# Top

**URL:** https://discuss.elastic.co/top.md?page=57&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 58

---

## [Where is the merge policy defined?](https://discuss.elastic.co/t/where-is-the-merge-policy-defined/232496)

<div class="topic-metadata">

**Author:** [@Emanuel\_Velzi](https://discuss.elastic.co/u/Emanuel_Velzi)\
**Replies:** 9\
**Last updated:** [May 14, 2020, 11:49am UTC](https://discuss.elastic.co/t/where-is-the-merge-policy-defined/232496 "2020-05-14T11:49:16Z")

</div>

Hi, I am using ES 7.6.2 and I can not find the merge policy for my indices. I don't see it in \_settings. In addition, I can not find the default merge policy in the elastic documentation. Can someone help me please?

---

## [Localisation des logs](https://discuss.elastic.co/t/localisation-des-logs/73687)

<div class="topic-metadata">

**Author:** [@Brendao](https://discuss.elastic.co/u/Brendao)\
**Replies:** 13\
**Last updated:** [February 3, 2017, 10:04am UTC](https://discuss.elastic.co/t/localisation-des-logs/73687 "2017-02-03T10:04:31Z")

</div>

Bonjour, je suis un petit nouveau sur ELK, et en tant que stagiaire je dois expliquer a mon maitre de stage le fonctionnement d'ELK. Mais il y a une chose que je ne comprend pas où son stocké les logs indexer par Logst…

---

## [Rollover by month](https://discuss.elastic.co/t/rollover-by-month/107977)

<div class="topic-metadata">

**Author:** [@acchaulk](https://discuss.elastic.co/u/acchaulk)\
**Replies:** 10\
**Last updated:** [November 16, 2017, 7:01pm UTC](https://discuss.elastic.co/t/rollover-by-month/107977 "2017-11-16T19:01:01Z")

</div>

Hello, I am trying to use the rollover api to help create indexes by month. However, the rollover api does not seem to support months as a max\_age unit: Failed to parse setting \[max\_age\] with value \[1M\] as a time value:…

---

## [How to pass basic authentication details in http filter plugin](https://discuss.elastic.co/t/how-to-pass-basic-authentication-details-in-http-filter-plugin/201246)

<div class="topic-metadata">

**Author:** [@saroja](https://discuss.elastic.co/u/saroja)\
**Replies:** 17\
**Last updated:** [October 3, 2019, 12:50pm UTC](https://discuss.elastic.co/t/how-to-pass-basic-authentication-details-in-http-filter-plugin/201246 "2019-10-03T12:50:02Z")

</div>

Hi, I am using logstash HTTP filter plugin. I want to pass basic authentication details such as username, and password in the request. Could you please suggest, how we can post a request using header, body, and basic-…

---

## [Breaking up ELK stack to individual machines](https://discuss.elastic.co/t/breaking-up-elk-stack-to-individual-machines/37796)

<div class="topic-metadata">

**Author:** [@jmillerparaport](https://discuss.elastic.co/u/jmillerparaport)\
**Replies:** 24\
**Last updated:** [December 29, 2015, 5:02pm UTC](https://discuss.elastic.co/t/breaking-up-elk-stack-to-individual-machines/37796 "2015-12-29T17:02:28Z")

</div>

Hello there, I am trying to break apart my current install of ELK that lives on one machine to an individual machine for Logstash, ElasticSearch, and Kibana. It seems as if connections to ES are being blocked as neit…

---

## [Multiple inputs and outputs in logstash conf file](https://discuss.elastic.co/t/multiple-inputs-and-outputs-in-logstash-conf-file/171025)

<div class="topic-metadata">

**Author:** [@sak6070](https://discuss.elastic.co/u/sak6070)\
**Replies:** 11\
**Last updated:** [March 29, 2019, 9:05am UTC](https://discuss.elastic.co/t/multiple-inputs-and-outputs-in-logstash-conf-file/171025 "2019-03-29T09:05:25Z")

</div>

I have included multiple inputs and outputs in my logstash conf file (without filter for now). I have also created different indexes for each input. I am not able to see all the logs on kibana , also indices are not vi…

---

## [Can't shutdown Elasticsearch when a watch is stuck](https://discuss.elastic.co/t/cant-shutdown-elasticsearch-when-a-watch-is-stuck/31892)

