# Top

**URL:** https://discuss.elastic.co/top.md?page=6&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 7

---

## [Add dictionary to index](https://discuss.elastic.co/t/add-dictionary-to-index/92415)

<div class="topic-metadata">

**Author:** [@avivc](https://discuss.elastic.co/u/avivc)\
**Replies:** 28\
**Last updated:** [July 17, 2017, 2:22pm UTC](https://discuss.elastic.co/t/add-dictionary-to-index/92415 "2017-07-17T14:22:38Z")

</div>

Hi, Very simple and straight forward question: Is there a way to push/insert a whole dictionary into my index pattern? without iterate over the dictionary and push each object into my index pattern Thx a lot :thumbsup: …

---

## [Comparing two terms](https://discuss.elastic.co/t/comparing-two-terms/46897)

<div class="topic-metadata">

**Author:** [@astickler](https://discuss.elastic.co/u/astickler)\
**Replies:** 14\
**Last updated:** [January 19, 2017, 9:39am UTC](https://discuss.elastic.co/t/comparing-two-terms/46897 "2017-01-19T09:39:45Z")

</div>

In Kibana (e.g Visualise), is it possible to compare one term with another? For example, I have indexed records that contain an indoorTemp value and a setpointTemp value - I have a line chart that shows the indoorTem…

---

## [Character encoding problems](https://discuss.elastic.co/t/character-encoding-problems/126714)

<div class="topic-metadata">

**Author:** [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Replies:** 10\
**Last updated:** [April 24, 2018, 1:50pm UTC](https://discuss.elastic.co/t/character-encoding-problems/126714 "2018-04-24T13:50:19Z")

</div>

Hello and thank you in advance for your help. I can't seem to get the UTF-8 encoding for my logstash output right. It always looks like UTF-8 data has been interpreted as ISO-8859-1. My data sources have been a MySQL da…

---

## [\[SOLVED\] Filebeat keeps open files forever](https://discuss.elastic.co/t/solved-filebeat-keeps-open-files-forever/40098)

<div class="topic-metadata">

**Author:** [@hamelg](https://discuss.elastic.co/u/hamelg)\
**Replies:** 22\
**Last updated:** [October 11, 2016, 6:43pm UTC](https://discuss.elastic.co/t/solved-filebeat-keeps-open-files-forever/40098 "2016-10-11T18:43:56Z")

</div>

Here is our setup : filebeat: prospectors: - paths: - "/var/log/apache2/\*access.log" document\_type: accesslog ignore\_older: 5m tail\_files: true Every day, logrotate rotates these f…

---

## [Logstash and JSON array split \[SOLVED\]](https://discuss.elastic.co/t/logstash-and-json-array-split-solved/64841)

<div class="topic-metadata">

**Author:** [@Emmanuel\_CHANSON](https://discuss.elastic.co/u/Emmanuel_CHANSON)\
**Replies:** 10\
**Last updated:** [November 5, 2016, 9:56am UTC](https://discuss.elastic.co/t/logstash-and-json-array-split-solved/64841 "2016-11-05T09:56:19Z")

</div>

Hello, I have the following input in JSON file: {"jobs":\[ {"name":"Onboarding\_Build","builds":\[{"duration":127431,"number":2480,"timestamp":1477608643723},{"duration":132275,"number":2479,"timestamp":1477605046524},{"d…

---

## [Logstash grok match pattern for message field](https://discuss.elastic.co/t/logstash-grok-match-pattern-for-message-field/25311)

<div class="topic-metadata">

**Author:** [@abathula](https://discuss.elastic.co/u/abathula)\
**Replies:** 33\
**Last updated:** [October 18, 2016, 5:52am UTC](https://discuss.elastic.co/t/logstash-grok-match-pattern-for-message-field/25311 "2016-10-18T05:52:24Z")

</div>

My log data is like, 2015-01-31 15:58:56,851 \[9\] DEBUG NCR.AKPOS.ShoppingCart.CartInvoicer - Setting offline returninvoice: c0000000-2144-04e2-f409-ffff08d20b85 2015-01-31 15:58:56,860 \[9\] DEBUG NCR.AKPOS.ShoppingCart.…

