# Top

**URL:** https://discuss.elastic.co/top.md?page=64&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 65

---

## [ElasticSearch Cluster Across Availability Zones in AWS](https://discuss.elastic.co/t/elasticsearch-cluster-across-availability-zones-in-aws/75416)

<div class="topic-metadata">

**Author:** [@mvz00](https://discuss.elastic.co/u/mvz00)\
**Replies:** 10\
**Last updated:** [February 17, 2017, 9:39am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-across-availability-zones-in-aws/75416 "2017-02-17T09:39:06Z")

</div>

Hi, I have a four node elasticsearch cluster with two nodes in each availability zone in AWS. The "discovery.zen.minimum\_master\_nodes" is set to 3 which means that three nodes have to be available for the cluster to be e…

---

## [APM on docker did not send logs trace to elastic cloud](https://discuss.elastic.co/t/apm-on-docker-did-not-send-logs-trace-to-elastic-cloud/295620)

<div class="topic-metadata">

**Author:** [@bekk777](https://discuss.elastic.co/u/bekk777)\
**Replies:** 25\
**Last updated:** [February 28, 2022, 1:36pm UTC](https://discuss.elastic.co/t/apm-on-docker-did-not-send-logs-trace-to-elastic-cloud/295620 "2022-02-28T13:36:07Z")

</div>

Hello everyone, I don´t understand why my configuration APM agent and server working on docker. But on the elastic cloud does not show anything on the APM service. But in Discover metrics show. cloud version v 7.15.2. …

---

## [How create a filter to my rails log?](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905)

<div class="topic-metadata">

**Author:** [@Candido\_Sales\_Gomes](https://discuss.elastic.co/u/Candido_Sales_Gomes)\
**Replies:** 9\
**Last updated:** [March 14, 2016, 6:35pm UTC](https://discuss.elastic.co/t/how-create-a-filter-to-my-rails-log/43905 "2016-03-14T18:35:24Z")

</div>

My stack is using Lograge (Gem) -\> Filebeat -\> Logstash -\> Elastic -\> KIbana. Elastic is indexing this in format: { "\_index": "filebeat-2016.03.09", "\_type": "log", "\_id": "AVNbq1ImHUX-l-CtdIqR", "\_score": nu…

---

## [ElasticSIEM unable to find \[logs-endpoint.alerts](https://discuss.elastic.co/t/elasticsiem-unable-to-find-logs-endpoint-alerts/277681)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 11\
**Last updated:** [July 21, 2021, 1:20pm UTC](https://discuss.elastic.co/t/elasticsiem-unable-to-find-logs-endpoint-alerts/277681 "2021-07-21T13:20:49Z")

</div>

I have been able to start using the elastic SIEM recently, and am having the following message show up in my Kibana, both in the UI as well as in the command line when I start the service. \</\> log \[15:02:19.220\] \[erro…

---

## [Logstash Config Error-JAVA](https://discuss.elastic.co/t/logstash-config-error-java/125546)

<div class="topic-metadata">

**Author:** [@Nagu\_R\_Pujari](https://discuss.elastic.co/u/Nagu_R_Pujari)\
**Replies:** 10\
**Last updated:** [August 3, 2021, 3:24am UTC](https://discuss.elastic.co/t/logstash-config-error-java/125546 "2021-08-03T03:24:15Z")

</div>

i have performing basic setup of logstash getting JAVA error. not able to complete the config test. Error: ERROR: Failed to load settings file from "path.settings". Aborting... path.setting=/etc/logstash/logstash.yml, …

---

## [Kibana React plugin](https://discuss.elastic.co/t/kibana-react-plugin/119029)

<div class="topic-metadata">

**Author:** [@undwood](https://discuss.elastic.co/u/undwood)\
**Replies:** 9\
**Last updated:** [April 8, 2018, 6:37am UTC](https://discuss.elastic.co/t/kibana-react-plugin/119029 "2018-04-08T06:37:17Z")

</div>

Hello. We are starting to develop some kibana plugin using react + redux for client side. We need to access elasticsearch for the data. In docs I had found 2 possible ways: using elasticsearch client api for JS. regest…

---

## [Filebeat cisco modue "Error starting the server address already in use"](https://discuss.elastic.co/t/filebeat-cisco-modue-error-starting-the-server-address-already-in-use/220217)

