# Top

**URL:** https://discuss.elastic.co/top.md?page=50&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 51

---

## [Duplicates events when file rotation occurs - Windows](https://discuss.elastic.co/t/duplicates-events-when-file-rotation-occurs-windows/53315)

<div class="topic-metadata">

**Author:** [@Bruno\_Lavoie](https://discuss.elastic.co/u/Bruno_Lavoie)\
**Replies:** 17\
**Last updated:** [July 11, 2016, 8:30am UTC](https://discuss.elastic.co/t/duplicates-events-when-file-rotation-occurs-windows/53315 "2016-07-11T08:30:59Z")

</div>

Hello, We're in some strange behavior with our Filebeat. Here the facts: filebeat 1.2.3 windows server (2012 r2 I think) we use log4j2 for logging current/active logging file is named like this: acces.log, audit.log,…

---

## [Size of indices are too large](https://discuss.elastic.co/t/size-of-indices-are-too-large/181801)

<div class="topic-metadata">

**Author:** [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Replies:** 10\
**Last updated:** [June 10, 2019, 5:26am UTC](https://discuss.elastic.co/t/size-of-indices-are-too-large/181801 "2019-06-10T05:26:13Z")

</div>

I am having logs of 6.9GB but the size of index created is more than 20GB. Is there any efficient way via which we can control the size of indices??????

---

## [Debugging information for JAVA agent](https://discuss.elastic.co/t/debugging-information-for-java-agent/160925)

<div class="topic-metadata">

**Author:** [@jhoninck](https://discuss.elastic.co/u/jhoninck)\
**Replies:** 26\
**Last updated:** [January 3, 2019, 10:32am UTC](https://discuss.elastic.co/t/debugging-information-for-java-agent/160925 "2019-01-03T10:32:04Z")

</div>

Doing my best to create some custom code to use as a tracer and add into APM. It is the intention to create a transaction and append from different locations spans to it using context. Have started APM/Elastic/kibana sta…

---

## [Strange filebeat behavior: timeout and duplicate pushing to logstash's beats plugin](https://discuss.elastic.co/t/strange-filebeat-behavior-timeout-and-duplicate-pushing-to-logstashs-beats-plugin/122148)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 12\
**Last updated:** [March 16, 2018, 12:55pm UTC](https://discuss.elastic.co/t/strange-filebeat-behavior-timeout-and-duplicate-pushing-to-logstashs-beats-plugin/122148 "2018-03-16T12:55:09Z")

</div>

Hi, During my migration from 5.1.2 / 5.2.0 to 6.1.x / 6.2.1 I encountered some issues. Trying to sharpen the cause of my issues I noticed strange behavior when shipping files from filebeat to logstash. I got reproducib…

---

## [IO / Disc "tear down" for elastic search](https://discuss.elastic.co/t/io-disc-tear-down-for-elastic-search/248013)

<div class="topic-metadata">

**Author:** [@Oleg\_Ruchovets](https://discuss.elastic.co/u/Oleg_Ruchovets)\
**Replies:** 41\
**Last updated:** [October 13, 2020, 7:08pm UTC](https://discuss.elastic.co/t/io-disc-tear-down-for-elastic-search/248013 "2020-10-13T19:08:49Z")

</div>

Hello, My task is to make an elastic search disk/io "hard life" :-). To not reinventing the wheel - is there a tool for simulation high disk load on elastic? what type of query is the most disk/io intensive? I saw many…

---

## [Upgrade 7.6-\>7.7 unable to verify the first certificate"](https://discuss.elastic.co/t/upgrade-7-6-7-7-unable-to-verify-the-first-certificate/233625)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 20\
**Last updated:** [June 10, 2020, 8:38pm UTC](https://discuss.elastic.co/t/upgrade-7-6-7-7-unable-to-verify-the-first-certificate/233625 "2020-06-10T20:38:56Z")

</div>

I've had my Elastic Stack secured using a public CA certificate for about a year now and upgraded from version to version without issue. Updated Elasticsearch and Kibana from 7.6.2 to 7.7.0 today and everything seemed t…

