# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=79

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 80

---

## [LDAP Configuration for Kibana Authentication](https://discuss.elastic.co/t/ldap-configuration-for-kibana-authentication/366305)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [September 10, 2024, 12:37pm UTC](https://discuss.elastic.co/t/ldap-configuration-for-kibana-authentication/366305 "2024-09-10T12:37:05Z")

</div>

Hello I have an Elastic cluster with two coordinator nodes, and I need to configure LDAP for Kibana authentication. Should the LDAP configuration and role\_mapping file be applied to just one coordinator node or to both? …

---

## [Sort over Aggregations buckets by text field over already sorted result](https://discuss.elastic.co/t/sort-over-aggregations-buckets-by-text-field-over-already-sorted-result/366297)

<div class="topic-metadata">

**Author:** [@ayanpoddar](https://discuss.elastic.co/u/ayanpoddar)\
**Replies:** 0\
**Last updated:** [September 10, 2024, 8:39am UTC](https://discuss.elastic.co/t/sort-over-aggregations-buckets-by-text-field-over-already-sorted-result/366297 "2024-09-10T08:39:30Z")

</div>

I am currently facing an issue with sorting aggregation results on a text field in Elasticsearch. this is my query { "size": 0, "query": { "bool": { "must": \[ { "query\_string": { …

---

## [PatternCaptureGroupTokenFilter throwing error - startOffset must be non-negative, and endOffset must be \>= startOffset, and offsets must not go backwards](https://discuss.elastic.co/t/patterncapturegrouptokenfilter-throwing-error-startoffset-must-be-non-negative-and-endoffset-must-be-startoffset-and-offsets-must-not-go-backwards/366199)

<div class="topic-metadata">

**Author:** [@shikha65786](https://discuss.elastic.co/u/shikha65786)\
**Replies:** 2\
**Last updated:** [September 10, 2024, 5:11am UTC](https://discuss.elastic.co/t/patterncapturegrouptokenfilter-throwing-error-startoffset-must-be-non-negative-and-endoffset-must-be-startoffset-and-offsets-must-not-go-backwards/366199 "2024-09-10T05:11:16Z")

</div>

I'm using the PatternCaptureGroupTokenFilter in my code to generate tokens based on multiple regular expressions and highlight matches in the string. I'm working with Lucene 9, but it's returning the following error. {"…

---

## [Java log Parsing with Filebeat and Logstash](https://discuss.elastic.co/t/java-log-parsing-with-filebeat-and-logstash/366280)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 2\
**Last updated:** [September 10, 2024, 4:17am UTC](https://discuss.elastic.co/t/java-log-parsing-with-filebeat-and-logstash/366280 "2024-09-10T04:17:46Z")

</div>

So I have a java log that I want to consume using filebeat. When I test in the local env I succeed, but when I try to use the production env the log is not successfully parsed. Because in the local env I use logstash but…

---

## [Elastic agent custom configuration to index in multiple indices](https://discuss.elastic.co/t/elastic-agent-custom-configuration-to-index-in-multiple-indices/366276)

<div class="topic-metadata">

**Author:** [@Abhi\_Abhishek](https://discuss.elastic.co/u/Abhi_Abhishek)\
**Replies:** 1\
**Last updated:** [September 10, 2024, 3:51am UTC](https://discuss.elastic.co/t/elastic-agent-custom-configuration-to-index-in-multiple-indices/366276 "2024-09-10T03:51:40Z")

</div>

Hi All, I am trying to index data into different indices in kubernetes integration, based on the container logs, output.elasticsearch: indices: - index: "test-analytics-%{+yyyy.MM}" when.contains: k…

---

## [Segregate Replicas](https://discuss.elastic.co/t/segregate-replicas/366260)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 5\
**Last updated:** [September 9, 2024, 5:50pm UTC](https://discuss.elastic.co/t/segregate-replicas/366260 "2024-09-09T17:50:27Z")

</div>

Is there a way we can segregate all replica shards on a separate node and all primary shard on a separate node?