<div class="topic-metadata">

**Author:** [@Enniu\_51](https://discuss.elastic.co/u/Enniu_51)\
**Replies:** 18\
**Last updated:** [October 12, 2015, 12:22am UTC](https://discuss.elastic.co/t/cant-shutdown-elasticsearch-when-a-watch-is-stuck/31892 "2015-10-12T00:22:40Z")

</div>

Es log: \[2015-10-09 12:29:25,149\]\[WARN \]\[watcher.watch \] \[crawler\_service\_001\] failed to acquire lock on watch \[my-watch\] (waited for \[30 seconds\]). It is possible that for some reason this watch execution i…

---

## [Kibana URL template with relative path](https://discuss.elastic.co/t/kibana-url-template-with-relative-path/228418)

<div class="topic-metadata">

**Author:** [@surajbarde](https://discuss.elastic.co/u/surajbarde)\
**Replies:** 10\
**Last updated:** [April 21, 2020, 9:05pm UTC](https://discuss.elastic.co/t/kibana-url-template-with-relative-path/228418 "2020-04-21T21:05:33Z")

</div>

I have a question regarding Kibana URL templates for fields in the index. I have used relative path for the below URL template. On local environment it is replaced with http://localhost:5601/s/reporting/app/kibana#/…

---

## [Issue in elastic search after moving data dir](https://discuss.elastic.co/t/issue-in-elastic-search-after-moving-data-dir/174712)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 16\
**Last updated:** [April 3, 2019, 7:22pm UTC](https://discuss.elastic.co/t/issue-in-elastic-search-after-moving-data-dir/174712 "2019-04-03T19:22:28Z")

</div>

Hi I installed elastic search on linux vm. Soon I figured my space was full. SO i stopped Elastic search and moved contents of data dir to a different dir and made changes in elasticsearch.yml file and restarted it. But…

---

## [Esrally configure does not find jdk on AWS linux (centos based)](https://discuss.elastic.co/t/esrally-configure-does-not-find-jdk-on-aws-linux-centos-based/64946)

<div class="topic-metadata">

**Author:** [@Alexander\_Gray\_II](https://discuss.elastic.co/u/Alexander_Gray_II)\
**Replies:** 11\
**Last updated:** [November 9, 2016, 9:32am UTC](https://discuss.elastic.co/t/esrally-configure-does-not-find-jdk-on-aws-linux-centos-based/64946 "2016-11-09T09:32:19Z")

</div>

When I run "esrally configure" it does not detect JDK8, which i have installed. yum list installed | grep jdk java-1.7.0-openjdk.x86\_64 1:1.7.0.111-2.6.7.2.68.amzn1 installed java-1.8.0-openjdk.x86\_64 …

---

## [Distinguishing between log files when sending multiple log files from filebeat to logstash](https://discuss.elastic.co/t/distinguishing-between-log-files-when-sending-multiple-log-files-from-filebeat-to-logstash/266043)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 17\
**Last updated:** [March 11, 2021, 11:27am UTC](https://discuss.elastic.co/t/distinguishing-between-log-files-when-sending-multiple-log-files-from-filebeat-to-logstash/266043 "2021-03-11T11:27:39Z")

</div>

I'm trying to collect multiple logs from filebeat and send them to logstash. I would like to use logstash's filter to process each log file individually, but I'm having trouble. For example, first I want to rename the …

---

## [Compare condition for checking strings in watcher is not Working?](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882)

<div class="topic-metadata">

**Author:** [@naveen\_K.N](https://discuss.elastic.co/u/naveen_K.N)\
**Replies:** 11\
**Last updated:** [April 9, 2018, 8:06am UTC](https://discuss.elastic.co/t/compare-condition-for-checking-strings-in-watcher-is-not-working/126882 "2018-04-09T08:06:11Z")

</div>

Hi Elastic Experts, we have a compare condition as follows: "condition": { "compare": { "ctx.payload.hits.hits.0.\_source.syslog\_message": { "gt": "lang.OutOfMemoryError:" } } } so here we want to check if sysl…

---

## [How to write while Loops inside plugins or filters?](https://discuss.elastic.co/t/how-to-write-while-loops-inside-plugins-or-filters/184426)

