# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=69

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 70

---

## [Some logs are not displayed in the index](https://discuss.elastic.co/t/some-logs-are-not-displayed-in-the-index/369037)

<div class="topic-metadata">

**Author:** [@Vladimir\_Fomin1](https://discuss.elastic.co/u/Vladimir_Fomin1)\
**Replies:** 0\
**Last updated:** [October 18, 2024, 6:30am UTC](https://discuss.elastic.co/t/some-logs-are-not-displayed-in-the-index/369037 "2024-10-18T06:30:53Z")

</div>

Logs come to Logstash, are parsed there and then sent to Elasticsearch in index cnv-tariffication-service-%{+YYYY.MM.dd}. But I don't see all the necessary logs in the index, only a part of them. I'm also testing a way…

---

## [Document annotated classes are not being added to Elastic search context after upgrading to spring data elastic search 5.2](https://discuss.elastic.co/t/document-annotated-classes-are-not-being-added-to-elastic-search-context-after-upgrading-to-spring-data-elastic-search-5-2/369036)

<div class="topic-metadata">

**Author:** [@Suchithra\_Nair](https://discuss.elastic.co/u/Suchithra_Nair)\
**Replies:** 1\
**Last updated:** [October 18, 2024, 6:13am UTC](https://discuss.elastic.co/t/document-annotated-classes-are-not-being-added-to-elastic-search-context-after-upgrading-to-spring-data-elastic-search-5-2/369036 "2024-10-18T06:13:18Z")

</div>

I am upgrading my service to springboot 3, Elastic search v8 and spring data Elasticsearch 5.2. For resolving indexes, I am using SimpleElasticsearchMappingContext to get the persistent entities currently. However, after…

---

## [ML Anomaly Detection jobs gives very low score for absense of events](https://discuss.elastic.co/t/ml-anomaly-detection-jobs-gives-very-low-score-for-absense-of-events/366963)

<div class="topic-metadata">

**Author:** [@GlebCA](https://discuss.elastic.co/u/GlebCA)\
**Replies:** 5\
**Last updated:** [October 18, 2024, 2:38am UTC](https://discuss.elastic.co/t/ml-anomaly-detection-jobs-gives-very-low-score-for-absense-of-events/366963 "2024-10-18T02:38:05Z")

</div>

Hi, I like to monitor # of specific logs event and raise an alert when flow is out of boundaries. Initially I was going to use moving average for it but found that Elastic does not support it and ML anomaly detection is…

---

## [Node went down but other cluster nodes reporting green and no decrease in # nodes](https://discuss.elastic.co/t/node-went-down-but-other-cluster-nodes-reporting-green-and-no-decrease-in-nodes/368951)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 1\
**Last updated:** [October 17, 2024, 9:03pm UTC](https://discuss.elastic.co/t/node-went-down-but-other-cluster-nodes-reporting-green-and-no-decrease-in-nodes/368951 "2024-10-17T21:03:28Z")

</div>

I have an environment with a 3 node cluster and the cluster/health endpoint showed 3 nodes and GREEN. After one node came down and remained down for 20 minutes, the two remaining nodes continued to report 3 nodes and GRE…

---

## [Terms aggregation on high cardinality field](https://discuss.elastic.co/t/terms-aggregation-on-high-cardinality-field/367196)

<div class="topic-metadata">

**Author:** [@ivan83](https://discuss.elastic.co/u/ivan83)\
**Replies:** 6\
**Last updated:** [October 17, 2024, 8:41pm UTC](https://discuss.elastic.co/t/terms-aggregation-on-high-cardinality-field/367196 "2024-10-17T20:41:32Z")

</div>

Hello! I am sharing the issue that I am having here hoping that someone can help me. We are executing terms on a field which has super high cardinality. I am talking about 40 million unique entries that represents prod…

---

## [Filebeat servce cannot start on my OS](https://discuss.elastic.co/t/filebeat-servce-cannot-start-on-my-os/368977)

<div class="topic-metadata">

**Author:** [@alex\_zolat](https://discuss.elastic.co/u/alex_zolat)\
**Replies:** 2\
**Last updated:** [October 17, 2024, 3:22pm UTC](https://discuss.elastic.co/t/filebeat-servce-cannot-start-on-my-os/368977 "2024-10-17T15:22:49Z")

