# Top

**URL:** https://discuss.elastic.co/top.md?page=27&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 28

---

## [Some logs are missing in Elasticsearch](https://discuss.elastic.co/t/some-logs-are-missing-in-elasticsearch/90214)

<div class="topic-metadata">

**Author:** [@ricky.chiu](https://discuss.elastic.co/u/ricky.chiu)\
**Replies:** 11\
**Last updated:** [June 21, 2017, 9:51am UTC](https://discuss.elastic.co/t/some-logs-are-missing-in-elasticsearch/90214 "2017-06-21T09:51:22Z")

</div>

Hi, We have a 3 node cluster ( 2 data nodes and 1 ingest node ) which is Centos 7.3, openjdk version "1.8.0\_121", Logstash 5.2 and Elasticsearch 5.2. We receives the log files every 5 minutes. We found that some logs…

---

## [ElasticSearch throwing “OutOfMemoryError\[unable to create new native thread\]” error](https://discuss.elastic.co/t/elasticsearch-throwing-outofmemoryerror-unable-to-create-new-native-thread-error/31686)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 10\
**Last updated:** [October 9, 2015, 1:03pm UTC](https://discuss.elastic.co/t/elasticsearch-throwing-outofmemoryerror-unable-to-create-new-native-thread-error/31686 "2015-10-09T13:03:35Z")

</div>

Hello, We have setup a cluster on the 2 BFM servers, I have only the basic cluster running with 1 data node, 1 master node and 1 client node. The master nodes will act as master + data and are configured to have a reser…

---

## [Date in index name doesn't change on rollover on the next day](https://discuss.elastic.co/t/date-in-index-name-doesnt-change-on-rollover-on-the-next-day/226701)

<div class="topic-metadata">

**Author:** [@EldrosKandar](https://discuss.elastic.co/u/EldrosKandar)\
**Replies:** 17\
**Last updated:** [May 15, 2020, 4:24am UTC](https://discuss.elastic.co/t/date-in-index-name-doesnt-change-on-rollover-on-the-next-day/226701 "2020-05-15T04:24:09Z")

</div>

For some reason, although the index naming convention is set in the Filebeat clients' configuration, the timestamp of the date isn't change when the index is rolled over on the next day. For example let's say I had inde…

---

## [Elasticsearch installation and configuration issue](https://discuss.elastic.co/t/elasticsearch-installation-and-configuration-issue/247130)

<div class="topic-metadata">

**Author:** [@bogdan.oproescu](https://discuss.elastic.co/u/bogdan.oproescu)\
**Replies:** 24\
**Last updated:** [September 2, 2020, 5:02pm UTC](https://discuss.elastic.co/t/elasticsearch-installation-and-configuration-issue/247130 "2020-09-02T17:02:31Z")

</div>

Hello Elasticsearch forum, My name is Bogdan Oproescu and I am senior data architect for EasyDO Digital Technologies in Bucharest. I am writing you today, to report an issue with our initial Elasticsearch engine configu…

---

## [.marvel-es-YYYY.MM.DD index deleted HOW-TO create it again](https://discuss.elastic.co/t/marvel-es-yyyy-mm-dd-index-deleted-how-to-create-it-again/33959)

<div class="topic-metadata">

**Author:** [@nskalis](https://discuss.elastic.co/u/nskalis)\
**Replies:** 29\
**Last updated:** [December 2, 2015, 10:44pm UTC](https://discuss.elastic.co/t/marvel-es-yyyy-mm-dd-index-deleted-how-to-create-it-again/33959 "2015-12-02T22:44:27Z")

</div>

Dear All, i recently installed Elasticsearch 2.0 and Marvel 2.0 i was experimenting with Curator and I accidentally delete the .marvel-es-YYY.MM.DD index health status index pri rep docs.count docs.deleted s…

---

## [Elasticsearch Yml configuration](https://discuss.elastic.co/t/elasticsearch-yml-configuration/198506)

<div class="topic-metadata">

**Author:** [@das\_santosh](https://discuss.elastic.co/u/das_santosh)\
**Replies:** 16\
**Last updated:** [September 12, 2019, 6:01am UTC](https://discuss.elastic.co/t/elasticsearch-yml-configuration/198506 "2019-09-12T06:01:08Z")

</div>

Hi , I am doing a 6 node elasticsearch cluster setup where 4 nodes i am taking as a master and 2 as a data node , but my cluster is not working as expected. can somebody please help me with complete cluster setup (ela…

