# Top

**URL:** https://discuss.elastic.co/top.md?page=12&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 13

---

## [Cant install Marvel License](https://discuss.elastic.co/t/cant-install-marvel-license/33352)

<div class="topic-metadata">

**Author:** [@AnixanSkystalkr](https://discuss.elastic.co/u/AnixanSkystalkr)\
**Replies:** 23\
**Last updated:** [June 28, 2017, 3:50am UTC](https://discuss.elastic.co/t/cant-install-marvel-license/33352 "2017-06-28T03:50:01Z")

</div>

Hi, I am attempting to install the Marvel License and it gives me the following errors: Standard Install sudo bin/plugin install license Error: -\> Installing license... Trying https://github.com/null/license/arc…

---

## [Performance aggregations vs collapsing](https://discuss.elastic.co/t/performance-aggregations-vs-collapsing/156295)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 31\
**Last updated:** [November 15, 2018, 1:13pm UTC](https://discuss.elastic.co/t/performance-aggregations-vs-collapsing/156295 "2018-11-15T13:13:12Z")

</div>

Hi, I'm using aggregations over individual shards - these are large (40M docs per shard) but made of small documents. The aggregations are pretty simple GET status/\_search?preference=\_shards:5 { "from": 0, "size": 0…

---

## [Exporting index data into csv from kibana](https://discuss.elastic.co/t/exporting-index-data-into-csv-from-kibana/207761)

<div class="topic-metadata">

**Author:** [@sarvendras](https://discuss.elastic.co/u/sarvendras)\
**Replies:** 9\
**Last updated:** [November 18, 2019, 11:41pm UTC](https://discuss.elastic.co/t/exporting-index-data-into-csv-from-kibana/207761 "2019-11-18T23:41:50Z")

</div>

Hello All, Is there any option to export index data into csv file from kibana in latest elasticsearch 7.4 Thanks Sarvendra

---

## [Compare Two Indexes](https://discuss.elastic.co/t/compare-two-indexes/269254)

<div class="topic-metadata">

**Author:** [@Dinesh\_Sharma](https://discuss.elastic.co/u/Dinesh_Sharma)\
**Replies:** 16\
**Last updated:** [April 8, 2021, 7:31am UTC](https://discuss.elastic.co/t/compare-two-indexes/269254 "2021-04-08T07:31:12Z")

</div>

Hi, I have one document in one index and other document in other index. Now I want to compare the fields of these two documents of different indexes. Is it possible to do it, not sure did some couldn't find any satisfac…

---

## [Filebeat Windows Config Help (filebeat.yml)](https://discuss.elastic.co/t/filebeat-windows-config-help-filebeat-yml/52656)

<div class="topic-metadata">

**Author:** [@filebeat\_win](https://discuss.elastic.co/u/filebeat_win)\
**Replies:** 13\
**Last updated:** [June 22, 2016, 3:54pm UTC](https://discuss.elastic.co/t/filebeat-windows-config-help-filebeat-yml/52656 "2016-06-22T15:54:49Z")

</div>

Trying to capture IIS logs in close to real time, but Kibana seems to only show old logs (the day before and older). Can anyone point me in the right direction to getting close to real-time logs displayed in Kibana? OS…

---

## [Syslog date without year](https://discuss.elastic.co/t/syslog-date-without-year/29834)

<div class="topic-metadata">

**Author:** [@Miguel\_Bessa](https://discuss.elastic.co/u/Miguel_Bessa)\
**Replies:** 10\
**Last updated:** [February 3, 2016, 11:47am UTC](https://discuss.elastic.co/t/syslog-date-without-year/29834 "2016-02-03T11:47:27Z")

</div>

Hi, I'm using Logstash to analyze my syslog files. My syslog files have the date like this: Jun 30 06:34:35. I want have the year to, because I need to use date to filter visualizations on kibana. I don't use kibana @…

---

## [Unknown key for a START\_OBJECT in \[knn\]](https://discuss.elastic.co/t/unknown-key-for-a-start-object-in-knn/319381)

<div class="topic-metadata">

**Author:** [@Scott\_M](https://discuss.elastic.co/u/Scott_M)\
**Replies:** 13\
**Last updated:** [November 25, 2022, 7:22am UTC](https://discuss.elastic.co/t/unknown-key-for-a-start-object-in-knn/319381 "2022-11-25T07:22:12Z")

