# Top

**URL:** https://discuss.elastic.co/top.md?page=65&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 66

---

## [ES error : Request Timeout after 3000 ms](https://discuss.elastic.co/t/es-error-request-timeout-after-3000-ms/90820)

<div class="topic-metadata">

**Author:** [@Maxou](https://discuss.elastic.co/u/Maxou)\
**Replies:** 11\
**Last updated:** [June 30, 2017, 3:15pm UTC](https://discuss.elastic.co/t/es-error-request-timeout-after-3000-ms/90820 "2017-06-30T15:15:14Z")

</div>

Bonjour à tous, depuis quelque jours mon serveur ELK en 5.2.2 m'indique une erreur de manière aléatoire sur l'état de ES. Premièrement l'erreur afficher sur l'interface de Kibana : Error: Request Timeout after 300…

---

## [Adding a Custom Volume for Backups](https://discuss.elastic.co/t/adding-a-custom-volume-for-backups/205324)

<div class="topic-metadata">

**Author:** [@Zorlack](https://discuss.elastic.co/u/Zorlack)\
**Replies:** 12\
**Last updated:** [September 9, 2020, 8:51pm UTC](https://discuss.elastic.co/t/adding-a-custom-volume-for-backups/205324 "2020-09-09T20:51:58Z")

</div>

Hello, I'm interested in mounting a shared NFS PersistentVolume across an Elasticsearch ECK cluster so that I can add it has a Snapshot Repository. (This seems to be the obvious solution for on-prem snapshotting) I've …

---

## [Logstash kafka input to elasticsearch output stops consuming](https://discuss.elastic.co/t/logstash-kafka-input-to-elasticsearch-output-stops-consuming/42880)

<div class="topic-metadata">

**Author:** [@zot42](https://discuss.elastic.co/u/zot42)\
**Replies:** 9\
**Last updated:** [March 5, 2016, 4:53pm UTC](https://discuss.elastic.co/t/logstash-kafka-input-to-elasticsearch-output-stops-consuming/42880 "2016-03-05T16:53:54Z")

</div>

Logstash 2.2 elasticsearch 1.7.4 I am seeing and issue where I am consuming from kafka and sending to elasticsearch. It consumes about 500 messages at start and then stops with this messages being output to logs {:t…

---

## [Elasticsearch | S3 Repository and Snapshot Creation Failure](https://discuss.elastic.co/t/elasticsearch-s3-repository-and-snapshot-creation-failure/171442)

<div class="topic-metadata">

**Author:** [@Nikesh](https://discuss.elastic.co/u/Nikesh)\
**Replies:** 12\
**Last updated:** [March 12, 2019, 5:50am UTC](https://discuss.elastic.co/t/elasticsearch-s3-repository-and-snapshot-creation-failure/171442 "2019-03-12T05:50:18Z")

</div>

Hi, I am working on Backup and Restore using s3 on my 4 node cluster. According to the documentation I first added access\_key and secret\_key using keystore : bin/elasticsearch-keystore add s3.client.default.access\_…

---

## [OOM killer triggered and machine crashes after using up all memory](https://discuss.elastic.co/t/oom-killer-triggered-and-machine-crashes-after-using-up-all-memory/176725)

<div class="topic-metadata">

**Author:** [@Jalaluddeen\_Mohammed](https://discuss.elastic.co/u/Jalaluddeen_Mohammed)\
**Replies:** 9\
**Last updated:** [April 14, 2019, 3:59pm UTC](https://discuss.elastic.co/t/oom-killer-triggered-and-machine-crashes-after-using-up-all-memory/176725 "2019-04-14T15:59:38Z")

</div>

I have a 12 node cluster with 24G RAM running only ELasticsearch. Elasticsearch is configured to use 11G of RAM as below. -Xms11g -Xmx11g There is no indexing or querying happening on this cluster, this is a fresh de…

---

## [Filebeat + elasticsearch make duplicates events](https://discuss.elastic.co/t/filebeat-elasticsearch-make-duplicates-events/151825)

