# Top

**URL:** https://discuss.elastic.co/top.md?page=16&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 17

---

## [Timeouts while deleting](https://discuss.elastic.co/t/timeouts-while-deleting/24564)

<div class="topic-metadata">

**Author:** [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Replies:** 26\
**Last updated:** [June 30, 2015, 9:46pm UTC](https://discuss.elastic.co/t/timeouts-while-deleting/24564 "2015-06-30T21:46:20Z")

</div>

Topic says it: org.elasticsearch.cluster.metadata.ProcessClusterEventTimeoutException: failed to process cluster event (delete-index \[logstash-2015.03.21\]) within 30s at org.elasticsearch.cluster.service.Intern…

---

## [Logstash Config File json](https://discuss.elastic.co/t/logstash-config-file-json/38911)

<div class="topic-metadata">

**Author:** [@jpsphar1](https://discuss.elastic.co/u/jpsphar1)\
**Replies:** 10\
**Last updated:** [November 22, 2016, 8:00am UTC](https://discuss.elastic.co/t/logstash-config-file-json/38911 "2016-11-22T08:00:03Z")

</div>

Having issues with the following config file after following a tutorial from someone on the web. Main goal was to take a json file and load into logstash and bring over all fields from the original json file. My input is…

---

## [Logstash is not start as expected](https://discuss.elastic.co/t/logstash-is-not-start-as-expected/36433)

<div class="topic-metadata">

**Author:** [@asifalis](https://discuss.elastic.co/u/asifalis)\
**Replies:** 17\
**Last updated:** [December 8, 2015, 6:02pm UTC](https://discuss.elastic.co/t/logstash-is-not-start-as-expected/36433 "2015-12-08T18:02:46Z")

</div>

Hi Expert, I installed Kibana 4.2 and Elasticsearch 2.1 and logstash 2.0, Kibana and elasticsearch working fine but logstash not working, the logstash.log \[root@centos logstash\]# tailf /var/log/logstash/logstash.log …

---

## [Action \[indices:admin/auto\_create\] is unauthorized for API key id \[####\] of user \[elastic/fleet-server\] on indices \[metricbeat-7.14.1-2021.09.08\], this action is granted by the index privileges \[auto\_configure,create\_index,manage,all\]](https://discuss.elastic.co/t/action-indices-admin-auto-create-is-unauthorized-for-api-key-id-of-user-elastic-fleet-server-on-indices-metricbeat-7-14-1-2021-09-08-this-action-is-granted-by-the-index-privileges-auto-configure-create-index-manage-all/283608)

<div class="topic-metadata">

**Author:** [@hamiland](https://discuss.elastic.co/u/hamiland)\
**Replies:** 29\
**Last updated:** [September 10, 2021, 7:16am UTC](https://discuss.elastic.co/t/action-indices-admin-auto-create-is-unauthorized-for-api-key-id-of-user-elastic-fleet-server-on-indices-metricbeat-7-14-1-2021-09-08-this-action-is-granted-by-the-index-privileges-auto-configure-create-index-manage-all/283608 "2021-09-10T07:16:16Z")

</div>

Hi All, I'm a bit green in the Elastic world so please bear with me. I have Fleet agents deployed to our Windows hosts, however I am having issues when Either "Collect Windows perfmon and service metrics" in the Window…

---

## [How to Make a Custom Date Range in a Kibana Visualization?](https://discuss.elastic.co/t/how-to-make-a-custom-date-range-in-a-kibana-visualization/27378)

<div class="topic-metadata">

**Author:** [@GordonM](https://discuss.elastic.co/u/GordonM)\
**Replies:** 9\
**Last updated:** [April 18, 2016, 10:54pm UTC](https://discuss.elastic.co/t/how-to-make-a-custom-date-range-in-a-kibana-visualization/27378 "2016-04-18T22:54:19Z")

</div>

I am trying to have a visualization (simple bar graph with a date histogram) display data in a date range with some date math applied, but when I try to add the appropriate JSON Input to the query, the query fails with a…

---

## [Search by phone number](https://discuss.elastic.co/t/search-by-phone-number/4873)

<div class="topic-metadata">

**Author:** [@Ian\_Eure](https://discuss.elastic.co/u/Ian_Eure)\
**Replies:** 13\
**Last updated:** [August 7, 2015, 10:26am UTC](https://discuss.elastic.co/t/search-by-phone-number/4873 "2015-08-07T10:26:14Z")

