# Top

**URL:** https://discuss.elastic.co/top.md?page=34&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 35

---

## [Filebeat won't start](https://discuss.elastic.co/t/filebeat-wont-start/265889)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 11\
**Last updated:** [March 2, 2021, 11:31am UTC](https://discuss.elastic.co/t/filebeat-wont-start/265889 "2021-03-02T11:31:06Z")

</div>

I'm trying to link filebeat with logstash, but filebeat suddenly stopped working. When I try systemctl start filebeat, it does not start. If I run systemctl status filebeat, I get the following message. ● filebeat.ser…

---

## [Elasticsearch 7.16.1 crashing randomly](https://discuss.elastic.co/t/elasticsearch-7-16-1-crashing-randomly/291827)

<div class="topic-metadata">

**Author:** [@ppuschmann](https://discuss.elastic.co/u/ppuschmann)\
**Replies:** 27\
**Last updated:** [December 29, 2021, 10:23am UTC](https://discuss.elastic.co/t/elasticsearch-7-16-1-crashing-randomly/291827 "2021-12-29T10:23:36Z")

</div>

Hi, after upgrading to Elasticsearch 7.16.1 (Debian-package from elastic.co), we're seeing some graver errors and crashes on some clusters: Instances are running with Debian Buster (10) \[2021-12-14T00:00:06,036\]\[ERRO…

---

## [Ctx.payload.hits.hits.0.\_source.field to watcher-history index](https://discuss.elastic.co/t/ctx-payload-hits-hits-0-source-field-to-watcher-history-index/127666)

<div class="topic-metadata">

**Author:** [@Alex\_Kefallonitis](https://discuss.elastic.co/u/Alex_Kefallonitis)\
**Replies:** 14\
**Last updated:** [April 12, 2018, 2:22pm UTC](https://discuss.elastic.co/t/ctx-payload-hits-hits-0-source-field-to-watcher-history-index/127666 "2018-04-12T14:22:28Z")

</div>

Hi all, I am trying to aggregate ctx source fields (triggered source event fields) and force watcher to write them to watcher-history index. For eg i wanna pass the ctx.payload.hits.hits.0.\_source.computer\_name of a win…

---

## [Missing authentication credentials for REST request](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588)

<div class="topic-metadata">

**Author:** [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Replies:** 29\
**Last updated:** [September 11, 2022, 6:19pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/313588 "2022-09-11T18:19:34Z")

</div>

Hi, I'm new to ELK Stack. So far I have configured \[Elasticsearch - Kibana - Logstash\] but the Filebeat configuration is causing issues. Note: All four services are running fine When I run the following command \</\> s…

---

## [Logstash Forwarder connection refused in docker container](https://discuss.elastic.co/t/logstash-forwarder-connection-refused-in-docker-container/29440)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 27\
**Last updated:** [September 21, 2015, 8:30pm UTC](https://discuss.elastic.co/t/logstash-forwarder-connection-refused-in-docker-container/29440 "2015-09-21T20:30:40Z")

</div>

Hello , i seem to follow the same rules on setting up the forwarder but it seems every time i run it i get a connection refused. The IP match as the same in the logstash conf file. I have also passed along the certs to t…

---

## [Unable to create index](https://discuss.elastic.co/t/unable-to-create-index/80939)

<div class="topic-metadata">

**Author:** [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Replies:** 12\
**Last updated:** [April 7, 2017, 6:54am UTC](https://discuss.elastic.co/t/unable-to-create-index/80939 "2017-04-07T06:54:35Z")

</div>

Hi All, I am unable to create index in Kibana dashboard and even deafault index also not showing. Some one please suggest what could be the reason behind this. Please find below screen shot. Regards Raja

---

## [Parsing json file with logstash](https://discuss.elastic.co/t/parsing-json-file-with-logstash/214080)

<div class="topic-metadata">

**Author:** [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Replies:** 11\
**Last updated:** [January 14, 2020, 10:27am UTC](https://discuss.elastic.co/t/parsing-json-file-with-logstash/214080 "2020-01-14T10:27:15Z")

</div>

Happy new year everyone! hoping someone can shed some light on this, i have a weird issue i cant set right with parsing a json file. This is the source json file { "SHA256": "766be5c99ba674f985ce844add4bc5ec423e90811f…

