# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=249

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 250

---

## [Does it use more storage with "fields" mapping?](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 6:43pm UTC](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883 "2023-06-05T18:43:22Z")

</div>

"some\_label" : { "type" : "keyword", "fields" : { "keyword" : { "type" : "keyword", "ignore\_above" : 256 } } } Supposed I have a …

---

## [Help optimize my query](https://discuss.elastic.co/t/help-optimize-my-query/335250)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 5:44pm UTC](https://discuss.elastic.co/t/help-optimize-my-query/335250 "2023-06-05T17:44:52Z")

</div>

I have this query: "query": { "bool": { "filter": { "bool": { "must": \[ { "range": { "movies-date": { "gt": "2018", "lt": "2022" } } }, given that this is a must query, does it make sense to move the range …

---

## [Cloud Provider - need change](https://discuss.elastic.co/t/cloud-provider-need-change/335113)

<div class="topic-metadata">

**Author:** [@Eduardo\_Maia](https://discuss.elastic.co/u/Eduardo_Maia)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 3:13pm UTC](https://discuss.elastic.co/t/cloud-provider-need-change/335113 "2023-06-05T15:13:49Z")

</div>

Hi, my enterprise use Elasticsearch and your first Provider was Google(GCP) and after change to Azure, when decide to change the cloud provider to Google again, we didn't get. And the problem is appear only Azure, and n…

---

## [Primary shard storage bottleneck](https://discuss.elastic.co/t/primary-shard-storage-bottleneck/335197)

<div class="topic-metadata">

**Author:** [@Hoang\_Vu](https://discuss.elastic.co/u/Hoang_Vu)\
**Replies:** 6\
**Last updated:** [June 5, 2023, 3:05pm UTC](https://discuss.elastic.co/t/primary-shard-storage-bottleneck/335197 "2023-06-05T15:05:05Z")

</div>

Hi everyone, I want to ask why the primary shard indexes for 1 day are only stored on 1 Hot3 node. Causing the Hot3 node to get a high CPU boost and denying the bulk request from the Coordination node that controls my fo…

---

## [What's the efficient way to filter and transfer data from Elastic](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006)

<div class="topic-metadata">

**Author:** [@Monkey\_D\_Luffy1](https://discuss.elastic.co/u/Monkey_D_Luffy1)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 1:23pm UTC](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006 "2023-06-05T13:23:43Z")

</div>

I have an Elastic Index which has 100 million documents inside it and I want to understand whats the efficient way of writing a python script to filter values and then transfer the filtered values to a SQL storage ?

---

## [How to encode the aggregation response and get doc by id response values in Elasticsearch 7.17.x](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220)

<div class="topic-metadata">

**Author:** [@Karunakaran-ti](https://discuss.elastic.co/u/Karunakaran-ti)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 1:05pm UTC](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220 "2023-06-05T13:05:27Z")

</div>

I am writing a custom Elasticsearch plugin. I want to do encode the response values from aggregation response and get doc by id. Using Elasticsearch v7.17.x I want to know what are interface/classes to be used from Ela…

---

## [JWT Realm configuration for Elasticsearch REST APIs authentication](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 11:35am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776 "2023-06-05T11:35:13Z")

</div>

I am new to Elasticsearch JWT Realm configuration. I am using trail version of Elasticsearch 8.7.1. I am configuring JWT Realm as follows in elasticsearch.yml xpack.security.authc.realms.jwt.jwt1: order: 1 token\_type…

---

## [Elasticsearch NEST deserializing issue. (Potential BUG)](https://discuss.elastic.co/t/elasticsearch-nest-deserializing-issue-potential-bug/335200)

<div class="topic-metadata">

**Author:** [@Jacques\_du\_Plessis](https://discuss.elastic.co/u/Jacques_du_Plessis)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 11:09am UTC](https://discuss.elastic.co/t/elasticsearch-nest-deserializing-issue-potential-bug/335200 "2023-06-05T11:09:06Z")

</div>

I am getting the following error while debugging the code. Basically I have an issue where I cant deserialize the response, see this How to run multiple search templates using NEST In frustration i pulled the github cod…

---

## [Filtering with nested query inner\_hits count](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202)

<div class="topic-metadata">

**Author:** [@LaySoft](https://discuss.elastic.co/u/LaySoft)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 10:08am UTC](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202 "2023-06-05T10:08:26Z")

</div>

I have the following query: "query": { "nested": { "path": "cuccok", "inner\_hits": {}, "query": { "bool": { "must": \[ …

---

## [Highlight in the field response](https://discuss.elastic.co/t/highlight-in-the-field-response/334955)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 10:07am UTC](https://discuss.elastic.co/t/highlight-in-the-field-response/334955 "2023-06-05T10:07:24Z")

</div>

Good morning, I have an application that read the results from my query in elasticsearch and I take all the fields of the response and after it, I put it in a windows form for the user. Now I would like remark the part…

---

## [C# ElasticClient search - field name upper case issue](https://discuss.elastic.co/t/c-elasticclient-search-field-name-upper-case-issue/334903)