</div>

I'm having a hard time matching documents with a phone number, and I'm not sure what's going on. Some of my data has phone numbers separated with spaces: "phone": "+1 415 931 1182", Others have them with nothin…

---

## [Filebeat Multiline Java Stack Trace](https://discuss.elastic.co/t/filebeat-multiline-java-stack-trace/150003)

<div class="topic-metadata">

**Author:** [@luggo](https://discuss.elastic.co/u/luggo)\
**Replies:** 12\
**Last updated:** [November 7, 2018, 9:37am UTC](https://discuss.elastic.co/t/filebeat-multiline-java-stack-trace/150003 "2018-11-07T09:37:36Z")

</div>

Hey there, I try to find out how to use Filebeat for my Java Log files. Actually it's not a big deal, except for my problems with multiline messages, because my Java Logs include Stack Traces. Can someone help me to fi…

---

## [Excessive garbage collection](https://discuss.elastic.co/t/excessive-garbage-collection/127527)

<div class="topic-metadata">

**Author:** [@davidkarlsen](https://discuss.elastic.co/u/davidkarlsen)\
**Replies:** 10\
**Last updated:** [April 16, 2018, 6:36am UTC](https://discuss.elastic.co/t/excessive-garbage-collection/127527 "2018-04-16T06:36:32Z")

</div>

I have a very strange situation around GC: x-pack will report around 50% heap use, and based on the graphs in x-pack it seems to do a full gc around every hour, still I am experiencing performance problems and seeing: 2…

---

## [Include Fields in Watcher Email Alert](https://discuss.elastic.co/t/include-fields-in-watcher-email-alert/115700)

<div class="topic-metadata">

**Author:** [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Replies:** 18\
**Last updated:** [February 5, 2018, 10:59am UTC](https://discuss.elastic.co/t/include-fields-in-watcher-email-alert/115700 "2018-02-05T10:59:35Z")

</div>

Hi there, I have set up an advanced Watch and it triggers upon 3 or more of the same TargetUserName with the EventID:4625, basically that alerts on any user failing to logon 3 times in 3 minutes. Here is my body section…

---

## [Elasticsearch performance very slow!](https://discuss.elastic.co/t/elasticsearch-performance-very-slow/93272)

<div class="topic-metadata">

**Author:** [@ELK\_GB](https://discuss.elastic.co/u/ELK_GB)\
**Replies:** 12\
**Last updated:** [July 18, 2017, 11:53pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-very-slow/93272 "2017-07-18T23:53:25Z")

</div>

Hi All, This is the second time im posting this and i hope someone can provide some feedback on the reason for why data is slowly being available for me in Kibana. I have data that is supposed to be near real time but …

---

## [How to mapping a json field when using logstash?](https://discuss.elastic.co/t/how-to-mapping-a-json-field-when-using-logstash/47618)

<div class="topic-metadata">

**Author:** [@JvonRudno](https://discuss.elastic.co/u/JvonRudno)\
**Replies:** 11\
**Last updated:** [May 25, 2016, 10:10am UTC](https://discuss.elastic.co/t/how-to-mapping-a-json-field-when-using-logstash/47618 "2016-05-25T10:10:07Z")

</div>

Hi everybody!!! I have a postgres table that have a json field. it looks like this: customer\_id ==\> integer categories ==\> json ==\> please note that this field is type json and the table have some records like …

---

## [Filebeat error write:connection reset by peer](https://discuss.elastic.co/t/filebeat-error-write-connection-reset-by-peer/164782)

<div class="topic-metadata">

**Author:** [@kvaga](https://discuss.elastic.co/u/kvaga)\
**Replies:** 14\
**Last updated:** [January 21, 2019, 11:26am UTC](https://discuss.elastic.co/t/filebeat-error-write-connection-reset-by-peer/164782 "2019-01-21T11:26:11Z")

</div>

client - filebeat-6.5.4-1.x86\_64 Log - logstash-6.5.4-1.noarch logs from client 2019-01-18T13:56:20.033+0300 ERROR logstash/async.go:256 Failed to publish events caused by: write tcp 10.129.10.8:34714-\>10.129.1…

---

## [Logstash adding duplicate rows for every run](https://discuss.elastic.co/t/logstash-adding-duplicate-rows-for-every-run/44775)

