# Top

**URL:** https://discuss.elastic.co/top.md?page=35&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 36

---

## [Elasticsearch output plugin does not write to elasticsearch](https://discuss.elastic.co/t/elasticsearch-output-plugin-does-not-write-to-elasticsearch/101401)

<div class="topic-metadata">

**Author:** [@Jeffrey\_Blayney](https://discuss.elastic.co/u/Jeffrey_Blayney)\
**Replies:** 10\
**Last updated:** [September 27, 2017, 7:58pm UTC](https://discuss.elastic.co/t/elasticsearch-output-plugin-does-not-write-to-elasticsearch/101401 "2017-09-27T19:58:17Z")

</div>

Hello! I've just upgraded logstash from 2.2 to 5.5. I have the current version of the elasticsearch output plugin installed (8.8.2) Logstash no longer outputs anything to elasticsearch with the same config file. The on…

---

## [How to parse snapshot .dat file?](https://discuss.elastic.co/t/how-to-parse-snapshot-dat-file/218888)

<div class="topic-metadata">

**Author:** [@Sheraz\_Tariq](https://discuss.elastic.co/u/Sheraz_Tariq)\
**Replies:** 12\
**Last updated:** [February 21, 2020, 1:36pm UTC](https://discuss.elastic.co/t/how-to-parse-snapshot-dat-file/218888 "2020-02-21T13:36:29Z")

</div>

I want to store all of the documents added to shards since the last snapshot to a database table and I don't want to restore an entire cluster for this. I've downloaded the snap-{uuid}.dat, meta-{uuid}.dat and relevant i…

---

## [Is it possible combine two index together in Kibana](https://discuss.elastic.co/t/is-it-possible-combine-two-index-together-in-kibana/246345)

<div class="topic-metadata">

**Author:** [@AKumar123](https://discuss.elastic.co/u/AKumar123)\
**Replies:** 12\
**Last updated:** [August 26, 2020, 2:27pm UTC](https://discuss.elastic.co/t/is-it-possible-combine-two-index-together-in-kibana/246345 "2020-08-26T14:27:44Z")

</div>

I have two index data which i am using in kibana.For that I created Visulazation as well and able to see Data in dashboard. But challange is when i am filtering data for Index1 after clicking on +Button other index data…

---

## [How to restrict fields from csv file using logstash?](https://discuss.elastic.co/t/how-to-restrict-fields-from-csv-file-using-logstash/32643)

<div class="topic-metadata">

**Author:** [@shankar.T](https://discuss.elastic.co/u/shankar.T)\
**Replies:** 12\
**Last updated:** [August 30, 2016, 11:31am UTC](https://discuss.elastic.co/t/how-to-restrict-fields-from-csv-file-using-logstash/32643 "2016-08-30T11:31:47Z")

</div>

For example in csv file i have 100 fields. But i want to load only 10 specific fileds which i needed. How can i achieve this using logstash? Thanks in advance.. Thanks & Regards, Shankarananth.T

---

## [Create Scripted Field using substring before "."](https://discuss.elastic.co/t/create-scripted-field-using-substring-before/238096)

<div class="topic-metadata">

**Author:** [@giacman](https://discuss.elastic.co/u/giacman)\
**Replies:** 10\
**Last updated:** [June 25, 2020, 12:20pm UTC](https://discuss.elastic.co/t/create-scripted-field-using-substring-before/238096 "2020-06-25T12:20:12Z")

</div>

I'm trying to create a Scripted Field for a dashboard in Kibana. My original field is called topic and has the following values, as an example: a b a.c b.f a.c.d b.e.t I would like to build a r…

---

## [Elasticsearch indexing performance: throttle merging](https://discuss.elastic.co/t/elasticsearch-indexing-performance-throttle-merging/71549)

<div class="topic-metadata">

**Author:** [@antonbormotov](https://discuss.elastic.co/u/antonbormotov)\
**Replies:** 9\
**Last updated:** [January 16, 2017, 12:23pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-performance-throttle-merging/71549 "2017-01-16T12:23:15Z")

</div>

We are importing data to elasticsearch cluster in few indices, around ~10gb each. At the same time, we care about search on existing indices, few of them are small-~100mb, few of them are big-~10gb. In order to optimiz…

---

## [Updating document mapping without re-indexing](https://discuss.elastic.co/t/updating-document-mapping-without-re-indexing/63466)

