# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=197

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 198

---

## [Restrict nested data in result of search](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 5:38pm UTC](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918 "2023-09-26T17:38:21Z")

</div>

I have a index that stores tasks to do, in it there is a user id, task id and inside there is nested data that is used to store a timer that the user started and finished working on a task. I have a script that I used i…

---

## [Indexing Subtitles and Maintaining Timestamps](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708)

<div class="topic-metadata">

**Author:** [@ADarkDividedGem](https://discuss.elastic.co/u/ADarkDividedGem)\
**Replies:** 7\
**Last updated:** [September 26, 2023, 5:32pm UTC](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708 "2023-09-26T17:32:00Z")

</div>

I am wanting to index subtitles and also maintain the timestamp data. My initial thought was to make each line of text a document with the start and end timestamps stored as fields for that document. For example the fol…

---

## [Discovery in multi node cluster using docker compose](https://discuss.elastic.co/t/discovery-in-multi-node-cluster-using-docker-compose/343199)

<div class="topic-metadata">

**Author:** [@JoyceBabu](https://discuss.elastic.co/u/JoyceBabu)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 3:21pm UTC](https://discuss.elastic.co/t/discovery-in-multi-node-cluster-using-docker-compose/343199 "2023-09-26T15:21:38Z")

</div>

I am trying to create a three node ElasticSEarch cluster following the tutorial When I set cluster.initial\_master\_nodes to es1,es2,es3, I am getting the warning this node is locked into cluster UUID \[lUWf3vbtRcarnQX…

---

## [Importing / Exporting dashboards and agent policy's](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:24pm UTC](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878 "2023-09-26T14:24:39Z")

</div>

Hi, I would like to export my dashboards and agent policies to use in another Elastic cluster. Is this possible to do? If so, how can I do this? Thanks!

---

## [Search\_after still gives me duplicates](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 1:22pm UTC](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861 "2023-09-26T13:22:32Z")

</div>

Hi, I have implemented a search-after pattern in my Elasticsearch implementation with a hope of solving duplicate issue we are currently facing. On the first request, I am getting a batch of 100 and then get the raw\_scor…

---

## [Why does the documentation lack so many topics?](https://discuss.elastic.co/t/why-does-the-documentation-lack-so-many-topics/343746)

<div class="topic-metadata">

**Author:** [@du-it](https://discuss.elastic.co/u/du-it)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 1:16pm UTC](https://discuss.elastic.co/t/why-does-the-documentation-lack-so-many-topics/343746 "2023-09-26T13:16:49Z")

</div>

To be able to replace org.elasticsearch.\* classes with co.elastic.\* classes it would be very helpful to find a good documentation with a lot of examples. Why is it poorly possible to find any? For instance, what are the…

---

## [Use a NEST based Client with Indices created from fscrawler](https://discuss.elastic.co/t/use-a-nest-based-client-with-indices-created-from-fscrawler/343782)

<div class="topic-metadata">

**Author:** [@Voidi](https://discuss.elastic.co/u/Voidi)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 12:20pm UTC](https://discuss.elastic.co/t/use-a-nest-based-client-with-indices-created-from-fscrawler/343782 "2023-09-26T12:20:17Z")

</div>

I want create Client program based on the NEST Library which queries an Index created with GitHub - dadoonet/fscrawler: Elasticsearch File System Crawler (FS Crawler) . Most NEST tutorials show that i should create a cl…

---

## [How to ignore last element of array in elastic watcher \\ mustache template](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 12:12pm UTC](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801 "2023-09-26T12:12:49Z")

</div>

Hello! I have an issue when trying to set an elasticsearch watcher. Here is the part of its config: "input": { "chain": { "inputs": \[ { "\*\*first\*\*": { "search": { …

---

## [Date math Incorrect HTTP method for uri](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 11:30am UTC](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843 "2023-09-26T11:30:53Z")

</div>

Hi I just want to create index with date math from dev tool console for rollover but I got below error: request PUT /%3Cindex\_test-%7Bnow%2Fd%7BYYYYMMDD%7D%7D%3E { "aliases": { "logs\_write": {} } } { "error…

---

## [Elastic apm instrumentation not working for my Flask application running in python 3.x](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693)

<div class="topic-metadata">

**Author:** [@Ankit\_kumar\_Srivasta](https://discuss.elastic.co/u/Ankit_kumar_Srivasta)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 11:22am UTC](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693 "2023-09-26T11:22:04Z")

</div>

I am unable to find out transaction traces on kibana server after using the apm object like this. app = Flask(\_\_name\_\_) app.secret\_key = "ahugekey@netcore#2019" app.config\['ELASTIC\_APM'\] = { 'SERVICE\_NAME': 'o…

