# Top

**URL:** https://discuss.elastic.co/top.md?page=55&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 56

---

## [AWS CloudWatch integration with Elastic using Elastic Agent](https://discuss.elastic.co/t/aws-cloudwatch-integration-with-elastic-using-elastic-agent/308318)

<div class="topic-metadata">

**Author:** [@JypraGroup](https://discuss.elastic.co/u/JypraGroup)\
**Replies:** 27\
**Last updated:** [August 8, 2022, 2:52pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-integration-with-elastic-using-elastic-agent/308318 "2022-08-08T14:52:36Z")

</div>

Hi all, I have Elastic agent installed on the endpoint and I can see the logs coming in. The policy has AWS CloudWatch integration however I am not sure what else is required to get the logs and metrics flowing from the…

---

## [Not able to match on short word](https://discuss.elastic.co/t/not-able-to-match-on-short-word/43791)

<div class="topic-metadata">

**Author:** [@mdessureault](https://discuss.elastic.co/u/mdessureault)\
**Replies:** 16\
**Last updated:** [March 21, 2016, 1:25pm UTC](https://discuss.elastic.co/t/not-able-to-match-on-short-word/43791 "2016-03-21T13:25:48Z")

</div>

My application relies on elasticsearch to search for people using different attributes. The user enters someone's first name, last name or both and the ES client does a boolean query across a handful of fields to find ma…

---

## [How to parse json inside text line](https://discuss.elastic.co/t/how-to-parse-json-inside-text-line/202800)

<div class="topic-metadata">

**Author:** [@Deny7](https://discuss.elastic.co/u/Deny7)\
**Replies:** 17\
**Last updated:** [October 10, 2019, 10:05am UTC](https://discuss.elastic.co/t/how-to-parse-json-inside-text-line/202800 "2019-10-10T10:05:24Z")

</div>

Hi, I have following log that looks like this: 1570519737247 I access {"date":"2019-10-08T09:28:57.247","rootTitle":"title1","rootModel":"model1","dcTitle":"\[1a\]"} 1570519737247 I access {"date":"2019-10-08T09:28:57.2…

---

## [ES Linux vs Windows - 100% mem use during index, different search times (Linux is slower)](https://discuss.elastic.co/t/es-linux-vs-windows-100-mem-use-during-index-different-search-times-linux-is-slower/54582)

<div class="topic-metadata">

**Author:** [@haldrich](https://discuss.elastic.co/u/haldrich)\
**Replies:** 9\
**Last updated:** [July 4, 2016, 9:23pm UTC](https://discuss.elastic.co/t/es-linux-vs-windows-100-mem-use-during-index-different-search-times-linux-is-slower/54582 "2016-07-04T21:23:56Z")

</div>

We have been running a Windows ES cluster for some time. We decided that it seemed Linux often was considered faster in performance... So when we upgraded our cluster, we used Linux boxes. A little background on the…

---

## [Elastic agent (metricbeat logs): Cannot index event publisher.Event](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364)

<div class="topic-metadata">

**Author:** [@Gomeisa](https://discuss.elastic.co/u/Gomeisa)\
**Replies:** 11\
**Last updated:** [September 6, 2021, 7:37am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-logs-cannot-index-event-publisher-event/282364 "2021-09-06T07:37:14Z")

</div>

Hi, I have recently installed a fleet-managed Elastic Agent on my servers. my metricbeat\_monitor-json.log is flooded with this message: {"log.level":"warn","@timestamp":"2021-08-24T15:26:57.009+0430","log.logger":"ela…

---

## [Deleted .marvel-es-data](https://discuss.elastic.co/t/deleted-marvel-es-data/35445)

<div class="topic-metadata">

**Author:** [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Replies:** 15\
**Last updated:** [December 2, 2015, 8:39am UTC](https://discuss.elastic.co/t/deleted-marvel-es-data/35445 "2015-12-02T08:39:21Z")

</div>

Elasticsearch 2.0 Marvel 2.0 Kibana 4.2.1 I set up collecting data from a cluster into a "monitoring" cluster. My exporter config on my ES nodes are: marvel.agent.exporters: id1: type: http host: \[ "10.1…

---

## [Improve performance of Logstash data loading into ES](https://discuss.elastic.co/t/improve-performance-of-logstash-data-loading-into-es/88828)

