# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=220

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 221

---

## [Aggregate latest values of documents](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868)

<div class="topic-metadata">

**Author:** [@MrFuxi](https://discuss.elastic.co/u/MrFuxi)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 10:40pm UTC](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868 "2023-08-01T22:40:42Z")

</div>

I have items that over the time can go from one category to the other. Each change results in a new document with current state of the item. I'm tying to get run basic analytics based on the latest state of the item li…

---

## [How to create a field that filters the data](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 9:01pm UTC](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861 "2023-08-01T21:01:50Z")

</div>

I have a "message" field contains bulk of data(like customerName,number,address) in logstash, Now I want to create a new field that filter the data contains only word "Incoming Message:" I'm using ELK 8.6.0 I am tryin…

---

## [How to use runtime mapping on field that is nested](https://discuss.elastic.co/t/how-to-use-runtime-mapping-on-field-that-is-nested/339853)

<div class="topic-metadata">

**Author:** [@jlucas](https://discuss.elastic.co/u/jlucas)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-use-runtime-mapping-on-field-that-is-nested/339853 "2023-08-01T19:57:18Z")

</div>

Lets say I have the following document on some index. { "\_source" : { "process1": { "part1": { "start": "2022-10-04T18:35:01.540Z", "end": "2022-10-04T18:35:01.540Z" }, "part2": {…

---

## [KEYSTORE\_PASSWORD\_FILE](https://discuss.elastic.co/t/keystore-password-file/339627)

<div class="topic-metadata">

**Author:** [@toughcoding](https://discuss.elastic.co/u/toughcoding)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 7:27pm UTC](https://discuss.elastic.co/t/keystore-password-file/339627 "2023-08-01T19:27:39Z")

</div>

Running Elasticsearch as docker container with --env KEYSTORE\_PASSWORD\_FILE=/run/secrets/keystore\_password does not setup password for elasticsearch keystore. Although I am successfull with Elasticsearch password itse…

---

## [Indices.fielddata.cache.size will be allocated within heap or outside heap?](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 6:54pm UTC](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846 "2023-08-01T18:54:49Z")

</div>

Hi Team, Q1). indices.fielddata.cache.size is set as 10% of heap by default. Does it mean it will consider 10% of heap lets say 1.2GB and it will allocate within heap or will it go outside of heap and take from overall …

---

## [Can I update ES mappings to exclude copy\_to?](https://discuss.elastic.co/t/can-i-update-es-mappings-to-exclude-copy-to/339834)

<div class="topic-metadata">

**Author:** [@Vlado](https://discuss.elastic.co/u/Vlado)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:34pm UTC](https://discuss.elastic.co/t/can-i-update-es-mappings-to-exclude-copy-to/339834 "2023-08-01T18:34:48Z")

</div>

Hi, What are ES back-compat rules around directives? Say, I have a copy\_to mapping on several fields with data already indexed and wanted to remove the "copy\_to" directive on some of those. Is this allowed? Or is it an…

---

## [Separate ELK pattern for log files](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [August 1, 2023, 6:14pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817 "2023-08-01T18:14:09Z")

</div>

Hi team, Can any one help me to find the solution for my below requirement. I have two apache server and I want to send the apache access and error logs to elk server via filebeat apache module to logstash. I configure…

---

## [Filebeat timestamp not working](https://discuss.elastic.co/t/filebeat-timestamp-not-working/339827)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:05pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-not-working/339827 "2023-08-01T18:05:53Z")

</div>

Hi all. I'm trying to tell Filebeat to use my timestamp, rather than creating one. I'm getting this error: "error": "failed parsing time field \_app.ACTUAL\_TIME='2023-08-01T11:49:09.386Z'", "errorCauses": \[{"error": "f…

---

## [Retrieving stored fields using java client](https://discuss.elastic.co/t/retrieving-stored-fields-using-java-client/339812)