---

## [Custom y axis](https://discuss.elastic.co/t/custom-y-axis/96000)

<div class="topic-metadata">

**Author:** [@Nithin\_Devang](https://discuss.elastic.co/u/Nithin_Devang)\
**Replies:** 9\
**Last updated:** [August 7, 2017, 5:55pm UTC](https://discuss.elastic.co/t/custom-y-axis/96000 "2017-08-07T17:55:43Z")

</div>

Hi, I have multiple doc in this format "x": { “frequency” : 13.671875, “amplitude”: 109.45423957023802 } I want to plot line graph with amplitude in y axis and frequency in x axis, I am not finding any option which…

---

## [Elasticsearch ILM stuck at forcemerge](https://discuss.elastic.co/t/elasticsearch-ilm-stuck-at-forcemerge/184506)

<div class="topic-metadata">

**Author:** [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Replies:** 15\
**Last updated:** [June 26, 2019, 4:00am UTC](https://discuss.elastic.co/t/elasticsearch-ilm-stuck-at-forcemerge/184506 "2019-06-26T04:00:11Z")

</div>

Hi, I currently have an ILM policy that does the following: As mentioned here, after shrink I end up having a shard size of 40GB. I have then configured ILM to delete the indices after 7 days. However, the ILM pol…

---

## [Best practise for index creation](https://discuss.elastic.co/t/best-practise-for-index-creation/109096)

<div class="topic-metadata">

**Author:** [@Souciance\_Eqdam\_Rash](https://discuss.elastic.co/u/Souciance_Eqdam_Rash)\
**Replies:** 14\
**Last updated:** [November 27, 2017, 6:24pm UTC](https://discuss.elastic.co/t/best-practise-for-index-creation/109096 "2017-11-27T18:24:17Z")

</div>

Hi, We are just starting out with elasticsearch for centralized logging. Our backend is an integration platform that has say 100 integrations currently running. My question has to do with index creation. What is the be…

---

## ["Failed to flush outgoing items" using shield](https://discuss.elastic.co/t/failed-to-flush-outgoing-items-using-shield/25401)

<div class="topic-metadata">

**Author:** [@bluethundr](https://discuss.elastic.co/u/bluethundr)\
**Replies:** 14\
**Last updated:** [July 14, 2015, 8:05pm UTC](https://discuss.elastic.co/t/failed-to-flush-outgoing-items-using-shield/25401 "2015-07-14T20:05:26Z")

</div>

Hey guys, I can't seem to use Logstash with ES Shield. I set this up on my test instances, because I'll be expected to make this work on the company setup this coming week. So lessons learned here will apply there. …

---

## [Grok after CSV filter](https://discuss.elastic.co/t/grok-after-csv-filter/96303)

<div class="topic-metadata">

**Author:** [@somu411](https://discuss.elastic.co/u/somu411)\
**Replies:** 12\
**Last updated:** [August 9, 2017, 1:54pm UTC](https://discuss.elastic.co/t/grok-after-csv-filter/96303 "2017-08-09T13:54:38Z")

</div>

Hi I would be thankful who helps me in extracting substring between two forward slashes using grok after csv filter My CSV file is GIS,/Dianon/CancerRegPHNMS,22876365,96589706,ID\_Dianon\_170708235043,2905,2017-07-09,01…

---

## [ECE RAM to Storage Ratio](https://discuss.elastic.co/t/ece-ram-to-storage-ratio/101878)

<div class="topic-metadata">

**Author:** [@adesouza](https://discuss.elastic.co/u/adesouza)\
**Replies:** 13\
**Last updated:** [September 27, 2017, 5:51pm UTC](https://discuss.elastic.co/t/ece-ram-to-storage-ratio/101878 "2017-09-27T17:51:33Z")

</div>

Hi, I was looking at how to change the RAM to storage ratio in ECE, I found a couple of threads asking the same question that had links to https://www.elastic.co/guide/en/cloud-enterprise/current/ece-change-ratio.html a…

---

## [Grok TIME](https://discuss.elastic.co/t/grok-time/43994)

<div class="topic-metadata">

**Author:** [@Prateek\_Kshtriya](https://discuss.elastic.co/u/Prateek_Kshtriya)\
**Replies:** 10\
**Last updated:** [March 11, 2016, 9:05am UTC](https://discuss.elastic.co/t/grok-time/43994 "2016-03-11T09:05:31Z")