<div class="topic-metadata">

**Author:** [@udaykirankona](https://discuss.elastic.co/u/udaykirankona)\
**Replies:** 15\
**Last updated:** [June 20, 2017, 1:51pm UTC](https://discuss.elastic.co/t/improve-performance-of-logstash-data-loading-into-es/88828 "2017-06-20T13:51:03Z")

</div>

HI, I am trying to load data into elasticsearch using logstash, but its loading very slow. 80000/minute into elasticsearch. So, its taking 10 mins for 11GB data. I have requirement to reduce this to 10 secs. Please h…

---

## [Mapping geo\_point](https://discuss.elastic.co/t/mapping-geo-point/155956)

<div class="topic-metadata">

**Author:** [@lemon](https://discuss.elastic.co/u/lemon)\
**Replies:** 10\
**Last updated:** [November 12, 2018, 1:12pm UTC](https://discuss.elastic.co/t/mapping-geo-point/155956 "2018-11-12T13:12:59Z")

</div>

Hi, i'm trying to put a custom index in order to change the type of my field \[Geolocation\] (currently is string) which contain coordinates like "42.12356,72.23523". When I put the mapping i have an error: My mapping f…

---

## [Where did these indices come from?](https://discuss.elastic.co/t/where-did-these-indices-come-from/26207)

<div class="topic-metadata">

**Author:** [@Bramin](https://discuss.elastic.co/u/Bramin)\
**Replies:** 14\
**Last updated:** [August 5, 2015, 11:39pm UTC](https://discuss.elastic.co/t/where-did-these-indices-come-from/26207 "2015-08-05T23:39:38Z")

</div>

I have Elasticsearch running on two nodes with kibana on one of them. I have port 9200 closed on the firewall and can't access it from outside the network. When I list the indices, it shows several that I did not creat…

---

## [Confused with the Smart Chinese Analysis plugin](https://discuss.elastic.co/t/confused-with-the-smart-chinese-analysis-plugin/46782)

<div class="topic-metadata">

**Author:** [@Morriaty](https://discuss.elastic.co/u/Morriaty)\
**Replies:** 12\
**Last updated:** [April 13, 2016, 6:48am UTC](https://discuss.elastic.co/t/confused-with-the-smart-chinese-analysis-plugin/46782 "2016-04-13T06:48:29Z")

</div>

I set smartcn as default analyzer in config file index.analysis.analyzer.default.type : "smartcn" And I create a type item which had a string field name, like this: "name": "开关/插座 -代金券-西门子" You can see it as…

---

## [How to I migrate my existing postgres data to elasticsearch and also keep it in sync?](https://discuss.elastic.co/t/how-to-i-migrate-my-existing-postgres-data-to-elasticsearch-and-also-keep-it-in-sync/154314)

<div class="topic-metadata">

**Author:** [@patrick007](https://discuss.elastic.co/u/patrick007)\
**Replies:** 9\
**Last updated:** [October 29, 2018, 7:59am UTC](https://discuss.elastic.co/t/how-to-i-migrate-my-existing-postgres-data-to-elasticsearch-and-also-keep-it-in-sync/154314 "2018-10-29T07:59:10Z")

</div>

I want to migrate my existing postgres db data to elasticsearch. And after the migration also want to update the elasticsearch with new update to the database

---

## [How can I speed up Kibana aggregation?](https://discuss.elastic.co/t/how-can-i-speed-up-kibana-aggregation/47161)

<div class="topic-metadata">

**Author:** [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Replies:** 9\
**Last updated:** [April 21, 2016, 11:06pm UTC](https://discuss.elastic.co/t/how-can-i-speed-up-kibana-aggregation/47161 "2016-04-21T23:06:12Z")

</div>

Hi All, We have the following ES cluster setup and I wonder if it is possible to speed up aggregation in Kibana. We index our IIS logs into daily indexes in Kibana, and each index is about 10GB with 2 primary shards a…

---

## [Failed to authenticate with host "https://elastic:9200": Hostname/IP does not match certificat](https://discuss.elastic.co/t/failed-to-authenticate-with-host-https-elastic-9200-hostname-ip-does-not-match-certificat/308167)

