# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=47

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 48

---

## [The doucment is returned even if it does not meet the criteria](https://discuss.elastic.co/t/the-doucment-is-returned-even-if-it-does-not-meet-the-criteria/374145)

<div class="topic-metadata">

**Author:** [@vinitp](https://discuss.elastic.co/u/vinitp)\
**Replies:** 4\
**Last updated:** [February 6, 2025, 9:47pm UTC](https://discuss.elastic.co/t/the-doucment-is-returned-even-if-it-does-not-meet-the-criteria/374145 "2025-02-06T21:47:45Z")

</div>

I use the following DSL query "size": 25, "query": { "bool": { "must": \[ { "term": { "hcAccountabilityOfficeCode.keyword": { "value": "550" } } }, { "nested": { "query": { …

---

## [Must\_not does not work in the nested array](https://discuss.elastic.co/t/must-not-does-not-work-in-the-nested-array/374191)

<div class="topic-metadata">

**Author:** [@vinitp](https://discuss.elastic.co/u/vinitp)\
**Replies:** 1\
**Last updated:** [February 6, 2025, 9:43pm UTC](https://discuss.elastic.co/t/must-not-does-not-work-in-the-nested-array/374191 "2025-02-06T21:43:50Z")

</div>

I have an application that generates Elasticsearch SQL dynamically based on the client's search criteria. The application then use the "/sql/translate" API to translate to the DSL query which it executes. The sample of t…

---

## [How to alert if two fields match](https://discuss.elastic.co/t/how-to-alert-if-two-fields-match/374143)

<div class="topic-metadata">

**Author:** [@SecurePete](https://discuss.elastic.co/u/SecurePete)\
**Replies:** 9\
**Last updated:** [February 6, 2025, 9:14pm UTC](https://discuss.elastic.co/t/how-to-alert-if-two-fields-match/374143 "2025-02-06T21:14:20Z")

</div>

I am very new to messing with Elastic pipelines and I need help. I want to alert based on whether two fields in a log match. I am not sure the correct way to do this. The logs are from a Cisco DUO integration. I want al…

---

## [Read-only file system](https://discuss.elastic.co/t/read-only-file-system/374182)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 7\
**Last updated:** [February 6, 2025, 9:03pm UTC](https://discuss.elastic.co/t/read-only-file-system/374182 "2025-02-06T21:03:25Z")

</div>

Hello everyone, From Kibana I started to visualize load errors and when checking the cluster I see that one of the servers is outside, I entered by SSH and the server is running and had the elasticsearch service running…

---

## [Mapper-Size Plugin Breaks Parsing](https://discuss.elastic.co/t/mapper-size-plugin-breaks-parsing/374074)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 10\
**Last updated:** [February 6, 2025, 2:11pm UTC](https://discuss.elastic.co/t/mapper-size-plugin-breaks-parsing/374074 "2025-02-06T14:11:27Z")

</div>

Hello, We want to enable mapper-size on our cloud clusters (we have done so on a single test cluster), and then we enabled \_size so that we can get ingest metrics for the cluster, but it breaks parsing. As soon as our d…

---

## [Standalone agent is not enrolling with Elastic Cluster](https://discuss.elastic.co/t/standalone-agent-is-not-enrolling-with-elastic-cluster/374171)

<div class="topic-metadata">

**Author:** [@Eshwar\_K](https://discuss.elastic.co/u/Eshwar_K)\
**Replies:** 3\
**Last updated:** [February 6, 2025, 11:40am UTC](https://discuss.elastic.co/t/standalone-agent-is-not-enrolling-with-elastic-cluster/374171 "2025-02-06T11:40:06Z")

</div>

Hi Support team, I had configured cluster with default certificates which are created while installing stack. Now, I has installed standalone elastic agent with below command. ./elastic-agent.exe install --insecure Bu…

---

## [Elastic search restore failure](https://discuss.elastic.co/t/elastic-search-restore-failure/374162)

<div class="topic-metadata">

**Author:** [@Karthiknathan\_c](https://discuss.elastic.co/u/Karthiknathan_c)\
**Replies:** 1\
**Last updated:** [February 6, 2025, 10:38am UTC](https://discuss.elastic.co/t/elastic-search-restore-failure/374162 "2025-02-06T10:38:55Z")

