# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=288

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 289

---

## [Is it possible to "conditionaly" analyze same field differently? \[synonyms\]](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 3:16pm UTC](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441 "2023-03-13T15:16:46Z")

</div>

Hi there, The index contains 3 business units, the goal is to provide different set of synonyms for each BU. The field is unstructured text (PDF rendition), occupying 95% of overall index storage, currently analyzed t…

---

## [Does every index have its own shard?](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526)

<div class="topic-metadata">

**Author:** [@emrethedev](https://discuss.elastic.co/u/emrethedev)\
**Replies:** 10\
**Last updated:** [March 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526 "2023-03-13T15:02:47Z")

</div>

Hi, (Sorry if this is a double post but i could not find answer.) Does every index have its own shard or may they have common shards? We know that when we create an index, it has 5 shards by default. So when we create a…

---

## [Geohash\_grid aggregation in opensearch](https://discuss.elastic.co/t/geohash-grid-aggregation-in-opensearch/327553)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 2:41pm UTC](https://discuss.elastic.co/t/geohash-grid-aggregation-in-opensearch/327553 "2023-03-13T14:41:35Z")

</div>

Hi. I'm gettin this error when trying "geohash\_grid" aggregation in java opensearch api. Seems opensearch doesn't have geohash\_grid aggregation type, So what can be the analog? "aggs": { "filter\_agg": { "filt…

---

## [Aggregation on specific object in an array](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 1:27pm UTC](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533 "2023-03-13T13:27:33Z")

</div>

Hi, So my document has a structure as below. I would like to aggregate based on \*\*value\*\*, but only on the object with {"label": "Business Priority"}. Can you help how I can achieve this?

---

## [Elastic Cloud showing "Unhealthy" but all zones are "Healthy"](https://discuss.elastic.co/t/elastic-cloud-showing-unhealthy-but-all-zones-are-healthy/327482)

<div class="topic-metadata">

**Author:** [@matto](https://discuss.elastic.co/u/matto)\
**Replies:** 8\
**Last updated:** [March 13, 2023, 1:26pm UTC](https://discuss.elastic.co/t/elastic-cloud-showing-unhealthy-but-all-zones-are-healthy/327482 "2023-03-13T13:26:00Z")

</div>

We are running Magneto 2.4 using Elastic hosted on Elastic.co. Elastic Cloud version 7.17 due to Magento 2.4 requirements. Recently our Elastic Cloud is showing "Unhealthy" but all zones are "Healthy" - screenshot atta…

---

## [Are there any limits to the number of snapshot repositories?](https://discuss.elastic.co/t/are-there-any-limits-to-the-number-of-snapshot-repositories/327541)

<div class="topic-metadata">

**Author:** [@John\_Newman1](https://discuss.elastic.co/u/John_Newman1)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 1:23pm UTC](https://discuss.elastic.co/t/are-there-any-limits-to-the-number-of-snapshot-repositories/327541 "2023-03-13T13:23:27Z")

</div>

Hi, I'm looking to backup a lot of historical indices, for now and going into the future, we have two a day going back till 2010. For our use case we'd like to set the base\_path per index, this means that we'll need to …

---

## [Transport error 429](https://discuss.elastic.co/t/transport-error-429/327528)

<div class="topic-metadata">

**Author:** [@Susendiran](https://discuss.elastic.co/u/Susendiran)\
**Replies:** 5\
**Last updated:** [March 13, 2023, 10:48am UTC](https://discuss.elastic.co/t/transport-error-429/327528 "2023-03-13T10:48:31Z")

</div>

Hi Team, We are getting elasticsearch exceptions - transport error 429 while providing es.search command using python pandas for some large set of data(upto 13-15k records). It's showing the limit is more than the thres…

---

## [Adding extra field in filebeat](https://discuss.elastic.co/t/adding-extra-field-in-filebeat/327534)

<div class="topic-metadata">

**Author:** [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 9:08am UTC](https://discuss.elastic.co/t/adding-extra-field-in-filebeat/327534 "2023-03-13T09:08:29Z")

</div>

filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different inputs for various configurations. # Below are the input specific configurations. - type: log # Change to t…

---

## [NOT STRING IN ARRAY IN WATCHER](https://discuss.elastic.co/t/not-string-in-array-in-watcher/327421)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 10:18am UTC](https://discuss.elastic.co/t/not-string-in-array-in-watcher/327421 "2023-03-13T10:18:19Z")

</div>

Hi team! I'm trying to setup a watcher for finding a way to check if an array has not a string value, but i getting stuck, could someone have an idea?

