# Top

**URL:** https://discuss.elastic.co/top.md?page=53&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 54

---

## [Unable to disable APM via environment variable](https://discuss.elastic.co/t/unable-to-disable-apm-via-environment-variable/180558)

<div class="topic-metadata">

**Author:** [@jaks](https://discuss.elastic.co/u/jaks)\
**Replies:** 10\
**Last updated:** [June 14, 2019, 11:19am UTC](https://discuss.elastic.co/t/unable-to-disable-apm-via-environment-variable/180558 "2019-06-14T11:19:31Z")

</div>

We are using the APM in production & pre-prod. For dev services, we want to disable the APM, for this we are trying to set via Environment variables. Currently using Java agent 1.6.1. Here are the kubernetes pod details…

---

## [Send syslog to Filebeat server](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987)

<div class="topic-metadata">

**Author:** [@msylvestre](https://discuss.elastic.co/u/msylvestre)\
**Replies:** 27\
**Last updated:** [October 4, 2023, 7:06pm UTC](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987 "2023-10-04T19:06:22Z")

</div>

Greetings, I'm trying to send my Cisco Switches logs to my Filebeat server but for some reason it's not working. I can see that the Filebeat receives the logs, but it doesn't ship them to elastic afterwards. I tried usi…

---

## [Large index size cause high Java heap occupation?](https://discuss.elastic.co/t/large-index-size-cause-high-java-heap-occupation/26936)

<div class="topic-metadata">

**Author:** [@yehua984710](https://discuss.elastic.co/u/yehua984710)\
**Replies:** 12\
**Last updated:** [August 12, 2015, 5:31am UTC](https://discuss.elastic.co/t/large-index-size-cause-high-java-heap-occupation/26936 "2015-08-12T05:31:40Z")

</div>

Hi all, We use Elasticsearch 1.6.0 and run two data nodes in two servers with 128G RAM and 24 Core CPU. ES java heap size is set to 30G and the index is configured to 5 shards with 1 replica. Unlike common log files,…

---

## [Kibana Blank Page After Deleting Index](https://discuss.elastic.co/t/kibana-blank-page-after-deleting-index/80164)

<div class="topic-metadata">

**Author:** [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Replies:** 21\
**Last updated:** [April 3, 2017, 6:54pm UTC](https://discuss.elastic.co/t/kibana-blank-page-after-deleting-index/80164 "2017-04-03T18:54:50Z")

</div>

I have a blank page for all pages, including the Discovery and Management pages. I have tried every option in terms of re-indexing, etc that I can find in order to get Kibana to reset. I have many visualizations, etc t…

---

## [Duplicate log entries](https://discuss.elastic.co/t/duplicate-log-entries/259394)

<div class="topic-metadata">

**Author:** [@leandro.borges](https://discuss.elastic.co/u/leandro.borges)\
**Replies:** 17\
**Last updated:** [December 23, 2020, 3:52pm UTC](https://discuss.elastic.co/t/duplicate-log-entries/259394 "2020-12-23T15:52:32Z")

</div>

Hi, We are facing some issues with elasticsearch. We are having lots of duplicate log entries like below. Inside logstash.yml there is only a file in path.config that we use: path.config: "/etc/logstash/pipeline.global.…

---

## [Can i use file filter for xml docs](https://discuss.elastic.co/t/can-i-use-file-filter-for-xml-docs/1913)

<div class="topic-metadata">

**Author:** [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Replies:** 11\
**Last updated:** [June 5, 2015, 1:11pm UTC](https://discuss.elastic.co/t/can-i-use-file-filter-for-xml-docs/1913 "2015-06-05T13:11:56Z")

</div>

input { file { path =\> "D:\\folder\*.xml" type =\> "string" start\_position =\> "beginning" } } filter { xml {.... } }

---

## [Kibana free authentication](https://discuss.elastic.co/t/kibana-free-authentication/227497)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 9\
**Last updated:** [April 10, 2020, 2:47pm UTC](https://discuss.elastic.co/t/kibana-free-authentication/227497 "2020-04-10T14:47:17Z")

</div>

Dears, Is there any option to configure Kibana (ELK 7.6.2) free authentication without x-pack? Best Regads, d

