# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=528

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 529

---

## [Is java API Client 7.16 be used with Elasticsearch version 7.9.2?](https://discuss.elastic.co/t/is-java-api-client-7-16-be-used-with-elasticsearch-version-7-9-2/315465)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 1:57pm UTC](https://discuss.elastic.co/t/is-java-api-client-7-16-be-used-with-elasticsearch-version-7-9-2/315465 "2022-09-29T13:57:26Z")

</div>

Hi all. Sorry if this very obvious question. As per documentation The Elasticsearch Java client is forward compatible; meaning that the client supports communicating with greater or equal minor versions of Elasticsearc…

---

## [Is Fuzzy sentence search in elasticsearch based on edit distance of words?](https://discuss.elastic.co/t/is-fuzzy-sentence-search-in-elasticsearch-based-on-edit-distance-of-words/315464)

<div class="topic-metadata">

**Author:** [@swapnil3597](https://discuss.elastic.co/u/swapnil3597)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 1:57pm UTC](https://discuss.elastic.co/t/is-fuzzy-sentence-search-in-elasticsearch-based-on-edit-distance-of-words/315464 "2022-09-29T13:57:19Z")

</div>

For a given index I have added documents like: \[ {"expression": "tell me something about elasticsearch"}, {"expression": "this is a new feature for elasticsearch"}, {"expression": "tell me something about kibana"}, # ..…

---

## [Easiest way to decrease Persistent Volume size?](https://discuss.elastic.co/t/easiest-way-to-decrease-persistent-volume-size/315415)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 2\
**Last updated:** [September 29, 2022, 1:38pm UTC](https://discuss.elastic.co/t/easiest-way-to-decrease-persistent-volume-size/315415 "2022-09-29T13:38:09Z")

</div>

Hello, I am trying to decrease the storage size of our Persistent Volumes in a particular cluster while still retaining all the data that is currently on the existing Persistent Volumes. The storage is currently over-pr…

---

## [Heartbeat.config.monitors path to c:/program files](https://discuss.elastic.co/t/heartbeat-config-monitors-path-to-c-program-files/315458)

<div class="topic-metadata">

**Author:** [@miguelbatista](https://discuss.elastic.co/u/miguelbatista)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 1:35pm UTC](https://discuss.elastic.co/t/heartbeat-config-monitors-path-to-c-program-files/315458 "2022-09-29T13:35:59Z")

</div>

Hi, I've installed Heartbeat on a Windows server VM in here "C:\\Program Files\\Heartbeat" and can't get heartbeat.yml config.monitors path right to read the monitors.d files.

---

## [Elasticsearch "snapshot\_restore\_exception" "reason": snapshot does not exist" when snapshot status is SUCCESS](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-exception-reason-snapshot-does-not-exist-when-snapshot-status-is-success/315457)

<div class="topic-metadata">

**Author:** [@arozaki](https://discuss.elastic.co/u/arozaki)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 1:24pm UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-exception-reason-snapshot-does-not-exist-when-snapshot-status-is-success/315457 "2022-09-29T13:24:49Z")

</div>

I am using the Java/Groovy client for Elasticsearch and I am trying to restore an ES snapshot during an upgrade. I am using the Groovy code I have so far for setting up my old and new clients and making them create & res…

---

## [Query document array is a subset of search input](https://discuss.elastic.co/t/query-document-array-is-a-subset-of-search-input/315419)

<div class="topic-metadata">

**Author:** [@bwly](https://discuss.elastic.co/u/bwly)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 1:03pm UTC](https://discuss.elastic.co/t/query-document-array-is-a-subset-of-search-input/315419 "2022-09-29T13:03:13Z")

</div>

I have document that has the this array attribute {array\_attr: \[ { id: "A", name: "A\_name" }, { id: "B", name: "B\_name" }, { id: "C", name: "B\_name" } \]} In my search query, I have…

---

## [Issue with implement proxy in elasticsearch/kibana](https://discuss.elastic.co/t/issue-with-implement-proxy-in-elasticsearch-kibana/315452)

