# Top

**URL:** https://discuss.elastic.co/top.md?page=45&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 46

---

## [Visualization in Kibana for floating values](https://discuss.elastic.co/t/visualization-in-kibana-for-floating-values/50246)

<div class="topic-metadata">

**Author:** [@bbhandari0121](https://discuss.elastic.co/u/bbhandari0121)\
**Replies:** 11\
**Last updated:** [May 24, 2016, 6:46pm UTC](https://discuss.elastic.co/t/visualization-in-kibana-for-floating-values/50246 "2016-05-24T18:46:15Z")

</div>

I have the series of the value like .003, .006, .005,.0021 etc in ES indexes. But, when i try to visualize this data, they all tends to divert to zero, meaning line chart are in the zero range. It was working fine prev…

---

## [Filebeat not parsing json in messages](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230)

<div class="topic-metadata">

**Author:** [@utsav2307](https://discuss.elastic.co/u/utsav2307)\
**Replies:** 9\
**Last updated:** [May 8, 2018, 7:33am UTC](https://discuss.elastic.co/t/filebeat-not-parsing-json-in-messages/130230 "2018-05-08T07:33:44Z")

</div>

I have deployed filebeat as a daemonset in Kubernetes for collecting logs and below is my filebeat configuration: - type: log paths: - /var/lib/docker/containers/\*/\*.log multiline.pattern: "^\[\[:s…

---

## [Performance degraded after upgrading to 7.x](https://discuss.elastic.co/t/performance-degraded-after-upgrading-to-7-x/206843)

<div class="topic-metadata">

**Author:** [@hyeteck](https://discuss.elastic.co/u/hyeteck)\
**Replies:** 13\
**Last updated:** [November 11, 2019, 6:54pm UTC](https://discuss.elastic.co/t/performance-degraded-after-upgrading-to-7-x/206843 "2019-11-11T18:54:20Z")

</div>

We were running elasticsearch 6.7.2 and decided to upgrade to 7.x but our performances has degraded since the upgrade. We use the cluster to ingest log data and ship all data via filebeat. Index names contain dates so …

---

## [Filebeat modules - problem with pipeline.json](https://discuss.elastic.co/t/filebeat-modules-problem-with-pipeline-json/103190)

<div class="topic-metadata">

**Author:** [@Miroslav\_Kudlac](https://discuss.elastic.co/u/Miroslav_Kudlac)\
**Replies:** 9\
**Last updated:** [October 16, 2017, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-modules-problem-with-pipeline-json/103190 "2017-10-16T13:16:48Z")

</div>

Hi, I am trying to make my own module, but I have a problem right on the beginning. I tried to write my own pipeline.json file, but after command execution I get this error: filebeat -e --modules test -setup 2017/10/0…

---

## [KIbana : Bypass Autentication for ifames to share in dashboard](https://discuss.elastic.co/t/kibana-bypass-autentication-for-ifames-to-share-in-dashboard/157991)

<div class="topic-metadata">

**Author:** [@rishabh1](https://discuss.elastic.co/u/rishabh1)\
**Replies:** 17\
**Last updated:** [December 4, 2018, 11:39am UTC](https://discuss.elastic.co/t/kibana-bypass-autentication-for-ifames-to-share-in-dashboard/157991 "2018-12-04T11:39:57Z")

</div>

I am using Kibana v6.4.3. I want to share the visualizations created in Kibana as iframes but I don' t want the user to authenteciate to see the dashboards. I read that hitting the POST API - /api/security/v1/login , we…

---

## [How to send CSV from Filebeat to Logstash](https://discuss.elastic.co/t/how-to-send-csv-from-filebeat-to-logstash/81745)

<div class="topic-metadata">

**Author:** [@nathan.tivaci](https://discuss.elastic.co/u/nathan.tivaci)\
**Replies:** 9\
**Last updated:** [April 24, 2017, 7:18am UTC](https://discuss.elastic.co/t/how-to-send-csv-from-filebeat-to-logstash/81745 "2017-04-24T07:18:39Z")

</div>

Hello guys, Please bear with the noobness of this thread. My objective here is to send CSV from Filebeat to Logstash-Elasticsearch-Kibana Here is my Filebeat.yml: - input\_type: log paths: - /var/log/domon…

---

## [Negative number aggregation return wrong results](https://discuss.elastic.co/t/negative-number-aggregation-return-wrong-results/91722)

