# Top

**URL:** https://discuss.elastic.co/top.md?page=43&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 44

---

## [Logstash - Méthode pour debugger les grokparsefailure](https://discuss.elastic.co/t/logstash-methode-pour-debugger-les-grokparsefailure/159353)

<div class="topic-metadata">

**Author:** [@MikaMinn](https://discuss.elastic.co/u/MikaMinn)\
**Replies:** 15\
**Last updated:** [January 16, 2019, 10:18am UTC](https://discuss.elastic.co/t/logstash-methode-pour-debugger-les-grokparsefailure/159353 "2019-01-16T10:18:56Z")

</div>

Bonjour à tous ! Je débute depuis plusieurs heures sur le parsing des log logstash. C'est peut-être une question très anodine pour vous mais je cherche les "best practice" pour parser mes logs et surtout rechercher les …

---

## [Problem with monitoring x-pack](https://discuss.elastic.co/t/problem-with-monitoring-x-pack/91112)

<div class="topic-metadata">

**Author:** [@Benjamin\_Peere](https://discuss.elastic.co/u/Benjamin_Peere)\
**Replies:** 19\
**Last updated:** [July 25, 2017, 5:12pm UTC](https://discuss.elastic.co/t/problem-with-monitoring-x-pack/91112 "2017-07-25T17:12:47Z")

</div>

hello! i actually have a problem with monitoring, i can't access it, i have the following message : here is what the logs says, i don't understand at all: Bad Request :: {"path":"\_xpack/security/user/\_has\_privileges…

---

## [CAP theorem](https://discuss.elastic.co/t/cap-theorem/3014)

<div class="topic-metadata">

**Author:** [@talsalmona](https://discuss.elastic.co/u/talsalmona)\
**Replies:** 10\
**Last updated:** [June 20, 2010, 9:56pm UTC](https://discuss.elastic.co/t/cap-theorem/3014 "2010-06-20T21:56:00Z")

</div>

Hi, According to the CAP theorem (http://en.wikipedia.org/wiki/CAP\_theorem and http://books.couchdb.org/relax/intro/eventual-consistency), ElasticSearch can satisfy two of the following: \* Consistency \* Availabili…

---

## [Автоматическое удаление старых индексов](https://discuss.elastic.co/t/topic/203209)

<div class="topic-metadata">

**Author:** [@beren](https://discuss.elastic.co/u/beren)\
**Replies:** 9\
**Last updated:** [October 11, 2019, 1:22pm UTC](https://discuss.elastic.co/t/topic/203209 "2019-10-11T13:22:04Z")

</div>

Всем привет. Как удалять индексы старше n дней. Гугл привёл https://serveradmin.ru/ochistka-elasticsearch-s-pomoshhyu-curator/ Но если так делать, то данные из индекса удаляться, но сам индекс в Kibana будет висеть.

---

## [Metricbeat is not capturing CPU and DISK information](https://discuss.elastic.co/t/metricbeat-is-not-capturing-cpu-and-disk-information/153075)

<div class="topic-metadata">

**Author:** [@chandukreddi](https://discuss.elastic.co/u/chandukreddi)\
**Replies:** 20\
**Last updated:** [November 19, 2018, 5:33pm UTC](https://discuss.elastic.co/t/metricbeat-is-not-capturing-cpu-and-disk-information/153075 "2018-11-19T17:33:47Z")

</div>

Hello Team, I have enabled system module in metricbeat but all I see is Processora details in Elasticsearch but I don;t find anything CPU/CORE/DISK related information captured. any idea? system.yml Dell-TMO-CT-Cass1…

---

## [Logstash Pipeline from 6.1 not working 6.2.1](https://discuss.elastic.co/t/logstash-pipeline-from-6-1-not-working-6-2-1/120548)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 37\
**Last updated:** [March 24, 2018, 3:50am UTC](https://discuss.elastic.co/t/logstash-pipeline-from-6-1-not-working-6-2-1/120548 "2018-03-24T03:50:18Z")

</div>

This is exhausting.... Creating a guide and started a new ElasticStack setup from scratch, new VMs and all. Installed ElasticStack 6.2.1 with each application on it's own VM. Started Logstash with my pipeline with no …

---

## [Using ES as a distributed datastore to only store binary data (mainly JPG, PNG, SVG), basically replacing our use of GlusterFs](https://discuss.elastic.co/t/using-es-as-a-distributed-datastore-to-only-store-binary-data-mainly-jpg-png-svg-basically-replacing-our-use-of-glusterfs/11129)

