# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=125

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 126

---

## [Elasticsearch Upgrade from Version 7.17.4 to 8.12.0](https://discuss.elastic.co/t/elasticsearch-upgrade-from-version-7-17-4-to-8-12-0/357253)

<div class="topic-metadata">

**Author:** [@DannyDuo](https://discuss.elastic.co/u/DannyDuo)\
**Replies:** 3\
**Last updated:** [April 12, 2024, 5:47am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-version-7-17-4-to-8-12-0/357253 "2024-04-12T05:47:41Z")

</div>

Hello everyone, I got 6 old version 7.17 nodes and 6 new version 8.12 nodes in the stack now. I am trying to remove old nodes. But some shards recovery failed. Is it just impossible to recovery from a 7.17 node to an …

---

## [Preventing document update based on field values](https://discuss.elastic.co/t/preventing-document-update-based-on-field-values/356858)

<div class="topic-metadata">

**Author:** [@ashish25](https://discuss.elastic.co/u/ashish25)\
**Replies:** 9\
**Last updated:** [April 12, 2024, 5:22am UTC](https://discuss.elastic.co/t/preventing-document-update-based-on-field-values/356858 "2024-04-12T05:22:17Z")

</div>

Is there anyway to prevent updating document based on some field? Eg- Below documents already present in elastic: { "business\_address" : "660 Sacramento St", "business\_city" : "San Francisco", "business\_id" : 22 } …

---

## [How to set up the deletion phase in an ILM policy](https://discuss.elastic.co/t/how-to-set-up-the-deletion-phase-in-an-ilm-policy/357233)

<div class="topic-metadata">

**Author:** [@Raul\_Anastacio](https://discuss.elastic.co/u/Raul_Anastacio)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 4:27pm UTC](https://discuss.elastic.co/t/how-to-set-up-the-deletion-phase-in-an-ilm-policy/357233 "2024-04-11T16:27:45Z")

</div>

I've configured my ILM policy; however, the deletion phase isn't functioning as expected. While indices transition through the warm, hot, and cold phases seamlessly, they aren't being deleted afterward. Do I need to esta…

---

## [REST request tracer](https://discuss.elastic.co/t/rest-request-tracer/357228)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 3:40pm UTC](https://discuss.elastic.co/t/rest-request-tracer/357228 "2024-04-11T15:40:15Z")

</div>

Hi, I try to trace all HTTP REST recuests for debugging purpose. I am indexing documents using an ingest pipeline on an Elasticsearch node which was deployed by ECK operator. I followed the guide here: Networking | Ela…

---

## [Purge elasticsearch data older than 1month](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 4\
**Last updated:** [April 11, 2024, 2:44pm UTC](https://discuss.elastic.co/t/purge-elasticsearch-data-older-than-1month/356909 "2024-04-11T14:44:41Z")

</div>

Hi, I am running ELK on Red Hat Enterprise Linux release 8.9 (Ootpa) elasticsearch-8.13.1-1.x86\_64 logstash-8.13.1-1.x86\_64 kibana-8.13.1-1.x86\_64 filebeat-8.13.1-1.x86\_64 Is there a way to purge elasticsearch data…

---

## [How to search documents with "empty" nested array using SQL](https://discuss.elastic.co/t/how-to-search-documents-with-empty-nested-array-using-sql/357145)

<div class="topic-metadata">

**Author:** [@vinitp](https://discuss.elastic.co/u/vinitp)\
**Replies:** 2\
**Last updated:** [April 11, 2024, 12:58pm UTC](https://discuss.elastic.co/t/how-to-search-documents-with-empty-nested-array-using-sql/357145 "2024-04-11T12:58:01Z")

</div>

Our custom application builds Elasticsearch SQL dynamically based on the criteria provided in the request. The document has a few nested arrays. e.g. "Person" may have an array of nested "addresses". I could build a SQL…

---

## [Set \_id during pipeline in bulk ingestion](https://discuss.elastic.co/t/set-id-during-pipeline-in-bulk-ingestion/357158)