</div>

I was trying to backup and restore ES to new cluster using below commands. //take snapshot curl -u backup:$password -s -XPUT ${endpoint} //restore curl -s -u backup:$password -X POST "${HOSTNAME}:${PORT}/\_snapshot/${BA…

---

## [Elastic Search 2nd node install is not updating elasticsearch.yml per instructions](https://discuss.elastic.co/t/elastic-search-2nd-node-install-is-not-updating-elasticsearch-yml-per-instructions/374092)

<div class="topic-metadata">

**Author:** [@mjanzen](https://discuss.elastic.co/u/mjanzen)\
**Replies:** 3\
**Last updated:** [February 5, 2025, 5:08pm UTC](https://discuss.elastic.co/t/elastic-search-2nd-node-install-is-not-updating-elasticsearch-yml-per-instructions/374092 "2025-02-05T17:08:07Z")

</div>

This category relates to the Enterprise Search set of products - App Search, Site Search and Workplace Search. If your question relates to core Elasticsearch functionality, please head over to the Elasticsearch category…

---

## [ES 7.17: Large cluster with big difference in shard size keeps high disparity between cold nodes sizing](https://discuss.elastic.co/t/es-7-17-large-cluster-with-big-difference-in-shard-size-keeps-high-disparity-between-cold-nodes-sizing/374139)

<div class="topic-metadata">

**Author:** [@carlosmg1](https://discuss.elastic.co/u/carlosmg1)\
**Replies:** 0\
**Last updated:** [February 5, 2025, 4:35pm UTC](https://discuss.elastic.co/t/es-7-17-large-cluster-with-big-difference-in-shard-size-keeps-high-disparity-between-cold-nodes-sizing/374139 "2025-02-05T16:35:04Z")

</div>

Hi, we're currently managing a ES cluster with cold/hot architecture, we have 25 cold nodes with 12 TB space each, and 42 hot nodes with 2 TB each. For quite a while a few of our cold nodes are running pretty low in sp…

---

## [Problem configuring/using Uptime Lab](https://discuss.elastic.co/t/problem-configuring-using-uptime-lab/373906)

<div class="topic-metadata">

**Author:** [@elasticrap](https://discuss.elastic.co/u/elasticrap)\
**Replies:** 7\
**Last updated:** [February 5, 2025, 2:50pm UTC](https://discuss.elastic.co/t/problem-configuring-using-uptime-lab/373906 "2025-02-05T14:50:56Z")

</div>

I am working on the Uptime lab. Item 4 states - Configure monitors inline heartbeat.monitors: Notice there is a sample monitor of type http with id my-monitor. Comment out or delete this monitor (but leave the heartbea…

---

## [How Elastic search built vector database](https://discuss.elastic.co/t/how-elastic-search-built-vector-database/374076)

<div class="topic-metadata">

**Author:** [@sumantapakira](https://discuss.elastic.co/u/sumantapakira)\
**Replies:** 4\
**Last updated:** [February 5, 2025, 1:01pm UTC](https://discuss.elastic.co/t/how-elastic-search-built-vector-database/374076 "2025-02-05T13:01:16Z")

</div>

I would like to study how Vector database is working using Apache Lucene. So for this I am looking into github GitHub - elastic/elasticsearch: Free and Open Source, Distributed, RESTful Search Engine but could not unders…

---

## [Mac address changed to mixed datatype in elastic](https://discuss.elastic.co/t/mac-address-changed-to-mixed-datatype-in-elastic/374051)

<div class="topic-metadata">

**Author:** [@meghananagaraja](https://discuss.elastic.co/u/meghananagaraja)\
**Replies:** 3\
**Last updated:** [February 5, 2025, 10:53am UTC](https://discuss.elastic.co/t/mac-address-changed-to-mixed-datatype-in-elastic/374051 "2025-02-05T10:53:38Z")

</div>

I am feeding data into ES index. The data has mac address. Elastic is mapping it to a mixed data type (part string part numeric). How to fix this issue. I am not able to use "term" option while querying. It wont fetch. …

