# Top

**URL:** https://discuss.elastic.co/top.md?page=51&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 52

---

## [Metricbeats timeout](https://discuss.elastic.co/t/metricbeats-timeout/73890)

<div class="topic-metadata">

**Author:** [@faustf](https://discuss.elastic.co/u/faustf)\
**Replies:** 14\
**Last updated:** [February 13, 2017, 9:20am UTC](https://discuss.elastic.co/t/metricbeats-timeout/73890 "2017-02-13T09:20:56Z")

</div>

Hi guys, I've a Cluster of 30 computers with 25 Virtual Machine. Every virtual machine has MetricBeat and FileBeat installed that send metrics and logs to a physical Elasticsearch server. Randomly I've some timeout err…

---

## [Create custom source elasticWorkplace](https://discuss.elastic.co/t/create-custom-source-elasticworkplace/252247)

<div class="topic-metadata">

**Author:** [@JorgeL-TI](https://discuss.elastic.co/u/JorgeL-TI)\
**Replies:** 39\
**Last updated:** [January 24, 2021, 9:12pm UTC](https://discuss.elastic.co/t/create-custom-source-elasticworkplace/252247 "2021-01-24T21:12:45Z")

</div>

Hello, I am using workplace search, and I want now to create a customised source. I explain my project. It consists of a search of documents (PDFs) that need to have a label with their topic. So I try to download thi…

---

## [Size of index is increasing abnormally?](https://discuss.elastic.co/t/size-of-index-is-increasing-abnormally/48024)

<div class="topic-metadata">

**Author:** [@shivam\_singh](https://discuss.elastic.co/u/shivam_singh)\
**Replies:** 12\
**Last updated:** [April 28, 2016, 1:46pm UTC](https://discuss.elastic.co/t/size-of-index-is-increasing-abnormally/48024 "2016-04-28T13:46:57Z")

</div>

Hi, The size of indexes in Elasticsearch is Abnormally increasing. What can be the issue? As u can see in the uploaded snapshot it increased from 1 Gb to 25 GB. Nuber of events came through as shown in kibana UI. 28,4…

---

## [Missing field in kibana visualization](https://discuss.elastic.co/t/missing-field-in-kibana-visualization/36486)

<div class="topic-metadata">

**Author:** [@deepak\_deore](https://discuss.elastic.co/u/deepak_deore)\
**Replies:** 10\
**Last updated:** [January 9, 2016, 8:55pm UTC](https://discuss.elastic.co/t/missing-field-in-kibana-visualization/36486 "2016-01-09T20:55:33Z")

</div>

ES version: 1.5.2 (amazon elasticearch service) I can see below field in discover view but when I create visulization as shown in screenshot, it doesn't show this field in graph. Is there any limit of characters why bel…

---

## [Elasticsearch network host cant be set?](https://discuss.elastic.co/t/elasticsearch-network-host-cant-be-set/55596)

<div class="topic-metadata">

**Author:** [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Replies:** 9\
**Last updated:** [July 21, 2016, 3:39pm UTC](https://discuss.elastic.co/t/elasticsearch-network-host-cant-be-set/55596 "2016-07-21T15:39:28Z")

</div>

I have downloaded ES and configure the yml file for network host to be 0.0.0.0. Then when I start it up with bin/elasticsearch, it gives me the following error. 172.16.1.237:9300}, bound\_addresses {\[::\]:9300} Exception…

---

## [Date histogram error](https://discuss.elastic.co/t/date-histogram-error/295155)

<div class="topic-metadata">

**Author:** [@EnJay](https://discuss.elastic.co/u/EnJay)\
**Replies:** 11\
**Last updated:** [January 26, 2022, 1:11am UTC](https://discuss.elastic.co/t/date-histogram-error/295155 "2022-01-26T01:11:54Z")

</div>

Hello, dear community. Have an error with date histogram. I have a cryptocurrency price base with a 5 minute interval (4 million records). Fields: { "\_source": { "time":…

---

## [How to reset elastic user default password](https://discuss.elastic.co/t/how-to-reset-elastic-user-default-password/256761)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 14\
**Last updated:** [December 2, 2020, 9:02am UTC](https://discuss.elastic.co/t/how-to-reset-elastic-user-default-password/256761 "2020-12-02T09:02:21Z")