<div class="topic-metadata">

**Author:** [@wnmills3](https://discuss.elastic.co/u/wnmills3)\
**Replies:** 5\
**Last updated:** [April 11, 2024, 12:04pm UTC](https://discuss.elastic.co/t/set-id-during-pipeline-in-bulk-ingestion/357158 "2024-04-11T12:04:10Z")

</div>

How can I set the \_id field to the value of the id property defined in my mappings? In my mappings I have an id field defined as follows: "id": { "type": "text", "fields": { "type": "keyword", "ign…

---

## [Lifecycle Policies per monitoring vm](https://discuss.elastic.co/t/lifecycle-policies-per-monitoring-vm/357194)

<div class="topic-metadata">

**Author:** [@Mr.Tomas](https://discuss.elastic.co/u/Mr.Tomas)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 9:45am UTC](https://discuss.elastic.co/t/lifecycle-policies-per-monitoring-vm/357194 "2024-04-11T09:45:20Z")

</div>

Hello community! My first try with Elastic, still learning and reading the documentation. But decided to ask a question in parallel to my studies. I got a task to collect events from ~100 windows servers. I’ve install…

---

## [Upgrade from 8.3 to 8.13 in a dockerized environment](https://discuss.elastic.co/t/upgrade-from-8-3-to-8-13-in-a-dockerized-environment/357156)

<div class="topic-metadata">

**Author:** [@Patrik\_H](https://discuss.elastic.co/u/Patrik_H)\
**Replies:** 2\
**Last updated:** [April 11, 2024, 6:39am UTC](https://discuss.elastic.co/t/upgrade-from-8-3-to-8-13-in-a-dockerized-environment/357156 "2024-04-11T06:39:58Z")

</div>

Hi there, Is there any restricted path between minor version upgrades to go from 8.3 to 8.13 per minor versions or can i upgrade my stack from 8.3 to 8.13 in one step? I did not find any documentation which mentions thi…

---

## [Elasticsearch snapshot/restore to s3](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-to-s3/357132)

<div class="topic-metadata">

**Author:** [@kannetisiva](https://discuss.elastic.co/u/kannetisiva)\
**Replies:** 1\
**Last updated:** [April 11, 2024, 5:03am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-restore-to-s3/357132 "2024-04-11T05:03:21Z")

</div>

HTTP/1.1 500 Internal Server Error X-elastic-product: Elasticsearch content-type: application/json;charset=utf-8 content-length: 654 {"error":{"root\_cause":\[{"type":"repository\_exception","reason":"\[s3\_repo\] Could no…

---

## [How to return bucket with 0 count in terms aggregation](https://discuss.elastic.co/t/how-to-return-bucket-with-0-count-in-terms-aggregation/357180)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 1:05am UTC](https://discuss.elastic.co/t/how-to-return-bucket-with-0-count-in-terms-aggregation/357180 "2024-04-11T01:05:52Z")

</div>

I want to get return bucket even though the count is 0. How to get daily histogram buckets with 0 count?? My aggregation query is below. I want to every histogram buckets from last Sunday to Saturday. { "size": 0, …

---

## [Not getting any results for a field that requires exact match](https://discuss.elastic.co/t/not-getting-any-results-for-a-field-that-requires-exact-match/357102)

<div class="topic-metadata">

**Author:** [@Sujinthan](https://discuss.elastic.co/u/Sujinthan)\
**Replies:** 6\
**Last updated:** [April 10, 2024, 7:37pm UTC](https://discuss.elastic.co/t/not-getting-any-results-for-a-field-that-requires-exact-match/357102 "2024-04-10T19:37:08Z")

</div>

I'm building a search feature that allows users to filter by certain field. One of the field is DOI. Filtering by DOI should only return results with exact match. I'm trying to index the following object: public class …

---

## [Elastic not searching in http.response.body.content field](https://discuss.elastic.co/t/elastic-not-searching-in-http-response-body-content-field/357130)

