# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=85

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 86

---

## [Unassigned shards with reason "ElasticSearch can allocate shards"](https://discuss.elastic.co/t/unassigned-shards-with-reason-elasticsearch-can-allocate-shards/364724)

<div class="topic-metadata">

**Author:** [@mukularora89](https://discuss.elastic.co/u/mukularora89)\
**Replies:** 8\
**Last updated:** [August 15, 2024, 6:27am UTC](https://discuss.elastic.co/t/unassigned-shards-with-reason-elasticsearch-can-allocate-shards/364724 "2024-08-15T06:27:07Z")

</div>

We have recently upgraded our cluster to ES 8.12.2. We are observing unassigned shards and on further looking cluster allocation explain API we could see that can\_allocate="yes" and allocate\_explanation "Elasticsearch ca…

---

## [ELK stack production servers for configurations](https://discuss.elastic.co/t/elk-stack-production-servers-for-configurations/364926)

<div class="topic-metadata">

**Author:** [@BevisDev](https://discuss.elastic.co/u/BevisDev)\
**Replies:** 1\
**Last updated:** [August 14, 2024, 7:05pm UTC](https://discuss.elastic.co/t/elk-stack-production-servers-for-configurations/364926 "2024-08-14T19:05:09Z")

</div>

Hi everyone, i am new in ELK Stack, i am interested to use ELK in production environment with purpose centralize logs all my application I need to your help to configure production server for below requirement. all my…

---

## [Elasticsearch rolling upgrade failed](https://discuss.elastic.co/t/elasticsearch-rolling-upgrade-failed/364907)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 9\
**Last updated:** [August 14, 2024, 6:20pm UTC](https://discuss.elastic.co/t/elasticsearch-rolling-upgrade-failed/364907 "2024-08-14T18:20:58Z")

</div>

I did rolling upgrade for my cluster with two nodes from 8.8 to 8.15. I got 503 error. Here is the result. curl -X GET -k -u elastic:PASSWORD 'https://localhost:9200' {"error":{"root\_cause":\[{"type":"status\_exception","…

---

## [Adjusting Field Boost Based on Indexed Scores in Elasticsearch](https://discuss.elastic.co/t/adjusting-field-boost-based-on-indexed-scores-in-elasticsearch/364826)

<div class="topic-metadata">

**Author:** [@Gokhan\_Gunes](https://discuss.elastic.co/u/Gokhan_Gunes)\
**Replies:** 2\
**Last updated:** [August 14, 2024, 5:49pm UTC](https://discuss.elastic.co/t/adjusting-field-boost-based-on-indexed-scores-in-elasticsearch/364826 "2024-08-14T17:49:25Z")

</div>

Description: I’m working on an e-commerce site where products are indexed in Elasticsearch. Users search through fields like brand, publisher, product\_name, and category. I typically give the highest boost to the name f…

---

## [Issue during version upgrade from 7.17.8 to 8.12.2](https://discuss.elastic.co/t/issue-during-version-upgrade-from-7-17-8-to-8-12-2/361491)

<div class="topic-metadata">

**Author:** [@mukularora89](https://discuss.elastic.co/u/mukularora89)\
**Replies:** 7\
**Last updated:** [August 14, 2024, 2:52pm UTC](https://discuss.elastic.co/t/issue-during-version-upgrade-from-7-17-8-to-8-12-2/361491 "2024-08-14T14:52:26Z")

</div>

Hi, I am trying to upgrade Kibana node from 7.17.8 to 8.12.2. So first we have installed Elasticsearch 8.12.2 on Kibana node and on elasticsearch service start I am getting below error java.lang.NullPointerException: …

---

## [Runtime Mapping agg query error](https://discuss.elastic.co/t/runtime-mapping-agg-query-error/364883)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 1\
**Last updated:** [August 14, 2024, 2:41pm UTC](https://discuss.elastic.co/t/runtime-mapping-agg-query-error/364883 "2024-08-14T14:41:27Z")

</div>

Can you help me the understand the meaning of this error. Added query, response and index mapping Query: { "runtime\_mappings": { "count\_defect": { "type": "long", "script": "emit(doc…

