# Top

**URL:** https://discuss.elastic.co/top.md?page=3&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 4

---

## [Saved "field" parameter is now invalid. Please select a new field. .... Visualize: "field" is a required parameter](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field-visualize-field-is-a-required-parameter/70034)

<div class="topic-metadata">

**Author:** [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Replies:** 27\
**Last updated:** [February 7, 2017, 1:05pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field-visualize-field-is-a-required-parameter/70034 "2017-02-07T13:05:25Z")

</div>

Hi- Am running Elastic Search, Kibana with 5.1.1 version with X-Pack installed. I started Metric beats service and running fine, sending data to Kibana dashboard as expected. When I try to open the dashboard, Am getti…

---

## [Implementing Ingest Attachment Processor Plugin](https://discuss.elastic.co/t/implementing-ingest-attachment-processor-plugin/52300)

<div class="topic-metadata">

**Author:** [@kruelah](https://discuss.elastic.co/u/kruelah)\
**Replies:** 33\
**Last updated:** [March 14, 2018, 1:51pm UTC](https://discuss.elastic.co/t/implementing-ingest-attachment-processor-plugin/52300 "2018-03-14T13:51:47Z")

</div>

I currently use a Mapper Attachments type in my Elasticsearch 2.3 mapping and I try to migrate to Elasticsearch 5.0.0-beta3. Unfortunatelly the plugin has been replaced by new Ingest Attachment Processor Plugin, which is…

---

## [Correct settings for "es.nodes.wan.only"](https://discuss.elastic.co/t/correct-settings-for-es-nodes-wan-only/58743)

<div class="topic-metadata">

**Author:** [@darthapple](https://discuss.elastic.co/u/darthapple)\
**Replies:** 12\
**Last updated:** [October 16, 2019, 8:29pm UTC](https://discuss.elastic.co/t/correct-settings-for-es-nodes-wan-only/58743 "2019-10-16T20:29:03Z")

</div>

Hello, I am trying to run a spark job to load data from emr to ES cluster hosted by elastic.co. \[ cluster ID "665e60" \] Following is code snippet i am using to test this. import java.io.PrintStream import org.apache…

---

## [How to use multiple inputs in Logstash?](https://discuss.elastic.co/t/how-to-use-multiple-inputs-in-logstash/36247)

<div class="topic-metadata">

**Author:** [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Replies:** 11\
**Last updated:** [December 13, 2015, 3:52pm UTC](https://discuss.elastic.co/t/how-to-use-multiple-inputs-in-logstash/36247 "2015-12-13T15:52:13Z")

</div>

Hi, My setup: Two Windows boxes; one is for Elasticsearch and Kibana, and other is for Logstash. I am already dumping Windows events to my ELK setup. Now, I want to collect Microsoft Exchange logs too. How can I cont…

---

## [How to make a field aggregatable in Kibana](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470)

<div class="topic-metadata">

**Author:** [@CDR](https://discuss.elastic.co/u/CDR)\
**Replies:** 12\
**Last updated:** [June 22, 2017, 7:42pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470 "2017-06-22T19:42:06Z")

</div>

I am running the latest versions of Kibana, Logstash and Elasticsearch. I am unsure how to make my logMessage field aggregatable. I have searched on the forums for a solid answer but can't seem to find a definitive one.…

---

## [How to set passwords for built-in users in batch mode?](https://discuss.elastic.co/t/how-to-set-passwords-for-built-in-users-in-batch-mode/119655)

<div class="topic-metadata">

**Author:** [@Vitaly\_il](https://discuss.elastic.co/u/Vitaly_il)\
**Replies:** 11\
**Last updated:** [March 12, 2018, 1:15pm UTC](https://discuss.elastic.co/t/how-to-set-passwords-for-built-in-users-in-batch-mode/119655 "2018-03-12T13:15:52Z")

</div>

I'd like to use "setup-passwords interactive" for settings passwords in my setup script. This command works nice in manual mode, but for some reason fails with Exception in thread "main" java.lang.NullPointerException …

---

## [Parent circuit breaker calculation seems to be wrong with version 7.x](https://discuss.elastic.co/t/parent-circuit-breaker-calculation-seems-to-be-wrong-with-version-7-x/183530)

