# Top

**URL:** https://discuss.elastic.co/top.md?page=62&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 63

---

## [Сортировка по началу запроса](https://discuss.elastic.co/t/topic/198575)

<div class="topic-metadata">

**Author:** [@111206](https://discuss.elastic.co/u/111206)\
**Replies:** 19\
**Last updated:** [September 12, 2019, 7:22pm UTC](https://discuss.elastic.co/t/topic/198575 "2019-09-12T19:22:46Z")

</div>

Использую эластик как поиск вместо БД. Не могу добиться правильной релевантности результатов и не очень понимаю в какую сторону копать. Нужна помошь в этом понимании. Есть поле "наименование" и хочется видеть по нему р…

---

## [ElasticSearch performance trouble when indexing data](https://discuss.elastic.co/t/elasticsearch-performance-trouble-when-indexing-data/268745)

<div class="topic-metadata">

**Author:** [@nicolaipre](https://discuss.elastic.co/u/nicolaipre)\
**Replies:** 10\
**Last updated:** [March 31, 2021, 11:01am UTC](https://discuss.elastic.co/t/elasticsearch-performance-trouble-when-indexing-data/268745 "2021-03-31T11:01:41Z")

</div>

Hi. I have about 4 TB of data I want to index in Elasticsearch. The amount of data per index will vary, depending on the source data file. These are only static files containing old data that will be ingested and made s…

---

## [Help for grok RFC3339 pattern](https://discuss.elastic.co/t/help-for-grok-rfc3339-pattern/105274)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 12\
**Last updated:** [October 26, 2017, 3:20pm UTC](https://discuss.elastic.co/t/help-for-grok-rfc3339-pattern/105274 "2017-10-26T15:20:45Z")

</div>

Hi i need use millisecond into syslog file, i have commented out the "RSYSLOG\_TraditionalFileFormat" template fron rsyslog.conf and now i have timestamp in RFC3339 format, i need parse this timestamp but I do not know wh…

---

## [Filebeat log fails to publish events](https://discuss.elastic.co/t/filebeat-log-fails-to-publish-events/324127)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 9\
**Last updated:** [February 1, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-log-fails-to-publish-events/324127 "2023-02-01T14:23:15Z")

</div>

Hello, Our ELK cluster has been stable for a long time, but recently we have started seeing the following error in the filebeat log: ERROR logstash/async.go:256 Failed to publish events caused by: write tcp xx.xx.x…

---

## [Shard reallocation stops](https://discuss.elastic.co/t/shard-reallocation-stops/103137)

<div class="topic-metadata">

**Author:** [@phil.lavin](https://discuss.elastic.co/u/phil.lavin)\
**Replies:** 10\
**Last updated:** [October 10, 2017, 5:50pm UTC](https://discuss.elastic.co/t/shard-reallocation-stops/103137 "2017-10-10T17:50:31Z")

</div>

Very confused here. Just upgraded the RAM in one node in a 2 node cluster. Node was shut down cleanly and brought up cleanly after the upgrade. When the node is started, shards start reallocating from the other node. How…

---

## [How to set more query to elasticsearch via java API](https://discuss.elastic.co/t/how-to-set-more-query-to-elasticsearch-via-java-api/51841)

<div class="topic-metadata">

**Author:** [@stefansaye](https://discuss.elastic.co/u/stefansaye)\
**Replies:** 13\
**Last updated:** [June 5, 2016, 6:25pm UTC](https://discuss.elastic.co/t/how-to-set-more-query-to-elasticsearch-via-java-api/51841 "2016-06-05T18:25:41Z")

</div>

Hi I am trying to do query on elastic search by following the sql query and I want to implement same logic using Java API select \* from log where name is "jay" and \[all\_field\_value\] LIKE "%keyword%" and @datetime betwe…

---

## [Repackaging beats .deb files - service won't start](https://discuss.elastic.co/t/repackaging-beats-deb-files-service-wont-start/37898)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 19\
**Last updated:** [November 23, 2016, 1:33am UTC](https://discuss.elastic.co/t/repackaging-beats-deb-files-service-wont-start/37898 "2016-11-23T01:33:40Z")

</div>

Hi all, I've extracted and repackaged the official .deb files for filebeat, packetbeat, and topbeat, so I can include my own configs and certs and deploy via puppet. I've also added my own postinst and prerm files to up…

