# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=82

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 83

---

## [Optimize the replica restore](https://discuss.elastic.co/t/optimize-the-replica-restore/365640)

<div class="topic-metadata">

**Author:** [@jhonsouza](https://discuss.elastic.co/u/jhonsouza)\
**Replies:** 0\
**Last updated:** [August 27, 2024, 7:05pm UTC](https://discuss.elastic.co/t/optimize-the-replica-restore/365640 "2024-08-27T19:05:37Z")

</div>

Hello everyone! I would like to know if there is a method to boost the restoration of replicas? When my cluster needs to restore many replicas, it takes a long time for the cluster health to turn green. If someone can …

---

## [Orphan indices on nodes with centos7 os](https://discuss.elastic.co/t/orphan-indices-on-nodes-with-centos7-os/365637)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 0\
**Last updated:** [August 27, 2024, 6:46pm UTC](https://discuss.elastic.co/t/orphan-indices-on-nodes-with-centos7-os/365637 "2024-08-27T18:46:33Z")

</div>

Hi, please do you have experience and tips how to solve the problem with ORPHANS on elastic nodes installed on old Centos7 VM 8core/32GB RAM, 2TB SSD nodes we have elasticsearch version 8.12.1 new nodes are running on…

---

## [Elasticsearch migration and rollback strategy (snapshot and restore)](https://discuss.elastic.co/t/elasticsearch-migration-and-rollback-strategy-snapshot-and-restore/365577)

<div class="topic-metadata">

**Author:** [@mario12](https://discuss.elastic.co/u/mario12)\
**Replies:** 7\
**Last updated:** [August 27, 2024, 6:05pm UTC](https://discuss.elastic.co/t/elasticsearch-migration-and-rollback-strategy-snapshot-and-restore/365577 "2024-08-27T18:05:46Z")

</div>

We are planning to migrate data of Elasticsearch cluster from AWS to new cluster set up in GCP (both clusters are self managed). Steps are as follows: Full snapshot AWS ES cluster Restore the full snapshot on GCP ES cl…

---

## [Higher number of active threads with elasticsearch-java dependency](https://discuss.elastic.co/t/higher-number-of-active-threads-with-elasticsearch-java-dependency/364385)

<div class="topic-metadata">

**Author:** [@sibasish.palo](https://discuss.elastic.co/u/sibasish.palo)\
**Replies:** 26\
**Last updated:** [August 27, 2024, 4:42pm UTC](https://discuss.elastic.co/t/higher-number-of-active-threads-with-elasticsearch-java-dependency/364385 "2024-08-27T16:42:00Z")

</div>

Hi we are currently migrating to Elasticsearch v8.12.0 and we have below code to create the Elasticsearch client to make the connections to Elasticsearch. we are using elasticsearch-java: v8.12.0 dependency @Provides …

---

## [Index mapping problem](https://discuss.elastic.co/t/index-mapping-problem/365607)

<div class="topic-metadata">

**Author:** [@cazzz99](https://discuss.elastic.co/u/cazzz99)\
**Replies:** 3\
**Last updated:** [August 27, 2024, 2:59pm UTC](https://discuss.elastic.co/t/index-mapping-problem/365607 "2024-08-27T14:59:47Z")

</div>

My current mapping is like: self.es\_client.indices.create( index=self.index\_name, mappings={ "properties":{ text\_field: {"type": "text"}, …

---

## [Using Transform for document count when document updated](https://discuss.elastic.co/t/using-transform-for-document-count-when-document-updated/364924)

<div class="topic-metadata">

**Author:** [@Derek.X](https://discuss.elastic.co/u/Derek.X)\
**Replies:** 3\
**Last updated:** [August 27, 2024, 2:44pm UTC](https://discuss.elastic.co/t/using-transform-for-document-count-when-document-updated/364924 "2024-08-27T14:44:02Z")

</div>

There is an index that documents are updated with time. We are looking for some way to continuesly (every several minutes) provide count of documents grouped by some condition. Example: 2024/08/15 00:00:00, order1, new …

