# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=8

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 9

---

## [Fastest way to retrieve all unique terms in batches](https://discuss.elastic.co/t/fastest-way-to-retrieve-all-unique-terms-in-batches/385057)

<div class="topic-metadata">

**Author:** [@srishtii](https://discuss.elastic.co/u/srishtii)\
**Replies:** 1\
**Last updated:** [February 15, 2026, 9:47pm UTC](https://discuss.elastic.co/t/fastest-way-to-retrieve-all-unique-terms-in-batches/385057 "2026-02-15T21:47:17Z")

</div>

I’m looking for the fastest and safest way to retrieve all unique values of a field for a given time range, in batches. My requirements are: :white\_check\_mark: Retrieve 100% of unique terms (no missing buckets) …

---

## [How to use sniffer capability in elasticsearch-java client tool?](https://discuss.elastic.co/t/how-to-use-sniffer-capability-in-elasticsearch-java-client-tool/385038)

<div class="topic-metadata">

**Author:** [@mloine](https://discuss.elastic.co/u/mloine)\
**Replies:** 3\
**Last updated:** [February 15, 2026, 3:05pm UTC](https://discuss.elastic.co/t/how-to-use-sniffer-capability-in-elasticsearch-java-client-tool/385038 "2026-02-15T15:05:13Z")

</div>

How to use sniffer capability in elasticsearch-java client tool? According to the documentation, it is not supported by default, and the dependencies are \<dependency\> \<groupId\>co.elastic.clients\</groupId\> \<artif…

---

## [APT will consider Elastic repositories invalid soon](https://discuss.elastic.co/t/apt-will-consider-elastic-repositories-invalid-soon/384448)

<div class="topic-metadata">

**Author:** [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Replies:** 4\
**Last updated:** [February 12, 2026, 8:57am UTC](https://discuss.elastic.co/t/apt-will-consider-elastic-repositories-invalid-soon/384448 "2026-02-12T08:57:44Z")

</div>

Hi, On Debian 13+, apt will soon consider Elastic repository invalid Warning: https://artifacts.elastic.co/packages/8.x/apt/dists/stable/InRelease: Policy will reject signature within a year, see --audit for details …

---

## [Elasticsearch Indexing, Relevance Tuning, and Performance Issues in a Dynamic Restaurant Menu Website](https://discuss.elastic.co/t/elasticsearch-indexing-relevance-tuning-and-performance-issues-in-a-dynamic-restaurant-menu-website/385012)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 1\
**Last updated:** [February 12, 2026, 6:37am UTC](https://discuss.elastic.co/t/elasticsearch-indexing-relevance-tuning-and-performance-issues-in-a-dynamic-restaurant-menu-website/385012 "2026-02-12T06:37:25Z")

</div>

I am managing a restaurant menu website that relies heavily on Elasticsearch to power search functionality across menu items, categories, ingredients, dietary tags, and promotional offers. The dataset includes hundreds o…

---

## [Elasticsearch migration from 7.17 to 8.15](https://discuss.elastic.co/t/elasticsearch-migration-from-7-17-to-8-15/384978)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 8\
**Last updated:** [February 11, 2026, 9:53pm UTC](https://discuss.elastic.co/t/elasticsearch-migration-from-7-17-to-8-15/384978 "2026-02-11T21:53:00Z")

</div>

We need to upgrade from ES 7.17.3 to 8.15.2. We have done the following so far: Ran Upgrade Assistant on 7.17.3 and fixed any reported “Critical” issues. No Critical issue is being reported now. Taken snapshot on a NA…

---

## [Completion Suggester Sorting](https://discuss.elastic.co/t/completion-suggester-sorting/384873)

<div class="topic-metadata">

**Author:** [@Pathwax](https://discuss.elastic.co/u/Pathwax)\
**Replies:** 1\
**Last updated:** [February 9, 2026, 8:15pm UTC](https://discuss.elastic.co/t/completion-suggester-sorting/384873 "2026-02-09T20:15:18Z")

</div>

Hi, I created an index that only contains the suggest property: PUT /test { "mappings": { "properties": { "suggest": { "type": "completion", "analyzer": "standard", "preserve\_separat…

