# Top

**URL:** https://discuss.elastic.co/top.md?page=68&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 69

---

## [What is excluded column in kibana index pattern?](https://discuss.elastic.co/t/what-is-excluded-column-in-kibana-index-pattern/252667)

<div class="topic-metadata">

**Author:** [@Matthew\_Field](https://discuss.elastic.co/u/Matthew_Field)\
**Replies:** 16\
**Last updated:** [October 23, 2020, 7:52am UTC](https://discuss.elastic.co/t/what-is-excluded-column-in-kibana-index-pattern/252667 "2020-10-23T07:52:45Z")

</div>

I am trying to create an index pattern in kibana and setting the time field to be @timestamp. The index pattern apparently creates OK with @timestamp as the time filter, but when i refresh the fields, the time filter ge…

---

## [Monitor inactivity in log files](https://discuss.elastic.co/t/monitor-inactivity-in-log-files/50597)

<div class="topic-metadata">

**Author:** [@vikas\_J](https://discuss.elastic.co/u/vikas_J)\
**Replies:** 14\
**Last updated:** [May 23, 2016, 11:03pm UTC](https://discuss.elastic.co/t/monitor-inactivity-in-log-files/50597 "2016-05-23T23:03:15Z")

</div>

I have certain log files being monitored through ELK stack using filbebeat to send files to log stash. Suppose if the server is down and the logs are no longer being written, i want to monitor the same. Is there some way…

---

## [Problem with xml filter](https://discuss.elastic.co/t/problem-with-xml-filter/80725)

<div class="topic-metadata">

**Author:** [@flalar](https://discuss.elastic.co/u/flalar)\
**Replies:** 11\
**Last updated:** [April 4, 2017, 7:37am UTC](https://discuss.elastic.co/t/problem-with-xml-filter/80725 "2017-04-04T07:37:35Z")

</div>

We're having issues setting a date pulled from a xml document as @timestamp in the date filter. input xml looks like this \<Task\> \<TaskId\>ServerTasks-5017\</TaskId\> \<TaskState\>Success\</TaskState\> \<Created\>2…

---

## [Building a custom tokenizer: "Could not find suitable constructor"](https://discuss.elastic.co/t/building-a-custom-tokenizer-could-not-find-suitable-constructor/101138)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 15\
**Last updated:** [September 25, 2017, 2:13pm UTC](https://discuss.elastic.co/t/building-a-custom-tokenizer-could-not-find-suitable-constructor/101138 "2017-09-25T14:13:08Z")

</div>

I'm building a custom tokenizer in response to this: Performance of doc\_values field vs analysed field None of this API appears to be documented (?), so I'm going off of code samples from other plugins/tokenizers, but w…

---

## [Adding/configuring available visualization fields](https://discuss.elastic.co/t/adding-configuring-available-visualization-fields/59467)

<div class="topic-metadata">

**Author:** [@hburnswell](https://discuss.elastic.co/u/hburnswell)\
**Replies:** 18\
**Last updated:** [September 14, 2016, 4:36pm UTC](https://discuss.elastic.co/t/adding-configuring-available-visualization-fields/59467 "2016-09-14T16:36:23Z")

</div>

All, I am new to ELK and have been reading and watching docs and videos for the last week. I have everything (Elasticsearch, Logstash, Kibana, filebeat) installed and have a dev apache server sending access and error l…

---

## [GROK filter throws ERROR](https://discuss.elastic.co/t/grok-filter-throws-error/143424)

<div class="topic-metadata">

**Author:** [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Replies:** 24\
**Last updated:** [August 9, 2018, 8:47am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424 "2018-08-09T08:47:48Z")

</div>

I have written a filter to parse logs based on some condition : filter { if \[message\] =~ "\\tat" { grok { match =\> \["message", "^(\\tat)"\] add\_tag =\> \["stacktrace"\] } } grok { if(\[fields\]\[log\_ty…

---

## [How to create multiple Indices of elasticsearch using logstash configuration](https://discuss.elastic.co/t/how-to-create-multiple-indices-of-elasticsearch-using-logstash-configuration/222537)

<div class="topic-metadata">

**Author:** [@Pathshala\_Gopi](https://discuss.elastic.co/u/Pathshala_Gopi)\
**Replies:** 14\
**Last updated:** [March 9, 2020, 12:16pm UTC](https://discuss.elastic.co/t/how-to-create-multiple-indices-of-elasticsearch-using-logstash-configuration/222537 "2020-03-09T12:16:57Z")