<div class="topic-metadata">

**Author:** [@vikram\_yerneni](https://discuss.elastic.co/u/vikram_yerneni)\
**Replies:** 10\
**Last updated:** [March 28, 2016, 6:58pm UTC](https://discuss.elastic.co/t/logstash-adding-duplicate-rows-for-every-run/44775 "2016-03-28T18:58:39Z")

</div>

Hello World, We implemented a solution to push Microsoft SQL Data in form of simple rows from SQL Server to Logstash which will index the data to Elasticsearch. The data (SQL rows and columns) are getting successfully by…

---

## [How to parse JSON in syslog\_msg to fields?](https://discuss.elastic.co/t/how-to-parse-json-in-syslog-msg-to-fields/155762)

<div class="topic-metadata">

**Author:** [@sghosh001c](https://discuss.elastic.co/u/sghosh001c)\
**Replies:** 11\
**Last updated:** [November 16, 2018, 1:44pm UTC](https://discuss.elastic.co/t/how-to-parse-json-in-syslog-msg-to-fields/155762 "2018-11-16T13:44:22Z")

</div>

I have JSON data available as the value of "syslog\_msg". How can I parse those data as field so that we can create dashboard based on the fields? Here is Sample JSON data... {"serverName":"0c9663d6-ca18-4ac2-7b5e-1cc9"…

---

## [How to setup multiple input and output in Filebeat config?](https://discuss.elastic.co/t/how-to-setup-multiple-input-and-output-in-filebeat-config/163325)

<div class="topic-metadata">

**Author:** [@ronald8192](https://discuss.elastic.co/u/ronald8192)\
**Replies:** 11\
**Last updated:** [January 10, 2019, 8:25am UTC](https://discuss.elastic.co/t/how-to-setup-multiple-input-and-output-in-filebeat-config/163325 "2019-01-10T08:25:26Z")

</div>

I need to have 2 set of input files and output target in Filebeat config. My current filebeat.yml config looks like this: filebeat.inputs: - type: log enabled: true paths: - /path/to/log-1.log filebeat.config.m…

---

## [How to stop kibana in RHEL](https://discuss.elastic.co/t/how-to-stop-kibana-in-rhel/83494)

<div class="topic-metadata">

**Author:** [@bvnages](https://discuss.elastic.co/u/bvnages)\
**Replies:** 13\
**Last updated:** [April 25, 2017, 10:24am UTC](https://discuss.elastic.co/t/how-to-stop-kibana-in-rhel/83494 "2017-04-25T10:24:24Z")

</div>

How to stop kibana . We are download tar file and unzipped after i will run kibana. cd kibana/bin ./kibana Above start kibana. But how to stop kibana. Could you please tell me.

---

## [Logstash 5.1.1 - Couldn't find any filter plugin named 'multiline'](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263)

<div class="topic-metadata">

**Author:** [@MikeSiz](https://discuss.elastic.co/u/MikeSiz)\
**Replies:** 11\
**Last updated:** [January 30, 2017, 3:42pm UTC](https://discuss.elastic.co/t/logstash-5-1-1-couldnt-find-any-filter-plugin-named-multiline/71263 "2017-01-30T15:42:15Z")

</div>

Hi, I am trying to migrate from logstash 2.3.4 to newer 5.1.1. After default installation (registering logstash 5.1 repo and yum install logstash) I found that logstash cannot find "multiline' plugin. I tried: /usr/…

---

## [Convert two field string into a single field geo\_point](https://discuss.elastic.co/t/convert-two-field-string-into-a-single-field-geo-point/173498)

<div class="topic-metadata">

**Author:** [@Theoooooo](https://discuss.elastic.co/u/Theoooooo)\
**Replies:** 31\
**Last updated:** [April 1, 2019, 3:25pm UTC](https://discuss.elastic.co/t/convert-two-field-string-into-a-single-field-geo-point/173498 "2019-04-01T15:25:10Z")

</div>

Hello everyone, i'm currently struggling with geo coordinates in my elasticsearch and i can't find any solution to my problem. I'm using the ingest-geoip plugin which allow me to process the incoming logs and add geolo…

