# Latest

**URL:** https://forum.opensearch.org/latest.md

[Latest](https://forum.opensearch.org/latest.md) · [Categories](https://forum.opensearch.org/categories.md) · [Tags](https://forum.opensearch.org/tags.md)

---

## [Permission denied Error message is not displayed in Dashboard](https://forum.opensearch.org/t/permission-denied-error-message-is-not-displayed-in-dashboard/14171)

<div class="topic-metadata">

**Author:** [@Chandana\_EP](https://forum.opensearch.org/u/Chandana_EP)\
**Replies:** 10\
**Last updated:** [September 23, 2026, 2:32pm UTC](https://forum.opensearch.org/t/permission-denied-error-message-is-not-displayed-in-dashboard/14171 "2026-09-23T14:32:25Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Opensearch v2.6.0 Describe the issue: I have created a user with limited permissions to access some index patterns. After logging in with the above created…

---

## ["follower\_index\_pattern" missing in CCR Auto-follow documentation](https://forum.opensearch.org/t/follower-index-pattern-missing-in-ccr-auto-follow-documentation/28284)

<div class="topic-metadata">

**Author:** [@farman](https://forum.opensearch.org/u/farman)\
**Replies:** 3\
**Last updated:** [September 23, 2026, 2:12pm UTC](https://forum.opensearch.org/t/follower-index-pattern-missing-in-ccr-auto-follow-documentation/28284 "2026-09-23T14:12:37Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: “follower\_index\_pattern” has been introduced in OpenSearch 3.8.0 as per release notes opensearch-build/release-notes/opensearch-release-n…

---

## [How to handle pre-existing indices using Auto-Follow](https://forum.opensearch.org/t/how-to-handle-pre-existing-indices-using-auto-follow/28289)

<div class="topic-metadata">

**Author:** [@farman](https://forum.opensearch.org/u/farman)\
**Replies:** 2\
**Last updated:** [September 23, 2026, 1:32pm UTC](https://forum.opensearch.org/t/how-to-handle-pre-existing-indices-using-auto-follow/28289 "2026-09-23T13:32:58Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: If I am using Auto-Follow for replication, then, follower indices are created automatically based on “pattern” and “follower\_index\_patter…

---

## [Before snapshot : is an operation "flush" needed?](https://forum.opensearch.org/t/before-snapshot-is-an-operation-flush-needed/28279)

<div class="topic-metadata">

**Author:** [@dmdevito](https://forum.opensearch.org/u/dmdevito)\
**Replies:** 2\
**Last updated:** [September 23, 2026, 12:19pm UTC](https://forum.opensearch.org/t/before-snapshot-is-an-operation-flush-needed/28279 "2026-09-23T12:19:36Z")

</div>

Versions : latest (non relevant) Describe the issue: Before taking an index snapshot, I have data in the in-memory ingesting buffer (and the translog too). Does taking a snapshot trigger a refresh and a flush of this i…

---

## [Teknofest finalist – SIEM log integrity project, looking for feedback](https://forum.opensearch.org/t/teknofest-finalist-siem-log-integrity-project-looking-for-feedback/28293)

<div class="topic-metadata">

**Author:** [@feridmehdiyevpersona](https://forum.opensearch.org/u/feridmehdiyevpersona)\
**Replies:** 2\
**Last updated:** [September 22, 2026, 8:29am UTC](https://forum.opensearch.org/t/teknofest-finalist-siem-log-integrity-project-looking-for-feedback/28293 "2026-09-22T08:29:04Z")

</div>

Hello everyone, I’m a cybersecurity engineering student at BHOS, and my team is currently in the final stage of the TEKNOFEST Blockchain Competition. Our project focuses on SIEM log integrity. We have built a working p…

---

## [Maintenance Mode](https://forum.opensearch.org/t/maintenance-mode/28251)

<div class="topic-metadata">

**Author:** [@ThePinkOne](https://forum.opensearch.org/u/ThePinkOne)\
**Replies:** 4\
**Last updated:** [September 17, 2026, 8:38am UTC](https://forum.opensearch.org/t/maintenance-mode/28251 "2026-09-17T08:38:03Z")

</div>

Versions OpenSearch 3.7.0 Describe the issue: Hello everyone, I’m running OpenSearch in a container and not (yet) as a cluster. The logs are sent from the hosts to OpenSearch via Fluent Bit. At the moment, the entire …

