# Top

**URL:** https://discuss.elastic.co/top.md?page=26&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 27

---

## [Elastic search: Slow performance on large data set](https://discuss.elastic.co/t/elastic-search-slow-performance-on-large-data-set/70358)

<div class="topic-metadata">

**Author:** [@nishant35](https://discuss.elastic.co/u/nishant35)\
**Replies:** 14\
**Last updated:** [January 6, 2017, 10:54am UTC](https://discuss.elastic.co/t/elastic-search-slow-performance-on-large-data-set/70358 "2017-01-06T10:54:13Z")

</div>

I have 7 node Elastic search (v2.3.3) cluster with 2 indices and both have nested object mapping. I am getting significant delay in insert to Index2 (through spark streaming v1.6). I am using Bulk insert which takes ~8-1…

---

## [Object mapping \[categories\] can't be changed from nested to non-nested](https://discuss.elastic.co/t/object-mapping-categories-cant-be-changed-from-nested-to-non-nested/232591)

<div class="topic-metadata">

**Author:** [@andrey1](https://discuss.elastic.co/u/andrey1)\
**Replies:** 9\
**Last updated:** [May 14, 2020, 9:02pm UTC](https://discuss.elastic.co/t/object-mapping-categories-cant-be-changed-from-nested-to-non-nested/232591 "2020-05-14T21:02:08Z")

</div>

Hi, I've got a legacy a project with old version of Elasticsearch and trying to get it working with ES 7.6.2. And encountered an error which I can't understand what is wrong. There is big index definition so I quote onl…

---

## [Java API - delete all documents within the specific index and the specific type](https://discuss.elastic.co/t/java-api-delete-all-documents-within-the-specific-index-and-the-specific-type/4681)

<div class="topic-metadata">

**Author:** [@Slava\_G](https://discuss.elastic.co/u/Slava_G)\
**Replies:** 12\
**Last updated:** [March 14, 2018, 4:20pm UTC](https://discuss.elastic.co/t/java-api-delete-all-documents-within-the-specific-index-and-the-specific-type/4681 "2018-03-14T16:20:10Z")

</div>

Hi, I'm trying to delete all documents within specific index and type or to delete entire index, using this piece of code: DeleteResponse response = client.prepareDelete().setIndex(indexKey) .execute() …

---

## [Adding more path.data folders and cluster becomes red](https://discuss.elastic.co/t/adding-more-path-data-folders-and-cluster-becomes-red/32990)

<div class="topic-metadata">

**Author:** [@eraserpx](https://discuss.elastic.co/u/eraserpx)\
**Replies:** 13\
**Last updated:** [July 18, 2016, 10:24pm UTC](https://discuss.elastic.co/t/adding-more-path-data-folders-and-cluster-becomes-red/32990 "2016-07-18T22:24:54Z")

</div>

Hello, I'm facing with a problem I can't get rid off of it. I'm running a two nodes cluster Elasticsearch, 1 master + 1 node. Everything is running smoothly and all the indices are green, up and running (though no r…

---

## [Logstash monitoring is not shown in kibana monitoring UI](https://discuss.elastic.co/t/logstash-monitoring-is-not-shown-in-kibana-monitoring-ui/180739)

<div class="topic-metadata">

**Author:** [@siddaram\_kj](https://discuss.elastic.co/u/siddaram_kj)\
**Replies:** 40\
**Last updated:** [June 22, 2019, 7:45am UTC](https://discuss.elastic.co/t/logstash-monitoring-is-not-shown-in-kibana-monitoring-ui/180739 "2019-06-22T07:45:29Z")

</div>

Hi i am using logstash version 7.0 and i set the x-pack monitoring for logstash , but the monitoring is not shown in the kibana monitoring UI and even the monitoring indices for logstash are also not getting created. be…

---

## [Node won't start up due to dupliate alias/index names](https://discuss.elastic.co/t/node-wont-start-up-due-to-dupliate-alias-index-names/174548)

<div class="topic-metadata">

**Author:** [@Ant](https://discuss.elastic.co/u/Ant)\
**Replies:** 17\
**Last updated:** [April 2, 2019, 1:49pm UTC](https://discuss.elastic.co/t/node-wont-start-up-due-to-dupliate-alias-index-names/174548 "2019-04-02T13:49:55Z")

</div>

I have just added a white list to one of the nodes so I could pull over some data for a feature we have been working on in developement and want to run on the main cluster now but keep all the historic data we gathered f…

