# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=310

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 311

---

## [Zscaler logs mapped to ECS](https://discuss.elastic.co/t/zscaler-logs-mapped-to-ecs/323963)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 1:40pm UTC](https://discuss.elastic.co/t/zscaler-logs-mapped-to-ecs/323963 "2023-01-26T13:40:54Z")

</div>

I'm working on ingesting zscaler zia logs and I'm trying to understand the mapping. I'm looking at the following websites: Zscaler Internet Access | Elastic docs for what happens inside Elastic/Kibana and NSS Feed Out…

---

## [In ES 7.0, when using sequence numbers based recovery,primary and replica shard will be inconsistent](https://discuss.elastic.co/t/in-es-7-0-when-using-sequence-numbers-based-recovery-primary-and-replica-shard-will-be-inconsistent/324006)

<div class="topic-metadata">

**Author:** [@warriorswin](https://discuss.elastic.co/u/warriorswin)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 1:29pm UTC](https://discuss.elastic.co/t/in-es-7-0-when-using-sequence-numbers-based-recovery-primary-and-replica-shard-will-be-inconsistent/324006 "2023-01-26T13:29:15Z")

</div>

add data=A node1 primary data=A seqNo=1 No persistence node2 replica data=A seqNo=1 Persistence node1,node2 shutdown node1 restart and add data=B node1 primary data=B seqNo=1 node2 restart When using sequence numb…

---

## [Role to ingesting for custom user](https://discuss.elastic.co/t/role-to-ingesting-for-custom-user/324020)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 12:34pm UTC](https://discuss.elastic.co/t/role-to-ingesting-for-custom-user/324020 "2023-01-26T12:34:36Z")

</div>

Hi everyone, i want to know what exactly roles required for ingesting if i want to create custom user only for ingesting? fyi, i'm using elastic v7.13 i've been read this page but i'm so confused. what privileges that…

---

## [ES\_TMPDIR not setting all temporary files](https://discuss.elastic.co/t/es-tmpdir-not-setting-all-temporary-files/324019)

<div class="topic-metadata">

**Author:** [@lquenti](https://discuss.elastic.co/u/lquenti)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 12:00pm UTC](https://discuss.elastic.co/t/es-tmpdir-not-setting-all-temporary-files/324019 "2023-01-26T12:00:42Z")

</div>

Hi all, I am currently trying to set up elasticsearch with a read-only config directory within a docker based on the elasticsearch image. After thoroughly reading the docs, the only related Option I found was the ES\_TMP…

---

## [Can i sort my documents by date several conditions?](https://discuss.elastic.co/t/can-i-sort-my-documents-by-date-several-conditions/324015)

<div class="topic-metadata">

**Author:** [@Volodymyr\_Dzhuryn](https://discuss.elastic.co/u/Volodymyr_Dzhuryn)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 11:55am UTC](https://discuss.elastic.co/t/can-i-sort-my-documents-by-date-several-conditions/324015 "2023-01-26T11:55:34Z")

</div>

I have index with document which have two field with dates "match\_date\_time" and "created\_at". I need query for getting documents sorted by next criteria 1. \[ASC order\] articles with future match date and time (sorted …

---

## [Not enough nodes to allocate all shard replicas](https://discuss.elastic.co/t/not-enough-nodes-to-allocate-all-shard-replicas/323360)

<div class="topic-metadata">

**Author:** [@michielswaanen](https://discuss.elastic.co/u/michielswaanen)\
**Replies:** 11\
**Last updated:** [January 26, 2023, 11:40am UTC](https://discuss.elastic.co/t/not-enough-nodes-to-allocate-all-shard-replicas/323360 "2023-01-26T11:40:18Z")

</div>

Hey all, My Elasticsearch deployment is showing the following health issue: I tried to fix the issue by following the suggested guide. I scaled our deployment up by increasing the availability zones (from 1 to 2), l…

