# Top

**URL:** https://discuss.elastic.co/top.md?page=30&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 31

---

## [Error to map date field with format yyyy-MM-dd HH:mm:ss.SSS](https://discuss.elastic.co/t/error-to-map-date-field-with-format-yyyy-mm-dd-hhss-sss/160341)

<div class="topic-metadata">

**Author:** [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Replies:** 9\
**Last updated:** [December 14, 2018, 10:05am UTC](https://discuss.elastic.co/t/error-to-map-date-field-with-format-yyyy-mm-dd-hhss-sss/160341 "2018-12-14T10:05:07Z")

</div>

Hello, can anyone help me to map the date, 2018-12-03 06:00:00.000 I have tried to give mapping to load into logstash as yyyy-MM-dd HH:mm:ss.SSS but getting below error "error"=\>{"type"=\>"mapper\_parsing\_exception", …

---

## [Elasticsearch POST API call gives 401 unauthorized](https://discuss.elastic.co/t/elasticsearch-post-api-call-gives-401-unauthorized/356786)

<div class="topic-metadata">

**Author:** [@ashutos](https://discuss.elastic.co/u/ashutos)\
**Replies:** 11\
**Last updated:** [April 9, 2024, 2:14pm UTC](https://discuss.elastic.co/t/elasticsearch-post-api-call-gives-401-unauthorized/356786 "2024-04-09T14:14:00Z")

</div>

Hello, We are using ELasticsearch 6.8 version and have enabled https for same. Accessing the URL is fine and it is also able to communicate with Kibana. However we are trying to send some data using POST method to elas…

---

## [Kibana 7.6.0 not starting because cannot install APM plugin](https://discuss.elastic.co/t/kibana-7-6-0-not-starting-because-cannot-install-apm-plugin/219807)

<div class="topic-metadata">

**Author:** [@josejfb](https://discuss.elastic.co/u/josejfb)\
**Replies:** 12\
**Last updated:** [March 2, 2020, 9:26am UTC](https://discuss.elastic.co/t/kibana-7-6-0-not-starting-because-cannot-install-apm-plugin/219807 "2020-03-02T09:26:04Z")

</div>

Hello. I'm working on upgrading our Elastic setup to version 7.6.0 and I'm having issues with Kibana startup. What I see in the logs is that Kibana is not able to install the "apm" plugin within the default 30 seconds (s…

---

## [CONFIG\_SECCOMP not compiled into kernel, CONFIG\_SECCOMP and CONFIG\_SECCOMP\_FILTER are needed](https://discuss.elastic.co/t/config-seccomp-not-compiled-into-kernel-config-seccomp-and-config-seccomp-filter-are-needed/87723)

<div class="topic-metadata">

**Author:** [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Replies:** 16\
**Last updated:** [June 1, 2017, 8:30am UTC](https://discuss.elastic.co/t/config-seccomp-not-compiled-into-kernel-config-seccomp-and-config-seccomp-filter-are-needed/87723 "2017-06-01T08:30:37Z")

</div>

Hello EveryOne, I just installed elasticsearch on a server as a service. It's a brand new VM. Elasticsearch worked normally but wanting to restart the service it shows me now the following error : elasticsearch dead b…

---

## [Error saving Spaces](https://discuss.elastic.co/t/error-saving-spaces/157118)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 39\
**Last updated:** [November 29, 2018, 10:15am UTC](https://discuss.elastic.co/t/error-saving-spaces/157118 "2018-11-29T10:15:07Z")

</div>

Hi all, I'm trying to create (using Kibana UI) a Spaces on Kibana 6.5 but I'm facing the error "Error saving space:". so I tried to create it using API. every command ends correctly but when I try to search it using Ki…

---

## [\[RESOLVED\] What SHOULD happen when a data node leaves a cluster? Help please](https://discuss.elastic.co/t/resolved-what-should-happen-when-a-data-node-leaves-a-cluster-help-please/25669)

<div class="topic-metadata">

**Author:** [@Chris\_Neal](https://discuss.elastic.co/u/Chris_Neal)\
**Replies:** 9\
**Last updated:** [July 17, 2015, 8:14pm UTC](https://discuss.elastic.co/t/resolved-what-should-happen-when-a-data-node-leaves-a-cluster-help-please/25669 "2015-07-17T20:14:14Z")