---

## [Winlogbeat TLS Connection to Logstash](https://discuss.elastic.co/t/winlogbeat-tls-connection-to-logstash/41905)

<div class="topic-metadata">

**Author:** [@doremon](https://discuss.elastic.co/u/doremon)\
**Replies:** 13\
**Last updated:** [March 8, 2016, 4:59pm UTC](https://discuss.elastic.co/t/winlogbeat-tls-connection-to-logstash/41905 "2016-03-08T16:59:43Z")

</div>

Hi, I've configured winlogbeat on a Windows Server 2012. However it doesn't work if I enable the tls option. I've tried turning off tls on both client side (winlogbeat config) and on server side (logstash beats input) …

---

## [Why are no javadocs available for the Java API?](https://discuss.elastic.co/t/why-are-no-javadocs-available-for-the-java-api/32779)

<div class="topic-metadata">

**Author:** [@Daverino](https://discuss.elastic.co/u/Daverino)\
**Replies:** 9\
**Last updated:** [April 5, 2016, 4:51pm UTC](https://discuss.elastic.co/t/why-are-no-javadocs-available-for-the-java-api/32779 "2016-04-05T16:51:53Z")

</div>

After much searching about javadocs for the API, all I find is people asking this question. . . Why has no standard documentation been provided for the API? I haven't found a good response either. I see people have bee…

---

## [Cannot read Security logs](https://discuss.elastic.co/t/cannot-read-security-logs/107842)

<div class="topic-metadata">

**Author:** [@robert-blankenship](https://discuss.elastic.co/u/robert-blankenship)\
**Replies:** 14\
**Last updated:** [November 20, 2017, 10:47pm UTC](https://discuss.elastic.co/t/cannot-read-security-logs/107842 "2017-11-20T22:47:59Z")

</div>

When I right click winlogbeat executable and select Run As Administrator, I get the following message in the log file: WARN EventLog\[Security\] Open() error. No events will be read from this source. Accessis denied." I…

---

## [How to create a date scripted field for extracting actual date from logs?](https://discuss.elastic.co/t/how-to-create-a-date-scripted-field-for-extracting-actual-date-from-logs/167389)

<div class="topic-metadata">

**Author:** [@sagarleo](https://discuss.elastic.co/u/sagarleo)\
**Replies:** 12\
**Last updated:** [February 8, 2019, 5:48am UTC](https://discuss.elastic.co/t/how-to-create-a-date-scripted-field-for-extracting-actual-date-from-logs/167389 "2019-02-08T05:48:38Z")

</div>

I want to create a date scripted field in kibana so that i can plot actual log dates in date histogram plot instead of using timestamp. My log format is: 2019-01-18 18:49:24.375 Progress: creating : resume I'm …

---

## [GC Failures](https://discuss.elastic.co/t/gc-failures/157699)

<div class="topic-metadata">

**Author:** [@Amit\_Michelson](https://discuss.elastic.co/u/Amit_Michelson)\
**Replies:** 9\
**Last updated:** [November 22, 2018, 12:08pm UTC](https://discuss.elastic.co/t/gc-failures/157699 "2018-11-22T12:08:21Z")

</div>

Hi, we have a cluster v6.3 (java 1.8) and from time to time we see a problem with the gc on the data nodes. The rate drops to zero and the jvm heap usage goes up to a 100% (which cause the cluster to stop serving). Th…

---

## [Reverse proxy behind nginx docker container not working Kibana 6.2.3](https://discuss.elastic.co/t/reverse-proxy-behind-nginx-docker-container-not-working-kibana-6-2-3/157466)

<div class="topic-metadata">

**Author:** [@aap](https://discuss.elastic.co/u/aap)\
**Replies:** 19\
**Last updated:** [December 2, 2018, 10:51pm UTC](https://discuss.elastic.co/t/reverse-proxy-behind-nginx-docker-container-not-working-kibana-6-2-3/157466 "2018-12-02T22:51:50Z")

</div>

Hi, I'm trying to set up Kibana behind my nginx container, but no matter what I do, I am unable to reach it. My Nginx config reads: location /kibana/ { auth\_request /admin/users/nginx/auth\_request/; …

