# Top

**URL:** https://discuss.elastic.co/top.md?page=17&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 18

---

## [Not enough active copies to meet write consistency of \[ALL\]](https://discuss.elastic.co/t/not-enough-active-copies-to-meet-write-consistency-of-all/44663)

<div class="topic-metadata">

**Author:** [@sumanbn](https://discuss.elastic.co/u/sumanbn)\
**Replies:** 19\
**Last updated:** [April 1, 2016, 12:47pm UTC](https://discuss.elastic.co/t/not-enough-active-copies-to-meet-write-consistency-of-all/44663 "2016-04-01T12:47:02Z")

</div>

I have set Conssistency level to "writeConsistencyLevel.ALL" But when trying to write , i get belo exception: ! org.elasticsearch.action.UnavailableShardsException: \[app-names\]\[0\] Not enough active copies to meet write…

---

## [Slow terms aggregation speed on ~130M documents](https://discuss.elastic.co/t/slow-terms-aggregation-speed-on-130m-documents/118759)

<div class="topic-metadata">

**Author:** [@jdgenio](https://discuss.elastic.co/u/jdgenio)\
**Replies:** 33\
**Last updated:** [May 10, 2019, 6:58pm UTC](https://discuss.elastic.co/t/slow-terms-aggregation-speed-on-130m-documents/118759 "2019-05-10T18:58:04Z")

</div>

Environment: ES version: 5.3 Data nodes: 3 We are trying to, through elasticsearch, provide users pregenerated suggestions based on the current dataset (130M documents). The target is to get all unique values of a cer…

---

## [Input 'aws-s3' failed with: failed to initialize s3 poller](https://discuss.elastic.co/t/input-aws-s3-failed-with-failed-to-initialize-s3-poller/288130)

<div class="topic-metadata">

**Author:** [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Replies:** 50\
**Last updated:** [December 15, 2021, 3:05am UTC](https://discuss.elastic.co/t/input-aws-s3-failed-with-failed-to-initialize-s3-poller/288130 "2021-12-15T03:05:25Z")

</div>

Hi, I've been trying to setup AWS module on 7.15 Elastic Stack cluster running as containers to ingest cloudtrail, cloudwatch, elb, s3access and vpcflow events (configured only for cloudtrail atm). However, there seems…

---

## [Create Index with filebeat](https://discuss.elastic.co/t/create-index-with-filebeat/211964)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 14\
**Last updated:** [January 25, 2020, 6:27am UTC](https://discuss.elastic.co/t/create-index-with-filebeat/211964 "2020-01-25T06:27:01Z")

</div>

Hello , I want to create a index and push data directly to elasticsearch with filebeat but i am not able to create a index its showing me the error can someone help me out. Exiting: setup.template.name and setup.templa…

---

## [Kibana 4.2 server memory usage](https://discuss.elastic.co/t/kibana-4-2-server-memory-usage/33575)

<div class="topic-metadata">

**Author:** [@PSi\_AU](https://discuss.elastic.co/u/PSi_AU)\
**Replies:** 14\
**Last updated:** [December 22, 2016, 9:46pm UTC](https://discuss.elastic.co/t/kibana-4-2-server-memory-usage/33575 "2016-12-22T21:46:32Z")

</div>

Is anyone else seeing insane memory growth of the Kibana 4.2 node process serverside? I restarted it before going to bed where it starts at just over 100MB, left it going overnight without touching the browser side at al…

---

## [Logstash taking too long to process data](https://discuss.elastic.co/t/logstash-taking-too-long-to-process-data/72096)

<div class="topic-metadata">

**Author:** [@jstar](https://discuss.elastic.co/u/jstar)\
**Replies:** 21\
**Last updated:** [February 2, 2017, 10:09pm UTC](https://discuss.elastic.co/t/logstash-taking-too-long-to-process-data/72096 "2017-02-02T22:09:41Z")

</div>

Hi, I have setup the following architecture filebeat -\> kafka -\> logstash -\> elasticsearch. Filebeat is sending data to kafka without any issue. I can validate that by using the command line of kafka. Logstash is consu…

---

## [After changing port number in Elasticsearch.yml file its get Failed to start Elasticsearch](https://discuss.elastic.co/t/after-changing-port-number-in-elasticsearch-yml-file-its-get-failed-to-start-elasticsearch/227115)