---

## [ES 6.8 vs 7.4 memory issues](https://discuss.elastic.co/t/es-6-8-vs-7-4-memory-issues/202849)

<div class="topic-metadata">

**Author:** [@andrx](https://discuss.elastic.co/u/andrx)\
**Replies:** 11\
**Last updated:** [November 8, 2019, 9:36pm UTC](https://discuss.elastic.co/t/es-6-8-vs-7-4-memory-issues/202849 "2019-11-08T21:36:25Z")

</div>

The following is not a part of aws elasticsearch managed service. I have ES6.8 cluster on m4.2xlarge (32GB RAM) centos7 machines on aws. GET \_cat/nodes?v&s=name ip heap.percent ram.percent cpu load\_1m load\_5m …

---

## [Kubernetes - Filebeat stops sending/picking up logs](https://discuss.elastic.co/t/kubernetes-filebeat-stops-sending-picking-up-logs/128578)

<div class="topic-metadata">

**Author:** [@bitva77](https://discuss.elastic.co/u/bitva77)\
**Replies:** 16\
**Last updated:** [May 29, 2018, 7:31am UTC](https://discuss.elastic.co/t/kubernetes-filebeat-stops-sending-picking-up-logs/128578 "2018-05-29T07:31:32Z")

</div>

Hi! Running Filebeat 6.2.3 in Kubernetes with filebeat.autodiscover. Here's the filebeat.yml ConfigMap: filebeat.yml: |- filebeat.autodiscover: providers: - type: kubernetes in\_cluster: t…

---

## [Elastic search 5.0 java transport client not working](https://discuss.elastic.co/t/elastic-search-5-0-java-transport-client-not-working/66956)

<div class="topic-metadata">

**Author:** [@banu](https://discuss.elastic.co/u/banu)\
**Replies:** 11\
**Last updated:** [November 23, 2016, 1:29pm UTC](https://discuss.elastic.co/t/elastic-search-5-0-java-transport-client-not-working/66956 "2016-11-23T13:29:38Z")

</div>

For the below code. The preBuildTransportClient class asks to two parameters. import org.elasticsearch.client.transport.TransportClient; import org.elasticsearch.common.settings.Settings; import org.elasticsearch.co…

---

## [How can I plot Google map with Long and Lat?](https://discuss.elastic.co/t/how-can-i-plot-google-map-with-long-and-lat/91647)

<div class="topic-metadata">

**Author:** [@patil-akshay](https://discuss.elastic.co/u/patil-akshay)\
**Replies:** 19\
**Last updated:** [July 4, 2017, 8:02am UTC](https://discuss.elastic.co/t/how-can-i-plot-google-map-with-long-and-lat/91647 "2017-07-04T08:02:38Z")

</div>

I have two columns in my data I am loading data directly using bulk API(without logstash) I want to plot the map how can I plot it or else what is format of GEOIP which kibana accepts by default how to convert lat long …

---

## [Elasticsearch Keep Stopping](https://discuss.elastic.co/t/elasticsearch-keep-stopping/306422)

<div class="topic-metadata">

**Author:** [@w0lfxpunk](https://discuss.elastic.co/u/w0lfxpunk)\
**Replies:** 22\
**Last updated:** [June 20, 2022, 3:31pm UTC](https://discuss.elastic.co/t/elasticsearch-keep-stopping/306422 "2022-06-20T15:31:21Z")

</div>

I am running Elasticsearch 8 on a server with 300gb hard drive and 16gb RAM. The Elasticsearch keep stopping in few hours. I tried restarting it using systemctl and got below message ● elasticsearch.service - Elasticse…

---

## [Facing issue while installing filebeat 6.2.4](https://discuss.elastic.co/t/facing-issue-while-installing-filebeat-6-2-4/133536)

<div class="topic-metadata">

**Author:** [@priti](https://discuss.elastic.co/u/priti)\
**Replies:** 10\
**Last updated:** [May 29, 2018, 7:01am UTC](https://discuss.elastic.co/t/facing-issue-while-installing-filebeat-6-2-4/133536 "2018-05-29T07:01:17Z")

</div>

While installing filebeat , i am getting below error. Please help. File C:\\Filebeat\\install-service-filebeat.ps1 cannot be loaded. The file C:\\Filebeat\\install-service-filebeat.ps1 is not digitally signed. You cannot r…