</div>

Hi I have a question. How to reset the default password? I have no idea why this suddenly became restricted account? Previously was working fine with tis predefine account. Now have this Connection refused error too to…

---

## [\[solved\]Float recognized as a text](https://discuss.elastic.co/t/solved-float-recognized-as-a-text/79757)

<div class="topic-metadata">

**Author:** [@nabiliii](https://discuss.elastic.co/u/nabiliii)\
**Replies:** 17\
**Last updated:** [April 4, 2017, 7:35am UTC](https://discuss.elastic.co/t/solved-float-recognized-as-a-text/79757 "2017-04-04T07:35:39Z")

</div>

Hi everyone! I'm sending Json data from logstash which are visible on kibana : { "modu" =\> "LORA", "data" =\> "", "ack" =\> false, "freq" =\> 868.1, "codr" =\> "4/5", …

---

## [Convert date to string string](https://discuss.elastic.co/t/convert-date-to-string-string/181128)

<div class="topic-metadata">

**Author:** [@Yoav\_Ben\_Moha](https://discuss.elastic.co/u/Yoav_Ben_Moha)\
**Replies:** 11\
**Last updated:** [May 16, 2019, 7:57pm UTC](https://discuss.elastic.co/t/convert-date-to-string-string/181128 "2019-05-16T19:57:08Z")

</div>

Hi, I am using ELK7 . I have a csv file with 3 columns I have successfully converted the first two columns from string to integer , but failed to convert the 3rd column from string to date. In Kibana the 3rd field i…

---

## [Elasticsearch documents deleted automatically](https://discuss.elastic.co/t/elasticsearch-documents-deleted-automatically/58505)

<div class="topic-metadata">

**Author:** [@Selvam\_ayyanar](https://discuss.elastic.co/u/Selvam_ayyanar)\
**Replies:** 11\
**Last updated:** [August 29, 2016, 7:18am UTC](https://discuss.elastic.co/t/elasticsearch-documents-deleted-automatically/58505 "2016-08-29T07:18:17Z")

</div>

Hi Team, In our production servers, documents are missing particular type and particular shard. same type other shard data available. no shard relocation, no node / cluster restart happen at the time. even no log me…

---

## [\[ERROR\]\[logstash.instrument.periodicpoller.jvm\] Periodi cPoller: exception](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281)

<div class="topic-metadata">

**Author:** [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Replies:** 33\
**Last updated:** [August 11, 2017, 8:59am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281 "2017-08-11T08:59:42Z")

</div>

We are running filebeat,logstash, kibana and elasticsearach in Master machine(1 machine) and from slave machines(6 machines). We are just running Filebeat and all the data from those machines is transferred to master mac…

---

## [Csv parse error](https://discuss.elastic.co/t/csv-parse-error/109187)

<div class="topic-metadata">

**Author:** [@cilzzz](https://discuss.elastic.co/u/cilzzz)\
**Replies:** 13\
**Last updated:** [November 28, 2017, 1:24pm UTC](https://discuss.elastic.co/t/csv-parse-error/109187 "2017-11-28T13:24:03Z")

</div>

Hello, i am trying to parse a csv file but when logstash piupeline started this error is showing my filter in logstash is : filter { if \[type\] == "soe\_phys\_tsm" { csv { columns =\> \["Pa…

---

## [Logstash : convert date to unix time problem](https://discuss.elastic.co/t/logstash-convert-date-to-unix-time-problem/108711)

<div class="topic-metadata">

**Author:** [@linsie](https://discuss.elastic.co/u/linsie)\
**Replies:** 11\
**Last updated:** [November 24, 2017, 5:42am UTC](https://discuss.elastic.co/t/logstash-convert-date-to-unix-time-problem/108711 "2017-11-24T05:42:43Z")

</div>

logstash verison : 5.0.1 i want to convert the time : 20171122194855.000000480 to unix time how can i do in logstash filter ? thanks so much.

