# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=298

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 299

---

## [What happens when the document data has special characters like "party-planning" or "Michelle\_obama" ? I see that Elasticsearch includes them in the hit. how do we ignore such documents? Is Elasticsearch case sensitive?](https://discuss.elastic.co/t/what-happens-when-the-document-data-has-special-characters-like-party-planning-or-michelle-obama-i-see-that-elasticsearch-includes-them-in-the-hit-how-do-we-ignore-such-documents-is-elasticsearch-case-sensitive/325901)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 1:17am UTC](https://discuss.elastic.co/t/what-happens-when-the-document-data-has-special-characters-like-party-planning-or-michelle-obama-i-see-that-elasticsearch-includes-them-in-the-hit-how-do-we-ignore-such-documents-is-elasticsearch-case-sensitive/325901 "2023-02-19T01:17:32Z")

</div>

Two questions: What happens when the document data has special characters like "party-planning" or "Michelle\_obama" ? I see that Elasticsearch includes them in the hit. how do we ignore such documents? Is Elasticsearch…

---

## [Elasticsearch node HTTP layer SSL configuration Keystore doesn't contain any PrivateKey entries where the associated certificate is a CA certificate](https://discuss.elastic.co/t/elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/325713)

<div class="topic-metadata">

**Author:** [@Behzad\_Nazemi](https://discuss.elastic.co/u/Behzad_Nazemi)\
**Replies:** 4\
**Last updated:** [February 18, 2023, 11:37am UTC](https://discuss.elastic.co/t/elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/325713 "2023-02-18T11:37:06Z")

</div>

Dear Elastic Team, Would you please help us with this issue? The new nodes could not join the cluster since we can not create a token for nodes. The http.p12 is already created and contained a PrivateKey but the error i…

---

## [Question about minimum requirements per zone on Elastic Cloud](https://discuss.elastic.co/t/question-about-minimum-requirements-per-zone-on-elastic-cloud/325861)

<div class="topic-metadata">

**Author:** [@lengoyvaerts](https://discuss.elastic.co/u/lengoyvaerts)\
**Replies:** 1\
**Last updated:** [February 18, 2023, 6:38am UTC](https://discuss.elastic.co/t/question-about-minimum-requirements-per-zone-on-elastic-cloud/325861 "2023-02-18T06:38:35Z")

</div>

When setting up a new deployment on Elastic Cloud, it is recommended to use minimum hardware requirements per zone, depending on the chosen provider. Using less could affect the performance of your deployment. Why is…

---

## [Shodan.io query return json mapping, nested dynamic mapping](https://discuss.elastic.co/t/shodan-io-query-return-json-mapping-nested-dynamic-mapping/325761)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 8:52pm UTC](https://discuss.elastic.co/t/shodan-io-query-return-json-mapping-nested-dynamic-mapping/325761 "2023-02-17T20:52:13Z")

</div>

hi, i'm using some python to query shodan.io, it returns a reasonably complex json that i'd like to push into Elasticsearch. i've got most mapped out and its work, but there is one field i just cant to map correctly. the…

---

## [How to Search word and digits](https://discuss.elastic.co/t/how-to-search-word-and-digits/325848)

<div class="topic-metadata">

**Author:** [@Mohamed\_Farshath](https://discuss.elastic.co/u/Mohamed_Farshath)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 8:24pm UTC](https://discuss.elastic.co/t/how-to-search-word-and-digits/325848 "2023-02-17T20:24:39Z")

</div>

Hey guys, I need help searching this message's contents which has a word and a code that varies from 4 to 6 digits. examples are follows: enter this : 4567 enter this : 567893

---

## [How does Anomaly Detection work?](https://discuss.elastic.co/t/how-does-anomaly-detection-work/325694)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [February 17, 2023, 6:34pm UTC](https://discuss.elastic.co/t/how-does-anomaly-detection-work/325694 "2023-02-17T18:34:47Z")

</div>

I have a question about the Anomaly Detection module provided by elastic stack. As per my understanding of Machine Learning the more data being fed to the model the better learning it will do provided the data is proper.…

---

## [Certificate issue](https://discuss.elastic.co/t/certificate-issue/325813)

<div class="topic-metadata">

**Author:** [@akhilkv43](https://discuss.elastic.co/u/akhilkv43)\
**Replies:** 1\
**Last updated:** [February 17, 2023, 5:02pm UTC](https://discuss.elastic.co/t/certificate-issue/325813 "2023-02-17T17:02:23Z")

