# Top

**URL:** https://discuss.elastic.co/top.md?page=11&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 12

---

## [Trying to access nested json in logstash mutate filter](https://discuss.elastic.co/t/trying-to-access-nested-json-in-logstash-mutate-filter/35120)

<div class="topic-metadata">

**Author:** [@skanjila](https://discuss.elastic.co/u/skanjila)\
**Replies:** 9\
**Last updated:** [November 22, 2015, 7:16pm UTC](https://discuss.elastic.co/t/trying-to-access-nested-json-in-logstash-mutate-filter/35120 "2015-11-22T19:16:07Z")

</div>

Hello Folks, I've tried hacking at this for a while now so I thought I'd ask for some help, I have the following json in the message string associated with my input: {"1.0":{"metric-id":"45","customer-id":"Cust","alarm…

---

## [Correct usage of Coordinating role node](https://discuss.elastic.co/t/correct-usage-of-coordinating-role-node/109988)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 17\
**Last updated:** [December 2, 2017, 6:08pm UTC](https://discuss.elastic.co/t/correct-usage-of-coordinating-role-node/109988 "2017-12-02T18:08:33Z")

</div>

hi everybody, currently, I have in theory 2 DATA nodes, 1 active MASTER , 1 passive MASTER (I mean, could only be a master, but it is not elected) and 1 COORDINATOR (with Kibana installed on it). I would like to know i…

---

## [Miracle G1 settings for 30GB heaps](https://discuss.elastic.co/t/miracle-g1-settings-for-30gb-heaps/25271)

<div class="topic-metadata">

**Author:** [@Chris\_Neal](https://discuss.elastic.co/u/Chris_Neal)\
**Replies:** 14\
**Last updated:** [December 27, 2016, 1:43pm UTC](https://discuss.elastic.co/t/miracle-g1-settings-for-30gb-heaps/25271 "2016-12-27T13:43:31Z")

</div>

Ok, maybe not miracle, but it made you look. \[smile\] I'm running this version of Java: java version "1.7.0\_65" OpenJDK Runtime Environment (rhel-2.5.1.2.el6\_5-x86\_64 u65-b17) OpenJDK 64-Bit Server VM (build 24.65-b04…

---

## [Sorting a string field numerically](https://discuss.elastic.co/t/sorting-a-string-field-numerically/9489)

<div class="topic-metadata">

**Author:** [@Axsuul](https://discuss.elastic.co/u/Axsuul)\
**Replies:** 14\
**Last updated:** [October 30, 2012, 2:48pm UTC](https://discuss.elastic.co/t/sorting-a-string-field-numerically/9489 "2012-10-30T14:48:47Z")

</div>

I have a field that is string type. Sometimes it will contain integer values such as 1, 2, 10, 20. Currently how it sorts those is 1, 10, 2, 20. How do I go aboutsorting that numerically so that it's 1, 2, 10, 20? …

---

## [Curator: Delete oldest indices based on ES cluster size](https://discuss.elastic.co/t/curator-delete-oldest-indices-based-on-es-cluster-size/66930)

<div class="topic-metadata">

**Author:** [@berg](https://discuss.elastic.co/u/berg)\
**Replies:** 9\
**Last updated:** [November 24, 2016, 1:33am UTC](https://discuss.elastic.co/t/curator-delete-oldest-indices-based-on-es-cluster-size/66930 "2016-11-24T01:33:28Z")

</div>

Not sure if this is a how to or a feature request; I have a requirement to keep as much time series data as possible for our central logging system. Our log event rates throughout the year vary wildly. If we delete ind…

---

## [\[SOLVED\] Filebeat to Logstash best practice](https://discuss.elastic.co/t/solved-filebeat-to-logstash-best-practice/89728)

<div class="topic-metadata">

**Author:** [@appno\_matt](https://discuss.elastic.co/u/appno_matt)\
**Replies:** 11\
**Last updated:** [June 19, 2017, 7:34am UTC](https://discuss.elastic.co/t/solved-filebeat-to-logstash-best-practice/89728 "2017-06-19T07:34:12Z")

</div>

Hi folks, I'm currently looking over a Filebeat config used to ship Nginx data to Logstash. Filebeat config is: filebeat: prospectors: - paths: - /var/log/syslog - /var/log/auth.log docum…

