# Top

**URL:** https://discuss.elastic.co/top.md?page=44&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 45

---

## [Query to calculate successrate](https://discuss.elastic.co/t/query-to-calculate-successrate/98886)

<div class="topic-metadata">

**Author:** [@mathias](https://discuss.elastic.co/u/mathias)\
**Replies:** 9\
**Last updated:** [September 1, 2017, 8:09am UTC](https://discuss.elastic.co/t/query-to-calculate-successrate/98886 "2017-09-01T08:09:09Z")

</div>

Hi, I am struggling with elasticsearch aggregation queries. I would like to calculate successrate per hour between two different events. I have one event with a field “name” with the value “attempt” each time an attem…

---

## [Docker\[ELK+Filebeat\] =\> No logs](https://discuss.elastic.co/t/docker-elk-filebeat-no-logs/40946)

<div class="topic-metadata">

**Author:** [@Ragnar](https://discuss.elastic.co/u/Ragnar)\
**Replies:** 10\
**Last updated:** [April 29, 2016, 2:48pm UTC](https://discuss.elastic.co/t/docker-elk-filebeat-no-logs/40946 "2016-04-29T14:48:42Z")

</div>

Hi everyone, I'm learning how to use ELK so I decided to do my own Hello world. I planned to make some graph with my syslog/auth.log I also decided to put every services in a Docker's container. I set up everything…

---

## [Stored procedure in Elastic search](https://discuss.elastic.co/t/stored-procedure-in-elastic-search/165882)

<div class="topic-metadata">

**Author:** [@Raghunadhan](https://discuss.elastic.co/u/Raghunadhan)\
**Replies:** 10\
**Last updated:** [February 11, 2019, 8:29am UTC](https://discuss.elastic.co/t/stored-procedure-in-elastic-search/165882 "2019-02-11T08:29:49Z")

</div>

Dear All, I from relational database background. In MySQL we use to store datas in database based on conditions for requirements.We used to write script that is stored procedures .Using stored procedure we used to store…

---

## [Not able to take snapshot](https://discuss.elastic.co/t/not-able-to-take-snapshot/25208)

<div class="topic-metadata">

**Author:** [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Replies:** 10\
**Last updated:** [July 10, 2015, 5:49am UTC](https://discuss.elastic.co/t/not-able-to-take-snapshot/25208 "2015-07-10T05:49:01Z")

</div>

Hi Experts, I am not able to take snapshot of ES index. This is what I have done 1) I have created one folder and then shared this to every one with read and write permission . 2) Now I mention this path in ES.yml fil…

---

## [Node experiencing relatively high CPU usage](https://discuss.elastic.co/t/node-experiencing-relatively-high-cpu-usage/8540)

<div class="topic-metadata">

**Author:** [@Nitish\_Sharma](https://discuss.elastic.co/u/Nitish_Sharma)\
**Replies:** 26\
**Last updated:** [October 11, 2012, 8:59am UTC](https://discuss.elastic.co/t/node-experiencing-relatively-high-cpu-usage/8540 "2012-10-11T08:59:28Z")

</div>

HI, We have a 5-node ES cluster. On one particular node ES process is consuming 600-700% CPU (8 cores) all the time. While other nodes' CPU usage is always below 100%. We are running 0.19.8 and each node has equal n…

---

## [JSON Webhooks](https://discuss.elastic.co/t/json-webhooks/1024)

<div class="topic-metadata">

**Author:** [@flecno](https://discuss.elastic.co/u/flecno)\
**Replies:** 9\
**Last updated:** [November 10, 2016, 6:58am UTC](https://discuss.elastic.co/t/json-webhooks/1024 "2016-11-10T06:58:11Z")

</div>

Hey, I try to build a simple Hipchat notification by using webhooks. If I use simple static messages my notifications arrive. How do I create a JSON payload body with mustache? I tried the follwing configuration: "w…

---

## [Read line error: invalid CRI log; filbeat halts processing logs](https://discuss.elastic.co/t/read-line-error-invalid-cri-log-filbeat-halts-processing-logs/146284)

<div class="topic-metadata">

**Author:** [@Jarek\_Miszkinis](https://discuss.elastic.co/u/Jarek_Miszkinis)\
**Replies:** 11\
**Last updated:** [August 31, 2018, 10:12am UTC](https://discuss.elastic.co/t/read-line-error-invalid-cri-log-filbeat-halts-processing-logs/146284 "2018-08-31T10:12:25Z")