<div class="topic-metadata">

**Author:** [@CoreCPU](https://discuss.elastic.co/u/CoreCPU)\
**Replies:** 3\
**Last updated:** [April 10, 2024, 3:11pm UTC](https://discuss.elastic.co/t/elastic-not-searching-in-http-response-body-content-field/357130 "2024-04-10T15:11:36Z")

</div>

Hello, I have an index which contains the field "http.response.body.content". I updated the ignore\_above values since this field was ignored. However, it would seem that elasticsearch does not search the content of th…

---

## [How to invoke processors with BulkIngester with Java APIs](https://discuss.elastic.co/t/how-to-invoke-processors-with-bulkingester-with-java-apis/356878)

<div class="topic-metadata">

**Author:** [@wnmills3](https://discuss.elastic.co/u/wnmills3)\
**Replies:** 10\
**Last updated:** [April 10, 2024, 2:57pm UTC](https://discuss.elastic.co/t/how-to-invoke-processors-with-bulkingester-with-java-apis/356878 "2024-04-10T14:57:59Z")

</div>

I'm trying to use the Java API's to invoke a processor while doing bulk indexing. I've set up the processor on my index to use the intfloat\_\_multilingual-e5-base (see below) to map the value of the passage field to a pas…

---

## [Is there a way to read from only the index set as write index](https://discuss.elastic.co/t/is-there-a-way-to-read-from-only-the-index-set-as-write-index/357135)

<div class="topic-metadata">

**Author:** [@Maitri](https://discuss.elastic.co/u/Maitri)\
**Replies:** 3\
**Last updated:** [April 10, 2024, 1:59pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-read-from-only-the-index-set-as-write-index/357135 "2024-04-10T13:59:33Z")

</div>

Hi, I have created two index with the same alias, Index1 and Index2. Current live data goes into Index1. The reason for creating index2 is I am developing a feature and when it is released I want to remove Index1 and sw…

---

## [Regarding Bulk Indexing Requests](https://discuss.elastic.co/t/regarding-bulk-indexing-requests/357034)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 17\
**Last updated:** [April 10, 2024, 1:55pm UTC](https://discuss.elastic.co/t/regarding-bulk-indexing-requests/357034 "2024-04-10T13:55:42Z")

</div>

Hi, Is there a way I can view the size (number of documents) of a bulk index request once it hits the elasticsearch queue? I want to estimate how efficiently logstash is batching requests that it pushes to elasticsearch…

---

## [Usage CPU during search query](https://discuss.elastic.co/t/usage-cpu-during-search-query/357059)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [April 10, 2024, 12:41pm UTC](https://discuss.elastic.co/t/usage-cpu-during-search-query/357059 "2024-04-10T12:41:05Z")

</div>

Hi I'm wondering why during search query, only one are overloading CPU, while we have index divided on 3 shards each on nodes.

---

## [Vector embedding huge size increase](https://discuss.elastic.co/t/vector-embedding-huge-size-increase/356670)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 2\
**Last updated:** [April 10, 2024, 12:40pm UTC](https://discuss.elastic.co/t/vector-embedding-huge-size-increase/356670 "2024-04-10T12:40:57Z")

</div>

Hello! I am currently doing a few tests on Vector Search and Vector Embeddings and found that with a subset of 1.000 documents I have an index with the size of 15mb(+-). When I create a new Index for the vector embeddin…

---

## [Stopping Elasticsearch using 'systemctl stop elasticsearch.service' operation consistently fails](https://discuss.elastic.co/t/stopping-elasticsearch-using-systemctl-stop-elasticsearch-service-operation-consistently-fails/357126)

<div class="topic-metadata">

**Author:** [@Mitanshu\_Bhoot](https://discuss.elastic.co/u/Mitanshu_Bhoot)\
**Replies:** 0\
**Last updated:** [April 10, 2024, 10:38am UTC](https://discuss.elastic.co/t/stopping-elasticsearch-using-systemctl-stop-elasticsearch-service-operation-consistently-fails/357126 "2024-04-10T10:38:00Z")

