# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=124

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 125

---

## [LEEF Input Plugin](https://discuss.elastic.co/t/leef-input-plugin/311008)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 4:44pm UTC](https://discuss.elastic.co/t/leef-input-plugin/311008 "2022-07-29T16:44:32Z")

</div>

Hello, I am looking for LEEF Input plugin for Logstash. How can I configure Logstash to consume events in LEEF format sent over syslog. Please advise. -- Thanks, Siddarth

---

## [Logstash-keystore permission denied](https://discuss.elastic.co/t/logstash-keystore-permission-denied/309426)

<div class="topic-metadata">

**Author:** [@Christer\_Palmen](https://discuss.elastic.co/u/Christer_Palmen)\
**Replies:** 2\
**Last updated:** [July 29, 2022, 1:03pm UTC](https://discuss.elastic.co/t/logstash-keystore-permission-denied/309426 "2022-07-29T13:03:13Z")

</div>

\`Hello. I´m going to install ELK for an customer, and as a start I´m setting up an test ELK with version 8.3.2 to see how it works. I am using Windows10 as the host for ELK As a start I have setup the Elasticsearch and …

---

## [Installing a logstash plugin on Elastic Cloud](https://discuss.elastic.co/t/installing-a-logstash-plugin-on-elastic-cloud/310902)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 3\
**Last updated:** [July 29, 2022, 11:49am UTC](https://discuss.elastic.co/t/installing-a-logstash-plugin-on-elastic-cloud/310902 "2022-07-29T11:49:04Z")

</div>

Hi all, I am a seasoned Elastic Stack on premise user. Recently I have been exploring the possibilities of a double run (prem / cloud) to consider the portability of our projects to the cloud solution I usually instal…

---

## [Integration with OCI logs ( Oracle cloud)](https://discuss.elastic.co/t/integration-with-oci-logs-oracle-cloud/310972)

<div class="topic-metadata">

**Author:** [@paolajuarez](https://discuss.elastic.co/u/paolajuarez)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 9:51am UTC](https://discuss.elastic.co/t/integration-with-oci-logs-oracle-cloud/310972 "2022-07-29T09:51:27Z")

</div>

How can I ingest logs from OCI to elastisearch? Any recommendation?

---

## [ConsumerConfig values with kafka input plugin](https://discuss.elastic.co/t/consumerconfig-values-with-kafka-input-plugin/310964)

<div class="topic-metadata">

**Author:** [@AlexB2](https://discuss.elastic.co/u/AlexB2)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 9:13am UTC](https://discuss.elastic.co/t/consumerconfig-values-with-kafka-input-plugin/310964 "2022-07-29T09:13:27Z")

</div>

Hi there I have a question: Is there a way to configure ConsumerConfig values for kafka input plugin I am interested in configure sasl.client.callback.handler.class There is no direct such option with kafka input pl…

---

## [Oracle Database monitoring by Elasticsearch, Logstash Pipeline](https://discuss.elastic.co/t/oracle-database-monitoring-by-elasticsearch-logstash-pipeline/310895)

<div class="topic-metadata">

**Author:** [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Replies:** 0\
**Last updated:** [July 28, 2022, 3:33pm UTC](https://discuss.elastic.co/t/oracle-database-monitoring-by-elasticsearch-logstash-pipeline/310895 "2022-07-28T15:33:39Z")

</div>

Hello Experts, I am trying to monitor Oracle Database (which is on a Linux Server) by Elasticsearch. I have created a Logstash Config file which I am running on my own machine. I have few questions; Please suggest / an…

---

## [Incoming syslog date missing in timestamp](https://discuss.elastic.co/t/incoming-syslog-date-missing-in-timestamp/310916)

<div class="topic-metadata">

**Author:** [@Giridharan\_C](https://discuss.elastic.co/u/Giridharan_C)\
**Replies:** 1\
**Last updated:** [July 28, 2022, 6:48pm UTC](https://discuss.elastic.co/t/incoming-syslog-date-missing-in-timestamp/310916 "2022-07-28T18:48:50Z")

