# Open Source Elasticsearch and Kibana

**URL:** https://forum.opensearch.org/c/general-elasticsearch/10.md

[Latest](https://forum.opensearch.org/latest.md) · [Categories](https://forum.opensearch.org/categories.md) · [Tags](https://forum.opensearch.org/tags.md)

---

## [About the Open Source Elasticsearch and Kibana category](https://forum.opensearch.org/t/about-the-open-source-elasticsearch-and-kibana-category/21)

<div class="topic-metadata">

**Author:** [@carlmead](https://forum.opensearch.org/u/carlmead)\
**Replies:** 0\
**Last updated:** [March 1, 2019, 9:18pm UTC](https://forum.opensearch.org/t/about-the-open-source-elasticsearch-and-kibana-category/21 "2019-03-01T21:18:29Z")

</div>

General discussion area for the base open source Elasticsearch and Kibana projects.

---

## [What does "dr","mr" etc stand for in roles for nodes](https://forum.opensearch.org/t/what-does-dr-mr-etc-stand-for-in-roles-for-nodes/5210)

<div class="topic-metadata">

**Author:** [@curiousmind](https://forum.opensearch.org/u/curiousmind)\
**Replies:** 2\
**Last updated:** [September 12, 2026, 7:51pm UTC](https://forum.opensearch.org/t/what-does-dr-mr-etc-stand-for-in-roles-for-nodes/5210 "2026-09-12T19:51:54Z")

</div>

The following request GET \_cat/nodes?v gave me response like this: I know that, d is for data, m is for master eligible, i is for ingest etc. But what does this “r” stands for?

---

## [Migrate Elasticsearch 8.9 to opensearch any version](https://forum.opensearch.org/t/migrate-elasticsearch-8-9-to-opensearch-any-version/28250)

<div class="topic-metadata">

**Author:** [@mannoj](https://forum.opensearch.org/u/mannoj)\
**Replies:** 0\
**Last updated:** [August 20, 2026, 10:46am UTC](https://forum.opensearch.org/t/migrate-elasticsearch-8-9-to-opensearch-any-version/28250 "2026-08-20T10:46:45Z")

</div>

Is it possible to migrate Elasticsearch from 8.9 to any Opensearch version? Thing we have rule-out : Re-index is not an option as it takes long time. Snapshot and Restore fails with UUID error. Dual Writes is possible…

---

## [How to Set Dark Mode for only me](https://forum.opensearch.org/t/how-to-set-dark-mode-for-only-me/28216)

<div class="topic-metadata">

**Author:** [@eldercryptid](https://forum.opensearch.org/u/eldercryptid)\
**Replies:** 2\
**Last updated:** [July 24, 2026, 1:14pm UTC](https://forum.opensearch.org/t/how-to-set-dark-mode-for-only-me/28216 "2026-07-24T13:14:36Z")

</div>

Hi there, I am trying to set the dark mode that comes with Kibana, but this appears to be a global setting, not something that is set per user, which basically makes it useless as most people I work with don’t use dark m…

---

## [ISM Policy and Searching restored indices](https://forum.opensearch.org/t/ism-policy-and-searching-restored-indices/28036)

<div class="topic-metadata">

**Author:** [@muraliv](https://forum.opensearch.org/u/muraliv)\
**Replies:** 5\
**Last updated:** [July 6, 2026, 11:57am UTC](https://forum.opensearch.org/t/ism-policy-and-searching-restored-indices/28036 "2026-07-06T11:57:28Z")

</div>

Hi there, I have an ISM policy that takes a snapshot and restores the index using the convert-remote-to-index action. Here is the complete ISM policy PUT \_plugins/\_ism/policies/vz-tsgi-hvuv-osdev-30m-ism-policy { "p…

---

## [Improving OpenSearch relevance with better normalization (beyond stemming)](https://forum.opensearch.org/t/improving-opensearch-relevance-with-better-normalization-beyond-stemming/27997)

<div class="topic-metadata">

**Author:** [@TonyJ](https://forum.opensearch.org/u/TonyJ)\
**Replies:** 1\
**Last updated:** [April 20, 2026, 3:02pm UTC](https://forum.opensearch.org/t/improving-opensearch-relevance-with-better-normalization-beyond-stemming/27997 "2026-04-20T15:02:22Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: In several OpenSearch projects we’ve seen stemming introduce noise early in the pipeline, especially in multilingual setups. For exampl…