---

## [Doubt about Elasticsearch module of Filebeat on container \[7.9.2\]](https://discuss.elastic.co/t/doubt-about-elasticsearch-module-of-filebeat-on-container-7-9-2/272189)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 11\
**Last updated:** [May 12, 2021, 8:53am UTC](https://discuss.elastic.co/t/doubt-about-elasticsearch-module-of-filebeat-on-container-7-9-2/272189 "2021-05-12T08:53:09Z")

</div>

Hi, everyone I have been testing with Elasticsearch module of Filebeat in order to have information about Elasticsearch. I work with Kubernetes and I have created a deployment with Filebeat. Here are you are my Filebea…

---

## [Passing multiple values in Kibana - ‘add filter’ - ‘is one of’](https://discuss.elastic.co/t/passing-multiple-values-in-kibana-add-filter-is-one-of/232694)

<div class="topic-metadata">

**Author:** [@ManuelF](https://discuss.elastic.co/u/ManuelF)\
**Replies:** 10\
**Last updated:** [May 15, 2020, 6:33pm UTC](https://discuss.elastic.co/t/passing-multiple-values-in-kibana-add-filter-is-one-of/232694 "2020-05-15T18:33:15Z")

</div>

Hi, I am having the same issue exposed in the topic below, but it never got a final answer nor solution (if any). In my case I have more than 400 entries and do it one by one it will take hours. The answer for this t…

---

## [Connect elasticsearch with spring boot application?](https://discuss.elastic.co/t/connect-elasticsearch-with-spring-boot-application/82895)

<div class="topic-metadata">

**Author:** [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Replies:** 18\
**Last updated:** [April 21, 2017, 8:09am UTC](https://discuss.elastic.co/t/connect-elasticsearch-with-spring-boot-application/82895 "2017-04-21T08:09:08Z")

</div>

Hi, I'm new in elasticsearch, i Create an elasticsearch instance running locally, i need to connect with the sspring boot application , I use a different example but he return an error creating bean . What's the princ…

---

## [Kibana 4.5 status red: unable to connect to elasticsearch](https://discuss.elastic.co/t/kibana-4-5-status-red-unable-to-connect-to-elasticsearch/50523)

<div class="topic-metadata">

**Author:** [@sarbjeet](https://discuss.elastic.co/u/sarbjeet)\
**Replies:** 43\
**Last updated:** [May 30, 2016, 11:08am UTC](https://discuss.elastic.co/t/kibana-4-5-status-red-unable-to-connect-to-elasticsearch/50523 "2016-05-30T11:08:12Z")

</div>

hi... i installed ELK and it works properly but now i upgrade kibana from 4.1 to 4.5 and elasticsearch 1.2 to 2.3 .error is occured

---

## [How to create users in Kibana and enable role management in Kibana?](https://discuss.elastic.co/t/how-to-create-users-in-kibana-and-enable-role-management-in-kibana/166514)

<div class="topic-metadata">

**Author:** [@aditya\_kanekar](https://discuss.elastic.co/u/aditya_kanekar)\
**Replies:** 12\
**Last updated:** [February 5, 2019, 11:02am UTC](https://discuss.elastic.co/t/how-to-create-users-in-kibana-and-enable-role-management-in-kibana/166514 "2019-02-05T11:02:16Z")

</div>

Continuing the discussion from Kibana Management missing Role Management: We are using ELk Stack 6.5 and after activating trial X-PACK license, we still can't see Kibana Role Management. Checked the license status its…

---

## [Logstash plugin installed but not found](https://discuss.elastic.co/t/logstash-plugin-installed-but-not-found/24369)

<div class="topic-metadata">

**Author:** [@whyapenny](https://discuss.elastic.co/u/whyapenny)\
**Replies:** 14\
**Last updated:** [February 9, 2017, 1:46pm UTC](https://discuss.elastic.co/t/logstash-plugin-installed-but-not-found/24369 "2017-02-09T13:46:35Z")

</div>

I have installed a logstash plugin logstash-input-jms. I build the .gem file and used the bin/plugin install command. It shows it installed successfully, yet when i run bin/plugin list, it is not listed. I tried with …

---

## [How can ship logs to Logstash using Windows Events?](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644)

<div class="topic-metadata">

**Author:** [@thyfere](https://discuss.elastic.co/u/thyfere)\
**Replies:** 20\
**Last updated:** [November 26, 2015, 7:23am UTC](https://discuss.elastic.co/t/how-can-ship-logs-to-logstash-using-windows-events/27644 "2015-11-26T07:23:57Z")

