# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=11

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 12

---

## [Problem with oracle dates though logstasg](https://discuss.elastic.co/t/problem-with-oracle-dates-though-logstasg/374770)

<div class="topic-metadata">

**Author:** [@Borja](https://discuss.elastic.co/u/Borja)\
**Replies:** 2\
**Last updated:** [February 20, 2025, 1:03pm UTC](https://discuss.elastic.co/t/problem-with-oracle-dates-though-logstasg/374770 "2025-02-20T13:03:48Z")

</div>

Hi all, We are migrating some queries used on logstash on a previous DB2 pipeline to a new oracle database pipeline. We have checked them on db clients like Dbvisualizer or dbviewer and running these converted queries …

---

## [Logstash 8.17.1 stuck on starting successfully](https://discuss.elastic.co/t/logstash-8-17-1-stuck-on-starting-successfully/374786)

<div class="topic-metadata">

**Author:** [@latte123](https://discuss.elastic.co/u/latte123)\
**Replies:** 2\
**Last updated:** [February 19, 2025, 10:01pm UTC](https://discuss.elastic.co/t/logstash-8-17-1-stuck-on-starting-successfully/374786 "2025-02-19T22:01:58Z")

</div>

I used config file with syslog for input/output from Openshift few times without changes successfully. It stopped working for unknown reason. Attached is output with traces on logstash restart; logstash.yml attached. Be…

---

## [Ruby dumps tons of runtime errors after upgrade to 8.16.2](https://discuss.elastic.co/t/ruby-dumps-tons-of-runtime-errors-after-upgrade-to-8-16-2/374774)

<div class="topic-metadata">

**Author:** [@Mash1](https://discuss.elastic.co/u/Mash1)\
**Replies:** 6\
**Last updated:** [February 19, 2025, 3:29pm UTC](https://discuss.elastic.co/t/ruby-dumps-tons-of-runtime-errors-after-upgrade-to-8-16-2/374774 "2025-02-19T15:29:59Z")

</div>

Hi everyone, After upgrading Logstash to 8.16.2 , The /var/log/logstash/logstash-plain.log is filling up very quickly with ERROR logs pointing to what seems to be runtime errors in Ruby code. We use Ruby in one of the f…

---

## [Extracting values from a JSON array without using a ruby script](https://discuss.elastic.co/t/extracting-values-from-a-json-array-without-using-a-ruby-script/374768)

<div class="topic-metadata">

**Author:** [@Matvey\_Dr](https://discuss.elastic.co/u/Matvey_Dr)\
**Replies:** 1\
**Last updated:** [February 19, 2025, 2:43pm UTC](https://discuss.elastic.co/t/extracting-values-from-a-json-array-without-using-a-ruby-script/374768 "2025-02-19T14:43:14Z")

</div>

Hello, I have json of this type at the input: { "folders": \[{ "template": "template\_name1", "attrs": \[{ "attrStr": { "key": "key1", …

---

## [OAUTH support for logstash kafka output for azure eventhub kafka endpoint](https://discuss.elastic.co/t/oauth-support-for-logstash-kafka-output-for-azure-eventhub-kafka-endpoint/374773)

<div class="topic-metadata">

**Author:** [@PARAS\_PAUL1](https://discuss.elastic.co/u/PARAS_PAUL1)\
**Replies:** 0\
**Last updated:** [February 19, 2025, 1:57pm UTC](https://discuss.elastic.co/t/oauth-support-for-logstash-kafka-output-for-azure-eventhub-kafka-endpoint/374773 "2025-02-19T13:57:55Z")

</div>

Hi All, I'm trying to push events to Azure Eventhub kafka endpoint. I'm able to successfully connect and publish to the topic when I use SASL\_SSL. But I want to use OAUTH. As per the microsoft documentation \[https://le…

---

## [How to parse optional fields in dhcp lease logs?](https://discuss.elastic.co/t/how-to-parse-optional-fields-in-dhcp-lease-logs/374602)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 5\
**Last updated:** [February 19, 2025, 10:47am UTC](https://discuss.elastic.co/t/how-to-parse-optional-fields-in-dhcp-lease-logs/374602 "2025-02-19T10:47:32Z")

