# Top

**URL:** https://discuss.elastic.co/top.md?page=19&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 20

---

## [How to reduce thread-pool data rejection in elasticsearch cluster?](https://discuss.elastic.co/t/how-to-reduce-thread-pool-data-rejection-in-elasticsearch-cluster/162400)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 23\
**Last updated:** [January 2, 2019, 7:21pm UTC](https://discuss.elastic.co/t/how-to-reduce-thread-pool-data-rejection-in-elasticsearch-cluster/162400 "2019-01-02T19:21:39Z")

</div>

My cluster has 3 nodes Linux3 - master node (2 core 8 gb ram) Linux2 - master and data node (4 core 8 gb ram) Linux1 - data node (2 core 8 gb ram) cluster having big amound of thread-pool rejection count. What is…

---

## [Failed to start elastic search](https://discuss.elastic.co/t/failed-to-start-elastic-search/273323)

<div class="topic-metadata">

**Author:** [@cedler](https://discuss.elastic.co/u/cedler)\
**Replies:** 18\
**Last updated:** [May 22, 2021, 10:27pm UTC](https://discuss.elastic.co/t/failed-to-start-elastic-search/273323 "2021-05-22T22:27:36Z")

</div>

Good evening, all seems ok, I have installed java 11, etc... But when I want to start the service I have somes errors... I put you the commandes and answers in putty : \[root@ortie-bio ~\]# systemctl start elasticsearch…

---

## [Synonyms in synonyms.txt not recognized](https://discuss.elastic.co/t/synonyms-in-synonyms-txt-not-recognized/113417)

<div class="topic-metadata">

**Author:** [@Aurelien\_Quillet](https://discuss.elastic.co/u/Aurelien_Quillet)\
**Replies:** 36\
**Last updated:** [January 8, 2018, 8:27am UTC](https://discuss.elastic.co/t/synonyms-in-synonyms-txt-not-recognized/113417 "2018-01-08T08:27:26Z")

</div>

I have created a synonyms.txt file as in Synonym token filter | Elasticsearch Guide \[8.11\] | Elastic . Synonyms.txt contains : i-pod, i pod =\> ipod, sea biscuit, sea biscit =\> seabiscuit I then use the following code…

---

## [Parsed JSON object/hash requires a target configuration option](https://discuss.elastic.co/t/parsed-json-object-hash-requires-a-target-configuration-option/59354)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 11\
**Last updated:** [March 2, 2017, 10:46am UTC](https://discuss.elastic.co/t/parsed-json-object-hash-requires-a-target-configuration-option/59354 "2017-03-02T10:46:00Z")

</div>

I'm seeing these messages in my logstash.log file: {:timestamp=\>"2016-08-30T11:36:51.811000-0700", :message=\>"Parsed JSON object/hash requires a target configuration option", :source=\>"message", :raw=\>"", :level=\>:warn…

---

## [All new indexes created have unassigned shards](https://discuss.elastic.co/t/all-new-indexes-created-have-unassigned-shards/57929)

<div class="topic-metadata">

**Author:** [@whyapenny](https://discuss.elastic.co/u/whyapenny)\
**Replies:** 9\
**Last updated:** [September 6, 2016, 4:14am UTC](https://discuss.elastic.co/t/all-new-indexes-created-have-unassigned-shards/57929 "2016-09-06T04:14:08Z")

</div>

Using elasticsearch for logstash and each morning when the new index is created, the shards are all unassigned. I have to go in and manually assign them with: curl -XPOST -d '{ "commands" : \[ { "allocate" : { "index" : …

---

## [Data table :hide column Count](https://discuss.elastic.co/t/data-table-hide-column-count/53037)

<div class="topic-metadata">

**Author:** [@pittoch](https://discuss.elastic.co/u/pittoch)\
**Replies:** 10\
**Last updated:** [September 26, 2017, 9:25pm UTC](https://discuss.elastic.co/t/data-table-hide-column-count/53037 "2017-09-26T21:25:10Z")

</div>

In a data table, is it possible to hide column Count ? I split line with other information. Thanks

---

## [500: An internal server error](https://discuss.elastic.co/t/500-an-internal-server-error/103543)

<div class="topic-metadata">

**Author:** [@annu](https://discuss.elastic.co/u/annu)\
**Replies:** 13\
**Last updated:** [October 17, 2017, 8:42am UTC](https://discuss.elastic.co/t/500-an-internal-server-error/103543 "2017-10-17T08:42:22Z")

