# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=217

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 218

---

## [Curator 7.0](https://discuss.elastic.co/t/curator-7-0/340407)

<div class="topic-metadata">

**Author:** [@Leandro\_Nieva](https://discuss.elastic.co/u/Leandro_Nieva)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:11pm UTC](https://discuss.elastic.co/t/curator-7-0/340407 "2023-08-08T21:11:51Z")

</div>

Estoy arrancando con Curator y tengo un inconveniente, deseo realizar un snapshot de cada índice de wazuh dia a dia, el cual me esta tomando 36 indices al generar la tarea. Dejo el detalle de mi accion y de lo que realiz…

---

## [Elasticsearch Java API client 8.7.1, No Option available to generate the correct format for source ordering for composition aggregation](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-7-1-no-option-available-to-generate-the-correct-format-for-source-ordering-for-composition-aggregation/337477)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 12\
**Last updated:** [August 8, 2023, 8:39pm UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-7-1-no-option-available-to-generate-the-correct-format-for-source-ordering-for-composition-aggregation/337477 "2023-08-08T20:39:45Z")

</div>

Elasticsearch Java API client 8.7.1 does not have option to supply order for the composite term aggregation but it was available server lib. Query runs fine in KIBANA but cannot build same in Java client library {"from…

---

## [Search where inside array ( like , search where in ) inside nested](https://discuss.elastic.co/t/search-where-inside-array-like-search-where-in-inside-nested/340307)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:10pm UTC](https://discuss.elastic.co/t/search-where-inside-array-like-search-where-in-inside-nested/340307 "2023-08-08T19:10:59Z")

</div>

hello , I have a nested search . It is working like this - GET /products/\_search { "size": 100, "query": { "bool": { "must": \[ { "nested": { "path": "owner", "query": { …

---

## [XContentBuilder](https://discuss.elastic.co/t/xcontentbuilder/340399)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 7:19pm UTC](https://discuss.elastic.co/t/xcontentbuilder/340399 "2023-08-08T19:19:00Z")

</div>

With the HLRC we were able to use XContentBuilder. For example: XContentBuilder xContentBuilder = // create XContentBuilder; IndexRequest request = new IndexRequest("index").id(id).source(xContentBuilder); Basically we…

---

## [I am trying to execute bulk query using Postman but getting an Error](https://discuss.elastic.co/t/i-am-trying-to-execute-bulk-query-using-postman-but-getting-an-error/340332)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 2:33pm UTC](https://discuss.elastic.co/t/i-am-trying-to-execute-bulk-query-using-postman-but-getting-an-error/340332 "2023-08-08T14:33:05Z")

</div>

PUT /library/\_bulk?refresh {"index":{"\_id": "Leviathan Wakes"}} {"name": "Leviathan Wakes", "author": "James S.A. Corey", "release\_date": "2011-06-02", "page\_count": 561} {"index":{"\_id": "Hyperion"}} {"name": "Hyperion"…

---

## [Upgrading to a patch version resulting in replication failure?](https://discuss.elastic.co/t/upgrading-to-a-patch-version-resulting-in-replication-failure/340374)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 1:30pm UTC](https://discuss.elastic.co/t/upgrading-to-a-patch-version-resulting-in-replication-failure/340374 "2023-08-08T13:30:41Z")

</div>

Hi all, We recently tried to upgrade from 7.17.0 -\> 7.17.8 in a rolling way, but in the middle of the upgrade we found replication error. explanation" : "cannot allocate replica shard to a node with version \[7.17.0\] si…

---

## [New Java API Client GetResponse](https://discuss.elastic.co/t/new-java-api-client-getresponse/340287)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 8\
**Last updated:** [August 8, 2023, 12:35pm UTC](https://discuss.elastic.co/t/new-java-api-client-getresponse/340287 "2023-08-08T12:35:40Z")

</div>

The HLRC provided getSourceAsMap in GetResponse. I'm trying to get the source as a map. How do I do this with the new client? Thanks.

---

## [Lucene query](https://discuss.elastic.co/t/lucene-query/340367)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:18pm UTC](https://discuss.elastic.co/t/lucene-query/340367 "2023-08-08T12:18:41Z")

</div>

The following document is from the "mart-index" index in Elasticsearch. I want to use this index as a data source in Grafana 9. I want to have only "IS\_AVAILABLE" and "GPRS\_CNT" values from "DTLS\_MA" object as table colu…

---

## [See duplicate transaction with same date and time](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 10:04am UTC](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340 "2023-08-08T10:04:24Z")

</div>

See duplicate transaction with same date and time .