</div>

Hi, I am very new to ELK stack. I have setup a stack using two Windows Server 2012 R2 VM machines, one is for Logstash and other for Kibana and Elastic search. Initially, I was thinking to use nxlog for logs forwarding…

---

## [cURL request not working with CA certificate on Windows](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566)

<div class="topic-metadata">

**Author:** [@Andy0708](https://discuss.elastic.co/u/Andy0708)\
**Replies:** 9\
**Last updated:** [March 31, 2022, 8:52am UTC](https://discuss.elastic.co/t/curl-request-not-working-with-ca-certificate-on-windows/299566 "2022-03-31T08:52:49Z")

</div>

Hi, The following command works fine on macOS, but I am unable to get it to work on Windows 10. curl --cacert config\\certs\\http\_ca.crt -u elastic https://localhost:9200 This happens after starting up a fresh cluster o…

---

## [NoNodeAvailableException, cannot connect Java API and Elasticsearch](https://discuss.elastic.co/t/nonodeavailableexception-cannot-connect-java-api-and-elasticsearch/25474)

<div class="topic-metadata">

**Author:** [@MagicZou](https://discuss.elastic.co/u/MagicZou)\
**Replies:** 10\
**Last updated:** [November 10, 2015, 5:16am UTC](https://discuss.elastic.co/t/nonodeavailableexception-cannot-connect-java-api-and-elasticsearch/25474 "2015-11-10T05:16:50Z")

</div>

Hi all, I am new to elasticsearch. I want to use Java API to communicate with ES cluster. This is my code right now: Settings settings = ImmutableSettings.settingsBuilder() .put("client.transport.ping\_tim…

---

## [How do I get Elasticsearch max\_clause\_count to take effect?](https://discuss.elastic.co/t/how-do-i-get-elasticsearch-max-clause-count-to-take-effect/6133)

<div class="topic-metadata">

**Author:** [@jbattle](https://discuss.elastic.co/u/jbattle)\
**Replies:** 12\
**Last updated:** [April 14, 2016, 3:20pm UTC](https://discuss.elastic.co/t/how-do-i-get-elasticsearch-max-clause-count-to-take-effect/6133 "2016-04-14T15:20:21Z")

</div>

I am currently setting the max\_clause\_count at the creation of my index as follows: "index":{ "type" :"new", "bulk\_size":"100000", "bulk\_timeout":"1000ms", "query":{ "bool":{ "max\_clause\_coun…

---

## [SAML support, custom authentication plugins](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813)

<div class="topic-metadata">

**Author:** [@owulff](https://discuss.elastic.co/u/owulff)\
**Replies:** 20\
**Last updated:** [February 9, 2018, 2:54pm UTC](https://discuss.elastic.co/t/saml-support-custom-authentication-plugins/1813 "2018-02-09T14:54:30Z")

</div>

This question has been raised in the Kibana community already: IMHO, it affects Elasticsearch and Shield as well. Does Shield provide an interface where I can handle the authentication process (validate SAML token) an…

---

## [Parsing logback log files with filebeat and sending them to Elasticsearch](https://discuss.elastic.co/t/parsing-logback-log-files-with-filebeat-and-sending-them-to-elasticsearch/49302)

<div class="topic-metadata">

**Author:** [@Jemli\_Fathi](https://discuss.elastic.co/u/Jemli_Fathi)\
**Replies:** 14\
**Last updated:** [December 16, 2016, 6:00pm UTC](https://discuss.elastic.co/t/parsing-logback-log-files-with-filebeat-and-sending-them-to-elasticsearch/49302 "2016-12-16T18:00:42Z")

</div>

Hi, i have a java application with logback for the log configuration and i want to parse my application log files, so they become more useful and to send them to ES, log files will be stored in a directory called logs an…

---

## [Calculate the time difference between consecutive documents](https://discuss.elastic.co/t/calculate-the-time-difference-between-consecutive-documents/128282)

<div class="topic-metadata">

**Author:** [@vinayakfutak](https://discuss.elastic.co/u/vinayakfutak)\
**Replies:** 19\
**Last updated:** [April 27, 2018, 12:28pm UTC](https://discuss.elastic.co/t/calculate-the-time-difference-between-consecutive-documents/128282 "2018-04-27T12:28:39Z")