<div class="topic-metadata">

**Author:** [@medch1](https://discuss.elastic.co/u/medch1)\
**Replies:** 13\
**Last updated:** [August 8, 2022, 8:58am UTC](https://discuss.elastic.co/t/failed-to-authenticate-with-host-https-elastic-9200-hostname-ip-does-not-match-certificat/308167 "2022-08-08T08:58:55Z")

</div>

Hello I was running Elastic on a pod in rancher kubernetes and Kibana in another one version 8.2.3 So I ended up in this with this log \[2022-06-25T16:15:56.848+00:00\]\[ERROR\]\[plugins.interactiveSetup.elasticsearch\]…

---

## [Installing Elasticsearch Plugins kopf](https://discuss.elastic.co/t/installing-elasticsearch-plugins-kopf/20070)

<div class="topic-metadata">

**Author:** [@vishal\_sharma](https://discuss.elastic.co/u/vishal_sharma)\
**Replies:** 13\
**Last updated:** [October 4, 2014, 5:39pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-plugins-kopf/20070 "2014-10-04T17:39:51Z")

</div>

Hi All, I am new to this group and new to logstash+elasticsearch tool. I am trying my hands on installing and running few things as mentioned on this link http://logstash.net/docs/1.4.2/tutorials/getting-started-…

---

## [Add field from csv to event log send by logstash](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677)

<div class="topic-metadata">

**Author:** [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Replies:** 23\
**Last updated:** [March 16, 2017, 10:01am UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677 "2017-03-16T10:01:34Z")

</div>

Hi friends, I have a question about filters. I have a conf file that works perfectly for sending active directory logs to elasticsearch. In my log, I have a field named "event\_data.TargetUserName and it has a registrat…

---

## [Performance of multi\_match](https://discuss.elastic.co/t/performance-of-multi-match/18296)

<div class="topic-metadata">

**Author:** [@Christoph\_Lingg](https://discuss.elastic.co/u/Christoph_Lingg)\
**Replies:** 20\
**Last updated:** [June 27, 2014, 6:01am UTC](https://discuss.elastic.co/t/performance-of-multi-match/18296 "2014-06-27T06:01:59Z")

</div>

Hi! we're using elasticsearch for an open source geocoder called photon. We're using solr previously but we switched to elasticsearch some time ago and I'am using now multi\_match's cross\_field query (which is…

---

## [Filebeat not fowarding to Logstash](https://discuss.elastic.co/t/filebeat-not-fowarding-to-logstash/75358)

<div class="topic-metadata">

**Author:** [@kmrychl](https://discuss.elastic.co/u/kmrychl)\
**Replies:** 22\
**Last updated:** [February 23, 2017, 4:16pm UTC](https://discuss.elastic.co/t/filebeat-not-fowarding-to-logstash/75358 "2017-02-23T16:16:28Z")

</div>

I can't seem to get filebeat to send the logs to logstash. I'm trying to set up the elk stack on a remote ssh and visualize the logs in kibana. I've read some of the other posts, but still can't figure out the error. I h…

---

## [Log in wrong index](https://discuss.elastic.co/t/log-in-wrong-index/62740)

<div class="topic-metadata">

**Author:** [@meaglin](https://discuss.elastic.co/u/meaglin)\
**Replies:** 14\
**Last updated:** [October 13, 2016, 11:42am UTC](https://discuss.elastic.co/t/log-in-wrong-index/62740 "2016-10-13T11:42:53Z")

</div>

Hello, I've got a strange problem. I'm using logstash to get logs from syslog and ossec into elasticsearch to make it possible to search through either kibana or queries run directly on it. I have different index pa…

---

## [Master nodes do not detect the other masters after service restart](https://discuss.elastic.co/t/master-nodes-do-not-detect-the-other-masters-after-service-restart/191913)

<div class="topic-metadata">

**Author:** [@mhoydis\_datto](https://discuss.elastic.co/u/mhoydis_datto)\
**Replies:** 9\
**Last updated:** [July 24, 2019, 9:46pm UTC](https://discuss.elastic.co/t/master-nodes-do-not-detect-the-other-masters-after-service-restart/191913 "2019-07-24T21:46:15Z")

</div>

Hello. I upgraded my existing elasticsearch cluster from 6.8.0 to 7.2.0. My cluster has 3 master instances, and many data instances. After some fighting and googling, I eventually was able to get the masters to behave…