---

## ["now throttling indexing"](https://discuss.elastic.co/t/now-throttling-indexing/22650)

<div class="topic-metadata">

**Author:** [@Eric\_Jain](https://discuss.elastic.co/u/Eric_Jain)\
**Replies:** 12\
**Last updated:** [January 5, 2016, 11:26am UTC](https://discuss.elastic.co/t/now-throttling-indexing/22650 "2016-01-05T11:26:45Z")

</div>

I set \`indices.store.throttle.type: none\` in the elasticsearch.yml, and yet this shows up in the logs: now throttling indexing: numMergesInFlight=5, maxNumMerges=4 stop throttling indexing: numMergesInFlight=3,…

---

## ["unable to find usable node.js executable" \[SOLVED\]](https://discuss.elastic.co/t/unable-to-find-usable-node-js-executable-solved/43264)

<div class="topic-metadata">

**Author:** [@dr01](https://discuss.elastic.co/u/dr01)\
**Replies:** 14\
**Last updated:** [September 28, 2016, 2:02pm UTC](https://discuss.elastic.co/t/unable-to-find-usable-node-js-executable-solved/43264 "2016-09-28T14:02:39Z")

</div>

Hello all, I've successfully installed ES 1.4.2 with Kibana 3.1.2 on a 64-bit Windows 7 Pro machine (for testing reasons I need to install this specific old version). Entering the directory c:\\elasticsearch-1.4.2\\bin\\k…

---

## [How to add hostname to logs that normally do not contain hostname?](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-that-normally-do-not-contain-hostname/54173)

<div class="topic-metadata">

**Author:** [@Michael1](https://discuss.elastic.co/u/Michael1)\
**Replies:** 13\
**Last updated:** [June 30, 2016, 9:54am UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-that-normally-do-not-contain-hostname/54173 "2016-06-30T09:54:52Z")

</div>

I am trying to send SharePoint logs to Logstash and the typical SharePoint logs do not contain the server name. Would I have to do this somewhere in the Beats config, or?

---

## [How to create visualization on the fly using a script](https://discuss.elastic.co/t/how-to-create-visualization-on-the-fly-using-a-script/31255)

<div class="topic-metadata">

**Author:** [@abhijitdeka11](https://discuss.elastic.co/u/abhijitdeka11)\
**Replies:** 11\
**Last updated:** [April 25, 2016, 2:18pm UTC](https://discuss.elastic.co/t/how-to-create-visualization-on-the-fly-using-a-script/31255 "2016-04-25T14:18:33Z")

</div>

Hi, I have some requirement where I need to create different visualization for different users which will differ very slightly on the query param.So, I am considering to create a script which will enable me to do this.…

---

## [How to collect all types of logs from my fortinet firewall using ELK](https://discuss.elastic.co/t/how-to-collect-all-types-of-logs-from-my-fortinet-firewall-using-elk/296830)

<div class="topic-metadata">

**Author:** [@randyvinoth](https://discuss.elastic.co/u/randyvinoth)\
**Replies:** 20\
**Last updated:** [March 16, 2022, 4:20am UTC](https://discuss.elastic.co/t/how-to-collect-all-types-of-logs-from-my-fortinet-firewall-using-elk/296830 "2022-03-16T04:20:54Z")

</div>

I configured Elasticsearch, Logstash and Kibana after lots of errors. I also configured my fortinet firewall for syslogd server to send the logs to ELK server. But I am not getting any data from my firewall. Also I confi…

---

## [P12 certificate is protected by password](https://discuss.elastic.co/t/p12-certificate-is-protected-by-password/157120)

<div class="topic-metadata">

**Author:** [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Replies:** 14\
**Last updated:** [November 21, 2018, 3:35am UTC](https://discuss.elastic.co/t/p12-certificate-is-protected-by-password/157120 "2018-11-21T03:35:36Z")

</div>

Hi all , My ES cluster containing 3 Master and 2 Data nodes. I have 5 p12 certificates for SSL. All p12 certificates are password protected. May I use these password protected certificates in cluster . When I am enab…

---

## [Struggling to parse JSON key/value pairs](https://discuss.elastic.co/t/struggling-to-parse-json-key-value-pairs/42400)

<div class="topic-metadata">

**Author:** [@StephenGoodall](https://discuss.elastic.co/u/StephenGoodall)\
**Replies:** 16\
**Last updated:** [June 29, 2016, 11:39am UTC](https://discuss.elastic.co/t/struggling-to-parse-json-key-value-pairs/42400 "2016-06-29T11:39:59Z")