---

## [We have facing some issue with elastic search 8.15.1](https://discuss.elastic.co/t/we-have-facing-some-issue-with-elastic-search-8-15-1/374113)

<div class="topic-metadata">

**Author:** [@calvin01](https://discuss.elastic.co/u/calvin01)\
**Replies:** 0\
**Last updated:** [February 5, 2025, 10:06am UTC](https://discuss.elastic.co/t/we-have-facing-some-issue-with-elastic-search-8-15-1/374113 "2025-02-05T10:06:24Z")

</div>

Hello Community, We are running an Elasticsearch 8.15.1 cluster with 7 nodes, each configured with -Xms28g -Xmx28g heap memory. Additionally, we have set vm.max\_map\_count=262144 on the instances. Unfortunately, our Ela…

---

## [Reindex with embeddings](https://discuss.elastic.co/t/reindex-with-embeddings/374088)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [February 5, 2025, 2:30am UTC](https://discuss.elastic.co/t/reindex-with-embeddings/374088 "2025-02-05T02:30:49Z")

</div>

I was trying to use the E5 model to generate embeddings for non english documents and I created a field that was a sparse\_vector. The index where I changed the mapping already has a sparse\_vector for another embedding a…

---

## [New Install 8.17 scripts not working - java](https://discuss.elastic.co/t/new-install-8-17-scripts-not-working-java/373862)

<div class="topic-metadata">

**Author:** [@mjanzen](https://discuss.elastic.co/u/mjanzen)\
**Replies:** 2\
**Last updated:** [February 4, 2025, 8:57pm UTC](https://discuss.elastic.co/t/new-install-8-17-scripts-not-working-java/373862 "2025-02-04T20:57:56Z")

</div>

New to Elasticsearch. Working on setting up a proof of concept. I'm using the tutorial here Tutorial 1: Installing a self-managed Elastic Stack | Elastic Installation and Upgrade Guide \[8.17\] | Elastic Anytime I try …

---

## [How to use the bulk api from kibana](https://discuss.elastic.co/t/how-to-use-the-bulk-api-from-kibana/374081)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 1\
**Last updated:** [February 4, 2025, 8:20pm UTC](https://discuss.elastic.co/t/how-to-use-the-bulk-api-from-kibana/374081 "2025-02-04T20:20:28Z")

</div>

I am trying to upload data using the bulk api from kibana. I was following this I have tried a syntax like this: POST /my-index/\_bulk { { "index": { "\_index": "myindex", "\_id": "1" } } { "name": "John Doe", "age"…

---

## [Use ELSER on data already in elastic](https://discuss.elastic.co/t/use-elser-on-data-already-in-elastic/373911)

<div class="topic-metadata">

**Author:** [@Carlos\_Fernando\_Palm](https://discuss.elastic.co/u/Carlos_Fernando_Palm)\
**Replies:** 2\
**Last updated:** [February 4, 2025, 8:15pm UTC](https://discuss.elastic.co/t/use-elser-on-data-already-in-elastic/373911 "2025-02-04T20:15:04Z")

</div>

I was going through the documentation for the ELSER model and I keep seeing that when using an inference point the model is applied to the data at ingestion time. Is there a way to populate the semantic\_text field for da…

---

## [Unable to set logging level for docker container](https://discuss.elastic.co/t/unable-to-set-logging-level-for-docker-container/374073)

<div class="topic-metadata">

**Author:** [@instantdreams](https://discuss.elastic.co/u/instantdreams)\
**Replies:** 0\
**Last updated:** [February 4, 2025, 4:42pm UTC](https://discuss.elastic.co/t/unable-to-set-logging-level-for-docker-container/374073 "2025-02-04T16:42:28Z")

</div>

I have an elasticsearch container using the following compose.yaml file: services: elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:latest container\_name: elasticsearch expose: - 9…

---

## [Docker compose file for v8.16](https://discuss.elastic.co/t/docker-compose-file-for-v8-16/374057)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 1\
**Last updated:** [February 4, 2025, 1:11pm UTC](https://discuss.elastic.co/t/docker-compose-file-for-v8-16/374057 "2025-02-04T13:11:24Z")