---

## [Enabling multiple snapshot operations in ES 6.5.4](https://discuss.elastic.co/t/enabling-multiple-snapshot-operations-in-es-6-5-4/327536)

<div class="topic-metadata">

**Author:** [@Het\_Desai](https://discuss.elastic.co/u/Het_Desai)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 10:16am UTC](https://discuss.elastic.co/t/enabling-multiple-snapshot-operations-in-es-6-5-4/327536 "2023-03-13T10:16:29Z")

</div>

We have ES 6.5.4 and using S3 repository in our different machines. We move data from one machine to another using snapshot/restore process. Now only 1 concurrent snapshot operation is allowed per machine. If we do some …

---

## [Adding only the appended part of a file to elastic using logstash](https://discuss.elastic.co/t/adding-only-the-appended-part-of-a-file-to-elastic-using-logstash/327520)

<div class="topic-metadata">

**Author:** [@aks03](https://discuss.elastic.co/u/aks03)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 4:37am UTC](https://discuss.elastic.co/t/adding-only-the-appended-part-of-a-file-to-elastic-using-logstash/327520 "2023-03-13T04:37:35Z")

</div>

Hey everyone, I am new to Elk stack but currently I want to add only the appended part of a file i.e, any extra content added to the file to elastic using logstash 6.3. The files are unstructured so even that has left …

---

## [ILM doesn't rollover](https://discuss.elastic.co/t/ilm-doesnt-rollover/327497)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 1\
**Last updated:** [March 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/ilm-doesnt-rollover/327497 "2023-03-12T16:46:56Z")

</div>

Hello all, can any one help me to get the ILM wrong, I created ILM for support the retention period so everything is well but the new rollover indices doesn't store any data (the docs count is 0), I need to move the da…

---

## [Help with http certs in elasticsearch](https://discuss.elastic.co/t/help-with-http-certs-in-elasticsearch/327371)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 5\
**Last updated:** [March 12, 2023, 1:11pm UTC](https://discuss.elastic.co/t/help-with-http-certs-in-elasticsearch/327371 "2023-03-12T13:11:19Z")

</div>

I used elasticsearch-certutil with my companies CA.jks to create http certificates for my node but I am at the last step to send the output zip file to the path I give I get the following error: Exception in thread "mai…

---

## [Curator 8 not showing all indexes](https://discuss.elastic.co/t/curator-8-not-showing-all-indexes/327381)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 2\
**Last updated:** [March 12, 2023, 12:17pm UTC](https://discuss.elastic.co/t/curator-8-not-showing-all-indexes/327381 "2023-03-12T12:17:07Z")

</div>

I am usining : pip install -U elasticsearch-curator to get version 8 ran: curator --dry-run --config ./curator.yml ./delete\_log\_files\_curator.yml action file :slight\_smile: actions: 1: action: delete\_indices …

---

## [How to filter buckets based on the comparison of two sub-aggregation metrics in ElasticSearch (python)?](https://discuss.elastic.co/t/how-to-filter-buckets-based-on-the-comparison-of-two-sub-aggregation-metrics-in-elasticsearch-python/327498)

<div class="topic-metadata">

**Author:** [@Ashar\_Ahmad](https://discuss.elastic.co/u/Ashar_Ahmad)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-filter-buckets-based-on-the-comparison-of-two-sub-aggregation-metrics-in-elasticsearch-python/327498 "2023-03-12T08:59:20Z")

</div>

My index has documents with the following fields: user\_id, user\_name, post\_text, post\_sentiment where post\_sentiment is of type double, and represents the sentiment of the post. A post\_sentiment greater than 0 indicates …

---

## [Unbale to view logs but indices available](https://discuss.elastic.co/t/unbale-to-view-logs-but-indices-available/327496)

<div class="topic-metadata">

**Author:** [@Prabhakar\_D](https://discuss.elastic.co/u/Prabhakar_D)\
**Replies:** 6\
**Last updated:** [March 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/unbale-to-view-logs-but-indices-available/327496 "2023-03-12T08:20:08Z")

