# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=97

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 98

---

## [No handler found](https://discuss.elastic.co/t/no-handler-found/362560)

<div class="topic-metadata">

**Author:** [@edgarmat1964](https://discuss.elastic.co/u/edgarmat1964)\
**Replies:** 2\
**Last updated:** [July 5, 2024, 7:32pm UTC](https://discuss.elastic.co/t/no-handler-found/362560 "2024-07-05T19:32:27Z")

</div>

Hi list, I've got an issue where I get a "no handler found" error. I've started a trial license which is still active. My relevant elasticsearch.yml: path.data: /data/elasticsearch path.logs: /var/log/elasticsearch net…

---

## [Issue when enabling TLS in Fluent-bit with Elasticsearch as output](https://discuss.elastic.co/t/issue-when-enabling-tls-in-fluent-bit-with-elasticsearch-as-output/362573)

<div class="topic-metadata">

**Author:** [@Aingeru\_Scotland](https://discuss.elastic.co/u/Aingeru_Scotland)\
**Replies:** 2\
**Last updated:** [July 5, 2024, 5:02pm UTC](https://discuss.elastic.co/t/issue-when-enabling-tls-in-fluent-bit-with-elasticsearch-as-output/362573 "2024-07-05T17:02:43Z")

</div>

I am setting a EFK stack in a Kubernetes single host cluster. Everything works perfectly with http. However, when I enable TLS in Fluent-bit ConfigMap, I experience the following error: \[2024/07/04 16:51:57\] \[error\] \[tl…

---

## [Problem in installing & configuration of elasticsearch](https://discuss.elastic.co/t/problem-in-installing-configuration-of-elasticsearch/362465)

<div class="topic-metadata">

**Author:** [@arjun2001](https://discuss.elastic.co/u/arjun2001)\
**Replies:** 9\
**Last updated:** [July 5, 2024, 1:49pm UTC](https://discuss.elastic.co/t/problem-in-installing-configuration-of-elasticsearch/362465 "2024-07-05T13:49:58Z")

</div>

Actually my requirement is to implement the elasticsearch in my angular application. so i installed the jvm & elasticsearch from the official websites and also i am successfully installed & configured that. but now i am …

---

## [All nodes are offline in the kibana dashboard](https://discuss.elastic.co/t/all-nodes-are-offline-in-the-kibana-dashboard/362613)

<div class="topic-metadata">

**Author:** [@Abdarrahmane](https://discuss.elastic.co/u/Abdarrahmane)\
**Replies:** 0\
**Last updated:** [July 5, 2024, 12:45pm UTC](https://discuss.elastic.co/t/all-nodes-are-offline-in-the-kibana-dashboard/362613 "2024-07-05T12:45:28Z")

</div>

hello, i'm currently learning about ELK stack and i'm in love with this solution background: my goal is Understanding and setting up a comprehensive security monitoring and incident response environment in my home lab…

---

## [How can I avoid existing semantic query slowdown during re-indexing using ELSER model in Elastic Search V8](https://discuss.elastic.co/t/how-can-i-avoid-existing-semantic-query-slowdown-during-re-indexing-using-elser-model-in-elastic-search-v8/362468)

<div class="topic-metadata">

**Author:** [@sudom0nk](https://discuss.elastic.co/u/sudom0nk)\
**Replies:** 5\
**Last updated:** [July 5, 2024, 11:28am UTC](https://discuss.elastic.co/t/how-can-i-avoid-existing-semantic-query-slowdown-during-re-indexing-using-elser-model-in-elastic-search-v8/362468 "2024-07-05T11:28:42Z")

</div>

We are using Elastic ELSER model for Semantic Search. I follow this doc to create my semantic tokens in the index: Tutorial: semantic search with ELSER | Elasticsearch Guide \[8.14\] | Elastic The Problem: The search data…

---

## [How to filter in multi knn query](https://discuss.elastic.co/t/how-to-filter-in-multi-knn-query/362582)

<div class="topic-metadata">

**Author:** [@melkon](https://discuss.elastic.co/u/melkon)\
**Replies:** 1\
**Last updated:** [July 5, 2024, 7:52am UTC](https://discuss.elastic.co/t/how-to-filter-in-multi-knn-query/362582 "2024-07-05T07:52:36Z")

