# Top

**URL:** https://discuss.elastic.co/top.md?page=46&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 47

---

## [Losing documents while Reindex](https://discuss.elastic.co/t/losing-documents-while-reindex/158131)

<div class="topic-metadata">

**Author:** [@smogami](https://discuss.elastic.co/u/smogami)\
**Replies:** 12\
**Last updated:** [December 4, 2018, 9:12am UTC](https://discuss.elastic.co/t/losing-documents-while-reindex/158131 "2018-12-04T09:12:31Z")

</div>

Elasticsearch: 6.2 Hello. I am trying to update the mapping of an existing index, by the operations described below. This operation works well for the index if number of documents are relatively small (e.g. 1,000). …

---

## [What should be the number of shards?](https://discuss.elastic.co/t/what-should-be-the-number-of-shards/66865)

<div class="topic-metadata">

**Author:** [@ANU\_SARA\_VARGHESE](https://discuss.elastic.co/u/ANU_SARA_VARGHESE)\
**Replies:** 12\
**Last updated:** [November 26, 2016, 7:51pm UTC](https://discuss.elastic.co/t/what-should-be-the-number-of-shards/66865 "2016-11-26T19:51:33Z")

</div>

Hi, I have build a POC in which there are 4 data nodes , 3 master nodes and 2 load balancer nodes(one client node is defined on the kibana itself). All are in cluster. What should be the number of shards in this sc…

---

## [Installation of filebeat 5.3.1 in windows 10?](https://discuss.elastic.co/t/installation-of-filebeat-5-3-1-in-windows-10/83594)

<div class="topic-metadata">

**Author:** [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Replies:** 9\
**Last updated:** [April 27, 2017, 2:57am UTC](https://discuss.elastic.co/t/installation-of-filebeat-5-3-1-in-windows-10/83594 "2017-04-27T02:57:38Z")

</div>

Hi, I installed filebeat in F:\\filebeat-5.3.1-windows-x86\_64\\Filebeat when i executed the install-service-filebeat.ps1 in powershell it opened and closed immediately i dont know why this is happening ? Even i changed…

---

## [Generating the Binary](https://discuss.elastic.co/t/generating-the-binary/32526)

<div class="topic-metadata">

**Author:** [@Prerna\_Manaktala](https://discuss.elastic.co/u/Prerna_Manaktala)\
**Replies:** 28\
**Last updated:** [October 23, 2015, 8:04am UTC](https://discuss.elastic.co/t/generating-the-binary/32526 "2015-10-23T08:04:34Z")

</div>

Hello I am new to golang and elasticsearch. I installed golang on mac and cloned the packetbeat repo.Trying to run the commang to execute step 1. Generating the Binary, but am unsuccesful. Can you please guide me as to…

---

## [o.e.d.z.UnicastZenPing - failed to resolve host: java.net.UnknownHostException](https://discuss.elastic.co/t/o-e-d-z-unicastzenping-failed-to-resolve-host-java-net-unknownhostexception/174507)

<div class="topic-metadata">

**Author:** [@lemon\_soft](https://discuss.elastic.co/u/lemon_soft)\
**Replies:** 9\
**Last updated:** [March 29, 2019, 12:18pm UTC](https://discuss.elastic.co/t/o-e-d-z-unicastzenping-failed-to-resolve-host-java-net-unknownhostexception/174507 "2019-03-29T12:18:04Z")

</div>

Hello. I have a simple problem. My elasticsearch nodes don't communicate each other. Could you help me? :worried: Elasticsearch 6.7.0(installed from rpm) CentOS Linux 7.6.1810 Linux 3.10.0-957.5.1.el7.x86\_64 on x86\_64 …

---

## [\[publisher\_pipeline\_output\] pipeline /output.go:154 Failed to connect to backoff(async(tcp://logstash-xxx-xxx.apps.-xxx.xxx:443)): EOF](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451)

<div class="topic-metadata">

**Author:** [@Rohan-boogeyman](https://discuss.elastic.co/u/Rohan-boogeyman)\
**Replies:** 13\
**Last updated:** [March 10, 2021, 7:42pm UTC](https://discuss.elastic.co/t/publisher-pipeline-output-pipeline-output-go-154-failed-to-connect-to-backoff-async-tcp-logstash-xxx-xxx-apps-xxx-xxx-443-eof/266451 "2021-03-10T19:42:50Z")

