# Top

**URL:** https://discuss.elastic.co/top.md?page=39&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 40

---

## [Elasticsearch java Rest High level Client](https://discuss.elastic.co/t/elasticsearch-java-rest-high-level-client/171669)

<div class="topic-metadata">

**Author:** [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Replies:** 27\
**Last updated:** [March 14, 2019, 10:18am UTC](https://discuss.elastic.co/t/elasticsearch-java-rest-high-level-client/171669 "2019-03-14T10:18:17Z")

</div>

Hi All, I am using Elasticsearch java High Level Client to connect with my local Elasticsearch to fetch data In Kibana DSL i used sql query to fetch data from my elasticsearch, likewise i need to use sql query in java H…

---

## [ES 6.8.2 on Mac OS 14.0.6 and Java JDK 12.0.2 ERROR](https://discuss.elastic.co/t/es-6-8-2-on-mac-os-14-0-6-and-java-jdk-12-0-2-error/195852)

<div class="topic-metadata">

**Author:** [@Mike\_Fritzsche](https://discuss.elastic.co/u/Mike_Fritzsche)\
**Replies:** 19\
**Last updated:** [August 22, 2019, 12:59pm UTC](https://discuss.elastic.co/t/es-6-8-2-on-mac-os-14-0-6-and-java-jdk-12-0-2-error/195852 "2019-08-22T12:59:50Z")

</div>

I installed on my Mac OS 14.0.6 Elasticsearch with brew. It must be ES V 6 - not 7. But I tied to install 7 too - same error. So must be problem with the jdk? After installation was running well, I start with command ela…

---

## [Delete old logs](https://discuss.elastic.co/t/delete-old-logs/245268)

<div class="topic-metadata">

**Author:** [@headtea](https://discuss.elastic.co/u/headtea)\
**Replies:** 13\
**Last updated:** [August 20, 2020, 7:30am UTC](https://discuss.elastic.co/t/delete-old-logs/245268 "2020-08-20T07:30:50Z")

</div>

Is it possible to have logs older than 3 month deleted? Or set a size limit? Is it possible to do so from Kibana? Thanks ahead!

---

## [CSV field from string to Date](https://discuss.elastic.co/t/csv-field-from-string-to-date/112069)

<div class="topic-metadata">

**Author:** [@Sridhar](https://discuss.elastic.co/u/Sridhar)\
**Replies:** 12\
**Last updated:** [December 22, 2017, 6:20am UTC](https://discuss.elastic.co/t/csv-field-from-string-to-date/112069 "2017-12-22T06:20:53Z")

</div>

Hi, I have to convert the Run\_date of the CSV file as date but its populating as string. Please help me..!! Sample CSV file; 30-NOV-17,GH,381,CUSTOMERS 30-NOV-17,GH,50047,TRANSACTIONS 30-NOV-17,IQ,0,TRANSACTIONS 30…

---

## [Data can not be indexed](https://discuss.elastic.co/t/data-can-not-be-indexed/137470)

<div class="topic-metadata">

**Author:** [@Yong\_Rhee](https://discuss.elastic.co/u/Yong_Rhee)\
**Replies:** 14\
**Last updated:** [August 24, 2018, 7:17pm UTC](https://discuss.elastic.co/t/data-can-not-be-indexed/137470 "2018-08-24T19:17:05Z")

</div>

I am trying to play with toy data example from the book. I can not load data because of the following problem. \[2018-06-26T11:58:16,824\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch. {:s…

---

## [Logstash Conf Error For Tweet](https://discuss.elastic.co/t/logstash-conf-error-for-tweet/49086)

<div class="topic-metadata">

**Author:** [@teatone](https://discuss.elastic.co/u/teatone)\
**Replies:** 30\
**Last updated:** [May 9, 2016, 11:23am UTC](https://discuss.elastic.co/t/logstash-conf-error-for-tweet/49086 "2016-05-09T11:23:22Z")

</div>

Hi, I'm trying to do this . But when i wrote all configurations and restart logstash. This error appears "Configuration error. Not restarting. Re-run with configtest parameter for details" . I tryied to find out this …

