# Top

**URL:** https://discuss.elastic.co/top.md?page=37&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 38

---

## [Getting org.elasticsearch.common.util.concurrent.EsRejectedExecutionException](https://discuss.elastic.co/t/getting-org-elasticsearch-common-util-concurrent-esrejectedexecutionexception/27731)

<div class="topic-metadata">

**Author:** [@sohilelasticsearch](https://discuss.elastic.co/u/sohilelasticsearch)\
**Replies:** 19\
**Last updated:** [September 14, 2015, 8:52pm UTC](https://discuss.elastic.co/t/getting-org-elasticsearch-common-util-concurrent-esrejectedexecutionexception/27731 "2015-09-14T20:52:29Z")

</div>

I have done setup of elasticsearch-1.4.2 and import ~150million records from mysql to elasticsearch. Everything was working fine and suddenly after 2 days I was getting below exception, Exception is present at http://p…

---

## [Shard Balancing](https://discuss.elastic.co/t/shard-balancing/6456)

<div class="topic-metadata">

**Author:** [@jjasinek](https://discuss.elastic.co/u/jjasinek)\
**Replies:** 11\
**Last updated:** [May 21, 2012, 9:39pm UTC](https://discuss.elastic.co/t/shard-balancing/6456 "2012-05-21T21:39:32Z")

</div>

While reviewing our ElasticSearch cluster today I noticed that the shards for one of the indexes didn't appear to be evenly balanced across the nodes. After speaking with another developer, we noticed that the total …

---

## [GMT Timezone to CST in logstash](https://discuss.elastic.co/t/gmt-timezone-to-cst-in-logstash/75424)

<div class="topic-metadata">

**Author:** [@abd.wsu](https://discuss.elastic.co/u/abd.wsu)\
**Replies:** 9\
**Last updated:** [February 17, 2017, 3:47pm UTC](https://discuss.elastic.co/t/gmt-timezone-to-cst-in-logstash/75424 "2017-02-17T15:47:58Z")

</div>

Hello, Can anyone help me convert a GMT timezone to CST? I tried some options but haven't had accurate results so far. I have a CSV file that contains fileds like below "Record Type","Record Code","Broker Name","Bro…

---

## [No results found in Kibana](https://discuss.elastic.co/t/no-results-found-in-kibana/47360)

<div class="topic-metadata">

**Author:** [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Replies:** 13\
**Last updated:** [April 29, 2016, 10:52am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360 "2016-04-29T10:52:24Z")

</div>

Hi, I just install all the latest kibana 4.5 / elasticsearch and logstash on a ubuntu server. I'm sending logs from syslog to the server but kibana still say that it can't find results. here is the conf file \[:sli…

---

## [Logstash configtest error..logstash 5.4](https://discuss.elastic.co/t/logstash-configtest-error-logstash-5-4/90437)

<div class="topic-metadata">

**Author:** [@Jonesthomas](https://discuss.elastic.co/u/Jonesthomas)\
**Replies:** 23\
**Last updated:** [June 22, 2017, 11:37am UTC](https://discuss.elastic.co/t/logstash-configtest-error-logstash-5-4/90437 "2017-06-22T11:37:47Z")

</div>

root@dev01:/usr/share/logstash/bin# ./logstash -configtest -e WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuin…

---

## [How can build Kibana 4.2 on windows Machine?](https://discuss.elastic.co/t/how-can-build-kibana-4-2-on-windows-machine/29139)

<div class="topic-metadata">

**Author:** [@Santhosh\_Varala](https://discuss.elastic.co/u/Santhosh_Varala)\
**Replies:** 19\
**Last updated:** [May 9, 2016, 3:12pm UTC](https://discuss.elastic.co/t/how-can-build-kibana-4-2-on-windows-machine/29139 "2016-05-09T15:12:44Z")

</div>

Hi, I want to build Kibana from 4.2 sources on Windows 8.1 machine. But it is giving errors. Please provide the proper steps to prepare the builds. thanks & regards, Santhosh

---

## [Grok Pattern for Apache Error Logs](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582)

<div class="topic-metadata">

**Author:** [@pkshara](https://discuss.elastic.co/u/pkshara)\
**Replies:** 16\
**Last updated:** [September 15, 2017, 1:31pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582 "2017-09-15T13:31:00Z")

