# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=77

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 78

---

## [Sorting the data based on date in Elasticseach using the transform](https://discuss.elastic.co/t/sorting-the-data-based-on-date-in-elasticseach-using-the-transform/366734)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 2\
**Last updated:** [September 18, 2024, 2:19pm UTC](https://discuss.elastic.co/t/sorting-the-data-based-on-date-in-elasticseach-using-the-transform/366734 "2024-09-18T14:19:29Z")

</div>

Hi Team, We are using a sort in our transform to sort the records based on a timestamp field by grouping them on a unique key and get only the latest record out of that. But we are facing an issue as in one use case my …

---

## [Conditional processing of "date" processor when empty value](https://discuss.elastic.co/t/conditional-processing-of-date-processor-when-empty-value/366418)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 10\
**Last updated:** [September 18, 2024, 12:51pm UTC](https://discuss.elastic.co/t/conditional-processing-of-date-processor-when-empty-value/366418 "2024-09-18T12:51:54Z")

</div>

Hello, My logs are parsed with a dissect processor which works flawlessly. Then I have some processors to enrich my data. One of these processors is a "date" on a field calle "date\_begin" which takes a string value an…

---

## [elasticsearch query for selecting records where agent1 is one of the agents but there are also other agents](https://discuss.elastic.co/t/elasticsearch-query-for-selecting-records-where-agent1-is-one-of-the-agents-but-there-are-also-other-agents/366678)

<div class="topic-metadata">

**Author:** [@ali7](https://discuss.elastic.co/u/ali7)\
**Replies:** 2\
**Last updated:** [September 18, 2024, 9:30am UTC](https://discuss.elastic.co/t/elasticsearch-query-for-selecting-records-where-agent1-is-one-of-the-agents-but-there-are-also-other-agents/366678 "2024-09-18T09:30:48Z")

</div>

I have an elasticsearch index that has this fields: user\_id, agent\_name, city, ... I want to run a query for selecting records where agent\_name "agent1" is one of the agents but there are also other agents, and then sel…

---

## [Best way to introduce multiple new NLP models to existing indexes?](https://discuss.elastic.co/t/best-way-to-introduce-multiple-new-nlp-models-to-existing-indexes/361209)

<div class="topic-metadata">

**Author:** [@Jason\_Woo](https://discuss.elastic.co/u/Jason_Woo)\
**Replies:** 1\
**Last updated:** [September 18, 2024, 9:07am UTC](https://discuss.elastic.co/t/best-way-to-introduce-multiple-new-nlp-models-to-existing-indexes/361209 "2024-09-18T09:07:53Z")

</div>

I am following this documentation: Add NLP inference to ingest pipelines | Machine Learning in the Elastic Stack \[8.14\] | Elastic and I learned that I can set up an ingest pipeline and reindex existing indexes into a new…

---

## [ML Inference speeds &](https://discuss.elastic.co/t/ml-inference-speeds/362084)

<div class="topic-metadata">

**Author:** [@Chenko](https://discuss.elastic.co/u/Chenko)\
**Replies:** 1\
**Last updated:** [September 18, 2024, 8:49am UTC](https://discuss.elastic.co/t/ml-inference-speeds/362084 "2024-09-18T08:49:05Z")

</div>

Hello, I have a question regarding the speed of which I embed my documents. I currently have an index with 10.000 documents, My ML node looks like this: As can be seen, I currently have 4GB of ram & 2vCPU's. With…

---

## [Local Storage in Elastic/kibana/Logstash VM](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607)

<div class="topic-metadata">

**Author:** [@otortosa](https://discuss.elastic.co/u/otortosa)\
**Replies:** 6\
**Last updated:** [September 18, 2024, 6:37am UTC](https://discuss.elastic.co/t/local-storage-in-elastic-kibana-logstash-vm/366607 "2024-09-18T06:37:37Z")

</div>

Hello Team, Im concern about the storage utility in my Elastic/Kibana/Logstash instance, is only 4 months up and 40 fleet agents and already used 500gb, is a normal behaviour? How can I avoid the high storage utility? …

