# Top

**URL:** https://discuss.elastic.co/top.md?page=47&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 48

---

## [Aggregate the total sum of aggregation field (bucket\_path)](https://discuss.elastic.co/t/aggregate-the-total-sum-of-aggregation-field-bucket-path/54364)

<div class="topic-metadata">

**Author:** [@NativAt](https://discuss.elastic.co/u/NativAt)\
**Replies:** 11\
**Last updated:** [December 19, 2016, 11:50am UTC](https://discuss.elastic.co/t/aggregate-the-total-sum-of-aggregation-field-bucket-path/54364 "2016-12-19T11:50:04Z")

</div>

Hi all, I'm trying with no luck so far, to aggregate the total impressions sum of impressions field, but I keep getting an error. I got the following query: GET smarttag-2016.06.28.\*/\_search?search\_type=count { "que…

---

## [Elasic-agent is online but don't send data](https://discuss.elastic.co/t/elasic-agent-is-online-but-dont-send-data/256293)

<div class="topic-metadata">

**Author:** [@aloalo2242](https://discuss.elastic.co/u/aloalo2242)\
**Replies:** 12\
**Last updated:** [July 13, 2022, 9:40am UTC](https://discuss.elastic.co/t/elasic-agent-is-online-but-dont-send-data/256293 "2022-07-13T09:40:44Z")

</div>

Hi, I'm trying to use Elastic Agent and Ingest Manager. I have enroll 2 windows agent with fleet. Installation is ok. In Fleet Tab, Kibana, 2 agent is Online. But it don't send any data (Logs, Index Management, Dashboar…

---

## [Elasticsearch-headで.rawの付いたフィールド名を表示するには](https://discuss.elastic.co/t/elasticsearch-head-raw/50512)

<div class="topic-metadata">

**Author:** [@yyam](https://discuss.elastic.co/u/yyam)\
**Replies:** 10\
**Last updated:** [June 20, 2016, 1:34am UTC](https://discuss.elastic.co/t/elasticsearch-head-raw/50512 "2016-06-20T01:34:51Z")

</div>

前回 、「kibanaで.rawの付いたフィールド名を表示するには」のご質問をして回答を頂いて解決しましたが、 マルチフィールドで生成されるフィールド ( ここでは .raw の付いたフィールドで、以下 name.raw と明記します) は、 元のフィールド ( ここでは .raw の付いていないフィールドで、以下 name と明記します) と同じように、 elasticsearchのデータベースの中に作成されて、 name …

---

## [Filebeat \> Nginx Module](https://discuss.elastic.co/t/filebeat-nginx-module/196026)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 34\
**Last updated:** [November 14, 2019, 3:22am UTC](https://discuss.elastic.co/t/filebeat-nginx-module/196026 "2019-11-14T03:22:30Z")

</div>

Hi all, i found that this Nginx Module's visualization does not provides the full template. How can I get it and steps to install it? As when I view the dashboard, some are appeared "Could not locate that index-pattern …

---

## [Data node cannot find master node](https://discuss.elastic.co/t/data-node-cannot-find-master-node/200662)

<div class="topic-metadata">

**Author:** [@Miao](https://discuss.elastic.co/u/Miao)\
**Replies:** 22\
**Last updated:** [September 24, 2019, 12:37pm UTC](https://discuss.elastic.co/t/data-node-cannot-find-master-node/200662 "2019-09-24T12:37:51Z")

</div>

I have two Windows VMs hosted on Azure. Both have ElasticSearch 7.x installed. One of them is designated as the master node, and the other a data node. Here are the contents of the elasticsearch.yml file on the master n…

---

## [Cardinality Aggregation - Different Unique Counts!](https://discuss.elastic.co/t/cardinality-aggregation-different-unique-counts/433)

<div class="topic-metadata">

**Author:** [@hmpmarketing](https://discuss.elastic.co/u/hmpmarketing)\
**Replies:** 17\
**Last updated:** [May 12, 2015, 10:15pm UTC](https://discuss.elastic.co/t/cardinality-aggregation-different-unique-counts/433 "2015-05-12T22:15:06Z")

</div>

Hey guys, I am still trying to figure this out, 2 ElasticSearch queries, unique count on one is 112019 And the other : 164322 Here are the Requests and responses http://pastebin.com/4kHJiL9t and http://paste…

