# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=292

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 293

---

## [How to enforce ordering within nested objects?](https://discuss.elastic.co/t/how-to-enforce-ordering-within-nested-objects/326889)

<div class="topic-metadata">

**Author:** [@pure](https://discuss.elastic.co/u/pure)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 9:19pm UTC](https://discuss.elastic.co/t/how-to-enforce-ordering-within-nested-objects/326889 "2023-03-02T21:19:27Z")

</div>

I'm using elasticsearch as a Key-Value store, so that I can guarantee the query always return just 1 document. There is a nested field in the document schema, and I want to make sure multiple values within the nested obj…

---

## [Custom TF-IDF implementation](https://discuss.elastic.co/t/custom-tf-idf-implementation/326872)

<div class="topic-metadata">

**Author:** [@Karel\_Haerens1](https://discuss.elastic.co/u/Karel_Haerens1)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 3:32pm UTC](https://discuss.elastic.co/t/custom-tf-idf-implementation/326872 "2023-03-02T15:32:29Z")

</div>

I'm trying to implement a custom TF-IDF-like algorithm with scripted similarity, my current approach: The way term frequency is determined is custom, these values are precalculated and stored in the records as lists. as…

---

## [WordPress plugin needed](https://discuss.elastic.co/t/wordpress-plugin-needed/326797)

<div class="topic-metadata">

**Author:** [@Peter\_Lipschutz](https://discuss.elastic.co/u/Peter_Lipschutz)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 2:24pm UTC](https://discuss.elastic.co/t/wordpress-plugin-needed/326797 "2023-03-02T14:24:23Z")

</div>

We want to implement an elasticsearch database that we can access through our WordPress site. We want to create a separate db in elasticsearch. It will NOT be used to search the WP MySQL db. I need to figure out what plu…

---

## [Max Number of data nodes per machines](https://discuss.elastic.co/t/max-number-of-data-nodes-per-machines/326788)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 1:41pm UTC](https://discuss.elastic.co/t/max-number-of-data-nodes-per-machines/326788 "2023-03-02T13:41:13Z")

</div>

Hi, I want to install few data nodes on one machines. Each data node will get 32GB RAM. Is there any formula for getting the max number of nodes per machine CPU and RAM? Thanks

---

## [Create and Deploy custom ML models for NLP](https://discuss.elastic.co/t/create-and-deploy-custom-ml-models-for-nlp/326777)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 12:57pm UTC](https://discuss.elastic.co/t/create-and-deploy-custom-ml-models-for-nlp/326777 "2023-03-02T12:57:22Z")

</div>

Hello, I've read the documentation on ML and deploying ML models Overview | Machine Learning in the Elastic Stack \[8.6\] | Elastic. Does anyone have examples of how to do the following: Create a custom ML model that f…

---

## [How to correctly determine the weight of a node](https://discuss.elastic.co/t/how-to-correctly-determine-the-weight-of-a-node/224871)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 1\
**Last updated:** [March 2, 2023, 9:59am UTC](https://discuss.elastic.co/t/how-to-correctly-determine-the-weight-of-a-node/224871 "2023-03-02T09:59:41Z")

</div>

Hey Team, I'm trying to calculate the weights of each node based on the below two settings taken from shard balancing heuristics: cluster.routing.allocation.balance.shard cluster.routing.allocation.balance.index Let's…

---

## [What are the strengths of 'Rally' compared to 'JMeter' or 'nGrinder'?](https://discuss.elastic.co/t/what-are-the-strengths-of-rally-compared-to-jmeter-or-ngrinder/326266)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 9:07am UTC](https://discuss.elastic.co/t/what-are-the-strengths-of-rally-compared-to-jmeter-or-ngrinder/326266 "2023-03-02T09:07:12Z")

</div>

What are the strengths of 'Rally' compared to 'JMeter' or 'nGrinder'? I have used 'Rally' before, but have not used 'Apache JMeter' or 'nGrinder'. Are there any relative advantages and disadvantages HAVE A GOOD DAY …

---

## [Blank spaces in Elastic monitoring indicating possible problems?](https://discuss.elastic.co/t/blank-spaces-in-elastic-monitoring-indicating-possible-problems/326828)