<div class="topic-metadata">

**Author:** [@MdRashid](https://discuss.elastic.co/u/MdRashid)\
**Replies:** 23\
**Last updated:** [April 17, 2020, 7:47am UTC](https://discuss.elastic.co/t/after-changing-port-number-in-elasticsearch-yml-file-its-get-failed-to-start-elasticsearch/227115 "2020-04-17T07:47:48Z")

</div>

Elasticsearch v7.5.2 (I'm using it) Changing Port from 9200 to 9300 See below images you will get understand why i am facing this issue for the past 3 days i want to give port number of 9300 instead of 9200 in elastic…

---

## [Localhost:9200: nodename nor servname provided, or not known](https://discuss.elastic.co/t/localhost-nodename-nor-servname-provided-or-not-known/186173)

<div class="topic-metadata">

**Author:** [@sneup](https://discuss.elastic.co/u/sneup)\
**Replies:** 15\
**Last updated:** [June 22, 2019, 2:56am UTC](https://discuss.elastic.co/t/localhost-nodename-nor-servname-provided-or-not-known/186173 "2019-06-22T02:56:36Z")

</div>

I am running elastic search version 6.4 locally and my dependency for the spring boot application is implementation 'org.elasticsearch.client:elasticsearch-rest-high-level-client:6.4.0' . I am getting java.io.IOException…

---

## [Use jvm.options or ES\_JAVA\_OPTS to configure the JVM ES\_HEAP\_SIZE=16G: set -Xms16G and -Xmx16G in jvm.options or add "-Xms16G -Xmx16G" to ES\_JAVA\_OPTS](https://discuss.elastic.co/t/use-jvm-options-or-es-java-opts-to-configure-the-jvm-es-heap-size-16g-set-xms16g-and-xmx16g-in-jvm-options-or-add-xms16g-xmx16g-to-es-java-opts/88962)

<div class="topic-metadata">

**Author:** [@francis1](https://discuss.elastic.co/u/francis1)\
**Replies:** 9\
**Last updated:** [June 23, 2017, 7:45am UTC](https://discuss.elastic.co/t/use-jvm-options-or-es-java-opts-to-configure-the-jvm-es-heap-size-16g-set-xms16g-and-xmx16g-in-jvm-options-or-add-xms16g-xmx16g-to-es-java-opts/88962 "2017-06-23T07:45:17Z")

</div>

At the moment I’ve been trying to run elasticsearch 5.2.2 as elastic user but I have been getting the following error. Use jvm.options or ES\_JAVA\_OPTS to configure the JVM ES\_HEAP\_SIZE=16G: set -Xms16G and -Xmx16G in j…

---

## [Authentication of \[elastic\] was terminated by realm \[reserved\]](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved/112206)

<div class="topic-metadata">

**Author:** [@kas-umi](https://discuss.elastic.co/u/kas-umi)\
**Replies:** 9\
**Last updated:** [December 20, 2017, 5:17am UTC](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved/112206 "2017-12-20T05:17:23Z")

</div>

when install the x-pack Plugin，startup elasticsearch occurred the next ERROR INFO: Authentication of \[elastic\] was terminated by realm \[reserved\]

---

## [Node disconnects every hour](https://discuss.elastic.co/t/node-disconnects-every-hour/37162)

<div class="topic-metadata">

**Author:** [@Omar\_Al\_Zabir](https://discuss.elastic.co/u/Omar_Al_Zabir)\
**Replies:** 17\
**Last updated:** [December 30, 2015, 12:03pm UTC](https://discuss.elastic.co/t/node-disconnects-every-hour/37162 "2015-12-30T12:03:07Z")

</div>

I see nodes are disconnecting almost regularly every hour: \[2015-12-14 11:31:19,677\]\[INFO \]\[cluster.service \] \[ec-dyl-3\] removed {{ec-rdl-2}{sNyCgx2HQUuJEJ8jb\_d9Yg}{10.187.147.59}{10.187.147.59:9300},}, reason…

---

## [Aggregation size 0 for top results](https://discuss.elastic.co/t/aggregation-size-0-for-top-results/135512)

<div class="topic-metadata">

**Author:** [@sylvainb](https://discuss.elastic.co/u/sylvainb)\
**Replies:** 13\
**Last updated:** [June 14, 2018, 6:39am UTC](https://discuss.elastic.co/t/aggregation-size-0-for-top-results/135512 "2018-06-14T06:39:18Z")

</div>

Hi everyone, I'm just migrating my application from elasticsearch 1.7 to 5.6 but I'm stuck with the following aggregation which previously relies on size:"0" (removed in 5.x). GET /stats/event/\_search { "query": { …