---

## [Delete index](https://discuss.elastic.co/t/delete-index/324016)

<div class="topic-metadata">

**Author:** [@mezzetto\_mezzetto](https://discuss.elastic.co/u/mezzetto_mezzetto)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 11:19am UTC](https://discuss.elastic.co/t/delete-index/324016 "2023-01-26T11:19:17Z")

</div>

Hi all, I'm newbie on elastic. I've a custom installation an I need to free storage space; I've a rollover policy that creates a new index after 30 days or if it reach 50GB; I have 14 index, if I try to close a very old …

---

## [Just 1 docker swarm node is visible in Kibana](https://discuss.elastic.co/t/just-1-docker-swarm-node-is-visible-in-kibana/324002)

<div class="topic-metadata">

**Author:** [@albert2022](https://discuss.elastic.co/u/albert2022)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 8:55am UTC](https://discuss.elastic.co/t/just-1-docker-swarm-node-is-visible-in-kibana/324002 "2023-01-26T08:55:56Z")

</div>

Hi, We configured a cluster using the docker swarm based on the following yml file: version: '3.8' services: node-master: deploy: replicas: 1 placement: constraints: - node.labels.e…

---

## [Full-text search is faster if queries are sent constantly](https://discuss.elastic.co/t/full-text-search-is-faster-if-queries-are-sent-constantly/323955)

<div class="topic-metadata">

**Author:** [@athlonIIx2](https://discuss.elastic.co/u/athlonIIx2)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 8:55am UTC](https://discuss.elastic.co/t/full-text-search-is-faster-if-queries-are-sent-constantly/323955 "2023-01-26T08:55:48Z")

</div>

Please help me understand my case, as I am new to Elasticsearch. I use Elasticsearch on a single node to make full-text search queries from a Python API. The problem is that searching time may vary from seconds to tens…

---

## [How to Generate UUID from Index Name?](https://discuss.elastic.co/t/how-to-generate-uuid-from-index-name/323979)

<div class="topic-metadata">

**Author:** [@Nebula](https://discuss.elastic.co/u/Nebula)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 3:36am UTC](https://discuss.elastic.co/t/how-to-generate-uuid-from-index-name/323979 "2023-01-26T03:36:16Z")

</div>

Hello everyone, I have some index patterns setup in my Elasticsearch. I see the index name gets encoded as a UUID in the URL (the value for the key “index:” in the URL once an index is selected). How can I go about gen…

---

## [Upgrade elasticsearch 8.5.0 master not discovered or elected yet and uncaught exception in thread](https://discuss.elastic.co/t/upgrade-elasticsearch-8-5-0-master-not-discovered-or-elected-yet-and-uncaught-exception-in-thread/323974)

<div class="topic-metadata">

**Author:** [@gps88](https://discuss.elastic.co/u/gps88)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 10:13pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-8-5-0-master-not-discovered-or-elected-yet-and-uncaught-exception-in-thread/323974 "2023-01-25T22:13:23Z")

</div>

I have 3 elasticsearch nodes, nodes 1 and 2 (Red Hat Enterprise Linux release 8.6 ) are configured as master, I try to start the service and it only starts node 3 which is data only, nodes 1 and 2 show the following in t…

---

## [Dynamic-mapped field changes type after rollover](https://discuss.elastic.co/t/dynamic-mapped-field-changes-type-after-rollover/323968)

<div class="topic-metadata">

**Author:** [@foxy](https://discuss.elastic.co/u/foxy)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 8:04pm UTC](https://discuss.elastic.co/t/dynamic-mapped-field-changes-type-after-rollover/323968 "2023-01-25T20:04:47Z")

</div>

A field in the latest backing index for a data-stream has been mapped to a different type following rollover: Is it possible to re-index the current write index into a new index that would match the index pattern (…

---

## [How to implement "immutable indices"?](https://discuss.elastic.co/t/how-to-implement-immutable-indices/323297)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 6\
**Last updated:** [January 25, 2023, 7:36pm UTC](https://discuss.elastic.co/t/how-to-implement-immutable-indices/323297 "2023-01-25T19:36:43Z")