---

## [TermsQuery class in elastic.clients.elasticsearch (8.x)](https://discuss.elastic.co/t/termsquery-class-in-elastic-clients-elasticsearch-8-x/366556)

<div class="topic-metadata">

**Author:** [@moyerskd](https://discuss.elastic.co/u/moyerskd)\
**Replies:** 5\
**Last updated:** [September 17, 2024, 10:27pm UTC](https://discuss.elastic.co/t/termsquery-class-in-elastic-clients-elasticsearch-8-x/366556 "2024-09-17T22:27:58Z")

</div>

In a .NET app, I am migrating from NEST (7.x) to Elastic.Clients.Elasticsearch (8.x). In NEST, I am dynamically building a List\<QueryContainer\> called queries. One section determines the need of a Terms query and if so,…

---

## [Logstash Time Column Issue](https://discuss.elastic.co/t/logstash-time-column-issue/366693)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 2\
**Last updated:** [September 17, 2024, 10:01pm UTC](https://discuss.elastic.co/t/logstash-time-column-issue/366693 "2024-09-17T22:01:55Z")

</div>

I am trying to get logstash to ingest the time column correctly into elasticsearch but it is not working. I am stuck and need help. in the csv I am trying to ingest the time looks like this: 2024-09-01 12:10:40.309 M…

---

## [Remove old index](https://discuss.elastic.co/t/remove-old-index/366694)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 0\
**Last updated:** [September 17, 2024, 6:05pm UTC](https://discuss.elastic.co/t/remove-old-index/366694 "2024-09-17T18:05:39Z")

</div>

If I am running 8.5.1 elastic version. can I remove old system index like .kibana\_task\_manager\_1... .kibana\_7.17.1\_001, 002 etc.. .kibana-event-log-7.17.1... .kibana\_task\_manager\_7.17.1\_001... .security-7 .monitor…

---

## [Transforms Movement If Node Goes Down](https://discuss.elastic.co/t/transforms-movement-if-node-goes-down/365974)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 1\
**Last updated:** [September 17, 2024, 12:31pm UTC](https://discuss.elastic.co/t/transforms-movement-if-node-goes-down/365974 "2024-09-17T12:31:33Z")

</div>

Hi Team, I have a small query regarding transform, if the node running a transform goes down, will it get moved to another node that has the transform role assigned. I am using ELK stack version 8.13.4.

---

## [Hit.id() nullable in newer java libs?](https://discuss.elastic.co/t/hit-id-nullable-in-newer-java-libs/366635)

<div class="topic-metadata">

**Author:** [@MChambers](https://discuss.elastic.co/u/MChambers)\
**Replies:** 2\
**Last updated:** [September 17, 2024, 11:16am UTC](https://discuss.elastic.co/t/hit-id-nullable-in-newer-java-libs/366635 "2024-09-17T11:16:26Z")

</div>

Updating to 8.15.1 form 8.12.1 and I've noticed the Hit class is id field is now nullable? Why? Is it possible to have docs without and ID? How does that even work?

---

## [My elastic cloud deployment is not replicating the indices after it got filled up 100%](https://discuss.elastic.co/t/my-elastic-cloud-deployment-is-not-replicating-the-indices-after-it-got-filled-up-100/366659)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 0\
**Last updated:** [September 17, 2024, 9:30am UTC](https://discuss.elastic.co/t/my-elastic-cloud-deployment-is-not-replicating-the-indices-after-it-got-filled-up-100/366659 "2024-09-17T09:30:06Z")

</div>

Hi Team, I recently upgraded the elastic cloud deployment to 8.15 version. After I made that all the new templates are unlinked with the lifecycle policy and data was keep on growing in the replica node. since it reache…

---

## [Synonyms API: Synonyms set not updating](https://discuss.elastic.co/t/synonyms-api-synonyms-set-not-updating/366647)

<div class="topic-metadata">

**Author:** [@SoleusRex](https://discuss.elastic.co/u/SoleusRex)\
**Replies:** 2\
**Last updated:** [September 17, 2024, 7:36am UTC](https://discuss.elastic.co/t/synonyms-api-synonyms-set-not-updating/366647 "2024-09-17T07:36:38Z")