---

## [How the upsert script will work in elastci search](https://discuss.elastic.co/t/how-the-upsert-script-will-work-in-elastci-search/340352)

<div class="topic-metadata">

**Author:** [@Sukhdeob\_95](https://discuss.elastic.co/u/Sukhdeob_95)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-the-upsert-script-will-work-in-elastci-search/340352 "2023-08-08T09:57:57Z")

</div>

Here is my logstash config file . In the output plugin I have added upsert script it compare the ingestionHash value with old documentation ingestionHash value. If the document\_id doesn't exist (new document ie 1st ti…

---

## [Perform CRUD Operation on Elasticsearch With REST API](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 5\
**Last updated:** [August 8, 2023, 9:48am UTC](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329 "2023-08-08T09:48:37Z")

</div>

Hi Team, Could anyone share how to perform CRUD operation in Elastic search with REST API. I had tried the below one with the curl command but getting error as "curl: (52) Empty reply from server" . Could you please gui…

---

## [// "reason": "Arrays (returned by \[ss\]) are not supported"](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 9:21am UTC](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136 "2023-08-08T09:21:00Z")

</div>

Elasticsearch updated version to 8.9, using SQL function, found abnormal collection data reports. Has anyone encountered them?

---

## [ECK fleet-server-agent errors after adding "policyID: eck-fleet-server"](https://discuss.elastic.co/t/eck-fleet-server-agent-errors-after-adding-policyid-eck-fleet-server/340347)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:18am UTC](https://discuss.elastic.co/t/eck-fleet-server-agent-errors-after-adding-policyid-eck-fleet-server/340347 "2023-08-08T09:18:04Z")

</div>

Hit the following errors after adding the suggested configuration according to https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-quickstart.html: {"log.level":"error","@timestamp":"2023-08-08T…

---

## [Purge index](https://discuss.elastic.co/t/purge-index/340265)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [August 8, 2023, 9:14am UTC](https://discuss.elastic.co/t/purge-index/340265 "2023-08-08T09:14:40Z")

</div>

hello, I would like to purge my data from my indexes in elasticsearch. I'd like to know how to do this without having to delete my index. How can I achieve that?

---

## [Elasticsearch upgrade from 7.17 to 8.x](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 8:16am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338 "2023-08-08T08:16:39Z")

</div>

Hi all, We are planning to upgrade our elasticsearch cluster from 7.17.x to 8.X. Apart from general upgrade recommendations from elastic, is there a specific 8.X version that we should be upgrading to?

---

## [Error on lifecycle policy alias](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 8:09am UTC](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337 "2023-08-08T08:09:00Z")

</div>

I wasn't aware of the alias requirement on lifecycle management, so now I have a ton of data imported, on indexes with this pattern based on an index template: dmarc-7.17.4-2023.08 Where the version, year and month var…

---

## [Group by id base of sum of range of value](https://discuss.elastic.co/t/group-by-id-base-of-sum-of-range-of-value/340322)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 4\
**Last updated:** [August 8, 2023, 8:05am UTC](https://discuss.elastic.co/t/group-by-id-base-of-sum-of-range-of-value/340322 "2023-08-08T08:05:45Z")

</div>

I had some data as below: \[ { "PAY\_DATE": "2019-10-24", "STATE": "Utah", "id": "1", "SALARY": 6045, "UUID": "a879492b-b402-40bd-8f5d-afc34d66d152" }, { "PAY\_DATE": "2021-01-17", "STATE"…

---

## [Semantic search and text expansion query with self-deployed model](https://discuss.elastic.co/t/semantic-search-and-text-expansion-query-with-self-deployed-model/339708)

<div class="topic-metadata">

**Author:** [@camoneme](https://discuss.elastic.co/u/camoneme)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:17am UTC](https://discuss.elastic.co/t/semantic-search-and-text-expansion-query-with-self-deployed-model/339708 "2023-08-08T07:17:42Z")

</div>

I'm trying to use the text expansion query to implement semantic search on a rank features field. I've read the ELSER documentation and understand the process. I'm using a local/downloaded elasticsearch on docker (not co…

---

## [Regarding traffic volume in fortinat firewall logs](https://discuss.elastic.co/t/regarding-traffic-volume-in-fortinat-firewall-logs/340327)

<div class="topic-metadata">

**Author:** [@TECHY\_GEEK](https://discuss.elastic.co/u/TECHY_GEEK)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 6:48am UTC](https://discuss.elastic.co/t/regarding-traffic-volume-in-fortinat-firewall-logs/340327 "2023-08-08T06:48:28Z")

</div>

Hi! there, We are monitoring our Fortinet firewalls using Elasticsearch, Filebeat, and Kibana. But the traffic volume shown by the firewall's in-built dashboard is different from the traffic volume aggregated by Elastic…

---

## [Migration from ES V6.8 to V7.17 with an additional node](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252)

<div class="topic-metadata">

**Author:** [@Franco901](https://discuss.elastic.co/u/Franco901)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 6:47am UTC](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252 "2023-08-08T06:47:43Z")

</div>

Hi there, I have a V6.8 instance with a ~350 GB index and plan to migrate to ES V7.17. I read that ES can migrate between major versions, so my idea was to setup a new V7.17 node and let him join to the existing V6.8 n…

