# Top

**URL:** https://discuss.elastic.co/top.md?page=40&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 41

---

## [Unable to login in Kibana after enable x-pack](https://discuss.elastic.co/t/unable-to-login-in-kibana-after-enable-x-pack/275862)

<div class="topic-metadata">

**Author:** [@Fabio1](https://discuss.elastic.co/u/Fabio1)\
**Replies:** 9\
**Last updated:** [July 16, 2021, 4:08pm UTC](https://discuss.elastic.co/t/unable-to-login-in-kibana-after-enable-x-pack/275862 "2021-07-16T16:08:57Z")

</div>

Hello, I was using elasticsearch and kibana without problem, but I need to enable some features related with users (to create some accounts and give some permissions to some users), so I need to enable x-pack option to …

---

## [How to create a new Beats output?](https://discuss.elastic.co/t/how-to-create-a-new-beats-output/61074)

<div class="topic-metadata">

**Author:** [@Geetha\_Adinarayan](https://discuss.elastic.co/u/Geetha_Adinarayan)\
**Replies:** 9\
**Last updated:** [October 6, 2016, 12:47pm UTC](https://discuss.elastic.co/t/how-to-create-a-new-beats-output/61074 "2016-10-06T12:47:33Z")

</div>

Is there a standard interface/framework to create a new beats output. To be specific, we want to create a new output using which beats can send data to IBM Bluemix (logmet service). Currently we have taken logstash ou…

---

## [HTTP\_POLLER Plugin for Logstash](https://discuss.elastic.co/t/http-poller-plugin-for-logstash/110498)

<div class="topic-metadata">

**Author:** [@Rym\_Guerbi\_Michaut](https://discuss.elastic.co/u/Rym_Guerbi_Michaut)\
**Replies:** 29\
**Last updated:** [January 28, 2018, 9:38pm UTC](https://discuss.elastic.co/t/http-poller-plugin-for-logstash/110498 "2018-01-28T21:38:36Z")

</div>

Hi there, I'm new at using ELK and I have to import data with HTTP\_POLLER (json statement). I don't really understand some stuff about input plugins for Logstash. My question is: Do I have to download the plugin to …

---

## [How can I configure kibana on different host?](https://discuss.elastic.co/t/how-can-i-configure-kibana-on-different-host/260069)

<div class="topic-metadata">

**Author:** [@Hi\_u\_Nguy\_n\_Dang](https://discuss.elastic.co/u/Hi_u_Nguy_n_Dang)\
**Replies:** 14\
**Last updated:** [January 5, 2021, 3:02am UTC](https://discuss.elastic.co/t/how-can-i-configure-kibana-on-different-host/260069 "2021-01-05T03:02:04Z")

</div>

How can I configure kibana if it run on a different host with elasticsearch and logstash? For example my elasticsearch server is 10.1.11.111 my kibana server is 10.1.11.112 and my logstash server is 10.1.11.113 ? In …

---

## [Kibana cant find Filebeat index Pattern](https://discuss.elastic.co/t/kibana-cant-find-filebeat-index-pattern/179719)

<div class="topic-metadata">

**Author:** [@Nils98](https://discuss.elastic.co/u/Nils98)\
**Replies:** 19\
**Last updated:** [June 3, 2019, 7:38pm UTC](https://discuss.elastic.co/t/kibana-cant-find-filebeat-index-pattern/179719 "2019-06-03T19:38:21Z")

</div>

Hello There, i installed ELK, the Beats etc. with follow Guide: But Kibana dont see the Filebeat to create an index pattern. I tryed my best, but i still cant find a way to fix this. Can you please help me, guys?…

---

## [OpenID error after authenticating against AWS Cognito](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018)

<div class="topic-metadata">

**Author:** [@nahojkap](https://discuss.elastic.co/u/nahojkap)\
**Replies:** 15\
**Last updated:** [November 13, 2019, 6:03pm UTC](https://discuss.elastic.co/t/openid-error-after-authenticating-against-aws-cognito/206018 "2019-11-13T18:03:44Z")

</div>

Attempting to configure a Elastic Cloud Kibana instance to use AWS Cognito for login but running into a the below error after successful login at the OP (AWS Cognito) side. {"statusCode":401,"error":"Unauthorized","mess…

---

## [Date filter recognizing custom grok pattern?](https://discuss.elastic.co/t/date-filter-recognizing-custom-grok-pattern/24363)