---

## [Json input - calculated with derived values like unique-count](https://discuss.elastic.co/t/json-input-calculated-with-derived-values-like-unique-count/121116)

<div class="topic-metadata">

**Author:** [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Replies:** 10\
**Last updated:** [February 23, 2018, 4:36pm UTC](https://discuss.elastic.co/t/json-input-calculated-with-derived-values-like-unique-count/121116 "2018-02-23T16:36:46Z")

</div>

Hi, I know how to use json input to display a simple calculation on 2 fields. For example { "script": "\_value / doc\['number\_field1'\] .value " } What I don't know is how to do a calculation on an aggregated field. For…

---

## [Split csv column to several fields](https://discuss.elastic.co/t/split-csv-column-to-several-fields/36927)

<div class="topic-metadata">

**Author:** [@eprst](https://discuss.elastic.co/u/eprst)\
**Replies:** 15\
**Last updated:** [December 15, 2015, 10:25am UTC](https://discuss.elastic.co/t/split-csv-column-to-several-fields/36927 "2015-12-15T10:25:01Z")

</div>

i use logstash to import from csv to elastic. the problem is that one of the fields contains the string formatted as "int|string|string" and i need to parse this and put into nested field. what are possible solutions for…

---

## [Logstash consuming messages slow](https://discuss.elastic.co/t/logstash-consuming-messages-slow/56900)

<div class="topic-metadata">

**Author:** [@mrunalgosar](https://discuss.elastic.co/u/mrunalgosar)\
**Replies:** 13\
**Last updated:** [October 15, 2016, 2:34pm UTC](https://discuss.elastic.co/t/logstash-consuming-messages-slow/56900 "2016-10-15T14:34:17Z")

</div>

Hi All I have recently setup ELK stack as belows. Kibana \<-- Elasticsearch \<-- Logstash \<-- Redis \<-- Filebeat. Here my Filebeat is producing log events faster than Logstash can consume..resulting in pile up on redis.…

---

## [Filebeat system modules](https://discuss.elastic.co/t/filebeat-system-modules/125998)

<div class="topic-metadata">

**Author:** [@Bhairavi](https://discuss.elastic.co/u/Bhairavi)\
**Replies:** 17\
**Last updated:** [April 3, 2018, 12:53pm UTC](https://discuss.elastic.co/t/filebeat-system-modules/125998 "2018-04-03T12:53:44Z")

</div>

Hi, I am trying to run filebeat system modules and the index filebeat-yyyy.mm.dd is also getting created in elasticsearch index but when configuring index pattern in kibana with filebeat-\* I am not able to view pre-built…

---

## [Word count from documents](https://discuss.elastic.co/t/word-count-from-documents/117379)

<div class="topic-metadata">

**Author:** [@manasguduri](https://discuss.elastic.co/u/manasguduri)\
**Replies:** 9\
**Last updated:** [January 31, 2018, 5:51pm UTC](https://discuss.elastic.co/t/word-count-from-documents/117379 "2018-01-31T17:51:04Z")

</div>

Is it possible to index a pdf document to visualize the count of words or like top 10 words with their count ? Thanks in advance.

---

## [Problem with mustache on watcher action](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745)

<div class="topic-metadata">

**Author:** [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Replies:** 26\
**Last updated:** [June 23, 2019, 9:01pm UTC](https://discuss.elastic.co/t/problem-with-mustache-on-watcher-action/184745 "2019-06-23T21:01:41Z")

</div>

Hi all I'm trying to do this action (a webhook) "hook-tornado2": { "webhook": { "scheme": "http", "host": "localhost", "port": 8080, "method": "post", "path": "/event/failed-passwords", "param…

---

## [Bootstrap Error](https://discuss.elastic.co/t/bootstrap-error/64426)

<div class="topic-metadata">

**Author:** [@Tim\_James](https://discuss.elastic.co/u/Tim_James)\
**Replies:** 9\
**Last updated:** [November 1, 2016, 8:48am UTC](https://discuss.elastic.co/t/bootstrap-error/64426 "2016-11-01T08:48:50Z")