<div class="topic-metadata">

**Author:** [@Stephane\_Bastian](https://discuss.elastic.co/u/Stephane_Bastian)\
**Replies:** 12\
**Last updated:** [May 27, 2013, 11:49pm UTC](https://discuss.elastic.co/t/using-es-as-a-distributed-datastore-to-only-store-binary-data-mainly-jpg-png-svg-basically-replacing-our-use-of-glusterfs/11129 "2013-05-27T23:49:39Z")

</div>

Hello All, I know the idea of replacing GlusterFs with ES may sound funny... or even plain silly but let me give you some background first We've been using ES for almost 2 years now and are extremely pleased with…

---

## [How to authenticate user to elasticsearch based on PKI](https://discuss.elastic.co/t/how-to-authenticate-user-to-elasticsearch-based-on-pki/184121)

<div class="topic-metadata">

**Author:** [@kartmsb](https://discuss.elastic.co/u/kartmsb)\
**Replies:** 17\
**Last updated:** [June 7, 2019, 3:19am UTC](https://discuss.elastic.co/t/how-to-authenticate-user-to-elasticsearch-based-on-pki/184121 "2019-06-07T03:19:34Z")

</div>

Hi I am newbie to elasticsearch. And I was trying to enable security and PKI based authentication in elasticsearch. I am using 6.5.1 es. And following "https://www.elastic.co/blog/elasticsearch-security-configure-tls-s…

---

## [Illegal\_state\_exception is preventing deletion of watches](https://discuss.elastic.co/t/illegal-state-exception-is-preventing-deletion-of-watches/55085)

<div class="topic-metadata">

**Author:** [@JohnMunson](https://discuss.elastic.co/u/JohnMunson)\
**Replies:** 20\
**Last updated:** [August 2, 2016, 10:59pm UTC](https://discuss.elastic.co/t/illegal-state-exception-is-preventing-deletion-of-watches/55085 "2016-08-02T22:59:24Z")

</div>

Hi. In searching for a solution to my problem, I found this post from last November: This is my problem exactly. But the solution isn't included in the post, and when I tried using the force option as suggested by @m…

---

## [Elasticsearch data node fail to join the cluster](https://discuss.elastic.co/t/elasticsearch-data-node-fail-to-join-the-cluster/110710)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 14\
**Last updated:** [December 12, 2017, 5:17pm UTC](https://discuss.elastic.co/t/elasticsearch-data-node-fail-to-join-the-cluster/110710 "2017-12-12T17:17:23Z")

</div>

Hello I have an elasticsearch 6.0.0 cluster running on GCE environment and I want to add a data node but this node is failing to join the cluster. I am getting the following in the logs: 2017-12-07T15:50:42,782\]\[WARN …

---

## [Some lines sent to Logstash are truncated](https://discuss.elastic.co/t/some-lines-sent-to-logstash-are-truncated/79900)

<div class="topic-metadata">

**Author:** [@Pierre\_Vincent\_Ledou](https://discuss.elastic.co/u/Pierre_Vincent_Ledou)\
**Replies:** 14\
**Last updated:** [May 22, 2017, 11:51am UTC](https://discuss.elastic.co/t/some-lines-sent-to-logstash-are-truncated/79900 "2017-05-22T11:51:52Z")

</div>

Hi, I'm parsing a lot of old logs files. All logs are in gz, so I have to uncompress then move it a folder watched by filebeat. On about 30millions of entries, I have about 1300 failures in logstash logs. I'm logging…

---

## [Change the default master connection timeout of 30s to 60s](https://discuss.elastic.co/t/change-the-default-master-connection-timeout-of-30s-to-60s/297311)

<div class="topic-metadata">

**Author:** [@elastic78](https://discuss.elastic.co/u/elastic78)\
**Replies:** 15\
**Last updated:** [February 17, 2022, 11:11pm UTC](https://discuss.elastic.co/t/change-the-default-master-connection-timeout-of-30s-to-60s/297311 "2022-02-17T23:11:33Z")

</div>

Hi, I am using Elasticsearch 5.5.2 version and when the node 2 is trying to connect to the master node node 1 I am getting the below error. I had opened this thread - Getting ConnectTimeoutException When joining in clust…

