# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=64

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 65

---

## [Logs are not getting save using NLog](https://discuss.elastic.co/t/logs-are-not-getting-save-using-nlog/370241)

<div class="topic-metadata">

**Author:** [@Habib\_Khan](https://discuss.elastic.co/u/Habib_Khan)\
**Replies:** 1\
**Last updated:** [November 8, 2024, 6:15pm UTC](https://discuss.elastic.co/t/logs-are-not-getting-save-using-nlog/370241 "2024-11-08T18:15:29Z")

</div>

Hi, i am using Elasticsearch 8 version every thing is correct but my logs are not getting save on Elasticsearch. please help me if anyone know about this . Below is my nlog.config

---

## [Cloud active directory auth (Not SAML)](https://discuss.elastic.co/t/cloud-active-directory-auth-not-saml/370190)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 3\
**Last updated:** [November 8, 2024, 4:46pm UTC](https://discuss.elastic.co/t/cloud-active-directory-auth-not-saml/370190 "2024-11-08T16:46:08Z")

</div>

Cloud 8.15.3, using SAML auth now, moving from on-prem using Active Directory. SAML works for interactive users, but apparently won't work for things like ingest and scripts. API keys work for scripts, but I get grumbl…

---

## [Elasticsearch appends object fields on update instead of overwriting](https://discuss.elastic.co/t/elasticsearch-appends-object-fields-on-update-instead-of-overwriting/370125)

<div class="topic-metadata">

**Author:** [@lukasz.p](https://discuss.elastic.co/u/lukasz.p)\
**Replies:** 4\
**Last updated:** [November 8, 2024, 3:15pm UTC](https://discuss.elastic.co/t/elasticsearch-appends-object-fields-on-update-instead-of-overwriting/370125 "2024-11-08T15:15:00Z")

</div>

I have a problem when trying to overwrite value of field of object type in ES document. I use update request with the following document: { "uid": "911e50cf-7ff6-48e2-999c-313490a0748e", "name": "name1", …

---

## [Ignore term frequency but maintain relevancy](https://discuss.elastic.co/t/ignore-term-frequency-but-maintain-relevancy/370230)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 0\
**Last updated:** [November 8, 2024, 2:53pm UTC](https://discuss.elastic.co/t/ignore-term-frequency-but-maintain-relevancy/370230 "2024-11-08T14:53:45Z")

</div>

Here is my problem. If someone searches for "power rangers" (without quotes) on my site, ES is scoring documents with 100 instances of "power rangers" much higher than documents that only contain 1 instance of "power ra…

---

## [Elasticsearch-py cluster info fetch](https://discuss.elastic.co/t/elasticsearch-py-cluster-info-fetch/370220)

<div class="topic-metadata">

**Author:** [@Narzhan1](https://discuss.elastic.co/u/Narzhan1)\
**Replies:** 0\
**Last updated:** [November 8, 2024, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-py-cluster-info-fetch/370220 "2024-11-08T12:37:14Z")

</div>

After the Elasticsearch client is initialized in elasticsearch-py==7.17.0 like so: import elasticsearch host = elasticsearch.Elasticsearch(get\_elastic\_url()) the client sends a get request to the root of the Elasticsea…

---

## [Is it possible to change Index-level data tier allocation after creation?](https://discuss.elastic.co/t/is-it-possible-to-change-index-level-data-tier-allocation-after-creation/370186)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 4\
**Last updated:** [November 8, 2024, 12:29pm UTC](https://discuss.elastic.co/t/is-it-possible-to-change-index-level-data-tier-allocation-after-creation/370186 "2024-11-08T12:29:22Z")

</div>

Hello, the documentation isn't clear on this - is it possible to set the data tier allocation AFTER an index has been created? e.g. index.routing.allocation.include.\_tier\_preference We are in a situation where a piece o…

---

## [Multiple actions on alias api 8.15](https://discuss.elastic.co/t/multiple-actions-on-alias-api-8-15/370213)

<div class="topic-metadata">

**Author:** [@HSN\_AD](https://discuss.elastic.co/u/HSN_AD)\
**Replies:** 0\
**Last updated:** [November 8, 2024, 11:01am UTC](https://discuss.elastic.co/t/multiple-actions-on-alias-api-8-15/370213 "2024-11-08T11:01:47Z")

