# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=271

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 272

---

## [Elastic search docker image - Jar hell error](https://discuss.elastic.co/t/elastic-search-docker-image-jar-hell-error/329767)

<div class="topic-metadata">

**Author:** [@priya\_dhana](https://discuss.elastic.co/u/priya_dhana)\
**Replies:** 11\
**Last updated:** [April 17, 2023, 12:55am UTC](https://discuss.elastic.co/t/elastic-search-docker-image-jar-hell-error/329767 "2023-04-17T00:55:27Z")

</div>

I am using docker.elastic.co/elasticsearch/elasticsearch:5.6.16 as base image and trying to upgrade the jackson packages to resolve Critical CVE. Dockerfile: # https://github.com/elastic/elasticsearch-docker FROM dock…

---

## [BulkIngester: Received \`not\_x\_content\_exception\` when adding json](https://discuss.elastic.co/t/bulkingester-received-not-x-content-exception-when-adding-json/329812)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:34am UTC](https://discuss.elastic.co/t/bulkingester-received-not-x-content-exception-when-adding-json/329812 "2023-04-12T08:34:09Z")

</div>

In the new BulkIngester, how to add json data? I have this json: { "time": "2023-04-13T02:44:16.1782763Z", "user\_id": 1, "user\_name": "admin", "host\_name": "localhost:5567", "type": "PRODUCT\_DELETE", "long\_…

---

## [Initiating a port scan](https://discuss.elastic.co/t/initiating-a-port-scan/329939)

<div class="topic-metadata">

**Author:** [@Infael](https://discuss.elastic.co/u/Infael)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 9:46pm UTC](https://discuss.elastic.co/t/initiating-a-port-scan/329939 "2023-04-17T21:46:23Z")

</div>

I need to scan all ports on my network. I have not been able to figure this out. I am very new to Elastic. Thanks! Michael

---

## [I am using the Sysmon-\> logstash -\> elasticsearch (ELK) architecture issues](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 11:14pm UTC](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076 "2023-04-15T23:14:36Z")

</div>

Hi, I am trying to use sysmon to logstash to elasticsearch. After advice from others in this forum, I finally came up with a combination of parms and processing that at least shows me data from my laptop IP in kibana. T…

---

## [Error starting watcher](https://discuss.elastic.co/t/error-starting-watcher/330143)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 6:34pm UTC](https://discuss.elastic.co/t/error-starting-watcher/330143 "2023-04-17T18:34:28Z")

</div>

We upgraded to 8.7.0 yesterday, since then none of our watchers have executed. We just keep getting this message in the elastic logs: error starting watcher I tried deleting the extra .watcher-history-\* indices via upda…

---

## [Limiting data in object properties coming to browser from elastic search](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 6\
**Last updated:** [April 17, 2023, 6:33pm UTC](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958 "2023-04-17T18:33:07Z")

</div>

Hi, We are currently pulling large amounts of data from Elasticsearch for reporting products in our software. For our larger clients this means sending a large amount of data to the browser which is then loaded into a r…

---

## [Are runtime multi-fields possible?](https://discuss.elastic.co/t/are-runtime-multi-fields-possible/330153)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 4:44pm UTC](https://discuss.elastic.co/t/are-runtime-multi-fields-possible/330153 "2023-04-17T16:44:48Z")

</div>

Is it possible to have a runtime mapping with a subfield? I mean, so I get fields like "field.keyword" and "field.text" like multi-fields, but at same time this is runtime mapping . I like elasticsearch dynamic mapping,…

---

## [Internal monitoring and log indices have "live forever" ILM policies](https://discuss.elastic.co/t/internal-monitoring-and-log-indices-have-live-forever-ilm-policies/330072)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 4:32pm UTC](https://discuss.elastic.co/t/internal-monitoring-and-log-indices-have-live-forever-ilm-policies/330072 "2023-04-17T16:32:21Z")

