# Top

**URL:** https://discuss.elastic.co/top.md?page=21&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 22

---

## [Disable X-Pack Feature in Kibana](https://discuss.elastic.co/t/disable-x-pack-feature-in-kibana/156783)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 10\
**Last updated:** [November 26, 2018, 5:40am UTC](https://discuss.elastic.co/t/disable-x-pack-feature-in-kibana/156783 "2018-11-26T05:40:35Z")

</div>

I'm looking at X-Pack Settings in Kibana | Kibana User Guide \[6.5\] | Elastic How does one disable app (X-Pack Feature) such as: Canvas, Infrastructure, Logs? Please advise.

---

## [Filebeat doesn't clear the registry file after logrotation](https://discuss.elastic.co/t/filebeat-doesnt-clear-the-registry-file-after-logrotation/68193)

<div class="topic-metadata">

**Author:** [@nan008](https://discuss.elastic.co/u/nan008)\
**Replies:** 14\
**Last updated:** [January 23, 2017, 10:34am UTC](https://discuss.elastic.co/t/filebeat-doesnt-clear-the-registry-file-after-logrotation/68193 "2017-01-23T10:34:43Z")

</div>

Hi, OS: Linux CentOS 7 Filebeat: filebeat.x86\_64 5.0.2-1 We decided to logrotate the logs that are send to ES. The logrotate is done and we want to track the the old file for 5 minutes to not loose any lines and t…

---

## [Dynamic mapping strict to true](https://discuss.elastic.co/t/dynamic-mapping-strict-to-true/269912)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 10\
**Last updated:** [April 14, 2021, 9:41pm UTC](https://discuss.elastic.co/t/dynamic-mapping-strict-to-true/269912 "2021-04-14T21:41:30Z")

</div>

I have a index template that I define with strict dynamic mapping. Now I would like to add a field I have remove template, recreated with dynamic=true but it still gives me error on adding field 'error': {'type': 'stri…

---

## [Trying to load Configuration file this error has arrives in Logstash-5.0.0-alpha-4 CMD on windows](https://discuss.elastic.co/t/trying-to-load-configuration-file-this-error-has-arrives-in-logstash-5-0-0-alpha-4-cmd-on-windows/57406)

<div class="topic-metadata">

**Author:** [@Danyal-Javeed](https://discuss.elastic.co/u/Danyal-Javeed)\
**Replies:** 19\
**Last updated:** [August 8, 2016, 10:17pm UTC](https://discuss.elastic.co/t/trying-to-load-configuration-file-this-error-has-arrives-in-logstash-5-0-0-alpha-4-cmd-on-windows/57406 "2016-08-08T22:17:45Z")

</div>

C:\\logstash-5.0.0-alpha4\>bin\\logstash agent -f logstash.conf --- jar coordinate com.fasterxml.jackson.core:jackson-annotations already loaded with version 2.7.1 - omit version 2.7.0 --- jar coordinate com.fasterxml.jacks…

---

## [Authentication using Java API and TransportClient](https://discuss.elastic.co/t/authentication-using-java-api-and-transportclient/64196)

<div class="topic-metadata">

**Author:** [@robgratz](https://discuss.elastic.co/u/robgratz)\
**Replies:** 11\
**Last updated:** [October 28, 2016, 3:56pm UTC](https://discuss.elastic.co/t/authentication-using-java-api-and-transportclient/64196 "2016-10-28T15:56:56Z")

</div>

I'm fairly new to using elasticsearch and xpack and am having trouble figuring out how to specify the username/password for authentication when connecting to a node using the TransportClient. I know my basic configurati…

---

## [Using tag found in array as index name](https://discuss.elastic.co/t/using-tag-found-in-array-as-index-name/46057)

<div class="topic-metadata">

**Author:** [@blindpet](https://discuss.elastic.co/u/blindpet)\
**Replies:** 17\
**Last updated:** [April 4, 2016, 10:26am UTC](https://discuss.elastic.co/t/using-tag-found-in-array-as-index-name/46057 "2016-04-04T10:26:22Z")

</div>

We are trying to automate Logstash configuration template creation for about 200 customers. Each customer will have its own index based on its company name. Is it possible to use the tag found in array as a variable fo…

---

## [Kibana not starting up](https://discuss.elastic.co/t/kibana-not-starting-up/113365)

<div class="topic-metadata">

**Author:** [@robov](https://discuss.elastic.co/u/robov)\
**Replies:** 12\
**Last updated:** [January 10, 2018, 7:14am UTC](https://discuss.elastic.co/t/kibana-not-starting-up/113365 "2018-01-10T07:14:09Z")