</div>

I want help in parsing of optional fields lease 1.1.1.1 { starts 5 2025/02/14 05:32:50; ends 5 2025/02/14 05:37:55; tstp 5 2025/02/14 05:37:55; cltt 5 2025/02/14 05:37:54; binding state free; hardware ethern…

---

## [Need help with grokking complex logfile](https://discuss.elastic.co/t/need-help-with-grokking-complex-logfile/374709)

<div class="topic-metadata">

**Author:** [@componentByss](https://discuss.elastic.co/u/componentByss)\
**Replies:** 1\
**Last updated:** [February 18, 2025, 10:52pm UTC](https://discuss.elastic.co/t/need-help-with-grokking-complex-logfile/374709 "2025-02-18T22:52:05Z")

</div>

Hello! If anyone could provide assistance with setting up the correct grok filter for a complex logfile like this: ======== Query 1 of 2 ======== /\* \[User: 239\] events :: edit \*/ SELECT \`Attribute\`.\`type\`, \`Attribute\`.\`…

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/374643)

<div class="topic-metadata">

**Author:** [@guru\_dev](https://discuss.elastic.co/u/guru_dev)\
**Replies:** 8\
**Last updated:** [February 18, 2025, 7:29am UTC](https://discuss.elastic.co/t/issue-with-logstash/374643 "2025-02-18T07:29:18Z")

</div>

When logstash restarts it pushes latest log. Other time it does not push logs. I restarted logstash on feb 7. I see only feb 7 log event in Elasticsearch even today. There is no errrors reported in logstash-plain.log l…

---

## [\_dateparsefailure while using JDBC plugin](https://discuss.elastic.co/t/dateparsefailure-while-using-jdbc-plugin/374595)

<div class="topic-metadata">

**Author:** [@jack\_a](https://discuss.elastic.co/u/jack_a)\
**Replies:** 3\
**Last updated:** [February 16, 2025, 1:33pm UTC](https://discuss.elastic.co/t/dateparsefailure-while-using-jdbc-plugin/374595 "2025-02-16T13:33:34Z")

</div>

I am trying to read some data from a database, but when i try to parse a date field i get \_dateparsefailure while the field i am trying to convert is in ISO8601 format. Here is my full logstash config: input { jdbc {…

---

## [Not able to parse the incoming msg to json structure](https://discuss.elastic.co/t/not-able-to-parse-the-incoming-msg-to-json-structure/374504)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 8\
**Last updated:** [February 15, 2025, 2:43am UTC](https://discuss.elastic.co/t/not-able-to-parse-the-incoming-msg-to-json-structure/374504 "2025-02-15T02:43:23Z")

</div>

Hello, Below is the message content: # HELP Embargo\_Index\_seconds Time taken for Embargo Index\\n# TYPE Embargo\_Index\_seconds summary\\nEmbargo\_Index\_seconds\_count{CUST=\\"RPS\\",ENV=\\"DEV\\",PRODUCT=\\"GTM\\",class=\\"com.e2o…

---

## [Input Kafka avro - registry authentication](https://discuss.elastic.co/t/input-kafka-avro-registry-authentication/374555)

<div class="topic-metadata">

**Author:** [@joaosf](https://discuss.elastic.co/u/joaosf)\
**Replies:** 0\
**Last updated:** [February 14, 2025, 12:30pm UTC](https://discuss.elastic.co/t/input-kafka-avro-registry-authentication/374555 "2025-02-14T12:30:19Z")

</div>

Olá, I have some issues related with registry authentication. My conf: input { kafka { id =\> "kafka\_xxx" bootstrap\_servers =\> "xxxxx:9094" topics =\> \["XXX\_XX\_XXX\_XX"\] auto\_offset\_reset =\> "earliest"…

---

## [Logstash java heap memory causing delay to pushing events to elasticsearch](https://discuss.elastic.co/t/logstash-java-heap-memory-causing-delay-to-pushing-events-to-elasticsearch/374423)

<div class="topic-metadata">

**Author:** [@devops\_training](https://discuss.elastic.co/u/devops_training)\
**Replies:** 6\
**Last updated:** [February 14, 2025, 11:22am UTC](https://discuss.elastic.co/t/logstash-java-heap-memory-causing-delay-to-pushing-events-to-elasticsearch/374423 "2025-02-14T11:22:13Z")