</div>

I've been trying to use the synonyms API, by way of a short curl script, to add to our synonyms set in Elastic Cloud. One thing I've found is that, when I go to the Dev Tools console to verify the updates, they don't see…

---

## [Cluster.initial\_master\_nodes setting needs more info and future of this setting](https://discuss.elastic.co/t/cluster-initial-master-nodes-setting-needs-more-info-and-future-of-this-setting/366616)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 3\
**Last updated:** [September 17, 2024, 7:26am UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-setting-needs-more-info-and-future-of-this-setting/366616 "2024-09-17T07:26:20Z")

</div>

I followed - Bootstrapping a cluster | Elasticsearch Guide \[8.15\] | Elastic Below are my questions and suggestions: 1). I was asked to remove this setting once cluster is up even from data or master nodes. Now if I n…

---

## [Suppressing Elasticsearch 8 deprecation warnings](https://discuss.elastic.co/t/suppressing-elasticsearch-8-deprecation-warnings/366485)

<div class="topic-metadata">

**Author:** [@s0r1n](https://discuss.elastic.co/u/s0r1n)\
**Replies:** 1\
**Last updated:** [September 17, 2024, 6:35am UTC](https://discuss.elastic.co/t/suppressing-elasticsearch-8-deprecation-warnings/366485 "2024-09-17T06:35:19Z")

</div>

In Elasticsearch 7.17 is possible to suppress the deprecation warnings by configuring logger.deprecation.level = off in the /usr/share/elasticsearch/config/log4j2.properties file, but in Elasticsearch 8.15 with the same …

---

## [ELK stack on a standalone machine?](https://discuss.elastic.co/t/elk-stack-on-a-standalone-machine/366603)

<div class="topic-metadata">

**Author:** [@karankamat\_21](https://discuss.elastic.co/u/karankamat_21)\
**Replies:** 1\
**Last updated:** [September 17, 2024, 4:55am UTC](https://discuss.elastic.co/t/elk-stack-on-a-standalone-machine/366603 "2024-09-17T04:55:02Z")

</div>

Hello, Is it a good practice to run ELK stack on a standalone machine? My concerns: The search dataset I'm trying to load is huge Minimum requirement to run Elastic Search, Logstash, Kibana, Elastic Agent Suggestion…

---

## [ES, KIBANA AND SNAPSHOT cluster with two machines (nodes) - ES version 8.15](https://discuss.elastic.co/t/es-kibana-and-snapshot-cluster-with-two-machines-nodes-es-version-8-15/366559)

<div class="topic-metadata">

**Author:** [@Alexander\_Santos](https://discuss.elastic.co/u/Alexander_Santos)\
**Replies:** 1\
**Last updated:** [September 16, 2024, 4:52pm UTC](https://discuss.elastic.co/t/es-kibana-and-snapshot-cluster-with-two-machines-nodes-es-version-8-15/366559 "2024-09-16T16:52:51Z")

</div>

Hi, i have a cluster with two nodes. machine one - master - roles - "master", "data", "ml", "remote\_cluster\_client" machine two - second - data - roles - "data" machine tree - kibana - snapshot - this machine don't ha…

---

## [The count of all nested objects and limit](https://discuss.elastic.co/t/the-count-of-all-nested-objects-and-limit/366634)

<div class="topic-metadata">

**Author:** [@Lei\_Yang](https://discuss.elastic.co/u/Lei_Yang)\
**Replies:** 0\
**Last updated:** [September 16, 2024, 4:25pm UTC](https://discuss.elastic.co/t/the-count-of-all-nested-objects-and-limit/366634 "2024-09-16T16:25:28Z")

</div>

Hi, I'm using nested objects, there are lot of nested objects inside a nested object, please view an example as following: 'transactions' =\> \[ 'type' =\> 'nested', 'properties' =\> \[ 'id' =\> \[ 'type' =\> 'keyword', \], …

