# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=128

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 129

---

## [Documents not getting udpated as per the pipeline](https://discuss.elastic.co/t/documents-not-getting-udpated-as-per-the-pipeline/309394)

<div class="topic-metadata">

**Author:** [@Apoorv\_Agarwal](https://discuss.elastic.co/u/Apoorv_Agarwal)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 9:29am UTC](https://discuss.elastic.co/t/documents-not-getting-udpated-as-per-the-pipeline/309394 "2022-07-12T09:29:03Z")

</div>

I am using one elapsed plugin to calculate the time difference between two events, with the output sending data into a "merged" index. For some reason, at certain times, the merged index is not getting updated in real ti…

---

## [Sudo ./logstash --path.settings /etc/logstash command is throwing error](https://discuss.elastic.co/t/sudo-logstash-path-settings-etc-logstash-command-is-throwing-error/309381)

<div class="topic-metadata">

**Author:** [@pooja5](https://discuss.elastic.co/u/pooja5)\
**Replies:** 0\
**Last updated:** [July 12, 2022, 7:14am UTC](https://discuss.elastic.co/t/sudo-logstash-path-settings-etc-logstash-command-is-throwing-error/309381 "2022-07-12T07:14:32Z")

</div>

Hello! We are trying to trigger multiple pipelines from pipelines.yml using the command sudo ./logstash --path.settings /etc/logstash However, we are facing the below errors \[ERROR\]\[logstash.agent \] Fail…

---

## [Timestamp for global target](https://discuss.elastic.co/t/timestamp-for-global-target/309358)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [July 12, 2022, 1:34am UTC](https://discuss.elastic.co/t/timestamp-for-global-target/309358 "2022-07-12T01:34:01Z")

</div>

Hi I'm facing with case that I couldn't brake the setting for timestamp for the rest of messages here my input: input { generator { lines =\> \[ "# snapshot,66472243,20220704061503", "list…

---

## [How to use logstash imap plugin to acquire data from multiple user account?](https://discuss.elastic.co/t/how-to-use-logstash-imap-plugin-to-acquire-data-from-multiple-user-account/309300)

<div class="topic-metadata">

**Author:** [@Ayush\_Gupta](https://discuss.elastic.co/u/Ayush_Gupta)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 8:47am UTC](https://discuss.elastic.co/t/how-to-use-logstash-imap-plugin-to-acquire-data-from-multiple-user-account/309300 "2022-07-11T08:47:07Z")

</div>

Hi, I am new to Elasticsearch and logstash. I am able to extract data from one user account.Now I want to extract data from multiple user accounts, plz help over this.

---

## [Get my systems with Filebeat  on them to communicate with my logstash system using Certs](https://discuss.elastic.co/t/get-my-systems-with-filebeat-on-them-to-communicate-with-my-logstash-system-using-certs/309341)

<div class="topic-metadata">

**Author:** [@timfox123](https://discuss.elastic.co/u/timfox123)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 3:55pm UTC](https://discuss.elastic.co/t/get-my-systems-with-filebeat-on-them-to-communicate-with-my-logstash-system-using-certs/309341 "2022-07-11T15:55:11Z")

</div>

Objective: To get my systems with Filebeat on them to communicate with my logstash system using Certs. License: Free Environment Elasticsearch nodes: We have 3 ES 7.17 Linux nodes that are working together just f…

---

## [Logstash not running in Remote Windows Continuously](https://discuss.elastic.co/t/logstash-not-running-in-remote-windows-continuously/309005)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 8\
**Last updated:** [July 11, 2022, 3:33pm UTC](https://discuss.elastic.co/t/logstash-not-running-in-remote-windows-continuously/309005 "2022-07-11T15:33:17Z")

</div>

I am using Logstash-7.17.4 version to index data from oracle db to Elasticsearch. When I am running through Command Prompt, it is running but when running through Task Scheduler, logstash has stopped automatically after…

---

## [Logstash Issue - export kafka messages into tsv format](https://discuss.elastic.co/t/logstash-issue-export-kafka-messages-into-tsv-format/309321)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 1\
**Last updated:** [July 11, 2022, 3:22pm UTC](https://discuss.elastic.co/t/logstash-issue-export-kafka-messages-into-tsv-format/309321 "2022-07-11T15:22:23Z")

</div>

Hi Elastic team, I am trying to export Kafka messages into tab separated file (tsv) file using below logstash configuration file......But not able to get desired output. input { kafka { bootstrap\_servers =\> "host:por…

---

## [Http\_poller logstash input plugin : socks5](https://discuss.elastic.co/t/http-poller-logstash-input-plugin-socks5/309333)

