# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=186

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 187

---

## [Transforms: How to aggregate multiple events into one event based on shared field?](https://discuss.elastic.co/t/transforms-how-to-aggregate-multiple-events-into-one-event-based-on-shared-field/345055)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 6:28pm UTC](https://discuss.elastic.co/t/transforms-how-to-aggregate-multiple-events-into-one-event-based-on-shared-field/345055 "2023-10-15T18:28:57Z")

</div>

Hi, I have the following events writing to the same index in ES: { "@timestamp": "2023-10-15T17:06:05.137039490Z", "ssn": null, "z4date": "1697207822", "criminalnotes": null, "reason": null, "notes": null, …

---

## [My search term has reserved characters, and I need to perform a wildcard search](https://discuss.elastic.co/t/my-search-term-has-reserved-characters-and-i-need-to-perform-a-wildcard-search/344943)

<div class="topic-metadata">

**Author:** [@NandhiniD](https://discuss.elastic.co/u/NandhiniD)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:51pm UTC](https://discuss.elastic.co/t/my-search-term-has-reserved-characters-and-i-need-to-perform-a-wildcard-search/344943 "2023-10-24T14:51:20Z")

</div>

Hi, I'm trying to search for multiple terms containing special characters using wildcards. To do this, I've employed the query string with the AND operator and multiple terms. When I exclusively use the code below, wil…

---

## [Doubt about Coordinating Node Resources](https://discuss.elastic.co/t/doubt-about-coordinating-node-resources/345394)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 8\
**Last updated:** [October 24, 2023, 1:22pm UTC](https://discuss.elastic.co/t/doubt-about-coordinating-node-resources/345394 "2023-10-24T13:22:03Z")

</div>

Hi, everyone I have a couple of questions about coordinating nodes: What are the minimum resources (RAM, CPU, disk) for a coordinating node? What do I need to do in order to estimate the resources for this kind of nod…

---

## [XMS-XMX settings set in the "options" files are ignored (elasticsearch-8.1, Windows)](https://discuss.elastic.co/t/xms-xmx-settings-set-in-the-options-files-are-ignored-elasticsearch-8-1-windows/345624)

<div class="topic-metadata">

**Author:** [@CrazyDiamond](https://discuss.elastic.co/u/CrazyDiamond)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 11:53am UTC](https://discuss.elastic.co/t/xms-xmx-settings-set-in-the-options-files-are-ignored-elasticsearch-8-1-windows/345624 "2023-10-24T11:53:35Z")

</div>

Hello all. I use a certain product with a built-in Elastic installation (it is installed along with the product, I did not deploy it myself). The server (Windows) has 16GB RAM, and Elastic uses 8 (I see this in the pro…

---

## [Logstash and Beats -Metricbeat,Filebeat stats monitoring using metricbeat](https://discuss.elastic.co/t/logstash-and-beats-metricbeat-filebeat-stats-monitoring-using-metricbeat/344385)

<div class="topic-metadata">

**Author:** [@Jason\_Paralta](https://discuss.elastic.co/u/Jason_Paralta)\
**Replies:** 5\
**Last updated:** [October 24, 2023, 11:50am UTC](https://discuss.elastic.co/t/logstash-and-beats-metricbeat-filebeat-stats-monitoring-using-metricbeat/344385 "2023-10-24T11:50:24Z")

</div>

Hello All, I've a simple requirement as stated below and unable to achieve after attempts: Multiple servers run metricbeat,filebeat and heartbeat in respective servers and in kibana dashboards I'd like to monitor in ta…

---

## [Opensearch adding new value to the old one](https://discuss.elastic.co/t/opensearch-adding-new-value-to-the-old-one/345626)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 9:59am UTC](https://discuss.elastic.co/t/opensearch-adding-new-value-to-the-old-one/345626 "2023-10-24T09:59:38Z")

</div>

I have an opensearch and logstash stack; logstash sending logs from the base and i need to not just replace old values(that’s already works with method update in logstash and templates in opensearch), but adding new to t…

---

## [Rollup job and summarize with distinct values](https://discuss.elastic.co/t/rollup-job-and-summarize-with-distinct-values/345625)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 9:54am UTC](https://discuss.elastic.co/t/rollup-job-and-summarize-with-distinct-values/345625 "2023-10-24T09:54:38Z")

</div>

Hi, Is there a way to have a daily rollup job and instead of aggregations like min, max, etc, we store the distinct values of specific fields instead? Not the distinct count, but the actual values. Thank you.

