# Top

**URL:** https://discuss.elastic.co/top.md?page=59&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 60

---

## [How to convert src\_ip to ip](https://discuss.elastic.co/t/how-to-convert-src-ip-to-ip/113557)

<div class="topic-metadata">

**Author:** [@Mario\_van\_Gemert](https://discuss.elastic.co/u/Mario_van_Gemert)\
**Replies:** 11\
**Last updated:** [December 29, 2017, 12:21pm UTC](https://discuss.elastic.co/t/how-to-convert-src-ip-to-ip/113557 "2017-12-29T12:21:55Z")

</div>

Just succesfull read my Cisco ASA logs, but I am now looking for a way to convert my src\_ip (string) in a way that I am able to use it as a geo\_point on the Coordinate Map. Can anyone tell me how my filter section should…

---

## [Elasticsearch: changing thread\_pool.search.max\_queue\_size on a high load cluster](https://discuss.elastic.co/t/elasticsearch-changing-thread-pool-search-max-queue-size-on-a-high-load-cluster/272980)

<div class="topic-metadata">

**Author:** [@cesar.hernandez.a3se](https://discuss.elastic.co/u/cesar.hernandez.a3se)\
**Replies:** 9\
**Last updated:** [May 14, 2021, 10:51am UTC](https://discuss.elastic.co/t/elasticsearch-changing-thread-pool-search-max-queue-size-on-a-high-load-cluster/272980 "2021-05-14T10:51:57Z")

</div>

Hi We have a elasticsearch cluster (version 7.8.1) using 7 nodes, every node with 96 cpu core and 192 GB RAM. During a stress test process, using locust software and simulating 1150 concurrent users, every one run a \_s…

---

## [Elastic Search Killed on start up!](https://discuss.elastic.co/t/elastic-search-killed-on-start-up/245162)

<div class="topic-metadata">

**Author:** [@carterdacat](https://discuss.elastic.co/u/carterdacat)\
**Replies:** 23\
**Last updated:** [August 17, 2020, 2:53am UTC](https://discuss.elastic.co/t/elastic-search-killed-on-start-up/245162 "2020-08-17T02:53:47Z")

</div>

Hi! I just installed elastic on my pi running ubuntu 20.06, i got v5.6, and when ever i run ./bin/elasticsearch it just returns "killed" ubuntu@ubuntu:~/elasticsearch-5.6.16$ sudo ES\_JAVA\_OPTS="-Xms2g -Xmx2g" ./bin/elas…

---

## [Duplicate Winlogbeat Events - (Logstash publishing events twice)](https://discuss.elastic.co/t/duplicate-winlogbeat-events-logstash-publishing-events-twice/49271)

<div class="topic-metadata">

**Author:** [@Alexey\_Khudyakov](https://discuss.elastic.co/u/Alexey_Khudyakov)\
**Replies:** 14\
**Last updated:** [May 10, 2016, 6:36am UTC](https://discuss.elastic.co/t/duplicate-winlogbeat-events-logstash-publishing-events-twice/49271 "2016-05-10T06:36:17Z")

</div>

Dear Community, I'm evaluating Winlogbeat-5.0.0 alpha 1 and noticed that all events shipped to elasticsearch were duplicated. This issue appears on all events shipped from my Windows servers. I don't know if it bug of …

---

## [Problem with JSON file import into ElasticSearch](https://discuss.elastic.co/t/problem-with-json-file-import-into-elasticsearch/240871)

<div class="topic-metadata">

**Author:** [@siva4](https://discuss.elastic.co/u/siva4)\
**Replies:** 9\
**Last updated:** [July 17, 2020, 6:35am UTC](https://discuss.elastic.co/t/problem-with-json-file-import-into-elasticsearch/240871 "2020-07-17T06:35:59Z")

</div>

Exported data from Mongo and generated JSON file. Sample JSON File data (1 record): { "\_id": { "$oid": "5d84438f4514cb1f8a" }, "slug": "test-home-technology", "title": "test home technology", "subtitle": …

---

## [File paths must be absolute, relative path specified](https://discuss.elastic.co/t/file-paths-must-be-absolute-relative-path-specified/260016)

<div class="topic-metadata">

**Author:** [@Cyphy](https://discuss.elastic.co/u/Cyphy)\
**Replies:** 9\
**Last updated:** [January 5, 2021, 4:09am UTC](https://discuss.elastic.co/t/file-paths-must-be-absolute-relative-path-specified/260016 "2021-01-05T04:09:27Z")

