# Top

**URL:** https://discuss.elastic.co/top.md?page=42&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 43

---

## [Ability to Search within Results](https://discuss.elastic.co/t/ability-to-search-within-results/29540)

<div class="topic-metadata">

**Author:** [@siddharth\_gupta](https://discuss.elastic.co/u/siddharth_gupta)\
**Replies:** 13\
**Last updated:** [September 21, 2015, 8:43am UTC](https://discuss.elastic.co/t/ability-to-search-within-results/29540 "2015-09-21T08:43:45Z")

</div>

Hello, I wanted to know that is it possible to search within the results that I get through elastic search ? I was going through the search API & saw this==\> "It is important to understand that once you get your se…

---

## [How to iterate through array of objects](https://discuss.elastic.co/t/how-to-iterate-through-array-of-objects/11898)

<div class="topic-metadata">

**Author:** [@waldemar](https://discuss.elastic.co/u/waldemar)\
**Replies:** 12\
**Last updated:** [May 20, 2013, 10:38am UTC](https://discuss.elastic.co/t/how-to-iterate-through-array-of-objects/11898 "2013-05-20T10:38:07Z")

</div>

HI All, I have index with mapping: "properties":{ "Availability":{"dynamic":"true","properties":{"Period":{ "type":"string"},"Price":{"type":"double"}}} } \*I want to iterate through array of objects how can I …

---

## [Cant start ES after update from 5.6.2 to 6.0](https://discuss.elastic.co/t/cant-start-es-after-update-from-5-6-2-to-6-0/108843)

<div class="topic-metadata">

**Author:** [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Replies:** 11\
**Last updated:** [November 30, 2017, 6:11am UTC](https://discuss.elastic.co/t/cant-start-es-after-update-from-5-6-2-to-6-0/108843 "2017-11-30T06:11:59Z")

</div>

ENV: OS: Centos 7 ES : 56.2 to 6.0 After upgrade, i reinstall all plugin ES, after that start ES but got error Nov 23 15:50:33 elastic-04 systemd\[1\]: Unit elasticsearch.service entered failed state. Nov 23 15:53:07 e…

---

## [GSoC 2018, Interested to contribute to Beats](https://discuss.elastic.co/t/gsoc-2018-interested-to-contribute-to-beats/120314)

<div class="topic-metadata">

**Author:** [@agathver](https://discuss.elastic.co/u/agathver)\
**Replies:** 21\
**Last updated:** [March 22, 2018, 1:49pm UTC](https://discuss.elastic.co/t/gsoc-2018-interested-to-contribute-to-beats/120314 "2018-03-22T13:49:59Z")

</div>

Hi I'm Amitosh Swain Mahapatra, a 3rd year CS undergrad from CET, Bhubaneswar, India. I'm interested to work on the idea - "Beats: Monitor Your Java Applications with JavaBeat". I've a good deal of experience of Go, an…

---

## [Error code 429 - circuit\_breaking\_exception](https://discuss.elastic.co/t/error-code-429-circuit-breaking-exception/202494)

<div class="topic-metadata">

**Author:** [@worapojc](https://discuss.elastic.co/u/worapojc)\
**Replies:** 9\
**Last updated:** [October 11, 2019, 9:09am UTC](https://discuss.elastic.co/t/error-code-429-circuit-breaking-exception/202494 "2019-10-11T09:09:29Z")

</div>

Hi Elastic team, I got this error from Logstash logs. \[2019-10-07T07:40:55,341\]\[INFO \]\[logstash.outputs.elasticsearch\] retrying failed action with response code: 429 ({"type"=\>"circuit\_breaking\_exception", "reason"=\>"…

---

## [Fleet Agents hitting 100% CPU usage](https://discuss.elastic.co/t/fleet-agents-hitting-100-cpu-usage/271529)

<div class="topic-metadata">

**Author:** [@MichaelHuff](https://discuss.elastic.co/u/MichaelHuff)\
**Replies:** 19\
**Last updated:** [May 4, 2021, 6:18pm UTC](https://discuss.elastic.co/t/fleet-agents-hitting-100-cpu-usage/271529 "2021-05-04T18:18:48Z")

</div>

We put the elastic-agent for fleet onto our VDI infrastructure. Each VDI machine started out with 2 vCPUs and 4 GB RAM. We installed the elastic-agent through fleet. The machine performed fine for a few hours then became…

