# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=1

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 2

---

## [Creation date of logstash created files, with %{+YYYY.MM.dd} in the name, is offset by few hours](https://discuss.elastic.co/t/creation-date-of-logstash-created-files-with-yyyy-mm-dd-in-the-name-is-offset-by-few-hours/385002)

<div class="topic-metadata">

**Author:** [@Toxic\_Bunny](https://discuss.elastic.co/u/Toxic_Bunny)\
**Replies:** 4\
**Last updated:** [February 22, 2026, 3:28pm UTC](https://discuss.elastic.co/t/creation-date-of-logstash-created-files-with-yyyy-mm-dd-in-the-name-is-offset-by-few-hours/385002 "2026-02-22T15:28:31Z")

</div>

Logstash sends all unprocessed leftovers into a separate .log file for archiving purposes output{ file { path =\> "/var/log/logstash/archive-%{+YYYY.MM.dd}.log" } } The problem is that logstash additionally offsets …

---

## [Windows version for logstash 9.3.0](https://discuss.elastic.co/t/windows-version-for-logstash-9-3-0/385109)

<div class="topic-metadata">

**Author:** [@Bojie](https://discuss.elastic.co/u/Bojie)\
**Replies:** 6\
**Last updated:** [February 20, 2026, 1:35pm UTC](https://discuss.elastic.co/t/windows-version-for-logstash-9-3-0/385109 "2026-02-20T13:35:47Z")

</div>

Hi, I would like to ask if there will be a windows version of Logstash 9.3.0 available for download, and if so, when would it be released? I would need version 9.3.0 as it contains the latest version of log4j (2.25.3) wh…

---

## [ELK final output](https://discuss.elastic.co/t/elk-final-output/384962)

<div class="topic-metadata">

**Author:** [@scorpoin82](https://discuss.elastic.co/u/scorpoin82)\
**Replies:** 3\
**Last updated:** [February 16, 2026, 2:59am UTC](https://discuss.elastic.co/t/elk-final-output/384962 "2026-02-16T02:59:34Z")

</div>

Hello community, I have setup a small ELK cluster with 3 Master nodes , 3 Data Nodes , 3 Logstash Nodes and 1 Kibana Node. 3 Logstash nodes are behind F5 load balancer and those logstash connected with data nodes. Now…

---

## [DLQ setup issue for specific application in Logstash pipeline](https://discuss.elastic.co/t/dlq-setup-issue-for-specific-application-in-logstash-pipeline/385059)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [February 15, 2026, 4:57pm UTC](https://discuss.elastic.co/t/dlq-setup-issue-for-specific-application-in-logstash-pipeline/385059 "2026-02-15T16:57:05Z")

</div>

We have a single Logstash pipeline that listens on port 5044 and receives data from multiple Beats sources. Filebeat is installed on one of the source servers, and we want to configure a Dead Letter Queue (DLQ) only for …

---

## [Logstash filter JSON parse error](https://discuss.elastic.co/t/logstash-filter-json-parse-error/384918)

<div class="topic-metadata">

**Author:** [@rokkotnik](https://discuss.elastic.co/u/rokkotnik)\
**Replies:** 7\
**Last updated:** [February 6, 2026, 12:42pm UTC](https://discuss.elastic.co/t/logstash-filter-json-parse-error/384918 "2026-02-06T12:42:06Z")

</div>

Hi, I keep getting json parse error and I’ve been playing with filter for hours. \[logstash.codecs.json \]\[main\]\[68389d\] JSON parse error, original data now in message field {:message=\>"Could not set field 'ip' on ob…

---

## [Logstash Grok filter Not working](https://discuss.elastic.co/t/logstash-grok-filter-not-working/384762)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 6\
**Last updated:** [January 28, 2026, 7:41pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-not-working/384762 "2026-01-28T19:41:41Z")

</div>

\<181\>Jan 28 14:49:00 cisco CISE\_RADIUS\_Accounting 0001444968 1 0 2026-01-28 14:49:00.791 +00:00 0794387998 3002 NOTICE Radius-Accounting: RADIUS Accounting watchdog update, ConfigVersionId=312, Device IP Address=1.1.1.1,…

---

## [Gitops: Building Logstash Plugin via gitlab runner?](https://discuss.elastic.co/t/gitops-building-logstash-plugin-via-gitlab-runner/384724)