<div class="topic-metadata">

**Author:** [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Replies:** 11\
**Last updated:** [June 30, 2016, 7:44am UTC](https://discuss.elastic.co/t/date-filter-recognizing-custom-grok-pattern/24363 "2016-06-30T07:44:16Z")

</div>

I am dealing with a log file that has a special timestamp, 2014-12-14 23:59:40.227 -8 ISO8601 will recognize the date and time but not the time zone, so I built my own, and when I tried to use the date filter, a…

---

## [Parse syslog from Syslog](https://discuss.elastic.co/t/parse-syslog-from-syslog/168291)

<div class="topic-metadata">

**Author:** [@Digital](https://discuss.elastic.co/u/Digital)\
**Replies:** 11\
**Last updated:** [February 25, 2019, 2:42pm UTC](https://discuss.elastic.co/t/parse-syslog-from-syslog/168291 "2019-02-25T14:42:53Z")

</div>

Hi all, I am new in ELK solution :smiley: and currently I am working on Logstash -\> Elasticsearch -\> Kibana. I send the syslog from a checkpoint to logstash however I would like to parse correctly the syslog with logs…

---

## [How to convert a nested field type?](https://discuss.elastic.co/t/how-to-convert-a-nested-field-type/46025)

<div class="topic-metadata">

**Author:** [@abcfy2](https://discuss.elastic.co/u/abcfy2)\
**Replies:** 11\
**Last updated:** [April 3, 2016, 2:42am UTC](https://discuss.elastic.co/t/how-to-convert-a-nested-field-type/46025 "2016-04-03T02:42:01Z")

</div>

I find mutate filter can convert a field type, but how to convert a nested one? I've tried: mutate { convert =\> {"logdetail.params" =\> "string"} } And mutate { convert =\> {"\[logdetail\]\[params\]" =\> "st…

---

## [How to use multiple csv files in logstash ,](https://discuss.elastic.co/t/how-to-use-multiple-csv-files-in-logstash/90200)

<div class="topic-metadata">

**Author:** [@vijjun123](https://discuss.elastic.co/u/vijjun123)\
**Replies:** 9\
**Last updated:** [June 21, 2017, 12:10pm UTC](https://discuss.elastic.co/t/how-to-use-multiple-csv-files-in-logstash/90200 "2017-06-21T12:10:25Z")

</div>

I want to use multiple csv files in logstash hence please guide me . now using single csv file as per the below. remaining file names are different ex : file1,file2,file3 input { file { path =\> "/tmp/AWSDiscove…

---

## [Filebeat - Syslog module no auth.logs in Elastic](https://discuss.elastic.co/t/filebeat-syslog-module-no-auth-logs-in-elastic/125428)

<div class="topic-metadata">

**Author:** [@jamesl](https://discuss.elastic.co/u/jamesl)\
**Replies:** 14\
**Last updated:** [April 8, 2018, 10:28am UTC](https://discuss.elastic.co/t/filebeat-syslog-module-no-auth-logs-in-elastic/125428 "2018-04-08T10:28:28Z")

</div>

HI, Just enabled the filebeat module - syslog on my Ubuntu 16.0.4 box. I'm getting syslog output into Elastic but not the auth.log files. I enabled debug from in the filebeat.yml file and can see the following so I'm a…

---

## [Sending multiple \_count requests in one go](https://discuss.elastic.co/t/sending-multiple-count-requests-in-one-go/171456)

<div class="topic-metadata">

**Author:** [@Yuval\_Khalifa](https://discuss.elastic.co/u/Yuval_Khalifa)\
**Replies:** 16\
**Last updated:** [March 8, 2019, 1:43pm UTC](https://discuss.elastic.co/t/sending-multiple-count-requests-in-one-go/171456 "2019-03-08T13:43:48Z")

</div>

Is it possible to send multiple requests to the \_count API in one go? I saw this post https://discuss.elastic.co/t/does-count-api-support-searching-by-multiple-terms-and-return-multiple-counts/10183/2 but from what I can…

---

## [Errors when answering by email](https://discuss.elastic.co/t/errors-when-answering-by-email/1242)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 17\
**Last updated:** [August 19, 2015, 11:58pm UTC](https://discuss.elastic.co/t/errors-when-answering-by-email/1242 "2015-08-19T23:58:35Z")

