# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=35

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 36

---

## [Implementing Relative Score Fusion for Hybrid Search in Elasticsearch](https://discuss.elastic.co/t/implementing-relative-score-fusion-for-hybrid-search-in-elasticsearch/364408)

<div class="topic-metadata">

**Author:** [@ayubSubhaniya](https://discuss.elastic.co/u/ayubSubhaniya)\
**Replies:** 3\
**Last updated:** [April 24, 2025, 7:50pm UTC](https://discuss.elastic.co/t/implementing-relative-score-fusion-for-hybrid-search-in-elasticsearch/364408 "2025-04-24T19:50:05Z")

</div>

Hello Elasticsearch Community, I'm interested in implementing Relative Score Fusion (RSF) directly in Elasticsearch to combine BM25 and kNN search results with weighted rankings based on query length or type. I want to …

---

## [Persist ESQL rows after applying AVG and STD\_DEV](https://discuss.elastic.co/t/persist-esql-rows-after-applying-avg-and-std-dev/377497)

<div class="topic-metadata">

**Author:** [@O\_O\_O](https://discuss.elastic.co/u/O_O_O)\
**Replies:** 0\
**Last updated:** [April 24, 2025, 5:01pm UTC](https://discuss.elastic.co/t/persist-esql-rows-after-applying-avg-and-std-dev/377497 "2025-04-24T17:01:10Z")

</div>

If I need to calculate the standard deviation (STD\_DEV) for each row (using a number column from the row), how do I do that? I currently have the snippet below: FROM logs-\* | WHERE event.code == "4768" AND field1 == "v…

---

## [The upgrading of the Elastic Core on premise environment (Kibana, Logstash and Elastic Cluster) from 7.17.28 to 8.17, any recommendations?](https://discuss.elastic.co/t/the-upgrading-of-the-elastic-core-on-premise-environment-kibana-logstash-and-elastic-cluster-from-7-17-28-to-8-17-any-recommendations/377465)

<div class="topic-metadata">

**Author:** [@carbon](https://discuss.elastic.co/u/carbon)\
**Replies:** 4\
**Last updated:** [April 24, 2025, 3:15pm UTC](https://discuss.elastic.co/t/the-upgrading-of-the-elastic-core-on-premise-environment-kibana-logstash-and-elastic-cluster-from-7-17-28-to-8-17-any-recommendations/377465 "2025-04-24T15:15:03Z")

</div>

The upgrading of the Elastic Core on premise environment (Kibana, Logstash and Elastic Cluster with 3 nodes) from 7.17.28 to 8.17, any recommendations?

---

## [Partial snapshot](https://discuss.elastic.co/t/partial-snapshot/377473)

<div class="topic-metadata">

**Author:** [@Farheen](https://discuss.elastic.co/u/Farheen)\
**Replies:** 6\
**Last updated:** [April 24, 2025, 2:03pm UTC](https://discuss.elastic.co/t/partial-snapshot/377473 "2025-04-24T14:03:11Z")

</div>

Why the snapshots of indices has been created as partially restored?

---

## [Nested fields Issues - Remove / rename](https://discuss.elastic.co/t/nested-fields-issues-remove-rename/377447)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 3\
**Last updated:** [April 24, 2025, 1:09pm UTC](https://discuss.elastic.co/t/nested-fields-issues-remove-rename/377447 "2025-04-24T13:09:55Z")

</div>

Hi, Can someone help me on the below issue. I have a nested object where i am unable to rename or remove such fields. Below is the format of such field. test.test1.test2.test3.test4.test5 It has 4 objects and 1 field…

---

## [Sometimes no documents are returned in Elasticsearch](https://discuss.elastic.co/t/sometimes-no-documents-are-returned-in-elasticsearch/377425)

<div class="topic-metadata">

**Author:** [@Sushmita\_Gupta](https://discuss.elastic.co/u/Sushmita_Gupta)\
**Replies:** 6\
**Last updated:** [April 24, 2025, 12:57pm UTC](https://discuss.elastic.co/t/sometimes-no-documents-are-returned-in-elasticsearch/377425 "2025-04-24T12:57:28Z")

