# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=267

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 268

---

## [Help on using stored filed in side a query](https://discuss.elastic.co/t/help-on-using-stored-filed-in-side-a-query/330825)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 11:08am UTC](https://discuss.elastic.co/t/help-on-using-stored-filed-in-side-a-query/330825 "2023-04-26T11:08:44Z")

</div>

I have index1 and index2. Running below query against Index1 where i point to index2. In indexs those fields created with stored option. Please help on this query. POST /Index1/\_search { "query": { "bool": {…

---

## [Map Composite Aggregation Payload in Java using Java Client 8.7](https://discuss.elastic.co/t/map-composite-aggregation-payload-in-java-using-java-client-8-7/330754)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 7:04am UTC](https://discuss.elastic.co/t/map-composite-aggregation-payload-in-java-using-java-client-8-7/330754 "2023-04-26T07:04:41Z")

</div>

{ "buckets": \[ { "key": { "SUBJNAME": "ALL", "ASOFYEARS": 2018 }, "doc\_count": 240, "cnt\_subj": { "value": 25521935824 }, "cnt\_dwnl": { "value": 4…

---

## [Mocking the .net client](https://discuss.elastic.co/t/mocking-the-net-client/330147)

<div class="topic-metadata">

**Author:** [@samlane](https://discuss.elastic.co/u/samlane)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 9:42am UTC](https://discuss.elastic.co/t/mocking-the-net-client/330147 "2023-04-26T09:42:23Z")

</div>

In 8.0 Release notes it mentions: " In order to support user testing scenarios, we have unsealed the ElasticsearchClient type and made its methods virtual. This supports mocking the type directly for unit testing." I h…

---

## [Elasticsearch 8.7.0 High Heap Usage](https://discuss.elastic.co/t/elasticsearch-8-7-0-high-heap-usage/330730)

<div class="topic-metadata">

**Author:** [@esi](https://discuss.elastic.co/u/esi)\
**Replies:** 6\
**Last updated:** [April 26, 2023, 9:00am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-0-high-heap-usage/330730 "2023-04-26T09:00:28Z")

</div>

Hello, we have a 3 node cluster one loadbalancer node, one slave node and one master node running with latest Ubuntu 22.04.2 and Elasticsearch with Kibana on version 8.7.0. The master and slave system has 4 CPUs and 64 G…

---

## [Response from SQL query does not contain "Rows" (Elastic.Clients.Elasticsearch 8.1.0 .NET)](https://discuss.elastic.co/t/response-from-sql-query-does-not-contain-rows-elastic-clients-elasticsearch-8-1-0-net/330791)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 7:28am UTC](https://discuss.elastic.co/t/response-from-sql-query-does-not-contain-rows-elastic-clients-elasticsearch-8-1-0-net/330791 "2023-04-26T07:28:29Z")

</div>

I have an Elasticsearch cluster, which contains an index called persons. I want to query the documents of the index using the SQL API of Elasticsearch. When using the REST API of Elasticsearch via Kibana everything works…

---

## [Failed to update mapping for index, failure org.elasticsearch.index.mapper.MapperParsingException: Failed to parse mapping: analyzer \[jobtitle\_synonym\_analyzer\] contains filters \[jobtitle\_synonym\_filter\] that are not allowed to run in index time mode](https://discuss.elastic.co/t/failed-to-update-mapping-for-index-failure-org-elasticsearch-index-mapper-mapperparsingexception-failed-to-parse-mapping-analyzer-jobtitle-synonym-analyzer-contains-filters-jobtitle-synonym-filter-that-are-not-allowed-to-run-in-index-time-mode/330785)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 6\
**Last updated:** [April 26, 2023, 5:51am UTC](https://discuss.elastic.co/t/failed-to-update-mapping-for-index-failure-org-elasticsearch-index-mapper-mapperparsingexception-failed-to-parse-mapping-analyzer-jobtitle-synonym-analyzer-contains-filters-jobtitle-synonym-filter-that-are-not-allowed-to-run-in-index-time-mode/330785 "2023-04-26T05:51:19Z")