</div>

Hi all, In my Dev environment of two data nodes, primaries = 1, replicas = 1, when I shut down one of the data nodes, all remaining shards are promoted to primaries (as to be expected I believe), the cluster state turn…

---

## [Timeout executing grok](https://discuss.elastic.co/t/timeout-executing-grok/76261)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 11\
**Last updated:** [March 6, 2017, 3:00pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261 "2017-03-06T15:00:05Z")

</div>

Hello I am getting a timeout issue when running a grok filter. My logstash config looks like so. filter { if \[type\] == "cast" { grok { break\_on\_match =\> false mat…

---

## [Elasticsearch high load/CPU usage](https://discuss.elastic.co/t/elasticsearch-high-load-cpu-usage/9180)

<div class="topic-metadata">

**Author:** [@Alpha01](https://discuss.elastic.co/u/Alpha01)\
**Replies:** 9\
**Last updated:** [October 1, 2012, 12:09am UTC](https://discuss.elastic.co/t/elasticsearch-high-load-cpu-usage/9180 "2012-10-01T00:09:24Z")

</div>

Hello, We have an Elasticserach cluster configured with 5 nodes. Every so often one random node will get an extremely high load/CPU usage. We thought the issue was garbage collection related because of the freque…

---

## [Error Kibana container is unhealthy](https://discuss.elastic.co/t/error-kibana-container-is-unhealthy/303409)

<div class="topic-metadata">

**Author:** [@Fabian\_Crespo\_Fernan](https://discuss.elastic.co/u/Fabian_Crespo_Fernan)\
**Replies:** 12\
**Last updated:** [May 20, 2022, 5:27pm UTC](https://discuss.elastic.co/t/error-kibana-container-is-unhealthy/303409 "2022-05-20T17:27:13Z")

</div>

Hello, We are trying to install and configure an Elasticsearch cluster in Ubuntu 20.04.4 LTS(x86-64) with the docker-compose.yml from https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html. The comm…

---

## [Filebeat missing authentication](https://discuss.elastic.co/t/filebeat-missing-authentication/162151)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 18\
**Last updated:** [January 5, 2019, 4:54am UTC](https://discuss.elastic.co/t/filebeat-missing-authentication/162151 "2019-01-05T04:54:06Z")

</div>

hi all, kindly, i installed filebeat, elasticsearch and kibana in my VMware; notably i am not using logstash. After that, i installed X-pack for kibana and elasticsearch,when i start elasticsearch and kibana, kibana con…

---

## [Logstash listening on port 5000 and is able to connect with Filebeat but not parsing logs](https://discuss.elastic.co/t/logstash-listening-on-port-5000-and-is-able-to-connect-with-filebeat-but-not-parsing-logs/40329)

<div class="topic-metadata">

**Author:** [@abinay](https://discuss.elastic.co/u/abinay)\
**Replies:** 17\
**Last updated:** [January 28, 2016, 8:15am UTC](https://discuss.elastic.co/t/logstash-listening-on-port-5000-and-is-able-to-connect-with-filebeat-but-not-parsing-logs/40329 "2016-01-28T08:15:15Z")

</div>

Hii I have this architecture with me - Filebeat ships logs to logstash(listening on port 5000) . Logstash parses logs (i can see on my console too) and pushes them to elasticsearch. Now when I am running my Filebeat , it…

---

## [java.lang.NoClassDefFoundError: org/elasticsearch/transport/TcpChannel](https://discuss.elastic.co/t/java-lang-noclassdeffounderror-org-elasticsearch-transport-tcpchannel/112875)

<div class="topic-metadata">

**Author:** [@ankur\_singla](https://discuss.elastic.co/u/ankur_singla)\
**Replies:** 11\
**Last updated:** [December 22, 2017, 7:57pm UTC](https://discuss.elastic.co/t/java-lang-noclassdeffounderror-org-elasticsearch-transport-tcpchannel/112875 "2017-12-22T19:57:08Z")

</div>

I am using 6.1.1 version of elastic but while building TransportClient using PreBuiltTransportClient this error comes up. Settings settings = Settings.builder() .put("cluster.name", "abcdef").build(); Transpor…

---

## [How does elasticsearch move a primary shard?](https://discuss.elastic.co/t/how-does-elasticsearch-move-a-primary-shard/161815)

