# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Logstash category](https://discuss.elastic.co/t/about-the-logstash-category/35)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [April 22, 2015, 7:15pm UTC](https://discuss.elastic.co/t/about-the-logstash-category/35 "2015-04-22T19:15:02Z")

</div>

Centralize, transform & stash your data Logstash is an open source server-side data processing pipeline that ingests data from a multitude of sources, transforms it, and then sends it to your favorite "stash." :warning: …

---

## [Logstash Plugin logstash-filter-json\_encode vanishes between 9.x upgrades](https://discuss.elastic.co/t/logstash-plugin-logstash-filter-json-encode-vanishes-between-9-x-upgrades/387482)

<div class="topic-metadata">

**Author:** [@Jesselastic](https://discuss.elastic.co/u/Jesselastic)\
**Replies:** 1\
**Last updated:** [September 5, 2026, 12:51pm UTC](https://discuss.elastic.co/t/logstash-plugin-logstash-filter-json-encode-vanishes-between-9-x-upgrades/387482 "2026-09-05T12:51:22Z")

</div>

After upgrading to version 9.x + running plugin updates, the filter "logstash-filter-json\_encode" becomes absent from the system, and pipelines that use it begin to fail. Interestingly, when one does a list query for it…

---

## [Intermittent metric registration error: worker\_millis\_per\_event](https://discuss.elastic.co/t/intermittent-metric-registration-error-worker-millis-per-event/383836)

<div class="topic-metadata">

**Author:** [@mariyabanatic](https://discuss.elastic.co/u/mariyabanatic)\
**Replies:** 8\
**Last updated:** [September 2, 2026, 6:02am UTC](https://discuss.elastic.co/t/intermittent-metric-registration-error-worker-millis-per-event/383836 "2026-09-02T06:02:11Z")

</div>

Issue Intermittent warning during pipeline startup. The worker\_millis\_per\_event metric fails to register but pipeline functions normally. \[org.logstash.execution.AbstractPipelineExt\] Metric registration error: \`worker\_m…

---

## [Inquiry schedule: Backport concurrent-ruby 1.3.7 to Logstash 8.19.x for CVE-2026-54904(High)](https://discuss.elastic.co/t/inquiry-schedule-backport-concurrent-ruby-1-3-7-to-logstash-8-19-x-for-cve-2026-54904-high/389887)

<div class="topic-metadata">

**Author:** [@Della](https://discuss.elastic.co/u/Della)\
**Replies:** 1\
**Last updated:** [August 24, 2026, 4:12pm UTC](https://discuss.elastic.co/t/inquiry-schedule-backport-concurrent-ruby-1-3-7-to-logstash-8-19-x-for-cve-2026-54904-high/389887 "2026-08-24T16:12:13Z")

</div>

Dear Elastic Security & Logstash Team, We are running Logstash 8.19.19 in production environment. Security scanning (Docker Scout/Trivy) detects high vulnerability CVE-2026-54904 in embedded concurrent-ruby gem 1.1.9. T…

---

## [Removing empty fields from an event (2026 edition!)](https://discuss.elastic.co/t/removing-empty-fields-from-an-event-2026-edition/389831)

<div class="topic-metadata">

**Author:** [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Replies:** 0\
**Last updated:** [August 20, 2026, 3:02pm UTC](https://discuss.elastic.co/t/removing-empty-fields-from-an-event-2026-edition/389831 "2026-08-20T15:02:02Z")

</div>

Continuing the discussion from Removing empty fields from an event (2024 edition!): It now removes any empty objects left over after removing empty fields: filter { ruby { id =\> "remove empty fields" path =\> …

---

## [logstash-output-elasticsearch error](https://discuss.elastic.co/t/logstash-output-elasticsearch-error/387936)

<div class="topic-metadata">

**Author:** [@wujun](https://discuss.elastic.co/u/wujun)\
**Replies:** 3\
**Last updated:** [August 20, 2026, 10:49am UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-error/387936 "2026-08-20T10:49:20Z")

</div>

\[WARN \] 2026-07-09 10:54:37.480 \[Ruby-0-Thread-9: /usr/share/logstash/vendor/bundle/jruby/3.4.0/gems/logstash-output-elasticsearch-12.1.3-java/lib/logstash/outputs/elasticsearch/http\_client/pool.rb:234\] elasticsearch - F…

