# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=278

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 279

---

## [In elasticsearch finding documents which meet a specific criteria for the latest for each group](https://discuss.elastic.co/t/in-elasticsearch-finding-documents-which-meet-a-specific-criteria-for-the-latest-for-each-group/329023)

<div class="topic-metadata">

**Author:** [@m.a.tanaka](https://discuss.elastic.co/u/m.a.tanaka)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 5:17pm UTC](https://discuss.elastic.co/t/in-elasticsearch-finding-documents-which-meet-a-specific-criteria-for-the-latest-for-each-group/329023 "2023-03-31T17:17:38Z")

</div>

I am trying to create a query in elasticsearch, which is able to retrieve the documents for each group, which is the latest document within each group and meet a specific criteria. But I have not been able to solve this …

---

## [Elasticsearch backup - S3 repository](https://discuss.elastic.co/t/elasticsearch-backup-s3-repository/328773)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 4:09pm UTC](https://discuss.elastic.co/t/elasticsearch-backup-s3-repository/328773 "2023-03-31T16:09:14Z")

</div>

Hi All, We're backing up the Elasticsearch cluster indices to a S3 bucket (S3 repository by snapshot API), daily backup is around 1TB, and deleting the snapshots older than 30 days. Total size of S3 bucket is more than …

---

## [Java API client : How to reset index settings value](https://discuss.elastic.co/t/java-api-client-how-to-reset-index-settings-value/329059)

<div class="topic-metadata">

**Author:** [@MathieuLacour](https://discuss.elastic.co/u/MathieuLacour)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 3:02pm UTC](https://discuss.elastic.co/t/java-api-client-how-to-reset-index-settings-value/329059 "2023-03-31T15:02:40Z")

</div>

For performance reasons, I need to temporarily disable refresh\_interval at index settings level while bulk loading takes place in the index, and enable it back afterwards. The refresh\_interval value is held by global cl…

---

## [Es restore \[parent\] data too large](https://discuss.elastic.co/t/es-restore-parent-data-too-large/329016)

<div class="topic-metadata">

**Author:** [@huang1](https://discuss.elastic.co/u/huang1)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 12:34pm UTC](https://discuss.elastic.co/t/es-restore-parent-data-too-large/329016 "2023-03-31T12:34:37Z")

</div>

The total data size of es is less than 1G. Perform a regular restore. After running for a period of time, throw the \[parent\] data too large. The node executing the restore has a high xmx and a high CPU utilization rate\_ …

---

## [Version\_conflict\_engine\_exception errors with status 409](https://discuss.elastic.co/t/version-conflict-engine-exception-errors-with-status-409/328855)

<div class="topic-metadata">

**Author:** [@Fernando\_Oliveira](https://discuss.elastic.co/u/Fernando_Oliveira)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 12:13pm UTC](https://discuss.elastic.co/t/version-conflict-engine-exception-errors-with-status-409/328855 "2023-03-31T12:13:14Z")

</div>

Hello, I clean my indexes in the elastic with the script below: POST /aplicacao/\_delete\_by\_query { "query": { "range": { "timeLog": { "lte": "now-5M" } } } } "aplicacao " is the name of the index, I leave …

---

## [Passing dynamic values to range query](https://discuss.elastic.co/t/passing-dynamic-values-to-range-query/329037)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 9:48am UTC](https://discuss.elastic.co/t/passing-dynamic-values-to-range-query/329037 "2023-03-31T09:48:24Z")

</div>

In kibana discover, with Elasticsearch Query DSL, I want to search for a range of timestamp dynamically here is the range I used: { "range": { "@timestamp": { "gte": "2023-03-03T15:0…

---

## [Function score weight rounding score If value is high](https://discuss.elastic.co/t/function-score-weight-rounding-score-if-value-is-high/329043)

<div class="topic-metadata">

**Author:** [@eerkisi](https://discuss.elastic.co/u/eerkisi)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 11:10am UTC](https://discuss.elastic.co/t/function-score-weight-rounding-score-if-value-is-high/329043 "2023-03-31T11:10:22Z")

</div>

Hello, We have function scores and functions which manipulate scores by some filters etc. We set one of the function score weight as high numbers because of the our business. Also we need fraction of the value to be abl…

