# Top

**URL:** https://discuss.elastic.co/top.md?page=71&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 72

---

## [Watcher Alert mail Issue](https://discuss.elastic.co/t/watcher-alert-mail-issue/33706)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 9\
**Last updated:** [December 15, 2015, 6:34am UTC](https://discuss.elastic.co/t/watcher-alert-mail-issue/33706 "2015-12-15T06:34:05Z")

</div>

Hi Team, I have created new watcher PUT /\_watcher/watch/cluster\_health\_watch { "trigger" : { "schedule" : { "interval" : "30s" } }, "input" : { "http" : { "request" : { "host" : "localhost", "port" : port, "path" : "…

---

## [Concat the XML array value in logstash](https://discuss.elastic.co/t/concat-the-xml-array-value-in-logstash/73346)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 20\
**Last updated:** [February 8, 2017, 2:08pm UTC](https://discuss.elastic.co/t/concat-the-xml-array-value-in-logstash/73346 "2017-02-08T14:08:30Z")

</div>

HI Team, I'm just working on new type of XML file. I have some array information in that file i want to gather all those data.. This array fields are repeating with same tags due to this while processing the log the i'm …

---

## [Can't find master nodes after node restart](https://discuss.elastic.co/t/cant-find-master-nodes-after-node-restart/245138)

<div class="topic-metadata">

**Author:** [@Barak](https://discuss.elastic.co/u/Barak)\
**Replies:** 13\
**Last updated:** [August 17, 2020, 1:29pm UTC](https://discuss.elastic.co/t/cant-find-master-nodes-after-node-restart/245138 "2020-08-17T13:29:36Z")

</div>

After upgrading to 7.7.1, the data nodes can't find the master nodes after a restart of the data node. I am using EC2 discovery plugin, and on the initial startup it joins the cluster as expected, but once restarted in …

---

## [Logstash – Both elasticsearch and email outputs](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714)

<div class="topic-metadata">

**Author:** [@Ben19](https://discuss.elastic.co/u/Ben19)\
**Replies:** 16\
**Last updated:** [March 24, 2017, 8:38pm UTC](https://discuss.elastic.co/t/logstash-both-elasticsearch-and-email-outputs/25714 "2017-03-24T20:38:00Z")

</div>

Hello, Please can some provide an example config that provides two outputs of the same input (syslog)? I’m wanting to pass syslogs both to elasticserarch and email. The below is my current output conf, the e-mail s…

---

## [Filebeat stops sending to es eventually, bulk index 400](https://discuss.elastic.co/t/filebeat-stops-sending-to-es-eventually-bulk-index-400/89114)

<div class="topic-metadata">

**Author:** [@JSkier](https://discuss.elastic.co/u/JSkier)\
**Replies:** 9\
**Last updated:** [June 16, 2017, 10:26am UTC](https://discuss.elastic.co/t/filebeat-stops-sending-to-es-eventually-bulk-index-400/89114 "2017-06-16T10:26:17Z")

</div>

Hello, I'm running ES, kibana, and beat version 5.4.1, ArchLinux (64bit), nginx-mainline 1.13.1 on all nodes, and I'm having issues with them consistently sending data to ES. I'm relatively new to this whole projec…

---

## [Elastic Agent service stops after launching but doesn't throw any error in command line](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547)

<div class="topic-metadata">

**Author:** [@icious](https://discuss.elastic.co/u/icious)\
**Replies:** 9\
**Last updated:** [January 20, 2021, 11:48am UTC](https://discuss.elastic.co/t/elastic-agent-service-stops-after-launching-but-doesnt-throw-any-error-in-command-line/260547 "2021-01-20T11:48:27Z")

</div>

Hi, I set up a Fleet environment and tested multiple integrations of Elastic Agent on Linux and Windows machines without any problem, but there is a specific Windows machine where it does not work, and I couldn't find t…

---

## [Packetbeat.yml with\_vlans](https://discuss.elastic.co/t/packetbeat-yml-with-vlans/28420)

<div class="topic-metadata">

**Author:** [@omeroner](https://discuss.elastic.co/u/omeroner)\
**Replies:** 13\
**Last updated:** [September 11, 2015, 6:33am UTC](https://discuss.elastic.co/t/packetbeat-yml-with-vlans/28420 "2015-09-11T06:33:06Z")

</div>

Hello there, How do I enable the option to packetbeat with\_vlans. Can you help?

