# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=228

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 229

---

## [How to delete docs.deleted from ELK?](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597)

<div class="topic-metadata">

**Author:** [@Yuri\_Pires](https://discuss.elastic.co/u/Yuri_Pires)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:50pm UTC](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597 "2023-07-17T18:50:01Z")

</div>

Hello, in this logstash index I used the delete\_by\_query endpoint to clean old logs from storage, I was successful in this step, but I found that the docs are still on the HD and I want to delete them to free up space. h…

---

## [Does DBeaver client translate SQL queries to API calls?](https://discuss.elastic.co/t/does-dbeaver-client-translate-sql-queries-to-api-calls/338445)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 5:08pm UTC](https://discuss.elastic.co/t/does-dbeaver-client-translate-sql-queries-to-api-calls/338445 "2023-07-17T17:08:01Z")

</div>

Following this document we have created a DBeaver connection to a testing Elasticsearch instance running the 30-day trial license. We tried SQL queries like select \* from "my-index-000001" limit 10; and the DBeaver clie…

---

## [Indices have lifecycle errors](https://discuss.elastic.co/t/indices-have-lifecycle-errors/338524)

<div class="topic-metadata">

**Author:** [@Nde](https://discuss.elastic.co/u/Nde)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:41am UTC](https://discuss.elastic.co/t/indices-have-lifecycle-errors/338524 "2023-07-17T09:41:41Z")

</div>

Hello, In Index Management in Kabana I got some indices with lifecycle errors. The error of these indices is about the rollover\_alias not pointed into an index. i've tried the /\_reindex method and add the alias to t…

---

## [Bytes value wraps to negative value](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533)

<div class="topic-metadata">

**Author:** [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 1:48pm UTC](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533 "2023-07-17T13:48:14Z")

</div>

Hello, Am attempting to multiply the number of bytes from netflow by 100. This is to offset the sampling rate. The pipeline has the following script: { "script": { "source": "ctx.network.true\_bytes2 = ctx.…

---

## [Using sql query with parameters in dotnet client](https://discuss.elastic.co/t/using-sql-query-with-parameters-in-dotnet-client/338553)

<div class="topic-metadata">

**Author:** [@darooman](https://discuss.elastic.co/u/darooman)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 12:32pm UTC](https://discuss.elastic.co/t/using-sql-query-with-parameters-in-dotnet-client/338553 "2023-07-17T12:32:22Z")

</div>

When using the .net nuget package Elastic.Clients.Elasticsearch (version 8.1.3) to connect to an elastic cloud instance (running elastic v8.7.1), I am trying to use the sql query but I am struggling with the Params prope…

---

## [How to automatically delete index data after a few days or after certain size limit](https://discuss.elastic.co/t/how-to-automatically-delete-index-data-after-a-few-days-or-after-certain-size-limit/338511)

<div class="topic-metadata">

**Author:** [@akash-asthana](https://discuss.elastic.co/u/akash-asthana)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 12:14pm UTC](https://discuss.elastic.co/t/how-to-automatically-delete-index-data-after-a-few-days-or-after-certain-size-limit/338511 "2023-07-17T12:14:49Z")

</div>

Hello, I have a scenario where i need to clean up the index data after a given number of days or after a certain storage size is occupied. Is there any way of achieving this without deleting the actual index? Thanks

---

## [Elasticsearch License Expired](https://discuss.elastic.co/t/elasticsearch-license-expired/338546)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 12:11pm UTC](https://discuss.elastic.co/t/elasticsearch-license-expired/338546 "2023-07-17T12:11:17Z")

</div>

Hi What happens when the Elasticsearch license expired? Currently, the cluster has assigned a commercial license and it will expire soon, so what will happen once the assigned date expired?