<div class="topic-metadata">

**Author:** [@Lay0ut](https://discuss.elastic.co/u/Lay0ut)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 8:13am UTC](https://discuss.elastic.co/t/blank-spaces-in-elastic-monitoring-indicating-possible-problems/326828 "2023-03-02T08:13:40Z")

</div>

Hello everyone, starting this week i noticed that there are occasional gaps in the monitoring graph of my elastic cluster. I wonder if these could indicate a possible problem with the cluster and what could cause these: …

---

## [Error when searching in a specific field](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734)

<div class="topic-metadata">

**Author:** [@Thoriqul\_Umar](https://discuss.elastic.co/u/Thoriqul_Umar)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 4:14am UTC](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734 "2023-03-02T04:14:51Z")

</div>

hello, I got error "failed to connect to console's backed. please check the kibana server is up and running" when tried to search on field "file\_content". here is my query { "query": { "multi\_match": { "qu…

---

## [Elasticsearch Indexing Issues](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768)

<div class="topic-metadata">

**Author:** [@H-Soni](https://discuss.elastic.co/u/H-Soni)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 11:54pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768 "2023-03-01T23:54:56Z")

</div>

Hi, We have a 5-node cluster, currently running ES 5.6.11. When there's an increased load in indexing, heap usage reaches 90% in one of the nodes, while some have only 40-50% heap usage. Because of this, elasticsearch t…

---

## [Need Help - with \_update\_by\_query query several indexes for two fields (one is optional)](https://discuss.elastic.co/t/need-help-with-update-by-query-query-several-indexes-for-two-fields-one-is-optional/326786)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 4:37pm UTC](https://discuss.elastic.co/t/need-help-with-update-by-query-query-several-indexes-for-two-fields-one-is-optional/326786 "2023-03-01T16:37:49Z")

</div>

Need help- with \_update\_by\_query to query several indexes for two fields (one is optional, for the indexes where the field exists). I was doing two separate update by query, one when the index' document has a field com…

---

## [Problema al agregar certificado de empresa en Elasticsearch Centos 7](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806)

<div class="topic-metadata">

**Author:** [@DARWIN\_PEREZ](https://discuss.elastic.co/u/DARWIN_PEREZ)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:40pm UTC](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806 "2023-03-01T21:40:24Z")

</div>

kibana server is not ready yet

---

## [I cannot update template](https://discuss.elastic.co/t/i-cannot-update-template/326775)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775 "2023-03-01T16:33:40Z")

</div>

I updated the template of filebeat in the elasticsearch node. It returned me an error: { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping definition has unsupported …

---

## [Rollover Errors](https://discuss.elastic.co/t/rollover-errors/325272)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 4:23pm UTC](https://discuss.elastic.co/t/rollover-errors/325272 "2023-03-01T16:23:34Z")

</div>

Hello I have been working on some code to be able to rollover my syslogs so that it will continue to populate the Kibana. I am getting the following error in the Dev Tools Illegal argument exception rollover target is…

---

## [Jupyter spark connect to elasticsearch](https://discuss.elastic.co/t/jupyter-spark-connect-to-elasticsearch/326585)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 11\
**Last updated:** [March 1, 2023, 3:14pm UTC](https://discuss.elastic.co/t/jupyter-spark-connect-to-elasticsearch/326585 "2023-03-01T15:14:21Z")

</div>

I'm trying to connect from spark to elasticsearch , so as first I've build docker images from spark3.2.1 for kubernetes then from jupyter notebook I've opened a session to spark a build the context to elasticsearch on t…

---

## [Filestream processing of CSV files](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 2:22pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704 "2023-03-01T14:22:23Z")

</div>

Hi all, I'm slowly migrating over to filestream to process some log files and have data coming in and stored into the message field. Here is an example: ec26.515d.ebcf,someUser,GSS-A-1FL-122,SD35 What I would like to …

---

## [ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688)

<div class="topic-metadata">

**Author:** [@senix](https://discuss.elastic.co/u/senix)\
**Replies:** 5\
**Last updated:** [March 1, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688 "2023-03-01T06:32:05Z")

</div>

We're using streamsets to send messages to Elasticsearch and are consistently getting the following error: ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms We've tried vario…

