# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=84

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 85

---

## [How to get documents added as-is due to fields with dot in them?](https://discuss.elastic.co/t/how-to-get-documents-added-as-is-due-to-fields-with-dot-in-them/365165)

<div class="topic-metadata">

**Author:** [@Michael\_Carter](https://discuss.elastic.co/u/Michael_Carter)\
**Replies:** 5\
**Last updated:** [August 20, 2024, 12:33pm UTC](https://discuss.elastic.co/t/how-to-get-documents-added-as-is-due-to-fields-with-dot-in-them/365165 "2024-08-20T12:33:51Z")

</div>

So basically I've got this json file being generated by a system that didn't know how to write json files. Here's the example of my problem: {"snapshot.updated\_by.uid": "mcarter", "snapshot.updated\_by": "michael cart…

---

## [Why metricbeat-7.2.0 indexes are created](https://discuss.elastic.co/t/why-metricbeat-7-2-0-indexes-are-created/365128)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 3\
**Last updated:** [August 20, 2024, 11:20am UTC](https://discuss.elastic.co/t/why-metricbeat-7-2-0-indexes-are-created/365128 "2024-08-20T11:20:03Z")

</div>

Hey, can anybody tell me. Why these indexes are created automatically.. Are they really important, Can I delete them metricbeat-7.2.0-2023.08.28-000002 0 p STARTED 52673106 15.7gb 10.222.21.245 node-2 metricb…

---

## [.NET client suggest query issue](https://discuss.elastic.co/t/net-client-suggest-query-issue/365061)

<div class="topic-metadata">

**Author:** [@jahedi](https://discuss.elastic.co/u/jahedi)\
**Replies:** 5\
**Last updated:** [August 20, 2024, 11:06am UTC](https://discuss.elastic.co/t/net-client-suggest-query-issue/365061 "2024-08-20T11:06:48Z")

</div>

Hi, I had an issue using new .NET client v8. I used to use v7 client (NEST) but recently decided to migrate to v8 client. let me explain my issue in details. I have an index with this mappings: { "mappings": { …

---

## [Elastic 8.15.0 missing InlineScript](https://discuss.elastic.co/t/elastic-8-15-0-missing-inlinescript/364824)

<div class="topic-metadata">

**Author:** [@p4paul](https://discuss.elastic.co/u/p4paul)\
**Replies:** 5\
**Last updated:** [August 20, 2024, 10:40am UTC](https://discuss.elastic.co/t/elastic-8-15-0-missing-inlinescript/364824 "2024-08-20T10:40:51Z")

</div>

It seems that co.elastic.clients.elasticsearch.\_types.InlineScript has been removed from 8.15.0 (exists in 8.14.3)? Is this intended? If so how do I migrate existing code? InlineScript inlineScript = InlineScript.of…

---

## [Uploading models to elasticsearch](https://discuss.elastic.co/t/uploading-models-to-elasticsearch/365185)

<div class="topic-metadata">

**Author:** [@devashishpawar](https://discuss.elastic.co/u/devashishpawar)\
**Replies:** 1\
**Last updated:** [August 20, 2024, 10:39am UTC](https://discuss.elastic.co/t/uploading-models-to-elasticsearch/365185 "2024-08-20T10:39:22Z")

</div>

Hey there, I am looking for a way to upload trained models to self hosted elasticsearch clusters. I am aware we do have a LTR plugin for uploading the XGBoost models but is there any other way to do that? Or will these …

---

## [ElasticSearch Java Client FunctionScoreQuery score mismatch with Console score](https://discuss.elastic.co/t/elasticsearch-java-client-functionscorequery-score-mismatch-with-console-score/365081)

<div class="topic-metadata">

**Author:** [@mantegna](https://discuss.elastic.co/u/mantegna)\
**Replies:** 1\
**Last updated:** [August 20, 2024, 9:58am UTC](https://discuss.elastic.co/t/elasticsearch-java-client-functionscorequery-score-mismatch-with-console-score/365081 "2024-08-20T09:58:56Z")

</div>

Consider I have the following function score query with an idea to find all animals by tags, and score them by mustHaveTags occurances: POST /animals/\_search { "size": 10, "query": { "function\_score": { "q…