</div>

I've tried to change the cluster memory from 1GB to 2GB from ECE console. Now no cluster(including logging and metrics cluster) is coming up and showing error "500: An internal server error ". I've enough memory left, ab…

---

## [How to increase Java heap space for Logstash running on Windows?](https://discuss.elastic.co/t/how-to-increase-java-heap-space-for-logstash-running-on-windows/75509)

<div class="topic-metadata">

**Author:** [@Adyne](https://discuss.elastic.co/u/Adyne)\
**Replies:** 12\
**Last updated:** [February 21, 2017, 4:43pm UTC](https://discuss.elastic.co/t/how-to-increase-java-heap-space-for-logstash-running-on-windows/75509 "2017-02-21T16:43:09Z")

</div>

After about 4-5 hours of running Logstash 5.2.1 on Windows I get this error: java.lang.OutOfMemoryError: Java heap space Dumping heap to C:\\logstash-5.2.1/heapdump.hprof ... Unable to create C:\\logstash-5.2.1/heapdump.…

---

## [Sorting in Discover not working](https://discuss.elastic.co/t/sorting-in-discover-not-working/204626)

<div class="topic-metadata">

**Author:** [@Ssingh12](https://discuss.elastic.co/u/Ssingh12)\
**Replies:** 12\
**Last updated:** [November 1, 2019, 7:26pm UTC](https://discuss.elastic.co/t/sorting-in-discover-not-working/204626 "2019-11-01T19:26:23Z")

</div>

Hi, I am struggling to a seeming humble issue. I am not able to get the sorting by fields work on the 'Discover'. So, in Discover, I 'added' a few fields to view and tried clicking on sort up/down arrows. The sorting i…

---

## [Unable to start HeartBeat](https://discuss.elastic.co/t/unable-to-start-heartbeat/181129)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 45\
**Last updated:** [June 6, 2019, 6:00pm UTC](https://discuss.elastic.co/t/unable-to-start-heartbeat/181129 "2019-06-06T18:00:21Z")

</div>

Hi I am new on this and starting to configure this feature. Unfortunately I am facing some difficulties getting the module to work. When executing : systemctl start heartbeat Results: Failed to start heartbeat.service:…

---

## [File input not read logstah \[SOLVED\]](https://discuss.elastic.co/t/file-input-not-read-logstah-solved/166829)

<div class="topic-metadata">

**Author:** [@Darkside](https://discuss.elastic.co/u/Darkside)\
**Replies:** 11\
**Last updated:** [February 3, 2019, 3:58pm UTC](https://discuss.elastic.co/t/file-input-not-read-logstah-solved/166829 "2019-02-03T15:58:48Z")

</div>

Hi i am new to ELK i have some troubles with reading file. My conf file input { file { path =\> "/files/nginx\_logs" start\_position =\> "beginning" ignore\_older =\> 0 } } output { stdout { } } a sample of log ngi…

---

## [How to collect the logs from multiple machines to my server efficiently?](https://discuss.elastic.co/t/how-to-collect-the-logs-from-multiple-machines-to-my-server-efficiently/135902)

<div class="topic-metadata">

**Author:** [@Pawan\_Chandra](https://discuss.elastic.co/u/Pawan_Chandra)\
**Replies:** 11\
**Last updated:** [June 15, 2018, 11:39am UTC](https://discuss.elastic.co/t/how-to-collect-the-logs-from-multiple-machines-to-my-server-efficiently/135902 "2018-06-15T11:39:55Z")

</div>

I want to send logs from multiple machines to my server via some end point. But I know that my files to be written is a log file which has the limits for a number of logs storage( maybe some 1000's). My logs would be any…

---

## [Export and import index](https://discuss.elastic.co/t/export-and-import-index/182491)

<div class="topic-metadata">

**Author:** [@aniaks](https://discuss.elastic.co/u/aniaks)\
**Replies:** 9\
**Last updated:** [May 23, 2019, 9:51pm UTC](https://discuss.elastic.co/t/export-and-import-index/182491 "2019-05-23T21:51:23Z")

</div>

Is there a way to export index from one cluster and import into another cluster ?

