# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=282

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 283

---

## [What is the ratio between raw data and ingested data that is stored in Elastic cluster](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 4:20pm UTC](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945 "2023-03-24T16:20:41Z")

</div>

Hi, I want to know what the ratio is between raw data and ingested data that is stored in Elastic cluster. I know raw logs and ingested logs are not same in size. Also is there any way to find the incoming raw log vol…

---

## [High availability with two servers](https://discuss.elastic.co/t/high-availability-with-two-servers/328467)

<div class="topic-metadata">

**Author:** [@amiraliw](https://discuss.elastic.co/u/amiraliw)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 2:43pm UTC](https://discuss.elastic.co/t/high-availability-with-two-servers/328467 "2023-03-24T14:43:53Z")

</div>

I have only two servers, how I should configure elasticsearch nodes to get high availability and avoid split-brain? should I only have one node on each server?

---

## [How variable width histogram with nested aggregations works](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219)

<div class="topic-metadata">

**Author:** [@rym](https://discuss.elastic.co/u/rym)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219 "2023-03-24T13:24:56Z")

</div>

Hi, I want to use the variable\_width\_histogram combined with other aggregations, such as min or max Here is an example of combinated aggregations on a numeric field: "aggs": { "aggregated-items": { …

---

## [Context suggester with search api](https://discuss.elastic.co/t/context-suggester-with-search-api/328245)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 12:13pm UTC](https://discuss.elastic.co/t/context-suggester-with-search-api/328245 "2023-03-24T12:13:09Z")

</div>

I am using Elasticsearch 7.4 and java client api. I want to use context suggester with search api given in this document Suggesters | Elasticsearch Guide \[8.6\] | Elastic can any one give me any sample documents which e…

---

## [Instantiating elasticsearch processors in custom processor](https://discuss.elastic.co/t/instantiating-elasticsearch-processors-in-custom-processor/328199)

<div class="topic-metadata">

**Author:** [@CaptainAmericaFan2](https://discuss.elastic.co/u/CaptainAmericaFan2)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 11:47am UTC](https://discuss.elastic.co/t/instantiating-elasticsearch-processors-in-custom-processor/328199 "2023-03-24T11:47:50Z")

</div>

Hi! I'm hoping to run language inference over a number of fields as documented in this blog: Multilingual search using language identification in Elasticsearch | Elastic Blog Because I want to run it over a number of fi…

---

## [Elasticsearch Cluster](https://discuss.elastic.co/t/elasticsearch-cluster/328443)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 10:03am UTC](https://discuss.elastic.co/t/elasticsearch-cluster/328443 "2023-03-24T10:03:07Z")

</div>

Could someone help me to have a cluster with a main machine that has elasticsearch and kibana and other 9 machines with only elasticsearch that are slaves.

---

## [Backfill of data stream](https://discuss.elastic.co/t/backfill-of-data-stream/328446)

<div class="topic-metadata">

**Author:** [@obi134](https://discuss.elastic.co/u/obi134)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 9:57am UTC](https://discuss.elastic.co/t/backfill-of-data-stream/328446 "2023-03-24T09:57:34Z")

</div>

Hi there, Currently we are using "normal" indexes instead of data streams in our application. But in the last days I was faced to ILM and it could be easier to implement with data streams. So I had a look if data stream…

---

## [Improve elasticsearch aggreation performance](https://discuss.elastic.co/t/improve-elasticsearch-aggreation-performance/328434)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 8:14am UTC](https://discuss.elastic.co/t/improve-elasticsearch-aggreation-performance/328434 "2023-03-24T08:14:42Z")

</div>

I am using elasticsearch aggregations to calculate counts for a faceted search. Therefore I define my general search query (e.g. status.keyword) and exlcude this filter from the status.keyword aggregation itself (the que…