</div>

Has anybody actually used the knn sample in the documentation here:k-nearest neighbor (kNN) search | Elasticsearch Guide \[master\] | Elastic ? Here is their sample: POST image-index/\_search { "query": { "match": {…

---

## [Excessive merging/small segment sizes](https://discuss.elastic.co/t/excessive-merging-small-segment-sizes/18491)

<div class="topic-metadata">

**Author:** [@Kireet\_Reddy](https://discuss.elastic.co/u/Kireet_Reddy)\
**Replies:** 25\
**Last updated:** [July 15, 2014, 12:39pm UTC](https://discuss.elastic.co/t/excessive-merging-small-segment-sizes/18491 "2014-07-15T12:39:25Z")

</div>

We have a situation where one of the four nodes in our cluster seems to get caught up endlessly merging. However it seems to be high CPU activity and not I/O constrainted. I have enabled the IndexWriter info stream …

---

## [Poor performance and a lot of GC overhead](https://discuss.elastic.co/t/poor-performance-and-a-lot-of-gc-overhead/140145)

<div class="topic-metadata">

**Author:** [@dboss101](https://discuss.elastic.co/u/dboss101)\
**Replies:** 18\
**Last updated:** [August 10, 2018, 9:26am UTC](https://discuss.elastic.co/t/poor-performance-and-a-lot-of-gc-overhead/140145 "2018-08-10T09:26:15Z")

</div>

Hi, we are running elasticsearch with the following spec: 1 node on a hardware server 16GB of RAM 2GB assigned for heap 8 CPU cores (Intel Xeon CPU E5620 @ 2.40GHz) HDD disks Elasticsearch 5.6.3 JVM 1.8.0\_171 we…

---

## [Getting 403 denied to elastic.co (for anything: apt refresh, wget, etc)](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/301150)

<div class="topic-metadata">

**Author:** [@total-dor](https://discuss.elastic.co/u/total-dor)\
**Replies:** 13\
**Last updated:** [May 9, 2022, 8:46am UTC](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/301150 "2022-05-09T08:46:26Z")

</div>

Our company runs out of several datacenters and we just provisioned a new one in a new region (within USA) and I cannot pull from elastic.co from this site. The below commands work perfectly fine for any other site with…

---

## [Need help to overcome 100% CPU](https://discuss.elastic.co/t/need-help-to-overcome-100-cpu/82126)

<div class="topic-metadata">

**Author:** [@Gang](https://discuss.elastic.co/u/Gang)\
**Replies:** 17\
**Last updated:** [April 27, 2017, 9:00am UTC](https://discuss.elastic.co/t/need-help-to-overcome-100-cpu/82126 "2017-04-27T09:00:59Z")

</div>

Hi, everybody I\`m stuck on cluster performance tuning/scale and need help. I'm implementing solution on top of Elasticsearch. Now I\`ve started load testing and 5 parallel thread requests put my cluster down. In short, …

---

## [Bulk inserting is slow](https://discuss.elastic.co/t/bulk-inserting-is-slow/18259)

<div class="topic-metadata">

**Author:** [@phoenix](https://discuss.elastic.co/u/phoenix)\
**Replies:** 13\
**Last updated:** [July 3, 2015, 6:27pm UTC](https://discuss.elastic.co/t/bulk-inserting-is-slow/18259 "2015-07-03T18:27:56Z")

</div>

Hi everyone, I'm inserting around 265 000 documents into an elastic search cluster composed of 3 nodes (real servers). On two servers i give elastic search 20g of heap, on third one which has 64g ram, i set 30g o…

---

## [How do I match a newline in grok/logstash](https://discuss.elastic.co/t/how-do-i-match-a-newline-in-grok-logstash/56339)

<div class="topic-metadata">

**Author:** [@Sri\_ram](https://discuss.elastic.co/u/Sri_ram)\
**Replies:** 12\
**Last updated:** [July 28, 2016, 2:49pm UTC](https://discuss.elastic.co/t/how-do-i-match-a-newline-in-grok-logstash/56339 "2016-07-28T14:49:18Z")

