# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=76

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 77

---

## [Hit.sort() method contract cnanges](https://discuss.elastic.co/t/hit-sort-method-contract-cnanges/366686)

<div class="topic-metadata">

**Author:** [@surkovoleg2010](https://discuss.elastic.co/u/surkovoleg2010)\
**Replies:** 1\
**Last updated:** [September 23, 2024, 3:31pm UTC](https://discuss.elastic.co/t/hit-sort-method-contract-cnanges/366686 "2024-09-23T15:31:19Z")

</div>

Hello, we use elasticsearch-java client version 8.4.3. after upgrading to 8.13.4 we found that the contract for Hit.sort method changed (returns List\<FieldValue\> instead of List\<String\>). could you suggest please how to…

---

## [Unauthorized User Error and Script Execution Issues During Kibana Setup with Elasticsearch 7.17.13](https://discuss.elastic.co/t/unauthorized-user-error-and-script-execution-issues-during-kibana-setup-with-elasticsearch-7-17-13/366971)

<div class="topic-metadata">

**Author:** [@kshanuy](https://discuss.elastic.co/u/kshanuy)\
**Replies:** 0\
**Last updated:** [September 23, 2024, 3:03pm UTC](https://discuss.elastic.co/t/unauthorized-user-error-and-script-execution-issues-during-kibana-setup-with-elasticsearch-7-17-13/366971 "2024-09-23T15:03:16Z")

</div>

I am encountering multiple errors while setting up Kibana with Elasticsearch version 7.17.13. The primary issues are: Unauthorized User error with the fleet plugin, indicating a failure in setting up central management…

---

## [How to combine KNN and query\_string search](https://discuss.elastic.co/t/how-to-combine-knn-and-query-string-search/366868)

<div class="topic-metadata">

**Author:** [@ivanqwam](https://discuss.elastic.co/u/ivanqwam)\
**Replies:** 5\
**Last updated:** [September 23, 2024, 2:05pm UTC](https://discuss.elastic.co/t/how-to-combine-knn-and-query-string-search/366868 "2024-09-23T14:05:11Z")

</div>

I am trying to combine both: KNN query Query\_string query When I search for a non existing ID with query\_string: POST myindex/\_search { "query": {"query\_string": {"default\_operator": "AND", "query": "id:\\"my\_wrong\_i…

---

## [Elastic cloud and Java garbage collector](https://discuss.elastic.co/t/elastic-cloud-and-java-garbage-collector/366962)

<div class="topic-metadata">

**Author:** [@Joey\_Visbeen](https://discuss.elastic.co/u/Joey_Visbeen)\
**Replies:** 0\
**Last updated:** [September 23, 2024, 12:57pm UTC](https://discuss.elastic.co/t/elastic-cloud-and-java-garbage-collector/366962 "2024-09-23T12:57:22Z")

</div>

Currently, I have a hosted deployment on the elastic cloud. Within this cluster, I store all the elastic cloud logs in a datastream. Now, I have run into the issue that there is too much garbage collector logs. I would l…

---

## [ELK cluster 5 data 1 master 1 ingest 1 transfer](https://discuss.elastic.co/t/elk-cluster-5-data-1-master-1-ingest-1-transfer/366958)

<div class="topic-metadata">

**Author:** [@sloth\_ape](https://discuss.elastic.co/u/sloth_ape)\
**Replies:** 0\
**Last updated:** [September 23, 2024, 11:40am UTC](https://discuss.elastic.co/t/elk-cluster-5-data-1-master-1-ingest-1-transfer/366958 "2024-09-23T11:40:30Z")

</div>

Hi guys i want to create ELK cluster with 5 data 1 master 1 ingest and 1 transfer i started installing to the all node elasticsearch and i wanna create cluster with enrollment token but i have problem to creating enro…

---

## [Discrepancy in Shard and Index Count in Cluster Stats](https://discuss.elastic.co/t/discrepancy-in-shard-and-index-count-in-cluster-stats/366953)