<div class="topic-metadata">

**Author:** [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Replies:** 10\
**Last updated:** [June 6, 2019, 3:03pm UTC](https://discuss.elastic.co/t/how-to-write-while-loops-inside-plugins-or-filters/184426 "2019-06-06T15:03:03Z")

</div>

Hi, Is there any way to write loops inside filters or outputs plugins? For a certain message {"time"=100,"name"="test"} I want to implement something like below: c=0, while c\<=10 time=time+c c=c+1 if c=10 reset to …

---

## ["failed to merge java.io.EOFException: read past EOF: NIOFSIndexInput("](https://discuss.elastic.co/t/failed-to-merge-java-io-eofexception-read-past-eof-niofsindexinput/12745)

<div class="topic-metadata">

**Author:** [@Andrew\_Stangl](https://discuss.elastic.co/u/Andrew_Stangl)\
**Replies:** 16\
**Last updated:** [July 14, 2013, 9:52am UTC](https://discuss.elastic.co/t/failed-to-merge-java-io-eofexception-read-past-eof-niofsindexinput/12745 "2013-07-14T09:52:43Z")

</div>

Hi all, I hope someone will be able to shed some light on this issue: we're experiencing a problem affecting a single server elasticsearch server which is being used to store and index tomcat and syslog data pushe…

---

## [Hosts tab in SIEM and WEF](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162)

<div class="topic-metadata">

**Author:** [@smerzlyakov](https://discuss.elastic.co/u/smerzlyakov)\
**Replies:** 16\
**Last updated:** [September 16, 2019, 2:25pm UTC](https://discuss.elastic.co/t/hosts-tab-in-siem-and-wef/190162 "2019-09-16T14:25:58Z")

</div>

There is Hosts tab in SIEM. I think nobody in Enterprise uses Winlogbeat on every Windows hosts. It is standard to use collector for logs and send Logs using Windows Event Forwarding on it. So, in field Host it will be n…

---

## [FIlebeat-Redis-Logstash : Filebeat fast and Logstah slow, logstash threading?](https://discuss.elastic.co/t/filebeat-redis-logstash-filebeat-fast-and-logstah-slow-logstash-threading/71052)

<div class="topic-metadata">

**Author:** [@nixmind](https://discuss.elastic.co/u/nixmind)\
**Replies:** 18\
**Last updated:** [January 13, 2017, 9:38am UTC](https://discuss.elastic.co/t/filebeat-redis-logstash-filebeat-fast-and-logstah-slow-logstash-threading/71052 "2017-01-13T09:38:03Z")

</div>

Hi all, I'm facing a latency issue with logstash. In fact I have an ELK stack built like this : I have several web front on AWS EC2 in an AWS autoscaling group I have filebeat installed on each front filebeat read…

---

## [Windows nxlog filtering](https://discuss.elastic.co/t/windows-nxlog-filtering/40061)

<div class="topic-metadata">

**Author:** [@jnpetty](https://discuss.elastic.co/u/jnpetty)\
**Replies:** 12\
**Last updated:** [January 27, 2016, 7:13am UTC](https://discuss.elastic.co/t/windows-nxlog-filtering/40061 "2016-01-27T07:13:18Z")

</div>

So now that I am receiving logs from my Windows server with NXLOG I an having trouble filtering it and making it useful. Most of the configurations below is from this example. https://gist.github.com/stuart-warren/672608…

---

## [Metricbeat - Capable of following?](https://discuss.elastic.co/t/metricbeat-capable-of-following/68776)

<div class="topic-metadata">

**Author:** [@rherr63](https://discuss.elastic.co/u/rherr63)\
**Replies:** 26\
**Last updated:** [February 24, 2017, 12:20pm UTC](https://discuss.elastic.co/t/metricbeat-capable-of-following/68776 "2017-02-24T12:20:26Z")

</div>

I would appreciate if someone could answer the following regarding MetricBeats =\> 1.) Does MetricBeat support secure data transmission? 2.) Regarding stability, is there any built-in agent fail-over? 3.) Is there a known…

---

## [Can anyone help on nested json parsing with Logstash?](https://discuss.elastic.co/t/can-anyone-help-on-nested-json-parsing-with-logstash/287661)