---

## [Can structured JSON output from containers override or extend the default log fields in OpenSearch?](https://forum.opensearch.org/t/can-structured-json-output-from-containers-override-or-extend-the-default-log-fields-in-opensearch/27988)

<div class="topic-metadata">

**Author:** [@codesrcdoc](https://forum.opensearch.org/u/codesrcdoc)\
**Replies:** 1\
**Last updated:** [April 17, 2026, 11:51am UTC](https://forum.opensearch.org/t/can-structured-json-output-from-containers-override-or-extend-the-default-log-fields-in-opensearch/27988 "2026-04-17T11:51:01Z")

</div>

Hi everyone, We’re running Node.js containers on Kubernetes (Rancher-managed CaaS shared clusters) with centralized logging to OpenSearch Dashboards. Currently, our container is captured and indexed with this structure: …

---

## [Open Search World map country border issue](https://forum.opensearch.org/t/open-search-world-map-country-border-issue/23453)

<div class="topic-metadata">

**Author:** [@manu](https://forum.opensearch.org/u/manu)\
**Replies:** 8\
**Last updated:** [November 11, 2025, 1:05pm UTC](https://forum.opensearch.org/t/open-search-world-map-country-border-issue/23453 "2025-11-11T13:05:43Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Open Search Version:2.3.0 OS version: “Oracle Linux 8” version: 8.10 Supported browser versions as per certification Google Chrome 1 Release(106) Microso…

---

## [Opensearch Widgets](https://forum.opensearch.org/t/opensearch-widgets/26446)

<div class="topic-metadata">

**Author:** [@Sana1](https://forum.opensearch.org/u/Sana1)\
**Replies:** 1\
**Last updated:** [September 25, 2025, 12:51pm UTC](https://forum.opensearch.org/t/opensearch-widgets/26446 "2025-09-25T12:51:09Z")

</div>

Hi All, I am facing issues when creating new widgets in the opensearch dashboard. I have created two different widgets with different filters, but the result for both of them is the same. Has anyone faced such an issu…

---

## [Help Implementing a Complex Kibana Metric in OpenDashboard](https://forum.opensearch.org/t/help-implementing-a-complex-kibana-metric-in-opendashboard/26245)

<div class="topic-metadata">

**Author:** [@balakrishnan.s.dsrc](https://forum.opensearch.org/u/balakrishnan.s.dsrc)\
**Replies:** 2\
**Last updated:** [September 2, 2025, 1:48pm UTC](https://forum.opensearch.org/t/help-implementing-a-complex-kibana-metric-in-opendashboard/26245 "2025-09-02T13:48:47Z")

</div>

Hi everyone, I need some guidance on how to implement the following metric in OpenDashboard. For reference, I have included a screenshot from Kibana and the formula I used. ( sum(delivery\_count, kql='\_index : "ind…

---

## [DLS fails with dynamic variable ${user.attrs.tenant\_id} but works with static values](https://forum.opensearch.org/t/dls-fails-with-dynamic-variable-user-attrs-tenant-id-but-works-with-static-values/26305)

<div class="topic-metadata">

**Author:** [@Vivek1](https://forum.opensearch.org/u/Vivek1)\
**Replies:** 0\
**Last updated:** [August 11, 2025, 7:24am UTC](https://forum.opensearch.org/t/dls-fails-with-dynamic-variable-user-attrs-tenant-id-but-works-with-static-values/26305 "2025-08-11T07:24:24Z")

</div>

Hello OpenSearch Community, I’m trying to implement Document Level Security (DLS) using a tenant\_id claim from our OIDC provider’s JWT, but I’ve run into a specific issue. The DLS works perfectly when I hardcode a value…

---

## [Keyword don't give autocomplete on one field](https://forum.opensearch.org/t/keyword-dont-give-autocomplete-on-one-field/24607)

<div class="topic-metadata">

**Author:** [@NielsPeter](https://forum.opensearch.org/u/NielsPeter)\
**Replies:** 0\
**Last updated:** [May 31, 2025, 3:47pm UTC](https://forum.opensearch.org/t/keyword-dont-give-autocomplete-on-one-field/24607 "2025-05-31T15:47:19Z")

</div>

Hello In my index keyword works for all fields but one text field. Both in discover and dashboard it just say: “There aren’t any options available”. I have tried “refresh” and “clear cache” in index management. What goe…