<div class="topic-metadata">

**Author:** [@hazem\_Alhamwi](https://discuss.elastic.co/u/hazem_Alhamwi)\
**Replies:** 18\
**Last updated:** [March 1, 2020, 5:38pm UTC](https://discuss.elastic.co/t/filebeat-cisco-modue-error-starting-the-server-address-already-in-use/220217 "2020-03-01T17:38:54Z")

</div>

i am trying to setup log server for network devices using ELK and filebeat with Ubuntu 18, but kibana doesn't display any output. when i run filebeat -e i get the following messages: 2020-02-20T14:53:10.891Z INFO…

---

## [Logstash slows down over time](https://discuss.elastic.co/t/logstash-slows-down-over-time/81072)

<div class="topic-metadata">

**Author:** [@jbeck](https://discuss.elastic.co/u/jbeck)\
**Replies:** 20\
**Last updated:** [June 4, 2017, 11:01pm UTC](https://discuss.elastic.co/t/logstash-slows-down-over-time/81072 "2017-06-04T23:01:04Z")

</div>

I'm having a weird problem with logstash and I'd like some help debugging it. Basically our logstash cluster slows down over a period of a couple of weeks. What I mean by slows down is that it starts rejecting messages…

---

## [Find age range according to Birthdate](https://discuss.elastic.co/t/find-age-range-according-to-birthdate/177691)

<div class="topic-metadata">

**Author:** [@chan\_1di](https://discuss.elastic.co/u/chan_1di)\
**Replies:** 14\
**Last updated:** [April 22, 2019, 10:35pm UTC](https://discuss.elastic.co/t/find-age-range-according-to-birthdate/177691 "2019-04-22T22:35:38Z")

</div>

My date of birth is storing as this "1995-08-10 00:00:00.314" ANd now I want to write a search query so that it can return the data according to the age of the person. My condition is I want to return data within 21-31 …

---

## [Dockerized Kibana not able to connect to elasticsearch nodes, unable to retrieve connection](https://discuss.elastic.co/t/dockerized-kibana-not-able-to-connect-to-elasticsearch-nodes-unable-to-retrieve-connection/241576)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 10\
**Last updated:** [July 24, 2020, 6:02pm UTC](https://discuss.elastic.co/t/dockerized-kibana-not-able-to-connect-to-elasticsearch-nodes-unable-to-retrieve-connection/241576 "2020-07-24T18:02:43Z")

</div>

Hello, I am having a complete elastic stack in docker and below is my docker-compose.yml. version: '3.2' services: elasticsearch: build: context: elasticsearch/ args: ELK\_VERSION: $ELK\_VERSIO…

---

## [Having an issue with filebeat pushing to Elasticsearch](https://discuss.elastic.co/t/having-an-issue-with-filebeat-pushing-to-elasticsearch/271822)

<div class="topic-metadata">

**Author:** [@gentle\_ghost](https://discuss.elastic.co/u/gentle_ghost)\
**Replies:** 21\
**Last updated:** [May 31, 2021, 9:24pm UTC](https://discuss.elastic.co/t/having-an-issue-with-filebeat-pushing-to-elasticsearch/271822 "2021-05-31T21:24:25Z")

</div>

Hello, I am receiving the following error when attempting to push log files to Elasticsearch: Exiting: error loading config file: yaml: line 2: did not find expected key Here is my .yaml file: filebeat.inputs: - ty…

---

## [Snapshot and Restore in readable format](https://discuss.elastic.co/t/snapshot-and-restore-in-readable-format/180578)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 12\
**Last updated:** [May 17, 2019, 9:32am UTC](https://discuss.elastic.co/t/snapshot-and-restore-in-readable-format/180578 "2019-05-17T09:32:33Z")

</div>

Hi all, I have configured an S3 bucket to push my snapshots to like the following: https://www.elastic.co/guide/en/cloud/current/ec-aws-custom-repository.html Is it possible out of the box to push the indexes in a rea…

---

## [Unable to create a new index pattern / indexes not loading](https://discuss.elastic.co/t/unable-to-create-a-new-index-pattern-indexes-not-loading/259527)

<div class="topic-metadata">

**Author:** [@elk\_guy\_1234](https://discuss.elastic.co/u/elk_guy_1234)\
**Replies:** 19\
**Last updated:** [December 28, 2020, 4:50pm UTC](https://discuss.elastic.co/t/unable-to-create-a-new-index-pattern-indexes-not-loading/259527 "2020-12-28T16:50:57Z")