</div>

Can I calculate time difference between consecutive document in elasticsearch? Suppose there are 3 records,the timestamp of first record is 10:45:00 and timestamp of second record is 10:47:00 and timestamp of next recor…

---

## [Failed to connect to localhost port 9200: Connection refused](https://discuss.elastic.co/t/failed-to-connect-to-localhost-port-9200-connection-refused/312954)

<div class="topic-metadata">

**Author:** [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Replies:** 14\
**Last updated:** [August 31, 2022, 5:17pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-localhost-port-9200-connection-refused/312954 "2022-08-31T17:17:08Z")

</div>

I am trying to install Elasticsearch 8.4.0 and kibana on Rocky Linux 8.6 using this article. Both elasticsearch and kibana are active and running but running this cmd: curl -X GET 'http://localhost:9200' I get curl: …

---

## [Date FIlter - \_dateparsefailure \[SOLVED\]](https://discuss.elastic.co/t/date-filter--dateparsefailure-solved/64692)

<div class="topic-metadata">

**Author:** [@Clement\_Ros](https://discuss.elastic.co/u/Clement_Ros)\
**Replies:** 20\
**Last updated:** [June 22, 2017, 8:28am UTC](https://discuss.elastic.co/t/date-filter--dateparsefailure-solved/64692 "2017-06-22T08:28:53Z")

</div>

Hi, I'm new with the date filter. I set up this configuration : filter { if "mail" in \[type\] and "maillog" in \[source\] { grok { match =\> \["message","%{CISCOTIMESTAMP:ma…

---

## [Sending filebeat data to AWS Elasticsearch service endpoint](https://discuss.elastic.co/t/sending-filebeat-data-to-aws-elasticsearch-service-endpoint/41974)

<div class="topic-metadata">

**Author:** [@pratik](https://discuss.elastic.co/u/pratik)\
**Replies:** 9\
**Last updated:** [October 27, 2016, 6:01pm UTC](https://discuss.elastic.co/t/sending-filebeat-data-to-aws-elasticsearch-service-endpoint/41974 "2016-10-27T18:01:39Z")

</div>

Hi, I have installed filebeat client on AWS EC2 which is configured to push messages to the AWS Elasticsearch service endpoint. Below is the detail of the filebeat yml file. ## Filebeat ### filebeat: # List o…

---

## [Unable to reset the ELK password](https://discuss.elastic.co/t/unable-to-reset-the-elk-password/155675)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 21\
**Last updated:** [November 10, 2018, 8:17am UTC](https://discuss.elastic.co/t/unable-to-reset-the-elk-password/155675 "2018-11-10T08:17:16Z")

</div>

HI, I'm trying to reset my ELK password, but im facing below issue, Please find my step one by one. Enabled "xpack.security.enabled: true" on both kibana and Elasticsearch Using "./setup-passwords auto/interactive" t…

---

## [Did I get to the upper limit of /bulk upload API?](https://discuss.elastic.co/t/did-i-get-to-the-upper-limit-of-bulk-upload-api/66620)

<div class="topic-metadata">

**Author:** [@small-tomorrow](https://discuss.elastic.co/u/small-tomorrow)\
**Replies:** 47\
**Last updated:** [December 1, 2016, 2:17am UTC](https://discuss.elastic.co/t/did-i-get-to-the-upper-limit-of-bulk-upload-api/66620 "2016-12-01T02:17:11Z")

</div>

fter upgrade from V 2.1.0 to V 5.0.0, I seemed to be so easy to got a OOM ERROR using /bulk api to upload data .few minutes after my service started, I would receive this :' \[gc\]\[91065\] overhead, spent \[16.5s\] collecting…

---

## [Memory lock not working](https://discuss.elastic.co/t/memory-lock-not-working/70576)

<div class="topic-metadata">

**Author:** [@Mormaii](https://discuss.elastic.co/u/Mormaii)\
**Replies:** 11\
**Last updated:** [January 5, 2017, 2:46pm UTC](https://discuss.elastic.co/t/memory-lock-not-working/70576 "2017-01-05T14:46:28Z")

</div>

I'm running a Fedora 25 ec2 image with elasticsearch 5.1.1 This are my settings: /etc/elasticsearch/elasticsearch.yml bootstrap.memory\_lock: true /usr/lib/systemd/system/elasticsearch.service LimitME…