</div>

Some log files trigger following error mesg and stops the log file from being processed: filebeat-vng6q filebeat 2018-08-28T07:32:54.968Z ERROR log/harvester.go:275 Read line error: invalid CRI log; File: /var/lib/docke…

---

## [Shards Failed | Most of the recent indexes are unassigned](https://discuss.elastic.co/t/shards-failed-most-of-the-recent-indexes-are-unassigned/203994)

<div class="topic-metadata">

**Author:** [@Sundaramoorthy\_Anand](https://discuss.elastic.co/u/Sundaramoorthy_Anand)\
**Replies:** 13\
**Last updated:** [October 29, 2019, 12:07pm UTC](https://discuss.elastic.co/t/shards-failed-most-of-the-recent-indexes-are-unassigned/203994 "2019-10-29T12:07:10Z")

</div>

I have a server with ELK along with heartbeat installed. (all are v6.4.2) Heartbeat is monitoring two other servers' elasticsearch and logstash with its pipeline in same domainfrom current server. It is creating index …

---

## [File beat keeps crashing](https://discuss.elastic.co/t/file-beat-keeps-crashing/141234)

<div class="topic-metadata">

**Author:** [@mugil1988](https://discuss.elastic.co/u/mugil1988)\
**Replies:** 17\
**Last updated:** [August 15, 2018, 6:48am UTC](https://discuss.elastic.co/t/file-beat-keeps-crashing/141234 "2018-08-15T06:48:58Z")

</div>

Hi Team, We have installed filebeats to ship logs to logstash..we haven't faced any issues for first 3 months.. From last week, file beat is keep crashing for every 5 minutes. There is no error in file beat logs and l…

---

## [Space is getting filled. Need some information how to clear/re-claim the space](https://discuss.elastic.co/t/space-is-getting-filled-need-some-information-how-to-clear-re-claim-the-space/129647)

<div class="topic-metadata">

**Author:** [@Tamal\_Kundu](https://discuss.elastic.co/u/Tamal_Kundu)\
**Replies:** 28\
**Last updated:** [May 8, 2018, 5:40am UTC](https://discuss.elastic.co/t/space-is-getting-filled-need-some-information-how-to-clear-re-claim-the-space/129647 "2018-05-08T05:40:18Z")

</div>

Hi , We have Elasticserch for monitoring our services for business production. But the space is getting filled after a while. We are facing this issue quite often. Need to know if there is a way we can claim or clear th…

---

## [Dynamic configuration of logstash](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358)

<div class="topic-metadata">

**Author:** [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)\
**Replies:** 11\
**Last updated:** [April 14, 2016, 7:08am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358 "2016-04-14T07:08:03Z")

</div>

Hi, Is there anyway to load logstash configuration dynamically using database or some filesystem. ? The usecase is lets say i have multiple apaches where I am getting data from and I am getting data with their ips (eac…

---

## [Illegal character in authority at index 8:](https://discuss.elastic.co/t/illegal-character-in-authority-at-index-8/243795)

<div class="topic-metadata">

**Author:** [@elaair](https://discuss.elastic.co/u/elaair)\
**Replies:** 12\
**Last updated:** [August 5, 2020, 6:37pm UTC](https://discuss.elastic.co/t/illegal-character-in-authority-at-index-8/243795 "2020-08-05T18:37:09Z")

</div>

I am using logstash 7.8 and am seeing this error while using the elasticsearch filter: :error=\>"Illegal character in authority at index 8: https://{:host=\>\\"fqdn.here.com\\", :scheme=\>\\"https\\", :protocol=\>\\"https\\", :po…

---

## [Kibana Word Cloud on Text Field](https://discuss.elastic.co/t/kibana-word-cloud-on-text-field/250523)

<div class="topic-metadata">

**Author:** [@spyderman4g63](https://discuss.elastic.co/u/spyderman4g63)\
**Replies:** 10\
**Last updated:** [October 2, 2020, 7:21am UTC](https://discuss.elastic.co/t/kibana-word-cloud-on-text-field/250523 "2020-10-02T07:21:16Z")

</div>

I'm trying to create a word cloud on a text field called "message". This is my configuration for the field in elasticsearch: { "my\_index" : { "mappings" : { "message" : { "full\_name" : "message", …