---

## [Error opening zip file or JAR manifest missing : /path/to/elastic-apm-agent-1.17.0.jar](https://discuss.elastic.co/t/error-opening-zip-file-or-jar-manifest-missing-path-to-elastic-apm-agent-1-17-0-jar/244932)

<div class="topic-metadata">

**Author:** [@bishanjitk](https://discuss.elastic.co/u/bishanjitk)\
**Replies:** 10\
**Last updated:** [August 14, 2020, 3:31pm UTC](https://discuss.elastic.co/t/error-opening-zip-file-or-jar-manifest-missing-path-to-elastic-apm-agent-1-17-0-jar/244932 "2020-08-14T15:31:18Z")

</div>

I tried giving the same commandas per doc, but getting same error now also . Please help . Error opening zip file or JAR manifest missing : /Users/bishanjitkumar/Downloads/elastic-apm-agent-1.17.0.jar Error occurred du…

---

## [FORBIDDEN/8/index write (api) - During date change on indexes](https://discuss.elastic.co/t/forbidden-8-index-write-api-during-date-change-on-indexes/179319)

<div class="topic-metadata">

**Author:** [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Replies:** 9\
**Last updated:** [May 18, 2019, 7:00pm UTC](https://discuss.elastic.co/t/forbidden-8-index-write-api-during-date-change-on-indexes/179319 "2019-05-18T19:00:30Z")

</div>

Hey, I'm seeing some weird issues and yet to find what is causing this behaviour. I have various indexes using the name-%{+YYYY.MM.dd} index pattern. When the indexes are being updated (i.e. today's index is created), i…

---

## [Logstash Parser error - tried to parse field as object, but found a concrete value](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140)

<div class="topic-metadata">

**Author:** [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Replies:** 13\
**Last updated:** [April 8, 2021, 6:42pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140 "2021-04-08T18:42:57Z")

</div>

Hi, I am trying to parse a log but i have this error. \[source\] tried to parse field \[source\] as object, but found a concrete value if "string" in \[tags\] { grok { match =\> \[ "message", "(?\<t…

---

## [No monitoring data found](https://discuss.elastic.co/t/no-monitoring-data-found/119516)

<div class="topic-metadata">

**Author:** [@alexvollmer](https://discuss.elastic.co/u/alexvollmer)\
**Replies:** 10\
**Last updated:** [February 27, 2018, 5:21am UTC](https://discuss.elastic.co/t/no-monitoring-data-found/119516 "2018-02-27T05:21:02Z")

</div>

We've been running Kibana and ES 5.6 with the basic license for quite a few months for the monitoring feature. For some reason now when I go to the monitoring section I get the dreaded "No monitoring data found" error. I…

---

## [Http output to logstash](https://discuss.elastic.co/t/http-output-to-logstash/33269)

<div class="topic-metadata">

**Author:** [@teampants](https://discuss.elastic.co/u/teampants)\
**Replies:** 15\
**Last updated:** [September 7, 2016, 1:56pm UTC](https://discuss.elastic.co/t/http-output-to-logstash/33269 "2016-09-07T13:56:22Z")

</div>

Hi, Is there any plan to implement output to logstash over http(s)? I am working on a project that will require all traffic to be over https, so lumberjack is not an option. At this point I believe my best option wi…

---

## [Install only one elasticsearch master with helm?](https://discuss.elastic.co/t/install-only-one-elasticsearch-master-with-helm/167875)

<div class="topic-metadata">

**Author:** [@JDev](https://discuss.elastic.co/u/JDev)\
**Replies:** 13\
**Last updated:** [February 19, 2019, 1:56pm UTC](https://discuss.elastic.co/t/install-only-one-elasticsearch-master-with-helm/167875 "2019-02-19T13:56:04Z")

</div>

Hello! I try to install on a elasticsearch with helm on Kubernetes. With the almost by default settings, the elasticsearch is installed. helm install --namespace efk --name elasticsearch elastic/elasticsearch --vers…

---

## [How logstash read input file?](https://discuss.elastic.co/t/how-logstash-read-input-file/88363)

<div class="topic-metadata">

**Author:** [@henrilabarre](https://discuss.elastic.co/u/henrilabarre)\
**Replies:** 9\
**Last updated:** [June 7, 2017, 10:18am UTC](https://discuss.elastic.co/t/how-logstash-read-input-file/88363 "2017-06-07T10:18:56Z")