<div class="topic-metadata">

**Author:** [@Shashi-GS](https://discuss.elastic.co/u/Shashi-GS)\
**Replies:** 19\
**Last updated:** [July 6, 2017, 2:48am UTC](https://discuss.elastic.co/t/negative-number-aggregation-return-wrong-results/91722 "2017-07-06T02:48:40Z")

</div>

Negative number aggregation is returning the wrong results. is there any indexing or searching property needs to be applied for this. Here is the sample data. TOT\_TRAN ACID 2000 0G50044716 -100 0G50044716 118839 1G60…

---

## [How exactly logstash-file-input plugin works?](https://discuss.elastic.co/t/how-exactly-logstash-file-input-plugin-works/113891)

<div class="topic-metadata">

**Author:** [@shreepad](https://discuss.elastic.co/u/shreepad)\
**Replies:** 13\
**Last updated:** [January 16, 2018, 12:49pm UTC](https://discuss.elastic.co/t/how-exactly-logstash-file-input-plugin-works/113891 "2018-01-16T12:49:46Z")

</div>

Hi there, We are facing some delay(5mins to 1hr) between actual log file creation and same log(file) being available in kibana. We are using file input plugin to read logs and elasticsearch as output plugin. Every hour…

---

## [Multiline java exceptions cannot be searchable in Kibana](https://discuss.elastic.co/t/multiline-java-exceptions-cannot-be-searchable-in-kibana/67486)

<div class="topic-metadata">

**Author:** [@himaz.m](https://discuss.elastic.co/u/himaz.m)\
**Replies:** 9\
**Last updated:** [December 1, 2016, 4:40am UTC](https://discuss.elastic.co/t/multiline-java-exceptions-cannot-be-searchable-in-kibana/67486 "2016-12-01T04:40:17Z")

</div>

I'm using filebeat + logstash + elasticsearch + kibana version 5.0 I have a log file with following format; 2016-11-20 06:12:54 | \[ajp-nio-8009-exec-2195\] | ADMIN\_API | INFO | c.i.admin.api.web.FileController - login…

---

## [Combine multiple sources](https://discuss.elastic.co/t/combine-multiple-sources/26795)

<div class="topic-metadata">

**Author:** [@Hornov](https://discuss.elastic.co/u/Hornov)\
**Replies:** 10\
**Last updated:** [December 4, 2015, 11:38am UTC](https://discuss.elastic.co/t/combine-multiple-sources/26795 "2015-12-04T11:38:28Z")

</div>

I've logs from multiple sources for the same user. But I need to report fields of this differents sources. Is it possible to store all this data in the same document ? Thanks

---

## [Logstash date filter in UNIX\_MS from two fields](https://discuss.elastic.co/t/logstash-date-filter-in-unix-ms-from-two-fields/99580)

<div class="topic-metadata">

**Author:** [@Frances\_Buontempo](https://discuss.elastic.co/u/Frances_Buontempo)\
**Replies:** 9\
**Last updated:** [September 7, 2017, 12:59pm UTC](https://discuss.elastic.co/t/logstash-date-filter-in-unix-ms-from-two-fields/99580 "2017-09-07T12:59:30Z")

</div>

I have some data from snort which has two subfields, in an !event¬ fields: “event-microsecond” =\> 289367, “event-second” =\> 1493741082, I am trying to compose these into a float and then tell Elasticsearch it’s the ti…

---

## [Watcher Question -Inserting log message contents into text and email body](https://discuss.elastic.co/t/watcher-question-inserting-log-message-contents-into-text-and-email-body/177500)

<div class="topic-metadata">

**Author:** [@Johnnie843](https://discuss.elastic.co/u/Johnnie843)\
**Replies:** 10\
**Last updated:** [April 24, 2019, 4:05pm UTC](https://discuss.elastic.co/t/watcher-question-inserting-log-message-contents-into-text-and-email-body/177500 "2019-04-24T16:05:29Z")

</div>

I set up a Watcher watch, It is running successfully but I'm trying to insert some contents of the log message into the action text and eventually an email body, is this possible? If so what is the syntax. Thank you for…

---

## [Kibana not showing data from logstash](https://discuss.elastic.co/t/kibana-not-showing-data-from-logstash/89384)

<div class="topic-metadata">

**Author:** [@BrunoC](https://discuss.elastic.co/u/BrunoC)\
**Replies:** 10\
**Last updated:** [June 15, 2017, 9:36am UTC](https://discuss.elastic.co/t/kibana-not-showing-data-from-logstash/89384 "2017-06-15T09:36:59Z")