---

## [Scripted fields - doc\[message.keyword\].value reading as empty - field is not empty](https://discuss.elastic.co/t/scripted-fields-doc-message-keyword-value-reading-as-empty-field-is-not-empty/280953)

<div class="topic-metadata">

**Author:** [@acastravet](https://discuss.elastic.co/u/acastravet)\
**Replies:** 15\
**Last updated:** [August 16, 2021, 7:05am UTC](https://discuss.elastic.co/t/scripted-fields-doc-message-keyword-value-reading-as-empty-field-is-not-empty/280953 "2021-08-16T07:05:48Z")

</div>

Hello everyone, I have a field that holds all the log information (multiple fields inside it). Field looks like this: logging.level="some info", @timestamp="some info", message="some info", trace\_id="some info" I am t…

---

## [Reusing existing HTTP connections](https://discuss.elastic.co/t/reusing-existing-http-connections/67130)

<div class="topic-metadata">

**Author:** [@Cara\_B](https://discuss.elastic.co/u/Cara_B)\
**Replies:** 16\
**Last updated:** [November 29, 2016, 7:00pm UTC](https://discuss.elastic.co/t/reusing-existing-http-connections/67130 "2016-11-29T19:00:11Z")

</div>

Hello everyone, We're currently testing our new ES solution and have found that it isn't reusing existing connections. The HTTP total\_opened value (GET \_nodes/stats/http) is consistently increasing as we do our indexi…

---

## [Logstash Not Connecting to Elasticsearch](https://discuss.elastic.co/t/logstash-not-connecting-to-elasticsearch/88336)

<div class="topic-metadata">

**Author:** [@relder](https://discuss.elastic.co/u/relder)\
**Replies:** 9\
**Last updated:** [June 16, 2017, 4:05pm UTC](https://discuss.elastic.co/t/logstash-not-connecting-to-elasticsearch/88336 "2017-06-16T16:05:28Z")

</div>

Hello everyone, I am running into a problem when I try to output Logstash to Elasticsearch. Everything works well when I'm merely outputting to stdout, but once I try to output to Elasticsearch, I am hit with this warni…

---

## [Deploying Filebeat on MacOS X](https://discuss.elastic.co/t/deploying-filebeat-on-macos-x/37785)

<div class="topic-metadata">

**Author:** [@dirkhschulz](https://discuss.elastic.co/u/dirkhschulz)\
**Replies:** 14\
**Last updated:** [February 1, 2016, 10:00pm UTC](https://discuss.elastic.co/t/deploying-filebeat-on-macos-x/37785 "2016-02-01T22:00:20Z")

</div>

Hi all, I am looking into deploying filebeat on Mac OS X (10.11). The package does not contain the wrapper binary filebeat-god, so the question is how to daemonize filebeat properly. Starting it manually I can use …

---

## [Docker Logs keep getting dropped with tried to parse field \[image\] as object, but found a concrete value error](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 49\
**Last updated:** [March 22, 2023, 1:15am UTC](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245 "2023-03-22T01:15:41Z")

</div>

When investigating why I couldn't find my docker logs in Elastic, I found that Elastic Agent has been dropping them. It keeps logging stuff like: {"log.level":"warn","@timestamp":"2023-02-22T18:48:50.007-0800","message"…

---

## [Filebeat and Kubernetes: excluding log files](https://discuss.elastic.co/t/filebeat-and-kubernetes-excluding-log-files/117837)

<div class="topic-metadata">

**Author:** [@jeremievallee](https://discuss.elastic.co/u/jeremievallee)\
**Replies:** 11\
**Last updated:** [February 1, 2018, 11:35am UTC](https://discuss.elastic.co/t/filebeat-and-kubernetes-excluding-log-files/117837 "2018-02-01T11:35:21Z")

</div>

Hi there, I'm having trouble configuring filebeat on Kubernetes. Let's say you want filebeat to get the containers logs from Kubernetes, but you would like to exclude some files (for example because you don't want to g…

---

## [Logstash \_grokparsefailure . Unable to find issue](https://discuss.elastic.co/t/logstash--grokparsefailure-unable-to-find-issue/61845)

<div class="topic-metadata">

**Author:** [@chromechris](https://discuss.elastic.co/u/chromechris)\
**Replies:** 15\
**Last updated:** [October 7, 2016, 5:46am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-unable-to-find-issue/61845 "2016-10-07T05:46:51Z")

