# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=61

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 62

---

## [Simple scenario where Filebeat transfers log lines into Elastic search - does not work](https://discuss.elastic.co/t/simple-scenario-where-filebeat-transfers-log-lines-into-elastic-search-does-not-work/370940)

<div class="topic-metadata">

**Author:** [@Gosforth](https://discuss.elastic.co/u/Gosforth)\
**Replies:** 5\
**Last updated:** [November 22, 2024, 7:55pm UTC](https://discuss.elastic.co/t/simple-scenario-where-filebeat-transfers-log-lines-into-elastic-search-does-not-work/370940 "2024-11-22T19:55:47Z")

</div>

Hi, my goal is to load Tshark logs into Elasticsearch using Filebeat. So here is my test file (for some lines port column is empty): 2024-11-21 19:29:28 192.168.1.144 142.250.186.196 52873\\443 2024-11-21 19:29:28 142.2…

---

## [Semantic Search while maintaining the contextual Information](https://discuss.elastic.co/t/semantic-search-while-maintaining-the-contextual-information/370967)

<div class="topic-metadata">

**Author:** [@Birendra\_Singh](https://discuss.elastic.co/u/Birendra_Singh)\
**Replies:** 0\
**Last updated:** [November 22, 2024, 4:07pm UTC](https://discuss.elastic.co/t/semantic-search-while-maintaining-the-contextual-information/370967 "2024-11-22T16:07:10Z")

</div>

Hi Team, Currently i am working on a POC wherein I am using Elasticsearch for vector search. I am getting good results for all the queries but when I tried to change the query a bit like changing the subject in query I …

---

## [Querying All Text/Keyword Fields, Including Nested Fields](https://discuss.elastic.co/t/querying-all-text-keyword-fields-including-nested-fields/370720)

<div class="topic-metadata">

**Author:** [@jalex](https://discuss.elastic.co/u/jalex)\
**Replies:** 5\
**Last updated:** [November 22, 2024, 3:19pm UTC](https://discuss.elastic.co/t/querying-all-text-keyword-fields-including-nested-fields/370720 "2024-11-22T15:19:01Z")

</div>

Hello, I am looking for a way to search across all text and keyword fields, including nested fields, in an index for keyword matches and then retrieve which field it hit on. I don’t necessarily know which field the keyw…

---

## [Total storage of Elasticsearch index grows abnormally](https://discuss.elastic.co/t/total-storage-of-elasticsearch-index-grows-abnormally/370936)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 3\
**Last updated:** [November 22, 2024, 3:05pm UTC](https://discuss.elastic.co/t/total-storage-of-elasticsearch-index-grows-abnormally/370936 "2024-11-22T15:05:37Z")

</div>

We are facing the following problem: We have seeded an index ~6 months ago. Back then the total space occupied was roughly 7TB of data. Over the last 6 months we have been updating the index to keep it synced with the …

---

## [Time for shard size to decrease after forcemerge](https://discuss.elastic.co/t/time-for-shard-size-to-decrease-after-forcemerge/370951)

<div class="topic-metadata">

**Author:** [@Emil](https://discuss.elastic.co/u/Emil)\
**Replies:** 0\
**Last updated:** [November 22, 2024, 1:08pm UTC](https://discuss.elastic.co/t/time-for-shard-size-to-decrease-after-forcemerge/370951 "2024-11-22T13:08:03Z")

</div>

When I do a forcemerge, I noticed shard size at first increases (as expected), and then later on decrease. However, after the forcemerge task is finished, some of the shards are still larger; it takes some time for them…

---

## [After Update 0365 Integration different types of datafields](https://discuss.elastic.co/t/after-update-0365-integration-different-types-of-datafields/370950)

<div class="topic-metadata">

**Author:** [@helldunkel](https://discuss.elastic.co/u/helldunkel)\
**Replies:** 0\
**Last updated:** [November 22, 2024, 12:27pm UTC](https://discuss.elastic.co/t/after-update-0365-integration-different-types-of-datafields/370950 "2024-11-22T12:27:07Z")