</div>

Hi We are using platinum subscription for our "elastic" stack from "elastic.co" and we are informed that they do not support "immutable indices" for our subscription. We are using the elasticsearch version 7.17.5 with o…

---

## [Migration tool for legacy index templates to composable?](https://discuss.elastic.co/t/migration-tool-for-legacy-index-templates-to-composable/323433)

<div class="topic-metadata">

**Author:** [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 7:35pm UTC](https://discuss.elastic.co/t/migration-tool-for-legacy-index-templates-to-composable/323433 "2023-01-25T19:35:55Z")

</div>

We have a large number of legacy index templates. Is there any migration tools to move them to their composable index template version? If not, what is the best way of migrating them?

---

## [Customize Kibana Alerting Rule](https://discuss.elastic.co/t/customize-kibana-alerting-rule/323961)

<div class="topic-metadata">

**Author:** [@lchan](https://discuss.elastic.co/u/lchan)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 7:05pm UTC](https://discuss.elastic.co/t/customize-kibana-alerting-rule/323961 "2023-01-25T19:05:44Z")

</div>

Hello, Is there a way to customize the canned alert rules in Elastic Cloud \> rules? (KQL Query?) Frozen node is using disk cache and always at 90% and I would like to filter the node role. I tried some KQL expression i…

---

## [Bulding nested query with new Java API](https://discuss.elastic.co/t/bulding-nested-query-with-new-java-api/323949)

<div class="topic-metadata">

**Author:** [@schmermeister](https://discuss.elastic.co/u/schmermeister)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 4:55pm UTC](https://discuss.elastic.co/t/bulding-nested-query-with-new-java-api/323949 "2023-01-25T16:55:36Z")

</div>

I try to achieve a query like this: { "query": { "bool": { "must": \[ { "match": { "metaData.cluster": "mobile" } } }, { "bool": …

---

## [Synonyms not being used in search results](https://discuss.elastic.co/t/synonyms-not-being-used-in-search-results/323920)

<div class="topic-metadata">

**Author:** [@appsol](https://discuss.elastic.co/u/appsol)\
**Replies:** 5\
**Last updated:** [January 25, 2023, 4:46pm UTC](https://discuss.elastic.co/t/synonyms-not-being-used-in-search-results/323920 "2023-01-25T16:46:55Z")

</div>

Hello, I have an index for services named 'testing\_services': 'properties' =\> \[ 'id' =\> \['type' =\> 'keyword'\], 'name' =\> \[ 'type' =\> 'text', 'analyzer' =\> 'english…

---

## [Analyzer conditional token filter with regular expression](https://discuss.elastic.co/t/analyzer-conditional-token-filter-with-regular-expression/323943)

<div class="topic-metadata">

**Author:** [@Wonder\_Garance](https://discuss.elastic.co/u/Wonder_Garance)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 4:29pm UTC](https://discuss.elastic.co/t/analyzer-conditional-token-filter-with-regular-expression/323943 "2023-01-25T16:29:25Z")

</div>

Hello, in an analyzer conditional token filter, I use a painless script with the regular expression. If a token contains only letters et hypens, then the compound word in the token is splitted, otherwise no. But my scri…

---

## [Watcher webhook to create a OTRS ticket](https://discuss.elastic.co/t/watcher-webhook-to-create-a-otrs-ticket/323855)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 5\
**Last updated:** [January 25, 2023, 4:27pm UTC](https://discuss.elastic.co/t/watcher-webhook-to-create-a-otrs-ticket/323855 "2023-01-25T16:27:22Z")

</div>

I can curl and make an OTRS ticket by using the following : curl "http://myotrs.com/otrs/nph-genericinterface.pl/Webservice/GenericTicketConnectorREST/Ticket?UserLogin=username&Password=password" -H "Content-Type: app…