---

## [Logstash not starting properly](https://discuss.elastic.co/t/logstash-not-starting-properly/120235)

<div class="topic-metadata">

**Author:** [@motts](https://discuss.elastic.co/u/motts)\
**Replies:** 12\
**Last updated:** [February 19, 2018, 9:27pm UTC](https://discuss.elastic.co/t/logstash-not-starting-properly/120235 "2018-02-19T21:27:28Z")

</div>

Hello there, I am trying to start LogStash 5.6 with /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d but when I do, I get several of these errors \[ERROR\] 2018-02-16 13:50:24.556 \[\[main\]\<tcp\] pipeline - A plugin…

---

## [ES5.0a1: The \[string\] type is removed in 5.0. You should now use either a \[text\] or \[keyword\] field instead for field](https://discuss.elastic.co/t/es5-0a1-the-string-type-is-removed-in-5-0-you-should-now-use-either-a-text-or-keyword-field-instead-for-field/47305)

<div class="topic-metadata">

**Author:** [@gquintana](https://discuss.elastic.co/u/gquintana)\
**Replies:** 13\
**Last updated:** [May 11, 2016, 7:44am UTC](https://discuss.elastic.co/t/es5-0a1-the-string-type-is-removed-in-5-0-you-should-now-use-either-a-text-or-keyword-field-instead-for-field/47305 "2016-05-11T07:44:54Z")

</div>

Hello, I am just trying out Elasticsearch 5.0 Alpha 1, I can not create an index because type string is removed. $ curl -XPUT "http://localhost:9200/monument?pretty" --data-binary @monument.settings.json { "error"…

---

## [How to fix primary-replica inconsistency?](https://discuss.elastic.co/t/how-to-fix-primary-replica-inconsistency/9016)

<div class="topic-metadata">

**Author:** [@arta](https://discuss.elastic.co/u/arta)\
**Replies:** 18\
**Last updated:** [April 14, 2014, 9:02am UTC](https://discuss.elastic.co/t/how-to-fix-primary-replica-inconsistency/9016 "2014-04-14T09:02:56Z")

</div>

Hi, I have a problem as same as described in here: http://elasticsearch-users.115913.n3.nabble.com/BUG-Alternating-result-set-across-every-query-tt4021027.html The same search query returns one document, then ne…

---

## [Impossible to set password for elastic builtin superuser](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 13\
**Last updated:** [October 27, 2022, 7:11am UTC](https://discuss.elastic.co/t/impossible-to-set-password-for-elastic-builtin-superuser/317305 "2022-10-27T07:11:51Z")

</div>

Hi, I just install elasticsearch 8.4.1 from elasticsearch-8.4.1-1.x86\_64 RPM on a Red Hat Enterprise Linux release 8.6 (Ootpa) server. Everything looks ok, elastic service is running. But I cannot find the elastic use…

---

## [Filtering Windows Event Logs](https://discuss.elastic.co/t/filtering-windows-event-logs/60889)

<div class="topic-metadata">

**Author:** [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Replies:** 10\
**Last updated:** [September 21, 2016, 11:41am UTC](https://discuss.elastic.co/t/filtering-windows-event-logs/60889 "2016-09-21T11:41:16Z")

</div>

Hi, I am creating a POC of ELK for analysing windows event logs. I am not getting how to apply filters on these event logs. Is there any pattern defined to be directly used in the Grok filter like for Syslogs? If not…

---

## [Проблемы производительности кластера. Оптимизация](https://discuss.elastic.co/t/topic/131468)

<div class="topic-metadata">

**Author:** [@111126](https://discuss.elastic.co/u/111126)\
**Replies:** 13\
**Last updated:** [June 6, 2018, 7:54am UTC](https://discuss.elastic.co/t/topic/131468 "2018-06-06T07:54:07Z")

</div>

Добрый день. Есть кластер (весь кластер базируется на ОС CentOs 6.9) в составе которого: Дата нода 1 (на хардварном сервере): 24 CPU X5660 @ 2.80GHz RAM 96Gb На ней стоит es со следующими параметрами: elastic (node.…

---

## [C# Elasticsearch 8.0.3+ 400 Bad Request media\_type\_header\_exception](https://discuss.elastic.co/t/c-elasticsearch-8-0-3-400-bad-request-media-type-header-exception/322816)

