# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=284

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 285

---

## [To Know about Legacy Index Template](https://discuss.elastic.co/t/to-know-about-legacy-index-template/327180)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 3\
**Last updated:** [March 21, 2023, 3:25pm UTC](https://discuss.elastic.co/t/to-know-about-legacy-index-template/327180 "2023-03-21T15:25:06Z")

</div>

Hi Team, We changed the ILM of one of the index from 10days to 7days, but we can see the Legacy index templates still showing ILM as 10days. If present ILM of 7days doesn't work, will it consider the older ILM of 10day…

---

## [Filtering two different nested fields in the same agg](https://discuss.elastic.co/t/filtering-two-different-nested-fields-in-the-same-agg/328169)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 1:55pm UTC](https://discuss.elastic.co/t/filtering-two-different-nested-fields-in-the-same-agg/328169 "2023-03-21T13:55:39Z")

</div>

I understand how to filter on two nested fields using sub aggregations and get individual doc\_counts out of them, but I want to filter and count one nested field by the value of another nested field. eg: Imagine a docu…

---

## [Request API to obtain active alerts](https://discuss.elastic.co/t/request-api-to-obtain-active-alerts/326461)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 1:27pm UTC](https://discuss.elastic.co/t/request-api-to-obtain-active-alerts/326461 "2023-03-21T13:27:45Z")

</div>

Hello everyone, On the Kibana interface I have a rule called "No logs from docker", this is a "Log threshold" rule which should tell me when I have not received a log containing the "event.dataset" with value "docker.co…

---

## [Merge 2 Clusters with same name](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 12:09pm UTC](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065 "2023-03-21T12:09:20Z")

</div>

Hi Team, Is there any way where we can merge 2 clusters with same name to 1. Scenario is... will have an existing cluster with name xyz and have some data. Will create additional cluster in different nodes with same na…

---

## [Is there a way to get less used/searched logs in Elasticsearch](https://discuss.elastic.co/t/is-there-a-way-to-get-less-used-searched-logs-in-elasticsearch/328081)

<div class="topic-metadata">

**Author:** [@Amulya\_Nanda](https://discuss.elastic.co/u/Amulya_Nanda)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 11:24am UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-less-used-searched-logs-in-elasticsearch/328081 "2023-03-21T11:24:07Z")

</div>

Hi Team, We are looking to list out less usage logs in Elasticsearch. For example: we have logs getting ingested from many setups. We wanted to query/ or list out less used logs from setups basis. How can we get the d…

---

## [Ingest logs from S3 bucket](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 10:25am UTC](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155 "2023-03-21T10:25:43Z")

</div>

Currently i am using elk stack to ingest only warning and errors logs to Elasticsearch server. Also i am using elastic beanstalk to rotate logs to S3 bucket. Now as i ingest only warning and error logs sometimes i need …

---

## [Import from Azure Log Analytics Workspace](https://discuss.elastic.co/t/import-from-azure-log-analytics-workspace/328144)

<div class="topic-metadata">

**Author:** [@tigerkungen](https://discuss.elastic.co/u/tigerkungen)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:57am UTC](https://discuss.elastic.co/t/import-from-azure-log-analytics-workspace/328144 "2023-03-21T08:57:41Z")

</div>

What is the recommended design for importing logs from Azure Log Analytics Workspace to Elastic Cloud? Read somewhere that you could export direct to elastic via the advanced menu in Azure Log Analytics workspace. But …

---

## [Sending data from 2 logstash nodes to an elasticsearch cluster](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 6:29am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128 "2023-03-21T06:29:34Z")

</div>

Hi Folks, I have 2 logstash nodes (version -8.6.2) that i want to send data to 2 elasticsearch nodes (version -8.6.2) ( a third node will be added soon to the cluster) . Do i just mention the elasticsearch nodes' in t…

---

## [Sort on multiple fields Not working](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 6:27am UTC](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131 "2023-03-21T06:27:58Z")

</div>

Hi, I'm trying to sort on multiple fields like - sort on field1 first if there is a tie on field1, sort based on field 2. POST sort\_logic/\_doc { "field1" : 4, "field2" : "4" } POST sort\_logic/\_doc { "field1" : …

---

## [Elasticsearch Java Client create query for field with list of values](https://discuss.elastic.co/t/elasticsearch-java-client-create-query-for-field-with-list-of-values/328040)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 1:59pm UTC](https://discuss.elastic.co/t/elasticsearch-java-client-create-query-for-field-with-list-of-values/328040 "2023-03-20T13:59:32Z")

</div>

String searchText = "TEST"; .query(q -\> q.bool(b -\> b .must(c-\> c .match(t -\> t .field("FI…

---

## [Sort based on absolute value](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 5:36am UTC](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078 "2023-03-21T05:36:07Z")

</div>

Hi, I'm looking to sort documents based on a field of long type by their absolute value. So, the change field has both positive and negative numbers. "change" : { "type" : "long" } I want to sort it in such a way th…