---

## [Parsing json logs using logstash](https://discuss.elastic.co/t/parsing-json-logs-using-logstash/274240)

<div class="topic-metadata">

**Author:** [@learningelk](https://discuss.elastic.co/u/learningelk)\
**Replies:** 10\
**Last updated:** [June 3, 2021, 2:15pm UTC](https://discuss.elastic.co/t/parsing-json-logs-using-logstash/274240 "2021-06-03T14:15:03Z")

</div>

Hi I want to parse the json logs using logstash and send them to elastic .There are multiple nested fields in my logs but I want very specific fields for eg , here is my log format : { "\_index": "ekslogs-2021.05.27", …

---

## [Logstash JDBC Plugin Cassandra Driver Not Loaded Error](https://discuss.elastic.co/t/logstash-jdbc-plugin-cassandra-driver-not-loaded-error/38210)

<div class="topic-metadata">

**Author:** [@Vijay\_Dodla](https://discuss.elastic.co/u/Vijay_Dodla)\
**Replies:** 12\
**Last updated:** [July 2, 2016, 11:14am UTC](https://discuss.elastic.co/t/logstash-jdbc-plugin-cassandra-driver-not-loaded-error/38210 "2016-07-02T11:14:05Z")

</div>

Hi All Can anyone point me to examples on how logstash can read cassandra DB using JDBC . I tried something like this from logstash installed directory Step 1 : Create config file for logstash (File name :simple-out…

---

## [Filebeat and updating existing docs](https://discuss.elastic.co/t/filebeat-and-updating-existing-docs/320781)

<div class="topic-metadata">

**Author:** [@Marcin\_Frankiewicz](https://discuss.elastic.co/u/Marcin_Frankiewicz)\
**Replies:** 30\
**Last updated:** [January 9, 2023, 12:57pm UTC](https://discuss.elastic.co/t/filebeat-and-updating-existing-docs/320781 "2023-01-09T12:57:04Z")

</div>

Hi, I'm trying to update documents when they exists.. it is possible with filebeat? Logstash has that functionality... output { elasticsearch { doc\_as\_upsert =\> true document\_id =\> "%{fingerprint}" The fing…

---

## [Elasticsearch 1.2 Delete and Reinstall](https://discuss.elastic.co/t/elasticsearch-1-2-delete-and-reinstall/18036)

<div class="topic-metadata">

**Author:** [@seja12](https://discuss.elastic.co/u/seja12)\
**Replies:** 17\
**Last updated:** [June 12, 2014, 7:55am UTC](https://discuss.elastic.co/t/elasticsearch-1-2-delete-and-reinstall/18036 "2014-06-12T07:55:33Z")

</div>

I recently upgraded to elasticsearch 1.2.1 and have since seen most of my scripts stop working. Nothing seems to work properly and I think I may have messed up during the upgrade. How can I properly delete elasticsea…

---

## [Logstash Kafka output storing topic offset option](https://discuss.elastic.co/t/logstash-kafka-output-storing-topic-offset-option/47696)

<div class="topic-metadata">

**Author:** [@stecino](https://discuss.elastic.co/u/stecino)\
**Replies:** 13\
**Last updated:** [July 12, 2016, 7:17pm UTC](https://discuss.elastic.co/t/logstash-kafka-output-storing-topic-offset-option/47696 "2016-07-12T19:17:26Z")

</div>

Hello, Due to some shared architecture that I have to deal with, I am asked to find out if logstash kafka output when writing to kafka topic, can save the offset in kafka as opose to the zookeper. Is there a way to do …

---

## [Want to Create Pie Chart Visualization (Showing Most Popular Browsers)](https://discuss.elastic.co/t/want-to-create-pie-chart-visualization-showing-most-popular-browsers/25393)

<div class="topic-metadata">

**Author:** [@bhutchinson](https://discuss.elastic.co/u/bhutchinson)\
**Replies:** 10\
**Last updated:** [October 13, 2015, 10:20am UTC](https://discuss.elastic.co/t/want-to-create-pie-chart-visualization-showing-most-popular-browsers/25393 "2015-10-13T10:20:47Z")

</div>

Windows 7 elasticsearch v1.6.0 logstash v1.5.2 kibana v4.1.0 Apache Access Log file (access\_log) Background I have successfully used logstash to import an Apache Access log with the Grok Fitler "COMBINEDAPACHELOG" …

