# Top

**URL:** https://discuss.elastic.co/top.md?page=63&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 64

---

## [Logstash json filter not working properly](https://discuss.elastic.co/t/logstash-json-filter-not-working-properly/144227)

<div class="topic-metadata">

**Author:** [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Replies:** 19\
**Last updated:** [August 15, 2018, 5:24pm UTC](https://discuss.elastic.co/t/logstash-json-filter-not-working-properly/144227 "2018-08-15T17:24:49Z")

</div>

I am using all the Latest version of ELK , we are trying to parse json using the json filter. some of the data gets filtered properly but other fields have an error saying "objects in arrays are not well supported" Which…

---

## [\[Ingest management\] Use insecure elasticsearch output managed in fleet mode for elastic agent](https://discuss.elastic.co/t/ingest-management-use-insecure-elasticsearch-output-managed-in-fleet-mode-for-elastic-agent/246022)

<div class="topic-metadata">

**Author:** [@arnold79](https://discuss.elastic.co/u/arnold79)\
**Replies:** 14\
**Last updated:** [August 26, 2020, 1:21pm UTC](https://discuss.elastic.co/t/ingest-management-use-insecure-elasticsearch-output-managed-in-fleet-mode-for-elastic-agent/246022 "2020-08-26T13:21:14Z")

</div>

I'm playing around with the new Elastic agent (7.9) and using the Ingest Manager BETA. Created several agent configs with several integrations and can them easily re-assign to an agent. Standalone the configuration goe…

---

## [High CPU usage in Monitoring Server due to ES](https://discuss.elastic.co/t/high-cpu-usage-in-monitoring-server-due-to-es/45734)

<div class="topic-metadata">

**Author:** [@vuradam](https://discuss.elastic.co/u/vuradam)\
**Replies:** 12\
**Last updated:** [April 5, 2016, 8:29pm UTC](https://discuss.elastic.co/t/high-cpu-usage-in-monitoring-server-due-to-es/45734 "2016-04-05T20:29:35Z")

</div>

I am running CentOS, and I have ELK(ElasticSearch, Logstash, Kibana) and Graphite, Graphana on this VM. When I run top I can see ES is the culprit PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 899 elasticsearch…

---

## [Transport Response Handler issue is crashing the ES and kibana 2.4.0](https://discuss.elastic.co/t/transport-response-handler-issue-is-crashing-the-es-and-kibana-2-4-0/73251)

<div class="topic-metadata">

**Author:** [@nethis](https://discuss.elastic.co/u/nethis)\
**Replies:** 13\
**Last updated:** [February 2, 2017, 4:16am UTC](https://discuss.elastic.co/t/transport-response-handler-issue-is-crashing-the-es-and-kibana-2-4-0/73251 "2017-02-02T04:16:28Z")

</div>

We are continuously facing the Transport Handler Issue in 2.4.0 and shards are becoming unassigned. This is taking longer time to assign all the shards back. I saw in a thread, that 2.4.1 fixes this issue. Can any onc…

---

## [Count over Time](https://discuss.elastic.co/t/count-over-time/293653)

<div class="topic-metadata">

**Author:** [@BoKu](https://discuss.elastic.co/u/BoKu)\
**Replies:** 11\
**Last updated:** [January 10, 2022, 3:56pm UTC](https://discuss.elastic.co/t/count-over-time/293653 "2022-01-10T15:56:23Z")

</div>

Hello and a happy new year, i ingest the Transports Logs from several Exchange Server via Logstash into Elastic. I'd like to count the TOP 10 Sender Adresses and TOP 10 Recipient Adresses in a given Timerange, like the…

---

## [Elasticsearch - shards not splitted equally](https://discuss.elastic.co/t/elasticsearch-shards-not-splitted-equally/183821)

<div class="topic-metadata">

**Author:** [@Lior\_Yakobov](https://discuss.elastic.co/u/Lior_Yakobov)\
**Replies:** 9\
**Last updated:** [June 7, 2019, 4:37am UTC](https://discuss.elastic.co/t/elasticsearch-shards-not-splitted-equally/183821 "2019-06-07T04:37:59Z")

</div>

Hello, I'm running an RPM based on-prem cluster with 21 data nodes: As shows, one node specifically has very high load, while logstashes complaining on bulk retries issue due to many writes to this node: Correspon…