</div>

Problem: When trying to create a new index pattern the error "The index pattern you've entered does not match any indices". Really the problem is my index's will not load from a config / schema. Index Details: This inde…

---

## [Fscrawler for ES clustering](https://discuss.elastic.co/t/fscrawler-for-es-clustering/216939)

<div class="topic-metadata">

**Author:** [@pyerunka](https://discuss.elastic.co/u/pyerunka)\
**Replies:** 40\
**Last updated:** [February 19, 2020, 11:07am UTC](https://discuss.elastic.co/t/fscrawler-for-es-clustering/216939 "2020-02-19T11:07:40Z")

</div>

Hello, I have configured ES cluster with 3 nodes. I want to index files using fscrawler. Is there any setting i need to do to mention all 3 nodes in fscrawler config file? Thanks, Priyanka

---

## [Winlogbeat transport problem on port 80 through reverse proxy to Elasticsearch](https://discuss.elastic.co/t/winlogbeat-transport-problem-on-port-80-through-reverse-proxy-to-elasticsearch/40965)

<div class="topic-metadata">

**Author:** [@UnclePhil](https://discuss.elastic.co/u/UnclePhil)\
**Replies:** 14\
**Last updated:** [February 9, 2016, 2:31pm UTC](https://discuss.elastic.co/t/winlogbeat-transport-problem-on-port-80-through-reverse-proxy-to-elasticsearch/40965 "2016-02-09T14:31:43Z")

</div>

Hello, I've just installed winlogbeat on scripting server, and It seems that a transport to elasticsearch on another port than 9200 is impossible I tested it with our standard 80 (working with powershell scripting on …

---

## [Filebeat splits message after 16k](https://discuss.elastic.co/t/filebeat-splits-message-after-16k/123718)

<div class="topic-metadata">

**Author:** [@paltryeffort](https://discuss.elastic.co/u/paltryeffort)\
**Replies:** 9\
**Last updated:** [March 26, 2018, 9:01am UTC](https://discuss.elastic.co/t/filebeat-splits-message-after-16k/123718 "2018-03-26T09:01:20Z")

</div>

\# filebeat 6.2.2 filebeat.prospectors: - paths: \[ "/var/lib/docker/containers/\*/\*-json.log" \] harvester\_buffer\_size: 65536 json.message\_key: log json.keys\_under\_root: true json.add\_error\_key: true fields\_unde…

---

## [Accuracy of elastic search aggregation (sum) when number of unique values in greater than a million](https://discuss.elastic.co/t/accuracy-of-elastic-search-aggregation-sum-when-number-of-unique-values-in-greater-than-a-million/180141)

<div class="topic-metadata">

**Author:** [@Prashant\_Priyadarshi](https://discuss.elastic.co/u/Prashant_Priyadarshi)\
**Replies:** 9\
**Last updated:** [May 9, 2019, 8:46am UTC](https://discuss.elastic.co/t/accuracy-of-elastic-search-aggregation-sum-when-number-of-unique-values-in-greater-than-a-million/180141 "2019-05-09T08:46:41Z")

</div>

Hi, I am new to elastic search. lets suppose I have elastic search documents with 3 fields: date, user\_id, money\_spent. I have around 10 million such documents and number of unique user\_id 's is greater than 1 million…

---

## [Hunspell dictionary issue installation](https://discuss.elastic.co/t/hunspell-dictionary-issue-installation/53337)

<div class="topic-metadata">

**Author:** [@Ivan\_Ghisleni](https://discuss.elastic.co/u/Ivan_Ghisleni)\
**Replies:** 9\
**Last updated:** [January 9, 2017, 4:48pm UTC](https://discuss.elastic.co/t/hunspell-dictionary-issue-installation/53337 "2017-01-09T16:48:13Z")

</div>

Hi, I'm trying to install hunspell dictionary for italian language but I don't know where set the dictionary path. Configuration: Os: CentOS 6.5 Elasticsearch: 2.1.0 - path: /etc/elasticsearch I put all the diction…

---

## ["Discover: Unable to parse/seralize body" due to truncated HTTP response](https://discuss.elastic.co/t/discover-unable-to-parse-seralize-body-due-to-truncated-http-response/139307)

