# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=225

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 226

---

## [RFE: SQL - Add listagg aggregate function](https://discuss.elastic.co/t/rfe-sql-add-listagg-aggregate-function/339111)

<div class="topic-metadata">

**Author:** [@t603](https://discuss.elastic.co/u/t603)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 2:14pm UTC](https://discuss.elastic.co/t/rfe-sql-add-listagg-aggregate-function/339111 "2023-07-24T14:14:12Z")

</div>

Hello, may I ask You in SQL language module to add "listagg" function into the aggregate (group by...having) SQL queries? This would help me to identify unique type of logs using this style of aggregation of string col…

---

## [Shards are in ALLOCATION\_FAILED or CLUSTER\_RECOVERED](https://discuss.elastic.co/t/shards-are-in-allocation-failed-or-cluster-recovered/339100)

<div class="topic-metadata">

**Author:** [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Replies:** 3\
**Last updated:** [July 24, 2023, 2:05pm UTC](https://discuss.elastic.co/t/shards-are-in-allocation-failed-or-cluster-recovered/339100 "2023-07-24T14:05:30Z")

</div>

Hi All, we have a 5 master and 41 node cluster, due to some storage hardware issue, Elasticsearch cluster was affected and after resolving hardware issue, some of the shards are showing as ALLOCATION\_FAILED or CLUSTER\_R…

---

## [Change log level for beats deployed by fleet managed elastic-agent](https://discuss.elastic.co/t/change-log-level-for-beats-deployed-by-fleet-managed-elastic-agent/338473)

<div class="topic-metadata">

**Author:** [@GibbsGreatly](https://discuss.elastic.co/u/GibbsGreatly)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 2:04pm UTC](https://discuss.elastic.co/t/change-log-level-for-beats-deployed-by-fleet-managed-elastic-agent/338473 "2023-07-24T14:04:51Z")

</div>

I've set up Elasticsearch and Kibana on a couple of test VM's. These will be running on Raspberry Pi's once I have it all figured out. Hence, it's pretty important that I limit logging. I am trying really hard to find…

---

## [Trying to use Synthetics but it shows an error on enrollment](https://discuss.elastic.co/t/trying-to-use-synthetics-but-it-shows-an-error-on-enrollment/337915)

<div class="topic-metadata">

**Author:** [@igorhodan](https://discuss.elastic.co/u/igorhodan)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 1:34pm UTC](https://discuss.elastic.co/t/trying-to-use-synthetics-but-it-shows-an-error-on-enrollment/337915 "2023-07-24T13:34:03Z")

</div>

Hello, I am trying to use the complete agent as recommended by the docs, for use the browser synthetics, according this post: Also i have alredy everything configured fine and working, without issues, but its a normal…

---

## [ELK Monitoring Cluster - issue with indexes reaching](https://discuss.elastic.co/t/elk-monitoring-cluster-issue-with-indexes-reaching/339021)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 8\
**Last updated:** [July 24, 2023, 1:27pm UTC](https://discuss.elastic.co/t/elk-monitoring-cluster-issue-with-indexes-reaching/339021 "2023-07-24T13:27:04Z")

</div>

Hello, I have following issue. I created ELK Onenode cluster with self-monitoring enabled (as ELK Monitoring Cluster) I joined another ELK Cluster environment to Monitoring Cluster. From another ELK Cluster I configu…

---

## [How to get unique documents with Search\_After](https://discuss.elastic.co/t/how-to-get-unique-documents-with-search-after/339098)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 12:38pm UTC](https://discuss.elastic.co/t/how-to-get-unique-documents-with-search-after/339098 "2023-07-24T12:38:11Z")

</div>

Hello, I would like to get unique documents basing on a field (unique\_id\_field) and by using search\_after algorithm GET /my\_index/\_search { "query": { "match\_all": {} } "size": 10000, "search\_after": \[sort\_field\_v…

---

## [Deployment of ELK Operator failing with namespace-level permissions](https://discuss.elastic.co/t/deployment-of-elk-operator-failing-with-namespace-level-permissions/339088)

<div class="topic-metadata">

**Author:** [@Kavish\_Mehta](https://discuss.elastic.co/u/Kavish_Mehta)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 11:41am UTC](https://discuss.elastic.co/t/deployment-of-elk-operator-failing-with-namespace-level-permissions/339088 "2023-07-24T11:41:19Z")

</div>

Hi, I am trying to Deploy Elasticsearch on Kubernetes using ECK, I only have namespace-level permissions in my k8s cluster, But the operator requires Daemonset permissions which is cluster level, and is thowing error …

---

## [Elasticsearch upgrade](https://discuss.elastic.co/t/elasticsearch-upgrade/339084)

<div class="topic-metadata">

**Author:** [@Sudheet\_Sid](https://discuss.elastic.co/u/Sudheet_Sid)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 11:26am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade/339084 "2023-07-24T11:26:30Z")

