# Top

**URL:** https://discuss.elastic.co/top.md?page=25&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 26

---

## [When add new node in elasticsearch 5.4 old node deleted](https://discuss.elastic.co/t/when-add-new-node-in-elasticsearch-5-4-old-node-deleted/86436)

<div class="topic-metadata">

**Author:** [@pjayramkumar](https://discuss.elastic.co/u/pjayramkumar)\
**Replies:** 51\
**Last updated:** [May 24, 2017, 1:51pm UTC](https://discuss.elastic.co/t/when-add-new-node-in-elasticsearch-5-4-old-node-deleted/86436 "2017-05-24T13:51:46Z")

</div>

Hello I created a node via command as elasticsearch user in server here is command bin/elasticsearch -Epath.data=/usr/share/elasticsearch/data/node\_3 -Epath.logs=/var/log/elasticsearch/node\_3 -Enode.name=fan the…

---

## [Deleting indices older than 90 days](https://discuss.elastic.co/t/deleting-indices-older-than-90-days/122811)

<div class="topic-metadata">

**Author:** [@shivu](https://discuss.elastic.co/u/shivu)\
**Replies:** 18\
**Last updated:** [March 8, 2018, 4:27pm UTC](https://discuss.elastic.co/t/deleting-indices-older-than-90-days/122811 "2018-03-08T16:27:15Z")

</div>

Hi i am trying to delete indices older than 90 days. My elastic search index pattern is indexname-%Y.%m in this case it is applicationlogs-2017-12 Below is my action.yml actions: 1: action: delete\_indices descripti…

---

## [DeleteIndex doesn't delete the index folder from disk](https://discuss.elastic.co/t/deleteindex-doesnt-delete-the-index-folder-from-disk/55288)

<div class="topic-metadata">

**Author:** [@SwethaS](https://discuss.elastic.co/u/SwethaS)\
**Replies:** 21\
**Last updated:** [July 14, 2016, 6:01am UTC](https://discuss.elastic.co/t/deleteindex-doesnt-delete-the-index-folder-from-disk/55288 "2016-07-14T06:01:34Z")

</div>

I am trying to delete index from elastic search using below code snippet. DeleteIndexResponse returns true, but the folder still exists in the physical location. DeleteIndexResponse res= client.admin().indices().prep…

---

## [Kibana is not showing all the logfiles from the path, shows only one file](https://discuss.elastic.co/t/kibana-is-not-showing-all-the-logfiles-from-the-path-shows-only-one-file/39747)

<div class="topic-metadata">

**Author:** [@chaitanyap](https://discuss.elastic.co/u/chaitanyap)\
**Replies:** 22\
**Last updated:** [February 11, 2016, 9:33am UTC](https://discuss.elastic.co/t/kibana-is-not-showing-all-the-logfiles-from-the-path-shows-only-one-file/39747 "2016-02-11T09:33:40Z")

</div>

Hi All, We have newly installed logstash and started exploring the features. We have given a path in beats configuration where we have number of log files(may be 10) but when we checked in kibana it is only showing o…

---

## [High latency on search](https://discuss.elastic.co/t/high-latency-on-search/44092)

<div class="topic-metadata">

**Author:** [@Arun\_Agarwal](https://discuss.elastic.co/u/Arun_Agarwal)\
**Replies:** 16\
**Last updated:** [April 8, 2016, 2:42am UTC](https://discuss.elastic.co/t/high-latency-on-search/44092 "2016-04-08T02:42:49Z")

</div>

Hey All, we are using elasticsearch for searching with sort. We perform sorts on 5 fields off which one is a string field which is analyzed. I know its recommended not to sort on analyzed fields but we have to suppor…

---

## [Kibana Setting "logging.dest" is deprecated can't be fixed](https://discuss.elastic.co/t/kibana-setting-logging-dest-is-deprecated-cant-be-fixed/291424)

<div class="topic-metadata">

**Author:** [@KillianS](https://discuss.elastic.co/u/KillianS)\
**Replies:** 13\
**Last updated:** [March 4, 2022, 10:19am UTC](https://discuss.elastic.co/t/kibana-setting-logging-dest-is-deprecated-cant-be-fixed/291424 "2022-03-04T10:19:48Z")

