# Top

**URL:** https://discuss.elastic.co/top.md?page=13&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 14

---

## ["failed to connect node" Transport Client](https://discuss.elastic.co/t/failed-to-connect-node-transport-client/85163)

<div class="topic-metadata">

**Author:** [@froufrou2224](https://discuss.elastic.co/u/froufrou2224)\
**Replies:** 16\
**Last updated:** [May 18, 2017, 1:12pm UTC](https://discuss.elastic.co/t/failed-to-connect-node-transport-client/85163 "2017-05-18T13:12:06Z")

</div>

Hello ! For my studies, I need to use ElasticSearch in Java, creating a project with Maven. I've got a problem with my Transport Client. I don't know if my installation is correct, so tell me if there's something wrong…

---

## [Master not discovered yet, this node has not previously joined a bootstrapped (v7+) cluster, and \[cluster.initial\_master\_nodes\] is empty on this node](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-v7-cluster-and-cluster-initial-master-nodes-is-empty-on-this-node/177649)

<div class="topic-metadata">

**Author:** [@meiyuan](https://discuss.elastic.co/u/meiyuan)\
**Replies:** 14\
**Last updated:** [April 26, 2019, 8:47pm UTC](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-v7-cluster-and-cluster-initial-master-nodes-is-empty-on-this-node/177649 "2019-04-26T20:47:08Z")

</div>

Hi, we just moved to Elasticseach 7.0.0. We're running into issues shown as below: \[2019-04-18T00:02:49,213\]\[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[dev-efk-backend03\] master not discovered yet, this node has no…

---

## [Marking url as dead. Last error: \[LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError\] Elasticsearch Unreachable](https://discuss.elastic.co/t/marking-url-as-dead-last-error-logstash-hostunreachableerror-elasticsearch-unreachable/162761)

<div class="topic-metadata">

**Author:** [@arun5635](https://discuss.elastic.co/u/arun5635)\
**Replies:** 29\
**Last updated:** [January 4, 2019, 10:19am UTC](https://discuss.elastic.co/t/marking-url-as-dead-last-error-logstash-hostunreachableerror-elasticsearch-unreachable/162761 "2019-01-04T10:19:44Z")

</div>

Hi I am not able to send the data to my AWS -ES . I am getting the below error \[logstash.outputs.elasticsearch\] Marking url as dead. Last error: \[LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableError\]…

---

## [Java high level rest client: how to deal with aggregations?](https://discuss.elastic.co/t/java-high-level-rest-client-how-to-deal-with-aggregations/112667)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 9\
**Last updated:** [January 2, 2018, 7:20am UTC](https://discuss.elastic.co/t/java-high-level-rest-client-how-to-deal-with-aggregations/112667 "2018-01-02T07:20:58Z")

</div>

Hi, I am trying out the high level java client for elasticsearch. I managed on a simple test to query some records, but I do not get the aggregations running. As I understand I need to put a query and the aggregation …

---

## [Setting up a multi-nodes cluster on a single machine ( 1 elasticsearch.yml file )](https://discuss.elastic.co/t/setting-up-a-multi-nodes-cluster-on-a-single-machine-1-elasticsearch-yml-file/272286)

<div class="topic-metadata">

**Author:** [@Catalin](https://discuss.elastic.co/u/Catalin)\
**Replies:** 15\
**Last updated:** [May 13, 2021, 9:02pm UTC](https://discuss.elastic.co/t/setting-up-a-multi-nodes-cluster-on-a-single-machine-1-elasticsearch-yml-file/272286 "2021-05-13T21:02:04Z")

</div>

I have been using elasticsearch for development on my local machine and managed to setup a 3 nodes cluster by starting each node with the following command: elasticsearch -Epath.data=data1 -Epath.logs=log1 -Enode.name=n…

---

## [Loading JSON-LD into ES](https://discuss.elastic.co/t/loading-json-ld-into-es/19970)

<div class="topic-metadata">

**Author:** [@abo](https://discuss.elastic.co/u/abo)\
**Replies:** 21\
**Last updated:** [February 6, 2019, 3:23am UTC](https://discuss.elastic.co/t/loading-json-ld-into-es/19970 "2019-02-06T03:23:59Z")

