# Top

**URL:** https://discuss.elastic.co/top.md?page=49&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 50

---

## [Failed to send join request to master in Elastic 6.4.0](https://discuss.elastic.co/t/failed-to-send-join-request-to-master-in-elastic-6-4-0/147943)

<div class="topic-metadata">

**Author:** [@dhananjay88](https://discuss.elastic.co/u/dhananjay88)\
**Replies:** 15\
**Last updated:** [September 10, 2018, 4:19pm UTC](https://discuss.elastic.co/t/failed-to-send-join-request-to-master-in-elastic-6-4-0/147943 "2018-09-10T16:19:54Z")

</div>

Hi, I am getting the Error of failed to send join request to master while running Elastic 6.4.0. Please see the below given log snapshot and help me. Master Node Config cluster.name: aabb node.name: linsee1 node.mast…

---

## [Another High CPU usage with Logstash](https://discuss.elastic.co/t/another-high-cpu-usage-with-logstash/202836)

<div class="topic-metadata">

**Author:** [@mhare](https://discuss.elastic.co/u/mhare)\
**Replies:** 16\
**Last updated:** [October 29, 2019, 1:15pm UTC](https://discuss.elastic.co/t/another-high-cpu-usage-with-logstash/202836 "2019-10-29T13:15:12Z")

</div>

1st: fairly new to ElasticStack configuration I've looked at the other topics on High CPU, but I do not believe they are helping me I have an Ubuntu box with 8 cores and 8 G of Ram This machine is running Logstash, El…

---

## [Deploy Cluster ES with multiple node?](https://discuss.elastic.co/t/deploy-cluster-es-with-multiple-node/37300)

<div class="topic-metadata">

**Author:** [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Replies:** 9\
**Last updated:** [December 16, 2015, 10:06am UTC](https://discuss.elastic.co/t/deploy-cluster-es-with-multiple-node/37300 "2015-12-16T10:06:24Z")

</div>

Hi, I'm Newbie. I have question : I'm setting up ELK with one Cluster (cluster name : Main-Cluster). I want to have three node (Node1, Node, Node3) for receiving data from Logstash. (data Node ???) I see three diffe…

---

## [Elasticsearch Index Completely Missing](https://discuss.elastic.co/t/elasticsearch-index-completely-missing/140640)

<div class="topic-metadata">

**Author:** [@hacker\_21](https://discuss.elastic.co/u/hacker_21)\
**Replies:** 13\
**Last updated:** [July 22, 2018, 4:34pm UTC](https://discuss.elastic.co/t/elasticsearch-index-completely-missing/140640 "2018-07-22T16:34:34Z")

</div>

Hey there, I've had an elasticsearch cluster running since late June. My search wasn't working today and when I looked at the app I was getting this error: elasticsearch.exceptions.NotFoundError: TransportError(404, '…

---

## [Injest Pipeline for conditional statement used in Scripts](https://discuss.elastic.co/t/injest-pipeline-for-conditional-statement-used-in-scripts/298178)

<div class="topic-metadata">

**Author:** [@shivani\_singh](https://discuss.elastic.co/u/shivani_singh)\
**Replies:** 25\
**Last updated:** [March 2, 2022, 5:25am UTC](https://discuss.elastic.co/t/injest-pipeline-for-conditional-statement-used-in-scripts/298178 "2022-03-02T05:25:12Z")

</div>

Hii, My goals - Find the existing field if present (responseBody.results\[i\].statusCode) and copy it's value into a new field (embedded\_error\_code ) at runtime My original field is a list of array. Below is the struct…

---

## [Unable see logs In kibana after 15 minutes](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462)

<div class="topic-metadata">

**Author:** [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Replies:** 19\
**Last updated:** [April 18, 2018, 11:17am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462 "2018-04-18T11:17:12Z")

</div>

Hi there, I am new in ELK, and I setup the ELK first time on my local machine. After restarting filebeat on client i am able to see logs on kibana dashboard. But after 15 mins. I am unable to see any logs and getting "N…

---

## [Display a string value (from a JSON key) in the tabular format of visualisation](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875)

