# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=104

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 105

---

## [Problems starting logstash (snmptrap)](https://discuss.elastic.co/t/problems-starting-logstash-snmptrap/319230)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 3\
**Last updated:** [November 18, 2022, 3:14pm UTC](https://discuss.elastic.co/t/problems-starting-logstash-snmptrap/319230 "2022-11-18T15:14:32Z")

</div>

Hello, I have a problem starting logstash. If I start logstash via "systemctl start logstash.service" I get the following error message: \[2022-11-17T18:11:59,947\]\[WARN \]\[logstash.inputs.snmptrap \]\[main\]\[eed358a3fbc602…

---

## [Logstash configuration error](https://discuss.elastic.co/t/logstash-configuration-error/319270)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 5\
**Last updated:** [November 18, 2022, 3:12pm UTC](https://discuss.elastic.co/t/logstash-configuration-error/319270 "2022-11-18T15:12:54Z")

</div>

Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:vpn, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\t\\r\\n\], "#", \[A-Za-z0-9\_-\], '"', "'", \[A-Za-z\_\], "-", \[0-9\], …

---

## [How to use DATEDIFF with logstash jdbc\_static filter](https://discuss.elastic.co/t/how-to-use-datediff-with-logstash-jdbc-static-filter/319293)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [November 18, 2022, 12:11pm UTC](https://discuss.elastic.co/t/how-to-use-datediff-with-logstash-jdbc-static-filter/319293 "2022-11-18T12:11:16Z")

</div>

Hi, I want to calculate the DATEDIFF under logstash and use it later under filter-\>jdbc\_static -\>local\_lookups query for comparison. when I tried to Calculate DATEDIFF under filter-\>jdbc\_static -\>local\_lookups , I g…

---

## [Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"NoMethodError", :message=\>"undefined method \`close' for nil:NilClass"](https://discuss.elastic.co/t/failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-nomethoderror-message-undefined-method-close-for-nil-nilclass/319186)

<div class="topic-metadata">

**Author:** [@Vedansh\_Singhal](https://discuss.elastic.co/u/Vedansh_Singhal)\
**Replies:** 10\
**Last updated:** [November 18, 2022, 11:14am UTC](https://discuss.elastic.co/t/failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-nomethoderror-message-undefined-method-close-for-nil-nilclass/319186 "2022-11-18T11:14:37Z")

</div>

\[2022-11-17T09:26:38,925\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.version"=\>"6.8.23"} \[2022-11-17T09:26:42,617\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::Pipel…

---

## [Errors with parsing json](https://discuss.elastic.co/t/errors-with-parsing-json/319234)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [November 18, 2022, 11:03am UTC](https://discuss.elastic.co/t/errors-with-parsing-json/319234 "2022-11-18T11:03:14Z")

</div>

Hi My pipeline works for shorter json file but when it was harnessed on the production files it has been crashed. I've enclosed a log files from logstash to present output. \[WARN \] 2022-11-17 18:08:03.585 \[\[ip40\]\>wor…

---

## [Separate yum repos for each architecture](https://discuss.elastic.co/t/separate-yum-repos-for-each-architecture/319220)

<div class="topic-metadata">

**Author:** [@sokratis](https://discuss.elastic.co/u/sokratis)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 4:19pm UTC](https://discuss.elastic.co/t/separate-yum-repos-for-each-architecture/319220 "2022-11-17T16:19:06Z")

</div>

Hello, I noticed that all rpms come under the same yum repo (as documented): \[logstash-8.x\] name=Elastic repository for 8.x packages baseurl=https://artifacts.elastic.co/packages/8.x/yum gpgcheck=1 gpgkey=https://artif…

---

## [Parse a json file that includes an xml](https://discuss.elastic.co/t/parse-a-json-file-that-includes-an-xml/317312)

<div class="topic-metadata">

**Author:** [@Alexandros](https://discuss.elastic.co/u/Alexandros)\
**Replies:** 7\
**Last updated:** [November 18, 2022, 8:40am UTC](https://discuss.elastic.co/t/parse-a-json-file-that-includes-an-xml/317312 "2022-11-18T08:40:06Z")

</div>

Hello all, I want to send the following json document to elasticsearch through logstash. "short\_message": "\<?xml version="1.0" encoding="utf-8"?\> \<ImportMessageBase xmlns:xsi="http://www.w3.org/2001/XMLSchem…

---

## [Https://discuss.elastic.co/t/logstash-not-working-with-jdk-11-0-16/315105/5](https://discuss.elastic.co/t/https-discuss-elastic-co-t-logstash-not-working-with-jdk-11-0-16-315105-5/317480)

