# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=70

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 71

---

## [Cluster does not start after updating certificates](https://discuss.elastic.co/t/cluster-does-not-start-after-updating-certificates/368795)

<div class="topic-metadata">

**Author:** [@aleksandr.komarov](https://discuss.elastic.co/u/aleksandr.komarov)\
**Replies:** 3\
**Last updated:** [October 15, 2024, 11:14pm UTC](https://discuss.elastic.co/t/cluster-does-not-start-after-updating-certificates/368795 "2024-10-15T23:14:03Z")

</div>

Our cluster's CA and node certificates have expired. We updated them by following these steps: Expired ca.crt/nodes certificates - how to renew such certificates? - Elastic Stack / Elasticsearch - Discuss the Elastic Sta…

---

## [Does sort need to be applied to query for applying index-sort optimizations? What about transforms?](https://discuss.elastic.co/t/does-sort-need-to-be-applied-to-query-for-applying-index-sort-optimizations-what-about-transforms/368872)

<div class="topic-metadata">

**Author:** [@Max5](https://discuss.elastic.co/u/Max5)\
**Replies:** 0\
**Last updated:** [October 15, 2024, 8:00pm UTC](https://discuss.elastic.co/t/does-sort-need-to-be-applied-to-query-for-applying-index-sort-optimizations-what-about-transforms/368872 "2024-10-15T20:00:46Z")

</div>

I'm trying to fully understand the best way to optimize for transforms and then searching running aggregations on resulting indices. The situation: Stuck on 7.17.21 currently Non-managed cluster Conversion to data str…

---

## [Searching against runtime mapped fields](https://discuss.elastic.co/t/searching-against-runtime-mapped-fields/361597)

<div class="topic-metadata">

**Author:** [@John\_Schoonover](https://discuss.elastic.co/u/John_Schoonover)\
**Replies:** 2\
**Last updated:** [October 15, 2024, 6:11pm UTC](https://discuss.elastic.co/t/searching-against-runtime-mapped-fields/361597 "2024-10-15T18:11:13Z")

</div>

Hey all! Long-time user, first-time poster! I've been trying to figure out a problem we're seeing with some unique search behavior on runtime fields when using CCS. REF: Runtime fields in a search request When done o…

---

## [Using values from an array as field names to contain values from another array](https://discuss.elastic.co/t/using-values-from-an-array-as-field-names-to-contain-values-from-another-array/368478)

<div class="topic-metadata">

**Author:** [@ccweirsw](https://discuss.elastic.co/u/ccweirsw)\
**Replies:** 5\
**Last updated:** [October 15, 2024, 2:58pm UTC](https://discuss.elastic.co/t/using-values-from-an-array-as-field-names-to-contain-values-from-another-array/368478 "2024-10-15T14:58:44Z")

</div>

I am ingesting event logs from Office 365. Some of these documents contain objects that look like this: "DeviceProperties": \[ { "Value": "Windows10", "Name": "OS" }, …

---

## [Retention errors in Transforms](https://discuss.elastic.co/t/retention-errors-in-transforms/368747)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 1\
**Last updated:** [October 15, 2024, 2:45pm UTC](https://discuss.elastic.co/t/retention-errors-in-transforms/368747 "2024-10-15T14:45:19Z")

</div>

Hi Team, We are using transforms in our cluster and we have applied retention in the transforms for 90 days. But now a days we are frequently seeing below warnings in transforms. Could you please help me to understand t…

---

## [Pull data from multiple index](https://discuss.elastic.co/t/pull-data-from-multiple-index/368843)

<div class="topic-metadata">

**Author:** [@charleskingsley](https://discuss.elastic.co/u/charleskingsley)\
**Replies:** 1\
**Last updated:** [October 15, 2024, 12:01pm UTC](https://discuss.elastic.co/t/pull-data-from-multiple-index/368843 "2024-10-15T12:01:24Z")

</div>

I am having 2 index as follows, this is a sample index. My request is to get Employees from employee-details-v1 index whose course is dotnet. Need to get this in single ES Query not in 2 steps It's a sample index. Same …

---

## [Errors from the virtual machine which hosts the ES](https://discuss.elastic.co/t/errors-from-the-virtual-machine-which-hosts-the-es/368175)

