# Top

**URL:** https://discuss.elastic.co/top.md?page=38&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 39

---

## [Filebeat failed to parse JSON with nested object](https://discuss.elastic.co/t/filebeat-failed-to-parse-json-with-nested-object/140209)

<div class="topic-metadata">

**Author:** [@grigory](https://discuss.elastic.co/u/grigory)\
**Replies:** 9\
**Last updated:** [August 12, 2018, 10:17pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-json-with-nested-object/140209 "2018-08-12T22:17:18Z")

</div>

Hi, I am trying to configure Filebeat to parse json logs produced by one of my service. Everything works find if log message has one level properties only. But if I include custom payload(nested object) Filebeat always …

---

## [Filebeat sending the whole log again after stoping and starting filebeat container](https://discuss.elastic.co/t/filebeat-sending-the-whole-log-again-after-stoping-and-starting-filebeat-container/150846)

<div class="topic-metadata">

**Author:** [@elk11](https://discuss.elastic.co/u/elk11)\
**Replies:** 14\
**Last updated:** [October 17, 2018, 10:18am UTC](https://discuss.elastic.co/t/filebeat-sending-the-whole-log-again-after-stoping-and-starting-filebeat-container/150846 "2018-10-17T10:18:57Z")

</div>

Hi, When I stop filebeat container for a while to do some maintenance work on elasticsearch (output) and then start it again, the whole log is being sent again. because of this along with the new info which was written …

---

## [Date parse error](https://discuss.elastic.co/t/date-parse-error/84269)

<div class="topic-metadata">

**Author:** [@Djelouah\_Laala](https://discuss.elastic.co/u/Djelouah_Laala)\
**Replies:** 12\
**Last updated:** [May 3, 2017, 12:18pm UTC](https://discuss.elastic.co/t/date-parse-error/84269 "2017-05-03T12:18:50Z")

</div>

Hi guys, i'm trying to parse a date like this one : 2017-04-29 00:00:00 +0200 I'm using this date filter : filter { date { match =\> \[ "txechecczhier\_date", "yyyy-MM-dd HH:mm:ss Z" \] } } I'm getting a result …

---

## [Limpeza de index](https://discuss.elastic.co/t/limpeza-de-index/270056)

<div class="topic-metadata">

**Author:** [@Fernando\_Oliveira](https://discuss.elastic.co/u/Fernando_Oliveira)\
**Replies:** 18\
**Last updated:** [March 17, 2022, 1:59am UTC](https://discuss.elastic.co/t/limpeza-de-index/270056 "2022-03-17T01:59:47Z")

</div>

Bom dia, sou novo no elastic e utilizo a versão instalada em um servidor linux, tenho a necessidade de liberar espaço em disco consumindo pelo elastic, os arquivos estão sendo gerados em /var/lib/elasticsearch/nodes/0/i…

---

## [Automatic Keywords extraction in ElasticSearch](https://discuss.elastic.co/t/automatic-keywords-extraction-in-elasticsearch/22187)

<div class="topic-metadata">

**Author:** [@Marria](https://discuss.elastic.co/u/Marria)\
**Replies:** 14\
**Last updated:** [February 18, 2015, 1:57pm UTC](https://discuss.elastic.co/t/automatic-keywords-extraction-in-elasticsearch/22187 "2015-02-18T13:57:30Z")

</div>

Hi all, I started using ElasticSearch to index my corpus of PDF files, I succeeded in indexing my PDF files as attachments (base64), my search queries on the content go right but I couldn't find how to extract …

---

## [ES 7.5 translog recovery is extremely slow](https://discuss.elastic.co/t/es-7-5-translog-recovery-is-extremely-slow/215505)

<div class="topic-metadata">

**Author:** [@Jonathan\_Mendenhall](https://discuss.elastic.co/u/Jonathan_Mendenhall)\
**Replies:** 14\
**Last updated:** [January 22, 2020, 2:45am UTC](https://discuss.elastic.co/t/es-7-5-translog-recovery-is-extremely-slow/215505 "2020-01-22T02:45:24Z")

</div>

A sample of the response from the recovery API: "translog" : { "recovered" : 17201, "total" : 4686825, "percent" : "0.4%", "total\_on\_start" : -1, "total\_time\_in\_millis" : 1790702 } This is on an index that is no …