---

## [Bulk is too slow](https://discuss.elastic.co/t/bulk-is-too-slow/107351)

<div class="topic-metadata">

**Author:** [@f4ct0r](https://discuss.elastic.co/u/f4ct0r)\
**Replies:** 33\
**Last updated:** [November 16, 2017, 11:33am UTC](https://discuss.elastic.co/t/bulk-is-too-slow/107351 "2017-11-16T11:33:35Z")

</div>

Hi, all: I wanna use ElasticSearch to store and search web logs in realtime, and I use Python API to bulk insert into ElasticSearch. I'm trying to bulk insert batches of 1000 documents into elastic search using a prede…

---

## [TLS connection failed because of certificate signed by unknown authority](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064)

<div class="topic-metadata">

**Author:** [@caoping](https://discuss.elastic.co/u/caoping)\
**Replies:** 16\
**Last updated:** [August 11, 2016, 10:48am UTC](https://discuss.elastic.co/t/tls-connection-failed-because-of-certificate-signed-by-unknown-authority/57064 "2016-08-11T10:48:05Z")

</div>

Hello, I have spent two days in configuring filebeat TLS, and always encountered below error. Can anyone give me some tips on how to resolve this issue? The error message in filebeat side: Below is the steps and co…

---

## [Elasticsearch listening on /127.0.0.1:9001 . Also shows Main PID: 12471 (code=exited, status=1/FAILURE) error messages- ubuntu server 16.04.3](https://discuss.elastic.co/t/elasticsearch-listening-on-127-0-0-1-9001-also-shows-main-pid-12471-code-exited-status-1-failure-error-messages-ubuntu-server-16-04-3/114810)

<div class="topic-metadata">

**Author:** [@bsaitechnosales](https://discuss.elastic.co/u/bsaitechnosales)\
**Replies:** 25\
**Last updated:** [January 14, 2018, 5:16am UTC](https://discuss.elastic.co/t/elasticsearch-listening-on-127-0-0-1-9001-also-shows-main-pid-12471-code-exited-status-1-failure-error-messages-ubuntu-server-16-04-3/114810 "2018-01-14T05:16:51Z")

</div>

Hi I am not been able to run sonarqube due to below mentioned log issue. Please advise how can i solved the issue root@storage:/opt/sonar/logs# more sonar.log --\> Wrapper Started as Daemon Launching a JVM... Wrapper (…

---

## ["Saved field parameter is now invalid, please select a new field"](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/83860)

<div class="topic-metadata">

**Author:** [@Tania\_Bonilla](https://discuss.elastic.co/u/Tania_Bonilla)\
**Replies:** 27\
**Last updated:** [May 5, 2017, 9:32pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/83860 "2017-05-05T21:32:59Z")

</div>

Hello, When we tried to run the Dashboard with Broadsoft, dashboard collaborate and the desktop sharing dashboards, we get the error saying "Saved field parameter is now invalid, please select a new field", we are usin…

---

## [Help please.. breaking changes?](https://discuss.elastic.co/t/help-please-breaking-changes/108010)

<div class="topic-metadata">

**Author:** [@Maekee](https://discuss.elastic.co/u/Maekee)\
**Replies:** 15\
**Last updated:** [December 8, 2017, 8:52am UTC](https://discuss.elastic.co/t/help-please-breaking-changes/108010 "2017-12-08T08:52:58Z")

</div>

Upgrading to 6.0.0 of the ELK stack Can anyone please help me why i get this entrys over and over in the Logstash log \[2017-11-16T20:49:36,973\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticse…

---

## ['java.lang.StackOverflowError' exception. Cannot evaluate org.elasticsearch.common.inject.InjectorImpl.toString()](https://discuss.elastic.co/t/java-lang-stackoverflowerror-exception-cannot-evaluate-org-elasticsearch-common-inject-injectorimpl-tostring/58884)

<div class="topic-metadata">

**Author:** [@popgis](https://discuss.elastic.co/u/popgis)\
**Replies:** 11\
**Last updated:** [February 21, 2017, 6:16am UTC](https://discuss.elastic.co/t/java-lang-stackoverflowerror-exception-cannot-evaluate-org-elasticsearch-common-inject-injectorimpl-tostring/58884 "2017-02-21T06:16:32Z")