</div>

I wonder if Logstash read the file (csv for example) line per line, and one line after the previous one? and if not how can I be sure logstash parse the file depending of the line number order.... I ask this because in…

---

## [Server returned HTTP response code: 400 for URL, when sending a post request to elasticsearch?](https://discuss.elastic.co/t/server-returned-http-response-code-400-for-url-when-sending-a-post-request-to-elasticsearch/64408)

<div class="topic-metadata">

**Author:** [@Kulasangar\_Gowrisang](https://discuss.elastic.co/u/Kulasangar_Gowrisang)\
**Replies:** 16\
**Last updated:** [October 31, 2016, 4:31pm UTC](https://discuss.elastic.co/t/server-returned-http-response-code-400-for-url-when-sending-a-post-request-to-elasticsearch/64408 "2016-10-31T16:31:53Z")

</div>

I'm using elasticsearch 5.0.0, and I've got three indexes which I'm trying to query and get data through my code. I'm sending a post request which includes a json body as well. It returns a 400 when when I'm running my c…

---

## [How to install xpack on elasticsearch hosted on docker](https://discuss.elastic.co/t/how-to-install-xpack-on-elasticsearch-hosted-on-docker/125858)

<div class="topic-metadata">

**Author:** [@Gaurav\_Agarwal](https://discuss.elastic.co/u/Gaurav_Agarwal)\
**Replies:** 17\
**Last updated:** [March 29, 2018, 7:07am UTC](https://discuss.elastic.co/t/how-to-install-xpack-on-elasticsearch-hosted-on-docker/125858 "2018-03-29T07:07:26Z")

</div>

Please let me know how to install xpack on docker the elasticsearch version which I am using on docker is 5.6.8 .

---

## [Data Table in Dashboard](https://discuss.elastic.co/t/data-table-in-dashboard/303478)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 17\
**Last updated:** [May 11, 2022, 12:45pm UTC](https://discuss.elastic.co/t/data-table-in-dashboard/303478 "2022-05-11T12:45:55Z")

</div>

Hello, i want to create a basic data table in a Kibana Dashboard with employees. I tried using the Table Lens but there is always a requirement for a metric like count, sum,.. which i do not need, as i only want to dis…

---

## [Automatically Delete older Documents](https://discuss.elastic.co/t/automatically-delete-older-documents/247078)

<div class="topic-metadata">

**Author:** [@Arun\_N](https://discuss.elastic.co/u/Arun_N)\
**Replies:** 10\
**Last updated:** [September 1, 2020, 1:16pm UTC](https://discuss.elastic.co/t/automatically-delete-older-documents/247078 "2020-09-01T13:16:54Z")

</div>

Hi Team, I need your help to understand how to set TTL like mechanism to delete the Elastic Search documentation automatically once it's reached the expiration time. I have read about delete by query API but the proble…

---

## [Kibana 4 dashboards access control with Shield](https://discuss.elastic.co/t/kibana-4-dashboards-access-control-with-shield/2151)

<div class="topic-metadata">

**Author:** [@matt](https://discuss.elastic.co/u/matt)\
**Replies:** 23\
**Last updated:** [September 14, 2016, 9:52am UTC](https://discuss.elastic.co/t/kibana-4-dashboards-access-control-with-shield/2151 "2016-09-14T09:52:39Z")

</div>

Hi all, I have bunch of dashboards (DB1, DB2, DB3 & DB4) and I like to enforce user level access control. user\_1: - DB1, DB2 & DB3 user\_2: - DB2 & DB4 user\_3: - DB1 & DB4 Also, let's say user\_2 has access to crea…

---

## [Why artifacts.elastic.co/GPG-KEY-elasticsearch returns 403 for russian IPs, but not always?](https://discuss.elastic.co/t/why-artifacts-elastic-co-gpg-key-elasticsearch-returns-403-for-russian-ips-but-not-always/300969)

<div class="topic-metadata">

**Author:** [@h\_Kleiser](https://discuss.elastic.co/u/h_Kleiser)\
**Replies:** 26\
**Last updated:** [July 17, 2022, 10:57pm UTC](https://discuss.elastic.co/t/why-artifacts-elastic-co-gpg-key-elasticsearch-returns-403-for-russian-ips-but-not-always/300969 "2022-07-17T22:57:50Z")

</div>

I'm making rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch and it return 403, but not always, like 30% of all request passes normally. What's the point of such behaviour?