---

## [.kibana Index yellow (Shard is UNASSIGNED) - why isn't it recoverying](https://discuss.elastic.co/t/kibana-index-yellow-shard-is-unassigned-why-isnt-it-recoverying/67361)

<div class="topic-metadata">

**Author:** [@guenther](https://discuss.elastic.co/u/guenther)\
**Replies:** 10\
**Last updated:** [December 16, 2016, 2:39pm UTC](https://discuss.elastic.co/t/kibana-index-yellow-shard-is-unassigned-why-isnt-it-recoverying/67361 "2016-12-16T14:39:30Z")

</div>

Hi, I use ES 5.0.0 with several indices including .kibana. Because this is the smallest one, I picked it for the demonstration here, but a lot of other indices are also yellow. They are not yellow from the beginning, …

---

## [Parsing and combining different CSV files in logstash](https://discuss.elastic.co/t/parsing-and-combining-different-csv-files-in-logstash/113587)

<div class="topic-metadata">

**Author:** [@anchasis](https://discuss.elastic.co/u/anchasis)\
**Replies:** 11\
**Last updated:** [January 18, 2018, 7:44am UTC](https://discuss.elastic.co/t/parsing-and-combining-different-csv-files-in-logstash/113587 "2018-01-18T07:44:52Z")

</div>

Hi, I am looking for some pointers on how to best tackle this problem. I have two csv files, roughly with 20 columns each. One of the CSV files contains a field (hostname) that is part of a field of the second csv file …

---

## [Logstash stopping and restatŕting every 5 seconds and is using more than 600% of cpu](https://discuss.elastic.co/t/logstash-stopping-and-restatrting-every-5-seconds-and-is-using-more-than-600-of-cpu/243202)

<div class="topic-metadata">

**Author:** [@hemant\_472](https://discuss.elastic.co/u/hemant_472)\
**Replies:** 17\
**Last updated:** [August 31, 2020, 9:54am UTC](https://discuss.elastic.co/t/logstash-stopping-and-restatrting-every-5-seconds-and-is-using-more-than-600-of-cpu/243202 "2020-08-31T09:54:54Z")

</div>

Logstash is using ore than 600% cpu and is starting and stopping again, actually it is working fine for the filters but still the cpu issue is critical and i am getting below error in the logstash logs - \[2020-07-30T10…

---

## [Stack Monitoring fails to load logstash pipelines](https://discuss.elastic.co/t/stack-monitoring-fails-to-load-logstash-pipelines/281209)

<div class="topic-metadata">

**Author:** [@radovan](https://discuss.elastic.co/u/radovan)\
**Replies:** 26\
**Last updated:** [October 13, 2021, 2:29pm UTC](https://discuss.elastic.co/t/stack-monitoring-fails-to-load-logstash-pipelines/281209 "2021-10-13T14:29:46Z")

</div>

Hi, I decided to create a monitoring cluster and after a few problems at the start all is running now. There are metricbeat clients on the logstash nodes with only logstash-xpack module enabled. Logs are flowing onto th…

---

## [Configuring x-pack for SSl communication betweeen elasticsearch and logstash](https://discuss.elastic.co/t/configuring-x-pack-for-ssl-communication-betweeen-elasticsearch-and-logstash/88985)

<div class="topic-metadata">

**Author:** [@vinod\_hy](https://discuss.elastic.co/u/vinod_hy)\
**Replies:** 15\
**Last updated:** [June 15, 2017, 6:04am UTC](https://discuss.elastic.co/t/configuring-x-pack-for-ssl-communication-betweeen-elasticsearch-and-logstash/88985 "2017-06-15T06:04:22Z")

</div>

Please help me in using x-pack. My Requirement: My setup is kibana and elasticsearch resides on one machine. Logstash and filebeat resides on another machine. My requirement is to secure the connection with SSL certif…

---

## [Cannot make Logstash read syslog](https://discuss.elastic.co/t/cannot-make-logstash-read-syslog/130687)

<div class="topic-metadata">

**Author:** [@AJ\_NOURI](https://discuss.elastic.co/u/AJ_NOURI)\
**Replies:** 9\
**Last updated:** [May 9, 2018, 3:03am UTC](https://discuss.elastic.co/t/cannot-make-logstash-read-syslog/130687 "2018-05-09T03:03:15Z")

