# Top

**URL:** https://discuss.elastic.co/top.md?page=66&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 67

---

## [Please reconsider hosting docker image on Docker Hub](https://discuss.elastic.co/t/please-reconsider-hosting-docker-image-on-docker-hub/92679)

<div class="topic-metadata">

**Author:** [@twang2218](https://discuss.elastic.co/u/twang2218)\
**Replies:** 9\
**Last updated:** [November 28, 2017, 10:11am UTC](https://discuss.elastic.co/t/please-reconsider-hosting-docker-image-on-docker-hub/92679 "2017-11-28T10:11:54Z")

</div>

Just found out the original elasticsearch, logstash and kibana images on Docker Hub are marked as deprecated, and all the images will be hosted on elastic.co repository, and there will be no update for the Docker Hub rep…

---

## [Upgrade ELK stack](https://discuss.elastic.co/t/upgrade-elk-stack/236590)

<div class="topic-metadata">

**Author:** [@anjana1](https://discuss.elastic.co/u/anjana1)\
**Replies:** 22\
**Last updated:** [June 12, 2020, 8:04pm UTC](https://discuss.elastic.co/t/upgrade-elk-stack/236590 "2020-06-12T20:04:05Z")

</div>

What is the right way to perform an upgrade of the stack to preserve the data .. I am trying to upgrade from 7.6 to 7.7.1 I am having challenges in upgrading without data loss. I went through the documentation and its…

---

## [Kibana Dashboard performance](https://discuss.elastic.co/t/kibana-dashboard-performance/99688)

<div class="topic-metadata">

**Author:** [@amichaim](https://discuss.elastic.co/u/amichaim)\
**Replies:** 11\
**Last updated:** [September 24, 2017, 11:02pm UTC](https://discuss.elastic.co/t/kibana-dashboard-performance/99688 "2017-09-24T23:02:18Z")

</div>

Hi We have Kibana Dashboard with ~35 visualizations. ~10 of them are using pipeline aggregation. Kibana & Elasticsearch are installed on machine with 16 CPU cores, 64 MB memory (we set 32 for ES). We have about 5 mill…

---

## [Simultaneously executing multiple queries on Scroll API to fetch Large Data](https://discuss.elastic.co/t/simultaneously-executing-multiple-queries-on-scroll-api-to-fetch-large-data/240649)

<div class="topic-metadata">

**Author:** [@N220](https://discuss.elastic.co/u/N220)\
**Replies:** 16\
**Last updated:** [July 10, 2020, 12:01pm UTC](https://discuss.elastic.co/t/simultaneously-executing-multiple-queries-on-scroll-api-to-fetch-large-data/240649 "2020-07-10T12:01:01Z")

</div>

How to fetch large data in parallel from elastic search? Using Scroll API I am able to fetch complete data from elasticsearch. But it is too slow. Takes around 40 seconds to fetch 500000 records. I am trying to use mul…

---

## [If I enable xpack , Elasticsearch stops working and my license won't work](https://discuss.elastic.co/t/if-i-enable-xpack-elasticsearch-stops-working-and-my-license-wont-work/248690)

<div class="topic-metadata">

**Author:** [@cctk](https://discuss.elastic.co/u/cctk)\
**Replies:** 9\
**Last updated:** [September 24, 2020, 2:27pm UTC](https://discuss.elastic.co/t/if-i-enable-xpack-elasticsearch-stops-working-and-my-license-wont-work/248690 "2020-09-24T14:27:36Z")

</div>

I have been having an issue viewing the Kibana login page. Since the update to 7x for Elasticsearch and Kibana, I have not been able to access the login page nor has it been prompted for me. Is there any way that this ca…

---

## [How to build Kibana from Source](https://discuss.elastic.co/t/how-to-build-kibana-from-source/148730)

<div class="topic-metadata">

**Author:** [@Artur\_Vieira](https://discuss.elastic.co/u/Artur_Vieira)\
**Replies:** 17\
**Last updated:** [September 19, 2018, 3:36am UTC](https://discuss.elastic.co/t/how-to-build-kibana-from-source/148730 "2018-09-19T03:36:40Z")

</div>

Hi, I recently switched from GA, your product is so nice. Thank you for the hard work. Here is the issue with why I switched, my use case is not covered! haha, so here I am. I have a use case, I hope you can help. I am …

