# Top

**URL:** https://discuss.elastic.co/top.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Elastic Observability vs OpenTelemetry: Are We Finally on the "Right" Path?](https://discuss.elastic.co/t/elastic-observability-vs-opentelemetry-are-we-finally-on-the-right-path/385880)

<div class="topic-metadata">

**Author:** [@nilsen](https://discuss.elastic.co/u/nilsen)\
**Replies:** 22\
**Last updated:** [August 20, 2026, 10:48am UTC](https://discuss.elastic.co/t/elastic-observability-vs-opentelemetry-are-we-finally-on-the-right-path/385880 "2026-08-20T10:48:12Z")

</div>

Context Our Elastic journey has been interesting and filled with trial and error. Around every corner we discover a different (and often better) way of doing the same thing, but it usually means redoing large parts of ou…

---

## [High CPU Usage on a few data nodes / Hotspotting of data](https://discuss.elastic.co/t/high-cpu-usage-on-a-few-data-nodes-hotspotting-of-data/383954)

<div class="topic-metadata">

**Author:** [@Lakshya\_Gupta](https://discuss.elastic.co/u/Lakshya_Gupta)\
**Replies:** 191\
**Last updated:** [January 14, 2026, 6:48am UTC](https://discuss.elastic.co/t/high-cpu-usage-on-a-few-data-nodes-hotspotting-of-data/383954 "2026-01-14T06:48:45Z")

</div>

Hi team, we have an Elastic Search Cluster with the following configurations ES Version 7.17.0 60 data nodes cluster 50 primary shards and 2 replica for each primary shards Here, we are using a particular custom routi…

---

## [X-pack-security warnings after upgrading to 9.3.3](https://discuss.elastic.co/t/x-pack-security-warnings-after-upgrading-to-9-3-3/385852)

<div class="topic-metadata">

**Author:** [@Koirin](https://discuss.elastic.co/u/Koirin)\
**Replies:** 9\
**Last updated:** [June 23, 2026, 8:48am UTC](https://discuss.elastic.co/t/x-pack-security-warnings-after-upgrading-to-9-3-3/385852 "2026-06-23T08:48:42Z")

</div>

Hello - I just upgraded our node in our monitoring-cluster (single-node) from 9.2.4 to 9.3.3 and have started receiving warnings regarding the x-pack-security getting denied reading some internal files in the docker-cont…

---

## [There is insufficient memory for the Java Runtime Environment to continue](https://discuss.elastic.co/t/there-is-insufficient-memory-for-the-java-runtime-environment-to-continue/383614)

<div class="topic-metadata">

**Author:** [@Aysel\_Guliyeva](https://discuss.elastic.co/u/Aysel_Guliyeva)\
**Replies:** 45\
**Last updated:** [January 28, 2026, 8:50pm UTC](https://discuss.elastic.co/t/there-is-insufficient-memory-for-the-java-runtime-environment-to-continue/383614 "2026-01-28T20:50:23Z")

</div>

Hello. I need help. In our system, there are 8 data nodes. And my Elasticsearch VM RAM is 16GB. Normally, Elasticsearch data nodes use 60-65% of RAM. I check via the command “top” on Ubuntu. Unfourtunately, once in a mo…

---

## [Logstash/Filebeat lag issue - Logs delayed by hours](https://discuss.elastic.co/t/logstash-filebeat-lag-issue-logs-delayed-by-hours/385101)

<div class="topic-metadata">

**Author:** [@Cesar\_Mejia](https://discuss.elastic.co/u/Cesar_Mejia)\
**Replies:** 45\
**Last updated:** [March 5, 2026, 1:02pm UTC](https://discuss.elastic.co/t/logstash-filebeat-lag-issue-logs-delayed-by-hours/385101 "2026-03-05T13:02:46Z")

</div>

Hello Elastic Community, I am experiencing a significant lag in log ingestion where logs are arriving with a variable delay (sometimes hours late) despite having a high-performance environment. I would appreciate your a…

---

## [Sharing my rule update experience on Elastic Security Serverless](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 13\
**Last updated:** [September 25, 2026, 12:27pm UTC](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853 "2026-09-25T12:27:47Z")

</div>

Hello, Just sharing my experience updating Elastic prebuilt Security rules after being away for about 1.5 months. When I logged back in, I had roughly 1,200 rule updates waiting. That is fine in itself - I clicked Upda…

