# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=259

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 260

---

## [Backup of Elasticsearch](https://discuss.elastic.co/t/backup-of-elasticsearch/332816)

<div class="topic-metadata">

**Author:** [@raw](https://discuss.elastic.co/u/raw)\
**Replies:** 4\
**Last updated:** [May 15, 2023, 10:25am UTC](https://discuss.elastic.co/t/backup-of-elasticsearch/332816 "2023-05-15T10:25:19Z")

</div>

I have a cluster of 3 nodes. I have set the backup directory on the 3 nodes to be: /var/lib/elasticsearch/backups. I tried to restore the content of a snapshot I took from kibana and restore it on another cluster. It sh…

---

## [Can someone explain how to use "Intervals query"?](https://discuss.elastic.co/t/can-someone-explain-how-to-use-intervals-query/333045)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 9:57am UTC](https://discuss.elastic.co/t/can-someone-explain-how-to-use-intervals-query/333045 "2023-05-15T09:57:51Z")

</div>

How to use them? What is the difference with query\_string and what are the benefits of using "Intervals query"? The documentation is really unclear and hard to understand.

---

## [Delete By query On Fields of type Text](https://discuss.elastic.co/t/delete-by-query-on-fields-of-type-text/333427)

<div class="topic-metadata">

**Author:** [@Martim\_Mourao](https://discuss.elastic.co/u/Martim_Mourao)\
**Replies:** 4\
**Last updated:** [May 15, 2023, 9:47am UTC](https://discuss.elastic.co/t/delete-by-query-on-fields-of-type-text/333427 "2023-05-15T09:47:55Z")

</div>

Elasticsearch Version: 8.7.1 We needed to do some deletes by Query using: Delete by query API | Elasticsearch Guide \[8.7\] | Elastic Our Request using dev tools on Kibana: POST /INDEX/\_delete\_by\_query { "query": { …

---

## [The length \[1133164\] of field \[code\] in doc\[8927\]/index\[ovaledge\_prasanthi4567890\_oequery\] exceeds the \[index.highlight.max\_analyzed\_offset\] limit \[1000000\]. To avoid this error, set the query parameter \[max\_analyzed\_offset\] to a value less than index set](https://discuss.elastic.co/t/the-length-1133164-of-field-code-in-doc-8927-index-ovaledge-prasanthi4567890-oequery-exceeds-the-index-highlight-max-analyzed-offset-limit-1000000-to-avoid-this-error-set-the-query-parameter-max-analyzed-offset-to-a-value-less-than-index-set/333412)

<div class="topic-metadata">

**Author:** [@g\_prashanth](https://discuss.elastic.co/u/g_prashanth)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 8:55am UTC](https://discuss.elastic.co/t/the-length-1133164-of-field-code-in-doc-8927-index-ovaledge-prasanthi4567890-oequery-exceeds-the-index-highlight-max-analyzed-offset-limit-1000000-to-avoid-this-error-set-the-query-parameter-max-analyzed-offset-to-a-value-less-than-index-set/333412 "2023-05-15T08:55:49Z")

</div>

Every time increase index.highlight.max\_analyzed\_offset is not correct right, suppose if the field string having 100 match take first match and ignore remaining matches in the highlight.

---

## [Identifying the cause of an unresponsive ES Cluster](https://discuss.elastic.co/t/identifying-the-cause-of-an-unresponsive-es-cluster/331050)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 23\
**Last updated:** [May 15, 2023, 8:38am UTC](https://discuss.elastic.co/t/identifying-the-cause-of-an-unresponsive-es-cluster/331050 "2023-05-15T08:38:58Z")

</div>

We are running a 3 node cluster to index logs from a firewall. The nodes are VMs (8 Core CPUs, 8GB RAM). The host runs on Intel i7, and has SSD storage. We have Kibana running on one of the nodes. The interface becomes…

---

## [Data view http\_poller is not time based Anomaly detection can only be run over indices which are time based](https://discuss.elastic.co/t/data-view-http-poller-is-not-time-based-anomaly-detection-can-only-be-run-over-indices-which-are-time-based/332758)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:28am UTC](https://discuss.elastic.co/t/data-view-http-poller-is-not-time-based-anomaly-detection-can-only-be-run-over-indices-which-are-time-based/332758 "2023-05-15T08:28:36Z")

</div>

Hi when i want to create new ML job it will give me this error: Data view http\_poller is not time based Anomaly detection can only be run over indices which are time based. FYI: this view contain indice(index) that c…

---

## [While helm upgrade getting error elasticsearch 7.17.5](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417)

<div class="topic-metadata">

**Author:** [@shivaji\_laxmi](https://discuss.elastic.co/u/shivaji_laxmi)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417 "2023-05-15T07:57:56Z")