</div>

Hello everyone, I am trying to create different indices of elasticsearch using logstash but i am not able to do this.can anyone help me out with this.How we can create and send multiple different index to elasticsearc…

---

## [How to check multiple values using if else condition in field and create a new scripted field?](https://discuss.elastic.co/t/how-to-check-multiple-values-using-if-else-condition-in-field-and-create-a-new-scripted-field/231967)

<div class="topic-metadata">

**Author:** [@Emna1](https://discuss.elastic.co/u/Emna1)\
**Replies:** 15\
**Last updated:** [May 14, 2020, 2:51pm UTC](https://discuss.elastic.co/t/how-to-check-multiple-values-using-if-else-condition-in-field-and-create-a-new-scripted-field/231967 "2020-05-14T14:51:42Z")

</div>

Hi, i want to use this code or transform it in kibana in scripted field ?how can i do that, any help please? Blockquote filter { if \[Duration\] \>= 360 { mutate { add\_field =\> { "MT" =\> "50" } } } else if \[Duratio…

---

## [ES 6.4.3 docker container keep crash with error code 139](https://discuss.elastic.co/t/es-6-4-3-docker-container-keep-crash-with-error-code-139/164684)

<div class="topic-metadata">

**Author:** [@blackgrill](https://discuss.elastic.co/u/blackgrill)\
**Replies:** 9\
**Last updated:** [January 25, 2019, 8:33am UTC](https://discuss.elastic.co/t/es-6-4-3-docker-container-keep-crash-with-error-code-139/164684 "2019-01-25T08:33:00Z")

</div>

Hi Everyone, I met a problem with ES v6.4.3 official docker container running on CentOS 7.6 and searchguard plugin.the docker container can start and working,but it will crash with error code 139,which cause we lost som…

---

## [Display text file in Kibana with filebeat and logstash](https://discuss.elastic.co/t/display-text-file-in-kibana-with-filebeat-and-logstash/189692)

<div class="topic-metadata">

**Author:** [@Vladpov](https://discuss.elastic.co/u/Vladpov)\
**Replies:** 11\
**Last updated:** [July 13, 2019, 10:29am UTC](https://discuss.elastic.co/t/display-text-file-in-kibana-with-filebeat-and-logstash/189692 "2019-07-13T10:29:44Z")

</div>

Hi guys, I run ELK Stack (one machine) with filebeat (second machine) as log shipper. I've got txt file with 4228 rows where each row is one log in follow form: Jul 4 13:56:17 vMMR mmr-core\[29839\]: GtsAwegAOMTbez\_15…

---

## [Stored Procedures](https://discuss.elastic.co/t/stored-procedures/115050)

<div class="topic-metadata">

**Author:** [@devil\_srj7](https://discuss.elastic.co/u/devil_srj7)\
**Replies:** 16\
**Last updated:** [January 18, 2018, 1:46pm UTC](https://discuss.elastic.co/t/stored-procedures/115050 "2018-01-18T13:46:08Z")

</div>

Can we have stored procedures in Elasticsearch as we have in MySql?? So that we can call the procedure from Java application just by its name.

---

## [Azure CSPM - Multiple questions](https://discuss.elastic.co/t/azure-cspm-multiple-questions/355534)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 16\
**Last updated:** [April 25, 2024, 11:05am UTC](https://discuss.elastic.co/t/azure-cspm-multiple-questions/355534 "2024-04-25T11:05:05Z")

</div>

Hello, So I just enabled Azure CSPM (8.12.2) and I have some questions: Is there is a way to snooze / acknowledge / ignore findings? Some of the findings are not applicable to our organization and we would like to ig…

---

## [Index is getting deleted automatically with-out deletion policy or command](https://discuss.elastic.co/t/index-is-getting-deleted-automatically-with-out-deletion-policy-or-command/264988)

<div class="topic-metadata">

**Author:** [@Rinku\_Gulia](https://discuss.elastic.co/u/Rinku_Gulia)\
**Replies:** 15\
**Last updated:** [March 2, 2021, 3:30am UTC](https://discuss.elastic.co/t/index-is-getting-deleted-automatically-with-out-deletion-policy-or-command/264988 "2021-03-02T03:30:48Z")