<div class="topic-metadata">

**Author:** [@banu](https://discuss.elastic.co/u/banu)\
**Replies:** 13\
**Last updated:** [October 20, 2016, 10:30am UTC](https://discuss.elastic.co/t/updating-document-mapping-without-re-indexing/63466 "2016-10-20T10:30:37Z")

</div>

I am trying to add copy\_to for the existing index. For Ex: PUT /my\_index { "mappings":{ "my\_type":{ "properties":{ "user\_name":{ "type":"string", "copy\_to":\["key"\], "index":"not\_analyzed", "include\_in\_all":false } } …

---

## [Logstash installation problems Ubuntu 20.04 VM](https://discuss.elastic.co/t/logstash-installation-problems-ubuntu-20-04-vm/235231)

<div class="topic-metadata">

**Author:** [@E\_Anon](https://discuss.elastic.co/u/E_Anon)\
**Replies:** 12\
**Last updated:** [June 13, 2020, 4:09am UTC](https://discuss.elastic.co/t/logstash-installation-problems-ubuntu-20-04-vm/235231 "2020-06-13T04:09:37Z")

</div>

Could someone please walk me through the correct Logstash installation procedure for Ubuntu 20.04? Starting with correct JDK installation as required by Logstash installation. Elasticsearch and Kibana install just fine…

---

## [Upper limit on cluster state](https://discuss.elastic.co/t/upper-limit-on-cluster-state/113816)

<div class="topic-metadata">

**Author:** [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Replies:** 12\
**Last updated:** [January 4, 2018, 4:33am UTC](https://discuss.elastic.co/t/upper-limit-on-cluster-state/113816 "2018-01-04T04:33:25Z")

</div>

I have spent good amount of time reading multiple blogs and documents, both on elasticsearch and other websites to understand the scalability limits of Elasticsearch. It looks like Cluster state is one of the critical d…

---

## [Time Series - Bytes per second as per the user guide?](https://discuss.elastic.co/t/time-series-bytes-per-second-as-per-the-user-guide/86886)

<div class="topic-metadata">

**Author:** [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Replies:** 11\
**Last updated:** [June 14, 2017, 12:10am UTC](https://discuss.elastic.co/t/time-series-bytes-per-second-as-per-the-user-guide/86886 "2017-06-14T00:10:17Z")

</div>

Hi, I'm trying to build a bytes per second graph and metric as per the user guide. https://www.elastic.co/guide/en/kibana/current/\_featured\_visualizations.html However I can't get it working. The sreenshots don't sho…

---

## [Filebeat перестаёт отправлять логи](https://discuss.elastic.co/t/filebeat/200967)

<div class="topic-metadata">

**Author:** [@Axizdkr](https://discuss.elastic.co/u/Axizdkr)\
**Replies:** 28\
**Last updated:** [October 2, 2019, 5:15am UTC](https://discuss.elastic.co/t/filebeat/200967 "2019-10-02T05:15:12Z")

</div>

День добрый. попробую сначала на русском. У меня есть папка в которой хранится большое количетсов фалйов (минимум 300 тысяч). Для этих файлов я сделал отдельный модуль, все записи через этот модуль отправляются на пря…

---

## [Terms lookup mechanism cause too\_many\_clauses exception](https://discuss.elastic.co/t/terms-lookup-mechanism-cause-too-many-clauses-exception/109766)

<div class="topic-metadata">

**Author:** [@xavierfacq](https://discuss.elastic.co/u/xavierfacq)\
**Replies:** 14\
**Last updated:** [December 11, 2017, 3:11pm UTC](https://discuss.elastic.co/t/terms-lookup-mechanism-cause-too-many-clauses-exception/109766 "2017-12-11T15:11:43Z")

</div>

Hi guys, I have a problem with big queries using the Terms lookup mechanism. @see https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-terms-query.html#query-dsl-terms-lookup As we have more and m…

---

## [Not able to join a node in cluster](https://discuss.elastic.co/t/not-able-to-join-a-node-in-cluster/106966)

<div class="topic-metadata">

**Author:** [@rangitgaddam](https://discuss.elastic.co/u/rangitgaddam)\
**Replies:** 14\
**Last updated:** [November 27, 2017, 9:54pm UTC](https://discuss.elastic.co/t/not-able-to-join-a-node-in-cluster/106966 "2017-11-27T21:54:55Z")