---

## [Put value of nested field into new field](https://discuss.elastic.co/t/put-value-of-nested-field-into-new-field/124522)

<div class="topic-metadata">

**Author:** [@LEK-LD](https://discuss.elastic.co/u/LEK-LD)\
**Replies:** 10\
**Last updated:** [March 20, 2018, 6:14pm UTC](https://discuss.elastic.co/t/put-value-of-nested-field-into-new-field/124522 "2018-03-20T18:14:16Z")

</div>

Hello there, i'm trying to put a value of a nested field into a new field by the help of logstash filters. I thought that the mutate-filter would be suitable for that. So here's what i'm trying to do: Log4J parses a L…

---

## [Search phase execution exception in kibana canvas](https://discuss.elastic.co/t/search-phase-execution-exception-in-kibana-canvas/186622)

<div class="topic-metadata">

**Author:** [@ksunil](https://discuss.elastic.co/u/ksunil)\
**Replies:** 12\
**Last updated:** [July 31, 2019, 8:16am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-in-kibana-canvas/186622 "2019-07-31T08:16:18Z")

</div>

Hi , Using canvas in kibana tried to display metrics for a server but shows an error "\[essql\] \> Unexpected error from Elasticsearch: search phase execution exception" . Below is the message from kibana.stdout "2019-06…

---

## [Elasticsearch will not start "error loading whitelist(s)"](https://discuss.elastic.co/t/elasticsearch-will-not-start-error-loading-whitelist-s/245314)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 20\
**Last updated:** [September 24, 2020, 5:58pm UTC](https://discuss.elastic.co/t/elasticsearch-will-not-start-error-loading-whitelist-s/245314 "2020-09-24T17:58:15Z")

</div>

My cluster ran low on space and ended up red due to unallocated shards. After cleaning out some data and doing my best to get the shards all allocated again, I tried restarting the node with the most disk space. Now it …

---

## [No results found (problem)](https://discuss.elastic.co/t/no-results-found-problem/162486)

<div class="topic-metadata">

**Author:** [@Ahmed\_Yousry](https://discuss.elastic.co/u/Ahmed_Yousry)\
**Replies:** 28\
**Last updated:** [January 6, 2019, 1:29pm UTC](https://discuss.elastic.co/t/no-results-found-problem/162486 "2019-01-06T13:29:27Z")

</div>

kibana show to me that No results found and i changed discover time to (lastes 5 years and Last 15 minutes ) but both not work and my elasticsearch can insert data and show it and kibana connected to it

---

## [Error using logstash : ParserError: Unexpected character ('\<'](https://discuss.elastic.co/t/error-using-logstash-parsererror-unexpected-character/281322)

<div class="topic-metadata">

**Author:** [@vp096](https://discuss.elastic.co/u/vp096)\
**Replies:** 18\
**Last updated:** [August 25, 2021, 5:54am UTC](https://discuss.elastic.co/t/error-using-logstash-parsererror-unexpected-character/281322 "2021-08-25T05:54:17Z")

</div>

Hello, I have been using ELK for a while and I am trying to retrieve the logs from a Wifi controller (Aruba Mobility Master). I checked with Wireshark, and I'm getting my syslog packets fine. However, logstash makes an …

---

## [ES 2.4 to 5.2 Upgrade Followed By Major Cluster Instability](https://discuss.elastic.co/t/es-2-4-to-5-2-upgrade-followed-by-major-cluster-instability/79943)

<div class="topic-metadata">

**Author:** [@mstruve](https://discuss.elastic.co/u/mstruve)\
**Replies:** 23\
**Last updated:** [March 29, 2017, 10:49pm UTC](https://discuss.elastic.co/t/es-2-4-to-5-2-upgrade-followed-by-major-cluster-instability/79943 "2017-03-29T22:49:17Z")

</div>

Hi, We recently upgraded our cluster from ES 2.4 to ES 5.2. The upgrade went smoothly but upon starting everything back up we noticed a lot of instability particularly with garbage collecting. What used to be a very s…