---

## [Elasticsearch does not start CentOS7](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 36\
**Last updated:** [November 21, 2022, 4:54pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373 "2022-11-21T16:54:38Z")

</div>

Hi! Installed Elasticsearch as mentioned in Elastic Docs Generated certificates and keys - followed this link - How to install Elasticsearch and Kibana 8.0 on Centos 7 puppet here in the log - just name of the serve…

---

## [Elastic Search can't setup password for Kibana](https://discuss.elastic.co/t/elastic-search-cant-setup-password-for-kibana/195051)

<div class="topic-metadata">

**Author:** [@Alexis\_Prat](https://discuss.elastic.co/u/Alexis_Prat)\
**Replies:** 13\
**Last updated:** [August 14, 2019, 10:16am UTC](https://discuss.elastic.co/t/elastic-search-cant-setup-password-for-kibana/195051 "2019-08-14T10:16:47Z")

</div>

Hi ! I'm a new user of the ELK suite. I would like to collect my log files onseveral server and put them on a central server. To do so, I use rsyslog. I succeed having them on my server but know I would like to impr…

---

## [Specific GROK filter for multi-line Postgresql log](https://discuss.elastic.co/t/specific-grok-filter-for-multi-line-postgresql-log/56286)

<div class="topic-metadata">

**Author:** [@111126](https://discuss.elastic.co/u/111126)\
**Replies:** 12\
**Last updated:** [August 11, 2016, 5:44pm UTC](https://discuss.elastic.co/t/specific-grok-filter-for-multi-line-postgresql-log/56286 "2016-08-11T17:44:57Z")

</div>

Hi All, I am having hard times trying to merge multi-line Postgresql logs with GROK into one Logstash event. My log file look like this: Jul 22 17:03:27 my.host example.com\[24977\]: \[137-1\] 2016-07-22 17:03:27.339 MSK …

---

## [Elasticsearch java API\[5.0\] using problem](https://discuss.elastic.co/t/elasticsearch-java-api-5-0-using-problem/68208)

<div class="topic-metadata">

**Author:** [@girish\_pathak](https://discuss.elastic.co/u/girish_pathak)\
**Replies:** 17\
**Last updated:** [December 7, 2016, 10:50am UTC](https://discuss.elastic.co/t/elasticsearch-java-api-5-0-using-problem/68208 "2016-12-07T10:50:21Z")

</div>

Hi , I am very new to elasticsearch , I want to connect with elasticsearch engine using java API\[5.0\]. Can anyone give the sample code for this.I tried googling but didn't find any full example which can help me regardin…

---

## [After Upgrade from 6.7 to Kibana 7.0 Service cannot Up](https://discuss.elastic.co/t/after-upgrade-from-6-7-to-kibana-7-0-service-cannot-up/176868)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 16\
**Last updated:** [May 6, 2019, 2:51am UTC](https://discuss.elastic.co/t/after-upgrade-from-6-7-to-kibana-7-0-service-cannot-up/176868 "2019-05-06T02:51:13Z")

</div>

Hi Guys, After upgrade from 6.7 to 7.0, my Kibana cannot up and haven't the error message below, I got one master node and one data node. Apr 15 17:33:25 z3aries-n10 systemd: Starting Kibana... Apr 15 17:33:27 z3arie…

---

## [Filebeat fails to process kibana json logs "failed to format message from \*json-.log "in a kubernetes enviroment](https://discuss.elastic.co/t/filebeat-fails-to-process-kibana-json-logs-failed-to-format-message-from-json-log-in-a-kubernetes-enviroment/163558)

<div class="topic-metadata">

**Author:** [@paltaa](https://discuss.elastic.co/u/paltaa)\
**Replies:** 16\
**Last updated:** [January 24, 2019, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-fails-to-process-kibana-json-logs-failed-to-format-message-from-json-log-in-a-kubernetes-enviroment/163558 "2019-01-24T14:21:57Z")

</div>

So ive mounted ELK stack with filebeat in a kubernetes enviroment, im parsing all the logs correctly, only problem is the kibana json-logs format that get error failed to format message from /var/lib/docker/containers/…

---

## [Elasticsearch failed to start yesterday](https://discuss.elastic.co/t/elasticsearch-failed-to-start-yesterday/87693)

<div class="topic-metadata">

**Author:** [@Saplog](https://discuss.elastic.co/u/Saplog)\
**Replies:** 21\
**Last updated:** [June 16, 2017, 1:37pm UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-start-yesterday/87693 "2017-06-16T13:37:42Z")

