# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=31

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 32

---

## [Query slowdowns when adding a second sort after \_score](https://discuss.elastic.co/t/query-slowdowns-when-adding-a-second-sort-after-score/378354)

<div class="topic-metadata">

**Author:** [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Replies:** 1\
**Last updated:** [May 28, 2025, 7:49am UTC](https://discuss.elastic.co/t/query-slowdowns-when-adding-a-second-sort-after-score/378354 "2025-05-28T07:49:18Z")

</div>

Hey there! I have an interesting problem that I do have a hunch on but lack a full explanation. I am querying an index with a solid double digit million number of documents. One of my queries (nested, function score, s…

---

## [Elasticsearch Multi Tenant Sharding](https://discuss.elastic.co/t/elasticsearch-multi-tenant-sharding/378617)

<div class="topic-metadata">

**Author:** [@cufflink3401](https://discuss.elastic.co/u/cufflink3401)\
**Replies:** 0\
**Last updated:** [May 27, 2025, 9:52pm UTC](https://discuss.elastic.co/t/elasticsearch-multi-tenant-sharding/378617 "2025-05-27T21:52:00Z")

</div>

Hey, I'm trying to stabilize an old cluster. We are running on 7.10, and plan to upgrade, but first need to stabilize the situation. Our current configuration is running 57 shards, replication 1, on 4 nodes + 3 master …

---

## [Field Year cannot be printed as the value 292278994 exceeds the maximum print width of 4](https://discuss.elastic.co/t/field-year-cannot-be-printed-as-the-value-292278994-exceeds-the-maximum-print-width-of-4/378581)

<div class="topic-metadata">

**Author:** [@jlp1](https://discuss.elastic.co/u/jlp1)\
**Replies:** 3\
**Last updated:** [May 27, 2025, 5:40pm UTC](https://discuss.elastic.co/t/field-year-cannot-be-printed-as-the-value-292278994-exceeds-the-maximum-print-width-of-4/378581 "2025-05-27T17:40:03Z")

</div>

I am using elasticsearch 7.17.6 I am getting "Field Year cannot be printed as the value 292278994 exceeds the maximum print width of 4" error when I try to sort by RegistrationDate. The strange thing is that I get this …

---

## [Error In Elasticsearch Service in EC2 Instance](https://discuss.elastic.co/t/error-in-elasticsearch-service-in-ec2-instance/378598)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 1\
**Last updated:** [May 27, 2025, 3:02pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-service-in-ec2-instance/378598 "2025-05-27T15:02:57Z")

</div>

HI Team, When setting up an Elasticsearch cluster on an AWS EC2 instance, it's important to configure the elasticsearch.yml file correctly. When using the private IP of the EC2 instance, the service starts successfully.…

---

## [What can I do to avoid exceeding the max\_clause\_count limit in match queries?](https://discuss.elastic.co/t/what-can-i-do-to-avoid-exceeding-the-max-clause-count-limit-in-match-queries/378574)

<div class="topic-metadata">

**Author:** [@Zoree](https://discuss.elastic.co/u/Zoree)\
**Replies:** 0\
**Last updated:** [May 27, 2025, 9:44am UTC](https://discuss.elastic.co/t/what-can-i-do-to-avoid-exceeding-the-max-clause-count-limit-in-match-queries/378574 "2025-05-27T09:44:00Z")

</div>

In our search, span\_near was previously used for distance search with term queries, but this led to a smaller sample than I would like, I moved the implementation to IntervalQuery with match, but now an error is being is…

---

## [Help with querying all the documents within a given @timestamp field from an index](https://discuss.elastic.co/t/help-with-querying-all-the-documents-within-a-given-timestamp-field-from-an-index/378562)

<div class="topic-metadata">

**Author:** [@Nikhil\_Shivanath](https://discuss.elastic.co/u/Nikhil_Shivanath)\
**Replies:** 4\
**Last updated:** [May 27, 2025, 8:10am UTC](https://discuss.elastic.co/t/help-with-querying-all-the-documents-within-a-given-timestamp-field-from-an-index/378562 "2025-05-27T08:10:01Z")

