# Elastic Tips and Common Fixes

**URL:** https://discuss.elastic.co/c/meta/elastic-tips/86.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Elastic Tips and Common Fixes category](https://discuss.elastic.co/t/about-the-elastic-tips-and-common-fixes-category/238568)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0

</div>

The idea behind this category is a space akin to a knowledge base. A space to share tips, solutions to common problems, and other neat things that exist in the Elastic Stack that you may not be aware of. This category i…

---

## [Storing APM data in custom/specific indices](https://discuss.elastic.co/t/storing-apm-data-in-custom-specific-indices/246381)

<div class="topic-metadata">

**Author:** [@axw](https://discuss.elastic.co/u/axw)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 9:51am UTC](https://discuss.elastic.co/t/storing-apm-data-in-custom-specific-indices/246381 "2023-01-26T09:51:51Z")

</div>

If you'd like to split your APM indices by the service, you can use the advice from this topic. You can change the index name by setting either output.elasticsearch.index or output.elasticsearch.indices. These configura…

---

## [Approaches to deal with "Limit of total fields \[1000\] in index has been exceeded"](https://discuss.elastic.co/t/approaches-to-deal-with-limit-of-total-fields-1000-in-index-has-been-exceeded/241039)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 1\
**Last updated:** [July 25, 2022, 11:52pm UTC](https://discuss.elastic.co/t/approaches-to-deal-with-limit-of-total-fields-1000-in-index-has-been-exceeded/241039 "2022-07-25T23:52:52Z")

</div>

This is a common warning seen due to what is commonly known as a mapping explosion. The docs go into this is more detail, but quickly (emphasis by the author); Defining too many fields in an index can lead to a mapping…

---

## [Can't get text on a START\_OBJECT](https://discuss.elastic.co/t/cant-get-text-on-a-start-object/244340)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 1\
**Last updated:** [June 1, 2022, 11:18pm UTC](https://discuss.elastic.co/t/cant-get-text-on-a-start-object/244340 "2022-06-01T23:18:06Z")

</div>

This error will be logged when Elasticsearch tries to index data that is an object, into a field that is not mapped as one. Or in reverse, if you try to index something that isn't an object into a field that is mapped as…

---

## [Enterprise Search 8.x - Docker Compose example](https://discuss.elastic.co/t/enterprise-search-8-x-docker-compose-example/284811)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [September 22, 2021, 7:39am UTC](https://discuss.elastic.co/t/enterprise-search-8-x-docker-compose-example/284811 "2021-09-22T07:39:07Z")

</div>

Here is a simple way to start Enterprise Search (App Search and Workplace Search) with docker-compose . File: docker-compose.yml --- version: "2.2" services: setup: image: docker.elastic.co/elasticsearch/elastic…

---

## [Setup Elasticsearch SlowLog Alerts in Elastic Cloud](https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085)

<div class="topic-metadata">

**Author:** [@Stef\_Nestor](https://discuss.elastic.co/u/Stef_Nestor)\
**Replies:** 2\
**Last updated:** [October 18, 2021, 4:38pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-slowlog-alerts-in-elastic-cloud/283085 "2021-10-18T16:38:02Z")

</div>

Is there a way to setup email alerts for SlowLogs in Elasticsearch on Elastic Cloud?

---

## [Enterprise Search 7.x - Docker Compose example](https://discuss.elastic.co/t/enterprise-search-7-x-docker-compose-example/239782)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [July 3, 2020, 11:02am UTC](https://discuss.elastic.co/t/enterprise-search-7-x-docker-compose-example/239782 "2020-07-03T11:02:21Z")

</div>

Here is a simple way to start Enterprise Search (App Search and Workplace Search) with docker-compose. Elasticsearch File: docker-compose-elasticsearch.yml --- version: '3' services: elasticsearch: image: $IMG\_E…

---

## [Persist Elasticsearch/Kibana Keystores with Docker](https://discuss.elastic.co/t/persist-elasticsearch-kibana-keystores-with-docker/283099)

<div class="topic-metadata">

**Author:** [@Stef\_Nestor](https://discuss.elastic.co/u/Stef_Nestor)\
**Replies:** 1\
**Last updated:** [September 1, 2021, 10:08pm UTC](https://discuss.elastic.co/t/persist-elasticsearch-kibana-keystores-with-docker/283099 "2021-09-01T22:08:02Z")

</div>

Goal: persist Elasticsearch/Kibana keystores across Docker sessions by mounting data directory Common errors: Exception in thread "main" java.nio.file.FileSystemException: /usr/share/elasticsearch/config/elasticsearch…