</div>

I'm using elasticserach since 2 month and yesterday, elasticsearch failed to start. I check log in /var/log/elasticsearch but thery are nothing.... Thanks for help :slight\_smile: ● elasticsearch.service - Elasticsearc…

---

## [\[URGENT\] Elasticsearch 5.1.1 cluster consuming more index space](https://discuss.elastic.co/t/urgent-elasticsearch-5-1-1-cluster-consuming-more-index-space/71878)

<div class="topic-metadata">

**Author:** [@ash007](https://discuss.elastic.co/u/ash007)\
**Replies:** 23\
**Last updated:** [January 25, 2017, 12:45am UTC](https://discuss.elastic.co/t/urgent-elasticsearch-5-1-1-cluster-consuming-more-index-space/71878 "2017-01-25T00:45:59Z")

</div>

Hi, I am new to elk stack. We already have a ES 2.4 cluster running and are trying to upgrade to 5.1.1 version. I am feeding live data to old(2.4.x) and new(5.1.1) cluster from logstash(5.x). The data is now in sync bet…

---

## [Color in a field in the dashboard](https://discuss.elastic.co/t/color-in-a-field-in-the-dashboard/245218)

<div class="topic-metadata">

**Author:** [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Replies:** 10\
**Last updated:** [August 19, 2020, 10:16am UTC](https://discuss.elastic.co/t/color-in-a-field-in-the-dashboard/245218 "2020-08-19T10:16:05Z")

</div>

Hello, I would like to know if its possible to display colored fields based on the message. For ex : If a server down is down, I would get the status as UP or DOWN on the dashboard. I would like to modify it as If th…

---

## [Logstash - newbie question - how to serach single event for a pattern, string](https://discuss.elastic.co/t/logstash-newbie-question-how-to-serach-single-event-for-a-pattern-string/50742)

<div class="topic-metadata">

**Author:** [@mke](https://discuss.elastic.co/u/mke)\
**Replies:** 18\
**Last updated:** [June 5, 2016, 3:33pm UTC](https://discuss.elastic.co/t/logstash-newbie-question-how-to-serach-single-event-for-a-pattern-string/50742 "2016-06-05T15:33:27Z")

</div>

Hi, I am just beginning my story with ELK, trying to understand grok and how to filter events Here is what I try to accomplish, I try to gather syslogs from routers and switches, here is example I 05/23/16 11:50:14 …

---

## [Count query is returning inaccurate results](https://discuss.elastic.co/t/count-query-is-returning-inaccurate-results/274436)

<div class="topic-metadata">

**Author:** [@kapso](https://discuss.elastic.co/u/kapso)\
**Replies:** 13\
**Last updated:** [June 1, 2021, 9:12am UTC](https://discuss.elastic.co/t/count-query-is-returning-inaccurate-results/274436 "2021-06-01T09:12:47Z")

</div>

Count query (filter term) is returning inaccurate results - \*/\_count We have tried to get the count using a regular search query using this approach - "size":0,"track\_total\_hits":true and the count is still inaccurate. …

---

## [How can I get top five results in date\_histogram aggregations?](https://discuss.elastic.co/t/how-can-i-get-top-five-results-in-date-histogram-aggregations/91661)

<div class="topic-metadata">

**Author:** [@Fleaa](https://discuss.elastic.co/u/Fleaa)\
**Replies:** 10\
**Last updated:** [July 4, 2017, 10:24am UTC](https://discuss.elastic.co/t/how-can-i-get-top-five-results-in-date-histogram-aggregations/91661 "2017-07-04T10:24:38Z")

</div>

Hi all, I have a simple aggregation that gives me the number of docs for each day in the last thirty days (using date\_histogram aggregation). I need the top 5 days as amount of documents. How can I get it? Thanks in …

---

## [Why does creating a repository fail?](https://discuss.elastic.co/t/why-does-creating-a-repository-fail/22697)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 15\
**Last updated:** [March 18, 2015, 4:55pm UTC](https://discuss.elastic.co/t/why-does-creating-a-repository-fail/22697 "2015-03-18T16:55:47Z")

</div>

Why does this happen? curl -XPUT 'http://localhost:9200/\_snapshot/my\_backup?pretty=true' -d '{ "type": "fs", "settings": { "location": "/mounts/prod\_backup/my\_backup", "compress": true } }' { "error" : "R…

