# \#elastic-stack-sql

**URL:** https://discuss.elastic.co/tag/elastic-stack-sql/13.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Wildcard phrases with slop using string query](https://discuss.elastic.co/t/wildcard-phrases-with-slop-using-string-query/385418)

<div class="topic-metadata">

**Author:** [@S-Dragon0302](https://discuss.elastic.co/u/S-Dragon0302)\
**Replies:** 1\
**Last updated:** [March 12, 2026, 8:29am UTC](https://discuss.elastic.co/t/wildcard-phrases-with-slop-using-string-query/385418 "2026-03-12T08:29:31Z")

</div>

Is this kind of query still not supported. This won't work. "query\_string": { "fields": \[ "nickname" \], "query": "content:\\"hello\\" AND \\"Rodan Fields?\\"", "default\_operator": "AND" } Writing "slop" like this w…

---

## [Issue with Multi terms aggregation with Boolean field](https://discuss.elastic.co/t/issue-with-multi-terms-aggregation-with-boolean-field/378585)

<div class="topic-metadata">

**Author:** [@bsehra](https://discuss.elastic.co/u/bsehra)\
**Replies:** 15\
**Last updated:** [June 5, 2025, 9:04am UTC](https://discuss.elastic.co/t/issue-with-multi-terms-aggregation-with-boolean-field/378585 "2025-06-05T09:04:45Z")

</div>

I'm using Elasticsearch server 8.17.3 and Elasticsearch net Client 8.17.3. Looks like there is an issue with Elasticsearch resolving the multi terms aggregation involving a boolean field. I get below error where as I'm o…

---

## [Search with multi-values](https://discuss.elastic.co/t/search-with-multi-values/372013)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [December 16, 2024, 9:58am UTC](https://discuss.elastic.co/t/search-with-multi-values/372013 "2024-12-16T09:58:17Z")

</div>

Hi, Is it possible to search with multiple values ? i have a list of words or group of words like \["John","command n345","Paris, France","Destination"\]. and I want to search an items contains with these values, not mu…

---

## [Is it possible to using \_id in elasticsearch sql](https://discuss.elastic.co/t/is-it-possible-to-using-id-in-elasticsearch-sql/369859)

<div class="topic-metadata">

**Author:** [@jimmy0](https://discuss.elastic.co/u/jimmy0)\
**Replies:** 4\
**Last updated:** [November 18, 2024, 1:35am UTC](https://discuss.elastic.co/t/is-it-possible-to-using-id-in-elasticsearch-sql/369859 "2024-11-18T01:35:31Z")

</div>

When i use \_id in a elasticsearch sql， GET /\_sql { "query": """ select \* from question where \_id='RzSIwnABg0jflGUtAmBx' """ } i get an error. { "error": { "root\_cause": \[ { "type": "verificat…

---

## [Running 3 queries in logstash](https://discuss.elastic.co/t/running-3-queries-in-logstash/370304)

<div class="topic-metadata">

**Author:** [@Santanu112](https://discuss.elastic.co/u/Santanu112)\
**Replies:** 1\
**Last updated:** [November 11, 2024, 1:26pm UTC](https://discuss.elastic.co/t/running-3-queries-in-logstash/370304 "2024-11-11T13:26:08Z")

</div>

HI , I want to use below sql queries :slight\_smile: select id form table 1 (it will give millions id) select id, name from table 2 select id , location from table 3 My doc should look like below : { id :1 name : a…

---

## [ES|QL panel doesn't refresh every n seconds](https://discuss.elastic.co/t/es-ql-panel-doesnt-refresh-every-n-seconds/369673)

<div class="topic-metadata">

**Author:** [@edgarmat1964](https://discuss.elastic.co/u/edgarmat1964)\
**Replies:** 3\
**Last updated:** [October 30, 2024, 9:35am UTC](https://discuss.elastic.co/t/es-ql-panel-doesnt-refresh-every-n-seconds/369673 "2024-10-30T09:35:34Z")

