# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=100

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 101

---

## [Logstash.conf error](https://discuss.elastic.co/t/logstash-conf-error/321157)

<div class="topic-metadata">

**Author:** [@limitless](https://discuss.elastic.co/u/limitless)\
**Replies:** 1\
**Last updated:** [December 13, 2022, 6:57pm UTC](https://discuss.elastic.co/t/logstash-conf-error/321157 "2022-12-13T18:57:04Z")

</div>

.\\bin\\logstash.bat -f logstash.conf "Using bundled JDK: A:\\logstash-8.5.3\\jdk\\bin\\java.exe" Sending Logstash logs to A:/logstash-8.5.3/logs which is now configured via log4j2.properties \[2022-12-13T22:19:36,586\]\[INFO …

---

## [Logstash Agent error Failed to execute action](https://discuss.elastic.co/t/logstash-agent-error-failed-to-execute-action/321147)

<div class="topic-metadata">

**Author:** [@suresh.vemu](https://discuss.elastic.co/u/suresh.vemu)\
**Replies:** 1\
**Last updated:** [December 13, 2022, 6:45pm UTC](https://discuss.elastic.co/t/logstash-agent-error-failed-to-execute-action/321147 "2022-12-13T18:45:42Z")

</div>

I am new to logstash, and just installed it. When i try to run its giving me the below error. i am using logstash 8.5.3 version. appreciate any help. \[2022-12-13T11:29:39,728\]\[ERROR\]\[logstash.agent \] Failed to…

---

## [ECS category & type vs Grok](https://discuss.elastic.co/t/ecs-category-type-vs-grok/321063)

<div class="topic-metadata">

**Author:** [@tricia](https://discuss.elastic.co/u/tricia)\
**Replies:** 3\
**Last updated:** [December 13, 2022, 12:19pm UTC](https://discuss.elastic.co/t/ecs-category-type-vs-grok/321063 "2022-12-13T12:19:39Z")

</div>

Hi! This seems like it should be a simple question but I'm having trouble finding relevant documentation, so I appreciate any advice y'all might have. I'm trying to write filters to handle OpenSSH log data, and I'd like…

---

## [Logstash JDBC plugin maintain state in database instead of file](https://discuss.elastic.co/t/logstash-jdbc-plugin-maintain-state-in-database-instead-of-file/321106)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [December 13, 2022, 9:50am UTC](https://discuss.elastic.co/t/logstash-jdbc-plugin-maintain-state-in-database-instead-of-file/321106 "2022-12-13T09:50:40Z")

</div>

Hi all, I am wondering if it would be possible to maintain the sql\_last\_value in a database instead of a .yml file? This would be beneficial in my case, because it is easier accessible for modification and initializatio…

---

## [Logstash escaping characters, want to disable](https://discuss.elastic.co/t/logstash-escaping-characters-want-to-disable/318984)

<div class="topic-metadata">

**Author:** [@Johanna12221](https://discuss.elastic.co/u/Johanna12221)\
**Replies:** 2\
**Last updated:** [December 13, 2022, 7:51am UTC](https://discuss.elastic.co/t/logstash-escaping-characters-want-to-disable/318984 "2022-12-13T07:51:32Z")

</div>

Hi! I'm having a problem with how Logstash with JDBC input escapes characters. When I run the SQL query in SSMS I get the result fine: "\\publicerat\\IN0022.pdf" The JDBC input looks like this: input { jdbc { …

---

## [How to split a message from rabbit?](https://discuss.elastic.co/t/how-to-split-a-message-from-rabbit/321067)

<div class="topic-metadata">

**Author:** [@TheZadok42](https://discuss.elastic.co/u/TheZadok42)\
**Replies:** 4\
**Last updated:** [December 13, 2022, 5:31am UTC](https://discuss.elastic.co/t/how-to-split-a-message-from-rabbit/321067 "2022-12-13T05:31:56Z")

