# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=105

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 106

---

## [Logstash startup error](https://discuss.elastic.co/t/logstash-startup-error/318511)

<div class="topic-metadata">

**Author:** [@harijld](https://discuss.elastic.co/u/harijld)\
**Replies:** 7\
**Last updated:** [November 15, 2022, 9:02pm UTC](https://discuss.elastic.co/t/logstash-startup-error/318511 "2022-11-15T21:02:56Z")

</div>

HI All, I am trying to bring up Logstash on production server, getting below. Same set up working fine in UAT. Error Message 2022-11-08T15:30:28,121\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.vers…

---

## [How Periodic\_flush common setting helpful in ruby logstash filter?](https://discuss.elastic.co/t/how-periodic-flush-common-setting-helpful-in-ruby-logstash-filter/318980)

<div class="topic-metadata">

**Author:** [@priti](https://discuss.elastic.co/u/priti)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 6:45pm UTC](https://discuss.elastic.co/t/how-periodic-flush-common-setting-helpful-in-ruby-logstash-filter/318980 "2022-11-15T18:45:37Z")

</div>

I added periodic\_flush =\> true in ruby filter but I didn't found any difference. ruby { path =\> \<ruby file path\> periodic\_flush =\> true }

---

## [Send parts of a message to different Elasticsearch indices from a single Logstash instance](https://discuss.elastic.co/t/send-parts-of-a-message-to-different-elasticsearch-indices-from-a-single-logstash-instance/318950)

<div class="topic-metadata">

**Author:** [@powerful\_clouds](https://discuss.elastic.co/u/powerful_clouds)\
**Replies:** 4\
**Last updated:** [November 15, 2022, 4:14pm UTC](https://discuss.elastic.co/t/send-parts-of-a-message-to-different-elasticsearch-indices-from-a-single-logstash-instance/318950 "2022-11-15T16:14:06Z")

</div>

Suppose my message has fields A and B. I want to separately send each of the fields to the same ES instance, but to different indices. Is that possible? E.g. if this is the message: {"A": some text, "B": some more text},…

---

## [Add file path as a field](https://discuss.elastic.co/t/add-file-path-as-a-field/318966)

<div class="topic-metadata">

**Author:** [@Matan\_Malka](https://discuss.elastic.co/u/Matan_Malka)\
**Replies:** 5\
**Last updated:** [November 15, 2022, 3:40pm UTC](https://discuss.elastic.co/t/add-file-path-as-a-field/318966 "2022-11-15T15:40:53Z")

</div>

Hey guys, Is it possible to add a field for the file path? input{ file{ path =\> \[ "/bitnami/jenkins/jenkins\_home/jobs/create-machine/builds/\*\*/log", "/bitnami/jenkins/jenkins\_home/jobs/delete-machine/builds/\*\*/log"…

---

## [Logstash document\_id for 3 joined tables](https://discuss.elastic.co/t/logstash-document-id-for-3-joined-tables/318896)

<div class="topic-metadata">

**Author:** [@Swati\_Kanade](https://discuss.elastic.co/u/Swati_Kanade)\
**Replies:** 2\
**Last updated:** [November 15, 2022, 11:58am UTC](https://discuss.elastic.co/t/logstash-document-id-for-3-joined-tables/318896 "2022-11-15T11:58:15Z")

</div>

Hi, I am new to ELK stack search. I have created an index by joining 3 tables - message, message\_recipient and message\_attachments - using inner join on message and message\_recipient and left outer join on message\_attach…

---

## [Logstash Pipeline for Sql Server Varbinary Column](https://discuss.elastic.co/t/logstash-pipeline-for-sql-server-varbinary-column/318944)

<div class="topic-metadata">

**Author:** [@ArvindSarkania](https://discuss.elastic.co/u/ArvindSarkania)\
**Replies:** 0\
**Last updated:** [November 15, 2022, 9:25am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-sql-server-varbinary-column/318944 "2022-11-15T09:25:49Z")

</div>

Hello Sir I am facing issue with Logstash Pipline WIth JDBC plug in I have a task to insert data into elasticsearch with varbinary input. This is my Conf file input { #columns\_charset =\> { "column0" =\> "UTF8" } jdbc…

---

## [Nested JSON data to Logstash](https://discuss.elastic.co/t/nested-json-data-to-logstash/318895)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 7\
**Last updated:** [November 14, 2022, 11:38pm UTC](https://discuss.elastic.co/t/nested-json-data-to-logstash/318895 "2022-11-14T23:38:06Z")

</div>

Hi Can You point me out how to use data filter to making correct timestamp from file, below data (already prepared in JSON format) timestamp should be taken from "collectionBeginTime" field. Thanks for help { "meas…

---

## [Fingerprint for kafka output](https://discuss.elastic.co/t/fingerprint-for-kafka-output/318878)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 3:01pm UTC](https://discuss.elastic.co/t/fingerprint-for-kafka-output/318878 "2022-11-14T15:01:59Z")

</div>

Hello! is there any option to use fingerprint in kafka output ? we have three nodes in high availability and we are tripling data. How can we avoid it ? Thank you in advanced!