<div class="topic-metadata">

**Author:** [@e-orz](https://discuss.elastic.co/u/e-orz)\
**Replies:** 21\
**Last updated:** [October 22, 2019, 7:52pm UTC](https://discuss.elastic.co/t/parent-circuit-breaker-calculation-seems-to-be-wrong-with-version-7-x/183530 "2019-10-22T19:52:31Z")

</div>

Hi, After upgrading to ES we started to notice that sometimes search or bulk request fail with: \[parent\] Data too large, data for \[\<transport\_request\>\] would be \[3070458198/2.8gb\], which is larger than the limit of \[30…

---

## [Log4j errors when starting ES](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 21\
**Last updated:** [November 2, 2016, 2:03pm UTC](https://discuss.elastic.co/t/log4j-errors-when-starting-es/64484 "2016-11-02T14:03:48Z")

</div>

Hello, I am installing the new ES and i keep recieving these errors on start. main ERROR Null object returned for RollingFile in Appenders. Oct 31 19:01:40 elasticsearch\[18779\]: 2016-10-31 19:01:40,165 main ERROR Nul…

---

## [I can not install any LogStash plug-in in ES 5.0](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313)

<div class="topic-metadata">

**Author:** [@michelmooren](https://discuss.elastic.co/u/michelmooren)\
**Replies:** 26\
**Last updated:** [February 1, 2017, 1:17pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313 "2017-02-01T13:17:43Z")

</div>

I did a fresh install of ES 5.0. When trying to install LS plug-ins like logstash-filter-multiline and logstash-filter-mutate I keep getting the following error message: An error occurred while installing logstash-cor…

---

## [No logs appearing in Kibana](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/126937)

<div class="topic-metadata">

**Author:** [@jarnold](https://discuss.elastic.co/u/jarnold)\
**Replies:** 22\
**Last updated:** [April 10, 2018, 2:50pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/126937 "2018-04-10T14:50:33Z")

</div>

See title. There are no errors in any of the log files for filebeat/logstash/elasticsearch/kibana. My pipeline is starting up & running properly. I've used this pipeline before on a previous install so I can confirm it's…

---

## [Ubuntu repo not working \[Solved\]](https://discuss.elastic.co/t/ubuntu-repo-not-working-solved/43043)

<div class="topic-metadata">

**Author:** [@doremon](https://discuss.elastic.co/u/doremon)\
**Replies:** 19\
**Last updated:** [March 1, 2016, 5:10am UTC](https://discuss.elastic.co/t/ubuntu-repo-not-working-solved/43043 "2016-03-01T05:10:38Z")

</div>

TL;DR The deb file available on download page work for both i686 and x64 BUT the package in the repo is only available for x64. This was the confusion which triggered this thread. Hi, I did included the elasticsearc…

---

## [Master node role in a cluster](https://discuss.elastic.co/t/master-node-role-in-a-cluster/2327)

<div class="topic-metadata">

**Author:** [@alexolivan](https://discuss.elastic.co/u/alexolivan)\
**Replies:** 9\
**Last updated:** [June 10, 2015, 11:49pm UTC](https://discuss.elastic.co/t/master-node-role-in-a-cluster/2327 "2015-06-10T23:49:37Z")

</div>

Hi again forum. Iḿ trying to grow up my baby cluster into something more capable, but every intent on modifying the current deploy leads to disaster. As starting point, I currently have a master/non-data node plus two …

---

## [WARNING: Could not find logstash.yml](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml/71219)

<div class="topic-metadata">

**Author:** [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Replies:** 18\
**Last updated:** [January 23, 2017, 1:44pm UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml/71219 "2017-01-23T13:44:45Z")

</div>

Hello/Bonjour I have installed ELK. Note : All lines of differents config files not mentionned after are commented (#xyabc) Elasticsearch conf in "/etc/elasticsearch/elasticsearch.yml" is : node.name: elastic1 …

---

## [ClusterBlockException occurred when node comes back to Cluster](https://discuss.elastic.co/t/clusterblockexception-occurred-when-node-comes-back-to-cluster/1052)