---

## [Elasticsearch and other components failed](https://discuss.elastic.co/t/elasticsearch-and-other-components-failed/177703)

<div class="topic-metadata">

**Author:** [@samerlol](https://discuss.elastic.co/u/samerlol)\
**Replies:** 23\
**Last updated:** [April 29, 2019, 9:29am UTC](https://discuss.elastic.co/t/elasticsearch-and-other-components-failed/177703 "2019-04-29T09:29:39Z")

</div>

Hello elastic members, I am new to elastic and I got into problems, I Installed elasticsearch, logstash and kibana in a virtual machine and when it's run, it's run all services kibana elastic search etc... but when I …

---

## [Unable to query specific number for specific field, so confused](https://discuss.elastic.co/t/unable-to-query-specific-number-for-specific-field-so-confused/44196)

<div class="topic-metadata">

**Author:** [@Matt\_Topolski](https://discuss.elastic.co/u/Matt_Topolski)\
**Replies:** 9\
**Last updated:** [March 18, 2016, 12:40am UTC](https://discuss.elastic.co/t/unable-to-query-specific-number-for-specific-field-so-confused/44196 "2016-03-18T00:40:10Z")

</div>

I'm querying from Kibana. I'm looking at nginx access logs processed by logstash and stored in elasticsearch. The response code of the log is in the "status" field in my implementation. I get exactly what I'm looking …

---

## [Extract Fields from JSON Array](https://discuss.elastic.co/t/extract-fields-from-json-array/150718)

<div class="topic-metadata">

**Author:** [@cappy](https://discuss.elastic.co/u/cappy)\
**Replies:** 10\
**Last updated:** [October 26, 2018, 11:31am UTC](https://discuss.elastic.co/t/extract-fields-from-json-array/150718 "2018-10-26T11:31:33Z")

</div>

Hello, I would like to extract the fields from the following JSON: { "startTime": "2018-10-01T20:33:56", "results": \[{ "flags": \[ "ScanPe::no\_resources", "ScanYara::compiling\_error" \], "flavors": { "mi…

---

## [Cannot Discover Master Node after upgrade to ES 6.0.0](https://discuss.elastic.co/t/cannot-discover-master-node-after-upgrade-to-es-6-0-0/108029)

<div class="topic-metadata">

**Author:** [@shreyask](https://discuss.elastic.co/u/shreyask)\
**Replies:** 14\
**Last updated:** [January 3, 2018, 3:49am UTC](https://discuss.elastic.co/t/cannot-discover-master-node-after-upgrade-to-es-6-0-0/108029 "2018-01-03T03:49:31Z")

</div>

I did a rolling upgrade on our 3 node ES cluster from 5.6.3 to 6.0.0. In this process 2/3 nodes were able to discover each other and the 3rd node is still not able to discover master, and the cluster state is red since t…

---

## [Bulk indexing: Load balancing over bulk queue size?](https://discuss.elastic.co/t/bulk-indexing-load-balancing-over-bulk-queue-size/76413)

<div class="topic-metadata">

**Author:** [@reuschling](https://discuss.elastic.co/u/reuschling)\
**Replies:** 10\
**Last updated:** [March 3, 2017, 10:02am UTC](https://discuss.elastic.co/t/bulk-indexing-load-balancing-over-bulk-queue-size/76413 "2017-03-03T10:02:49Z")

</div>

Hi there, we have a small cluster with 6 machines and heterogeneous count of cores on each machine. 1x16, 3x24 and 2x48 cores inclusive hyperthreading are available (194 in sum). Further, on some of the machines other jo…

---

## [How to Move Panels on Kibana5 Shared Dashboards?](https://discuss.elastic.co/t/how-to-move-panels-on-kibana5-shared-dashboards/67460)

<div class="topic-metadata">

**Author:** [@alexandre.machado](https://discuss.elastic.co/u/alexandre.machado)\
**Replies:** 10\
**Last updated:** [December 21, 2016, 4:29am UTC](https://discuss.elastic.co/t/how-to-move-panels-on-kibana5-shared-dashboards/67460 "2016-12-21T04:29:58Z")

