# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=98

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 99

---

## [Better cluster configuration for 63 terrabyes of data](https://discuss.elastic.co/t/better-cluster-configuration-for-63-terrabyes-of-data/362347)

<div class="topic-metadata">

**Author:** [@paladin\_paterson](https://discuss.elastic.co/u/paladin_paterson)\
**Replies:** 5\
**Last updated:** [July 2, 2024, 9:00pm UTC](https://discuss.elastic.co/t/better-cluster-configuration-for-63-terrabyes-of-data/362347 "2024-07-02T21:00:59Z")

</div>

Hey gang, out team has an Elasticsearch cluster filled with HTML documents. Here is some data abour our current configuration: It consists of 10 data nodes, each with a heap.size of 32GB It contains a total of 600 shar…

---

## [How to calc login,logout duration inside special time span](https://discuss.elastic.co/t/how-to-calc-login-logout-duration-inside-special-time-span/362201)

<div class="topic-metadata">

**Author:** [@moryaden](https://discuss.elastic.co/u/moryaden)\
**Replies:** 4\
**Last updated:** [July 2, 2024, 4:30pm UTC](https://discuss.elastic.co/t/how-to-calc-login-logout-duration-inside-special-time-span/362201 "2024-07-02T16:30:54Z")

</div>

Guys, I already struggled from es docs for days, but not a better solution could be found. Need your professional opinions!! I have these recorded data lines: {"uid":1, "login": "2024-06-28 17:00:00", "logout":"2024-…

---

## [Encrypt Password In Filebeat Yml](https://discuss.elastic.co/t/encrypt-password-in-filebeat-yml/361743)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 5\
**Last updated:** [July 2, 2024, 3:37pm UTC](https://discuss.elastic.co/t/encrypt-password-in-filebeat-yml/361743 "2024-07-02T15:37:13Z")

</div>

Hi Team, Could you please help me how we can encrypt the plain text password which we are mentioning in filebeat.yml file. Thanks, Debasis

---

## [Change in dense\_vector field indexation default in ES 8.14 - Existing indices behaviour?](https://discuss.elastic.co/t/change-in-dense-vector-field-indexation-default-in-es-8-14-existing-indices-behaviour/362385)

<div class="topic-metadata">

**Author:** [@clemsau](https://discuss.elastic.co/u/clemsau)\
**Replies:** 1\
**Last updated:** [July 2, 2024, 4:13pm UTC](https://discuss.elastic.co/t/change-in-dense-vector-field-indexation-default-in-es-8-14-existing-indices-behaviour/362385 "2024-07-02T16:13:04Z")

</div>

Hello, In the ES 8.14 patch notes, we can see that now, the dense\_vector field type used for vector search will now be indexed by default with the quantized hnsw\_int8 graphs. Prior to that, hnsw\_int8 was the graph used…

---

## [Elastic Agent not working on RAspberry Pi5](https://discuss.elastic.co/t/elastic-agent-not-working-on-raspberry-pi5/362390)

<div class="topic-metadata">

**Author:** [@Toony](https://discuss.elastic.co/u/Toony)\
**Replies:** 0\
**Last updated:** [July 2, 2024, 2:53pm UTC](https://discuss.elastic.co/t/elastic-agent-not-working-on-raspberry-pi5/362390 "2024-07-02T14:53:31Z")

</div>

After the "elastic-agent-8.12.2-linux-arm64.tar.gz" agent installation, the agent binary execution is systematically failing with this message: ./elastic-agent: cannot execute: required file not found Is this a bug or …

---

## [Optimal Shard Strategy for High Search Load with Elasticsearch Cluster](https://discuss.elastic.co/t/optimal-shard-strategy-for-high-search-load-with-elasticsearch-cluster/362242)

<div class="topic-metadata">

**Author:** [@taichi](https://discuss.elastic.co/u/taichi)\
**Replies:** 8\
**Last updated:** [July 2, 2024, 11:19am UTC](https://discuss.elastic.co/t/optimal-shard-strategy-for-high-search-load-with-elasticsearch-cluster/362242 "2024-07-02T11:19:25Z")

</div>

Hi, I am working on optimizing an Elasticsearch cluster and am seeking advice on the best shard strategy. Here are the specifics of my setup: Node Details: 4 data nodes running on AWS r6g.large instances, with 3 maste…