</div>

Hi i am not able to join simple data node(running in another server) to existing cluster(master running in another server) with in a network please check my config files below elasticserach.yml(for master node) cluste…

---

## [Fatal error: runtime: cannot map pages in arena address space](https://discuss.elastic.co/t/fatal-error-runtime-cannot-map-pages-in-arena-address-space/51250)

<div class="topic-metadata">

**Author:** [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)\
**Replies:** 26\
**Last updated:** [September 1, 2016, 6:10am UTC](https://discuss.elastic.co/t/fatal-error-runtime-cannot-map-pages-in-arena-address-space/51250 "2016-09-01T06:10:46Z")

</div>

Hi all, I am getting the following error on windows servers, when the filebeat starts. fatal error: runtime: cannot map pages in arena address space Filebeat is 32bit Any idea, how to solve ? Thanks, Ori

---

## [Kibana dashboards Could not locate that index-pattern (id: packetbeat-\*),](https://discuss.elastic.co/t/kibana-dashboards-could-not-locate-that-index-pattern-id-packetbeat/116301)

<div class="topic-metadata">

**Author:** [@kencrozier](https://discuss.elastic.co/u/kencrozier)\
**Replies:** 9\
**Last updated:** [February 14, 2018, 2:43am UTC](https://discuss.elastic.co/t/kibana-dashboards-could-not-locate-that-index-pattern-id-packetbeat/116301 "2018-02-14T02:43:41Z")

</div>

HI, I'm new to ELK so sorry if this is posted in the wrong place. I have a new installation, there are two VM's #1 is running the full stack ELK version 6.1.2 and the indices are created \[root@elkhost bin\]# curl -XGET …

---

## [Mutual tls/ssl on elasticsearch](https://discuss.elastic.co/t/mutual-tls-ssl-on-elasticsearch/252502)

<div class="topic-metadata">

**Author:** [@Daniel\_Schneider](https://discuss.elastic.co/u/Daniel_Schneider)\
**Replies:** 26\
**Last updated:** [October 21, 2020, 10:15am UTC](https://discuss.elastic.co/t/mutual-tls-ssl-on-elasticsearch/252502 "2020-10-21T10:15:13Z")

</div>

Hi I have problem that reminds me topic https://discuss.elastic.co/t/mutual-tls-ssl-on-elasticsearch/197768 I'm trying to set mutual tls/ssl authentication between ES server and CURL client. TLS communication works, ES…

---

## [Leveraging the query parser](https://discuss.elastic.co/t/leveraging-the-query-parser/9277)

<div class="topic-metadata">

**Author:** [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Replies:** 13\
**Last updated:** [October 16, 2012, 7:07am UTC](https://discuss.elastic.co/t/leveraging-the-query-parser/9277 "2012-10-16T07:07:07Z")

</div>

Part of my system accepts strings in the Lucene syntax, which are either single terms "123" or groups "(123 4 3412)". With Lucene, I can use a QueryParser to parse a query string and it would return either a TermQue…

---

## [Grok csv filter](https://discuss.elastic.co/t/grok-csv-filter/108839)

<div class="topic-metadata">

**Author:** [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Replies:** 13\
**Last updated:** [November 24, 2017, 1:00pm UTC](https://discuss.elastic.co/t/grok-csv-filter/108839 "2017-11-24T13:00:07Z")

</div>

Please assist with CSV Filter i tried using columns and Source nothing is happening to my event. csv { source =\> "payData.features" } csv { columns=\> "" } \[csv\]

---

## [How to determine number of master nodes](https://discuss.elastic.co/t/how-to-determine-number-of-master-nodes/309780)

<div class="topic-metadata">

**Author:** [@wisam\_9mol](https://discuss.elastic.co/u/wisam_9mol)\
**Replies:** 10\
**Last updated:** [July 17, 2022, 9:37am UTC](https://discuss.elastic.co/t/how-to-determine-number-of-master-nodes/309780 "2022-07-17T09:37:58Z")

</div>

Is there a way to find out how many master nodes I need for a number of data nodes For example If I have 100 data nodes, how many masters nodes do I need? In the case of 12 data nodes Or 18 data nodes