---

## [GROK Parsing Problem - IP within brackets AND parentheses](https://discuss.elastic.co/t/grok-parsing-problem-ip-within-brackets-and-parentheses/141845)

<div class="topic-metadata">

**Author:** [@NeQter](https://discuss.elastic.co/u/NeQter)\
**Replies:** 9\
**Last updated:** [July 27, 2018, 1:12pm UTC](https://discuss.elastic.co/t/grok-parsing-problem-ip-within-brackets-and-parentheses/141845 "2018-07-27T13:12:14Z")

</div>

Hello. I am having some trouble parsing the following log: \<14\>Jul 26 13:37:17 NL-Syn1-RI Connection: User \[SYNNAS\\WIN7$\] from \[192.168.10.111(192.168.10.111)\] via \[CIFS(SMB2)\] accessed shared folder \[sysvol\]. This is …

---

## [Recommended maximum fields per index](https://discuss.elastic.co/t/recommended-maximum-fields-per-index/4388)

<div class="topic-metadata">

**Author:** [@maho](https://discuss.elastic.co/u/maho)\
**Replies:** 9\
**Last updated:** [May 12, 2011, 9:57pm UTC](https://discuss.elastic.co/t/recommended-maximum-fields-per-index/4388 "2011-05-12T21:57:43Z")

</div>

Hi, is there a maximum number of fields per index you should not exceed because performance issues? In my case I have 10 types per index and 150 fields per type - summarized 1500 fields per index. And secondly…

---

## [Installed Kibana 5. Can only run as root](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462)

<div class="topic-metadata">

**Author:** [@brandondash](https://discuss.elastic.co/u/brandondash)\
**Replies:** 12\
**Last updated:** [May 24, 2017, 6:13pm UTC](https://discuss.elastic.co/t/installed-kibana-5-can-only-run-as-root/86462 "2017-05-24T18:13:10Z")

</div>

If I run as root everything works fine. If I do not run as root I get the following error: /usr/share/kibana/bin/../node/bin/node /usr/share/kibana/bin/../src/cli -c /etc/kibana/kibana.yml net.js:10 const cares = proce…

---

## [8.2.3 Failed to parse field of type text](https://discuss.elastic.co/t/8-2-3-failed-to-parse-field-of-type-text/308168)

<div class="topic-metadata">

**Author:** [@Jack\_Park](https://discuss.elastic.co/u/Jack_Park)\
**Replies:** 12\
**Last updated:** [June 29, 2022, 11:42pm UTC](https://discuss.elastic.co/t/8-2-3-failed-to-parse-field-of-type-text/308168 "2022-06-29T23:42:48Z")

</div>

I created a gist here It could be something as trivial as the way I crafted the mappings. I've been using ES 6 for years, but migrating to 8+ brings on new adventures. The gist gives the json object I am passing in. I…

---

## [Elasticsearch appears to ignore -XX:+UseG1GC in jvm.options](https://discuss.elastic.co/t/elasticsearch-appears-to-ignore-xx-useg1gc-in-jvm-options/96862)

<div class="topic-metadata">

**Author:** [@goldfish](https://discuss.elastic.co/u/goldfish)\
**Replies:** 14\
**Last updated:** [August 22, 2017, 1:25am UTC](https://discuss.elastic.co/t/elasticsearch-appears-to-ignore-xx-useg1gc-in-jvm-options/96862 "2017-08-22T01:25:28Z")

</div>

Hi, We’re running Elasticsearch 5.4.1 on OpenJDK 1.8.0\_141. We recently tried switching from CMS to G1GC by replacing the following lines in jvm.options: -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -…

---

## [Elasticsearch JVM Memory Pressure Issue](https://discuss.elastic.co/t/elasticsearch-jvm-memory-pressure-issue/181621)

<div class="topic-metadata">

**Author:** [@dey\_subhro](https://discuss.elastic.co/u/dey_subhro)\
**Replies:** 28\
**Last updated:** [May 29, 2019, 10:04am UTC](https://discuss.elastic.co/t/elasticsearch-jvm-memory-pressure-issue/181621 "2019-05-29T10:04:33Z")

</div>

Hi, I am using m4.large.elasticsearch with 2 nodes having 512 GB of EBS Volume.In total of 1TB disk space. I have setup the fielddata cache limit to 40%. We are continuously experiencing Cluster Index Blocking issue wh…

