# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=9

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 10

---

## [Issues with mapping conflicts at scale](https://discuss.elastic.co/t/issues-with-mapping-conflicts-at-scale/384780)

<div class="topic-metadata">

**Author:** [@logalicious](https://discuss.elastic.co/u/logalicious)\
**Replies:** 2\
**Last updated:** [January 29, 2026, 4:59pm UTC](https://discuss.elastic.co/t/issues-with-mapping-conflicts-at-scale/384780 "2026-01-29T16:59:28Z")

</div>

We ingest data with Elastic’s integrations. What we have found over the years is that Elastic will release an integration and make changes to the field mappings over time. This is understandable, but we eventually run in…

---

## [Upgrade to 9x preparation: migrate watches](https://discuss.elastic.co/t/upgrade-to-9x-preparation-migrate-watches/384793)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 1\
**Last updated:** [January 29, 2026, 3:10pm UTC](https://discuss.elastic.co/t/upgrade-to-9x-preparation-migrate-watches/384793 "2026-01-29T15:10:21Z")

</div>

Hello I am going through the upgrade assistant on my QA cluster in preparation for the upgrade from 8.19.4 to 9.2.x The assistant marks the following index as critical block for the upgrade: .reindexed-v7-watches-6 T…

---

## [Upgrade from 8.19.1 to 9.2.3 failed because of .security-7 index](https://discuss.elastic.co/t/upgrade-from-8-19-1-to-9-2-3-failed-because-of-security-7-index/384755)

<div class="topic-metadata">

**Author:** [@Balait4](https://discuss.elastic.co/u/Balait4)\
**Replies:** 5\
**Last updated:** [January 29, 2026, 1:48pm UTC](https://discuss.elastic.co/t/upgrade-from-8-19-1-to-9-2-3-failed-because-of-security-7-index/384755 "2026-01-29T13:48:42Z")

</div>

Hi, I upgrade the cluster from 7.16.1 to 8.19.1 as per the upgrade guide. The kibana ugprade assistant did’t report anything. Now I’m upgrading to version 9.2.3 where getting the below issue for security index. The inde…

---

## [Maximum Scroll Context](https://discuss.elastic.co/t/maximum-scroll-context/384754)

<div class="topic-metadata">

**Author:** [@Lakshya\_Gupta](https://discuss.elastic.co/u/Lakshya_Gupta)\
**Replies:** 5\
**Last updated:** [January 29, 2026, 1:07pm UTC](https://discuss.elastic.co/t/maximum-scroll-context/384754 "2026-01-29T13:07:35Z")

</div>

Hi guys, I was wondering that the maximum scroll context is a node level property across all the indices right? If that’s true, then does it mean that any elastic cluster wherein let’s assume number of primary shards = n…

---

## [Error dialing x509: certificate signed by unknown authority Kubernetes integration](https://discuss.elastic.co/t/error-dialing-x509-certificate-signed-by-unknown-authority-kubernetes-integration/370859)

<div class="topic-metadata">

**Author:** [@clockard](https://discuss.elastic.co/u/clockard)\
**Replies:** 11\
**Last updated:** [January 29, 2026, 1:49am UTC](https://discuss.elastic.co/t/error-dialing-x509-certificate-signed-by-unknown-authority-kubernetes-integration/370859 "2026-01-29T01:49:56Z")

</div>

I know there is allot on info about this, but I'm not grokking what needs to be done. The agents for the integration with kubernetes deploys in the kube-system namespace. i am using the quickstart fyi. What do i need to…

---

## [There is insufficient memory for the Java Runtime Environment to continue](https://discuss.elastic.co/t/there-is-insufficient-memory-for-the-java-runtime-environment-to-continue/383614)

<div class="topic-metadata">

**Author:** [@Aysel\_Guliyeva](https://discuss.elastic.co/u/Aysel_Guliyeva)\
**Replies:** 45\
**Last updated:** [January 28, 2026, 8:50pm UTC](https://discuss.elastic.co/t/there-is-insufficient-memory-for-the-java-runtime-environment-to-continue/383614 "2026-01-28T20:50:23Z")

</div>

Hello. I need help. In our system, there are 8 data nodes. And my Elasticsearch VM RAM is 16GB. Normally, Elasticsearch data nodes use 60-65% of RAM. I check via the command “top” on Ubuntu. Unfourtunately, once in a mo…