</div>

Cannot make logstash receive syslog 514 traffic. ELK run successfully and listens to port 514: # docker-compose ps Name Command State Port…

---

## [Filebeat SSH dashboard failing to show events (Kibana 7.0)](https://discuss.elastic.co/t/filebeat-ssh-dashboard-failing-to-show-events-kibana-7-0/177792)

<div class="topic-metadata">

**Author:** [@bradfordaemorton](https://discuss.elastic.co/u/bradfordaemorton)\
**Replies:** 16\
**Last updated:** [May 3, 2019, 5:49am UTC](https://discuss.elastic.co/t/filebeat-ssh-dashboard-failing-to-show-events-kibana-7-0/177792 "2019-05-03T05:49:18Z")

</div>

Hi All, I have recently rebuilt my elasticsearch and kibana infrastructure to 7.0 and reinstalled my filebeat and metricbeat collectors to 7.0. I currently collect access and error logs for apache2 (I have the module …

---

## [Corrupted ElasticSearch index?](https://discuss.elastic.co/t/corrupted-elasticsearch-index/15727)

<div class="topic-metadata">

**Author:** [@bizzorama](https://discuss.elastic.co/u/bizzorama)\
**Replies:** 17\
**Last updated:** [December 22, 2014, 1:29pm UTC](https://discuss.elastic.co/t/corrupted-elasticsearch-index/15727 "2014-12-22T13:29:31Z")

</div>

Hi, I've noticed a very disturbing ElasticSearch behaviour ... my environment is: 1 logstash (1.3.2) (+ redis to store some data) + 1 elasticsearch (0.90.10) + kibana which process about 7 000 000 records per…

---

## [How to "tag" from which location data is coming from?](https://discuss.elastic.co/t/how-to-tag-from-which-location-data-is-coming-from/82795)

<div class="topic-metadata">

**Author:** [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Replies:** 17\
**Last updated:** [April 23, 2017, 8:50am UTC](https://discuss.elastic.co/t/how-to-tag-from-which-location-data-is-coming-from/82795 "2017-04-23T08:50:50Z")

</div>

Hello, Not sure if this should go here or in the elastic discussion, apologies. Lets say I got remote location A, B and C and each of them are sending their netflow, snmp and syslogs to a central ELK stack. The re…

---

## [Multiple pipelines - distributor pattern](https://discuss.elastic.co/t/multiple-pipelines-distributor-pattern/194058)

<div class="topic-metadata">

**Author:** [@penguinairlines](https://discuss.elastic.co/u/penguinairlines)\
**Replies:** 21\
**Last updated:** [August 8, 2019, 12:53pm UTC](https://discuss.elastic.co/t/multiple-pipelines-distributor-pattern/194058 "2019-08-08T12:53:25Z")

</div>

Looks like I'm having a similar problem to another thread that was closed without being resolved. I am trying to use the distributor pattern. The linked doc makes some sense, but I have a few remaining questions. Rega…

---

## [Logstash doesn't receive logs from kafka (filebeat transfer logs to kafka)](https://discuss.elastic.co/t/logstash-doesnt-receive-logs-from-kafka-filebeat-transfer-logs-to-kafka/311972)

<div class="topic-metadata">

**Author:** [@NAM\_VO](https://discuss.elastic.co/u/NAM_VO)\
**Replies:** 15\
**Last updated:** [August 19, 2022, 3:26am UTC](https://discuss.elastic.co/t/logstash-doesnt-receive-logs-from-kafka-filebeat-transfer-logs-to-kafka/311972 "2022-08-19T03:26:16Z")

</div>

Hi, I'm currently using: filebeat 8.3.3 (installed on Windows), Elasticsearch version 8.3.3 logstash 8.3.3 kafka 3.2.1 elk, kafka are on 1 server (192.168.9.70) the Windows IP which installing filebeat is 192.168.9.…

---

## [FATAL CLI ERROR YAMLException: can not read a block mapping entry; a multiline key may not be an implicit key at line 9, column 1: # Enables you to specify a path](https://discuss.elastic.co/t/fatal-cli-error-yamlexception-can-not-read-a-block-mapping-entry-a-multiline-key-may-not-be-an-implicit-key-at-line-9-column-1-enables-you-to-specify-a-path/165092)

