# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=135

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 136

---

## [How can I resolve issues with updating nested objects in Elasticsearch DSL within Django Rest Framework?](https://discuss.elastic.co/t/how-can-i-resolve-issues-with-updating-nested-objects-in-elasticsearch-dsl-within-django-rest-framework/355531)

<div class="topic-metadata">

**Author:** [@Manikandan\_FMJ](https://discuss.elastic.co/u/Manikandan_FMJ)\
**Replies:** 0\
**Last updated:** [March 16, 2024, 7:32am UTC](https://discuss.elastic.co/t/how-can-i-resolve-issues-with-updating-nested-objects-in-elasticsearch-dsl-within-django-rest-framework/355531 "2024-03-16T07:32:31Z")

</div>

When updating nested objects in Django Rest Framework (DRF), they might be stored as objects instead of Nested, causing issues during search queries. How can I resolve this issue? View file from .details\_document impor…

---

## [How can I upgrade the ELK from 8.5.1 to 8.11.4 \[Docker\] without losing data?](https://discuss.elastic.co/t/how-can-i-upgrade-the-elk-from-8-5-1-to-8-11-4-docker-without-losing-data/355045)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [March 15, 2024, 8:01pm UTC](https://discuss.elastic.co/t/how-can-i-upgrade-the-elk-from-8-5-1-to-8-11-4-docker-without-losing-data/355045 "2024-03-15T20:01:20Z")

</div>

I have this cluster on premisse and would like to upgrade the version but as it is on Docker I'm not sure on how I could keep the older data into the newest version.

---

## [Trouble Matching nested objects with multi\_match Query Using Wildcards in Elasticsearch](https://discuss.elastic.co/t/trouble-matching-nested-objects-with-multi-match-query-using-wildcards-in-elasticsearch/355513)

<div class="topic-metadata">

**Author:** [@Morzaram](https://discuss.elastic.co/u/Morzaram)\
**Replies:** 1\
**Last updated:** [March 15, 2024, 5:56pm UTC](https://discuss.elastic.co/t/trouble-matching-nested-objects-with-multi-match-query-using-wildcards-in-elasticsearch/355513 "2024-03-15T17:56:53Z")

</div>

Hey everyone, I'm encountering an issue where my documents aren't being matched by a multi\_match query when I include a wildcard with the search string. I'm trying to search across multiple fields, including nested name…

---

## [Fileset suricata/test is configured but doesn't exist](https://discuss.elastic.co/t/fileset-suricata-test-is-configured-but-doesnt-exist/355510)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 0\
**Last updated:** [March 15, 2024, 4:42pm UTC](https://discuss.elastic.co/t/fileset-suricata-test-is-configured-but-doesnt-exist/355510 "2024-03-15T16:42:56Z")

</div>

Hi, i'm running ELK 8.12.1 on Ubuntu 22.04 LTS. I try to rename a fileset (don't know if this is possible). What i found in the net was this: /etc/filebeat/modules.d/suricata.yml: - module: suricata eve: enabl…

---

## [Index keeps getting deleted](https://discuss.elastic.co/t/index-keeps-getting-deleted/317859)

<div class="topic-metadata">

**Author:** [@shivang.ahd](https://discuss.elastic.co/u/shivang.ahd)\
**Replies:** 26\
**Last updated:** [March 15, 2024, 3:17pm UTC](https://discuss.elastic.co/t/index-keeps-getting-deleted/317859 "2024-03-15T15:17:50Z")

</div>

Hi, I am new to elasticsearch. I need to make 140 million entries in elasticsearch. For that i have to keep elasticsearch running. Twice it happened that in the middle of ingesting data, when I am halfway to the numb…

---

## [How can I resolve issues with updating nested objects in Elasticsearch DSL within Django Rest Framework?](https://discuss.elastic.co/t/how-can-i-resolve-issues-with-updating-nested-objects-in-elasticsearch-dsl-within-django-rest-framework/355501)

<div class="topic-metadata">

**Author:** [@Manikandan\_FMJ](https://discuss.elastic.co/u/Manikandan_FMJ)\
**Replies:** 0\
**Last updated:** [March 15, 2024, 2:49pm UTC](https://discuss.elastic.co/t/how-can-i-resolve-issues-with-updating-nested-objects-in-elasticsearch-dsl-within-django-rest-framework/355501 "2024-03-15T14:49:42Z")

</div>

When updating nested objects in Django Rest Framework (DRF), they might be stored as objects instead of Nested, causing issues during search queries. How can I resolve this issue?