</div>

Hello Guys, Thanks in advance for taking your time to look into the issue i am experiencing. Error in File beat at the time of Debug \[publisher\_pipeline\_output\] pipeline /output.go:154 Failed to connect to backof…

---

## [Search across multiple ES data sources](https://discuss.elastic.co/t/search-across-multiple-es-data-sources/171959)

<div class="topic-metadata">

**Author:** [@vasekz](https://discuss.elastic.co/u/vasekz)\
**Replies:** 43\
**Last updated:** [April 3, 2019, 9:46am UTC](https://discuss.elastic.co/t/search-across-multiple-es-data-sources/171959 "2019-04-03T09:46:36Z")

</div>

Hi, I have a hundred of independent ES servers with data of the same structure. For example NY server keeps NY phone book, LA server keeps LA phone book, etc. Is there a way to query this data from a central point? For …

---

## [Order log in kibana based on log timestamp](https://discuss.elastic.co/t/order-log-in-kibana-based-on-log-timestamp/80070)

<div class="topic-metadata">

**Author:** [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Replies:** 9\
**Last updated:** [March 27, 2017, 10:25am UTC](https://discuss.elastic.co/t/order-log-in-kibana-based-on-log-timestamp/80070 "2017-03-27T10:25:32Z")

</div>

Hi I want to order my log in kibana based on log timestamp my logstash.conf filter { grok { match =\> \[ "message", "%{DATESTAMP:timestamp}" \] } date { locale =\> "en" match =\> \[ "timestamp", "YYYY…

---

## [How to change the cluster\_update\_settings time?](https://discuss.elastic.co/t/how-to-change-the-cluster-update-settings-time/101648)

<div class="topic-metadata">

**Author:** [@zqc0512](https://discuss.elastic.co/u/zqc0512)\
**Replies:** 11\
**Last updated:** [September 25, 2017, 11:38am UTC](https://discuss.elastic.co/t/how-to-change-the-cluster-update-settings-time/101648 "2017-09-25T11:38:03Z")

</div>

the default is 30s ,but in big cluster this is small? how to change the time thanks. { "error" : { "root\_cause" : \[ { "type" : "process\_cluster\_event\_timeout\_exception", "reason" : "failed t…

---

## [Can't get delete by query to actually delete](https://discuss.elastic.co/t/cant-get-delete-by-query-to-actually-delete/205323)

<div class="topic-metadata">

**Author:** [@CityofRome](https://discuss.elastic.co/u/CityofRome)\
**Replies:** 19\
**Last updated:** [November 7, 2019, 8:27pm UTC](https://discuss.elastic.co/t/cant-get-delete-by-query-to-actually-delete/205323 "2019-11-07T20:27:32Z")

</div>

I can't seem to get a delete query (ANY delete query) to actually delete anything. I've even tried the basic ones in the documentation (edited for my test index) and they don't work either. What am I overlooking? I'm …

---

## [Unable to query .keyword fields from an index created using the default logstash template](https://discuss.elastic.co/t/unable-to-query-keyword-fields-from-an-index-created-using-the-default-logstash-template/84185)

<div class="topic-metadata">

**Author:** [@GuillaumeN](https://discuss.elastic.co/u/GuillaumeN)\
**Replies:** 9\
**Last updated:** [May 2, 2017, 5:10am UTC](https://discuss.elastic.co/t/unable-to-query-keyword-fields-from-an-index-created-using-the-default-logstash-template/84185 "2017-05-02T05:10:29Z")

</div>

Hi all, Using an ELK v5.3 stack, I'm trying to load and search syslogs from archived files. I'm using a simple logstash mapping file and my logs all to to a logstash-YYY.MM.DD index. This index uses the default elastic…

---

## [Auditbeat - 120% CPU?](https://discuss.elastic.co/t/auditbeat-120-cpu/234909)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 29\
**Last updated:** [July 11, 2020, 11:44am UTC](https://discuss.elastic.co/t/auditbeat-120-cpu/234909 "2020-07-11T11:44:14Z")

</div>

The high CPU usage of this process has been an ongoing issue. Recently I created a portal host for remote workers. Just supposed to be a gateway to move to other machines. 2 CPUs, 4Gb RAM, etc. Started getting reports o…