<div class="topic-metadata">

**Author:** [@Jagadeesh12](https://discuss.elastic.co/u/Jagadeesh12)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 5:37pm UTC](https://discuss.elastic.co/t/retrieving-stored-fields-using-java-client/339812 "2023-08-01T17:37:21Z")

</div>

Hi, I am facing issues while retrieving stored fields from Elasticsearch using java client. creating template: PUT \_index\_template/test\_tf\_template { "index\_patterns": \["test-tf-\*"\], "template": { "mappings":…

---

## [Is new Geometry simplifier (ES 8.9.0) available for direct use?](https://discuss.elastic.co/t/is-new-geometry-simplifier-es-8-9-0-available-for-direct-use/339832)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/is-new-geometry-simplifier-es-8-9-0-available-for-direct-use/339832 "2023-08-01T16:33:47Z")

</div>

Hello ES friends, Is the new Geometry simplifier in ES version 8.9.0. available for direct use or is it only an internally callable feature ? From What's new document, it seems to me that it can be used merely for int…

---

## [Naming convention for ingest pipelines etc](https://discuss.elastic.co/t/naming-convention-for-ingest-pipelines-etc/339480)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 6\
**Last updated:** [August 1, 2023, 3:32pm UTC](https://discuss.elastic.co/t/naming-convention-for-ingest-pipelines-etc/339480 "2023-08-01T15:32:59Z")

</div>

Elastic-Provided Naming Convention :question: Is there a naming convention for ingest pipelines, index templates, component templates, or any other such configuration objects? I see in the docs \[1,2,3,4\] there are examp…

---

## [Elasticsearch for Data Science](https://discuss.elastic.co/t/elasticsearch-for-data-science/339818)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 3:02pm UTC](https://discuss.elastic.co/t/elasticsearch-for-data-science/339818 "2023-08-01T15:02:14Z")

</div>

Hi, Some context. I'm using Elasticsearch and filebeat to store documents. I have 6 fields. One field represents the timestamp and the other 5 are keywords. Two fields correspond to IDs (id\_1 and id\_2). The IDs have man…

---

## [Combine data older then x days](https://discuss.elastic.co/t/combine-data-older-then-x-days/339804)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 1:53pm UTC](https://discuss.elastic.co/t/combine-data-older-then-x-days/339804 "2023-08-01T13:53:18Z")

</div>

Hi, I want to combine network data (based on scr/dst/port) to an aggregated index after 20 days. This to decrease the disk usage of this indices but still have the combined data available for specific searches. I'm che…

---

## [Setup a elastic cluster](https://discuss.elastic.co/t/setup-a-elastic-cluster/339741)

<div class="topic-metadata">

**Author:** [@psanggabuana](https://discuss.elastic.co/u/psanggabuana)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 12:50pm UTC](https://discuss.elastic.co/t/setup-a-elastic-cluster/339741 "2023-08-01T12:50:09Z")

</div>

Hi everyone, I want to set up my cluster with the right server requirement. My cluster consists of: Master Data Coordinating Transform Ingest Can anyone share with me how much CPU, RAM, and storage for each server? …

---

## [Dont work preference in es version 6](https://discuss.elastic.co/t/dont-work-preference-in-es-version-6/339756)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 12:22pm UTC](https://discuss.elastic.co/t/dont-work-preference-in-es-version-6/339756 "2023-08-01T12:22:44Z")

</div>

I know that the preference custome string is a function that allows you to search with the same shard, but every time you search, a different shard is searched, so the search results of search after are strange. What sh…

---

## [URGENT: Handshake failed. unexpected remote node](https://discuss.elastic.co/t/urgent-handshake-failed-unexpected-remote-node/339796)

<div class="topic-metadata">

**Author:** [@Piyush\_Goyal1](https://discuss.elastic.co/u/Piyush_Goyal1)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 12:05pm UTC](https://discuss.elastic.co/t/urgent-handshake-failed-unexpected-remote-node/339796 "2023-08-01T12:05:00Z")