</div>

When I restore the Index with the use of snapshot, It restored successfully but, I am getting an error called all shards are failed. When I search for an Explaination It shows that failed to update mapping for index, fai…

---

## [Trying to transform data from one index to another by applying pipeline in transform,But pipeline is executing only first half of it till Android filter](https://discuss.elastic.co/t/trying-to-transform-data-from-one-index-to-another-by-applying-pipeline-in-transform-but-pipeline-is-executing-only-first-half-of-it-till-android-filter/330721)

<div class="topic-metadata">

**Author:** [@Chinmay\_Bhusate](https://discuss.elastic.co/u/Chinmay_Bhusate)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 5:35am UTC](https://discuss.elastic.co/t/trying-to-transform-data-from-one-index-to-another-by-applying-pipeline-in-transform-but-pipeline-is-executing-only-first-half-of-it-till-android-filter/330721 "2023-04-26T05:35:14Z")

</div>

Sharing my transform alongwith Pipeline. Transform POST \_transform/\_preview { "source": { "index": \[ "events.test" \] }, "pivot": { "group\_by": { "session\_id": { "terms": { …

---

## [Change 4000 fields in my index](https://discuss.elastic.co/t/change-4000-fields-in-my-index/330504)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 11:22pm UTC](https://discuss.elastic.co/t/change-4000-fields-in-my-index/330504 "2023-04-25T23:22:03Z")

</div>

I have nested json documents with about 4000 fields. To change the field type, I understand I have to reindex with a new index and updated mapping. But what if i want to change like 2500 fields? is there an alternative w…

---

## [Elasticsearch slow at the beginning of searching , and segment memory is 0](https://discuss.elastic.co/t/elasticsearch-slow-at-the-beginning-of-searching-and-segment-memory-is-0/330638)

<div class="topic-metadata">

**Author:** [@yuhan\_zhang2](https://discuss.elastic.co/u/yuhan_zhang2)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:08pm UTC](https://discuss.elastic.co/t/elasticsearch-slow-at-the-beginning-of-searching-and-segment-memory-is-0/330638 "2023-04-25T23:08:14Z")

</div>

When I was testing the performance on 10 millions of docs, I found the performance was really bad at the beginning (~20s) but fast after thousands of search. Then I use \_cat/segments?v=true to check my segments and t…

---

## [Warning Observed after integrating with Active Directory](https://discuss.elastic.co/t/warning-observed-after-integrating-with-active-directory/330631)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:03pm UTC](https://discuss.elastic.co/t/warning-observed-after-integrating-with-active-directory/330631 "2023-04-25T23:03:31Z")

</div>

Hi team, We have a cluster running with docker with multiple nodes. The cluster is a licensed cluster and we recently enabled TLS security on the cluster. We have enabled TLS security for node-to-node communication. We …

---

## [Changing IP on a running cluster](https://discuss.elastic.co/t/changing-ip-on-a-running-cluster/330673)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 10:58pm UTC](https://discuss.elastic.co/t/changing-ip-on-a-running-cluster/330673 "2023-04-25T22:58:14Z")

</div>

Hello, We have a ELK 7.6.2 stack cluster (3 Master and 5 Data nodes) running in our Production environment. We need to migrate the servers (Cloud VMs) to a more robust ones. This process would result in changing the I…

---

## [Delete indices by date (Elasticsearch 8.7)](https://discuss.elastic.co/t/delete-indices-by-date-elasticsearch-8-7/330750)

<div class="topic-metadata">

**Author:** [@Suren\_Baboyan](https://discuss.elastic.co/u/Suren_Baboyan)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 10:46pm UTC](https://discuss.elastic.co/t/delete-indices-by-date-elasticsearch-8-7/330750 "2023-04-25T22:46:49Z")

</div>

Hello. I created index from logstash (%{\[project\]\[name\]}-%{\[project\]\[service\]}-%{+YYYY.MM.dd}), and I want to keep only last 10 days logs. How can I delete automatically older data?