---

## [Logstash permission problem](https://discuss.elastic.co/t/logstash-permission-problem/110175)

<div class="topic-metadata">

**Author:** [@Tal\_Druckmann](https://discuss.elastic.co/u/Tal_Druckmann)\
**Replies:** 16\
**Last updated:** [December 7, 2017, 5:49pm UTC](https://discuss.elastic.co/t/logstash-permission-problem/110175 "2017-12-07T17:49:08Z")

</div>

I am running logstash on windows 2016 vm . I use it from administrator command line. I keep getting this message. It won't let me save my visualization on kibana and keeps me from shutting it down (ctrl+c). This is the …

---

## [Delete data from Indices](https://discuss.elastic.co/t/delete-data-from-indices/276540)

<div class="topic-metadata">

**Author:** [@danny.tveria](https://discuss.elastic.co/u/danny.tveria)\
**Replies:** 11\
**Last updated:** [June 28, 2021, 5:33am UTC](https://discuss.elastic.co/t/delete-data-from-indices/276540 "2021-06-28T05:33:04Z")

</div>

Hi, I new in ELK. Our previous sysadmin installed and configured the elk server but he getting out of space... I want to know if I can delete data from indices without reconfiguring the entire server or ELK?

---

## [Installing Sense on Win10](https://discuss.elastic.co/t/installing-sense-on-win10/63433)

<div class="topic-metadata">

**Author:** [@jimbolya](https://discuss.elastic.co/u/jimbolya)\
**Replies:** 16\
**Last updated:** [December 10, 2016, 8:12am UTC](https://discuss.elastic.co/t/installing-sense-on-win10/63433 "2016-12-10T08:12:34Z")

</div>

Trying to install Sense on Win10. Elastic node went in fine and is up and running as well as Kibana. Any help would be great. Never used anything like this before.

---

## [Courier Fetch Errors](https://discuss.elastic.co/t/courier-fetch-errors/74321)

<div class="topic-metadata">

**Author:** [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Replies:** 36\
**Last updated:** [February 14, 2017, 11:34am UTC](https://discuss.elastic.co/t/courier-fetch-errors/74321 "2017-02-14T11:34:49Z")

</div>

I recently upgraded my 6 data nodes from 4 CPUs to 8 CPUs each. Now I am seeing these errors in Kibana that I've never seen before: Shard Failures The following shard failures ocurred: Index: logstash-2017.02.08 Sha…

---

## [How can I pass a JSON query string to a Query builder](https://discuss.elastic.co/t/how-can-i-pass-a-json-query-string-to-a-query-builder/7110)

<div class="topic-metadata">

**Author:** [@Robert\_Simmons](https://discuss.elastic.co/u/Robert_Simmons)\
**Replies:** 11\
**Last updated:** [March 26, 2012, 3:19pm UTC](https://discuss.elastic.co/t/how-can-i-pass-a-json-query-string-to-a-query-builder/7110 "2012-03-26T15:19:33Z")

</div>

I have been trying for hours to get this working. Basically I have a class that performs a filtered query and I want the user to be able to pass a JSON query string to my constructor and then use that on the filtered…

---

## [KV Filter Question](https://discuss.elastic.co/t/kv-filter-question/82702)

<div class="topic-metadata">

**Author:** [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Replies:** 20\
**Last updated:** [April 27, 2017, 5:16am UTC](https://discuss.elastic.co/t/kv-filter-question/82702 "2017-04-27T05:16:40Z")

</div>

Hi, I can now succesfully recieve Logs from my Synology. Now i have to add some fields. At the moment i don't have everything as a field in Kibana. So in Kibana the message contains the import information. The messag…

---

## [What filter should i use to remove the "\\" from my logfile](https://discuss.elastic.co/t/what-filter-should-i-use-to-remove-the-from-my-logfile/92017)

<div class="topic-metadata">

**Author:** [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Replies:** 11\
**Last updated:** [July 12, 2017, 12:26pm UTC](https://discuss.elastic.co/t/what-filter-should-i-use-to-remove-the-from-my-logfile/92017 "2017-07-12T12:26:46Z")

</div>

this is an example of my log file.. {"LogMsg":"{\\"deviceId\\":\\"911490250554400\\",\\"description\\":\\"P701\\",\\"owner\\":\\"admin\\",\\"passcodeEnabled\\":\\"false\\",\\"batteryLevel\\":18.0,\\"internalAvailableMemory\\":2.78478848E8,\\…