</div>

I'm getting this now: We're sorry, but your email message to \["discuss+35309678d2f68e7f4eeba30249bfc97c@elastic.co"\] (titled Re: \[Elasticsearch\] Failed to send ping to) didn't work. The provided reply key is invalid…

---

## [What's the recommended strategy to reindex all (over 500) indices from 5.6.3 to 7.x?](https://discuss.elastic.co/t/whats-the-recommended-strategy-to-reindex-all-over-500-indices-from-5-6-3-to-7-x/190124)

<div class="topic-metadata">

**Author:** [@shradhatx](https://discuss.elastic.co/u/shradhatx)\
**Replies:** 13\
**Last updated:** [July 15, 2019, 4:49pm UTC](https://discuss.elastic.co/t/whats-the-recommended-strategy-to-reindex-all-over-500-indices-from-5-6-3-to-7-x/190124 "2019-07-15T16:49:08Z")

</div>

I have to migrate from ES5.6.3 to latest ES 7.x There are over 500 indices, 10 flavor of index, high number of index because of rollover ex index1-yyyy.mm and so on. The two options can be - scripting - ex bash script…

---

## [Elasticsearch 7.4 won't start properly](https://discuss.elastic.co/t/elasticsearch-7-4-wont-start-properly/201891)

<div class="topic-metadata">

**Author:** [@phucvandinh](https://discuss.elastic.co/u/phucvandinh)\
**Replies:** 14\
**Last updated:** [October 16, 2019, 9:48pm UTC](https://discuss.elastic.co/t/elasticsearch-7-4-wont-start-properly/201891 "2019-10-16T21:48:17Z")

</div>

I have a problem after upgrade elasticsearch from 7.3 to 7.4 on my dedicated server, it won't be able to start ● elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; ena…

---

## [No node available Exception](https://discuss.elastic.co/t/no-node-available-exception/7381)

<div class="topic-metadata">

**Author:** [@Eugene\_Strokin](https://discuss.elastic.co/u/Eugene_Strokin)\
**Replies:** 9\
**Last updated:** [November 4, 2014, 9:12am UTC](https://discuss.elastic.co/t/no-node-available-exception/7381 "2014-11-04T09:12:07Z")

</div>

After several months of work with no problem (without even restart), my application start to throw this exception once in a while: Exception in thread "main" org.elasticsearch.client.transport.NoNodeAvailable…

---

## [Testing Elastic Stack and winlogbeat / query exceeds 1000 shards](https://discuss.elastic.co/t/testing-elastic-stack-and-winlogbeat-query-exceeds-1000-shards/77923)

<div class="topic-metadata">

**Author:** [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Replies:** 31\
**Last updated:** [March 11, 2017, 3:35am UTC](https://discuss.elastic.co/t/testing-elastic-stack-and-winlogbeat-query-exceeds-1000-shards/77923 "2017-03-11T03:35:47Z")

</div>

Hello all, I'll begin by listing the components and versions I've installed first; all of the below are installed on one FreeBSD 11 p8 box: Elasticsearch 5.0.2 Logstash 5.0.2 Kibana 5.0.2 Winlogbeat 5.2.2 is installe…

---

## [Getting an error when using boost for multiple fields](https://discuss.elastic.co/t/getting-an-error-when-using-boost-for-multiple-fields/186187)

<div class="topic-metadata">

**Author:** [@pyerunka](https://discuss.elastic.co/u/pyerunka)\
**Replies:** 26\
**Last updated:** [June 21, 2019, 7:02am UTC](https://discuss.elastic.co/t/getting-an-error-when-using-boost-for-multiple-fields/186187 "2019-06-21T07:02:14Z")

</div>

Hello, When i am trying to add boost for multiple queries : POST /new\_master\_query/\_search { "query": { "match" : { "title": { "query": "test", "boost": 2 }, "object\_summary":{ "query":"Test", "boost": 1 } …

---

## [Unable to reach APM Server: ('Connection aborted.', RemoteDisconnected('Remote end closed connection without response',))](https://discuss.elastic.co/t/unable-to-reach-apm-server-connection-aborted-remotedisconnected-remote-end-closed-connection-without-response/166500)

<div class="topic-metadata">

**Author:** [@thienngho](https://discuss.elastic.co/u/thienngho)\
**Replies:** 11\
**Last updated:** [February 12, 2019, 3:39pm UTC](https://discuss.elastic.co/t/unable-to-reach-apm-server-connection-aborted-remotedisconnected-remote-end-closed-connection-without-response/166500 "2019-02-12T15:39:41Z")