<div class="topic-metadata">

**Author:** [@eribeltran19](https://discuss.elastic.co/u/eribeltran19)\
**Replies:** 10\
**Last updated:** [January 21, 2019, 9:52pm UTC](https://discuss.elastic.co/t/fatal-cli-error-yamlexception-can-not-read-a-block-mapping-entry-a-multiline-key-may-not-be-an-implicit-key-at-line-9-column-1-enables-you-to-specify-a-path/165092 "2019-01-21T21:52:00Z")

</div>

Buen dia tengo el error FATAL CLI ERROR YAMLException: can not read a block mapping entry; a multiline key may not be an implicit key at line 9, column 1: # Enables you to specify a path ... at generateError (/usr/s…

---

## [Custom fields are not stored in the message root](https://discuss.elastic.co/t/custom-fields-are-not-stored-in-the-message-root/33585)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 11\
**Last updated:** [March 9, 2016, 9:27am UTC](https://discuss.elastic.co/t/custom-fields-are-not-stored-in-the-message-root/33585 "2016-03-09T09:27:00Z")

</div>

Hi there, As per filebeat: prospectors: paths: - /var/log/foo.log field - Pastebin.com Adding custom fields under prospectors: fields: does not give the expected result. Any custom fields are added under a field named…

---

## [Языковые анализаторы, синонимы, nGram](https://discuss.elastic.co/t/ngram/116096)

<div class="topic-metadata">

**Author:** [@v.ishchenko](https://discuss.elastic.co/u/v.ishchenko)\
**Replies:** 12\
**Last updated:** [February 1, 2018, 11:27pm UTC](https://discuss.elastic.co/t/ngram/116096 "2018-02-01T23:27:15Z")

</div>

Всем привет, кто знает как лучше реализовать поиск с учетом русского, английского языков (тобиж нескольких), и применения синонимов, nGram фильтра итд. Стоит ли выделить анализатор для языков/синонимов/nGram отдельно (и…

---

## [Not able to connect to elastic from kibana](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652)

<div class="topic-metadata">

**Author:** [@chitra\_perumal](https://discuss.elastic.co/u/chitra_perumal)\
**Replies:** 16\
**Last updated:** [September 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652 "2023-09-15T08:00:12Z")

</div>

Hello, I am trying to set up the OIDC authentication for Kibana in SSO . I have followed the steps from elastic guide. The CA and HTTP certificates are created as per the details provided in above link. The elastic is…

---

## [Filter search by score](https://discuss.elastic.co/t/filter-search-by-score/208322)

<div class="topic-metadata">

**Author:** [@AlejandroNextChance](https://discuss.elastic.co/u/AlejandroNextChance)\
**Replies:** 16\
**Last updated:** [December 13, 2019, 6:49am UTC](https://discuss.elastic.co/t/filter-search-by-score/208322 "2019-12-13T06:49:22Z")

</div>

I’d like to perform a search, but only get back search results that have a score greater-than 1 for instance. Is this possible?

---

## [Infrastructure d'Elasticsearch](https://discuss.elastic.co/t/infrastructure-delasticsearch/54529)

<div class="topic-metadata">

**Author:** [@Fabien\_Sarlat](https://discuss.elastic.co/u/Fabien_Sarlat)\
**Replies:** 17\
**Last updated:** [July 6, 2016, 6:11am UTC](https://discuss.elastic.co/t/infrastructure-delasticsearch/54529 "2016-07-06T06:11:38Z")

</div>

Bonjour à tous ! J'ai quelques questions concernant l’installation et le management d'ES :smiley: J'ai pour l'instant un site web hébergé sur un mutualisé et je vais changer d'architecture (j'hésite entre soit google…

---

## [Display all documents with duplicated value of a given field](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246)

<div class="topic-metadata">

**Author:** [@jcaballero](https://discuss.elastic.co/u/jcaballero)\
**Replies:** 9\
**Last updated:** [May 9, 2019, 12:54am UTC](https://discuss.elastic.co/t/display-all-documents-with-duplicated-value-of-a-given-field/180246 "2019-05-09T00:54:02Z")

</div>

Hi Kibana 5.4.1 Let's say I have this type of data in ElasticSearch: name \<other fields\> aa ... bb ... cc ... bb ... dd ... ee ... ff ... aa ... gg ... and so on. I would like to know if there is…

