# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=75

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 76

---

## [How to create a search request with multiple knn fields using the Node Client](https://discuss.elastic.co/t/how-to-create-a-search-request-with-multiple-knn-fields-using-the-node-client/367098)

<div class="topic-metadata">

**Author:** [@Bruce\_Mcpherson](https://discuss.elastic.co/u/Bruce_Mcpherson)\
**Replies:** 4\
**Last updated:** [September 25, 2024, 1:27pm UTC](https://discuss.elastic.co/t/how-to-create-a-search-request-with-multiple-knn-fields-using-the-node-client/367098 "2024-09-25T13:27:33Z")

</div>

My first post here - I'm using elasticsearch 8.15.0 Node client. I have an index with multiple dense-vector fields, and I want to search on them all. With the python client, I am able to do this. {query: {bool: {shoul…

---

## [Elasticsearch to conditionally match all tags, categories and keywords](https://discuss.elastic.co/t/elasticsearch-to-conditionally-match-all-tags-categories-and-keywords/367095)

<div class="topic-metadata">

**Author:** [@Wilson\_Chen](https://discuss.elastic.co/u/Wilson_Chen)\
**Replies:** 1\
**Last updated:** [September 25, 2024, 1:06pm UTC](https://discuss.elastic.co/t/elasticsearch-to-conditionally-match-all-tags-categories-and-keywords/367095 "2024-09-25T13:06:08Z")

</div>

I am trying to build a music search function, using Elasticsearch 9.15. I am currently using .NET client. I am happy to just get the idea how it would look like via DSL, so that I can replicate it for .NET. Every piece…

---

## [Pattern\_replace Token Filter and preserve original tokens](https://discuss.elastic.co/t/pattern-replace-token-filter-and-preserve-original-tokens/367088)

<div class="topic-metadata">

**Author:** [@John.Doe](https://discuss.elastic.co/u/John.Doe)\
**Replies:** 1\
**Last updated:** [September 25, 2024, 8:24am UTC](https://discuss.elastic.co/t/pattern-replace-token-filter-and-preserve-original-tokens/367088 "2024-09-25T08:24:15Z")

</div>

Hi, Is there any way how to apply pattern\_replace token filter and preserve original tokens too? I cannot use multifields as a solution. Thanks in advance !

---

## [Elasticsearch 8.8.2 vulnerabilities issue](https://discuss.elastic.co/t/elasticsearch-8-8-2-vulnerabilities-issue/367086)

<div class="topic-metadata">

**Author:** [@Sandeep6](https://discuss.elastic.co/u/Sandeep6)\
**Replies:** 1\
**Last updated:** [September 25, 2024, 7:28am UTC](https://discuss.elastic.co/t/elasticsearch-8-8-2-vulnerabilities-issue/367086 "2024-09-25T07:28:55Z")

</div>

Hi Team, We have elasticsearch version 8.8.2, and it is in this version that we discovered the vulnerability issue. So, how can I avoid this issue? And what is the new updated version where there are no vulnerabilities…

---

## [Kibana is not connecting with elasticsearch of 8.15.0](https://discuss.elastic.co/t/kibana-is-not-connecting-with-elasticsearch-of-8-15-0/367082)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 0\
**Last updated:** [September 25, 2024, 6:06am UTC](https://discuss.elastic.co/t/kibana-is-not-connecting-with-elasticsearch-of-8-15-0/367082 "2024-09-25T06:06:44Z")

</div>

Hi, My elasticsearch is not connecting with kibana because we are using 8.15.0 version.It is giving error \[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes. security\_exceptio…

---

## [Joining two documents with a unique session Id](https://discuss.elastic.co/t/joining-two-documents-with-a-unique-session-id/367066)

<div class="topic-metadata">

**Author:** [@sintim](https://discuss.elastic.co/u/sintim)\
**Replies:** 1\
**Last updated:** [September 25, 2024, 6:02am UTC](https://discuss.elastic.co/t/joining-two-documents-with-a-unique-session-id/367066 "2024-09-25T06:02:02Z")

</div>

Is it possible to join two documents in Elasticsearch based on the same session ID? The goal is to create a visualization that shows the field in one of the documents together with another field from the other document. …