---

## [Filebeat missing log lines](https://discuss.elastic.co/t/filebeat-missing-log-lines/46991)

<div class="topic-metadata">

**Author:** [@paritosh](https://discuss.elastic.co/u/paritosh)\
**Replies:** 15\
**Last updated:** [April 27, 2016, 6:30am UTC](https://discuss.elastic.co/t/filebeat-missing-log-lines/46991 "2016-04-27T06:30:45Z")

</div>

I have filebeat up and running. FileBeat version : 1.2.0 Operating System : Ubuntu My configuration looks something like filebeat: prospectors: - paths: - /home/abc/access.log.2016\* input…

---

## [Unable to assign logstash aliases to index](https://discuss.elastic.co/t/unable-to-assign-logstash-aliases-to-index/182994)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 21\
**Last updated:** [June 4, 2019, 7:41am UTC](https://discuss.elastic.co/t/unable-to-assign-logstash-aliases-to-index/182994 "2019-06-04T07:41:40Z")

</div>

Hi Guys, my index lifecycle policies is giving below error, Index lifecycle error illegal\_argument\_exception: index.lifecycle.rollover\_alias \[logstash\] does not point to index \[logstash\] i tried to edit the index and …

---

## [How to set up a cluster locally with multiple VM's?](https://discuss.elastic.co/t/how-to-set-up-a-cluster-locally-with-multiple-vms/106361)

<div class="topic-metadata">

**Author:** [@jamilnyc](https://discuss.elastic.co/u/jamilnyc)\
**Replies:** 14\
**Last updated:** [November 5, 2017, 7:39pm UTC](https://discuss.elastic.co/t/how-to-set-up-a-cluster-locally-with-multiple-vms/106361 "2017-11-05T19:39:05Z")

</div>

Note: I'm just doing this to play around with and understand clustering while in development. I have two instances of ES 5.6 running on two separate Ubuntu 16.04 virtual machines (that are on the same Windows host). I'…

---

## [Elasticsearch : order aggregation by score performance](https://discuss.elastic.co/t/elasticsearch-order-aggregation-by-score-performance/74231)

<div class="topic-metadata">

**Author:** [@Mickael\_Magniez](https://discuss.elastic.co/u/Mickael_Magniez)\
**Replies:** 10\
**Last updated:** [February 8, 2017, 8:47am UTC](https://discuss.elastic.co/t/elasticsearch-order-aggregation-by-score-performance/74231 "2017-02-08T08:47:28Z")

</div>

Hi, On elastic 5.2, I'm trying to sort my aggregation buckets by maximum score of matching documents, but performance are terrible (x10) compare to the \_count sort. { "query": { "match": {"text": "shirt"} }, …

---

## [Unable to open Kibana on chrome after upgrade from version 7.3.x to 7.4.0](https://discuss.elastic.co/t/unable-to-open-kibana-on-chrome-after-upgrade-from-version-7-3-x-to-7-4-0/205041)

<div class="topic-metadata">

**Author:** [@zulfiqar4891](https://discuss.elastic.co/u/zulfiqar4891)\
**Replies:** 17\
**Last updated:** [October 28, 2019, 6:01pm UTC](https://discuss.elastic.co/t/unable-to-open-kibana-on-chrome-after-upgrade-from-version-7-3-x-to-7-4-0/205041 "2019-10-28T18:01:21Z")

</div>

Hi There, I upgraded the whole ELK stack from 7.3.x to 7.4.0 yesterday. After upgrade, I am unable to open Kibana from the browser after authentication. It goes into a loop refreshing the page with errors all the time. …

---

## [Can't run Logstash as a Service](https://discuss.elastic.co/t/cant-run-logstash-as-a-service/299202)

<div class="topic-metadata">

**Author:** [@Simone1](https://discuss.elastic.co/u/Simone1)\
**Replies:** 26\
**Last updated:** [March 11, 2022, 8:06am UTC](https://discuss.elastic.co/t/cant-run-logstash-as-a-service/299202 "2022-03-11T08:06:57Z")

</div>

If i run logstash manually it works fine and sends all data in the right way. But when i try to run it as a service it shows this error: Cmd that i use: sudo systemctl start logstash.service OS Ubuntu 20.04.1 Log…

---

## [Logstash not working on Windows](https://discuss.elastic.co/t/logstash-not-working-on-windows/47022)

<div class="topic-metadata">

**Author:** [@Mag\_Carl](https://discuss.elastic.co/u/Mag_Carl)\
**Replies:** 24\
**Last updated:** [April 26, 2016, 8:46am UTC](https://discuss.elastic.co/t/logstash-not-working-on-windows/47022 "2016-04-26T08:46:04Z")