---

## [Select your space You can change your space at anytime{ No spaces match search criteria }](https://discuss.elastic.co/t/select-your-space-you-can-change-your-space-at-anytime-no-spaces-match-search-criteria/237565)

<div class="topic-metadata">

**Author:** [@Gopi\_mdvk](https://discuss.elastic.co/u/Gopi_mdvk)\
**Replies:** 28\
**Last updated:** [August 13, 2020, 2:04pm UTC](https://discuss.elastic.co/t/select-your-space-you-can-change-your-space-at-anytime-no-spaces-match-search-criteria/237565 "2020-08-13T14:04:26Z")

</div>

Hi team, I am using elk 7.x and i am getting a strange error that "No spaces match search criteria".I am getting this error cople of times.my kibana was working till yesterday but when i try to open i getting the above…

---

## [How to get results over 10K in App search](https://discuss.elastic.co/t/how-to-get-results-over-10k-in-app-search/351310)

<div class="topic-metadata">

**Author:** [@pradeepjanga](https://discuss.elastic.co/u/pradeepjanga)\
**Replies:** 10\
**Last updated:** [January 30, 2024, 8:28pm UTC](https://discuss.elastic.co/t/how-to-get-results-over-10k-in-app-search/351310 "2024-01-30T20:28:13Z")

</div>

HI, We have 27K documents ingested into our engine. and we are trying to do a rest api call to gather the distinct field value across all the documents and that would be 27k id. how can gather those array of id's as a r…

---

## [List of string must match all provided values](https://discuss.elastic.co/t/list-of-string-must-match-all-provided-values/240351)

<div class="topic-metadata">

**Author:** [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Replies:** 13\
**Last updated:** [July 15, 2020, 1:07pm UTC](https://discuss.elastic.co/t/list-of-string-must-match-all-provided-values/240351 "2020-07-15T13:07:30Z")

</div>

Hi, I'm new to Elastic Search, and I simply would like to make a query that filter all entries that have exactly all the supplied values (not an OR but an AND). Here is an example of my document \[ { "Areas" : …

---

## [Delete alias](https://discuss.elastic.co/t/delete-alias/32959)

<div class="topic-metadata">

**Author:** [@kodermax](https://discuss.elastic.co/u/kodermax)\
**Replies:** 9\
**Last updated:** [October 27, 2015, 6:10am UTC](https://discuss.elastic.co/t/delete-alias/32959 "2015-10-27T06:10:26Z")

</div>

Why When I remove alias, my index removed too?

---

## [The below bugs appers when running esrally](https://discuss.elastic.co/t/the-below-bugs-appers-when-running-esrally/57063)

<div class="topic-metadata">

**Author:** [@laoyang360](https://discuss.elastic.co/u/laoyang360)\
**Replies:** 28\
**Last updated:** [August 8, 2016, 8:40am UTC](https://discuss.elastic.co/t/the-below-bugs-appers-when-running-esrally/57063 "2016-08-08T08:40:12Z")

</div>

\[root@laoyang .rally\]# esrally fatal: Not a git repository (or any of the parent directories): .git \_\_\_\_ \_\_\_\_ / \_ \_\_\_\_ \_/ / / \_\_ / /\_/ / \_\_ \`/ / / / / / / , \_/ // / / / /\_/ / /\_/ ||\_,//\_/\_\_, / …

---

## [Elasticsearch-1.7.0 installation in window7](https://discuss.elastic.co/t/elasticsearch-1-7-0-installation-in-window7/26281)

<div class="topic-metadata">

**Author:** [@alloycivic](https://discuss.elastic.co/u/alloycivic)\
**Replies:** 18\
**Last updated:** [March 9, 2017, 1:09pm UTC](https://discuss.elastic.co/t/elasticsearch-1-7-0-installation-in-window7/26281 "2017-03-09T13:09:22Z")

</div>

cant install elasticsearch-1.7.0 in window 7. am having the error in the command prompt: "JAVA\_HOME point to an invalid java installation(no java.exe found in C:\\program files\\java\\jdk1.8.0\_45\\bin)". please i need some h…

---

## [Change GEO.LOCATION to GEO\_POINT data type](https://discuss.elastic.co/t/change-geo-location-to-geo-point-data-type/73015)