<div class="topic-metadata">

**Author:** [@ranzez](https://discuss.elastic.co/u/ranzez)\
**Replies:** 9\
**Last updated:** [July 26, 2015, 4:29am UTC](https://discuss.elastic.co/t/clusterblockexception-occurred-when-node-comes-back-to-cluster/1052 "2015-07-26T04:29:36Z")

</div>

I was running resiliency tests for Elasticsearch and found that when Master or Data node recovers after being killed, my client library throws org.elasticsearch.cluster.block.ClusterBlockException: blocked by: \[SERVICE\_U…

---

## [Force change cluster master](https://discuss.elastic.co/t/force-change-cluster-master/46155)

<div class="topic-metadata">

**Author:** [@Zaid\_Amir](https://discuss.elastic.co/u/Zaid_Amir)\
**Replies:** 10\
**Last updated:** [June 19, 2019, 11:40am UTC](https://discuss.elastic.co/t/force-change-cluster-master/46155 "2019-06-19T11:40:14Z")

</div>

Hi, Today I've been trying to increase the storage of my elasticsearch nodes. The nodes are hosted on AWS EC2 each with an attached EBS of 10 GB. I was trying to increase the EBS size to 20GB for each node and it all w…

---

## [I will run elasticsearch it will getting error](https://discuss.elastic.co/t/i-will-run-elasticsearch-it-will-getting-error/82103)

<div class="topic-metadata">

**Author:** [@bvnages](https://discuss.elastic.co/u/bvnages)\
**Replies:** 25\
**Last updated:** [April 14, 2017, 7:20am UTC](https://discuss.elastic.co/t/i-will-run-elasticsearch-it-will-getting-error/82103 "2017-04-14T07:20:39Z")

</div>

Hi All , I am run the elasticsearch it will getting error. ./elasticsearch \[2017-04-12T07:23:31,443\]\[INFO \]\[o.e.n.Node \] \[\] initializing ... \[2017-04-12T07:23:31,476\]\[WARN \]\[o.e.b.ElasticsearchUncaught…

---

## [How to parse date field into @timestamp](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/107396)

<div class="topic-metadata">

**Author:** [@sdussin](https://discuss.elastic.co/u/sdussin)\
**Replies:** 17\
**Last updated:** [November 14, 2017, 7:26pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/107396 "2017-11-14T19:26:26Z")

</div>

I'm trying to replace the @timestamp that's generated by logstash with the contents of an existing field in my data. I've been fighting with this all day, and I'm nowhere. My data looks like this { "start\_time" : "201…

---

## [Logstash OOM - understanding heap sizing](https://discuss.elastic.co/t/logstash-oom-understanding-heap-sizing/103495)

<div class="topic-metadata">

**Author:** [@dandrestor](https://discuss.elastic.co/u/dandrestor)\
**Replies:** 13\
**Last updated:** [October 12, 2017, 6:36am UTC](https://discuss.elastic.co/t/logstash-oom-understanding-heap-sizing/103495 "2017-10-12T06:36:42Z")

</div>

Hello Could you help me understand logstash's memory requirements? I am currently getting these errors: \[2017-10-11T09:45:02,586\]\[INFO \]\[org.logstash.beats.BeatsHandler\] Exception: java.lang.OutOfMemoryError: Java heap…

---

## [Logstash errors after upgrading to filebeat-6.3.0](https://discuss.elastic.co/t/logstash-errors-after-upgrading-to-filebeat-6-3-0/135984)

<div class="topic-metadata">

**Author:** [@gregvolk](https://discuss.elastic.co/u/gregvolk)\
**Replies:** 28\
**Last updated:** [July 2, 2018, 11:50pm UTC](https://discuss.elastic.co/t/logstash-errors-after-upgrading-to-filebeat-6-3-0/135984 "2018-07-02T23:50:55Z")

</div>

After upgrading from filebeat-6.2.4 to filebeat-6.3.0 none of my log messages make into logstash. I did not make any filebeat.yml or logstash.conf changes during the upgrade. The logstash.stdout is full of errors like th…