</div>

Hi, I'm using Elasticsearch and I’ve noticed something strange. For some queries, I get no documents back, even though I have set top\_k = 4. What’s confusing is that sometimes the same query does return results, but oth…

---

## [Guidance on architectural decision making](https://discuss.elastic.co/t/guidance-on-architectural-decision-making/377484)

<div class="topic-metadata">

**Author:** [@billie007711](https://discuss.elastic.co/u/billie007711)\
**Replies:** 0\
**Last updated:** [April 24, 2025, 10:01am UTC](https://discuss.elastic.co/t/guidance-on-architectural-decision-making/377484 "2025-04-24T10:01:40Z")

</div>

I want to move logs from Cloudwatch logs ====\> SELF MANAGED ELASTIC SEARCH CLUSTER The volume of log is 5TB/day Option1: I use aws-forwarder plugin provided by Elasticsearch Option2 I use this flow Cloudwatch log…

---

## [Analysis of ES 7.16 Memory Consumption: Multiple Factors Leading to Memory Surge and the Mystery of 9GB Memory Stuck in GC and Optimization Exploration](https://discuss.elastic.co/t/analysis-of-es-7-16-memory-consumption-multiple-factors-leading-to-memory-surge-and-the-mystery-of-9gb-memory-stuck-in-gc-and-optimization-exploration/377472)

<div class="topic-metadata">

**Author:** [@zhangzhihua](https://discuss.elastic.co/u/zhangzhihua)\
**Replies:** 0\
**Last updated:** [April 24, 2025, 3:45am UTC](https://discuss.elastic.co/t/analysis-of-es-7-16-memory-consumption-multiple-factors-leading-to-memory-surge-and-the-mystery-of-9gb-memory-stuck-in-gc-and-optimization-exploration/377472 "2025-04-24T03:45:07Z")

</div>

The recent memory consumption of JVM is as follows: The green area has optimized space for resident memory ES的Heap内存基本上被Segment Memory、Filter Cache、Field Data Cache、Bulk Queue、Indexing Buffer、Cluster State Buffer、各类…

---

## [Filtered Fleet Agents Show in other spaces](https://discuss.elastic.co/t/filtered-fleet-agents-show-in-other-spaces/377419)

<div class="topic-metadata">

**Author:** [@kulisiber](https://discuss.elastic.co/u/kulisiber)\
**Replies:** 2\
**Last updated:** [April 24, 2025, 1:54am UTC](https://discuss.elastic.co/t/filtered-fleet-agents-show-in-other-spaces/377419 "2025-04-24T01:54:32Z")

</div>

Hi everyone, Can I display the fleet agents that have been filtered specifically for that space in the Management \>\> Fleet menu. Please advise. Thanks before

---

## [Reindexing to new index after doing some filter](https://discuss.elastic.co/t/reindexing-to-new-index-after-doing-some-filter/377469)

<div class="topic-metadata">

**Author:** [@kulisiber](https://discuss.elastic.co/u/kulisiber)\
**Replies:** 0\
**Last updated:** [April 24, 2025, 1:49am UTC](https://discuss.elastic.co/t/reindexing-to-new-index-after-doing-some-filter/377469 "2025-04-24T01:49:40Z")

</div>

I would like to ask about ingest pipeline in Elastic SIEM. I'm a newbie here, sorry if I have a lot of questions. How to reindex from default index .kibana\_alerting\_cases\_8.15.0\_001 to a new index after filtering? I've …

---

## [ES v7.9 versus ES v8.17.3 performance](https://discuss.elastic.co/t/es-v7-9-versus-es-v8-17-3-performance/377459)

<div class="topic-metadata">

**Author:** [@kbnm](https://discuss.elastic.co/u/kbnm)\
**Replies:** 0\
**Last updated:** [April 23, 2025, 7:07pm UTC](https://discuss.elastic.co/t/es-v7-9-versus-es-v8-17-3-performance/377459 "2025-04-23T19:07:17Z")

</div>

Hi Elastic, I am wondering what performance gains there are from upgrading from Elasticsearch 7.9 to Elasticsearch 8.17.3. Is there documentation on performance metrics comparisons?