---

## [Corrupted S3 Repository: 1.3M Metadata lines & snapshot\_missing\_exception (Cluster size: 6.5 TB)](https://discuss.elastic.co/t/corrupted-s3-repository-1-3m-metadata-lines-snapshot-missing-exception-cluster-size-6-5-tb/384970)

<div class="topic-metadata">

**Author:** [@Disha\_Vala](https://discuss.elastic.co/u/Disha_Vala)\
**Replies:** 1\
**Last updated:** [February 9, 2026, 12:31pm UTC](https://discuss.elastic.co/t/corrupted-s3-repository-1-3m-metadata-lines-snapshot-missing-exception-cluster-size-6-5-tb/384970 "2026-02-09T12:31:41Z")

</div>

Hi Elastic Team, I am facing a repository corruption issue on Elasticsearch 8.5.3 and would appreciate guidance on how to perform a "surgical" repair of our snapshot metadata. The Situation: Cluster Scale: Our live cl…

---

## [Vulnerability Apache Tika 1.13 \< 3.2.2 XXE (CVE-2025-66516) and Apache Log4j 2.0-beta9 \< 2.25.3 MitM in VA scan report of server](https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881)

<div class="topic-metadata">

**Author:** [@Ravinder07Sharma](https://discuss.elastic.co/u/Ravinder07Sharma)\
**Replies:** 1\
**Last updated:** [February 9, 2026, 10:09am UTC](https://discuss.elastic.co/t/vulnerability-apache-tika-1-13-3-2-2-xxe-cve-2025-66516-and-apache-log4j-2-0-beta9-2-25-3-mitm-in-va-scan-report-of-server/384881 "2026-02-09T10:09:04Z")

</div>

we are running Elasticsearch-8.17.10 on 6 RHEL 8 servers. But we are getting vulnerability Apache Tika 1.13 \< 3.2.2 XXE (CVE-2025-66516) and Apache Log4j 2.0-beta9 \< 2.25.3 MitM in VA scan report of server. log4j vulnera…

---

## [Upgrade assistant can not migrate system indeces during upgrade from 8.18.10 to 9 version](https://discuss.elastic.co/t/upgrade-assistant-can-not-migrate-system-indeces-during-upgrade-from-8-18-10-to-9-version/384973)

<div class="topic-metadata">

**Author:** [@GyurkanMehmed](https://discuss.elastic.co/u/GyurkanMehmed)\
**Replies:** 1\
**Last updated:** [February 9, 2026, 9:20am UTC](https://discuss.elastic.co/t/upgrade-assistant-can-not-migrate-system-indeces-during-upgrade-from-8-18-10-to-9-version/384973 "2026-02-09T09:20:47Z")

</div>

I have two clusters which i am trying to upgade to 9.1.0 from 8.18.10, but migrate system indices throws async\_search: illegal\_state\_exception, so I can not proceed with the upgrade. Both cluster were originally 7v and …

---

## [ElasticSearch in kubernetes is failling with Bad\_certificate](https://discuss.elastic.co/t/elasticsearch-in-kubernetes-is-failling-with-bad-certificate/384959)

<div class="topic-metadata">

**Author:** [@senbe](https://discuss.elastic.co/u/senbe)\
**Replies:** 0\
**Last updated:** [February 8, 2026, 1:27pm UTC](https://discuss.elastic.co/t/elasticsearch-in-kubernetes-is-failling-with-bad-certificate/384959 "2026-02-08T13:27:31Z")

</div>

We setup a Elasticsearch using the eck-stack github repo and let elasticsearch creates its own CA transport certificate. within sometimes, we see the Elasticsearch is moving from green to yellow On analysis, we observed…

---

## [Elasticsearch upgrade from 7 to 8](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-to-8/384901)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [February 6, 2026, 9:27pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-to-8/384901 "2026-02-06T21:27:27Z")

</div>

Hi All, Our current cluster is running on elasticsearch version 7.17.3 and we are planning to upgrade to version 8.15.2 (hopefully an allowed version) We want to adopt a "rolling upgrade" doing one instance at a time. …

