# Top

**URL:** https://discuss.elastic.co/top.md?page=60&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 61

---

## [Error creating Machine Learning job](https://discuss.elastic.co/t/error-creating-machine-learning-job/86986)

<div class="topic-metadata">

**Author:** [@tarp](https://discuss.elastic.co/u/tarp)\
**Replies:** 16\
**Last updated:** [May 30, 2017, 9:09pm UTC](https://discuss.elastic.co/t/error-creating-machine-learning-job/86986 "2017-05-30T21:09:29Z")

</div>

Hi, I'm trying to create a Machine Learning job multi-metric job. Upon the last step of clicking the Create Job button, I get the error in the red box at the top of the page. Save failed: \[remote\_transport\_exception\]\[…

---

## [Logstash mysql using jdbc on windows: library error](https://discuss.elastic.co/t/logstash-mysql-using-jdbc-on-windows-library-error/37313)

<div class="topic-metadata">

**Author:** [@krushnat\_khawale](https://discuss.elastic.co/u/krushnat_khawale)\
**Replies:** 9\
**Last updated:** [December 17, 2015, 8:45am UTC](https://discuss.elastic.co/t/logstash-mysql-using-jdbc-on-windows-library-error/37313 "2015-12-17T08:45:46Z")

</div>

I want to insert data from mysql to elasticsearch using logstash. when I am running command, logstash -f myconf.conf I am getting following error: D:\\Users\\admin\\setups\\logstash-2.1.1\\bin\>logstash -f myconf.conf io/…

---

## [Changing the \_type of all entries](https://discuss.elastic.co/t/changing-the-type-of-all-entries/105669)

<div class="topic-metadata">

**Author:** [@ChaosMTA](https://discuss.elastic.co/u/ChaosMTA)\
**Replies:** 10\
**Last updated:** [October 29, 2017, 11:44pm UTC](https://discuss.elastic.co/t/changing-the-type-of-all-entries/105669 "2017-10-29T23:44:35Z")

</div>

Hey guys, Would really appreciate if someone could tell me how I can change all of my \_type entries in a index to be the same. Right now some are 'log' and some are 'doc' when really they should all be doc. I hear tha…

---

## [Zen discovery not working](https://discuss.elastic.co/t/zen-discovery-not-working/89152)

<div class="topic-metadata">

**Author:** [@Tamizh](https://discuss.elastic.co/u/Tamizh)\
**Replies:** 10\
**Last updated:** [June 13, 2017, 11:07am UTC](https://discuss.elastic.co/t/zen-discovery-not-working/89152 "2017-06-13T11:07:04Z")

</div>

When I try to add a node to my single node cluster. These are my node configurations Node - 1 cluster.name: \<Cluster Name\> node.name: \<Node Name\> discovery.zen.ping.unicast.hosts: \["127.0.0.1:9300", "\<new-node-ip\>:9300…

---

## [Can't install X-Pack in a offline machine if Elasticseach was installed by RPM](https://discuss.elastic.co/t/cant-install-x-pack-in-a-offline-machine-if-elasticseach-was-installed-by-rpm/118911)

<div class="topic-metadata">

**Author:** [@matiasf](https://discuss.elastic.co/u/matiasf)\
**Replies:** 16\
**Last updated:** [February 20, 2018, 8:12am UTC](https://discuss.elastic.co/t/cant-install-x-pack-in-a-offline-machine-if-elasticseach-was-installed-by-rpm/118911 "2018-02-20T08:12:41Z")

</div>

Hi all, I follow this installation guide https://www.elastic.co/guide/en/elasticearch/reference/6.2/installing-xpack-es.html with Internet connection and all work fine. But now I what to do the same with the downloadin…

---

## [Node will not join cluster](https://discuss.elastic.co/t/node-will-not-join-cluster/206456)

<div class="topic-metadata">

**Author:** [@Terran](https://discuss.elastic.co/u/Terran)\
**Replies:** 11\
**Last updated:** [November 11, 2019, 12:20pm UTC](https://discuss.elastic.co/t/node-will-not-join-cluster/206456 "2019-11-11T12:20:20Z")