<div class="topic-metadata">

**Author:** [@lgriger](https://discuss.elastic.co/u/lgriger)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 12:41pm UTC](https://discuss.elastic.co/t/issue-with-implement-proxy-in-elasticsearch-kibana/315452 "2022-09-29T12:41:23Z")

</div>

elasticsearch config xpack.http.proxy.host: http:// xpack.http.proxy.port: 8080 xpack.http.proxy.scheme:http kibana config xpack.fleet.registryProxyUrl: http://\<user:password@url\> xpack.actions.proxyUrl: http://\<us…

---

## [Stemming and the near span query](https://discuss.elastic.co/t/stemming-and-the-near-span-query/315449)

<div class="topic-metadata">

**Author:** [@af1](https://discuss.elastic.co/u/af1)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 11:51am UTC](https://discuss.elastic.co/t/stemming-and-the-near-span-query/315449 "2022-09-29T11:51:59Z")

</div>

Hello community, hope to get your help on an issue we are having, we are using the english stemming and are running a near span query that basically searches for "buying near before" now if I search for a match phras…

---

## [Search\_phase\_execution\_exception in partitioned terms aggregation](https://discuss.elastic.co/t/search-phase-execution-exception-in-partitioned-terms-aggregation/315443)

<div class="topic-metadata">

**Author:** [@Sederfo](https://discuss.elastic.co/u/Sederfo)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 10:00am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-in-partitioned-terms-aggregation/315443 "2022-09-29T10:00:04Z")

</div>

I have an index which contains millions of documents that I want to aggregate. This is the query I am using to obtain the aggregated results. aggs = { "0": { "terms": { …

---

## [Convert es (Bucket aggregation) query to java](https://discuss.elastic.co/t/convert-es-bucket-aggregation-query-to-java/315321)

<div class="topic-metadata">

**Author:** [@Shubh](https://discuss.elastic.co/u/Shubh)\
**Replies:** 8\
**Last updated:** [September 29, 2022, 9:15am UTC](https://discuss.elastic.co/t/convert-es-bucket-aggregation-query-to-java/315321 "2022-09-29T09:15:05Z")

</div>

Hi, Can anyone help me convert this query in java program and how would i get only the aggreagtion result from query. The query is given below. GET /\_search { "size": 0, "query": { "bool": { "filter": \[ …

---

## [How to create a kibana dashboard which could search through index relations?](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Replies:** 8\
**Last updated:** [September 29, 2022, 8:25am UTC](https://discuss.elastic.co/t/how-to-create-a-kibana-dashboard-which-could-search-through-index-relations/315276 "2022-09-29T08:25:16Z")

</div>

Hi everybody I have 3 different indices, A, B and C A and B both sharing a field suppose F1 B and C also sharing another field suppose F2 I've added 3 different saved search to a dash board. So when I want to sear…

---

## [Rolling Restart doubt](https://discuss.elastic.co/t/rolling-restart-doubt/315429)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 2\
**Last updated:** [September 29, 2022, 7:49am UTC](https://discuss.elastic.co/t/rolling-restart-doubt/315429 "2022-09-29T07:49:01Z")

</div>

hello! i have a cluster with 20 data nodes, 3 masters and 2 ml. We want to do a rolling restart so that there is no loss of service. i know the method to follow.... disable shard allocation, temporarily stop ml jobs, r…

---

## [Import Elastic DNF/Yum repos into Artifactory](https://discuss.elastic.co/t/import-elastic-dnf-yum-repos-into-artifactory/315375)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 0\
**Last updated:** [September 28, 2022, 1:05pm UTC](https://discuss.elastic.co/t/import-elastic-dnf-yum-repos-into-artifactory/315375 "2022-09-28T13:05:03Z")

</div>

I want to include this repo. \[elastic-8.x\] name=Elastic repository for 8.x packages baseurl=https://artifacts.elastic.co/packages/8.x/yum gpgcheck=1 gpgkey=https://artifacts.elastic.co/GPG-KEY-elasticsearch enabled=1 au…

---

## [Windows system configuration](https://discuss.elastic.co/t/windows-system-configuration/315427)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 6:46am UTC](https://discuss.elastic.co/t/windows-system-configuration/315427 "2022-09-29T06:46:24Z")

</div>

In documentation there are explanation on configuration related to Linux, such file descriptor, virtual memory, etc. Is there any special configuration for Windows?