<div class="topic-metadata">

**Author:** [@dudwell](https://discuss.elastic.co/u/dudwell)\
**Replies:** 10\
**Last updated:** [October 28, 2021, 5:08pm UTC](https://discuss.elastic.co/t/can-anyone-help-on-nested-json-parsing-with-logstash/287661 "2021-10-28T17:08:31Z")

</div>

I am currently looking to parse some json records on logstash to then push to opensearch/kibana for analysis. Specifically I hope to pull the "rtt" and associated "instance" value metric from each message body so I can r…

---

## [Elasticsearch Cluster issues](https://discuss.elastic.co/t/elasticsearch-cluster-issues/178319)

<div class="topic-metadata">

**Author:** [@jbenner](https://discuss.elastic.co/u/jbenner)\
**Replies:** 16\
**Last updated:** [April 25, 2019, 3:18pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-issues/178319 "2019-04-25T15:18:03Z")

</div>

Hello, I am trying to build an elasticsearch cluster and keep running into an issue. I have the following: 5 physical nodes, centos 7 installed and trying to run dedicated master/data nodes. ElasticSearch 6.6.2 I hav…

---

## [Seems like elasticsearch is not reading my yml file](https://discuss.elastic.co/t/seems-like-elasticsearch-is-not-reading-my-yml-file/38122)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 19\
**Last updated:** [December 29, 2015, 9:45pm UTC](https://discuss.elastic.co/t/seems-like-elasticsearch-is-not-reading-my-yml-file/38122 "2015-12-29T21:45:47Z")

</div>

I am currently trying to set up two different elasticsearch nodes. I have the cluster label the same in both of the yml but node.name different. When i look at marvel it doesn't show any of these name. When I try " curl …

---

## [Disabling Default Analyzer for Most Fields](https://discuss.elastic.co/t/disabling-default-analyzer-for-most-fields/7707)

<div class="topic-metadata">

**Author:** [@dkullmann](https://discuss.elastic.co/u/dkullmann)\
**Replies:** 12\
**Last updated:** [June 21, 2012, 7:28am UTC](https://discuss.elastic.co/t/disabling-default-analyzer-for-most-fields/7707 "2012-06-21T07:28:37Z")

</div>

Hello, I want to disable the default analyzer for most of the fields in my document. The document represents a piece of real estate and most of the fields are integers or are keywords like you would find in a sele…

---

## [Logstash Lumberjack Cert](https://discuss.elastic.co/t/logstash-lumberjack-cert/174885)

<div class="topic-metadata">

**Author:** [@kharvey](https://discuss.elastic.co/u/kharvey)\
**Replies:** 9\
**Last updated:** [April 26, 2019, 9:58pm UTC](https://discuss.elastic.co/t/logstash-lumberjack-cert/174885 "2019-04-26T21:58:36Z")

</div>

I have a pipeline that is designed like: Filebeat -\> Logstash A -\> Logstash B -\> Elastic Search It took me a while but I figured out how to get communication up and running between Logstash A and Logstash B. But now I …

---

## [Any suggestion way of doing soft delete in ES](https://discuss.elastic.co/t/any-suggestion-way-of-doing-soft-delete-in-es/139455)

<div class="topic-metadata">

**Author:** [@Lan\_Qi](https://discuss.elastic.co/u/Lan_Qi)\
**Replies:** 12\
**Last updated:** [July 13, 2018, 5:51am UTC](https://discuss.elastic.co/t/any-suggestion-way-of-doing-soft-delete-in-es/139455 "2018-07-13T05:51:01Z")

</div>

Hi, I would like to know if there is some official way of doing soft delete in ES? Thank you

---

## [Shield.transport.ssl failure](https://discuss.elastic.co/t/shield-transport-ssl-failure/45153)

<div class="topic-metadata">

**Author:** [@bblank](https://discuss.elastic.co/u/bblank)\
**Replies:** 17\
**Last updated:** [March 28, 2016, 4:42pm UTC](https://discuss.elastic.co/t/shield-transport-ssl-failure/45153 "2016-03-28T16:42:42Z")

</div>

When attempting to enable ssl on the transport, we are getting the following error in the log file (pointing to an untrusted certificate authority) and the nodes will not communicate with one another. \[2016-03-22 10:48…