</div>

Kibana version: 6.6.0 Elasticsearch version: 6.6.0 APM Server version: 6.6.0 APM Agent language and version: Python Browser version: FF 65.0 Original install method (e.g. download page, yum, deb, from source, etc.) …

---

## [Gc takes a lot of time](https://discuss.elastic.co/t/gc-takes-a-lot-of-time/114539)

<div class="topic-metadata">

**Author:** [@gensmusic](https://discuss.elastic.co/u/gensmusic)\
**Replies:** 13\
**Last updated:** [January 8, 2018, 3:13pm UTC](https://discuss.elastic.co/t/gc-takes-a-lot-of-time/114539 "2018-01-08T15:13:59Z")

</div>

we use elasticsearch to store log data. Currently we have 16 data nodes and 3 master. Each data node is 24 core cpu, 2.6Tx12 disk, and 32G memory. We use half of the memory for elasticsearch. We use index name like b…

---

## [Reasons Behind HPROF Files - What is the Cause?](https://discuss.elastic.co/t/reasons-behind-hprof-files-what-is-the-cause/223832)

<div class="topic-metadata">

**Author:** [@sarahFYB](https://discuss.elastic.co/u/sarahFYB)\
**Replies:** 11\
**Last updated:** [March 25, 2020, 8:47am UTC](https://discuss.elastic.co/t/reasons-behind-hprof-files-what-is-the-cause/223832 "2020-03-25T08:47:34Z")

</div>

Hi All We are on Elasticsearch 6.2.2 where it has thrown a HPROF file when indexing the content of documents for Micro Focus' Content Manager. The file seems to be referring to massive amounts of memory leaks. Is ther…

---

## [Metricbeat windows service does not startup](https://discuss.elastic.co/t/metricbeat-windows-service-does-not-startup/76043)

<div class="topic-metadata">

**Author:** [@Hussain\_Kothari](https://discuss.elastic.co/u/Hussain_Kothari)\
**Replies:** 10\
**Last updated:** [March 29, 2017, 4:48pm UTC](https://discuss.elastic.co/t/metricbeat-windows-service-does-not-startup/76043 "2017-03-29T16:48:38Z")

</div>

Hi, I'm trying to install metrics beat agent using PS-DSC script on our servers. But the service does not start up. It gives this error. And when i try to manually start the service from the server too, i get this e…

---

## [Missing beat.hostname from Filebeat Index Pattern](https://discuss.elastic.co/t/missing-beat-hostname-from-filebeat-index-pattern/139785)

<div class="topic-metadata">

**Author:** [@Saris](https://discuss.elastic.co/u/Saris)\
**Replies:** 17\
**Last updated:** [July 19, 2018, 3:10pm UTC](https://discuss.elastic.co/t/missing-beat-hostname-from-filebeat-index-pattern/139785 "2018-07-19T15:10:07Z")

</div>

Using Filebeat for collecting Windows Firewall Logs. Everything is going well except my Index Pattern does not include the beat.hostname. Filebeat used to report the Host field, but since updating to 6.3.0, was removed…

---

## [One ES node not showing in Kibana Monitoring](https://discuss.elastic.co/t/one-es-node-not-showing-in-kibana-monitoring/200212)

<div class="topic-metadata">

**Author:** [@thealy](https://discuss.elastic.co/u/thealy)\
**Replies:** 26\
**Last updated:** [November 7, 2019, 2:24pm UTC](https://discuss.elastic.co/t/one-es-node-not-showing-in-kibana-monitoring/200212 "2019-11-07T14:24:22Z")

</div>

I recently upgraded 3 (of 9) nodes to new hardware. Since that time, one of the nodes (es02) is not visible in the Kibana "Monitoring" page. ALL nodes are visible via Elasticsearch Head plugin. Version 6.8.3 Based on e…

---

## [ERROR: Unknown command 'Logstash'](https://discuss.elastic.co/t/error-unknown-command-logstash/187620)

<div class="topic-metadata">

**Author:** [@Kevin\_Juliano](https://discuss.elastic.co/u/Kevin_Juliano)\
**Replies:** 9\
**Last updated:** [July 1, 2019, 12:55pm UTC](https://discuss.elastic.co/t/error-unknown-command-logstash/187620 "2019-07-01T12:55:08Z")