---

## [As the final mapping would have more than 1 type](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type/129507)

<div class="topic-metadata">

**Author:** [@Jouad\_Mohammed](https://discuss.elastic.co/u/Jouad_Mohammed)\
**Replies:** 10\
**Last updated:** [April 27, 2018, 10:04am UTC](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type/129507 "2018-04-27T10:04:34Z")

</div>

Please with 6.2 how to overcome this issue : reason=Rejecting mapping update to \[stock\] as the final mapping would have more than 1 type: \[CUSTOMER, BRAND\]\]\] Code: IndexRequest request = new IndexRequest(this.getName(…

---

## [401 Unathorized when trying to call the Kibana API](https://discuss.elastic.co/t/401-unathorized-when-trying-to-call-the-kibana-api/263225)

<div class="topic-metadata">

**Author:** [@rbjoergensen](https://discuss.elastic.co/u/rbjoergensen)\
**Replies:** 9\
**Last updated:** [February 22, 2021, 3:35pm UTC](https://discuss.elastic.co/t/401-unathorized-when-trying-to-call-the-kibana-api/263225 "2021-02-22T15:35:48Z")

</div>

I am trying to use a generated API key to export my workpads. However no matter what i do i end up getting a 401 unathorized back from Kibana. This happens even when i use the exact curl command from the documentation h…

---

## [No valid shards](https://discuss.elastic.co/t/no-valid-shards/282344)

<div class="topic-metadata">

**Author:** [@\_bugc4t](https://discuss.elastic.co/u/_bugc4t)\
**Replies:** 9\
**Last updated:** [September 8, 2021, 12:05pm UTC](https://discuss.elastic.co/t/no-valid-shards/282344 "2021-09-08T12:05:20Z")

</div>

I'm having some issues with my index where it won't allocate any shards so I can't create an Index Pattern. I've looked into the Stats on the Index Management page, which gets: "\_shards": { "total": 2, "succes…

---

## [Ordering terms aggregation based on Pipeline metric](https://discuss.elastic.co/t/ordering-terms-aggregation-based-on-pipeline-metric/31839)

<div class="topic-metadata">

**Author:** [@Nick\_Pentreath](https://discuss.elastic.co/u/Nick_Pentreath)\
**Replies:** 10\
**Last updated:** [March 2, 2017, 9:22am UTC](https://discuss.elastic.co/t/ordering-terms-aggregation-based-on-pipeline-metric/31839 "2017-03-02T09:22:44Z")

</div>

Hi, I'm looking into the new pipeline aggregations for computing things like ratios per term bucket (e.g. click-through rate). I can compute the CTR per item using something like this: q = { "query": { …

---

## [Status : "kibana is not working" but it works on browser. Why?](https://discuss.elastic.co/t/status-kibana-is-not-working-but-it-works-on-browser-why/75261)

<div class="topic-metadata">

**Author:** [@tanimoto](https://discuss.elastic.co/u/tanimoto)\
**Replies:** 10\
**Last updated:** [February 17, 2017, 6:51am UTC](https://discuss.elastic.co/t/status-kibana-is-not-working-but-it-works-on-browser-why/75261 "2017-02-17T06:51:26Z")

</div>

I rebooted OS and kibana automatically restarted by demon. I checked status and it says kibana is not working. error log is as below {"type":"log","@timestamp":"2017-02-16T01:58:20Z","tags":\["status","plugin:kibana…

---

## [Error registering plugin, Pipeline aborted due to error (\<TypeError: can't dup Fixnum\>), Failed to execute action](https://discuss.elastic.co/t/error-registering-plugin-pipeline-aborted-due-to-error-typeerror-cant-dup-fixnum-failed-to-execute-action/128987)

<div class="topic-metadata">

**Author:** [@chu](https://discuss.elastic.co/u/chu)\
**Replies:** 10\
**Last updated:** [May 4, 2018, 7:43am UTC](https://discuss.elastic.co/t/error-registering-plugin-pipeline-aborted-due-to-error-typeerror-cant-dup-fixnum-failed-to-execute-action/128987 "2018-05-04T07:43:50Z")

</div>

Hi, everyone: I'm a beginner on ELK and trying to load data from mysql to elasticsearch(for next step i want query them via javarestclient), so i used logstash6.2.4 and elasticsearch6.2.4. and followed a example here. …

---

## [How to get last X documents sorted by a timestamp](https://discuss.elastic.co/t/how-to-get-last-x-documents-sorted-by-a-timestamp/191046)