---

## [Curl: (7) Failed connect to localhost:9200;](https://discuss.elastic.co/t/curl-7-failed-connect-to-localhost-9200/182044)

<div class="topic-metadata">

**Author:** [@Light](https://discuss.elastic.co/u/Light)\
**Replies:** 12\
**Last updated:** [May 23, 2019, 12:58pm UTC](https://discuss.elastic.co/t/curl-7-failed-connect-to-localhost-9200/182044 "2019-05-23T12:58:52Z")

</div>

Hello, I'm new here, and not too skilled with programming/setting up tools on servers either. I'm trying to install ElasticSearch on my CentOS7 server. I followed the istructions from this website, exactly as they are …

---

## [Duplicate field 'field'\\n at \[Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@xxxxx; line: 7, column: 18](https://discuss.elastic.co/t/duplicate-field-field-n-at-source-org-elasticsearch-transport-netty4-bytebufstreaminput-xxxxx-line-7-column-18/211554)

<div class="topic-metadata">

**Author:** [@Shiv18](https://discuss.elastic.co/u/Shiv18)\
**Replies:** 9\
**Last updated:** [December 13, 2019, 9:15am UTC](https://discuss.elastic.co/t/duplicate-field-field-n-at-source-org-elasticsearch-transport-netty4-bytebufstreaminput-xxxxx-line-7-column-18/211554 "2019-12-13T09:15:27Z")

</div>

Hi Team, I'm trying to create ingest pipeline in elasticsearch for lowercase few fields. below is my api, PUT \_ingest/pipeline/lowercase\_pipeline { "description" : "lowercases the incoming field values", "processors…

---

## [Unable to parse imported visualizations on version 5.2.0](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087)

<div class="topic-metadata">

**Author:** [@jmaelbrancke](https://discuss.elastic.co/u/jmaelbrancke)\
**Replies:** 35\
**Last updated:** [March 6, 2017, 2:01pm UTC](https://discuss.elastic.co/t/unable-to-parse-imported-visualizations-on-version-5-2-0/74087 "2017-03-06T14:01:59Z")

</div>

Hey Guys, I just installed the new Kibana and Elasticsearch (5.2.0) on my env and got some issues with my already created dashboards. With the previous version 5.1.2 i did not get these errors. What i try to do is cre…

---

## [Backup and Restore to GCS](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154)

<div class="topic-metadata">

**Author:** [@sbalaz01](https://discuss.elastic.co/u/sbalaz01)\
**Replies:** 17\
**Last updated:** [June 2, 2017, 9:08pm UTC](https://discuss.elastic.co/t/backup-and-restore-to-gcs/87154 "2017-06-02T21:08:04Z")

</div>

Hi, I've been tasked to create the backup and restore for our Elasticsearch. I want to create the backup on my local machine and then copy the snapshot to GCS. Google Cloud Storage. How can I accomplish this without …

---

## [\[kibana 6.5.1\] Reporting fails with elasticcloud endpoint (but not elasticsearch selfhosted)](https://discuss.elastic.co/t/kibana-6-5-1-reporting-fails-with-elasticcloud-endpoint-but-not-elasticsearch-selfhosted/162516)

<div class="topic-metadata">

**Author:** [@dao](https://discuss.elastic.co/u/dao)\
**Replies:** 19\
**Last updated:** [January 9, 2019, 7:18am UTC](https://discuss.elastic.co/t/kibana-6-5-1-reporting-fails-with-elasticcloud-endpoint-but-not-elasticsearch-selfhosted/162516 "2019-01-09T07:18:53Z")

</div>

Hello, I am connecting my self hosted kibana to an elastic cloud endpoint. I know that elastic cloud is shipped with a kibana, but for some reasons, I have to use my own kibana. Unfortunately, the reporting keeps failin…

---

## [Metricbeat Cluster Monitoring: logstash.node: Could not find field 'id' in Logstash API response](https://discuss.elastic.co/t/metricbeat-cluster-monitoring-logstash-node-could-not-find-field-id-in-logstash-api-response/299651)

<div class="topic-metadata">

**Author:** [@marcus\_lhisp](https://discuss.elastic.co/u/marcus_lhisp)\
**Replies:** 16\
**Last updated:** [April 12, 2022, 6:36pm UTC](https://discuss.elastic.co/t/metricbeat-cluster-monitoring-logstash-node-could-not-find-field-id-in-logstash-api-response/299651 "2022-04-12T18:36:41Z")