</div>

Hello, I'm using ES8.15 and Kibana 8.15 and I've made a dashboard containing a single ES|QL panel which contains this query: FROM myIndex | WHERE message.keyword RLIKE ".\*\[Ee\]\[Rr\]\[Rr\]\[Oo\]\[Rr\].\*" | EVAL Time = date\_form…

---

## [Translate from DSL to SQL](https://discuss.elastic.co/t/translate-from-dsl-to-sql/368999)

<div class="topic-metadata">

**Author:** [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Replies:** 1\
**Last updated:** [October 17, 2024, 2:48pm UTC](https://discuss.elastic.co/t/translate-from-dsl-to-sql/368999 "2024-10-17T14:48:23Z")

</div>

Hi, the sql translate feature converts from SQL --\> DSL. Is there a feature to do the reverse? i.e. convert from DSL to Elastic SQL ? Thanks

---

## [Load json text in oracle table to elastic search via logstash](https://discuss.elastic.co/t/load-json-text-in-oracle-table-to-elastic-search-via-logstash/367208)

<div class="topic-metadata">

**Author:** [@karthikeyanc2003](https://discuss.elastic.co/u/karthikeyanc2003)\
**Replies:** 7\
**Last updated:** [October 5, 2024, 4:32am UTC](https://discuss.elastic.co/t/load-json-text-in-oracle-table-to-elastic-search-via-logstash/367208 "2024-10-05T04:32:16Z")

</div>

Dear Team, I have data in Oracle table Tbl\_user in the below table format. JSON column has the value in the JSON format. I want to insert this data into the Elastic search index with userid as a document ID via logstas…

---

## [How to create read-only user in elastic](https://discuss.elastic.co/t/how-to-create-read-only-user-in-elastic/366749)

<div class="topic-metadata">

**Author:** [@Samantha\_V](https://discuss.elastic.co/u/Samantha_V)\
**Replies:** 4\
**Last updated:** [September 20, 2024, 4:57am UTC](https://discuss.elastic.co/t/how-to-create-read-only-user-in-elastic/366749 "2024-09-20T04:57:57Z")

</div>

Hi Team, there is a requirment to create read-only user for elastic. I tried my best but could not achieve it. I want to start from scratch. Please give me some suggestion how to achieve this.

---

## [Elasticsearch Sql CLI Not working](https://discuss.elastic.co/t/elasticsearch-sql-cli-not-working/365589)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [August 28, 2024, 6:34am UTC](https://discuss.elastic.co/t/elasticsearch-sql-cli-not-working/365589 "2024-08-28T06:34:14Z")

</div>

Hi Team, I am trying to connect elastic sql through below command but not able to connect. \[root@cb-1 bin\]# ./elasticsearch-sql-cli https://xx.xx.xx.xx:9200 ERROR: Cannot communicate with the server https://xx.xx.xx.xx…

---

## [Comparing different methods of rolling back database changes in pytest tests for SQLAlchemy](https://discuss.elastic.co/t/comparing-different-methods-of-rolling-back-database-changes-in-pytest-tests-for-sqlalchemy/364354)

<div class="topic-metadata">

**Author:** [@vivan](https://discuss.elastic.co/u/vivan)\
**Replies:** 1\
**Last updated:** [August 6, 2024, 7:51pm UTC](https://discuss.elastic.co/t/comparing-different-methods-of-rolling-back-database-changes-in-pytest-tests-for-sqlalchemy/364354 "2024-08-06T19:51:37Z")

</div>

I'm working on a project that uses FastAPI and SQL Alchemy asynchronously. I've written pytest tests for this project and have successfully implemented database rollback after each test run. I've found two different im…

---

## [When to support Embeddings\_SQL](https://discuss.elastic.co/t/when-to-support-embeddings-sql/364064)

<div class="topic-metadata">

**Author:** [@trillionmonster](https://discuss.elastic.co/u/trillionmonster)\
**Replies:** 0\
**Last updated:** [July 30, 2024, 2:08pm UTC](https://discuss.elastic.co/t/when-to-support-embeddings-sql/364064 "2024-07-30T14:08:07Z")