<div class="topic-metadata">

**Author:** [@stanimir\_kirilov](https://discuss.elastic.co/u/stanimir_kirilov)\
**Replies:** 8\
**Last updated:** [October 15, 2024, 8:07am UTC](https://discuss.elastic.co/t/errors-from-the-virtual-machine-which-hosts-the-es/368175 "2024-10-15T08:07:45Z")

</div>

Hello, Could you please help me out, I am trying to understand why this errors are generated, but without any success. Thanks in advance! AppIdentifier:onli Culture:en-US Environment:prd-eu EventCode:100007 EventDe…

---

## [Too much time spending on build\_scorer in elasticsearch queries](https://discuss.elastic.co/t/too-much-time-spending-on-build-scorer-in-elasticsearch-queries/368825)

<div class="topic-metadata">

**Author:** [@Chanaka\_Liyanarachch](https://discuss.elastic.co/u/Chanaka_Liyanarachch)\
**Replies:** 0\
**Last updated:** [October 15, 2024, 7:52am UTC](https://discuss.elastic.co/t/too-much-time-spending-on-build-scorer-in-elasticsearch-queries/368825 "2024-10-15T07:52:04Z")

</div>

Too much time spending on calculating the score in the below queries, I have only used the filters but still, it's calculates the score, Query:- { "from": 0, "size": 10, "query": { "bool": { "filter": \[…

---

## [One Huge Index or Multiple Indexes?](https://discuss.elastic.co/t/one-huge-index-or-multiple-indexes/368803)

<div class="topic-metadata">

**Author:** [@paladin\_paterson](https://discuss.elastic.co/u/paladin_paterson)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 9:19pm UTC](https://discuss.elastic.co/t/one-huge-index-or-multiple-indexes/368803 "2024-10-14T21:19:52Z")

</div>

Our company has a very large Elasticsearch index in production. The cluster holds HTML documents that are large. The index has 600 shards in it. The largest shard has 1000GB in it. We are planning a rework of our system …

---

## [How does knn affects the score?](https://discuss.elastic.co/t/how-does-knn-affects-the-score/365759)

<div class="topic-metadata">

**Author:** [@Yoann\_Buzenet](https://discuss.elastic.co/u/Yoann_Buzenet)\
**Replies:** 4\
**Last updated:** [October 15, 2024, 5:31am UTC](https://discuss.elastic.co/t/how-does-knn-affects-the-score/365759 "2024-10-15T05:31:16Z")

</div>

Hello, I saw that knn cannot be used in the \_explain API in Kibana and wondered why. I've seen that Reciprocal Ranking Fusion and Convex Combination both allow to compute a result from a classical query score and a knn…

---

## [Does increase in index size require more RAM or disk is sufficient?](https://discuss.elastic.co/t/does-increase-in-index-size-require-more-ram-or-disk-is-sufficient/368816)

<div class="topic-metadata">

**Author:** [@Abhishek\_Sen](https://discuss.elastic.co/u/Abhishek_Sen)\
**Replies:** 0\
**Last updated:** [October 15, 2024, 3:48am UTC](https://discuss.elastic.co/t/does-increase-in-index-size-require-more-ram-or-disk-is-sufficient/368816 "2024-10-15T03:48:54Z")

</div>

Does the entire elastic index remain in memory in the index servers? Is the index stored in the disk? If the index size increases do I need more RAM or more disk space in the index servers? We have situation where we a…

---

## [Why is there such a big gap between the cumulative time from the search profiler and the latency from esrally?](https://discuss.elastic.co/t/why-is-there-such-a-big-gap-between-the-cumulative-time-from-the-search-profiler-and-the-latency-from-esrally/368479)

<div class="topic-metadata">

**Author:** [@corojoon93](https://discuss.elastic.co/u/corojoon93)\
**Replies:** 5\
**Last updated:** [October 14, 2024, 10:22pm UTC](https://discuss.elastic.co/t/why-is-there-such-a-big-gap-between-the-cumulative-time-from-the-search-profiler-and-the-latency-from-esrally/368479 "2024-10-14T22:22:00Z")

