# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=7

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 8

---

## [Can I use ESQL Lookup Join to match fields with different names?](https://discuss.elastic.co/t/can-i-use-esql-lookup-join-to-match-fields-with-different-names/385324)

<div class="topic-metadata">

**Author:** [@TSlump](https://discuss.elastic.co/u/TSlump)\
**Replies:** 7\
**Last updated:** [March 4, 2026, 1:33pm UTC](https://discuss.elastic.co/t/can-i-use-esql-lookup-join-to-match-fields-with-different-names/385324 "2026-03-04T13:33:03Z")

</div>

Hi, I have two indices with matching fields that I want to use for an ESQL Lookup Join, however, the fields in each index have different names. Am I still able to use a lookup join? As an example, I have a ‘customers’ …

---

## [Tragic failure of primary marks all replica failed](https://discuss.elastic.co/t/tragic-failure-of-primary-marks-all-replica-failed/385277)

<div class="topic-metadata">

**Author:** [@xuanyuan300](https://discuss.elastic.co/u/xuanyuan300)\
**Replies:** 5\
**Last updated:** [March 4, 2026, 12:28am UTC](https://discuss.elastic.co/t/tragic-failure-of-primary-marks-all-replica-failed/385277 "2026-03-04T00:28:52Z")

</div>

Hi team We recently encountered the same problem Index with multiple replicas turned red when node with primary went down . Are there any plans to fix it?

---

## [How to apply ILM to ML indices? If not possible what,s the workaround?](https://discuss.elastic.co/t/how-to-apply-ilm-to-ml-indices-if-not-possible-what-s-the-workaround/385310)

<div class="topic-metadata">

**Author:** [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Replies:** 1\
**Last updated:** [March 3, 2026, 7:31pm UTC](https://discuss.elastic.co/t/how-to-apply-ilm-to-ml-indices-if-not-possible-what-s-the-workaround/385310 "2026-03-03T19:31:37Z")

</div>

Understand that ILM cannot be used on ML results indices. ILM is used on the ML state index out-of-the-box. Seems like this is a long open enhancement. \[ML\] Add an ML results index rollover endpoint · Issue #29946 · el…

---

## [Question about certificates and auto-generating configuration](https://discuss.elastic.co/t/question-about-certificates-and-auto-generating-configuration/385318)

<div class="topic-metadata">

**Author:** [@hairless\_mess](https://discuss.elastic.co/u/hairless_mess)\
**Replies:** 0\
**Last updated:** [March 3, 2026, 9:59am UTC](https://discuss.elastic.co/t/question-about-certificates-and-auto-generating-configuration/385318 "2026-03-03T09:59:36Z")

</div>

Hello everyone! I have some questions regarding the certificates used when deploying elasticsearch. Elasticsearch auto generates certificates for http and transport which work out of the box, however from my understand…

---

## [Does "Serverless" mean it cant be used on self hosted intances?](https://discuss.elastic.co/t/does-serverless-mean-it-cant-be-used-on-self-hosted-intances/385267)

<div class="topic-metadata">

**Author:** [@ItsMeBrille](https://discuss.elastic.co/u/ItsMeBrille)\
**Replies:** 11\
**Last updated:** [March 2, 2026, 7:38pm UTC](https://discuss.elastic.co/t/does-serverless-mean-it-cant-be-used-on-self-hosted-intances/385267 "2026-03-02T19:38:56Z")

</div>

Does the "Serverless" tag mean I can’t use those services on self hosted intances? I want to connect to the MCP endpoint /api/agent\_builder/mcp, but it says the docs have the “tag” Serverless. Does this mean I cannot …

---

## [Elasticsearch 8.12.2 Connector Weekly scheduling never triggers sync job](https://discuss.elastic.co/t/elasticsearch-8-12-2-connector-weekly-scheduling-never-triggers-sync-job/385214)

<div class="topic-metadata">

**Author:** [@apostolos.e](https://discuss.elastic.co/u/apostolos.e)\
**Replies:** 3\
**Last updated:** [March 2, 2026, 3:40pm UTC](https://discuss.elastic.co/t/elasticsearch-8-12-2-connector-weekly-scheduling-never-triggers-sync-job/385214 "2026-03-02T15:40:44Z")

