# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=116

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 117

---

## [Ingest Lag or Pipeline not working?](https://discuss.elastic.co/t/ingest-lag-or-pipeline-not-working/314148)

<div class="topic-metadata">

**Author:** [@Ely\_96](https://discuss.elastic.co/u/Ely_96)\
**Replies:** 5\
**Last updated:** [September 12, 2022, 1:02pm UTC](https://discuss.elastic.co/t/ingest-lag-or-pipeline-not-working/314148 "2022-09-12T13:02:31Z")

</div>

Hi guys, I have a doubt my pipelines. I have 2 pipelines to see (in Kibana) the most recent requests within a platform. Each request is a json that has a couple of fields and: req-id req-timestamp My pipelines: T…

---

## [Grok date filter problem with french timestamp](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151)

<div class="topic-metadata">

**Author:** [@marwen](https://discuss.elastic.co/u/marwen)\
**Replies:** 4\
**Last updated:** [September 12, 2022, 12:13am UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151 "2022-09-12T00:13:15Z")

</div>

good day everyone, using elastic stack 17.7.5 I'm parsing log events to logstash the problem is date filter not working with my logs (catalina) here is example: avr. 23, 2022 1:46:19 PM org.apache.coyote.AbstractProtoc…

---

## [How to grok those multiline log syntax?](https://discuss.elastic.co/t/how-to-grok-those-multiline-log-syntax/314118)

<div class="topic-metadata">

**Author:** [@cowderwelsh](https://discuss.elastic.co/u/cowderwelsh)\
**Replies:** 2\
**Last updated:** [September 10, 2022, 7:33pm UTC](https://discuss.elastic.co/t/how-to-grok-those-multiline-log-syntax/314118 "2022-09-10T19:33:02Z")

</div>

Hi, I'm new to Elastic and after creating my first pipeline, I'm now trying to process a simple, local multiline Firewall log, it looks like this: Time: 01/28/2022 01:27:22 Event: Traffic IP-Address: 20.199.120.85 …

---

## [Error parsing csv](https://discuss.elastic.co/t/error-parsing-csv/314099)

<div class="topic-metadata">

**Author:** [@manuel.urbano](https://discuss.elastic.co/u/manuel.urbano)\
**Replies:** 11\
**Last updated:** [September 10, 2022, 4:06pm UTC](https://discuss.elastic.co/t/error-parsing-csv/314099 "2022-09-10T16:06:35Z")

</div>

Hi, I'm reading a CSV file and sending it to Elasticsearch, everything works fine but some rows are throwing an exception: Error parsing csv {:field=\>"message", :source=\>"6123464a-420f-4838-8ecb-fcce87f16297;20878376219…

---

## [Single quotes makes MySQL statement invalid using jdbc\_streaming filter](https://discuss.elastic.co/t/single-quotes-makes-mysql-statement-invalid-using-jdbc-streaming-filter/314078)

<div class="topic-metadata">

**Author:** [@roeeklinger](https://discuss.elastic.co/u/roeeklinger)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 4:39pm UTC](https://discuss.elastic.co/t/single-quotes-makes-mysql-statement-invalid-using-jdbc-streaming-filter/314078 "2022-09-09T16:39:48Z")

</div>

Hello, I am trying to use the jdbc\_streaming filter with a regexp statement, like this: jdbc\_streaming { jdbc\_driver\_library =\> "/usr/share/logstash/jdbc\_drivers/mysql-connector-java-8.0.30.jar" jdbc\_driver\_…

---

## [XML - Illegal Argument Exception](https://discuss.elastic.co/t/xml-illegal-argument-exception/313704)

<div class="topic-metadata">

**Author:** [@hnf](https://discuss.elastic.co/u/hnf)\
**Replies:** 9\
**Last updated:** [September 9, 2022, 4:17pm UTC](https://discuss.elastic.co/t/xml-illegal-argument-exception/313704 "2022-09-09T16:17:40Z")