<div class="topic-metadata">

**Author:** [@Wajid\_Hussain](https://discuss.elastic.co/u/Wajid_Hussain)\
**Replies:** 0\
**Last updated:** [September 23, 2024, 10:30am UTC](https://discuss.elastic.co/t/discrepancy-in-shard-and-index-count-in-cluster-stats/366953 "2024-09-23T10:30:34Z")

</div>

Hi, I’m noticing a discrepancy in the cluster stats on my Elastic Cloud deployment. When running GET /\_cluster/stats?pretty, it shows 122 indices and shards, despite having only 6 primary indices and shards. Could some…

---

## [Decrypted value not available in search box when sending hashed query](https://discuss.elastic.co/t/decrypted-value-not-available-in-search-box-when-sending-hashed-query/366945)

<div class="topic-metadata">

**Author:** [@Pankaj\_yadav](https://discuss.elastic.co/u/Pankaj_yadav)\
**Replies:** 0\
**Last updated:** [September 23, 2024, 9:08am UTC](https://discuss.elastic.co/t/decrypted-value-not-available-in-search-box-when-sending-hashed-query/366945 "2024-09-23T09:08:06Z")

</div>

I am encrypting the search query before sending user to results page , where user is not able to see the query in address bar(only encrypted field is visible), but before sending to Elasticsearch I decrypt the field and …

---

## [AWS API Intergration with Mulesoft](https://discuss.elastic.co/t/aws-api-intergration-with-mulesoft/366937)

<div class="topic-metadata">

**Author:** [@brother\_info](https://discuss.elastic.co/u/brother_info)\
**Replies:** 1\
**Last updated:** [September 23, 2024, 8:10am UTC](https://discuss.elastic.co/t/aws-api-intergration-with-mulesoft/366937 "2024-09-23T08:10:09Z")

</div>

I am trying to call my AWS API through mulesoft. My AWS API is perfectly working in browser and Postman. I have created HTTP listener and HTTP request in mulesoft but it is giving HTTP connectivity error. Does anyone h…

---

## [How to get http status code | Python](https://discuss.elastic.co/t/how-to-get-http-status-code-python/366915)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [September 23, 2024, 7:22am UTC](https://discuss.elastic.co/t/how-to-get-http-status-code-python/366915 "2024-09-23T07:22:58Z")

</div>

Hi Team I want to get status code while connecting to cluster. from elasticsearch import Elasticsearch client = Elasticsearch( "https://0.0.0.0.:9200", basic\_auth=("elastic", "elastic"), verify\_certs=False…

---

## [Need an example to search incoming value in a Multi valued attribute](https://discuss.elastic.co/t/need-an-example-to-search-incoming-value-in-a-multi-valued-attribute/366917)

<div class="topic-metadata">

**Author:** [@vkrishna](https://discuss.elastic.co/u/vkrishna)\
**Replies:** 1\
**Last updated:** [September 22, 2024, 4:20pm UTC](https://discuss.elastic.co/t/need-an-example-to-search-incoming-value-in-a-multi-valued-attribute/366917 "2024-09-22T16:20:28Z")

</div>

Hi Team, I need an example to search a value in a multi valued attribute. Example: Let's say I have below documents in an index. \[ { "id":1, "lenders"=\[32,76\], "lender\_yield"=1.0 }, { "id":2, "lenders"=\[1,9\], "le…

---

## [How to deserialize SearchResponse properly in Elasticsearch Java Client](https://discuss.elastic.co/t/how-to-deserialize-searchresponse-properly-in-elasticsearch-java-client/366904)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 22, 2024, 4:15pm UTC](https://discuss.elastic.co/t/how-to-deserialize-searchresponse-properly-in-elasticsearch-java-client/366904 "2024-09-22T16:15:14Z")

</div>

I have Elasticsearch version 8.5.3 and many documents in my index. A document looks like this: { "myArray": \[ { "myGrocery": { "myId": "aString", "apple": "aString", "banana": aNumbe…