---

## [Misspelled words or Typo Mistakes handling in Elastic Search without fuzziness](https://discuss.elastic.co/t/misspelled-words-or-typo-mistakes-handling-in-elastic-search-without-fuzziness/351083)

<div class="topic-metadata">

**Author:** [@Mohandass](https://discuss.elastic.co/u/Mohandass)\
**Replies:** 15\
**Last updated:** [January 18, 2024, 8:45am UTC](https://discuss.elastic.co/t/misspelled-words-or-typo-mistakes-handling-in-elastic-search-without-fuzziness/351083 "2024-01-18T08:45:13Z")

</div>

Hi All, We are working on an ecommerce product with Next JS and Python API driven project. In this we have implemented Elasticsearch Rest based API calls from React JS. We are facing a problem as below, Spelling Mista…

---

## [Ruby code in logstash](https://discuss.elastic.co/t/ruby-code-in-logstash/107735)

<div class="topic-metadata">

**Author:** [@Shekhar\_Pandey](https://discuss.elastic.co/u/Shekhar_Pandey)\
**Replies:** 12\
**Last updated:** [November 16, 2017, 8:41am UTC](https://discuss.elastic.co/t/ruby-code-in-logstash/107735 "2017-11-16T08:41:54Z")

</div>

I want to fetch the column name in ruby... for example mrp = Rs.23 brand = Apple Above is my mysql database.... So I am using event.get(mrp) and getting value. But I also want mrp as a name. So how can I get. And …

---

## [Slow performance of Elasticsearch-Hadoop + Spark SQL](https://discuss.elastic.co/t/slow-performance-of-elasticsearch-hadoop-spark-sql/1859)

<div class="topic-metadata">

**Author:** [@dmitriyf](https://discuss.elastic.co/u/dmitriyf)\
**Replies:** 10\
**Last updated:** [June 22, 2015, 4:54pm UTC](https://discuss.elastic.co/t/slow-performance-of-elasticsearch-hadoop-spark-sql/1859 "2015-06-22T16:54:51Z")

</div>

Hi Costin, Thank you for quick reply and detail explanation. I understand that working with Elasticsearch via Spark SQL cannot be free and it makes sense that the performance would be slower by some percentage compar…

---

## [Cluster broken after 7.2 -\> 7.4 upgrade](https://discuss.elastic.co/t/cluster-broken-after-7-2-7-4-upgrade/206170)

<div class="topic-metadata">

**Author:** [@Grimur\_Danielsson](https://discuss.elastic.co/u/Grimur_Danielsson)\
**Replies:** 14\
**Last updated:** [November 8, 2019, 10:02am UTC](https://discuss.elastic.co/t/cluster-broken-after-7-2-7-4-upgrade/206170 "2019-11-08T10:02:00Z")

</div>

Hi I upgraded my cluster (3 master nodes) from 7.2 to 7.4 last night after which it completely fell apart. It looks like there is some communication issue between the nodes in the cluster and they keep on trying to ele…

---

## [No Result Found Kibana](https://discuss.elastic.co/t/no-result-found-kibana/117244)

<div class="topic-metadata">

**Author:** [@Sam12](https://discuss.elastic.co/u/Sam12)\
**Replies:** 12\
**Last updated:** [February 7, 2018, 6:43pm UTC](https://discuss.elastic.co/t/no-result-found-kibana/117244 "2018-02-07T18:43:23Z")

</div>

Hello Everyone Is there a way to represent data as 0 instead of No result found status. Thanks Sam

---

## [Kibana 7.7.0 Basic version: management tab missing Security panel when started from docker](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412)

<div class="topic-metadata">

**Author:** [@jimisdrpc](https://discuss.elastic.co/u/jimisdrpc)\
**Replies:** 26\
**Last updated:** [May 21, 2020, 6:38pm UTC](https://discuss.elastic.co/t/kibana-7-7-0-basic-version-management-tab-missing-security-panel-when-started-from-docker/233412 "2020-05-21T18:38:02Z")

</div>

I can't find Security under Kibana 7.7 when I pull it from docker instead of downloading and installing manually Kibana. I posted same question in (https://stackoverflow.com/questions/61900546/kibana-7-7-0-basic-version-…

---

## [Cluster will not leave 'red' state no matter what I do](https://discuss.elastic.co/t/cluster-will-not-leave-red-state-no-matter-what-i-do/867)