</div>

My filebeat service cannot start and is showing follow log in follow path: /var/log/filebeat/filebeat.log-20241017.ndjson {"log.level":"error","@timestamp":"2024-10-17T10:58:05.253+0330","log.logger":"input","log.orig…

---

## [Migrating from java client 1.4.2 to the 8 client](https://discuss.elastic.co/t/migrating-from-java-client-1-4-2-to-the-8-client/366949)

<div class="topic-metadata">

**Author:** [@intrepid1](https://discuss.elastic.co/u/intrepid1)\
**Replies:** 2\
**Last updated:** [October 17, 2024, 3:14pm UTC](https://discuss.elastic.co/t/migrating-from-java-client-1-4-2-to-the-8-client/366949 "2024-10-17T15:14:04Z")

</div>

Hi there, I have been tasked with migrating an ancient Elasticsearch v1.5.1 cluster and the associated java service using the Elasticsearch 1.4.2 java client (elasticsearch-1.4.2.jar). Whilst the migration of the cluste…

---

## [Translate from DSL to SQL](https://discuss.elastic.co/t/translate-from-dsl-to-sql/368999)

<div class="topic-metadata">

**Author:** [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Replies:** 1\
**Last updated:** [October 17, 2024, 2:48pm UTC](https://discuss.elastic.co/t/translate-from-dsl-to-sql/368999 "2024-10-17T14:48:23Z")

</div>

Hi, the sql translate feature converts from SQL --\> DSL. Is there a feature to do the reverse? i.e. convert from DSL to Elastic SQL ? Thanks

---

## [Inquiry on Subscription and Separation Options for Cloned Engine](https://discuss.elastic.co/t/inquiry-on-subscription-and-separation-options-for-cloned-engine/369004)

<div class="topic-metadata">

**Author:** [@ritika.marwaha](https://discuss.elastic.co/u/ritika.marwaha)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 1:54pm UTC](https://discuss.elastic.co/t/inquiry-on-subscription-and-separation-options-for-cloned-engine/369004 "2024-10-17T13:54:12Z")

</div>

|a)|Is it possible to set up a separate subscription for a cloned engine? If so, how much does it cost?| |b)|If not possible to separate the subscriptions, is it possible to actually separate the engines entirely, and w…

---

## [Query to get all the children](https://discuss.elastic.co/t/query-to-get-all-the-children/368932)

<div class="topic-metadata">

**Author:** [@yulinxp](https://discuss.elastic.co/u/yulinxp)\
**Replies:** 2\
**Last updated:** [October 17, 2024, 1:38pm UTC](https://discuss.elastic.co/t/query-to-get-all-the-children/368932 "2024-10-17T13:38:43Z")

</div>

Here is mapping PUT my\_index { "mappings": { "properties": { "my\_join\_field": { "type": "join", "relations": { "parent": "child" } }, "name": { "type": "keyword"…

---

## [How to calculate the standard deviation in a transform?](https://discuss.elastic.co/t/how-to-calculate-the-standard-deviation-in-a-transform/368845)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 4\
**Last updated:** [October 17, 2024, 1:05pm UTC](https://discuss.elastic.co/t/how-to-calculate-the-standard-deviation-in-a-transform/368845 "2024-10-17T13:05:59Z")

</div>

I am trying to create a transform report, but I'm unable to create a range based on the avg(total). For example, I want to assign customers into a bucket based on their average total spend, like the range $0-$100. Can …

---

## [Calculate the similarity between two fields same doc](https://discuss.elastic.co/t/calculate-the-similarity-between-two-fields-same-doc/369000)

<div class="topic-metadata">

**Author:** [@pereyrdi](https://discuss.elastic.co/u/pereyrdi)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 12:56pm UTC](https://discuss.elastic.co/t/calculate-the-similarity-between-two-fields-same-doc/369000 "2024-10-17T12:56:01Z")

</div>

Hello, I trying during log ingestion calculate the percentage of similarity between two fields. For example, A=foobar B=barfoor I have read about this here: similarity | Elasticsearch Guide \[8.15\] | Elastic But I dont …

