# Top

**URL:** https://discuss.elastic.co/top.md?page=67&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 68

---

## [Logstash email alerts dynamically from multiple log files](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009)

<div class="topic-metadata">

**Author:** [@abathula](https://discuss.elastic.co/u/abathula)\
**Replies:** 9\
**Last updated:** [July 7, 2015, 1:39pm UTC](https://discuss.elastic.co/t/logstash-email-alerts-dynamically-from-multiple-log-files/25009 "2015-07-07T13:39:13Z")

</div>

I have the logstash config file in which i have written the mail alert for particular text present in the message then automatically send an email with the message. Please find the configuration file (logstash.conf). i…

---

## [List/backup/restore watchers](https://discuss.elastic.co/t/list-backup-restore-watchers/123403)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 11\
**Last updated:** [April 14, 2018, 9:44pm UTC](https://discuss.elastic.co/t/list-backup-restore-watchers/123403 "2018-04-14T21:44:33Z")

</div>

I created several Watches via Kibana and after looking over at Watcher APIs | Elasticsearch Reference \[6.2\] | Elastic I have following questions: Is there a way to get list all watchers? Is there a way to GET watcher …

---

## [How to implement deflate (best compression)?](https://discuss.elastic.co/t/how-to-implement-deflate-best-compression/289984)

<div class="topic-metadata">

**Author:** [@Linuxuser](https://discuss.elastic.co/u/Linuxuser)\
**Replies:** 23\
**Last updated:** [November 25, 2021, 11:00pm UTC](https://discuss.elastic.co/t/how-to-implement-deflate-best-compression/289984 "2021-11-25T23:00:24Z")

</div>

Hello, kindly help me out. My elastic version is 6.3 how can i implement best compression for the log stored by elastic. Thanks

---

## [Kibana stopped showing logs; error failed to poll for work](https://discuss.elastic.co/t/kibana-stopped-showing-logs-error-failed-to-poll-for-work/308894)

<div class="topic-metadata">

**Author:** [@Baguette](https://discuss.elastic.co/u/Baguette)\
**Replies:** 10\
**Last updated:** [July 6, 2022, 1:43pm UTC](https://discuss.elastic.co/t/kibana-stopped-showing-logs-error-failed-to-poll-for-work/308894 "2022-07-06T13:43:48Z")

</div>

Hello there, I recently have some trouble with my ELK stack which suddently stoppend working since 2022 july 4th. With some research in the logs, i've found somehting strange : {"ecs":{"version":"8.0.0"},"@timestamp":…

---

## [Fluentd to elastic](https://discuss.elastic.co/t/fluentd-to-elastic/190427)

<div class="topic-metadata">

**Author:** [@Soumitra\_Ghosh](https://discuss.elastic.co/u/Soumitra_Ghosh)\
**Replies:** 14\
**Last updated:** [July 16, 2019, 1:37pm UTC](https://discuss.elastic.co/t/fluentd-to-elastic/190427 "2019-07-16T13:37:17Z")

</div>

I am shipping logs using fluentd in k8s cluster i see a bunch of the following messages and logs stop flowing to ES warn\]: \[elasticsearch\] failed to write data into buffer by buffer overflow action=:block Any thoughts …

---

## [Disable increment of version counter on some update operations possible?](https://discuss.elastic.co/t/disable-increment-of-version-counter-on-some-update-operations-possible/15294)

<div class="topic-metadata">

**Author:** [@joa](https://discuss.elastic.co/u/joa)\
**Replies:** 16\
**Last updated:** [January 20, 2014, 7:37pm UTC](https://discuss.elastic.co/t/disable-increment-of-version-counter-on-some-update-operations-possible/15294 "2014-01-20T19:37:37Z")

</div>

Is it possible to disable the increment of the version counter on some update operations? I've a views counter which is updated whenever user "opens" a file in ma app. body: { script: 'ctx.\_source.views += 1',}…

---

## [Confused about query\_string and the use of wildcards](https://discuss.elastic.co/t/confused-about-query-string-and-the-use-of-wildcards/4103)