</div>

I am using Logstash to parse and filter the data. The input data looks something like: \> Tue Apr 05 01:33:13 EDT 2016 r/s w/s cache free\_mem used\_mem swap\_mem page faults id wa 0 0 0 7535996 72612 232184…

---

## [Logstash out of memory error](https://discuss.elastic.co/t/logstash-out-of-memory-error/104638)

<div class="topic-metadata">

**Author:** [@uLan](https://discuss.elastic.co/u/uLan)\
**Replies:** 11\
**Last updated:** [October 24, 2017, 2:41am UTC](https://discuss.elastic.co/t/logstash-out-of-memory-error/104638 "2017-10-24T02:41:24Z")

</div>

I have logstash in a docker container that crashes and says out of memory error after restart. I restart it using docker-compose restart logstash. docker stats says it consumes 400MiB~ of RAM when it's running normally a…

---

## [Unable to connect to Kibana using an IP address](https://discuss.elastic.co/t/unable-to-connect-to-kibana-using-an-ip-address/138275)

<div class="topic-metadata">

**Author:** [@APJ](https://discuss.elastic.co/u/APJ)\
**Replies:** 15\
**Last updated:** [July 5, 2018, 11:04pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-kibana-using-an-ip-address/138275 "2018-07-05T23:04:19Z")

</div>

I have installed Kibana and Elastic search on one of my organization's server. The server runs on Cent OS 6.6. I have been following this tutorial \[Link\](https://www.digitalocean.com/community/tutorials/how-to-install-e…

---

## [How to convert field date from String to Date?](https://discuss.elastic.co/t/how-to-convert-field-date-from-string-to-date/224467)

<div class="topic-metadata">

**Author:** [@Emna1](https://discuss.elastic.co/u/Emna1)\
**Replies:** 12\
**Last updated:** [March 23, 2020, 9:57am UTC](https://discuss.elastic.co/t/how-to-convert-field-date-from-string-to-date/224467 "2020-03-23T09:57:42Z")

</div>

I want to convert the field of date from string to date, i try this code in my config file but it doesn't change in kibana..I don't know why! any help?? filter{ csv{ columns =\> \["car","date","dateEntree","dateSortie"\] …

---

## [Filebeat do not see file updates after a while](https://discuss.elastic.co/t/filebeat-do-not-see-file-updates-after-a-while/34914)

<div class="topic-metadata">

**Author:** [@ogauchard](https://discuss.elastic.co/u/ogauchard)\
**Replies:** 32\
**Last updated:** [May 26, 2016, 7:21am UTC](https://discuss.elastic.co/t/filebeat-do-not-see-file-updates-after-a-while/34914 "2016-05-26T07:21:43Z")

</div>

Hello, I am facing a strange issue with Filebeat on Windows : I use it to consume log files generated with log4net. These files are configures to rotate every day. Filebeat is only watching the current file. Everyt…

---

## [No space - disaster](https://discuss.elastic.co/t/no-space-disaster/34158)

<div class="topic-metadata">

**Author:** [@scaarup](https://discuss.elastic.co/u/scaarup)\
**Replies:** 18\
**Last updated:** [June 29, 2017, 7:59am UTC](https://discuss.elastic.co/t/no-space-disaster/34158 "2017-06-29T07:59:13Z")

</div>

Running out of space on the elasticsearch-server is a total disaster. After freeing up some space, I am trying to start ES again, but the following error continues to appear in the log: \[2015-11-09 14:56:38,021\]\[WARN \]…

---

## [All nodes except Master show as "Offline"](https://discuss.elastic.co/t/all-nodes-except-master-show-as-offline/46274)

<div class="topic-metadata">

**Author:** [@tebriel](https://discuss.elastic.co/u/tebriel)\
**Replies:** 27\
**Last updated:** [April 27, 2016, 9:38pm UTC](https://discuss.elastic.co/t/all-nodes-except-master-show-as-offline/46274 "2016-04-27T21:38:51Z")

</div>

Running Elasticsearch 2.3.0 Kibana 4.5.0 Marvel-agent 2.3.0 Description The nodes page in Marvel shows all 4 nodes in my cluster, with proper metadata about each (hostname, ip address, name). However all except the mas…