</div>

Hi all, We are facing an issue with Kibana 7.16.0 on Ubuntu 18.04. In Kibana log I can see a warning message \["warning","config","deprecation"\],"pid":24471,"message":""logging.dest" has been deprecated and will be remov…

---

## [What is my "index patter"?](https://discuss.elastic.co/t/what-is-my-index-patter/89900)

<div class="topic-metadata">

**Author:** [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Replies:** 51\
**Last updated:** [August 12, 2017, 1:46pm UTC](https://discuss.elastic.co/t/what-is-my-index-patter/89900 "2017-08-12T13:46:56Z")

</div>

Hello. I installed "Elasticsrach","Kibana" and "Logstash" for Windows log management and I configured "syslog-NG" as below : options { flush\_lines (0); time\_reopen (10); log\_fifo\_size (1000);…

---

## [Using Logstash as a bulk index buffer to ES](https://discuss.elastic.co/t/using-logstash-as-a-bulk-index-buffer-to-es/68090)

<div class="topic-metadata">

**Author:** [@Quentin\_Leffray](https://discuss.elastic.co/u/Quentin_Leffray)\
**Replies:** 13\
**Last updated:** [December 12, 2016, 4:44pm UTC](https://discuss.elastic.co/t/using-logstash-as-a-bulk-index-buffer-to-es/68090 "2016-12-12T16:44:36Z")

</div>

Hi, I'm trying to use Logstash as a buffering tool to spread large spikes of bulk requests across time, so they don't crash my ES cluster. The idea is to consume documents from a Redis queue and upload them directly to…

---

## [Generate @timestamp in-logstash-by-concatenating-date-from-filename-and-time-from-logs](https://discuss.elastic.co/t/generate-timestamp-in-logstash-by-concatenating-date-from-filename-and-time-from-logs/82556)

<div class="topic-metadata">

**Author:** [@shammi](https://discuss.elastic.co/u/shammi)\
**Replies:** 21\
**Last updated:** [May 16, 2017, 5:49am UTC](https://discuss.elastic.co/t/generate-timestamp-in-logstash-by-concatenating-date-from-filename-and-time-from-logs/82556 "2017-05-16T05:49:53Z")

</div>

Hi, I have log file name 'log.20170410.123146.txt' and time in log entry. I want to merge date from filename and time from logs to generate @timestamp in logstash. grok { match =\> \["message", "^(?\<t…

---

## [Cluster stuck in a yellow state](https://discuss.elastic.co/t/cluster-stuck-in-a-yellow-state/33472)

<div class="topic-metadata">

**Author:** [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Replies:** 15\
**Last updated:** [November 10, 2015, 4:07am UTC](https://discuss.elastic.co/t/cluster-stuck-in-a-yellow-state/33472 "2015-11-10T04:07:21Z")

</div>

Hey all, Recently I had to replace one of my ES nodes which died suddenly on Digital Ocean. So I ran this command to remove the node from the cluster: curl -XPUT localhost:9200/\_cluster/settings -d '{ "transient…

---

## [Logstash can't finde the certificate](https://discuss.elastic.co/t/logstash-cant-finde-the-certificate/286476)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 15\
**Last updated:** [October 14, 2021, 2:17pm UTC](https://discuss.elastic.co/t/logstash-cant-finde-the-certificate/286476 "2021-10-14T14:17:03Z")

</div>

Hello, I am trying to set up Logstash but I am failing for a week and now ask for your help. ( Using: /usr/share/logstash/bin/logstash ) I have a certificate chain, which contains the certificate for the webserver and t…

---

## [ElasticSearch Connect Exception](https://discuss.elastic.co/t/elasticsearch-connect-exception/205657)

<div class="topic-metadata">

**Author:** [@souravbasu45](https://discuss.elastic.co/u/souravbasu45)\
**Replies:** 9\
**Last updated:** [October 30, 2019, 11:38am UTC](https://discuss.elastic.co/t/elasticsearch-connect-exception/205657 "2019-10-30T11:38:35Z")

</div>

I am getting a java.net.ConnectException: Timeout connecting when I am trying to connect to the ELasticSearch cluster at port 9200. The error is as follows: java.net.ConnectException: Timeout connecting to \[/172.29.57.…