---

## [Kafka.consumer.RangeAssignor: No broker partitions consumed by consumer thread logstash\_logstash-indexer](https://discuss.elastic.co/t/kafka-consumer-rangeassignor-no-broker-partitions-consumed-by-consumer-thread-logstash-logstash-indexer/33012)

<div class="topic-metadata">

**Author:** [@Deb](https://discuss.elastic.co/u/Deb)\
**Replies:** 9\
**Last updated:** [November 5, 2015, 10:31am UTC](https://discuss.elastic.co/t/kafka-consumer-rangeassignor-no-broker-partitions-consumed-by-consumer-thread-logstash-logstash-indexer/33012 "2015-11-05T10:31:13Z")

</div>

I have an ELK Set-up in which a logstash is pushing data to Kafka and another logstash is pulling data from Kafka. Below are my Kafka Input Config:- input { kafka { zk\_connect =\> "kafka:2181" grou…

---

## [Using painless with aggregation results](https://discuss.elastic.co/t/using-painless-with-aggregation-results/115368)

<div class="topic-metadata">

**Author:** [@elkcurious](https://discuss.elastic.co/u/elkcurious)\
**Replies:** 13\
**Last updated:** [February 5, 2018, 7:35pm UTC](https://discuss.elastic.co/t/using-painless-with-aggregation-results/115368 "2018-02-05T19:35:47Z")

</div>

Hi, I am a little new to using painless scripting. I was able to use it in a kibana visualization to convert the units of a field. Also in a query\_and\_update scenario. Now I have a situation/aggregation that does not…

---

## [How to resolve the index missing exception](https://discuss.elastic.co/t/how-to-resolve-the-index-missing-exception/11185)

<div class="topic-metadata">

**Author:** [@Srikanth\_gone](https://discuss.elastic.co/u/Srikanth_gone)\
**Replies:** 10\
**Last updated:** [March 19, 2013, 5:45am UTC](https://discuss.elastic.co/t/how-to-resolve-the-index-missing-exception/11185 "2013-03-19T05:45:29Z")

</div>

Hi All, i have used in windows system to search based on text using elastic search java api..it is working.. when i moved it into linux i am getting index not found exception.. \[dc\_user\_idx\] missing …

---

## [TLS/SSL enabled cluster , SSL is working TSL not working with p12 cert password protected](https://discuss.elastic.co/t/tls-ssl-enabled-cluster-ssl-is-working-tsl-not-working-with-p12-cert-password-protected/157956)

<div class="topic-metadata">

**Author:** [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Replies:** 21\
**Last updated:** [December 2, 2018, 11:02pm UTC](https://discuss.elastic.co/t/tls-ssl-enabled-cluster-ssl-is-working-tsl-not-working-with-p12-cert-password-protected/157956 "2018-12-02T23:02:54Z")

</div>

Hi All , My ES Cluster is 3 maser and 2 data nodes. In my elastic and kibana conf when i am using SSL conf only its working. i can connect from kibana to ES data node with url http://ip:9200 In the same conf if I …

---

## [Visualize:Bad Gateway error for long period searches on Dashboard when using Apache as a reverse proxy \[SOLVED\]](https://discuss.elastic.co/t/visualize-bad-gateway-error-for-long-period-searches-on-dashboard-when-using-apache-as-a-reverse-proxy-solved/34594)

<div class="topic-metadata">

**Author:** [@GustavoHoyer1](https://discuss.elastic.co/u/GustavoHoyer1)\
**Replies:** 11\
**Last updated:** [November 20, 2015, 3:15pm UTC](https://discuss.elastic.co/t/visualize-bad-gateway-error-for-long-period-searches-on-dashboard-when-using-apache-as-a-reverse-proxy-solved/34594 "2015-11-20T15:15:53Z")

</div>

Here's a summary of my environment (ommiting some private info): User -\> Apache (port:443) -\> Kibana (port:5601) -\> Elasticsearch (port:9200) Elasticsearch: { "status" : 200, "version" : { "number" : "1.…

---

## [Problem Couldn't find any Elasticsearch data](https://discuss.elastic.co/t/problem-couldnt-find-any-elasticsearch-data/178798)

<div class="topic-metadata">

**Author:** [@kumar4](https://discuss.elastic.co/u/kumar4)\
**Replies:** 14\
**Last updated:** [April 29, 2019, 7:17pm UTC](https://discuss.elastic.co/t/problem-couldnt-find-any-elasticsearch-data/178798 "2019-04-29T19:17:22Z")

