# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=115

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 116

---

## [How to print input data to logstash-plain.log file?](https://discuss.elastic.co/t/how-to-print-input-data-to-logstash-plain-log-file/314466)

<div class="topic-metadata">

**Author:** [@WonhyeongCho](https://discuss.elastic.co/u/WonhyeongCho)\
**Replies:** 3\
**Last updated:** [September 15, 2022, 4:37am UTC](https://discuss.elastic.co/t/how-to-print-input-data-to-logstash-plain-log-file/314466 "2022-09-15T04:37:49Z")

</div>

Hello. I'm using logstash for log collection. I want to write data coming into logstash to a log file. I tried many plugins to write data to log file but it didn't work. And I edit log4j2 settings like logger.logstas…

---

## [Unable to find valid certification path logstash](https://discuss.elastic.co/t/unable-to-find-valid-certification-path-logstash/314358)

<div class="topic-metadata">

**Author:** [@rt\_888](https://discuss.elastic.co/u/rt_888)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 3:17am UTC](https://discuss.elastic.co/t/unable-to-find-valid-certification-path-logstash/314358 "2022-09-14T03:17:17Z")

</div>

I am running ELK version 8.3.3 on docker and Logstash seperately . After I edit my logstash config file and running the Logstash, i got the error with "unable to find valid certification path to request target" . I think…

---

## [Parsing LEEF data](https://discuss.elastic.co/t/parsing-leef-data/314448)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 1\
**Last updated:** [September 14, 2022, 11:48pm UTC](https://discuss.elastic.co/t/parsing-leef-data/314448 "2022-09-14T23:48:31Z")

</div>

Hello, How can I parse LEEF data. The format includes | separation in the heard and SPACE separation in Body. Below is a sample event, please advise. The objective is to parse both the LEEF header (LEEF:1.0|Cyber-Ark|V…

---

## [Logstash cli with file option issue](https://discuss.elastic.co/t/logstash-cli-with-file-option-issue/314349)

<div class="topic-metadata">

**Author:** [@karlkras](https://discuss.elastic.co/u/karlkras)\
**Replies:** 6\
**Last updated:** [September 14, 2022, 11:05pm UTC](https://discuss.elastic.co/t/logstash-cli-with-file-option-issue/314349 "2022-09-14T23:05:43Z")

</div>

Windows 10 Logstash for Windows 8.4.1 Good afternoon. I've been working through some courseware on using logstash and have run into a problem while attempting to use the -f option with the logstash.bat file. The fi…

---

## [Filter XML plugin namespace available?](https://discuss.elastic.co/t/filter-xml-plugin-namespace-available/314463)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 9:37pm UTC](https://discuss.elastic.co/t/filter-xml-plugin-namespace-available/314463 "2022-09-14T21:37:30Z")

</div>

When using the namespace =\> { or the remove\_namespace I don't get any positive response when wanting to assign or remove the namespace, since I am getting this error Error parsing xml with XmlSimple \<REXML::UndefinedNa…

---

## [Filebeat v Logstash handling when Elastic endpoint is down](https://discuss.elastic.co/t/filebeat-v-logstash-handling-when-elastic-endpoint-is-down/314460)

<div class="topic-metadata">

**Author:** [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Replies:** 1\
**Last updated:** [September 14, 2022, 8:58pm UTC](https://discuss.elastic.co/t/filebeat-v-logstash-handling-when-elastic-endpoint-is-down/314460 "2022-09-14T20:58:42Z")

</div>

Quick question on how both filebeat and logstash handle data if Elasticsearch is down. In this scenario both would be pulling from a Kafka topic. We are wondering how the two operate if the endpoint is down but data is …

---

## [\[ERROR\] \[\[main\]\<file\] json - JSON parse error, original data now in message fiel {:message=\>"incompatible json object type=java.lanString, only hash map or arrays are supported", :exception=\>LogStash::Json::ParserError, data=\>" /"bandwidthLimits](https://discuss.elastic.co/t/error-main-file-json-json-parse-error-original-data-now-in-message-fiel-message-incompatible-json-object-type-java-lanstring-only-hash-map-or-arrays-are-supported-exception-logstash-parsererror-data-bandwidthlimits/314447)

<div class="topic-metadata">

**Author:** [@Queren\_Santos](https://discuss.elastic.co/u/Queren_Santos)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 6:21pm UTC](https://discuss.elastic.co/t/error-main-file-json-json-parse-error-original-data-now-in-message-fiel-message-incompatible-json-object-type-java-lanstring-only-hash-map-or-arrays-are-supported-exception-logstash-parsererror-data-bandwidthlimits/314447 "2022-09-14T18:21:04Z")

