# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=306

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 307

---

## [How to create mapping for special characters and autocomplete search](https://discuss.elastic.co/t/how-to-create-mapping-for-special-characters-and-autocomplete-search/324115)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 2:14pm UTC](https://discuss.elastic.co/t/how-to-create-mapping-for-special-characters-and-autocomplete-search/324115 "2023-02-03T14:14:06Z")

</div>

Hi, In my project, I need to search data with special characters like č,ć,ž,đ, ?, !. What is the best practice for searching special characters in version 8.5? Also, how to create a mapping for autocomplete search? Ho…

---

## [Elastic cloud 8.6 read only role](https://discuss.elastic.co/t/elastic-cloud-8-6-read-only-role/324569)

<div class="topic-metadata">

**Author:** [@aneeshks1982](https://discuss.elastic.co/u/aneeshks1982)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 11:20am UTC](https://discuss.elastic.co/t/elastic-cloud-8-6-read-only-role/324569 "2023-02-03T11:20:06Z")

</div>

Hi, Can someone tell me how to create a read-only role in elastic cloud 8.6 version

---

## [Create data view api](https://discuss.elastic.co/t/create-data-view-api/324641)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 10:52am UTC](https://discuss.elastic.co/t/create-data-view-api/324641 "2023-02-03T10:52:23Z")

</div>

Hi I have filebeat installed on one machine. and elasticsearch and kibana on one machine. and logstash on another machine. I am using an ansible playbook which picks logs using filebeat and ships it to logstash. Eevryth…

---

## [Create elastic user with more roles](https://discuss.elastic.co/t/create-elastic-user-with-more-roles/324632)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 9:31am UTC](https://discuss.elastic.co/t/create-elastic-user-with-more-roles/324632 "2023-02-03T09:31:12Z")

</div>

As part of bootstrap, Can we create the builtin user "elastic" with providing more roles other than superuser role When elastic user gets created it is assigned with super user role. I need to assign few more privilege…

---

## [S3 optimization in elk](https://discuss.elastic.co/t/s3-optimization-in-elk/324298)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 22\
**Last updated:** [February 3, 2023, 9:03am UTC](https://discuss.elastic.co/t/s3-optimization-in-elk/324298 "2023-02-03T09:03:39Z")

</div>

Hi , We have a 8 node cluster in on premise with 3 years data (3 master + 5 data node) one data node out of this being acting as s3 for cold storage. Our s3 is getting space issues and we would like to optimize by mov…

---

## [Elastic Case Insensitive Search](https://discuss.elastic.co/t/elastic-case-insensitive-search/324527)

<div class="topic-metadata">

**Author:** [@Tam2](https://discuss.elastic.co/u/Tam2)\
**Replies:** 12\
**Last updated:** [February 3, 2023, 8:19am UTC](https://discuss.elastic.co/t/elastic-case-insensitive-search/324527 "2023-02-03T08:19:06Z")

</div>

Hi All, I have a schema which uses Keywords to store values an example of a document would be something like this: We aggregate on a number of properties too such as make/model/colour/condition etc { "properties": {…

---

## [Not all primary shards of \[.geoip\_databases\] index are active](https://discuss.elastic.co/t/not-all-primary-shards-of-geoip-databases-index-are-active/324401)

<div class="topic-metadata">

**Author:** [@LiuJintao](https://discuss.elastic.co/u/LiuJintao)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 8:51am UTC](https://discuss.elastic.co/t/not-all-primary-shards-of-geoip-databases-index-are-active/324401 "2023-02-03T08:51:36Z")

</div>

When I start elasticsearch cluster with a single node,it throw an error: \[2023-02-01T15:34:09,249\]\[ERROR\]\[o.e.i.g.GeoIpDownloader \] \[node1\] exception during geoip databases updateorg.elasticsearch.ElasticsearchExceptio…

---

## [Bertopic in Elasticsearch](https://discuss.elastic.co/t/bertopic-in-elasticsearch/324617)

<div class="topic-metadata">

**Author:** [@alvaro\_ing](https://discuss.elastic.co/u/alvaro_ing)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 8:35am UTC](https://discuss.elastic.co/t/bertopic-in-elasticsearch/324617 "2023-02-03T08:35:12Z")

</div>

Hello, I have been training a BERTopic model and I would like to know if there is a way to import it into Elastic. I've seen that some models can be imported with Eland API but I'm not sure if this could be done. Berto…