</div>

hi my friend, i installed ealstichsearch, logstach, kibana and filebeat on the same server but my problem is that cant visulaize my data in kibana, when tryin to create an index ig give me an error "Couldn't find any Ela…

---

## [LDAP integrated ELK with Shield](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810)

<div class="topic-metadata">

**Author:** [@vienodp](https://discuss.elastic.co/u/vienodp)\
**Replies:** 25\
**Last updated:** [July 6, 2016, 5:23am UTC](https://discuss.elastic.co/t/ldap-integrated-elk-with-shield/52810 "2016-07-06T05:23:33Z")

</div>

We are configuring ELK Shield plugin. The ELK server is integrated with LDAP server which is working fine. For Kibana, we have used Apache reverse proxy. The problem we are facing is with the configuration of Shield p…

---

## [Timeshift functionality in Elasticsearch](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585)

<div class="topic-metadata">

**Author:** [@trekr5](https://discuss.elastic.co/u/trekr5)\
**Replies:** 9\
**Last updated:** [June 18, 2015, 2:40pm UTC](https://discuss.elastic.co/t/timeshift-functionality-in-elasticsearch/2585 "2015-06-18T14:40:02Z")

</div>

Hello, Is there a way, in Elasticsearch, to compare current values against values in another time period .i.e, finding the current value of status 500 errors against the same value 24 hours ago in order to create a tr…

---

## [.security index not found](https://discuss.elastic.co/t/security-index-not-found/58873)

<div class="topic-metadata">

**Author:** [@piyush](https://discuss.elastic.co/u/piyush)\
**Replies:** 13\
**Last updated:** [August 26, 2016, 5:56pm UTC](https://discuss.elastic.co/t/security-index-not-found/58873 "2016-08-26T17:56:06Z")

</div>

Hi Team, Just now started with shield, Active Directory configurations and AD user authentication got failed. In the trace log i found .security index not found error, PFA snapshot. I created an esuser and it getting …

---

## [Mathematical formula](https://discuss.elastic.co/t/mathematical-formula/54407)

<div class="topic-metadata">

**Author:** [@dkspace](https://discuss.elastic.co/u/dkspace)\
**Replies:** 17\
**Last updated:** [August 5, 2016, 6:56am UTC](https://discuss.elastic.co/t/mathematical-formula/54407 "2016-08-05T06:56:13Z")

</div>

Dear colleagues. i\` have amount of data as float or integer type. But i search how to recalculate some values with some special formula - could you recommend some method for this solution ? Is the some to use some plug…

---

## [Logstash/elasticsearch failed to parse date field tried both date format \[dateOptionalTime\], and timestamp number with locale](https://discuss.elastic.co/t/logstash-elasticsearch-failed-to-parse-date-field-tried-both-date-format-dateoptionaltime-and-timestamp-number-with-locale/48442)

<div class="topic-metadata">

**Author:** [@Dee](https://discuss.elastic.co/u/Dee)\
**Replies:** 9\
**Last updated:** [September 8, 2016, 1:10pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-failed-to-parse-date-field-tried-both-date-format-dateoptionaltime-and-timestamp-number-with-locale/48442 "2016-09-08T13:10:35Z")

</div>

Hi, for some reason, logstash (version 1.5) can't process logs with this exception: {:timestamp=\>"2016-04-26T09:20:12.141000-0400", :message=\>"Failed parsing date from field", :field=\>"time", :value=\>"2016-04-26T09:20…

---

## [How to monitor logstash itself?](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172)

<div class="topic-metadata">

**Author:** [@MichaelScofield](https://discuss.elastic.co/u/MichaelScofield)\
**Replies:** 11\
**Last updated:** [August 14, 2015, 7:44am UTC](https://discuss.elastic.co/t/how-to-monitor-logstash-itself/27172 "2015-08-14T07:44:45Z")

</div>

Are there any tools that can monitor logstash's health? I googled it but found no answers.