<div class="topic-metadata">

**Author:** [@ppp](https://discuss.elastic.co/u/ppp)\
**Replies:** 10\
**Last updated:** [March 1, 2016, 5:38pm UTC](https://discuss.elastic.co/t/display-a-string-value-from-a-json-key-in-the-tabular-format-of-visualisation/42875 "2016-03-01T17:38:00Z")

</div>

Hello, I'd really appreciate your help in the following. I am receiving JSON messages in Kibana and in them there is a key called warning. I'd like to create a simple visualisation (in tabular format?) that shows the t…

---

## [\[SOLVED\] Split filter question a.k.a flatten json sub array](https://discuss.elastic.co/t/solved-split-filter-question-a-k-a-flatten-json-sub-array/130481)

<div class="topic-metadata">

**Author:** [@blastik](https://discuss.elastic.co/u/blastik)\
**Replies:** 14\
**Last updated:** [May 3, 2018, 7:14pm UTC](https://discuss.elastic.co/t/solved-split-filter-question-a-k-a-flatten-json-sub-array/130481 "2018-05-03T19:14:54Z")

</div>

Hi there! I have a json input which looks like this: \[{ "Action": "COUNT", "Timestamp": "2018-05-02T13:09:58Z", "Request": { "Country": "ES", "URI": "/uploadMultiplePhotos.aspx", "Headers": \[{ \> "Name": "…

---

## [Not allowed to increase reporting capture timeouts in Elastic cloud](https://discuss.elastic.co/t/not-allowed-to-increase-reporting-capture-timeouts-in-elastic-cloud/234697)

<div class="topic-metadata">

**Author:** [@Martijn04](https://discuss.elastic.co/u/Martijn04)\
**Replies:** 10\
**Last updated:** [July 6, 2020, 10:39am UTC](https://discuss.elastic.co/t/not-allowed-to-increase-reporting-capture-timeouts-in-elastic-cloud/234697 "2020-07-06T10:39:12Z")

</div>

Hello, We are using the Elastic Cloud service. When generating a report I get the following error message: An error occurred when trying to open the Kibana URL. You may need to increase 'xpack.reporting.capture.timeout…

---

## [Off-heap memory leak?](https://discuss.elastic.co/t/off-heap-memory-leak/128202)

<div class="topic-metadata">

**Author:** [@hokiegeek2](https://discuss.elastic.co/u/hokiegeek2)\
**Replies:** 14\
**Last updated:** [April 27, 2018, 11:10am UTC](https://discuss.elastic.co/t/off-heap-memory-leak/128202 "2018-04-27T11:10:12Z")

</div>

I continue to observe an elasticsearch on docker instance that continues to grab more and more off-heap memory until Mesos kills the docker container. Since there is no data going in with the exception of the .monitor i…

---

## [Security index is unavailable](https://discuss.elastic.co/t/security-index-is-unavailable/314824)

<div class="topic-metadata">

**Author:** [@rkulanga](https://discuss.elastic.co/u/rkulanga)\
**Replies:** 12\
**Last updated:** [September 21, 2022, 10:32am UTC](https://discuss.elastic.co/t/security-index-is-unavailable/314824 "2022-09-21T10:32:02Z")

</div>

Hi, Due to the low disk space (95% used) on my system goes down. Then I have removed some files from the indices directory and restart both Kibana and Elasticsearch service. But system is not working now. According to…

---

## [How to Reduce Received Logs Size in ELK Stack?](https://discuss.elastic.co/t/how-to-reduce-received-logs-size-in-elk-stack/301066)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 31\
**Last updated:** [April 4, 2022, 7:56am UTC](https://discuss.elastic.co/t/how-to-reduce-received-logs-size-in-elk-stack/301066 "2022-04-04T07:56:54Z")

</div>

Hi, I would like to ask, any way we can compress / dedup the sizes of the logs that we received in ELK stack? Thanks.