---

## [Kibana 9.1.4 on Windows fails to start due to Timelion plugin: Cannot find module '../series\_functions/undefined'](https://discuss.elastic.co/t/kibana-9-1-4-on-windows-fails-to-start-due-to-timelion-plugin-cannot-find-module-series-functions-undefined/382144)

<div class="topic-metadata">

**Author:** [@kevin\_wang2](https://discuss.elastic.co/u/kevin_wang2)\
**Replies:** 17\
**Last updated:** [December 4, 2025, 6:19pm UTC](https://discuss.elastic.co/t/kibana-9-1-4-on-windows-fails-to-start-due-to-timelion-plugin-cannot-find-module-series-functions-undefined/382144 "2025-12-04T18:19:37Z")

</div>

Hi team, I’m hitting a fatal startup crash on Kibana 9.1.4 (Windows x64) where the Timelion plugin fails while loading its server-side functions. The process reaches preboot, then shuts down with: \[2025-09-23T10:04:14.…

---

## [Shards getting marked as stale frequently causing cluster to go yellow](https://discuss.elastic.co/t/shards-getting-marked-as-stale-frequently-causing-cluster-to-go-yellow/231835)

<div class="topic-metadata">

**Author:** [@Faiz\_Ahmed\_Mushtak\_H](https://discuss.elastic.co/u/Faiz_Ahmed_Mushtak_H)\
**Replies:** 24\
**Last updated:** [May 16, 2020, 12:24pm UTC](https://discuss.elastic.co/t/shards-getting-marked-as-stale-frequently-causing-cluster-to-go-yellow/231835 "2020-05-16T12:24:44Z")

</div>

We use elasticsearch 7.2. It's a 11 node cluster with around 2TB of data sharded across 30 shards We use G1GC & have fixed this https://github.com/elastic/elasticsearch/pull/46169 Lately we've been seeing unnecessary c…

---

## [Access elasticsearch from public ip instead of LAN ipv4](https://discuss.elastic.co/t/access-elasticsearch-from-public-ip-instead-of-lan-ipv4/248087)

<div class="topic-metadata">

**Author:** [@Abdul\_Samad](https://discuss.elastic.co/u/Abdul_Samad)\
**Replies:** 12\
**Last updated:** [September 14, 2020, 12:46pm UTC](https://discuss.elastic.co/t/access-elasticsearch-from-public-ip-instead-of-lan-ipv4/248087 "2020-09-14T12:46:42Z")

</div>

I have elasticsearch installed in one machine with local LAN ipv4 = 192.168.. public ip = 39...\* i have http.port: 9200 network.host: 0.0.0.0 in my elasticsearch.yml I can access this with in same network: ipv4:9…

---

## [GeoIP location has added brackets and not able to visualize](https://discuss.elastic.co/t/geoip-location-has-added-brackets-and-not-able-to-visualize/44259)

<div class="topic-metadata">

**Author:** [@Hans](https://discuss.elastic.co/u/Hans)\
**Replies:** 10\
**Last updated:** [July 22, 2016, 6:45pm UTC](https://discuss.elastic.co/t/geoip-location-has-added-brackets-and-not-able-to-visualize/44259 "2016-07-22T18:45:07Z")

</div>

Hi, I have been trying to figure this out without success and hope there is someone out there that can assist with this matter. I have the GoeIP filter on the source and destination IP address and all works very well wit…

---

## [Transport Error Unauthorized](https://discuss.elastic.co/t/transport-error-unauthorized/280476)

<div class="topic-metadata">

**Author:** [@agentw](https://discuss.elastic.co/u/agentw)\
**Replies:** 11\
**Last updated:** [August 12, 2021, 4:33pm UTC](https://discuss.elastic.co/t/transport-error-unauthorized/280476 "2021-08-12T16:33:31Z")

</div>

I upgraded our cluster to 7.14, and after the update for Logstash I received "Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<Elasticsearch::Transport::Transport::Errors::Unauthorized: \[401\]". I was able to isolate i…

---

## [Finding past due orders in Kibana by subracting one date from another](https://discuss.elastic.co/t/finding-past-due-orders-in-kibana-by-subracting-one-date-from-another/36906)