</div>

Hello Everyone, I'm unable to dissect my xml file. I'm getting some error of "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"mapper \[CELL\] cannot be changed from type \[text\] to \[ObjectMapper\]"}. Please find b…

---

## [LogStash Next Step](https://discuss.elastic.co/t/logstash-next-step/313927)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 11\
**Last updated:** [September 9, 2022, 4:01pm UTC](https://discuss.elastic.co/t/logstash-next-step/313927 "2022-09-09T16:01:17Z")

</div>

Team, I'm not sure what I'm missing or I have broken here. I have an Elastic Server, Kibana Server, and Logstash Server. Elastic and Kibana are working. I'v setup one cisco switch to send logs to logstash and setup logs…

---

## [Need to frequently change url-timestamp value within logstash input](https://discuss.elastic.co/t/need-to-frequently-change-url-timestamp-value-within-logstash-input/314026)

<div class="topic-metadata">

**Author:** [@Pukar](https://discuss.elastic.co/u/Pukar)\
**Replies:** 3\
**Last updated:** [September 9, 2022, 3:56pm UTC](https://discuss.elastic.co/t/need-to-frequently-change-url-timestamp-value-within-logstash-input/314026 "2022-09-09T15:56:39Z")

</div>

Hi, I'm parsing some json data from a website using rest api with start\_timestamp of 4 hours before current time period. Is there a way within logstash to write such code to get data from last 4 hours on every runtime o…

---

## [Multiple syslog messages in one event](https://discuss.elastic.co/t/multiple-syslog-messages-in-one-event/314071)

<div class="topic-metadata">

**Author:** [@simpleman](https://discuss.elastic.co/u/simpleman)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 3:09pm UTC](https://discuss.elastic.co/t/multiple-syslog-messages-in-one-event/314071 "2022-09-09T15:09:41Z")

</div>

I am trying to send logs from Symantec Endpoint Protection to Logstash using syslog. Unfortunately, Beats is not an option for our setup. So I have SEP send syslogs over tcp at port 50000. At the moment, I simply print t…

---

## [File transfer error from logstash to elasticsearch](https://discuss.elastic.co/t/file-transfer-error-from-logstash-to-elasticsearch/313950)

<div class="topic-metadata">

**Author:** [@Sagar\_Shrestha](https://discuss.elastic.co/u/Sagar_Shrestha)\
**Replies:** 9\
**Last updated:** [September 9, 2022, 12:54pm UTC](https://discuss.elastic.co/t/file-transfer-error-from-logstash-to-elasticsearch/313950 "2022-09-09T12:54:41Z")

</div>

In my windows machine. My Logstash is working fine as administrator. When I input any raw data in the console (when input is stdin { } ) it is indexed into the Elasticsearch. But when any file format document is executed…

---

## [Logstash to logstash](https://discuss.elastic.co/t/logstash-to-logstash/314051)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 1\
**Last updated:** [September 9, 2022, 11:59am UTC](https://discuss.elastic.co/t/logstash-to-logstash/314051 "2022-09-09T11:59:20Z")

</div>

Hello, I am trying to add another output to some of our logstashes to output beats data to another logstash. I am attempting to use the lumberjack protocol and have been following the elastic documentation to do so. I h…

---

## [How to send only error logs path from filebeat to logstash](https://discuss.elastic.co/t/how-to-send-only-error-logs-path-from-filebeat-to-logstash/314050)

<div class="topic-metadata">

**Author:** [@poojitha0812](https://discuss.elastic.co/u/poojitha0812)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 10:55am UTC](https://discuss.elastic.co/t/how-to-send-only-error-logs-path-from-filebeat-to-logstash/314050 "2022-09-09T10:55:07Z")

</div>

Hi , I am able to send logs from filebeat to logstash but i enabled logging level and given path to save under /var/log/filebeat to save the error files . filebeat is connected to logstash and now i am want logstash to …