---

## [Copy a remote index using Reindex API](https://discuss.elastic.co/t/copy-a-remote-index-using-reindex-api/324548)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 7:47am UTC](https://discuss.elastic.co/t/copy-a-remote-index-using-reindex-api/324548 "2023-02-03T07:47:00Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. The whole process is running in a remote server. I need to make a copy of the index into…

---

## [Elastic search does not work during operation, causing problems in restarting](https://discuss.elastic.co/t/elastic-search-does-not-work-during-operation-causing-problems-in-restarting/324556)

<div class="topic-metadata">

**Author:** [@sramana235](https://discuss.elastic.co/u/sramana235)\
**Replies:** 3\
**Last updated:** [February 3, 2023, 7:22am UTC](https://discuss.elastic.co/t/elastic-search-does-not-work-during-operation-causing-problems-in-restarting/324556 "2023-02-03T07:22:33Z")

</div>

\[2023-02-02T18:22:39,230\]\[INFO \]\[o.e.e.NodeEnvironment \] \[name\] using \[1\] data paths, mounts \[\[/data (/dev/data)\]\], net usable\_space \[55.9gb\], net total\_space \[98.4gb\], types \[ext4\] \[2023-02-02T18:22:39,231\]\[INFO \]\[o.…

---

## [Search returning zero document and zero shards | Index was closed and then opened](https://discuss.elastic.co/t/search-returning-zero-document-and-zero-shards-index-was-closed-and-then-opened/324603)

<div class="topic-metadata">

**Author:** [@esuser27](https://discuss.elastic.co/u/esuser27)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 6:42am UTC](https://discuss.elastic.co/t/search-returning-zero-document-and-zero-shards-index-was-closed-and-then-opened/324603 "2023-02-03T06:42:05Z")

</div>

Hi Folks, I had closed few of my indices for maintenance activity and I opened them after some time. Health wise the index is green and has a shard, but my search query is getting empty results even though there are do…

---

## [Failed to find a X509ExtendedTrustManager](https://discuss.elastic.co/t/failed-to-find-a-x509extendedtrustmanager/324593)

<div class="topic-metadata">

**Author:** [@hitlll](https://discuss.elastic.co/u/hitlll)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 2:35am UTC](https://discuss.elastic.co/t/failed-to-find-a-x509extendedtrustmanager/324593 "2023-02-03T02:35:36Z")

</div>

Environment : Dokcer Image elasticsearch-7.17.8 JDK: openjdk:8u342-jdk How should I solve the problem？

---

## [Nested Aggregation to just get some nested type without aggregatioon](https://discuss.elastic.co/t/nested-aggregation-to-just-get-some-nested-type-without-aggregatioon/324588)

<div class="topic-metadata">

**Author:** [@Jason\_Yu1](https://discuss.elastic.co/u/Jason_Yu1)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 1:59am UTC](https://discuss.elastic.co/t/nested-aggregation-to-just-get-some-nested-type-without-aggregatioon/324588 "2023-02-03T01:59:06Z")

</div>

I am not sure if is that possible. We have a set of documents with the same testId, and each set of those docs, always only have 1 of them has the frames nested type. So I want to do the aggression with the data, there …

---

## [Different aggregation count for the same value](https://discuss.elastic.co/t/different-aggregation-count-for-the-same-value/324566)

<div class="topic-metadata">

**Author:** [@mbklein](https://discuss.elastic.co/u/mbklein)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 4:47pm UTC](https://discuss.elastic.co/t/different-aggregation-count-for-the-same-value/324566 "2023-02-02T16:47:22Z")

</div>

I don't understand the results I'm seeing. I am asking for two different aggs in the same query. The first is “show me the doc counts for subject.label for these specific values,” and the second is “show me the doc count…

---

## [Common points in two geo\_bounding\_box](https://discuss.elastic.co/t/common-points-in-two-geo-bounding-box/324387)

<div class="topic-metadata">

**Author:** [@maya\_khan](https://discuss.elastic.co/u/maya_khan)\
**Replies:** 10\
**Last updated:** [February 2, 2023, 7:00am UTC](https://discuss.elastic.co/t/common-points-in-two-geo-bounding-box/324387 "2023-02-02T07:00:17Z")

</div>

I have two geo\_bounding\_box within these two shapes many points exist. i want only those points that are common in both geo\_bounding\_box. { "bool":{ "should":\[ { "geo\_bounding\_box":{ "geo\_coords":{ "top\_left": { …