</div>

How can i generate a pem certificate in Elasticsearch I am using 8.5 version

---

## [How to plan and implement shard allocation awareness for the below 3 master 6 data node setup](https://discuss.elastic.co/t/how-to-plan-and-implement-shard-allocation-awareness-for-the-below-3-master-6-data-node-setup/325858)

<div class="topic-metadata">

**Author:** [@H\_K7](https://discuss.elastic.co/u/H_K7)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 3:23pm UTC](https://discuss.elastic.co/t/how-to-plan-and-implement-shard-allocation-awareness-for-the-below-3-master-6-data-node-setup/325858 "2023-02-17T15:23:27Z")

</div>

Current setup hosted in aws ec2, self managed/hosted opensource version of elasticsearch master-1 - us-east-1a master-2 - us-east-1b master-2 - us-east-1c data-1 - us-east-1a data-2 - us-east-1b data-3 - us-east-1c …

---

## [Operators in Ingest Pipeline](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743)

<div class="topic-metadata">

**Author:** [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 3:23pm UTC](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743 "2023-02-17T15:23:59Z")

</div>

Hello, I am trying to parse and compare values through ingest pipeline, but couldn't do it, I was running below code, grok is running fine, but couldn't be able to compare value in set condition. POST \_ingest/pipeline/…

---

## [SSL termination for Elasticsearch cluster](https://discuss.elastic.co/t/ssl-termination-for-elasticsearch-cluster/325613)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 3:21pm UTC](https://discuss.elastic.co/t/ssl-termination-for-elasticsearch-cluster/325613 "2023-02-17T15:21:12Z")

</div>

Hi, I'm trying to add a HAProxy service within the docker-compose.yml outlined here: (Install Elasticsearch with Docker | Elasticsearch Guide \[8.6\] | Elastic). I was wondering if anyone had done the same and could share …

---

## [Custom grok write for my message](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 5\
**Last updated:** [February 17, 2023, 2:37pm UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728 "2023-02-17T14:37:47Z")

</div>

Hello Everyone I am having following example logs I want to extract field using filebeat any one can help ? 0.0.0.0 - - \[16/Feb/2023:09:54:40 +0000\] "POST /api/WebsiteCategory/ProductDesigns HTTP/1.1" 200 95521 "https:…

---

## [How to keep only longest token occupying the same positions](https://discuss.elastic.co/t/how-to-keep-only-longest-token-occupying-the-same-positions/325849)

<div class="topic-metadata">

**Author:** [@Valentin\_Pletzer](https://discuss.elastic.co/u/Valentin_Pletzer)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 2:04pm UTC](https://discuss.elastic.co/t/how-to-keep-only-longest-token-occupying-the-same-positions/325849 "2023-02-17T14:04:09Z")

</div>

Is there a way too keep only the longest token if two or more tokens occupy the same positions? e.g. if I define "fox" and "quick fox" as keep words obviously both would be return when analyzing the sentence "the quick …

---

## [Fielddata on a custom analyzer that is of keyword tokenizer](https://discuss.elastic.co/t/fielddata-on-a-custom-analyzer-that-is-of-keyword-tokenizer/325846)

<div class="topic-metadata">

**Author:** [@drjz](https://discuss.elastic.co/u/drjz)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 1:35pm UTC](https://discuss.elastic.co/t/fielddata-on-a-custom-analyzer-that-is-of-keyword-tokenizer/325846 "2023-02-17T13:35:18Z")

</div>

I created a custom analyzer that does lowercasing. The reason why I did not use a normalizer is because I need to apply stopword filter that the normalizer is not supporting. "lowercase\_analyzer": { …

---

## [ELK setup on ARO](https://discuss.elastic.co/t/elk-setup-on-aro/325837)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 12:20pm UTC](https://discuss.elastic.co/t/elk-setup-on-aro/325837 "2023-02-17T12:20:38Z")

</div>

i would like to know that is it possible to setup ELK on ARO or no .as per some references ,says its not possible . if yes could you pls let me know how to setup ELK on ARO thanking in advance :slight\_smile:

---

## [I wanted to add comments in Chinese to make it easier to learn and understand. Why did the build fail?](https://discuss.elastic.co/t/i-wanted-to-add-comments-in-chinese-to-make-it-easier-to-learn-and-understand-why-did-the-build-fail/325826)

<div class="topic-metadata">

**Author:** [@xiaodizi](https://discuss.elastic.co/u/xiaodizi)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 9:35am UTC](https://discuss.elastic.co/t/i-wanted-to-add-comments-in-chinese-to-make-it-easier-to-learn-and-understand-why-did-the-build-fail/325826 "2023-02-17T09:35:39Z")

</div>

!\[image|690x183\](upload: //nMdNEBcTf10uHBGKWm5z6abOYth.jpeg) I wanted to add comments in Chinese to make it easier to learn and understand. Why did the build fail?

