# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=137

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 138

---

## [Filter on \_search performed with text\_expansion is not working](https://discuss.elastic.co/t/filter-on-search-performed-with-text-expansion-is-not-working/355110)

<div class="topic-metadata">

**Author:** [@Ankur\_Garg](https://discuss.elastic.co/u/Ankur_Garg)\
**Replies:** 4\
**Last updated:** [March 11, 2024, 1:29pm UTC](https://discuss.elastic.co/t/filter-on-search-performed-with-text-expansion-is-not-working/355110 "2024-03-11T13:29:53Z")

</div>

I have an Elasticsearch index ingested with an inference pipeline using ELSER. While performing the search I would like to filter and show all the data where my field "Country" has a certain value "XYZ". My query below …

---

## [Combine Platinum version with Free license version](https://discuss.elastic.co/t/combine-platinum-version-with-free-license-version/354834)

<div class="topic-metadata">

**Author:** [@ekas](https://discuss.elastic.co/u/ekas)\
**Replies:** 14\
**Last updated:** [March 11, 2024, 11:35am UTC](https://discuss.elastic.co/t/combine-platinum-version-with-free-license-version/354834 "2024-03-11T11:35:46Z")

</div>

Hi! I deployed 1 ELK stack on premise. I have only 1 Elastic node. I am going to upgrade my license from Free to Platinum (still on premise) and delete the ELK free version cluster. I am going to buy only 1 Elastic no…

---

## [Using 1 action's output result in another action](https://discuss.elastic.co/t/using-1-actions-output-result-in-another-action/355136)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 0\
**Last updated:** [March 11, 2024, 9:10am UTC](https://discuss.elastic.co/t/using-1-actions-output-result-in-another-action/355136 "2024-03-11T09:10:24Z")

</div>

Hi all, I am trying to extract the value from one action output and I want to use that result in the another action block. I am using the below watcher script to extract the value but with this I am not able to get the …

---

## [Scripting aggregation on Object](https://discuss.elastic.co/t/scripting-aggregation-on-object/354905)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 3\
**Last updated:** [March 11, 2024, 7:51am UTC](https://discuss.elastic.co/t/scripting-aggregation-on-object/354905 "2024-03-11T07:51:26Z")

</div>

Hi, I have an index with mapping, { "resume": { "otherInformation": { "IndustryScore": { "accounting\_finance": { "type": "text" }, …

---

## [How to route docs of same \_routing key in Elasticsearch into multiple shard?](https://discuss.elastic.co/t/how-to-route-docs-of-same-routing-key-in-elasticsearch-into-multiple-shard/355105)

<div class="topic-metadata">

**Author:** [@sumandas0](https://discuss.elastic.co/u/sumandas0)\
**Replies:** 2\
**Last updated:** [March 11, 2024, 3:49am UTC](https://discuss.elastic.co/t/how-to-route-docs-of-same-routing-key-in-elasticsearch-into-multiple-shard/355105 "2024-03-11T03:49:34Z")

</div>

We have a very large index of almost 600 million documents. A field called \_\_assetType allows us to distinguish between document types. Currently, there's a 10-90% distribution of document types, and we primarily search …

---

## [Install Elastic Search using Powershell](https://discuss.elastic.co/t/install-elastic-search-using-powershell/354697)

<div class="topic-metadata">

**Author:** [@kottak01](https://discuss.elastic.co/u/kottak01)\
**Replies:** 7\
**Last updated:** [March 9, 2024, 5:56pm UTC](https://discuss.elastic.co/t/install-elastic-search-using-powershell/354697 "2024-03-09T17:56:13Z")

</div>

Hi, I'm currently using Powershell to install Elastic Search and Kibana as my command prompt is not working. I'm unable to install by running ".\\elasticsearch.bat" on powershell. Can anyone assist with my issue?