</div>

I upgraded the kubernetes cluster from 1.24 to 1.25. When I try to add additional node in elasticsearch cluster. I am getting following error. $ helm upgrade esdata . -f esdata\_prod.yml -n dea-elk --debug --dry-run up…

---

## [Migrating from Hot to Hot-Cold Elastic Cluster using Snapshot and Restore](https://discuss.elastic.co/t/migrating-from-hot-to-hot-cold-elastic-cluster-using-snapshot-and-restore/332886)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:40pm UTC](https://discuss.elastic.co/t/migrating-from-hot-to-hot-cold-elastic-cluster-using-snapshot-and-restore/332886 "2023-05-14T23:40:47Z")

</div>

Hi Elastic Community, We're considering migrating from a Elastic cluster (with only Hot nodes) to a hot-cold cluster to optimize performance and reduce hardware costs. Our question is, how will the cluster behave when w…

---

## [What are alternatives for query string to implement slope between phrases?](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:36pm UTC](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158 "2023-05-14T23:36:29Z")

</div>

What are alternatives for query string to implement slope between phrases?

---

## [How to increase output efficiency in logstash to elastic search?](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291)

<div class="topic-metadata">

**Author:** [@Arjav](https://discuss.elastic.co/u/Arjav)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 6:51pm UTC](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291 "2023-05-14T18:51:07Z")

</div>

I have a logstash configuration that has input for postgres database table that has 14 lakh records and an output to elasticsearch database that in setup on ec2 machine c5 x large, when i see documents formation for that…

---

## [Prioritized a master node in ES cluster](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 13\
**Last updated:** [May 14, 2023, 2:25pm UTC](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350 "2023-05-14T14:25:22Z")

</div>

Hello, My ES Cluster contains 3 Master nodes (node-1, node-2, node-3), and nodes have a priority (99,98,97) in order so when node-1 goes down it elects node-2 as the new master node this is good till now, but when node-…

---

## [Best practice for data model of geo data - less objects with nested vs. more objects with duplication](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376)

<div class="topic-metadata">

**Author:** [@gmmorris](https://discuss.elastic.co/u/gmmorris)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 11:48am UTC](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376 "2023-05-14T11:48:47Z")

</div>

Hello, my dear Elasticians, I miss you dearly. :wave: On my new adventure, I encountered a data modelling dilemma and thought I'd ask the experts what they think. We're ingesting large data sets of geospatial data and …

---

## [Could not able to install ELK in windows11](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369)

<div class="topic-metadata">

**Author:** [@priyanka\_g](https://discuss.elastic.co/u/priyanka_g)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 3:47am UTC](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369 "2023-05-14T03:47:52Z")

</div>

Hi Team, As i need to do pattern analysis for log files. i had downloaded Elasticsearch, Kibana and Logstack. But when i gave "elasticsearch.bat" in the command prompt, it is not getting installed properly, instead i…

---

## [Integration Ingest pipeline not executed when logstash ouptut is activated for Agent Policy (Fleet)](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 3\
**Last updated:** [May 13, 2023, 1:12pm UTC](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936 "2023-05-13T13:12:27Z")

</div>

8.7 here For some obscure reason, when I add a pipeline to an integration via Custom configurations (lower red rectangle in first screen below), it is not triggered when the policy integration output is set to logstash…

---

## [Custom Sample data - same sata reoccuring every week](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348 "2023-05-13T12:27:51Z")

</div>

How to achieve a configuration in an Elasticsearch/Kibana, which will handle my custom sample data to be shown as reoccurring for, lets say, every week? Just like the essential "Kibana Sample Data" - these are clearly li…

---

## [Unique Doc related to one \`field\`](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 6:02am UTC](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344 "2023-05-13T06:02:38Z")

</div>

Hey, I am using pagination and i want to filter duplicated doc related to one field. For the moment i am trying it with Collapse functionality to filter duplicated and with Cardinality aggregation to get the total unique…

---

## [Run ELK with docker compose](https://discuss.elastic.co/t/run-elk-with-docker-compose/332969)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 7\
**Last updated:** [May 12, 2023, 11:29pm UTC](https://discuss.elastic.co/t/run-elk-with-docker-compose/332969 "2023-05-12T23:29:56Z")

</div>

Hi everyone I want to run the ELK 8.7.0 using docker compose I create the docker-compose.yml file with this configuration : version: '3' services: mysql: container\_name: mysql hostname: mysql image: 'm…

---

## [Aggregations count vs hits count](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648)

<div class="topic-metadata">

**Author:** [@NNI](https://discuss.elastic.co/u/NNI)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 5:01pm UTC](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648 "2023-05-12T17:01:11Z")

</div>

Hi I would like to concern on aggregations count for explain in more details But for the sake of presenting the case a little background : I have cluster contains with 3 master nodes, 3 ingest nodes, 3 data nodes so t…

