# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=266

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 267

---

## [Elastic machine learning - question about Anomaly Explorer](https://discuss.elastic.co/t/elastic-machine-learning-question-about-anomaly-explorer/330780)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 3:14am UTC](https://discuss.elastic.co/t/elastic-machine-learning-question-about-anomaly-explorer/330780 "2023-04-28T03:14:03Z")

</div>

Hi, I am new to Elastic machine learning. I input some data about users access a product API endpoint, and I have set up 2 influncers, which are the user name and product brand name. I make one user enormously to acces…

---

## [Failed installing file:///tmp/analysis-phonetic-7.17.7.zip](https://discuss.elastic.co/t/failed-installing-file-tmp-analysis-phonetic-7-17-7-zip/330988)

<div class="topic-metadata">

**Author:** [@markedperf](https://discuss.elastic.co/u/markedperf)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:39pm UTC](https://discuss.elastic.co/t/failed-installing-file-tmp-analysis-phonetic-7-17-7-zip/330988 "2023-04-27T21:39:54Z")

</div>

I am trying to install the analysis-phonetic plugin from a downloaded .zip file. I have copied the files to the local filesystem /tmp directory and inside the container to the /tmp directory. Below is the dockerfile th…

---

## [Upscaling Elastic Cloud Instance using Azure CLI](https://discuss.elastic.co/t/upscaling-elastic-cloud-instance-using-azure-cli/330947)

<div class="topic-metadata">

**Author:** [@Jacob\_Concrete](https://discuss.elastic.co/u/Jacob_Concrete)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 6:40pm UTC](https://discuss.elastic.co/t/upscaling-elastic-cloud-instance-using-azure-cli/330947 "2023-04-27T18:40:38Z")

</div>

Hello, I am trying to automate a process of Elastic installation on Azure. One of the steps is to upscale Elasticsearch from 2 zone 240GB storage 8GB RAM to 3 zone 870 GB Storage 29GB RAM after the deployment is created…

---

## [Logstash on windows sends data directly to the security onion SOC, not elasticsearch on windows?](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 6:09pm UTC](https://discuss.elastic.co/t/logstash-on-windows-sends-data-directly-to-the-security-onion-soc-not-elasticsearch-on-windows/330985 "2023-04-27T18:09:06Z")

</div>

Hi, I am still learning about the sysmon data going to security onion. It seems that using elasticsearch on windows handles only windows data and does not send the data to security onion kibana. You can download kibana…

---

## [Handling ambiguous field names in search query](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941)

<div class="topic-metadata">

**Author:** [@denvaar](https://discuss.elastic.co/u/denvaar)\
**Replies:** 1\
**Last updated:** [April 27, 2023, 4:59pm UTC](https://discuss.elastic.co/t/handling-ambiguous-field-names-in-search-query/329941 "2023-04-27T16:59:25Z")

</div>

I have a query that I run against multiple indices. Some of the indices being searched share some common field names, and I'm not sure what the best way to differentiate between them would be. I can get the desired resu…

---

## [Discovery.seed\_hosts and cluster.initial\_master\_nodes](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 4:43pm UTC](https://discuss.elastic.co/t/discovery-seed-hosts-and-cluster-initial-master-nodes/330945 "2023-04-27T16:43:40Z")

</div>

I'm struggling to understand the discovery settings now that discovery.zen.minimum\_master\_nodes has gone away. (where current is 8.7) says that discovery.seed\_hosts Provides a list of the addresses of the master-el…

---

## [Kibana not updating index in Discover](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 11\
**Last updated:** [April 27, 2023, 3:30pm UTC](https://discuss.elastic.co/t/kibana-not-updating-index-in-discover/330885 "2023-04-27T15:30:19Z")

</div>

Hi All, I see this issue where Kibana is not updating index on the "Discover" page while there is a definite increase in the size of the related index. Also for some reason Discover page shows data with one hour interva…

---

## [Return JSON Array of Arrays from elastic](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 3:23pm UTC](https://discuss.elastic.co/t/return-json-array-of-arrays-from-elastic/330971 "2023-04-27T15:23:10Z")

</div>

Hi, We've noticed that the overhead of the JSON object structure is creating some performance problems for us. One of the largest parts of this overhead is the repetitiveness of the object properties in each object. We'…