</div>

Hello, Kibana is not showing anything from logstash, I can create an index but no data comes out. {"reason":"match","flags":"none","rule":"5","type":"syslog","ip\_ver":"4","sub\_rule":"16777216","src\_ip":"192.168.0.152"…

---

## [Log was not appeared in elastic search and kibana](https://discuss.elastic.co/t/log-was-not-appeared-in-elastic-search-and-kibana/175518)

<div class="topic-metadata">

**Author:** [@vinodh023](https://discuss.elastic.co/u/vinodh023)\
**Replies:** 20\
**Last updated:** [April 5, 2019, 8:48am UTC](https://discuss.elastic.co/t/log-was-not-appeared-in-elastic-search-and-kibana/175518 "2019-04-05T08:48:43Z")

</div>

Hi, I new to go language development. In my product development, I want to see the logger in kibana dashboard. I installed elastic search,logstach, kibana and file beat. but unable to get logger in kibana dashboard. Can …

---

## [5.0.0 Using Painless in ESIntegTestCase](https://discuss.elastic.co/t/5-0-0-using-painless-in-esintegtestcase/64447)

<div class="topic-metadata">

**Author:** [@dawi](https://discuss.elastic.co/u/dawi)\
**Replies:** 13\
**Last updated:** [November 14, 2016, 4:28pm UTC](https://discuss.elastic.co/t/5-0-0-using-painless-in-esintegtestcase/64447 "2016-11-14T16:28:03Z")

</div>

Hi together, we are currently updating our application from Elasticsearch 2.4.1 to Elasticsearch 5.0.0 and in the same process we are updating our integration tests to use the ESIntegTestCase as foundation. Everythin…

---

## [Logstash Multiple Pipelines Doesn't work](https://discuss.elastic.co/t/logstash-multiple-pipelines-doesnt-work/110251)

<div class="topic-metadata">

**Author:** [@pavuk](https://discuss.elastic.co/u/pavuk)\
**Replies:** 15\
**Last updated:** [December 7, 2017, 7:40am UTC](https://discuss.elastic.co/t/logstash-multiple-pipelines-doesnt-work/110251 "2017-12-07T07:40:28Z")

</div>

Unfortunately announced Multiple Pipelines feature doesn't work. I have created file # cat /etc/logstash/pipeline.yml - pipeline.id: nginx path.config: "/etc/logstash/conf.d/nginx.conf" #queue.type: persisted - pip…

---

## [How to bump elasticsearch 'processors' setting in order to increase thread\_pool.bulk.size?](https://discuss.elastic.co/t/how-to-bump-elasticsearch-processors-setting-in-order-to-increase-thread-pool-bulk-size/98781)

<div class="topic-metadata">

**Author:** [@Chris\_Bedford](https://discuss.elastic.co/u/Chris_Bedford)\
**Replies:** 11\
**Last updated:** [September 1, 2017, 5:25am UTC](https://discuss.elastic.co/t/how-to-bump-elasticsearch-processors-setting-in-order-to-increase-thread-pool-bulk-size/98781 "2017-09-01T05:25:35Z")

</div>

We've done pretty extensive performance analysis and found that our write heavy-Elasticsearch 5.5.1-based application is under-utilizing CPU resources (load average is about same as number of cores, and we are 25% idle…

---

## [java.lang.OutOfMemoryError: Java heap space - GC overhead using visualizations](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-gc-overhead-using-visualizations/138660)

<div class="topic-metadata">

**Author:** [@akapit](https://discuss.elastic.co/u/akapit)\
**Replies:** 15\
**Last updated:** [July 5, 2018, 10:39am UTC](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-gc-overhead-using-visualizations/138660 "2018-07-05T10:39:51Z")

</div>

I'm running Elastic and kibana on a clean linode instance with 8 GB RAM. Only imported a csv file through logstash into Elasticsearch in a index. Plain text fields with two Dates and some numeric ones. About the index,…

---

## [Kibana weird fail after upgrade to 7.14.0](https://discuss.elastic.co/t/kibana-weird-fail-after-upgrade-to-7-14-0/280686)

<div class="topic-metadata">

**Author:** [@kleckns](https://discuss.elastic.co/u/kleckns)\
**Replies:** 25\
**Last updated:** [August 10, 2021, 1:42pm UTC](https://discuss.elastic.co/t/kibana-weird-fail-after-upgrade-to-7-14-0/280686 "2021-08-10T13:42:16Z")

