# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=95

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 96

---

## [Manage the connection pool size in Java client](https://discuss.elastic.co/t/manage-the-connection-pool-size-in-java-client/362762)

<div class="topic-metadata">

**Author:** [@Priyansh\_Maheshwari](https://discuss.elastic.co/u/Priyansh_Maheshwari)\
**Replies:** 2\
**Last updated:** [July 12, 2024, 4:04pm UTC](https://discuss.elastic.co/t/manage-the-connection-pool-size-in-java-client/362762 "2024-07-12T16:04:42Z")

</div>

Hi, I am currently utilizing the ElasticsearchClient library in java for connecting to Elasticsearch. As per the docs the library manages its own connection pool and its not required to create a separate client with eac…

---

## [GeoIP - Elasticsearch](https://discuss.elastic.co/t/geoip-elasticsearch/363035)

<div class="topic-metadata">

**Author:** [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Replies:** 10\
**Last updated:** [July 12, 2024, 2:18pm UTC](https://discuss.elastic.co/t/geoip-elasticsearch/363035 "2024-07-12T14:18:55Z")

</div>

Hi: I have an Elasticsearch installed in Ubuntu. What are the proper steps to setup Geoip so that every time I ingest data it is enriched with geolocation data? Thanks

---

## [ERROR: Aborting enrolling to cluster. Could not communicate with the node on any of the addresses from the enrollment token. All of \[10.0.30.94:9200\] were attempted., with exit code 69](https://discuss.elastic.co/t/error-aborting-enrolling-to-cluster-could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrollment-token-all-of-10-0-30-94-9200-were-attempted-with-exit-code-69/363019)

<div class="topic-metadata">

**Author:** [@martianzz](https://discuss.elastic.co/u/martianzz)\
**Replies:** 0\
**Last updated:** [July 12, 2024, 10:17am UTC](https://discuss.elastic.co/t/error-aborting-enrolling-to-cluster-could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrollment-token-all-of-10-0-30-94-9200-were-attempted-with-exit-code-69/363019 "2024-07-12T10:17:51Z")

</div>

ERROR: Aborting enrolling to cluster. Could not communicate with the node on any of the addresses from the enrollment token. All of \[10.0.30.94:9200\] were attempted., with exit code 69. Please

---

## [Cannot build v8.4.2](https://discuss.elastic.co/t/cannot-build-v8-4-2/362985)

<div class="topic-metadata">

**Author:** [@sc-ahn](https://discuss.elastic.co/u/sc-ahn)\
**Replies:** 2\
**Last updated:** [July 12, 2024, 7:56am UTC](https://discuss.elastic.co/t/cannot-build-v8-4-2/362985 "2024-07-12T07:56:15Z")

</div>

wget https://github.com/elastic/elasticsearch/archive/refs/tags/v8.4.2.tar.gz tar -xvf v8.4.2.tar.gz cd elasticsearch-8.4.2 ... \[user001@host elasticsearch-8.4.2\]$ ./gradlew localDistro \> Task :build-tools:compileJava…

---

## [Aggregation result from search query into a field](https://discuss.elastic.co/t/aggregation-result-from-search-query-into-a-field/363000)

<div class="topic-metadata">

**Author:** [@Debatri\_Ash](https://discuss.elastic.co/u/Debatri_Ash)\
**Replies:** 0\
**Last updated:** [July 12, 2024, 7:12am UTC](https://discuss.elastic.co/t/aggregation-result-from-search-query-into-a-field/363000 "2024-07-12T07:12:56Z")

</div>

Is there a way to convert aggregation query result into a field in the index used for the aggregation? My aggregation query result gives me values under an array name w.r.t the values in a field which already exists in t…

---

## [Aggregation on IP arrays](https://discuss.elastic.co/t/aggregation-on-ip-arrays/362851)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 2\
**Last updated:** [July 12, 2024, 6:22am UTC](https://discuss.elastic.co/t/aggregation-on-ip-arrays/362851 "2024-07-12T06:22:28Z")

