# Top

**URL:** https://discuss.elastic.co/top.md?page=41&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 42

---

## [Illegal\_state\_exception Watcher status :500](https://discuss.elastic.co/t/illegal-state-exception-watcher-status-500/72575)

<div class="topic-metadata">

**Author:** [@Rajasekaran\_Mari](https://discuss.elastic.co/u/Rajasekaran_Mari)\
**Replies:** 21\
**Last updated:** [January 30, 2017, 1:21pm UTC](https://discuss.elastic.co/t/illegal-state-exception-watcher-status-500/72575 "2017-01-30T13:21:08Z")

</div>

{ "error": { "root\_cause": \[ { "type": "remote\_transport\_exception", "reason": "\[es-master-node\]\[10.1.1.55:9300\]\[cluster:admin/watcher/watch/put\]" } \], "type…

---

## [The indices which match this index pattern don't contain any time fields](https://discuss.elastic.co/t/the-indices-which-match-this-index-pattern-dont-contain-any-time-fields/293403)

<div class="topic-metadata">

**Author:** [@damienhaynes](https://discuss.elastic.co/u/damienhaynes)\
**Replies:** 21\
**Last updated:** [January 10, 2022, 6:41am UTC](https://discuss.elastic.co/t/the-indices-which-match-this-index-pattern-dont-contain-any-time-fields/293403 "2022-01-10T06:41:07Z")

</div>

Hello, I need assistance in creating an index pattern so I can search logs in Kibana. I have the following logstash configuration: input { beats { port =\> 5044 host =\> "0.0.0.0" } } filter { json { …

---

## [Best way to bulk insert?](https://discuss.elastic.co/t/best-way-to-bulk-insert/25102)

<div class="topic-metadata">

**Author:** [@linlma](https://discuss.elastic.co/u/linlma)\
**Replies:** 12\
**Last updated:** [July 11, 2015, 4:42am UTC](https://discuss.elastic.co/t/best-way-to-bulk-insert/25102 "2015-07-11T04:42:57Z")

</div>

Hello Elastic experts, Wondering what is the best way to insert large number of records into an index? thanks in advance, Lin

---

## [Manipulating XML before hitting XML Filter](https://discuss.elastic.co/t/manipulating-xml-before-hitting-xml-filter/119732)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 32\
**Last updated:** [March 2, 2018, 6:33am UTC](https://discuss.elastic.co/t/manipulating-xml-before-hitting-xml-filter/119732 "2018-03-02T06:33:53Z")

</div>

Alright, I have a couple changes I want to make prior to an XML file hitting the XML parser. Strip versioning/encoding statement from the file Ensure tags \<feedback\> and \</feedback\> are placed on their own lines if the…

---

## [How to use OCR in Elasticsearch ingest attachment plugin?](https://discuss.elastic.co/t/how-to-use-ocr-in-elasticsearch-ingest-attachment-plugin/263007)

<div class="topic-metadata">

**Author:** [@OB1290](https://discuss.elastic.co/u/OB1290)\
**Replies:** 11\
**Last updated:** [February 4, 2021, 4:27pm UTC](https://discuss.elastic.co/t/how-to-use-ocr-in-elasticsearch-ingest-attachment-plugin/263007 "2021-02-04T16:27:31Z")

</div>

I was able to make the plugin work with PDFs that contain searchable text. When I give it a PDF or PNG with non searchable text, it fails to extract the text from the binary data. Unfortunately, I couldn't find anything…

---

## [Map, analyze and search phone number](https://discuss.elastic.co/t/map-analyze-and-search-phone-number/5088)

<div class="topic-metadata">

**Author:** [@Sindre\_Sorhus](https://discuss.elastic.co/u/Sindre_Sorhus)\
**Replies:** 14\
**Last updated:** [August 19, 2011, 3:14pm UTC](https://discuss.elastic.co/t/map-analyze-and-search-phone-number/5088 "2011-08-19T15:14:55Z")

</div>

What is the best way to map, analyze and search a field with a phone number? I have phone numbers in various formats. +47 23546798 +47 23 54 67 98 +47 235 46 798 +4723546798 23546798 I need to be able to searc…

---

## [Can Filebeat and Metricbeat together be using the same port of logstash](https://discuss.elastic.co/t/can-filebeat-and-metricbeat-together-be-using-the-same-port-of-logstash/93648)