</div>

Today I upgraded my ES stack from 7.9.3 to 7.14.0. ES and filebeats upgraded with no issues. I have kibana installed on one of the master ES nodes. After upgrading kibana I received the output in the UI. Kibana doesn't a…

---

## [Dashboard taking much time to load](https://discuss.elastic.co/t/dashboard-taking-much-time-to-load/49427)

<div class="topic-metadata">

**Author:** [@bbhandari0121](https://discuss.elastic.co/u/bbhandari0121)\
**Replies:** 10\
**Last updated:** [May 17, 2016, 5:04pm UTC](https://discuss.elastic.co/t/dashboard-taking-much-time-to-load/49427 "2016-05-17T17:04:28Z")

</div>

Hi all, I have 5 nodes ES cluster, and around 45 servers, sending the log to kafka to the ES. I have build around 8 visualization from my log, And saved it into the dashboard. Now, my dashboard is taking much time to lo…

---

## [Is there any length limitation of the key in term aggregation ? I mean results display](https://discuss.elastic.co/t/is-there-any-length-limitation-of-the-key-in-term-aggregation-i-mean-results-display/58024)

<div class="topic-metadata">

**Author:** [@pill663](https://discuss.elastic.co/u/pill663)\
**Replies:** 20\
**Last updated:** [August 18, 2016, 6:09am UTC](https://discuss.elastic.co/t/is-there-any-length-limitation-of-the-key-in-term-aggregation-i-mean-results-display/58024 "2016-08-18T06:09:26Z")

</div>

I have some long string documents stored in elasticsearch(version 2.3). I want to do a term aggregation for my documents. I choose one Field for the term , the records that stored in this field is some long strings. the …

---

## [Aggregation on suggestions results](https://discuss.elastic.co/t/aggregation-on-suggestions-results/65078)

<div class="topic-metadata">

**Author:** [@webpatser](https://discuss.elastic.co/u/webpatser)\
**Replies:** 10\
**Last updated:** [November 10, 2016, 1:10pm UTC](https://discuss.elastic.co/t/aggregation-on-suggestions-results/65078 "2016-11-10T13:10:12Z")

</div>

Hi, How do I aggregate on a suggestions list? I want to 'group by' on the text field returned by the suggest :slight\_smile: I use the \_search endpoint with this as the query { "\_source": "suggest", "suggest": {…

---

## [Netflow module launch errors, some SSL related(?)](https://discuss.elastic.co/t/netflow-module-launch-errors-some-ssl-related/149596)

<div class="topic-metadata">

**Author:** [@SmFs](https://discuss.elastic.co/u/SmFs)\
**Replies:** 12\
**Last updated:** [October 5, 2018, 4:28pm UTC](https://discuss.elastic.co/t/netflow-module-launch-errors-some-ssl-related/149596 "2018-10-05T16:28:43Z")

</div>

Was hoping someone might be able to advise. Running: latest versions of esearch, kibana, and logstash installed via repo plus Oracle Java 1.8.0\_181 on a Ubuntu Server 18.04 VM. I'm trying to set up an ELK stack for ne…

---

## [2 nodes with the same cluster but in configured in different machines](https://discuss.elastic.co/t/2-nodes-with-the-same-cluster-but-in-configured-in-different-machines/42004)

<div class="topic-metadata">

**Author:** [@arianayay](https://discuss.elastic.co/u/arianayay)\
**Replies:** 17\
**Last updated:** [May 4, 2017, 9:58pm UTC](https://discuss.elastic.co/t/2-nodes-with-the-same-cluster-but-in-configured-in-different-machines/42004 "2017-05-04T21:58:38Z")

</div>

I'm about to make 2 nodes with the same cluster but each node is configured in separate elasticsearch.yml in different machines. For the first node is in machine 1: cluster.name: sql node.name: engineering node.master…

---

## [Can we access Elastic Search API over Internet, i.e. Using IP address of server?](https://discuss.elastic.co/t/can-we-access-elastic-search-api-over-internet-i-e-using-ip-address-of-server/39455)

<div class="topic-metadata">

**Author:** [@trushad](https://discuss.elastic.co/u/trushad)\
**Replies:** 9\
**Last updated:** [January 22, 2016, 11:08am UTC](https://discuss.elastic.co/t/can-we-access-elastic-search-api-over-internet-i-e-using-ip-address-of-server/39455 "2016-01-22T11:08:38Z")

</div>

Can we access Elastic Search API over Internet, i.e. Using IP address of server ?