---

## [Elastic Agents fail to upgrade from Fleet, shows "Updating" status for more than a week](https://discuss.elastic.co/t/elastic-agents-fail-to-upgrade-from-fleet-shows-updating-status-for-more-than-a-week/325426)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 13\
**Last updated:** [February 28, 2023, 4:57pm UTC](https://discuss.elastic.co/t/elastic-agents-fail-to-upgrade-from-fleet-shows-updating-status-for-more-than-a-week/325426 "2023-02-28T16:57:37Z")

</div>

I recently upgraded my Elastic Cloud instance to 8.6.1. After upgrading, I triggered an agent upgrade in Fleet to v8.6.1. The agents DID NOT upgrade and were stuck in Updating status for almost a week. If I go into the s…

---

## [Run Logstash in the background on Ubuntu](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422)

<div class="topic-metadata">

**Author:** [@hHelen](https://discuss.elastic.co/u/hHelen)\
**Replies:** 9\
**Last updated:** [July 25, 2018, 7:10pm UTC](https://discuss.elastic.co/t/run-logstash-in-the-background-on-ubuntu/141422 "2018-07-25T19:10:49Z")

</div>

I already have logstash running on the termial with this command: sudo -Hu logstash /usr/share/logstash/bin/logstash --path.settings=/etc/logstash -f logstash-simple.conf I can see files scrolling past on the terminal,…

---

## [Logstash Queue](https://discuss.elastic.co/t/logstash-queue/40865)

<div class="topic-metadata">

**Author:** [@abinay](https://discuss.elastic.co/u/abinay)\
**Replies:** 22\
**Last updated:** [February 4, 2016, 7:11pm UTC](https://discuss.elastic.co/t/logstash-queue/40865 "2016-02-04T19:11:00Z")

</div>

Hii I am using logstash to parse my logs . This is my architecture . Filebeat ships logs from server to Logstash. Logstash parses the logs and sends it to Elasticsearch . Elasticsearch's logs can be viewed using kibana .…

---

## [Filebeat + netflow module , there is nothing to visualize on kibana](https://discuss.elastic.co/t/filebeat-netflow-module-there-is-nothing-to-visualize-on-kibana/246849)

<div class="topic-metadata">

**Author:** [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Replies:** 13\
**Last updated:** [September 1, 2020, 8:55pm UTC](https://discuss.elastic.co/t/filebeat-netflow-module-there-is-nothing-to-visualize-on-kibana/246849 "2020-09-01T20:55:49Z")

</div>

Hi guys , im very exited about watching netflow data on elk. My elk is already working, I added metricbeat and can see nice graphics. Then with similar methods , installed filebeat and enable netflow module following t…

---

## [Kibana not loading properly](https://discuss.elastic.co/t/kibana-not-loading-properly/192161)

<div class="topic-metadata">

**Author:** [@Arshdeep\_Sandhu](https://discuss.elastic.co/u/Arshdeep_Sandhu)\
**Replies:** 18\
**Last updated:** [August 22, 2019, 5:04am UTC](https://discuss.elastic.co/t/kibana-not-loading-properly/192161 "2019-08-22T05:04:52Z")

</div>

I am using Kibana 7.2.0 and getting the following result while accessing http://localhost:5601 I am getting the following error in kibana.bat: log \[04:06:22.223\] \[info\]\[status\]\[plugin:reporting@7.2.0\] Status chang…

---

## [\_geoip\_database\_unavailable\_GeoLite2-ASN.mmdb](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 22\
**Last updated:** [April 26, 2023, 1:34pm UTC](https://discuss.elastic.co/t/geoip-database-unavailable-geolite2-asn-mmdb/330772 "2023-04-26T13:34:16Z")

</div>

Hello there, I am running packetbeat-8.4.3-amd64.deb on a node that i want to monitor and I am shiping the metrics to elastcsearch and kibana. I also added geoip data from Enrich events with geoIP information | Packetbea…

---

## ['mage' is not recognized as an internal or external command](https://discuss.elastic.co/t/mage-is-not-recognized-as-an-internal-or-external-command/217082)