</div>

Running version 7.3.1. I have a single node cluster and this is operating fine. I want to join two other nodes to this cluster. Each time I try I either get another single node cluster, or elasticsearch will not start…

---

## [Multi Index Visualization](https://discuss.elastic.co/t/multi-index-visualization/55666)

<div class="topic-metadata">

**Author:** [@Mormaii](https://discuss.elastic.co/u/Mormaii)\
**Replies:** 14\
**Last updated:** [July 20, 2016, 10:10pm UTC](https://discuss.elastic.co/t/multi-index-visualization/55666 "2016-07-20T22:10:55Z")

</div>

Trying to set up one visualization graph that has several indexes on it. I have indexes like this: agslx-blabla-varnish agslx-blabla2-varnish agslx-blabla3-varnish I've configured Kibana to use: "agslx-\*-varnish" ind…

---

## [How to use the JSON filter correctly?](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 13\
**Last updated:** [July 28, 2023, 2:27pm UTC](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372 "2023-07-28T14:27:51Z")

</div>

Application logs is of below JSON format and I'm unsure what should be the source field incase I'm using the JSON filter ? I would like to have all the fields appear on the Kibana output, particularly the message field,…

---

## [Logstash udp input queue\_size](https://discuss.elastic.co/t/logstash-udp-input-queue-size/24253)

<div class="topic-metadata">

**Author:** [@achechen](https://discuss.elastic.co/u/achechen)\
**Replies:** 9\
**Last updated:** [January 8, 2016, 2:02pm UTC](https://discuss.elastic.co/t/logstash-udp-input-queue-size/24253 "2016-01-08T14:02:41Z")

</div>

Hello There, what exactly does queue\_size parameter in UDP input do? I have a logstash server which is not able to consume all UDP events that are sent to it therefore a lot of UDP events are being dropped. Documen…

---

## [@timestamp converts timezones when it shouldn't - Weird issue](https://discuss.elastic.co/t/timestamp-converts-timezones-when-it-shouldnt-weird-issue/50028)

<div class="topic-metadata">

**Author:** [@thcurrie](https://discuss.elastic.co/u/thcurrie)\
**Replies:** 11\
**Last updated:** [May 18, 2016, 5:15pm UTC](https://discuss.elastic.co/t/timestamp-converts-timezones-when-it-shouldnt-weird-issue/50028 "2016-05-18T17:15:05Z")

</div>

Hello, I'm new to Elastic Search Logstash and Kibana and would appreciate some help with an issue I've been unable to resolve. I'm forwarding logs from various labs in Canada (EDT), Turkey (EEST), and Vietnam (IST) usi…

---

## [Xml-file too big for logstash?](https://discuss.elastic.co/t/xml-file-too-big-for-logstash/179016)

<div class="topic-metadata">

**Author:** [@nane96](https://discuss.elastic.co/u/nane96)\
**Replies:** 27\
**Last updated:** [May 13, 2019, 8:35pm UTC](https://discuss.elastic.co/t/xml-file-too-big-for-logstash/179016 "2019-05-13T20:35:11Z")

</div>

Hello, I've been trying out a logstash config file for a pretty large xml-file containing log events. Thanks to the help of someon on here it originally worked, but only for a smaller version of the file, with about 400…

---

## [New to Elastic Search, I get this exception: org.elasticsearch.action.UnavailableShardsException](https://discuss.elastic.co/t/new-to-elastic-search-i-get-this-exception-org-elasticsearch-action-unavailableshardsexception/5120)

<div class="topic-metadata">

**Author:** [@ogregras](https://discuss.elastic.co/u/ogregras)\
**Replies:** 14\
**Last updated:** [August 18, 2011, 12:08pm UTC](https://discuss.elastic.co/t/new-to-elastic-search-i-get-this-exception-org-elasticsearch-action-unavailableshardsexception/5120 "2011-08-18T12:08:58Z")

</div>

I'm new to Elastic search, the project is fantastic! In fact it works very well most of the time. But once in a while (not sure when exactly) I get this exception: ======================= org.elasticsearch.act…