---

## [Running multiple instances of Elasticsearch on the same host - Allocated processors setting](https://discuss.elastic.co/t/running-multiple-instances-of-elasticsearch-on-the-same-host-allocated-processors-setting/362372)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [July 2, 2024, 10:50am UTC](https://discuss.elastic.co/t/running-multiple-instances-of-elasticsearch-on-the-same-host-allocated-processors-setting/362372 "2024-07-02T10:50:44Z")

</div>

Hi, I have machine with 86 cores and I want to run multiple instances of Elasticsearch on it. I want to isolate the number of cores foreach node. I saw in \[multiple instances of Elasticsearch on the same host\]( Thread…

---

## [Looking for document or technical article which explains the Memory Utilization of Java.exe when Elasticsearch is running on Windows server](https://discuss.elastic.co/t/looking-for-document-or-technical-article-which-explains-the-memory-utilization-of-java-exe-when-elasticsearch-is-running-on-windows-server/362354)

<div class="topic-metadata">

**Author:** [@Kalidastate](https://discuss.elastic.co/u/Kalidastate)\
**Replies:** 1\
**Last updated:** [July 2, 2024, 9:09am UTC](https://discuss.elastic.co/t/looking-for-document-or-technical-article-which-explains-the-memory-utilization-of-java-exe-when-elasticsearch-is-running-on-windows-server/362354 "2024-07-02T09:09:49Z")

</div>

During extensive testing of Elasticsearch's search functionality, we noticed that the memory utilization of java.exe spikes, causing overall system memory utilization to reach 100%. Despite this, no search failures were …

---

## [Highlighting issue with fuzzy query with edge\_ngram tokens](https://discuss.elastic.co/t/highlighting-issue-with-fuzzy-query-with-edge-ngram-tokens/362345)

<div class="topic-metadata">

**Author:** [@lschnei](https://discuss.elastic.co/u/lschnei)\
**Replies:** 0\
**Last updated:** [July 2, 2024, 7:08am UTC](https://discuss.elastic.co/t/highlighting-issue-with-fuzzy-query-with-edge-ngram-tokens/362345 "2024-07-02T07:08:35Z")

</div>

I couldn’t find a relevant example, so here’s my issue: I’m developing a search-as-you-type feature using edge\_ngram tokens, which allows for spelling mistakes (fuzzy queries) while highlighting the current edge\_ngram t…

---

## [Looking up values from a diiferent index to the one being searched](https://discuss.elastic.co/t/looking-up-values-from-a-diiferent-index-to-the-one-being-searched/362111)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [June 26, 2024, 5:33pm UTC](https://discuss.elastic.co/t/looking-up-values-from-a-diiferent-index-to-the-one-being-searched/362111 "2024-06-26T17:33:53Z")

</div>

Let's say we have an index for Jobs to be carried out called "jobs". In this index there is a field called localityId which is a string that represnets where the job location is. This string is defined in another index c…

---

## [Dynamic index creation](https://discuss.elastic.co/t/dynamic-index-creation/362280)

<div class="topic-metadata">

**Author:** [@siakc](https://discuss.elastic.co/u/siakc)\
**Replies:** 4\
**Last updated:** [July 1, 2024, 2:07pm UTC](https://discuss.elastic.co/t/dynamic-index-creation/362280 "2024-07-01T14:07:11Z")

</div>

From what I understand ES tries to create index by some rules from incoming logs (which I think we call documents). Now I have too many fields in my docs which ES creates index for. What I need is to stop it from includ…

---

## [Documents in being deleted after indexed](https://discuss.elastic.co/t/documents-in-being-deleted-after-indexed/362307)

<div class="topic-metadata">

**Author:** [@gomay](https://discuss.elastic.co/u/gomay)\
**Replies:** 1\
**Last updated:** [July 1, 2024, 5:09pm UTC](https://discuss.elastic.co/t/documents-in-being-deleted-after-indexed/362307 "2024-07-01T17:09:59Z")

</div>

Some of the documents of an index are being deleted, the input is logstash jdbc plugin. No id's comes from the source. the settings of my index are as following { "settings": { "index": { "routing": { …