</div>

Sorry if I'm asking a very basic question. I have setup ELK on windows 7. I am trying to get twitter feed using below config file input { twitter { # add your data consumer\_key =\> "" consumer\_secret =\>"" oauth\_toke…

---

## [Filebeat does not exit on EOF (input\_type=stdin)](https://discuss.elastic.co/t/filebeat-does-not-exit-on-eof-input-type-stdin/69545)

<div class="topic-metadata">

**Author:** [@tokland](https://discuss.elastic.co/u/tokland)\
**Replies:** 17\
**Last updated:** [January 9, 2017, 4:12pm UTC](https://discuss.elastic.co/t/filebeat-does-not-exit-on-eof-input-type-stdin/69545 "2017-01-09T16:12:03Z")

</div>

I want to send logs to logstash from the command line, so I thought using filebeat with input\_type=stdin should work. Using ArchLinux, filebeat-5.1.1-1. My filebeat.yml: filebeat.prospectors: - input\_type: stdin out…

---

## [Add plugins from classpath in embedded Elasticsearch client node](https://discuss.elastic.co/t/add-plugins-from-classpath-in-embedded-elasticsearch-client-node/36269)

<div class="topic-metadata">

**Author:** [@joschi](https://discuss.elastic.co/u/joschi)\
**Replies:** 12\
**Last updated:** [March 18, 2017, 8:50pm UTC](https://discuss.elastic.co/t/add-plugins-from-classpath-in-embedded-elasticsearch-client-node/36269 "2017-03-18T20:50:24Z")

</div>

Hi, I'm currently working on upgrading an application to Elasticsearch 2.1.0 and ran into some problems regarding loading Elasticsearch plugins from the classpath (instead of loading them from the plugins directory). …

---

## [Response code: 429](https://discuss.elastic.co/t/response-code-429/68470)

<div class="topic-metadata">

**Author:** [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Replies:** 9\
**Last updated:** [December 9, 2016, 12:50am UTC](https://discuss.elastic.co/t/response-code-429/68470 "2016-12-09T00:50:37Z")

</div>

Hi All, I am getting below error and I understand from other thread I am overloading elasticsearch. I am looking on what to dail down to get rid of this problem and get the most of performance. I have 9 LS nodes. My l…

---

## [Logstash cannot find config file](https://discuss.elastic.co/t/logstash-cannot-find-config-file/45491)

<div class="topic-metadata">

**Author:** [@Shashi\_Ravula](https://discuss.elastic.co/u/Shashi_Ravula)\
**Replies:** 10\
**Last updated:** [June 2, 2017, 3:15pm UTC](https://discuss.elastic.co/t/logstash-cannot-find-config-file/45491 "2017-06-02T15:15:52Z")

</div>

Hi guys , I am trying to run logstash as a container on marathon framework (DCOS) taking input from Kafka . the marathon json file fetches the uri from gist which has the logstash.conf file . I can also see the conf f…

---

## ["Allocate missing replica shards" X-Pack 5.6.1](https://discuss.elastic.co/t/allocate-missing-replica-shards-x-pack-5-6-1/101904)

<div class="topic-metadata">

**Author:** [@Michael\_S\_Ryder](https://discuss.elastic.co/u/Michael_S_Ryder)\
**Replies:** 11\
**Last updated:** [October 11, 2017, 5:23pm UTC](https://discuss.elastic.co/t/allocate-missing-replica-shards-x-pack-5-6-1/101904 "2017-10-11T17:23:12Z")

</div>

After installing and learning how to install all the ELK stack components, getting the pipeline working, watching data flow into ES, I then installed the X-pack plug-in. This broke everything, but I eventually got all t…

---

## [Elasticsearch multi threading problems and How to improve elasticsearch performance](https://discuss.elastic.co/t/elasticsearch-multi-threading-problems-and-how-to-improve-elasticsearch-performance/146243)

<div class="topic-metadata">

**Author:** [@gogua](https://discuss.elastic.co/u/gogua)\
**Replies:** 14\
**Last updated:** [August 31, 2018, 7:52am UTC](https://discuss.elastic.co/t/elasticsearch-multi-threading-problems-and-how-to-improve-elasticsearch-performance/146243 "2018-08-31T07:52:10Z")

