# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=78

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 79

---

## [Logstash getting stopped with error asNo space left on device - /usr/share/logstash/data/plugins/inputs/google\_cloud\_storage/d](https://discuss.elastic.co/t/logstash-getting-stopped-with-error-asno-space-left-on-device-usr-share-logstash-data-plugins-inputs-google-cloud-storage-d/366453)

<div class="topic-metadata">

**Author:** [@Deepa\_Karthika](https://discuss.elastic.co/u/Deepa_Karthika)\
**Replies:** 3\
**Last updated:** [September 13, 2024, 12:46pm UTC](https://discuss.elastic.co/t/logstash-getting-stopped-with-error-asno-space-left-on-device-usr-share-logstash-data-plugins-inputs-google-cloud-storage-d/366453 "2024-09-13T12:46:36Z")

</div>

Hi My elasticsearch taking input from google\_cloud\_storage and indexing to Elasticsearch index stops consistently with below error \[2024-09-12T07:09:16,306\]\[ERROR\]\[logstash.javapipeline \] A plugin had an unrecover…

---

## [Elasticsearch behind load balancing proxy](https://discuss.elastic.co/t/elasticsearch-behind-load-balancing-proxy/366528)

<div class="topic-metadata">

**Author:** [@VolvoxGlobator](https://discuss.elastic.co/u/VolvoxGlobator)\
**Replies:** 0\
**Last updated:** [September 13, 2024, 11:25am UTC](https://discuss.elastic.co/t/elasticsearch-behind-load-balancing-proxy/366528 "2024-09-13T11:25:19Z")

</div>

Hello, we have on have a little bit more abstraction between cluster setup and our python code and plan on hiding the cluster behind load balancing proxy (nginx), thus just single endpoint from client point of view. I ha…

---

## [Reindex API does not complete the re-indexing](https://discuss.elastic.co/t/reindex-api-does-not-complete-the-re-indexing/366389)

<div class="topic-metadata">

**Author:** [@abhadauria](https://discuss.elastic.co/u/abhadauria)\
**Replies:** 4\
**Last updated:** [September 13, 2024, 11:19am UTC](https://discuss.elastic.co/t/reindex-api-does-not-complete-the-re-indexing/366389 "2024-09-13T11:19:52Z")

</div>

using ES version 7.17, after triggering the re-index API from query node, it stops re-indexing after some time and does not complete the re-indexing of all the docs in the source index, eg, we have ~110 million docs in t…

---

## [Elastic.Clients.Elasticsearch Version="8.15.6": maxScore is always null](https://discuss.elastic.co/t/elastic-clients-elasticsearch-version-8-15-6-maxscore-is-always-null/366152)

<div class="topic-metadata">

**Author:** [@PitAttack](https://discuss.elastic.co/u/PitAttack)\
**Replies:** 1\
**Last updated:** [September 13, 2024, 9:24am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-version-8-15-6-maxscore-is-always-null/366152 "2024-09-13T09:24:24Z")

</div>

I have this query, created in C#. { "min\_score": 20, "query": { "bool": { "filter": { "term": { "glnType": { "value": "Company" } } }, "must": { …

---

## [Ingest Pipeline: Compare two arrays with Painless Script](https://discuss.elastic.co/t/ingest-pipeline-compare-two-arrays-with-painless-script/366510)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 0\
**Last updated:** [September 13, 2024, 7:01am UTC](https://discuss.elastic.co/t/ingest-pipeline-compare-two-arrays-with-painless-script/366510 "2024-09-13T07:01:11Z")

</div>

Hi everyone, I'm working on an ingest pipeline in Elasticsearch where I have two array fields (alfa and beta), both populated by two different enrich processors earlier in the same pipeline. I would like to add a script…

---

## [Logstash crashes when trying to install cloudwatch\_logs plugin](https://discuss.elastic.co/t/logstash-crashes-when-trying-to-install-cloudwatch-logs-plugin/366499)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 5\
**Last updated:** [September 13, 2024, 5:44am UTC](https://discuss.elastic.co/t/logstash-crashes-when-trying-to-install-cloudwatch-logs-plugin/366499 "2024-09-13T05:44:05Z")