---

## [Regarding Coordinator Node Heap Usage](https://discuss.elastic.co/t/regarding-coordinator-node-heap-usage/152080)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 25\
**Last updated:** [October 31, 2018, 8:11pm UTC](https://discuss.elastic.co/t/regarding-coordinator-node-heap-usage/152080 "2018-10-31T20:11:02Z")

</div>

Hi, I have a problem with coordinator node memory usage on one of our elasticsearch 5.6.3 clusters. We have 3 x coordinator nodes sitting in front of 6 data nodes. Normally, I size our coordinators with 8GB RAM and 5-6G…

---

## [Increasing CLOSE\_WAIT connections and HTTP current\_open metric](https://discuss.elastic.co/t/increasing-close-wait-connections-and-http-current-open-metric/8223)

<div class="topic-metadata">

**Author:** [@otisg](https://discuss.elastic.co/u/otisg)\
**Replies:** 15\
**Last updated:** [July 2, 2012, 10:16am UTC](https://discuss.elastic.co/t/increasing-close-wait-connections-and-http-current-open-metric/8223 "2012-07-02T10:16:43Z")

</div>

Hello, I've been fighting with ES that stops working after it gets hit for several minutes by about 1200 QPS. This is happening with ES 0.19.3 and 0.19.4 on big boxes (24 cores, 96 GB RAM). What seems to be ha…

---

## [SNMP Trap Integration](https://discuss.elastic.co/t/snmp-trap-integration/130220)

<div class="topic-metadata">

**Author:** [@ysumit](https://discuss.elastic.co/u/ysumit)\
**Replies:** 10\
**Last updated:** [May 31, 2018, 5:48am UTC](https://discuss.elastic.co/t/snmp-trap-integration/130220 "2018-05-31T05:48:57Z")

</div>

Hi Team Do we have any document for Integration of SNMP Traps with Logstash? We are trying to send SNMP traps to Logstash. Regards Sumit

---

## [2.3.3 heap used too high，jvm old gen percent 100%，not crash](https://discuss.elastic.co/t/2-3-3-heap-used-too-high-jvm-old-gen-percent-100-not-crash/74582)

<div class="topic-metadata">

**Author:** [@hellokitty](https://discuss.elastic.co/u/hellokitty)\
**Replies:** 13\
**Last updated:** [February 15, 2017, 2:46am UTC](https://discuss.elastic.co/t/2-3-3-heap-used-too-high-jvm-old-gen-percent-100-not-crash/74582 "2017-02-15T02:46:51Z")

</div>

Elasticsearch version:2.3.3 Plugins installed: \[\] JVM version:1.8\_091 OS version:linux-3.10.101kernel Description of the problem including expected versus actual behavior: We deploy 12 es nodes in 3 machine. Afte…

---

## [Many small indices vs one large index?](https://discuss.elastic.co/t/many-small-indices-vs-one-large-index/4705)

<div class="topic-metadata">

**Author:** [@Hari\_Shankar](https://discuss.elastic.co/u/Hari_Shankar)\
**Replies:** 9\
**Last updated:** [June 27, 2011, 9:24pm UTC](https://discuss.elastic.co/t/many-small-indices-vs-one-large-index/4705 "2011-06-27T21:24:08Z")

</div>

Hi, Is there any obvious problem if I have a huge number of indices? Say I keep 10 indices for each customer, and I have 1000 customers, which would mean 10000 indices. I was thinking of this approach because I have…

---

## [SOLVED - ELASTICSEARCH - Unable to start elastic search service on linux](https://discuss.elastic.co/t/solved-elasticsearch-unable-to-start-elastic-search-service-on-linux/45732)

<div class="topic-metadata">

**Author:** [@vbondalapati](https://discuss.elastic.co/u/vbondalapati)\
**Replies:** 12\
**Last updated:** [April 1, 2016, 8:46pm UTC](https://discuss.elastic.co/t/solved-elasticsearch-unable-to-start-elastic-search-service-on-linux/45732 "2016-04-01T20:46:23Z")

</div>

It all started when we terminated the the over-running snapshot restore process. after this when we tried to start the elastic search we are getting below error . could some please help , its a elastic search 1.3.4 vers…

---

## [Registering S3 repository to ElasticSearch running on AWS ECS](https://discuss.elastic.co/t/registering-s3-repository-to-elasticsearch-running-on-aws-ecs/61556)