<div class="topic-metadata">

**Author:** [@Raghunandan\_Sk](https://discuss.elastic.co/u/Raghunandan_Sk)\
**Replies:** 9\
**Last updated:** [August 2, 2017, 2:06pm UTC](https://discuss.elastic.co/t/can-filebeat-and-metricbeat-together-be-using-the-same-port-of-logstash/93648 "2017-08-02T14:06:07Z")

</div>

Hello , I am new to Metricbeat . I have system set which is running Filebeat ---\> logstash ----\> ES ----\> Kibana. Now I want to configure Metricbeat and want to send the data into logstash . So I stopped the filebeat and…

---

## [Filebeat as a UDP Syslog Listener Dropping Alot of Logs](https://discuss.elastic.co/t/filebeat-as-a-udp-syslog-listener-dropping-alot-of-logs/267132)

<div class="topic-metadata">

**Author:** [@sudont](https://discuss.elastic.co/u/sudont)\
**Replies:** 24\
**Last updated:** [March 30, 2021, 8:04pm UTC](https://discuss.elastic.co/t/filebeat-as-a-udp-syslog-listener-dropping-alot-of-logs/267132 "2021-03-30T20:04:24Z")

</div>

So we've been using a single filebeat as a listener for a GOOD amount of Juniper SRX firewalls (like 50 or so) and it's been working really well. We recently did a test and ran a script that fires 10 firewall logs on an…

---

## [Filebeat Autodiscover Hints Breaking Template](https://discuss.elastic.co/t/filebeat-autodiscover-hints-breaking-template/137310)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 10\
**Last updated:** [June 26, 2018, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-hints-breaking-template/137310 "2018-06-26T15:58:08Z")

</div>

Hi, We're using the below to scrape Kubernetes logs based on the presence of a specific annotation: filebeat.autodiscover: providers: - type: kubernetes in\_cluster: true tags: …

---

## [Downgrade ELK stack from 6.5.1 to 6.4.3](https://discuss.elastic.co/t/downgrade-elk-stack-from-6-5-1-to-6-4-3/158580)

<div class="topic-metadata">

**Author:** [@Venkata\_Naresh](https://discuss.elastic.co/u/Venkata_Naresh)\
**Replies:** 15\
**Last updated:** [November 28, 2018, 4:48pm UTC](https://discuss.elastic.co/t/downgrade-elk-stack-from-6-5-1-to-6-4-3/158580 "2018-11-28T16:48:30Z")

</div>

I want to downgrade ELK to lower version from 6.5.1 as some of the plugins not supported in 6.5.1. Help me with the process of downgrading without any index and dashboards loss

---

## [Logstash sending date instead of string](https://discuss.elastic.co/t/logstash-sending-date-instead-of-string/122866)

<div class="topic-metadata">

**Author:** [@jainbhavya53](https://discuss.elastic.co/u/jainbhavya53)\
**Replies:** 10\
**Last updated:** [March 14, 2018, 3:31am UTC](https://discuss.elastic.co/t/logstash-sending-date-instead-of-string/122866 "2018-03-14T03:31:22Z")

</div>

I am using grok filter to parse logs.In that there is a "time" field for which I am using "TIMESTAMP\_ISO8601" as the grok pattern. By default logstash should send this "time" field as "string" but it is sending it as da…

---

## [Как правильно переиндексировать индекс?](https://discuss.elastic.co/t/topic/36715)

<div class="topic-metadata">

**Author:** [@stanleer](https://discuss.elastic.co/u/stanleer)\
**Replies:** 9\
**Last updated:** [December 14, 2015, 9:39am UTC](https://discuss.elastic.co/t/topic/36715 "2015-12-14T09:39:05Z")

</div>

Если стоит задача полной переиндексации большого по объему данных индекса, то как правильно это сделать? Не удалять же старый и создавать новый.

