# Top

**URL:** https://discuss.elastic.co/top.md?page=29&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 30

---

## [Hosting multiple ES instances on one host](https://discuss.elastic.co/t/hosting-multiple-es-instances-on-one-host/60557)

<div class="topic-metadata">

**Author:** [@stecino](https://discuss.elastic.co/u/stecino)\
**Replies:** 9\
**Last updated:** [September 15, 2016, 10:07pm UTC](https://discuss.elastic.co/t/hosting-multiple-es-instances-on-one-host/60557 "2016-09-15T22:07:50Z")

</div>

Hello, I want to run 2 instances of ES where each instance is going to be member of a different cluster. I have enough resources on it. What I wanted to know is how I should deploy it: Version 1: where all setting…

---

## [Guidance on Using Multiple Indexes vs One Index for Time Series Data from Multiple Sources](https://discuss.elastic.co/t/guidance-on-using-multiple-indexes-vs-one-index-for-time-series-data-from-multiple-sources/32729)

<div class="topic-metadata">

**Author:** [@sgt\_b2002](https://discuss.elastic.co/u/sgt_b2002)\
**Replies:** 10\
**Last updated:** [October 27, 2015, 10:32am UTC](https://discuss.elastic.co/t/guidance-on-using-multiple-indexes-vs-one-index-for-time-series-data-from-multiple-sources/32729 "2015-10-27T10:32:39Z")

</div>

Hi everyone, sorry for the somewhat generic title, hopefully I can elaborate effectively. We're using Elasticsearch to store logs from various applications, operating systems, and network devices ("multiple sources"). …

---

## [How to have multiple nodes on same machine with Elasticsearch 2.0.0](https://discuss.elastic.co/t/how-to-have-multiple-nodes-on-same-machine-with-elasticsearch-2-0-0/35578)

<div class="topic-metadata">

**Author:** [@Miguel\_Bessa](https://discuss.elastic.co/u/Miguel_Bessa)\
**Replies:** 19\
**Last updated:** [December 8, 2015, 6:43am UTC](https://discuss.elastic.co/t/how-to-have-multiple-nodes-on-same-machine-with-elasticsearch-2-0-0/35578 "2015-12-08T06:43:04Z")

</div>

Hi, I have one machine with ELK (Elasticsearch 2.0.0, Logstash 2.0 and Kibana 4.2.0) stack, but I just have a single node, but I want more 3 nodes. How can I do this? And how I can define on logstash in waht node wil…

---

## [Failed to import dashboard 7.2.0](https://discuss.elastic.co/t/failed-to-import-dashboard-7-2-0/187804)

<div class="topic-metadata">

**Author:** [@alerta](https://discuss.elastic.co/u/alerta)\
**Replies:** 10\
**Last updated:** [July 12, 2019, 3:10pm UTC](https://discuss.elastic.co/t/failed-to-import-dashboard-7-2-0/187804 "2019-07-12T15:10:02Z")

</div>

ES version: 7.2.0 (with xpack.security.enabled: true) Kibana version: 7.2.0 Filebeat version: 7.2.0 Hello guys! I tried add data to Kibana with filebeat. And when i run command "filebeat setup" i see some errors in o…

---

## [Design of data structure: one big index vs many smaller indexes](https://discuss.elastic.co/t/design-of-data-structure-one-big-index-vs-many-smaller-indexes/166131)

<div class="topic-metadata">

**Author:** [@esseti](https://discuss.elastic.co/u/esseti)\
**Replies:** 13\
**Last updated:** [February 8, 2019, 8:47am UTC](https://discuss.elastic.co/t/design-of-data-structure-one-big-index-vs-many-smaller-indexes/166131 "2019-02-08T08:47:12Z")

</div>

Hi there, we are facing a design problem in the place I work. Let's say that we have many data structures that contain documents, this data structure can be of different forms, with fields that are generated by the user…

---

## [Disk space getting filled up](https://discuss.elastic.co/t/disk-space-getting-filled-up/137622)

<div class="topic-metadata">

**Author:** [@joshua625](https://discuss.elastic.co/u/joshua625)\
**Replies:** 10\
**Last updated:** [July 2, 2018, 1:57pm UTC](https://discuss.elastic.co/t/disk-space-getting-filled-up/137622 "2018-07-02T13:57:56Z")