</div>

I have been using esrally and search profiler to test the performance of search queries processed by the existing cluster. I turned off request cache and the query cache for the index. Test result After running the sea…

---

## [In filter context, is the filter array AND or OR?](https://discuss.elastic.co/t/in-filter-context-is-the-filter-array-and-or-or/368802)

<div class="topic-metadata">

**Author:** [@matt.snyder](https://discuss.elastic.co/u/matt.snyder)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 8:19pm UTC](https://discuss.elastic.co/t/in-filter-context-is-the-filter-array-and-or-or/368802 "2024-10-14T20:19:32Z")

</div>

In query DSL, I have a function score with a date decay, and a filter on that date decay, and I'm surprised to find that the filters in the filter array appear to be OR'd, not ANDed. In other words, the date decay is ap…

---

## [Elastic search parsing error](https://discuss.elastic.co/t/elastic-search-parsing-error/368666)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 10\
**Last updated:** [October 14, 2024, 6:38pm UTC](https://discuss.elastic.co/t/elastic-search-parsing-error/368666 "2024-10-14T18:38:10Z")

</div>

Hello, i have same problem as Logstash json parse error, but i am not using any codec =\> json or not handling json data. But when i use output { if \[type\] == "mssql-audit-dwh" { stdout { codec …

---

## [Failed to create index template with same priority](https://discuss.elastic.co/t/failed-to-create-index-template-with-same-priority/368797)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 4:22pm UTC](https://discuss.elastic.co/t/failed-to-create-index-template-with-same-priority/368797 "2024-10-14T16:22:02Z")

</div>

Hi, I am trying to create two templates with patterns: \*my\_index1\_id1\* \*my\_index2\_id1\* I am failing on have the same priority \[0\], multiple index templates may not match during index creation, please use a different …

---

## [Elastic Search - How to make stats bucket over calculated bucket using bucket script and bucket path](https://discuss.elastic.co/t/elastic-search-how-to-make-stats-bucket-over-calculated-bucket-using-bucket-script-and-bucket-path/368791)

<div class="topic-metadata">

**Author:** [@vitor.rubio](https://discuss.elastic.co/u/vitor.rubio)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 2:53pm UTC](https://discuss.elastic.co/t/elastic-search-how-to-make-stats-bucket-over-calculated-bucket-using-bucket-script-and-bucket-path/368791 "2024-10-14T14:53:21Z")

</div>

Lets start with a simple query in an Elastic Search netflow database. I need to get the sum of network bytes aggregated by network.direction, so I do: { "query": { "bool": { "filter": \[ { "…

---

## [Having both filebeat and logstash event time in a log](https://discuss.elastic.co/t/having-both-filebeat-and-logstash-event-time-in-a-log/368773)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 12:41pm UTC](https://discuss.elastic.co/t/having-both-filebeat-and-logstash-event-time-in-a-log/368773 "2024-10-14T12:41:50Z")

</div>

Assume i do have a log in the following format: \[ISO8601\_timestamp\] \[log\_message\] what i want to do is to have 3 timestamp after i store my log in Elasticsearch. right now im reading logs with filebeat and then send th…

---

## [Efficient more-like-this using vector search](https://discuss.elastic.co/t/efficient-more-like-this-using-vector-search/368728)

<div class="topic-metadata">

**Author:** [@martin-k](https://discuss.elastic.co/u/martin-k)\
**Replies:** 2\
**Last updated:** [October 14, 2024, 12:32pm UTC](https://discuss.elastic.co/t/efficient-more-like-this-using-vector-search/368728 "2024-10-14T12:32:13Z")

</div>

Hello friends, I am learning about semantic search and vector embeddings and it’s making me love life more every day. What a time to be alive! I’m thinking about- and experimenting with- ways I could implement this to …

---

## [When \`discovery.type: single-node\` is not set, disabling TLS at the HTTP layer will cause elasticsearch to fail to start](https://discuss.elastic.co/t/when-discovery-type-single-node-is-not-set-disabling-tls-at-the-http-layer-will-cause-elasticsearch-to-fail-to-start/368753)