---

## [SOLVED:Issue in LDAP group authentication (shield):](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041)

<div class="topic-metadata">

**Author:** [@ankur.aggarwal](https://discuss.elastic.co/u/ankur.aggarwal)\
**Replies:** 27\
**Last updated:** [June 27, 2016, 7:42am UTC](https://discuss.elastic.co/t/solved-issue-in-ldap-group-authentication-shield/51041 "2016-06-27T07:42:19Z")

</div>

Shield v 2.3.2 If a add user in role\_mapping file , user can authenticate against LDAP: - "uid=testuser,ou=People,dc=company,dc=com"" But if a try to add group (to which this user is a member) i get an authentication e…

---

## [FortiGate Firewall](https://discuss.elastic.co/t/fortigate-firewall/129245)

<div class="topic-metadata">

**Author:** [@lcguy](https://discuss.elastic.co/u/lcguy)\
**Replies:** 10\
**Last updated:** [April 24, 2018, 3:37pm UTC](https://discuss.elastic.co/t/fortigate-firewall/129245 "2018-04-24T15:37:14Z")

</div>

Hi All, I am trying to parse the FortiGate firewall syslog in Logstash and still failing after spending many times. Need your expertise for standard FortiGate syslog logstash config. Here is current config. I'm gettin…

---

## [Datetime from sql to Timestamp logstash](https://discuss.elastic.co/t/datetime-from-sql-to-timestamp-logstash/117594)

<div class="topic-metadata">

**Author:** [@Anuar\_Mukatov](https://discuss.elastic.co/u/Anuar_Mukatov)\
**Replies:** 24\
**Last updated:** [February 7, 2018, 11:24am UTC](https://discuss.elastic.co/t/datetime-from-sql-to-timestamp-logstash/117594 "2018-02-07T11:24:02Z")

</div>

Hello everybody! Help me please with @timestamp, i have jdbc input with mssql server, and in my output i have variable - datetime, which include time of created table. How i can use it instead @timestamp? this is my co…

---

## [Kibana Source Installation gives Npm Error](https://discuss.elastic.co/t/kibana-source-installation-gives-npm-error/86065)

<div class="topic-metadata">

**Author:** [@FareehaNaaz](https://discuss.elastic.co/u/FareehaNaaz)\
**Replies:** 37\
**Last updated:** [June 6, 2017, 4:05am UTC](https://discuss.elastic.co/t/kibana-source-installation-gives-npm-error/86065 "2017-06-06T04:05:59Z")

</div>

Hi! i was working on kibana source installation and i went through the following steps: Install git from yum I installed Node.Js from https://nodejs.org/download/release/latest/ 3.git clone https://github.com/elastic/…

---

## [Kibana not able to save searches](https://discuss.elastic.co/t/kibana-not-able-to-save-searches/161464)

<div class="topic-metadata">

**Author:** [@osamaikhlas](https://discuss.elastic.co/u/osamaikhlas)\
**Replies:** 32\
**Last updated:** [January 1, 2019, 5:00am UTC](https://discuss.elastic.co/t/kibana-not-able-to-save-searches/161464 "2019-01-01T05:00:18Z")

</div>

Not able to save searches and can't edit in anything kibana. it gives me error forbidden error 403

---

## [Handshake failure (TransportClientNodesService: failed to connect to node)](https://discuss.elastic.co/t/handshake-failure-transportclientnodesservice-failed-to-connect-to-node/82787)

<div class="topic-metadata">

**Author:** [@esearch](https://discuss.elastic.co/u/esearch)\
**Replies:** 10\
**Last updated:** [April 21, 2017, 8:58pm UTC](https://discuss.elastic.co/t/handshake-failure-transportclientnodesservice-failed-to-connect-to-node/82787 "2017-04-21T20:58:53Z")

</div>

I'm a little stuck figuring out why I'm getting a handshake failure when trying to connect to ES. I ran ES with the following command: docker run -e ES\_JAVA\_OPTS='-Xms1g -Xmx1g' --name elasticsearch -e "http.host=0.0.…

---

## [Kibana Server :Authentication Exception](https://discuss.elastic.co/t/kibana-server-authentication-exception/55947)

<div class="topic-metadata">

**Author:** [@sukesh](https://discuss.elastic.co/u/sukesh)\
**Replies:** 12\
**Last updated:** [July 27, 2016, 5:19am UTC](https://discuss.elastic.co/t/kibana-server-authentication-exception/55947 "2016-07-27T05:19:31Z")