</div>

Hi, after Update and new roleout from the o365 integrationen we have diverent missmatches in the datafields. old is was: source.geo.location new is: source.geo.location.lat source.geo.location.lon some more datafi…

---

## [Debian repository checksum mismatch](https://discuss.elastic.co/t/debian-repository-checksum-mismatch/370425)

<div class="topic-metadata">

**Author:** [@lisuml](https://discuss.elastic.co/u/lisuml)\
**Replies:** 20\
**Last updated:** [November 22, 2024, 10:19am UTC](https://discuss.elastic.co/t/debian-repository-checksum-mismatch/370425 "2024-11-22T10:19:31Z")

</div>

I'm getting the following error when trying to add the elastic repository to my Debian 12 box: E: Failed to fetch https://artifacts.elastic.co/packages/8.x/apt/dists/stable/main/binary-amd64/Packages.bz2 File has unexp…

---

## [V7.10 Build failed on my apple silicon macbook](https://discuss.elastic.co/t/v7-10-build-failed-on-my-apple-silicon-macbook/370927)

<div class="topic-metadata">

**Author:** [@kingswan](https://discuss.elastic.co/u/kingswan)\
**Replies:** 5\
**Last updated:** [November 22, 2024, 8:53am UTC](https://discuss.elastic.co/t/v7-10-build-failed-on-my-apple-silicon-macbook/370927 "2024-11-22T08:53:02Z")

</div>

Hi folk, when I try to build v7.10 on my apple m2 macbook, I got error: \> Task :buildSrc:check UP-TO-DATE \> Task :buildSrc:build UP-TO-DATE FAILURE: Build failed with an exception. \* What went wrong: A problem occurr…

---

## [Missing logs cluster green to yellow](https://discuss.elastic.co/t/missing-logs-cluster-green-to-yellow/370931)

<div class="topic-metadata">

**Author:** [@Nicoletta](https://discuss.elastic.co/u/Nicoletta)\
**Replies:** 0\
**Last updated:** [November 22, 2024, 7:41am UTC](https://discuss.elastic.co/t/missing-logs-cluster-green-to-yellow/370931 "2024-11-22T07:41:49Z")

</div>

Hi, in the Observability \> Logs section I am filtering all the logs containing "Cluster health status changed" string (I also tried "YELLOW" or just "Cluster health status"). I get these results: I was wondering wh…

---

## [ELSER for long texts](https://discuss.elastic.co/t/elser-for-long-texts/370928)

<div class="topic-metadata">

**Author:** [@Sarah2](https://discuss.elastic.co/u/Sarah2)\
**Replies:** 0\
**Last updated:** [November 22, 2024, 6:59am UTC](https://discuss.elastic.co/t/elser-for-long-texts/370928 "2024-11-22T06:59:57Z")

</div>

I am using Elastic Search 8.11 and want to use ELSER to incorporate semantic search. But fields I have to perform search is long text fields. I found this link saying If your data set contains long documents, divide t…

---

## [Elastic cloud request entity max length](https://discuss.elastic.co/t/elastic-cloud-request-entity-max-length/370845)

<div class="topic-metadata">

**Author:** [@dealomuss](https://discuss.elastic.co/u/dealomuss)\
**Replies:** 3\
**Last updated:** [November 21, 2024, 7:47pm UTC](https://discuss.elastic.co/t/elastic-cloud-request-entity-max-length/370845 "2024-11-21T19:47:18Z")

</div>

Hello, i have an elastic cloud cluster and im facing a request entity payload that seems to be too large the error received on the console is : { "statusCode": 413, "error": "Request Entity Too Large", "message"…

---

## [Restore of snapshot from s3 is failing](https://discuss.elastic.co/t/restore-of-snapshot-from-s3-is-failing/370785)

<div class="topic-metadata">

**Author:** [@mealbert23](https://discuss.elastic.co/u/mealbert23)\
**Replies:** 3\
**Last updated:** [November 21, 2024, 3:49pm UTC](https://discuss.elastic.co/t/restore-of-snapshot-from-s3-is-failing/370785 "2024-11-21T15:49:12Z")