---

## [IOException while reading synonyms\_path\_path: /etc/elasticsearch/C:/elasticsearch-6.2.2/config/synonym.txt](https://discuss.elastic.co/t/ioexception-while-reading-synonyms-path-path-etc-elasticsearch-c-elasticsearch-6-2-2-config-synonym-txt/128629)

<div class="topic-metadata">

**Author:** [@Abhinaw](https://discuss.elastic.co/u/Abhinaw)\
**Replies:** 14\
**Last updated:** [April 24, 2018, 6:02pm UTC](https://discuss.elastic.co/t/ioexception-while-reading-synonyms-path-path-etc-elasticsearch-c-elasticsearch-6-2-2-config-synonym-txt/128629 "2018-04-24T18:02:51Z")

</div>

While trying to restore snapshot in Azure VM. I am facing this issue . { "error": { "root\_cause": \[ { "type": "exception", "reason": "Failed to verify index \[articleinformation/2Sr5kjDzT7WmB…

---

## [How to upload a file into ElastiSearch](https://discuss.elastic.co/t/how-to-upload-a-file-into-elastisearch/243491)

<div class="topic-metadata">

**Author:** [@noor\_basha](https://discuss.elastic.co/u/noor_basha)\
**Replies:** 11\
**Last updated:** [August 9, 2020, 9:35pm UTC](https://discuss.elastic.co/t/how-to-upload-a-file-into-elastisearch/243491 "2020-08-09T21:35:39Z")

</div>

Hi I am new to ELK, I need to upload different types of files into ELASTIC SEARCH, is it possible to do that. if it is anyone can please help me how to do with sample code. As of now, I am doing with reading the file an…

---

## [ODBC connection to elastic](https://discuss.elastic.co/t/odbc-connection-to-elastic/174043)

<div class="topic-metadata">

**Author:** [@sverma](https://discuss.elastic.co/u/sverma)\
**Replies:** 14\
**Last updated:** [April 3, 2019, 12:27am UTC](https://discuss.elastic.co/t/odbc-connection-to-elastic/174043 "2019-04-03T00:27:25Z")

</div>

Hi, installed version details : logstash-6.6.1-1.noarch elasticsearch-6.7.0-1.noarch kibana-6.6.1-1.x86\_64 I am trying to configure a ODBC connection to my elastic node but I get error when setting up the connection…

---

## [Kibana 4 Running ordinary search so so slow](https://discuss.elastic.co/t/kibana-4-running-ordinary-search-so-so-slow/37024)

<div class="topic-metadata">

**Author:** [@shilong](https://discuss.elastic.co/u/shilong)\
**Replies:** 15\
**Last updated:** [November 8, 2016, 12:08pm UTC](https://discuss.elastic.co/t/kibana-4-running-ordinary-search-so-so-slow/37024 "2016-11-08T12:08:48Z")

</div>

Hi is there any one can help me this issue? How come Kibana 4 Running ordinary search so so slow, I use the apache access logs for the raw data, I just search the goolebot and load last 60 days, it actually really tak…

---

## [Filebeat missing files](https://discuss.elastic.co/t/filebeat-missing-files/61028)

<div class="topic-metadata">

**Author:** [@bbach](https://discuss.elastic.co/u/bbach)\
**Replies:** 18\
**Last updated:** [October 6, 2016, 12:17am UTC](https://discuss.elastic.co/t/filebeat-missing-files/61028 "2016-10-06T00:17:11Z")

</div>

Hi, filebeat version 1.3.1 (amd64) logstash 2.3.4 elasticsearch Version: 2.3.5, Build: 90f439f/2016-07-27T10:36:52Z, JVM: 1.8.0\_101 all running on Ubuntu 14.04 I have 40 or so servers feeding application logs wit…

---

## [Configure pfsense to ELK](https://discuss.elastic.co/t/configure-pfsense-to-elk/249360)

<div class="topic-metadata">

**Author:** [@Lusca\_lusca](https://discuss.elastic.co/u/Lusca_lusca)\
**Replies:** 11\
**Last updated:** [October 5, 2020, 6:29pm UTC](https://discuss.elastic.co/t/configure-pfsense-to-elk/249360 "2020-10-05T18:29:26Z")

</div>

Hi I am an intern at an IT company and I have to set up ELK to get logs from pfsense firewall, I am doing it all by myself but I don't have much knowledge about the topic. I am using an Azure server that I acess with my…

---

## [Couchdb\_changes index only doc field from event](https://discuss.elastic.co/t/couchdb-changes-index-only-doc-field-from-event/39223)