</div>

Hello eveyone, I have 15.1 Million documents and I have such a problem with elasticsearch multi threading, I'm trying to search 46 aggregations(count, cardinality, date\_histogram) together and it takes about 20-45 sec. T…

---

## [Error Return code 21: SSL encryption between filebeat 5.2 and kafka 1.0 (self signed)](https://discuss.elastic.co/t/error-return-code-21-ssl-encryption-between-filebeat-5-2-and-kafka-1-0-self-signed/119126)

<div class="topic-metadata">

**Author:** [@Gangadhar\_Mahadevan](https://discuss.elastic.co/u/Gangadhar_Mahadevan)\
**Replies:** 29\
**Last updated:** [February 12, 2018, 7:41pm UTC](https://discuss.elastic.co/t/error-return-code-21-ssl-encryption-between-filebeat-5-2-and-kafka-1-0-self-signed/119126 "2018-02-12T19:41:34Z")

</div>

I am trying to set up ssl connection between filebeat 5.2 and kafka 1.0 using the below steps. I am fairly new to encryption world and seeing errors during this process. Not sure if I am missing something in cert/key or …

---

## [Split string into array](https://discuss.elastic.co/t/split-string-into-array/123079)

<div class="topic-metadata">

**Author:** [@Lycan](https://discuss.elastic.co/u/Lycan)\
**Replies:** 10\
**Last updated:** [March 9, 2018, 9:47am UTC](https://discuss.elastic.co/t/split-string-into-array/123079 "2018-03-09T09:47:07Z")

</div>

Hi. What I'm trying to do is accessing a nested string in "doc" called "message" (doc.message?), and this string contains a couple of things, including a case specification. That specification is what I am trying to ext…

---

## [Cannot connect to the Elastichsearch cluster](https://discuss.elastic.co/t/cannot-connect-to-the-elastichsearch-cluster/170674)

<div class="topic-metadata">

**Author:** [@DavidLevi](https://discuss.elastic.co/u/DavidLevi)\
**Replies:** 10\
**Last updated:** [March 7, 2019, 12:50pm UTC](https://discuss.elastic.co/t/cannot-connect-to-the-elastichsearch-cluster/170674 "2019-03-07T12:50:16Z")

</div>

Hello, One of my Kibana server gives error as below. Can anyone help me how can troubleshoot this. Thank you very much. \*\*Cannot connect to the Elasticsearch cluster currently configured for Kibana. \*\* Refer to the K…

---

## [Extract Data from message to display each field as a column in kibana](https://discuss.elastic.co/t/extract-data-from-message-to-display-each-field-as-a-column-in-kibana/122924)

<div class="topic-metadata">

**Author:** [@Prabh\_Natt](https://discuss.elastic.co/u/Prabh_Natt)\
**Replies:** 9\
**Last updated:** [March 9, 2018, 9:56pm UTC](https://discuss.elastic.co/t/extract-data-from-message-to-display-each-field-as-a-column-in-kibana/122924 "2018-03-09T21:56:06Z")

</div>

I want to be able to extract the fields i need from message and be able to select them as their own fields, as well as index everything dynamically using the "clientCode". I have been working on this for the past couple …

---

## [Using painless to calculate durations](https://discuss.elastic.co/t/using-painless-to-calculate-durations/119495)

<div class="topic-metadata">

**Author:** [@crazyphil](https://discuss.elastic.co/u/crazyphil)\
**Replies:** 18\
**Last updated:** [March 7, 2018, 11:02am UTC](https://discuss.elastic.co/t/using-painless-to-calculate-durations/119495 "2018-03-07T11:02:54Z")

</div>

I have several different indices grabbing events that have definitive start and stop points (I have an eventKey field that says "started" or "ended"). Each field also has a unique eventId field so that all things that h…

---

## [Error importing URL/file: Failed to import index-pattern: : error loading /tmp/tmp401063577/beats-dashboards-5.4.0/filebeat/index-pattern/filebeat.json: couldn't load json. Error: 401 Unauthorized](https://discuss.elastic.co/t/error-importing-url-file-failed-to-import-index-pattern-error-loading-tmp-tmp401063577-beats-dashboards-5-4-0-filebeat-index-pattern-filebeat-json-couldnt-load-json-error-401-unauthorized/97461)