---

## [Find and replace in elasticsearch all documents](https://discuss.elastic.co/t/find-and-replace-in-elasticsearch-all-documents/56612)

<div class="topic-metadata">

**Author:** [@madhuakula](https://discuss.elastic.co/u/madhuakula)\
**Replies:** 9\
**Last updated:** [July 28, 2016, 1:12pm UTC](https://discuss.elastic.co/t/find-and-replace-in-elasticsearch-all-documents/56612 "2016-07-28T13:12:51Z")

</div>

I wanted to replace the single username in all my elasticsearch index documents. Is there any API query ? I tried searching multiple but couldn't find. Any one has idea? Thanks in advance :slight\_smile:

---

## [Shipping logs from multiple files](https://discuss.elastic.co/t/shipping-logs-from-multiple-files/48881)

<div class="topic-metadata">

**Author:** [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Replies:** 23\
**Last updated:** [June 3, 2016, 3:28pm UTC](https://discuss.elastic.co/t/shipping-logs-from-multiple-files/48881 "2016-06-03T15:28:43Z")

</div>

Hi, I am using ELK stack on Windows box and configuring filebeat to ship logs from a computer's folder where logs have been generated everyday on a new file. How can I configure .yml conf to ship these logs to Elastics…

---

## ["Check file" timer and "send events" delay](https://discuss.elastic.co/t/check-file-timer-and-send-events-delay/100061)

<div class="topic-metadata">

**Author:** [@trabakoulas](https://discuss.elastic.co/u/trabakoulas)\
**Replies:** 10\
**Last updated:** [September 12, 2017, 2:38pm UTC](https://discuss.elastic.co/t/check-file-timer-and-send-events-delay/100061 "2017-09-12T14:38:55Z")

</div>

Hello, I have two general questions. I'm using the Filebeat to send logs to Logstash. I notice that when I change a file (that is monitored by the Filebeat), the event is published with a delay of ~5-6 seconds. Is this …

---

## [Kibana 5, Unregistered auth agent](https://discuss.elastic.co/t/kibana-5-unregistered-auth-agent/64751)

<div class="topic-metadata">

**Author:** [@skeer](https://discuss.elastic.co/u/skeer)\
**Replies:** 17\
**Last updated:** [November 4, 2016, 8:37pm UTC](https://discuss.elastic.co/t/kibana-5-unregistered-auth-agent/64751 "2016-11-04T20:37:09Z")

</div>

So Ive been having all sorts of issues after starting from a clean slate.. :frowning: So starting kibana via sudo systemctl start kibana Returns: Nov 02 11:10:20 localhost.localdomain sudo\[8883\]: mtops : TTY=pts/…

---

## [How to find bandwidth usage from netflow data](https://discuss.elastic.co/t/how-to-find-bandwidth-usage-from-netflow-data/62005)

<div class="topic-metadata">

**Author:** [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Replies:** 15\
**Last updated:** [June 1, 2017, 12:32pm UTC](https://discuss.elastic.co/t/how-to-find-bandwidth-usage-from-netflow-data/62005 "2017-06-01T12:32:25Z")

</div>

I want to display bandwidth usage as on x-axis timestamp and on y-axis data usage in mbps. I have netflow v5 data. How should I do this? Thank you.

---

## [Syslog with millisecond pattern not matching](https://discuss.elastic.co/t/syslog-with-millisecond-pattern-not-matching/130678)

<div class="topic-metadata">

**Author:** [@nodesocket](https://discuss.elastic.co/u/nodesocket)\
**Replies:** 13\
**Last updated:** [May 5, 2018, 6:31am UTC](https://discuss.elastic.co/t/syslog-with-millisecond-pattern-not-matching/130678 "2018-05-05T06:31:20Z")

</div>

I am using the following: input { tcp { port =\> 5000 type =\> syslog } } filter { if \[type\] == "syslog" { grok { match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_h…

---

## [No config files found in path](https://discuss.elastic.co/t/no-config-files-found-in-path/327879)

<div class="topic-metadata">

**Author:** [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Replies:** 16\
**Last updated:** [March 18, 2023, 6:56pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879 "2023-03-18T18:56:27Z")

</div>

Hello everyone I am new with Logstash and i trying to start Logstash 8.6.2 on a Windows Server 2019 Server to forward syslogs from a Firewall to Wazuh. When I try to run as administrator in PS the command C:\\logstash-8…

---

## [Fleet Pipeline does not exist - Data Streams not getting data](https://discuss.elastic.co/t/fleet-pipeline-does-not-exist-data-streams-not-getting-data/285877)

<div class="topic-metadata">

**Author:** [@Heroj04](https://discuss.elastic.co/u/Heroj04)\
**Replies:** 21\
**Last updated:** [November 2, 2021, 11:29am UTC](https://discuss.elastic.co/t/fleet-pipeline-does-not-exist-data-streams-not-getting-data/285877 "2021-11-02T11:29:46Z")