</div>

I am trying to run a stack on my ubuntu docker system, and I tried many different containers but I simply cannot get it to work. The last one i tried,,, hence this discussion is :elastic/stack-docker When I run that.. …

---

## [Cannot recover index because of missing tanslog files](https://discuss.elastic.co/t/cannot-recover-index-because-of-missing-tanslog-files/38336)

<div class="topic-metadata">

**Author:** [@haizaar](https://discuss.elastic.co/u/haizaar)\
**Replies:** 10\
**Last updated:** [April 17, 2017, 7:50am UTC](https://discuss.elastic.co/t/cannot-recover-index-because-of-missing-tanslog-files/38336 "2017-04-17T07:50:59Z")

</div>

Good day. I have ES 2.1.0 with Kibana in single node demo environment. After unclean shutdown, .kibana index refuses to come up because of the following error in the logs: \[2016-01-04 18:52:06,313\]\[WARN \]\[cluster.a…

---

## [Java - build query due to the many fields](https://discuss.elastic.co/t/java-build-query-due-to-the-many-fields/116493)

<div class="topic-metadata">

**Author:** [@Nikita\_Krasnov](https://discuss.elastic.co/u/Nikita_Krasnov)\
**Replies:** 15\
**Last updated:** [January 24, 2018, 8:28am UTC](https://discuss.elastic.co/t/java-build-query-due-to-the-many-fields/116493 "2018-01-24T08:28:27Z")

</div>

I use Java and Java High Level REST Client. I need to build query that will find documents. This query should contain many fields for searching. For example, I have such json: { "timeStamp": "Fri, 29 Dec 2017 15:32:…

---

## [High CPU, disk load only on one node in cluster](https://discuss.elastic.co/t/high-cpu-disk-load-only-on-one-node-in-cluster/108926)

<div class="topic-metadata">

**Author:** [@vanch](https://discuss.elastic.co/u/vanch)\
**Replies:** 13\
**Last updated:** [December 13, 2017, 2:35pm UTC](https://discuss.elastic.co/t/high-cpu-disk-load-only-on-one-node-in-cluster/108926 "2017-12-13T14:35:52Z")

</div>

Hello there. Setup that i have: Cluster of 3 nodes with ES 5.3.0. All nodes are VMs in KVM hypervisor, with no more highloaded VMs on local hypervisors. VMs: Ubuntu 16.04 linux-4.4.0 kernel (different minor builds), …

---

## [Normalize the logs with ELK](https://discuss.elastic.co/t/normalize-the-logs-with-elk/178684)

<div class="topic-metadata">

**Author:** [@Labidi\_Ayoub](https://discuss.elastic.co/u/Labidi_Ayoub)\
**Replies:** 40\
**Last updated:** [May 10, 2019, 2:40pm UTC](https://discuss.elastic.co/t/normalize-the-logs-with-elk/178684 "2019-05-10T14:40:48Z")

</div>

Dear ELK Team, it is my first time with ELK, in the my workplace i woud get collection , standardization, analysis, correlation, reporting the logs of Firewall palo and switch CISCO...I am in a hurry, I worked with a l…

---

## [How to set up multiple clusters](https://discuss.elastic.co/t/how-to-set-up-multiple-clusters/108959)

<div class="topic-metadata">

**Author:** [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Replies:** 13\
**Last updated:** [December 1, 2017, 7:08am UTC](https://discuss.elastic.co/t/how-to-set-up-multiple-clusters/108959 "2017-12-01T07:08:06Z")

</div>

Hi, I am new in ES, I want to use multiple clusters to store data. My OS is windows 10. How could I set up the multiple cluster?Tune the config ? or doing something? this is the Elasticsearch.yml: \[image\] thank you …

---

## [Running Logstash as a service on windows using NSSM is not working](https://discuss.elastic.co/t/running-logstash-as-a-service-on-windows-using-nssm-is-not-working/100370)

<div class="topic-metadata">

**Author:** [@rajesh](https://discuss.elastic.co/u/rajesh)\
**Replies:** 9\
**Last updated:** [September 18, 2017, 2:37pm UTC](https://discuss.elastic.co/t/running-logstash-as-a-service-on-windows-using-nssm-is-not-working/100370 "2017-09-18T14:37:45Z")