</div>

Hello, I'm new to Elasticsearch, so forgive me if this is a basic question or if it's in some documentation that I haven't read... I am trying to load a json-ld file into ES. The json-ld file was generated from…

---

## [Pipelines or "if else" conditions for output](https://discuss.elastic.co/t/pipelines-or-if-else-conditions-for-output/124372)

<div class="topic-metadata">

**Author:** [@phil.zac](https://discuss.elastic.co/u/phil.zac)\
**Replies:** 12\
**Last updated:** [March 29, 2018, 2:41pm UTC](https://discuss.elastic.co/t/pipelines-or-if-else-conditions-for-output/124372 "2018-03-29T14:41:14Z")

</div>

Hi, I am using elasticsearch-5.6.1 kibana-5.6.1 logstash-5.6.1 metricbeat-5.6.1 packetbeat-5.6.1 x-pack-5.6.1 for Windows Server 2012 R2 My issue - I cant figure out how to make multiple output for logstash.co…

---

## [Logstash to PostgreSQL as output](https://discuss.elastic.co/t/logstash-to-postgresql-as-output/93500)

<div class="topic-metadata">

**Author:** [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)\
**Replies:** 9\
**Last updated:** [August 2, 2017, 10:25pm UTC](https://discuss.elastic.co/t/logstash-to-postgresql-as-output/93500 "2017-08-02T22:25:34Z")

</div>

Does anyone tried to output data logs to PostgreSQL? Right now my output is Elasticsearch and I want that every time a data will be output to elasticsearch, it will also output to PostreSQL

---

## [Logstash grok filter for apache customized logs](https://discuss.elastic.co/t/logstash-grok-filter-for-apache-customized-logs/92915)

<div class="topic-metadata">

**Author:** [@marcelo](https://discuss.elastic.co/u/marcelo)\
**Replies:** 11\
**Last updated:** [July 15, 2017, 3:17am UTC](https://discuss.elastic.co/t/logstash-grok-filter-for-apache-customized-logs/92915 "2017-07-15T03:17:20Z")

</div>

Hi guys, I'm trying to use the elk to generate dashboards of apache access logs. However I can't split up in various fields the message field. It turns out that my apache access logs are a little customized because I …

---

## [Logstash requires setting a file](https://discuss.elastic.co/t/logstash-requires-setting-a-file/64658)

<div class="topic-metadata">

**Author:** [@w0lverine](https://discuss.elastic.co/u/w0lverine)\
**Replies:** 10\
**Last updated:** [February 28, 2017, 6:28pm UTC](https://discuss.elastic.co/t/logstash-requires-setting-a-file/64658 "2017-02-28T18:28:39Z")

</div>

Logstash Info error: A setting file is missing I installed the deb file of logstash 5.0 and I starting logstash for the first time. I get an INFO error: INFO: Logstash requires a setting file which is typically locate…

---

## [Speed limitations of filebeat?](https://discuss.elastic.co/t/speed-limitations-of-filebeat/46818)

<div class="topic-metadata">

**Author:** [@jclose](https://discuss.elastic.co/u/jclose)\
**Replies:** 13\
**Last updated:** [April 26, 2017, 10:12am UTC](https://discuss.elastic.co/t/speed-limitations-of-filebeat/46818 "2017-04-26T10:12:44Z")

</div>

We are trying to use Filebeat in front of our ELK stack, feeding it logs from network sensors. We have some particularly 'talky' logs coming out of a system. One of the logs can generate 15k lines per second (eps), and…

---

## [Can’t start logstash after x-pack installation](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353)

<div class="topic-metadata">

**Author:** [@GSCully](https://discuss.elastic.co/u/GSCully)\
**Replies:** 17\
**Last updated:** [February 6, 2018, 3:43pm UTC](https://discuss.elastic.co/t/can-t-start-logstash-after-x-pack-installation/115353 "2018-02-06T15:43:26Z")

</div>

I have this issue now as well, I had logstash running and connecting without issue, after installing x-pack it is now looking at localhost for elastic which doesn't exist. Elastic 6.1.1, logstash 6.1.1 Windows 2012R2. …

---

## [Searching not analyzed term name and value in case insensitive manner](https://discuss.elastic.co/t/searching-not-analyzed-term-name-and-value-in-case-insensitive-manner/50537)