---

## [Can I upgrade my existing ELK setup to 8.x?](https://discuss.elastic.co/t/can-i-upgrade-my-existing-elk-setup-to-8-x/354129)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 28\
**Last updated:** [March 9, 2024, 1:53pm UTC](https://discuss.elastic.co/t/can-i-upgrade-my-existing-elk-setup-to-8-x/354129 "2024-03-09T13:53:14Z")

</div>

Hello, I have a query regarding the ELK stack upgrade from 7.17.15 to 8.11 or higher? Please note the current set up is of a production server and is on 7.17.15 and is also basic version (NOT a licensed version) also…

---

## [When Query string contains hyphen characters, hyphen characters will be ignored](https://discuss.elastic.co/t/when-query-string-contains-hyphen-characters-hyphen-characters-will-be-ignored/355039)

<div class="topic-metadata">

**Author:** [@Jerry163](https://discuss.elastic.co/u/Jerry163)\
**Replies:** 2\
**Last updated:** [March 9, 2024, 11:30am UTC](https://discuss.elastic.co/t/when-query-string-contains-hyphen-characters-hyphen-characters-will-be-ignored/355039 "2024-03-09T11:30:36Z")

</div>

I want to filter the error logs starting with "ORA-" in the Oracle Alert log, but when I use the query expression of message: "ORA-\*" to filter, many strings starting with ORA are also matched, hyphen characters will be …

---

## [Is the repo broken?](https://discuss.elastic.co/t/is-the-repo-broken/355043)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 2\
**Last updated:** [March 8, 2024, 9:29pm UTC](https://discuss.elastic.co/t/is-the-repo-broken/355043 "2024-03-08T21:29:25Z")

</div>

On an existing system running 8.12, I'm getting this error: dnf --enablerepo=elasticsearch update Elasticsearch repository for 8.x packages 0.0 B/s | 0 B 00:00 Errors durin…

---

## [In-memory evaluation](https://discuss.elastic.co/t/in-memory-evaluation/355011)

<div class="topic-metadata">

**Author:** [@arpit\_upadhyay](https://discuss.elastic.co/u/arpit_upadhyay)\
**Replies:** 1\
**Last updated:** [March 8, 2024, 1:04pm UTC](https://discuss.elastic.co/t/in-memory-evaluation/355011 "2024-03-08T13:04:11Z")

</div>

I have a json object and and Elasticsearch query , I want to evaluate if that json will match with that query or not (just like if that json document was indexed and when ES run the given query it will or will not return…

---

## [Elasticsearch master node is not up in version 8.12.0 of multinode cluster](https://discuss.elastic.co/t/elasticsearch-master-node-is-not-up-in-version-8-12-0-of-multinode-cluster/353758)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 0\
**Last updated:** [February 21, 2024, 9:12am UTC](https://discuss.elastic.co/t/elasticsearch-master-node-is-not-up-in-version-8-12-0-of-multinode-cluster/353758 "2024-02-21T09:12:13Z")

</div>

When I restart the elasticsearch node 1 from which I formed a multinode cluster using enrollment token. Service is failed and getting the logs. tail -f /var/log/elasticsearch/HELK.log| grep ERROR \[ERROR\]\[o.e.x.s.a.s.Fi…

---

## [Migrate from Docker compose to linux cluster installation](https://discuss.elastic.co/t/migrate-from-docker-compose-to-linux-cluster-installation/353126)

<div class="topic-metadata">

**Author:** [@Nishad\_Angre](https://discuss.elastic.co/u/Nishad_Angre)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 5:58am UTC](https://discuss.elastic.co/t/migrate-from-docker-compose-to-linux-cluster-installation/353126 "2024-02-13T05:58:02Z")

</div>

Currently I have a docker cluster for ELK stack on a single machine. Till now its working fine. But in future, I am expecting that there will be a increase in load on this cluster; and because its a single machine, the …

---

## [Add self-managed node to cloud](https://discuss.elastic.co/t/add-self-managed-node-to-cloud/355023)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 2\
**Last updated:** [March 8, 2024, 10:49am UTC](https://discuss.elastic.co/t/add-self-managed-node-to-cloud/355023 "2024-03-08T10:49:21Z")

</div>

Is it possible to add a self managed node to the cloud?