</div>

Recently we made changes to java heap memory from 1G to 4G. Sometime it was stopped as it was not possible to process the event. when we increased the java heap memory logstash is processing the log events but elasticse…

---

## [Why can't my logStash account password connect to ES?](https://discuss.elastic.co/t/why-cant-my-logstash-account-password-connect-to-es/373212)

<div class="topic-metadata">

**Author:** [@Jerry\_Williams](https://discuss.elastic.co/u/Jerry_Williams)\
**Replies:** 12\
**Last updated:** [February 14, 2025, 12:33am UTC](https://discuss.elastic.co/t/why-cant-my-logstash-account-password-connect-to-es/373212 "2025-02-14T00:33:04Z")

</div>

I cannot connect to my ES in my docker environment. My account and password are configured correctly, but LogStash still cannot be used! Curl Result: logstash@0ef097e0f:~$ curl -u elastic:7z\_xxxxxxx http://elasticsearc…

---

## [Howto config winlogbeat + logstash + elasticsearch?](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393)

<div class="topic-metadata">

**Author:** [@Lynn\_Karllo](https://discuss.elastic.co/u/Lynn_Karllo)\
**Replies:** 13\
**Last updated:** [February 14, 2025, 12:26am UTC](https://discuss.elastic.co/t/howto-config-winlogbeat-logstash-elasticsearch/374393 "2025-02-14T00:26:10Z")

</div>

Config winlogbeat: winlogbeat.event\_logs: - name: Application ignore\_older: 72h - name: System - name: Security - name: Microsoft-Windows-Sysmon/Operational - name: Windows PowerShell event\_id: 400, 403…

---

## [Your settings are invalid. Reason: Setting "xpack.geoip.downloader.enabled" hasn't been registered](https://discuss.elastic.co/t/your-settings-are-invalid-reason-setting-xpack-geoip-downloader-enabled-hasnt-been-registered/374521)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 2\
**Last updated:** [February 13, 2025, 10:47pm UTC](https://discuss.elastic.co/t/your-settings-are-invalid-reason-setting-xpack-geoip-downloader-enabled-hasnt-been-registered/374521 "2025-02-13T22:47:48Z")

</div>

says: If you work in air-gapped environment and want to disable the database auto-update feature, set the xpack.geoip.downloader.enabled value to false in logstash.yml. So I set that, and now Logstash won't start a…

---

## [No logs coming from AWS integration CloudTrail logs from S3](https://discuss.elastic.co/t/no-logs-coming-from-aws-integration-cloudtrail-logs-from-s3/374517)

<div class="topic-metadata">

**Author:** [@Noj\_Eod](https://discuss.elastic.co/u/Noj_Eod)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 3:56pm UTC](https://discuss.elastic.co/t/no-logs-coming-from-aws-integration-cloudtrail-logs-from-s3/374517 "2025-02-13T15:56:33Z")

</div>

I'm experiencing issues with Elastic—I can't see any logs or errors related to AWS, but the agent is healthy. I'm using AWS integration CloudTrail logs from S3 only. The data stream for AWS also disappear. A help will b…

---

## [Following documentation for editing the Gemfile breaks Logstash](https://discuss.elastic.co/t/following-documentation-for-editing-the-gemfile-breaks-logstash/374317)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 4\
**Last updated:** [February 13, 2025, 11:12am UTC](https://discuss.elastic.co/t/following-documentation-for-editing-the-gemfile-breaks-logstash/374317 "2025-02-13T11:12:29Z")

</div>

I need to make Logstash 7 on a server that doesn't have Internet access use a local Gem repository. If I follow the instructions at Private Gem Repositories | Logstash Reference \[7.17\] | Elastic then instead of After …

---

## [Reindex shrink](https://discuss.elastic.co/t/reindex-shrink/374489)

<div class="topic-metadata">

**Author:** [@rezgui](https://discuss.elastic.co/u/rezgui)\
**Replies:** 0\
**Last updated:** [February 13, 2025, 9:37am UTC](https://discuss.elastic.co/t/reindex-shrink/374489 "2025-02-13T09:37:53Z")

</div>

hi i need to reidex shrink to remove conflic . in index i have filed type intger and in shrink type sting . how can i do?

