# Top

**URL:** https://discuss.elastic.co/top.md?page=24&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 25

---

## [Filebeat unable to sent logs](https://discuss.elastic.co/t/filebeat-unable-to-sent-logs/134595)

<div class="topic-metadata">

**Author:** [@mamta](https://discuss.elastic.co/u/mamta)\
**Replies:** 70\
**Last updated:** [July 24, 2018, 6:14am UTC](https://discuss.elastic.co/t/filebeat-unable-to-sent-logs/134595 "2018-07-24T06:14:01Z")

</div>

Hi, I have installed ELK 5.6.8 on Redhat server and filebeat on another redhat server. I have used logstash to collect data from filebeat. I have changed default port 5044 with 5045 in the filebeat.yml file because 50…

---

## [Cannot access elasticsearch from my browser and curl command not working for public ip from server terminal](https://discuss.elastic.co/t/cannot-access-elasticsearch-from-my-browser-and-curl-command-not-working-for-public-ip-from-server-terminal/166881)

<div class="topic-metadata">

**Author:** [@Arvind\_Singh](https://discuss.elastic.co/u/Arvind_Singh)\
**Replies:** 21\
**Last updated:** [February 4, 2019, 5:07am UTC](https://discuss.elastic.co/t/cannot-access-elasticsearch-from-my-browser-and-curl-command-not-working-for-public-ip-from-server-terminal/166881 "2019-02-04T05:07:10Z")

</div>

Hi, Hope anyone helps me here... I am having two ec2 instances and one of the instance having elasticsearch sucessfully running and accessible from browser. However issue with second instance where i have elasticsearch…

---

## [Adding S3 bucket for snapshot](https://discuss.elastic.co/t/adding-s3-bucket-for-snapshot/110643)

<div class="topic-metadata">

**Author:** [@mudgilgaurav](https://discuss.elastic.co/u/mudgilgaurav)\
**Replies:** 35\
**Last updated:** [December 13, 2017, 10:28am UTC](https://discuss.elastic.co/t/adding-s3-bucket-for-snapshot/110643 "2017-12-13T10:28:26Z")

</div>

I am trying to add S3 bucket for taking snapshot of my elastic cluster. I am running Elasticsearch 2.3.3 and installed plugin cloud-aws. Following is syntax of my request curl -X POST "http://XXX.XXX.XXX.XXX:9200/\_snaps…

---

## [Kibana behind Haproxy : A basepath problem?](https://discuss.elastic.co/t/kibana-behind-haproxy-a-basepath-problem/161564)

<div class="topic-metadata">

**Author:** [@Oliv](https://discuss.elastic.co/u/Oliv)\
**Replies:** 21\
**Last updated:** [January 9, 2019, 4:37pm UTC](https://discuss.elastic.co/t/kibana-behind-haproxy-a-basepath-problem/161564 "2019-01-09T16:37:18Z")

</div>

Hello Everybody, First of all I'm pretty new to the Kibana world and Haproxy. Installation : Centos 7 Haproxy 1.5.18 : installed through yum install haproxy. Kibana : 6.5 latest release. It's an 'In the box configu…

---

## [Elasticsearch transport client spawning a large number of threads](https://discuss.elastic.co/t/elasticsearch-transport-client-spawning-a-large-number-of-threads/526)

<div class="topic-metadata">

**Author:** [@Ash\_S](https://discuss.elastic.co/u/Ash_S)\
**Replies:** 11\
**Last updated:** [February 9, 2016, 6:37pm UTC](https://discuss.elastic.co/t/elasticsearch-transport-client-spawning-a-large-number-of-threads/526 "2016-02-09T18:37:19Z")

</div>

From an Apache storm bolt, I am using Elasticsearch's transport client to remotely connect to an ES cluster. When I take a jstack output of the storm process, I notice that there are nearly 1000 threads with an ES stack …

---

## [Getting "empty text" and "invalid version format" exceptions](https://discuss.elastic.co/t/getting-empty-text-and-invalid-version-format-exceptions/52471)

<div class="topic-metadata">

**Author:** [@Gen\_Ohta](https://discuss.elastic.co/u/Gen_Ohta)\
**Replies:** 12\
**Last updated:** [June 11, 2016, 1:29am UTC](https://discuss.elastic.co/t/getting-empty-text-and-invalid-version-format-exceptions/52471 "2016-06-11T01:29:16Z")