<div class="topic-metadata">

**Author:** [@Enrique\_Medina\_Monte](https://discuss.elastic.co/u/Enrique_Medina_Monte)\
**Replies:** 34\
**Last updated:** [March 17, 2011, 10:13am UTC](https://discuss.elastic.co/t/confused-about-query-string-and-the-use-of-wildcards/4103 "2011-03-17T10:13:24Z")

</div>

Hi, I'm struggling on why a simple query like this one: "query": { "query\_string": { "default\_operator": "AND", "query": "\*phone" } } does not return any results, whereas this one (n…

---

## [Kibana Extremely slow Start Up Time on Openshift/Kubernetes while Optimizing and caching bundles](https://discuss.elastic.co/t/kibana-extremely-slow-start-up-time-on-openshift-kubernetes-while-optimizing-and-caching-bundles/245203)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 13\
**Last updated:** [August 20, 2020, 2:22pm UTC](https://discuss.elastic.co/t/kibana-extremely-slow-start-up-time-on-openshift-kubernetes-while-optimizing-and-caching-bundles/245203 "2020-08-20T14:22:11Z")

</div>

Hi guys, The deployment of kibana on openshift is extremely slow after or during this step: "Optimizing and caching bundles.... This may take a few minutes" The deployment takes about 7-8 minutes. You have an Idea how…

---

## [2.2.0 ESIntegTestCase - ClassNotFoundException when executing groovy script in search](https://discuss.elastic.co/t/2-2-0-esintegtestcase-classnotfoundexception-when-executing-groovy-script-in-search/43579)

<div class="topic-metadata">

**Author:** [@Olafur\_Gauti\_Gudmund](https://discuss.elastic.co/u/Olafur_Gauti_Gudmund)\
**Replies:** 10\
**Last updated:** [March 8, 2016, 11:19am UTC](https://discuss.elastic.co/t/2-2-0-esintegtestcase-classnotfoundexception-when-executing-groovy-script-in-search/43579 "2016-03-08T11:19:38Z")

</div>

Hi, I've been using Elastic 1.4.4, but we're now upgrading to 2.2.0. I am having trouble getting my integration tests to run. The error I'm getting is following: { "error": { "root\_cause": \[{ "t…

---

## [Unable to add "total\_fields.limit" in template in ELK 6.3.0](https://discuss.elastic.co/t/unable-to-add-total-fields-limit-in-template-in-elk-6-3-0/146620)

<div class="topic-metadata">

**Author:** [@deepsing](https://discuss.elastic.co/u/deepsing)\
**Replies:** 23\
**Last updated:** [September 6, 2018, 1:13pm UTC](https://discuss.elastic.co/t/unable-to-add-total-fields-limit-in-template-in-elk-6-3-0/146620 "2018-09-06T13:13:02Z")

</div>

Hi Followed this link to update the template Increase total fields limit via creation of index in logstash to add "index.mapping.total\_fields.limit": 10000 in template.json Below is the part of my updated template.json…

---

## [Struggling with Multiline](https://discuss.elastic.co/t/struggling-with-multiline/109357)

<div class="topic-metadata">

**Author:** [@rosselg](https://discuss.elastic.co/u/rosselg)\
**Replies:** 10\
**Last updated:** [December 1, 2017, 7:00am UTC](https://discuss.elastic.co/t/struggling-with-multiline/109357 "2017-12-01T07:00:10Z")

</div>

Good morning, I'm (still) facing some problems with the filebeat multiline feature. My filebeat.yml is the following: prospectors: - paths: - /tmp/multiline\*.log input\_type: log …

---

## [Can't not bind listen port 5140 to logstash ubuntu 18.04](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428)

<div class="topic-metadata">

**Author:** [@Bubba\_Shakes](https://discuss.elastic.co/u/Bubba_Shakes)\
**Replies:** 24\
**Last updated:** [October 6, 2019, 5:41pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428 "2019-10-06T17:41:20Z")

</div>

Nothing is using that port, guyp@ubuntu:/etc/logstash/conf.d$ netstat -an | grep 5140 tcp 0 0 127.0.0.1:9200 127.0.0.1:51406 ESTABLISHED tcp 0 0 127.0.0.1:9200 127.0.0…

---

## [How to get currently logged in USERID in plugin?](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627)

<div class="topic-metadata">

**Author:** [@dianadijan](https://discuss.elastic.co/u/dianadijan)\
**Replies:** 10\
**Last updated:** [April 18, 2017, 9:00pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627 "2017-04-18T21:00:25Z")

</div>

I am developing a plugin for Kibana 4.3.0 How to get the userid of currently logged in Kibana user?