</div>

Hi, Just trying out 5.0.0. On my previous 2.4 instance I had set network.host to 0.0.0.0. as otherwise I couldn't connect to Elasticsearch from logstash. In 5.0.0, if I make the same change, Elasticsearch won't start…

---

## [Indexing word, pdf documents?](https://discuss.elastic.co/t/indexing-word-pdf-documents/235758)

<div class="topic-metadata">

**Author:** [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Replies:** 11\
**Last updated:** [June 9, 2020, 7:56am UTC](https://discuss.elastic.co/t/indexing-word-pdf-documents/235758 "2020-06-09T07:56:20Z")

</div>

Can someone please guide me to a step-by-step documentation to index a word or pdf document in elasticsearch ?? I have gone through couple of posts on this and came across FS crawler etc. I would like to know if there …

---

## [Logstash - how to flat json array with ruby filter?](https://discuss.elastic.co/t/logstash-how-to-flat-json-array-with-ruby-filter/165322)

<div class="topic-metadata">

**Author:** [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Replies:** 10\
**Last updated:** [February 6, 2019, 10:42am UTC](https://discuss.elastic.co/t/logstash-how-to-flat-json-array-with-ruby-filter/165322 "2019-02-06T10:42:50Z")

</div>

I have a log file with json format, and there are json arrays in it. for example, a piece of array log is like below. I am using json+ruby fitler to make the array element parsed flatten. but my filter looks like doesn…

---

## [Elasticsearch : NoSuchFieldError](https://discuss.elastic.co/t/elasticsearch-nosuchfielderror/58923)

<div class="topic-metadata">

**Author:** [@PriyaRajan](https://discuss.elastic.co/u/PriyaRajan)\
**Replies:** 14\
**Last updated:** [September 2, 2016, 11:22am UTC](https://discuss.elastic.co/t/elasticsearch-nosuchfielderror/58923 "2016-09-02T11:22:10Z")

</div>

I'm beginner to Elasticsearch using version-2.3.5 Jackson lib jackson-core-2.6.6.jar and jackson-dataformat-smile-2.6.6.jar Code: QueryBuilder qb = QueryBuilders.rangeQuery("timestamp").from("2016-08-03 12:03:06").to("…

---

## [Logstash not sending to elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-to-elasticsearch/55357)

<div class="topic-metadata">

**Author:** [@Sergio\_Pavez](https://discuss.elastic.co/u/Sergio_Pavez)\
**Replies:** 13\
**Last updated:** [May 5, 2017, 5:23am UTC](https://discuss.elastic.co/t/logstash-not-sending-to-elasticsearch/55357 "2017-05-05T05:23:40Z")

</div>

Hello. I have a logstash configuration with a custom template. The template appears when I ask for it: "GET /\_template/\*". I followed this example: Logstash mapping If I send the data to a file with json format this is …

---

## [Deleting indices with curator 4.0](https://discuss.elastic.co/t/deleting-indices-with-curator-4-0/55729)

<div class="topic-metadata">

**Author:** [@Jpuch](https://discuss.elastic.co/u/Jpuch)\
**Replies:** 9\
**Last updated:** [March 27, 2017, 9:04am UTC](https://discuss.elastic.co/t/deleting-indices-with-curator-4-0/55729 "2017-03-27T09:04:30Z")

</div>

Hi there, I just read this thread How do I know if curator is cleaning up? (SOLVED) and same as the last comment, when i use this command line : curator delete indices --older-than 5 --time-unit days --timestring %Y.%…

---

## [Remotely accessing Kibana Web Interface](https://discuss.elastic.co/t/remotely-accessing-kibana-web-interface/228415)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 15\
**Last updated:** [April 24, 2020, 2:49am UTC](https://discuss.elastic.co/t/remotely-accessing-kibana-web-interface/228415 "2020-04-24T02:49:46Z")

</div>

I am trying to access the Kibana interface remotely and locally. When I change server.host to the IP of the machine, it does not load locally nor remotely. When I set it to 0.0.0.0, I can only access locally. I made …

---

## [Filestream input sends duplicates events on restart and during operation](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951)