</div>

Hello Team, We have elasticsearch and kibana version 7.14.0 (docker) which is running on my Linux system with version "Ubuntu 20.04.2 LTS" Here have we upgrade our OS to latest OS after upgradation is it running as be…

---

## [Reindex error in version6 after upgrading it from ESv5](https://discuss.elastic.co/t/reindex-error-in-version6-after-upgrading-it-from-esv5/336529)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 7\
**Last updated:** [July 24, 2023, 10:27am UTC](https://discuss.elastic.co/t/reindex-error-in-version6-after-upgrading-it-from-esv5/336529 "2023-07-24T10:27:03Z")

</div>

Hi ES Community, I need some advice, I have to perform reindexing operation after upgrading the ES from v5 to v6. But while doing the reindexing i am getting the some mapping error. I am not very much sure which part s…

---

## [I have installed ELK 7.17.9 and Kibana 7.17.9 , i would want to make the kibana url as https](https://discuss.elastic.co/t/i-have-installed-elk-7-17-9-and-kibana-7-17-9-i-would-want-to-make-the-kibana-url-as-https/339065)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 10:03am UTC](https://discuss.elastic.co/t/i-have-installed-elk-7-17-9-and-kibana-7-17-9-i-would-want-to-make-the-kibana-url-as-https/339065 "2023-07-24T10:03:14Z")

</div>

Hi Team, I have installed ELK 7.17.9 and all other components related to it. the cluster is up and working fine. I would want to make the kibana url as https. how can i do it . there are some questions regarding it. E…

---

## [Storage utilization - indices spread across multiple storage devices attached to the same node](https://discuss.elastic.co/t/storage-utilization-indices-spread-across-multiple-storage-devices-attached-to-the-same-node/339053)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 8:54am UTC](https://discuss.elastic.co/t/storage-utilization-indices-spread-across-multiple-storage-devices-attached-to-the-same-node/339053 "2023-07-24T08:54:06Z")

</div>

Hi, We are running a 3 node cluster (Elasticsearch 8.8.2) running on 3 identical physical machines. Each machine has 2 onboard SSD storage devices. As of now, only one of the two SSDs is in use. It has the OS(Ubuntu) an…

---

## [About ElasticSearch Queries generated by SQL Workbench](https://discuss.elastic.co/t/about-elasticsearch-queries-generated-by-sql-workbench/339035)

<div class="topic-metadata">

**Author:** [@loco\_d.iwamoto](https://discuss.elastic.co/u/loco_d.iwamoto)\
**Replies:** 3\
**Last updated:** [July 24, 2023, 8:38am UTC](https://discuss.elastic.co/t/about-elasticsearch-queries-generated-by-sql-workbench/339035 "2023-07-24T08:38:33Z")

</div>

Thank you for your assistance. I would like to ask about the accuracy and speed of Elasticsearch Queries generated from QueryWorkBench. This is IndexMapping. "mappings": { "properties": { "a": { …

---

## [Snapshots (only backup before delete)?](https://discuss.elastic.co/t/snapshots-only-backup-before-delete/338809)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 6:22am UTC](https://discuss.elastic.co/t/snapshots-only-backup-before-delete/338809 "2023-07-24T06:22:16Z")

</div>

We are wanting to use Elastic Search Snapshots, but we are trying to keep costs down. It appears from what I am reading that the Snapshot feature wants to backup all indices that match a pattern, however we are only want…

---

## [LDAP Integration not working as expected](https://discuss.elastic.co/t/ldap-integration-not-working-as-expected/338921)

<div class="topic-metadata">

**Author:** [@forabraham1](https://discuss.elastic.co/u/forabraham1)\
**Replies:** 3\
**Last updated:** [July 24, 2023, 4:53am UTC](https://discuss.elastic.co/t/ldap-integration-not-working-as-expected/338921 "2023-07-24T04:53:59Z")

</div>

We've integrated Elastisearch with LDAP, but it is not working as expected followed the same steps provided in the documentation. Could some one take a look and what is wrong in the config. Issue: Exception thrown sayi…

---

## [Grok pattern for ubuntu apache web server access and error log](https://discuss.elastic.co/t/grok-pattern-for-ubuntu-apache-web-server-access-and-error-log/338790)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 4:40am UTC](https://discuss.elastic.co/t/grok-pattern-for-ubuntu-apache-web-server-access-and-error-log/338790 "2023-07-24T04:40:52Z")

</div>

Hi Anyone can help me out to get the custom grok pattern for apache access and error log instead of using combined option. I mentioned my both log format.. Access Log: 181.56.83.87 + 22407 0 - - \[19/Jul/2023:12:24:11 …

---

## [Yet another "No Nodes Alive Exception" discussion](https://discuss.elastic.co/t/yet-another-no-nodes-alive-exception-discussion/339024)