---

## [Parsing multiline logs : line + xml](https://discuss.elastic.co/t/parsing-multiline-logs-line-xml/38417)

<div class="topic-metadata">

**Author:** [@carmelom](https://discuss.elastic.co/u/carmelom)\
**Replies:** 9\
**Last updated:** [January 7, 2016, 12:11pm UTC](https://discuss.elastic.co/t/parsing-multiline-logs-line-xml/38417 "2016-01-07T12:11:46Z")

</div>

Below an example of my logs indent preformatted text by 4 spaces INFO 05-01-16 08:06:01 \[http-nio-8080-exec-8\] (AbstractServer.java:454) - \<dialogue\> \<server\>localhost\</server\> \<duration\>311\</duration\> …

---

## [ElasticSearch Linux startup failed. Procedure](https://discuss.elastic.co/t/elasticsearch-linux-startup-failed-procedure/298799)

<div class="topic-metadata">

**Author:** [@zx\_emo](https://discuss.elastic.co/u/zx_emo)\
**Replies:** 10\
**Last updated:** [March 20, 2022, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-linux-startup-failed-procedure/298799 "2022-03-20T09:47:30Z")

</div>

Elasticsearch has been deployed to Linux and I have encountered a problem with the certificate signing. After following the steps to resolve these problems, I get an exception when I start Elasticsearch. How do I resolve…

---

## [Kibana 4.1.1 not starting](https://discuss.elastic.co/t/kibana-4-1-1-not-starting/40425)

<div class="topic-metadata">

**Author:** [@wby](https://discuss.elastic.co/u/wby)\
**Replies:** 12\
**Last updated:** [January 29, 2016, 10:48pm UTC](https://discuss.elastic.co/t/kibana-4-1-1-not-starting/40425 "2016-01-29T22:48:06Z")

</div>

I'm rebuilding an ELK cluster (3 separate nodes each in AWS for each of logstash, elasticsearch, kibana) with slightly newer versions (the same configs before were working with very little intervention for setup). I'm ge…

---

## [Not able to run elastic search on Server IP](https://discuss.elastic.co/t/not-able-to-run-elastic-search-on-server-ip/167725)

<div class="topic-metadata">

**Author:** [@dheeraj.Kumar](https://discuss.elastic.co/u/dheeraj.Kumar)\
**Replies:** 18\
**Last updated:** [February 26, 2019, 5:22am UTC](https://discuss.elastic.co/t/not-able-to-run-elastic-search-on-server-ip/167725 "2019-02-26T05:22:54Z")

</div>

HI , I am new on ElasticSearch and trying to configure it on Fedora VM, Host machine is Windows 10 Pro. Elastic search ver. 6.6.0 i am able to run elastic search with KIbana on Localhost:9200. but if change "network.…

---

## [Effective Way to Remove Existing Duplicate Documents in ElasticSearch](https://discuss.elastic.co/t/effective-way-to-remove-existing-duplicate-documents-in-elasticsearch/258798)

<div class="topic-metadata">

**Author:** [@test\_tester](https://discuss.elastic.co/u/test_tester)\
**Replies:** 11\
**Last updated:** [December 17, 2020, 11:31pm UTC](https://discuss.elastic.co/t/effective-way-to-remove-existing-duplicate-documents-in-elasticsearch/258798 "2020-12-17T23:31:15Z")

</div>

Hi Everyone, Using aggregation, I am able query out doc\_count: 272152 of duplicates instances in my elasticsearch database. The problem now is if I were to simply run a \_delete\_by\_query, it will delete everything inclu…

---

## [How to add a new relation to an existing join field](https://discuss.elastic.co/t/how-to-add-a-new-relation-to-an-existing-join-field/103827)

<div class="topic-metadata">

**Author:** [@pancs\_li](https://discuss.elastic.co/u/pancs_li)\
**Replies:** 10\
**Last updated:** [October 16, 2017, 3:27am UTC](https://discuss.elastic.co/t/how-to-add-a-new-relation-to-an-existing-join-field/103827 "2017-10-16T03:27:25Z")

</div>

hi，guys I use Elasticsearch and the version is 6.0 ,I created a parent-child relationship field in accordance with the official document.The document said “It is possible to add a new relation to an existing join field.…