</div>

Hi, I'm struggling to parse a JSON Log4J2 output as the context map (MDC) looks to be stored as an array of JSON (i think!). Whats the best way of taking the KV pairs out of this: {"timeMillis":1456156644547,"thread":"…

---

## [Loading many (big) json files into elasticsearch](https://discuss.elastic.co/t/loading-many-big-json-files-into-elasticsearch/128078)

<div class="topic-metadata">

**Author:** [@nkaenzig](https://discuss.elastic.co/u/nkaenzig)\
**Replies:** 13\
**Last updated:** [April 25, 2018, 8:20pm UTC](https://discuss.elastic.co/t/loading-many-big-json-files-into-elasticsearch/128078 "2018-04-25T20:20:00Z")

</div>

Dear community, I have about 1TB of data splitted into many smaller .json files in newline delimited JSON (NDJSON) format. The sizes of the .json files vary between 500MB and 20GB. The files are too big to load using t…

---

## [Subquery with elasticsearch](https://discuss.elastic.co/t/subquery-with-elasticsearch/119832)

<div class="topic-metadata">

**Author:** [@sabdoul](https://discuss.elastic.co/u/sabdoul)\
**Replies:** 10\
**Last updated:** [February 16, 2018, 4:57pm UTC](https://discuss.elastic.co/t/subquery-with-elasticsearch/119832 "2018-02-16T16:57:04Z")

</div>

Hello, how to simulate this subquery with elasticsearch: Select NOM from Table where NOM not in (select NOM from Table where Prenom='Paul') Thanks!

---

## [Recommended ELK architecture for production?](https://discuss.elastic.co/t/recommended-elk-architecture-for-production/62747)

<div class="topic-metadata">

**Author:** [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Replies:** 14\
**Last updated:** [November 3, 2016, 9:35pm UTC](https://discuss.elastic.co/t/recommended-elk-architecture-for-production/62747 "2016-11-03T21:35:43Z")

</div>

Is there a recommended "minimal" ELK architecture for production? I know, I know, this depends In my case, I want to set up a central ELK stack where we can send our application logs (via rsyslog) to the stack. Here i…

---

## [Post-upgrade issues: 6.4.2 ES heap running away (6.5.0 too)](https://discuss.elastic.co/t/post-upgrade-issues-6-4-2-es-heap-running-away-6-5-0-too/151096)

<div class="topic-metadata">

**Author:** [@hollowimage](https://discuss.elastic.co/u/hollowimage)\
**Replies:** 41\
**Last updated:** [December 13, 2018, 2:11am UTC](https://discuss.elastic.co/t/post-upgrade-issues-6-4-2-es-heap-running-away-6-5-0-too/151096 "2018-12-13T02:11:59Z")

</div>

I have recently upgraded my cluster from 6.2.3 --\> 6.4.2 (all components: elasticsearch, logstash, kibana) Ever since then, we've been having issues with the heap space running out. I have trimmed down indices all over…

---

## [Filebeat service could not start](https://discuss.elastic.co/t/filebeat-service-could-not-start/66079)

<div class="topic-metadata">

**Author:** [@VijayKarthikeyan](https://discuss.elastic.co/u/VijayKarthikeyan)\
**Replies:** 9\
**Last updated:** [November 17, 2016, 9:22am UTC](https://discuss.elastic.co/t/filebeat-service-could-not-start/66079 "2016-11-17T09:22:54Z")

</div>

Hi, Am using filebeat to read log files and stash it in elasticsearch. But am not able to start the service of filebeat. As am new to ELK, I followed the instructions given in the guide and it says the below command …

---

## [Getting "master not discovered or elected yet, an election requires at least 2 nodes" after enabling SSL/HTTPS](https://discuss.elastic.co/t/getting-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-after-enabling-ssl-https/296950)

<div class="topic-metadata">

**Author:** [@cgnusr01](https://discuss.elastic.co/u/cgnusr01)\
**Replies:** 10\
**Last updated:** [February 16, 2022, 8:11am UTC](https://discuss.elastic.co/t/getting-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-after-enabling-ssl-https/296950 "2022-02-16T08:11:54Z")

</div>

I recently upgraded Elastic from version: 7.2 to version 7.16.1 with a rolling update and there were no problems. After some time and after following the instructions here: Set up basic security for the Elastic Stack | E…