</div>

Hi , I could really use some help with querying all the documents from an index between the @timestamp value of may 21 and may 22 ,. I'm using the python client as of now but it only seems to return 10,000 of these docum…

---

## [ECE to ELK migration](https://discuss.elastic.co/t/ece-to-elk-migration/378032)

<div class="topic-metadata">

**Author:** [@sharathsurya](https://discuss.elastic.co/u/sharathsurya)\
**Replies:** 2\
**Last updated:** [May 27, 2025, 5:16am UTC](https://discuss.elastic.co/t/ece-to-elk-migration/378032 "2025-05-27T05:16:54Z")

</div>

Hi I am new to elastic products. We have a requirement to migrate from ECE (Elastic Cloud Enterprise, paid version ) to ELK (Elasticsearch, Kibana, Log stash) Open source version. Is it possible to migrate with existing…

---

## [Backup Of Elastic Cluster](https://discuss.elastic.co/t/backup-of-elastic-cluster/378474)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [May 26, 2025, 4:30pm UTC](https://discuss.elastic.co/t/backup-of-elastic-cluster/378474 "2025-05-26T16:30:45Z")

</div>

Hi Team, If we want to take backup of elastic cluster by using below command. Will it take backup everything in cluster like ILM Policy, SLM Policy and any settings related to cluster. PUT \_slm/policy/weekly-snapshots …

---

## [We can create our own dashboard on views per dashboard?](https://discuss.elastic.co/t/we-can-create-our-own-dashboard-on-views-per-dashboard/377185)

<div class="topic-metadata">

**Author:** [@shinysap](https://discuss.elastic.co/u/shinysap)\
**Replies:** 2\
**Last updated:** [May 26, 2025, 1:38pm UTC](https://discuss.elastic.co/t/we-can-create-our-own-dashboard-on-views-per-dashboard/377185 "2025-05-26T13:38:15Z")

</div>

Dear elastic Team, With recent release of kibana we noticed that there is a Dashboard views option. we can create our own dashboard on views per dashboard? However i could never find the source index for the dashboard …

---

## [Hello elastic world](https://discuss.elastic.co/t/hello-elastic-world/378507)

<div class="topic-metadata">

**Author:** [@roseebony532](https://discuss.elastic.co/u/roseebony532)\
**Replies:** 1\
**Last updated:** [May 26, 2025, 8:01am UTC](https://discuss.elastic.co/t/hello-elastic-world/378507 "2025-05-26T08:01:18Z")

</div>

Hello, is there a plugin that lets you text search and move your cursor while collecting the entire dap scope of a debugging session? Thank you,

---

## [XOR operator in a Query String Query](https://discuss.elastic.co/t/xor-operator-in-a-query-string-query/373135)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 2\
**Last updated:** [May 26, 2025, 5:10am UTC](https://discuss.elastic.co/t/xor-operator-in-a-query-string-query/373135 "2025-05-26T05:10:12Z")

</div>

Hi, First of all a happy 2025! I was reading the syntax documentation of the Query String Query and the Simple one. I noticed there was no XOR operator but there is OR AND and NOT. So I was wondering if it was possib…

---

## [Implement filebeat with ingest pipelies](https://discuss.elastic.co/t/implement-filebeat-with-ingest-pipelies/378482)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 19\
**Last updated:** [May 25, 2025, 10:40pm UTC](https://discuss.elastic.co/t/implement-filebeat-with-ingest-pipelies/378482 "2025-05-25T22:40:53Z")

</div>

Hello, I have ELK instance which consists of elasticsearch, logstash and kibana. I would like to implement filebeat with ingest pipelines - meaning filebeat sends logs with tags and ingest pipelines recognize it and cr…

---

## [Possible to have Elasticsearch prefer same availability zone shard allocation?](https://discuss.elastic.co/t/possible-to-have-elasticsearch-prefer-same-availability-zone-shard-allocation/378504)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [May 25, 2025, 10:37pm UTC](https://discuss.elastic.co/t/possible-to-have-elasticsearch-prefer-same-availability-zone-shard-allocation/378504 "2025-05-25T22:37:04Z")