<div class="topic-metadata">

**Author:** [@Horus](https://discuss.elastic.co/u/Horus)\
**Replies:** 19\
**Last updated:** [November 6, 2018, 11:35am UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-make-duplicates-events/151825 "2018-11-06T11:35:35Z")

</div>

I have a trouble with events dublicates in elasticsearch. I used filebeat to aggregate events from logback logs. It's config: filebeat.inputs: - type: log enabled: true paths: - /#/\*/#/\*/#/logs/\*.log - /…

---

## [Kibana interface open problem](https://discuss.elastic.co/t/kibana-interface-open-problem/89604)

<div class="topic-metadata">

**Author:** [@Ximeng\_Zhao](https://discuss.elastic.co/u/Ximeng_Zhao)\
**Replies:** 9\
**Last updated:** [June 16, 2017, 4:00pm UTC](https://discuss.elastic.co/t/kibana-interface-open-problem/89604 "2017-06-16T16:00:13Z")

</div>

Hi all, I installed elasticsearch 5.2.2 and kibana 5.2.2 on one ec2 instance. Both runs without any issue. But I cannot open kibana interface, for example in localhost mode, I can check kibana interface by 127.0.0.1:56…

---

## [Logstash with elasticsearch input and output keep looping results](https://discuss.elastic.co/t/logstash-with-elasticsearch-input-and-output-keep-looping-results/115031)

<div class="topic-metadata">

**Author:** [@layla](https://discuss.elastic.co/u/layla)\
**Replies:** 14\
**Last updated:** [February 22, 2018, 3:59am UTC](https://discuss.elastic.co/t/logstash-with-elasticsearch-input-and-output-keep-looping-results/115031 "2018-02-22T03:59:16Z")

</div>

I would like to reindex and filter my log again. What I get the information from Internet is using the logstash to filter the data again. I tried and it can really split my data into different fields, however, the data k…

---

## [Winlogbeat как отбрасывать все поля, кроме заданных?](https://discuss.elastic.co/t/winlogbeat/173330)

<div class="topic-metadata">

**Author:** [@artem33region](https://discuss.elastic.co/u/artem33region)\
**Replies:** 27\
**Last updated:** [April 5, 2019, 1:34pm UTC](https://discuss.elastic.co/t/winlogbeat/173330 "2019-04-05T13:34:41Z")

</div>

Всем привет, есть конфиг и вроде он должен отбрасывать все поля кроме заданных, но почему то не работает, в elasticsearch приходят все поля... winlogbeat.event\_logs: - name: Microsoft-Windows-TerminalServices-LocalSes…

---

## [Need help tuning 3K+ EPS with ForwardedEvents](https://discuss.elastic.co/t/need-help-tuning-3k-eps-with-forwardedevents/94384)

<div class="topic-metadata">

**Author:** [@grants](https://discuss.elastic.co/u/grants)\
**Replies:** 12\
**Last updated:** [July 25, 2017, 7:57pm UTC](https://discuss.elastic.co/t/need-help-tuning-3k-eps-with-forwardedevents/94384 "2017-07-25T19:57:09Z")

</div>

I'm running winlogbeats on a windows 2012 server that is used as a windows event forwarding aggregation point. 2700+ clients report security logs to this 1 server in near real-time with the built in windows event forward…

---

## [Change destination datastream with Elasticsearch ingest pipeline](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 6:11pm UTC](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912 "2023-06-30T18:11:51Z")

</div>

We run Elastic stack in docker containers. The container logs are collected with Elastic Agent, using docker integration and datastreams. This means that the logs of elasticsearch container itself by default end up in l…

---

## [Elasticsearch 7.0 bootstrapping in AWS](https://discuss.elastic.co/t/elasticsearch-7-0-bootstrapping-in-aws/176491)

<div class="topic-metadata">

**Author:** [@kd5dbl](https://discuss.elastic.co/u/kd5dbl)\
**Replies:** 17\
**Last updated:** [May 15, 2019, 6:29am UTC](https://discuss.elastic.co/t/elasticsearch-7-0-bootstrapping-in-aws/176491 "2019-05-15T06:29:34Z")

</div>

Has anyone else gone through the fun of bringing up a new cluster in AWS now that we have this new "bootstrapping" stuff in 7.0? The problem I seem to have is that the cluster wants me to specify the master nodes to boo…