<div class="topic-metadata">

**Author:** [@Yujie\_S](https://discuss.elastic.co/u/Yujie_S)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 9:28am UTC](https://discuss.elastic.co/t/c-elasticclient-search-field-name-upper-case-issue/334903 "2023-06-05T09:28:09Z")

</div>

My record is like this: { "\_index": "cmmtest2", "id": "q3\_WdIgBcz5F0I953TG", "\_score": 1, "\_source": { "characteristic": "150 W8 Prof 0.1 J", "actual": 0.019991, "nominal": 0, "partno": "2022\_7933 S2", "XBAR"…

---

## [Unable to find valid sertification path to requested target](https://discuss.elastic.co/t/unable-to-find-valid-sertification-path-to-requested-target/334810)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 8:20am UTC](https://discuss.elastic.co/t/unable-to-find-valid-sertification-path-to-requested-target/334810 "2023-06-05T08:20:37Z")

</div>

Hi, I have a watcher with webhook action. And get an error when the watcher is firing "type": "s\_s\_l\_handshake\_exception", "reason": " PKIX path building failed: sun.security.provider.certpath.SunCertPathBuildException…

---

## [Elasticsearch killed by oom-killer](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982)

<div class="topic-metadata">

**Author:** [@Andy\_Ni](https://discuss.elastic.co/u/Andy_Ni)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 3:27am UTC](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982 "2023-06-05T03:27:33Z")

</div>

Elasticsearch version: 6.2.3 System: \[root@my-host-name\]# uname -s -r -v -m -p -i -o Linux 5.4.8-1.el7.elrepo.x86\_64 #1 SMP Sat Jan 4 15:29:03 EST 2020 x86\_64 x86\_64 x86\_64 GNU/Linux ErrorMessage in /var/log/message: …

---

## [Not able to create index patterns as kibana is not getting the indices](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 15\
**Last updated:** [June 5, 2023, 1:23am UTC](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565 "2023-06-05T01:23:30Z")

</div>

\-I am getting indices for most of services, but unable to get indices for few services. So I am unable to create index patterns. We are getting logs in servers but unable to see logs in Kibana dashboard. \_Filebeat is up…

---

## [how geo\_distance query works under the hood in Elasticsearch?](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 8:38pm UTC](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154 "2023-06-04T20:38:32Z")

</div>

I need to use geo\_distance query on Elasticsearch. Need info about how it works under the hood and what is latency? I am not able to find any doc relevant to this. please help

---

## [Unable to restart the nginx service](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 7:48pm UTC](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170 "2023-06-04T19:48:02Z")

</div>

ubuntu@ip-172-31-37-106:~$ sudo service nginx restart Job for nginx.service failed because the control process exited with error code. See "systemctl status nginx.service" and "journalctl -xe" for details. systemctl s…

---

## [Error when attempting to create component template using the ECS generator](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004)

<div class="topic-metadata">

**Author:** [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 6:40pm UTC](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004 "2023-06-04T18:40:56Z")

</div>

Hello all, I am using the ECS mapping template generator to create the relevant components so we can start using the ECS fields. I cloned GitHub - elastic/ecs: Elastic Common Schema and generated essentially the default…

---

## [Elastisearch doesn't create .security index after loss of data](https://discuss.elastic.co/t/elastisearch-doesnt-create-security-index-after-loss-of-data/335123)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 4\
**Last updated:** [June 4, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elastisearch-doesnt-create-security-index-after-loss-of-data/335123 "2023-06-04T14:30:40Z")

</div>

Hello! We are using Elasticsearch and Kibana on Kubernetes deployed via Helm charts and recently we occasionaly deleted all the data from persistent volumes that our two nodes Elasticsearch cluster uses. Since then we ca…

---

## [Elastic Cluster Architecture Best Practices](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 5\
**Last updated:** [June 4, 2023, 4:57am UTC](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138 "2023-06-04T04:57:20Z")

</div>

Hi all, I have an upcoming project to set up a small cluster and thought would use the community help to validate the design scenario that I have in mind. A little background about available resources for that project: …

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 2\
**Last updated:** [June 4, 2023, 4:36am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146 "2023-06-04T04:36:10Z")

</div>

ubuntu@ip-172-31-37-106:~$ systemctl status elasticsearch.service ● elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; disabled; vendor preset: enabled) Active: failed (Re…

---

## [Index Life cycle settings disturbed after setting \_index\_template](https://discuss.elastic.co/t/index-life-cycle-settings-disturbed-after-setting-index-template/335141)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [June 3, 2023, 8:09pm UTC](https://discuss.elastic.co/t/index-life-cycle-settings-disturbed-after-setting-index-template/335141 "2023-06-03T20:09:17Z")

</div>

Hello, I had a template named "30days\_cleanup\_template" set for a particular index which was part of the ILM policy named "cleanup-history". Template was set as follows: PUT \_template/30days\_cleanup\_template { "inde…