---

## [How many nodes are required for 10 TB of data?](https://discuss.elastic.co/t/how-many-nodes-are-required-for-10-tb-of-data/365133)

<div class="topic-metadata">

**Author:** [@AnushreeRaikar](https://discuss.elastic.co/u/AnushreeRaikar)\
**Replies:** 14\
**Last updated:** [August 20, 2024, 9:48am UTC](https://discuss.elastic.co/t/how-many-nodes-are-required-for-10-tb-of-data/365133 "2024-08-20T09:48:59Z")

</div>

Data Size: 6.8 TB Monthly Increase: 150 GB Time Period: 18 months Calculation: Total Increase in Data: Total Increase=150GB/month×18months=2700GB=2.7TB Total Data Size After 18 Months: Final Data Size=6.8TB+2.7TB=…

---

## [NotFoundError](https://discuss.elastic.co/t/notfounderror/365150)

<div class="topic-metadata">

**Author:** [@dsagent](https://discuss.elastic.co/u/dsagent)\
**Replies:** 11\
**Last updated:** [August 19, 2024, 6:35pm UTC](https://discuss.elastic.co/t/notfounderror/365150 "2024-08-19T18:35:49Z")

</div>

Hi, I have alias in which a number of index are associated When I want to update documents using alias it returns this error to me From Update Method-\> NotFoundError(404, 'document missing exception', '\[ks5N 44B1PKbf…

---

## [ELK Snaspshots are not getting listed](https://discuss.elastic.co/t/elk-snaspshots-are-not-getting-listed/365102)

<div class="topic-metadata">

**Author:** [@Nijal](https://discuss.elastic.co/u/Nijal)\
**Replies:** 5\
**Last updated:** [August 19, 2024, 10:59am UTC](https://discuss.elastic.co/t/elk-snaspshots-are-not-getting-listed/365102 "2024-08-19T10:59:30Z")

</div>

I am using the below approach to backup/restore elasticsearch data Snapshot the data to Shared File system Repo. Before copying the contents, I made the repository read only , so no more data will be written to it. Cop…

---

## [Corrupted Drive](https://discuss.elastic.co/t/corrupted-drive/365122)

<div class="topic-metadata">

**Author:** [@LucasKH](https://discuss.elastic.co/u/LucasKH)\
**Replies:** 1\
**Last updated:** [August 19, 2024, 9:11am UTC](https://discuss.elastic.co/t/corrupted-drive/365122 "2024-08-19T09:11:31Z")

</div>

Hello, I have set up a POC for Elastic Stack and it has been gathering logs for ~1-2 months in smaller volumes. However, one day the service has stopped and upon connecting to the server I was faced with the following e…

---

## [Recreate index, error 'resource\_already\_exists\_exception'](https://discuss.elastic.co/t/recreate-index-error-resource-already-exists-exception/365105)

<div class="topic-metadata">

**Author:** [@LiJie20190102](https://discuss.elastic.co/u/LiJie20190102)\
**Replies:** 4\
**Last updated:** [August 19, 2024, 7:36am UTC](https://discuss.elastic.co/t/recreate-index-error-resource-already-exists-exception/365105 "2024-08-19T07:36:40Z")

</div>

My goal is to quickly clear the index, but I found that the 'delete-by\_query' courier is slow, so I plan to delete it first and then create a new index like before, but I find that errors often occur：

---

## [Elasticsearch error :missing authentication credentials for REST request](https://discuss.elastic.co/t/elasticsearch-error-missing-authentication-credentials-for-rest-request/364941)

<div class="topic-metadata">

**Author:** [@Frank23](https://discuss.elastic.co/u/Frank23)\
**Replies:** 1\
**Last updated:** [August 19, 2024, 3:24am UTC](https://discuss.elastic.co/t/elasticsearch-error-missing-authentication-credentials-for-rest-request/364941 "2024-08-19T03:24:26Z")

</div>

I installed version 8.11.1 of elasticsearch in the domain server. After the local configuration is complete, the web page can be opened normally. But when you try to open a web page in an external browser, you are promp…