<div class="topic-metadata">

**Author:** [@michaelbu](https://discuss.elastic.co/u/michaelbu)\
**Replies:** 33\
**Last updated:** [June 25, 2023, 4:22pm UTC](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951 "2023-06-25T16:22:10Z")

</div>

We use more than 1.800 filebeats with the filestream-input in version: $ filebeat version filebeat version 8.7.0 (amd64), libbeat 8.7.0 \[a8dbc6c06381f4fe33a5dc23906d63c04c9e2444 built 2023-03-23 00:37:07 +0000 UTC\] Ro…

---

## [Apm-server failed connect to ElasticSearch with Xpack enabled (401 Unauthorized )](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929)

<div class="topic-metadata">

**Author:** [@blump](https://discuss.elastic.co/u/blump)\
**Replies:** 10\
**Last updated:** [July 16, 2019, 12:24pm UTC](https://discuss.elastic.co/t/apm-server-failed-connect-to-elasticsearch-with-xpack-enabled-401-unauthorized/187929 "2019-07-16T12:24:22Z")

</div>

Hello, ELK\_VERSION = 7.2.0 On my docker environment, I can not connect apm-server with elastic Search when xpack (basic mode) is enabled. When Xpack is disabled, it's work ERROR pipeline/output.go:100 Failed to conne…

---

## [Problem with raw field](https://discuss.elastic.co/t/problem-with-raw-field/28841)

<div class="topic-metadata">

**Author:** [@peterbergman](https://discuss.elastic.co/u/peterbergman)\
**Replies:** 12\
**Last updated:** [December 2, 2015, 3:05pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841 "2015-12-02T15:05:02Z")

</div>

Hi, I have a problem using a raw field for term aggregation in a data table visualization. Whenever I try to view the data for a specific raw field used in a search through the visualization, I get no results. However,…

---

## [Query DSL count distinct](https://discuss.elastic.co/t/query-dsl-count-distinct/299751)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 15\
**Last updated:** [March 16, 2022, 11:09am UTC](https://discuss.elastic.co/t/query-dsl-count-distinct/299751 "2022-03-16T11:09:35Z")

</div>

Hi, I am looking for precise count results for index with over 70 millions documents. Equal to this: SQL: select count(distinct column) from table; I already tried Terms-aggregation, composite-aggregation, cardinality…

---

## [Log entries gets truncated on file rotation](https://discuss.elastic.co/t/log-entries-gets-truncated-on-file-rotation/66725)

<div class="topic-metadata">

**Author:** [@dr\_rock](https://discuss.elastic.co/u/dr_rock)\
**Replies:** 9\
**Last updated:** [November 23, 2016, 10:56am UTC](https://discuss.elastic.co/t/log-entries-gets-truncated-on-file-rotation/66725 "2016-11-23T10:56:47Z")

</div>

Hi there, We are using Filebeat 5.0.0 to parse log files. Log rotate on a daily basis (we are using Log4J's DailyRollingFileAppender to produce our log files). Log rotates every day at 00:00 and we get a truncated event…

---

## [ElasticSearch 5.0.0-aplha4 won't start without setting vm.max\_map\_count](https://discuss.elastic.co/t/elasticsearch-5-0-0-aplha4-wont-start-without-setting-vm-max-map-count/57471)

<div class="topic-metadata">

**Author:** [@mrunalgosar](https://discuss.elastic.co/u/mrunalgosar)\
**Replies:** 17\
**Last updated:** [March 5, 2017, 4:04am UTC](https://discuss.elastic.co/t/elasticsearch-5-0-0-aplha4-wont-start-without-setting-vm-max-map-count/57471 "2017-03-05T04:04:55Z")

</div>

Hi Team I wish to update my ES version from 2.3 to 5.0.0-alpha4 to be able to use Ingest nodes and remove Logstash out of the question. But it seems ES 5.x version won't start without me setting vm.max\_map\_count to 26214…

---

## [Snapshot problems with Amazon S3](https://discuss.elastic.co/t/snapshot-problems-with-amazon-s3/111765)

<div class="topic-metadata">

**Author:** [@baltendo](https://discuss.elastic.co/u/baltendo)\
**Replies:** 11\
**Last updated:** [January 11, 2018, 11:52pm UTC](https://discuss.elastic.co/t/snapshot-problems-with-amazon-s3/111765 "2018-01-11T23:52:35Z")