---

## [Nest elasticsearch 7 Geolocation indexing](https://discuss.elastic.co/t/nest-elasticsearch-7-geolocation-indexing/184307)

<div class="topic-metadata">

**Author:** [@Ilyoskhuja](https://discuss.elastic.co/u/Ilyoskhuja)\
**Replies:** 15\
**Last updated:** [June 23, 2019, 6:34pm UTC](https://discuss.elastic.co/t/nest-elasticsearch-7-geolocation-indexing/184307 "2019-06-23T18:34:24Z")

</div>

Please help me with indexing geolocation in nest elastic search 7, this is my code Model public class ElasticSearchModel : Model\<Building\> { public ElasticSearchModel() { BuildingRooms …

---

## [I couldn't run Kibana 6.0.0 in Windows 32bit](https://discuss.elastic.co/t/i-couldnt-run-kibana-6-0-0-in-windows-32bit/109074)

<div class="topic-metadata">

**Author:** [@AhmyOhlin](https://discuss.elastic.co/u/AhmyOhlin)\
**Replies:** 11\
**Last updated:** [November 30, 2017, 3:11pm UTC](https://discuss.elastic.co/t/i-couldnt-run-kibana-6-0-0-in-windows-32bit/109074 "2017-11-30T15:11:46Z")

</div>

Hi, i installed Kibana 6.0 on Windows7 32bit. everytime when i run it, i get an error that my windows 7 32bit is not not compatible!! i installed the Kibana version 5.6.4 iand it was working fine without problem!!!? …

---

## [Best practice architecture using ES](https://discuss.elastic.co/t/best-practice-architecture-using-es/18630)

<div class="topic-metadata">

**Author:** [@rayman\_2](https://discuss.elastic.co/u/rayman_2)\
**Replies:** 18\
**Last updated:** [July 15, 2014, 2:04pm UTC](https://discuss.elastic.co/t/best-practice-architecture-using-es/18630 "2014-07-15T14:04:39Z")

</div>

I have simple web app containing the client side(Angular JS) and the server layer(Spring,Spring MVC) I am taking the simplest case of searching when a user have single search input. behind the scenes I assume the …

---

## [Tag based searching](https://discuss.elastic.co/t/tag-based-searching/10200)

<div class="topic-metadata">

**Author:** [@aash\_dhariya](https://discuss.elastic.co/u/aash_dhariya)\
**Replies:** 10\
**Last updated:** [January 4, 2013, 5:53am UTC](https://discuss.elastic.co/t/tag-based-searching/10200 "2013-01-04T05:53:09Z")

</div>

I am running a Rails application where I need to implement search functionality of users, using elasticsearch. There are many registered users on the website. User can submit his/her information like college, company,…

---

## [Shard Initialization slow down](https://discuss.elastic.co/t/shard-initialization-slow-down/17476)

<div class="topic-metadata">

**Author:** [@Paul\_5](https://discuss.elastic.co/u/Paul_5)\
**Replies:** 10\
**Last updated:** [May 13, 2014, 12:47pm UTC](https://discuss.elastic.co/t/shard-initialization-slow-down/17476 "2014-05-13T12:47:32Z")

</div>

We are seeing a slow down in shard initialization speed as the number of shards/indices grows in our cluster. With 0-100's of indices/shards existing in the cluster a new bulk creation of indices up the 100's at a…

---

## [Search Plugin to intercept search response](https://discuss.elastic.co/t/search-plugin-to-intercept-search-response/19494)

<div class="topic-metadata">

**Author:** [@ElasticSearch\_Users\_](https://discuss.elastic.co/u/ElasticSearch_Users_)\
**Replies:** 18\
**Last updated:** [August 9, 2016, 9:28am UTC](https://discuss.elastic.co/t/search-plugin-to-intercept-search-response/19494 "2016-08-09T09:28:23Z")

</div>

Hi, Is there any action/module that I can extend/register/add so that I can intercept the SearchResponse on the server node before the response is sent back to the TransportClient on the calling box? Thanks, S…

---

## [Snapshot and restore module (concurrency)](https://discuss.elastic.co/t/snapshot-and-restore-module-concurrency/105668)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 10\
**Last updated:** [October 30, 2017, 9:19am UTC](https://discuss.elastic.co/t/snapshot-and-restore-module-concurrency/105668 "2017-10-30T09:19:48Z")