---

## [.security-6 Reindex (update assistant)](https://discuss.elastic.co/t/security-6-reindex-update-assistant/328422)

<div class="topic-metadata">

**Author:** [@Moe\_Hmaidan](https://discuss.elastic.co/u/Moe_Hmaidan)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 7:33am UTC](https://discuss.elastic.co/t/security-6-reindex-update-assistant/328422 "2023-03-24T07:33:48Z")

</div>

Hello, We have a cluster running elasticsearch 7.17.7, we recently decided to work on upgrading the cluster to 8.x and everything was going well, I was working on creating a snapshot when I noticed that the system indic…

---

## [License Banned Nexus IQ Vulnerability in 7.16.2](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419)

<div class="topic-metadata">

**Author:** [@PAVK\_PRASAD](https://discuss.elastic.co/u/PAVK_PRASAD)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:31am UTC](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419 "2023-03-24T06:31:39Z")

</div>

Hi Team, We are using 7.16.2 Version of ES and we Observed "License Banned" Nexus IQ Scan issue in 7.16.2 with Elastic Search where as ES 7.10.0 doesn't have this issue. If We want go back to 7.10.0, In that version we…

---

## [Unable to do cross cluster replication , Please help here](https://discuss.elastic.co/t/unable-to-do-cross-cluster-replication-please-help-here/328345)

<div class="topic-metadata">

**Author:** [@JayaPavani\_Pathakota](https://discuss.elastic.co/u/JayaPavani_Pathakota)\
**Replies:** 10\
**Last updated:** [March 24, 2023, 6:28am UTC](https://discuss.elastic.co/t/unable-to-do-cross-cluster-replication-please-help-here/328345 "2023-03-24T06:28:14Z")

</div>

I created two clusters in 2 data centers and I am trying to do cross cluster replication , in one of the cluster I configured leader index and in the other I did the remote configuration pointing to the cluster of leader…

---

## [Hide size parameter from URL](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397)

<div class="topic-metadata">

**Author:** [@ach](https://discuss.elastic.co/u/ach)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397 "2023-03-24T06:18:14Z")

</div>

Hi all, I want to hide the size parameter from the search query URL, e.g., site.com/?q=phone&size=n\_10\_n and I want to hide '&size=n\_10\_n.' Is configuring the routing options the way to go? I would greatly appreciate i…

---

## [Hyperthreading effects on Elasticsearch performance](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 3:39am UTC](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402 "2023-03-24T03:39:48Z")

</div>

Hi team, What's the current recommendations regarding Hyper Threading with Elasticsearch, do we get any benefits and are there any downsides to keep HT enabled? I've seen multiple performance tests documents which clai…

---

## [Kubernetes deployment - Elastic Search](https://discuss.elastic.co/t/kubernetes-deployment-elastic-search/328384)

<div class="topic-metadata">

**Author:** [@aharo-lumificyber](https://discuss.elastic.co/u/aharo-lumificyber)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 1:21am UTC](https://discuss.elastic.co/t/kubernetes-deployment-elastic-search/328384 "2023-03-24T01:21:57Z")

</div>

We currently use Elasticsearch through the Azure implementation but is getting too expensive, and I would like to know the procedure to host my own image of Elasticsearch and kibana through kubernetes. Do I need to pay f…

---

## [Multiple search criteria](https://discuss.elastic.co/t/multiple-search-criteria/328400)

<div class="topic-metadata">

**Author:** [@Sheng111](https://discuss.elastic.co/u/Sheng111)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 10:52pm UTC](https://discuss.elastic.co/t/multiple-search-criteria/328400 "2023-03-23T22:52:49Z")

</div>

Hi there, one common question, how to do multiple criteria search using elasticsearch UI? for example I search for attribute A==5 and attribute B within recent 3 months; is this possible to combine above 2 filter criter…

---

## [How does document update work under the hood?](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392)

<div class="topic-metadata">

**Author:** [@egalpin](https://discuss.elastic.co/u/egalpin)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 9:10pm UTC](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392 "2023-03-23T21:10:32Z")