</div>

Hello Loggers, I have been receiveing a \_grokparsefailure tag in Logstash but cannot find the issue. My Logstash Grok filter looks like this: grok { match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp}…

---

## [Logstash - création d'index en fonction de l'IP de provenance](https://discuss.elastic.co/t/logstash-creation-dindex-en-fonction-de-lip-de-provenance/72502)

<div class="topic-metadata">

**Author:** [@vdsm](https://discuss.elastic.co/u/vdsm)\
**Replies:** 26\
**Last updated:** [February 16, 2017, 8:28am UTC](https://discuss.elastic.co/t/logstash-creation-dindex-en-fonction-de-lip-de-provenance/72502 "2017-02-16T08:28:33Z")

</div>

Bonjour à tous, Etant, comme beaucoup, nouveau sur ELK, je rencontre un petit soucis par rapport à l'output de Logstash. En fait, pour donner le contexte, j'ai un serveur Rsyslog qui centralise les logs d'un certains nom…

---

## [java.net.UnknownHostException using Java Rest client 5.6.3](https://discuss.elastic.co/t/java-net-unknownhostexception-using-java-rest-client-5-6-3/106329)

<div class="topic-metadata">

**Author:** [@mc1392](https://discuss.elastic.co/u/mc1392)\
**Replies:** 18\
**Last updated:** [November 10, 2017, 12:35pm UTC](https://discuss.elastic.co/t/java-net-unknownhostexception-using-java-rest-client-5-6-3/106329 "2017-11-10T12:35:11Z")

</div>

I keep getting java.net.UnknownHostException for connecting to my host elasticsearch. I have not completed the actual search body yet, because I am getting unknown host error. I figure I can solve that problem later. …

---

## [Error: Cannot read properties of undefined (reading 'includes')](https://discuss.elastic.co/t/error-cannot-read-properties-of-undefined-reading-includes/303696)

<div class="topic-metadata">

**Author:** [@Amitesh\_Gupta](https://discuss.elastic.co/u/Amitesh_Gupta)\
**Replies:** 10\
**Last updated:** [July 12, 2022, 8:29am UTC](https://discuss.elastic.co/t/error-cannot-read-properties-of-undefined-reading-includes/303696 "2022-07-12T08:29:43Z")

</div>

When I am trying to access security from kibana dashboard I'm getting this error. Error Error: Cannot read properties of undefined (reading 'includes') at c (http://10.9.1.8:5601/50723/bundles/plugin/securitySoluti…

---

## [Snapshot and restore | S3 and Glacier](https://discuss.elastic.co/t/snapshot-and-restore-s3-and-glacier/26337)

<div class="topic-metadata">

**Author:** [@Piyush\_Goyal](https://discuss.elastic.co/u/Piyush_Goyal)\
**Replies:** 18\
**Last updated:** [July 28, 2015, 8:55am UTC](https://discuss.elastic.co/t/snapshot-and-restore-s3-and-glacier/26337 "2015-07-28T08:55:32Z")

</div>

Hi, In our production environment, we take backup of our ES daily to S3 repository. Now since the process is year long and we have a huge list of snapshot, we decided to move the old snapshots from S3 to Glacier. Follo…

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to http://X.X.X.X:5601/api/status fails: fail to execute the HTTP GET request: Get "http://X.X.X.X:5601/api/status": context deadline exceeded. Response:](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-x-x-x-x-5601-api-status-fails-fail-to-execute-the-http-get-request-get-http-x-x-x-x-5601-api-status-context-deadline-exceeded-response/317848)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 22\
**Last updated:** [November 1, 2022, 11:36pm UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-x-x-x-x-5601-api-status-fails-fail-to-execute-the-http-get-request-get-http-x-x-x-x-5601-api-status-context-deadline-exceeded-response/317848 "2022-11-01T23:36:27Z")

</div>

Hello, I'm having errors loading --dashboards from filebeats to kibana. But when running the command below, it returns me the following message: \[rcmag.kta@XXXXXXXX ~\]$ sudo filebeat setup --dashboards Loading dashboar…

---

## [Deprecate and remove Multiple Data Paths](https://discuss.elastic.co/t/deprecate-and-remove-multiple-data-paths/297911)

<div class="topic-metadata">

**Author:** [@st4r.f1sch](https://discuss.elastic.co/u/st4r.f1sch)\
**Replies:** 9\
**Last updated:** [April 25, 2022, 11:05am UTC](https://discuss.elastic.co/t/deprecate-and-remove-multiple-data-paths/297911 "2022-04-25T11:05:25Z")