---

## [Regarding Filebeat Ouput to a File in Remote Server or NFS](https://discuss.elastic.co/t/regarding-filebeat-ouput-to-a-file-in-remote-server-or-nfs/46038)

<div class="topic-metadata">

**Author:** [@vivc](https://discuss.elastic.co/u/vivc)\
**Replies:** 37\
**Last updated:** [June 22, 2016, 6:07am UTC](https://discuss.elastic.co/t/regarding-filebeat-ouput-to-a-file-in-remote-server-or-nfs/46038 "2016-06-22T06:07:26Z")

</div>

I want to output data from filebeat to a file in NFS on remote server. Please suggest how we can do that. I have found the option to forward data using following configuration . But how we can we forward the data to fi…

---

## [How do I combine 2 index data in elasticsearch?](https://discuss.elastic.co/t/how-do-i-combine-2-index-data-in-elasticsearch/199044)

<div class="topic-metadata">

**Author:** [@mr\_searchng](https://discuss.elastic.co/u/mr_searchng)\
**Replies:** 21\
**Last updated:** [September 12, 2019, 1:53pm UTC](https://discuss.elastic.co/t/how-do-i-combine-2-index-data-in-elasticsearch/199044 "2019-09-12T13:53:23Z")

</div>

How do I combine 2 index data in elasticsearch? Example; 1.index data = {appId,name,clasId} 2.index data={clasId,name,description} 1.index via clasId 2.index class name how do I pull ?

---

## [Cannot disable TLS and security in EKS](https://discuss.elastic.co/t/cannot-disable-tls-and-security-in-eks/222335)

<div class="topic-metadata">

**Author:** [@yannalbou](https://discuss.elastic.co/u/yannalbou)\
**Replies:** 11\
**Last updated:** [October 20, 2021, 8:16am UTC](https://discuss.elastic.co/t/cannot-disable-tls-and-security-in-eks/222335 "2021-10-20T08:16:16Z")

</div>

Hello, I Installed ECK open source 1.0.1 in k8s 1.15.5 I tried to disable the security and TLS using: apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: elasticsearch spec: …

---

## [Elasticsearch Issue I can't figure out (can't curl 9200)](https://discuss.elastic.co/t/elasticsearch-issue-i-cant-figure-out-cant-curl-9200/129816)

<div class="topic-metadata">

**Author:** [@crypto-99](https://discuss.elastic.co/u/crypto-99)\
**Replies:** 9\
**Last updated:** [June 12, 2018, 10:26pm UTC](https://discuss.elastic.co/t/elasticsearch-issue-i-cant-figure-out-cant-curl-9200/129816 "2018-06-12T22:26:59Z")

</div>

I made a thread on reddit and was recommended to make one here: https://www.reddit.com/r/elasticsearch/comments/8dvkx0/elasticsearch\_issue\_i\_cant\_figure\_out\_cant\_curl/ We have a really annoying issue that is effecting o…

---

## [Setting Up Logstash In Docker-Compose For Bulk Ingest Of CSV Files In Local Machine](https://discuss.elastic.co/t/setting-up-logstash-in-docker-compose-for-bulk-ingest-of-csv-files-in-local-machine/346916)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 112\
**Last updated:** [November 23, 2023, 5:55pm UTC](https://discuss.elastic.co/t/setting-up-logstash-in-docker-compose-for-bulk-ingest-of-csv-files-in-local-machine/346916 "2023-11-23T17:55:14Z")

</div>

CONTINUATION FROM kibana-8-11-0-failed-to-start-exit-code-1 My use case is to bulk ingest csv files into Elasticsearch. Understand i need Logstash to do it. Not sure how to start. Should I be using a default or cus…

---

## [Curl timeout settings - PHP-api](https://discuss.elastic.co/t/curl-timeout-settings-php-api/43023)

<div class="topic-metadata">

**Author:** [@evert](https://discuss.elastic.co/u/evert)\
**Replies:** 13\
**Last updated:** [July 5, 2016, 1:29pm UTC](https://discuss.elastic.co/t/curl-timeout-settings-php-api/43023 "2016-07-05T13:29:28Z")

</div>

Hi everyone! I am pretty new to Elasticsearch, sorry if this is too dumb or newbie. I am having problems with Curl Timeout exceeding 60 seconds and its configuration. Here is the error message: FatalErrorException …