---

## [Recieving exception on my worker nodes](https://discuss.elastic.co/t/recieving-exception-on-my-worker-nodes/368988)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 9:33am UTC](https://discuss.elastic.co/t/recieving-exception-on-my-worker-nodes/368988 "2024-10-17T09:33:37Z")

</div>

i am getting these kind of exception on my worker nodes \*\*\[node.id\](http://node.id/)\*\* \*\*":"eqCCF2S4TPG1jExPCtnbng","\*\* \*\*\[elasticsearch.node.name\](http://elasticsearch.node.name/)\*\* \*\*":"eck-master-and-worker-nodes-es-…

---

## [Elastic search behind nginx proxy - Node updates](https://discuss.elastic.co/t/elastic-search-behind-nginx-proxy-node-updates/368968)

<div class="topic-metadata">

**Author:** [@Deeraj\_Theepshi](https://discuss.elastic.co/u/Deeraj_Theepshi)\
**Replies:** 1\
**Last updated:** [October 17, 2024, 8:46am UTC](https://discuss.elastic.co/t/elastic-search-behind-nginx-proxy-node-updates/368968 "2024-10-17T08:46:17Z")

</div>

I have a setup such that I'm proxying requests over a custom domain that points to an nginx server to Elasticsearch cluster. I have noticed that nginx is caching the data node ips as per the ttl. Now, when a node goes d…

---

## [ErrImagePull Error with a message authenticationrequired](https://discuss.elastic.co/t/errimagepull-error-with-a-message-authenticationrequired/368964)

<div class="topic-metadata">

**Author:** [@zakhan](https://discuss.elastic.co/u/zakhan)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 4:21am UTC](https://discuss.elastic.co/t/errimagepull-error-with-a-message-authenticationrequired/368964 "2024-10-17T04:21:57Z")

</div>

Elasticsearch operator is installed on Openshift. While creating the elasticsearch cluster, below error is seen: Normal Pulling 5s (x2 over 27s) kubelet Pulling image "docker.elastic…

---

## [What happens when synchronization between the primary and replica shards is lost?](https://discuss.elastic.co/t/what-happens-when-synchronization-between-the-primary-and-replica-shards-is-lost/366120)

<div class="topic-metadata">

**Author:** [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Replies:** 5\
**Last updated:** [October 16, 2024, 9:31pm UTC](https://discuss.elastic.co/t/what-happens-when-synchronization-between-the-primary-and-replica-shards-is-lost/366120 "2024-10-16T21:31:00Z")

</div>

What happens when synchronization between the primary and replica shards is lost in Elasticsearch? :thinking: For example, a node is disconnected and a replica is unassigned. The indexing is persist to the primary shard…

---

## [Transform with two input indices with different unique ids](https://discuss.elastic.co/t/transform-with-two-input-indices-with-different-unique-ids/368475)

<div class="topic-metadata">

**Author:** [@Phil\_McLachlan](https://discuss.elastic.co/u/Phil_McLachlan)\
**Replies:** 3\
**Last updated:** [October 16, 2024, 9:11pm UTC](https://discuss.elastic.co/t/transform-with-two-input-indices-with-different-unique-ids/368475 "2024-10-16T21:11:18Z")

</div>

Hi, we have a transform with two input indices with different unique ids. One input index has a unique id of product\_pk, and another has product\_pk combined with catalog\_type. There are two possible catalog\_types: cata…

---

## [Bootstrap check failure in 8.15.2](https://discuss.elastic.co/t/bootstrap-check-failure-in-8-15-2/368660)

<div class="topic-metadata">

**Author:** [@mousumis](https://discuss.elastic.co/u/mousumis)\
**Replies:** 2\
**Last updated:** [October 16, 2024, 8:07pm UTC](https://discuss.elastic.co/t/bootstrap-check-failure-in-8-15-2/368660 "2024-10-16T20:07:20Z")

</div>

I am trying to upgrade an elasticsearch deployment from 8.14.1 to 8.15.2. It is not able to start up due to the following bootstrap check failure. \[ERROR\]\[org.elasticsearch.bootstrap.Elasticsearch\] \[server-deployment\] n…