</div>

Hi! Elasticsearch: 5.4.2 Cloud: AWS OS: Amazon Linux Since 17th of November we get failures when our daily backup snapshots are created: "failures": \[ { "index": "user-reviews", "index\_uu…

---

## [Auto incremental property](https://discuss.elastic.co/t/auto-incremental-property/4121)

<div class="topic-metadata">

**Author:** [@Mustafa\_Sener](https://discuss.elastic.co/u/Mustafa_Sener)\
**Replies:** 13\
**Last updated:** [March 18, 2011, 12:54pm UTC](https://discuss.elastic.co/t/auto-incremental-property/4121 "2011-03-18T12:54:42Z")

</div>

Hi, Is it possible to add a feature to configure auto increment properties for a type. -- Mustafa Sener www.ifountain.com

---

## [Elasticsearch HTTPS](https://discuss.elastic.co/t/elasticsearch-https/197347)

<div class="topic-metadata">

**Author:** [@Dev-Flo](https://discuss.elastic.co/u/Dev-Flo)\
**Replies:** 17\
**Last updated:** [September 5, 2019, 9:39am UTC](https://discuss.elastic.co/t/elasticsearch-https/197347 "2019-09-05T09:39:01Z")

</div>

Hey, I enabled encrypted HTTP client connections via TLS, following this guide: https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html#tls-http. However, now I cannot connect to the Elast…

---

## [Kibana error when The GUI popped up](https://discuss.elastic.co/t/kibana-error-when-the-gui-popped-up/44193)

<div class="topic-metadata">

**Author:** [@rvaedex23](https://discuss.elastic.co/u/rvaedex23)\
**Replies:** 14\
**Last updated:** [April 19, 2017, 10:47pm UTC](https://discuss.elastic.co/t/kibana-error-when-the-gui-popped-up/44193 "2017-04-19T22:47:12Z")

</div>

I tried to bring up the Kibana GUI. IP:5601 this error appeared: This version of Kibana requires Elasticsearch ^2.2.0 on all nodes. I found the following incompatible nodes in your cluster: Elasticsearch v1.3.9 @ inetl…

---

## [Filebeat - High CPU for windows machines](https://discuss.elastic.co/t/filebeat-high-cpu-for-windows-machines/58920)

<div class="topic-metadata">

**Author:** [@ori.rubinfeld](https://discuss.elastic.co/u/ori.rubinfeld)\
**Replies:** 25\
**Last updated:** [September 15, 2016, 6:08am UTC](https://discuss.elastic.co/t/filebeat-high-cpu-for-windows-machines/58920 "2016-09-15T06:08:20Z")

</div>

Hi, We are noticing the Filebeat consuming a lot of CPU on windows monitored machines. It can be above 20% and also above 40% all the time. The Filebeat suppose to be a light program which should not be felt at all. W…

---

## [Reindexing: Can't parse boolean value \[{format=disabled}\], expected \[true\] or \[false\]](https://discuss.elastic.co/t/reindexing-cant-parse-boolean-value-format-disabled-expected-true-or-false/80823)

<div class="topic-metadata">

**Author:** [@dcam](https://discuss.elastic.co/u/dcam)\
**Replies:** 21\
**Last updated:** [April 3, 2017, 5:08pm UTC](https://discuss.elastic.co/t/reindexing-cant-parse-boolean-value-format-disabled-expected-true-or-false/80823 "2017-04-03T17:08:28Z")

</div>

I got the following error when I try to reindex from v4 to v5. \[edit\] v2 to v5 Can't parse boolean value \[{format=disabled}\], expected \[true\] or \[false\] There should no be any boolean value, I can confirm it when I g…

---

## [Logstash dont use \*.conf files](https://discuss.elastic.co/t/logstash-dont-use-conf-files/234277)

<div class="topic-metadata">

**Author:** [@ahiyaz](https://discuss.elastic.co/u/ahiyaz)\
**Replies:** 27\
**Last updated:** [May 30, 2020, 4:31pm UTC](https://discuss.elastic.co/t/logstash-dont-use-conf-files/234277 "2020-05-30T16:31:59Z")