---

## [Can we index images with extension types like .jpeg,.img,jpg in elasticsearch?](https://discuss.elastic.co/t/can-we-index-images-with-extension-types-like-jpeg-img-jpg-in-elasticsearch/195678)

<div class="topic-metadata">

**Author:** [@pyerunka](https://discuss.elastic.co/u/pyerunka)\
**Replies:** 34\
**Last updated:** [September 27, 2019, 9:37am UTC](https://discuss.elastic.co/t/can-we-index-images-with-extension-types-like-jpeg-img-jpg-in-elasticsearch/195678 "2019-09-27T09:37:38Z")

</div>

Hello, Can we index images with extension types like .jpeg,.img,jpg in elasticsearch? If yes, then can anyone explain how i can achieve it? Thanks & Regards, Priyanka Yerunkar.

---

## [Logstash on Windows - Multiple Pipeline Problem](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846)

<div class="topic-metadata">

**Author:** [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Replies:** 18\
**Last updated:** [March 21, 2018, 3:12pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846 "2018-03-21T15:12:22Z")

</div>

Is it possible to run multiple pipelines on the Windows version of Logstash? I can’t seem to get this to work for the life of me. I have installed Logstash on Windows, and placed a pipelines.yml file in C:\\Program Files…

---

## [File beat fails to send events to logstash](https://discuss.elastic.co/t/file-beat-fails-to-send-events-to-logstash/48885)

<div class="topic-metadata">

**Author:** [@sarathymv](https://discuss.elastic.co/u/sarathymv)\
**Replies:** 16\
**Last updated:** [May 9, 2016, 1:40pm UTC](https://discuss.elastic.co/t/file-beat-fails-to-send-events-to-logstash/48885 "2016-05-09T13:40:42Z")

</div>

File beat is not sending events to logstash after a while. Initially when i setup the filebeat (three instances) it was successfully sending the events to logstash after a couple of hours it thrown an error message "send…

---

## [Elasticsearch certificate error when access with public ip](https://discuss.elastic.co/t/elasticsearch-certificate-error-when-access-with-public-ip/315213)

<div class="topic-metadata">

**Author:** [@jay.annapureddy](https://discuss.elastic.co/u/jay.annapureddy)\
**Replies:** 13\
**Last updated:** [October 3, 2022, 4:26pm UTC](https://discuss.elastic.co/t/elasticsearch-certificate-error-when-access-with-public-ip/315213 "2022-10-03T16:26:49Z")

</div>

Hi, Problem: Elasticsearch cluster url having a certificate error, needed this to configure on beats on other vm. I am experimenting it on Azure VM with ubuntu operating system. Followed this official guide to install…

---

## [Filebeat 2 hours latency](https://discuss.elastic.co/t/filebeat-2-hours-latency/81741)

<div class="topic-metadata">

**Author:** [@aqiao](https://discuss.elastic.co/u/aqiao)\
**Replies:** 16\
**Last updated:** [April 28, 2017, 2:45pm UTC](https://discuss.elastic.co/t/filebeat-2-hours-latency/81741 "2017-04-28T14:45:09Z")

</div>

{"@timestamp":"2017-04-07T18:22:59.075Z","beat":{"hostname":"localhost","name":"localhost","version":"5.2.1"},"input\_type":"log","message":"2017-04-07T15:19:29.670Z,RACI,EURAB6E15Y=QQ,BRKR,CheckFID=22;Rate=1.083;FID2=25;…

---

## [Watcher that counts the documents that arrive to an index in kibana](https://discuss.elastic.co/t/watcher-that-counts-the-documents-that-arrive-to-an-index-in-kibana/270609)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 45\
**Last updated:** [April 24, 2021, 2:06am UTC](https://discuss.elastic.co/t/watcher-that-counts-the-documents-that-arrive-to-an-index-in-kibana/270609 "2021-04-24T02:06:21Z")

</div>

I have a problem with this watcher, I need to get the number of samples of an index, that is, the count of the documents sent by heartbeat to kibana and send an email every day with the number of documents that arrived t…

---

## [Using my own document\_id - is there a faster way?](https://discuss.elastic.co/t/using-my-own-document-id-is-there-a-faster-way/108667)