<div class="topic-metadata">

**Author:** [@Attila\_Nagy](https://discuss.elastic.co/u/Attila_Nagy)\
**Replies:** 9\
**Last updated:** [December 21, 2018, 12:12pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-move-a-primary-shard/161815 "2018-12-21T12:12:03Z")

</div>

Hi, I wonder, what is the exact process of moving a primary shard to another node? I'm not interested in how to do this with the HTTP API but what happens when the user or elasticsearch decides to do this. How does the…

---

## [Advice needed multiple logstash instance Vs single](https://discuss.elastic.co/t/advice-needed-multiple-logstash-instance-vs-single/28598)

<div class="topic-metadata">

**Author:** [@achakrab22](https://discuss.elastic.co/u/achakrab22)\
**Replies:** 15\
**Last updated:** [June 15, 2016, 5:46am UTC](https://discuss.elastic.co/t/advice-needed-multiple-logstash-instance-vs-single/28598 "2016-06-15T05:46:26Z")

</div>

Hi, I am trying to scan multiple folder paths like dev, qa, prod (maybe 45 paths something like /var/tmp/xyz-dev-abc/\*.logs , or /var/tmp/xyz-qa-abc/\*.logs) I have 15 such different envs(dev/qa/qa1 etc) and 3 such path p…

---

## [How I can modify timestamp in log message to UTC](https://discuss.elastic.co/t/how-i-can-modify-timestamp-in-log-message-to-utc/45830)

<div class="topic-metadata">

**Author:** [@nagesh](https://discuss.elastic.co/u/nagesh)\
**Replies:** 15\
**Last updated:** [April 6, 2016, 4:37pm UTC](https://discuss.elastic.co/t/how-i-can-modify-timestamp-in-log-message-to-utc/45830 "2016-04-06T16:37:33Z")

</div>

Hi, Our log messages contain timestamp in EST format. How I can modify the timestamp to UTC before displaying logs into Kibana. Example message: 2016-03-26T01:55:47.78-0500 \[App/0\] OUT \[AUDIT \] CWWKE0001I: T…

---

## [New tag applied to every document?](https://discuss.elastic.co/t/new-tag-applied-to-every-document/41929)

<div class="topic-metadata">

**Author:** [@Jerry\_Hoffmeister](https://discuss.elastic.co/u/Jerry_Hoffmeister)\
**Replies:** 9\
**Last updated:** [March 9, 2017, 8:23pm UTC](https://discuss.elastic.co/t/new-tag-applied-to-every-document/41929 "2017-03-09T20:23:35Z")

</div>

I've updated everything to the latest versions (logstash, elasticsearch, filebeat, kibana) and I see this tag added to every document: beats\_input\_codec\_plain\_applied Everything looks to be working but what does this …

---

## [Unable to load org.elasticsearch.xpack.core.XPackPlugin](https://discuss.elastic.co/t/unable-to-load-org-elasticsearch-xpack-core-xpackplugin/199094)

<div class="topic-metadata">

**Author:** [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Replies:** 21\
**Last updated:** [September 13, 2019, 2:57pm UTC](https://discuss.elastic.co/t/unable-to-load-org-elasticsearch-xpack-core-xpackplugin/199094 "2019-09-13T14:57:42Z")

</div>

Dear All, Configuring AD realm and having a problem of unable to load security plugin in 7.3 version. I do not want to load any SSL certificates as of now and neither want to enable SSL. Initially want to test a plain A…

---

## [Change Kibana 4.2 logo](https://discuss.elastic.co/t/change-kibana-4-2-logo/32341)

<div class="topic-metadata">

**Author:** [@kruelah](https://discuss.elastic.co/u/kruelah)\
**Replies:** 13\
**Last updated:** [August 23, 2016, 6:37pm UTC](https://discuss.elastic.co/t/change-kibana-4-2-logo/32341 "2016-08-23T18:37:30Z")

</div>

Hi floks, Is there a way to replace Kibana 2 logo ? I tried to replace src/ui/public/images/kibana.png but with no success. Any idea?