</div>

Hello Community, Today I've upgraded our ELK Stack from 8.0 to 8.1. Since then the metricbeat, running on the logstash node, started to log something that I wasn't able to figure out by myself with my "Google-fu". Bes…

---

## [ECE installation hanging on bootstrap issue](https://discuss.elastic.co/t/ece-installation-hanging-on-bootstrap-issue/89403)

<div class="topic-metadata">

**Author:** [@Aymeric](https://discuss.elastic.co/u/Aymeric)\
**Replies:** 12\
**Last updated:** [June 19, 2017, 6:47am UTC](https://discuss.elastic.co/t/ece-installation-hanging-on-bootstrap-issue/89403 "2017-06-19T06:47:29Z")

</div>

Hi, I m' very interested in ECE capbilities. Currently trying to install it to figure out exactly what it actually does, and does not. For now, I'm stuck in the installation process, hanging on the "Monitoring bootstra…

---

## [Regexp Query cannot escape reserved symbols](https://discuss.elastic.co/t/regexp-query-cannot-escape-reserved-symbols/108527)

<div class="topic-metadata">

**Author:** [@Hayk\_Hovhanisyan](https://discuss.elastic.co/u/Hayk_Hovhanisyan)\
**Replies:** 9\
**Last updated:** [December 22, 2017, 9:50am UTC](https://discuss.elastic.co/t/regexp-query-cannot-escape-reserved-symbols/108527 "2017-12-22T09:50:15Z")

</div>

My environment: ElasticSearch "2.4.4" Java "1.8.0\_151" Hi there, please clarify for me part of escaping reserved symbols . ? + \* | { } \[ \] ( ) " I used backslash, but result still empty. I stored displayName= A…

---

## [Restarting an active node without needing to recover all data remotely](https://discuss.elastic.co/t/restarting-an-active-node-without-needing-to-recover-all-data-remotely/13133)

<div class="topic-metadata">

**Author:** [@Greg\_Brown](https://discuss.elastic.co/u/Greg_Brown)\
**Replies:** 12\
**Last updated:** [January 9, 2014, 7:49pm UTC](https://discuss.elastic.co/t/restarting-an-active-node-without-needing-to-recover-all-data-remotely/13133 "2014-01-09T19:49:23Z")

</div>

Hi all, My understanding was that when recovering shards after a node restart only those documents that have changed in the meantime should need to be synced from other nodes. In restarting a single node with abou…

---

## [I have create a new user but couldn't set a privilege or role to it](https://discuss.elastic.co/t/i-have-create-a-new-user-but-couldnt-set-a-privilege-or-role-to-it/83999)

<div class="topic-metadata">

**Author:** [@vijayramachandran](https://discuss.elastic.co/u/vijayramachandran)\
**Replies:** 10\
**Last updated:** [May 19, 2017, 5:53am UTC](https://discuss.elastic.co/t/i-have-create-a-new-user-but-couldnt-set-a-privilege-or-role-to-it/83999 "2017-05-19T05:53:53Z")

</div>

Hi there, I have installed X-Pack and created a user called vijay, but somehow I couldn't authenticate with that user, I get the below error message. I know that some privilege or role has to be assigned to the user, b…

---

## [Unable to connect to Kibana](https://discuss.elastic.co/t/unable-to-connect-to-kibana/243974)

<div class="topic-metadata">

**Author:** [@pchar](https://discuss.elastic.co/u/pchar)\
**Replies:** 17\
**Last updated:** [August 7, 2020, 1:48pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-kibana/243974 "2020-08-07T13:48:17Z")

</div>

Hello, I have configured ELK with a nginx in front for HTTPS and authentication. This setup worked perfectly until this morning (I stopped the server for days and restarted it). WHen I try to connect to kibana with Fir…

---

## [Anomaly detection in kibana?](https://discuss.elastic.co/t/anomaly-detection-in-kibana/26720)

<div class="topic-metadata">

**Author:** [@tarunsapra](https://discuss.elastic.co/u/tarunsapra)\
**Replies:** 9\
**Last updated:** [May 11, 2017, 12:35pm UTC](https://discuss.elastic.co/t/anomaly-detection-in-kibana/26720 "2017-05-11T12:35:49Z")