</div>

Below is the error log: \[Mon Nov 28 04:38:24 2016\] \[error\] \[client 10.114.34.43\] File does not exist: /fep10/oraapps/appl/fep10comn/portal/FEP10\_j201s648/favicon.ico I had written grok pattern as "message"=\> "\[(?%{DAY…

---

## [Logstash split xml fields](https://discuss.elastic.co/t/logstash-split-xml-fields/89070)

<div class="topic-metadata">

**Author:** [@Makra](https://discuss.elastic.co/u/Makra)\
**Replies:** 21\
**Last updated:** [June 16, 2017, 1:45pm UTC](https://discuss.elastic.co/t/logstash-split-xml-fields/89070 "2017-06-16T13:45:12Z")

</div>

With reference to the xml file from https://discuss.elastic.co/t/logstash-split-event-from-an-xml-file-in-multiples-documents-keeping-information-from-root-tags/59801/9 given at the end I am trying to split the xml tags …

---

## [Run multiple instance of logstash](https://discuss.elastic.co/t/run-multiple-instance-of-logstash/92456)

<div class="topic-metadata">

**Author:** [@karim](https://discuss.elastic.co/u/karim)\
**Replies:** 13\
**Last updated:** [July 13, 2017, 9:14am UTC](https://discuss.elastic.co/t/run-multiple-instance-of-logstash/92456 "2017-07-13T09:14:42Z")

</div>

i have this Error : FATAL logstash.runner - Logstash could not be started because there is already another instance using the configured data directory. If you wish to run multiple instances, you must change the "path.…

---

## [Filebeat vs Logstash](https://discuss.elastic.co/t/filebeat-vs-logstash/127485)

<div class="topic-metadata">

**Author:** [@jawad846](https://discuss.elastic.co/u/jawad846)\
**Replies:** 83\
**Last updated:** [April 16, 2018, 9:33am UTC](https://discuss.elastic.co/t/filebeat-vs-logstash/127485 "2018-04-16T09:33:22Z")

</div>

Please give me the solution for forwarding the log to logstash from filebeat, were the filebeat and logstash are in different VM am getting the error of : 2018-04-10T11:39:05.750Z ERROR pipeline/output.go:74 Failed to …

---

## [How do you install elastic search on Windows?](https://discuss.elastic.co/t/how-do-you-install-elastic-search-on-windows/36050)

<div class="topic-metadata">

**Author:** [@nqioweryuadfge](https://discuss.elastic.co/u/nqioweryuadfge)\
**Replies:** 58\
**Last updated:** [December 8, 2015, 12:43pm UTC](https://discuss.elastic.co/t/how-do-you-install-elastic-search-on-windows/36050 "2015-12-08T12:43:31Z")

</div>

How do you install elastic search on Windows? I already have JDK 1.8.0, and Netbeans 8.0.2 in my computer. Will I need anything else in order to create an Auto complete Grammar checker?

---

## [When using inner\_hits on nested query, we are getting an index\_out\_of\_bounds\_exception](https://discuss.elastic.co/t/when-using-inner-hits-on-nested-query-we-are-getting-an-index-out-of-bounds-exception/89968)

<div class="topic-metadata">

**Author:** [@BLZB0B](https://discuss.elastic.co/u/BLZB0B)\
**Replies:** 18\
**Last updated:** [July 21, 2017, 6:59am UTC](https://discuss.elastic.co/t/when-using-inner-hits-on-nested-query-we-are-getting-an-index-out-of-bounds-exception/89968 "2017-07-21T06:59:41Z")

</div>

Hi, I'm pulling my hair out on this (and I don't have much left to pull out!) We have a set of documents which are replicated to Elastic from Couchbase. We're new to Elastic, so feel free to say "Why are you doing …

---

## [Partial phrase or exact phrase matching](https://discuss.elastic.co/t/partial-phrase-or-exact-phrase-matching/242320)

<div class="topic-metadata">

**Author:** [@bradconor](https://discuss.elastic.co/u/bradconor)\
**Replies:** 9\
**Last updated:** [July 23, 2020, 2:53pm UTC](https://discuss.elastic.co/t/partial-phrase-or-exact-phrase-matching/242320 "2020-07-23T14:53:56Z")