---

## [Is there any performance comparison between the default index codec and best\_compression?](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 3:17am UTC](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312 "2023-08-08T03:17:18Z")

</div>

Hello, I'm looking into ways to optimize the disk usage of my indices on my cluster and before go on the route to remove the \_source field I've decided to try and change the index codec to best\_compression. The documen…

---

## [What's the difference between consumption-based and resource-based pricing?](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 2:44am UTC](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308 "2023-08-08T02:44:12Z")

</div>

I see two billing models on this page and wondering: does the resource-based model mean I have to pay for ECU of kibana node even if I'm not doing analytics? does the consumption-based model mean I wouldn't need to pay…

---

## [Painless, watcher, alerts](https://discuss.elastic.co/t/painless-watcher-alerts/340305)

<div class="topic-metadata">

**Author:** [@sunny2502](https://discuss.elastic.co/u/sunny2502)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:00am UTC](https://discuss.elastic.co/t/painless-watcher-alerts/340305 "2023-08-08T00:00:46Z")

</div>

Hi I need to maintain key value pair for my output of transform block and send that to action block to send email to particular value its key. my sample code is below, my issue is in action block my payload is not getti…

---

## [Issues Moving Elasticsearch and Kibana to new server (with all existing custom indexes and dashboards)](https://discuss.elastic.co/t/issues-moving-elasticsearch-and-kibana-to-new-server-with-all-existing-custom-indexes-and-dashboards/340189)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 10\
**Last updated:** [August 7, 2023, 8:44pm UTC](https://discuss.elastic.co/t/issues-moving-elasticsearch-and-kibana-to-new-server-with-all-existing-custom-indexes-and-dashboards/340189 "2023-08-07T20:44:45Z")

</div>

Hello there, I am working on a large ec2 ubuntu instance where I manually downloaded and installed elasticsearch and kibana (I didn't use docker) . I connected my stack with external data sources and made a lot of custo…

---

## [Search for docs from last 24h on data field not timestamp](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 4:47pm UTC](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199 "2023-08-07T16:47:39Z")

</div>

Hi, in my documents i have the field report\_last\_request, in kibana i need a query that get all documents that has the report\_last\_request date from last 24h. Hope is clear. Thanks in advance.

---

## [Slow query concerns, how to optimize?](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902)

<div class="topic-metadata">

**Author:** [@chenlx594](https://discuss.elastic.co/u/chenlx594)\
**Replies:** 6\
**Last updated:** [August 7, 2023, 4:34pm UTC](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902 "2023-08-07T16:34:44Z")

</div>

Originally, there was an index a1. Now, it's modified to have index a1 with alias A, and index a2 with alias A. When querying using alias A, the query speed increases from 7ms to 60ms compared to directly querying using …

---

## [Making complete row of data table clickable (Drilldown)](https://discuss.elastic.co/t/making-complete-row-of-data-table-clickable-drilldown/340288)

<div class="topic-metadata">

**Author:** [@hughes](https://discuss.elastic.co/u/hughes)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 4:22pm UTC](https://discuss.elastic.co/t/making-complete-row-of-data-table-clickable-drilldown/340288 "2023-08-07T16:22:52Z")

</div>

This is to further expand off of this post. I have the paid version of elastic, but still am unable to execute the drilldown from clicking the table row. There are three dots on the far right side of the row that I inst…

---

## [Delete data stream and all it's index](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 7, 2023, 3:03pm UTC](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085 "2023-08-07T15:03:12Z")

</div>

I have a test data stream. it works fine. But now I am trying to delete it and I can't When I do delete via command or via GUI it recreates it self DELETE /\_data\_stream/msyos1-log I can't delete index template as wel…

---

## [Wazuh template ILM policy resets to blank post-upgrade to 4.4.4](https://discuss.elastic.co/t/wazuh-template-ilm-policy-resets-to-blank-post-upgrade-to-4-4-4/340260)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 2:39pm UTC](https://discuss.elastic.co/t/wazuh-template-ilm-policy-resets-to-blank-post-upgrade-to-4-4-4/340260 "2023-08-07T14:39:58Z")

</div>

Hi, I use Wazuh with Elastic, and recently I performed an update of wazuh to 4.4.4. Since the upgrade the ILM policy on the Wazuh template reset to null and therefore indexes didn't roll over. I thought i fixed the ind…

---

## [In MySQL to create a database we execute a query: CREATE DATABASE DEMODB, so can we create a DATABASE in Elasticsearch also?](https://discuss.elastic.co/t/in-mysql-to-create-a-database-we-execute-a-query-create-database-demodb-so-can-we-create-a-database-in-elasticsearch-also/340279)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/in-mysql-to-create-a-database-we-execute-a-query-create-database-demodb-so-can-we-create-a-database-in-elasticsearch-also/340279 "2023-08-07T13:41:58Z")

</div>

If possible, give me reference link or Command here.

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=216)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=218)