<div class="topic-metadata">

**Author:** [@\_alexey\_](https://discuss.elastic.co/u/_alexey_)\
**Replies:** 31\
**Last updated:** [July 9, 2016, 6:41pm UTC](https://discuss.elastic.co/t/couchdb-changes-index-only-doc-field-from-event/39223 "2016-07-09T18:41:14Z")

</div>

Hello Logstash Community! I want to upgrade elasticsearch to newew version and replace couchdb\_river with couchdb\_changes plugin while working this input plugin create events with folowing fields \["doc","doc\_as\_upsert",…

---

## [Can't get a field type IP](https://discuss.elastic.co/t/cant-get-a-field-type-ip/45255)

<div class="topic-metadata">

**Author:** [@johncst](https://discuss.elastic.co/u/johncst)\
**Replies:** 11\
**Last updated:** [March 24, 2016, 8:44pm UTC](https://discuss.elastic.co/t/cant-get-a-field-type-ip/45255 "2016-03-24T20:44:26Z")

</div>

I'm trying to get an IP field so I can then geoip it. I've looked at the blog posts and other sites, and tried everything, but still no working IP fields. I looked at the internal blog posts, and some seem to minimize th…

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232)

<div class="topic-metadata">

**Author:** [@Tybe\_sacha](https://discuss.elastic.co/u/Tybe_sacha)\
**Replies:** 27\
**Last updated:** [November 8, 2023, 2:23pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232 "2023-11-08T14:23:01Z")

</div>

Hi everyone, I'm new here ! :ok\_woman: I just finished set up basic security on my server (1VM with : Elasticsearch, 1 node, Kibana). I ran those commands : ./bin/elasticsearch-keystore add xpack.security.transport.ss…

---

## [Elasticsearch Start up Problem](https://discuss.elastic.co/t/elasticsearch-start-up-problem/51322)

<div class="topic-metadata">

**Author:** [@Arivazhagan\_Vaithili](https://discuss.elastic.co/u/Arivazhagan_Vaithili)\
**Replies:** 16\
**Last updated:** [May 31, 2016, 1:17pm UTC](https://discuss.elastic.co/t/elasticsearch-start-up-problem/51322 "2016-05-31T13:17:58Z")

</div>

Hi, I recently installed Elasticsearch on my server - while starting I'm getting below exception: Exception in thread "main" java.lang.UnsupportedClassVersionError: org/elasticsearch/bootstrap/Elasticsearch : Unsupport…

---

## [Kibana stuck in login loop](https://discuss.elastic.co/t/kibana-stuck-in-login-loop/246101)

<div class="topic-metadata">

**Author:** [@ayushr](https://discuss.elastic.co/u/ayushr)\
**Replies:** 17\
**Last updated:** [August 26, 2020, 9:00am UTC](https://discuss.elastic.co/t/kibana-stuck-in-login-loop/246101 "2020-08-26T09:00:35Z")

</div>

Hi I am using Kibana version 7.5.2 which is linked to my elasticsearch instance. I have created a dashboard of visualizations on Kibana and have embedded the dashboard in a web page that I make available to the users of…

---

## [The timestamp date in kibana is one day less than the date field shown in ES](https://discuss.elastic.co/t/the-timestamp-date-in-kibana-is-one-day-less-than-the-date-field-shown-in-es/82916)

<div class="topic-metadata">

**Author:** [@Bhavana](https://discuss.elastic.co/u/Bhavana)\
**Replies:** 9\
**Last updated:** [April 26, 2017, 2:46pm UTC](https://discuss.elastic.co/t/the-timestamp-date-in-kibana-is-one-day-less-than-the-date-field-shown-in-es/82916 "2017-04-26T14:46:17Z")

</div>

Hello Everyone, I am fetching the date field in ES as timestamp field in kibana. If the date is "2017-01-17" in ES, the same data in kibana the timestamp range is "2017-01-16 00:00:00.00" to "2017-01-16 20:00:00.000" …

---

## [LDAP Authentication Failed](https://discuss.elastic.co/t/ldap-authentication-failed/130558)

<div class="topic-metadata">

**Author:** [@paul1243](https://discuss.elastic.co/u/paul1243)\
**Replies:** 12\
**Last updated:** [May 7, 2018, 10:04am UTC](https://discuss.elastic.co/t/ldap-authentication-failed/130558 "2018-05-07T10:04:18Z")