---

## [ECE to opensearch migration](https://forum.opensearch.org/t/ece-to-opensearch-migration/24576)

<div class="topic-metadata">

**Author:** [@sharathsuryanarayana](https://forum.opensearch.org/u/sharathsuryanarayana)\
**Replies:** 0\
**Last updated:** [May 29, 2025, 4:56am UTC](https://forum.opensearch.org/t/ece-to-opensearch-migration/24576 "2025-05-29T04:56:24Z")

</div>

Is there any possibility to migrate from existing ECE to OpenSearch without loosing data and less downtime. If yes, please guide me Regards

---

## [Kibana watchers migration to Opensearch Dashboard](https://forum.opensearch.org/t/kibana-watchers-migration-to-opensearch-dashboard/24381)

<div class="topic-metadata">

**Author:** [@amitsinghkhati](https://forum.opensearch.org/u/amitsinghkhati)\
**Replies:** 0\
**Last updated:** [May 13, 2025, 7:10pm UTC](https://forum.opensearch.org/t/kibana-watchers-migration-to-opensearch-dashboard/24381 "2025-05-13T19:10:18Z")

</div>

I am trying to mimic kibana watchers functionality to Opensearch dashboard. Alerting is configured for opensearch dashboard, but I am unable to fetch columns of indexes in mail(action) of opensearch alerting which is in…

---

## [Expand action button needs to be configured in log table visualization](https://forum.opensearch.org/t/expand-action-button-needs-to-be-configured-in-log-table-visualization/23765)

<div class="topic-metadata">

**Author:** [@ishnoor](https://forum.opensearch.org/u/ishnoor)\
**Replies:** 0\
**Last updated:** [March 13, 2025, 8:03am UTC](https://forum.opensearch.org/t/expand-action-button-needs-to-be-configured-in-log-table-visualization/23765 "2025-03-13T08:03:19Z")

</div>

I have a severity dashboard which has multiple panels in it which contain logs, i need to have a expand button in every log like the ones available under the indexes under alerts in kibana which would expand and give a j…

---

## [Logstash-OSS with x-pack load error](https://forum.opensearch.org/t/logstash-oss-with-x-pack-load-error/23488)

<div class="topic-metadata">

**Author:** [@Shweta1](https://forum.opensearch.org/u/Shweta1)\
**Replies:** 1\
**Last updated:** [February 25, 2025, 6:43pm UTC](https://forum.opensearch.org/t/logstash-oss-with-x-pack-load-error/23488 "2025-02-25T18:43:40Z")

</div>

Hello! I am trying to upgrade logstash 7.16.3 to logstash-oss 8.17.2. After installing logsatsh-oss I am getting x-pack load error even though all x-pack settings are commented out in logstash.yml file. Opensearch versi…

---

## [What parameters range to consider to experiment with Lucene; Faiss engine types using HNSW algorithm](https://forum.opensearch.org/t/what-parameters-range-to-consider-to-experiment-with-lucene-faiss-engine-types-using-hnsw-algorithm/23471)

<div class="topic-metadata">

**Author:** [@Abdurrahman](https://forum.opensearch.org/u/Abdurrahman)\
**Replies:** 0\
**Last updated:** [February 21, 2025, 1:14pm UTC](https://forum.opensearch.org/t/what-parameters-range-to-consider-to-experiment-with-lucene-faiss-engine-types-using-hnsw-algorithm/23471 "2025-02-21T13:14:18Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): OpenSearch 2.17 Describe the issue: I want to know the range of parameters to consider or experiment with. For Lucene-HNSW ef\_construction, m, while index …

---

## [Looking for Best Practices for Optimizing Elasticsearch Performance?](https://forum.opensearch.org/t/looking-for-best-practices-for-optimizing-elasticsearch-performance/23469)

<div class="topic-metadata">

**Author:** [@derektheler](https://forum.opensearch.org/u/derektheler)\
**Replies:** 0\
**Last updated:** [February 21, 2025, 11:19am UTC](https://forum.opensearch.org/t/looking-for-best-practices-for-optimizing-elasticsearch-performance/23469 "2025-02-21T11:19:37Z")

</div>

Hey everyone, I have been using Elasticsearch for a while…, but I am looking for some expert advice on optimizing performance, especially for large datasets. I have noticed some slow queries and increased resource usage…