---

## [Autofocus lose while typing in SearchBox](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091)

<div class="topic-metadata">

**Author:** [@raj22](https://discuss.elastic.co/u/raj22)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 10:06am UTC](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091 "2023-07-17T10:06:22Z")

</div>

Hello, I have component from \> @elastic/react-search-ui . For searchbox desing customization used inputView. But when I started typing suddenly autofocus is losing , so I need to enter cusor again into input element …

---

## [Search by script with field range + docs without exesting fields](https://discuss.elastic.co/t/search-by-script-with-field-range-docs-without-exesting-fields/338403)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/search-by-script-with-field-range-docs-without-exesting-fields/338403 "2023-07-17T09:54:24Z")

</div>

Hi, I try to make a query using template. Here are docs in my index: { "\_index" : "instruments", "\_type" : "\_doc", "\_id" : "721905", "\_score" : null, "\_source" : { "sess…

---

## [Is there a way to make the query string fuzzy by default?](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150)

<div class="topic-metadata">

**Author:** [@johnrodey](https://discuss.elastic.co/u/johnrodey)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:50am UTC](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150 "2023-07-17T09:50:37Z")

</div>

I submit a query string via Java Rest API (QueryStringQueryBuilder). Right now I pass in whatever the user enters and use that as my query string however I would like to automatically apply fuzzy searching, when it make…

---

## [Adding multiple client to the ELK centralised logging system](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:43am UTC](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526 "2023-07-17T09:43:44Z")

</div>

How to add multiple clients to the ELK centralised logging system so that we can visualise their logs. I have already installed filebeat on the client nodes and configure the filebeat.yml file too. But, not able to see t…

---

## [Aggregation return data that do not match query](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184)

<div class="topic-metadata">

**Author:** [@Edyta\_Szkiladz](https://discuss.elastic.co/u/Edyta_Szkiladz)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 9:42am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184 "2023-07-17T09:42:32Z")

</div>

I am trying to do aggregation on documents which contains categories field. Categories is an array of strings. Sample document: { "\_index": "test-v11", "\_type": "\_doc", "\_id": "954961", "\_version": 4, "\_score"…

---

## [Curl error when connecting with ElasticSearch running from docker - Windows](https://discuss.elastic.co/t/curl-error-when-connecting-with-elasticsearch-running-from-docker-windows/338525)

<div class="topic-metadata">

**Author:** [@Chaitanya\_Kanth](https://discuss.elastic.co/u/Chaitanya_Kanth)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:41am UTC](https://discuss.elastic.co/t/curl-error-when-connecting-with-elasticsearch-running-from-docker-windows/338525 "2023-07-17T09:41:50Z")

</div>

I installed Elasticsearch docker image on windows 10 machine. Docker v4.21.1 and elasticsearch v8.2.2. I downloaded the cert file and running the curl command from same location where file is downloaded. Running below co…

---

## [Add resiliency on .security-7 index](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121 "2023-07-17T09:23:39Z")

</div>

Hi, During multiple incident with cluster restart we lost the nodes where the index .security-7 was stored. It had a huge impact and we want to avoid as much as possible this situation to occur again. We have seen on t…

---

## [Connect oracle to elastic / kibana](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436)

<div class="topic-metadata">

**Author:** [@Oytoch](https://discuss.elastic.co/u/Oytoch)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 9:03am UTC](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436 "2023-07-17T09:03:53Z")

</div>

Hi, I try to understand kibana / Elasticsearch to interface my oracle database in order to make dashboard with kibana ( BI) I work with an "on premise" version First question, is it possible to do that with kibana ? …

---

## [How to use Search templates in collate for phrase suggester](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515)

<div class="topic-metadata">

**Author:** [@To\_Noroozi](https://discuss.elastic.co/u/To_Noroozi)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 8:33am UTC](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515 "2023-07-17T08:33:38Z")

</div>

Hi guys, according to the this link for collate: Suggesters | Elasticsearch Guide \[8.8\] | Elastic we can use our custom search template to use more complex query. i create sample search template and it is ok with name …

---

## [ES fails to restart after reboot](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 8:21am UTC](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465 "2023-07-17T08:21:20Z")

</div>

version 7.17.1 running on ubuntu -- started from systemctl When ever the server is rebooted ES fails to restart properly. Subsequent manual restart works just fine. \[2023-07-16T01:37:33,109\]\[INFO \]\[o.e.p.PluginsServic…

