# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=110

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 111

---

## [Can we use conditions in input plugin of logstash](https://discuss.elastic.co/t/can-we-use-conditions-in-input-plugin-of-logstash/316873)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [October 18, 2022, 9:51am UTC](https://discuss.elastic.co/t/can-we-use-conditions-in-input-plugin-of-logstash/316873 "2022-10-18T09:51:46Z")

</div>

Hi team, Can we used multiple inputs plugin based on conditions we have specified

---

## [How to extract timestamp and log level from message and add it as a filed](https://discuss.elastic.co/t/how-to-extract-timestamp-and-log-level-from-message-and-add-it-as-a-filed/316639)

<div class="topic-metadata">

**Author:** [@Akumar22](https://discuss.elastic.co/u/Akumar22)\
**Replies:** 6\
**Last updated:** [October 18, 2022, 9:47am UTC](https://discuss.elastic.co/t/how-to-extract-timestamp-and-log-level-from-message-and-add-it-as-a-filed/316639 "2022-10-18T09:47:42Z")

</div>

Hi I want to extract timestamp and log level from message and want to add it as a field can you please suggest some filter or grok pattern to do this sample log : 2022-10-12 12:02:32,611 \[DEBUG\]\[pool-5-thread-14\]\[com.…

---

## [Palo alto sent to server via syslog](https://discuss.elastic.co/t/palo-alto-sent-to-server-via-syslog/316870)

<div class="topic-metadata">

**Author:** [@GEHsu](https://discuss.elastic.co/u/GEHsu)\
**Replies:** 0\
**Last updated:** [October 18, 2022, 9:40am UTC](https://discuss.elastic.co/t/palo-alto-sent-to-server-via-syslog/316870 "2022-10-18T09:40:34Z")

</div>

I tried paloalto (TRAFFIC/THREAT) 2 kinds of logs. Build to a different index. Below is my Logstash config input { syslog { port =\> "4560" } } filter { # Traffic Logs grok { match =\> { "message" =\> "%{…

---

## [Filebeat and logstash ssl config is correct?](https://discuss.elastic.co/t/filebeat-and-logstash-ssl-config-is-correct/316868)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [October 18, 2022, 9:31am UTC](https://discuss.elastic.co/t/filebeat-and-logstash-ssl-config-is-correct/316868 "2022-10-18T09:31:23Z")

</div>

filebeat filebeat.inputs: - type: filestream paths: - G:\\filebeat-8.4.3-windows-x86\_64\\logs\\\*.\* output.logstash: hosts: \["172.22.10.202:5044"\] protocol: "http" ssl.enabled: true ssl.certificate\_a…

---

## [Replace the last search result in the log](https://discuss.elastic.co/t/replace-the-last-search-result-in-the-log/316801)

<div class="topic-metadata">

**Author:** [@lmo](https://discuss.elastic.co/u/lmo)\
**Replies:** 0\
**Last updated:** [October 17, 2022, 2:34pm UTC](https://discuss.elastic.co/t/replace-the-last-search-result-in-the-log/316801 "2022-10-17T14:34:00Z")

</div>

I am currently monitoring the database(Jdbc). This bank refers to product sales, where at first the status of the sale receives "WAITING FOR PAYMENT" and after payment it receives the status of "PAID". however, when th…

---

## [Getting Configuration Error (No configuration found in the configured sources) : Logstash in Windows 11 Systems](https://discuss.elastic.co/t/getting-configuration-error-no-configuration-found-in-the-configured-sources-logstash-in-windows-11-systems/316784)

<div class="topic-metadata">

**Author:** [@SP003](https://discuss.elastic.co/u/SP003)\
**Replies:** 6\
**Last updated:** [October 17, 2022, 7:14pm UTC](https://discuss.elastic.co/t/getting-configuration-error-no-configuration-found-in-the-configured-sources-logstash-in-windows-11-systems/316784 "2022-10-17T19:14:07Z")