</div>

We are adding data to our 2 indexes( interaction-open\_read\_model\_12 and interaction-closed\_read\_model\_12) with aliases(list\_open\_interactions\_12 && list\_closed\_interactions\_1). we have 3 node system. Almost in one day,…

---

## [Permission denied when starting Elasticsearch 7.17.0 installed via RPM](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192)

<div class="topic-metadata">

**Author:** [@ed\_vf](https://discuss.elastic.co/u/ed_vf)\
**Replies:** 11\
**Last updated:** [April 26, 2022, 8:10pm UTC](https://discuss.elastic.co/t/permission-denied-when-starting-elasticsearch-7-17-0-installed-via-rpm/303192 "2022-04-26T20:10:31Z")

</div>

We are trying to expand our cluster size from 3 nodes to 5 nodes. After installing Elasticsearch via RPM on the new nodes we receive the following 'Permission denied' error when starting the service. \[root@host user\]# s…

---

## [Upgraded first node from 7.17.5 to 8.4. Won't start, claiming there is a 6.4.5 index, but I can't find it](https://discuss.elastic.co/t/upgraded-first-node-from-7-17-5-to-8-4-wont-start-claiming-there-is-a-6-4-5-index-but-i-cant-find-it/317811)

<div class="topic-metadata">

**Author:** [@Brett\_C](https://discuss.elastic.co/u/Brett_C)\
**Replies:** 11\
**Last updated:** [January 7, 2023, 10:57am UTC](https://discuss.elastic.co/t/upgraded-first-node-from-7-17-5-to-8-4-wont-start-claiming-there-is-a-6-4-5-index-but-i-cant-find-it/317811 "2023-01-07T10:57:10Z")

</div>

Hi Everyone, I have just started upgrading my cluster from 7.17.5 to 8.4. I completed the first node, but when I went to start the service, it complained that: \[2022-10-31T17:08:08,683\]\[ERROR\]\[o.e.b.Elasticsearch \]…

---

## [Logstash not sending logs to Elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-logs-to-elasticsearch/300037)

<div class="topic-metadata">

**Author:** [@wallace84](https://discuss.elastic.co/u/wallace84)\
**Replies:** 11\
**Last updated:** [March 23, 2022, 5:46pm UTC](https://discuss.elastic.co/t/logstash-not-sending-logs-to-elasticsearch/300037 "2022-03-23T17:46:32Z")

</div>

Hello, I have been trying for some time to send a simple log to Elasticsearch and after trying a very simple example, the logs are not been sent to Elasticsearch from logstash. Services: In same server for this test O…

---

## [Xml filter array](https://discuss.elastic.co/t/xml-filter-array/96055)

<div class="topic-metadata">

**Author:** [@Lukas\_Tilch](https://discuss.elastic.co/u/Lukas_Tilch)\
**Replies:** 16\
**Last updated:** [August 28, 2017, 12:09pm UTC](https://discuss.elastic.co/t/xml-filter-array/96055 "2017-08-28T12:09:17Z")

</div>

Hello I have a XML file wich contains 10k+ elements, I played around with the XML filter for logstash wich only gives me arrays like this "date" =\> \[ \[ 0\] "Jun 21, 2013 1:48:43 PM", \[ 1\] "Apr 22, 2013 12:16:00 PM", …

---

## [About clean\_removed in Filebeat 5.0.0-alpha5](https://discuss.elastic.co/t/about-clean-removed-in-filebeat-5-0-0-alpha5/59949)

<div class="topic-metadata">

**Author:** [@vin](https://discuss.elastic.co/u/vin)\
**Replies:** 14\
**Last updated:** [September 13, 2016, 7:10am UTC](https://discuss.elastic.co/t/about-clean-removed-in-filebeat-5-0-0-alpha5/59949 "2016-09-13T07:10:07Z")

</div>

Filebeat config: filebeat: prospectors: - paths: - /var/log/applog/app\_\*.log input\_type: log document\_type: applog ignore\_older: 2m close\_eof: true clean\_inactive: 5m close\_removed: true clean\_removed: true …

---

## [Elasticsearch global state file](https://discuss.elastic.co/t/elasticsearch-global-state-file/179416)

<div class="topic-metadata">

**Author:** [@basdfa23](https://discuss.elastic.co/u/basdfa23)\
**Replies:** 17\
**Last updated:** [May 9, 2019, 5:26pm UTC](https://discuss.elastic.co/t/elasticsearch-global-state-file/179416 "2019-05-09T17:26:45Z")