---

## [Kibana Dashboard Error – Set fielddata=true on fieldname](https://discuss.elastic.co/t/kibana-dashboard-error-set-fielddata-true-on-fieldname/82812)

<div class="topic-metadata">

**Author:** [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Replies:** 19\
**Last updated:** [May 24, 2017, 6:46am UTC](https://discuss.elastic.co/t/kibana-dashboard-error-set-fielddata-true-on-fieldname/82812 "2017-05-24T06:46:59Z")

</div>

I am getting performance data using metricbeat and I am trying to produce Dashboards in kibana. Im using ELK stack version 5.3 and once i imported the metricbeat dashboards, im getting below error. 9Courier Fetch: 10 o…

---

## [Unable to enroll fleet server as assinged policy does not have fleet server input](https://discuss.elastic.co/t/unable-to-enroll-fleet-server-as-assinged-policy-does-not-have-fleet-server-input/277846)

<div class="topic-metadata">

**Author:** [@cheapsupps](https://discuss.elastic.co/u/cheapsupps)\
**Replies:** 26\
**Last updated:** [November 5, 2021, 7:26am UTC](https://discuss.elastic.co/t/unable-to-enroll-fleet-server-as-assinged-policy-does-not-have-fleet-server-input/277846 "2021-11-05T07:26:27Z")

</div>

Hi, I am setting up fleet-server in air-gap environment. However, I am unable to enroll the fleet-server to elasticsearch. I am having the below error. 2021-07-05T22:37:11.552+0800 INFO cmd/enroll\_cmd.go:300 Ge…

---

## [Filebeat not reading new logs changes when manually updated one of the logs](https://discuss.elastic.co/t/filebeat-not-reading-new-logs-changes-when-manually-updated-one-of-the-logs/37058)

<div class="topic-metadata">

**Author:** [@vivc](https://discuss.elastic.co/u/vivc)\
**Replies:** 16\
**Last updated:** [January 25, 2016, 6:55am UTC](https://discuss.elastic.co/t/filebeat-not-reading-new-logs-changes-when-manually-updated-one-of-the-logs/37058 "2016-01-25T06:55:51Z")

</div>

Manually update one of the logs in the logs directory but filebeat is not reading the logs unless filebeat service is restarted . I'm sending the logs to logstash once it's read. Using filebeat version filebeat-1.0.0-i…

---

## [Could not find or load main class Files](https://discuss.elastic.co/t/could-not-find-or-load-main-class-files/126443)

<div class="topic-metadata">

**Author:** [@sahadevgd](https://discuss.elastic.co/u/sahadevgd)\
**Replies:** 17\
**Last updated:** [April 2, 2018, 4:42pm UTC](https://discuss.elastic.co/t/could-not-find-or-load-main-class-files/126443 "2018-04-02T16:42:42Z")

</div>

HI Team, We are observing below issue when trying to run the logstash. Could you please help us on this. ELK version 6.2.3 OS - Windows JDK - 1.8 Error: Could not find or load main class Files\\Java\\jdk1.7.0\_51\\lib;D…

---

## [ES Write timeout](https://discuss.elastic.co/t/es-write-timeout/102337)

<div class="topic-metadata">

**Author:** [@Yogesh\_BG](https://discuss.elastic.co/u/Yogesh_BG)\
**Replies:** 27\
**Last updated:** [October 6, 2017, 11:40am UTC](https://discuss.elastic.co/t/es-write-timeout/102337 "2017-10-06T11:40:49Z")

</div>

i have 3 data node cluster. each has 15gb memory for ES and 15gb for lucen have each record of sixe 5kb around around 100 fields pumping documents at 5000 per seconds after some time i am getting write timeout is it …

---

## [Fail to checkin to fleet-server](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/334210)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 16\
**Last updated:** [June 12, 2023, 12:33pm UTC](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/334210 "2023-06-12T12:33:16Z")

</div>

Hi All, I have successfully enrolled my remote server/machine into my Fleet server and I can see my metrics and logs coming thru. The issue is that at the beginning of the enrollment the status of the agent in kiban…

---

## [Forums Are Now Live at http://discuss.elastic.co](https://discuss.elastic.co/t/forums-are-now-live-at-http-discuss-elastic-co/23544)