</div>

Hello, Greetings ! I am running Logstash from my system (windows 11) I have configured Elasticsearch and Kibana and its running fine. But Getting below error, while configuring log stash. Could you please tell me w…

---

## [Filebeat's logs doesn't create](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710)

<div class="topic-metadata">

**Author:** [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Replies:** 10\
**Last updated:** [October 17, 2022, 6:40pm UTC](https://discuss.elastic.co/t/filebeats-logs-doesnt-create/316710 "2022-10-17T18:40:02Z")

</div>

This is my current configuration file. filebeat.inputs: - type: log enabled: true paths: - /var/log/\*.log output.elasticsearch: hosts: \["localhost:9200"\] username: "elastic" password: "1" enabled: false…

---

## [Elasticsearch filter, ca\_file problem](https://discuss.elastic.co/t/elasticsearch-filter-ca-file-problem/316699)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [October 16, 2022, 10:50pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-ca-file-problem/316699 "2022-10-16T22:50:39Z")

</div>

Hi Im trying to use elasticsearch filter and I get this error: Host name 'my-elastic-ip' does not match the certificate subject provided by the peer (CN=instance)\> this is my conf: filter{ elasticsearch { hosts =\>…

---

## [Logstash strange warning](https://discuss.elastic.co/t/logstash-strange-warning/316676)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 0\
**Last updated:** [October 15, 2022, 9:50am UTC](https://discuss.elastic.co/t/logstash-strange-warning/316676 "2022-10-15T09:50:55Z")

</div>

\[2022-10-15T09:46:37,901\]\[WARN \]\[logstash.outputs.elasticsearch\]\[prima\] Elasticsearch Output configured with ecs\_compatibility =\> v8, which resolved to an UNRELEASED preview of version 8.0.0 of the Elastic Common Schema.…

---

## [Csv: map each field name to an array index](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673)

<div class="topic-metadata">

**Author:** [@ktomu](https://discuss.elastic.co/u/ktomu)\
**Replies:** 3\
**Last updated:** [October 15, 2022, 8:41pm UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673 "2022-10-15T20:41:21Z")

</div>

Hi, I have a csv file with 2000 fields and I need only 5 from them and I know their position. It's easy to get that 5 fields using filebeat (decode\_csv\_fields and extract\_array) because everything that I need it just map…

---

## [Logstash stalls processing and becomes unresponsitive after some runtime (filter issues?)](https://discuss.elastic.co/t/logstash-stalls-processing-and-becomes-unresponsitive-after-some-runtime-filter-issues/316640)

<div class="topic-metadata">

**Author:** [@gweiss76](https://discuss.elastic.co/u/gweiss76)\
**Replies:** 2\
**Last updated:** [October 14, 2022, 5:15pm UTC](https://discuss.elastic.co/t/logstash-stalls-processing-and-becomes-unresponsitive-after-some-runtime-filter-issues/316640 "2022-10-14T17:15:26Z")

</div>

Hi fellow log analysts. We are currently using Logstash for all syslog related logdata. Currently we have the issue, that logstash (almost) stops processing logdata after some time which results in backpressure to the …

---

## [Pagination Logic in input of HTTP Poller plugin, if not how to do it in custom plugin](https://discuss.elastic.co/t/pagination-logic-in-input-of-http-poller-plugin-if-not-how-to-do-it-in-custom-plugin/316595)

<div class="topic-metadata">

**Author:** [@Sayontani\_Bose1](https://discuss.elastic.co/u/Sayontani_Bose1)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 6:44am UTC](https://discuss.elastic.co/t/pagination-logic-in-input-of-http-poller-plugin-if-not-how-to-do-it-in-custom-plugin/316595 "2022-10-14T06:44:41Z")

</div>

I have to bulk import data via LogStash as below: Source: Restful Get APIs Destination : Elasticsearch My .conf file looks as below: input { http\_poller { urls =\> { ticket\_status =\> { method =\> get url =\> "https…