---

## [Elastic-operator "Shutting down due to signal"](https://discuss.elastic.co/t/elastic-operator-shutting-down-due-to-signal/315352)

<div class="topic-metadata">

**Author:** [@lnx](https://discuss.elastic.co/u/lnx)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 6:05am UTC](https://discuss.elastic.co/t/elastic-operator-shutting-down-due-to-signal/315352 "2022-09-29T06:05:44Z")

</div>

The elastic operator pod stops and comes up again every 3-4 min. Just before it stops I see this in the logs {"log.level":"info","@timestamp":"2022-09-28T09:52:42.062Z","log.logger":"manager","message":"Shutting down du…

---

## [Elasticsearch \[6.8\] Shard distribution based on traffic](https://discuss.elastic.co/t/elasticsearch-6-8-shard-distribution-based-on-traffic/315422)

<div class="topic-metadata">

**Author:** [@srivatsa](https://discuss.elastic.co/u/srivatsa)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 5:32am UTC](https://discuss.elastic.co/t/elasticsearch-6-8-shard-distribution-based-on-traffic/315422 "2022-09-29T05:32:37Z")

</div>

Hi Folks, We are seeing scenarios where the cluster is allocating 6 -10 shards(primaries & replicas) of an index with shard sizes around 50GB on a single node of the cluster even though all nodes in the cluster are of t…

---

## [Logstash 8.4.2 Extremely High CPU Loading](https://discuss.elastic.co/t/logstash-8-4-2-extremely-high-cpu-loading/315417)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 3\
**Last updated:** [September 29, 2022, 4:35am UTC](https://discuss.elastic.co/t/logstash-8-4-2-extremely-high-cpu-loading/315417 "2022-09-29T04:35:38Z")

</div>

My Logstash loading has been about avg. ~10% loading for couple months. Without any change on grokking and configuration, even event/s is about the same rate, just upgrading my Logstash to v8.4.2 causing CPU loading jump…

---

## [Extract attribute from XML field in search results](https://discuss.elastic.co/t/extract-attribute-from-xml-field-in-search-results/315420)

<div class="topic-metadata">

**Author:** [@Eddie\_Vuong](https://discuss.elastic.co/u/Eddie_Vuong)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 3:45am UTC](https://discuss.elastic.co/t/extract-attribute-from-xml-field-in-search-results/315420 "2022-09-29T03:45:20Z")

</div>

I have a field that contains XML string in my data and I want to, instead of retrieving the full XML, extract a few attributes from it in the final results. In practice I can do it using Python (query all the needed dat…

---

## [Kibana dashboard error](https://discuss.elastic.co/t/kibana-dashboard-error/315332)

<div class="topic-metadata">

**Author:** [@wodhgud](https://discuss.elastic.co/u/wodhgud)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 2:19am UTC](https://discuss.elastic.co/t/kibana-dashboard-error/315332 "2022-09-29T02:19:28Z")

</div>

I am currently using version 7.11.1. When dashboarding in kibana " \[parent\] data too large, data for \[index:data/read/search\[step/query\]\] is \[1045822710/997.3mb\], It is larger than the limit of \[1020054732/972.7mb\]. A…

---

## [Uptime Monitor Status Rule / Alert , Which field is considered to filter?](https://discuss.elastic.co/t/uptime-monitor-status-rule-alert-which-field-is-considered-to-filter/314200)