---

## [Map keyword field in kibana 6.3.0](https://discuss.elastic.co/t/map-keyword-field-in-kibana-6-3-0/151821)

<div class="topic-metadata">

**Author:** [@deepsing](https://discuss.elastic.co/u/deepsing)\
**Replies:** 20\
**Last updated:** [October 14, 2018, 2:24pm UTC](https://discuss.elastic.co/t/map-keyword-field-in-kibana-6-3-0/151821 "2018-10-14T14:24:03Z")

</div>

Hi In latest verson of kibana 6.3.0, there are separate fields. One is without "keyword" and another is with "keyword". I want to map both fields and showed a single one.

---

## [Unable to do terms query](https://discuss.elastic.co/t/unable-to-do-terms-query/231937)

<div class="topic-metadata">

**Author:** [@ahmedbrandver](https://discuss.elastic.co/u/ahmedbrandver)\
**Replies:** 10\
**Last updated:** [May 12, 2020, 3:11pm UTC](https://discuss.elastic.co/t/unable-to-do-terms-query/231937 "2020-05-12T15:11:31Z")

</div>

I am unable to a terms query on my data when I check the mapping field type was text. Is there a way where I can do an IN query on this field. There is only single data which is an id of my different database.

---

## [Cluster not able to keep up?](https://discuss.elastic.co/t/cluster-not-able-to-keep-up/15097)

<div class="topic-metadata">

**Author:** [@tdjb](https://discuss.elastic.co/u/tdjb)\
**Replies:** 11\
**Last updated:** [January 10, 2014, 3:47am UTC](https://discuss.elastic.co/t/cluster-not-able-to-keep-up/15097 "2014-01-10T03:47:17Z")

</div>

We have recently built out our Elasticsearch cluster and are now running close to our true volume of data through it. Unfortunately it seems like our cluster basically runs out of steam after a bit and can't keep up.…

---

## [Monitoring -\> Elasticsearch -\> Nodes - no data nodes(](https://discuss.elastic.co/t/monitoring-elasticsearch-nodes-no-data-nodes/167321)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 21\
**Last updated:** [February 7, 2019, 6:15pm UTC](https://discuss.elastic.co/t/monitoring-elasticsearch-nodes-no-data-nodes/167321 "2019-02-07T18:15:48Z")

</div>

Hello World! ... while trying to navigate through Monitoring -\> Elasticsearch -\> Nodes, I've noticed that some of nodes are missing from the list (even though node count on top is correct), all nodes that are missing ar…

---

## [Problem securing entire stack](https://discuss.elastic.co/t/problem-securing-entire-stack/286778)

<div class="topic-metadata">

**Author:** [@jceddy](https://discuss.elastic.co/u/jceddy)\
**Replies:** 13\
**Last updated:** [October 20, 2021, 7:42pm UTC](https://discuss.elastic.co/t/problem-securing-entire-stack/286778 "2021-10-20T19:42:27Z")

</div>

I have been trying to secure communications within (and connections to) my elastic stack, and am running into issues. I will just go through my configuration and what I've done so far. I have three servers (let's call t…

---

## [Getting date stamp from file properties](https://discuss.elastic.co/t/getting-date-stamp-from-file-properties/300)

<div class="topic-metadata">

**Author:** [@Andy](https://discuss.elastic.co/u/Andy)\
**Replies:** 9\
**Last updated:** [May 22, 2015, 11:56am UTC](https://discuss.elastic.co/t/getting-date-stamp-from-file-properties/300 "2015-05-22T11:56:43Z")

</div>

Hi, I'm wondering if I can get at log data in files that only have a time stamp (no date) for each line in the file. The file name contains the date that the file was created but only the day number. The file is overwr…

---

## [Index restoration from snapshot is taking a lot of time in 7.2.0 ES](https://discuss.elastic.co/t/index-restoration-from-snapshot-is-taking-a-lot-of-time-in-7-2-0-es/227184)