---

## [Aucun Index pattern par défaut](https://discuss.elastic.co/t/aucun-index-pattern-par-defaut/41292)

<div class="topic-metadata">

**Author:** [@Tristan\_Ferioli](https://discuss.elastic.co/u/Tristan_Ferioli)\
**Replies:** 12\
**Last updated:** [February 12, 2016, 11:38am UTC](https://discuss.elastic.co/t/aucun-index-pattern-par-defaut/41292 "2016-02-12T11:38:55Z")

</div>

Bonjour, je poste sur ce forum pour avoir la réponse a mon problème. Alors voila j'ai installé le trio ELK pour centraliser les logs des mes boitiers VPN et et de mon SOnicFirewall. Quand je lance mon kibana 4 en localh…

---

## [Default TimeZone](https://discuss.elastic.co/t/default-timezone/304729)

<div class="topic-metadata">

**Author:** [@M.Naim](https://discuss.elastic.co/u/M.Naim)\
**Replies:** 12\
**Last updated:** [May 17, 2022, 5:18am UTC](https://discuss.elastic.co/t/default-timezone/304729 "2022-05-17T05:18:19Z")

</div>

Hi, I am getting issue in Timezone while Querying data on stored index. Issue: We have Dates stored like "2021-10-04T11:11:27-07:00" on server "GMT" but while pulling Data using Aggr it gets converted to "2021-10-04T18…

---

## [Winlogbeat not outputting to Logstash](https://discuss.elastic.co/t/winlogbeat-not-outputting-to-logstash/57500)

<div class="topic-metadata">

**Author:** [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Replies:** 13\
**Last updated:** [August 16, 2016, 2:10pm UTC](https://discuss.elastic.co/t/winlogbeat-not-outputting-to-logstash/57500 "2016-08-16T14:10:17Z")

</div>

All, I've read several posts here regarding getting Winlogbeat to send logs to an ELK server. However, these haven't helped me get it working. As I usually do, I probably am missing something simple. I already have…

---

## [Recency: Boost by Date](https://discuss.elastic.co/t/recency-boost-by-date/3782)

<div class="topic-metadata">

**Author:** [@Karussell1](https://discuss.elastic.co/u/Karussell1)\
**Replies:** 25\
**Last updated:** [July 13, 2011, 1:26pm UTC](https://discuss.elastic.co/t/recency-boost-by-date/3782 "2011-07-13T13:26:18Z")

</div>

Hi, I would like to boost recent documents. The same question was asked but not answered here \[1\]. I would like to execute the script config/scripts/queryboost.mvel with the following content: newScore = \_score;…

---

## [LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"if\\", \[A-Za-z0-9\_-\], '\\"', \\"'\\", \\"}\\"](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of-t-r-n-if-a-za-z0-9/312402)

<div class="topic-metadata">

**Author:** [@Queren\_Santos](https://discuss.elastic.co/u/Queren_Santos)\
**Replies:** 12\
**Last updated:** [August 24, 2022, 3:33pm UTC](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of-t-r-n-if-a-za-z0-9/312402 "2022-08-24T15:33:18Z")

</div>

I'm having trouble understanding my code configuration error. Shows the following message when trying to run the logs and their settings: \[ERROR\]\[logstash.agent\] Failed to execute action {:action=\>LogStash::PipelineActi…

---

## [Deleting index setting](https://discuss.elastic.co/t/deleting-index-setting/33676)

<div class="topic-metadata">

**Author:** [@Pradeep\_Gowda](https://discuss.elastic.co/u/Pradeep_Gowda)\
**Replies:** 14\
**Last updated:** [November 4, 2015, 6:00pm UTC](https://discuss.elastic.co/t/deleting-index-setting/33676 "2015-11-04T18:00:35Z")

</div>

Hi All, I added a index setting using below curl command curl -XPUT 'localhost:9200/\<myindex\>/\_settings' \\ -d '{"index.routing.allocation.disable\_allocation": false}' Now I want to remove this setting and bring …

---

## [Master not discovered or elected yet, an election requires a node with id \[F-Tn-Q6vQuKE0Fgi5qtUMg\] + 503 master not discovered exception](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-an-election-requires-a-node-with-id-f-tn-q6vquke0fgi5qtumg-503-master-not-discovered-exception/355949)

<div class="topic-metadata">

**Author:** [@Haoke98](https://discuss.elastic.co/u/Haoke98)\
**Replies:** 22\
**Last updated:** [March 24, 2024, 10:52am UTC](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-an-election-requires-a-node-with-id-f-tn-q6vquke0fgi5qtumg-503-master-not-discovered-exception/355949 "2024-03-24T10:52:41Z")