</div>

Hello, I'm running out of disk volume even though my indices shows less amt of space. i.e I have something like 250GB out of which I can see 8 gb of indices. but, its occupying almost 150+GB/250 GB space of stuff. I bel…

---

## [Filebeat code=exited, status=1/FAILURE](https://discuss.elastic.co/t/filebeat-code-exited-status-1-failure/258926)

<div class="topic-metadata">

**Author:** [@dave.mc](https://discuss.elastic.co/u/dave.mc)\
**Replies:** 23\
**Last updated:** [December 28, 2020, 6:11pm UTC](https://discuss.elastic.co/t/filebeat-code-exited-status-1-failure/258926 "2020-12-28T18:11:57Z")

</div>

Newbie here, so think basic. :slightly\_smiling\_face: Filebeat service won't start (on Debian), fails with code=exited, status=1/FAILURE. If I run filebeat -v -e -d "\*", I get: Exiting: error loading config file: yaml…

---

## [Parsing json with delimiters using logstash](https://discuss.elastic.co/t/parsing-json-with-delimiters-using-logstash/49281)

<div class="topic-metadata">

**Author:** [@LoriG](https://discuss.elastic.co/u/LoriG)\
**Replies:** 23\
**Last updated:** [June 6, 2016, 9:37pm UTC](https://discuss.elastic.co/t/parsing-json-with-delimiters-using-logstash/49281 "2016-06-06T21:37:57Z")

</div>

I am trying to parse json which is divided by delimiter($). Does someone have idea how I can configure my logstash? Example: My log includes: ReportBody:{"prop1": val1, "prop2":val2}${"prop1": val3, "prop2":val4}${"prop1…

---

## [Caused by: java.lang.NoSuchMethodError: org.springframework.beans.factory.xml.XmlReaderContext.getEnvironment()Lorg/springframework/c](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-org-springframework-beans-factory-xml-xmlreadercontext-getenvironment-lorg-springframework-c/43999)

<div class="topic-metadata">

**Author:** [@prashanthrd](https://discuss.elastic.co/u/prashanthrd)\
**Replies:** 10\
**Last updated:** [March 10, 2016, 2:41pm UTC](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-org-springframework-beans-factory-xml-xmlreadercontext-getenvironment-lorg-springframework-c/43999 "2016-03-10T14:41:40Z")

</div>

Hi, I am trying to load an XML file consisting of elasticsearch properties. In the jave spring web application, I am trying to load the xml file using the below line - ClassPathXmlApplicationContext ctx = new ClassPat…

---

## [Shards Taking a Long Time to Move Between Nodes - Cloud \[7.1.1\]](https://discuss.elastic.co/t/shards-taking-a-long-time-to-move-between-nodes-cloud-7-1-1/186652)

<div class="topic-metadata">

**Author:** [@ljefferies](https://discuss.elastic.co/u/ljefferies)\
**Replies:** 49\
**Last updated:** [July 1, 2019, 2:42pm UTC](https://discuss.elastic.co/t/shards-taking-a-long-time-to-move-between-nodes-cloud-7-1-1/186652 "2019-07-01T14:42:56Z")

</div>

We are running a 17 node cluster with 10 dedicated hot nodes, 3 master nodes and 4 dedicated warm nodes. We have an index with 5 primary shards and a replication factor of 1 that writes only to the hot nodes, which is d…

---

## [Logstash cannot call SQL Stored Procedure](https://discuss.elastic.co/t/logstash-cannot-call-sql-stored-procedure/44271)

<div class="topic-metadata">

**Author:** [@vikram\_yerneni](https://discuss.elastic.co/u/vikram_yerneni)\
**Replies:** 13\
**Last updated:** [May 17, 2017, 4:26pm UTC](https://discuss.elastic.co/t/logstash-cannot-call-sql-stored-procedure/44271 "2017-05-17T16:26:49Z")

</div>

Hi ELK Folks, I have an issue with pulling the data by calling a SQL Stored Procedure. I am using logstash agent to push the data and we are trying to pull in SQL Data in the form of a Stored Procedure. Its keep on thro…

---

## [To which elasticsearch node should logstash send to](https://discuss.elastic.co/t/to-which-elasticsearch-node-should-logstash-send-to/108909)

<div class="topic-metadata">

**Author:** [@subin](https://discuss.elastic.co/u/subin)\
**Replies:** 11\
**Last updated:** [November 24, 2017, 4:48pm UTC](https://discuss.elastic.co/t/to-which-elasticsearch-node-should-logstash-send-to/108909 "2017-11-24T16:48:52Z")