</div>

Hi. I'm trying to use filter in multi knn query but getting below error. It's working with the example from docs but I need to apply pre filter for case when knn is array of many knn queries. Elasticsearch::Transport…

---

## [After enable-elasticsearch-plugin.sh, the es cannot start](https://discuss.elastic.co/t/after-enable-elasticsearch-plugin-sh-the-es-cannot-start/362501)

<div class="topic-metadata">

**Author:** [@mixsuffix](https://discuss.elastic.co/u/mixsuffix)\
**Replies:** 6\
**Last updated:** [July 5, 2024, 7:33am UTC](https://discuss.elastic.co/t/after-enable-elasticsearch-plugin-sh-the-es-cannot-start/362501 "2024-07-05T07:33:51Z")

</div>

uncaught exception in thread \[main\] java.lang.IllegalStateException: failed to load plugin ranger-elasticsearch-plugin due to jar hell Likely root cause: java.security.AccessControlException: access denied ("java.io.File…

---

## [Dynamic role mapping of OIDC Realm ID value to Realm ID field value in document](https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 3\
**Last updated:** [July 5, 2024, 6:48am UTC](https://discuss.elastic.co/t/dynamic-role-mapping-of-oidc-realm-id-value-to-realm-id-field-value-in-document/362371 "2024-07-05T06:48:27Z")

</div>

Hello, Looking for some suggestions regarding dynamic role mapping between Realm ID field value returned from OIDC token claim and Realm ID field value in document. Could not find strong documentation regarding it. Is …

---

## [Frequent Creation of Threads by elastic.clients](https://discuss.elastic.co/t/frequent-creation-of-threads-by-elastic-clients/362505)

<div class="topic-metadata">

**Author:** [@tom\_ding](https://discuss.elastic.co/u/tom_ding)\
**Replies:** 10\
**Last updated:** [July 5, 2024, 1:41am UTC](https://discuss.elastic.co/t/frequent-creation-of-threads-by-elastic-clients/362505 "2024-07-05T01:41:50Z")

</div>

I am using Elasticsearch Java API Client \[8.13\] and Elasticsearch (8.13), but I encounter the following exception: 复制代码 unable to create native thread: possibly out of memory or process/resource limits reached at j…

---

## [ElasticSearch partial update request merge Map\<\>](https://discuss.elastic.co/t/elasticsearch-partial-update-request-merge-map/362559)

<div class="topic-metadata">

**Author:** [@nolik](https://discuss.elastic.co/u/nolik)\
**Replies:** 0\
**Last updated:** [July 4, 2024, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearch-partial-update-request-merge-map/362559 "2024-07-04T13:42:02Z")

</div>

I have a complex ES document with multiple fields: public class SomeDocument { @JsonProperty("id") private final String id; ... @JsonProperty("hits") private final Map\<String, Double\> hits = new HashMap\<\>(); }…

---

## [Mapping how and where](https://discuss.elastic.co/t/mapping-how-and-where/362577)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 0\
**Last updated:** [July 4, 2024, 7:31pm UTC](https://discuss.elastic.co/t/mapping-how-and-where/362577 "2024-07-04T19:31:00Z")

</div>

According to what I have read, when the data is ingested it receives a default text value. At this moment I am in the task of mapping to define the correct type of the fields since for example "src" has "text" type. Thi…

---

## [Getting shard id in script engine](https://discuss.elastic.co/t/getting-shard-id-in-script-engine/362566)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 0\
**Last updated:** [July 4, 2024, 3:51pm UTC](https://discuss.elastic.co/t/getting-shard-id-in-script-engine/362566 "2024-07-04T15:51:14Z")

</div>

In a plugin like this where it's extending ScriptEngine, LeafFactory, and DocReader, is it possible to get the shard the script is running on? I assume the script would run on each shard individually and then combine da…