---

## [Inconsistent timestamp format from logstash out](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568)

<div class="topic-metadata">

**Author:** [@dchavan](https://discuss.elastic.co/u/dchavan)\
**Replies:** 5\
**Last updated:** [October 13, 2022, 8:29pm UTC](https://discuss.elastic.co/t/inconsistent-timestamp-format-from-logstash-out/316568 "2022-10-13T20:29:51Z")

</div>

There seems to be some inconsistency in the way logstash @timestamp is added in the out file. {"host":"X","version":"unknown","event":{"original":"2022-10-12T15:51:22,937 WARN \[EAF11E629F8C4DF987673EAABE186797\]\[schedul…

---

## [\<OpenSSL::SSL::SSLError: Certificates do not conform to algorithm constraints\>,](https://discuss.elastic.co/t/openssl-certificates-do-not-conform-to-algorithm-constraints/316180)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 4\
**Last updated:** [October 13, 2022, 4:01pm UTC](https://discuss.elastic.co/t/openssl-certificates-do-not-conform-to-algorithm-constraints/316180 "2022-10-13T16:01:04Z")

</div>

Getting the below error when trying to connect to remote syslog server using ssl-tcp protocol. SSL Error {:exception=\>#\<OpenSSL::SSL::SSLError: Certificates do not conform to algorithm constraints\>, :backtrace=\>\['org/jr…

---

## [Installing 8.4.x on docker and having issues](https://discuss.elastic.co/t/installing-8-4-x-on-docker-and-having-issues/316530)

<div class="topic-metadata">

**Author:** [@neilwcdl](https://discuss.elastic.co/u/neilwcdl)\
**Replies:** 1\
**Last updated:** [October 13, 2022, 11:34am UTC](https://discuss.elastic.co/t/installing-8-4-x-on-docker-and-having-issues/316530 "2022-10-13T11:34:17Z")

</div>

Hi, Sorry I'm very new to logstash and docker and currently looking at installing 8.4.3, as we are currently on 8.3.2. Installing 8.3.3 - no issues Installing 8.4.0 - the issues start ---\> Running in 54f67362af15 Us…

---

## [Logstash Elasticsearch output - one field only](https://discuss.elastic.co/t/logstash-elasticsearch-output-one-field-only/316395)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 5\
**Last updated:** [October 13, 2022, 7:49am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-one-field-only/316395 "2022-10-13T07:49:11Z")

</div>

Hi, Is it possible to send only the "message" field to elasticsearch from logstash? I have tried codec =\> line { format =\> "%{message}" } but the full beat output is still sent. Thanks.

---

## [Filebeat-\* as Index in Elasticsearch Input plugin in Logstash Config](https://discuss.elastic.co/t/filebeat-as-index-in-elasticsearch-input-plugin-in-logstash-config/315273)

<div class="topic-metadata">

**Author:** [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Replies:** 0\
**Last updated:** [September 27, 2022, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-as-index-in-elasticsearch-input-plugin-in-logstash-config/315273 "2022-09-27T14:32:38Z")

</div>

Hello Experts, Expecting replies from you :slight\_smile: I have created a Logstash Config file, which takes Elasticsearch Index ( filebeat-7.16.3-2022.09.16-000020) as Input. Now that index is full and new index is cr…

---

## [Unable to index winlogbeat using logstash](https://discuss.elastic.co/t/unable-to-index-winlogbeat-using-logstash/316434)

<div class="topic-metadata">

**Author:** [@bamfery](https://discuss.elastic.co/u/bamfery)\
**Replies:** 2\
**Last updated:** [October 13, 2022, 6:53am UTC](https://discuss.elastic.co/t/unable-to-index-winlogbeat-using-logstash/316434 "2022-10-13T06:53:09Z")