---

## [Support Needed on Metricbeat setup issue](https://discuss.elastic.co/t/support-needed-on-metricbeat-setup-issue/162748)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 31\
**Last updated:** [January 22, 2019, 3:40am UTC](https://discuss.elastic.co/t/support-needed-on-metricbeat-setup-issue/162748 "2019-01-22T03:40:46Z")

</div>

Hi all, below is my metricbeat.yml file. Error msg when running "metricbeat setup": Did not find expected key. \` ###################### Metricbeat Configuration Example ####################### # This file is an e…

---

## [Sync.go:85: ERR Failed to publish events caused by: EOF](https://discuss.elastic.co/t/sync-go-85-err-failed-to-publish-events-caused-by-eof/99435)

<div class="topic-metadata">

**Author:** [@ISPHOST](https://discuss.elastic.co/u/ISPHOST)\
**Replies:** 10\
**Last updated:** [September 12, 2017, 12:30pm UTC](https://discuss.elastic.co/t/sync-go-85-err-failed-to-publish-events-caused-by-eof/99435 "2017-09-12T12:30:06Z")

</div>

Hello. I am using Elasticsearch, Logstash, Kibana Docker images and have some troubles. Error in the filebeat container: 2017/09/05 13:10:36.973731 tls.go:200: WARN SSL/TLS verifications disabled. 2017/09/05 13:10:41.…

---

## [Very First Elastic Install... Elastic fails to determine health](https://discuss.elastic.co/t/very-first-elastic-install-elastic-fails-to-determine-health/356469)

<div class="topic-metadata">

**Author:** [@Technolust1](https://discuss.elastic.co/u/Technolust1)\
**Replies:** 10\
**Last updated:** [April 1, 2024, 5:31pm UTC](https://discuss.elastic.co/t/very-first-elastic-install-elastic-fails-to-determine-health/356469 "2024-04-01T17:31:05Z")

</div>

I'm new to ELK.. When I get to the step for checking if Elastic is running properly I get an error unable to authenticate. I realized I forgot to write down the password during the install... Now I'm trying to run elasti…

---

## [Elasticsearch highlighting](https://discuss.elastic.co/t/elasticsearch-highlighting/29773)

<div class="topic-metadata">

**Author:** [@evvo](https://discuss.elastic.co/u/evvo)\
**Replies:** 12\
**Last updated:** [September 24, 2015, 8:21am UTC](https://discuss.elastic.co/t/elasticsearch-highlighting/29773 "2015-09-24T08:21:39Z")

</div>

im using elasticsearch within a C# project using the NEST API. i want to show the searched terms as highlights in the results page but dont know how i handle the display of them. All the docs tell me how to set up the hi…

---

## [Call a python script from ElasticSearch daily](https://discuss.elastic.co/t/call-a-python-script-from-elasticsearch-daily/146557)

<div class="topic-metadata">

**Author:** [@aashishgahlawat](https://discuss.elastic.co/u/aashishgahlawat)\
**Replies:** 9\
**Last updated:** [August 31, 2018, 5:34pm UTC](https://discuss.elastic.co/t/call-a-python-script-from-elasticsearch-daily/146557 "2018-08-31T17:34:12Z")

</div>

I am using logstash with scheduling to load data from database to ElasticSearch daily, now I have a script that will do some machine learning stuff on my index, how can I call a python script whenever an index is updated…

---

## [35 shards but maxing out JVM heap](https://discuss.elastic.co/t/35-shards-but-maxing-out-jvm-heap/121474)

<div class="topic-metadata">

**Author:** [@Callahan](https://discuss.elastic.co/u/Callahan)\
**Replies:** 11\
**Last updated:** [March 8, 2018, 6:20pm UTC](https://discuss.elastic.co/t/35-shards-but-maxing-out-jvm-heap/121474 "2018-03-08T18:20:55Z")

</div>

Hi, I've been experiencing long term issues with Elasticsearch and one of my 3 node setups running out of heap space (the specific node varies each time it seems). The specifics of my setup are as follows: OS: Windows…

---

## [Frozen Tier heap memory requirements](https://discuss.elastic.co/t/frozen-tier-heap-memory-requirements/305546)

<div class="topic-metadata">

**Author:** [@schapman](https://discuss.elastic.co/u/schapman)\
**Replies:** 10\
**Last updated:** [May 25, 2022, 7:20pm UTC](https://discuss.elastic.co/t/frozen-tier-heap-memory-requirements/305546 "2022-05-25T19:20:42Z")