</div>

I have elastic setup and working using regular beats fine. I have since setup fleet and trying to add servers using that. however I am seeing a bunch of errors about pipelines not existing, only for certain items. See an…

---

## [After SSL was enabled, Kibana is not working](https://discuss.elastic.co/t/after-ssl-was-enabled-kibana-is-not-working/80397)

<div class="topic-metadata">

**Author:** [@arianayay](https://discuss.elastic.co/u/arianayay)\
**Replies:** 10\
**Last updated:** [April 4, 2017, 2:00pm UTC](https://discuss.elastic.co/t/after-ssl-was-enabled-kibana-is-not-working/80397 "2017-04-04T14:00:36Z")

</div>

Hi, Do you have any idea why Kibana is not connecting but Elasticsearch is accessible via https. As per checking in the security of Google Chrome, the certificate is valid. When SSL was not enabled, both Elasticsearch a…

---

## [Tutorial for Backup](https://discuss.elastic.co/t/tutorial-for-backup/43624)

<div class="topic-metadata">

**Author:** [@gringo](https://discuss.elastic.co/u/gringo)\
**Replies:** 16\
**Last updated:** [April 5, 2016, 9:24am UTC](https://discuss.elastic.co/t/tutorial-for-backup/43624 "2016-04-05T09:24:28Z")

</div>

Is there any working documentation for back up? This link is what I can find https://www.elastic.co/guide/en/elasticsearch/guide/current/backing-up-your-cluster.html It does not work at all. Totally useless

---

## [Filebeat log monitoring/alerting](https://discuss.elastic.co/t/filebeat-log-monitoring-alerting/53350)

<div class="topic-metadata">

**Author:** [@maheshraju](https://discuss.elastic.co/u/maheshraju)\
**Replies:** 11\
**Last updated:** [July 11, 2016, 8:47am UTC](https://discuss.elastic.co/t/filebeat-log-monitoring-alerting/53350 "2016-07-11T08:47:07Z")

</div>

I'm looking for a way to monitor Filebeat (running on windows) log and generate alerts in case of errors. Is there a way Filebeat can send events/log to windows event log?

---

## [Installing a Plugin, certificate store error](https://discuss.elastic.co/t/installing-a-plugin-certificate-store-error/104749)

<div class="topic-metadata">

**Author:** [@Dan\_Rough](https://discuss.elastic.co/u/Dan_Rough)\
**Replies:** 9\
**Last updated:** [October 22, 2017, 9:49am UTC](https://discuss.elastic.co/t/installing-a-plugin-certificate-store-error/104749 "2017-10-22T09:49:07Z")

</div>

Hello, I'm attempting to install the repository-s3 plugin, using the following command: bin/elasticsearch-plugin install repository-s3 I receive an error: Exception in thread "main" javax.net.ssl.SSLHandshakeException…

---

## [Nodes randomly disconnected from the ES cluster](https://discuss.elastic.co/t/nodes-randomly-disconnected-from-the-es-cluster/23028)

<div class="topic-metadata">

**Author:** [@Anil\_Karaka](https://discuss.elastic.co/u/Anil_Karaka)\
**Replies:** 9\
**Last updated:** [January 14, 2020, 7:14am UTC](https://discuss.elastic.co/t/nodes-randomly-disconnected-from-the-es-cluster/23028 "2020-01-14T07:14:31Z")

</div>

I greped for "removed" in master node and these are the logs that I see. \[2015-04-01 05:32:55,813\]\[INFO \]\[cluster.service \] \[ESBigNode3\] removed {\[ES30GBNode2\]\[Yf8ODQh0TE2\_0hQ35Y0M\_w\]\[ip-153-31-43-55\]\[ine…

---

## [Get text fields length with script](https://discuss.elastic.co/t/get-text-fields-length-with-script/125484)

<div class="topic-metadata">

**Author:** [@Bilal\_Demir](https://discuss.elastic.co/u/Bilal_Demir)\
**Replies:** 9\
**Last updated:** [March 30, 2018, 6:52pm UTC](https://discuss.elastic.co/t/get-text-fields-length-with-script/125484 "2018-03-30T18:52:50Z")