</div>

Hi All, I'm curious if anyone knows if the following scenario is possible within Elasticsearch. Suppose I have a 6-node cluster spread across 3 availability zones (AZ) (2 nodes per AZ). I want to have some resiliency, …

---

## [Issue with rollover ERROR](https://discuss.elastic.co/t/issue-with-rollover-error/378009)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 4\
**Last updated:** [May 24, 2025, 1:14am UTC](https://discuss.elastic.co/t/issue-with-rollover-error/378009 "2025-05-24T01:14:50Z")

</div>

Hello, I have isssue with rollover error during step with ILM. I created ILM (all rollover settings disabled) to remove indexes after 365 days. During ILM work I founded below error: \> \> "step": "check-rollover-read…

---

## [bucket script to find the percent change in filter bucket](https://discuss.elastic.co/t/bucket-script-to-find-the-percent-change-in-filter-bucket/378458)

<div class="topic-metadata">

**Author:** [@Ramji\_Balu\_Sudarsan](https://discuss.elastic.co/u/Ramji_Balu_Sudarsan)\
**Replies:** 0\
**Last updated:** [May 23, 2025, 7:24am UTC](https://discuss.elastic.co/t/bucket-script-to-find-the-percent-change-in-filter-bucket/378458 "2025-05-23T07:24:07Z")

</div>

I have formed an aggregation query to bucket my tickets based on created\_at epoch. Based on my query I will get two buckets each named previous and current. GET tickets\_trend\_analysis/\_search { "aggs": { "time\_win…

---

## [Increased Read IOPS usage after upgrade from 8.18.0 to 9.0.1](https://discuss.elastic.co/t/increased-read-iops-usage-after-upgrade-from-8-18-0-to-9-0-1/377986)

<div class="topic-metadata">

**Author:** [@applike-ss](https://discuss.elastic.co/u/applike-ss)\
**Replies:** 23\
**Last updated:** [May 22, 2025, 10:36am UTC](https://discuss.elastic.co/t/increased-read-iops-usage-after-upgrade-from-8-18-0-to-9-0-1/377986 "2025-05-22T10:36:06Z")

</div>

Hi all, since upgrading from 8.18.0 to 9.0.1 i'm seeing a massive increase of read IOPS on the data node disks. I couldn't see anything obvious in the release notes of 8.18.1, 9.0.0 and 9.0.1 that would lead to this. …

---

## [In Elasticsearch, Is updating document done in real time?](https://discuss.elastic.co/t/in-elasticsearch-is-updating-document-done-in-real-time/378407)

<div class="topic-metadata">

**Author:** [@yudianer](https://discuss.elastic.co/u/yudianer)\
**Replies:** 2\
**Last updated:** [May 22, 2025, 9:00am UTC](https://discuss.elastic.co/t/in-elasticsearch-is-updating-document-done-in-real-time/378407 "2025-05-22T09:00:56Z")

</div>

Hi, Refresh mechanism makes confused about if updating succeed once I get response from ES. Or is updating done in real-time and synchronised with user update request sending?. As many say, updating a document execute…

---

## [Circuit breaking Issue occurring](https://discuss.elastic.co/t/circuit-breaking-issue-occurring/378386)

<div class="topic-metadata">

**Author:** [@mnaumtian](https://discuss.elastic.co/u/mnaumtian)\
**Replies:** 2\
**Last updated:** [May 21, 2025, 2:10pm UTC](https://discuss.elastic.co/t/circuit-breaking-issue-occurring/378386 "2025-05-21T14:10:20Z")

</div>

"root\_cause" : \[ { "type" : "circuit\_breaking\_exception", "reason" : "\[fielddata\] Data too large, data for \[\_id\] would be \[434536627/414.4mb\], which is larger than the limit of \[429496729/409.5mb\]", "bytes\_wanted" : …