---

## [Vulnerable Java version bundled with 8.14.3 & 8.15](https://discuss.elastic.co/t/vulnerable-java-version-bundled-with-8-14-3-8-15/364861)

<div class="topic-metadata">

**Author:** [@dan\_walker](https://discuss.elastic.co/u/dan_walker)\
**Replies:** 5\
**Last updated:** [August 14, 2024, 1:37pm UTC](https://discuss.elastic.co/t/vulnerable-java-version-bundled-with-8-14-3-8-15/364861 "2024-08-14T13:37:14Z")

</div>

Java 22.0.1 contains a HIGH vulnerability, as indicated by CVEs reported in July 2024. This version is/was bundled with ES 8.14.3. I was expecting a version patch to be included in the next ES release, but looking at th…

---

## [Elasticsearch snapshot issue in kubernets](https://discuss.elastic.co/t/elasticsearch-snapshot-issue-in-kubernets/364878)

<div class="topic-metadata">

**Author:** [@Nauman\_Kyani](https://discuss.elastic.co/u/Nauman_Kyani)\
**Replies:** 17\
**Last updated:** [August 14, 2024, 11:57am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-issue-in-kubernets/364878 "2024-08-14T11:57:54Z")

</div>

Hi , I am currently running an Elasticsearch cluster on Kubernetes using the Elastic Operator. My setup includes 3 master nodes, 2 client nodes, and 3 worker nodes. I have configured the cluster to use an NFS path for s…

---

## [ElasticSearch Highlighting not doing what I would expect](https://discuss.elastic.co/t/elasticsearch-highlighting-not-doing-what-i-would-expect/364831)

<div class="topic-metadata">

**Author:** [@Akesh\_Jadhav](https://discuss.elastic.co/u/Akesh_Jadhav)\
**Replies:** 3\
**Last updated:** [August 14, 2024, 10:07am UTC](https://discuss.elastic.co/t/elasticsearch-highlighting-not-doing-what-i-would-expect/364831 "2024-08-14T10:07:56Z")

</div>

Hi, I am performing one regex query on the keyword field POST 1101741821\_mails/\_search { "query": { "regexp": { "body.not\_analyzed": ".hello my." } }, "highlight": { "fields": { "body.not\_analyzed": { "pre\_ta…

---

## [Is it possible to use ScoreFunctionBuilder/ScoreFunction plugin within script\_score query?](https://discuss.elastic.co/t/is-it-possible-to-use-scorefunctionbuilder-scorefunction-plugin-within-script-score-query/364904)

<div class="topic-metadata">

**Author:** [@maartenkroon](https://discuss.elastic.co/u/maartenkroon)\
**Replies:** 0\
**Last updated:** [August 14, 2024, 10:03am UTC](https://discuss.elastic.co/t/is-it-possible-to-use-scorefunctionbuilder-scorefunction-plugin-within-script-score-query/364904 "2024-08-14T10:03:28Z")

</div>

Hi, I have developed a custom ScoreFunctionBuilder / ScoreFunction as part of Elasticsearch SearchPlugin. I now can use this function "my\_function" within an Elasticsearch query as part of a function\_score query like: {…

---

## [Ingest data from AWS Kinesis Data Firehose](https://discuss.elastic.co/t/ingest-data-from-aws-kinesis-data-firehose/363540)

<div class="topic-metadata">

**Author:** [@noor.muradi](https://discuss.elastic.co/u/noor.muradi)\
**Replies:** 1\
**Last updated:** [August 14, 2024, 7:32am UTC](https://discuss.elastic.co/t/ingest-data-from-aws-kinesis-data-firehose/363540 "2024-08-14T07:32:41Z")

</div>

I have ECK cluster, and I want to ingest AWS WAF logs to elastic using Kineses Data Firehose, created encoded api key in Kibana with superuser role, in Kenises data firehose, have configured destination endpoint with ela…

---

## [.NET new client migration issue](https://discuss.elastic.co/t/net-new-client-migration-issue/364774)

<div class="topic-metadata">

**Author:** [@jahedi](https://discuss.elastic.co/u/jahedi)\
**Replies:** 3\
**Last updated:** [August 14, 2024, 5:14am UTC](https://discuss.elastic.co/t/net-new-client-migration-issue/364774 "2024-08-14T05:14:15Z")