</div>

Elasticsearch's stop operation fails when attempting to gracefully stop using the systemctl command. The node contains a substantial amount of data, around 10TBs with 200 shards. ES version is 8.9. Is there any solution …

---

## [On k8s, elasticsearch events return degrated status, but all is green on cluster](https://discuss.elastic.co/t/on-k8s-elasticsearch-events-return-degrated-status-but-all-is-green-on-cluster/356112)

<div class="topic-metadata">

**Author:** [@jeromepp](https://discuss.elastic.co/u/jeromepp)\
**Replies:** 1\
**Last updated:** [April 10, 2024, 10:38am UTC](https://discuss.elastic.co/t/on-k8s-elasticsearch-events-return-degrated-status-but-all-is-green-on-cluster/356112 "2024-04-10T10:38:37Z")

</div>

Hello, We use ECK with latest Helm version and Elastisearch 8.12. But this seems to be not relevant to version, there were a similar case without any response : Get events for Elasticsearch cluster health degraded , but…

---

## [ES snapshot getting failed when ES pod get restarted](https://discuss.elastic.co/t/es-snapshot-getting-failed-when-es-pod-get-restarted/357125)

<div class="topic-metadata">

**Author:** [@Nilesh\_Tilani](https://discuss.elastic.co/u/Nilesh_Tilani)\
**Replies:** 0\
**Last updated:** [April 10, 2024, 10:35am UTC](https://discuss.elastic.co/t/es-snapshot-getting-failed-when-es-pod-get-restarted/357125 "2024-04-10T10:35:00Z")

</div>

Hello Team, I have enable the snapshot using below keystore feature elasticsearch-keystore add-file gcs.client.default.credentials\_file ./backup.json but when ES pod get restarted keystore config remove above config …

---

## [Setting Rollover Alias for Multiple Indices Under a Single Template](https://discuss.elastic.co/t/setting-rollover-alias-for-multiple-indices-under-a-single-template/355235)

<div class="topic-metadata">

**Author:** [@saisimo01](https://discuss.elastic.co/u/saisimo01)\
**Replies:** 3\
**Last updated:** [April 10, 2024, 9:59am UTC](https://discuss.elastic.co/t/setting-rollover-alias-for-multiple-indices-under-a-single-template/355235 "2024-04-10T09:59:21Z")

</div>

Hello Elastic Community, I am currently managing multiple Elastic indices formatted like es-project1-app1, es-project1-app2,... es-project2-app1, es-project2-app2, etc., across various projects. At the moment, it seems …

---

## [Elasticsearch bulk indexing the documents using Java API Client](https://discuss.elastic.co/t/elasticsearch-bulk-indexing-the-documents-using-java-api-client/356995)

<div class="topic-metadata">

**Author:** [@harsha\_kannan](https://discuss.elastic.co/u/harsha_kannan)\
**Replies:** 1\
**Last updated:** [April 10, 2024, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-bulk-indexing-the-documents-using-java-api-client/356995 "2024-04-10T08:51:02Z")

</div>

0 I have inserted some documents into my index using ElasticsearchRepository's saveAll() method and Bulk Indexing method. When I tried fetching records using elasticSearchOperations and I see the fields name has changed…

---

## [Extracting logs form archive before ingestion to elasticsearch](https://discuss.elastic.co/t/extracting-logs-form-archive-before-ingestion-to-elasticsearch/357120)

<div class="topic-metadata">

**Author:** [@pieke](https://discuss.elastic.co/u/pieke)\
**Replies:** 0\
**Last updated:** [April 10, 2024, 8:45am UTC](https://discuss.elastic.co/t/extracting-logs-form-archive-before-ingestion-to-elasticsearch/357120 "2024-04-10T08:45:44Z")

</div>

hello, For a project I am working on i am trying to create a centralized automated logging collection and visualisation solution using elasticstack. for this i need to ingest log files from multiple devices to elasticse…