---

## [ILM warm shrinked indicies vs delete phase](https://discuss.elastic.co/t/ilm-warm-shrinked-indicies-vs-delete-phase/366231)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 5\
**Last updated:** [September 9, 2024, 2:36pm UTC](https://discuss.elastic.co/t/ilm-warm-shrinked-indicies-vs-delete-phase/366231 "2024-09-09T14:36:17Z")

</div>

Running a v.8.15.0 cluster of 3x data nodes and got a 30 days ILM policy like this: { "30-days-default": { "version": 3, "modified\_date": "2023-03-17T23:13:14.838Z", "policy": { "phases": { "…

---

## [Get Task from index.default\_pipeline](https://discuss.elastic.co/t/get-task-from-index-default-pipeline/366037)

<div class="topic-metadata">

**Author:** [@Shell\_Dias](https://discuss.elastic.co/u/Shell_Dias)\
**Replies:** 3\
**Last updated:** [September 9, 2024, 1:53pm UTC](https://discuss.elastic.co/t/get-task-from-index-default-pipeline/366037 "2024-09-09T13:53:11Z")

</div>

I have a mapping that by default creates an index with the index.default\_pipeline configuration pointing to an ingest pipeline. PUT search-d { "settings": { "index.default\_pipeline": "e5-small-ingest-pipeline" …

---

## [Timeout happens to do Azure Authentication in Elastic Search 8.15.0 Custom Plugin](https://discuss.elastic.co/t/timeout-happens-to-do-azure-authentication-in-elastic-search-8-15-0-custom-plugin/366248)

<div class="topic-metadata">

**Author:** [@Super\_B](https://discuss.elastic.co/u/Super_B)\
**Replies:** 0\
**Last updated:** [September 9, 2024, 1:20pm UTC](https://discuss.elastic.co/t/timeout-happens-to-do-azure-authentication-in-elastic-search-8-15-0-custom-plugin/366248 "2024-09-09T13:20:12Z")

</div>

Hello, I'm trying to authenticate in a Elastic Search custom plugin using the Azure Java SDK, but I get a timeout at credential.getToken().block() If I use credential.getTokenSync(), it gets blocked on this function for…

---

## [Xpack.security.enabled=false](https://discuss.elastic.co/t/xpack-security-enabled-false/366233)

<div class="topic-metadata">

**Author:** [@Yo0kii](https://discuss.elastic.co/u/Yo0kii)\
**Replies:** 0\
**Last updated:** [September 9, 2024, 9:53am UTC](https://discuss.elastic.co/t/xpack-security-enabled-false/366233 "2024-09-09T09:53:13Z")

</div>

ECK-Operator When using ECK to deploy Elasticsearch, can you set it not to use username and password?

---

## [How does the syncAlerts settings work for case creation?](https://discuss.elastic.co/t/how-does-the-syncalerts-settings-work-for-case-creation/366224)

<div class="topic-metadata">

**Author:** [@Danyal\_Danish](https://discuss.elastic.co/u/Danyal_Danish)\
**Replies:** 0\
**Last updated:** [September 9, 2024, 7:23am UTC](https://discuss.elastic.co/t/how-does-the-syncalerts-settings-work-for-case-creation/366224 "2024-09-09T07:23:01Z")

</div>

Hi, I want to know how the syncAlerts settings affect the case creation process. I can't any details or information about on a Elasticsearch documentation pages.

---

## [Client request timeout for One Hour Data , while the same query when executed for 15 minutes or less give the data in some microseconds, What can be the root cause](https://discuss.elastic.co/t/client-request-timeout-for-one-hour-data-while-the-same-query-when-executed-for-15-minutes-or-less-give-the-data-in-some-microseconds-what-can-be-the-root-cause/366217)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 0\
**Last updated:** [September 9, 2024, 4:17am UTC](https://discuss.elastic.co/t/client-request-timeout-for-one-hour-data-while-the-same-query-when-executed-for-15-minutes-or-less-give-the-data-in-some-microseconds-what-can-be-the-root-cause/366217 "2024-09-09T04:17:34Z")

</div>

I am not finding any logs related to such an error on coordination or on any master node, The Elastic nodes have the high bandwidth within themselves, but some time I observe retries when testing the bandwidth , Can thi…

---

## [PatternCaptureGroupTokenFilter is creating the same offset positions, which is causing highlighting issue](https://discuss.elastic.co/t/patterncapturegrouptokenfilter-is-creating-the-same-offset-positions-which-is-causing-highlighting-issue/366200)