---

## [Main process exited, code=exited, status=1/FAILURE](https://discuss.elastic.co/t/main-process-exited-code-exited-status-1-failure/297751)

<div class="topic-metadata">

**Author:** [@allamsettiramesh](https://discuss.elastic.co/u/allamsettiramesh)\
**Replies:** 11\
**Last updated:** [February 22, 2022, 6:55am UTC](https://discuss.elastic.co/t/main-process-exited-code-exited-status-1-failure/297751 "2022-02-22T06:55:44Z")

</div>

Elasticsearch throwing below issue Version 7.17.0, Job for Elasticsearch.service failed because the control process exited with error code. See "systemctl status Elasticsearch.service" and "journalctl -xe" for detail…

---

## [LS-ES connection issue](https://discuss.elastic.co/t/ls-es-connection-issue/169205)

<div class="topic-metadata">

**Author:** [@Kanthasamyraja](https://discuss.elastic.co/u/Kanthasamyraja)\
**Replies:** 17\
**Last updated:** [February 25, 2019, 8:56am UTC](https://discuss.elastic.co/t/ls-es-connection-issue/169205 "2019-02-25T08:56:20Z")

</div>

Hi, Unable to start Logstash after xpack enabled. Exception Unable to retrieve license information from license server {:message=\>"Got response code '401' contacting Elasticsearch at URL 'http://HOSTNAME:9200/\_xpack'"…

---

## [Custom Aggregations](https://discuss.elastic.co/t/custom-aggregations/15740)

<div class="topic-metadata">

**Author:** [@Justin\_Uang](https://discuss.elastic.co/u/Justin_Uang)\
**Replies:** 15\
**Last updated:** [February 14, 2022, 2:40pm UTC](https://discuss.elastic.co/t/custom-aggregations/15740 "2022-02-14T14:40:23Z")

</div>

Is there any way we can define our own aggregation functions beyond the provided metric and bucket aggregations? Thanks! Justin -- You received this message because you are subscribed to the Google Groups "e…

---

## [Unable to connect to Elasticsearch at http://server\_ip:9200](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-at-http-server-ip-9200/137366)

<div class="topic-metadata">

**Author:** [@davis](https://discuss.elastic.co/u/davis)\
**Replies:** 10\
**Last updated:** [June 26, 2018, 8:56am UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-at-http-server-ip-9200/137366 "2018-06-26T08:56:05Z")

</div>

hi all... I installed Es in my ubuntu machine, successfully... And, I can curl in in command.The result is below: curl -XGET "http://ip\_address:9200" { "name" : ".....", "cluster\_name" : "elasticsearch", "cluster\_uu…

---

## [Delete index at a regular basis](https://discuss.elastic.co/t/delete-index-at-a-regular-basis/54621)

<div class="topic-metadata">

**Author:** [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Replies:** 10\
**Last updated:** [July 7, 2016, 6:06am UTC](https://discuss.elastic.co/t/delete-index-at-a-regular-basis/54621 "2016-07-07T06:06:38Z")

</div>

I have made different kinds of indexes into ES and everytime I want to delete some old indexes, I need to write the currator command to delete old indices. Even though I have read through the examples from https://www.e…

---

## [Elastic snapshot for GCS seem to be ignoring my client credentials](https://discuss.elastic.co/t/elastic-snapshot-for-gcs-seem-to-be-ignoring-my-client-credentials/217526)

<div class="topic-metadata">

**Author:** [@Guillaume\_Roderick](https://discuss.elastic.co/u/Guillaume_Roderick)\
**Replies:** 17\
**Last updated:** [February 3, 2020, 4:47pm UTC](https://discuss.elastic.co/t/elastic-snapshot-for-gcs-seem-to-be-ignoring-my-client-credentials/217526 "2020-02-03T16:47:44Z")

</div>

Hi, I've exhausted my google-fu and have trawled the documentation and similar issues discussed in these support and am completely stuck. I'm attempting to snapshot my cluster to GCS, and the system seems to be ignorin…

---

## [Elasticsearch 5.5.0 cluster crash -- elasticsearch.yml processors set too high](https://discuss.elastic.co/t/elasticsearch-5-5-0-cluster-crash-elasticsearch-yml-processors-set-too-high/92397)

<div class="topic-metadata">

**Author:** [@LogBabel](https://discuss.elastic.co/u/LogBabel)\
**Replies:** 26\
**Last updated:** [July 12, 2017, 3:42pm UTC](https://discuss.elastic.co/t/elasticsearch-5-5-0-cluster-crash-elasticsearch-yml-processors-set-too-high/92397 "2017-07-12T15:42:00Z")

</div>

Hello. We have a problem with ES 5.5.0 today about 12 hours after upgrading from 5.2.3. The upgrade was OK and the cluster was performing OK for many hours before the elected master crashed. Five hours later we resta…