</div>

Hi there, I am new to elasticsearch and I want to search for a phrase. Suppose I query with this phrase : i am new to elasticsearch And I have some data like new to elasticsearch I have tried with match\_phrase but …

---

## [ElasticSearch Unstable](https://discuss.elastic.co/t/elasticsearch-unstable/133566)

<div class="topic-metadata">

**Author:** [@joshsmoore](https://discuss.elastic.co/u/joshsmoore)\
**Replies:** 12\
**Last updated:** [June 6, 2018, 2:08pm UTC](https://discuss.elastic.co/t/elasticsearch-unstable/133566 "2018-06-06T14:08:53Z")

</div>

Hi I have ELK stack setup running on docker swarm. I have 3 VM with 16GB of memory and each one has a ES instance running with 10GB of heap space (version 6.2.3). The problem is that it is unstable. I have turn off swa…

---

## [Gsub replacing \\\\n with \\n](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517)

<div class="topic-metadata">

**Author:** [@saramali](https://discuss.elastic.co/u/saramali)\
**Replies:** 10\
**Last updated:** [July 18, 2018, 4:11pm UTC](https://discuss.elastic.co/t/gsub-replacing-n-with-n/140517 "2018-07-18T16:11:27Z")

</div>

I want to replace '\\\\n' with '\\n' i am using the gsub method but cannot replace ruby { code =\> "@mystring=event.get('stockLines'); @mystring=@mystring.gsub('\\\\n', '\\n');" }

---

## [SQSSNSS3 plugin error queue not valid for endpoint](https://discuss.elastic.co/t/sqssnss3-plugin-error-queue-not-valid-for-endpoint/282685)

<div class="topic-metadata">

**Author:** [@afoster](https://discuss.elastic.co/u/afoster)\
**Replies:** 39\
**Last updated:** [September 16, 2021, 6:14pm UTC](https://discuss.elastic.co/t/sqssnss3-plugin-error-queue-not-valid-for-endpoint/282685 "2021-09-16T18:14:13Z")

</div>

cannot establish connection to amazon SQS the address https://sqs.us-gov-east-1.amazonaws is not valid for this endpoint. is there any options or suggestions to troubleshoot this further

---

## [Could not index event to Elasticsearch. "reason"=\>"if \_id is specified it must not be empty"}](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181)

<div class="topic-metadata">

**Author:** [@tenet\_testuser1](https://discuss.elastic.co/u/tenet_testuser1)\
**Replies:** 10\
**Last updated:** [May 28, 2020, 8:16pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-if-id-is-specified-it-must-not-be-empty/234181 "2020-05-28T20:16:34Z")

</div>

Hello, I have setup a logstash pipeline. It works fine bringing the updates and refreshing the index. However, it throws an error while bringing updates. I am trying to understand the reasons behind. output { elastics…

---

## [Elasticsearch isn't allowed to allocate this shard to any of the nodes in the cluster](https://discuss.elastic.co/t/elasticsearch-isnt-allowed-to-allocate-this-shard-to-any-of-the-nodes-in-the-cluster/319085)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 11\
**Last updated:** [November 17, 2022, 3:14pm UTC](https://discuss.elastic.co/t/elasticsearch-isnt-allowed-to-allocate-this-shard-to-any-of-the-nodes-in-the-cluster/319085 "2022-11-17T15:14:58Z")

</div>

Shards are unassigned s&pretty" { "persistent" : { "cluster.routing.allocation.enable" : "all", "indices.recovery.max\_bytes\_per\_sec" : "50mb" }, "transient" : { "cluster.routing.allocation.enable" : "…

---

## [Inserting a Complex Nested Json from Postgres to Elasticsearch via Logstash](https://discuss.elastic.co/t/inserting-a-complex-nested-json-from-postgres-to-elasticsearch-via-logstash/58405)

<div class="topic-metadata">

**Author:** [@anushav85](https://discuss.elastic.co/u/anushav85)\
**Replies:** 11\
**Last updated:** [November 21, 2016, 6:42pm UTC](https://discuss.elastic.co/t/inserting-a-complex-nested-json-from-postgres-to-elasticsearch-via-logstash/58405 "2016-11-21T18:42:19Z")