</div>

Hi, I have two elasticsearch clusters (prod and dev). I have both clusters pointing to the same s3 back snapshot repo. The snapshots in prod say they are completing without error. However, when I try to restore from …

---

## [Help to understand fuzzy score](https://discuss.elastic.co/t/help-to-understand-fuzzy-score/370870)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 3\
**Last updated:** [November 21, 2024, 12:57pm UTC](https://discuss.elastic.co/t/help-to-understand-fuzzy-score/370870 "2024-11-21T12:57:23Z")

</div>

Given the following search: { "size": 100, "query": { "bool": { "must": \[ { "match": { "business\_names": { "query": "my company", "operator": "and"…

---

## [Elastic Search .Net Combine Must and Should Showing All Queries rather than correct combination](https://discuss.elastic.co/t/elastic-search-net-combine-must-and-should-showing-all-queries-rather-than-correct-combination/370852)

<div class="topic-metadata">

**Author:** [@GaryBtP](https://discuss.elastic.co/u/GaryBtP)\
**Replies:** 2\
**Last updated:** [November 21, 2024, 12:22pm UTC](https://discuss.elastic.co/t/elastic-search-net-combine-must-and-should-showing-all-queries-rather-than-correct-combination/370852 "2024-11-21T12:22:27Z")

</div>

I'm struggling to generate a .Net search which will combine a must field of one value and a should search of one of two values from a different field - e.g. results must contain value1 from field1 and either value2 or va…

---

## [New nodes added to cluster are not rebalancing](https://discuss.elastic.co/t/new-nodes-added-to-cluster-are-not-rebalancing/370715)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 9\
**Last updated:** [November 21, 2024, 12:12pm UTC](https://discuss.elastic.co/t/new-nodes-added-to-cluster-are-not-rebalancing/370715 "2024-11-21T12:12:11Z")

</div>

I have 50 nodes in the Elasticsearch 7.5 cluster and added five new nodes. All shards are balancing between nodes . These five new nodes for some reason do not go into balance, and their disks are near empty. There are…

---

## [Http client did not trust this server's certificate, closing connection](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-closing-connection/357189)

<div class="topic-metadata">

**Author:** [@abhinavtyagi](https://discuss.elastic.co/u/abhinavtyagi)\
**Replies:** 5\
**Last updated:** [November 21, 2024, 11:24am UTC](https://discuss.elastic.co/t/http-client-did-not-trust-this-servers-certificate-closing-connection/357189 "2024-11-21T11:24:43Z")

</div>

I am trying to sync MySQL with Elasticsearch and using version 8.13.2. I followed the docs for setup. But getting below error in my Elasticsearch logs: {"@timestamp":"2024-04-11T07:52:04.039Z", "log.level": "WARN", "m…

---

## [Filter\_path usage in multi-search](https://discuss.elastic.co/t/filter-path-usage-in-multi-search/370822)

<div class="topic-metadata">

**Author:** [@sevdog](https://discuss.elastic.co/u/sevdog)\
**Replies:** 1\
**Last updated:** [November 21, 2024, 8:10am UTC](https://discuss.elastic.co/t/filter-path-usage-in-multi-search/370822 "2024-11-21T08:10:31Z")

</div>

Hello everybody, i recenlty started using the filter\_path parameter (Common options | Elasticsearch Guide \[8.16\] | Elastic) to reduce output of a msearch performed on some metricbeat indicies: the first search looks for …

---

## [ElasticsearchClient.healthReport() give cluster status as yellow even though cluster is green](https://discuss.elastic.co/t/elasticsearchclient-healthreport-give-cluster-status-as-yellow-even-though-cluster-is-green/370695)

<div class="topic-metadata">

**Author:** [@sibasish.palo](https://discuss.elastic.co/u/sibasish.palo)\
**Replies:** 9\
**Last updated:** [November 21, 2024, 6:36am UTC](https://discuss.elastic.co/t/elasticsearchclient-healthreport-give-cluster-status-as-yellow-even-though-cluster-is-green/370695 "2024-11-21T06:36:44Z")

</div>

Hi Noticing one weird issue where ElasticsearchClient.healthReport() gives status as Yellow even though the cluster status is green /\_cluster/health { "cluster\_name": "es\_cluster", "status": "green", "timed\_out"…