---

## [ISM policy for Remote indices](https://forum.opensearch.org/t/ism-policy-for-remote-indices/28290)

<div class="topic-metadata">

**Author:** [@muraliv](https://forum.opensearch.org/u/muraliv)\
**Replies:** 0\
**Last updated:** [September 16, 2026, 3:54pm UTC](https://forum.opensearch.org/t/ism-policy-for-remote-indices/28290 "2026-09-16T15:54:08Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.6 Describe the issue: I want to change the policy attached to a remote or restored index and getting an exception. The index is in a failed state due to …

---

## [Shards appear to have negative size, and block listing them](https://forum.opensearch.org/t/shards-appear-to-have-negative-size-and-block-listing-them/28288)

<div class="topic-metadata">

**Author:** [@Camusensei](https://forum.opensearch.org/u/Camusensei)\
**Replies:** 0\
**Last updated:** [September 16, 2026, 9:10am UTC](https://forum.opensearch.org/t/shards-appear-to-have-negative-size-and-block-listing-them/28288 "2026-09-16T09:10:15Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.8.0 Describe the issue: Some shards appear to report a negative size. It’s impossible to list the shards because of this. Configuration: Read/write separa…

---

## [Is changing cluster.name safe during a Kubernetes rolling update (StatefulSet)?](https://forum.opensearch.org/t/is-changing-cluster-name-safe-during-a-kubernetes-rolling-update-statefulset/28278)

<div class="topic-metadata">

**Author:** [@shubtiwa](https://forum.opensearch.org/u/shubtiwa)\
**Replies:** 1\
**Last updated:** [September 15, 2026, 2:44pm UTC](https://forum.opensearch.org/t/is-changing-cluster-name-safe-during-a-kubernetes-rolling-update-statefulset/28278 "2026-09-15T14:44:46Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.7.0 Describe the issue: We run OpenSearch 3.7.0 on Kubernetes via Helm. The cluster.name is set through the CLUSTER\_NAME environment variable, which gets …

---

## [Alerting / Monitors](https://forum.opensearch.org/t/alerting-monitors/28286)

<div class="topic-metadata">

**Author:** [@muraliv](https://forum.opensearch.org/u/muraliv)\
**Replies:** 3\
**Last updated:** [September 15, 2026, 12:15pm UTC](https://forum.opensearch.org/t/alerting-monitors/28286 "2026-09-15T12:15:55Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.8 Describe the issue: Members sharing at least one common backend role are not able to see the alerts or monitor definition. When I look at the monitor d…

---

## [Can JWT and OIDC authentication be used simultaneously with OpenSearch Dashboards?](https://forum.opensearch.org/t/can-jwt-and-oidc-authentication-be-used-simultaneously-with-opensearch-dashboards/28268)

<div class="topic-metadata">

**Author:** [@shubtiwa](https://forum.opensearch.org/u/shubtiwa)\
**Replies:** 3\
**Last updated:** [September 14, 2026, 11:56pm UTC](https://forum.opensearch.org/t/can-jwt-and-oidc-authentication-be-used-simultaneously-with-opensearch-dashboards/28268 "2026-09-14T23:56:29Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 2.19 Describe the issue: Hi, I currently have JWT authentication working with OpenSearch Dashboards, and OIDC authentication is also working independently. …

---

## [Orphaned blobs Cleanup](https://forum.opensearch.org/t/orphaned-blobs-cleanup/28198)

<div class="topic-metadata">

**Author:** [@muraliv](https://forum.opensearch.org/u/muraliv)\
**Replies:** 4\
**Last updated:** [September 14, 2026, 12:31pm UTC](https://forum.opensearch.org/t/orphaned-blobs-cleanup/28198 "2026-09-14T12:31:10Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.7 Describe the issue: When I try to run the following API POST /\_snapshot/\<repo\>/\_cleanup I am getting the following error. { "error": { "root\_ca…

---

## [What does "dr","mr" etc stand for in roles for nodes](https://forum.opensearch.org/t/what-does-dr-mr-etc-stand-for-in-roles-for-nodes/5210)

<div class="topic-metadata">

**Author:** [@curiousmind](https://forum.opensearch.org/u/curiousmind)\
**Replies:** 2\
**Last updated:** [September 12, 2026, 7:51pm UTC](https://forum.opensearch.org/t/what-does-dr-mr-etc-stand-for-in-roles-for-nodes/5210 "2026-09-12T19:51:54Z")

</div>

The following request GET \_cat/nodes?v gave me response like this: I know that, d is for data, m is for master eligible, i is for ingest etc. But what does this “r” stands for?