</div>

Look at this page : when to support Embeddings\_SQL like this select text, translation(text, 'de', null) 'text (DE)', translation(text, 'es', null) 'text (ES)', translation(text, 'fr', null) 'text (FR)' from txtai whe…

---

## [Paging issues when developing search capabilities using Elasticsearch and MySQL](https://discuss.elastic.co/t/paging-issues-when-developing-search-capabilities-using-elasticsearch-and-mysql/359777)

<div class="topic-metadata">

**Author:** [@jaden](https://discuss.elastic.co/u/jaden)\
**Replies:** 4\
**Last updated:** [May 20, 2024, 6:34am UTC](https://discuss.elastic.co/t/paging-issues-when-developing-search-capabilities-using-elasticsearch-and-mysql/359777 "2024-05-20T06:34:58Z")

</div>

We are developing a search function for space rental products using Elasticsearch and MySQL. \[Search form\] From DateTime To DateTime Min Price Max Price The search form is the same as above, and there is no problem w…

---

## [Avoid duplicate in nested table via logstagh](https://discuss.elastic.co/t/avoid-duplicate-in-nested-table-via-logstagh/359123)

<div class="topic-metadata">

**Author:** [@karthikeyanc2003](https://discuss.elastic.co/u/karthikeyanc2003)\
**Replies:** 1\
**Last updated:** [May 9, 2024, 4:26am UTC](https://discuss.elastic.co/t/avoid-duplicate-in-nested-table-via-logstagh/359123 "2024-05-09T04:26:09Z")

</div>

Can someone please help with mapping when there are more than 1 nested type properties in the aggregate mapping I am seeing a duplicate of data getting created in the document for the nested type properties, when in the…

---

## [Export parent child oracle table in elastic search](https://discuss.elastic.co/t/export-parent-child-oracle-table-in-elastic-search/358651)

<div class="topic-metadata">

**Author:** [@karthikeyanc2003](https://discuss.elastic.co/u/karthikeyanc2003)\
**Replies:** 1\
**Last updated:** [May 2, 2024, 5:35pm UTC](https://discuss.elastic.co/t/export-parent-child-oracle-table-in-elastic-search/358651 "2024-05-02T17:35:13Z")

</div>

Dear Team, I am an RDBMS guy and new to Elastic search. I require your expertise and help on the below requirements, I have the below tables in Oracle. Director & movies Director Name Year of birth Name id Birth …

---

## [Elastic SQL - exclude documents based on nested objects](https://discuss.elastic.co/t/elastic-sql-exclude-documents-based-on-nested-objects/356272)

<div class="topic-metadata">

**Author:** [@elichai](https://discuss.elastic.co/u/elichai)\
**Replies:** 0\
**Last updated:** [March 27, 2024, 11:19am UTC](https://discuss.elastic.co/t/elastic-sql-exclude-documents-based-on-nested-objects/356272 "2024-03-27T11:19:42Z")

</div>

Hi, I need to filter out documents that meet a condition in one of its nested objects. For example, if there is at least one nested object that has a code of 708 the document should not match. However, when I specify "A…

---

## [Unexpected behavior with date fields in Elasticsearch](https://discuss.elastic.co/t/unexpected-behavior-with-date-fields-in-elasticsearch/355527)

<div class="topic-metadata">

**Author:** [@victor\_gonzalez](https://discuss.elastic.co/u/victor_gonzalez)\
**Replies:** 5\
**Last updated:** [March 18, 2024, 10:00pm UTC](https://discuss.elastic.co/t/unexpected-behavior-with-date-fields-in-elasticsearch/355527 "2024-03-18T22:00:42Z")

</div>

I'm encountering an unexpected behavior with date fields in Elasticsearch. After converting date fields to text fields in SQL Server and indexing them in Elasticsearch, we noticed that Elasticsearch seems to adjust the d…