---

## [Hadoop / Elasticsearch functionality](https://discuss.elastic.co/t/hadoop-elasticsearch-functionality/47367)

<div class="topic-metadata">

**Author:** [@dandrestor](https://discuss.elastic.co/u/dandrestor)\
**Replies:** 19\
**Last updated:** [May 2, 2016, 9:43am UTC](https://discuss.elastic.co/t/hadoop-elasticsearch-functionality/47367 "2016-05-02T09:43:01Z")

</div>

Hello all, this is my first post here! I am just starting to learn about Elasticsearch and Hadoop, and there is one thing I don't understand about how they work together. My (admittedly very simplistic) understanding o…

---

## [The remote server returned an error: (429) Too Many Requests](https://discuss.elastic.co/t/the-remote-server-returned-an-error-429-too-many-requests/86879)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 13\
**Last updated:** [May 26, 2017, 3:08pm UTC](https://discuss.elastic.co/t/the-remote-server-returned-an-error-429-too-many-requests/86879 "2017-05-26T15:08:56Z")

</div>

I am creating new topic on this as the old was closed. I increased resources but still I getting this error at some peak hour i have +3000 clients indexing documents using NEST client and i see lot of connection fails wi…

---

## [Don't want to use https and user:password](https://discuss.elastic.co/t/dont-want-to-use-https-and-user-password/202332)

<div class="topic-metadata">

**Author:** [@Kumar\_Saurabh\_Srivas](https://discuss.elastic.co/u/Kumar_Saurabh_Srivas)\
**Replies:** 12\
**Last updated:** [January 13, 2021, 3:39pm UTC](https://discuss.elastic.co/t/dont-want-to-use-https-and-user-password/202332 "2021-01-13T15:39:01Z")

</div>

Hi I am deploying ECK on GKE in a private Kubernetes cluster. That cluster has the only service which will talk to Elasticsearch. So I don't need to have any https or user:password authentication. All I want is a simple…

---

## [How do i make sure that logstash received data from filebeat?](https://discuss.elastic.co/t/how-do-i-make-sure-that-logstash-received-data-from-filebeat/49666)

<div class="topic-metadata">

**Author:** [@Roshan\_r](https://discuss.elastic.co/u/Roshan_r)\
**Replies:** 25\
**Last updated:** [May 23, 2016, 4:11pm UTC](https://discuss.elastic.co/t/how-do-i-make-sure-that-logstash-received-data-from-filebeat/49666 "2016-05-23T16:11:42Z")

</div>

I am trying to use the filebeat and ELK for the first time. I have my components running on RHEL5 server. Filebeat is running on another server with RHEL6 as OS and ELK is running in a 3rd server with RHEL6 as OS. As s…

---

## [Elasticsearch failed to restart](https://discuss.elastic.co/t/elasticsearch-failed-to-restart/139949)

<div class="topic-metadata">

**Author:** [@asalma](https://discuss.elastic.co/u/asalma)\
**Replies:** 35\
**Last updated:** [July 16, 2018, 3:00pm UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-restart/139949 "2018-07-16T15:00:09Z")

</div>

Hi, Please, I need help with this !! \[root@frghcslnetv12 elasticsearch\]# systemctl restart elasticsearch.service Job for elasticsearch.service failed because the control process exited with error code. See "systemctl s…

---

## [Errors after installing X-Pack](https://discuss.elastic.co/t/errors-after-installing-x-pack/64210)

<div class="topic-metadata">

**Author:** [@x10Corey](https://discuss.elastic.co/u/x10Corey)\
**Replies:** 26\
**Last updated:** [June 4, 2019, 9:57am UTC](https://discuss.elastic.co/t/errors-after-installing-x-pack/64210 "2019-06-04T09:57:21Z")

</div>

I upgraded to ES5 and installed X-Pack, however I seem to be having some issues with it. I have 2 clients, 3 masters, and 5 data nodes. On all 10 servers it is now outputting the below error in the ES log multiple time…

---

## [Fail to index a document: mapper\_parsing\_exception: failed to parse, document is empty](https://discuss.elastic.co/t/fail-to-index-a-document-mapper-parsing-exception-failed-to-parse-document-is-empty/69357)