</div>

Hi, I’ve found that multiple actions on the Alias API do not work properly. While it works fine in Kibana, it doesn't work in the .NET Elastic Client v8.15. Here’s my code:" await \_elasticClient.Indices.UpdateAliasesAs…

---

## [Data loss in docker based elasticsearch at random index](https://discuss.elastic.co/t/data-loss-in-docker-based-elasticsearch-at-random-index/369288)

<div class="topic-metadata">

**Author:** [@Shivji\_Bhagat](https://discuss.elastic.co/u/Shivji_Bhagat)\
**Replies:** 1\
**Last updated:** [November 8, 2024, 10:11am UTC](https://discuss.elastic.co/t/data-loss-in-docker-based-elasticsearch-at-random-index/369288 "2024-11-08T10:11:51Z")

</div>

I am using elasticsearch v8.13.2 with docker and single node. I have been facing loss of docs at random indices. this used to get resolved automatically earlier on increasing the ram size, but at current stage that is al…

---

## [Elasticsearch build failure](https://discuss.elastic.co/t/elasticsearch-build-failure/369889)

<div class="topic-metadata">

**Author:** [@HAT](https://discuss.elastic.co/u/HAT)\
**Replies:** 7\
**Last updated:** [November 8, 2024, 9:30am UTC](https://discuss.elastic.co/t/elasticsearch-build-failure/369889 "2024-11-08T09:30:50Z")

</div>

I am trying to build Elasticsearch from source and getting the below error when I run "./gradlew assemble" \> Task :distribution:docker:buildWolfiDockerImage FAILED FAILURE: Build failed with an exception. \* What went …

---

## [Docker Failed Install Puglin Kuromoji In 7.17.25](https://discuss.elastic.co/t/docker-failed-install-puglin-kuromoji-in-7-17-25/370195)

<div class="topic-metadata">

**Author:** [@KuroDecimal](https://discuss.elastic.co/u/KuroDecimal)\
**Replies:** 0\
**Last updated:** [November 8, 2024, 4:25am UTC](https://discuss.elastic.co/t/docker-failed-install-puglin-kuromoji-in-7-17-25/370195 "2024-11-08T04:25:43Z")

</div>

Hello, friends. I was editing official Dockerfile 7.17.25 distributed on Github for develop a custom elasticsearch image. (Office Dockerfile URL : dockerfiles/elasticsearch/Dockerfile at 9a2cb64607abe3574f8f1d0fa8b9680…

---

## [Caching of runtime mappings](https://discuss.elastic.co/t/caching-of-runtime-mappings/370185)

<div class="topic-metadata">

**Author:** [@nicole.oresme](https://discuss.elastic.co/u/nicole.oresme)\
**Replies:** 0\
**Last updated:** [November 7, 2024, 9:34pm UTC](https://discuss.elastic.co/t/caching-of-runtime-mappings/370185 "2024-11-07T21:34:02Z")

</div>

Does anyone know when the results of runtime mappings are cached? I've seen instances where my first run takes 10s of seconds, but my second is near instant - so they are clearly being cached sometimes. But then I do w…

---

## [Increased CPU usage on data nodes after Elasticsearch upgrade from 8.8.2 to 8.15.3](https://discuss.elastic.co/t/increased-cpu-usage-on-data-nodes-after-elasticsearch-upgrade-from-8-8-2-to-8-15-3/370184)

<div class="topic-metadata">

**Author:** [@lifer](https://discuss.elastic.co/u/lifer)\
**Replies:** 0\
**Last updated:** [November 7, 2024, 8:50pm UTC](https://discuss.elastic.co/t/increased-cpu-usage-on-data-nodes-after-elasticsearch-upgrade-from-8-8-2-to-8-15-3/370184 "2024-11-07T20:50:53Z")

</div>

Hi! We are observing 1.5-2x increase in CPU usage after upgrade of our ES cluster from version 8.8.2 to 8.15.3. Our cluster is hosted on AWS EC2 instances, it consists of 6 nodes: 3 master nodes (c6i.large) and 3 data …