---

## [Why Composite aggregation shows Empty buckets first](https://discuss.elastic.co/t/why-composite-aggregation-shows-empty-buckets-first/354123)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 1:21pm UTC](https://discuss.elastic.co/t/why-composite-aggregation-shows-empty-buckets-first/354123 "2024-02-26T13:21:20Z")

</div>

Hi, I have a index with 9 Million documents. I performed Composite aggregation on nested field and I also mentioned doc\_count sorting. Here I lost a lot of perfect buckets. Here is my aggregation query with size 2000 "…

---

## [What happens when you go over 32GiB of JVM heap memory?](https://discuss.elastic.co/t/what-happens-when-you-go-over-32gib-of-jvm-heap-memory/354883)

<div class="topic-metadata">

**Author:** [@Santi\_Santichaivekin](https://discuss.elastic.co/u/Santi_Santichaivekin)\
**Replies:** 5\
**Last updated:** [March 8, 2024, 9:16am UTC](https://discuss.elastic.co/t/what-happens-when-you-go-over-32gib-of-jvm-heap-memory/354883 "2024-03-08T09:16:19Z")

</div>

Elasticsearch does not recommend setting memory limit over 32GiB due to a pointer optimization called "compressed oops" that only happens when the heap size is under 32GiB. (1). However, I have found little discussion o…

---

## [Duplicate Docs Getting Created](https://discuss.elastic.co/t/duplicate-docs-getting-created/355006)

<div class="topic-metadata">

**Author:** [@sajid](https://discuss.elastic.co/u/sajid)\
**Replies:** 1\
**Last updated:** [March 8, 2024, 7:34am UTC](https://discuss.elastic.co/t/duplicate-docs-getting-created/355006 "2024-03-08T07:34:11Z")

</div>

We are running fluentd in our Kubernetes cluster as DaemonSet and logs are getting shipped to Elasticsearch directly. We are observing duplicate logs are being stored in ES i.e. for a single line of log, we are seeing mu…

---

## [How to remove the information from the data stream of the agent](https://discuss.elastic.co/t/how-to-remove-the-information-from-the-data-stream-of-the-agent/355005)

<div class="topic-metadata">

**Author:** [@strawberryfly](https://discuss.elastic.co/u/strawberryfly)\
**Replies:** 0\
**Last updated:** [March 8, 2024, 6:48am UTC](https://discuss.elastic.co/t/how-to-remove-the-information-from-the-data-stream-of-the-agent/355005 "2024-03-08T06:48:26Z")

</div>

Hello everyone, I've been struggling with the following values for a few days now: agent.ephemeral\_id,agent.id,agent.name,agent.type,agent.version I use the plugin Palo Alto to transfer the logs to elasticserach and th…

---

## [ElasticSearch JAVA create custom sort in place of attribute value sort](https://discuss.elastic.co/t/elasticsearch-java-create-custom-sort-in-place-of-attribute-value-sort/354982)

<div class="topic-metadata">

**Author:** [@Manoj\_Upadhyay](https://discuss.elastic.co/u/Manoj_Upadhyay)\
**Replies:** 1\
**Last updated:** [March 8, 2024, 6:20am UTC](https://discuss.elastic.co/t/elasticsearch-java-create-custom-sort-in-place-of-attribute-value-sort/354982 "2024-03-08T06:20:47Z")

</div>

For example, I have 6 accounts (1,2,34,5,6)of transactions in index and I want to search transactions and sort by order by account 4,6,3,2,1,5(custom order ) then how I can use it . SearchResponse\<MyClass\> esResponse = …