<div class="topic-metadata">

**Author:** [@teopatl](https://discuss.elastic.co/u/teopatl)\
**Replies:** 0\
**Last updated:** [January 23, 2026, 9:44pm UTC](https://discuss.elastic.co/t/gitops-building-logstash-plugin-via-gitlab-runner/384724 "2026-01-23T21:44:40Z")

</div>

Anyone successfully building logstash java plugins as artifacts via gitlab runners? I’ve attempted a multi-stage docker build with the following gitlab-ci.yml, from which fails with the error A problem was found with…

---

## [\[Syslog output\] Erratic message output behavior](https://discuss.elastic.co/t/syslog-output-erratic-message-output-behavior/384670)

<div class="topic-metadata">

**Author:** [@TLB35](https://discuss.elastic.co/u/TLB35)\
**Replies:** 6\
**Last updated:** [January 21, 2026, 6:01pm UTC](https://discuss.elastic.co/t/syslog-output-erratic-message-output-behavior/384670 "2026-01-21T18:01:53Z")

</div>

Hi, I'm doing this post as I am encountering a "weird" issue with the syslog-output plugin behavior. My use case is quite simple. My logstash perform a redirection to a nginx cluster. Here is the code snippet : if \[ty…

---

## [How should logstash connect to ECK created TLS encrypted elasticsearch in kubernets](https://discuss.elastic.co/t/how-should-logstash-connect-to-eck-created-tls-encrypted-elasticsearch-in-kubernets/384586)

<div class="topic-metadata">

**Author:** [@VOCTERMA](https://discuss.elastic.co/u/VOCTERMA)\
**Replies:** 0\
**Last updated:** [January 16, 2026, 3:26pm UTC](https://discuss.elastic.co/t/how-should-logstash-connect-to-eck-created-tls-encrypted-elasticsearch-in-kubernets/384586 "2026-01-16T15:26:13Z")

</div>

How should logstash connect to ECK created TLS encrypted elasticsearch in kubernets

---

## [Logstash - %{+YYYY} returns a year two years behind around year boundary – how is this possible?](https://discuss.elastic.co/t/logstash-yyyy-returns-a-year-two-years-behind-around-year-boundary-how-is-this-possible/384359)

<div class="topic-metadata">

**Author:** [@josh\_tran](https://discuss.elastic.co/u/josh_tran)\
**Replies:** 12\
**Last updated:** [January 15, 2026, 9:46am UTC](https://discuss.elastic.co/t/logstash-yyyy-returns-a-year-two-years-behind-around-year-boundary-how-is-this-possible/384359 "2026-01-15T09:46:00Z")

</div>

I have a Logstash pipeline where I build a timestamp string manually and then parse it into event.timestamp because we do not have a year value in the log message, there are just day and month in the file name. Environm…

---

## [Logstash GROK](https://discuss.elastic.co/t/logstash-grok/384394)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 2\
**Last updated:** [January 7, 2026, 12:00pm UTC](https://discuss.elastic.co/t/logstash-grok/384394 "2026-01-07T12:00:00Z")

</div>

"\<190\>606524: 876342: Jan 6 2026 17:27:24.835 UTC: %SEC-6-IPACCESSLOGP: list BLOCK-Wifi denied udp 11.12.2.75(51811) -\> 111.22.13.60(5246), 2 packets " Grok Parser succeeds but i am getting grok error in Elastics…

---

## [Logstash PKI : Why does Logstash rely on optionnal metadata (Bag Attributes)?](https://discuss.elastic.co/t/logstash-pki-why-does-logstash-rely-on-optionnal-metadata-bag-attributes/384389)

<div class="topic-metadata">

**Author:** [@CitizenSteak](https://discuss.elastic.co/u/CitizenSteak)\
**Replies:** 1\
**Last updated:** [January 6, 2026, 2:03pm UTC](https://discuss.elastic.co/t/logstash-pki-why-does-logstash-rely-on-optionnal-metadata-bag-attributes/384389 "2026-01-06T14:03:03Z")

</div>

I renewed my Logstash PKI but when re-deploying all the client certificates to my Beats, they all encountered the following error : \`ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to b…

---

## [Ingesting logs from S3 bucket elastic-agent vs logstash](https://discuss.elastic.co/t/ingesting-logs-from-s3-bucket-elastic-agent-vs-logstash/384339)

<div class="topic-metadata">

**Author:** [@liquidkite](https://discuss.elastic.co/u/liquidkite)\
**Replies:** 2\
**Last updated:** [January 2, 2026, 4:46pm UTC](https://discuss.elastic.co/t/ingesting-logs-from-s3-bucket-elastic-agent-vs-logstash/384339 "2026-01-02T16:46:33Z")