</div>

Hi, I'm trying to get text fields length to calculate my response size. doc\['filedname.subfield'\].value only geting numeric fields. After Elasticsearc 5.x version we can use "params.\_souerce.fieldname.subfield" but this…

---

## [If/else within Logstash output plugin](https://discuss.elastic.co/t/if-else-within-logstash-output-plugin/185965)

<div class="topic-metadata">

**Author:** [@g.le](https://discuss.elastic.co/u/g.le)\
**Replies:** 13\
**Last updated:** [June 19, 2019, 4:33pm UTC](https://discuss.elastic.co/t/if-else-within-logstash-output-plugin/185965 "2019-06-19T16:33:46Z")

</div>

Hello, I'm having a Logstash configuration similar to the below: input { beats { port =\> 5044 } } filter { clone { clones =\> \["local-dc"\] add\_tag =\> \["cloned"\] } } output { if "cloned" in \[tags\] {…

---

## [Postgres logs not properly parsed by filebeat](https://discuss.elastic.co/t/postgres-logs-not-properly-parsed-by-filebeat/137371)

<div class="topic-metadata">

**Author:** [@amitphulera](https://discuss.elastic.co/u/amitphulera)\
**Replies:** 10\
**Last updated:** [July 1, 2018, 8:25pm UTC](https://discuss.elastic.co/t/postgres-logs-not-properly-parsed-by-filebeat/137371 "2018-07-01T20:25:07Z")

</div>

Hi, I have started with Elastic Stack recently. My use case is to monitor multiple raspberry pis with Beats module and visualize the data in Kibana Dashboards. I tried to set up Metricbeat and filebeat on Raspi 3, it w…

---

## [How to get internal ip address from filebeat?](https://discuss.elastic.co/t/how-to-get-internal-ip-address-from-filebeat/169769)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 23\
**Last updated:** [April 1, 2019, 7:20am UTC](https://discuss.elastic.co/t/how-to-get-internal-ip-address-from-filebeat/169769 "2019-04-01T07:20:27Z")

</div>

I want to get internal ip address in as a field value in filebeat. currently only global ips indexed into elastic. why is that ? indexed json i got from elastic as below { "\_index": "filebeat-6.4.3-2019.02.25", "\_t…

---

## [Agent doesn't start : unable to retrieve connection to Kibana (.net core 3.1)](https://discuss.elastic.co/t/agent-doesnt-start-unable-to-retrieve-connection-to-kibana-net-core-3-1/252510)

<div class="topic-metadata">

**Author:** [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Replies:** 13\
**Last updated:** [October 19, 2020, 12:11pm UTC](https://discuss.elastic.co/t/agent-doesnt-start-unable-to-retrieve-connection-to-kibana-net-core-3-1/252510 "2020-10-19T12:11:16Z")

</div>

Hi, I can't make the .net core Agent work for APM Server, I get the following error \[08:32:13 ERR\] {CentralConfigFetcher} Exception was thrown while fetching configuration from APM Server and parsing it. ETag: \`\<null\>'…

---

## [Filebeat 5.0.0-alpha5 multiple harvesters for same file sending the same messages over and over](https://discuss.elastic.co/t/filebeat-5-0-0-alpha5-multiple-harvesters-for-same-file-sending-the-same-messages-over-and-over/59866)

<div class="topic-metadata">

**Author:** [@Tim\_Burt](https://discuss.elastic.co/u/Tim_Burt)\
**Replies:** 30\
**Last updated:** [October 10, 2016, 12:02pm UTC](https://discuss.elastic.co/t/filebeat-5-0-0-alpha5-multiple-harvesters-for-same-file-sending-the-same-messages-over-and-over/59866 "2016-10-10T12:02:27Z")

</div>

I am re opening this subject because it is also still an issue in alpha5. Using filebeat witb Kafka. Very happy with performance. Kafka disk filled up and Kafka stopped ack of lines received. Filebeats continued to…

---

## [How to send only the newly added log events instead of the entire content of a log file?](https://discuss.elastic.co/t/how-to-send-only-the-newly-added-log-events-instead-of-the-entire-content-of-a-log-file/79127)

<div class="topic-metadata">

**Author:** [@Sharath\_Vutpala](https://discuss.elastic.co/u/Sharath_Vutpala)\
**Replies:** 17\
**Last updated:** [March 23, 2017, 3:54pm UTC](https://discuss.elastic.co/t/how-to-send-only-the-newly-added-log-events-instead-of-the-entire-content-of-a-log-file/79127 "2017-03-23T15:54:30Z")