<div class="topic-metadata">

**Author:** [@shivani\_aggarwal](https://discuss.elastic.co/u/shivani_aggarwal)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 6:27am UTC](https://discuss.elastic.co/t/https-discuss-elastic-co-t-logstash-not-working-with-jdk-11-0-16-315105-5/317480 "2022-11-18T06:27:11Z")

</div>

Hi, This is in continuation of my prev query that got auto-closed. Summary: Logstash 7.17.3 is not working with jdk \>= 11.0.16 As per @stephenb 's response, I've checked LS\_JAVA\_HOME is properly set. I see that th…

---

## [Date parsing issue](https://discuss.elastic.co/t/date-parsing-issue/319246)

<div class="topic-metadata">

**Author:** [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Replies:** 5\
**Last updated:** [November 18, 2022, 4:27am UTC](https://discuss.elastic.co/t/date-parsing-issue/319246 "2022-11-18T04:27:36Z")

</div>

I m having strange issue with Date parsing. Here is my config. input { stdin { } } output { stdout { codec =\> rubydebug } } filter { date { match =\> \["message", "ISO8601"\] } } when i run echo '2022-11-17 15:…

---

## [Change logstash index creation format](https://discuss.elastic.co/t/change-logstash-index-creation-format/319254)

<div class="topic-metadata">

**Author:** [@koreagrammer](https://discuss.elastic.co/u/koreagrammer)\
**Replies:** 0\
**Last updated:** [November 18, 2022, 2:56am UTC](https://discuss.elastic.co/t/change-logstash-index-creation-format/319254 "2022-11-18T02:56:14Z")

</div>

How do I set the logstash output index name to the client IP where metricbeat is installed? I just want logstash output index format to have below Metricbeat-{metricbeat.client.ip}-metricbeat.version-{YYYY.MM.DD}

---

## [Waiting for input plugin, Dropping events to unblock input plugin, Pipeline terminated](https://discuss.elastic.co/t/waiting-for-input-plugin-dropping-events-to-unblock-input-plugin-pipeline-terminated/319081)

<div class="topic-metadata">

**Author:** [@AdxDaz](https://discuss.elastic.co/u/AdxDaz)\
**Replies:** 3\
**Last updated:** [November 17, 2022, 11:19pm UTC](https://discuss.elastic.co/t/waiting-for-input-plugin-dropping-events-to-unblock-input-plugin-pipeline-terminated/319081 "2022-11-17T23:19:38Z")

</div>

Hi Elastic team, I was working in the next post "Locate json field with jsonpath (logstash) - #2 by Badger" and despite the code works, i have the next error when the position of the json value change: \[2022-11-15T09:3…

---

## [Two file output in Logstash](https://discuss.elastic.co/t/two-file-output-in-logstash/319056)

<div class="topic-metadata">

**Author:** [@Vrops](https://discuss.elastic.co/u/Vrops)\
**Replies:** 4\
**Last updated:** [November 17, 2022, 10:07pm UTC](https://discuss.elastic.co/t/two-file-output-in-logstash/319056 "2022-11-17T22:07:51Z")

</div>

Hello, I have explored several forums but can't find any answers to my question. I'm trying to get 2 Filebeat inputs and redirect them via Logstash with 2 different file outputs. Here are my configuration files: file…

---

## [We are getting Ruby exception error in logstash](https://discuss.elastic.co/t/we-are-getting-ruby-exception-error-in-logstash/319188)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 1\
**Last updated:** [November 17, 2022, 5:02pm UTC](https://discuss.elastic.co/t/we-are-getting-ruby-exception-error-in-logstash/319188 "2022-11-17T17:02:46Z")

</div>

Hi, we are getting ruby exception error in logstash as shown in below. \[ERROR\]\[logstash.filters.ruby \]\[xxxxxxxxxx\]\[634d732ae35f96b2b7a40d6e0005815a22897257fd1aa2279fe1d02125a79ba0\] Ruby exception occurred: undefined…

---

## [Wrong path in logstash output (FileBeat)](https://discuss.elastic.co/t/wrong-path-in-logstash-output-filebeat/319215)

<div class="topic-metadata">

**Author:** [@Vrops](https://discuss.elastic.co/u/Vrops)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 3:22pm UTC](https://discuss.elastic.co/t/wrong-path-in-logstash-output-filebeat/319215 "2022-11-17T15:22:55Z")

</div>

I have a problem when taking logs with FileBeat to Logstash, my logs arrive well in a file but the path of log is wrong in the output (It's the default location on an apache server). Here the config of FileBeat in the c…

---

## [TLS Logstash](https://discuss.elastic.co/t/tls-logstash/318865)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 1\
**Last updated:** [November 17, 2022, 2:50pm UTC](https://discuss.elastic.co/t/tls-logstash/318865 "2022-11-17T14:50:45Z")

