# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=179

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 180

---

## [Updating field mapping in Index Template](https://discuss.elastic.co/t/updating-field-mapping-in-index-template/345528)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/updating-field-mapping-in-index-template/345528 "2023-11-13T10:10:30Z")

</div>

Hello all, We have an application that sends logs daily to our ELK server. We are an index template which creates an new indice for each day. We are using ELK (with filebeat) 7.10 I am looking to update the mapping to …

---

## [Does anyone use connection pooling in ElasticSearch8.5? How to use it?](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346975)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 10:00am UTC](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346975 "2023-11-13T10:00:19Z")

</div>

Does anyone use connection pooling in Elasticsearch8.5? How to use it?

---

## [How to access index of array correct in plainess?](https://discuss.elastic.co/t/how-to-access-index-of-array-correct-in-plainess/345617)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 8:46am UTC](https://discuss.elastic.co/t/how-to-access-index-of-array-correct-in-plainess/345617 "2023-11-13T08:46:51Z")

</div>

Hi everyone, I'm facing a situation like this. I have index example: PUT my\_index { "mappings": { "properties": { "targetoperator": { type: "keyword" }, "targetvalue": { type: "keyword" } } } …

---

## [Using analyze API for encryption at rest](https://discuss.elastic.co/t/using-analyze-api-for-encryption-at-rest/346960)

<div class="topic-metadata">

**Author:** [@harispy](https://discuss.elastic.co/u/harispy)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 7:46am UTC](https://discuss.elastic.co/t/using-analyze-api-for-encryption-at-rest/346960 "2023-11-13T07:46:21Z")

</div>

Hi everyone. we want to encrypt one field of our documents in Elastic and I went through lots of methods for doing this and none of them was good with our situation (for example third-party proxy and plugins because the…

---

## [Having log error while trying to install pega 8.5 on kubernetes cluster](https://discuss.elastic.co/t/having-log-error-while-trying-to-install-pega-8-5-on-kubernetes-cluster/346943)

<div class="topic-metadata">

**Author:** [@musheer](https://discuss.elastic.co/u/musheer)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 5:12am UTC](https://discuss.elastic.co/t/having-log-error-while-trying-to-install-pega-8-5-on-kubernetes-cluster/346943 "2023-11-13T05:12:39Z")

</div>

Hi, when i installed pega 8.5 on kubernetes cluster ,the pod of pega search was in pending state and i checked the logs and got following error .Need to solve this issue as soon as possible.Please help ERROR: kubectl …

---

## [Warm nodes respond poorly](https://discuss.elastic.co/t/warm-nodes-respond-poorly/346552)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 4\
**Last updated:** [November 12, 2023, 6:12pm UTC](https://discuss.elastic.co/t/warm-nodes-respond-poorly/346552 "2023-11-12T18:12:54Z")

</div>

Hello, I have the following issue. Our largest datastream ("C") is responding poorly to the queries. The main parts of the stack: 10\*hot nodes (each: 16 cores, 60GB+ memory) 6\*warm nodes (each: 16 cores, 60GB+ memo…

---

## [Eql with time range](https://discuss.elastic.co/t/eql-with-time-range/346928)

<div class="topic-metadata">

**Author:** [@mary-20](https://discuss.elastic.co/u/mary-20)\
**Replies:** 0\
**Last updated:** [November 12, 2023, 1:30pm UTC](https://discuss.elastic.co/t/eql-with-time-range/346928 "2023-11-12T13:30:22Z")

</div>

Hi guys, I'm looking for EQL to match logs with a timestamp within the last 5 minutes. I have read a with maxspan statement, but it has some limitation: It must be used with sequence it starts at the first event’s ti…

---

## [Adding data for all documents in an index](https://discuss.elastic.co/t/adding-data-for-all-documents-in-an-index/346761)

<div class="topic-metadata">

**Author:** [@dor](https://discuss.elastic.co/u/dor)\
**Replies:** 2\
**Last updated:** [November 12, 2023, 7:10am UTC](https://discuss.elastic.co/t/adding-data-for-all-documents-in-an-index/346761 "2023-11-12T07:10:50Z")

</div>

Hi, My case is the following: I have data in elastic indexes. At some stage, I'm running some post-processing on this data using Python, and I have a new field that I want to be able to make queries on. For example, th…

---

## [How to remove master nodes from the elasticsearch cluster](https://discuss.elastic.co/t/how-to-remove-master-nodes-from-the-elasticsearch-cluster/346732)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 7\
**Last updated:** [November 11, 2023, 6:20pm UTC](https://discuss.elastic.co/t/how-to-remove-master-nodes-from-the-elasticsearch-cluster/346732 "2023-11-11T18:20:36Z")

</div>

How could I delete two master nodes that are in my cluster, I currently have 3 master nodes, the cluster version is 7.17. thank you

---

## [Best strategy to join two clusters](https://discuss.elastic.co/t/best-strategy-to-join-two-clusters/346883)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [November 11, 2023, 7:05am UTC](https://discuss.elastic.co/t/best-strategy-to-join-two-clusters/346883 "2023-11-11T07:05:36Z")