</div>

Hi, I'm receiving Syslog from logstash pipeline and that doesn't have a date field. How can I manipulate the date using the system's current date by matching "message\_time"? "message\_time" =\> "13:51:10"

---

## [When logstash is not storing the logs it receive, what is present in pipeline of logstah?](https://discuss.elastic.co/t/when-logstash-is-not-storing-the-logs-it-receive-what-is-present-in-pipeline-of-logstah/310908)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 3\
**Last updated:** [July 28, 2022, 6:43pm UTC](https://discuss.elastic.co/t/when-logstash-is-not-storing-the-logs-it-receive-what-is-present-in-pipeline-of-logstah/310908 "2022-07-28T18:43:05Z")

</div>

When logstash is not storing the logs it receive, what is present in pipeline of logstah? I am just trying to reload the pipeline (or delete some entries) when the pipeline is full or blocked, due to the unavailability …

---

## [SNMPv3 Poller Input - Multiple hosts input](https://discuss.elastic.co/t/snmpv3-poller-input-multiple-hosts-input/310327)

<div class="topic-metadata">

**Author:** [@Giridharan\_C](https://discuss.elastic.co/u/Giridharan_C)\
**Replies:** 2\
**Last updated:** [July 28, 2022, 6:28pm UTC](https://discuss.elastic.co/t/snmpv3-poller-input-multiple-hosts-input/310327 "2022-07-28T18:28:16Z")

</div>

Hi, I want to collect logs using an SNMP input filter where logstash needs to poll the SNMP events using OIDs. I have successfully created an SNMP input filter and can fetch/poll events from one device. My question is h…

---

## [Is it possible to create a single document with an array of objects?](https://discuss.elastic.co/t/is-it-possible-to-create-a-single-document-with-an-array-of-objects/310616)

<div class="topic-metadata">

**Author:** [@Wellington\_Bezerra](https://discuss.elastic.co/u/Wellington_Bezerra)\
**Replies:** 1\
**Last updated:** [July 28, 2022, 3:09pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-single-document-with-an-array-of-objects/310616 "2022-07-28T15:09:05Z")

</div>

I'm creating a query to feed my index that has a field in common and I wanted to include all values ​​with the same field in a single document. Example SQL DATA: ID NAME CODE ACTIVE QTD PROD 181304…

---

## [Monitoring ELK](https://discuss.elastic.co/t/monitoring-elk/310887)

<div class="topic-metadata">

**Author:** [@escanor\_sama](https://discuss.elastic.co/u/escanor_sama)\
**Replies:** 0\
**Last updated:** [July 28, 2022, 2:53pm UTC](https://discuss.elastic.co/t/monitoring-elk/310887 "2022-07-28T14:53:06Z")

</div>

Hi everyone, so I installed the ELK stack 8.2 for my cluster with 11 nodes, and I want to know if there is any possibility to monitor the stack, for example if ElasticSearch or kibana shut down or something like this I w…

---

## [HTTP output plugin failed to execute](https://discuss.elastic.co/t/http-output-plugin-failed-to-execute/310878)

<div class="topic-metadata">

**Author:** [@tylersiemers](https://discuss.elastic.co/u/tylersiemers)\
**Replies:** 0\
**Last updated:** [July 28, 2022, 2:08pm UTC](https://discuss.elastic.co/t/http-output-plugin-failed-to-execute/310878 "2022-07-28T14:08:24Z")

</div>

Trying to use the http output plugin and have some basic newbie questions on the payload. I am getting these errors when trying to use the plugin. Jul 28 13:57:00 nt-logstash logstash\[335749\]: \[2022-07-28T13:57:00,180\]\[…

---

## [Unable to convert fields into DATE type in Logstash](https://discuss.elastic.co/t/unable-to-convert-fields-into-date-type-in-logstash/310830)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [July 28, 2022, 10:35am UTC](https://discuss.elastic.co/t/unable-to-convert-fields-into-date-type-in-logstash/310830 "2022-07-28T10:35:28Z")