---

## [Grok filter - issues with spaces and special charecters](https://discuss.elastic.co/t/grok-filter-issues-with-spaces-and-special-charecters/85805)

<div class="topic-metadata">

**Author:** [@Nikhilpawar1985](https://discuss.elastic.co/u/Nikhilpawar1985)\
**Replies:** 10\
**Last updated:** [May 15, 2017, 9:50pm UTC](https://discuss.elastic.co/t/grok-filter-issues-with-spaces-and-special-charecters/85805 "2017-05-15T21:50:19Z")

</div>

Hi , I am having issues with skipping spaces and special characters which i am testing . I am trying to parse INPUT :- \[2017-05-15 00:00:07,397\] :|: INFO :|: dubprdsfe33.dub.jabodo.com I am using followi…

---

## [Separate indexes for each kubernetes namespace](https://discuss.elastic.co/t/separate-indexes-for-each-kubernetes-namespace/169131)

<div class="topic-metadata">

**Author:** [@gurusrinivasamurthy](https://discuss.elastic.co/u/gurusrinivasamurthy)\
**Replies:** 9\
**Last updated:** [March 4, 2019, 8:21pm UTC](https://discuss.elastic.co/t/separate-indexes-for-each-kubernetes-namespace/169131 "2019-03-04T20:21:35Z")

</div>

Hi Team Setup: ELK cluster is setup using docker-compose on one beefy bare metal server. On the kubernetes side I am running filebeat as a DaemonSet to ship container logs to logstash. Our K8S cluster will have aroun…

---

## [Error when converting Date](https://discuss.elastic.co/t/error-when-converting-date/26306)

<div class="topic-metadata">

**Author:** [@EricK](https://discuss.elastic.co/u/EricK)\
**Replies:** 13\
**Last updated:** [August 6, 2015, 1:18pm UTC](https://discuss.elastic.co/t/error-when-converting-date/26306 "2015-08-06T13:18:57Z")

</div>

Trying to add date from field (start\_date) to @timestamp using the following filter: date { match =\> \[ "start\_date", "yyyy-MM-dd HH:mm:ss Z" \] } start\_date is in the format: 2015-07-26 11:54:43 +0100 I get t…

---

## [Am I missing an installation step?](https://discuss.elastic.co/t/am-i-missing-an-installation-step/36222)

<div class="topic-metadata">

**Author:** [@Russ](https://discuss.elastic.co/u/Russ)\
**Replies:** 20\
**Last updated:** [December 11, 2015, 8:30pm UTC](https://discuss.elastic.co/t/am-i-missing-an-installation-step/36222 "2015-12-11T20:30:55Z")

</div>

I'm running Elasticsearch on an AIX 7.1.0.0 server, and just installed Logstash v2.1.0 today. Once I untar the installation file, I attempted to run the basic example command in the tutorial, and I'm getting a Java erro…

---

## [Incremental Snapshot / Restore](https://discuss.elastic.co/t/incremental-snapshot-restore/28282)

<div class="topic-metadata">

**Author:** [@dimalini](https://discuss.elastic.co/u/dimalini)\
**Replies:** 12\
**Last updated:** [April 19, 2017, 8:05am UTC](https://discuss.elastic.co/t/incremental-snapshot-restore/28282 "2017-04-19T08:05:45Z")

</div>

Hi, I am trying out the snapshot/restore feature in ES. I did the following (1) Registered one of my local directory as repo (2) Took snapshot of indexed data using command PUT /\_snapshot/repo1/snapshot1 (3) Made modif…

---

## [Remote Access Available But Local Access Not Available](https://discuss.elastic.co/t/remote-access-available-but-local-access-not-available/268752)

<div class="topic-metadata">

**Author:** [@sewox](https://discuss.elastic.co/u/sewox)\
**Replies:** 22\
**Last updated:** [April 8, 2021, 1:53pm UTC](https://discuss.elastic.co/t/remote-access-available-but-local-access-not-available/268752 "2021-04-08T13:53:43Z")

</div>

Hi Everyone, I can access it remotely elasticsearch but I can't access local with PHP driver. \<?php ini\_set('display\_errors', 1); ini\_set('display\_startup\_errors', 1); error\_reporting(E\_ALL); requi…

---

## [Marvel.agent: failed to flush exporter bulks](https://discuss.elastic.co/t/marvel-agent-failed-to-flush-exporter-bulks/35817)

<div class="topic-metadata">

**Author:** [@Enniu\_51](https://discuss.elastic.co/u/Enniu_51)\
**Replies:** 12\
**Last updated:** [March 6, 2017, 8:36pm UTC](https://discuss.elastic.co/t/marvel-agent-failed-to-flush-exporter-bulks/35817 "2017-03-06T20:36:36Z")