</div>

Hello, I am using Elasticsearch version 2.3.0 and Logstash version 2.2.2. At the moment, I am getting "empty text" and "invalid version format" java exceptions for my Elasticsearch node, which are shown in the logs be…

---

## [Elasticsearch using too much memory](https://discuss.elastic.co/t/elasticsearch-using-too-much-memory/242808)

<div class="topic-metadata">

**Author:** [@SteveHodges](https://discuss.elastic.co/u/SteveHodges)\
**Replies:** 9\
**Last updated:** [July 29, 2020, 11:08pm UTC](https://discuss.elastic.co/t/elasticsearch-using-too-much-memory/242808 "2020-07-29T23:08:12Z")

</div>

Hello, Originally the ELK stack was working great but after several months of collecting logs, Kibana reports are failing to run properly and it appears due to Elasticsearch memory issues. At least for the past week th…

---

## [How to implement multi tenant environment in Elasticsearch](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 18\
**Last updated:** [August 31, 2023, 4:38am UTC](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606 "2023-08-31T04:38:05Z")

</div>

What is the approach the Elasticsearch community recommends to use in a multi-tenant environment? Is one index Approach good? what are the pros and cons? Thanks, Harshal

---

## [Failed to create shard exception](https://discuss.elastic.co/t/failed-to-create-shard-exception/46715)

<div class="topic-metadata">

**Author:** [@Youxu](https://discuss.elastic.co/u/Youxu)\
**Replies:** 18\
**Last updated:** [June 14, 2016, 6:32am UTC](https://discuss.elastic.co/t/failed-to-create-shard-exception/46715 "2016-06-14T06:32:28Z")

</div>

I got following exception in Elasticsearch log file: \[2016-04-07 11:26:37,740\]\[WARN \]\[indices.cluster \] \[data-node-vm2\] \[\[mmx\_20160210\]\[2\]\] marking and sending shard failed due to \[failed to create shard\] org.…

---

## [Splitting Values in Data](https://discuss.elastic.co/t/splitting-values-in-data/26682)

<div class="topic-metadata">

**Author:** [@dray0n](https://discuss.elastic.co/u/dray0n)\
**Replies:** 11\
**Last updated:** [August 3, 2015, 1:01am UTC](https://discuss.elastic.co/t/splitting-values-in-data/26682 "2015-08-03T01:01:56Z")

</div>

I have been searching the internet for a few hours now trying to solve this question. I am currently parsing out data from Cuckoo Sandbox (automated malware analysis) which comes as a key-value pair. The issue I am runn…

---

## [While updating logstash 1.4.2 we encounter - Unable to find JRuby error](https://discuss.elastic.co/t/while-updating-logstash-1-4-2-we-encounter-unable-to-find-jruby-error/36152)

<div class="topic-metadata">

**Author:** [@meet2datta](https://discuss.elastic.co/u/meet2datta)\
**Replies:** 26\
**Last updated:** [December 10, 2015, 10:15am UTC](https://discuss.elastic.co/t/while-updating-logstash-1-4-2-we-encounter-unable-to-find-jruby-error/36152 "2015-12-10T10:15:25Z")

</div>

Hello Team, We were trying to update logstash for 1.4.2 to 2.1.0 latest version. We encounter below issues -- /opt/logstash/bin/logstash: line 22: dirname: command not found /opt/logstash/bin/logstash: line 22: //b…

---

## [Can't log in in Kibana GUI](https://discuss.elastic.co/t/cant-log-in-in-kibana-gui/213106)

<div class="topic-metadata">

**Author:** [@emilio](https://discuss.elastic.co/u/emilio)\
**Replies:** 9\
**Last updated:** [January 15, 2020, 12:12pm UTC](https://discuss.elastic.co/t/cant-log-in-in-kibana-gui/213106 "2020-01-15T12:12:55Z")

</div>

Dear all, I need your support. I have installed ES 7.5, Kibana 7.5 I have switched license type to trial in order to use x-pack. Also, i have changed all built-in users passwords. Currently no one user can log in K…

---

## [Data Loss in elasticsearch in high load](https://discuss.elastic.co/t/data-loss-in-elasticsearch-in-high-load/114515)

<div class="topic-metadata">

**Author:** [@paramlogicoy](https://discuss.elastic.co/u/paramlogicoy)\
**Replies:** 23\
**Last updated:** [January 9, 2018, 12:36pm UTC](https://discuss.elastic.co/t/data-loss-in-elasticsearch-in-high-load/114515 "2018-01-09T12:36:46Z")