</div>

Hi All , I am new to ELK and trying to forward a non-real time log by applying grok in config file to pick the log time .I referred few previous discussions to find that Grok could be used to parse the data & Date{} co…

---

## [Kibana is slow to respond](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290)

<div class="topic-metadata">

**Author:** [@vilas](https://discuss.elastic.co/u/vilas)\
**Replies:** 12\
**Last updated:** [March 25, 2016, 5:24pm UTC](https://discuss.elastic.co/t/kibana-is-slow-to-respond/45290 "2016-03-25T17:24:31Z")

</div>

Hi, We have elasticsearch 1.5.2 cluster with following distribution: Node1: Master+Data Node2: Master+Data Node3: Master+Data Node4: Data Node5: Data Node6: Client (For Kibana) Node7: Client Node3, Node4, Node5 =\> On…

---

## [Issue installing metricbeat](https://discuss.elastic.co/t/issue-installing-metricbeat/196598)

<div class="topic-metadata">

**Author:** [@Mezoloth](https://discuss.elastic.co/u/Mezoloth)\
**Replies:** 15\
**Last updated:** [August 26, 2019, 3:12pm UTC](https://discuss.elastic.co/t/issue-installing-metricbeat/196598 "2019-08-26T15:12:01Z")

</div>

I am following the setup guide from elastic for metric beat, and get the following when I run " metricbeat setup -e" 019-08-23T20:48:31.017Z INFO kibana/client.go:117 Kibana url: http://localhost:5601 201…

---

## [Curator - SSL Connection Issue](https://discuss.elastic.co/t/curator-ssl-connection-issue/70800)

<div class="topic-metadata">

**Author:** [@MSAdmin](https://discuss.elastic.co/u/MSAdmin)\
**Replies:** 16\
**Last updated:** [January 6, 2017, 5:52pm UTC](https://discuss.elastic.co/t/curator-ssl-connection-issue/70800 "2017-01-06T17:52:31Z")

</div>

I just installed Curator 4.2 from the repository. It is installed on the ELK server. I created the ~/.curator/curator.yml file with the following contents: # Remember, leave a key empty if there is no value. None will…

---

## [Can not open Stack monitoring](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772)

<div class="topic-metadata">

**Author:** [@v.n](https://discuss.elastic.co/u/v.n)\
**Replies:** 45\
**Last updated:** [September 30, 2020, 8:16pm UTC](https://discuss.elastic.co/t/can-not-open-stack-monitoring/237772 "2020-09-30T20:16:15Z")

</div>

Hi, Recently I couldn't open Stack Monitoring. Then I decided to upgrade to new version 7.8.0. But after upgrading my problem still exists. My user has role superuser so I don't understand why I cannot have access to m…

---

## [Running Logstash in a Docker container: data directory permissions](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028)

<div class="topic-metadata">

**Author:** [@espogian](https://discuss.elastic.co/u/espogian)\
**Replies:** 10\
**Last updated:** [June 12, 2018, 1:56pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028 "2018-06-12T13:56:18Z")

</div>

Hello, I'm trying to run a Docker container with this setup: docker run --name logstash6 -d -v /srv/logstash6/pipeline/:/usr/share/logstash/pipeline/ -v /srv/logstash6/data/:/usr/share/logstash/data/ docker.elastic.co/l…

---

## [Avoid duplication](https://discuss.elastic.co/t/avoid-duplication/155731)

<div class="topic-metadata">

**Author:** [@totuyim](https://discuss.elastic.co/u/totuyim)\
**Replies:** 12\
**Last updated:** [November 9, 2018, 4:01pm UTC](https://discuss.elastic.co/t/avoid-duplication/155731 "2018-11-09T16:01:45Z")

</div>

Hi there, I've a lot of traffic logs (around 20 millions per day) to index and I would like to know suggestion of how to avoid duplication with these amount of data. I was reading this article but I haven't such experi…

---

## [Retry for java High level rest client. ES version 6.1](https://discuss.elastic.co/t/retry-for-java-high-level-rest-client-es-version-6-1/174240)