</div>

Hi all, i need docker-compose file for elastic v.8.16.3 i followed this link -\> Install Elasticsearch with Docker | Elasticsearch Guide \[8.16\] | Elastic tried below compose file-\> version: '3.8' services: es01: …

---

## [Pipelines execution in Elastic.Serilog.Sinks](https://discuss.elastic.co/t/pipelines-execution-in-elastic-serilog-sinks/374056)

<div class="topic-metadata">

**Author:** [@Wojciech\_Szabowicz](https://discuss.elastic.co/u/Wojciech_Szabowicz)\
**Replies:** 0\
**Last updated:** [February 4, 2025, 10:15am UTC](https://discuss.elastic.co/t/pipelines-execution-in-elastic-serilog-sinks/374056 "2025-02-04T10:15:33Z")

</div>

Hi, I am using Elastic.Serilog.Sinks to stream some data directly to elasticsearch a very simple mechanism .WriteTo.Logger(lc =\> { lc.Filter.ByIncludingOnly(le =\> le.Properties.ContainsKey("ecs.ver…

---

## [Search for Variations of Persian Names in Elasticsearch?](https://discuss.elastic.co/t/search-for-variations-of-persian-names-in-elasticsearch/374039)

<div class="topic-metadata">

**Author:** [@HassanJalali](https://discuss.elastic.co/u/HassanJalali)\
**Replies:** 0\
**Last updated:** [February 4, 2025, 4:04am UTC](https://discuss.elastic.co/t/search-for-variations-of-persian-names-in-elasticsearch/374039 "2025-02-04T04:04:06Z")

</div>

I'm using Elasticsearch in my .NET app and i construct a query like this: POST xxx/\_search?typed\_keys=true { "query": { "bool": { "must": \[ { "query\_string": { "fields": \[ …

---

## [Include\_lower / include\_upper is deprecated?](https://discuss.elastic.co/t/include-lower-include-upper-is-deprecated/373295)

<div class="topic-metadata">

**Author:** [@Jamshid](https://discuss.elastic.co/u/Jamshid)\
**Replies:** 3\
**Last updated:** [February 3, 2025, 10:36pm UTC](https://discuss.elastic.co/t/include-lower-include-upper-is-deprecated/373295 "2025-02-03T22:36:24Z")

</div>

After upgrading to elasticsearch 8.17 it seems I started seeing this deprecation log. \],\[299 Elasticsearch-8.17.0-2b6a7fed44faa321997703718f07ee0420804b41 "Deprecated field \[include\_upper\] used, this field is unused and…

---

## [New index not created by ingestion pipeline](https://discuss.elastic.co/t/new-index-not-created-by-ingestion-pipeline/374018)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 19\
**Last updated:** [February 3, 2025, 10:24pm UTC](https://discuss.elastic.co/t/new-index-not-created-by-ingestion-pipeline/374018 "2025-02-03T22:24:06Z")

</div>

Hi I am using elastic-agent in k8s cluster with kubernetes integration. I have added a custom pipeline for kubernetes container logs to re-route all logs from containers in a specific namespace. The following is the …

---

## [Complex search queries with multiple nested aggregations](https://discuss.elastic.co/t/complex-search-queries-with-multiple-nested-aggregations/374032)

<div class="topic-metadata">

**Author:** [@Petar\_Vitanov](https://discuss.elastic.co/u/Petar_Vitanov)\
**Replies:** 0\
**Last updated:** [February 3, 2025, 7:43pm UTC](https://discuss.elastic.co/t/complex-search-queries-with-multiple-nested-aggregations/374032 "2025-02-03T19:43:45Z")

</div>

Hello everyone, I want to use Elasticsearch to track user events like placing bets, making deposits, withdrawals etc. I have created a data stream with document which track timestamp of the event, user\_id as keyword an…

---

## [Backup repository s3 bucket size is almost 5 times the actual index size](https://discuss.elastic.co/t/backup-repository-s3-bucket-size-is-almost-5-times-the-actual-index-size/373910)