---

## [Access event fields for connector action](https://discuss.elastic.co/t/access-event-fields-for-connector-action/365097)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [August 19, 2024, 2:25am UTC](https://discuss.elastic.co/t/access-event-fields-for-connector-action/365097 "2024-08-19T02:25:50Z")

</div>

Hi, I am trying to create an alert which utilises the index connector. The connector works fine and writes to the index, however I have been unable to populate any data from the event itself. What I want is something …

---

## [How Can I Efficiently Use Elasticsearch for Location-Based Searches with a Focus on Qibla Direction Online Tools?](https://discuss.elastic.co/t/how-can-i-efficiently-use-elasticsearch-for-location-based-searches-with-a-focus-on-qibla-direction-online-tools/365087)

<div class="topic-metadata">

**Author:** [@HilaireDenise](https://discuss.elastic.co/u/HilaireDenise)\
**Replies:** 1\
**Last updated:** [August 18, 2024, 7:00pm UTC](https://discuss.elastic.co/t/how-can-i-efficiently-use-elasticsearch-for-location-based-searches-with-a-focus-on-qibla-direction-online-tools/365087 "2024-08-18T19:00:30Z")

</div>

I’ve been using Elasticsearch for a while now, mainly for various search-related tasks, and I recently came across the need to perform location-based searches. Specifically, I’m curious about how Elasticsearch handles ge…

---

## [HTTPS config for Elasticsearch](https://discuss.elastic.co/t/https-config-for-elasticsearch/365073)

<div class="topic-metadata">

**Author:** [@BrainFried](https://discuss.elastic.co/u/BrainFried)\
**Replies:** 13\
**Last updated:** [August 18, 2024, 6:51pm UTC](https://discuss.elastic.co/t/https-config-for-elasticsearch/365073 "2024-08-18T18:51:15Z")

</div>

I've been stuck for a few days tying to enable HTTPS for public access from my elasticsearch javascript client. My elasticsearch server is running on the host machine. The server is only reachable using HTTP: curl -k -…

---

## [How can I make fields in Elasticsearch v8 match v7?](https://discuss.elastic.co/t/how-can-i-make-fields-in-elasticsearch-v8-match-v7/365025)

<div class="topic-metadata">

**Author:** [@acarrazzoni-qontigo](https://discuss.elastic.co/u/acarrazzoni-qontigo)\
**Replies:** 1\
**Last updated:** [August 16, 2024, 8:48pm UTC](https://discuss.elastic.co/t/how-can-i-make-fields-in-elasticsearch-v8-match-v7/365025 "2024-08-16T20:48:01Z")

</div>

I have a Elasticsearch environment I use for logging that I'm updating from v7 to v8 and I noticed that when I look at the logs in Kibana every field that has a name that ends with .keyword in v7 now has a name that ends…

---

## [How to free up write thread queues](https://discuss.elastic.co/t/how-to-free-up-write-thread-queues/364981)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [August 16, 2024, 4:56pm UTC](https://discuss.elastic.co/t/how-to-free-up-write-thread-queues/364981 "2024-08-16T16:56:36Z")

</div>

Hello, How do we free or flush the threadpool write queue in Elastic?

---

## [Failed to get the temporary directory; falling back to: /tmp \[2022-09-23T20:38:58,847\]\[ERROR\]\[o.e.b.Elasticsearch      \] \[elastic\] fatal exception while booting Elasticsearch java.security.AccessControlException: access denied ("java.io.FilePermission" "/](https://discuss.elastic.co/t/failed-to-get-the-temporary-directory-falling-back-to-tmp-2022-09-23t2058-847-error-o-e-b-elasticsearch-elastic-fatal-exception-while-booting-elasticsearch-java-security-accesscontrolexception-access-denied-java-io-filepermission/365041)

<div class="topic-metadata">

**Author:** [@sarathrock](https://discuss.elastic.co/u/sarathrock)\
**Replies:** 1\
**Last updated:** [August 16, 2024, 4:36pm UTC](https://discuss.elastic.co/t/failed-to-get-the-temporary-directory-falling-back-to-tmp-2022-09-23t2058-847-error-o-e-b-elasticsearch-elastic-fatal-exception-while-booting-elasticsearch-java-security-accesscontrolexception-access-denied-java-io-filepermission/365041 "2024-08-16T16:36:06Z")