</div>

In Kibana5, It seems not possible to drag containers in a shared dashboard (loaded in an iframe). The new interface changed the drag and drop control to a button in the upper right corner of the container (together wit…

---

## [Elasticsearch nodes continually disconneting/reconnecting. Resulting in very high number of unassigned shards](https://discuss.elastic.co/t/elasticsearch-nodes-continually-disconneting-reconnecting-resulting-in-very-high-number-of-unassigned-shards/243784)

<div class="topic-metadata">

**Author:** [@anda](https://discuss.elastic.co/u/anda)\
**Replies:** 17\
**Last updated:** [August 6, 2020, 12:59pm UTC](https://discuss.elastic.co/t/elasticsearch-nodes-continually-disconneting-reconnecting-resulting-in-very-high-number-of-unassigned-shards/243784 "2020-08-06T12:59:43Z")

</div>

I'm running an es cluster (7.4) with 3 master, 3 data, and 1 coord node. After running smoothly for months, nodes began to continually disconnect/reconnect from the cluster. From observing, it seems like 1 particular ma…

---

## [Can't get filebeat to work properly on any port other than 9200](https://discuss.elastic.co/t/cant-get-filebeat-to-work-properly-on-any-port-other-than-9200/99499)

<div class="topic-metadata">

**Author:** [@rdesanno](https://discuss.elastic.co/u/rdesanno)\
**Replies:** 9\
**Last updated:** [September 6, 2017, 6:56pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-work-properly-on-any-port-other-than-9200/99499 "2017-09-06T18:56:37Z")

</div>

I have a problem that is driving me crazy. I set up a POC for ELK and configured filebeat to send our logs via loghost:9200, the same port that logstash is listening to. That was fine for the test but now I want to use g…

---

## [Snapshot and path.repo on one cluster node](https://discuss.elastic.co/t/snapshot-and-path-repo-on-one-cluster-node/155717)

<div class="topic-metadata">

**Author:** [@Guillaume\_RENARD](https://discuss.elastic.co/u/Guillaume_RENARD)\
**Replies:** 13\
**Last updated:** [November 7, 2018, 5:05pm UTC](https://discuss.elastic.co/t/snapshot-and-path-repo-on-one-cluster-node/155717 "2018-11-07T17:05:31Z")

</div>

How can I create a snapshot on my kibana index with a cluster of 4 nodes. I have created a /data/bakcup folder on my kibana host, then add path.repo=\["/data/backup"\], restarted ES; Then I try to PUT /\_snapshot/my\_backu…

---

## [Watcher license expired with status code 403](https://discuss.elastic.co/t/watcher-license-expired-with-status-code-403/171011)

<div class="topic-metadata">

**Author:** [@dis](https://discuss.elastic.co/u/dis)\
**Replies:** 9\
**Last updated:** [March 7, 2019, 12:30am UTC](https://discuss.elastic.co/t/watcher-license-expired-with-status-code-403/171011 "2019-03-07T00:30:13Z")

</div>

Hi, I get the license expired error when trying to insert a watch. But in the elasticsearch server startup I see the watcher module is loaded. The curl command is executed inside the es-master container. Maybe, I'm n…

---

## [Kibana keeps logging users out with message "An unexpected authentication error occurred. Please log in again."](https://discuss.elastic.co/t/kibana-keeps-logging-users-out-with-message-an-unexpected-authentication-error-occurred-please-log-in-again/299729)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 10\
**Last updated:** [May 6, 2022, 5:00pm UTC](https://discuss.elastic.co/t/kibana-keeps-logging-users-out-with-message-an-unexpected-authentication-error-occurred-please-log-in-again/299729 "2022-05-06T17:00:39Z")

</div>

I am running an Elastic Service v7.16.2, when I open a single tab or multiply tabs of Kibana, it unexpectedly logs the user out, sometimes after a minute or less. Other times it seems to be stable and keeps user logged i…

---

## [Logstash 6.2.4 read\_to\_eof: no delimiter found in current chunk](https://discuss.elastic.co/t/logstash-6-2-4-read-to-eof-no-delimiter-found-in-current-chunk/130613)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 10\
**Last updated:** [May 9, 2018, 12:22pm UTC](https://discuss.elastic.co/t/logstash-6-2-4-read-to-eof-no-delimiter-found-in-current-chunk/130613 "2018-05-09T12:22:45Z")

