# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=181

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 182

---

## [Sorting when scoring documents with child function\_score](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551)

<div class="topic-metadata">

**Author:** [@AngX](https://discuss.elastic.co/u/AngX)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 6:28pm UTC](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551 "2023-11-06T18:28:45Z")

</div>

Hi all, Running into a tricky requirement when it comes to sorting in search so would appreciate getting some thoughts or advice on the matter We have two collections of documents set with a join. The child documents h…

---

## [Plugin \[analysis-icu\] was built for Elasticsearch version 8.5.0 but version 8.9.1 is running](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062)

<div class="topic-metadata">

**Author:** [@lanz](https://discuss.elastic.co/u/lanz)\
**Replies:** 5\
**Last updated:** [November 6, 2023, 5:26pm UTC](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062 "2023-11-06T17:26:15Z")

</div>

Hello, I am trying to upgrade the ELK from 8.5.0 to 8.9.1 version, Once installed 8.9.1 version, I need to install the analysis-icu\] plug-in . Therefore I have followed the steps of this link ICU analysis plugin | Elas…

---

## [Server-client search architecture with PIT in ElasticSearch](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545)

<div class="topic-metadata">

**Author:** [@forceson](https://discuss.elastic.co/u/forceson)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 4:41pm UTC](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545 "2023-11-06T16:41:58Z")

</div>

I want to use search\_after and PIT to provide consistent search results. The guide documentation suggests that PITs should be generated in the background and utilized after each search, rather than after every search. M…

---

## [Need assist with Painless scripting](https://discuss.elastic.co/t/need-assist-with-painless-scripting/345116)

<div class="topic-metadata">

**Author:** [@KristjanH](https://discuss.elastic.co/u/KristjanH)\
**Replies:** 3\
**Last updated:** [November 6, 2023, 3:58pm UTC](https://discuss.elastic.co/t/need-assist-with-painless-scripting/345116 "2023-11-06T15:58:25Z")

</div>

I'm trying to make a script that sorts text that contains text + numbers in numbering order. Example, we have the the data: "Box 1", "Box 2", "Box 3", "Box 10", "Box 20" By using normal alphabetical ordering then it w…

---

## [Multiple Pipelines with condition](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 4\
**Last updated:** [November 6, 2023, 3:44pm UTC](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405 "2023-11-06T15:44:20Z")

</div>

Hi Team, I have been trying to add a condition on my multi processor pipeline. { "4modelprocessor\_peopleagg": { "processors": \[ { "pipeline": { "name": "ner\_pipeline\_peopleagg" } }, { "pipeline": { "name": "e…

---

## [Extra Volume attached to elasticsearch but not not able to use](https://discuss.elastic.co/t/extra-volume-attached-to-elasticsearch-but-not-not-able-to-use/346512)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 12:42pm UTC](https://discuss.elastic.co/t/extra-volume-attached-to-elasticsearch-but-not-not-able-to-use/346512 "2023-11-06T12:42:49Z")

</div>

Hi, I have attached 50 gb of volume to the ec2 instance of ecs in which elasticsearch service is running.But after running GET /\_cat/allocation?v in elasticsearch shards disk.indices disk.used disk.avail disk.total dis…

---

## [Use index action to write to multiple indices](https://discuss.elastic.co/t/use-index-action-to-write-to-multiple-indices/346369)

<div class="topic-metadata">

**Author:** [@rorii](https://discuss.elastic.co/u/rorii)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 12:34pm UTC](https://discuss.elastic.co/t/use-index-action-to-write-to-multiple-indices/346369 "2023-11-06T12:34:11Z")

</div>

I have following action in my watcher: "actions": { "writetoindex": { "transform": { "script": { "id": "my\_tranform\_script", } } "index": { "index": "myindex…

---

## [Clearing the search context manually after reindexing is done](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517)

<div class="topic-metadata">

**Author:** [@Achyut\_Muley](https://discuss.elastic.co/u/Achyut_Muley)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 11:28am UTC](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517 "2023-11-06T11:28:36Z")

</div>

We have a shell script which takes the name of an index and then reindexes it. We are using ES 7.17.0 The reindex command- response=$(curl -u $CREDENTIALS -X POST "$PROTOCOL://$HOST:9200/\_reindex?slices=50&refresh&wai…

---

## [About ES8.10.4 pytorch\_inference](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513)

<div class="topic-metadata">

**Author:** [@jaeho](https://discuss.elastic.co/u/jaeho)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:37am UTC](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513 "2023-11-06T10:37:31Z")

</div>

Hello, I'm using Elasticsearch 8.10.4. I'm aiming to perform vector searches using a custom model through eland. You can find more details on this at NLP를 배포하는 방법: 텍스트 임베딩 및 벡터 검색 | Elastic Blog. I'm facing a long inde…