</div>

Hi! I am trying to split this message: {"test": "Test"} {"test": "Test2"} into two messages using this simple config: input { rabbitmq { …

---

## [Logstash GeoIP Database Manager: PKIX path building failed, \_geoip\_expired\_database tag](https://discuss.elastic.co/t/logstash-geoip-database-manager-pkix-path-building-failed-geoip-expired-database-tag/321073)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [December 12, 2022, 11:31pm UTC](https://discuss.elastic.co/t/logstash-geoip-database-manager-pkix-path-building-failed-geoip-expired-database-tag/321073 "2022-12-12T23:31:24Z")

</div>

Hello, I started to get this error on a couple of Logstash nodes. \[2022-12-12T20:10:23,983\]\[ERROR\]\[logstash.filters.geoip.databasemanager\] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderExc…

---

## [Read from Logstash file and format](https://discuss.elastic.co/t/read-from-logstash-file-and-format/320970)

<div class="topic-metadata">

**Author:** [@mail2shanth](https://discuss.elastic.co/u/mail2shanth)\
**Replies:** 1\
**Last updated:** [December 12, 2022, 6:22pm UTC](https://discuss.elastic.co/t/read-from-logstash-file-and-format/320970 "2022-12-12T18:22:35Z")

</div>

Hi, I am new to the Logstash. I've below log that I want to read in from a file, it is basically from another logstash server. Below is just one row from the file, there are millions of such rows. {"@timestamp":"2022-…

---

## [Using Grok filter](https://discuss.elastic.co/t/using-grok-filter/321051)

<div class="topic-metadata">

**Author:** [@Groove](https://discuss.elastic.co/u/Groove)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 3:31pm UTC](https://discuss.elastic.co/t/using-grok-filter/321051 "2022-12-12T15:31:40Z")

</div>

Hello, I am pretty new to ELK stack. Currently I am trying to parse my application log using grok pattern. But since my logs are not structured I may have to use grok conditions, because in output I have windows event an…

---

## [A Google Bigquery output plugin error](https://discuss.elastic.co/t/a-google-bigquery-output-plugin-error/321021)

<div class="topic-metadata">

**Author:** [@dalaopo](https://discuss.elastic.co/u/dalaopo)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 11:22am UTC](https://discuss.elastic.co/t/a-google-bigquery-output-plugin-error/321021 "2022-12-12T11:22:19Z")

</div>

Hello! The old field data I read from Kafka is object，It seems that there is no way to identify the setting record This is my first configuration csv\_schema =\> "old:STRING,...." And first error \[2022-12-12T19:06:04,…

---

## [Logstash won't send data to ES after re-create ES Cluster(Kafka Input)](https://discuss.elastic.co/t/logstash-wont-send-data-to-es-after-re-create-es-cluster-kafka-input/320230)

<div class="topic-metadata">

**Author:** [@da-head0](https://discuss.elastic.co/u/da-head0)\
**Replies:** 3\
**Last updated:** [December 12, 2022, 2:15am UTC](https://discuss.elastic.co/t/logstash-wont-send-data-to-es-after-re-create-es-cluster-kafka-input/320230 "2022-12-12T02:15:12Z")

</div>

Hello, ELK version : 8.4.2 Environment: Logstash in EKS, ECK Elasticsearch Hello, I used to send data to Elasticsearch with these config. input { kafka { bootstrap\_servers =\> "xx:9094, xx2:909…

---

## [Output isolator pattern is not sending logs to Elastic search, when my syslog server is down](https://discuss.elastic.co/t/output-isolator-pattern-is-not-sending-logs-to-elastic-search-when-my-syslog-server-is-down/320977)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 0\
**Last updated:** [December 11, 2022, 5:51pm UTC](https://discuss.elastic.co/t/output-isolator-pattern-is-not-sending-logs-to-elastic-search-when-my-syslog-server-is-down/320977 "2022-12-11T17:51:39Z")