---

## [Elastic Cloud Licensing](https://discuss.elastic.co/t/elastic-cloud-licensing/367078)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [September 25, 2024, 5:16am UTC](https://discuss.elastic.co/t/elastic-cloud-licensing/367078 "2024-09-25T05:16:44Z")

</div>

Hi All, I wanted to know whether the elastic stack offering on elastic cloud is same as elastic cloud offering on azure marketplace. If so, can I use the same license from elastic cloud to spin up cluster in elastic cl…

---

## [Script field could not run in the visualize](https://discuss.elastic.co/t/script-field-could-not-run-in-the-visualize/366852)

<div class="topic-metadata">

**Author:** [@xiaofei\_lu](https://discuss.elastic.co/u/xiaofei_lu)\
**Replies:** 1\
**Last updated:** [September 25, 2024, 1:48am UTC](https://discuss.elastic.co/t/script-field-could-not-run-in-the-visualize/366852 "2024-09-25T01:48:24Z")

</div>

I create a script field as follwing if (params.\_source.containsKey('datav1') && params.\_source.datav1.containsKey('messageHistory')) { def firstElement = params.\_source.datav1.messageHistory\[0\]; if (firstElement…

---

## [Very poor elastic-agent performance with SQS/S3 for Cloudtrail logs](https://discuss.elastic.co/t/very-poor-elastic-agent-performance-with-sqs-s3-for-cloudtrail-logs/367055)

<div class="topic-metadata">

**Author:** [@Scott\_Hiemstra](https://discuss.elastic.co/u/Scott_Hiemstra)\
**Replies:** 6\
**Last updated:** [September 25, 2024, 1:28am UTC](https://discuss.elastic.co/t/very-poor-elastic-agent-performance-with-sqs-s3-for-cloudtrail-logs/367055 "2024-09-25T01:28:59Z")

</div>

I've read the July blog post claiming 8 x t3.micro instances can process \> 40,000 events/second using SQS/S3. That comes out to \> 5,000 events/second/host. I currently have 1 x m6a.large and 1 x t3a.small running 8.15.…

---

## [How to specify "wait several N seconds before retry" in Elastic Python Client?](https://discuss.elastic.co/t/how-to-specify-wait-several-n-seconds-before-retry-in-elastic-python-client/360726)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 6\
**Last updated:** [September 24, 2024, 5:29pm UTC](https://discuss.elastic.co/t/how-to-specify-wait-several-n-seconds-before-retry-in-elastic-python-client/360726 "2024-09-24T17:29:51Z")

</div>

Hello guys! I found that I can specify the number of attempts to retry a request if the connection is lost (below example for Python Client): from elasticsearch import Elasticsearch es = Elasticsearch(url, basic\_auth=(…

---

## [External Certificate configuration](https://discuss.elastic.co/t/external-certificate-configuration/366891)

<div class="topic-metadata">

**Author:** [@Santanu112](https://discuss.elastic.co/u/Santanu112)\
**Replies:** 6\
**Last updated:** [September 24, 2024, 5:07pm UTC](https://discuss.elastic.co/t/external-certificate-configuration/366891 "2024-09-24T17:07:31Z")

</div>

Hi Team, I am trying to add my org certificate (.pfx) to elastic security so we can securely access it from other servers. i am not able to import it in existing CA cert. Could any one please tell me how to add it in …

---

## [After upgrading from 7.7.18 to 8.15.1 I DO NOT see nodes folder](https://discuss.elastic.co/t/after-upgrading-from-7-7-18-to-8-15-1-i-do-not-see-nodes-folder/367058)

<div class="topic-metadata">

**Author:** [@devin](https://discuss.elastic.co/u/devin)\
**Replies:** 2\
**Last updated:** [September 24, 2024, 3:10pm UTC](https://discuss.elastic.co/t/after-upgrading-from-7-7-18-to-8-15-1-i-do-not-see-nodes-folder/367058 "2024-09-24T15:10:51Z")