</div>

hey there, hope you can help me :slight\_smile: I started my ELK setup with docker-compose a few days ago. It looked fine as all 3 containers where running without any data. Today i wanted to import some xml files with …

---

## [Cannot Monitor Logstash](https://discuss.elastic.co/t/cannot-monitor-logstash/81957)

<div class="topic-metadata">

**Author:** [@arianayay](https://discuss.elastic.co/u/arianayay)\
**Replies:** 13\
**Last updated:** [April 12, 2017, 8:16am UTC](https://discuss.elastic.co/t/cannot-monitor-logstash/81957 "2017-04-12T08:16:35Z")

</div>

Hi, Logstash is not showing in the Monitor Tab of Kibana. Only Elasicsearch and Kibana is showing. I have configured mypipeline.conf input { stdin { }} output { elasticsearch { hosts =\> \["CTLSQL12WPPOC:9200"\] } …

---

## [Using Java TransportClient for access to AWS ElasticSearch instance](https://discuss.elastic.co/t/using-java-transportclient-for-access-to-aws-elasticsearch-instance/93941)

<div class="topic-metadata">

**Author:** [@Josca](https://discuss.elastic.co/u/Josca)\
**Replies:** 10\
**Last updated:** [July 25, 2017, 3:32pm UTC](https://discuss.elastic.co/t/using-java-transportclient-for-access-to-aws-elasticsearch-instance/93941 "2017-07-25T15:32:01Z")

</div>

Hi, Is it possible to use Java TransportClient when using AWS ElasticSearch instance and access token? Where can I find documentation for that, please? Thanks for any advice.

---

## [How to reindex ElasticSearch quickly?](https://discuss.elastic.co/t/how-to-reindex-elasticsearch-quickly/12335)

<div class="topic-metadata">

**Author:** [@Dmitry\_Babitsky](https://discuss.elastic.co/u/Dmitry_Babitsky)\
**Replies:** 13\
**Last updated:** [June 20, 2013, 9:04am UTC](https://discuss.elastic.co/t/how-to-reindex-elasticsearch-quickly/12335 "2013-06-20T09:04:59Z")

</div>

I have an ElasticSearch index with around 200M documents, total index size of 90Gb. I changed mapping, so I would like ElasticSearch to re-index all the documents. I wrote a script that creates a new index (wit…

---

## [Claculation of Transactions per minute / Request per minute](https://discuss.elastic.co/t/claculation-of-transactions-per-minute-request-per-minute/178958)

<div class="topic-metadata">

**Author:** [@suikast42](https://discuss.elastic.co/u/suikast42)\
**Replies:** 10\
**Last updated:** [May 2, 2019, 9:12am UTC](https://discuss.elastic.co/t/claculation-of-transactions-per-minute-request-per-minute/178958 "2019-05-02T09:12:06Z")

</div>

Hi, how calculates the kibana apm ui the metrics for transaction or request per minute. For example. I have custom span test with the java agent. It writes one transaction per minute. The "transaction per minute" ini…

---

## [Cluster turns to red after reboot](https://discuss.elastic.co/t/cluster-turns-to-red-after-reboot/158298)

<div class="topic-metadata">

**Author:** [@Yogesh\_BG](https://discuss.elastic.co/u/Yogesh_BG)\
**Replies:** 28\
**Last updated:** [December 7, 2018, 6:57am UTC](https://discuss.elastic.co/t/cluster-turns-to-red-after-reboot/158298 "2018-12-07T06:57:53Z")

</div>

Hi I have a ES two node setup as below \[root@metrics-datastore-0 esutilities\]# sh check\_cluster.sh { "cluster\_name" : "metrics-datastore", "status" : "red", "timed\_out" : false, "number\_of\_nodes" : 2, "number\_of\_…

---

## [Node shutdown due to OutOfMemoryError: Direct buffer memory](https://discuss.elastic.co/t/node-shutdown-due-to-outofmemoryerror-direct-buffer-memory/205994)

<div class="topic-metadata">

**Author:** [@Odd\_Erik\_Gronberg](https://discuss.elastic.co/u/Odd_Erik_Gronberg)\
**Replies:** 17\
**Last updated:** [November 1, 2019, 8:11am UTC](https://discuss.elastic.co/t/node-shutdown-due-to-outofmemoryerror-direct-buffer-memory/205994 "2019-11-01T08:11:52Z")