<div class="topic-metadata">

**Author:** [@KoalaBear](https://discuss.elastic.co/u/KoalaBear)\
**Replies:** 11\
**Last updated:** [January 27, 2023, 12:08pm UTC](https://discuss.elastic.co/t/c-elasticsearch-8-0-3-400-bad-request-media-type-header-exception/322816 "2023-01-27T12:08:39Z")

</div>

Just started with a new small project with Elasticsearch, while developing Elasticsearch it is currently running in Docker (docker-elk), with the added "http.cors" things: http.cors.enabled: true http.cors.allow-origin:…

---

## [Elastic agent on Raspberry Pi](https://discuss.elastic.co/t/elastic-agent-on-raspberry-pi/305182)

<div class="topic-metadata">

**Author:** [@l3keboy](https://discuss.elastic.co/u/l3keboy)\
**Replies:** 15\
**Last updated:** [May 31, 2022, 6:55pm UTC](https://discuss.elastic.co/t/elastic-agent-on-raspberry-pi/305182 "2022-05-31T18:55:39Z")

</div>

Hello All! I am trying to install the elastic agent to a raspberry pi and trying to enroll it onto our fleet server. When trying to install the agent I get the error: ./elastic-agent: 1: Syntax error: word unexpected (…

---

## [Error while starting elasticsearch](https://discuss.elastic.co/t/error-while-starting-elasticsearch/180551)

<div class="topic-metadata">

**Author:** [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Replies:** 16\
**Last updated:** [May 31, 2019, 7:38am UTC](https://discuss.elastic.co/t/error-while-starting-elasticsearch/180551 "2019-05-31T07:38:18Z")

</div>

Whenever I am trying to start elasticsearch7.0 via systemctl it give me an error: elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; enabled; vendor preset: disabled) …

---

## [Конфигурация Threadpool](https://discuss.elastic.co/t/threadpool/51054)

<div class="topic-metadata">

**Author:** [@Evgeny\_Lazarev](https://discuss.elastic.co/u/Evgeny_Lazarev)\
**Replies:** 27\
**Last updated:** [June 3, 2016, 6:37pm UTC](https://discuss.elastic.co/t/threadpool/51054 "2016-06-03T18:37:55Z")

</div>

Добрый день. Разбираюсь с возможными конфигурациями ES. Сейчас пытаюсь играться с настройками для ускорения заливки данных (hdfs -\> elasticsearch-spark -\> ES). Пытался пару раз изменять настройки threadpool.bulk (увеличи…

---

## [ES indexing rate varies horribly](https://discuss.elastic.co/t/es-indexing-rate-varies-horribly/38414)

<div class="topic-metadata">

**Author:** [@Kenny\_Qiao](https://discuss.elastic.co/u/Kenny_Qiao)\
**Replies:** 19\
**Last updated:** [March 5, 2016, 5:22pm UTC](https://discuss.elastic.co/t/es-indexing-rate-varies-horribly/38414 "2016-03-05T17:22:55Z")

</div>

Here is one example of my indexing rates for "latest 15 minutes" . I have 5 data nodes with ES2.1. I've no idea why indexing behaved like this periodically(from ~80,000/s to zero and then back to ~80,000/s). Is it …

---

## [ERR SSL client failed to connect with: read tcp](https://discuss.elastic.co/t/err-ssl-client-failed-to-connect-with-read-tcp/50156)

<div class="topic-metadata">

**Author:** [@evmiguel](https://discuss.elastic.co/u/evmiguel)\
**Replies:** 10\
**Last updated:** [May 12, 2017, 11:27am UTC](https://discuss.elastic.co/t/err-ssl-client-failed-to-connect-with-read-tcp/50156 "2017-05-12T11:27:32Z")

</div>

Hello, I'm running into SSL issues when trying to connect to logstash: 2016/05/16 20:44:56.611376 log.go:113: INFO Harvester started for file: /var/log/messages 2016/05/16 20:44:56.612388 spooler.go:77: INFO Starting…

---

## [Logstash default template for elasticsearch output](https://discuss.elastic.co/t/logstash-default-template-for-elasticsearch-output/26526)

<div class="topic-metadata">

**Author:** [@pavan\_bkv](https://discuss.elastic.co/u/pavan_bkv)\
**Replies:** 12\
**Last updated:** [August 3, 2015, 9:38pm UTC](https://discuss.elastic.co/t/logstash-default-template-for-elasticsearch-output/26526 "2015-08-03T21:38:59Z")