<div class="topic-metadata">

**Author:** [@toog](https://discuss.elastic.co/u/toog)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 3:16pm UTC](https://discuss.elastic.co/t/http-poller-logstash-input-plugin-socks5/309333 "2022-07-11T15:16:14Z")

</div>

I try to use http\_poller to request url but i need to use a dynamic ssh forwarding. How i can specify to http\_poller to use the socks5 proxy to resolve the url request ? i try this config but i have this message http\_…

---

## [Logstash Auto Reconnect Stomp](https://discuss.elastic.co/t/logstash-auto-reconnect-stomp/309332)

<div class="topic-metadata">

**Author:** [@tahseenjamal](https://discuss.elastic.co/u/tahseenjamal)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 2:59pm UTC](https://discuss.elastic.co/t/logstash-auto-reconnect-stomp/309332 "2022-07-11T14:59:37Z")

</div>

Am using stomp input plugin to fetch data from ActiveMQ I tested a scenario, where I stopped and then started ActiveMQ. This caused logstash to stop fetching data from ActiveMQ. This means logstash is not auto reconnect…

---

## [Logstach configuration](https://discuss.elastic.co/t/logstach-configuration/309306)

<div class="topic-metadata">

**Author:** [@escanor\_sama](https://discuss.elastic.co/u/escanor_sama)\
**Replies:** 1\
**Last updated:** [July 11, 2022, 11:19am UTC](https://discuss.elastic.co/t/logstach-configuration/309306 "2022-07-11T11:19:14Z")

</div>

Hello, Hope everyone is doing well I installed ELK on a Debian recently and I want Logstash to receive logs from another machine (windows) that is in the same network. Can I achieve that without using Filebeat? Can I …

---

## [Logstash not working, if installed in a location where the path contains parentheses (on windows)](https://discuss.elastic.co/t/logstash-not-working-if-installed-in-a-location-where-the-path-contains-parentheses-on-windows/309291)

<div class="topic-metadata">

**Author:** [@simon137](https://discuss.elastic.co/u/simon137)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 6:57am UTC](https://discuss.elastic.co/t/logstash-not-working-if-installed-in-a-location-where-the-path-contains-parentheses-on-windows/309291 "2022-07-11T06:57:03Z")

</div>

Hello together, As the title suggests, with a sample path of "C:\\ProgramData\\Test)Test\\logstash", the call to ".\\bin\\logstash.bat" fails with the message: "Test\\logstash\\jdk\\bin\\java.exe" cannot be processed syntactical…

---

## [Connecting logstash to Elasticsearch via SSL](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl/308828)

<div class="topic-metadata">

**Author:** [@dsilvera](https://discuss.elastic.co/u/dsilvera)\
**Replies:** 5\
**Last updated:** [July 10, 2022, 2:01am UTC](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl/308828 "2022-07-10T02:01:32Z")

</div>

So I have read that since v8.0 Elasticsearch has encryption turned on by default for connections from Logstash, Kabana, Beats. But I'm not finding a guide on how to setup the certificate and connect to Elasticsearch fro…

---

## [Logstash filter if internal networks](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 2\
**Last updated:** [July 9, 2022, 5:07am UTC](https://discuss.elastic.co/t/logstash-filter-if-internal-networks/309238 "2022-07-09T05:07:01Z")

</div>

This is a continuation of my previous thread which Badger kindly solved. I have sflow data coming in with the src\_ip and dst\_ip fields My internal networks are in this range and I'd like them not to be scanned for geoi…

---

## [ECS expect \`target\` value](https://discuss.elastic.co/t/ecs-expect-target-value/308652)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 8\
**Last updated:** [July 2, 2022, 12:40am UTC](https://discuss.elastic.co/t/ecs-expect-target-value/308652 "2022-07-02T00:40:54Z")

</div>

Hello boys and girls, I'm playing with logstash and sflow codec input Trying to enrich the data with geoip and get this error: \[WARN \]\[logstash.filters.geoip \]\[3\_sflow\] ECS expect \`target\` value \`destination.geo.ip\`…

---

## [If statement not work](https://discuss.elastic.co/t/if-statement-not-work/309183)

<div class="topic-metadata">

**Author:** [@david-a76](https://discuss.elastic.co/u/david-a76)\
**Replies:** 6\
**Last updated:** [July 8, 2022, 6:13pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183 "2022-07-08T18:13:32Z")

</div>

Hi all, I'm trying to import a sample json file: ... { "id": 2, "timestamp": "2019-08-11T17:55:56Z", "paymentType": "Visa", "name": "Darby Dacks", "gender": "Female", "ip\_address": "77.72.239.47", "purpos…