</div>

Hi, We are running a 5 node cluster with 3 data nodes (where 1 is master eligible) and 2 master (non-data eligible nodes) as windows services. Each of the data node has 6 GB allocated heap memory and runs on machines w…

---

## [GC Settings for Elasticsearch](https://discuss.elastic.co/t/gc-settings-for-elasticsearch/24521)

<div class="topic-metadata">

**Author:** [@Michael\_\_Rennecke](https://discuss.elastic.co/u/Michael__Rennecke)\
**Replies:** 9\
**Last updated:** [June 30, 2015, 8:21am UTC](https://discuss.elastic.co/t/gc-settings-for-elasticsearch/24521 "2015-06-30T08:21:02Z")

</div>

Hello, my chief architect means G1GC is awesome and works better then default GC. He mentioned, https://www.elastic.co/guide/en/elasticsearch/guide/current/\_don\_8217\_t\_touch\_these\_settings.html is outdated. We run Elas…

---

## [Logstash grok pattern failed check config](https://discuss.elastic.co/t/logstash-grok-pattern-failed-check-config/189939)

<div class="topic-metadata">

**Author:** [@Dave\_Hafid](https://discuss.elastic.co/u/Dave_Hafid)\
**Replies:** 22\
**Last updated:** [August 5, 2019, 11:29am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-failed-check-config/189939 "2019-08-05T11:29:14Z")

</div>

Dear ALL, i try to create ssh grok pattern this is my pattern input { beats { port =\> 5044 host =\> "192.168.11.13" } } # Capture\_all\_MSG filter { if \[fileset\]\[name\] == "auth" { grok { match =\> { "message" =\>…

---

## [Metricbeat on FreeBSD using a lot of resources](https://discuss.elastic.co/t/metricbeat-on-freebsd-using-a-lot-of-resources/55412)

<div class="topic-metadata">

**Author:** [@michbsd](https://discuss.elastic.co/u/michbsd)\
**Replies:** 20\
**Last updated:** [August 2, 2016, 2:34pm UTC](https://discuss.elastic.co/t/metricbeat-on-freebsd-using-a-lot-of-resources/55412 "2016-08-02T14:34:16Z")

</div>

Hi, I am running Metricbeat on FreeBSD. ❯ ./metricbeat -version \[3:42:34 PM\] metricbeat version 5.0.0-alpha4 (amd64), libbeat 5.0.0-alpha4 It seems to use a whole lot…

---

## [How to keep EnterpriseSearch running all the time](https://discuss.elastic.co/t/how-to-keep-enterprisesearch-running-all-the-time/274448)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 24\
**Last updated:** [February 15, 2022, 1:25pm UTC](https://discuss.elastic.co/t/how-to-keep-enterprisesearch-running-all-the-time/274448 "2022-02-15T13:25:24Z")

</div>

I have an SSL connection to the server where EnterpriseSearch is set up, and start EnterpriseSearch from the command line with the following command. $ ENT\_SEARCH\_DEFAULT\_PASSWORD=\[REDACTED\] bin/enterprise-search After…

---

## [I've sensor that sends X Y coordinates for an Indoor Map I want to Convert X-Y to correspondent geolocation and Plot Coordinates into a Custom Map](https://discuss.elastic.co/t/ive-sensor-that-sends-x-y-coordinates-for-an-indoor-map-i-want-to-convert-x-y-to-correspondent-geolocation-and-plot-coordinates-into-a-custom-map/92622)

<div class="topic-metadata">

**Author:** [@Alex\_S](https://discuss.elastic.co/u/Alex_S)\
**Replies:** 22\
**Last updated:** [July 24, 2017, 4:20pm UTC](https://discuss.elastic.co/t/ive-sensor-that-sends-x-y-coordinates-for-an-indoor-map-i-want-to-convert-x-y-to-correspondent-geolocation-and-plot-coordinates-into-a-custom-map/92622 "2017-07-24T16:20:39Z")

</div>

Hello Geeks , I've sensors that send X Y coordinates for an Indoor Map , I have successfully managed to Build a custom map on kibana using GeoServer , But I'm stuck with the following for more than a month now. 1-…

---

## [Filebeat config for files that are never updated with new logs](https://discuss.elastic.co/t/filebeat-config-for-files-that-are-never-updated-with-new-logs/69197)

<div class="topic-metadata">

**Author:** [@Airn5475](https://discuss.elastic.co/u/Airn5475)\
**Replies:** 15\
**Last updated:** [December 20, 2016, 9:32am UTC](https://discuss.elastic.co/t/filebeat-config-for-files-that-are-never-updated-with-new-logs/69197 "2016-12-20T09:32:27Z")