---

## [Bad bulk performance with self-generated id](https://discuss.elastic.co/t/bad-bulk-performance-with-self-generated-id/103344)

<div class="topic-metadata">

**Author:** [@ginger](https://discuss.elastic.co/u/ginger)\
**Replies:** 16\
**Last updated:** [October 12, 2017, 4:35am UTC](https://discuss.elastic.co/t/bad-bulk-performance-with-self-generated-id/103344 "2017-10-12T04:35:32Z")

</div>

Hi, all. We recently use ES to store monitor data and depend on self-generated id to remove duplicate data. Our ES configure is as follows: 3 node(24core, 128GB, 3T SSD) -Xms30g -Xmx30g indices.memory.index\_buffer\_s…

---

## [Elastic Agents disappearing](https://discuss.elastic.co/t/elastic-agents-disappearing/280172)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 23\
**Last updated:** [August 19, 2021, 8:27am UTC](https://discuss.elastic.co/t/elastic-agents-disappearing/280172 "2021-08-19T08:27:36Z")

</div>

I'm on 7.13.4 using fleet server and my agents have disappeared overnight. I've tried restarting the entire cluster (in elastic cloud) and the agents all still show as offline in fleet. The cluster health is al good too…

---

## [How to reduce the log size?](https://discuss.elastic.co/t/how-to-reduce-the-log-size/106903)

<div class="topic-metadata">

**Author:** [@manojcts91](https://discuss.elastic.co/u/manojcts91)\
**Replies:** 9\
**Last updated:** [November 8, 2017, 9:29pm UTC](https://discuss.elastic.co/t/how-to-reduce-the-log-size/106903 "2017-11-08T21:29:26Z")

</div>

Hi Team, Sorry if this question is already answered. I have a serious problem, My each log in Elasticsearch is about 2 MB (My indices now are around 350 GB), I am confused Is that the expected behavior from Elasticsearc…

---

## [Hunspell](https://discuss.elastic.co/t/hunspell/106807)

<div class="topic-metadata">

**Author:** [@Atul\_Harsha](https://discuss.elastic.co/u/Atul_Harsha)\
**Replies:** 10\
**Last updated:** [November 10, 2017, 5:26am UTC](https://discuss.elastic.co/t/hunspell/106807 "2017-11-10T05:26:36Z")

</div>

INPUT: PUT /my\_index { "settings": { "analysis": { "filter": { "en\_US": { "type": "hunspell", "language": "en\_US" } }, "analyzer": { "en\_US": { …

---

## [Logstash not working!](https://discuss.elastic.co/t/logstash-not-working/264983)

<div class="topic-metadata">

**Author:** [@Mohyden](https://discuss.elastic.co/u/Mohyden)\
**Replies:** 9\
**Last updated:** [March 7, 2021, 5:17am UTC](https://discuss.elastic.co/t/logstash-not-working/264983 "2021-03-07T05:17:27Z")

</div>

Hello, I'm running Ubuntu 16.04. When I try to start Logstash with systemctl start logstash, and then systemctl status logstash, it shows these: logstash.service - logstash Loaded: loaded (/etc/systemd/system/logstash…

---

## [Indexing on the basis of fields in filebeat.yml](https://discuss.elastic.co/t/indexing-on-the-basis-of-fields-in-filebeat-yml/48684)

<div class="topic-metadata">

**Author:** [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Replies:** 12\
**Last updated:** [May 3, 2016, 11:59am UTC](https://discuss.elastic.co/t/indexing-on-the-basis-of-fields-in-filebeat-yml/48684 "2016-05-03T11:59:10Z")

</div>

Hi, I am using FB to send logs to LS-Shipper. Event processing pipeline is FB-LS-Shipper-\>Redis-\>LS-Indexer-\>nGinx--\>ES Below is FB configuration. Note: I have created one field Application with 'A' in uppercase. f…