---

## [(Official) Training for OpenSearch?](https://forum.opensearch.org/t/official-training-for-opensearch/5951)

<div class="topic-metadata">

**Author:** [@ralph](https://forum.opensearch.org/u/ralph)\
**Replies:** 5\
**Last updated:** [September 11, 2026, 4:34am UTC](https://forum.opensearch.org/t/official-training-for-opensearch/5951 "2026-09-11T04:34:53Z")

</div>

as you might be aware, elastic is offering trainings and certifications. i also just saw now that they’re changing their training to be more focused on Elastic Cloud (which is anyway not relevant for OpenSearch). are th…

---

## [Recap: Washington DC OpenSearch User Group Meetup #2, August 13](https://forum.opensearch.org/t/recap-washington-dc-opensearch-user-group-meetup-2-august-13/28282)

<div class="topic-metadata">

**Author:** [@rutger](https://forum.opensearch.org/u/rutger)\
**Replies:** 1\
**Last updated:** [September 10, 2026, 11:00pm UTC](https://forum.opensearch.org/t/recap-washington-dc-opensearch-user-group-meetup-2-august-13/28282 "2026-09-10T23:00:58Z")

</div>

We were back at Carahsoft in Reston on August 13 for the second Washington DC OpenSearch User Group meetup. Twelve people checked in, and what struck me was how many of them I was meeting for the first time. The room was…

---

## [Opensearch Nagpur User Group - September Meetup 2026](https://forum.opensearch.org/t/opensearch-nagpur-user-group-september-meetup-2026/28273)

<div class="topic-metadata">

**Author:** [@aryanvijaykar](https://forum.opensearch.org/u/aryanvijaykar)\
**Replies:** 1\
**Last updated:** [September 8, 2026, 4:04pm UTC](https://forum.opensearch.org/t/opensearch-nagpur-user-group-september-meetup-2026/28273 "2026-09-08T16:04:28Z")

</div>

Hey everyone! :waving\_hand: For a while, we had been wondering… Why doesn’t Nagpur have an OpenSearch User Group? There are so many amazing OpenSearch communities around the world, and we felt it was time for Nagpur to…

---

## [A static linter for aggregation queries: catching the ones that return 200 OK](https://forum.opensearch.org/t/a-static-linter-for-aggregation-queries-catching-the-ones-that-return-200-ok/28280)

<div class="topic-metadata">

**Author:** [@anagha11](https://forum.opensearch.org/u/anagha11)\
**Replies:** 0\
**Last updated:** [September 8, 2026, 4:03pm UTC](https://forum.opensearch.org/t/a-static-linter-for-aggregation-queries-catching-the-ones-that-return-200-ok/28280 "2026-09-08T16:03:23Z")

</div>

Hi all, I wrote a small open source tool that lints an aggs block against your mapping without a running cluster, and I’m sharing it here partly in case it’s useful and partly because I want to know which rules it’s mis…

---

## [My docker opensearch data prepper can't find pipelines](https://forum.opensearch.org/t/my-docker-opensearch-data-prepper-cant-find-pipelines/28275)

<div class="topic-metadata">

**Author:** [@NordeN](https://forum.opensearch.org/u/NordeN)\
**Replies:** 2\
**Last updated:** [September 8, 2026, 10:39am UTC](https://forum.opensearch.org/t/my-docker-opensearch-data-prepper-cant-find-pipelines/28275 "2026-09-08T10:39:13Z")

</div>

I’m trying to configure the OpenSearch Data Prepper log collector with Winlogbeat to write to OpenSearch. My OpenSearch is deployed on a host. And the OpenSearch Data Prepper is in a Docker container. I have the follow…

---

## [Help configuring an OpenSearch 3.5 alerting monitor with three triggers](https://forum.opensearch.org/t/help-configuring-an-opensearch-3-5-alerting-monitor-with-three-triggers/28261)