</div>

Hi, I am currently using v7 Elastic .NET client Nest. I want to migrate to the new Elastic.Client.Elasticsearch package v8. I have problems with this package's documentations and I can not find proper docs to use this …

---

## [On premise elasticsearch and kibana license](https://discuss.elastic.co/t/on-premise-elasticsearch-and-kibana-license/364866)

<div class="topic-metadata">

**Author:** [@TheGreatBaldOne](https://discuss.elastic.co/u/TheGreatBaldOne)\
**Replies:** 2\
**Last updated:** [August 14, 2024, 4:08am UTC](https://discuss.elastic.co/t/on-premise-elasticsearch-and-kibana-license/364866 "2024-08-14T04:08:50Z")

</div>

Ok so i read here that elasticsearch, with the basic license is free if self managed. I understand if i am a cloud provider( which i am not ) that does not apply for me. Are there other maybe limits in total cpu or ram…

---

## [Hi i have question about cancel\_after\_time\_interval option](https://discuss.elastic.co/t/hi-i-have-question-about-cancel-after-time-interval-option/364877)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 0\
**Last updated:** [August 14, 2024, 2:48am UTC](https://discuss.elastic.co/t/hi-i-have-question-about-cancel-after-time-interval-option/364877 "2024-08-14T02:48:27Z")

</div>

i have any question The timeout option removes the output of a specific shard and responds within the exception time if a specific shard does not respond for more than that number of seconds. What is the cancel\_after\_t…

---

## [Synonyms returning no\_such\_file\_exception exceptin](https://discuss.elastic.co/t/synonyms-returning-no-such-file-exception-exceptin/364875)

<div class="topic-metadata">

**Author:** [@ryoga](https://discuss.elastic.co/u/ryoga)\
**Replies:** 0\
**Last updated:** [August 14, 2024, 1:54am UTC](https://discuss.elastic.co/t/synonyms-returning-no-such-file-exception-exceptin/364875 "2024-08-14T01:54:43Z")

</div>

Elasticsearch 8.15. Followed the instructions to upload synonyms file inside a zip file /dictionaries/synonyms.txt using custom bundles ( Upload custom plugins and bundles | Elasticsearch Service Documentation | Elastic)…

---

## [Icu\_normalizer is not working](https://discuss.elastic.co/t/icu-normalizer-is-not-working/364858)

<div class="topic-metadata">

**Author:** [@Aliaksandr\_Khramtsov](https://discuss.elastic.co/u/Aliaksandr_Khramtsov)\
**Replies:** 0\
**Last updated:** [August 13, 2024, 7:26pm UTC](https://discuss.elastic.co/t/icu-normalizer-is-not-working/364858 "2024-08-13T19:26:10Z")

</div>

GET /\_cat/plugins?v=true&s=component&h=name,component,version,description name component version description es01 analysis-icu 8.12.2 The ICU Analysis plugin integrates the Lucene ICU module into Elastics…

---

## [o.e.d.HandshakingTransportAddressConnector](https://discuss.elastic.co/t/o-e-d-handshakingtransportaddressconnector/364855)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 0\
**Last updated:** [August 13, 2024, 6:55pm UTC](https://discuss.elastic.co/t/o-e-d-handshakingtransportaddressconnector/364855 "2024-08-13T18:55:56Z")

</div>

\[WARN \]\[o.e.d.HandshakingTransportAddressConnector\] \[localhost.localdomain\] handshake to \[127.0.0.1:9300\] failed org.elasticsearch.transport.RemoteTransportException: \[localhost.localdomain\]\[127.0.0.1:9300\]\[internal:tra…

---

## [Regarding the error message when clicking the Validate Repository button in Elasticsearch snapshot function](https://discuss.elastic.co/t/regarding-the-error-message-when-clicking-the-validate-repository-button-in-elasticsearch-snapshot-function/363333)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 4\
**Last updated:** [August 13, 2024, 6:11pm UTC](https://discuss.elastic.co/t/regarding-the-error-message-when-clicking-the-validate-repository-button-in-elasticsearch-snapshot-function/363333 "2024-08-13T18:11:14Z")