</div>

Hi there, While I don't agree that this should be discussed here, but if that helps ¯\_(ツ)\_/¯ The issue is that Elastic is removing multiple data paths from the configuration that is a big issue when you have a ton of d…

---

## [Index a text file into elasticsearch using logstash](https://discuss.elastic.co/t/index-a-text-file-into-elasticsearch-using-logstash/51584)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 9\
**Last updated:** [July 10, 2016, 6:47pm UTC](https://discuss.elastic.co/t/index-a-text-file-into-elasticsearch-using-logstash/51584 "2016-07-10T18:47:32Z")

</div>

Is there a way to index a text file which has the data in the following format. Date Time : 23/05/2016-12.01.38.AM File : log Reason : parser is not working Stack : at java.util.package(Exception e) …

---

## [Kibana 4.1.2 YUM RPM](https://discuss.elastic.co/t/kibana-4-1-2-yum-rpm/29332)

<div class="topic-metadata">

**Author:** [@Phil\_Scala](https://discuss.elastic.co/u/Phil_Scala)\
**Replies:** 9\
**Last updated:** [January 28, 2016, 11:51pm UTC](https://discuss.elastic.co/t/kibana-4-1-2-yum-rpm/29332 "2016-01-28T23:51:23Z")

</div>

Hi, I was wondering if or when the Kibana 4.1.2 RPM would be available in the YUM repo, I still only see 4.1.1 when looking at http://packages.elastic.co/ : \<Contents\> \<Key\>kibana/4.1/centos/kibana-4.1.1-1.x86\_64.r…

---

## [Kibana - Not able to open dashboard](https://discuss.elastic.co/t/kibana-not-able-to-open-dashboard/38219)

<div class="topic-metadata">

**Author:** [@Chitender\_Kumar](https://discuss.elastic.co/u/Chitender_Kumar)\
**Replies:** 20\
**Last updated:** [January 20, 2016, 3:43pm UTC](https://discuss.elastic.co/t/kibana-not-able-to-open-dashboard/38219 "2016-01-20T15:43:14Z")

</div>

Hi, after installing elasticsearch and marvel plugin. i installed kibana 4.3.1. after configuring it when i am trying to access the kibana dashboard from browser. i am getting stuck at first info page, where it display…

---

## ["Visualize: "field" is a required parameter" error](https://discuss.elastic.co/t/visualize-field-is-a-required-parameter-error/69536)

<div class="topic-metadata">

**Author:** [@zacesa](https://discuss.elastic.co/u/zacesa)\
**Replies:** 10\
**Last updated:** [December 28, 2016, 2:21pm UTC](https://discuss.elastic.co/t/visualize-field-is-a-required-parameter-error/69536 "2016-12-28T14:21:43Z")

</div>

Hi all, I'm new to ELK Stack, I have it installed on Ubuntu 16.04 and I'm also using packetbeat. I have packetbeat capture data through a tap and then, send it to logstash, then to elasticsearch. The data is coming in n…

---

## [Logstash's Pipeline has terminated](https://discuss.elastic.co/t/logstashs-pipeline-has-terminated/121772)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 11\
**Last updated:** [March 6, 2018, 2:18am UTC](https://discuss.elastic.co/t/logstashs-pipeline-has-terminated/121772 "2018-03-06T02:18:47Z")

</div>

I'm Running Logstash on Docker, yet running into following issue: logstash\_1 | Sending Logstash's logs to /usr/share/logstash/logs which is now configured via log4j2.properties logstash\_1 | \[2018-02-28T04:02:06,811\]\[I…

---

## [Old file with new name found](https://discuss.elastic.co/t/old-file-with-new-name-found/41766)

<div class="topic-metadata">

**Author:** [@lwhitworth](https://discuss.elastic.co/u/lwhitworth)\
**Replies:** 30\
**Last updated:** [October 2, 2016, 7:48pm UTC](https://discuss.elastic.co/t/old-file-with-new-name-found/41766 "2016-10-02T19:48:19Z")

</div>

I'm seeing an issue where filebeat is detecting: "Old file with new name found" an awful lot for files are most certainly not renames. Full log of one instance is: 2016-02-15T11:03:00Z INFO Old file with new name foun…

---

## [NoMethodError: "undefined method 'to\_hash'" with CSV input in Logstash 5.6.2](https://discuss.elastic.co/t/nomethoderror-undefined-method-to-hash-with-csv-input-in-logstash-5-6-2/103545)