<div class="topic-metadata">

**Author:** [@Yiw](https://discuss.elastic.co/u/Yiw)\
**Replies:** 23\
**Last updated:** [February 6, 2020, 7:54pm UTC](https://discuss.elastic.co/t/mage-is-not-recognized-as-an-internal-or-external-command/217082 "2020-02-06T19:54:23Z")

</div>

Hi all, I am having an issue and hoping you have seen this previously. #Using Windows 10# I cloned the beats source code according to https://www.elastic.co/guide/en/beats/devguide/current/beats-contributing.html Whe…

---

## [Curator delete\_indices. \<type 'exceptions.KeyError'\>: 'indices'](https://discuss.elastic.co/t/curator-delete-indices-type-exceptions-keyerror-indices/126954)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 16\
**Last updated:** [April 10, 2018, 3:21pm UTC](https://discuss.elastic.co/t/curator-delete-indices-type-exceptions-keyerror-indices/126954 "2018-04-10T15:21:29Z")

</div>

Hi, running curator job and once a while I get the following error... Failed to complete action: delete\_indices. \<type 'exceptions.KeyError'\>: 'indices' Otherwise it works. Here is the action... actions: 2: …

---

## [Importing dashboard and index pattern id](https://discuss.elastic.co/t/importing-dashboard-and-index-pattern-id/255688)

<div class="topic-metadata">

**Author:** [@Maria20](https://discuss.elastic.co/u/Maria20)\
**Replies:** 16\
**Last updated:** [December 15, 2020, 4:47pm UTC](https://discuss.elastic.co/t/importing-dashboard-and-index-pattern-id/255688 "2020-12-15T16:47:35Z")

</div>

Hi, I have an issue related to importing Kibana dashboard. My dashboard contains visualizations from different indices. When I import & export the dashboard using UI everything works fine. But when I export and then i…

---

## [Concurrent patch updates](https://discuss.elastic.co/t/concurrent-patch-updates/296257)

<div class="topic-metadata">

**Author:** [@SriAkash](https://discuss.elastic.co/u/SriAkash)\
**Replies:** 9\
**Last updated:** [March 15, 2022, 11:01pm UTC](https://discuss.elastic.co/t/concurrent-patch-updates/296257 "2022-03-15T23:01:14Z")

</div>

Is there a way to handle concurrent patch updates to same document in Elastic App Search? Its been observed that when two concurrent update statements(patch calls) are sent to Elastic App Search, only changes in one of …

---

## [Understanding pipelines v6.x](https://discuss.elastic.co/t/understanding-pipelines-v6-x/112888)

<div class="topic-metadata">

**Author:** [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Replies:** 13\
**Last updated:** [December 22, 2017, 1:54pm UTC](https://discuss.elastic.co/t/understanding-pipelines-v6-x/112888 "2017-12-22T13:54:17Z")

</div>

Elasticsearch/Logstash version 6.1.1 When I start logstash I receive the following error with the below settings: I have my logstash.yml with: path.data: /var/lib/logstash path.logs: /var/log/logstash # ------------…

---

## [Visualize / Search Date more than X days ago](https://discuss.elastic.co/t/visualize-search-date-more-than-x-days-ago/269905)

<div class="topic-metadata">

**Author:** [@csatola](https://discuss.elastic.co/u/csatola)\
**Replies:** 13\
**Last updated:** [April 15, 2021, 12:47pm UTC](https://discuss.elastic.co/t/visualize-search-date-more-than-x-days-ago/269905 "2021-04-15T12:47:49Z")

</div>

In my scenario, I'm logging server vulnerability data. @timestamp is when the document was added (and that's fine), but I also have a "PatchReleasedDate" field. What I would like to do is build visualizations for # of do…

---

## [Elastic Search 5.6 : Sharding and Replication](https://discuss.elastic.co/t/elastic-search-5-6-sharding-and-replication/101627)

<div class="topic-metadata">

**Author:** [@Nakshathri](https://discuss.elastic.co/u/Nakshathri)\
**Replies:** 10\
**Last updated:** [September 25, 2017, 9:13am UTC](https://discuss.elastic.co/t/elastic-search-5-6-sharding-and-replication/101627 "2017-09-25T09:13:33Z")

</div>

Hello there, We are using latest 5.6.0 version of the elastic search in production running on CentOs 7. We have a 3 node cluster (all of them are master eligible data nodes) setup. We went through the detailed documenta…