</div>

Hi All, I am inserting a table into ES which contains a column that is of type Nested Jsonb (I am converting it to Json while extracting the data) in Postgres. This is my logstash conf file: input { jdbc { …

---

## [Bulk indexing performance](https://discuss.elastic.co/t/bulk-indexing-performance/71278)

<div class="topic-metadata">

**Author:** [@augusto-altman](https://discuss.elastic.co/u/augusto-altman)\
**Replies:** 9\
**Last updated:** [January 13, 2017, 9:57pm UTC](https://discuss.elastic.co/t/bulk-indexing-performance/71278 "2017-01-13T21:57:29Z")

</div>

Hello everybody, We have an indexing process that reads data batches from some datasource and index this data on an Elasticsearch cluster using bulk index requests (let's say one bulk per batch). The data in a same bat…

---

## [List of all kibana apis](https://discuss.elastic.co/t/list-of-all-kibana-apis/43946)

<div class="topic-metadata">

**Author:** [@jstar](https://discuss.elastic.co/u/jstar)\
**Replies:** 11\
**Last updated:** [October 5, 2018, 12:10am UTC](https://discuss.elastic.co/t/list-of-all-kibana-apis/43946 "2018-10-05T00:10:43Z")

</div>

Hi all, I wanted to customized kibana. The ideas is to filter all the apis calls made by kibana which I do not. So I worrying if somebody can help me with the list of all the apis that kibana calls when it connects to…

---

## [Ingest node, what's the deal? It's required ?!](https://discuss.elastic.co/t/ingest-node-whats-the-deal-its-required/79862)

<div class="topic-metadata">

**Author:** [@domisan](https://discuss.elastic.co/u/domisan)\
**Replies:** 9\
**Last updated:** [March 24, 2017, 10:22am UTC](https://discuss.elastic.co/t/ingest-node-whats-the-deal-its-required/79862 "2017-03-24T10:22:22Z")

</div>

Dears, Am I the only one struggling with ELK and ingest nodes since 5.x? Let's consider my simple ELK Test Cluster consisting of 3 nodes. Before I would assign them then the roles of master, data and client. Now, th…

---

## [Geoip is not generate .location](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951)

<div class="topic-metadata">

**Author:** [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)\
**Replies:** 22\
**Last updated:** [July 4, 2017, 7:40am UTC](https://discuss.elastic.co/t/geoip-is-not-generate-location/90951 "2017-07-04T07:40:02Z")

</div>

Good morning, I'm working with ELK for Palo Alto and I wanna to make an update from normal charts to Map Chart. I've read different tutorials but it's not working properly Logstash filter if \[SourceAddress\] and \[Sour…

---

## [Dev Build: Visualization Editor: blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];:](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197)

<div class="topic-metadata">

**Author:** [@eugenefedoto](https://discuss.elastic.co/u/eugenefedoto)\
**Replies:** 9\
**Last updated:** [January 2, 2018, 9:33am UTC](https://discuss.elastic.co/t/dev-build-visualization-editor-blocked-by-forbidden-12-index-read-only-allow-delete-api/110197 "2018-01-02T09:33:28Z")

</div>

I started using the dev build from GitHub. When I try to save a visualization, I get "Visualization Editor: blocked by: \[FORBIDDEN/12/index read-only / allow delete (api)\];: \[cluster\_block\_exception\] blocked by: \[FORBID…

---

## [FIlebeat Alpha latest version ERR Failed to publish events caused by: read tcp](https://discuss.elastic.co/t/filebeat-alpha-latest-version-err-failed-to-publish-events-caused-by-read-tcp/63930)

<div class="topic-metadata">

**Author:** [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Replies:** 14\
**Last updated:** [November 10, 2016, 12:45pm UTC](https://discuss.elastic.co/t/filebeat-alpha-latest-version-err-failed-to-publish-events-caused-by-read-tcp/63930 "2016-11-10T12:45:26Z")

</div>

filebeat can not publish events can some one advice me to proceed further fIlebeat.yml # Deleted actual paths in post filebeat: prospectors: - paths: - /var/log/t.log - /var/log/puppet/puppe…