</div>

Hi, A customer hand me two clusters, these are in two servers, on each server there are 3 nodes on dockers, what will the best strategy to join these two clusters? Also I was thinking that would be better to get rid of …

---

## [I create a model in Elasticsearch after some time later my Elasticsearch model does not found](https://discuss.elastic.co/t/i-create-a-model-in-elasticsearch-after-some-time-later-my-elasticsearch-model-does-not-found/346903)

<div class="topic-metadata">

**Author:** [@rakibulinux](https://discuss.elastic.co/u/rakibulinux)\
**Replies:** 1\
**Last updated:** [November 11, 2023, 3:48am UTC](https://discuss.elastic.co/t/i-create-a-model-in-elasticsearch-after-some-time-later-my-elasticsearch-model-does-not-found/346903 "2023-11-11T03:48:20Z")

</div>

Hi, @stephenb, how are you today? I create a model in elasticsearch after some time later my elasticsearch model does not found. I see it's automatically get removed. And throwing me this error. {"error":{"root\_cause":\[…

---

## [Help to understand match fields](https://discuss.elastic.co/t/help-to-understand-match-fields/346851)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 2:08pm UTC](https://discuss.elastic.co/t/help-to-understand-match-fields/346851 "2023-11-10T14:08:24Z")

</div>

I have a Problem i have a es database with a huge amount of text and now i try to understand why one article is not found. Here we have our ES-Indexsettings: { "stories": { "aliases": {}, "mappings": { "stories…

---

## [I can't install plugins elasticsearch in docker](https://discuss.elastic.co/t/i-cant-install-plugins-elasticsearch-in-docker/346723)

<div class="topic-metadata">

**Author:** [@arro](https://discuss.elastic.co/u/arro)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 10:43am UTC](https://discuss.elastic.co/t/i-cant-install-plugins-elasticsearch-in-docker/346723 "2023-11-10T10:43:53Z")

</div>

I'm trying to install a plugin for elasticsearch in a docker container. I run the command: docker exec a15de2d3dc21 bin/elasticsearch-plugin install analysis-phonetic and get an error: -\> Installing analysis-phonetic …

---

## [Extend the expiry of the certificates](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 5\
**Last updated:** [November 10, 2023, 10:37am UTC](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548 "2023-11-10T10:37:45Z")

</div>

Hi, we have enabled security for Elasticsearch. We extended the expiry of certificates. But still instance certificate does not get changed and retains the default expiry of 3 years Is there a way to make it work

---

## [Can I change http client used for @elastic/elasticsearch in node js?](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843)

<div class="topic-metadata">

**Author:** [@ghanshyam1](https://discuss.elastic.co/u/ghanshyam1)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:39am UTC](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843 "2023-11-10T07:39:42Z")

</div>

I want to use axios as http client underneath @elastic/elasticsearch.... I am trying using following code, const { Client } = require('@elastic/elasticsearch'); const axios = require('axios'); // Create a custom trans…

---

## [How can I fix a query dsl so that ALL documents are boosted in the function\_score?](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839)

<div class="topic-metadata">

**Author:** [@Kirill\_Cyber](https://discuss.elastic.co/u/Kirill_Cyber)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:05am UTC](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839 "2023-11-10T07:05:45Z")

</div>

I have dsl query with structure { "query": { "function\_score": { "query": { "bool": { "must": { "multi\_match": { …

---

## [Want to create new index daily with date associated with index name](https://discuss.elastic.co/t/want-to-create-new-index-daily-with-date-associated-with-index-name/346197)

<div class="topic-metadata">

**Author:** [@Swapnadeep\_Mondal](https://discuss.elastic.co/u/Swapnadeep_Mondal)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 6:57am UTC](https://discuss.elastic.co/t/want-to-create-new-index-daily-with-date-associated-with-index-name/346197 "2023-11-10T06:57:22Z")

</div>

Hello Team, I've recently learned about date math and I'm interested in creating an ILM (Index Lifecycle Management) policy to generate a new index every day, with the index name associated with the date. For example, I…

---

## [Ingest kafka syslog to elasticsearch or kibana](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834)

<div class="topic-metadata">

**Author:** [@manasi](https://discuss.elastic.co/u/manasi)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 6:08am UTC](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834 "2023-11-10T06:08:37Z")

</div>

Hi all, How to ingest kafka syslog to elasticsearch or kibana? I'm using elasticsearch and Kibana of 8.10.4 version. I want to visualize kafka syslogs on kibana dashboards. But I don't know how to push or integrate the…

---

## [Set "index.mapping.dimension\_fields.limit" does not work](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 3:39am UTC](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330 "2023-11-10T03:39:59Z")

</div>

Hi everyone, We would like to extend the number of dimension\_fields of our TSDS by POST \_index\_template/ds-micrometer-metrics-prod { "index\_patterns": \[ "micrometer" \], "data\_stream": {}, "template": { …

---

## [Sorting results not working properly](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 11:27pm UTC](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816 "2023-11-09T23:27:38Z")