<div class="topic-metadata">

**Author:** [@nrmohta](https://discuss.elastic.co/u/nrmohta)\
**Replies:** 24\
**Last updated:** [May 2, 2017, 2:43pm UTC](https://discuss.elastic.co/t/searching-not-analyzed-term-name-and-value-in-case-insensitive-manner/50537 "2017-05-02T14:43:49Z")

</div>

Searching term name and value in case insensitive manner Present structure - Field Mapping: "NAME": { "type": "string", "index": "not\_analyzed", "store": true …

---

## [Failed to process cluster event (create-index-template) within 30s](https://discuss.elastic.co/t/failed-to-process-cluster-event-create-index-template-within-30s/199486)

<div class="topic-metadata">

**Author:** [@usr20190913](https://discuss.elastic.co/u/usr20190913)\
**Replies:** 23\
**Last updated:** [September 17, 2019, 2:21pm UTC](https://discuss.elastic.co/t/failed-to-process-cluster-event-create-index-template-within-30s/199486 "2019-09-17T14:21:55Z")

</div>

First post. History This is our production instance and it has been down now for 5 days I have inherited a system that has been running for years without issue. The system has not been updated, so I find it very surpr…

---

## [Configure Elastic APM for Tomcat](https://discuss.elastic.co/t/configure-elastic-apm-for-tomcat/146608)

<div class="topic-metadata">

**Author:** [@Senz79](https://discuss.elastic.co/u/Senz79)\
**Replies:** 23\
**Last updated:** [September 3, 2018, 10:59am UTC](https://discuss.elastic.co/t/configure-elastic-apm-for-tomcat/146608 "2018-09-03T10:59:08Z")

</div>

Hello I want to configure APM for Spring Web MVC with Tomcat and Jetty. The build generates a .WAR file. The current approach needs APM agent to be attached with standalone application with .JAR. Please suggest. Thank…

---

## [Logstash without SSL?](https://discuss.elastic.co/t/logstash-without-ssl/732)

<div class="topic-metadata">

**Author:** [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Replies:** 14\
**Last updated:** [March 19, 2016, 2:01am UTC](https://discuss.elastic.co/t/logstash-without-ssl/732 "2016-03-19T02:01:40Z")

</div>

Hi, I want to know whether we can ship logs to logstash without SSL? is there any way to disable SSL and then configure logstash and forwarder without SSL certificates? br, Sunil

---

## [Minimum and Maximum date in Elasticsearch](https://discuss.elastic.co/t/minimum-and-maximum-date-in-elasticsearch/7239)

<div class="topic-metadata">

**Author:** [@vijuitech](https://discuss.elastic.co/u/vijuitech)\
**Replies:** 23\
**Last updated:** [April 20, 2012, 3:52am UTC](https://discuss.elastic.co/t/minimum-and-maximum-date-in-elasticsearch/7239 "2012-04-20T03:52:21Z")

</div>

Hi, Is there any alternative in elasticsearch for the MySqlQuery SELECT MIN(Date) AS MINDATE, MAX(Date) AS MAXDATE, HOUR(Date) FROM TableName; How can I get the minimum or maximum date in elasticsearch? Chee…

---

## [Kibana service running but port 5601 not opened](https://discuss.elastic.co/t/kibana-service-running-but-port-5601-not-opened/223415)

<div class="topic-metadata">

**Author:** [@mohmmadyahya](https://discuss.elastic.co/u/mohmmadyahya)\
**Replies:** 12\
**Last updated:** [March 16, 2020, 2:54pm UTC](https://discuss.elastic.co/t/kibana-service-running-but-port-5601-not-opened/223415 "2020-03-16T14:54:48Z")

</div>

I'm new to kibana and I'm facing a problem I'm following https://digitalave.github.io/spring/2020/01/15/Install-and-configre-wazuh-security-monitoring-and-detection-system.html tutorial to setup everything my kibana.yml …

---

## [How to run logstash as a service in CentOS](https://discuss.elastic.co/t/how-to-run-logstash-as-a-service-in-centos/140461)

<div class="topic-metadata">

**Author:** [@ramanna\_hk](https://discuss.elastic.co/u/ramanna_hk)\
**Replies:** 11\
**Last updated:** [July 19, 2018, 6:23am UTC](https://discuss.elastic.co/t/how-to-run-logstash-as-a-service-in-centos/140461 "2018-07-19T06:23:52Z")