</div>

Hello from Japan I have a question for all the dear Elastic engineers I want to use the snapshot function to save a snapshot on one node in a cluster. \*I have configured a cluster of three Elasticsearch machines. I h…

---

## [Elatic Search Index ILM Policies comfigs](https://discuss.elastic.co/t/elatic-search-index-ilm-policies-comfigs/364837)

<div class="topic-metadata">

**Author:** [@RAVI\_GOPALANI](https://discuss.elastic.co/u/RAVI_GOPALANI)\
**Replies:** 3\
**Last updated:** [August 13, 2024, 5:34pm UTC](https://discuss.elastic.co/t/elatic-search-index-ilm-policies-comfigs/364837 "2024-08-13T17:34:45Z")

</div>

Hi Elastic search team, We want implement hot, cold , warm tier in index ILM. So, we know how ro define cofigs but how we can map those tier with storage Lets say hot tier keep index data for initially 30 days with sto…

---

## [Oracle JDK vulnerability updates](https://discuss.elastic.co/t/oracle-jdk-vulnerability-updates/364846)

<div class="topic-metadata">

**Author:** [@kamalhus123](https://discuss.elastic.co/u/kamalhus123)\
**Replies:** 1\
**Last updated:** [August 13, 2024, 5:30pm UTC](https://discuss.elastic.co/t/oracle-jdk-vulnerability-updates/364846 "2024-08-13T17:30:42Z")

</div>

We have an installed version of Elasticseach which is currently showing a vulnerability identified by Nessus scans identified back on July 2024. Specifically, these are the identified vulnerabilities: CVE-2024-21131,CVE…

---

## [Bucket Selector with Top Hits aggregation](https://discuss.elastic.co/t/bucket-selector-with-top-hits-aggregation/364847)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [August 13, 2024, 4:24pm UTC](https://discuss.elastic.co/t/bucket-selector-with-top-hits-aggregation/364847 "2024-08-13T16:24:24Z")

</div>

Hello, I have this query that is aggregates with top hits to retrieve the last doc. I want to use the bucket selector to filter for buckets that match a source field, event.outcome: "failure". I am struggling with the…

---

## [Let's encrypt](https://discuss.elastic.co/t/lets-encrypt/364805)

<div class="topic-metadata">

**Author:** [@Honestabe](https://discuss.elastic.co/u/Honestabe)\
**Replies:** 2\
**Last updated:** [August 13, 2024, 4:13pm UTC](https://discuss.elastic.co/t/lets-encrypt/364805 "2024-08-13T16:13:31Z")

</div>

i have it working with kibana but cant seem to get it to work with my elastic cluster. I succesfuly mounted the share to my wildcard cert and I symlinked the privetkey.pem and fullchain .pem. i used xpack.security.http…

---

## [Question about FSCrawler releases and changelog](https://discuss.elastic.co/t/question-about-fscrawler-releases-and-changelog/364830)

<div class="topic-metadata">

**Author:** [@lengoyvaerts](https://discuss.elastic.co/u/lengoyvaerts)\
**Replies:** 3\
**Last updated:** [August 13, 2024, 2:14pm UTC](https://discuss.elastic.co/t/question-about-fscrawler-releases-and-changelog/364830 "2024-08-13T14:14:53Z")

</div>

First of all, thanks for providing the FSCrawler. Regarding releases and changelog, I was wondering if there is a plan to "officially" release 2.10, and maybe maintaining some kind of release schedule (with major, minor…

---

## [FSCrawler question about password protected Word documents](https://discuss.elastic.co/t/fscrawler-question-about-password-protected-word-documents/359590)

<div class="topic-metadata">

**Author:** [@lengoyvaerts](https://discuss.elastic.co/u/lengoyvaerts)\
**Replies:** 6\
**Last updated:** [August 13, 2024, 12:59pm UTC](https://discuss.elastic.co/t/fscrawler-question-about-password-protected-word-documents/359590 "2024-08-13T12:59:15Z")

</div>

I have a question about the fscrawler Is it possible to crawl password protected Word documents? I came upon this issue on the Github repository, but It doesn't provide much insight outside of a single unit test. I don'…