<div class="topic-metadata">

**Author:** [@elastic\_paul](https://discuss.elastic.co/u/elastic_paul)\
**Replies:** 25\
**Last updated:** [November 29, 2017, 6:24am UTC](https://discuss.elastic.co/t/using-my-own-document-id-is-there-a-faster-way/108667 "2017-11-29T06:24:54Z")

</div>

Hi Everyone, For years I have been using my own document \_id to de-duplicate my data. The principle is that I use a ruby filter to create a unique hash of the IP address and the SHA fingerprint, and use this as the docu…

---

## [Unavailable\_shards\_exception and primary shard is not active](https://discuss.elastic.co/t/unavailable-shards-exception-and-primary-shard-is-not-active/173899)

<div class="topic-metadata">

**Author:** [@nageswar](https://discuss.elastic.co/u/nageswar)\
**Replies:** 10\
**Last updated:** [March 26, 2019, 12:40pm UTC](https://discuss.elastic.co/t/unavailable-shards-exception-and-primary-shard-is-not-active/173899 "2019-03-26T12:40:17Z")

</div>

Hi All, My Elasticsearch data is keep getting corrupted and latest data will be not available. For this temporarily we are solving like if you delete the last date data then it allows logstash to send the data into el…

---

## [New replica are not getting assigned](https://discuss.elastic.co/t/new-replica-are-not-getting-assigned/93450)

<div class="topic-metadata">

**Author:** [@Dhara\_Desai](https://discuss.elastic.co/u/Dhara_Desai)\
**Replies:** 23\
**Last updated:** [July 24, 2017, 10:29pm UTC](https://discuss.elastic.co/t/new-replica-are-not-getting-assigned/93450 "2017-07-24T22:29:26Z")

</div>

I use kopf for visualization, and I tried changing the number of replica setting for an index from 17 to 20, making the replication group of 21 using kopf. (total 20 primary shards + 3 availability zones) The observation…

---

## [Create Cluster with Nodes in Different Server](https://discuss.elastic.co/t/create-cluster-with-nodes-in-different-server/42977)

<div class="topic-metadata">

**Author:** [@gringo](https://discuss.elastic.co/u/gringo)\
**Replies:** 21\
**Last updated:** [March 3, 2016, 6:18am UTC](https://discuss.elastic.co/t/create-cluster-with-nodes-in-different-server/42977 "2016-03-03T06:18:55Z")

</div>

Is there any documentation that mention how this is done. All the webpages that I can find out there cannot work. Is this feature still available on elasticsearch? If yes. Can someone point me to the right place?

---

## [How to upsert an initial value into elasticsearch using spark?](https://discuss.elastic.co/t/how-to-upsert-an-initial-value-into-elasticsearch-using-spark/29450)

<div class="topic-metadata">

**Author:** [@Terran\_Yiu](https://discuss.elastic.co/u/Terran_Yiu)\
**Replies:** 13\
**Last updated:** [September 26, 2015, 2:35pm UTC](https://discuss.elastic.co/t/how-to-upsert-an-initial-value-into-elasticsearch-using-spark/29450 "2015-09-26T14:35:55Z")

</div>

With HTTP POST, the following script can insert a new field createtime or update lastupdatetime: curl -XPOST 'localhost:9200/test/type1/1/\_update' -d '{ "doc": { "lastupdatetime": "2015-09-16T18:00:00" } "upsert" :…

---

## [Remote Access to Elastic Search](https://discuss.elastic.co/t/remote-access-to-elastic-search/108108)

<div class="topic-metadata">

**Author:** [@sancroth](https://discuss.elastic.co/u/sancroth)\
**Replies:** 9\
**Last updated:** [November 17, 2017, 12:32pm UTC](https://discuss.elastic.co/t/remote-access-to-elastic-search/108108 "2017-11-17T12:32:34Z")

</div>

I have created a demo server to play around and i am trying to make elasticsearch remotely accessible for some services of mine. I have set network.host : 0.0.0.0 -\> not working network.host : xxx.xxx.xxx.xxx -\> not w…

---

## [Filebeat Registry Issue](https://discuss.elastic.co/t/filebeat-registry-issue/195268)

<div class="topic-metadata">

**Author:** [@monica2](https://discuss.elastic.co/u/monica2)\
**Replies:** 9\
**Last updated:** [August 22, 2019, 6:44pm UTC](https://discuss.elastic.co/t/filebeat-registry-issue/195268 "2019-08-22T18:44:57Z")