---

## [Need help in understanding architecture of cloud hosted and cloud serverless](https://discuss.elastic.co/t/need-help-in-understanding-architecture-of-cloud-hosted-and-cloud-serverless/384773)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 2\
**Last updated:** [January 28, 2026, 3:43pm UTC](https://discuss.elastic.co/t/need-help-in-understanding-architecture-of-cloud-hosted-and-cloud-serverless/384773 "2026-01-28T15:43:45Z")

</div>

hello everyone ! i have just started my journey with elastic and i have some question which i am not able to understand through documentation Que. briefly explain dif in architecture of cloud hosted and cloud serverles…

---

## [How to migrate Milvus data to Elasticsearch](https://discuss.elastic.co/t/how-to-migrate-milvus-data-to-elasticsearch/384775)

<div class="topic-metadata">

**Author:** [@midon\_king](https://discuss.elastic.co/u/midon_king)\
**Replies:** 1\
**Last updated:** [January 28, 2026, 3:32pm UTC](https://discuss.elastic.co/t/how-to-migrate-milvus-data-to-elasticsearch/384775 "2026-01-28T15:32:54Z")

</div>

I have a Milvus cluster. Now I want to transfer all the data within this Milvus cluster to Elasticsearch. What steps need to be taken for this? Are there any available migration tools or solutions that can be used?

---

## [Upgrading kibana from 8.18.4 to 8.19.4](https://discuss.elastic.co/t/upgrading-kibana-from-8-18-4-to-8-19-4/384668)

<div class="topic-metadata">

**Author:** [@Anjali3](https://discuss.elastic.co/u/Anjali3)\
**Replies:** 4\
**Last updated:** [January 28, 2026, 10:50am UTC](https://discuss.elastic.co/t/upgrading-kibana-from-8-18-4-to-8-19-4/384668 "2026-01-28T10:50:01Z")

</div>

Hi Team, Need quick help! I am upgrading elasticsearch from 8.18.4 to 8.19.4 but getting below errors: at org.elasticsearch.server.cli.JvmOption.flagsFinal(JvmOption.java:125) at org.elasticsearch.server.cli.JvmOption.…

---

## [Elasticsearch discovery seed\_hosts](https://discuss.elastic.co/t/elasticsearch-discovery-seed-hosts/384733)

<div class="topic-metadata">

**Author:** [@varun\_vetrivendan](https://discuss.elastic.co/u/varun_vetrivendan)\
**Replies:** 4\
**Last updated:** [January 26, 2026, 2:15pm UTC](https://discuss.elastic.co/t/elasticsearch-discovery-seed-hosts/384733 "2026-01-26T14:15:05Z")

</div>

The Current Master ensures that the cluster state is present in all the nodes inclusive of the data nodes. Which means the datanodes know the cluster state and who the current master is and which nodes are master eligibl…

---

## [Recoverability from node replacement on a 2-node cluster](https://discuss.elastic.co/t/recoverability-from-node-replacement-on-a-2-node-cluster/384685)

<div class="topic-metadata">

**Author:** [@crazyzhou](https://discuss.elastic.co/u/crazyzhou)\
**Replies:** 3\
**Last updated:** [January 26, 2026, 10:32am UTC](https://discuss.elastic.co/t/recoverability-from-node-replacement-on-a-2-node-cluster/384685 "2026-01-26T10:32:57Z")

</div>

We are using eck-operator and running Elasticsearch cluster on Kubernetes. We have a 3 master-eligible nodes and several worker nodes in the cluster. In the case for running the cluster on 2 physical nodes, if a node go…

---

## [Where can I find Dutch word lists](https://discuss.elastic.co/t/where-can-i-find-dutch-word-lists/384649)

<div class="topic-metadata">

**Author:** [@jberkvens](https://discuss.elastic.co/u/jberkvens)\
**Replies:** 1\
**Last updated:** [January 25, 2026, 2:39am UTC](https://discuss.elastic.co/t/where-can-i-find-dutch-word-lists/384649 "2026-01-25T02:39:20Z")

</div>

I’m trying to make my pages searchable by indexing the page contents in Elasticsearch, but currently it can’t find a page that talks about “koffiekopjes” when I search for “koffie” (Dutch compound words). I found this ar…