---

## [Elastic Search for storing Historical data](https://discuss.elastic.co/t/elastic-search-for-storing-historical-data/29210)

<div class="topic-metadata">

**Author:** [@code\_blue](https://discuss.elastic.co/u/code_blue)\
**Replies:** 20\
**Last updated:** [January 20, 2016, 6:54am UTC](https://discuss.elastic.co/t/elastic-search-for-storing-historical-data/29210 "2016-01-20T06:54:57Z")

</div>

We are considering storing Historical data in ES. Is there any pattern or best practice guideline defined for this? The way we want to do this is via a scheduled job that will pull data on a defined interval and store …

---

## [Detection and Response for HAFNIUM Activity](https://discuss.elastic.co/t/detection-and-response-for-hafnium-activity/266289)

<div class="topic-metadata">

**Author:** [@devonkerr](https://discuss.elastic.co/u/devonkerr)\
**Replies:** 2\
**Last updated:** [March 10, 2021, 10:47pm UTC](https://discuss.elastic.co/t/detection-and-response-for-hafnium-activity/266289 "2021-03-10T22:47:14Z")

</div>

Detection and Response for HAFNIUM Activity Executive summary On March 2, 2021, Microsoft released a security update for on-premises Exchange servers to address vulnerabilities being exploited. Security vendors are seein…

---

## [Logstash-elasticsearch output plugin issue(UNEXPECTED POOL ERROR)](https://discuss.elastic.co/t/logstash-elasticsearch-output-plugin-issue-unexpected-pool-error/64899)

<div class="topic-metadata">

**Author:** [@rai](https://discuss.elastic.co/u/rai)\
**Replies:** 12\
**Last updated:** [March 28, 2017, 6:01am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-plugin-issue-unexpected-pool-error/64899 "2017-03-28T06:01:46Z")

</div>

I have created a docker image based on elk 5.0.0. and used logstash-kafka input plugin. ELK server has started without any issue and but can't see any log on kibana. I am also able to curl elasticsearch (curl "http://\*\*\*…

---

## [Web Portocols and Ports used by Elasticsearch](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055)

<div class="topic-metadata">

**Author:** [@somebody](https://discuss.elastic.co/u/somebody)\
**Replies:** 17\
**Last updated:** [March 24, 2020, 10:37am UTC](https://discuss.elastic.co/t/web-portocols-and-ports-used-by-elasticsearch/220055 "2020-03-24T10:37:22Z")

</div>

Hi, I need to know all the protocols ( http, tcp.. etc) Elasticsearch uses for client-server communication (indexing, querying.. etc) Inter-communication between primary and replica shards ( For leader election, recov…

---

## [Permanent way of making ES Replicas = 0](https://discuss.elastic.co/t/permanent-way-of-making-es-replicas-0/58206)

<div class="topic-metadata">

**Author:** [@jamesl](https://discuss.elastic.co/u/jamesl)\
**Replies:** 15\
**Last updated:** [August 21, 2016, 12:31am UTC](https://discuss.elastic.co/t/permanent-way-of-making-es-replicas-0/58206 "2016-08-21T00:31:49Z")

</div>

Hello. I know that by issuing this command on my ES node it will set all current replicas to 0 but how about if I want to make it persistent so all of them are 0 from now on.. curl -XPUT 'localhost:9200/\_settings' -d ' …

---

## [Unusually high Metricbeat memory usage](https://discuss.elastic.co/t/unusually-high-metricbeat-memory-usage/184621)

<div class="topic-metadata">

**Author:** [@apang](https://discuss.elastic.co/u/apang)\
**Replies:** 13\
**Last updated:** [July 10, 2019, 1:41pm UTC](https://discuss.elastic.co/t/unusually-high-metricbeat-memory-usage/184621 "2019-07-10T13:41:39Z")

</div>

I have metricbeat installed on a Windows Server 2016 Datacenter server that also has an Elasticsearch node. I also have metricbeat installed on a Windows Server 2012 Standard server with an Elasticsearch node as well in…

---

## [Error creating sniffer on OS X - permission denied](https://discuss.elastic.co/t/error-creating-sniffer-on-os-x-permission-denied/32622)