---

## [Installation ELK on OCI](https://discuss.elastic.co/t/installation-elk-on-oci/378378)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 1\
**Last updated:** [May 21, 2025, 11:00am UTC](https://discuss.elastic.co/t/installation-elk-on-oci/378378 "2025-05-21T11:00:03Z")

</div>

I have requirement to install ELK in our OCI servers. When I checked in Elastic website to download the RPM,I found there are many . Which one I should use? Please guide me ,I am very new to this product

---

## [I'm experiencing an issue with rule configuration in Stack Management](https://discuss.elastic.co/t/im-experiencing-an-issue-with-rule-configuration-in-stack-management/378343)

<div class="topic-metadata">

**Author:** [@elastic\_interogation](https://discuss.elastic.co/u/elastic_interogation)\
**Replies:** 4\
**Last updated:** [May 21, 2025, 8:47am UTC](https://discuss.elastic.co/t/im-experiencing-an-issue-with-rule-configuration-in-stack-management/378343 "2025-05-21T08:47:45Z")

</div>

Hi, I would like some help in the Rules and Connectors folder, I created rules based on an Elasticsearch query to detect the number of matches, using a custom threshold that I want to set myself. However, I don't unde…

---

## [Product compatibility with version 9.X not available on Support Matrix](https://discuss.elastic.co/t/product-compatibility-with-version-9-x-not-available-on-support-matrix/378306)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 4\
**Last updated:** [May 21, 2025, 4:33am UTC](https://discuss.elastic.co/t/product-compatibility-with-version-9-x-not-available-on-support-matrix/378306 "2025-05-21T04:33:37Z")

</div>

Hello, This is a simple question, what are the product compatibility from older versions with the stack on version 9.X? The columns for the compatibility with Beats, Elastic Agent and Logstash in the support matrix pag…

---

## [ElasticSearch Node Rebuilt - lost indices](https://discuss.elastic.co/t/elasticsearch-node-rebuilt-lost-indices/377507)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 3\
**Last updated:** [May 20, 2025, 8:51pm UTC](https://discuss.elastic.co/t/elasticsearch-node-rebuilt-lost-indices/377507 "2025-05-20T20:51:47Z")

</div>

I had to rebuild a failing ES NODE and after I finished the re-indexing I can see that in the nodes folder there are several other indices that I didn't restore and I don't think are needed by anyone. I don't think they…

---

## [One index or multiple index for exact same mapping, but the data are clustered based on a field](https://discuss.elastic.co/t/one-index-or-multiple-index-for-exact-same-mapping-but-the-data-are-clustered-based-on-a-field/378311)

<div class="topic-metadata">

**Author:** [@orfeas\_filippopoulos](https://discuss.elastic.co/u/orfeas_filippopoulos)\
**Replies:** 2\
**Last updated:** [May 20, 2025, 7:10pm UTC](https://discuss.elastic.co/t/one-index-or-multiple-index-for-exact-same-mapping-but-the-data-are-clustered-based-on-a-field/378311 "2025-05-20T19:10:33Z")

</div>

Hi there, community! I have a short question. I have around 100k documents, each ranging from a few hundred KB to a maximum of 1MB. The documents have exactly the same mapping but can be grouped into three different cl…

---

## [How to Use Custom Embeddings (Ollama) for Hybrid Search in Elasticsearch?](https://discuss.elastic.co/t/how-to-use-custom-embeddings-ollama-for-hybrid-search-in-elasticsearch/378323)

<div class="topic-metadata">

**Author:** [@Muhammad\_Fhadli](https://discuss.elastic.co/u/Muhammad_Fhadli)\
**Replies:** 1\
**Last updated:** [May 20, 2025, 6:15pm UTC](https://discuss.elastic.co/t/how-to-use-custom-embeddings-ollama-for-hybrid-search-in-elasticsearch/378323 "2025-05-20T18:15:47Z")

</div>

I'm trying to combine lexical search and semantic search using the RRF (Reciprocal Rank Fusion) algorithm, as described in the Elasticsearch documentation: Since my data is in Indonesian, I need to use a custom embeddi…