</div>

As part of the workflow I am creating snapshot for each index (periodically) and backup it in AWS S3 repository (with Elasticsearch plugin). Those snapshots (one per index) are later on restored in a different cluster t…

---

## [Problems getting started w/ log stash and elasticsearch](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797)

<div class="topic-metadata">

**Author:** [@jcc](https://discuss.elastic.co/u/jcc)\
**Replies:** 11\
**Last updated:** [August 17, 2015, 3:00pm UTC](https://discuss.elastic.co/t/problems-getting-started-w-log-stash-and-elasticsearch/797 "2015-08-17T15:00:45Z")

</div>

Hello, I just installed elasticsearch and logstash on a Mac (Java 1.7). Elasticsearch seems to be running as expected and while logstash works with the simplest examples, it fails when I try to connect it to elastic se…

---

## [How to setup logstash to send whole xml event log to elasticsearch](https://discuss.elastic.co/t/how-to-setup-logstash-to-send-whole-xml-event-log-to-elasticsearch/252098)

<div class="topic-metadata">

**Author:** [@muru1](https://discuss.elastic.co/u/muru1)\
**Replies:** 15\
**Last updated:** [October 20, 2020, 12:26am UTC](https://discuss.elastic.co/t/how-to-setup-logstash-to-send-whole-xml-event-log-to-elasticsearch/252098 "2020-10-20T00:26:04Z")

</div>

I am trying to setup logstash to send xml event logs to elasticseach, however it is inserting each line as a separate entry into es, I tried using multiline codec but its buffering that many lines and inserting into es i…

---

## [Elasticsearch-Exporter - All Data](https://discuss.elastic.co/t/elasticsearch-exporter-all-data/26981)

<div class="topic-metadata">

**Author:** [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Replies:** 10\
**Last updated:** [August 10, 2015, 10:31am UTC](https://discuss.elastic.co/t/elasticsearch-exporter-all-data/26981 "2015-08-10T10:31:44Z")

</div>

Hi, I’ve been using the Elasticsearch-Exporter (https://github.com/mallocator/Elasticsearch-Exporter) to migrate indexes across the network to other nodes and I’ve been trying to test exporting the indices to file but am…

---

## [How to perform authentication in kibana?](https://discuss.elastic.co/t/how-to-perform-authentication-in-kibana/98630)

<div class="topic-metadata">

**Author:** [@abhisek](https://discuss.elastic.co/u/abhisek)\
**Replies:** 23\
**Last updated:** [September 7, 2017, 4:55am UTC](https://discuss.elastic.co/t/how-to-perform-authentication-in-kibana/98630 "2017-09-07T04:55:42Z")

</div>

Hi team , Can X-pack authenticate kibana for multiple users ? As i am new to Kibana, so need assistance to make authentication possible in kibana.

---

## [Elasticsearch java 8 check fail](https://discuss.elastic.co/t/elasticsearch-java-8-check-fail/97762)

<div class="topic-metadata">

**Author:** [@Cristian\_Jadox](https://discuss.elastic.co/u/Cristian_Jadox)\
**Replies:** 9\
**Last updated:** [August 21, 2017, 3:09pm UTC](https://discuss.elastic.co/t/elasticsearch-java-8-check-fail/97762 "2017-08-21T15:09:54Z")

</div>

Hi, I’m trying to run elasticsearch on my mac but it fails due to java version incompatibility. The thing is that I have the latest version of Java installed on my system ( 8 Update 144 ) but I keep getting this error …

---

## [Extremely Large Documents: Querying and Dealing with](https://discuss.elastic.co/t/extremely-large-documents-querying-and-dealing-with/284393)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 16\
**Last updated:** [September 30, 2021, 11:19am UTC](https://discuss.elastic.co/t/extremely-large-documents-querying-and-dealing-with/284393 "2021-09-30T11:19:31Z")

</div>

We are in a situation where extremely large documents were indexed (to text fields) and our ElasticSearch instance has been going down/crazy recently with out of disk and out of memory. We've also run into HTTP response …