</div>

Logstash version: 8.15.1 OS: Amazon Linux 2 All packages updated Steps to reproduce: rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch in /etc/yum.repos.d/logstash.repo \[logstash-8.x\] name=Elastic rep…

---

## [Default password expiry in Elastic 8.14](https://discuss.elastic.co/t/default-password-expiry-in-elastic-8-14/366467)

<div class="topic-metadata">

**Author:** [@h.d.intodata](https://discuss.elastic.co/u/h.d.intodata)\
**Replies:** 2\
**Last updated:** [September 12, 2024, 1:01pm UTC](https://discuss.elastic.co/t/default-password-expiry-in-elastic-8-14/366467 "2024-09-12T13:01:03Z")

</div>

Hi team, I have a quick question, what is the default password expiry for the super user in Elastic 8.14 Kind regards, Hugo

---

## [Beats 7.17.10 with Elastic Stack 8.15](https://discuss.elastic.co/t/beats-7-17-10-with-elastic-stack-8-15/366476)

<div class="topic-metadata">

**Author:** [@anastasia](https://discuss.elastic.co/u/anastasia)\
**Replies:** 0\
**Last updated:** [September 12, 2024, 12:52pm UTC](https://discuss.elastic.co/t/beats-7-17-10-with-elastic-stack-8-15/366476 "2024-09-12T12:52:14Z")

</div>

Good day to all! I ran into a problem. At work, one of the computers has the Windows 7 operating system installed, due to specific software that is not supported in new versions of Windows. Auditbeat and winlogbeat versi…

---

## [Error getting while adding second repository for snapshot](https://discuss.elastic.co/t/error-getting-while-adding-second-repository-for-snapshot/366450)

<div class="topic-metadata">

**Author:** [@Nikhil\_Borse](https://discuss.elastic.co/u/Nikhil_Borse)\
**Replies:** 0\
**Last updated:** [September 12, 2024, 7:14am UTC](https://discuss.elastic.co/t/error-getting-while-adding-second-repository-for-snapshot/366450 "2024-09-12T07:14:54Z")

</div>

Hi, I am trying to add 2 snapshot repositories as s3. Both the buckets are oci buckets. When I added first Bucket it is working fine as expected but when I am trying to add another bucket with different access key and se…

---

## [Elasticsearch search query returning "empty" response using elasticsearch python API](https://discuss.elastic.co/t/elasticsearch-search-query-returning-empty-response-using-elasticsearch-python-api/365983)

<div class="topic-metadata">

**Author:** [@manropinxu](https://discuss.elastic.co/u/manropinxu)\
**Replies:** 9\
**Last updated:** [September 12, 2024, 7:17am UTC](https://discuss.elastic.co/t/elasticsearch-search-query-returning-empty-response-using-elasticsearch-python-api/365983 "2024-09-12T07:17:40Z")

</div>

I am using elasticsearch py client in my real time application. The application performs search query aggregations like "sum of field settledAmount in last 10 days". Most of queries work without problems. However a tin…

---

## [Can we use ILM on the index created by using transform](https://discuss.elastic.co/t/can-we-use-ilm-on-the-index-created-by-using-transform/366445)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [September 12, 2024, 6:15am UTC](https://discuss.elastic.co/t/can-we-use-ilm-on-the-index-created-by-using-transform/366445 "2024-09-12T06:15:42Z")

</div>

Hi Team, we are using 180 days retention for all the data in our Elastic cluster. Now we have some transforms where we are using the transforms retention\_policy to keep the data for 180 days. Now we wanted to remove the…

---

## [Updating the datastream from logstash](https://discuss.elastic.co/t/updating-the-datastream-from-logstash/366446)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [September 12, 2024, 6:13am UTC](https://discuss.elastic.co/t/updating-the-datastream-from-logstash/366446 "2024-09-12T06:13:35Z")

</div>

Hi Team, we are trying to lookup the data in one datastream with anothe data in another datastream based on a key using logstash elasticseach input plugin and elasticsearch filter as shown in the sample config below. M…