---

## [How does elastic react with x-pack crack](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 8:13am UTC](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503 "2023-07-17T08:13:55Z")

</div>

I'm researching on ESTC stock and wondering how does elastic react with x-pack crack? If SMB modifies Elastic code and builds it on-premise, it seems ESTC will lost much revenue

---

## [I have 2 aggregation in my query for Dau, Mau. how to combine them to find the ratio. have tried with bucket\_script, scripted metric. nothing works,](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373)

<div class="topic-metadata">

**Author:** [@Dev\_Profile](https://discuss.elastic.co/u/Dev_Profile)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:58am UTC](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373 "2023-07-17T06:58:28Z")

</div>

Below is my query. is there any way to access multi-buckets value to manipulate n return the results. { "\_source": false, "aggs": { "nested\_dau": { "nested": { "path": "dau" }, "aggs": …

---

## [Collection and storage of information from netflow sources](https://discuss.elastic.co/t/collection-and-storage-of-information-from-netflow-sources/335759)

<div class="topic-metadata">

**Author:** [@BugS](https://discuss.elastic.co/u/BugS)\
**Replies:** 12\
**Last updated:** [July 16, 2023, 12:22pm UTC](https://discuss.elastic.co/t/collection-and-storage-of-information-from-netflow-sources/335759 "2023-07-16T12:22:10Z")

</div>

Hello everyone. Maybe it's a newbie question, but I have limited experience with ELK. Currently, I'm trying to use it as a netflow collector. I've configured everything according to the documentation, but I'm a bit conce…

---

## [DBeaver to Elasticsearch connectivity is OK but fails on listing tables](https://discuss.elastic.co/t/dbeaver-to-elasticsearch-connectivity-is-ok-but-fails-on-listing-tables/338444)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 3\
**Last updated:** [July 16, 2023, 12:50am UTC](https://discuss.elastic.co/t/dbeaver-to-elasticsearch-connectivity-is-ok-but-fails-on-listing-tables/338444 "2023-07-16T00:50:26Z")

</div>

On DBeaver v23.1.0, we created a connection to an instance of Elasticsearch v8.6.1. The connectivity test, and logging in are OK. However, when clicking on the icons to expand the "Tables", it got an error saying, ... T…

---

## [Inaccessibility of Artifact Link for Elasticsearch Versions 2.x and 5.x: Seeking Clarification](https://discuss.elastic.co/t/inaccessibility-of-artifact-link-for-elasticsearch-versions-2-x-and-5-x-seeking-clarification/338457)

<div class="topic-metadata">

**Author:** [@amit\_phulera](https://discuss.elastic.co/u/amit_phulera)\
**Replies:** 3\
**Last updated:** [July 15, 2023, 11:54am UTC](https://discuss.elastic.co/t/inaccessibility-of-artifact-link-for-elasticsearch-versions-2-x-and-5-x-seeking-clarification/338457 "2023-07-15T11:54:07Z")

</div>

We have been using the following artifact link (https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-{{ elasticsearch\_version }}-linux-x86\_64.tar.gz) to download and test various components on elasticsearch…

---

## [How do return exact term matching irrespective of order?](https://discuss.elastic.co/t/how-do-return-exact-term-matching-irrespective-of-order/338297)

<div class="topic-metadata">

**Author:** [@at\_ohn](https://discuss.elastic.co/u/at_ohn)\
**Replies:** 3\
**Last updated:** [July 15, 2023, 6:30am UTC](https://discuss.elastic.co/t/how-do-return-exact-term-matching-irrespective-of-order/338297 "2023-07-15T06:30:12Z")

</div>

Hi community, appreciate if anyone has any insights on this. We want to return only exact matches irrespective of the order of the terms, and disregard any terms that are not in the query. For example, if we search "Ne…

---

## [Machine Learning - Anomaly Detection Jobs](https://discuss.elastic.co/t/machine-learning-anomaly-detection-jobs/338433)