<div class="topic-metadata">

**Author:** [@EldrosKandar](https://discuss.elastic.co/u/EldrosKandar)\
**Replies:** 24\
**Last updated:** [August 6, 2018, 11:08am UTC](https://discuss.elastic.co/t/discover-unable-to-parse-seralize-body-due-to-truncated-http-response/139307 "2018-08-06T11:08:52Z")

</div>

We have currently an Elastic Search Stack release 6.2.4 installed on our server. It was updated from 5.2 (via 5.6). I've been trying to search all entries where the field "session" begins with a specific uuid, using filt…

---

## [Example files for sending nginx, tomcat, postgresql files (from server A) to ELK server (server B)](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745)

<div class="topic-metadata">

**Author:** [@ghx](https://discuss.elastic.co/u/ghx)\
**Replies:** 13\
**Last updated:** [July 11, 2016, 9:38am UTC](https://discuss.elastic.co/t/example-files-for-sending-nginx-tomcat-postgresql-files-from-server-a-to-elk-server-server-b/54745 "2016-07-11T09:38:12Z")

</div>

Hello, I just installed ELK server (on server B) and want to send log file for tomcat (catalina.out), nginx (access.log, error.log) and posgresql logs (from server A) using filebeat I tested it with logs like syslog …

---

## [How to send logs from server to local machine to VM. where ELK is running?](https://discuss.elastic.co/t/how-to-send-logs-from-server-to-local-machine-to-vm-where-elk-is-running/216120)

<div class="topic-metadata">

**Author:** [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Replies:** 18\
**Last updated:** [January 25, 2020, 1:19am UTC](https://discuss.elastic.co/t/how-to-send-logs-from-server-to-local-machine-to-vm-where-elk-is-running/216120 "2020-01-25T01:19:12Z")

</div>

I have filebeat running on server which collects logs and ships them to logstash. But I want to try to send logs to logstash on my machine. Not on localhost, but on my windows machine to VM. So it will basically be a di…

---

## [Unable to store the data in index](https://discuss.elastic.co/t/unable-to-store-the-data-in-index/135332)

<div class="topic-metadata">

**Author:** [@kish](https://discuss.elastic.co/u/kish)\
**Replies:** 31\
**Last updated:** [June 15, 2018, 7:33am UTC](https://discuss.elastic.co/t/unable-to-store-the-data-in-index/135332 "2018-06-15T07:33:22Z")

</div>

Hello - I have the below format to store the data and in my logs i able to see that data is stored but when i execute indices or see data stored i am getting nothing. API used to store the data: put1, err := elasticSe…

---

## [What happens to events that are not processed by any output](https://discuss.elastic.co/t/what-happens-to-events-that-are-not-processed-by-any-output/102417)

<div class="topic-metadata">

**Author:** [@rbrandstaedter](https://discuss.elastic.co/u/rbrandstaedter)\
**Replies:** 10\
**Last updated:** [October 11, 2017, 11:56am UTC](https://discuss.elastic.co/t/what-happens-to-events-that-are-not-processed-by-any-output/102417 "2017-10-11T11:56:30Z")

</div>

I'm wondering what happens to events that are not written by any output plugin? Reason why I'm asking is that I have a logstash instance running for a couple of days and for no reason (no increased load) it dies with an…

---

## [Multi-Fields search using Span Queries with fuzziness in Elasticsearch](https://discuss.elastic.co/t/multi-fields-search-using-span-queries-with-fuzziness-in-elasticsearch/152596)

<div class="topic-metadata">

**Author:** [@Nikesh](https://discuss.elastic.co/u/Nikesh)\
**Replies:** 14\
**Last updated:** [October 16, 2018, 11:23am UTC](https://discuss.elastic.co/t/multi-fields-search-using-span-queries-with-fuzziness-in-elasticsearch/152596 "2018-10-16T11:23:25Z")

</div>

Hi all, I am using Span queries to enable match phrase with fuzziness. I am able to do this on single field but since i am using fuzzy query with span\_multi query, I am failing it to use this query for multiple fields b…

---

## [Can we ingest csv directly into elastric search from python?](https://discuss.elastic.co/t/can-we-ingest-csv-directly-into-elastric-search-from-python/320404)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 14\
**Last updated:** [December 6, 2022, 6:07am UTC](https://discuss.elastic.co/t/can-we-ingest-csv-directly-into-elastric-search-from-python/320404 "2022-12-06T06:07:24Z")