</div>

Hi all, I am using ELK 8.12.2 along with Elastic PostgreSQL connector 8.12.2. Both have been setup/self-installed on premises. When configuring the connector to get executed on a Weekly schedule, sync jobs do not get c…

---

## [Multiple clusters on EKS](https://discuss.elastic.co/t/multiple-clusters-on-eks/381519)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [March 1, 2026, 9:36pm UTC](https://discuss.elastic.co/t/multiple-clusters-on-eks/381519 "2026-03-01T21:36:15Z")

</div>

Does this mean I can spin up multiple elasticsearch clusters on the same EKS? If that is the case, can I use 1 ERU (64 GB RAM) across 2 clusters if they are under 32 GB RAM each? Also, I do not see any documentation …

---

## [Ceph or LVM disk as ELK storage](https://discuss.elastic.co/t/ceph-or-lvm-disk-as-elk-storage/385279)

<div class="topic-metadata">

**Author:** [@marian.veverka](https://discuss.elastic.co/u/marian.veverka)\
**Replies:** 1\
**Last updated:** [February 28, 2026, 8:22am UTC](https://discuss.elastic.co/t/ceph-or-lvm-disk-as-elk-storage/385279 "2026-02-28T08:22:37Z")

</div>

Hello, I have ELK Stack: Nodes have 10G network. On disk for data is Ext4 filesystem and after several weeks have errors on filesystem on all disks. And my question is, is it possible due Ceph and LVM would be bette…

---

## [UnHealthy agent](https://discuss.elastic.co/t/unhealthy-agent/385188)

<div class="topic-metadata">

**Author:** [@harry22](https://discuss.elastic.co/u/harry22)\
**Replies:** 3\
**Last updated:** [February 28, 2026, 5:20am UTC](https://discuss.elastic.co/t/unhealthy-agent/385188 "2026-02-28T05:20:36Z")

</div>

PS C:\\Program Files\\Elastic\\Agent\> .'.\\elastic-agent.exe' status ┌─ fleet │ └─ status: (STARTING) └─ elastic-agent ├─ status: (DEGRADED) 1 or more components/units in a degraded state └─ endpoint-default ├─ status…

---

## [🐴 Elastic AutoOps is now free for every self-managed cluster — no license upgrade, no credit card, no strings attached](https://discuss.elastic.co/t/elastic-autoops-is-now-free-for-every-self-managed-cluster-no-license-upgrade-no-credit-card-no-strings-attached/385258)

<div class="topic-metadata">

**Author:** [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Replies:** 0\
**Last updated:** [February 26, 2026, 10:50pm UTC](https://discuss.elastic.co/t/elastic-autoops-is-now-free-for-every-self-managed-cluster-no-license-upgrade-no-credit-card-no-strings-attached/385258 "2026-02-26T22:50:08Z")

</div>

:partying\_face: Sharing this great news here for more visibility. Elastic AutoOps brings diagnostics and operational insights directly to your environment, transforming the way you manage Elasticsearch. Today, we are m…

---

## [Upgrade to 9.x - logstash-filter-elastic\_integration](https://discuss.elastic.co/t/upgrade-to-9-x-logstash-filter-elastic-integration/385035)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 5\
**Last updated:** [February 25, 2026, 2:24pm UTC](https://discuss.elastic.co/t/upgrade-to-9-x-logstash-filter-elastic-integration/385035 "2026-02-25T14:24:41Z")

</div>

Hello, we are planning our upgrade from 8.19.x to 9.2.x For some ingestflows we use the logstash-filter-elastic\_integration In the upgrade documentation Elastic recommends upgrading Elasticsearch first, followed by Ki…

---

## [Is it possible to add additional fields to the elastic serverless forwarder config?](https://discuss.elastic.co/t/is-it-possible-to-add-additional-fields-to-the-elastic-serverless-forwarder-config/385215)