---

## [Elastic cluster is getting down after 2 - 3 hours](https://discuss.elastic.co/t/elastic-cluster-is-getting-down-after-2-3-hours/383971)

<div class="topic-metadata">

**Author:** [@sathish12](https://discuss.elastic.co/u/sathish12)\
**Replies:** 55\
**Last updated:** [December 17, 2025, 10:50am UTC](https://discuss.elastic.co/t/elastic-cluster-is-getting-down-after-2-3-hours/383971 "2025-12-17T10:50:55Z")

</div>

Hi Everyone. I am using elastic 8.13.4 and I have 3 machines with 30 gb of RAM and 1tb of hard disk for each machine. I am creating 2 nodes per each machine through elastic portable download ealsticsearch-8.13.4.tar.gz.…

---

## [Elasticsearch Kibana 9.4.0 Basic authentication returns 401 Unauthorized](https://discuss.elastic.co/t/elasticsearch-kibana-9-4-0-basic-authentication-returns-401-unauthorized/386318)

<div class="topic-metadata">

**Author:** [@GeertVerbeurgt](https://discuss.elastic.co/u/GeertVerbeurgt)\
**Replies:** 37\
**Last updated:** [May 22, 2026, 11:05am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-9-4-0-basic-authentication-returns-401-unauthorized/386318 "2026-05-22T11:05:15Z")

</div>

After upgrading from elasticsearch/kibana version 9.3.0 to elasticsearch/kibana 9.4.0 I'm no longer able to login with basic authentication via the Authorization Header. This returns the error 401 Unauthorized. { "ser…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/383028)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 44\
**Last updated:** [November 4, 2025, 7:16pm UTC](https://discuss.elastic.co/t/elasticsearch/383028 "2025-11-04T19:16:09Z")

</div>

‘‘‘ Hi Folks, #lasticsearch.yml file of node ip ending in 17 ( 8.15.2) still not upgraded ’’’ path.data: /var/lib/elasticsearch/data path.logs: /var/log/elasticsearch/logs xpack.security.enabled: false xpack.secur…

---

## [Elasticsearch monitoring tool - A chrome extension](https://discuss.elastic.co/t/elasticsearch-monitoring-tool-a-chrome-extension/388969)

<div class="topic-metadata">

**Author:** [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Replies:** 18\
**Last updated:** [September 28, 2026, 7:29am UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-tool-a-chrome-extension/388969 "2026-09-28T07:29:15Z")

</div>

Hey guys, I've been debugging Elasticsearch clusters for years, and I got tired of jumping between \_cat APIs, and terminal tabs just to check cluster health. So I built a lightweight Chrome extension that surfaces the m…

---

## [Elasticsearch Segment Merge Impacting Search Performance](https://discuss.elastic.co/t/elasticsearch-segment-merge-impacting-search-performance/389792)

<div class="topic-metadata">

**Author:** [@Dhruv\_Mavani](https://discuss.elastic.co/u/Dhruv_Mavani)\
**Replies:** 11\
**Last updated:** [August 23, 2026, 8:10pm UTC](https://discuss.elastic.co/t/elasticsearch-segment-merge-impacting-search-performance/389792 "2026-08-23T20:10:18Z")

</div>

We are looking for some guidance from the Elasticsearch community on a performance issue we are facing. We have a 3-node Elasticsearch cluster running on Azure, with approximately 250 GB Premium SSD per node. Our workl…

---

## [Massive performance drop for certain queries in ES9 compared to ES8](https://discuss.elastic.co/t/massive-performance-drop-for-certain-queries-in-es9-compared-to-es8/383393)

<div class="topic-metadata">

**Author:** [@msh](https://discuss.elastic.co/u/msh)\
**Replies:** 16\
**Last updated:** [December 2, 2025, 12:49pm UTC](https://discuss.elastic.co/t/massive-performance-drop-for-certain-queries-in-es9-compared-to-es8/383393 "2025-12-02T12:49:32Z")

</div>

We discovered a massive performance drop after migration to ES 9 for certain queries with aggregations. Our mapping an be seen here: INGe/inge\_es\_connector/src/main/resources/es\_index\_items.json at spring6 · MPDL/INGe ·…

---

## [Issue enrolling into fleet](https://discuss.elastic.co/t/issue-enrolling-into-fleet/383470)

<div class="topic-metadata">

**Author:** [@f4n-1nh1b1t10n](https://discuss.elastic.co/u/f4n-1nh1b1t10n)\
**Replies:** 16\
**Last updated:** [November 19, 2025, 4:26pm UTC](https://discuss.elastic.co/t/issue-enrolling-into-fleet/383470 "2025-11-19T16:26:58Z")