---

## [Login expiration Issue (Kibana 5.2)](https://discuss.elastic.co/t/login-expiration-issue-kibana-5-2/74135)

<div class="topic-metadata">

**Author:** [@111148](https://discuss.elastic.co/u/111148)\
**Replies:** 20\
**Last updated:** [February 17, 2017, 5:20pm UTC](https://discuss.elastic.co/t/login-expiration-issue-kibana-5-2/74135 "2017-02-17T17:20:26Z")

</div>

Hello, i have ELK cluster on Azure. (3 Windows server nodes) and recently I have updated all ELK stack to the 5.2 version. But now i am facing with login issue when more than one node is up and i see "session expired err…

---

## [What are the steps to install elasticsearch plugin in Windows environment?](https://discuss.elastic.co/t/what-are-the-steps-to-install-elasticsearch-plugin-in-windows-environment/14226)

<div class="topic-metadata">

**Author:** [@Stephanie\_Lew](https://discuss.elastic.co/u/Stephanie_Lew)\
**Replies:** 20\
**Last updated:** [March 19, 2014, 6:47pm UTC](https://discuss.elastic.co/t/what-are-the-steps-to-install-elasticsearch-plugin-in-windows-environment/14226 "2014-03-19T18:47:50Z")

</div>

Dear all, What are the steps to install ES plugins like ElasticSearch Head and Inquistor on a Windows 64-bit environment? I have downloaded the zip file, from https://github.com/polyfractal/elasticsearch-inquis…

---

## [Fleet not working anymore \[Unable to initialize Fleet\]](https://discuss.elastic.co/t/fleet-not-working-anymore-unable-to-initialize-fleet/258890)

<div class="topic-metadata">

**Author:** [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Replies:** 14\
**Last updated:** [December 18, 2020, 7:59am UTC](https://discuss.elastic.co/t/fleet-not-working-anymore-unable-to-initialize-fleet/258890 "2020-12-18T07:59:10Z")

</div>

Hello, I am trying elastic Endpoint under elastic and kibana version 8.0.0 (from source), and since few days I am geeting this error in my logs when I click on the Fleet on Kibana 404 Not Found' error response from pac…

---

## [Not able to parse custom logs having multi line xml](https://discuss.elastic.co/t/not-able-to-parse-custom-logs-having-multi-line-xml/107743)

<div class="topic-metadata">

**Author:** [@Husain\_Khan](https://discuss.elastic.co/u/Husain_Khan)\
**Replies:** 14\
**Last updated:** [November 24, 2017, 12:39pm UTC](https://discuss.elastic.co/t/not-able-to-parse-custom-logs-having-multi-line-xml/107743 "2017-11-24T12:39:53Z")

</div>

I have following log file, 5d563f04-b5d8-4b8d-b3ac-df26028c3719 SoapRequest CheckUserPassword \<properties\> \<hostname\>crt-mon\</hostname\> \<date\>2016.11.01\</date\> \<time\>01:23:04 CET\</time\> \<release\>11.6\</release\> \<version\>…

---

## [Errors after Elastic 6](https://discuss.elastic.co/t/errors-after-elastic-6/107776)

<div class="topic-metadata">

**Author:** [@ocabj](https://discuss.elastic.co/u/ocabj)\
**Replies:** 13\
**Last updated:** [December 14, 2017, 4:03pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776 "2017-12-14T16:03:39Z")

</div>

I did an upgrade on my personal ELK stack to 6 yesterday and everything was fine until 1600PST / 0000 UTC. \[2017-11-14T16:00:05,887\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch. {:statu…

---

## [How to add created\_at and updated\_at fields](https://discuss.elastic.co/t/how-to-add-created-at-and-updated-at-fields/355178)

<div class="topic-metadata">

**Author:** [@Marco\_Solari](https://discuss.elastic.co/u/Marco_Solari)\
**Replies:** 18\
**Last updated:** [March 12, 2024, 7:46pm UTC](https://discuss.elastic.co/t/how-to-add-created-at-and-updated-at-fields/355178 "2024-03-12T19:46:20Z")

