# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=122

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 123

---

## [Does logstash support mips?](https://discuss.elastic.co/t/does-logstash-support-mips/311709)

<div class="topic-metadata">

**Author:** [@xsky](https://discuss.elastic.co/u/xsky)\
**Replies:** 0\
**Last updated:** [August 9, 2022, 10:16am UTC](https://discuss.elastic.co/t/does-logstash-support-mips/311709 "2022-08-09T10:16:21Z")

</div>

logstash versoin: 7.17.5 java version: OpenJDK 11.0.15 cpu: mips64el I use the logstash-7.17.5-linux-aarch64.tar.gz installation package, replace the jdk directory in logstash with mips jdk, and start logstahs, the …

---

## [Logstash-8.3.3 (latest) still using jackson-databind-2.9.10.8](https://discuss.elastic.co/t/logstash-8-3-3-latest-still-using-jackson-databind-2-9-10-8/311694)

<div class="topic-metadata">

**Author:** [@shivani\_aggarwal](https://discuss.elastic.co/u/shivani_aggarwal)\
**Replies:** 0\
**Last updated:** [August 9, 2022, 8:12am UTC](https://discuss.elastic.co/t/logstash-8-3-3-latest-still-using-jackson-databind-2-9-10-8/311694 "2022-08-09T08:12:06Z")

</div>

As per logstash 8.3.0 release notes , Jackson and jackson-databind have been updated to 2.13.3 #13945 But we see the logstash rpm also brings a plugin logstash-input-beats - that still uses jackson-databind-2.9.10.8. …

---

## [Control the log flow from Logstash](https://discuss.elastic.co/t/control-the-log-flow-from-logstash/311691)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 0\
**Last updated:** [August 9, 2022, 7:51am UTC](https://discuss.elastic.co/t/control-the-log-flow-from-logstash/311691 "2022-08-09T07:51:12Z")

</div>

Hi Team, We are frequently facing logs lagging in Kibana due to other application team while doing performance testing and also they are sending a bulk data at a time. In that scenario, that would be taking too much ti…

---

## [Logstash, ES connection error](https://discuss.elastic.co/t/logstash-es-connection-error/311683)

<div class="topic-metadata">

**Author:** [@hellocomputer](https://discuss.elastic.co/u/hellocomputer)\
**Replies:** 3\
**Last updated:** [August 9, 2022, 3:45am UTC](https://discuss.elastic.co/t/logstash-es-connection-error/311683 "2022-08-09T03:45:02Z")

</div>

Hello I used ubuntu20.04 version and ELK stack 8.3.2 version. Then, I's working in connecting with logstash and ES. 2022-08-09T02:14:45,699\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\] Failed to perform request {:me…

---

## [How to prevent Logstash file input duplicate reading with rotating log?](https://discuss.elastic.co/t/how-to-prevent-logstash-file-input-duplicate-reading-with-rotating-log/311264)

<div class="topic-metadata">

**Author:** [@kent010341](https://discuss.elastic.co/u/kent010341)\
**Replies:** 14\
**Last updated:** [August 9, 2022, 3:14am UTC](https://discuss.elastic.co/t/how-to-prevent-logstash-file-input-duplicate-reading-with-rotating-log/311264 "2022-08-09T03:14:01Z")

</div>

I have a system that keeps writing logs (with log4j) and it will rotate and compress to a .gz file when the log file reaches 100 MB. I use Logstash file input plugin to read those log files, and there are several compre…

---

## [OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC](https://discuss.elastic.co/t/openjdk-64-bit-server-vm-warning-option-useconcmarksweepgc/311661)

<div class="topic-metadata">

**Author:** [@bezder](https://discuss.elastic.co/u/bezder)\
**Replies:** 1\
**Last updated:** [August 8, 2022, 5:42pm UTC](https://discuss.elastic.co/t/openjdk-64-bit-server-vm-warning-option-useconcmarksweepgc/311661 "2022-08-08T17:42:24Z")

</div>

hello, any idea how to get rid of that warning? OpenJDK 64-Bit Server VM warning: .... thanks root@universe-new:/home/heap# sudo -u logstash /usr/share/logstash/bin/logstash --path.settings /etc/logstash -t Using bun…

---

## [Trailing Whitespaces in Message Field](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574)

<div class="topic-metadata">

**Author:** [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Replies:** 16\
**Last updated:** [August 8, 2022, 4:31pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574 "2022-08-08T16:31:36Z")

</div>

Here is my sample data: EventQ 00001350 Fri 08/05 20:19:20.541 \_00008\_ 39765 990 HEARTBEAT SYSTEM=\>MDETMGR i"SINGLETON" //beep// added to EventQueue for a new total of 1 Pending Event This is one line and Ela…