---

## [How to make the "Discover" tab data to Table view](https://discuss.elastic.co/t/how-to-make-the-discover-tab-data-to-table-view/257001)

<div class="topic-metadata">

**Author:** [@qub123](https://discuss.elastic.co/u/qub123)\
**Replies:** 12\
**Last updated:** [December 3, 2020, 4:14pm UTC](https://discuss.elastic.co/t/how-to-make-the-discover-tab-data-to-table-view/257001 "2020-12-03T16:14:43Z")

</div>

Hi, Right now the default looks of the discover mode is not in table view, just wondering is there a setting to change the documents show in a table view, instead of document per document ?

---

## [Remove fields that match regex](https://discuss.elastic.co/t/remove-fields-that-match-regex/132830)

<div class="topic-metadata">

**Author:** [@M\_B\_I](https://discuss.elastic.co/u/M_B_I)\
**Replies:** 12\
**Last updated:** [June 14, 2018, 3:14pm UTC](https://discuss.elastic.co/t/remove-fields-that-match-regex/132830 "2018-06-14T15:14:49Z")

</div>

Hi! Could someone tell me , can I delete a few fields that match regex expression? I get snmp traps and in my filter I set all information that I need to a specific fields, so I don't need anymore fields that starts wi…

---

## [Noob help with Kibana, Mappings & Nested Objects in Arrays](https://discuss.elastic.co/t/noob-help-with-kibana-mappings-nested-objects-in-arrays/104884)

<div class="topic-metadata">

**Author:** [@jchannon](https://discuss.elastic.co/u/jchannon)\
**Replies:** 16\
**Last updated:** [November 3, 2017, 4:18pm UTC](https://discuss.elastic.co/t/noob-help-with-kibana-mappings-nested-objects-in-arrays/104884 "2017-11-03T16:18:09Z")

</div>

Hi, I'm investigating using Kibana and giving this to our customers as an analytics tool for the data our app produces. Currently I have data that looks like this: Github GIST - data.json I am using the NEST .NET Clie…

---

## [Почему не работает dfs\_query\_then\_fetch?](https://discuss.elastic.co/t/dfs-query-then-fetch/262474)

<div class="topic-metadata">

**Author:** [@GreenX](https://discuss.elastic.co/u/GreenX)\
**Replies:** 23\
**Last updated:** [February 4, 2021, 8:42pm UTC](https://discuss.elastic.co/t/dfs-query-then-fetch/262474 "2021-02-04T20:42:05Z")

</div>

Давным-давно, была проблема: выполняя один и тот же запрос мы получали разный список документов. Оказалось из-за близости \_score два документна меняли местами в зависимости от того на какой шард уйдет запрос. Тогда я из…

---

## [Kibana ui not loading](https://discuss.elastic.co/t/kibana-ui-not-loading/131607)

<div class="topic-metadata">

**Author:** [@anuj6664](https://discuss.elastic.co/u/anuj6664)\
**Replies:** 12\
**Last updated:** [May 16, 2018, 5:04am UTC](https://discuss.elastic.co/t/kibana-ui-not-loading/131607 "2018-05-16T05:04:00Z")

</div>

\[2018-05-13T05:42:01,336\]\[WARN \]\[r.suppressed \] path: /.kibana/\_search, params: {size=10000, index=.kibana, from=0} org.elasticsearch.action.search.SearchPhaseExecutionException: all shards failed at org.el…

---

## [Unable to load geoip in elasticsearch/logstash](https://discuss.elastic.co/t/unable-to-load-geoip-in-elasticsearch-logstash/175529)

<div class="topic-metadata">

**Author:** [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Replies:** 27\
**Last updated:** [April 7, 2019, 1:44am UTC](https://discuss.elastic.co/t/unable-to-load-geoip-in-elasticsearch-logstash/175529 "2019-04-07T01:44:04Z")

</div>

Dear All, I am new to ELK stack. I am unable to add/load geoip details into my elasticsearch/logstash. I have installed ELK 6.7 version + filebeat & metricbeat, I tried using /usr/share/elasticsearch/bin/elasticsearch-…