</div>

I am using filbeat version 7.2.0. Using Docker . I am succesfully creating image and running iamge without any issues. But I am having issues on registry file. I specified the registry file to be /etc/filebeat/data/regi…

---

## [Es 5 node cannot join the master node](https://discuss.elastic.co/t/es-5-node-cannot-join-the-master-node/82692)

<div class="topic-metadata">

**Author:** [@karim](https://discuss.elastic.co/u/karim)\
**Replies:** 37\
**Last updated:** [April 21, 2017, 10:39am UTC](https://discuss.elastic.co/t/es-5-node-cannot-join-the-master-node/82692 "2017-04-21T10:39:32Z")

</div>

I configured two-node cluster with one master node. It's Red Hat servers. Unfortunately second node cannot join to the master node. Here is configuration of master node: Use a descriptive name for the node: node.name…

---

## [Date format incorrect results](https://discuss.elastic.co/t/date-format-incorrect-results/40643)

<div class="topic-metadata">

**Author:** [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Replies:** 22\
**Last updated:** [February 15, 2016, 3:55pm UTC](https://discuss.elastic.co/t/date-format-incorrect-results/40643 "2016-02-15T15:55:32Z")

</div>

hi, I want to do date filter and search. My mapping : $myTypeMapping\['properties'\]\['mydate'\]\['type'\]='date'; $myTypeMapping\['properties'\]\['mydate'\]\['index'\]='analyzed'; $myTypeMapping\['properties'\]\['mydate'\]\[…

---

## [Collapse with multi value](https://discuss.elastic.co/t/collapse-with-multi-value/270437)

<div class="topic-metadata">

**Author:** [@arcturuscom](https://discuss.elastic.co/u/arcturuscom)\
**Replies:** 13\
**Last updated:** [April 21, 2021, 11:15am UTC](https://discuss.elastic.co/t/collapse-with-multi-value/270437 "2021-04-21T11:15:16Z")

</div>

Hello, i tried to collapse multivalued field and its doesnt work e.g: "field": \[id1, id2, id3\] i'm asking if there's a workaround to solve this issue. any suggestions please !!

---

## [Logstash update @timestamp](https://discuss.elastic.co/t/logstash-update-timestamp/77816)

<div class="topic-metadata">

**Author:** [@Exocomp](https://discuss.elastic.co/u/Exocomp)\
**Replies:** 9\
**Last updated:** [March 9, 2017, 3:27pm UTC](https://discuss.elastic.co/t/logstash-update-timestamp/77816 "2017-03-09T15:27:28Z")

</div>

Hi, I have a field that is already a datetime field: "last\_execution\_time" =\> 2017-03-08T12:19:14.593Z, I would like this field to be the value of @timestamp. When I try: mutate { update =\> { "@timestamp" =\> …

---

## [Logstash not showing out put again](https://discuss.elastic.co/t/logstash-not-showing-out-put-again/48279)

<div class="topic-metadata">

**Author:** [@sarbjeet](https://discuss.elastic.co/u/sarbjeet)\
**Replies:** 12\
**Last updated:** [April 27, 2016, 7:44am UTC](https://discuss.elastic.co/t/logstash-not-showing-out-put-again/48279 "2016-04-27T07:44:18Z")

</div>

hi... when i run logstash config file .it display output but when we run it again then no output displayed. its new for me. i installed logstash 2.2,elasticsearch 2.2 and kibana 1.4. plz reply soon .its urgent.

---

## [Filebeat is not reading the log file in real time](https://discuss.elastic.co/t/filebeat-is-not-reading-the-log-file-in-real-time/261270)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 13\
**Last updated:** [January 19, 2021, 4:00pm UTC](https://discuss.elastic.co/t/filebeat-is-not-reading-the-log-file-in-real-time/261270 "2021-01-19T16:00:40Z")

</div>

Hello Team, We setup new elasticsearch cluster with version 7.10 and beats version is also 7.10. When we setup the cluster it was working fine and we were getting the logs on kibana dashboard in real time. But now we …

---

## [Bad Gateway Errors in Discover in Kibana 6.4 on some indices](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576)

<div class="topic-metadata">

**Author:** [@mikesparr](https://discuss.elastic.co/u/mikesparr)\
**Replies:** 16\
**Last updated:** [September 11, 2018, 4:07am UTC](https://discuss.elastic.co/t/bad-gateway-errors-in-discover-in-kibana-6-4-on-some-indices/146576 "2018-09-11T04:07:43Z")