</div>

So using logstash exec input (JSON response) to output to an elasticsearch cluster (using the default mapping template). Somehow even though the resultant EXEC event has a @timestamp, my mapping misses it and hence mak…

---

## [Scientific notation in incoming data](https://discuss.elastic.co/t/scientific-notation-in-incoming-data/59517)

<div class="topic-metadata">

**Author:** [@dkspace](https://discuss.elastic.co/u/dkspace)\
**Replies:** 11\
**Last updated:** [September 8, 2016, 2:06pm UTC](https://discuss.elastic.co/t/scientific-notation-in-incoming-data/59517 "2016-09-08T14:06:40Z")

</div>

Dear colleagues. do you know the maximum possible number of fields for index ? In my case i have over 200 from the fluentd configured but in Kibana indexes i have Fields (45) only visible . Is there some limitation for …

---

## [Event Correlation \\ populate one field with data from other field in elasticsearch](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372)

<div class="topic-metadata">

**Author:** [@shaigb](https://discuss.elastic.co/u/shaigb)\
**Replies:** 17\
**Last updated:** [July 19, 2016, 8:11am UTC](https://discuss.elastic.co/t/event-correlation-populate-one-field-with-data-from-other-field-in-elasticsearch/55372 "2016-07-19T08:11:02Z")

</div>

Hi, i'm looking to do correlation searches in elastic (kibana 4.4 actually) is there a way to have a search like the following - 1 - find all ip addresses from a certain type (lets say from critical stack intel, via file…

---

## [Need help with setting up Apache2 to monitor the session time on every website](https://discuss.elastic.co/t/need-help-with-setting-up-apache2-to-monitor-the-session-time-on-every-website/147145)

<div class="topic-metadata">

**Author:** [@Lee\_Weng\_Sheng](https://discuss.elastic.co/u/Lee_Weng_Sheng)\
**Replies:** 41\
**Last updated:** [November 6, 2018, 11:20am UTC](https://discuss.elastic.co/t/need-help-with-setting-up-apache2-to-monitor-the-session-time-on-every-website/147145 "2018-11-06T11:20:43Z")

</div>

Hi, I'm new to this Kibana/logstash stuff, and due to the current situation, so I'm seeking some help here. My objective: Setting up Apache2 on Kibana/Logstash server so that I can get the following information from t…

---

## [Hourly index for filebeat](https://discuss.elastic.co/t/hourly-index-for-filebeat/68299)

<div class="topic-metadata">

**Author:** [@lolo67](https://discuss.elastic.co/u/lolo67)\
**Replies:** 12\
**Last updated:** [December 8, 2016, 1:59pm UTC](https://discuss.elastic.co/t/hourly-index-for-filebeat/68299 "2016-12-08T13:59:29Z")

</div>

Hello, I want hourly Filebeat indices. In the doc for filebeat.yml, I only see : index =\> "%{\[@metadata\]\[beat\]}-%{+YYYY.MM.dd}" I tried with output: logstash: hosts: \["elk-docker:5044"\] index: 'filebeat-%{+…

---

## [Problem with the date-filter (timezone)](https://discuss.elastic.co/t/problem-with-the-date-filter-timezone/85145)

<div class="topic-metadata">

**Author:** [@prime](https://discuss.elastic.co/u/prime)\
**Replies:** 16\
**Last updated:** [May 10, 2017, 2:05pm UTC](https://discuss.elastic.co/t/problem-with-the-date-filter-timezone/85145 "2017-05-10T14:05:52Z")

</div>

Hi, i'm new to elk, so it may be a layer 8 problem, but i'm not able to fix it. So i hope here's somebody able to help me. So currently the date-filter in my logstash config is not doing what i expect. I import csv File…

---

## [Elasticsearch Not Working](https://discuss.elastic.co/t/elasticsearch-not-working/18516)

<div class="topic-metadata">

**Author:** [@shriyansh\_jain](https://discuss.elastic.co/u/shriyansh_jain)\
**Replies:** 11\
**Last updated:** [July 8, 2014, 10:40pm UTC](https://discuss.elastic.co/t/elasticsearch-not-working/18516 "2014-07-08T22:40:06Z")

</div>

When I am verifying the elastic-search status, its giving me the following error message. \*elasticsearch dead but subsys locked\* Please help me out solving this. Thank you. Shriyansh Jain -- You receive…