---

## [Fleet server goes offline right after successfull install](https://discuss.elastic.co/t/fleet-server-goes-offline-right-after-successfull-install/355944)

<div class="topic-metadata">

**Author:** [@MheniMerz](https://discuss.elastic.co/u/MheniMerz)\
**Replies:** 12\
**Last updated:** [April 10, 2024, 6:44am UTC](https://discuss.elastic.co/t/fleet-server-goes-offline-right-after-successfull-install/355944 "2024-04-10T06:44:56Z")

</div>

Hi, i followed the steps in kibana and the docs to install a fleet server on premise (generated certificates from the elasticsearch CA), curl -L -O https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-age…

---

## [Save data from error handler to other index](https://discuss.elastic.co/t/save-data-from-error-handler-to-other-index/357094)

<div class="topic-metadata">

**Author:** [@Observador](https://discuss.elastic.co/u/Observador)\
**Replies:** 0\
**Last updated:** [April 9, 2024, 4:56pm UTC](https://discuss.elastic.co/t/save-data-from-error-handler-to-other-index/357094 "2024-04-09T16:56:20Z")

</div>

Hi, I’d like to make an update and save thouse which doesn’t exist in other index. I’ve done an Error Handler but I don’t know how make the call there to write each not existing record data in other index.

---

## [How to make custom synonym analyzer?](https://discuss.elastic.co/t/how-to-make-custom-synonym-analyzer/357001)

<div class="topic-metadata">

**Author:** [@Oerlikon](https://discuss.elastic.co/u/Oerlikon)\
**Replies:** 1\
**Last updated:** [April 9, 2024, 4:26pm UTC](https://discuss.elastic.co/t/how-to-make-custom-synonym-analyzer/357001 "2024-04-09T16:26:41Z")

</div>

I got this error Traceback (most recent call last): File "C:\\Users\\User\\PycharmProjects\\pythonProject\_full\_text\\Preprocesing\_slovak\_synonyms.py", line 91, in \<module\> es.indices.create(index=index\_name, body=mappi…

---

## [How import self-signed ca for es8.4.2](https://discuss.elastic.co/t/how-import-self-signed-ca-for-es8-4-2/356990)

<div class="topic-metadata">

**Author:** [@YZ\_Xie](https://discuss.elastic.co/u/YZ_Xie)\
**Replies:** 2\
**Last updated:** [April 9, 2024, 3:54pm UTC](https://discuss.elastic.co/t/how-import-self-signed-ca-for-es8-4-2/356990 "2024-04-09T15:54:07Z")

</div>

We signed a cert from our internal ca, then xpack.security.transport.ssl configured use this cert, I know need import ca cert to es to solve this problem, but how to import it? I tried below command, but failed keytool…

---

## [How do query in Discover for list hosts if we have fleet agent policy id](https://discuss.elastic.co/t/how-do-query-in-discover-for-list-hosts-if-we-have-fleet-agent-policy-id/357087)

<div class="topic-metadata">

**Author:** [@Love\_all1](https://discuss.elastic.co/u/Love_all1)\
**Replies:** 0\
**Last updated:** [April 9, 2024, 3:34pm UTC](https://discuss.elastic.co/t/how-do-query-in-discover-for-list-hosts-if-we-have-fleet-agent-policy-id/357087 "2024-04-09T15:34:33Z")

</div>

I have list of hosts around 1040 i need to query and that list exported to excel.

---

## [How the size of index is related to number of shards?](https://discuss.elastic.co/t/how-the-size-of-index-is-related-to-number-of-shards/356686)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 2\
**Last updated:** [April 9, 2024, 3:25pm UTC](https://discuss.elastic.co/t/how-the-size-of-index-is-related-to-number-of-shards/356686 "2024-04-09T15:25:38Z")

</div>

Hi there, I have some question about number of sharding and size of indexes. I am currently in a single node configuration. I have one index in february : index with 1 shard, size 477 Gb and 600 million of documents …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=124)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=126)