</div>

Hi, Am trying to get the LDAP authentication using X-pack security feature, I had provided LDAP details and generated the cacert.pem using openssl and mapped it in the elasticsearch.yml, below is my elasticsearch.yml se…

---

## [\[ELK\]logstash default timezone cause index splitting problem in different timezones](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615)

<div class="topic-metadata">

**Author:** [@Weiwei\_Wang](https://discuss.elastic.co/u/Weiwei_Wang)\
**Replies:** 14\
**Last updated:** [April 24, 2017, 7:49am UTC](https://discuss.elastic.co/t/elk-logstash-default-timezone-cause-index-splitting-problem-in-different-timezones/26615 "2017-04-24T07:49:18Z")

</div>

I'm a Chinese developer, our timezone is +08:00，the problem using logstash is that @timestamp is always formatted as @timestamp" =\> "2015-07-25T16:00:30.000Z, the input time is 2015-07-26 00:00:30. This problem will caus…

---

## [Disable monitoring exporters](https://discuss.elastic.co/t/disable-monitoring-exporters/158308)

<div class="topic-metadata">

**Author:** [@saif](https://discuss.elastic.co/u/saif)\
**Replies:** 17\
**Last updated:** [December 10, 2018, 5:33pm UTC](https://discuss.elastic.co/t/disable-monitoring-exporters/158308 "2018-12-10T17:33:49Z")

</div>

Hello, i need to disable monitoring exporters and set the monitoring to default setting GET /\_cluster/settings { "persistent" : { "xpack" : { "monitoring" : { "elasticsearch" : { "collect…

---

## [Logstash CPU utilization is high](https://discuss.elastic.co/t/logstash-cpu-utilization-is-high/132727)

<div class="topic-metadata">

**Author:** [@mamta](https://discuss.elastic.co/u/mamta)\
**Replies:** 39\
**Last updated:** [May 28, 2018, 12:15pm UTC](https://discuss.elastic.co/t/logstash-cpu-utilization-is-high/132727 "2018-05-28T12:15:33Z")

</div>

Hi, I am using logstash 6.2.4 version. When I try to run any conf file at that time CPU utilization is high. So currently there is no conf file is running but still, CPU usages are high. I have attached a screenshot of …

---

## [Cannot restore snapshot, process already running](https://discuss.elastic.co/t/cannot-restore-snapshot-process-already-running/56746)

<div class="topic-metadata">

**Author:** [@snoir](https://discuss.elastic.co/u/snoir)\
**Replies:** 10\
**Last updated:** [August 3, 2016, 12:57pm UTC](https://discuss.elastic.co/t/cannot-restore-snapshot-process-already-running/56746 "2016-08-03T12:57:47Z")

</div>

Hello, We're having some troubles here with our elasticseach cluster. The cluster is made with 10 nodes, under Debian Jessie with elasticsearch 2.3.4 I'm trying to restore an index with the following command, on one …

---

## [Marvel multiple node error](https://discuss.elastic.co/t/marvel-multiple-node-error/38203)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 10\
**Last updated:** [January 6, 2016, 9:55pm UTC](https://discuss.elastic.co/t/marvel-multiple-node-error/38203 "2016-01-06T21:55:11Z")

</div>

i currently have two nodes running. I ran into this issue when trying to start a third but I have errors that is not allowing elasticsearch to start. I tried declaring one of my nodes as master.node : true then I start…

---

## [Converting schema.xml from solr to ES](https://discuss.elastic.co/t/converting-schema-xml-from-solr-to-es/8513)

<div class="topic-metadata">

**Author:** [@Bernd\_Fehling](https://discuss.elastic.co/u/Bernd_Fehling)\
**Replies:** 17\
**Last updated:** [July 29, 2012, 11:32am UTC](https://discuss.elastic.co/t/converting-schema-xml-from-solr-to-es/8513 "2012-07-29T11:32:00Z")

</div>

Is there a guide for converting a schema.xml from solr to ES? e.g. in solr I have a fieldType of class solr.TextField with positionIncrementGap of 100. How is the setting for this in ES? How to set the precision…

---

## [7.3.2 и потеря мастера](https://discuss.elastic.co/t/7-3-2/201228)

<div class="topic-metadata">

**Author:** [@Denis\_Lamanov](https://discuss.elastic.co/u/Denis_Lamanov)\
**Replies:** 72\
**Last updated:** [October 29, 2019, 1:07pm UTC](https://discuss.elastic.co/t/7-3-2/201228 "2019-10-29T13:07:53Z")