---

## [How to force replica placement in cluster](https://discuss.elastic.co/t/how-to-force-replica-placement-in-cluster/23968)

<div class="topic-metadata">

**Author:** [@salat](https://discuss.elastic.co/u/salat)\
**Replies:** 10\
**Last updated:** [June 23, 2015, 8:37am UTC](https://discuss.elastic.co/t/how-to-force-replica-placement-in-cluster/23968 "2015-06-23T08:37:04Z")

</div>

Dear Folks, how is it possible to force OR prevent a node from receiving/getting replica shards? We already know this here: https://www.elastic.co/guide/en/elasticsearch/reference/current/modules-cluster.html#allocat…

---

## [Offline installation of Sense](https://discuss.elastic.co/t/offline-installation-of-sense/45876)

<div class="topic-metadata">

**Author:** [@abhijat](https://discuss.elastic.co/u/abhijat)\
**Replies:** 12\
**Last updated:** [April 8, 2016, 9:04pm UTC](https://discuss.elastic.co/t/offline-installation-of-sense/45876 "2016-04-08T21:04:45Z")

</div>

Where can I get a versioned installer of Sense for offline installation? Sense installation guide shows how we can download Sense during plugin installation phase. However, I wanted to know if Sense can be downloaded f…

---

## [Watcher with proxy issue](https://discuss.elastic.co/t/watcher-with-proxy-issue/199957)

<div class="topic-metadata">

**Author:** [@bharat1](https://discuss.elastic.co/u/bharat1)\
**Replies:** 14\
**Last updated:** [October 7, 2019, 12:17pm UTC](https://discuss.elastic.co/t/watcher-with-proxy-issue/199957 "2019-10-07T12:17:09Z")

</div>

Dear All, I am trying to configure watcher with webhook API via Kibana to create alert. I am using proxy. The webhook is failing with "failed to send request to "servicenow:443/api..." and also with a "received 503 sta…

---

## [Logstash-output-syslog full json in message?](https://discuss.elastic.co/t/logstash-output-syslog-full-json-in-message/142642)

<div class="topic-metadata">

**Author:** [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Replies:** 10\
**Last updated:** [August 2, 2018, 2:58pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-full-json-in-message/142642 "2018-08-02T14:58:30Z")

</div>

Hi, I'm sending filebeat data to logstash and from there I send a copy to elastic and another to a 3rd party SIM which only supports syslog. Is there a way to send the full json line in the message without adding a bun…

---

## [Kibana Instances "Unable to Connect to Server"](https://discuss.elastic.co/t/kibana-instances-unable-to-connect-to-server/104118)

<div class="topic-metadata">

**Author:** [@IanGabes](https://discuss.elastic.co/u/IanGabes)\
**Replies:** 11\
**Last updated:** [October 30, 2017, 6:52pm UTC](https://discuss.elastic.co/t/kibana-instances-unable-to-connect-to-server/104118 "2017-10-30T18:52:01Z")

</div>

I have installed ECE on a few machines, and have set up 2 clusters, each with a seperate kibana instance. After about a week of normal operation, I attempted to access one of the kibana dashboards, to received an "intern…

---

## [Error setting up reverse proxy for Kibana](https://discuss.elastic.co/t/error-setting-up-reverse-proxy-for-kibana/84071)

<div class="topic-metadata">

**Author:** [@ericfu88](https://discuss.elastic.co/u/ericfu88)\
**Replies:** 10\
**Last updated:** [May 9, 2017, 1:16pm UTC](https://discuss.elastic.co/t/error-setting-up-reverse-proxy-for-kibana/84071 "2017-05-09T13:16:21Z")

</div>

I try to setup a reverse nginx proxy by following advice on this thread: https://discuss.elastic.co/t/auto-authenticating-to-an-embedded-kibana-dashboard-on-elastic-co-cloud/71248/10 I am using Elastic Cloud for both K…

---

## [Shipping log files](https://discuss.elastic.co/t/shipping-log-files/35224)

<div class="topic-metadata">

**Author:** [@dhaval1](https://discuss.elastic.co/u/dhaval1)\
**Replies:** 18\
**Last updated:** [November 26, 2015, 6:07pm UTC](https://discuss.elastic.co/t/shipping-log-files/35224 "2015-11-26T18:07:41Z")

</div>

This is my first post. If it is not the right place, kindly redirect me to the correct place. I want to first ship the log files from the remote server to the central sever "as it is" with out any formatting using log…