---

## [Adding multiple values to an array](https://discuss.elastic.co/t/adding-multiple-values-to-an-array/296494)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 19\
**Last updated:** [February 14, 2022, 5:31pm UTC](https://discuss.elastic.co/t/adding-multiple-values-to-an-array/296494 "2022-02-14T17:31:27Z")

</div>

Hello, I have an array which contains a bunch of time stamps which get added every time the record is modified from the source PGSQL database. I'm looking to modify this array to contain both a string and a time stamp. …

---

## [Time delay between logstash and elasticsearch](https://discuss.elastic.co/t/time-delay-between-logstash-and-elasticsearch/227749)

<div class="topic-metadata">

**Author:** [@honglei](https://discuss.elastic.co/u/honglei)\
**Replies:** 11\
**Last updated:** [April 14, 2020, 3:20pm UTC](https://discuss.elastic.co/t/time-delay-between-logstash-and-elasticsearch/227749 "2020-04-14T15:20:13Z")

</div>

My current pipeline is: filebeat-\>Logstash-\>ES(3 nodes). Filebeat and Logstash are deployed in the kubernetes cluster, both of the them are version-7.6.2. ES is deployed as a container on a virtual machine, images ver…

---

## [Logstach Starting issue!](https://discuss.elastic.co/t/logstach-starting-issue/102830)

<div class="topic-metadata">

**Author:** [@SJN8](https://discuss.elastic.co/u/SJN8)\
**Replies:** 14\
**Last updated:** [October 6, 2017, 10:14am UTC](https://discuss.elastic.co/t/logstach-starting-issue/102830 "2017-10-06T10:14:34Z")

</div>

Hi All, I have configured File beat and logstach for log management . I am able to start Filebeat but while starting getting below error , ##################################################### root@logstach\_host bin\]…

---

## [Full backup of a single node](https://discuss.elastic.co/t/full-backup-of-a-single-node/26088)

<div class="topic-metadata">

**Author:** [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Replies:** 10\
**Last updated:** [July 24, 2015, 8:15pm UTC](https://discuss.elastic.co/t/full-backup-of-a-single-node/26088 "2015-07-24T20:15:35Z")

</div>

Topic says it...I have a single node running...I just want to do a full backup to a file before I do an upgrade. I've been poking around the list here, but haven't seen what I'm looking for...I did see the Knapsack plug…

---

## [Elasticsearch loses its Master every few minutes](https://discuss.elastic.co/t/elasticsearch-loses-its-master-every-few-minutes/31631)

<div class="topic-metadata">

**Author:** [@Michel\_Laporte](https://discuss.elastic.co/u/Michel_Laporte)\
**Replies:** 9\
**Last updated:** [October 9, 2015, 11:01am UTC](https://discuss.elastic.co/t/elasticsearch-loses-its-master-every-few-minutes/31631 "2015-10-09T11:01:26Z")

</div>

Hi, I have Graylog working with ES. I have 2 nodes and one elected as Master and the slave is Master eligible. I have installed KOPF on each one. However, after a few days of ES being started, i cannot load the KOP…

---

## [Connecting to a Elasticsearch running on a remote host](https://discuss.elastic.co/t/connecting-to-a-elasticsearch-running-on-a-remote-host/138453)

<div class="topic-metadata">

**Author:** [@Pritom\_Ahmed](https://discuss.elastic.co/u/Pritom_Ahmed)\
**Replies:** 9\
**Last updated:** [July 6, 2018, 5:59am UTC](https://discuss.elastic.co/t/connecting-to-a-elasticsearch-running-on-a-remote-host/138453 "2018-07-06T05:59:33Z")

</div>

Hi, I want to connect to an Elasticsearch running on a remote host. My code is as follows String host = "10.169.149.134"; byte\[\]ip = new byte\[\]{(byte)10, (byte) 169, (byte) 149, (byte) 134}; in…

---

## [Delete 7 days old data everyday](https://discuss.elastic.co/t/delete-7-days-old-data-everyday/156418)

<div class="topic-metadata">

**Author:** [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)\
**Replies:** 18\
**Last updated:** [November 26, 2018, 12:36pm UTC](https://discuss.elastic.co/t/delete-7-days-old-data-everyday/156418 "2018-11-26T12:36:28Z")