---

## [Prometheus exporter for Elasticsearch version 7.17.14](https://discuss.elastic.co/t/prometheus-exporter-for-elasticsearch-version-7-17-14/346510)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:12am UTC](https://discuss.elastic.co/t/prometheus-exporter-for-elasticsearch-version-7-17-14/346510 "2023-11-06T10:12:44Z")

</div>

Hello Team: I have upgraded Elasticsearch to version 7.17.14. We are using Prometheus - Grafana Dashboard to monitor the metrics of Elasticsearch Cluster and its Machine. I am unable to find Prometheus Exporter for El…

---

## [Sending cisco switch logs to elasticsearch](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 9:39am UTC](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458 "2023-11-06T09:39:36Z")

</div>

Hello community. I want to send my cisco switches logs to Elasticsearch, and we can't install elastic agent or beats to switches so what are the best ways we can send those logs to the elasticsearch.

---

## [Boolean should query wrong result](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 9:14am UTC](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381 "2023-11-06T09:14:47Z")

</div>

Depending on order of queries, there is no match (wrong) or there is a match (correct). This wrong behavior is only the case of queryes containing one of synonyms. This is my index, data and explain queries: PUT /pokus…

---

## [Best practice for adding/complement additional data to existing documents](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498)

<div class="topic-metadata">

**Author:** [@daniel-san](https://discuss.elastic.co/u/daniel-san)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:32am UTC](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498 "2023-11-06T08:32:12Z")

</div>

Hello there, we're only scratched the surface regarding the possibilities in Elasticsearch so the following question/example might be pretty basic: In our example we have multiple Hosts (VDI Workplaces) that are tied/o…

---

## [ELK v 7.6.0 Paloalto take certain types of logs](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479 "2023-11-06T05:12:42Z")

</div>

Hello I am working with ELK v 7.6.0 I have asked the paloalto firewall administrator to send me the logs via Syslog on port 514 to my server where I have ELK. In the linux operating system in the path /etc/ the file r…

---

## [Integrate APM Logs Format to ELK](https://discuss.elastic.co/t/integrate-apm-logs-format-to-elk/346345)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 8\
**Last updated:** [November 6, 2023, 3:37am UTC](https://discuss.elastic.co/t/integrate-apm-logs-format-to-elk/346345 "2023-11-06T03:37:50Z")

</div>

I have use ELK Stack to my system. My system have integrate my system logs format { "@timestamp": "2023-11-03T08:47:32.547Z", "log.level": "INFO", "message": "Schedule messages: size=1, markerTime=2023-11-03T15:4…

---

## [Node Replacement Procedure](https://discuss.elastic.co/t/node-replacement-procedure/346478)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [November 5, 2023, 11:05pm UTC](https://discuss.elastic.co/t/node-replacement-procedure/346478 "2023-11-05T23:05:01Z")

</div>

Hi All, I have a multi-tier elastic cluster setup. My Hot tier is made up of 4 nodes. I need to replace one of these nodes with a completely new instance (machine). Can anyone recommend the best procedure to follow t…

---

## [Elasticsearch fails to start after reboot](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-reboot/346462)

<div class="topic-metadata">

**Author:** [@gisly](https://discuss.elastic.co/u/gisly)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 3:15pm UTC](https://discuss.elastic.co/t/elasticsearch-fails-to-start-after-reboot/346462 "2023-11-05T15:15:50Z")

</div>

I am running the following version of Elasticsearch "version" : { "number" : "7.12.0", "build\_flavor" : "default", "build\_type" : "rpm", "build\_hash" : "78722783c38caa25a70982b5b042074cde5d3b3a", "b…

---

## [Import Pretrained Model to Elasticsearch Cluster](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 3:09am UTC](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440 "2023-11-05T03:09:09Z")

</div>

Hello everyone. I have a question about import sentence-transformer model to elasticsearch cluster. When I run the python script below, I see only 1 node has allocated my mode, but I want to allocate my model in 2 nodes …

---

## [How to create a document where the \_id has spaces (Dev Tools)](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 9\
**Last updated:** [November 4, 2023, 10:08pm UTC](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404 "2023-11-04T22:08:45Z")

</div>

I am attempting to create a document in an index where \_id has spaces. I get a parsing exception in Dev Tools. Here is the start of POST statement: POST /label-expression/\_doc/(AB\_123 | CD\_123) I must have the spaces, …

---

## [Query for the fields which is non empty](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 5\
**Last updated:** [November 4, 2023, 6:27pm UTC](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764 "2023-11-04T18:27:32Z")

</div>

Hi Team, I'm reaching out query that I have, I want a query which returns the field with any random value inside it and filter out the empty records. For eg: In my case, I have a FileContent.content field and it has va…