---

## [Logstash elastic\_agent input: connection resets](https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-resets/388898)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 1\
**Last updated:** [August 13, 2026, 4:57am UTC](https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-resets/388898 "2026-08-13T04:57:55Z")

</div>

I notice a lot of java.net.SocketException: Connection reset warnings in my Logstash logs. It seems this is related to the elastic\_agent input and is noticeably higher in combination with Defend. It also occurs on device…

---

## [Loghstash service is not getting started going in continues restart having error: Logstash stopped processing because of an error: (NoMethodError) private method \`run' called for #\<LogStash::Runner:0x32a806ef\>](https://discuss.elastic.co/t/loghstash-service-is-not-getting-started-going-in-continues-restart-having-error-logstash-stopped-processing-because-of-an-error-nomethoderror-private-method-run-called-for-logstash-0x32a806ef/386799)

<div class="topic-metadata">

**Author:** [@ashish.jagtap](https://discuss.elastic.co/u/ashish.jagtap)\
**Replies:** 15\
**Last updated:** [June 12, 2026, 6:47am UTC](https://discuss.elastic.co/t/loghstash-service-is-not-getting-started-going-in-continues-restart-having-error-logstash-stopped-processing-because-of-an-error-nomethoderror-private-method-run-called-for-logstash-0x32a806ef/386799 "2026-06-12T06:47:06Z")

</div>

loghstash service is not getting started going in continues restart. Error: Logstash stopped processing because of an error: (NoMethodError) private method run' called for #\<LogStash::Runner:0x32a806ef\> Jun 10 16:15:03…

---

## [Csv filter parsing error](https://discuss.elastic.co/t/csv-filter-parsing-error/386766)

<div class="topic-metadata">

**Author:** [@carellevbt](https://discuss.elastic.co/u/carellevbt)\
**Replies:** 2\
**Last updated:** [June 10, 2026, 9:45am UTC](https://discuss.elastic.co/t/csv-filter-parsing-error/386766 "2026-06-10T09:45:20Z")

</div>

Hello, I have multiple csv files I need to ingest. Among the csv files I have 13 column header names variations. I would like to use the autodetect\_column\_names to avoid manually configuring these column names. Also ple…

---

## [Logstash credentials management](https://discuss.elastic.co/t/logstash-credentials-management/386680)

<div class="topic-metadata">

**Author:** [@ShubhamKumarJena](https://discuss.elastic.co/u/ShubhamKumarJena)\
**Replies:** 1\
**Last updated:** [June 3, 2026, 1:14pm UTC](https://discuss.elastic.co/t/logstash-credentials-management/386680 "2026-06-03T13:14:51Z")

</div>

Hello ! \*\* Problem Statement\*\* We are reviewing the current authentication mechanism used by our Logstash deployment and would like to align it with industry best practices. Currently, certain Logstash pipelines requ…

---

## [Logstash output input Logstash](https://discuss.elastic.co/t/logstash-output-input-logstash/386571)

<div class="topic-metadata">

**Author:** [@Sam11](https://discuss.elastic.co/u/Sam11)\
**Replies:** 3\
**Last updated:** [May 29, 2026, 4:01pm UTC](https://discuss.elastic.co/t/logstash-output-input-logstash/386571 "2026-05-29T16:01:44Z")

</div>

Recently I started getting frequent Read timed out errors from Logstash 1 which is seding to another logstash via the plugin input/output Logstash. I am experiencing a major latency issue. Data is not lost, but logs arr…

---

## [Intermittent log loss observed in a UDP-based Logstash architecture behind a load balancer, with ongoing investigation into possible packet drops, idle-timeout behavior, and UDP input tuning recommendations.](https://discuss.elastic.co/t/intermittent-log-loss-observed-in-a-udp-based-logstash-architecture-behind-a-load-balancer-with-ongoing-investigation-into-possible-packet-drops-idle-timeout-behavior-and-udp-input-tuning-recommendations/386494)