<div class="topic-metadata">

**Author:** [@Vukasin\_Jockovic](https://discuss.elastic.co/u/Vukasin_Jockovic)\
**Replies:** 9\
**Last updated:** [December 21, 2016, 9:08am UTC](https://discuss.elastic.co/t/fail-to-index-a-document-mapper-parsing-exception-failed-to-parse-document-is-empty/69357 "2016-12-21T09:08:50Z")

</div>

I really do not understand what is the problem here... I'm just testing simple Elasticsearch-php There's no big data to transfer or anything similar Just want to index one simple document via Elasticsearch-php When I …

---

## [Delete index older than a week](https://discuss.elastic.co/t/delete-index-older-than-a-week/320737)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 23\
**Last updated:** [December 8, 2022, 10:26am UTC](https://discuss.elastic.co/t/delete-index-older-than-a-week/320737 "2022-12-08T10:26:15Z")

</div>

Currently i have logs from 5 to 6 servers coming to elk. I want to delete all indices older than a week. what is the best way to achieve this? i went through ILM but didn't get the exact way to do this

---

## [Enable Remote Access Kibana](https://discuss.elastic.co/t/enable-remote-access-kibana/71314)

<div class="topic-metadata">

**Author:** [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Replies:** 10\
**Last updated:** [March 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/enable-remote-access-kibana/71314 "2017-03-06T05:13:01Z")

</div>

Hi - I have started Metric beats on a remote server, which is kept sending data to the Elastic search. I have hosted Elastic Search and Kibana on a different Remote machine, Am able to access the Elastic Search. Could…

---

## [Why is it ElasticSearch is not allowed to run as root](https://discuss.elastic.co/t/why-is-it-elasticsearch-is-not-allowed-to-run-as-root/60413)

<div class="topic-metadata">

**Author:** [@lin-zhao](https://discuss.elastic.co/u/lin-zhao)\
**Replies:** 9\
**Last updated:** [December 6, 2016, 7:38pm UTC](https://discuss.elastic.co/t/why-is-it-elasticsearch-is-not-allowed-to-run-as-root/60413 "2016-12-06T19:38:46Z")

</div>

I'm deploying ElasticSearch inside of a Docker container, which usually run processes as root user. I get "org.elasticsearch.bootstrap.StartupError: java.lang.RuntimeException: can not run elasticsearch as root" error wh…

---

## [Elasticsearch only accessible from localhost](https://discuss.elastic.co/t/elasticsearch-only-accessible-from-localhost/65782)

<div class="topic-metadata">

**Author:** [@Pokecallum](https://discuss.elastic.co/u/Pokecallum)\
**Replies:** 21\
**Last updated:** [November 14, 2016, 2:05pm UTC](https://discuss.elastic.co/t/elasticsearch-only-accessible-from-localhost/65782 "2016-11-14T14:05:47Z")

</div>

I have Elasticsearch, Logstash and Kibana all running on verion 5 on CentOS 7 I'm still very new to ELK so my understanding might not be correct. I'm trying to create an Elasticsearch cluster, so its my understanding t…

---

## [How to handle multiple inputs with Logstash to different indices](https://discuss.elastic.co/t/how-to-handle-multiple-inputs-with-logstash-to-different-indices/24541)

<div class="topic-metadata">

**Author:** [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Replies:** 18\
**Last updated:** [February 27, 2017, 3:31pm UTC](https://discuss.elastic.co/t/how-to-handle-multiple-inputs-with-logstash-to-different-indices/24541 "2017-02-27T15:31:35Z")

</div>

Directory Structure: ....Results ....Project1 +....RUN1 +....Run2 ....Project2 +....RUN1 +....Run2 "Results" directory contains Project1 & Project2 sub director…

---

## [Invalid initial heap size](https://discuss.elastic.co/t/invalid-initial-heap-size/143248)

<div class="topic-metadata">

**Author:** [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Replies:** 32\
**Last updated:** [September 14, 2018, 2:43pm UTC](https://discuss.elastic.co/t/invalid-initial-heap-size/143248 "2018-09-14T14:43:06Z")

</div>

Hey guys, I have a machine running elasticsearch as a service, it initially had 3GB of RAM available, which worked, but now I could increase the RAM and get Elasticsearch 9GB of RAM, but I always get the error invalid i…