<div class="topic-metadata">

**Author:** [@thechauffeur](https://discuss.elastic.co/u/thechauffeur)\
**Replies:** 11\
**Last updated:** [October 20, 2017, 1:17am UTC](https://discuss.elastic.co/t/nomethoderror-undefined-method-to-hash-with-csv-input-in-logstash-5-6-2/103545 "2017-10-20T01:17:41Z")

</div>

I'm trying to send data from a .csv file containing JMeter results to an online Elasticsearch instance. My .conf file looks this way: input { file { path =\> \["\\path\\to\\somefile.csv"\] start\_position =\> "beginning" …

---

## [Logstash nested array JSON parsing](https://discuss.elastic.co/t/logstash-nested-array-json-parsing/101100)

<div class="topic-metadata">

**Author:** [@aditya\_soni](https://discuss.elastic.co/u/aditya_soni)\
**Replies:** 14\
**Last updated:** [September 22, 2017, 8:49am UTC](https://discuss.elastic.co/t/logstash-nested-array-json-parsing/101100 "2017-09-22T08:49:17Z")

</div>

I have a JSON log of my application which contains elements in a nested array form, here is the sample of it:- { "msgs": \[ { "ts": "2017-09-04T07:07:46.37098Z", "tid": 25, "lvl": "Informat…

---

## [Receiving logstash error after installing watcher: SERVICE\_UNAVAILABLE/1/state not recovered / initialized SERVICE\_UNAVAILABLE/2/no master](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721)

<div class="topic-metadata">

**Author:** [@darinfisher](https://discuss.elastic.co/u/darinfisher)\
**Replies:** 9\
**Last updated:** [October 23, 2015, 2:26am UTC](https://discuss.elastic.co/t/receiving-logstash-error-after-installing-watcher-service-unavailable-1-state-not-recovered-initialized-service-unavailable-2-no-master/32721 "2015-10-23T02:26:36Z")

</div>

Hi, I installed Watcher on my ES cluster and started receiving this error from my logstash servers: :timestamp=\>"2015-10-21T10:56:48.613000-0700", :message=\>"Failed to flush outgoing items", :outgoing\_count=\>37, :exc…

---

## [ProcessClusterEventTimeoutException in Elasticsearch. Is this timeout value configurable? If yes how?](https://discuss.elastic.co/t/processclustereventtimeoutexception-in-elasticsearch-is-this-timeout-value-configurable-if-yes-how/15458)

<div class="topic-metadata">

**Author:** [@Munna](https://discuss.elastic.co/u/Munna)\
**Replies:** 9\
**Last updated:** [February 19, 2016, 12:09am UTC](https://discuss.elastic.co/t/processclustereventtimeoutexception-in-elasticsearch-is-this-timeout-value-configurable-if-yes-how/15458 "2016-02-19T00:09:44Z")

</div>

Getting timeout exceptions like below for different index operations. Below one shows for "index-aliases" operation. I would like to know how can I configure this timeout value in elasticsearch.yml so that I configu…

---

## [Curl: (7) couldn't connect to host](https://discuss.elastic.co/t/curl-7-couldnt-connect-to-host/162709)

<div class="topic-metadata">

**Author:** [@simpsonr](https://discuss.elastic.co/u/simpsonr)\
**Replies:** 42\
**Last updated:** [January 8, 2019, 4:13pm UTC](https://discuss.elastic.co/t/curl-7-couldnt-connect-to-host/162709 "2019-01-08T16:13:41Z")

</div>

Good Afternoon team, I keeping receiving this error. any help is appreciated. Thanks, rob

---

## [ES stuck in Red state, despite the fact that all nodes are in cluster: "ClusterBlockException\[blocked by: \[SERVICE\_UNAVAILABLE/1/state not recovered / initialized\];\]"](https://discuss.elastic.co/t/es-stuck-in-red-state-despite-the-fact-that-all-nodes-are-in-cluster-clusterblockexception-blocked-by-service-unavailable-1-state-not-recovered-initialized/158825)

<div class="topic-metadata">

**Author:** [@robert-blankenship](https://discuss.elastic.co/u/robert-blankenship)\
**Replies:** 17\
**Last updated:** [December 18, 2018, 6:48pm UTC](https://discuss.elastic.co/t/es-stuck-in-red-state-despite-the-fact-that-all-nodes-are-in-cluster-clusterblockexception-blocked-by-service-unavailable-1-state-not-recovered-initialized/158825 "2018-12-18T18:48:57Z")