<div class="topic-metadata">

**Author:** [@Faiz\_Ahmed\_Mushtak\_H](https://discuss.elastic.co/u/Faiz_Ahmed_Mushtak_H)\
**Replies:** 19\
**Last updated:** [May 8, 2020, 8:32am UTC](https://discuss.elastic.co/t/index-restoration-from-snapshot-is-taking-a-lot-of-time-in-7-2-0-es/227184 "2020-05-08T08:32:34Z")

</div>

Elasticsearch version ( bin/elasticsearch --version ): 7.2.0 Plugins installed : JVM version ( java -version ): JDK 12 (bundled) OS version ( uname -a if on a Unix-like system): Ubuntu 14.04.5 LTS This is in ref…

---

## [Aggregation error - nil can't be coerced into Fixnum](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678)

<div class="topic-metadata">

**Author:** [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Replies:** 36\
**Last updated:** [February 21, 2019, 5:13pm UTC](https://discuss.elastic.co/t/aggregation-error-nil-cant-be-coerced-into-fixnum/168678 "2019-02-21T17:13:34Z")

</div>

Hi, I am trying to understand what is wrong with my aggregation: My code: aggregate { task\_id =\> "%{ResolutionDate}" code =\> " map\['Date'\] = event.get('ResolutionDate') …

---

## [Error when loading Google Cloud Storage credentials file](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 11\
**Last updated:** [December 2, 2019, 4:14pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370 "2019-12-02T16:14:22Z")

</div>

I’m trying to get Google Cloud Storage Repository Plugin going: I installed repository-gcs plugin: # /opt/elasticsearch/bin/elasticsearch-plugin install repository-gcs -\> Downloading repository-gcs from elastic \[======…

---

## [Khibana Dashboard](https://discuss.elastic.co/t/khibana-dashboard/156029)

<div class="topic-metadata">

**Author:** [@shakir](https://discuss.elastic.co/u/shakir)\
**Replies:** 15\
**Last updated:** [November 14, 2018, 6:50am UTC](https://discuss.elastic.co/t/khibana-dashboard/156029 "2018-11-14T06:50:43Z")

</div>

Hi, there I was trying to configure elasticsearch and kihbana on LINUX ( ubunutu 18.04 ). After following steps given in official doc i am getting below response of khibana screen It appears you're running the oss-onl…

---

## [I can't access Kibana](https://discuss.elastic.co/t/i-cant-access-kibana/136811)

<div class="topic-metadata">

**Author:** [@cassiocesarps](https://discuss.elastic.co/u/cassiocesarps)\
**Replies:** 11\
**Last updated:** [June 22, 2018, 9:43am UTC](https://discuss.elastic.co/t/i-cant-access-kibana/136811 "2018-06-22T09:43:06Z")

</div>

Hi guys, after updating Kibana to version 6.3 I can not access it. The following error message appears. \[kibana\] Does anyone know how to solve this?

---

## [Split nested json array from log](https://discuss.elastic.co/t/split-nested-json-array-from-log/228668)

<div class="topic-metadata">

**Author:** [@rajender](https://discuss.elastic.co/u/rajender)\
**Replies:** 12\
**Last updated:** [April 20, 2020, 12:42pm UTC](https://discuss.elastic.co/t/split-nested-json-array-from-log/228668 "2020-04-20T12:42:31Z")

</div>

I would like to to retrieve every element in below JSON to be a field so as to visualize in kibana by applying metrics in dashboard. I need each object in the array msg to be a separate entry in Elasticsearch and ever…

---

## [Filebeat pods keeps increasing Memory usage](https://discuss.elastic.co/t/filebeat-pods-keeps-increasing-memory-usage/325124)

<div class="topic-metadata">

**Author:** [@oandre7](https://discuss.elastic.co/u/oandre7)\
**Replies:** 12\
**Last updated:** [March 13, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-pods-keeps-increasing-memory-usage/325124 "2023-03-13T14:23:01Z")

</div>

Hi all, We are having a quite a strange issue that running filebeat in any version higher than 8.0.0 will cause filebeats agent to start increasing Memory consumption until the pod is OOM killed. As mentioned versions 8…

---

## [How to get index data into custom visualization?](https://discuss.elastic.co/t/how-to-get-index-data-into-custom-visualization/177447)