---

## [Watcher action: multiple actions foreach](https://discuss.elastic.co/t/watcher-action-multiple-actions-foreach/325817)

<div class="topic-metadata">

**Author:** [@mch1307](https://discuss.elastic.co/u/mch1307)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 7:01am UTC](https://discuss.elastic.co/t/watcher-action-multiple-actions-foreach/325817 "2023-02-17T07:01:52Z")

</div>

Hi, I have a watcher with an aggregation query. In the action section, I am trying to execute two actions (transform, then webhook) for each element in the query response. From the logs, it seems the webhook is being ex…

---

## [Restore all User created Indices, exclude the indices starting with](https://discuss.elastic.co/t/restore-all-user-created-indices-exclude-the-indices-starting-with/324428)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 6\
**Last updated:** [February 17, 2023, 5:16am UTC](https://discuss.elastic.co/t/restore-all-user-created-indices-exclude-the-indices-starting-with/324428 "2023-02-17T05:16:12Z")

</div>

I am trying to ALL restore user created indices. I don't want to restore the .geoip\_databases, .security, .ds-.logs-deprecation.elasticsearch-default\* and so on. I tried this :- { "indices": "\*", "include\_global\_sta…

---

## [ElasticSearch losing documents](https://discuss.elastic.co/t/elasticsearch-losing-documents/325185)

<div class="topic-metadata">

**Author:** [@apelk](https://discuss.elastic.co/u/apelk)\
**Replies:** 12\
**Last updated:** [February 17, 2023, 4:42am UTC](https://discuss.elastic.co/t/elasticsearch-losing-documents/325185 "2023-02-17T04:42:32Z")

</div>

Using ELK 7.8. We have a Logstash pipeline from JDBC database to Elasticsearch. Using persisted queues and DLQ. We lose about 1% of the documents we send to Elasticsearch. We have enabled TRACE on Elasticsearch and t…

---

## [How to get version of the es server using Java Api client](https://discuss.elastic.co/t/how-to-get-version-of-the-es-server-using-java-api-client/325796)

<div class="topic-metadata">

**Author:** [@4color](https://discuss.elastic.co/u/4color)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 3:08am UTC](https://discuss.elastic.co/t/how-to-get-version-of-the-es-server-using-java-api-client/325796 "2023-02-17T03:08:03Z")

</div>

i can't find api in source

---

## [Aggregate Score for Hybrid Search](https://discuss.elastic.co/t/aggregate-score-for-hybrid-search/325205)

<div class="topic-metadata">

**Author:** [@Kok\_Gin\_Xian](https://discuss.elastic.co/u/Kok_Gin_Xian)\
**Replies:** 21\
**Last updated:** [February 17, 2023, 1:12am UTC](https://discuss.elastic.co/t/aggregate-score-for-hybrid-search/325205 "2023-02-17T01:12:37Z")

</div>

Hi, I'm new to Elasticsearch and am trying out the new hybrid search by specifying the "knn" and "query" parameters in my search. I set k=100 in knn, size=k=100 in the search request. For pure vector search (omitting t…

---

## [X-Forwarded-For in Elasticsearch/Kibana Logs](https://discuss.elastic.co/t/x-forwarded-for-in-elasticsearch-kibana-logs/325779)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 11:31pm UTC](https://discuss.elastic.co/t/x-forwarded-for-in-elasticsearch-kibana-logs/325779 "2023-02-16T23:31:11Z")

</div>

We have Kibana and Elasticsearch behind AVI (Nginx) load-balancers, and that is unfortunately masking the true client IP addresses that are accessing Kibana/Elasticsearch. We are logging XFF headers on all the LB configs…

---

## [Automatic synonyms generation using ChatGPT or other AI solution?](https://discuss.elastic.co/t/automatic-synonyms-generation-using-chatgpt-or-other-ai-solution/325785)

<div class="topic-metadata">

**Author:** [@Youxu](https://discuss.elastic.co/u/Youxu)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 11:24pm UTC](https://discuss.elastic.co/t/automatic-synonyms-generation-using-chatgpt-or-other-ai-solution/325785 "2023-02-16T23:24:35Z")

</div>

Anyone know if there is out-of-box automatic synonym generation based on index data using AI, like ChatGPT?