---

## [Running elasticsearch as a Service on RHEL Linux](https://discuss.elastic.co/t/running-elasticsearch-as-a-service-on-rhel-linux/85969)

<div class="topic-metadata">

**Author:** [@hungl99](https://discuss.elastic.co/u/hungl99)\
**Replies:** 14\
**Last updated:** [June 14, 2017, 8:17am UTC](https://discuss.elastic.co/t/running-elasticsearch-as-a-service-on-rhel-linux/85969 "2017-06-14T08:17:40Z")

</div>

We have to start our elasticsearch manually every time our servers are rebooted due to security patching or other OS maintenance related so I'm looking for a script to start elasticsearch automatically after a server is …

---

## [Je rencontre un problème : Limit of total fields \[1000\] in index \[index\] has been exceeded](https://discuss.elastic.co/t/je-rencontre-un-probleme-limit-of-total-fields-1000-in-index-index-has-been-exceeded/110633)

<div class="topic-metadata">

**Author:** [@Rym\_Guerbi\_Michaut](https://discuss.elastic.co/u/Rym_Guerbi_Michaut)\
**Replies:** 17\
**Last updated:** [January 3, 2018, 8:37am UTC](https://discuss.elastic.co/t/je-rencontre-un-probleme-limit-of-total-fields-1000-in-index-index-has-been-exceeded/110633 "2018-01-03T08:37:58Z")

</div>

Bonjour, Utilisatrice novice des outils ELK, je rencontre un souci d'import de données en JSON. J’utilise Logstash avec le plugin HTTP Poller en input et Elasticsearch en output. J'ai créé mon fichier de config pour c…

---

## [No communication between Filebeat and Logstash](https://discuss.elastic.co/t/no-communication-between-filebeat-and-logstash/56317)

<div class="topic-metadata">

**Author:** [@Gisamark](https://discuss.elastic.co/u/Gisamark)\
**Replies:** 10\
**Last updated:** [July 29, 2016, 3:31pm UTC](https://discuss.elastic.co/t/no-communication-between-filebeat-and-logstash/56317 "2016-07-29T15:31:09Z")

</div>

Hi all ! I tried to install the ELK solution on a server and filebeat on my client, but it seems that there is no communication between the two... I tried beatname -c config.yml -e -d "\*" to help you but I get "comm…

---

## [Localhost:9200 not working after install](https://discuss.elastic.co/t/localhost-9200-not-working-after-install/95625)

<div class="topic-metadata">

**Author:** [@jarves](https://discuss.elastic.co/u/jarves)\
**Replies:** 13\
**Last updated:** [August 3, 2017, 9:45am UTC](https://discuss.elastic.co/t/localhost-9200-not-working-after-install/95625 "2017-08-03T09:45:15Z")

</div>

Hi, I first installed ELK where i got the installer from github on my laptop and its working fine. I then installed it on a windows 2008 r2 server and it by typing in my browser localhost:9200 and localhost:5601 gives m…

---

## [java.lang.NoClassDefFoundError: org/elasticsearch/transport/Netty4Plugin](https://discuss.elastic.co/t/java-lang-noclassdeffounderror-org-elasticsearch-transport-netty4plugin/110959)

<div class="topic-metadata">

**Author:** [@Anjana\_Surendrababu](https://discuss.elastic.co/u/Anjana_Surendrababu)\
**Replies:** 11\
**Last updated:** [December 10, 2017, 2:36pm UTC](https://discuss.elastic.co/t/java-lang-noclassdeffounderror-org-elasticsearch-transport-netty4plugin/110959 "2017-12-10T14:36:11Z")

</div>

I am getting this error on tomcat start. java.lang.NoClassDefFoundError: org/elasticsearch/transport/Netty4Plugin I am using elasticsearch-6.0.0.jar, transport-5.6.4.jar. In maven it showed 5 other jars having compiler …

---

## [Elasticsearch uses more memory than JVM heap settings, reaches container memory limit and crash](https://discuss.elastic.co/t/elasticsearch-uses-more-memory-than-jvm-heap-settings-reaches-container-memory-limit-and-crash/218873)