<div class="topic-metadata">

**Author:** [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Replies:** 3\
**Last updated:** [September 28, 2022, 10:56pm UTC](https://discuss.elastic.co/t/uptime-monitor-status-rule-alert-which-field-is-considered-to-filter/314200 "2022-09-28T22:56:34Z")

</div>

Hello Experts, I have configured Heartbeat. To reduce the data , I have used "include fields" processor as below. So, now I get data for below fields and metadata fields (default). the issue is , in "Uptime Monitor …

---

## [Logstash Failed to install template Error 400](https://discuss.elastic.co/t/logstash-failed-to-install-template-error-400/315403)

<div class="topic-metadata">

**Author:** [@fformoso](https://discuss.elastic.co/u/fformoso)\
**Replies:** 0\
**Last updated:** [September 28, 2022, 8:34pm UTC](https://discuss.elastic.co/t/logstash-failed-to-install-template-error-400/315403 "2022-09-28T20:34:39Z")

</div>

Dear all, I need help to understand root cause, I can add the template via api, but not using logstash 8.3 I've tried to fix it adding diferent roles to user =\> "logstash\_writer" and didnt work Error: \[2022-09-28T17…

---

## [How to display exact match and variations after](https://discuss.elastic.co/t/how-to-display-exact-match-and-variations-after/315394)

<div class="topic-metadata">

**Author:** [@Guilherme\_Mello](https://discuss.elastic.co/u/Guilherme_Mello)\
**Replies:** 1\
**Last updated:** [September 28, 2022, 5:47pm UTC](https://discuss.elastic.co/t/how-to-display-exact-match-and-variations-after/315394 "2022-09-28T17:47:34Z")

</div>

How can I display first the exact match and search variations after? example: query: all star results: all star red (exact) all star blue (exact) all star long (exact) dress all red (partial) shoes star (partial) …

---

## [Offline install of ELK stack on Oracle Linux](https://discuss.elastic.co/t/offline-install-of-elk-stack-on-oracle-linux/315389)

<div class="topic-metadata">

**Author:** [@ccloutr.alex](https://discuss.elastic.co/u/ccloutr.alex)\
**Replies:** 1\
**Last updated:** [September 28, 2022, 4:36pm UTC](https://discuss.elastic.co/t/offline-install-of-elk-stack-on-oracle-linux/315389 "2022-09-28T16:36:21Z")

</div>

I need to install ELK stack with all of its dependencies on a Oracle Linux box that is not connected to the internet. Is there a Offline install package that contains all dependencies?

---

## [Hot indices vs cold indices in same cluster](https://discuss.elastic.co/t/hot-indices-vs-cold-indices-in-same-cluster/315294)

<div class="topic-metadata">

**Author:** [@sara251186](https://discuss.elastic.co/u/sara251186)\
**Replies:** 1\
**Last updated:** [September 28, 2022, 3:36pm UTC](https://discuss.elastic.co/t/hot-indices-vs-cold-indices-in-same-cluster/315294 "2022-09-28T15:36:04Z")

</div>

I have a cluster for 12 data nodes running for a e commerce search, we also have 6 indices representing countries like US, CA, DE etc. I was running perf test against this cluster with just 1 index (i.e US - this compri…

---

## [Getting runtime\_exception exceeds maxClauseCount after Elasticsearch upgrade](https://discuss.elastic.co/t/getting-runtime-exception-exceeds-maxclausecount-after-elasticsearch-upgrade/315380)

<div class="topic-metadata">

**Author:** [@gwillis](https://discuss.elastic.co/u/gwillis)\
**Replies:** 0\
**Last updated:** [September 28, 2022, 2:55pm UTC](https://discuss.elastic.co/t/getting-runtime-exception-exceeds-maxclausecount-after-elasticsearch-upgrade/315380 "2022-09-28T14:55:23Z")

</div>

We are upgrading from Elasticsearch 6.2.4 to Elasticsearch 8.4.1 and are experiencing problems with several queries getting a runtime\_exception exceeds maxClauseCount. Elasticsearch 6.2.4 uses the default for index.query…