---

## [Date\_histogram supports 1M, 1Y but not 3M or 6M. Any ways to achieve the same](https://discuss.elastic.co/t/date-histogram-supports-1m-1y-but-not-3m-or-6m-any-ways-to-achieve-the-same/384687)

<div class="topic-metadata">

**Author:** [@mike123](https://discuss.elastic.co/u/mike123)\
**Replies:** 1\
**Last updated:** [January 22, 2026, 7:53am UTC](https://discuss.elastic.co/t/date-histogram-supports-1m-1y-but-not-3m-or-6m-any-ways-to-achieve-the-same/384687 "2026-01-22T07:53:09Z")

</div>

3M or 3Y cannot be achieved using fixed interval. While calendar interval only supports 1M, 1Y. Is there any ways to achieve date histogram over 3M or 6M.

---

## [FSCrawler 2.10-SNAPSHOT not indexing PDF content](https://discuss.elastic.co/t/fscrawler-2-10-snapshot-not-indexing-pdf-content/384593)

<div class="topic-metadata">

**Author:** [@DaManDOH](https://discuss.elastic.co/u/DaManDOH)\
**Replies:** 11\
**Last updated:** [January 22, 2026, 12:33am UTC](https://discuss.elastic.co/t/fscrawler-2-10-snapshot-not-indexing-pdf-content/384593 "2026-01-22T00:33:45Z")

</div>

TL;DR: Under a full ES v9.2 stack running under Docker Compose, FSCrawler v2.10-SNAPSHOT only returns TesseractOCRParser timeout errors when trying to ingest any PDFs. Full details I’m currently building a local Elasti…

---

## [Elasticsearch RAG - AI Playground - fix needed](https://discuss.elastic.co/t/elasticsearch-rag-ai-playground-fix-needed/384671)

<div class="topic-metadata">

**Author:** [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Replies:** 0\
**Last updated:** [January 21, 2026, 12:18pm UTC](https://discuss.elastic.co/t/elasticsearch-rag-ai-playground-fix-needed/384671 "2026-01-21T12:18:46Z")

</div>

Hello guys, Thanks for sharing this amazing Elasticsearch RAG playground. It’s well prepared and easy to follow the instructions. There is a small bug in the last step, Export code =\> Install code dependencies part. The…

---

## [Using ignore\_malformed in dynamic template doesn't seems to work](https://discuss.elastic.co/t/using-ignore-malformed-in-dynamic-template-doesnt-seems-to-work/384647)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 1\
**Last updated:** [January 20, 2026, 5:40pm UTC](https://discuss.elastic.co/t/using-ignore-malformed-in-dynamic-template-doesnt-seems-to-work/384647 "2026-01-20T17:40:49Z")

</div>

Dear Community! I’m having a strange problem while trying to implement ignore\_malformed to avoid documents being dropped when a field contains invalid data. From my Logstash logs, I often see messages like this: \[...\]…

---

## [Entitlements and tmpdir](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627)

<div class="topic-metadata">

**Author:** [@frantz45](https://discuss.elastic.co/u/frantz45)\
**Replies:** 4\
**Last updated:** [January 20, 2026, 3:02pm UTC](https://discuss.elastic.co/t/entitlements-and-tmpdir/384627 "2026-01-20T15:02:29Z")

</div>

Hello, I’ve just tried v8.19.10 and I get an issue with entitlements: \[2026-01-19T17:13:13,437\]\[ERROR\]\[o.e.b.Elasticsearch \] \[redacted\] fatal exception while booting Elasticsearch java.lang.IllegalArgumentExceptio…

---

## [Primary shards for search](https://discuss.elastic.co/t/primary-shards-for-search/384310)

<div class="topic-metadata">

**Author:** [@Elastic04](https://discuss.elastic.co/u/Elastic04)\
**Replies:** 10\
**Last updated:** [January 20, 2026, 5:56am UTC](https://discuss.elastic.co/t/primary-shards-for-search/384310 "2026-01-20T05:56:30Z")

</div>

I a currently using 3 primary shards and 2 replica shards. How reducing number of primary shards affects search and what’s the impact on cluster?