---

## [Output.elasticsearch.hosts doe snot exist persisten error](https://discuss.elastic.co/t/output-elasticsearch-hosts-doe-snot-exist-persisten-error/374455)

<div class="topic-metadata">

**Author:** [@latte123](https://discuss.elastic.co/u/latte123)\
**Replies:** 4\
**Last updated:** [February 13, 2025, 6:36am UTC](https://discuss.elastic.co/t/output-elasticsearch-hosts-doe-snot-exist-persisten-error/374455 "2025-02-13T06:36:45Z")

</div>

ES, Logstash 8.17.1. I've implemented syslog via conf file in conf.d directory of Logstash to connect to OpenShift in Sandbox/dev environment. It all worked one day. Next day logs stopped with error in /var/log/logstash/…

---

## [Logstash not giving the expected output](https://discuss.elastic.co/t/logstash-not-giving-the-expected-output/374034)

<div class="topic-metadata">

**Author:** [@nkknkk](https://discuss.elastic.co/u/nkknkk)\
**Replies:** 37\
**Last updated:** [February 12, 2025, 6:16pm UTC](https://discuss.elastic.co/t/logstash-not-giving-the-expected-output/374034 "2025-02-12T18:16:14Z")

</div>

I am trying to parse my sample catalina.out file. here is my tomcat.conf file i am giving to the logstash ./logstash -f conf.d/tomcat.conf -r here is my tomcat.conf input { file { path =\> "/elkstack/logs/input…

---

## [Http communication failure connection refused](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208)

<div class="topic-metadata">

**Author:** [@Jecks\_Speed](https://discuss.elastic.co/u/Jecks_Speed)\
**Replies:** 7\
**Last updated:** [February 12, 2025, 7:15am UTC](https://discuss.elastic.co/t/http-communication-failure-connection-refused/374208 "2025-02-12T07:15:32Z")

</div>

Is there a way to keep the http port open in logstash?

---

## [Unable to parse data with grok](https://discuss.elastic.co/t/unable-to-parse-data-with-grok/374362)

<div class="topic-metadata">

**Author:** [@Eshwar\_K](https://discuss.elastic.co/u/Eshwar_K)\
**Replies:** 1\
**Last updated:** [February 11, 2025, 12:55pm UTC](https://discuss.elastic.co/t/unable-to-parse-data-with-grok/374362 "2025-02-11T12:55:29Z")

</div>

Hi Team, I have following logs and trying to parse with grok pattern but not able to get proper grok pattern for it. Kindly help me to to parse data into JSON format. I am trying to write the pattern as below. 2025-01…

---

## [MongoDB input plug-in for logstash](https://discuss.elastic.co/t/mongodb-input-plug-in-for-logstash/374345)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [February 11, 2025, 6:08am UTC](https://discuss.elastic.co/t/mongodb-input-plug-in-for-logstash/374345 "2025-02-11T06:08:05Z")

</div>

Hi Team, I am using Logstash (v8.17.1) to sync data from MongoDB to Elasticsearch. The document creation works fine, but I am facing issues with syncing only updated documents from MongoDB. I tried filtering documents …

---

## [Indexing delays in elastic search after increase the java heap memory on logstash](https://discuss.elastic.co/t/indexing-delays-in-elastic-search-after-increase-the-java-heap-memory-on-logstash/374324)

<div class="topic-metadata">

**Author:** [@devops\_training](https://discuss.elastic.co/u/devops_training)\
**Replies:** 0\
**Last updated:** [February 10, 2025, 3:41pm UTC](https://discuss.elastic.co/t/indexing-delays-in-elastic-search-after-increase-the-java-heap-memory-on-logstash/374324 "2025-02-10T15:41:48Z")

</div>

Hi Team - I would like to tune refresh interval and control bulk size parameters on Logstash. Could you please explain more about this parameters.