---

## [Help with POST URL](https://discuss.elastic.co/t/help-with-post-url/343444)

<div class="topic-metadata">

**Author:** [@ElasticNovis](https://discuss.elastic.co/u/ElasticNovis)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 11:14am UTC](https://discuss.elastic.co/t/help-with-post-url/343444 "2023-09-26T11:14:49Z")

</div>

Hi, I am new to POST URLs but my goal is to generate a pdf from a dashboard automatically, and save it locally to a shared area. I have got my POST URL of my dashboard and using Unix curl command I have tried to get the…

---

## [How to restore a snapshot/how to backup the indexes in my locally installed Elastic Search from Elastic Cloud?](https://discuss.elastic.co/t/how-to-restore-a-snapshot-how-to-backup-the-indexes-in-my-locally-installed-elastic-search-from-elastic-cloud/343852)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 11:06am UTC](https://discuss.elastic.co/t/how-to-restore-a-snapshot-how-to-backup-the-indexes-in-my-locally-installed-elastic-search-from-elastic-cloud/343852 "2023-09-26T11:06:45Z")

</div>

So, I have some indices on my elastic cloud. Initially, I registered a repository on my own AWS S3 bucket and then created a snapshot that has all the indices stored within it. Now, I have installed Elastic Search and Ki…

---

## [How to update ES node transport address](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851)

<div class="topic-metadata">

**Author:** [@HadesC](https://discuss.elastic.co/u/HadesC)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:59am UTC](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851 "2023-09-26T10:59:32Z")

</div>

I have two Red Hat installed ES 7.9.1 nodes (build type: tar) in my environment, joined to same cluster. Suppose one of the Red Hat nodes should only have private IP 10.121.0.2, somehow there is another private IP 10.12…

---

## [Asking how to nested logstash](https://discuss.elastic.co/t/asking-how-to-nested-logstash/343826)

<div class="topic-metadata">

**Author:** [@Shi\_Eng\_Ng](https://discuss.elastic.co/u/Shi_Eng_Ng)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:47am UTC](https://discuss.elastic.co/t/asking-how-to-nested-logstash/343826 "2023-09-26T03:47:33Z")

</div>

"archives\_id": null, "level\_of\_detail": null, "items": \[ { "barcode": "000892", "brn": "4188", "collection": "\["Books"\]", "updated\_time": "2023-09-13 11:36:56.000000", "suffix": "LAI", "status": "Available", "a…

---

## [Unable to Upload Winevt to Elastic Stack](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809)

<div class="topic-metadata">

**Author:** [@scott\_securit360](https://discuss.elastic.co/u/scott_securit360)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:20pm UTC](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809 "2023-09-25T21:20:18Z")

</div>

Hello! I've recently enabled Security on my Elastic stack (7.17) using the documentation here. I've completed up until the "Configure Beats security" section, as that is not needed in my environment. I'm using the Bur…

---

## [Elastic Fleet - Add GeoData to winlog through Ingest Pipeline](https://discuss.elastic.co/t/elastic-fleet-add-geodata-to-winlog-through-ingest-pipeline/343805)

<div class="topic-metadata">

**Author:** [@Shane\_Martin](https://discuss.elastic.co/u/Shane_Martin)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elastic-fleet-add-geodata-to-winlog-through-ingest-pipeline/343805 "2023-09-25T19:56:06Z")

</div>

Trying to add geo data based on the winlog.event\_data.destinationIp field. I'm trying to use the custom ingest pipeline in fleets / integration. Testing the pipeline with test data seems to work, but the geo fields in …

---

## [Is it possible to have the cluster use a node's hardware specs for allocation decisions?](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634)

<div class="topic-metadata">

**Author:** [@Mike\_Snare](https://discuss.elastic.co/u/Mike_Snare)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 5:59pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634 "2023-09-25T17:59:44Z")

</div>

I know that it's possible to use custom attributes in allocations for things like rack-awareness, but I'm more interested in whether or not elastic is capable of taking a node's hardware specs into consideration when dec…

---

## [High resource usage of query with large term filter](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585)

<div class="topic-metadata">

**Author:** [@Ray\_Zhang](https://discuss.elastic.co/u/Ray_Zhang)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:15pm UTC](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585 "2023-09-25T17:15:32Z")

</div>

We are running some rather large queries with about 6 thousand of term values in the filter sections. The queries take 20 to 40 more seconds to run and much more CPU usage were observed when running with the large term …

---

## [How to find polygons that contain a given point in Elasticsearch](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769)

<div class="topic-metadata">

**Author:** [@Pranav\_Kapur](https://discuss.elastic.co/u/Pranav_Kapur)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769 "2023-09-25T16:05:57Z")

</div>

I need to build a query on a database with around 50k terrain polygons (stored as geo\_shape polygons on ES) where I give a point and it returns every polygon that contains this point. I tried to create it, but getting i…

---

## [Transform checkpoints not optimized with date histogram](https://discuss.elastic.co/t/transform-checkpoints-not-optimized-with-date-histogram/343561)