---

## [Newline character not processed by logback logstash JSON appender in Spring boot logger](https://discuss.elastic.co/t/newline-character-not-processed-by-logback-logstash-json-appender-in-spring-boot-logger/318841)

<div class="topic-metadata">

**Author:** [@jayanth91](https://discuss.elastic.co/u/jayanth91)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 9:00am UTC](https://discuss.elastic.co/t/newline-character-not-processed-by-logback-logstash-json-appender-in-spring-boot-logger/318841 "2022-11-14T09:00:58Z")

</div>

So i'm trying to format my json string but somehow the newline characters are not being processed and get printed as-is.

---

## [Unable to start Logstash docker 8.5.0](https://discuss.elastic.co/t/unable-to-start-logstash-docker-8-5-0/318815)

<div class="topic-metadata">

**Author:** [@diogogm](https://discuss.elastic.co/u/diogogm)\
**Replies:** 4\
**Last updated:** [November 14, 2022, 2:50am UTC](https://discuss.elastic.co/t/unable-to-start-logstash-docker-8-5-0/318815 "2022-11-14T02:50:08Z")

</div>

Hi everyone, I'm trying to start my logstash docker after hours configuring jvm.options, log4j2.properties, logstash.yml and pipelines.yml it's still showing "Logstash shut down" , I'm running the latest version of Elas…

---

## [Multiple filebeat instances sending logs](https://discuss.elastic.co/t/multiple-filebeat-instances-sending-logs/318651)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 12:06pm UTC](https://discuss.elastic.co/t/multiple-filebeat-instances-sending-logs/318651 "2022-11-10T12:06:33Z")

</div>

Hi, I have installed filebeat on multiple servers to pick system logs. The filebeat for server a works fine. filebeat.yml type: log enabled: true paths: /var/log/jenkins/jenkins.log exclude\_files: \['.gz$'\] multi…

---

## [Attempted to resurrect connection to dead ES instance](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/318562)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 2\
**Last updated:** [November 13, 2022, 4:52am UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/318562 "2022-11-13T04:52:10Z")

</div>

Hello folks, \[INFO \] 2022-11-09 16:05:14.964 \[Ruby-0-Thread-9: :1\] elasticsearch - Failed to perform request {:message=\>"PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to f…

---

## [Configuring logstash input for mysql jdbc](https://discuss.elastic.co/t/configuring-logstash-input-for-mysql-jdbc/318745)

<div class="topic-metadata">

**Author:** [@Khammassi\_HoussemEdd](https://discuss.elastic.co/u/Khammassi_HoussemEdd)\
**Replies:** 2\
**Last updated:** [November 12, 2022, 8:03am UTC](https://discuss.elastic.co/t/configuring-logstash-input-for-mysql-jdbc/318745 "2022-11-12T08:03:13Z")

</div>

this is my output : root@elk:/usr/share/logstash# sudo /usr/share/logstash/bin/logstash -f jdbc.conf Using bundled JDK: /usr/share/logstash/jdk WARNING: Could not find logstash.yml which is typically located in $LS\_HOME…

---

## [File "vendor/bundle/jruby/2.5.0/gems/pleaserun-0.0.31/bin/pleaserun" with access permission 777, who knows why?](https://discuss.elastic.co/t/file-vendor-bundle-jruby-2-5-0-gems-pleaserun-0-0-31-bin-pleaserun-with-access-permission-777-who-knows-why/317933)

<div class="topic-metadata">

**Author:** [@weng77](https://discuss.elastic.co/u/weng77)\
**Replies:** 1\
**Last updated:** [November 12, 2022, 6:15am UTC](https://discuss.elastic.co/t/file-vendor-bundle-jruby-2-5-0-gems-pleaserun-0-0-31-bin-pleaserun-with-access-permission-777-who-knows-why/317933 "2022-11-12T06:15:14Z")

</div>

File access permission with 777 will make things world writeable, it's an awful idea. But in logstash 7.7.0~logstash 7.12.0 pkg(from https://www.elastic.co/cn/downloads/past-releases/), we find out two files in vendor/b…

---

## [LogStash - Add fields between two unique events (start and stop)](https://discuss.elastic.co/t/logstash-add-fields-between-two-unique-events-start-and-stop/317586)

