# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=244

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 245

---

## [Update elasticsearch from 7.15 to 7.17 version](https://discuss.elastic.co/t/update-elasticsearch-from-7-15-to-7-17-version/336006)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 8:49pm UTC](https://discuss.elastic.co/t/update-elasticsearch-from-7-15-to-7-17-version/336006 "2023-06-14T20:49:09Z")

</div>

Hi, I'm migrating elasticsearch from 7.15 to 7.17 version and i want to ensure that the jvm options is it correct this way : the java version is: openjdk version "1.8.0\_372" pl\_elasticstack::params::jvm\_options: \[ '-…

---

## [Accuracy of the scores and rankings in ANN output](https://discuss.elastic.co/t/accuracy-of-the-scores-and-rankings-in-ann-output/336009)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 7:37pm UTC](https://discuss.elastic.co/t/accuracy-of-the-scores-and-rankings-in-ann-output/336009 "2023-06-14T19:37:26Z")

</div>

As per the ES8 documentation, when running an ANN query with k=100, Elastic will: Find the 100 closest neighbors, using the HNSW approximation Calculate each result's similarity and rank them using the specified simila…

---

## [Rescoring the output of a knn-query hybrid retrieval](https://discuss.elastic.co/t/rescoring-the-output-of-a-knn-query-hybrid-retrieval/336008)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 6:58pm UTC](https://discuss.elastic.co/t/rescoring-the-output-of-a-knn-query-hybrid-retrieval/336008 "2023-06-14T18:58:07Z")

</div>

According to the kNN documentation: You can perform hybrid retrieval by providing both the knn option and a query. This search finds the global top k = 5 vector matches, combines them with the matches from the match qu…

---

## [I can't reopen a closed index](https://discuss.elastic.co/t/i-cant-reopen-a-closed-index/335895)

<div class="topic-metadata">

**Author:** [@Hatef](https://discuss.elastic.co/u/Hatef)\
**Replies:** 8\
**Last updated:** [June 14, 2023, 6:34pm UTC](https://discuss.elastic.co/t/i-cant-reopen-a-closed-index/335895 "2023-06-14T18:34:15Z")

</div>

Hi all, I'm pretty new to ES but have played around with ELK stack a bit and I'm more familiar now to run some API queries and modifying configs. I have closed an index called accelerate which is the main source of our…

---

## [Advantages of getting data from Elastic using Python](https://discuss.elastic.co/t/advantages-of-getting-data-from-elastic-using-python/335118)

<div class="topic-metadata">

**Author:** [@Jeferson\_Schiavinato](https://discuss.elastic.co/u/Jeferson_Schiavinato)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 5:16pm UTC](https://discuss.elastic.co/t/advantages-of-getting-data-from-elastic-using-python/335118 "2023-06-14T17:16:31Z")

</div>

Hello guys, I am a begginer at ELK and I am studying elasticsearch package in python. I have a shell script which reads large logs, extract data and send them to Zabbix. Theses large log files are now at Elasticsearch. …

---

## [Create ElasticSearch cluster with 2 or 3 nodes](https://discuss.elastic.co/t/create-elasticsearch-cluster-with-2-or-3-nodes/335901)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 4\
**Last updated:** [June 14, 2023, 1:45pm UTC](https://discuss.elastic.co/t/create-elasticsearch-cluster-with-2-or-3-nodes/335901 "2023-06-14T13:45:46Z")

</div>

I need to create an Elasticsearch cluster on Ubuntu machines, but to ensure high availability I would like to have more than one node in case I need to update or upgrade the server. Is there any material that teaches ho…

---

## [Elasticsearch: Terms Aggregation Bucket Order is not skipping the unmapped fields](https://discuss.elastic.co/t/elasticsearch-terms-aggregation-bucket-order-is-not-skipping-the-unmapped-fields/335986)

<div class="topic-metadata">

**Author:** [@crchaulagain1](https://discuss.elastic.co/u/crchaulagain1)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:45pm UTC](https://discuss.elastic.co/t/elasticsearch-terms-aggregation-bucket-order-is-not-skipping-the-unmapped-fields/335986 "2023-06-14T13:45:04Z")

</div>

My Elasticsearch alias is pointed to two different indices where the mapping is of a different type. I want the query to execute and get the response from the index where the given filter matches. But the terms aggregati…