</div>

This suggests keeping to less than 20 shards / GB of heap. But this blog post about the frozen tier seems to (if I read it correctly) benchmarked a test case with 12500 shards on a node with 29GB of heap for a ratio of …

---

## [Filebeat 6.4.2 Read line error: invalid CRI log format; File](https://discuss.elastic.co/t/filebeat-6-4-2-read-line-error-invalid-cri-log-format-file/154506)

<div class="topic-metadata">

**Author:** [@justinw](https://discuss.elastic.co/u/justinw)\
**Replies:** 17\
**Last updated:** [December 5, 2018, 9:11pm UTC](https://discuss.elastic.co/t/filebeat-6-4-2-read-line-error-invalid-cri-log-format-file/154506 "2018-12-05T21:11:33Z")

</div>

Hi, I've seen this: https://github.com/elastic/beats/issues/8175, and it looks like the fix is merged into the 6.4.2 release. However, I'm still seeing this error frequently. 2018-10-29T18:58:06.818Z INFO log/harvester…

---

## [Kibana not running as a service](https://discuss.elastic.co/t/kibana-not-running-as-a-service/328829)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 12\
**Last updated:** [March 30, 2023, 8:35am UTC](https://discuss.elastic.co/t/kibana-not-running-as-a-service/328829 "2023-03-30T08:35:51Z")

</div>

Hello everyone, I've installed ELK stack on an Ubuntu Server 22.04. My problem is that I've start elasticsearch with "systemctl start elasticsearch.service" because bin/elasticsearch does not work, I always have an err…

---

## [Change thread pool search queue\_size? yes or not?](https://discuss.elastic.co/t/change-thread-pool-search-queue-size-yes-or-not/97284)

<div class="topic-metadata">

**Author:** [@mitabrev](https://discuss.elastic.co/u/mitabrev)\
**Replies:** 12\
**Last updated:** [September 6, 2017, 8:20am UTC](https://discuss.elastic.co/t/change-thread-pool-search-queue-size-yes-or-not/97284 "2017-09-06T08:20:52Z")

</div>

Got one question. Working on my elastic stack. Basically it’s “developing production”. Got one server with 16GB of RAM, 4 CPUs, ELK 5.4.0. No cluster or extra nodes. Got no problems with adding data and searching, the …

---

## [ElasticSearch on NAS](https://discuss.elastic.co/t/elasticsearch-on-nas/309156)

<div class="topic-metadata">

**Author:** [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Replies:** 17\
**Last updated:** [July 10, 2022, 6:48pm UTC](https://discuss.elastic.co/t/elasticsearch-on-nas/309156 "2022-07-10T18:48:23Z")

</div>

We have deployed ES7 to an Oracle PCA environment. This consists of several Oracle VMs connected to an Oracle NAS filer. Initially, the ES data partitions were mounted as NFS, but we are hitting the filer IOPS limits. Ou…

---

## [Create multiple indexs with multiple input in logstash](https://discuss.elastic.co/t/create-multiple-indexs-with-multiple-input-in-logstash/201779)

<div class="topic-metadata">

**Author:** [@Asmaa\_Sarih](https://discuss.elastic.co/u/Asmaa_Sarih)\
**Replies:** 13\
**Last updated:** [October 2, 2019, 11:52am UTC](https://discuss.elastic.co/t/create-multiple-indexs-with-multiple-input-in-logstash/201779 "2019-10-02T11:52:33Z")

</div>

Hi Team, Can anyone help me in confugiring multiple indexes from multiple input with logstash, I am unable to create multiple index in elastic (with multiple if conditions) . One index is getting created but not both, …

---

## [Elasticsearch Benchmarking](https://discuss.elastic.co/t/elasticsearch-benchmarking/40508)

<div class="topic-metadata">

**Author:** [@Omer\_Uludag](https://discuss.elastic.co/u/Omer_Uludag)\
**Replies:** 15\
**Last updated:** [February 3, 2016, 8:38pm UTC](https://discuss.elastic.co/t/elasticsearch-benchmarking/40508 "2016-02-03T20:38:40Z")

</div>

Hello together, I am fairly new in Benchmarking and also in Benchmarking Elasticsearch. I'm using Apache JMeter in order to assess Elasticsearch's performance. Currently, I am working on the indexing performance of El…

