# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=250

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 251

---

## [Query\_string search exact phrase causes performance issues](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 10:44am UTC](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055 "2023-06-02T10:44:22Z")

</div>

Hi all, When I make query\_string search exact phrase in Elasticsearch, POST /myindex\_\*/\_search { "query": { "query\_string": { "query": "\\"Classe A\\"" } } The query is run and shows hits, but sho…

---

## [Elastic Stack 8.3.3 - config changes fails](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969)

<div class="topic-metadata">

**Author:** [@afmin](https://discuss.elastic.co/u/afmin)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 10:10am UTC](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969 "2023-06-02T10:10:19Z")

</div>

Hi I am trying to increase my Master Nodes with more diskspace. The two nodes are used with 82 and 83% diskspace. When I try an config change from 1 to 2 availability zones it fails by the step "Calling Elasticsearch no…

---

## [Elasticsearch performance in HDD vs SSD and 32 GB vs 64 GB of RAM](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 24\
**Last updated:** [June 2, 2023, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622 "2023-06-02T09:47:22Z")

</div>

I understand from what I have read that ES works best in conjunction with a sweet spot of 64 GB RAM per node and a fair bit of SSD (3-4 TB per node, with multiple shards in each node to handle primary copies and replicas…

---

## [Elasticsearch 7.10.2 error](https://discuss.elastic.co/t/elasticsearch-7-10-2-error/334975)

<div class="topic-metadata">

**Author:** [@anderstr1](https://discuss.elastic.co/u/anderstr1)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 9:08am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-2-error/334975 "2023-06-02T09:08:53Z")

</div>

I am trying to setup Elasticsearch version 7.10.2 using the official docker image. I only need a single-node cluster and I have successfully managed to set it up locally in the container. This is the output from health …

---

## [How to remove low correlation results?](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 8:31am UTC](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056 "2023-06-02T08:31:03Z")

</div>

I want to be able to filter my search results for less relevant results. So I use the min\_score for filtering. like this: GET xxx/\_search { "min\_score": 2.8, "query": { "match": { "xxx": "xxxx" } }…

---

## [Exporting message fields from Elasticsearch for one years](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029)

<div class="topic-metadata">

**Author:** [@Brat\_Qaqa](https://discuss.elastic.co/u/Brat_Qaqa)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 6:44am UTC](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029 "2023-06-02T06:44:35Z")

</div>

Hi, what is the best/easiest way of exporting message field from Elasticsearch to some text/json file?

---

## [Suggestion needed in painless script](https://discuss.elastic.co/t/suggestion-needed-in-painless-script/335052)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 6:20am UTC](https://discuss.elastic.co/t/suggestion-needed-in-painless-script/335052 "2023-06-02T06:20:51Z")

</div>

Hi Team, Sorry, I am new to painless script and ES transform. Please bear with me on the query below. I have scenario to define a painless script in ES transform where the script needs to increase the timestamp by 1sec…

---

## [Need help in setting up Elasticsearch cluster](https://discuss.elastic.co/t/need-help-in-setting-up-elasticsearch-cluster/334642)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 8\
**Last updated:** [June 2, 2023, 5:57am UTC](https://discuss.elastic.co/t/need-help-in-setting-up-elasticsearch-cluster/334642 "2023-06-02T05:57:18Z")

</div>

Hi there, I am trying to run 2 nodes of elasticsearch and want them to form a cluster. But while running i am getting:- {"@timestamp":"2023-05-30T07:06:22.601Z", "log.level": "WARN", "message":"This node is a fully-fo…

---

## [How can I unwind array in elasticsearch](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 5:14am UTC](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046 "2023-06-02T05:14:35Z")

</div>

Hii { "size": 0, "aggs": { "location\_buckets": { "composite": { "size": 1000, "sources": \[ { "city": { "terms": { "field": "location.city…

---

## [Multiple Out Of Memory Errors occurring, sometimes causing Cluster State Red Alerts](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 4:03am UTC](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985 "2023-06-02T04:03:34Z")

</div>

We are getting many Out Of Memory errors on one cluster, but other clusters with similar size are not facing the issue. All the errors are of same type. \[2023-06-01T11:30:41,368\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtExcept…