<div class="topic-metadata">

**Author:** [@Pan-Vad](https://forum.opensearch.org/u/Pan-Vad)\
**Replies:** 3\
**Last updated:** [September 4, 2026, 4:06pm UTC](https://forum.opensearch.org/t/help-configuring-an-opensearch-3-5-alerting-monitor-with-three-triggers/28261 "2026-09-04T16:06:28Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): OpenSearch 3.5/OSD 3.5/Win10/Google Chrome Describe the issue: I am using OpenSearch 3.5 and need assistance configuring an Alerting Monitor. I need to cre…

---

## [Log4j 2.25.4 Vulnerability in OpenSearch 3.8.0](https://forum.opensearch.org/t/log4j-2-25-4-vulnerability-in-opensearch-3-8-0/28266)

<div class="topic-metadata">

**Author:** [@scott](https://forum.opensearch.org/u/scott)\
**Replies:** 1\
**Last updated:** [September 3, 2026, 5:23pm UTC](https://forum.opensearch.org/t/log4j-2-25-4-vulnerability-in-opensearch-3-8-0/28266 "2026-09-03T17:23:06Z")

</div>

Versions: OpenSearch 3.8.0 & Log4j 2.25.4 Describe the issue: OpenSearch 3.8.0 uses Log4j 2.25.4 which has a vulnerability, CVE-2026-49844. Does CVE-2026-49844 impact OpenSearch? Any plans to upgrade Log4j version? …

---

## [Best way to store document chunks for vector search as production standard](https://forum.opensearch.org/t/best-way-to-store-document-chunks-for-vector-search-as-production-standard/27918)

<div class="topic-metadata">

**Author:** [@grunggy](https://forum.opensearch.org/u/grunggy)\
**Replies:** 2\
**Last updated:** [September 3, 2026, 12:49am UTC](https://forum.opensearch.org/t/best-way-to-store-document-chunks-for-vector-search-as-production-standard/27918 "2026-09-03T00:49:28Z")

</div>

Hi, working on a RAG setup and trying to land on a sensible production architecture for chunk storage and retrieval. Curious what others are running at scale. Large documents get split into chunks at ingestion, each chu…

---

## [\[RFC\] Upgrade Kotlin Version Across OpenSearch Plugins to a Supported Release](https://forum.opensearch.org/t/rfc-upgrade-kotlin-version-across-opensearch-plugins-to-a-supported-release/28270)

<div class="topic-metadata">

**Author:** [@Yogita](https://forum.opensearch.org/u/Yogita)\
**Replies:** 0\
**Last updated:** [September 2, 2026, 3:51pm UTC](https://forum.opensearch.org/t/rfc-upgrade-kotlin-version-across-opensearch-plugins-to-a-supported-release/28270 "2026-09-02T15:51:52Z")

</div>

The current Kotlin version used by OpenSearch plugins appears to be on an unsupported release stream. Kotlin 2.3 is no longer the current supported release stream, while Kotlin 2.4.x is actively maintained and receives …

---

## [CCR and Snapshot](https://forum.opensearch.org/t/ccr-and-snapshot/28267)

<div class="topic-metadata">

**Author:** [@farman](https://forum.opensearch.org/u/farman)\
**Replies:** 0\
**Last updated:** [September 2, 2026, 5:42am UTC](https://forum.opensearch.org/t/ccr-and-snapshot/28267 "2026-09-02T05:42:08Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: If CCR is configured between Leader and Follower clusters, when snapshot of Follower is taken will it also include replication specific m…

---

## [Prometheus exporter plugin 2.19.6.0 released!](https://forum.opensearch.org/t/prometheus-exporter-plugin-2-19-6-0-released/28265)

<div class="topic-metadata">

**Author:** [@ps48](https://forum.opensearch.org/u/ps48)\
**Replies:** 0\
**Last updated:** [August 28, 2026, 8:50pm UTC](https://forum.opensearch.org/t/prometheus-exporter-plugin-2-19-6-0-released/28265 "2026-08-28T20:50:22Z")

</div>

Hi everyone, I’m happy to announce a new release of the Prometheus exporter plugin for OpenSearch: version 2.19.6.0. As always, all plugin releases can be found on the GitHub releases page. This is a maintenance releas…