<div class="topic-metadata">

**Author:** [@mmethe](https://discuss.elastic.co/u/mmethe)\
**Replies:** 19\
**Last updated:** [February 3, 2017, 2:15pm UTC](https://discuss.elastic.co/t/change-geo-location-to-geo-point-data-type/73015 "2017-02-03T14:15:54Z")

</div>

All, I am collecting syslogs from my Cisco ASA firewall. Logstash is getting info just fine. I can discover and visualize current data as expected. I cannot get geo mapping to work and cannot find a concise, unders…

---

## [How to Create Super User in Kibana](https://discuss.elastic.co/t/how-to-create-super-user-in-kibana/196257)

<div class="topic-metadata">

**Author:** [@Syed.Ubaid](https://discuss.elastic.co/u/Syed.Ubaid)\
**Replies:** 23\
**Last updated:** [August 26, 2019, 11:24am UTC](https://discuss.elastic.co/t/how-to-create-super-user-in-kibana/196257 "2019-08-26T11:24:17Z")

</div>

Hello how to create super user with full access so i will create another user with role of dashboard mode only... I have ELK stack 7 and x pack by default is install in ELK . Can someone help. I have set password in kiba…

---

## [Logstash can not find JAVA\_HOME](https://discuss.elastic.co/t/logstash-can-not-find-java-home/183224)

<div class="topic-metadata">

**Author:** [@zenimagine](https://discuss.elastic.co/u/zenimagine)\
**Replies:** 10\
**Last updated:** [May 29, 2019, 8:28pm UTC](https://discuss.elastic.co/t/logstash-can-not-find-java-home/183224 "2019-05-29T20:28:01Z")

</div>

Unable to install Logstash because it can not find JAVA\_HOME I did not install JAVA because it is included in ELK. Elasticsearch, Kibana and Logstash are on the same server. Elacticsearh and Kibana works. But how to co…

---

## [Loading incremental data into Elasticsearch from Oracle database](https://discuss.elastic.co/t/loading-incremental-data-into-elasticsearch-from-oracle-database/102007)

<div class="topic-metadata">

**Author:** [@Newuser](https://discuss.elastic.co/u/Newuser)\
**Replies:** 17\
**Last updated:** [October 16, 2017, 11:53am UTC](https://discuss.elastic.co/t/loading-incremental-data-into-elasticsearch-from-oracle-database/102007 "2017-10-16T11:53:59Z")

</div>

Hi all, I need to Load incremental data into Elasticsearch from Oracle database, after the first load ( via Logstash), i need to load only the data updated. Could you advise on this please? Regrads,

---

## [Filtering by date and time as different fields](https://discuss.elastic.co/t/filtering-by-date-and-time-as-different-fields/33665)

<div class="topic-metadata">

**Author:** [@xtingray](https://discuss.elastic.co/u/xtingray)\
**Replies:** 9\
**Last updated:** [November 5, 2015, 4:53pm UTC](https://discuss.elastic.co/t/filtering-by-date-and-time-as-different-fields/33665 "2015-11-05T16:53:54Z")

</div>

Hi! I am trying to create a filter for my query using a date range and a time range. In my case, date and time are different fields. So I want to run queries like: Show me all the events happening this month (15-11-01/…

---

## [Elasticsearch query time range issue](https://discuss.elastic.co/t/elasticsearch-query-time-range-issue/268672)

<div class="topic-metadata">

**Author:** [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Replies:** 50\
**Last updated:** [April 8, 2021, 12:41pm UTC](https://discuss.elastic.co/t/elasticsearch-query-time-range-issue/268672 "2021-04-08T12:41:54Z")

</div>

Hello Experts, I am not able to retrieve all the status\_code values with below query. It has given only less value than actual values. \*\*My query\*\* "\_source": \[ "status\_code", "referrer", "timestamp" \], "query":…

---

## [GET API requests sometimes slow (up to 200ms instead of 2ms)](https://discuss.elastic.co/t/get-api-requests-sometimes-slow-up-to-200ms-instead-of-2ms/46301)

<div class="topic-metadata">

**Author:** [@iquito](https://discuss.elastic.co/u/iquito)\
**Replies:** 9\
**Last updated:** [January 19, 2017, 12:03pm UTC](https://discuss.elastic.co/t/get-api-requests-sometimes-slow-up-to-200ms-instead-of-2ms/46301 "2017-01-19T12:03:46Z")