<div class="topic-metadata">

**Author:** [@Ahriss](https://discuss.elastic.co/u/Ahriss)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 2:53am UTC](https://discuss.elastic.co/t/yet-another-no-nodes-alive-exception-discussion/339024 "2023-07-24T02:53:49Z")

</div>

Hello there! I'm new here, and I've come here for help. As the name implies, I'm getting a "No nodes alive" error in a simple, single node elasticsearch php application. I have researched the issue for hours, it apparent…

---

## [Rally: How do the number of requests get calculated in a cluster?](https://discuss.elastic.co/t/rally-how-do-the-number-of-requests-get-calculated-in-a-cluster/338851)

<div class="topic-metadata">

**Author:** [@lquenti](https://discuss.elastic.co/u/lquenti)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 12:30am UTC](https://discuss.elastic.co/t/rally-how-do-the-number-of-requests-get-calculated-in-a-cluster/338851 "2023-07-24T00:30:27Z")

</div>

Hi, we want to use clustered rally to do a really large scaling test (n=100 ES nodes, ? load distributors) for different corpora and FS settings. In order to accomplish that, I have a few questions regarding the actual…

---

## [Lucene vs Elastic Search Document Count difference and its impact on term aggregation buckets](https://discuss.elastic.co/t/lucene-vs-elastic-search-document-count-difference-and-its-impact-on-term-aggregation-buckets/338827)

<div class="topic-metadata">

**Author:** [@S\_Star](https://discuss.elastic.co/u/S_Star)\
**Replies:** 9\
**Last updated:** [July 23, 2023, 8:10pm UTC](https://discuss.elastic.co/t/lucene-vs-elastic-search-document-count-difference-and-its-impact-on-term-aggregation-buckets/338827 "2023-07-23T20:10:39Z")

</div>

We have an index with lot of auto generated data for load testing and we noticed that there is significant difference in Elasticsearch doc count (using the \_count API) vs /indices API e.g ES documents : ~80 million Luc…

---

## [Elasticsearch Docker container cannot Snapshot to Google Cloud Storage (GCS)](https://discuss.elastic.co/t/elasticsearch-docker-container-cannot-snapshot-to-google-cloud-storage-gcs/338994)

<div class="topic-metadata">

**Author:** [@davidbernat](https://discuss.elastic.co/u/davidbernat)\
**Replies:** 1\
**Last updated:** [July 23, 2023, 12:54am UTC](https://discuss.elastic.co/t/elasticsearch-docker-container-cannot-snapshot-to-google-cloud-storage-gcs/338994 "2023-07-23T00:54:30Z")

</div>

Editors Note: this post is cross-posted on StackOverflow. Please respond in whichever forum the Elasticsearch community finds most appropriate for debugging user issues. Please note that the Elastic Co forum does not all…

---

## [TypeError: Class extends value undefined is not a constructor or null with Elastic Search Library with TypeScript](https://discuss.elastic.co/t/typeerror-class-extends-value-undefined-is-not-a-constructor-or-null-with-elastic-search-library-with-typescript/338984)

<div class="topic-metadata">

**Author:** [@Tanmay\_Sharma](https://discuss.elastic.co/u/Tanmay_Sharma)\
**Replies:** 0\
**Last updated:** [July 22, 2023, 9:28am UTC](https://discuss.elastic.co/t/typeerror-class-extends-value-undefined-is-not-a-constructor-or-null-with-elastic-search-library-with-typescript/338984 "2023-07-22T09:28:31Z")

</div>

Hello Everyone, While using the Elastic Search Library with TypeScript in Svelte giving unknown TypeError: import { Client } from "@elastic/elasticsearch"; import \* as fs from "fs"; const client = new Client({…

---

## [Store Text Content of PDF in elastic search](https://discuss.elastic.co/t/store-text-content-of-pdf-in-elastic-search/338924)

<div class="topic-metadata">

**Author:** [@a.nguyentuan](https://discuss.elastic.co/u/a.nguyentuan)\
**Replies:** 1\
**Last updated:** [July 22, 2023, 12:34am UTC](https://discuss.elastic.co/t/store-text-content-of-pdf-in-elastic-search/338924 "2023-07-22T00:34:30Z")

</div>

I had a database which contain millions of document text content records. I would like to sync those text into Elasticsearch index for document content searching purpose. Could you please suggest what is the best way to …

---

## [Delete By Query Not Working](https://discuss.elastic.co/t/delete-by-query-not-working/338971)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [July 21, 2023, 11:43pm UTC](https://discuss.elastic.co/t/delete-by-query-not-working/338971 "2023-07-21T23:43:54Z")

</div>

I have a field that frequently has the value of :. I'm trying to delete all of these entries using the below. POST /index/\_delete\_by\_query { "query": { "match": { "log.message": ":" } } } Using dev…