</div>

Hi all, A little background about my production test-bed before my question: Elasticsearch 6.0: 3 nodes, both data and master-eligible nodes. Each with 16G of RAM, with JVM heap set to 8G. 1 node, coordinating-only n…

---

## [Logstash conf error - NoSuchMethodError for PipelineAction::Create](https://discuss.elastic.co/t/logstash-conf-error-nosuchmethoderror-for-pipelineaction-create/217553)

<div class="topic-metadata">

**Author:** [@c95mbq](https://discuss.elastic.co/u/c95mbq)\
**Replies:** 23\
**Last updated:** [February 5, 2020, 7:53pm UTC](https://discuss.elastic.co/t/logstash-conf-error-nosuchmethoderror-for-pipelineaction-create/217553 "2020-02-05T19:53:36Z")

</div>

Hi, I've setup elastic-7.1.1 and enabled http.ssl and transport.ssl and this seems to be working fine (I've also installed Kibana). I next lifted an old conf file from a previous version of Logstash that I'm running on…

---

## [How to use filebeat to filter the tomcate log?](https://discuss.elastic.co/t/how-to-use-filebeat-to-filter-the-tomcate-log/38372)

<div class="topic-metadata">

**Author:** [@Mohamed\_Ibrahim](https://discuss.elastic.co/u/Mohamed_Ibrahim)\
**Replies:** 11\
**Last updated:** [January 18, 2016, 6:06pm UTC](https://discuss.elastic.co/t/how-to-use-filebeat-to-filter-the-tomcate-log/38372 "2016-01-18T18:06:19Z")

</div>

i installed Logstash and elasticsearch from the below tutorial https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-centos-7 and tomcat logs successfully appe…

---

## [Filtering the data list from Discover to only see Unique Ids](https://discuss.elastic.co/t/filtering-the-data-list-from-discover-to-only-see-unique-ids/280472)

<div class="topic-metadata">

**Author:** [@bailarch](https://discuss.elastic.co/u/bailarch)\
**Replies:** 10\
**Last updated:** [August 12, 2021, 1:10pm UTC](https://discuss.elastic.co/t/filtering-the-data-list-from-discover-to-only-see-unique-ids/280472 "2021-08-12T13:10:25Z")

</div>

Hello guys - not sure if the subcategory for this issue is docker (not sure what this is but the other options seem incorrect for me) I am trying to get the list of all the users name from Discovery. However I am seein…

---

## [How to get S3 repository working with AWS instance profile](https://discuss.elastic.co/t/how-to-get-s3-repository-working-with-aws-instance-profile/80380)

<div class="topic-metadata">

**Author:** [@r0c](https://discuss.elastic.co/u/r0c)\
**Replies:** 11\
**Last updated:** [April 1, 2017, 11:53am UTC](https://discuss.elastic.co/t/how-to-get-s3-repository-working-with-aws-instance-profile/80380 "2017-04-01T11:53:25Z")

</div>

Elasticsearch version: 5.2 Plugins installed: \[repository-s3\] JVM version: java version "1.8.0\_102" Java(TM) SE Runtime Environment (build 1.8.0\_102-b14) Java HotSpot(TM) 64-Bit Server VM (build 25.102-b14, mixed mo…

---

## [Logstash index is not creating](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276)

<div class="topic-metadata">

**Author:** [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Replies:** 16\
**Last updated:** [August 1, 2016, 9:44am UTC](https://discuss.elastic.co/t/logstash-index-is-not-creating/56276 "2016-08-01T09:44:30Z")

</div>

Hi, I am unable to get the Logstash index created with my Logstash conf file. Below is the configuration file, input { file { path =\> "/logs/exampledata\_01.log" type =\> "json" start\_position =\> beginning ign…

---

## [Secure connection on HTTP layer](https://discuss.elastic.co/t/secure-connection-on-http-layer/193805)

<div class="topic-metadata">

**Author:** [@Ayush\_Mathur](https://discuss.elastic.co/u/Ayush_Mathur)\
**Replies:** 13\
**Last updated:** [August 6, 2019, 10:18am UTC](https://discuss.elastic.co/t/secure-connection-on-http-layer/193805 "2019-08-06T10:18:21Z")

</div>

I currently have 3 node ES cluster running on 6.2.3 version with transport security configured successfully. Now I'm planning to secure the HTTP client connections to my cluster by following steps mentioned in : https:…

