# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=99

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 100

---

## [Springdata elasticsearch 5.2 nested aggregation without subAggregation](https://discuss.elastic.co/t/springdata-elasticsearch-5-2-nested-aggregation-without-subaggregation/362052)

<div class="topic-metadata">

**Author:** [@thVlm](https://discuss.elastic.co/u/thVlm)\
**Replies:** 4\
**Last updated:** [June 27, 2024, 9:58am UTC](https://discuss.elastic.co/t/springdata-elasticsearch-5-2-nested-aggregation-without-subaggregation/362052 "2024-06-27T09:58:40Z")

</div>

Help Needed: Nested Aggregations with Java API Client v8 I'm working on a project using Elasticsearch with the Java API Client v8, and I'm struggling to correctly implement nested aggregations. I'd greatly appreciate any…

---

## [Configuring a Cluster for High Throughput](https://discuss.elastic.co/t/configuring-a-cluster-for-high-throughput/362117)

<div class="topic-metadata">

**Author:** [@jhop](https://discuss.elastic.co/u/jhop)\
**Replies:** 3\
**Last updated:** [June 26, 2024, 9:50pm UTC](https://discuss.elastic.co/t/configuring-a-cluster-for-high-throughput/362117 "2024-06-26T21:50:35Z")

</div>

I have tried to load data into Elasticsearch real-time using Python. I am new to Elasticsearch. I used a single node and a single server. Elasticsearch was not able able to keep up with the real-time data coming into the…

---

## [Elasticsearch query failing with downsampling index](https://discuss.elastic.co/t/elasticsearch-query-failing-with-downsampling-index/362122)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 0\
**Last updated:** [June 26, 2024, 9:01pm UTC](https://discuss.elastic.co/t/elasticsearch-query-failing-with-downsampling-index/362122 "2024-06-26T21:01:42Z")

</div>

We are using ELK 7.9.0 with downsampling turned on at 7 days. I have this query that works when the range is before the downsampling ocured. But if its in that range it gives me this exception. This is the query curl -…

---

## [Elasticsearch cluster change schema in the same index](https://discuss.elastic.co/t/elasticsearch-cluster-change-schema-in-the-same-index/362054)

<div class="topic-metadata">

**Author:** [@thatelasticguy](https://discuss.elastic.co/u/thatelasticguy)\
**Replies:** 3\
**Last updated:** [June 26, 2024, 5:32pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-change-schema-in-the-same-index/362054 "2024-06-26T17:32:03Z")

</div>

We are using elasticsearch cluster version 7.10. And have some data in an index. We have updated schema for the cluster index and wanted to migrate the data from old schema to new schema in the same index. Is there any …

---

## [Deletion on fields within an index](https://discuss.elastic.co/t/deletion-on-fields-within-an-index/362093)

<div class="topic-metadata">

**Author:** [@Moni\_Hazarika](https://discuss.elastic.co/u/Moni_Hazarika)\
**Replies:** 5\
**Last updated:** [June 26, 2024, 3:28pm UTC](https://discuss.elastic.co/t/deletion-on-fields-within-an-index/362093 "2024-06-26T15:28:43Z")

</div>

We have this usecase: Create Application with fields A (text), B (text), C (text). Application is more of a UI term but we have say for each application a collection in mongoDB to store the metadata of the application. …

---

## [Cannot specify multiple documents in a single corpora](https://discuss.elastic.co/t/cannot-specify-multiple-documents-in-a-single-corpora/362065)

<div class="topic-metadata">

**Author:** [@mradulag](https://discuss.elastic.co/u/mradulag)\
**Replies:** 6\
**Last updated:** [June 26, 2024, 12:05pm UTC](https://discuss.elastic.co/t/cannot-specify-multiple-documents-in-a-single-corpora/362065 "2024-06-26T12:05:33Z")

</div>

I have multiple input JSON documents (around 5000) and want to ingest them using Rally, I have created a track.json based on those input JSON documents like this: (Shows the first few lines of the file) { "version":…

