# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=94

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 95

---

## [Node not able to be a master node in case elastic search service stopped on another master node](https://discuss.elastic.co/t/node-not-able-to-be-a-master-node-in-case-elastic-search-service-stopped-on-another-master-node/363255)

<div class="topic-metadata">

**Author:** [@Bipindra.1.s](https://discuss.elastic.co/u/Bipindra.1.s)\
**Replies:** 1\
**Last updated:** [July 17, 2024, 7:07am UTC](https://discuss.elastic.co/t/node-not-able-to-be-a-master-node-in-case-elastic-search-service-stopped-on-another-master-node/363255 "2024-07-17T07:07:37Z")

</div>

For a poc purpose we have created a 2 node Elasticsearch cluster on windows machines. Cluster is working fine when both nodes are running. To test failure scenario we stopped elasticSearch on one machine we are expectin…

---

## [Snapshot and Restore of an index](https://discuss.elastic.co/t/snapshot-and-restore-of-an-index/363253)

<div class="topic-metadata">

**Author:** [@abhadauria](https://discuss.elastic.co/u/abhadauria)\
**Replies:** 3\
**Last updated:** [July 17, 2024, 6:14am UTC](https://discuss.elastic.co/t/snapshot-and-restore-of-an-index/363253 "2024-07-17T06:14:19Z")

</div>

Hi Team, we want to upgrade the older version of index(6.x) to newer version(7.x) in the ES cluster with version 7.17. However the new index which is getting created as part of snapshot restore is getting created with ol…

---

## [Retrieve array sizein script](https://discuss.elastic.co/t/retrieve-array-sizein-script/363108)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 7\
**Last updated:** [July 16, 2024, 4:25pm UTC](https://discuss.elastic.co/t/retrieve-array-sizein-script/363108 "2024-07-16T16:25:11Z")

</div>

We are trying to execute a script :slight\_smile: "if (ctx.\_source.repliesList == null) {ctx.\_source.repliesList = new ArrayList();}" + "if(ctx.\_source.repliesList.size()\<10) { ctx.\_source.repliesList.add('" + proid + "'…

---

## [BULK API RFC - multi-objects POST](https://discuss.elastic.co/t/bulk-api-rfc-multi-objects-post/363228)

<div class="topic-metadata">

**Author:** [@Adrien\_WATTEZ](https://discuss.elastic.co/u/Adrien_WATTEZ)\
**Replies:** 1\
**Last updated:** [July 16, 2024, 3:42pm UTC](https://discuss.elastic.co/t/bulk-api-rfc-multi-objects-post/363228 "2024-07-16T15:42:46Z")

</div>

Hi Elastic Community, I am currently exploring the Bulk API and seeking some clarification and guidance regarding the submission of multiple objects in a single REST POST request. Specifically, I have the following ques…

---

## [Elasticsearch: Slow query with min\_doc\_count=0 on field aggregation](https://discuss.elastic.co/t/elasticsearch-slow-query-with-min-doc-count-0-on-field-aggregation/363158)

<div class="topic-metadata">

**Author:** [@fherenius](https://discuss.elastic.co/u/fherenius)\
**Replies:** 8\
**Last updated:** [July 16, 2024, 1:43pm UTC](https://discuss.elastic.co/t/elasticsearch-slow-query-with-min-doc-count-0-on-field-aggregation/363158 "2024-07-16T13:43:10Z")

</div>

For more background, see the previous topic on this issue: Elasticsearch queue issue after upgrading from 8.6.2 to 8.12.1/8.12.2 - #2 by Amos66 Specifically the replies by Amos66. As described in the linked post, the q…

---

## [Elasticsearch networking with Podman](https://discuss.elastic.co/t/elasticsearch-networking-with-podman/362979)

<div class="topic-metadata">

**Author:** [@Mason\_Keresty](https://discuss.elastic.co/u/Mason_Keresty)\
**Replies:** 4\
**Last updated:** [July 16, 2024, 12:56pm UTC](https://discuss.elastic.co/t/elasticsearch-networking-with-podman/362979 "2024-07-16T12:56:26Z")