</div>

Hello all, We are ingesting logs into an AWS S3 bucket and I’m exploring various ingestion mechanisms into elasticsearch. After some research, the options are elastic-agent using the S3/SQS and using Logstash S3 input.…

---

## [How to handle duplicate records in datastreams using fingerprint](https://discuss.elastic.co/t/how-to-handle-duplicate-records-in-datastreams-using-fingerprint/384260)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 2\
**Last updated:** [December 26, 2025, 11:34am UTC](https://discuss.elastic.co/t/how-to-handle-duplicate-records-in-datastreams-using-fingerprint/384260 "2025-12-26T11:34:00Z")

</div>

Hi Team, I am ingesting data from a Kafka topic into Elasticsearch using Logstash. The incoming data can contain duplicates, so I am using a fingerprint filter on a unique business field (seqId) and setting it as the d…

---

## [I can't seem to connect to logstash for some reason?](https://discuss.elastic.co/t/i-cant-seem-to-connect-to-logstash-for-some-reason/384209)

<div class="topic-metadata">

**Author:** [@Miksos](https://discuss.elastic.co/u/Miksos)\
**Replies:** 5\
**Last updated:** [December 22, 2025, 11:00am UTC](https://discuss.elastic.co/t/i-cant-seem-to-connect-to-logstash-for-some-reason/384209 "2025-12-22T11:00:20Z")

</div>

Dec 20 17:46:32 ELK-Server logstash\[690\]: \[2025-12-20T17:46:32,609\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Attempted to resurrect connection to dead ES instance, but got an error {:url=\>"khttp://localhost:9200/", :…

---

## [Logstash not reading log files from Windows network share folder](https://discuss.elastic.co/t/logstash-not-reading-log-files-from-windows-network-share-folder/384144)

<div class="topic-metadata">

**Author:** [@dalal404](https://discuss.elastic.co/u/dalal404)\
**Replies:** 10\
**Last updated:** [December 19, 2025, 12:14pm UTC](https://discuss.elastic.co/t/logstash-not-reading-log-files-from-windows-network-share-folder/384144 "2025-12-19T12:14:47Z")

</div>

Hello, I am running Logstash 9.1.2 on Windows Server 2019, and i am trying to read logs from a network share folder - //MACHINE-1/folder$/somedir/star\*/some\*star.log ( read the “star” as star character ). But it doesnt…

---

## ['No operations allowed after connection closed' errors during Filter phase](https://discuss.elastic.co/t/no-operations-allowed-after-connection-closed-errors-during-filter-phase/384139)

<div class="topic-metadata">

**Author:** [@maldoror](https://discuss.elastic.co/u/maldoror)\
**Replies:** 4\
**Last updated:** [December 18, 2025, 11:44am UTC](https://discuss.elastic.co/t/no-operations-allowed-after-connection-closed-errors-during-filter-phase/384139 "2025-12-18T11:44:36Z")

</div>

Hello friends, We are facing a critical issue with our Logstash indexing pipeline during the filtering phase, which executes some very heavy queries on our application DB. Our business application is executing constant…

---

## [Logs parsing for multiline logs](https://discuss.elastic.co/t/logs-parsing-for-multiline-logs/384151)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [December 17, 2025, 6:33pm UTC](https://discuss.elastic.co/t/logs-parsing-for-multiline-logs/384151 "2025-12-17T18:33:35Z")

</div>

Hello Team, Below is the sample logs | 2025-06-24 07:47:24 |ERROR| request-worker-13 | com.orsyp.central.ldap.MD5Login | Authentication Exception javax.naming.AuthenticationException: \[LDAP: error code 49 - 8009030C: L…

---

## [You are using a deprecated config setting "truststore" set in http. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Use \`ssl\_truststore\_path\` instead](https://discuss.elastic.co/t/you-are-using-a-deprecated-config-setting-truststore-set-in-http-deprecated-settings-will-continue-to-work-but-are-scheduled-for-removal-from-logstash-in-the-future-use-ssl-truststore-path-instead/384071)

<div class="topic-metadata">

**Author:** [@Prateek\_Garg](https://discuss.elastic.co/u/Prateek_Garg)\
**Replies:** 3\
**Last updated:** [December 16, 2025, 4:45pm UTC](https://discuss.elastic.co/t/you-are-using-a-deprecated-config-setting-truststore-set-in-http-deprecated-settings-will-continue-to-work-but-are-scheduled-for-removal-from-logstash-in-the-future-use-ssl-truststore-path-instead/384071 "2025-12-16T16:45:47Z")

