match in sequence. The searc…

---

## [Error with same mappings on all indices](https://discuss.elastic.co/t/error-with-same-mappings-on-all-indices/371035)

<div class="topic-metadata">

**Author:** [@danmera-ingenes](https://discuss.elastic.co/u/danmera-ingenes)\
**Replies:** 5\
**Last updated:** [November 26, 2024, 3:52pm UTC](https://discuss.elastic.co/t/error-with-same-mappings-on-all-indices/371035 "2024-11-26T15:52:51Z")

</div>

I've been having a big issue with my elastic stack, I am sending information from sql server to elasticsearch using logstash, and each index for each table gets created with the table columns as mappings in the index in …

---

## [Illegal\_argument\_exception](https://discuss.elastic.co/t/illegal-argument-exception/371065)

<div class="topic-metadata">

**Author:** [@shubham21101997](https://discuss.elastic.co/u/shubham21101997)\
**Replies:** 1\
**Last updated:** [November 26, 2024, 12:07pm UTC](https://discuss.elastic.co/t/illegal-argument-exception/371065 "2024-11-26T12:07:54Z")

</div>

I am getting these error messaage , how to reslove it and also want to know if if i can skip for those document which exceeds the limit { "took": 382, "timed\_out": false, "\_shards": { "total": 16, "success…

---

## [Azure Service Health](https://discuss.elastic.co/t/azure-service-health/371039)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 7:25pm UTC](https://discuss.elastic.co/t/azure-service-health/371039 "2024-11-25T19:25:25Z")

</div>

Is there a way to capture Azure Service Health data and ingest into Elastic?

---

## [Watcher Trigger Running on Sunday although cron set for MON-FRI](https://discuss.elastic.co/t/watcher-trigger-running-on-sunday-although-cron-set-for-mon-fri/371030)

<div class="topic-metadata">

**Author:** [@clos012](https://discuss.elastic.co/u/clos012)\
**Replies:** 4\
**Last updated:** [November 25, 2024, 6:27pm UTC](https://discuss.elastic.co/t/watcher-trigger-running-on-sunday-although-cron-set-for-mon-fri/371030 "2024-11-25T18:27:39Z")

</div>

Hello - I have setup a watcher to run between MON-FRI from 0600-1900 every 30mins. The cron job is adjusted for the -6 UTC time based on our current system time profile. The job should only run MON-FRI but I am seeing th…

---

## [Space in Key Value Pipeline](https://discuss.elastic.co/t/space-in-key-value-pipeline/371018)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 11:30am UTC](https://discuss.elastic.co/t/space-in-key-value-pipeline/371018 "2024-11-25T11:30:31Z")

</div>

Hello, I need to use the Key-Value processor to extract fields using Ingest Pipeline. Unfortunately, there are spaces in the field value. How do they have such a log extract the fields. field=1 field2=2 field3=Nov 25 2…

---

## [Storing string with : and](https://discuss.elastic.co/t/storing-string-with-and/371016)

<div class="topic-metadata">

**Author:** [@dikesGearing](https://discuss.elastic.co/u/dikesGearing)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 10:34am UTC](https://discuss.elastic.co/t/storing-string-with-and/371016 "2024-11-25T10:34:48Z")

</div>

So... I a problem with my or no the companies data which can contain : and . and other valid value a-z0-9åäö.:!#$%&''\*+/=?^\_\`{|}~- , in multiple fields and it can look like this sdk:narhalsan:0203:vgregion.se. I'm alread…

---

## [Elastic ML alert](https://discuss.elastic.co/t/elastic-ml-alert/371015)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 10:01am UTC](https://discuss.elastic.co/t/elastic-ml-alert/371015 "2024-11-25T10:01:35Z")

</div>

Is it possible to use elastic machine learning to get notified if: index size hits a particular value? (or increases by a certain percentage) cluster storage increases by a certain value (or increases by a certain perc…

---

## [Hardware recommendation for vector search](https://discuss.elastic.co/t/hardware-recommendation-for-vector-search/370815)

<div class="topic-metadata">

**Author:** [@sandra\_a](https://discuss.elastic.co/u/sandra_a)\
**Replies:** 7\
**Last updated:** [November 25, 2024, 7:51am UTC](https://discuss.elastic.co/t/hardware-recommendation-for-vector-search/370815 "2024-11-25T07:51:29Z")