</div>

Is there a way to store the Elasticsearch cluster global state file in a different directory then what is specified under the path.data variable? The problem we are experience is in a hot/cold cluster. Hot nodes are al…

---

## [How to setup logstash with geoip](https://discuss.elastic.co/t/how-to-setup-logstash-with-geoip/72078)

<div class="topic-metadata">

**Author:** [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Replies:** 13\
**Last updated:** [January 24, 2017, 9:01am UTC](https://discuss.elastic.co/t/how-to-setup-logstash-with-geoip/72078 "2017-01-24T09:01:50Z")

</div>

I want to enable this

---

## [Оптимизация в облаке](https://discuss.elastic.co/t/topic/108965)

<div class="topic-metadata">

**Author:** [@111140](https://discuss.elastic.co/u/111140)\
**Replies:** 28\
**Last updated:** [December 10, 2017, 7:43pm UTC](https://discuss.elastic.co/t/topic/108965 "2017-12-10T19:43:14Z")

</div>

Здравствуйте! Использую облачное решение, cluster ID - a275c3. В последнее время столкнулся с периодическим "залипанием" при запросах, даже за короткий промежуток времени. Диск заполнен на 83%, оперативная минимум на 8…

---

## [Одна нода использует больше места на ssd, чем вторая в ES 2.0](https://discuss.elastic.co/t/ssd-es-2-0/32082)

<div class="topic-metadata">

**Author:** [@11116](https://discuss.elastic.co/u/11116)\
**Replies:** 16\
**Last updated:** [October 21, 2015, 7:11pm UTC](https://discuss.elastic.co/t/ssd-es-2-0/32082 "2015-10-21T19:11:45Z")

</div>

Здравствуйте. Из-за нехватки места на SSD под индекс решил попробовать версию 2.0, в которой появился deflate. Удалось снизить используемое место почти в два раза, но возникла такая проблема - периодически одна из нод н…

---

## [How to get rid of wrongly named index that must be lower case](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550)

<div class="topic-metadata">

**Author:** [@ikovalev](https://discuss.elastic.co/u/ikovalev)\
**Replies:** 10\
**Last updated:** [June 17, 2016, 2:15am UTC](https://discuss.elastic.co/t/how-to-get-rid-of-wrongly-named-index-that-must-be-lower-case/52550 "2016-06-17T02:15:12Z")

</div>

Wrong index name esm\_DMZ\_results was put into Logstash config file /opt/logstash/first-pipeline.conf . After that elasticsearch log /data/elastic/logs/elastic\_concept.log start showing "Invalid index name \[esm\_DMZ\_r…

---

## [Getting and Setting Transaction ID](https://discuss.elastic.co/t/getting-and-setting-transaction-id/197947)

<div class="topic-metadata">

**Author:** [@Alsheh](https://discuss.elastic.co/u/Alsheh)\
**Replies:** 12\
**Last updated:** [September 24, 2019, 9:28pm UTC](https://discuss.elastic.co/t/getting-and-setting-transaction-id/197947 "2019-09-24T21:28:48Z")

</div>

We're using the APM Python Flask agent to trace HTTP transactions and collect service metrics and Filebeat+Logstash for collecting service logs. We would like to link logs with the APM metrics: Using the APM transactio…

---

## [Slow Bulk Insert](https://discuss.elastic.co/t/slow-bulk-insert/10552)

<div class="topic-metadata">

**Author:** [@kayngee](https://discuss.elastic.co/u/kayngee)\
**Replies:** 10\
**Last updated:** [February 1, 2013, 8:50am UTC](https://discuss.elastic.co/t/slow-bulk-insert/10552 "2013-02-01T08:50:31Z")

</div>

Hi guys I'm trying to bulk insert batches of 1000 documents into elastic search using a predefined Mapping. Yet each bulk insert takes roughly 15-20 seconds any idea why? Predfined Mapping -\> http://pastebin.c…

---

## [Ingest pipline - multiple fields processed by one porcessor](https://discuss.elastic.co/t/ingest-pipline-multiple-fields-processed-by-one-porcessor/170320)

<div class="topic-metadata">

**Author:** [@derekmizak](https://discuss.elastic.co/u/derekmizak)\
**Replies:** 11\
**Last updated:** [March 3, 2019, 3:26am UTC](https://discuss.elastic.co/t/ingest-pipline-multiple-fields-processed-by-one-porcessor/170320 "2019-03-03T03:26:28Z")