</div>

You are using a deprecated config setting "truststore" set in http. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Use ssl\_truststore\_path instead If you have any qu…

---

## [Trouble Running a Second Pipeline in Logstash 8.x (Multiple Pipelines Not Working)](https://discuss.elastic.co/t/trouble-running-a-second-pipeline-in-logstash-8-x-multiple-pipelines-not-working/383956)

<div class="topic-metadata">

**Author:** [@Grzegosz](https://discuss.elastic.co/u/Grzegosz)\
**Replies:** 5\
**Last updated:** [December 11, 2025, 3:36pm UTC](https://discuss.elastic.co/t/trouble-running-a-second-pipeline-in-logstash-8-x-multiple-pipelines-not-working/383956 "2025-12-11T15:36:17Z")

</div>

Hello. Please help me understand why the second pipeline in Logstash is not working. I have Logstash 8+ installed. I added a second pipeline path in the pipelines.yml file as follows: - pipeline.id: audit path.config…

---

## [On what version of logstash has fix for issue AIKIDO-2024-10428](https://discuss.elastic.co/t/on-what-version-of-logstash-has-fix-for-issue-aikido-2024-10428/383875)

<div class="topic-metadata">

**Author:** [@Saikiran\_Pulijala](https://discuss.elastic.co/u/Saikiran_Pulijala)\
**Replies:** 2\
**Last updated:** [December 10, 2025, 5:47am UTC](https://discuss.elastic.co/t/on-what-version-of-logstash-has-fix-for-issue-aikido-2024-10428/383875 "2025-12-10T05:47:00Z")

</div>

Hello there, Our internal container image scanning tool has flagged a vulnerability related to JRuby’s StringIO library bundled with Logstash 8.19.7. Issue Details A vulnerability was reported in StringIO, where the me…

---

## [Logstash split one JSON document into multiple events](https://discuss.elastic.co/t/logstash-split-one-json-document-into-multiple-events/383935)

<div class="topic-metadata">

**Author:** [@eoszej](https://discuss.elastic.co/u/eoszej)\
**Replies:** 1\
**Last updated:** [December 9, 2025, 8:40pm UTC](https://discuss.elastic.co/t/logstash-split-one-json-document-into-multiple-events/383935 "2025-12-09T20:40:25Z")

</div>

Would you please help split a single JSON document being sent to Logstash into multiple events? There are some fields that are shared across the events but the fields that have a trailing number, such as "\_0001", are un…

---

## [TCP output codec json not working in Logstash (data not sending)](https://discuss.elastic.co/t/tcp-output-codec-json-not-working-in-logstash-data-not-sending/383927)

<div class="topic-metadata">

**Author:** [@powary1415](https://discuss.elastic.co/u/powary1415)\
**Replies:** 1\
**Last updated:** [December 9, 2025, 8:08pm UTC](https://discuss.elastic.co/t/tcp-output-codec-json-not-working-in-logstash-data-not-sending/383927 "2025-12-09T20:08:39Z")

</div>

Hello Team, I am using Logstash to forward events using the TCP output plugin. When I configure the output with JSON codec, data is not being sent to the receiver. output { tcp { host =\> "hostName" port =\> 1415 cod…

---

## [Elastic 8.10.4](https://discuss.elastic.co/t/elastic-8-10-4/383848)

<div class="topic-metadata">

**Author:** [@jgomezf](https://discuss.elastic.co/u/jgomezf)\
**Replies:** 7\
**Last updated:** [December 9, 2025, 5:32pm UTC](https://discuss.elastic.co/t/elastic-8-10-4/383848 "2025-12-09T17:32:57Z")

</div>

Hello. We are working with elastic 8.4.x and the ecs-logstash was working correctly. We have updated the version 8.10..4 and the ecs-logstash and pattern is not found. It's possibility that the version is not available.…

---

## [Logstash 8.9.0: How to match messages containing words starting with "sap" (e.g., sapxxx) using a filter?](https://discuss.elastic.co/t/logstash-8-9-0-how-to-match-messages-containing-words-starting-with-sap-e-g-sapxxx-using-a-filter/383889)

<div class="topic-metadata">

**Author:** [@Pan\_Vad](https://discuss.elastic.co/u/Pan_Vad)\
**Replies:** 11\
**Last updated:** [December 8, 2025, 1:18pm UTC](https://discuss.elastic.co/t/logstash-8-9-0-how-to-match-messages-containing-words-starting-with-sap-e-g-sapxxx-using-a-filter/383889 "2025-12-08T13:18:45Z")