</div>

Наконец-то обновились до 7.3.2 с 6.8.2 Индексы поднялись и при минимальной нагрузке одна нода теряет выбранный мастер и соответственно вылетела из кластера через пару минут присоединившись При этом проблем с железом и …

---

## [Json input and splitting](https://discuss.elastic.co/t/json-input-and-splitting/232677)

<div class="topic-metadata">

**Author:** [@tcaetano1995](https://discuss.elastic.co/u/tcaetano1995)\
**Replies:** 11\
**Last updated:** [May 15, 2020, 9:53pm UTC](https://discuss.elastic.co/t/json-input-and-splitting/232677 "2020-05-15T21:53:30Z")

</div>

Hello, I'm new to the elastic ecosystem. I'm trying to use logstash to take a json file as input and then use a filter to split into different events but I'm drowned by all of the info there is online. This is a short…

---

## [Force all the JSON values as String type - Error - Merging dynamic updates triggered a conflict](https://discuss.elastic.co/t/force-all-the-json-values-as-string-type-error-merging-dynamic-updates-triggered-a-conflict/43380)

<div class="topic-metadata">

**Author:** [@Paco\_B](https://discuss.elastic.co/u/Paco_B)\
**Replies:** 11\
**Last updated:** [April 19, 2016, 10:00am UTC](https://discuss.elastic.co/t/force-all-the-json-values-as-string-type-error-merging-dynamic-updates-triggered-a-conflict/43380 "2016-04-19T10:00:32Z")

</div>

Hello, We are trying to store a lot of JSON but ElasticSearch throws the following exception: Merging dynamic updates triggered a conflict: mapper \[our\_type\] of different type, current\_type \[string\], merged\_type \[lon…

---

## [Traces are not shown in Kibana](https://discuss.elastic.co/t/traces-are-not-shown-in-kibana/295757)

<div class="topic-metadata">

**Author:** [@rishisalunkhe](https://discuss.elastic.co/u/rishisalunkhe)\
**Replies:** 30\
**Last updated:** [February 27, 2022, 11:34am UTC](https://discuss.elastic.co/t/traces-are-not-shown-in-kibana/295757 "2022-02-27T11:34:19Z")

</div>

Kibana version: 7.15.2 Elasticsearch version: 7.16.3 APM Server version: 7.16.3 APM Agent language and version: Java 11, agent version: 1.28.4 Browser version: Google chrome 97.0.4692.99 \*\*Description: I am trying t…

---

## [Aggregate multiple records to single chart](https://discuss.elastic.co/t/aggregate-multiple-records-to-single-chart/86561)

<div class="topic-metadata">

**Author:** [@avivc](https://discuss.elastic.co/u/avivc)\
**Replies:** 24\
**Last updated:** [August 8, 2017, 4:49pm UTC](https://discuss.elastic.co/t/aggregate-multiple-records-to-single-chart/86561 "2017-08-08T16:49:12Z")

</div>

Hi, The API I'm using holds nested json data (i.e, base-derived nodes relation) When index it in ES, it's flat-json index What I'm trying to do simply is to aggregate base object with derived object into single chart E…

---

## [Index management and rollover](https://discuss.elastic.co/t/index-management-and-rollover/202226)

<div class="topic-metadata">

**Author:** [@Marcell0e](https://discuss.elastic.co/u/Marcell0e)\
**Replies:** 34\
**Last updated:** [November 8, 2019, 7:37pm UTC](https://discuss.elastic.co/t/index-management-and-rollover/202226 "2019-11-08T19:37:53Z")

</div>

I have setup ILM and everything was going good until the index didn't roll over like I thought it would. I have it set to 30Gbs or 60 days. My first question is do both requirements have to be met before it will roll o…

---

## [Kibana "Fails to load indices" when trying to set up an index pattern in Management tab](https://discuss.elastic.co/t/kibana-fails-to-load-indices-when-trying-to-set-up-an-index-pattern-in-management-tab/173964)

<div class="topic-metadata">

**Author:** [@ljh33txm](https://discuss.elastic.co/u/ljh33txm)\
**Replies:** 17\
**Last updated:** [April 9, 2019, 7:11pm UTC](https://discuss.elastic.co/t/kibana-fails-to-load-indices-when-trying-to-set-up-an-index-pattern-in-management-tab/173964 "2019-04-09T19:11:56Z")