<div class="topic-metadata">

**Author:** [@Usha\_Nookala](https://discuss.elastic.co/u/Usha_Nookala)\
**Replies:** 1\
**Last updated:** [May 25, 2026, 5:02pm UTC](https://discuss.elastic.co/t/intermittent-log-loss-observed-in-a-udp-based-logstash-architecture-behind-a-load-balancer-with-ongoing-investigation-into-possible-packet-drops-idle-timeout-behavior-and-udp-input-tuning-recommendations/386494 "2026-05-25T17:02:03Z")

</div>

Hi everyone, We are currently troubleshooting intermittent log loss in a Logstash setup using the UDP input plugin and wanted to check if anyone in the community has faced similar behavior. Current setup (genericized): …

---

## [How to group application logs by error uniqueness and count occurrences in Elasticsearch/Kibana?](https://discuss.elastic.co/t/how-to-group-application-logs-by-error-uniqueness-and-count-occurrences-in-elasticsearch-kibana/386445)

<div class="topic-metadata">

**Author:** [@Raushan](https://discuss.elastic.co/u/Raushan)\
**Replies:** 1\
**Last updated:** [May 22, 2026, 5:31pm UTC](https://discuss.elastic.co/t/how-to-group-application-logs-by-error-uniqueness-and-count-occurrences-in-elasticsearch-kibana/386445 "2026-05-22T17:31:28Z")

</div>

Hi everyone, We are currently shipping our application logs directly to Elasticsearch, and we are trying to find a way to analyze our error patterns more effectively. Specifically, we need to: Identify the uniqueness …

---

## [Windows - LS 9.4.0 - Unable to update plugins](https://discuss.elastic.co/t/windows-ls-9-4-0-unable-to-update-plugins/386405)

<div class="topic-metadata">

**Author:** [@novaksam](https://discuss.elastic.co/u/novaksam)\
**Replies:** 2\
**Last updated:** [May 21, 2026, 1:41pm UTC](https://discuss.elastic.co/t/windows-ls-9-4-0-unable-to-update-plugins/386405 "2026-05-21T13:41:04Z")

</div>

Is anyone else having issues updating plugins on windows with fresh downloads of logstash? I'm getting the following error: Error Bundler::InstallError, retrying 1/10 Bundler::GenericSystemCallError: There was an error…

---

## [Syncing Tables from Microsoft SQL Server to Elastic using Logstash](https://discuss.elastic.co/t/syncing-tables-from-microsoft-sql-server-to-elastic-using-logstash/386309)

<div class="topic-metadata">

**Author:** [@Mevevlin](https://discuss.elastic.co/u/Mevevlin)\
**Replies:** 9\
**Last updated:** [May 15, 2026, 12:23am UTC](https://discuss.elastic.co/t/syncing-tables-from-microsoft-sql-server-to-elastic-using-logstash/386309 "2026-05-15T00:23:14Z")

</div>

I'm trying to sync my SQL server database to my elasticsearch database. I've got the following input setup now: input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/drivers/mssql-jdbc.jre8.jar" jdbc\_driv…

---

## [Beats Input Logging](https://discuss.elastic.co/t/beats-input-logging/386116)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [May 1, 2026, 1:56pm UTC](https://discuss.elastic.co/t/beats-input-logging/386116 "2026-05-01T13:56:34Z")

</div>

Hi, Can anyone give me a steer regarding difference between logstash.input.beats and org.logstash.beats in the logging hierarchy? How do they relate to one another and how do they differ? Thx D

---

## [Unifi Syslog ECS Mapping](https://discuss.elastic.co/t/unifi-syslog-ecs-mapping/386089)

<div class="topic-metadata">

**Author:** [@AxelZoldik](https://discuss.elastic.co/u/AxelZoldik)\
**Replies:** 0\
**Last updated:** [April 29, 2026, 7:24am UTC](https://discuss.elastic.co/t/unifi-syslog-ecs-mapping/386089 "2026-04-29T07:24:33Z")

</div>

Hello everyone I hope you are all doing well, I'm wondering if someone has already a pipeline logstash for mapping Unifi firewall logs to ECS, It might be worth to create an integration directly in Kibana if I'm not al…

---

## [Parse syslog with filepath backslashes](https://discuss.elastic.co/t/parse-syslog-with-filepath-backslashes/385919)

<div class="topic-metadata">

**Author:** [@Adrian\_Wallis](https://discuss.elastic.co/u/Adrian_Wallis)\
**Replies:** 2\
**Last updated:** [April 28, 2026, 2:28pm UTC](https://discuss.elastic.co/t/parse-syslog-with-filepath-backslashes/385919 "2026-04-28T14:28:55Z")