<div class="topic-metadata">

**Author:** [@Leslie\_Hawthorn](https://discuss.elastic.co/u/Leslie_Hawthorn)\
**Replies:** 22\
**Last updated:** [May 28, 2015, 11:54am UTC](https://discuss.elastic.co/t/forums-are-now-live-at-http-discuss-elastic-co/23544 "2015-05-28T11:54:09Z")

</div>

Hello everyone, We took in feedback on moving to a Discourse based forum for about a month, and it sounds like most of the folks who thought it might not be optimal were people who preferred to interact with maili…

---

## [I'm trying to setup a cluster with 2 nodes. one master node and other data node](https://discuss.elastic.co/t/im-trying-to-setup-a-cluster-with-2-nodes-one-master-node-and-other-data-node/133870)

<div class="topic-metadata">

**Author:** [@komal\_mittal](https://discuss.elastic.co/u/komal_mittal)\
**Replies:** 20\
**Last updated:** [June 4, 2018, 11:14am UTC](https://discuss.elastic.co/t/im-trying-to-setup-a-cluster-with-2-nodes-one-master-node-and-other-data-node/133870 "2018-06-04T11:14:53Z")

</div>

Continuing the discussion from Elasticsearch: Not enough master nodes discovered during pinging:

---

## [Getting failed to send join request to master](https://discuss.elastic.co/t/getting-failed-to-send-join-request-to-master/143140)

<div class="topic-metadata">

**Author:** [@dhananjay88](https://discuss.elastic.co/u/dhananjay88)\
**Replies:** 12\
**Last updated:** [August 9, 2018, 12:41pm UTC](https://discuss.elastic.co/t/getting-failed-to-send-join-request-to-master/143140 "2018-08-09T12:41:36Z")

</div>

Hi All, I have installed elasticsearch on three machines \["10.135.144.XX","10.182.197.XX","10.182.197.XX"\] where 10.135.144.XX is master node and other 197.XX are date nodes. Whenever I am trying to make elasticsearch…

---

## [Kibana stops working after disabling X-Pack Security](https://discuss.elastic.co/t/kibana-stops-working-after-disabling-x-pack-security/65801)

<div class="topic-metadata">

**Author:** [@Rasdef](https://discuss.elastic.co/u/Rasdef)\
**Replies:** 13\
**Last updated:** [November 17, 2016, 5:22pm UTC](https://discuss.elastic.co/t/kibana-stops-working-after-disabling-x-pack-security/65801 "2016-11-17T17:22:14Z")

</div>

I'm using a functional ELK stack with nginx, but when I install X-Pack and then disable Security with xpack.security.enabled: false in both Kibana and Elasticsearch config files I get "502 Bad Gateway nginx/1.10.0 (Ubunt…

---

## [Kibana error fetching fields for index pattern](https://discuss.elastic.co/t/kibana-error-fetching-fields-for-index-pattern/242725)

<div class="topic-metadata">

**Author:** [@Tuckson](https://discuss.elastic.co/u/Tuckson)\
**Replies:** 18\
**Last updated:** [September 3, 2020, 11:27am UTC](https://discuss.elastic.co/t/kibana-error-fetching-fields-for-index-pattern/242725 "2020-09-03T11:27:13Z")

</div>

Hi, Have seen this question pass by several times, however yet I have found no solution. I have this ELK 7.7 stack. I try to index a log file and view the reults in Kibana. I have quite a default kibana installation a…

---

## [What happends if I change master: true, data: true node to master-only node?](https://discuss.elastic.co/t/what-happends-if-i-change-master-true-data-true-node-to-master-only-node/42337)

<div class="topic-metadata">

**Author:** [@dynamicscope](https://discuss.elastic.co/u/dynamicscope)\
**Replies:** 15\
**Last updated:** [February 22, 2016, 5:15pm UTC](https://discuss.elastic.co/t/what-happends-if-i-change-master-true-data-true-node-to-master-only-node/42337 "2016-02-22T17:15:07Z")

</div>

I have 1 master/data node and 2 data-only nodes I would like to change master/data node to master-only node due to OutOfMemoryError. Q. What happends to the data already stored in master/data node? Would they be tran…

---

## [Get value from json object](https://discuss.elastic.co/t/get-value-from-json-object/224347)

<div class="topic-metadata">

**Author:** [@Avend544](https://discuss.elastic.co/u/Avend544)\
**Replies:** 10\
**Last updated:** [April 6, 2020, 4:56am UTC](https://discuss.elastic.co/t/get-value-from-json-object/224347 "2020-04-06T04:56:36Z")