<div class="topic-metadata">

**Author:** [@shikha65786](https://discuss.elastic.co/u/shikha65786)\
**Replies:** 0\
**Last updated:** [September 8, 2024, 10:38am UTC](https://discuss.elastic.co/t/patterncapturegrouptokenfilter-is-creating-the-same-offset-positions-which-is-causing-highlighting-issue/366200 "2024-09-08T10:38:19Z")

</div>

I am implementing the PatternCaptureGroupTokenFilter in my code to generate tokens based on multiple regular expressions, with the goal of highlighting any matches found within the string. Currently, I am working with Lu…

---

## [Under which conditions could a completion suggestion deplete thread pool and heap memory?](https://discuss.elastic.co/t/under-which-conditions-could-a-completion-suggestion-deplete-thread-pool-and-heap-memory/366197)

<div class="topic-metadata">

**Author:** [@captain-nemo](https://discuss.elastic.co/u/captain-nemo)\
**Replies:** 0\
**Last updated:** [September 8, 2024, 7:15am UTC](https://discuss.elastic.co/t/under-which-conditions-could-a-completion-suggestion-deplete-thread-pool-and-heap-memory/366197 "2024-09-08T07:15:50Z")

</div>

Situation: Elasticsearch cluster crashed (thread pool and soon after heap memory depleted). When investigating the heap dump it showed that the suggester was processing unusual queries like this: +"\\uffab-\\uffaa/(+-\\uf…

---

## [Heterogeneous Cluster](https://discuss.elastic.co/t/heterogeneous-cluster/366184)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 10\
**Last updated:** [September 8, 2024, 5:57am UTC](https://discuss.elastic.co/t/heterogeneous-cluster/366184 "2024-09-08T05:57:03Z")

</div>

Do elasticsearch support Heterogeneous Cluster? Like if I have 1 master node at 7.17.6 , 2 data nodes at 7.17.6 & 1 data node at 8.11.1 will that work? This is to confirm that whether we can rolling upgrade ES without …

---

## [Percolate query - get reason why document was not matched](https://discuss.elastic.co/t/percolate-query-get-reason-why-document-was-not-matched/366186)

<div class="topic-metadata">

**Author:** [@alesmenzel](https://discuss.elastic.co/u/alesmenzel)\
**Replies:** 0\
**Last updated:** [September 7, 2024, 9:23am UTC](https://discuss.elastic.co/t/percolate-query-get-reason-why-document-was-not-matched/366186 "2024-09-07T09:23:30Z")

</div>

Hi, I have read through the documentation Percolate query | Elasticsearch Guide \[8.15\] | Elastic but could not find a way to get the reason why a percolate query would not match given documents, is it somehow possible t…

---

## [ElasticPress Authentication for remote server](https://discuss.elastic.co/t/elasticpress-authentication-for-remote-server/364723)

<div class="topic-metadata">

**Author:** [@aiusdyasiudy](https://discuss.elastic.co/u/aiusdyasiudy)\
**Replies:** 4\
**Last updated:** [September 6, 2024, 8:32pm UTC](https://discuss.elastic.co/t/elasticpress-authentication-for-remote-server/364723 "2024-09-06T20:32:43Z")

</div>

I am setting up a demo Elasticsearch server to take it for a spin on my Wordpress sites using ElasticPress plugin. I have Elasticsearch setup properly, and Kibana as well in Debian on an OVH virtual machine to test. Th…

---

## [Postgresql connector skipping query](https://discuss.elastic.co/t/postgresql-connector-skipping-query/366058)

<div class="topic-metadata">

**Author:** [@mrtl](https://discuss.elastic.co/u/mrtl)\
**Replies:** 7\
**Last updated:** [September 6, 2024, 6:38pm UTC](https://discuss.elastic.co/t/postgresql-connector-skipping-query/366058 "2024-09-06T18:38:19Z")

</div>

Hi, my connector is correcly connected to elasticsearch but in the log ther e is this line : Skipping query select \[...\] as primary key column name is not present in query. I don't understand if it's related to elast…

---

## [\_source field exclusion seems to fail indexing field as well](https://discuss.elastic.co/t/source-field-exclusion-seems-to-fail-indexing-field-as-well/366113)

<div class="topic-metadata">

**Author:** [@RubiHali](https://discuss.elastic.co/u/RubiHali)\
**Replies:** 5\
**Last updated:** [September 6, 2024, 11:30am UTC](https://discuss.elastic.co/t/source-field-exclusion-seems-to-fail-indexing-field-as-well/366113 "2024-09-06T11:30:37Z")