</div>

Hi guys, I am using the new file input plugin 4.1.1 and keep getting the below warn message churning out numerous times - what is it about? \[WARN \]\[filewatch.tailmode.handlers.grow\] read\_to\_eof: no delimiter found in c…

---

## [Enterprise Log collection Architecture with Elastic](https://discuss.elastic.co/t/enterprise-log-collection-architecture-with-elastic/107599)

<div class="topic-metadata">

**Author:** [@eamonn](https://discuss.elastic.co/u/eamonn)\
**Replies:** 20\
**Last updated:** [December 12, 2017, 1:36pm UTC](https://discuss.elastic.co/t/enterprise-log-collection-architecture-with-elastic/107599 "2017-12-12T13:36:22Z")

</div>

I am tasked with designing a log collection architecture which involves collecting application and infrastructure logs from a number of Linux and windows severs and databases which are virtualization clustered and load b…

---

## [Java error](https://discuss.elastic.co/t/java-error/138488)

<div class="topic-metadata">

**Author:** [@jrplus](https://discuss.elastic.co/u/jrplus)\
**Replies:** 14\
**Last updated:** [July 25, 2018, 10:28am UTC](https://discuss.elastic.co/t/java-error/138488 "2018-07-25T10:28:17Z")

</div>

Ran into this while executing \\bin\\elasticsearch.bat, anyone encountered the same error?? Picked up \_JAVA\_OPTIONS: -Xmx512M -Xms256M \\Java\\jre1.8.0\_171\\bin\\java.exe" -cp "!ES\_CLASSPATH!" "org.elasticsearch.tools.launc…

---

## [Issues with upgrade from 8.18.1 to 9.0.1](https://discuss.elastic.co/t/issues-with-upgrade-from-8-18-1-to-9-0-1/378753)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 29\
**Last updated:** [November 21, 2025, 8:31am UTC](https://discuss.elastic.co/t/issues-with-upgrade-from-8-18-1-to-9-0-1/378753 "2025-11-21T08:31:43Z")

</div>

Hello, I'm trying to upgrade current 8.18.1 to 9.0.1 but facing a lot of issues, Most of them have compatibility issues preventing upgrade. For example everytime I'm receiving something like below: "error.stack\_trac…

---

## [Parsing Json object array](https://discuss.elastic.co/t/parsing-json-object-array/190954)

<div class="topic-metadata">

**Author:** [@Shawcs](https://discuss.elastic.co/u/Shawcs)\
**Replies:** 9\
**Last updated:** [August 12, 2019, 12:31pm UTC](https://discuss.elastic.co/t/parsing-json-object-array/190954 "2019-08-12T12:31:01Z")

</div>

Hi, I have trouble with a dynamic Json file. My json have an array of "circuitPath". This circuit path is a nested array inside my main json file that can be N element long. I would like to parse it dynamicaly like s…

---

## [How to get data into the beats specific index via logstash](https://discuss.elastic.co/t/how-to-get-data-into-the-beats-specific-index-via-logstash/286328)

<div class="topic-metadata">

**Author:** [@gwvandesteeg](https://discuss.elastic.co/u/gwvandesteeg)\
**Replies:** 19\
**Last updated:** [October 13, 2021, 12:15am UTC](https://discuss.elastic.co/t/how-to-get-data-into-the-beats-specific-index-via-logstash/286328 "2021-10-13T00:15:58Z")

</div>

The use case here is that we have: \*beats -\> logstash -\> elasticsearch cloud The following requirements are in place: The hosts running the beats do not have direct internet access and can only communicate via logsta…

---

## [Generate interactive dashboards for relational data](https://discuss.elastic.co/t/generate-interactive-dashboards-for-relational-data/1146)

<div class="topic-metadata">

**Author:** [@Darpan205](https://discuss.elastic.co/u/Darpan205)\
**Replies:** 9\
**Last updated:** [May 27, 2015, 8:36am UTC](https://discuss.elastic.co/t/generate-interactive-dashboards-for-relational-data/1146 "2015-05-27T08:36:59Z")