</div>

Hi All, We are facing a strange and critical issue while testing elastic-search in high speed transaction monitoring. We are using Elastic-search for dumping high speed data coming from JMX MXbean. Our JMX listeners ar…

---

## [Scoring by distance](https://discuss.elastic.co/t/scoring-by-distance/75141)

<div class="topic-metadata">

**Author:** [@enp](https://discuss.elastic.co/u/enp)\
**Replies:** 16\
**Last updated:** [February 17, 2017, 6:36am UTC](https://discuss.elastic.co/t/scoring-by-distance/75141 "2017-02-17T06:36:19Z")

</div>

Hi, I need to set score by distance and I found good example - https://www.elastic.co/guide/en/elasticsearch/guide/current/decay-functions.html - but it looks not working in my case. My request: GET earth/destinati…

---

## [Service is getting stopped automatically](https://discuss.elastic.co/t/service-is-getting-stopped-automatically/106797)

<div class="topic-metadata">

**Author:** [@Sandeep.K](https://discuss.elastic.co/u/Sandeep.K)\
**Replies:** 9\
**Last updated:** [November 9, 2017, 8:26am UTC](https://discuss.elastic.co/t/service-is-getting-stopped-automatically/106797 "2017-11-09T08:26:33Z")

</div>

Hi Team Need help on the below topic. I have elasticsearch in my environment. It was running fine but suddenly elasticsearch service "Elasticsearch 2.3.2 (elasticsearch-service-x64)" got stopped. Now i am trying to res…

---

## [Elasticsearch status:red](https://discuss.elastic.co/t/elasticsearch-status-red/109932)

<div class="topic-metadata">

**Author:** [@minidan](https://discuss.elastic.co/u/minidan)\
**Replies:** 14\
**Last updated:** [December 8, 2017, 9:49am UTC](https://discuss.elastic.co/t/elasticsearch-status-red/109932 "2017-12-08T09:49:21Z")

</div>

Hi team and all, Newbie to ELK and evaluating to put live soon, was all working until it stopped... no changes made just adding servers in one by one using winbeatlog direct to elasticsearch. Can someone tell me what I…

---

## [Search Exact and partial match](https://discuss.elastic.co/t/search-exact-and-partial-match/209282)

<div class="topic-metadata">

**Author:** [@KrishK](https://discuss.elastic.co/u/KrishK)\
**Replies:** 16\
**Last updated:** [January 10, 2020, 7:55am UTC](https://discuss.elastic.co/t/search-exact-and-partial-match/209282 "2020-01-10T07:55:33Z")

</div>

Hi Support, I have keyword like: 'ABC - DEF', 'ABC DEF', 'ABC is there any combination with DEF'. Exact Match : "ABC-DEF" - Its gives perfect result ("ABC-DEF"). Partial Match: "ABC-DE" - its gives more result (all 3…

---

## [Get events through Logstash to Qradar](https://discuss.elastic.co/t/get-events-through-logstash-to-qradar/62502)

<div class="topic-metadata">

**Author:** [@christiaan.spriet](https://discuss.elastic.co/u/christiaan.spriet)\
**Replies:** 9\
**Last updated:** [November 2, 2016, 12:33pm UTC](https://discuss.elastic.co/t/get-events-through-logstash-to-qradar/62502 "2016-11-02T12:33:39Z")

</div>

Hi, we're planning on using Logstash as a central shippier to send logs to a SIEM (qradar in this case) & Logstash. Qradar however doesn't want to automatically parse these events as it doesn't recognize the source (it…

---

## [NoNodeAvailableException\[None of the configured nodes are available: \[{#transport#-1}{DzxzK0iPRpWhbsQrG1XL-Q}{localhost}{127.0.0.1:9200}\]\]](https://discuss.elastic.co/t/nonodeavailableexception-none-of-the-configured-nodes-are-available-transport-1-dzxzk0iprpwhbsqrg1xl-q-localhost-127-0-0-1-9200/164625)

<div class="topic-metadata">

**Author:** [@Sajawal\_Sohail](https://discuss.elastic.co/u/Sajawal_Sohail)\
**Replies:** 11\
**Last updated:** [January 18, 2019, 12:48pm UTC](https://discuss.elastic.co/t/nonodeavailableexception-none-of-the-configured-nodes-are-available-transport-1-dzxzk0iprpwhbsqrg1xl-q-localhost-127-0-0-1-9200/164625 "2019-01-18T12:48:03Z")