---

## [Elasticsearch Data Lost After Restart Minikube & After Restart Pod In Local Minikube](https://discuss.elastic.co/t/elasticsearch-data-lost-after-restart-minikube-after-restart-pod-in-local-minikube/362081)

<div class="topic-metadata">

**Author:** [@Arfa\_T](https://discuss.elastic.co/u/Arfa_T)\
**Replies:** 1\
**Last updated:** [June 26, 2024, 11:20am UTC](https://discuss.elastic.co/t/elasticsearch-data-lost-after-restart-minikube-after-restart-pod-in-local-minikube/362081 "2024-06-26T11:20:26Z")

</div>

I have a problem dealing with persistent data from elasticsearch after I shut down and restart my minikube Requirement: CPUS: 4 Memory: 7000Mbi Driver: hyperv (windows - local) Scenario: Deploy elastic to minikube A…

---

## [Elasticsearch server sizing](https://discuss.elastic.co/t/elasticsearch-server-sizing/362087)

<div class="topic-metadata">

**Author:** [@sl89](https://discuss.elastic.co/u/sl89)\
**Replies:** 0\
**Last updated:** [June 26, 2024, 10:54am UTC](https://discuss.elastic.co/t/elasticsearch-server-sizing/362087 "2024-06-26T10:54:34Z")

</div>

Hello. I have a single ES node running on my server with lots of indexes and data. It is time for me to cluster my data/indices. Where can I learn about, how to size the cluster ? ( No. of nodes, shards etc keeping i…

---

## [Error : master\_not\_discovered\_exception / ELK 7.17.12 - RHEL8](https://discuss.elastic.co/t/error-master-not-discovered-exception-elk-7-17-12-rhel8/362039)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 3\
**Last updated:** [June 26, 2024, 8:00am UTC](https://discuss.elastic.co/t/error-master-not-discovered-exception-elk-7-17-12-rhel8/362039 "2024-06-26T08:00:51Z")

</div>

Hi, I getting this error when i execute those command : curl -X GET "http://SFAPRL17026.gestion.mrqgest:9200/\_licence curl -X GET "http://SFAPRL17026.gestion.mrqgest:9200/\_cluster/health?pretty" error text : { "err…

---

## [Template setting is not honored by the index](https://discuss.elastic.co/t/template-setting-is-not-honored-by-the-index/361903)

<div class="topic-metadata">

**Author:** [@siakc](https://discuss.elastic.co/u/siakc)\
**Replies:** 10\
**Last updated:** [June 24, 2024, 1:14pm UTC](https://discuss.elastic.co/t/template-setting-is-not-honored-by-the-index/361903 "2024-06-24T13:14:55Z")

</div>

I created an index template with settings: { 'index.mapping.total\_fields.limit': 1500, 'index.mapping.ignore\_malformed': true } After that I create an index with matching pattern. But the index hi…

---

## [Find Cluster information Index](https://discuss.elastic.co/t/find-cluster-information-index/361989)

<div class="topic-metadata">

**Author:** [@Bibhutibhusan\_Sahoo](https://discuss.elastic.co/u/Bibhutibhusan_Sahoo)\
**Replies:** 1\
**Last updated:** [June 26, 2024, 5:24am UTC](https://discuss.elastic.co/t/find-cluster-information-index/361989 "2024-06-26T05:24:36Z")

</div>

Hi Team, We have 3 nodes cluster for Elasticsearch and all of them are master eligible + data node. If two of ES nodes were down the third ES node is not able to find master node which is expected. Once this happens (t…

---

## [ELK architecture](https://discuss.elastic.co/t/elk-architecture/362026)

<div class="topic-metadata">

**Author:** [@vnovotny98](https://discuss.elastic.co/u/vnovotny98)\
**Replies:** 5\
**Last updated:** [June 25, 2024, 11:03pm UTC](https://discuss.elastic.co/t/elk-architecture/362026 "2024-06-25T23:03:17Z")

</div>

Hello, I need some advice. I have an Elasticsearch cluster with six nodes (due to licensing). I have two locations, so ideally, I want to have data in pairs. I collect data through Filebeat -\> Logstash(server) -\> Elast…

