We recently upgraded our ELK stack from 5.6.6. to 6.2.3
In 5.6.6 with the _all field enabled if a user didn't specify a field, the query would hit the _all field and get the results
In 6.2.3 with the _all field disabled, if a user doesn't specify a field, elasticsearch looks at all the fields. This results in a significant increase in query time and search thread pools being more saturated.
Has anyone faced a similar issue?
Is these a way to block searches where a key field is not specified?