</div>

Could you please help me with a Logstash filter pipeline configuration that can catch messages of the following type: \<30\>Dec 5 15:01:05 saphcmdevdb systemd\[1\]: snapperd.service: Deactivated successfully. I need to d…

---

## [Kafka output gets permanently stuck after temporary wrong port — pipeline-to-pipeline address unavailable & retrying\_send stall](https://discuss.elastic.co/t/kafka-output-gets-permanently-stuck-after-temporary-wrong-port-pipeline-to-pipeline-address-unavailable-retrying-send-stall/383877)

<div class="topic-metadata">

**Author:** [@Mahesh\_Kumar1](https://discuss.elastic.co/u/Mahesh_Kumar1)\
**Replies:** 5\
**Last updated:** [December 5, 2025, 5:32pm UTC](https://discuss.elastic.co/t/kafka-output-gets-permanently-stuck-after-temporary-wrong-port-pipeline-to-pipeline-address-unavailable-retrying-send-stall/383877 "2025-12-05T17:32:58Z")

</div>

Kafka output gets permanently stuck after temporary wrong port — pipeline-to-pipeline address unavailable & retrying\_send stall Hi, I am facing an issue with Logstash Kafka output when the Kafka broker becomes temporari…

---

## [How to get kafka metadata from a confluent kafka topic](https://discuss.elastic.co/t/how-to-get-kafka-metadata-from-a-confluent-kafka-topic/383844)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 2\
**Last updated:** [December 4, 2025, 5:35am UTC](https://discuss.elastic.co/t/how-to-get-kafka-metadata-from-a-confluent-kafka-topic/383844 "2025-12-04T05:35:20Z")

</div>

Hi, I am reading the data using logstash from a confluent kafka topic and I am trying to get the complete kafka metadata including header etc into my data. I have tried the below config but still i am unable to see the …

---

## [Logstash file output - pipeline stop working after flush error](https://discuss.elastic.co/t/logstash-file-output-pipeline-stop-working-after-flush-error/383505)

<div class="topic-metadata">

**Author:** [@Po-temkin](https://discuss.elastic.co/u/Po-temkin)\
**Replies:** 9\
**Last updated:** [December 1, 2025, 12:35pm UTC](https://discuss.elastic.co/t/logstash-file-output-pipeline-stop-working-after-flush-error/383505 "2025-12-01T12:35:21Z")

</div>

Have a nice day everyone. Not long ago, I started to notice missing syslog logs from random host groups. At first, I simply restarted our Logstash nodes that act as syslog forwarders, and the problem went away. But ov…

---

## [Does Logstash Kafka Plugin support Azure Managed Identity Authentication](https://discuss.elastic.co/t/does-logstash-kafka-plugin-support-azure-managed-identity-authentication/383776)

<div class="topic-metadata">

**Author:** [@dmj0013](https://discuss.elastic.co/u/dmj0013)\
**Replies:** 0\
**Last updated:** [December 1, 2025, 8:24am UTC](https://discuss.elastic.co/t/does-logstash-kafka-plugin-support-azure-managed-identity-authentication/383776 "2025-12-01T08:24:04Z")

</div>

Currently, does the Logstash Kafka Plugin support Azure Managed Identity Authentication for Event Hubs Kafka Endpoint? According to this article https://www.elastic.co/blog/ingest-data-azure-event-hub-entra-id?ref=dailyd…

---

## [Best way to reliably forward logs from Elasticsearch to multiple destinations using Logstash](https://discuss.elastic.co/t/best-way-to-reliably-forward-logs-from-elasticsearch-to-multiple-destinations-using-logstash/383730)

<div class="topic-metadata">

**Author:** [@Mahesh\_Kumar1](https://discuss.elastic.co/u/Mahesh_Kumar1)\
**Replies:** 1\
**Last updated:** [November 27, 2025, 1:49pm UTC](https://discuss.elastic.co/t/best-way-to-reliably-forward-logs-from-elasticsearch-to-multiple-destinations-using-logstash/383730 "2025-11-27T13:49:52Z")

</div>

Hi all, I am collecting logs from multiple sources (Syslog, SNMP, Windows EventLog,) and storing them in Elasticsearch. Now I need to forward these stored logs from Elasticsearch to multiple external destinations using…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=2)