<div class="topic-metadata">

**Author:** [@nikuland](https://discuss.elastic.co/u/nikuland)\
**Replies:** 9\
**Last updated:** [April 2, 2019, 7:00am UTC](https://discuss.elastic.co/t/retry-for-java-high-level-rest-client-es-version-6-1/174240 "2019-04-02T07:00:00Z")

</div>

we are using 6.1 ES, and Java High level Rest client. Intermittently we see "Connection reset by Peer" and "Listener timedout after 30000ms". In python there is way to set the max retries for such failures. Is there simi…

---

## [\[indices:data/read/field\_stats\[s\]\]\]; nested: IllegalArgumentException\[field \[@timestamp\] doesn't exist\]](https://discuss.elastic.co/t/indices-data-read-field-stats-s-nested-illegalargumentexception-field-timestamp-doesnt-exist/52738)

<div class="topic-metadata">

**Author:** [@DreadPirateRob](https://discuss.elastic.co/u/DreadPirateRob)\
**Replies:** 14\
**Last updated:** [July 8, 2016, 4:04pm UTC](https://discuss.elastic.co/t/indices-data-read-field-stats-s-nested-illegalargumentexception-field-timestamp-doesnt-exist/52738 "2016-07-08T16:04:26Z")

</div>

First time user of ELK, originally I created an issue against elasticsearch on github, but it was suggested that I bring this issue to this forum, and so here we are. In my /var/log/elasticsearch/logstashTesting.log f…

---

## [\[ANN\] Elasticsearch Simple Action Plugin](https://discuss.elastic.co/t/ann-elasticsearch-simple-action-plugin/17889)

<div class="topic-metadata">

**Author:** [@jprante](https://discuss.elastic.co/u/jprante)\
**Replies:** 29\
**Last updated:** [September 11, 2014, 6:49pm UTC](https://discuss.elastic.co/t/ann-elasticsearch-simple-action-plugin/17889 "2014-09-11T18:49:03Z")

</div>

Hi, many of us want to start writing extensions for Elasticsearch. Except submitting pull requests to the core code, one great advantage of Elasticsearch is the plugin mechanism. Here, custom code can be hooked in…

---

## [Sharding Strategy](https://discuss.elastic.co/t/sharding-strategy/103573)

<div class="topic-metadata">

**Author:** [@Manikanth\_Reddy](https://discuss.elastic.co/u/Manikanth_Reddy)\
**Replies:** 17\
**Last updated:** [October 25, 2017, 9:56am UTC](https://discuss.elastic.co/t/sharding-strategy/103573 "2017-10-25T09:56:07Z")

</div>

Hi, We have a cluster of 8nodes with 3,248 indices and 29,544 shards with 1 replica. We have 5shards per each index. These are daily indices with size ranging from 10MB to max 2GB. Out of these 8 nodes, 3Master,3Data a…

---

## [DataLoss in Logstash!](https://discuss.elastic.co/t/dataloss-in-logstash/27970)

<div class="topic-metadata">

**Author:** [@sreeram](https://discuss.elastic.co/u/sreeram)\
**Replies:** 11\
**Last updated:** [April 11, 2017, 3:13am UTC](https://discuss.elastic.co/t/dataloss-in-logstash/27970 "2017-04-11T03:13:16Z")

</div>

Hi, I'm using ELK for Centralized logging and i'm facing DataLoss while processing 5lakh logs(kibana hits), (Logstash (Shipper&Indexer same instance)) Machine 1 -\> (ElasticSearch -\> Kibana) Machine 2 Scenario for Da…

---

## [Default-mapping.json](https://discuss.elastic.co/t/default-mapping-json/6111)

<div class="topic-metadata">

**Author:** [@Slava\_G](https://discuss.elastic.co/u/Slava_G)\
**Replies:** 32\
**Last updated:** [December 16, 2011, 4:29pm UTC](https://discuss.elastic.co/t/default-mapping-json/6111 "2011-12-16T16:29:52Z")

</div>

Hi, I've create default-mapping.json file with this content: { "\_default\_" : { "\_source" : {"enabled" : false} } } in the elasticsearch / config folder but it seems that \_source field is s…