---

## [Confused by deprecation message](https://discuss.elastic.co/t/confused-by-deprecation-message/325780)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 10:10pm UTC](https://discuss.elastic.co/t/confused-by-deprecation-message/325780 "2023-02-16T22:10:43Z")

</div>

I am looking at upgrading my 7.17 cluster to version 8, first stop the depreciation logs! I notice that there is both a deprecation.log and a deprecation.json and they have different data. deprecation.log: \[2020-11-16…

---

## [Issue with ingestion pipeline with conditional](https://discuss.elastic.co/t/issue-with-ingestion-pipeline-with-conditional/325747)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 9:51pm UTC](https://discuss.elastic.co/t/issue-with-ingestion-pipeline-with-conditional/325747 "2023-02-16T21:51:34Z")

</div>

Hello, I am trying to parse and compare values through ingest pipeline, but couldn't do it, I was running below code, grok is running fine, but couldn't be able to compare value in set condition. POST \_ingest/pipeline/…

---

## [Update API can't find document](https://discuss.elastic.co/t/update-api-cant-find-document/325777)

<div class="topic-metadata">

**Author:** [@friaca](https://discuss.elastic.co/u/friaca)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 9:37pm UTC](https://discuss.elastic.co/t/update-api-cant-find-document/325777 "2023-02-16T21:37:25Z")

</div>

I'm trying to update a document field but had no success doing it. I can do a GET by ID with ticket-2/ticketelastic/134532 so that clarifies that the ID is valid and the document exists. { "\_index" : "ticket-2", "\_…

---

## [Error while uploading bulk json to elasticsearch domain](https://discuss.elastic.co/t/error-while-uploading-bulk-json-to-elasticsearch-domain/325774)

<div class="topic-metadata">

**Author:** [@truptivala](https://discuss.elastic.co/u/truptivala)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 8:18pm UTC](https://discuss.elastic.co/t/error-while-uploading-bulk-json-to-elasticsearch-domain/325774 "2023-02-16T20:18:36Z")

</div>

I am trying to upload the below json file to the elasticsearch domain I have on aws and getting the below error: Input json file: {"index": {"\_index": "ods-pcd-poc","\_id": "1"}}{"Page": 0,"Path": "//Document/Figure","T…

---

## [Reindex debuging](https://discuss.elastic.co/t/reindex-debuging/325772)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 8:01pm UTC](https://discuss.elastic.co/t/reindex-debuging/325772 "2023-02-16T20:01:41Z")

</div>

Hi I'm going through some of troubleshooting for reindex process by bulkprocessor Under that proc Failed to execute bulk request. Reason: \<mark\>java.net.SocketTimeoutException\</mark\>: 8,000 milliseconds \<mark\>timeout\</…

---

## [ELK CCR Setup](https://discuss.elastic.co/t/elk-ccr-setup/324719)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 7\
**Last updated:** [February 16, 2023, 6:36pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719 "2023-02-16T18:36:00Z")

</div>

Hello, I want to test the CCR feature, and I understand these two limitations exist: A follower can only follow one leader. No way to directly write events from the client side to the follower index. with these two l…

---

## [Use of aggregations with multiple queries](https://discuss.elastic.co/t/use-of-aggregations-with-multiple-queries/325763)

<div class="topic-metadata">

**Author:** [@usergbgc](https://discuss.elastic.co/u/usergbgc)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 4:31pm UTC](https://discuss.elastic.co/t/use-of-aggregations-with-multiple-queries/325763 "2023-02-16T16:31:24Z")

</div>

Hello, I've been having trouble getting some results for a while, and I'm starting to wonder if my query is even feasible. I have a set of documents collecting articles, with fields like date, title, and a nested autho…

---

## [Migrate indices from elasticsearsh 6.8 to 7.17](https://discuss.elastic.co/t/migrate-indices-from-elasticsearsh-6-8-to-7-17/325745)

<div class="topic-metadata">

**Author:** [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 2:02pm UTC](https://discuss.elastic.co/t/migrate-indices-from-elasticsearsh-6-8-to-7-17/325745 "2023-02-16T14:02:29Z")

</div>

We have Elasticsearch 6.8 running at the moment and want to migrate it to 7.17. I have created another cluster with 7.17 running and we would like migrate the indices from 6.8. what is the best way to do it, I would li…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=297)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=299)