</div>

Hi. I'm quite new to Elasticsearch. I'm using the python client (v8.12.0). I'd like to add to my index the timestamp fields created\_at and updated\_at for every document. Reading various docs I think I have to use Ing…

---

## [Improving Bulk Indexing](https://discuss.elastic.co/t/improving-bulk-indexing/15549)

<div class="topic-metadata">

**Author:** [@IronMike](https://discuss.elastic.co/u/IronMike)\
**Replies:** 11\
**Last updated:** [February 5, 2014, 12:15am UTC](https://discuss.elastic.co/t/improving-bulk-indexing/15549 "2014-02-05T00:15:49Z")

</div>

I would appreciate if I can get some tips and others perspective on bulk indexing since I am new to this. The end goal is to index 10 to 20 million document. So, I started working on my local machine with a sample…

---

## [Logstash 5.1.2 starting with errors](https://discuss.elastic.co/t/logstash-5-1-2-starting-with-errors/72188)

<div class="topic-metadata">

**Author:** [@kodo83](https://discuss.elastic.co/u/kodo83)\
**Replies:** 9\
**Last updated:** [January 24, 2017, 10:49am UTC](https://discuss.elastic.co/t/logstash-5-1-2-starting-with-errors/72188 "2017-01-24T10:49:16Z")

</div>

Hi, I'm new in logstash and elasticsearch. i want to index mysql database to elasticsearch using logstash. i downloded the last versions 5.1.2 (of logstash and elasticsearch). elasticsearch start without problems. for lo…

---

## [Delete Index after x amount of days](https://discuss.elastic.co/t/delete-index-after-x-amount-of-days/246492)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 10\
**Last updated:** [August 27, 2020, 1:49am UTC](https://discuss.elastic.co/t/delete-index-after-x-amount-of-days/246492 "2020-08-27T01:49:48Z")

</div>

Currently reading logs from Logstash to Elasticsearch and creating daily indexes. Is there a way to delete each of these indexes after an X amount of days? Also, is there an auto delete feature when my elasticsearch clu…

---

## [Data node high CPU](https://discuss.elastic.co/t/data-node-high-cpu/117014)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 18\
**Last updated:** [January 29, 2018, 5:46pm UTC](https://discuss.elastic.co/t/data-node-high-cpu/117014 "2018-01-29T17:46:18Z")

</div>

Hi Guys (@Christian\_Dahlqvist / @Igor\_Motov), Setup: Elasticsearch 1.4.7 (legacy) 3 master nodes - 2GB RAM, 1vCPUs. 4 data nodes - 30GB RAM, 8 vCPUs, EBS 500GB SSD two different availability zones. 2 client nodes - …

---

## [Kibana search 7 days throws error](https://discuss.elastic.co/t/kibana-search-7-days-throws-error/25864)

<div class="topic-metadata">

**Author:** [@allenmchan](https://discuss.elastic.co/u/allenmchan)\
**Replies:** 15\
**Last updated:** [July 27, 2015, 12:38am UTC](https://discuss.elastic.co/t/kibana-search-7-days-throws-error/25864 "2015-07-27T00:38:23Z")

</div>

Hi i am getting this error (Discover throws error: "An error occured with your request. Reset your inputs and try again") in kibana when i try to do a search of time length 7 days or longer. I modified the request\_time…

---

## [How to use ELK to extract data from specific dates from Date field in csv](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623)

<div class="topic-metadata">

**Author:** [@poornima](https://discuss.elastic.co/u/poornima)\
**Replies:** 12\
**Last updated:** [February 17, 2016, 2:42am UTC](https://discuss.elastic.co/t/how-to-use-elk-to-extract-data-from-specific-dates-from-date-field-in-csv/41623 "2016-02-17T02:42:08Z")

</div>

Hi all, Need help in creating dashboard for defects. I need to extract data based on date field column in a csv file and plot graphs based on it. I want X axis to be based on specific date range field from the csv fil…

---

## [2.0rc-1 can't install Marvel](https://discuss.elastic.co/t/2-0rc-1-cant-install-marvel/32305)

<div class="topic-metadata">

**Author:** [@mos](https://discuss.elastic.co/u/mos)\
**Replies:** 11\
**Last updated:** [August 29, 2016, 8:43pm UTC](https://discuss.elastic.co/t/2-0rc-1-cant-install-marvel/32305 "2016-08-29T20:43:48Z")