---

## [Elasticsearch restart failed](https://discuss.elastic.co/t/elasticsearch-restart-failed/83357)

<div class="topic-metadata">

**Author:** [@shaonbean](https://discuss.elastic.co/u/shaonbean)\
**Replies:** 10\
**Last updated:** [April 25, 2017, 2:52am UTC](https://discuss.elastic.co/t/elasticsearch-restart-failed/83357 "2017-04-25T02:52:57Z")

</div>

when yum install elasticsearch && confifure yml,can start elasticsearch succeed,but when I again retsrat elasticsearch will happend errors,like example: java.lang.IllegalStateException: detected index data in default.p…

---

## [How to create a scripted field with multiple conditions check?](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 9\
**Last updated:** [March 24, 2018, 1:24pm UTC](https://discuss.elastic.co/t/how-to-create-a-scripted-field-with-multiple-conditions-check/125427 "2018-03-24T13:24:29Z")

</div>

Hi, I am using ELK GA 5.0.0. In my index, I have a string field named name. I want to create a field named category based on the value of name. Below is the pseudo code; if(name== 'elephant' || name== 'lion' || name== …

---

## [Re-indexing an aggregation for later use](https://discuss.elastic.co/t/re-indexing-an-aggregation-for-later-use/45012)

<div class="topic-metadata">

**Author:** [@beckerdo](https://discuss.elastic.co/u/beckerdo)\
**Replies:** 9\
**Last updated:** [May 17, 2017, 8:33pm UTC](https://discuss.elastic.co/t/re-indexing-an-aggregation-for-later-use/45012 "2017-05-17T20:33:14Z")

</div>

I am performing an aggregation on our company daily data stream in Elastic. I am bucketing the data by an "mid: field, and summing the "amount" field in the payload. It looks like this: { "aggs": { "tpv": { …

---

## [Find e-mail](https://discuss.elastic.co/t/find-e-mail/6376)

<div class="topic-metadata">

**Author:** [@Hugo](https://discuss.elastic.co/u/Hugo)\
**Replies:** 9\
**Last updated:** [October 19, 2015, 2:42pm UTC](https://discuss.elastic.co/t/find-e-mail/6376 "2015-10-19T14:42:45Z")

</div>

Hi all, Can anyone please help me on this issue? I'm trying to find an e-mail with elasticsearch but can't seem to get it to work properly. I've created an index with the following mapping: $ curl -s -XPUT http…

---

## [Task exception could not be deserialized](https://discuss.elastic.co/t/task-exception-could-not-be-deserialized/45960)

<div class="topic-metadata">

**Author:** [@Jonathan\_Spooner](https://discuss.elastic.co/u/Jonathan_Spooner)\
**Replies:** 11\
**Last updated:** [March 23, 2017, 10:27am UTC](https://discuss.elastic.co/t/task-exception-could-not-be-deserialized/45960 "2017-03-23T10:27:13Z")

</div>

I have a Spark job that runs on my localhost but when run on EMR I'm getting a Warning for WARN ThrowableSerializationWrapper: Task exception could not be deserialized java.lang.ClassNotFoundException: org.elasticsear…

---

## [X-pack basic](https://discuss.elastic.co/t/x-pack-basic/108709)

<div class="topic-metadata">

**Author:** [@GambitK](https://discuss.elastic.co/u/GambitK)\
**Replies:** 14\
**Last updated:** [December 15, 2017, 8:19am UTC](https://discuss.elastic.co/t/x-pack-basic/108709 "2017-12-15T08:19:29Z")

</div>

I've recently registered for a basic license of x-pack and tried installing it without luck. I only want the kibana UI feature for logstash that's available in the basic license. I don't want authentication. Is it possi…

---

## [How to configure filebeat template](https://discuss.elastic.co/t/how-to-configure-filebeat-template/115855)

<div class="topic-metadata">

**Author:** [@zhangrandl](https://discuss.elastic.co/u/zhangrandl)\
**Replies:** 9\
**Last updated:** [January 18, 2018, 1:54am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-template/115855 "2018-01-18T01:54:27Z")

</div>

HI， I'm setting up a Filebeat with elasticsearch output, when i setting two index , I setting two template in filebeat.yml setup.template.name: "nginx" setup.template.overwrite: false setup.template.pattern: "nginx-\*"…