<div class="topic-metadata">

**Author:** [@Imran\_Arshad](https://discuss.elastic.co/u/Imran_Arshad)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:01pm UTC](https://discuss.elastic.co/t/transform-checkpoints-not-optimized-with-date-histogram/343561 "2023-09-25T16:01:20Z")

</div>

I am running a transform that groups by 2 fields: 1. terms on a keyword field (client\_id), 2. date histogram on a date field (transaction\_time). For sync, I am using a separate date field (updated\_at) that is basically t…

---

## [No way to rollover mutable timeseries data](https://discuss.elastic.co/t/no-way-to-rollover-mutable-timeseries-data/343784)

<div class="topic-metadata">

**Author:** [@kmcclellan](https://discuss.elastic.co/u/kmcclellan)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 2:57pm UTC](https://discuss.elastic.co/t/no-way-to-rollover-mutable-timeseries-data/343784 "2023-09-25T14:57:56Z")

</div>

Since datastreams are append-only, Tutorial: Automate rollover with ILM | Elasticsearch Guide \[8.10\] | Elastic suggests an alternative technique for rolling over mutable documents: In these cases, you can use an index …

---

## [How different are Elasticsearch and OpenSearch?](https://discuss.elastic.co/t/how-different-are-elasticsearch-and-opensearch/343691)

<div class="topic-metadata">

**Author:** [@heermaas3](https://discuss.elastic.co/u/heermaas3)\
**Replies:** 6\
**Last updated:** [September 25, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-different-are-elasticsearch-and-opensearch/343691 "2023-09-25T14:48:50Z")

</div>

I wanted to ask for a neutral opinion on the differences between Elasticsearch and OpenSearch. Are there differences in use/integrating them into my Software? Do I have to write different code to use both of them? Can …

---

## [How to implement Phrase suggester using .net elastic.clients.elasticsearch?](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 1:25pm UTC](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757 "2023-09-25T13:25:39Z")

</div>

How to implement Phrase suggester using .net elastic.clients.elasticsearch in a best way

---

## [Mapper\_exception while using runtime dynamic mapping](https://discuss.elastic.co/t/mapper-exception-while-using-runtime-dynamic-mapping/343764)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:13pm UTC](https://discuss.elastic.co/t/mapper-exception-while-using-runtime-dynamic-mapping/343764 "2023-09-25T13:13:49Z")

</div>

Hi, We are using runtime dynamic mapping for indices and receiving below error while indexing. Indexing failed for some events, type: mapper\_exception, reason: timed out while waiting for a dynamic mapping update Even…

---

## [Update ILM and link to an existing index](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762 "2023-09-25T13:03:21Z")

</div>

Hello, I have to update an ILM and update link to an existing index but i have a doubt on my API call Is that good one? curl -u elastic:xxxx -k -X PUT "https://elasticsearch-1:9200/index-raw-syslog/settings?pretty" -H…

---

## [Calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:32pm UTC](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754 "2023-09-25T12:32:33Z")

</div>

How do you calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license for master and data nodes in Elasticsearch ,please ?

---

## [UNASSIGNED NODE\_LEFT](https://discuss.elastic.co/t/unassigned-node-left/343737)

<div class="topic-metadata">

**Author:** [@PugachevLB](https://discuss.elastic.co/u/PugachevLB)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:51am UTC](https://discuss.elastic.co/t/unassigned-node-left/343737 "2023-09-25T09:51:30Z")

</div>

We have a cluster of 30 nodes (3 phys servers 64 cpu + 512 mem with 10 ES instances on each (1 master + 9 data)). Sometimes after uploading a new index (~700 Gb 24 shards \* 2 rep factor) we have some instances crushed (…

---

## [How to fetch nested json data in separate fields](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 5:23am UTC](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701 "2023-09-25T05:23:02Z")

</div>

Hello I need a little help. I want to fetch some nested json data into separate fields input { beats { port =\> 5044 } } filter { if "/var/log/ABC.log" in \[log\]\[file\]\[path\] { grok { match =\> …

---

## [Elasticsearch Node went down abruptly and lost data](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566)

<div class="topic-metadata">

**Author:** [@nsoni](https://discuss.elastic.co/u/nsoni)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:16am UTC](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566 "2023-09-25T05:16:23Z")

</div>

I am running Elasticsearch cluster version 7.10.0 It's running for a year now, never faced any issues. Our setup comprises 1 primary and 1 replica in a different availability zone. Distribution is through the rack\_id a…

---

## [Regarding the usage of nested fields](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 4:22am UTC](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655 "2023-09-25T04:22:45Z")

</div>

Hi all, I need to ingest a large volume of records from one data source to another and one topic that I am currently debating is regarding the usage of Nested Field with Arrays or using Multi match and search across mu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=196)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=198)