---

## [Your settings are invalid. Reason: Cloud Id, after decoding, is invalid. Format: '\<segment1\>$\<segment2\>$\<segment3\>'. Received: ""](https://discuss.elastic.co/t/your-settings-are-invalid-reason-cloud-id-after-decoding-is-invalid-format-segment1-segment2-segment3-received/311331)

<div class="topic-metadata">

**Author:** [@Reset](https://discuss.elastic.co/u/Reset)\
**Replies:** 1\
**Last updated:** [August 8, 2022, 3:16pm UTC](https://discuss.elastic.co/t/your-settings-are-invalid-reason-cloud-id-after-decoding-is-invalid-format-segment1-segment2-segment3-received/311331 "2022-08-08T15:16:26Z")

</div>

Hello, Been struggling with this issue for a few days. Not sure what's going on. Here's the command executed: root@machine:/home/devops# /usr/share/logstash/bin/logstash --config.debug --log.level=debug --path.settings…

---

## [Add data according to JSON file](https://discuss.elastic.co/t/add-data-according-to-json-file/311630)

<div class="topic-metadata">

**Author:** [@mehmetalix](https://discuss.elastic.co/u/mehmetalix)\
**Replies:** 0\
**Last updated:** [August 8, 2022, 7:39am UTC](https://discuss.elastic.co/t/add-data-according-to-json-file/311630 "2022-08-08T07:39:49Z")

</div>

Hi, I'm ingesting data from database and trying to create new field and ingest data according to a JSON file. Let me give an example: I have field named 'type' and data in this field as 'cat', 'dog', 'flower'. Also ha…

---

## [Convert String to date and compare it](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 9\
**Last updated:** [August 7, 2022, 4:41pm UTC](https://discuss.elastic.co/t/convert-string-to-date-and-compare-it/311394 "2022-08-07T16:41:14Z")

</div>

Hi, I have two fields and I want to compare it field1: 20220720091723 field2: 07/20/22 09:17 I want to compare it so i don't know if i should convert to date then compare and how or can someone please tell me what i …

---

## [Logstash showing error when executed from python but executes from terminal](https://discuss.elastic.co/t/logstash-showing-error-when-executed-from-python-but-executes-from-terminal/311508)

<div class="topic-metadata">

**Author:** [@Morning\_Star](https://discuss.elastic.co/u/Morning_Star)\
**Replies:** 4\
**Last updated:** [August 6, 2022, 6:15am UTC](https://discuss.elastic.co/t/logstash-showing-error-when-executed-from-python-but-executes-from-terminal/311508 "2022-08-06T06:15:49Z")

</div>

I'm new to ELK stack and any help would be appriciated I have tried both os and subprocess both are giving same error This is getting executed from terminal \` /usr/share/logstash/bin/logstash -f /root/folder1/folder…

---

## [Aggregated Logs and Reformatting for QRADAR](https://discuss.elastic.co/t/aggregated-logs-and-reformatting-for-qradar/311557)

<div class="topic-metadata">

**Author:** [@ombit](https://discuss.elastic.co/u/ombit)\
**Replies:** 1\
**Last updated:** [August 6, 2022, 5:28am UTC](https://discuss.elastic.co/t/aggregated-logs-and-reformatting-for-qradar/311557 "2022-08-06T05:28:03Z")

</div>

Hi all, I'm currently researching logstash (along with filebeat) as a possible solution for a problem we're seeing. We currently have a log server that is acting as a central manager, with a bunch of different Linux an…

---

## [Logstash port 5044 is not listening after logstash Installation](https://discuss.elastic.co/t/logstash-port-5044-is-not-listening-after-logstash-installation/311472)

<div class="topic-metadata">

**Author:** [@Nilesh1997](https://discuss.elastic.co/u/Nilesh1997)\
**Replies:** 2\
**Last updated:** [August 6, 2022, 4:56am UTC](https://discuss.elastic.co/t/logstash-port-5044-is-not-listening-after-logstash-installation/311472 "2022-08-06T04:56:52Z")

</div>

Dear all, I would like to receive log from remote server through file beat .However I find the port 5044 is not listening but status of logstash is active and enable. I did all the configuration needed for logstash.any …

---

## [Issue with gsub and regex not affecting the resulting strings](https://discuss.elastic.co/t/issue-with-gsub-and-regex-not-affecting-the-resulting-strings/311570)

<div class="topic-metadata">

**Author:** [@I\_need\_an\_adult](https://discuss.elastic.co/u/I_need_an_adult)\
**Replies:** 4\
**Last updated:** [August 5, 2022, 8:45pm UTC](https://discuss.elastic.co/t/issue-with-gsub-and-regex-not-affecting-the-resulting-strings/311570 "2022-08-05T20:45:23Z")

</div>

Hello, I'm attempting to remove specific items of a return string so that I have accurate aggregated filetypes within elasticsearch. The general format of the TrID output is this: 34.2% (.DLL) Win32 Dynamic Link Librar…