</div>

My logstash filter code catches incorrect data, can anyone help me with the correct syntax? input { file { path =\> "/var/tmp/wd/accounts/\*.json" codec =\> "json" start\_position =\> "beginning" sincedb\_pa…

---

## [Yet another case of Logstash Delays](https://discuss.elastic.co/t/yet-another-case-of-logstash-delays/314445)

<div class="topic-metadata">

**Author:** [@mread830](https://discuss.elastic.co/u/mread830)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 6:07pm UTC](https://discuss.elastic.co/t/yet-another-case-of-logstash-delays/314445 "2022-09-14T18:07:11Z")

</div>

I’m working on a logging solution that is really nothing more than a forwarder. rsyslog on several servers are sending their logs to Logstash, which then send them out to HEC splunk endpoint. In Logstash, we are using …

---

## [Parsing JSON](https://discuss.elastic.co/t/parsing-json/314435)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 5:39pm UTC](https://discuss.elastic.co/t/parsing-json/314435 "2022-09-14T17:39:21Z")

</div>

I want to extract only JSON data but don't know how to do it 2022-09-14 10:08:37,597 DEBUG logging.RequestLoggingAdvice Request received=\[{ "Name" : "John", "var1" : "Value1", "var2" : "Value2", "var3" : "Value3", "var4…

---

## [Using mutate to parse broken JSON](https://discuss.elastic.co/t/using-mutate-to-parse-broken-json/314436)

<div class="topic-metadata">

**Author:** [@Dan\_Fielder](https://discuss.elastic.co/u/Dan_Fielder)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 3:43pm UTC](https://discuss.elastic.co/t/using-mutate-to-parse-broken-json/314436 "2022-09-14T15:43:09Z")

</div>

I have messages arriving with very large blocks of broken JSON. These logs fail to parse when they arrive, so I'm using Filebeat to read from logstash-plain.log and feed them back in for extra processing. Each log cont…

---

## [UDP Listener Died](https://discuss.elastic.co/t/udp-listener-died/314339)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 12:37pm UTC](https://discuss.elastic.co/t/udp-listener-died/314339 "2022-09-14T12:37:51Z")

</div>

I'm seeing this error in my logstash-plain.log file and I ham not sure where to start looking: \[2022-09-13T17:25:47,905\]\[ERROR\]\[logstash.inputs.udp \]\[main\]\[8a46caaeb3cca4377e6163891fd9b8dd48405025c4a31918ce883ba824…

---

## [Error in logstash output by using elasticsearch update by query](https://discuss.elastic.co/t/error-in-logstash-output-by-using-elasticsearch-update-by-query/314405)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 11:47am UTC](https://discuss.elastic.co/t/error-in-logstash-output-by-using-elasticsearch-update-by-query/314405 "2022-09-14T11:47:35Z")

</div>

Hi All, I am trying to update new field to the existing documents using update by query through logstash and below is the configuration I have tried, input { http\_poller { urls =\> { version =\> "https://d…

---

## [Split single object in array to multiple?](https://discuss.elastic.co/t/split-single-object-in-array-to-multiple/314392)

<div class="topic-metadata">

**Author:** [@Hamza\_Khalid](https://discuss.elastic.co/u/Hamza_Khalid)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 9:37am UTC](https://discuss.elastic.co/t/split-single-object-in-array-to-multiple/314392 "2022-09-14T09:37:36Z")

</div>

I'm using logstash to index data from mysql to elasticsearch. Is there a way to convert this output: "interests" : \[ { "interest\_id" : "1,2", "interest\_name" : "Business,Farming" } \] To this: "interests" : \[ { …

---

## [How to avoid double indexing when using rollover indice](https://discuss.elastic.co/t/how-to-avoid-double-indexing-when-using-rollover-indice/314366)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 7\
**Last updated:** [September 14, 2022, 6:18am UTC](https://discuss.elastic.co/t/how-to-avoid-double-indexing-when-using-rollover-indice/314366 "2022-09-14T06:18:52Z")

</div>

Hello All, I'm using the rollover feature for my indices on daily basis along with doc\_as\_upsert,to maintain unique documents only.The rollover Index gets deleted after 30 days. I can see the issue of double indexing,E…

---

## [Filter http - delete by query doesn't work](https://discuss.elastic.co/t/filter-http-delete-by-query-doesnt-work/314371)

<div class="topic-metadata">

**Author:** [@Ely\_96](https://discuss.elastic.co/u/Ely_96)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 6:18am UTC](https://discuss.elastic.co/t/filter-http-delete-by-query-doesnt-work/314371 "2022-09-14T06:18:22Z")