---

## [Delete data older than 30 days](https://discuss.elastic.co/t/delete-data-older-than-30-days/362564)

<div class="topic-metadata">

**Author:** [@lshmikanth](https://discuss.elastic.co/u/lshmikanth)\
**Replies:** 1\
**Last updated:** [July 4, 2024, 2:38pm UTC](https://discuss.elastic.co/t/delete-data-older-than-30-days/362564 "2024-07-04T14:38:28Z")

</div>

I have an index in Elasticsearch which stores huge data. Till two weeks I was able to delete the data older than 30 days by DELETE BY QUERY with some time. At that time it's storage is 40% used. Now it has reached 77% an…

---

## [Snapshot to S3 error](https://discuss.elastic.co/t/snapshot-to-s3-error/362547)

<div class="topic-metadata">

**Author:** [@koskartsev](https://discuss.elastic.co/u/koskartsev)\
**Replies:** 2\
**Last updated:** [July 4, 2024, 2:18pm UTC](https://discuss.elastic.co/t/snapshot-to-s3-error/362547 "2024-07-04T14:18:02Z")

</div>

Hi, Elasticsearch 8.2.3 I'm trying to add an S3 snapshot repository, the endpoint is Yandexcloud S3 I've set the keys in the keystore on all master nodes, check it with show elasticsearch-keystore add s3.client.defau…

---

## [How to sort on nested values that matches certain filters](https://discuss.elastic.co/t/how-to-sort-on-nested-values-that-matches-certain-filters/362557)

<div class="topic-metadata">

**Author:** [@juanm889](https://discuss.elastic.co/u/juanm889)\
**Replies:** 0\
**Last updated:** [July 4, 2024, 1:25pm UTC](https://discuss.elastic.co/t/how-to-sort-on-nested-values-that-matches-certain-filters/362557 "2024-07-04T13:25:43Z")

</div>

I want to sort by the field has\_stock (sending false to the bottom) but only on those elements of the nested that matches the query { "mappings": { "properties": { "product\_id": { …

---

## [Issues Encountered During Elasticsearch plugin Upgrade from 8.9 to 8.14](https://discuss.elastic.co/t/issues-encountered-during-elasticsearch-plugin-upgrade-from-8-9-to-8-14/362454)

<div class="topic-metadata">

**Author:** [@ramsankar](https://discuss.elastic.co/u/ramsankar)\
**Replies:** 6\
**Last updated:** [July 4, 2024, 10:54am UTC](https://discuss.elastic.co/t/issues-encountered-during-elasticsearch-plugin-upgrade-from-8-9-to-8-14/362454 "2024-07-04T10:54:48Z")

</div>

We are working on upgrading Elasticsearch plugin from version 8.9 to 8.14 and encountering issues. We have modified the following constructor: In 8.9: highlighter = new CustomUnifiedHighlighter( searcher, analy…

---

## [CorruptIndexException: docs out of order](https://discuss.elastic.co/t/corruptindexexception-docs-out-of-order/362536)

<div class="topic-metadata">

**Author:** [@maroe](https://discuss.elastic.co/u/maroe)\
**Replies:** 0\
**Last updated:** [July 4, 2024, 9:59am UTC](https://discuss.elastic.co/t/corruptindexexception-docs-out-of-order/362536 "2024-07-04T09:59:45Z")

</div>

Hi, I am running elasticsearch v8.2.2 as part of our ELK stack on a Windows Server 2019. I seem to have a corrupt index. Health status has been red due to an unassigned shard. I have no snapshot or replica. Data is not …

---

## [upsert operation and refresh set to 3s](https://discuss.elastic.co/t/upsert-operation-and-refresh-set-to-3s/362526)

<div class="topic-metadata">

**Author:** [@blqck](https://discuss.elastic.co/u/blqck)\
**Replies:** 0\
**Last updated:** [July 4, 2024, 8:20am UTC](https://discuss.elastic.co/t/upsert-operation-and-refresh-set-to-3s/362526 "2024-07-04T08:20:49Z")

</div>

i'm doing upsert like this public async Task AddOrUpdate(Car car, CancellationToken cancellationToken) { await \_client.IndexAsync(user, i =\> i .Index(latestIndexName) .Id(car.Id), cancellationToken); } and i set refres…