---

## [Elasticsearch cross cluster replication - bi-directional is not working](https://discuss.elastic.co/t/elasticsearch-cross-cluster-replication-bi-directional-is-not-working/365619)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 6\
**Last updated:** [August 27, 2024, 2:43pm UTC](https://discuss.elastic.co/t/elasticsearch-cross-cluster-replication-bi-directional-is-not-working/365619 "2024-08-27T14:43:12Z")

</div>

Hi We need to do the cross cluster replication to avoid the downtime in our environment It is working fine in the single/uni directional DR datacenter and the leader index is replicating fine the follower index but wh…

---

## [Raise Elasticsearch field limit via config](https://discuss.elastic.co/t/raise-elasticsearch-field-limit-via-config/365602)

<div class="topic-metadata">

**Author:** [@daniel90](https://discuss.elastic.co/u/daniel90)\
**Replies:** 2\
**Last updated:** [August 27, 2024, 8:13am UTC](https://discuss.elastic.co/t/raise-elasticsearch-field-limit-via-config/365602 "2024-08-27T08:13:38Z")

</div>

I tried the obvious, but that gives me the: "node settings must not contain any index level settings" Error So how do i do it? I want a permanent solution that does not involve a cronjob setting the limit to X every …

---

## [Unable to Split Large Index](https://discuss.elastic.co/t/unable-to-split-large-index/365233)

<div class="topic-metadata">

**Author:** [@Ian\_Simpson](https://discuss.elastic.co/u/Ian_Simpson)\
**Replies:** 1\
**Last updated:** [August 26, 2024, 6:21pm UTC](https://discuss.elastic.co/t/unable-to-split-large-index/365233 "2024-08-26T18:21:18Z")

</div>

I have an index with 21 primary shards and 2 replicas that has grown such that each shard is between 90-120 GB. This is spread between 9 nodes that sit at around 37-40% disk usage right now. I attempted a split operatio…

---

## [Monitoring elasticstack whit elastic agent](https://discuss.elastic.co/t/monitoring-elasticstack-whit-elastic-agent/365482)

<div class="topic-metadata">

**Author:** [@erickhillo](https://discuss.elastic.co/u/erickhillo)\
**Replies:** 1\
**Last updated:** [August 26, 2024, 5:35pm UTC](https://discuss.elastic.co/t/monitoring-elasticstack-whit-elastic-agent/365482 "2024-08-26T17:35:55Z")

</div>

Hi! I've a production elasticsatack deployment (elasticsearch, kibana, logstash) these are running in containers with docker, and at the same time I've anoher deploy in diferent server with just elasticsearch, kibana an…

---

## [Issue with otlp-collectors and elastic](https://discuss.elastic.co/t/issue-with-otlp-collectors-and-elastic/361584)

<div class="topic-metadata">

**Author:** [@iamp3](https://discuss.elastic.co/u/iamp3)\
**Replies:** 3\
**Last updated:** [August 26, 2024, 5:24pm UTC](https://discuss.elastic.co/t/issue-with-otlp-collectors-and-elastic/361584 "2024-08-26T17:24:06Z")

</div>

Hi, It looks like smth block search/view of metric data in real-time mode (from otel-collectors) and produces this data incrementally. For example, on 12 June I could check data till 01:00, but at 13 June I could see dat…

---

## [Query string search with \`allow\_leading\_wildcard\` set to false does not throws](https://discuss.elastic.co/t/query-string-search-with-allow-leading-wildcard-set-to-false-does-not-throws/365564)

<div class="topic-metadata">

**Author:** [@darshan\_v](https://discuss.elastic.co/u/darshan_v)\
**Replies:** 0\
**Last updated:** [August 26, 2024, 4:11pm UTC](https://discuss.elastic.co/t/query-string-search-with-allow-leading-wildcard-set-to-false-does-not-throws/365564 "2024-08-26T16:11:55Z")