</div>

Hello, I have an ELK stack secured in TLS. Exchanges between nodes and with kibana are secure. I have set up logstash to collect logs from the different equipments via the syslog protocol. I have questions about the …

---

## [Logstash Cloudwatch Logs](https://discuss.elastic.co/t/logstash-cloudwatch-logs/319211)

<div class="topic-metadata">

**Author:** [@Ryan5](https://discuss.elastic.co/u/Ryan5)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 2:40pm UTC](https://discuss.elastic.co/t/logstash-cloudwatch-logs/319211 "2022-11-17T14:40:39Z")

</div>

Hi, Whats the best way to get aws cloudwatch logs into logstash version 8.5? We want to avoid using this plugin due to it no longer being maintained and having dependency issues. dependency conflict · Issue #101 · lukew…

---

## [How to get sum\_other\_doc\_count in aggregations?](https://discuss.elastic.co/t/how-to-get-sum-other-doc-count-in-aggregations/319200)

<div class="topic-metadata">

**Author:** [@Purushottam22](https://discuss.elastic.co/u/Purushottam22)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 1:52pm UTC](https://discuss.elastic.co/t/how-to-get-sum-other-doc-count-in-aggregations/319200 "2022-11-17T13:52:59Z")

</div>

I am running an aggregation to see what document types does my 'documents' index has (documentType is the field that has the type): GET my\_documents/\_search { size: 0, "aggs": { "dataTypes": { "terms": { "field": …

---

## [Getting token using http\_poller to do some request](https://discuss.elastic.co/t/getting-token-using-http-poller-to-do-some-request/319153)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [November 17, 2022, 11:44am UTC](https://discuss.elastic.co/t/getting-token-using-http-poller-to-do-some-request/319153 "2022-11-17T11:44:48Z")

</div>

Hi there, maybe this topic has been opened by many people, but I still haven't found the answer. so, i would like to ask. i have configuration like this: input{ http\_poller{ test4 =\> { method =\> post …

---

## [Logstash WMI plugin logstash-input-wmi error](https://discuss.elastic.co/t/logstash-wmi-plugin-logstash-input-wmi-error/319163)

<div class="topic-metadata">

**Author:** [@houwenguang](https://discuss.elastic.co/u/houwenguang)\
**Replies:** 0\
**Last updated:** [November 17, 2022, 10:07am UTC](https://discuss.elastic.co/t/logstash-wmi-plugin-logstash-input-wmi-error/319163 "2022-11-17T10:07:12Z")

</div>

Hi, I use logstash to collect wmi remotely on linux. input { prueba local input { wmi { query =\> "select \* from Win32\_Process" host =\> "192.168.146.203" user =\> "Administrator" password =\> "1909" } } output { …

---

## [Increment custom field ID on certain event using logstash conf file](https://discuss.elastic.co/t/increment-custom-field-id-on-certain-event-using-logstash-conf-file/317839)

<div class="topic-metadata">

**Author:** [@Poongkuyil\_Muse](https://discuss.elastic.co/u/Poongkuyil_Muse)\
**Replies:** 10\
**Last updated:** [November 17, 2022, 5:48am UTC](https://discuss.elastic.co/t/increment-custom-field-id-on-certain-event-using-logstash-conf-file/317839 "2022-11-17T05:48:32Z")

</div>

Problem: I want to increment trap\_id on every process.php request. but in my case, trap\_id is always 0. I dont know why. Please help me My log file is in csv format. I am trying to fetch the periodical logs of a single …

---

## [I see the following message in logstash after enabling security on elaticsearch side](https://discuss.elastic.co/t/i-see-the-following-message-in-logstash-after-enabling-security-on-elaticsearch-side/319120)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 5:19pm UTC](https://discuss.elastic.co/t/i-see-the-following-message-in-logstash-after-enabling-security-on-elaticsearch-side/319120 "2022-11-16T17:19:45Z")

</div>

Hello, I am running elasticsearch cluster 7.9 with logstash to parse logfiles and ingest. After enabling security on elasticsearch I am seeing the following error messages into the logstash logs. \[ERROR\]\[logstash.licen…

---

## [How to drop DNS event if they are present into top 1 million file](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 5\
**Last updated:** [November 16, 2022, 4:55pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981 "2022-11-16T16:55:32Z")

</div>

Dear all, I'm wonderion how to configure a logstash pipeline that will handle my DNS logs. From that logs, there are lots of logs I don't want to see because I know they are legitimate. So I would like to have logstash…

---

## [Extract multiple substrings from a field using grok](https://discuss.elastic.co/t/extract-multiple-substrings-from-a-field-using-grok/319071)

<div class="topic-metadata">

**Author:** [@Matan\_Malka](https://discuss.elastic.co/u/Matan_Malka)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 12:26pm UTC](https://discuss.elastic.co/t/extract-multiple-substrings-from-a-field-using-grok/319071 "2022-11-16T12:26:13Z")

