# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=239

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 240

---

## [Count arrays as an object](https://discuss.elastic.co/t/count-arrays-as-an-object/336626)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:57am UTC](https://discuss.elastic.co/t/count-arrays-as-an-object/336626 "2023-06-23T11:57:56Z")

</div>

Hi, I am struggling to get an aggregation to work. We have an array with multiple values and what I am trying to do is count (and return the values) how many documents have the exact same set of values in the array. The…

---

## [How can i write with red color?](https://discuss.elastic.co/t/how-can-i-write-with-red-color/336764)

<div class="topic-metadata">

**Author:** [@Hocine\_MEZOUGHI](https://discuss.elastic.co/u/Hocine_MEZOUGHI)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:48am UTC](https://discuss.elastic.co/t/how-can-i-write-with-red-color/336764 "2023-06-23T11:48:36Z")

</div>

I have a WATCHER that calculates the percentage difference and I'd like to write this difference in red in the body of the email. Using like this : {{ecart}} My example doesn't work, what wrong ???? "actions": { "sen…

---

## [Elasticsearch 8 won't start on Centos 7](https://discuss.elastic.co/t/elasticsearch-8-wont-start-on-centos-7/336722)

<div class="topic-metadata">

**Author:** [@Geek2.0](https://discuss.elastic.co/u/Geek2.0)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 8:06am UTC](https://discuss.elastic.co/t/elasticsearch-8-wont-start-on-centos-7/336722 "2023-06-23T08:06:26Z")

</div>

I have installed Elasticsearch 7.8 on centos 7 server and it was running normally. After uninstalling it and installing elasticsearch 8.8, I get the following error when trying to start it with the command sudo systemc…

---

## [Sort results by query string](https://discuss.elastic.co/t/sort-results-by-query-string/336743)

<div class="topic-metadata">

**Author:** [@samba](https://discuss.elastic.co/u/samba)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 7:40am UTC](https://discuss.elastic.co/t/sort-results-by-query-string/336743 "2023-06-23T07:40:11Z")

</div>

Hello, It is possible to set sort order by querystring? What I mean is when a user searches pink chairs the results beggining with pink and containing chairs must appear first and followed by that contain the query str…

---

## [Aggregate count and max per document query](https://discuss.elastic.co/t/aggregate-count-and-max-per-document-query/334583)

<div class="topic-metadata">

**Author:** [@dimalini](https://discuss.elastic.co/u/dimalini)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 7:03am UTC](https://discuss.elastic.co/t/aggregate-count-and-max-per-document-query/334583 "2023-06-23T07:03:18Z")

</div>

Hi, I have a mapping similar to PUT my-index-000001 { "mappings": { "properties": { "message": { "type": "keyword" } } } } now this field holds an array of messages. What I would like to…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/336738)

<div class="topic-metadata">

**Author:** [@Sudhangshu](https://discuss.elastic.co/u/Sudhangshu)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 6:30am UTC](https://discuss.elastic.co/t/elasticsearch/336738 "2023-06-23T06:30:56Z")

</div>

(myenv) C:\\Misc\\Django\_elasticsearch\>python manage.py search\_index --rebuild C:\\Misc\\Django\_elasticsearch\\myenv\\Lib\\site-packages\\elasticsearch\\connection\\base.py:200: ElasticsearchWarning: this request accesses system …

---

## [Component template and \_tier\_preference index setting](https://discuss.elastic.co/t/component-template-and-tier-preference-index-setting/336500)

<div class="topic-metadata">

**Author:** [@bstdenis](https://discuss.elastic.co/u/bstdenis)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 3:49am UTC](https://discuss.elastic.co/t/component-template-and-tier-preference-index-setting/336500 "2023-06-23T03:49:14Z")

</div>

I am trying to use component\_templates per the warning I received after using old index template. It seems to work, other than the \_tier\_preference setting. Specifically, setting "\_tier\_preference" to "data\_content" or …

---

## [Prevent ingest pipeline processor from nesting field names](https://discuss.elastic.co/t/prevent-ingest-pipeline-processor-from-nesting-field-names/336723)

<div class="topic-metadata">

**Author:** [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 8:18pm UTC](https://discuss.elastic.co/t/prevent-ingest-pipeline-processor-from-nesting-field-names/336723 "2023-06-22T20:18:25Z")

</div>

Consider the following ingest pipeline w/simulation... PUT \_ingest/pipeline/test { "processors": \[ { "set": { "field": "donot.nest", "value": "somevalue", "if": "ctx\['somedata'\] == 2"…

---

## [Unable to access Elastic with error message: "This Elastic installation has strict security requirements enabled that your current browser does not meet."](https://discuss.elastic.co/t/unable-to-access-elastic-with-error-message-this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/336606)

<div class="topic-metadata">

**Author:** [@AlexCloudSec](https://discuss.elastic.co/u/AlexCloudSec)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 7:16pm UTC](https://discuss.elastic.co/t/unable-to-access-elastic-with-error-message-this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/336606 "2023-06-22T19:16:59Z")

</div>

Basically Title. My Browser is upgraded. Receiving this error across Chrome, Edge, and Firefox. How do I resolve this issue?