</div>

Hi, I have a log file that need to be sent to logstash using filebeat. My log file of size ~500 MB. Whenever a new event is added to the log file, filebeat is sending the whole log file to logstash. I am interested in…

---

## [Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<NoMethodError: undefined method \`close' for nil:NilClass\>](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706)

<div class="topic-metadata">

**Author:** [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Replies:** 44\
**Last updated:** [February 23, 2022, 9:50am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706 "2022-02-23T09:50:06Z")

</div>

I have that error in logstash logs when logstash starting. Here my config file for logstash: input { beats { port =\> 5044 } } filter { grok { patterns\_dir =\> \["/etc/logstash/pattern"\] match =\>…

---

## [Oracle 11g Synchronization with logstash](https://discuss.elastic.co/t/oracle-11g-synchronization-with-logstash/71639)

<div class="topic-metadata">

**Author:** [@Abdullah\_Alaiwat](https://discuss.elastic.co/u/Abdullah_Alaiwat)\
**Replies:** 19\
**Last updated:** [January 16, 2017, 1:09pm UTC](https://discuss.elastic.co/t/oracle-11g-synchronization-with-logstash/71639 "2017-01-16T13:09:09Z")

</div>

Hello, I'm using the logstash 5.1.1 to get the data from Oracle DB 11g to elastic search, the connection and data fetching is working fine but the problem is with the synchronization between the DB and Elasticsearch, e…

---

## [Very long GC](https://discuss.elastic.co/t/very-long-gc/13177)

<div class="topic-metadata">

**Author:** [@dezmodue](https://discuss.elastic.co/u/dezmodue)\
**Replies:** 10\
**Last updated:** [August 20, 2013, 9:56pm UTC](https://discuss.elastic.co/t/very-long-gc/13177 "2013-08-20T21:56:32Z")

</div>

Hi, We run an 8 instances ES cluster in EC2, one index (size: 3695.5gb), 48 shards, 1 replica per shard. ES version is 0.20.2, Oracle JVM 1.6.38, 30GB heap, total RAM 60GB, 2 \* 1024GB SSD drives in raid 0 (lvm stri…

---

## [Incorrect Order by Descending in Kibana visualization](https://discuss.elastic.co/t/incorrect-order-by-descending-in-kibana-visualization/48984)

<div class="topic-metadata">

**Author:** [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Replies:** 9\
**Last updated:** [July 18, 2016, 9:41pm UTC](https://discuss.elastic.co/t/incorrect-order-by-descending-in-kibana-visualization/48984 "2016-07-18T21:41:08Z")

</div>

I have created a visualization to show the number of netflows per IPV4\_SRC\_ADDR over time. It is supposed to sort the IP in the legend by Count in descending order. However as you look at the graph below, the IP with pin…

---

## [Removing leading character and trailing 2 characters](https://discuss.elastic.co/t/removing-leading-character-and-trailing-2-characters/214634)

<div class="topic-metadata">

**Author:** [@DWbank](https://discuss.elastic.co/u/DWbank)\
**Replies:** 14\
**Last updated:** [January 15, 2020, 3:58pm UTC](https://discuss.elastic.co/t/removing-leading-character-and-trailing-2-characters/214634 "2020-01-15T15:58:40Z")

</div>

I am using kv to parse my fields due to the fields change depends on the logs that are sent from the siem. kv { value\_split =\> “=’” field\_split =\> “’ “…

---

## [Java.lang.AssertionError with Integration Tests](https://discuss.elastic.co/t/java-lang-assertionerror-with-integration-tests/25124)

<div class="topic-metadata">

**Author:** [@dadepo](https://discuss.elastic.co/u/dadepo)\
**Replies:** 9\
**Last updated:** [July 8, 2015, 10:47am UTC](https://discuss.elastic.co/t/java-lang-assertionerror-with-integration-tests/25124 "2015-07-08T10:47:42Z")

</div>

I am trying to use the Integration features that now comes with Elasticsearch. So I have my test class annotated with @ClusterScope(scope = Scope.TEST), extending the ElasticsearchIntegrationTest and using the methods cr…