---

## [Repeat field extraction and aggregation](https://discuss.elastic.co/t/repeat-field-extraction-and-aggregation/311558)

<div class="topic-metadata">

**Author:** [@RitzMak](https://discuss.elastic.co/u/RitzMak)\
**Replies:** 6\
**Last updated:** [August 5, 2022, 7:49pm UTC](https://discuss.elastic.co/t/repeat-field-extraction-and-aggregation/311558 "2022-08-05T19:49:17Z")

</div>

Hello All, I have some logs as below and I would like to get a total of all CACHE\_TIMING and DATABASE\_TIMING fields. I am thinking to create an array of these fields using gsub replacement and kv filter and then add the…

---

## [Logstash filter verifier - daemon mode in Docker](https://discuss.elastic.co/t/logstash-filter-verifier-daemon-mode-in-docker/311556)

<div class="topic-metadata">

**Author:** [@rilcy](https://discuss.elastic.co/u/rilcy)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 3:54pm UTC](https://discuss.elastic.co/t/logstash-filter-verifier-daemon-mode-in-docker/311556 "2022-08-05T15:54:05Z")

</div>

Hi everyone, I use this great project from Magnus Bäck GitHub - magnusbaeck/logstash-filter-verifier to validate my Logstash filters in a Gitlab CI. It runs the version 1.6.3 in a Docker container to validate filters f…

---

## [Enforcing events to be outputted in order](https://discuss.elastic.co/t/enforcing-events-to-be-outputted-in-order/311552)

<div class="topic-metadata">

**Author:** [@ebram96](https://discuss.elastic.co/u/ebram96)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 3:27pm UTC](https://discuss.elastic.co/t/enforcing-events-to-be-outputted-in-order/311552 "2022-08-05T15:27:07Z")

</div>

I've a pipeline like this: input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/logstash-core/lib/jars/postgresql-42.2.6.jar" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_connection\_string =\> "$…

---

## [How can i extract timestamp from my log in logstash](https://discuss.elastic.co/t/how-can-i-extract-timestamp-from-my-log-in-logstash/311484)

<div class="topic-metadata">

**Author:** [@Akumar22](https://discuss.elastic.co/u/Akumar22)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 2:41pm UTC](https://discuss.elastic.co/t/how-can-i-extract-timestamp-from-my-log-in-logstash/311484 "2022-08-05T14:41:59Z")

</div>

Below is the format of my logs 05-08-2022 13:20:13,468 INFO \[stdout\] (151\_bYD2+EULzJ\_SLR\_124219\_-\_mymailfc@mailinator.com) Subject: Products Offer exceeded threshold limit of 10% I want to extract the timestamp from t…

---

## [Can I use conditionals inside json {} filter?](https://discuss.elastic.co/t/can-i-use-conditionals-inside-json-filter/311547)

<div class="topic-metadata">

**Author:** [@mfloris](https://discuss.elastic.co/u/mfloris)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 2:40pm UTC](https://discuss.elastic.co/t/can-i-use-conditionals-inside-json-filter/311547 "2022-08-05T14:40:07Z")

</div>

My input does not always contain some fields and I want to parse it accordingly, like this: filter { json { source =\> "message" if "thisField" in \[message\] { add\_field =\> { "MyField" =\> "%{\[message\]\[this…

---

## [Compare fields value](https://discuss.elastic.co/t/compare-fields-value/311387)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 2\
**Last updated:** [August 5, 2022, 2:12pm UTC](https://discuss.elastic.co/t/compare-fields-value/311387 "2022-08-05T14:12:53Z")

</div>

Hi, I would like if it is possible how to compare this value of two fields field1 : 123456XXXXXX1234 field2 : 1234567890001234 I mean i want to do if first 6 chars and last 4 chars of field1 are similar to field2 the…

---

## [Compare two fields with different documents](https://discuss.elastic.co/t/compare-two-fields-with-different-documents/311529)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 5\
**Last updated:** [August 5, 2022, 1:59pm UTC](https://discuss.elastic.co/t/compare-two-fields-with-different-documents/311529 "2022-08-05T13:59:45Z")

</div>

Hi, I want to compare two fields but not in the same document is that possible ? for example : if date.document1 == date.document2 and x.document1 == y.document2 { #DO somthing } Any help would be sincerely appre…

---

## [Is there a "stop" instruction in the block that skips to the next block?](https://discuss.elastic.co/t/is-there-a-stop-instruction-in-the-block-that-skips-to-the-next-block/311511)

<div class="topic-metadata">

**Author:** [@mfloris](https://discuss.elastic.co/u/mfloris)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 12:31pm UTC](https://discuss.elastic.co/t/is-there-a-stop-instruction-in-the-block-that-skips-to-the-next-block/311511 "2022-08-05T12:31:59Z")

