# Elasticsearch

**URL:** <https://discuss.elastic.co/t/elasticsearch/383028>\
**Category:** Elasticsearch\
**Tags:** ccs-cross-cluster-search\
**Created:** [October 27, 2025, 5:12pm UTC](https://discuss.elastic.co/t/elasticsearch/383028 "2025-10-27T17:12:13Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 27, 2025, 5:12pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/1 "2025-10-27T17:12:13Z")

</div>

‘‘‘  
Hi Folks,

#lasticsearch.yml file of node ip ending in 17 ( 8.15.2) still not upgraded  
’’’  
path.data: /var/lib/elasticsearch/data  
path.logs: /var/log/elasticsearch/logs

xpack.security.enabled: false  
xpack.security.enrollment.enabled: false

xpack.security.http.ssl:  
enabled: false  
keystore.path: certs/http.p12

xpack.security.transport.ssl:  
enabled: false  
verification\_mode: certificate  
keystore.path: certs/transport.p12  
truststore.path: certs/transport.p12

#cluster.initial\_master\_nodes:  
#- node1  
#- node2  
#- node3

network.host: localhost,192.168.0.10  
http.port: 9201

searchguard.enterprise\_modules\_enabled: false

thread\_pool.write.queue\_size: 1000

xpack.security.http.ssl.supported\_protocols:

- TLSv1.3  
xpack.security.transport.ssl.supported\_protocols:
- TLSv1.3

http.max\_content\_length: 500mb  
indices.query.bool.max\_clause\_count: 200000  
thread\_pool.search.size: 50

searchguard.ssl.transport.pemkey\_filepath: node.key  
searchguard.ssl.transport.pemcert\_filepath: node-cert.pem  
searchguard.ssl.transport.pemtrustedcas\_filepath: ca-cert.pem  
searchguard.ssl.transport.enforce\_hostname\_verification: false  
searchguard.ssl.transport.enabled\_protocols:

- TLSv1.2
- TLSv1.3

searchguard.ssl.http.pemkey\_filepath: node.key  
searchguard.ssl.http.pemcert\_filepath: node-cert.pem  
searchguard.ssl.http.pemtrustedcas\_filepath: ca-cert.pem  
searchguard.ssl.http.enabled: true

searchguard.ssl.http.enabled\_ciphers:

- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384
- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256
- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384
- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256
- TLS\_AES\_256\_GCM\_SHA384
- TLS\_CHACHA20\_POLY1305\_SHA256
- TLS\_AES\_128\_GCM\_SHA256
- TLS\_AES\_128\_CCM\_8\_SHA256
- TLS\_AES\_128\_CCM\_SHA256

searchguard.ssl.http.enabled\_protocols:

- TLSv1.2
- TLSv1.3

searchguard.authcz.admin\_dn:

- [emailAddress=admin@example.com](mailto:emailAddress=admin@example.com),CN=signed-cert,OU=IT,O=ExampleOrg,L=City,ST=State,C=US

searchguard.nodes\_dn:

- [emailAddress=admin@example.com](mailto:emailAddress=admin@example.com),CN=signed-cert,OU=IT,O=ExampleOrg,L=City,ST=State,C=US

searchguard.check\_snapshot\_restore\_write\_privileges: true

searchguard.restapi.roles\_enabled:

- SGS\_ALL\_ACCESS

discovery.seed\_hosts:

- 192.168.0.11
- 192.168.0.12
- 192.168.0.13

cluster.name: elasticsearch  
node.name: node1  
node.roles: [master]

bootstrap.memory\_lock: true  
’’’

I was upgrading two data nodes first from ES8.15.2 to 8.19.3 of three nodes cluster.  
Cluster is not forming. node with Ip1 and node with ip2 are upgraded from 8.15.2 to 8.19.3 and on master-only node3 there is still ES 8.15.2 running.

ES service is up and running on are three nodes. On two nodes ES8.19.3 is installed and on third one ES8.15.2 is installed.