</div>

Hello, I seem to stumble on the issue of enrolling my agent securely into fleet. i’ve tried the FAQ where they suggest to install the agent first, and then enroll it into fleet (upgrading the agent to a fleet server wi…

---

## [Elasticseach 9.4.0 Won't Start on Nehalem CPU "does not support all the following CPU features"](https://discuss.elastic.co/t/elasticseach-9-4-0-wont-start-on-nehalem-cpu-does-not-support-all-the-following-cpu-features/386216)

<div class="topic-metadata">

**Author:** [@amorrow](https://discuss.elastic.co/u/amorrow)\
**Replies:** 12\
**Last updated:** [July 8, 2026, 3:08pm UTC](https://discuss.elastic.co/t/elasticseach-9-4-0-wont-start-on-nehalem-cpu-does-not-support-all-the-following-cpu-features/386216 "2026-07-08T15:08:12Z")

</div>

I got an unexpected surprise today when I tried to upgrade my Elasticsearch cluster from 9.3.4 to 9.4.0 on Ubuntu 24.04 LTS using deb packages. The service won't start. May 07 08:33:52 elk3 systemd\[1\]: Starting elastics…

---

## [Change grpc port to 6788 on fleet controled agent](https://discuss.elastic.co/t/change-grpc-port-to-6788-on-fleet-controled-agent/388416)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 12\
**Last updated:** [August 8, 2026, 4:44am UTC](https://discuss.elastic.co/t/change-grpc-port-to-6788-on-fleet-controled-agent/388416 "2026-08-08T04:44:56Z")

</div>

Hello, i want to install UniFi OS Server on my windows server. Unfortunately the elastic agent is using port 6789. I wonder if i can change this with a dedicated policy for this server? seems like agent.grpc.port: 67…

---

## [ELK Architecture Distribution for Hardware to Achieve high availability](https://discuss.elastic.co/t/elk-architecture-distribution-for-hardware-to-achieve-high-availability/384936)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 16\
**Last updated:** [February 11, 2026, 9:22am UTC](https://discuss.elastic.co/t/elk-architecture-distribution-for-hardware-to-achieve-high-availability/384936 "2026-02-11T09:22:20Z")

</div>

I want to know how to distribute the nodes VMs across the physical servers to achieve HA my cluster will be contain of these specs below and I want to make something like this

---

## [Block USB(s) by default with Elastic Agent?](https://discuss.elastic.co/t/block-usb-s-by-default-with-elastic-agent/382809)

<div class="topic-metadata">

**Author:** [@BlueGreenRed1](https://discuss.elastic.co/u/BlueGreenRed1)\
**Replies:** 9\
**Last updated:** [November 18, 2025, 7:50pm UTC](https://discuss.elastic.co/t/block-usb-s-by-default-with-elastic-agent/382809 "2025-11-18T19:50:56Z")

</div>

Hello, I am posting to find out if this feature is still on the Elastic Team’s roadmap? I found previous posts from 2022 and 2023 requesting this feature. In short, it would be a nice feature if the Elastic Agent could…

---

## [Migrating off ElasticSearch as sole primary database for a relational business domain — anyone done this?](https://discuss.elastic.co/t/migrating-off-elasticsearch-as-sole-primary-database-for-a-relational-business-domain-anyone-done-this/386137)

<div class="topic-metadata">

**Author:** [@lets\_get\_relational](https://discuss.elastic.co/u/lets_get_relational)\
**Replies:** 13\
**Last updated:** [May 15, 2026, 12:34pm UTC](https://discuss.elastic.co/t/migrating-off-elasticsearch-as-sole-primary-database-for-a-relational-business-domain-anyone-done-this/386137 "2026-05-15T12:34:16Z")

</div>

\# Migrating off Elasticsearch as sole primary database for a relational business domain — anyone done this? I've inherited a ~6 year old production Django application where Elasticsearch is the only data store. Not "ES …

---

## [Readiness check for Elasticsearch coordinator nodes behind a load balancer?](https://discuss.elastic.co/t/readiness-check-for-elasticsearch-coordinator-nodes-behind-a-load-balancer/386690)