</div>

Hey! I was testing some query\_string search queries on Elasticsearch 8.14.0 where I had set allow\_leading\_wildcard to false but the actual query contained a leading wildcard. Instead of throwing an exception, ES returns …

---

## [Elasticsearch Python client: Global timeout configuration?](https://discuss.elastic.co/t/elasticsearch-python-client-global-timeout-configuration/365536)

<div class="topic-metadata">

**Author:** [@Imad\_Saddik](https://discuss.elastic.co/u/Imad_Saddik)\
**Replies:** 0\
**Last updated:** [August 26, 2024, 7:50am UTC](https://discuss.elastic.co/t/elasticsearch-python-client-global-timeout-configuration/365536 "2024-08-26T07:50:28Z")

</div>

I'm working with multiple indices using the Elasticsearch Python client API and have a question about timeout configuration. When creating the Elasticsearch client, we can specify a timeout: client = Elasticsearch( …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/365518)

<div class="topic-metadata">

**Author:** [@hassan\_developer](https://discuss.elastic.co/u/hassan_developer)\
**Replies:** 3\
**Last updated:** [August 26, 2024, 3:27pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/365518 "2024-08-26T15:27:53Z")

</div>

Hi ! I am new to Elasticsearch . I tried installing it on Cloud instance all worked well. Until I tird installing Plugin for windows event logs it asked me to add these 2 lines to elasticsearch.yml file - xpack.securi…

---

## [Use knn inside functional\_score query](https://discuss.elastic.co/t/use-knn-inside-functional-score-query/365554)

<div class="topic-metadata">

**Author:** [@kunal\_foundit](https://discuss.elastic.co/u/kunal_foundit)\
**Replies:** 2\
**Last updated:** [August 26, 2024, 2:20pm UTC](https://discuss.elastic.co/t/use-knn-inside-functional-score-query/365554 "2024-08-26T14:20:20Z")

</div>

I am using elasticsearch-java client (co.elastic.clients) v8.11 I need to create a knn query inside functional\_score query similar to query shared below. { "size": 3, "query": { "function\_score": { "query": {…

---

## [Elasticsearch HTTPS and Adding to Java Rest Client](https://discuss.elastic.co/t/elasticsearch-https-and-adding-to-java-rest-client/365477)

<div class="topic-metadata">

**Author:** [@GoldNotepad](https://discuss.elastic.co/u/GoldNotepad)\
**Replies:** 1\
**Last updated:** [August 26, 2024, 12:07pm UTC](https://discuss.elastic.co/t/elasticsearch-https-and-adding-to-java-rest-client/365477 "2024-08-26T12:07:58Z")

</div>

I'm attempting to enable HTTPS for elasticsearch. First I create the elasticsearch certificate authority. elasticsearch-certutil ca Then I generate the certificate. elasticsearch-certutil cert --ca elastic-stack-ca.p…

---

## [Nested Array Problem](https://discuss.elastic.co/t/nested-array-problem/365538)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 3\
**Last updated:** [August 26, 2024, 10:24am UTC](https://discuss.elastic.co/t/nested-array-problem/365538 "2024-08-26T10:24:49Z")

</div>

Hi Team, We have groups on article like this \[\[Group1, Group2\], \[Group3, Group4\]\] Suppose we have 3 users and groups of these users are like below User 1 Group \[Group1, Group4\] User 2 Group \[Group1, Group2\] User 3 …

---

## [Elasticsearch cluster new Node addition error](https://discuss.elastic.co/t/elasticsearch-cluster-new-node-addition-error/365429)

<div class="topic-metadata">

**Author:** [@saxena\_shk7](https://discuss.elastic.co/u/saxena_shk7)\
**Replies:** 8\
**Last updated:** [August 26, 2024, 10:21am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-new-node-addition-error/365429 "2024-08-26T10:21:57Z")

</div>

I am trying to add third node in my elasticsearch existing cluster, but is unable to do so. I have tried everything from uncommenting transport.host option and setting it to 0.0.0.0 also setting discovery.seed\_host to m…