</div>

Hi, Is there any solution how I could process multiple filds with a single processor using ingest node. For e.g. I would like to process source.ip dst.ip ip client.ip I would like t process all of them using geoip …

---

## [Kibana no longer working](https://discuss.elastic.co/t/kibana-no-longer-working/208399)

<div class="topic-metadata">

**Author:** [@getorca](https://discuss.elastic.co/u/getorca)\
**Replies:** 13\
**Last updated:** [December 3, 2019, 8:09pm UTC](https://discuss.elastic.co/t/kibana-no-longer-working/208399 "2019-12-03T20:09:40Z")

</div>

As of a few hours ago, Kibana is no longer working. it crashed suddenly and no the pod for Kibana is failing to achieve a Ready state. The ES pods are still working fine. The most obvious errors from the kibana pods see…

---

## [Elasticsearch Hadoop on HDInsight](https://discuss.elastic.co/t/elasticsearch-hadoop-on-hdinsight/24722)

<div class="topic-metadata">

**Author:** [@Sampaio](https://discuss.elastic.co/u/Sampaio)\
**Replies:** 11\
**Last updated:** [November 3, 2016, 12:51pm UTC](https://discuss.elastic.co/t/elasticsearch-hadoop-on-hdinsight/24722 "2016-11-03T12:51:58Z")

</div>

I searched the topics, posts, users and categories and no results popped up for HDInsight. It looks like an exotic concern to imagine Elasticsearch running inside a Windows based hadoop cluster. I'm curious to find out i…

---

## [Elastic Search Index Data Compression (v1.4.2)](https://discuss.elastic.co/t/elastic-search-index-data-compression-v1-4-2/23936)

<div class="topic-metadata">

**Author:** [@sagarshah1983](https://discuss.elastic.co/u/sagarshah1983)\
**Replies:** 10\
**Last updated:** [June 19, 2015, 4:48pm UTC](https://discuss.elastic.co/t/elastic-search-index-data-compression-v1-4-2/23936 "2015-06-19T16:48:07Z")

</div>

Hello everyone, I have been using Elastic Search for storing application logs. Elastic Search version: 1.4.2 Log Retention Policy: 30 days Number of logs generated per month: 250 million Number of shards per index: 5 …

---

## [Upgrade issues unable to upgrade the mappings for the index, field name contains dot](https://discuss.elastic.co/t/upgrade-issues-unable-to-upgrade-the-mappings-for-the-index-field-name-contains-dot/171501)

<div class="topic-metadata">

**Author:** [@Vishal\_0611](https://discuss.elastic.co/u/Vishal_0611)\
**Replies:** 25\
**Last updated:** [March 22, 2019, 4:05pm UTC](https://discuss.elastic.co/t/upgrade-issues-unable-to-upgrade-the-mappings-for-the-index-field-name-contains-dot/171501 "2019-03-22T16:05:01Z")

</div>

Hi All, Getting below error while restoring snapshot of 1.7 ES data on 2.4 ES: {"error":{"root\_cause":\[{"type":"snapshot\_restore\_exception","reason":"\[my\_backup:snapshot\_20190213\] cannot restore index \[test\_09\] because…

---

## [New index pattern to current index - topbeat-\*?](https://discuss.elastic.co/t/new-index-pattern-to-current-index-topbeat/41627)

<div class="topic-metadata">

**Author:** [@plonka2000](https://discuss.elastic.co/u/plonka2000)\
**Replies:** 10\
**Last updated:** [April 11, 2016, 4:29pm UTC](https://discuss.elastic.co/t/new-index-pattern-to-current-index-topbeat/41627 "2016-04-11T16:29:15Z")

</div>

Hi all, I'm trying to update an existing topbeat-\[YYYY-MM-DD\] index to accept an updated index pattern. I am doing this because the topbeat sample dashboard has issues with beat.name and beat.hostname showing up as a…

---

## [Trouble with Index Patterns](https://discuss.elastic.co/t/trouble-with-index-patterns/188981)

<div class="topic-metadata">

**Author:** [@mindorod](https://discuss.elastic.co/u/mindorod)\
**Replies:** 12\
**Last updated:** [July 5, 2019, 2:33pm UTC](https://discuss.elastic.co/t/trouble-with-index-patterns/188981 "2019-07-05T14:33:01Z")