<div class="topic-metadata">

**Author:** [@sagar\_cenation](https://discuss.elastic.co/u/sagar_cenation)\
**Replies:** 33\
**Last updated:** [July 29, 2026, 10:54am UTC](https://discuss.elastic.co/t/readiness-check-for-elasticsearch-coordinator-nodes-behind-a-load-balancer/386690 "2026-07-29T10:54:03Z")

</div>

Hello, I am trying to choose the right readiness check for Elasticsearch coordinator nodes behind a load balancer / proxy. We are on Elasticsearch 8.8.2. The coorinator nodes serve search traffic behind a load balancer…

---

## [Cluster will not start after upgrade from 8.x to 9.x](https://discuss.elastic.co/t/cluster-will-not-start-after-upgrade-from-8-x-to-9-x/383690)

<div class="topic-metadata">

**Author:** [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Replies:** 19\
**Last updated:** [November 27, 2025, 5:03pm UTC](https://discuss.elastic.co/t/cluster-will-not-start-after-upgrade-from-8-x-to-9-x/383690 "2025-11-27T17:03:11Z")

</div>

Hello all, I’ve upgraded from Elasticsearch 8.19 to 9.2.1. Since doing so none of the cluster nodes will start, the error message in the cluster log: java.lang.IllegalStateException: The index \[.reporting-2021-12-12/E…

---

## [HA-Cluster: Simple design on prem, self managed](https://discuss.elastic.co/t/ha-cluster-simple-design-on-prem-self-managed/390177)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 12\
**Last updated:** [September 9, 2026, 5:33pm UTC](https://discuss.elastic.co/t/ha-cluster-simple-design-on-prem-self-managed/390177 "2026-09-09T17:33:34Z")

</div>

Hi there, I am looking for a simple HA-design for a logging use case, on prem & self managed. Would this be a good design? NODE-1 master, data, ingest, kibana, logstash, redis NODE-2 master, data, ingest, kibana, log…

---

## [Too\_many\_scroll\_contexts\_exception](https://discuss.elastic.co/t/too-many-scroll-contexts-exception/384981)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 9\
**Last updated:** [February 20, 2026, 10:07pm UTC](https://discuss.elastic.co/t/too-many-scroll-contexts-exception/384981 "2026-02-20T22:07:39Z")

</div>

elasticsearch -{"statusCode":500,"error":"Internal Server Error","message":"\[search\_phase\_execution\_exception\\n\\tRoot causes:\\n\\t\\ttoo\_many\_scroll\_contexts\_exception: Trying to create too many scroll contexts. Must be le…

---

## [API key does or does not rely on permissions from user that created it](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 14\
**Last updated:** [December 31, 2025, 10:08pm UTC](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663 "2025-12-31T22:08:43Z")

</div>

We had previously been creating API keys with our SSO user accounts. Then we found that after an SSO IdP provider change our users were effectively “different” such that we could no longer edit API keys (e.g. to add or r…

---

## [Urgent Help Needed Elastic Shutting down ingestion & All the write load is being transferred to one of the hot nodes](https://discuss.elastic.co/t/urgent-help-needed-elastic-shutting-down-ingestion-all-the-write-load-is-being-transferred-to-one-of-the-hot-nodes/388083)

<div class="topic-metadata">

**Author:** [@kkumar123](https://discuss.elastic.co/u/kkumar123)\
**Replies:** 30\
**Last updated:** [July 21, 2026, 2:48pm UTC](https://discuss.elastic.co/t/urgent-help-needed-elastic-shutting-down-ingestion-all-the-write-load-is-being-transferred-to-one-of-the-hot-nodes/388083 "2026-07-21T14:48:33Z")

</div>

I have issue with cluster all the time i can see is queue on one of the hot nodes at a time. node\_name name active queue rejected elastic-frozen2 write 0 0 0 elastic-hot…

---

## [Billing Insane ECU for learning Elastic Serverless instance](https://discuss.elastic.co/t/billing-insane-ecu-for-learning-elastic-serverless-instance/383973)

<div class="topic-metadata">

**Author:** [@Bhaskar\_Reddy](https://discuss.elastic.co/u/Bhaskar_Reddy)\
**Replies:** 21\
**Last updated:** [December 12, 2025, 4:21pm UTC](https://discuss.elastic.co/t/billing-insane-ecu-for-learning-elastic-serverless-instance/383973 "2025-12-12T16:21:10Z")

</div>

Details: I recently provisioned an Elastic Serverless instance on GCP (asia-south1) purely for learning and experimentation. My usage has been extremely minimal: Only one record stored in a single index. At most o…