---

## [UDP input codec](https://discuss.elastic.co/t/udp-input-codec/313740)

<div class="topic-metadata">

**Author:** [@Laurent\_DEGEN](https://discuss.elastic.co/u/Laurent_DEGEN)\
**Replies:** 7\
**Last updated:** [September 9, 2022, 7:48am UTC](https://discuss.elastic.co/t/udp-input-codec/313740 "2022-09-09T07:48:54Z")

</div>

Hi, I have an NB-IOT sensor that outputs UDP packets containing some data. I used the default UDP input plugin and default plain codec but It does not decode the packet's UDP payload the way I want it to (headers work …

---

## [Logstash process killed and as a result the ingestion stopped](https://discuss.elastic.co/t/logstash-process-killed-and-as-a-result-the-ingestion-stopped/314032)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 6:59am UTC](https://discuss.elastic.co/t/logstash-process-killed-and-as-a-result-the-ingestion-stopped/314032 "2022-09-09T06:59:14Z")

</div>

Hi All, I had a perfectly fine working configuration of Logstash. I colleague of mine tried to troubleshoote and killed the Logstash process thought. After Logstash restarted the ingestion stopped and in the log file …

---

## [Logstash create plugin tutorial](https://discuss.elastic.co/t/logstash-create-plugin-tutorial/314031)

<div class="topic-metadata">

**Author:** [@Laurent\_DEGEN](https://discuss.elastic.co/u/Laurent_DEGEN)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 5:31am UTC](https://discuss.elastic.co/t/logstash-create-plugin-tutorial/314031 "2022-09-09T05:31:31Z")

</div>

Hi, I'am looking for good/updated ressources to learn how to create a codec-plugin. I have tried to follow this one : How to write a Logstash codec plugin | Logstash Reference \[8.4\] | Elastic ( I used the plugin genera…

---

## [Issue with selecting date fields from the \`jdbc\_streaming\` \`filter\` plugin](https://discuss.elastic.co/t/issue-with-selecting-date-fields-from-the-jdbc-streaming-filter-plugin/314023)

<div class="topic-metadata">

**Author:** [@nkumarcc](https://discuss.elastic.co/u/nkumarcc)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 10:39pm UTC](https://discuss.elastic.co/t/issue-with-selecting-date-fields-from-the-jdbc-streaming-filter-plugin/314023 "2022-09-08T22:39:34Z")

</div>

I have a nested field in my Elasticsearch mapping which holds an array of objects. We wanted to add this array to records via a jdbc\_streaming filter. However, 2 of the fields we query for are timestamp fields, which cau…

---

## [Logstash remove N/A field](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002)

<div class="topic-metadata">

**Author:** [@mleg](https://discuss.elastic.co/u/mleg)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 6:29pm UTC](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002 "2022-09-08T18:29:11Z")

</div>

I am trying to remove all the fields which have N/A next to the them like "toto: N/A", I am currently removing them with a enormous IF forest which I have hard coded but I would like a better alternative, to an enormous …

---

## [Redirecting stdout to /dev/null](https://discuss.elastic.co/t/redirecting-stdout-to-dev-null/313973)

<div class="topic-metadata">

**Author:** [@jatindavey](https://discuss.elastic.co/u/jatindavey)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 6:02pm UTC](https://discuss.elastic.co/t/redirecting-stdout-to-dev-null/313973 "2022-09-08T18:02:57Z")

</div>

Hi I am not sure if this has already been discussed in the forums but i could not find a definitive help in this regard. Basically when i run logstash as a systemd service , whenever logstash gets log files for process…

---

## [Logstash: filter unique key documents](https://discuss.elastic.co/t/logstash-filter-unique-key-documents/313880)

<div class="topic-metadata">

**Author:** [@Moshe\_Sharon1](https://discuss.elastic.co/u/Moshe_Sharon1)\
**Replies:** 4\
**Last updated:** [September 8, 2022, 1:08pm UTC](https://discuss.elastic.co/t/logstash-filter-unique-key-documents/313880 "2022-09-08T13:08:37Z")