<div class="topic-metadata">

**Author:** [@Don\_Pich](https://discuss.elastic.co/u/Don_Pich)\
**Replies:** 11\
**Last updated:** [May 22, 2015, 1:34pm UTC](https://discuss.elastic.co/t/cluster-will-not-leave-red-state-no-matter-what-i-do/867 "2015-05-22T13:34:44Z")

</div>

I have an elasticsearch cluster that will not leave a red state no matter what I try. "cluster\_name" : "es-logstash", "status" : "red", "timed\_out" : false, "number\_of\_nodes" : 13, "number\_o…

---

## [Querying with Completion Suggesters with Java API](https://discuss.elastic.co/t/querying-with-completion-suggesters-with-java-api/16822)

<div class="topic-metadata">

**Author:** [@Bill\_Wortinger](https://discuss.elastic.co/u/Bill_Wortinger)\
**Replies:** 13\
**Last updated:** [April 28, 2014, 7:37pm UTC](https://discuss.elastic.co/t/querying-with-completion-suggesters-with-java-api/16822 "2014-04-28T19:37:19Z")

</div>

I have my indices created, and mapping type for my 'suggest' field set to completion. I can't figure out how to configure the query for completion suggestions in elastic-search (Java API). I'm trying to use thi…

---

## [Duplicate events with Filebeat on windows on service restart](https://discuss.elastic.co/t/duplicate-events-with-filebeat-on-windows-on-service-restart/78743)

<div class="topic-metadata">

**Author:** [@eirc](https://discuss.elastic.co/u/eirc)\
**Replies:** 14\
**Last updated:** [March 21, 2017, 12:43pm UTC](https://discuss.elastic.co/t/duplicate-events-with-filebeat-on-windows-on-service-restart/78743 "2017-03-21T12:43:16Z")

</div>

We have a log file we are harvesting with Filebeat on some Windows hosts (2008 R2 Datacenter). Whenever the filebeat service is restarted the file gets fully resent. Here the log of filebeat shutting down: 2017-03-15…

---

## [Logstash pipeline grok issue with regex](https://discuss.elastic.co/t/logstash-pipeline-grok-issue-with-regex/308252)

<div class="topic-metadata">

**Author:** [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Replies:** 24\
**Last updated:** [July 20, 2022, 6:49am UTC](https://discuss.elastic.co/t/logstash-pipeline-grok-issue-with-regex/308252 "2022-07-20T06:49:18Z")

</div>

Hi , we have a Logstash pipeline , for Kafka on-premise Confluent Platform logs - shipped using Filebeat Kafka module , We are using a grok pattern to extract some of the entries in the data in order to use that data i…

---

## [Elasticsearch cluster in Yellow state and 1 Unassigned Shard](https://discuss.elastic.co/t/elasticsearch-cluster-in-yellow-state-and-1-unassigned-shard/247290)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 26\
**Last updated:** [September 4, 2020, 7:00pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-in-yellow-state-and-1-unassigned-shard/247290 "2020-09-04T19:00:13Z")

</div>

Hi All, I am running ELK 7.6.2 stack. Recently the cluster state went "Yellow" and it started showing one Unassigned Shard. Please see below: { "cluster\_name" : "elkcluster-prod", "status" : "yellow", "timed\_ou…

---

## [What is a Valid Geometry in ES?](https://discuss.elastic.co/t/what-is-a-valid-geometry-in-es/94465)

<div class="topic-metadata">

**Author:** [@cabane77](https://discuss.elastic.co/u/cabane77)\
**Replies:** 15\
**Last updated:** [July 28, 2017, 2:29pm UTC](https://discuss.elastic.co/t/what-is-a-valid-geometry-in-es/94465 "2017-07-28T14:29:15Z")

</div>

My question is a repeat of the below, but since there was no response, I had to ask again. This is really causing us a lot of problems as we simply can't import the spatial data in ES - although we have validated those …

---

## [Shield accepts any username/password combination](https://discuss.elastic.co/t/shield-accepts-any-username-password-combination/45269)

<div class="topic-metadata">

**Author:** [@Michael1](https://discuss.elastic.co/u/Michael1)\
**Replies:** 28\
**Last updated:** [March 25, 2016, 4:23pm UTC](https://discuss.elastic.co/t/shield-accepts-any-username-password-combination/45269 "2016-03-25T16:23:07Z")