---

## [Elasticsearch 2.4.0 crashing during heavy bulk index loads](https://discuss.elastic.co/t/elasticsearch-2-4-0-crashing-during-heavy-bulk-index-loads/60316)

<div class="topic-metadata">

**Author:** [@NightWriter](https://discuss.elastic.co/u/NightWriter)\
**Replies:** 17\
**Last updated:** [October 28, 2016, 4:12am UTC](https://discuss.elastic.co/t/elasticsearch-2-4-0-crashing-during-heavy-bulk-index-loads/60316 "2016-10-28T04:12:13Z")

</div>

Hi all, I am fairly new to Elasticsearch and am very impressed thus far. However, I am running into a problem as I test it to insure it is something I could run in a production environment. I'm hopeful that someone her…

---

## [Palo alto logs](https://discuss.elastic.co/t/palo-alto-logs/222511)

<div class="topic-metadata">

**Author:** [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)\
**Replies:** 21\
**Last updated:** [March 13, 2020, 10:54pm UTC](https://discuss.elastic.co/t/palo-alto-logs/222511 "2020-03-13T22:54:27Z")

</div>

Hello everybody, Im trying to ingest data from PAN-OS Syslog Integration 8.1.10. I read I can use filebeat + pawn module. I read the https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-panw.html to…

---

## [Elasticsearch query slow response via kibana console](https://discuss.elastic.co/t/elasticsearch-query-slow-response-via-kibana-console/217494)

<div class="topic-metadata">

**Author:** [@Sha](https://discuss.elastic.co/u/Sha)\
**Replies:** 18\
**Last updated:** [February 26, 2020, 9:27pm UTC](https://discuss.elastic.co/t/elasticsearch-query-slow-response-via-kibana-console/217494 "2020-02-26T21:27:18Z")

</div>

Server background : 3 node elasticsearch cluster + kibana + logstash running on docker environment. host server runs rhel7.7(2cpu, 8GB RAM + 200GB fileshare). Versions : elasticsearch 7.5.1 kibana 7.5.1 logstash 7.5.1 …

---

## [Logstash - aggregate results](https://discuss.elastic.co/t/logstash-aggregate-results/164351)

<div class="topic-metadata">

**Author:** [@Francisca\_Lima](https://discuss.elastic.co/u/Francisca_Lima)\
**Replies:** 18\
**Last updated:** [January 17, 2019, 6:12pm UTC](https://discuss.elastic.co/t/logstash-aggregate-results/164351 "2019-01-17T18:12:49Z")

</div>

Hello, When I am using the aggregate filter in logstash (to get the total sales of each product, for example), is there a way to send the aggregated results to a different output and not line by line? Thank you!

---

## [Elasticsearch can't login https://localhost:9200 after setting ssl](https://discuss.elastic.co/t/elasticsearch-cant-login-https-localhost-9200-after-setting-ssl/270169)

<div class="topic-metadata">

**Author:** [@gricn](https://discuss.elastic.co/u/gricn)\
**Replies:** 10\
**Last updated:** [April 15, 2021, 2:50pm UTC](https://discuss.elastic.co/t/elasticsearch-cant-login-https-localhost-9200-after-setting-ssl/270169 "2021-04-15T14:50:25Z")

</div>

Environment: Win10 WLS2 Ubuntu 20.04, Docker version 20.10.5, Docker-compose version 1.29.0, ELK 7.12.0, nginx version 1.18.0 I have enabled xpack in the last version docker-compose.yml setting and use ./bin/elasticsear…

---

## [Java Transport Client 5.4.1 NullPointerException](https://discuss.elastic.co/t/java-transport-client-5-4-1-nullpointerexception/88590)

<div class="topic-metadata">

**Author:** [@aszac](https://discuss.elastic.co/u/aszac)\
**Replies:** 15\
**Last updated:** [June 21, 2017, 10:39am UTC](https://discuss.elastic.co/t/java-transport-client-5-4-1-nullpointerexception/88590 "2017-06-21T10:39:00Z")

</div>

Hello, I am trying to upgrade my service from Elasticsearch 1.4 to Elasticsearch 5.4.1. It run without issues on Centos 6.8, but after the upgrade I am getting the following error: Exception in thread "main" java.lan…