---

## [Hide Entitlement warnings?](https://discuss.elastic.co/t/hide-entitlement-warnings/384929)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 2\
**Last updated:** [February 6, 2026, 5:32pm UTC](https://discuss.elastic.co/t/hide-entitlement-warnings/384929 "2026-02-06T17:32:02Z")

</div>

Some of our elasticsearch installations are encountering warnings such as the following and I am wondering, since this is just a warning, is there any way to disable it or set the logging level lower to make this not app…

---

## [ES loses quorum every hour](https://discuss.elastic.co/t/es-loses-quorum-every-hour/384937)

<div class="topic-metadata">

**Author:** [@elastic\_noob1](https://discuss.elastic.co/u/elastic_noob1)\
**Replies:** 3\
**Last updated:** [February 6, 2026, 2:02pm UTC](https://discuss.elastic.co/t/es-loses-quorum-every-hour/384937 "2026-02-06T14:02:12Z")

</div>

We have our clusters running for a few years now on 7.17 with java8. Due to company requirements, I upgraded the cluster to use java17. We use our own java binary due to company policies. Once the cluster was on java17, …

---

## [Elasticsearch trial license downgraded to basic after pod recreation on Kubernetes](https://discuss.elastic.co/t/elasticsearch-trial-license-downgraded-to-basic-after-pod-recreation-on-kubernetes/384885)

<div class="topic-metadata">

**Author:** [@djeannerod](https://discuss.elastic.co/u/djeannerod)\
**Replies:** 1\
**Last updated:** [February 5, 2026, 4:55pm UTC](https://discuss.elastic.co/t/elasticsearch-trial-license-downgraded-to-basic-after-pod-recreation-on-kubernetes/384885 "2026-02-05T16:55:28Z")

</div>

I have deployed a ES stack on Kubernetes with the operator (ECK). Just ES + Kibana, and it is Ok. I’m trying to test some enterprise functions, and activate a trial licence, but elasticsearch reverts to a basic license …

---

## [ES|QL Invoke-WebRequest how to](https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848)

<div class="topic-metadata">

**Author:** [@a11](https://discuss.elastic.co/u/a11)\
**Replies:** 1\
**Last updated:** [February 5, 2026, 3:24pm UTC](https://discuss.elastic.co/t/es-ql-invoke-webrequest-how-to/384848 "2026-02-05T15:24:19Z")

</div>

Hello, I’m trying to send a webrequest with a powershell script: { "query": """ FROM packetbeat-tls | WHERE dnsdomain.keyword == "%domain%" AND @timestamp \> NOW() - 7days | KEEP host.name.keyword, source.ip.keyword …

---

## [Elasticsearch Rule SMTP Action - How to include line breaks](https://discuss.elastic.co/t/elasticsearch-rule-smtp-action-how-to-include-line-breaks/384900)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 2\
**Last updated:** [February 5, 2026, 2:05pm UTC](https://discuss.elastic.co/t/elasticsearch-rule-smtp-action-how-to-include-line-breaks/384900 "2026-02-05T14:05:38Z")

</div>

{{#context.hits}} Source IP Address: {{\_source.src\_ip}} Message {{\_source.new\_port}} {{/context.hits}} I need spaces after every context entry , right now its all jammed together Source IP Address: Message Source …

---

## [Polar encircling geo\_shape geometry](https://discuss.elastic.co/t/polar-encircling-geo-shape-geometry/384919)

<div class="topic-metadata">

**Author:** [@jpolchlo](https://discuss.elastic.co/u/jpolchlo)\
**Replies:** 1\
**Last updated:** [February 5, 2026, 11:25am UTC](https://discuss.elastic.co/t/polar-encircling-geo-shape-geometry/384919 "2026-02-05T11:25:23Z")

</div>

I’ve been looking for an answer to this around the internet, but I want to get some clarity before sinking time into it. The question is whether geo\_shape geometry properly handles polar-encircling geometries. I haven’…

---

## [% by breaking subgroup](https://discuss.elastic.co/t/by-breaking-subgroup/384865)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 8\
**Last updated:** [February 4, 2026, 6:12pm UTC](https://discuss.elastic.co/t/by-breaking-subgroup/384865 "2026-02-04T18:12:52Z")