<div class="topic-metadata">

**Author:** [@Prerna\_Manaktala](https://discuss.elastic.co/u/Prerna_Manaktala)\
**Replies:** 15\
**Last updated:** [June 21, 2016, 10:07am UTC](https://discuss.elastic.co/t/error-creating-sniffer-on-os-x-permission-denied/32622 "2016-06-21T10:07:34Z")

</div>

I am trying to run packetbeat on mac with packetbeat.yml configured to have mac settings and http port changes from default: # Select the network interfaces to sniff the data. You can use the "any" # keyword to sniff …

---

## [Failed starting 'elasticsearch-service-x64' service](https://discuss.elastic.co/t/failed-starting-elasticsearch-service-x64-service/93784)

<div class="topic-metadata">

**Author:** [@Navakanth\_B](https://discuss.elastic.co/u/Navakanth_B)\
**Replies:** 9\
**Last updated:** [August 14, 2017, 3:47pm UTC](https://discuss.elastic.co/t/failed-starting-elasticsearch-service-x64-service/93784 "2017-08-14T15:47:12Z")

</div>

ES version: elasticsearch-5.5.0 Java version: 1.8.0\_91 OS: Windows-7(64 bit) Description: Could not start elasticsearch-service-x64 service, showing Failed starting 'elasticsearch-service-x64' service message in conso…

---

## [Issue with s3 repository](https://discuss.elastic.co/t/issue-with-s3-repository/114542)

<div class="topic-metadata">

**Author:** [@paulglavin](https://discuss.elastic.co/u/paulglavin)\
**Replies:** 16\
**Last updated:** [January 9, 2018, 5:05pm UTC](https://discuss.elastic.co/t/issue-with-s3-repository/114542 "2018-01-09T17:05:31Z")

</div>

I've just upgraded our cluster from 5.6 to 6.1, everything is fine apart from accessing repositories in an s3 bucket. I've migrated the access key and secret key settings to the keystore using these two options s3.clie…

---

## [Elaticsearch not recognising path repo](https://discuss.elastic.co/t/elaticsearch-not-recognising-path-repo/101352)

<div class="topic-metadata">

**Author:** [@vishu.kolki](https://discuss.elastic.co/u/vishu.kolki)\
**Replies:** 18\
**Last updated:** [September 23, 2017, 2:38pm UTC](https://discuss.elastic.co/t/elaticsearch-not-recognising-path-repo/101352 "2017-09-23T14:38:03Z")

</div>

Hi, My elasticsearch applications are running on docker. i have mounted the path.repo but i am getting following error: {"error":"RepositoryException\[\[my\_backup\] failed to create repository\]; nested: CreationException\[…

---

## [Bulk update is too slow elasticsearch 6.2](https://discuss.elastic.co/t/bulk-update-is-too-slow-elasticsearch-6-2/129213)

<div class="topic-metadata">

**Author:** [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)\
**Replies:** 24\
**Last updated:** [May 7, 2018, 11:24am UTC](https://discuss.elastic.co/t/bulk-update-is-too-slow-elasticsearch-6-2/129213 "2018-05-07T11:24:16Z")

</div>

Hi guys, Hers is my configuration: ES version = 6.2 JVM = 30gb Ram = 128gb CPU = 24core SDK = PHP I am experiencing Bulk update is too slow. I tried given solution which not working. Any suggestion will be apprec…

---

## [Is my response time is ok?](https://discuss.elastic.co/t/is-my-response-time-is-ok/134326)

<div class="topic-metadata">

**Author:** [@artpolikarpov](https://discuss.elastic.co/u/artpolikarpov)\
**Replies:** 17\
**Last updated:** [June 8, 2018, 2:58pm UTC](https://discuss.elastic.co/t/is-my-response-time-is-ok/134326 "2018-06-08T14:58:53Z")

</div>

Hi there! I am a novice in ES. And I want to know if I’m doing something wrong or trying to achieve impossible things. I think my searches are slow. I have index messages (22.9 GB, 77m docs). Mapping is simple: esClien…

---

## [Elasticsearch Metricbeat Module not parsing hosts properly](https://discuss.elastic.co/t/elasticsearch-metricbeat-module-not-parsing-hosts-properly/205893)

<div class="topic-metadata">

**Author:** [@Rad\_Engel](https://discuss.elastic.co/u/Rad_Engel)\
**Replies:** 15\
**Last updated:** [November 14, 2019, 7:43pm UTC](https://discuss.elastic.co/t/elasticsearch-metricbeat-module-not-parsing-hosts-properly/205893 "2019-11-14T19:43:34Z")