</div>

I have some data which we want to only index for filtering but not store in \_source field. We have used \_source exclusion for those fields. We have a scenario where in certain cases, the document doesn't contain that fi…

---

## [GET /\_cat/indices not showing all indices after upgrade to 7.3](https://discuss.elastic.co/t/get-cat-indices-not-showing-all-indices-after-upgrade-to-7-3/366123)

<div class="topic-metadata">

**Author:** [@elastic\_noob1](https://discuss.elastic.co/u/elastic_noob1)\
**Replies:** 1\
**Last updated:** [September 6, 2024, 2:06am UTC](https://discuss.elastic.co/t/get-cat-indices-not-showing-all-indices-after-upgrade-to-7-3/366123 "2024-09-06T02:06:21Z")

</div>

I upgraded our cluster from 6.8 to 7.3.2 and I can only view all indices if I authenticate to the cluster. This was not the case on 6.8: I get only system indices without authentication: ➜ curl -s -XGET https://timel…

---

## [Ingest Pipeline - Date Processor - Parsing Failure](https://discuss.elastic.co/t/ingest-pipeline-date-processor-parsing-failure/366122)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [September 5, 2024, 9:50pm UTC](https://discuss.elastic.co/t/ingest-pipeline-date-processor-parsing-failure/366122 "2024-09-05T21:50:14Z")

</div>

Hello, I don't know why I am getting this error: This is the format I specified: YYYY/MM/DD HH:MM:SS.SSS This is the field value: 2024/09/04 23:38:49.930 Is this not right?

---

## [Elastic Stack 8.15.0 on Red Hat Enterprise Linux 8.10](https://discuss.elastic.co/t/elastic-stack-8-15-0-on-red-hat-enterprise-linux-8-10/366062)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 2\
**Last updated:** [September 5, 2024, 6:25pm UTC](https://discuss.elastic.co/t/elastic-stack-8-15-0-on-red-hat-enterprise-linux-8-10/366062 "2024-09-05T18:25:16Z")

</div>

Hi, I am currently running Elastic Stack 8.15.0 on an older hardware server with approximately 150GB of Elasticsearch data on a Red Hat Enterprise Linux 8.10 operating system. We have a brand-new hardware server which …

---

## [Issue with Loading Data from Elasticsearch into Databricks](https://discuss.elastic.co/t/issue-with-loading-data-from-elasticsearch-into-databricks/366087)

<div class="topic-metadata">

**Author:** [@Hernando\_Segovia](https://discuss.elastic.co/u/Hernando_Segovia)\
**Replies:** 2\
**Last updated:** [September 5, 2024, 2:41pm UTC](https://discuss.elastic.co/t/issue-with-loading-data-from-elasticsearch-into-databricks/366087 "2024-09-05T14:41:50Z")

</div>

Hello, I'm encountering an issue while trying to load data from Elasticsearch into Databricks. Below is the code I'm using and the error message I'm receiving. Code: es\_read\_conf = { "es.nodes": "your-cluster-url"…

---

## [.NET Elastic.Clients.Elasticsearch (version \>= 8.13.12) - SearchAsync](https://discuss.elastic.co/t/net-elastic-clients-elasticsearch-version-8-13-12-searchasync/366097)

<div class="topic-metadata">

**Author:** [@Premysl\_Capek](https://discuss.elastic.co/u/Premysl_Capek)\
**Replies:** 1\
**Last updated:** [September 5, 2024, 1:58pm UTC](https://discuss.elastic.co/t/net-elastic-clients-elasticsearch-version-8-13-12-searchasync/366097 "2024-09-05T13:58:00Z")

</div>

Hi, I have problem with ES client version \>= 8.13.12. In past I use this code to get the latest document from an index but in new version I get a document from a different index. What is correct query for new clients? v…

---

## [My groke pattern on elastic pipleline creation changes](https://discuss.elastic.co/t/my-groke-pattern-on-elastic-pipleline-creation-changes/365984)

<div class="topic-metadata">

**Author:** [@ermisma](https://discuss.elastic.co/u/ermisma)\
**Replies:** 2\
**Last updated:** [September 5, 2024, 1:56pm UTC](https://discuss.elastic.co/t/my-groke-pattern-on-elastic-pipleline-creation-changes/365984 "2024-09-05T13:56:24Z")