---

## [Building packetbeat for the raspberry pi](https://discuss.elastic.co/t/building-packetbeat-for-the-raspberry-pi/60224)

<div class="topic-metadata">

**Author:** [@Steinar\_Bang](https://discuss.elastic.co/u/Steinar_Bang)\
**Replies:** 14\
**Last updated:** [September 20, 2016, 6:55am UTC](https://discuss.elastic.co/t/building-packetbeat-for-the-raspberry-pi/60224 "2016-09-20T06:55:45Z")

</div>

I'm trying to build packagebeat for a raspberry Pi 2 with raspbian jessie. I'm trying to build it on the rPi itself. So far I've done : 1. As root installed required software (python 2.7.9, and GNU make was already i…

---

## [Logstash doesn't start](https://discuss.elastic.co/t/logstash-doesnt-start/236919)

<div class="topic-metadata">

**Author:** [@Uzzi](https://discuss.elastic.co/u/Uzzi)\
**Replies:** 50\
**Last updated:** [June 19, 2020, 6:47am UTC](https://discuss.elastic.co/t/logstash-doesnt-start/236919 "2020-06-19T06:47:45Z")

</div>

Hi,I'm debugging Logstash istance: /usr/share/logstash/bin/logstash --config.test\_and\_exit --path.settings --config.debug -f /etc/logstash/conf.d/01-wazuh.conf ---\> Config Validation Result: OK. Exiting Logstash /us…

---

## [Transform stability](https://discuss.elastic.co/t/transform-stability/274870)

<div class="topic-metadata">

**Author:** [@alexs1](https://discuss.elastic.co/u/alexs1)\
**Replies:** 19\
**Last updated:** [July 5, 2021, 10:28am UTC](https://discuss.elastic.co/t/transform-stability/274870 "2021-07-05T10:28:40Z")

</div>

Hello I've started to use transforms, and they are great- saving lots of pain of using external tools. What concerns me, is the I had few times a load on the cluster, which caused a node to leave the cluster, and cause…

---

## [How can we convert join query into elastic search](https://discuss.elastic.co/t/how-can-we-convert-join-query-into-elastic-search/197783)

<div class="topic-metadata">

**Author:** [@rameshkr1994](https://discuss.elastic.co/u/rameshkr1994)\
**Replies:** 10\
**Last updated:** [September 6, 2019, 1:11pm UTC](https://discuss.elastic.co/t/how-can-we-convert-join-query-into-elastic-search/197783 "2019-09-06T13:11:53Z")

</div>

Dear All. i having problem with below query :-1: Please help me to convert into Elastic-search query:- { "query":"SELECT \* FROM dbdataindex\_join\_allcolumns\_qa INNER JOIN dbdataindex\_join\_allcolumns\_qa\_added\_benefic…

---

## [Elastic search Indexed content retruns nothing with title should query](https://discuss.elastic.co/t/elastic-search-indexed-content-retruns-nothing-with-title-should-query/123386)

<div class="topic-metadata">

**Author:** [@satyarajp](https://discuss.elastic.co/u/satyarajp)\
**Replies:** 12\
**Last updated:** [March 14, 2018, 9:06am UTC](https://discuss.elastic.co/t/elastic-search-indexed-content-retruns-nothing-with-title-should-query/123386 "2018-03-14T09:06:53Z")

</div>

Hi Team, I've indexed a content in to my elastic search v5.6.0 in local through json. Now I can query this using POST http://localhost:9200/content/\_search with empty body, and the search returns all results indexed in…

---

## [Native authentication with Basic License](https://discuss.elastic.co/t/native-authentication-with-basic-license/194494)

<div class="topic-metadata">

**Author:** [@harryk1](https://discuss.elastic.co/u/harryk1)\
**Replies:** 11\
**Last updated:** [August 20, 2019, 12:23pm UTC](https://discuss.elastic.co/t/native-authentication-with-basic-license/194494 "2019-08-20T12:23:10Z")

</div>

We are building a 3-node elastic cluster v7.1.0 (statefulset), and single-node Kibana (deployment) on Kuberenetes using basic license. Was wondering how can we implement native authentication?