</div>

I have a elasticsearch cluster and it was work well before. But yesterday I accidentally deleted the Master node that has been elected. After this, the another master node cannot be elected by other nodes, at the same …

---

## [Elastic superuser: You need permission to access Machine Learning](https://discuss.elastic.co/t/elastic-superuser-you-need-permission-to-access-machine-learning/193378)

<div class="topic-metadata">

**Author:** [@sergiodcm00](https://discuss.elastic.co/u/sergiodcm00)\
**Replies:** 9\
**Last updated:** [August 20, 2019, 8:59am UTC](https://discuss.elastic.co/t/elastic-superuser-you-need-permission-to-access-machine-learning/193378 "2019-08-20T08:59:57Z")

</div>

Hello, suddenly, I'm not user when (perphaps after change ES cluster name) I cant load Machine Learning tab (logged in Kibana with superuser elastic). Kibana says: You need permission to access Machine Learning You mu…

---

## [ES 2.1 shards stuck in translog recovery](https://discuss.elastic.co/t/es-2-1-shards-stuck-in-translog-recovery/35716)

<div class="topic-metadata">

**Author:** [@jochen\_st](https://discuss.elastic.co/u/jochen_st)\
**Replies:** 13\
**Last updated:** [September 1, 2016, 4:09pm UTC](https://discuss.elastic.co/t/es-2-1-shards-stuck-in-translog-recovery/35716 "2016-09-01T16:09:35Z")

</div>

We are running ES 2.1 single node cluster on Windows 7 / NTFS. After ES crashed due to faulty disk (replacement is under way), the indices being written to at time of crash are stuck in translog recovery phase. I will us…

---

## [Strange memory leak ElasticSearch](https://discuss.elastic.co/t/strange-memory-leak-elasticsearch/258814)

<div class="topic-metadata">

**Author:** [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Replies:** 20\
**Last updated:** [December 24, 2020, 10:33am UTC](https://discuss.elastic.co/t/strange-memory-leak-elasticsearch/258814 "2020-12-24T10:33:32Z")

</div>

Hi, we have a cluster of ES. Our Heap is 31 Gb on each node. Total RAM 128 Gb on each node. And our RAM fills up over time and starts to run out, it that time we get faults of cluster. We see that "cached" constantly …

---

## [Getting MasterNotDiscoveredException for ES node for client](https://discuss.elastic.co/t/getting-masternotdiscoveredexception-for-es-node-for-client/16841)

<div class="topic-metadata">

**Author:** [@bagui](https://discuss.elastic.co/u/bagui)\
**Replies:** 11\
**Last updated:** [April 8, 2014, 4:30pm UTC](https://discuss.elastic.co/t/getting-masternotdiscoveredexception-for-es-node-for-client/16841 "2014-04-08T16:30:01Z")

</div>

Hi, I'm using the below code for indexing data from cloud. But getting the below exception while calling prepareIndex . Please let me know why the exception is coming. public static IndexResponse insertESDocu…

---

## [Merging two indexes by a common field](https://discuss.elastic.co/t/merging-two-indexes-by-a-common-field/96576)

<div class="topic-metadata">

**Author:** [@marwa](https://discuss.elastic.co/u/marwa)\
**Replies:** 11\
**Last updated:** [August 10, 2017, 12:04pm UTC](https://discuss.elastic.co/t/merging-two-indexes-by-a-common-field/96576 "2017-08-10T12:04:36Z")

</div>

Hi, I have an index named ‘transactions’ and an other one called ‘costs’ the transactions indexe contains { product\_id: “1111”, price\_unit: “23.56”, customer\_name:“Marda Elbin” } the costs index contains the id of ea…

---

## [AWS EC2 based cluster best practices](https://discuss.elastic.co/t/aws-ec2-based-cluster-best-practices/235354)

<div class="topic-metadata">

**Author:** [@Lior\_Yakobov](https://discuss.elastic.co/u/Lior_Yakobov)\
**Replies:** 17\
**Last updated:** [July 16, 2020, 11:22am UTC](https://discuss.elastic.co/t/aws-ec2-based-cluster-best-practices/235354 "2020-07-16T11:22:23Z")

</div>

Hello, We are currently running a 20 data nodes cluster on AWS EC2 instances. Since we have only 1 replica per shard, and we cannot tolerate failure of more than 1 node at the time, we are not using ephermal storage bu…