---

## [Elastic agent enroll fail : Error: fail to enroll: fail to execute request to fleet-server: Forbidden](https://discuss.elastic.co/t/elastic-agent-enroll-fail-error-fail-to-enroll-fail-to-execute-request-to-fleet-server-forbidden/376893)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 1\
**Last updated:** [April 23, 2025, 4:28pm UTC](https://discuss.elastic.co/t/elastic-agent-enroll-fail-error-fail-to-enroll-fail-to-execute-request-to-fleet-server-forbidden/376893 "2025-04-23T16:28:35Z")

</div>

{"log.level":"info","@timestamp":"2025-04-08T10:39:28.316+0530","log.origin":{"function":"github.com/elastic/elastic-agent/internal/pkg/agent/cmd.(\*enrollCmd).enrollWithBackoff","file.name":"cmd/enroll\_cmd.go","file.line…

---

## [Elasticsearch version upgradation](https://discuss.elastic.co/t/elasticsearch-version-upgradation/377439)

<div class="topic-metadata">

**Author:** [@Vigneshraja](https://discuss.elastic.co/u/Vigneshraja)\
**Replies:** 1\
**Last updated:** [April 23, 2025, 2:02pm UTC](https://discuss.elastic.co/t/elasticsearch-version-upgradation/377439 "2025-04-23T14:02:36Z")

</div>

hello, actually we are using elasticseach and kibana as a docker container in version 8.14.1. currently the version is 9.0.0, how can we migrate to latest version without any data/indices loss?? when we tried using vo…

---

## [Performance penalty of many multi-fields with chains of normalizers](https://discuss.elastic.co/t/performance-penalty-of-many-multi-fields-with-chains-of-normalizers/377440)

<div class="topic-metadata">

**Author:** [@petrsimon](https://discuss.elastic.co/u/petrsimon)\
**Replies:** 0\
**Last updated:** [April 23, 2025, 1:11pm UTC](https://discuss.elastic.co/t/performance-penalty-of-many-multi-fields-with-chains-of-normalizers/377440 "2025-04-23T13:11:11Z")

</div>

Hi, I wanted to tidy up one index where several fields were created in application just for some specific searches. The content of those fields is normalized (some text removed, some replaced). So the application did th…

---

## [When Does BBQ Quantization Outperform Scalar Quantization](https://discuss.elastic.co/t/when-does-bbq-quantization-outperform-scalar-quantization/377393)

<div class="topic-metadata">

**Author:** [@DylanWelzel](https://discuss.elastic.co/u/DylanWelzel)\
**Replies:** 1\
**Last updated:** [April 23, 2025, 12:32pm UTC](https://discuss.elastic.co/t/when-does-bbq-quantization-outperform-scalar-quantization/377393 "2025-04-23T12:32:26Z")

</div>

Hi all, I’m experimenting with the new vector quantization formats in Elasticsearch 8.x and trying to figure out at what dataset size BBQ (binary quantization) really starts to outperform scalar quantization. What I’m …

---

## [\`WriteTo\` JSON formatter](https://discuss.elastic.co/t/writeto-json-formatter/377362)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [April 23, 2025, 12:03pm UTC](https://discuss.elastic.co/t/writeto-json-formatter/377362 "2025-04-23T12:03:04Z")

</div>

I use GitHub - denis-peshkov/Serilog.Enrichers.HttpContext: Enriches Serilog events with client IP, Correlation Id, RequestBody, RequestQuery, HTTP request headers and information of the memory usage. to extract http h…

---

## [Issue with OpenJDK Vulnerabilities (CVE-2024) in Elasticsearch 8.15.2](https://discuss.elastic.co/t/issue-with-openjdk-vulnerabilities-cve-2024-in-elasticsearch-8-15-2/377328)

<div class="topic-metadata">

**Author:** [@debbbuu](https://discuss.elastic.co/u/debbbuu)\
**Replies:** 8\
**Last updated:** [April 23, 2025, 11:14am UTC](https://discuss.elastic.co/t/issue-with-openjdk-vulnerabilities-cve-2024-in-elasticsearch-8-15-2/377328 "2025-04-23T11:14:19Z")