</div>

Hi - Having a bit of trouble with the SIEM + beats configuration regarding index mappings. I've stood up 7.2 with the latest beats and followed the documentation to the T. When I open the SIEM app, I can see most of my d…

---

## [Packetbeat index not created and no info from Kibana](https://discuss.elastic.co/t/packetbeat-index-not-created-and-no-info-from-kibana/62197)

<div class="topic-metadata">

**Author:** [@Kernel\_Panic](https://discuss.elastic.co/u/Kernel_Panic)\
**Replies:** 17\
**Last updated:** [October 7, 2016, 6:56am UTC](https://discuss.elastic.co/t/packetbeat-index-not-created-and-no-info-from-kibana/62197 "2016-10-07T06:56:25Z")

</div>

Hi there guys, I'm new to ELK stack, I was able to install ELK, I can see some dashbords, topbeat for example, I can discover over filebeat index also but no luck with packet beat, this is what I've got. curl 'localho…

---

## [Logstash date extraction in logs](https://discuss.elastic.co/t/logstash-date-extraction-in-logs/171563)

<div class="topic-metadata">

**Author:** [@JeanSec](https://discuss.elastic.co/u/JeanSec)\
**Replies:** 16\
**Last updated:** [March 13, 2019, 2:47pm UTC](https://discuss.elastic.co/t/logstash-date-extraction-in-logs/171563 "2019-03-13T14:47:04Z")

</div>

Hello, I'm new to Elastic stack and i'm currently running an ELK stack on windows with Filebeat. I can see data in Kibana but the displayed timestamp does not correspond to the date written in the logs which is annoying…

---

## [Not able to sort data in kibana UI](https://discuss.elastic.co/t/not-able-to-sort-data-in-kibana-ui/254102)

<div class="topic-metadata">

**Author:** [@Varun\_S](https://discuss.elastic.co/u/Varun_S)\
**Replies:** 15\
**Last updated:** [December 1, 2020, 10:24am UTC](https://discuss.elastic.co/t/not-able-to-sort-data-in-kibana-ui/254102 "2020-12-01T10:24:11Z")

</div>

Hi Team, I am not able to sort data in kibana, Data in kibana UI are jumbled . Is there any way to sort data in Kibana UI?

---

## [@timestamp not overwriten by date filter](https://discuss.elastic.co/t/timestamp-not-overwriten-by-date-filter/48197)

<div class="topic-metadata">

**Author:** [@daq](https://discuss.elastic.co/u/daq)\
**Replies:** 11\
**Last updated:** [May 5, 2016, 1:48am UTC](https://discuss.elastic.co/t/timestamp-not-overwriten-by-date-filter/48197 "2016-05-05T01:48:51Z")

</div>

I'm trying to back fill catalina.out from Tomcat so I need to overwrite timestamp with the one from the logs. Example message is: \[INFO\] 2016-04-22 17:50:20,769 \[Blah1\] \[Blah2\] ... My filter is: filter { if \[type…

---

## [Logstash upgrade from 2.2 to 2.3 failed](https://discuss.elastic.co/t/logstash-upgrade-from-2-2-to-2-3-failed/45887)

<div class="topic-metadata">

**Author:** [@abcfy2](https://discuss.elastic.co/u/abcfy2)\
**Replies:** 14\
**Last updated:** [April 3, 2016, 5:47am UTC](https://discuss.elastic.co/t/logstash-upgrade-from-2-2-to-2-3-failed/45887 "2016-04-03T05:47:30Z")

</div>

Here is my config, and works well in 2.2. cat /etc/logstash/conf.d/logstash.conf input { redis { data\_type =\> "list" batch\_count =\> 50 host =\> "127.0.0.1" key =\> "logstash" …

---

## [Unable to pick the data from NAS Drive](https://discuss.elastic.co/t/unable-to-pick-the-data-from-nas-drive/80992)

<div class="topic-metadata">

**Author:** [@Sujith](https://discuss.elastic.co/u/Sujith)\
**Replies:** 10\
**Last updated:** [April 5, 2017, 11:49am UTC](https://discuss.elastic.co/t/unable-to-pick-the-data-from-nas-drive/80992 "2017-04-05T11:49:58Z")