</div>

I am having search engine data (Searches and Clicks), there are two tables(as table field in Elasticsearch) searches and clicks. I have a mapping between them (Same id in corresponding data), now I want to generate the v…

---

## [Elasticsearch data structure & changing mapping](https://discuss.elastic.co/t/elasticsearch-data-structure-changing-mapping/190426)

<div class="topic-metadata">

**Author:** [@datademo](https://discuss.elastic.co/u/datademo)\
**Replies:** 11\
**Last updated:** [July 15, 2019, 1:04pm UTC](https://discuss.elastic.co/t/elasticsearch-data-structure-changing-mapping/190426 "2019-07-15T13:04:17Z")

</div>

Hi, We have an application around data visualisation running purely from Elasticsearch and have a question regarding the our current data structure within Elastcsearch and how that can lead to mapping explosion. The da…

---

## [Search\_query](https://discuss.elastic.co/t/search-query/4682)

<div class="topic-metadata">

**Author:** [@sandeep15mca](https://discuss.elastic.co/u/sandeep15mca)\
**Replies:** 41\
**Last updated:** [July 2, 2011, 7:37am UTC](https://discuss.elastic.co/t/search-query/4682 "2011-07-02T07:37:03Z")

</div>

Hi! if anybody have been used groupby query in elastic search.Please reply me. Your Thankfully Sandeep Ku…

---

## [Index not creating](https://discuss.elastic.co/t/index-not-creating/285232)

<div class="topic-metadata">

**Author:** [@jubin03](https://discuss.elastic.co/u/jubin03)\
**Replies:** 16\
**Last updated:** [October 14, 2021, 6:22pm UTC](https://discuss.elastic.co/t/index-not-creating/285232 "2021-10-14T18:22:40Z")

</div>

Following with this topic Index not creating - #17 by jubin03 I have created a new ELK and fetched data and it is working fine and able to create index patter, but the existing one is not working. Could somebody have an…

---

## [Watcher for Disk Space](https://discuss.elastic.co/t/watcher-for-disk-space/222817)

<div class="topic-metadata">

**Author:** [@sroseman](https://discuss.elastic.co/u/sroseman)\
**Replies:** 14\
**Last updated:** [March 17, 2020, 3:31pm UTC](https://discuss.elastic.co/t/watcher-for-disk-space/222817 "2020-03-17T15:31:18Z")

</div>

How would I create a watcher for disk space for my hosts? I am using the UI, but I think I will need to do a custom JSON watcher. I want to be notified when system.filesystem.used.pct is over a certain percentage for eac…

---

## [Is it necessary to use Ingest Attachment Processor to index pdf files](https://discuss.elastic.co/t/is-it-necessary-to-use-ingest-attachment-processor-to-index-pdf-files/148265)

<div class="topic-metadata">

**Author:** [@rahulnama](https://discuss.elastic.co/u/rahulnama)\
**Replies:** 27\
**Last updated:** [October 12, 2018, 4:40am UTC](https://discuss.elastic.co/t/is-it-necessary-to-use-ingest-attachment-processor-to-index-pdf-files/148265 "2018-10-12T04:40:07Z")

</div>

Hello All I'm confused whether to use Ingest Attachment processor to index pdf files or not? I'm already converting the pdf to text and extracting the metadata using python. Now I guess I can directly send the text to…

---

## [Simple Central log monitoring with ELK](https://discuss.elastic.co/t/simple-central-log-monitoring-with-elk/280488)

<div class="topic-metadata">

**Author:** [@Prabhath\_samarasingh](https://discuss.elastic.co/u/Prabhath_samarasingh)\
**Replies:** 20\
**Last updated:** [August 16, 2021, 2:32pm UTC](https://discuss.elastic.co/t/simple-central-log-monitoring-with-elk/280488 "2021-08-16T14:32:49Z")

</div>

Need to ship my servers logs (Linux system logs " /var/logs/\*" and windows server logs) to logstash to ELK and display in KIbana dash board. Please guide to perform this task.