---

## [Unable to get deployment users through the API](https://discuss.elastic.co/t/unable-to-get-deployment-users-through-the-api/362411)

<div class="topic-metadata">

**Author:** [@Gustavo\_Valente](https://discuss.elastic.co/u/Gustavo_Valente)\
**Replies:** 1\
**Last updated:** [July 4, 2024, 2:39am UTC](https://discuss.elastic.co/t/unable-to-get-deployment-users-through-the-api/362411 "2024-07-04T02:39:15Z")

</div>

Hi team, I am trying to create a script to get all users and roles from a specific Elasticsearch deployment instance. I have prepared the API call as "{deployment\_URL}/\_security/user", but I am getting this 401 error. I…

---

## [\_stats failing probably due to query cache overflow](https://discuss.elastic.co/t/stats-failing-probably-due-to-query-cache-overflow/362492)

<div class="topic-metadata">

**Author:** [@psmit](https://discuss.elastic.co/u/psmit)\
**Replies:** 0\
**Last updated:** [July 3, 2024, 7:44pm UTC](https://discuss.elastic.co/t/stats-failing-probably-due-to-query-cache-overflow/362492 "2024-07-03T19:44:19Z")

</div>

We've been running into periodic issues essentially trying to do a GET on m3\*/\_stats , with the error from ES being: elastic: Error 400 (Bad Request): Values less than -1 bytes are not supported: -9223372036826080625b \[…

---

## [Elasticsearch container spends 6 minutes in limbo before proceeding with startup](https://discuss.elastic.co/t/elasticsearch-container-spends-6-minutes-in-limbo-before-proceeding-with-startup/362484)

<div class="topic-metadata">

**Author:** [@shockdm](https://discuss.elastic.co/u/shockdm)\
**Replies:** 0\
**Last updated:** [July 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/elasticsearch-container-spends-6-minutes-in-limbo-before-proceeding-with-startup/362484 "2024-07-03T17:08:04Z")

</div>

Hi folks, I am hitting a very strange issue when running an Elasticsearch container in an Openshift environment. Basically when the container spins up - our init scripts run - and then trigger /usr/share/elasticsearch/bi…

---

## [Recovery failed](https://discuss.elastic.co/t/recovery-failed/362440)

<div class="topic-metadata">

**Author:** [@Phu\_Van\_Nguyen](https://discuss.elastic.co/u/Phu_Van_Nguyen)\
**Replies:** 2\
**Last updated:** [July 3, 2024, 9:00am UTC](https://discuss.elastic.co/t/recovery-failed/362440 "2024-07-03T09:00:07Z")

</div>

Hi team, A few days ago, I encountered a circuite\_breaking\_exception that caused a node on my cluster to break. I increased my node's memory and did a rolling restart for my cluster. After that, everything worked normal…

---

## [How to get all data from elasticsearch to Power bi](https://discuss.elastic.co/t/how-to-get-all-data-from-elasticsearch-to-power-bi/362471)

<div class="topic-metadata">

**Author:** [@Ali\_Salim](https://discuss.elastic.co/u/Ali_Salim)\
**Replies:** 0\
**Last updated:** [July 3, 2024, 1:43pm UTC](https://discuss.elastic.co/t/how-to-get-all-data-from-elasticsearch-to-power-bi/362471 "2024-07-03T13:43:00Z")

</div>

I am using this query but it returns 10000 let // Define Elasticsearch URL and Credentials baseUrl = "", // Include username and password in the URL indexName = "cube", searchEndpoint = "/cube/\_search", …

---

## [elasticsearch regex split into groups 255 characters](https://discuss.elastic.co/t/elasticsearch-regex-split-into-groups-255-characters/362408)

<div class="topic-metadata">

**Author:** [@Bruno\_Sebastian\_Alva](https://discuss.elastic.co/u/Bruno_Sebastian_Alva)\
**Replies:** 7\
**Last updated:** [July 3, 2024, 12:34pm UTC](https://discuss.elastic.co/t/elasticsearch-regex-split-into-groups-255-characters/362408 "2024-07-03T12:34:16Z")