---

## [Kibana login broken after trying to enable reporting. "You do not have permission to access the requested page" message - Need help to fix it](https://discuss.elastic.co/t/kibana-login-broken-after-trying-to-enable-reporting-you-do-not-have-permission-to-access-the-requested-page-message-need-help-to-fix-it/384554)

<div class="topic-metadata">

**Author:** [@eparreiras](https://discuss.elastic.co/u/eparreiras)\
**Replies:** 24\
**Last updated:** [January 18, 2026, 8:34pm UTC](https://discuss.elastic.co/t/kibana-login-broken-after-trying-to-enable-reporting-you-do-not-have-permission-to-access-the-requested-page-message-need-help-to-fix-it/384554 "2026-01-18T20:34:05Z")

</div>

Hi there, After trying to enable reporting in Kibana following the document below: I am not able to login into Kibana anymore. I am using a Kibana 8.10.4 container version. The Elasticsearch is a IBM Cloud managed…

---

## [Updating xpack certificates to a new CA in an active Elasticsearch cluster without downtime](https://discuss.elastic.co/t/updating-xpack-certificates-to-a-new-ca-in-an-active-elasticsearch-cluster-without-downtime/385871)

<div class="topic-metadata">

**Author:** [@Anup\_Kumar](https://discuss.elastic.co/u/Anup_Kumar)\
**Replies:** 22\
**Last updated:** [May 15, 2026, 12:39pm UTC](https://discuss.elastic.co/t/updating-xpack-certificates-to-a-new-ca-in-an-active-elasticsearch-cluster-without-downtime/385871 "2026-05-15T12:39:34Z")

</div>

Hi, We have an active Elasticsearch cluster (large) with TLS/SSL enabled for inter-node communication (xpack.security.transport.ssl). We are planning to replace the existing node certificates with new ones issued by a d…

---

## [Elastic Defend Windows Defender question](https://discuss.elastic.co/t/elastic-defend-windows-defender-question/383157)

<div class="topic-metadata">

**Author:** [@YousefNein](https://discuss.elastic.co/u/YousefNein)\
**Replies:** 9\
**Last updated:** [November 3, 2025, 1:44pm UTC](https://discuss.elastic.co/t/elastic-defend-windows-defender-question/383157 "2025-11-03T13:44:45Z")

</div>

From the attached pic, I don’t understand this warning restriction. I also need some clarification with: Enable to register Elastic as an official Antivirus solution for Windows OS. This will also disable Windows Defe…

---

## [Elasticsearch-reset-password on linux can't accept special characters](https://discuss.elastic.co/t/elasticsearch-reset-password-on-linux-cant-accept-special-characters/383050)

<div class="topic-metadata">

**Author:** [@Ryan\_Clark](https://discuss.elastic.co/u/Ryan_Clark)\
**Replies:** 20\
**Last updated:** [December 11, 2025, 4:50pm UTC](https://discuss.elastic.co/t/elasticsearch-reset-password-on-linux-cant-accept-special-characters/383050 "2025-12-11T16:50:32Z")

</div>

When using the elasticsearch password reset tool (elasticsearch-reset-password) in Linux, using a special character will pick up the shell interpretation and not the character itself. In particular, I’m having issues usi…

---

## [ClientTimeout while awaiting headers](https://discuss.elastic.co/t/clienttimeout-while-awaiting-headers/383330)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 16\
**Last updated:** [November 12, 2025, 2:59pm UTC](https://discuss.elastic.co/t/clienttimeout-while-awaiting-headers/383330 "2025-11-12T14:59:45Z")

</div>

Hi Team, I want to monitor one url https://abccc.com/acbs. I am using http ping method . But i am getting \`Could not connect xx.xx.xx.xx:443 with error:dial tcp xx.xx.xx.xx:443:i/o timeout(Client.Timeout exceeds while …

---

## [2025: The Year in Review](https://discuss.elastic.co/t/2025-the-year-in-review/384333)

<div class="topic-metadata">

**Author:** [@system](https://discuss.elastic.co/u/system)\
**Replies:** 12\
**Last updated:** [January 1, 2026, 9:52pm UTC](https://discuss.elastic.co/t/2025-the-year-in-review/384333 "2026-01-01T21:52:24Z")

</div>

2025's Top Users Most Time Reading User Hours Read @RainTown 237 @stephenb 124 @leandrojmp 103 @Tortoise 81 @Christian\_Dahlqvist 80 @Rios 49 @DavidTurner 25 @Badger 25 @dadoonet 15 @…