</div>

Installed marvel plugin to my elasticsearch, but the log gives: \[2015-11-29 15:59:52,514\]\[ERROR\]\[marvel.agent \] \[crawler\_service\_001\] background thread had an uncaught exception ElasticsearchException\[faile…

---

## [Break up large index into multiple smaller equally sized indexes?](https://discuss.elastic.co/t/break-up-large-index-into-multiple-smaller-equally-sized-indexes/265745)

<div class="topic-metadata">

**Author:** [@stevedwray](https://discuss.elastic.co/u/stevedwray)\
**Replies:** 22\
**Last updated:** [March 4, 2021, 12:45am UTC](https://discuss.elastic.co/t/break-up-large-index-into-multiple-smaller-equally-sized-indexes/265745 "2021-03-04T00:45:31Z")

</div>

Whats the best way to break up large index into multiple smaller equally sized indexes? I've looked at using reindex with a query but it seems extremely slow: XPOST localhost:9200/\_reindex { "source": { …

---

## [Unable to connect kibana after encryption?](https://discuss.elastic.co/t/unable-to-connect-kibana-after-encryption/24767)

<div class="topic-metadata">

**Author:** [@Akhilesh\_Anb](https://discuss.elastic.co/u/Akhilesh_Anb)\
**Replies:** 24\
**Last updated:** [July 9, 2015, 2:00pm UTC](https://discuss.elastic.co/t/unable-to-connect-kibana-after-encryption/24767 "2015-07-09T14:00:57Z")

</div>

I have done the encryption ( ssl ) ... now my elasticsearch link is https://localhost:9200 I mentioned this link with https in kibana.yml.. Now im unable to start kibana.. im getting errors like: "error","node\_env":…

---

## [Too many open files](https://discuss.elastic.co/t/too-many-open-files/14304)

<div class="topic-metadata">

**Author:** [@onthefloorr](https://discuss.elastic.co/u/onthefloorr)\
**Replies:** 9\
**Last updated:** [January 8, 2014, 4:16am UTC](https://discuss.elastic.co/t/too-many-open-files/14304 "2014-01-08T04:16:48Z")

</div>

Hi guys, I have a little problem with elasticsearch.. Despite the fact that I set the number of open files on the system as described on the site : http://www.elasticsearch.org/tutorials/too-many-open-files/ , I a…

---

## [Create Index with GeoPoint type](https://discuss.elastic.co/t/create-index-with-geopoint-type/107293)

<div class="topic-metadata">

**Author:** [@yanwei2508](https://discuss.elastic.co/u/yanwei2508)\
**Replies:** 9\
**Last updated:** [November 23, 2017, 8:22pm UTC](https://discuss.elastic.co/t/create-index-with-geopoint-type/107293 "2017-11-23T20:22:07Z")

</div>

NEST/Elasticsearch.Net version:5.5 I want to Create index with model like below: public class company { public long id { get; set; } public string name { get; set; } public string address { get; set; } public long…

---

## [Fleet-server: http: server gave HTTP response to HTTPS client](https://discuss.elastic.co/t/fleet-server-http-server-gave-http-response-to-https-client/301203)

<div class="topic-metadata">

**Author:** [@secopsgeek](https://discuss.elastic.co/u/secopsgeek)\
**Replies:** 25\
**Last updated:** [April 11, 2022, 4:44pm UTC](https://discuss.elastic.co/t/fleet-server-http-server-gave-http-response-to-https-client/301203 "2022-04-11T16:44:48Z")

</div>

Morning Elastic, I was wondering could anyone help me with this issue on enrolling my Linux Agent into Fleet. I am getting this error message when I enroll my agent. 2022-03-31T08:41:12.570-0500 WARN \[tls\] tlsc…

---

## [Why doesn't add\_tag =\> \["${HOSTNAME}"\] work?](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366)

<div class="topic-metadata">

**Author:** [@JimP](https://discuss.elastic.co/u/JimP)\
**Replies:** 18\
**Last updated:** [April 26, 2018, 12:44am UTC](https://discuss.elastic.co/t/why-doesnt-add-tag-hostname-work/129366 "2018-04-26T00:44:09Z")

</div>

This is an environment variable, but I can't get it to work? The tag save is, ${HOSTNAME}, not the environment variable value. https://www.elastic.co/guide/en/logstash/current/environment-variables.html#\_setting\_the\_va…