</div>

Hey all, I recently upgraded my elastic stack to 6.6.2 from 5.6.x. I got everything running but when I load into Kibana's Management tab to create my index patterns it says "Failed to load indices". The strange thing i…

---

## [Filebeat and tile map visualization](https://discuss.elastic.co/t/filebeat-and-tile-map-visualization/58969)

<div class="topic-metadata">

**Author:** [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Replies:** 14\
**Last updated:** [September 9, 2016, 5:30am UTC](https://discuss.elastic.co/t/filebeat-and-tile-map-visualization/58969 "2016-09-09T05:30:54Z")

</div>

I'm trying to use Filebeat input to create tile maps of http access. The geoip data are captured, but when I try and create a map, I get the following error: No Compatible Fields: The "filebeat-\*" index pattern does n…

---

## [Check if string is in field](https://discuss.elastic.co/t/check-if-string-is-in-field/269479)

<div class="topic-metadata">

**Author:** [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Replies:** 9\
**Last updated:** [April 7, 2021, 7:20pm UTC](https://discuss.elastic.co/t/check-if-string-is-in-field/269479 "2021-04-07T19:20:18Z")

</div>

Hi, I need some help checking if a string is contained within the value of a field. my json has a key "log.file.path.keyword":\["myfolder/mypath/mylog.log" I tried to parse it with filter{ if "mylog.log" in \[log.file…

---

## [\[Resolved\] Requesting help for a initial indexing for over 30 Million Documents](https://discuss.elastic.co/t/resolved-requesting-help-for-a-initial-indexing-for-over-30-million-documents/37043)

<div class="topic-metadata">

**Author:** [@dominikmank](https://discuss.elastic.co/u/dominikmank)\
**Replies:** 20\
**Last updated:** [December 16, 2015, 1:43pm UTC](https://discuss.elastic.co/t/resolved-requesting-help-for-a-initial-indexing-for-over-30-million-documents/37043 "2015-12-16T13:43:01Z")

</div>

Hey, after a long time of testing and hitting the wall with my head, i decided to ask here in the forum. In our product we want to use Elasticsearch. Basicly, its implemented a long time already (started with version…

---

## [Database en elasticsearch](https://discuss.elastic.co/t/database-en-elasticsearch/66889)

<div class="topic-metadata">

**Author:** [@Diego\_Gomez](https://discuss.elastic.co/u/Diego_Gomez)\
**Replies:** 34\
**Last updated:** [April 17, 2017, 4:10pm UTC](https://discuss.elastic.co/t/database-en-elasticsearch/66889 "2017-04-17T16:10:37Z")

</div>

Buenos Tardes, queria consultarles necesito desde un gateway que recibe informacion y este crea una base de datos la quiero ingresar a elastisearch. Desde el Gateway puedo configurar que grabe en una base de datos extern…

---

## [Esrally run failed for "Cannot find documents-2.json.bz2"](https://discuss.elastic.co/t/esrally-run-failed-for-cannot-find-documents-2-json-bz2/137109)

<div class="topic-metadata">

**Author:** [@Jessica254](https://discuss.elastic.co/u/Jessica254)\
**Replies:** 53\
**Last updated:** [July 17, 2018, 7:33am UTC](https://discuss.elastic.co/t/esrally-run-failed-for-cannot-find-documents-2-json-bz2/137109 "2018-07-17T07:33:43Z")

</div>

it report errors as following: \*\*\*\*\*\* Use this pipeline only if you are aware of the tradeoffs. \*\*\*\*\*\* \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* Watch your step! \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\* \[INFO\] Racing on track \[geonames\], cha…

---

## [Questions about Self Monitoring Systems blog post](https://discuss.elastic.co/t/questions-about-self-monitoring-systems-blog-post/43542)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 18\
**Last updated:** [January 6, 2017, 2:23pm UTC](https://discuss.elastic.co/t/questions-about-self-monitoring-systems-blog-post/43542 "2017-01-06T14:23:14Z")

</div>

I found A case for self monitoring systems | Elastic Blog very interesting. It's very close to what I really want to do here at work. The problem is that that setup relies on Watcher for sending alerts. There's no way we…