<div class="topic-metadata">

**Author:** [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Replies:** 3\
**Last updated:** [October 14, 2024, 12:30pm UTC](https://discuss.elastic.co/t/when-discovery-type-single-node-is-not-set-disabling-tls-at-the-http-layer-will-cause-elasticsearch-to-fail-to-start/368753 "2024-10-14T12:30:03Z")

</div>

When discovery.type: single-node is not set, disabling TLS at the HTTP layer will cause elasticsearch to fail to start. I used a simple docker-compose.yml to verify this. Just run docker compose up -d. services: es01…

---

## [GeoShape Polygon Query not returning expected documents](https://discuss.elastic.co/t/geoshape-polygon-query-not-returning-expected-documents/368630)

<div class="topic-metadata">

**Author:** [@Shaun1](https://discuss.elastic.co/u/Shaun1)\
**Replies:** 2\
**Last updated:** [October 11, 2024, 5:02pm UTC](https://discuss.elastic.co/t/geoshape-polygon-query-not-returning-expected-documents/368630 "2024-10-11T17:02:07Z")

</div>

Summary GeoShape Polygon Query not returning expected documents that suspect are within the polygon; but am aware it maybe related to crossing the International Date Line. My environment details below Kibana version: …

---

## [Elastic 8.15.0 slow query if search \> 6 days](https://discuss.elastic.co/t/elastic-8-15-0-slow-query-if-search-6-days/367061)

<div class="topic-metadata">

**Author:** [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Replies:** 5\
**Last updated:** [October 14, 2024, 11:29am UTC](https://discuss.elastic.co/t/elastic-8-15-0-slow-query-if-search-6-days/367061 "2024-10-14T11:29:30Z")

</div>

hi guys, i'm seeing slow queries from kibana if I search for more than 6 days using a wildard search like so: \*word\*. If I query for 6 days result is instant at about 3 seconds, but more than 6 days and kibana just hang…

---

## [Elasticsearch stop responding with too many scroll contexts](https://discuss.elastic.co/t/elasticsearch-stop-responding-with-too-many-scroll-contexts/368510)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 1\
**Last updated:** [October 14, 2024, 10:59am UTC](https://discuss.elastic.co/t/elasticsearch-stop-responding-with-too-many-scroll-contexts/368510 "2024-10-14T10:59:58Z")

</div>

We have .NET app that use NEST to store events in elastic. Randomly after some time my elasticsearch cluster of 3 nodes stop working and i see these errors. \[indices:data/read/search\[phase/query\]\]\\nCaused by: org.elasti…

---

## [SSO, query API, index privileges](https://discuss.elastic.co/t/sso-query-api-index-privileges/368741)

<div class="topic-metadata">

**Author:** [@johnwood](https://discuss.elastic.co/u/johnwood)\
**Replies:** 2\
**Last updated:** [October 14, 2024, 9:34am UTC](https://discuss.elastic.co/t/sso-query-api-index-privileges/368741 "2024-10-14T09:34:04Z")

</div>

Hi ElasticBrains I have an ES cloud that I wish to access via the API - my users are defined in Auth0 SSO and I use role mapping to set their index privileges in ES. I have an app that front ends their ES/QL queries vi…

---

## [Using Elastic Search With ElasticsearchClient](https://discuss.elastic.co/t/using-elastic-search-with-elasticsearchclient/368710)

<div class="topic-metadata">

**Author:** [@GANESHAN\_RAMAN](https://discuss.elastic.co/u/GANESHAN_RAMAN)\
**Replies:** 4\
**Last updated:** [October 14, 2024, 6:35am UTC](https://discuss.elastic.co/t/using-elastic-search-with-elasticsearchclient/368710 "2024-10-14T06:35:16Z")

</div>

Hi, Iam migrating from RestHighLevelClient to ElasticsearchClient and as part of this change i need to replace NativeSearchQuery and NativeSearchQueryBuilder with NativeQuery and NativeQueryBuilder But iam not able to p…

---

## [Receiving below error after updating ES indices deletion script to python 3.11](https://discuss.elastic.co/t/receiving-below-error-after-updating-es-indices-deletion-script-to-python-3-11/368742)