</div>

I just deployed Shield + Shield plugin for Kibana. All is working but one major issue is happening :: The Shield login page will accept any username/password combination and allows into Kibana to see everything!!!! W…

---

## [Logstash xpack.monitoring.elasticsearch.password](https://discuss.elastic.co/t/logstash-xpack-monitoring-elasticsearch-password/196604)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 18\
**Last updated:** [August 28, 2019, 11:38pm UTC](https://discuss.elastic.co/t/logstash-xpack-monitoring-elasticsearch-password/196604 "2019-08-28T23:38:12Z")

</div>

Hi there, Is it possible to use a keystore to store this password. I don't want to have any plain text passwords in config file I'm specifically talking about this setting xpack.monitoring.elasticsearch.username: "log…

---

## [Missing logs with rotate log](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401)

<div class="topic-metadata">

**Author:** [@Amos\_Shahar](https://discuss.elastic.co/u/Amos_Shahar)\
**Replies:** 14\
**Last updated:** [July 18, 2016, 6:27am UTC](https://discuss.elastic.co/t/missing-logs-with-rotate-log/54401 "2016-07-18T06:27:10Z")

</div>

hi, I am using filebeat (version 1.2.3-1 on AWS linux AMI) to forward to logstash and I have missing logs (every time the file rotates I think). the specific file is rotating every 20M and in the peak time it is rotat…

---

## [Concept of Elasticsearch cluster](https://discuss.elastic.co/t/concept-of-elasticsearch-cluster/201376)

<div class="topic-metadata">

**Author:** [@pyerunka](https://discuss.elastic.co/u/pyerunka)\
**Replies:** 74\
**Last updated:** [November 19, 2019, 7:24am UTC](https://discuss.elastic.co/t/concept-of-elasticsearch-cluster/201376 "2019-11-19T07:24:42Z")

</div>

Hello, I want to apply elasticsearch cluster on my environment. I have done some changes in elasticsearch.yaml file like: cluster.name: Test node.name: node-1 node.data: true node.master: true what values we have t…

---

## [Percolator performance](https://discuss.elastic.co/t/percolator-performance/28997)

<div class="topic-metadata">

**Author:** [@sherifzain](https://discuss.elastic.co/u/sherifzain)\
**Replies:** 17\
**Last updated:** [September 11, 2015, 12:16pm UTC](https://discuss.elastic.co/t/percolator-performance/28997 "2015-09-11T12:16:04Z")

</div>

Hello, I'm currently writing an application that heavily uses ES percolator. To give an idea about what I'm trying to do: I'm percolating an average of 20k new documents through a job that runs every 2 mins, each doc…

---

## [Can't see the second node whilst attempting to build a cluster](https://discuss.elastic.co/t/cant-see-the-second-node-whilst-attempting-to-build-a-cluster/163187)

<div class="topic-metadata">

**Author:** [@sc1](https://discuss.elastic.co/u/sc1)\
**Replies:** 14\
**Last updated:** [February 1, 2019, 4:30pm UTC](https://discuss.elastic.co/t/cant-see-the-second-node-whilst-attempting-to-build-a-cluster/163187 "2019-02-01T16:30:24Z")

</div>

Hello, I am looking to add a second node and create a cluster. I have installed version 6.5.1 of Elasticsearch on 2 servers. The primary node has the full stack (Elasticsearch, Kibana, Logstash) and the second node has …

---

## [Get list with all users name?](https://discuss.elastic.co/t/get-list-with-all-users-name/25434)

<div class="topic-metadata">

**Author:** [@Smasell](https://discuss.elastic.co/u/Smasell)\
**Replies:** 9\
**Last updated:** [July 14, 2015, 5:35am UTC](https://discuss.elastic.co/t/get-list-with-all-users-name/25434 "2015-07-14T05:35:33Z")

</div>

Hi!!! I have many documents with field "user-name". I want to see list with all user names in it.