</div>

Here I am trying to isolate the pipelines using output isolator pattern, and when I have rsyslog server and elastic 2 configured under one pipeline. And I have another pipeline which has only elastic 1 alone. When my …

---

## [Statically match multiple values depending on matchin regex](https://discuss.elastic.co/t/statically-match-multiple-values-depending-on-matchin-regex/320972)

<div class="topic-metadata">

**Author:** [@pondo\_m](https://discuss.elastic.co/u/pondo_m)\
**Replies:** 0\
**Last updated:** [December 11, 2022, 2:12pm UTC](https://discuss.elastic.co/t/statically-match-multiple-values-depending-on-matchin-regex/320972 "2022-12-11T14:12:50Z")

</div>

I want to set a statically defined value depending on the matching regex. Currently Im using the translate filter plugin with a dictionary of 400 entries to set the value depending on the matching regex. Is it possible…

---

## [Logstash filter plugin .gem file install on kubernetes Can't file local file](https://discuss.elastic.co/t/logstash-filter-plugin-gem-file-install-on-kubernetes-cant-file-local-file/320948)

<div class="topic-metadata">

**Author:** [@jijesh\_vu](https://discuss.elastic.co/u/jijesh_vu)\
**Replies:** 0\
**Last updated:** [December 10, 2022, 12:46pm UTC](https://discuss.elastic.co/t/logstash-filter-plugin-gem-file-install-on-kubernetes-cant-file-local-file/320948 "2022-12-10T12:46:30Z")

</div>

Im trying to install a custom .gem filter plugin using kubernetes StatefulSet. The gem file is in /tmp directory. pod log is showing ERROR: File not found for: file:///tmp/logstash-filter-kubernetes-0.3.1.gem, message: C…

---

## [Error: unable to load mongojdbc4.8.jar from :jdbc\_driver\_library, file not readable (please check user and group permissions for the path)](https://discuss.elastic.co/t/error-unable-to-load-mongojdbc4-8-jar-from-jdbc-driver-library-file-not-readable-please-check-user-and-group-permissions-for-the-path/320937)

<div class="topic-metadata">

**Author:** [@Vasanth2](https://discuss.elastic.co/u/Vasanth2)\
**Replies:** 0\
**Last updated:** [December 10, 2022, 6:08am UTC](https://discuss.elastic.co/t/error-unable-to-load-mongojdbc4-8-jar-from-jdbc-driver-library-file-not-readable-please-check-user-and-group-permissions-for-the-path/320937 "2022-12-10T06:08:02Z")

</div>

Error: unable to load mongojdbc4.8.jar from :jdbc\_driver\_library, file not readable (please check user and group permissions for the path)

---

## [How to configure 'ls.cgroup.cpu.path.override' in the Logstash JAVA\_OPTS environment variable](https://discuss.elastic.co/t/how-to-configure-ls-cgroup-cpu-path-override-in-the-logstash-java-opts-environment-variable/320880)

<div class="topic-metadata">

**Author:** [@jijesh\_vu](https://discuss.elastic.co/u/jijesh_vu)\
**Replies:** 2\
**Last updated:** [December 10, 2022, 5:46am UTC](https://discuss.elastic.co/t/how-to-configure-ls-cgroup-cpu-path-override-in-the-logstash-java-opts-environment-variable/320880 "2022-12-10T05:46:44Z")

</div>

I would like to know how to configure ls.cgroup.cpu.path.override and what this is means actaully? \[DEBUG\] 2022-12-09 12:27:37.592 \[pool-6-thread-1\] cpuresource - File /sys/fs/cgroup/cpu/kubepods.slice/kubepods-burstabl…

---

## [Where is Logstash installed by default?](https://discuss.elastic.co/t/where-is-logstash-installed-by-default/320913)

<div class="topic-metadata">

**Author:** [@timer5764](https://discuss.elastic.co/u/timer5764)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 8:42pm UTC](https://discuss.elastic.co/t/where-is-logstash-installed-by-default/320913 "2022-12-09T20:42:47Z")