<div class="topic-metadata">

**Author:** [@reillye](https://discuss.elastic.co/u/reillye)\
**Replies:** 15\
**Last updated:** [May 1, 2019, 3:01pm UTC](https://discuss.elastic.co/t/how-to-get-index-data-into-custom-visualization/177447 "2019-05-01T15:01:12Z")

</div>

I am trying to create a new custom Kibana visualization in version 6.5. Based off of examples and blogs posts, I have managed to create a bare bones visualization, but I am unsure how to retrieve data from an elastic in…

---

## [Can't I send emails from my own server in elastic service?](https://discuss.elastic.co/t/cant-i-send-emails-from-my-own-server-in-elastic-service/268083)

<div class="topic-metadata">

**Author:** [@sireesha\_m](https://discuss.elastic.co/u/sireesha_m)\
**Replies:** 25\
**Last updated:** [March 23, 2021, 10:09pm UTC](https://discuss.elastic.co/t/cant-i-send-emails-from-my-own-server-in-elastic-service/268083 "2021-03-23T22:09:29Z")

</div>

I am not able to update the settings in Elasticsearch.yml file. Not able to include any settings in .yml file -\> Elasticsearch - 'xpack.notification.email.html.sanitization': is not allowed

---

## [Clamp::UsageError: Unrecognised option '-c'](https://discuss.elastic.co/t/clamp-usageerror-unrecognised-option-c/45871)

<div class="topic-metadata">

**Author:** [@seeni](https://discuss.elastic.co/u/seeni)\
**Replies:** 10\
**Last updated:** [March 31, 2016, 7:04am UTC](https://discuss.elastic.co/t/clamp-usageerror-unrecognised-option-c/45871 "2016-03-31T07:04:48Z")

</div>

Clamp::UsageError: Unrecognised option '-c' signal\_usage\_error at C:/.../Vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:103 find\_option at C:/.../Vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp…

---

## [Heap used always \> 85%](https://discuss.elastic.co/t/heap-used-always-85/40363)

<div class="topic-metadata">

**Author:** [@matiasdecarli](https://discuss.elastic.co/u/matiasdecarli)\
**Replies:** 13\
**Last updated:** [February 2, 2016, 6:36pm UTC](https://discuss.elastic.co/t/heap-used-always-85/40363 "2016-02-02T18:36:48Z")

</div>

Hi guys, im new to this forum & to Elasticsearch! I've read a lot, and I been doing some test with a 9-node Elasticsearch running on Docker. Each node in a different VM using an internal network, and I've configured 3 …

---

## [FATAL error after updating to 7.16.1](https://discuss.elastic.co/t/fatal-error-after-updating-to-7-16-1/291959)

<div class="topic-metadata">

**Author:** [@maltewhiite](https://discuss.elastic.co/u/maltewhiite)\
**Replies:** 14\
**Last updated:** [December 17, 2021, 2:11pm UTC](https://discuss.elastic.co/t/fatal-error-after-updating-to-7-16-1/291959 "2021-12-17T14:11:19Z")

</div>

\[FATAL\] 2021-12-15 11:35:53.567 \[main\] Logstash - Logstash was unable to start due to an unexpected Gemfile change. What is the Gemfile change? How do I debug this? Anyone else experienced this? I can't find anything…

---

## [Shield AD authentication error: peer not authenticated](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012)

<div class="topic-metadata">

**Author:** [@Speedman](https://discuss.elastic.co/u/Speedman)\
**Replies:** 12\
**Last updated:** [September 12, 2016, 12:33pm UTC](https://discuss.elastic.co/t/shield-ad-authentication-error-peer-not-authenticated/60012 "2016-09-12T12:33:50Z")

</div>

First, the error: \[2016-09-07 13:38:32,362\]\[WARN \]\[shield.authc.activedirectory\] \[node\_test01\] authentication failed for user \[KibanaTest\]: failed to connect to any active directory servers cause: com.unboundid.ldap.sd…

---

## [Indexing performance degradation over time](https://discuss.elastic.co/t/indexing-performance-degradation-over-time/107470)