---

## [Spike on CPU usage relates to the increase of fielddata memory](https://discuss.elastic.co/t/spike-on-cpu-usage-relates-to-the-increase-of-fielddata-memory/335303)

<div class="topic-metadata">

**Author:** [@GustavoSantos](https://discuss.elastic.co/u/GustavoSantos)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 1:43pm UTC](https://discuss.elastic.co/t/spike-on-cpu-usage-relates-to-the-increase-of-fielddata-memory/335303 "2023-06-14T13:43:41Z")

</div>

Hi team, We faced a very weird situation in one of our production clusters. Suddenly the CPU utilization of all nodes got 100% after being consistently under 30% for a long time. Looking at Kibana metrics, the only var…

---

## [How to highlight multifields? Iis there a way to highlight all results with the same multifield (same source, different analyzers) Multi-fields with multiple analyzers](https://discuss.elastic.co/t/how-to-highlight-multifields-iis-there-a-way-to-highlight-all-results-with-the-same-multifield-same-source-different-analyzers-multi-fields-with-multiple-analyzers/335985)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:41pm UTC](https://discuss.elastic.co/t/how-to-highlight-multifields-iis-there-a-way-to-highlight-all-results-with-the-same-multifield-same-source-different-analyzers-multi-fields-with-multiple-analyzers/335985 "2023-06-14T13:41:05Z")

</div>

How to highlight multifield? Is there a way to highlight all results with the same multifield (same source, different analyzers)? Multi-fields with multiple analyzers

---

## [Bool Filter doubt / Match\_all](https://discuss.elastic.co/t/bool-filter-doubt-match-all/335982)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:19pm UTC](https://discuss.elastic.co/t/bool-filter-doubt-match-all/335982 "2023-06-14T13:19:32Z")

</div>

Hi everybody. Maybe this is a silly doubt but if someone can answer. I have 3 docs, 1 with status:true field, 1 with status:false field and 1 doc without status field. POST idx\_test/\_bulk {"index":{}} {"name":"xpto 1"…

---

## [After restarting the master node, data and client nodes cannot discover the master](https://discuss.elastic.co/t/after-restarting-the-master-node-data-and-client-nodes-cannot-discover-the-master/334804)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 10\
**Last updated:** [June 14, 2023, 1:11pm UTC](https://discuss.elastic.co/t/after-restarting-the-master-node-data-and-client-nodes-cannot-discover-the-master/334804 "2023-06-14T13:11:53Z")

</div>

Hi, I am using elasticsearch cluster (8.7.0) on Kubernetes, I have 1 master, 1 client and 3 data nodes. After the restart of my master node, the other nodes cannot discover the master again. This is in the log of the d…

---

## [Limit a role and API key privledges](https://discuss.elastic.co/t/limit-a-role-and-api-key-privledges/335883)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 12:29pm UTC](https://discuss.elastic.co/t/limit-a-role-and-api-key-privledges/335883 "2023-06-14T12:29:22Z")

</div>

Hello, I have a use case for creating a 'stack maintenance' user that will be called up with Ansible to perform the cluster.routing.allocation.enable action to limit shard allocation before Elasticsearch is stopped and …

---

## [Elastic Augeas Not Working](https://discuss.elastic.co/t/elastic-augeas-not-working/335718)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 4\
**Last updated:** [June 14, 2023, 11:59am UTC](https://discuss.elastic.co/t/elastic-augeas-not-working/335718 "2023-06-14T11:59:40Z")

</div>

SELECT value FROM augeas WHERE path = '/etc/resolv.conf' AND label = 'nameserver'; SELECT \* FROM USERS When I am running this command, it's running successfully, but it's not retrieving the results.