---

## [Match query with only 2 word search in search query](https://discuss.elastic.co/t/match-query-with-only-2-word-search-in-search-query/365526)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 1\
**Last updated:** [August 26, 2024, 7:03am UTC](https://discuss.elastic.co/t/match-query-with-only-2-word-search-in-search-query/365526 "2024-08-26T07:03:37Z")

</div>

Document 1: { "id": 1, "title": "marble flooring" } Document 2: { "id": 2, "title": "flooring marble" } Document 3: { "id": 3, "title": "italian marble flooring" } Existing query which am us…

---

## [Unable to update elastic data](https://discuss.elastic.co/t/unable-to-update-elastic-data/365530)

<div class="topic-metadata">

**Author:** [@irajeshr](https://discuss.elastic.co/u/irajeshr)\
**Replies:** 0\
**Last updated:** [August 26, 2024, 6:52am UTC](https://discuss.elastic.co/t/unable-to-update-elastic-data/365530 "2024-08-26T06:52:17Z")

</div>

i am trying to update elastic data based on ID, but the error is failing with bad request/data missing error. Code: Dim testIndex1 = New testIndex With { .id = txtId.Text.Trim, .User = txtUserid.Text.Trim, …

---

## [Sort on Elastic Search .NET API](https://discuss.elastic.co/t/sort-on-elastic-search-net-api/365527)

<div class="topic-metadata">

**Author:** [@irajeshr](https://discuss.elastic.co/u/irajeshr)\
**Replies:** 0\
**Last updated:** [August 26, 2024, 6:43am UTC](https://discuss.elastic.co/t/sort-on-elastic-search-net-api/365527 "2024-08-26T06:43:47Z")

</div>

can anyone pls share object initializer syntax for sort requests instead of lambdas? i tried couple of things but they are not working Code: Dim req = New SearchRequest(Of testIndex)(txtIndex2.Text.Trim) With { .…

---

## [Winlogbeat error connecting to ElasticSearch](https://discuss.elastic.co/t/winlogbeat-error-connecting-to-elasticsearch/365316)

<div class="topic-metadata">

**Author:** [@Edzel\_Severino](https://discuss.elastic.co/u/Edzel_Severino)\
**Replies:** 10\
**Last updated:** [August 26, 2024, 12:58am UTC](https://discuss.elastic.co/t/winlogbeat-error-connecting-to-elasticsearch/365316 "2024-08-26T00:58:22Z")

</div>

Hello, can someone help me? I am having a problem after winlogbeat installation. when i run .\\winlogbeat.exe setup -e is show error: Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error…

---

## [I have trial subscription - No ML nodes exist in the cluster](https://discuss.elastic.co/t/i-have-trial-subscription-no-ml-nodes-exist-in-the-cluster/365504)

<div class="topic-metadata">

**Author:** [@Rahul\_Chandra](https://discuss.elastic.co/u/Rahul_Chandra)\
**Replies:** 1\
**Last updated:** [August 26, 2024, 1:08am UTC](https://discuss.elastic.co/t/i-have-trial-subscription-no-ml-nodes-exist-in-the-cluster/365504 "2024-08-26T01:08:59Z")

</div>

I have trial subscription When creating an inference endpoint I get following error Could not start deployment because no suitable nodes were found, allocation explanation \[No ML nodes exist in the cluster\]". How can …

---

## [Failed to connect to localhost port 9200: Connection refused](https://discuss.elastic.co/t/failed-to-connect-to-localhost-port-9200-connection-refused/364710)

<div class="topic-metadata">

**Author:** [@Edzel\_Severino](https://discuss.elastic.co/u/Edzel_Severino)\
**Replies:** 6\
**Last updated:** [August 25, 2024, 11:48am UTC](https://discuss.elastic.co/t/failed-to-connect-to-localhost-port-9200-connection-refused/364710 "2024-08-25T11:48:06Z")

</div>

Can someone help me? I followed a link on installing elastic,kibana and logstash and i was able to successfully installed elastic. However, when i try to netstat and look for the port 9200, it wasnt there. Also I can't …