---

## [VA's in elastic search](https://discuss.elastic.co/t/vas-in-elastic-search/366902)

<div class="topic-metadata">

**Author:** [@amjad](https://discuss.elastic.co/u/amjad)\
**Replies:** 0\
**Last updated:** [September 21, 2024, 6:18am UTC](https://discuss.elastic.co/t/vas-in-elastic-search/366902 "2024-09-21T06:18:41Z")

</div>

Hi All, Hope all are doing well. we are creating the users in elastic cluster with the rest api's of elastic, now We have received 3 VA's for the elasticsearch api's, Insecure HTTP methods enabled Missing Cache Contr…

---

## [Sparse Vectors](https://discuss.elastic.co/t/sparse-vectors/366856)

<div class="topic-metadata">

**Author:** [@Harsh\_Sonaiya](https://discuss.elastic.co/u/Harsh_Sonaiya)\
**Replies:** 18\
**Last updated:** [September 20, 2024, 3:30pm UTC](https://discuss.elastic.co/t/sparse-vectors/366856 "2024-09-20T15:30:53Z")

</div>

Is there a way to create index with sparse vectors and insert sparse vectors

---

## [6.X License time running out](https://discuss.elastic.co/t/6-x-license-time-running-out/366869)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 1\
**Last updated:** [September 20, 2024, 3:02pm UTC](https://discuss.elastic.co/t/6-x-license-time-running-out/366869 "2024-09-20T15:02:56Z")

</div>

Hello, I recently made this post this post basically asks what happens when Elastic 5.6's license time runs out. Now I was wondering what would happen in V6.X if the license were to run out. Any insights are appreciat…

---

## [How to restore source-only indices and rebuild index](https://discuss.elastic.co/t/how-to-restore-source-only-indices-and-rebuild-index/366871)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 0\
**Last updated:** [September 20, 2024, 10:13am UTC](https://discuss.elastic.co/t/how-to-restore-source-only-indices-and-rebuild-index/366871 "2024-09-20T10:13:16Z")

</div>

When I created the snapshot repo, I chose source-only to save space. When I restored it, I found it didn't rebuild the index. Instead of restoring it to a temporary index, then call the reindex API. Is there a simpler m…

---

## [Dynamic template create error in 8.14+ java, works in 8.12](https://discuss.elastic.co/t/dynamic-template-create-error-in-8-14-java-works-in-8-12/366639)

<div class="topic-metadata">

**Author:** [@MChambers](https://discuss.elastic.co/u/MChambers)\
**Replies:** 3\
**Last updated:** [September 20, 2024, 10:03am UTC](https://discuss.elastic.co/t/dynamic-template-create-error-in-8-14-java-works-in-8-12/366639 "2024-09-20T10:03:03Z")

</div>

When I try to create an index using a mapping that has a dynamic template that matches a type, I get this error: \[es/indices.create\] failed: \[mapper\_parsing\_exception\] Failed to parse mapping: No field type matched on \[…

---

## [5.6 License time testing/running out](https://discuss.elastic.co/t/5-6-license-time-testing-running-out/366677)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 10\
**Last updated:** [September 20, 2024, 9:49am UTC](https://discuss.elastic.co/t/5-6-license-time-testing-running-out/366677 "2024-09-20T09:49:43Z")

</div>

Hello, I want to test what happens when my license runs out on 5.6. We currently have a prospect whose license will run out soon so I thought a good way to simulate this was to locally set up an Elastic 5.6 environment…

---

## [Do I need to apply index/component templates retroactively to free up shards?](https://discuss.elastic.co/t/do-i-need-to-apply-index-component-templates-retroactively-to-free-up-shards/366863)

<div class="topic-metadata">

**Author:** [@Jac\_Pettersson](https://discuss.elastic.co/u/Jac_Pettersson)\
**Replies:** 0\
**Last updated:** [September 20, 2024, 8:37am UTC](https://discuss.elastic.co/t/do-i-need-to-apply-index-component-templates-retroactively-to-free-up-shards/366863 "2024-09-20T08:37:11Z")

</div>

Hello! I have an issue that we are running out of shards in our elastic cloud cluster. (lots of errors saying: "this action would add \[2\] shards, but this cluster currently has \[2000\]/\[2000\] maximum normal shards open…