---

## [Trouble Matching nested objects with multi\_match Query Using Wildcards in Elasticsearch](https://discuss.elastic.co/t/trouble-matching-nested-objects-with-multi-match-query-using-wildcards-in-elasticsearch/355513)

<div class="topic-metadata">

**Author:** [@Morzaram](https://discuss.elastic.co/u/Morzaram)\
**Replies:** 1\
**Last updated:** [March 15, 2024, 5:56pm UTC](https://discuss.elastic.co/t/trouble-matching-nested-objects-with-multi-match-query-using-wildcards-in-elasticsearch/355513 "2024-03-15T17:56:53Z")

</div>

Hey everyone, I'm encountering an issue where my documents aren't being matched by a multi\_match query when I include a wildcard with the search string. I'm trying to search across multiple fields, including nested name…

---

## [Getting internal "\_id" field via jdbc](https://discuss.elastic.co/t/getting-internal-id-field-via-jdbc/355314)

<div class="topic-metadata">

**Author:** [@Kenjiro](https://discuss.elastic.co/u/Kenjiro)\
**Replies:** 4\
**Last updated:** [March 13, 2024, 7:34pm UTC](https://discuss.elastic.co/t/getting-internal-id-field-via-jdbc/355314 "2024-03-13T19:34:50Z")

</div>

Hello, I'm new to elasticsearch and as far as I've read, \_id field is not accesible via sql endpoint at the moment. I've read some posts about duplicating it as a regular field in order to reach via sql endpoint. But I…

---

## [After ES7.5 why "WHERE isn't (yet) compatible with scalar functions on nested fields"](https://discuss.elastic.co/t/after-es7-5-why-where-isnt-yet-compatible-with-scalar-functions-on-nested-fields/352611)

<div class="topic-metadata">

**Author:** [@muhao1020](https://discuss.elastic.co/u/muhao1020)\
**Replies:** 0\
**Last updated:** [February 6, 2024, 8:48am UTC](https://discuss.elastic.co/t/after-es7-5-why-where-isnt-yet-compatible-with-scalar-functions-on-nested-fields/352611 "2024-02-06T08:48:12Z")

</div>

ref : SQL Limitations | Elasticsearch Guide \[7.10\] | Elastic why above limit occurded?

---

## [Data not getting synced properly from SQL to elastic](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351722)

<div class="topic-metadata">

**Author:** [@abhishek\_agarwal](https://discuss.elastic.co/u/abhishek_agarwal)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 3:52pm UTC](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351722 "2024-01-24T15:52:58Z")

</div>

I am syncing data from sql to elastic and in filter in the code block I am appending to map eg features but what is happening is that when I am running the bulk sql query ,not all features are getting appended to each in…

---

## [Elastic Canvas: Discrepancy on data using ES SQL](https://discuss.elastic.co/t/elastic-canvas-discrepancy-on-data-using-es-sql/350882)

<div class="topic-metadata">

**Author:** [@pikaia](https://discuss.elastic.co/u/pikaia)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 6:35pm UTC](https://discuss.elastic.co/t/elastic-canvas-discrepancy-on-data-using-es-sql/350882 "2024-01-11T18:35:24Z")

</div>

Hi, I've been uploading vulnerabilities to Elastic where the fields are already mapped to ECS, and so far, everything has been working fine. Now, I have the need to generate a report at the beginning of each month to pr…

---

## [Creating Mappings for Index Interconnections in ElasticSearch: How to Establish Relationships Between Tables?](https://discuss.elastic.co/t/creating-mappings-for-index-interconnections-in-elasticsearch-how-to-establish-relationships-between-tables/350749)

<div class="topic-metadata">

**Author:** [@Neelesh\_Gupta](https://discuss.elastic.co/u/Neelesh_Gupta)\
**Replies:** 2\
**Last updated:** [January 11, 2024, 12:21am UTC](https://discuss.elastic.co/t/creating-mappings-for-index-interconnections-in-elasticsearch-how-to-establish-relationships-between-tables/350749 "2024-01-11T00:21:22Z")