</div>

I am able to run logstash successfully using below: /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/app.conf But it is not working, when i run following commands /usr/share/logstash/bin/logstash -f /etc/logst…

---

## [Case sensitivity in ES](https://discuss.elastic.co/t/case-sensitivity-in-es/7918)

<div class="topic-metadata">

**Author:** [@Kara](https://discuss.elastic.co/u/Kara)\
**Replies:** 10\
**Last updated:** [September 22, 2014, 4:24am UTC](https://discuss.elastic.co/t/case-sensitivity-in-es/7918 "2014-09-22T04:24:57Z")

</div>

Can someone refer me to a good documentation where it shows how to enable the ES case sensitivity. I need to integrate it with my Java client where I only issue queries. Thanks, Karine

---

## [SOLVED! Error "Request to Elasticsearch failed: "Bad Request"" after upgrading ES to 5.5.1](https://discuss.elastic.co/t/solved-error-request-to-elasticsearch-failed-bad-request-after-upgrading-es-to-5-5-1/96556)

<div class="topic-metadata">

**Author:** [@JR\_FFM](https://discuss.elastic.co/u/JR_FFM)\
**Replies:** 9\
**Last updated:** [August 25, 2017, 7:45am UTC](https://discuss.elastic.co/t/solved-error-request-to-elasticsearch-failed-bad-request-after-upgrading-es-to-5-5-1/96556 "2017-08-25T07:45:44Z")

</div>

Hello, I’m new in this forum and not very familiar with Elasticsearch and Kibana. After upgrading our Elasticsearch-system to 5.5.1 I get the following error-message in Kibana when I try to access the “winlogbeat-\*”-da…

---

## [Filtering nested objects](https://discuss.elastic.co/t/filtering-nested-objects/291911)

<div class="topic-metadata">

**Author:** [@dev\_test](https://discuss.elastic.co/u/dev_test)\
**Replies:** 11\
**Last updated:** [January 7, 2022, 3:45pm UTC](https://discuss.elastic.co/t/filtering-nested-objects/291911 "2022-01-07T15:45:10Z")

</div>

Hi, I'm trying to build a system that will have a user's phone book in nested field and this will have user\_id and user\_gender. I am trying to filter over gender in search result but i'm only getting the whole nested obj…

---

## [How to get rid of deleted documents and reclaim disk space?](https://discuss.elastic.co/t/how-to-get-rid-of-deleted-documents-and-reclaim-disk-space/303184)

<div class="topic-metadata">

**Author:** [@rgelb](https://discuss.elastic.co/u/rgelb)\
**Replies:** 14\
**Last updated:** [May 3, 2022, 4:09pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-deleted-documents-and-reclaim-disk-space/303184 "2022-05-03T16:09:19Z")

</div>

I have a bunch of indexes with a massive amount of deleted documents. I've tried running POST /\_forcemerge?only\_expunge\_deletes=true multiple times, but it doesn't seem to do anything. The command returns Gateway Ti…

---

## [Logstash with x-pack authentication problems](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897)

<div class="topic-metadata">

**Author:** [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Replies:** 9\
**Last updated:** [March 31, 2017, 1:44am UTC](https://discuss.elastic.co/t/logstash-with-x-pack-authentication-problems/77897 "2017-03-31T01:44:14Z")

</div>

I have x-pack installed and I keep getting errors in the logstash log WARN \]\[logstash.outputs.elasticsearch\] Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>#\<URI::HTTP:0xa3a53ec URL:htt…

---

## [How to Compare two different fields value of two different index?](https://discuss.elastic.co/t/how-to-compare-two-different-fields-value-of-two-different-index/132533)

<div class="topic-metadata">

**Author:** [@addanuj](https://discuss.elastic.co/u/addanuj)\
**Replies:** 17\
**Last updated:** [May 24, 2018, 9:44pm UTC](https://discuss.elastic.co/t/how-to-compare-two-different-fields-value-of-two-different-index/132533 "2018-05-24T21:44:18Z")

</div>

please guide me.. please guide me to the following problem, I have two different index and i want to compare two fields value and get result which exist in different index for example :- Index 1: threatintel fields :…

---

## [Replace @timestamp with source log timestamp](https://discuss.elastic.co/t/replace-timestamp-with-source-log-timestamp/162346)