</div>

I am facing this error while implementing elastic search in spring boot. org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'loaders': Invocation of init method failed; nested excepti…

---

## [Watcher input extract fields](https://discuss.elastic.co/t/watcher-input-extract-fields/40315)

<div class="topic-metadata">

**Author:** [@nidheeshb](https://discuss.elastic.co/u/nidheeshb)\
**Replies:** 17\
**Last updated:** [March 10, 2016, 4:51pm UTC](https://discuss.elastic.co/t/watcher-input-extract-fields/40315 "2016-03-10T16:51:34Z")

</div>

I am working towards creating a watcher that triggers a webhook when my JVM heap usage crosses a particular threshold. I have a http input which requests the node stats from the cluster. Currently the entire response is…

---

## [My elasticsearch fatal error in thread](https://discuss.elastic.co/t/my-elasticsearch-fatal-error-in-thread/140645)

<div class="topic-metadata">

**Author:** [@chenzilong444](https://discuss.elastic.co/u/chenzilong444)\
**Replies:** 10\
**Last updated:** [July 19, 2018, 9:20pm UTC](https://discuss.elastic.co/t/my-elasticsearch-fatal-error-in-thread/140645 "2018-07-19T21:20:25Z")

</div>

that is log \[2018-07-19T10:08:09,453\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtExceptionHandler\] \[\] fatal error in thread \[elasticsearch\[cvhieo8\]\[management\]\[T#1848\]\], exiting java.lang.OutOfMemoryError: Java heap space Heap…

---

## [Filebeat can not publish events to Elastic Search](https://discuss.elastic.co/t/filebeat-can-not-publish-events-to-elastic-search/72438)

<div class="topic-metadata">

**Author:** [@sam281](https://discuss.elastic.co/u/sam281)\
**Replies:** 16\
**Last updated:** [February 7, 2017, 1:28am UTC](https://discuss.elastic.co/t/filebeat-can-not-publish-events-to-elastic-search/72438 "2017-02-07T01:28:10Z")

</div>

Hi All, I am a newbie in ELK stack and working on a POC. I am trying to ingest some log data using File beats from a RHEL machine to elastic search on a remote windows machine. I keep seeing an error message saying th…

---

## [Corrupted translog](https://discuss.elastic.co/t/corrupted-translog/87254)

<div class="topic-metadata">

**Author:** [@bontchev](https://discuss.elastic.co/u/bontchev)\
**Replies:** 17\
**Last updated:** [May 30, 2017, 8:42pm UTC](https://discuss.elastic.co/t/corrupted-translog/87254 "2017-05-30T20:42:44Z")

</div>

After a power failure, something in my Elasticsearch database has become corrupted and the eleasticsearch service refuses to work. The error in the error log is: \[2017-05-26T14:28:33,318\]\[WARN \]\[o.e.c.a.s.ShardStateAct…

---

## [Getting Timeout Exceptions with Elasticsearch](https://discuss.elastic.co/t/getting-timeout-exceptions-with-elasticsearch/20713)

<div class="topic-metadata">

**Author:** [@shriyansh\_jain](https://discuss.elastic.co/u/shriyansh_jain)\
**Replies:** 11\
**Last updated:** [November 12, 2014, 9:39pm UTC](https://discuss.elastic.co/t/getting-timeout-exceptions-with-elasticsearch/20713 "2014-11-12T21:39:34Z")

</div>

Hi all, I am getting timeout exceptions with elastic search while deleting an index and while looking for logs in kibana its taking lot of time to load logs. Following are the log details and setup info. API Cal…

---

## [Error encountered after modified elasticsearch.yml](https://discuss.elastic.co/t/error-encountered-after-modified-elasticsearch-yml/125526)

<div class="topic-metadata">

**Author:** [@yks](https://discuss.elastic.co/u/yks)\
**Replies:** 18\
**Last updated:** [March 28, 2018, 2:15am UTC](https://discuss.elastic.co/t/error-encountered-after-modified-elasticsearch-yml/125526 "2018-03-28T02:15:45Z")

</div>

Hi, I am trying out new version Elasticsearch 6.2.3 on AWS Ubuntu 16.04 After configuring the elasticsearch.yml file I received these error ubuntu@ip-172-31-25-205:/etc$ sudo /etc/init.d/elasticsearch status ● elasti…

---

## [Cluster (connect 2 nodes)](https://discuss.elastic.co/t/cluster-connect-2-nodes/134384)

<div class="topic-metadata">

**Author:** [@asalma](https://discuss.elastic.co/u/asalma)\
**Replies:** 51\
**Last updated:** [June 5, 2018, 8:28am UTC](https://discuss.elastic.co/t/cluster-connect-2-nodes/134384 "2018-06-05T08:28:39Z")

</div>

Hi, I want to connecte 2 nodes Elastic search to make a cluster, the two nodes are on a different servers. Can someone help me to do this ?