</div>

Our 231 node, cloud ES cluster is stuck in a "RED" state. Cluster health: { "cluster\_name" : "exabeam-es", "status" : "red", "timed\_out" : false, "number\_of\_nodes" : 231, "number\_of\_data\_nodes" : 230, "acti…

---

## [How to integrate syslog input plugin](https://discuss.elastic.co/t/how-to-integrate-syslog-input-plugin/349025)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 41\
**Last updated:** [December 26, 2023, 12:24pm UTC](https://discuss.elastic.co/t/how-to-integrate-syslog-input-plugin/349025 "2023-12-26T12:24:13Z")

</div>

Hi, I have installed full stack ELK (version 7.17.13) and now I want to integrate syslog input plugin. Need some directions on the same on how to setup. Also when I tried with some changes in logstash.conf but I am fa…

---

## [Elastic Search for misspelled words](https://discuss.elastic.co/t/elastic-search-for-misspelled-words/14074)

<div class="topic-metadata">

**Author:** [@samir\_selia](https://discuss.elastic.co/u/samir_selia)\
**Replies:** 14\
**Last updated:** [November 6, 2013, 5:58am UTC](https://discuss.elastic.co/t/elastic-search-for-misspelled-words/14074 "2013-11-06T05:58:01Z")

</div>

Dear All, I want to display best possible results for misspelled search terms I tried using fuzzy method. It works well for search term having single word. For multiple words it doesn't return any result. Belo…

---

## [How to access elastic search in local network - windows 10 elastic search 5.0](https://discuss.elastic.co/t/how-to-access-elastic-search-in-local-network-windows-10-elastic-search-5-0/106185)

<div class="topic-metadata">

**Author:** [@nmathur](https://discuss.elastic.co/u/nmathur)\
**Replies:** 11\
**Last updated:** [November 7, 2017, 12:21pm UTC](https://discuss.elastic.co/t/how-to-access-elastic-search-in-local-network-windows-10-elastic-search-5-0/106185 "2017-11-07T12:21:15Z")

</div>

I am trying to make the elasticsearch accessible to all the devices connected to my LAN. The system on which elastic search is installed get IP address randomly (e.g. - 192.168.1.10, 192.168.1.11 and so on ..) Elasticse…

---

## [Converting date to ISO8601](https://discuss.elastic.co/t/converting-date-to-iso8601/35347)

<div class="topic-metadata">

**Author:** [@Forgand](https://discuss.elastic.co/u/Forgand)\
**Replies:** 10\
**Last updated:** [May 14, 2017, 8:58pm UTC](https://discuss.elastic.co/t/converting-date-to-iso8601/35347 "2017-05-14T20:58:55Z")

</div>

Hi guys. I have a date converting problem. I have logs in this format: 2015.11.10 03:02:23.832: Some text. And I parse logs by grok: match =\> \[ "message", "%{YEAR:year}.%{MONTHNUM:month}.%{MONTHDAY:day}%{SPACE}%{TI…

---

## [Elasticsearch 6.3.0 shard recovery is slow](https://discuss.elastic.co/t/elasticsearch-6-3-0-shard-recovery-is-slow/140940)

<div class="topic-metadata">

**Author:** [@ctluce](https://discuss.elastic.co/u/ctluce)\
**Replies:** 13\
**Last updated:** [August 29, 2018, 1:39pm UTC](https://discuss.elastic.co/t/elasticsearch-6-3-0-shard-recovery-is-slow/140940 "2018-08-29T13:39:27Z")

</div>

Moving from a 2.4.6 to a 6.3.0 cluster we have noticed that shard recovery is a lot slower. On the 2.4.6 cluster recovery time is ~3 minutes for shards, on the 6.3.0 cluster recovery time is ~9-11 minutes. The clusters …

---

## [How to specify number of logstash workers in configuration file?](https://discuss.elastic.co/t/how-to-specify-number-of-logstash-workers-in-configuration-file/32972)

<div class="topic-metadata">

**Author:** [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)\
**Replies:** 9\
**Last updated:** [June 28, 2017, 3:24pm UTC](https://discuss.elastic.co/t/how-to-specify-number-of-logstash-workers-in-configuration-file/32972 "2017-06-28T15:24:45Z")

</div>

is there any way to specify number of filter workers from configuration file. ? Right now I am using "service logstash start" command to start logstash, can we pass somehow pass number of worker threads to this command…