</div>

Hi I'm new to Logstash and I am following this blog (https://www.elastic.co/blog/logstash-jdbc-input-plugin) to connect postgresql to elasticsearch using logstash, but I am getting this error: logstash-7.2.0/bin/logsta…

---

## [Issue after upgrading to 7.5.2 - SyntaxError: Unexpected token u in JSON at position 0 at JSON.parse (\<anonymous\>) at server.route.handler](https://discuss.elastic.co/t/issue-after-upgrading-to-7-5-2-syntaxerror-unexpected-token-u-in-json-at-position-0-at-json-parse-anonymous-at-server-route-handler/216623)

<div class="topic-metadata">

**Author:** [@saif3r](https://discuss.elastic.co/u/saif3r)\
**Replies:** 12\
**Last updated:** [April 6, 2020, 7:58pm UTC](https://discuss.elastic.co/t/issue-after-upgrading-to-7-5-2-syntaxerror-unexpected-token-u-in-json-at-position-0-at-json-parse-anonymous-at-server-route-handler/216623 "2020-04-06T19:58:07Z")

</div>

Hello, Today we have performed an upgrate to Kiana 7.5.2 (ES at 7.5) and we have noticed an issue with one of our indices which was working fine. It seems like this particular index pattern is returning an error. Other …

---

## [This node is locked](https://discuss.elastic.co/t/this-node-is-locked/323040)

<div class="topic-metadata">

**Author:** [@Randomize](https://discuss.elastic.co/u/Randomize)\
**Replies:** 11\
**Last updated:** [January 16, 2023, 10:25am UTC](https://discuss.elastic.co/t/this-node-is-locked/323040 "2023-01-16T10:25:02Z")

</div>

Hello I updated elasticsearch to version 8.4.1 Now im trying to start elasticsearch using discovery.type: single-node in config file. But its does not starting. I can see status activating in systemctl status. In elast…

---

## [Circuit\_breaking\_exception during reindex](https://discuss.elastic.co/t/circuit-breaking-exception-during-reindex/198255)

<div class="topic-metadata">

**Author:** [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Replies:** 21\
**Last updated:** [October 23, 2019, 11:04am UTC](https://discuss.elastic.co/t/circuit-breaking-exception-during-reindex/198255 "2019-10-23T11:04:15Z")

</div>

We've started getting frequent circuit breaker exceptions in our cluster, and I need some advice on how to tackle our situation. I've read up on circuit breakers, read lots of posts on the topic, but I'm still not sure w…

---

## [Yellow Status- Unassigned Shards](https://discuss.elastic.co/t/yellow-status-unassigned-shards/198272)

<div class="topic-metadata">

**Author:** [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Replies:** 10\
**Last updated:** [September 6, 2019, 1:21pm UTC](https://discuss.elastic.co/t/yellow-status-unassigned-shards/198272 "2019-09-06T13:21:17Z")

</div>

Hi, I have many indices with yellow status and Unassigned Shards. How i can fixed that? Is this related that my nodes are on different countries and there is delay on network or it's something else?

---

## [Certificate error occurred when installing the fleet server](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710)

<div class="topic-metadata">

**Author:** [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Replies:** 46\
**Last updated:** [December 23, 2022, 3:12am UTC](https://discuss.elastic.co/t/certificate-error-occurred-when-installing-the-fleet-server/321710 "2022-12-23T03:12:45Z")

</div>

My Elasticsearch and Kibana versions are 8.5.0. When installing the fly, certificate errors are reported all the time. My elasticsearch has set three nodes, and the certificate generated by using the （elasticsearch-certu…

---

## [Unrecognized VM option 'UseConcMarkSweepGC'](https://discuss.elastic.co/t/unrecognized-vm-option-useconcmarksweepgc/264960)

<div class="topic-metadata">

**Author:** [@realtech2338](https://discuss.elastic.co/u/realtech2338)\
**Replies:** 10\
**Last updated:** [February 20, 2021, 11:26pm UTC](https://discuss.elastic.co/t/unrecognized-vm-option-useconcmarksweepgc/264960 "2021-02-20T23:26:55Z")

</div>

C:\\elastic\_stack\\logstash-7.11.1-windows-x86\_64\\logstash-7.11.1\\bin\>logstash -f logstash-simple.conf Using JAVA\_HOME defined java: C:\\Program Files\\Java\\jdk-15.0.2 WARNING, using JAVA\_HOME while Logstash distribution c…