</div>

Hello, Summary: I'm having some errors creating an elasticsearch cluster across multiple servers. Setup: 2 rhel8 ec2 instances running elasticsearch 8.5 in podman containers docker-compose.yml on server A: es03: …

---

## [When Starting Data Frame, there is an error](https://discuss.elastic.co/t/when-starting-data-frame-there-is-an-error/363129)

<div class="topic-metadata">

**Author:** [@Muqali\_He](https://discuss.elastic.co/u/Muqali_He)\
**Replies:** 3\
**Last updated:** [July 16, 2024, 9:23am UTC](https://discuss.elastic.co/t/when-starting-data-frame-there-is-an-error/363129 "2024-07-16T09:23:02Z")

</div>

My Elasticsearch is 7.8. I can create a data frame job. but when I start it, I got the error "{"error":{"root\_cause":\[{"type":"exception","reason":"Failed to launch data frame analytics memory usage estimation process fo…

---

## [Downsample again time series metrics](https://discuss.elastic.co/t/downsample-again-time-series-metrics/363204)

<div class="topic-metadata">

**Author:** [@nekirc](https://discuss.elastic.co/u/nekirc)\
**Replies:** 0\
**Last updated:** [July 16, 2024, 8:49am UTC](https://discuss.elastic.co/t/downsample-again-time-series-metrics/363204 "2024-07-16T08:49:47Z")

</div>

Hi, I would like to know if there is a chance to downsample downsampled time series data (metrics). I have set ILM policy to downsample data every 2 minutes after 1 day which is fine and it works. Additionally, set an…

---

## [Repository\_verification\_exception](https://discuss.elastic.co/t/repository-verification-exception/363174)

<div class="topic-metadata">

**Author:** [@Naresh\_Kumar1](https://discuss.elastic.co/u/Naresh_Kumar1)\
**Replies:** 3\
**Last updated:** [July 16, 2024, 5:28am UTC](https://discuss.elastic.co/t/repository-verification-exception/363174 "2024-07-16T05:28:57Z")

</div>

I am using ES 8.13.4 in the EKS cluster, On the daily snapshot we are getting snapshot exceptions like connection pool shutdown. What was the reason behind this it was working fine suddenly without any changes we are get…

---

## [Java.lang.IllegalArgumentException with environment variable placeholder](https://discuss.elastic.co/t/java-lang-illegalargumentexception-with-environment-variable-placeholder/362901)

<div class="topic-metadata">

**Author:** [@EAC](https://discuss.elastic.co/u/EAC)\
**Replies:** 4\
**Last updated:** [July 15, 2024, 5:46pm UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-with-environment-variable-placeholder/362901 "2024-07-15T17:46:40Z")

</div>

Context of environment: Newbee engaged with the learning and building of a current-version single node elasticsearch-kibana-logstash stack with manually configured security, within a current virtual Ubuntu machine. Cont…

---

## [Identify the difference in data for two successive days](https://discuss.elastic.co/t/identify-the-difference-in-data-for-two-successive-days/363131)

<div class="topic-metadata">

**Author:** [@lshmikanth](https://discuss.elastic.co/u/lshmikanth)\
**Replies:** 2\
**Last updated:** [July 15, 2024, 3:53pm UTC](https://discuss.elastic.co/t/identify-the-difference-in-data-for-two-successive-days/363131 "2024-07-15T15:53:10Z")

</div>

I have a query which gives the tabular data on the key value pairs. I want to analyse the same query for two successive days and find out the new additions or deletions from the key values in the table. Any option avail…

---

## [Java client 7.6.2 socket timeout seems has problem](https://discuss.elastic.co/t/java-client-7-6-2-socket-timeout-seems-has-problem/362460)

<div class="topic-metadata">

**Author:** [@renhongchao](https://discuss.elastic.co/u/renhongchao)\
**Replies:** 4\
**Last updated:** [July 15, 2024, 3:39pm UTC](https://discuss.elastic.co/t/java-client-7-6-2-socket-timeout-seems-has-problem/362460 "2024-07-15T15:39:22Z")

