# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=212

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 213

---

## [Null value in field type with nested](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 4:18pm UTC](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278 "2023-08-21T16:18:24Z")

</div>

I have a filed , that if has value , it has ID and TITLE . so , wold be like this - category: { id: 2, title: 'monitor' } but can be like this as well category: NULL So I did like this the mapping - "category":…

---

## [Should I disable scroll time if I don't explicitly use scroll in any search or index operation?](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158)

<div class="topic-metadata">

**Author:** [@arifd](https://discuss.elastic.co/u/arifd)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 2:39pm UTC](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158 "2023-08-21T14:39:40Z")

</div>

Hello! So I am not (as far as I am aware) using the Scroll API, and yet I was able to get the "Trying to create too many scroll contexts. Must be less than or equal to: \[500\]" error. From searching around, I am under t…

---

## [Two custom analyzers with the same synonym filter - why no match](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:17pm UTC](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264 "2023-08-21T14:17:23Z")

</div>

I have index with two fields. Each field uses different custom analyzer. Each of those analyzers use the same synonym filter. When querying with bool + should + match on both fields, it matches no document. I dont under…

---

## [High Index Count impacting Elasticsearch Performance](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259)

<div class="topic-metadata">

**Author:** [@Nitish\_Goyal](https://discuss.elastic.co/u/Nitish_Goyal)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:07pm UTC](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259 "2023-08-21T14:07:43Z")

</div>

Problem Statement : Decrease in cluster throughput as we increase the number of indices in the cluster Cluster Set up Nodes = 8 Cores per node = 18 Memory = 90 GB Heap = 28 GB Version = 8.9.0 We are seeing decrease…

---

## [Elaticsearch SQL CLI is not working](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/341258)

<div class="topic-metadata">

**Author:** [@SivaPrasadELK](https://discuss.elastic.co/u/SivaPrasadELK)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:02pm UTC](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/341258 "2023-08-21T14:02:32Z")

</div>

Hi team, I am not able to run the SQL commands in SQL CLI tool. Any pointers how to use it or any supporting docs to refer. i am getting different kind of error messages when trying to run the queries in SQL CLI . "er…

---

## [Render Json strings from Elastic API client objects](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 1:59pm UTC](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238 "2023-08-21T13:59:53Z")

</div>

Hi, I am using the Elasticsearch API client (8.9) for java and wondering how to render those Queries and Responses as json strings. For example I can do a simple query like so: val query = Query.of { q -\> q.matchAll {…

---

## [Update-by-query: No mapping found for \[id\] in order to sort on](https://discuss.elastic.co/t/update-by-query-no-mapping-found-for-id-in-order-to-sort-on/339671)

<div class="topic-metadata">

**Author:** [@davysteegen](https://discuss.elastic.co/u/davysteegen)\
**Replies:** 6\
**Last updated:** [August 21, 2023, 1:34pm UTC](https://discuss.elastic.co/t/update-by-query-no-mapping-found-for-id-in-order-to-sort-on/339671 "2023-08-21T13:34:27Z")

</div>

Hi, We are in the process of migrating from Elasticsearch 2.3 to 8.6. One thing I noticed is that the sorting in the update-by-query API now only allows to provide a comma separated list of field/sort direction combos. …

---

## [Spring + elastic 8.9.0 How to create index template](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033)

<div class="topic-metadata">

**Author:** [@Prasanth\_Gutlapalli](https://discuss.elastic.co/u/Prasanth_Gutlapalli)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 1:09pm UTC](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033 "2023-08-21T13:09:26Z")

</div>

How to create index template give java example

---

## [Best way to load an elastic query and manipulate it](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 12:10pm UTC](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099 "2023-08-21T12:10:06Z")

</div>

Hi, I am using the Elasticsearch Java client and what I basically want to achieve is the following: Our backend is basically a ES Proxy, so there is an endpoint that takes an ES query as input, adds a clause (to scope t…

---

## [Large indice, a lot of IO read](https://discuss.elastic.co/t/large-indice-a-lot-of-io-read/341211)

<div class="topic-metadata">

**Author:** [@pdgaaa](https://discuss.elastic.co/u/pdgaaa)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/large-indice-a-lot-of-io-read/341211 "2023-08-21T08:17:35Z")