---

## [Canvas formatting options](https://discuss.elastic.co/t/canvas-formatting-options/265127)

<div class="topic-metadata">

**Author:** [@fefontana](https://discuss.elastic.co/u/fefontana)\
**Replies:** 14\
**Last updated:** [March 23, 2021, 7:04pm UTC](https://discuss.elastic.co/t/canvas-formatting-options/265127 "2021-03-23T19:04:33Z")

</div>

Hello, is it possible to change the format (and orientation) of the legends in the X and Y axis in a canvas chart ?. Also, is it possible to change the format of a data in a table inside a canvas ?. An image is attache…

---

## [Validate SAML token in Kibana](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185)

<div class="topic-metadata">

**Author:** [@mdconner](https://discuss.elastic.co/u/mdconner)\
**Replies:** 10\
**Last updated:** [February 20, 2017, 8:24pm UTC](https://discuss.elastic.co/t/validate-saml-token-in-kibana/1185 "2017-02-20T20:24:06Z")

</div>

Does Kibana support SAML tokens? If not, any assistance with getting this to done (Apache HTTP Server, or other)?

---

## [Fatal error on the network layer](https://discuss.elastic.co/t/fatal-error-on-the-network-layer/95425)

<div class="topic-metadata">

**Author:** [@niraj\_kumar](https://discuss.elastic.co/u/niraj_kumar)\
**Replies:** 10\
**Last updated:** [August 2, 2017, 6:38pm UTC](https://discuss.elastic.co/t/fatal-error-on-the-network-layer/95425 "2017-08-02T18:38:55Z")

</div>

Hi Everyone, I am almost stumped now. My elasticsearch went dead and all shards were in unassigned state. We started the services back and when the shards started getting relocated things were fine upto certain point bu…

---

## [Cannot setup single node elasticsearch in docker](https://discuss.elastic.co/t/cannot-setup-single-node-elasticsearch-in-docker/186193)

<div class="topic-metadata">

**Author:** [@agreatfool](https://discuss.elastic.co/u/agreatfool)\
**Replies:** 10\
**Last updated:** [June 18, 2019, 1:36pm UTC](https://discuss.elastic.co/t/cannot-setup-single-node-elasticsearch-in-docker/186193 "2019-06-18T13:36:54Z")

</div>

docker-compose config: es\_1: image: "elasticsearch:7.0.0" container\_name: "es\_1" hostname: "es\_1" volumes: - es\_vol\_1\_data:/usr/share/elasticsearch/data - es\_vol\_1\_logs:/usr/share/elasticsearch/logs …

---

## [Can't stop a snapshot running on my cluster](https://discuss.elastic.co/t/cant-stop-a-snapshot-running-on-my-cluster/17707)

<div class="topic-metadata">

**Author:** [@Andrew\_Vos](https://discuss.elastic.co/u/Andrew_Vos)\
**Replies:** 9\
**Last updated:** [May 27, 2014, 3:39pm UTC](https://discuss.elastic.co/t/cant-stop-a-snapshot-running-on-my-cluster/17707 "2014-05-27T15:39:59Z")

</div>

A few days ago I started a snapshot, but instead of using a shared network I used the local filesystem. Because my root partition only had 8gb (and this is where I stored the snapshots) the partition got filled up an…

---

## [Elasticsearch failed to start on Ubuntu 18.04](https://discuss.elastic.co/t/elasticsearch-failed-to-start-on-ubuntu-18-04/268262)

<div class="topic-metadata">

**Author:** [@Sebastian\_F](https://discuss.elastic.co/u/Sebastian_F)\
**Replies:** 21\
**Last updated:** [April 1, 2021, 6:54am UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-start-on-ubuntu-18-04/268262 "2021-04-01T06:54:29Z")

</div>

Hi folks, I am an elastic noob and I am stuck with running elasticsearch on an Ubuntu 18.04 V-Server with 4 Cores, 8Gb Ram and a 100GB Hard drive. I followed the instructions from this post: Installieren und Konfigurier…

---

## [Connecting to remote server](https://discuss.elastic.co/t/connecting-to-remote-server/201732)

<div class="topic-metadata">

**Author:** [@prachic](https://discuss.elastic.co/u/prachic)\
**Replies:** 18\
**Last updated:** [October 3, 2019, 5:03am UTC](https://discuss.elastic.co/t/connecting-to-remote-server/201732 "2019-10-03T05:03:16Z")