</div>

Hi, everyone. I have installed and configured the three ElasticSearch hosts with cluster. It's OK when I use the HTTP API, but excepted when I use transport mode by Java client API. The ElasticSearch server version …

---

## [Gc overhead, spent \[\] collecting in the last \[\], causing crashes](https://discuss.elastic.co/t/gc-overhead-spent-collecting-in-the-last-causing-crashes/224049)

<div class="topic-metadata">

**Author:** [@norup](https://discuss.elastic.co/u/norup)\
**Replies:** 21\
**Last updated:** [March 23, 2020, 12:26pm UTC](https://discuss.elastic.co/t/gc-overhead-spent-collecting-in-the-last-causing-crashes/224049 "2020-03-23T12:26:31Z")

</div>

Im getting this alot: Which i think means something is wrong with my resource amounts. The VM has 64GB memory so that should be plenty. The jvm.options has -Xms16g and -Xmx16g . What else is relevant here? There…

---

## [Logstash 2.4 -- Check if two \[tags\] is present then ouput](https://discuss.elastic.co/t/logstash-2-4-check-if-two-tags-is-present-then-ouput/79277)

<div class="topic-metadata">

**Author:** [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Replies:** 20\
**Last updated:** [March 21, 2017, 3:11pm UTC](https://discuss.elastic.co/t/logstash-2-4-check-if-two-tags-is-present-then-ouput/79277 "2017-03-21T15:11:33Z")

</div>

Hello, Would like to have information I am having a little difficulty with my logstash config, I would like to be able to "filter" out IF traffic come and goes from internal network, then output it to a specific index f…

---

## [Delete old indexes](https://discuss.elastic.co/t/delete-old-indexes/226933)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 9\
**Last updated:** [April 15, 2020, 3:29pm UTC](https://discuss.elastic.co/t/delete-old-indexes/226933 "2020-04-15T15:29:27Z")

</div>

My indexes are created every day like xxx-yy-mm-dd, how can I automatic remove old indexes? I am looking for some easy way, because whole is generated automatic by tshark. To be honest I tried with index templates to a…

---

## [After new install "Can not run elasticsearch as root"](https://discuss.elastic.co/t/after-new-install-can-not-run-elasticsearch-as-root/196796)

<div class="topic-metadata">

**Author:** [@Hortiks](https://discuss.elastic.co/u/Hortiks)\
**Replies:** 12\
**Last updated:** [September 5, 2019, 3:02pm UTC](https://discuss.elastic.co/t/after-new-install-can-not-run-elasticsearch-as-root/196796 "2019-09-05T15:02:43Z")

</div>

Hello, after the installation of elasticsearch\_7.3.1, i've got the message "can not run elasticsearch as root". I had a functionnal 1.7.3 with some changes : -/etc/default/elasticsearch =\> uncommented lines START\_DAEM…

---

## [Cisco Log Processing](https://discuss.elastic.co/t/cisco-log-processing/79870)

<div class="topic-metadata">

**Author:** [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Replies:** 22\
**Last updated:** [April 3, 2017, 10:17am UTC](https://discuss.elastic.co/t/cisco-log-processing/79870 "2017-04-03T10:17:56Z")

</div>

Anyone with working Logstash Working config for processinf Cisco Logs

---

## [Marvel is now free for production](https://discuss.elastic.co/t/marvel-is-now-free-for-production/33180)

<div class="topic-metadata">

**Author:** [@sinneduy](https://discuss.elastic.co/u/sinneduy)\
**Replies:** 38\
**Last updated:** [June 28, 2017, 3:47am UTC](https://discuss.elastic.co/t/marvel-is-now-free-for-production/33180 "2017-06-28T03:47:22Z")

</div>

How can I get rid of the annoying pop up in marvel that is asking me to register a license?