---

## [Filtering request urls wildcard](https://discuss.elastic.co/t/filtering-request-urls-wildcard/370166)

<div class="topic-metadata">

**Author:** [@Myles\_Kingsnorth1](https://discuss.elastic.co/u/Myles_Kingsnorth1)\
**Replies:** 1\
**Last updated:** [November 7, 2024, 7:24pm UTC](https://discuss.elastic.co/t/filtering-request-urls-wildcard/370166 "2024-11-07T19:24:49Z")

</div>

I'm using Kibana edit query DSL feature to try and filter for a URL structure. I have 2 types of urls: /products/example/example2 /products/example I'm trying to produce a query that will match /products/example NOT b…

---

## [Help with pipeline and reindex and search using E5 embedding model](https://discuss.elastic.co/t/help-with-pipeline-and-reindex-and-search-using-e5-embedding-model/369359)

<div class="topic-metadata">

**Author:** [@Sergio\_Fernandez\_Col](https://discuss.elastic.co/u/Sergio_Fernandez_Col)\
**Replies:** 1\
**Last updated:** [November 7, 2024, 5:42pm UTC](https://discuss.elastic.co/t/help-with-pipeline-and-reindex-and-search-using-e5-embedding-model/369359 "2024-11-07T17:42:43Z")

</div>

Hi all, I have uploaded a tsv file with chunked information, this information is divided in this columns: "document\_name", "page\_number" and "text". I did this many times but using elser\_v2, now I have to use the built…

---

## [Elastic search to Postgres migration and building Cache for trillions records](https://discuss.elastic.co/t/elastic-search-to-postgres-migration-and-building-cache-for-trillions-records/370105)

<div class="topic-metadata">

**Author:** [@S8ukumar](https://discuss.elastic.co/u/S8ukumar)\
**Replies:** 6\
**Last updated:** [November 7, 2024, 10:53am UTC](https://discuss.elastic.co/t/elastic-search-to-postgres-migration-and-building-cache-for-trillions-records/370105 "2024-11-07T10:53:46Z")

</div>

I am working on a product design where we provide source data as input which is having details of files and folders. This data is huge and in trillions. This goes for metadata scan and keep the metadata scan details of i…

---

## [Issue : Data in a elasticsearch index is randomly getting deleted and the primary shard is getting unassigned](https://discuss.elastic.co/t/issue-data-in-a-elasticsearch-index-is-randomly-getting-deleted-and-the-primary-shard-is-getting-unassigned/370154)

<div class="topic-metadata">

**Author:** [@hariv0](https://discuss.elastic.co/u/hariv0)\
**Replies:** 0\
**Last updated:** [November 7, 2024, 7:41am UTC](https://discuss.elastic.co/t/issue-data-in-a-elasticsearch-index-is-randomly-getting-deleted-and-the-primary-shard-is-getting-unassigned/370154 "2024-11-07T07:41:44Z")

</div>

I am using elasticsearch v8.13.2 with docker and single node. I have been facing loss of docs at random indices. this used to get resolved automatically earlier on increasing the ram size, but at current stage that is al…

---

## [Whether our SaaS product can use Elasticsearch 8.x for free under Elastic License](https://discuss.elastic.co/t/whether-our-saas-product-can-use-elasticsearch-8-x-for-free-under-elastic-license/370118)

<div class="topic-metadata">

**Author:** [@Nigel\_C](https://discuss.elastic.co/u/Nigel_C)\
**Replies:** 2\
**Last updated:** [November 7, 2024, 6:45am UTC](https://discuss.elastic.co/t/whether-our-saas-product-can-use-elasticsearch-8-x-for-free-under-elastic-license/370118 "2024-11-07T06:45:18Z")

</div>

Hi Elastic team, we are developing a SaaS application mainly used to provide users with collaboration functions. Currently, we plan to use Elasticsearch to provide the search function in our application. Our specific usa…

---

## [Elastic License activation without internet (on prem)](https://discuss.elastic.co/t/elastic-license-activation-without-internet-on-prem/370110)

<div class="topic-metadata">

**Author:** [@TCT](https://discuss.elastic.co/u/TCT)\
**Replies:** 1\
**Last updated:** [November 7, 2024, 1:58am UTC](https://discuss.elastic.co/t/elastic-license-activation-without-internet-on-prem/370110 "2024-11-07T01:58:03Z")