</div>

I have intermittent but reproduceable slow requests when I get a record via /index/type/id (the most basic request possible for Elasticsearch, with no body) - instead of 1-2ms it sometimes takes up to 220ms. During many …

---

## [Input file log rotation](https://discuss.elastic.co/t/input-file-log-rotation/26742)

<div class="topic-metadata">

**Author:** [@mparthas](https://discuss.elastic.co/u/mparthas)\
**Replies:** 13\
**Last updated:** [October 23, 2016, 2:06am UTC](https://discuss.elastic.co/t/input-file-log-rotation/26742 "2016-10-23T02:06:11Z")

</div>

Hi, I am new to this group. I have been playing around with Logstash for about a couple of weeks. I was surprised to see that Logstash does not provide the feature where in, it reads a log file once and forgets about i…

---

## [org.elasticsearch.common.util.concurrent.EsRejectedExecutionException: rejected execution of org.elasticsearch.transport.TransportService](https://discuss.elastic.co/t/org-elasticsearch-common-util-concurrent-esrejectedexecutionexception-rejected-execution-of-org-elasticsearch-transport-transportservice/117431)

<div class="topic-metadata">

**Author:** [@reeenz20](https://discuss.elastic.co/u/reeenz20)\
**Replies:** 24\
**Last updated:** [January 30, 2018, 11:24am UTC](https://discuss.elastic.co/t/org-elasticsearch-common-util-concurrent-esrejectedexecutionexception-rejected-execution-of-org-elasticsearch-transport-transportservice/117431 "2018-01-30T11:24:52Z")

</div>

Hi guys, I have this error on elasticsearch. The logs keeps on increasing. Urgently needed help here. Thank you! :slight\_smile: org.elasticsearch.common.util.concurrent.EsRejectedExecutionException: rejected execution o…

---

## [Beats with multiline](https://discuss.elastic.co/t/beats-with-multiline/35957)

<div class="topic-metadata">

**Author:** [@Jeferson\_Martins](https://discuss.elastic.co/u/Jeferson_Martins)\
**Replies:** 14\
**Last updated:** [February 9, 2017, 2:10pm UTC](https://discuss.elastic.co/t/beats-with-multiline/35957 "2017-02-09T14:10:16Z")

</div>

can i use FileBeat With multiline?

---

## [Multiple IF conditions - Logstash](https://discuss.elastic.co/t/multiple-if-conditions-logstash/166186)

<div class="topic-metadata">

**Author:** [@Jasna\_Bencic](https://discuss.elastic.co/u/Jasna_Bencic)\
**Replies:** 13\
**Last updated:** [February 1, 2019, 9:40am UTC](https://discuss.elastic.co/t/multiple-if-conditions-logstash/166186 "2019-02-01T09:40:21Z")

</div>

Hi, I am fixing bigger logstash config file where I have custom grok patterns but that is just tip of the iceberg regarding my problems. In Filebeat I have multiple log files and some of them (their log events) are vis…

---

## [Logs are not displaying in order](https://discuss.elastic.co/t/logs-are-not-displaying-in-order/80409)

<div class="topic-metadata">

**Author:** [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Replies:** 49\
**Last updated:** [April 3, 2017, 9:54am UTC](https://discuss.elastic.co/t/logs-are-not-displaying-in-order/80409 "2017-04-03T09:54:50Z")

</div>

Hi All, I have configured ELK with Layer 7 logs locally by taking the logs from gateway. I am able to get the logs in Kibana dashboard but the logs are not displayed in order. Below log is complete one entry but in …

---

## [Analysis logs for security events](https://discuss.elastic.co/t/analysis-logs-for-security-events/48893)

<div class="topic-metadata">

**Author:** [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Replies:** 9\
**Last updated:** [May 12, 2016, 2:48pm UTC](https://discuss.elastic.co/t/analysis-logs-for-security-events/48893 "2016-05-12T14:48:18Z")

</div>

I am new to winlogbeat. How can I analyse Windows Event (espacially in Security , e.g. AD Login, Logout error) with winlogbeat and visualize it?