</div>

Isn't Marvel available for the Release Candidate? We like to use and test the 2.0 Release Candidate, but without Marvel we will wait ... \> plugin install elasticsearch/marvel/latest -v -\> Installing elasticsearch/marve…

---

## [High CPU usage logstash](https://discuss.elastic.co/t/high-cpu-usage-logstash/315468)

<div class="topic-metadata">

**Author:** [@Cheroufa](https://discuss.elastic.co/u/Cheroufa)\
**Replies:** 10\
**Last updated:** [September 30, 2022, 3:27pm UTC](https://discuss.elastic.co/t/high-cpu-usage-logstash/315468 "2022-09-30T15:27:06Z")

</div>

Hi all, Whene i start logstash CPU usage jump to 99%, 100% and the logstash status is running but realy not started and no logs written can someone please help me to resolve this issue ? thank you.

---

## [Please help. I'm not getting how to input IIS logs](https://discuss.elastic.co/t/please-help-im-not-getting-how-to-input-iis-logs/56197)

<div class="topic-metadata">

**Author:** [@George\_Nussbaum](https://discuss.elastic.co/u/George_Nussbaum)\
**Replies:** 9\
**Last updated:** [July 27, 2016, 5:59pm UTC](https://discuss.elastic.co/t/please-help-im-not-getting-how-to-input-iis-logs/56197 "2016-07-27T17:59:25Z")

</div>

Hello, I installed ELK a couple weeks ago and I'm pulling what I have left of my haIr out. I'm having trouble with getting IIS log data to show up. I have filebeat installed on the clients and am using IIS Advanced l…

---

## [Return (emit) @timestamp date value in runtime field](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001)

<div class="topic-metadata">

**Author:** [@nilei](https://discuss.elastic.co/u/nilei)\
**Replies:** 15\
**Last updated:** [July 31, 2022, 11:59am UTC](https://discuss.elastic.co/t/return-emit-timestamp-date-value-in-runtime-field/311001 "2022-07-31T11:59:12Z")

</div>

Dear all, I am trying to output the value of @timestamp in a runtime field (configured in Kibana 7.13.3). My goal is then to get only the month as display value with a modified format 'MMM'. Unfortunately, I have been u…

---

## [Kibana, Discover: Field data loading is forbidden on srcip](https://discuss.elastic.co/t/kibana-discover-field-data-loading-is-forbidden-on-srcip/41426)

<div class="topic-metadata">

**Author:** [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Replies:** 19\
**Last updated:** [February 18, 2016, 8:46pm UTC](https://discuss.elastic.co/t/kibana-discover-field-data-loading-is-forbidden-on-srcip/41426 "2016-02-18T20:46:46Z")

</div>

not needed anymore. Ive come to understand it is "by design" whatever it means.. I could work around using "field".raw in any case.. im still trying to figure how to "field format" thing, lets say for exemple : sent …

---

## [I can't find anything after hypens or underscores](https://discuss.elastic.co/t/i-cant-find-anything-after-hypens-or-underscores/20705)

<div class="topic-metadata">

**Author:** [@bnf\_lsn](https://discuss.elastic.co/u/bnf_lsn)\
**Replies:** 9\
**Last updated:** [January 30, 2015, 11:00am UTC](https://discuss.elastic.co/t/i-cant-find-anything-after-hypens-or-underscores/20705 "2015-01-30T11:00:54Z")

</div>

Hi, I'm very newbie on ElasticSearch. I'm try to indexing a set of biological data. There are some fields like 'gene\_id' or 'gene\_shortname' that should be processed as literal strings. When I try to search for 'ZNF…

---

## [Cluster Setup 3 Node Cluster problem](https://discuss.elastic.co/t/cluster-setup-3-node-cluster-problem/188526)

<div class="topic-metadata">

**Author:** [@thev0yager](https://discuss.elastic.co/u/thev0yager)\
**Replies:** 47\
**Last updated:** [July 15, 2019, 3:41pm UTC](https://discuss.elastic.co/t/cluster-setup-3-node-cluster-problem/188526 "2019-07-15T15:41:46Z")