</div>

Hi! I have Kibana 7.3.2. I want to use own scripted field. I spent 5 hours for looking for the good try to get value from json object for a my scripted field. I have a next field with json object: { "timestamp": "20…

---

## [Elasticsearch Garbage Collection issue](https://discuss.elastic.co/t/elasticsearch-garbage-collection-issue/56143)

<div class="topic-metadata">

**Author:** [@dopey](https://discuss.elastic.co/u/dopey)\
**Replies:** 12\
**Last updated:** [August 6, 2016, 5:55pm UTC](https://discuss.elastic.co/t/elasticsearch-garbage-collection-issue/56143 "2016-08-06T17:55:55Z")

</div>

Elasticsearch version: 1.7.3 - 2.3.3 JVM version: "1.8.0\_72" OS version: Ubuntu 14.04 Description of the problem including expected versus actual behavior: Running ES on a 5 node cluster cluster where each node has 1…

---

## [Kibana+elasticsearch with authentication from elastic git repository fails](https://discuss.elastic.co/t/kibana-elasticsearch-with-authentication-from-elastic-git-repository-fails/190511)

<div class="topic-metadata">

**Author:** [@techcraft](https://discuss.elastic.co/u/techcraft)\
**Replies:** 20\
**Last updated:** [August 24, 2019, 8:17am UTC](https://discuss.elastic.co/t/kibana-elasticsearch-with-authentication-from-elastic-git-repository-fails/190511 "2019-08-24T08:17:52Z")

</div>

Hello you all, Im trying to configure kibana with elasticsearch using the xpack security module from the elastic helm official repository (https://github.com/elastic/helm-charts) I followed the guides for the security …

---

## [Logstash stop sending the logs to the ElasticSearch](https://discuss.elastic.co/t/logstash-stop-sending-the-logs-to-the-elasticsearch/38393)

<div class="topic-metadata">

**Author:** [@maxcherednik](https://discuss.elastic.co/u/maxcherednik)\
**Replies:** 10\
**Last updated:** [December 5, 2016, 9:06pm UTC](https://discuss.elastic.co/t/logstash-stop-sending-the-logs-to-the-elasticsearch/38393 "2016-12-05T21:06:25Z")

</div>

Version: logstash-2.1.1 After elasticsearch was out for a while and the logstash generates error like this: {:timestamp=\>"2015-12-25T17:32:47.451000+0200", :message=\>"Attempted to send a bulk request to Elasticsearch c…

---

## [Monitoring data not showing up in kibana](https://discuss.elastic.co/t/monitoring-data-not-showing-up-in-kibana/181112)

<div class="topic-metadata">

**Author:** [@Tanya\_Shah](https://discuss.elastic.co/u/Tanya_Shah)\
**Replies:** 33\
**Last updated:** [May 21, 2019, 1:09pm UTC](https://discuss.elastic.co/t/monitoring-data-not-showing-up-in-kibana/181112 "2019-05-21T13:09:40Z")

</div>

Hi, I am trying to see the monitoring data in kibana for the indices I have in elasticsearch. No data is showing even after adding the relevant settings in elasticsearch.yml and kibana.yml. Please help . I will post …

---

## [How to bind port with Logstash service?](https://discuss.elastic.co/t/how-to-bind-port-with-logstash-service/27635)

<div class="topic-metadata">

**Author:** [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Replies:** 10\
**Last updated:** [January 20, 2016, 6:35pm UTC](https://discuss.elastic.co/t/how-to-bind-port-with-logstash-service/27635 "2016-01-20T18:35:26Z")

</div>

Hi, I hope everyone is doing great. I am very new to ELK stack and deploying it on two virtual machines. One is for Logstash and the other is for Kibana and Elastic search. OS is Windows Server 2012 R2. I am setting…

---

## [Kibana iFrame CORS](https://discuss.elastic.co/t/kibana-iframe-cors/54291)

<div class="topic-metadata">

**Author:** [@Elijah\_Wilkes](https://discuss.elastic.co/u/Elijah_Wilkes)\
**Replies:** 11\
**Last updated:** [April 3, 2017, 4:58pm UTC](https://discuss.elastic.co/t/kibana-iframe-cors/54291 "2017-04-03T16:58:56Z")

</div>

I would like for elements in Kibana, on my app, to be links. My thought was to make them links using JQuery once the iframe is finished loading. This creates a CORS error. Is there any sort of config to allow Cross Origi…