---

## [All files collected under on index only. Is it possible to have multiple indexes for multiple files?](https://discuss.elastic.co/t/all-files-collected-under-on-index-only-is-it-possible-to-have-multiple-indexes-for-multiple-files/212806)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 75\
**Last updated:** [January 25, 2020, 1:34am UTC](https://discuss.elastic.co/t/all-files-collected-under-on-index-only-is-it-possible-to-have-multiple-indexes-for-multiple-files/212806 "2020-01-25T01:34:10Z")

</div>

EVery time I search GET cat/index? in kibana, I only get one index under all files are collected. I want to get three indexes for three different log files given in filebeat. This is logstash.conf file input { bea…

---

## [Topbeat 1.0 stops sending events although it is running](https://discuss.elastic.co/t/topbeat-1-0-stops-sending-events-although-it-is-running/36590)

<div class="topic-metadata">

**Author:** [@Omar\_Al\_Zabir](https://discuss.elastic.co/u/Omar_Al_Zabir)\
**Replies:** 28\
**Last updated:** [December 30, 2015, 2:23pm UTC](https://discuss.elastic.co/t/topbeat-1-0-stops-sending-events-although-it-is-running/36590 "2015-12-30T14:23:42Z")

</div>

ps aux shows: root 10592 0.3 7.5 411648 305972 ? Sl Nov29 39:17 ./topbeat -v -e -c topbeat.yml So it is running. But the log shows: 2015/12/03 21:35:35.773149 single.go:143: INFO send fail 2015/12/…

---

## [How can a configure two node in one cluster](https://discuss.elastic.co/t/how-can-a-configure-two-node-in-one-cluster/171088)

<div class="topic-metadata">

**Author:** [@dattack13](https://discuss.elastic.co/u/dattack13)\
**Replies:** 12\
**Last updated:** [March 6, 2019, 6:23pm UTC](https://discuss.elastic.co/t/how-can-a-configure-two-node-in-one-cluster/171088 "2019-03-06T18:23:09Z")

</div>

Hi, I have situation where I have installed two instance of Elasticsearch setup in remote server 1 (node1) and remote server 2 (node2), and I want to connect both these node in one cluster, however I also installed the …

---

## [Grok patterns with quotation marks](https://discuss.elastic.co/t/grok-patterns-with-quotation-marks/273003)

<div class="topic-metadata">

**Author:** [@qttv](https://discuss.elastic.co/u/qttv)\
**Replies:** 17\
**Last updated:** [May 18, 2021, 10:01pm UTC](https://discuss.elastic.co/t/grok-patterns-with-quotation-marks/273003 "2021-05-18T22:01:48Z")

</div>

Good Evening, I'm trying to extrapolate some fields from the following log message: { "message": "Throw: Il prodotto estratto non è presente tra quelli del menu a tendina in fase di emissione della proposta", "level":…

---

## [Message :Invalid Frame Type, received: 84 et 69 dans logstash](https://discuss.elastic.co/t/message-invalid-frame-type-received-84-et-69-dans-logstash/71528)

<div class="topic-metadata">

**Author:** [@debellabre](https://discuss.elastic.co/u/debellabre)\
**Replies:** 18\
**Last updated:** [January 17, 2017, 7:05am UTC](https://discuss.elastic.co/t/message-invalid-frame-type-received-84-et-69-dans-logstash/71528 "2017-01-17T07:05:38Z")

</div>

Bonjour, j'utilise un docker elk qui reçoit les logs d'un serveur postgresql via filbeat. Logstash crache cette erreur à chaque fois que filebeat lui envoi un evènement. Les 2 os sont redhat 7. Les FW sont désactivés,…

---

## [Publication of cluster state fails - followers check retry count exceeded](https://discuss.elastic.co/t/publication-of-cluster-state-fails-followers-check-retry-count-exceeded/330097)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 49\
**Last updated:** [June 20, 2023, 4:31pm UTC](https://discuss.elastic.co/t/publication-of-cluster-state-fails-followers-check-retry-count-exceeded/330097 "2023-06-20T16:31:34Z")

</div>

Hi everyone, We are running Elasticsearch 8.6.1 (on Kubernetes) with 12 data nodes (pods) and 3 dedicated master pods. We are heavily indexing data (bulks) and we did some configuration tunes to improve indexing: indi…