<div class="topic-metadata">

**Author:** [@apyshchyk](https://discuss.elastic.co/u/apyshchyk)\
**Replies:** 18\
**Last updated:** [November 21, 2017, 1:33pm UTC](https://discuss.elastic.co/t/indexing-performance-degradation-over-time/107470 "2017-11-21T13:33:14Z")

</div>

Hi everyone, I'm using ES 5.5.0 on Amazon EC2 (18 Data nodes 8 CPU, 32GB RAM, 3 master) 1 TB EBS GP2 ssd (3000 IOPS). and have issue with indexing performance (segment merging time). A bit about workflow - I'm indexing …

---

## ["Failed to decode response" error from Java Client 8.8.0](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 10\
**Last updated:** [September 20, 2023, 9:12am UTC](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309 "2023-09-20T09:12:14Z")

</div>

Hello: I am trying to use Elastic Java Client 8.8.0 (also known low-level rest client) and getting the error: status: 200, \[es/search\] Failed to decode response I used the same library to create a new index and insert …

---

## [Python ZOPE Application Framework Integration to Elastic APM](https://discuss.elastic.co/t/python-zope-application-framework-integration-to-elastic-apm/315277)

<div class="topic-metadata">

**Author:** [@Dixit](https://discuss.elastic.co/u/Dixit)\
**Replies:** 52\
**Last updated:** [December 14, 2022, 11:53pm UTC](https://discuss.elastic.co/t/python-zope-application-framework-integration-to-elastic-apm/315277 "2022-12-14T23:53:51Z")

</div>

@lwintergerst @Bansriyar @ravindra ramnanani @rajesh @rajesh.balakrishnan@elastic.co Usecase – We are integrating the APM soln to our Product Ecosystem which involved Python, Messaging systems & DB. We have achieved 5…

---

## [Graphing Collectd Metrics in Kibana 4](https://discuss.elastic.co/t/graphing-collectd-metrics-in-kibana-4/37770)

<div class="topic-metadata">

**Author:** [@ariceELK](https://discuss.elastic.co/u/ariceELK)\
**Replies:** 9\
**Last updated:** [November 20, 2016, 5:54am UTC](https://discuss.elastic.co/t/graphing-collectd-metrics-in-kibana-4/37770 "2016-11-20T05:54:43Z")

</div>

Hi, Have collectd sending logs to Logstash but cant get the graphs for the metric value. This is my search: type: "collectd" AND plugin: "memory" AND type\_instance: "used" AND value: "" Is there a better way to sea…

---

## [Logstash beginner configuration issues](https://discuss.elastic.co/t/logstash-beginner-configuration-issues/216692)

<div class="topic-metadata">

**Author:** [@Marie-Laure\_Aix](https://discuss.elastic.co/u/Marie-Laure_Aix)\
**Replies:** 10\
**Last updated:** [January 29, 2020, 2:00pm UTC](https://discuss.elastic.co/t/logstash-beginner-configuration-issues/216692 "2020-01-29T14:00:08Z")

</div>

Hi there, I am a complete beginner with Logstash and I have issues configurating it. I am getting this error message : Thread.exclusive is deprecated, use Thread::Mutex Sending Logstash logs to /var/log/logstash which…

---

## [How to execute Must and Should query that matches an individual Nested field?](https://discuss.elastic.co/t/how-to-execute-must-and-should-query-that-matches-an-individual-nested-field/239648)

<div class="topic-metadata">

**Author:** [@rd8388](https://discuss.elastic.co/u/rd8388)\
**Replies:** 9\
**Last updated:** [July 21, 2020, 10:26am UTC](https://discuss.elastic.co/t/how-to-execute-must-and-should-query-that-matches-an-individual-nested-field/239648 "2020-07-21T10:26:52Z")

</div>

A record has two items/values indexed in a nested field type addresses.fulladdress. "11 High Street" and "88 West Avenue" If a user searched for "11 West" this record should not be matched. How should we structure the …

---

## [Logstash -\> Elasticsearch index template](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339)

<div class="topic-metadata">

**Author:** [@egray](https://discuss.elastic.co/u/egray)\
**Replies:** 9\
**Last updated:** [July 31, 2020, 8:52pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-index-template/243339 "2020-07-31T20:52:23Z")