---

## [Query rules / Curations](https://discuss.elastic.co/t/query-rules-curations/370868)

<div class="topic-metadata">

**Author:** [@pngworkforce](https://discuss.elastic.co/u/pngworkforce)\
**Replies:** 0\
**Last updated:** [November 21, 2024, 12:50am UTC](https://discuss.elastic.co/t/query-rules-curations/370868 "2024-11-21T00:50:59Z")

</div>

Hello! I have created the following ruleset in my Elastic Cloud instance PUT \_query\_rules/rule1 { "rules": \[ { "rule\_id": "rates", "type": "pinned", "criteria": \[ { "…

---

## [Force a full recrawl](https://discuss.elastic.co/t/force-a-full-recrawl/370484)

<div class="topic-metadata">

**Author:** [@pngworkforce](https://discuss.elastic.co/u/pngworkforce)\
**Replies:** 4\
**Last updated:** [November 21, 2024, 12:41am UTC](https://discuss.elastic.co/t/force-a-full-recrawl/370484 "2024-11-21T00:41:00Z")

</div>

Hello! Is there a way to force a full recrawl of all documents in the Elastic Cloud UI? We have added some mapped fields but they are not applied to docs indexed before the mapped fields were added. I read that a rein…

---

## [How can an one node server handle shards limit?](https://discuss.elastic.co/t/how-can-an-one-node-server-handle-shards-limit/370855)

<div class="topic-metadata">

**Author:** [@Benny-RR](https://discuss.elastic.co/u/Benny-RR)\
**Replies:** 3\
**Last updated:** [November 20, 2024, 8:01pm UTC](https://discuss.elastic.co/t/how-can-an-one-node-server-handle-shards-limit/370855 "2024-11-20T20:01:05Z")

</div>

Hello, I have been assiged to maintain an ELK stack server where there are scripts that run automatically, these scripts get reports from IntelMQ and VulnWhisperer. IntelMQ's reports generate an index per day and the Vul…

---

## [Dial tcp \*.\*.\*.\*:9200 connct : cannot assign requested](https://discuss.elastic.co/t/dial-tcp-9200-connct-cannot-assign-requested/370779)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 11\
**Last updated:** [November 20, 2024, 7:08pm UTC](https://discuss.elastic.co/t/dial-tcp-9200-connct-cannot-assign-requested/370779 "2024-11-20T19:08:42Z")

</div>

Hi How to get elasticsearch to receive orders up to 100,000 Because when I search elasticsearch I get the following error dial tcp ...:9200 connct : cannot assign requested

---

## [Remote node](https://discuss.elastic.co/t/remote-node/370287)

<div class="topic-metadata">

**Author:** [@sandra\_a](https://discuss.elastic.co/u/sandra_a)\
**Replies:** 2\
**Last updated:** [November 20, 2024, 6:33pm UTC](https://discuss.elastic.co/t/remote-node/370287 "2024-11-20T18:33:01Z")

</div>

I want to setup two nodes remotely which mean master node will be in host 1 (eg. 172.16.3.8) and node 2 be in 172.16.3.10 and node 3 be in 172.16.3.70 how should i setup docker-compose? is there any documents or anythi…

---

## [IgnoreUrls](https://discuss.elastic.co/t/ignoreurls/370844)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 0\
**Last updated:** [November 20, 2024, 3:23pm UTC](https://discuss.elastic.co/t/ignoreurls/370844 "2024-11-20T15:23:19Z")

</div>

Good morning, I'm using the package "Elastic.Apm.NetCoreAll (1.25.3)" in a dotnet service and my intention is that some transactions not appears in APM, but it don't works :frowning: I have configured the appsettings: …

---

## [Elastic search REST client get a 15 minute timeouts on random occasions](https://discuss.elastic.co/t/elastic-search-rest-client-get-a-15-minute-timeouts-on-random-occasions/370710)