</div>

when I am trying to starting the kibana it is showing error like Authentication Exception C:\\Users\\483551\\Downloads\\kibana-4.5.0-windows\\kibana-4.5.0-windows\\bin\>kibana log \[12:34:17.608\] \[info\]\[status\]\[plugin:sens…

---

## [Convert MySQL query to elasticsearch](https://discuss.elastic.co/t/convert-mysql-query-to-elasticsearch/40830)

<div class="topic-metadata">

**Author:** [@Croos](https://discuss.elastic.co/u/Croos)\
**Replies:** 15\
**Last updated:** [February 12, 2016, 3:13pm UTC](https://discuss.elastic.co/t/convert-mysql-query-to-elasticsearch/40830 "2016-02-12T15:13:03Z")

</div>

Help me to convert this MySQL query to elasticsearch (json) query and how to visualize it on kibana. SELECT user, call\_date, sum(length\_in\_sec) as 'work\_time', (max(end\_epoch)-min(start\_epoch))-sum(length\_i…

---

## [Error: No matching indices found: No indices match pattern "filebeat-\*"](https://discuss.elastic.co/t/error-no-matching-indices-found-no-indices-match-pattern-filebeat/103675)

<div class="topic-metadata">

**Author:** [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Replies:** 15\
**Last updated:** [October 19, 2017, 12:52pm UTC](https://discuss.elastic.co/t/error-no-matching-indices-found-no-indices-match-pattern-filebeat/103675 "2017-10-19T12:52:49Z")

</div>

No matching indices found: No indices match pattern "filebeat-\*" Less Info OK Error: No matching indices found: No indices match pattern "filebeat-\*" at http://localhost:5601/bundles/kibana.bundle.js?v=15976:231:2635…

---

## [Elastic Agent not sending Data](https://discuss.elastic.co/t/elastic-agent-not-sending-data/245728)

<div class="topic-metadata">

**Author:** [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Replies:** 18\
**Last updated:** [November 2, 2020, 8:00pm UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data/245728 "2020-11-02T20:00:44Z")

</div>

So I upgraded my stack to 7.9 last night to try out elastic security, but thing is I am able to enroll the agent usings fleets update the configurations and all but my agent is not able to send any data to elasticsearch,…

---

## [Not able to start elasticsearch due to failed memory lock](https://discuss.elastic.co/t/not-able-to-start-elasticsearch-due-to-failed-memory-lock/158009)

<div class="topic-metadata">

**Author:** [@frasmd](https://discuss.elastic.co/u/frasmd)\
**Replies:** 11\
**Last updated:** [November 26, 2018, 11:13am UTC](https://discuss.elastic.co/t/not-able-to-start-elasticsearch-due-to-failed-memory-lock/158009 "2018-11-26T11:13:19Z")

</div>

I am trying to install elasticstash 6.2.4 using RPMs. When i was tring to start service i was was getting below errors my elasticsearch logs. \[2\] bootstrap checks failed \[1\]: memory locking requested for elasticsearch …

---

## [Trying to setup winlogbeat to ship windows events to working ELK stack](https://discuss.elastic.co/t/trying-to-setup-winlogbeat-to-ship-windows-events-to-working-elk-stack/52624)

<div class="topic-metadata">

**Author:** [@iqbal\_nazir](https://discuss.elastic.co/u/iqbal_nazir)\
**Replies:** 19\
**Last updated:** [June 16, 2016, 10:13am UTC](https://discuss.elastic.co/t/trying-to-setup-winlogbeat-to-ship-windows-events-to-working-elk-stack/52624 "2016-06-16T10:13:30Z")

</div>

Hello, I have a working ELK server on Ubuntu 16.04. I have another ubuntu 14.04 which is sending logs to my ELK successfully. Now, I want to add a windows client to my ELK which will send its events to ELK. To do so, I'm…

---

## [Delete elasticsearch document with logstash-jdbc-input](https://discuss.elastic.co/t/delete-elasticsearch-document-with-logstash-jdbc-input/47490)