</div>

Hi, I am trying to run Logstash as a service on windows using NSSM. It says the Logstash service is started successfully but I don't see any output logs(set the level as debug). Could it be related to permission issue? …

---

## [Filtering data from database](https://discuss.elastic.co/t/filtering-data-from-database/34797)

<div class="topic-metadata">

**Author:** [@vikas.saini](https://discuss.elastic.co/u/vikas.saini)\
**Replies:** 22\
**Last updated:** [November 19, 2015, 2:49pm UTC](https://discuss.elastic.co/t/filtering-data-from-database/34797 "2015-11-19T14:49:37Z")

</div>

I am taking data from database tables .how to filter this data ?can i filter

---

## [Unable to run set-password in 6.x](https://discuss.elastic.co/t/unable-to-run-set-password-in-6-x/117382)

<div class="topic-metadata">

**Author:** [@stephenpatten](https://discuss.elastic.co/u/stephenpatten)\
**Replies:** 10\
**Last updated:** [January 30, 2018, 12:22pm UTC](https://discuss.elastic.co/t/unable-to-run-set-password-in-6-x/117382 "2018-01-30T12:22:48Z")

</div>

Hello, I'm setting up a 6.1.2 windows cluster and have a gold license. This is the first machine in the cluster so I have generated a CA cert with a password and placed it in the config directory. relevant keys from th…

---

## [How to name new index based on time from log](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336)

<div class="topic-metadata">

**Author:** [@John16](https://discuss.elastic.co/u/John16)\
**Replies:** 9\
**Last updated:** [February 1, 2017, 8:37am UTC](https://discuss.elastic.co/t/how-to-name-new-index-based-on-time-from-log/73336 "2017-02-01T08:37:02Z")

</div>

Hello, by default logstash names index using pattern logstash-%{+yyyy.MM.dd} (and filebeat-%{+yyyy.MM.dd} for filebeat), where %{+yyyy.MM.dd} is the date when event is being published to ES. How can I substitute date…

---

## [Logstash is not listening port 5044](https://discuss.elastic.co/t/logstash-is-not-listening-port-5044/302621)

<div class="topic-metadata">

**Author:** [@Meda\_Akshay](https://discuss.elastic.co/u/Meda_Akshay)\
**Replies:** 18\
**Last updated:** [April 18, 2022, 3:34pm UTC](https://discuss.elastic.co/t/logstash-is-not-listening-port-5044/302621 "2022-04-18T15:34:55Z")

</div>

Hi, Am new to Logstash, here my issue is logstash is not listening at port 5044, here is my filebeat configuration output.logstash configured as following # ------------------------------ Logstash Output -------------…

---

## [Windows - packetbeat service failed to start](https://discuss.elastic.co/t/windows-packetbeat-service-failed-to-start/29523)

<div class="topic-metadata">

**Author:** [@inlikefletch](https://discuss.elastic.co/u/inlikefletch)\
**Replies:** 14\
**Last updated:** [May 2, 2016, 8:12am UTC](https://discuss.elastic.co/t/windows-packetbeat-service-failed-to-start/29523 "2016-05-02T08:12:33Z")

</div>

Hi, I am having trouble starting the packetbeat service on my application servers and local elk stack. Even if I install on my local elasticsearch server, windows server, keep the default yml file because those configura…

---

## [PostgreSQL integration](https://discuss.elastic.co/t/postgresql-integration/8316)

<div class="topic-metadata">

**Author:** [@Sanx\_El\_Santo](https://discuss.elastic.co/u/Sanx_El_Santo)\
**Replies:** 18\
**Last updated:** [July 31, 2014, 5:42pm UTC](https://discuss.elastic.co/t/postgresql-integration/8316 "2014-07-31T17:42:20Z")

</div>

Greetings to all Is there a process for setting up ElasticSearch to automatically index data in PostgreSQL and make it search-able? I am begining a project and I'm not quite sure where I have to start anyone ha…

---

## [Elastic master not discovered yet, this node has not previously joined a bootstrapped (v7+) cluster, and this node must discover master-eligible nodes](https://discuss.elastic.co/t/elastic-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-v7-cluster-and-this-node-must-discover-master-eligible-nodes/214118)

<div class="topic-metadata">

**Author:** [@Sreekanth3](https://discuss.elastic.co/u/Sreekanth3)\
**Replies:** 10\
**Last updated:** [January 8, 2020, 3:52pm UTC](https://discuss.elastic.co/t/elastic-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-v7-cluster-and-this-node-must-discover-master-eligible-nodes/214118 "2020-01-08T15:52:49Z")