<div class="topic-metadata">

**Author:** [@vroad](https://discuss.elastic.co/u/vroad)\
**Replies:** 10\
**Last updated:** [February 17, 2020, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-uses-more-memory-than-jvm-heap-settings-reaches-container-memory-limit-and-crash/218873 "2020-02-17T08:35:35Z")

</div>

Elasticsearch uses more memory than JVM heap settings, which is currently -Xms512m, -Xmx512m. I tried setting those values to 1g and reverted because the container crashed immediately after relaunching containers, becaus…

---

## [Extracting Domain from URL](https://discuss.elastic.co/t/extracting-domain-from-url/36219)

<div class="topic-metadata">

**Author:** [@Hans](https://discuss.elastic.co/u/Hans)\
**Replies:** 14\
**Last updated:** [April 18, 2016, 5:41pm UTC](https://discuss.elastic.co/t/extracting-domain-from-url/36219 "2016-04-18T17:41:06Z")

</div>

Is it possible to extract the domain only from a URL using lostash: URL: e10.whatsapp.net mtalk.google.com teredo.ipv6.microsoft.com extshort.weixin.qq.com Domain whatsapp.net google.com microsoft.com qq.com

---

## [Latest Kibana proxy under IIS (Windows)](https://discuss.elastic.co/t/latest-kibana-proxy-under-iis-windows/47167)

<div class="topic-metadata">

**Author:** [@johncst](https://discuss.elastic.co/u/johncst)\
**Replies:** 16\
**Last updated:** [April 14, 2017, 3:19am UTC](https://discuss.elastic.co/t/latest-kibana-proxy-under-iis-windows/47167 "2017-04-14T03:19:26Z")

</div>

I've been trying to protect Kibana behind a proxy under Windows IIS. I haven't found a solution that works online, so I thought I might ask the experts here. When I start at localhost:5601, everything works. When I try…

---

## [Large results sets and paging for Aggregations](https://discuss.elastic.co/t/large-results-sets-and-paging-for-aggregations/20653)

<div class="topic-metadata">

**Author:** [@pulkitsinghal](https://discuss.elastic.co/u/pulkitsinghal)\
**Replies:** 9\
**Last updated:** [February 11, 2015, 2:35pm UTC](https://discuss.elastic.co/t/large-results-sets-and-paging-for-aggregations/20653 "2015-02-11T14:35:52Z")

</div>

Based on the reference docs I couldn't figure out what happens when the aggregation result set is very large. Does it get cut off? What is the upperbound? Does ES crash? I see closed issues that indicate that pagi…

---

## [Fatal exception while booting Elasticsearch](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/322390)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 11\
**Last updated:** [January 5, 2023, 11:45am UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/322390 "2023-01-05T11:45:14Z")

</div>

Hello, I have 5 nodes under rhel 8.7, the system is hardened so the partitions /var /var/tmp /var/log /home /var/log/audit and /tmp are in noexec I managed to work around the problem on the first two nodes by adding th…

---

## [Parse firewall logs collected by logstash through syslog](https://discuss.elastic.co/t/parse-firewall-logs-collected-by-logstash-through-syslog/132812)

<div class="topic-metadata">

**Author:** [@Dora](https://discuss.elastic.co/u/Dora)\
**Replies:** 11\
**Last updated:** [June 15, 2018, 2:55pm UTC](https://discuss.elastic.co/t/parse-firewall-logs-collected-by-logstash-through-syslog/132812 "2018-06-15T14:55:26Z")

</div>

Hello, I am using ELK (version 6.2.4), and I would like to collect firewall logs (Fortigate) from another SIEM, so I followed the following steps: I configured the other SIEM to forward these logs to ELK via the UDP p…

---

## [Delete\_by\_query? , gateway timeout](https://discuss.elastic.co/t/delete-by-query-gateway-timeout/155430)

<div class="topic-metadata">

**Author:** [@Roque\_Moyano](https://discuss.elastic.co/u/Roque_Moyano)\
**Replies:** 13\
**Last updated:** [November 9, 2018, 4:23pm UTC](https://discuss.elastic.co/t/delete-by-query-gateway-timeout/155430 "2018-11-09T16:23:55Z")

</div>

Hi , I have a problem , I have some huge indexes , and I want to delete some documents but only if they have some value , I have tried it: POST docker-2018.07.05/\_delete\_by\_query?conflicts=proceed&timeout=10m { "query…