---

## [Elastic Nest 7 , unknown from: POST /\_reindex?wait\_for\_completion=true](https://discuss.elastic.co/t/elastic-nest-7-unknown-from-post-reindex-wait-for-completion-true/368903)

<div class="topic-metadata">

**Author:** [@blqck](https://discuss.elastic.co/u/blqck)\
**Replies:** 3\
**Last updated:** [October 16, 2024, 7:36pm UTC](https://discuss.elastic.co/t/elastic-nest-7-unknown-from-post-reindex-wait-for-completion-true/368903 "2024-10-16T19:36:49Z")

</div>

i'm reindexing docs from one index to another and usually i got this exception which i dont know what cause it, in my local pc i didnt have it but in az pipeline it happens frequently . this is the code i'm using to do t…

---

## [ILM rollover problem](https://discuss.elastic.co/t/ilm-rollover-problem/368940)

<div class="topic-metadata">

**Author:** [@idadash](https://discuss.elastic.co/u/idadash)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 7:21pm UTC](https://discuss.elastic.co/t/ilm-rollover-problem/368940 "2024-10-16T19:21:58Z")

</div>

Hi. I have a problem with index lifecycle management - rollout that is my ILM policy { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": {} }, "delete": { "mi…

---

## [It shows sucessfully run but unable to access it](https://discuss.elastic.co/t/it-shows-sucessfully-run-but-unable-to-access-it/368937)

<div class="topic-metadata">

**Author:** [@shamir](https://discuss.elastic.co/u/shamir)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 6:59pm UTC](https://discuss.elastic.co/t/it-shows-sucessfully-run-but-unable-to-access-it/368937 "2024-10-16T18:59:54Z")

</div>

This category relates to the Enterprise Search set of products - App Search, Site Search and Workplace Search. If your question relates to core Elasticsearch functionality, please head over to the Elasticsearch category…

---

## [RequestCancelledException](https://discuss.elastic.co/t/requestcancelledexception/368936)

<div class="topic-metadata">

**Author:** [@kaly](https://discuss.elastic.co/u/kaly)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 5:32pm UTC](https://discuss.elastic.co/t/requestcancelledexception/368936 "2024-10-16T17:32:22Z")

</div>

Elasticsearch 8.12 java client api with GetRequest and IndexRequest gives RequestCancelledException.

---

## [Read timeout errors](https://discuss.elastic.co/t/read-timeout-errors/366820)

<div class="topic-metadata">

**Author:** [@dpitchford](https://discuss.elastic.co/u/dpitchford)\
**Replies:** 9\
**Last updated:** [October 16, 2024, 4:43pm UTC](https://discuss.elastic.co/t/read-timeout-errors/366820 "2024-10-16T16:43:55Z")

</div>

A single-threaded script I'm working on is experiencing repeated read timeout errors from Elasticsearch. This is happening when trying to bulk-index data to an index with 12 primary and 0 replicas shards across 4 nodes. …

---

## [how is Answer document related to tags in the Question document in Elasticsearch documentation example](https://discuss.elastic.co/t/how-is-answer-document-related-to-tags-in-the-question-document-in-elasticsearch-documentation-example/368930)

<div class="topic-metadata">

**Author:** [@yulinxp](https://discuss.elastic.co/u/yulinxp)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 4:05pm UTC](https://discuss.elastic.co/t/how-is-answer-document-related-to-tags-in-the-question-document-in-elasticsearch-documentation-example/368930 "2024-10-16T16:05:19Z")

</div>

I am reading Elasticsearch documentation 8.15. Parent 1 has tags array. PUT child\_example/\_doc/1 { "join": { "name": "question" }, "body": "\<p\>I have Windows 2003 server and i bought a ne…

---

## [Updating elastic django documents conditionally based on older documents](https://discuss.elastic.co/t/updating-elastic-django-documents-conditionally-based-on-older-documents/368922)

<div class="topic-metadata">

**Author:** [@Anshu\_Garg](https://discuss.elastic.co/u/Anshu_Garg)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 2:07pm UTC](https://discuss.elastic.co/t/updating-elastic-django-documents-conditionally-based-on-older-documents/368922 "2024-10-16T14:07:05Z")