---

## [Updating only a few fields out of many](https://discuss.elastic.co/t/updating-only-a-few-fields-out-of-many/345508)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 3\
**Last updated:** [October 24, 2023, 1:57am UTC](https://discuss.elastic.co/t/updating-only-a-few-fields-out-of-many/345508 "2023-10-24T01:57:32Z")

</div>

ES version: 7.10 100 data nodes 1000 primary shards 5 B documents, 12 TB External versioning We are upserting almost 500 M documents a day and it is done via Index API. Each document could have 50 - 300 fields and in t…

---

## [Docker Elasticsearch 8.10.3 Java Crash](https://discuss.elastic.co/t/docker-elasticsearch-8-10-3-java-crash/345137)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 1:36am UTC](https://discuss.elastic.co/t/docker-elasticsearch-8-10-3-java-crash/345137 "2023-10-24T01:36:00Z")

</div>

Hey all, I tried upgrading my docker image from 8.8.0 which has been working fine, to 8.10.3 since thats the latest and encountered a Java crash when doing so. I havent been able to get a container running the 8.10.3 im…

---

## [Index Pattern Refresh](https://discuss.elastic.co/t/index-pattern-refresh/345603)

<div class="topic-metadata">

**Author:** [@Manuel\_Javier\_Martin](https://discuss.elastic.co/u/Manuel_Javier_Martin)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 12:23am UTC](https://discuss.elastic.co/t/index-pattern-refresh/345603 "2023-10-24T00:23:26Z")

</div>

Hi, Im using ES 7.10.2, and Im trying to refresh index patterns within python code, I already hit some endpoints GET api/index\_patterns/\_fields\_for\_wildcard?pattern=statsboard\_logs-\*&stored\_fields=\_source&stored\_fields=…

---

## [Elasticsearch automatic rebalancing process](https://discuss.elastic.co/t/elasticsearch-automatic-rebalancing-process/345582)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 5:39pm UTC](https://discuss.elastic.co/t/elasticsearch-automatic-rebalancing-process/345582 "2023-10-23T17:39:40Z")

</div>

Hi, We are running two (almost) identical Elasticsearch clusters v8.7.0, one of them works perfectly fine and in the second one we have shard balancing issues: is there a way to see why the automatic rebalancing pro…

---

## [ScanError while scrolling more than 10k docs](https://discuss.elastic.co/t/scanerror-while-scrolling-more-than-10k-docs/345517)

<div class="topic-metadata">

**Author:** [@mans4singh](https://discuss.elastic.co/u/mans4singh)\
**Replies:** 5\
**Last updated:** [October 23, 2023, 4:08pm UTC](https://discuss.elastic.co/t/scanerror-while-scrolling-more-than-10k-docs/345517 "2023-10-23T16:08:08Z")

</div>

Hi: I am getting ScanError (ScanError('Scroll request has only succeeded on 7 (+5 skipped) shards out of 15.')) when the search results is large (mostly when it is more than 10k). I have a few questions about it: Wha…

---

## [Elastic Cloud Persistent Queue?](https://discuss.elastic.co/t/elastic-cloud-persistent-queue/345066)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 5\
**Last updated:** [October 23, 2023, 4:00pm UTC](https://discuss.elastic.co/t/elastic-cloud-persistent-queue/345066 "2023-10-23T16:00:53Z")

</div>

I am ingesting logs from an on-prem logstash to Elastic Cloud. My Logstash instance has persistent queue enabled. I ingested a large set of data, about 50 million events from my on-prem Elasticsearch instance using the…

---

## [URL redirect for specific queries instead of search results](https://discuss.elastic.co/t/url-redirect-for-specific-queries-instead-of-search-results/345579)

<div class="topic-metadata">

**Author:** [@Max\_Townsend](https://discuss.elastic.co/u/Max_Townsend)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 3:06pm UTC](https://discuss.elastic.co/t/url-redirect-for-specific-queries-instead-of-search-results/345579 "2023-10-23T15:06:00Z")

</div>

Is it possible to redirect to another page when certain keywords are searched? We are a marketplace and would like to redirect users to specific brand pages instead of a results page. Ability to configure certain queri…

---

## [Correct configuration Elastic Search 8.10.4](https://discuss.elastic.co/t/correct-configuration-elastic-search-8-10-4/345238)

<div class="topic-metadata">

**Author:** [@Fernando\_Oliveira](https://discuss.elastic.co/u/Fernando_Oliveira)\
**Replies:** 9\
**Last updated:** [October 23, 2023, 1:50pm UTC](https://discuss.elastic.co/t/correct-configuration-elastic-search-8-10-4/345238 "2023-10-23T13:50:11Z")

</div>

I'm starting a new Elastic installation search and Kibana, version 8.10.4.. My goal is to make a better distribution following some recommendations I saw, for example 3 master, 2 data hot, 2 warm in different zones.. S…