<div class="topic-metadata">

**Author:** [@111131](https://discuss.elastic.co/u/111131)\
**Replies:** 16\
**Last updated:** [September 30, 2016, 10:21am UTC](https://discuss.elastic.co/t/registering-s3-repository-to-elasticsearch-running-on-aws-ecs/61556 "2016-09-30T10:21:01Z")

</div>

HI. I'm trying to register S3 repository to ES(v.2.4) which is docker container running on AWS ECS cluster instance. config/elasticsearch.yml repositories: s3: bucket: "my.bucket" region: "ap-no…

---

## [Is REST Client for Elasticsearch the only way to go in the future?](https://discuss.elastic.co/t/is-rest-client-for-elasticsearch-the-only-way-to-go-in-the-future/93233)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 14\
**Last updated:** [August 10, 2017, 2:55pm UTC](https://discuss.elastic.co/t/is-rest-client-for-elasticsearch-the-only-way-to-go-in-the-future/93233 "2017-08-10T14:55:59Z")

</div>

I recently attended an Elasticsearch Developers course and understand that the Java API will be dropped in the near future and the Java REST client is the way to go. A Elasticsearch blog post seemed to confirm this too…

---

## [Elasticsearch \<-\> kibana mutual tls authentication: Empty client certificate chain](https://discuss.elastic.co/t/elasticsearch-kibana-mutual-tls-authentication-empty-client-certificate-chain/305954)

<div class="topic-metadata">

**Author:** [@psylity](https://discuss.elastic.co/u/psylity)\
**Replies:** 11\
**Last updated:** [June 5, 2022, 9:04pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-mutual-tls-authentication-empty-client-certificate-chain/305954 "2022-06-05T21:04:29Z")

</div>

Hello! I'm using elasticsearch & kibana both 7.17.1 and can't run mutual tls authentication setup where both elasticsearch server and clients authenticate each other. I've followed official documentation on this, and it…

---

## [Faster speed when indexing log files](https://discuss.elastic.co/t/faster-speed-when-indexing-log-files/27827)

<div class="topic-metadata">

**Author:** [@simonrisberg](https://discuss.elastic.co/u/simonrisberg)\
**Replies:** 10\
**Last updated:** [August 21, 2015, 2:40pm UTC](https://discuss.elastic.co/t/faster-speed-when-indexing-log-files/27827 "2015-08-21T14:40:25Z")

</div>

Hi! Right now I'm indexing about 15 log files with a total of 2 million log events all together. This takes a very long time and I am wondering if there is a way to speed up the process? Best regards Simon

---

## [Elasticsearch cannot start when I use a hard disk mount to data path](https://discuss.elastic.co/t/elasticsearch-cannot-start-when-i-use-a-hard-disk-mount-to-data-path/86507)

<div class="topic-metadata">

**Author:** [@majx](https://discuss.elastic.co/u/majx)\
**Replies:** 16\
**Last updated:** [May 20, 2017, 9:35am UTC](https://discuss.elastic.co/t/elasticsearch-cannot-start-when-i-use-a-hard-disk-mount-to-data-path/86507 "2017-05-20T09:35:06Z")

</div>

When i use file system , elasticsearch runs well, but if i mount a disk like /dev/sdk1 to data path /var/lib/elasticsearch, then elasticsearch cannot work any more. And the log like this: \[2017-05-20 13:14\] \[INFO\]\[plugin…

---

## [Custom Realm with JWT token](https://discuss.elastic.co/t/custom-realm-with-jwt-token/107310)

<div class="topic-metadata">

**Author:** [@jvemugunta](https://discuss.elastic.co/u/jvemugunta)\
**Replies:** 13\
**Last updated:** [November 14, 2017, 9:37pm UTC](https://discuss.elastic.co/t/custom-realm-with-jwt-token/107310 "2017-11-14T21:37:44Z")

</div>

I am struggling to make it work. I have understood the sample code given in https://github.com/elastic/shield-custom-realm-example This is my use case. I want to enable SSO for my Kibana/Elastic Search instance through …

---

## [Logstash and Jboss](https://discuss.elastic.co/t/logstash-and-jboss/51507)

<div class="topic-metadata">

**Author:** [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Replies:** 15\
**Last updated:** [December 12, 2018, 12:16pm UTC](https://discuss.elastic.co/t/logstash-and-jboss/51507 "2018-12-12T12:16:32Z")