---

## [Show which tokens were not found in full text search](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331)

<div class="topic-metadata">

**Author:** [@kadermetov](https://discuss.elastic.co/u/kadermetov)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 4:48pm UTC](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331 "2023-05-12T16:48:34Z")

</div>

Hello, beautiful community! Is there a way to determine which words (tokens) in a phrase was or wasn't found during full text search. I need it to make something like Google does: Under each query result it shows wh…

---

## [Verify internode communication is using TLS](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975 "2023-05-12T14:51:18Z")

</div>

Having set up TLS for internode communication per is there a way to confirm that is is being used? E.g. is there something specific that gets written to the log during start up when it's in use, or is there something t…

---

## [How to determine the bottleneck between Filebeat and ES?](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272 "2023-05-12T14:48:01Z")

</div>

Hi, I'm trying to determine the bottleneck for my Netflow setup, to see if I can further optimize the performance. I am ingesting Netflow traffic into a Linux server running both filebeat and elasticsearch 7.1.4. I'm u…

---

## [CSV Response Data Format from SQL Rest API](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224 "2023-05-12T14:20:12Z")

</div>

Hi, I was told in a previous post: that Elasticsearch cannot return csv as response data: Then I found this: I've been trying to play around with it, but must admit I'm a little lost. I have a Kibana query that lo…

---

## [ScrollID is coming as null](https://discuss.elastic.co/t/scrollid-is-coming-as-null/330938)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 1:47pm UTC](https://discuss.elastic.co/t/scrollid-is-coming-as-null/330938 "2023-05-12T13:47:59Z")

</div>

I am using elastic8. with java client. I first used elasticclient.search() request this returned scrollId then i used same scrollID to call client.scroll(scrollID) api however the first call elasticclient.search() i…

---

## [3 Node Elasticsearch cluster is failing repeatedly with error: this node is unhealthy: health check failed due to broken node lock](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 1:17pm UTC](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234 "2023-05-12T13:17:16Z")

</div>

Hi All, I am stuck in a very weird situation. My 3-node ES cluster is failing after 8-10 days abruptly with error: \[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[elasticsearch-0.es-service\] this node is unhealthy: he…

---

## [Create a new index when document has a particular field?](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 1:06pm UTC](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307 "2023-05-12T13:06:15Z")

</div>

Is it possible to create a new index everytime my document has a particular field updated? say all docs with 'tenant':"100" are part of one index and if a document comes with a field "tenant":101, a new index is created…

---

## [Index Thread Pools](https://discuss.elastic.co/t/index-thread-pools/333302)

<div class="topic-metadata">

**Author:** [@Mohit\_Munjal](https://discuss.elastic.co/u/Mohit_Munjal)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 12:54pm UTC](https://discuss.elastic.co/t/index-thread-pools/333302 "2023-05-12T12:54:34Z")

</div>

My objective is to calculate how many index requests can a elasticsearch cluster hold in it's queue before starting rejecting it. My elasticsearch cluster(v6.8) has 8 data nodes of r5.xlarge instance i.e. 4 vCPU's. In …

---

## [Invalid NEST response built from a successful (404) low level call on GET:](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-404-low-level-call-on-get/333044)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [May 12, 2023, 12:23pm UTC](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-404-low-level-call-on-get/333044 "2023-05-12T12:23:28Z")

</div>

Hello I'm doing a Get Request in my code: var response = await Repository.ElasticClient.GetAsync\<Reservation\>(maskId).ConfigureAwait(false); And I'm getting this as a response: Invalid NEST response built from a succ…

---

## [ILM leaves empty shards of 225bytes](https://discuss.elastic.co/t/ilm-leaves-empty-shards-of-225bytes/333252)

<div class="topic-metadata">

**Author:** [@Lin\_Yu](https://discuss.elastic.co/u/Lin_Yu)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:27am UTC](https://discuss.elastic.co/t/ilm-leaves-empty-shards-of-225bytes/333252 "2023-05-12T11:27:52Z")

</div>

Hello, I'm using elastcisearch v8.5 and filebeat. My question is : How could i solve 0 bytes shard keep rolling over? How to delete 0bytes shards? How to set up ILM correctly? This is the configuration of filebeat.y…

---

## [How do I 'Update All Fields Where'](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293 "2023-05-12T11:21:05Z")

</div>

I have a few different indicies that have logs in them that were digested using Logstash. The filter in my config looks like this: filter { csv { autodetect\_column\_names =\> false columns =\> \["uid", "ip"\] …

---

## [Why does the performance difference occur when searching in the regular or keyword field?](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289)

<div class="topic-metadata">

**Author:** [@Ruveyda\_Aksoy](https://discuss.elastic.co/u/Ruveyda_Aksoy)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289 "2023-05-12T11:13:39Z")

</div>

Hi, I have a question regarding query performance. The data types of the fields I am querying are as follows. "primaryIdentificationNumber" : { "type" : "keyword", "fields" : { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=258)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=260)
