# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=208

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 209

---

## [Elastic search order of the highlighted fields not matching with the ranking](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889)

<div class="topic-metadata">

**Author:** [@Vikram\_Jadhav](https://discuss.elastic.co/u/Vikram_Jadhav)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 2:19pm UTC](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889 "2023-08-29T14:19:23Z")

</div>

Hello, In the below document, I am trying to match multiple fields and I also want to know what fields are getting matched from the document that's why used the highlighted fields. sample doc: { "therapeutic\_area": "…

---

## [How to compare document fields in a elasticsearch query](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814)

<div class="topic-metadata">

**Author:** [@juanmgarciaf](https://discuss.elastic.co/u/juanmgarciaf)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 2:17pm UTC](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814 "2023-08-29T14:17:06Z")

</div>

Hello! I have an index with a lot of documents and I need to group these documents by an specific field and after this I need to compare if the two last documents (with the most recent timestamp) from each group have a s…

---

## [Hi elasticsearch resthighlevelclient SocketTimeOutException issue](https://discuss.elastic.co/t/hi-elasticsearch-resthighlevelclient-sockettimeoutexception-issue/341885)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:59pm UTC](https://discuss.elastic.co/t/hi-elasticsearch-resthighlevelclient-sockettimeoutexception-issue/341885 "2023-08-29T13:59:19Z")

</div>

As the title says, I'm currently facing a SocketTimeoutException. There are almost no servers and it happens even expected (about 2 per traffic?) So I think it's a client problem, not a server performance problem. It …

---

## [Preferred proxy for fleet](https://discuss.elastic.co/t/preferred-proxy-for-fleet/341884)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:55pm UTC](https://discuss.elastic.co/t/preferred-proxy-for-fleet/341884 "2023-08-29T13:55:13Z")

</div>

Is there a preferred proxy software recommended for fleet setup on elasticsearch 8.9 self hosted setup. I am dicey between squid and nginx.

---

## [No\_shard\_available\_action\_exception](https://discuss.elastic.co/t/no-shard-available-action-exception/341883)

<div class="topic-metadata">

**Author:** [@Nibort](https://discuss.elastic.co/u/Nibort)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:25pm UTC](https://discuss.elastic.co/t/no-shard-available-action-exception/341883 "2023-08-29T13:25:32Z")

</div>

Hello, I'm trying to send rsyslog with filebeat to my Elasticsearch cluster I've added the global path where logs are stored (/var/log/\*.log) filebeat.yml filebeat.inputs: - type: log id: rsyslog paths: - /va…

---

## [Querying on large docs](https://discuss.elastic.co/t/querying-on-large-docs/341759)

<div class="topic-metadata">

**Author:** [@m4kkur0](https://discuss.elastic.co/u/m4kkur0)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 12:53pm UTC](https://discuss.elastic.co/t/querying-on-large-docs/341759 "2023-08-29T12:53:15Z")

</div>

Hello all, I would like to know what are some good options to query an index that each doc in it structured like: field1, keyword field2, long field3, object, enabled: false (mostly below 1 mb but sometimes goes up t…

---

## [How to get in C# client not-null response even for failed search requests?](https://discuss.elastic.co/t/how-to-get-in-c-client-not-null-response-even-for-failed-search-requests/341358)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 7:15am UTC](https://discuss.elastic.co/t/how-to-get-in-c-client-not-null-response-even-for-failed-search-requests/341358 "2023-08-29T07:15:17Z")

</div>

Hi there! There is C# code that generates searches through code like that: searchResult = client.Search(descriptor); The request generated contains inappropriate data, and therefore I get Elasticsearch.Net.Elasticsea…

---

## [Remove 7.x indices after upgrade to 8.x](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 6:34am UTC](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000 "2023-08-29T06:34:57Z")

</div>

Hi I was wondering if we could remove the old 7.x indices from our Elastic Stack, since we upgraded to 8.x? E.g. Kibana: Remark: I found out about the allow\_restricted\_indices setting, which would probably allow me…

---

## [How to store/compress large string field in index (V6.8)](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777)

<div class="topic-metadata">

**Author:** [@elron](https://discuss.elastic.co/u/elron)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 6:08am UTC](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777 "2023-08-29T06:08:04Z")

</div>

We are planning to store in the index a large string(error log) with a classifier for future use in a machine learning project. The error log can get to the size of tens of megabytes and we are planning to store tens of …

---

## [Data getting SWAPPED in Elasticsearch with pipeline](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 5:33am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796 "2023-08-29T05:33:36Z")

</div>

Hello Team We are using Elasticsearch version 7.8.0 We are having Index with Pipeline Defined .. Our Problem is data is getting SWAPPED between two fields of Elasticsearch. Data of "OBJ\_NAM\_FILDT" is getting posted i…