<div class="topic-metadata">

**Author:** [@jjdepaul](https://discuss.elastic.co/u/jjdepaul)\
**Replies:** 14\
**Last updated:** [July 24, 2016, 7:49am UTC](https://discuss.elastic.co/t/finding-past-due-orders-in-kibana-by-subracting-one-date-from-another/36906 "2016-07-24T07:49:10Z")

</div>

Environment: LS2.0, ES2.0, Kib4.2 and Sh2.0 We are capturing order flow data in an Index complete with time stamps of the major order fulfillment events. We want to identify few key orders that are past due. I want…

---

## [Help needed: Filebeat Container input \> Elasticsearch \>Kibana](https://discuss.elastic.co/t/help-needed-filebeat-container-input-elasticsearch-kibana/197059)

<div class="topic-metadata">

**Author:** [@Iosif\_Zamfirescu](https://discuss.elastic.co/u/Iosif_Zamfirescu)\
**Replies:** 11\
**Last updated:** [September 24, 2019, 11:54am UTC](https://discuss.elastic.co/t/help-needed-filebeat-container-input-elasticsearch-kibana/197059 "2019-09-24T11:54:21Z")

</div>

Hi all, Docker home user here who needs some help. Architecture: Host OS: Windows 10 Pro Docker for Windows latest version. I use docker compose managed through dockstation.io In the attached picture you can see wh…

---

## [Filebat - Create a custom index on elasticsearch](https://discuss.elastic.co/t/filebat-create-a-custom-index-on-elasticsearch/197741)

<div class="topic-metadata">

**Author:** [@jaderolyver](https://discuss.elastic.co/u/jaderolyver)\
**Replies:** 13\
**Last updated:** [September 25, 2019, 7:10am UTC](https://discuss.elastic.co/t/filebat-create-a-custom-index-on-elasticsearch/197741 "2019-09-25T07:10:20Z")

</div>

Please someone here understand what is happen with my config, my filebeat doenst create index with my custom name. When i run the command filebeat setup the filebeat communicate with my elastic and create a index default…

---

## [Does logstash jdbc connection work with Windows Authentication?](https://discuss.elastic.co/t/does-logstash-jdbc-connection-work-with-windows-authentication/141562)

<div class="topic-metadata">

**Author:** [@Palash\_Tichkule](https://discuss.elastic.co/u/Palash_Tichkule)\
**Replies:** 10\
**Last updated:** [August 6, 2018, 6:07am UTC](https://discuss.elastic.co/t/does-logstash-jdbc-connection-work-with-windows-authentication/141562 "2018-08-06T06:07:30Z")

</div>

How to use logstash JDBC connection with Windows Authentication. The server does not accepts username and password even if they are passed

---

## [Trial license expired](https://discuss.elastic.co/t/trial-license-expired/283705)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 9\
**Last updated:** [September 9, 2021, 11:26pm UTC](https://discuss.elastic.co/t/trial-license-expired/283705 "2021-09-09T23:26:48Z")

</div>

I am running elastic 7.11 and had the enterprise trial license installed. We have xpack security enabled via the elastic configs and I noticed it says when reverting to basic the security will be disabled. Does changing …

---

## [Can Elastic run complex search using annotated tokens?](https://discuss.elastic.co/t/can-elastic-run-complex-search-using-annotated-tokens/29630)

<div class="topic-metadata">

**Author:** [@jeko](https://discuss.elastic.co/u/jeko)\
**Replies:** 9\
**Last updated:** [September 25, 2015, 4:50pm UTC](https://discuss.elastic.co/t/can-elastic-run-complex-search-using-annotated-tokens/29630 "2015-09-25T16:50:32Z")

</div>

Hello, Is it possible using elastic to run a request that'll return all documents with tokens matching: word:dog (followed-by) type:verb With documents looking like this: { "sentence": "the dog barks", …

---

## [Java.lang.OutOfMemoryError: Java heap space](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space/12466)

<div class="topic-metadata">

**Author:** [@vinod\_eligeti](https://discuss.elastic.co/u/vinod_eligeti)\
**Replies:** 24\
**Last updated:** [October 4, 2013, 5:41am UTC](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space/12466 "2013-10-04T05:41:10Z")

</div>

I am getting heap space error. Basically I am starting a embedded ES node with data set to true option. The elasticsearch.yml is not in the classpath which means it will go for defaults. I created 1 index seeded 3…