---

## [Sorting a terms aggregation by keys case insensitive but display the original value](https://discuss.elastic.co/t/sorting-a-terms-aggregation-by-keys-case-insensitive-but-display-the-original-value/270087)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [April 14, 2021, 8:05am UTC](https://discuss.elastic.co/t/sorting-a-terms-aggregation-by-keys-case-insensitive-but-display-the-original-value/270087 "2021-04-14T08:05:31Z")

</div>

When you normalize a keyword field with a lowercase normalizer it becomes case insensitive but what if you want to display the "original" text? Here is a way to do that by using a top\_hits aggregation to fetch the text …

---

## [What is included in Cloud by Elastic?](https://discuss.elastic.co/t/what-is-included-in-cloud-by-elastic/266911)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [March 11, 2021, 9:07am UTC](https://discuss.elastic.co/t/what-is-included-in-cloud-by-elastic/266911 "2021-03-11T09:07:20Z")

</div>

Here are some useful links: Elastic Cloud Feature Matrix. It tells exactly what you could expect on cloud by elastic and the required license level for a given feature. You can check the pricing using the Pricing Calc…

---

## [How do I size my cluster?](https://discuss.elastic.co/t/how-do-i-size-my-cluster/249483)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 0\
**Last updated:** [September 22, 2020, 8:56am UTC](https://discuss.elastic.co/t/how-do-i-size-my-cluster/249483 "2020-09-22T08:56:06Z")

</div>

The ultimate answer is the 42 of IT aka It depends. Let's break this down and see, which factors come into play. It's rather hard to give exact advice here, as many factors come into play Your indexing load, how many …

---

## [How to retrieve all unique values from a given field](https://discuss.elastic.co/t/how-to-retrieve-all-unique-values-from-a-given-field/247312)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [September 3, 2020, 1:43am UTC](https://discuss.elastic.co/t/how-to-retrieve-all-unique-values-from-a-given-field/247312 "2020-09-03T01:43:37Z")

</div>

The quickest way to do this is to run a zero size, terms aggregation on the field. Using the Kibana sample log data set as an example, you would run; GET kibana\_sample\_data\_logs/\_search { "size": "0", "aggs": { …

---

## [Is it safe to expose Elasticsearch to the Internet?](https://discuss.elastic.co/t/is-it-safe-to-expose-elasticsearch-to-the-internet/247041)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [September 1, 2020, 5:29am UTC](https://discuss.elastic.co/t/is-it-safe-to-expose-elasticsearch-to-the-internet/247041 "2020-09-01T05:29:47Z")

</div>

TLDR - Elasticsearch is not designed to be exposed to the internet. To dig into this with more detail, here's more information taken from this topic. This page in the docs says: NOTE: Elasticsearch installations are …

---

## [Deleting log files after they have finished processing](https://discuss.elastic.co/t/deleting-log-files-after-they-have-finished-processing/246382)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [August 26, 2020, 4:17am UTC](https://discuss.elastic.co/t/deleting-log-files-after-they-have-finished-processing/246382 "2020-08-26T04:17:44Z")

</div>

Filebeat does not have the capabilities to handle deleting files from a host's filesystem after they have been processed. The best option is to use a cron job or scheduled task on your OS to delete them after a safe peri…

---

## [Why am I seeing a "FORBIDDEN/12/index read-only / allow delete" response against my index?](https://discuss.elastic.co/t/why-am-i-seeing-a-forbidden-12-index-read-only-allow-delete-response-against-my-index/244344)

<div class="topic-metadata">

**Author:** [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Replies:** 0\
**Last updated:** [August 10, 2020, 6:25am UTC](https://discuss.elastic.co/t/why-am-i-seeing-a-forbidden-12-index-read-only-allow-delete-response-against-my-index/244344 "2020-08-10T06:25:16Z")

</div>

You will usually see this error when your node(s) reach their flood stage disk level. When Elasticsearch detects a node's disk is nearing being full, it sets any index that the node holds to a read only state to protect…

---

## [What can Elastic SIEM be used for?](https://discuss.elastic.co/t/what-can-elastic-siem-be-used-for/244637)

<div class="topic-metadata">

**Author:** [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Replies:** 0\
**Last updated:** [August 11, 2020, 10:00pm UTC](https://discuss.elastic.co/t/what-can-elastic-siem-be-used-for/244637 "2020-08-11T22:00:46Z")

</div>

(This was originally posted in https://discuss.elastic.co/t/what-siem-can-do/244483/2, and has been slightly adapted) SIEM and security is very broad and has many different context's depending on your individual and com…