</div>

Failed to get the temporary directory; falling back to: /tmp \[2022-09-23T20:38:58,847\]\[ERROR\]\[o.e.b.Elasticsearch \] \[elastic\] fatal exception while booting Elasticsearch java.security.AccessControlException: acces…

---

## [Apm-server not getting connected to kibana. Using v 7.17.1 for all](https://discuss.elastic.co/t/apm-server-not-getting-connected-to-kibana-using-v-7-17-1-for-all/364888)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 2\
**Last updated:** [August 16, 2024, 11:24am UTC](https://discuss.elastic.co/t/apm-server-not-getting-connected-to-kibana-using-v-7-17-1-for-all/364888 "2024-08-16T11:24:42Z")

</div>

Hi all, issue is cant see index here http://127.0.0.1:9200/\_cat/indices ------------docker-compose file--------------- version: '3' services: elasticsearch: container\_name: elasticsearch image: docker.elastic.co/e…

---

## [Elastic Search is giving same score for all parent document which has nested documents](https://discuss.elastic.co/t/elastic-search-is-giving-same-score-for-all-parent-document-which-has-nested-documents/364931)

<div class="topic-metadata">

**Author:** [@Santanu112](https://discuss.elastic.co/u/Santanu112)\
**Replies:** 2\
**Last updated:** [August 15, 2024, 8:24pm UTC](https://discuss.elastic.co/t/elastic-search-is-giving-same-score-for-all-parent-document-which-has-nested-documents/364931 "2024-08-15T20:24:27Z")

</div>

I am trying elstic search query and all my search results is showing same \_score. For that i am not getting the appropriate result. GET my\_index/\_search { "from": 0, "size": 10, "query": { "bool": { "mu…

---

## [License clarification](https://discuss.elastic.co/t/license-clarification/364934)

<div class="topic-metadata">

**Author:** [@elastic\_noob1](https://discuss.elastic.co/u/elastic_noob1)\
**Replies:** 4\
**Last updated:** [August 15, 2024, 8:14pm UTC](https://discuss.elastic.co/t/license-clarification/364934 "2024-08-15T20:14:22Z")

</div>

We have a platinum license that will expire in Oct 2024. We are running 6.8 and plan to upgrade to 7.17. This upgrade will be a 2 step process: 6.8 \> 7.3 \> 7.17 I upgraded from 6.8 to 7.3 with the platinum license. I de…

---

## [Remote Monitoring Cluster - No Monitoring Data Found](https://discuss.elastic.co/t/remote-monitoring-cluster-no-monitoring-data-found/364976)

<div class="topic-metadata">

**Author:** [@axvfvv79zcx57xv7k](https://discuss.elastic.co/u/axvfvv79zcx57xv7k)\
**Replies:** 0\
**Last updated:** [August 15, 2024, 4:45pm UTC](https://discuss.elastic.co/t/remote-monitoring-cluster-no-monitoring-data-found/364976 "2024-08-15T16:45:06Z")

</div>

Hey there, I'm currently trying to set up a remote monitoring cluster for my production cluster using Elastic Agent and Fleet. I am using the Elasticsearch integration with my agent, which is installed on my production …

---

## [Learning resources for ES Java client](https://discuss.elastic.co/t/learning-resources-for-es-java-client/364953)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 1\
**Last updated:** [August 15, 2024, 3:45pm UTC](https://discuss.elastic.co/t/learning-resources-for-es-java-client/364953 "2024-08-15T15:45:50Z")

</div>

Do you know any resources (other than official documentation) for learning Java client for ES?