---

## [How to parse mix json logs](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594)

<div class="topic-metadata">

**Author:** [@amolp](https://discuss.elastic.co/u/amolp)\
**Replies:** 27\
**Last updated:** [February 25, 2019, 1:59pm UTC](https://discuss.elastic.co/t/how-to-parse-mix-json-logs/167594 "2019-02-25T13:59:54Z")

</div>

hi, i am very new to elk.so i do not know how to parse the mixed json logs here is sample log that i want parse,i getting these logs from filebeat. 2019-02-03 23:51:54,263 | {" MACID":"00009934","ID":"1","SS":"26","FW"…

---

## [ARM support](https://discuss.elastic.co/t/arm-support/142235)

<div class="topic-metadata">

**Author:** [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Replies:** 10\
**Last updated:** [October 2, 2018, 3:07pm UTC](https://discuss.elastic.co/t/arm-support/142235 "2018-10-02T15:07:41Z")

</div>

Has there been any discussion regarding adding official arm64 support for Beats? I feel like this just makes sense since with IoT / sensor data collection you'd want some sort of "lightweight data shipper" to Elasticsear…

---

## [Nodes fail to join cluster after full cluster restart (cluster uuid mismatch?)](https://discuss.elastic.co/t/nodes-fail-to-join-cluster-after-full-cluster-restart-cluster-uuid-mismatch/208290)

<div class="topic-metadata">

**Author:** [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Replies:** 10\
**Last updated:** [November 25, 2019, 7:06pm UTC](https://discuss.elastic.co/t/nodes-fail-to-join-cluster-after-full-cluster-restart-cluster-uuid-mismatch/208290 "2019-11-25T19:06:11Z")

</div>

I was forced to stop all nodes in our cluster and now I can't bring the cluster back up. Looks like the there is a cluster uuid mismatch, but I don't know why this has happened or how to fix it. "type": "server", "times…

---

## [Monitoring csv files in a directory using logstash.conf](https://discuss.elastic.co/t/monitoring-csv-files-in-a-directory-using-logstash-conf/85104)

<div class="topic-metadata">

**Author:** [@sirsyedian](https://discuss.elastic.co/u/sirsyedian)\
**Replies:** 12\
**Last updated:** [May 10, 2017, 3:50pm UTC](https://discuss.elastic.co/t/monitoring-csv-files-in-a-directory-using-logstash-conf/85104 "2017-05-10T15:50:26Z")

</div>

Dear All, I am new to ELK stack and have recently installed logstash, Elasticsearch and Kibana (all version 5.4 on CentOS 6.5). Objective is to monitor a directory for new csv files and parse them using logstash and i…

---

## [Nginx access and error logs show incorroct value in kibana dashboard](https://discuss.elastic.co/t/nginx-access-and-error-logs-show-incorroct-value-in-kibana-dashboard/269453)

<div class="topic-metadata">

**Author:** [@fati](https://discuss.elastic.co/u/fati)\
**Replies:** 22\
**Last updated:** [April 17, 2021, 6:46am UTC](https://discuss.elastic.co/t/nginx-access-and-error-logs-show-incorroct-value-in-kibana-dashboard/269453 "2021-04-17T06:46:42Z")

</div>

I am new in ELK. I have ELK stack 7.12.0 (filebeat -\> logstash -\> elasticsearch cluster -\> kibana) I installed filebeat on nginx server and enabled nginx module. these are my configuration files: filebeat.yml fi…

---

## [\[sincedb creation\]](https://discuss.elastic.co/t/sincedb-creation/34851)

<div class="topic-metadata">

**Author:** [@varun\_kumar1](https://discuss.elastic.co/u/varun_kumar1)\
**Replies:** 32\
**Last updated:** [December 9, 2015, 9:19pm UTC](https://discuss.elastic.co/t/sincedb-creation/34851 "2015-12-09T21:19:02Z")

</div>

I have a following config file for logstasth input { file{ path =\> "D:/Log/\*/\*" } file{ path =\> "D:/Log/\*/MIP/\*" } file{ path =\> "D:/Log/\*/NHGS/\*" } } filter{ mutate{ gsub =\> \["path","D:/Log/", ""\] } …

---

## [Help parsing \[06/Sep/2017:10:57:42 -0400\]](https://discuss.elastic.co/t/help-parsing-06-sep-2017-10-57-42-0400/99622)

<div class="topic-metadata">

**Author:** [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Replies:** 23\
**Last updated:** [September 12, 2017, 7:10pm UTC](https://discuss.elastic.co/t/help-parsing-06-sep-2017-10-57-42-0400/99622 "2017-09-12T19:10:36Z")