---

## [Elastic monitoring default retention period](https://discuss.elastic.co/t/elastic-monitoring-default-retention-period/330723)

<div class="topic-metadata">

**Author:** [@Mateusz\_Migala](https://discuss.elastic.co/u/Mateusz_Migala)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 9:57am UTC](https://discuss.elastic.co/t/elastic-monitoring-default-retention-period/330723 "2023-04-25T09:57:54Z")

</div>

Hey, If I ship the metrics and logs to Elastic monitoring cluster using this feature: What is the default retention period for this data and how can I modify it ? I've found some threads in the forum where this ques…

---

## [Elasticsearch Querying a document to grab field using another documents field value](https://discuss.elastic.co/t/elasticsearch-querying-a-document-to-grab-field-using-another-documents-field-value/330411)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 10:32pm UTC](https://discuss.elastic.co/t/elasticsearch-querying-a-document-to-grab-field-using-another-documents-field-value/330411 "2023-04-25T22:32:25Z")

</div>

Hello all, I'm unable to find documentation on the following which I believe might be a niche implementation, but will try to explain the best I can. My inexperience aside, at first glance this seems to probably relate …

---

## [Bulk upload in Elasticsearch 6.8.19 using python](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 3:25pm UTC](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752 "2023-04-25T15:25:47Z")

</div>

Due to some reasons, I need to upload bulk csv data in Elasticsearch 6.8.19. Can someone provide me a piece of code for that. The latest version python code is not working for obvious reasons.

---

## [Elasticsearch.Net.ElasticsearchClientException](https://discuss.elastic.co/t/elasticsearch-net-elasticsearchclientexception/330735)

<div class="topic-metadata">

**Author:** [@Atilla\_Cokmez](https://discuss.elastic.co/u/Atilla_Cokmez)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 1:00pm UTC](https://discuss.elastic.co/t/elasticsearch-net-elasticsearchclientexception/330735 "2023-04-25T13:00:47Z")

</div>

I Use Elasticsearch 7.16.2 on docker and Nest 7.16.0 I added these codes by collecting them from two different classes. It may look complicated ConnectionSettings conStr = new ConnectionSettings(new Uri("http://localho…

---

## [How to apply ilm policy to index patter tenat-\*](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428 "2023-04-25T10:42:28Z")

</div>

Hello Expert, I have to apply an ilm policy to my index patter so that the space full issue should not occur. Im able to create the policy but not able to apply to index patter as i need to add manually for index patte…

---

## [Sampling aggregation with a fixed seed producing unstable results](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849)

<div class="topic-metadata">

**Author:** [@geoffballinger](https://discuss.elastic.co/u/geoffballinger)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 10:10am UTC](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849 "2023-04-25T10:10:31Z")

</div>

We would like to use sampling aggregations to improve aggregation performance in some dashboards, but the results must be the same each time to avoid confusing customers. We are thus setting the seed since if we do that …

---

## [Handling of null and \[\] (empty list)](https://discuss.elastic.co/t/handling-of-null-and-empty-list/330720)

<div class="topic-metadata">

**Author:** [@nguyen\_huy](https://discuss.elastic.co/u/nguyen_huy)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 9:24am UTC](https://discuss.elastic.co/t/handling-of-null-and-empty-list/330720 "2023-04-25T09:24:01Z")

</div>

Hi everybody, I am very new to Elasticsearch and I have a question regarding the handling of null and \[\] (empty list) values. Specifically, in my dummy index example, I have a document as follows { "hits": \[ …

---

## [Elasticsearchversion 7.17.9 is not starting - Exception in thread "main" java.lang.RuntimeException: starting java](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 5:48am UTC](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658 "2023-04-25T05:48:42Z")

</div>

Elasticsearch 7.8 is upgraded to version 7.17.9, then unable to start the service. And in logs getting following Error: Exception in thread "main" java.lang.RuntimeException: starting java.

---

## [None of the configured nodes are available](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340)

<div class="topic-metadata">

**Author:** [@zz-GuoYF](https://discuss.elastic.co/u/zz-GuoYF)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 8:35am UTC](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340 "2023-04-25T08:35:58Z")

</div>

The version of Elasticsearch I used is 2.4.6 and the deployment mode is single-node es. When I was running a query with a data volume of 7 million, the following error occurred in es： In addition, by adding GC log p…

---

## [Is Elasticsearch 7.17.9 is compatible withOpenJDK 1.8?](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:59am UTC](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654 "2023-04-25T05:59:59Z")

</div>

Is OpenJDK 1.8 version is compatible with elasticsearch 7.17.9 version? If not Which version of OpenJDK is compatible with elasticsearch 7.17.9?