---

## [Packetbeat on windows 10 : error connecting to kibana, fail to get the kibana version : HTTP GET request to http://192.168.217.128:5601](https://discuss.elastic.co/t/packetbeat-on-windows-10-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-192-168-217-128-5601/303655)

<div class="topic-metadata">

**Author:** [@TARIK\_MAZOUZ](https://discuss.elastic.co/u/TARIK_MAZOUZ)\
**Replies:** 21\
**Last updated:** [May 3, 2022, 5:17pm UTC](https://discuss.elastic.co/t/packetbeat-on-windows-10-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-http-192-168-217-128-5601/303655 "2022-05-03T17:17:34Z")

</div>

hey everybody, so i do have a problem with packetbeat in my windows 10 VM, so when i execute the command is powershell as an administrator , .\\packetbeat.exe setup -e , the error i get is : Exiting: error connecting to …

---

## [Logstash output and multiple destinations (elasticsearch and local file)](https://discuss.elastic.co/t/logstash-output-and-multiple-destinations-elasticsearch-and-local-file/58895)

<div class="topic-metadata">

**Author:** [@somerandomguy](https://discuss.elastic.co/u/somerandomguy)\
**Replies:** 9\
**Last updated:** [September 3, 2016, 1:19am UTC](https://discuss.elastic.co/t/logstash-output-and-multiple-destinations-elasticsearch-and-local-file/58895 "2016-09-03T01:19:54Z")

</div>

Hello. I have a requirement to send beats to multiple locations, ES (which is workning fine) and to a local file (that will be processed by another system). For the local file I might need to format it out of JSON format…

---

## [Modify json field](https://discuss.elastic.co/t/modify-json-field/168961)

<div class="topic-metadata">

**Author:** [@manasapp](https://discuss.elastic.co/u/manasapp)\
**Replies:** 11\
**Last updated:** [February 19, 2019, 12:56pm UTC](https://discuss.elastic.co/t/modify-json-field/168961 "2019-02-19T12:56:53Z")

</div>

Hi Everyone, I need to add one timestamp value to JSON. i share u code n output input { stdin{} } filter{ if (\[message\] =~ "{\\"index") { drop {} } json { source …

---

## [Data Import Fail: Can't merge a non object mapping](https://discuss.elastic.co/t/data-import-fail-cant-merge-a-non-object-mapping/196545)

<div class="topic-metadata">

**Author:** [@0x00](https://discuss.elastic.co/u/0x00)\
**Replies:** 13\
**Last updated:** [August 27, 2019, 12:51am UTC](https://discuss.elastic.co/t/data-import-fail-cant-merge-a-non-object-mapping/196545 "2019-08-27T00:51:09Z")

</div>

First, apologies if this is a simple question, kinda new to this still. Help is greatly appreciated. I am attempting to import zeek/bro logs via the data visualizer and for the most part, most things seem to be going ok…

---

## [Cannot login to Kibana with elastic login](https://discuss.elastic.co/t/cannot-login-to-kibana-with-elastic-login/190561)

<div class="topic-metadata">

**Author:** [@jstewart\_lsa](https://discuss.elastic.co/u/jstewart_lsa)\
**Replies:** 10\
**Last updated:** [July 17, 2019, 1:34pm UTC](https://discuss.elastic.co/t/cannot-login-to-kibana-with-elastic-login/190561 "2019-07-17T13:34:12Z")

</div>

I'm trying to setup Elasticsearch and Kibana v7.2 in GKE using the elastic helm-charts. I've followed the instructions to enable security on these pages: https://github.com/elastic/helm-charts/blob/master/elasticsearch/…

---

## [Configuration keys](https://discuss.elastic.co/t/configuration-keys/229280)

<div class="topic-metadata">

**Author:** [@compengineer](https://discuss.elastic.co/u/compengineer)\
**Replies:** 14\
**Last updated:** [April 27, 2020, 4:11pm UTC](https://discuss.elastic.co/t/configuration-keys/229280 "2020-04-27T16:11:44Z")

</div>

I am getting a fatal error. FATAL Error: Unknown configuration key(s): "elastic.username", "elastic.password". Check for spelling errors. I have already added the correct configuration keys. I have no idea where kiba…

---

## [How to create grok/json filter to parse the below json format](https://discuss.elastic.co/t/how-to-create-grok-json-filter-to-parse-the-below-json-format/296022)