---

## [Bucket Selector Aggregation to eliminate null buckets](https://discuss.elastic.co/t/bucket-selector-aggregation-to-eliminate-null-buckets/330943)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 10:58am UTC](https://discuss.elastic.co/t/bucket-selector-aggregation-to-eliminate-null-buckets/330943 "2023-04-27T10:58:29Z")

</div>

I'm trying to use the Bucket Selector aggregation to eliminate Null values from other pipeline aggregations without success First Try of null checking: "bucket\_filter": { "bucket\_selector": { "buc…

---

## [ElasticSearch 8.7 initial single node setting fails](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870)

<div class="topic-metadata">

**Author:** [@Pfiffikus](https://discuss.elastic.co/u/Pfiffikus)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 7:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-initial-single-node-setting-fails/330870 "2023-04-27T07:22:09Z")

</div>

I get elasticsearch-create-enrollment-token -s kibana ERROR: Failed to determine the health of the cluster. Unexpected http status \[401\] for xpack: security: authc: realms: file: file1: …

---

## [Using Sort API via Elastic.Clients.Elasticsearch 8.1.0 .NET](https://discuss.elastic.co/t/using-sort-api-via-elastic-clients-elasticsearch-8-1-0-net/330908)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 9:37am UTC](https://discuss.elastic.co/t/using-sort-api-via-elastic-clients-elasticsearch-8-1-0-net/330908 "2023-04-27T09:37:32Z")

</div>

I have an Elasticsearch cluster, which contains an index called persons. I want to query and sort the documents of the index using the latest Elasticsearch client for .NET (Elastic.Clients.Elasticsearch 8.1.0 .NET). The …

---

## [Knn to show results for 'Other Locations you may like'](https://discuss.elastic.co/t/knn-to-show-results-for-other-locations-you-may-like/330933)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [April 27, 2023, 9:29am UTC](https://discuss.elastic.co/t/knn-to-show-results-for-other-locations-you-may-like/330933 "2023-04-27T09:29:40Z")

</div>

I want to create Proximity Search/Reccomendation with Location data. so my search results should have results - 'Other Locations you may like'. My data has Geo ID and Pincode for Location data. I was thinking of creati…

---

## [Elasticsearch.Net.UnexpectedElasticsearchClientException: expected:'{', actual:'\[', at offset:13520](https://discuss.elastic.co/t/elasticsearch-net-unexpectedelasticsearchclientexception-expected-actual-at-offset-13520/330290)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 8:23am UTC](https://discuss.elastic.co/t/elasticsearch-net-unexpectedelasticsearchclientexception-expected-actual-at-offset-13520/330290 "2023-04-27T08:23:08Z")

</div>

Hello I am updating a project to a the new NEST version: 7.17 But keep getting this error from the logging: Elasticsearch.Net.UnexpectedElasticsearchClientException: expected:'{', actual:'\[', at offset:13520 ---\> Elas…

---

## [Wrong documents' count after inserting](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284)

<div class="topic-metadata">

**Author:** [@Gregory\_Kovalchuk](https://discuss.elastic.co/u/Gregory_Kovalchuk)\
**Replies:** 4\
**Last updated:** [April 27, 2023, 8:07am UTC](https://discuss.elastic.co/t/wrong-documents-count-after-inserting/330284 "2023-04-27T08:07:51Z")

</div>

Hello, please help, I inserted data with spark several times but the count was all the time bigger than expected, how it can be? The version of ES is 8.5.0. The query that I used to check: GET index/\_count.

---

## ["sync" command in Transform API](https://discuss.elastic.co/t/sync-command-in-transform-api/328960)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 6\
**Last updated:** [April 27, 2023, 7:52am UTC](https://discuss.elastic.co/t/sync-command-in-transform-api/328960 "2023-04-27T07:52:28Z")

</div>

When a new document is indexed I want to implement a transform instance in which the transform index (dest) is updated every period of "frequency". This is the query I executed. PUT \_transform/test\_transform\_instance …

---

## [Fatal exception while booting Elasticsearch](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/330887)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 3\
**Last updated:** [April 27, 2023, 3:41am UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/330887 "2023-04-27T03:41:39Z")