---

## [Embedding query to baseurl](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:03am UTC](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984 "2023-06-02T01:03:44Z")

</div>

I have url to connect to elasticsearch forexample ip:9200 I have query suppose { "query": { "range": { "@timestamp": { "gte": "now-1d/d", "lt": "now/d" } } }, "aggs": { …

---

## [Can we use dense vector field in ES v7.10 for free?](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994)

<div class="topic-metadata">

**Author:** [@Vivek\_Sagar](https://discuss.elastic.co/u/Vivek_Sagar)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 1:02am UTC](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994 "2023-06-02T01:02:56Z")

</div>

With my installation of elasticsearch v7.10. I see x-pack enabled is true. So I am assuming the free features in x-pack is available to use. When i create a mapping with data type dense vector, I am able to do so and al…

---

## [Understanding subscriptions](https://discuss.elastic.co/t/understanding-subscriptions/335026)

<div class="topic-metadata">

**Author:** [@kevingscott](https://discuss.elastic.co/u/kevingscott)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 12:37am UTC](https://discuss.elastic.co/t/understanding-subscriptions/335026 "2023-06-02T00:37:27Z")

</div>

Hello, We are trying to estimate the cost of implementing Elastic and I am confused about how the subscriptions work. Let's say that we purchased the Premium subscription and then deployed a Dev, QA and Production envi…

---

## [Cross Cluster Replication for existing indexes](https://discuss.elastic.co/t/cross-cluster-replication-for-existing-indexes/334515)

<div class="topic-metadata">

**Author:** [@vvsh](https://discuss.elastic.co/u/vvsh)\
**Replies:** 8\
**Last updated:** [June 1, 2023, 3:58pm UTC](https://discuss.elastic.co/t/cross-cluster-replication-for-existing-indexes/334515 "2023-06-01T15:58:53Z")

</div>

Hello! I am considering CCR as a tool to migrate all the data (including historical data) from a source Elasticsearch single-node cluster to a target Elasticsearch multi-node cluster (both clusters have 7.17.7 version). …

---

## [Mutual tls between fluentd(act as client) and elasticsearch(act as server)](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816)

<div class="topic-metadata">

**Author:** [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 3:05pm UTC](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816 "2023-06-01T15:05:33Z")

</div>

Hi I am trying to establish mutual tls between fluentd and elasticsearch. I have followed steps described in https://www.elastic.co/guide/en/elasticsearch/reference/8.7/security-basic-setup.html#generate-certificates …

---

## [Connecting elastic search with microsoft fabric](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 3:04pm UTC](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000 "2023-06-01T15:04:19Z")

</div>

Microsoft has released fabric for data analysis. It can connect to many types and sources of data How to connect elasticsearch data to microsoft fabric?

---

## [Can anyone share the dockercompose yaml file for elasticsearch8 and kibana8 installation with xpack.security](https://discuss.elastic.co/t/can-anyone-share-the-dockercompose-yaml-file-for-elasticsearch8-and-kibana8-installation-with-xpack-security/334979)

<div class="topic-metadata">

**Author:** [@vikranthshetty02413](https://discuss.elastic.co/u/vikranthshetty02413)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 2:14pm UTC](https://discuss.elastic.co/t/can-anyone-share-the-dockercompose-yaml-file-for-elasticsearch8-and-kibana8-installation-with-xpack-security/334979 "2023-06-01T14:14:15Z")

</div>

Can anyone share the dockercompose yaml file for elasticsearch8 and kibana8 installation with xpack.security

---

## [Elastic - Spark connector failing to read data](https://discuss.elastic.co/t/elastic-spark-connector-failing-to-read-data/334231)

<div class="topic-metadata">

**Author:** [@ljSolaiman](https://discuss.elastic.co/u/ljSolaiman)\
**Replies:** 7\
**Last updated:** [June 1, 2023, 1:57pm UTC](https://discuss.elastic.co/t/elastic-spark-connector-failing-to-read-data/334231 "2023-06-01T13:57:46Z")