---

## [Query in rated requests should not contain aggregations](https://discuss.elastic.co/t/query-in-rated-requests-should-not-contain-aggregations/324559)

<div class="topic-metadata">

**Author:** [@ocastaneda](https://discuss.elastic.co/u/ocastaneda)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 2:51pm UTC](https://discuss.elastic.co/t/query-in-rated-requests-should-not-contain-aggregations/324559 "2023-02-02T14:51:07Z")

</div>

Hello! Our search team is considering diversifying search results with diversified\_sampler aggregation and child top\_hits aggregation. I noticed that aggregations don’t work with the ranking evaluation API. Anyone got s…

---

## [Rollover for Daily indices in Elasticsearch](https://discuss.elastic.co/t/rollover-for-daily-indices-in-elasticsearch/324558)

<div class="topic-metadata">

**Author:** [@Veysel\_yuksel](https://discuss.elastic.co/u/Veysel_yuksel)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 2:42pm UTC](https://discuss.elastic.co/t/rollover-for-daily-indices-in-elasticsearch/324558 "2023-02-02T14:42:25Z")

</div>

Hello, I am trying to implement rollover mechanism to my environments. Let me explain as is and to be design; Log data stores in syslog-%{+YYYY.MM.dd} indices right now. I keep data for 3 days. No rollover - No warm or…

---

## [Restoring indices from S3 repository](https://discuss.elastic.co/t/restoring-indices-from-s3-repository/324464)

<div class="topic-metadata">

**Author:** [@iyin](https://discuss.elastic.co/u/iyin)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 2:20pm UTC](https://discuss.elastic.co/t/restoring-indices-from-s3-repository/324464 "2023-02-02T14:20:21Z")

</div>

Hi, I took a snapshot of an elastic cluster (version 7.17.8) and saved it on an Amazon S3 repository before the cluster was deleted. Although, I am able to see the backup files in the s3 bucket, I have been unable to re…

---

## [Hardware Specifications for Storage Types](https://discuss.elastic.co/t/hardware-specifications-for-storage-types/324553)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 1:44pm UTC](https://discuss.elastic.co/t/hardware-specifications-for-storage-types/324553 "2023-02-02T13:44:21Z")

</div>

Hi, we have choose the type of storage to associate to an Elasticsearch cluster. In particular, we wonder if there is any indication of the minimum characteristics that a certain type of storage must have; for example …

---

## [Filter and Count on a field](https://discuss.elastic.co/t/filter-and-count-on-a-field/324546)

<div class="topic-metadata">

**Author:** [@mayur](https://discuss.elastic.co/u/mayur)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 12:31pm UTC](https://discuss.elastic.co/t/filter-and-count-on-a-field/324546 "2023-02-02T12:31:45Z")

</div>

I am trying to calculate Recall from a field, which is populated with two values, TP and FN. Recall formula is Count(TP) / (Count(TP) + Count(FN)). How to achieve this opensearch?

---

## [Sample data required](https://discuss.elastic.co/t/sample-data-required/324522)

<div class="topic-metadata">

**Author:** [@NS\_Midhun](https://discuss.elastic.co/u/NS_Midhun)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 10:12am UTC](https://discuss.elastic.co/t/sample-data-required/324522 "2023-02-02T10:12:26Z")

</div>

I need sample data (GB's) in json format to upload in opensearch. Please suggest

---

## [Term query not working where type is "text"](https://discuss.elastic.co/t/term-query-not-working-where-type-is-text/324422)

<div class="topic-metadata">

**Author:** [@shebbi](https://discuss.elastic.co/u/shebbi)\
**Replies:** 6\
**Last updated:** [February 2, 2023, 10:05am UTC](https://discuss.elastic.co/t/term-query-not-working-where-type-is-text/324422 "2023-02-02T10:05:08Z")

</div>

Hi Team, We are using ES 7.16.2 version and below is the query which we have generated using Java apis, Please let us know why it is not working or are we doing something wrong? Query: - { "bool" : { "must" : \[ …

---

## [Sliced search not returning all hits](https://discuss.elastic.co/t/sliced-search-not-returning-all-hits/324513)

<div class="topic-metadata">

**Author:** [@jkruger](https://discuss.elastic.co/u/jkruger)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 8:30am UTC](https://discuss.elastic.co/t/sliced-search-not-returning-all-hits/324513 "2023-02-02T08:30:38Z")