---

## [Improving resiliency or changing settings of system indices](https://discuss.elastic.co/t/improving-resiliency-or-changing-settings-of-system-indices/326108)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 1:45am UTC](https://discuss.elastic.co/t/improving-resiliency-or-changing-settings-of-system-indices/326108 "2023-03-01T01:45:22Z")

</div>

Hi, I'm trying to improve the resiliency of my elastic stack. I want to make it tolerant to any two node failures, but I can't update system indices to have more than one replica. The setting in question is index.auto…

---

## [Search all indexes for document's parameter name or retrieve one document p/index](https://discuss.elastic.co/t/search-all-indexes-for-documents-parameter-name-or-retrieve-one-document-p-index/325175)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 5\
**Last updated:** [February 28, 2023, 10:48pm UTC](https://discuss.elastic.co/t/search-all-indexes-for-documents-parameter-name-or-retrieve-one-document-p-index/325175 "2023-02-28T22:48:31Z")

</div>

Hi I am a bit new in elastic and started in a project that has more than 800 indexes and I need to rename some old names to the new ones requested. I already found some indexes that has parameters with values that need …

---

## [Update\_By\_Query in elasticsearch\_dsl matches \<field\> but doesn't match \<object\>.\<field\>](https://discuss.elastic.co/t/update-by-query-in-elasticsearch-dsl-matches-field-but-doesnt-match-object-field/325889)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 10:33pm UTC](https://discuss.elastic.co/t/update-by-query-in-elasticsearch-dsl-matches-field-but-doesnt-match-object-field/325889 "2023-02-28T22:33:56Z")

</div>

I managed to do an update\_by\_query script with elasticsearch\_dsl. response = ubq.script(source="pm\_data\_source.hw\_alias' = params.new\_ap\_name",lang="painless",params={"new\_ap\_name": new\_ap})\\ .query("match", pm\_…

---

## [Changing index settings when closed can corrupt an index](https://discuss.elastic.co/t/changing-index-settings-when-closed-can-corrupt-an-index/326705)

<div class="topic-metadata">

**Author:** [@dwilches](https://discuss.elastic.co/u/dwilches)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 8:13pm UTC](https://discuss.elastic.co/t/changing-index-settings-when-closed-can-corrupt-an-index/326705 "2023-02-28T20:13:07Z")

</div>

I found a warning in this documentation page about updating index settings while they are closed: Changing static or dynamic index settings on a closed index could result in incorrect settings that are impossible to re…

---

## [Fleet API account missing security settings](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 6:32pm UTC](https://discuss.elastic.co/t/fleet-api-account-missing-security-settings/325643 "2023-02-28T18:32:11Z")

</div>

Hi all, I'm on v8.6 of the ELK stack and working on some new custom log parsing. It looks like the configuration is reading our initial test data properly, however it appears the built-in Fleet API account is missing so…

---

## [Got error "The bulk request must be terminated by a newline \[\\\\n\]" when importing data with curl and insomnia](https://discuss.elastic.co/t/got-error-the-bulk-request-must-be-terminated-by-a-newline-n-when-importing-data-with-curl-and-insomnia/326697)

<div class="topic-metadata">

**Author:** [@Kalimink](https://discuss.elastic.co/u/Kalimink)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 5:08pm UTC](https://discuss.elastic.co/t/got-error-the-bulk-request-must-be-terminated-by-a-newline-n-when-importing-data-with-curl-and-insomnia/326697 "2023-02-28T17:08:08Z")

</div>

Hello, after several attempts to integrate my data which are in json form via Curl and even insomnia I always get the same error : "The bulk request must be terminated by a newline \[\\n\]" but even after adding a newlin…

---

## [Telemetry Devices and Rally 2.7.0](https://discuss.elastic.co/t/telemetry-devices-and-rally-2-7-0/326638)

<div class="topic-metadata">

**Author:** [@Safty](https://discuss.elastic.co/u/Safty)\
**Replies:** 3\
**Last updated:** [February 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/telemetry-devices-and-rally-2-7-0/326638 "2023-02-28T15:57:32Z")