---

## [Convert field data type from text to Date](https://discuss.elastic.co/t/convert-field-data-type-from-text-to-date/260781)

<div class="topic-metadata">

**Author:** [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Replies:** 10\
**Last updated:** [January 15, 2021, 6:08am UTC](https://discuss.elastic.co/t/convert-field-data-type-from-text-to-date/260781 "2021-01-15T06:08:30Z")

</div>

Hi All, We have created an index that consists of text data type for all fields, but we need to convert timestamp field from text to date (format "2021-01-12 09:19:25.890") but unable to do. I have tried creating a new…

---

## [How to avoid the calculation for "hits.total" in search?](https://discuss.elastic.co/t/how-to-avoid-the-calculation-for-hits-total-in-search/57644)

<div class="topic-metadata">

**Author:** [@CharlieChen](https://discuss.elastic.co/u/CharlieChen)\
**Replies:** 19\
**Last updated:** [August 11, 2016, 5:23pm UTC](https://discuss.elastic.co/t/how-to-avoid-the-calculation-for-hits-total-in-search/57644 "2016-08-11T17:23:00Z")

</div>

The result of search request has a value of "total", how to disable Elasticsearch to calculate the "hits.total"? The reason is that we have native script filter which is very heavy, we need to avoid unnecessary calculati…

---

## [Simple range query not working, why?](https://discuss.elastic.co/t/simple-range-query-not-working-why/150682)

<div class="topic-metadata">

**Author:** [@Jacob\_Bogers](https://discuss.elastic.co/u/Jacob_Bogers)\
**Replies:** 12\
**Last updated:** [October 2, 2018, 11:41am UTC](https://discuss.elastic.co/t/simple-range-query-not-working-why/150682 "2018-10-02T11:41:39Z")

</div>

i execute this query below, the datas are always formatted in such a way that a simple string comparison str1 \> str2 will return true if the actual date of str1 is larger then str2 \> { \> "query": { \> "bool"…

---

## [Watcher throwing thread pool capacity error](https://discuss.elastic.co/t/watcher-throwing-thread-pool-capacity-error/25211)

<div class="topic-metadata">

**Author:** [@sumithub](https://discuss.elastic.co/u/sumithub)\
**Replies:** 10\
**Last updated:** [September 23, 2015, 7:18am UTC](https://discuss.elastic.co/t/watcher-throwing-thread-pool-capacity-error/25211 "2015-09-23T07:18:48Z")

</div>

Hello Folks, We're running watcher beta version with few watches configured. After running for few days, we started getting "failed to run triggered watch \[someID\] due to thread pool capacity" error which stopped the w…

---

## [Regex query in search field of kibana dashboard](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038)

<div class="topic-metadata">

**Author:** [@Bhavana](https://discuss.elastic.co/u/Bhavana)\
**Replies:** 16\
**Last updated:** [May 10, 2017, 4:14pm UTC](https://discuss.elastic.co/t/regex-query-in-search-field-of-kibana-dashboard/84038 "2017-05-10T16:14:11Z")

</div>

Hello Everyone, I am using a regex query in search field of kibana dashboard. my query is page: "http://www.somename.com/places/" \* result expected: All the extension pages of "http://www.somename.com/places/"…

---

## [File changes not detected after a while](https://discuss.elastic.co/t/file-changes-not-detected-after-a-while/33304)

<div class="topic-metadata">

**Author:** [@jhidalgo](https://discuss.elastic.co/u/jhidalgo)\
**Replies:** 14\
**Last updated:** [November 5, 2015, 9:30am UTC](https://discuss.elastic.co/t/file-changes-not-detected-after-a-while/33304 "2015-11-05T09:30:51Z")

</div>

I am checking the loadbalancer feature, in my test seems like filebeat stalls after a while. I have an elk cluster with 4 LS nodes. I have a loop generating msgs to /var/log/messages constantly, and when I start filebeat…

---

## [Cluster RED, and not recovering](https://discuss.elastic.co/t/cluster-red-and-not-recovering/25675)

<div class="topic-metadata">

**Author:** [@bdunbar](https://discuss.elastic.co/u/bdunbar)\
**Replies:** 17\
**Last updated:** [July 18, 2015, 7:00am UTC](https://discuss.elastic.co/t/cluster-red-and-not-recovering/25675 "2015-07-18T07:00:59Z")

</div>

My cluster is red and it won't get better on it's own. Given the data returned below .. is it getting better? This is the second time this happened, but the first time was when I had no data in the system and starting…

---

## [Logstash monitoring info not showing in kibana](https://discuss.elastic.co/t/logstash-monitoring-info-not-showing-in-kibana/170321)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 17\
**Last updated:** [April 1, 2019, 10:12pm UTC](https://discuss.elastic.co/t/logstash-monitoring-info-not-showing-in-kibana/170321 "2019-04-01T22:12:23Z")

