# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=71

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 72

---

## [Two cluster member failing to start](https://discuss.elastic.co/t/two-cluster-member-failing-to-start/368485)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 4\
**Last updated:** [October 11, 2024, 5:37pm UTC](https://discuss.elastic.co/t/two-cluster-member-failing-to-start/368485 "2024-10-11T17:37:51Z")

</div>

Version 1.17.12 two members of the my cluster are failing to start with the following error \[2024-10-09T15:17:43,176\]\[ERROR\]\[o.e.b.Bootstrap \] \[secesprd07\] node validation exception \[1\] bootstrap checks failed…

---

## [Error Setting ignore\_dynamic\_beyond\_limit to false](https://discuss.elastic.co/t/error-setting-ignore-dynamic-beyond-limit-to-false/368637)

<div class="topic-metadata">

**Author:** [@palkema](https://discuss.elastic.co/u/palkema)\
**Replies:** 2\
**Last updated:** [October 11, 2024, 3:41pm UTC](https://discuss.elastic.co/t/error-setting-ignore-dynamic-beyond-limit-to-false/368637 "2024-10-11T15:41:21Z")

</div>

Hi, I am trying to set the setting, index.mapping.total\_fields.ignore\_dynamic\_beyond\_limit to equal false. This is mentioned in the documentation here. When I run the request below, I am getting an error PUT /test-in…

---

## [KNN search fails on empty index](https://discuss.elastic.co/t/knn-search-fails-on-empty-index/368670)

<div class="topic-metadata">

**Author:** [@JornWildt](https://discuss.elastic.co/u/JornWildt)\
**Replies:** 8\
**Last updated:** [October 11, 2024, 1:07pm UTC](https://discuss.elastic.co/t/knn-search-fails-on-empty-index/368670 "2024-10-11T13:07:08Z")

</div>

Doing a KNN search on an empty index fails with "All shards failed". A normal search with a GET like this succeeds with zero its: https://host/my-index/\_search But if I do a POST like this, ES fails with status code 4…

---

## [Restoring 7.x snapshot to fresh 8.14.3 ECK: System data streams missing after migration](https://discuss.elastic.co/t/restoring-7-x-snapshot-to-fresh-8-14-3-eck-system-data-streams-missing-after-migration/368674)

<div class="topic-metadata">

**Author:** [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Replies:** 0\
**Last updated:** [October 11, 2024, 9:00am UTC](https://discuss.elastic.co/t/restoring-7-x-snapshot-to-fresh-8-14-3-eck-system-data-streams-missing-after-migration/368674 "2024-10-11T09:00:13Z")

</div>

I created the snapshot of my old version 7.x elk stack , and I now I am trying to restore the old snapshot on the new eck-elasticsearch version 8.14.3. Context: Upgraded from Elasticsearch v7.17.22 to v8.14.3 using ECK…

---

## [Winlogbeat process drop event doesn't work](https://discuss.elastic.co/t/winlogbeat-process-drop-event-doesnt-work/368675)

<div class="topic-metadata">

**Author:** [@kingofsa06](https://discuss.elastic.co/u/kingofsa06)\
**Replies:** 0\
**Last updated:** [October 11, 2024, 9:02am UTC](https://discuss.elastic.co/t/winlogbeat-process-drop-event-doesnt-work/368675 "2024-10-11T09:02:53Z")

</div>

Hi all, I have a confuse question. I need to transfer IIS logs from Exchange Server. But the data is too huge for server. So I want to have only wan IP log in Exchange Server to transport to graylog And used the win…

---

## [BulkRequest failed when handle JSON data](https://discuss.elastic.co/t/bulkrequest-failed-when-handle-json-data/368611)

<div class="topic-metadata">

**Author:** [@ChatLee](https://discuss.elastic.co/u/ChatLee)\
**Replies:** 4\
**Last updated:** [October 11, 2024, 2:44am UTC](https://discuss.elastic.co/t/bulkrequest-failed-when-handle-json-data/368611 "2024-10-11T02:44:44Z")