---

## [Getting field data error in Kibana dashboards](https://discuss.elastic.co/t/getting-field-data-error-in-kibana-dashboards/76684)

<div class="topic-metadata">

**Author:** [@tcouto](https://discuss.elastic.co/u/tcouto)\
**Replies:** 9\
**Last updated:** [February 28, 2017, 8:57pm UTC](https://discuss.elastic.co/t/getting-field-data-error-in-kibana-dashboards/76684 "2017-02-28T20:57:30Z")

</div>

I'm getting the following error when trying to view my Kibana dashboards after reaching the storage limit in an elastic cloud instance. Visualize: Fielddata is disabled on text fields by default. Set fielddata=true on …

---

## [What is the scope of TF & IDF calculation?](https://discuss.elastic.co/t/what-is-the-scope-of-tf-idf-calculation/50283)

<div class="topic-metadata">

**Author:** [@Youxu](https://discuss.elastic.co/u/Youxu)\
**Replies:** 11\
**Last updated:** [May 24, 2016, 2:01pm UTC](https://discuss.elastic.co/t/what-is-the-scope-of-tf-idf-calculation/50283 "2016-05-24T14:01:42Z")

</div>

I am not quire clear how ES calculate TF/IDF in some situations, like cross index/type search, search with filters etc. Assume I have two indices, index1 and index2, each of which has two types, type1, and type2. All t…

---

## [Issue with logsatsh](https://discuss.elastic.co/t/issue-with-logsatsh/330227)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 38\
**Last updated:** [May 10, 2023, 6:34am UTC](https://discuss.elastic.co/t/issue-with-logsatsh/330227 "2023-05-10T06:34:23Z")

</div>

Hello, I am currently working on a subject. I am trying to parse my data in JSON format to store it in Elasticsearch, but Logstash is unable to parse my data and is generating errors. Can you help me?

---

## [Problems Joining a Cluster](https://discuss.elastic.co/t/problems-joining-a-cluster/351904)

<div class="topic-metadata">

**Author:** [@bryanrood](https://discuss.elastic.co/u/bryanrood)\
**Replies:** 32\
**Last updated:** [February 2, 2024, 8:03pm UTC](https://discuss.elastic.co/t/problems-joining-a-cluster/351904 "2024-02-02T20:03:04Z")

</div>

Hi Everyone, I think I posted my first post in the wrong elasticsearch category. I'm trying to get my new cluster up and working and I'm really struggling with order of operation. I have tried a whole bunch of things bu…

---

## [Partial Search of a sentence not working as expected](https://discuss.elastic.co/t/partial-search-of-a-sentence-not-working-as-expected/193067)

<div class="topic-metadata">

**Author:** [@GuruPrasath\_Ramesh](https://discuss.elastic.co/u/GuruPrasath_Ramesh)\
**Replies:** 12\
**Last updated:** [August 7, 2019, 9:17am UTC](https://discuss.elastic.co/t/partial-search-of-a-sentence-not-working-as-expected/193067 "2019-08-07T09:17:55Z")

</div>

I use Translate API to get the native elastic search queries from SQL queries. At first try, we use the RLIKE query to match a partial word in a sentence. POST /\_xpack/sql/translate { "query": "SELECT \* FROM c1s\_may…

---

## [Logserver in AWS not receiving any logs](https://discuss.elastic.co/t/logserver-in-aws-not-receiving-any-logs/42463)

<div class="topic-metadata">

**Author:** [@babeesh](https://discuss.elastic.co/u/babeesh)\
**Replies:** 18\
**Last updated:** [March 1, 2016, 12:48pm UTC](https://discuss.elastic.co/t/logserver-in-aws-not-receiving-any-logs/42463 "2016-03-01T12:48:50Z")

</div>

I have setup logserver using ELK in aws ubuntu instance. And I need to send syslogs from my production server to logserver. For that filebeat is installed in production server. Contents of configuration files are given…

---

## [Can't upgrade elasticsearch 5.2.1 to 5.6.5](https://discuss.elastic.co/t/cant-upgrade-elasticsearch-5-2-1-to-5-6-5/115403)

<div class="topic-metadata">

**Author:** [@Arter\_Xu](https://discuss.elastic.co/u/Arter_Xu)\
**Replies:** 16\
**Last updated:** [January 14, 2018, 4:03pm UTC](https://discuss.elastic.co/t/cant-upgrade-elasticsearch-5-2-1-to-5-6-5/115403 "2018-01-14T16:03:07Z")