---

## [Performance Help](https://discuss.elastic.co/t/performance-help/44025)

<div class="topic-metadata">

**Author:** [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Replies:** 26\
**Last updated:** [May 24, 2016, 12:36pm UTC](https://discuss.elastic.co/t/performance-help/44025 "2016-05-24T12:36:32Z")

</div>

Right now I am using ES to store and search NSM logs produced with Bro. I am monitoring a 4.4g network which as you can imagine produces an extreme amount of log data. My current setup: Sensor using logstash to read…

---

## [How to rightsize HEAP , long GC , ES 2.4](https://discuss.elastic.co/t/how-to-rightsize-heap-long-gc-es-2-4/60805)

<div class="topic-metadata">

**Author:** [@Kim-Kruse-Hansen](https://discuss.elastic.co/u/Kim-Kruse-Hansen)\
**Replies:** 14\
**Last updated:** [October 1, 2016, 2:30pm UTC](https://discuss.elastic.co/t/how-to-rightsize-heap-long-gc-es-2-4/60805 "2016-10-01T14:30:05Z")

</div>

Hi There I have recently deployed 2 separate ES 2.4 Clusters , 2 nodes in each cluster , running on Windows 2012 R2 standard , Virtual Machines on vmware , 12 Cores , 24 GB RAM , 1 TB disk. I am using Java 1.8 , update…

---

## [Default index pattern not found in kibana](https://discuss.elastic.co/t/default-index-pattern-not-found-in-kibana/115394)

<div class="topic-metadata">

**Author:** [@Ankita\_Mukherjee](https://discuss.elastic.co/u/Ankita_Mukherjee)\
**Replies:** 12\
**Last updated:** [January 19, 2018, 5:21am UTC](https://discuss.elastic.co/t/default-index-pattern-not-found-in-kibana/115394 "2018-01-19T05:21:37Z")

</div>

Hello everyone, I have just completed installing Kibana, but now its showing me Create index pattern page. Am not able to view the configure page as well and its not showing me the default index pattern. I have searched…

---

## [Getting error while parsing documents](https://discuss.elastic.co/t/getting-error-while-parsing-documents/83846)

<div class="topic-metadata">

**Author:** [@venuambati](https://discuss.elastic.co/u/venuambati)\
**Replies:** 12\
**Last updated:** [May 11, 2017, 7:01am UTC](https://discuss.elastic.co/t/getting-error-while-parsing-documents/83846 "2017-05-11T07:01:33Z")

</div>

Hi Everyone, I am using Ingest-attachment for indexing documents. I am able to parse text documents (.txt files). When I try to parse .doc or pdf files getting this error. FILE = /elastic/files/englishAnalyzer.doc ID…

---

## [X-pack questions on installation](https://discuss.elastic.co/t/x-pack-questions-on-installation/129849)

<div class="topic-metadata">

**Author:** [@irb7501](https://discuss.elastic.co/u/irb7501)\
**Replies:** 36\
**Last updated:** [May 7, 2018, 6:37pm UTC](https://discuss.elastic.co/t/x-pack-questions-on-installation/129849 "2018-05-07T18:37:22Z")

</div>

Greetings - I have just installed x-pack 6.2.4 with ELK versions 6.2.4. I created the user passwords for elastic, kibana, and logstash-system. Kibana is running and I'm able to login - however I am not receiving any ne…

---

## [Why are bounding box geo queries so slow?](https://discuss.elastic.co/t/why-are-bounding-box-geo-queries-so-slow/11696)

<div class="topic-metadata">

**Author:** [@Jason\_5](https://discuss.elastic.co/u/Jason_5)\
**Replies:** 14\
**Last updated:** [January 16, 2014, 12:35am UTC](https://discuss.elastic.co/t/why-are-bounding-box-geo-queries-so-slow/11696 "2014-01-16T00:35:53Z")

</div>

I have an index with around 3 million documents in which there is a single geo\_point field. When performing a geo\_distance query I see response times of around 25,000 ms. After looking more at how geo\_distance need…

---

## [Selecting multiple fields to display in a line graph](https://discuss.elastic.co/t/selecting-multiple-fields-to-display-in-a-line-graph/51081)