---

## [ElasticSearch cluster with four nodes](https://discuss.elastic.co/t/elasticsearch-cluster-with-four-nodes/32547)

<div class="topic-metadata">

**Author:** [@chinmoyd](https://discuss.elastic.co/u/chinmoyd)\
**Replies:** 15\
**Last updated:** [November 4, 2015, 1:12pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-with-four-nodes/32547 "2015-11-04T13:12:43Z")

</div>

My java application distribution is as below: Four physical servers has three JVMs each. Hence total 12 instances of java applications are running. Each java application logs two different log files that are captured by…

---

## [Memory usage increased to more than 90 while running Elastic search service on window machine](https://discuss.elastic.co/t/memory-usage-increased-to-more-than-90-while-running-elastic-search-service-on-window-machine/181590)

<div class="topic-metadata">

**Author:** [@Sharma3007](https://discuss.elastic.co/u/Sharma3007)\
**Replies:** 18\
**Last updated:** [May 20, 2019, 6:07pm UTC](https://discuss.elastic.co/t/memory-usage-increased-to-more-than-90-while-running-elastic-search-service-on-window-machine/181590 "2019-05-20T18:07:11Z")

</div>

Hi Team, Memory usage increased to more than 90 while running Elastic search service on window machine. I am using elastic version 7.0.1 / my system RAM is 4gb. Can you please help me how to handle / what configurati…

---

## [Error in Powershell during Config](https://discuss.elastic.co/t/error-in-powershell-during-config/139163)

<div class="topic-metadata">

**Author:** [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Replies:** 23\
**Last updated:** [July 10, 2018, 12:53pm UTC](https://discuss.elastic.co/t/error-in-powershell-during-config/139163 "2018-07-10T12:53:21Z")

</div>

I have been following the tutorial to get Winlogbeat installed, and I got stuck on this bit: https://www.elastic.co/guide/en/beats/winlogbeat/master/winlogbeat-template.html#load-template-manually. Whenever I run this …

---

## [Very bad performance with large text field](https://discuss.elastic.co/t/very-bad-performance-with-large-text-field/89924)

<div class="topic-metadata">

**Author:** [@mos](https://discuss.elastic.co/u/mos)\
**Replies:** 10\
**Last updated:** [June 29, 2017, 1:09pm UTC](https://discuss.elastic.co/t/very-bad-performance-with-large-text-field/89924 "2017-06-29T13:09:41Z")

</div>

At one of my customer projects we work with documents containing a very large text-field (content of eBooks....). We saw that queries slow down more then 100 x times when such documents are queried. Even if we use the s…

---

## [GEOIP Enable](https://discuss.elastic.co/t/geoip-enable/74116)

<div class="topic-metadata">

**Author:** [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Replies:** 24\
**Last updated:** [February 9, 2017, 3:21am UTC](https://discuss.elastic.co/t/geoip-enable/74116 "2017-02-09T03:21:56Z")

</div>

Hi Firstly i am apologise for bugging the forum but it is just that i really want this to work. I have setup the stack using this link https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logsta…

---

## [Problem With logstash output email plugin](https://discuss.elastic.co/t/problem-with-logstash-output-email-plugin/84379)

<div class="topic-metadata">

**Author:** [@Baco](https://discuss.elastic.co/u/Baco)\
**Replies:** 14\
**Last updated:** [June 27, 2017, 3:25pm UTC](https://discuss.elastic.co/t/problem-with-logstash-output-email-plugin/84379 "2017-06-27T15:25:17Z")

</div>

Could you help me with this error on my logstash 5.3 ? couldn't find any output plugin named 'email'. Thanks

---

## [Issues with encoding](https://discuss.elastic.co/t/issues-with-encoding/35160)

<div class="topic-metadata">

**Author:** [@vinod8427](https://discuss.elastic.co/u/vinod8427)\
**Replies:** 28\
**Last updated:** [November 24, 2015, 10:30am UTC](https://discuss.elastic.co/t/issues-with-encoding/35160 "2015-11-24T10:30:00Z")

</div>

I came across a major issue( atleast in my case ). The issue is as explained below and I am assuming it has to do with some sort of encoding. The logs in my case which are being parsed contain special characters and suc…