---

## [Creating customised reference values based on lagged information](https://discuss.elastic.co/t/creating-customised-reference-values-based-on-lagged-information/329036)

<div class="topic-metadata">

**Author:** [@NiklasHBB](https://discuss.elastic.co/u/NiklasHBB)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 9:38am UTC](https://discuss.elastic.co/t/creating-customised-reference-values-based-on-lagged-information/329036 "2023-03-31T09:38:29Z")

</div>

What is the best way to create reference values which are based on past information in Elasticsearch? My current use case involves detailling in Kibana how the values for a day, week or month relate to past developments…

---

## [Curl command to delete cluster settings](https://discuss.elastic.co/t/curl-command-to-delete-cluster-settings/329019)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 9:15am UTC](https://discuss.elastic.co/t/curl-command-to-delete-cluster-settings/329019 "2023-03-31T09:15:54Z")

</div>

Hi Team, Is there any API where i can utilize to delete the cluster settings? I have configured the cluster settings to use sniff mode but when i tried to change that to proxy mode, i am getting error that its already …

---

## [Configure Username and password](https://discuss.elastic.co/t/configure-username-and-password/328913)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 9:11am UTC](https://discuss.elastic.co/t/configure-username-and-password/328913 "2023-03-31T09:11:47Z")

</div>

How to configure the username and password while running elasticsearch in Docker without docker-compose.

---

## [Date range not working as expected between Elasticsearch 7.17 and Elasticsearch 8.6](https://discuss.elastic.co/t/date-range-not-working-as-expected-between-elasticsearch-7-17-and-elasticsearch-8-6/328825)

<div class="topic-metadata">

**Author:** [@MarynaCherniavska](https://discuss.elastic.co/u/MarynaCherniavska)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 8:50am UTC](https://discuss.elastic.co/t/date-range-not-working-as-expected-between-elasticsearch-7-17-and-elasticsearch-8-6/328825 "2023-03-31T08:50:08Z")

</div>

We're exploring a move from (self-managed) Elasticsearch 7.17 to Elasticsearch 8.6. Some of the tests on the application fail if we switch. We traced the failure to an inconsistency between the results on the range using…

---

## [Elasticsearch installation using helm chart ..Used nfs-storageclass](https://discuss.elastic.co/t/elasticsearch-installation-using-helm-chart-used-nfs-storageclass/329025)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-installation-using-helm-chart-used-nfs-storageclass/329025 "2023-03-31T08:40:44Z")

</div>

ERROR: {"@timestamp":"2023-03-31T08:10:14.942Z", "log.level":"ERROR", "message":"uncaught exception in thread \[process reaper (pid 228)\]", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elasticsearch.se…

---

## [What should the bucket path be with a top hits](https://discuss.elastic.co/t/what-should-the-bucket-path-be-with-a-top-hits/329024)

<div class="topic-metadata">

**Author:** [@m.a.tanaka](https://discuss.elastic.co/u/m.a.tanaka)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 8:16am UTC](https://discuss.elastic.co/t/what-should-the-bucket-path-be-with-a-top-hits/329024 "2023-03-31T08:16:17Z")

</div>

I am trying to create a query in elasticsearch, which is able to retrieve the documents for each group, which is the latest document within each group and meet a specific criteria. But I have not been able to solve this …

---

## [Autocompletion by most popular phrases in the text](https://discuss.elastic.co/t/autocompletion-by-most-popular-phrases-in-the-text/329012)

<div class="topic-metadata">

**Author:** [@Quaerere](https://discuss.elastic.co/u/Quaerere)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 6:52am UTC](https://discuss.elastic.co/t/autocompletion-by-most-popular-phrases-in-the-text/329012 "2023-03-31T06:52:59Z")

</div>

Let's say I have many text fields indexed: { "body": "The quick brown fox jumps over the lazy dog" } { "body": "There was a quick brown fox in a forest" } { "body": "Forest was a most fun place for a lazy dog to…

---

## ["Internal Server error" while pulling the data from elastic search](https://discuss.elastic.co/t/internal-server-error-while-pulling-the-data-from-elastic-search/328898)