---

## [複数行にまたがるログのパースについて](https://discuss.elastic.co/t/topic/176846)

<div class="topic-metadata">

**Author:** [@iasenust](https://discuss.elastic.co/u/iasenust)\
**Replies:** 14\
**Last updated:** [April 19, 2019, 12:45am UTC](https://discuss.elastic.co/t/topic/176846 "2019-04-19T00:45:46Z")

</div>

初心者の者です。どうかご教授ください。 2行にまたがっているログを1ドキュメントとして取り出したいと思っています。 ログの中身は以下です。 \[2019/04/15 11:19:26.743\] ID=1787 DEV=東京01＜改行＞ ls＜改行＞ \[2019/04/15 11:19:30.743\] ID=1788 DEV=東京02＜改行＞ ls＜改行＞ ・ ・ ・ というように、 \[日時\] ID=ID番号 DEV=DE…

---

## [Mbeans error](https://discuss.elastic.co/t/mbeans-error/93541)

<div class="topic-metadata">

**Author:** [@alvaro13](https://discuss.elastic.co/u/alvaro13)\
**Replies:** 11\
**Last updated:** [July 18, 2017, 10:36am UTC](https://discuss.elastic.co/t/mbeans-error/93541 "2017-07-18T10:36:26Z")

</div>

Hello, I just started studying elasticsearch and kibana for a project that I have in mind, and I am trying to set this up. When I downloaded elasticsearch 5.5.0 and I try to run it, is showing up: blues-mbp:bin …

---

## [Kibana launch failed](https://discuss.elastic.co/t/kibana-launch-failed/277629)

<div class="topic-metadata">

**Author:** [@EpLiar](https://discuss.elastic.co/u/EpLiar)\
**Replies:** 18\
**Last updated:** [July 9, 2021, 9:34am UTC](https://discuss.elastic.co/t/kibana-launch-failed/277629 "2021-07-09T09:34:44Z")

</div>

I deploy elasticsearch on 192.168.50.216 and 192.168.50.69. Both are working. \[epi@localhost ~\]$ curl 192.168.50.69:9200 { "name" : "EpCent-1", "cluster\_name" : "EpCluster", "cluster\_uuid" : "XuZIcIMhR46iStO7LJIdN…

---

## ["Bootstrap check failed" still a mystery?](https://discuss.elastic.co/t/bootstrap-check-failed-still-a-mystery/159957)

<div class="topic-metadata">

**Author:** [@Nikhil\_Jaiswal](https://discuss.elastic.co/u/Nikhil_Jaiswal)\
**Replies:** 11\
**Last updated:** [December 10, 2018, 9:37am UTC](https://discuss.elastic.co/t/bootstrap-check-failed-still-a-mystery/159957 "2018-12-10T09:37:17Z")

</div>

Hi, I read many threads related to "Bootstrap check failed" but didn't get any solution. I am using elasticsearch for production environment. below is my ES configuration clustername: elasticsearch node.name: xyz nod…

---

## [Take out bits of a URIPATH in Logstash](https://discuss.elastic.co/t/take-out-bits-of-a-uripath-in-logstash/24597)

<div class="topic-metadata">

**Author:** [@simonrisberg](https://discuss.elastic.co/u/simonrisberg)\
**Replies:** 20\
**Last updated:** [July 1, 2015, 12:40pm UTC](https://discuss.elastic.co/t/take-out-bits-of-a-uripath-in-logstash/24597 "2015-07-01T12:40:46Z")

</div>

Hi! My name is Simon and I'm pretty new to ELK. I have been working with it for a few weeks now and I'm starting to understand how everything works (I think?). Back to the point, I am right now using Logstash to read f…

---

## [Indexing PDF's and Perform Text Analytics with ES](https://discuss.elastic.co/t/indexing-pdfs-and-perform-text-analytics-with-es/146803)

<div class="topic-metadata">

**Author:** [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Replies:** 11\
**Last updated:** [September 11, 2018, 12:46pm UTC](https://discuss.elastic.co/t/indexing-pdfs-and-perform-text-analytics-with-es/146803 "2018-09-11T12:46:05Z")

</div>

Hello All I've Indexed PDF into ES. Now I want to try out text analytics on the same pdf. Here is sample pdf after indexing in kibana Now I want to run elastic's cool analysers(something related to NLP: like removin…