</div>

Hi I want to delete 7 days old data in my index everyday. I have not used time based index. In that scenario, will curator help? If so, I prefer to write java scheduler,can i write a java code using curator? Or Is it on…

---

## [Getting “master not discovered or elected yet” causing cluster not up in version 7.9.1](https://discuss.elastic.co/t/getting-master-not-discovered-or-elected-yet-causing-cluster-not-up-in-version-7-9-1/250269)

<div class="topic-metadata">

**Author:** [@Jinlian\_Chen](https://discuss.elastic.co/u/Jinlian_Chen)\
**Replies:** 20\
**Last updated:** [October 10, 2020, 8:43am UTC](https://discuss.elastic.co/t/getting-master-not-discovered-or-elected-yet-causing-cluster-not-up-in-version-7-9-1/250269 "2020-10-10T08:43:35Z")

</div>

Hi, I am building a 5 nodes cluster using k8s, 3 master nodes, and 2 data nodes. When restart 3 masters orderly, got error "master not discovered or elected yet", the cluster can't work. This situation last several hours…

---

## [Filebeat CRIT Exiting: Prospector with same ID already exists](https://discuss.elastic.co/t/filebeat-crit-exiting-prospector-with-same-id-already-exists/84897)

<div class="topic-metadata">

**Author:** [@sLuvpreet33](https://discuss.elastic.co/u/sLuvpreet33)\
**Replies:** 11\
**Last updated:** [June 12, 2017, 11:14pm UTC](https://discuss.elastic.co/t/filebeat-crit-exiting-prospector-with-same-id-already-exists/84897 "2017-06-12T23:14:08Z")

</div>

I am getting the error same as the Title. Filebeat is not running. What is the reason and how to cure this problem ?

---

## [Can not get to security setting in kibana on a basic licence](https://discuss.elastic.co/t/can-not-get-to-security-setting-in-kibana-on-a-basic-licence/190727)

<div class="topic-metadata">

**Author:** [@Ej\_R](https://discuss.elastic.co/u/Ej_R)\
**Replies:** 22\
**Last updated:** [July 18, 2019, 11:39am UTC](https://discuss.elastic.co/t/can-not-get-to-security-setting-in-kibana-on-a-basic-licence/190727 "2019-07-18T11:39:16Z")

</div>

Hi guys, So under management in Kibana I cannot seem to get to any of the security settings (the option does not appear in the menu). I have enabled xpack security settings. If I go through the dashboard to security th…

---

## [Return document for aggregation result](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510)

<div class="topic-metadata">

**Author:** [@animageofmine](https://discuss.elastic.co/u/animageofmine)\
**Replies:** 9\
**Last updated:** [May 12, 2017, 2:43pm UTC](https://discuss.elastic.co/t/return-document-for-aggregation-result/85510 "2017-05-12T14:43:36Z")

</div>

Stupid question and might be easy for experts: I want to perform max aggregation and want to get the corresponding document for the the result: POST /sales/\_search?&size=1 { "aggs" : { "max\_price"…

---

## [Kibana automatic activity is flooding audit log](https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413)

<div class="topic-metadata">

**Author:** [@Guy\_Shilo](https://discuss.elastic.co/u/Guy_Shilo)\
**Replies:** 11\
**Last updated:** [March 27, 2017, 1:28pm UTC](https://discuss.elastic.co/t/kibana-automatic-activity-is-flooding-audit-log/79413 "2017-03-27T13:28:53Z")

</div>

Hello I enabled auditing in my cluster using x-pack. In the log file I can see that Kibana is constantly sending monitoring and health check requests to the cluster, even when there is no user activity. Every few secon…

---

## [How to integrate AWS Lambda with plugin Elastic](https://discuss.elastic.co/t/how-to-integrate-aws-lambda-with-plugin-elastic/306506)

<div class="topic-metadata">

**Author:** [@Renato\_Souza](https://discuss.elastic.co/u/Renato_Souza)\
**Replies:** 33\
**Last updated:** [July 7, 2022, 11:57am UTC](https://discuss.elastic.co/t/how-to-integrate-aws-lambda-with-plugin-elastic/306506 "2022-07-07T11:57:37Z")