</div>

Hello, I have some syslogs to parse which are in a very basic comma delimited format. Everything looks and works fine apart from a file path with backslashes. I've seen several suggestions on the forum around mutate an…

---

## [Logstash 8.19.x is required which java 17 or Java 21](https://discuss.elastic.co/t/logstash-8-19-x-is-required-which-java-17-or-java-21/386036)

<div class="topic-metadata">

**Author:** [@Siddhartha](https://discuss.elastic.co/u/Siddhartha)\
**Replies:** 2\
**Last updated:** [April 27, 2026, 7:06am UTC](https://discuss.elastic.co/t/logstash-8-19-x-is-required-which-java-17-or-java-21/386036 "2026-04-27T07:06:23Z")

</div>

Logstash 8.19.x is required which java 17 or Java 21 though JDK 21 is bundled with it

---

## [Logstash SNMP plugin not polling all OIDs](https://discuss.elastic.co/t/logstash-snmp-plugin-not-polling-all-oids/385975)

<div class="topic-metadata">

**Author:** [@tom.verbeek](https://discuss.elastic.co/u/tom.verbeek)\
**Replies:** 8\
**Last updated:** [April 22, 2026, 12:40pm UTC](https://discuss.elastic.co/t/logstash-snmp-plugin-not-polling-all-oids/385975 "2026-04-22T12:40:11Z")

</div>

Hi, I'm setting up a logstash that has a snmp input plugin and an elasticsearch output. Everything works except 1 specific OID, I checked and the OID has data and it is available. I ca't figure out why he is not pollin…

---

## [Elastic Agent Logstash data streams not working](https://discuss.elastic.co/t/elastic-agent-logstash-data-streams-not-working/385925)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 2\
**Last updated:** [April 17, 2026, 11:05am UTC](https://discuss.elastic.co/t/elastic-agent-logstash-data-streams-not-working/385925 "2026-04-17T11:05:28Z")

</div>

This is my logstash.yml else if "apps" in \[tags\] { mutate { # replace =\> { "\[@metadata\]\[index\_prefix\]" =\> "applications-%{+YYYY.MM}" } add\_field =\> { "\[data\_stream\]\[type\]" =\> "logs" "\[d…

---

## [Date filter plugin in Logstash configuration](https://discuss.elastic.co/t/date-filter-plugin-in-logstash-configuration/385899)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 6\
**Last updated:** [April 16, 2026, 5:24am UTC](https://discuss.elastic.co/t/date-filter-plugin-in-logstash-configuration/385899 "2026-04-16T05:24:53Z")

</div>

In my Logstash configuration we use the "Date filter plugin" several times. It already looks like a mess for me. Is it possible to use only once the "Date Filter Plugin" at the end of the Filter section in the logstash …

---

## [Architecture check: Offloading Logstash gsub regex to K8s pod sidecars to save CPU?](https://discuss.elastic.co/t/architecture-check-offloading-logstash-gsub-regex-to-k8s-pod-sidecars-to-save-cpu/385800)

<div class="topic-metadata">

**Author:** [@Ilya\_Ploskovitov](https://discuss.elastic.co/u/Ilya_Ploskovitov)\
**Replies:** 0\
**Last updated:** [April 7, 2026, 1:43pm UTC](https://discuss.elastic.co/t/architecture-check-offloading-logstash-gsub-regex-to-k8s-pod-sidecars-to-save-cpu/385800 "2026-04-07T13:43:49Z")

</div>

Hi everyone, We’ve been dealing with a classic pipeline bottleneck: our Logstash nodes are burning massive amounts of CPU because we have dozens of gsub mutate filters to scrub PII and secrets (like emails, Stripe token…

---

## [Need help parsing XML and general strategy with logstash](https://discuss.elastic.co/t/need-help-parsing-xml-and-general-strategy-with-logstash/385787)