---

## [Kibana SSL verification Trust Issues](https://discuss.elastic.co/t/kibana-ssl-verification-trust-issues/322836)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 19\
**Last updated:** [January 25, 2023, 4:38pm UTC](https://discuss.elastic.co/t/kibana-ssl-verification-trust-issues/322836 "2023-01-25T16:38:24Z")

</div>

Hi everyone! I'm trying to set up certificate verification in my elk stack version 8.5.3. I'm using self generated certificates using my companys ca for each stack component and my cluster works fine as long as I set e…

---

## [Enabling X-Pack in Logstash 7 gives me this error](https://discuss.elastic.co/t/enabling-x-pack-in-logstash-7-gives-me-this-error/176671)

<div class="topic-metadata">

**Author:** [@teamg](https://discuss.elastic.co/u/teamg)\
**Replies:** 9\
**Last updated:** [April 15, 2019, 2:21pm UTC](https://discuss.elastic.co/t/enabling-x-pack-in-logstash-7-gives-me-this-error/176671 "2019-04-15T14:21:53Z")

</div>

I have a single node ELK 7 stack and I want Kibana to display Logstash in Monitoring. I enabled X-Pack in /etc/logstash/logstash.yml and restart logstash. I see this in /var/log: Apr 12 11:21:28 nocptc-elk logstash: …

---

## [Unknown setting \[index.lifecycle.name\] please check that any required plugins](https://discuss.elastic.co/t/unknown-setting-index-lifecycle-name-please-check-that-any-required-plugins/180091)

<div class="topic-metadata">

**Author:** [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Replies:** 14\
**Last updated:** [May 9, 2019, 9:47pm UTC](https://discuss.elastic.co/t/unknown-setting-index-lifecycle-name-please-check-that-any-required-plugins/180091 "2019-05-09T21:47:39Z")

</div>

Hello Team, I am exploring ILM option but I am running into below error, can anyone shade some light? following below doc: https://www.elastic.co/guide/en/elasticsearch/reference/6.7/index-lifecycle-error-handling.htm…

---

## [Delete JndiLookup.class](https://discuss.elastic.co/t/delete-jndilookup-class/291507)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 16\
**Last updated:** [January 4, 2022, 2:49pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507 "2022-01-04T14:49:58Z")

</div>

Dear Team, I am unable to find the file zip -q -d \<LOGSTASH\_HOME\>/logstash-core/lib/jars/log4j-core-2.\* org/apache/logging/log4j/core/lookup/JndiLookup.class Can someone please help me or guide me. Regards

---

## [Logstash consuming CPU usage over 100%](https://discuss.elastic.co/t/logstash-consuming-cpu-usage-over-100/57084)

<div class="topic-metadata">

**Author:** [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Replies:** 10\
**Last updated:** [August 10, 2016, 6:12am UTC](https://discuss.elastic.co/t/logstash-consuming-cpu-usage-over-100/57084 "2016-08-10T06:12:03Z")

</div>

Hi! I would like ask question about logstash plugin. I am now using logstash but looks like it is consuming high CPU usage. Below is part of lines from my config. input { file { path =\> \["/var/log/logstash/da…

---

## [Debugging extremely slow indexing](https://discuss.elastic.co/t/debugging-extremely-slow-indexing/258498)

<div class="topic-metadata">

**Author:** [@beckerr](https://discuss.elastic.co/u/beckerr)\
**Replies:** 38\
**Last updated:** [January 19, 2021, 11:48am UTC](https://discuss.elastic.co/t/debugging-extremely-slow-indexing/258498 "2021-01-19T11:48:32Z")

</div>

I have recently "inherited" an ES cluster at work that used to run just fine (since I inherited at least) but recently has been experiencing extreme performance issues around indexing. We have 20 "processor" containers i…

---

## [Elasticsearch query with timezone conversion](https://discuss.elastic.co/t/elasticsearch-query-with-timezone-conversion/215220)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 10\
**Last updated:** [February 10, 2020, 5:21pm UTC](https://discuss.elastic.co/t/elasticsearch-query-with-timezone-conversion/215220 "2020-02-10T17:21:39Z")

</div>

I have put a record in elk input message =\> '{"submitted\_date": "2020-01-14 10:05:11.11"}' it got saved as UTC, 8 hour earlier (Singapore timezone) { "submitted\_date" =\> 2020-01-14T02:05:11.110Z } in kibana dev …

[Previous page](https://discuss.elastic.co/top.md?page=16&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=18&per_page=50&period=all)