---

## [ILM failing for rollover for Wazuh module / data](https://discuss.elastic.co/t/ilm-failing-for-rollover-for-wazuh-module-data/291781)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 38\
**Last updated:** [January 7, 2022, 9:34am UTC](https://discuss.elastic.co/t/ilm-failing-for-rollover-for-wazuh-module-data/291781 "2022-01-07T09:34:34Z")

</div>

I have setup a rollover policy for wazuh index with the below policy defination { "policy": "Wazuh", "phase\_definition": { "min\_age": "0ms", "actions": { "rollover": { "max\_size": "20gb", …

---

## [Error when navigating to Watchers](https://discuss.elastic.co/t/error-when-navigating-to-watchers/118677)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 28\
**Last updated:** [February 19, 2018, 8:14am UTC](https://discuss.elastic.co/t/error-when-navigating-to-watchers/118677 "2018-02-19T08:14:52Z")

</div>

Hi Guys, So... I deleted my index today and then added it again. After doing so I then tried to navigate to the watches within Kibana. This gave me the following error message: Error: Watcher: Error 503 Service Unavai…

---

## [APM queue is full](https://discuss.elastic.co/t/apm-queue-is-full/221513)

<div class="topic-metadata">

**Author:** [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Replies:** 11\
**Last updated:** [March 16, 2020, 1:28am UTC](https://discuss.elastic.co/t/apm-queue-is-full/221513 "2020-03-16T01:28:26Z")

</div>

Kibana version: 7.5.2 Elasticsearch version: 7.5.2 APM Server version: 7.6.0 APM Agent language and version: Java 1.12.0 Browser version: Original install method (e.g. download page, yum, deb, from source, etc.) and…

---

## [Master not discovered or elected yet, after docker compose stop and start](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-after-docker-compose-stop-and-start/177653)

<div class="topic-metadata">

**Author:** [@nufje](https://discuss.elastic.co/u/nufje)\
**Replies:** 10\
**Last updated:** [April 20, 2019, 5:48am UTC](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-after-docker-compose-stop-and-start/177653 "2019-04-20T05:48:21Z")

</div>

Hello, Strange problem here (i think :slight\_smile: ) I start elasticsearch on my laptop with docker-compose up -d es01, let the container start completly. Stop the containers with docker-compose stop. Then i do docker…

---

## [Elasticsearch2.30のelasticsearch-head プラグインがインストールできません](https://discuss.elastic.co/t/elasticsearch2-30-elasticsearch-head/46316)

<div class="topic-metadata">

**Author:** [@yyam](https://discuss.elastic.co/u/yyam)\
**Replies:** 11\
**Last updated:** [April 6, 2016, 11:29pm UTC](https://discuss.elastic.co/t/elasticsearch2-30-elasticsearch-head/46316 "2016-04-06T23:29:41Z")

</div>

elasticsearch-1.7.1では set JAVA\_OPTS=-DproxyHost=proxy.xxxxxxxxxx -DproxyPort=xxxx bin\\plugin -install mobz/elasticsearch-head でelasticsearch-head プラグインがインストールできたのですが elasticsearch-2.3.0ではインストールができません。 set JAVA\_OPTS=-Dpro…

---

## [Parse logfile date into Kibana's timestamp](https://discuss.elastic.co/t/parse-logfile-date-into-kibanas-timestamp/82163)

<div class="topic-metadata">

**Author:** [@ibrahimsharaf](https://discuss.elastic.co/u/ibrahimsharaf)\
**Replies:** 17\
**Last updated:** [April 12, 2017, 3:05pm UTC](https://discuss.elastic.co/t/parse-logfile-date-into-kibanas-timestamp/82163 "2017-04-12T15:05:44Z")

</div>

Hello, I have a date in log file like this one 2017-01-01 07:57:22 , I want to extract only the month and the day 01-01, using a logstash filter, then use it as Kibana's timestamp. here's how my logstash filter looks l…

---

## [How can ı drawing ip based map](https://discuss.elastic.co/t/how-can-i-drawing-ip-based-map/174252)

<div class="topic-metadata">

**Author:** [@khergner](https://discuss.elastic.co/u/khergner)\
**Replies:** 11\
**Last updated:** [March 29, 2019, 7:00am UTC](https://discuss.elastic.co/t/how-can-i-drawing-ip-based-map/174252 "2019-03-29T07:00:13Z")

</div>

Hi everyone I want to draw ip map but it gives an error. I use model ip type for srcIp. "csIp": { "type": "ip" } The error I received is as follows.