</div>

I intend to drop .json files into a directory that Filebeat is monitoring (they eventually end up in Elasticsearch) The goal is to hit the data source for the latest changes every 15 minutes and output to a .json file. …

---

## [Logstash/Elasticsearch 5.x Errors](https://discuss.elastic.co/t/logstash-elasticsearch-5-x-errors/71781)

<div class="topic-metadata">

**Author:** [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Replies:** 20\
**Last updated:** [January 20, 2017, 1:22am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-5-x-errors/71781 "2017-01-20T01:22:10Z")

</div>

Forgive me, for I am a n00b when I comes to Unix or even Logstash/Elasticsearch. I had several localized clusters online for almost a year when I began upgrading them to 5.x. My environment is such that, each location o…

---

## [Kibana unable to connect to package registry after upgrade to 8.8.1](https://discuss.elastic.co/t/kibana-unable-to-connect-to-package-registry-after-upgrade-to-8-8-1/336317)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 16\
**Last updated:** [June 26, 2023, 8:44am UTC](https://discuss.elastic.co/t/kibana-unable-to-connect-to-package-registry-after-upgrade-to-8-8-1/336317 "2023-06-26T08:44:26Z")

</div>

Hi all I have a problems with kibana after upgrading from version 8.5.2 to version 8.8.1 All thing work normally but the intergration keep giving me this error Kibana cannot connect to the Elastic Package Registry, wh…

---

## [Trying setting up ELK stack](https://discuss.elastic.co/t/trying-setting-up-elk-stack/26894)

<div class="topic-metadata">

**Author:** [@lukas\_meier](https://discuss.elastic.co/u/lukas_meier)\
**Replies:** 12\
**Last updated:** [August 11, 2015, 1:45pm UTC](https://discuss.elastic.co/t/trying-setting-up-elk-stack/26894 "2015-08-11T13:45:12Z")

</div>

hi im new to this, so many guides are available, but every single is special in part, i installed elasticsearch, logstash and the forwarder, then when i start logstash on the server, with simple direct output and saving …

---

## [Elastic-apm-agent jdbcHelper seems to use a lot of memory](https://discuss.elastic.co/t/elastic-apm-agent-jdbchelper-seems-to-use-a-lot-of-memory/195295)

<div class="topic-metadata">

**Author:** [@Paul\_Harris1](https://discuss.elastic.co/u/Paul_Harris1)\
**Replies:** 24\
**Last updated:** [August 25, 2019, 11:57pm UTC](https://discuss.elastic.co/t/elastic-apm-agent-jdbchelper-seems-to-use-a-lot-of-memory/195295 "2019-08-25T23:57:12Z")

</div>

Firstly, I'm not sure how i replicate this problem apologies in advance... Looking into memory usage on an app at the moment because it seems to be using a bunch more memory than it should be... Drilling in with the pr…

---

## [Adding a type field dynamically for logs](https://discuss.elastic.co/t/adding-a-type-field-dynamically-for-logs/73883)

<div class="topic-metadata">

**Author:** [@Maria\_Delarosa](https://discuss.elastic.co/u/Maria_Delarosa)\
**Replies:** 11\
**Last updated:** [February 10, 2017, 5:59pm UTC](https://discuss.elastic.co/t/adding-a-type-field-dynamically-for-logs/73883 "2017-02-10T17:59:43Z")

</div>

Logstash is gathering logs from multiple directories. Each directory represents logs from an specific application. I am using the type to indicate the type of logs. However, I have many applications and adding each one w…

---

## [How to combine all tokens into one?](https://discuss.elastic.co/t/how-to-combine-all-tokens-into-one/143158)

<div class="topic-metadata">

**Author:** [@zouxiang](https://discuss.elastic.co/u/zouxiang)\
**Replies:** 10\
**Last updated:** [August 6, 2018, 3:17pm UTC](https://discuss.elastic.co/t/how-to-combine-all-tokens-into-one/143158 "2018-08-06T15:17:46Z")

</div>

Hello, I'm trying to find a token filter that can combine all the tokens into one. For example: the text "bags and shoes" ==\> 3 tokens: "bags" "and" "shoes" (use StandardTokenizer) "bags" "and" "shoes" ==\> …