</div>

Hi all, We want to index data into the ES with bulk api in the java client, the dependency is: elasticsearch-java: 8.13.2 the source data is a JSON string like this: t String createDoc1 = "{" + " …

---

## [Documentation bug on splitting shards -- free disk space requirement?](https://discuss.elastic.co/t/documentation-bug-on-splitting-shards-free-disk-space-requirement/367203)

<div class="topic-metadata">

**Author:** [@Jamshid](https://discuss.elastic.co/u/Jamshid)\
**Replies:** 3\
**Last updated:** [October 11, 2024, 2:50am UTC](https://discuss.elastic.co/t/documentation-bug-on-splitting-shards-free-disk-space-requirement/367203 "2024-10-11T02:50:06Z")

</div>

This doc says elasticsearch requires enough free disk space for a second copy of the index when splitting shards. The node handling the split process must have sufficient free disk space to accommodate a second copy …

---

## [Elasticsearch 8.15.1 in FIPS mode](https://discuss.elastic.co/t/elasticsearch-8-15-1-in-fips-mode/366983)

<div class="topic-metadata">

**Author:** [@fox9](https://discuss.elastic.co/u/fox9)\
**Replies:** 12\
**Last updated:** [October 11, 2024, 2:25am UTC](https://discuss.elastic.co/t/elasticsearch-8-15-1-in-fips-mode/366983 "2024-10-11T02:25:53Z")

</div>

Heya, I am trying to configure a 3-node cluster in FIPS mode but TLS doesn't seem to work. Here are the system details: Ubuntu 20.04 Elasticsearch 8.15.1 FIPS enabled: bc-fips-2.0.0.jar, bctls-fips-2.0.19.jar, bcpkix-…

---

## [Remove xpack.security.authc.realms.active\_directory.my\_ad.secure\_bind\_password](https://discuss.elastic.co/t/remove-xpack-security-authc-realms-active-directory-my-ad-secure-bind-password/368436)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 1\
**Last updated:** [October 11, 2024, 2:23am UTC](https://discuss.elastic.co/t/remove-xpack-security-authc-realms-active-directory-my-ad-secure-bind-password/368436 "2024-10-11T02:23:17Z")

</div>

Hello I was trying to setup AD auth but I see the license doesnt support it anymore so I was trying to remove it but now I get Caused by: org.elasticsearch.common.settings.SettingsException: found settings for the real…

---

## [Elasticsearch watcher Error](https://discuss.elastic.co/t/elasticsearch-watcher-error/368562)

<div class="topic-metadata">

**Author:** [@0593098](https://discuss.elastic.co/u/0593098)\
**Replies:** 1\
**Last updated:** [October 11, 2024, 2:20am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-error/368562 "2024-10-11T02:20:45Z")

</div>

Below is my watcher code its simply to send report via email. { "trigger": { "schedule": { "interval": "1m" } }, "input": { "none": {} }, "condition": { "always": {} }, "actions": { "email\_admin": { "email…

---

## [\[QUERY\] Top hits of nested fields sum aggregated by parent document](https://discuss.elastic.co/t/query-top-hits-of-nested-fields-sum-aggregated-by-parent-document/368656)

<div class="topic-metadata">

**Author:** [@zephyx](https://discuss.elastic.co/u/zephyx)\
**Replies:** 0\
**Last updated:** [October 10, 2024, 11:27pm UTC](https://discuss.elastic.co/t/query-top-hits-of-nested-fields-sum-aggregated-by-parent-document/368656 "2024-10-10T23:27:24Z")

</div>

Hi, I am a begginner in Elastic Search and I don't know how to write my aggregation correctly and even if what I want is possible. But between nested, inner\_hits, top\_hits, reverse\_nested, bucket\_sort, composite, etc..…

---

## [Elasticsearch’s S3 Snapshot Repository: The Mystery of the Inaccessible S3 Bucket ==\> Access Denied](https://discuss.elastic.co/t/elasticsearch-s-s3-snapshot-repository-the-mystery-of-the-inaccessible-s3-bucket-access-denied/362900)