<div class="topic-metadata">

**Author:** [@wholzgruber](https://discuss.elastic.co/u/wholzgruber)\
**Replies:** 26\
**Last updated:** [January 23, 2019, 6:23pm UTC](https://discuss.elastic.co/t/replace-timestamp-with-source-log-timestamp/162346 "2019-01-23T18:23:07Z")

</div>

Dear Community, I´m quite new in ELK and also here in the community. So at first hi everybody! I´ve spent a couple of hours by solving this issue. A lot of ther topics here in the community had simmilar issues. But th…

---

## [Specifying \_type with Filebeat](https://discuss.elastic.co/t/specifying--type-with-filebeat/94957)

<div class="topic-metadata">

**Author:** [@spur01](https://discuss.elastic.co/u/spur01)\
**Replies:** 13\
**Last updated:** [July 28, 2017, 8:47pm UTC](https://discuss.elastic.co/t/specifying--type-with-filebeat/94957 "2017-07-28T20:47:36Z")

</div>

I’m at a bit of a loss on how to do this correctly. I have a Filebeat pushing to a pipeline which targets an index that has dynamic mapping set to false and a type that enforces strict mapping. The type I’m using is no…

---

## [Unable to "import" json file into ES2.1](https://discuss.elastic.co/t/unable-to-import-json-file-into-es2-1/35857)

<div class="topic-metadata">

**Author:** [@oguchi](https://discuss.elastic.co/u/oguchi)\
**Replies:** 21\
**Last updated:** [December 6, 2015, 10:11am UTC](https://discuss.elastic.co/t/unable-to-import-json-file-into-es2-1/35857 "2015-12-06T10:11:36Z")

</div>

Why does this not work in ES2.1?: curl -XPOST "http://localhos:9200/\_bulk" --data-binary @I:\\ES\\flu\_tweet\_file.json {"create": {"index": "flu", "type": "tweets", "\_id": 1}} \\n {"title": "flu tweets"} \\n (note: the js…

---

## [Migrate dashboards from Kibana3 to Kibana4](https://discuss.elastic.co/t/migrate-dashboards-from-kibana3-to-kibana4/837)

<div class="topic-metadata">

**Author:** [@vvanhollebeke](https://discuss.elastic.co/u/vvanhollebeke)\
**Replies:** 18\
**Last updated:** [July 5, 2017, 6:04am UTC](https://discuss.elastic.co/t/migrate-dashboards-from-kibana3-to-kibana4/837 "2017-07-05T06:04:39Z")

</div>

Hi, We are currently using Kibana 3 in my company. We plan to migrate to Kibana4 to benefit new improvements when building dashboards. My question is : How to migrate my old Kibana 3 dashboards to Kibana 4 ? Vincen…

---

## [Can't access 9300 port](https://discuss.elastic.co/t/cant-access-9300-port/179281)

<div class="topic-metadata">

**Author:** [@yyfdayin](https://discuss.elastic.co/u/yyfdayin)\
**Replies:** 14\
**Last updated:** [May 6, 2019, 1:39pm UTC](https://discuss.elastic.co/t/cant-access-9300-port/179281 "2019-05-06T13:39:05Z")

</div>

I got two problems here. My CentOS version: 3.10.0-957.12.1.el7.x86\_64. I can't use 6.x and 7.0.0 elasticsearch on my system, but 5.x is OK! as you can see, here is something different between. ES02 will stop itself…

---

## [Not getting correct results when using special characters in query string](https://discuss.elastic.co/t/not-getting-correct-results-when-using-special-characters-in-query-string/169372)

<div class="topic-metadata">

**Author:** [@\_Shyam](https://discuss.elastic.co/u/_Shyam)\
**Replies:** 14\
**Last updated:** [February 25, 2019, 9:38am UTC](https://discuss.elastic.co/t/not-getting-correct-results-when-using-special-characters-in-query-string/169372 "2019-02-25T09:38:33Z")

</div>

Hi am new to elastic search and trying to use query string as below but not getting the excat matches if use special characters GET\_search { "query": { "bool": { "must": { …