---

## [Creating geoip data for internal networks](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729)

<div class="topic-metadata">

**Author:** [@JimCheetham](https://discuss.elastic.co/u/JimCheetham)\
**Replies:** 11\
**Last updated:** [May 15, 2017, 11:42pm UTC](https://discuss.elastic.co/t/creating-geoip-data-for-internal-networks/729 "2017-05-15T23:42:48Z")

</div>

I have many internal users, and both public and private address space in use. I would like to be able to usefully separate my networks from the country we're in, and provide sensible geoip data. For my public range, I …

---

## [Unable to start Elasticsearch - java.lang.IllegalStateException: Duplicate key org.elasticsearch.plugins.PluginsService$Bundle@e3623fe](https://discuss.elastic.co/t/unable-to-start-elasticsearch-java-lang-illegalstateexception-duplicate-key-org-elasticsearch-plugins-pluginsservice-bundle-e3623fe/170847)

<div class="topic-metadata">

**Author:** [@subhas](https://discuss.elastic.co/u/subhas)\
**Replies:** 30\
**Last updated:** [April 25, 2019, 12:11pm UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-java-lang-illegalstateexception-duplicate-key-org-elasticsearch-plugins-pluginsservice-bundle-e3623fe/170847 "2019-04-25T12:11:24Z")

</div>

After server reboot, elasticsearch fails to restart. I use only 2 plugins namely ingest-geoip and ingest-user-agent. Same issue is coming when i try to uninstall and install them again. Below is the error log - \[2019-03…

---

## [Kibana - Error: EACCES: permission denied, open '/etc/kibana/kibana.yml'](https://discuss.elastic.co/t/kibana-error-eacces-permission-denied-open-etc-kibana-kibana-yml/291117)

<div class="topic-metadata">

**Author:** [@Peter\_M](https://discuss.elastic.co/u/Peter_M)\
**Replies:** 14\
**Last updated:** [December 7, 2021, 2:16pm UTC](https://discuss.elastic.co/t/kibana-error-eacces-permission-denied-open-etc-kibana-kibana-yml/291117 "2021-12-07T14:16:13Z")

</div>

Hey all, Fairly new to setting up Kibana, we are setting up on a test environment at the moment, an azure vm using CentOs. We installed Elasticseach and Kibana with Ansible playbooks, during some troubleshooting we had…

---

## [Filebeat configuration option 'tail\_files'](https://discuss.elastic.co/t/filebeat-configuration-option-tail-files/43084)

<div class="topic-metadata">

**Author:** [@Augustin\_Chen](https://discuss.elastic.co/u/Augustin_Chen)\
**Replies:** 12\
**Last updated:** [May 30, 2016, 8:29am UTC](https://discuss.elastic.co/t/filebeat-configuration-option-tail-files/43084 "2016-05-30T08:29:24Z")

</div>

I am working on the filebeat 1.1.1. The following is the snippet of the configuation file. I assume the filebeat reads from the end of the log files as the 'tail\_files' is true. But it seems the filebeat doesn't work as …

---

## [Packetbeat Error: x509 Certificate is valid for X, not Y](https://discuss.elastic.co/t/packetbeat-error-x509-certificate-is-valid-for-x-not-y/116121)

<div class="topic-metadata">

**Author:** [@adam.wendling](https://discuss.elastic.co/u/adam.wendling)\
**Replies:** 12\
**Last updated:** [January 31, 2018, 5:47pm UTC](https://discuss.elastic.co/t/packetbeat-error-x509-certificate-is-valid-for-x-not-y/116121 "2018-01-31T17:47:41Z")

</div>

I had packetbeat running no problem until I introduced SSL into the mix. I changed my server name in the mix of this. Packetbeat is looking for the certificate for "oldeservername" and I need it to be "newservername". Th…

---

## [Logstash array length check](https://discuss.elastic.co/t/logstash-array-length-check/39681)

<div class="topic-metadata">

**Author:** [@bubu.senapati](https://discuss.elastic.co/u/bubu.senapati)\
**Replies:** 14\
**Last updated:** [May 3, 2017, 10:22am UTC](https://discuss.elastic.co/t/logstash-array-length-check/39681 "2017-05-03T10:22:55Z")

</div>

Hi , How can i check the length of an array in logstash. I have a request that is request=/acoounts/debenhams/summary. I had split it by "/". I have to check the request.length i.e. the array size of the splitted array r…