---

## [Sudden data loss!](https://discuss.elastic.co/t/sudden-data-loss/12769)

<div class="topic-metadata">

**Author:** [@Amit](https://discuss.elastic.co/u/Amit)\
**Replies:** 14\
**Last updated:** [July 16, 2013, 7:54pm UTC](https://discuss.elastic.co/t/sudden-data-loss/12769 "2013-07-16T19:54:32Z")

</div>

Hi All, I have a elastic search cluster of 2 nodes in my staging environment. both the nodes have following config; cluster.name: Staging node.name: "node1" index.number\_of\_shards: 5 index.number\_of\_replicas:…

---

## [Filebeat for binary files?](https://discuss.elastic.co/t/filebeat-for-binary-files/46479)

<div class="topic-metadata">

**Author:** [@rahin88](https://discuss.elastic.co/u/rahin88)\
**Replies:** 9\
**Last updated:** [September 17, 2020, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-for-binary-files/46479 "2020-09-17T18:52:34Z")

</div>

Hello Folks, I am new to whole Logstash/ELK. But I am wondering if I can use filebeat for streaming binary data to network ? Here is what I am trying to do. Multiple processes (in hundreds) have lib in them to encod…

---

## [Verify PKI enabling in elastic nodes](https://discuss.elastic.co/t/verify-pki-enabling-in-elastic-nodes/166744)

<div class="topic-metadata">

**Author:** [@B123](https://discuss.elastic.co/u/B123)\
**Replies:** 21\
**Last updated:** [February 6, 2019, 10:54am UTC](https://discuss.elastic.co/t/verify-pki-enabling-in-elastic-nodes/166744 "2019-02-06T10:54:05Z")

</div>

I have enabled the PKI in elasticsearch.yml as below: xpack.security.authc.realms.pki1.type: pki xpack.security.authc.realms.pki1.order: 1 xpack.security.authc.realms.pki1.certificate\_authorities: \[ path to cacert \] W…

---

## [How to confirm if my apm-server is collecting the data from apm agent](https://discuss.elastic.co/t/how-to-confirm-if-my-apm-server-is-collecting-the-data-from-apm-agent/190558)

<div class="topic-metadata">

**Author:** [@SachinHulawale](https://discuss.elastic.co/u/SachinHulawale)\
**Replies:** 16\
**Last updated:** [August 1, 2019, 11:05am UTC](https://discuss.elastic.co/t/how-to-confirm-if-my-apm-server-is-collecting-the-data-from-apm-agent/190558 "2019-08-01T11:05:12Z")

</div>

Hi Team, I have installed APM-Server and ElasticSearch on machine with default configurations. APM agent resides on another machine and i have added the agent to JVM startup. I have tested the APM server config and ou…

---

## [Grok filter for logstash/filebeats](https://discuss.elastic.co/t/grok-filter-for-logstash-filebeats/216481)

<div class="topic-metadata">

**Author:** [@gsuboc](https://discuss.elastic.co/u/gsuboc)\
**Replies:** 42\
**Last updated:** [March 24, 2020, 4:59pm UTC](https://discuss.elastic.co/t/grok-filter-for-logstash-filebeats/216481 "2020-03-24T16:59:29Z")

</div>

I'm trying to extract my logs field using grok but it doesn't work. Here's my grok filter: filter { # parse the CSV structure generated from the log file into fields grok { match =\> {"message" =\> "%{GREEDYDATA:Job\_Name…

---

## [Elasticsearch EC2 instance not accessible](https://discuss.elastic.co/t/elasticsearch-ec2-instance-not-accessible/60016)

<div class="topic-metadata">

**Author:** [@bradfordli](https://discuss.elastic.co/u/bradfordli)\
**Replies:** 10\
**Last updated:** [January 11, 2017, 1:41am UTC](https://discuss.elastic.co/t/elasticsearch-ec2-instance-not-accessible/60016 "2017-01-11T01:41:26Z")

</div>

I am trying to access my ElasticSearch on a running EC2 instance from outside the Cloud. I currently have SSH/HTTP/HTTPS open to the public for inbound traffic as well as all open for outbound traffic. I set up a public …

---

## [How do I set routing option with elasticsearch-hadoop plugin in storm?](https://discuss.elastic.co/t/how-do-i-set-routing-option-with-elasticsearch-hadoop-plugin-in-storm/43326)

<div class="topic-metadata">

**Author:** [@ted.fed](https://discuss.elastic.co/u/ted.fed)\
**Replies:** 25\
**Last updated:** [April 7, 2016, 9:43am UTC](https://discuss.elastic.co/t/how-do-i-set-routing-option-with-elasticsearch-hadoop-plugin-in-storm/43326 "2016-04-07T09:43:50Z")