---

## [Filebeat as a non-root user](https://discuss.elastic.co/t/filebeat-as-a-non-root-user/58946)

<div class="topic-metadata">

**Author:** [@lrem006](https://discuss.elastic.co/u/lrem006)\
**Replies:** 13\
**Last updated:** [August 31, 2016, 1:42am UTC](https://discuss.elastic.co/t/filebeat-as-a-non-root-user/58946 "2016-08-31T01:42:42Z")

</div>

Trying to get filebeat to run as a non-root user on a rpm distro. So far this is what I have: created a user useradd filebeat -u 5044 -c "Filebeat Service Account" -d /dev/null -s /sbin/nologin edited the filebe…

---

## [How to add another node to existingt cluster](https://discuss.elastic.co/t/how-to-add-another-node-to-existingt-cluster/94855)

<div class="topic-metadata">

**Author:** [@shyamalaponnada](https://discuss.elastic.co/u/shyamalaponnada)\
**Replies:** 14\
**Last updated:** [August 3, 2017, 6:42pm UTC](https://discuss.elastic.co/t/how-to-add-another-node-to-existingt-cluster/94855 "2017-08-03T18:42:38Z")

</div>

HI, I have already one under cluster.Now i would like to add one more to the same cluster.I have made few changes in .yml file.but still new node is not added.Please find .yml file below; NOTE: Elasticsearch comes …

---

## [Endpoint agent consistent 90+% CPU for some PCs](https://discuss.elastic.co/t/endpoint-agent-consistent-90-cpu-for-some-pcs/260693)

<div class="topic-metadata">

**Author:** [@The1WhoPrtNocks](https://discuss.elastic.co/u/The1WhoPrtNocks)\
**Replies:** 15\
**Last updated:** [February 17, 2021, 4:03pm UTC](https://discuss.elastic.co/t/endpoint-agent-consistent-90-cpu-for-some-pcs/260693 "2021-02-17T16:03:37Z")

</div>

Hi, I have recently been rolling our the Elastic Endpoint Agent to some clients for testing. As part of the policy they are pushed Endpoint Security, System and Windows. For certain clients they are getting consistent…

---

## [Embed kibana dashboard/visualizations on an external webpage as iFrame](https://discuss.elastic.co/t/embed-kibana-dashboard-visualizations-on-an-external-webpage-as-iframe/256279)

<div class="topic-metadata">

**Author:** [@Gokul6](https://discuss.elastic.co/u/Gokul6)\
**Replies:** 14\
**Last updated:** [December 17, 2020, 12:38pm UTC](https://discuss.elastic.co/t/embed-kibana-dashboard-visualizations-on-an-external-webpage-as-iframe/256279 "2020-12-17T12:38:43Z")

</div>

I am doing these below mentioned steps Create a visualization, apply the filters, then save the visualization Click "Share" at the top Copy the iframe code Paste the iframe code into your external HTML. when i paste t…

---

## [Trying to setup elasticsearch cluster with docker-compose](https://discuss.elastic.co/t/trying-to-setup-elasticsearch-cluster-with-docker-compose/106803)

<div class="topic-metadata">

**Author:** [@hanase](https://discuss.elastic.co/u/hanase)\
**Replies:** 9\
**Last updated:** [November 17, 2017, 2:32am UTC](https://discuss.elastic.co/t/trying-to-setup-elasticsearch-cluster-with-docker-compose/106803 "2017-11-17T02:32:05Z")

</div>

Hi, My environment is two physical machine, both running in docker-compose. I want to create elasticsearch cluster cross two docker container. here's my configure: ES1: IP: 10.251.34.60 docker-compose.yml: version…

---

## [Squid access.log \> filebeat \> logstash \> elasticsearch](https://discuss.elastic.co/t/squid-access-log-filebeat-logstash-elasticsearch/46672)

<div class="topic-metadata">

**Author:** [@Ashvin\_Meetoo](https://discuss.elastic.co/u/Ashvin_Meetoo)\
**Replies:** 14\
**Last updated:** [April 13, 2016, 5:26am UTC](https://discuss.elastic.co/t/squid-access-log-filebeat-logstash-elasticsearch/46672 "2016-04-13T05:26:38Z")

</div>

Hello, I am a rookie, please bear with me. I need to parse squid3's access.log to elasticsearch, I have searched on the web to no avail. I am looking for a working example (all latest version es 2.3 etc.) of: filebea…