---

## [Dateformat with milliseconds and Zimezone](https://discuss.elastic.co/t/dateformat-with-milliseconds-and-zimezone/355460)

<div class="topic-metadata">

**Author:** [@helldunkel](https://discuss.elastic.co/u/helldunkel)\
**Replies:** 2\
**Last updated:** [March 15, 2024, 11:26am UTC](https://discuss.elastic.co/t/dateformat-with-milliseconds-and-zimezone/355460 "2024-03-15T11:26:12Z")

</div>

Hi, my timestamp is "2024-03-15T01:14:42.429088+01:00" but no pattern work for me. yyyy-MM-dd'T'HH:mm:ss.SSSSSSX yyyy-MM-dd'T'HH:mm:ss.SSSSSSZ yyyy-MM-ddTHH:mm:ss.ssssssTZD YYYY-MM-DDTHH:MM:SS.ssssss±HH:MM can anyb…

---

## [Mapping elastic query response to POCOs in NEST](https://discuss.elastic.co/t/mapping-elastic-query-response-to-pocos-in-nest/355458)

<div class="topic-metadata">

**Author:** [@Daniel\_Makos](https://discuss.elastic.co/u/Daniel_Makos)\
**Replies:** 0\
**Last updated:** [March 15, 2024, 9:18am UTC](https://discuss.elastic.co/t/mapping-elastic-query-response-to-pocos-in-nest/355458 "2024-03-15T09:18:15Z")

</div>

Following up on this question here: How to map C# DateTime property to @timestamp field I initialize the Elastic connection: ElasticsearchClientSettings settings; using (settings = new ElasticsearchClientSe…

---

## [Build rpm package with ES source file elasticsearch-8.12.1-linux-x86\_64.tar.gz file excluding jdk , so that I can reduce its size](https://discuss.elastic.co/t/build-rpm-package-with-es-source-file-elasticsearch-8-12-1-linux-x86-64-tar-gz-file-excluding-jdk-so-that-i-can-reduce-its-size/355429)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 5\
**Last updated:** [March 15, 2024, 8:51am UTC](https://discuss.elastic.co/t/build-rpm-package-with-es-source-file-elasticsearch-8-12-1-linux-x86-64-tar-gz-file-excluding-jdk-so-that-i-can-reduce-its-size/355429 "2024-03-15T08:51:32Z")

</div>

I have downloaded ES source file elasticsearch-8.12.1-linux-x86\_64.tar.gz file which has all binaries, libraries, jdk and Modules etcetera. I have tried to build rpm package I am getting error . I am following this lin…

---

## [How to get the match records based on two tables in same indices](https://discuss.elastic.co/t/how-to-get-the-match-records-based-on-two-tables-in-same-indices/355368)

<div class="topic-metadata">

**Author:** [@Tqvenkata](https://discuss.elastic.co/u/Tqvenkata)\
**Replies:** 1\
**Last updated:** [March 15, 2024, 7:45am UTC](https://discuss.elastic.co/t/how-to-get-the-match-records-based-on-two-tables-in-same-indices/355368 "2024-03-15T07:45:16Z")

</div>

Hi , I need to get the output based on join condition tokenaccess.token with employee table and token access table (like sql join) please find the sample mapping and data PUT joinindex/\_mapping { "properties": { …

---

## [Working set memory High](https://discuss.elastic.co/t/working-set-memory-high/355215)

<div class="topic-metadata">

**Author:** [@Kesavan\_raina](https://discuss.elastic.co/u/Kesavan_raina)\
**Replies:** 6\
**Last updated:** [March 15, 2024, 3:52am UTC](https://discuss.elastic.co/t/working-set-memory-high/355215 "2024-03-15T03:52:48Z")

</div>

Hi all, I'm running an Elasticsearch cluster with just one node JVM configuration uses the default values with -Xms 2g -Xmx 2g but when I checked the memory usage I saw that the working set memory value is up to 25gb…

---

## [How to delete an unassigned primary shard](https://discuss.elastic.co/t/how-to-delete-an-unassigned-primary-shard/355446)