</div>

hi all i have an issue using configuration files that are under /etc/logstash/conf.d directory. The issue is that when loading logstash using systemctl the demon don't pull the configuration from the \*.conf file unde…

---

## [What does it mean to "store" a field?](https://discuss.elastic.co/t/what-does-it-mean-to-store-a-field/5893)

<div class="topic-metadata">

**Author:** [@Nick\_Hoffman](https://discuss.elastic.co/u/Nick_Hoffman)\
**Replies:** 22\
**Last updated:** [September 24, 2014, 9:02am UTC](https://discuss.elastic.co/t/what-does-it-mean-to-store-a-field/5893 "2014-09-24T09:02:22Z")

</div>

Throughout the documentation on the website, the "store" option is mentioned. Eg: "The field is stored in the index" "Set to yes the store actual field in the index, no to not store it." http://www.elasticsearch.o…

---

## [Parser error from ElasticSearch](https://discuss.elastic.co/t/parser-error-from-elasticsearch/5647)

<div class="topic-metadata">

**Author:** [@vineeth\_mohan](https://discuss.elastic.co/u/vineeth_mohan)\
**Replies:** 17\
**Last updated:** [October 20, 2011, 3:11pm UTC](https://discuss.elastic.co/t/parser-error-from-elasticsearch/5647 "2011-10-20T15:11:39Z")

</div>

Hi , I am seeing the following error from elasticSearch side. I took the same source shown in ES and tried it from command line and it went tru. We are using httpClient library of apache to push data to ES. Also th…

---

## [High-Cardinality Aggregation Alternate Approaches (2 million buckets)](https://discuss.elastic.co/t/high-cardinality-aggregation-alternate-approaches-2-million-buckets/222814)

<div class="topic-metadata">

**Author:** [@khickey](https://discuss.elastic.co/u/khickey)\
**Replies:** 10\
**Last updated:** [March 15, 2020, 9:11am UTC](https://discuss.elastic.co/t/high-cardinality-aggregation-alternate-approaches-2-million-buckets/222814 "2020-03-15T09:11:49Z")

</div>

Requirement: calculate a sum aggregate on a high-cardinality field of 2M unique values, order the results by the sum, and return the top 10 (or pages of 10 each). We are moving some of our materialized-view based data s…

---

## [Apache Error logs timestamp](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010)

<div class="topic-metadata">

**Author:** [@mkorayem](https://discuss.elastic.co/u/mkorayem)\
**Replies:** 9\
**Last updated:** [April 12, 2017, 9:43am UTC](https://discuss.elastic.co/t/apache-error-logs-timestamp/82010 "2017-04-12T09:43:59Z")

</div>

Hi I tried to get the pattern for apache error timestamp but all failed The timestamp is used in elasticsearch is when it is indexed not the time of the error e.g. \[Sun Feb 05 00:32:24.992868 2017\] \[mpm\_winnt:notic…

---

## [How to hide some fields in \_store using mappings](https://discuss.elastic.co/t/how-to-hide-some-fields-in--store-using-mappings/14498)

<div class="topic-metadata">

**Author:** [@akram79](https://discuss.elastic.co/u/akram79)\
**Replies:** 18\
**Last updated:** [November 23, 2013, 3:29pm UTC](https://discuss.elastic.co/t/how-to-hide-some-fields-in--store-using-mappings/14498 "2013-11-23T15:29:56Z")

</div>

Hi, I have some data, which should be hidden/not displayed as part of the \_source. when I set \_source : { enabled : false}, source is being returned as null. How to make some fields are not displayed, but disp…

---

## [Output Exec Script](https://discuss.elastic.co/t/output-exec-script/2750)

<div class="topic-metadata">

**Author:** [@neoform](https://discuss.elastic.co/u/neoform)\
**Replies:** 10\
**Last updated:** [June 17, 2015, 3:25am UTC](https://discuss.elastic.co/t/output-exec-script/2750 "2015-06-17T03:25:58Z")