---

## [Force filebeat resend ONE particular file](https://discuss.elastic.co/t/force-filebeat-resend-one-particular-file/267115)

<div class="topic-metadata">

**Author:** [@notricky](https://discuss.elastic.co/u/notricky)\
**Replies:** 18\
**Last updated:** [April 20, 2021, 10:11am UTC](https://discuss.elastic.co/t/force-filebeat-resend-one-particular-file/267115 "2021-04-20T10:11:09Z")

</div>

How should I force a filebeat to resend just only one particular file. Or how may I drop for only one certain file its offset to force filebeat start processing this one file again? Again, I'm talknig only about one co…

---

## [Logstash not ingesting fast moving log](https://discuss.elastic.co/t/logstash-not-ingesting-fast-moving-log/361807)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 10\
**Last updated:** [June 24, 2024, 2:36am UTC](https://discuss.elastic.co/t/logstash-not-ingesting-fast-moving-log/361807 "2024-06-24T02:36:22Z")

</div>

Hi All, We have a very fast moving/ rolling log file on our Linux server. This log moves very quickly and a job gzips it every hour. I enabled filebeat output to console using the following in filebeat.yml: output.co…

---

## [Load not evenly distributed](https://discuss.elastic.co/t/load-not-evenly-distributed/101343)

<div class="topic-metadata">

**Author:** [@jannesvh](https://discuss.elastic.co/u/jannesvh)\
**Replies:** 19\
**Last updated:** [September 23, 2017, 7:52am UTC](https://discuss.elastic.co/t/load-not-evenly-distributed/101343 "2017-09-23T07:52:04Z")

</div>

Hi, I have a 3+ node setup, with all nodes having all roles. 1 node gets up to 90% cpu and frequent garbage collection 2nd node is a bit less but reasonable and then nodes 3+ are doing nearly nothing. If I stop and sta…

---

## [Logstash Forwarder not supported on AIX - what now?!](https://discuss.elastic.co/t/logstash-forwarder-not-supported-on-aix-what-now/33305)

<div class="topic-metadata">

**Author:** [@jjdepaul](https://discuss.elastic.co/u/jjdepaul)\
**Replies:** 12\
**Last updated:** [October 27, 2016, 8:50am UTC](https://discuss.elastic.co/t/logstash-forwarder-not-supported-on-aix-what-now/33305 "2016-10-27T08:50:06Z")

</div>

I just found out that Logstash Forwarder is not supported on the AIX platform - currently that's our application platform from which we need to source our logs and send them to the ELK stack on a Linux box. Our applica…

---

## [Which is the best (right) use of NGrams?](https://discuss.elastic.co/t/which-is-the-best-right-use-of-ngrams/10825)

<div class="topic-metadata">

**Author:** [@roytmana](https://discuss.elastic.co/u/roytmana)\
**Replies:** 18\
**Last updated:** [February 27, 2013, 7:50pm UTC](https://discuss.elastic.co/t/which-is-the-best-right-use-of-ngrams/10825 "2013-02-27T19:50:40Z")

</div>

Hello, I was reading this group posts and it seems to be two school of thoughts for ngram use 1. index with ngram enabled analyzer but search with analyzer without ngrams so that a complete search terms are mat…

---

## [Question on "Multiple Connections for Logstash High Availability" diagram published in logstash documentation](https://discuss.elastic.co/t/question-on-multiple-connections-for-logstash-high-availability-diagram-published-in-logstash-documentation/29800)

<div class="topic-metadata">

**Author:** [@RajkumarV](https://discuss.elastic.co/u/RajkumarV)\
**Replies:** 9\
**Last updated:** [September 24, 2015, 7:06pm UTC](https://discuss.elastic.co/t/question-on-multiple-connections-for-logstash-high-availability-diagram-published-in-logstash-documentation/29800 "2015-09-24T19:06:15Z")

</div>

Hi Logstash Team Can you explain whether duplicate events or log messages will be processed if we implement the logstash stack as per HA architecture explained in 2nd diagram of "Multiple Connections for Logstash High …