---

## [DotNetAgent: No data has been received from agents yet](https://discuss.elastic.co/t/dotnetagent-no-data-has-been-received-from-agents-yet/241056)

<div class="topic-metadata">

**Author:** [@ImdotnetJunkie](https://discuss.elastic.co/u/ImdotnetJunkie)\
**Replies:** 16\
**Last updated:** [July 28, 2020, 10:51am UTC](https://discuss.elastic.co/t/dotnetagent-no-data-has-been-received-from-agents-yet/241056 "2020-07-28T10:51:00Z")

</div>

Kibana version: 7.8.0 Elasticsearch version: 7.8.0 APM Server version: 7.8.0 APM Agent language and version: .NET (1.6.0) Browser version: Version 78.0.3904.97 (Official Build) (64-bit) Original install method (e.g…

---

## [Config management](https://discuss.elastic.co/t/config-management/225)

<div class="topic-metadata">

**Author:** [@electrical](https://discuss.elastic.co/u/electrical)\
**Replies:** 12\
**Last updated:** [August 21, 2015, 8:07am UTC](https://discuss.elastic.co/t/config-management/225 "2015-08-21T08:07:35Z")

</div>

I'm the creator of Elastic's Puppet Modules for Elasticsearch and Logstash. As you can imagine, I care a lot about configuration management and am a Puppet fan. I'd welcome feedback from the community on the modules an…

---

## [Wrong version of elasticsearch release](https://discuss.elastic.co/t/wrong-version-of-elasticsearch-release/73135)

<div class="topic-metadata">

**Author:** [@sharongur](https://discuss.elastic.co/u/sharongur)\
**Replies:** 9\
**Last updated:** [January 30, 2017, 9:25am UTC](https://discuss.elastic.co/t/wrong-version-of-elasticsearch-release/73135 "2017-01-30T09:25:32Z")

</div>

Hi, Im new to elasticSearch but encountered a weird problem (in my opinion). I download the ES from the website, the version is 5.1.2; when i run it via the elasticsearch.bat it comes up and when i try to access it it …

---

## [Unable to get gte and lte from elastic Java API in range query](https://discuss.elastic.co/t/unable-to-get-gte-and-lte-from-elastic-java-api-in-range-query/257781)

<div class="topic-metadata">

**Author:** [@AKASH\_DUBEY1](https://discuss.elastic.co/u/AKASH_DUBEY1)\
**Replies:** 22\
**Last updated:** [December 9, 2020, 8:47am UTC](https://discuss.elastic.co/t/unable-to-get-gte-and-lte-from-elastic-java-api-in-range-query/257781 "2020-12-09T08:47:57Z")

</div>

Hi , I am using RestHighLevelclient to get data from elastic.I am using below query BoolQueryBuilder boolQuery=QueryBuilders.boolQuery(); boolQuery.must(QueryBuilders.rangeQuery("ipFromLong").gte(ipLong)); boolQuery.…

---

## [Accidentally deleted Index- Error: failed to find metadata for existing index](https://discuss.elastic.co/t/accidentally-deleted-index-error-failed-to-find-metadata-for-existing-index/197983)

<div class="topic-metadata">

**Author:** [@rajatrj16](https://discuss.elastic.co/u/rajatrj16)\
**Replies:** 9\
**Last updated:** [September 4, 2019, 11:33am UTC](https://discuss.elastic.co/t/accidentally-deleted-index-error-failed-to-find-metadata-for-existing-index/197983 "2019-09-04T11:33:07Z")

</div>

I have accidentally deleted 2-3 indexes form path: elasticsearch/data/nodes/0 And now I can't able to restart the elastic search. It gives me the error: Caused by: java.io.IOException: failed to find metadata for exis…

---

## [Elasticsearch-sql can't query unindexed field](https://discuss.elastic.co/t/elasticsearch-sql-cant-query-unindexed-field/251635)

<div class="topic-metadata">

**Author:** [@ITzhangqiang](https://discuss.elastic.co/u/ITzhangqiang)\
**Replies:** 26\
**Last updated:** [October 14, 2020, 2:52am UTC](https://discuss.elastic.co/t/elasticsearch-sql-cant-query-unindexed-field/251635 "2020-10-14T02:52:03Z")