---

## [Scripts of type \[inline\], operation \[aggs\] and lang \[groovy\] are disabled](https://discuss.elastic.co/t/scripts-of-type-inline-operation-aggs-and-lang-groovy-are-disabled/2493)

<div class="topic-metadata">

**Author:** [@refaelos](https://discuss.elastic.co/u/refaelos)\
**Replies:** 9\
**Last updated:** [October 5, 2016, 4:50pm UTC](https://discuss.elastic.co/t/scripts-of-type-inline-operation-aggs-and-lang-groovy-are-disabled/2493 "2016-10-05T16:50:14Z")

</div>

Keep getting this error: \[2015-06-11 16:09:46,824\]\[DEBUG\]\[action.search.type \] \[Radion the Atomic Man\] \[logstash-2014.12.30\]\[0\], node\[SoTj\_ahJSJa5WtFhRUPWow\], \[P\], s\[STARTED\]: Failed to execute \[org.elasticsear…

---

## [Retrying individual bulk actions that failed or were rejected by the previous bulk request](https://discuss.elastic.co/t/retrying-individual-bulk-actions-that-failed-or-were-rejected-by-the-previous-bulk-request/138419)

<div class="topic-metadata">

**Author:** [@m\_5amy](https://discuss.elastic.co/u/m_5amy)\
**Replies:** 13\
**Last updated:** [July 4, 2018, 11:47am UTC](https://discuss.elastic.co/t/retrying-individual-bulk-actions-that-failed-or-were-rejected-by-the-previous-bulk-request/138419 "2018-07-04T11:47:28Z")

</div>

Hi all, logstash logs return this error retrying failed action with response code: 403 ({"type"=\>"cluster\_block\_exception", "reason"=\>"blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\]; what should i do …

---

## [Conditional update to the document](https://discuss.elastic.co/t/conditional-update-to-the-document/64964)

<div class="topic-metadata">

**Author:** [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Replies:** 22\
**Last updated:** [September 7, 2020, 11:56am UTC](https://discuss.elastic.co/t/conditional-update-to-the-document/64964 "2020-09-07T11:56:25Z")

</div>

Hello, If I wanted to update an existing document completely (not partially), if it satisfies the condition. See an example below: Index: Twitter Type: tweet Add tweet and lastupdated fields to document 1 as below.…

---

## [WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022)

<div class="topic-metadata">

**Author:** [@sayed\_mohamed](https://discuss.elastic.co/u/sayed_mohamed)\
**Replies:** 23\
**Last updated:** [May 10, 2018, 8:14am UTC](https://discuss.elastic.co/t/warning-could-not-find-logstash-yml-which-is-typically-located-in-ls-home-config-or-etc-logstash/131022 "2018-05-10T08:14:59Z")

</div>

i have a problem that i run file as command : sudo bin/logstash --path.data sensor38 -f /home/sayed/logstash/sayed.conf and i have an warning that i set some configuration on it WARNING: Could not find logstash.yml whi…

---

## [Kibana login username & password](https://discuss.elastic.co/t/kibana-login-username-password/69016)

<div class="topic-metadata">

**Author:** [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Replies:** 15\
**Last updated:** [December 15, 2016, 10:37am UTC](https://discuss.elastic.co/t/kibana-login-username-password/69016 "2016-12-15T10:37:00Z")

</div>

Can I disable it ? Where do I set a username and password? It is the first time I am running the Kibana 5.

---

## [FileBeat EOF Error](https://discuss.elastic.co/t/filebeat-eof-error/60882)

<div class="topic-metadata">

**Author:** [@il.bert](https://discuss.elastic.co/u/il.bert)\
**Replies:** 42\
**Last updated:** [October 18, 2016, 11:08am UTC](https://discuss.elastic.co/t/filebeat-eof-error/60882 "2016-10-18T11:08:33Z")

</div>

Hi guys, I am running a ELK on a cluster of machine, 3 ES, 2-4LS and 12 FB I have a problem with Filebeat: sometimes it write this error in the log 2016-09-19T14:31:21+02:00 ERR Failed to publish events caused by: EO…