---

## [Logstash error "Errno::EACCES: Permission denied - NUL" when installing plugin input-syslog](https://discuss.elastic.co/t/logstash-error-errno-permission-denied-nul-when-installing-plugin-input-syslog/308523)

<div class="topic-metadata">

**Author:** [@CarlosD](https://discuss.elastic.co/u/CarlosD)\
**Replies:** 3\
**Last updated:** [July 8, 2022, 6:04pm UTC](https://discuss.elastic.co/t/logstash-error-errno-permission-denied-nul-when-installing-plugin-input-syslog/308523 "2022-07-08T18:04:39Z")

</div>

Hi, I haven't been able to install logstash-input-syslog I thought this could be solved by following this but it did not solve it I am trying this in a Windows 11 Enterprise Evaluation VM (WINDEV2204EVAL) Attaching t…

---

## [Convert json nested fields into integer](https://discuss.elastic.co/t/convert-json-nested-fields-into-integer/309167)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 7\
**Last updated:** [July 8, 2022, 4:23pm UTC](https://discuss.elastic.co/t/convert-json-nested-fields-into-integer/309167 "2022-07-08T16:23:35Z")

</div>

Hi. I am trying to convert a field read by a json filter in logstash. I am used to convert fields from other sources, but with this nested field from a json log file, I cannot convert a quoted number string to a integer. …

---

## [Grok Parsing](https://discuss.elastic.co/t/grok-parsing/309200)

<div class="topic-metadata">

**Author:** [@escanor\_sama](https://discuss.elastic.co/u/escanor_sama)\
**Replies:** 2\
**Last updated:** [July 8, 2022, 2:03pm UTC](https://discuss.elastic.co/t/grok-parsing/309200 "2022-07-08T14:03:28Z")

</div>

Hi everyone, I am having trouble when I want to parse this Fortigate Log \<189\>devname="FWFG240D" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1565130979 srcip=146.0.138.202 srcport=61103 dstip=192…

---

## [Elasticsearch Unreachable Error](https://discuss.elastic.co/t/elasticsearch-unreachable-error/309185)

<div class="topic-metadata">

**Author:** [@pooja5](https://discuss.elastic.co/u/pooja5)\
**Replies:** 1\
**Last updated:** [July 8, 2022, 11:15am UTC](https://discuss.elastic.co/t/elasticsearch-unreachable-error/309185 "2022-07-08T11:15:55Z")

</div>

Hello! We have observed a log message \[ERROR\]\[logstash.outputs.elasticsearch\]\[.monitoring-logstash\] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error\_messa…

---

## [Bad parsing json with logstash](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121)

<div class="topic-metadata">

**Author:** [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Replies:** 4\
**Last updated:** [July 7, 2022, 2:55pm UTC](https://discuss.elastic.co/t/bad-parsing-json-with-logstash/309121 "2022-07-07T14:55:39Z")

</div>

Hello, I'm having trouble with logstash json parsing. I receive several events of this type: { "ignoreSimilarity" =\> false, "message" =\> "19/04/22 19h47\\n\\nLogin:\*\*\*", "@timestamp" =\> 2022-04…

---

## [Logstash output question](https://discuss.elastic.co/t/logstash-output-question/309138)

<div class="topic-metadata">

**Author:** [@jlbai](https://discuss.elastic.co/u/jlbai)\
**Replies:** 3\
**Last updated:** [July 7, 2022, 10:25pm UTC](https://discuss.elastic.co/t/logstash-output-question/309138 "2022-07-07T22:25:25Z")

</div>

sh-4.2$ sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/firewall.conf Using bundled JDK: /usr/share/logstash/jdk OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 a…

---

## [Conexión SharePoint a logstash](https://discuss.elastic.co/t/conexion-sharepoint-a-logstash/309047)

<div class="topic-metadata">

**Author:** [@arley\_nova\_salgado](https://discuss.elastic.co/u/arley_nova_salgado)\
**Replies:** 2\
**Last updated:** [July 7, 2022, 2:18pm UTC](https://discuss.elastic.co/t/conexion-sharepoint-a-logstash/309047 "2022-07-07T14:18:36Z")

</div>

I'm trying to create an input that receives data from sharepoint, but I can't find any information on this topic. Can you help me, please.