<div class="topic-metadata">

**Author:** [@jimmyn](https://discuss.elastic.co/u/jimmyn)\
**Replies:** 12\
**Last updated:** [July 20, 2019, 8:26am UTC](https://discuss.elastic.co/t/how-to-get-last-x-documents-sorted-by-a-timestamp/191046 "2019-07-20T08:26:47Z")

</div>

I have a huge set of email events of different types e.g. sent, delivered, complaint, bounced etc. My goal is: get the last 10k sent events sorted by a timestamp find the timestamp of the earliest event in this subset …

---

## [Number of replicas automatically reset to 1](https://discuss.elastic.co/t/number-of-replicas-automatically-reset-to-1/129905)

<div class="topic-metadata">

**Author:** [@Antoine\_Garrido](https://discuss.elastic.co/u/Antoine_Garrido)\
**Replies:** 35\
**Last updated:** [May 9, 2018, 10:40am UTC](https://discuss.elastic.co/t/number-of-replicas-automatically-reset-to-1/129905 "2018-05-09T10:40:07Z")

</div>

Hi, I got a problem but don't know how to solve it. I have installed elasticsearch 5 on my server. And created manually my index 'coloc'. It is a single node cluster so i set the number of replicas to 0. But when i la…

---

## [The number of master node of Elasticsearch is only one?](https://discuss.elastic.co/t/the-number-of-master-node-of-elasticsearch-is-only-one/55817)

<div class="topic-metadata">

**Author:** [@Suzuki\_Keita](https://discuss.elastic.co/u/Suzuki_Keita)\
**Replies:** 11\
**Last updated:** [July 19, 2016, 5:24am UTC](https://discuss.elastic.co/t/the-number-of-master-node-of-elasticsearch-is-only-one/55817 "2016-07-19T05:24:40Z")

</div>

discovery.zen.minimum\_master\_nodes: 2 Nodes of the cluster in the three , the minimum number of master nodes is set to two . But look at the cluster, the master node has become to one . Maybe elasticsearch-head of th…

---

## [Document Level Permissions Filtering](https://discuss.elastic.co/t/document-level-permissions-filtering/7085)

<div class="topic-metadata">

**Author:** [@richardwhatever](https://discuss.elastic.co/u/richardwhatever)\
**Replies:** 18\
**Last updated:** [June 26, 2016, 7:15pm UTC](https://discuss.elastic.co/t/document-level-permissions-filtering/7085 "2016-06-26T19:15:40Z")

</div>

Hi, I'm looking for a search engine that provides document level access / filtering. I had looked at ManifoldCF with Solr as one option. Does elasticsearch offer this kind of functionality? I need to be able to …

---

## [Filebeat on Windows seem to not use the registry file](https://discuss.elastic.co/t/filebeat-on-windows-seem-to-not-use-the-registry-file/76241)

<div class="topic-metadata">

**Author:** [@Steiniche](https://discuss.elastic.co/u/Steiniche)\
**Replies:** 12\
**Last updated:** [March 20, 2017, 8:52am UTC](https://discuss.elastic.co/t/filebeat-on-windows-seem-to-not-use-the-registry-file/76241 "2017-03-20T08:52:39Z")

</div>

Hello, We have just migrated to Elastic Stack 5.2. Filebeat version 5.2.1 We have filebeats running on Windows Server 2012 R2 and every time the filebeat service is restart all lines from all harvested logs gets se…

---

## [Installation in error \[Solved\]](https://discuss.elastic.co/t/installation-in-error-solved/81977)

<div class="topic-metadata">

**Author:** [@rlatrasse45](https://discuss.elastic.co/u/rlatrasse45)\
**Replies:** 9\
**Last updated:** [April 12, 2017, 12:18pm UTC](https://discuss.elastic.co/t/installation-in-error-solved/81977 "2017-04-12T12:18:06Z")

</div>

Hey, I want install elasticsearch on my server (Linux RHEL-6Server-6.6.0.2.el6.x86\_64) with jdk1.8.0\_112 but I always the same error. I try with the latest version of jdk (1.8.0.121) but the result is the same. \[elas…

---

## [Winlogbeat and User sessions (parsing fields from message)](https://discuss.elastic.co/t/winlogbeat-and-user-sessions-parsing-fields-from-message/43003)