---

## [Tomcat logs are seeing appearing in order in discover section in kibana](https://discuss.elastic.co/t/tomcat-logs-are-seeing-appearing-in-order-in-discover-section-in-kibana/286969)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 31\
**Last updated:** [October 26, 2021, 10:03pm UTC](https://discuss.elastic.co/t/tomcat-logs-are-seeing-appearing-in-order-in-discover-section-in-kibana/286969 "2021-10-26T22:03:55Z")

</div>

Hi Team, I have tomcat application running on two servers and sending logs to logstash through filebeat, when checking logs in discover section of kibana, I am not seeing exact sequence of logs in kibana as in server. f…

---

## [One time batch processing big number of files](https://discuss.elastic.co/t/one-time-batch-processing-big-number-of-files/46461)

<div class="topic-metadata">

**Author:** [@Alexander\_Popov](https://discuss.elastic.co/u/Alexander_Popov)\
**Replies:** 12\
**Last updated:** [April 6, 2016, 1:37pm UTC](https://discuss.elastic.co/t/one-time-batch-processing-big-number-of-files/46461 "2016-04-06T13:37:52Z")

</div>

Have ~ 50K files in single directory( ~200Gb ) of logs. trying to process to parse and add them to elasticsearch my config: input { file { path =\> "/mnt/storage/\*.txt" sincedb\_path =\> "/dev/null" codec …

---

## [Can we assign colors to specific fields in kibana?](https://discuss.elastic.co/t/can-we-assign-colors-to-specific-fields-in-kibana/327624)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 10\
**Last updated:** [January 10, 2024, 3:32pm UTC](https://discuss.elastic.co/t/can-we-assign-colors-to-specific-fields-in-kibana/327624 "2024-01-10T15:32:00Z")

</div>

Hello, I can see how to select a color palette for a kibanaq dashboard lens visualization, but what I'd really like to be able to do is choose a particular field (like a "bad" field) and assign it red, and choose a "goo…

---

## [Usage of "or" operator in logstash grok filters](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132)

<div class="topic-metadata">

**Author:** [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Replies:** 10\
**Last updated:** [August 28, 2019, 5:31pm UTC](https://discuss.elastic.co/t/usage-of-or-operator-in-logstash-grok-filters/197132 "2019-08-28T17:31:18Z")

</div>

Hello, I have a condition to check if the 7th-word matches either /list/ or /list or /simple/ or /simple using below condition \[@metadata\]\[copyOfMessage\]\[6\] =~ /^\\/list\\// or /^\\/list/ or /^\\/simple\\// or /^\\/simple/ T…

---

## [High CPU usage state](https://discuss.elastic.co/t/high-cpu-usage-state/26715)

<div class="topic-metadata">

**Author:** [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Replies:** 11\
**Last updated:** [August 7, 2015, 12:35am UTC](https://discuss.elastic.co/t/high-cpu-usage-state/26715 "2015-08-07T00:35:15Z")

</div>

Topic says it...my linuxbox has entered this weird cpu state...where es is taking up a lot of CPU at idle. Logs are clean with no errors. Is there something I can look at to determine the cause? This is on a home mach…

---

## [Folding German characters like umlauts](https://discuss.elastic.co/t/folding-german-characters-like-umlauts/3720)

<div class="topic-metadata">

**Author:** [@harryf](https://discuss.elastic.co/u/harryf)\
**Replies:** 10\
**Last updated:** [November 29, 2011, 7:37am UTC](https://discuss.elastic.co/t/folding-german-characters-like-umlauts/3720 "2011-11-29T07:37:15Z")

</div>

Wondering how best to handle German characters like "ü". Given a word like "Zürich", it needs to be possible to match it with both "Zurich" and "Zuerich". "Zurich" would be regarded as the "international" form that,…

---

## [Replace legend values in Kibana visualizations using Elasticsearch](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862)

<div class="topic-metadata">

**Author:** [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Replies:** 10\
**Last updated:** [November 24, 2019, 9:23am UTC](https://discuss.elastic.co/t/replace-legend-values-in-kibana-visualizations-using-elasticsearch/206862 "2019-11-24T09:23:28Z")

</div>

How can I replace the ID values at the bottom of this graph with something like A, B, C using Elasticsearch or Kibana UI tool?