---

## [How to use Kibana to run Elasticsearch query?](https://discuss.elastic.co/t/how-to-use-kibana-to-run-elasticsearch-query/54683)

<div class="topic-metadata">

**Author:** [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Replies:** 17\
**Last updated:** [July 7, 2016, 2:22am UTC](https://discuss.elastic.co/t/how-to-use-kibana-to-run-elasticsearch-query/54683 "2016-07-07T02:22:14Z")

</div>

I am using Elasticsearch 2.3.2, and Kibana-4.5. I have found from https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-movavg-aggregation.html which states that moving average can …

---

## [How to exclude other namespaces?](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 23\
**Last updated:** [October 9, 2020, 2:39am UTC](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544 "2020-10-09T02:39:05Z")

</div>

filebeat.autodiscover: providers: - type: kubernetes node: ${NODE\_NAME} hints.enabled: false hints.default\_config: type: container finished: true paths: - "/var/…

---

## [How to search case sensitive in elasticsearch without mapping](https://discuss.elastic.co/t/how-to-search-case-sensitive-in-elasticsearch-without-mapping/139482)

<div class="topic-metadata">

**Author:** [@satyaveer1](https://discuss.elastic.co/u/satyaveer1)\
**Replies:** 14\
**Last updated:** [July 12, 2018, 10:13am UTC](https://discuss.elastic.co/t/how-to-search-case-sensitive-in-elasticsearch-without-mapping/139482 "2018-07-12T10:13:19Z")

</div>

I am creating an elasticsearch app where i need to case sensitive search without use of mapping. So please suggest me how to do this.

---

## [64 Gb limit for per NODE](https://discuss.elastic.co/t/64-gb-limit-for-per-node/319950)

<div class="topic-metadata">

**Author:** [@Kamran\_Ahmadzade](https://discuss.elastic.co/u/Kamran_Ahmadzade)\
**Replies:** 11\
**Last updated:** [December 5, 2022, 2:03pm UTC](https://discuss.elastic.co/t/64-gb-limit-for-per-node/319950 "2022-12-05T14:03:54Z")

</div>

Why do we have 64 GB limit for per node in cluster ?

---

## [Testing TLS/SSL secured elastic cluster](https://discuss.elastic.co/t/testing-tls-ssl-secured-elastic-cluster/250572)

<div class="topic-metadata">

**Author:** [@dzyubanv](https://discuss.elastic.co/u/dzyubanv)\
**Replies:** 31\
**Last updated:** [November 10, 2020, 5:36pm UTC](https://discuss.elastic.co/t/testing-tls-ssl-secured-elastic-cluster/250572 "2020-11-10T17:36:31Z")

</div>

I configured 2 node es cluster with the TLS security section in es yml file using certificates in PKCS#12 format, native realm by default, basic license, elasticsearch-7.8.0-linux-86\_64.tar.gz, RHEL 5.11. Used command w…

---

## [Uniqueness constraint](https://discuss.elastic.co/t/uniqueness-constraint/8615)

<div class="topic-metadata">

**Author:** [@Greg\_3](https://discuss.elastic.co/u/Greg_3)\
**Replies:** 12\
**Last updated:** [October 9, 2013, 12:41pm UTC](https://discuss.elastic.co/t/uniqueness-constraint/8615 "2013-10-09T12:41:01Z")

</div>

Hi all Is it possible to enforce a uniqueness constraint for a particular field in Elasticsearch? I would like to prevent multiple documents from being indexed with the same email address. Thanks Greg

---

## [Troubles with a Date Field, Null Data and Fielddata](https://discuss.elastic.co/t/troubles-with-a-date-field-null-data-and-fielddata/80080)

<div class="topic-metadata">

**Author:** [@timmy8ken](https://discuss.elastic.co/u/timmy8ken)\
**Replies:** 12\
**Last updated:** [March 30, 2017, 10:12am UTC](https://discuss.elastic.co/t/troubles-with-a-date-field-null-data-and-fielddata/80080 "2017-03-30T10:12:06Z")

</div>

Hello, I have created an Elasticsearch instanced where we are place log data from a web site that includes information about when people book appointments, and I am having problems with a field that holds the start tim…