---

## [Logstash plugin azure\_event\_hubs: undefined method \`getHostContext'](https://discuss.elastic.co/t/logstash-plugin-azure-event-hubs-undefined-method-gethostcontext/366500)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 1\
**Last updated:** [September 16, 2024, 4:10pm UTC](https://discuss.elastic.co/t/logstash-plugin-azure-event-hubs-undefined-method-gethostcontext/366500 "2024-09-16T16:10:28Z")

</div>

Logstash version: 8.15.1 OS: Amazon Linux 2 Steps to reproduce: rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch added repo in /etc/yum.repos.d/logstash.repo \[logstash-8.x\] name=Elastic repository for…

---

## [New user created with API has admin role not recognized](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551)

<div class="topic-metadata">

**Author:** [@ismael\_mv](https://discuss.elastic.co/u/ismael_mv)\
**Replies:** 6\
**Last updated:** [September 16, 2024, 1:16pm UTC](https://discuss.elastic.co/t/new-user-created-with-api-has-admin-role-not-recognized/366551 "2024-09-16T13:16:47Z")

</div>

Hi, I'm trying to create a user for Kibana (elastic is reserved so I can't use it). I had executed these API call to do so, but admin role seems not beeing recognized. Do you have any clue ? (user and password are temp…

---

## [How to search for text within text?](https://discuss.elastic.co/t/how-to-search-for-text-within-text/366576)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 18\
**Last updated:** [September 16, 2024, 7:39am UTC](https://discuss.elastic.co/t/how-to-search-for-text-within-text/366576 "2024-09-16T07:39:41Z")

</div>

Hi I have an index in which there is data, including the email, and I want to search in this field (email) for specific data, for example mary.smith@sakilacustomer.org I want to look for fields that contain smith from…

---

## [Query\_string phrase search with regex](https://discuss.elastic.co/t/query-string-phrase-search-with-regex/366604)

<div class="topic-metadata">

**Author:** [@sonofmun](https://discuss.elastic.co/u/sonofmun)\
**Replies:** 0\
**Last updated:** [September 16, 2024, 6:58am UTC](https://discuss.elastic.co/t/query-string-phrase-search-with-regex/366604 "2024-09-16T06:58:12Z")

</div>

I am trying to search for a multi-word phrase using regular expressions. I would prefer to use the FVH because the unified highlighter tends to break highlighting chunks between the words within a phrase. So I would pref…

---

## [Need to give read access .fleet-artifacts system index to non admin user(Developer Role)](https://discuss.elastic.co/t/need-to-give-read-access-fleet-artifacts-system-index-to-non-admin-user-developer-role/366082)

<div class="topic-metadata">

**Author:** [@SachinJoshi](https://discuss.elastic.co/u/SachinJoshi)\
**Replies:** 17\
**Last updated:** [September 16, 2024, 4:07am UTC](https://discuss.elastic.co/t/need-to-give-read-access-fleet-artifacts-system-index-to-non-admin-user-developer-role/366082 "2024-09-16T04:07:00Z")

</div>

I want to give read access to .fleet-artifacts index to non admin users, these users having developer role. I have given the permission but i am getting following error when i try to access via api. "type": "security\_ex…

---

## ["How to Create Index and Search with Azerbaijani Character Normalization in Elasticsearch?"](https://discuss.elastic.co/t/how-to-create-index-and-search-with-azerbaijani-character-normalization-in-elasticsearch/366594)

<div class="topic-metadata">

**Author:** [@karim\_mirzaguliyev](https://discuss.elastic.co/u/karim_mirzaguliyev)\
**Replies:** 0\
**Last updated:** [September 15, 2024, 9:17pm UTC](https://discuss.elastic.co/t/how-to-create-index-and-search-with-azerbaijani-character-normalization-in-elasticsearch/366594 "2024-09-15T21:17:57Z")

</div>

Hello Elasticsearch community, I am working on an Elasticsearch implementation to support searches in Azerbaijani, where users can input transliterated versions of words (e.g., "sixmemmedov") and still match documents c…