---

## [Process Cluster Event Timeout Exception on put-mapping](https://discuss.elastic.co/t/process-cluster-event-timeout-exception-on-put-mapping/127227)

<div class="topic-metadata">

**Author:** [@ashokm](https://discuss.elastic.co/u/ashokm)\
**Replies:** 11\
**Last updated:** [May 3, 2018, 9:12pm UTC](https://discuss.elastic.co/t/process-cluster-event-timeout-exception-on-put-mapping/127227 "2018-05-03T21:12:43Z")

</div>

Hi All, Occasionally I am getting following exception on my 6 node ES cluster 2.4.6 2018-04-08 03:04:09,903\]\[DEBUG\]\[action.admin.indices.mapping.put\] \[PROD Node1\] failed to put mappings on indices \[\[index\_XXXXX\]\], type…

---

## [How can I use aggregations to query distinct values across all time grouped by first seen](https://discuss.elastic.co/t/how-can-i-use-aggregations-to-query-distinct-values-across-all-time-grouped-by-first-seen/25482)

<div class="topic-metadata">

**Author:** [@simon](https://discuss.elastic.co/u/simon)\
**Replies:** 16\
**Last updated:** [September 25, 2015, 8:35am UTC](https://discuss.elastic.co/t/how-can-i-use-aggregations-to-query-distinct-values-across-all-time-grouped-by-first-seen/25482 "2015-09-25T08:35:10Z")

</div>

Hi, I am trying to query unique uuids across all time grouped by first seen. I can do this in mysql using a nested select like follows. select firstSeen, count(\*) from ( select uuid, date\_format(min(createdAt), "%Y-%…

---

## [How to Index file system](https://discuss.elastic.co/t/how-to-index-file-system/28281)

<div class="topic-metadata">

**Author:** [@Sahas\_Sahas](https://discuss.elastic.co/u/Sahas_Sahas)\
**Replies:** 10\
**Last updated:** [November 21, 2016, 7:40pm UTC](https://discuss.elastic.co/t/how-to-index-file-system/28281 "2016-11-21T19:40:43Z")

</div>

I am new to elasticsearch framework and My task is to build a search engine for file server using ES framework. I am using ES 1.7 version. My high level requirements are below 1. The file should be searchable by its Nam…

---

## [Org.elasticsearch.cluster.block.ClusterBlockException: blocked by: \[SERVICE\_UNAVAILABLE/2/no master\];](https://discuss.elastic.co/t/org-elasticsearch-cluster-block-clusterblockexception-blocked-by-service-unavailable-2-no-master/27380)

<div class="topic-metadata">

**Author:** [@Blured\_Derulb](https://discuss.elastic.co/u/Blured_Derulb)\
**Replies:** 33\
**Last updated:** [October 1, 2015, 2:46pm UTC](https://discuss.elastic.co/t/org-elasticsearch-cluster-block-clusterblockexception-blocked-by-service-unavailable-2-no-master/27380 "2015-10-01T14:46:47Z")

</div>

Bonjour, Assez souvent j'ai ce type d'erreur dans mes logs lors de l'insertion dans du ELS 1.7. Est-ce une erreur réseau ou ceci pourrait il être causé par une saturation d'une des 2 machines de mon cluster ? SERV…

---

## [Error parsing json with Logstash](https://discuss.elastic.co/t/error-parsing-json-with-logstash/198749)

<div class="topic-metadata">

**Author:** [@aleksei.saiko](https://discuss.elastic.co/u/aleksei.saiko)\
**Replies:** 14\
**Last updated:** [September 12, 2019, 11:32am UTC](https://discuss.elastic.co/t/error-parsing-json-with-logstash/198749 "2019-09-12T11:32:10Z")

</div>

Hi there, I'm using ELK 7.3.1 And getting Error parsing json for "message" This is how message looks like in origin (Exacmple)- message {"time\_date": "2019-02-14T14:00:39+00:00","client": "10.xxx.xxx.xxx", "h…