---

## [Filebeat migrate registry file - recent versions](https://discuss.elastic.co/t/filebeat-migrate-registry-file-recent-versions/354990)

<div class="topic-metadata">

**Author:** [@lucasenc](https://discuss.elastic.co/u/lucasenc)\
**Replies:** 0\
**Last updated:** [March 7, 2024, 10:14pm UTC](https://discuss.elastic.co/t/filebeat-migrate-registry-file-recent-versions/354990 "2024-03-07T22:14:29Z")

</div>

I've failing to implement the process to migrate the filebeat registry file from Elasticsearch 8.9.0 to 8.11.1 and crossed my mind that the guidance for this process found here works only for old versions. Could someone…

---

## [I am trying to install ELK in docker and facing the below error](https://discuss.elastic.co/t/i-am-trying-to-install-elk-in-docker-and-facing-the-below-error/354979)

<div class="topic-metadata">

**Author:** [@aishu\_modala](https://discuss.elastic.co/u/aishu_modala)\
**Replies:** 1\
**Last updated:** [March 7, 2024, 9:43pm UTC](https://discuss.elastic.co/t/i-am-trying-to-install-elk-in-docker-and-facing-the-below-error/354979 "2024-03-07T21:43:13Z")

</div>

\[2024-03-07T20:09:22.543+00:00\]\[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes. security\_exception Root causes: security\_exception: unable to authenticate user \[kibana\_sys…

---

## [Vector Search with Search-UI and App Search](https://discuss.elastic.co/t/vector-search-with-search-ui-and-app-search/354972)

<div class="topic-metadata">

**Author:** [@Adam\_Patarino](https://discuss.elastic.co/u/Adam_Patarino)\
**Replies:** 1\
**Last updated:** [March 7, 2024, 6:58pm UTC](https://discuss.elastic.co/t/vector-search-with-search-ui-and-app-search/354972 "2024-03-07T18:58:44Z")

</div>

Hello, we have setup Elsor on our index and now want to include those vector fields as users use our search-ui. We use search-ui with @elastic/search-ui-app-search-connector. Ideally results would be a combination of k…

---

## [Elastic Search data is not being stored in one of the three PVCs](https://discuss.elastic.co/t/elastic-search-data-is-not-being-stored-in-one-of-the-three-pvcs/354872)

<div class="topic-metadata">

**Author:** [@Siva\_Vignesh\_K](https://discuss.elastic.co/u/Siva_Vignesh_K)\
**Replies:** 3\
**Last updated:** [March 7, 2024, 6:19am UTC](https://discuss.elastic.co/t/elastic-search-data-is-not-being-stored-in-one-of-the-three-pvcs/354872 "2024-03-07T06:19:36Z")

</div>

Using Helm Chart, I have deployed three replicas of elasticsearch in a Kubernetes cluster. I've noticed that data is only being stored in the two PVCs. My storage is filling up quickly since the third one is not recei…

---

## [Query Elasticsearch DLS/ Field = Field?](https://discuss.elastic.co/t/query-elasticsearch-dls-field-field/354536)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 8\
**Last updated:** [March 7, 2024, 4:38pm UTC](https://discuss.elastic.co/t/query-elasticsearch-dls-field-field/354536 "2024-03-07T16:38:46Z")

</div>

Hi Guy, I am thinking of using an Elasticsearch query to display documents where the value of Field 1 equals Field 2. Does Elasticsearch support this type of query? If anyone knows, please provide me with more details. …

---

## [(bump) shards constantly relocating](https://discuss.elastic.co/t/bump-shards-constantly-relocating/354966)

<div class="topic-metadata">

**Author:** [@raymondmintz11](https://discuss.elastic.co/u/raymondmintz11)\
**Replies:** 7\
**Last updated:** [March 7, 2024, 3:39pm UTC](https://discuss.elastic.co/t/bump-shards-constantly-relocating/354966 "2024-03-07T15:39:01Z")