---

## [Alert : kibana.alert.rule.name: "Remote Execution via File Shares"](https://discuss.elastic.co/t/alert-kibana-alert-rule-name-remote-execution-via-file-shares/315378)

<div class="topic-metadata">

**Author:** [@Viral-Technology](https://discuss.elastic.co/u/Viral-Technology)\
**Replies:** 0\
**Last updated:** [September 28, 2022, 2:16pm UTC](https://discuss.elastic.co/t/alert-kibana-alert-rule-name-remote-execution-via-file-shares/315378 "2022-09-28T14:16:48Z")

</div>

Hello All, We are very new to the Elastic Stack, We had an alert show up this morning for " Remote Execution via File Shares" However, I can not find any corresponding data to go with it. is it normal that this alert do…

---

## [APM transaction propogation does not shown in Kibana](https://discuss.elastic.co/t/apm-transaction-propogation-does-not-shown-in-kibana/315374)

<div class="topic-metadata">

**Author:** [@zeevik.sha](https://discuss.elastic.co/u/zeevik.sha)\
**Replies:** 2\
**Last updated:** [September 28, 2022, 1:56pm UTC](https://discuss.elastic.co/t/apm-transaction-propogation-does-not-shown-in-kibana/315374 "2022-09-28T13:56:54Z")

</div>

Hi everyone, I have an Angular app and 2 node.js services that I want to monitor using APM. The angular app is the first transaction, I followed the elastic APM documentation to propogate the trace from the angular app…

---

## [Is there a plan to update nodejs version to v16.17.1 in kibana 7.17?](https://discuss.elastic.co/t/is-there-a-plan-to-update-nodejs-version-to-v16-17-1-in-kibana-7-17/315350)

<div class="topic-metadata">

**Author:** [@tan\_minkee](https://discuss.elastic.co/u/tan_minkee)\
**Replies:** 2\
**Last updated:** [September 28, 2022, 1:30pm UTC](https://discuss.elastic.co/t/is-there-a-plan-to-update-nodejs-version-to-v16-17-1-in-kibana-7-17/315350 "2022-09-28T13:30:53Z")

</div>

As per subject. Would like to request kibana v7.17 to update nodejs to v16.17.1 due to its vulnerability in CVE - CVE-2022-35255 (mitre.org) and CVE - CVE-2022-35256 (mitre.org)

---

## [How to Send the alerts to opsgenie from kibana using ALERT-API URL](https://discuss.elastic.co/t/how-to-send-the-alerts-to-opsgenie-from-kibana-using-alert-api-url/315370)

<div class="topic-metadata">

**Author:** [@ankamsandeep](https://discuss.elastic.co/u/ankamsandeep)\
**Replies:** 1\
**Last updated:** [September 28, 2022, 1:02pm UTC](https://discuss.elastic.co/t/how-to-send-the-alerts-to-opsgenie-from-kibana-using-alert-api-url/315370 "2022-09-28T13:02:46Z")

</div>

Hi all, I am new to Elastic and Kibana, can anyone help in how can i integrate opsgenie with Kibana using Alert api. Unable to find the solution, if any one of you can assist on this would be really helpful. Looking …

---

## [Why does Elasticsearch's default settings for logging via log4j2 retain such large amounts logs?](https://discuss.elastic.co/t/why-does-elasticsearchs-default-settings-for-logging-via-log4j2-retain-such-large-amounts-logs/315255)

<div class="topic-metadata">

**Author:** [@bassistcz](https://discuss.elastic.co/u/bassistcz)\
**Replies:** 4\
**Last updated:** [September 28, 2022, 12:22pm UTC](https://discuss.elastic.co/t/why-does-elasticsearchs-default-settings-for-logging-via-log4j2-retain-such-large-amounts-logs/315255 "2022-09-28T12:22:33Z")

</div>

I am curious about the logging settings for Elasticsearch, (I am running 7.17.3) as they appear much larger then what I typically expect for application logging. I have run into issues where the logs have filled my loggi…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=527)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=529)