---

## [Filebeat not picking the files as expected](https://discuss.elastic.co/t/filebeat-not-picking-the-files-as-expected/72851)

<div class="topic-metadata">

**Author:** [@Ajay1](https://discuss.elastic.co/u/Ajay1)\
**Replies:** 11\
**Last updated:** [February 1, 2017, 8:59am UTC](https://discuss.elastic.co/t/filebeat-not-picking-the-files-as-expected/72851 "2017-02-01T08:59:34Z")

</div>

I have the following config , /var/lib/transfers/report/\*/archive/processed/ABC-Reconciliation\*.csv --\> which is new reports files everyday Each day new files with different name file for one of the defined prospect…

---

## [Kibana Discover not showing data for any time range](https://discuss.elastic.co/t/kibana-discover-not-showing-data-for-any-time-range/212597)

<div class="topic-metadata">

**Author:** [@sharry007](https://discuss.elastic.co/u/sharry007)\
**Replies:** 9\
**Last updated:** [January 30, 2020, 6:10am UTC](https://discuss.elastic.co/t/kibana-discover-not-showing-data-for-any-time-range/212597 "2020-01-30T06:10:02Z")

</div>

I have an index with timestamp field mapping as following: "@timestamp": { "type": "date", "format": "EEE, dd MMM YYYY HH:mm:ss z" } @timestamp field in document shows "@timestamp" : "Wed, 26 Sep 2018 11:55:41 …

---

## [Searching for exact string in big fields (Lucene Limitation)](https://discuss.elastic.co/t/searching-for-exact-string-in-big-fields-lucene-limitation/117288)

<div class="topic-metadata">

**Author:** [@amersabagzad](https://discuss.elastic.co/u/amersabagzad)\
**Replies:** 13\
**Last updated:** [February 3, 2018, 9:40am UTC](https://discuss.elastic.co/t/searching-for-exact-string-in-big-fields-lucene-limitation/117288 "2018-02-03T09:40:53Z")

</div>

I spent a long time trying to figure out a way to use Elasticsearch for exact string searches like we do normally in MySQL: SELECT \* FROM mytable WHERE long\_text\_field like "%search\_text%" I am talking about fields long…

---

## [Missing Client Nodes in v5.6](https://discuss.elastic.co/t/missing-client-nodes-in-v5-6/100464)

<div class="topic-metadata">

**Author:** [@iam.Carrot](https://discuss.elastic.co/u/iam.Carrot)\
**Replies:** 39\
**Last updated:** [September 18, 2017, 10:46am UTC](https://discuss.elastic.co/t/missing-client-nodes-in-v5-6/100464 "2017-09-18T10:46:17Z")

</div>

Hi I upgraded to elastic version 5.6, Now in the yml file when I put node.client: true it says there is nothing called as client. And when I searched online, I don't find anything with client node in the v5.6 instead i g…

---

## [Socket hang up error in kibana v 6.2.1](https://discuss.elastic.co/t/socket-hang-up-error-in-kibana-v-6-2-1/124791)

<div class="topic-metadata">

**Author:** [@vissu](https://discuss.elastic.co/u/vissu)\
**Replies:** 11\
**Last updated:** [March 27, 2018, 1:35pm UTC](https://discuss.elastic.co/t/socket-hang-up-error-in-kibana-v-6-2-1/124791 "2018-03-27T13:35:54Z")

</div>

i am using Elasticsearch and kibana version 6.2.1. When i enable SSL on kibana Webserver i am getting below error continuously in kibana logs. {"type":"error","@timestamp":"2018-03-20T14:32:09Z","tags":\["connection","c…

---

## [\[circuit\_breaking\_exception\] \[parent\] Data too large](https://discuss.elastic.co/t/circuit-breaking-exception-parent-data-too-large/246512)

<div class="topic-metadata">

**Author:** [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Replies:** 13\
**Last updated:** [August 27, 2020, 7:06am UTC](https://discuss.elastic.co/t/circuit-breaking-exception-parent-data-too-large/246512 "2020-08-27T07:06:48Z")

</div>

Hi all, since this morning I am getting the following errors from time to time in my ECK elasticsearch 7.9.0 cluster. Version: 7.9.0 Build: 33813 Error at Fetch.\_callee3$ (https://kibana.problem.cluster/33813/bundl…

---

## [Bulk API Rejected records but I can't see a reason](https://discuss.elastic.co/t/bulk-api-rejected-records-but-i-cant-see-a-reason/78368)