</div>

Actually, I've tried pushing the data but to no use. I'm using Elastic Search version '8.4.1'. I want to push the CSV directly into the Elasticsearch without uploading it manually using the File Data Visualizer option in…

---

## [Class not found exception for org.apache.lucene.util.Version](https://discuss.elastic.co/t/class-not-found-exception-for-org-apache-lucene-util-version/153729)

<div class="topic-metadata">

**Author:** [@Sanjaybg](https://discuss.elastic.co/u/Sanjaybg)\
**Replies:** 11\
**Last updated:** [October 27, 2018, 5:37am UTC](https://discuss.elastic.co/t/class-not-found-exception-for-org-apache-lucene-util-version/153729 "2018-10-27T05:37:21Z")

</div>

I am using Elasticsearch6.4 Java High Level REST Client. I am using lucene-core-7.4.0.jar and lucene-queryparser-7.4.0.jar, but im getting the following exception. 24-Oct-2018 11:43:31.164 SEVERE \[http-nio-8080-exec-9…

---

## [Performance killed when faceting on high cardinality fields](https://discuss.elastic.co/t/performance-killed-when-faceting-on-high-cardinality-fields/7809)

<div class="topic-metadata">

**Author:** [@otisg](https://discuss.elastic.co/u/otisg)\
**Replies:** 25\
**Last updated:** [January 27, 2013, 6:17pm UTC](https://discuss.elastic.co/t/performance-killed-when-faceting-on-high-cardinality-fields/7809 "2013-01-27T18:17:58Z")

</div>

Hi, We're doing some ES performance testing with a relatively small index. All is peachy until we want to facet on a field that has relatively high cardinality - in this case it's a "tags" field that, as you can …

---

## [Genre Expansion в Elasticsearch 6.1](https://discuss.elastic.co/t/genre-expansion-elasticsearch-6-1/115708)

<div class="topic-metadata">

**Author:** [@acorned](https://discuss.elastic.co/u/acorned)\
**Replies:** 25\
**Last updated:** [February 9, 2018, 10:07am UTC](https://discuss.elastic.co/t/genre-expansion-elasticsearch-6-1/115708 "2018-02-09T10:07:47Z")

</div>

Здравствуйте! Во втором эластике была возможность создавать иерархические структуры синонимов для поиска: https://www.elastic.co/guide/en/elasticsearch/guide/current/synonyms-expand-or-contract.html Однако в шестой ве…

---

## [Filebeat 7.10 is not harvesting](https://discuss.elastic.co/t/filebeat-7-10-is-not-harvesting/256182)

<div class="topic-metadata">

**Author:** [@elkwhat](https://discuss.elastic.co/u/elkwhat)\
**Replies:** 16\
**Last updated:** [November 25, 2020, 6:50pm UTC](https://discuss.elastic.co/t/filebeat-7-10-is-not-harvesting/256182 "2020-11-25T18:50:24Z")

</div>

Hi, I got a weird problem that i would like to share. I have one filebeat instance trying to harvest a particular file and its just doing nothing. Here's my filebeat config - # ============================== Filebea…

---

## [Transactions using OpenAPI C# is not showing up](https://discuss.elastic.co/t/transactions-using-openapi-c-is-not-showing-up/221492)

<div class="topic-metadata">

**Author:** [@kaushas](https://discuss.elastic.co/u/kaushas)\
**Replies:** 24\
**Last updated:** [March 24, 2020, 9:21am UTC](https://discuss.elastic.co/t/transactions-using-openapi-c-is-not-showing-up/221492 "2020-03-24T09:21:35Z")

</div>

Kibana version:7.6.0 Elasticsearch version:7.6.0 APM Server version:7.6.0 APM Agent language and version: OpenAPI using C# in a console app, manually instrumented using Transactions. Browser version: IE 11.1685 and C…

---

## [Elasticsearch 6.2.2 nodes crash after reaching ulimit setting](https://discuss.elastic.co/t/elasticsearch-6-2-2-nodes-crash-after-reaching-ulimit-setting/124172)

<div class="topic-metadata">

**Author:** [@iamredlus](https://discuss.elastic.co/u/iamredlus)\
**Replies:** 11\
**Last updated:** [April 9, 2018, 9:35am UTC](https://discuss.elastic.co/t/elasticsearch-6-2-2-nodes-crash-after-reaching-ulimit-setting/124172 "2018-04-09T09:35:24Z")