---

## [Lost all index suddenly](https://discuss.elastic.co/t/lost-all-index-suddenly/70422)

<div class="topic-metadata">

**Author:** [@Carmine\_Fabrizio](https://discuss.elastic.co/u/Carmine_Fabrizio)\
**Replies:** 22\
**Last updated:** [January 23, 2017, 3:06pm UTC](https://discuss.elastic.co/t/lost-all-index-suddenly/70422 "2017-01-23T15:06:26Z")

</div>

Hi guys, I do not know why and how, but on 31/12 I've lost all the index , 1TB of index. I have 3 nodes and on all of them I have the same issue, Any ideas? someone knows something? Regards Carmine

---

## [Parsing nessus XML in Logstash](https://discuss.elastic.co/t/parsing-nessus-xml-in-logstash/120861)

<div class="topic-metadata">

**Author:** [@wdaburu](https://discuss.elastic.co/u/wdaburu)\
**Replies:** 22\
**Last updated:** [February 24, 2018, 2:10pm UTC](https://discuss.elastic.co/t/parsing-nessus-xml-in-logstash/120861 "2018-02-24T14:10:05Z")

</div>

Hi, i've come upon a problem on parsing the xml file to be displayed on kibana. Below are the configuration for my logstash input { file { path =\> "/home/user/nessus/\*" start\_position =\> "beginning" tags =\> …

---

## [Lucene Merge Thread в hot threads](https://discuss.elastic.co/t/lucene-merge-thread-hot-threads/191169)

<div class="topic-metadata">

**Author:** [@Denis\_Lamanov](https://discuss.elastic.co/u/Denis_Lamanov)\
**Replies:** 38\
**Last updated:** [September 29, 2019, 5:41pm UTC](https://discuss.elastic.co/t/lucene-merge-thread-hot-threads/191169 "2019-09-29T17:41:36Z")

</div>

Добрый день! В последние 2 дня наблюдаем на одной ноде нагрузку в 1.5-2 раза больше чем на других по i/o В hot threads постоянно вижу там: 41.8% (208.8ms out of 500ms) cpu usage by thread 'elasticsearch\[node-00\]\[\[sess…

---

## [Logstash get data but Kibana can't show it!](https://discuss.elastic.co/t/logstash-get-data-but-kibana-cant-show-it/98006)

<div class="topic-metadata">

**Author:** [@hack3rcon](https://discuss.elastic.co/u/hack3rcon)\
**Replies:** 21\
**Last updated:** [August 27, 2017, 7:52am UTC](https://discuss.elastic.co/t/logstash-get-data-but-kibana-cant-show-it/98006 "2017-08-27T07:52:34Z")

</div>

Hello. I'm using "Winlogbeat for sending Windows event Log to my ELK. Logstash get data: $ curl -XGET 'http://localhost:9200/\_cat/indices?v' yellow open beat-2017.08.22 Ez89QEvaR8207QD06iY3jw 5 1 …

---

## [Ldap Authentication in elasticsearch and kibana](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884)

<div class="topic-metadata">

**Author:** [@Jhansi](https://discuss.elastic.co/u/Jhansi)\
**Replies:** 9\
**Last updated:** [December 6, 2019, 2:44pm UTC](https://discuss.elastic.co/t/ldap-authentication-in-elasticsearch-and-kibana/210884 "2019-12-06T14:44:04Z")

</div>

I am trying to login the elastic and kibana by using ldap users.For ldap configuration I follows the below reference link https://www.elastic.co/guide/en/elasticsearch/reference/7.4/ldap-realm.html I configured the lda…

---

## [Tried to parse field \[body\] as object, but found a concrete value](https://discuss.elastic.co/t/tried-to-parse-field-body-as-object-but-found-a-concrete-value/181113)

<div class="topic-metadata">

**Author:** [@gruselglatz](https://discuss.elastic.co/u/gruselglatz)\
**Replies:** 11\
**Last updated:** [May 29, 2019, 12:27pm UTC](https://discuss.elastic.co/t/tried-to-parse-field-body-as-object-but-found-a-concrete-value/181113 "2019-05-29T12:27:04Z")

</div>

Kibana version: Kibana 6.7.2 Elasticsearch version: 6.7.2 APM Server version: 6.7.2 APM Agent language and version: Java 1.6.1 Original install method (e.g. download page, yum, deb, from source, etc.) and version:…

