# 2.x change to 6.x agg bug or not，what can i do？

**URL:** <https://discuss.elastic.co/t/2-x-change-to-6-x-agg-bug-or-not-what-can-i-do/248793>\
**Category:** Elasticsearch\
**Created:** [September 16, 2020, 8:39am UTC](https://discuss.elastic.co/t/2-x-change-to-6-x-agg-bug-or-not-what-can-i-do/248793 "2020-09-16T08:39:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CSuperC](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@CSuperC](https://discuss.elastic.co/u/CSuperC)\
**Post date:** [September 16, 2020, 8:39am UTC](https://discuss.elastic.co/t/2-x-change-to-6-x-agg-bug-or-not-what-can-i-do/248793/1 "2020-09-16T08:39:44Z")

</div>

our 2.x agg very good，bug agg 6.x is worst  
one day 3kw logs，then agg logs by a,b,c,d, very well in 2.x，when use in 6.x ，server is bad ，out of memery  
2.x and 6.x java heap is almost the same ，6.x is more heap  
one day in 2.x index size is 50GB，but 100GB in 6.x，is it the reason，when 6.x go down？，if this is the question ，what can i do to decrease the index in 6.x version 6.7.1 version 2.4.5

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [September 16, 2020, 9:06am UTC](https://discuss.elastic.co/t/2-x-change-to-6-x-agg-bug-or-not-what-can-i-do/248793/2 "2020-09-16T09:06:18Z")

</div>

You should try with 7.x.  
6.x is already very different from 2.x so that might explain what you are seeing, specifically in term of disk space.  
Keyword datatype now uses `doc_values` (on disk) instead of `fielddata` (on memory).

If you need help, you need to share more about what you are doing. Like a typical query and a typical response from elasticsearch.

---

<div class="post-metadata">

**Author:** ![CSuperC](https://avatars.discourse-cdn.com/v4/letter/c/dec6dc/32.png) [@CSuperC](https://discuss.elastic.co/u/CSuperC)\
**Post date:** [September 16, 2020, 9:28am UTC](https://discuss.elastic.co/t/2-x-change-to-6-x-agg-bug-or-not-what-can-i-do/248793/3 "2020-09-16T09:28:53Z")

</div>

thank you very much for you first reply ,i will write more info,you say,  
Keyword datatype now uses `doc_values` (on disk) instead of `fielddata` (on memory).  
but i look in 2.x docs, text ( not\_analyzed) use doc\_values the same

> **[String datatype | Elasticsearch Reference \[2.4\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/string.html#string)**

  
,i can give template,template is here in 2.x  
{  
"order": 0,  
"template": "user\_active\__",  
"settings": {  
"index": {  
"number\_of\_replicas": "1",  
"number\_of\_shards": "5",  
"refresh\_interval": "120s"  
}  
},  
"mappings": {  
"default": {  
"all": {  
"enabled": false  
}  
},  
"user\_active\_detail": {  
"date\_detection": false,  
"properties": {  
"result": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"systemName": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"sourcePort": {  
"type": "integer"  
},  
"destIp": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"endTime": {  
"type": "long"  
},  
"business": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"id": {  
"type": "string"  
},  
"cardNo": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"response": {  
"ignore\_above": 256,  
"analyzer": "ik\_max\_word",  
"type": "string"  
},  
"time": {  
"type": "long"  
},  
"networkCode": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"responseType": {  
"type": "string"  
},  
"keyWords": {  
"ignore\_above": 256,  
"analyzer": "ik\_smart",  
"type": "string"  
},  
"systemId": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"networkName": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"responseTime": {  
"type": "long"  
},  
"module": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"policeId": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"sn": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"terminalIp": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"requestId": {  
"type": "string"  
},  
"extend": {  
"type": "nested"  
},  
"imei": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"params": {  
"analyzer": "ik\_max\_word",  
"type": "string"  
},  
"uri": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"url": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"content": {  
"index": "not\_analyzed",  
"ignore\_above": 256,  
"type": "string"  
},  
"errorLog": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"source": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"sessionId": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"errorCode": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"sourceIp": {  
"index": "not\_analyzed",  
"type": "string"  
},  
"bizType": {  
"type": "string"  
},  
"formatParam": {  
"index": "not\_analyzed",  
"ignore\_above": 256,  
"type": "string"  
},  
"destPort": {  
"type": "integer"  
},  
"logType": {  
"index": "not\_analyzed",  
"type": "string"  
}  
}  
}  
},  
"aliases": {  
"user-active": {}  
}  
}  
and 6.x tempalte  
{  
"index\_patterns": "user\_active_",  
"settings": {  
"index": {  
"number\_of\_shards": "5",  
"number\_of\_replicas": "1",  
"refresh\_interval": "120s"  
}  
},  
"mappings": {  
"_default_": {  
"\_all": {  
"enabled": false  
}  
},  
"user\_active\_detail": {  
"date\_detection": false,  
"properties": {  
"destIp": {  
"type": "keyword"  
},  
"logType": {  
"type": "keyword"  
},  
"policeId": {  
"type": "keyword"  
},  
"sourcePort": {  
"type": "integer"  
},  
"formatParam": {  
"ignore\_above": 256,  
"type": "keyword"  
},  
"bizType": {  
"type": "keyword"  
},  
"networkName": {  
"type": "keyword"  
},  
"errorCode": {  
"type": "keyword"  
},  
"source": {  
"type": "keyword"  
},  
"cardNo": {  
"type": "keyword"  
},  
"content": {  
"ignore\_above": 256,  
"type": "keyword"  
},  
"result": {  
"type": "keyword"  
},  
"responseType": {  
"type": "keyword"  
},  
"destPort": {  
"type": "integer"  
},  
"systemName": {  
"type": "keyword"  
},  
"requestId": {  
"type": "keyword"  
},  
"id": {  
"type": "keyword"  
},  
"sn": {  
"type": "keyword"  
},  
"keyWords": {  
"analyzer": "ik\_smart",  
"type": "text"  
},  
"systemId": {  
"type": "keyword"  
},  
"responseTime": {  
"type": "long"  
},  
"module": {  
"type": "keyword"  
},  
"errorLog": {  
"type": "keyword"  
},  
"sessionId": {  
"type": "keyword"  
},  
"params": {  
"analyzer": "ik\_max\_word",  
"type": "text"  
},  
"uri": {  
"type": "keyword"  
},  
"url": {  
"type": "keyword"  
},  
"sourceIp": {  
"type": "keyword"  
},  
"response": {  
"analyzer": "ik\_max\_word",  
"type": "text"  
},  
"networkCode": {  
"type": "keyword"  
},  
"endTime": {  
"type": "long"  
},  
"time": {  
"type": "long"  
},  
"terminalIp": {  
"type": "keyword"  
},  
"business": {  
"type": "keyword"  
},  
"imei": {  
"type": "keyword"  
},  
"extend": {  
"type": "nested"  
}  
}  
}  
},  
"aliases": {  
"user\_active\_detail": {}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 9:28am UTC](https://discuss.elastic.co/t/2-x-change-to-6-x-agg-bug-or-not-what-can-i-do/248793/4 "2020-10-14T09:28:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