</div>

Hi; At the moment I have a cluster with 8 nodes, 2TB RAM and 5TB SSD disk. but after indexing vectors (1.2TB for now and will increase by time), search on it took 30 seconds. I've tried quantization , add more nodes a…

---

## [Cannot start elastic on windows](https://discuss.elastic.co/t/cannot-start-elastic-on-windows/371000)

<div class="topic-metadata">

**Author:** [@ahsan0331](https://discuss.elastic.co/u/ahsan0331)\
**Replies:** 3\
**Last updated:** [November 25, 2024, 7:36am UTC](https://discuss.elastic.co/t/cannot-start-elastic-on-windows/371000 "2024-11-25T07:36:05Z")

</div>

Hi, I am new to elastic. was trying to run it on windows to lab it for learning purpose. I was first time able to run it . then i deleted both the unziped folders of kibana and elasticsearch. and tried to run the elast…

---

## [Issue with Lifecycle Policy Compatibility in Elasticsearch 8.15.2](https://discuss.elastic.co/t/issue-with-lifecycle-policy-compatibility-in-elasticsearch-8-15-2/371008)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 6:15am UTC](https://discuss.elastic.co/t/issue-with-lifecycle-policy-compatibility-in-elasticsearch-8-15-2/371008 "2024-11-25T06:15:59Z")

</div>

Hi, Below is the lifecycle policy I used with Elasticsearch version 7.17.9, where it was working successfully. However, the same policy is not functioning as expected with Elasticsearch version 8.15.2. I would greatly a…

---

## [What is the largest size that one node can hold?](https://discuss.elastic.co/t/what-is-the-largest-size-that-one-node-can-hold/370851)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 38\
**Last updated:** [November 25, 2024, 6:05am UTC](https://discuss.elastic.co/t/what-is-the-largest-size-that-one-node-can-hold/370851 "2024-11-25T06:05:04Z")

</div>

Hello I have a lot of data and I want to store it in elasticsearch What is the largest size that one node can hold?

---

## [Cannot create index for web crawler on the console](https://discuss.elastic.co/t/cannot-create-index-for-web-crawler-on-the-console/371005)

<div class="topic-metadata">

**Author:** [@Soumarshi](https://discuss.elastic.co/u/Soumarshi)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 4:12am UTC](https://discuss.elastic.co/t/cannot-create-index-for-web-crawler-on-the-console/371005 "2024-11-25T04:12:03Z")

</div>

Hello, I am not able to create an index for web crawler. It always throws "Search encountered an error. Check Kibana Server logs for details.". I am not able to get any logs for Kibana. Can you please guide me

---

## [Meaning of the columns in the output of API: GET \_cat/indices?v](https://discuss.elastic.co/t/meaning-of-the-columns-in-the-output-of-api-get-cat-indices-v/370810)

<div class="topic-metadata">

**Author:** [@ChatLee](https://discuss.elastic.co/u/ChatLee)\
**Replies:** 4\
**Last updated:** [November 25, 2024, 12:35am UTC](https://discuss.elastic.co/t/meaning-of-the-columns-in-the-output-of-api-get-cat-indices-v/370810 "2024-11-25T00:35:36Z")

</div>

Hi teams, When using the API: GET \_cat/indices?v, the output would includes columns here: health status index uuid pri rep docs.count do…

---

## [Getting timeout exception while inserting data to elastic index](https://discuss.elastic.co/t/getting-timeout-exception-while-inserting-data-to-elastic-index/370973)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [November 24, 2024, 2:03pm UTC](https://discuss.elastic.co/t/getting-timeout-exception-while-inserting-data-to-elastic-index/370973 "2024-11-24T14:03:31Z")

</div>

Hello All, From past 1 week I am getting below exception for elastic index and unable ti find RCA. It showing timeout and not able to find what could be reason for timeout while inserting data to index Even in elastic …

---

## [Significance of @timestamp in Index Patterns](https://discuss.elastic.co/t/significance-of-timestamp-in-index-patterns/370982)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 10\
**Last updated:** [November 23, 2024, 10:33pm UTC](https://discuss.elastic.co/t/significance-of-timestamp-in-index-patterns/370982 "2024-11-23T22:33:54Z")

</div>

Hi All, What is the significance of @timestamp field that populates by default in all indices in Kibana? I ask this question as this time differs with the recvdTime field that is set in the application and gets displ…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=59)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=61)