</div>

Hi all, I have been working on getting a Elastic Stack cluster working for the past few weeks. I was told to setup the elasticsearch cluster as such. I have three nodes each one of these nodes has a elasticsearch, kibana…

---

## [ES - Debian 8 - PB - port 9200](https://discuss.elastic.co/t/es-debian-8-pb-port-9200/44654)

<div class="topic-metadata">

**Author:** [@Fnizou](https://discuss.elastic.co/u/Fnizou)\
**Replies:** 13\
**Last updated:** [March 18, 2016, 12:12pm UTC](https://discuss.elastic.co/t/es-debian-8-pb-port-9200/44654 "2016-03-18T12:12:19Z")

</div>

Bonjour, Voila 3 jours que je bataille, j'ai installé ES sur Debian 8 tout semble ok , dans /etc/elasticsearch/elasticsearch.yml j'ai bien mis network.host: localhost et dès que je test : curl -X GET 'http://localh…

---

## [How to pass array field to kv-filter](https://discuss.elastic.co/t/how-to-pass-array-field-to-kv-filter/34496)

<div class="topic-metadata">

**Author:** [@mne](https://discuss.elastic.co/u/mne)\
**Replies:** 14\
**Last updated:** [November 17, 2015, 8:24am UTC](https://discuss.elastic.co/t/how-to-pass-array-field-to-kv-filter/34496 "2015-11-17T08:24:26Z")

</div>

Hi all, i'm looking for a way within logstash to pass an array to the kv-filter and use it as parameter "include\_fields". For example in my json event i have an array named "keys": "keys" =\> \[ \[0\] "key1", …

---

## [How to check some condition through all docs in aggregation](https://discuss.elastic.co/t/how-to-check-some-condition-through-all-docs-in-aggregation/139150)

<div class="topic-metadata">

**Author:** [@\_Sergey](https://discuss.elastic.co/u/_Sergey)\
**Replies:** 15\
**Last updated:** [July 25, 2018, 8:52am UTC](https://discuss.elastic.co/t/how-to-check-some-condition-through-all-docs-in-aggregation/139150 "2018-07-25T08:52:54Z")

</div>

Hey ES community! I have a query: (the part of code is below...btw script was taken from visualization in kibana request) "aggs": { "uuid": { "terms": { "field": "device\_uuid", "size":…

---

## [Hyphen search](https://discuss.elastic.co/t/hyphen-search/8478)

<div class="topic-metadata">

**Author:** [@such\_mensch](https://discuss.elastic.co/u/such_mensch)\
**Replies:** 10\
**Last updated:** [July 25, 2012, 9:11am UTC](https://discuss.elastic.co/t/hyphen-search/8478 "2012-07-25T09:11:26Z")

</div>

What kind of tokenizers are the best for search for words with hyphens in them?? Example: a search for "test" between following phrases {"test", "test-2", "3-test"} should return all 3 and not just "test".

---

## [7.15.2 is also very slow](https://discuss.elastic.co/t/7-15-2-is-also-very-slow/290596)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 17\
**Last updated:** [December 23, 2021, 7:23am UTC](https://discuss.elastic.co/t/7-15-2-is-also-very-slow/290596 "2021-12-23T07:23:37Z")

</div>

following thread is close hence open new one. https://discuss.elastic.co/t/7-15-1-is-extremely-slow/287617/10 I show 7.15.2 is out hence decided to test in this setup I have Elasticsearch -\> 7.15.1 and kibane 7.15.2. …

---

## ["\[pipeline\] required property is missing"](https://discuss.elastic.co/t/pipeline-required-property-is-missing/115569)

<div class="topic-metadata">

**Author:** [@tkzv](https://discuss.elastic.co/u/tkzv)\
**Replies:** 12\
**Last updated:** [January 23, 2018, 10:18am UTC](https://discuss.elastic.co/t/pipeline-required-property-is-missing/115569 "2018-01-23T10:18:45Z")

</div>

I need to monitor exchange between 2 servers. I'm trying to use Packetbeat + Elasticsearch for that (without ). I keep getting warnings in the log: client.go:465: WARN Can not index event (status=400): {"type":"mapper\_…

[Previous page](https://discuss.elastic.co/top.md?page=56&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=58&per_page=50&period=all)