---

## [The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call. Some functionality may not be compatible if the server is running an unsupported product](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call-some-functionality-may-not-be-compatible-if-the-server-is-running-an-unsupported-product/310969)

<div class="topic-metadata">

**Author:** [@shashi1](https://discuss.elastic.co/u/shashi1)\
**Replies:** 10\
**Last updated:** [July 29, 2022, 1:09pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call-some-functionality-may-not-be-compatible-if-the-server-is-running-an-unsupported-product/310969 "2022-07-29T13:09:39Z")

</div>

Invalid NEST response built from a unsuccessful () low level call on POST: /client/az30268j/\_search?pretty=true&error\_trace=true&typed\_keys=true Audit trail of this API call: \[1\] ProductCheckOnStartup: Took: 00:00:00.7…

---

## [Grok Parsing failure](https://discuss.elastic.co/t/grok-parsing-failure/73981)

<div class="topic-metadata">

**Author:** [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Replies:** 11\
**Last updated:** [February 6, 2017, 6:03pm UTC](https://discuss.elastic.co/t/grok-parsing-failure/73981 "2017-02-06T18:03:41Z")

</div>

I am getting into Logstash files from Filebeat, grok them and insert into Elasticsearch. As my log file contains various formats I created 6 different groks, all in the same "if" on the type of the input and in each gro…

---

## [Can Kibana make Interactive Forms](https://discuss.elastic.co/t/can-kibana-make-interactive-forms/40834)

<div class="topic-metadata">

**Author:** [@usahitya](https://discuss.elastic.co/u/usahitya)\
**Replies:** 11\
**Last updated:** [January 13, 2017, 12:07am UTC](https://discuss.elastic.co/t/can-kibana-make-interactive-forms/40834 "2017-01-13T00:07:41Z")

</div>

Hi Buddies, Is it possible to create interactive forms in Kibana Dashboard? For example where a user can enter something and that is fed to a search query. I know it is relatively easy to create this in Splunk. Right n…

---

## [Discover tab won't load anymore](https://discuss.elastic.co/t/discover-tab-wont-load-anymore/38549)

<div class="topic-metadata">

**Author:** [@TheShanMan](https://discuss.elastic.co/u/TheShanMan)\
**Replies:** 25\
**Last updated:** [January 16, 2017, 10:04pm UTC](https://discuss.elastic.co/t/discover-tab-wont-load-anymore/38549 "2017-01-16T22:04:46Z")

</div>

Kibana was working fine and all of a sudden the Discover tab stopped working. In my chrome dev tools console I get: PUT http://mfs-tcmetrics:5601/elasticsearch/.kibana/\_mapping/search 400 (Bad Request) and: Error: …

---

## [Cannot create index pattern](https://discuss.elastic.co/t/cannot-create-index-pattern/136458)

<div class="topic-metadata">

**Author:** [@carlnordling](https://discuss.elastic.co/u/carlnordling)\
**Replies:** 13\
**Last updated:** [June 19, 2018, 3:36pm UTC](https://discuss.elastic.co/t/cannot-create-index-pattern/136458 "2018-06-19T15:36:42Z")

</div>

Hi, I have used logstash with jdbc to transfer data from a mySQL databse to ES. However when I try to create an index pattern in Kibana I get the following error-message: "Could not locate that index-pattern (id: false…

---

## [Is it possible to send gzip compressed requests to ES?](https://discuss.elastic.co/t/is-it-possible-to-send-gzip-compressed-requests-to-es/10859)

<div class="topic-metadata">

**Author:** [@C\_Keser](https://discuss.elastic.co/u/C_Keser)\
**Replies:** 9\
**Last updated:** [February 24, 2013, 12:20pm UTC](https://discuss.elastic.co/t/is-it-possible-to-send-gzip-compressed-requests-to-es/10859 "2013-02-24T12:20:08Z")

</div>

Hi, I have a visual query generator in my application from which user can generate complex and large ES queries. As these queries may be quite large (a few megabytes), I want to compress the search request I'm sen…

---

## [Conditional colouring using kibana canvas expression editor](https://discuss.elastic.co/t/conditional-colouring-using-kibana-canvas-expression-editor/177929)