<div class="topic-metadata">

**Author:** [@matthieurobin](https://discuss.elastic.co/u/matthieurobin)\
**Replies:** 9\
**Last updated:** [March 21, 2016, 2:47pm UTC](https://discuss.elastic.co/t/winlogbeat-and-user-sessions-parsing-fields-from-message/43003 "2016-03-21T14:47:04Z")

</div>

Hello, I have installed winlogbeat on my Windows server, and it works fine, I have all data. Unfortunately, I would like to have the count of user logon and logoff and there arent' the data corresponding. All informat…

---

## [Logstash not start after upgrade to new version](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849)

<div class="topic-metadata">

**Author:** [@Alexander\_Popov](https://discuss.elastic.co/u/Alexander_Popov)\
**Replies:** 9\
**Last updated:** [December 30, 2021, 4:48pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849 "2021-12-30T16:48:35Z")

</div>

was 7.10.2, upgrade to 7.16.1 but it not start: 21-12-14T17:31:17,721\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<LogStash::ConfigurationError: Could not connect to a co…

---

## [Query string containing the "/" (forward slash) raises the error "Cannot parse ... Encountered: \<EOF\>"](https://discuss.elastic.co/t/query-string-containing-the-forward-slash-raises-the-error-cannot-parse-encountered-eof/226645)

<div class="topic-metadata">

**Author:** [@Josip\_Cagalj](https://discuss.elastic.co/u/Josip_Cagalj)\
**Replies:** 9\
**Last updated:** [April 8, 2020, 1:41pm UTC](https://discuss.elastic.co/t/query-string-containing-the-forward-slash-raises-the-error-cannot-parse-encountered-eof/226645 "2020-04-08T13:41:37Z")

</div>

Hi, I'm encountering the above-mentioned error when I'm searching for a document using: "query\_string": { "default\_field": "innerId.txt", "query": "XMT01/195077567" } I'm getting the parse exception error "Cann…

---

## [Filebeat writing to its own index](https://discuss.elastic.co/t/filebeat-writing-to-its-own-index/310842)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 48\
**Last updated:** [August 5, 2022, 3:24pm UTC](https://discuss.elastic.co/t/filebeat-writing-to-its-own-index/310842 "2022-08-05T15:24:51Z")

</div>

\###################### Filebeat Configuration ######################### # You can find the full configuration reference here: # https://www.elastic.co/guide/en/beats/filebeat/index.html #===========================…

---

## [How to configure Elasticsearch output](https://discuss.elastic.co/t/how-to-configure-elasticsearch-output/173291)

<div class="topic-metadata">

**Author:** [@nagr](https://discuss.elastic.co/u/nagr)\
**Replies:** 9\
**Last updated:** [March 21, 2019, 3:03pm UTC](https://discuss.elastic.co/t/how-to-configure-elasticsearch-output/173291 "2019-03-21T15:03:11Z")

</div>

Hi All, I am trying to load the log data over logstash to elasticsearch, so i have done the below steps, installed filebeat and configured "filebeat.yml" --\> like below #----------------------------- Logstash output …

---

## [Problem communicating within nodes in cluster - send message failed, node gets removed from cluster](https://discuss.elastic.co/t/problem-communicating-within-nodes-in-cluster-send-message-failed-node-gets-removed-from-cluster/156736)

<div class="topic-metadata">

**Author:** [@elco\_comm1982](https://discuss.elastic.co/u/elco_comm1982)\
**Replies:** 10\
**Last updated:** [November 19, 2018, 7:48pm UTC](https://discuss.elastic.co/t/problem-communicating-within-nodes-in-cluster-send-message-failed-node-gets-removed-from-cluster/156736 "2018-11-19T19:48:39Z")

</div>

Hi, We keep seeing this issue intermittently in our cluster.. After the message failed error comes, the node gets removed from the cluster and the cluster state goes into red.. Immediately afterwards, the node gets ad…

---

## [Парсинг логов в Logstash с помощью grok](https://discuss.elastic.co/t/logstash-grok/155037)

<div class="topic-metadata">

**Author:** [@artem33region](https://discuss.elastic.co/u/artem33region)\
**Replies:** 23\
**Last updated:** [November 7, 2018, 6:56am UTC](https://discuss.elastic.co/t/logstash-grok/155037 "2018-11-07T06:56:55Z")