</div>

Hi all, I am trying to read data from Elasticsearch to Databricks (Spark) but I'm getting the following error: org.elasticsearch.hadoop.EsHadoopIllegalArgumentException: Cannot detect ES version - typically this happen…

---

## [Can not restart Elasticsearch service](https://discuss.elastic.co/t/can-not-restart-elasticsearch-service/334688)

<div class="topic-metadata">

**Author:** [@lcsb-sysadmins](https://discuss.elastic.co/u/lcsb-sysadmins)\
**Replies:** 18\
**Last updated:** [June 1, 2023, 12:57pm UTC](https://discuss.elastic.co/t/can-not-restart-elasticsearch-service/334688 "2023-06-01T12:57:02Z")

</div>

Hi, Elastic Stack Version - 7.17.5 We had an issue with our server (iDRAC is unable to successfully communicate with the device RAID Controller) which caused disruption for our elastic stack. However we solved that is…

---

## [Whole elasticsearh cluster become unresponsive if only one node is saturating](https://discuss.elastic.co/t/whole-elasticsearh-cluster-become-unresponsive-if-only-one-node-is-saturating/334960)

<div class="topic-metadata">

**Author:** [@shahzadkhan](https://discuss.elastic.co/u/shahzadkhan)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 12:14pm UTC](https://discuss.elastic.co/t/whole-elasticsearh-cluster-become-unresponsive-if-only-one-node-is-saturating/334960 "2023-06-01T12:14:53Z")

</div>

Hello All, we have elasticsearch cluster with 12 nodes and all the nodes are configured as master/data. these days we encountring an issue that all the queries are automatically forwarded to a only one node and the thr…

---

## [How to give multiple kibana FQDN in rp.redirect\_uri](https://discuss.elastic.co/t/how-to-give-multiple-kibana-fqdn-in-rp-redirect-uri/334961)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:12am UTC](https://discuss.elastic.co/t/how-to-give-multiple-kibana-fqdn-in-rp-redirect-uri/334961 "2023-06-01T11:12:25Z")

</div>

Hi Team, We are running two instance of kibana and we have seperate fqdn for this two kibana instance. We have successfully integrated Azure AD OIDC with Elasticsearch and kibana. During the testing we were testing only…

---

## [Migrating from .net Nest client to v8.\* Elastic.Clients.Elasticsearch .net client](https://discuss.elastic.co/t/migrating-from-net-nest-client-to-v8-elastic-clients-elasticsearch-net-client/334959)

<div class="topic-metadata">

**Author:** [@Jere](https://discuss.elastic.co/u/Jere)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:04am UTC](https://discuss.elastic.co/t/migrating-from-net-nest-client-to-v8-elastic-clients-elasticsearch-net-client/334959 "2023-06-01T11:04:24Z")

</div>

I’m migrating an API codebase from the .net v7.\* Nest client to the newer v8 .net client The API codebase using the Nest client makes frequent use of QueryDescriptors with logic operators that derive QueryContainer obje…

---

## [Split non-ILM large index](https://discuss.elastic.co/t/split-non-ilm-large-index/334922)

<div class="topic-metadata">

**Author:** [@Anabel](https://discuss.elastic.co/u/Anabel)\
**Replies:** 7\
**Last updated:** [June 1, 2023, 10:55am UTC](https://discuss.elastic.co/t/split-non-ilm-large-index/334922 "2023-06-01T10:55:53Z")

</div>

Hi I have a writable index with 2.1Tb. 1 shards, 1 replica. No ILM (my mistake). named office-project-version (no 000001 in the end) How can I split it into smaller pieces? adding ILM doesn't work, as an alies does…

---

## [Fluentd crashing on startup when trying to connect to Elasticsearch](https://discuss.elastic.co/t/fluentd-crashing-on-startup-when-trying-to-connect-to-elasticsearch/334950)

<div class="topic-metadata">

**Author:** [@xbfh0516](https://discuss.elastic.co/u/xbfh0516)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 10:06am UTC](https://discuss.elastic.co/t/fluentd-crashing-on-startup-when-trying-to-connect-to-elasticsearch/334950 "2023-06-01T10:06:13Z")