</div>

Hi guys, in my pipeline, filter section I use the http plugin in order to remove old data: http { url =\> "http://localhost:9200/test-main/\_delete\_by\_query" verb =\> "POST" body\_format =\> …

---

## [Logstash unable to start and collect logs](https://discuss.elastic.co/t/logstash-unable-to-start-and-collect-logs/314296)

<div class="topic-metadata">

**Author:** [@khanchand](https://discuss.elastic.co/u/khanchand)\
**Replies:** 10\
**Last updated:** [September 14, 2022, 5:24am UTC](https://discuss.elastic.co/t/logstash-unable-to-start-and-collect-logs/314296 "2022-09-14T05:24:15Z")

</div>

Hi I have configure Elasticsearch, kibana & logstash on same machine. Want to receive firewall logs in logstash but facing below error. For now want to show these event on console only once received will forward in elast…

---

## [Sending events from specific ip adress to specific index](https://discuss.elastic.co/t/sending-events-from-specific-ip-adress-to-specific-index/314344)

<div class="topic-metadata">

**Author:** [@wmulobole1](https://discuss.elastic.co/u/wmulobole1)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 11:36pm UTC](https://discuss.elastic.co/t/sending-events-from-specific-ip-adress-to-specific-index/314344 "2022-09-13T23:36:16Z")

</div>

Hi, I am trying to separate my indexes by ip address. I want logs coming from three particular ips to go a specific index and the rest to go another index. I am not successful because the index is not showing up in Kiban…

---

## [Need to know ways of controlling the write to storage account for event hub access](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/313551)

<div class="topic-metadata">

**Author:** [@karthik\_Ravichandran](https://discuss.elastic.co/u/karthik_Ravichandran)\
**Replies:** 17\
**Last updated:** [September 13, 2022, 6:00pm UTC](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/313551 "2022-09-13T18:00:41Z")

</div>

I am having azure event hub as input logstash code , please advise how can i controlling events the write to storage account for event Hub Acess , this method will help in cost saving. please advise your thoughts

---

## [Pause between events ingested in elasticsearch](https://discuss.elastic.co/t/pause-between-events-ingested-in-elasticsearch/314025)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 13\
**Last updated:** [September 13, 2022, 5:22pm UTC](https://discuss.elastic.co/t/pause-between-events-ingested-in-elasticsearch/314025 "2022-09-13T17:22:54Z")

</div>

hello, I would like to know if it is possible, and if there is any filter that can put a time between events before sending them to elastic, for example: I have logs in elastic that are being ingested in the same second,…

---

## [What's the best way of creating a keystore with Dockerized Logstash?](https://discuss.elastic.co/t/whats-the-best-way-of-creating-a-keystore-with-dockerized-logstash/313810)

<div class="topic-metadata">

**Author:** [@rcorfield](https://discuss.elastic.co/u/rcorfield)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 1:18pm UTC](https://discuss.elastic.co/t/whats-the-best-way-of-creating-a-keystore-with-dockerized-logstash/313810 "2022-09-13T13:18:57Z")

</div>

Hi, we are currently wrestling with the problem of how to create a keystore for use with dockerized logstash. I have seen one solution in the forum already: How to use keystore in Dockerized logstash?, however we do not…

---

## [Elasticsearch array of an object using logstash](https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295)

<div class="topic-metadata">

**Author:** [@Hamza\_Khalid](https://discuss.elastic.co/u/Hamza_Khalid)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295 "2022-09-13T12:37:27Z")

</div>

I have a mysql database working as a primary database and i'm ingesting data into elasticsearch from mysql using logstash. I have successfully indexed the users table into elasticsearch and it is working perfectly fine h…

---

## [S3 input plugin taking really long time to process](https://discuss.elastic.co/t/s3-input-plugin-taking-really-long-time-to-process/313261)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 4\
**Last updated:** [September 13, 2022, 12:26pm UTC](https://discuss.elastic.co/t/s3-input-plugin-taking-really-long-time-to-process/313261 "2022-09-13T12:26:27Z")

</div>

Hi Team, I am using s3 input plugins to get billing data from aws. There are almost 15-20 files (ending with .csv.gz), each 115-120 MB of size. Now these files are replaced next day with new set of files Logstash conf…

---

## [Logstash not working](https://discuss.elastic.co/t/logstash-not-working/314123)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 8\
**Last updated:** [September 13, 2022, 12:23pm UTC](https://discuss.elastic.co/t/logstash-not-working/314123 "2022-09-13T12:23:07Z")

</div>

Hello, My logstash instance which is integrated with Azure Sentinel was working well with out any error (All the pipelines were functional, and the events were received at Azure Sentinel). A while ago, I made a couple o…