</div>

Hi, We're experiencing a critical production issue in elasticsearch 6.2.2 related to open\_file\_descriptors. The cluster is an exact replica (as much as possible) of a 5.2.2 cluster, and documents are indexed into both c…

---

## [Public SSL'ed access with Ingress not working](https://discuss.elastic.co/t/public-ssled-access-with-ingress-not-working/189634)

<div class="topic-metadata">

**Author:** [@tadgh](https://discuss.elastic.co/u/tadgh)\
**Replies:** 9\
**Last updated:** [July 29, 2019, 4:25pm UTC](https://discuss.elastic.co/t/public-ssled-access-with-ingress-not-working/189634 "2019-07-29T16:25:53Z")

</div>

hey all, I have followed the quickstart guide from master branch of the docs, and all works perfectly well when i set the network type to LoadBalancer for kibana and elastic. I am able to curl the endpoints (with the sel…

---

## [Understanding HA with Kafka](https://discuss.elastic.co/t/understanding-ha-with-kafka/116162)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 22\
**Last updated:** [January 27, 2018, 4:18pm UTC](https://discuss.elastic.co/t/understanding-ha-with-kafka/116162 "2018-01-27T16:18:33Z")

</div>

Hi, running 6.1.1. I have 3 Kafka brokers (Confluent 3.3.1e, Kafka 0.11.0). I physically downed 2 of the brokers for 10 minutes, but logs kept getting indexed! The topic has replica count 1. Unless I don't understand …

---

## [LDAP User Authentication fails with invalid DN error](https://discuss.elastic.co/t/ldap-user-authentication-fails-with-invalid-dn-error/79605)

<div class="topic-metadata">

**Author:** [@koladoo](https://discuss.elastic.co/u/koladoo)\
**Replies:** 12\
**Last updated:** [March 23, 2017, 10:15am UTC](https://discuss.elastic.co/t/ldap-user-authentication-fails-with-invalid-dn-error/79605 "2017-03-23T10:15:11Z")

</div>

Hi all, I am currently trying to setup LDAP user authentication. I added the configuration below to elasticsearch.yml file: xpack: security: audit: enabled: true authc: realms: ldap1: …

---

## [Fastest copy of index](https://discuss.elastic.co/t/fastest-copy-of-index/125608)

<div class="topic-metadata">

**Author:** [@Kennethtruyers](https://discuss.elastic.co/u/Kennethtruyers)\
**Replies:** 20\
**Last updated:** [April 3, 2018, 11:35am UTC](https://discuss.elastic.co/t/fastest-copy-of-index/125608 "2018-04-03T11:35:16Z")

</div>

I know this question may have been asked before, but the responses in other threads are not sufficient for my use case. Data: Cluster: 6 nodes Index size: 10GB Document count: 35.000.000 Shards: 5 We want to be abl…

---

## [Mutate plugin in Grok Filter](https://discuss.elastic.co/t/mutate-plugin-in-grok-filter/101945)

<div class="topic-metadata">

**Author:** [@akarsha](https://discuss.elastic.co/u/akarsha)\
**Replies:** 9\
**Last updated:** [October 5, 2017, 6:18am UTC](https://discuss.elastic.co/t/mutate-plugin-in-grok-filter/101945 "2017-10-05T06:18:49Z")

</div>

I want one of my field to be converted to "integer". I tried using mutate option in grok, however, not getting the change reflected in kibana, also not getting any exception in logstash logs. config file: filter { if …

---

## [Geoip create everything but the geoip.location](https://discuss.elastic.co/t/geoip-create-everything-but-the-geoip-location/109900)

<div class="topic-metadata">

**Author:** [@Adesfire](https://discuss.elastic.co/u/Adesfire)\
**Replies:** 13\
**Last updated:** [December 5, 2017, 7:23am UTC](https://discuss.elastic.co/t/geoip-create-everything-but-the-geoip-location/109900 "2017-12-05T07:23:55Z")

</div>

Good morning everyone, today I'm trying to implement the geoip filter, using this input file : filter { if \[host\] =~ /10\\.0\\.0\\.1/ { grok { match =\> \[ "message", "\\A%{SYSLOG…

---

## [Create custom metric for Y-axis, dealing with no existed values](https://discuss.elastic.co/t/create-custom-metric-for-y-axis-dealing-with-no-existed-values/105222)