---

## [Dash character in hostnames and filesystem mount points](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790)

<div class="topic-metadata">

**Author:** [@Chris\_Clifton](https://discuss.elastic.co/u/Chris_Clifton)\
**Replies:** 19\
**Last updated:** [March 2, 2016, 8:04am UTC](https://discuss.elastic.co/t/dash-character-in-hostnames-and-filesystem-mount-points/36790 "2016-03-02T08:04:40Z")

</div>

topbeat dashboard seems not to like hostnames with "-" character or in filesystem mount points, there's a warning about "-" not being supported because those fields are analyzed fields. Is there a way to change the topbe…

---

## [ElasticSearch Windows Service 100% CPU](https://discuss.elastic.co/t/elasticsearch-windows-service-100-cpu/101734)

<div class="topic-metadata">

**Author:** [@aleha84](https://discuss.elastic.co/u/aleha84)\
**Replies:** 13\
**Last updated:** [September 26, 2017, 1:12pm UTC](https://discuss.elastic.co/t/elasticsearch-windows-service-100-cpu/101734 "2017-09-26T13:12:01Z")

</div>

Also got similar SO question Using ElasticSearch 5.4.0 as Windows Service. Windows Server 2016 with 16 GB RAM. Installed via command: elasticsearch-service.bat manager Java options: -Xms8g -Xmx8g -XX:+UseConcMarkSwee…

---

## [Delete some snapshots on S3](https://discuss.elastic.co/t/delete-some-snapshots-on-s3/151482)

<div class="topic-metadata">

**Author:** [@dao](https://discuss.elastic.co/u/dao)\
**Replies:** 11\
**Last updated:** [October 15, 2018, 7:45am UTC](https://discuss.elastic.co/t/delete-some-snapshots-on-s3/151482 "2018-10-15T07:45:41Z")

</div>

Hello, I have created a snapshot automation to s3 with a crontab 0 \*/3 \* \* \* curl -XPUT -u elastic:aaaaaa "http://localhost:9200/\_snapshot/s3\_repository/snapshot\_$(date +\\%Y\\%m\\%d\_\\%H)" I can see my S3 billing going u…

---

## [Starting elasticsearch via command line gives weird error](https://discuss.elastic.co/t/starting-elasticsearch-via-command-line-gives-weird-error/77212)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 25\
**Last updated:** [March 5, 2017, 11:18am UTC](https://discuss.elastic.co/t/starting-elasticsearch-via-command-line-gives-weird-error/77212 "2017-03-05T11:18:55Z")

</div>

Hello, I am starting the elasticsearch via command line using the following command: /usr/share/elasticsearch/bin/elasticsearch -d -Edefault.cluster.name=test -Edefault.node.name=test-client-cluster-1 -Edefault.http…

---

## [Pipeline with id \[\] does not exist](https://discuss.elastic.co/t/pipeline-with-id-does-not-exist/259476)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 12\
**Last updated:** [December 26, 2020, 12:53pm UTC](https://discuss.elastic.co/t/pipeline-with-id-does-not-exist/259476 "2020-12-26T12:53:05Z")

</div>

There are few references to this problem already here but none provide resolution, I am getting the below error on 7.6.2 and i do see the pipeline when i run the GET API call { "index" : "xxxxxxxxxx-2020.45-reind…

---

## [TimeTaken by a Cluster State Update Task](https://discuss.elastic.co/t/timetaken-by-a-cluster-state-update-task/28329)

<div class="topic-metadata">

**Author:** [@ananth](https://discuss.elastic.co/u/ananth)\
**Replies:** 11\
**Last updated:** [September 1, 2015, 6:19am UTC](https://discuss.elastic.co/t/timetaken-by-a-cluster-state-update-task/28329 "2015-09-01T06:19:52Z")

</div>

Hi, Last week we had a update in our application which uses node client to communicate Es Cluster. Though we have 15 node clients , we will update one by one). Application update finished in all 15 machines with-in t…

---

## [Connect ssh and access log in logstash](https://discuss.elastic.co/t/connect-ssh-and-access-log-in-logstash/80406)

<div class="topic-metadata">

**Author:** [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Replies:** 10\
**Last updated:** [March 29, 2017, 7:17am UTC](https://discuss.elastic.co/t/connect-ssh-and-access-log-in-logstash/80406 "2017-03-29T07:17:15Z")