<div class="topic-metadata">

**Author:** [@sandy007](https://discuss.elastic.co/u/sandy007)\
**Replies:** 25\
**Last updated:** [August 29, 2017, 12:14pm UTC](https://discuss.elastic.co/t/error-importing-url-file-failed-to-import-index-pattern-error-loading-tmp-tmp401063577-beats-dashboards-5-4-0-filebeat-index-pattern-filebeat-json-couldnt-load-json-error-401-unauthorized/97461 "2017-08-29T12:14:01Z")

</div>

I have installed a new version of elk 5.5.0 alongwith xpack \>\> next i tried to configure the filebeat index its giving me below error message while importing the dashboard i am getting the below error message - Error i…

---

## [Can I update analyzer settings without recreating the index?](https://discuss.elastic.co/t/can-i-update-analyzer-settings-without-recreating-the-index/7161)

<div class="topic-metadata">

**Author:** [@Nick\_Dunn](https://discuss.elastic.co/u/Nick_Dunn)\
**Replies:** 11\
**Last updated:** [April 4, 2012, 7:05pm UTC](https://discuss.elastic.co/t/can-i-update-analyzer-settings-without-recreating-the-index/7161 "2012-04-04T19:05:08Z")

</div>

I am looking at using a hosted ES service (Bonsai.io) which offers an index per customer, pre-created. Usually I create a config file containing my custom analyzers and send this when creating an index, however becaus…

---

## [Can't start Elasticsearch 7 service on Windows](https://discuss.elastic.co/t/cant-start-elasticsearch-7-service-on-windows/177358)

<div class="topic-metadata">

**Author:** [@dandago](https://discuss.elastic.co/u/dandago)\
**Replies:** 10\
**Last updated:** [June 24, 2019, 8:54pm UTC](https://discuss.elastic.co/t/cant-start-elasticsearch-7-service-on-windows/177358 "2019-06-24T20:54:06Z")

</div>

Hi, I'm trying to set up Elasticsearch on my Windows machine. I've done it before, but now I'm doing it again with version 7.0.0. I set JAVA\_HOME and can run Elasticsearch successfully with elasticsearch.bat (I can con…

---

## [What is the recommend memory size to run logstash?](https://discuss.elastic.co/t/what-is-the-recommend-memory-size-to-run-logstash/271083)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 13\
**Last updated:** [May 3, 2021, 8:47am UTC](https://discuss.elastic.co/t/what-is-the-recommend-memory-size-to-run-logstash/271083 "2021-05-03T08:47:46Z")

</div>

Hi all, Please explain What is the recommend memory size to run logstash. Thanks

---

## [Kibana SAML authentication issue](https://discuss.elastic.co/t/kibana-saml-authentication-issue/119420)

<div class="topic-metadata">

**Author:** [@Athul\_Jayson](https://discuss.elastic.co/u/Athul_Jayson)\
**Replies:** 15\
**Last updated:** [February 14, 2018, 6:36am UTC](https://discuss.elastic.co/t/kibana-saml-authentication-issue/119420 "2018-02-14T06:36:51Z")

</div>

Hi, I had been trying to get Kibana to work with SAML authentication, but to no avail. Kibana Config server.name: kibana server.host: "0" elasticsearch.url: https://192.168.99.100:9200 elasticsearch.username: elasti…

---

## [Jmx](https://discuss.elastic.co/t/jmx/12111)

<div class="topic-metadata">

**Author:** [@Nicolas\_Labrot](https://discuss.elastic.co/u/Nicolas_Labrot)\
**Replies:** 11\
**Last updated:** [August 21, 2013, 3:55pm UTC](https://discuss.elastic.co/t/jmx/12111 "2013-08-21T15:55:20Z")

</div>

Hello, JMX is a common way to monitor a lot of Java Apps and a lot a monitor apps have JMX connector. I read on this group that Shay does not recommend JMX for monitoring ES. Stats API is prefered. Is there any re…

---

## [You are not authorized to access Ingest Manager](https://discuss.elastic.co/t/you-are-not-authorized-to-access-ingest-manager/247705)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 9\
**Last updated:** [September 8, 2020, 1:40am UTC](https://discuss.elastic.co/t/you-are-not-authorized-to-access-ingest-manager/247705 "2020-09-08T01:40:46Z")

</div>

I didn't set up a login user.