---

## [Error decoding JSON: json: cannot unmarshal string into Go value of type map\[string\]interface {}](https://discuss.elastic.co/t/error-decoding-json-json-cannot-unmarshal-string-into-go-value-of-type-map-string-interface/134498)

<div class="topic-metadata">

**Author:** [@john.akash](https://discuss.elastic.co/u/john.akash)\
**Replies:** 9\
**Last updated:** [June 7, 2018, 5:15pm UTC](https://discuss.elastic.co/t/error-decoding-json-json-cannot-unmarshal-string-into-go-value-of-type-map-string-interface/134498 "2018-06-07T17:15:25Z")

</div>

Hi Team, We are using filebeat-6.0.1-1 and trying to parse a custom log to ES (5.5.x), { "Level":"DEBUG", "Date": "2018-06-04 20:11:24.277", "Thread": "\[https-jsse-nio-8443-exec-9\]", "Context": "RestProcessor", "Log": …

---

## [How to use Multiple if statements in filter section of logstash configuration file](https://discuss.elastic.co/t/how-to-use-multiple-if-statements-in-filter-section-of-logstash-configuration-file/234942)

<div class="topic-metadata">

**Author:** [@Matish\_Bhuyan](https://discuss.elastic.co/u/Matish_Bhuyan)\
**Replies:** 12\
**Last updated:** [June 12, 2020, 7:45am UTC](https://discuss.elastic.co/t/how-to-use-multiple-if-statements-in-filter-section-of-logstash-configuration-file/234942 "2020-06-12T07:45:37Z")

</div>

Hi All, I am a newbie to the elk. I am currently using logstash version 7.2. My issue here is to update and new values to the keywords, Below is my logstash configuration file input { http { …

---

## [License information from the X-Pack plugin could not be obtained from Elasticsearch for the \[data\] cluster](https://discuss.elastic.co/t/license-information-from-the-x-pack-plugin-could-not-be-obtained-from-elasticsearch-for-the-data-cluster/148030)

<div class="topic-metadata">

**Author:** [@Zelfapp](https://discuss.elastic.co/u/Zelfapp)\
**Replies:** 9\
**Last updated:** [September 11, 2018, 8:29pm UTC](https://discuss.elastic.co/t/license-information-from-the-x-pack-plugin-could-not-be-obtained-from-elasticsearch-for-the-data-cluster/148030 "2018-09-11T20:29:23Z")

</div>

Today, on my localhost dev I upgraded from ES and Kibana 6.1.2 to 6.3.2. The upgrade has all gone smoothly except for kibana. In my kibana.yml you can see that I'm connecting to a remove url. This worked great in kibana…

---

## [Delete documents by timestamp](https://discuss.elastic.co/t/delete-documents-by-timestamp/92058)

<div class="topic-metadata">

**Author:** [@Vedran\_Maricevic](https://discuss.elastic.co/u/Vedran_Maricevic)\
**Replies:** 17\
**Last updated:** [July 6, 2017, 10:42am UTC](https://discuss.elastic.co/t/delete-documents-by-timestamp/92058 "2017-07-06T10:42:10Z")

</div>

I am using ELK, and some of my indexes are getting large. I would like to delete some documents that fir provided timeframe. For example, delete all documents in certain time range. I am using 5.3.2 ElasticSearch I use…

---

## [Filebeat on FreeBSD / PFsense](https://discuss.elastic.co/t/filebeat-on-freebsd-pfsense/38278)

<div class="topic-metadata">

**Author:** [@Noebas](https://discuss.elastic.co/u/Noebas)\
**Replies:** 31\
**Last updated:** [April 6, 2017, 8:35pm UTC](https://discuss.elastic.co/t/filebeat-on-freebsd-pfsense/38278 "2017-04-06T20:35:31Z")

</div>

I'am trying to use filebeat on freebsd (pfsense), reading the filter.log This is working fine on filebeat startup, but after this the logging stops, If i then stop and restart filebeat it starts logging againt and stop…

---

## [Log rotation and filebeat](https://discuss.elastic.co/t/log-rotation-and-filebeat/140285)

<div class="topic-metadata">

**Author:** [@bsikander](https://discuss.elastic.co/u/bsikander)\
**Replies:** 16\
**Last updated:** [July 23, 2018, 2:22pm UTC](https://discuss.elastic.co/t/log-rotation-and-filebeat/140285 "2018-07-23T14:22:57Z")

</div>

I have multiple long running jobs that produce alot of logs. We are using logrotate utility of Linux to rotate the logs. The problem is that filebeat can miss logs. For example, if I have a log file named output.log and …

---

## [Elasticsearch: Failed to obtain node locks](https://discuss.elastic.co/t/elasticsearch-failed-to-obtain-node-locks/260102)

<div class="topic-metadata">

**Author:** [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Replies:** 12\
**Last updated:** [January 17, 2021, 6:34pm UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-obtain-node-locks/260102 "2021-01-17T18:34:45Z")