</div>

I am using a self-managed Elastic Stack in a private network without internet access, and I want to know if it's possible to activate the Elastic License without an internet connection. In the License Management section…

---

## [Null\_pointer\_exception when using aggregation](https://discuss.elastic.co/t/null-pointer-exception-when-using-aggregation/370029)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [November 6, 2024, 5:41pm UTC](https://discuss.elastic.co/t/null-pointer-exception-when-using-aggregation/370029 "2024-11-06T17:41:18Z")

</div>

Hi Community, I want to run this query GET employees/\_search { "aggs": { "Total Income": { "sum": { "field": "Package", "script": { "source": "if(params.\_source\['name.keyword'\]=='E…

---

## [Antivirus directory exclusions on separate Kibana, Logstash, and Elastic Servers - Linux](https://discuss.elastic.co/t/antivirus-directory-exclusions-on-separate-kibana-logstash-and-elastic-servers-linux/370095)

<div class="topic-metadata">

**Author:** [@mmletzko](https://discuss.elastic.co/u/mmletzko)\
**Replies:** 2\
**Last updated:** [November 6, 2024, 1:38pm UTC](https://discuss.elastic.co/t/antivirus-directory-exclusions-on-separate-kibana-logstash-and-elastic-servers-linux/370095 "2024-11-06T13:38:55Z")

</div>

Was wondering if anyone could tell me exactly what folders on each of these servers should be excluded from AntiVirus, or point me to the documentation that covers it: -Kibana: Linux -Logstash: Linux -Elastic: Linu…

---

## [Elasticsearch BULK API with .NET for upsert](https://discuss.elastic.co/t/elasticsearch-bulk-api-with-net-for-upsert/370003)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 16\
**Last updated:** [November 6, 2024, 6:34am UTC](https://discuss.elastic.co/t/elasticsearch-bulk-api-with-net-for-upsert/370003 "2024-11-06T06:34:22Z")

</div>

Hi Team, I am using .NET 8 and ES Version="8.15.6". I an trying to use bulk api with a logic for upsert based on the document id. I tried the below index, update commands from Kibana as per documentation and they work f…

---

## [Issue: Nodes Getting Deleted Suddenly in Elasticsearch](https://discuss.elastic.co/t/issue-nodes-getting-deleted-suddenly-in-elasticsearch/370073)

<div class="topic-metadata">

**Author:** [@hariv0](https://discuss.elastic.co/u/hariv0)\
**Replies:** 4\
**Last updated:** [November 5, 2024, 1:54pm UTC](https://discuss.elastic.co/t/issue-nodes-getting-deleted-suddenly-in-elasticsearch/370073 "2024-11-05T13:54:19Z")

</div>

I am experiencing an issue where nodes in our Elasticsearch cluster are getting deleted suddenly. This issue is causing shard allocation failures and recovery problems. Below are the anonymized logs related to the issue: …

---

## [How to filter movies by title and multiple genres, while aggregating genre counts in Elasticsearch?](https://discuss.elastic.co/t/how-to-filter-movies-by-title-and-multiple-genres-while-aggregating-genre-counts-in-elasticsearch/370039)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 4\
**Last updated:** [November 5, 2024, 1:46pm UTC](https://discuss.elastic.co/t/how-to-filter-movies-by-title-and-multiple-genres-while-aggregating-genre-counts-in-elasticsearch/370039 "2024-11-05T13:46:20Z")

</div>

Hi everyone! I'm working with a movie index in Elasticsearch and need help building a query. Here’s the requirement: I want to retrieve movies where the title contains a specific term, such as "car," and the genre ma…

---

## [Reading scroll request IDs leads to OOB access](https://discuss.elastic.co/t/reading-scroll-request-ids-leads-to-oob-access/370070)

<div class="topic-metadata">

**Author:** [@fetch](https://discuss.elastic.co/u/fetch)\
**Replies:** 2\
**Last updated:** [November 5, 2024, 1:14pm UTC](https://discuss.elastic.co/t/reading-scroll-request-ids-leads-to-oob-access/370070 "2024-11-05T13:14:16Z")