---

## [Make package: yaml.v2': No such file or directory](https://discuss.elastic.co/t/make-package-yaml-v2-no-such-file-or-directory/66357)

<div class="topic-metadata">

**Author:** [@Aliaksandr\_Zabrodski](https://discuss.elastic.co/u/Aliaksandr_Zabrodski)\
**Replies:** 29\
**Last updated:** [January 24, 2017, 1:01am UTC](https://discuss.elastic.co/t/make-package-yaml-v2-no-such-file-or-directory/66357 "2017-01-24T01:01:27Z")

</div>

Hello, I am getting the following error when i try to package a newly generated beat (with cookiecutter) on debian jessie: $ make package Cloning into '/go/src/github.com/tsg/gotpl'... cp: cannot stat '/go/src/github…

---

## [Fresh ELK setup.. no http?](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576)

<div class="topic-metadata">

**Author:** [@skeer](https://discuss.elastic.co/u/skeer)\
**Replies:** 16\
**Last updated:** [November 2, 2016, 10:30pm UTC](https://discuss.elastic.co/t/fresh-elk-setup-no-http/64576 "2016-11-02T22:30:39Z")

</div>

Following here: https://www.elastic.co/guide/en/elastic-stack/current/installing-elastic-stack.html And I've gotten elasticsearch, kibana, logstash and teh x-pack installed but no http when I hit teh servers IP. It's li…

---

## [How to downgrade elasticsearch single node from 7.9.2 to 7.9.1 with out any data loss](https://discuss.elastic.co/t/how-to-downgrade-elasticsearch-single-node-from-7-9-2-to-7-9-1-with-out-any-data-loss/258207)

<div class="topic-metadata">

**Author:** [@Vinay\_Kumar2](https://discuss.elastic.co/u/Vinay_Kumar2)\
**Replies:** 9\
**Last updated:** [December 10, 2020, 3:21pm UTC](https://discuss.elastic.co/t/how-to-downgrade-elasticsearch-single-node-from-7-9-2-to-7-9-1-with-out-any-data-loss/258207 "2020-12-10T15:21:22Z")

</div>

We are planning to downgrade elasticsearch 7.9.2 to 7.9.1. Please let us know how it will works with out any data loss along with the details.

---

## [Cannot access Kibana remotely or on local machine](https://discuss.elastic.co/t/cannot-access-kibana-remotely-or-on-local-machine/196986)

<div class="topic-metadata">

**Author:** [@Terran](https://discuss.elastic.co/u/Terran)\
**Replies:** 15\
**Last updated:** [October 31, 2019, 5:33pm UTC](https://discuss.elastic.co/t/cannot-access-kibana-remotely-or-on-local-machine/196986 "2019-10-31T17:33:56Z")

</div>

I have installed ES in a 3 node cluster. I have Kibana on #3 as well. ES is running fine as far as I can tell. Kibana installed and started fine. I have edited the .yml file with the following Contents of kibana.yml …

---

## [How to split into multiple events dynamically for a given json? Tried from various question in forums](https://discuss.elastic.co/t/how-to-split-into-multiple-events-dynamically-for-a-given-json-tried-from-various-question-in-forums/167745)

<div class="topic-metadata">

**Author:** [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Replies:** 9\
**Last updated:** [February 11, 2019, 7:28am UTC](https://discuss.elastic.co/t/how-to-split-into-multiple-events-dynamically-for-a-given-json-tried-from-various-question-in-forums/167745 "2019-02-11T07:28:29Z")

</div>

Hi All These question has been asked multiple times in forum as i see but no definite answer. I saw one of the Elastic member answered in a nice way, but it is not working for me. I have a json data in this format com…

---

## [Logstash and databse](https://discuss.elastic.co/t/logstash-and-databse/26225)

<div class="topic-metadata">

**Author:** [@Anmol\_Gupta](https://discuss.elastic.co/u/Anmol_Gupta)\
**Replies:** 15\
**Last updated:** [July 30, 2015, 5:30am UTC](https://discuss.elastic.co/t/logstash-and-databse/26225 "2015-07-30T05:30:04Z")

</div>

First of all thanks to team that they provided us with jdbc plugin . I really needed it . Now i am stuck again I connected this plugin , ran the config file and yippie i could see the reflection in kibana. But now i wa…

[Previous page](https://discuss.elastic.co/top.md?page=40&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=42&per_page=50&period=all)