</div>

Hello, I’m attempting to read a log file and run a script as output. The script accepts STDIN data, but I don’t think I’ve set up the log stash configs properly since the script never gets executed the way it’s curren…

---

## [Filebeat in windows is unable to send logs to logstash in Ubuntu server](https://discuss.elastic.co/t/filebeat-in-windows-is-unable-to-send-logs-to-logstash-in-ubuntu-server/87344)

<div class="topic-metadata">

**Author:** [@sasanka\_mourya](https://discuss.elastic.co/u/sasanka_mourya)\
**Replies:** 31\
**Last updated:** [May 29, 2017, 3:31pm UTC](https://discuss.elastic.co/t/filebeat-in-windows-is-unable-to-send-logs-to-logstash-in-ubuntu-server/87344 "2017-05-29T15:31:00Z")

</div>

My filebeat in windows runs fine. but i am unable to send logs from filebeat in windows to logstash in ubuntu server. Im running both windows and ubuntu in VM's. Here is my config file and the error. filebeat.prospecto…

---

## [Reindex with Scan-scroll and bulk\_API](https://discuss.elastic.co/t/reindex-with-scan-scroll-and-bulk-api/31379)

<div class="topic-metadata">

**Author:** [@krish0608](https://discuss.elastic.co/u/krish0608)\
**Replies:** 10\
**Last updated:** [March 6, 2017, 9:19pm UTC](https://discuss.elastic.co/t/reindex-with-scan-scroll-and-bulk-api/31379 "2017-03-06T21:19:08Z")

</div>

I need to reindex my data. I was able to get a scroll\_id using the scan and scroll API. Now I need to insert those data to my new index, but can't figure out how to use the bulk API to do this. Please Give some Example…

---

## [Share canvas embed on website](https://discuss.elastic.co/t/share-canvas-embed-on-website/273006)

<div class="topic-metadata">

**Author:** [@accateo](https://discuss.elastic.co/u/accateo)\
**Replies:** 26\
**Last updated:** [May 28, 2021, 7:32am UTC](https://discuss.elastic.co/t/share-canvas-embed-on-website/273006 "2021-05-28T07:32:30Z")

</div>

Hello, Isn't it really possible to embed a canvas workpad on a site, but it shows live data? Thank you

---

## [How to get the sum in time of values in Lens](https://discuss.elastic.co/t/how-to-get-the-sum-in-time-of-values-in-lens/310735)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 51\
**Last updated:** [August 5, 2022, 6:13am UTC](https://discuss.elastic.co/t/how-to-get-the-sum-in-time-of-values-in-lens/310735 "2022-08-05T06:13:32Z")

</div>

I collect logs in Elasticsearch and keep track of certain values in the logs with fields. Since the values are numeric, I would like to calculate the sum over a certain time interval and see the transition. However, wh…

---

## [\[Unresolved\] Absolutely nothing shows in any \[Filebeat\] Kibana Dashboards ("No results found")](https://discuss.elastic.co/t/unresolved-absolutely-nothing-shows-in-any-filebeat-kibana-dashboards-no-results-found/166839)

<div class="topic-metadata">

**Author:** [@wad11656](https://discuss.elastic.co/u/wad11656)\
**Replies:** 17\
**Last updated:** [February 8, 2019, 10:53pm UTC](https://discuss.elastic.co/t/unresolved-absolutely-nothing-shows-in-any-filebeat-kibana-dashboards-no-results-found/166839 "2019-02-08T22:53:17Z")

</div>

Host: Debian 9 ELK Stack version: 6.6.0 Sending logs through Elasticsearch or Logstash: Elasticsearch (hopefully Logstash later) Summary: I get "No results found :neutral\_face:" on every \[Filebeat\] Dashboard in Kiban…

---

## [Elasticsearch performance in HDD vs SSD and 32 GB vs 64 GB of RAM](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 24\
**Last updated:** [June 2, 2023, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622 "2023-06-02T09:47:22Z")

</div>

I understand from what I have read that ES works best in conjunction with a sweet spot of 64 GB RAM per node and a fair bit of SSD (3-4 TB per node, with multiple shards in each node to handle primary copies and replicas…