<div class="topic-metadata">

**Author:** [@Rx7TyreBurna](https://discuss.elastic.co/u/Rx7TyreBurna)\
**Replies:** 2\
**Last updated:** [April 7, 2026, 3:35am UTC](https://discuss.elastic.co/t/need-help-parsing-xml-and-general-strategy-with-logstash/385787 "2026-04-07T03:35:46Z")

</div>

I have XML output from a tool called nmap. I am wanting to pull the ports from this, but also want to take the scan information and either append that, or stick that in an Elastic index and hopefully get some unique ID …

---

## [One Deata view @timestamp alarm](https://discuss.elastic.co/t/one-deata-view-timestamp-alarm/385624)

<div class="topic-metadata">

**Author:** [@Wing\_W](https://discuss.elastic.co/u/Wing_W)\
**Replies:** 3\
**Last updated:** [March 27, 2026, 6:10am UTC](https://discuss.elastic.co/t/one-deata-view-timestamp-alarm/385624 "2026-03-27T06:10:22Z")

</div>

This request queries Elasticsearch to fetch the documents. Search session id: d53c937d-ef25-4122-862c-9cc00f861186 Node c60fcARCT5m2jef2\_njmog Reason error fetching \[structured.@timestamp\]: Field \[structured.@timest…

---

## [Logstash.outputs.elasticsearch - Failed to perform request: Connection refused](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-failed-to-perform-request-connection-refused/385421)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 11\
**Last updated:** [March 20, 2026, 1:25pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-failed-to-perform-request-connection-refused/385421 "2026-03-20T13:25:13Z")

</div>

I am using an on-prem 8.11.3 elastic+logstash stack. logstash uses elasticsearch output plugin to post events to elastic. current set-up uses 2 servers. elasticsearch { hosts =\> \[ "srv1:9200", "srv2:9200" \] data\_str…

---

## [Logstash pipeline shutting off/starting order](https://discuss.elastic.co/t/logstash-pipeline-shutting-off-starting-order/385423)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 3\
**Last updated:** [March 12, 2026, 10:09pm UTC](https://discuss.elastic.co/t/logstash-pipeline-shutting-off-starting-order/385423 "2026-03-12T22:09:16Z")

</div>

How to force logstash to switch off pipelines in given order? In my setup, I’m often receiving data via http input and distributing those messages among various pipelines based on content, however if I turn the logstash…

---

## [High availability Ingest architecture](https://discuss.elastic.co/t/high-availability-ingest-architecture/385425)

<div class="topic-metadata">

**Author:** [@fer.mt](https://discuss.elastic.co/u/fer.mt)\
**Replies:** 2\
**Last updated:** [March 12, 2026, 6:29pm UTC](https://discuss.elastic.co/t/high-availability-ingest-architecture/385425 "2026-03-12T18:29:09Z")

</div>

Context: My team manages an on-prem Elastic deployment. We have an ECE license. We had an outage a few weeks ago when our elastic nodes ran out of space caused by a problem with the move of data to the frozen layer. S…

---

## [Why does /var/log/logstash\_flow\_stats.log appear by default in RPM installation?](https://discuss.elastic.co/t/why-does-var-log-logstash-flow-stats-log-appear-by-default-in-rpm-installation/385321)

<div class="topic-metadata">

**Author:** [@kuroro](https://discuss.elastic.co/u/kuroro)\
**Replies:** 1\
**Last updated:** [March 5, 2026, 2:16am UTC](https://discuss.elastic.co/t/why-does-var-log-logstash-flow-stats-log-appear-by-default-in-rpm-installation/385321 "2026-03-05T02:16:31Z")

</div>

Hi everyone, I’m running Logstash 8.17.6 installed via RPM, with Stack Monitoring enabled (xpack.monitoring.enabled: true). I noticed that a file named: /var/log/logstash\_flow\_stats.log is created automatically. Base…

---

## [Elastic Agent to Logstash](https://discuss.elastic.co/t/elastic-agent-to-logstash/385314)

<div class="topic-metadata">

**Author:** [@arav](https://discuss.elastic.co/u/arav)\
**Replies:** 3\
**Last updated:** [March 3, 2026, 1:14pm UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash/385314 "2026-03-03T13:14:30Z")

</div>

I cant send the elastic agent to logstash I have the logstash listed in Fleet → Settings While creating a policy, while selecting output for integration, the logstash option is available but not clickable

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=1)