---

## [Mapping LDAP Groups to Roles](https://discuss.elastic.co/t/mapping-ldap-groups-to-roles/118073)

<div class="topic-metadata">

**Author:** [@jchannon](https://discuss.elastic.co/u/jchannon)\
**Replies:** 13\
**Last updated:** [February 12, 2018, 11:40am UTC](https://discuss.elastic.co/t/mapping-ldap-groups-to-roles/118073 "2018-02-12T11:40:55Z")

</div>

I have the below ldap config in elasticsearch.yml xpack: security: authc: realms: ldap1: type: ldap url: "ldap://ldap:389" bind\_dn: "cn=admin,dc=vqcomms" bind\_…

---

## [Strange behavior in PHP Elasticsearch 8.5 API](https://discuss.elastic.co/t/strange-behavior-in-php-elasticsearch-8-5-api/318622)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 9\
**Last updated:** [November 10, 2022, 4:57pm UTC](https://discuss.elastic.co/t/strange-behavior-in-php-elasticsearch-8-5-api/318622 "2022-11-10T16:57:47Z")

</div>

I feel totally lost. Having spent some time understanding that to connect to an Elasticsearch single-node, built with docker-compose, without security, I should use the configuration below, now I find that it doesn't wo…

---

## [Dealing with improperly formatted XML](https://discuss.elastic.co/t/dealing-with-improperly-formatted-xml/78638)

<div class="topic-metadata">

**Author:** [@Kvetch](https://discuss.elastic.co/u/Kvetch)\
**Replies:** 12\
**Last updated:** [April 3, 2017, 5:08am UTC](https://discuss.elastic.co/t/dealing-with-improperly-formatted-xml/78638 "2017-04-03T05:08:08Z")

</div>

I have an XML that isn't parsing correctly unless I use something like xmllint to prettify it. The XML file is written line by line but doesn't contain indentation and such and for whatever reason my logstash config doe…

---

## [Run query and recreate index every run](https://discuss.elastic.co/t/run-query-and-recreate-index-every-run/154679)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 20\
**Last updated:** [December 19, 2018, 8:06pm UTC](https://discuss.elastic.co/t/run-query-and-recreate-index-every-run/154679 "2018-12-19T20:06:46Z")

</div>

I have logstash config file and would like to run this everytime and recreate index everytime. that way it mimic live data basically when running job's status is completed it should drop from query and I don't want to s…

---

## [Filebeat doesn't show in kibana monitoring](https://discuss.elastic.co/t/filebeat-doesnt-show-in-kibana-monitoring/127474)

<div class="topic-metadata">

**Author:** [@roketyyang](https://discuss.elastic.co/u/roketyyang)\
**Replies:** 13\
**Last updated:** [April 13, 2018, 11:52am UTC](https://discuss.elastic.co/t/filebeat-doesnt-show-in-kibana-monitoring/127474 "2018-04-13T11:52:48Z")

</div>

I have two filebeat running. But I just can see one filebeat instance in kibana monitoring. Both filebeat are sending monitor metric: {"monitoring": {"metrics": {"beat":{"cpu":{"system":{"ticks":10,"time":17},"total"…

---

## [Grokparsefailure with a pattern verified by grok debug](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251)

<div class="topic-metadata">

**Author:** [@Mehdi\_Mouslih](https://discuss.elastic.co/u/Mehdi_Mouslih)\
**Replies:** 9\
**Last updated:** [August 25, 2017, 10:02am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251 "2017-08-25T10:02:44Z")

</div>

Hello i am using logstash to collect cisco logs like the following one :slight\_smile: 2017-08-23T11:03:43.068Z 192.168.1.254 \<189\>79: \*Mar 1 01:17:53.151: %SYS-5-CONFIG\_I: Configured from console by console this is my…

---

## [Unable to update/delete/execute watch](https://discuss.elastic.co/t/unable-to-update-delete-execute-watch/31514)

<div class="topic-metadata">

**Author:** [@peter.walsh82](https://discuss.elastic.co/u/peter.walsh82)\
**Replies:** 15\
**Last updated:** [December 14, 2015, 11:34pm UTC](https://discuss.elastic.co/t/unable-to-update-delete-execute-watch/31514 "2015-12-14T23:34:46Z")

</div>

After several successful executions, my watch became "stuck", in which it could no longer be executed, updated, or deleted. The error I get back contains the below: "TimeoutException\[could not delete watch \[wiresto…

---

## [Sorting based on event\_time in logstash](https://discuss.elastic.co/t/sorting-based-on-event-time-in-logstash/91636)