---

## [Weekly indices with name as starting day of the week](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307)

<div class="topic-metadata">

**Author:** [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Replies:** 10\
**Last updated:** [October 19, 2017, 6:34pm UTC](https://discuss.elastic.co/t/weekly-indices-with-name-as-starting-day-of-the-week/104307 "2017-10-19T18:34:33Z")

</div>

Hi, As of now, we are using daily indices and are trying to create weekly indices going forward. I have tried configuring indexprefix-%{+xxxx.ww} but it is giving indices by week number out of year. I have been trying …

---

## [LDAP inappropriate authentication](https://discuss.elastic.co/t/ldap-inappropriate-authentication/132320)

<div class="topic-metadata">

**Author:** [@tommer](https://discuss.elastic.co/u/tommer)\
**Replies:** 20\
**Last updated:** [June 5, 2018, 3:20pm UTC](https://discuss.elastic.co/t/ldap-inappropriate-authentication/132320 "2018-06-05T15:20:01Z")

</div>

Hello, i use X-Pack 6.1 and configure a LDAP access, but i get: LDAPException(resultCode=48 (inappropriate authentication), but a ldapsearch with same config works fine. Does elasticsearch requests the ldap server in a…

---

## [Filebeat doesn't send logs to logstash in client server architecture](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-logstash-in-client-server-architecture/44932)

<div class="topic-metadata">

**Author:** [@jstar](https://discuss.elastic.co/u/jstar)\
**Replies:** 10\
**Last updated:** [September 16, 2016, 6:49pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-send-logs-to-logstash-in-client-server-architecture/44932 "2016-09-16T18:49:01Z")

</div>

Hi all, I just set up filebeat following the documentation. But I can't have logs of my cluster in logstash. I use a client-server architecture (i.e a client with Filebeat configured and installed and a server with log…

---

## [ERR Failed to publish events caused by: read tcp 127.0.0.1:50248-\>127.0.0.1:5601: i/o timeout](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-read-tcp-127-0-0-1-50248-127-0-0-1-5601-i-o-timeout/101813)

<div class="topic-metadata">

**Author:** [@daffe0x77](https://discuss.elastic.co/u/daffe0x77)\
**Replies:** 13\
**Last updated:** [September 26, 2017, 2:04pm UTC](https://discuss.elastic.co/t/err-failed-to-publish-events-caused-by-read-tcp-127-0-0-1-50248-127-0-0-1-5601-i-o-timeout/101813 "2017-09-26T14:04:19Z")

</div>

To visualize Windows Event Logs I've setup an ELK server running all 3 components on the same box. Think for testing and learning ELK should be doable. Logs forwarded are account lockouts (Event ID 4740) from Domain Con…

---

## [Stack Monitoring with Fleet/elastic-agent](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244)

<div class="topic-metadata">

**Author:** [@rastro](https://discuss.elastic.co/u/rastro)\
**Replies:** 36\
**Last updated:** [December 6, 2023, 8:25am UTC](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244 "2023-12-06T08:25:21Z")

</div>

In Kibana, when you go to Stack Monitoring, it says "No monitoring data found" and suggests using Metricbeat. Except, shouldn't we be using Elastic Agent? So, how can I get the Stack Monitoring page working with Agent?…

---

## [Winlogbeat actively refused by target](https://discuss.elastic.co/t/winlogbeat-actively-refused-by-target/56752)

<div class="topic-metadata">

**Author:** [@Andrew\_Schulz](https://discuss.elastic.co/u/Andrew_Schulz)\
**Replies:** 13\
**Last updated:** [July 29, 2016, 10:11pm UTC](https://discuss.elastic.co/t/winlogbeat-actively-refused-by-target/56752 "2016-07-29T22:11:55Z")

</div>

Hi, I am very new to the ELK stack and Beats. I have a ELK stack setup on a Windows 2012 R2 server and am collecting winlogbeat, packetbeat and topbeat from the host of the ELK stack. I'm now trying to add winlogbeat …

[Previous page](https://discuss.elastic.co/top.md?page=38&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=40&per_page=50&period=all)