---

## [\[indices:admin/create\] is unauthorized for user Elastic Stack](https://discuss.elastic.co/t/indices-admin-create-is-unauthorized-for-user-elastic-stack/383767)

<div class="topic-metadata">

**Author:** [@frahmn](https://discuss.elastic.co/u/frahmn)\
**Replies:** 17\
**Last updated:** [November 30, 2025, 9:19pm UTC](https://discuss.elastic.co/t/indices-admin-create-is-unauthorized-for-user-elastic-stack/383767 "2025-11-30T21:19:30Z")

</div>

I have read through many articles and am not able to solve this issue for me. I’m trying to generate a new api key that has rights over creating indicies using filebeat. I have tried doing this through the superuser acco…

---

## [Error: entity content is too long \[105072697\] for the configured buffer limit \[104857600\]](https://discuss.elastic.co/t/error-entity-content-is-too-long-105072697-for-the-configured-buffer-limit-104857600/385636)

<div class="topic-metadata">

**Author:** [@Chen\_Wen](https://discuss.elastic.co/u/Chen_Wen)\
**Replies:** 16\
**Last updated:** [March 31, 2026, 8:49am UTC](https://discuss.elastic.co/t/error-entity-content-is-too-long-105072697-for-the-configured-buffer-limit-104857600/385636 "2026-03-31T08:49:15Z")

</div>

When I query data from ES8.2.3 with a big size in one req that the index docs are more than 10K and got en error Error: entity content is too long \[105072697\] for the configured buffer limit \[104857600\]. After search th…

---

## [Enable APM for springboot running on windows](https://discuss.elastic.co/t/enable-apm-for-springboot-running-on-windows/383568)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 20\
**Last updated:** [November 26, 2025, 2:56pm UTC](https://discuss.elastic.co/t/enable-apm-for-springboot-running-on-windows/383568 "2025-11-26T14:56:31Z")

</div>

Hello , I want to enable APM for java application running on tomcat server(windows). I’ve followed the steps mentioned in the setup-tomcat-windows . I have restarted the tomcat service running on windows but it was not …

---

## [Kibana 9.3.1 Disabling message "New! Connect AutoOps to this self-managed cluster"](https://discuss.elastic.co/t/kibana-9-3-1-disabling-message-new-connect-autoops-to-this-self-managed-cluster/385736)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 14\
**Last updated:** [April 16, 2026, 10:10am UTC](https://discuss.elastic.co/t/kibana-9-3-1-disabling-message-new-connect-autoops-to-this-self-managed-cluster/385736 "2026-04-16T10:10:01Z")

</div>

We would like to not present this message to our users. Is there a way this disable this?

---

## [Migration Strategy (ES7 → ES8) via Dual‑Write + Snapshot Restore + Selective Merge by updated\_at](https://discuss.elastic.co/t/migration-strategy-es7-es8-via-dual-write-snapshot-restore-selective-merge-by-updated-at/383235)

<div class="topic-metadata">

**Author:** [@Aditya\_Rathi](https://discuss.elastic.co/u/Aditya_Rathi)\
**Replies:** 10\
**Last updated:** [November 5, 2025, 4:41pm UTC](https://discuss.elastic.co/t/migration-strategy-es7-es8-via-dual-write-snapshot-restore-selective-merge-by-updated-at/383235 "2025-11-05T16:41:51Z")

</div>

Environment / Versions: Source cluster: Elasticsearch 7.x ( live on production ) Target cluster: Elasticsearch 8.x Data volume: ~1 TB across ~100+ indices Write throughput: ~53 requests/sec, ~1,100 docs/sec (…

---

## [\[search\_phase\_execution\_exception\] without a root reason](https://discuss.elastic.co/t/search-phase-execution-exception-without-a-root-reason/382922)

<div class="topic-metadata">

**Author:** [@al123od](https://discuss.elastic.co/u/al123od)\
**Replies:** 10\
**Last updated:** [October 23, 2025, 2:20pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-without-a-root-reason/382922 "2025-10-23T14:20:37Z")

</div>

Hello. I’m using Elasticsearch 9.1.3, access with java client (no security, almost all setting but cluster name are default). If to execute query\_string query with wrong syntax like GET test/\_search { "query": {…

---

## [Any Reason traces-apm@template is using Standard Index mode instead of timeseries or logsdb](https://discuss.elastic.co/t/any-reason-traces-apm-template-is-using-standard-index-mode-instead-of-timeseries-or-logsdb/383301)