<div class="topic-metadata">

**Author:** [@Randika\_Munasinghe](https://discuss.elastic.co/u/Randika_Munasinghe)\
**Replies:** 0\
**Last updated:** [October 13, 2024, 10:59pm UTC](https://discuss.elastic.co/t/receiving-below-error-after-updating-es-indices-deletion-script-to-python-3-11/368742 "2024-10-13T22:59:47Z")

</div>

\[ERROR\] 2024-10-13T00:00:15.135Z 60708a75-e354-4207-96e0-24481a4a6c05 Missing 'index\_retention' in the event payload. Code is as below # Fetch all indexes all\_indexes = es.indices.get\_alias("\*") # Loop through all ind…

---

## [Polygon rejected as self-intersecting, but it does not self-intersect](https://discuss.elastic.co/t/polygon-rejected-as-self-intersecting-but-it-does-not-self-intersect/368714)

<div class="topic-metadata">

**Author:** [@jamesdiacono](https://discuss.elastic.co/u/jamesdiacono)\
**Replies:** 2\
**Last updated:** [October 13, 2024, 8:54am UTC](https://discuss.elastic.co/t/polygon-rejected-as-self-intersecting-but-it-does-not-self-intersect/368714 "2024-10-13T08:54:32Z")

</div>

Elasticsearch 8.15.2 is refusing to index a polygon which, as far as I can tell, is perfectly valid. Here is an image of the polygon on a map. Notice that it is just a trapezoid with nothing funny going on, and it does n…

---

## [Index sorting on query performance when unable to perform early termination](https://discuss.elastic.co/t/index-sorting-on-query-performance-when-unable-to-perform-early-termination/368717)

<div class="topic-metadata">

**Author:** [@samde](https://discuss.elastic.co/u/samde)\
**Replies:** 0\
**Last updated:** [October 13, 2024, 5:03am UTC](https://discuss.elastic.co/t/index-sorting-on-query-performance-when-unable-to-perform-early-termination/368717 "2024-10-13T05:03:31Z")

</div>

Trying to understand the query performance implications of index sorting when track\_total\_hits is true, along with the following query parameters listed below. As afaik when track\_total\_hits is enabled, Elasticsearch wi…

---

## [What is the best practice that can be carried out?](https://discuss.elastic.co/t/what-is-the-best-practice-that-can-be-carried-out/368702)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 7\
**Last updated:** [October 12, 2024, 5:28am UTC](https://discuss.elastic.co/t/what-is-the-best-practice-that-can-be-carried-out/368702 "2024-10-12T05:28:55Z")

</div>

hi I have a server with great specifications and I want to use elasticsearch to store data from 3100 devices What is the best practice? 1 Do I install the Linux system on the server and install one elasticsearch node, …

---

## [Data attributes for inclusion and exclusion are not working](https://discuss.elastic.co/t/data-attributes-for-inclusion-and-exclusion-are-not-working/359656)

<div class="topic-metadata">

**Author:** [@Dongmyoung\_Kim](https://discuss.elastic.co/u/Dongmyoung_Kim)\
**Replies:** 1\
**Last updated:** [October 11, 2024, 7:49pm UTC](https://discuss.elastic.co/t/data-attributes-for-inclusion-and-exclusion-are-not-working/359656 "2024-10-11T19:49:11Z")

</div>

I've implemented the "data-elastic-exclude" attribute in the body tag and "data-elastic-include" in specific content sections to ensure that only those parts are indexed by Elasticsearch web crawler. However, it appears …

---

## [8.15.0 Migration and RangeQuery builder](https://discuss.elastic.co/t/8-15-0-migration-and-rangequery-builder/366627)

<div class="topic-metadata">

**Author:** [@Gerald\_PONT](https://discuss.elastic.co/u/Gerald_PONT)\
**Replies:** 7\
**Last updated:** [October 11, 2024, 8:14pm UTC](https://discuss.elastic.co/t/8-15-0-migration-and-rangequery-builder/366627 "2024-10-11T20:14:34Z")

</div>

Hi all, We are using Elasticsearch in our software. We are migrating from version 8.10.1 to 8.15.1. We had this code in our software : rangeQueryBuilder = new RangeQuery.Builder() .field(fieldName) .gte(JsonData.of(…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=69)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=71)