---

## [The elasticsearch cluster often turns red,marking and sending shard failed due to \[failed to create shard\]](https://discuss.elastic.co/t/the-elasticsearch-cluster-often-turns-red-marking-and-sending-shard-failed-due-to-failed-to-create-shard/364759)

<div class="topic-metadata">

**Author:** [@xiaxiantao](https://discuss.elastic.co/u/xiaxiantao)\
**Replies:** 9\
**Last updated:** [August 13, 2024, 10:34am UTC](https://discuss.elastic.co/t/the-elasticsearch-cluster-often-turns-red-marking-and-sending-shard-failed-due-to-failed-to-create-shard/364759 "2024-08-13T10:34:51Z")

</div>

continue with the previous issue on GitHub，I found that this problem mostly occurs on one index. An index often shows "failed to obtain in-memory shard lock", resulting in shard unassignment. Both primary and replica sha…

---

## [ES query slows down in high concurrency](https://discuss.elastic.co/t/es-query-slows-down-in-high-concurrency/363267)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [August 13, 2024, 8:31am UTC](https://discuss.elastic.co/t/es-query-slows-down-in-high-concurrency/363267 "2024-08-13T08:31:13Z")

</div>

We now have a large number of NetFlow records that need to be queried, with a data volume of 200,000 records/s. The query logic is to go to es to associate users based on time, aIp, start and end ports, and bIp. The spe…

---

## [Spikes in Indexing Speed in Elasticsearch](https://discuss.elastic.co/t/spikes-in-indexing-speed-in-elasticsearch/364204)

<div class="topic-metadata">

**Author:** [@Priyansh\_Maheshwari](https://discuss.elastic.co/u/Priyansh_Maheshwari)\
**Replies:** 1\
**Last updated:** [August 13, 2024, 8:18am UTC](https://discuss.elastic.co/t/spikes-in-indexing-speed-in-elasticsearch/364204 "2024-08-13T08:18:37Z")

</div>

Hi, for our application we are currently using a single node ES instance (planning to migrate to cluster in future). The average duration of pushing data from my Java based interface to ES server is around 10ms. However,…

---

## [Watcher execute OpenAPI definition](https://discuss.elastic.co/t/watcher-execute-openapi-definition/364228)

<div class="topic-metadata">

**Author:** [@Apolexian](https://discuss.elastic.co/u/Apolexian)\
**Replies:** 1\
**Last updated:** [August 13, 2024, 8:13am UTC](https://discuss.elastic.co/t/watcher-execute-openapi-definition/364228 "2024-08-13T08:13:46Z")

</div>

Hi, I was wondering if there is an OpenAPI definition for the watcher execute (Execute watch API | Elasticsearch Guide \[8.14\] | Elastic) API? The only spec I have found is the following: Which does not have the watch…

---

## [Unable to use automatic slicing in reindex API](https://discuss.elastic.co/t/unable-to-use-automatic-slicing-in-reindex-api/364378)

<div class="topic-metadata">

**Author:** [@abhadauria](https://discuss.elastic.co/u/abhadauria)\
**Replies:** 2\
**Last updated:** [August 13, 2024, 8:12am UTC](https://discuss.elastic.co/t/unable-to-use-automatic-slicing-in-reindex-api/364378 "2024-08-13T08:12:00Z")

</div>

We are re-indexing data in ES cluster using \_reindex API ES version 7.17. We want to leverage automated slicing to finish the process sooner as we have really large index with doc count ~150 million. We were following …

---

## [How to enforce datatypes in an Index](https://discuss.elastic.co/t/how-to-enforce-datatypes-in-an-index/364579)

<div class="topic-metadata">

**Author:** [@werto165](https://discuss.elastic.co/u/werto165)\
**Replies:** 1\
**Last updated:** [August 13, 2024, 8:09am UTC](https://discuss.elastic.co/t/how-to-enforce-datatypes-in-an-index/364579 "2024-08-13T08:09:09Z")

</div>

I have types that define my mappings, I am using the old client to create my mapping for the index. With this mapping I have set dynamic to "strict" which has allowed me to enforce that when passing an update for example…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=84)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=86)