<div class="topic-metadata">

**Author:** [@zameer712](https://discuss.elastic.co/u/zameer712)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 6:46am UTC](https://discuss.elastic.co/t/internal-server-error-while-pulling-the-data-from-elastic-search/328898 "2023-03-31T06:46:28Z")

</div>

Hello team, we are using Elastic cloud on Azure and all the versions of kibana, filebeat , Elasticsearch is 8.6.2 right now. Facing an issue respect to one of our API please help by checking below error { "id": "c70b…

---

## [API: Exporting the data into CSV file](https://discuss.elastic.co/t/api-exporting-the-data-into-csv-file/328967)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 6:05am UTC](https://discuss.elastic.co/t/api-exporting-the-data-into-csv-file/328967 "2023-03-31T06:05:09Z")

</div>

Is there any API which supports the exports of data in CSV format from elasticsearch?

---

## [Elasticsearch 5.5.1 version not reflecting after installation on debian based system](https://discuss.elastic.co/t/elasticsearch-5-5-1-version-not-reflecting-after-installation-on-debian-based-system/328831)

<div class="topic-metadata">

**Author:** [@beju](https://discuss.elastic.co/u/beju)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 4:36am UTC](https://discuss.elastic.co/t/elasticsearch-5-5-1-version-not-reflecting-after-installation-on-debian-based-system/328831 "2023-03-31T04:36:05Z")

</div>

wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-5.5.1.deb sha1sum elasticsearch-5.5.1.deb sudo dpkg -i elasticsearch-5.5.1.deb n# curl -XGET 'http://localhost:9200' { "name" : "advance365", …

---

## [Will legacy index template work after version 8 upgrade?](https://discuss.elastic.co/t/will-legacy-index-template-work-after-version-8-upgrade/327908)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 8\
**Last updated:** [March 31, 2023, 3:26am UTC](https://discuss.elastic.co/t/will-legacy-index-template-work-after-version-8-upgrade/327908 "2023-03-31T03:26:29Z")

</div>

Hello team, I currently working on cluster with version 7.17.7 and now I am thinking of upgrading it to version 8.x. I received an API deprecation log that Legacy index templates are deprecated in favor of composable te…

---

## [Issue when installing Elasticsearch using helm by staying in rancher](https://discuss.elastic.co/t/issue-when-installing-elasticsearch-using-helm-by-staying-in-rancher/328827)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 11:15pm UTC](https://discuss.elastic.co/t/issue-when-installing-elasticsearch-using-helm-by-staying-in-rancher/328827 "2023-03-30T23:15:23Z")

</div>

my values.yaml file antiAffinity: hard antiAffinityTopologyKey: kubernetes.io/hostname clusterHealthCheckParams: wait\_for\_status=green&timeout=1s clusterName: elasticsearch createCert: true enableServiceLinks: tru…

---

## [Does multinode cluster require different certificates or just one will suffice?](https://discuss.elastic.co/t/does-multinode-cluster-require-different-certificates-or-just-one-will-suffice/328963)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 11:05pm UTC](https://discuss.elastic.co/t/does-multinode-cluster-require-different-certificates-or-just-one-will-suffice/328963 "2023-03-30T23:05:56Z")

</div>

Hey team, I have a multi node cluster running which has a hot warm architecture. I have multiple hot nodes running on a single machine as docker images and multiple warm nodes running on another machine(this is also a s…

---

## [doc\['LogMessage.keyword'\].size() returns 0 meaning there is no such field when that field exists and has value](https://discuss.elastic.co/t/doc-logmessage-keyword-size-returns-0-meaning-there-is-no-such-field-when-that-field-exists-and-has-value/328665)

<div class="topic-metadata">

**Author:** [@skazan](https://discuss.elastic.co/u/skazan)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 10:04pm UTC](https://discuss.elastic.co/t/doc-logmessage-keyword-size-returns-0-meaning-there-is-no-such-field-when-that-field-exists-and-has-value/328665 "2023-03-30T22:04:52Z")

</div>

I coded a scripted field named "unique\_log\_message\_\_" as show below. The whole purpose of such field is to show a unique version of some other field named "LogMessage.keyword". And to get into a unique value, I simply re…