</div>

Hi All, Can anyone please share their experience regarding depiction of Anomaly (using graphs) in elasticsearch data using Kibana, how did you implement it, did you use some 3rd party plugins for the same? Thanks, Ta…

---

## [Filbeat still OOMs?](https://discuss.elastic.co/t/filbeat-still-ooms/156211)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 36\
**Last updated:** [November 27, 2018, 8:55pm UTC](https://discuss.elastic.co/t/filbeat-still-ooms/156211 "2018-11-27T20:55:05Z")

</div>

Hi, running 6.4.2 I see this in my /var/log/messages Nov 11 18:49:37 xxxxxx-0002 systemd: filebeat.service: main process exited, code=exited, status=2/INVALIDARGUMENT Nov 11 18:49:37 xxxxxx-0002 systemd: Unit filebea…

---

## [Get all results at once in Elasticsearch SQL syntax](https://discuss.elastic.co/t/get-all-results-at-once-in-elasticsearch-sql-syntax/153935)

<div class="topic-metadata">

**Author:** [@legendu](https://discuss.elastic.co/u/legendu)\
**Replies:** 11\
**Last updated:** [November 5, 2018, 1:56pm UTC](https://discuss.elastic.co/t/get-all-results-at-once-in-elasticsearch-sql-syntax/153935 "2018-11-05T13:56:14Z")

</div>

I have a simple SQL query in Elasticsearch which I know returns less than 100 rows of results. How can I get all these results at once (i.e., without using scroll)? I tried the limit n clause but it works when n is less …

---

## [Loosing data in elasticsearch](https://discuss.elastic.co/t/loosing-data-in-elasticsearch/92433)

<div class="topic-metadata">

**Author:** [@Idarlington](https://discuss.elastic.co/u/Idarlington)\
**Replies:** 24\
**Last updated:** [July 20, 2017, 10:27am UTC](https://discuss.elastic.co/t/loosing-data-in-elasticsearch/92433 "2017-07-20T10:27:11Z")

</div>

I have elasticsearch 2.0.0 set up with kafka elasticsearch connector. I recently discovered I am loosing data. I can't see some old data anymore. Data is lost in a FIFO way. At first, I thought it was a heap error and…

---

## [Long field is returned as integer if the value is less in Java API](https://discuss.elastic.co/t/long-field-is-returned-as-integer-if-the-value-is-less-in-java-api/9127)

<div class="topic-metadata">

**Author:** [@Deepak\_Chezhian](https://discuss.elastic.co/u/Deepak_Chezhian)\
**Replies:** 11\
**Last updated:** [May 25, 2017, 7:50am UTC](https://discuss.elastic.co/t/long-field-is-returned-as-integer-if-the-value-is-less-in-java-api/9127 "2017-05-25T07:50:48Z")

</div>

Hi, I am querying the document which contains long field. If the long field contains lesser values like 1, the java api returns integer object but if the values are high like 999999999999999999, the java api retur…

---

## [Trouble enabling SSL for elastic search](https://discuss.elastic.co/t/trouble-enabling-ssl-for-elastic-search/68492)

<div class="topic-metadata">

**Author:** [@jamesla](https://discuss.elastic.co/u/jamesla)\
**Replies:** 11\
**Last updated:** [December 13, 2016, 8:56pm UTC](https://discuss.elastic.co/t/trouble-enabling-ssl-for-elastic-search/68492 "2016-12-13T20:56:22Z")

</div>

I'm trying to enable ssl for the elasticsearch service on tcp 9200 I've followed the instructions using certgen and updating the config here: https://www.elastic.co/guide/en/x-pack/current/ssl-tls.html When I start e…

---

## [Filebeat - logstash performances troubleshooting](https://discuss.elastic.co/t/filebeat-logstash-performances-troubleshooting/77037)

<div class="topic-metadata">

**Author:** [@gleroy](https://discuss.elastic.co/u/gleroy)\
**Replies:** 14\
**Last updated:** [March 20, 2017, 8:52am UTC](https://discuss.elastic.co/t/filebeat-logstash-performances-troubleshooting/77037 "2017-03-20T08:52:10Z")