---

## [Need confirmation for few Elasticsearch queries](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 5:15am UTC](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849 "2023-08-29T05:15:30Z")

</div>

Hi Team, Can you please confirm below query comes under SQL query or DSL query ? curl -X POST "https://localhost:9200/\_sql?format=txt&pretty" -H 'Content-Type: application/json' -d' { "query": "SELECT \* FROM custo…

---

## [Elasticsearch snapshot google.cloud.storage.StorageException](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 4:45am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848 "2023-08-29T04:45:52Z")

</div>

Elastic GCS bucket snapshot failed and we cannot able to retrive the old inremental backup in that bucket, Is there any possibility to recover the back FYI, we can able to view the data storage inside that bucket in th…

---

## [Term negation and fuzziness](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 9:47pm UTC](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645 "2023-08-28T21:47:49Z")

</div>

The use case is a search engine over text documents for the general public. We were previously using a simple match query, but recently switched to simple\_query\_string in order to easily support phrase matching. I'm fi…

---

## [Is it safe to delete logs-deprecation indices, where can we disable creation of these indices?](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 9:34pm UTC](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714 "2023-08-28T21:34:44Z")

</div>

We have some system indices generated by ES, can we turn off generation of these indices and is it safe to delete them? health status index green open .ds-ilm-history-5-2023.06.02-000012 green open .ds-.logs-dep…

---

## [Investigate high GC time when indexing](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 17\
**Last updated:** [August 28, 2023, 7:42pm UTC](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154 "2023-08-28T19:42:54Z")

</div>

Hello, I am looking for some advice as to why we are seeing a high GC time on our Elasticsearch cluster. On average, we see 5 - 8% of GC time across all the nodes. This is the setup we have: 150 data nodes 1000 primar…

---

## [Retrieving millions of large documents](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803)

<div class="topic-metadata">

**Author:** [@Tomer\_Avira](https://discuss.elastic.co/u/Tomer_Avira)\
**Replies:** 6\
**Last updated:** [August 28, 2023, 6:06pm UTC](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803 "2023-08-28T18:06:58Z")

</div>

Hello everyone, first time i am requesting your help. I am working with elastic version 8.5.3 with java client 7.17.1, let me represent you with the problem I'm having. I have daily indices with the largest of them hol…

---

## [How do parse log format apache access](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790 "2023-08-28T15:19:04Z")

</div>

Good afternoon I have a log with the format of the apache access log service (access\_log) 10.0.xx.xx - - \[28/Aug/2023:15:25:18 +0700\] "GET /xxx/en/neoclassic/cases/main HTTP/1.0" 200 2007 133793 "-" "Mozilla/5.0 (Wind…

---

## [Varying data types in object causing mapping errors](https://discuss.elastic.co/t/varying-data-types-in-object-causing-mapping-errors/341717)

<div class="topic-metadata">

**Author:** [@Wesley84](https://discuss.elastic.co/u/Wesley84)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 2:39pm UTC](https://discuss.elastic.co/t/varying-data-types-in-object-causing-mapping-errors/341717 "2023-08-28T14:39:28Z")

</div>

I have a data object called "weekly\_values" that I want to send to an existing elastic index. This object contains fields which when populated have a float data type. However these fields do not always have a value and w…

---

## [Elastic master node down, how to make slave new master?](https://discuss.elastic.co/t/elastic-master-node-down-how-to-make-slave-new-master/341568)

<div class="topic-metadata">

**Author:** [@webfr](https://discuss.elastic.co/u/webfr)\
**Replies:** 7\
**Last updated:** [August 28, 2023, 2:32pm UTC](https://discuss.elastic.co/t/elastic-master-node-down-how-to-make-slave-new-master/341568 "2023-08-28T14:32:26Z")

</div>

Hello, my master node is currently down since few days, how to make my slave new master if problem on master persists? Thanks.

---

## [Migrate elasticsearch data from 7.17 to 8.6.2 server](https://discuss.elastic.co/t/migrate-elasticsearch-data-from-7-17-to-8-6-2-server/341807)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/migrate-elasticsearch-data-from-7-17-to-8-6-2-server/341807 "2023-08-28T14:00:19Z")

</div>

We are running elasticsearch on a single node. We are in the process of upgrading our Elasticsearch server from 7.17 to 8.6.2 and we want to migrate elasticsearch data from 7.17 to 8.6.2 version. What is the best appro…

---

## [Rust - How to use PIT?](https://discuss.elastic.co/t/rust-how-to-use-pit/341809)

<div class="topic-metadata">

**Author:** [@Frederick\_Sauvage](https://discuss.elastic.co/u/Frederick_Sauvage)\
**Replies:** 0\
**Last updated:** [August 28, 2023, 1:35pm UTC](https://discuss.elastic.co/t/rust-how-to-use-pit/341809 "2023-08-28T13:35:28Z")