<div class="topic-metadata">

**Author:** [@Churchill](https://discuss.elastic.co/u/Churchill)\
**Replies:** 1\
**Last updated:** [March 15, 2024, 3:50am UTC](https://discuss.elastic.co/t/how-to-delete-an-unassigned-primary-shard/355446 "2024-03-15T03:50:46Z")

</div>

Good day, We're currently experiencing an issue with one of our index (let's call it sample\_index) which has 21 primary shards with 1 replica. The primary shards of sample\_index are distributed on all our nodes. Unfortu…

---

## [This field does not work with the selected function](https://discuss.elastic.co/t/this-field-does-not-work-with-the-selected-function/355365)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 6\
**Last updated:** [March 15, 2024, 3:45am UTC](https://discuss.elastic.co/t/this-field-does-not-work-with-the-selected-function/355365 "2024-03-15T03:45:19Z")

</div>

I have a dashboard but I don't understand why the field status\_request seem is error Please help me resolve the above error

---

## [Master only node Volume size](https://discuss.elastic.co/t/master-only-node-volume-size/355345)

<div class="topic-metadata">

**Author:** [@pop2413](https://discuss.elastic.co/u/pop2413)\
**Replies:** 4\
**Last updated:** [March 14, 2024, 11:49pm UTC](https://discuss.elastic.co/t/master-only-node-volume-size/355345 "2024-03-14T23:49:02Z")

</div>

Hello, I try to configure ES cluster using 4 nodes (1 master only node, 3 data only nodes) but, I'm not sure how much to set the volume size for the master node. (The volume is mounted on /usr/share/elasticsearch/dat…

---

## [Need help on DateHistogram queries](https://discuss.elastic.co/t/need-help-on-datehistogram-queries/355430)

<div class="topic-metadata">

**Author:** [@Laksh\_0009](https://discuss.elastic.co/u/Laksh_0009)\
**Replies:** 0\
**Last updated:** [March 14, 2024, 5:02pm UTC](https://discuss.elastic.co/t/need-help-on-datehistogram-queries/355430 "2024-03-14T17:02:09Z")

</div>

I need a help in building a query, I have two time fields in a index in same formats, First I need to groupBy "returnCompletedDate" field but by rounding the time part to 00:00:00, like "2024-02-21 12:00:00" will be "…

---

## [Elasticsearch not loading logs from logstash and filebeat](https://discuss.elastic.co/t/elasticsearch-not-loading-logs-from-logstash-and-filebeat/355391)

<div class="topic-metadata">

**Author:** [@codi639](https://discuss.elastic.co/u/codi639)\
**Replies:** 3\
**Last updated:** [March 14, 2024, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-not-loading-logs-from-logstash-and-filebeat/355391 "2024-03-14T15:10:25Z")

</div>

Hello guys, I'm trying to build a SIEM, after searching for different solutions I wanted to try the ELK-Stack with Filebeat. I've followed this tutorial, and occur the error at the end of the fourth part. I tried to re…

---

## [Elasticsearch tokens with adjacent concat while preserving other words](https://discuss.elastic.co/t/elasticsearch-tokens-with-adjacent-concat-while-preserving-other-words/355399)

<div class="topic-metadata">

**Author:** [@bhavyajain](https://discuss.elastic.co/u/bhavyajain)\
**Replies:** 1\
**Last updated:** [March 14, 2024, 11:45am UTC](https://discuss.elastic.co/t/elasticsearch-tokens-with-adjacent-concat-while-preserving-other-words/355399 "2024-03-14T11:45:12Z")

</div>

I want to create a custom analyzer which generates tokens so that in each token, one pair of adjacent words are concatenated while preserving rest of the query string. Example Query : "quick brown fox jumps" Generated …

---

## [Is it possible to configure replica shards to synchronize data?](https://discuss.elastic.co/t/is-it-possible-to-configure-replica-shards-to-synchronize-data/355371)

<div class="topic-metadata">

**Author:** [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Replies:** 5\
**Last updated:** [March 14, 2024, 9:19am UTC](https://discuss.elastic.co/t/is-it-possible-to-configure-replica-shards-to-synchronize-data/355371 "2024-03-14T09:19:26Z")

</div>

By default, Elasticsearch replicates data from primary shards to replica shards. However, in some cases, this can lead to performance issues. For example: When the cluster experiences high query volume and has many re…