---

## [Elasticsearch 6.8 security update error while configuring it](https://discuss.elastic.co/t/elasticsearch-6-8-security-update-error-while-configuring-it/183484)

<div class="topic-metadata">

**Author:** [@akshay\_singh2](https://discuss.elastic.co/u/akshay_singh2)\
**Replies:** 11\
**Last updated:** [June 11, 2019, 8:44am UTC](https://discuss.elastic.co/t/elasticsearch-6-8-security-update-error-while-configuring-it/183484 "2019-06-11T08:44:43Z")

</div>

Hello, I'm trying to setup security x.pack on existing cluster (6.8.0), while setting up in test environment I'm getting below error: 2019-05-30T13:23:13,926\]\[WARN \]\[o.e.h.n.Netty4HttpServerTransport\] \[data-master1\] ca…

---

## [Aggregate fields based on nested filter with custom separator](https://discuss.elastic.co/t/aggregate-fields-based-on-nested-filter-with-custom-separator/98008)

<div class="topic-metadata">

**Author:** [@malhotras](https://discuss.elastic.co/u/malhotras)\
**Replies:** 15\
**Last updated:** [August 25, 2017, 8:39pm UTC](https://discuss.elastic.co/t/aggregate-fields-based-on-nested-filter-with-custom-separator/98008 "2017-08-25T20:39:16Z")

</div>

I would like to aggregate some of the fields based on other nested fields. Here is how my data looks like: { "place" =\> "abc", "m\_id" =\> 5099, "address" =\> "Kurt-Schumacher-Ring 15-17", "name" =\>…

---

## [Filebeat docker running on windows not allowing application to rotate the log!](https://discuss.elastic.co/t/filebeat-docker-running-on-windows-not-allowing-application-to-rotate-the-log/89616)

<div class="topic-metadata">

**Author:** [@Somnath\_Shantveer](https://discuss.elastic.co/u/Somnath_Shantveer)\
**Replies:** 12\
**Last updated:** [June 16, 2017, 8:19pm UTC](https://discuss.elastic.co/t/filebeat-docker-running-on-windows-not-allowing-application-to-rotate-the-log/89616 "2017-06-16T20:19:32Z")

</div>

I am using filebeat image - docker.elastic.co/beats/filebeat:5.4.1 to setup filebeat container locally on windows to read logs from an application and send data to logstash. The application which generate logs will rotat…

---

## [Adding a custom field in alerts without defining in query](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts-without-defining-in-query/255300)

<div class="topic-metadata">

**Author:** [@PD98](https://discuss.elastic.co/u/PD98)\
**Replies:** 12\
**Last updated:** [November 20, 2020, 4:23am UTC](https://discuss.elastic.co/t/adding-a-custom-field-in-alerts-without-defining-in-query/255300 "2020-11-20T04:23:13Z")

</div>

Hi, I have a field called organization.name in my logs. I have created a rule based on the field externalId only. However I want that the organization.name field should also be fetched when the alert is generated. I don…

---

## [How to concatenate two fields using add fields processor in filebeat](https://discuss.elastic.co/t/how-to-concatenate-two-fields-using-add-fields-processor-in-filebeat/306488)

<div class="topic-metadata">

**Author:** [@Anagha\_nambiar](https://discuss.elastic.co/u/Anagha_nambiar)\
**Replies:** 13\
**Last updated:** [June 9, 2022, 4:16pm UTC](https://discuss.elastic.co/t/how-to-concatenate-two-fields-using-add-fields-processor-in-filebeat/306488 "2022-06-09T16:16:45Z")

</div>

I have 2 fields with one field carrying date value and another field carrying time value. I would like to have a single field with both date and time values concatenated. Could you please suggest?