---

## [Alias creation operation goes very slow when we have more than 100000 aliases](https://discuss.elastic.co/t/alias-creation-operation-goes-very-slow-when-we-have-more-than-100000-aliases/42996)

<div class="topic-metadata">

**Author:** [@mahdi\_malaki](https://discuss.elastic.co/u/mahdi_malaki)\
**Replies:** 43\
**Last updated:** [March 6, 2016, 6:32pm UTC](https://discuss.elastic.co/t/alias-creation-operation-goes-very-slow-when-we-have-more-than-100000-aliases/42996 "2016-03-06T18:32:32Z")

</div>

I've developed a snippet of code so that it tries to create 100000 Aliases on Elasticsearch. I found that as long as number of Aliases was increasing the time takes for creation an Alias was raising as well. It seems com…

---

## [Need help with IBM JDK Issues with ES 1.4.5](https://discuss.elastic.co/t/need-help-with-ibm-jdk-issues-with-es-1-4-5/1748)

<div class="topic-metadata">

**Author:** [@ramkumar](https://discuss.elastic.co/u/ramkumar)\
**Replies:** 18\
**Last updated:** [June 27, 2016, 3:17pm UTC](https://discuss.elastic.co/t/need-help-with-ibm-jdk-issues-with-es-1-4-5/1748 "2016-06-27T15:17:23Z")

</div>

Hello ! Today we tried upgrading our ES instance from 1.4.0 to 1.4.5 and realized that it fails to initialize with all versions of IBM JDK and ES throws the following message while startup. {1.4.5}: Initialization Fa…

---

## [Unable to get winlogbeat to send to logstash](https://discuss.elastic.co/t/unable-to-get-winlogbeat-to-send-to-logstash/82636)

<div class="topic-metadata">

**Author:** [@Greenie](https://discuss.elastic.co/u/Greenie)\
**Replies:** 28\
**Last updated:** [April 27, 2017, 6:33pm UTC](https://discuss.elastic.co/t/unable-to-get-winlogbeat-to-send-to-logstash/82636 "2017-04-27T18:33:27Z")

</div>

I'm new to ELK stack. running version 5.3 for all components of ELK. Able to telnet successfully from winlogbeat client to ELK server on ports 5044 and 9200. Cannot get winlogbeat data to show up in logstash. Any help wo…

---

## [Need to start ES instance for test purpose](https://discuss.elastic.co/t/need-to-start-es-instance-for-test-purpose/115918)

<div class="topic-metadata">

**Author:** [@prakharjain17](https://discuss.elastic.co/u/prakharjain17)\
**Replies:** 18\
**Last updated:** [January 22, 2018, 11:51am UTC](https://discuss.elastic.co/t/need-to-start-es-instance-for-test-purpose/115918 "2018-01-22T11:51:48Z")

</div>

Hi Ivan and others, I would like to discuss what I am doing, and need help regarding it. We have two components - App (Jersey client) and Data (Elasticsearch) We used to have Couchbase as a data component but we ar…

---

## [Filebeat is not monitoring logs on centos 7?](https://discuss.elastic.co/t/filebeat-is-not-monitoring-logs-on-centos-7/92787)

<div class="topic-metadata">

**Author:** [@atharvajava](https://discuss.elastic.co/u/atharvajava)\
**Replies:** 21\
**Last updated:** [July 28, 2017, 1:57pm UTC](https://discuss.elastic.co/t/filebeat-is-not-monitoring-logs-on-centos-7/92787 "2017-07-28T13:57:35Z")

</div>

I just installed ELK stack everything seems to be working fine but the filebeat is not showing me logs beyond the date of installation and also it is only pointing to yum.log eventhough I specified inside filebeat.yml …

---

## [Data node constantly dropping out of the cluster](https://discuss.elastic.co/t/data-node-constantly-dropping-out-of-the-cluster/194216)

<div class="topic-metadata">

**Author:** [@Jorge\_Betancourt](https://discuss.elastic.co/u/Jorge_Betancourt)\
**Replies:** 18\
**Last updated:** [September 4, 2019, 11:36am UTC](https://discuss.elastic.co/t/data-node-constantly-dropping-out-of-the-cluster/194216 "2019-09-04T11:36:43Z")

</div>

We had a situation after migrating to Elasticsearch 7.3. We run 3 dedicated masters and 4 data nodes. Each data node has 24 vCPUs and 30GB of RAM, used primarily for ingesting logs. One of our data nodes was constantly b…