---

## [Could not find or load main class logstash](https://discuss.elastic.co/t/could-not-find-or-load-main-class-logstash/85337)

<div class="topic-metadata">

**Author:** [@avdnowhere](https://discuss.elastic.co/u/avdnowhere)\
**Replies:** 12\
**Last updated:** [May 11, 2017, 9:56am UTC](https://discuss.elastic.co/t/could-not-find-or-load-main-class-logstash/85337 "2017-05-11T09:56:18Z")

</div>

Dear All, I am trying to load some data into Kibana using Logstash. I searched on the internet about it and I found a sample how to load the data from this link : https://github.com/elastic/examples/tree/master/Elastic…

---

## [Index PDF in ES](https://discuss.elastic.co/t/index-pdf-in-es/79535)

<div class="topic-metadata">

**Author:** [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Replies:** 13\
**Last updated:** [March 27, 2017, 11:10am UTC](https://discuss.elastic.co/t/index-pdf-in-es/79535 "2017-03-27T11:10:23Z")

</div>

Can i create index for pdf file? How?

---

## [I am installing the new ES and i keep receiving these errors on start. main ERROR Null object returned for RollingFile in Appenders](https://discuss.elastic.co/t/i-am-installing-the-new-es-and-i-keep-receiving-these-errors-on-start-main-error-null-object-returned-for-rollingfile-in-appenders/125002)

<div class="topic-metadata">

**Author:** [@KKB](https://discuss.elastic.co/u/KKB)\
**Replies:** 9\
**Last updated:** [April 4, 2018, 2:07pm UTC](https://discuss.elastic.co/t/i-am-installing-the-new-es-and-i-keep-receiving-these-errors-on-start-main-error-null-object-returned-for-rollingfile-in-appenders/125002 "2018-04-04T14:07:26Z")

</div>

Hi, I am installing the new ES and i keep receiving these errors on start. main ERROR Null object returned for RollingFile in Appenders. I trouble shoot by all the recommendation which had posted in forums relates to t…

---

## [Timezone affected dates](https://discuss.elastic.co/t/timezone-affected-dates/10421)

<div class="topic-metadata">

**Author:** [@amnesia7](https://discuss.elastic.co/u/amnesia7)\
**Replies:** 9\
**Last updated:** [February 4, 2013, 4:41pm UTC](https://discuss.elastic.co/t/timezone-affected-dates/10421 "2013-02-04T16:41:07Z")

</div>

I have \*my\_datetime\* and \*time\_zone\* fields (my\_datetime is a datetime UTC field and time\_zone is the string version of the timezone, eg "Europe/Paris". I currently use the \*AT TIME ZONE\* function in \*postgres\* to…

---

## [Elasticsearch Segment Size](https://discuss.elastic.co/t/elasticsearch-segment-size/2165)

<div class="topic-metadata">

**Author:** [@Harlin\_ES](https://discuss.elastic.co/u/Harlin_ES)\
**Replies:** 17\
**Last updated:** [March 31, 2017, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-segment-size/2165 "2017-03-31T12:37:28Z")

</div>

I am currently building a large Elasticsearch cluster that needs to be able to eventually handle 1,000,000 index requests per second. I am currently scaling to that point (at about 250k/s) but I are being held back by a …

---

## [ERROR: Failed to determine the health of the cluster](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 11\
**Last updated:** [March 30, 2023, 5:20pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746 "2023-03-30T17:20:52Z")

</div>

I am trying to add nodes to a cluster for ES 8.6.2 in an AWS EC2 environment. After creating a master node and the first of several data nodes, the two instances give healthy responses to the following commands but do n…

---

## [@timestamp field not matching with the Actual log field](https://discuss.elastic.co/t/timestamp-field-not-matching-with-the-actual-log-field/343)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 20\
**Last updated:** [September 10, 2015, 6:01am UTC](https://discuss.elastic.co/t/timestamp-field-not-matching-with-the-actual-log-field/343 "2015-09-10T06:01:01Z")

</div>

Hi, I'm new to ELK, Please help me in getting out of this issue. I have logs having a "AdmitDate" field. @timestamp field is showing the date and time which I have uploaded the logs.The requirement is, @timestamp field…