<div class="topic-metadata">

**Author:** [@blackOcean](https://discuss.elastic.co/u/blackOcean)\
**Replies:** 10\
**Last updated:** [July 4, 2017, 12:44pm UTC](https://discuss.elastic.co/t/sorting-based-on-event-time-in-logstash/91636 "2017-07-04T12:44:45Z")

</div>

Hi, Thanks for helping me in all the stuff. Now, I am facing a weird problem. These are my logs 2017-01-03 05:40:50.522 INFO main ---\> org.springframework.context.support.PostProcessorRegistrationDelegate$BeanPo…

---

## [Azure active directory integration with elasticsearch](https://discuss.elastic.co/t/azure-active-directory-integration-with-elasticsearch/204023)

<div class="topic-metadata">

**Author:** [@sanket07](https://discuss.elastic.co/u/sanket07)\
**Replies:** 22\
**Last updated:** [November 9, 2019, 7:02pm UTC](https://discuss.elastic.co/t/azure-active-directory-integration-with-elasticsearch/204023 "2019-11-09T19:02:43Z")

</div>

Hello, I have elasticsearch server hosted on virtual machine in azure cloud. I have an azure default directory and users added to it. I want to login to elasticsearch using credentials for the users in active directory.…

---

## [Need multiple post\_filter condition](https://discuss.elastic.co/t/need-multiple-post-filter-condition/156255)

<div class="topic-metadata">

**Author:** [@fardhana](https://discuss.elastic.co/u/fardhana)\
**Replies:** 16\
**Last updated:** [November 15, 2018, 6:49am UTC](https://discuss.elastic.co/t/need-multiple-post-filter-condition/156255 "2018-11-15T06:49:22Z")

</div>

Hi, I have directory listing site that use elasticsearch as search engine. In this site people able to: Find the most related doc by keyword (keyword will be checked to multiple field) sort by nearest location and lim…

---

## [Setup mode is not available You do not have the necessary permissions to do this](https://discuss.elastic.co/t/setup-mode-is-not-available-you-do-not-have-the-necessary-permissions-to-do-this/245635)

<div class="topic-metadata">

**Author:** [@Yogesh\_Kumar1](https://discuss.elastic.co/u/Yogesh_Kumar1)\
**Replies:** 29\
**Last updated:** [August 29, 2020, 7:36am UTC](https://discuss.elastic.co/t/setup-mode-is-not-available-you-do-not-have-the-necessary-permissions-to-do-this/245635 "2020-08-29T07:36:38Z")

</div>

i have installed a Elasticsearch cluster of 3 master and 2 data nodes and a single node Elasticsearch monitoring cluster. i am sending the metrics of Elasticsearch using metricbeat. i can see the metrics when i check th…

---

## [Logstash field split](https://discuss.elastic.co/t/logstash-field-split/78693)

<div class="topic-metadata">

**Author:** [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Replies:** 20\
**Last updated:** [March 20, 2017, 8:49am UTC](https://discuss.elastic.co/t/logstash-field-split/78693 "2017-03-20T08:49:34Z")

</div>

How to split "content" =\> "command hitesh.restaurants command: drop { drop: \\"restaurants\\" } keyUpdates:0 writeConflicts:0 numYields:0 reslen:81 locks:{ Global: { acquireCount: { r: 1, w: 1 } }, Database: { acquireC…

---

## [Need to replace default @timestamp with userdefined timestamp](https://discuss.elastic.co/t/need-to-replace-default-timestamp-with-userdefined-timestamp/98637)

<div class="topic-metadata">

**Author:** [@fazi347](https://discuss.elastic.co/u/fazi347)\
**Replies:** 13\
**Last updated:** [August 30, 2017, 1:45pm UTC](https://discuss.elastic.co/t/need-to-replace-default-timestamp-with-userdefined-timestamp/98637 "2017-08-30T13:45:11Z")

</div>

Hi, I want to remove the default @timestamp entry from log messages and need to change the default log search timestamp a different one. Kibana Version 5.5.2

---

## [All Nodes Failed Exception](https://discuss.elastic.co/t/all-nodes-failed-exception/275627)

<div class="topic-metadata">

**Author:** [@NLSVTN](https://discuss.elastic.co/u/NLSVTN)\
**Replies:** 15\
**Last updated:** [June 12, 2021, 5:43am UTC](https://discuss.elastic.co/t/all-nodes-failed-exception/275627 "2021-06-12T05:43:39Z")