</div>

As we know , unindexed field will store in \_source field,so we can get those unindexed fields in \_source.But Elasticsearch-sql can't get unindexed field. GET /\_sql/translate { "query":""" select \* from "view-laohu-s…

---

## [Unable to install elasticsearch on ubuntu 16.04](https://discuss.elastic.co/t/unable-to-install-elasticsearch-on-ubuntu-16-04/139225)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 9\
**Last updated:** [July 14, 2018, 1:52pm UTC](https://discuss.elastic.co/t/unable-to-install-elasticsearch-on-ubuntu-16-04/139225 "2018-07-14T13:52:49Z")

</div>

Hi Team, I am trying to install elasticsearch on Ubuntu 16.04 through ks.cfg but somehow this is not going, can someone please have a look at the error and confirm what could be th issue?

---

## [IAM credentials not recognised/used for s3 - plugins used input-s3 + codec-cloudtrail](https://discuss.elastic.co/t/iam-credentials-not-recognised-used-for-s3-plugins-used-input-s3-codec-cloudtrail/32464)

<div class="topic-metadata">

**Author:** [@plonka2000](https://discuss.elastic.co/u/plonka2000)\
**Replies:** 12\
**Last updated:** [October 27, 2015, 9:27am UTC](https://discuss.elastic.co/t/iam-credentials-not-recognised-used-for-s3-plugins-used-input-s3-codec-cloudtrail/32464 "2015-10-27T09:27:12Z")

</div>

Hi, Scenario is I am trying to use Logstash to: -pull AWS CloudTrail '.json.gz' logs from an S3 bucket using logstash-input-s3 plugin -process them using the logstash-codec-cloudtrail plugin -send them to Elasticsearch…

---

## [Filebeat not sending logs to logstash (port 5044 )](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-logstash-port-5044/264514)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 17\
**Last updated:** [February 19, 2021, 12:50pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-logstash-port-5044/264514 "2021-02-19T12:50:58Z")

</div>

My filebeat is reading the log file but it 's not sending anything to logstash Here are my filebeats.yml: filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different …

---

## [Logstash Yum Repo down?](https://discuss.elastic.co/t/logstash-yum-repo-down/84599)

<div class="topic-metadata">

**Author:** [@duxy007](https://discuss.elastic.co/u/duxy007)\
**Replies:** 12\
**Last updated:** [May 9, 2017, 1:06pm UTC](https://discuss.elastic.co/t/logstash-yum-repo-down/84599 "2017-05-09T13:06:38Z")

</div>

I am trying to install logstash from the yum repo. Instructions say to point at https://artifacts.elastic.co/packages/5.3/yum. This does not seem to be available when you go to the URL. When running the yum command I…

---

## [Winlogbeat message\_error: "The system cannot find the file specified."](https://discuss.elastic.co/t/winlogbeat-message-error-the-system-cannot-find-the-file-specified/48125)

<div class="topic-metadata">

**Author:** [@Markus\_Korn](https://discuss.elastic.co/u/Markus_Korn)\
**Replies:** 12\
**Last updated:** [August 9, 2016, 7:43am UTC](https://discuss.elastic.co/t/winlogbeat-message-error-the-system-cannot-find-the-file-specified/48125 "2016-08-09T07:43:08Z")

</div>

Hi, we have a lot of Windows Systems which are forwarding all their events to a central window system. From their I want to move the messages to logstash by using WinLogBeat. It works fine for all "Windows OS" Even…

---

## [Regexp in conditional](https://discuss.elastic.co/t/regexp-in-conditional/194223)

<div class="topic-metadata">

**Author:** [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Replies:** 9\
**Last updated:** [August 9, 2019, 12:59pm UTC](https://discuss.elastic.co/t/regexp-in-conditional/194223 "2019-08-09T12:59:22Z")

</div>

Hi, I'm trying to apply a tag based on the contents of a field. I've been trying it like this: if \[field.keyword\] =~ /^(TEST|test)-.\*$/ { mutate { add\_tag =\> \[ "TEST" \] } } } The above does not work, …

---

## [Can not be imported as a dangling index](https://discuss.elastic.co/t/can-not-be-imported-as-a-dangling-index/157644)

<div class="topic-metadata">

**Author:** [@cowensel](https://discuss.elastic.co/u/cowensel)\
**Replies:** 9\
**Last updated:** [November 21, 2018, 3:27pm UTC](https://discuss.elastic.co/t/can-not-be-imported-as-a-dangling-index/157644 "2018-11-21T15:27:16Z")