</div>

I am trying to create a Ingest pipeline with the below grok pattern (v 8.15.0): ".\*\\"msg\\"\\: \\"(?\<resmsg\>\[^\\"\]+)\\"\\,.\*" sample source data as below: \[0;31mfatal: \[localhost\]: FAILED! =\> {"changed": false, "elapsed": …

---

## [Index design for product with multi image and similarity search](https://discuss.elastic.co/t/index-design-for-product-with-multi-image-and-similarity-search/365976)

<div class="topic-metadata">

**Author:** [@rastin\_rastini](https://discuss.elastic.co/u/rastin_rastini)\
**Replies:** 2\
**Last updated:** [September 5, 2024, 11:49am UTC](https://discuss.elastic.co/t/index-design-for-product-with-multi-image-and-similarity-search/365976 "2024-09-05T11:49:06Z")

</div>

Hi im scrapping product pages where each product has a description and multi image. generate vector for each image. finally i want search similar images with a given image and return products similar with that image. w…

---

## [Why is the default value of \`xpack.security.http.ssl.enabled\` in ElasticSearch's Docker Image set to \`true\`?](https://discuss.elastic.co/t/why-is-the-default-value-of-xpack-security-http-ssl-enabled-in-elasticsearchs-docker-image-set-to-true/366089)

<div class="topic-metadata">

**Author:** [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Replies:** 1\
**Last updated:** [September 5, 2024, 11:26am UTC](https://discuss.elastic.co/t/why-is-the-default-value-of-xpack-security-http-ssl-enabled-in-elasticsearchs-docker-image-set-to-true/366089 "2024-09-05T11:26:21Z")

</div>

Security settings in Elasticsearch | Elasticsearch Guide \[8.15\] | Elastic mentions that the default value of xpack.security.http.ssl.enabled is false. (Static) Used to enable or disable TLS/SSL on the HTTP networking …

---

## [Elasticsearch.Net 7.17.X unable to connect Elasticsearch 8.13.4 version](https://discuss.elastic.co/t/elasticsearch-net-7-17-x-unable-to-connect-elasticsearch-8-13-4-version/364184)

<div class="topic-metadata">

**Author:** [@sathish12](https://discuss.elastic.co/u/sathish12)\
**Replies:** 6\
**Last updated:** [September 5, 2024, 7:59am UTC](https://discuss.elastic.co/t/elasticsearch-net-7-17-x-unable-to-connect-elasticsearch-8-13-4-version/364184 "2024-09-05T07:59:23Z")

</div>

I have upgraded from elasticsearch 2.3.2 to 8.13.4. I have created a multi node cluster and I am trying to connect to elasticsearch through my .NET. I have heard that elastic.client.elasticsearch library is not providing…

---

## [After upgrading from 7.x to 8.x, Elasticsearch cannot start](https://discuss.elastic.co/t/after-upgrading-from-7-x-to-8-x-elasticsearch-cannot-start/365842)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 5\
**Last updated:** [September 4, 2024, 8:27pm UTC](https://discuss.elastic.co/t/after-upgrading-from-7-x-to-8-x-elasticsearch-cannot-start/365842 "2024-09-04T20:27:41Z")

</div>

These are the errors in the logs: Aug 29 13:45:34 ELK-Stack.uhtasi.local systemd-entrypoint\[13266\]: Error occurred during initialization of boot layer Aug 29 13:45:34 ELK-Stack.uhtasi.local systemd-entrypoint\[13266\]: j…

---

## [ES8.14 has 5 nodes. But master is down and reinstalled. How to join the new cluster?](https://discuss.elastic.co/t/es8-14-has-5-nodes-but-master-is-down-and-reinstalled-how-to-join-the-new-cluster/366025)

<div class="topic-metadata">

**Author:** [@hoover\_he](https://discuss.elastic.co/u/hoover_he)\
**Replies:** 1\
**Last updated:** [September 4, 2024, 11:48pm UTC](https://discuss.elastic.co/t/es8-14-has-5-nodes-but-master-is-down-and-reinstalled-how-to-join-the-new-cluster/366025 "2024-09-04T23:48:03Z")

</div>

ES8.14 has 5 nodes. But master was down and reinstalled. How to join the new cluster? ES8.14 has 5 nodes. But master\[node-04\] was down and reinstalled. The current es cluster is running well with new master\[node-05\]. I…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=78)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=80)