</div>

I've enabled the X-Pack on Elasticsearch Module in Metricbeat 7.4.1. I have SSL set up for my Elasticsearch cluster (single node, Kibana, Losgstash, and other beats are fine) and am attempting to get Metricbeat to query…

---

## [Create new user](https://discuss.elastic.co/t/create-new-user/122362)

<div class="topic-metadata">

**Author:** [@shahpx](https://discuss.elastic.co/u/shahpx)\
**Replies:** 9\
**Last updated:** [April 3, 2018, 4:34am UTC](https://discuss.elastic.co/t/create-new-user/122362 "2018-04-03T04:34:41Z")

</div>

Hello, I have installed ELK stack with x-pack. Now I logged in with Kibana user and trying to create new user but it is throwing error: You do not have permission to manage users. Please contact your administrator. A…

---

## [Newbie to Linux/elastic. I'm having trouble setting up elasticsearch](https://discuss.elastic.co/t/newbie-to-linux-elastic-im-having-trouble-setting-up-elasticsearch/298687)

<div class="topic-metadata">

**Author:** [@elasticScrub](https://discuss.elastic.co/u/elasticScrub)\
**Replies:** 19\
**Last updated:** [March 8, 2022, 11:19pm UTC](https://discuss.elastic.co/t/newbie-to-linux-elastic-im-having-trouble-setting-up-elasticsearch/298687 "2022-03-08T23:19:49Z")

</div>

As the title says I'm new to Elasticsearch and Linux in general. I have setup an Ubuntu server in VirtualBox for installing Elasticsearch. I followed the guide listed on installing it and am currently stuck on this step. …

---

## [Logstash Variables](https://discuss.elastic.co/t/logstash-variables/70822)

<div class="topic-metadata">

**Author:** [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Replies:** 24\
**Last updated:** [January 23, 2017, 3:45pm UTC](https://discuss.elastic.co/t/logstash-variables/70822 "2017-01-23T15:45:59Z")

</div>

Hello all, I am doing my level best to understand where I define variable. Please forgive me as I am not very strong in unix as a whole and learning as I go. But this page: https://www.elastic.co/guide/en/logstash/curr…

---

## [How to clean logs generated by Logstash?](https://discuss.elastic.co/t/how-to-clean-logs-generated-by-logstash/48548)

<div class="topic-metadata">

**Author:** [@djvidov](https://discuss.elastic.co/u/djvidov)\
**Replies:** 11\
**Last updated:** [May 4, 2016, 8:35am UTC](https://discuss.elastic.co/t/how-to-clean-logs-generated-by-logstash/48548 "2016-05-04T08:35:13Z")

</div>

Today my logstash stops to work because it's log folder was full with old logs since 2015. There is a setting in logstash to delete logs older that x days? Thanks, Ovidiu

---

## [How to post a json array to elasticsearch](https://discuss.elastic.co/t/how-to-post-a-json-array-to-elasticsearch/9757)

<div class="topic-metadata">

**Author:** [@Bill\_Wang](https://discuss.elastic.co/u/Bill_Wang)\
**Replies:** 9\
**Last updated:** [November 28, 2013, 8:33am UTC](https://discuss.elastic.co/t/how-to-post-a-json-array-to-elasticsearch/9757 "2013-11-28T08:33:22Z")

</div>

Hi all, I'm a newbie here, when I post an item to elasticsearch curl -XPOST http://localhost:9200/sg/Location -d "@Location.json" Location.json { "Name" : "aaa", "Age" : "20" } However, if I want t…

---

## [Logstash filter verifier - any working example?](https://discuss.elastic.co/t/logstash-filter-verifier-any-working-example/41880)

<div class="topic-metadata">

**Author:** [@terramexx](https://discuss.elastic.co/u/terramexx)\
**Replies:** 28\
**Last updated:** [March 2, 2017, 10:13pm UTC](https://discuss.elastic.co/t/logstash-filter-verifier-any-working-example/41880 "2017-03-02T22:13:54Z")

</div>

Continuing the discussion from Logstash test with rspec: The tool https://github.com/magnusbaeck/logstash-filter-verifier seems to be exactly what I was looking for: - easy install (in compare to rspec) - based on logs…