---

## [How many indices can elasticsearch handle](https://discuss.elastic.co/t/how-many-indices-can-elasticsearch-handle/37907)

<div class="topic-metadata">

**Author:** [@Sai\_Birada](https://discuss.elastic.co/u/Sai_Birada)\
**Replies:** 10\
**Last updated:** [December 29, 2015, 8:53pm UTC](https://discuss.elastic.co/t/how-many-indices-can-elasticsearch-handle/37907 "2015-12-29T20:53:01Z")

</div>

Hai, I am currently running my Elasticsearch cluster on two EC2 d2.2x large machines, so i had 8 cores, 32 gb heap space and 32gb left for os, and 11tb hdd harddisk on each machine and one EC2 d2 x large for master only …

---

## [ES Cluster on ZFS with PCIe3.0 SSD/SATA SSD](https://discuss.elastic.co/t/es-cluster-on-zfs-with-pcie3-0-ssd-sata-ssd/41911)

<div class="topic-metadata">

**Author:** [@BigPete](https://discuss.elastic.co/u/BigPete)\
**Replies:** 16\
**Last updated:** [October 13, 2016, 7:51am UTC](https://discuss.elastic.co/t/es-cluster-on-zfs-with-pcie3-0-ssd-sata-ssd/41911 "2016-10-13T07:51:51Z")

</div>

Hi, Just wondering if anyone has configured ES on a ZFS Pool of PCIe x3.0 SSDs and SATA3 SSDs yet and if how they found performance? If so did you do anything special with the PCIe SSD and the L2ARC? Thanks, BigPet…

---

## [Mysql data not seen in packetbeats](https://discuss.elastic.co/t/mysql-data-not-seen-in-packetbeats/56350)

<div class="topic-metadata">

**Author:** [@shaikmuzakkir](https://discuss.elastic.co/u/shaikmuzakkir)\
**Replies:** 23\
**Last updated:** [August 8, 2016, 12:18pm UTC](https://discuss.elastic.co/t/mysql-data-not-seen-in-packetbeats/56350 "2016-08-08T12:18:24Z")

</div>

I do not see the mysql data in the packetbeats when I run the command packetbeat -e -d "publish" -N. Whereas I see the DNS and Redis data flowing in. I have used the 127.0.0.1 ip to access mysql instead of localhost. My…

---

## [Logstash jdbc-input taking long time to load data from Oracle DataBase](https://discuss.elastic.co/t/logstash-jdbc-input-taking-long-time-to-load-data-from-oracle-database/246646)

<div class="topic-metadata">

**Author:** [@amitgupta](https://discuss.elastic.co/u/amitgupta)\
**Replies:** 21\
**Last updated:** [September 7, 2020, 8:55am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-taking-long-time-to-load-data-from-oracle-database/246646 "2020-09-07T08:55:37Z")

</div>

I am using ELK stack. I have to load Oracle data to ElasticSearch. There are around 5 million data to load at initial. Problem: The logstash is very very slow to load data, it loads around 50k in 30 mins. this speed is …

---

## [Half-dead node lead to cluster hang](https://discuss.elastic.co/t/half-dead-node-lead-to-cluster-hang/113658)

<div class="topic-metadata">

**Author:** [@ginger](https://discuss.elastic.co/u/ginger)\
**Replies:** 31\
**Last updated:** [February 20, 2018, 2:24am UTC](https://discuss.elastic.co/t/half-dead-node-lead-to-cluster-hang/113658 "2018-02-20T02:24:49Z")

</div>

Elasticsearch version (bin/elasticsearch --version): 5.6.4 JVM version (java -version): 1.8.0\_91 Description of the problem including expected versus actual behavior: In production enviroment, we have encounter hard…

---

## [Identifying hot shards to address uneven load](https://discuss.elastic.co/t/identifying-hot-shards-to-address-uneven-load/13775)

<div class="topic-metadata">

**Author:** [@David\_O\_Dell](https://discuss.elastic.co/u/David_O_Dell)\
**Replies:** 11\
**Last updated:** [October 15, 2013, 5:14am UTC](https://discuss.elastic.co/t/identifying-hot-shards-to-address-uneven-load/13775 "2013-10-15T05:14:42Z")

</div>

I have read many posts in this group about uneven load and hot shards. We are experiencing the same symptoms where one data node out of 8 has 100% CPU usage and the other 7 nodes operate at 40%. My question is how …

---

## [Failed to perform any bulk index operations: 403 Forbidden:](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-403-forbidden/153207)

<div class="topic-metadata">

**Author:** [@sirababu](https://discuss.elastic.co/u/sirababu)\
**Replies:** 11\
**Last updated:** [November 2, 2018, 11:44pm UTC](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-403-forbidden/153207 "2018-11-02T23:44:00Z")