</div>

Hi all, Recently installed ECK on Kubernetes (hosted on DigitalOcean). Followed the Deploy ECK in your Kubernetes cluster | Elastic Cloud on Kubernetes \[2.8\] | Elastic tutorial and got Elasticsearch and Kibana up and ru…

---

## [Filebeat 8.8 input configuration - Add Fields](https://discuss.elastic.co/t/filebeat-8-8-input-configuration-add-fields/334949)

<div class="topic-metadata">

**Author:** [@Alessio\_Melis](https://discuss.elastic.co/u/Alessio_Melis)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 10:06am UTC](https://discuss.elastic.co/t/filebeat-8-8-input-configuration-add-fields/334949 "2023-06-01T10:06:01Z")

</div>

Hi, configuration: \[filebeat 8.8\] --\> \[logstash 8.8\] --\> \[elasticsearch 8.8\] I'm trying to add fields in my input configuration but when the data is sent to logstash, the index is created without my field. using the v…

---

## [Query with Text field](https://discuss.elastic.co/t/query-with-text-field/334687)

<div class="topic-metadata">

**Author:** [@Kunjal\_Patel](https://discuss.elastic.co/u/Kunjal_Patel)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 9:44am UTC](https://discuss.elastic.co/t/query-with-text-field/334687 "2023-06-01T09:44:56Z")

</div>

I have index settings and mappings are as below "settings": { "number\_of\_shards": 1, "number\_of\_replicas": 1, "index": {"max\_result\_window": 10000000, "max\_inner\_result\_window": 1000}, "analysis": { "analyzer": { …

---

## [Implement filter aggregation API via elastic .net client 8.1.1](https://discuss.elastic.co/t/implement-filter-aggregation-api-via-elastic-net-client-8-1-1/334940)

<div class="topic-metadata">

**Author:** [@Sagar\_Kayasth2](https://discuss.elastic.co/u/Sagar_Kayasth2)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 9:35am UTC](https://discuss.elastic.co/t/implement-filter-aggregation-api-via-elastic-net-client-8-1-1/334940 "2023-06-01T09:35:57Z")

</div>

Hello I created this json query for searching & aggregation. In aggregation with did filtered specification attributes. How can i implement this query using elastic .net client 8.1.1 sdk through in my .net project? Pl…

---

## [How to run multiple search templates using NEST](https://discuss.elastic.co/t/how-to-run-multiple-search-templates-using-nest/334933)

<div class="topic-metadata">

**Author:** [@Jacques\_du\_Plessis](https://discuss.elastic.co/u/Jacques_du_Plessis)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 9:13am UTC](https://discuss.elastic.co/t/how-to-run-multiple-search-templates-using-nest/334933 "2023-06-01T09:13:20Z")

</div>

I am trying perform a multi-template search using NEST, and then read the reponses, but seems like it always returns null when I try to cast it to the POCO type. The DSL query I run in Kibana looks like this. Just for r…

---

## [Root mapping definition has unsupported parameters](https://discuss.elastic.co/t/root-mapping-definition-has-unsupported-parameters/334931)

<div class="topic-metadata">

**Author:** [@pirogan](https://discuss.elastic.co/u/pirogan)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 9:02am UTC](https://discuss.elastic.co/t/root-mapping-definition-has-unsupported-parameters/334931 "2023-06-01T09:02:19Z")

</div>

cant create an easiest mapping from a doc mapping = { "mappings": { "properties": { "age": { "type": "integer" }, "email": { "type": "keyword" }, "name": { "type": "text" } } } } …

---

## [Reverse nested problem](https://discuss.elastic.co/t/reverse-nested-problem/334783)

<div class="topic-metadata">

**Author:** [@Kenan\_Seyidov](https://discuss.elastic.co/u/Kenan_Seyidov)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 8:46am UTC](https://discuss.elastic.co/t/reverse-nested-problem/334783 "2023-06-01T08:46:05Z")

</div>

In Elasticsearch we use a nested query, when we use the reverse nesting it does not remember the previous aggregation, it only returns the topmost eligible documents. For example : In the following query, rate\_option, s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=249)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=251)