---

## [Inconsistency with queries on unknown fields](https://discuss.elastic.co/t/inconsistency-with-queries-on-unknown-fields/335841)

<div class="topic-metadata">

**Author:** [@yfful](https://discuss.elastic.co/u/yfful)\
**Replies:** 4\
**Last updated:** [June 22, 2023, 6:56pm UTC](https://discuss.elastic.co/t/inconsistency-with-queries-on-unknown-fields/335841 "2023-06-22T18:56:35Z")

</div>

Hello, If you make a search request with a geo\_bounding\_box query, it will fail with a QueryShardException with message failed to find geo field \[my-field\] in the case where the index doesn't have a mapping for my-field.…

---

## [Elastic Search Transport Client(6.8.23) not able to connect to ES 7.17.10](https://discuss.elastic.co/t/elastic-search-transport-client-6-8-23-not-able-to-connect-to-es-7-17-10/336637)

<div class="topic-metadata">

**Author:** [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Replies:** 5\
**Last updated:** [June 22, 2023, 6:06pm UTC](https://discuss.elastic.co/t/elastic-search-transport-client-6-8-23-not-able-to-connect-to-es-7-17-10/336637 "2023-06-22T18:06:18Z")

</div>

Hi Team My application is using the Elastic Search Transport Client(6.8.23) and am trying to connect to an Elasticsearch server which is 7.17.10 version. And am getting the below exception. Caused by: NoNodeAvailableEx…

---

## [Elastic \`\_cluster/health\` showing unassigned shards](https://discuss.elastic.co/t/elastic-cluster-health-showing-unassigned-shards/336691)

<div class="topic-metadata">

**Author:** [@PresGas](https://discuss.elastic.co/u/PresGas)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 5:54pm UTC](https://discuss.elastic.co/t/elastic-cluster-health-showing-unassigned-shards/336691 "2023-06-22T17:54:33Z")

</div>

Hello! I inherited a 3 node Elastic 7.17 cluster and yesterday, the health status was red. \_cluster/health?pretty=true { "cluster\_name" : "graylog-production", "status" : "red", "timed\_out" : false, "number\_of\_…

---

## [Create a job from a model imported with Eland](https://discuss.elastic.co/t/create-a-job-from-a-model-imported-with-eland/336713)

<div class="topic-metadata">

**Author:** [@Lulu\_Martinez](https://discuss.elastic.co/u/Lulu_Martinez)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 4:35pm UTC](https://discuss.elastic.co/t/create-a-job-from-a-model-imported-with-eland/336713 "2023-06-22T16:35:53Z")

</div>

Hello, I would like to know if it is possible to create a machine learning job from an external model that I imported into Elastic platform using Eland. If so, how I can run that job each hour thus ingesting the data f…

---

## [Derivatives with "missing docs"](https://discuss.elastic.co/t/derivatives-with-missing-docs/336705)

<div class="topic-metadata">

**Author:** [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 2:25pm UTC](https://discuss.elastic.co/t/derivatives-with-missing-docs/336705 "2023-06-22T14:25:46Z")

</div>

Hi, I have a problem where I need to calculate the derivative on a sequence of documents that are Not at a specific interval. As a simplified example , imagine a series "login" event inserted into an index with a times…

---

## [Elasticsearch not loading logs](https://discuss.elastic.co/t/elasticsearch-not-loading-logs/336700)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 1:26pm UTC](https://discuss.elastic.co/t/elasticsearch-not-loading-logs/336700 "2023-06-22T13:26:41Z")

</div>

Hi, We have an elasticsearch cluster in docker swarm that consists of: 3 x controllers 1 x hot node 1 x warm node 1 x cold node The cluster is showing as healthy and the nodes all have quite low memory/CPU usage ho…

---

## [App search filters not working](https://discuss.elastic.co/t/app-search-filters-not-working/336697)

<div class="topic-metadata">

**Author:** [@teoman\_kirac](https://discuss.elastic.co/u/teoman_kirac)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 1:12pm UTC](https://discuss.elastic.co/t/app-search-filters-not-working/336697 "2023-06-22T13:12:57Z")