---

## [Missing event - file input plugin / NFS](https://discuss.elastic.co/t/missing-event-file-input-plugin-nfs/107838)

<div class="topic-metadata">

**Author:** [@franck.lefebure](https://discuss.elastic.co/u/franck.lefebure)\
**Replies:** 19\
**Last updated:** [November 17, 2017, 4:29pm UTC](https://discuss.elastic.co/t/missing-event-file-input-plugin-nfs/107838 "2017-11-17T16:29:40Z")

</div>

Hi, We have a problem with our Logstash Installation and I 'm a little stuck. Initially, our logstash install was a v2.4 four nodes install. We recently spent some days to migrate towards 5.6.4 with some hope the probl…

---

## [ELK Stack restrict access to some data](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687)

<div class="topic-metadata">

**Author:** [@asyakovlev](https://discuss.elastic.co/u/asyakovlev)\
**Replies:** 12\
**Last updated:** [October 6, 2017, 4:02am UTC](https://discuss.elastic.co/t/elk-stack-restrict-access-to-some-data/102687 "2017-10-06T04:02:41Z")

</div>

Now I'm touch a elk stack for a log collecting, also install xpack to kibana and elasticsearch. How I can restrict access to some logs group (any hosts) for any people? For log collecting I'm using logstash, listen some …

---

## [Winlogbeat v5 - Message not read fully](https://discuss.elastic.co/t/winlogbeat-v5-message-not-read-fully/51062)

<div class="topic-metadata">

**Author:** [@rhyse](https://discuss.elastic.co/u/rhyse)\
**Replies:** 9\
**Last updated:** [May 31, 2016, 10:27am UTC](https://discuss.elastic.co/t/winlogbeat-v5-message-not-read-fully/51062 "2016-05-31T10:27:40Z")

</div>

Hi I am testing the eventlog beat for file / folder auditing. There seems to be a problem with pulling out the Access request Information of the message. The error I am getting on the client side is 2016-05-24T20:…

---

## [Logstash open\_file handle issue For Linux](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959)

<div class="topic-metadata">

**Author:** [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Replies:** 22\
**Last updated:** [March 1, 2019, 3:14am UTC](https://discuss.elastic.co/t/logstash-open-file-handle-issue-for-linux/168959 "2019-03-01T03:14:21Z")

</div>

I'm facing until recently a very peculiar warning on the logstash log file \[filewatch.tailmode.handlers.createinitial\] open\_file OPEN\_WARN\_INTERVAL is '300', i've searched around the web for every possible help to dig i…

---

## [Plugin head for elasticsearch-5.0.0-alpha1](https://discuss.elastic.co/t/plugin-head-for-elasticsearch-5-0-0-alpha1/46714)

<div class="topic-metadata">

**Author:** [@Diyal](https://discuss.elastic.co/u/Diyal)\
**Replies:** 12\
**Last updated:** [July 26, 2016, 9:58am UTC](https://discuss.elastic.co/t/plugin-head-for-elasticsearch-5-0-0-alpha1/46714 "2016-07-26T09:58:52Z")

</div>

Hi, This command : bin/elasticsearch-plugin install mobz/elasticsearch-head doesn't work for elasticsearch-5.0.0-alpha1. So, the head plugin for this elasticsearch's version is already available or not ? Thanks …

---

## [\[ERROR\]\[logstash.filters.ruby \] Ruby exception occurred: undefined method \`split' for nil:NilClass](https://discuss.elastic.co/t/error-logstash-filters-ruby-ruby-exception-occurred-undefined-method-split-for-nil-nilclass/178329)

<div class="topic-metadata">

**Author:** [@mattsdevop](https://discuss.elastic.co/u/mattsdevop)\
**Replies:** 9\
**Last updated:** [June 19, 2019, 6:36pm UTC](https://discuss.elastic.co/t/error-logstash-filters-ruby-ruby-exception-occurred-undefined-method-split-for-nil-nilclass/178329 "2019-06-19T18:36:37Z")

</div>

Attempting to send syslog from a Barracuda firewall to logstash. Hoping somebody can help out here. Using logstash configuration from here (waf.conf) with the appropriate changes for my stack: https://campus.barracuda.co…

---

## [Filebeat not sending new logs to ELK server untill restart](https://discuss.elastic.co/t/filebeat-not-sending-new-logs-to-elk-server-untill-restart/60060)

<div class="topic-metadata">

**Author:** [@vsairam](https://discuss.elastic.co/u/vsairam)\
**Replies:** 12\
**Last updated:** [September 20, 2016, 11:53am UTC](https://discuss.elastic.co/t/filebeat-not-sending-new-logs-to-elk-server-untill-restart/60060 "2016-09-20T11:53:24Z")