</div>

Hi team, I am stuck on the below problem. Can somebody please help I am using django elasticsearch DSL and have below model structure and corresponding document class Token(AppModel): # fields f1, f2, f3 …

---

## [How to unblock .security-x index?](https://discuss.elastic.co/t/how-to-unblock-security-x-index/368918)

<div class="topic-metadata">

**Author:** [@Oleg\_G](https://discuss.elastic.co/u/Oleg_G)\
**Replies:** 0\
**Last updated:** [October 16, 2024, 1:41pm UTC](https://discuss.elastic.co/t/how-to-unblock-security-x-index/368918 "2024-10-16T13:41:41Z")

</div>

We run Elastic and Kibana in Docker. We hit the disk space limit and indices moved to read-only state. After cleaned up I tried to set them to read-write state by executing this command- $ curl -XPUT -H "Content-Type: …

---

## [Not able to create basic authentication with username and password on elasticsearch 8.15.0 and kibana 8.15.0](https://discuss.elastic.co/t/not-able-to-create-basic-authentication-with-username-and-password-on-elasticsearch-8-15-0-and-kibana-8-15-0/368820)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 5\
**Last updated:** [October 16, 2024, 1:05pm UTC](https://discuss.elastic.co/t/not-able-to-create-basic-authentication-with-username-and-password-on-elasticsearch-8-15-0-and-kibana-8-15-0/368820 "2024-10-16T13:05:40Z")

</div>

Hi, I want that elasticsearch of 8.15.0 should connect with kibana 8.15.0 with basic authentication but kibana is giving error i.e not server yet.But it is running without basic authentication.My docker-compose file is b…

---

## [如何用Criteria实现实现 and (a or b or c) 这种效果？](https://discuss.elastic.co/t/criteria-and-a-or-b-or-c/368900)

<div class="topic-metadata">

**Author:** [@a1248145775](https://discuss.elastic.co/u/a1248145775)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 10:11am UTC](https://discuss.elastic.co/t/criteria-and-a-or-b-or-c/368900 "2024-10-16T10:11:52Z")

</div>

各位好，请教个问题，为什么用es的Criteria多个or连接在一起，最终生成的dsl只有这个or里面的最后一个？debug到org.springframework.data.elasticsearch.client.elc.CriteriaQueryProcessor#createQuery，发现should不会拿链式调用下面的内容

---

## [Transform missing documents in continuous mode](https://discuss.elastic.co/t/transform-missing-documents-in-continuous-mode/368695)

<div class="topic-metadata">

**Author:** [@Luka\_Jagmaidze](https://discuss.elastic.co/u/Luka_Jagmaidze)\
**Replies:** 0\
**Last updated:** [October 11, 2024, 3:25pm UTC](https://discuss.elastic.co/t/transform-missing-documents-in-continuous-mode/368695 "2024-10-11T15:25:42Z")

</div>

I have an issue with the transform i have created. It is aggregating on the source index which has events of the messages in it. The transform is running in continuous mode with the following options: "sync": { "t…

---

## [How to reduce the high score when a term appears repeatedly in a record in Elasticsearch, for example, the term 'fruit' should have a lower score in the record 'fruit' compared to 'record2 fruit xx fruit'?](https://discuss.elastic.co/t/how-to-reduce-the-high-score-when-a-term-appears-repeatedly-in-a-record-in-elasticsearch-for-example-the-term-fruit-should-have-a-lower-score-in-the-record-fruit-compared-to-record2-fruit-xx-fruit/368879)

<div class="topic-metadata">

**Author:** [@lmr520](https://discuss.elastic.co/u/lmr520)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 6:06am UTC](https://discuss.elastic.co/t/how-to-reduce-the-high-score-when-a-term-appears-repeatedly-in-a-record-in-elasticsearch-for-example-the-term-fruit-should-have-a-lower-score-in-the-record-fruit-compared-to-record2-fruit-xx-fruit/368879 "2024-10-16T06:06:10Z")

</div>

How to reduce the high score when a term appears repeatedly in a record in Elasticsearch, for example, the term 'fruit' should have a lower score in the record 'fruit' compared to 'record2 fruit xx fruit'?

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=68)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=70)