---

## [Best strategy to "JOIN" data from diferent .json files (Data enrichment? Rollup? Transform? Dictionary?)](https://discuss.elastic.co/t/best-strategy-to-join-data-from-diferent-json-files-data-enrichment-rollup-transform-dictionary/366434)

<div class="topic-metadata">

**Author:** [@syunusic](https://discuss.elastic.co/u/syunusic)\
**Replies:** 4\
**Last updated:** [September 11, 2024, 10:05pm UTC](https://discuss.elastic.co/t/best-strategy-to-join-data-from-diferent-json-files-data-enrichment-rollup-transform-dictionary/366434 "2024-09-11T22:05:32Z")

</div>

Let's say I have three .json files containing this information: employees.json: { "employee\_id":1, "name":"John" }, { "employee\_id":2, "name":"Elton" } companies.json: { "company\_id":1001, "company\_name":"ACME" }, { …

---

## [Running Separate Instance under one elasticsearch](https://discuss.elastic.co/t/running-separate-instance-under-one-elasticsearch/366337)

<div class="topic-metadata">

**Author:** [@Raj\_Badhiwala](https://discuss.elastic.co/u/Raj_Badhiwala)\
**Replies:** 1\
**Last updated:** [September 11, 2024, 9:19pm UTC](https://discuss.elastic.co/t/running-separate-instance-under-one-elasticsearch/366337 "2024-09-11T21:19:49Z")

</div>

I have create ELK stack VM for my students and everything is working file except one thing. I sent logs from my VM through logstash in elasticsearch for analysis, created index in it. But if another student will do the s…

---

## [How to resolve "Http client did not trust this server’s certificate"](https://discuss.elastic.co/t/how-to-resolve-http-client-did-not-trust-this-server-s-certificate/365790)

<div class="topic-metadata">

**Author:** [@darius12](https://discuss.elastic.co/u/darius12)\
**Replies:** 8\
**Last updated:** [September 11, 2024, 4:13pm UTC](https://discuss.elastic.co/t/how-to-resolve-http-client-did-not-trust-this-server-s-certificate/365790 "2024-09-11T16:13:11Z")

</div>

i get this error, despite following documentation for configuring elasticsearch on windows for HTTPS. I did the following steps: STEP 1. Run CMD.EXE as ADMIN, Navigate to Elastic /BIN folder elasticsearch-certutil ca …

---

## [Elasticsearch 'xpack.security.transport.ssl' related error after upgrade to 8.x](https://discuss.elastic.co/t/elasticsearch-xpack-security-transport-ssl-related-error-after-upgrade-to-8-x/366387)

<div class="topic-metadata">

**Author:** [@kotsobot](https://discuss.elastic.co/u/kotsobot)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 7:50am UTC](https://discuss.elastic.co/t/elasticsearch-xpack-security-transport-ssl-related-error-after-upgrade-to-8-x/366387 "2024-09-11T07:50:26Z")

</div>

Hi all, after upgrading elasticsearch (deployed in k8s) from 7.17.3 to 8.5, elasticsearch cannot start due to error: \[2024-09-11T07:22:27,949\]\[ERROR\]\[o.e.b.Elasticsearch \] \[a-elasticsearch-master-0\] fatal exception…

---

## [Delete csv reports from Elasticsearch 8.15](https://discuss.elastic.co/t/delete-csv-reports-from-elasticsearch-8-15/366411)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 1:28pm UTC](https://discuss.elastic.co/t/delete-csv-reports-from-elasticsearch-8-15/366411 "2024-09-11T13:28:45Z")

</div>

Hi team, I usually delete .reporting-yyyy-mm-dd indices from curl command. After I upgrade ELK to 8.15 version, I cannot find this index. Do you have any other alternative method? Thanks

---

## [JWT Authentication](https://discuss.elastic.co/t/jwt-authentication/366409)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 12:29pm UTC](https://discuss.elastic.co/t/jwt-authentication/366409 "2024-09-11T12:29:52Z")

</div>

I really want to setup JWT authentication for my Elastic Cloud instance so that one of my applications, which gets a jwt token assigned, can use that token to log data to Elastic. And I used the example from the documen…