</div>

I have recently setup curator to delete old data but since then I am seeing a large increase in errors for dangling index and it relates to .Kibana which doesn't get touched by curator. \[2018-11-21T07:45:45,876\]\[WARN \]\[…

---

## [Is there a plan for lucene to expand max doc size per index?](https://discuss.elastic.co/t/is-there-a-plan-for-lucene-to-expand-max-doc-size-per-index/64690)

<div class="topic-metadata">

**Author:** [@makeyang](https://discuss.elastic.co/u/makeyang)\
**Replies:** 10\
**Last updated:** [November 4, 2016, 2:39am UTC](https://discuss.elastic.co/t/is-there-a-plan-for-lucene-to-expand-max-doc-size-per-index/64690 "2016-11-04T02:39:19Z")

</div>

init design is 2^32. but as the data is growing fast and growing big, is there a plan to make it 2^64 or something bigger than current value

---

## [Metricbeat: postgresql (module); kibana: dashboard and/or visualize is missing?](https://discuss.elastic.co/t/metricbeat-postgresql-module-kibana-dashboard-and-or-visualize-is-missing/109436)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 9\
**Last updated:** [November 28, 2017, 8:52pm UTC](https://discuss.elastic.co/t/metricbeat-postgresql-module-kibana-dashboard-and-or-visualize-is-missing/109436 "2017-11-28T20:52:20Z")

</div>

I renamed postgresql.yml.disabled to postgresql.yml inside of /etc/metricbeat/modules.d/ directory, followed by restarting of metricbeat.service per following: PostgreSQL Module | Metricbeat Reference \[6.0\] | Elastic I…

---

## [Filebeat multiline patterns not working](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478)

<div class="topic-metadata">

**Author:** [@lalu](https://discuss.elastic.co/u/lalu)\
**Replies:** 10\
**Last updated:** [May 24, 2016, 8:53pm UTC](https://discuss.elastic.co/t/filebeat-multiline-patterns-not-working/50478 "2016-05-24T20:53:34Z")

</div>

filebeat v1.2.2 (64 bit) OS: centos 6.7 multiline: --\> patterns: --\> '-' --\> pattern: (not working) multiline: --\> pattern: (working) Found detail here: (Enhanced LS Config) Is this supposed to work or feature no…

---

## [Dateparsefailure while replacing @timestamp](https://discuss.elastic.co/t/dateparsefailure-while-replacing-timestamp/87791)

<div class="topic-metadata">

**Author:** [@pratheek\_k](https://discuss.elastic.co/u/pratheek_k)\
**Replies:** 18\
**Last updated:** [June 14, 2017, 5:34am UTC](https://discuss.elastic.co/t/dateparsefailure-while-replacing-timestamp/87791 "2017-06-14T05:34:43Z")

</div>

Problem: Logs not ordered in when viewing through kibana. Goal: Replace timestamp with the time in the log messaage. So that i can order my logs in kibana Error: dataparsefailure. I dont see any other error message i…

---

## [Cannot create snapshot repository](https://discuss.elastic.co/t/cannot-create-snapshot-repository/279833)

<div class="topic-metadata">

**Author:** [@Nicole\_Hirshler](https://discuss.elastic.co/u/Nicole_Hirshler)\
**Replies:** 12\
**Last updated:** [July 28, 2021, 1:47pm UTC](https://discuss.elastic.co/t/cannot-create-snapshot-repository/279833 "2021-07-28T13:47:05Z")

</div>

I have ELK running in a docker. Directory in my home dir is mounted as volume in the docker and was defined as repo\_path in elasticsearch. The permissions are set correctly and folder owner is elasticsearch. When I try…

---

## [Need help with the grok and the date filter for parsing logs](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523)

<div class="topic-metadata">

**Author:** [@Gaurav\_Singh1](https://discuss.elastic.co/u/Gaurav_Singh1)\
**Replies:** 28\
**Last updated:** [June 27, 2017, 2:56pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-and-the-date-filter-for-parsing-logs/86523 "2017-06-27T14:56:54Z")

</div>

I am trying to parse logs from a CSV file . Issue 1\> I am using below mentioned conf file. input { file { path =\> "/tmp/test1.csv" type =\> "core2" start\_position =\> "beginning" } } filter { csv { …