</div>

I have newly setup a JBOSS JVM server and would like to use ELK to visualize the Server Host Usage Metrics. Though I can see there are server logs but seem are not showing the Host Usage Metrics, i.g. cpu usage, disk usa…

---

## [How to uniquely identify data from different sources](https://discuss.elastic.co/t/how-to-uniquely-identify-data-from-different-sources/90151)

<div class="topic-metadata">

**Author:** [@CDR](https://discuss.elastic.co/u/CDR)\
**Replies:** 12\
**Last updated:** [June 21, 2017, 3:40pm UTC](https://discuss.elastic.co/t/how-to-uniquely-identify-data-from-different-sources/90151 "2017-06-21T15:40:25Z")

</div>

I have different sources of data that provide the same type of logs. I would like to be able to uniquely identify where each log file came from. Here is an example of what I am talking about: There are three sources na…

---

## [Failed to install filebeat RPM on EL5 Linux machine](https://discuss.elastic.co/t/failed-to-install-filebeat-rpm-on-el5-linux-machine/76638)

<div class="topic-metadata">

**Author:** [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Replies:** 9\
**Last updated:** [March 1, 2017, 4:34pm UTC](https://discuss.elastic.co/t/failed-to-install-filebeat-rpm-on-el5-linux-machine/76638 "2017-03-01T16:34:58Z")

</div>

I am trying to install filebeat-5.0.1 and getting the following error: error: /petavm/abpapp1/inf/petavm2/Beats/packages/filebeat-5.0.1-x86\_64.rpm: Header V4 RSA/SHA512 signature: BAD, key ID d88e42b4 error: /petavm/ab…

---

## [Debug " Request Timeout after 1500ms"](https://discuss.elastic.co/t/debug-request-timeout-after-1500ms/49017)

<div class="topic-metadata">

**Author:** [@ggilat](https://discuss.elastic.co/u/ggilat)\
**Replies:** 19\
**Last updated:** [May 19, 2016, 11:31am UTC](https://discuss.elastic.co/t/debug-request-timeout-after-1500ms/49017 "2016-05-19T11:31:12Z")

</div>

Hi, all was working fine till few days ago. than i started to get this message: Request Timeout after 1500ms. i can't find any info about it in the log files. how can i debug this problem? thanks, guy

---

## [Saved objects api](https://discuss.elastic.co/t/saved-objects-api/116634)

<div class="topic-metadata">

**Author:** [@sanek64](https://discuss.elastic.co/u/sanek64)\
**Replies:** 9\
**Last updated:** [January 23, 2018, 1:22pm UTC](https://discuss.elastic.co/t/saved-objects-api/116634 "2018-01-23T13:22:55Z")

</div>

Hi, please help me with my problem: i am trying to import searches and index-patterns using api from https://github.com/elastic/kibana/pull/11632. I perform: curl -X POST 'http://localhost:5601/api/saved\_objects/searc…

---

## [Elasticsearch 2 mapping](https://discuss.elastic.co/t/elasticsearch-2-mapping/34366)

<div class="topic-metadata">

**Author:** [@mramaprasad](https://discuss.elastic.co/u/mramaprasad)\
**Replies:** 13\
**Last updated:** [November 17, 2015, 6:59pm UTC](https://discuss.elastic.co/t/elasticsearch-2-mapping/34366 "2015-11-17T18:59:53Z")

</div>

Here is the mapping for acronym field and am running elsaticsearch 1.1.1. "isbnfield": { "type":"multi\_field", "fields":{ "isbn":{"type":"string","index":"analyzed", "store" : true}, "isbn…

---

## [\[WARN \]\[o.e.d.i.m.MapperService \] \[unmapped\_type:string\] should be replaced with \[unmapped\_type:keyword\]](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948)

<div class="topic-metadata">

**Author:** [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Replies:** 17\
**Last updated:** [April 2, 2017, 1:14pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948 "2017-04-02T13:14:29Z")

</div>

Hi, how can I fix this ElasticSearch 5.2.2 Warning? \[WARN \]\[o.e.d.i.m.MapperService \] \[unmapped\_type:string\] should be replaced with \[unmapped\_type:keyword\] This is my indices configuration: https://gist.github.com/…