---

## [Http\_poller is not working for me, please help](https://discuss.elastic.co/t/http-poller-is-not-working-for-me-please-help/124050)

<div class="topic-metadata">

**Author:** [@David\_Gidony](https://discuss.elastic.co/u/David_Gidony)\
**Replies:** 19\
**Last updated:** [March 29, 2018, 12:16pm UTC](https://discuss.elastic.co/t/http-poller-is-not-working-for-me-please-help/124050 "2018-03-29T12:16:18Z")

</div>

Hi, i'm trying to fetch data from solarwinds via the rest-api, when i use the url in my browser, everything works fine. when i run this config file, i get this weird error, im not even sure how to read it. this is my …

---

## [Permission denied error while collecting logs from external ip](https://discuss.elastic.co/t/permission-denied-error-while-collecting-logs-from-external-ip/231112)

<div class="topic-metadata">

**Author:** [@Hari\_Krishna](https://discuss.elastic.co/u/Hari_Krishna)\
**Replies:** 9\
**Last updated:** [May 7, 2020, 7:35am UTC](https://discuss.elastic.co/t/permission-denied-error-while-collecting-logs-from-external-ip/231112 "2020-05-07T07:35:24Z")

</div>

Hi, I am trying to collect syslogs from a juniper router. I have configured the router to send logs to the IP where Logstash is running. I have written the input config for Logstash as: input { syslog { …

---

## [Detecting bottleneck in Elasticsearch indexing](https://discuss.elastic.co/t/detecting-bottleneck-in-elasticsearch-indexing/242060)

<div class="topic-metadata">

**Author:** [@Merlin\_Nunez](https://discuss.elastic.co/u/Merlin_Nunez)\
**Replies:** 17\
**Last updated:** [August 20, 2020, 2:04pm UTC](https://discuss.elastic.co/t/detecting-bottleneck-in-elasticsearch-indexing/242060 "2020-08-20T14:04:48Z")

</div>

I posted about this same issue before but did not get an answer, I continued investigating but I´m still unable to get to the root cause of this. I have the following configuration in docker containers: 3 ES data nodes…

---

## [TLS for Filebeat Kafka Output](https://discuss.elastic.co/t/tls-for-filebeat-kafka-output/58756)

<div class="topic-metadata">

**Author:** [@anefassa](https://discuss.elastic.co/u/anefassa)\
**Replies:** 11\
**Last updated:** [September 8, 2016, 11:58pm UTC](https://discuss.elastic.co/t/tls-for-filebeat-kafka-output/58756 "2016-09-08T23:58:32Z")

</div>

Has anyone been successful configuring the Filebeat Kafka output to use TLS and client/server certificates to connect to Kafka? I am able to use SSL to connect to the same Kafka cluster from logstash and also other clien…

---

## [How to fix Index Lifecycle Rollover Alias is empty or not defined](https://discuss.elastic.co/t/how-to-fix-index-lifecycle-rollover-alias-is-empty-or-not-defined/351675)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 28\
**Last updated:** [February 4, 2024, 1:10am UTC](https://discuss.elastic.co/t/how-to-fix-index-lifecycle-rollover-alias-is-empty-or-not-defined/351675 "2024-02-04T01:10:54Z")

</div>

I've been running this (uses date math) but it doesn't seem to be working: PUT /%3Cos-linux-%7Bnow%2Fd%7D-000001%3E { "aliases": { "os-linux": { "is\_write\_index": true } } } which pr…

---

## [Configure cluster](https://discuss.elastic.co/t/configure-cluster/77392)

<div class="topic-metadata">

**Author:** [@talial](https://discuss.elastic.co/u/talial)\
**Replies:** 12\
**Last updated:** [March 9, 2017, 3:51pm UTC](https://discuss.elastic.co/t/configure-cluster/77392 "2017-03-09T15:51:58Z")

</div>

Hi, I created 3 vm machine with elasticsearch installation I want to create cluster with one master and 2 data nodes configure the yml as follow: master node: cluster.name: elastic node.name: master\_elk node.…

---

## [Fresh install kibana Rejecting mapping update to \[.kibana\] as the final mapping would have more than 1 type: \[log, doc\]](https://discuss.elastic.co/t/fresh-install-kibana-rejecting-mapping-update-to-kibana-as-the-final-mapping-would-have-more-than-1-type-log-doc/117413)