---

## [Convert message into eps data and create a visualization](https://discuss.elastic.co/t/convert-message-into-eps-data-and-create-a-visualization/338903)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 5\
**Last updated:** [July 21, 2023, 6:22pm UTC](https://discuss.elastic.co/t/convert-message-into-eps-data-and-create-a-visualization/338903 "2023-07-21T18:22:45Z")

</div>

Note - I do have a ticket in with support but I felt that maybe this would be useful to the community as well so I will update things as we move along. What were doing: Shipping from 9 DLC's running in Openshift with F…

---

## [Elastic search data nodes kept crashing continuously](https://discuss.elastic.co/t/elastic-search-data-nodes-kept-crashing-continuously/337993)

<div class="topic-metadata">

**Author:** [@pratiksha](https://discuss.elastic.co/u/pratiksha)\
**Replies:** 7\
**Last updated:** [July 21, 2023, 8:43am UTC](https://discuss.elastic.co/t/elastic-search-data-nodes-kept-crashing-continuously/337993 "2023-07-21T08:43:54Z")

</div>

We are using Elasticsearch v7.10.2 deployed in kubernetes environment. Elasticsearch cluster was running fine earlier. As part of kubernetes cluster we updated a certificate in our k8s cluster which has not impacted ela…

---

## [Ngrams or dense vectors for similarity between arrays?](https://discuss.elastic.co/t/ngrams-or-dense-vectors-for-similarity-between-arrays/338929)

<div class="topic-metadata">

**Author:** [@kgeographer](https://discuss.elastic.co/u/kgeographer)\
**Replies:** 0\
**Last updated:** [July 21, 2023, 8:07am UTC](https://discuss.elastic.co/t/ngrams-or-dense-vectors-for-similarity-between-arrays/338929 "2023-07-21T08:07:30Z")

</div>

I have an index field "names" holding an array of place names. My goal is an ES query that sends an array of place names and returns the most similar docs based on all the names in both the query array and the index arra…

---

## [Change in Time In elasticsearch and Database](https://discuss.elastic.co/t/change-in-time-in-elasticsearch-and-database/338869)

<div class="topic-metadata">

**Author:** [@UshasMerrinGeorge](https://discuss.elastic.co/u/UshasMerrinGeorge)\
**Replies:** 3\
**Last updated:** [July 21, 2023, 8:01am UTC](https://discuss.elastic.co/t/change-in-time-in-elasticsearch-and-database/338869 "2023-07-21T08:01:04Z")

</div>

Hi all, I'm having trouble with data parsing from a database to Elasticsearch. The "downloaddate" field in the database has a value like "2023-07-12 17:30:17.000." When I print it in the terminal using stdout, it's co…

---

## [Monitor indexes from ELK with monitoring feature enabled](https://discuss.elastic.co/t/monitor-indexes-from-elk-with-monitoring-feature-enabled/338724)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 11:17pm UTC](https://discuss.elastic.co/t/monitor-indexes-from-elk-with-monitoring-feature-enabled/338724 "2023-07-20T23:17:57Z")

</div>

Hello I deployed ELK Monitoring Cluster (ELK with feature of monitoring enabled ) and I have couple of other clusters with metricbeat connecting to elasticsearch on it. I would like to implement rule that when in index…

---

## [Mocking an Aggregation](https://discuss.elastic.co/t/mocking-an-aggregation/338363)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 8:14pm UTC](https://discuss.elastic.co/t/mocking-an-aggregation/338363 "2023-07-20T20:14:29Z")

</div>

I'm trying to mock an Aggregation result for a Unit Test. var mockedSearchResponse = SearchResponse.of(r -\> r .took(10) .timedOut(false) .hits(h -\> h …

---

## [String\_query doesn't respond to some characters](https://discuss.elastic.co/t/string-query-doesnt-respond-to-some-characters/338567)

<div class="topic-metadata">

**Author:** [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 7:40pm UTC](https://discuss.elastic.co/t/string-query-doesnt-respond-to-some-characters/338567 "2023-07-20T19:40:03Z")

</div>

Hello! I have a misunderstanding of how string\_query works. Index creating: PUT \_index\_template/test { "priority": 500, "template": { "settings": { "index.default\_pipeline": "set-timestamp" }, "ma…

---

## [ElasticsearchClient datetime?](https://discuss.elastic.co/t/elasticsearchclient-datetime/338899)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 5:47pm UTC](https://discuss.elastic.co/t/elasticsearchclient-datetime/338899 "2023-07-20T17:47:58Z")

</div>

Hi all. I just upgraded ElasticsearchClient to 8.8. A Builder that used to accept a String ("now-7d") now needs a DateTime object. Does anyone have a working example of DateTime usage? This used to work: requestBui…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=224)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=226)