---

## [Ingest events from ArcSight Logger to Elasticsearch using Forwarder](https://discuss.elastic.co/t/ingest-events-from-arcsight-logger-to-elasticsearch-using-forwarder/106646)

<div class="topic-metadata">

**Author:** [@undelete](https://discuss.elastic.co/u/undelete)\
**Replies:** 18\
**Last updated:** [December 12, 2017, 2:54pm UTC](https://discuss.elastic.co/t/ingest-events-from-arcsight-logger-to-elasticsearch-using-forwarder/106646 "2017-12-12T14:54:09Z")

</div>

I am using the ArcSight module to receive events from my SmartConnectors. However I have an ArcSight Logger filled with events and I would like to use the Forwarding capabilities in ArcSight Logger to forward events to E…

---

## [FS Crawler 2.4 on Apache Log4j2 Remote Code Execution (RCE) Vulnerability](https://discuss.elastic.co/t/fs-crawler-2-4-on-apache-log4j2-remote-code-execution-rce-vulnerability/291649)

<div class="topic-metadata">

**Author:** [@joseph-l.amalraj](https://discuss.elastic.co/u/joseph-l.amalraj)\
**Replies:** 16\
**Last updated:** [January 28, 2022, 6:14pm UTC](https://discuss.elastic.co/t/fs-crawler-2-4-on-apache-log4j2-remote-code-execution-rce-vulnerability/291649 "2022-01-28T18:14:21Z")

</div>

Hi David, recently we have received about Apache Log4j2 Remote Code Execution (RCE) Vulnerability. I am using FS Crawler 2.4 version along with ELK 6.8.14, we planned to do remediation plan for log4j in ELK. We would l…

---

## [GenerateCustomBeat returns error for missing github.com/elastic/beats/v7](https://discuss.elastic.co/t/generatecustombeat-returns-error-for-missing-github-com-elastic-beats-v7/223785)

<div class="topic-metadata">

**Author:** [@andrew-expanse](https://discuss.elastic.co/u/andrew-expanse)\
**Replies:** 19\
**Last updated:** [May 5, 2020, 10:19am UTC](https://discuss.elastic.co/t/generatecustombeat-returns-error-for-missing-github-com-elastic-beats-v7/223785 "2020-05-05T10:19:23Z")

</div>

Hi all, I'm attempting to create a new custom beat but am hitting some errors when using the mage GenerateCustomBeat command. mage GenerateCustomBeat Enter the beat name \[examplebeat\]: testbeat Enter your github name \[…

---

## [Failed, restarting discovery Master not available](https://discuss.elastic.co/t/failed-restarting-discovery-master-not-available/203401)

<div class="topic-metadata">

**Author:** [@nytramworc](https://discuss.elastic.co/u/nytramworc)\
**Replies:** 12\
**Last updated:** [October 22, 2019, 1:17pm UTC](https://discuss.elastic.co/t/failed-restarting-discovery-master-not-available/203401 "2019-10-22T13:17:26Z")

</div>

Hi I hope someone here can help. i've recently setup a three node cluster on AKS using the elasticsearch helm chart, using pretty much all of the default values (aprat from the obvious persistent volumes etc..) and ever…

---

## [Viewing EPS graph in Kibana](https://discuss.elastic.co/t/viewing-eps-graph-in-kibana/261665)

<div class="topic-metadata">

**Author:** [@Falikou1](https://discuss.elastic.co/u/Falikou1)\
**Replies:** 10\
**Last updated:** [January 25, 2021, 8:09pm UTC](https://discuss.elastic.co/t/viewing-eps-graph-in-kibana/261665 "2021-01-25T20:09:04Z")

</div>

I want to display a graph of the EPS in kibana. But, it displays a graph every 30 seconds over 1 hour that I defined. While I have set by second. Is there a possibility for it to display per second? Thanks for your h…

---

## [Logstash filter to drop data](https://discuss.elastic.co/t/logstash-filter-to-drop-data/106060)

<div class="topic-metadata">

**Author:** [@larryf](https://discuss.elastic.co/u/larryf)\
**Replies:** 20\
**Last updated:** [November 8, 2017, 4:12pm UTC](https://discuss.elastic.co/t/logstash-filter-to-drop-data/106060 "2017-11-08T16:12:09Z")