</div>

Hello, I am using the following regex to parse out \[06/Sep/2017:10:57:42 -0400\] \[0-9\]{2}/\[A-z\]{3}/\[0-9\]{4}:\[0-9\]{2}:\[0-9\]{2}:\[0-9\]{2} -\[0-9\]{4} I used the HTTPDATE grok, but this is placing my timestamp in a CST timez…

---

## [Elastic agent is unable to enroll to fleet](https://discuss.elastic.co/t/elastic-agent-is-unable-to-enroll-to-fleet/301679)

<div class="topic-metadata">

**Author:** [@spo](https://discuss.elastic.co/u/spo)\
**Replies:** 21\
**Last updated:** [April 12, 2022, 2:59pm UTC](https://discuss.elastic.co/t/elastic-agent-is-unable-to-enroll-to-fleet/301679 "2022-04-12T14:59:21Z")

</div>

Hi I have used this documentation to setup fleet but when I try to do the 2nd step in that document to add elastic agent to the fleet am getting an error 2022-04-05T21:42:01.934Z WARN \[tls\] tlscommon/tl…

---

## [Error: Unknown key for a VALUE\_STRING in \[analyzer\]](https://discuss.elastic.co/t/error-unknown-key-for-a-value-string-in-analyzer/286105)

<div class="topic-metadata">

**Author:** [@Drsaud](https://discuss.elastic.co/u/Drsaud)\
**Replies:** 10\
**Last updated:** [October 10, 2021, 7:37am UTC](https://discuss.elastic.co/t/error-unknown-key-for-a-value-string-in-analyzer/286105 "2021-10-10T07:37:23Z")

</div>

Hi, I'm having this error in postman Unknown key for a VALUE\_STRING in \[analyzer\]. when I search like this: (note I get this after I add the analyzer) { "query": { "terms": { "username": …

---

## [Failed to start Elasticsearch | 'failed' state with result 'signal'](https://discuss.elastic.co/t/failed-to-start-elasticsearch-failed-state-with-result-signal/336849)

<div class="topic-metadata">

**Author:** [@Alex\_BeimDaddeln](https://discuss.elastic.co/u/Alex_BeimDaddeln)\
**Replies:** 12\
**Last updated:** [June 26, 2023, 9:25am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-failed-state-with-result-signal/336849 "2023-06-26T09:25:48Z")

</div>

Today I tried to install Elasticseatch on my new Ubuntu 22.04 server. The setup did not show any error. Nevertheless, at startup always comes this error: -- Support: \*\*\* -- The unit elasticsearch.service completed and…

---

## [Why elasticsearch-5.2.0 throw NullPointerException when start](https://discuss.elastic.co/t/why-elasticsearch-5-2-0-throw-nullpointerexception-when-start/74739)

<div class="topic-metadata">

**Author:** [@xiaodong.hu](https://discuss.elastic.co/u/xiaodong.hu)\
**Replies:** 13\
**Last updated:** [March 4, 2017, 5:20am UTC](https://discuss.elastic.co/t/why-elasticsearch-5-2-0-throw-nullpointerexception-when-start/74739 "2017-03-04T05:20:36Z")

</div>

mr@zdh108:~/elasticsearch-5.2.0/bin\> java -version java version "1.8.0\_121" Java(TM) SE Runtime Environment (build 1.8.0\_121-b13) Java HotSpot(TM) 64-Bit Server VM (build 25.121-b13, mixed mode) mr@zdh108:~/elasticsearc…

---

## [Filters in logstash for ELK](https://discuss.elastic.co/t/filters-in-logstash-for-elk/98995)

<div class="topic-metadata">

**Author:** [@iam.Carrot](https://discuss.elastic.co/u/iam.Carrot)\
**Replies:** 30\
**Last updated:** [September 20, 2017, 4:56am UTC](https://discuss.elastic.co/t/filters-in-logstash-for-elk/98995 "2017-09-20T04:56:00Z")

</div>

Hi, I am relatively new to the ELK stack. I am writing up a logstash fconfig to push my logs to elastic index for kibana. Below is the case scenario: I am using the gork filter with match =\> { “message” =\> “%{COMBINEDA…

[Previous page](https://discuss.elastic.co/top.md?page=37&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=39&per_page=50&period=all)