---

## [Getting errors in logstash log "Lumberjack input pipeline is blocked"](https://discuss.elastic.co/t/getting-errors-in-logstash-log-lumberjack-input-pipeline-is-blocked/42487)

<div class="topic-metadata">

**Author:** [@shan](https://discuss.elastic.co/u/shan)\
**Replies:** 22\
**Last updated:** [March 5, 2016, 1:30pm UTC](https://discuss.elastic.co/t/getting-errors-in-logstash-log-lumberjack-input-pipeline-is-blocked/42487 "2016-03-05T13:30:03Z")

</div>

Hi, I'm getting the below error in my logstash logs message=\>"Lumberjack input: the pipeline is blocked, temporary refusing new connection.", :level=\>:warn} message=\>"CircuitBreaker::rescuing exceptions", :name=\>"Lum…

---

## [Помогите разобраться с grok filter](https://discuss.elastic.co/t/grok-filter/121988)

<div class="topic-metadata">

**Author:** [@pavuk](https://discuss.elastic.co/u/pavuk)\
**Replies:** 37\
**Last updated:** [March 19, 2018, 3:30am UTC](https://discuss.elastic.co/t/grok-filter/121988 "2018-03-19T03:30:44Z")

</div>

Здравствуйте, Вопрос у меня такой. Использую http\_poller input plugin для Logstash. По API выдергиваю данные в формате json из UserVoice. Там довольно большой объем данных приходит, все это улетает в ElasticSearch. В пр…

---

## [Docker-compose instructions lead to "unable to authenticate user \[elastic\]"](https://discuss.elastic.co/t/docker-compose-instructions-lead-to-unable-to-authenticate-user-elastic/333060)

<div class="topic-metadata">

**Author:** [@Pinch](https://discuss.elastic.co/u/Pinch)\
**Replies:** 27\
**Last updated:** [June 6, 2023, 1:09pm UTC](https://discuss.elastic.co/t/docker-compose-instructions-lead-to-unable-to-authenticate-user-elastic/333060 "2023-06-06T13:09:10Z")

</div>

Following these official instructions: Brings me to a state of "Kibana server is not ready yet." in the browser. Inspecting the logs I can see from the Kibana container that kibana\_system is not authenticated. Then c…

---

## [404 error while pushing traces from OTel Exporter to APM server](https://discuss.elastic.co/t/404-error-while-pushing-traces-from-otel-exporter-to-apm-server/315795)

<div class="topic-metadata">

**Author:** [@gvencadze](https://discuss.elastic.co/u/gvencadze)\
**Replies:** 14\
**Last updated:** [October 25, 2022, 9:57pm UTC](https://discuss.elastic.co/t/404-error-while-pushing-traces-from-otel-exporter-to-apm-server/315795 "2022-10-25T21:57:06Z")

</div>

Hey guys, I've setup opentelemetry exporter in cluster, then connected services to it and see traces in exporter logs. But, when they are pushing to APM server it returns http 404 Exporting failed. The error is not retr…

---

## [Logs appear in ES with a delay](https://discuss.elastic.co/t/logs-appear-in-es-with-a-delay/132234)

<div class="topic-metadata">

**Author:** [@Kiran\_Kumar](https://discuss.elastic.co/u/Kiran_Kumar)\
**Replies:** 14\
**Last updated:** [June 15, 2018, 9:06pm UTC](https://discuss.elastic.co/t/logs-appear-in-es-with-a-delay/132234 "2018-06-15T21:06:23Z")

</div>

I have a setup with Elastic Search, Log Stash, Kibana and Filebeat with versions as shown below. Elastic Search: 6.2.4 LogStash: 6.2.4 kibana: 6.2.4 My Logstash pipeline is as below: sudo vim /etc/logstash/conf.d/02-…

---

## [Winlogbeat via Logstash into Elasticsearch](https://discuss.elastic.co/t/winlogbeat-via-logstash-into-elasticsearch/90081)

<div class="topic-metadata">

**Author:** [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Replies:** 17\
**Last updated:** [June 24, 2017, 5:40am UTC](https://discuss.elastic.co/t/winlogbeat-via-logstash-into-elasticsearch/90081 "2017-06-24T05:40:32Z")

</div>

Hi, I have a on a Windows machine winlogbeat and it's working fine so far. At the moment all logs are going into the same index in elasticsearch. Yes i have searched and found topics with that question but i was unable …

[Previous page](https://discuss.elastic.co/top.md?page=25&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=27&per_page=50&period=all)