<div class="topic-metadata">

**Author:** [@Cylindric](https://discuss.elastic.co/u/Cylindric)\
**Replies:** 9\
**Last updated:** [March 14, 2017, 1:31pm UTC](https://discuss.elastic.co/t/bulk-api-rejected-records-but-i-cant-see-a-reason/78368 "2017-03-14T13:31:53Z")

</div>

Hi folks, I am trying to index a fairly high-volume log source, and am using the ElasticNEST client in a C# app to do so. On most of my batches, I am getting an Invalid NEST response error. As far as I can see, the err…

---

## [org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[indices:data/write/bulk\[s\]\[r\]\]](https://discuss.elastic.co/t/org-elasticsearch-common-breaker-circuitbreakingexception-parent-data-too-large-data-for-indices-data-write-bulk-s-r/275660)

<div class="topic-metadata">

**Author:** [@Vdm88](https://discuss.elastic.co/u/Vdm88)\
**Replies:** 13\
**Last updated:** [July 6, 2021, 10:14am UTC](https://discuss.elastic.co/t/org-elasticsearch-common-breaker-circuitbreakingexception-parent-data-too-large-data-for-indices-data-write-bulk-s-r/275660 "2021-07-06T10:14:55Z")

</div>

Cluster always get CircuitBreakingException after update to ES7.13. -Xms31g -Xmx31g 14-:-XX:+UseG1GC 14-:-XX:G1ReservePercent=25 14-:-XX:InitiatingHeapOccupancyPercent=30 We checked and we have no huge query execut…

---

## [Creating Indexes with proper mapping in ES 5.0 on Java API](https://discuss.elastic.co/t/creating-indexes-with-proper-mapping-in-es-5-0-on-java-api/67065)

<div class="topic-metadata">

**Author:** [@jiouser](https://discuss.elastic.co/u/jiouser)\
**Replies:** 14\
**Last updated:** [November 28, 2016, 7:13pm UTC](https://discuss.elastic.co/t/creating-indexes-with-proper-mapping-in-es-5-0-on-java-api/67065 "2016-11-28T19:13:17Z")

</div>

I am trying to index documents in ES which is running on local usign JAVA API. Its ES 5.0 No matter what I do, I am not able to create the index and hence not able to index. Two fields : name : String data: Object Althou…

---

## [Elastic curator in cron job?](https://discuss.elastic.co/t/elastic-curator-in-cron-job/80139)

<div class="topic-metadata">

**Author:** [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Replies:** 10\
**Last updated:** [March 28, 2017, 9:10am UTC](https://discuss.elastic.co/t/elastic-curator-in-cron-job/80139 "2017-03-28T09:10:37Z")

</div>

Hi, i have curator in linux environment which is in live so i can't experiment with that . i need one clarification regarding the command i have curator files in /home/hero/.curator . If i run the below cron job comm…

---

## [Примерный поиск и сортировка результатов](https://discuss.elastic.co/t/topic/36413)

<div class="topic-metadata">

**Author:** [@hmx](https://discuss.elastic.co/u/hmx)\
**Replies:** 12\
**Last updated:** [December 9, 2015, 6:50pm UTC](https://discuss.elastic.co/t/topic/36413 "2015-12-09T18:50:25Z")

</div>

Всем добрый вечер! Есть документы, в которых хранится 2 поля: Имя и фамилия. Нужно создать запрос, который выводил бы документы, В имени и/или фамилии содержится запрос. Запросы могут выть вида: "Марина карпова", "м карп…

---

## [Strange indexes](https://discuss.elastic.co/t/strange-indexes/31305)

<div class="topic-metadata">

**Author:** [@it2](https://discuss.elastic.co/u/it2)\
**Replies:** 16\
**Last updated:** [December 29, 2015, 8:25am UTC](https://discuss.elastic.co/t/strange-indexes/31305 "2015-12-29T08:25:49Z")

</div>

Hi there! I have an ES Cluster. And everyday strange indexes are creating. It looks like In logs I see next root@logstashm:~# cat /var/log/elasticsearch/cloud.log | grep awgasv1.html \[2015-09-29 08:13:36,632\]\[DEBUG\]…

---

## [Logstash not pushing logs to ElasticSearch](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-elasticsearch/190915)