<div class="topic-metadata">

**Author:** [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Replies:** 16\
**Last updated:** [October 10, 2024, 8:27pm UTC](https://discuss.elastic.co/t/elasticsearch-s-s3-snapshot-repository-the-mystery-of-the-inaccessible-s3-bucket-access-denied/362900 "2024-10-10T20:27:20Z")

</div>

Elasticsearch Version 7.17.12 Installed Plugins repository-s3 Java Version JAVA\_RUNTIME\_VERSION="20.0.2+9-78 OS Version Linux elasticsearch-data-0 5.10.214-202.855.amzn2.x86\_64 #1 SMP Tue Apr 9 06:57:12 UTC 2024 x86\_6…

---

## [S3 Snapshots (Storage Tiers)](https://discuss.elastic.co/t/s3-snapshots-storage-tiers/368643)

<div class="topic-metadata">

**Author:** [@Devin\_Acosta](https://discuss.elastic.co/u/Devin_Acosta)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 8:31pm UTC](https://discuss.elastic.co/t/s3-snapshots-storage-tiers/368643 "2024-10-10T20:31:33Z")

</div>

I have been successfully using the Elasticsearch S3 Snapshot feature with version 7.15.1, and we are currently using the most expensive (standard) tier. My work has asked me to look into moving to data into S3 Glacier In…

---

## [How to correctly calculate sync duration of connector run](https://discuss.elastic.co/t/how-to-correctly-calculate-sync-duration-of-connector-run/368623)

<div class="topic-metadata">

**Author:** [@Ankur\_Mathur](https://discuss.elastic.co/u/Ankur_Mathur)\
**Replies:** 2\
**Last updated:** [October 10, 2024, 11:43am UTC](https://discuss.elastic.co/t/how-to-correctly-calculate-sync-duration-of-connector-run/368623 "2024-10-10T11:43:47Z")

</div>

I need some help in calculating sync duration for a connector run. I am trying to measure performance of connector. Here is what I am observing:- My Google Drive connector is running for 5m and 20 seconds and has upser…

---

## [Integrating Elasticsearch into Hugo project using Webpack 5](https://discuss.elastic.co/t/integrating-elasticsearch-into-hugo-project-using-webpack-5/368610)

<div class="topic-metadata">

**Author:** [@samiahmedsiddiqui](https://discuss.elastic.co/u/samiahmedsiddiqui)\
**Replies:** 0\
**Last updated:** [October 10, 2024, 9:10am UTC](https://discuss.elastic.co/t/integrating-elasticsearch-into-hugo-project-using-webpack-5/368610 "2024-10-10T09:10:01Z")

</div>

I am integrating Elasticsearch into my Hugo project using Webpack 5. I have created a new JavaScript file and imported the Elasticsearch client library. const { Client } = require('@elastic/elasticsearch'); However, I …

---

## [GeoIP Service Elasticsearch requires connection to storage.googleapis.com](https://discuss.elastic.co/t/geoip-service-elasticsearch-requires-connection-to-storage-googleapis-com/368618)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 0\
**Last updated:** [October 10, 2024, 9:55am UTC](https://discuss.elastic.co/t/geoip-service-elasticsearch-requires-connection-to-storage-googleapis-com/368618 "2024-10-10T09:55:55Z")

</div>

Hello everyone, i'am currently trying to setup the geoip service of elasticsearch. I'am mainly following the steps outlined in the documentation: Now i came across the circumstance that the geoip service requires to …

---

## [ES 8.6 - High contention over Global Ordingals Field Data for terms aggregation under load](https://discuss.elastic.co/t/es-8-6-high-contention-over-global-ordingals-field-data-for-terms-aggregation-under-load/368525)

<div class="topic-metadata">

**Author:** [@Mikhail\_Khludnev](https://discuss.elastic.co/u/Mikhail_Khludnev)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 8:33am UTC](https://discuss.elastic.co/t/es-8-6-high-contention-over-global-ordingals-field-data-for-terms-aggregation-under-load/368525 "2024-10-10T08:33:39Z")

</div>

Hello Under a moderate load (mostly filtering and massive terms aggregation) I see "benign" hot\_threads ie ..8.6..index.fielddata.ordinals.GlobalOrdinalMapping.lookupOrd(GlobalOrdinalMapping.java:71) ..8.6..index.mappe…

---

## [What are the requirements?](https://discuss.elastic.co/t/what-are-the-requirements/368279)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 52\
**Last updated:** [October 10, 2024, 7:27am UTC](https://discuss.elastic.co/t/what-are-the-requirements/368279 "2024-10-10T07:27:40Z")

</div>

Hi If I have 1500 devices and each device uploads about 3 GB of data per day How much do I need a node? And what are their specifications such as RAM, hard disk and CPU ?