</div>

Hello, fellow elastic/rally kids. Does Rally 2.7.0 support Telemetry Devices? If so is the expectation that all tracks are supported? Meaning you can run any telemetry devices listed under 'esrally list telemetry'. …

---

## [ANN Search: ElasticSearch vs FAISS](https://discuss.elastic.co/t/ann-search-elasticsearch-vs-faiss/326653)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 3:29pm UTC](https://discuss.elastic.co/t/ann-search-elasticsearch-vs-faiss/326653 "2023-02-28T15:29:54Z")

</div>

As i know, Elasticsearch 8.x support for knn search with hnsw index by default, so i try to compare elasticsearch vs faiss (hnsw index), i set both elasticsearch and faiss with same parameter (m=32, efconstruct=128, efs…

---

## [Having trouble running elasticsearch](https://discuss.elastic.co/t/having-trouble-running-elasticsearch/326528)

<div class="topic-metadata">

**Author:** [@bawac](https://discuss.elastic.co/u/bawac)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 2:37pm UTC](https://discuss.elastic.co/t/having-trouble-running-elasticsearch/326528 "2023-02-28T14:37:06Z")

</div>

I am trying to run elasticsearch from my terminal and I'm getting this error: warning: ignoring JAVA\_HOME=/usr/lib/jvm/java-11-openjdk-arm64; using bundled JDK Dynarec for ARM64, with extension: ASIMD AES CRC32 PMULL AT…

---

## [Possible bug with monitoring creating thousands of elasticsearch.index.recovery duplicate docs](https://discuss.elastic.co/t/possible-bug-with-monitoring-creating-thousands-of-elasticsearch-index-recovery-duplicate-docs/324673)

<div class="topic-metadata">

**Author:** [@sparrowt](https://discuss.elastic.co/u/sparrowt)\
**Replies:** 5\
**Last updated:** [February 28, 2023, 1:41pm UTC](https://discuss.elastic.co/t/possible-bug-with-monitoring-creating-thousands-of-elasticsearch-index-recovery-duplicate-docs/324673 "2023-02-28T13:41:19Z")

</div>

Since upgrading to 8.x and (via cloud.elastic.co) enabling Monitoring \> Logs and metrics \> Ship to a deployment, I was surprised at the volume of data arriving into the .monitoring-es-8-mb datastream. On investigation i…

---

## [GET DATA FROM PAYLOAD IN ILM WATCHER](https://discuss.elastic.co/t/get-data-from-payload-in-ilm-watcher/326680)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 11:41am UTC](https://discuss.elastic.co/t/get-data-from-payload-in-ilm-watcher/326680 "2023-02-28T11:41:45Z")

</div>

Hi to all!! I'm trying to get the index with ILM errors, so i created a watcher like this: { "trigger": { "schedule": { "interval": "10m" } }, "input": { "http": { "request": { "scheme": "https", "host": "$host", "port…

---

## [Explain API parsing and displaying tools](https://discuss.elastic.co/t/explain-api-parsing-and-displaying-tools/326677)

<div class="topic-metadata">

**Author:** [@Eylon\_Koren1](https://discuss.elastic.co/u/Eylon_Koren1)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 11:35am UTC](https://discuss.elastic.co/t/explain-api-parsing-and-displaying-tools/326677 "2023-02-28T11:35:18Z")

</div>

Hey ! I'm using the Elasticsearch Explain API in order to understand the ES internal scoring. The explain results is complex json, which i extract the impact of each field on the query overall score. Are there any too…

---

## [Inconsistent AWS Opensearch ingest attachment processor behaviour](https://discuss.elastic.co/t/inconsistent-aws-opensearch-ingest-attachment-processor-behaviour/326602)

<div class="topic-metadata">

**Author:** [@pcvijayvignesh](https://discuss.elastic.co/u/pcvijayvignesh)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 11:26am UTC](https://discuss.elastic.co/t/inconsistent-aws-opensearch-ingest-attachment-processor-behaviour/326602 "2023-02-28T11:26:53Z")

</div>

We are using AWS OpenSearch for one of our application. We have configured ingest attachment processor for extracting text from .docx files. Here is our environment setup details, Note: For DEV/QA, we use same instance…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=291)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=293)
