# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=303

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 304

---

## [Facing issue with kibana and elasticsearch](https://discuss.elastic.co/t/facing-issue-with-kibana-and-elasticsearch/325132)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 1:32pm UTC](https://discuss.elastic.co/t/facing-issue-with-kibana-and-elasticsearch/325132 "2023-02-09T13:32:24Z")

</div>

Hi Team, I have installed the elasticsearch and kibana throgh eck , its working I can able to login If we login first time i'm getting issue like \< elastic did not load properly check the server output for information\> …

---

## [Need help with search query](https://discuss.elastic.co/t/need-help-with-search-query/325048)

<div class="topic-metadata">

**Author:** [@PA3mEP](https://discuss.elastic.co/u/PA3mEP)\
**Replies:** 4\
**Last updated:** [February 9, 2023, 1:01pm UTC](https://discuss.elastic.co/t/need-help-with-search-query/325048 "2023-02-09T13:01:10Z")

</div>

Hi, guys. Sorry to interrupt your beautiful, but may be someone can help me with search query I'm trying to figure out. Here goes.. I have an index where filebeat sends logs. For example /var/log/messages. Documents loo…

---

## [Fuzzy query don't working as expected](https://discuss.elastic.co/t/fuzzy-query-dont-working-as-expected/325070)

<div class="topic-metadata">

**Author:** [@pavel4008](https://discuss.elastic.co/u/pavel4008)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 11:29am UTC](https://discuss.elastic.co/t/fuzzy-query-dont-working-as-expected/325070 "2023-02-09T11:29:08Z")

</div>

Hello! Recently I started studying elasticsearch(8.6.1) and got a very incomprehensible behavior. My index: PUT items2/\_settings { "settings": { "analysis": { "filter": { "ru\_stop": { "ty…

---

## [Turn off “Elasticsearch built-in security features are not enabled” notifications from Python?](https://discuss.elastic.co/t/turn-off-elasticsearch-built-in-security-features-are-not-enabled-notifications-from-python/325034)

<div class="topic-metadata">

**Author:** [@mmoraschini](https://discuss.elastic.co/u/mmoraschini)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 9:43am UTC](https://discuss.elastic.co/t/turn-off-elasticsearch-built-in-security-features-are-not-enabled-notifications-from-python/325034 "2023-02-09T09:43:51Z")

</div>

With respect to this question Which is about silencing the error ElasticsearchWarning: Elasticsearch built-in security features are not enabled. Without authentication, your cluster could be accessible to anyone. See…

---

## [Lower latency by using more shards (with routing)](https://discuss.elastic.co/t/lower-latency-by-using-more-shards-with-routing/325117)

<div class="topic-metadata">

**Author:** [@frankkoornstra](https://discuss.elastic.co/u/frankkoornstra)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 9:32am UTC](https://discuss.elastic.co/t/lower-latency-by-using-more-shards-with-routing/325117 "2023-02-09T09:32:56Z")

</div>

Hey, I'm trying to lower the search latency for an index which has routing enabled (and we consistently use it for all queries) and I was wondering if increasing the amount of shards would do the trick? We're deployed o…

---

## [Understanding Metrics ( Cumulative indexing time of primary shards )](https://discuss.elastic.co/t/understanding-metrics-cumulative-indexing-time-of-primary-shards/324986)

<div class="topic-metadata">

**Author:** [@Sriram\_Kumar](https://discuss.elastic.co/u/Sriram_Kumar)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 8:29am UTC](https://discuss.elastic.co/t/understanding-metrics-cumulative-indexing-time-of-primary-shards/324986 "2023-02-09T08:29:12Z")

</div>

Hi , I have a corpus of 100k ( 1 lakh products ) in json , I am bulk indexing to one of the cluster with bulk\_size of 10k . GET product\_\_v99/\_stats { "indexing": { "index\_total": 100000, "index\_t…

---

## [Is there document count limitation for aggregations?](https://discuss.elastic.co/t/is-there-document-count-limitation-for-aggregations/325108)

<div class="topic-metadata">

**Author:** [@ysj6987](https://discuss.elastic.co/u/ysj6987)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 7:52am UTC](https://discuss.elastic.co/t/is-there-document-count-limitation-for-aggregations/325108 "2023-02-09T07:52:02Z")

</div>

Hello, I'm trying to get percentiles aggregation from rather big document size count ( over 400,000 ) I know that query size limitation of documents is10000 as default. I wonder it applies to aggregation so that it res…