</div>

I have an index with a handful of docs. These docs contain an array "subnets" who's individual elements of of type IP. They contain individual IPs as well as subnets. Eg\> { ...., ...., subnets: \["192.168.0.0/24", "2…

---

## [Impact of frequency value for continuous transform](https://discuss.elastic.co/t/impact-of-frequency-value-for-continuous-transform/362903)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 3\
**Last updated:** [July 11, 2024, 10:25pm UTC](https://discuss.elastic.co/t/impact-of-frequency-value-for-continuous-transform/362903 "2024-07-11T22:25:28Z")

</div>

Hi, I created a continuous transform job to run once a day and calculate aggregations about communications with IPs and protocole/port. This is the skeleton of my transform { "source": { "index": \[ "my\_sou…

---

## [Number of requests to cloud during an incremental snapshot](https://discuss.elastic.co/t/number-of-requests-to-cloud-during-an-incremental-snapshot/362981)

<div class="topic-metadata">

**Author:** [@aditya.pingale](https://discuss.elastic.co/u/aditya.pingale)\
**Replies:** 0\
**Last updated:** [July 11, 2024, 8:00pm UTC](https://discuss.elastic.co/t/number-of-requests-to-cloud-during-an-incremental-snapshot/362981 "2024-07-11T20:00:31Z")

</div>

Hi, I am trying to setup a snapshot repository with AWS or google cloud. There is a tradeoff between cost for requests and storage cost. I wanted to know whether there is a way I could guess the amount of requests elast…

---

## [Difference of Sets in ES](https://discuss.elastic.co/t/difference-of-sets-in-es/362924)

<div class="topic-metadata">

**Author:** [@Jader\_Gonzalez](https://discuss.elastic.co/u/Jader_Gonzalez)\
**Replies:** 1\
**Last updated:** [July 11, 2024, 6:51pm UTC](https://discuss.elastic.co/t/difference-of-sets-in-es/362924 "2024-07-11T18:51:51Z")

</div>

I have experience working with SQL and am familiar with performing set differences using SQL. Although I understand that Elasticsearch (ES) operates differently, I believe there must be an efficient method for achieving …

---

## [Implement TTL for "dynamic" documents](https://discuss.elastic.co/t/implement-ttl-for-dynamic-documents/362822)

<div class="topic-metadata">

**Author:** [@timetolive](https://discuss.elastic.co/u/timetolive)\
**Replies:** 5\
**Last updated:** [July 11, 2024, 1:07pm UTC](https://discuss.elastic.co/t/implement-ttl-for-dynamic-documents/362822 "2024-07-11T13:07:31Z")

</div>

Current situation I have an Elasticsearch workflow equivalent to the following: I have tons of "animal sighting stations", each occasionally sending a "sighting event" of a specific animal species to the backend. The b…

---

## [How to send an SNMP trap to opennms when any node in the cluster has bad health?](https://discuss.elastic.co/t/how-to-send-an-snmp-trap-to-opennms-when-any-node-in-the-cluster-has-bad-health/362959)

<div class="topic-metadata">

**Author:** [@BOYO](https://discuss.elastic.co/u/BOYO)\
**Replies:** 0\
**Last updated:** [July 11, 2024, 12:28pm UTC](https://discuss.elastic.co/t/how-to-send-an-snmp-trap-to-opennms-when-any-node-in-the-cluster-has-bad-health/362959 "2024-07-11T12:28:25Z")

</div>

We want to monitor out elasticsearch cluster and send an snmp trap to opennms if the health of any node in the cluster becomes bad. Is there any way to integrate the two without implementing a custom module ?