</div>

Hi, ELK uable to view logs for specific period but indices available. Someone please suggest how to recover the indices which is already rolledup as per lifecycle

---

## [How Translog Work on elastic](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [March 11, 2023, 10:35am UTC](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880 "2023-03-11T10:35:29Z")

</div>

Hi everyone, I have a question about translog. So here is the situation: I have one index with 1 primary and 1 replica shard and continuously ingesting data. If i read documentation, it says that primary and replica sh…

---

## [Going from data nodes to hot and warm nodes](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 8:36pm UTC](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311 "2023-03-10T20:36:01Z")

</div>

Lab Environment: 3 Master and 2 Data nodes. Just sent some data to cluster without building custom templates or ILM policies or mappings. I added 2 more Data nodes and made the first two Hot and the new 2 Warm nodes p…

---

## [Connect sql server database to elasticsearch](https://discuss.elastic.co/t/connect-sql-server-database-to-elasticsearch/327465)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 4:23pm UTC](https://discuss.elastic.co/t/connect-sql-server-database-to-elasticsearch/327465 "2023-03-10T16:23:56Z")

</div>

I want to connect sql server database to elasticsearch without copying the sql data to elasticsearch, with a simple call of the sql data or simple connection , without loading the data from sql server to elasticsearch I…

---

## [The stack cannot be started according to the instructions](https://discuss.elastic.co/t/the-stack-cannot-be-started-according-to-the-instructions/327431)

<div class="topic-metadata">

**Author:** [@alexanderzhirov](https://discuss.elastic.co/u/alexanderzhirov)\
**Replies:** 13\
**Last updated:** [March 10, 2023, 4:00pm UTC](https://discuss.elastic.co/t/the-stack-cannot-be-started-according-to-the-instructions/327431 "2023-03-10T16:00:14Z")

</div>

I'm trying to run the stack in docker according to this instruction. My .env: # Password for the 'elastic' user (at least 6 characters) ELASTIC\_PASSWORD=elastic # Password for the 'kibana\_system' user (at least 6 char…

---

## [Is it possible to move a one time snapshot to Glacier?](https://discuss.elastic.co/t/is-it-possible-to-move-a-one-time-snapshot-to-glacier/327455)

<div class="topic-metadata">

**Author:** [@John\_Newman1](https://discuss.elastic.co/u/John_Newman1)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 2:41pm UTC](https://discuss.elastic.co/t/is-it-possible-to-move-a-one-time-snapshot-to-glacier/327455 "2023-03-10T14:41:09Z")

</div>

Hi, In the docs, it states that after snapshotting an index to S3 you shouldn't transition it to Glacier. I have a use case where I would like to snapshot an index as a one off event and store it as cheaply as possible,…

---

## [Nested aggregation Error](https://discuss.elastic.co/t/nested-aggregation-error/327451)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 1:50pm UTC](https://discuss.elastic.co/t/nested-aggregation-error/327451 "2023-03-10T13:50:01Z")

</div>

So, I have my mappings as this and my query request object as referred to \[this link\](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-nested-aggregation.html) Query JSON { …

---

## [Error Loading data into ElasticSearch using Azure Data Factory - Zappysys connector](https://discuss.elastic.co/t/error-loading-data-into-elasticsearch-using-azure-data-factory-zappysys-connector/327442)

<div class="topic-metadata">

**Author:** [@gau\_prpce](https://discuss.elastic.co/u/gau_prpce)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 10:58am UTC](https://discuss.elastic.co/t/error-loading-data-into-elasticsearch-using-azure-data-factory-zappysys-connector/327442 "2023-03-10T10:58:33Z")

</div>

I was trying to load data from azure postgresql to elasticsearch through ADF copy activity using Zappysys connector. Facing this issue. Failure happened on 'Sink' side. ErrorCode=UserErrorOdbcOperationFailed,'Type=Micr…

---

## [How to create managed indexes with current date in names?](https://discuss.elastic.co/t/how-to-create-managed-indexes-with-current-date-in-names/327312)

<div class="topic-metadata">

**Author:** [@maar](https://discuss.elastic.co/u/maar)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 12:46pm UTC](https://discuss.elastic.co/t/how-to-create-managed-indexes-with-current-date-in-names/327312 "2023-03-10T12:46:10Z")