---

## [Saml Connection in Elastic cloud](https://discuss.elastic.co/t/saml-connection-in-elastic-cloud/325047)

<div class="topic-metadata">

**Author:** [@Jenil\_Gupta](https://discuss.elastic.co/u/Jenil_Gupta)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 6:07am UTC](https://discuss.elastic.co/t/saml-connection-in-elastic-cloud/325047 "2023-02-09T06:07:23Z")

</div>

Hi team, We are getting some error " You do not have permission to access the requested page Either go back to the previous page or log in as a different user." . I have attached the screenshot below. Please kindly he…

---

## [Data Nodes disconnected randomly](https://discuss.elastic.co/t/data-nodes-disconnected-randomly/325071)

<div class="topic-metadata">

**Author:** [@ignaciood](https://discuss.elastic.co/u/ignaciood)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 5:05am UTC](https://discuss.elastic.co/t/data-nodes-disconnected-randomly/325071 "2023-02-09T05:05:43Z")

</div>

Hi everyone, I have an Elasticsearch (7.10.2) cluster with 11 cluster nodes (3 master, 8 data). Randomly there are data nodes that start to disconnect from the cluster. The node is healthy but offline, it comes back on…

---

## [Unable to install Elasticsearch using Helm chart](https://discuss.elastic.co/t/unable-to-install-elasticsearch-using-helm-chart/325078)

<div class="topic-metadata">

**Author:** [@techavidity](https://discuss.elastic.co/u/techavidity)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 4:15am UTC](https://discuss.elastic.co/t/unable-to-install-elasticsearch-using-helm-chart/325078 "2023-02-09T04:15:35Z")

</div>

I am trying to setup Elasticsearch on multi node Kubernetes cluster. I did create the storage class, after that i installed the Elasticsearch using Helm. helm repo add elastic https://helm.elastic.co helm repo update …

---

## [Query multiple conditions of an array property](https://discuss.elastic.co/t/query-multiple-conditions-of-an-array-property/325068)

<div class="topic-metadata">

**Author:** [@thomas.schroeder](https://discuss.elastic.co/u/thomas.schroeder)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 10:40pm UTC](https://discuss.elastic.co/t/query-multiple-conditions-of-an-array-property/325068 "2023-02-08T22:40:42Z")

</div>

Hey everyone, I have a document which describes when an entry was/is valid. The entry can be valid for multiple time periods but these can never overlap. Now I want to query only documents which have been changed it's a…

---

## [Connector error](https://discuss.elastic.co/t/connector-error/325062)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 9:52pm UTC](https://discuss.elastic.co/t/connector-error/325062 "2023-02-08T21:52:31Z")

</div>

Hi! I get this error: "\[DEPTH\_ZERO\_SELF\_SIGNED\_CERT\] self signed certificate" on local Elastic Stack infrastructure when I want to use a connector with "https" address. Any help, please?

---

## [ELK Migartion to 8x](https://discuss.elastic.co/t/elk-migartion-to-8x/324539)

<div class="topic-metadata">

**Author:** [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Replies:** 1\
**Last updated:** [February 8, 2023, 8:26pm UTC](https://discuss.elastic.co/t/elk-migartion-to-8x/324539 "2023-02-08T20:26:48Z")

</div>

Hello, Current ELK stack version details: Elasticsearch: 7.17.8 Kibana: 7.17.8 Logstash: 7.17.8 Could you please help me out with the steps for upgrading ELK stack into multi-tier architecture cluster when we upgra…

---

## [Can't Add Terms Query to a Search Template](https://discuss.elastic.co/t/cant-add-terms-query-to-a-search-template/325038)

<div class="topic-metadata">

**Author:** [@krmathieu](https://discuss.elastic.co/u/krmathieu)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 8:37pm UTC](https://discuss.elastic.co/t/cant-add-terms-query-to-a-search-template/325038 "2023-02-08T20:37:31Z")

</div>

I have started work on a search template and hit a snag when trying to add a terms query to the template. Here is the template definition: POST \_scripts/establishments\_search { "script": { "lang": "mustache", …

---

## [Append elements to array avoiding duplicates](https://discuss.elastic.co/t/append-elements-to-array-avoiding-duplicates/325059)

<div class="topic-metadata">

**Author:** [@Sergio\_Serra](https://discuss.elastic.co/u/Sergio_Serra)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 7:35pm UTC](https://discuss.elastic.co/t/append-elements-to-array-avoiding-duplicates/325059 "2023-02-08T19:35:55Z")

</div>

Hello everyone, Is there a performant way to append elements to an array avoiding duplicates basically making it work like a Set instead of a List ? This is the script i'm using, but this will duplicate entries in the …