---

## [How to protect Kibana 4 dashboards using apache httpd?](https://discuss.elastic.co/t/how-to-protect-kibana-4-dashboards-using-apache-httpd/28396)

<div class="topic-metadata">

**Author:** [@gustavomr](https://discuss.elastic.co/u/gustavomr)\
**Replies:** 11\
**Last updated:** [March 24, 2016, 12:35am UTC](https://discuss.elastic.co/t/how-to-protect-kibana-4-dashboards-using-apache-httpd/28396 "2016-03-24T00:35:11Z")

</div>

Hi, we're trying to protect some dashboards using apache httpd but we don't have any URL that identify the dashboard as an unique resource. Using Chrome dev tools we could see that when a dashboard is requested the url…

---

## [Recursive nested documents in elasticsearch](https://discuss.elastic.co/t/recursive-nested-documents-in-elasticsearch/74048)

<div class="topic-metadata">

**Author:** [@GautamP](https://discuss.elastic.co/u/GautamP)\
**Replies:** 9\
**Last updated:** [February 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/recursive-nested-documents-in-elasticsearch/74048 "2017-02-06T13:41:27Z")

</div>

Hi all, I have a log file containing a series of jobs (each job containing sub jobs recursively) along with start and end time for each job. The log file looks like this: Job Name Start time End …

---

## [java.io.StreamCorruptedException: invalid internal transport message format, got (16,3,3,0)](https://discuss.elastic.co/t/java-io-streamcorruptedexception-invalid-internal-transport-message-format-got-16-3-3-0/257679)

<div class="topic-metadata">

**Author:** [@prashanth\_sri](https://discuss.elastic.co/u/prashanth_sri)\
**Replies:** 16\
**Last updated:** [December 24, 2020, 3:55am UTC](https://discuss.elastic.co/t/java-io-streamcorruptedexception-invalid-internal-transport-message-format-got-16-3-3-0/257679 "2020-12-24T03:55:13Z")

</div>

hi , i am updating my xpack security in all my cluster nodes , by using this yml.file, action.auto\_create\_index: .monitoring\*,.watches,.triggered\_watches,.watcher-history\*,.ml\* xpack.security.audit.enabled: true …

---

## [Fields not appearing in Kibana which are defined in Logstash](https://discuss.elastic.co/t/fields-not-appearing-in-kibana-which-are-defined-in-logstash/124537)

<div class="topic-metadata">

**Author:** [@falsekingpin](https://discuss.elastic.co/u/falsekingpin)\
**Replies:** 19\
**Last updated:** [April 4, 2018, 9:37am UTC](https://discuss.elastic.co/t/fields-not-appearing-in-kibana-which-are-defined-in-logstash/124537 "2018-04-04T09:37:11Z")

</div>

Hi all, I've defined some fields in logstash filter which is stored in /etc/logstash/conf.d/ The filter is as follows: input { beats { port =\> 5044 } } filter { if \[type\] == "log" { grok { match =\> { "message"…

---

## [Cannot set up mlockall 'true' on RedHat 6.6](https://discuss.elastic.co/t/cannot-set-up-mlockall-true-on-redhat-6-6/1059)

<div class="topic-metadata">

**Author:** [@ccrivelli](https://discuss.elastic.co/u/ccrivelli)\
**Replies:** 13\
**Last updated:** [September 25, 2015, 8:46pm UTC](https://discuss.elastic.co/t/cannot-set-up-mlockall-true-on-redhat-6-6/1059 "2015-09-25T20:46:36Z")

</div>

I read a lot around, but I'm not able to set mlockall as 'true' yet. Can you please help me? This is the procedure I followed so far: elasticsearch config # vim /etc/elasticsearch/elasticsearch.yml bootstrap.mlock…

---

## [Please help to grok my TMG Logs. How to use GeoIP?](https://discuss.elastic.co/t/please-help-to-grok-my-tmg-logs-how-to-use-geoip/61206)

<div class="topic-metadata">

**Author:** [@toasti](https://discuss.elastic.co/u/toasti)\
**Replies:** 20\
**Last updated:** [October 4, 2016, 10:14am UTC](https://discuss.elastic.co/t/please-help-to-grok-my-tmg-logs-how-to-use-geoip/61206 "2016-10-04T10:14:19Z")