<div class="topic-metadata">

**Author:** [@Frankie\_Braybon](https://discuss.elastic.co/u/Frankie_Braybon)\
**Replies:** 1\
**Last updated:** [November 12, 2022, 3:18am UTC](https://discuss.elastic.co/t/logstash-add-fields-between-two-unique-events-start-and-stop/317586 "2022-11-12T03:18:24Z")

</div>

Hi, I have logs shipping to Logstash via FileBeat, which I'm doing log enrichment on before passing on to Elasticsearch. One of the enrichments I would like to do is add a field to each event which is between two uniqu…

---

## [Logtash CSV Parser Fail Muline Value is counting next raw](https://discuss.elastic.co/t/logtash-csv-parser-fail-muline-value-is-counting-next-raw/318617)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 10\
**Last updated:** [November 11, 2022, 6:33pm UTC](https://discuss.elastic.co/t/logtash-csv-parser-fail-muline-value-is-counting-next-raw/318617 "2022-11-11T18:33:14Z")

</div>

see in my First raw last coulumn have multiline and second raw haveing signle line

---

## [Logstash Not Starting On Reboot - Ubuntu](https://discuss.elastic.co/t/logstash-not-starting-on-reboot-ubuntu/318406)

<div class="topic-metadata">

**Author:** [@AlP9923](https://discuss.elastic.co/u/AlP9923)\
**Replies:** 5\
**Last updated:** [November 11, 2022, 5:19pm UTC](https://discuss.elastic.co/t/logstash-not-starting-on-reboot-ubuntu/318406 "2022-11-11T17:19:51Z")

</div>

Hi My single node setup works fine except on reboot of the Ubuntu server when Logstash usually does not auto start up. But using the systemctl start logstash works ok. It looks like the issue is that Logstash is trying…

---

## [Logstash Syslog output plugin streaming adds additional headers](https://discuss.elastic.co/t/logstash-syslog-output-plugin-streaming-adds-additional-headers/318719)

<div class="topic-metadata">

**Author:** [@Anandh\_Kumar](https://discuss.elastic.co/u/Anandh_Kumar)\
**Replies:** 1\
**Last updated:** [November 11, 2022, 1:45pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-plugin-streaming-adds-additional-headers/318719 "2022-11-11T13:45:43Z")

</div>

Hi We are using Logstash syslog output plugin v3.0.5 to stream audit log to a external SIEM server using TCP with SSL. It is observed that there are additional headers automatically appended by the plugin to the origina…

---

## [CEF message parsing](https://discuss.elastic.co/t/cef-message-parsing/318743)

<div class="topic-metadata">

**Author:** [@d\_c](https://discuss.elastic.co/u/d_c)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 1:14pm UTC](https://discuss.elastic.co/t/cef-message-parsing/318743 "2022-11-11T13:14:15Z")

</div>

Hello, I'm using TCP Input plugin with CEF codec to receive CEF messages. Problem is, that some messages are not parsed parsed correctly. Message isn't processed as whole, but it's split at blankspace character within m…

---

## [Pipeline getting terminated with OrgJrubyExceptions::ThreadKill](https://discuss.elastic.co/t/pipeline-getting-terminated-with-orgjrubyexceptions-threadkill/318724)

<div class="topic-metadata">

**Author:** [@Hafis](https://discuss.elastic.co/u/Hafis)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 10:25am UTC](https://discuss.elastic.co/t/pipeline-getting-terminated-with-orgjrubyexceptions-threadkill/318724 "2022-11-11T10:25:45Z")

</div>

Hi Am using logstash 8.4.0 with csv filter. Am facing an issue that logstash is getting killed itself. From the logs I can see that the pipeline is getting terminated. Below I have pasted sample logs. \[2022-11-11T06:40…

---

## [Winlogbeat events not parsed](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518)

<div class="topic-metadata">

**Author:** [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Replies:** 1\
**Last updated:** [November 11, 2022, 9:08am UTC](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518 "2022-11-11T09:08:50Z")

</div>

Hello, I am using elasticstack v8. The messages are sent from winlogbeat -\> logstash -\> elastic. The message is arrived unparsed. Logstash config: input { beats { port =\> "5044" …

---

## [Network devices like switch and firewall logs not visible in ELk](https://discuss.elastic.co/t/network-devices-like-switch-and-firewall-logs-not-visible-in-elk/318711)

<div class="topic-metadata">

**Author:** [@vrkumar79](https://discuss.elastic.co/u/vrkumar79)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 6:48am UTC](https://discuss.elastic.co/t/network-devices-like-switch-and-firewall-logs-not-visible-in-elk/318711 "2022-11-11T06:48:25Z")