</div>

Hi, As part of the vulnerability assessment (VA) scan on our ELK servers, we identified that the OpenJDK version is affected by multiple vulnerabilities. We are using a self-managed cluster. We did upgrade the ELK stack…

---

## [Non romanized lanuages like chinese, korean japanese](https://discuss.elastic.co/t/non-romanized-lanuages-like-chinese-korean-japanese/376786)

<div class="topic-metadata">

**Author:** [@Shabana\_Rumane](https://discuss.elastic.co/u/Shabana_Rumane)\
**Replies:** 1\
**Last updated:** [April 23, 2025, 8:57am UTC](https://discuss.elastic.co/t/non-romanized-lanuages-like-chinese-korean-japanese/376786 "2025-04-23T08:57:34Z")

</div>

Along with using plugins to help tokenize documents, is there any other way to identify similar words in different script or synonyms other than specifying them in the synonyms.txt?

---

## [Logs by network device](https://discuss.elastic.co/t/logs-by-network-device/377387)

<div class="topic-metadata">

**Author:** [@josep68](https://discuss.elastic.co/u/josep68)\
**Replies:** 3\
**Last updated:** [April 23, 2025, 7:36am UTC](https://discuss.elastic.co/t/logs-by-network-device/377387 "2025-04-23T07:36:56Z")

</div>

Hello, I am a new user of ELK. I have seen how to use filebeat to monitor Linux and windows. How can I proceed to monitor lan devices such as Dahua or Hanwha cameras or Cambium and Ubiquity radio bridges? Thanks

---

## [Multiple data path](https://discuss.elastic.co/t/multiple-data-path/377401)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [April 22, 2025, 8:35pm UTC](https://discuss.elastic.co/t/multiple-data-path/377401 "2025-04-22T20:35:04Z")

</div>

Are Elastic removing multple data.path? It was deprecated in 8.0 but not remove due to push back from community. what is the verdict on version 9.0?

---

## [Filebeats NetFlow: Events dropped due to out of range of long value](https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375)

<div class="topic-metadata">

**Author:** [@vjineo](https://discuss.elastic.co/u/vjineo)\
**Replies:** 1\
**Last updated:** [April 22, 2025, 2:42pm UTC](https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375 "2025-04-22T14:42:41Z")

</div>

Most of the events are dropped with below error: {\\"type\\":\\"document\_parsing\_exception\\",\\"reason\\":\\"\[1:1475\] failed to parse field \[netflow.flow\_id\] of type \[long\] in document with id 'M7a4XZYB\_Zr7jpsbS6pn'. Preview …

---

## [Dockerfiles – Ubuntu 20.04 EOL May 31, 2025 (Ubuntu 22.04 Upgrade)](https://discuss.elastic.co/t/dockerfiles-ubuntu-20-04-eol-may-31-2025-ubuntu-22-04-upgrade/377381)

<div class="topic-metadata">

**Author:** [@pclem](https://discuss.elastic.co/u/pclem)\
**Replies:** 0\
**Last updated:** [April 22, 2025, 2:41pm UTC](https://discuss.elastic.co/t/dockerfiles-ubuntu-20-04-eol-may-31-2025-ubuntu-22-04-upgrade/377381 "2025-04-22T14:41:38Z")

</div>

Hey Community! This is my first time posting here, so apologies if my post breaks any rules. Our team relies heavily on Elasticsearch Docker Images (Elasticsearch, Logstash, Filebeat), which currently use Ubuntu 20.04 …

---

## [Changes removed from system index templates](https://discuss.elastic.co/t/changes-removed-from-system-index-templates/377371)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 0\
**Last updated:** [April 22, 2025, 12:58pm UTC](https://discuss.elastic.co/t/changes-removed-from-system-index-templates/377371 "2025-04-22T12:58:54Z")

</div>

I have made some changes to a system index template (.alerts-security.alerts-default-index-template) by adding a new Component Template to map some custom fields for use as filters in the Alerts dashboard. However, after…

---

## [Update part of a url](https://discuss.elastic.co/t/update-part-of-a-url/377354)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [April 21, 2025, 11:34pm UTC](https://discuss.elastic.co/t/update-part-of-a-url/377354 "2025-04-21T23:34:17Z")