</div>

Hello, Hoping some one can help solve me this puzzle, I was previously on ES-7.7.18 and I just upgraded to 8.15.1 but as opposed to ES-7.7.18 I do not see nodes folder created in ES-8.15.1 and Instead all I see is a nod…

---

## [Assigning Different Data Tier to Indices on a Same Node](https://discuss.elastic.co/t/assigning-different-data-tier-to-indices-on-a-same-node/367054)

<div class="topic-metadata">

**Author:** [@kdwolf](https://discuss.elastic.co/u/kdwolf)\
**Replies:** 0\
**Last updated:** [September 24, 2024, 2:42pm UTC](https://discuss.elastic.co/t/assigning-different-data-tier-to-indices-on-a-same-node/367054 "2024-09-24T14:42:54Z")

</div>

Hello, All I understand a concept of different tiers for various types of indices (content data, Hot, Cold, etc.) but I cannot find any reference / documentation if there is a practical benefit to assign different indic…

---

## [How can I query many indexes based on a particular field value?](https://discuss.elastic.co/t/how-can-i-query-many-indexes-based-on-a-particular-field-value/367026)

<div class="topic-metadata">

**Author:** [@\_Zhang](https://discuss.elastic.co/u/_Zhang)\
**Replies:** 3\
**Last updated:** [September 24, 2024, 2:08pm UTC](https://discuss.elastic.co/t/how-can-i-query-many-indexes-based-on-a-particular-field-value/367026 "2024-09-24T14:08:57Z")

</div>

Background: Indexes: index-apple, index-banana, index-orange, etc. Each of them has a field called type. I wanna query "apple" and "banana": POST /index-apple,index-banana/\_search { "query": { "terms": { …

---

## [ES 8.14.1 throwing java exception for zstd on s390x platform](https://discuss.elastic.co/t/es-8-14-1-throwing-java-exception-for-zstd-on-s390x-platform/367036)

<div class="topic-metadata">

**Author:** [@asati](https://discuss.elastic.co/u/asati)\
**Replies:** 1\
**Last updated:** [September 24, 2024, 2:08pm UTC](https://discuss.elastic.co/t/es-8-14-1-throwing-java-exception-for-zstd-on-s390x-platform/367036 "2024-09-24T14:08:25Z")

</div>

We have upgraded elasticsearch in our env which is on s390x platform from 8.13.3 to 8.14.1. We started getting java exceptions for zstd , saying not supported on s390x arch. tried adding zstd package using dnf install i…

---

## [/\_count don't return valid result](https://discuss.elastic.co/t/count-dont-return-valid-result/367052)

<div class="topic-metadata">

**Author:** [@Daniel\_M\_Oliveira](https://discuss.elastic.co/u/Daniel_M_Oliveira)\
**Replies:** 0\
**Last updated:** [September 24, 2024, 2:07pm UTC](https://discuss.elastic.co/t/count-dont-return-valid-result/367052 "2024-09-24T14:07:26Z")

</div>

Hi, First of all, sorry for my question. I recently started to work with elastic. I think it is a simple question, but I can't found an explation for it. I have this indexes. When I run /prd-pdl-core-labels/\_count…

---

## [Elastic/Kibana data exportaion (over 1b hits)](https://discuss.elastic.co/t/elastic-kibana-data-exportaion-over-1b-hits/366402)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 3\
**Last updated:** [September 24, 2024, 2:06pm UTC](https://discuss.elastic.co/t/elastic-kibana-data-exportaion-over-1b-hits/366402 "2024-09-24T14:06:50Z")

</div>

Hello. I have the assignment to export specific client data from the elastic to any compatible format (csv, json, ndjson, etc.) There is an option to generate a CSV Report from Kibana by a saved query. However, this…

---

## [Editing jvm.options in cloud environment](https://discuss.elastic.co/t/editing-jvm-options-in-cloud-environment/367038)

<div class="topic-metadata">

**Author:** [@Joey\_Visbeen](https://discuss.elastic.co/u/Joey_Visbeen)\
**Replies:** 0\
**Last updated:** [September 24, 2024, 12:18pm UTC](https://discuss.elastic.co/t/editing-jvm-options-in-cloud-environment/367038 "2024-09-24T12:18:28Z")

</div>

I would like to change the logging level of the garbage collector on the hosted elastic cloud. Is this possible? If so, then please explain how, If not, what was the reasoning behind not making it possible?