---

## [Deployment of Elasticsearch to EKS cluster with helm](https://discuss.elastic.co/t/deployment-of-elasticsearch-to-eks-cluster-with-helm/323944)

<div class="topic-metadata">

**Author:** [@Boris\_Tsekinovsky](https://discuss.elastic.co/u/Boris_Tsekinovsky)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 4:00pm UTC](https://discuss.elastic.co/t/deployment-of-elasticsearch-to-eks-cluster-with-helm/323944 "2023-01-25T16:00:53Z")

</div>

Hello elastic community, I'm trying to install ELK stack on AWS EKS cluster. I've created the cluster using CDK and now trying to deploy elasticsearch using helm: helm install elasticsearch elastic/elasticsearch -n mon…

---

## [Watcher Email Action with Custom X-Header?](https://discuss.elastic.co/t/watcher-email-action-with-custom-x-header/323938)

<div class="topic-metadata">

**Author:** [@bsherman](https://discuss.elastic.co/u/bsherman)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 3:01pm UTC](https://discuss.elastic.co/t/watcher-email-action-with-custom-x-header/323938 "2023-01-25T15:01:18Z")

</div>

My organization is using the Watcher Email Action and recently we discovered our emails are not reaching their recipient because a custom X-header is expected but we are not populating it. Is there a way to set a custom…

---

## [Highlight: Nested search highlights entire phrase instead of matched term](https://discuss.elastic.co/t/highlight-nested-search-highlights-entire-phrase-instead-of-matched-term/323934)

<div class="topic-metadata">

**Author:** [@sandy01](https://discuss.elastic.co/u/sandy01)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:49pm UTC](https://discuss.elastic.co/t/highlight-nested-search-highlights-entire-phrase-instead-of-matched-term/323934 "2023-01-25T14:49:30Z")

</div>

Hello, I have a lot of data of this type: { "timestamp": "2021-01-01T01:22:31" "urls": \[ { "visited": false, "url": "https://drive.google.com", }, { "…

---

## [Cluster red, unassigned shards, no response on writes](https://discuss.elastic.co/t/cluster-red-unassigned-shards-no-response-on-writes/322114)

<div class="topic-metadata">

**Author:** [@decibel83](https://discuss.elastic.co/u/decibel83)\
**Replies:** 16\
**Last updated:** [January 25, 2023, 2:41pm UTC](https://discuss.elastic.co/t/cluster-red-unassigned-shards-no-response-on-writes/322114 "2023-01-25T14:41:58Z")

</div>

Hi everyone, I'm dealing with a problem on Elasticsearch 7.17.5 (I've also tried to upgrade it to version 8 but I'm having the same problem with that version too) which is hanged, red status and unresponsive on any writ…

---

## [Get count based on geo\_distance filter and term search inside an item attribute in ES 7.10](https://discuss.elastic.co/t/get-count-based-on-geo-distance-filter-and-term-search-inside-an-item-attribute-in-es-7-10/323933)

<div class="topic-metadata">

**Author:** [@Coman\_Alexandru](https://discuss.elastic.co/u/Coman_Alexandru)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:35pm UTC](https://discuss.elastic.co/t/get-count-based-on-geo-distance-filter-and-term-search-inside-an-item-attribute-in-es-7-10/323933 "2023-01-25T14:35:48Z")

</div>

I'm running Elasticsearch version: 7.10 with an index and below you have an example for an index item: { "\_index": "wonder-search", "\_type": "\_doc", "\_id": "Bvpam4UBCGd9T\_03g7QP", "\_version": 1, "\_seq\_no": 2000, "…

---

## [Omit indices when searching on multiple indices](https://discuss.elastic.co/t/omit-indices-when-searching-on-multiple-indices/323866)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [January 25, 2023, 1:32pm UTC](https://discuss.elastic.co/t/omit-indices-when-searching-on-multiple-indices/323866 "2023-01-25T13:32:23Z")