<div class="topic-metadata">

**Author:** [@lsouvleros](https://discuss.elastic.co/u/lsouvleros)\
**Replies:** 12\
**Last updated:** [October 27, 2017, 9:47am UTC](https://discuss.elastic.co/t/create-custom-metric-for-y-axis-dealing-with-no-existed-values/105222 "2017-10-27T09:47:39Z")

</div>

Hello, I just started to use ELK and I want your help with issues. I have a dataset with the following fields Username,Name,Recruitment\_date,Recruitment\_year,duration\_at\_company,leave\_date, leave\_year and I want to f…

---

## [Entity extraction using elasticsearch](https://discuss.elastic.co/t/entity-extraction-using-elasticsearch/59888)

<div class="topic-metadata">

**Author:** [@mitali\_bhoir](https://discuss.elastic.co/u/mitali_bhoir)\
**Replies:** 9\
**Last updated:** [September 7, 2016, 9:23am UTC](https://discuss.elastic.co/t/entity-extraction-using-elasticsearch/59888 "2016-09-07T09:23:17Z")

</div>

I need to develop an application which will take input as a text article,then it will search for named entities like a person, an organization then import this data to CSV file. is there any way to do it? I searched for …

---

## [Increased Read IOPS usage after upgrade from 8.18.0 to 9.0.1](https://discuss.elastic.co/t/increased-read-iops-usage-after-upgrade-from-8-18-0-to-9-0-1/377986)

<div class="topic-metadata">

**Author:** [@applike-ss](https://discuss.elastic.co/u/applike-ss)\
**Replies:** 23\
**Last updated:** [May 22, 2025, 10:36am UTC](https://discuss.elastic.co/t/increased-read-iops-usage-after-upgrade-from-8-18-0-to-9-0-1/377986 "2025-05-22T10:36:06Z")

</div>

Hi all, since upgrading from 8.18.0 to 9.0.1 i'm seeing a massive increase of read IOPS on the data node disks. I couldn't see anything obvious in the release notes of 8.18.1, 9.0.0 and 9.0.1 that would lead to this. …

---

## [Reindexing with new mapping](https://discuss.elastic.co/t/reindexing-with-new-mapping/5348)

<div class="topic-metadata">

**Author:** [@Curtis\_Caravone](https://discuss.elastic.co/u/Curtis_Caravone)\
**Replies:** 13\
**Last updated:** [July 26, 2012, 8:03am UTC](https://discuss.elastic.co/t/reindexing-with-new-mapping/5348 "2012-07-26T08:03:56Z")

</div>

We are in a situation where we need to reindex a few hundred million docs (add some indexed fields, add some new fields). We hope to do this online by changing the mapping then performing updates on all the old docs t…

---

## [More on Solr vs ES faceting](https://discuss.elastic.co/t/more-on-solr-vs-es-faceting/5322)

<div class="topic-metadata">

**Author:** [@drigolin](https://discuss.elastic.co/u/drigolin)\
**Replies:** 31\
**Last updated:** [September 11, 2011, 7:05pm UTC](https://discuss.elastic.co/t/more-on-solr-vs-es-faceting/5322 "2011-09-11T19:05:14Z")

</div>

During last week I did lots of testing about faceting medium size documents sets (2M bibliographic records) using both solr and ES. After some issue faced at the beginning I spent some time to configure index and mappin…

---

## [Ingesting JSON files, format problem?](https://discuss.elastic.co/t/ingesting-json-files-format-problem/36411)

<div class="topic-metadata">

**Author:** [@CraigFoote](https://discuss.elastic.co/u/CraigFoote)\
**Replies:** 12\
**Last updated:** [December 9, 2015, 6:02pm UTC](https://discuss.elastic.co/t/ingesting-json-files-format-problem/36411 "2015-12-09T18:02:22Z")

</div>

I have a series of JSON files, each with one rather large, single-line JSON document. I'm trying to ingest via the file input plugin: input{ file{ path =\> "/path/to/files/\*.txt" start-position =\> "beginning" sin…

---

## [Datanodes cant see each other using EC2 Discovery Plugin](https://discuss.elastic.co/t/datanodes-cant-see-each-other-using-ec2-discovery-plugin/112086)