---

## [Search not working when adding special characters in query](https://discuss.elastic.co/t/search-not-working-when-adding-special-characters-in-query/366872)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 7\
**Last updated:** [September 24, 2024, 12:04pm UTC](https://discuss.elastic.co/t/search-not-working-when-adding-special-characters-in-query/366872 "2024-09-24T12:04:46Z")

</div>

I have a cluster which stores device logs and I use a java client to fetch data into my application. The device logs contain special characters. So as per the documents the special characters do not get analyzed and I am…

---

## [Unable to bulk insert JSON object with no error message](https://discuss.elastic.co/t/unable-to-bulk-insert-json-object-with-no-error-message/367020)

<div class="topic-metadata">

**Author:** [@MANLW-Vestas](https://discuss.elastic.co/u/MANLW-Vestas)\
**Replies:** 4\
**Last updated:** [September 24, 2024, 11:52am UTC](https://discuss.elastic.co/t/unable-to-bulk-insert-json-object-with-no-error-message/367020 "2024-09-24T11:52:01Z")

</div>

Hi! I've set up a small local docker instance, where I'm trying to run a POC for my project. Though it has been quite intuitive and easy to set it up, and getting started with inserting data into the indices, I still hav…

---

## [hello  Do you know how I could remove or bypass this block from CloudFront?  Thanks a lot for your help](https://discuss.elastic.co/t/hello-do-you-know-how-i-could-remove-or-bypass-this-block-from-cloudfront-thanks-a-lot-for-your-help/367023)

<div class="topic-metadata">

**Author:** [@Ngocnguyen](https://discuss.elastic.co/u/Ngocnguyen)\
**Replies:** 1\
**Last updated:** [September 24, 2024, 9:22am UTC](https://discuss.elastic.co/t/hello-do-you-know-how-i-could-remove-or-bypass-this-block-from-cloudfront-thanks-a-lot-for-your-help/367023 "2024-09-24T09:22:44Z")

</div>

403 Forbidden "\\n\<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"\>\\nERROR: The request could not be satisfied\\n\\n 403 ERROR\\nThe request could not be satisfied.\\n\<HR noshade size="1px"\>\\nRequest bl…

---

## [Assistance with Querying CVEs in Elasticsearch](https://discuss.elastic.co/t/assistance-with-querying-cves-in-elasticsearch/367001)

<div class="topic-metadata">

**Author:** [@Youi](https://discuss.elastic.co/u/Youi)\
**Replies:** 0\
**Last updated:** [September 24, 2024, 2:43am UTC](https://discuss.elastic.co/t/assistance-with-querying-cves-in-elasticsearch/367001 "2024-09-24T02:43:04Z")

</div>

Hello everyone, I hope this message finds you well. I am fairly new to Elasticsearch and I am encountering some difficulties with querying. On a computer with MariaDB 10.11.1 installed, the CPE ID is as follows: cpe:…

---

## [Elasticsearch dense\_vector is taking up too much storage space！Help](https://discuss.elastic.co/t/elasticsearch-dense-vector-is-taking-up-too-much-storage-space-help/366046)

<div class="topic-metadata">

**Author:** [@Andy\_Cong](https://discuss.elastic.co/u/Andy_Cong)\
**Replies:** 8\
**Last updated:** [September 24, 2024, 7:39am UTC](https://discuss.elastic.co/t/elasticsearch-dense-vector-is-taking-up-too-much-storage-space-help/366046 "2024-09-24T07:39:06Z")

</div>

I'm having an issue with Elasticsearch where my dense\_vector data is taking up significantly more storage space than expected. ES Version 8.2.3 Data Model: vector field: Type is dense\_vector with a dimension of 1024…

---

## [How to increase the speed of response?](https://discuss.elastic.co/t/how-to-increase-the-speed-of-response/366190)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 31\
**Last updated:** [September 24, 2024, 7:25am UTC](https://discuss.elastic.co/t/how-to-increase-the-speed-of-response/366190 "2024-09-24T07:25:13Z")

</div>

Hi I have a lot of data up to 10 billion and in order to be quick I made 7 contracts and it was still very slow What is the best practice in order to be a quick response?