---

## [Occasional spike in data indexing of Elasticsearch](https://discuss.elastic.co/t/occasional-spike-in-data-indexing-of-elasticsearch/366288)

<div class="topic-metadata">

**Author:** [@Priyansh\_Maheshwari](https://discuss.elastic.co/u/Priyansh_Maheshwari)\
**Replies:** 11\
**Last updated:** [September 11, 2024, 11:11am UTC](https://discuss.elastic.co/t/occasional-spike-in-data-indexing-of-elasticsearch/366288 "2024-09-11T11:11:35Z")

</div>

Hi, we are currently working with a single node ES instance, to which we connect with our application using ESJavaClient. Recently we re-indexed all our indexes after enabling search on a time based field. Post migration…

---

## [Sizing and identification of the ressources](https://discuss.elastic.co/t/sizing-and-identification-of-the-ressources/366399)

<div class="topic-metadata">

**Author:** [@akabigsmokee](https://discuss.elastic.co/u/akabigsmokee)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 9:30am UTC](https://discuss.elastic.co/t/sizing-and-identification-of-the-ressources/366399 "2024-09-11T09:30:11Z")

</div>

Hello community, I hope you are doing well, I'm trying to make the sizing and identify the resources to make a POC for a customer and wondering how many vm box i need and how can i identify the ressources for each box …

---

## [Cancel block write, throw exception: unknown setting \[archived.index.merge.policy.auto\_merge\_enabled\]](https://discuss.elastic.co/t/cancel-block-write-throw-exception-unknown-setting-archived-index-merge-policy-auto-merge-enabled/366377)

<div class="topic-metadata">

**Author:** [@jimmy0](https://discuss.elastic.co/u/jimmy0)\
**Replies:** 0\
**Last updated:** [September 11, 2024, 7:04am UTC](https://discuss.elastic.co/t/cancel-block-write-throw-exception-unknown-setting-archived-index-merge-policy-auto-merge-enabled/366377 "2024-09-11T07:04:51Z")

</div>

I'm to clone a index, follow the steps: block write. PUT /question\_answer\_v2/\_block/write clone. POST /question\_answer\_v2/\_clone/question\_answer\_v2\_20240823 cancel block write. PUT /question\_answer\_v2/\_settings …

---

## [How to paging with elasticsearch sql](https://discuss.elastic.co/t/how-to-paging-with-elasticsearch-sql/364433)

<div class="topic-metadata">

**Author:** [@jimmy0](https://discuss.elastic.co/u/jimmy0)\
**Replies:** 2\
**Last updated:** [September 11, 2024, 6:55am UTC](https://discuss.elastic.co/t/how-to-paging-with-elasticsearch-sql/364433 "2024-09-11T06:55:39Z")

</div>

The document offers "limit", but without "offset". I'm using elasticsearch 7.10.1.

---

## [Reindex Approach with zero downtime but with minimum delay](https://discuss.elastic.co/t/reindex-approach-with-zero-downtime-but-with-minimum-delay/366005)

<div class="topic-metadata">

**Author:** [@shanay\_20](https://discuss.elastic.co/u/shanay_20)\
**Replies:** 3\
**Last updated:** [September 11, 2024, 5:38am UTC](https://discuss.elastic.co/t/reindex-approach-with-zero-downtime-but-with-minimum-delay/366005 "2024-09-11T05:38:49Z")

</div>

Hi Team, I want to reindex the multiple indexes that have a lot of data in them. To reduce CPU usage, I am using the Reindex API POST \_reindex with the parameter request\_per\_second. But during the reindexing, if some ne…

---

## [Response time spike at fixed interval of every ~10 minutes](https://discuss.elastic.co/t/response-time-spike-at-fixed-interval-of-every-10-minutes/366300)

<div class="topic-metadata">

**Author:** [@sibasish.palo](https://discuss.elastic.co/u/sibasish.palo)\
**Replies:** 5\
**Last updated:** [September 11, 2024, 5:16am UTC](https://discuss.elastic.co/t/response-time-spike-at-fixed-interval-of-every-10-minutes/366300 "2024-09-11T05:16:09Z")