</div>

Hi , I have upgraded my elasticsearch cluster of 3 nodes from 7.4.0 to 7.5.1 and after completing the upgradation of the ES . I'm getting this error master not discovered yet, this node has not previously joined a boot…

---

## [Can we create two GeoIP Filters in one logstash config file?](https://discuss.elastic.co/t/can-we-create-two-geoip-filters-in-one-logstash-config-file/42849)

<div class="topic-metadata">

**Author:** [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Replies:** 16\
**Last updated:** [July 15, 2016, 4:18pm UTC](https://discuss.elastic.co/t/can-we-create-two-geoip-filters-in-one-logstash-config-file/42849 "2016-07-15T16:18:57Z")

</div>

Hi Experts, My requirement is to create 2 maps , one is for Source IP and other is for Destination IP. For Source IP what I have done is I used GeoIP filter as below geoip { source =\> "src"} Now I am trying the sam…

---

## [Restore from S3 repository\_exception](https://discuss.elastic.co/t/restore-from-s3-repository-exception/268848)

<div class="topic-metadata">

**Author:** [@twilight](https://discuss.elastic.co/u/twilight)\
**Replies:** 9\
**Last updated:** [April 4, 2021, 1:38pm UTC](https://discuss.elastic.co/t/restore-from-s3-repository-exception/268848 "2021-04-04T13:38:27Z")

</div>

Hello, This is about restoring on self-managed from a snapshot created by managed stack. I have ES and Kibana 7.12 installed on Amazon Linux AMI. I have a cloud based cluster too which has created a number of snapshot…

---

## [Adding certificate to keystore](https://discuss.elastic.co/t/adding-certificate-to-keystore/323941)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 12\
**Last updated:** [February 7, 2023, 9:10am UTC](https://discuss.elastic.co/t/adding-certificate-to-keystore/323941 "2023-02-07T09:10:07Z")

</div>

Hi ! Using Elastic 8.6.0 here I started over a clean installation of Elastic and immediatly tried to overwrite the self-generate certificate of Elastic with my organization certificate (which is a certificate generate b…

---

## [JSON Array using Logstash](https://discuss.elastic.co/t/json-array-using-logstash/93088)

<div class="topic-metadata">

**Author:** [@code\_blue](https://discuss.elastic.co/u/code_blue)\
**Replies:** 20\
**Last updated:** [July 19, 2017, 9:47pm UTC](https://discuss.elastic.co/t/json-array-using-logstash/93088 "2017-07-19T21:47:40Z")

</div>

I am fetching data from SQL Server using Log stash. JDBC Rivers would convert columns with "." notation to Array structures. I am looking for a similar way in Log stash. I am using the logstash-filter-aggregate pluggin…

---

## [Can someone share nginx config for reverse proxying Kibana4.4/4,5](https://discuss.elastic.co/t/can-someone-share-nginx-config-for-reverse-proxying-kibana4-4-4-5/46326)

<div class="topic-metadata">

**Author:** [@abhijitdeka11](https://discuss.elastic.co/u/abhijitdeka11)\
**Replies:** 9\
**Last updated:** [June 2, 2017, 10:13am UTC](https://discuss.elastic.co/t/can-someone-share-nginx-config-for-reverse-proxying-kibana4-4-4-5/46326 "2017-06-02T10:13:54Z")

</div>

Hi, I am struggling to make reverse proxy work with latest versions of Kibana Kibana4.4 /Kibana 4.5 This is my current setting of nginx. My config for basepath is - server.basepath : "/analytics" I want to redire…

---

## [Kafka input and output plugin for logstash is not working](https://discuss.elastic.co/t/kafka-input-and-output-plugin-for-logstash-is-not-working/42271)

<div class="topic-metadata">

**Author:** [@gaurav1424](https://discuss.elastic.co/u/gaurav1424)\
**Replies:** 11\
**Last updated:** [August 16, 2016, 1:35pm UTC](https://discuss.elastic.co/t/kafka-input-and-output-plugin-for-logstash-is-not-working/42271 "2016-08-16T13:35:27Z")

</div>

Hello All, I am using Logstash 2.1.1 and kafka version 2.10-0.8.2.1. I am getting following syntax error. What are the minumum required settings for kafka plugin. Input.conf input { tcp { port =\> 5010 #typ…

---

## [Exclude dash "-" in Kibana search](https://discuss.elastic.co/t/exclude-dash-in-kibana-search/77572)

<div class="topic-metadata">

**Author:** [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Replies:** 9\
**Last updated:** [March 16, 2017, 4:44am UTC](https://discuss.elastic.co/t/exclude-dash-in-kibana-search/77572 "2017-03-16T04:44:48Z")

</div>

I am running Kibana 5x in AWS elasticsearch. I can't find a way to exclude a dash - when searching. I've tried... -referrer:- -referrer:"-" -referrer:-\* And none seem to work.