---

## [Upload log file in elasticsearch using logstash](https://discuss.elastic.co/t/upload-log-file-in-elasticsearch-using-logstash/163736)

<div class="topic-metadata">

**Author:** [@Bhavesh\_Padharia](https://discuss.elastic.co/u/Bhavesh_Padharia)\
**Replies:** 10\
**Last updated:** [January 11, 2019, 10:54am UTC](https://discuss.elastic.co/t/upload-log-file-in-elasticsearch-using-logstash/163736 "2019-01-11T10:54:07Z")

</div>

Hello Everyone , i am new in elasticsearch I try to upload log file in elasticsearch using logstash i use this curl command system@system-VirtualBox:~/Downloads/logstash-6.5.4$ curl -s -XPOST localhost:9200/\_bulk --…

---

## [Elasticsearch cluster setup with 3 nodes](https://discuss.elastic.co/t/elasticsearch-cluster-setup-with-3-nodes/310238)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 15\
**Last updated:** [July 24, 2022, 10:29pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-setup-with-3-nodes/310238 "2022-07-24T22:29:59Z")

</div>

Hi, I am trying to setup elastic-search 8.3 cluster with 3 nodes(2 master, 1 data node) in VMWare(ubuntu os) (IP's - 192.168.15.11(master), 192.168.15.12(master), 192.168.15.13). Below is the elasticsearch.yml file fr…

---

## [Visualization of lat lon coordinates on Kibana's graph](https://discuss.elastic.co/t/visualization-of-lat-lon-coordinates-on-kibanas-graph/106177)

<div class="topic-metadata">

**Author:** [@citanionarrei](https://discuss.elastic.co/u/citanionarrei)\
**Replies:** 17\
**Last updated:** [November 8, 2017, 10:49am UTC](https://discuss.elastic.co/t/visualization-of-lat-lon-coordinates-on-kibanas-graph/106177 "2017-11-08T10:49:22Z")

</div>

hi i have a problem i have log files with two fields: "lat" and "lon" \[Screenshot (8)\] and this error on kibana visualization "the "meetup-\*" index pattern does not contain any of the following field types: geo\_poin…

---

## [Using logstash, How to filter Errors only from logs?](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234)

<div class="topic-metadata">

**Author:** [@devalkars](https://discuss.elastic.co/u/devalkars)\
**Replies:** 9\
**Last updated:** [July 25, 2018, 11:56am UTC](https://discuss.elastic.co/t/using-logstash-how-to-filter-errors-only-from-logs/43234 "2018-07-25T11:56:22Z")

</div>

Hi, I am using logstash in our project, How to filter Errors only from logs ? i am using below configuration: input { file { path =\> "D:/apache-tomcat-7.0.67/logs/cpe.log" start\_position =\> "beginning" …

---

## [How to search for a complete URL and Create a Visualization for counts](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114)

<div class="topic-metadata">

**Author:** [@Sameer\_Panicker](https://discuss.elastic.co/u/Sameer_Panicker)\
**Replies:** 13\
**Last updated:** [May 19, 2016, 4:34pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-complete-url-and-create-a-visualization-for-counts/44114 "2016-05-19T16:34:38Z")

</div>

I am not able to search for URL since it has slashes. i.e. https://123.123.123/MyService/api/calls Also, How can I create a visualization for searched URL counts i.e. how many times a particular URL was invoked ? So t…

---

## [Make .p12 to .pem for kibana](https://discuss.elastic.co/t/make-p12-to-pem-for-kibana/183231)

<div class="topic-metadata">

**Author:** [@Min\_Mah](https://discuss.elastic.co/u/Min_Mah)\
**Replies:** 14\
**Last updated:** [May 29, 2019, 8:38am UTC](https://discuss.elastic.co/t/make-p12-to-pem-for-kibana/183231 "2019-05-29T08:38:34Z")

</div>

Hi, i have a question for continue my work I'm using ES 7.1, Kb 7.1 I want to encrypting kibana communication for using https I was using .p12(pkcs#12) in elasticsearch, but kibana can't support that. so i need to .…