---

## [Could not lock IndexWriter isLocked \[false\] org.apache.lucene.store.LockObtainFailedException: Lock obtain timed out: NativeFSLock](https://discuss.elastic.co/t/could-not-lock-indexwriter-islocked-false-org-apache-lucene-store-lockobtainfailedexception-lock-obtain-timed-out-nativefslock/14902)

<div class="topic-metadata">

**Author:** [@Bryan\_Helmig](https://discuss.elastic.co/u/Bryan_Helmig)\
**Replies:** 23\
**Last updated:** [December 18, 2013, 7:34pm UTC](https://discuss.elastic.co/t/could-not-lock-indexwriter-islocked-false-org-apache-lucene-store-lockobtainfailedexception-lock-obtain-timed-out-nativefslock/14902 "2013-12-18T19:34:57Z")

</div>

Here is are some logs of the start of the incident https://gist.github.com/bryanhelmig/3c17edfe5c4e9065e5a3 And basically these logs over and over: https://gist.github.com/bryanhelmig/cfb9303bc033a1183701 A l…

---

## [Aggregation-keywords](https://discuss.elastic.co/t/aggregation-keywords/160300)

<div class="topic-metadata">

**Author:** [@Raghunadhan](https://discuss.elastic.co/u/Raghunadhan)\
**Replies:** 10\
**Last updated:** [December 14, 2018, 7:34am UTC](https://discuss.elastic.co/t/aggregation-keywords/160300 "2018-12-14T07:34:12Z")

</div>

Dear All, What does term and keyword mean that are used in aggregation query, Please find the example below GET /bank/\_search { "size": 0, "aggs": { "group\_by\_state": { "terms": { "field": "state.keyword" }, "…

---

## [Объем требуемого дискового пространства стал больше в ElasticSearch 5.x](https://discuss.elastic.co/t/elasticsearch-5-x/75593)

<div class="topic-metadata">

**Author:** [@Dmytro](https://discuss.elastic.co/u/Dmytro)\
**Replies:** 23\
**Last updated:** [March 1, 2017, 9:40pm UTC](https://discuss.elastic.co/t/elasticsearch-5-x/75593 "2017-03-01T21:40:19Z")

</div>

Здравствуйте! После перехода на пятую версию Эластика, при индексации одних и тех же данных, обнаружили, что размер индекса стал больше от 1,5 до 2 раз. В чем может быть причина такого резкого увеличения размера индекс…

---

## [KV field\_split prevents logstash ingesting data](https://discuss.elastic.co/t/kv-field-split-prevents-logstash-ingesting-data/100434)

<div class="topic-metadata">

**Author:** [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Replies:** 19\
**Last updated:** [September 20, 2017, 7:46am UTC](https://discuss.elastic.co/t/kv-field-split-prevents-logstash-ingesting-data/100434 "2017-09-20T07:46:06Z")

</div>

Hi, I found something strange going on with the field\_split option. I'm trying to parse fortigate logfiles. Default log: status=deny policyid=0 dst\_country="Reserved" src\_country="Reserved" service=1947/udp proto=17…

---

## [JSON parse error, original data now in message field {:message=\>"Unexpected character ('\<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')\\n at \[Source: (String)](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-unexpected-character-code-60-expected-a-valid-value-number-string-array-object-true-false-or-null-n-at-source-string/322015)

<div class="topic-metadata">

**Author:** [@shafiwebsphere](https://discuss.elastic.co/u/shafiwebsphere)\
**Replies:** 11\
**Last updated:** [January 4, 2023, 2:26pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-unexpected-character-code-60-expected-a-valid-value-number-string-array-object-true-false-or-null-n-at-source-string/322015 "2023-01-04T14:26:44Z")

</div>

Same code worked in previous version 7 but i have updated to latest version Elasticsearch logstash and kibana 7.17 , the logstash code is not working and getting error, i have been trying this from 15 days , When i have …

---

## [java.lang.ClassNotFoundException: org.bouncycastle.operator.OperatorCreationException](https://discuss.elastic.co/t/java-lang-classnotfoundexception-org-bouncycastle-operator-operatorcreationexception/171133)

<div class="topic-metadata">

**Author:** [@avinash\_07](https://discuss.elastic.co/u/avinash_07)\
**Replies:** 10\
**Last updated:** [March 8, 2019, 6:41pm UTC](https://discuss.elastic.co/t/java-lang-classnotfoundexception-org-bouncycastle-operator-operatorcreationexception/171133 "2019-03-08T18:41:39Z")