---

## [Unexpected high memory usage in Elasticsearch cluster – looking for optimization advice](https://discuss.elastic.co/t/unexpected-high-memory-usage-in-elasticsearch-cluster-looking-for-optimization-advice/384629)

<div class="topic-metadata">

**Author:** [@jimmykalru](https://discuss.elastic.co/u/jimmykalru)\
**Replies:** 1\
**Last updated:** [January 19, 2026, 5:55pm UTC](https://discuss.elastic.co/t/unexpected-high-memory-usage-in-elasticsearch-cluster-looking-for-optimization-advice/384629 "2026-01-19T17:55:39Z")

</div>

I’m running an Elasticsearch cluster in a production environment and recently noticed consistently high memory usage across all data nodes. Even during periods of low query activity, heap usage remains elevated and occas…

---

## [How to see status of enhancement requests?](https://discuss.elastic.co/t/how-to-see-status-of-enhancement-requests/384601)

<div class="topic-metadata">

**Author:** [@mistrhanky1](https://discuss.elastic.co/u/mistrhanky1)\
**Replies:** 1\
**Last updated:** [January 19, 2026, 2:43pm UTC](https://discuss.elastic.co/t/how-to-see-status-of-enhancement-requests/384601 "2026-01-19T14:43:03Z")

</div>

I have a few enhancement requests filed through elastic support. How can I find the status of these requests? I am sure there is a searchable place to see this, likely in github, but it did not stand out to me. As a fo…

---

## [Watcher chain results not in the ctx.payload for a condition](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574)

<div class="topic-metadata">

**Author:** [@Joey\_Visbeen](https://discuss.elastic.co/u/Joey_Visbeen)\
**Replies:** 2\
**Last updated:** [January 19, 2026, 9:50am UTC](https://discuss.elastic.co/t/watcher-chain-results-not-in-the-ctx-payload-for-a-condition/384574 "2026-01-19T09:50:01Z")

</div>

Lately I ran into an issue I am trying to make a watcher. The main purpose is to see if the elastic agents we are running are still producing logs. The agents run on different hosts, therefore the query on the host names…

---

## [TRANSFORM Destination index is not using Index Template](https://discuss.elastic.co/t/transform-destination-index-is-not-using-index-template/384611)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 1\
**Last updated:** [January 19, 2026, 7:29am UTC](https://discuss.elastic.co/t/transform-destination-index-is-not-using-index-template/384611 "2026-01-19T07:29:20Z")

</div>

Hello Team, We are using Elasticsearch 7.8.0 version. I understand its very old \[ w are in process of upgradation too \] While using TRANSFORM feature , I am finding that my destination index is not using template sett…

---

## [Advices & opinions on my Wazuh-Elastic Stack SIEM](https://discuss.elastic.co/t/advices-opinions-on-my-wazuh-elastic-stack-siem/384567)

<div class="topic-metadata">

**Author:** [@Ken\_1](https://discuss.elastic.co/u/Ken_1)\
**Replies:** 0\
**Last updated:** [January 15, 2026, 9:18pm UTC](https://discuss.elastic.co/t/advices-opinions-on-my-wazuh-elastic-stack-siem/384567 "2026-01-15T21:18:30Z")

</div>

Hello everyone, I want to build an open-source SIEM solution using Wazuh and the Elastic Stack to monitor roughly 300 hosts (Linux servers, firewalls, switches, Windows servers, Linux hosts, and Windows hosts). I’d appr…

---

## [Gmail oauth disabled](https://discuss.elastic.co/t/gmail-oauth-disabled/384565)

<div class="topic-metadata">

**Author:** [@Jaydeep\_Rathore1](https://discuss.elastic.co/u/Jaydeep_Rathore1)\
**Replies:** 0\
**Last updated:** [January 15, 2026, 6:29pm UTC](https://discuss.elastic.co/t/gmail-oauth-disabled/384565 "2026-01-15T18:29:37Z")

</div>

my gmail account was disabled by google, and i used to login using oauth only. now i dont have access to my gmail, and i am not able to login to elastic cloud console. any idea what i should do? there is not chance of ge…

---

## [Question about the implementation principle of post-filtering query for sparse vectors](https://discuss.elastic.co/t/question-about-the-implementation-principle-of-post-filtering-query-for-sparse-vectors/384540)