---

## [Upgraded from 6.4.2 to 6.5.0. Says "Kibana server is not ready yet"](https://discuss.elastic.co/t/upgraded-from-6-4-2-to-6-5-0-says-kibana-server-is-not-ready-yet/156994)

<div class="topic-metadata">

**Author:** [@mlemartien](https://discuss.elastic.co/u/mlemartien)\
**Replies:** 12\
**Last updated:** [November 20, 2018, 12:50pm UTC](https://discuss.elastic.co/t/upgraded-from-6-4-2-to-6-5-0-says-kibana-server-is-not-ready-yet/156994 "2018-11-20T12:50:41Z")

</div>

Hi did my rolling upgrade this morning: Logstahs, then Elastic then Kibana. Everything went well and cluster (3 nodes) status is green. Now when starting Kibana, it says in the browser: Kibana server is not ready yet I…

---

## [Slow Data loading to elasticsearch](https://discuss.elastic.co/t/slow-data-loading-to-elasticsearch/89261)

<div class="topic-metadata">

**Author:** [@gowtham.go](https://discuss.elastic.co/u/gowtham.go)\
**Replies:** 14\
**Last updated:** [June 15, 2017, 1:47pm UTC](https://discuss.elastic.co/t/slow-data-loading-to-elasticsearch/89261 "2017-06-15T13:47:50Z")

</div>

Hi, I am new to Elasticsearch. I am trying to create a reporting application with Elastic search as Data Store. I get Input files, try and index it into ES via Logstash, and search / filter in ES for report output. The …

---

## [ES 5.2.2: Sudden heap spikes followed by cluster crash](https://discuss.elastic.co/t/es-5-2-2-sudden-heap-spikes-followed-by-cluster-crash/80977)

<div class="topic-metadata">

**Author:** [@AirOnSkin](https://discuss.elastic.co/u/AirOnSkin)\
**Replies:** 14\
**Last updated:** [May 11, 2017, 8:54am UTC](https://discuss.elastic.co/t/es-5-2-2-sudden-heap-spikes-followed-by-cluster-crash/80977 "2017-05-11T08:54:43Z")

</div>

Hello community, We've recently upgraded from ES 2.4.4 to 5.2.2 and observe random cluster crashes since then. We're at a loss as to what causes the crashes other than knowing that heap memory suddenly grows to its full…

---

## [Match query is working differently for few inputs](https://discuss.elastic.co/t/match-query-is-working-differently-for-few-inputs/25426)

<div class="topic-metadata">

**Author:** [@anusha6](https://discuss.elastic.co/u/anusha6)\
**Replies:** 20\
**Last updated:** [July 23, 2015, 8:58am UTC](https://discuss.elastic.co/t/match-query-is-working-differently-for-few-inputs/25426 "2015-07-23T08:58:09Z")

</div>

Hi, I kept following mappings: PUT pdlfull/pdlfull\_type/\_mapping { "pdlfull\_type": { "properties": { "GenericDescriptionId": { "type": "string", "index": "…

---

## [Trace.id and transaction.id not being added to log entry](https://discuss.elastic.co/t/trace-id-and-transaction-id-not-being-added-to-log-entry/268838)

<div class="topic-metadata">

**Author:** [@pculebras](https://discuss.elastic.co/u/pculebras)\
**Replies:** 13\
**Last updated:** [May 26, 2021, 4:21pm UTC](https://discuss.elastic.co/t/trace-id-and-transaction-id-not-being-added-to-log-entry/268838 "2021-05-26T16:21:51Z")

</div>

Good evening everyone, I was able to set up the APM Java Agent and activated the log\_correlation option without further issues. Next, I got the tool to log into a file by using the ECS Java Logging tool and its standar…

---

## [Syslog-ng directly into Redis from which a central Logstash indexer can read](https://discuss.elastic.co/t/syslog-ng-directly-into-redis-from-which-a-central-logstash-indexer-can-read/32590)

<div class="topic-metadata">

**Author:** [@ottignon](https://discuss.elastic.co/u/ottignon)\
**Replies:** 11\
**Last updated:** [January 13, 2016, 4:18pm UTC](https://discuss.elastic.co/t/syslog-ng-directly-into-redis-from-which-a-central-logstash-indexer-can-read/32590 "2016-01-13T16:18:44Z")