---

## [How to resolve "Can not decode an entire message...." error in logstash while usingImap plugin?](https://discuss.elastic.co/t/how-to-resolve-can-not-decode-an-entire-message-error-in-logstash-while-usingimap-plugin/309114)

<div class="topic-metadata">

**Author:** [@Ayush\_Gupta](https://discuss.elastic.co/u/Ayush_Gupta)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 12:32pm UTC](https://discuss.elastic.co/t/how-to-resolve-can-not-decode-an-entire-message-error-in-logstash-while-usingimap-plugin/309114 "2022-07-07T12:32:19Z")

</div>

Hi, I am new to Elasticsearch and logstash when I use imap plugin "Can not decode an entire message...." error appears. I have read many posts, understood a few but still unable to get what to do to resolve these errors …

---

## [Date field is not Parsing](https://discuss.elastic.co/t/date-field-is-not-parsing/309006)

<div class="topic-metadata">

**Author:** [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)\
**Replies:** 3\
**Last updated:** [July 7, 2022, 12:14pm UTC](https://discuss.elastic.co/t/date-field-is-not-parsing/309006 "2022-07-07T12:14:43Z")

</div>

Hello Team, i have some data carrying date and this data is tagged with date data type. but sometime this filed is carrying empty body (without Date String) How can i parse for both conditions ? In the Time of Date is i…

---

## [Error while installing index templates](https://discuss.elastic.co/t/error-while-installing-index-templates/309110)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 12:11pm UTC](https://discuss.elastic.co/t/error-while-installing-index-templates/309110 "2022-07-07T12:11:30Z")

</div>

Hi guys, I am having a problem across some pipelines on logstash. Everytime i restart or start logstash i can see that it outputs an error line for some of the pipelines configured. The error is the following: Failed …

---

## [Help with logstash output](https://discuss.elastic.co/t/help-with-logstash-output/309011)

<div class="topic-metadata">

**Author:** [@PJss](https://discuss.elastic.co/u/PJss)\
**Replies:** 3\
**Last updated:** [July 7, 2022, 12:03pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011 "2022-07-07T12:03:55Z")

</div>

Hello I'm getting ELK running node in command, that i don't configure, and this string below goes to arcsight: 2022-07-04T12:50:30.046Z {name=TST-FT13} Jul 4 15:50:29 TST-FT13 sshd\[1872\]: Accepted keyboard-interactive/p…

---

## [Zabbix + Logstash = Field referenced by ... is missing](https://discuss.elastic.co/t/zabbix-logstash-field-referenced-by-is-missing/309100)

<div class="topic-metadata">

**Author:** [@voidx](https://discuss.elastic.co/u/voidx)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 10:50am UTC](https://discuss.elastic.co/t/zabbix-logstash-field-referenced-by-is-missing/309100 "2022-07-07T10:50:29Z")

</div>

I'm trying to configure sending messages from the log to Zabbix, I ran into this problem. When running Logstash, there are a bunch of errors of this type in the log \[logstash.outputs.zabbix\]\[main\]\[2ef3e6f6411863c21dc15…

---

## [Logstash filter is not working ...kindly help](https://discuss.elastic.co/t/logstash-filter-is-not-working-kindly-help/306306)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 11\
**Last updated:** [July 7, 2022, 10:20am UTC](https://discuss.elastic.co/t/logstash-filter-is-not-working-kindly-help/306306 "2022-07-07T10:20:18Z")

</div>

Hi, Need your help I've bunch of messages if kafka. few samples are given below. {"processId":40,"parentProcessId":40,"type":"Info","service":"a-b-c","object":"common\_factory","method":"listUsers","log":"Start listUs…

---

## [Format issue using http output plugin to send logs from logstash to azure eventhub](https://discuss.elastic.co/t/format-issue-using-http-output-plugin-to-send-logs-from-logstash-to-azure-eventhub/309073)

<div class="topic-metadata">

**Author:** [@Shakib\_farooq](https://discuss.elastic.co/u/Shakib_farooq)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 6:02am UTC](https://discuss.elastic.co/t/format-issue-using-http-output-plugin-to-send-logs-from-logstash-to-azure-eventhub/309073 "2022-07-07T06:02:02Z")

</div>

Hello, I am facing an issue in forwarding logs from logstash to the event hub, below is the conf file. the requirement is to forward winlog beats logs to the event hub. I am receiving logs in elastic if I kept the form…

---

## [Send an email when Logstash service is down/not running](https://discuss.elastic.co/t/send-an-email-when-logstash-service-is-down-not-running/309068)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 2\
**Last updated:** [July 7, 2022, 5:56am UTC](https://discuss.elastic.co/t/send-an-email-when-logstash-service-is-down-not-running/309068 "2022-07-07T05:56:33Z")

</div>

Hi team, I have run Logstash as a service in Remote windows. It is working fine now. But in case of failure scenario, If Logstash service shuts down unexpectedly, then I need to send(alert) an email to the team. How c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=127)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=129)