</div>

Hello, I am a new Elastic user, and I already ran into an issue. I am trying to extract all logs from a certain index. In order to deal with large indices I want to implement pagination using search\_after and PiTs (Poin…

---

## [Winlogbeat I am getting error when winlogbeat is 7.5 and elastic is 8.5.3](https://discuss.elastic.co/t/winlogbeat-i-am-getting-error-when-winlogbeat-is-7-5-and-elastic-is-8-5-3/324500)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:02am UTC](https://discuss.elastic.co/t/winlogbeat-i-am-getting-error-when-winlogbeat-is-7-5-and-elastic-is-8-5-3/324500 "2023-02-02T06:02:50Z")

</div>

I am getting error when winlogbeat is 7.5 and elastic is 8.5.3 and kibana is also 8.5.3 if winlogbeat is 7.5 and elastic and kibana also 7.5 it is working fine ERROR pipeline/output.go:100 Failed to connect to backoff(…

---

## [When creating an api key does run-as override the other settings?](https://discuss.elastic.co/t/when-creating-an-api-key-does-run-as-override-the-other-settings/324280)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 3:12am UTC](https://discuss.elastic.co/t/when-creating-an-api-key-does-run-as-override-the-other-settings/324280 "2023-02-02T03:12:29Z")

</div>

I created an API key and left the other settings apart from run-as as default (i.e. wide open) and set run as to a user with a role that has the desired priviliges. Will this key have the restriction of the assigned rol…

---

## [Is number of documents in an Index is proportional to store.size or pri.store.size?](https://discuss.elastic.co/t/is-number-of-documents-in-an-index-is-proportional-to-store-size-or-pri-store-size/324496)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 3:06am UTC](https://discuss.elastic.co/t/is-number-of-documents-in-an-index-is-proportional-to-store-size-or-pri-store-size/324496 "2023-02-02T03:06:12Z")

</div>

GET /\<index\>/\_count gives me the total number of documents in an index. GET /\_cat/indices/\<index\> gives me both total documents, store.size and pri.store.size. Say if I have an index with 1 primary and 1 replica. say …

---

## [Latency (No data to display) Stack Monitoring Elasticsearch](https://discuss.elastic.co/t/latency-no-data-to-display-stack-monitoring-elasticsearch/324489)

<div class="topic-metadata">

**Author:** [@jacksparrow414](https://discuss.elastic.co/u/jacksparrow414)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 1:32am UTC](https://discuss.elastic.co/t/latency-no-data-to-display-stack-monitoring-elasticsearch/324489 "2023-02-02T01:32:46Z")

</div>

I use Metricbeat to monitor an Elasticsearch node and send metrics to it. The versions of all components are 8.5.3 The Metricbeat configuration file is as follows ## Metricbeat configuration metricbeat.config: modul…

---

## [Combining records that have the same id with a query](https://discuss.elastic.co/t/combining-records-that-have-the-same-id-with-a-query/324479)

<div class="topic-metadata">

**Author:** [@chachew](https://discuss.elastic.co/u/chachew)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 9:24pm UTC](https://discuss.elastic.co/t/combining-records-that-have-the-same-id-with-a-query/324479 "2023-02-01T21:24:45Z")

</div>

I have records for call logs that i want to query and combine into 1 result per record instead of 2. This is for logging of calls from one person to another. The person that initiates the call has the 'initiator' flag se…

---

## [Make a copy of a running Elastic node](https://discuss.elastic.co/t/make-a-copy-of-a-running-elastic-node/324448)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 8\
**Last updated:** [February 1, 2023, 9:02pm UTC](https://discuss.elastic.co/t/make-a-copy-of-a-running-elastic-node/324448 "2023-02-01T21:02:49Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. The whole process is running in a remote server. I need to make a copy of the index int…

---

## [Elasticsearch 1.7.0 has authentication at all?](https://discuss.elastic.co/t/elasticsearch-1-7-0-has-authentication-at-all/324394)

<div class="topic-metadata">

**Author:** [@RaZzLe](https://discuss.elastic.co/u/RaZzLe)\
**Replies:** 6\
**Last updated:** [February 1, 2023, 8:23pm UTC](https://discuss.elastic.co/t/elasticsearch-1-7-0-has-authentication-at-all/324394 "2023-02-01T20:23:48Z")

</div>

Hello all, I have received an e-mail from the security department that one of the machines which is under my administration has a basic authentication on Elasticsearch. I have checked the respective Elasticsearch insta…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=305)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=307)