</div>

I am using functions beat to get logs from aws lambda (cloudwatch). But, i know exists an integration ready for AWS Lambda at Browse all integrations in cloud Elastic. I don't find documentation how to use this integrati…

---

## [Unnable to list snapshots in Elasticsearch repository](https://discuss.elastic.co/t/unnable-to-list-snapshots-in-elasticsearch-repository/271425)

<div class="topic-metadata">

**Author:** [@KA3AXCTAH](https://discuss.elastic.co/u/KA3AXCTAH)\
**Replies:** 38\
**Last updated:** [May 12, 2021, 8:35am UTC](https://discuss.elastic.co/t/unnable-to-list-snapshots-in-elasticsearch-repository/271425 "2021-05-12T08:35:15Z")

</div>

I have an Elasticsearch snapshot repository configured to folder on NFS share, and i'm unable to do list snapshots because of strange errors curl -X GET "10.0.1.159:9200/\_cat/snapshots/temp\_elastic\_backup?v&s=id&pretty"…

---

## [Delete by query not working for multiple ids](https://discuss.elastic.co/t/delete-by-query-not-working-for-multiple-ids/7991)

<div class="topic-metadata">

**Author:** [@SG1](https://discuss.elastic.co/u/SG1)\
**Replies:** 14\
**Last updated:** [December 12, 2012, 4:13am UTC](https://discuss.elastic.co/t/delete-by-query-not-working-for-multiple-ids/7991 "2012-12-12T04:13:37Z")

</div>

I am trying to delete all the indices which matches the id array, when I try to fetch with "ids": {"values":\["1","2","3"\]} exact data are fetching. but when the same is used for delete it shows as failed. curl -XDEL…

---

## [Disable \_source field](https://discuss.elastic.co/t/disable-source-field/132036)

<div class="topic-metadata">

**Author:** [@nsphaniraj](https://discuss.elastic.co/u/nsphaniraj)\
**Replies:** 9\
**Last updated:** [May 17, 2018, 5:53am UTC](https://discuss.elastic.co/t/disable-source-field/132036 "2018-05-17T05:53:28Z")

</div>

Hello, I had harvested 100 csv files. using filebeat -\> logstash (Using csv filter) -\> Elasticsearch. The disk size of 100 CSV flat files is 609 MB and translated to 1 GB in elasticsearch (pri.store.size). I am aware o…

---

## [Reading Data From Kafka and use filter json fails with ParserError](https://discuss.elastic.co/t/reading-data-from-kafka-and-use-filter-json-fails-with-parsererror/132179)

<div class="topic-metadata">

**Author:** [@paano](https://discuss.elastic.co/u/paano)\
**Replies:** 18\
**Last updated:** [June 7, 2018, 3:13pm UTC](https://discuss.elastic.co/t/reading-data-from-kafka-and-use-filter-json-fails-with-parsererror/132179 "2018-06-07T15:13:57Z")

</div>

Version: 6.2.3 Operating System: RHEL Config File : input { kafka { bootstrap\_servers =\> "127.0.0.1:9092" auto\_offset\_reset =\> earliest topics =\> \["test"\] gr…

---

## [APM is working, but not User Experience](https://discuss.elastic.co/t/apm-is-working-but-not-user-experience/266376)

<div class="topic-metadata">

**Author:** [@A\_Chichi](https://discuss.elastic.co/u/A_Chichi)\
**Replies:** 21\
**Last updated:** [April 2, 2021, 5:00pm UTC](https://discuss.elastic.co/t/apm-is-working-but-not-user-experience/266376 "2021-04-02T17:00:45Z")

</div>

Hello, I have a small problem with the "User Experienc" tab indeed, I set up APM on my Python/Flask application. APM works perfectly : However, when I go to the "User Experience" tab I see nothing: Also, in the "w…

---

## [Copy some fields from one index to another](https://discuss.elastic.co/t/copy-some-fields-from-one-index-to-another/307421)

<div class="topic-metadata">

**Author:** [@lubosvr](https://discuss.elastic.co/u/lubosvr)\
**Replies:** 9\
**Last updated:** [June 20, 2022, 11:24am UTC](https://discuss.elastic.co/t/copy-some-fields-from-one-index-to-another/307421 "2022-06-20T11:24:48Z")