</div>

I wanted to try out X-Pack and when i run my spring application after adding the dependencies, I am getting the following error Caused by: java.lang.NoClassDefFoundError: org/bouncycastle/operator/OperatorCreationExcept…

---

## [SystemMemoryOutofException thrown while indexing files as an attachment](https://discuss.elastic.co/t/systemmemoryoutofexception-thrown-while-indexing-files-as-an-attachment/50916)

<div class="topic-metadata">

**Author:** [@ASN](https://discuss.elastic.co/u/ASN)\
**Replies:** 39\
**Last updated:** [May 30, 2016, 10:14am UTC](https://discuss.elastic.co/t/systemmemoryoutofexception-thrown-while-indexing-files-as-an-attachment/50916 "2016-05-30T10:14:33Z")

</div>

Hi all, I'm getting an error while using IndexMany for indexing documents as attachments. Yesterday, When I published the application on server it worked fine. But when I try to run it from visual studio it is throwing …

---

## [Ganglia Packets as Input in Logstash](https://discuss.elastic.co/t/ganglia-packets-as-input-in-logstash/522)

<div class="topic-metadata">

**Author:** [@ChrisMark](https://discuss.elastic.co/u/ChrisMark)\
**Replies:** 17\
**Last updated:** [January 30, 2016, 7:18pm UTC](https://discuss.elastic.co/t/ganglia-packets-as-input-in-logstash/522 "2016-01-30T19:18:08Z")

</div>

Hello guys, i would like to take ganglia packets in Logstash as input. From Logstash documention (http://www.logstash.net/docs/1.4.2/inputs/ganglia) i make that i have to configure my Logstash Server to listen on a por…

---

## [Elasticsearch Ingest node gsub processor escape character](https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-escape-character/68013)

<div class="topic-metadata">

**Author:** [@wenyao](https://discuss.elastic.co/u/wenyao)\
**Replies:** 13\
**Last updated:** [December 6, 2016, 3:50am UTC](https://discuss.elastic.co/t/elasticsearch-ingest-node-gsub-processor-escape-character/68013 "2016-12-06T03:50:25Z")

</div>

I am trying to use the gsub processor to replace characters such as \[, \] and . This is the example given in the elastic site (https://www.elastic.co/guide/en/elasticsearch/reference/current/gsub-processor.html): \> { \> …

---

## [Slow terms aggregations](https://discuss.elastic.co/t/slow-terms-aggregations/27496)

<div class="topic-metadata">

**Author:** [@artursmet](https://discuss.elastic.co/u/artursmet)\
**Replies:** 13\
**Last updated:** [August 21, 2015, 10:39pm UTC](https://discuss.elastic.co/t/slow-terms-aggregations/27496 "2015-08-21T22:39:34Z")

</div>

Hi, I have a problem with my ES deployment. My queries are using a few terms aggregations at once, and I have extremely low performance of queries (~8s for one query). Cluster: - Two machines (each with two CPU cores…

---

## [Recovery mechanism in filebeat](https://discuss.elastic.co/t/recovery-mechanism-in-filebeat/47539)

<div class="topic-metadata">

**Author:** [@kasi](https://discuss.elastic.co/u/kasi)\
**Replies:** 10\
**Last updated:** [May 17, 2017, 11:34pm UTC](https://discuss.elastic.co/t/recovery-mechanism-in-filebeat/47539 "2017-05-17T23:34:07Z")

</div>

I am seeing a disturbing behavior with filebeat and hope it is not true: When the output destination is not reachable or is down, filebeat tries for some time and then gives up, flushes the events to log file if debug …

---

## [Query String Regex/WildCard Search](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 15\
**Last updated:** [January 11, 2022, 10:36pm UTC](https://discuss.elastic.co/t/query-string-regex-wildcard-search/293845 "2022-01-11T22:36:13Z")

</div>

Hi Team, Problem Statement Search String - "Hello \* World" Expected Output - 1. "Hello First World" 2. "Hello Second World" I need results that contain one word in place of \*. I have tried using query string regex …

---

## [Talk to server... ERROR Connection marked as failed because the onConnect callback failed: invalid license found, requires a basic or a valid trial l icense and received Open sour](https://discuss.elastic.co/t/talk-to-server-error-connection-marked-as-failed-because-the-onconnect-callback-failed-invalid-license-found-requires-a-basic-or-a-valid-trial-l-icense-and-received-open-sour/210910)