---

## [How to install logstash-input-jdbc in windows](https://discuss.elastic.co/t/how-to-install-logstash-input-jdbc-in-windows/26149)

<div class="topic-metadata">

**Author:** [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Replies:** 12\
**Last updated:** [March 11, 2016, 2:42pm UTC](https://discuss.elastic.co/t/how-to-install-logstash-input-jdbc-in-windows/26149 "2016-03-11T14:42:40Z")

</div>

hi, I tried to use logstash-input-jdbc using followed command :plugin install logstash-input-jdbc But it is showing some error, i am using logstash logstash-1.5.2 , how to install jdbc plugin in windows machine so I…

---

## [Kibana 6.4 getting Request failed with status code: 403](https://discuss.elastic.co/t/kibana-6-4-getting-request-failed-with-status-code-403/146538)

<div class="topic-metadata">

**Author:** [@amit.patra](https://discuss.elastic.co/u/amit.patra)\
**Replies:** 14\
**Last updated:** [September 4, 2018, 8:11pm UTC](https://discuss.elastic.co/t/kibana-6-4-getting-request-failed-with-status-code-403/146538 "2018-09-04T20:11:25Z")

</div>

Hi, I have removed kibana 5.5 from my redhat 6.9 server and installed 6.4. But on every request I got the below error : Config: Request failed with status code: 403 Error: Request failed with status code: 403 $@ht…

---

## [Pipeline/output.go:154 Failed to connect to backoff](https://discuss.elastic.co/t/pipeline-output-go-154-failed-to-connect-to-backoff/290767)

<div class="topic-metadata">

**Author:** [@abhi.logs](https://discuss.elastic.co/u/abhi.logs)\
**Replies:** 10\
**Last updated:** [December 7, 2021, 5:03am UTC](https://discuss.elastic.co/t/pipeline-output-go-154-failed-to-connect-to-backoff/290767 "2021-12-07T05:03:31Z")

</div>

Hello, I'm getting this error, does anyone knows how to solve this? ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(https://xxxxxx:9200)): Connection marked as failed…

---

## [Blocked by: \[FORBIDDEN/8/index write (api)\]; Reindex](https://discuss.elastic.co/t/blocked-by-forbidden-8-index-write-api-reindex/285799)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 10\
**Last updated:** [October 6, 2021, 11:01am UTC](https://discuss.elastic.co/t/blocked-by-forbidden-8-index-write-api-reindex/285799 "2021-10-06T11:01:44Z")

</div>

Hey team, I was reindexing one of my index but suddenly it stopped because shard size reaches to 60gb and it rollover to new index.I am getting an error now i cannot write after index get rollover "cause" : { …

---

## [Elasticsearch.service: Can't open PID file /run/elasticsearch/elasticsearch.pid No such file or directory](https://discuss.elastic.co/t/elasticsearch-service-cant-open-pid-file-run-elasticsearch-elasticsearch-pid-no-such-file-or-directory/119597)

<div class="topic-metadata">

**Author:** [@stardiviner](https://discuss.elastic.co/u/stardiviner)\
**Replies:** 9\
**Last updated:** [February 19, 2018, 3:23pm UTC](https://discuss.elastic.co/t/elasticsearch-service-cant-open-pid-file-run-elasticsearch-elasticsearch-pid-no-such-file-or-directory/119597 "2018-02-19T15:23:21Z")

</div>

Environment: Arch Linux ElasticSearch package version: 6.2.1-1 (Arch package version) Config files: (All configs are by default from package). Systemd service unit file: /usr/lib/systemd/system/elasticsearch.servic…

---

## [Got response code '401' after Securing the Stack](https://discuss.elastic.co/t/got-response-code-401-after-securing-the-stack/201087)

<div class="topic-metadata">

**Author:** [@mfisher](https://discuss.elastic.co/u/mfisher)\
**Replies:** 17\
**Last updated:** [October 1, 2019, 2:09pm UTC](https://discuss.elastic.co/t/got-response-code-401-after-securing-the-stack/201087 "2019-10-01T14:09:00Z")

</div>

I recently used this guide https://www.elastic.co/blog/getting-started-with-elasticsearch-security to secure our ELK stack. I am able to log in to Kibana and TSL is working correctly. However my syslogs from logstash h…

---

## [Have to run logstash config file automatically](https://discuss.elastic.co/t/have-to-run-logstash-config-file-automatically/106195)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 16\
**Last updated:** [November 10, 2017, 9:27am UTC](https://discuss.elastic.co/t/have-to-run-logstash-config-file-automatically/106195 "2017-11-10T09:27:52Z")