---

## [Topbeat beat.hostname analyzed](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930)

<div class="topic-metadata">

**Author:** [@jderieg](https://discuss.elastic.co/u/jderieg)\
**Replies:** 10\
**Last updated:** [February 13, 2016, 1:41am UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930 "2016-02-13T01:41:12Z")

</div>

Hi there, I noticed that after I load in the topbeat template, and create an index pattern for topbeat, the 'beat.hostname' field is analyzed. I'm kind of a noob with beats/elasticsearch... could someone help me to cha…

---

## [How to get Unique Records](https://discuss.elastic.co/t/how-to-get-unique-records/255029)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 15\
**Last updated:** [November 12, 2020, 12:23pm UTC](https://discuss.elastic.co/t/how-to-get-unique-records/255029 "2020-11-12T12:23:21Z")

</div>

Hello Team I am using Elasticsearch version 7.8.0. I am having an INDEX in which there is one field. "userId" : { "type" : "text", "fields" : { "keyword" : { "type" : "ke…

---

## [Two way substring search](https://discuss.elastic.co/t/two-way-substring-search/331052)

<div class="topic-metadata">

**Author:** [@Andr](https://discuss.elastic.co/u/Andr)\
**Replies:** 9\
**Last updated:** [May 2, 2023, 12:28pm UTC](https://discuss.elastic.co/t/two-way-substring-search/331052 "2023-05-02T12:28:48Z")

</div>

Hello! I would like to implement a search which returns a document if a query string is substring of the document field or the document field is substring of the query string. For example, I have a document with a text…

---

## [Elastic defend is not working](https://discuss.elastic.co/t/elastic-defend-is-not-working/358737)

<div class="topic-metadata">

**Author:** [@Intruder](https://discuss.elastic.co/u/Intruder)\
**Replies:** 46\
**Last updated:** [May 8, 2024, 2:45pm UTC](https://discuss.elastic.co/t/elastic-defend-is-not-working/358737 "2024-05-08T14:45:14Z")

</div>

In the beginning , it works fine , BUT AFTER I changed the IP of the machine(which also disconnected the internet) , It starts unhealthy with this issue . I changed the yml file , and fleet server IP , but can no…

---

## [Hourly displaying of data](https://discuss.elastic.co/t/hourly-displaying-of-data/278695)

<div class="topic-metadata">

**Author:** [@cool999](https://discuss.elastic.co/u/cool999)\
**Replies:** 10\
**Last updated:** [July 16, 2021, 3:29pm UTC](https://discuss.elastic.co/t/hourly-displaying-of-data/278695 "2021-07-16T15:29:02Z")

</div>

Hi Team, I have log file from which I am filtering specific words and I want to create curl request that will show results based on each hours of current day. In below screenshot, when I select Date histogram on @times…

---

## [Rename Field in Index (index, visu, dashboard, etc...)](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881)

<div class="topic-metadata">

**Author:** [@GitsBdr](https://discuss.elastic.co/u/GitsBdr)\
**Replies:** 10\
**Last updated:** [December 12, 2018, 4:04pm UTC](https://discuss.elastic.co/t/rename-field-in-index-index-visu-dashboard-etc/159881 "2018-12-12T16:04:38Z")

</div>

Hi all, Thanks in advance for the help! I want to rename a field in an index 'everywhere'. By everywhere, I mean that I don't want my graphs and dashboard based on this field to be impacted, I don't know if there is a…

---

## [MISP and Elastic Security](https://discuss.elastic.co/t/misp-and-elastic-security/257644)

<div class="topic-metadata">

**Author:** [@Ameer\_Mukadam](https://discuss.elastic.co/u/Ameer_Mukadam)\
**Replies:** 15\
**Last updated:** [January 30, 2021, 8:45am UTC](https://discuss.elastic.co/t/misp-and-elastic-security/257644 "2021-01-30T08:45:20Z")

</div>

I have a use case where I want to index attributes from MISP to Elasticsearch for using the new Threat Matching rule in Elastic Security 7.10. Everything is working fine but the issue is when I try to ingest more attrib…