</div>

I am thinking if it's possible to merge two indices to holt my data first\_index: PUT first\_index { "mappings": { "dynamic": "false", "\_source": { "excludes": \["content"\] }, "properties": { …

---

## [Kibana Error: Uncaught TypeError: \_\_webpack\_require\_\_(...).register is not a function](https://discuss.elastic.co/t/kibana-error-uncaught-typeerror---webpack-require---register-is-not-a-function/92987)

<div class="topic-metadata">

**Author:** [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Replies:** 12\
**Last updated:** [August 24, 2017, 1:41pm UTC](https://discuss.elastic.co/t/kibana-error-uncaught-typeerror---webpack-require---register-is-not-a-function/92987 "2017-08-24T13:41:41Z")

</div>

Hi Team, I am getting below error while I open kibana. Error: Uncaught TypeError: webpack\_require(...).register is not a function (http://bngwidap108.aonnet.aon.net:5601/bundles/kibana.bundle.js?v=15382:319) at w…

---

## [Logstash stopped due to throttle](https://discuss.elastic.co/t/logstash-stopped-due-to-throttle/36257)

<div class="topic-metadata">

**Author:** [@marcmga](https://discuss.elastic.co/u/marcmga)\
**Replies:** 21\
**Last updated:** [July 5, 2016, 3:29pm UTC](https://discuss.elastic.co/t/logstash-stopped-due-to-throttle/36257 "2016-07-05T15:29:26Z")

</div>

Hi, I have an issue in logstash. It stopped suddenly and no event are parsed. If i check logstas.err and .stadout no entries apear, BUT in .log it appears an error which is causing this behaviour in logstash. I copy …

---

## [Logstash SSL configuration problem](https://discuss.elastic.co/t/logstash-ssl-configuration-problem/49404)

<div class="topic-metadata">

**Author:** [@Aljaz\_Gantar](https://discuss.elastic.co/u/Aljaz_Gantar)\
**Replies:** 10\
**Last updated:** [February 1, 2017, 5:14pm UTC](https://discuss.elastic.co/t/logstash-ssl-configuration-problem/49404 "2017-02-01T17:14:49Z")

</div>

Okei so i have this case: I have tree server which are running the whole stack, and they are set up so: Filebeat =\> Logstash =\> Elasticsearch/Kibana And I successfully configured that the Filebeat sends logs from his s…

---

## [Parsing HTTP logs](https://discuss.elastic.co/t/parsing-http-logs/114571)

<div class="topic-metadata">

**Author:** [@a\_kasireddy](https://discuss.elastic.co/u/a_kasireddy)\
**Replies:** 14\
**Last updated:** [February 1, 2018, 5:05pm UTC](https://discuss.elastic.co/t/parsing-http-logs/114571 "2018-02-01T17:05:21Z")

</div>

Hello All, I'm trying to parse http logs using filebeat and am running into some issues parsing the ip information. We have the X-FORWARDED-FOR header enabled, which is sending two ip's for some of the calls we get (be…

---

## [Low disk watermark \[15%\] exceeded on](https://discuss.elastic.co/t/low-disk-watermark-15-exceeded-on/33052)

<div class="topic-metadata">

**Author:** [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Replies:** 12\
**Last updated:** [October 29, 2015, 8:49pm UTC](https://discuss.elastic.co/t/low-disk-watermark-15-exceeded-on/33052 "2015-10-29T20:49:47Z")

</div>

Hi, I have 3 nodes cluster in our environment. Each node has data.path where 70GB space is available. Still ES is showing "low disk watermark \[15%\] exceeded on". Can anybody explain me why its that? br, Sunil Chaudhari…

---

## [Elasticsearch 8.3.3 localhost:9200 not working](https://discuss.elastic.co/t/elasticsearch-8-3-3-localhost-9200-not-working/311613)

<div class="topic-metadata">

**Author:** [@Kay\_Yes](https://discuss.elastic.co/u/Kay_Yes)\
**Replies:** 14\
**Last updated:** [August 8, 2022, 3:49pm UTC](https://discuss.elastic.co/t/elasticsearch-8-3-3-localhost-9200-not-working/311613 "2022-08-08T15:49:32Z")