---

## [CircuitBreakingException - Data too large](https://discuss.elastic.co/t/circuitbreakingexception-data-too-large/243633)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [August 4, 2020, 1:16am UTC](https://discuss.elastic.co/t/circuitbreakingexception-data-too-large/243633 "2020-08-04T01:16:19Z")

</div>

Following on from this topic, we've extracted and expanded on this excellent explanation from @HenningAndersen. Seeing an error like this means that Elasticsearch prevented a request from executing to avoid an out of me…

---

## [How do I increase or reduce the shard count of an existing index?](https://discuss.elastic.co/t/how-do-i-increase-or-reduce-the-shard-count-of-an-existing-index/242704)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [July 27, 2020, 7:37am UTC](https://discuss.elastic.co/t/how-do-i-increase-or-reduce-the-shard-count-of-an-existing-index/242704 "2020-07-27T07:37:17Z")

</div>

Traditionally, once you created an index with a given number of primary shards, it was set until you reindexed your data. That meant that if you hit the limit of documents in a shard, you might have been caught in a bit …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/241217)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [July 15, 2020, 1:47am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/241217 "2020-07-15T01:47:48Z")

</div>

If you run into this there are a few things you can do to try resolve the error. Check Elasticsearch connectivity From your Kibana host, run curl -XGET es-ip-or-hostname:9200/, you should see a response like; { "name…

---

## [Pagination, Deep pagination and extraction of data](https://discuss.elastic.co/t/pagination-deep-pagination-and-extraction-of-data/238625)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [June 25, 2020, 8:58am UTC](https://discuss.elastic.co/t/pagination-deep-pagination-and-extraction-of-data/238625 "2020-06-25T08:58:23Z")

</div>

When you want to get more results than the default 10 first, you can use: the size and from parameters to display by default up to 10000 records to your users. If you want to change this limit, you can change index.max…

---

## [Composite aggregations and pagination](https://discuss.elastic.co/t/composite-aggregations-and-pagination/240268)

<div class="topic-metadata">

**Author:** [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Replies:** 0\
**Last updated:** [July 8, 2020, 6:10am UTC](https://discuss.elastic.co/t/composite-aggregations-and-pagination/240268 "2020-07-08T06:10:33Z")

</div>

Here's an example on how to do forward and reverse pagination with a composite aggregation. Example data, for use in Kibana's Dev Tools: POST test/\_doc { "date": "2020-01-01", "product": "a" } POST test/\_doc { "d…

---

## [What are ports 9200 and 9300 used for?](https://discuss.elastic.co/t/what-are-ports-9200-and-9300-used-for/238578)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [June 25, 2020, 12:51am UTC](https://discuss.elastic.co/t/what-are-ports-9200-and-9300-used-for/238578 "2020-06-25T00:51:06Z")

</div>

\[This is an extension on an older thread - Elasticsearch port 9200 or 9300?\] By default, Elasticsearch uses two ports to listen to external TCP traffic; Port 9200 is used for all API calls over HTTP. This includes se…

---

## [Should I increase my threadpool size if I get rejected executions or HTTP 429 responses?](https://discuss.elastic.co/t/should-i-increase-my-threadpool-size-if-i-get-rejected-executions-or-http-429-responses/241044)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0\
**Last updated:** [July 14, 2020, 2:23am UTC](https://discuss.elastic.co/t/should-i-increase-my-threadpool-size-if-i-get-rejected-executions-or-http-429-responses/241044 "2020-07-14T02:23:13Z")

</div>

Threadpools are described in the documentation as; A node uses several thread pools to manage memory consumption. Queues associated with many of the thread pools enable pending requests to be held instead of discarded. …

---

## [Stack - Docker Compose example](https://discuss.elastic.co/t/stack-docker-compose-example/238624)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [June 25, 2020, 8:56am UTC](https://discuss.elastic.co/t/stack-docker-compose-example/238624 "2020-06-25T08:56:10Z")

</div>

Here is how you can easily start Elasticsearch and Kibana with docker compose. Write the following in your docker-compose.yml file: --- version: '3' services: elasticsearch: image: docker.elastic.co/elasticsearc…

---

## [How should I encrypt data at rest with Elasticsearch?](https://discuss.elastic.co/t/how-should-i-encrypt-data-at-rest-with-elasticsearch/96)

<div class="topic-metadata">

**Author:** [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Replies:** 0\
**Last updated:** [May 1, 2015, 10:40am UTC](https://discuss.elastic.co/t/how-should-i-encrypt-data-at-rest-with-elasticsearch/96 "2015-05-01T10:40:15Z")

</div>

Note: while we recommend these options, we cannot provide support for any particular tool or help debugging issues with dm-crypt itself. For the purpose of protecting Data at Rest through encryption, from the Elasticsea…