---

## [400 'illegal\_argument\_exception', 'explicit index in bulk is not allowed'](https://forum.opensearch.org/t/400-illegal-argument-exception-explicit-index-in-bulk-is-not-allowed/23246)

<div class="topic-metadata">

**Author:** [@umakant](https://forum.opensearch.org/u/umakant)\
**Replies:** 2\
**Last updated:** [January 29, 2025, 7:15pm UTC](https://forum.opensearch.org/t/400-illegal-argument-exception-explicit-index-in-bulk-is-not-allowed/23246 "2025-01-29T19:15:26Z")

</div>

Folks, I am trying to use opensearch and facing the following error. Error RequestError(400, 'illegal\_argument\_exception', 'explicit index in bulk is not allowed') Setup OpenSearch Versions tested: 1.3.17, 2.18.0, 2.9.…

---

## [OpenSearch searchable snapshot](https://forum.opensearch.org/t/opensearch-searchable-snapshot/22925)

<div class="topic-metadata">

**Author:** [@Nikita\_sahu](https://forum.opensearch.org/u/Nikita_sahu)\
**Replies:** 4\
**Last updated:** [January 13, 2025, 10:27am UTC](https://forum.opensearch.org/t/opensearch-searchable-snapshot/22925 "2025-01-13T10:27:01Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): I used opensearch 2.11.1 version Describe the issue: I used an OpenSearch cluster to store my data and implemented an ILM (Index Lifecycle Management) poli…

---

## [Lengthy Opensearch Query formed from SQL using opendistro](https://forum.opensearch.org/t/lengthy-opensearch-query-formed-from-sql-using-opendistro/12206)

<div class="topic-metadata">

**Author:** [@Sahil](https://forum.opensearch.org/u/Sahil)\
**Replies:** 1\
**Last updated:** [January 6, 2025, 11:53am UTC](https://forum.opensearch.org/t/lengthy-opensearch-query-formed-from-sql-using-opendistro/12206 "2025-01-06T11:53:54Z")

</div>

When we hit the opendistro endpoint with SQL query we are receiving an Opensearch query. For the current query, we get huge query. Is there any way using which we can optimise it ? POST \_opendistro/\_sql/\_explain { "qu…

---

## [Copy dashboards from elasticsearch to opensearch](https://forum.opensearch.org/t/copy-dashboards-from-elasticsearch-to-opensearch/22135)

<div class="topic-metadata">

**Author:** [@Deepa](https://forum.opensearch.org/u/Deepa)\
**Replies:** 0\
**Last updated:** [October 29, 2024, 5:19am UTC](https://forum.opensearch.org/t/copy-dashboards-from-elasticsearch-to-opensearch/22135 "2024-10-29T05:19:57Z")

</div>

Hi Am copying dashboards created in elasticsearch kibana to opensearch , using export Import functionality. But am getting message as Please help

---

## [I want Advice to Increase Search Effectiveness in Large Datasets](https://forum.opensearch.org/t/i-want-advice-to-increase-search-effectiveness-in-large-datasets/21796)

<div class="topic-metadata">

**Author:** [@inaraghj](https://forum.opensearch.org/u/inaraghj)\
**Replies:** 0\
**Last updated:** [October 4, 2024, 10:20am UTC](https://forum.opensearch.org/t/i-want-advice-to-increase-search-effectiveness-in-large-datasets/21796 "2024-10-04T10:20:13Z")

</div>

Hi everyone, I am working on a project that involves searching and analyzing large datasets & I want advice on optimizing search performance using OpenSearch. My primary goal is to ensure that our search queries return …

---

## [Opensearch with Kibana](https://forum.opensearch.org/t/opensearch-with-kibana/21600)

<div class="topic-metadata">

**Author:** [@zainakram](https://forum.opensearch.org/u/zainakram)\
**Replies:** 1\
**Last updated:** [September 23, 2024, 6:44pm UTC](https://forum.opensearch.org/t/opensearch-with-kibana/21600 "2024-09-23T18:44:44Z")

</div>

Hi, I wanted to know if there is any way that i can connect Opensearch with Kibana??