</div>

Hello team, I am unbale to convert field into data type. Can you please help me on this. Format is coming as Text only Sample Log: CIG,CCI05\_05\_NRW\_22102020043728\_000014635.txt,26/07/2022 04:37:50,26/07/2022 04:42:12,…

---

## [Unable to integrate logstash to salesforce](https://discuss.elastic.co/t/unable-to-integrate-logstash-to-salesforce/310850)

<div class="topic-metadata">

**Author:** [@Ayaan\_Shaik](https://discuss.elastic.co/u/Ayaan_Shaik)\
**Replies:** 0\
**Last updated:** [July 28, 2022, 10:13am UTC](https://discuss.elastic.co/t/unable-to-integrate-logstash-to-salesforce/310850 "2022-07-28T10:13:21Z")

</div>

Hi, I'm Trying to integrate salesforce to the logstash for data log ingest into ELK stack, But i'm not able connect succefully to the logstash salesforce connection. I have done connected app as per elastic doc and the…

---

## [Output Logstash plugin for Azure Data Explorer (ADX) quickly running out of capacity](https://discuss.elastic.co/t/output-logstash-plugin-for-azure-data-explorer-adx-quickly-running-out-of-capacity/310599)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 1\
**Last updated:** [July 28, 2022, 9:29am UTC](https://discuss.elastic.co/t/output-logstash-plugin-for-azure-data-explorer-adx-quickly-running-out-of-capacity/310599 "2022-07-28T09:29:03Z")

</div>

Dear All, I use the ADX output plugin to send FW logs to ADX. I first tried it with a stdout{} plugin to massage the data and parse it my way and it was working fine. Now when I enabled the kusto output (That is how i…

---

## [Logstash CEF codec and ECS cannot parse 'rt' field throws an error](https://discuss.elastic.co/t/logstash-cef-codec-and-ecs-cannot-parse-rt-field-throws-an-error/310705)

<div class="topic-metadata">

**Author:** [@wii](https://discuss.elastic.co/u/wii)\
**Replies:** 2\
**Last updated:** [July 28, 2022, 8:54am UTC](https://discuss.elastic.co/t/logstash-cef-codec-and-ecs-cannot-parse-rt-field-throws-an-error/310705 "2022-07-28T08:54:29Z")

</div>

Without ECS, the 'rt' field could be parsed fine and mapped into 'deviceReceiptTime' field. But after enabling ECS in Logstash configuration it throws me an error in log ingesting. Could somebody guide me through this as…

---

## [Logstah : nonexistent lob error from jdbc plugin](https://discuss.elastic.co/t/logstah-nonexistent-lob-error-from-jdbc-plugin/310823)

<div class="topic-metadata">

**Author:** [@Venkatesan\_M](https://discuss.elastic.co/u/Venkatesan_M)\
**Replies:** 0\
**Last updated:** [July 28, 2022, 7:33am UTC](https://discuss.elastic.co/t/logstah-nonexistent-lob-error-from-jdbc-plugin/310823 "2022-07-28T07:33:52Z")

</div>

While selecting blob data from input jdbc getting nonexistent lob value error.Could you someone help me on this.

---

## [Logstash not listening port 5044 even when we configured the beats](https://discuss.elastic.co/t/logstash-not-listening-port-5044-even-when-we-configured-the-beats/310792)

<div class="topic-metadata">

**Author:** [@KALAVATHI\_YALAMANCHA](https://discuss.elastic.co/u/KALAVATHI_YALAMANCHA)\
**Replies:** 17\
**Last updated:** [July 28, 2022, 5:34am UTC](https://discuss.elastic.co/t/logstash-not-listening-port-5044-even-when-we-configured-the-beats/310792 "2022-07-28T05:34:16Z")