---

## [Logstash CEF Field Mapping Inconsistency Between 7.16.2 and 8.16.3](https://discuss.elastic.co/t/logstash-cef-field-mapping-inconsistency-between-7-16-2-and-8-16-3/374212)

<div class="topic-metadata">

**Author:** [@Kfiro](https://discuss.elastic.co/u/Kfiro)\
**Replies:** 3\
**Last updated:** [February 8, 2025, 7:57am UTC](https://discuss.elastic.co/t/logstash-cef-field-mapping-inconsistency-between-7-16-2-and-8-16-3/374212 "2025-02-08T07:57:55Z")

</div>

I am running Logstash containers to process CEF messages, and I have observed an inconsistency in field mappings between Logstash 7.16.2 and 8.16.3. When using Logstash 7.16.2, fields are mapped as expected, but in 8.16…

---

## [Logstash to Logstash with Lumbejack to Beats and SSL issue](https://discuss.elastic.co/t/logstash-to-logstash-with-lumbejack-to-beats-and-ssl-issue/374236)

<div class="topic-metadata">

**Author:** [@ottobus](https://discuss.elastic.co/u/ottobus)\
**Replies:** 0\
**Last updated:** [February 7, 2025, 5:36pm UTC](https://discuss.elastic.co/t/logstash-to-logstash-with-lumbejack-to-beats-and-ssl-issue/374236 "2025-02-07T17:36:55Z")

</div>

Hi, I'm trying to connect two Logsatsh with Lumberjack output plugin and Beats input plugin But I'm getting an error on ssl verify... Let's give more context ! First I'm using Logstash 8.5 on both side (I also tried wi…

---

## [Input CEF Codec output Rubydebug (Multiple use of codec)](https://discuss.elastic.co/t/input-cef-codec-output-rubydebug-multiple-use-of-codec/374213)

<div class="topic-metadata">

**Author:** [@moomoo21](https://discuss.elastic.co/u/moomoo21)\
**Replies:** 0\
**Last updated:** [February 7, 2025, 9:27am UTC](https://discuss.elastic.co/t/input-cef-codec-output-rubydebug-multiple-use-of-codec/374213 "2025-02-07T09:27:43Z")

</div>

Hello, I have a logstash config that goes something like: input{ pipeline { address =\> "output1" codec =\> cef{ ecs\_compatibility =\> disabled } } } output { stdout {codec =\> rubydebug} } The…

---

## [Output isolator pattern not working as expected when elastic is not reachable](https://discuss.elastic.co/t/output-isolator-pattern-not-working-as-expected-when-elastic-is-not-reachable/374166)

<div class="topic-metadata">

**Author:** [@himans](https://discuss.elastic.co/u/himans)\
**Replies:** 2\
**Last updated:** [February 7, 2025, 7:05am UTC](https://discuss.elastic.co/t/output-isolator-pattern-not-working-as-expected-when-elastic-is-not-reachable/374166 "2025-02-07T07:05:44Z")

</div>

Hi, I have implemented output isolator pattern having with 4 pipelines, main, elastic, http and mongodb. Now when the connectivity of elastic is lost, it doesn't push events to http and mongodb also. I have gone throug…

---

## [Multilevel split filter in logstash](https://discuss.elastic.co/t/multilevel-split-filter-in-logstash/374159)

<div class="topic-metadata">

**Author:** [@sravan\_kaheti](https://discuss.elastic.co/u/sravan_kaheti)\
**Replies:** 1\
**Last updated:** [February 6, 2025, 1:27pm UTC](https://discuss.elastic.co/t/multilevel-split-filter-in-logstash/374159 "2025-02-06T13:27:56Z")

</div>

Hi everyone, My original raw output for a custom API is like bellow \> '\[{"sourceSystem":"D365","totalCasesReceived":4,"success":{"count":1,"cases":\[{"transactionId":"D0000001775-7","correlationId":"d1c755de-5a03-4dde-a…

---

## [How to connect with GLPI API?](https://discuss.elastic.co/t/how-to-connect-with-glpi-api/371242)

<div class="topic-metadata">

**Author:** [@sebastien\_jacques](https://discuss.elastic.co/u/sebastien_jacques)\
**Replies:** 1\
**Last updated:** [February 5, 2025, 6:27pm UTC](https://discuss.elastic.co/t/how-to-connect-with-glpi-api/371242 "2025-02-05T18:27:17Z")

</div>

Hi I come to seek your help. I configured my logstash to retrieve data from my "alert2" index. it works. My goal is that when an event from this index arrives with the name "root-connection", it will create a ticket i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=10)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=12)