</div>

I have a CentOS machine that I recently installed Logstash on, using the following command: sudo yum install logstash The command executed successfully and Logstash was installed, as shown in the screenshot below: H…

---

## [Aggregate logs of different grok matches](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 1\
**Last updated:** [December 9, 2022, 7:51pm UTC](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901 "2022-12-09T19:51:43Z")

</div>

Hi, I apologize in advance if the request appears incorrect I need calculate the time difference between a request and response of a REST service, this service produce two logs, one for request e and one for response an…

---

## [Clone cluster with Logstash](https://discuss.elastic.co/t/clone-cluster-with-logstash/320551)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 19\
**Last updated:** [December 9, 2022, 9:44am UTC](https://discuss.elastic.co/t/clone-cluster-with-logstash/320551 "2022-12-09T09:44:25Z")

</div>

Hey Everyone, We're trying to figure out the best way to clone a cluster completely, and Logstash seems to be the best option on a large scale as there's no need to use a custom solution. An example configuration of wh…

---

## [Multiple Logstash instances sharing code](https://discuss.elastic.co/t/multiple-logstash-instances-sharing-code/320861)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [December 9, 2022, 7:05am UTC](https://discuss.elastic.co/t/multiple-logstash-instances-sharing-code/320861 "2022-12-09T07:05:59Z")

</div>

Hi, I have four pipelines, two related to seeding data, and two related to continuously update data in elasticsearch. All pipelines share a lot of code. I am planning to run the pipelines in docker, and would like to cr…

---

## [A logstash to bigquery transmission problem](https://discuss.elastic.co/t/a-logstash-to-bigquery-transmission-problem/320771)

<div class="topic-metadata">

**Author:** [@dalaopo](https://discuss.elastic.co/u/dalaopo)\
**Replies:** 4\
**Last updated:** [December 9, 2022, 2:01am UTC](https://discuss.elastic.co/t/a-logstash-to-bigquery-transmission-problem/320771 "2022-12-09T02:01:50Z")

</div>

Hello！ I encountered an error when I used logstash to transfer kafka data to google bigquery \[ERROR\]\[logstash.outputs.googlebigquery\]\[main\]\[30729410306cb4d98635a59cbf171cea3b769fd734b29b17e925785d4edac5ba\] Error upload…

---

## [Error in logstash plain file](https://discuss.elastic.co/t/error-in-logstash-plain-file/320624)

<div class="topic-metadata">

**Author:** [@michaeljsamuel](https://discuss.elastic.co/u/michaeljsamuel)\
**Replies:** 18\
**Last updated:** [December 8, 2022, 8:39pm UTC](https://discuss.elastic.co/t/error-in-logstash-plain-file/320624 "2022-12-08T20:39:04Z")

</div>

Hi there, I am trying to use logstash on windows and believe I have downloaded it correctly however i am unable to forward any logs and this is what is in my plain file \[2022-12-07T10:41:03,853\]\[INFO \]\[logstash.runner …

---

## [Logstash | pubsub |Consume the early message instead of the oldest?](https://discuss.elastic.co/t/logstash-pubsub-consume-the-early-message-instead-of-the-oldest/320802)

<div class="topic-metadata">

**Author:** [@dfraz](https://discuss.elastic.co/u/dfraz)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 3:13pm UTC](https://discuss.elastic.co/t/logstash-pubsub-consume-the-early-message-instead-of-the-oldest/320802 "2022-12-08T15:13:50Z")

</div>

Hi Could it be possible to configure logstash to consume the early messages in Pubsub instead of the oldest ? thx for the help.