</div>

Всем привет, пытаюсь в grok debugger распарсить лог, и впринципе все получается, но... Есть лог: "11/01/2018 11:41:36","767","\<8F753F80AA7E5221FDF8B1086CD4FC58@domain.ru\>","info@domain.ru","ma@domain.ru","",\*\*"Аудиокни…

---

## [ES is getting killed :(](https://discuss.elastic.co/t/es-is-getting-killed/279354)

<div class="topic-metadata">

**Author:** [@kamal\_khushi](https://discuss.elastic.co/u/kamal_khushi)\
**Replies:** 13\
**Last updated:** [July 26, 2021, 11:39am UTC](https://discuss.elastic.co/t/es-is-getting-killed/279354 "2021-07-26T11:39:12Z")

</div>

OS:-ubuntu ram:-16gb Storage:-500GB CPU:-i5 10th gen i have Cloned ES in two different directory : Es1 Es2 Then first i launched Es1/bin/elastisearch And next i launched Es2/bin/elastisearch while Es2 is launchi…

---

## [Filebeat Not harvesting, file didn't change - do not use modification time](https://discuss.elastic.co/t/filebeat-not-harvesting-file-didnt-change-do-not-use-modification-time/49834)

<div class="topic-metadata">

**Author:** [@wmcdonald](https://discuss.elastic.co/u/wmcdonald)\
**Replies:** 10\
**Last updated:** [June 13, 2016, 6:57am UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-file-didnt-change-do-not-use-modification-time/49834 "2016-06-13T06:57:59Z")

</div>

My understanding is that filebeat will look at the modification timestamp provided by the OS to determine if the file has been modified and then the harvester will try and read from where it left off, correct? There is…

---

## [Watcher: Error 500 Internal Server Error: An internal server error occurred](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 10\
**Last updated:** [December 12, 2017, 2:33pm UTC](https://discuss.elastic.co/t/watcher-error-500-internal-server-error-an-internal-server-error-occurred/109624 "2017-12-12T14:33:29Z")

</div>

Hi there, I have just installed the 6.0 update and when navigating to my watchers I am receiving an internal server error, does anybody know a fix for this? Or any possible reasons why I might be receiving this error? T…

---

## [Kibana 5.0 - Step back?](https://discuss.elastic.co/t/kibana-5-0-step-back/66019)

<div class="topic-metadata">

**Author:** [@Nadir](https://discuss.elastic.co/u/Nadir)\
**Replies:** 10\
**Last updated:** [November 30, 2016, 4:43am UTC](https://discuss.elastic.co/t/kibana-5-0-step-back/66019 "2016-11-30T04:43:24Z")

</div>

Hi ! In so many YouTube videos about Kibana I see very nice dashboards. Line Charts with a grid in the background, Pie and donut charts with values and spark charts. Clean panels with a border and a very structured des…

---

## [Metricbeat CPU Visualization missing](https://discuss.elastic.co/t/metricbeat-cpu-visualization-missing/127466)

<div class="topic-metadata">

**Author:** [@t03r1cht](https://discuss.elastic.co/u/t03r1cht)\
**Replies:** 13\
**Last updated:** [April 25, 2018, 8:14am UTC](https://discuss.elastic.co/t/metricbeat-cpu-visualization-missing/127466 "2018-04-25T08:14:00Z")

</div>

I'm trying to setup Metricbeat, unfortunately not much data is being visualized. \[Screenshot\_44\] I am mostly interested in the CPU usage. I am using the example configuration presented at Step 2: Configure Metricbeat. …

---

## [Where cluster metadata is stored?](https://discuss.elastic.co/t/where-cluster-metadata-is-stored/44540)

<div class="topic-metadata">

**Author:** [@haizaar](https://discuss.elastic.co/u/haizaar)\
**Replies:** 12\
**Last updated:** [July 17, 2016, 11:18am UTC](https://discuss.elastic.co/t/where-cluster-metadata-is-stored/44540 "2016-07-17T11:18:49Z")

</div>

I have a ES 2.2.x cluster with dedicated data, master and client nodes. Master nodes manage the cluster metadata, but where do they persist it? (i.e. where is it stored if I gracefully shutdown all of the nodes) Thanks…

---

## [Could not open job because no ML nodes with sufficient capacity were found](https://discuss.elastic.co/t/could-not-open-job-because-no-ml-nodes-with-sufficient-capacity-were-found/146882)