<div class="topic-metadata">

**Author:** [@zzchen](https://discuss.elastic.co/u/zzchen)\
**Replies:** 22\
**Last updated:** [January 31, 2018, 11:28am UTC](https://discuss.elastic.co/t/fresh-install-kibana-rejecting-mapping-update-to-kibana-as-the-final-mapping-would-have-more-than-1-type-log-doc/117413 "2018-01-31T11:28:40Z")

</div>

Hi, \[Background\] I upgrade ES from 5.6 to 6.1.2 and the kibana version is 6.1.2 (All are docker with OSS distributed version). For some reason, i would like to use a fresh new kibana installation, so i delete '.kibana…

---

## [Marvel Screen Not Showing Data](https://discuss.elastic.co/t/marvel-screen-not-showing-data/34006)

<div class="topic-metadata">

**Author:** [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Replies:** 21\
**Last updated:** [November 23, 2016, 7:22pm UTC](https://discuss.elastic.co/t/marvel-screen-not-showing-data/34006 "2016-11-23T19:22:39Z")

</div>

ES 2.0 Logstash 2.0 Kibana 4.2 I installed marvel 2.0 two days ago and it was working as expected until today. Now when I go to the marvel tab in Kibana I see the following: and when I look at the index I see: I…

---

## [Filebeat cannot able to index into elasticsearch](https://discuss.elastic.co/t/filebeat-cannot-able-to-index-into-elasticsearch/76927)

<div class="topic-metadata">

**Author:** [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Replies:** 26\
**Last updated:** [April 6, 2017, 7:43am UTC](https://discuss.elastic.co/t/filebeat-cannot-able-to-index-into-elasticsearch/76927 "2017-04-06T07:43:26Z")

</div>

Filebeat cannot able to index into elasticsearch please find the error below, ES ping not happening. Please suggest 2017-03-01T13:14:44+05:30 DBG ES Ping(url=http://10.209.68.81:9201, timeout=1m30s) 2017-03-01T13:1…

---

## [OutOfMemoryError: Direct buffer memory](https://discuss.elastic.co/t/outofmemoryerror-direct-buffer-memory/11233)

<div class="topic-metadata">

**Author:** [@Jilles\_van\_Gurp](https://discuss.elastic.co/u/Jilles_van_Gurp)\
**Replies:** 13\
**Last updated:** [December 2, 2013, 8:07pm UTC](https://discuss.elastic.co/t/outofmemoryerror-direct-buffer-memory/11233 "2013-12-02T20:07:37Z")

</div>

My colleague is running into a strange memory error with elastic search on his mac book. That seems to come and go. We've been seeing this error pretty much the moment after I migrated to using the lucene 4.x snapsho…

---

## [Kibana 4.3 showing blank pages after creating or deleting Indices](https://discuss.elastic.co/t/kibana-4-3-showing-blank-pages-after-creating-or-deleting-indices/36357)

<div class="topic-metadata">

**Author:** [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Replies:** 19\
**Last updated:** [November 28, 2016, 8:39am UTC](https://discuss.elastic.co/t/kibana-4-3-showing-blank-pages-after-creating-or-deleting-indices/36357 "2016-11-28T08:39:04Z")

</div>

Hi Experts, Sorry to ask this again but I am not able to get anything on my kibana pages after creating or deleting index in ES2.1.0 . I have just downloaded a fresh Kibana 4.3 with ES2.1.0. Initially when there no inde…

---

## [Shard re-allocation taking a very long time](https://discuss.elastic.co/t/shard-re-allocation-taking-a-very-long-time/172190)

<div class="topic-metadata">

**Author:** [@stevemw](https://discuss.elastic.co/u/stevemw)\
**Replies:** 15\
**Last updated:** [March 18, 2019, 1:46pm UTC](https://discuss.elastic.co/t/shard-re-allocation-taking-a-very-long-time/172190 "2019-03-18T13:46:28Z")

</div>

We had a situation where an engineer on my team recycled the es service on a cluster node without disabling shard allocation or doing a sync/flush, and the node failed to come back online within the delay period. Once it…

[Previous page](https://discuss.elastic.co/top.md?page=24&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=26&per_page=50&period=all)