</div>

Kibana version : 7.8.0 Elasticsearch version : 7.8.0 APM Server version : 7.8.0 Hi Team My elasticsearch server is up and running from more than 2-3 months. All of a sudden it's down today. When I tried to debug I se…

---

## [How can I make the string field not\_analyzed?](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230)

<div class="topic-metadata">

**Author:** [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Replies:** 16\
**Last updated:** [March 23, 2017, 5:17pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230 "2017-03-23T17:17:33Z")

</div>

I am using logstash 1.5.1 and elasticsearch 1.7.3.0. I used logstash elasticsearch output to index the records residing in a bunch of csv files, and used my own mapping document where I set strings to be not\_analyzed, al…

---

## [Extracting the JSON fields from the message](https://discuss.elastic.co/t/extracting-the-json-fields-from-the-message/226590)

<div class="topic-metadata">

**Author:** [@Raed](https://discuss.elastic.co/u/Raed)\
**Replies:** 9\
**Last updated:** [April 7, 2020, 1:37am UTC](https://discuss.elastic.co/t/extracting-the-json-fields-from-the-message/226590 "2020-04-07T01:37:22Z")

</div>

I'm getting the below JSON as a message: { "requestUrl": "http://localhost:8080/frameworks/298", "requestUri": "/frameworks/298", "requestMethod": "PUT", "requestHeaders": { "authorization": "\*\*\*", "ac…

---

## [Logstash reporting error sending to Elasticsearch](https://discuss.elastic.co/t/logstash-reporting-error-sending-to-elasticsearch/72351)

<div class="topic-metadata">

**Author:** [@kopacko](https://discuss.elastic.co/u/kopacko)\
**Replies:** 56\
**Last updated:** [February 8, 2017, 5:26am UTC](https://discuss.elastic.co/t/logstash-reporting-error-sending-to-elasticsearch/72351 "2017-02-08T05:26:03Z")

</div>

I have just finished rebuilding my entire ELK stack environment. I got the clusters build last night and finished turning everything back on about 3 hours ago. With the help of others in here and the Logstash forums, I …

---

## [Querying a multiple level nested object](https://discuss.elastic.co/t/querying-a-multiple-level-nested-object/56889)

<div class="topic-metadata">

**Author:** [@gigouni](https://discuss.elastic.co/u/gigouni)\
**Replies:** 10\
**Last updated:** [May 2, 2017, 11:50am UTC](https://discuss.elastic.co/t/querying-a-multiple-level-nested-object/56889 "2017-05-02T11:50:26Z")

</div>

Hello everyone, I would like to precise that I've searched before annoy you with my question but I didn't found the answer on Google or even through this forum (but maybe that it has already been asked somewhere with …

---

## [High CPU usage / load average while no running queries](https://discuss.elastic.co/t/high-cpu-usage-load-average-while-no-running-queries/162569)

<div class="topic-metadata">

**Author:** [@ES-beginner](https://discuss.elastic.co/u/ES-beginner)\
**Replies:** 15\
**Last updated:** [January 8, 2019, 8:51am UTC](https://discuss.elastic.co/t/high-cpu-usage-load-average-while-no-running-queries/162569 "2019-01-08T08:51:37Z")

</div>

Hello everyone! I am a beginner with ES, and I am encountering my first performance issue. Setup: Hardware: 2 vCore, 8 GB RAM, 80 GB SSD Ubuntu 18.04 Java 1.8.0\_191 ElasticSearch 6.5.1 Default ES configuration 1 clu…

---

## [How do i import data from mysql to elastic search 1.6](https://discuss.elastic.co/t/how-do-i-import-data-from-mysql-to-elastic-search-1-6/2658)

<div class="topic-metadata">

**Author:** [@Deepak\_Kumar](https://discuss.elastic.co/u/Deepak_Kumar)\
**Replies:** 26\
**Last updated:** [November 9, 2016, 9:38pm UTC](https://discuss.elastic.co/t/how-do-i-import-data-from-mysql-to-elastic-search-1-6/2658 "2016-11-09T21:38:08Z")

</div>

How do i import data from mysql to elastic search 1.6 as river is depriciated. and also suggest method to update elastic search real time

[Previous page](https://discuss.elastic.co/top.md?page=5&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=7&per_page=50&period=all)