---

## [java.lang.ClassNotFoundException: org.elasticsearch.search.aggregations.metrics.cardinality.ParsedCardinality](https://discuss.elastic.co/t/java-lang-classnotfoundexception-org-elasticsearch-search-aggregations-metrics-cardinality-parsedcardinality/194304)

<div class="topic-metadata">

**Author:** [@iti](https://discuss.elastic.co/u/iti)\
**Replies:** 17\
**Last updated:** [September 12, 2019, 9:11pm UTC](https://discuss.elastic.co/t/java-lang-classnotfoundexception-org-elasticsearch-search-aggregations-metrics-cardinality-parsedcardinality/194304 "2019-09-12T21:11:33Z")

</div>

My environment: two ES clusters: one ES 6.7 and one ES 7.1 My app need to use High Level REST Client to access both cluster at the same time. When I am using 7.x REST CLIENT with 7.X ES library. When accessing 6.x ES,…

---

## [Logstash issue with Netflow module](https://discuss.elastic.co/t/logstash-issue-with-netflow-module/102898)

<div class="topic-metadata">

**Author:** [@juanquy](https://discuss.elastic.co/u/juanquy)\
**Replies:** 35\
**Last updated:** [October 17, 2017, 7:04am UTC](https://discuss.elastic.co/t/logstash-issue-with-netflow-module/102898 "2017-10-17T07:04:08Z")

</div>

HI : :smile: I'm having this issue with logstash with netflow module active: If I ran it from CLI with this command : ./logstash --modules netflow It work perfect , Kibana get the index patter netflow-\* and I can se…

---

## [Elasticsearch bulk update is extremely slow](https://discuss.elastic.co/t/elasticsearch-bulk-update-is-extremely-slow/78258)

<div class="topic-metadata">

**Author:** [@Vignesh\_Chandrasekar](https://discuss.elastic.co/u/Vignesh_Chandrasekar)\
**Replies:** 10\
**Last updated:** [March 13, 2017, 3:49am UTC](https://discuss.elastic.co/t/elasticsearch-bulk-update-is-extremely-slow/78258 "2017-03-13T03:49:31Z")

</div>

Hi Team, I have setup a cluster which indexes ~160GB of data per day into elasticsearch. I am currently facing this case where I need to update almost all the docs in all indices with a small amount of data(~16GB) per …

---

## [Delete Unassigned replica shards](https://discuss.elastic.co/t/delete-unassigned-replica-shards/182880)

<div class="topic-metadata">

**Author:** [@elk2](https://discuss.elastic.co/u/elk2)\
**Replies:** 9\
**Last updated:** [May 30, 2019, 3:09pm UTC](https://discuss.elastic.co/t/delete-unassigned-replica-shards/182880 "2019-05-30T15:09:02Z")

</div>

After a cluster crash for filesystem corruption , I restarted the 5 nodes elasticsearch. Actually I have 30 Unassigned replica shards that elasticsearch try to reassign without success. I want to delete them without lo…

---

## [What is the purpose of type field in Input section](https://discuss.elastic.co/t/what-is-the-purpose-of-type-field-in-input-section/39828)

<div class="topic-metadata">

**Author:** [@gaurav1424](https://discuss.elastic.co/u/gaurav1424)\
**Replies:** 17\
**Last updated:** [February 2, 2016, 7:05am UTC](https://discuss.elastic.co/t/what-is-the-purpose-of-type-field-in-input-section/39828 "2016-02-02T07:05:14Z")

</div>

Hello All, Whats the use of "type =\> " in Input section of Logstash ? Anyways I will be using grok filter in filter section to filter incoming messages ? Thanks, gaurav