</div>

After upgrading to 6.4 in Elastic Cloud, and using the Discover feature in Kibana, indices are now displaying "Bad Gateway" errors. If the timespan is short and there are no records, the "no records" correctly displays. …

---

## [Scripted field with division does not show result](https://discuss.elastic.co/t/scripted-field-with-division-does-not-show-result/97246)

<div class="topic-metadata">

**Author:** [@doume06](https://discuss.elastic.co/u/doume06)\
**Replies:** 13\
**Last updated:** [September 6, 2017, 7:43pm UTC](https://discuss.elastic.co/t/scripted-field-with-division-does-not-show-result/97246 "2017-09-06T19:43:02Z")

</div>

HI, I have created a very simple scripted field in Kibana 5 to make the division of two other fields (numeric) and the result doesn't show up. The scripted field is defined this way: I tried to replace the division …

---

## [Initializing\_shards got struck](https://discuss.elastic.co/t/initializing-shards-got-struck/252511)

<div class="topic-metadata">

**Author:** [@muthug](https://discuss.elastic.co/u/muthug)\
**Replies:** 30\
**Last updated:** [October 20, 2020, 8:55am UTC](https://discuss.elastic.co/t/initializing-shards-got-struck/252511 "2020-10-20T08:55:34Z")

</div>

Hi Team, initializing\_shards got struck, if i delete those shards wat will happen? it will become Green and will work smoothly? Kibana link is working for some time and its showing error timeout 30000ms some time. { …

---

## ["PollError \[illegal\_argument\_exception\]](https://discuss.elastic.co/t/pollerror-illegal-argument-exception/174017)

<div class="topic-metadata">

**Author:** [@sblancocr](https://discuss.elastic.co/u/sblancocr)\
**Replies:** 11\
**Last updated:** [March 28, 2019, 1:24pm UTC](https://discuss.elastic.co/t/pollerror-illegal-argument-exception/174017 "2019-03-28T13:24:24Z")

</div>

Hi. I have a Kibana server, that this configuration: server.port: 5601 server.host: "log-kibana-01.alpha.ci.ucr.ac.cr" server.name: "log-kibana-01.alpha.ci.ucr.ac.cr" elasticsearch.hosts: \["http://log-elasticsearch-…

---

## [Kibana url not working. FATAL Error: \[config validation of \[elasticsearch\].username\]: value of "elastic" is forbidden. This is a superuser account that cannot write to system indices that Kibana needs to function. Use a service account token instead](https://discuss.elastic.co/t/kibana-url-not-working-fatal-error-config-validation-of-elasticsearch-username-value-of-elastic-is-forbidden-this-is-a-superuser-account-that-cannot-write-to-system-indices-that-kibana-needs-to-function-use-a-service-account-token-instead/317026)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 13\
**Last updated:** [November 18, 2022, 12:28am UTC](https://discuss.elastic.co/t/kibana-url-not-working-fatal-error-config-validation-of-elasticsearch-username-value-of-elastic-is-forbidden-this-is-a-superuser-account-that-cannot-write-to-system-indices-that-kibana-needs-to-function-use-a-service-account-token-instead/317026 "2022-11-18T00:28:06Z")

</div>

Hi Team, Kindly help here how can i fix this. ? Previously, ELK failed due to an error "java.lang. IllegalStateException: A node cannot be upgraded directly from version \[7.10.2\] to version \[8.4.3\], it must first be…

---

## [Slow Cluster in Elastic Cloud since updating to 7.12](https://discuss.elastic.co/t/slow-cluster-in-elastic-cloud-since-updating-to-7-12/268844)

<div class="topic-metadata">

**Author:** [@marcosvrrs](https://discuss.elastic.co/u/marcosvrrs)\
**Replies:** 25\
**Last updated:** [April 23, 2021, 2:18pm UTC](https://discuss.elastic.co/t/slow-cluster-in-elastic-cloud-since-updating-to-7-12/268844 "2021-04-23T14:18:24Z")

</div>

Hi guys, Since we updated our cluster we noticed that it's very slow, and we didn't increase the data volume or the number of shards. In my logs in Elastic Cloud one kind of message keeps repeating: \[instance-00000000…

---

## [Unable to start elasticsearch after creating cert for http communication](https://discuss.elastic.co/t/unable-to-start-elasticsearch-after-creating-cert-for-http-communication/175037)