---

## [Context Error During Reindex with Elser](https://discuss.elastic.co/t/context-error-during-reindex-with-elser/362038)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 5\
**Last updated:** [June 25, 2024, 7:04pm UTC](https://discuss.elastic.co/t/context-error-during-reindex-with-elser/362038 "2024-06-25T19:04:23Z")

</div>

Hello, I am currently running into an error where I reindex documents from an index with a subset of data, run them through a pipeline to create vector embeddings with ELSER and create passages, which also have vector …

---

## [App search engine nested filter not working](https://discuss.elastic.co/t/app-search-engine-nested-filter-not-working/361864)

<div class="topic-metadata">

**Author:** [@gautham.pushpakumar](https://discuss.elastic.co/u/gautham.pushpakumar)\
**Replies:** 6\
**Last updated:** [June 25, 2024, 4:57pm UTC](https://discuss.elastic.co/t/app-search-engine-nested-filter-not-working/361864 "2024-06-25T16:57:06Z")

</div>

I have zero luck in getting this work. First of all the engine expects us to create subfields and after we do that the filter query returns empty results. I followed exactly what is given here and no luck I have e…

---

## [Curl -X GET Command Error](https://discuss.elastic.co/t/curl-x-get-command-error/362035)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 8\
**Last updated:** [June 25, 2024, 4:49pm UTC](https://discuss.elastic.co/t/curl-x-get-command-error/362035 "2024-06-25T16:49:49Z")

</div>

I am trying to install Elasticsearch on Ubuntu. When I run curl -X GET 'http://localhost:9200 I get an error: Empty Reply from Server. I get this when the firewall is disabled and also when it is enabled. I have adju…

---

## [Elastic Common Schema Jobss Logs Implementation](https://discuss.elastic.co/t/elastic-common-schema-jobss-logs-implementation/362002)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [June 25, 2024, 9:38am UTC](https://discuss.elastic.co/t/elastic-common-schema-jobss-logs-implementation/362002 "2024-06-25T09:38:57Z")

</div>

Hello i am injesting jboss logs to the elastic have some of the fields to grok, but i want to use the ELastic Common schema to store those here is my log: 2024-06-25 11:59:50,358 ERROR \[stderr\] (default task-100) at o…

---

## [Improper access controll](https://discuss.elastic.co/t/improper-access-controll/361999)

<div class="topic-metadata">

**Author:** [@Muhammad\_Idris](https://discuss.elastic.co/u/Muhammad_Idris)\
**Replies:** 2\
**Last updated:** [June 25, 2024, 8:37am UTC](https://discuss.elastic.co/t/improper-access-controll/361999 "2024-06-25T08:37:47Z")

</div>

improper access controll

---

## [Moving data streams to warm phase dowsampling](https://discuss.elastic.co/t/moving-data-streams-to-warm-phase-dowsampling/361596)

<div class="topic-metadata">

**Author:** [@Honestabe](https://discuss.elastic.co/u/Honestabe)\
**Replies:** 1\
**Last updated:** [June 24, 2024, 4:46pm UTC](https://discuss.elastic.co/t/moving-data-streams-to-warm-phase-dowsampling/361596 "2024-06-24T16:46:48Z")

</div>

POST \_ilm/move/.ds-heartbeat-8.13.2-2024.04.29-000001 { "current\_step": { "phase": "warm", "action": "complete", "name": "complete" }, "next\_step": { "phase": "warm", "action": "downsample", …

---

## [Managing 10TB of Data in Elasticsearch with 30GB Heap: Best Practices and Considerations](https://discuss.elastic.co/t/managing-10tb-of-data-in-elasticsearch-with-30gb-heap-best-practices-and-considerations/361948)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 0\
**Last updated:** [June 24, 2024, 12:09pm UTC](https://discuss.elastic.co/t/managing-10tb-of-data-in-elasticsearch-with-30gb-heap-best-practices-and-considerations/361948 "2024-06-24T12:09:44Z")