---

## [Scientific Notation appearing for very small numbers during Sum aggregation](https://discuss.elastic.co/t/scientific-notation-appearing-for-very-small-numbers-during-sum-aggregation/368583)

<div class="topic-metadata">

**Author:** [@tejas7](https://discuss.elastic.co/u/tejas7)\
**Replies:** 0\
**Last updated:** [October 10, 2024, 3:50am UTC](https://discuss.elastic.co/t/scientific-notation-appearing-for-very-small-numbers-during-sum-aggregation/368583 "2024-10-10T03:50:23Z")

</div>

We are getting scientific notation for very small values approximately to zero when using the sum aggregation in Kibana visualizations. Could you please help us to workaround or provide a fix for the issue. Thanks i…

---

## [Create snapshot](https://discuss.elastic.co/t/create-snapshot/363915)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 15\
**Last updated:** [July 28, 2024, 5:49pm UTC](https://discuss.elastic.co/t/create-snapshot/363915 "2024-07-28T17:49:03Z")

</div>

I have a node1, node2, node3 contract in several places and I want to make a snapshot of a specific indicator that is available for example in node2 I made the path.repo in the configuration file for each node and when…

---

## [Unclear minhash filter behavior in near-duplicate detection for short texts](https://discuss.elastic.co/t/unclear-minhash-filter-behavior-in-near-duplicate-detection-for-short-texts/368561)

<div class="topic-metadata">

**Author:** [@m-sean](https://discuss.elastic.co/u/m-sean)\
**Replies:** 1\
**Last updated:** [October 9, 2024, 8:29pm UTC](https://discuss.elastic.co/t/unclear-minhash-filter-behavior-in-near-duplicate-detection-for-short-texts/368561 "2024-10-09T20:29:51Z")

</div>

I am working on a solution for near-duplicate detection of short texts (social media, review, snippetized articles, etc). I have been attempting to configure the MinHash filter per the documentation. I have set the para…

---

## [Create a search for IOCs](https://discuss.elastic.co/t/create-a-search-for-iocs/368532)

<div class="topic-metadata">

**Author:** [@JA\_cintegration](https://discuss.elastic.co/u/JA_cintegration)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 1:17pm UTC](https://discuss.elastic.co/t/create-a-search-for-iocs/368532 "2024-10-09T13:17:54Z")

</div>

Trying to create a query search for IPs found in the last 24 hours. I have been testing with: GET /index/\_search { "query": { "match": { "event.category": "network" } } } Or: POST /\*index\_name\*/\_as…

---

## [Need Help in understanding how to convert Datastreams to Regular Index](https://discuss.elastic.co/t/need-help-in-understanding-how-to-convert-datastreams-to-regular-index/368113)

<div class="topic-metadata">

**Author:** [@kushalOtter](https://discuss.elastic.co/u/kushalOtter)\
**Replies:** 4\
**Last updated:** [October 9, 2024, 7:46pm UTC](https://discuss.elastic.co/t/need-help-in-understanding-how-to-convert-datastreams-to-regular-index/368113 "2024-10-09T19:46:45Z")

</div>

Hi all, So we are using EFK stack for logging purposes. We have ES at 7.17.23 and filebeat at 7 version. Unfortunately on some of the machines, the filebeat got upgraded to 8 , it forcefully modified the Index template …

---

## [How I can do rollover log with serilog app?](https://discuss.elastic.co/t/how-i-can-do-rollover-log-with-serilog-app/368559)