<div class="topic-metadata">

**Author:** [@Adabi\_Raihan](https://discuss.elastic.co/u/Adabi_Raihan)\
**Replies:** 9\
**Last updated:** [February 2, 2022, 8:49am UTC](https://discuss.elastic.co/t/how-to-create-grok-json-filter-to-parse-the-below-json-format/296022 "2022-02-02T08:49:28Z")

</div>

Hi Guys, I want to parse this JSON to Kibana using Logstash { "Format": "IDEA0", "ID": "2b03eb1f-fc4c-4f67-94e5-31c9fb32dccc", "DetectTime": "2022-01-31T08:16:12.600470+07:00", "EventTime": "2022-01-31T01:23:01.637438+…

---

## [Filebeat didn't parse log file](https://discuss.elastic.co/t/filebeat-didnt-parse-log-file/127062)

<div class="topic-metadata">

**Author:** [@Slop](https://discuss.elastic.co/u/Slop)\
**Replies:** 21\
**Last updated:** [May 15, 2018, 1:32pm UTC](https://discuss.elastic.co/t/filebeat-didnt-parse-log-file/127062 "2018-05-15T13:32:16Z")

</div>

I've created new log files recently, but I didn't succeed to having them harvest by filebeat. Currently filebeat haverst two tomcat log files. Here's my filebeat.yml : - input\_type: log # Paths that should be crawl…

---

## [CentOS 7: Metadata file does not match checksum during yum update](https://discuss.elastic.co/t/centos-7-metadata-file-does-not-match-checksum-during-yum-update/284913)

<div class="topic-metadata">

**Author:** [@Daniel\_S](https://discuss.elastic.co/u/Daniel_S)\
**Replies:** 21\
**Last updated:** [September 23, 2021, 9:10am UTC](https://discuss.elastic.co/t/centos-7-metadata-file-does-not-match-checksum-during-yum-update/284913 "2021-09-23T09:10:27Z")

</div>

Hi, I am getting an error message: elasticsearch-7.x/primary FAILED https://artifacts.elastic.co/packages/7.x/yum/repodata/primary.xml.gz: \[Errno -1\] Metadata file does no…

---

## [SearchContextMissingException during long scroll/scan operations?](https://discuss.elastic.co/t/searchcontextmissingexception-during-long-scroll-scan-operations/23775)

<div class="topic-metadata">

**Author:** [@ptrei](https://discuss.elastic.co/u/ptrei)\
**Replies:** 10\
**Last updated:** [December 18, 2017, 12:58pm UTC](https://discuss.elastic.co/t/searchcontextmissingexception-during-long-scroll-scan-operations/23775 "2017-12-18T12:58:18Z")

</div>

Does anyone else have problems with SearchContextMissingExceptions in scroll/scan operations? I have logstash indices which each contain 10s of millions of records. I need to walk over the entire index, processing data…

---

## [3/6 shards failing when trying to visualize on Kibana](https://discuss.elastic.co/t/3-6-shards-failing-when-trying-to-visualize-on-kibana/191857)

<div class="topic-metadata">

**Author:** [@sarahvo](https://discuss.elastic.co/u/sarahvo)\
**Replies:** 14\
**Last updated:** [July 29, 2019, 6:41pm UTC](https://discuss.elastic.co/t/3-6-shards-failing-when-trying-to-visualize-on-kibana/191857 "2019-07-29T18:41:50Z")

</div>

Hi, I'm currently trying to do a simple POC for a potential monitoring system for my company using the Elastic stack. I have metricbeat & winlogbeat going through Logstash, which ships to Elasticsearch. I'm currently onl…

---

## [\[FORBIDDEN/12/index read-only / allow delete (api)\];"})](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113)

<div class="topic-metadata">

**Author:** [@Yashwant\_Shettigar](https://discuss.elastic.co/u/Yashwant_Shettigar)\
**Replies:** 9\
**Last updated:** [December 26, 2018, 2:46pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/162113 "2018-12-26T14:46:36Z")

</div>

Can someone please let me know where I can exactly apply these settings in 6.5, as I'm totally new to ELK : And are these steps applicable on 6.5 version ? Thank you

---

## [ES allocates primary shards on the same data node](https://discuss.elastic.co/t/es-allocates-primary-shards-on-the-same-data-node/139326)