---

## [Seek a reference for scope of work and efforts required to setup Elasticsearch](https://discuss.elastic.co/t/seek-a-reference-for-scope-of-work-and-efforts-required-to-setup-elasticsearch/355373)

<div class="topic-metadata">

**Author:** [@guojun.qiao](https://discuss.elastic.co/u/guojun.qiao)\
**Replies:** 1\
**Last updated:** [March 14, 2024, 8:15am UTC](https://discuss.elastic.co/t/seek-a-reference-for-scope-of-work-and-efforts-required-to-setup-elasticsearch/355373 "2024-03-14T08:15:43Z")

</div>

Hi I would like to setup Elasticsearch in two data centers. Two data centers will have same setup (refer to screenshot attached). Three nodes for master and data role. One node for Kibana. Could anyone share me a refer…

---

## [How to check if results are empty in SearchHitIterator in php](https://discuss.elastic.co/t/how-to-check-if-results-are-empty-in-searchhititerator-in-php/355366)

<div class="topic-metadata">

**Author:** [@Aditya\_Dixit1](https://discuss.elastic.co/u/Aditya_Dixit1)\
**Replies:** 0\
**Last updated:** [March 14, 2024, 7:25am UTC](https://discuss.elastic.co/t/how-to-check-if-results-are-empty-in-searchhititerator-in-php/355366 "2024-03-14T07:25:05Z")

</div>

I am using a SearchHitIterator in php like this $params = \[ 'index' =\> 'empire', 'body' =\> \[ 'query' =\> \[ 'match' =\> \[ …

---

## [AWS Integration and Inspector](https://discuss.elastic.co/t/aws-integration-and-inspector/354145)

<div class="topic-metadata">

**Author:** [@jeffmaley](https://discuss.elastic.co/u/jeffmaley)\
**Replies:** 2\
**Last updated:** [March 13, 2024, 10:37pm UTC](https://discuss.elastic.co/t/aws-integration-and-inspector/354145 "2024-03-13T22:37:42Z")

</div>

I have ELK running with the AWS integration. I have one agent policy running on several agents with a role configured for the agent to use. The agents are running on EC2 and are able to assume the role easily. I've setup…

---

## [Getting internal "\_id" field via jdbc](https://discuss.elastic.co/t/getting-internal-id-field-via-jdbc/355314)

<div class="topic-metadata">

**Author:** [@Kenjiro](https://discuss.elastic.co/u/Kenjiro)\
**Replies:** 4\
**Last updated:** [March 13, 2024, 7:34pm UTC](https://discuss.elastic.co/t/getting-internal-id-field-via-jdbc/355314 "2024-03-13T19:34:50Z")

</div>

Hello, I'm new to elasticsearch and as far as I've read, \_id field is not accesible via sql endpoint at the moment. I've read some posts about duplicating it as a regular field in order to reach via sql endpoint. But I…

---

## [Version issue with Jaeger using elastic search](https://discuss.elastic.co/t/version-issue-with-jaeger-using-elastic-search/355099)

<div class="topic-metadata">

**Author:** [@Ranjit\_Kumar](https://discuss.elastic.co/u/Ranjit_Kumar)\
**Replies:** 2\
**Last updated:** [March 13, 2024, 6:39pm UTC](https://discuss.elastic.co/t/version-issue-with-jaeger-using-elastic-search/355099 "2024-03-13T18:39:54Z")

</div>

We are using Jaeger with ELK stack in Azure. Recently updated the Jaeger version to 1.52 and Elasticsearch version to 8.11. After upgrade the Jaeger UI is not showing any services not even the Jaeger services. But we can…

---

## [Find documents where same field value is found in any outer or nested fields](https://discuss.elastic.co/t/find-documents-where-same-field-value-is-found-in-any-outer-or-nested-fields/355325)

<div class="topic-metadata">

**Author:** [@spinesmovie](https://discuss.elastic.co/u/spinesmovie)\
**Replies:** 0\
**Last updated:** [March 13, 2024, 4:00pm UTC](https://discuss.elastic.co/t/find-documents-where-same-field-value-is-found-in-any-outer-or-nested-fields/355325 "2024-03-13T16:00:16Z")

</div>

Elasticsearch has an index where \_source is of schema { ... "color" : "white", "items" : \[ { ... "color": "blue", "items": \[...\] }, { ... "color": "red", "items": \[.…