</div>

Hi, We are getting the following error: Error summary: EsHadoopNoNodesLeftException: Connection error (check network and/or proxy settings)- all nodes failed; tried \[\[https://search-seqr-gris-prod-65wdlm6cncfxo5d326vkd…

---

## [Issue with elasticsearch-analysis-icu plugin](https://discuss.elastic.co/t/issue-with-elasticsearch-analysis-icu-plugin/86394)

<div class="topic-metadata">

**Author:** [@yesu](https://discuss.elastic.co/u/yesu)\
**Replies:** 19\
**Last updated:** [May 30, 2017, 12:18pm UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-analysis-icu-plugin/86394 "2017-05-30T12:18:41Z")

</div>

I am trying to use elasticsearch-analysis-icu plugin to achieve case-insensitivity sort, data is getting sorted correctly but its returning data in china language for both sort field in queries and aggregation bucket. Is…

---

## [What's limiting my Elasticsearch?](https://discuss.elastic.co/t/whats-limiting-my-elasticsearch/42391)

<div class="topic-metadata">

**Author:** [@Karol\_Stojek](https://discuss.elastic.co/u/Karol_Stojek)\
**Replies:** 18\
**Last updated:** [March 7, 2016, 11:47am UTC](https://discuss.elastic.co/t/whats-limiting-my-elasticsearch/42391 "2016-03-07T11:47:56Z")

</div>

Hello! I'm trying to make my Elasticsearch work faster. I have a logstash that's processing 17k/s events, when using null output. If I set Elasticsearch as my output I'm able to get 6k/s only. The Elasticsearch 1.7.1…

---

## [How to replace @timestamp with actual log time](https://discuss.elastic.co/t/how-to-replace-timestamp-with-actual-log-time/149276)

<div class="topic-metadata">

**Author:** [@ashok9177](https://discuss.elastic.co/u/ashok9177)\
**Replies:** 18\
**Last updated:** [September 21, 2018, 9:22am UTC](https://discuss.elastic.co/t/how-to-replace-timestamp-with-actual-log-time/149276 "2018-09-21T09:22:15Z")

</div>

I am using below grok filter to parse the log , \`filter { grok { match =\> \[ "message", "%{TIMESTAMP\_ISO8601:timestamp} (\\\[%{WORD:loglevel}\\\]) %{DATA} - %{DATA:method} processing time for transactionId : …

---

## [Logstash Mutliline Inquiry](https://discuss.elastic.co/t/logstash-mutliline-inquiry/55750)

<div class="topic-metadata">

**Author:** [@sombilat](https://discuss.elastic.co/u/sombilat)\
**Replies:** 16\
**Last updated:** [July 21, 2016, 6:12pm UTC](https://discuss.elastic.co/t/logstash-mutliline-inquiry/55750 "2016-07-21T18:12:42Z")

</div>

Hello, I would like to ask a question on the Multiline function of Logstash. How does it work? When does it "compile" the pattern into the event? I noticed that during execution, the events are singular and when …

---

## [Why is my heap usage always high?](https://discuss.elastic.co/t/why-is-my-heap-usage-always-high/45017)

<div class="topic-metadata">

**Author:** [@trevan](https://discuss.elastic.co/u/trevan)\
**Replies:** 9\
**Last updated:** [February 3, 2017, 9:59pm UTC](https://discuss.elastic.co/t/why-is-my-heap-usage-always-high/45017 "2017-02-03T21:59:39Z")

</div>

I have a cluster with 8 nodes and all the nodes almost always show a heap usage in the high 70%. I never seem to see a "pretty jigsaw" pattern in the heap usage. All the nodes are in individual systems that have 64GB …

---

## [Logstash doesn't use all CPU available](https://discuss.elastic.co/t/logstash-doesnt-use-all-cpu-available/66189)

<div class="topic-metadata">

**Author:** [@Oliver\_Hernandez](https://discuss.elastic.co/u/Oliver_Hernandez)\
**Replies:** 13\
**Last updated:** [November 17, 2016, 6:16am UTC](https://discuss.elastic.co/t/logstash-doesnt-use-all-cpu-available/66189 "2016-11-17T06:16:00Z")

</div>

Hi guys, Hope you can help me. i'm running logstash 5.0.1 on a Blade server with 40 cores and 256GB of RAM. I'm getting a LOT of logs into a single file (around 50.000 lines per minute) from a service we're running i…