</div>

Hi Buddy :slight\_smile: My log is in ssh which have username password port I have ELK pack in my local i want to connect ssh and access log for that I dont know how to configure logstash.conf can you help

---

## [Shard failure during kibana visualisation and 'Discover'](https://discuss.elastic.co/t/shard-failure-during-kibana-visualisation-and-discover/181806)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 9\
**Last updated:** [May 24, 2019, 5:38pm UTC](https://discuss.elastic.co/t/shard-failure-during-kibana-visualisation-and-discover/181806 "2019-05-24T17:38:56Z")

</div>

Hi, I'm upgrading elasticsearch cluster from 5.x to 7.0. I have setup a 7.0.0 cluster and then reindexed data from 5.x cluster. And then exported all the saved objects from old cluster to new one. post this, I'm getti…

---

## [How to read CPU usage, RAM usage and Disk usage using filebeat?](https://discuss.elastic.co/t/how-to-read-cpu-usage-ram-usage-and-disk-usage-using-filebeat/165561)

<div class="topic-metadata">

**Author:** [@Vinit\_Kumar](https://discuss.elastic.co/u/Vinit_Kumar)\
**Replies:** 10\
**Last updated:** [January 24, 2019, 12:30pm UTC](https://discuss.elastic.co/t/how-to-read-cpu-usage-ram-usage-and-disk-usage-using-filebeat/165561 "2019-01-24T12:30:31Z")

</div>

I am using filebeat, ELK stack. I want to get CPU, RAM, and Disk usage information using filebeat and send it to logstash to elasticsearch to kibana. Version of ELK stack is:- filebeat 6.5.4 ELK 5.6.4 Any body have an…

---

## [Cannot retrieve the elasticsearch cloud license, expiry time out of range](https://discuss.elastic.co/t/cannot-retrieve-the-elasticsearch-cloud-license-expiry-time-out-of-range/174361)

<div class="topic-metadata">

**Author:** [@Ben\_Touss](https://discuss.elastic.co/u/Ben_Touss)\
**Replies:** 17\
**Last updated:** [May 9, 2019, 9:49am UTC](https://discuss.elastic.co/t/cannot-retrieve-the-elasticsearch-cloud-license-expiry-time-out-of-range/174361 "2019-05-09T09:49:20Z")

</div>

Hello there, I'm discovering Elastic and I'm trying to setup a filebeat client to read log files and push these log to an Elastic instance. I'm guided by the tutorial from kibana to add a filebeat data source. As expl…

---

## [Tuning filebeat performance, why i can not drive CPU usage close to 100%](https://discuss.elastic.co/t/tuning-filebeat-performance-why-i-can-not-drive-cpu-usage-close-to-100/189891)

<div class="topic-metadata">

**Author:** [@filebeater](https://discuss.elastic.co/u/filebeater)\
**Replies:** 20\
**Last updated:** [August 6, 2019, 11:05am UTC](https://discuss.elastic.co/t/tuning-filebeat-performance-why-i-can-not-drive-cpu-usage-close-to-100/189891 "2019-08-06T11:05:36Z")

</div>

Hello, I tried to tune filebeat performance, as @steffens suggested in one post, i changed the output to console, one thing I find strange is: I allocated 3 cores to filebeat, however, i can only drive the CPU usage to …

---

## [How to include the ctx.payload.value in the email text for watcher alert?](https://discuss.elastic.co/t/how-to-include-the-ctx-payload-value-in-the-email-text-for-watcher-alert/269655)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 23\
**Last updated:** [April 26, 2021, 4:07pm UTC](https://discuss.elastic.co/t/how-to-include-the-ctx-payload-value-in-the-email-text-for-watcher-alert/269655 "2021-04-26T16:07:21Z")

</div>

Hello All, I am trying to create a watcher alert for the servers that communicated to elastic in last 48 hrs but not in last 35 mins. I want to include the ctx.payload.value result in my email text but all I am getting …