</div>

We are unable to fetch data from NAS path. We have given path as example \\BNGWIDFL001\\ECMLogs\\Service.log we can see filebeat is sending data and no errors found in filebeat logs, but as in elasticsearch we can see e…

---

## [APM: 503 Queue is full, server sleeping, nothing helps](https://discuss.elastic.co/t/apm-503-queue-is-full-server-sleeping-nothing-helps/203180)

<div class="topic-metadata">

**Author:** [@lamka02sk](https://discuss.elastic.co/u/lamka02sk)\
**Replies:** 9\
**Last updated:** [October 23, 2019, 6:09pm UTC](https://discuss.elastic.co/t/apm-503-queue-is-full-server-sleeping-nothing-helps/203180 "2019-10-23T18:09:37Z")

</div>

Hello, We are trying to use APM to monitor our website but so far APM starts producing 503 Queue is full error after some time. After this happens it won't get back to normal, only restart of the APM service helps. The …

---

## [Query Execution Time, Performance](https://discuss.elastic.co/t/query-execution-time-performance/7472)

<div class="topic-metadata">

**Author:** [@Ridvan\_Gyundogan](https://discuss.elastic.co/u/Ridvan_Gyundogan)\
**Replies:** 12\
**Last updated:** [May 10, 2012, 5:39pm UTC](https://discuss.elastic.co/t/query-execution-time-performance/7472 "2012-05-10T17:39:33Z")

</div>

Hi Group, I've read all the info in the net about performance tunning of elasticsearch, but still not satisfied from the query execution time of our index. We have the following: Hardware: - 2 bare metal AMD machin…

---

## [Load balancer ( like F5) vs Coordinating node](https://discuss.elastic.co/t/load-balancer-like-f5-vs-coordinating-node/87168)

<div class="topic-metadata">

**Author:** [@venkata\_sreekanth\_bh](https://discuss.elastic.co/u/venkata_sreekanth_bh)\
**Replies:** 11\
**Last updated:** [June 26, 2017, 3:51pm UTC](https://discuss.elastic.co/t/load-balancer-like-f5-vs-coordinating-node/87168 "2017-06-26T15:51:31Z")

</div>

Which is better and why ? Edit Small 3 node cluster all master,data nodes. Each node 8 cores, 32 GB RAM, 8 GB Heap Purpose of cluster - search Request Rate 150/s Would adding a coordinating decrease the latency and…

---

## [Double datatypes values returned as 0 rather than 0.0 in Elastic Search Results](https://discuss.elastic.co/t/double-datatypes-values-returned-as-0-rather-than-0-0-in-elastic-search-results/114893)

<div class="topic-metadata">

**Author:** [@Niranjan\_Velakanti](https://discuss.elastic.co/u/Niranjan_Velakanti)\
**Replies:** 16\
**Last updated:** [January 11, 2018, 9:22pm UTC](https://discuss.elastic.co/t/double-datatypes-values-returned-as-0-rather-than-0-0-in-elastic-search-results/114893 "2018-01-11T21:22:12Z")

</div>

Hi We are in a process of migrating ES from 1.5.2 to 6.1.1 and we hit a problem. We have an index where one of the properties is of type "double". The value for the property in the documents loaded into the index is …

---

## [Determine Top Keywords from the fetched list of documents](https://discuss.elastic.co/t/determine-top-keywords-from-the-fetched-list-of-documents/201710)

<div class="topic-metadata">

**Author:** [@Noctis17](https://discuss.elastic.co/u/Noctis17)\
**Replies:** 22\
**Last updated:** [October 3, 2019, 7:09am UTC](https://discuss.elastic.co/t/determine-top-keywords-from-the-fetched-list-of-documents/201710 "2019-10-03T07:09:25Z")

</div>

This is a continuation of what I've posted months ago, but was not able to comment anymore because the post got locked. First, I would like to thank sir @Dadoonet for helping me out the last time, I was able to maximi…

---

## [Logstash cannot assign correct date to log timestamp](https://discuss.elastic.co/t/logstash-cannot-assign-correct-date-to-log-timestamp/89249)

<div class="topic-metadata">

**Author:** [@John\_06](https://discuss.elastic.co/u/John_06)\
**Replies:** 10\
**Last updated:** [June 15, 2017, 5:57am UTC](https://discuss.elastic.co/t/logstash-cannot-assign-correct-date-to-log-timestamp/89249 "2017-06-15T05:57:10Z")