<div class="topic-metadata">

**Author:** [@sesha](https://discuss.elastic.co/u/sesha)\
**Replies:** 15\
**Last updated:** [September 15, 2018, 8:21pm UTC](https://discuss.elastic.co/t/could-not-open-job-because-no-ml-nodes-with-sufficient-capacity-were-found/146882 "2018-09-15T20:21:54Z")

</div>

I have dedicated ml node with 64 GB memory, 10 CPU. I am using x-pack 6.4 with small index 900mb data, Right now I can able to run 199 Jobs, but need to run more jobs, but have more remaining RAM nearly 40 GB RAM. Initi…

---

## [Install Elasticsearch Service in Windows](https://discuss.elastic.co/t/install-elasticsearch-service-in-windows/80814)

<div class="topic-metadata">

**Author:** [@kiarash](https://discuss.elastic.co/u/kiarash)\
**Replies:** 12\
**Last updated:** [April 20, 2017, 11:26am UTC](https://discuss.elastic.co/t/install-elasticsearch-service-in-windows/80814 "2017-04-20T11:26:02Z")

</div>

Elasticsearch service can not install in windows, When I run blow command: .\\elasticsearch-service.bat install This output displayed in the command prompt: C:\\Users\\Kiarash\\Desktop\\elasticsearch\\bin\>.\\elasticsearch…

---

## [Elasticsearch authentication failed error](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952)

<div class="topic-metadata">

**Author:** [@ajoealex](https://discuss.elastic.co/u/ajoealex)\
**Replies:** 11\
**Last updated:** [July 22, 2016, 5:48am UTC](https://discuss.elastic.co/t/elasticsearch-authentication-failed-error/52952 "2016-07-22T05:48:29Z")

</div>

I am using elasticsearch 2.3.3 , kibana 4.5 and shield for both. I set up everything in kibana.yml My kibana.yml file is pasted below. I am getting an error while running kibana.bat log \[22:22:16.344\] \[error\]\[status…

---

## [Superuser unable to manage xpack security](https://discuss.elastic.co/t/superuser-unable-to-manage-xpack-security/124755)

<div class="topic-metadata">

**Author:** [@annk](https://discuss.elastic.co/u/annk)\
**Replies:** 13\
**Last updated:** [March 26, 2018, 11:54am UTC](https://discuss.elastic.co/t/superuser-unable-to-manage-xpack-security/124755 "2018-03-26T11:54:29Z")

</div>

I lost the elastic user password since I activated x-pack , I created a new superuser called admin /bin/x-pack/users list admin : superuser now when I access the kibana -\> management -\> security -\> Roles / User…

---

## [Fail to start kibana, the kibana.pid file not accessable](https://discuss.elastic.co/t/fail-to-start-kibana-the-kibana-pid-file-not-accessable/92983)

<div class="topic-metadata">

**Author:** [@jjuu](https://discuss.elastic.co/u/jjuu)\
**Replies:** 9\
**Last updated:** [July 31, 2017, 7:01am UTC](https://discuss.elastic.co/t/fail-to-start-kibana-the-kibana-pid-file-not-accessable/92983 "2017-07-31T07:01:46Z")

</div>

I installed kibana in AWS EC2 instance. It has problem to start. The kibana.pid is in /var/run/. I have changed the mode of the directory to 777. ll -d /var/run lrwxrwxrwx 1 root root 4 Jun 19 23:49 /var/run -\> /run/ l…

---

## [Filebeat 6.x could not support running under OS alpine](https://discuss.elastic.co/t/filebeat-6-x-could-not-support-running-under-os-alpine/116195)

<div class="topic-metadata">

**Author:** [@lauea](https://discuss.elastic.co/u/lauea)\
**Replies:** 11\
**Last updated:** [January 25, 2018, 1:04am UTC](https://discuss.elastic.co/t/filebeat-6-x-could-not-support-running-under-os-alpine/116195 "2018-01-25T01:04:15Z")

</div>

Hi guys, During filebeat 5.x, I built a very tiny weight docker image for filebeat with alpine. But for filebeat 6.x later, seems not support running based OS alpine. Anyone advise? Thanks.

[Previous page](https://discuss.elastic.co/top.md?page=34&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=36&per_page=50&period=all)