</div>

Hi, I'm running logstash on linux machine as a service. I have 2 config files through which data is indexing. Now, I want this logstash configs to run as a service ( so that indexing will not stop after restarting the…

---

## [\[DEBUG\]\[o.e.a.s.TransportSearchAction\] \[myhost\] All shards failed for phase: \[query\]](https://discuss.elastic.co/t/debug-o-e-a-s-transportsearchaction-myhost-all-shards-failed-for-phase-query/137351)

<div class="topic-metadata">

**Author:** [@Watch\_out](https://discuss.elastic.co/u/Watch_out)\
**Replies:** 21\
**Last updated:** [July 7, 2018, 8:21am UTC](https://discuss.elastic.co/t/debug-o-e-a-s-transportsearchaction-myhost-all-shards-failed-for-phase-query/137351 "2018-07-07T08:21:43Z")

</div>

ELK version 6.2.4 Filebeat version 6.2.4 My entire ELK stack were working fine till 1.35 A IST as of 06/26/2018 Suddenly i can't see any logs in kibana from June-26-2018 1:40 AM IST onwards. When i open kibana it sho…

---

## [JSON array parsing in Logstash using the ruby filter](https://discuss.elastic.co/t/json-array-parsing-in-logstash-using-the-ruby-filter/146829)

<div class="topic-metadata">

**Author:** [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Replies:** 10\
**Last updated:** [September 24, 2018, 11:26am UTC](https://discuss.elastic.co/t/json-array-parsing-in-logstash-using-the-ruby-filter/146829 "2018-09-24T11:26:55Z")

</div>

Hi All, I have to parse json logs using Logstash. I have a file with my JSON data. I am using the following config and it works perfectly fine for most cases. input { file { path =\> "/opt/logs/\*.log" sincedb\_…

---

## [Empty Indexes?](https://discuss.elastic.co/t/empty-indexes/154466)

<div class="topic-metadata">

**Author:** [@KuboMD](https://discuss.elastic.co/u/KuboMD)\
**Replies:** 15\
**Last updated:** [November 2, 2018, 3:30pm UTC](https://discuss.elastic.co/t/empty-indexes/154466 "2018-11-02T15:30:45Z")

</div>

Hi there, I'm running a Graylog server. I accidentally deleted the contents of my index folders. /var/lib/elasticsearch/nodes/0/indices/TkNxWZ2BQmGznq5Xv77CxQ/3/index# ls Returns nothing. The same goes for my 0, 1, a…

---

## [Kibana is not starting anymore](https://discuss.elastic.co/t/kibana-is-not-starting-anymore/106054)

<div class="topic-metadata">

**Author:** [@metcheverry](https://discuss.elastic.co/u/metcheverry)\
**Replies:** 14\
**Last updated:** [November 1, 2017, 6:32pm UTC](https://discuss.elastic.co/t/kibana-is-not-starting-anymore/106054 "2017-11-01T18:32:18Z")

</div>

Hi , i installed a elk years ago , and everything is fine , but i start to getting this in kibana : \[error\_de\_kibana\] any idea?

---

## [Request Timeout](https://discuss.elastic.co/t/request-timeout/124641)

<div class="topic-metadata">

**Author:** [@Pororo](https://discuss.elastic.co/u/Pororo)\
**Replies:** 22\
**Last updated:** [March 20, 2018, 1:23am UTC](https://discuss.elastic.co/t/request-timeout/124641 "2018-03-20T01:23:21Z")

</div>

I just upgraded kibana 6.2.1 to 6.2.2 and everything is going well except I received the error info from the backend console interface. Other than this, the functionality is not impacted. Unhandled rejection Error: Requ…

---

## [ElasticSearch : observer: timeout notification from cluster service](https://discuss.elastic.co/t/elasticsearch-observer-timeout-notification-from-cluster-service/32904)

<div class="topic-metadata">

**Author:** [@Deb](https://discuss.elastic.co/u/Deb)\
**Replies:** 9\
**Last updated:** [October 27, 2015, 5:27am UTC](https://discuss.elastic.co/t/elasticsearch-observer-timeout-notification-from-cluster-service/32904 "2015-10-27T05:27:13Z")

</div>

I have a ElasticSearch Cluster with 3 Data Master Nodes, one dedicated Client Node & a logstash sending events to Elasticsearch Cluster via the elasticsearch client node. The Client is not able to connect to the clus…