</div>

I have gone through https://www.elastic.co/guide/en/elasticsearch/hadoop/current/storm.html#storm-write and through https://www.elastic.co/guide/en/elasticsearch/hadoop/current/reference.html But none of these specify…

---

## [Nodes randomly, temporarily, leaving 7.3.2 cluster](https://discuss.elastic.co/t/nodes-randomly-temporarily-leaving-7-3-2-cluster/224925)

<div class="topic-metadata">

**Author:** [@lag13](https://discuss.elastic.co/u/lag13)\
**Replies:** 16\
**Last updated:** [April 3, 2020, 9:49am UTC](https://discuss.elastic.co/t/nodes-randomly-temporarily-leaving-7-3-2-cluster/224925 "2020-04-03T09:49:55Z")

</div>

I'm really stumped here so I'm hoping that someone can point me in the right direction. Thanks! Over the past couple weeks I've noticed that nodes will occasionally leave our cluster and then rejoin a short time later a…

---

## [ERR Fail to publish event to REDIS: write tcp sourceHost:sourcePort-\>redisHost:redisPort: i/o timeout](https://discuss.elastic.co/t/err-fail-to-publish-event-to-redis-write-tcp-sourcehost-sourceport-redishost-redisport-i-o-timeout/54399)

<div class="topic-metadata">

**Author:** [@mrunalgosar](https://discuss.elastic.co/u/mrunalgosar)\
**Replies:** 19\
**Last updated:** [July 20, 2016, 7:26am UTC](https://discuss.elastic.co/t/err-fail-to-publish-event-to-redis-write-tcp-sourcehost-sourceport-redishost-redisport-i-o-timeout/54399 "2016-07-20T07:26:33Z")

</div>

I have recently setup below ELK stack for one of my application: FileBeat --\> Redis --\> Logstash --\> Elasticsearch --\> Kibana My FileBeat config: filebeat: prospectors: - paths: - LogPath in…

---

## [Unbalanced cluster nodes](https://discuss.elastic.co/t/unbalanced-cluster-nodes/152867)

<div class="topic-metadata">

**Author:** [@elk2](https://discuss.elastic.co/u/elk2)\
**Replies:** 11\
**Last updated:** [October 23, 2018, 12:36pm UTC](https://discuss.elastic.co/t/unbalanced-cluster-nodes/152867 "2018-10-23T12:36:31Z")

</div>

From some days I have this situation for my cluster: \[root@elk ~\]# curl -XGET 'localhost:9200/\_cat/nodes?v' host ip heap.percent ram.percent load node.role master name 192.168.0.51 192.168.0.51 …

---

## [Minimum interval on "Date Histogram" aggregation](https://discuss.elastic.co/t/minimum-interval-on-date-histogram-aggregation/238973)

<div class="topic-metadata">

**Author:** [@laurentml](https://discuss.elastic.co/u/laurentml)\
**Replies:** 14\
**Last updated:** [July 7, 2020, 2:40pm UTC](https://discuss.elastic.co/t/minimum-interval-on-date-histogram-aggregation/238973 "2020-07-07T14:40:25Z")

</div>

Hi folks, I'm using ELK stack (v7.8.0, same on v7.7.1) for an application used by historians, where each entry is an archive which can be like from year 1687 for example. Rendering options of Kibana are generally very …

---

## [Fleet initial error](https://discuss.elastic.co/t/fleet-initial-error/347225)

<div class="topic-metadata">

**Author:** [@mohd\_sa](https://discuss.elastic.co/u/mohd_sa)\
**Replies:** 17\
**Last updated:** [December 13, 2023, 8:12am UTC](https://discuss.elastic.co/t/fleet-initial-error/347225 "2023-12-13T08:12:49Z")

</div>

Hi after upgrade from 8.9.1 to 8.11.1 , I have error on fleet page "unable to initialize fleet, uninstall token is missing the token"

---

## [Persistent Queue Configuration question](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408)

<div class="topic-metadata">

**Author:** [@ash007](https://discuss.elastic.co/u/ash007)\
**Replies:** 12\
**Last updated:** [February 16, 2017, 4:20pm UTC](https://discuss.elastic.co/t/persistent-queue-configuration-question/73408 "2017-02-16T16:20:15Z")

</div>

Hi, This might a very simple question but i am new to logstash. I have just configured my logstash instance with the following configuration in the logstash.yml file: path.data: /var/lib/logstash queue.type: persiste…