</div>

Hello Search Guru's I am getting this error, i have a AWS ELK POC cluster(1 node), i am using filebeat to ingest data, getting this error With curl i can create index, any suggestions, thanks elasticsearch/client.go:3…

---

## [Logstash Peformance](https://discuss.elastic.co/t/logstash-peformance/80966)

<div class="topic-metadata">

**Author:** [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Replies:** 34\
**Last updated:** [April 21, 2017, 8:37am UTC](https://discuss.elastic.co/t/logstash-peformance/80966 "2017-04-21T08:37:25Z")

</div>

Hello, I would like know tips to increase performance of Logtash. Currently i have : OS RH 7.1 : 12 CPU & 24 Go RAM Filebeat as shipper Elasticsearch : Xms Xmx : 12g Logstash (define in logstash.yml) : Work…

---

## [How to remove deleted elasticsearch logs from file system?](https://discuss.elastic.co/t/how-to-remove-deleted-elasticsearch-logs-from-file-system/174076)

<div class="topic-metadata">

**Author:** [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Replies:** 16\
**Last updated:** [April 7, 2019, 1:18pm UTC](https://discuss.elastic.co/t/how-to-remove-deleted-elasticsearch-logs-from-file-system/174076 "2019-04-07T13:18:40Z")

</div>

Hi everyone! I have a problem: I run elasticsearch 6.2 on CentOS7 machine, and I see that my disk is filling up (by running "df" command). When I check with the "du" command I don't see anything that could account for …

---

## [Attachment(PDF/DOC) Indexing and Searching on ElasticSearch in PHP](https://discuss.elastic.co/t/attachment-pdf-doc-indexing-and-searching-on-elasticsearch-in-php/72370)

<div class="topic-metadata">

**Author:** [@selimppc](https://discuss.elastic.co/u/selimppc)\
**Replies:** 9\
**Last updated:** [January 22, 2017, 4:48pm UTC](https://discuss.elastic.co/t/attachment-pdf-doc-indexing-and-searching-on-elasticsearch-in-php/72370 "2017-01-22T16:48:40Z")

</div>

I have installed elasticsearch in my local pc. Also installed mapper-attachments and kibana. I can index string data into a index and search. But when I trying to search text from PDF or docx in a folder :: Its not wo…

---

## [Error creating machine learning job "autodetect"](https://discuss.elastic.co/t/error-creating-machine-learning-job-autodetect/98703)

<div class="topic-metadata">

**Author:** [@Richard\_Neely](https://discuss.elastic.co/u/Richard_Neely)\
**Replies:** 13\
**Last updated:** [September 1, 2017, 12:48pm UTC](https://discuss.elastic.co/t/error-creating-machine-learning-job-autodetect/98703 "2017-09-01T12:48:25Z")

</div>

I get an error creating the most basic machine learning job. In kibana it says “could not open job an internal server error occured.” In the elastic logs this is what it says. I can launch autodetect plugin from the cli …

---

## [Status red in Kibana](https://discuss.elastic.co/t/status-red-in-kibana/124196)

<div class="topic-metadata">

**Author:** [@Piyushpky](https://discuss.elastic.co/u/Piyushpky)\
**Replies:** 11\
**Last updated:** [March 16, 2018, 7:58am UTC](https://discuss.elastic.co/t/status-red-in-kibana/124196 "2018-03-16T07:58:58Z")

</div>

I am new here. I did setup the elk and that was running fine until i did sudo yum update. Now the status is red. I have attached the screenshot. My elasticsearch version is 5.6.8. Thanks.\[Screenshot%20(6)\]

---

## [ES 5.5.0 will not start up with gce discovery](https://discuss.elastic.co/t/es-5-5-0-will-not-start-up-with-gce-discovery/94541)

<div class="topic-metadata">

**Author:** [@svanschalkwyk](https://discuss.elastic.co/u/svanschalkwyk)\
**Replies:** 21\
**Last updated:** [July 27, 2017, 2:14am UTC](https://discuss.elastic.co/t/es-5-5-0-will-not-start-up-with-gce-discovery/94541 "2017-07-27T02:14:12Z")

</div>

My elasticsearch.yml looks like this: cluster.name: gce-cluster discovery.zen.ping.unicast.hosts: - 104.198.44.16 - 35.184.239.42 http.port: 9200 network.host: \_gce\_ node.data: false node.master: true transport.tcp.po…