</div>

hi sorry if there is another way to bumb expired topics/comments Was there a solution to this dialogue ? Thanks! (sorry for the irrelevant tag, the preset options arent applicable)

---

## [Elasticsearch index wildcard vs alias performance inpact](https://discuss.elastic.co/t/elasticsearch-index-wildcard-vs-alias-performance-inpact/354933)

<div class="topic-metadata">

**Author:** [@J\_Kit](https://discuss.elastic.co/u/J_Kit)\
**Replies:** 1\
**Last updated:** [March 7, 2024, 10:07am UTC](https://discuss.elastic.co/t/elasticsearch-index-wildcard-vs-alias-performance-inpact/354933 "2024-03-07T10:07:06Z")

</div>

Hi I currently manage daily indices such as day1, day2, day3, and so on. When performing queries, we use a wildcard like day\*/\_search. I'm considering converting these daily indices to an alias, let's call it DAY, whic…

---

## [Elasticsearch for Image Extraction](https://discuss.elastic.co/t/elasticsearch-for-image-extraction/354786)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 3\
**Last updated:** [March 7, 2024, 10:05am UTC](https://discuss.elastic.co/t/elasticsearch-for-image-extraction/354786 "2024-03-07T10:05:16Z")

</div>

Hello Elastic, I want to ask, are we able to do image extraction in order to do searching for images in Elastic, for .jpg .png format? If we can do so, I need guidance for this. Thanks!

---

## [Elastic Stack](https://discuss.elastic.co/t/elastic-stack/354792)

<div class="topic-metadata">

**Author:** [@qu\_c\_th\_nguy\_n](https://discuss.elastic.co/u/qu_c_th_nguy_n)\
**Replies:** 2\
**Last updated:** [March 7, 2024, 9:35am UTC](https://discuss.elastic.co/t/elastic-stack/354792 "2024-03-07T09:35:05Z")

</div>

I'm a newbie, can someone introduce me where can i practice Elasticsearch

---

## [Cannot upgrade to Elasticsearch 8.12.1 directly from 7.12.0](https://discuss.elastic.co/t/cannot-upgrade-to-elasticsearch-8-12-1-directly-from-7-12-0/353553)

<div class="topic-metadata">

**Author:** [@Justo1982](https://discuss.elastic.co/u/Justo1982)\
**Replies:** 15\
**Last updated:** [March 7, 2024, 8:28am UTC](https://discuss.elastic.co/t/cannot-upgrade-to-elasticsearch-8-12-1-directly-from-7-12-0/353553 "2024-03-07T08:28:17Z")

</div>

Hi All, I'm trying to install ELK stack in QA environment but get the error below with Elasticsearch: 'java.lang.IllegalStateException: cannot upgrade a node from version \[7.12.0\] directly to version \[8.12.1\], upgrade …

---

## [Found cold tier replica in hot node](https://discuss.elastic.co/t/found-cold-tier-replica-in-hot-node/354907)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 2\
**Last updated:** [March 7, 2024, 7:08am UTC](https://discuss.elastic.co/t/found-cold-tier-replica-in-hot-node/354907 "2024-03-07T07:08:22Z")

</div>

My ES cluster got 3 hot nodes and 1 cold node 1 primary shard and 1 replica for each index. I create a two tier ilm policy. Hot and Cold index move to cold node when it is in cold tier. However, I find my prirep: p i…

---

## [Search.max\_buckets](https://discuss.elastic.co/t/search-max-buckets/354910)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [March 7, 2024, 6:47am UTC](https://discuss.elastic.co/t/search-max-buckets/354910 "2024-03-07T06:47:24Z")

</div>

My cluster's setting is { "defaults": { "search": { "max\_buckets": "65536" } } } Trying to perform query it compliant ...the number of buckets was exceeded. In order to make the query work, is enla…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=136)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=138)