</div>

RestClientBuilder builder = RestClient.builder(httpHostArray) .setRequestConfigCallback(requestConfigBuilder -\> requestConfigBuilder .setConnectTimeout(connectTimeout) …

---

## [Grok patter is not parsing multiline log](https://discuss.elastic.co/t/grok-patter-is-not-parsing-multiline-log/363164)

<div class="topic-metadata">

**Author:** [@Nitesh\_Singhal](https://discuss.elastic.co/u/Nitesh_Singhal)\
**Replies:** 0\
**Last updated:** [July 15, 2024, 3:15pm UTC](https://discuss.elastic.co/t/grok-patter-is-not-parsing-multiline-log/363164 "2024-07-15T15:15:31Z")

</div>

Hi, I have a log line in multiline pattern and my grok parser is only parsing one line of the log and ignoring the others. How this can be fixed to include the complete message? filebeat.inputs: - type: log enabled: t…

---

## [Duplicate data](https://discuss.elastic.co/t/duplicate-data/363091)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 3\
**Last updated:** [July 15, 2024, 2:58pm UTC](https://discuss.elastic.co/t/duplicate-data/363091 "2024-07-15T14:58:53Z")

</div>

I have an indicator with duplicate data I want to delete this duplicate data and keep only one and the rest of the duplicates are deleted I want to do this operation periodically What is the best practice to do this? P…

---

## [Ignore\_malformed within an object](https://discuss.elastic.co/t/ignore-malformed-within-an-object/363147)

<div class="topic-metadata">

**Author:** [@TiredPanda](https://discuss.elastic.co/u/TiredPanda)\
**Replies:** 2\
**Last updated:** [July 15, 2024, 1:37pm UTC](https://discuss.elastic.co/t/ignore-malformed-within-an-object/363147 "2024-07-15T13:37:53Z")

</div>

Hi, can anyone provide confirmation or clarification if using ignore\_malformed on a property within an object is supported. The docs say they are not supported on object types but does this extend to properties within t…

---

## [Getting exception "Timed out while waiting for a dynamic mapping update"](https://discuss.elastic.co/t/getting-exception-timed-out-while-waiting-for-a-dynamic-mapping-update/362719)

<div class="topic-metadata">

**Author:** [@sibasish.palo](https://discuss.elastic.co/u/sibasish.palo)\
**Replies:** 5\
**Last updated:** [July 15, 2024, 1:34pm UTC](https://discuss.elastic.co/t/getting-exception-timed-out-while-waiting-for-a-dynamic-mapping-update/362719 "2024-07-15T13:34:34Z")

</div>

Hi we have dynamic mappings for our indices, we are receiving below exception while bulk indexing using kafka-connect-elasticsearch plugin type: mapper\_exception, reason: timed out while waiting for a dynamic mapping u…

---

## [Syslog input to logstash time zone - drifts by 2h. everything set to UTC](https://discuss.elastic.co/t/syslog-input-to-logstash-time-zone-drifts-by-2h-everything-set-to-utc/362905)

<div class="topic-metadata">

**Author:** [@sliddjur](https://discuss.elastic.co/u/sliddjur)\
**Replies:** 4\
**Last updated:** [July 15, 2024, 1:32pm UTC](https://discuss.elastic.co/t/syslog-input-to-logstash-time-zone-drifts-by-2h-everything-set-to-utc/362905 "2024-07-15T13:32:03Z")

</div>

Debug stdout logstash | { logstash | "message" =\> "notice syslog-ng\[2219\]: Syslog connection established; fd='67', server='AF\_INET(10.6.10.93:5140)', local='AF\_INET(0.0.0.0:0)'\\n", logstash | "e…

---

## [Setting up password as env variable is not woking in openshift](https://discuss.elastic.co/t/setting-up-password-as-env-variable-is-not-woking-in-openshift/363045)