</div>

Hi All! And thanks in advance for helping me troubleshoot :slight\_smile: I am using app search with a gcp firestore search extension. ANd it automagically cruds according to my collection, but I can't search with a geo\_…

---

## [Frequent shard failures](https://discuss.elastic.co/t/frequent-shard-failures/336358)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 6\
**Last updated:** [June 22, 2023, 1:02pm UTC](https://discuss.elastic.co/t/frequent-shard-failures/336358 "2023-06-22T13:02:19Z")

</div>

Hi, We are running a 3 node Elasticsearch Cluster on Elastic stack version 8.8.1. The nodes are running on 3 identical computers with SSD storage and 16GB RAM. The setup is being used to index Firewall logs. Node 1: es…

---

## [Forcing consistent response when using \_source](https://discuss.elastic.co/t/forcing-consistent-response-when-using-source/336693)

<div class="topic-metadata">

**Author:** [@mikkelduif](https://discuss.elastic.co/u/mikkelduif)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 12:54pm UTC](https://discuss.elastic.co/t/forcing-consistent-response-when-using-source/336693 "2023-06-22T12:54:02Z")

</div>

Hi there, I have a question about using the "\_source" field, where I have noticed that the response is not always consistent with the document, and would like to ask if there is some way to tweak the elasticsearch behav…

---

## [Unexpected character while posting a payload to elastic search via rest client](https://discuss.elastic.co/t/unexpected-character-while-posting-a-payload-to-elastic-search-via-rest-client/335802)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 2\
**Last updated:** [June 22, 2023, 12:53pm UTC](https://discuss.elastic.co/t/unexpected-character-while-posting-a-payload-to-elastic-search-via-rest-client/335802 "2023-06-22T12:53:25Z")

</div>

Hi, Hi, I am using 7.17.3 stack for elastic. Low level Elasticsearch rest client is from 7.15.2 I am trying to send a payload having special characters in it using the below code. Request request = new Request("PUT", …

---

## [High thread count with rest client](https://discuss.elastic.co/t/high-thread-count-with-rest-client/335801)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 13\
**Last updated:** [June 22, 2023, 12:52pm UTC](https://discuss.elastic.co/t/high-thread-count-with-rest-client/335801 "2023-06-22T12:52:08Z")

</div>

Hi, I am using 7.17.3 stack for elastic. Low level Elasticsearch rest client is from 7.15.2 I see very high waiting thread count when I build the client for each request and do that in try block so it gets auto closed…

---

## [Rollover Failure - Unable to auto set lifecycle.rollover\_alias after rollover - Moving to ERROR step](https://discuss.elastic.co/t/rollover-failure-unable-to-auto-set-lifecycle-rollover-alias-after-rollover-moving-to-error-step/336235)

<div class="topic-metadata">

**Author:** [@vedalas21](https://discuss.elastic.co/u/vedalas21)\
**Replies:** 8\
**Last updated:** [June 22, 2023, 12:48pm UTC](https://discuss.elastic.co/t/rollover-failure-unable-to-auto-set-lifecycle-rollover-alias-after-rollover-moving-to-error-step/336235 "2023-06-22T12:48:55Z")

</div>

Getting a "Moving to ERROR step" while rollover from an alias when "max\_age" paramter is met Steps to reproduce Create an Index Template { "name": "temp-test\_idx\_template", "index\_template": { "in…

---

## [Enabling X-Pack Security](https://discuss.elastic.co/t/enabling-x-pack-security/336684)

<div class="topic-metadata">

**Author:** [@tomer\_zamir](https://discuss.elastic.co/u/tomer_zamir)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 12:04pm UTC](https://discuss.elastic.co/t/enabling-x-pack-security/336684 "2023-06-22T12:04:49Z")

</div>

Hi, I just installed Elasticsearch on my ubuntu VM and I'm trying to run it for the first time but encountering errors. I'm doing everything according to this tutorial: digitalocean I added these lines: discovery.typ…

---

## [How injest darktrace SysLog Json to FIlebeat / Elasticseach](https://discuss.elastic.co/t/how-injest-darktrace-syslog-json-to-filebeat-elasticseach/336676)

<div class="topic-metadata">

**Author:** [@yari\_arcopinto](https://discuss.elastic.co/u/yari_arcopinto)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 11:11am UTC](https://discuss.elastic.co/t/how-injest-darktrace-syslog-json-to-filebeat-elasticseach/336676 "2023-06-22T11:11:58Z")