</div>

Hello! my team and I were trying to perform an update operation for several records that match having a certain url: GET myindex/\_search { "query": { "wildcard": { "url": { "value": "\*myteam.com\*" …

---

## [Elser in self managed cluster](https://discuss.elastic.co/t/elser-in-self-managed-cluster/375490)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 5\
**Last updated:** [April 21, 2025, 2:04pm UTC](https://discuss.elastic.co/t/elser-in-self-managed-cluster/375490 "2025-04-21T14:04:36Z")

</div>

The elser documentation seems to be tailored for cloud deployment . If one wants to deploy and install elser in self managed cluster where could I find the steps . Please help

---

## [Elasticsearch 8.15.2: OpenJDK CVEs](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335)

<div class="topic-metadata">

**Author:** [@debbbuu](https://discuss.elastic.co/u/debbbuu)\
**Replies:** 1\
**Last updated:** [April 21, 2025, 1:47pm UTC](https://discuss.elastic.co/t/elasticsearch-8-15-2-openjdk-cves/377335 "2025-04-21T13:47:32Z")

</div>

Hi, As part of the vulnerability assessment (VA) scan on our ELK servers, we identified that the bundled OpenJDK version is affected by multiple vulnerabilities. We are using a self-managed cluster. We did upgrade the E…

---

## [Issue with OpenJDK Vulnerabilities (CVE-2024) in Elasticsearch 8.15.2](https://discuss.elastic.co/t/issue-with-openjdk-vulnerabilities-cve-2024-in-elasticsearch-8-15-2/377330)

<div class="topic-metadata">

**Author:** [@debbbuu](https://discuss.elastic.co/u/debbbuu)\
**Replies:** 1\
**Last updated:** [April 21, 2025, 1:47pm UTC](https://discuss.elastic.co/t/issue-with-openjdk-vulnerabilities-cve-2024-in-elasticsearch-8-15-2/377330 "2025-04-21T13:47:11Z")

</div>

Hi, As part of the vulnerability assessment (VA) scan on our ELK servers, we identified that the bundled OpenJDK version is affected by multiple vulnerabilities. We are using a self-managed cluster. We did upgrade the E…

---

## [Elastic Search Logs delay and missing](https://discuss.elastic.co/t/elastic-search-logs-delay-and-missing/377320)

<div class="topic-metadata">

**Author:** [@nishant\_goyal](https://discuss.elastic.co/u/nishant_goyal)\
**Replies:** 1\
**Last updated:** [April 21, 2025, 8:28am UTC](https://discuss.elastic.co/t/elastic-search-logs-delay-and-missing/377320 "2025-04-21T08:28:05Z")

</div>

using Elasticsearch , logstash and kibana on 16vcore linux azure server and approx 300 micro service logs pushing through logback to logstash. i observed sometimes logs not storing to Elasticsearch and sometimes delay. …

---

## [\[cluster:monitor/nodes/stats\[n\]\] timed out](https://discuss.elastic.co/t/cluster-monitor-nodes-stats-n-timed-out/377322)

<div class="topic-metadata">

**Author:** [@ZaynJiang](https://discuss.elastic.co/u/ZaynJiang)\
**Replies:** 0\
**Last updated:** [April 21, 2025, 5:31am UTC](https://discuss.elastic.co/t/cluster-monitor-nodes-stats-n-timed-out/377322 "2025-04-21T05:31:44Z")

</div>

I encountered exactly the same problem. Both the thread stack and the logs are identical. This issue has been closed, but it remains unsolved.

---

## [Elasticserach table visualization export format](https://discuss.elastic.co/t/elasticserach-table-visualization-export-format/377311)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 0\
**Last updated:** [April 19, 2025, 4:06pm UTC](https://discuss.elastic.co/t/elasticserach-table-visualization-export-format/377311 "2025-04-19T16:06:04Z")

</div>

I have table like when i export the table as CSV it format changes, and the columnd heards become the rows of the CSV file, like below Is there a way to export so the output would be the same as how table is disp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=34)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=36)