---

## [Having issue bringing accessing Kibana UI](https://discuss.elastic.co/t/having-issue-bringing-accessing-kibana-ui/186545)

<div class="topic-metadata">

**Author:** [@chowdary1110](https://discuss.elastic.co/u/chowdary1110)\
**Replies:** 9\
**Last updated:** [June 21, 2019, 5:50am UTC](https://discuss.elastic.co/t/having-issue-bringing-accessing-kibana-ui/186545 "2019-06-21T05:50:36Z")

</div>

I installed 7.1.1 version of Kibana,Elastic search and tried binging Kibana up with the required changes. I am fairly new the the installation on elastic search stack. Not sure if I am missing anything. I see port liste…

---

## [Watcher doesn't work (empty result)](https://discuss.elastic.co/t/watcher-doesnt-work-empty-result/136316)

<div class="topic-metadata">

**Author:** [@\_Sergey](https://discuss.elastic.co/u/_Sergey)\
**Replies:** 21\
**Last updated:** [June 25, 2018, 11:30am UTC](https://discuss.elastic.co/t/watcher-doesnt-work-empty-result/136316 "2018-06-25T11:30:56Z")

</div>

Hi all, I have a watcher in Kibana that doesn't work (condition is if ctx.payload.hits.total == 0, then send notification via slack). BUT: If you check the Execution Output of Watcher you can see that there are no to…

---

## [./scripts/import\_dashboards: No such file or directory](https://discuss.elastic.co/t/scripts-import-dashboards-no-such-file-or-directory/100910)

<div class="topic-metadata">

**Author:** [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Replies:** 20\
**Last updated:** [September 20, 2017, 7:10pm UTC](https://discuss.elastic.co/t/scripts-import-dashboards-no-such-file-or-directory/100910 "2017-09-20T19:10:17Z")

</div>

I installed Filebeat 6 , i can find ./scripts/import\_dashboards please assist, only found migrate\_beat\_config\_1\_x\_to\_5\_0.py

---

## [\[RESOLU\] Aide sur Grok (problème d'encodage)](https://discuss.elastic.co/t/resolu-aide-sur-grok-probleme-dencodage/40468)

<div class="topic-metadata">

**Author:** [@C\_H](https://discuss.elastic.co/u/C_H)\
**Replies:** 20\
**Last updated:** [February 1, 2016, 2:28pm UTC](https://discuss.elastic.co/t/resolu-aide-sur-grok-probleme-dencodage/40468 "2016-02-01T14:28:29Z")

</div>

Bonjour, comment feriez-vous pour parser une log dont la syntaxe est ainsi, avec grok : \[AAAA-MM-JJ HH:MM:SS\]\[machine\]\[host\]\[login\]\[userElevPrivs\]\[nomTbx\]\[entree\] message Ex. : \[2016-01-29 11:45:48\]\[S00V09951584\]\[par…

---

## [Want to create multiple index for multiple input](https://discuss.elastic.co/t/want-to-create-multiple-index-for-multiple-input/95538)

<div class="topic-metadata">

**Author:** [@vivekpandey564](https://discuss.elastic.co/u/vivekpandey564)\
**Replies:** 18\
**Last updated:** [August 4, 2017, 5:06am UTC](https://discuss.elastic.co/t/want-to-create-multiple-index-for-multiple-input/95538 "2017-08-04T05:06:01Z")

</div>

Hi I have multiple log file created based on user. i want to take input all user log file and create index for that. For Ex Input section nput { file { add\_field =\> \[ "host", "my-dev-host" \] path =\> "D:\\JHips…

---

## [Cannot Get Enterprise Search Beta1 to work](https://discuss.elastic.co/t/cannot-get-enterprise-search-beta1-to-work/180584)

<div class="topic-metadata">

**Author:** [@christopher.farmer](https://discuss.elastic.co/u/christopher.farmer)\
**Replies:** 21\
**Last updated:** [August 9, 2019, 5:48pm UTC](https://discuss.elastic.co/t/cannot-get-enterprise-search-beta1-to-work/180584 "2019-08-09T17:48:39Z")

</div>

I have a clean build of Fedora/ELK running with Oracle 8 JDK, but cannot get EES to work - getting the following; Found java executable in PATH Java version: 1.8.0\_211 Starting the following Elastic Enterprise Search …

[Previous page](https://discuss.elastic.co/top.md?page=44&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=46&per_page=50&period=all)