</div>

Version: 8.5.0 The cluster has 3 nodes: node-001 (master) node-002 (data) node-003 (data) The master node VM crashed and upon restarting the master node, the data nodes are not getting discovered. The cluster was ru…

---

## [Rack Awarness and Node Aware](https://discuss.elastic.co/t/rack-awarness-and-node-aware/339786)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 11:00am UTC](https://discuss.elastic.co/t/rack-awarness-and-node-aware/339786 "2023-08-01T11:00:23Z")

</div>

I'm in 7.17.7 ES. I have 6BareMetal(BM), each BM will have 4VirtualMachines(VM), each VM's having ES service running and all 5BM are in 3 Physical Racks. Reason: I dont want Primary and Replica to reside on same BM as …

---

## [Lens formula conditionals](https://discuss.elastic.co/t/lens-formula-conditionals/339784)

<div class="topic-metadata">

**Author:** [@davidleongz](https://discuss.elastic.co/u/davidleongz)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 10:36am UTC](https://discuss.elastic.co/t/lens-formula-conditionals/339784 "2023-08-01T10:36:16Z")

</div>

I want to use conditional on Lens Formula but I have this message "Operations if, eq not found" I'm using 7.16.2 version. What do I have to do to be able to use conditionals? Is possible?

---

## [EsHadoopIllegalArgumentException: Detected type name in resource On elastic 8.8.2](https://discuss.elastic.co/t/eshadoopillegalargumentexception-detected-type-name-in-resource-on-elastic-8-8-2/339660)

<div class="topic-metadata">

**Author:** [@Joachim\_Rodrigues](https://discuss.elastic.co/u/Joachim_Rodrigues)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 9:27pm UTC](https://discuss.elastic.co/t/eshadoopillegalargumentexception-detected-type-name-in-resource-on-elastic-8-8-2/339660 "2023-07-31T21:27:19Z")

</div>

Hi I upgraded my elastic server fom 7.9.3 to 8.8.2 With my previous configuration : implementation("org.elasticsearch:elasticsearch-spark-20\_2.11:7.9.3") { exclude("org.apache.spark") } This code was …

---

## [How can I reindex TSDB enabled data stream?](https://discuss.elastic.co/t/how-can-i-reindex-tsdb-enabled-data-stream/339774)

<div class="topic-metadata">

**Author:** [@Aliabbas](https://discuss.elastic.co/u/Aliabbas)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:48am UTC](https://discuss.elastic.co/t/how-can-i-reindex-tsdb-enabled-data-stream/339774 "2023-08-01T08:48:24Z")

</div>

Hi, I am currently facing conflicts in a fields host.ip. I can resolve that by using an Reindexing API but the problem is the data stream is TSDB enabled. Any idea how can we reindex a TSDB enabled data stream? FYI I am…

---

## [Kibana console is running very slow](https://discuss.elastic.co/t/kibana-console-is-running-very-slow/339766)

<div class="topic-metadata">

**Author:** [@Vartika\_Singh](https://discuss.elastic.co/u/Vartika_Singh)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 10:10am UTC](https://discuss.elastic.co/t/kibana-console-is-running-very-slow/339766 "2023-08-01T10:10:36Z")

</div>

in kibana console sub tabs were working very slow...what is reason behind that?

---

## [Getting Null Pointer while using reloadable synonyms](https://discuss.elastic.co/t/getting-null-pointer-while-using-reloadable-synonyms/339775)

<div class="topic-metadata">

**Author:** [@Siddharth\_Gupta1](https://discuss.elastic.co/u/Siddharth_Gupta1)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 10:06am UTC](https://discuss.elastic.co/t/getting-null-pointer-while-using-reloadable-synonyms/339775 "2023-08-01T10:06:17Z")

</div>

Hi Team I am currently facing an issue while utilizing readable synonyms from a file with my completion suggestor. The problem seems to be related to the search\_analyzers in my mappings. Strangely, the completion sugges…

