# How can I clear "keyword" entries that have no documents?

**URL:** <https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537>\
**Category:** Elasticsearch\
**Created:** [November 9, 2022, 11:42am UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537 "2022-11-09T11:42:51Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [November 9, 2022, 11:42am UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/1 "2022-11-09T11:42:51Z")

</div>

I accidentally indexed a document with a wrong text/keyword field. I later removed the document, but the keyword is still there.

For instance, when I run the query:

```auto
GET _search
{
  "size": 0,
  "aggs": {
    "group_by_foo": {
      "terms": {
        "field": "foo.keyword",
        "size": 500,
        "min_doc_count": 0
      }
    }
  }
}

```

I get results with the wrong keyword and a doc count of 0:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95ec19f092085874f89eae9cd9c56b35e99cda56.png)

How can I remove these incorrect entries altogether, such that this query will not return the wrong keyword?

---

<div class="post-metadata">

**Author:** ![TimBosman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timbosman/32/84120_2.png) [@TimBosman](https://discuss.elastic.co/u/TimBosman)\
**Post date:** [November 9, 2022, 1:01pm UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/2 "2022-11-09T13:01:13Z")

</div>

Hey Werner,

Using a min\_doc\_count of 1 should solve the problem

Tim

---

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [November 9, 2022, 1:13pm UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/3 "2022-11-09T13:13:15Z")

</div>

Thanks for the suggestion. I should have clarified that this is not the solution I need. Later, I want to filter the query by a certain time range, and I will have to include results with a doc count of 0 here.

For instance, assume the field is a server hostname, and it sends a heartbeat every 10 minutes. I want to find out whether a server is down by checking whether the sum of heartbeats for each hostname is 0 or not, within a certain time interval. So I need the results where the doc count is 0, and all hostnames that actually exist should be included in the aggregation.

---

<div class="post-metadata">

**Author:** ![TimBosman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timbosman/32/84120_2.png) [@TimBosman](https://discuss.elastic.co/u/TimBosman)\
**Post date:** [November 9, 2022, 1:42pm UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/4 "2022-11-09T13:42:48Z")

</div>

Hey Werner,

That makes sense. This blog describes how Lucene and Elasticsearch handle document deletions. [Lucene's Handling of Deleted Documents | Elastic Blog](https://www.elastic.co/blog/lucenes-handling-of-deleted-documents) . The phenomenon you are observing is called "ghost terms".

I hope this helps

---

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [November 9, 2022, 2:06pm UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/5 "2022-11-09T14:06:32Z")

</div>

Thanks, I see what the underlying issue is, and I am aware that this might have performance impacts. Probably it will be a one-time operation to clean up the index.

What I don't directly see from the linked post is what I can do now, if anything at all. The blog post references a deprecated optimize API for Elasticsearch 1.x that doesn't exist anymore.

Do I understand correctly that the [force merge](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-forcemerge.html) action will achieve what I need? In particular, am I correctly understanding that I need to set `only_expunge_deletes` to `true`?

---

<div class="post-metadata">

**Author:** ![TimBosman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timbosman/32/84120_2.png) [@TimBosman](https://discuss.elastic.co/u/TimBosman)\
**Post date:** [November 9, 2022, 3:09pm UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/6 "2022-11-09T15:09:06Z")

</div>

This depends on what you still want to do with your index. Force merging is only recommended for read-only indices (See the warning Box on the Force merge page). If you still want to write/update in the index, you could wait for a merge. Otherwise you could rollover (in case of a data stream) and force merge the index then.

---

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [November 9, 2022, 3:11pm UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/7 "2022-11-09T15:11:27Z")

</div>

I could set it to read-only for as long as it force-merges, and then allow writes again, so I think this should be the solution.

---

<div class="post-metadata">

**Author:** ![wrobitza\_aveq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrobitza_aveq/32/105113_2.png) [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Post date:** [November 16, 2022, 10:45am UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/8 "2022-11-16T10:45:21Z")

</div>

Interesting. I didn't do anything and the field disappeared. Could it be that Elasticsearch automatically cleans up these keywords? (I have not configured anything special for this index.)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2022, 10:46am UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537/9 "2022-12-14T10:46:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