</div>

i am using ELK version 6.5.4. what i did , i changed elastic cluster settings and added as persistent xpack.monitoring.collection.enabled : true i changed logstash.yml file as xpack.monitoring.enabled: true xpack.mo…

---

## [No results in Kibana with metricbeat](https://discuss.elastic.co/t/no-results-in-kibana-with-metricbeat/69590)

<div class="topic-metadata">

**Author:** [@saiterio](https://discuss.elastic.co/u/saiterio)\
**Replies:** 16\
**Last updated:** [January 19, 2017, 11:26am UTC](https://discuss.elastic.co/t/no-results-in-kibana-with-metricbeat/69590 "2017-01-19T11:26:41Z")

</div>

Hi, I'm using Metricbeat 5.1.1 ==\> Elastic Search 5.1.1 ==\> Kibana 5.1.1, I used import\_dashboards script to import metricbeat dashboards in Kibana. All components are installed on the same machine (localhost). When…

---

## [ERR Failed to connect: Connection marked as failed because the onConnect callback failed: Error loading Elasticsearch template: could not load template: couldn't load template: couldn't load json. Error: 400 Bad Request](https://discuss.elastic.co/t/err-failed-to-connect-connection-marked-as-failed-because-the-onconnect-callback-failed-error-loading-elasticsearch-template-could-not-load-template-couldnt-load-template-couldnt-load-json-error-400-bad-request/177071)

<div class="topic-metadata">

**Author:** [@ishu52](https://discuss.elastic.co/u/ishu52)\
**Replies:** 11\
**Last updated:** [April 25, 2019, 7:01am UTC](https://discuss.elastic.co/t/err-failed-to-connect-connection-marked-as-failed-because-the-onconnect-callback-failed-error-loading-elasticsearch-template-could-not-load-template-couldnt-load-template-couldnt-load-json-error-400-bad-request/177071 "2019-04-25T07:01:26Z")

</div>

I get this error when I deploy filebeat. it was tested before with 6.6.1 version and was working fine but now the same yaml is giving this error.

---

## [High rate Remote Syslog into filebeat](https://discuss.elastic.co/t/high-rate-remote-syslog-into-filebeat/33092)

<div class="topic-metadata">

**Author:** [@matt.koivisto](https://discuss.elastic.co/u/matt.koivisto)\
**Replies:** 9\
**Last updated:** [October 29, 2015, 7:35am UTC](https://discuss.elastic.co/t/high-rate-remote-syslog-into-filebeat/33092 "2015-10-29T07:35:40Z")

</div>

I had a setup working, using logstash with udp input and rabbitmq output, to consume a high rate of remote syslog messages and publish it into elastic search (with another logstash instance using rabbitmq as input, and o…

---

## [Filebeat service hangs on first start amazon ec2](https://discuss.elastic.co/t/filebeat-service-hangs-on-first-start-amazon-ec2/46436)

<div class="topic-metadata">

**Author:** [@bmiramont](https://discuss.elastic.co/u/bmiramont)\
**Replies:** 33\
**Last updated:** [May 24, 2016, 7:50am UTC](https://discuss.elastic.co/t/filebeat-service-hangs-on-first-start-amazon-ec2/46436 "2016-05-24T07:50:56Z")

</div>

Hi, I have a java app on elastic beanstalk. I have a ./ebextensions/filebeat.config deployed to my ec2 instances upon EB deployement. Problem is : the first time the filebeat process is started, it hangs. I have to e…

---

## [Can get document by ID but not find it in query all?](https://discuss.elastic.co/t/can-get-document-by-id-but-not-find-it-in-query-all/12531)

<div class="topic-metadata">

**Author:** [@Edward\_Sargisson\_2](https://discuss.elastic.co/u/Edward_Sargisson_2)\
**Replies:** 20\
**Last updated:** [August 7, 2013, 9:44pm UTC](https://discuss.elastic.co/t/can-get-document-by-id-but-not-find-it-in-query-all/12531 "2013-08-07T21:44:11Z")

</div>

Hi all, Why would we be able to find a document by its ID but not see it if we use a q=\*:\* search? Or a search with no criteria. This must be a newbie question because we must be missing something but at the moment…