---

## [Date Histogram bucket boundaries](https://discuss.elastic.co/t/date-histogram-bucket-boundaries/345301)

<div class="topic-metadata">

**Author:** [@arunachala](https://discuss.elastic.co/u/arunachala)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 11:18am UTC](https://discuss.elastic.co/t/date-histogram-bucket-boundaries/345301 "2023-10-23T11:18:35Z")

</div>

Hi, I understand that the bucket boundaries for date\_histogram are calculated with respect to epoch time. Is there any option to change this to a specific time? I am trying to achieve similar results as what some of da…

---

## [Aggregate two records in one index](https://discuss.elastic.co/t/aggregate-two-records-in-one-index/345503)

<div class="topic-metadata">

**Author:** [@reza\_sabz](https://discuss.elastic.co/u/reza_sabz)\
**Replies:** 6\
**Last updated:** [October 23, 2023, 9:52am UTC](https://discuss.elastic.co/t/aggregate-two-records-in-one-index/345503 "2023-10-23T09:52:42Z")

</div>

Hello guys, I have an index with a lot of records, like these: "\_source": { "terminal\_number": " 123456", "date": "2023-10-18 12:02:31.676", "iin": " 111111111 ", "service\_type": "o.t.s.transactions.trm.TerminalServ…

---

## [Issues with kibana visualization data table not showing matching results](https://discuss.elastic.co/t/issues-with-kibana-visualization-data-table-not-showing-matching-results/345553)

<div class="topic-metadata">

**Author:** [@Srikanth\_V](https://discuss.elastic.co/u/Srikanth_V)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 9:31am UTC](https://discuss.elastic.co/t/issues-with-kibana-visualization-data-table-not-showing-matching-results/345553 "2023-10-23T09:31:19Z")

</div>

Dear, I am using kibana data table visualization to show various fields in my dashboard. There is an issue that I am facing with regards to missing rows. I have 2 indexes, for french and dutch. There seems to be a mism…

---

## [Elasticsearch "ignore\_above" issues. Unable to use the updated mapping setting after reindex](https://discuss.elastic.co/t/elasticsearch-ignore-above-issues-unable-to-use-the-updated-mapping-setting-after-reindex/345498)

<div class="topic-metadata">

**Author:** [@Shi\_Eng\_Ng](https://discuss.elastic.co/u/Shi_Eng_Ng)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-ignore-above-issues-unable-to-use-the-updated-mapping-setting-after-reindex/345498 "2023-10-23T08:35:47Z")

</div>

Index Mapping(In Kibana) GET /new\_index/\_mapping I already reset the "ignore\_above" to the larger size, but it seems not working for my index when I query for searching. I heard from other solutions that I need to rei…

---

## [Not condition met after configure watcher alert to email](https://discuss.elastic.co/t/not-condition-met-after-configure-watcher-alert-to-email/345538)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 4:10am UTC](https://discuss.elastic.co/t/not-condition-met-after-configure-watcher-alert-to-email/345538 "2023-10-23T04:10:18Z")

</div>

Hi everyone! I have text configured alert send watcher to email. However it is seem wrong text and not condition met send to email: code: { "trigger": { "schedule": { "interval": "1m" } }, "input": { "search":…

---

## [How to suppress ElasticSearch output stats](https://discuss.elastic.co/t/how-to-suppress-elasticsearch-output-stats/345533)

<div class="topic-metadata">

**Author:** [@hs121](https://discuss.elastic.co/u/hs121)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 2:34am UTC](https://discuss.elastic.co/t/how-to-suppress-elasticsearch-output-stats/345533 "2023-10-23T02:34:26Z")

</div>

Hi, Upon creating connection to Elasticsearch or indexing using python API, the output console shows elastic\_transport.transport stats. Is there a way I can suppress this information? Thanks e.g nodes = \[ https://el…

---

## [ElasticSearch 7.10 Spark hadoop support for sign requests ( AWS Signature V4)](https://discuss.elastic.co/t/elasticsearch-7-10-spark-hadoop-support-for-sign-requests-aws-signature-v4/345531)

<div class="topic-metadata">

**Author:** [@deepblue1618](https://discuss.elastic.co/u/deepblue1618)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 1:48am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-spark-hadoop-support-for-sign-requests-aws-signature-v4/345531 "2023-10-23T01:48:48Z")

</div>

We are using Elasticsearch v7.10 and use spark to write bulk documents to the index. I was under the impression that we can sign request by passing headers like beow: df.write.mode("append").format('org.elasticsearch.s…