<div class="topic-metadata">

**Author:** [@Lasra\_Bilaj](https://discuss.elastic.co/u/Lasra_Bilaj)\
**Replies:** 0\
**Last updated:** [February 25, 2026, 12:51pm UTC](https://discuss.elastic.co/t/is-it-possible-to-add-additional-fields-to-the-elastic-serverless-forwarder-config/385215 "2026-02-25T12:51:29Z")

</div>

In the config.yml for Elastics serverless forwarder, is it possible to do something like this. outputs: - type: elasticsearch args: cloud\_id: ${ELASTIC\_CLOUD\_ID} api\_key: ${ELASTIC\_API\_…

---

## [Elastic Agent + Security Onion](https://discuss.elastic.co/t/elastic-agent-security-onion/385187)

<div class="topic-metadata">

**Author:** [@harry22](https://discuss.elastic.co/u/harry22)\
**Replies:** 0\
**Last updated:** [February 24, 2026, 4:31pm UTC](https://discuss.elastic.co/t/elastic-agent-security-onion/385187 "2026-02-24T16:31:55Z")

</div>

Hi team, I recentely deployed Security onion lab on Vmware workstation Allowed allow hosts on Security Onion with my home private Subnet Checked and verified all services showing up on VM Checked and verified on Pow…

---

## [Is reindexing much heavier than initial indexing?](https://discuss.elastic.co/t/is-reindexing-much-heavier-than-initial-indexing/385177)

<div class="topic-metadata">

**Author:** [@some](https://discuss.elastic.co/u/some)\
**Replies:** 0\
**Last updated:** [February 24, 2026, 11:46am UTC](https://discuss.elastic.co/t/is-reindexing-much-heavier-than-initial-indexing/385177 "2026-02-24T11:46:39Z")

</div>

I have single server with ES 9.2.5. It has 40cores/256GB RAM/12TB of SSD. Thers are 2 aliases, ILM is rotating indices at 200GB (10 shards per index). Everything works fine in terms of indexing/search speed, but I can…

---

## [Having 2 allocation IDs in in\_sync\_allocations when there are no replicas](https://discuss.elastic.co/t/having-2-allocation-ids-in-in-sync-allocations-when-there-are-no-replicas/385174)

<div class="topic-metadata">

**Author:** [@winter\_crescents](https://discuss.elastic.co/u/winter_crescents)\
**Replies:** 2\
**Last updated:** [February 24, 2026, 10:23am UTC](https://discuss.elastic.co/t/having-2-allocation-ids-in-in-sync-allocations-when-there-are-no-replicas/385174 "2026-02-24T10:23:14Z")

</div>

Hi I am facing this issue where I had an index with an initial replication of 1. However, one year ago, due to disk storage issues I reduced the replication to 0. One year later, I now run this operation: GET /\_cluster…

---

## [Adding license seem to work, then reverts back to Basic](https://discuss.elastic.co/t/adding-license-seem-to-work-then-reverts-back-to-basic/385164)

<div class="topic-metadata">

**Author:** [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Replies:** 4\
**Last updated:** [February 24, 2026, 9:04am UTC](https://discuss.elastic.co/t/adding-license-seem-to-work-then-reverts-back-to-basic/385164 "2026-02-24T09:04:43Z")

</div>

Adding the license to our self-hosted Kubernetes cluster using the API, it gets accepted (API response true/valid) and we can see that the license is active in both Kibana and Stack Monitoring. However, shortly after the…

---

## [Stack monitoring understanding](https://discuss.elastic.co/t/stack-monitoring-understanding/385140)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [February 24, 2026, 7:05am UTC](https://discuss.elastic.co/t/stack-monitoring-understanding/385140 "2026-02-24T07:05:53Z")

</div>

Hi, Community, I am trying to understand this stack monitoring one of my busy index’s advance monitoring show this is this means total 888 search request came in and combine it tool 918.49ms ? or is it just one searc…

---

## [Enabling auth after upgrading elasticsearch cluster from 7.17.9 to 8.17.6](https://discuss.elastic.co/t/enabling-auth-after-upgrading-elasticsearch-cluster-from-7-17-9-to-8-17-6/385154)