---

## [Find source of request using invalid API Key](https://discuss.elastic.co/t/find-source-of-request-using-invalid-api-key/366757)

<div class="topic-metadata">

**Author:** [@Steve\_Foster](https://discuss.elastic.co/u/Steve_Foster)\
**Replies:** 1\
**Last updated:** [September 20, 2024, 6:58am UTC](https://discuss.elastic.co/t/find-source-of-request-using-invalid-api-key/366757 "2024-09-20T06:58:44Z")

</div>

Hi, I've seen these in the logs for a while now but I've been able to find a way to show where the request is coming from. Authentication using apikey failed - unable to find apikey with id \<ID\> Any suggestions?

---

## [How to Disable Default Index Creation in ELK and Kibana to Save Storage Space](https://discuss.elastic.co/t/how-to-disable-default-index-creation-in-elk-and-kibana-to-save-storage-space/366785)

<div class="topic-metadata">

**Author:** [@Krishnamohan\_M](https://discuss.elastic.co/u/Krishnamohan_M)\
**Replies:** 3\
**Last updated:** [September 20, 2024, 6:14am UTC](https://discuss.elastic.co/t/how-to-disable-default-index-creation-in-elk-and-kibana-to-save-storage-space/366785 "2024-09-20T06:14:19Z")

</div>

Hi ELK Community, I'm currently facing a significant storage issue due to the default indices created by ELK and Kibana. My environment has over 40 indices, These indices are consuming a considerable amount of storage …

---

## [How to create read-only user in elastic](https://discuss.elastic.co/t/how-to-create-read-only-user-in-elastic/366749)

<div class="topic-metadata">

**Author:** [@Samantha\_V](https://discuss.elastic.co/u/Samantha_V)\
**Replies:** 4\
**Last updated:** [September 20, 2024, 4:57am UTC](https://discuss.elastic.co/t/how-to-create-read-only-user-in-elastic/366749 "2024-09-20T04:57:57Z")

</div>

Hi Team, there is a requirment to create read-only user for elastic. I tried my best but could not achieve it. I want to start from scratch. Please give me some suggestion how to achieve this.

---

## [Rollover action during a reindex](https://discuss.elastic.co/t/rollover-action-during-a-reindex/366821)

<div class="topic-metadata">

**Author:** [@brandon.n](https://discuss.elastic.co/u/brandon.n)\
**Replies:** 4\
**Last updated:** [September 19, 2024, 8:39pm UTC](https://discuss.elastic.co/t/rollover-action-during-a-reindex/366821 "2024-09-19T20:39:54Z")

</div>

Hello, Currently working on reindexing an old index with a massive 170ishGB single primary shard into a new datastream index, with an ILM policy of 30GB/30D. We configured for 8 primary, 1 replica, but currently the ro…

---

## [API Interface for Elastic Search Index](https://discuss.elastic.co/t/api-interface-for-elastic-search-index/366817)

<div class="topic-metadata">

**Author:** [@raylowe](https://discuss.elastic.co/u/raylowe)\
**Replies:** 3\
**Last updated:** [September 19, 2024, 6:42pm UTC](https://discuss.elastic.co/t/api-interface-for-elastic-search-index/366817 "2024-09-19T18:42:07Z")

</div>

Hi, I am having some trouble with the API interface for the Elasticsearch web crawler. Background: I have a created an Elastic search index with a web crawler. I have also created an engine using the "Elasticsearch i…

---

## [Best practice for legacy address database searches](https://discuss.elastic.co/t/best-practice-for-legacy-address-database-searches/366804)

<div class="topic-metadata">

**Author:** [@Stubbs](https://discuss.elastic.co/u/Stubbs)\
**Replies:** 1\
**Last updated:** [September 19, 2024, 6:01pm UTC](https://discuss.elastic.co/t/best-practice-for-legacy-address-database-searches/366804 "2024-09-19T18:01:03Z")