---

## [Elasticsearch pricing for POCs?](https://discuss.elastic.co/t/elasticsearch-pricing-for-pocs/366997)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 3\
**Last updated:** [September 24, 2024, 4:08am UTC](https://discuss.elastic.co/t/elasticsearch-pricing-for-pocs/366997 "2024-09-24T04:08:00Z")

</div>

Hello we want to offer some POCs of our service which uses Elasticsearch SaaS for document indexing - the problem is the pricing. These POCs are fixed price and the customer commits to only indexing a known quantity of …

---

## [Fatal exception while booting Elasticsearch | Missing secret key for s3 client](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch-missing-secret-key-for-s3-client/366857)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 1\
**Last updated:** [September 23, 2024, 7:08pm UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch-missing-secret-key-for-s3-client/366857 "2024-09-23T19:08:12Z")

</div>

I run it as a docker container in swarm environment. The error I got: stamp":"2024-09-20T07:03:20.868Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticsearch", "ecs.version": "1.2.0","service.name…

---

## [8.14.0 Migration : Unknown field 'preserve\_original'](https://discuss.elastic.co/t/8-14-0-migration-unknown-field-preserve-original/366975)

<div class="topic-metadata">

**Author:** [@John.Doe](https://discuss.elastic.co/u/John.Doe)\
**Replies:** 2\
**Last updated:** [September 23, 2024, 5:21pm UTC](https://discuss.elastic.co/t/8-14-0-migration-unknown-field-preserve-original/366975 "2024-09-23T17:21:31Z")

</div>

Hi, I am trying to migrate to version 8.14.0. In my filter mapping, I have the following filter : "leadingZeroTrim": { "type": "pattern\_replace", "preserve\_original": "true", "pattern": "^0+(.\*)", "replacemen…

---

## [Downgrade from es version 8.15.0 to 8.13.4](https://discuss.elastic.co/t/downgrade-from-es-version-8-15-0-to-8-13-4/366905)

<div class="topic-metadata">

**Author:** [@hamedheidarian](https://discuss.elastic.co/u/hamedheidarian)\
**Replies:** 7\
**Last updated:** [September 23, 2024, 4:36pm UTC](https://discuss.elastic.co/t/downgrade-from-es-version-8-15-0-to-8-13-4/366905 "2024-09-23T16:36:43Z")

</div>

Hi, Is there any possibility for doing such downgrade without data loss? I have seen this topic and this one before. but I don't have a snapshot before the 8.15.0 version and tried snapshot of 8.15.0 on elastic cluster …

---

## [APM Trace is not capturing complete request](https://discuss.elastic.co/t/apm-trace-is-not-capturing-complete-request/366978)

<div class="topic-metadata">

**Author:** [@akash\_bg](https://discuss.elastic.co/u/akash_bg)\
**Replies:** 0\
**Last updated:** [September 23, 2024, 3:51pm UTC](https://discuss.elastic.co/t/apm-trace-is-not-capturing-complete-request/366978 "2024-09-23T15:51:15Z")

</div>

Hi, I have an issue in APM Traces for java-based applications. The elastic Java APM agent is not capturing the complete transaction. Its has captured only the root request. How can I enable it to capture complete trace …

---

## [Hybrid Search high score on irrelevant documents](https://discuss.elastic.co/t/hybrid-search-high-score-on-irrelevant-documents/366519)

<div class="topic-metadata">

**Author:** [@mg3090](https://discuss.elastic.co/u/mg3090)\
**Replies:** 9\
**Last updated:** [September 23, 2024, 3:43pm UTC](https://discuss.elastic.co/t/hybrid-search-high-score-on-irrelevant-documents/366519 "2024-09-23T15:43:15Z")

</div>

Hello, i am building a RAG and i am facing a problem with the \_score returned in the Hybrid Query that uses KNN. Or at least, i am not fully understanding how it works. My elastic contains only economy related document…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=74)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=76)