<div class="topic-metadata">

**Author:** [@Pavan\_Kumar\_Nallam](https://discuss.elastic.co/u/Pavan_Kumar_Nallam)\
**Replies:** 2\
**Last updated:** [November 20, 2024, 12:38pm UTC](https://discuss.elastic.co/t/elastic-search-rest-client-get-a-15-minute-timeouts-on-random-occasions/370710 "2024-11-20T12:38:06Z")

</div>

Hi we are using Elasticsearch to store business data for Sportsbook events, and its a critical cluster in our stack, we have atleast 4-5 Elasticsearch clusters in multiple projects in our Company. but only in 2 clusters …

---

## [BulkIngester not reliably executing afterBulk handlers](https://discuss.elastic.co/t/bulkingester-not-reliably-executing-afterbulk-handlers/364838)

<div class="topic-metadata">

**Author:** [@blackwinter](https://discuss.elastic.co/u/blackwinter)\
**Replies:** 5\
**Last updated:** [November 20, 2024, 11:31am UTC](https://discuss.elastic.co/t/bulkingester-not-reliably-executing-afterbulk-handlers/364838 "2024-11-20T11:31:46Z")

</div>

We're having difficulties adjusting to the new listener thread pool (see pull request #830) with elasticsearch-java version 8.15.0 on Java 17. We're relying on afterBulk handlers for statistics gathering and error handli…

---

## [Distributed nodes](https://discuss.elastic.co/t/distributed-nodes/370256)

<div class="topic-metadata">

**Author:** [@sandra\_a](https://discuss.elastic.co/u/sandra_a)\
**Replies:** 3\
**Last updated:** [November 20, 2024, 7:14am UTC](https://discuss.elastic.co/t/distributed-nodes/370256 "2024-11-20T07:14:10Z")

</div>

Hi, I have an Elasticsearch cluster with 6 nodes on a single system, and it contains some data. Now, I want to add more nodes on different systems. For example, nodes 3-6 will be in VMs 3-6 (each VM should have one data…

---

## [How to increase max\_clause\_count in Elasticsearch 8.0.1 without using deprecated settings?](https://discuss.elastic.co/t/how-to-increase-max-clause-count-in-elasticsearch-8-0-1-without-using-deprecated-settings/370721)

<div class="topic-metadata">

**Author:** [@Sahil\_Kapoor](https://discuss.elastic.co/u/Sahil_Kapoor)\
**Replies:** 0\
**Last updated:** [November 18, 2024, 9:45pm UTC](https://discuss.elastic.co/t/how-to-increase-max-clause-count-in-elasticsearch-8-0-1-without-using-deprecated-settings/370721 "2024-11-18T21:45:10Z")

</div>

I recently upgraded Elasticsearch from version 7.5.1 to 8.0.1, and I encountered an issue with my queries that require around 20k boolean clauses. In Elasticsearch 7, I manually updated the persistent settings to increas…

---

## [How to calculate unique contact duplicates using different fields](https://discuss.elastic.co/t/how-to-calculate-unique-contact-duplicates-using-different-fields/370716)

<div class="topic-metadata">

**Author:** [@andreyshiryaev13](https://discuss.elastic.co/u/andreyshiryaev13)\
**Replies:** 2\
**Last updated:** [November 19, 2024, 9:00pm UTC](https://discuss.elastic.co/t/how-to-calculate-unique-contact-duplicates-using-different-fields/370716 "2024-11-19T21:00:04Z")

</div>

Hi, I am trying to find an effective way to count unique contacts. Elastic 8.15 Index structure { id, email, phone, first, last } Data Example { 1, user@gmail.com, 1111111, Tom, Hanks }, { 2, user2@gmail.com, 1111111…

---

## [Analyse logs RNmessagesending transport message](https://discuss.elastic.co/t/analyse-logs-rnmessagesending-transport-message/370790)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [November 19, 2024, 8:35pm UTC](https://discuss.elastic.co/t/analyse-logs-rnmessagesending-transport-message/370790 "2024-11-19T20:35:45Z")

</div>

Hi Can You check together with me what could be the root cause What I have already check from this log. I didn't observe also any CPU throttling on that node it was used 3 core from 13 available. Node consists 26 heap …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=60)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=62)