---

## [Elasticsearch 7.8 worse heap management](https://discuss.elastic.co/t/elasticsearch-7-8-worse-heap-management/240996)

<div class="topic-metadata">

**Author:** [@Carlos\_Moya](https://discuss.elastic.co/u/Carlos_Moya)\
**Replies:** 39\
**Last updated:** [September 23, 2020, 5:50pm UTC](https://discuss.elastic.co/t/elasticsearch-7-8-worse-heap-management/240996 "2020-09-23T17:50:26Z")

</div>

Hello, We have an Elasticsearch cluster of 94 servers and last Wednesday we updated it from 7.6.2 to 7.8.0. On Friday one of our teams reported that a nightly process reduced its performance dramatically. We verified i…

---

## [How to overwrite message (set to minus) if it is not overwrited in grok?](https://discuss.elastic.co/t/how-to-overwrite-message-set-to-minus-if-it-is-not-overwrited-in-grok/138518)

<div class="topic-metadata">

**Author:** [@lek](https://discuss.elastic.co/u/lek)\
**Replies:** 12\
**Last updated:** [July 13, 2018, 3:12pm UTC](https://discuss.elastic.co/t/how-to-overwrite-message-set-to-minus-if-it-is-not-overwrited-in-grok/138518 "2018-07-13T15:12:38Z")

</div>

Hello. In message there is json, but in some messages there is no json. I want set message to dash in first case (where there is no json). How to do it? Please, help me. cat /etc/logstash/mytests/test1 input { genera…

---

## [Dynamic Dashboard Schema and Dynamic kibana charts](https://discuss.elastic.co/t/dynamic-dashboard-schema-and-dynamic-kibana-charts/60472)

<div class="topic-metadata">

**Author:** [@David\_L](https://discuss.elastic.co/u/David_L)\
**Replies:** 9\
**Last updated:** [October 23, 2017, 4:07pm UTC](https://discuss.elastic.co/t/dynamic-dashboard-schema-and-dynamic-kibana-charts/60472 "2017-10-23T16:07:09Z")

</div>

Hi All, I trying to find the way to configure/develop kibana Dashboard that change dynamically over time. I mean that i stream 100 parameters data into elasticsearch in real time and want to see the top 10 parameters ev…

---

## [Kibana4: Authentication Exception](https://discuss.elastic.co/t/kibana4-authentication-exception/39063)

<div class="topic-metadata">

**Author:** [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)\
**Replies:** 19\
**Last updated:** [October 24, 2016, 4:12am UTC](https://discuss.elastic.co/t/kibana4-authentication-exception/39063 "2016-10-24T04:12:27Z")

</div>

---

## [Numeral.js custom format](https://discuss.elastic.co/t/numeral-js-custom-format/29334)

<div class="topic-metadata">

**Author:** [@scaarup](https://discuss.elastic.co/u/scaarup)\
**Replies:** 12\
**Last updated:** [February 3, 2017, 10:04am UTC](https://discuss.elastic.co/t/numeral-js-custom-format/29334 "2017-02-03T10:04:34Z")

</div>

hi guys. I am trying to figure out this Numeral.js. I want a "." as thousand operator and a "," to round numbers off. Example of my number field: 100000. I want that to look like 1.000,00. Possible?

---

## [Invalid NEST response built from a unsuccessful () low level call on PUT:](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-unsuccessful-low-level-call-on-put/212202)

<div class="topic-metadata">

**Author:** [@Ilyoskhuja](https://discuss.elastic.co/u/Ilyoskhuja)\
**Replies:** 9\
**Last updated:** [December 24, 2019, 6:23am UTC](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-unsuccessful-low-level-call-on-put/212202 "2019-12-24T06:23:35Z")

</div>

I have this error "Invalid NEST response built from a unsuccessful () low level call on PUT:/ nameOfIndex". I use Elasticsearch.Net/7.1.0 and ElasticSearch Cloud 7.5 BadRequest: Node: https://f3bf622c3-----------------a…

---

## [Kibana doesn't work with wildcards since Shield 2.1.0](https://discuss.elastic.co/t/kibana-doesnt-work-with-wildcards-since-shield-2-1-0/35590)