---

## [Push notification from Elasticsearch to Microsoft teams via Logstash pipeline](https://discuss.elastic.co/t/push-notification-from-elasticsearch-to-microsoft-teams-via-logstash-pipeline/320159)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 1:40pm UTC](https://discuss.elastic.co/t/push-notification-from-elasticsearch-to-microsoft-teams-via-logstash-pipeline/320159 "2022-12-08T13:40:16Z")

</div>

Hi All, I want to send some notifications from Elasticsearch to Microsoft teams via logstash pipeline. Based on my knowledge, I should use http output plugin to connect to Microsoft teams and push notification under me…

---

## [How to sync data from htttp\_poller](https://discuss.elastic.co/t/how-to-sync-data-from-htttp-poller/320787)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 12:29pm UTC](https://discuss.elastic.co/t/how-to-sync-data-from-htttp-poller/320787 "2022-12-08T12:29:18Z")

</div>

Hello, I am having 1 Billion data coming from an http API. The Api has pagination so that I can fetch data in batches. How can I implement that pagination in logstash using http\_poller plugin... My config file structur…

---

## [Problem connection LogStash to ElasticSearch in DockerCompose](https://discuss.elastic.co/t/problem-connection-logstash-to-elasticsearch-in-dockercompose/320773)

<div class="topic-metadata">

**Author:** [@mabsIpca](https://discuss.elastic.co/u/mabsIpca)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 11:15am UTC](https://discuss.elastic.co/t/problem-connection-logstash-to-elasticsearch-in-dockercompose/320773 "2022-12-08T11:15:03Z")

</div>

Hi everyone, I am currently developing a little project for university essay with educational purposes. In this project, I'm trying to use rabbit mq to send Log messages to Logstash from a Spring Boot Backend. Currentl…

---

## [Manipulating Nested Fields](https://discuss.elastic.co/t/manipulating-nested-fields/320768)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [December 8, 2022, 10:44am UTC](https://discuss.elastic.co/t/manipulating-nested-fields/320768 "2022-12-08T10:44:45Z")

</div>

Hi, Given a field \[field\]\[sub-field\], how can I move the value from "sub-field" to field? That is, convert this from an object to a string? I've tried: mutate { covert =\> { "field" =\> "string" } } and: mutate {…

---

## [Upsert solution Logstash](https://discuss.elastic.co/t/upsert-solution-logstash/320764)

<div class="topic-metadata">

**Author:** [@Vincent001](https://discuss.elastic.co/u/Vincent001)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 9:56am UTC](https://discuss.elastic.co/t/upsert-solution-logstash/320764 "2022-12-08T09:56:36Z")

</div>

Hello, I have a solution with filebeat(on server) -\> logstash(on server) -\> elasticsearch(as service) i have to ingest data from file.log in json format. each row have an "GUID" element wich is use for upsert. there i…

---

## [Logs dont have date in timestamp](https://discuss.elastic.co/t/logs-dont-have-date-in-timestamp/320544)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 8:26am UTC](https://discuss.elastic.co/t/logs-dont-have-date-in-timestamp/320544 "2022-12-08T08:26:44Z")

</div>

hi! using logtash I collect logs from communigate, but they come with a timestamp without a date 15:32:37.159 SMTPI-875156(\[40.11.11.11\]) \[33221\] received encrypted, 9618 bytes 15:32:37.160 QUEUE(\[33221\]) from 9618 byt…

---

## [Extract base64 encoded field from JSON message and write the decoded field to a file](https://discuss.elastic.co/t/extract-base64-encoded-field-from-json-message-and-write-the-decoded-field-to-a-file/320398)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 5\
**Last updated:** [December 8, 2022, 7:48am UTC](https://discuss.elastic.co/t/extract-base64-encoded-field-from-json-message-and-write-the-decoded-field-to-a-file/320398 "2022-12-08T07:48:51Z")

</div>

Hi All, I have the following logstash pipeline configuration. input { tcp { port =\> 5102 codec =\> json } } filter { json { source =\> "message" } } output { stdout { c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=99)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=101)