</div>

Hello there, I am absolutely new to the ELK-Stack, but as described in my other thread I have an ELK-Stack running since yesterday and absolutely flashed what is possible with this. Since yesterday I also send my TMG…

---

## [Logstash "Connection Refused"](https://discuss.elastic.co/t/logstash-connection-refused/330748)

<div class="topic-metadata">

**Author:** [@baba72210](https://discuss.elastic.co/u/baba72210)\
**Replies:** 11\
**Last updated:** [April 26, 2023, 12:02pm UTC](https://discuss.elastic.co/t/logstash-connection-refused/330748 "2023-04-26T12:02:12Z")

</div>

Hello, I'm using a docker-compose to start my whole stack and I have a problem with my logstash. I have two errors on my logstash logs. elasticsearch - Failed to perform request {:message=\>"Connect to localhost:9200 \[l…

---

## [Cannot search JSON logs in Kibana](https://discuss.elastic.co/t/cannot-search-json-logs-in-kibana/244855)

<div class="topic-metadata">

**Author:** [@bc\_andrew](https://discuss.elastic.co/u/bc_andrew)\
**Replies:** 9\
**Last updated:** [August 16, 2020, 9:24am UTC](https://discuss.elastic.co/t/cannot-search-json-logs-in-kibana/244855 "2020-08-16T09:24:15Z")

</div>

Hi. I'm sending custom JSON logs to ES/Kibana v 7.8.1 using filebeat. My filebeat config is: cloud.auth: \<username:password\> cloud.id: \<cloud ID\> filebeat.inputs: - enabled: true json.add\_error\_key…

---

## [Logstash Filebeat module Configuration - No data has been received from this module yet](https://discuss.elastic.co/t/logstash-filebeat-module-configuration-no-data-has-been-received-from-this-module-yet/242990)

<div class="topic-metadata">

**Author:** [@GraceYu](https://discuss.elastic.co/u/GraceYu)\
**Replies:** 11\
**Last updated:** [July 30, 2020, 8:44am UTC](https://discuss.elastic.co/t/logstash-filebeat-module-configuration-no-data-has-been-received-from-this-module-yet/242990 "2020-07-30T08:44:54Z")

</div>

Hi, I have been trying to configure Logstash Filebeat module. However I received message "No data has been received from this module yet". I have installed Logstash. The following log from console: Sending Logstash…

---

## [Kafka input plugin - decorate\_events does not take effect](https://discuss.elastic.co/t/kafka-input-plugin-decorate-events-does-not-take-effect/136712)

<div class="topic-metadata">

**Author:** [@ArunANayagam](https://discuss.elastic.co/u/ArunANayagam)\
**Replies:** 11\
**Last updated:** [June 20, 2018, 3:24pm UTC](https://discuss.elastic.co/t/kafka-input-plugin-decorate-events-does-not-take-effect/136712 "2018-06-20T15:24:03Z")

</div>

Hi, I have a Kafka logstash input plugin that's reading messages from a Kafka 1.0.0 fine. But the "decorate\_events" property does not seem to take effect, i.e, I receive none of the kafka topic/partition information, h…

---

## [Filebeat use (deleted) files](https://discuss.elastic.co/t/filebeat-use-deleted-files/59172)

<div class="topic-metadata">

**Author:** [@zakabluk](https://discuss.elastic.co/u/zakabluk)\
**Replies:** 12\
**Last updated:** [September 12, 2016, 8:36am UTC](https://discuss.elastic.co/t/filebeat-use-deleted-files/59172 "2016-09-12T08:36:35Z")

</div>

filebeat-1.2.3-x86\_64 - conf: filebeat: prospectors: - paths: - /var/opt/tibco/logs/\*.log input\_type: log close\_older: 5m document\_type: tibco\_6 multiline: pattern…

---

## [Data getting duplicated - rsync'ing output to Logstash file input](https://discuss.elastic.co/t/data-getting-duplicated-rsyncing-output-to-logstash-file-input/64886)

<div class="topic-metadata">

**Author:** [@Rajat\_Singh](https://discuss.elastic.co/u/Rajat_Singh)\
**Replies:** 10\
**Last updated:** [November 7, 2016, 6:07am UTC](https://discuss.elastic.co/t/data-getting-duplicated-rsyncing-output-to-logstash-file-input/64886 "2016-11-07T06:07:18Z")