</div>

Hi, I'm trying to add PIT in but I don't find how to do. My code is similar as : let client = Elasticsearch::default(); let s = client.search(SearchParts::None).size(1000).timeout("120s"); let search = Search::new().…

---

## [Setup Elasticsearch cluster mode](https://discuss.elastic.co/t/setup-elasticsearch-cluster-mode/341228)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 13\
**Last updated:** [August 28, 2023, 1:16pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-cluster-mode/341228 "2023-08-28T13:16:58Z")

</div>

I want to setup cluster mode between 2 linux servers One of them will be master and data node and other one will only be a data node. Whenever i try to setup any external IP/interfaces to transport.host, elasticsearch …

---

## [New python client (8.x) for sql query](https://discuss.elastic.co/t/new-python-client-8-x-for-sql-query/340083)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 28, 2023, 12:52pm UTC](https://discuss.elastic.co/t/new-python-client-8-x-for-sql-query/340083 "2023-08-28T12:52:50Z")

</div>

I am using sql query in my old python client 7.x and it works like this data = es.sql.query(body={"query": sql\_query1, "fetch\_size": 30000}) now using new client 8.x it give me this warning DeprecationWarning: The 'b…

---

## [Aggregating In Elastic Search](https://discuss.elastic.co/t/aggregating-in-elastic-search/341762)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 11:45pm UTC](https://discuss.elastic.co/t/aggregating-in-elastic-search/341762 "2023-08-27T23:45:36Z")

</div>

Hi @leandrojmp , I have a below requirement, where I need to perform aggregation based on certain fields of Elasticsearch. Documents indexed are as below PUT rollup-index/\_doc/1 { "environment" : "preview", "person…

---

## [Slicing without point in time](https://discuss.elastic.co/t/slicing-without-point-in-time/341765)

<div class="topic-metadata">

**Author:** [@kmcclellan](https://discuss.elastic.co/u/kmcclellan)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 10:04pm UTC](https://discuss.elastic.co/t/slicing-without-point-in-time/341765 "2023-08-27T22:04:13Z")

</div>

When you specify "slices" for a search request, you will receive an error if the search is not a point-in-time or scrolled query: "\[slice\] can only be used with \[scroll\] or \[point-in-time\] requests". I don't quite under…

---

## [Why Elastic Search allow to put number in text field?](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 3:04pm UTC](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756 "2023-08-27T15:04:54Z")

</div>

Hi, I have mapping like this: "mappings": { "dynamic": "strict", "properties": { "name": { "typ…

---

## [Is it possible to search only when there are a certain number of terms in the query?](https://discuss.elastic.co/t/is-it-possible-to-search-only-when-there-are-a-certain-number-of-terms-in-the-query/341420)

<div class="topic-metadata">

**Author:** [@gony](https://discuss.elastic.co/u/gony)\
**Replies:** 2\
**Last updated:** [August 27, 2023, 11:05am UTC](https://discuss.elastic.co/t/is-it-possible-to-search-only-when-there-are-a-certain-number-of-terms-in-the-query/341420 "2023-08-27T11:05:01Z")

</div>

When using a match query, is it possible to search only when there are a certain number of terms in the query? I need that functionality, not for the entire query, but as part of a subquery that I will put inside a bool…

---

## [Install Curator 7.0.0 in rhel](https://discuss.elastic.co/t/install-curator-7-0-0-in-rhel/341223)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 5\
**Last updated:** [August 27, 2023, 8:12am UTC](https://discuss.elastic.co/t/install-curator-7-0-0-in-rhel/341223 "2023-08-27T08:12:51Z")

</div>

As per official doc https://www.elastic.co/guide/en/elasticsearch/client/curator/7.0/pip.html Current system - RHEL 8 Elasticsearch - 7.17.3 I am trying to install curator in linux machine and i have install python3 …

---

## [After update , changes order list](https://discuss.elastic.co/t/after-update-changes-order-list/341751)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 5:01pm UTC](https://discuss.elastic.co/t/after-update-changes-order-list/341751 "2023-08-26T17:01:23Z")

</div>

hello , I have a crud . that I list products , in admin area . I change the price of a product , in a CRUD . after , I give a refresh on the page . and it changed the order that is searching this product . does have …

---

## [Empty indexes in Kibana](https://discuss.elastic.co/t/empty-indexes-in-kibana/341745)

<div class="topic-metadata">

**Author:** [@anshtyagi14](https://discuss.elastic.co/u/anshtyagi14)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 12:43pm UTC](https://discuss.elastic.co/t/empty-indexes-in-kibana/341745 "2023-08-26T12:43:40Z")

</div>

I am trying to visualise system logs in kibana, for the process i am using 3's AWS Amazon Linux 2023 EC2 instance in the following way Instance 01 - Filebeat Instance 02 - Logstash Instance 03 - Elasticsearch, Kibana …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=207)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=209)