Below is curl command to list all cluster nodes, Its output throws an error as  
master\_not\_discovered\_exception

#curl -XGET -u user:pass [https://localhost:9201/\_cat/nodes?v](https://localhost:9201/_cat/nodes?v) -k  
{"error":{"root\_cause":[{"type":"master\_not\_discovered\_exception","reason":null}],"type":"master\_not\_discovered\_exception","reason":null},"status":503}[root@localhost Elasticsearch]#

#yaml file of ip1 ES8.19.3 Data node with ssl  
[root@localhost Elasticsearch]# vi /etc/elasticsearch/elasticsearch.yml  
path.data: /var/lib/elasticsearch/elasticsearch  
path.logs: /var/log/elasticsearch/elasticsearch  
xpack.security.enabled: true  
xpack.security.enrollment.enabled: false  
xpack.security.http.ssl:  
enabled: true  
key: cenode.key  
certificate: cecert.pem  
certificate\_authorities: cacert.pem  
xpack.security.transport.ssl:  
enabled: true  
verification\_mode: certificate  
key: cenode.key  
certificate: cecert.pem  
certificate\_authorities: cacert.pem  
cluster.initial\_master\_nodes:

- ip1

- ip2

- ip3  
network.host: localhost,ip1  
http.port: 9201  
http.max\_content\_length: 500mb  
indices.query.bool.max\_clause\_count: 200000  
thread\_pool.write.queue\_size: 1000  
thread\_pool.search.size: 50  
xpack.security.http.ssl.supported\_protocols:

- TLSv1.2

- TLSv1.3  
xpack.security.http.ssl.cipher\_suites:

- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384

- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256

- TLS\_AES\_256\_GCM\_SHA384

- TLS\_CHACHA20\_POLY1305\_SHA256

- TLS\_AES\_128\_GCM\_SHA256

- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384

- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256

- TLS\_AES\_128\_CCM\_8\_SHA256

- TLS\_AES\_128\_CCM\_SHA256  
xpack.security.transport.ssl.supported\_protocols:

- TLSv1.2

- TLSv1.3  
discovery.seed\_hosts:

- ip1

- ip2

- ip3  
cluster.name: elasticsearch  
node.name: localhost  
node.roles: [data, master]  
bootstrap.memory\_lock: true

[root@localhost Elasticsearch]# vi /etc/elasticsearch/elasticsearch.yml  
path.data: /var/lib/elasticsearch/elasticsearch  
path.logs: /var/log/elasticsearch/elasticsearch  
xpack.security.enabled: true  
xpack.security.enrollment.enabled: false  
xpack.security.http.ssl:  
enabled: true  
key: cenode.key  
certificate: cecert.pem  
certificate\_authorities: cacert.pem  
xpack.security.transport.ssl:  
enabled: true  
verification\_mode: certificate  
key: cenode.key  
certificate: cecert.pem  
certificate\_authorities: cacert.pem  
cluster.initial\_master\_nodes:

- ip1
- ip2
- ip3  
network.host: localhost,ip2  
http.port: 9201  
http.max\_content\_length: 500mb  
indices.query.bool.max\_clause\_count: 200000  
thread\_pool.write.queue\_size: 1000  
thread\_pool.search.size: 50  
xpack.security.http.ssl.supported\_protocols:
- TLSv1.2
- TLSv1.3  
xpack.security.http.ssl.cipher\_suites:
- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384
- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256
- TLS\_AES\_256\_GCM\_SHA384
- TLS\_CHACHA20\_POLY1305\_SHA256
- TLS\_AES\_128\_GCM\_SHA256
- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384
- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256
- TLS\_AES\_128\_CCM\_8\_SHA256
- TLS\_AES\_128\_CCM\_SHA256  
xpack.security.transport.ssl.supported\_protocols:
- TLSv1.2
- TLSv1.3  
discovery.seed\_hosts:
- ip1
- ip2
- ip3  
cluster.name: elasticsearch  
node.name: localhost  
node.roles: [data, master]  
bootstrap.memory\_lock: true

#curl command to list all cluster nodes  
’curl -XGET -u user:pass [https://localhost:9201/\_cat/nodes?v](https://localhost:9201/_cat/nodes?v) -k’  
’’’  
{"error":{"root\_cause":[{"type":"master\_not\_discovered\_exception","reason":null}],"type":"master\_not\_discovered\_exception","reason":null},"status":503}[root@localhost Elasticsearch]#  
’’’

Usually cluster forms but sometime I got stuck at this problem.