---

## [Want to do partial match without using wildcards](https://discuss.elastic.co/t/want-to-do-partial-match-without-using-wildcards/362928)

<div class="topic-metadata">

**Author:** [@PratikStar](https://discuss.elastic.co/u/PratikStar)\
**Replies:** 5\
**Last updated:** [July 11, 2024, 10:33am UTC](https://discuss.elastic.co/t/want-to-do-partial-match-without-using-wildcards/362928 "2024-07-11T10:33:00Z")

</div>

I want to do a partial match on text fields (these fields include Japanese text data, but more on that later, I want to nail the core functionality correctly before going into Japanese.) without using wildcards. Here ar…

---

## [Is ECK operator is compatible with elastic-search version 8.10.3 on EKS?](https://discuss.elastic.co/t/is-eck-operator-is-compatible-with-elastic-search-version-8-10-3-on-eks/362882)

<div class="topic-metadata">

**Author:** [@Omar\_Khaled](https://discuss.elastic.co/u/Omar_Khaled)\
**Replies:** 1\
**Last updated:** [July 11, 2024, 10:04am UTC](https://discuss.elastic.co/t/is-eck-operator-is-compatible-with-elastic-search-version-8-10-3-on-eks/362882 "2024-07-11T10:04:47Z")

</div>

Is ECK operator is compatible with elastic-search version 8.10.3 on EKS? thanks for the support!

---

## [Tracking document updates and deletions with Audit Logging](https://discuss.elastic.co/t/tracking-document-updates-and-deletions-with-audit-logging/362931)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 0\
**Last updated:** [July 11, 2024, 7:10am UTC](https://discuss.elastic.co/t/tracking-document-updates-and-deletions-with-audit-logging/362931 "2024-07-11T07:10:32Z")

</div>

Hi, I would like to know if it is possible to use the audit logging feature in Elasticsearch to track when a user updates or deletes a document in a specific index. Specifically, I need to determine if there are records…

---

## [How do i show a list of last search value (a.k.a. recent picks) in my global search bar](https://discuss.elastic.co/t/how-do-i-show-a-list-of-last-search-value-a-k-a-recent-picks-in-my-global-search-bar/362833)

<div class="topic-metadata">

**Author:** [@9d224d4833094bd482cf](https://discuss.elastic.co/u/9d224d4833094bd482cf)\
**Replies:** 2\
**Last updated:** [July 11, 2024, 7:01am UTC](https://discuss.elastic.co/t/how-do-i-show-a-list-of-last-search-value-a-k-a-recent-picks-in-my-global-search-bar/362833 "2024-07-11T07:01:30Z")

</div>

I am developing global search bar in UI. We have 20 odd indices in elasticsearch and we search across those indices. I want to add one more feature called 'Recent Picks' which will list last search terms. What is a best …

---

## [7.10.0 elasticsearch period crash by stackoverflow](https://discuss.elastic.co/t/7-10-0-elasticsearch-period-crash-by-stackoverflow/362864)

<div class="topic-metadata">

**Author:** [@luye19870406](https://discuss.elastic.co/u/luye19870406)\
**Replies:** 2\
**Last updated:** [July 11, 2024, 5:28am UTC](https://discuss.elastic.co/t/7-10-0-elasticsearch-period-crash-by-stackoverflow/362864 "2024-07-11T05:28:43Z")

</div>

hello..recentlly I got a weird elasticsearch crash problem and it lasts nearly one month .since I reindex some of my index to enlarge the shards from 1 to 6..and the error like following \[o.e.b.ElasticsearchUncaughtExce…

---

## [Looking for guidance on how to create a DSL query](https://discuss.elastic.co/t/looking-for-guidance-on-how-to-create-a-dsl-query/362663)

<div class="topic-metadata">

**Author:** [@RobertBM](https://discuss.elastic.co/u/RobertBM)\
**Replies:** 3\
**Last updated:** [July 10, 2024, 7:35pm UTC](https://discuss.elastic.co/t/looking-for-guidance-on-how-to-create-a-dsl-query/362663 "2024-07-10T19:35:44Z")

</div>

Hello, please, I am looking for guidance on how to perform a simple search. I have the following set of data: POST /processing\_records/\_bulk {"index":{}} {"processing\_id":"1234","file\_name":"file1.xls","start\_processing…