---

## [Elastic Indexes and Data Streams](https://discuss.elastic.co/t/elastic-indexes-and-data-streams/377674)

<div class="topic-metadata">

**Author:** [@h0nus](https://discuss.elastic.co/u/h0nus)\
**Replies:** 2\
**Last updated:** [May 20, 2025, 4:16pm UTC](https://discuss.elastic.co/t/elastic-indexes-and-data-streams/377674 "2025-05-20T16:16:51Z")

</div>

Hello everyone, I was wondering how should I make my policy for Elastic to clean the space up on a 200GB limited space VM. I studied deeply the config of Index Policies and I've set my custom ones for my needs. Since …

---

## [Does in-flight request breaker really track writing requests?](https://discuss.elastic.co/t/does-in-flight-request-breaker-really-track-writing-requests/378330)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 2\
**Last updated:** [May 20, 2025, 2:25pm UTC](https://discuss.elastic.co/t/does-in-flight-request-breaker-really-track-writing-requests/378330 "2025-05-20T14:25:34Z")

</div>

According to the comment above CircuitBreaker#IN\_FLIGHT\_REQUESTS: /\*\* \* The in-flight request breaker tracks bytes allocated for reading and \* writing requests on the network layer. \*/ String IN\_F…

---

## [\[multi\_match\] unknown token \[START\_ARRAY\] after \[query\]](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415)

<div class="topic-metadata">

**Author:** [@anujtom](https://discuss.elastic.co/u/anujtom)\
**Replies:** 5\
**Last updated:** [May 20, 2025, 1:14pm UTC](https://discuss.elastic.co/t/multi-match-unknown-token-start-array-after-query/376415 "2025-05-20T13:14:48Z")

</div>

Hi, I am trying to fetch fields within same attribute to send response. Fetch "abc" "yui" pattern from full\_message attribute. GET /my\_index/\_search { "query": { "multi\_match": { "query": \[ "abc" , "yui" \] , "f…

---

## [Elasticsearch: How to delete restricted indices](https://discuss.elastic.co/t/elasticsearch-how-to-delete-restricted-indices/378284)

<div class="topic-metadata">

**Author:** [@cisupport-zkb](https://discuss.elastic.co/u/cisupport-zkb)\
**Replies:** 2\
**Last updated:** [May 20, 2025, 6:33am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-delete-restricted-indices/378284 "2025-05-20T06:33:56Z")

</div>

Hi everyone, I'm trying to upgrade from Elasticsearch 8.18.0 to 9.0.1, but before upgrading I need to set to read only or delete old created indices with compatibility 7090199, otherwise won't boot up the Elasticsearch …

---

## [Optimizing Large-Scale Elasticsearch Logging Cluster for Resilience and Stability](https://discuss.elastic.co/t/optimizing-large-scale-elasticsearch-logging-cluster-for-resilience-and-stability/378283)

<div class="topic-metadata">

**Author:** [@mazerunner](https://discuss.elastic.co/u/mazerunner)\
**Replies:** 4\
**Last updated:** [May 20, 2025, 5:24am UTC](https://discuss.elastic.co/t/optimizing-large-scale-elasticsearch-logging-cluster-for-resilience-and-stability/378283 "2025-05-20T05:24:11Z")

</div>

We operate a logging cluster with: 180 hot nodes (i3.4xlarge, 400TB, 3-month retention) 250 warm nodes (i3en.2xlarge, 700TB, 15-month retention) 24 router nodes (r5.2xlarge) 3 master eligible nodes (c5.metal) Weekly in…

---

## [Issue with contextlink value for alerts](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496)

<div class="topic-metadata">

**Author:** [@MarioCDS](https://discuss.elastic.co/u/MarioCDS)\
**Replies:** 6\
**Last updated:** [May 19, 2025, 11:46pm UTC](https://discuss.elastic.co/t/issue-with-contextlink-value-for-alerts/376496 "2025-05-19T23:46:08Z")

</div>

Hello, We've been having an issue where our context.link in staging displays the wrong value for our alerts. In dev it shows the correct url like elk-dev.company.com but in staging it shows company-elk-staging.kb.westeu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=30)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=32)