---

## [Index\_failed number is increasing after adding a new node to elasticsearch cluster(previously single node)](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 5:32am UTC](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098 "2023-03-21T05:32:45Z")

</div>

Hi Folks, Today i added a new node to a previously single -node elasticsearch cluster and the process was successful . however when i look at the node stats (via the node stats API) it shows the index\_failed numbers to …

---

## [What the better way, create 400 columns with types keyword, text, float, date and boolean in index or 5 nested fields?](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123)

<div class="topic-metadata">

**Author:** [@Yuri\_Khmelevsky](https://discuss.elastic.co/u/Yuri_Khmelevsky)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123 "2023-03-21T04:02:18Z")

</div>

What is the better for read and write performance? And in general is this good idea to store 400 columns in index (I know that I can store 1000 columns per index by default). I expect that one documents will have 5-15 t…

---

## [How to join two indexes or use an index as a lookup](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 1:19am UTC](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073 "2023-03-21T01:19:15Z")

</div>

I have log indexes with 500 million records daily in one index (logs-20230320,logs-20230321,...) And i have malicious IP addresses list ( ~150.000 records) in another index (blacklist-202303) (rebuilt every day) I need…

---

## [Scripted fields in pyspark](https://discuss.elastic.co/t/scripted-fields-in-pyspark/328092)

<div class="topic-metadata">

**Author:** [@nissan15](https://discuss.elastic.co/u/nissan15)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 10:41pm UTC](https://discuss.elastic.co/t/scripted-fields-in-pyspark/328092 "2023-03-20T22:41:12Z")

</div>

Hey, Is it possible to use scripted fields using pyspark? if so how can I use it? and if not - how can I query field and convert the field from float to integer in the query itself? thanks

---

## [Issue with apache Tika Extraction for Tabular Column Data in PDF](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080)

<div class="topic-metadata">

**Author:** [@Sai\_Kiran\_solix](https://discuss.elastic.co/u/Sai_Kiran_solix)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 9:05pm UTC](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080 "2023-03-20T21:05:04Z")

</div>

I extracted a PDF that has tabular column data using apache Tika, in the result the row data from different columns are getting merged Before Extracting | Column A | Column B | | -------- | -------- | | 1 | saikiran | |…

---

## [My Runtime Script is not returning a value](https://discuss.elastic.co/t/my-runtime-script-is-not-returning-a-value/327217)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 8:33pm UTC](https://discuss.elastic.co/t/my-runtime-script-is-not-returning-a-value/327217 "2023-03-20T20:33:10Z")

</div>

Hello, I have created a runtime field named "user". My goal is to extract the username (user=Bob) from a 'event.original' mapping which looks like this: "event.original": \[ "Mar 7 10:17:44 Bob gdm-password\]\[15454…

---

## [RPM signing key is invalid on newer operating systems](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 7:04pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476 "2023-03-20T19:04:59Z")

</div>

The signing key used for RPM packages (and I assume other package types) is no longer valid on newer operating systems since the key is SHA1 and these newer operating systems have deprecated SHA1. Specifically, I'm tryi…

---

## [My elasticsearch is not running with error code 128](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892)

<div class="topic-metadata">

**Author:** [@Terry\_2018](https://discuss.elastic.co/u/Terry_2018)\
**Replies:** 9\
**Last updated:** [March 20, 2023, 6:54pm UTC](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892 "2023-03-20T18:54:02Z")

</div>

Hi. I'm using Elasticsearch 8.6.2 on Ubuntu 22.04. Since a few days ago, my elastic is not running. Please help me. The system output is below. dev@logserver:~$ sudo systemctl status elasticsearch × elasticsearch.se…

---

## [Allocation Failed](https://discuss.elastic.co/t/allocation-failed/328097)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 5:58pm UTC](https://discuss.elastic.co/t/allocation-failed/328097 "2023-03-20T17:58:03Z")

</div>

Hi, I've got many error messages like that: { "index" : "logstash-prod\_operations\_clear-001098", "shard" : 0, "primary" : false, "current\_state" : "unassigned", "unassigned\_info" : { "reason" : "ALLOCATIO…

---

## [Does Rally support benchmark the performance about deleting a type of documents?](https://discuss.elastic.co/t/does-rally-support-benchmark-the-performance-about-deleting-a-type-of-documents/328033)

<div class="topic-metadata">

**Author:** [@gloriacs](https://discuss.elastic.co/u/gloriacs)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 4:53pm UTC](https://discuss.elastic.co/t/does-rally-support-benchmark-the-performance-about-deleting-a-type-of-documents/328033 "2023-03-20T16:53:08Z")

</div>

Hi all, I want to use Rally to benchmark the performance of deleting documents instead of deleting an index. Like, delete all documents from that specific day. I know elasticsearch support that by using delete\_by\_query …

---

## [Unable to configure curator to archive data from Elasticsearch](https://discuss.elastic.co/t/unable-to-configure-curator-to-archive-data-from-elasticsearch/323354)