---

## [Logstash 5 alpha5-1 - Failed to load settings file from "path.settings". Aborting](https://discuss.elastic.co/t/logstash-5-alpha5-1-failed-to-load-settings-file-from-path-settings-aborting/58360)

<div class="topic-metadata">

**Author:** [@rwagner](https://discuss.elastic.co/u/rwagner)\
**Replies:** 15\
**Last updated:** [March 19, 2017, 7:50pm UTC](https://discuss.elastic.co/t/logstash-5-alpha5-1-failed-to-load-settings-file-from-path-settings-aborting/58360 "2017-03-19T19:50:44Z")

</div>

I'm getting the following error when try run: # /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/logstash.conf --- jar coordinate com.fasterxml.jackson.core:jackson-annotations already loaded with version 2.7.1…

---

## [Watcher Email configuration Issue](https://discuss.elastic.co/t/watcher-email-configuration-issue/33047)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 31\
**Last updated:** [August 5, 2016, 8:57am UTC](https://discuss.elastic.co/t/watcher-email-configuration-issue/33047 "2016-08-05T08:57:53Z")

</div>

Hi, I have configured watcher to Elasticsearch to get Alert & Notifications and I have setup Email configuration in yml file as shown below. watcher.actions.email.service.account: company\_account: profile: company sm…

---

## [Output file configuration](https://discuss.elastic.co/t/output-file-configuration/136269)

<div class="topic-metadata">

**Author:** [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Replies:** 22\
**Last updated:** [June 22, 2018, 6:24am UTC](https://discuss.elastic.co/t/output-file-configuration/136269 "2018-06-22T06:24:06Z")

</div>

Hi, I have this configuration on 30-elasticsearch-output.conf output { elasticsearch { hosts =\> \["localhost:9200"\] sniffing =\> true manage\_template =\> false index =\> "%{\[@metadata\]\[beat\]}-%{+YYYY.MM.dd}" document…

---

## [Automatically delete 1 month old records/documents(without deleting index) in elastic search/kibana](https://discuss.elastic.co/t/automatically-delete-1-month-old-records-documents-without-deleting-index-in-elastic-search-kibana/160041)

<div class="topic-metadata">

**Author:** [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Replies:** 20\
**Last updated:** [December 13, 2018, 9:19am UTC](https://discuss.elastic.co/t/automatically-delete-1-month-old-records-documents-without-deleting-index-in-elastic-search-kibana/160041 "2018-12-13T09:19:40Z")

</div>

When i try to create time based index for filebeats,it says "unable to fetch mapping , do you have indices matching that pattern". However the normal index is getting created when i type in filebeat-\*. Can anybody pleas…

---

## [Elasticsearch Service won't start after full cluster upgrade from 5.4 to 6.0](https://discuss.elastic.co/t/elasticsearch-service-wont-start-after-full-cluster-upgrade-from-5-4-to-6-0/108048)

<div class="topic-metadata">

**Author:** [@Anarmun\_Munkhbayar](https://discuss.elastic.co/u/Anarmun_Munkhbayar)\
**Replies:** 9\
**Last updated:** [December 12, 2017, 6:54pm UTC](https://discuss.elastic.co/t/elasticsearch-service-wont-start-after-full-cluster-upgrade-from-5-4-to-6-0/108048 "2017-12-12T18:54:51Z")

</div>

Hi, I was running elasticsearch cluster with 3 nodes version 5.4 on Centos. And I decided to upgrade it to version 6. I did full cluster restart upgrade followed all the https://www.elastic.co/guide/en/elasticsearch/ref…

---

## [Split and get part of a long string in painless](https://discuss.elastic.co/t/split-and-get-part-of-a-long-string-in-painless/295575)

<div class="topic-metadata">

**Author:** [@auato](https://discuss.elastic.co/u/auato)\
**Replies:** 17\
**Last updated:** [February 2, 2022, 10:36am UTC](https://discuss.elastic.co/t/split-and-get-part-of-a-long-string-in-painless/295575 "2022-02-02T10:36:49Z")

</div>

Hi, I would like to get from the following examples of string a specific part (in bold) in painless script in Kibana: APAC42\_OM/VM:Virtual machine name=APAC42\_ELETYPE\_\*\*CSBBU\*\*\_0 APAC42\_OM/VM:Virtual machine name=APAC42…

[Previous page](https://discuss.elastic.co/top.md?page=10&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=12&per_page=50&period=all)