</div>

we are seeing one weird issue where the response time spike around every 10 minutes and same time the GC is getting triggered. any help or information i can share would very helpful. we are using version 8.12 Please l…

---

## [Block Mapping Updates](https://discuss.elastic.co/t/block-mapping-updates/366330)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 3\
**Last updated:** [September 11, 2024, 5:02am UTC](https://discuss.elastic.co/t/block-mapping-updates/366330 "2024-09-11T05:02:36Z")

</div>

Do Elasticsearch gives an option to block mapping updates for a while and re enable them afterwards. Usecase: While doing rolling upgrade, due to incoming writes I am getting mapping updates not allowed exception. So i…

---

## [How to perform filter with condition?](https://discuss.elastic.co/t/how-to-perform-filter-with-condition/366295)

<div class="topic-metadata">

**Author:** [@\_Zhang](https://discuss.elastic.co/u/_Zhang)\
**Replies:** 2\
**Last updated:** [September 11, 2024, 2:13am UTC](https://discuss.elastic.co/t/how-to-perform-filter-with-condition/366295 "2024-09-11T02:13:29Z")

</div>

In SQL: select \* from my\_index where type in ('a', 'b') and (type \<\> 'a' or value\_field = 'sth') Filter by field value\_field when type is 'a'. Using script: { "query": { "bool": { "filter": \[ …

---

## [Mapping track path on local disk under docker](https://discuss.elastic.co/t/mapping-track-path-on-local-disk-under-docker/366349)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 4\
**Last updated:** [September 10, 2024, 6:51pm UTC](https://discuss.elastic.co/t/mapping-track-path-on-local-disk-under-docker/366349 "2024-09-10T18:51:32Z")

</div>

Hi I'm strangling how to change repo for track to local track. I'm trying to load rally benchmark on simply test "--track-path=/rally/.rally/nyc\_taxis" so I've mapped volume with above patch and changed path in track.j…

---

## [Elasticsearch 7.17.6 can't be started as root](https://discuss.elastic.co/t/elasticsearch-7-17-6-cant-be-started-as-root/366274)

<div class="topic-metadata">

**Author:** [@ch101495](https://discuss.elastic.co/u/ch101495)\
**Replies:** 5\
**Last updated:** [September 10, 2024, 5:33pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-6-cant-be-started-as-root/366274 "2024-09-10T17:33:58Z")

</div>

Hello, I'm using RHEL 7.6 Maipo and I'm trying to start the elasticsearch service in a single node instance as root, but I'm receiving this error after i try to start the service using ./elasticsearch -d Error meesage: …

---

## [Multi Tenancy Single Sign on with Microsoft Entra](https://discuss.elastic.co/t/multi-tenancy-single-sign-on-with-microsoft-entra/366345)

<div class="topic-metadata">

**Author:** [@adamwood](https://discuss.elastic.co/u/adamwood)\
**Replies:** 0\
**Last updated:** [September 10, 2024, 4:48pm UTC](https://discuss.elastic.co/t/multi-tenancy-single-sign-on-with-microsoft-entra/366345 "2024-09-10T16:48:41Z")

</div>

HI Folks, we are using Elastic Cloud, and would like to set up Single Sign on using Microsoft Entra, with the addition of using multiple (any) Microsoft Azure Tenants. I would like to achieve this without needing to regi…

---

## [Error when transfer text field to numeric](https://discuss.elastic.co/t/error-when-transfer-text-field-to-numeric/366338)

<div class="topic-metadata">

**Author:** [@wtxdlut2021](https://discuss.elastic.co/u/wtxdlut2021)\
**Replies:** 0\
**Last updated:** [September 10, 2024, 3:48pm UTC](https://discuss.elastic.co/t/error-when-transfer-text-field-to-numeric/366338 "2024-09-10T15:48:27Z")

</div>

I have an index from an older version of Elasticsearch, in which one of the fields is of the 'text' type and does not have the 'keyword' attribute, but it actually contains numerical values. I would like to treat it as a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=77)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=79)