</div>

I was very interested in frozen indices, but it seems like they are deprecated. According to the blog, You would now only need 2.5GB of heap memory to keep 10TB of geonames-like data indices open. I want to understa…

---

## [Variable\_width\_histogram cannot be nested in sampler](https://discuss.elastic.co/t/variable-width-histogram-cannot-be-nested-in-sampler/361822)

<div class="topic-metadata">

**Author:** [@jewell](https://discuss.elastic.co/u/jewell)\
**Replies:** 1\
**Last updated:** [June 24, 2024, 9:39am UTC](https://discuss.elastic.co/t/variable-width-histogram-cannot-be-nested-in-sampler/361822 "2024-06-24T09:39:24Z")

</div>

Greetings The variable\_width\_histogram works fine as the first aggregation GET ntsp\_dbas\_bfg/\_search { "query": { "term": { "name": { "value": "Valsartanic acid" } } }, "size": 0, "a…

---

## [Download osquery result](https://discuss.elastic.co/t/download-osquery-result/361884)

<div class="topic-metadata">

**Author:** [@azno](https://discuss.elastic.co/u/azno)\
**Replies:** 1\
**Last updated:** [June 24, 2024, 8:54am UTC](https://discuss.elastic.co/t/download-osquery-result/361884 "2024-06-24T08:54:01Z")

</div>

Does anyone know how to download the osquery result to an CSV file?

---

## [Okta apps validation](https://discuss.elastic.co/t/okta-apps-validation/361895)

<div class="topic-metadata">

**Author:** [@brother\_info](https://discuss.elastic.co/u/brother_info)\
**Replies:** 1\
**Last updated:** [June 24, 2024, 8:47am UTC](https://discuss.elastic.co/t/okta-apps-validation/361895 "2024-06-24T08:47:57Z")

</div>

I have 3 okta apps setup. Okta app for backend Okta spa app Okta web app The Okta spa app is able to use the access token it got and pass to Okta app for backend and the token is validated. However, the Okta web app a…

---

## [Authentication using apikey failed - apikey authentication for id encountered a failure org.elasticsearch.cluster.block.ClusterBlockException: blocked by: \[SERVICE\_UNAVAILABLE/1/state not recovered / initialized\]](https://discuss.elastic.co/t/authentication-using-apikey-failed-apikey-authentication-for-id-encountered-a-failure-org-elasticsearch-cluster-block-clusterblockexception-blocked-by-service-unavailable-1-state-not-recovered-initialized/361830)

<div class="topic-metadata">

**Author:** [@Cyber\_Labs](https://discuss.elastic.co/u/Cyber_Labs)\
**Replies:** 2\
**Last updated:** [June 21, 2024, 8:28am UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-apikey-authentication-for-id-encountered-a-failure-org-elasticsearch-cluster-block-clusterblockexception-blocked-by-service-unavailable-1-state-not-recovered-initialized/361830 "2024-06-21T08:28:27Z")

</div>

I am running a 3 node cluster, but last week i was constantly getting the kibana server not ready error, but on looking at it, my kibana\_system user was not able to authenticate to the cluster neither any of my users cre…

---

## [Elastic and Sec Onion manger not getting Zeek logs](https://discuss.elastic.co/t/elastic-and-sec-onion-manger-not-getting-zeek-logs/361683)

<div class="topic-metadata">

**Author:** [@farmertom](https://discuss.elastic.co/u/farmertom)\
**Replies:** 1\
**Last updated:** [June 23, 2024, 3:49pm UTC](https://discuss.elastic.co/t/elastic-and-sec-onion-manger-not-getting-zeek-logs/361683 "2024-06-23T15:49:27Z")

</div>

Hello, I have setup a Sec onion search manager and a sec onion sensor setup in esxi. The manager has accepted the sensor into the grid and its says everything is working. But when I go to hunt in the sec onion web inter…

---

## [Unable to generate a enrollement token with scope level to node ERROR: Failed to determine the health of the cluster. , with exit code 69](https://discuss.elastic.co/t/unable-to-generate-a-enrollement-token-with-scope-level-to-node-error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/361887)