---

## [Optimal Cluster for Production](https://discuss.elastic.co/t/optimal-cluster-for-production/364618)

<div class="topic-metadata">

**Author:** [@fatima1](https://discuss.elastic.co/u/fatima1)\
**Replies:** 6\
**Last updated:** [August 15, 2024, 2:53pm UTC](https://discuss.elastic.co/t/optimal-cluster-for-production/364618 "2024-08-15T14:53:17Z")

</div>

I am overseeing a production cluster consisting of approximately 83 nodes, and we are handling nearly a million of data points daily . To optimize the production environment, what are the recommended best practices regar…

---

## [How can I delete a document when it is X month old?](https://discuss.elastic.co/t/how-can-i-delete-a-document-when-it-is-x-month-old/364958)

<div class="topic-metadata">

**Author:** [@Arkapravo\_Das](https://discuss.elastic.co/u/Arkapravo_Das)\
**Replies:** 1\
**Last updated:** [August 15, 2024, 2:40pm UTC](https://discuss.elastic.co/t/how-can-i-delete-a-document-when-it-is-x-month-old/364958 "2024-08-15T14:40:57Z")

</div>

I have an index and document gets added to that index everyday ,lets say with a frequency of 10,000 daily. I want to delete the documents which are 5 month old from that index and want to run this deletion process daily …

---

## [What means a hits.total.value of -1](https://discuss.elastic.co/t/what-means-a-hits-total-value-of-1/364961)

<div class="topic-metadata">

**Author:** [@Voidi](https://discuss.elastic.co/u/Voidi)\
**Replies:** 0\
**Last updated:** [August 15, 2024, 2:14pm UTC](https://discuss.elastic.co/t/what-means-a-hits-total-value-of-1/364961 "2024-08-15T14:14:05Z")

</div>

When hits.total.value is 0 there are no matching documents for the query ( in my case a simple multi\_match query over a three text fields with Fuzziness.AUTO). But what does it mean if hits.total.value is -1?

---

## [Retrieve length of array which is part of object present in map](https://discuss.elastic.co/t/retrieve-length-of-array-which-is-part-of-object-present-in-map/364960)

<div class="topic-metadata">

**Author:** [@Abhi1984](https://discuss.elastic.co/u/Abhi1984)\
**Replies:** 0\
**Last updated:** [August 15, 2024, 2:12pm UTC](https://discuss.elastic.co/t/retrieve-length-of-array-which-is-part-of-object-present-in-map/364960 "2024-08-15T14:12:00Z")

</div>

Hi, I'm need to write a query which provides the length of array fields inside an object which is stored as value in a map. E.g. { "id":1, "data": { { "2023": { "array1" : \["A","B"\], "array2" : \["A","B","C"\] "a…

---

## [Behaviour of elastic when using EBS snapshotted data in kubernetes](https://discuss.elastic.co/t/behaviour-of-elastic-when-using-ebs-snapshotted-data-in-kubernetes/364949)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 4\
**Last updated:** [August 15, 2024, 11:40am UTC](https://discuss.elastic.co/t/behaviour-of-elastic-when-using-ebs-snapshotted-data-in-kubernetes/364949 "2024-08-15T11:40:41Z")

</div>

We are running elastic on a kubernetes cluster in AWS. We have created a volume snapshot of elastic pvcs using the amazon volume snapshotting method: There are 7 nodes in the cluster running in kubernetes. Each node is…

---

## ["kubectl patch" on Elastic ECK](https://discuss.elastic.co/t/kubectl-patch-on-elastic-eck/364950)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 0\
**Last updated:** [August 15, 2024, 11:38am UTC](https://discuss.elastic.co/t/kubectl-patch-on-elastic-eck/364950 "2024-08-15T11:38:31Z")

</div>

HHello everyone, I noticed something I cannot explain: I deploy Elasticsearch (following the quickstart guide) with the DeleteOnScaledownAndClusterDeletion policy. Then I patch the policy to DeleteOnScaledownOnly and …

---

## [Query Terms limit error](https://discuss.elastic.co/t/query-terms-limit-error/364948)

<div class="topic-metadata">

**Author:** [@cahl](https://discuss.elastic.co/u/cahl)\
**Replies:** 0\
**Last updated:** [August 15, 2024, 10:28am UTC](https://discuss.elastic.co/t/query-terms-limit-error/364948 "2024-08-15T10:28:56Z")

</div>

I read the terms is limited to around 65k on the default config. However, I am trying to make a query with around 2k values in the terms and it is failing. I notice if I use 665 works fine but if I add an extra value it …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=83)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=85)