</div>

i am pulling logs from remote server using rsync command in every 5 minutes and then feeding it to the logstash what is happening that it is just creating the duplicate logs of it

---

## [Failed to create elasticsearch client](https://discuss.elastic.co/t/failed-to-create-elasticsearch-client/156206)

<div class="topic-metadata">

**Author:** [@davlinds](https://discuss.elastic.co/u/davlinds)\
**Replies:** 17\
**Last updated:** [November 20, 2018, 7:42pm UTC](https://discuss.elastic.co/t/failed-to-create-elasticsearch-client/156206 "2018-11-20T19:42:34Z")

</div>

Hi, I am trying to learn about Elastic and fscrawler so I can catalogue and search my pdf’s on a win7 machine. I am going up a very steep learning curve haha I have installed elastic version 6.4.2 using the suggested in…

---

## [FORBIDDEN/12/index read-only / allow delete (api)\]](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/110282)

<div class="topic-metadata">

**Author:** [@Tal\_Druckmann](https://discuss.elastic.co/u/Tal_Druckmann)\
**Replies:** 7\
**Last updated:** [September 2, 2020, 11:24pm UTC](https://discuss.elastic.co/t/forbidden-12-index-read-only-allow-delete-api/110282 "2020-09-02T23:24:17Z")

</div>

I am running logstash on windows 2016 vm . I use it from administrator command line. I keep getting this message. It won't let me save my visualization on kibana and keeps me from shutting it down (ctrl+c). This is the …

---

## [Use logstash or filebeat for sending azure JSON logs?](https://discuss.elastic.co/t/use-logstash-or-filebeat-for-sending-azure-json-logs/74456)

<div class="topic-metadata">

**Author:** [@111148](https://discuss.elastic.co/u/111148)\
**Replies:** 15\
**Last updated:** [March 1, 2017, 8:29pm UTC](https://discuss.elastic.co/t/use-logstash-or-filebeat-for-sending-azure-json-logs/74456 "2017-03-01T20:29:27Z")

</div>

Hello, sorry for silly question but I was trying about a week to adjust logstash 5.2 config for sending azure JSON logs to elastic 5.2, but all my attempts were failed. Logstash throws many different exceptions and error…

---

## [Could not clone from 'https://github.com/elastic/rally-tracks'](https://discuss.elastic.co/t/could-not-clone-from-https-github-com-elastic-rally-tracks/64983)

<div class="topic-metadata">

**Author:** [@xihuanbanku](https://discuss.elastic.co/u/xihuanbanku)\
**Replies:** 13\
**Last updated:** [November 15, 2016, 1:06am UTC](https://discuss.elastic.co/t/could-not-clone-from-https-github-com-elastic-rally-tracks/64983 "2016-11-15T01:06:44Z")

</div>

I'm working with esrally recently, facing problems, and also fixed some of them. But here is one I\`m not quite sure. 2016-11-04 03:50:02,686 root ERROR Cannot run subcommand \[race\]. Traceback (most recent call last): …

---

## [Filter base on score](https://discuss.elastic.co/t/filter-base-on-score/14001)

<div class="topic-metadata">

**Author:** [@Marcelo\_Elias\_Del\_Va](https://discuss.elastic.co/u/Marcelo_Elias_Del_Va)\
**Replies:** 13\
**Last updated:** [October 20, 2013, 5:18pm UTC](https://discuss.elastic.co/t/filter-base-on-score/14001 "2013-10-20T17:18:20Z")

</div>

I would like to filter results based on score, but min\_score only works on top of my search, it doesn 't work inside a filtered query. Is there any other way to not return results with score = 0, besides min\_score? …

---

## [Problem with @timestamp time in indexes](https://discuss.elastic.co/t/problem-with-timestamp-time-in-indexes/222280)

<div class="topic-metadata">

**Author:** [@Vinnyard](https://discuss.elastic.co/u/Vinnyard)\
**Replies:** 21\
**Last updated:** [March 10, 2020, 6:46am UTC](https://discuss.elastic.co/t/problem-with-timestamp-time-in-indexes/222280 "2020-03-10T06:46:37Z")

</div>

Hello, we have filebeat sending messages directly to elasticsearch index. And we found such problem, @timestamp in kibana view ( when we search) is different from timestamp we have in file on server( which use filebeat)…

[Previous page](https://discuss.elastic.co/top.md?page=62&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=64&per_page=50&period=all)