<div class="topic-metadata">

**Author:** [@Dharani\_Vattamwar](https://discuss.elastic.co/u/Dharani_Vattamwar)\
**Replies:** 25\
**Last updated:** [February 3, 2025, 3:26pm UTC](https://discuss.elastic.co/t/backup-repository-s3-bucket-size-is-almost-5-times-the-actual-index-size/373910 "2025-02-03T15:26:18Z")

</div>

our elasticsearch indices are about 12TB and we have backups happening on daily basis with retention of 3 days. How can the snapshot storage s3 size be 60TB? Is there any way to estimate the size if we retain snapshots …

---

## [String\_index\_out\_of\_bounds\_exception when attempting to register S3 bucket with Elasticsearch instance](https://discuss.elastic.co/t/string-index-out-of-bounds-exception-when-attempting-to-register-s3-bucket-with-elasticsearch-instance/373958)

<div class="topic-metadata">

**Author:** [@trai](https://discuss.elastic.co/u/trai)\
**Replies:** 3\
**Last updated:** [February 3, 2025, 1:59pm UTC](https://discuss.elastic.co/t/string-index-out-of-bounds-exception-when-attempting-to-register-s3-bucket-with-elasticsearch-instance/373958 "2025-02-03T13:59:25Z")

</div>

I'm wanting to do a backup & restore on an Elasticsearch 7.10 instance. I've used Terraform to create a role which the user assumes using PassRole which seems to work, however I'm getting an error when attempting to add …

---

## [Searchable snapshot](https://discuss.elastic.co/t/searchable-snapshot/364764)

<div class="topic-metadata">

**Author:** [@Lim](https://discuss.elastic.co/u/Lim)\
**Replies:** 2\
**Last updated:** [February 3, 2025, 10:52am UTC](https://discuss.elastic.co/t/searchable-snapshot/364764 "2025-02-03T10:52:52Z")

</div>

Hello, I’m conducting performance tests on Searchable Snapshots and would like to discuss my approach to see if it is correct. Currently, I’ve created a snapshot repository on NAS to generate a 100GB partial shard for …

---

## [Compatible version for ARM machines](https://discuss.elastic.co/t/compatible-version-for-arm-machines/374005)

<div class="topic-metadata">

**Author:** [@wasim\_wasim](https://discuss.elastic.co/u/wasim_wasim)\
**Replies:** 3\
**Last updated:** [February 3, 2025, 10:49am UTC](https://discuss.elastic.co/t/compatible-version-for-arm-machines/374005 "2025-02-03T10:49:18Z")

</div>

Elastisearch docker image is not supporting for arm machines. IMAGE - docker.elastic.co/elasticsearch/elasticsearch:8.6.0 ARCH - Linux AIG-OCTEONTX-84-CSK 5.15.72 #12 SMP PREEMPT Mon Dec 9 08:57:20 UTC 2024 aarch64 …

---

## [Reindex indices](https://discuss.elastic.co/t/reindex-indices/373992)

<div class="topic-metadata">

**Author:** [@Logistic\_dilated](https://discuss.elastic.co/u/Logistic_dilated)\
**Replies:** 2\
**Last updated:** [February 3, 2025, 10:42am UTC](https://discuss.elastic.co/t/reindex-indices/373992 "2025-02-03T10:42:57Z")

</div>

elastic: 8.15.1 kibana: 8.15.1 logstash: 8.15.1 Ubuntu 22.04LTS Hello folks, I've made a mistake with the way I ingest logstash pipelines, and now I've exhausted my maximum shard count (1000/1000 used). I deleted a …

---

## [Cisco switch integration](https://discuss.elastic.co/t/cisco-switch-integration/373440)

<div class="topic-metadata">

**Author:** [@amarasinghe.kaluarac](https://discuss.elastic.co/u/amarasinghe.kaluarac)\
**Replies:** 2\
**Last updated:** [February 3, 2025, 10:33am UTC](https://discuss.elastic.co/t/cisco-switch-integration/373440 "2025-02-03T10:33:05Z")

</div>

Hi, I have a need to integrate a Cisco Catalyst 3850 switch with my Elastic cluster, so as I was browsing through the integration, I didn't see any integration for a Catalyst switch. Could anyone help me with this? Tha…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=46)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=48)