---

## [Configuring logstash to connect to Oracle AQ (JMS) without a web server](https://discuss.elastic.co/t/configuring-logstash-to-connect-to-oracle-aq-jms-without-a-web-server/314266)

<div class="topic-metadata">

**Author:** [@ztine77](https://discuss.elastic.co/u/ztine77)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 8:35am UTC](https://discuss.elastic.co/t/configuring-logstash-to-connect-to-oracle-aq-jms-without-a-web-server/314266 "2022-09-13T08:35:30Z")

</div>

I use dockerized version of logstash and would like to use Oracle AQ as an input. This is my ./pipeline/logstash.conf file: input { jms { broker\_url =\> 'jdbc:oracle:thin:@server:1521:sid' destination =\> 'MYQ…

---

## [Logstash high CPU](https://discuss.elastic.co/t/logstash-high-cpu/314238)

<div class="topic-metadata">

**Author:** [@jpeppard](https://discuss.elastic.co/u/jpeppard)\
**Replies:** 6\
**Last updated:** [September 13, 2022, 1:30am UTC](https://discuss.elastic.co/t/logstash-high-cpu/314238 "2022-09-13T01:30:18Z")

</div>

Hi all. Just installed ELKstack v8.4.1 on ubuntu server 20 to play around with. All is well with the data itself, Metricbeat is sending data to Elasticsearch from two other Ubuntu server machines. Visualizations and dat…

---

## [Apache Error Logs Not Parsing Correctly](https://discuss.elastic.co/t/apache-error-logs-not-parsing-correctly/314211)

<div class="topic-metadata">

**Author:** [@Loc\_Tran](https://discuss.elastic.co/u/Loc_Tran)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 5:39pm UTC](https://discuss.elastic.co/t/apache-error-logs-not-parsing-correctly/314211 "2022-09-12T17:39:30Z")

</div>

I'm not able to parse the apache error logs. I keep getting these errors: \[0\] "\_grokparsefailure" which means that there's an error in parsing the logs. Apache Error Logs \[Wed Aug 17 20:00:00.661037 2022\] \[proxy:err…

---

## [LOGSTASH Using different input index than the one specified](https://discuss.elastic.co/t/logstash-using-different-input-index-than-the-one-specified/314139)

<div class="topic-metadata">

**Author:** [@Moshe\_Sharon1](https://discuss.elastic.co/u/Moshe_Sharon1)\
**Replies:** 3\
**Last updated:** [September 12, 2022, 4:03pm UTC](https://discuss.elastic.co/t/logstash-using-different-input-index-than-the-one-specified/314139 "2022-09-12T16:03:54Z")

</div>

In logstash configuration file I set input to use "my \_indsex" as input and "result" as output after restarting logstash I found that the output have documents from another configuration input index ׳׳׳ input { elast…

---

## [Does Logstash 7.17.x support jdk17?](https://discuss.elastic.co/t/does-logstash-7-17-x-support-jdk17/314203)

<div class="topic-metadata">

**Author:** [@shivani\_aggarwal](https://discuss.elastic.co/u/shivani_aggarwal)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 3:38pm UTC](https://discuss.elastic.co/t/does-logstash-7-17-x-support-jdk17/314203 "2022-09-12T15:38:13Z")

</div>

Hi, I am using logstash 7.17.3 with Java 11 in containerized env. Does this version of logstash also support java 17? There is conflicting information from the two doc links from elastic - and hence the query for clar…

---

## [Error parsing xml with XmlSimple / UndefinedNamespaceException: undefined prefix log4j found](https://discuss.elastic.co/t/error-parsing-xml-with-xmlsimple-undefinednamespaceexception-undefined-prefix-log4j-found/314097)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 3:07pm UTC](https://discuss.elastic.co/t/error-parsing-xml-with-xmlsimple-undefinednamespaceexception-undefined-prefix-log4j-found/314097 "2022-09-12T15:07:09Z")

</div>

I am working with local filebeat and logstash and elasticsearch and kibana on a server. I need to convert the information that comes to me from the logs from xml to json. My configuration works when it reads a file with …

---

## [Logstash error : invalid setting for elasticsearch output plugin](https://discuss.elastic.co/t/logstash-error-invalid-setting-for-elasticsearch-output-plugin/314196)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 1:50pm UTC](https://discuss.elastic.co/t/logstash-error-invalid-setting-for-elasticsearch-output-plugin/314196 "2022-09-12T13:50:41Z")

</div>

Hi, I have two pipeline configurations located in /etc/logstash/conf.d. I can make work both seperately by running /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/\*\*.conf -r, and it sends data to elasticsearch …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=114)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=116)