<div class="topic-metadata">

**Author:** [@rheng](https://discuss.elastic.co/u/rheng)\
**Replies:** 17\
**Last updated:** [May 26, 2016, 9:09pm UTC](https://discuss.elastic.co/t/selecting-multiple-fields-to-display-in-a-line-graph/51081 "2016-05-26T21:09:37Z")

</div>

I was wondering can we select more than 1 field for comparision purposes. for example, i have 3 line graph, 1 line shows a count of user in los angeles, another count in san jose, and another in colorado. So i wanted…

---

## [GROK Failure](https://discuss.elastic.co/t/grok-failure/107270)

<div class="topic-metadata">

**Author:** [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Replies:** 29\
**Last updated:** [November 15, 2017, 6:48pm UTC](https://discuss.elastic.co/t/grok-failure/107270 "2017-11-15T18:48:25Z")

</div>

please help , i have tried almost everything here is my log and filebeat and logstash configs OUT:999.777.666.172\\tErrorCode=00000\\tOpStatus=00000\\tExceptionReason=null\\tJSON={\\"op\_gsn\\":\\"ghhhh.intra.test.com\\",\\"op\_s…

---

## [How to gain ingestion rate](https://discuss.elastic.co/t/how-to-gain-ingestion-rate/49476)

<div class="topic-metadata">

**Author:** [@Marcin\_Kubica](https://discuss.elastic.co/u/Marcin_Kubica)\
**Replies:** 14\
**Last updated:** [May 9, 2016, 10:28am UTC](https://discuss.elastic.co/t/how-to-gain-ingestion-rate/49476 "2016-05-09T10:28:47Z")

</div>

Hi, trying to pass 10k doc/s on a 9 node 8c/32g ram cluster Dataset in totall can reach 400GB Started small with 6 shards no replicas and can't reach above 10k docs/s What am I missing? Should I allocate a shard p…

---

## [Logstach 2.3.2 hang while run with .conf file](https://discuss.elastic.co/t/logstach-2-3-2-hang-while-run-with-conf-file/49348)

<div class="topic-metadata">

**Author:** [@dhyeem](https://discuss.elastic.co/u/dhyeem)\
**Replies:** 10\
**Last updated:** [May 21, 2016, 11:29pm UTC](https://discuss.elastic.co/t/logstach-2-3-2-hang-while-run-with-conf-file/49348 "2016-05-21T23:29:23Z")

</div>

Dears , there is an issue with the logstash i have , I try to run it with the .conf file i created but it hang after pipeline , this is one of the .conf i try to run : \`input { stdin {} file { …

---

## [GROK FILTER NOT WORKING WITH MULTILINE UNSTRUCTURED MESSAGE](https://discuss.elastic.co/t/grok-filter-not-working-with-multiline-unstructured-message/172386)

<div class="topic-metadata">

**Author:** [@Sharma3007](https://discuss.elastic.co/u/Sharma3007)\
**Replies:** 23\
**Last updated:** [March 15, 2019, 6:09pm UTC](https://discuss.elastic.co/t/grok-filter-not-working-with-multiline-unstructured-message/172386 "2019-03-15T18:09:39Z")

</div>

Hello, I am new to ELK stack and currently I am having issues with GROK filter. My grok filter is working fine with the grok debugger http://grokdebug.herokuapp.com/. But when I try to use it on logstash then it is n…

---

## [Accessing tf-idf](https://discuss.elastic.co/t/accessing-tf-idf/13976)

<div class="topic-metadata">

**Author:** [@benmccann](https://discuss.elastic.co/u/benmccann)\
**Replies:** 11\
**Last updated:** [May 5, 2014, 1:34pm UTC](https://discuss.elastic.co/t/accessing-tf-idf/13976 "2014-05-05T13:34:26Z")

</div>

Can you access the tf-idf to use outside of ElasticSearch? Also, is the tf-idf calculated on a per-field basis or a per-document basis? Thanks, Ben -- You received this message because you are subscribed to th…

---

## [CircuitBreaking Exception](https://discuss.elastic.co/t/circuitbreaking-exception/258568)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 17\
**Last updated:** [December 20, 2020, 1:21pm UTC](https://discuss.elastic.co/t/circuitbreaking-exception/258568 "2020-12-20T13:21:11Z")

</div>

I am using ELK cluster(3 master+3 data +2 coordinate) + kafka cluster.I am also using winlogbeat and packetbeat at client side.In kibana discover i saw that winlogbeat data was coming slow and packetbeat data was coming …