---

## [Standard Cloud Deployment unresponsive +12h](https://discuss.elastic.co/t/standard-cloud-deployment-unresponsive-12h/339765)

<div class="topic-metadata">

**Author:** [@Novel\_one](https://discuss.elastic.co/u/Novel_one)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:41am UTC](https://discuss.elastic.co/t/standard-cloud-deployment-unresponsive-12h/339765 "2023-08-01T09:41:12Z")

</div>

Hi, thanks for any early response, I have been running a small deployment for almost a year. Yesterday I activated sending the internal logs and metrics to the same deployment, and during the last 12h any attempt on sto…

---

## [Adding new user in role mapping](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:03am UTC](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755 "2023-08-01T09:03:06Z")

</div>

HI Team, I'm trying to add new user in my existing role mapping and when i perform the action it delete all the existing user from it and create the new user which im parsing. I need to append this in my existing role …

---

## [How to remove a user from role mapping](https://discuss.elastic.co/t/how-to-remove-a-user-from-role-mapping/339688)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-remove-a-user-from-role-mapping/339688 "2023-08-01T08:59:17Z")

</div>

HI Team, we are using ELK version 7.17.10 and we have created Roles to manage our indices. my question is if want to remove user from role mapping how do i perform by using Delete command. Looking forward your input. …

---

## [Get all fieldnames of index from](https://discuss.elastic.co/t/get-all-fieldnames-of-index-from/339769)

<div class="topic-metadata">

**Author:** [@aniket\_mandhare](https://discuss.elastic.co/u/aniket_mandhare)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:27am UTC](https://discuss.elastic.co/t/get-all-fieldnames-of-index-from/339769 "2023-08-01T08:27:39Z")

</div>

How to get all only fieldnames(key name) and not the values of it from index in Elasticsearch I tried using following request GET /my\_index/\_field\_caps?fields=\*&filter\_path=fields.\* Expected output { fields:{ "fiel…

---

## [Cluster config](https://discuss.elastic.co/t/cluster-config/339767)

<div class="topic-metadata">

**Author:** [@gagidza](https://discuss.elastic.co/u/gagidza)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:21am UTC](https://discuss.elastic.co/t/cluster-config/339767 "2023-08-01T08:21:13Z")

</div>

Hi all. Expert help needed. I have a 1 node cluster with a 7.4 TB hard drive dedicated to it. The server has 32 GB of RAM. Elastic is configured automatically and here are some of its health/stats: health: { "cluster…

---

## [Elasticsearch-java query slowly](https://discuss.elastic.co/t/elasticsearch-java-query-slowly/339382)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 12\
**Last updated:** [August 1, 2023, 8:19am UTC](https://discuss.elastic.co/t/elasticsearch-java-query-slowly/339382 "2023-08-01T08:19:58Z")

</div>

We have an es cluster, a single node, the version is 8.5.3, and then the java program is linked to do the query. The problem now is that the response speed is within 10ms when we directly curl the query on the host where…

---

## [Tuning of index segmentation](https://discuss.elastic.co/t/tuning-of-index-segmentation/339763)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:11am UTC](https://discuss.elastic.co/t/tuning-of-index-segmentation/339763 "2023-08-01T08:11:11Z")

</div>

Hi I am curious if this is recommended or if there are any tips about set parameters for segmentation. In my case the index is refreshed frequently (new data is uploaded and old data is deleted) what values or segment…

---

## [A failure occurred due to an unknown query](https://discuss.elastic.co/t/a-failure-occurred-due-to-an-unknown-query/339591)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 7:04am UTC](https://discuss.elastic.co/t/a-failure-occurred-due-to-an-unknown-query/339591 "2023-08-01T07:04:01Z")

</div>

A query was performed that didn't originate from our team, and this caused a brief breakdown. Do you know where this query originates from? The version is 6.8 and I am using elasticsearch, not opensearch. { "size":…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=219)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=221)