</div>

We have a legacy database of addresses that contains data from multiple countries and is quite frankly, a mess! We have lots of duplicates, lots of entries where the same postcode is entered with and without spaces and o…

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - the truststore \[/etc/elasticsearch/certs/root.p12\] does not contain any trusted certificate entries](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-etc-elasticsearch-certs-root-p12-does-not-contain-any-trusted-certificate-entries/366584)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [September 19, 2024, 2:36pm UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-etc-elasticsearch-certs-root-p12-does-not-contain-any-trusted-certificate-entries/366584 "2024-09-19T14:36:02Z")

</div>

I am trying to create my own PKCS12 certificate files to use with elasticsearch, but when I do systemctl start elasticsearch, I get this error: 2024-09-15T01:24:22,581\]\[ERROR\]\[o.e.b.Elasticsearch \] \[node1\] fatal ex…

---

## [Extract multiline logs as single event](https://discuss.elastic.co/t/extract-multiline-logs-as-single-event/366545)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 3\
**Last updated:** [September 19, 2024, 12:41pm UTC](https://discuss.elastic.co/t/extract-multiline-logs-as-single-event/366545 "2024-09-19T12:41:44Z")

</div>

Hello I am trying to extract java logs , these logs are multiline but I want extract as single event Ingest pipeline: POST \_ingest/pipeline/\_simulate { "pipeline": { "description": "Pipeline to combine multiline lo…

---

## [Queries with nested fields and "having" clauses](https://discuss.elastic.co/t/queries-with-nested-fields-and-having-clauses/366643)

<div class="topic-metadata">

**Author:** [@Ludmilla1963](https://discuss.elastic.co/u/Ludmilla1963)\
**Replies:** 4\
**Last updated:** [September 19, 2024, 12:14pm UTC](https://discuss.elastic.co/t/queries-with-nested-fields-and-having-clauses/366643 "2024-09-19T12:14:51Z")

</div>

I have this index with a nested field: { "test-nested": { "mappings": { "properties": { "indicator": { "type": "nested", "properties": { "id": { "type": …

---

## [No ML nodes with sufficient capacity for trained model deployment](https://discuss.elastic.co/t/no-ml-nodes-with-sufficient-capacity-for-trained-model-deployment/357517)

<div class="topic-metadata">

**Author:** [@msola](https://discuss.elastic.co/u/msola)\
**Replies:** 9\
**Last updated:** [September 19, 2024, 9:18am UTC](https://discuss.elastic.co/t/no-ml-nodes-with-sufficient-capacity-for-trained-model-deployment/357517 "2024-09-19T09:18:23Z")

</div>

Hi, I'm new with elasticsearch. I currently have the trial period Platinum subscription, since I want to check if elasticsearch fits with what I want to do. I want to test the elster\_model\_2 ML model. However, every ti…

---

## [Elasticsearch LDAP - java.io.FilePermission error](https://discuss.elastic.co/t/elasticsearch-ldap-java-io-filepermission-error/366756)

<div class="topic-metadata">

**Author:** [@v1p3r0u5](https://discuss.elastic.co/u/v1p3r0u5)\
**Replies:** 2\
**Last updated:** [September 19, 2024, 5:58am UTC](https://discuss.elastic.co/t/elasticsearch-ldap-java-io-filepermission-error/366756 "2024-09-19T05:58:29Z")

</div>

Hello everybody :slight\_smile: I'm having a very strange problem while setting up LDAP for elasticsearch. First of all some information about my environment Elasticsearch version: \[root@elastic ~\]# /usr/share/elastic…

---

## [Default behavior of sorting in the transform](https://discuss.elastic.co/t/default-behavior-of-sorting-in-the-transform/366729)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 2\
**Last updated:** [September 18, 2024, 3:50pm UTC](https://discuss.elastic.co/t/default-behavior-of-sorting-in-the-transform/366729 "2024-09-18T15:50:43Z")

</div>

We are using transform and doing sorting based in extractDateTime. We want to know if we two logs available with the exact same extractDateTime value. Then based on which behavior it will show the log. Or is it random i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=75)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=77)