---

## [Logstash pipeline not starting](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937)

<div class="topic-metadata">

**Author:** [@g.le](https://discuss.elastic.co/u/g.le)\
**Replies:** 10\
**Last updated:** [March 29, 2017, 8:01pm UTC](https://discuss.elastic.co/t/logstash-pipeline-not-starting/79937 "2017-03-29T20:01:38Z")

</div>

Hello, I have created a rather complex Logstash config using various plugins. I have noticed that Logstash normally produces the following entries in /var/log/logstash/logstash-plain.log: \[2017-03-24T20:01:05,639\]\[IN…

---

## [Custom format isn't supported](https://discuss.elastic.co/t/custom-format-isnt-supported/41083)

<div class="topic-metadata">

**Author:** [@arizonawayfarer](https://discuss.elastic.co/u/arizonawayfarer)\
**Replies:** 10\
**Last updated:** [November 20, 2016, 2:21pm UTC](https://discuss.elastic.co/t/custom-format-isnt-supported/41083 "2016-11-20T14:21:50Z")

</div>

Howdy everyone, I'm getting an exception in elasticsearch when trying to view logs in kibana. The index is reporting green in /\_cat/indices and shard allocation looks good.. I haven't had a problem with this particula…

---

## [I have this error bash: ./metricbeat: cannot execute binary file: Exec format error](https://discuss.elastic.co/t/i-have-this-error-bash-metricbeat-cannot-execute-binary-file-exec-format-error/269157)

<div class="topic-metadata">

**Author:** [@muradazz](https://discuss.elastic.co/u/muradazz)\
**Replies:** 29\
**Last updated:** [April 10, 2021, 2:56am UTC](https://discuss.elastic.co/t/i-have-this-error-bash-metricbeat-cannot-execute-binary-file-exec-format-error/269157 "2021-04-10T02:56:45Z")

</div>

root@mu:/home/murad/metricbeat-7.12.0-darwin-x86\_64# uname -m x86\_64 root@mu:/home/murad/metricbeat-7.12.0-darwin-x86\_64# file metricbeat metricbeat: Mach-O 64-bit x86\_64 executable, flags:\<|DYLDLINK\> root@mu:/home/m…

---

## [GEOIP / Nginx logs, no drop down in map visual](https://discuss.elastic.co/t/geoip-nginx-logs-no-drop-down-in-map-visual/91106)

<div class="topic-metadata">

**Author:** [@runtman](https://discuss.elastic.co/u/runtman)\
**Replies:** 35\
**Last updated:** [July 28, 2017, 1:15pm UTC](https://discuss.elastic.co/t/geoip-nginx-logs-no-drop-down-in-map-visual/91106 "2017-07-28T13:15:24Z")

</div>

Hello, so I want to visualise some of the Nginx logs we have with the geoip source. So I have the following in Filebeat configurations to push the logs - input\_type: log paths: - /var/log/nginx/dev/access.log d…

---

## [Winlogbeat getting x509: certificate signed by unknown authority while setting up Kibana](https://discuss.elastic.co/t/winlogbeat-getting-x509-certificate-signed-by-unknown-authority-while-setting-up-kibana/125006)

<div class="topic-metadata">

**Author:** [@elasticprof](https://discuss.elastic.co/u/elasticprof)\
**Replies:** 18\
**Last updated:** [March 22, 2018, 8:15pm UTC](https://discuss.elastic.co/t/winlogbeat-getting-x509-certificate-signed-by-unknown-authority-while-setting-up-kibana/125006 "2018-03-22T20:15:51Z")

</div>

I am getting x509: certificate signed by unknown authority error while trying to setup Kibana PS C:\\winlogbeat\> .\\winlogbeat.exe setup --dashboards Logstash Beats configuration file input { stdin {} beats { …

---

## [Elasticsearch not starting, with no errors in the logs](https://discuss.elastic.co/t/elasticsearch-not-starting-with-no-errors-in-the-logs/136169)

<div class="topic-metadata">

**Author:** [@Michael\_Chora](https://discuss.elastic.co/u/Michael_Chora)\
**Replies:** 17\
**Last updated:** [June 17, 2018, 10:45am UTC](https://discuss.elastic.co/t/elasticsearch-not-starting-with-no-errors-in-the-logs/136169 "2018-06-17T10:45:02Z")

</div>

Whats confusing is that it was working yesterday, I rebooted the machine, and today im getting this: root@ip-172-31-8-215:/home/admin# sudo service elasticsearch status ● elasticsearch.service - Elasticsearch Loaded:…

---

## [Bootstrap.system\_call\_filter to false not able to configure cluster](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062)