‘‘‘  
#Logs elasticsearch.log  
see [Troubleshooting discovery | Elasticsearch Guide [8.19] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.19/discovery-troubleshooting.html)  
[2025-10-28T09:56:30,853][INFO][o.e.c.c.ElectionSchedulerFactory] [localhostjimmysecond] retrying master election after [390] failed attempts; election attempts are currently scheduled up to [10000ms] apart  
[2025-10-28T09:56:38,866][WARN][o.e.c.c.ClusterFormationFailureHelper] [localhostjimmysecond] master not discovered or elected yet, an election requires 2 nodes with ids [wCc8I8nFRGu3aEAgy7BO2g, O8-JnJJnSc-mW69ho5b9hw], have discovered possible quorum [{localhostjimmysecond}{wCc8I8nFRGu3aEAgy7BO2g}{vMo5\_Gk7RL-oHo26dec0Gw}{localhostjimmysecond}{X.X.97.18}{X.X97.18:9300}{dm}{8.19.3}{7000099-8536000}, {localhost.localdomain}{O8-JnJJnSc-mW69ho5b9hw}{3MF2LSx4Q1esTwGbKpxO9Q}{localhost.localdomain}{X.X.97.17}{X.X.97.17:9300}{m}{8.15.2}{7000099-8512000}, {localhostjimmy}{iWBhVh\_4R82to5nuOd9PRA}{TAYCLd2oRlWrF0JnrkRLAw}{localhostjimmy}{X.X.97.19}{X.X97.19:9300}{dm}{8.19.3}{7000099-8536000}]; discovery will continue using [X.X.97.19:9300, X.X.97.17:9300] from hosts providers and [{localhostjimmysecond}{wCc8I8nFRGu3aEAgy7BO2g}{vMo5\_Gk7RL-oHo26dec0Gw}{localhostjimmysecond}{X.X.97.18}{X.X.97.18:9300}{dm}{8.19.3}{7000099-8536000}] from last-known cluster state; node term 0, last-accepted version 0 in term 0; for troubleshooting guidance, see [Troubleshooting discovery | Elasticsearch Guide [8.19] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.19/discovery-troubleshooting.html)  
[2025-10-28T09:56:48,867][WARN][o.e.c.c.ClusterFormationFailureHelper] [localhostjimmysecond] master not discovered or elected yet, an election requires 2 nodes with ids [wCc8I8nFRGu3aEAgy7BO2g, O8-JnJJnSc-mW69ho5b9hw], have discovered possible quorum [{localhostjimmysecond}{wCc8I8nFRGu3aEAgy7BO2g}{vMo5\_Gk7RL-oHo26dec0Gw}{localhostjimmysecond}{X.X97.18}{X.X.97.18:9300}{dm}{8.19.3}{7000099-8536000}, {localhost.localdomain}{O8-JnJJnSc-mW69ho5b9hw}{3MF2LSx4Q1esTwGbKpxO9Q}{localhost.localdomain}{X.X97.17}{X.X97.17:9300}{m}{8.15.2}{7000099-8512000}, {localhostjimmy}{iWBhVh\_4R82to5nuOd9PRA}{TAYCLd2oRlWrF0JnrkRLAw}{localhostjimmy}{X.X97.19}{X.X.97.19:9300}{dm}{8.19.3}{7000099-8536000}]; discovery will continue using [X.X97.19:9300, X.X.97.17:9300] from hosts providers and [{localhostjimmysecond}{wCc8I8nFRGu3aEAgy7BO2g}{vMo5\_Gk7RL-oHo26dec0Gw}{localhostjimmysecond}{X.X.97.18}{X.X.97.18:9300}{dm}{8.19.3}{7000099-8536000}] from last-known cluster state; node term 0, last-accepted version 0 in term 0; for troubleshooting guidance, see [Troubleshooting discovery | Elasticsearch Guide [8.19] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.19/discovery-troubleshooting.html)  
’’’

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [October 28, 2025, 1:22am UTC](https://discuss.elastic.co/t/elasticsearch/383028/2 "2025-10-28T01:22:47Z")

</div>

Try to edit the message and better format the logs and config files please. Its is very difficult to read your message. You appear to have cluster.initial\_master\_nodes set on the 2 configuration files you did share. Those settings are not needed after the 3-node cluster has fully formed. discovery.seed\_hosts should be enough. There is often a message telling you this in the logs.

Since you have 3 nodes in your cluster, please share all 3 nodes configuration and logs.