<div class="topic-metadata">

**Author:** [@Pendela-BhargavaSai](https://discuss.elastic.co/u/Pendela-BhargavaSai)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/unable-to-configure-curator-to-archive-data-from-elasticsearch/323354 "2023-03-20T15:37:39Z")

</div>

Hi I am a newbie to Elastic search. In my project we are working on archiving data using Curator. I am trying to configure the curator with Elasticsearch but unable to do that. I am facing some connectivity issues for c…

---

## [Prefix and port appear flipped in es-hadoop implementation](https://discuss.elastic.co/t/prefix-and-port-appear-flipped-in-es-hadoop-implementation/328072)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 3:01pm UTC](https://discuss.elastic.co/t/prefix-and-port-appear-flipped-in-es-hadoop-implementation/328072 "2023-03-20T15:01:51Z")

</div>

Attempting to read/write with es-hadoop however I am getting the following error in Databricks EsHadoopInvalidRequest: \[HEAD\] on \[index\_name\] failed; server \[https://serveraddress.com/es:443\] returned \[405|Method Not Al…

---

## [How to write elastic search query for one required parameter and another optional paramater](https://discuss.elastic.co/t/how-to-write-elastic-search-query-for-one-required-parameter-and-another-optional-paramater/328089)

<div class="topic-metadata">

**Author:** [@Phoenix1990](https://discuss.elastic.co/u/Phoenix1990)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 2:39pm UTC](https://discuss.elastic.co/t/how-to-write-elastic-search-query-for-one-required-parameter-and-another-optional-paramater/328089 "2023-03-20T14:39:33Z")

</div>

I need to create an Elasticsearch endpoint with two paramater : Session(required field),CallType(Optional) which returns call details bewteen Teacher and student. I can search for specific session with below details. My …

---

## [Transform for change between states](https://discuss.elastic.co/t/transform-for-change-between-states/328082)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 2:06pm UTC](https://discuss.elastic.co/t/transform-for-change-between-states/328082 "2023-03-20T14:06:27Z")

</div>

Hi All I have a large index that is populated using logstash with a Kafka input ~200m documents in it. We are building a pretty conmplex dashboard based on the data from that index I need some guidance on how I can bui…

---

## [\[half\_float\] parsing error](https://discuss.elastic.co/t/half-float-parsing-error/328057)

<div class="topic-metadata">

**Author:** [@Raul\_Uria](https://discuss.elastic.co/u/Raul_Uria)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:51pm UTC](https://discuss.elastic.co/t/half-float-parsing-error/328057 "2023-03-20T13:51:00Z")

</div>

Hi, I can´t understand why my data is not parsed. I got this on my logs: status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[MyFIELD-NAME\] of type \[half\_float\] in document with …

---

## [Not able to sort on Long field and Function score also not working](https://discuss.elastic.co/t/not-able-to-sort-on-long-field-and-function-score-also-not-working/328077)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:27pm UTC](https://discuss.elastic.co/t/not-able-to-sort-on-long-field-and-function-score-also-not-working/328077 "2023-03-20T13:27:15Z")

</div>

Hello, I am performing a simple query and sorting on a field (Long Type). It is not sorting. { "from":0, "size": 5000, "query" : { "match\_all" : {} }, "sort":\[ { "sort\_field"…

---

## [Solr to Elasticsearh Migration Size Differance](https://discuss.elastic.co/t/solr-to-elasticsearh-migration-size-differance/327915)

<div class="topic-metadata">

**Author:** [@bilgicsin](https://discuss.elastic.co/u/bilgicsin)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 11:24am UTC](https://discuss.elastic.co/t/solr-to-elasticsearh-migration-size-differance/327915 "2023-03-20T11:24:21Z")

</div>

Hi Everyone, We have Solr and Elasticsearch in our company and we want to do a benchmark test to decide for buying extra license. We tried to transfer 4 gb Solr collection to an elasticsearch indice. We query the whole …

---

## [Unable to Tessellate shape (Polygon)](https://discuss.elastic.co/t/unable-to-tessellate-shape-polygon/327850)

<div class="topic-metadata">

**Author:** [@Shaheryar\_Mahmood](https://discuss.elastic.co/u/Shaheryar_Mahmood)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 11:00am UTC](https://discuss.elastic.co/t/unable-to-tessellate-shape-polygon/327850 "2023-03-20T11:00:06Z")

</div>

I'm having an issue while indexing the polygon below. What's wrong in the shape Elasticsearch version 7.7. {"error":{"root\_cause":\[{"type":"mapper\_parsing\_exception","reason":"failed to parse field \[location\] of type \[g…

---

## [How to index the PDF documents](https://discuss.elastic.co/t/how-to-index-the-pdf-documents/327987)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 8\
**Last updated:** [March 20, 2023, 10:36am UTC](https://discuss.elastic.co/t/how-to-index-the-pdf-documents/327987 "2023-03-20T10:36:03Z")

</div>

How to index the PDF and image documents into elasticsearch. Would like to extract the entities to enable the search on keywords. Whether the workplace search provide this functionality? Whether Apache Tika has been used…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=283)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=285)