<div class="topic-metadata">

**Author:** [@antonopo](https://discuss.elastic.co/u/antonopo)\
**Replies:** 24\
**Last updated:** [December 16, 2019, 3:09pm UTC](https://discuss.elastic.co/t/talk-to-server-error-connection-marked-as-failed-because-the-onconnect-callback-failed-invalid-license-found-requires-a-basic-or-a-valid-trial-l-icense-and-received-open-sour/210910 "2019-12-16T15:09:45Z")

</div>

Hi, I am still facing this license problem to one of my ELK nodes. elasticsearch: http://itkvmxh01.emea.nsn-net.net:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 151…

---

## [Disk space full elasticsearch](https://discuss.elastic.co/t/disk-space-full-elasticsearch/220037)

<div class="topic-metadata">

**Author:** [@Ilija\_Angeloski](https://discuss.elastic.co/u/Ilija_Angeloski)\
**Replies:** 10\
**Last updated:** [February 23, 2020, 11:00am UTC](https://discuss.elastic.co/t/disk-space-full-elasticsearch/220037 "2020-02-23T11:00:35Z")

</div>

After I deleted all the indices the disk space is still almost full, no place is freed up. I tried \`\`\` curl -XPOST 'http://localhost:9200/\_forcemerge?only\_expunge\_deletes=true', but still the disk has same amount. Is th…

---

## [Disabling machine learning does not allow Elasticsearch to stop](https://discuss.elastic.co/t/disabling-machine-learning-does-not-allow-elasticsearch-to-stop/88869)

<div class="topic-metadata">

**Author:** [@yoshioiwamoto](https://discuss.elastic.co/u/yoshioiwamoto)\
**Replies:** 17\
**Last updated:** [June 14, 2017, 8:31am UTC](https://discuss.elastic.co/t/disabling-machine-learning-does-not-allow-elasticsearch-to-stop/88869 "2017-06-14T08:31:57Z")

</div>

I make a fresh install of ES 5.4.1 in Ubuntu 16.04 and now I can not stop the service gracefully. I found that this occurs when I install X-Pack and explicitly disable the machine learning feature during the trial period…

---

## [Where is my infrastructure data?](https://discuss.elastic.co/t/where-is-my-infrastructure-data/157039)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 26\
**Last updated:** [December 3, 2018, 3:11pm UTC](https://discuss.elastic.co/t/where-is-my-infrastructure-data/157039 "2018-12-03T15:11:11Z")

</div>

Just discovered the new "infrastructure" menu item. Unfortunately, despite having many, many GB of data there doesn't seem to be anything to display here. I have plenty of dashboard data and am gathering from a slew of d…

---

## [Could not load : can't convert nil into String?](https://discuss.elastic.co/t/could-not-load-cant-convert-nil-into-string/1814)

<div class="topic-metadata">

**Author:** [@Siddharth\_Trikha](https://discuss.elastic.co/u/Siddharth_Trikha)\
**Replies:** 10\
**Last updated:** [June 4, 2015, 9:15am UTC](https://discuss.elastic.co/t/could-not-load-cant-convert-nil-into-string/1814 "2015-06-04T09:15:20Z")

</div>

I want to read logs only after a particular date. So my approach is to drop all the events previous to that date. I try to achieve it like this: So I am dropping all logs before June 1, 2015: Logstash config file: …

---

## [How to implement this in elastic](https://discuss.elastic.co/t/how-to-implement-this-in-elastic/118255)

<div class="topic-metadata">

**Author:** [@aliyesami](https://discuss.elastic.co/u/aliyesami)\
**Replies:** 34\
**Last updated:** [February 6, 2018, 8:38pm UTC](https://discuss.elastic.co/t/how-to-implement-this-in-elastic/118255 "2018-02-06T20:38:02Z")

</div>

how can I implement these sql conditions in elastic ? select \* from \<index\_name\> where ACCTTYPE\_ACCT\_TYPE\_CODE != '07' and PLAZA\_PLAZA\_ID in ('009500', '009502') and emp\_emp\_code != '9985' and PURSTAT\_PUR\_STATUS\_CO…

---

## [Packetbeat:How to add a new protocol?](https://discuss.elastic.co/t/packetbeat-how-to-add-a-new-protocol/48372)

<div class="topic-metadata">

**Author:** [@lindsayshow](https://discuss.elastic.co/u/lindsayshow)\
**Replies:** 16\
**Last updated:** [June 17, 2016, 1:16pm UTC](https://discuss.elastic.co/t/packetbeat-how-to-add-a-new-protocol/48372 "2016-06-17T13:16:28Z")