</div>

How to setup ILM policies with dates in the names of the indexes? Here's the setup that works (without dates): PUT \_index\_template/index-test { "index\_patterns": \["index-test-\*"\], "template": { …

---

## [How can I delete unnassigned shards?](https://discuss.elastic.co/t/how-can-i-delete-unnassigned-shards/327433)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 10:56am UTC](https://discuss.elastic.co/t/how-can-i-delete-unnassigned-shards/327433 "2023-03-10T10:56:03Z")

</div>

In my cluster there are unassigned shards which are not primary shards. I don't know why I have these secondary shards in my cluster. I didn't create them intentionally and I use the default configuration (elasticsearch…

---

## [How to remove the empty result set caused by bucket\_selector?](https://discuss.elastic.co/t/how-to-remove-the-empty-result-set-caused-by-bucket-selector/327430)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 10:48am UTC](https://discuss.elastic.co/t/how-to-remove-the-empty-result-set-caused-by-bucket-selector/327430 "2023-03-10T10:48:13Z")

</div>

This operation will show you my problem. 1、Create Index PUT car { "mappings": { "properties": { "color": { "type": "keyword" }, "company": { "type": "keyword" }, "pri…

---

## [Finding similar/related news articles process](https://discuss.elastic.co/t/finding-similar-related-news-articles-process/327427)

<div class="topic-metadata">

**Author:** [@cyril\_g](https://discuss.elastic.co/u/cyril_g)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 9:12am UTC](https://discuss.elastic.co/t/finding-similar-related-news-articles-process/327427 "2023-03-10T09:12:15Z")

</div>

Hello, I am working on a news app in the gaming industry and I would like to be able to identify headlines/ articles with titles about the same subject. One thing to note is that games and platforms have many alternati…

---

## [Cannot race. too many values to unpack (expected 2) error while benchmarking](https://discuss.elastic.co/t/cannot-race-too-many-values-to-unpack-expected-2-error-while-benchmarking/327214)

<div class="topic-metadata">

**Author:** [@amitsa](https://discuss.elastic.co/u/amitsa)\
**Replies:** 8\
**Last updated:** [March 10, 2023, 9:02am UTC](https://discuss.elastic.co/t/cannot-race-too-many-values-to-unpack-expected-2-error-while-benchmarking/327214 "2023-03-10T09:02:08Z")

</div>

/ /\_/ / \_\_ \`/ / / / / / \[pod/benchmark-rb8nf/benchmark\] / \_, \_/ /\_/ / / / /\_/ / \[pod/benchmark-rb8nf/benchmark\] /\_/ |\_|\\\_\_,\_/\_/\_/\\\_\_, / \[pod/benchmark-rb8nf/benchmark\] /\_\_\_\_/ \[pod/benchmark-rb8nf/benchma…

---

## [How much user can login at same time for basic license ELK version 8.0.0](https://discuss.elastic.co/t/how-much-user-can-login-at-same-time-for-basic-license-elk-version-8-0-0/327383)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 8:21am UTC](https://discuss.elastic.co/t/how-much-user-can-login-at-same-time-for-basic-license-elk-version-8-0-0/327383 "2023-03-10T08:21:59Z")

</div>

Hi Team, I am using basic license of ELK version 8.0.0 , wanted to know how many user can login at same time we are using a docker image for setting it up.

---

## [How to filter the buckets that have more than N documents using ElasticSearch DSL in python?](https://discuss.elastic.co/t/how-to-filter-the-buckets-that-have-more-than-n-documents-using-elasticsearch-dsl-in-python/327412)

<div class="topic-metadata">

**Author:** [@Ashar\_Ahmad](https://discuss.elastic.co/u/Ashar_Ahmad)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 4:41am UTC](https://discuss.elastic.co/t/how-to-filter-the-buckets-that-have-more-than-n-documents-using-elasticsearch-dsl-in-python/327412 "2023-03-10T04:41:09Z")

</div>

I have an index in Elasticsearch that contains information of a user in each document, along with the facebook posts they have made (in a denormalized manner). Each document contains: User\_ID | User\_Name | Post\_Text | P…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=287)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=289)