<div class="topic-metadata">

**Author:** [@syed-asak](https://discuss.elastic.co/u/syed-asak)\
**Replies:** 4\
**Last updated:** [February 23, 2026, 10:42am UTC](https://discuss.elastic.co/t/enabling-auth-after-upgrading-elasticsearch-cluster-from-7-17-9-to-8-17-6/385154 "2026-02-23T10:42:30Z")

</div>

Hello everyone, I am looking for guidance on safely enabling security on an existing large Elasticsearch cluster. Current Environment Elasticsearch version: 8.17.6 Deployment type: VM-based cluster (not Kubernetes…

---

## [“libvec.dylib” Not Opened](https://discuss.elastic.co/t/libvec-dylib-not-opened/385136)

<div class="topic-metadata">

**Author:** [@anjanesh](https://discuss.elastic.co/u/anjanesh)\
**Replies:** 3\
**Last updated:** [February 21, 2026, 4:16am UTC](https://discuss.elastic.co/t/libvec-dylib-not-opened/385136 "2026-02-21T04:16:04Z")

</div>

I can’t seem to get EleasticSearch 9.3.0 working on my MacBook Air M2 - Sequoia 15.7.4 (24G517) bin % ./elasticsearch --version Version: 9.3.0, Build: tar/17b451d8979a29e31935fe1eb901310350b30e62/2026-01-29T10:05:46.708…

---

## [Too\_many\_scroll\_contexts\_exception](https://discuss.elastic.co/t/too-many-scroll-contexts-exception/384981)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 9\
**Last updated:** [February 20, 2026, 10:07pm UTC](https://discuss.elastic.co/t/too-many-scroll-contexts-exception/384981 "2026-02-20T22:07:39Z")

</div>

elasticsearch -{"statusCode":500,"error":"Internal Server Error","message":"\[search\_phase\_execution\_exception\\n\\tRoot causes:\\n\\t\\ttoo\_many\_scroll\_contexts\_exception: Trying to create too many scroll contexts. Must be le…

---

## [Elasticsearch classic plugin: problem with entitlements](https://discuss.elastic.co/t/elasticsearch-classic-plugin-problem-with-entitlements/385137)

<div class="topic-metadata">

**Author:** [@Peter\_van\_der\_Weerd](https://discuss.elastic.co/u/Peter_van_der_Weerd)\
**Replies:** 1\
**Last updated:** [February 20, 2026, 3:55pm UTC](https://discuss.elastic.co/t/elasticsearch-classic-plugin-problem-with-entitlements/385137 "2026-02-20T15:55:33Z")

</div>

I’m writing a classic plugin for a custom similarity. ES9.0.1. The plugin tries to load resources from its own jar: Enumeration\<java.net.URL\> resources = Utils.class.getClassLoader().getResources("META-INF/MANIFEST.MF"…

---

## [How do you calculate the average document size in streams?](https://discuss.elastic.co/t/how-do-you-calculate-the-average-document-size-in-streams/385117)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 1\
**Last updated:** [February 19, 2026, 4:08pm UTC](https://discuss.elastic.co/t/how-do-you-calculate-the-average-document-size-in-streams/385117 "2026-02-19T16:08:24Z")

</div>

Streams is a really great feature that you have added, which was really needed. Now for the question. As the title suggests. How does the daily average get calculated? I tried calculating the average document size by…

---

## [How to implement RAG with index mapping](https://discuss.elastic.co/t/how-to-implement-rag-with-index-mapping/385095)

<div class="topic-metadata">

**Author:** [@kirancchand](https://discuss.elastic.co/u/kirancchand)\
**Replies:** 0\
**Last updated:** [February 18, 2026, 12:22pm UTC](https://discuss.elastic.co/t/how-to-implement-rag-with-index-mapping/385095 "2026-02-18T12:22:39Z")

</div>

I need to create a RAG application which use mappings of my index to create query and execute and then response back.can i get any idea to do this? does vectorise and implement RAG or my query which would be better to im…

---

## [Elasticsearch put all indices to read-only mode before upgrade](https://discuss.elastic.co/t/elasticsearch-put-all-indices-to-read-only-mode-before-upgrade/378590)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 7\
**Last updated:** [February 18, 2026, 10:41am UTC](https://discuss.elastic.co/t/elasticsearch-put-all-indices-to-read-only-mode-before-upgrade/378590 "2026-02-18T10:41:01Z")