<div class="topic-metadata">

**Author:** [@Serak\_Shiferaw](https://discuss.elastic.co/u/Serak_Shiferaw)\
**Replies:** 10\
**Last updated:** [December 22, 2025, 8:51am UTC](https://discuss.elastic.co/t/any-reason-traces-apm-template-is-using-standard-index-mode-instead-of-timeseries-or-logsdb/383301 "2025-12-22T08:51:09Z")

</div>

we are capturing enterprise java traces, and the trace is filling up all the spaces on my cluster, its generating 1.4TB daily and i cant keep up, then upon checking there is no compression on the created index and its ju…

---

## [Which architecture is better for the Elasticsearch structure?](https://discuss.elastic.co/t/which-architecture-is-better-for-the-elasticsearch-structure/383008)

<div class="topic-metadata">

**Author:** [@celikbaris61](https://discuss.elastic.co/u/celikbaris61)\
**Replies:** 12\
**Last updated:** [October 28, 2025, 11:49am UTC](https://discuss.elastic.co/t/which-architecture-is-better-for-the-elasticsearch-structure/383008 "2025-10-28T11:49:10Z")

</div>

Hello everyone,I'm going to set up a cluster for Elasticsearch. My data size is approximately 50 TB and will continue to grow. I will primarily use it for search and cross-queries. My question is:I will be using virtual …

---

## [java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_state/\_pu2t.cfs](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250)

<div class="topic-metadata">

**Author:** [@TheJ](https://discuss.elastic.co/u/TheJ)\
**Replies:** 15\
**Last updated:** [September 19, 2026, 6:07pm UTC](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250 "2026-09-19T18:07:12Z")

</div>

Hi, I have a problem with one of my elasticsearch node. For some reason node was shutdown due to some error. When I look into the log, I get the error java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_st…

---

## [Setting up self managed ELK stack with TLS/HTTPS issue](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102)

<div class="topic-metadata">

**Author:** [@BenNCSU](https://discuss.elastic.co/u/BenNCSU)\
**Replies:** 11\
**Last updated:** [March 5, 2026, 2:16am UTC](https://discuss.elastic.co/t/setting-up-self-managed-elk-stack-with-tls-https-issue/385102 "2026-03-05T02:16:44Z")

</div>

I’m trying to set up an ELK stack for SIEM doing a standard install. I installed Elasticsearch and Kibana, which worked fine using HTTP, but when I tried to set up TLS using a self-signed certificate from our CA, I can’…

---

## [ES, kibana both having ca.crt issues?](https://discuss.elastic.co/t/es-kibana-both-having-ca-crt-issues/389738)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 12\
**Last updated:** [August 21, 2026, 10:13am UTC](https://discuss.elastic.co/t/es-kibana-both-having-ca-crt-issues/389738 "2026-08-21T10:13:56Z")

</div>

I'm not able to start up either the ES or kibana containers and I suspect the root cause has to do with ca-cert issues. i'm attaching my compose file below for reference with ES, the log shows this error: "@timestamp"…

---

## [How to update fields that are not opened in the source document without affecting them](https://discuss.elastic.co/t/how-to-update-fields-that-are-not-opened-in-the-source-document-without-affecting-them/383175)

<div class="topic-metadata">

**Author:** [@S-Dragon0302](https://discuss.elastic.co/u/S-Dragon0302)\
**Replies:** 14\
**Last updated:** [November 11, 2025, 1:48am UTC](https://discuss.elastic.co/t/how-to-update-fields-that-are-not-opened-in-the-source-document-without-affecting-them/383175 "2025-11-11T01:48:32Z")

</div>

My template { "mappings":{"dynamic": "false","\_source":{"includes":\["a","b"\]},"properties":{"a":{"type": "keyword"},"b":{"type": "keyword"},"c":{"type": "keyword"}}}} PUT /your\_index\_name/\_doc/1 {"a": "value\_a","b": "…

---

## [Grafana to Elastic stack migration](https://discuss.elastic.co/t/grafana-to-elastic-stack-migration/387604)

<div class="topic-metadata">

**Author:** [@Ts\_P](https://discuss.elastic.co/u/Ts_P)\
**Replies:** 11\
**Last updated:** [July 27, 2026, 3:28pm UTC](https://discuss.elastic.co/t/grafana-to-elastic-stack-migration/387604 "2026-07-27T15:28:18Z")