---

## [High HD utilization](https://discuss.elastic.co/t/high-hd-utilization/10023)

<div class="topic-metadata">

**Author:** [@Eugene\_Strokin](https://discuss.elastic.co/u/Eugene_Strokin)\
**Replies:** 15\
**Last updated:** [December 13, 2012, 6:20pm UTC](https://discuss.elastic.co/t/high-hd-utilization/10023 "2012-12-13T18:20:43Z")

</div>

On production, I've slowly, but constantly growing index base. Now it's about 6M documents few Kb each. The index size is about 6Gb. Today server became almost unusable. I see high hard drive use by ES process. I'v…

---

## [Logstash how to send string as not\_analyzed into elasticsearch](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922)

<div class="topic-metadata">

**Author:** [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)\
**Replies:** 10\
**Last updated:** [September 6, 2016, 9:49am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922 "2016-09-06T09:49:26Z")

</div>

Hi , I am usng logstash 1.5.4 , while indexing the data through logstash, all the string data type indexing as analyzed , but my requirement is it should be not\_analyzed .. So I had changed the file elastic-template.j…

---

## [How my config file should be on publish mode with a single node?](https://discuss.elastic.co/t/how-my-config-file-should-be-on-publish-mode-with-a-single-node/189034)

<div class="topic-metadata">

**Author:** [@emrealtan](https://discuss.elastic.co/u/emrealtan)\
**Replies:** 12\
**Last updated:** [July 8, 2019, 11:10am UTC](https://discuss.elastic.co/t/how-my-config-file-should-be-on-publish-mode-with-a-single-node/189034 "2019-07-08T11:10:59Z")

</div>

Hello, I'm trying to setup Elasticsearch on our porduction server. Initially, we'll use only one server, which means we'll have only one node. But I couldn't figure out how the configuration should be on a production se…

---

## [Watch history not written](https://discuss.elastic.co/t/watch-history-not-written/49869)

<div class="topic-metadata">

**Author:** [@lennylinux](https://discuss.elastic.co/u/lennylinux)\
**Replies:** 23\
**Last updated:** [January 9, 2017, 1:25pm UTC](https://discuss.elastic.co/t/watch-history-not-written/49869 "2017-01-09T13:25:22Z")

</div>

Hi! I´m trying to add a watch with a chain input. The idea: Based on the cluster health example the watch should search in the watch\_history for the last result, check the current cluster state and trigger an action o…

---

## [Периодические зависания](https://discuss.elastic.co/t/topic/107865)

<div class="topic-metadata">

**Author:** [@IvanTushin](https://discuss.elastic.co/u/IvanTushin)\
**Replies:** 24\
**Last updated:** [November 23, 2017, 12:30pm UTC](https://discuss.elastic.co/t/topic/107865 "2017-11-23T12:30:12Z")

</div>

Добрый день! У нас возникла проблема с периодическим зависанием elastic. Такие зависания происходят в момент активного поиска + обновления индекса. В момент зависания elastic практически не отвечает на запросы, даже hot\_…

---

## [Spark-sql does not seem to read from a nested schema](https://discuss.elastic.co/t/spark-sql-does-not-seem-to-read-from-a-nested-schema/24672)

<div class="topic-metadata">

**Author:** [@Puneet\_Jaiswal](https://discuss.elastic.co/u/Puneet_Jaiswal)\
**Replies:** 14\
**Last updated:** [January 9, 2016, 1:20pm UTC](https://discuss.elastic.co/t/spark-sql-does-not-seem-to-read-from-a-nested-schema/24672 "2016-01-09T13:20:03Z")

</div>

Hi, I tried with 2.1.0 and 2.2.SNAPSHOT versions and it seems that when I have nested schema, spark-sql is not able to read the data. public class SimpleApp { public static void main(String\[\] args) { SparkConf c…

---

## [Garbage collection](https://discuss.elastic.co/t/garbage-collection/13990)

<div class="topic-metadata">

**Author:** [@shift](https://discuss.elastic.co/u/shift)\
**Replies:** 12\
**Last updated:** [November 22, 2013, 10:00pm UTC](https://discuss.elastic.co/t/garbage-collection/13990 "2013-11-22T22:00:13Z")