---

## [Filebeat : Badly Stuck with Connection reset by peer error](https://discuss.elastic.co/t/filebeat-badly-stuck-with-connection-reset-by-peer-error/66878)

<div class="topic-metadata">

**Author:** [@jashwanth](https://discuss.elastic.co/u/jashwanth)\
**Replies:** 14\
**Last updated:** [November 23, 2016, 11:58pm UTC](https://discuss.elastic.co/t/filebeat-badly-stuck-with-connection-reset-by-peer-error/66878 "2016-11-23T23:58:12Z")

</div>

Hi, I'm badly stuck with connection reset by peer error even though all tcp ports are opened. Can anyone guide me here. 2016-11-22T13:32:39Z INFO Error publishing events (retrying): read tcp 10.3.2.20:35816-\>10.3.1.13:…

---

## [Very large number of fields in Index leading to slow index rate](https://discuss.elastic.co/t/very-large-number-of-fields-in-index-leading-to-slow-index-rate/86110)

<div class="topic-metadata">

**Author:** [@anand.d](https://discuss.elastic.co/u/anand.d)\
**Replies:** 10\
**Last updated:** [May 18, 2017, 9:44am UTC](https://discuss.elastic.co/t/very-large-number-of-fields-in-index-leading-to-slow-index-rate/86110 "2017-05-18T09:44:15Z")

</div>

hi all, I have to store some 60 million+ documents in elasticsearch. I am using bulkprocessor in JAVA api with Transport Client in Elasticsearch 5.3.1. I have tried indexing fixed number of fields (around 200) and able…

---

## [java.io.IOException: failed to obtain in-memory shard lock](https://discuss.elastic.co/t/java-io-ioexception-failed-to-obtain-in-memory-shard-lock/147375)

<div class="topic-metadata">

**Author:** [@Priya\_Prabhakar](https://discuss.elastic.co/u/Priya_Prabhakar)\
**Replies:** 14\
**Last updated:** [September 24, 2018, 2:06pm UTC](https://discuss.elastic.co/t/java-io-ioexception-failed-to-obtain-in-memory-shard-lock/147375 "2018-09-24T14:06:44Z")

</div>

We are intermittently getting the below error in elasticsearch logs. It gets this error after some time, it will be back. elasticsearch version - "6.3.2" Real concern in the log marking and sending shard failed due …

---

## [Filebeat to logstash multiple indexs](https://discuss.elastic.co/t/filebeat-to-logstash-multiple-indexs/67399)

<div class="topic-metadata">

**Author:** [@bob-bza](https://discuss.elastic.co/u/bob-bza)\
**Replies:** 21\
**Last updated:** [December 6, 2016, 6:21pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-multiple-indexs/67399 "2016-12-06T18:21:21Z")

</div>

i'm new to ELK was trying to configure filebeat on multiple instances. i have different types of logs. 1. kafka logs 2. zookeeper logs 3. hdfs logs 4. yarn logs . . . on all these instances i was trying to configure f…

---

## [Geoip error while deploying elasticsearch](https://discuss.elastic.co/t/geoip-error-while-deploying-elasticsearch/284080)

<div class="topic-metadata">

**Author:** [@ssen85](https://discuss.elastic.co/u/ssen85)\
**Replies:** 10\
**Last updated:** [September 26, 2021, 6:34am UTC](https://discuss.elastic.co/t/geoip-error-while-deploying-elasticsearch/284080 "2021-09-26T06:34:04Z")

</div>

Hi, I'm trying to start a single node elasticsearch cluster using Docker. I get the following error in the startup logs "type": "server", "timestamp": "2021-09-13T13:41:29,255Z", "level": "ERROR", "component": "o.e.i.…

---

## [Shard has exceeded the maximum number of retries](https://discuss.elastic.co/t/shard-has-exceeded-the-maximum-number-of-retries/215954)

<div class="topic-metadata">

**Author:** [@Jonathan\_Mendenhall](https://discuss.elastic.co/u/Jonathan_Mendenhall)\
**Replies:** 12\
**Last updated:** [January 27, 2020, 11:54pm UTC](https://discuss.elastic.co/t/shard-has-exceeded-the-maximum-number-of-retries/215954 "2020-01-27T23:54:53Z")

</div>

After moving one of our clusters from ES 6.4 to 7.5,we have been seeing frequent instances of shards failing to allocate because they hit the max of 5 retries. "explanation" : "shard has exceeded the maximum number of r…