---

## [Unexpected token i error?](https://discuss.elastic.co/t/unexpected-token-i-error/24472)

<div class="topic-metadata">

**Author:** [@linlma](https://discuss.elastic.co/u/linlma)\
**Replies:** 13\
**Last updated:** [June 29, 2015, 9:16am UTC](https://discuss.elastic.co/t/unexpected-token-i-error/24472 "2015-06-29T09:16:55Z")

</div>

Hello ElasticSearch experts, I am a new user of ElasticSearch, I am testing with basic query below and got error of "Unexpected token i", Does anyone have any thoughts? { "query": { "match\_all" : { } } } t…

---

## [Filebeat not reading all docker container logs](https://discuss.elastic.co/t/filebeat-not-reading-all-docker-container-logs/160801)

<div class="topic-metadata">

**Author:** [@elizajanus](https://discuss.elastic.co/u/elizajanus)\
**Replies:** 10\
**Last updated:** [January 8, 2019, 5:56pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-all-docker-container-logs/160801 "2019-01-08T17:56:37Z")

</div>

Filebeat is reading some docker container logs, but not all. I checked one of the log files that was being excluded and it has been updating recently but I can't see any information for that container in Kibana. There ar…

---

## [Get Month From Date/Time Field \[Painless\]](https://discuss.elastic.co/t/get-month-from-date-time-field-painless/262916)

<div class="topic-metadata">

**Author:** [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Replies:** 17\
**Last updated:** [February 3, 2021, 10:54pm UTC](https://discuss.elastic.co/t/get-month-from-date-time-field-painless/262916 "2021-02-03T22:54:57Z")

</div>

Hello Following this example When using doc\['timestamp'\].value.getMonth(); Getting an error \[Possible causing node crash, still monitoring\] doc\['timestamp'\].value.getMonthValue(); works as expected and returning mont…

---

## [Error "ReduceSearchPhaseException"](https://discuss.elastic.co/t/error-reducesearchphaseexception/16030)

<div class="topic-metadata">

**Author:** [@Prashant\_Pal](https://discuss.elastic.co/u/Prashant_Pal)\
**Replies:** 16\
**Last updated:** [August 14, 2014, 9:00am UTC](https://discuss.elastic.co/t/error-reducesearchphaseexception/16030 "2014-08-14T09:00:10Z")

</div>

Hi All, I am executing a cluster query to fetch the documents and cluster it using Carrot2. If I am doing the query with the words "mobiles, samsung, test" it works fine but if I do the query with word "mobile" i…

---

## [Elastic Endpoint Security missing host](https://discuss.elastic.co/t/elastic-endpoint-security-missing-host/250420)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 20\
**Last updated:** [October 7, 2020, 9:32pm UTC](https://discuss.elastic.co/t/elastic-endpoint-security-missing-host/250420 "2020-10-07T21:32:39Z")

</div>

Hi, I am running ELK v7.9.2 standalone I just started to test Elastic Endpoint Security (from now on "EES"). I managed to enable all the necessary settings on the ELK host side and deployed EES in two different hosts: …

---

## [Elasticsearch IOPS](https://discuss.elastic.co/t/elasticsearch-iops/265680)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 10\
**Last updated:** [March 1, 2021, 6:10am UTC](https://discuss.elastic.co/t/elasticsearch-iops/265680 "2021-03-01T06:10:15Z")

</div>

Hello Team I am having Elasticsearch version 5.6.3 running on RHEL 7.4. This Cluster is of 10 nodes. Hardware : 8 CPU and 32 GB RAM. Hard Disk : HDD { CEPH Storage } Elastic Data Paths : Multiple { 7 Different mount …

---

## [Org.elasticsearch.indices.IndexMissingException](https://discuss.elastic.co/t/org-elasticsearch-indices-indexmissingexception/2946)

<div class="topic-metadata">

**Author:** [@John\_Chang](https://discuss.elastic.co/u/John_Chang)\
**Replies:** 11\
**Last updated:** [May 14, 2010, 9:06pm UTC](https://discuss.elastic.co/t/org-elasticsearch-indices-indexmissingexception/2946 "2010-05-14T21:06:31Z")