</div>

network devices like switches and firewall logs are not visible in Elk. we are using customized UDP ports for each location,

---

## [How to enable authentication with logstash email output](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 11\
**Last updated:** [November 10, 2022, 5:28pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473 "2022-11-10T17:28:44Z")

</div>

I want to learn how to use logstash with mailtrap smtp for development purposes. I installed logstash then ran this command: /usr/share/logstash/bin/logstash -e 'input { stdin { } } output { email { to =\> "user@examp…

---

## [Incompatible encodings: IBM437 and UTF-8](https://discuss.elastic.co/t/incompatible-encodings-ibm437-and-utf-8/316918)

<div class="topic-metadata">

**Author:** [@Helmut](https://discuss.elastic.co/u/Helmut)\
**Replies:** 11\
**Last updated:** [November 10, 2022, 3:48pm UTC](https://discuss.elastic.co/t/incompatible-encodings-ibm437-and-utf-8/316918 "2022-11-10T15:48:06Z")

</div>

Hi, I just installed logstash 8.4.3 on Windows Server 2019 and copied over configs from 8.2.3. logstash doesn't start: \[2022-10-18T18:24:26,830\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\]\[42989fb99e78bec7495dbe5bfe5a…

---

## [HTTP Headers response Logstash http filter](https://discuss.elastic.co/t/http-headers-response-logstash-http-filter/318652)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 12:08pm UTC](https://discuss.elastic.co/t/http-headers-response-logstash-http-filter/318652 "2022-11-10T12:08:54Z")

</div>

Hello! I am trying to use logstash's http filter to get some data from apis. One of the most important values is received as a header and yet logstash is not showing me all the headers. Including those that have the sa…

---

## [Using http poller for https server](https://discuss.elastic.co/t/using-http-poller-for-https-server/318648)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 11:58am UTC](https://discuss.elastic.co/t/using-http-poller-for-https-server/318648 "2022-11-10T11:58:38Z")

</div>

Hi there i want to ask about http poller. so i test this plugin in my VM, and this is the configuration: input{ http\_poller{ urls =\> { test =\> { method =\> get user =\> "elastic" password =\> "myPassword" url =\> "h…

---

## [Access request header in plugin configuration](https://discuss.elastic.co/t/access-request-header-in-plugin-configuration/318642)

<div class="topic-metadata">

**Author:** [@dhggw](https://discuss.elastic.co/u/dhggw)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 10:08am UTC](https://discuss.elastic.co/t/access-request-header-in-plugin-configuration/318642 "2022-11-10T10:08:47Z")

</div>

Hi all, we use the Http input plugin to process events via http request in Logstash. The Logstash version is 7.16.2. With the http request we get a special http header, e.g. x-test-header: test-value We now want to r…

---

## [Logstash and elasticsearch certification issue](https://discuss.elastic.co/t/logstash-and-elasticsearch-certification-issue/318326)

<div class="topic-metadata">

**Author:** [@manasa3](https://discuss.elastic.co/u/manasa3)\
**Replies:** 8\
**Last updated:** [November 10, 2022, 9:37am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch-certification-issue/318326 "2022-11-10T09:37:44Z")

</div>

below is the configuration of our conf file input { file { path =\> "C:\\Users\\Windows\\Documents\\elk\\mule.csv" start\_position =\> "beginning" } } filter { csv { columns =\> \["Title", "Author", "ID","Pages"\] …

---

## [Splitting a json array format with same fields name](https://discuss.elastic.co/t/splitting-a-json-array-format-with-same-fields-name/318509)

<div class="topic-metadata">

**Author:** [@Adabi\_Raihan](https://discuss.elastic.co/u/Adabi_Raihan)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 7:44am UTC](https://discuss.elastic.co/t/splitting-a-json-array-format-with-same-fields-name/318509 "2022-11-10T07:44:06Z")

</div>

Hi Everyone, Currently, i have this kind of JSON array with the same field, what I wanted is to split this data into an independent field and the field name is based on a "name" field events.parameters (this is the fie…

---

## [Requirement to build a Multiple Input system in Logstash as given below, Can I build something like this?](https://discuss.elastic.co/t/requirement-to-build-a-multiple-input-system-in-logstash-as-given-below-can-i-build-something-like-this/318584)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 2\
**Last updated:** [November 10, 2022, 6:56am UTC](https://discuss.elastic.co/t/requirement-to-build-a-multiple-input-system-in-logstash-as-given-below-can-i-build-something-like-this/318584 "2022-11-10T06:56:39Z")

</div>

I need to implement a UDP system in between the input and output patterns as mentioned below. inputs : beats, tcp output: elastic-search meanwhile i need to send all the data from the inputs like beats, tcp to an UDPO…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=104)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=106)