</div>

A question and maybe a feature request. We have 100 indices for filebeat with this pattern: filebeat-{CLUSTER\_NAME}-{NAMESPACE}-{DATE} . Documents are: {"@timestamp" : "..." , "cluster" : "prod", "namespace" : "kub…

---

## [Determine if field containing special characters in name is not null in Elasticsearch ingest pipeline](https://discuss.elastic.co/t/determine-if-field-containing-special-characters-in-name-is-not-null-in-elasticsearch-ingest-pipeline/322406)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 2:10pm UTC](https://discuss.elastic.co/t/determine-if-field-containing-special-characters-in-name-is-not-null-in-elasticsearch-ingest-pipeline/322406 "2023-01-25T14:10:47Z")

</div>

I'm monitoring a set of pods using elastic-agent which have labels which resolve to the following format when ingested: kubernetes.labels.foo\_bar/baz: value I need to do something in Elasticsearch ingest pipeline if th…

---

## [How to use the http.p12, http\_ca.crt and transport.p12 generated by elasticsearch when run as a single node](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913)

<div class="topic-metadata">

**Author:** [@Raja\_Muneer](https://discuss.elastic.co/u/Raja_Muneer)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 12:51pm UTC](https://discuss.elastic.co/t/how-to-use-the-http-p12-http-ca-crt-and-transport-p12-generated-by-elasticsearch-when-run-as-a-single-node/323913 "2023-01-25T12:51:25Z")

</div>

I am trying to enable HTTPS on my elk-stack. While I am able to do so using the following link. Configuring ssl,tls and https However, When we run elasticsearch as a single node it generates some default certificates w…

---

## [Elastic Transforms - continous mode is not detecting changes](https://discuss.elastic.co/t/elastic-transforms-continous-mode-is-not-detecting-changes/323895)

<div class="topic-metadata">

**Author:** [@catrexis](https://discuss.elastic.co/u/catrexis)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 12:32pm UTC](https://discuss.elastic.co/t/elastic-transforms-continous-mode-is-not-detecting-changes/323895 "2023-01-25T12:32:07Z")

</div>

I have a problem with my index transformation and already tried so many different versions but nothing helped: My documents in the source index look like: { "content" : { "creationTime" : "2022-07-25 16:00:49 +02…

---

## [Correct way to get Not Exists or Exists and empty fields Query for multiple level of nested properties](https://discuss.elastic.co/t/correct-way-to-get-not-exists-or-exists-and-empty-fields-query-for-multiple-level-of-nested-properties/323903)

<div class="topic-metadata">

**Author:** [@Denis\_Kostaev](https://discuss.elastic.co/u/Denis_Kostaev)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 9:39am UTC](https://discuss.elastic.co/t/correct-way-to-get-not-exists-or-exists-and-empty-fields-query-for-multiple-level-of-nested-properties/323903 "2023-01-25T09:39:31Z")

</div>

Hello, I have a mapping with the multiple level of nested properties. I'm trying to get Not Exists (not mapped) fields on 3 lvl or Exists and empty (empty string or null values). "mappings": { "properties": { …

---

## [ES 8 Java client: BoolQuery.Builder no longer has hasClauses() method](https://discuss.elastic.co/t/es-8-java-client-boolquery-builder-no-longer-has-hasclauses-method/323894)

<div class="topic-metadata">

**Author:** [@yusufozcan](https://discuss.elastic.co/u/yusufozcan)\
**Replies:** 3\
**Last updated:** [January 25, 2023, 10:33am UTC](https://discuss.elastic.co/t/es-8-java-client-boolquery-builder-no-longer-has-hasclauses-method/323894 "2023-01-25T10:33:00Z")

</div>

Hello. We are upgrading our elastic java client from 6.8.10 to 8.1.3 and it seems BoolQuery.Builder doesn't have hasClauses() method anymore. Is there any workaround which provides the same functionality? Thanks in adv…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=309)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=311)