<div class="topic-metadata">

**Author:** [@felipej](https://discuss.elastic.co/u/felipej)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 7:29pm UTC](https://discuss.elastic.co/t/how-i-can-do-rollover-log-with-serilog-app/368559 "2024-10-09T19:29:48Z")

</div>

Hello guys. I have some apps .net running in my environment. My apps are using serilog to send logs to Elasticsearch. We aren't use any plugin or middle to do this, like logstash, filebeat, etc. When I leave the app to…

---

## [Need help with search\_after and PIT for deep pagination](https://discuss.elastic.co/t/need-help-with-search-after-and-pit-for-deep-pagination/368484)

<div class="topic-metadata">

**Author:** [@jax020](https://discuss.elastic.co/u/jax020)\
**Replies:** 11\
**Last updated:** [October 9, 2024, 4:26pm UTC](https://discuss.elastic.co/t/need-help-with-search-after-and-pit-for-deep-pagination/368484 "2024-10-09T16:26:33Z")

</div>

okay so i need help. i am currently working on a project where millions of documents have to be displayed. Currently, there are 50 documents on each page, and there are 200 pages, totaling 10,000 documents. however, i wa…

---

## [Widows file server crawling and indexing](https://discuss.elastic.co/t/widows-file-server-crawling-and-indexing/368531)

<div class="topic-metadata">

**Author:** [@Tuncay\_Gunduz](https://discuss.elastic.co/u/Tuncay_Gunduz)\
**Replies:** 1\
**Last updated:** [October 9, 2024, 2:22pm UTC](https://discuss.elastic.co/t/widows-file-server-crawling-and-indexing/368531 "2024-10-09T14:22:56Z")

</div>

Hi I m new to Elastic search. I looking into this if feasible as on premises Install Elastic on a linux server (on premises) Index our files located on windows server (on premises - same LAN) search from a basic page…

---

## [Does Elastic internally perform 'query' and 'suggest' requests in parallel?](https://discuss.elastic.co/t/does-elastic-internally-perform-query-and-suggest-requests-in-parallel/368536)

<div class="topic-metadata">

**Author:** [@alliswell](https://discuss.elastic.co/u/alliswell)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 1:40pm UTC](https://discuss.elastic.co/t/does-elastic-internally-perform-query-and-suggest-requests-in-parallel/368536 "2024-10-09T13:40:42Z")

</div>

Elastics search provides feature to get search results and suggestions in a single request, reducing network overhead. POST my-index-000001/\_search { "query" : { "match": { "message": "tring out Elasticsearc…

---

## [Gatling test on ES EKS cluster](https://discuss.elastic.co/t/gatling-test-on-es-eks-cluster/368295)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 6\
**Last updated:** [October 9, 2024, 11:13am UTC](https://discuss.elastic.co/t/gatling-test-on-es-eks-cluster/368295 "2024-10-09T11:13:38Z")

</div>

Maybe someone has some expierence in performing gatling test on Elasticsearch? Indeed I'm interesting on query responses time, I have a cluster build on 10 data nodes(14 CPU handling ES) with 52GB RAMnodes a 3(6CPU) mast…

---

## [Multilingual-e5 sparse vector support](https://discuss.elastic.co/t/multilingual-e5-sparse-vector-support/368497)

<div class="topic-metadata">

**Author:** [@czek0](https://discuss.elastic.co/u/czek0)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 7:10am UTC](https://discuss.elastic.co/t/multilingual-e5-sparse-vector-support/368497 "2024-10-09T07:10:21Z")

</div>

Hello Upon investigatoing into your examples for the miltilingual-e5-base, I see you are using the dense vector type as the passage\_embedding. Is it possible to use sparse vector types as the passage\_embedding? And how …

---

## [Reallocate shards from DR to PR](https://discuss.elastic.co/t/reallocate-shards-from-dr-to-pr/368492)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 6:15am UTC](https://discuss.elastic.co/t/reallocate-shards-from-dr-to-pr/368492 "2024-10-09T06:15:54Z")

</div>

Hello, I have an elastic cluster with seven PR nodes and three DR nodes. All nodes are either master, hot or warm configured. My primary and replica shards are distributed randomly in between the PR and DR nodes in the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=70)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=72)