</div>

Hi ! Having an elastic cluster with 3 nodes under docker. 2 data nodes (indices with replica 1 and only 1 shard) and one node for the master eligibilty. ES 7.17.x 8 GB RAM / data node, 6 GB for docker, 3 GB XMX for ES.…

---

## [What is Query delay and bucket span](https://discuss.elastic.co/t/what-is-query-delay-and-bucket-span/340886)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:26am UTC](https://discuss.elastic.co/t/what-is-query-delay-and-bucket-span/340886 "2023-08-21T07:26:21Z")

</div>

Hi Team We are running two jobs of anomaly detection where for one job we are using 10 min of bucket span and for second one we are using 1 hour bucket span. Query delay is same for both jobs i.e. default value. For bo…

---

## [Logtash url is not working](https://discuss.elastic.co/t/logtash-url-is-not-working/341176)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 7:20am UTC](https://discuss.elastic.co/t/logtash-url-is-not-working/341176 "2023-08-21T07:20:59Z")

</div>

Error: Address already in use: bind Exception: Java::JavaNet::BindException Stack: sun.nio.ch.Net.bind0(Native Method) sun.nio.ch.Net.bind(sun/nio/ch/Net.java:555) sun.nio.ch.ServerSocketChannelImpl.netBind(sun/nio/c…

---

## [Transforms from first principles](https://discuss.elastic.co/t/transforms-from-first-principles/340706)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 3:36am UTC](https://discuss.elastic.co/t/transforms-from-first-principles/340706 "2023-08-21T03:36:36Z")

</div>

Hi, I've got an 8.8.1 cluster which is functioning well and ingesting data into a hot/warm architecture. I have a number of users with some pretty heavy dashboards and, to lighten the load on the cluster, I thought it …

---

## [Need to remove the scientific notation on sum Aggregation](https://discuss.elastic.co/t/need-to-remove-the-scientific-notation-on-sum-aggregation/341193)

<div class="topic-metadata">

**Author:** [@Sakthi1](https://discuss.elastic.co/u/Sakthi1)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 1:16am UTC](https://discuss.elastic.co/t/need-to-remove-the-scientific-notation-on-sum-aggregation/341193 "2023-08-21T01:16:40Z")

</div>

My Index Mapping: "total"{ "type": :"double" "ignore\_malformaed": "true" } when i perform sum on this field i am getting the scientific notation. Query i triggered: POST /\_sql { "query": "select sum(total) from "…

---

## [Access a field's value in elastic search without indexing](https://discuss.elastic.co/t/access-a-fields-value-in-elastic-search-without-indexing/341150)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 3\
**Last updated:** [August 20, 2023, 1:26pm UTC](https://discuss.elastic.co/t/access-a-fields-value-in-elastic-search-without-indexing/341150 "2023-08-20T13:26:25Z")

</div>

Hi, I have a requirement to form a script query from java code where it has to formulate the final score after getting the elastic score plus referring a variable on the runtime. document is indexed like below { "ran…

---

## [Aggregation Path](https://discuss.elastic.co/t/aggregation-path/341172)

<div class="topic-metadata">

**Author:** [@noman13bd](https://discuss.elastic.co/u/noman13bd)\
**Replies:** 0\
**Last updated:** [August 20, 2023, 6:05am UTC](https://discuss.elastic.co/t/aggregation-path/341172 "2023-08-20T06:05:05Z")

</div>

I want to use global number of total docs in bucket script. But getting the error No aggregation found for path \[global\_total\_docs\>total\_docs\] can you please help me to identify the right aggregation path? GET bl\_log\_d…

---

## [Elasticsearch Keystore not being created](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 11\
**Last updated:** [August 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120 "2023-08-20T04:30:08Z")

</div>

Hi there, So, I am trying to run a simple ES single-node cluster. Here is the Dockerfile:- FROM elasticsearch:8.7.0 COPY . . #this copies the start\_es.sh ENTRYPOINT \["./start\_es.sh"\] The start\_es.sh contains noth…