---

## [Search UI Dynamically Change Facets Search parameters From External Component](https://discuss.elastic.co/t/search-ui-dynamically-change-facets-search-parameters-from-external-component/230882)

<div class="topic-metadata">

**Author:** [@M\_M](https://discuss.elastic.co/u/M_M)\
**Replies:** 10\
**Last updated:** [May 11, 2020, 12:16pm UTC](https://discuss.elastic.co/t/search-ui-dynamically-change-facets-search-parameters-from-external-component/230882 "2020-05-11T12:16:25Z")

</div>

Hi, I am trying to dynamically modify the geo center in the range search for the National Parks codesandbox example. I am trying to changing the geo-center coordinate for the range search via custom component with se…

---

## [Help needed for scripting for runtime fields](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 26\
**Last updated:** [March 7, 2023, 3:35pm UTC](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001 "2023-03-07T15:35:29Z")

</div>

Hello everyone, I am completely new to Elastic and scripting in general. I was told to install ElasticStack on our network for monitoring purposes. I now have both Elasticsearch and Kibana installed. I am currently try…

---

## [Logstash elasticsearch error with x pack](https://discuss.elastic.co/t/logstash-elasticsearch-error-with-x-pack/89556)

<div class="topic-metadata">

**Author:** [@raghvendra](https://discuss.elastic.co/u/raghvendra)\
**Replies:** 11\
**Last updated:** [June 16, 2017, 7:45am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-error-with-x-pack/89556 "2017-06-16T07:45:51Z")

</div>

Hi.. Can anyone help me in solving this error .. I have been trying to solve this for four days .. I am new to ELK stack so. I have installed x pack in my ELK stack . Elasticsearch and kibana is working fine but when I…

---

## [Фильтр nGram на синонимы](https://discuss.elastic.co/t/ngram/36173)

<div class="topic-metadata">

**Author:** [@MaWr](https://discuss.elastic.co/u/MaWr)\
**Replies:** 16\
**Last updated:** [January 19, 2016, 6:43am UTC](https://discuss.elastic.co/t/ngram/36173 "2016-01-19T06:43:53Z")

</div>

Добрый день! Ситуация следующая. Был следующий индекс: { "settings":{ "analysis":{ "analyzer":{ "str\_search\_analyzer":{ "tokenizer":"keyword", "filter":\["lo…

---

## [Cluster nodes unable to communicate with each other](https://discuss.elastic.co/t/cluster-nodes-unable-to-communicate-with-each-other/176644)

<div class="topic-metadata">

**Author:** [@rao-uno](https://discuss.elastic.co/u/rao-uno)\
**Replies:** 18\
**Last updated:** [April 15, 2019, 10:37am UTC](https://discuss.elastic.co/t/cluster-nodes-unable-to-communicate-with-each-other/176644 "2019-04-15T10:37:16Z")

</div>

Hi, I have a cluster of 3 nodes. The nodes storage got full (91%) and no new index were being created. But then my servers hanged and had to be rebooted. Now when I am starting the cluster, the cluster is not able to i…

---

## [Winlogbeat v5 fail to start after upgrade](https://discuss.elastic.co/t/winlogbeat-v5-fail-to-start-after-upgrade/47483)

<div class="topic-metadata">

**Author:** [@tuankun](https://discuss.elastic.co/u/tuankun)\
**Replies:** 11\
**Last updated:** [September 1, 2016, 9:06pm UTC](https://discuss.elastic.co/t/winlogbeat-v5-fail-to-start-after-upgrade/47483 "2016-09-01T21:06:27Z")

</div>

Hi Sir, I installed winlogbeat 1.1.2 on windows server 2012 R2, since it could not generate event\_data field ,I uninstalled the winlogbeat service using uninstall-service-winlogbeat.ps1,and replaced it with winlogbeat v…

---

## [Logstash going OOM - help confirming issue](https://discuss.elastic.co/t/logstash-going-oom-help-confirming-issue/56902)

<div class="topic-metadata">

**Author:** [@David\_McClain](https://discuss.elastic.co/u/David_McClain)\
**Replies:** 19\
**Last updated:** [August 7, 2016, 2:33pm UTC](https://discuss.elastic.co/t/logstash-going-oom-help-confirming-issue/56902 "2016-08-07T14:33:52Z")