</div>

Hi, I am new to elasticsearch. I installed elasticsearch and kibana on local machine. All my operations are performed properly on local machine. I want to access remote machine/server on which elasticserver is running. …

---

## [Elasticsearch does not start because of a graylog-server error](https://discuss.elastic.co/t/elasticsearch-does-not-start-because-of-a-graylog-server-error/237495)

<div class="topic-metadata">

**Author:** [@uek](https://discuss.elastic.co/u/uek)\
**Replies:** 13\
**Last updated:** [June 29, 2020, 12:05pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-because-of-a-graylog-server-error/237495 "2020-06-29T12:05:13Z")

</div>

Hello there, my elasticsearch-oss I would like to use in combination with prometheus and grafana does not start on my centos8 machine because of theese errors : Automatic restarting of the unit graylog-server.service…

---

## [Parsing a crappy date format](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263)

<div class="topic-metadata">

**Author:** [@Aviv\_Ratzon](https://discuss.elastic.co/u/Aviv_Ratzon)\
**Replies:** 10\
**Last updated:** [October 15, 2015, 7:03pm UTC](https://discuss.elastic.co/t/parsing-a-crappy-date-format/32263 "2015-10-15T19:03:34Z")

</div>

Hi everyone, I have a real problem that I couldn't find a decent solution to. I need to parse log files and extract dates inside these files. the date format is really crappy and looks like this: 10/09/15 13:55:57:20…

---

## [Class Not Found, for a local jar I try to add to a plugin](https://discuss.elastic.co/t/class-not-found-for-a-local-jar-i-try-to-add-to-a-plugin/104369)

<div class="topic-metadata">

**Author:** [@Junaid03](https://discuss.elastic.co/u/Junaid03)\
**Replies:** 14\
**Last updated:** [November 13, 2017, 10:56pm UTC](https://discuss.elastic.co/t/class-not-found-for-a-local-jar-i-try-to-add-to-a-plugin/104369 "2017-11-13T22:56:09Z")

</div>

I am getting a class not found exception for a local jar file I add to my project using Gradle. So here are more details: Using mvn command to install the jar to local repo: mvn install:install-file -Dfile=/Users/prim…

---

## [Cannot Open Shared Object File](https://discuss.elastic.co/t/cannot-open-shared-object-file/134267)

<div class="topic-metadata">

**Author:** [@CDR](https://discuss.elastic.co/u/CDR)\
**Replies:** 15\
**Last updated:** [June 8, 2018, 5:43pm UTC](https://discuss.elastic.co/t/cannot-open-shared-object-file/134267 "2018-06-08T17:43:29Z")

</div>

I am trying to start Elasticsearch on a Linux machine and keep getting the response: /opt/cust/suite/javabin/jre/bin/java: error while loading shared libraries: libjli.so: cannot open shared object file: No such file o…

---

## [Trivial syslog processing not working](https://discuss.elastic.co/t/trivial-syslog-processing-not-working/84848)

<div class="topic-metadata">

**Author:** [@dcn](https://discuss.elastic.co/u/dcn)\
**Replies:** 15\
**Last updated:** [May 8, 2017, 5:48pm UTC](https://discuss.elastic.co/t/trivial-syslog-processing-not-working/84848 "2017-05-08T17:48:25Z")

</div>

I'm sorry to post here if the answer is finally trivial too, but I've now past countless hours reading everywhere trying to solve it. I'm basically sending syslog message to Logstash: input { tcp { …

---

## [Can you stream all contents of the log file to ELK?](https://discuss.elastic.co/t/can-you-stream-all-contents-of-the-log-file-to-elk/39687)

<div class="topic-metadata">

**Author:** [@gsaray101](https://discuss.elastic.co/u/gsaray101)\
**Replies:** 15\
**Last updated:** [January 21, 2016, 9:35pm UTC](https://discuss.elastic.co/t/can-you-stream-all-contents-of-the-log-file-to-elk/39687 "2016-01-21T21:35:15Z")