</div>

Old Version: Elasticsearch version : 5.2.1 JVM version : 1.8.0\_71 OS version : centos 7.3 New Verision: Elasticsearch version : 5.6.5 JVM version : 1.8.0\_131 OS version : centos 7.3 The details: I have six elasi…

---

## [Kibana not working after licence deletion](https://discuss.elastic.co/t/kibana-not-working-after-licence-deletion/178516)

<div class="topic-metadata">

**Author:** [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Replies:** 29\
**Last updated:** [May 2, 2019, 4:09am UTC](https://discuss.elastic.co/t/kibana-not-working-after-licence-deletion/178516 "2019-05-02T04:09:54Z")

</div>

Hi Guys, While play ing with ELK version 6.5.4 with trial xpack version, i have deleted the licence and since then Kibana & elasticsearch not working. I have attached the screen shot, however i upgraded the Elasticse…

---

## [Identify lines older than X days](https://discuss.elastic.co/t/identify-lines-older-than-x-days/60388)

<div class="topic-metadata">

**Author:** [@Alex\_6](https://discuss.elastic.co/u/Alex_6)\
**Replies:** 11\
**Last updated:** [September 20, 2016, 6:21pm UTC](https://discuss.elastic.co/t/identify-lines-older-than-x-days/60388 "2016-09-20T18:21:04Z")

</div>

Logstash 2.3.4 I have dates extracted from the log lines using the date filter. I want to drop any log line which is older than 5 days and not put it into Elasticsearch at all. Is there a standard filter which does thi…

---

## [Add\_kubernetes\_metadata + rename = disappearing field?](https://discuss.elastic.co/t/add-kubernetes-metadata-rename-disappearing-field/140160)

<div class="topic-metadata">

**Author:** [@tallavi](https://discuss.elastic.co/u/tallavi)\
**Replies:** 26\
**Last updated:** [August 29, 2018, 7:52am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-rename-disappearing-field/140160 "2018-08-29T07:52:18Z")

</div>

Hi, I have a very strange issue I can't pinpoint. add\_kubernetes\_metadata works - I see the fields rename works - I can rename fields BUT, I can't rename the kubernetes fields. I added the -d \* switch to filebeat to …

---

## [Elasticsearch Cluster not reachable by Logstash](https://discuss.elastic.co/t/elasticsearch-cluster-not-reachable-by-logstash/26373)

<div class="topic-metadata">

**Author:** [@vilas](https://discuss.elastic.co/u/vilas)\
**Replies:** 17\
**Last updated:** [July 28, 2015, 11:34pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-not-reachable-by-logstash/26373 "2015-07-28T23:34:31Z")

</div>

Hi, I am using cluster name in logstash elasticsearch output plugin. But it is failing to send data to the cluster. Nevertheless, I could reach the server when I specify the hostname. I would like to know if I have t…

---

## [How logstash can get the total number of line in a file (count))](https://discuss.elastic.co/t/how-logstash-can-get-the-total-number-of-line-in-a-file-count/130233)

<div class="topic-metadata">

**Author:** [@alicia1](https://discuss.elastic.co/u/alicia1)\
**Replies:** 10\
**Last updated:** [May 3, 2018, 4:37pm UTC](https://discuss.elastic.co/t/how-logstash-can-get-the-total-number-of-line-in-a-file-count/130233 "2018-05-03T16:37:34Z")

</div>

Hi, I have 3 files CSV in windows, one is to store logs errors Error.csv, one is for all succes events success.csv and the last for all incomming events totalEvent.csv (= logs errors + succes events). I want to have a …

---

## [How to visualize the Winlogbeat data in Kibana Dashboard](https://discuss.elastic.co/t/how-to-visualize-the-winlogbeat-data-in-kibana-dashboard/69975)

<div class="topic-metadata">

**Author:** [@prakash1243](https://discuss.elastic.co/u/prakash1243)\
**Replies:** 12\
**Last updated:** [December 27, 2016, 4:39am UTC](https://discuss.elastic.co/t/how-to-visualize-the-winlogbeat-data-in-kibana-dashboard/69975 "2016-12-27T04:39:06Z")