---

## [Reindex api is not copying the \_ignored field values from source index](https://discuss.elastic.co/t/reindex-api-is-not-copying-the-ignored-field-values-from-source-index/355316)

<div class="topic-metadata">

**Author:** [@rkbbce](https://discuss.elastic.co/u/rkbbce)\
**Replies:** 0\
**Last updated:** [March 13, 2024, 2:40pm UTC](https://discuss.elastic.co/t/reindex-api-is-not-copying-the-ignored-field-values-from-source-index/355316 "2024-03-13T14:40:02Z")

</div>

Hello Folks, I am trying to reindex the app search documents index from older version of es v7.17 to v8.8 but the target index is not maintaining the same \_ignored field value as source index. do we have any options in…

---

## [Searching special characters in elastic](https://discuss.elastic.co/t/searching-special-characters-in-elastic/355016)

<div class="topic-metadata">

**Author:** [@peter\_falk](https://discuss.elastic.co/u/peter_falk)\
**Replies:** 3\
**Last updated:** [March 13, 2024, 12:30pm UTC](https://discuss.elastic.co/t/searching-special-characters-in-elastic/355016 "2024-03-13T12:30:18Z")

</div>

Hello, I have a problem I could not index special characters in Elasticsearch. I try to do it like that: PUT my-index-000001 { "settings": { "index": { "max\_result\_window": 100000, "n…

---

## [Is Elastic Search paid?](https://discuss.elastic.co/t/is-elastic-search-paid/355301)

<div class="topic-metadata">

**Author:** [@ShubhamSaxena8](https://discuss.elastic.co/u/ShubhamSaxena8)\
**Replies:** 4\
**Last updated:** [March 13, 2024, 11:08am UTC](https://discuss.elastic.co/t/is-elastic-search-paid/355301 "2024-03-13T11:08:42Z")

</div>

Hello Team, My team is setting up a centralized logging system for our .Net applications. We have decided to go with Elastic Search but I am still a bit confused on the pricing part. I am assuming that I will be using …

---

## [What does "bulk operation" mean exactly in custom track on es-rally?](https://discuss.elastic.co/t/what-does-bulk-operation-mean-exactly-in-custom-track-on-es-rally/355278)

<div class="topic-metadata">

**Author:** [@qksjdhi1212](https://discuss.elastic.co/u/qksjdhi1212)\
**Replies:** 1\
**Last updated:** [March 13, 2024, 6:46am UTC](https://discuss.elastic.co/t/what-does-bulk-operation-mean-exactly-in-custom-track-on-es-rally/355278 "2024-03-13T06:46:31Z")

</div>

I set the bulk operation with 5000 bulk-size and 5 clients { "version": 2, "description": "", "indices": \[ { "name": "indexing-1gb", "body": "index.json" } \], "corpora": \[ { "name…

---

## [Which one is the best to retrieve selected fields from a search: \`\_source\` or \`fields\`?](https://discuss.elastic.co/t/which-one-is-the-best-to-retrieve-selected-fields-from-a-search-source-or-fields/355270)

<div class="topic-metadata">

**Author:** [@deadlyn](https://discuss.elastic.co/u/deadlyn)\
**Replies:** 3\
**Last updated:** [March 13, 2024, 6:16am UTC](https://discuss.elastic.co/t/which-one-is-the-best-to-retrieve-selected-fields-from-a-search-source-or-fields/355270 "2024-03-13T06:16:57Z")

</div>

\_source vs fields: which is fastest to retrieve selected fields? The ES 8.10.x official doc mentioned that ES will load whole \_source object while using \_source and the doc preferred to use fields. You can use both o…

---

## [Running rally locally](https://discuss.elastic.co/t/running-rally-locally/354924)

<div class="topic-metadata">

**Author:** [@Qia](https://discuss.elastic.co/u/Qia)\
**Replies:** 15\
**Last updated:** [March 13, 2024, 5:56am UTC](https://discuss.elastic.co/t/running-rally-locally/354924 "2024-03-13T05:56:37Z")

</div>

After following Developing Rally - Rally 2.10.0.dev0 documentation I ran: (.venv) ➜ rally git:(master) python esrally/rally.py race --pipeline=benchmark-only --target-host=127.0.0.1:39200 --track=geonames --challenge=…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=134)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=136)