---

## [ISM Rollover with Multiple Conditions](https://forum.opensearch.org/t/ism-rollover-with-multiple-conditions/28139)

<div class="topic-metadata">

**Author:** [@muraliv](https://forum.opensearch.org/u/muraliv)\
**Replies:** 2\
**Last updated:** [August 27, 2026, 10:31am UTC](https://forum.opensearch.org/t/ism-rollover-with-multiple-conditions/28139 "2026-08-27T10:31:40Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 3.7 Describe the issue: I have an ISM policy with min\_index\_age, min\_shard\_size & min\_doc\_count. Since it’s an OR condition, I am having indices with 0 doc…

---

## [Remote state fails to write because of a wrong generated path](https://forum.opensearch.org/t/remote-state-fails-to-write-because-of-a-wrong-generated-path/28249)

<div class="topic-metadata">

**Author:** [@Camusensei](https://forum.opensearch.org/u/Camusensei)\
**Replies:** 7\
**Last updated:** [August 26, 2026, 1:09pm UTC](https://forum.opensearch.org/t/remote-state-fails-to-write-because-of-a-wrong-generated-path/28249 "2026-08-26T13:09:43Z")

</div>

Versions (OpenSearch): 3.6.0 and 3.7.0 Describe the issue: Enabling remote store (minio) leads to state index metadata failing to get written because the path is incorrectly constructed Instead of sending the files to: …

---

## [Data node thread pool](https://forum.opensearch.org/t/data-node-thread-pool/28179)

<div class="topic-metadata">

**Author:** [@aussie](https://forum.opensearch.org/u/aussie)\
**Replies:** 6\
**Last updated:** [August 25, 2026, 1:53pm UTC](https://forum.opensearch.org/t/data-node-thread-pool/28179 "2026-08-25T13:53:39Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: Certain OpenSearch data nodes are becoming overloaded due to heavy search execution. The overload is visible through elevated search thre…

---

## [CIDR modifier for sigma detection rules works only for IPv4 addresses, not for IPv6 resulting in sigma detection error](https://forum.opensearch.org/t/cidr-modifier-for-sigma-detection-rules-works-only-for-ipv4-addresses-not-for-ipv6-resulting-in-sigma-detection-error/28232)

<div class="topic-metadata">

**Author:** [@mutant](https://forum.opensearch.org/u/mutant)\
**Replies:** 5\
**Last updated:** [August 25, 2026, 9:22am UTC](https://forum.opensearch.org/t/cidr-modifier-for-sigma-detection-rules-works-only-for-ipv4-addresses-not-for-ipv6-resulting-in-sigma-detection-error/28232 "2026-08-25T09:22:12Z")

</div>

I was getting a Sigma Detection Error when trying to import a rule from Sigma repository to opensearch. Upon further inspection in the source code, i found out that only IPv4 addresses are validated. IPv6 addresses fail …

---

## [Incompatible index on upgrade to v3.0.0](https://forum.opensearch.org/t/incompatible-index-on-upgrade-to-v3-0-0/24373)

<div class="topic-metadata">

**Author:** [@joelp](https://forum.opensearch.org/u/joelp)\
**Replies:** 4\
**Last updated:** [August 25, 2026, 6:52am UTC](https://forum.opensearch.org/t/incompatible-index-on-upgrade-to-v3-0-0/24373 "2026-08-25T06:52:05Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): OpenSearch 3.0.0 Describe the issue: I’m trying to upgrade to version 3.0. But getting this error: org.opensearch.bootstrap.StartupException: java.lang.Il…

---

## [Opensearch startup errors that disappear over time](https://forum.opensearch.org/t/opensearch-startup-errors-that-disappear-over-time/28211)

<div class="topic-metadata">

**Author:** [@Ruslan1](https://forum.opensearch.org/u/Ruslan1)\
**Replies:** 24\
**Last updated:** [August 24, 2026, 3:46pm UTC](https://forum.opensearch.org/t/opensearch-startup-errors-that-disappear-over-time/28211 "2026-08-24T15:46:41Z")

</div>

Good day ! I have a problem with my OpenSearch setup using Docker Compose. I have the following configuration in my \`docker-compose.yml\` file: services: opensearch: image: opensearch:3.7.0 container\_name: o…

[Next page](https://forum.opensearch.org/latest.md?page=1)