---

## [Search by full name](https://discuss.elastic.co/t/search-by-full-name/335960)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 11:57am UTC](https://discuss.elastic.co/t/search-by-full-name/335960 "2023-06-14T11:57:40Z")

</div>

Hi everyone. I have an index wich consists of 3 fields: sys\_name full\_name man\_id. I want to search by full name wich consists of 3 words: GET managers/\_search { "query": { "match": { "full\_name": "William Garvey J…

---

## [Remove multiple spaces with script](https://discuss.elastic.co/t/remove-multiple-spaces-with-script/335638)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 11:56am UTC](https://discuss.elastic.co/t/remove-multiple-spaces-with-script/335638 "2023-06-14T11:56:26Z")

</div>

Hello, In street fields, the number of spaces has constantly changing values as follows. "street": "YALIM MAH. last/ şajdsj sdkdşfd" I can remove the spaces as follows, bu…

---

## [Elasticsearch snapshots fail everyday](https://discuss.elastic.co/t/elasticsearch-snapshots-fail-everyday/335747)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 11:23am UTC](https://discuss.elastic.co/t/elasticsearch-snapshots-fail-everyday/335747 "2023-06-14T11:23:01Z")

</div>

Hi, I am using elasticsearch 8.7 in out production cluster on Azure kubernetes platform which has 8 data and master nodes and almost 4TB per node disks being used to store our observability data. we have 699 indexes as …

---

## [Checking elasticsearch backups](https://discuss.elastic.co/t/checking-elasticsearch-backups/335955)

<div class="topic-metadata">

**Author:** [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 9:37am UTC](https://discuss.elastic.co/t/checking-elasticsearch-backups/335955 "2023-06-14T09:37:30Z")

</div>

i have Elasticsearch on which snapshots are taken daily, there is also a separately Elasticsearch which every day is restored by a script from the last snapshot and after restoration sends to the mail how much space th…

---

## [Question about elasticsearch index and logstash ingestion](https://discuss.elastic.co/t/question-about-elasticsearch-index-and-logstash-ingestion/335057)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 20\
**Last updated:** [June 14, 2023, 9:10am UTC](https://discuss.elastic.co/t/question-about-elasticsearch-index-and-logstash-ingestion/335057 "2023-06-14T09:10:27Z")

</div>

Hello everyone I'd like to ask you 2 questions. I receive approximately 270 csv per month, 9 of them per day. Each csv is between 1kB and 3MG in size. All these csv are sent to the same index on elasticsearch with log…

---

## [Overwride field "\_time" in splunk](https://discuss.elastic.co/t/overwride-field-time-in-splunk/335944)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:12am UTC](https://discuss.elastic.co/t/overwride-field-time-in-splunk/335944 "2023-06-14T08:12:24Z")

</div>

Hi I have logstash config that send logs to Splunk HEC. these data contain field that call "time". Now question is: does it possible to consider "time" as "\_time" on logstash config? FYI: i want to consider this time…

---

## [Shards are going to Intialized state againa and again, like in every 15 mins](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902)

<div class="topic-metadata">

**Author:** [@priyankaMS](https://discuss.elastic.co/u/priyankaMS)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902 "2023-06-14T06:59:02Z")

</div>

My Elasticsearch cluster is going to yellow state in about every 15 min, becuase 2 replica shards are going to initialization state. After 5 mins or so, cluster is going back to green state. Error Logs: \[o.e.t.Outbou…

---

## [java.lang.OutOfMemoryError: Java heap space (logstash, http\_poller)](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-logstash-http-poller/335935)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 6:39am UTC](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-logstash-http-poller/335935 "2023-06-14T06:39:55Z")

</div>

Hi I run logstash to fetch data from infludb via http\_poller and return below error: java.lang.OutOfMemoryError: Java heap space Here is the jvm.options: -Xms10g -Xmx10g Now question is: data locate on influxdb are …

---

## [Index to red state cluster](https://discuss.elastic.co/t/index-to-red-state-cluster/335763)

<div class="topic-metadata">

**Author:** [@DJ\_Zhu](https://discuss.elastic.co/u/DJ_Zhu)\
**Replies:** 10\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/index-to-red-state-cluster/335763 "2023-06-14T06:59:46Z")

</div>

I have a question regarding shard selection during index/bulk operations in Elasticsearch version 6.8.6. In my cluster, I have three data nodes: A, B, and C. The shards (with no replicas) are evenly allocated across the…

---

## [Multiple ES-Hadoop versions detected in the classpath](https://discuss.elastic.co/t/multiple-es-hadoop-versions-detected-in-the-classpath/335852)

<div class="topic-metadata">

**Author:** [@Suna.Y](https://discuss.elastic.co/u/Suna.Y)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 3:29am UTC](https://discuss.elastic.co/t/multiple-es-hadoop-versions-detected-in-the-classpath/335852 "2023-06-14T03:29:44Z")