---

## [How to search a value by special character](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 17\
**Last updated:** [June 6, 2023, 11:17am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611 "2023-06-06T11:17:22Z")

</div>

Hi there, so i have a field named uri\_api and some of them have a value like this: /scrt/kpi/v3/code/shean%20jeremy%20patok i want to search other value like that in uri\_api field. how can i achieve it? i already try …

---

## [Red status caused by stuck initializing\_shards](https://discuss.elastic.co/t/red-status-caused-by-stuck-initializing-shards/135177)

<div class="topic-metadata">

**Author:** [@elk2](https://discuss.elastic.co/u/elk2)\
**Replies:** 11\
**Last updated:** [June 21, 2018, 2:20pm UTC](https://discuss.elastic.co/t/red-status-caused-by-stuck-initializing-shards/135177 "2018-06-21T14:20:25Z")

</div>

I have a single index in initializing shards stuck with red status cluster. I tried to reassign index to another node without success because it is not an unassigned shard. I have only primary shards and this is the sta…

---

## [Failed to parse JSON response: json: cannot unmarshal string into Go struct field .Version of type struct { Number string }\]](https://discuss.elastic.co/t/failed-to-parse-json-response-json-cannot-unmarshal-string-into-go-struct-field-version-of-type-struct-number-string/163321)

<div class="topic-metadata">

**Author:** [@Bhavesh\_Padharia](https://discuss.elastic.co/u/Bhavesh_Padharia)\
**Replies:** 16\
**Last updated:** [January 11, 2019, 12:25pm UTC](https://discuss.elastic.co/t/failed-to-parse-json-response-json-cannot-unmarshal-string-into-go-struct-field-version-of-type-struct-number-string/163321 "2019-01-11T12:25:39Z")

</div>

How to solve this error? Exiting: Couldn't connect to any of the configured Elasticsearch hosts. Errors: \[Error connection to Elasticsearch http://localhost:9600: Failed to parse JSON response: json: cannot unmarshal …

---

## [Data loss using UDP input plugin](https://discuss.elastic.co/t/data-loss-using-udp-input-plugin/32988)

<div class="topic-metadata">

**Author:** [@Anusha\_sunkadh](https://discuss.elastic.co/u/Anusha_sunkadh)\
**Replies:** 18\
**Last updated:** [November 4, 2015, 3:46am UTC](https://discuss.elastic.co/t/data-loss-using-udp-input-plugin/32988 "2015-11-04T03:46:07Z")

</div>

Almost 80% of data is lost when i use UDP input plugin for netflow data. Below is my configuration file. input { udp { queue\_size =\> 50000 port =\> 9993 type =\> "netflow" workers =\> 4 codec =\> netflow { version…

---

## [Wildcard search not working for "-" in the wildcard](https://discuss.elastic.co/t/wildcard-search-not-working-for-in-the-wildcard/120381)

<div class="topic-metadata">

**Author:** [@Ram\_Ibaset](https://discuss.elastic.co/u/Ram_Ibaset)\
**Replies:** 13\
**Last updated:** [February 23, 2018, 5:45pm UTC](https://discuss.elastic.co/t/wildcard-search-not-working-for-in-the-wildcard/120381 "2018-02-23T17:45:41Z")

</div>

I am trying to do a wildcard search on 3 fields and it looks like a search string with "-" and wildcard does not work. I am using a java restclient implementation. The query string is as follows: curl -H 'Content-Type…

---

## [Not able to connect to Kibana from any IP other than localhost loopback address](https://discuss.elastic.co/t/not-able-to-connect-to-kibana-from-any-ip-other-than-localhost-loopback-address/227207)

<div class="topic-metadata">

**Author:** [@mneely](https://discuss.elastic.co/u/mneely)\
**Replies:** 10\
**Last updated:** [April 9, 2020, 7:57pm UTC](https://discuss.elastic.co/t/not-able-to-connect-to-kibana-from-any-ip-other-than-localhost-loopback-address/227207 "2020-04-09T19:57:47Z")

</div>

Hello, I am able to connect to http://localhost:5601 on my ubuntu 18.04 machine that is running docker and the ELK stack, but not able to connect to my Ethernet IP. mneely@umbrella-kibana:~$ curl -i http://localhost:560…

[Previous page](https://discuss.elastic.co/top.md?page=39&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=41&per_page=50&period=all)