</div>

Hello team, I'm new on ELK Stack System, so i want to apologize if my questions will be stupid. I have installed succeffully the ELK stack system on a my server, and i have installed the agents on all my server. All is…

---

## [Index numbers in strings as numeric and words](https://discuss.elastic.co/t/index-numbers-in-strings-as-numeric-and-words/336666)

<div class="topic-metadata">

**Author:** [@Michael\_Lockwood](https://discuss.elastic.co/u/Michael_Lockwood)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 10:33am UTC](https://discuss.elastic.co/t/index-numbers-in-strings-as-numeric-and-words/336666 "2023-06-22T10:33:45Z")

</div>

Hi, I have a requirement where I want to search for numbers within a string by both the numeric value (e.g. 3) and the string value (e.g. "three"). For example given the following index configuration PUT number-test { …

---

## [Metricbeat get data of eck](https://discuss.elastic.co/t/metricbeat-get-data-of-eck/336663)

<div class="topic-metadata">

**Author:** [@Rick\_Vailer](https://discuss.elastic.co/u/Rick_Vailer)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 10:06am UTC](https://discuss.elastic.co/t/metricbeat-get-data-of-eck/336663 "2023-06-22T10:06:28Z")

</div>

Hello, We are in the process of monitoring an eck elasticsearch. Basically a metricbeat is already configured on the node worker were the eck is running. Is it possible to connect and pull metrics from this eck and ship…

---

## [Ask for help](https://discuss.elastic.co/t/ask-for-help/336655)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 9:19am UTC](https://discuss.elastic.co/t/ask-for-help/336655 "2023-06-22T09:19:27Z")

</div>

Good morning, i have a probelm in index elasticsearch elasticsearch.BadRequestError: BadRequestError(400, 'illegal\_argument\_exception', 'mapper \[doc.session\_id\] cannot be changed from type \[text\] to \[long\]') can anyone h…

---

## [Fetching documents with calendarItems.minNights first value greater than 2 using Elasticsearch DSL](https://discuss.elastic.co/t/fetching-documents-with-calendaritems-minnights-first-value-greater-than-2-using-elasticsearch-dsl/335411)

<div class="topic-metadata">

**Author:** [@Engin\_KARTAL](https://discuss.elastic.co/u/Engin_KARTAL)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 7:51am UTC](https://discuss.elastic.co/t/fetching-documents-with-calendaritems-minnights-first-value-greater-than-2-using-elasticsearch-dsl/335411 "2023-06-22T07:51:24Z")

</div>

Hello, I would like to learn how to fetch documents with the first value of the calendarItems.minNights field greater than 2 using Elasticsearch DSL. The data structure looks like this: In the above data structure, I w…

---

## [Elasticsearch restoration of a huge dump fails with client connection timeout errors](https://discuss.elastic.co/t/elasticsearch-restoration-of-a-huge-dump-fails-with-client-connection-timeout-errors/336622)

<div class="topic-metadata">

**Author:** [@bhavaniprasad\_reddy](https://discuss.elastic.co/u/bhavaniprasad_reddy)\
**Replies:** 9\
**Last updated:** [June 22, 2023, 7:21am UTC](https://discuss.elastic.co/t/elasticsearch-restoration-of-a-huge-dump-fails-with-client-connection-timeout-errors/336622 "2023-06-22T07:21:32Z")

</div>

Hi Team, I am trying to restore a 50GB elastic dump file into a new elasticsearch cluster running with 3 elasticsearch replicas on a kubernetes cluster. The elasticsearch is running with a 7.10.2 oss version image and …

---

## [Hashing in ElasticSearch](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 4\
**Last updated:** [June 22, 2023, 5:05am UTC](https://discuss.elastic.co/t/hashing-in-elasticsearch/336470 "2023-06-22T05:05:08Z")

</div>

Hello Team, We have a requirement to store an array of 100,000 users in an Elasticsearch field. During search, we need to match if a user exists in that array and return the corresponding document. Is it possible to ac…

---

## [Random spike in write performance](https://discuss.elastic.co/t/random-spike-in-write-performance/336635)

<div class="topic-metadata">

**Author:** [@dna01](https://discuss.elastic.co/u/dna01)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 2:33am UTC](https://discuss.elastic.co/t/random-spike-in-write-performance/336635 "2023-06-22T02:33:13Z")

</div>

I'm noticing random "slowness" when writing. e.g., while most of the time the write operation completed under 20ms, there are occasional write operation that took \>1s. my setup: 6 data nodes, 24G JVM heap. (there are …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=238)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=240)