</div>

Hi, Currently doing a feasability test of the ELK stack and Redis solution as a replacement for Splunk. I've done much googling and lot of testing but it's hard to run wild in a DevOps enviroment where everything is po…

---

## [Problem with master re-election under ZenDiscovery (5.2.2)](https://discuss.elastic.co/t/problem-with-master-re-election-under-zendiscovery-5-2-2/78617)

<div class="topic-metadata">

**Author:** [@loren](https://discuss.elastic.co/u/loren)\
**Replies:** 18\
**Last updated:** [March 22, 2017, 2:41pm UTC](https://discuss.elastic.co/t/problem-with-master-re-election-under-zendiscovery-5-2-2/78617 "2017-03-22T14:41:11Z")

</div>

I am testing recovery. I have a 5.2.2 cluster with 3 master-elegible nodes. When I kill the elected master node (in this case master-0), the entire cluster shuts down (except for Kibana). The gist of the problem seems to…

---

## [Logstash Too small initial heap](https://discuss.elastic.co/t/logstash-too-small-initial-heap/66068)

<div class="topic-metadata">

**Author:** [@manojvenkat](https://discuss.elastic.co/u/manojvenkat)\
**Replies:** 10\
**Last updated:** [November 17, 2016, 2:28pm UTC](https://discuss.elastic.co/t/logstash-too-small-initial-heap/66068 "2016-11-17T14:28:59Z")

</div>

Team, I have installed logstash 2.2 on my AWS linux instance . When I executed the command to test the config file: service logstash configtest I get the heap error as below, \[root@ip-10-34-77-105 conf.d\]# service lo…

---

## [Create new field on object using painless](https://discuss.elastic.co/t/create-new-field-on-object-using-painless/245211)

<div class="topic-metadata">

**Author:** [@david.preston](https://discuss.elastic.co/u/david.preston)\
**Replies:** 11\
**Last updated:** [August 17, 2020, 2:50pm UTC](https://discuss.elastic.co/t/create-new-field-on-object-using-painless/245211 "2020-08-17T14:50:44Z")

</div>

Hi I'm trying to set an object field from another using an update query but am getting an error. Currently by doc has an event object in the root of the doc with a field: id i.e. { event { id: 1 } } all the docume…

---

## [Azure App Services to ELK](https://discuss.elastic.co/t/azure-app-services-to-elk/273327)

<div class="topic-metadata">

**Author:** [@madmunki](https://discuss.elastic.co/u/madmunki)\
**Replies:** 15\
**Last updated:** [May 20, 2021, 4:31am UTC](https://discuss.elastic.co/t/azure-app-services-to-elk/273327 "2021-05-20T04:31:49Z")

</div>

I currently manage more than 50 Azure App Services and looking for a solution to collect the logs and put them where devs can look at the logs and troubleshoot issues. If I go into the App Log Stream, it displays what I …

---

## [Elasticsearch | 3 master/data nodes vs 1 master and 2 data nodes](https://discuss.elastic.co/t/elasticsearch-3-master-data-nodes-vs-1-master-and-2-data-nodes/169768)

<div class="topic-metadata">

**Author:** [@Nikesh](https://discuss.elastic.co/u/Nikesh)\
**Replies:** 14\
**Last updated:** [February 26, 2019, 3:44pm UTC](https://discuss.elastic.co/t/elasticsearch-3-master-data-nodes-vs-1-master-and-2-data-nodes/169768 "2019-02-26T15:44:23Z")

</div>

Hi, I was wondering what would be the advantages and disadvantages of using a single cluster with 3 data/master nodes and one dedicated master and two data nodes? Will there be any effect on Cluster performance, stabil…

---

## [This interval creates too many buckets to show in the selected time rage](https://discuss.elastic.co/t/this-interval-creates-too-many-buckets-to-show-in-the-selected-time-rage/273001)

<div class="topic-metadata">

**Author:** [@Hamza\_El\_Aouane](https://discuss.elastic.co/u/Hamza_El_Aouane)\
**Replies:** 27\
**Last updated:** [May 19, 2021, 8:29pm UTC](https://discuss.elastic.co/t/this-interval-creates-too-many-buckets-to-show-in-the-selected-time-rage/273001 "2021-05-19T20:29:17Z")

</div>

Hello guys. I have set a elastic search and kibana to receive some syslogs from our OnPrem server. When I go to the discover section and set the time range to refresh every second. I got the warning This interval crea…