</div>

I am trying to set up winlogbeat to ship data to a logstash server, which further forwards to another logstash server and then to elasticsearch. I am seeing that when I add index =\> "%{\[@metadata\]\[beat\]}-%{+YYYY.MM.dd}" …

---

## [Handling a JSON key with a name being an empty string ""](https://discuss.elastic.co/t/handling-a-json-key-with-a-name-being-an-empty-string/316486)

<div class="topic-metadata">

**Author:** [@geekpete](https://discuss.elastic.co/u/geekpete)\
**Replies:** 0\
**Last updated:** [October 13, 2022, 4:49am UTC](https://discuss.elastic.co/t/handling-a-json-key-with-a-name-being-an-empty-string/316486 "2022-10-13T04:49:50Z")

</div>

Given a block of JSON like: {"":"value1","field2":"value2"} Where the first key has a blank name "" but has a regular looking value of value1, you might want to conditionally handle such data to avoid problems once ind…

---

## [Keystore in Elastic Cloud](https://discuss.elastic.co/t/keystore-in-elastic-cloud/316459)

<div class="topic-metadata">

**Author:** [@rlperry](https://discuss.elastic.co/u/rlperry)\
**Replies:** 1\
**Last updated:** [October 13, 2022, 12:04am UTC](https://discuss.elastic.co/t/keystore-in-elastic-cloud/316459 "2022-10-13T00:04:38Z")

</div>

Secrets keystore for secure settings | Logstash Reference \[8.4\] | Elastic outlines how to use environment variables inside pipelines and how to create and maintain a Keystore in the path.settings directory. How does one…

---

## [Why logstash merge index of 3 different config?](https://discuss.elastic.co/t/why-logstash-merge-index-of-3-different-config/316450)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 4:12pm UTC](https://discuss.elastic.co/t/why-logstash-merge-index-of-3-different-config/316450 "2022-10-12T16:12:07Z")

</div>

i ve 3 config but i see the 3 index is similar why ? all index contais info all 3 index this is my type config is different for path and name index in \*\* lines input { file { \*\*path =\> \[ "/logstash\_dir/fede…

---

## [Logstash cut line why?](https://discuss.elastic.co/t/logstash-cut-line-why/316440)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 4\
**Last updated:** [October 12, 2022, 2:51pm UTC](https://discuss.elastic.co/t/logstash-cut-line-why/316440 "2022-10-12T14:51:06Z")

</div>

i have this secotion of logs 2022-09-28 16:19:49,383 ERROR \[it.unidoc.cdr.core.route.Iti41MllpSource\] (TcpSocketConsumerRunnable\[mllp://0.0.0.0:9010\] - /192.168.0.7:56372 =\> /192.168.0.32:9010) Conversion error: ca.uhn…

---

## [MYSQL to Elasticsearch via Logstash Problem: incompatible encodings: CP850 and UTF-8](https://discuss.elastic.co/t/mysql-to-elasticsearch-via-logstash-problem-incompatible-encodings-cp850-and-utf-8/314122)

<div class="topic-metadata">

**Author:** [@engineer86](https://discuss.elastic.co/u/engineer86)\
**Replies:** 5\
**Last updated:** [October 12, 2022, 9:57am UTC](https://discuss.elastic.co/t/mysql-to-elasticsearch-via-logstash-problem-incompatible-encodings-cp850-and-utf-8/314122 "2022-10-12T09:57:45Z")

</div>

I am using an elk stack via docker-compose with ES version 8.4.0 My goal is to use Logstash to copy an entire table from my MYSQL DB to ES. The connection works and Logstash copies about 30 entries with no problems. But…

---

## [Logstash http\_poller "read time out" on http 200 response](https://discuss.elastic.co/t/logstash-http-poller-read-time-out-on-http-200-response/316416)