</div>

Hi, My filebeat version : filebeat version 1.2.3 My Filebeat.yml is pretty straighforward : filebeat: prospectors: - paths: - /var/log/messages - /var/log/mesos/\* input\_type: log…

---

## [Example documents](https://discuss.elastic.co/t/example-documents/48726)

<div class="topic-metadata">

**Author:** [@reza\_sadoddin](https://discuss.elastic.co/u/reza_sadoddin)\
**Replies:** 11\
**Last updated:** [May 26, 2016, 3:53pm UTC](https://discuss.elastic.co/t/example-documents/48726 "2016-05-26T15:53:03Z")

</div>

The graph has the nice feature of "show example documents". However, I just can see the ID's of documents. No information is shown for other fields of documents. Does that mean the documents should be returned by IDs in …

---

## [Term Filter not working](https://discuss.elastic.co/t/term-filter-not-working/37159)

<div class="topic-metadata">

**Author:** [@NathanCoats](https://discuss.elastic.co/u/NathanCoats)\
**Replies:** 10\
**Last updated:** [December 15, 2015, 3:23am UTC](https://discuss.elastic.co/t/term-filter-not-working/37159 "2015-12-15T03:23:42Z")

</div>

Hey everybody i have been trying to get my query working for a while now, and i finally broke down and added a new field into my mongo database. i use mongo-connector to import the data from mongo to elastic search. htt…

---

## [ES service keeps crashing](https://discuss.elastic.co/t/es-service-keeps-crashing/250661)

<div class="topic-metadata">

**Author:** [@Craig2188](https://discuss.elastic.co/u/Craig2188)\
**Replies:** 11\
**Last updated:** [October 2, 2020, 10:38am UTC](https://discuss.elastic.co/t/es-service-keeps-crashing/250661 "2020-10-02T10:38:48Z")

</div>

Hi, Just realised that after I start the service for Elastic it stops running after about 2 minutes. Checked the event logs and see some errors: Application: elasticsearch.exe Framework Version: v4.0.30319 Descripti…

---

## [Kubernetes - ConfigMap](https://discuss.elastic.co/t/kubernetes-configmap/123812)

<div class="topic-metadata">

**Author:** [@bitva77](https://discuss.elastic.co/u/bitva77)\
**Replies:** 9\
**Last updated:** [March 16, 2018, 4:35pm UTC](https://discuss.elastic.co/t/kubernetes-configmap/123812 "2018-03-16T16:35:04Z")

</div>

Hi! I'm having an issue with Filebeat running in Kubernetes. I'm using the filebeat-kubernetes.yml file from the documentation and have made following change to the filebeat-prospectors ConfigMap: \> data: \> kubernet…

---

## [Can't connect to ES 1.6](https://discuss.elastic.co/t/cant-connect-to-es-1-6/2315)

<div class="topic-metadata">

**Author:** [@Trident50](https://discuss.elastic.co/u/Trident50)\
**Replies:** 21\
**Last updated:** [June 17, 2015, 8:18am UTC](https://discuss.elastic.co/t/cant-connect-to-es-1-6/2315 "2015-06-17T08:18:53Z")

</div>

I was able to index 230K documents overnight, doing a curl on health and indices I can see the index and the health returns a yellow status - everything just like on the previous version of ES - except I can't seem to co…

---

## [GeoIP enrichment not working](https://discuss.elastic.co/t/geoip-enrichment-not-working/275084)

<div class="topic-metadata">

**Author:** [@farciarz121](https://discuss.elastic.co/u/farciarz121)\
**Replies:** 30\
**Last updated:** [June 8, 2021, 5:56pm UTC](https://discuss.elastic.co/t/geoip-enrichment-not-working/275084 "2021-06-08T17:56:39Z")

</div>

I am trying to setup Geolocation based on IP. I am conecting packetbeat to elastic cloud directly. I have followed instruction from : https://www.elastic.co/guide/en/beats/packetbeat/master/packetbeat-geoip.html But I…

---

## [Indexing around 140 million addresses - need some performance tips](https://discuss.elastic.co/t/indexing-around-140-million-addresses-need-some-performance-tips/13462)