</div>

I am running Logstash and a three-node Elasticsearch cluster in docker containers. In the Elasticsearch output plugin of Logstash, I'm attempting to use a custom index template with the following lines in logstash.conf: …

---

## [Issues with sending SMTP](https://discuss.elastic.co/t/issues-with-sending-smtp/1176)

<div class="topic-metadata">

**Author:** [@danielmoon](https://discuss.elastic.co/u/danielmoon)\
**Replies:** 11\
**Last updated:** [December 10, 2015, 6:44am UTC](https://discuss.elastic.co/t/issues-with-sending-smtp/1176 "2015-12-10T06:44:41Z")

</div>

I'm trying to get watcher to send me an email and it's giving me failed to execute \[email\] action \[my\_first\_watch\_0-2015-05-22T13:45:55.181Z/send\_email\]. error: cannot find default email account as no accounts have be…

---

## [Elasticsearch mapping with timezone](https://discuss.elastic.co/t/elasticsearch-mapping-with-timezone/271060)

<div class="topic-metadata">

**Author:** [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Replies:** 10\
**Last updated:** [April 30, 2021, 11:06am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-with-timezone/271060 "2021-04-30T11:06:27Z")

</div>

I have some JSON data that I am parsing with Filebeat and feeding into elasticsearch. There're some timestamps like this "joinTime": "2021-04-23 10:48:10+08:00" and I used the following in mapping to store it "joinTim…

---

## [Sorting results from composite aggregation](https://discuss.elastic.co/t/sorting-results-from-composite-aggregation/239076)

<div class="topic-metadata">

**Author:** [@Vignesh\_Theyagarajan](https://discuss.elastic.co/u/Vignesh_Theyagarajan)\
**Replies:** 13\
**Last updated:** [July 6, 2020, 9:51am UTC](https://discuss.elastic.co/t/sorting-results-from-composite-aggregation/239076 "2020-07-06T09:51:21Z")

</div>

I'm using a combination of composite, terms and tophits aggregation. I'd like to sort the results (groups retrieved) based on a document's property (nested field property). I read about bucket sort, but really not sure …

---

## [6.4 to 6.7.1: MultiPolygon cannot be indexed anymore using new geo\_shape field](https://discuss.elastic.co/t/6-4-to-6-7-1-multipolygon-cannot-be-indexed-anymore-using-new-geo-shape-field/177480)

<div class="topic-metadata">

**Author:** [@timost](https://discuss.elastic.co/u/timost)\
**Replies:** 14\
**Last updated:** [June 13, 2019, 2:07pm UTC](https://discuss.elastic.co/t/6-4-to-6-7-1-multipolygon-cannot-be-indexed-anymore-using-new-geo-shape-field/177480 "2019-06-13T14:07:25Z")

</div>

Hi, I've migrated my clusters from ES 6.4 to ES 6.7.1. On these I have some indices which have some geo\_shape fields. The mappings were defined using the "old" geo\_shape parameters: { "location": { "type":…

---

## [Conditional insert of data in ES](https://discuss.elastic.co/t/conditional-insert-of-data-in-es/13486)

<div class="topic-metadata">

**Author:** [@Amit\_Soni](https://discuss.elastic.co/u/Amit_Soni)\
**Replies:** 14\
**Last updated:** [September 17, 2013, 12:43am UTC](https://discuss.elastic.co/t/conditional-insert-of-data-in-es/13486 "2013-09-17T00:43:11Z")

</div>

Hi everyone - I am wondering if ElasticSearch provides a mechanism wherein an insert/update of a document is allowed only if a specified condition is met. Lets say that I have a document with id=id1 and my\_version=8. …

---

## [Filebeat does not work while using cloud.id and cloud.auth](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167)

<div class="topic-metadata">

**Author:** [@newKibanaUser](https://discuss.elastic.co/u/newKibanaUser)\
**Replies:** 15\
**Last updated:** [January 17, 2020, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-does-not-work-while-using-cloud-id-and-cloud-auth/215167 "2020-01-17T14:48:04Z")