---

## [Elastic Field Types - Range Query](https://discuss.elastic.co/t/elastic-field-types-range-query/362249)

<div class="topic-metadata">

**Author:** [@Karthik\_Vaidyanathan](https://discuss.elastic.co/u/Karthik_Vaidyanathan)\
**Replies:** 1\
**Last updated:** [July 1, 2024, 10:28am UTC](https://discuss.elastic.co/t/elastic-field-types-range-query/362249 "2024-07-01T10:28:32Z")

</div>

Hello All, Pretty new to using Elastic and currently using the Serverless option. I have a field called street number , currently it's stored as a text. It contains values which are both string and text: \[100, 101A, 10…

---

## [Elastic search Managed instance on Azure - Data storage](https://discuss.elastic.co/t/elastic-search-managed-instance-on-azure-data-storage/362276)

<div class="topic-metadata">

**Author:** [@Bipindra.1.s](https://discuss.elastic.co/u/Bipindra.1.s)\
**Replies:** 3\
**Last updated:** [July 1, 2024, 9:09am UTC](https://discuss.elastic.co/t/elastic-search-managed-instance-on-azure-data-storage/362276 "2024-07-01T09:09:27Z")

</div>

We are planning to use elastic cloud managed instance from azure portal. what I understood that Azure portal is only for billing purpose actual instance will be created on elastic cloud only. Below are some queries relat…

---

## [Constant merges in new index](https://discuss.elastic.co/t/constant-merges-in-new-index/360710)

<div class="topic-metadata">

**Author:** [@margilit](https://discuss.elastic.co/u/margilit)\
**Replies:** 8\
**Last updated:** [July 1, 2024, 6:39am UTC](https://discuss.elastic.co/t/constant-merges-in-new-index/360710 "2024-07-01T06:39:03Z")

</div>

When creating a new index, we often see a significant and sustained increase in the number of internal refreshes. Merges are constantly triggered, affecting CPU usage and search speed accordingly. The only workaround we …

---

## [\[User error, please ignore\] Can't upgrade from 7.17.19 to ES8. Docs indicate that you should be able to](https://discuss.elastic.co/t/user-error-please-ignore-cant-upgrade-from-7-17-19-to-es8-docs-indicate-that-you-should-be-able-to/362229)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 12\
**Last updated:** [July 1, 2024, 6:06am UTC](https://discuss.elastic.co/t/user-error-please-ignore-cant-upgrade-from-7-17-19-to-es8-docs-indicate-that-you-should-be-able-to/362229 "2024-07-01T06:06:13Z")

</div>

I am upgrading from 7.17.19 to 8.11.3 specifically and got the following message: Upgrading to \[8.11.3\] is only supported from version \[7.17.0\] (full error below) \[2024-06-28T19:16:18,650\]\[ERROR\]\[org.elasticsearch.boot…

---

## [I need to upgrade my on prem setup from docker-compose](https://discuss.elastic.co/t/i-need-to-upgrade-my-on-prem-setup-from-docker-compose/361882)

<div class="topic-metadata">

**Author:** [@sourabh\_rawat](https://discuss.elastic.co/u/sourabh_rawat)\
**Replies:** 4\
**Last updated:** [July 1, 2024, 5:11am UTC](https://discuss.elastic.co/t/i-need-to-upgrade-my-on-prem-setup-from-docker-compose/361882 "2024-07-01T05:11:24Z")

</div>

Hi, I did an on-prem setup from a docker-compose.yml. Now I wanted to upgrade to 8.14.1 from 8.6. Not able to find any simple step. I tried changing the version to 8.14.1 in the env file. After running the command do…

---

## [Cannot race, worker has exited prematurely](https://discuss.elastic.co/t/cannot-race-worker-has-exited-prematurely/362145)

<div class="topic-metadata">

**Author:** [@Varun\_Tokas](https://discuss.elastic.co/u/Varun_Tokas)\
**Replies:** 6\
**Last updated:** [July 1, 2024, 3:49am UTC](https://discuss.elastic.co/t/cannot-race-worker-has-exited-prematurely/362145 "2024-07-01T03:49:15Z")