</div>

If I forward everything in the log to ELK without creating index first, would I be able to create charts on every entry in the log. Is this recommended? Sincere there are many servers and apps, creating index could becom…

---

## [Logs do not displayed in ELK. What is the problem? How to fix the error?](https://discuss.elastic.co/t/logs-do-not-displayed-in-elk-what-is-the-problem-how-to-fix-the-error/100058)

<div class="topic-metadata">

**Author:** [@rchumarin](https://discuss.elastic.co/u/rchumarin)\
**Replies:** 10\
**Last updated:** [September 12, 2017, 7:13am UTC](https://discuss.elastic.co/t/logs-do-not-displayed-in-elk-what-is-the-problem-how-to-fix-the-error/100058 "2017-09-12T07:13:23Z")

</div>

Hello. Kibana version: 5.4.2 Elasticsearch version: 5.4.2 Logstash version: 5.4.2 Server OS version: Linux Red Hat, docker container kibana, logstash, elasticsearch and curator. Logs do not displayed in ELK. What is…

---

## [Logstash Error - causing shutdown and restart](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232)

<div class="topic-metadata">

**Author:** [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Replies:** 19\
**Last updated:** [December 12, 2019, 8:51am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232 "2019-12-12T08:51:47Z")

</div>

Hi may I know how to resolve this? I am unable to identify which file is causing this error.

---

## [\[x-pack\] enabled: Unable to communicate to Elasticsearch using only cacert from client machines](https://discuss.elastic.co/t/x-pack-enabled-unable-to-communicate-to-elasticsearch-using-only-cacert-from-client-machines/194280)

<div class="topic-metadata">

**Author:** [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Replies:** 18\
**Last updated:** [August 9, 2019, 6:48am UTC](https://discuss.elastic.co/t/x-pack-enabled-unable-to-communicate-to-elasticsearch-using-only-cacert-from-client-machines/194280 "2019-08-09T06:48:47Z")

</div>

Hi, i have upgraded my cluster from 6.7.0 to 6.8.2 to use x-pack opensource version, after enabling x-pack am able to communicate to elasticsearch using "cacert" and username, password, but i am trying to authenticate o…

---

## [Support for indexing Windows fileshare](https://discuss.elastic.co/t/support-for-indexing-windows-fileshare/68677)

<div class="topic-metadata">

**Author:** [@martinfy](https://discuss.elastic.co/u/martinfy)\
**Replies:** 15\
**Last updated:** [December 14, 2016, 2:46pm UTC](https://discuss.elastic.co/t/support-for-indexing-windows-fileshare/68677 "2016-12-14T14:46:58Z")

</div>

Hi, Is it possible to use Elasticsearch to index WIndows filshares? If so: are search results security trimmed based on the user executing the query?

---

## [Sending Logstash data to multiple servers](https://discuss.elastic.co/t/sending-logstash-data-to-multiple-servers/167639)

<div class="topic-metadata">

**Author:** [@The1](https://discuss.elastic.co/u/The1)\
**Replies:** 9\
**Last updated:** [February 11, 2019, 8:37am UTC](https://discuss.elastic.co/t/sending-logstash-data-to-multiple-servers/167639 "2019-02-11T08:37:17Z")

</div>

Hi! I would like to know if it is possible to send collected data from Logstash to multiple destinations outside of my cluster which run Elasticsearch. Many thanks!

---

## [Unable to connect through hadoop](https://discuss.elastic.co/t/unable-to-connect-through-hadoop/38763)

<div class="topic-metadata">

**Author:** [@firewater](https://discuss.elastic.co/u/firewater)\
**Replies:** 9\
**Last updated:** [January 11, 2016, 11:31pm UTC](https://discuss.elastic.co/t/unable-to-connect-through-hadoop/38763 "2016-01-11T23:31:54Z")

</div>

My pig code: register /PATH/elasticsearch-hadoop-2.1.2.jar A = LOAD 'logstash-2016.01.08.18/logs' USING org.elasticsearch.hadoop.pig.EsStorage('es.nodes=http://my-url-here.net:9200'); I get the below error saying: E…

---

## [How to remove trial license on not running elastic pod](https://discuss.elastic.co/t/how-to-remove-trial-license-on-not-running-elastic-pod/224967)