</div>

Hi community My elasticsearch was Up until that i changed all the passwords. After that i tried starting elasticsearch services and it didn't work. When i saw the logs in /var/log/elasticsearch/elasticsearch.log …

---

## [Python -\> ElasticSearch Data Stream.. i'm doing something wrong.. suggestions](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 2\
**Last updated:** [April 27, 2023, 3:12am UTC](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874 "2023-04-27T03:12:32Z")

</div>

i'm trying to write a pretty basic python script to bulk insert some ip blacklists into an elasticsearch data stream. this is my code, its basic for now: def bulkESSubmit(self): try: count=1 …

---

## [Certain watches never execute when added via the API](https://discuss.elastic.co/t/certain-watches-never-execute-when-added-via-the-api/330883)

<div class="topic-metadata">

**Author:** [@tang214](https://discuss.elastic.co/u/tang214)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 9:23pm UTC](https://discuss.elastic.co/t/certain-watches-never-execute-when-added-via-the-api/330883 "2023-04-26T21:23:21Z")

</div>

I have certain watches that never execute when being added via the API. The exact same watch json will work fine when added via the UI or Dev Tools Console. The watch code does update when pushed to the API but still won…

---

## [Connect to Elastic Cloud using python client](https://discuss.elastic.co/t/connect-to-elastic-cloud-using-python-client/330875)

<div class="topic-metadata">

**Author:** [@Venkatesh\_Guruprasad](https://discuss.elastic.co/u/Venkatesh_Guruprasad)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 7:22pm UTC](https://discuss.elastic.co/t/connect-to-elastic-cloud-using-python-client/330875 "2023-04-26T19:22:14Z")

</div>

I am using python client to connect to Elastic Cloud. I have tried connecting using basic\_auth and api\_keys. In both instances it gives me the following error elasticsearch.AuthorizationException: AuthorizationException…

---

## [Elastic search 8.5.3 Aggregations query erroring](https://discuss.elastic.co/t/elastic-search-8-5-3-aggregations-query-erroring/330777)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 13\
**Last updated:** [April 26, 2023, 5:51pm UTC](https://discuss.elastic.co/t/elastic-search-8-5-3-aggregations-query-erroring/330777 "2023-04-26T17:51:13Z")

</div>

Elastic search 8.5.3 not at all running aggregation queries , Even for small index ( just 5 documents ) Below Thread information. Same query works perfectly fine in Elastic Search 7.17 100.2% \[cpu=100.2%, other=0.0%…

---

## [Pattern Recognition AML ML model](https://discuss.elastic.co/t/pattern-recognition-aml-ml-model/330371)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 5:30pm UTC](https://discuss.elastic.co/t/pattern-recognition-aml-ml-model/330371 "2023-04-26T17:30:08Z")

</div>

Hi is it possible to do some pattern recognition with Elasticsearch ML? I have a dataset with financial data that looks like this: Timestamp,From Bank,Account,To Bank,Account,Amount Received,Receiving Currency,Amount P…

---

## [How do you limit how long a search query will run for or how much resources one query can use?](https://discuss.elastic.co/t/how-do-you-limit-how-long-a-search-query-will-run-for-or-how-much-resources-one-query-can-use/330858)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 5:04pm UTC](https://discuss.elastic.co/t/how-do-you-limit-how-long-a-search-query-will-run-for-or-how-much-resources-one-query-can-use/330858 "2023-04-26T17:04:53Z")

</div>

My Googlefu must not be strong. When using Elasticsearch 8.x, how does one limit how long a query runs or how many resources a query consumes. We're noticing possible denial of service attacks from certain people running…

---

## [Index external files](https://discuss.elastic.co/t/index-external-files/330771)

<div class="topic-metadata">

**Author:** [@fabian\_barnich](https://discuss.elastic.co/u/fabian_barnich)\
**Replies:** 5\
**Last updated:** [April 26, 2023, 3:11pm UTC](https://discuss.elastic.co/t/index-external-files/330771 "2023-04-26T15:11:21Z")

</div>

Good morning, I installed elasticsearch and kibana on a VM in debian, my documents that I want to index are on another VM. How can I tell Elasticsearch to index them? Thanks in advance