<div class="topic-metadata">

**Author:** [@cloud\_sora](https://discuss.elastic.co/u/cloud_sora)\
**Replies:** 15\
**Last updated:** [December 21, 2017, 12:40pm UTC](https://discuss.elastic.co/t/datanodes-cant-see-each-other-using-ec2-discovery-plugin/112086 "2017-12-21T12:40:11Z")

</div>

hello guys, im currently having an issue after configuring the elasticsearch to see the other ec2 datanodes note that im using elasticsearch-6.0.1-1 the below is my configuration ##################### cluster.name:…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314273)

<div class="topic-metadata">

**Author:** [@khanchand](https://discuss.elastic.co/u/khanchand)\
**Replies:** 10\
**Last updated:** [September 13, 2022, 10:00am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314273 "2022-09-13T10:00:46Z")

</div>

Hi everyone, I am new on Elasticsearch and have created my lab before going to deploy in production. For lab purpose I have deployed all three (elasticsearch, kibana & logstash) on a single centos server. While I am faci…

---

## [OSQuery Live Queries don't go through](https://discuss.elastic.co/t/osquery-live-queries-dont-go-through/274428)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 14\
**Last updated:** [June 17, 2021, 9:31pm UTC](https://discuss.elastic.co/t/osquery-live-queries-dont-go-through/274428 "2021-06-17T21:31:07Z")

</div>

Hey, I'm using a 7.13 stack with 7.13 Elastic Agents on multiple machines. I have the OSQuery Manager Integration installed (v. 0.2.3) and applied a respective policy to three Agents (2x Ubuntu 20.04, 1x Windows Server …

---

## [Metricset 'postgresql/bgwriter' is not registered, module not found](https://discuss.elastic.co/t/metricset-postgresql-bgwriter-is-not-registered-module-not-found/61020)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 22\
**Last updated:** [October 5, 2016, 9:36pm UTC](https://discuss.elastic.co/t/metricset-postgresql-bgwriter-is-not-registered-module-not-found/61020 "2016-10-05T21:36:19Z")

</div>

I have configure metricbeat to send postgresql metric but get this error when starting filebeat: 2016/09/20 13:54:29.102566 metricbeat.go:26: INFO Register \[ModuleFactory:\[\], MetricSetFactory:\[apache/status, mongodb/st…

---

## [Running filebeat](https://discuss.elastic.co/t/running-filebeat/47766)

<div class="topic-metadata">

**Author:** [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Replies:** 14\
**Last updated:** [April 21, 2016, 11:05am UTC](https://discuss.elastic.co/t/running-filebeat/47766 "2016-04-21T11:05:31Z")

</div>

Hi, I am running filebeat using PS C:\\Program Files\\Filebeat\> Start-Service filebeat However it just creates one file Start-Service in home directory and nothing happens. Please help. I am referring below link. https:…

---

## [Logstash: \[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error | Cannot get new connection from pool](https://discuss.elastic.co/t/logstash-error-logstash-javapipeline-main-pipeline-error-cannot-get-new-connection-from-pool/300696)

<div class="topic-metadata">

**Author:** [@Bavaria](https://discuss.elastic.co/u/Bavaria)\
**Replies:** 11\
**Last updated:** [March 29, 2022, 1:40pm UTC](https://discuss.elastic.co/t/logstash-error-logstash-javapipeline-main-pipeline-error-cannot-get-new-connection-from-pool/300696 "2022-03-29T13:40:02Z")

</div>

I am trying to start logstash pipeline. But after long search, I do not know what I am doing wrong. I am getting this output: C:\\Users\\Name\\ElasticStack\\logstash-8.0.1\>.\\bin\\logstash.bat -f erste-pipeline.conf "Using bu…

---

## [Calculate time difference in scripted field](https://discuss.elastic.co/t/calculate-time-difference-in-scripted-field/216893)

<div class="topic-metadata">

**Author:** [@Anne\_Kim](https://discuss.elastic.co/u/Anne_Kim)\
**Replies:** 11\
**Last updated:** [February 7, 2020, 3:21pm UTC](https://discuss.elastic.co/t/calculate-time-difference-in-scripted-field/216893 "2020-02-07T15:21:12Z")

</div>

Hello, The question is how to get the difference rounded to a day between the dates in a document? For example, if date1 = 2019-12-27T23:00:00.999 and date2 = 2019-12-28T01:00:00.999, the answer is 1. I'm already usin…

[Previous page](https://discuss.elastic.co/top.md?page=63&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=65&per_page=50&period=all)