</div>

I know the https://www.elastic.co/guide/en/beats/packetbeat/current/new-protocol.html guide,but the guide is too old for the latest packetbeat version or source code.I find it's too hard to learn how to add a new protoc…

---

## [Filebeat refuse the connection with logstash](https://discuss.elastic.co/t/filebeat-refuse-the-connection-with-logstash/71038)

<div class="topic-metadata">

**Author:** [@shubhrant](https://discuss.elastic.co/u/shubhrant)\
**Replies:** 11\
**Last updated:** [January 11, 2017, 9:57am UTC](https://discuss.elastic.co/t/filebeat-refuse-the-connection-with-logstash/71038 "2017-01-11T09:57:15Z")

</div>

while shipping the log filebeat give an error i.e. INFO Connecting error publishing events (retrying): dial tcp 10.228.13.59:5044: getsockopt: connection refused my logstash configuration file is input { beats { …

---

## [How to backup "index pattern", "setting of visualization or dashboard" and et al.?](https://discuss.elastic.co/t/how-to-backup-index-pattern-setting-of-visualization-or-dashboard-and-et-al/28755)

<div class="topic-metadata">

**Author:** [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Replies:** 14\
**Last updated:** [September 8, 2015, 10:54am UTC](https://discuss.elastic.co/t/how-to-backup-index-pattern-setting-of-visualization-or-dashboard-and-et-al/28755 "2015-09-08T10:54:22Z")

</div>

Hi all, After I updating license (Extend Shield and Watcher License), all of kibana setting (Web operations) are gone, I don't know why? I would like to backup kibana setting (Web operations), is it possible or some…

---

## [Could not get Windows Performance Counters since Metricbeats 7.3.0](https://discuss.elastic.co/t/could-not-get-windows-performance-counters-since-metricbeats-7-3-0/198676)

<div class="topic-metadata">

**Author:** [@jbeyer](https://discuss.elastic.co/u/jbeyer)\
**Replies:** 19\
**Last updated:** [December 19, 2019, 2:06pm UTC](https://discuss.elastic.co/t/could-not-get-windows-performance-counters-since-metricbeats-7-3-0/198676 "2019-12-19T14:06:41Z")

</div>

I use Metricbeats to send Windows Perfomance Counters, like processor time and private bytes to elasticsearch. Until Metricbeats version 7.2.0 it runs well, but the same configuration doesn't run in version 7.3.0 and 7.3…

---

## [Simple queries takes lots of time and uses 100% cpu](https://discuss.elastic.co/t/simple-queries-takes-lots-of-time-and-uses-100-cpu/206243)

<div class="topic-metadata">

**Author:** [@aimarjg](https://discuss.elastic.co/u/aimarjg)\
**Replies:** 33\
**Last updated:** [December 2, 2019, 9:38am UTC](https://discuss.elastic.co/t/simple-queries-takes-lots-of-time-and-uses-100-cpu/206243 "2019-12-02T09:38:20Z")

</div>

Hi! I'm having an issue with filtering data gathered using winlogbeat to ES - whenever I want to filter for single host.name or winlog.computer\_name (kinda the same) only for last 24 hours - it takes more than 60 000ms …

---

## [Installing Elasticsearch on Ubuntu 24](https://discuss.elastic.co/t/installing-elasticsearch-on-ubuntu-24/372215)

<div class="topic-metadata">

**Author:** [@Fredb69](https://discuss.elastic.co/u/Fredb69)\
**Replies:** 11\
**Last updated:** [June 15, 2025, 10:12pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-on-ubuntu-24/372215 "2025-06-15T22:12:06Z")

</div>

Hi I want installing Elasticsearch on Ubuntu 24 but I have a problem with the PGP Key. The message is : W: Erreur de GPG : https://artifacts.elastic.co/packages/8.x/apt stable InRelease : Les signatures suivantes n'on…

---

## [Configure JDBC Input plugin for logstash](https://discuss.elastic.co/t/configure-jdbc-input-plugin-for-logstash/127593)

<div class="topic-metadata">

**Author:** [@pvderivco](https://discuss.elastic.co/u/pvderivco)\
**Replies:** 14\
**Last updated:** [April 12, 2018, 10:25am UTC](https://discuss.elastic.co/t/configure-jdbc-input-plugin-for-logstash/127593 "2018-04-12T10:25:33Z")

</div>

I am exploring my knowledge on configuring input plugins to my logstash. I have a docker container with elk running on it. I was successfully able to create metric beats and fetch logs from a REST API and create visualiz…