</div>

Hi! I was investigating an issue with too much retained data in our ES cloud cluster and realized that a lot of it comes from the internal monitoring and log indices. Specifically, the following indices with correspondi…

---

## [Use reciprocal ranking fusion to combine the results of two queries](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614)

<div class="topic-metadata">

**Author:** [@flando](https://discuss.elastic.co/u/flando)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 2:32pm UTC](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614 "2023-04-17T14:32:21Z")

</div>

Hi everyone, I'm trying to use reciprocal ranking fusion (RRF) to combine the results of two query performed with the following code: GET /books\_index/\_search { "query": { "bool": { "should": \[ { …

---

## [Trying to update a document but keep getting validation or parse errors](https://discuss.elastic.co/t/trying-to-update-a-document-but-keep-getting-validation-or-parse-errors/330117)

<div class="topic-metadata">

**Author:** [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Replies:** 9\
**Last updated:** [April 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/trying-to-update-a-document-but-keep-getting-validation-or-parse-errors/330117 "2023-04-17T14:25:57Z")

</div>

I have a set of documents created by filebeat -\> logstash pushed to Elasticsearch and they look like this... { "\_index": "sub\_myapp\_prod-filebeat-7.17.7-2023.04", "\_type": "\_doc", "\_id": "IPLahocBBfkGcvN800\_A", …

---

## [Perform aggregation on a modified term](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141)

<div class="topic-metadata">

**Author:** [@manropinxu](https://discuss.elastic.co/u/manropinxu)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 2:11pm UTC](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141 "2023-04-17T14:11:29Z")

</div>

I'd like to perform an aggregation grouping by a modified version of amessage field. I have lots of messages like invalid x with uuid=1e659cfc-a375-4a8a-88f5-467419fdf87d invalid x with uuid=49c4742e-0368-49a2-aab4-7f…

---

## [CVE-2022-1471 is not listed in Security Issues site](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110)

<div class="topic-metadata">

**Author:** [@Mike\_Joseph](https://discuss.elastic.co/u/Mike_Joseph)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:24pm UTC](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110 "2023-04-17T13:24:13Z")

</div>

Continuing the discussion from Snakeyaml vulnerability (CVE-2022-1471) on latest ES version: @DavidTurner Forwarded the topic to Security issues but it is still not addressed in the site.

---

## [How to enable CORS for all possible connections?](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 1:12pm UTC](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135 "2023-04-17T13:12:12Z")

</div>

How to enable CORS for all possible connections?

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061)

<div class="topic-metadata">

**Author:** [@Hugo\_Demont](https://discuss.elastic.co/u/Hugo_Demont)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:03pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061 "2023-04-17T13:03:10Z")

</div>

Hello ! I'm try to run elasticsearch on my linux computer to download Magento 2 when I try sudo systemctl start elasticsearch I get an error and I dont know how to solve it :confused: Error : \`avril 15 10:34:55 demon…

---

## [Clarification on end of maintenance of elastic search 8.x](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129)

<div class="topic-metadata">

**Author:** [@mohammed\_rizwan](https://discuss.elastic.co/u/mohammed_rizwan)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 12:55pm UTC](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129 "2023-04-17T12:55:01Z")

</div>

Hi team, From the Elasticsearch link Elastic Product End of Life Dates | Elastic, the Elasticsearch (8.x) end of maintenance is mentioned as "The later of 2024-08-10 or 6 months after the release date of 9.0 (TBD)". Is…

---

## [Recommended RAM/CPU size for hot data nodes in gcp](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119)

<div class="topic-metadata">

**Author:** [@alok.nashikkar](https://discuss.elastic.co/u/alok.nashikkar)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 11:16am UTC](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119 "2023-04-17T11:16:30Z")

</div>

Hello, I am exploring recommendations for infra sizing for Elasticsearch hot data nodes in GCP with recommendations for CPU and RAM for probably 3 TB SSD with machine types ex n2d/e2 or some other in similar performance…