---

## [Save Spark Dataframe into ES - Can't handle type exception](https://discuss.elastic.co/t/save-spark-dataframe-into-es-cant-handle-type-exception/29469)

<div class="topic-metadata">

**Author:** [@eliasah](https://discuss.elastic.co/u/eliasah)\
**Replies:** 24\
**Last updated:** [April 5, 2016, 3:23pm UTC](https://discuss.elastic.co/t/save-spark-dataframe-into-es-cant-handle-type-exception/29469 "2016-04-05T15:23:52Z")

</div>

I have designed a simple job to read data from MySQL and save it in Elasticsearch with Spark. Here is the code : JavaSparkContext sc = new JavaSparkContext( new SparkConf().setAppName("MySQLtoEs") …

---

## [Having issues with a specific "message" field while parsing using Filebeat and Logstash](https://discuss.elastic.co/t/having-issues-with-a-specific-message-field-while-parsing-using-filebeat-and-logstash/127086)

<div class="topic-metadata">

**Author:** [@Deepak\_Poola](https://discuss.elastic.co/u/Deepak_Poola)\
**Replies:** 18\
**Last updated:** [April 11, 2018, 4:33pm UTC](https://discuss.elastic.co/t/having-issues-with-a-specific-message-field-while-parsing-using-filebeat-and-logstash/127086 "2018-04-11T16:33:32Z")

</div>

I am trying to push logs in json format to logstash through filebeat. My logs are decoded/parsed correctly except for only one field with name "message". When I rename the field, it is being parsed correctly. There is is…

---

## [How to make histogram by grouped aggregation count?](https://discuss.elastic.co/t/how-to-make-histogram-by-grouped-aggregation-count/124709)

<div class="topic-metadata">

**Author:** [@Artur\_Zhdanov](https://discuss.elastic.co/u/Artur_Zhdanov)\
**Replies:** 11\
**Last updated:** [March 20, 2018, 12:13pm UTC](https://discuss.elastic.co/t/how-to-make-histogram-by-grouped-aggregation-count/124709 "2018-03-20T12:13:33Z")

</div>

Hello, I have some events, which user did. /events: {"type":"register", "user.id":"1", "event.id": "1"} {"type":"register", "user.id":"1", "event.id": "2"} {"type":"register", "user.id":"1", "event.id": "3"} {"type…

---

## [How to show ratio of 2 fields which are result of 2 filters in a bar chart](https://discuss.elastic.co/t/how-to-show-ratio-of-2-fields-which-are-result-of-2-filters-in-a-bar-chart/93303)

<div class="topic-metadata">

**Author:** [@ppseal](https://discuss.elastic.co/u/ppseal)\
**Replies:** 12\
**Last updated:** [July 24, 2017, 12:48pm UTC](https://discuss.elastic.co/t/how-to-show-ratio-of-2-fields-which-are-result-of-2-filters-in-a-bar-chart/93303 "2017-07-24T12:48:42Z")

</div>

Hi, I am looking to have two different sum numbers on the same field but on different filters. The filed is related to trade status which can be 'successful', 'not successful', 'incomplete', 'partly done' etc. I am loo…

---

## [Fielddata is disabled, but I have added a keyword field](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353)

<div class="topic-metadata">

**Author:** [@Terran](https://discuss.elastic.co/u/Terran)\
**Replies:** 30\
**Last updated:** [March 27, 2020, 4:46pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353 "2020-03-27T16:46:25Z")

</div>

I seem to be having an issue with mapping in my template. I have a field with data type "text", when I look into the Kibana SIEM console I receive the following error for several of my fields: \[illegal\_argument\_excepti…

---

## [Courier Fetch: 3 out of 33 shards failed](https://discuss.elastic.co/t/courier-fetch-3-out-of-33-shards-failed/122094)

<div class="topic-metadata">

**Author:** [@hadi](https://discuss.elastic.co/u/hadi)\
**Replies:** 12\
**Last updated:** [March 1, 2018, 6:28pm UTC](https://discuss.elastic.co/t/courier-fetch-3-out-of-33-shards-failed/122094 "2018-03-01T18:28:39Z")

</div>

Hello Everyone! Once trying to check a specific index via Kibana, I get the following error! \[fffffff\] The related logs that I see in my elastic search for this Courier Fetch: 3 shard failed are as follows: 2018-03-0…