<div class="topic-metadata">

**Author:** [@opouwels](https://discuss.elastic.co/u/opouwels)\
**Replies:** 14\
**Last updated:** [March 25, 2020, 3:15pm UTC](https://discuss.elastic.co/t/how-to-remove-trial-license-on-not-running-elastic-pod/224967 "2020-03-25T15:15:59Z")

</div>

When elastic server is down (not the pod) caused by ending trial license how can I remove the trial license from the pod and start elastic? elasticsearch {"type": "server", "timestamp": "2020-03-25T09:27:14,081Z", "le…

---

## [Benchmarking Filebeats](https://discuss.elastic.co/t/benchmarking-filebeats/79746)

<div class="topic-metadata">

**Author:** [@Ravi\_Shanker\_Reddy](https://discuss.elastic.co/u/Ravi_Shanker_Reddy)\
**Replies:** 11\
**Last updated:** [April 5, 2017, 1:46pm UTC](https://discuss.elastic.co/t/benchmarking-filebeats/79746 "2017-04-05T13:46:28Z")

</div>

As explained in this post I enabled my filebeat with very simple configurations as startup. filebeat.prospectors: - input\_type: log paths: - /root/\*.log ignore\_older: 5m scan\_frequency: 10s close\_inactive:…

---

## [Maximize dashboard by default](https://discuss.elastic.co/t/maximize-dashboard-by-default/167198)

<div class="topic-metadata">

**Author:** [@lquin1978](https://discuss.elastic.co/u/lquin1978)\
**Replies:** 11\
**Last updated:** [February 8, 2019, 4:05pm UTC](https://discuss.elastic.co/t/maximize-dashboard-by-default/167198 "2019-02-08T16:05:12Z")

</div>

Is there anyway to have a dashboard load "maximized" by default rather than having to select it from the menu?

---

## [org.elasticsearch.index.mapper.MapperParsingException: object mapping for \[message\] tried to parse field \[message\] as object, but found a concrete value](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 10\
**Last updated:** [May 24, 2019, 4:13pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597 "2019-05-24T16:13:54Z")

</div>

I upload a template, and try to parse a column, but it recognized as a string, how to make it as a object, please help... Here is my template: { "index\_patterns": "springboot\*", "order": 0, "settings": { "num…

---

## [Endpoints are enrolling stuck message](https://discuss.elastic.co/t/endpoints-are-enrolling-stuck-message/258599)

<div class="topic-metadata">

**Author:** [@VictorG](https://discuss.elastic.co/u/VictorG)\
**Replies:** 19\
**Last updated:** [January 13, 2021, 2:33pm UTC](https://discuss.elastic.co/t/endpoints-are-enrolling-stuck-message/258599 "2021-01-13T14:33:19Z")

</div>

Hi Elastic team, I am currently running the latest version of Elastic Agent which is enrolled in the fleet but I don't see any endpoint enrolled yet. The message I get for a few days now in Security/Detections/Administr…

---

## [Logstash parshing unicode characters](https://discuss.elastic.co/t/logstash-parshing-unicode-characters/296890)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 16\
**Last updated:** [February 23, 2022, 8:46pm UTC](https://discuss.elastic.co/t/logstash-parshing-unicode-characters/296890 "2022-02-23T20:46:48Z")

</div>

hi, we are running into parsing errors when sending data through logstash pipelines. After digging a little, found that the source system has been sending a lot of unicode special characters - something like below: \\u00…

---

## [ML - Datafeed is encountering errors extracting data: all shards failed](https://discuss.elastic.co/t/ml-datafeed-is-encountering-errors-extracting-data-all-shards-failed/264994)

<div class="topic-metadata">

**Author:** [@cezar996](https://discuss.elastic.co/u/cezar996)\
**Replies:** 23\
**Last updated:** [February 24, 2021, 12:59pm UTC](https://discuss.elastic.co/t/ml-datafeed-is-encountering-errors-extracting-data-all-shards-failed/264994 "2021-02-24T12:59:10Z")

</div>

Hi! I have created a ML job, but when I select Start Datafeed, I get this error: Datafeed is encountering errors extracting data: all shards failed, as in the image below. I really dont have any idea why I get this. …