---

## [Merging of segments results in java.lang.OutOfMemoryError: Java heap space](https://discuss.elastic.co/t/merging-of-segments-results-in-java-lang-outofmemoryerror-java-heap-space/26301)

<div class="topic-metadata">

**Author:** [@Srinath\_C](https://discuss.elastic.co/u/Srinath_C)\
**Replies:** 27\
**Last updated:** [August 26, 2015, 3:22am UTC](https://discuss.elastic.co/t/merging-of-segments-results-in-java-lang-outofmemoryerror-java-heap-space/26301 "2015-08-26T03:22:45Z")

</div>

Hi, We found an OOM error when elasticsearch was merging segments. Our cluster 4 instances of c3.xlarge instances running on aws running elasticsearch 1.7.0 There is continuous indexing of small documents (~5kb) at t…

---

## [Kibana not recognizing integer fields](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387)

<div class="topic-metadata">

**Author:** [@foresightyj](https://discuss.elastic.co/u/foresightyj)\
**Replies:** 15\
**Last updated:** [October 5, 2016, 2:34pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387 "2016-10-05T14:34:50Z")

</div>

My logstash index's mapping looks like this: Clearly time\_taken is an long integer field. But Kibana is not recognizing this field as a number field and throws me errors like No Compatible Fields: The "logstash-\*" ind…

---

## ["io.netty.handler.ssl.NotSslRecordException: not an SSL/TLS record" after ssl enabling my cluster](https://discuss.elastic.co/t/io-netty-handler-ssl-notsslrecordexception-not-an-ssl-tls-record-after-ssl-enabling-my-cluster/77987)

<div class="topic-metadata">

**Author:** [@Guy\_Shilo](https://discuss.elastic.co/u/Guy_Shilo)\
**Replies:** 9\
**Last updated:** [March 21, 2017, 8:52pm UTC](https://discuss.elastic.co/t/io-netty-handler-ssl-notsslrecordexception-not-an-ssl-tls-record-after-ssl-enabling-my-cluster/77987 "2017-03-21T20:52:35Z")

</div>

Hello I'm testing X-Pack security and I wanted to encrypt communication in my cluster (non-production). So I followed the instructions here and created self signed certificate for each node. I also changed/added all n…

---

## [Kibana 5 default password](https://discuss.elastic.co/t/kibana-5-default-password/55073)

<div class="topic-metadata">

**Author:** [@alainc](https://discuss.elastic.co/u/alainc)\
**Replies:** 10\
**Last updated:** [November 3, 2016, 1:48pm UTC](https://discuss.elastic.co/t/kibana-5-default-password/55073 "2016-11-03T13:48:58Z")

</div>

Hi i found once the default user and password on kibana 5 and i can't find on which page is it on this site can somebody tell me here on on persoanl message? thanks

---

## [Convert json to ndjson](https://discuss.elastic.co/t/convert-json-to-ndjson/83255)

<div class="topic-metadata">

**Author:** [@httpex](https://discuss.elastic.co/u/httpex)\
**Replies:** 11\
**Last updated:** [April 22, 2017, 1:28am UTC](https://discuss.elastic.co/t/convert-json-to-ndjson/83255 "2017-04-22T01:28:47Z")

</div>

What's the best way to convert json to ndjson?

---

## [Getting "master not discovered or elected yet" causing cluster not up in version 7.1.0](https://discuss.elastic.co/t/getting-master-not-discovered-or-elected-yet-causing-cluster-not-up-in-version-7-1-0/182489)

<div class="topic-metadata">

**Author:** [@niudaye123](https://discuss.elastic.co/u/niudaye123)\
**Replies:** 27\
**Last updated:** [June 3, 2019, 4:46pm UTC](https://discuss.elastic.co/t/getting-master-not-discovered-or-elected-yet-causing-cluster-not-up-in-version-7-1-0/182489 "2019-06-03T16:46:34Z")

</div>

Hi, I am building a 6 nodes cluster, node 1-3 master nodes, and node 4-6 data nodes. I have the following in elasticsearch.yml on each node: bootstrap.memory\_lock: false cluster.initial\_master\_nodes: awselsdevlap01.e…