</div>

Hi all! I’m curious to learn about how the process of document update (and upsert/partial upsert) works under the hood. I know that Lucene segments are immutable and that “deleting” a doc is a soft delete by way of tomb…

---

## [Fscrawler - change the index mapping，reduce redundant field or object](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296)

<div class="topic-metadata">

**Author:** [@bolo](https://discuss.elastic.co/u/bolo)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 8:04pm UTC](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296 "2023-03-23T20:04:04Z")

</div>

i am new to fscrawler and really appreciate it. i know, the mapping can be changed. But to which content？just the analyzer? or the field type ? or the whole structure(because i dont want too much inner object). thank you …

---

## [Strip array off of ndjson data set using elasticsearch pipeline](https://discuss.elastic.co/t/strip-array-off-of-ndjson-data-set-using-elasticsearch-pipeline/328118)

<div class="topic-metadata">

**Author:** [@nika](https://discuss.elastic.co/u/nika)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 6:44pm UTC](https://discuss.elastic.co/t/strip-array-off-of-ndjson-data-set-using-elasticsearch-pipeline/328118 "2023-03-23T18:44:08Z")

</div>

Hello, I have data being ingested into elasticsearch (currently using version 7.3) sent to it from filebeat (7.3). The logs are in ndjson format. A section of the data is in the format {"tagset": {"username": { "domain…

---

## [WARN message when trying to install on windows 10](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348)

<div class="topic-metadata">

**Author:** [@Ene\_Dragos](https://discuss.elastic.co/u/Ene_Dragos)\
**Replies:** 10\
**Last updated:** [March 23, 2023, 4:08pm UTC](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348 "2023-03-23T16:08:19Z")

</div>

Hi! I'm trying to install elasticsearch on windows and i've followed the guid on here: Install Elasticsearch with .zip on Windows | Elasticsearch Guide \[8.6\] | Elastic. The issue is, when I try to configure Elasticsearc…

---

## [Kafka sink Connector to Elasticsearch](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:20pm UTC](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361 "2023-03-23T15:20:15Z")

</div>

I am trying to set up ingestion pipeline to elasticsearch cluster via kafka sink connector. A question I have is if I have a doc that haas multiple json objects like this: \[ {"name":"abc", "company":"123","dept":"test"…

---

## [Filebeat is not pushing the documents to kibana (through elasticsearch)](https://discuss.elastic.co/t/filebeat-is-not-pushing-the-documents-to-kibana-through-elasticsearch/328358)

<div class="topic-metadata">

**Author:** [@Maneesh545](https://discuss.elastic.co/u/Maneesh545)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 2:56pm UTC](https://discuss.elastic.co/t/filebeat-is-not-pushing-the-documents-to-kibana-through-elasticsearch/328358 "2023-03-23T14:56:04Z")

</div>

I am using the below configuration in filebeat.yml to push the logs into kibana to visualize. Initially documents used to flow into kibana but since last couple of days the documents are not flowing through elasticsear…

---

## [KNN search speed](https://discuss.elastic.co/t/knn-search-speed/326961)

<div class="topic-metadata">

**Author:** [@dendog1](https://discuss.elastic.co/u/dendog1)\
**Replies:** 11\
**Last updated:** [March 23, 2023, 2:38pm UTC](https://discuss.elastic.co/t/knn-search-speed/326961 "2023-03-23T14:38:07Z")

</div>

Hi! Today we are using ES mainly as a key / value store where most of our reads are just get by key. We have recently started to use KNN, where we have: Around 10MM docs. 384 dim vectors. Using cosine sim as the metr…

---

## [Slow aKNN search](https://discuss.elastic.co/t/slow-aknn-search/326915)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 6\
**Last updated:** [March 23, 2023, 2:30pm UTC](https://discuss.elastic.co/t/slow-aknn-search/326915 "2023-03-23T14:30:50Z")