<div class="topic-metadata">

**Author:** [@Sohaib\_El\_Mediouni](https://discuss.elastic.co/u/Sohaib_El_Mediouni)\
**Replies:** 2\
**Last updated:** [July 15, 2024, 12:19pm UTC](https://discuss.elastic.co/t/setting-up-password-as-env-variable-is-not-woking-in-openshift/363045 "2024-07-15T12:19:32Z")

</div>

Hello, I'm trying to implement basic security for my elasticsearch in openshift using a statefulset. The problem I have encountered is that when I deploy my statefulset and try to test my elasticsearch, it gives me the …

---

## [HTTP Certificates when CA is a chain](https://discuss.elastic.co/t/http-certificates-when-ca-is-a-chain/362738)

<div class="topic-metadata">

**Author:** [@Nick5](https://discuss.elastic.co/u/Nick5)\
**Replies:** 12\
**Last updated:** [July 15, 2024, 8:22am UTC](https://discuss.elastic.co/t/http-certificates-when-ca-is-a-chain/362738 "2024-07-15T08:22:34Z")

</div>

I'm following the documentation here: Tutorial 2: Securing a self-managed Elastic Stack | Elastic Installation and Upgrade Guide \[8.14\] | Elastic and have got to Step 3. The CA I've exported from our Microsoft Enterpris…

---

## [ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already be part of a cluster and this auto setup utility is designed to configure Security for new clusters only](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only/362955)

<div class="topic-metadata">

**Author:** [@martianzz](https://discuss.elastic.co/u/martianzz)\
**Replies:** 4\
**Last updated:** [July 15, 2024, 9:35am UTC](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only/362955 "2024-07-15T09:35:52Z")

</div>

ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already be part of a cluster and this auto setup utility is designed to configure Securit…

---

## [How to get city,state, country using geoiplocation](https://discuss.elastic.co/t/how-to-get-city-state-country-using-geoiplocation/363128)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [July 15, 2024, 8:51am UTC](https://discuss.elastic.co/t/how-to-get-city-state-country-using-geoiplocation/363128 "2024-07-15T08:51:36Z")

</div>

Hi Team, I have CustomerGeoLocation field coming in document. Is there any way to get country, city , state. If I use geoip filter in source it will accept Ip. But in our case geolocation field is coming not Ip.

---

## [Internal Indexes replication settings best practices](https://discuss.elastic.co/t/internal-indexes-replication-settings-best-practices/363115)

<div class="topic-metadata">

**Author:** [@mkkkksim](https://discuss.elastic.co/u/mkkkksim)\
**Replies:** 0\
**Last updated:** [July 15, 2024, 3:22am UTC](https://discuss.elastic.co/t/internal-indexes-replication-settings-best-practices/363115 "2024-07-15T03:22:19Z")

</div>

Whats the best way to manage number\_of\_replicas index setting for indexes that are managed by Elasticsearch. Before we used legacy template that matches \* and sets number\_of\_replicas = 0. But since 8.14 version Data Stre…

---

## [Cold tiers and platinum/enterprise licencing](https://discuss.elastic.co/t/cold-tiers-and-platinum-enterprise-licencing/362870)

<div class="topic-metadata">

**Author:** [@cscott](https://discuss.elastic.co/u/cscott)\
**Replies:** 4\
**Last updated:** [July 14, 2024, 9:28pm UTC](https://discuss.elastic.co/t/cold-tiers-and-platinum-enterprise-licencing/362870 "2024-07-14T21:28:04Z")

</div>

Trying to get my head round tiering and platinum/enterprise licencing We're a FE college in the UK (very small budget) implementing Elastic Security as our SIEM, running on Elastic Cloud. Currently running a 2 zone ho…

---

## [Mappings (Ignore\_above)](https://discuss.elastic.co/t/mappings-ignore-above/363076)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 15\
**Last updated:** [July 14, 2024, 2:55pm UTC](https://discuss.elastic.co/t/mappings-ignore-above/363076 "2024-07-14T14:55:56Z")