<div class="topic-metadata">

**Author:** [@suntuo](https://discuss.elastic.co/u/suntuo)\
**Replies:** 12\
**Last updated:** [January 19, 2017, 1:43am UTC](https://discuss.elastic.co/t/delete-elasticsearch-document-with-logstash-jdbc-input/47490 "2017-01-19T01:43:48Z")

</div>

Insert and update work with below config file but elasticseach has no response as i excute delete-sql on mysql input { jdbc { jdbc\_driver\_library =\> "/opt/logstash-2.2.2/mysql-connector-java-5.1.38/mysql-connecto…

---

## [Dropdown filter kibana canvas](https://discuss.elastic.co/t/dropdown-filter-kibana-canvas/187082)

<div class="topic-metadata">

**Author:** [@wadhah](https://discuss.elastic.co/u/wadhah)\
**Replies:** 15\
**Last updated:** [July 10, 2019, 7:14pm UTC](https://discuss.elastic.co/t/dropdown-filter-kibana-canvas/187082 "2019-07-10T19:14:21Z")

</div>

Helo, I have a question please : I am at the moment working on a canvas dashboard and I am using a dropdown column that I want it to be applied properly on the whole canvas dashboard knowing that I am querying data from…

---

## ["service logstash start" does not work](https://discuss.elastic.co/t/service-logstash-start-does-not-work/83002)

<div class="topic-metadata">

**Author:** [@X\_Calibur](https://discuss.elastic.co/u/X_Calibur)\
**Replies:** 14\
**Last updated:** [April 24, 2017, 12:12pm UTC](https://discuss.elastic.co/t/service-logstash-start-does-not-work/83002 "2017-04-24T12:12:38Z")

</div>

Hi, I have Ubuntu 16.10 and the latest Logstash installed. Running Logstash manually with /usr/share/logstash/bin/logstash "--path.settings" "/etc/logstash" works just fine but I'm unable to run it as a service. Any h…

---

## [Best practices: CPU core count vs. no. active shards per node](https://discuss.elastic.co/t/best-practices-cpu-core-count-vs-no-active-shards-per-node/180638)

<div class="topic-metadata">

**Author:** [@IanRC72](https://discuss.elastic.co/u/IanRC72)\
**Replies:** 19\
**Last updated:** [May 12, 2019, 12:02pm UTC](https://discuss.elastic.co/t/best-practices-cpu-core-count-vs-no-active-shards-per-node/180638 "2019-05-12T12:02:55Z")

</div>

I've been reading Amazon's ES best practices guide here. Crunching the numbers, they are suggesting 2.56 cores per active shard. This reference recommends a 1:1 ratio. What does Elastic say about this? If I have say 1…

---

## [Logstash is very slow in sending the data to elasticsearch](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130)

<div class="topic-metadata">

**Author:** [@anisen](https://discuss.elastic.co/u/anisen)\
**Replies:** 17\
**Last updated:** [January 24, 2017, 11:14am UTC](https://discuss.elastic.co/t/logstash-is-very-slow-in-sending-the-data-to-elasticsearch/72130 "2017-01-24T11:14:56Z")

</div>

Hi, I am parsing an IIS log-file which is in below format: 2014-07-12:00:08:54 100.200.50.0 GET /mypath/mypage.asmx - 80 - 100.100.50.0 Mozilla/4.1+(compatible;+MSIE+4.01;+Windows+NT;+MS+Search+8.0+Robot) - 403 0 0 3…

---

## [Authentication of \[elastic\] was terminated by realm \[reserved\]](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved/275072)

<div class="topic-metadata">

**Author:** [@Akanksha\_Pandey](https://discuss.elastic.co/u/Akanksha_Pandey)\
**Replies:** 14\
**Last updated:** [June 7, 2021, 2:28pm UTC](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved/275072 "2021-06-07T14:28:09Z")

</div>

My ELK stack version is 7.9.2 My aim is to enable authentication in Kibana login page but I'm not able to do that. I'm alays directed to the dashboard directly and it never asks for username and password ELK servers ar…

---

## [Can't start filebeat with TLS configured](https://discuss.elastic.co/t/cant-start-filebeat-with-tls-configured/40594)

<div class="topic-metadata">

**Author:** [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Replies:** 18\
**Last updated:** [February 5, 2016, 3:01pm UTC](https://discuss.elastic.co/t/cant-start-filebeat-with-tls-configured/40594 "2016-02-05T15:01:04Z")