<div class="topic-metadata">

**Author:** [@Ningsir](https://discuss.elastic.co/u/Ningsir)\
**Replies:** 1\
**Last updated:** [January 14, 2026, 4:25pm UTC](https://discuss.elastic.co/t/question-about-the-implementation-principle-of-post-filtering-query-for-sparse-vectors/384540 "2026-01-14T16:25:21Z")

</div>

For the implementation of sparse vector post filtering, is it to query all results and then perform post filtering, or to query k results and then perform post filtering. { "query": { "bool": { "must": \[{"sp…

---

## [High CPU Usage on a few data nodes / Hotspotting of data](https://discuss.elastic.co/t/high-cpu-usage-on-a-few-data-nodes-hotspotting-of-data/383954)

<div class="topic-metadata">

**Author:** [@Lakshya\_Gupta](https://discuss.elastic.co/u/Lakshya_Gupta)\
**Replies:** 191\
**Last updated:** [January 14, 2026, 6:48am UTC](https://discuss.elastic.co/t/high-cpu-usage-on-a-few-data-nodes-hotspotting-of-data/383954 "2026-01-14T06:48:45Z")

</div>

Hi team, we have an Elastic Search Cluster with the following configurations ES Version 7.17.0 60 data nodes cluster 50 primary shards and 2 replica for each primary shards Here, we are using a particular custom routi…

---

## [How to measure daily log volume (count and size) in Elasticsearch?](https://discuss.elastic.co/t/how-to-measure-daily-log-volume-count-and-size-in-elasticsearch/384485)

<div class="topic-metadata">

**Author:** [@gueguet57](https://discuss.elastic.co/u/gueguet57)\
**Replies:** 3\
**Last updated:** [January 13, 2026, 3:30pm UTC](https://discuss.elastic.co/t/how-to-measure-daily-log-volume-count-and-size-in-elasticsearch/384485 "2026-01-13T15:30:00Z")

</div>

Hi Elastic community, I’m looking for a reliable way to track the amount of logs we are receiving in our Elasticsearch/ELK stack on a daily basis. Specifically, I’d like to know: The number of logs ingested per day. …

---

## [Elastic Netflow integration (discrepancies with Nfsen)](https://discuss.elastic.co/t/elastic-netflow-integration-discrepancies-with-nfsen/384502)

<div class="topic-metadata">

**Author:** [@duckasylum](https://discuss.elastic.co/u/duckasylum)\
**Replies:** 0\
**Last updated:** [January 13, 2026, 10:59am UTC](https://discuss.elastic.co/t/elastic-netflow-integration-discrepancies-with-nfsen/384502 "2026-01-13T10:59:04Z")

</div>

I have a few Netflow collectors running pmacctd to collect netflow traffic. I send v9 to Nfsen and v10 (IPFIX) to an elastic agent with a configured netflow integration. My problem is that Nfsen shows close to 10 times m…

---

## [Create custom token filter](https://discuss.elastic.co/t/create-custom-token-filter/384497)

<div class="topic-metadata">

**Author:** [@sginer](https://discuss.elastic.co/u/sginer)\
**Replies:** 0\
**Last updated:** [January 13, 2026, 8:34am UTC](https://discuss.elastic.co/t/create-custom-token-filter/384497 "2026-01-13T08:34:08Z")

</div>

Elasticsearch version : 8.19.9 Elasticsearch version : 9.2.2 Hello, I try to create a custom TokenFilter who is able to cypher index content. I create the class who cypher tokens and extends TokenFilter class and I…

---

## [Elasticsearch Java Client throws Exception when deserialize hotThreads response](https://discuss.elastic.co/t/elasticsearch-java-client-throws-exception-when-deserialize-hotthreads-response/365144)

<div class="topic-metadata">

**Author:** [@corojoon93](https://discuss.elastic.co/u/corojoon93)\
**Replies:** 5\
**Last updated:** [January 12, 2026, 2:13pm UTC](https://discuss.elastic.co/t/elasticsearch-java-client-throws-exception-when-deserialize-hotthreads-response/365144 "2026-01-12T14:13:16Z")

</div>

I used "co.elastic.clients:elasticsearch-java:8.15.0", "org.springframework.boot:3.2.7" And this is my Java code. @Service @RequiredArgsConstructor public class NodeHealthService { private final ElasticsearchClien…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=8)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=10)