</div>

After about 24 to 36 hours the heap is full on the 7 nodes in our elasticsearch cluster. Old generation space is full, and collection times spike up to 25+ second pauses. Do y'all have any JVM tuning recommendati…

---

## [Elasticsearch SAML integration while using HTTP-Redirect](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658)

<div class="topic-metadata">

**Author:** [@talon](https://discuss.elastic.co/u/talon)\
**Replies:** 55\
**Last updated:** [August 7, 2018, 5:42am UTC](https://discuss.elastic.co/t/elasticsearch-saml-integration-while-using-http-redirect/139658 "2018-08-07T05:42:18Z")

</div>

I am integrating ELK with a AD serve via SAML, the partial message from metadata file supplied by AD serve is { \</ds:X509Data\>\</ds:KeyInfo\>\</md:KeyDescriptor\>md:NameIDFormaturn:oasis:names:tc:SAML:1.1:nameid-format:un…

---

## [Logstash shuts down within some seconds after starting up](https://discuss.elastic.co/t/logstash-shuts-down-within-some-seconds-after-starting-up/192609)

<div class="topic-metadata">

**Author:** [@pharshil9697](https://discuss.elastic.co/u/pharshil9697)\
**Replies:** 11\
**Last updated:** [July 29, 2019, 10:16am UTC](https://discuss.elastic.co/t/logstash-shuts-down-within-some-seconds-after-starting-up/192609 "2019-07-29T10:16:29Z")

</div>

Hi all, I am trying to run a log file, but after instantiating logstash suddenly stops. Logstash 7.2.0 Error Log : \`\[2019-07-29T11:59:28,765\]\[WARN \]\[logstash.config.source.multilocal\] Ignoring the 'pipelines.ym…

---

## [Elasticsearch start](https://discuss.elastic.co/t/elasticsearch-start/76594)

<div class="topic-metadata">

**Author:** [@Tigryss](https://discuss.elastic.co/u/Tigryss)\
**Replies:** 13\
**Last updated:** [March 1, 2017, 6:21am UTC](https://discuss.elastic.co/t/elasticsearch-start/76594 "2017-03-01T06:21:23Z")

</div>

Hi I'm current on upgrade my elk from 2.3.4 to 5.1.2 and I have a troble with ES start. I tried start it as daemon (init file) start as root but run as function USER, and i tried also as the user and no daemon, just a …

---

## [Logstash not listening on port](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 10\
**Last updated:** [November 23, 2020, 2:31pm UTC](https://discuss.elastic.co/t/logstash-not-listening-on-port/255356 "2020-11-23T14:31:01Z")

</div>

I noticed that nothing is listening on port 5044 on my ELK server. Logstash is running. Is there some configuration I missed somewhere to have it running/listening on that port? Here are the last few lines from my log …

---

## [Convert String to date format](https://discuss.elastic.co/t/convert-string-to-date-format/258899)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 25\
**Last updated:** [December 17, 2020, 9:29pm UTC](https://discuss.elastic.co/t/convert-string-to-date-format/258899 "2020-12-17T21:29:12Z")

</div>

Hi All, I am using ELK7.6.2 Trying to convert "createdTime" field from String to date format. Added following filter in my logstash config file: date { match =\> \["createdTime", "YYYY-MM-dd HH:mm:ss.SSS"\] target =\> "cr…

---

## [To Raid or not to Raid](https://discuss.elastic.co/t/to-raid-or-not-to-raid/21234)

<div class="topic-metadata">

**Author:** [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Replies:** 11\
**Last updated:** [January 10, 2015, 5:23pm UTC](https://discuss.elastic.co/t/to-raid-or-not-to-raid/21234 "2015-01-10T17:23:07Z")

</div>

When running Elasticsearch on physical hardware you have it create replicas to make sure no node is a single point of failure. From everyone's experiance should I use Hardware Raid as well, or is it not needed? --…

---

## [How to know the time when elasticsearch indexed the data](https://discuss.elastic.co/t/how-to-know-the-time-when-elasticsearch-indexed-the-data/258603)

<div class="topic-metadata">

**Author:** [@soufian.eldouqe](https://discuss.elastic.co/u/soufian.eldouqe)\
**Replies:** 9\
**Last updated:** [December 21, 2020, 5:31pm UTC](https://discuss.elastic.co/t/how-to-know-the-time-when-elasticsearch-indexed-the-data/258603 "2020-12-21T17:31:15Z")