</div>

I keep getting org.elasticsearch.indices.IndexMissingException from ActionFuture.actionGet() when I try to search using the java client. It throws the exception below and then hangs; never gets to the next line. I…

---

## [Ruby exception occurred: undefined method \`split' for nil:NilClass](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352)

<div class="topic-metadata">

**Author:** [@monika](https://discuss.elastic.co/u/monika)\
**Replies:** 9\
**Last updated:** [June 26, 2019, 11:16am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352 "2019-06-26T11:16:16Z")

</div>

This is my config for logstash (filter file ) filter { if "ETL\_log\_enriched" in \[tags\] { grok { match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:log\_timestamp} (%{LOGLEVEL:loglevel}|%{WORD:loglevel}) (?\[^\]\]+)- %{GREEDY…

---

## [Hide/Display menu in Kibana UI](https://discuss.elastic.co/t/hide-display-menu-in-kibana-ui/138168)

<div class="topic-metadata">

**Author:** [@Preethi](https://discuss.elastic.co/u/Preethi)\
**Replies:** 9\
**Last updated:** [July 3, 2018, 5:17pm UTC](https://discuss.elastic.co/t/hide-display-menu-in-kibana-ui/138168 "2018-07-03T17:17:49Z")

</div>

Hi, I use these settings in kibana.yml, only the Timeline is not getting displayed. The Dev Tools still getting displayed, even after restating the Kibana service. Any idea? console.enabled: false timelion.enabled: fa…

---

## [Query returns the same document 7 times](https://discuss.elastic.co/t/query-returns-the-same-document-7-times/12228)

<div class="topic-metadata">

**Author:** [@Kya\_W](https://discuss.elastic.co/u/Kya_W)\
**Replies:** 21\
**Last updated:** [June 4, 2013, 9:15am UTC](https://discuss.elastic.co/t/query-returns-the-same-document-7-times/12228 "2013-06-04T09:15:59Z")

</div>

Hi there! I'm currently trying to use Elasticsearch in my thesis work, but encountered a problem. If I use a term, for example "Monkey", which has 1 hit in my index... It returns this document 7 times. I use Jest to…

---

## [Error from server (Timeout): error when creating "STDIN": Timeout: request did not complete within requested timeout 30s](https://discuss.elastic.co/t/error-from-server-timeout-error-when-creating-stdin-timeout-request-did-not-complete-within-requested-timeout-30s/196680)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 10\
**Last updated:** [March 31, 2020, 8:58pm UTC](https://discuss.elastic.co/t/error-from-server-timeout-error-when-creating-stdin-timeout-request-did-not-complete-within-requested-timeout-30s/196680 "2020-03-31T20:58:21Z")

</div>

Hello World! I'm trying to follow Quickstart | Elastic Cloud on Kubernetes \[0.9\] | Elastic: Deploy ECK in your Kubernetes cluster $ kubectl apply -f https://download.elastic.co/downloads/eck/0.9.0/all-in-one.yaml cust…

---

## [How to modify term frequency formula?](https://discuss.elastic.co/t/how-to-modify-term-frequency-formula/16501)

<div class="topic-metadata">

**Author:** [@geantbrun](https://discuss.elastic.co/u/geantbrun)\
**Replies:** 24\
**Last updated:** [April 10, 2014, 2:29pm UTC](https://discuss.elastic.co/t/how-to-modify-term-frequency-formula/16501 "2014-04-10T14:29:42Z")

</div>

Hi, If I understand well, the formula used for the term frequency part in the default similarity module is the square root of the actual frequency. Is it possible to modify that formula to include something like a …

---

## [Wrong mapping, need to change it \\ lost in how to and documentation](https://discuss.elastic.co/t/wrong-mapping-need-to-change-it-lost-in-how-to-and-documentation/56131)

<div class="topic-metadata">

**Author:** [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Replies:** 9\
**Last updated:** [July 26, 2016, 2:16pm UTC](https://discuss.elastic.co/t/wrong-mapping-need-to-change-it-lost-in-how-to-and-documentation/56131 "2016-07-26T14:16:44Z")

</div>

Hello, sorry to bother you all. and sorry for any "lack of information" on my sides.. I'm running ELK stalk to index logs from syslog Fortinet Analyzer, all of my "fields" are currentely STRING except a few exception .…