</div>

First of all, sorry for my English. I have encountered the following issue when performing a query with regular expressions in Elasticsearch. This index field is a text longer than 255 characters (This is important). F…

---

## [Help creating a visualization?](https://discuss.elastic.co/t/help-creating-a-visualization/362331)

<div class="topic-metadata">

**Author:** [@amv](https://discuss.elastic.co/u/amv)\
**Replies:** 3\
**Last updated:** [July 3, 2024, 8:45am UTC](https://discuss.elastic.co/t/help-creating-a-visualization/362331 "2024-07-03T08:45:15Z")

</div>

Hey everyone, I've stood up Fleet and elastic which i finally got working properly. My question is with the discover / search. I'm trying to create a dashboard from this: agent.name:\* and winlog.event\_id:4624 and winlo…

---

## [Only update selected fields if document alread exists](https://discuss.elastic.co/t/only-update-selected-fields-if-document-alread-exists/362375)

<div class="topic-metadata">

**Author:** [@johanwallenborg](https://discuss.elastic.co/u/johanwallenborg)\
**Replies:** 0\
**Last updated:** [July 2, 2024, 11:43am UTC](https://discuss.elastic.co/t/only-update-selected-fields-if-document-alread-exists/362375 "2024-07-02T11:43:17Z")

</div>

I'm using IndexMany-method today and that updates if document with same ID alread exists. Is there any way except try to create and then index, to choose what fields that should be updated if document exists or maybe eve…

---

## [Empty fields on rule writes to index](https://discuss.elastic.co/t/empty-fields-on-rule-writes-to-index/362424)

<div class="topic-metadata">

**Author:** [@znaskoe](https://discuss.elastic.co/u/znaskoe)\
**Replies:** 0\
**Last updated:** [July 3, 2024, 6:37am UTC](https://discuss.elastic.co/t/empty-fields-on-rule-writes-to-index/362424 "2024-07-03T06:37:20Z")

</div>

Hi everyone, I'm having some issues with my Disk Usage rule, more specifically with the document to index part. Some of my fields come out as empty. This is my current 'Document to index': { "doc\_type": "alert", "…

---

## [I have a Sales force Marketing cloud Application , i want to monitor it using elastic search](https://discuss.elastic.co/t/i-have-a-sales-force-marketing-cloud-application-i-want-to-monitor-it-using-elastic-search/362069)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 3\
**Last updated:** [July 3, 2024, 5:56am UTC](https://discuss.elastic.co/t/i-have-a-sales-force-marketing-cloud-application-i-want-to-monitor-it-using-elastic-search/362069 "2024-07-03T05:56:45Z")

</div>

Hello Team, I want to monitor the Sales force applications (Marketing cloud) using Elasticsearch. i have the API of the Sales force. how can i monitor it using the Elasticsearch. Any documents or reference will be help…

---

## [Shrink issues through ILM](https://discuss.elastic.co/t/shrink-issues-through-ilm/362420)

<div class="topic-metadata">

**Author:** [@albus471105](https://discuss.elastic.co/u/albus471105)\
**Replies:** 0\
**Last updated:** [July 3, 2024, 5:39am UTC](https://discuss.elastic.co/t/shrink-issues-through-ilm/362420 "2024-07-03T05:39:32Z")

</div>

hi there, I have some questions about using shrink through ILM. First, I set the index to shrink to 1 shard when it moves to the warm phase. I encountered two issues: When shards relocates (transfer to warm node), it …

---

## [Enrich policy working only on some documents](https://discuss.elastic.co/t/enrich-policy-working-only-on-some-documents/362326)

<div class="topic-metadata">

**Author:** [@gomay](https://discuss.elastic.co/u/gomay)\
**Replies:** 2\
**Last updated:** [July 3, 2024, 2:31am UTC](https://discuss.elastic.co/t/enrich-policy-working-only-on-some-documents/362326 "2024-07-03T02:31:30Z")

</div>

hello guys!! I did the simulate pipeline with two documents, one that gets enriched and one that is not. This is the pipeline { "peruchannelspm-ingest-pipeline": { "processors": \[ { "enrich": { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=96)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=98)