---

## [ElasticSearch - Refresh issue ? Too many Requests ? Can't find documents randomly](https://discuss.elastic.co/t/elasticsearch-refresh-issue-too-many-requests-cant-find-documents-randomly/268197)

<div class="topic-metadata">

**Author:** [@Rayzbam](https://discuss.elastic.co/u/Rayzbam)\
**Replies:** 16\
**Last updated:** [May 17, 2021, 1:34pm UTC](https://discuss.elastic.co/t/elasticsearch-refresh-issue-too-many-requests-cant-find-documents-randomly/268197 "2021-05-17T13:34:30Z")

</div>

Hi, It's been some week i encounter some issues on ElasticSearch "Search" API. Sometimes, the search doesn't return a result which has been indexed before (sometimes while before, like 30min or 1hour). I made some res…

---

## [Data is not available for syslog dashboard](https://discuss.elastic.co/t/data-is-not-available-for-syslog-dashboard/147026)

<div class="topic-metadata">

**Author:** [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Replies:** 16\
**Last updated:** [September 5, 2018, 3:51am UTC](https://discuss.elastic.co/t/data-is-not-available-for-syslog-dashboard/147026 "2018-09-05T03:51:58Z")

</div>

Hello All, I am using ELK6.4.0 and beats 6.4.0. I have enabled the filebeat system module and getting the data over dashboard for syslog and auth.log. But when i am checking the filebeat dashboard for syslog no data is …

---

## [Kibana maps not showing locations](https://discuss.elastic.co/t/kibana-maps-not-showing-locations/172331)

<div class="topic-metadata">

**Author:** [@sc1](https://discuss.elastic.co/u/sc1)\
**Replies:** 10\
**Last updated:** [March 26, 2019, 4:32pm UTC](https://discuss.elastic.co/t/kibana-maps-not-showing-locations/172331 "2019-03-26T16:32:57Z")

</div>

Hello, I have noticed that any map I have on a dashboard isn't showing the geolocations. For example, the sample dashboards from Filebeat showing attempted SSHs loads the dashboards, but it doesn't plot where any of the…

---

## [WHY index stops accepting any documents](https://discuss.elastic.co/t/why-index-stops-accepting-any-documents/50825)

<div class="topic-metadata">

**Author:** [@nskalis](https://discuss.elastic.co/u/nskalis)\
**Replies:** 15\
**Last updated:** [May 29, 2016, 3:14pm UTC](https://discuss.elastic.co/t/why-index-stops-accepting-any-documents/50825 "2016-05-29T15:14:05Z")

</div>

Hi guys, I would really need your advice on this one; There is 1 elastic search node with 4 indices. kopf shows After 22h, the \_\_10 index stops indexing documents, while the other ones operate as expected The dat…

---

## [Upload xml file into elasticsearch](https://discuss.elastic.co/t/upload-xml-file-into-elasticsearch/162629)

<div class="topic-metadata">

**Author:** [@Alaoui](https://discuss.elastic.co/u/Alaoui)\
**Replies:** 10\
**Last updated:** [January 3, 2019, 9:38am UTC](https://discuss.elastic.co/t/upload-xml-file-into-elasticsearch/162629 "2019-01-03T09:38:45Z")

</div>

Hi everyone, i want that logstash can groupe the data of each section of my xml file, what i should to modify on remove in my config file. for example i want my result like that : "\_index": "logstash-xml", "\_type…

---

## [Filebeat, Logstash, Elasticsearch robustness and duplicated documents](https://discuss.elastic.co/t/filebeat-logstash-elasticsearch-robustness-and-duplicated-documents/42711)

<div class="topic-metadata">

**Author:** [@mr\_caos](https://discuss.elastic.co/u/mr_caos)\
**Replies:** 10\
**Last updated:** [June 10, 2016, 10:20am UTC](https://discuss.elastic.co/t/filebeat-logstash-elasticsearch-robustness-and-duplicated-documents/42711 "2016-06-10T10:20:39Z")

</div>

For logging in AWS EC2, I'm testing the robustness of the chain Filebeat, Logstash, Elasticsearch. I have one AMI with an appplication + Filebeat, one with Logstash and one with Elastisearch + Kibana. With the applicatio…