<div class="topic-metadata">

**Author:** [@sunmesiav](https://discuss.elastic.co/u/sunmesiav)\
**Replies:** 11\
**Last updated:** [September 2, 2017, 1:09am UTC](https://discuss.elastic.co/t/bootstrap-system-call-filter-to-false-not-able-to-configure-cluster/99062 "2017-09-02T01:09:49Z")

</div>

Hi, Iam using the Elasticsearch 5.5.2, and Iam not able to configure cluster. I dont see my nodes talking to each other. I tried using the following configuration in my elasticsearch.yml. I tried changing the transport…

---

## [Installing Kibana to connect to Elasticsearch production server](https://discuss.elastic.co/t/installing-kibana-to-connect-to-elasticsearch-production-server/66027)

<div class="topic-metadata">

**Author:** [@BrianAnderson](https://discuss.elastic.co/u/BrianAnderson)\
**Replies:** 15\
**Last updated:** [November 23, 2016, 12:34am UTC](https://discuss.elastic.co/t/installing-kibana-to-connect-to-elasticsearch-production-server/66027 "2016-11-23T00:34:50Z")

</div>

Hello, First post, so there is a likelihood that I may not understand how things work in connecting Kibana and Elasticsearch in a secure production environment. So, I have a live website that has access to our closed…

---

## [What's nested documents layout inside the lucene?](https://discuss.elastic.co/t/whats-nested-documents-layout-inside-the-lucene/59944)

<div class="topic-metadata">

**Author:** [@makeyang](https://discuss.elastic.co/u/makeyang)\
**Replies:** 13\
**Last updated:** [September 8, 2016, 8:35am UTC](https://discuss.elastic.co/t/whats-nested-documents-layout-inside-the-lucene/59944 "2016-09-08T08:35:14Z")

</div>

with nested objects, all entities live within the same document while but when use the sample in reference doc below, it is 3 docs. so my question is: what's nested documents layout inside the lucene PUT /my\_index { "ma…

---

## [How can I improve Logstash performance?](https://discuss.elastic.co/t/how-can-i-improve-logstash-performance/140882)

<div class="topic-metadata">

**Author:** [@white\_rabbit](https://discuss.elastic.co/u/white_rabbit)\
**Replies:** 24\
**Last updated:** [July 27, 2018, 7:50am UTC](https://discuss.elastic.co/t/how-can-i-improve-logstash-performance/140882 "2018-07-27T07:50:02Z")

</div>

Hello, I have logs in file and my logstash.conf looks in the way shown below. When I run sudo ./logstash -f /path/logstash.conf -b 100000 -w 1 and monitor elasticsearch node in Kibana I see on the graph in document count…

---

## [Getting Cannot assign requested address while starting elasticsearch](https://discuss.elastic.co/t/getting-cannot-assign-requested-address-while-starting-elasticsearch/141410)

<div class="topic-metadata">

**Author:** [@dhananjay88](https://discuss.elastic.co/u/dhananjay88)\
**Replies:** 12\
**Last updated:** [July 25, 2018, 6:39am UTC](https://discuss.elastic.co/t/getting-cannot-assign-requested-address-while-starting-elasticsearch/141410 "2018-07-25T06:39:53Z")

</div>

I am not able to get perfect solution from any of the previously posted question so I am asking this again as I am a newbie to elastic. Here what all I have done Installed elasticsearch on linux using git clone. Runnin…

---

## [Logstash Mixing Throttled and Non-Throttled inputs](https://discuss.elastic.co/t/logstash-mixing-throttled-and-non-throttled-inputs/26548)

<div class="topic-metadata">

**Author:** [@Yarden\_Bar](https://discuss.elastic.co/u/Yarden_Bar)\
**Replies:** 14\
**Last updated:** [October 5, 2015, 3:26am UTC](https://discuss.elastic.co/t/logstash-mixing-throttled-and-non-throttled-inputs/26548 "2015-10-05T03:26:26Z")

</div>

Hi, Intro We use Logstash with both throttled and unthrottled inputs. There's already an issue on github, but per suyograo recommendation, I'm opening the question here as well. Components configuration: Elasticsear…

---

## [Combining two fields into one during Reindex](https://discuss.elastic.co/t/combining-two-fields-into-one-during-reindex/194700)