Correct anything I got wrong - your cluster was 3 nodes but only 2 of these (ip1 + ip2) were data nodes. And only one of those data nodes (ip1) has been updated to 8.19.3, along with master-only ip3 ? The 3 nodes in your cluster appear to be called, localhostjimmy == ip1, localhostjimmysecond == ip2 , localhost.localdomain == ip3, IMHO thats poor node naming but shouldn’t really matter.

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 28, 2025, 2:58am UTC](https://discuss.elastic.co/t/elasticsearch/383028/3 "2025-10-28T02:58:38Z")

</div>

Hi RainTown, thanks for your reply.

It was a three nodes cluster(8.15.2) installed. Then I have started upgrade.

In Upgrade , in my environment it uninstall Old ES(8.15.2) and then Fresh install 8.19.3.

I have started upgrade on node with ip1 and ip2 . Now On node (ip1+ip2) are upgraded to 8.19.3 as data nodes.  
3rd node with ip3 still has (8.15.2) master node installed.  
That’s why cluster.initial\_master\_nodes: setting is not comented out.

On Third node there is still ES8.15.2 is installed.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 28, 2025, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/4 "2025-10-28T13:41:04Z")

</div>

Can you share the 3 configuration files correctly formatted?

Use the prefromatted text button, the `</>` to format them, it is really complicated to understand what is the issue and what are the configuration files.

But a couple of things, once a cluster has formed, you need to remove the `cluster.initial_master_nodes`, unless you removed all data of all nodes, and are starting a fresh cluster, you need to remove this from all configuration files.

If you upgrade 2 nodes to 8.19.3, you also need to upgrade the last one, a node on version 8.15.2 will not join a cluster with master nodes on 8.19.3.

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 28, 2025, 1:55pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/5 "2025-10-28T13:55:26Z")

</div>

“If you upgrade 2 nodes to 8.19.3, you also need to upgrade the last one, a node on version 8.15.2 will not join a cluster with master nodes on 8.19.3.”

Yes but usually two nodes cluster forms. If I start upgrading third node then Yes cluster will form. But now two nodes cluster is not forming . Curl command is throwing this error

curl -XGET -u username:password [https://localhost:9201/\_cat/nodes?v](https://localhost:9201/_cat/nodes?v) -k

{"error":{"root\_cause":[{"type":"master\_not\_discovered\_exception","reason":null}],"type":"master\_not\_discovered\_exception","reason":null},"status":503}[root@localhostjimmy ~]

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 28, 2025, 2:14pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/6 "2025-10-28T14:14:21Z")

</div>

You need to share the formatted configuration as asked to make it easier to understand how your cluster is configured.

If you have 2 cluster on the same version and they are not forming a cluster, then probably there is something wrong in your configuration.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [October 28, 2025, 2:45pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/7 "2025-10-28T14:45:24Z")

</div>

> [@Varinder](#):
>
> If I start upgrading third node then Yes cluster will form. But now two nodes cluster is not forming

Er, whats your reason for not upgrading the 3rd node? You are going to have to do this at some point.

> [@Varinder](#):
>
> 3rd node with ip3 still has (8.15.2) master node installed.

It’s not a “master node” any more, and it wont be again until you upgrade.

But as told already, you should remove the `cluster.initial_master_nodes` from the config file, on assumption you had a working 3-node cluster, and you didn’t “wipe everything” on the 2 nodes you already upgraded.

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 28, 2025, 2:58pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/8 "2025-10-28T14:58:35Z")

</div>

Yes, I am going to upgrade third node eventually . Actually when I upgrade third node then cluster forms also.

But 8/10 two node cluster also forms. But why this time its not happening.  
Yes, I do remove cluster.initial\_master\_nodes setting once cluster is formed. But now cluster is not formed yet. Thats why this setting is not removed.

Question is this, why I get this error

’curl -XGET -u user:pass [https://localhost:9201/\_cat/nodes?v](https://localhost:9201/_cat/nodes?v) -k’  
’{"error":{"root\_cause":[{"type":"master\_not\_discovered\_exception","reason":null}],"type":"master\_not\_discovered\_exception","reason":null},"status":503}’

Any official documentation which states about these errors attached in elasticsearch.logs and how can I remove them.