</div>

Hello, We have an index which has multiple documents with the same phone number. Each document will always contain the phone number and may contain additional information (see example below) The documents are written …

---

## [Logstash delay](https://discuss.elastic.co/t/logstash-delay/313991)

<div class="topic-metadata">

**Author:** [@tom.verbeek](https://discuss.elastic.co/u/tom.verbeek)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 1:03pm UTC](https://discuss.elastic.co/t/logstash-delay/313991 "2022-09-08T13:03:31Z")

</div>

Hi, I have a problem with logs being ingested into elastic with a delay. This delay does not start from the beginning but it builds up. Right now the delay is 1 day and 10 hours. We checked the Source device sending th…

---

## [Unable to split the logs using child pipeline](https://discuss.elastic.co/t/unable-to-split-the-logs-using-child-pipeline/313944)

<div class="topic-metadata">

**Author:** [@Abinayaganesan](https://discuss.elastic.co/u/Abinayaganesan)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 5:31am UTC](https://discuss.elastic.co/t/unable-to-split-the-logs-using-child-pipeline/313944 "2022-09-08T05:31:23Z")

</div>

Hi I can get all application logs in kibana dashboard. But I want to split the logs using log.file.path and send that respective logs to child pipeline that's why I tried conditions like if (\[log\]\[file\]\[path\] == \["/var…

---

## [How load balancing work between logstash and elasticsearch](https://discuss.elastic.co/t/how-load-balancing-work-between-logstash-and-elasticsearch/313821)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 8\
**Last updated:** [September 8, 2022, 10:51am UTC](https://discuss.elastic.co/t/how-load-balancing-work-between-logstash-and-elasticsearch/313821 "2022-09-08T10:51:14Z")

</div>

Hi everyone, I have a question about logstash and how it load balances to an elasticsearch servers cluster. The warning "high disk watermark \[90%\] exceeded" is displayed in the logstash log file, and documents are no l…

---

## [JSON parse error, Could not set field 'ip' on object '\<hostname\>.\<domain\>.com' to value '10.XXX.XX.XX'.This is probably due to trying to set a field like \[foo\]\[bar\] = someValuewhen \[foo\] is not either a map or a string"](https://discuss.elastic.co/t/json-parse-error-could-not-set-field-ip-on-object-hostname-domain-com-to-value-10-xxx-xx-xx-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/313928)

<div class="topic-metadata">

**Author:** [@Enzo\_baker](https://discuss.elastic.co/u/Enzo_baker)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 9:41pm UTC](https://discuss.elastic.co/t/json-parse-error-could-not-set-field-ip-on-object-hostname-domain-com-to-value-10-xxx-xx-xx-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/313928 "2022-09-07T21:41:51Z")

</div>

Hi, Error message - JSON parse error, Could not set field 'ip' on object '\<hostname\>.\<domain\>.com' to value '10.XXX.XX.XX'.This is probably due to trying to set a field like \[foo\]\[bar\] = someValuewhen \[foo\] is not eit…

---

## [Jdbc input plugin connection pooling?](https://discuss.elastic.co/t/jdbc-input-plugin-connection-pooling/313915)

<div class="topic-metadata">

**Author:** [@steevhise](https://discuss.elastic.co/u/steevhise)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 6:50pm UTC](https://discuss.elastic.co/t/jdbc-input-plugin-connection-pooling/313915 "2022-09-07T18:50:44Z")

</div>

Is there a way to give logstash jdbc plugin several db servers (all replicas of same master) to connect to? Do you just provide an array of connection strings? or what?