</div>

Hello, is there any way to know the time that elasticsearch indexed the data ? in others words, when did the index received de data. Thank you

---

## [Unexpected file opening error: File info is not identical with opened file](https://discuss.elastic.co/t/unexpected-file-opening-error-file-info-is-not-identical-with-opened-file/84026)

<div class="topic-metadata">

**Author:** [@jenciso](https://discuss.elastic.co/u/jenciso)\
**Replies:** 20\
**Last updated:** [May 9, 2017, 6:20am UTC](https://discuss.elastic.co/t/unexpected-file-opening-error-file-info-is-not-identical-with-opened-file/84026 "2017-05-09T06:20:05Z")

</div>

I'm trying to collect smtp logs of a windows system environment using filbeat, but I don't get any data because the logfile change very quickly This is the error in filbeat log: 2017-04-28T11:47:02-03:00 ERR Harvest…

---

## [How can Index a Filesystem?](https://discuss.elastic.co/t/how-can-index-a-filesystem/24088)

<div class="topic-metadata">

**Author:** [@pumacy112](https://discuss.elastic.co/u/pumacy112)\
**Replies:** 12\
**Last updated:** [February 19, 2016, 1:17pm UTC](https://discuss.elastic.co/t/how-can-index-a-filesystem/24088 "2016-02-19T13:17:28Z")

</div>

In elasticsearch 1.5 are Rivers deprecated. The FSRiver Plugin is not working with ElasticSearch V. 1.6. How is a good way to Index a File System (example: C.\\temp) without the FSRiver?

---

## [Filebeat is not able to parse json from files where \\n separated json lines (events) are written. It sometimes misses the records and sometimes gives error when traffic is high](https://discuss.elastic.co/t/filebeat-is-not-able-to-parse-json-from-files-where-n-separated-json-lines-events-are-written-it-sometimes-misses-the-records-and-sometimes-gives-error-when-traffic-is-high/107155)

<div class="topic-metadata">

**Author:** [@Aman\_Sehgal](https://discuss.elastic.co/u/Aman_Sehgal)\
**Replies:** 14\
**Last updated:** [December 1, 2017, 5:00am UTC](https://discuss.elastic.co/t/filebeat-is-not-able-to-parse-json-from-files-where-n-separated-json-lines-events-are-written-it-sometimes-misses-the-records-and-sometimes-gives-error-when-traffic-is-high/107155 "2017-12-01T05:00:40Z")

</div>

I am using BELK stack for Log Analytics. versions: ES-5.1.1 is on AWS service Logstash-5.3.0, filebeat-5.3.0 and kibana-5.1.1 filebeat is running on the server where cdrs are generated. Logstash is running on separa…

---

## [Long delay between indexing a document and its availability in search results](https://discuss.elastic.co/t/long-delay-between-indexing-a-document-and-its-availability-in-search-results/103876)

<div class="topic-metadata">

**Author:** [@Michael\_Korbakov](https://discuss.elastic.co/u/Michael_Korbakov)\
**Replies:** 15\
**Last updated:** [October 20, 2017, 8:03pm UTC](https://discuss.elastic.co/t/long-delay-between-indexing-a-document-and-its-availability-in-search-results/103876 "2017-10-20T20:03:41Z")

</div>

Hi all! We are experiencing a problem with ES 5.4.2 on production. About 25% of our indexed documents are only appearing in search results after 3 seconds or more after success response from indexing request. Our cluste…

---

## [Organizacion de los filtros de logstash para filtros propios](https://discuss.elastic.co/t/organizacion-de-los-filtros-de-logstash-para-filtros-propios/198246)

<div class="topic-metadata">

**Author:** [@cristianaxion](https://discuss.elastic.co/u/cristianaxion)\
**Replies:** 33\
**Last updated:** [September 24, 2019, 7:29am UTC](https://discuss.elastic.co/t/organizacion-de-los-filtros-de-logstash-para-filtros-propios/198246 "2019-09-24T07:29:05Z")

</div>

Hola buenas, tengo la siguiente configuracion de los filtros: vale hasta ahi perfecto porque kibana me funciona perfectamente pero lo que quiero es crear un filtro que me recoja los siguientes datos creado con el grok…

[Previous page](https://discuss.elastic.co/top.md?page=29&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=31&per_page=50&period=all)