---

## [After migration from Elasticsearch 6.3 to 7.17 the index size on disk doubled](https://discuss.elastic.co/t/after-migration-from-elasticsearch-6-3-to-7-17-the-index-size-on-disk-doubled/330678)

<div class="topic-metadata">

**Author:** [@igor\_sokolov](https://discuss.elastic.co/u/igor_sokolov)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 2:39pm UTC](https://discuss.elastic.co/t/after-migration-from-elasticsearch-6-3-to-7-17-the-index-size-on-disk-doubled/330678 "2023-04-26T14:39:52Z")

</div>

Hello everyone, I've migrated an Elasticsearch 6.3 cluster to the version of 7.17 (by creating a new cluster with the same index mapping/shard structure and reindexing) and the index size on the disk almost doubled. The…

---

## [Elasticsearch upgrade from 2.4.6 to 7.x](https://discuss.elastic.co/t/elasticsearch-upgrade-from-2-4-6-to-7-x/330620)

<div class="topic-metadata">

**Author:** [@iarunava](https://discuss.elastic.co/u/iarunava)\
**Replies:** 7\
**Last updated:** [April 26, 2023, 1:12pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-2-4-6-to-7-x/330620 "2023-04-26T13:12:14Z")

</div>

Hi. Arunava here. Im trying to upgrade elasticsearch 2.4.6 to 7.17.x Im new to elasticsearch. I would appreciate some pointers. The 7.17 stack is ready. and there is a task defined which tries to bulk insert the data …

---

## [Ha in two node elasticsearch](https://discuss.elastic.co/t/ha-in-two-node-elasticsearch/330819)

<div class="topic-metadata">

**Author:** [@Monish22](https://discuss.elastic.co/u/Monish22)\
**Replies:** 9\
**Last updated:** [April 26, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ha-in-two-node-elasticsearch/330819 "2023-04-26T12:58:07Z")

</div>

Hi, Currently, we setup two node elasticsearch cluster in my lab and configured ha. We set the both the nodes are master and data. but when the elk01 master node is down, the elk02 doesnt take the leader process. ELK02…

---

## [New elasticsearch node does not run enrichments](https://discuss.elastic.co/t/new-elasticsearch-node-does-not-run-enrichments/330523)

<div class="topic-metadata">

**Author:** [@FKarraz](https://discuss.elastic.co/u/FKarraz)\
**Replies:** 9\
**Last updated:** [April 26, 2023, 12:40pm UTC](https://discuss.elastic.co/t/new-elasticsearch-node-does-not-run-enrichments/330523 "2023-04-26T12:40:06Z")

</div>

Hello, as I mentioned in enrich processor missing documents, I am facing some issues in my elasticsearch cluster related to document enrichment. I'm opening a new thread as I suspect they are different problems. As the …

---

## [Search query builder and mapping](https://discuss.elastic.co/t/search-query-builder-and-mapping/330715)

<div class="topic-metadata">

**Author:** [@SIMONE2](https://discuss.elastic.co/u/SIMONE2)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 11:55am UTC](https://discuss.elastic.co/t/search-query-builder-and-mapping/330715 "2023-04-26T11:55:11Z")

</div>

Hello everyone, I inherited the mapping of a service (JAVA SPRING BOOT)with Elasticsearch and I'm going crazy for the search. my field is so mapped: "organizationNames":{ "type":"text", "fields":{ …

---

## [Elasticsearch 6.8.23 happen OOM](https://discuss.elastic.co/t/elasticsearch-6-8-23-happen-oom/330802)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 11:37am UTC](https://discuss.elastic.co/t/elasticsearch-6-8-23-happen-oom/330802 "2023-04-26T11:37:05Z")

</div>

Hi, We have a 8core/16GB ( 4 nodes cluster ) for the Elasticsearch and the Elasticsearch process is getting killed. JDK settings -Xms8g -Xmx8g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSI…

---

## [Search templates with nested query](https://discuss.elastic.co/t/search-templates-with-nested-query/330745)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 11:25am UTC](https://discuss.elastic.co/t/search-templates-with-nested-query/330745 "2023-04-26T11:25:41Z")

</div>

Hi everyone. I'm trying to make a search template with bool query. This bool query uses 'should' operator, which searches data throgh 4 fields of index. These results than must be filtered by two fields, so I try to use…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=265)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=267)