---

## [There are two types of Flattened Field Types, is that correct?](https://discuss.elastic.co/t/there-are-two-types-of-flattened-field-types-is-that-correct/325057)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 7:34pm UTC](https://discuss.elastic.co/t/there-are-two-types-of-flattened-field-types-is-that-correct/325057 "2023-02-08T19:34:33Z")

</div>

I am learning about Flattened Field Types for index mappings. Can someone confirm if my findings are correct? There are two types of flattened field types. 1. Explicitly Flattened Field Types - This documentation is a…

---

## [Question for Logging Cluster - is 3master, 2data node is good?](https://discuss.elastic.co/t/question-for-logging-cluster-is-3master-2data-node-is-good/324445)

<div class="topic-metadata">

**Author:** [@ggalihpp-jubelio](https://discuss.elastic.co/u/ggalihpp-jubelio)\
**Replies:** 5\
**Last updated:** [February 8, 2023, 5:15pm UTC](https://discuss.elastic.co/t/question-for-logging-cluster-is-3master-2data-node-is-good/324445 "2023-02-08T17:15:17Z")

</div>

Hi everyone, So we tried to move to ECK, and want to execute it perfectly or at least the right way... My use case is for logging and APM, Indexing around 7000ish/s Search rate 50-100/s Now we have an ECK cluster co…

---

## [Elasticsearch 8.5.1 Won't Build. Failed to Apply SpotlessPlugin](https://discuss.elastic.co/t/elasticsearch-8-5-1-wont-build-failed-to-apply-spotlessplugin/324476)

<div class="topic-metadata">

**Author:** [@alxdaly](https://discuss.elastic.co/u/alxdaly)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elasticsearch-8-5-1-wont-build-failed-to-apply-spotlessplugin/324476 "2023-02-08T17:07:27Z")

</div>

I am trying to build an instance of elasticsearch 8.5.1 in a linux environment. I have had to modify the gradle files to point to my company's artifact repositories. When I try to run any ./gradlew commands, I get the er…

---

## [How to only get the highest score of a token graphs multiple sub-queries](https://discuss.elastic.co/t/how-to-only-get-the-highest-score-of-a-token-graphs-multiple-sub-queries/325046)

<div class="topic-metadata">

**Author:** [@Nicolas\_Labrot](https://discuss.elastic.co/u/Nicolas_Labrot)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-only-get-the-highest-score-of-a-token-graphs-multiple-sub-queries/325046 "2023-02-08T16:47:30Z")

</div>

Hello, For example, is indexed "european union" with an hunspell english filter. The filter generates the following tokens token: european / position: 0 token: union / position: 1 token: ion / position: 1 If I do a …

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/325023)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 3:58pm UTC](https://discuss.elastic.co/t/elasticsearch/325023 "2023-02-08T15:58:42Z")

</div>

Hi Team, Is there any major changes and Features in the elasticsearch V7.14 to 8.5.3 Thanks&Regards, SM

---

## [Add description to my logstas index based on another csv field](https://discuss.elastic.co/t/add-description-to-my-logstas-index-based-on-another-csv-field/325002)

<div class="topic-metadata">

**Author:** [@Miriam](https://discuss.elastic.co/u/Miriam)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 3:58pm UTC](https://discuss.elastic.co/t/add-description-to-my-logstas-index-based-on-another-csv-field/325002 "2023-02-08T15:58:21Z")

</div>

I have my index created using logstah config file. Reading from log file following information: id, iduser,datetimInit, dateTimeends 0001 210 2023-02-03 04:45:16.78 2023-02-03 04:46:16.78 0002 1003 2023-02-03 08:45:16.7…

---

## [Rank based on rarity of a field value](https://discuss.elastic.co/t/rank-based-on-rarity-of-a-field-value/323546)

<div class="topic-metadata">

**Author:** [@pheeria](https://discuss.elastic.co/u/pheeria)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 3:09pm UTC](https://discuss.elastic.co/t/rank-based-on-rarity-of-a-field-value/323546 "2023-02-08T15:09:34Z")

</div>

Hi :vulcan\_salute: I'd like to know how can I rank lower items, which have fields that are frequently appearing among the results. Say, we have a similar result set: "name": "Red T-Shirt" "store": "Zara" "name": "Yel…

---

## [Does elasticsearch support listening on a non root path for the URL?](https://discuss.elastic.co/t/does-elasticsearch-support-listening-on-a-non-root-path-for-the-url/324939)

<div class="topic-metadata">

**Author:** [@ghettosamson](https://discuss.elastic.co/u/ghettosamson)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 2:04pm UTC](https://discuss.elastic.co/t/does-elasticsearch-support-listening-on-a-non-root-path-for-the-url/324939 "2023-02-08T14:04:37Z")