</div>

Hello, I have an application which generates ~50 files/minute with 10000 events (monoline). Previously, I read these files with logstash, processed them and sent them to Elasticsearch. Unfortunately, I was CPU-bound, s…

---

## [Step 3 - Init and create the metricset failure](https://discuss.elastic.co/t/step-3-init-and-create-the-metricset-failure/112046)

<div class="topic-metadata">

**Author:** [@rvigeant](https://discuss.elastic.co/u/rvigeant)\
**Replies:** 13\
**Last updated:** [January 30, 2018, 8:39pm UTC](https://discuss.elastic.co/t/step-3-init-and-create-the-metricset-failure/112046 "2018-01-30T20:39:18Z")

</div>

Hi, I know the same problem has been reported before but what I do is exactly what apparently solved the problem for the other developer. I am trying to create a beat based on metricbeat and I am following the recipe d…

---

## [Cannot start elasticsearch under user](https://discuss.elastic.co/t/cannot-start-elasticsearch-under-user/226587)

<div class="topic-metadata">

**Author:** [@gefela](https://discuss.elastic.co/u/gefela)\
**Replies:** 16\
**Last updated:** [April 14, 2020, 4:51pm UTC](https://discuss.elastic.co/t/cannot-start-elasticsearch-under-user/226587 "2020-04-14T16:51:20Z")

</div>

When I try to start elasticsearch , I get the following \[gefela@gefela bin\] ./elasticsearch ./elasticsearch-env: line 75: /etc/sysconfig/elasticsearch: Permission denied \[gefela@gefela bin\] ^C What do I need to do to f…

---

## [Kibana service restarting after few seconds](https://discuss.elastic.co/t/kibana-service-restarting-after-few-seconds/270418)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 24\
**Last updated:** [April 23, 2021, 10:38am UTC](https://discuss.elastic.co/t/kibana-service-restarting-after-few-seconds/270418 "2021-04-23T10:38:52Z")

</div>

We have kibana 7.4 installed on two servers where elasticsearch is also installed. Kibana service is getting restarted after some time. Can someone please help. Here is the kibana config file - cat /etc/kibana/kibana.…

---

## [Syslog and filebeat assistance request](https://discuss.elastic.co/t/syslog-and-filebeat-assistance-request/192993)

<div class="topic-metadata">

**Author:** [@Brian\_Tima](https://discuss.elastic.co/u/Brian_Tima)\
**Replies:** 24\
**Last updated:** [September 19, 2019, 7:27pm UTC](https://discuss.elastic.co/t/syslog-and-filebeat-assistance-request/192993 "2019-09-19T19:27:40Z")

</div>

We have been running ELK v. 6.2.x We have a central syslog server on EL5 pushing log files with filebeat to logstash I have been tasked with setting up a new central syslog server on EL7 (replace EL5 instance). Filebe…

---

## [Errors while running the elasticsearch instance using gradlew run](https://discuss.elastic.co/t/errors-while-running-the-elasticsearch-instance-using-gradlew-run/168716)

<div class="topic-metadata">

**Author:** [@MKU](https://discuss.elastic.co/u/MKU)\
**Replies:** 21\
**Last updated:** [March 3, 2019, 8:19am UTC](https://discuss.elastic.co/t/errors-while-running-the-elasticsearch-instance-using-gradlew-run/168716 "2019-03-03T08:19:39Z")

</div>

Task :distribution:run#createKeystore FAILED Standard output: Standard error: Exception in thread "main" java.lang.IllegalStateException: unable to read from standard input; is standard input open and a tty attached? …

---

## [Using aggregate filter to count number of events and sum field's values](https://discuss.elastic.co/t/using-aggregate-filter-to-count-number-of-events-and-sum-fields-values/244448)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 28\
**Last updated:** [August 17, 2020, 2:24pm UTC](https://discuss.elastic.co/t/using-aggregate-filter-to-count-number-of-events-and-sum-fields-values/244448 "2020-08-17T14:24:06Z")

</div>

Hi all, I have an index in elasticsearch name as "myindex" so that have fields like"date\_eng","company\_name","service\_name", "amount". I want to use aggregate filter so that counts the times which an services has been u…

[Previous page](https://discuss.elastic.co/top.md?page=50&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=52&per_page=50&period=all)