</div>

Hi- Am able to run the Winlogbeat successfully and able to create the .winlogbeat.yml file and logs shows succesffully sending the data to Elastic Search pointing to http://localhost:9200 Would you please let me know, …

---

## [類義語を同じようにスコアリングしたい](https://discuss.elastic.co/t/topic/104070)

<div class="topic-metadata">

**Author:** [@joh](https://discuss.elastic.co/u/joh)\
**Replies:** 14\
**Last updated:** [November 20, 2017, 9:08am UTC](https://discuss.elastic.co/t/topic/104070 "2017-11-20T09:08:03Z")

</div>

類義語のスコアリングが低いように思えるので、同じようにスコアリングしたいと思っています。 "settings": { "analysis": {"analyzer": {"my\_analyzer": {"type": "custom", "tokenizer": "kuromoji\_tokenizer", "char\_filter": \["icu\_normalizer",\], "filter": \["synonym",…

---

## [Custom field formatter in production](https://discuss.elastic.co/t/custom-field-formatter-in-production/28761)

<div class="topic-metadata">

**Author:** [@piebuo](https://discuss.elastic.co/u/piebuo)\
**Replies:** 16\
**Last updated:** [April 19, 2016, 8:31pm UTC](https://discuss.elastic.co/t/custom-field-formatter-in-production/28761 "2016-04-19T20:31:58Z")

</div>

Hi everyone, i followed these instructions to create a custom field formatter: Writing Custom Field Formatters for Kibana now in development environment i have my custom field as i wanted. How can i port these customizat…

---

## [Watcher in x-pack returns NullPointerException](https://discuss.elastic.co/t/watcher-in-x-pack-returns-nullpointerexception/60259)

<div class="topic-metadata">

**Author:** [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Replies:** 15\
**Last updated:** [November 21, 2016, 10:35am UTC](https://discuss.elastic.co/t/watcher-in-x-pack-returns-nullpointerexception/60259 "2016-11-21T10:35:14Z")

</div>

Hi! I would like to ask question related to watcher in x-pack. My environment is x-pack -5.0.0 alpha5 elasticsearch 5.0.0alpha5 I get below error when watcher is executed. \[2016-09-12 16:43:12,322\]\[ERROR\]\[xpack…

---

## [Metricbeat 5.2.2 configtest fails to find templates](https://discuss.elastic.co/t/metricbeat-5-2-2-configtest-fails-to-find-templates/85449)

<div class="topic-metadata">

**Author:** [@csobchuk](https://discuss.elastic.co/u/csobchuk)\
**Replies:** 12\
**Last updated:** [May 16, 2017, 7:03pm UTC](https://discuss.elastic.co/t/metricbeat-5-2-2-configtest-fails-to-find-templates/85449 "2017-05-16T19:03:48Z")

</div>

I am using Metricbeat 5.2.2 on a Ubuntu 14.04.05 LTS 64 bit trying to run metricbeat configtest from the /usr/share/metricbeat/bin directory as: sudo ./metricbeat -c /etc/metricbeat/metricbeat.yml -configtest However, …

---

## [Which input logstash plugin is the fastest?](https://discuss.elastic.co/t/which-input-logstash-plugin-is-the-fastest/62622)

<div class="topic-metadata">

**Author:** [@111126](https://discuss.elastic.co/u/111126)\
**Replies:** 12\
**Last updated:** [October 13, 2016, 6:45am UTC](https://discuss.elastic.co/t/which-input-logstash-plugin-is-the-fastest/62622 "2016-10-13T06:45:58Z")

</div>

Hello everybody. I need hight event rate to logstash - at least 50k, and I must also have a way of further scaling How I can forward 50k, 100k, 150k events per second? I have central rsyslog server that stores logs o…

---

## [Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/251719)

<div class="topic-metadata">

**Author:** [@nitin194](https://discuss.elastic.co/u/nitin194)\
**Replies:** 23\
**Last updated:** [December 7, 2020, 12:47pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/251719 "2020-12-07T12:47:55Z")

</div>

We are trying to index Nginx access and error log separately in Elasticsearch. for that we have created Filbeat and Logstash config as below. Below is our /etc/filebeat/filebeat.yml configuration filebeat.inputs: …

[Previous page](https://discuss.elastic.co/top.md?page=70&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=72&per_page=50&period=all)