<div class="topic-metadata">

**Author:** [@vmcano](https://discuss.elastic.co/u/vmcano)\
**Replies:** 14\
**Last updated:** [June 23, 2016, 4:16pm UTC](https://discuss.elastic.co/t/kibana-doesnt-work-with-wildcards-since-shield-2-1-0/35590 "2016-06-23T16:16:17Z")

</div>

Since I updated to ES 2.1.0, Shield 2.1.0 and Kibana 4.3.0, Kibana doesn't work properly. If I set an index with a wildcard in the Settings tab (for example, logstash-\*), when I go to the Discover tab, I get an error tha…

---

## [Metricbeat failed to connect with elasticsearch](https://discuss.elastic.co/t/metricbeat-failed-to-connect-with-elasticsearch/188922)

<div class="topic-metadata">

**Author:** [@zmira\_meriem](https://discuss.elastic.co/u/zmira_meriem)\
**Replies:** 15\
**Last updated:** [July 5, 2019, 2:34pm UTC](https://discuss.elastic.co/t/metricbeat-failed-to-connect-with-elasticsearch/188922 "2019-07-05T14:34:07Z")

</div>

\[root@scw-elated-franklin ~\]# sudo metricbeat test output elasticsearch: http://51.77.:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 51.77.. dial up... ERROR dial tcp 51.77.:92…

---

## ["Operation timed out" while accessing Kibana](https://discuss.elastic.co/t/operation-timed-out-while-accessing-kibana/104917)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 22\
**Last updated:** [October 26, 2017, 1:46pm UTC](https://discuss.elastic.co/t/operation-timed-out-while-accessing-kibana/104917 "2017-10-26T13:46:24Z")

</div>

Hi, I have installed X-pack on Elasticsearch and Kibana on the server. I'm able to access Elasticsearch from my machine (which is on the same network) but not able to access Kibana. From the terminal, I'm getting the f…

---

## [Problem with filebeat.yml](https://discuss.elastic.co/t/problem-with-filebeat-yml/134144)

<div class="topic-metadata">

**Author:** [@Saketh\_Chandra\_Kolis](https://discuss.elastic.co/u/Saketh_Chandra_Kolis)\
**Replies:** 12\
**Last updated:** [June 4, 2018, 3:30am UTC](https://discuss.elastic.co/t/problem-with-filebeat-yml/134144 "2018-06-04T03:30:04Z")

</div>

hi there, I am trying to send logs from filebeat to logstash.As stated in the yml file i have commented the elasticsearch output and uncommented the one for logstash but i happen to get this error: PS C:\\Program Files\\…

---

## [Index creates in different timezone other than UTC?](https://discuss.elastic.co/t/index-creates-in-different-timezone-other-than-utc/148941)

<div class="topic-metadata">

**Author:** [@af615dbd55cac2cacf32](https://discuss.elastic.co/u/af615dbd55cac2cacf32)\
**Replies:** 10\
**Last updated:** [September 20, 2018, 12:12pm UTC](https://discuss.elastic.co/t/index-creates-in-different-timezone-other-than-utc/148941 "2018-09-20T12:12:43Z")

</div>

Hello, My ELK servers are located in Asia/Seoul timezone which is GMT+9:00. Elasticsearch creates indices on a daily basis, but the indices are created at 9AM (instead of 12AM) due to timezone difference. I know Kiban…

---

## [How does String search in Logstash filter work?](https://discuss.elastic.co/t/how-does-string-search-in-logstash-filter-work/107467)

<div class="topic-metadata">

**Author:** [@amruth](https://discuss.elastic.co/u/amruth)\
**Replies:** 12\
**Last updated:** [November 14, 2017, 7:47pm UTC](https://discuss.elastic.co/t/how-does-string-search-in-logstash-filter-work/107467 "2017-11-14T19:47:07Z")

</div>

Hi, I am using following filter in Logstash, if "INFO" in \[message\] and "instance" in \[message\] { mutate{ remove\_field =\> \["name"\] } } And it's doing not…

---

## [Elasticsearch cluster architecture](https://discuss.elastic.co/t/elasticsearch-cluster-architecture/244057)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 15\
**Last updated:** [August 13, 2020, 9:18am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-architecture/244057 "2020-08-13T09:18:15Z")

</div>

I am planning to deploy a cluster with 2 nodes. Following is the proposed architecture, I would like a community review. Purpose: Non-enterprise. Final year project that will be collecting data from internet sensors (…

[Previous page](https://discuss.elastic.co/top.md?page=26&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=28&per_page=50&period=all)