---

## [ELastic-CertUtil erro trying to create Certificate-authorities, .crt, .key](https://discuss.elastic.co/t/elastic-certutil-erro-trying-to-create-certificate-authorities-crt-key/334865)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 5\
**Last updated:** [June 3, 2023, 6:43pm UTC](https://discuss.elastic.co/t/elastic-certutil-erro-trying-to-create-certificate-authorities-crt-key/334865 "2023-06-03T18:43:19Z")

</div>

Hey guys, i am having issues with generating Ca, crt and key for my nodes specifically using any o the below file and this command : \\Users\\YashCyb\\Downloads\\elasticsearch-8.8.0-windows-x86\_64\\elasticsearch-8.8.0\\bin\>…

---

## [ElasticSearch TLS/SSL Certificate issues 1](https://discuss.elastic.co/t/elasticsearch-tls-ssl-certificate-issues-1/334898)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 5\
**Last updated:** [June 3, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elasticsearch-tls-ssl-certificate-issues-1/334898 "2023-06-03T18:29:55Z")

</div>

Hey everyone, a very quick question, i have tried to modify my elasticsearch so it may resemble and work with my generated openssl Certificate.crt + private.key. ┌──(root㉿kali)-\[/etc\] └─# openssl req -x509 -nodes -days …

---

## [Synonyms and semantic search](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 5:37pm UTC](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880 "2023-06-03T17:37:02Z")

</div>

Need your help with one more thing. What is the best way to support synonyms (we have our own custom list) with semantic search?? Couldn't find anything related to this in the documentation.

---

## [Highlighting and text\_expansion query](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679)

<div class="topic-metadata">

**Author:** [@Mark\_Harwood1](https://discuss.elastic.co/u/Mark_Harwood1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 2:04pm UTC](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679 "2023-06-03T14:04:54Z")

</div>

Playing with the new ELSER model and the text\_expansion query in 8.8 which looks to be matching OK. Now I want end users to understand why documents matched but can't get highlighting to work. Does it? I've tried settin…

---

## [I have two Elastic cloud indices on the same cluster both have one common field Transactionid , Can I join both indices to get combined results](https://discuss.elastic.co/t/i-have-two-elastic-cloud-indices-on-the-same-cluster-both-have-one-common-field-transactionid-can-i-join-both-indices-to-get-combined-results/334915)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 3\
**Last updated:** [June 3, 2023, 2:50am UTC](https://discuss.elastic.co/t/i-have-two-elastic-cloud-indices-on-the-same-cluster-both-have-one-common-field-transactionid-can-i-join-both-indices-to-get-combined-results/334915 "2023-06-03T02:50:38Z")

</div>

I have two Elastic cloud indices on the same cluster both have one common field Transactionid , Can I join both indices to get combined results

---

## [Existing index and lifecycle policy](https://discuss.elastic.co/t/existing-index-and-lifecycle-policy/334666)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 3:23pm UTC](https://discuss.elastic.co/t/existing-index-and-lifecycle-policy/334666 "2023-06-02T15:23:49Z")

</div>

Hello, I need some help, I've seen many web pages how to configure it but none of them were helpfull. My existing index (daily index) is filebeat-exch-8.7.1-2023.05.30 I have created lifecycle policy 2-days whe…

---

## [How to size the ELK platform for on-premise setup / on-cloud setup](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048)

<div class="topic-metadata">

**Author:** [@shpankaj](https://discuss.elastic.co/u/shpankaj)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:45pm UTC](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048 "2023-06-02T13:45:12Z")

</div>

We have to ingest logs and analyze as part of SOC services covering 100 windows 10 / 11 endpoints, 2 FortiGate F100 firewall, 20 Windows servers, 20 managed network switches of 24 ports, 120 EDR - sentinelOne. What shou…

---

## [Migrating Fluent Mappings from NEST to Elastic.Clients.Elasticsearch 8.1.1 Client](https://discuss.elastic.co/t/migrating-fluent-mappings-from-nest-to-elastic-clients-elasticsearch-8-1-1-client/335077)

<div class="topic-metadata">

**Author:** [@jrogalan](https://discuss.elastic.co/u/jrogalan)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 12:33pm UTC](https://discuss.elastic.co/t/migrating-fluent-mappings-from-nest-to-elastic-clients-elasticsearch-8-1-1-client/335077 "2023-06-02T12:33:02Z")

</div>

How are we supposed to migrate a code like the following using NEST 7.17.5 to the new Elastic.Clients.Elasticsearch 8.1.1 client where the method .Object does not accept any longer the generic type of the child object. …

---

## [Cannot find write index](https://discuss.elastic.co/t/cannot-find-write-index/334683)

<div class="topic-metadata">

**Author:** [@Shreyansh\_Narang](https://discuss.elastic.co/u/Shreyansh_Narang)\
**Replies:** 13\
**Last updated:** [June 2, 2023, 11:46am UTC](https://discuss.elastic.co/t/cannot-find-write-index/334683 "2023-06-02T11:46:41Z")

</div>

Getting below error policy \[ilm\_cedar\] for index \[cedar-00001\] failed on step \[{"phase":"hot","action":"rollover","name":"check-rollover-ready"}\]. Moving to ERROR step java.lang.IllegalArgumentException: rollover targe…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=248)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=250)