---

## [Elasticsearch Transform API - Trying to Script a Moving Average](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115 "2023-04-17T10:43:09Z")

</div>

My use case requieres keeping the moving average over hours withing a windows of the last 12 hours, every time the transofrm is executed. It's possible to use the "pivot" "group by" to program a transform that keeps tra…

---

## [Document size, weight and performance in an automatic mapping and improve it afterwards manually](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 5:13am UTC](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085 "2023-04-17T05:13:21Z")

</div>

Is it possible to know the weight of a document in terms of bytes, to know the impact index in terms of indexing? All this in order to better optimize, to know how to configure a mapping of fields in such and such a way…

---

## [Docker-compose issue with elasticsearch and kibana docker image](https://discuss.elastic.co/t/docker-compose-issue-with-elasticsearch-and-kibana-docker-image/330067)

<div class="topic-metadata">

**Author:** [@toki0709](https://discuss.elastic.co/u/toki0709)\
**Replies:** 3\
**Last updated:** [April 16, 2023, 3:49pm UTC](https://discuss.elastic.co/t/docker-compose-issue-with-elasticsearch-and-kibana-docker-image/330067 "2023-04-16T15:49:51Z")

</div>

I am trying to create a docker-compose file with the latest image version of Elasticsearch and Kibana. Even after mentioning the version name in docker-compose.yml, I am noticing that the image version is 7.11.1 for both…

---

## [Send logs from filebeat to elastic search](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078)

<div class="topic-metadata">

**Author:** [@Abdolah\_Said](https://discuss.elastic.co/u/Abdolah_Said)\
**Replies:** 0\
**Last updated:** [April 16, 2023, 6:53am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078 "2023-04-16T06:53:10Z")

</div>

i'm using winlogbeat to send log to logstash and i store logs in file path \[ /var/log/file.log \] and i have file beat in this server who send logs from the path to elasticsearch the problem is the elasticsearch show logs…

---

## [Query questions (autocomplete)](https://discuss.elastic.co/t/query-questions-autocomplete/330047)

<div class="topic-metadata">

**Author:** [@tallboy](https://discuss.elastic.co/u/tallboy)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 10:02pm UTC](https://discuss.elastic.co/t/query-questions-autocomplete/330047 "2023-04-14T22:02:17Z")

</div>

Hello, I am trying to craft a query which will allow a realtime search dropdown: My search data has 3 columns: name (text) alternate\_names (array of text) description (text) The only column which shows in the dro…

---

## [How can I get several search results on a huge document? (like a book or a big article)](https://discuss.elastic.co/t/how-can-i-get-several-search-results-on-a-huge-document-like-a-book-or-a-big-article/329885)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [April 15, 2023, 9:47am UTC](https://discuss.elastic.co/t/how-can-i-get-several-search-results-on-a-huge-document-like-a-book-or-a-big-article/329885 "2023-04-15T09:47:35Z")

</div>

Is it possible to use elasticsearch to get several search results when preforming search on big documents? Like a book or huge articles.. So I get not only the article itself but also all the positions of relevant data…

---

## [Elasticsearch - search by two fields. And how to use one text with Text type and custom analyzer](https://discuss.elastic.co/t/elasticsearch-search-by-two-fields-and-how-to-use-one-text-with-text-type-and-custom-analyzer/330054)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 6:04am UTC](https://discuss.elastic.co/t/elasticsearch-search-by-two-fields-and-how-to-use-one-text-with-text-type-and-custom-analyzer/330054 "2023-04-15T06:04:49Z")

</div>

There is a set of data that I want to fit into Elasticsearch. Product description - a few paragraphs. I have a lot of them - about 250mln. At the same time I want to remove stop words, hunspell and a couple of other thi…

---

## [Remove Processor return an illegal\_argument\_exception error](https://discuss.elastic.co/t/remove-processor-return-an-illegal-argument-exception-error/329470)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 2:47am UTC](https://discuss.elastic.co/t/remove-processor-return-an-illegal-argument-exception-error/329470 "2023-04-06T02:47:37Z")