</div>

Hello, I have a datastream that is updated often, I want to get unique results for the field @timestamp, I use this query: GET datastream\_name/\_search { "sort" : \[ { "@timestamp" : { "order":"desc…

---

## [Create Rules in kibana-\> unknown field \[aggs\]](https://discuss.elastic.co/t/create-rules-in-kibana-unknown-field-aggs/346522)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 5:53pm UTC](https://discuss.elastic.co/t/create-rules-in-kibana-unknown-field-aggs/346522 "2023-11-09T17:53:10Z")

</div>

Hi I need to create some rules in kibana over aggregation function but I don't understand what's wrong I got "Error testing query: EsError: \[1:118\] unknown field \[aggs\]" { "query":{ "aggs": { "last\_values"…

---

## [Showing query parameters in DSL query results](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758)

<div class="topic-metadata">

**Author:** [@bgyomorei\_c](https://discuss.elastic.co/u/bgyomorei_c)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 5:00pm UTC](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758 "2023-11-09T17:00:10Z")

</div>

Let's take the DSL query example below. I'd like to see the value of fixed\_interval in date\_histogram in the generated response. Is it possible to tell in the DSL query to display this or any parameter value in the resul…

---

## [Understanding search-as-you-type Fields](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661)

<div class="topic-metadata">

**Author:** [@safakkbilici](https://discuss.elastic.co/u/safakkbilici)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 4:36pm UTC](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661 "2023-11-09T16:36:43Z")

</div>

Hello community, I am using ES on my local machine with version of 8.10.4 I was experimenting with search-as-you-type lately and I am confused by ".\_2gram" and ".\_3gram" fields. I created a basic index as PUT autosugg…

---

## [Same shards on different physicals servers](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 4:01pm UTC](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768 "2023-11-09T16:01:04Z")

</div>

Hi I have deployed EFK stack on Kubernetes cluster, I have 3 nodes that have both roles data and master, the 3 Elasticsearch nodes are on 3 different Kubernetes nodes, but the Kubernetes nodes are on 2 different physical…

---

## [Wrong dynamic mapping in Elasticsearch 8.11 prevents indexation of arrays of more than 127 strings](https://discuss.elastic.co/t/wrong-dynamic-mapping-in-elasticsearch-8-11-prevents-indexation-of-arrays-of-more-than-127-strings/346803)

<div class="topic-metadata">

**Author:** [@JulienCarnec](https://discuss.elastic.co/u/JulienCarnec)\
**Replies:** 4\
**Last updated:** [November 9, 2023, 2:24pm UTC](https://discuss.elastic.co/t/wrong-dynamic-mapping-in-elasticsearch-8-11-prevents-indexation-of-arrays-of-more-than-127-strings/346803 "2023-11-09T14:24:54Z")

</div>

Since 8.11.0, when using dynamic mapping, there is a defect preventing the indexation of documents with an array field containing more than 127 strings. Here is how to reproduce: 1- start Elasticsearch 8.11.0: docker …

---

## [Why should we not use Metricbeat with scope: node for clusters with dedicated master nodes](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 9\
**Last updated:** [November 9, 2023, 1:35pm UTC](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715 "2023-11-09T13:35:36Z")

</div>

I am currently reading the documentation on collecting Elasticsearch monitoring data with Metricbeat. I had already posted something about this here in the forum, which led to this issue. The documentation has improved s…

---

## [How to improve fuzzy match performance](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794)

<div class="topic-metadata">

**Author:** [@chengyang.backend](https://discuss.elastic.co/u/chengyang.backend)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 1:19pm UTC](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794 "2023-11-09T13:19:22Z")

</div>

---

## [Watcher log history not available for some watchers scripts](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 12:48pm UTC](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795 "2023-11-09T12:48:29Z")

</div>

Hi, I am currently facing issue with the watcher logs, currently I am using ELK version 7.11 and when I check Execution history of some watcher for last 1 hour, 1 day or even last week , no logs are available. For few w…

---

## [Single file indexing with multiple docs in es](https://discuss.elastic.co/t/single-file-indexing-with-multiple-docs-in-es/346785)

<div class="topic-metadata">

**Author:** [@ravikiran\_gunda](https://discuss.elastic.co/u/ravikiran_gunda)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 11:56am UTC](https://discuss.elastic.co/t/single-file-indexing-with-multiple-docs-in-es/346785 "2023-11-09T11:56:44Z")

</div>

Hi Everyone, I have one large file and I indexed but that large file created multiple docs in Elasticsearch with myid+sequence no. so is there anyway to create multiple docs under single id, why i am asking is while sear…

---

## [Data nodes removed from cluster one by one after indexing activity peak](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764)

<div class="topic-metadata">

**Author:** [@jalker](https://discuss.elastic.co/u/jalker)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 8:35am UTC](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764 "2023-11-09T08:35:12Z")

</div>

Elasticsearch 7.17, Debian, 12 data nodes, 5.5 Bi primary docs, 11.0 TB primary doc size. We have seen the following behavior twice now and we are clueless as to its root cause. We see an sudden increase of indexing a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=178)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=180)