---

## [Couldn't find any Elasticsearch data](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020)

<div class="topic-metadata">

**Author:** [@Rajkumar\_idsil](https://discuss.elastic.co/u/Rajkumar_idsil)\
**Replies:** 15\
**Last updated:** [April 16, 2018, 5:52pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020 "2018-04-16T17:52:50Z")

</div>

when i start kibana and looking in management tab it is displaying message : "Couldn't find any Elasticsearch data You'll need to index some data into Elasticsearch before you can create an index pattern " \[image\] ki…

---

## [Very high CPU usage on one Elasticsearch data node](https://discuss.elastic.co/t/very-high-cpu-usage-on-one-elasticsearch-data-node/124466)

<div class="topic-metadata">

**Author:** [@grunde](https://discuss.elastic.co/u/grunde)\
**Replies:** 17\
**Last updated:** [April 11, 2018, 6:32am UTC](https://discuss.elastic.co/t/very-high-cpu-usage-on-one-elasticsearch-data-node/124466 "2018-04-11T06:32:20Z")

</div>

Hi, I'm having problems where sometimes one of my serving data nodes starts having 100% CPU usage while others don't. Restarting it solves the issue for a while. There was no rise in traffic. My ES cluster has 8 data…

---

## [Search string with space in a long text](https://discuss.elastic.co/t/search-string-with-space-in-a-long-text/156074)

<div class="topic-metadata">

**Author:** [@3ms1](https://discuss.elastic.co/u/3ms1)\
**Replies:** 10\
**Last updated:** [November 22, 2018, 11:39am UTC](https://discuss.elastic.co/t/search-string-with-space-in-a-long-text/156074 "2018-11-22T11:39:39Z")

</div>

Hi, I would like to hear from anyone who has a solid structural solution of setting and mapping for an index that will have fields that consist of long text where I can search with space in. To use wildcard, field type…

---

## [Creating drop filters based on a string search in a message field](https://discuss.elastic.co/t/creating-drop-filters-based-on-a-string-search-in-a-message-field/64050)

<div class="topic-metadata">

**Author:** [@dvosbury](https://discuss.elastic.co/u/dvosbury)\
**Replies:** 12\
**Last updated:** [March 22, 2019, 4:40am UTC](https://discuss.elastic.co/t/creating-drop-filters-based-on-a-string-search-in-a-message-field/64050 "2019-03-22T04:40:23Z")

</div>

I'm new to the Elastic stack and Logstash. I have a new Logstash instance that is accepting logs from beats sending to Elasticsearch. I'm trying to create a filter that will drop some logs that we aren't that interested …

---

## [Node types in an ElasticSearch cluster](https://discuss.elastic.co/t/node-types-in-an-elasticsearch-cluster/25488)

<div class="topic-metadata">

**Author:** [@linlma](https://discuss.elastic.co/u/linlma)\
**Replies:** 12\
**Last updated:** [July 14, 2015, 6:04am UTC](https://discuss.elastic.co/t/node-types-in-an-elasticsearch-cluster/25488 "2015-07-14T06:04:58Z")

</div>

Hello everyone, I am reading this article and it seems we have various types of nodes, master nodes, client nodes, aggregation query result nodes, data nodes, etc. Wondering if there is an introduction for all kinds …

---

## [Frustrating error: Could not locate that index-pattern (id: false), click here to re-create it](https://discuss.elastic.co/t/frustrating-error-could-not-locate-that-index-pattern-id-false-click-here-to-re-create-it/141911)

<div class="topic-metadata">

**Author:** [@achiskon](https://discuss.elastic.co/u/achiskon)\
**Replies:** 10\
**Last updated:** [August 1, 2018, 8:15am UTC](https://discuss.elastic.co/t/frustrating-error-could-not-locate-that-index-pattern-id-false-click-here-to-re-create-it/141911 "2018-08-01T08:15:13Z")

</div>

There is definitely a bug in version 6.3.x.. While creating an index pattern (after successfully matching with an index), regardless of what timestamp I choose (or not at all): I get the following Could not locate that…

[Previous page](https://discuss.elastic.co/top.md?page=2&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=4&per_page=50&period=all)