<div class="topic-metadata">

**Author:** [@Gruido](https://discuss.elastic.co/u/Gruido)\
**Replies:** 14\
**Last updated:** [April 5, 2019, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-after-creating-cert-for-http-communication/175037 "2019-04-05T15:28:35Z")

</div>

Hello, I'm a noob at ES and learning from different angles in troubleshooting ES. My error here are two but first, is that I've install elasticsearch 6.7 deb. version on ubuntu 18.04. The second is xpack security error …

---

## [Как поменять количество шардов?](https://discuss.elastic.co/t/topic/171914)

<div class="topic-metadata">

**Author:** [@KOTOXJle6](https://discuss.elastic.co/u/KOTOXJle6)\
**Replies:** 18\
**Last updated:** [March 22, 2019, 6:51pm UTC](https://discuss.elastic.co/t/topic/171914 "2019-03-22T18:51:28Z")

</div>

Добрый день. У меня настроен кластер из одного сервера, в нем добавлено несколько паттернов индексов. Каждый день при создании нового индекса в нём появляются 5 лишних шардов. Первое время я их чистил вручную командой …

---

## [Index.routing.allocation.disable\_allocation in Elastic Search 5.2](https://discuss.elastic.co/t/index-routing-allocation-disable-allocation-in-elastic-search-5-2/80603)

<div class="topic-metadata">

**Author:** [@tomer](https://discuss.elastic.co/u/tomer)\
**Replies:** 17\
**Last updated:** [March 30, 2017, 8:45am UTC](https://discuss.elastic.co/t/index-routing-allocation-disable-allocation-in-elastic-search-5-2/80603 "2017-03-30T08:45:55Z")

</div>

Hi, I got a problem of many "unassigned shards". So through some reading I tryed to do : index.routing.allocation.disable\_allocation= false This returned me: index.routing.allocation.disable\_allocation please check …

---

## [X-pack not working on new ELK stack](https://discuss.elastic.co/t/x-pack-not-working-on-new-elk-stack/105093)

<div class="topic-metadata">

**Author:** [@carlfriedrichgauss](https://discuss.elastic.co/u/carlfriedrichgauss)\
**Replies:** 12\
**Last updated:** [October 26, 2017, 4:06pm UTC](https://discuss.elastic.co/t/x-pack-not-working-on-new-elk-stack/105093 "2017-10-26T16:06:49Z")

</div>

ES and Kibana on 5.6.3 ... Everything in the cluster seems to be working fine, except in the browser I get the error: Login is currently disabled because the license could not be determined. Please check that Elasticsea…

---

## [Delete/update nested documents with elasticsearch Java API](https://discuss.elastic.co/t/delete-update-nested-documents-with-elasticsearch-java-api/11523)

<div class="topic-metadata">

**Author:** [@Andrei\_Tolnai](https://discuss.elastic.co/u/Andrei_Tolnai)\
**Replies:** 11\
**Last updated:** [October 28, 2014, 6:34am UTC](https://discuss.elastic.co/t/delete-update-nested-documents-with-elasticsearch-java-api/11523 "2014-10-28T06:34:25Z")

</div>

Hello. I use \*Elastic Search Java API \*for basic \*CRUD \*operations on ES documents; with \*root type\* documents it is working fine. However when I want to delete a nested document, I don't know how to use the \*J…

---

## [MDC logs, ELK and filebeat](https://discuss.elastic.co/t/mdc-logs-elk-and-filebeat/222413)

<div class="topic-metadata">

**Author:** [@ash2](https://discuss.elastic.co/u/ash2)\
**Replies:** 9\
**Last updated:** [March 6, 2020, 4:30pm UTC](https://discuss.elastic.co/t/mdc-logs-elk-and-filebeat/222413 "2020-03-06T16:30:08Z")

</div>

Hi, I am new to Elastic stack. I am trying to creating a log management system. And while searching I came across MDC. So, I want to know about MDC logs and how it is useful in respect of filebeat or logstash log parsin…

---

## [Skip first few lines in file](https://discuss.elastic.co/t/skip-first-few-lines-in-file/38198)

<div class="topic-metadata">

**Author:** [@tweetybird](https://discuss.elastic.co/u/tweetybird)\
**Replies:** 10\
**Last updated:** [January 4, 2016, 3:38pm UTC](https://discuss.elastic.co/t/skip-first-few-lines-in-file/38198 "2016-01-04T15:38:34Z")

</div>

Is it possible to to skip (ie. not send them to logstash) lines in a log file? The log I'm working with has 4 lines at the top which I would like to ignore and not send to logstash. Is this possible?