</div>

Hi, I'm trying to extract the job name ("create-machine") and the build number ("\*\*") from the file path but it is not possible to use duplicate keys. Do you have any other suggestions? input{ file{ path =\> \[ "/bi…

---

## [Iam trying to parse fortigate syslog to logstash](https://discuss.elastic.co/t/iam-trying-to-parse-fortigate-syslog-to-logstash/319059)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 10:55am UTC](https://discuss.elastic.co/t/iam-trying-to-parse-fortigate-syslog-to-logstash/319059 "2022-11-16T10:55:04Z")

</div>

when i run the command: /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/fortigate.conf I get the error : udp - UDP listener died {:exception=\>#\<Errno::EADDRINUSE: Address already in use - bind(2) for "192.168…

---

## [Grok Pattern For Java stack traces](https://discuss.elastic.co/t/grok-pattern-for-java-stack-traces/319036)

<div class="topic-metadata">

**Author:** [@Nessy](https://discuss.elastic.co/u/Nessy)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 8:56am UTC](https://discuss.elastic.co/t/grok-pattern-for-java-stack-traces/319036 "2022-11-16T08:56:34Z")

</div>

Hello, I have been workin on this topic for a long time. Here my logstash conf : filter { if \[fields\]\[application\_name\] =~ "APPNAME" { grok { match =\> { "message" =\> "(?\<timestamp\>%{TIMESTAMP\_ISO8601})…

---

## [Logstash sql pipeline stops working](https://discuss.elastic.co/t/logstash-sql-pipeline-stops-working/318945)

<div class="topic-metadata">

**Author:** [@knakul853](https://discuss.elastic.co/u/knakul853)\
**Replies:** 0\
**Last updated:** [November 15, 2022, 9:34am UTC](https://discuss.elastic.co/t/logstash-sql-pipeline-stops-working/318945 "2022-11-15T09:34:37Z")

</div>

Hi all! I have a sync job for logstash which continuously picked data that have these config setups use\_column\_value =\> true tracking\_column =\> "last\_update\_time" tracking\_column\_type =\> "timestamp" my question is …

---

## [Convert Logstash Main pipeline to multiple pipelines](https://discuss.elastic.co/t/convert-logstash-main-pipeline-to-multiple-pipelines/318899)

<div class="topic-metadata">

**Author:** [@adityak248](https://discuss.elastic.co/u/adityak248)\
**Replies:** 6\
**Last updated:** [November 16, 2022, 1:55am UTC](https://discuss.elastic.co/t/convert-logstash-main-pipeline-to-multiple-pipelines/318899 "2022-11-16T01:55:01Z")

</div>

Hello team, I have a main pipeline that has multiple inputs like beats, kafka and filters for many application and single and big output file with many if, else if and else. The pipeline is so messed now and am not cer…

---

## [How to parse glastopf honeypot log json using logstash for kibana visualization?](https://discuss.elastic.co/t/how-to-parse-glastopf-honeypot-log-json-using-logstash-for-kibana-visualization/319010)

<div class="topic-metadata">

**Author:** [@Febrian12345](https://discuss.elastic.co/u/Febrian12345)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 12:45am UTC](https://discuss.elastic.co/t/how-to-parse-glastopf-honeypot-log-json-using-logstash-for-kibana-visualization/319010 "2022-11-16T00:45:12Z")

</div>

I have a raw data in json format that I want to visualize in Kibana, but I'm having trouble parsing the data in logstash, previously I was able to visualize raw data for honeypot dionaea and cowrie. please help me in doi…

---

## [Logstash stopped processing because of an error](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error/319009)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 1\
**Last updated:** [November 16, 2022, 12:05am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error/319009 "2022-11-16T00:05:16Z")

</div>

First time installing logstash and need some help please and thanks! \[2022-11-15T18:45:54,229\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.version"=\>"8.5.0", "jruby.version"=\>"jruby 9.3.8.0 (2.6.8) 20…

---

## [Locate json field with jsonpath (logstash)](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812)

<div class="topic-metadata">

**Author:** [@AdxDaz](https://discuss.elastic.co/u/AdxDaz)\
**Replies:** 4\
**Last updated:** [November 15, 2022, 11:31pm UTC](https://discuss.elastic.co/t/locate-json-field-with-jsonpath-logstash/318812 "2022-11-15T23:31:32Z")

</div>

Hi Elastic team, I have the next Json: {"response-code":"4000","response":{"result":\[{"DetailsPageURL":"/show.do?resourceid=22&method=show&PRINTER\_FRIENDLY=true","TODAYUNAVAILPERCENT":"0","Attribute":\[{"DISPLAYNAME":"T…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=103)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=105)