---

## [Apparently I need to edit a Filebeat 'data stream template'. Such a thing does not exist!](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 5\
**Last updated:** [August 24, 2024, 3:04pm UTC](https://discuss.elastic.co/t/apparently-i-need-to-edit-a-filebeat-data-stream-template-such-a-thing-does-not-exist/364495 "2024-08-24T15:04:47Z")

</div>

We're using Filebeat 8.14.3 to index network logs. We'd like to enable the \_size field for all Filebeat data streams. (My previous thread on this topic). Here's the attempt to enable the "\_size" field: PUT /\_index\_temp…

---

## [Problem in editing @timestamp through ingest pipeline](https://discuss.elastic.co/t/problem-in-editing-timestamp-through-ingest-pipeline/365491)

<div class="topic-metadata">

**Author:** [@fardadmh](https://discuss.elastic.co/u/fardadmh)\
**Replies:** 2\
**Last updated:** [August 24, 2024, 1:37pm UTC](https://discuss.elastic.co/t/problem-in-editing-timestamp-through-ingest-pipeline/365491 "2024-08-24T13:37:04Z")

</div>

Hello there. I've been trying to manipulate @timestamp through a script in a ingest pipeline (substract 8 hours). I tried referencing @timestamp using this syntax: ctx.\_source\['@timestamp'\] = ctx.\_source\['@timestamp'\].…

---

## [Zero-Downtime Split Operation](https://discuss.elastic.co/t/zero-downtime-split-operation/365161)

<div class="topic-metadata">

**Author:** [@Ian\_Simpson](https://discuss.elastic.co/u/Ian_Simpson)\
**Replies:** 1\
**Last updated:** [August 24, 2024, 12:06pm UTC](https://discuss.elastic.co/t/zero-downtime-split-operation/365161 "2024-08-24T12:06:36Z")

</div>

I'm trying to figure out the best way to perform a zero-downtime split operation. I have a few questions: Is it possible for writes to go into the new index while the split is ongoing? Or should I shut down write opera…

---

## [Auto-generated deafult password hash error](https://discuss.elastic.co/t/auto-generated-deafult-password-hash-error/365401)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 4\
**Last updated:** [August 24, 2024, 11:45am UTC](https://discuss.elastic.co/t/auto-generated-deafult-password-hash-error/365401 "2024-08-24T11:45:19Z")

</div>

so as i am following Tutorial 1: Installing a self-managed Elastic Stack at the end of step 3 i should be able to run curl command and see some sort of default message that indicate my set up was fine but instead i get t…

---

## [ElasticSearch sorting by text length and huge ignore\_above](https://discuss.elastic.co/t/elasticsearch-sorting-by-text-length-and-huge-ignore-above/365462)

<div class="topic-metadata">

**Author:** [@sukhoy94](https://discuss.elastic.co/u/sukhoy94)\
**Replies:** 2\
**Last updated:** [August 24, 2024, 7:27am UTC](https://discuss.elastic.co/t/elasticsearch-sorting-by-text-length-and-huge-ignore-above/365462 "2024-08-24T07:27:04Z")

</div>

I need to sort my elasticsearch documents by length of a text field. However, this field can sometimes contain a very large amount of text (up to 15000 characters). I am aware that the ignore\_above parameter, which defau…

---

## [Unable to create extensions in managed elastic gold tier](https://discuss.elastic.co/t/unable-to-create-extensions-in-managed-elastic-gold-tier/365484)

<div class="topic-metadata">

**Author:** [@gsk6](https://discuss.elastic.co/u/gsk6)\
**Replies:** 1\
**Last updated:** [August 24, 2024, 6:09am UTC](https://discuss.elastic.co/t/unable-to-create-extensions-in-managed-elastic-gold-tier/365484 "2024-08-24T06:09:59Z")

</div>

I am trying to create an extension in elasticsearch using the UI, but under the extensions page, the "Upload extension" option is disabled for me. I could not find a similar case online, can someone help on this? I read…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=81)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=83)