---

## [Search request's timeout doesn't work as expected](https://discuss.elastic.co/t/search-requests-timeout-doesnt-work-as-expected/328247)

<div class="topic-metadata">

**Author:** [@hari-ram-s](https://discuss.elastic.co/u/hari-ram-s)\
**Replies:** 17\
**Last updated:** [March 26, 2023, 7:24pm UTC](https://discuss.elastic.co/t/search-requests-timeout-doesnt-work-as-expected/328247 "2023-03-26T19:24:21Z")

</div>

ES Verson: 7.15.0 We were exploring the significant\_text plugin of ES (via REST API) for generating word cloud from our data. As the query took more time to execute, we decided to use a timeout. Here is what the officia…

---

## [Elasticsearch aggregation OOM](https://discuss.elastic.co/t/elasticsearch-aggregation-oom/71001)

<div class="topic-metadata">

**Author:** [@abhijith\_reddy](https://discuss.elastic.co/u/abhijith_reddy)\
**Replies:** 22\
**Last updated:** [January 15, 2017, 9:05pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregation-oom/71001 "2017-01-15T21:05:07Z")

</div>

I am trying to debug an OOM issue that happens when we try to run some expensive aggregations. The aggregation looks like this { "aggs":{ "name":{ "terms":{ "field":"name", "min\_doc…

---

## [High CPU (cgroup) usage/utilization](https://discuss.elastic.co/t/high-cpu-cgroup-usage-utilization/258964)

<div class="topic-metadata">

**Author:** [@NejcK](https://discuss.elastic.co/u/NejcK)\
**Replies:** 19\
**Last updated:** [March 16, 2021, 8:34am UTC](https://discuss.elastic.co/t/high-cpu-cgroup-usage-utilization/258964 "2021-03-16T08:34:09Z")

</div>

Hi. We have only one node in our cluster (hosted on Elastic cloud, v7.10.0) with Kibana (for filebeat and metricbeat) and everything was working fine until about last week. I'm pretty new to all this, but I've set up al…

---

## [Upgrade from elastic 1.3.2 to 2.3.1 and more space for the indexes](https://discuss.elastic.co/t/upgrade-from-elastic-1-3-2-to-2-3-1-and-more-space-for-the-indexes/49437)

<div class="topic-metadata">

**Author:** [@saiprasad\_mishra](https://discuss.elastic.co/u/saiprasad_mishra)\
**Replies:** 32\
**Last updated:** [June 5, 2016, 3:26am UTC](https://discuss.elastic.co/t/upgrade-from-elastic-1-3-2-to-2-3-1-and-more-space-for-the-indexes/49437 "2016-06-05T03:26:59Z")

</div>

Hi All I am seeing double the space when we migrated data for one index in es 1.3.2 version to 2.3.1 version even with doc\_values false for our non analyzed fields The index size was 772 GB in 1.3.2 and it became 1.3…

---

## [High CPU Usage on a few data nodes / Hotspotting of data](https://discuss.elastic.co/t/high-cpu-usage-on-a-few-data-nodes-hotspotting-of-data/383954)

<div class="topic-metadata">

**Author:** [@Lakshya\_Gupta](https://discuss.elastic.co/u/Lakshya_Gupta)\
**Replies:** 191\
**Last updated:** [January 14, 2026, 6:48am UTC](https://discuss.elastic.co/t/high-cpu-usage-on-a-few-data-nodes-hotspotting-of-data/383954 "2026-01-14T06:48:45Z")

</div>

Hi team, we have an Elastic Search Cluster with the following configurations ES Version 7.17.0 60 data nodes cluster 50 primary shards and 2 replica for each primary shards Here, we are using a particular custom routi…

---

## [To store and search a File content using elastic search](https://discuss.elastic.co/t/to-store-and-search-a-file-content-using-elastic-search/237062)

<div class="topic-metadata">

**Author:** [@Romy\_Bobby](https://discuss.elastic.co/u/Romy_Bobby)\
**Replies:** 11\
**Last updated:** [June 15, 2020, 12:18pm UTC](https://discuss.elastic.co/t/to-store-and-search-a-file-content-using-elastic-search/237062 "2020-06-15T12:18:53Z")

</div>

Hi, My requirement is an FAQ in my application where I require to Upload FAQ documents and later search and find these documents using the keywords in search cloumn. I Would like to know how to store and search a File c…

[Previous page](https://discuss.elastic.co/top.md?page=41&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=43&per_page=50&period=all)