---

## [Sending logs to opensearch via filebeat](https://forum.opensearch.org/t/sending-logs-to-opensearch-via-filebeat/21078)

<div class="topic-metadata">

**Author:** [@blason](https://forum.opensearch.org/u/blason)\
**Replies:** 1\
**Last updated:** [September 3, 2024, 9:42pm UTC](https://forum.opensearch.org/t/sending-logs-to-opensearch-via-filebeat/21078 "2024-09-03T21:42:12Z")

</div>

Hi Team, I have been using logstash to ingest the logs to opensearch from my linux DNS server, now my requirement is I wanted to ingest the logs via filebeat → logstash → opensearch. Unfortunately that is not working a…

---

## [Data not visible in web interface after migration on OpenSearch](https://forum.opensearch.org/t/data-not-visible-in-web-interface-after-migration-on-opensearch/20809)

<div class="topic-metadata">

**Author:** [@kdr](https://forum.opensearch.org/u/kdr)\
**Replies:** 11\
**Last updated:** [August 30, 2024, 2:52am UTC](https://forum.opensearch.org/t/data-not-visible-in-web-interface-after-migration-on-opensearch/20809 "2024-08-30T02:52:31Z")

</div>

Hello. I have the next situation. I have 2 servers on rhel with: Graylog 3.3 + ElasticSearch 6.8.5 + Mongo 3 Graylog 5.2.9 + OpenSearch 2.15.0 + Mongo 7 On both servers all programms work in docker. I try to migrat…

---

## [Is there any way to send the reports to email addresses](https://forum.opensearch.org/t/is-there-any-way-to-send-the-reports-to-email-addresses/4981)

<div class="topic-metadata">

**Author:** [@blason](https://forum.opensearch.org/u/blason)\
**Replies:** 17\
**Last updated:** [August 27, 2024, 9:46am UTC](https://forum.opensearch.org/t/is-there-any-way-to-send-the-reports-to-email-addresses/4981 "2024-08-27T09:46:11Z")

</div>

Hi Team, Is there any way to send the reports to email address on a predefined schedule? Wondering if through API or any setting that needs to be enabled TIA Blason R

---

## [Opensearch Log Volume](https://forum.opensearch.org/t/opensearch-log-volume/20846)

<div class="topic-metadata">

**Author:** [@michipicchu](https://forum.opensearch.org/u/michipicchu)\
**Replies:** 0\
**Last updated:** [August 16, 2024, 9:02am UTC](https://forum.opensearch.org/t/opensearch-log-volume/20846 "2024-08-16T09:02:42Z")

</div>

Hi. I am trying to determine the log volume (daily or monthly) of my OpenSearch cluster. I have already researched, but I haven’t found a proper way to do this yet. Maybe someone has experience with this? Best, Michi

---

## [PS Insights - OpenSearch Dashboard Visualization displaying as 9.313,225,746,154,785e-10](https://forum.opensearch.org/t/ps-insights-opensearch-dashboard-visualization-displaying-as-9-313-225-746-154-785e-10/20648)

<div class="topic-metadata">

**Author:** [@Ivy](https://forum.opensearch.org/u/Ivy)\
**Replies:** 0\
**Last updated:** [August 1, 2024, 5:31pm UTC](https://forum.opensearch.org/t/ps-insights-opensearch-dashboard-visualization-displaying-as-9-313-225-746-154-785e-10/20648 "2024-08-01T17:31:57Z")

</div>

Hello, I use PeopleSoft Insights and OpenSearch Dashboard. I have created a visualization that displays aggregated numeric fields using “sum”. Some of the values show as scientific notation when summing to zero. I ent…

---

## [Opensearch (with compatibilityMode ON 7.10.2)NOT working with elastalert2 (400 error) : include\_type\_name=true](https://forum.opensearch.org/t/opensearch-with-compatibilitymode-on-7-10-2-not-working-with-elastalert2-400-error-include-type-name-true/20619)

<div class="topic-metadata">

**Author:** [@rajivk](https://forum.opensearch.org/u/rajivk)\
**Replies:** 0\
**Last updated:** [July 31, 2024, 8:53am UTC](https://forum.opensearch.org/t/opensearch-with-compatibilitymode-on-7-10-2-not-working-with-elastalert2-400-error-include-type-name-true/20619 "2024-07-31T08:53:24Z")

</div>

Hi there, We are having problems with using elastalert2 and Opensearch. We are using Opensearch, but need to use the compatibility mode 7.10.2, as some team members have found that Logstash and Beats (which we are using…

[Next page](https://forum.opensearch.org/c/general-elasticsearch/10.md?page=1)