---

## [Monitoring Undertow using Elastic APM java agent is not giving any transaction data](https://discuss.elastic.co/t/monitoring-undertow-using-elastic-apm-java-agent-is-not-giving-any-transaction-data/242455)

<div class="topic-metadata">

**Author:** [@khgupta3](https://discuss.elastic.co/u/khgupta3)\
**Replies:** 24\
**Last updated:** [August 19, 2020, 10:01am UTC](https://discuss.elastic.co/t/monitoring-undertow-using-elastic-apm-java-agent-is-not-giving-any-transaction-data/242455 "2020-08-19T10:01:30Z")

</div>

Kibana version: 7.7.0 Elasticsearch version: 7.7.0 APM Server version: apm-server-7.7.0-x86\_64.rpm APM Agent language and version: elastic-apm-agent-1.16.0.jar Browser version: Chrome 84.0 Original install method (e…

---

## [Failed to close the XContentBuilder](https://discuss.elastic.co/t/failed-to-close-the-xcontentbuilder/175492)

<div class="topic-metadata">

**Author:** [@EliuFlorez](https://discuss.elastic.co/u/EliuFlorez)\
**Replies:** 10\
**Last updated:** [April 5, 2019, 5:10pm UTC](https://discuss.elastic.co/t/failed-to-close-the-xcontentbuilder/175492 "2019-04-05T17:10:44Z")

</div>

Hi guys, I'm presenting an error to install the plugin or make a query. Code: @Override public XContentBuilder toXContent(XContentBuilder builder, Params params) throws IOException { builder.startObject(simple…

---

## [Date mapping issue](https://discuss.elastic.co/t/date-mapping-issue/112899)

<div class="topic-metadata">

**Author:** [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Replies:** 16\
**Last updated:** [December 22, 2017, 1:20pm UTC](https://discuss.elastic.co/t/date-mapping-issue/112899 "2017-12-22T13:20:15Z")

</div>

I've been getting this warning when running my Logstash pipeline. I'm using the date filter on this field and math this pattern: yyyy-MM-dd HH:mm:ss so I'm not sure why I'm seeing this warning. \[2017-12-21T21:27:55,443\]…

---

## [Entity-Centric Indexing - reliability and performance](https://discuss.elastic.co/t/entity-centric-indexing-reliability-and-performance/93374)

<div class="topic-metadata">

**Author:** [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Replies:** 15\
**Last updated:** [July 19, 2017, 8:19am UTC](https://discuss.elastic.co/t/entity-centric-indexing-reliability-and-performance/93374 "2017-07-19T08:19:44Z")

</div>

I get the general principle of Mark Harwood's entity-centric indexing pattern, and I've written some code, and it works. The problem I've got is around the "periodic extracts sorted by entity ID and time" - how do you …

---

## [How to query multiple fileds in Kibana](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611)

<div class="topic-metadata">

**Author:** [@dev9](https://discuss.elastic.co/u/dev9)\
**Replies:** 22\
**Last updated:** [June 9, 2022, 12:41am UTC](https://discuss.elastic.co/t/how-to-query-multiple-fileds-in-kibana/306611 "2022-06-09T00:41:10Z")

</div>

Hi, I am trying to query kibana for multiple fields where the servicename is serviceworker and the correlationId is one of many. My understanding is using terms is the best option here but I cannot get this query to wo…

---

## [Filebeat rc1 resends full data set data upon random restart (registry file not updated properly)?](https://discuss.elastic.co/t/filebeat-rc1-resends-full-data-set-data-upon-random-restart-registry-file-not-updated-properly/63580)

<div class="topic-metadata">

**Author:** [@shog](https://discuss.elastic.co/u/shog)\
**Replies:** 19\
**Last updated:** [November 8, 2016, 4:17pm UTC](https://discuss.elastic.co/t/filebeat-rc1-resends-full-data-set-data-upon-random-restart-registry-file-not-updated-properly/63580 "2016-11-08T16:17:43Z")

</div>

Hi, Recently I've reported https://discuss.elastic.co/t/filebeat-beta1-resends-random-data-upon-every-restart-registry-file-not-updated-properly/61813/1 where we didn't really reach a clear conclusion, but I was able …

[Previous page](https://discuss.elastic.co/top.md?page=65&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=67&per_page=50&period=all)