---

## [Failure with sorts and new co.elastic.clients:elasticsearch-java client](https://discuss.elastic.co/t/failure-with-sorts-and-new-co-elastic-clients-elasticsearch-java-client/291511)

<div class="topic-metadata">

**Author:** [@ilgrosso](https://discuss.elastic.co/u/ilgrosso)\
**Replies:** 13\
**Last updated:** [December 20, 2021, 4:53pm UTC](https://discuss.elastic.co/t/failure-with-sorts-and-new-co-elastic-clients-elasticsearch-java-client/291511 "2021-12-20T16:53:14Z")

</div>

I am upgrading from Java High-level REST client 7.15 to the new Java client. I am almost done, it seems only one issue is left. I am currently using bare Map\<String, Object\> for documents, hence my index requests look …

---

## [Data stream logs not showing in discover](https://discuss.elastic.co/t/data-stream-logs-not-showing-in-discover/310662)

<div class="topic-metadata">

**Author:** [@metalaarif](https://discuss.elastic.co/u/metalaarif)\
**Replies:** 14\
**Last updated:** [July 27, 2022, 9:12pm UTC](https://discuss.elastic.co/t/data-stream-logs-not-showing-in-discover/310662 "2022-07-27T21:12:26Z")

</div>

So I have a setup where my rabbitmq send logs to logstash and then to elasticsearch and kibana. This is what I have setup in my /etc/logstash/conf.d/rabbitmq.conf input { rabbitmq { host =\> "0.0.0.0" …

---

## [Elasticsearch problems](https://discuss.elastic.co/t/elasticsearch-problems/28404)

<div class="topic-metadata">

**Author:** [@zpp](https://discuss.elastic.co/u/zpp)\
**Replies:** 9\
**Last updated:** [June 13, 2017, 10:54pm UTC](https://discuss.elastic.co/t/elasticsearch-problems/28404 "2017-06-13T22:54:41Z")

</div>

over the weekend, i had a couple of problem elasticseach, and wasn't able to recover yet. I only have one elasticsearch node, and there are two time-based indices (e.g. test-2015.09.01) feeding data in. the first error…

---

## [How do I host an Elasticsearch server on a local machine and allow other machines to access that data?](https://discuss.elastic.co/t/how-do-i-host-an-elasticsearch-server-on-a-local-machine-and-allow-other-machines-to-access-that-data/307766)

<div class="topic-metadata">

**Author:** [@DataStorageMuse](https://discuss.elastic.co/u/DataStorageMuse)\
**Replies:** 18\
**Last updated:** [June 21, 2022, 11:42pm UTC](https://discuss.elastic.co/t/how-do-i-host-an-elasticsearch-server-on-a-local-machine-and-allow-other-machines-to-access-that-data/307766 "2022-06-21T23:42:59Z")

</div>

I have an Elasticsearch server running on a local machine with an ip address: {local\_machine\_ip}. I have another computer that has an ip {client\_ip}. How do I allow the client computer to access the Elasticsearch server …

---

## [Parse multi line json](https://discuss.elastic.co/t/parse-multi-line-json/242677)

<div class="topic-metadata">

**Author:** [@laxmikanth](https://discuss.elastic.co/u/laxmikanth)\
**Replies:** 11\
**Last updated:** [July 28, 2020, 9:57am UTC](https://discuss.elastic.co/t/parse-multi-line-json/242677 "2020-07-28T09:57:40Z")

</div>

Hi, When I try to parse multi line json as below, I am seeing in ELK as multiline, \_jsonparsefailure, \_grokparsefailure from below json file content, want to remove KEY4 & host and send rest of the fields to elastic se…

[Previous page](https://discuss.elastic.co/top.md?page=49&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=51&per_page=50&period=all)