<div class="topic-metadata">

**Author:** [@Nikhil04](https://discuss.elastic.co/u/Nikhil04)\
**Replies:** 10\
**Last updated:** [August 20, 2019, 10:06am UTC](https://discuss.elastic.co/t/combining-two-fields-into-one-during-reindex/194700 "2019-08-20T10:06:42Z")

</div>

Hi, We have a requirement wherein we want to combine two fields into one field during reindex. For Example: Original Index: field1: firstname field2: lastname After reindex: Name: firstname lastname I have checke…

---

## [Elasticsearch.Net NEST connection string when Active Directory turn on (Elasticsearch Authentication)](https://discuss.elastic.co/t/elasticsearch-net-nest-connection-string-when-active-directory-turn-on-elasticsearch-authentication/71753)

<div class="topic-metadata">

**Author:** [@sabahshariq](https://discuss.elastic.co/u/sabahshariq)\
**Replies:** 13\
**Last updated:** [January 17, 2017, 8:19pm UTC](https://discuss.elastic.co/t/elasticsearch-net-nest-connection-string-when-active-directory-turn-on-elasticsearch-authentication/71753 "2017-01-17T20:19:40Z")

</div>

We have a cluster running Elasticsearch v5.0.0. Recently active directory functionality is turn on in ES so, the way connection string was written earlier it is not working and giving following error when perform Search/…

---

## [Cannot install x-pack to Kibana due to no valid URL](https://discuss.elastic.co/t/cannot-install-x-pack-to-kibana-due-to-no-valid-url/64112)

<div class="topic-metadata">

**Author:** [@Andersch\_Be](https://discuss.elastic.co/u/Andersch_Be)\
**Replies:** 12\
**Last updated:** [February 6, 2017, 1:13pm UTC](https://discuss.elastic.co/t/cannot-install-x-pack-to-kibana-due-to-no-valid-url/64112 "2017-02-06T13:13:28Z")

</div>

Good morning, I'm absolutely new to the whole Stack, so please be patient with my lack of knowledge. :wink: Trying to install Elasticsearch, Kibana, Logstash and Winlogbeat to get a whiff of how to handle it all, I r…

---

## [Unable to connect to ES Cluster on AWS Elasticsearch Service through Hadoop](https://discuss.elastic.co/t/unable-to-connect-to-es-cluster-on-aws-elasticsearch-service-through-hadoop/39283)

<div class="topic-metadata">

**Author:** [@shamak](https://discuss.elastic.co/u/shamak)\
**Replies:** 14\
**Last updated:** [March 22, 2016, 5:49pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-es-cluster-on-aws-elasticsearch-service-through-hadoop/39283 "2016-03-22T17:49:10Z")

</div>

I'm using version 2.2.0 of the elasticsearch-hadoop library. My ES cluster is hosted on Amazon Elasticsearch Service (https://aws.amazon.com/elasticsearch-service/). There is only one exposed URL to hit the cluster (htt…

---

## [Bulk updates are extremely slow after upgrading to 5.2](https://discuss.elastic.co/t/bulk-updates-are-extremely-slow-after-upgrading-to-5-2/79450)

<div class="topic-metadata">

**Author:** [@Zaid\_Amir](https://discuss.elastic.co/u/Zaid_Amir)\
**Replies:** 27\
**Last updated:** [April 21, 2017, 11:02am UTC](https://discuss.elastic.co/t/bulk-updates-are-extremely-slow-after-upgrading-to-5-2/79450 "2017-04-21T11:02:20Z")

</div>

I am having an issue after upgrading my cluster from ES 1.7 to 5.2. The reindexing and upgrade were done two days ago and I did not have an issue on 1.7 before upgrading. The bulk update tasks are taking a long time to …

---

## ["Failed to publish events", "use of closed network connection"](https://discuss.elastic.co/t/failed-to-publish-events-use-of-closed-network-connection/119399)

<div class="topic-metadata">

**Author:** [@Andrew\_Shu](https://discuss.elastic.co/u/Andrew_Shu)\
**Replies:** 12\
**Last updated:** [March 22, 2018, 8:50am UTC](https://discuss.elastic.co/t/failed-to-publish-events-use-of-closed-network-connection/119399 "2018-03-22T08:50:01Z")

</div>

I'm trying to get a basic ELK setup, but I've been having difficulties verifying that Filebeat publishes to Logstash. Filebeat reports that it can't publish events because "use of closed network connection". I suspect i…

[Previous page](https://discuss.elastic.co/top.md?page=20&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=22&per_page=50&period=all)