</div>

good morning...new user to be gentle if I don't quite say thing correctly :slight\_smile: My logstash is V 2.2.2, running on CentOS 7.3. Part of the data logstash handles is from a Progress RDBMS database log file. In …

---

## [XML encoded logs from Mcafee EPO logs to logstash](https://discuss.elastic.co/t/xml-encoded-logs-from-mcafee-epo-logs-to-logstash/104380)

<div class="topic-metadata">

**Author:** [@junaid](https://discuss.elastic.co/u/junaid)\
**Replies:** 9\
**Last updated:** [October 27, 2017, 5:02am UTC](https://discuss.elastic.co/t/xml-encoded-logs-from-mcafee-epo-logs-to-logstash/104380 "2017-10-27T05:02:40Z")

</div>

Hi my scenario is we need to collect logs from Mcafee EPO and send to our third party cloud logging platform.We have logstash server in between and its receiving logs from EPO and forwarding to logging platform.However m…

---

## [Not receiving email for CPU usage](https://discuss.elastic.co/t/not-receiving-email-for-cpu-usage/52316)

<div class="topic-metadata">

**Author:** [@iqbal\_nazir](https://discuss.elastic.co/u/iqbal_nazir)\
**Replies:** 25\
**Last updated:** [June 1, 2017, 6:00am UTC](https://discuss.elastic.co/t/not-receiving-email-for-cpu-usage/52316 "2017-06-01T06:00:04Z")

</div>

I am with watcher. I don't receive any email for cpu and memory usage. I know my email configuration in elasticsearch.yml is correct because I receive email for another watch (i.e. event\_critical\_watch). I have followed…

---

## [Configuration elasticsearch](https://discuss.elastic.co/t/configuration-elasticsearch/329506)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 10\
**Last updated:** [April 8, 2023, 11:14pm UTC](https://discuss.elastic.co/t/configuration-elasticsearch/329506 "2023-04-08T23:14:51Z")

</div>

hi i want to Start Elasticsearch in Docker by this command : docker run --name es01 --net elastic -p 9200:9200 -it docker.elastic.co/elasticsearch/elasticsearch:8.7.0 but i have this probleme : ERROR: Elasticsearch di…

---

## [Upgrade procedure from 1.4.2.to 1.5](https://discuss.elastic.co/t/upgrade-procedure-from-1-4-2-to-1-5/745)

<div class="topic-metadata">

**Author:** [@Chris\_Adams](https://discuss.elastic.co/u/Chris_Adams)\
**Replies:** 12\
**Last updated:** [August 24, 2015, 5:52pm UTC](https://discuss.elastic.co/t/upgrade-procedure-from-1-4-2-to-1-5/745 "2015-08-24T17:52:29Z")

</div>

I am currently testing an ELK stack based on 1.4.2 - what steps should I take to upgrade. Isn't this a great FAQ question? \[smile\]

---

## [ERR File reading error. Stopping harvester. Error: EOF](https://discuss.elastic.co/t/err-file-reading-error-stopping-harvester-error-eof/34764)

<div class="topic-metadata">

**Author:** [@vinod8427](https://discuss.elastic.co/u/vinod8427)\
**Replies:** 10\
**Last updated:** [November 20, 2015, 10:36am UTC](https://discuss.elastic.co/t/err-file-reading-error-stopping-harvester-error-eof/34764 "2015-11-20T10:36:55Z")

</div>

I am facing an issue with filebeat halting completely after encountering file reading error (ERR File reading error. Stopping harvester. Error: EOF). The use case is explained as below: We have some logs which are gene…

---

## [Filebeat cant send data to logstash](https://discuss.elastic.co/t/filebeat-cant-send-data-to-logstash/116341)

<div class="topic-metadata">

**Author:** [@dorinand](https://discuss.elastic.co/u/dorinand)\
**Replies:** 10\
**Last updated:** [January 23, 2018, 4:36pm UTC](https://discuss.elastic.co/t/filebeat-cant-send-data-to-logstash/116341 "2018-01-23T16:36:48Z")

</div>

I have problem to send data from \*.log file to logstash. This is filebeat configuration: filebeat.prospectors: - type: log enabled: true paths: - /home/centos/logs/\*.log filebeat.config.modules: path: ${path…

[Previous page](https://discuss.elastic.co/top.md?page=61&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=63&per_page=50&period=all)