---

## [Reassigning Shards](https://discuss.elastic.co/t/reassigning-shards/48736)

<div class="topic-metadata">

**Author:** [@jnpetty](https://discuss.elastic.co/u/jnpetty)\
**Replies:** 15\
**Last updated:** [October 4, 2016, 3:28pm UTC](https://discuss.elastic.co/t/reassigning-shards/48736 "2016-10-04T15:28:34Z")

</div>

We had to hard shutdown all of our Elasticsearch server due to an environmental issue. Now all of our shards are unassigned: { "cluster\_name" : "Elasticsearch-Cluster-1", "status" : "red", "timed\_out" : false, …

---

## [Active primary shards too many? Health status Yellow](https://discuss.elastic.co/t/active-primary-shards-too-many-health-status-yellow/135674)

<div class="topic-metadata">

**Author:** [@thitami](https://discuss.elastic.co/u/thitami)\
**Replies:** 28\
**Last updated:** [June 14, 2018, 1:40pm UTC](https://discuss.elastic.co/t/active-primary-shards-too-many-health-status-yellow/135674 "2018-06-14T13:40:18Z")

</div>

Hello all, I am quite new to ElasticSearch and experiencing some issues. I am using the AWS ES service and this is its health: StatusYellow Number of nodes 3 Number of data nodes 3 Active primary shards 26 Active s…

---

## [Ingesting CSV reports through Filebeat to Logstash](https://discuss.elastic.co/t/ingesting-csv-reports-through-filebeat-to-logstash/137680)

<div class="topic-metadata">

**Author:** [@joshua625](https://discuss.elastic.co/u/joshua625)\
**Replies:** 20\
**Last updated:** [July 3, 2018, 8:41pm UTC](https://discuss.elastic.co/t/ingesting-csv-reports-through-filebeat-to-logstash/137680 "2018-07-03T20:41:59Z")

</div>

Hello, I am facing a critical problem on writing a filter config for logstash to parse the incoming csv data (having 50+ headers and 300 MB) . I tried many ways, but, I was unable to index the data on Elasticsearch. I…

---

## [I don't see command setup-passwords in ../bin/x-pack/](https://discuss.elastic.co/t/i-dont-see-command-setup-passwords-in-bin-x-pack/113265)

<div class="topic-metadata">

**Author:** [@sachin8778](https://discuss.elastic.co/u/sachin8778)\
**Replies:** 11\
**Last updated:** [December 27, 2017, 11:14am UTC](https://discuss.elastic.co/t/i-dont-see-command-setup-passwords-in-bin-x-pack/113265 "2017-12-27T11:14:15Z")

</div>

Hi, I have installed x-pack plugins for elasticsearch and kibana. Now as per documentation, I am trying to setup the passwords for standard users e.g. elastic, kibana. However I don't see that command (setup-passwords) …

---

## [Http\_poller 's weird behavior with polling URLs](https://discuss.elastic.co/t/http-poller-s-weird-behavior-with-polling-urls/28620)

<div class="topic-metadata">

**Author:** [@Ramdev\_Wudali](https://discuss.elastic.co/u/Ramdev_Wudali)\
**Replies:** 21\
**Last updated:** [February 18, 2016, 9:31pm UTC](https://discuss.elastic.co/t/http-poller-s-weird-behavior-with-polling-urls/28620 "2016-02-18T21:31:18Z")

</div>

http\_poller with logstash 1.5.1 , ES 1.5.2, on Java 7 I have configured http\_poller to poll the following endpoint http://:10710/jolokia/read/:type=Registrar/InstanceName (I am using jolokia to access the JMX applica…

---

## [Building Kibana Dashboard Dynamically](https://discuss.elastic.co/t/building-kibana-dashboard-dynamically/33713)

<div class="topic-metadata">

**Author:** [@Asad\_Rehman](https://discuss.elastic.co/u/Asad_Rehman)\
**Replies:** 9\
**Last updated:** [June 13, 2017, 12:55am UTC](https://discuss.elastic.co/t/building-kibana-dashboard-dynamically/33713 "2017-06-13T00:55:07Z")

</div>

Hi All, I have some indexes in elasticsearch and I have build my required dashboard with required visualizations in Kibana. My index contains data from different shops regarding their sales and revenues and visualization…

[Previous page](https://discuss.elastic.co/top.md?page=23&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=25&per_page=50&period=all)