---

## [Is there a quick and easy way to check if my node is running in compressed oop?](https://discuss.elastic.co/t/is-there-a-quick-and-easy-way-to-check-if-my-node-is-running-in-compressed-oop/328971)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 9:48pm UTC](https://discuss.elastic.co/t/is-there-a-quick-and-easy-way-to-check-if-my-node-is-running-in-compressed-oop/328971 "2023-03-30T21:48:52Z")

</div>

version 7.15.3

---

## [JVM Heap size larger than 32 GB](https://discuss.elastic.co/t/jvm-heap-size-larger-than-32-gb/328869)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 9:35pm UTC](https://discuss.elastic.co/t/jvm-heap-size-larger-than-32-gb/328869 "2023-03-30T21:35:11Z")

</div>

We have several machines with 512 GB of RAM and I wanted to know if we can set JVM heap size for Elasticsearch larger than 32 GB (up to 256 GB). This page says we should keep the heap size below the threshold for compre…

---

## [Elasticsearch static settings - per node?](https://discuss.elastic.co/t/elasticsearch-static-settings-per-node/328691)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 7\
**Last updated:** [March 30, 2023, 9:30pm UTC](https://discuss.elastic.co/t/elasticsearch-static-settings-per-node/328691 "2023-03-30T21:30:21Z")

</div>

Hi, I am trying to understand the logic behind the static settings. I am trying to keep all nodes with the same configuration/settings where possible, but I'm curios and want to validate about the right way of doing it…

---

## [Configuration as Code for Elasticsearch](https://discuss.elastic.co/t/configuration-as-code-for-elasticsearch/328449)

<div class="topic-metadata">

**Author:** [@sonnenhund](https://discuss.elastic.co/u/sonnenhund)\
**Replies:** 14\
**Last updated:** [March 30, 2023, 9:17pm UTC](https://discuss.elastic.co/t/configuration-as-code-for-elasticsearch/328449 "2023-03-30T21:17:46Z")

</div>

Hi! We are attempting to stand up a full ELK stack and wish to have Elasticsearch fully configured, including ILM policies, Index Templates, and if necessary bootstrapping indices, such that when data begins flowing int…

---

## [Joining instances to form cluster](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 6:23pm UTC](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860 "2023-03-30T18:23:46Z")

</div>

reference:ERROR: Failed to determine the health of the cluster - #7 by DRW-ATCA My goal is to create a 6-instance cluster in a private VPC (AWS), 1 master, 5 data nodes, with additional instances hosting Kibana and rela…

---

## [ERROR: Failed to determine the health of the cluster](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 11\
**Last updated:** [March 30, 2023, 5:20pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746 "2023-03-30T17:20:52Z")

</div>

I am trying to add nodes to a cluster for ES 8.6.2 in an AWS EC2 environment. After creating a master node and the first of several data nodes, the two instances give healthy responses to the following commands but do n…

---

## [Date Histogram doesn't work with calendar\_interval month](https://discuss.elastic.co/t/date-histogram-doesnt-work-with-calendar-interval-month/328848)

<div class="topic-metadata">

**Author:** [@Tobse](https://discuss.elastic.co/u/Tobse)\
**Replies:** 8\
**Last updated:** [March 30, 2023, 3:24pm UTC](https://discuss.elastic.co/t/date-histogram-doesnt-work-with-calendar-interval-month/328848 "2023-03-30T15:24:01Z")

</div>

I have tried to use a group\_by with a date\_histogram by month. Our example works like expected with "calendar\_interval": "day" but returns nothing with "calendar\_interval": "month". In fact it seems wo work with day, wee…

---

## [How to distribute Primary & Replica shards equally across the nodes](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950 "2023-03-30T15:03:05Z")

</div>

Hi Team, I have Elastic cluster with 3 Master, 5 Data & 2 Client nodes. I have created index called my-index with 5 Primary and 1 Replica also i used setting called number of shards per node is 2. But i could see at f…

---

## [Match query with specific order of terms](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936)

<div class="topic-metadata">

**Author:** [@Rafael\_Kubina](https://discuss.elastic.co/u/Rafael_Kubina)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 2:09pm UTC](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936 "2023-03-30T14:09:14Z")

</div>

We need to match a set of terms in a field while taking the order into account. Example: The document: { "my\_field": "foo bar" } It should match when the user search for foo bar, foo bar baz or baz foo bar but no…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=277)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=279)