<div class="topic-metadata">

**Author:** [@Anthony\_Campagna](https://discuss.elastic.co/u/Anthony_Campagna)\
**Replies:** 11\
**Last updated:** [September 4, 2013, 9:12pm UTC](https://discuss.elastic.co/t/indexing-around-140-million-addresses-need-some-performance-tips/13462 "2013-09-04T21:12:32Z")

</div>

I am about to begin a project to index 140 million documents with street addresses, city, state, and zip. I will need to do searches against the entire index everytime a user types in a letter in our search. I was w…

---

## [CSV Timstamp issues](https://discuss.elastic.co/t/csv-timstamp-issues/43050)

<div class="topic-metadata">

**Author:** [@hursto75](https://discuss.elastic.co/u/hursto75)\
**Replies:** 19\
**Last updated:** [March 6, 2016, 6:55am UTC](https://discuss.elastic.co/t/csv-timstamp-issues/43050 "2016-03-06T06:55:14Z")

</div>

Here is my conf file, and it seems to be working ok, except I need the timestamp to be the actually time in the csv file. Not the time the file was added. What am i doing wrong.... total Noob here. Sorry. input { …

---

## [Архитектура кластера ElasticSearch](https://discuss.elastic.co/t/elasticsearch/198019)

<div class="topic-metadata">

**Author:** [@Lebedev](https://discuss.elastic.co/u/Lebedev)\
**Replies:** 10\
**Last updated:** [September 11, 2019, 9:22am UTC](https://discuss.elastic.co/t/elasticsearch/198019 "2019-09-11T09:22:57Z")

</div>

Здравствуйте, коллеги. Проконсультируйте, пожалуйста. В настоящий момент я собираю кластер ElasticSearch. Получается следующая схема (HA): Площадка 1(основная): 1хMaster node 3хData node(hot) Площадка 2(резервная …

---

## [Elasticsearch 5.6.9 and x-pack monitoring](https://discuss.elastic.co/t/elasticsearch-5-6-9-and-x-pack-monitoring/195088)

<div class="topic-metadata">

**Author:** [@shradhatx](https://discuss.elastic.co/u/shradhatx)\
**Replies:** 29\
**Last updated:** [August 29, 2019, 7:11pm UTC](https://discuss.elastic.co/t/elasticsearch-5-6-9-and-x-pack-monitoring/195088 "2019-08-29T19:11:08Z")

</div>

The elasticsearch is running version 5.6.9 I like to monitor cluster with x-pack monitoring (free features given in later versions). It is complaining about licenses. Can it be turned off without upgrading cluster to 6…

---

## [Misconfigured instance or proxy (302 redirect loop)](https://discuss.elastic.co/t/misconfigured-instance-or-proxy-302-redirect-loop/221126)

<div class="topic-metadata">

**Author:** [@jbpratt](https://discuss.elastic.co/u/jbpratt)\
**Replies:** 11\
**Last updated:** [March 18, 2020, 7:49pm UTC](https://discuss.elastic.co/t/misconfigured-instance-or-proxy-302-redirect-loop/221126 "2020-03-18T19:49:57Z")

</div>

Hi! I am running into issues with my Kibana instance behind an Nginx reverse proxy. I have a very minimal Kibana config which could be an issue though it seems like I have what I need. That being said, I am quite sure …

---

## [How to check/wait until all outstanding bulk (index) operations are complete?](https://discuss.elastic.co/t/how-to-check-wait-until-all-outstanding-bulk-index-operations-are-complete/232490)

<div class="topic-metadata">

**Author:** [@redec](https://discuss.elastic.co/u/redec)\
**Replies:** 10\
**Last updated:** [May 13, 2020, 11:50pm UTC](https://discuss.elastic.co/t/how-to-check-wait-until-all-outstanding-bulk-index-operations-are-complete/232490 "2020-05-13T23:50:21Z")

</div>

Is there some way to wait for all outstanding indexing operations to complete, across the entire index? the refresh=wait\_for parameter will only wait for the documents which are modified in this query, and only on the s…

[Previous page](https://discuss.elastic.co/top.md?page=66&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=68&per_page=50&period=all)