</div>

input { beats { type =\> beats host =\> "localhost" port =\> 5044 }

---

## [How can I check if a log file was analyzed by logstash or not?](https://discuss.elastic.co/t/how-can-i-check-if-a-log-file-was-analyzed-by-logstash-or-not/310375)

<div class="topic-metadata">

**Author:** [@maoxuguang](https://discuss.elastic.co/u/maoxuguang)\
**Replies:** 2\
**Last updated:** [July 27, 2022, 11:56pm UTC](https://discuss.elastic.co/t/how-can-i-check-if-a-log-file-was-analyzed-by-logstash-or-not/310375 "2022-07-27T23:56:28Z")

</div>

I found one of my log is missing in elasticsearch， how can I know if logstash analyzed it or not? or how can I know what problem logstah meet? In logstash-plain.log the information is limited, there is no information a…

---

## [Connect Logstash to SQL by jdbc with AD Account](https://discuss.elastic.co/t/connect-logstash-to-sql-by-jdbc-with-ad-account/310631)

<div class="topic-metadata">

**Author:** [@Oriya](https://discuss.elastic.co/u/Oriya)\
**Replies:** 4\
**Last updated:** [July 27, 2022, 6:34pm UTC](https://discuss.elastic.co/t/connect-logstash-to-sql-by-jdbc-with-ad-account/310631 "2022-07-27T18:34:30Z")

</div>

Hi, we have a new environment with 1 logstash server and 3 node servers. in the logstash i have just only one pipeline that i configured with jdbc to connect to sql server. this is the Input configuration pipeline : i…

---

## [Output jdbc data inserts](https://discuss.elastic.co/t/output-jdbc-data-inserts/310780)

<div class="topic-metadata">

**Author:** [@Calvete](https://discuss.elastic.co/u/Calvete)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 5:33pm UTC](https://discuss.elastic.co/t/output-jdbc-data-inserts/310780 "2022-07-27T17:33:16Z")

</div>

Hello, my input is a file in s3 and I am making insections to an amazon aurora postgresq database. The time is not good to insert more than 1 million records, it takes 1 hour and a half. Help me pipeline: batch: siz…

---

## [Issue while configuring metricbeat in logstash version 7.16.3](https://discuss.elastic.co/t/issue-while-configuring-metricbeat-in-logstash-version-7-16-3/310677)

<div class="topic-metadata">

**Author:** [@Subhanwita\_Mullick](https://discuss.elastic.co/u/Subhanwita_Mullick)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 6:24pm UTC](https://discuss.elastic.co/t/issue-while-configuring-metricbeat-in-logstash-version-7-16-3/310677 "2022-07-26T18:24:02Z")

</div>

Hello, I am migrating the logstash to version 7.16.3 from 7.9.3. But there is some error while updating the metricbeat in logstash. Error: Class org.jruby.RubyFloat cannot be cast to class Java.lang.double PFA the scr…

---

## [Aggregate exception occurred {:ERROR=\>#\<NoMethodERROR: undefined method \`-' for nil:NilClass\>](https://discuss.elastic.co/t/aggregate-exception-occurred-error-nomethoderror-undefined-method-for-nil-nilclass/308435)

<div class="topic-metadata">

**Author:** [@The-morpho](https://discuss.elastic.co/u/The-morpho)\
**Replies:** 6\
**Last updated:** [July 27, 2022, 8:13am UTC](https://discuss.elastic.co/t/aggregate-exception-occurred-error-nomethoderror-undefined-method-for-nil-nilclass/308435 "2022-07-27T08:13:39Z")

</div>

Hello, I'm new with elastic, I'm working with logs, I want to process from them a new fields based on aggregation. This the my configuration file input { beats { port =\> 5044 } } filter { json { source =\>…

---

## [How to separate objects inside an array of objects?](https://discuss.elastic.co/t/how-to-separate-objects-inside-an-array-of-objects/310274)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 6:56pm UTC](https://discuss.elastic.co/t/how-to-separate-objects-inside-an-array-of-objects/310274 "2022-07-26T18:56:51Z")