</div>

Hello, I'm using a cluster with 3 ELK nodes with 7.10.1 version installed in it. I know that it's a bit old, but any update usually brings much pain with my data, so I dont touch it while it works fine. Today I've noti…

---

## [seach higher than in a message field](https://discuss.elastic.co/t/seach-higher-than-in-a-message-field/370023)

<div class="topic-metadata">

**Author:** [@Joost2](https://discuss.elastic.co/u/Joost2)\
**Replies:** 1\
**Last updated:** [November 5, 2024, 12:56pm UTC](https://discuss.elastic.co/t/seach-higher-than-in-a-message-field/370023 "2024-11-05T12:56:36Z")

</div>

Message field , is SUCCES Sending eenheidUpdated to URL https://xx.local Time elapsed: 7xx milliseconds, ( 7xx different values) search with: message: "time elapsed" and https://xx.local/ and 700 The results are: SUC…

---

## [How to clear cache of keyword field in elastic search?](https://discuss.elastic.co/t/how-to-clear-cache-of-keyword-field-in-elastic-search/366026)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 9\
**Last updated:** [November 5, 2024, 9:43am UTC](https://discuss.elastic.co/t/how-to-clear-cache-of-keyword-field-in-elastic-search/366026 "2024-11-05T09:43:41Z")

</div>

Hi , I am facing cache issue with keyword field in Elastic. I have a document with keyword field which is indexed with some value example : abc later the same document is reindexed again with some value abcd, old value …

---

## [What does the \_split api do internally when creating a new index](https://discuss.elastic.co/t/what-does-the-split-api-do-internally-when-creating-a-new-index/370050)

<div class="topic-metadata">

**Author:** [@techytushar](https://discuss.elastic.co/u/techytushar)\
**Replies:** 0\
**Last updated:** [November 5, 2024, 6:55am UTC](https://discuss.elastic.co/t/what-does-the-split-api-do-internally-when-creating-a-new-index/370050 "2024-11-05T06:55:29Z")

</div>

I have a few questions on the internal working of the split api: In the documentation it is mentioned that Hashes all documents again, after low level files are created, to delete documents that belong to a different …

---

## [Elasticsearch.service](https://discuss.elastic.co/t/elasticsearch-service/370049)

<div class="topic-metadata">

**Author:** [@charbel\_Bob](https://discuss.elastic.co/u/charbel_Bob)\
**Replies:** 2\
**Last updated:** [November 5, 2024, 7:37am UTC](https://discuss.elastic.co/t/elasticsearch-service/370049 "2024-11-05T07:37:13Z")

</div>

Hello; I install Elasticsearch on my Azure VM and I tried to start the service but it failed to start I only edit the network host and enable the port in elasticsearch.yml file nothing more so please find below the logs…

---

## [Unable start logstash](https://discuss.elastic.co/t/unable-start-logstash/370048)

<div class="topic-metadata">

**Author:** [@Santanu112](https://discuss.elastic.co/u/Santanu112)\
**Replies:** 0\
**Last updated:** [November 5, 2024, 6:19am UTC](https://discuss.elastic.co/t/unable-start-logstash/370048 "2024-11-05T06:19:01Z")

</div>

PFB my configuration file : input { dead\_letter\_queue { path =\> "E:\\elk-8.14\\elkerrors\\QA\\FullIndex" commit\_offsets =\> true pipeline\_id =\> "main" } dead\_letter\_queue { path =\> "E:\\elk-8.14\\elkerrors\\QA\\Incrementa…

---

## [Elasticsearch.slowlog.id is null when sending X-Opaque-Id header](https://discuss.elastic.co/t/elasticsearch-slowlog-id-is-null-when-sending-x-opaque-id-header/369826)

<div class="topic-metadata">

**Author:** [@margaretp](https://discuss.elastic.co/u/margaretp)\
**Replies:** 2\
**Last updated:** [November 4, 2024, 10:12pm UTC](https://discuss.elastic.co/t/elasticsearch-slowlog-id-is-null-when-sending-x-opaque-id-header/369826 "2024-11-04T22:12:07Z")

</div>

Hello, I have been using slowlogs for awhile, and now I'm trying to get X-Opaque-Id to show up in slowlogs so I can trace slow queries to their source. I believe that if it is set, the header should appear in the output…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=63)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=65)