</div>

When using Elasticsearch, I keep getting errors of this sort. $ esrally race --track-path=. --pipeline=benchmark-only --target-hosts="https://10.43.34.12:9200" --client-options="basic\_auth\_user:'elastic',basic\_auth\_pass…

---

## [How to store geoshape Linestring with C#?](https://discuss.elastic.co/t/how-to-store-geoshape-linestring-with-c/361950)

<div class="topic-metadata">

**Author:** [@Motsols](https://discuss.elastic.co/u/Motsols)\
**Replies:** 9\
**Last updated:** [June 30, 2024, 8:27am UTC](https://discuss.elastic.co/t/how-to-store-geoshape-linestring-with-c/361950 "2024-06-30T08:27:48Z")

</div>

Using the latest .NET client Elastic.Clients.Elasticsearch 8.14.3, how can I in code add a geoJSON geoshape of type LineString to Elasticsearch? The documentation is completely lacking information on this and I have yet…

---

## [Speed up Indexing](https://discuss.elastic.co/t/speed-up-indexing/362243)

<div class="topic-metadata">

**Author:** [@venkatesh\_aamanchi](https://discuss.elastic.co/u/venkatesh_aamanchi)\
**Replies:** 4\
**Last updated:** [June 29, 2024, 4:28pm UTC](https://discuss.elastic.co/t/speed-up-indexing/362243 "2024-06-29T16:28:36Z")

</div>

I have a deployment setup with 2 nodes and a storage of 70GB. I need to index 20 million records. Uploading just these documents is taking me a little over 4 hrs. Is there anyway to speed up the process? I do not have a…

---

## [Sharding and partitioning on the ES Index](https://discuss.elastic.co/t/sharding-and-partitioning-on-the-es-index/361122)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 2\
**Last updated:** [June 29, 2024, 2:53am UTC](https://discuss.elastic.co/t/sharding-and-partitioning-on-the-es-index/361122 "2024-06-29T02:53:27Z")

</div>

Currently we have our data in MongoDB and we will continue to keep it there for ACID compliance. However we are moving our search capabilities to Elastic. Since our app supports multi-tenancy our MongoDB architecture is …

---

## [Moving From 1.7.5 to 7.10.2 - DLS Changes](https://discuss.elastic.co/t/moving-from-1-7-5-to-7-10-2-dls-changes/362235)

<div class="topic-metadata">

**Author:** [@djfrodo](https://discuss.elastic.co/u/djfrodo)\
**Replies:** 13\
**Last updated:** [June 29, 2024, 1:42am UTC](https://discuss.elastic.co/t/moving-from-1-7-5-to-7-10-2-dls-changes/362235 "2024-06-29T01:42:07Z")

</div>

I've used an ancient (1.7.5) version of Elasticsearch for years and it's been great. The initial setup was a bit difficult, but when completed it has always been rock solid. Unfortunately my Elasticsearch provider wants…

---

## [Query to return documents with field A gt 10 AND field B gt 5](https://discuss.elastic.co/t/query-to-return-documents-with-field-a-gt-10-and-field-b-gt-5/362226)

<div class="topic-metadata">

**Author:** [@trs80](https://discuss.elastic.co/u/trs80)\
**Replies:** 4\
**Last updated:** [June 28, 2024, 7:40pm UTC](https://discuss.elastic.co/t/query-to-return-documents-with-field-a-gt-10-and-field-b-gt-5/362226 "2024-06-28T19:40:28Z")

</div>

Hi, can someone help me write the correct query if possible? I want to return documents with field A gt 10 AND field B gt 10. The below query only returns documents with filed A gt 10 and field B (but B is not gt 10). Pl…

---

## [Parse logs Trent Micro Email Security](https://discuss.elastic.co/t/parse-logs-trent-micro-email-security/362217)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 5\
**Last updated:** [June 28, 2024, 3:00pm UTC](https://discuss.elastic.co/t/parse-logs-trent-micro-email-security/362217 "2024-06-28T15:00:32Z")

</div>

Hello everyone, I am currently in the process of normalizing and parsing logs from the manufacturer trend micro email security. Maybe for you it is obvious but in my case as I am not an expert I must mention that I am …

---

## [How to query on computed script\_fields?](https://discuss.elastic.co/t/how-to-query-on-computed-script-fields/362205)