</div>

Hi, I still new to ELK and I have been trying to process data that come to me as json file. The json file looks lie this. \[ { "user": "Beta", "percent": 28, "startTime": "2022-07-07T11:31:45", "type": "CPU",…

---

## [After creating new config file and run it copy also old config file data in newly created index](https://discuss.elastic.co/t/after-creating-new-config-file-and-run-it-copy-also-old-config-file-data-in-newly-created-index/310669)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 4:54pm UTC](https://discuss.elastic.co/t/after-creating-new-config-file-and-run-it-copy-also-old-config-file-data-in-newly-created-index/310669 "2022-07-26T16:54:38Z")

</div>

Initially i have created c10.conf file it store csv data in recordv2 index it is working fine. After that i have created new configuration file gmrtant.conf to read multiple csv file to read new data which is different t…

---

## [Looukps with memcahed or tanslate filter](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650)

<div class="topic-metadata">

**Author:** [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Replies:** 1\
**Last updated:** [July 26, 2022, 2:43pm UTC](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650 "2022-07-26T14:43:39Z")

</div>

Hi, I am doubt about lookups. Recently I implemented a pipeline using the filter plugin Memcached, but the Memcached plugin does not work well with json values. I needed to do this for work: memcached { hosts =\>…

---

## [Logstash-output-cloudwatchlogs](https://discuss.elastic.co/t/logstash-output-cloudwatchlogs/310653)

<div class="topic-metadata">

**Author:** [@jlbai](https://discuss.elastic.co/u/jlbai)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 2:20pm UTC](https://discuss.elastic.co/t/logstash-output-cloudwatchlogs/310653 "2022-07-26T14:20:53Z")

</div>

I am looking to get logs out our network devices, firewalls, aruba controllers, switches etc. I am looking at using the output plugin for cloud watch logs GitHub - amazon-archives/logstash-output-cloudwatchlogs: A logsta…

---

## [Make elasticsearch aggregation response shorter](https://discuss.elastic.co/t/make-elasticsearch-aggregation-response-shorter/310254)

<div class="topic-metadata">

**Author:** [@Akshay\_Kulkarni](https://discuss.elastic.co/u/Akshay_Kulkarni)\
**Replies:** 9\
**Last updated:** [July 26, 2022, 12:22pm UTC](https://discuss.elastic.co/t/make-elasticsearch-aggregation-response-shorter/310254 "2022-07-26T12:22:03Z")

</div>

Hi, I am dealing with elasticsearch aggregation response json like below. { "took": 2, "timed\_out": false, "\_shards": { "total": 1, "successful": 1, "skipped": 0, "failed": 0 }, "hits": { …

---

## [Multiple filebeat log with logstash not working](https://discuss.elastic.co/t/multiple-filebeat-log-with-logstash-not-working/310472)

<div class="topic-metadata">

**Author:** [@sazzad114](https://discuss.elastic.co/u/sazzad114)\
**Replies:** 4\
**Last updated:** [July 26, 2022, 12:15pm UTC](https://discuss.elastic.co/t/multiple-filebeat-log-with-logstash-not-working/310472 "2022-07-26T12:15:55Z")

</div>

filebeat.input: - type: log enabled: true paths: - /var/log/nginx/\*log tags: \["server-log"\] fields: {log\_type: Server-log} - type: log enabled: true paths: - /var/www/laravel/storage/logs/\*.log tags…

---

## [How does Logstash determine that a field matches a string regularly？](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586)

<div class="topic-metadata">

**Author:** [@wentao\_Xiong](https://discuss.elastic.co/u/wentao_Xiong)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 9:16am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586 "2022-07-26T09:16:30Z")

</div>

I am a newcomer to ELK, and now I encounter a problem as shown in the title: How does Logstash determine that a field matches a string regularly? such as whether the \[path\] field contains the "err" string? (the path fie…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=123)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=125)