</div>

I've successfully uploaded 10 CSV file as tables to Elasticsearch to create a Kibana dashboard. However, since these tables are interlinked with foreign keys, they have been transformed into JSON (NoSQL) format in elasti…

---

## [Conditional background in canvas doesn't work](https://discuss.elastic.co/t/conditional-background-in-canvas-doesnt-work/346970)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 2\
**Last updated:** [December 24, 2023, 8:03am UTC](https://discuss.elastic.co/t/conditional-background-in-canvas-doesnt-work/346970 "2023-12-24T08:03:03Z")

</div>

Hi all I want to condition my background for specific value of SQL returned, I try to have a condition for my metric color and its work but in background color its not ! can anyone explain why? this is my expression …

---

## [Exact replacement of LIKE with MATCH() / QUERY() in SQL query](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134)

<div class="topic-metadata">

**Author:** [@Grzegorz\_Kolakowski](https://discuss.elastic.co/u/Grzegorz_Kolakowski)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134 "2023-12-12T11:13:21Z")

</div>

Hi! The documentation suggests to use MATCH()/QUERY() instead of LIKE for performance reasons. I am wondering if it is possible to translate expression from LIKE filter to either MATCH or QUERY in order to achieve exact…

---

## [Cannot search my pdf files](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297)

<div class="topic-metadata">

**Author:** [@Mandy\_Poon](https://discuss.elastic.co/u/Mandy_Poon)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 7:44am UTC](https://discuss.elastic.co/t/cannot-search-my-pdf-files/348297 "2023-12-01T07:44:33Z")

</div>

I have a pdf file and there is a wording "XXX Contract ID - 170458" on the pdf. However I cannot search my file if I use "Contract ID - 170458". (I can search the pdf file if I use "170458") Anyone can help? Thank yo…

---

## [Elastic Search](https://discuss.elastic.co/t/elastic-search/343614)

<div class="topic-metadata">

**Author:** [@Gopal\_Gupta](https://discuss.elastic.co/u/Gopal_Gupta)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 7:15am UTC](https://discuss.elastic.co/t/elastic-search/343614 "2023-10-09T07:15:17Z")

</div>

PROBLEM STATEMENT I am using Join field type Sample Mapping { "mappings": { "properties": { "firstname": { "type": "keyword" }, "lastname": { "type": "keyword" }, "my\_jo…

---

## [Having trouble adding muliple tables using logstash](https://discuss.elastic.co/t/having-trouble-adding-muliple-tables-using-logstash/344020)

<div class="topic-metadata">

**Author:** [@Mustapha\_Hadj](https://discuss.elastic.co/u/Mustapha_Hadj)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 11:30pm UTC](https://discuss.elastic.co/t/having-trouble-adding-muliple-tables-using-logstash/344020 "2023-09-28T23:30:01Z")

</div>

so i have 7 tables in my sql database and i'v been trying to add all of them to an index trough logstash jdbc using a query file , the query goes somthing like SELECT \* FROM \[TABLE\]; SELECT \* FROM \[TABLE\]; SELECT \* FR…

---

## [Search\_after still gives me duplicates](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 1:22pm UTC](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861 "2023-09-26T13:22:32Z")

</div>

Hi, I have implemented a search-after pattern in my Elasticsearch implementation with a hope of solving duplicate issue we are currently facing. On the first request, I am getting a batch of 100 and then get the raw\_scor…

---

## [SQL Lite aggregare on non grouped Column](https://discuss.elastic.co/t/sql-lite-aggregare-on-non-grouped-column/343539)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 12:32pm UTC](https://discuss.elastic.co/t/sql-lite-aggregare-on-non-grouped-column/343539 "2023-09-21T12:32:23Z")

</div>

Hi @leandrojmp , I have a requirement where I need to apply order on a filed in Elasticsearch which is formed dynamically on the fly and it is not part of original index. My Sample document looks like { "deviceType"…

[Next page](https://discuss.elastic.co/tag/elastic-stack-sql/13.md?match_all_tags=true&page=1&tags%5B%5D=elastic-stack-sql)