---

## [JSON filter wipes out existing objects in memory](https://discuss.elastic.co/t/json-filter-wipes-out-existing-objects-in-memory/312047)

<div class="topic-metadata">

**Author:** [@juan.domenech](https://discuss.elastic.co/u/juan.domenech)\
**Replies:** 3\
**Last updated:** [September 7, 2022, 5:40pm UTC](https://discuss.elastic.co/t/json-filter-wipes-out-existing-objects-in-memory/312047 "2022-09-07T17:40:45Z")

</div>

I'd like to share this behaviour to find out whether or not is expected or desired. Problem: A field exists in memory (i.e. log.syslog.hostname:ZEUS1 ) A JSON message arrives that includes a sub-field of the existing …

---

## [ISSUE WITH INSTALATION KIBANA IN CENTOS](https://discuss.elastic.co/t/issue-with-instalation-kibana-in-centos/312451)

<div class="topic-metadata">

**Author:** [@andres07](https://discuss.elastic.co/u/andres07)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 11:59am UTC](https://discuss.elastic.co/t/issue-with-instalation-kibana-in-centos/312451 "2022-09-07T11:59:23Z")

</div>

Hi, I am trying to install Kibana on a centos server so that I can collect logs from different machines. On my server and installed kibana, elasticsearch and logstash. All these agents are working, but I am not able to…

---

## [Django syncs to ElasticSearch even when logstash container is removed?](https://discuss.elastic.co/t/django-syncs-to-elasticsearch-even-when-logstash-container-is-removed/313878)

<div class="topic-metadata">

**Author:** [@scheung38](https://discuss.elastic.co/u/scheung38)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 11:29am UTC](https://discuss.elastic.co/t/django-syncs-to-elasticsearch-even-when-logstash-container-is-removed/313878 "2022-09-07T11:29:27Z")

</div>

What is the reason behind Django data updated to Elasticsearch when logstash container is removed? Initially checked no index here - (empty) http://localhost:5601/app/management/data/index\_management/indices docker ki…

---

## [How can I dynamically create elasticsearch indices using logtsash using jdbc?](https://discuss.elastic.co/t/how-can-i-dynamically-create-elasticsearch-indices-using-logtsash-using-jdbc/313873)

<div class="topic-metadata">

**Author:** [@shantam\_saxena](https://discuss.elastic.co/u/shantam_saxena)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 10:21am UTC](https://discuss.elastic.co/t/how-can-i-dynamically-create-elasticsearch-indices-using-logtsash-using-jdbc/313873 "2022-09-07T10:21:43Z")

</div>

I have a table in snowflake for which I have a target column. The target column has 20 distinct values and will increase with time. My intention is to use logstash to create separate indices for all the unique values in …

---

## [Logstash I/O error](https://discuss.elastic.co/t/logstash-i-o-error/313858)

<div class="topic-metadata">

**Author:** [@Hardy\_Fong](https://discuss.elastic.co/u/Hardy_Fong)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 8:00am UTC](https://discuss.elastic.co/t/logstash-i-o-error/313858 "2022-09-07T08:00:51Z")

</div>

Dear all , I have one elk server collecting all decive syslog, and we found one of fibre switch(DELL DS6610B) have prompt this error in starting logstash. But the weird point is we have 3 fibre switch which are same c…

---

## [Logstash on docker does not work with auditbeat](https://discuss.elastic.co/t/logstash-on-docker-does-not-work-with-auditbeat/313657)

<div class="topic-metadata">

**Author:** [@mammodde](https://discuss.elastic.co/u/mammodde)\
**Replies:** 5\
**Last updated:** [September 7, 2022, 6:48am UTC](https://discuss.elastic.co/t/logstash-on-docker-does-not-work-with-auditbeat/313657 "2022-09-07T06:48:04Z")

</div>

Hi, I am currently trying to configure a docker with Logstash by sending there logs with auditbeat installed on my pc. The problem is that I constantly receive the same error when I do .\\auditbeat.exe setup -e Exiting: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=115)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=117)