</div>

I've recently begun having problems where logstash continues to go out of memory a few seconds (or maybe a minute) after startup. I have an idea of what may be happening, but I'm hoping that some of the more seasoned pro…

---

## [Split json message into a new column in kibana table](https://discuss.elastic.co/t/split-json-message-into-a-new-column-in-kibana-table/224565)

<div class="topic-metadata">

**Author:** [@ARoy](https://discuss.elastic.co/u/ARoy)\
**Replies:** 12\
**Last updated:** [March 24, 2020, 3:07pm UTC](https://discuss.elastic.co/t/split-json-message-into-a-new-column-in-kibana-table/224565 "2020-03-24T15:07:28Z")

</div>

Hi, I need to add new column in kibana from the json message. The message is as follows : {"results":\[{"gender":"female","name":{"title":"Ms","first":"Eden","last":"Morel"},"location":{"street":{"number":1412,"name":"R…

---

## [Parse and ingest email files using logstack -- help needed](https://discuss.elastic.co/t/parse-and-ingest-email-files-using-logstack-help-needed/119141)

<div class="topic-metadata">

**Author:** [@abildgaard](https://discuss.elastic.co/u/abildgaard)\
**Replies:** 16\
**Last updated:** [February 9, 2018, 9:44pm UTC](https://discuss.elastic.co/t/parse-and-ingest-email-files-using-logstack-help-needed/119141 "2018-02-09T21:44:20Z")

</div>

I have multiple files each containing a single email in the following format: Message-ID: \<18435268.1075855378308.JavaMail.evans@thyme\> Date: Mon, 7 May 2001 12:28:00 -0700 (PDT) From: phillip@xxx.com To: matthew@xxx.co…

---

## [Plugin/ingest-NLP semantic enrichment design and pluggability vs Spark UIMA?](https://discuss.elastic.co/t/plugin-ingest-nlp-semantic-enrichment-design-and-pluggability-vs-spark-uima/43399)

<div class="topic-metadata">

**Author:** [@luto](https://discuss.elastic.co/u/luto)\
**Replies:** 10\
**Last updated:** [March 4, 2016, 8:11am UTC](https://discuss.elastic.co/t/plugin-ingest-nlp-semantic-enrichment-design-and-pluggability-vs-spark-uima/43399 "2016-03-04T08:11:45Z")

</div>

The core of my work is on semantic enrichment through various NLP techniques (e.g. Annotators or Taggers, being implemented using statistical methods of various kinds, from Bayesian to rule based and gazetteer /ontology …

---

## [No results found - Kibana - Localhost not sending logs](https://discuss.elastic.co/t/no-results-found-kibana-localhost-not-sending-logs/64132)

<div class="topic-metadata">

**Author:** [@saunderstd](https://discuss.elastic.co/u/saunderstd)\
**Replies:** 22\
**Last updated:** [November 1, 2016, 12:32pm UTC](https://discuss.elastic.co/t/no-results-found-kibana-localhost-not-sending-logs/64132 "2016-11-01T12:32:29Z")

</div>

Morning, I am having a issue with the localhost server populating Kibana. I have been trying for two days now and stepping through the config files double checking everything. The localhost OS is Fedora 24. Would someon…

---

## [Data delay in ELK](https://discuss.elastic.co/t/data-delay-in-elk/72472)

<div class="topic-metadata">

**Author:** [@sundar1](https://discuss.elastic.co/u/sundar1)\
**Replies:** 10\
**Last updated:** [January 25, 2017, 3:23pm UTC](https://discuss.elastic.co/t/data-delay-in-elk/72472 "2017-01-25T15:23:25Z")

</div>

Hi, Everyday we are getting close to 2 TB data and per sec 70K events from Kafka to ELK. The below are my ELK and hardware setup. 15 logstash servers(36 GM RAM, 6 CPU) 25 data nodes(36 GM RAM, 6 CPU) and each data node h…

[Previous page](https://discuss.elastic.co/top.md?page=59&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=61&per_page=50&period=all)