---

## [ElasticSearch Exact Word Issue](https://discuss.elastic.co/t/elasticsearch-exact-word-issue/51654)

<div class="topic-metadata">

**Author:** [@tarlok](https://discuss.elastic.co/u/tarlok)\
**Replies:** 11\
**Last updated:** [June 15, 2016, 3:24pm UTC](https://discuss.elastic.co/t/elasticsearch-exact-word-issue/51654 "2016-06-15T15:24:17Z")

</div>

Hi, I am not able to customize elasticsearch. My text is "This is apple" when user search for "apple" it returns 1 result. I want exact sentence search and don't want any result until user search for full sentence "Thi…

---

## [How to specify file to Ingest Attachment](https://discuss.elastic.co/t/how-to-specify-file-to-ingest-attachment/75843)

<div class="topic-metadata">

**Author:** [@fjosef](https://discuss.elastic.co/u/fjosef)\
**Replies:** 10\
**Last updated:** [February 21, 2017, 2:34pm UTC](https://discuss.elastic.co/t/how-to-specify-file-to-ingest-attachment/75843 "2017-02-21T14:34:29Z")

</div>

Hi everyone! I have a Wordpress website and replaced native search with ElasticSearch using ElasticPress plugin. Every thing is working perfect, but now we want to index binary file contents (especially pdf). For te…

---

## [How to delete UNASSIGNED .watches?](https://discuss.elastic.co/t/how-to-delete-unassigned-watches/110091)

<div class="topic-metadata">

**Author:** [@tjliu](https://discuss.elastic.co/u/tjliu)\
**Replies:** 9\
**Last updated:** [December 8, 2017, 11:05am UTC](https://discuss.elastic.co/t/how-to-delete-unassigned-watches/110091 "2017-12-08T11:05:13Z")

</div>

Hi, The status of my cluster is RED. It seems it will be green if I delete 2 UNASSIGNED ".watches" from the following log. How can I fix this? Thanks. Blockquote $ curl -XGET 'http://xxx:9200/\_cat/shards' .watcher-h…

---

## [Elasticsearch and cassandra integration?](https://discuss.elastic.co/t/elasticsearch-and-cassandra-integration/11250)

<div class="topic-metadata">

**Author:** [@utkarsh2012](https://discuss.elastic.co/u/utkarsh2012)\
**Replies:** 13\
**Last updated:** [January 6, 2015, 1:03pm UTC](https://discuss.elastic.co/t/elasticsearch-and-cassandra-integration/11250 "2015-01-06T13:03:35Z")

</div>

Hello! I am looking for an integration b/w elastic search and cassandra, so that I can index and search my data sitting in cassandra cluster. I found a bunch of plugins for ES but not for cassandra. Is there is a …

---

## [How to separate index of filebeat coming from 2 or more hosts](https://discuss.elastic.co/t/how-to-separate-index-of-filebeat-coming-from-2-or-more-hosts/152463)

<div class="topic-metadata">

**Author:** [@mark.quilates](https://discuss.elastic.co/u/mark.quilates)\
**Replies:** 10\
**Last updated:** [October 18, 2018, 10:17am UTC](https://discuss.elastic.co/t/how-to-separate-index-of-filebeat-coming-from-2-or-more-hosts/152463 "2018-10-18T10:17:55Z")

</div>

Hi Guys, Can you help me, I have 2 filebeats in separate host and I used logstash pipeline. The thing is I want the other filebeat it to stored its data in new index. How can I make that? To have new index name in my …

---

## [In\_flight\_request is too large and throw \[circuit\_breaking\_exception\] \[parent\] Data too large](https://discuss.elastic.co/t/in-flight-request-is-too-large-and-throw-circuit-breaking-exception-parent-data-too-large/246482)

<div class="topic-metadata">

**Author:** [@greyhats13](https://discuss.elastic.co/u/greyhats13)\
**Replies:** 25\
**Last updated:** [September 1, 2020, 10:21am UTC](https://discuss.elastic.co/t/in-flight-request-is-too-large-and-throw-circuit-breaking-exception-parent-data-too-large/246482 "2020-09-01T10:21:05Z")

</div>

{"statusCode":500,"error":"Internal Server Error","message":"\[parent\] Data too large, data for \[indices:data/read/get\[s\]\] would be \[32115499902/29.9gb\], which is larger than the limit of \[31621696716/29.4gb\], real usage:…

[Previous page](https://discuss.elastic.co/top.md?page=58&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=60&per_page=50&period=all)