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [October 28, 2025, 3:20pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/9 "2025-10-28T15:20:18Z")

</div>

OK, sorry, but you are not articulating clearly what you are trying to do/prove/demonstrate/…

Me, I’d rather completely my upgrade, get my cluster formed, and go on to the next task. It’s an old school approach I know, but it’s served me pretty well 🙂

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 28, 2025, 3:33pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/10 "2025-10-28T15:33:34Z")

</div>

Yes! I completely agree with you. But its a design/requirement by my company ”two node cluster should form”.  
I am doing R&D now.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 28, 2025, 3:44pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/11 "2025-10-28T15:44:24Z")

</div>

If you had this cluster working before on a previous version, you should remove the `cluster.initial_master_nodes` setting, it doesn't matter if you are going to upgrade, shutdown everything etc, once a cluster is bootstraped the first time, this setting should be removed.

> But its a design/requirement by my company ”two node cluster should form”.

This is not exactly how elasticsearch works, if you have a cluster running with 3 master nodes and you lose one of them, your cluster will still work with 2 master nodes running.

But If you shutdown your nodes, to form a cluster again the master election process needs a quorum to form a majority, which is not possible with just 2 nodes running, so you need to upgrade your third node to the same version as the others and start it.

I recommend that you check this [documentation](https://www.elastic.co/docs/deploy-manage/distributed-architecture/discovery-cluster-formation/modules-discovery-quorums).

Check the important note on the documentation page.

> If you stop half or more of the nodes in the voting configuration at the same time then **the cluster will be unavailable until you bring enough nodes back online to form a quorum again**. While the cluster is unavailable, any remaining nodes will report in their logs that they cannot discover or elect a master node.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 28, 2025, 4:52pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/12 "2025-10-28T16:52:38Z")

</div>

> [@Varinder](#):
>
> node.name: localhost

Do both the nodes you posted config for have the same node name?

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 28, 2025, 7:06pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/13 "2025-10-28T19:06:07Z")

</div>

Yes @Christian_Dahlqvist

Both nodes have same nodename

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 28, 2025, 7:18pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/14 "2025-10-28T19:18:25Z")

</div>

I have always thought node names need to be unique, but do not see this mentioned [in the documentation](https://www.elastic.co/docs/deploy-manage/deploy/self-managed/important-settings-configuration#node-name). Was this configured the same way in the old version or is this something that may have changed?

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 28, 2025, 8:03pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/15 "2025-10-28T20:03:20Z")

</div>

Not sure about old one, but in ES8 I usually use as default nodename.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 28, 2025, 8:25pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/16 "2025-10-28T20:25:26Z")

</div>

I think it is a recommendation, it is pretty common to have a unique node name as using the same node name for multiple nodes is really confusing and does not make much sense, but I don't think it does anything else, the node uses the node id to talk with each other and know about each node.

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 29, 2025, 3:32am UTC](https://discuss.elastic.co/t/elasticsearch/383028/17 "2025-10-29T03:32:39Z")

</div>

#I have just added elasticsearch.yml file info for 3rd node(8.15.2)  
’’’  
path.data: /var/lib/elasticsearch/data  
path.logs: /var/log/elasticsearch/logs

xpack.security.enabled: false  
xpack.security.enrollment.enabled: false

xpack.security.http.ssl:  
enabled: false  
keystore.path: certs/http.p12

xpack.security.transport.ssl:  
enabled: false  
verification\_mode: certificate  
keystore.path: certs/transport.p12  
truststore.path: certs/transport.p12

#cluster.initial\_master\_nodes:  
#- node1  
#- node2  
#- node3

network.host: localhost,ip3  
http.port: 9201

searchguard.enterprise\_modules\_enabled: false

thread\_pool.write.queue\_size: 1000

xpack.security.http.ssl.supported\_protocols:

- TLSv1.3  
xpack.security.transport.ssl.supported\_protocols:
- TLSv1.3

http.max\_content\_length: 500mb  
indices.query.bool.max\_clause\_count: 200000  
thread\_pool.search.size: 50

searchguard.ssl.transport.pemkey\_filepath: node.key  
searchguard.ssl.transport.pemcert\_filepath: node-cert.pem  
searchguard.ssl.transport.pemtrustedcas\_filepath: ca-cert.pem  
searchguard.ssl.transport.enforce\_hostname\_verification: false  
searchguard.ssl.transport.enabled\_protocols:

- TLSv1.2
- TLSv1.3

searchguard.ssl.http.pemkey\_filepath: node.key  
searchguard.ssl.http.pemcert\_filepath: node-cert.pem  
searchguard.ssl.http.pemtrustedcas\_filepath: ca-cert.pem  
searchguard.ssl.http.enabled: true

searchguard.ssl.http.enabled\_ciphers:

- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384
- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_CBC\_SHA256
- TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384
- TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256
- TLS\_AES\_256\_GCM\_SHA384
- TLS\_CHACHA20\_POLY1305\_SHA256
- TLS\_AES\_128\_GCM\_SHA256
- TLS\_AES\_128\_CCM\_8\_SHA256
- TLS\_AES\_128\_CCM\_SHA256

searchguard.ssl.http.enabled\_protocols:

- TLSv1.2
- TLSv1.3

searchguard.authcz.admin\_dn:

- [emailAddress=admin@example.com](mailto:emailAddress=admin@example.com),CN=signed-cert,OU=IT,O=ExampleOrg,L=City,ST=State,C=US

searchguard.nodes\_dn:

- [emailAddress=admin@example.com](mailto:emailAddress=admin@example.com),CN=signed-cert,OU=IT,O=ExampleOrg,L=City,ST=State,C=US

searchguard.check\_snapshot\_restore\_write\_privileges: true

searchguard.restapi.roles\_enabled:

- SGS\_ALL\_ACCESS

discovery.seed\_hosts:

- node1
- node2
- node3

cluster.name: elasticsearch  
node.name: node3  
node.roles: [master]

bootstrap.memory\_lock: true  
’’’

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 29, 2025, 5:40am UTC](https://discuss.elastic.co/t/elasticsearch/383028/18 "2025-10-29T05:40:22Z")

</div>

> [@Varinder](#):
>
> xpack.security.enabled: false

> [@Varinder](#):
>
> searchguard.ssl.transport.pemkey\_filepath: node.key  
> searchguard.ssl.transport.pemcert\_filepath: node-cert.pem  
> searchguard.ssl.transport.pemtrustedcas\_filepath: ca-cert.pem  
> searchguard.ssl.transport.enforce\_hostname\_verification: false

It looks like you are trying to use Searchguard. Is this only configured on one node or have you removed this config from the other nodes you posted earlier?

The security config need to be the same across the whole cluster and you can not use Elastic security on some nodes and Searchguard on some. Searchguard is also a third party plugin that is not supported here so if you are looking to use this I would recommend you reach out to that community.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 29, 2025, 12:13pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/19 "2025-10-29T12:13:40Z")

</div>

Have you read the shared documentation on my previous answer? This [one](https://www.elastic.co/docs/deploy-manage/distributed-architecture/discovery-cluster-formation/modules-discovery-quorums) ?

If your 2 other nodes are already on 8.19.2 this node will never join the cluster until it is upgrade, if your 2 other nodes also cannot form a cluster, they will also not form a cluster until you have a majority quorum, so you need 3 nodes running to form the cluster again.

Also, you are using searchguard, which is a third-party plugin that is not supported here and that has impact on the communication between nodes, we cannot provide any insight about it because mostly people here do not use it.

You need to upgrade your last node and see if you can form a cluster, if not, you should remove all searchguard configurations and try using only native elasticsearch settings to see if the issue persists.

---

<div class="post-metadata">

**Author:** ![Varinder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/varinder/32/123243_2.png) [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Post date:** [October 29, 2025, 12:53pm UTC](https://discuss.elastic.co/t/elasticsearch/383028/20 "2025-10-29T12:53:50Z")

</div>

Thanks @leandrojmp  
Yes! upgrade to third node forms the cluster. In Previous package we were using searchguard in 8.15.2 and now we have removed searchguard completely.

Actually this is a blocker bug in my company (Upgraded ES 8.19.3 should form a cluster should form. Eventually I have to solve this.

I have try to stop service on .17 node (ES8.15.2) then delete data and then restarting on two nodes 8.19.3. But all unvain.  
rm -rf /var/lib/elasticsearch/nodes

Same output:  
{"error":{"root\_cause":[{"type":"master\_not\_discovered\_exception","reason":null}],"type":"master\_not\_discovered\_exception","reason":null},"status":503}

[Next page](https://discuss.elastic.co/t/elasticsearch/383028.md?page=2)