---

## [JSON Parse error](https://discuss.elastic.co/t/json-parse-error/59251)

<div class="topic-metadata">

**Author:** [@pstarconsult](https://discuss.elastic.co/u/pstarconsult)\
**Replies:** 9\
**Last updated:** [August 30, 2016, 6:30pm UTC](https://discuss.elastic.co/t/json-parse-error/59251 "2016-08-30T18:30:26Z")

</div>

I get a parse error when trying to index a JSON file. I am running this from the Python API for ES and, as I step deep into the code, it appears to be based on the format that Tika generates. I have a very simple TXT fil…

---

## [Elasticsearch 7.2 slow query after update](https://discuss.elastic.co/t/elasticsearch-7-2-slow-query-after-update/189784)

<div class="topic-metadata">

**Author:** [@roytmana](https://discuss.elastic.co/u/roytmana)\
**Replies:** 14\
**Last updated:** [July 21, 2019, 9:03pm UTC](https://discuss.elastic.co/t/elasticsearch-7-2-slow-query-after-update/189784 "2019-07-21T21:03:50Z")

</div>

I noticed that after posting update to even single document when I search on that index for this single document (query is not trivial but not especially complex either but it has nested element) there is a perceptible …

---

## [Unable to start filebeats](https://discuss.elastic.co/t/unable-to-start-filebeats/159659)

<div class="topic-metadata">

**Author:** [@Chandana](https://discuss.elastic.co/u/Chandana)\
**Replies:** 10\
**Last updated:** [December 6, 2018, 11:13am UTC](https://discuss.elastic.co/t/unable-to-start-filebeats/159659 "2018-12-06T11:13:34Z")

</div>

I get the below error when I tried to start the filebeat. ● filebeat.service - filebeat Loaded: loaded (/usr/lib/systemd/system/filebeat.service; disabled; vendor preset: disabled) Active: failed (Result: start-limit)…

---

## [Cannot search on field \[log.original\] since it is not indexed](https://discuss.elastic.co/t/cannot-search-on-field-log-original-since-it-is-not-indexed/295897)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 12\
**Last updated:** [February 1, 2022, 9:32pm UTC](https://discuss.elastic.co/t/cannot-search-on-field-log-original-since-it-is-not-indexed/295897 "2022-02-01T21:32:09Z")

</div>

Hi --I am not sure how to diagnose this issue. My searching has offered no results. When I try to refine my iptables query with \> log.original: "ID=1234" I get the error: failed to create query: Cannot search on field …

---

## [I have config logstash for ELK to monitor IIS logs in window 7 but Kibana is not able to index logstash](https://discuss.elastic.co/t/i-have-config-logstash-for-elk-to-monitor-iis-logs-in-window-7-but-kibana-is-not-able-to-index-logstash/146622)

<div class="topic-metadata">

**Author:** [@anwarshahtarn](https://discuss.elastic.co/u/anwarshahtarn)\
**Replies:** 19\
**Last updated:** [August 31, 2018, 11:01am UTC](https://discuss.elastic.co/t/i-have-config-logstash-for-elk-to-monitor-iis-logs-in-window-7-but-kibana-is-not-able-to-index-logstash/146622 "2018-08-31T11:01:07Z")

</div>

\[INFO \] 2018-08-30 10:21:32.130 \[Ruby-0-Thread-5: C:/Program Files/Elastic/logst ash-6.4.0/logstash-6.4.0/vendor/bundle/jruby/2.3.0/gems/logstash-output-elastics earch-9.2.0-java/lib/logstash/outputs/elasticsearch/common…

---

## [Conditional filtering not working in logstash](https://discuss.elastic.co/t/conditional-filtering-not-working-in-logstash/166913)

<div class="topic-metadata">

**Author:** [@MiddlewareTeam](https://discuss.elastic.co/u/MiddlewareTeam)\
**Replies:** 12\
**Last updated:** [February 6, 2019, 12:27pm UTC](https://discuss.elastic.co/t/conditional-filtering-not-working-in-logstash/166913 "2019-02-06T12:27:19Z")

</div>

We have below setup in filebeat based on which we are using filtering in logstash but it is not working as expected. Filebeat input: \< -type: log paths: /app/logpath fields: log\_type: apache\_access application: …

[Previous page](https://discuss.elastic.co/top.md?page=46&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=48&per_page=50&period=all)