---

## [The aggregations key is missing from the response, check your permissions for this request](https://discuss.elastic.co/t/the-aggregations-key-is-missing-from-the-response-check-your-permissions-for-this-request/207932)

<div class="topic-metadata">

**Author:** [@Akhil\_K](https://discuss.elastic.co/u/Akhil_K)\
**Replies:** 24\
**Last updated:** [December 6, 2019, 5:50pm UTC](https://discuss.elastic.co/t/the-aggregations-key-is-missing-from-the-response-check-your-permissions-for-this-request/207932 "2019-12-06T17:50:25Z")

</div>

I am pretty new to ELK stack. We monitor a particular server health using ELK stack. We have Metricbeat which sends statics and based on that we have index created in Elastic. Kibana visualization is created based on thi…

---

## [Using NEST - No Results](https://discuss.elastic.co/t/using-nest-no-results/106191)

<div class="topic-metadata">

**Author:** [@parsa](https://discuss.elastic.co/u/parsa)\
**Replies:** 18\
**Last updated:** [December 4, 2017, 10:26pm UTC](https://discuss.elastic.co/t/using-nest-no-results/106191 "2017-12-04T22:26:28Z")

</div>

This is my result of search by calling: http://localhost:9200/servers/server/\_search?q=servername:"server1-9" {"took":1233,"timed\_out":false,"\_shards":{"total":5,"successful":5,"skipped":0,"failed":0},"hits":{"total":1…

---

## [Data is not update using schedule](https://discuss.elastic.co/t/data-is-not-update-using-schedule/105776)

<div class="topic-metadata">

**Author:** [@Sumit\_Gupta1](https://discuss.elastic.co/u/Sumit_Gupta1)\
**Replies:** 9\
**Last updated:** [October 31, 2017, 2:21pm UTC](https://discuss.elastic.co/t/data-is-not-update-using-schedule/105776 "2017-10-31T14:21:15Z")

</div>

I'm using Following command. This is not updating Data as schedule . It is my Script: input { jdbc { jdbc\_driver\_library =\> "/app/logstash-5.6.2/lib/ojdbc7.jar" jdbc\_driver\_class =\> "Java::oracle.jd…

---

## [Invalid field name: \_allow\_permissions,\_deny\_permissions](https://discuss.elastic.co/t/invalid-field-name-allow-permissions-deny-permissions/274287)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 43\
**Last updated:** [June 29, 2021, 12:50am UTC](https://discuss.elastic.co/t/invalid-field-name-allow-permissions-deny-permissions/274287 "2021-06-29T00:50:18Z")

</div>

I am trying to implement WorkplaceSearch. Since I want to include online documents used in the company in the search, I am setting up a custom source by referring to the following url. However, when I run the followin…

---

## [Problem with logstash-plain.log](https://discuss.elastic.co/t/problem-with-logstash-plain-log/223795)

<div class="topic-metadata">

**Author:** [@Pablo95](https://discuss.elastic.co/u/Pablo95)\
**Replies:** 16\
**Last updated:** [March 20, 2020, 12:51pm UTC](https://discuss.elastic.co/t/problem-with-logstash-plain-log/223795 "2020-03-20T12:51:07Z")

</div>

Hi, i'm having problems with my logstash-plain.log file. When I execute the "less" command, this is the code that i receive: \[2020-03-06T11:35:43,304\]\[WARN \]\[logstash.config.source.multilocal\] Ignoring the 'pipelines.ym…

---

## [Storing table-like data in Elastic Search](https://discuss.elastic.co/t/storing-table-like-data-in-elastic-search/9732)

<div class="topic-metadata">

**Author:** [@haizaar](https://discuss.elastic.co/u/haizaar)\
**Replies:** 14\
**Last updated:** [November 27, 2012, 9:46am UTC](https://discuss.elastic.co/t/storing-table-like-data-in-elastic-search/9732 "2012-11-27T09:46:52Z")

</div>

Hi! I'm a ElasticSearch newbie and approaching the following project - I have many millions (100+ and counting) of tables in JSON format like this: { "title" : "dogs species", "col\_names" : \[ "name", "descript…

[Previous page](https://discuss.elastic.co/top.md?page=54&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=56&per_page=50&period=all)