---

## [Getting shards from nodes and its data tier](https://discuss.elastic.co/t/getting-shards-from-nodes-and-its-data-tier/362887)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 1\
**Last updated:** [July 10, 2024, 4:11pm UTC](https://discuss.elastic.co/t/getting-shards-from-nodes-and-its-data-tier/362887 "2024-07-10T16:11:11Z")

</div>

Gretting everyone! I'm having a question for you guys! Is there an API wil can use into ES to retrive the shards that are on a specific node showing the tier/phase they are in? By "tier/phase", I mean "data\_hot", "da…

---

## [Delete lost primary shard](https://discuss.elastic.co/t/delete-lost-primary-shard/362888)

<div class="topic-metadata">

**Author:** [@ALIT](https://discuss.elastic.co/u/ALIT)\
**Replies:** 3\
**Last updated:** [July 10, 2024, 3:45pm UTC](https://discuss.elastic.co/t/delete-lost-primary-shard/362888 "2024-07-10T15:45:46Z")

</div>

Hi, due to running out of disk space, I reduced number of replicas to 0 for a few indices. Of course during this time one node had a disk failure and I think the data is lost. Now the cluster is red because one index h…

---

## [Encryption In Elasticsearch](https://discuss.elastic.co/t/encryption-in-elasticsearch/360778)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 15\
**Last updated:** [July 10, 2024, 3:09pm UTC](https://discuss.elastic.co/t/encryption-in-elasticsearch/360778 "2024-07-10T15:09:37Z")

</div>

HI Team, We need to implement Encryption In Elasticsearch. As we know there are two types of encryption. Encryption in Transit. Encryption while data at REST. Please help us how to achieve the same. Thanks, Debasis …

---

## [KNN search with boost on specific field?](https://discuss.elastic.co/t/knn-search-with-boost-on-specific-field/362772)

<div class="topic-metadata">

**Author:** [@JdKock](https://discuss.elastic.co/u/JdKock)\
**Replies:** 6\
**Last updated:** [July 10, 2024, 2:36pm UTC](https://discuss.elastic.co/t/knn-search-with-boost-on-specific-field/362772 "2024-07-10T14:36:43Z")

</div>

Is it possible to do some tweaking with a KNN search? For example I have documents with a title, description, country and a category. I have created the embeddings with the E5 model for the title & description fields (…

---

## [Comparing two indexes in java](https://discuss.elastic.co/t/comparing-two-indexes-in-java/362837)

<div class="topic-metadata">

**Author:** [@always\_improving123](https://discuss.elastic.co/u/always_improving123)\
**Replies:** 1\
**Last updated:** [July 10, 2024, 1:58pm UTC](https://discuss.elastic.co/t/comparing-two-indexes-in-java/362837 "2024-07-10T13:58:01Z")

</div>

Hello! I am trying to efficiently compare two indexes, one index is formed of my own data (say of many nationalities and their average height) and the other index is incomplete data (only contains nationalities), where …

---

## [Elastic search query - parent child permissions](https://discuss.elastic.co/t/elastic-search-query-parent-child-permissions/362824)

<div class="topic-metadata">

**Author:** [@anuj99](https://discuss.elastic.co/u/anuj99)\
**Replies:** 0\
**Last updated:** [July 9, 2024, 10:10pm UTC](https://discuss.elastic.co/t/elastic-search-query-parent-child-permissions/362824 "2024-07-09T22:10:57Z")

</div>

I have the following use case : I have multiple folders each having associated accesses for users and teams. Each folder is associated with multiple files and inherits the folder permissions. I want to query based on…

---

## [Query suggestion for a search engine](https://discuss.elastic.co/t/query-suggestion-for-a-search-engine/362706)

<div class="topic-metadata">

**Author:** [@jahedi](https://discuss.elastic.co/u/jahedi)\
**Replies:** 5\
**Last updated:** [July 10, 2024, 9:10am UTC](https://discuss.elastic.co/t/query-suggestion-for-a-search-engine/362706 "2024-07-10T09:10:58Z")