---

## [Watcher and Microsoft Teams webhook](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189)

<div class="topic-metadata">

**Author:** [@wellerbar](https://discuss.elastic.co/u/wellerbar)\
**Replies:** 11\
**Last updated:** [October 16, 2019, 12:57pm UTC](https://discuss.elastic.co/t/watcher-and-microsoft-teams-webhook/203189 "2019-10-16T12:57:35Z")

</div>

Hi there, I would like to use watcher UI to send messages to a microsoft teams webhook. However, when I send a notification, on my firewall, I find "tcp-rst-from-server". I do not understand why. how could I fix this …

---

## [After upgrade from ES-2.1.1 to ES-2.2.0 groovy scripting is broken](https://discuss.elastic.co/t/after-upgrade-from-es-2-1-1-to-es-2-2-0-groovy-scripting-is-broken/40977)

<div class="topic-metadata">

**Author:** [@mumpi](https://discuss.elastic.co/u/mumpi)\
**Replies:** 14\
**Last updated:** [February 26, 2016, 7:15am UTC](https://discuss.elastic.co/t/after-upgrade-from-es-2-1-1-to-es-2-2-0-groovy-scripting-is-broken/40977 "2016-02-26T07:15:56Z")

</div>

trying a test-query after upgrading from ES-2.1.1 to ES-2-2-0 POST smd\_\*/\_search { "query": { "match\_all": {} }, "script\_fields": { "test": { "script": { "inline": "1 + 1" }}}} bring…

---

## [Can't avoid swapping on Windows cluster](https://discuss.elastic.co/t/cant-avoid-swapping-on-windows-cluster/72414)

<div class="topic-metadata">

**Author:** [@jthoni](https://discuss.elastic.co/u/jthoni)\
**Replies:** 15\
**Last updated:** [February 13, 2017, 5:24pm UTC](https://discuss.elastic.co/t/cant-avoid-swapping-on-windows-cluster/72414 "2017-02-13T17:24:26Z")

</div>

We have a cluster that has three indexes (one main, and two supporting) with 5 shards and one replica. I am using 7 Windows nodes, each of which have 8 cores and 56gb RAM. I have set the heap to use 28gb. I have disab…

---

## [How create watcher email alerts and elasticsearch.yml file settings](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314)

<div class="topic-metadata">

**Author:** [@vishnuvardhan](https://discuss.elastic.co/u/vishnuvardhan)\
**Replies:** 12\
**Last updated:** [November 6, 2019, 9:45am UTC](https://discuss.elastic.co/t/how-create-watcher-email-alerts-and-elasticsearch-yml-file-settings/206314 "2019-11-06T09:45:39Z")

</div>

please share step by step configure watcher and elasticsearch.yml file settings and smtp mail configurations . thanks in advance .

---

## [Help parsing custom nginx logs using Filebeat and Ingest Pipelines](https://discuss.elastic.co/t/help-parsing-custom-nginx-logs-using-filebeat-and-ingest-pipelines/349974)

<div class="topic-metadata">

**Author:** [@BDeveloper](https://discuss.elastic.co/u/BDeveloper)\
**Replies:** 17\
**Last updated:** [December 29, 2023, 7:09pm UTC](https://discuss.elastic.co/t/help-parsing-custom-nginx-logs-using-filebeat-and-ingest-pipelines/349974 "2023-12-29T19:09:18Z")

</div>

Hi, I am new to using ELK stack. I have custom logs for my nginx access.log files and I am needing help parsing them by using filebeat and ingest pipeline (Log Files -\> Filebeat -\> (Parse with Ingest Pipeline Parse) Ela…

---

## [Not Getting Logs in Elastic Stack](https://discuss.elastic.co/t/not-getting-logs-in-elastic-stack/305025)

<div class="topic-metadata">

**Author:** [@Rajesh119](https://discuss.elastic.co/u/Rajesh119)\
**Replies:** 19\
**Last updated:** [May 18, 2022, 1:13pm UTC](https://discuss.elastic.co/t/not-getting-logs-in-elastic-stack/305025 "2022-05-18T13:13:37Z")

</div>

Hi, i recently install latest version of elastic stack(Elasticsearch, kibana, logstash and filebeat) but iam not getting logs in elastic stack. please any one help me. curl -X GET "localhost:9200/\_cat/indices?v" outp…