</div>

Hello - I am trying to use cloud.id and cloud.auth in my file beat configuration file. But that seems not working. This Works perfectly without using cloud.id and cloud\_auth. output.elasticsearch: hosts: \["https://4d…

---

## [Kafka error](https://discuss.elastic.co/t/kafka-error/43582)

<div class="topic-metadata">

**Author:** [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Replies:** 16\
**Last updated:** [November 9, 2016, 3:38pm UTC](https://discuss.elastic.co/t/kafka-error/43582 "2016-11-09T15:38:10Z")

</div>

I am using kafka as a queue. My data is getting into the kafka cluster just fine, and the majority of it is being output to my ES cluster just fine except for one topic. My config for the logstash node consuming the …

---

## [Elasticsearch not returning all relevant results](https://discuss.elastic.co/t/elasticsearch-not-returning-all-relevant-results/13544)

<div class="topic-metadata">

**Author:** [@KS1](https://discuss.elastic.co/u/KS1)\
**Replies:** 9\
**Last updated:** [September 11, 2013, 9:42am UTC](https://discuss.elastic.co/t/elasticsearch-not-returning-all-relevant-results/13544 "2013-09-11T09:42:33Z")

</div>

I am using elastic search to search for files stored in MongoDB. I would like to retrieve all files whose name match a pattern. When I queried in MongoDB it returns 6754 files. FSsearch:PRIMARY\> db.fs.files.fi…

---

## [Large heap usage with each node](https://discuss.elastic.co/t/large-heap-usage-with-each-node/969)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 14\
**Last updated:** [November 25, 2015, 1:15am UTC](https://discuss.elastic.co/t/large-heap-usage-with-each-node/969 "2015-11-25T01:15:44Z")

</div>

Hi, running... ES 1.5.2 Java 1.8\_45 Windows 2008 4 nodes of: 32 cores 128GB 5 TB SSDs (each) ES\_HEAP\_SIZE configured to 30g I just finished bulk indexing 380,000,000 records but all 4 nodes are consuming 60% heap u…

---

## [Is the HighLevelRestClient no supported in the Java Testing Framework?](https://discuss.elastic.co/t/is-the-highlevelrestclient-no-supported-in-the-java-testing-framework/218083)

<div class="topic-metadata">

**Author:** [@dg1](https://discuss.elastic.co/u/dg1)\
**Replies:** 12\
**Last updated:** [February 21, 2020, 7:05am UTC](https://discuss.elastic.co/t/is-the-highlevelrestclient-no-supported-in-the-java-testing-framework/218083 "2020-02-21T07:05:56Z")

</div>

After spending quite a bit of time fighting jar hell issues trying to setup the java testing framework, and tweaking intellij settings to accommodate it, I ended up not being able to get my HighLevelRestClient to connect…

---

## [Is it really that painfull ? need advice](https://discuss.elastic.co/t/is-it-really-that-painfull-need-advice/57727)

<div class="topic-metadata">

**Author:** [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Replies:** 14\
**Last updated:** [September 29, 2016, 12:22am UTC](https://discuss.elastic.co/t/is-it-really-that-painfull-need-advice/57727 "2016-09-29T00:22:23Z")

</div>

Hello all, sorry to bother you. just wondering and by wondering I mean , smashing my head on the computer desk over and over thinking and probably over thinking it ... Lets say I have access to 1 server 16gigabyte of…

---

## [Data mismatch in elasticsearch when loading data from database using logstash](https://discuss.elastic.co/t/data-mismatch-in-elasticsearch-when-loading-data-from-database-using-logstash/161513)

<div class="topic-metadata">

**Author:** [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Replies:** 17\
**Last updated:** [January 7, 2019, 7:32am UTC](https://discuss.elastic.co/t/data-mismatch-in-elasticsearch-when-loading-data-from-database-using-logstash/161513 "2019-01-07T07:32:42Z")

</div>

Hello, I have loaded 6lakhs+ of data from database into elasticsearch using logstash. Observed the count of the number of rows in database is equal to the number of records in elasticsearch(as highlighted in yellow col…

[Previous page](https://discuss.elastic.co/top.md?page=64&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=66&per_page=50&period=all)