</div>

I wanna migrate from Grafana to Elastic stack . I found this repository and few articles. Can I download the binary files directly obs-migrate?(for windows 11 x64)

---

## [Elasticsearch indexing\_pressure.memory.limit](https://discuss.elastic.co/t/elasticsearch-indexing-pressure-memory-limit/383670)

<div class="topic-metadata">

**Author:** [@ee99](https://discuss.elastic.co/u/ee99)\
**Replies:** 15\
**Last updated:** [December 2, 2025, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-pressure-memory-limit/383670 "2025-12-02T14:04:00Z")

</div>

When I try to index large log files through bulk\_index, I notice got logs missing. Suspecting it could be due to the memory issue of the elasticsearch nodes. I tried to change the indexing\_pressure.memory.limit to 40%. B…

---

## [Messaging.message.conversation\_id visible in Traces but not searchable in Discover](https://discuss.elastic.co/t/messaging-message-conversation-id-visible-in-traces-but-not-searchable-in-discover/390038)

<div class="topic-metadata">

**Author:** [@ex.ko](https://discuss.elastic.co/u/ex.ko)\
**Replies:** 9\
**Last updated:** [September 8, 2026, 10:50am UTC](https://discuss.elastic.co/t/messaging-message-conversation-id-visible-in-traces-but-not-searchable-in-discover/390038 "2026-09-08T10:50:29Z")

</div>

Hi everyone, We're using the JMS Correlation ID in our application. In Elastic APM / Traces, I can see the field and its value on individual spans in the field: attributes.messaging.message.conversation\_id However, I c…

---

## [How to reindex when source indices are continuously receiving data?](https://discuss.elastic.co/t/how-to-reindex-when-source-indices-are-continuously-receiving-data/385685)

<div class="topic-metadata">

**Author:** [@yogesh119905](https://discuss.elastic.co/u/yogesh119905)\
**Replies:** 10\
**Last updated:** [August 3, 2026, 7:41pm UTC](https://discuss.elastic.co/t/how-to-reindex-when-source-indices-are-continuously-receiving-data/385685 "2026-08-03T19:41:48Z")

</div>

Title: How to reindex when source indices are continuously receiving data? Description: I’m trying to perform a reindex operation in Elasticsearch where the source indices are continuously receiving new data. Scenari…

---

## [Slow cluster recovery after node system updates](https://discuss.elastic.co/t/slow-cluster-recovery-after-node-system-updates/383462)

<div class="topic-metadata">

**Author:** [@ecology5913](https://discuss.elastic.co/u/ecology5913)\
**Replies:** 9\
**Last updated:** [November 18, 2025, 6:34pm UTC](https://discuss.elastic.co/t/slow-cluster-recovery-after-node-system-updates/383462 "2025-11-18T18:34:20Z")

</div>

I’ve been doing lifecycle management for ES clusters recently, from clusters with indices without replicas to clusters with 1TB shards. While the problems with those examples are obvious, I recently got more ‘normal‘ cl…

---

## [How to reliably verify a snapshot restore succeeded? Failed shards disappear from \_recovery](https://discuss.elastic.co/t/how-to-reliably-verify-a-snapshot-restore-succeeded-failed-shards-disappear-from-recovery/389912)

<div class="topic-metadata">

**Author:** [@ciprianamza](https://discuss.elastic.co/u/ciprianamza)\
**Replies:** 10\
**Last updated:** [August 30, 2026, 4:03pm UTC](https://discuss.elastic.co/t/how-to-reliably-verify-a-snapshot-restore-succeeded-failed-shards-disappear-from-recovery/389912 "2026-08-30T16:03:41Z")

</div>

Hello, I'd like to raise a possible problem I recently ran into in an internal application, and which I see the current Curator implementation mirrors as well (curator/curator/utils.py at v5.8.4 · elastic/curator · GitH…

---

## [Alerting on field value change](https://discuss.elastic.co/t/alerting-on-field-value-change/383451)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 12\
**Last updated:** [November 16, 2025, 1:10pm UTC](https://discuss.elastic.co/t/alerting-on-field-value-change/383451 "2025-11-16T13:10:12Z")

</div>

I’m currently logging on-change data in ES, and I’m running a latest transform to store the most updated data into a separate index. I was advised that an ingest pipeline will help me compare any value coming in with th…

[Next page](https://discuss.elastic.co/top.md?page=1&per_page=50)