---

## [Custom sorting](https://discuss.elastic.co/t/custom-sorting/345525)

<div class="topic-metadata">

**Author:** [@maxim-pushchinskiy](https://discuss.elastic.co/u/maxim-pushchinskiy)\
**Replies:** 1\
**Last updated:** [October 22, 2023, 4:52pm UTC](https://discuss.elastic.co/t/custom-sorting/345525 "2023-10-22T16:52:26Z")

</div>

I have documents like: POST /your-index-name/\_doc/1 { "bbCategories": \["Shirts"\], "otherField": "value1" } POST /your-index-name/\_doc/2 { "bbCategories": \["Trousers"\], "otherField": "value2" } POST /your-index…

---

## [Elasticsearch stopped working , it is not extracting contents from documents](https://discuss.elastic.co/t/elasticsearch-stopped-working-it-is-not-extracting-contents-from-documents/345072)

<div class="topic-metadata">

**Author:** [@priyankaa](https://discuss.elastic.co/u/priyankaa)\
**Replies:** 16\
**Last updated:** [October 21, 2023, 10:24pm UTC](https://discuss.elastic.co/t/elasticsearch-stopped-working-it-is-not-extracting-contents-from-documents/345072 "2023-10-21T22:24:26Z")

</div>

due to disk storage got full , Elasticsearch was stopped working , so we have now increased it , still after increasing disk storage Elasticsearch is not working , I performed reindexing as per my senior suggestion , but…

---

## [Index with multiple replicas turned red when node with primary went down](https://discuss.elastic.co/t/index-with-multiple-replicas-turned-red-when-node-with-primary-went-down/345439)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 10\
**Last updated:** [October 21, 2023, 6:46pm UTC](https://discuss.elastic.co/t/index-with-multiple-replicas-turned-red-when-node-with-primary-went-down/345439 "2023-10-21T18:46:33Z")

</div>

Hi all, I saw an unusual issue in our cluster where one of the indices configured with 1p:2r turned red when the node with primary shard went down. By the time I was checking the node was already back in cluster and the…

---

## [How to excute size function in script Plainess when I want access my field with type nested?](https://discuss.elastic.co/t/how-to-excute-size-function-in-script-plainess-when-i-want-access-my-field-with-type-nested/345429)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 1\
**Last updated:** [October 21, 2023, 3:58pm UTC](https://discuss.elastic.co/t/how-to-excute-size-function-in-script-plainess-when-i-want-access-my-field-with-type-nested/345429 "2023-10-21T15:58:18Z")

</div>

Example, I have index following: PUT candidates { "mappings": { "language": { type: "nested" } } } POST candidates/\_doc { "firstname": "Mike", "age": 31, "city": "New York", "language":\[ { …

---

## [Does Spring Boot 3.1 require Elasticsearch 8?](https://discuss.elastic.co/t/does-spring-boot-3-1-require-elasticsearch-8/345335)

<div class="topic-metadata">

**Author:** [@Michal\_Stefaniuk](https://discuss.elastic.co/u/Michal_Stefaniuk)\
**Replies:** 7\
**Last updated:** [October 21, 2023, 3:31pm UTC](https://discuss.elastic.co/t/does-spring-boot-3-1-require-elasticsearch-8/345335 "2023-10-21T15:31:29Z")

</div>

Hey, quick question. We're working on an application that is currently using java 11, spring boot 2.7 and elasticsearch 7.17.10. We are migrating to java 17 and spring boot 3.1. Recently we stumbled upon a document tha…

---

## [Splitting query returns](https://discuss.elastic.co/t/splitting-query-returns/345416)

<div class="topic-metadata">

**Author:** [@ken.s](https://discuss.elastic.co/u/ken.s)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/splitting-query-returns/345416 "2023-10-19T19:09:36Z")

</div>

Hi there. I'm working on returning multple query results based on an inner array. For instance, I have an object that looks like this: { "customer\_order\_number": "T391704031545", "aggregation\_date\_time": "2023-…

---

## [Web crawler and semantic search](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485)

<div class="topic-metadata">

**Author:** [@Michal\_Stoklasa](https://discuss.elastic.co/u/Michal_Stoklasa)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 8:13pm UTC](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485 "2023-10-20T20:13:18Z")

</div>

Hi, im looking for web crawler connected to similarity search for my chatbot product. I have to be able to crawl website and then search similar parts based on query. Something like classic vector search with embedding…

---

## [DELETE index command returns varying JSON objects](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 6:03pm UTC](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410 "2023-10-20T18:03:02Z")

</div>

(ES 8.6.2, W10) In Insomnia, when I try to delete an non-existent index, using command DELETE and url https://localhost:9500/my\_test\_index, I always seem to get a JSON object like this: { "error": { "root\_cause": \[ …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=185)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=187)