<div class="topic-metadata">

**Author:** [@Jhonfechavez](https://discuss.elastic.co/u/Jhonfechavez)\
**Replies:** 2\
**Last updated:** [July 14, 2023, 10:09pm UTC](https://discuss.elastic.co/t/machine-learning-anomaly-detection-jobs/338433 "2023-07-14T22:09:10Z")

</div>

We have a Job in order to monitor our APM services using the following detectors: Yesterday we restarted the Job (Stop - start datafeed) and we are getting the following error: "Datafeed is encountering errors extra…

---

## [Using scripts with aggregation](https://discuss.elastic.co/t/using-scripts-with-aggregation/338378)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 9:13pm UTC](https://discuss.elastic.co/t/using-scripts-with-aggregation/338378 "2023-07-14T21:13:38Z")

</div>

Hi, I have a use case where the value of a field name signal can be 0, 1, or 2. I have to perform aggregation on this field but there are few records in the index without the field. For the field not\_exist, I need to as…

---

## [Ingest pipeline: copy all fields that contains a word to a single new field](https://discuss.elastic.co/t/ingest-pipeline-copy-all-fields-that-contains-a-word-to-a-single-new-field/338432)

<div class="topic-metadata">

**Author:** [@drjz](https://discuss.elastic.co/u/drjz)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 8:48pm UTC](https://discuss.elastic.co/t/ingest-pipeline-copy-all-fields-that-contains-a-word-to-a-single-new-field/338432 "2023-07-14T20:48:02Z")

</div>

Hi all, I am puzzling with the Script processor in an Ingest pipeline to copy all fields to a single new field. This is the same idea as using the copy\_to in the mapping, but instead of creating the copy in the index, we…

---

## [Elastic Search 7.17.9 ClusterFormationFailure](https://discuss.elastic.co/t/elastic-search-7-17-9-clusterformationfailure/337963)

<div class="topic-metadata">

**Author:** [@SSRR](https://discuss.elastic.co/u/SSRR)\
**Replies:** 5\
**Last updated:** [July 14, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-search-7-17-9-clusterformationfailure/337963 "2023-07-14T18:29:09Z")

</div>

I am facing some issues in my elasticsearch cluster related to Cluster Formation with 2 nodes. I'm trying to upgrade from elasticsearch from 7.17.0 to 7.17.9. Node1 is set as master and Node2 is not. I stopped elastics…

---

## [Simple? Where's the URL to query elastic cloud instance?](https://discuss.elastic.co/t/simple-wheres-the-url-to-query-elastic-cloud-instance/338318)

<div class="topic-metadata">

**Author:** [@midi-man](https://discuss.elastic.co/u/midi-man)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 6:20pm UTC](https://discuss.elastic.co/t/simple-wheres-the-url-to-query-elastic-cloud-instance/338318 "2023-07-14T18:20:33Z")

</div>

A hopefully simple question: Where is the URL to query an elastic cloud instance for a given deployment? The docs say to always use api dot elastic-cloud dot com/api/v1/deployments but this doesn't appear to work for…

---

## [Making a field hidden in search \_source](https://discuss.elastic.co/t/making-a-field-hidden-in-search-source/338418)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 3\
**Last updated:** [July 14, 2023, 5:48pm UTC](https://discuss.elastic.co/t/making-a-field-hidden-in-search-source/338418 "2023-07-14T17:48:05Z")

</div>

I have a index which has TBs of data now I am adding a new field to it say foo using ingest pipeline http://localhost:9200/\_ingest/pipeline/add { "processors" : \[{ "set": { "field" : "foo", …

---

## [Aggregation Query filtering on results](https://discuss.elastic.co/t/aggregation-query-filtering-on-results/338343)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 8\
**Last updated:** [July 14, 2023, 5:11pm UTC](https://discuss.elastic.co/t/aggregation-query-filtering-on-results/338343 "2023-07-14T17:11:12Z")

</div>

I have this query: GET user\_info,user\_auth\_cards\_info/\_search { "size": 0, "aggs": { "sorted\_user\_id": { "terms": { "field": "user\_id", "size": 15 }, "aggs": { "filtered…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=227)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=229)