</div>

I have a field with data of numbers, letters, symbols, and the length of this dystrophy is more than 255, and I want to use term to return the data accurately, but it does not return anything, and when I use match, it re…

---

## [Mapping Apache HTTPD log output to ECS Schema?](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082)

<div class="topic-metadata">

**Author:** [@greenbeans](https://discuss.elastic.co/u/greenbeans)\
**Replies:** 3\
**Last updated:** [July 14, 2024, 1:40am UTC](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082 "2024-07-14T01:40:54Z")

</div>

Has anyone mapped the various Apache HTTPD logging variables/output to the Elastic Common Schema? Seems like it should be pretty straightforward but tedious, and really useful. If you've done any of this, please share! …

---

## [Elasticsearch Scoring Documents to be able to fetch specific number of document per page](https://discuss.elastic.co/t/elasticsearch-scoring-documents-to-be-able-to-fetch-specific-number-of-document-per-page/363068)

<div class="topic-metadata">

**Author:** [@jahe.book](https://discuss.elastic.co/u/jahe.book)\
**Replies:** 2\
**Last updated:** [July 13, 2024, 7:18pm UTC](https://discuss.elastic.co/t/elasticsearch-scoring-documents-to-be-able-to-fetch-specific-number-of-document-per-page/363068 "2024-07-13T19:18:58Z")

</div>

I have an index as books, and the structure of the document is as follows: { "category\_ids": \[1,2,3\], "title": "Book Title", "description": "some long description", "entity\_type": "regular", //regular,featu…

---

## [Index Lifecycle Policies](https://discuss.elastic.co/t/index-lifecycle-policies/363069)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 5\
**Last updated:** [July 13, 2024, 3:14pm UTC](https://discuss.elastic.co/t/index-lifecycle-policies/363069 "2024-07-13T15:14:19Z")

</div>

How do I change the field value Maximum docs in the primary shard?

---

## [Is there a way to set in the config of the search provider which URL it should listen to to trigger the search](https://discuss.elastic.co/t/is-there-a-way-to-set-in-the-config-of-the-search-provider-which-url-it-should-listen-to-to-trigger-the-search/363074)

<div class="topic-metadata">

**Author:** [@kudumine](https://discuss.elastic.co/u/kudumine)\
**Replies:** 0\
**Last updated:** [July 13, 2024, 1:40pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-set-in-the-config-of-the-search-provider-which-url-it-should-listen-to-to-trigger-the-search/363074 "2024-07-13T13:40:23Z")

</div>

I have a frontend app using Elasticsearch UI, React, NextJS, and with a custom connector. Originally I had the search page on the root '/' and now I have a task to make a '/search' route instead. Is there a way to provi…

---

## [Unassaigned shards on .apm-agent-configuration](https://discuss.elastic.co/t/unassaigned-shards-on-apm-agent-configuration/363057)

<div class="topic-metadata">

**Author:** [@Milad\_Akhlaghi](https://discuss.elastic.co/u/Milad_Akhlaghi)\
**Replies:** 0\
**Last updated:** [July 12, 2024, 8:54pm UTC](https://discuss.elastic.co/t/unassaigned-shards-on-apm-agent-configuration/363057 "2024-07-12T20:54:29Z")

</div>

Hi , i have a strange problem there is .apm-agent-configuration unassigned shards when I use GET \_cat/shards and my cluster health is red ! but everything works fine! any idea how can I resolve it??

---

## [Error while running transform \`task encountered irrecoverable failure\`](https://discuss.elastic.co/t/error-while-running-transform-task-encountered-irrecoverable-failure/362479)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 5\
**Last updated:** [July 12, 2024, 4:05pm UTC](https://discuss.elastic.co/t/error-while-running-transform-task-encountered-irrecoverable-failure/362479 "2024-07-12T16:05:57Z")

</div>

Hey team, I'm running ELK 8.13 I have a transform that occasionally fails to run. If I restart it - the failure persists. If I recreate it - the error goes away for a few days and that returns. It fails with this er…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=93)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=95)