---

## [Logstash 2.1 is filling my Disk volumes](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924)

<div class="topic-metadata">

**Author:** [@soodlikesjava](https://discuss.elastic.co/u/soodlikesjava)\
**Replies:** 13\
**Last updated:** [March 21, 2016, 8:03am UTC](https://discuss.elastic.co/t/logstash-2-1-is-filling-my-disk-volumes/44924 "2016-03-21T08:03:41Z")

</div>

Hi Team , I am facing an issue that when my logstash process is running for 4-5 days , my disk volume on the machine where logstash is installed is getting exhausted and i have to restart the logstash process to free the…

---

## ["illegal\_argument\_exception"](https://discuss.elastic.co/t/illegal-argument-exception/171123)

<div class="topic-metadata">

**Author:** [@saqibjavid](https://discuss.elastic.co/u/saqibjavid)\
**Replies:** 10\
**Last updated:** [March 7, 2019, 12:45pm UTC](https://discuss.elastic.co/t/illegal-argument-exception/171123 "2019-03-07T12:45:40Z")

</div>

{ "error": { "root\_cause": \[ { "type": "illegal\_argument\_exception", "reason": "mapper \[resume.experience.job.daterange.start\] of different type, current\_type \[text\], merged\_type \[ObjectMapper\]" } \], "type": "ill…

---

## [Unable to install Fleet Server](https://discuss.elastic.co/t/unable-to-install-fleet-server/319110)

<div class="topic-metadata">

**Author:** [@leschev](https://discuss.elastic.co/u/leschev)\
**Replies:** 20\
**Last updated:** [December 5, 2022, 1:51pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-server/319110 "2022-12-05T13:51:59Z")

</div>

Hello! I am trying to install Fleet Server with my self-hosted ELK. So, I have the error: sudo ./elastic-agent install -f --fleet-server-es=https://\*\*\*\*.org:9200 --fleet-server-service-token=AAEAAWV\*\*\*\* --fleet-serv…

---

## [How to take Manual backup of AWS elasticsearch to s3 bucket with indexname](https://discuss.elastic.co/t/how-to-take-manual-backup-of-aws-elasticsearch-to-s3-bucket-with-indexname/158540)

<div class="topic-metadata">

**Author:** [@arun5635](https://discuss.elastic.co/u/arun5635)\
**Replies:** 14\
**Last updated:** [December 3, 2018, 1:15pm UTC](https://discuss.elastic.co/t/how-to-take-manual-backup-of-aws-elasticsearch-to-s3-bucket-with-indexname/158540 "2018-12-03T13:15:25Z")

</div>

Hi I am trying to take back up of my AWS elasticsearch indices . and I configured IAM role and policy and using curl to take the back . All the indices are backed up in s3 bucket. But inside the indices folder in s3 buck…

---

## [Please give me easy sample to use xml filter](https://discuss.elastic.co/t/please-give-me-easy-sample-to-use-xml-filter/31616)

<div class="topic-metadata">

**Author:** [@kikuchan](https://discuss.elastic.co/u/kikuchan)\
**Replies:** 10\
**Last updated:** [October 13, 2015, 12:50am UTC](https://discuss.elastic.co/t/please-give-me-easy-sample-to-use-xml-filter/31616 "2015-10-13T00:50:15Z")

</div>

Hello. I'd like to use XML filter,but I didn't use it very well. please give me easy sample to use xml filter. sincerely.

---

## [Getting ssl error while trying to create httpclient](https://discuss.elastic.co/t/getting-ssl-error-while-trying-to-create-httpclient/245327)

<div class="topic-metadata">

**Author:** [@elastic78](https://discuss.elastic.co/u/elastic78)\
**Replies:** 16\
**Last updated:** [August 19, 2020, 6:12am UTC](https://discuss.elastic.co/t/getting-ssl-error-while-trying-to-create-httpclient/245327 "2020-08-19T06:12:59Z")

</div>

I am getting the below error while trying to create new http client in 7.8.1 version. Please help. code : RestHighLevelClient client = new RestHighLevelClient(RestClient. builder ( new HttpHost(getLocalHost(), getPort(…

[Previous page](https://discuss.elastic.co/top.md?page=45&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=47&per_page=50&period=all)