</div>

I have my elasticsearch deployed as a Docker container on AWS, sitting behind an Application Load Balancer. The container is listening on port 9200 as usual, but I'm using path based routing for all my micro-services beh…

---

## [Sum of a field in a parent node and grouping by a field in a child node](https://discuss.elastic.co/t/sum-of-a-field-in-a-parent-node-and-grouping-by-a-field-in-a-child-node/324948)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [February 8, 2023, 1:46pm UTC](https://discuss.elastic.co/t/sum-of-a-field-in-a-parent-node-and-grouping-by-a-field-in-a-child-node/324948 "2023-02-08T13:46:55Z")

</div>

I'm trying to get the sum of a field in a parent node while aggregating on a field of a child node. For example, this is what I've setup: PUT order POST order/\_mapping { "properties": { "order\_items": { "t…

---

## [Eland dataframe: search\_phase\_execution\_exception](https://discuss.elastic.co/t/eland-dataframe-search-phase-execution-exception/325006)

<div class="topic-metadata">

**Author:** [@mruiter](https://discuss.elastic.co/u/mruiter)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 11:02am UTC](https://discuss.elastic.co/t/eland-dataframe-search-phase-execution-exception/325006 "2023-02-08T11:02:27Z")

</div>

Hello everybody, For our ETL process we're loading multiple indices, however for the bigger ones with 10 million+ rows, we sometimes run into an error on our server. Other times all the indices will load correctly. The …

---

## [Elasticsearch query to SQL](https://discuss.elastic.co/t/elasticsearch-query-to-sql/324814)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 10:35am UTC](https://discuss.elastic.co/t/elasticsearch-query-to-sql/324814 "2023-02-08T10:35:42Z")

</div>

I know there is SQL API which can convert SQL query to REST is there a way around. convert REST query to SQL ?

---

## [Roller over at mid night with Index per 30days in ILM](https://discuss.elastic.co/t/roller-over-at-mid-night-with-index-per-30days-in-ilm/324982)

<div class="topic-metadata">

**Author:** [@pruthvi](https://discuss.elastic.co/u/pruthvi)\
**Replies:** 4\
**Last updated:** [February 8, 2023, 10:04am UTC](https://discuss.elastic.co/t/roller-over-at-mid-night-with-index-per-30days-in-ilm/324982 "2023-02-08T10:04:10Z")

</div>

Hi There, Need to create Index per 30 days interval, total of 60+ index for 5 years of data with ILM. So while searching within the date range I could search only the index created within that date range which would in…

---

## [ElasticsearchClient didn't close socket connect and file open](https://discuss.elastic.co/t/elasticsearchclient-didnt-close-socket-connect-and-file-open/324705)

<div class="topic-metadata">

**Author:** [@Adam\_Lin](https://discuss.elastic.co/u/Adam_Lin)\
**Replies:** 6\
**Last updated:** [February 8, 2023, 6:14am UTC](https://discuss.elastic.co/t/elasticsearchclient-didnt-close-socket-connect-and-file-open/324705 "2023-02-08T06:14:18Z")

</div>

Hi all, I tried to query logs from the ELK server through java RestClient. This is how I set up search client try { restClient = RestClient .builder(new HttpHost(host, port)) .setRequestConfigCallback(new Res…

---

## [Is there a way to log or to check the log with time taken to complete the transition from Phases in ILM](https://discuss.elastic.co/t/is-there-a-way-to-log-or-to-check-the-log-with-time-taken-to-complete-the-transition-from-phases-in-ilm/324357)

<div class="topic-metadata">

**Author:** [@pruthvi](https://discuss.elastic.co/u/pruthvi)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 8:34am UTC](https://discuss.elastic.co/t/is-there-a-way-to-log-or-to-check-the-log-with-time-taken-to-complete-the-transition-from-phases-in-ilm/324357 "2023-02-08T08:34:20Z")

</div>

I have implemented ILM(index lifecycle management) with roller over from Hot to warm and move to cold after period of time. I have indexed few thousand of document into index. Rollover is also happing with max age in po…

---

## [Is there a limit on number of fields on which we can aggregate?](https://discuss.elastic.co/t/is-there-a-limit-on-number-of-fields-on-which-we-can-aggregate/324947)

<div class="topic-metadata">

**Author:** [@mattkallo](https://discuss.elastic.co/u/mattkallo)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 7:13am UTC](https://discuss.elastic.co/t/is-there-a-limit-on-number-of-fields-on-which-we-can-aggregate/324947 "2023-02-08T07:13:06Z")

</div>

Is there a limit on number of fields on which we can aggregate? I could not find any specific info on this. I could find details on # of buckets for a given field, but not for the number of fields itself. Currently I h…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=302)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=304)