---

## [Elasticsearch 8 single node replicas 0](https://discuss.elastic.co/t/elasticsearch-8-single-node-replicas-0/299676)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 9\
**Last updated:** [March 28, 2022, 6:45am UTC](https://discuss.elastic.co/t/elasticsearch-8-single-node-replicas-0/299676 "2022-03-28T06:45:26Z")

</div>

I have a single node cluster which is showing yellow because replicas are set to 1 Is there a way to get this setup so that all future indexes have replicas set to 0 This used to be easy with legacy templates curl -XP…

---

## [FileBeat not Creating New Index in Elasticsearch](https://discuss.elastic.co/t/filebeat-not-creating-new-index-in-elasticsearch/134807)

<div class="topic-metadata">

**Author:** [@83500bcd6348a4be6df4](https://discuss.elastic.co/u/83500bcd6348a4be6df4)\
**Replies:** 9\
**Last updated:** [June 7, 2018, 1:01pm UTC](https://discuss.elastic.co/t/filebeat-not-creating-new-index-in-elasticsearch/134807 "2018-06-07T13:01:03Z")

</div>

When I'm Running FileBeat to Send the Log File from path - C:\\ProgramData\\Elastic\\Elasticsearch\\logs\\elasticsearch.log using the following filebeat.yml file filebeat.prospectors: type: log enabled: false paths: …

---

## [Unable to communicate with Fleet Server after Upgrade to 7.14](https://discuss.elastic.co/t/unable-to-communicate-with-fleet-server-after-upgrade-to-7-14/280388)

<div class="topic-metadata">

**Author:** [@thleh](https://discuss.elastic.co/u/thleh)\
**Replies:** 15\
**Last updated:** [August 20, 2021, 7:08am UTC](https://discuss.elastic.co/t/unable-to-communicate-with-fleet-server-after-upgrade-to-7-14/280388 "2021-08-20T07:08:18Z")

</div>

Hi, after Upgrading to 7.14 (elasticsearch and elastic-agent hosting fleet-server) i'm unable to start other elastic-agents version 7.14. 2021-08-04T09:11:32.489+0200 ERROR fleet/fleet\_gateway.go:205 Could not communic…

---

## [\[Solved\] Authorization header isn't being sent on POST](https://discuss.elastic.co/t/solved-authorization-header-isnt-being-sent-on-post/82785)

<div class="topic-metadata">

**Author:** [@Kikketer](https://discuss.elastic.co/u/Kikketer)\
**Replies:** 11\
**Last updated:** [May 18, 2017, 9:05pm UTC](https://discuss.elastic.co/t/solved-authorization-header-isnt-being-sent-on-post/82785 "2017-05-18T21:05:17Z")

</div>

I have a custom app that sends a POST to get some data. I noticed however in my local development (without xpack installed) the Authorization header isn't sent. Here's a bit of code that works (from another plugin but…

---

## [LogStash Stops after a few hours](https://discuss.elastic.co/t/logstash-stops-after-a-few-hours/2249)

<div class="topic-metadata">

**Author:** [@dirtdiver512](https://discuss.elastic.co/u/dirtdiver512)\
**Replies:** 17\
**Last updated:** [July 9, 2015, 6:40pm UTC](https://discuss.elastic.co/t/logstash-stops-after-a-few-hours/2249 "2015-07-09T18:40:10Z")

</div>

All, I have a few devices sending logs to ELK. All are sending based on syslog going to specific ports and being indexed based on the port it goes to. All of it so far is just networking gear such as juniper and cisc…

---

## [Filebeat 1.1.0 exclude lines with only CRLF or LF](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587)

<div class="topic-metadata">

**Author:** [@Steiniche](https://discuss.elastic.co/u/Steiniche)\
**Replies:** 15\
**Last updated:** [May 15, 2017, 5:13pm UTC](https://discuss.elastic.co/t/filebeat-1-1-0-exclude-lines-with-only-crlf-or-lf/41587 "2017-05-15T17:13:56Z")

</div>

Hello, I have been trying to exclude lines which ONLY contains CRLF or LF i.e. empty lines. However, I have not found a solution yet I have tried with exclude\_lines: \["^\\r?\\n$"\] And all the variations I can think of,…