</div>

Hey guys, I'm trying to setup my first filebeat forwarder after having used logstash-forwarder for quite a while. When I try to start up filebeat I'm getting this error: \`\[root@web1:/etc/filebeat\] #systemctl stat…

---

## [Replace @timestamp with some other field](https://discuss.elastic.co/t/replace-timestamp-with-some-other-field/28284)

<div class="topic-metadata">

**Author:** [@ajays](https://discuss.elastic.co/u/ajays)\
**Replies:** 10\
**Last updated:** [June 30, 2016, 7:18am UTC](https://discuss.elastic.co/t/replace-timestamp-with-some-other-field/28284 "2016-06-30T07:18:41Z")

</div>

Hi, I want to replace @timestamp with some other timestamp field having format like this 11/Jan/2014:05:06:24 +05:30. Can anybody please help? Regards, AjayS

---

## [UNASSIGNED ALLOCATION\_FAILED](https://discuss.elastic.co/t/unassigned-allocation-failed/229642)

<div class="topic-metadata">

**Author:** [@rnappert](https://discuss.elastic.co/u/rnappert)\
**Replies:** 18\
**Last updated:** [May 7, 2020, 12:19pm UTC](https://discuss.elastic.co/t/unassigned-allocation-failed/229642 "2020-05-07T12:19:45Z")

</div>

I have a Elasticsearch 6.2.3 setup (single node). The system was running smoothly for a period of time. Needed to expand the hard-drive, since the disk space was about to run out. After the expansion, Elasticsearch came …

---

## [How to send multiple log files to Kibana through logstash?](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101)

<div class="topic-metadata">

**Author:** [@tashinfrus](https://discuss.elastic.co/u/tashinfrus)\
**Replies:** 18\
**Last updated:** [May 23, 2016, 6:33am UTC](https://discuss.elastic.co/t/how-to-send-multiple-log-files-to-kibana-through-logstash/50101 "2016-05-23T06:33:53Z")

</div>

I am new to ELK and I want to send multiple files to Kibana using Logstash like apache access logs of different servers. How can I do that?

---

## [Kibana authentication when sharing the dashboard in web application](https://discuss.elastic.co/t/kibana-authentication-when-sharing-the-dashboard-in-web-application/44987)

<div class="topic-metadata">

**Author:** [@sriram](https://discuss.elastic.co/u/sriram)\
**Replies:** 28\
**Last updated:** [January 3, 2022, 1:34pm UTC](https://discuss.elastic.co/t/kibana-authentication-when-sharing-the-dashboard-in-web-application/44987 "2022-01-03T13:34:53Z")

</div>

Hi, cluster ID : cd59e4 want to show kibana dashboard in my webapplication. on opening kibana it is asking for authentication . I dont want my user to enter credentials again . and anonymous user is not secure ... c…

---

## [Logstash how to handle exceptions](https://discuss.elastic.co/t/logstash-how-to-handle-exceptions/37843)

<div class="topic-metadata">

**Author:** [@chicco\_95](https://discuss.elastic.co/u/chicco_95)\
**Replies:** 27\
**Last updated:** [January 7, 2016, 1:53pm UTC](https://discuss.elastic.co/t/logstash-how-to-handle-exceptions/37843 "2016-01-07T13:53:28Z")

</div>

Hi, i have a problem in managing exceptions in filter logstash. I have to define some dates which don't always show the same format and this causes the following error: Ruby exception occurred: invalid strptime format…

---

## [How to identify message causing error in bulk request](https://discuss.elastic.co/t/how-to-identify-message-causing-error-in-bulk-request/42885)

<div class="topic-metadata">

**Author:** [@unknownunknown](https://discuss.elastic.co/u/unknownunknown)\
**Replies:** 9\
**Last updated:** [February 28, 2016, 1:21am UTC](https://discuss.elastic.co/t/how-to-identify-message-causing-error-in-bulk-request/42885 "2016-02-28T01:21:08Z")

</div>

I'm using BulkProcessor. Something is causing a problem: \[elasticsearch\[moo\]\[transport\_client\_worker\]\[T#19\]{New I/O worker #84}\] ERROR - Failed to index record: MapperParsingException\[failed to parse \[\_source\]\]; nested…