</div>

I have following record month client minute 1/1/25 A 100 1/1/25 B 100 2/1/25 A 100 2/1/25 B 100 I want to setup table vz by month aggregation 1/1/25 A 100 25% …

---

## [How to hash sensitive fields in Elasticsearch and show hash vs original based on user permissions?](https://discuss.elastic.co/t/how-to-hash-sensitive-fields-in-elasticsearch-and-show-hash-vs-original-based-on-user-permissions/384905)

<div class="topic-metadata">

**Author:** [@Abhi\_Abhishek](https://discuss.elastic.co/u/Abhi_Abhishek)\
**Replies:** 2\
**Last updated:** [February 4, 2026, 1:09pm UTC](https://discuss.elastic.co/t/how-to-hash-sensitive-fields-in-elasticsearch-and-show-hash-vs-original-based-on-user-permissions/384905 "2026-02-04T13:09:04Z")

</div>

We have some fields containing sensitive information, and we do not want all users to see the original values. We want to store these fields in a hashed form while indexing and control what different users can see. I h…

---

## [Index/Datastream Daily ingest size](https://discuss.elastic.co/t/index-datastream-daily-ingest-size/384801)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 2\
**Last updated:** [February 3, 2026, 8:07pm UTC](https://discuss.elastic.co/t/index-datastream-daily-ingest-size/384801 "2026-02-03T20:07:35Z")

</div>

I need to find out our daily ingest rate how do you do this for Datastreams how do you do this for Indices

---

## [Further enhance TOP ES|QL function please](https://discuss.elastic.co/t/further-enhance-top-es-ql-function-please/384898)

<div class="topic-metadata">

**Author:** [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Replies:** 0\
**Last updated:** [February 3, 2026, 7:50pm UTC](https://discuss.elastic.co/t/further-enhance-top-es-ql-function-please/384898 "2026-02-03T19:50:22Z")

</div>

Now that 9.3.0 is out, I notice this added (and very useful) ES|QL feature: Support extra field (outputField) in TOP function. Values of outputField will be returned instead of values of field , as discussed here and t…

---

## [Elastic Stack 9.3?](https://discuss.elastic.co/t/elastic-stack-9-3/384875)

<div class="topic-metadata">

**Author:** [@gauchj](https://discuss.elastic.co/u/gauchj)\
**Replies:** 5\
**Last updated:** [February 3, 2026, 2:57pm UTC](https://discuss.elastic.co/t/elastic-stack-9-3/384875 "2026-02-03T14:57:03Z")

</div>

We just upgraded our elastic stack from 8.19 to 9.2. When upgrading kibana (elasticsearch on 9.2.4), we get an error: kibana 9.3 cannot communicate to elasticsearch 9.2.4. There is no announcement on the release notes, …

---

## [Elastic self manage / architecture](https://discuss.elastic.co/t/elastic-self-manage-architecture/384856)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 2\
**Last updated:** [February 3, 2026, 11:27am UTC](https://discuss.elastic.co/t/elastic-self-manage-architecture/384856 "2026-02-03T11:27:46Z")

</div>

Hello everyone ! i am very new to elastic and while going through the documentation i was not able to find somethings ,so if possible help me understand these and also provide the documentation link so i can verify (in …

---

## [Encountering Elasticsearch Server Error while Percolating in 8.19.6](https://discuss.elastic.co/t/encountering-elasticsearch-server-error-while-percolating-in-8-19-6/384859)

<div class="topic-metadata">

**Author:** [@mserrato](https://discuss.elastic.co/u/mserrato)\
**Replies:** 1\
**Last updated:** [February 2, 2026, 4:44pm UTC](https://discuss.elastic.co/t/encountering-elasticsearch-server-error-while-percolating-in-8-19-6/384859 "2026-02-02T16:44:02Z")

</div>

Hello! After upgrading my cluster from 7.17 to 8.19, I’ve started encountering an intermittent server error: java.util.NoSuchElementException when performing percolation. I’ve opened up an issue on the elasticsearch rep…

---

## [OIDC integration with kibana without Elastic license](https://discuss.elastic.co/t/oidc-integration-with-kibana-without-elastic-license/374617)