<div class="topic-metadata">

**Author:** [@Brindha\_S](https://discuss.elastic.co/u/Brindha_S)\
**Replies:** 26\
**Last updated:** [July 31, 2019, 12:40pm UTC](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-elasticsearch/190915 "2019-07-31T12:40:41Z")

</div>

I have configured syslog server and ELK in a single Windows machine. I'm getting logs via port 514 without issues, which creates a new text file everyday. The logstash's config output creates new indices every day as pe…

---

## [Elasticsearch high latency](https://discuss.elastic.co/t/elasticsearch-high-latency/130179)

<div class="topic-metadata">

**Author:** [@arun\_kishore](https://discuss.elastic.co/u/arun_kishore)\
**Replies:** 18\
**Last updated:** [May 9, 2018, 8:47am UTC](https://discuss.elastic.co/t/elasticsearch-high-latency/130179 "2018-05-09T08:47:32Z")

</div>

Hey guys, we have been using Elasticsearch 1.7.4 for over 3 years now, and we just upgraded to 6.1.1 version, We have completed our data backfill and start testing our queries. But unfortunately we are seeing really hig…

---

## [Elasticsearch shield SSL nodes unavailable](https://discuss.elastic.co/t/elasticsearch-shield-ssl-nodes-unavailable/52549)

<div class="topic-metadata">

**Author:** [@raaj\_mndl](https://discuss.elastic.co/u/raaj_mndl)\
**Replies:** 25\
**Last updated:** [August 8, 2016, 8:58pm UTC](https://discuss.elastic.co/t/elasticsearch-shield-ssl-nodes-unavailable/52549 "2016-08-08T20:58:24Z")

</div>

I am trying to connect to elastic search 2.1.1 using transport client by setting up Shield SSL. I have succeeded in creating the certificate and the keystore as mentioned in the Shield SSL set up guide using OpenSSL and …

---

## [How to create email alerts in kibana](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 11\
**Last updated:** [July 18, 2023, 9:37am UTC](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219 "2023-07-18T09:37:00Z")

</div>

how can i create email alert for logs in elasticsearch and how can i create connectors in kibana UI

---

## [Parsing word and pdf file in elasticsearch using logstash](https://discuss.elastic.co/t/parsing-word-and-pdf-file-in-elasticsearch-using-logstash/79212)

<div class="topic-metadata">

**Author:** [@Nikparab](https://discuss.elastic.co/u/Nikparab)\
**Replies:** 13\
**Last updated:** [March 23, 2017, 9:12am UTC](https://discuss.elastic.co/t/parsing-word-and-pdf-file-in-elasticsearch-using-logstash/79212 "2017-03-23T09:12:09Z")

</div>

I m trying to read pdf file using logstash i use following config file input { file { path =\> "D:\\ELKstack\\elastic\\page\_ELK.pdf" start\_position =\> "beginning" } } filter { if \[type\] == ".pdf…

---

## [Index keeps getting deleted](https://discuss.elastic.co/t/index-keeps-getting-deleted/317859)

<div class="topic-metadata">

**Author:** [@shivang.ahd](https://discuss.elastic.co/u/shivang.ahd)\
**Replies:** 26\
**Last updated:** [March 15, 2024, 3:17pm UTC](https://discuss.elastic.co/t/index-keeps-getting-deleted/317859 "2024-03-15T15:17:50Z")

</div>

Hi, I am new to elasticsearch. I need to make 140 million entries in elasticsearch. For that i have to keep elasticsearch running. Twice it happened that in the middle of ingesting data, when I am halfway to the numb…

---

## [Logstash filter multiline not working](https://discuss.elastic.co/t/logstash-filter-multiline-not-working/91885)

<div class="topic-metadata">

**Author:** [@tharu85](https://discuss.elastic.co/u/tharu85)\
**Replies:** 9\
**Last updated:** [July 11, 2017, 6:46pm UTC](https://discuss.elastic.co/t/logstash-filter-multiline-not-working/91885 "2017-07-11T18:46:58Z")

</div>

I have a java log which has multiline in the log entries. So I have used multiline in filter function in logstash as below. input { file { path =\> "/etc/logstash-5.2.2/sample7.log" start\_position =\> b…

---

## [Elasticsearch service start](https://discuss.elastic.co/t/elasticsearch-service-start/45092)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 16\
**Last updated:** [March 29, 2016, 6:56am UTC](https://discuss.elastic.co/t/elasticsearch-service-start/45092 "2016-03-29T06:56:27Z")