</div>

We have implemented vector similarity search using ES dense\_vector field and KNN option in the search API. We are using 1024 dimension embeddings and our index size is about 60 Gb for approx 11\_000\_000 documents. So our…

---

## [Can't join elastic to microsoft active directory ldap](https://discuss.elastic.co/t/cant-join-elastic-to-microsoft-active-directory-ldap/326514)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 16\
**Last updated:** [March 23, 2023, 2:05pm UTC](https://discuss.elastic.co/t/cant-join-elastic-to-microsoft-active-directory-ldap/326514 "2023-03-23T14:05:36Z")

</div>

Hi ldap users can't login on kibana: here is the log when user attempt to login: Feb 26 11:55:21 logdev kibana\[1784685\]: \[2023-02-26T11:55:21.243+03:30\]\[INFO \]\[plugins.security.routes\] Logging in with provider "bas…

---

## [Elasticsearch NoShardAvailableActionException](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279)

<div class="topic-metadata">

**Author:** [@Lohanna\_Sarah](https://discuss.elastic.co/u/Lohanna_Sarah)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279 "2023-03-23T13:35:51Z")

</div>

Suppose a cluster is composed of three data nodes. If one of the nodes throws the exception "NoShardAvailableActionException", what is the impact on the cluster and how is the request handled? Specifically, is the reques…

---

## [How to search a piece of URI](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 8\
**Last updated:** [March 23, 2023, 12:36pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342 "2023-03-23T12:36:28Z")

</div>

I want to search a piece of URL. I am using the sample weblogs in elasticsearch. If I analyze the field: GET /\_analyze { "analyzer" : "standard", "text" : \["http://nytimes.com/success/kevin-Kregel"\] } I get: { "…

---

## [Regex lookahead in painless](https://discuss.elastic.co/t/regex-lookahead-in-painless/328268)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 12:17pm UTC](https://discuss.elastic.co/t/regex-lookahead-in-painless/328268 "2023-03-23T12:17:25Z")

</div>

Is it possible to use regex with lookahead in Painless? I want to match a pattern in a string starting with a certain expression and ending before a certain expression.

---

## [Cluster en elastic search; error: main process exited, failed with result 'exit-code'](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 11:37am UTC](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337 "2023-03-23T11:37:24Z")

</div>

I am trying to create a cluster with two machines and I am trying to configure the /etc/elasticsearch/elasticsearch.yml file but I get an error. I am attaching code captures. The attached screenshot is from the ma…

---

## [How to add an inner field as a source field in ML inference pipeline?](https://discuss.elastic.co/t/how-to-add-an-inner-field-as-a-source-field-in-ml-inference-pipeline/328323)

<div class="topic-metadata">

**Author:** [@848bb15cf6e891bef7ba](https://discuss.elastic.co/u/848bb15cf6e891bef7ba)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-to-add-an-inner-field-as-a-source-field-in-ml-inference-pipeline/328323 "2023-03-23T11:21:18Z")

</div>

Hi, I am trying out vector search. While creating a Machine Learning Inference Pipeline, I see that some fields in the index are not recognised. Only the top level fields are shown. Consider the below example with fiel…

---

## [ElasticSearch - Java layered search BoolQueryBuilder](https://discuss.elastic.co/t/elasticsearch-java-layered-search-boolquerybuilder/328256)

<div class="topic-metadata">

**Author:** [@Sachin\_Sharma](https://discuss.elastic.co/u/Sachin_Sharma)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 9:21am UTC](https://discuss.elastic.co/t/elasticsearch-java-layered-search-boolquerybuilder/328256 "2023-03-23T09:21:50Z")

</div>

I have data in Elastic. Elastic data is as below. Name Parties Parties is array of objects that contains partyCode and displayCode { "query": { "bool": { "should": \[ { "bool": { "must": \[ …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=281)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=283)