</div>

Could anybody clarify if it's possible to add date part to log timestamp in Logstash not in 'UTC' but in servers time zone. For example, if I have log record timestamp like this (without date part): 21:17:43,124 INF…

---

## [Logstash TCP Input with SSL failing with non descript error](https://discuss.elastic.co/t/logstash-tcp-input-with-ssl-failing-with-non-descript-error/288312)

<div class="topic-metadata">

**Author:** [@AlanMark](https://discuss.elastic.co/u/AlanMark)\
**Replies:** 14\
**Last updated:** [November 8, 2021, 8:23am UTC](https://discuss.elastic.co/t/logstash-tcp-input-with-ssl-failing-with-non-descript-error/288312 "2021-11-08T08:23:20Z")

</div>

I'm trying to set up a TCP Input with an SSL certificate, but no matter how I configure it, i keep getting a non descript error. This is running on Logstash 7.9.1 OSS. My config is the following: input { tcp {…

---

## [Grokparsefailure, Geoip lookup failure](https://discuss.elastic.co/t/grokparsefailure-geoip-lookup-failure/141477)

<div class="topic-metadata">

**Author:** [@Adah](https://discuss.elastic.co/u/Adah)\
**Replies:** 11\
**Last updated:** [July 27, 2018, 11:38pm UTC](https://discuss.elastic.co/t/grokparsefailure-geoip-lookup-failure/141477 "2018-07-27T23:38:38Z")

</div>

Hi! I am using ELK 6.2.4 on Ubuntu Centos7. I'm a student doing a project and i am having trouble in getting the geoip :frowning: logstash conf file: i run /usr/share/logstash/bin$ sudo ./logstash -f /etc/logstash/…

---

## [Missing spans](https://discuss.elastic.co/t/missing-spans/176112)

<div class="topic-metadata">

**Author:** [@dvisz-inf](https://discuss.elastic.co/u/dvisz-inf)\
**Replies:** 21\
**Last updated:** [May 10, 2019, 5:57pm UTC](https://discuss.elastic.co/t/missing-spans/176112 "2019-05-10T17:57:51Z")

</div>

Hi, I'm trying to troubleshoot spans that seem to be disappearing in a distributed trace environment. In my current case, associations between transactions across multiple services are correctly tracked. However, some…

---

## [Slow ingestion problem (v 6.2.3)](https://discuss.elastic.co/t/slow-ingestion-problem-v-6-2-3/136225)

<div class="topic-metadata">

**Author:** [@klahnakoski](https://discuss.elastic.co/u/klahnakoski)\
**Replies:** 13\
**Last updated:** [June 24, 2018, 4:11pm UTC](https://discuss.elastic.co/t/slow-ingestion-problem-v-6-2-3/136225 "2018-06-24T16:11:26Z")

</div>

I have a 12 node cluster, with 28 indices and 1646 shards (I am targeting 20gigs per shard) I have spent a month, on and off, trying to figure out why ingestion is too slow; it can not keep up with the rate that the doc…

---

## [Using Wildcards in Date type](https://discuss.elastic.co/t/using-wildcards-in-date-type/95504)

<div class="topic-metadata">

**Author:** [@abhikrbng](https://discuss.elastic.co/u/abhikrbng)\
**Replies:** 9\
**Last updated:** [August 2, 2017, 2:37pm UTC](https://discuss.elastic.co/t/using-wildcards-in-date-type/95504 "2017-08-02T14:37:02Z")

</div>

{ “query”: { “wildcard”: { “myStringTypeFieldName”: “\*\*” } } } The above query doesn’t work , if “myStringTypeFieldName” is replaced with a “Date-Type” Field I am getting IllegalArgument exception. Because , wil…

---

## [Is default spell checker available in elastic search?](https://discuss.elastic.co/t/is-default-spell-checker-available-in-elastic-search/228852)

<div class="topic-metadata">

**Author:** [@Sagar\_jain](https://discuss.elastic.co/u/Sagar_jain)\
**Replies:** 11\
**Last updated:** [April 20, 2020, 3:54pm UTC](https://discuss.elastic.co/t/is-default-spell-checker-available-in-elastic-search/228852 "2020-04-20T15:54:31Z")

</div>

Is default spell checker available in elastic search?

[Previous page](https://discuss.elastic.co/top.md?page=67&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=69&per_page=50&period=all)