---

## [Im having a firewall pushing logs towards a linux destination server with middle contains linux machine having logstash server](https://discuss.elastic.co/t/im-having-a-firewall-pushing-logs-towards-a-linux-destination-server-with-middle-contains-linux-machine-having-logstash-server/340511)

<div class="topic-metadata">

**Author:** [@sudharsanam132](https://discuss.elastic.co/u/sudharsanam132)\
**Replies:** 4\
**Last updated:** [August 19, 2023, 9:38am UTC](https://discuss.elastic.co/t/im-having-a-firewall-pushing-logs-towards-a-linux-destination-server-with-middle-contains-linux-machine-having-logstash-server/340511 "2023-08-19T09:38:35Z")

</div>

So firewall pushing logs towards logstash server in logstash i have mentioned in the output plugin to the destination server i need to filter my logs if for example:192.168.1.143 contains the ip in the message i need to …

---

## [Elasticsearch.service failed after restart](https://discuss.elastic.co/t/elasticsearch-service-failed-after-restart/341056)

<div class="topic-metadata">

**Author:** [@dirtdart666](https://discuss.elastic.co/u/dirtdart666)\
**Replies:** 2\
**Last updated:** [August 19, 2023, 3:01am UTC](https://discuss.elastic.co/t/elasticsearch-service-failed-after-restart/341056 "2023-08-19T03:01:55Z")

</div>

Hi everyone, I am attempitng to install Elasticsearch on an Ubuntu server 22.04. LTS VM but I am running into a few issues. After configuring /etc/elasticsearch/elasticsearch.yml saving and then running sudo systemctl …

---

## [Disabling shard allocation not working as expected](https://discuss.elastic.co/t/disabling-shard-allocation-not-working-as-expected/341135)

<div class="topic-metadata">

**Author:** [@Brent\_Plummer](https://discuss.elastic.co/u/Brent_Plummer)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 11:20pm UTC](https://discuss.elastic.co/t/disabling-shard-allocation-not-working-as-expected/341135 "2023-08-18T23:20:15Z")

</div>

One of my 6 Elasticsearch clusters at work is not respecting when i try to disable shard allocation prior to pull a node/server from the cluster. When I run the curl command below I get the "true" response you would exp…

---

## [ELK status Yellow to green](https://discuss.elastic.co/t/elk-status-yellow-to-green/341064)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 7:47pm UTC](https://discuss.elastic.co/t/elk-status-yellow-to-green/341064 "2023-08-18T19:47:02Z")

</div>

ELK index is yellow . I want to change yellow to green . { "ace\_logs": { "settings": { "index": { "routing": { "allocation": { "include": { "\_tier\_preference": "data\_content" } } }, "number\_of\_shards": "1", …

---

## [Kibana clock time different from Elasticsearch?](https://discuss.elastic.co/t/kibana-clock-time-different-from-elasticsearch/340960)

<div class="topic-metadata">

**Author:** [@Hannah\_Zhang](https://discuss.elastic.co/u/Hannah_Zhang)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 6:42pm UTC](https://discuss.elastic.co/t/kibana-clock-time-different-from-elasticsearch/340960 "2023-08-18T18:42:51Z")

</div>

It seems the Kibana clock time setting is different from Elasticsearch, so when I posted index into Elasticsearch, I can see that immediately from Elasticsearch, but can't see it with Kibana "Discover" if I set time inte…

---

## [Big index design](https://discuss.elastic.co/t/big-index-design/341118)

<div class="topic-metadata">

**Author:** [@maradev](https://discuss.elastic.co/u/maradev)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 5:19pm UTC](https://discuss.elastic.co/t/big-index-design/341118 "2023-08-18T17:19:59Z")

</div>

Hi, I'm working od designing and implementing search for my project, I'm not so experienced with Elastic and I'm afraid that I'll made wrong design decisions. Could you please share your thoughts about it? I have follow…

---

## [Activated Warm Tier Not Able To Shut it Down](https://discuss.elastic.co/t/activated-warm-tier-not-able-to-shut-it-down/341102)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/activated-warm-tier-not-able-to-shut-it-down/341102 "2023-08-18T14:14:12Z")