<div class="topic-metadata">

**Author:** [@akmoharana](https://discuss.elastic.co/u/akmoharana)\
**Replies:** 6\
**Last updated:** [February 1, 2026, 1:57pm UTC](https://discuss.elastic.co/t/oidc-integration-with-kibana-without-elastic-license/374617 "2026-02-01T13:57:56Z")

</div>

Hi Team, I have deployed ELK on Kubernetes and am currently using OIDC integration for SSO with an Elastic Platinum license. However, the licensing cost is exceeding our budget. I’m exploring options to exclude the lice…

---

## [How to Increase the throughput for KNN in my ES cluster](https://discuss.elastic.co/t/how-to-increase-the-throughput-for-knn-in-my-es-cluster/384252)

<div class="topic-metadata">

**Author:** [@Esteban\_Velasquez](https://discuss.elastic.co/u/Esteban_Velasquez)\
**Replies:** 6\
**Last updated:** [January 31, 2026, 10:44am UTC](https://discuss.elastic.co/t/how-to-increase-the-throughput-for-knn-in-my-es-cluster/384252 "2026-01-31T10:44:11Z")

</div>

Hello! I created a track in ESrally with some queries that are normally done in my ES cluster and I replicated the big index (using snapshot) from the original cluster I have into a new one. I am doing an ESrally test f…

---

## [ELSER model loaded in ML node, but do I need it?](https://discuss.elastic.co/t/elser-model-loaded-in-ml-node-but-do-i-need-it/384835)

<div class="topic-metadata">

**Author:** [@taprove](https://discuss.elastic.co/u/taprove)\
**Replies:** 0\
**Last updated:** [January 30, 2026, 7:46pm UTC](https://discuss.elastic.co/t/elser-model-loaded-in-ml-node-but-do-i-need-it/384835 "2026-01-30T19:46:50Z")

</div>

My questions: Do ML nodes have to have a Trained Model assigned? Does adding a Trained Model for other features (AI Assistant, KB functionality) cause it to automatically deploy to ML nodes? Is there anyway to remove i…

---

## [Impact of CVE-2025-68161 on Elasticsearch v7.17.28](https://discuss.elastic.co/t/impact-of-cve-2025-68161-on-elasticsearch-v7-17-28/384825)

<div class="topic-metadata">

**Author:** [@amolrm](https://discuss.elastic.co/u/amolrm)\
**Replies:** 4\
**Last updated:** [January 30, 2026, 4:31pm UTC](https://discuss.elastic.co/t/impact-of-cve-2025-68161-on-elasticsearch-v7-17-28/384825 "2026-01-30T16:31:48Z")

</div>

Hi, Kindly let know if Elasticsearch v7.17.28 is impacted by CVE-2025-68161 CVE Details as follows - Description: The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostna…

---

## [Upgrading from 7.x to 8.x with soft deletes disabled](https://discuss.elastic.co/t/upgrading-from-7-x-to-8-x-with-soft-deletes-disabled/384722)

<div class="topic-metadata">

**Author:** [@ahmedasadi](https://discuss.elastic.co/u/ahmedasadi)\
**Replies:** 6\
**Last updated:** [January 29, 2026, 6:34pm UTC](https://discuss.elastic.co/t/upgrading-from-7-x-to-8-x-with-soft-deletes-disabled/384722 "2026-01-29T18:34:21Z")

</div>

Hi, We use Elasticsearch as a lightweight index rather than a primary data store. The actual documents live elsewhere, and ES is only used to retrieve matching document IDs. Our current Elasticsearch 7.x setup includes…

---

## [See Fleet Policies and Agents across all Spaces](https://discuss.elastic.co/t/see-fleet-policies-and-agents-across-all-spaces/384806)

<div class="topic-metadata">

**Author:** [@cconard.kcsr](https://discuss.elastic.co/u/cconard.kcsr)\
**Replies:** 0\
**Last updated:** [January 29, 2026, 6:12pm UTC](https://discuss.elastic.co/t/see-fleet-policies-and-agents-across-all-spaces/384806 "2026-01-29T18:12:23Z")

</div>

We have a number of Kibana Spaces defined for our users, including Fleet Agents defined by Spaces. This is great functionality to allow our users some access to their agents. However, as general admins and SMEs (Subject …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=7)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=9)