<div class="topic-metadata">

**Author:** [@ksunil](https://discuss.elastic.co/u/ksunil)\
**Replies:** 18\
**Last updated:** [July 7, 2019, 7:01am UTC](https://discuss.elastic.co/t/conditional-colouring-using-kibana-canvas-expression-editor/177929 "2019-07-07T07:01:33Z")

</div>

Hi, I have an metric element called "Memory%", now would like to display the metric value in different colours based on the value. If the value is greater than 75% and less than 90% want to display the value in amber co…

---

## [Parse json data from log file into Kibana via Filebeat and Logstash](https://discuss.elastic.co/t/parse-json-data-from-log-file-into-kibana-via-filebeat-and-logstash/228627)

<div class="topic-metadata">

**Author:** [@theFatCat](https://discuss.elastic.co/u/theFatCat)\
**Replies:** 9\
**Last updated:** [April 21, 2020, 9:17am UTC](https://discuss.elastic.co/t/parse-json-data-from-log-file-into-kibana-via-filebeat-and-logstash/228627 "2020-04-21T09:17:06Z")

</div>

I am using Filebeat and Logstash for parsing json log file into Kibana. filebeat.inputs: - type: log enabled: true paths: - /home/tiennd/filebeat/logstash/\*.json json.keys\_under\_root: true processors: - add…

---

## [Convert uppercase in lowercase](https://discuss.elastic.co/t/convert-uppercase-in-lowercase/90416)

<div class="topic-metadata">

**Author:** [@erion](https://discuss.elastic.co/u/erion)\
**Replies:** 12\
**Last updated:** [June 22, 2017, 1:44pm UTC](https://discuss.elastic.co/t/convert-uppercase-in-lowercase/90416 "2017-06-22T13:44:59Z")

</div>

Hi, i've tried to convert field.keyword in lowrcase by using this mapping: filter { mutate { lowercase =\> { match =\> \[ "request"\] } } grok { match =\> { "message" =\> '%{IPORHOST:clien…

---

## [Unable to create client connect; SSL certificate verify failed](https://discuss.elastic.co/t/unable-to-create-client-connect-ssl-certificate-verify-failed/229352)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 41\
**Last updated:** [May 13, 2020, 8:17pm UTC](https://discuss.elastic.co/t/unable-to-create-client-connect-ssl-certificate-verify-failed/229352 "2020-05-13T20:17:44Z")

</div>

I have read posts reading this issue but not sure if its a python- curator version issue here or certificate. I want no ssl\_validate but still curator throws an error while verifying the certificate. Below is the error a…

---

## [Unable to make a field aggregatable in kibana](https://discuss.elastic.co/t/unable-to-make-a-field-aggregatable-in-kibana/161912)

<div class="topic-metadata">

**Author:** [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Replies:** 26\
**Last updated:** [December 28, 2018, 8:03pm UTC](https://discuss.elastic.co/t/unable-to-make-a-field-aggregatable-in-kibana/161912 "2018-12-28T20:03:08Z")

</div>

I have a field called "message" . I need to make it as aggregatable. I am unable to do so . Can someone please suggest how to achieve that.

---

## [Filebeat 5.0 with multiline, split event data to two events](https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380)

<div class="topic-metadata">

**Author:** [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)\
**Replies:** 37\
**Last updated:** [October 30, 2016, 2:46pm UTC](https://discuss.elastic.co/t/filebeat-5-0-with-multiline-split-event-data-to-two-events/60380 "2016-10-30T14:46:00Z")

</div>

Hi, I am testing to use Filebeat against direct Ingest Node. The filebeat reads multiline events. Sometimes there is a cut in an event (A Java stack trace), which splits into two events. The first part, will suit the G…

---

## [How to filter only error from log file](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591)

<div class="topic-metadata">

**Author:** [@baha1](https://discuss.elastic.co/u/baha1)\
**Replies:** 9\
**Last updated:** [June 9, 2017, 11:54am UTC](https://discuss.elastic.co/t/how-to-filter-only-error-from-log-file/88591 "2017-06-09T11:54:27Z")

</div>

Hi community, i have a log file contains INFO,WARN and ERROR like : 17:37:17,103 ERROR \[org.apache.catalina.core.ContainerBase.\[jboss.web\].\[default-host\].....rest of text. what is the convenient grok to filter only A…

[Previous page](https://discuss.elastic.co/top.md?page=12&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=14&per_page=50&period=all)