---

## [Logstash и JSON](https://discuss.elastic.co/t/logstash-json/75314)

<div class="topic-metadata">

**Author:** [@cwt](https://discuss.elastic.co/u/cwt)\
**Replies:** 41\
**Last updated:** [April 28, 2017, 3:55pm UTC](https://discuss.elastic.co/t/logstash-json/75314 "2017-04-28T15:55:17Z")

</div>

У нас все логи веб-приложений пишутся в JSON, при этом "кто в лес кто по дрова". Собирается все на центральный сервер syslog-ng который переодически перестает работать из-за лимита json ключей 65к. Пытаюсь скормить такой…

---

## [Error: Kibana server is not ready yet](https://discuss.elastic.co/t/error-kibana-server-is-not-ready-yet/327488)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 18\
**Last updated:** [March 12, 2023, 11:29pm UTC](https://discuss.elastic.co/t/error-kibana-server-is-not-ready-yet/327488 "2023-03-12T23:29:39Z")

</div>

Hello. I'm running Elasticsearch and Kibana via docker containers, whose images I'm building from the Dockerfiles from this repository: GitHub - elastic/dockerfiles: Dockerfiles for the official Elastic Stack images. Whe…

---

## [Transport.go:125: ERR SSL client failed to connect with: EOF](https://discuss.elastic.co/t/transport-go-125-err-ssl-client-failed-to-connect-with-eof/35272)

<div class="topic-metadata">

**Author:** [@Marco](https://discuss.elastic.co/u/Marco)\
**Replies:** 13\
**Last updated:** [May 12, 2016, 5:00pm UTC](https://discuss.elastic.co/t/transport-go-125-err-ssl-client-failed-to-connect-with-eof/35272 "2016-05-12T17:00:44Z")

</div>

I want to migrate from Logstash Forwarder to Filebeat. In my filebeat.yml filebeat: prospectors: - paths: - /var/log/nginxlog/access.20151102.log field: type: nginxaccesslog inpu…

---

## [Logstash with zabbix output ISSUE](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434)

<div class="topic-metadata">

**Author:** [@Cenzoooo](https://discuss.elastic.co/u/Cenzoooo)\
**Replies:** 27\
**Last updated:** [August 17, 2015, 3:50pm UTC](https://discuss.elastic.co/t/logstash-with-zabbix-output-issue/1434 "2015-08-17T15:50:49Z")

</div>

Hello! I have problem, my zabbix output just don't work and i can't find reason why. For example, i've created simple logstash conf file: input { tcp { port =\> 6000 type =\> syslog } udp { port =\> 6…

---

## [Unable to start Elasticsearch after clean installation (CentOS or Ubuntu)](https://discuss.elastic.co/t/unable-to-start-elasticsearch-after-clean-installation-centos-or-ubuntu/208181)

<div class="topic-metadata">

**Author:** [@theo1](https://discuss.elastic.co/u/theo1)\
**Replies:** 21\
**Last updated:** [November 19, 2019, 1:52am UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-after-clean-installation-centos-or-ubuntu/208181 "2019-11-19T01:52:37Z")

</div>

I've installed Elasticsearch on a clean, new, updated build of CentOS (7.7.1908). This installation is in support of a Wazuh installation using instructions found here: https://documentation.wazuh.com/3.10/installation-…

---

## [Curl request return 404 (Not Found)](https://discuss.elastic.co/t/curl-request-return-404-not-found/57043)

<div class="topic-metadata">

**Author:** [@michele\_crudele](https://discuss.elastic.co/u/michele_crudele)\
**Replies:** 10\
**Last updated:** [November 23, 2016, 10:53pm UTC](https://discuss.elastic.co/t/curl-request-return-404-not-found/57043 "2016-11-23T22:53:34Z")

</div>

I'm experiencing a strange problem trying to run an aggregation search through kibana. If I run this: curl -H"kbn-version:4.5.0" -H"content-type:application/json" -d'{ "size": 0, "aggs": { …

---

## [Version conflict (409) question](https://discuss.elastic.co/t/version-conflict-409-question/311335)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 10\
**Last updated:** [August 30, 2022, 11:43pm UTC](https://discuss.elastic.co/t/version-conflict-409-question/311335 "2022-08-30T23:43:48Z")

</div>

Is version conflict bulk write error (409) only occur when I'm updating the same document from 2 different writers? I am starting to see this error more often in our system and trying to figure out if our data pattern h…

[Previous page](https://discuss.elastic.co/top.md?page=15&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=17&per_page=50&period=all)