</div>

I want to remove some duplicated fileds' value by using remove processor in ingest pipeline. I using Elastic Agent to collect log. The problem is I always got an error in output is: "field \[field\_name\] not present as par…

---

## [Watcher's transform adds smaller number of the values](https://discuss.elastic.co/t/watchers-transform-adds-smaller-number-of-the-values/329497)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 9:07am UTC](https://discuss.elastic.co/t/watchers-transform-adds-smaller-number-of-the-values/329497 "2023-04-06T09:07:48Z")

</div>

Hi, I'd like to make watcher which will write to a certain index unique values of the particular field. A part of my query is { "query" : { "bool": { "must": \[ { "wildcard": { "field": { "value"…

---

## [Elasticsearch keyword not generated](https://discuss.elastic.co/t/elasticsearch-keyword-not-generated/330043)

<div class="topic-metadata">

**Author:** [@pjangam](https://discuss.elastic.co/u/pjangam)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:20pm UTC](https://discuss.elastic.co/t/elasticsearch-keyword-not-generated/330043 "2023-04-14T21:20:01Z")

</div>

I have Elasticsearch entry with text field value as 14-Apr-2023 20:44:46.693 INFO \[pool-2-thread-24\] com.xyz.log \[app\_id:uuid\] calling execute-task with url=https://example.com/api/applications/uuid/tasks/TASK\_NAME/exec…

---

## [How to implement a search by multiple fields and support whitespace, symbols, case insensitive](https://discuss.elastic.co/t/how-to-implement-a-search-by-multiple-fields-and-support-whitespace-symbols-case-insensitive/330030)

<div class="topic-metadata">

**Author:** [@Juan\_Manuel](https://discuss.elastic.co/u/Juan_Manuel)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 8:00pm UTC](https://discuss.elastic.co/t/how-to-implement-a-search-by-multiple-fields-and-support-whitespace-symbols-case-insensitive/330030 "2023-04-14T20:00:12Z")

</div>

I have an index with many fields and I want to be able to search by some of them at the same time, and this search should support partial match (in any position), case insensitive, support some symbols. Example of my in…

---

## [Find Unique values of field while using match query on other field](https://discuss.elastic.co/t/find-unique-values-of-field-while-using-match-query-on-other-field/330037)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 7:02pm UTC](https://discuss.elastic.co/t/find-unique-values-of-field-while-using-match-query-on-other-field/330037 "2023-04-14T19:02:34Z")

</div>

Hello, I would like find all unique set values of field3 that roll up under a specific value of field1 and a specific value of field2. I've tried collapsing on field3 but it gives me the error that no mapping was found…

---

## [Edge n-gram search for terms with optional spaces](https://discuss.elastic.co/t/edge-n-gram-search-for-terms-with-optional-spaces/330018)

<div class="topic-metadata">

**Author:** [@kedomingo](https://discuss.elastic.co/u/kedomingo)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 4:08pm UTC](https://discuss.elastic.co/t/edge-n-gram-search-for-terms-with-optional-spaces/330018 "2023-04-14T16:08:31Z")

</div>

Short version: I have "Pentium 3" and "Pentium4", in the index. I want to be able to search "Pentium 4" and get the record for "Pentium4". I want to be able to search "Pentium3" and get the record for "Pentium 3" I want…

---

## [Alternative to lookup datatype?](https://discuss.elastic.co/t/alternative-to-lookup-datatype/329836)

<div class="topic-metadata">

**Author:** [@captainzura195](https://discuss.elastic.co/u/captainzura195)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 3:53pm UTC](https://discuss.elastic.co/t/alternative-to-lookup-datatype/329836 "2023-04-14T15:53:51Z")

</div>

I wanted to populate a description field using its corresponding key, code, and another index having a key, lookup\_code, column, and a corresponding description column but without the lookup datatype I am finding it hard…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=270)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=272)