---

## [Can’t merge a non object mapping with an object mapping error in machine learning(beta) module](https://discuss.elastic.co/t/can-t-merge-a-non-object-mapping-with-an-object-mapping-error-in-machine-learning-beta-module/93497)

<div class="topic-metadata">

**Author:** [@gautamv](https://discuss.elastic.co/u/gautamv)\
**Replies:** 9\
**Last updated:** [July 21, 2017, 8:36am UTC](https://discuss.elastic.co/t/can-t-merge-a-non-object-mapping-with-an-object-mapping-error-in-machine-learning-beta-module/93497 "2017-07-21T08:36:23Z")

</div>

Hi, I'm trying out the new machine learning module in x pack. I'm trying to identify rare response codes in HTTP Access logs in time. My logs are being stored in elasticsearch as below: { "\_index": "logstash-2017.0…

---

## [Kibana url gives connection refused from outside machine](https://discuss.elastic.co/t/kibana-url-gives-connection-refused-from-outside-machine/122067)

<div class="topic-metadata">

**Author:** [@Obay\_Abdelgader](https://discuss.elastic.co/u/Obay_Abdelgader)\
**Replies:** 9\
**Last updated:** [March 5, 2018, 8:31am UTC](https://discuss.elastic.co/t/kibana-url-gives-connection-refused-from-outside-machine/122067 "2018-03-05T08:31:42Z")

</div>

From localhost I can curl fine. But from my desktop curl gives connection refused. I have no firewall on the server. My kibana.yml file: server.host: "evm" logging.dest: /var/log/kibana/kibana.log I can open the lo…

---

## [How do you install Marvel in windows?](https://discuss.elastic.co/t/how-do-you-install-marvel-in-windows/37064)

<div class="topic-metadata">

**Author:** [@nqioweryuadfge](https://discuss.elastic.co/u/nqioweryuadfge)\
**Replies:** 40\
**Last updated:** [December 14, 2015, 9:54pm UTC](https://discuss.elastic.co/t/how-do-you-install-marvel-in-windows/37064 "2015-12-14T21:54:01Z")

</div>

How do you install Marvel in windows? Does it come before installing Elastic search or after? Also, I have tried installing Elasticsearch1.6.0, then I receive an article that says you have to install version 2.1.0. Whil…

---

## [SSH login attempts dashboard on kibana](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 27\
**Last updated:** [October 17, 2018, 8:28am UTC](https://discuss.elastic.co/t/ssh-login-attempts-dashboard-on-kibana/150837 "2018-10-17T08:28:44Z")

</div>

Hello Team, I am using ELK 6.4.0 and Beat (Filebeat, Metricbeat). My architecture is Filebeat-\>Logstash-\>Elasticsearch-\>Kibana. I am sending my auth.log using filebeat but i am not using filebeat system module. Because…

---

## [Logstash not indexing anything](https://discuss.elastic.co/t/logstash-not-indexing-anything/24844)

<div class="topic-metadata">

**Author:** [@simonrisberg](https://discuss.elastic.co/u/simonrisberg)\
**Replies:** 26\
**Last updated:** [September 24, 2015, 5:40am UTC](https://discuss.elastic.co/t/logstash-not-indexing-anything/24844 "2015-09-24T05:40:37Z")

</div>

Hello! I thought I had Logstash all figured out but apparently I don't. It worked fine for me up until today. It indexed the log files I wanted to but today it just won't index anything at all and in the log I keep getti…

---

## [All Rules are showing Failed](https://discuss.elastic.co/t/all-rules-are-showing-failed/264318)

<div class="topic-metadata">

**Author:** [@emmett.carey](https://discuss.elastic.co/u/emmett.carey)\
**Replies:** 28\
**Last updated:** [February 25, 2021, 5:16pm UTC](https://discuss.elastic.co/t/all-rules-are-showing-failed/264318 "2021-02-25T17:16:15Z")

</div>

Hi, I've recently set up Elastic Search and Kibana 7.11 and enrolled a VM via Fleet and Agent. In the process I set up a Policy and Assigned some detection rules as well as added the Security Endpoint Integration as we…

[Previous page](https://discuss.elastic.co/top.md?page=11&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=13&per_page=50&period=all)