---

## [Base64 in WrapperBuilder. co.elastic.clients](https://discuss.elastic.co/t/base64-in-wrapperbuilder-co-elastic-clients/365930)

<div class="topic-metadata">

**Author:** [@S\_R](https://discuss.elastic.co/u/S_R)\
**Replies:** 2\
**Last updated:** [September 14, 2024, 11:38am UTC](https://discuss.elastic.co/t/base64-in-wrapperbuilder-co-elastic-clients/365930 "2024-09-14T11:38:22Z")

</div>

Hi Community, I encountered strange behavior with a new Elasticsearch Java client. Before, I used org.elasticsearch:elasticsearch:7:8:1 WrapperQueryBuilder wrapperQueryBuilder = new WrapperQueryBuilder("string") to g…

---

## [Error in fleet-server, kibana, elastic search](https://discuss.elastic.co/t/error-in-fleet-server-kibana-elastic-search/366362)

<div class="topic-metadata">

**Author:** [@soularius](https://discuss.elastic.co/u/soularius)\
**Replies:** 13\
**Last updated:** [September 14, 2024, 7:49am UTC](https://discuss.elastic.co/t/error-in-fleet-server-kibana-elastic-search/366362 "2024-09-14T07:49:40Z")

</div>

Issue when trying to connect Fleet Server with Elasticsearch in Docker I am setting up an Elastic Stack environment in Docker, including containers for Elasticsearch, Kibana, and Elastic Agent with Fleet Server enabled.…

---

## [Restore Snapshot from Deployment-A to Deployment-B](https://discuss.elastic.co/t/restore-snapshot-from-deployment-a-to-deployment-b/362044)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 7\
**Last updated:** [September 13, 2024, 3:24pm UTC](https://discuss.elastic.co/t/restore-snapshot-from-deployment-a-to-deployment-b/362044 "2024-09-13T15:24:44Z")

</div>

Hi there. In Elastic Cloud, I'm trying to do the following: From my local server (I want to automate it): issue a curl call of the Elastic API that tells Deployment-A to create a snapshot then issue a curl call of th…

---

## [Issues encountered for zip files](https://discuss.elastic.co/t/issues-encountered-for-zip-files/365071)

<div class="topic-metadata">

**Author:** [@saifstech26](https://discuss.elastic.co/u/saifstech26)\
**Replies:** 2\
**Last updated:** [September 13, 2024, 2:04pm UTC](https://discuss.elastic.co/t/issues-encountered-for-zip-files/365071 "2024-09-13T14:04:03Z")

</div>

Hi @dadoonet, I have come up with an issue of zip files. My config is pretty straight forward. --- name: "test" fs: url: "\<LOCAL\_PATH\_OF\_DOC\_FOLDER\>" update\_rate: "15h" excludes: - "\*/~\*" - "\*.zip/\*.html" …

---

## [\_geo\_distance sort always returning Infinity](https://discuss.elastic.co/t/geo-distance-sort-always-returning-infinity/366523)

<div class="topic-metadata">

**Author:** [@sircameron](https://discuss.elastic.co/u/sircameron)\
**Replies:** 5\
**Last updated:** [September 13, 2024, 2:00pm UTC](https://discuss.elastic.co/t/geo-distance-sort-always-returning-infinity/366523 "2024-09-13T14:00:31Z")

</div>

I have an index: { index: 'discoveries', mappings: { properties: { id: { type: 'integer' }, description: { type: 'text' }, location: { type: 'geo\_point' }, }, …

---

## [Ignore stopwords inside double quotes](https://discuss.elastic.co/t/ignore-stopwords-inside-double-quotes/366496)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 3\
**Last updated:** [September 13, 2024, 1:41pm UTC](https://discuss.elastic.co/t/ignore-stopwords-inside-double-quotes/366496 "2024-09-13T13:41:09Z")

</div>

I am using the standard stopwords file for my index. But I would like to NOT remove stopwords when they are within double quotes, since that is exactly what the user is searching for. For example, if someone searches "…

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=76)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=78)