---

## [Extracting all values for a term](https://discuss.elastic.co/t/extracting-all-values-for-a-term/4254)

<div class="topic-metadata">

**Author:** [@plaflamme](https://discuss.elastic.co/u/plaflamme)\
**Replies:** 14\
**Last updated:** [April 21, 2011, 11:03am UTC](https://discuss.elastic.co/t/extracting-all-values-for-a-term/4254 "2011-04-21T11:03:53Z")

</div>

Hi, I'm brand new in the elasticsearch world and I have to say I'm quite impressed with its quality. Kudos! One of my use cases is to extract all values (and document ID) of a particular term sorted by document I…

---

## [Eventual consistency of SEARCH on something that I've just indexed](https://discuss.elastic.co/t/eventual-consistency-of-search-on-something-that-ive-just-indexed/48777)

<div class="topic-metadata">

**Author:** [@alienmind](https://discuss.elastic.co/u/alienmind)\
**Replies:** 12\
**Last updated:** [May 23, 2016, 10:57am UTC](https://discuss.elastic.co/t/eventual-consistency-of-search-on-something-that-ive-just-indexed/48777 "2016-05-23T10:57:48Z")

</div>

Hi I've run into a problem where there's a single process accessing ES to search for some documents, do some local calculations and update them in bulk. A few milliseconds later it is (unlikely) but possible that I nee…

---

## [Version conflict, document already exists (current version \[1\])](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 11\
**Last updated:** [May 11, 2023, 8:46pm UTC](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107 "2023-05-11T20:46:01Z")

</div>

I am running metricbeat on few system. sending that data to proxy server. proxy then sends data to two logstash servers logstash then parse this and stores records in Elasticsearch. I am creating my own \_id for each …

---

## [Error Machine Learning in APM with Basic License](https://discuss.elastic.co/t/error-machine-learning-in-apm-with-basic-license/288490)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 10\
**Last updated:** [November 10, 2021, 9:58pm UTC](https://discuss.elastic.co/t/error-machine-learning-in-apm-with-basic-license/288490 "2021-11-10T21:58:50Z")

</div>

Kibana version: 7.15.1 Elasticsearch version: 7.15.1 APM Server version: 7.15.1 APM Agent language and version: NodeJS ^3.17.0 Browser version: Microsoft Edge 95.0.1020.40 Original install method (e.g. download pag…

---

## [Topbeat for JVM metrics monitoring](https://discuss.elastic.co/t/topbeat-for-jvm-metrics-monitoring/38444)

<div class="topic-metadata">

**Author:** [@kushan85](https://discuss.elastic.co/u/kushan85)\
**Replies:** 10\
**Last updated:** [April 13, 2017, 11:04am UTC](https://discuss.elastic.co/t/topbeat-for-jvm-metrics-monitoring/38444 "2017-04-13T11:04:07Z")

</div>

Can we use topbeat for monitoring JVM metrics like heap memory, active threads, garbage collection etc. ?

---

## [Limit of total fields \[1000\] in index has been exceeded particular json's](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-particular-jsons/222627)

<div class="topic-metadata">

**Author:** [@Bahadir\_Eyuboglu](https://discuss.elastic.co/u/Bahadir_Eyuboglu)\
**Replies:** 12\
**Last updated:** [March 17, 2020, 10:00am UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-particular-jsons/222627 "2020-03-17T10:00:26Z")

</div>

I have huge json files, so i split the json files and index them one by one but no matter how smallest the split gets, i get limit total fields exception, Im using elastisearch on python, and i splitthe json objects thr…

---

## [Dynamic Bucket Names or Directories in AWS S3 Output](https://discuss.elastic.co/t/dynamic-bucket-names-or-directories-in-aws-s3-output/2459)

<div class="topic-metadata">

**Author:** [@umutcan](https://discuss.elastic.co/u/umutcan)\
**Replies:** 9\
**Last updated:** [February 15, 2017, 8:57pm UTC](https://discuss.elastic.co/t/dynamic-bucket-names-or-directories-in-aws-s3-output/2459 "2017-02-15T20:57:03Z")

</div>

Hi, I am doing some tests on storing data on AWS S3. I have read the documents and couldn't find a dynamic bucket name or directory option like Elasticsearch output provides in index name. Is there a way to do this? T…

[Previous page](https://discuss.elastic.co/top.md?page=36&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=38&per_page=50&period=all)