</div>

ERROR: Multiple ES-Hadoop versions detected - Elastic Stack / Elasticsearch - Discuss the Elastic Stack I met the same question as above. If keep those versions, it occurs Multiple ES-Hadoop versions detected as follow…

---

## [Adding added field to index](https://discuss.elastic.co/t/adding-added-field-to-index/335440)

<div class="topic-metadata">

**Author:** [@rexxdad](https://discuss.elastic.co/u/rexxdad)\
**Replies:** 12\
**Last updated:** [June 14, 2023, 2:33am UTC](https://discuss.elastic.co/t/adding-added-field-to-index/335440 "2023-06-14T02:33:17Z")

</div>

i use the docker elk stack on macos with the logstash http pipeline to accept our apps http posts as input it created an index (I didn't before) reviewing the content, there are two fields that combined could make a ge…

---

## [Backup Snapshot](https://discuss.elastic.co/t/backup-snapshot/335856)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/backup-snapshot/335856 "2023-06-13T10:10:59Z")

</div>

Hello I want to perform the next backup system, but I don’t know how I can do it. Perform the backup of an explicit index of the current day example filebeat-%DD%MM%YYYY to the repository /backup. Export from the …

---

## [Fetching warnings from Elasticsearch response](https://discuss.elastic.co/t/fetching-warnings-from-elasticsearch-response/335903)

<div class="topic-metadata">

**Author:** [@Daniel\_Schneider](https://discuss.elastic.co/u/Daniel_Schneider)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 6:45pm UTC](https://discuss.elastic.co/t/fetching-warnings-from-elasticsearch-response/335903 "2023-06-13T18:45:27Z")

</div>

Hi, Is it possible to fetch warnings from Elasticsearch response in JAVA? E.g., when Elasticsearch security is not enabled rest client logs appropriate warning that comes with response: \[WARN \] o.e.c.RestClient - reque…

---

## [About the \`index()\` method of \`Elasticsearch Python Client\` library, is it using PUT or POST?](https://discuss.elastic.co/t/about-the-index-method-of-elasticsearch-python-client-library-is-it-using-put-or-post/335920)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 11:35pm UTC](https://discuss.elastic.co/t/about-the-index-method-of-elasticsearch-python-client-library-is-it-using-put-or-post/335920 "2023-06-13T23:35:24Z")

</div>

We are looking into a Python library Elasticsearch Python Client, and its official online document contains the below example for ingesting data into Elastic. We hope to make the ingest action idempotent, so we wonder w…

---

## [Elasticsearch 7.17.10 stuck with "triggering scheduled \[ML\] maintenance tasks"](https://discuss.elastic.co/t/elasticsearch-7-17-10-stuck-with-triggering-scheduled-ml-maintenance-tasks/335545)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 7\
**Last updated:** [June 13, 2023, 10:33pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-10-stuck-with-triggering-scheduled-ml-maintenance-tasks/335545 "2023-06-13T22:33:32Z")

</div>

Hi, After using Elasticsearch on my laptop for quite a while without problems, I recently upgraded from 7.17.7 to 7.17.10. Since that, I encountered twice a total freeze/stuck behavior. First time I stopped and restarte…

---

## [Are mappings carried over when using daily indexes?](https://discuss.elastic.co/t/are-mappings-carried-over-when-using-daily-indexes/335807)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 6\
**Last updated:** [June 13, 2023, 9:36pm UTC](https://discuss.elastic.co/t/are-mappings-carried-over-when-using-daily-indexes/335807 "2023-06-13T21:36:15Z")

</div>

We are looking into an issue where we continue to hit field limits. We have been bumping them but we know this is not a permanent solution and we need to find a long term solution. We are using daily indexes that we ar…

---

## [Aggregate data per document](https://discuss.elastic.co/t/aggregate-data-per-document/334812)

<div class="topic-metadata">

**Author:** [@JohnJoe](https://discuss.elastic.co/u/JohnJoe)\
**Replies:** 2\
**Last updated:** [June 13, 2023, 7:18pm UTC](https://discuss.elastic.co/t/aggregate-data-per-document/334812 "2023-06-13T19:18:31Z")

</div>

Hi All, I am wondering if the following is possible. I want to be able aggregate nested data within a document and then filter by the aggregated data. So if we have PUT warehouse/ { "mappings": { "properties": { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=243)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=245)