---

## [BitSet.or consumes almost 60% cpu](https://discuss.elastic.co/t/bitset-or-consumes-almost-60-cpu/286763)

<div class="topic-metadata">

**Author:** [@chembohuang](https://discuss.elastic.co/u/chembohuang)\
**Replies:** 23\
**Last updated:** [October 19, 2021, 11:25am UTC](https://discuss.elastic.co/t/bitset-or-consumes-almost-60-cpu/286763 "2021-10-19T11:25:40Z")

</div>

ES 7.7.1, jdk 14. We have two nodes with the same hardware(physical machine) under the same cluster which only hosts one index with 1 replica. Each node has the same shard. The weird thing is that, one of the machine'…

---

## [Disk and file system usage collection using Logstash](https://discuss.elastic.co/t/disk-and-file-system-usage-collection-using-logstash/43731)

<div class="topic-metadata">

**Author:** [@gabe](https://discuss.elastic.co/u/gabe)\
**Replies:** 17\
**Last updated:** [March 9, 2016, 8:34am UTC](https://discuss.elastic.co/t/disk-and-file-system-usage-collection-using-logstash/43731 "2016-03-09T08:34:21Z")

</div>

Hi All, Looking for some help to implement disk and file system (files and directories) usage collection by Logstash and storage in Elasticsearch. Basically, data processing workflows that we want to evaluate server …

---

## [Getting nested object with json filter](https://discuss.elastic.co/t/getting-nested-object-with-json-filter/215921)

<div class="topic-metadata">

**Author:** [@toms130](https://discuss.elastic.co/u/toms130)\
**Replies:** 9\
**Last updated:** [January 22, 2020, 10:49am UTC](https://discuss.elastic.co/t/getting-nested-object-with-json-filter/215921 "2020-01-22T10:49:16Z")

</div>

Hi all, I've got problem when trying to get some nested fields in a json object with json filter. My field look like this { "total\_count" : 3, "orders" : \[ { "marketplace\_order\_id" : "malikilledme3", "order\_line…

---

## [Index writer memory Continue to rise](https://discuss.elastic.co/t/index-writer-memory-continue-to-rise/213514)

<div class="topic-metadata">

**Author:** [@ITzhangqiang](https://discuss.elastic.co/u/ITzhangqiang)\
**Replies:** 21\
**Last updated:** [January 15, 2020, 4:08pm UTC](https://discuss.elastic.co/t/index-writer-memory-continue-to-rise/213514 "2020-01-15T16:08:11Z")

</div>

hi，all： I have a question that has puzzled me for a long time。 One node in the cluster has too much index writer memory (other node is fline), and it keeps going up,and it lead to index throttling . And then I adju…

---

## [Fuzzy Search not working as intended](https://discuss.elastic.co/t/fuzzy-search-not-working-as-intended/80489)

<div class="topic-metadata">

**Author:** [@amlanrath](https://discuss.elastic.co/u/amlanrath)\
**Replies:** 10\
**Last updated:** [March 30, 2017, 6:56pm UTC](https://discuss.elastic.co/t/fuzzy-search-not-working-as-intended/80489 "2017-03-30T18:56:41Z")

</div>

I changed the default Fuzziness logic of ES from Fuzziness.AUTO to my own which is as follows - 0-3 - no edits allowed or Fuzziness.ZERO 4-10 - 1 edit allowed or Fuzziness.ONE 10+ - 2 edits allowed or Fuzziness.TWO E…

---

## [How to update the geoip with the new?](https://discuss.elastic.co/t/how-to-update-the-geoip-with-the-new/124205)

<div class="topic-metadata">

**Author:** [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Replies:** 16\
**Last updated:** [March 20, 2018, 1:06am UTC](https://discuss.elastic.co/t/how-to-update-the-geoip-with-the-new/124205 "2018-03-20T01:06:26Z")

</div>

how to update the geoip with the new? can give a docs? i find some iP in my geoip can't output the city.

[Previous page](https://discuss.elastic.co/top.md?page=42&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=44&per_page=50&period=all)