---

## [Searching for Single Character](https://discuss.elastic.co/t/searching-for-single-character/8500)

<div class="topic-metadata">

**Author:** [@Sumit\_Guptaa](https://discuss.elastic.co/u/Sumit_Guptaa)\
**Replies:** 14\
**Last updated:** [July 28, 2012, 4:47am UTC](https://discuss.elastic.co/t/searching-for-single-character/8500 "2012-07-28T04:47:11Z")

</div>

hi all i have created four document in elastic search and i want to search for "UserGender":"M" between the date like "post\_date":{"from":"2009-11-15T14:12:12","to":"2009-11-16T14:12:12"} how we can find these…

---

## [Filebeat not pushing on Logstash,](https://discuss.elastic.co/t/filebeat-not-pushing-on-logstash/49073)

<div class="topic-metadata">

**Author:** [@nitesh](https://discuss.elastic.co/u/nitesh)\
**Replies:** 19\
**Last updated:** [May 4, 2016, 12:57pm UTC](https://discuss.elastic.co/t/filebeat-not-pushing-on-logstash/49073 "2016-05-04T12:57:36Z")

</div>

I am trying to provide logs from filebeat to logstash. But they are not sent and at server side if I try : curl -XGET 'http://localhost:9200/filebeat-\*/\_search?pretty' { "took" : 1, "timed\_out" : false, "\_shards…

---

## [Filtering "long" type values returns 0 hits, no results](https://discuss.elastic.co/t/filtering-long-type-values-returns-0-hits-no-results/52975)

<div class="topic-metadata">

**Author:** [@twee](https://discuss.elastic.co/u/twee)\
**Replies:** 12\
**Last updated:** [April 3, 2018, 1:21pm UTC](https://discuss.elastic.co/t/filtering-long-type-values-returns-0-hits-no-results/52975 "2018-04-03T13:21:26Z")

</div>

Hi, I'm having an index with mapping as following: domainId":{"type":"long"} In kibana, I see values for this field, for example: 7,653,256,037,708,803,072 7,055,736,606,716,153,856 -3,956,219,722,791,012,864 . . …

---

## [FileBeat Connection error to elastic search](https://discuss.elastic.co/t/filebeat-connection-error-to-elastic-search/176538)

<div class="topic-metadata">

**Author:** [@KK23](https://discuss.elastic.co/u/KK23)\
**Replies:** 12\
**Last updated:** [April 12, 2019, 8:38am UTC](https://discuss.elastic.co/t/filebeat-connection-error-to-elastic-search/176538 "2019-04-12T08:38:36Z")

</div>

Getting below errors in FileBeat after starting filebeat ERROR pipeline/output.go:100 Failed to connect to backoff(elasticsearch(http://localhost:9200)): Get http://localhost:9200: EOF Filebeat config file has this …

---

## [ML Job on Scripted field](https://discuss.elastic.co/t/ml-job-on-scripted-field/116820)

<div class="topic-metadata">

**Author:** [@sarvendra.singh](https://discuss.elastic.co/u/sarvendra.singh)\
**Replies:** 21\
**Last updated:** [February 19, 2018, 3:55pm UTC](https://discuss.elastic.co/t/ml-job-on-scripted-field/116820 "2018-02-19T15:55:13Z")

</div>

Hi Team, Need your advice relating to creating machine learning job. I am trying to create single metric job for detecting anomalies in mean of some scripted field(which is created with help of injected fields using l…

---

## [Elastic search depreciated classes](https://discuss.elastic.co/t/elastic-search-depreciated-classes/116232)

<div class="topic-metadata">

**Author:** [@Master](https://discuss.elastic.co/u/Master)\
**Replies:** 18\
**Last updated:** [January 25, 2018, 1:01pm UTC](https://discuss.elastic.co/t/elastic-search-depreciated-classes/116232 "2018-01-25T13:01:14Z")

</div>

i want to migrate elastic search from 2.x to 6.x. In this process created new indexed and loaded data from DB to ES 6.x but in service layer(java) facing some issue like below orQueryBuilder.add(QueryBuilders.termQuery…

[Previous page](https://discuss.elastic.co/top.md?page=52&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=54&per_page=50&period=all)