</div>

Hi, I decided to experiment with the warm data tier instance in ES. It seems to have moved data on to this tier (to be expected). But now I can't remove this instance. From what I've seen, this is a solution: But it …

---

## [ILM action failed “check-rollover-ready,Moving to ERROR step”?](https://discuss.elastic.co/t/ilm-action-failed-check-rollover-ready-moving-to-error-step/340922)

<div class="topic-metadata">

**Author:** [@njain213](https://discuss.elastic.co/u/njain213)\
**Replies:** 5\
**Last updated:** [August 18, 2023, 1:43pm UTC](https://discuss.elastic.co/t/ilm-action-failed-check-rollover-ready-moving-to-error-step/340922 "2023-08-18T13:43:40Z")

</div>

Hello Team, I am using ELK stack version 7.9.3 and sometimes I use to get below error when randomly ILM policy stops working and no new index with new date is created and data is getting piled in previous date index. Wh…

---

## ["error": "no handler found for uri \[/\_security/role/kib\] and method \[POST\]"](https://discuss.elastic.co/t/error-no-handler-found-for-uri-security-role-kib-and-method-post/341085)

<div class="topic-metadata">

**Author:** [@Ramon\_Moraga\_Fernand](https://discuss.elastic.co/u/Ramon_Moraga_Fernand)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 11:03am UTC](https://discuss.elastic.co/t/error-no-handler-found-for-uri-security-role-kib-and-method-post/341085 "2023-08-18T11:03:32Z")

</div>

I have this elasticsearch.yml configuration(cluster.name: elasticsearch\_cluster discovery.seed\_hosts: \["elasticsearch"\] discovery.type: single-node bootstrap.memory\_lock: true http.host: 0.0.0.0 transport.host: 0.0.…

---

## [Trying to create templte from index](https://discuss.elastic.co/t/trying-to-create-templte-from-index/341086)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 10:31am UTC](https://discuss.elastic.co/t/trying-to-create-templte-from-index/341086 "2023-08-18T10:31:19Z")

</div>

I'm trying to create a template through Kibana from an already imported index, so I can reimport them, and apply the template to them (and also apply a lifecycle policy). The index mappings looks like this: { "mappin…

---

## [Unable to start Elasticsearch 8.8.2 even after disabling xpack](https://discuss.elastic.co/t/unable-to-start-elasticsearch-8-8-2-even-after-disabling-xpack/341080)

<div class="topic-metadata">

**Author:** [@Abhishek\_Mantripraga](https://discuss.elastic.co/u/Abhishek_Mantripraga)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 7:31am UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-8-8-2-even-after-disabling-xpack/341080 "2023-08-18T07:31:32Z")

</div>

\[2023-08-18T08:03:06,110\]\[WARN \]\[c.a.a.p.i.BasicProfileConfigFileLoader\] \[\] Unable to load config file null java.security.AccessControlException: access denied ("java.io.FilePermission" "/nonexistent/.aws/config" "read")…

---

## [Kibana Lucene query string does not match the result](https://discuss.elastic.co/t/kibana-lucene-query-string-does-not-match-the-result/340703)

<div class="topic-metadata">

**Author:** [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 6:17am UTC](https://discuss.elastic.co/t/kibana-lucene-query-string-does-not-match-the-result/340703 "2023-08-18T06:17:35Z")

</div>

Kibana Lucene query string: host:\*AGC\* AND NOT host:\*LGAGC\* AND NOT host:\*AP\* AND message:"\\:ORA\\-" AND NOT message:"ReconnectableOraErrCodes" However, the query result not 100% match, such the pattern below in documen…

---

## [Remote cluster node query](https://discuss.elastic.co/t/remote-cluster-node-query/341033)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 6\
**Last updated:** [August 18, 2023, 5:18am UTC](https://discuss.elastic.co/t/remote-cluster-node-query/341033 "2023-08-18T05:18:41Z")

</div>

We have an existing elasticsearch stack running basic license, is it possible to add more nodes to the cluster which do not hold any data and only pass data from a location to existing data / master nodes with basic lice…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=211)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=213)