---

## [Getting error on starting elasticsearch ingest.geoip.downloader.enabled: false](https://discuss.elastic.co/t/getting-error-on-starting-elasticsearch-ingest-geoip-downloader-enabled-false/319388)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 24\
**Last updated:** [November 28, 2022, 9:26am UTC](https://discuss.elastic.co/t/getting-error-on-starting-elasticsearch-ingest-geoip-downloader-enabled-false/319388 "2022-11-28T09:26:05Z")

</div>

Hi, I have installed elk stack 8.5.1. with authentication without https on elasticsearch xpack.security.http.ssl: enabled: false keystore.path: certs/http.p12 When i start elasticsearch and kibana it shows active, …

---

## [Impossible to uninstall Elastic Endpoint](https://discuss.elastic.co/t/impossible-to-uninstall-elastic-endpoint/351717)

<div class="topic-metadata">

**Author:** [@BlueNick](https://discuss.elastic.co/u/BlueNick)\
**Replies:** 25\
**Last updated:** [April 30, 2025, 2:11pm UTC](https://discuss.elastic.co/t/impossible-to-uninstall-elastic-endpoint/351717 "2025-04-30T14:11:14Z")

</div>

Hello, I've uninstalled the elastic agent on a windows machine successfully, the uninstall command runs successfully but, the Elastic Endpoint Folder is still present. I've tried to delete manually the folder with an …

---

## [Date Range Query Java](https://discuss.elastic.co/t/date-range-query-java/45610)

<div class="topic-metadata">

**Author:** [@ajmariella](https://discuss.elastic.co/u/ajmariella)\
**Replies:** 9\
**Last updated:** [March 29, 2016, 12:12pm UTC](https://discuss.elastic.co/t/date-range-query-java/45610 "2016-03-29T12:12:40Z")

</div>

I'm trying to create a range query in ES. Here's my Java example: QueryBuilder qb = QueryBuilders.rangeQUery("updateTime") .from(fromDate) .to(toDa…

---

## [Received response for a request that has timed out, sent \[213025ms\] ago, timed out \[140336ms\] ago](https://discuss.elastic.co/t/received-response-for-a-request-that-has-timed-out-sent-213025ms-ago-timed-out-140336ms-ago/169188)

<div class="topic-metadata">

**Author:** [@soumrock123](https://discuss.elastic.co/u/soumrock123)\
**Replies:** 13\
**Last updated:** [March 1, 2019, 1:48pm UTC](https://discuss.elastic.co/t/received-response-for-a-request-that-has-timed-out-sent-213025ms-ago-timed-out-140336ms-ago/169188 "2019-03-01T13:48:08Z")

</div>

I am trying to insert bulk data from multiple remote relational databases into Elasticsearch. It works perfectly when the number of databases is around 10-15. But if I try inserting queries from 50 or more databases, it …

---

## [Nearly All Indices UNASSIGNED and All Are Red](https://discuss.elastic.co/t/nearly-all-indices-unassigned-and-all-are-red/39137)

<div class="topic-metadata">

**Author:** [@ToddL](https://discuss.elastic.co/u/ToddL)\
**Replies:** 31\
**Last updated:** [January 25, 2016, 11:37pm UTC](https://discuss.elastic.co/t/nearly-all-indices-unassigned-and-all-are-red/39137 "2016-01-25T23:37:33Z")

</div>

I am trying to repair an Elasticsearch / Logstash / Kibana (ELK) installation implemented by a former coworker. The system seemed to be running along fine until it ran out of space (several times now). I have successfull…

---

## [No matching indices found no indices match pattern filebeat-\*](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-pattern-filebeat/139745)

<div class="topic-metadata">

**Author:** [@kranthi\_851](https://discuss.elastic.co/u/kranthi_851)\
**Replies:** 17\
**Last updated:** [July 17, 2018, 7:21am UTC](https://discuss.elastic.co/t/no-matching-indices-found-no-indices-match-pattern-filebeat/139745 "2018-07-17T07:21:45Z")

</div>

Hi All, I am getting this error on kibana such that file beat has created, but kibana unable to fetch the data. Kindly check my filebeat.yml code & input logsatsh code. Please help me it's important. it's my filebeat…

[Previous page](https://discuss.elastic.co/top.md?page=18&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=20&per_page=50&period=all)