---

## [What happened to the .Net client?](https://discuss.elastic.co/t/what-happened-to-the-net-client/346068)

<div class="topic-metadata">

**Author:** [@Eric\_Paul](https://discuss.elastic.co/u/Eric_Paul)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 2:21pm UTC](https://discuss.elastic.co/t/what-happened-to-the-net-client/346068 "2023-11-04T14:21:45Z")

</div>

OK it's been a bit since I coded against elasticsearch. Now it looks like there is a new client to replace nest. But the documentation is severely lacking. I don't see any examples of code except for the most basic stuff…

---

## [Elasticsearch vector](https://discuss.elastic.co/t/elasticsearch-vector/346425)

<div class="topic-metadata">

**Author:** [@zhl19911203](https://discuss.elastic.co/u/zhl19911203)\
**Replies:** 0\
**Last updated:** [November 4, 2023, 11:00am UTC](https://discuss.elastic.co/t/elasticsearch-vector/346425 "2023-11-04T11:00:48Z")

</div>

Is there an official example of how to add, delete, modify, and check vector data in Elasticsearch8.10.2 version? Using Elasticsearch Java client operations

---

## [Unable to load pipelines arraycopy: length -1 is negative](https://discuss.elastic.co/t/unable-to-load-pipelines-arraycopy-length-1-is-negative/346407)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:55pm UTC](https://discuss.elastic.co/t/unable-to-load-pipelines-arraycopy-length-1-is-negative/346407 "2023-11-03T20:55:42Z")

</div>

Hi there, I noticed one of my ingest pipelines didn't appear to be working, and when I went to look at the ingest pipelines, this error message popped up. I haven't been able to find this error anywhere else on any foru…

---

## [Certificate signed by unknown authority](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/346348)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 6\
**Last updated:** [November 3, 2023, 8:12pm UTC](https://discuss.elastic.co/t/certificate-signed-by-unknown-authority/346348 "2023-11-03T20:12:00Z")

</div>

This is my filebeat.yml file but when I want to check it shows error : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: …

---

## [High cpu for new data nodes for several days?](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 7:22pm UTC](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400 "2023-11-03T19:22:55Z")

</div>

Has anybody experienced this? Or is this normal? After adding 6 new data nodes, the high CPU (bouncing off 100%) often persisted for several days (around 5 days). The shards are balanced within a day of new node addit…

---

## [Accessing Aggregation buckets to get the \`key\` value and \`\_doc\` values](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391)

<div class="topic-metadata">

**Author:** [@Santosh\_mandyajayara](https://discuss.elastic.co/u/Santosh_mandyajayara)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 5:12pm UTC](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391 "2023-11-03T17:12:50Z")

</div>

We were using the Rest High Level Client before and below was the usage to access the aggregation buckets from the SearchResponse ParsedStringTerms aggregation1 = searchResponse.getAggregations().get(AGGREGATION1.name…

---

## [Deleting indices older than 30 days with policy problem](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 4:51pm UTC](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388 "2023-11-03T16:51:25Z")

</div>

I am using an application that creates daily indices, using legacy index template. Two types of indices are created: jaeger-spans-date and jaeger-services-date (where date is the date produced). Using the kibana UI, I c…

---

## [Elastic nodes started to give hardware error on esxi 8.01c servers](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208)

<div class="topic-metadata">

**Author:** [@cemkayar](https://discuss.elastic.co/u/cemkayar)\
**Replies:** 8\
**Last updated:** [November 3, 2023, 9:56am UTC](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208 "2023-11-03T09:56:09Z")

</div>

Hi, After upgrading ESXi servers from 7.0.3l to 8.0.1c some of the elastic clusters started to give hardware errors during index hash. If move the problematic elastics VMs to the old version of the esxi servers (7.0.3l …

---

## [After stopping elasticserver 8.x it is shown status deactivating](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329)

<div class="topic-metadata">

**Author:** [@subrahmanyam](https://discuss.elastic.co/u/subrahmanyam)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 8:58am UTC](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329 "2023-11-03T08:58:01Z")

</div>

Loaded: loaded (/etc/systemd/system/Elasticsearch8.service; enabled; vendor preset: disabled) Active: deactivating (stop-sigterm) since Thu 2023-11-02 13:28:39 GMT; 16h ago Process: 2780103 ExecStop=/test/config/elasti…

---

## [Nested JSON in CSV](https://discuss.elastic.co/t/nested-json-in-csv/346310)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 4:54am UTC](https://discuss.elastic.co/t/nested-json-in-csv/346310 "2023-11-03T04:54:39Z")

</div>

I have a CSV file with 1500 rows of data. I am wanting to optimize how I have certain data and nest it in Elastic. Here's an example: Name, Location, Age, Favorite Colors Bob, USA, 32, Orange, Pink Jane, USA, 28, Gr…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=180)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=182)