<div class="topic-metadata">

**Author:** [@Oferkes](https://discuss.elastic.co/u/Oferkes)\
**Replies:** 18\
**Last updated:** [July 11, 2018, 6:54am UTC](https://discuss.elastic.co/t/es-allocates-primary-shards-on-the-same-data-node/139326 "2018-07-11T06:54:56Z")

</div>

Hi, i am creating an index with 10 primary shards and 0 replicas, however ES keeps creating the shards on the same data node. i tried to set cluster.routing.allocation.balance.index to 0.75 but this seem to have no eff…

---

## [Installing Metricbeat Dashboards on Kibana for Amazon Elasticsearch](https://discuss.elastic.co/t/installing-metricbeat-dashboards-on-kibana-for-amazon-elasticsearch/102180)

<div class="topic-metadata">

**Author:** [@mdanner](https://discuss.elastic.co/u/mdanner)\
**Replies:** 12\
**Last updated:** [October 10, 2017, 7:34am UTC](https://discuss.elastic.co/t/installing-metricbeat-dashboards-on-kibana-for-amazon-elasticsearch/102180 "2017-10-10T07:34:23Z")

</div>

I'm trying to install the Sample Kibana Dashboards on an instance of the Amazon Elasticsearch Service. That service is protected by AWS Signature Version 4 Signing. I issued these commands from an EC2 instance of Ubunt…

---

## [Logstash Custom Filters and Patterns](https://discuss.elastic.co/t/logstash-custom-filters-and-patterns/93031)

<div class="topic-metadata">

**Author:** [@thecrimsoncoder](https://discuss.elastic.co/u/thecrimsoncoder)\
**Replies:** 10\
**Last updated:** [July 14, 2017, 12:38pm UTC](https://discuss.elastic.co/t/logstash-custom-filters-and-patterns/93031 "2017-07-14T12:38:13Z")

</div>

Hello All, I am very new to the ELK stack and I have been tasked with parsing out some custom logs. I feel like im on the right track but it keeps breaking and Im not sure what Im doing wrong. Basically what I am trying…

---

## [Unable to bring up Kibana Dashboard](https://discuss.elastic.co/t/unable-to-bring-up-kibana-dashboard/46018)

<div class="topic-metadata">

**Author:** [@seeni](https://discuss.elastic.co/u/seeni)\
**Replies:** 16\
**Last updated:** [April 3, 2016, 4:37pm UTC](https://discuss.elastic.co/t/unable-to-bring-up-kibana-dashboard/46018 "2016-04-03T16:37:21Z")

</div>

when trying to access Kibana for the first time. I have started elasticsearch successfully. Error: Uncaught TypeError: undefined is not a function (http://localhost:5601/bundles/commons.bundle.js?v=9889:32054) at…

---

## [How to run configured pipeline.yml in logstash](https://discuss.elastic.co/t/how-to-run-configured-pipeline-yml-in-logstash/276072)

<div class="topic-metadata">

**Author:** [@sudo-ranjith](https://discuss.elastic.co/u/sudo-ranjith)\
**Replies:** 9\
**Last updated:** [June 28, 2021, 6:27am UTC](https://discuss.elastic.co/t/how-to-run-configured-pipeline-yml-in-logstash/276072 "2021-06-28T06:27:41Z")

</div>

I have configured 2 logstash.conf file in pipelines.yml file, pipeline.id: sys\_log\_1 pipeline.workers: 2 path.config: "D:/Elastic/Logstash/7.12.1/config/logstash\_sys\_1.conf" pipeline.id: sys\_log\_2 pipeline.workers: …

---

## [Filebeat fails to pickup other files](https://discuss.elastic.co/t/filebeat-fails-to-pickup-other-files/51202)

<div class="topic-metadata">

**Author:** [@stecino](https://discuss.elastic.co/u/stecino)\
**Replies:** 23\
**Last updated:** [June 17, 2016, 1:14pm UTC](https://discuss.elastic.co/t/filebeat-fails-to-pickup-other-files/51202 "2016-06-17T13:14:55Z")

</div>

Hello I run into this type of issue: 2016-05-27T20:05:19Z INFO Old file with new name found: /flow\_base\_dir/dump/flows-201605270835.dump is no /flow\_base\_dir/dump/flows-201605272000.dump 2016-05-27T20:05:19Z INFO Detec…

[Previous page](https://discuss.elastic.co/top.md?page=43&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=45&per_page=50&period=all)