<div class="topic-metadata">

**Author:** [@Marc\_Hoog](https://discuss.elastic.co/u/Marc_Hoog)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 8:11am UTC](https://discuss.elastic.co/t/logstash-http-poller-read-time-out-on-http-200-response/316416 "2022-10-12T08:11:33Z")

</div>

So I got this pipeline in logstash using http\_poller and it works when the client is responding with a 401, but It breaks when it responses with a 200 with a little bit of data. These request also do work with curl from…

---

## [Match and replace in logstash](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 7:21am UTC](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406 "2022-10-12T07:21:54Z")

</div>

Hello, I have a setup where I collect PfSense VPN logs and pass them through Logstash to extract some fields. My VPN logs have LDAP usernames such as doejo, which implies the full name of John Doe. Now I need the logs …

---

## [Logstash service discover\_files {:count=\>0}](https://discuss.elastic.co/t/logstash-service-discover-files-count-0/316376)

<div class="topic-metadata">

**Author:** [@fantastas](https://discuss.elastic.co/u/fantastas)\
**Replies:** 5\
**Last updated:** [October 12, 2022, 6:33am UTC](https://discuss.elastic.co/t/logstash-service-discover-files-count-0/316376 "2022-10-12T06:33:30Z")

</div>

hello, i have an issue i can't figure out. I am also not sure how logstash sincedb\_path works too so if someone could help me understand - I'd highly appreciate. I am running ELK on RedHat Linux virtual machine. If i …

---

## [Read data from postgres and calling external api in Logstash](https://discuss.elastic.co/t/read-data-from-postgres-and-calling-external-api-in-logstash/316398)

<div class="topic-metadata">

**Author:** [@mani7](https://discuss.elastic.co/u/mani7)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 6:28am UTC](https://discuss.elastic.co/t/read-data-from-postgres-and-calling-external-api-in-logstash/316398 "2022-10-12T06:28:19Z")

</div>

I am looking forward to read data from Postgres using Logstash, taking one value as a input to call one external api. and taking the output results of that. And storing into elastic. Can anyone tell what all can be the …

---

## [Condition filter not working after upgrading to logstash8](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300)

<div class="topic-metadata">

**Author:** [@PIYUSH\_MISHRA1](https://discuss.elastic.co/u/PIYUSH_MISHRA1)\
**Replies:** 5\
**Last updated:** [October 12, 2022, 5:35am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300 "2022-10-12T05:35:52Z")

</div>

Hi Team, I have following configuration in my logstash.conf file. irresepective of the value in ${ENV}, always else block is getting executed. Same piece of code used to work with logstash older versions (2.X and 6.x)…

---

## [Logstash with the cloud version / "Could not connect to a compatible version of Elasticsearch\>, "](https://discuss.elastic.co/t/logstash-with-the-cloud-version-could-not-connect-to-a-compatible-version-of-elasticsearch/316363)

<div class="topic-metadata">

**Author:** [@LeoCP](https://discuss.elastic.co/u/LeoCP)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 9:18pm UTC](https://discuss.elastic.co/t/logstash-with-the-cloud-version-could-not-connect-to-a-compatible-version-of-elasticsearch/316363 "2022-10-11T21:18:19Z")

</div>

Greeting, I am evaluating the cloud version of Elasticsearch, and I want to mount some test data, using logstash (version 8.4.3), but I get an error telling me the following: "Could not connect to a compatible version…

---

## [Multiple syslog input into logstash](https://discuss.elastic.co/t/multiple-syslog-input-into-logstash/316360)

<div class="topic-metadata">

**Author:** [@kazishafiullah](https://discuss.elastic.co/u/kazishafiullah)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 5:24pm UTC](https://discuss.elastic.co/t/multiple-syslog-input-into-logstash/316360 "2022-10-11T17:24:27Z")

</div>

Hello, I wanted to parse logs of network devices into logstash. I have configured individual pipeline for cisco and paloalto. I have configured the input as syslog with different ports and output to different index name…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=109)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=111)