<div class="topic-metadata">

**Author:** [@arunraj](https://discuss.elastic.co/u/arunraj)\
**Replies:** 2\
**Last updated:** [June 23, 2024, 1:44pm UTC](https://discuss.elastic.co/t/unable-to-generate-a-enrollement-token-with-scope-level-to-node-error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/361887 "2024-06-23T13:44:25Z")

</div>

my elasticsearch config file content # ======================== Elasticsearch Configuration ========================= # # NOTE: Elasticsearch comes with reasonable defaults for most settings. # Before you set out to …

---

## [Missing some logs](https://discuss.elastic.co/t/missing-some-logs/361536)

<div class="topic-metadata">

**Author:** [@Milad\_Akhlaghi](https://discuss.elastic.co/u/Milad_Akhlaghi)\
**Replies:** 4\
**Last updated:** [June 23, 2024, 10:01am UTC](https://discuss.elastic.co/t/missing-some-logs/361536 "2024-06-23T10:01:30Z")

</div>

Hi friends , I have elk stack ( version 8.14 )that shipped my app log( json ) with filebeat to logstash and then to elasticsearch.i have 13million logs every 30 minutes , Logs are shipped and shown in kibana but some …

---

## [Shard Count and Index Splitting Strategies about PB-Level Storage in Elasticsearch](https://discuss.elastic.co/t/shard-count-and-index-splitting-strategies-about-pb-level-storage-in-elasticsearch/361880)

<div class="topic-metadata">

**Author:** [@Andy\_Cong](https://discuss.elastic.co/u/Andy_Cong)\
**Replies:** 3\
**Last updated:** [June 22, 2024, 1:32pm UTC](https://discuss.elastic.co/t/shard-count-and-index-splitting-strategies-about-pb-level-storage-in-elasticsearch/361880 "2024-06-22T13:32:00Z")

</div>

Quick description： I'm dealing with a scenario where we have over 10 billion records, requiring storage at the petabyte level. Following the Elasticsearch official best practices, which recommend keeping each shard betwe…

---

## [Occasionally shards failing during scroll API (Scroll request has only succeeded on 270 (+0 skipped) shards out of 280)](https://discuss.elastic.co/t/occasionally-shards-failing-during-scroll-api-scroll-request-has-only-succeeded-on-270-0-skipped-shards-out-of-280/361841)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 5\
**Last updated:** [June 21, 2024, 12:33pm UTC](https://discuss.elastic.co/t/occasionally-shards-failing-during-scroll-api-scroll-request-has-only-succeeded-on-270-0-skipped-shards-out-of-280/361841 "2024-06-21T12:33:07Z")

</div>

Hi, I am facing some weird errors on our Elasticsearch cluster using scroll API. For some data pipeline that I created I need to use the scroll API. Everything worked fine, but recently I have been encountering the foll…

---

## [Search Like Google](https://discuss.elastic.co/t/search-like-google/361550)

<div class="topic-metadata">

**Author:** [@Aswini\_Kumar\_Rout](https://discuss.elastic.co/u/Aswini_Kumar_Rout)\
**Replies:** 4\
**Last updated:** [June 19, 2024, 5:24am UTC](https://discuss.elastic.co/t/search-like-google/361550 "2024-06-19T05:24:19Z")

</div>

I want to perform a search like google when the user starts typing. For an example my documents looks like this - { "fir\_number": "12345", "fir\_id": "123", "accused\_first\_name": "spi…

---

## [Filebeat and Elasticsearch Notification](https://discuss.elastic.co/t/filebeat-and-elasticsearch-notification/361732)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [June 21, 2024, 7:03am UTC](https://discuss.elastic.co/t/filebeat-and-elasticsearch-notification/361732 "2024-06-21T07:03:07Z")

</div>

Hi Team, We had requirement that how the end user get notified in case the filebeat and Elasticsearch service get stopped. Note:- Both is configured through systemctl process. Thanks, Debasis

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=98)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=100)