<div class="topic-metadata">

**Author:** [@Nicolas\_Noukies](https://discuss.elastic.co/u/Nicolas_Noukies)\
**Replies:** 0\
**Last updated:** [June 28, 2024, 11:06am UTC](https://discuss.elastic.co/t/how-to-query-on-computed-script-fields/362205 "2024-06-28T11:06:30Z")

</div>

Hello, I would like to query on a script field. I'm trying this query without success : { "query": { "multi\_match": { "query": "machinbidule", "fields": \[ "name^9", "concatenated\_synon…

---

## [Unable to create index based on POD names with provided prefix](https://discuss.elastic.co/t/unable-to-create-index-based-on-pod-names-with-provided-prefix/362196)

<div class="topic-metadata">

**Author:** [@Mandar\_Pimplapure](https://discuss.elastic.co/u/Mandar_Pimplapure)\
**Replies:** 1\
**Last updated:** [June 28, 2024, 9:39am UTC](https://discuss.elastic.co/t/unable-to-create-index-based-on-pod-names-with-provided-prefix/362196 "2024-06-28T09:39:10Z")

</div>

We used multi\_format format to read logs but then indexes are not created properly with pod names. Here it seems unable to read pod\_name using below prefix : logstash\_prefix "{ENV\['K8S\_NODE\_NAME'\]}-${record\['kubernetes'…

---

## [SSL Handshake Exception: Empty Client Certificate Chain](https://discuss.elastic.co/t/ssl-handshake-exception-empty-client-certificate-chain/362158)

<div class="topic-metadata">

**Author:** [@Teddy\_Bear](https://discuss.elastic.co/u/Teddy_Bear)\
**Replies:** 1\
**Last updated:** [June 28, 2024, 6:26am UTC](https://discuss.elastic.co/t/ssl-handshake-exception-empty-client-certificate-chain/362158 "2024-06-28T06:26:50Z")

</div>

Hello, I’m currently working on a task to test a secure connection between Archiving and Elasticsearch. Following the command: curl -k https://\<ip\>:\<port\>/\_security/\_authenticate However, I’m encountering an issue wi…

---

## [Providing Hyphenation Files on self hosted Kubernetes cluster](https://discuss.elastic.co/t/providing-hyphenation-files-on-self-hosted-kubernetes-cluster/362176)

<div class="topic-metadata">

**Author:** [@JDev64](https://discuss.elastic.co/u/JDev64)\
**Replies:** 0\
**Last updated:** [June 27, 2024, 9:39pm UTC](https://discuss.elastic.co/t/providing-hyphenation-files-on-self-hosted-kubernetes-cluster/362176 "2024-06-27T21:39:29Z")

</div>

I'm building a multi-node elk stack which is going to use the Hyphenation decompounder token filter for multiple languages. The official documentation states, that to use the filter the hyphenation\_patterns\_path needs to…

---

## [1 node in an elasticsearch cluster getting stuck for 15 minutes and then starts working](https://discuss.elastic.co/t/1-node-in-an-elasticsearch-cluster-getting-stuck-for-15-minutes-and-then-starts-working/362137)

<div class="topic-metadata">

**Author:** [@anandgopalratnam](https://discuss.elastic.co/u/anandgopalratnam)\
**Replies:** 3\
**Last updated:** [June 27, 2024, 7:34pm UTC](https://discuss.elastic.co/t/1-node-in-an-elasticsearch-cluster-getting-stuck-for-15-minutes-and-then-starts-working/362137 "2024-06-27T19:34:13Z")

</div>

We have seen an issue since the last six months in versions 6.4.2 , 6.8.23 and 7.17.1 where a specific node gets stuck for 15 minutes resulting in timeouts for all calls to that node. We have seen this in TransportClient…

---

## [Making index data immutable](https://discuss.elastic.co/t/making-index-data-immutable/362157)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [June 27, 2024, 12:50pm UTC](https://discuss.elastic.co/t/making-index-data-immutable/362157 "2024-06-27T12:50:51Z")

</div>

Hi All, we have a an application that is indexing data into one index per day, say app\_index\_. We want to make sure Only data is appended/inserted - ie no data is deleted/updated at any point once indexing is complete…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=97)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=99)