---

## [Unable to install fleet server](https://discuss.elastic.co/t/unable-to-install-fleet-server/282613)

<div class="topic-metadata">

**Author:** [@Dovan](https://discuss.elastic.co/u/Dovan)\
**Replies:** 9\
**Last updated:** [September 1, 2021, 6:57pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-server/282613 "2021-09-01T18:57:07Z")

</div>

I'm trying to install fleet server on my local server (the same where elasticsearch is installed) and I'm not succeeding. I've tried to uninstall and reinstall elastic-agent 7.14 and it doesn't work. the commands and th…

---

## [Maximize read/write throughput](https://discuss.elastic.co/t/maximize-read-write-throughput/194932)

<div class="topic-metadata">

**Author:** [@surilshah](https://discuss.elastic.co/u/surilshah)\
**Replies:** 10\
**Last updated:** [September 3, 2019, 8:14pm UTC](https://discuss.elastic.co/t/maximize-read-write-throughput/194932 "2019-09-03T20:14:04Z")

</div>

We are performing load test on elasticsearch cluster and trying to maximize read/write throughput. Here are the details of our elasticsearch cluster: Master nodes : 3 Data nodes : 6 Indexes : 1 Primary Shards : 2 No o…

---

## [Downgrade kibana version from v7.9 to v7.8](https://discuss.elastic.co/t/downgrade-kibana-version-from-v7-9-to-v7-8/246292)

<div class="topic-metadata">

**Author:** [@FATIMA\_EZZAHRA\_AIT](https://discuss.elastic.co/u/FATIMA_EZZAHRA_AIT)\
**Replies:** 17\
**Last updated:** [August 30, 2020, 2:42pm UTC](https://discuss.elastic.co/t/downgrade-kibana-version-from-v7-9-to-v7-8/246292 "2020-08-30T14:42:34Z")

</div>

Platform: Centos 7 How can I downgrade the current kibana (version 7.9) to a lower version (version 7.8) ? I do not have a backup of the previous version, is it possible to downgrade? and how can I stop kibana to upgr…

---

## [How can i give color to my Data Table/ Metric/ Markdown Widget in Visualization of Kibana](https://discuss.elastic.co/t/how-can-i-give-color-to-my-data-table-metric-markdown-widget-in-visualization-of-kibana/553)

<div class="topic-metadata">

**Author:** [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Replies:** 10\
**Last updated:** [April 7, 2017, 6:21pm UTC](https://discuss.elastic.co/t/how-can-i-give-color-to-my-data-table-metric-markdown-widget-in-visualization-of-kibana/553 "2017-04-07T18:21:35Z")

</div>

How can i give color to my Data Table/ Metric/ Markdown Widget in Visualization of Kibana To make the look and feel of my Kibana Dashbaord cool, i want to give colors to various visualization components. Please let me …

---

## [Elasticsearch doesn’t start: status=1/FAILURE (TLS/x-pack)](https://discuss.elastic.co/t/elasticsearch-doesn-t-start-status-1-failure-tls-x-pack/123498)

<div class="topic-metadata">

**Author:** [@manst](https://discuss.elastic.co/u/manst)\
**Replies:** 16\
**Last updated:** [March 15, 2018, 7:26pm UTC](https://discuss.elastic.co/t/elasticsearch-doesn-t-start-status-1-failure-tls-x-pack/123498 "2018-03-15T19:26:12Z")

</div>

Hello! I've tried to follow this list: Install a single ES node. Install X-Pack on that node. Run setup-passwords on that node. Add additional nodes (ES + X-Pack). Enable TLS for node transport. Enable TLS for HT…

---

## [Kibana APM not showing @CaptureSpan and @CaptureTransaction](https://discuss.elastic.co/t/kibana-apm-not-showing-capturespan-and-capturetransaction/173026)

<div class="topic-metadata">

**Author:** [@ivanqwam](https://discuss.elastic.co/u/ivanqwam)\
**Replies:** 39\
**Last updated:** [April 15, 2019, 3:57pm UTC](https://discuss.elastic.co/t/kibana-apm-not-showing-capturespan-and-capturetransaction/173026 "2019-04-15T15:57:37Z")

</div>

Kibana version 6.5.3: Elasticsearch version 6.5.3: APM Server version 1.4.0: APM Agent language and version 1.4.0 for Java & Tomcat: We installed an APM server and Agent for our java app on Tomcat. We added this to …

[Previous page](https://discuss.elastic.co/top.md?page=33&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=35&per_page=50&period=all)