---

## [Send logs from filebeat to elasticsearch](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:39am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628 "2023-04-25T05:39:27Z")

</div>

I am trying to send logs from filebeat to elasticsearch. Here is the filbeat.yml filebeat.inputs: - type: filestream id: my-filestream-id enabled: true paths: - C:\\ProgramData\\sample\_logs\\sample.log - type: lo…

---

## [Analyzer \[full\_chinese\] contains filters \[my\_synonym\] that are not allowed to run in index time mode](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626)

<div class="topic-metadata">

**Author:** [@YKX-Can](https://discuss.elastic.co/u/YKX-Can)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 2:59am UTC](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626 "2023-04-25T02:59:38Z")

</div>

this my setting PUT test { "settings": { "analysis": { "char\_filter": { "my\_tsconvert": { "convert\_type": "t2s", "type": "stconvert" } }, "filter": { "my\_synonym": { "type": "synon…

---

## [Runtime Field Convert the Timestamp to Display Month and Year](https://discuss.elastic.co/t/runtime-field-convert-the-timestamp-to-display-month-and-year/330164)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:53pm UTC](https://discuss.elastic.co/t/runtime-field-convert-the-timestamp-to-display-month-and-year/330164 "2023-04-24T19:53:47Z")

</div>

I have a requirement to show only the month and Year from the date on a Dashboard For instance I want to show how number of tickets by month and year - Apr 2023 currently the visualization shows this as below, I want t…

---

## [Elastic search on windows](https://discuss.elastic.co/t/elastic-search-on-windows/330409)

<div class="topic-metadata">

**Author:** [@Preethi\_Manu](https://discuss.elastic.co/u/Preethi_Manu)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 6:34pm UTC](https://discuss.elastic.co/t/elastic-search-on-windows/330409 "2023-04-24T18:34:34Z")

</div>

While installing Elastic search on windows , getting below error like plugin db2jcc4.jar is missing a descriptor properties file. Please help to resolve this

---

## [100% disk, single node cluster how to fix?](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 5:12pm UTC](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588 "2023-04-24T17:12:47Z")

</div>

I have a test single node cluster. I know what the problem is but can't seems to figure out how to get out of it and fix without removing everything and star over this node has all index without replica because I exe…

---

## [Using Time Serie DataStream (TSDS) for discrete events with high cardinality](https://discuss.elastic.co/t/using-time-serie-datastream-tsds-for-discrete-events-with-high-cardinality/330679)

<div class="topic-metadata">

**Author:** [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:57pm UTC](https://discuss.elastic.co/t/using-time-serie-datastream-tsds-for-discrete-events-with-high-cardinality/330679 "2023-04-24T16:57:04Z")

</div>

Hi there! I'm new to TSDS and time series in general. Let's say I have the following index mapping: { "properties": { "@timestamp": { "type": "date" }, "game\_id": { "…

---

## [Update nested documents via painless](https://discuss.elastic.co/t/update-nested-documents-via-painless/330676)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:12pm UTC](https://discuss.elastic.co/t/update-nested-documents-via-painless/330676 "2023-04-24T16:12:47Z")

</div>

Hi, Assuming we have the following mapping "mappings": { "properties": { "id": { "type": "text", }, "messages": { "type": "nested", "dynamic": "strict", "properties": { "id…

---

## [\[NEWBIE\] Increase speed of indexation huge logs](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 25\
**Last updated:** [April 24, 2023, 9:21am UTC](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069 "2023-04-24T09:21:27Z")

</div>

Hi everybody, I'm french and i m a very newbie with elasticsearch. Elasticsearch version imposed by security team : 7.10.2 I create a cluster like this with dedicate nodes: 2 master node 1 master only eligible node 1…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=266)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=268)