</div>

Hi, I am currently working on a web search engine just like Google for my web site. I have crawled my website pages and indexed data in Elasticsearch. the indexed documents have such fields: string Id string U…

---

## [Elastic.Extensions.Logging - customization](https://discuss.elastic.co/t/elastic-extensions-logging-customization/362874)

<div class="topic-metadata">

**Author:** [@PCDiver](https://discuss.elastic.co/u/PCDiver)\
**Replies:** 0\
**Last updated:** [July 10, 2024, 10:56am UTC](https://discuss.elastic.co/t/elastic-extensions-logging-customization/362874 "2024-07-10T10:56:31Z")

</div>

Hi all, I'm working on a .NETlogger that logs directly to Elasticsearch. I looked at the source code for Elastic.Extensions.Logging and I cannot find any "customization" options. Examples: How can we change the user…

---

## [Encryption At REST In ELASTICSEARCH](https://discuss.elastic.co/t/encryption-at-rest-in-elasticsearch/362868)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 0\
**Last updated:** [July 10, 2024, 10:19am UTC](https://discuss.elastic.co/t/encryption-at-rest-in-elasticsearch/362868 "2024-07-10T10:19:43Z")

</div>

Hi Team, In one of our requirement, we need data encryption at REST so while going through the subscription page (Subscriptions | Elastic Stack Products & Support | Elastic) we found below two things . In one section it…

---

## [Connect To Elastic Sales Team For licensing](https://discuss.elastic.co/t/connect-to-elastic-sales-team-for-licensing/362836)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 2\
**Last updated:** [July 10, 2024, 9:35am UTC](https://discuss.elastic.co/t/connect-to-elastic-sales-team-for-licensing/362836 "2024-07-10T09:35:11Z")

</div>

Hi Team, One of our colleague trying to reach sales team to discuss for further discussion on Enterprise Elasticsearch but no response from team. Is there any other way to connect for faster processing the request. T…

---

## [Filtering first input result as my second input in Watcher](https://discuss.elastic.co/t/filtering-first-input-result-as-my-second-input-in-watcher/362799)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 0\
**Last updated:** [July 9, 2024, 2:03pm UTC](https://discuss.elastic.co/t/filtering-first-input-result-as-my-second-input-in-watcher/362799 "2024-07-09T14:03:03Z")

</div>

Hi all, I am using 2 inputs in watcher. In the first input I have aggreagation level detail of error\_codes, I want to use those error\_codes as filter in my second input. I have tried below but this is not working. Kindl…

---

## [Duplicate metadata from \_id into a new field](https://discuss.elastic.co/t/duplicate-metadata-from-id-into-a-new-field/362838)

<div class="topic-metadata">

**Author:** [@mvasqueznr](https://discuss.elastic.co/u/mvasqueznr)\
**Replies:** 0\
**Last updated:** [July 10, 2024, 5:07am UTC](https://discuss.elastic.co/t/duplicate-metadata-from-id-into-a-new-field/362838 "2024-07-10T05:07:41Z")

</div>

I have a Filebeat data pipeline that ingests metrics into an Elasticsearch index. In a separate Python application, I fetch some of this data using the SQL API to display it in a web application. The problem arises when …

---

## [Using Painless stored script in role mapping](https://discuss.elastic.co/t/using-painless-stored-script-in-role-mapping/362530)

<div class="topic-metadata">

**Author:** [@jonaslb](https://discuss.elastic.co/u/jonaslb)\
**Replies:** 7\
**Last updated:** [July 10, 2024, 2:32am UTC](https://discuss.elastic.co/t/using-painless-stored-script-in-role-mapping/362530 "2024-07-10T02:32:54Z")

</div>

The Kibana interface suggests that it should be possible to use a painless stored script to perform role mapping: I would like to use this feature to put logic around which roles a given SSO realm is allowed to assig…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=94)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=96)