</div>

Hello Elasticsearch experts, I followed the installation procedure given by a few videos on youtube. I have downloaded elasticsearch 8.3.3. I installed JDK 17.0.4 I added the bin folder of jdk to my PATH: C:\\Program…

---

## [Can you put Logstash behind Nginx proxy?](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665)

<div class="topic-metadata">

**Author:** [@droplet](https://discuss.elastic.co/u/droplet)\
**Replies:** 12\
**Last updated:** [August 5, 2021, 3:51pm UTC](https://discuss.elastic.co/t/can-you-put-logstash-behind-nginx-proxy/279665 "2021-08-05T15:51:25Z")

</div>

Hello, Can you put Logstash behind Nginx proxy the same way you put Kibana behind an nginx proxy to use a custom domain with SSL? All this while also using HTTP Basic authentication with Nginx? ElasticSearch, Kibana, a…

---

## [Remove unnecessary fields in ElasticSearch](https://discuss.elastic.co/t/remove-unnecessary-fields-in-elasticsearch/29673)

<div class="topic-metadata">

**Author:** [@Hayder\_Abbass](https://discuss.elastic.co/u/Hayder_Abbass)\
**Replies:** 10\
**Last updated:** [February 11, 2016, 2:45am UTC](https://discuss.elastic.co/t/remove-unnecessary-fields-in-elasticsearch/29673 "2016-02-11T02:45:00Z")

</div>

Hello, We are populating Elasticsearch via logstash. The thing is that I see some unnecessary fields that I had like to remove like for example: @version file geoip host message offset tags Is it possible to do this…

---

## [Logstash 7 GROK Filter plugin 'break\_on\_match' appears to be broken](https://discuss.elastic.co/t/logstash-7-grok-filter-plugin-break-on-match-appears-to-be-broken/176578)

<div class="topic-metadata">

**Author:** [@paul\_nzl](https://discuss.elastic.co/u/paul_nzl)\
**Replies:** 13\
**Last updated:** [April 22, 2019, 9:52pm UTC](https://discuss.elastic.co/t/logstash-7-grok-filter-plugin-break-on-match-appears-to-be-broken/176578 "2019-04-22T21:52:57Z")

</div>

Hi, We have just installed v7 of Logstash and ElasticSearch. Our configuration worked fine in 6.7 of both. What we have noticed is that under 7.0 the 'break\_on\_match' option does not appear to be honoured anymore. An…

---

## [Write queue continue to rise](https://discuss.elastic.co/t/write-queue-continue-to-rise/213652)

<div class="topic-metadata">

**Author:** [@ITzhangqiang](https://discuss.elastic.co/u/ITzhangqiang)\
**Replies:** 22\
**Last updated:** [January 7, 2020, 2:21am UTC](https://discuss.elastic.co/t/write-queue-continue-to-rise/213652 "2020-01-07T02:21:59Z")

</div>

One es node write queue continue to rise from about 08:00。But I set thread\_pool.write.queue\_size: 2000，why this node's write queue more than 2000? And why queue Sudden rise?I check bulk request not much changed as usua…

---

## [Filebeat won't read log files](https://discuss.elastic.co/t/filebeat-wont-read-log-files/190821)

<div class="topic-metadata">

**Author:** [@tsc036](https://discuss.elastic.co/u/tsc036)\
**Replies:** 9\
**Last updated:** [August 8, 2019, 10:04am UTC](https://discuss.elastic.co/t/filebeat-wont-read-log-files/190821 "2019-08-08T10:04:03Z")

</div>

My filebeat doesn't read log files to send to logstash on a remote server. Here is my config file: filebeat.inputs: type: log enabled: true paths: -/var/log/demisto/\*.log logging.level: debug logging.to\_files: t…

---

## [Filebeat syslog parse error](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 9\
**Last updated:** [July 31, 2019, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643 "2019-07-31T15:16:08Z")

</div>

Filebeat is giving errors while parsing syslog messages from ASA. ERROR \[syslog\] syslog/input.go:132 can't parse event as syslog rfc3164 {"message": "\<165\>:Jul 10 07:10:12 IST: %ASA-config-5-111010: User 'XXXXX', runnin…

[Previous page](https://discuss.elastic.co/top.md?page=48&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=50&per_page=50&period=all)