</div>

Hello, Is is possible to put all indexes including all system to read-only mode ? I was looking about that but could find only read-only mode to dedicated one index. I'm doing test upgrade and everytime when I try to …

---

## [Field \_size on data stream](https://discuss.elastic.co/t/field-size-on-data-stream/384982)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 15\
**Last updated:** [February 18, 2026, 10:18am UTC](https://discuss.elastic.co/t/field-size-on-data-stream/384982 "2026-02-18T10:18:30Z")

</div>

Hi,I'd like to set the \_size field on a data stream associated with an integration. How can I do this? The data stream has a custom index template associated with it: GET \_index\_template/logs-thales\_udp.log-custom { "…

---

## [Is it safe to upgrade on cloud using upgrade button from console](https://discuss.elastic.co/t/is-it-safe-to-upgrade-on-cloud-using-upgrade-button-from-console/385077)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 0\
**Last updated:** [February 17, 2026, 11:10am UTC](https://discuss.elastic.co/t/is-it-safe-to-upgrade-on-cloud-using-upgrade-button-from-console/385077 "2026-02-17T11:10:58Z")

</div>

I am upgrading from v8.9 to v8.19.x to v9.3.0. we are currently using java HLR 7.17. So, I want to move to server v8.19.x first and then deploy java REST v8.19 and then upgrade server to v9.3.0. Is it ok to use upgrade …

---

## [Nodes Stats Breaker Tripped Meaning](https://discuss.elastic.co/t/nodes-stats-breaker-tripped-meaning/359392)

<div class="topic-metadata">

**Author:** [@jquisenberry](https://discuss.elastic.co/u/jquisenberry)\
**Replies:** 1\
**Last updated:** [February 17, 2026, 11:00am UTC](https://discuss.elastic.co/t/nodes-stats-breaker-tripped-meaning/359392 "2026-02-17T11:00:33Z")

</div>

In the Nodes Stats API, what does "tripped": ### mean? I am running version 7.17. I understand that tripping a circuit breaker means that some activity has caused JVM heap consumption in excess of limit\_size. What I wo…

---

## [Long-term snapshot compatibility across major versions (10+ year archive use case)](https://discuss.elastic.co/t/long-term-snapshot-compatibility-across-major-versions-10-year-archive-use-case/385068)

<div class="topic-metadata">

**Author:** [@jiriNovotny](https://discuss.elastic.co/u/jiriNovotny)\
**Replies:** 9\
**Last updated:** [February 16, 2026, 8:01pm UTC](https://discuss.elastic.co/t/long-term-snapshot-compatibility-across-major-versions-10-year-archive-use-case/385068 "2026-02-16T20:01:31Z")

</div>

Hello, I’m looking for clarification regarding the functionality described in the documentation about reading indices from older Elasticsearch versions: Currently, our process is as follows: We store indices as sna…

---

## [Best practices for migrating ELK artifacts and configurations across environments](https://discuss.elastic.co/t/best-practices-for-migrating-elk-artifacts-and-configurations-across-environments/385051)

<div class="topic-metadata">

**Author:** [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Replies:** 4\
**Last updated:** [February 16, 2026, 1:25pm UTC](https://discuss.elastic.co/t/best-practices-for-migrating-elk-artifacts-and-configurations-across-environments/385051 "2026-02-16T13:25:19Z")

</div>

Hi All, I am looking for guidance on best practices for migrating ELK artifacts from lower environments (e.g., Dev/Test) to higher environments (e.g., UAT/Prod). For application code, we typically use GitLab/Jenkins wi…

---

## [Packaging quantity not searchable](https://discuss.elastic.co/t/packaging-quantity-not-searchable/384914)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 2\
**Last updated:** [February 16, 2026, 10:05am UTC](https://discuss.elastic.co/t/packaging-quantity-not-searchable/384914 "2026-02-16T10:05:44Z")

</div>

We are currently getting zero results when searching with term along with quantity for example coke 1l. So, I want to index a new field packquantity which has values like 1 kg, 500 g, 2l. But my concern here is how to ha…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=6)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=8)