</div>

I want to split my filter block into separate files for better readability and easier maintenance and of course by doing that I cannot if-else through the various checks meaning that every input will go through all the f…

---

## [S3 Output malformed JSON](https://discuss.elastic.co/t/s3-output-malformed-json/311495)

<div class="topic-metadata">

**Author:** [@Giridharan\_C](https://discuss.elastic.co/u/Giridharan_C)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 9:07am UTC](https://discuss.elastic.co/t/s3-output-malformed-json/311495 "2022-08-05T09:07:36Z")

</div>

I am using some grok filter to parse the Syslog from TCP input and store them into S3. What I'm seeing is some malformed JSON. Some syslog events are good and some are not (Multiple events are grouping together as a sing…

---

## [Logstash http input plugin, 429 busy and max\_pending\_requests](https://discuss.elastic.co/t/logstash-http-input-plugin-429-busy-and-max-pending-requests/311462)

<div class="topic-metadata">

**Author:** [@dorth](https://discuss.elastic.co/u/dorth)\
**Replies:** 0\
**Last updated:** [August 4, 2022, 10:20pm UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-429-busy-and-max-pending-requests/311462 "2022-08-04T22:20:42Z")

</div>

I am using the Logstash Http Input Plugin to receive logging data from an API Gateway (Apigee) and then send it into various S3 buckets. There are 6 Logstash nodes (m5.large 2 CPU/8 GB) sitting behind an AWS Application…

---

## [If Condition in JSON filter](https://discuss.elastic.co/t/if-condition-in-json-filter/311456)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 5\
**Last updated:** [August 4, 2022, 8:10pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456 "2022-08-04T20:10:15Z")

</div>

Hello, I am ingesting JSON data to logstash, and I am using JSON filter. In the JSON data, when the KEY is either Value 1 or Value 2, I should add a field, and if this key is missing in the logs, I will have to drop it…

---

## [Prune Plugin error](https://discuss.elastic.co/t/prune-plugin-error/311323)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 4\
**Last updated:** [August 4, 2022, 6:09pm UTC](https://discuss.elastic.co/t/prune-plugin-error/311323 "2022-08-04T18:09:50Z")

</div>

Hello, I am trying to use Prune filter to parse the data because the data format is foo:bar, but I am unsuccessful. I am getting the below error. The configuration is working without the prune filter. Please advise on …

---

## [Pattern to extract specific integer and string](https://discuss.elastic.co/t/pattern-to-extract-specific-integer-and-string/311332)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 6\
**Last updated:** [August 4, 2022, 3:57pm UTC](https://discuss.elastic.co/t/pattern-to-extract-specific-integer-and-string/311332 "2022-08-04T15:57:59Z")

</div>

Input: CEES:1.0|NGINX|NGINX|1.17.6|400|devTime=03/Aug Output response\_code: 400 message: devTime=03/Aug Pattern i have applied ^LEEF.\*\\|%{INT:response\_code}%{GREEDYDATA:log\_message Output i got response\_code: 400 …

---

## [Logstash filling up my space inside/var/log/messages file](https://discuss.elastic.co/t/logstash-filling-up-my-space-inside-var-log-messages-file/311415)

<div class="topic-metadata">

**Author:** [@zanoob](https://discuss.elastic.co/u/zanoob)\
**Replies:** 1\
**Last updated:** [August 4, 2022, 1:06pm UTC](https://discuss.elastic.co/t/logstash-filling-up-my-space-inside-var-log-messages-file/311415 "2022-08-04T13:06:39Z")

</div>

Hello all, I been tying to find a solution for this since long. Trying to reach out to the community. The logstash is filling up the file /var/log/messages file space, I understand logstash does not log to /var/log/me…

---

## [If condition in logstash output doesn't work](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276)

<div class="topic-metadata">

**Author:** [@zzcpower](https://discuss.elastic.co/u/zzcpower)\
**Replies:** 8\
**Last updated:** [August 4, 2022, 11:05am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276 "2022-08-04T11:05:58Z")

</div>

The config file is shown as below input { kafka { bootstrap\_servers =\> "localhost:9092" group\_id =\> "log\_monitor" auto\_offset\_reset =\> "latest" consumer\_threads =\> 1 topics =\> \["test\_log"\] } } f…

---

## [Logstash filter condition not working some times](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722)

<div class="topic-metadata">

**Author:** [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Replies:** 6\
**Last updated:** [August 4, 2022, 6:31am UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722 "2022-08-04T06:31:29Z")

</div>

Hello, I have following logstash configuration file for winlogbeat events: input { #Winlgobeat beats { port =\> 5044 } } filter { #Filter winlogbeat events mutate { rename =\> { "…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=121)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=123)