</div>

HI, I want to start elasticsearch as service in linux machine. Before i was used service wrapper to start elasticsearch as service. But now i m unable to use it because im using elasticsearch 2.2.1 version. Kindly help m…

---

## [Elasticsearch with Amazon Elastic File System](https://discuss.elastic.co/t/elasticsearch-with-amazon-elastic-file-system/55867)

<div class="topic-metadata">

**Author:** [@ivten](https://discuss.elastic.co/u/ivten)\
**Replies:** 13\
**Last updated:** [October 27, 2016, 8:53pm UTC](https://discuss.elastic.co/t/elasticsearch-with-amazon-elastic-file-system/55867 "2016-10-27T20:53:33Z")

</div>

Hi, I have a single Elasticsearch node on Amazon EC2 instance. I've also mounted AWS Elastic File System to the instance under /usr/share/elasticsearch. When I start elasticsearch it starts normally and I can see that …

---

## [How to convert string to JSON?](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845)

<div class="topic-metadata">

**Author:** [@iStepich](https://discuss.elastic.co/u/iStepich)\
**Replies:** 9\
**Last updated:** [October 6, 2017, 9:31am UTC](https://discuss.elastic.co/t/how-to-convert-string-to-json/102845 "2017-10-06T09:31:36Z")

</div>

My logstash configuration is: input { tcp{ codec =\> json\_lines {charset =\> "CP1251"} ... } } output { elasticsearch{...}} But there is a problem that I can recieve string to already mapped as object field. In t…

---

## [%{\[@metadata\]\[beat\]}-%{\[@metadata\]\[version\]}-%{+YYYY.MM.dd}](https://discuss.elastic.co/t/metadata-beat-metadata-version-yyyy-mm-dd/127360)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 15\
**Last updated:** [April 16, 2018, 3:40pm UTC](https://discuss.elastic.co/t/metadata-beat-metadata-version-yyyy-mm-dd/127360 "2018-04-16T15:40:24Z")

</div>

I'm trying to follow Configure the Logstash output | Metricbeat Reference (Accessing metadata fields) # curl --silent --request GET $ELASTICSEARCH\_URI/\_cat/indices | grep metadata green open %{\[@metadata\]\[beat\]}-%{\[@met…

---

## [ERROR: All shards failed for phase: \[query\]](https://discuss.elastic.co/t/error-all-shards-failed-for-phase-query/118236)

<div class="topic-metadata">

**Author:** [@gunesg](https://discuss.elastic.co/u/gunesg)\
**Replies:** 18\
**Last updated:** [February 5, 2018, 12:11pm UTC](https://discuss.elastic.co/t/error-all-shards-failed-for-phase-query/118236 "2018-02-05T12:11:04Z")

</div>

Hello, I'm using ElasticSearch and Kibana with X-Pack. When I try to start elasticsearch, I get these error messages. And I have no logout button on Kibana. I've created a kibana\_user and a superuser, I Can log in wit…

---

## [How to insert data from a json file using bulk API in ES2.1](https://discuss.elastic.co/t/how-to-insert-data-from-a-json-file-using-bulk-api-in-es2-1/36758)

<div class="topic-metadata">

**Author:** [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Replies:** 15\
**Last updated:** [November 10, 2016, 10:59am UTC](https://discuss.elastic.co/t/how-to-insert-data-from-a-json-file-using-bulk-api-in-es2-1/36758 "2016-11-10T10:59:07Z")

</div>

Hi Experts, I have downloaded accounts.json from here and saved it in my local drive . Path is E:\\data\\accounts.json Now when I fired POST /bank/account/\_bulk?pretty --data-binary E:\\data\\accounts.json I am gettin…

---

## [Failed to publish events caused by: read tcp](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-read-tcp/217410)

<div class="topic-metadata">

**Author:** [@daz1761](https://discuss.elastic.co/u/daz1761)\
**Replies:** 14\
**Last updated:** [February 12, 2020, 11:00pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-caused-by-read-tcp/217410 "2020-02-12T23:00:35Z")

</div>

I am new to ELK, and I noticed these ERROR logs coming from the Filebeat Docker container: filebeat | 2020-01-31T14:27:27.422Z ERROR logstash/async.go:256 Failed to publish events caused by: read tcp 172…

[Previous page](https://discuss.elastic.co/top.md?page=28&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=30&per_page=50&period=all)
