# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=129

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 130

---

## [Http input logstash I want filter logs](https://discuss.elastic.co/t/http-input-logstash-i-want-filter-logs/307724)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 1\
**Last updated:** [July 6, 2022, 11:37pm UTC](https://discuss.elastic.co/t/http-input-logstash-i-want-filter-logs/307724 "2022-07-06T23:37:12Z")

</div>

Hello Everyone I am using http input plugin in logstash I want to filter only POST request from Perticular URL logs should be input and output to elasticsearch how can I achive this.

---

## [Error while starting logstash 8.3.1](https://discuss.elastic.co/t/error-while-starting-logstash-8-3-1/308811)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 2\
**Last updated:** [July 6, 2022, 10:01pm UTC](https://discuss.elastic.co/t/error-while-starting-logstash-8-3-1/308811 "2022-07-06T22:01:21Z")

</div>

Hello guys, Recently i upgraded my logstash instance from 7.x to 8.3.1. But now when i try to start the logstash service, i get the following log: \[ERROR\]\[logstash.runner \] Logging configuration uses Script …

---

## [Logstash isn't starting. Getting a FATAL error](https://discuss.elastic.co/t/logstash-isnt-starting-getting-a-fatal-error/309045)

<div class="topic-metadata">

**Author:** [@kakkarsachin7](https://discuss.elastic.co/u/kakkarsachin7)\
**Replies:** 6\
**Last updated:** [July 6, 2022, 8:40pm UTC](https://discuss.elastic.co/t/logstash-isnt-starting-getting-a-fatal-error/309045 "2022-07-06T20:40:00Z")

</div>

I am new to ELK stack. I am able to start Elasticsearch and Kibana but unable to start Logstash using command logstash -f logstash-studio.conf Version 7.14 Java Version 1.8 Here are the logs:- Using JAVA\_HOME defined…

---

## [Read the value from a file for a variable being used in elasticsearch plugin in input of logstash config file](https://discuss.elastic.co/t/read-the-value-from-a-file-for-a-variable-being-used-in-elasticsearch-plugin-in-input-of-logstash-config-file/309033)

<div class="topic-metadata">

**Author:** [@pooja5](https://discuss.elastic.co/u/pooja5)\
**Replies:** 1\
**Last updated:** [July 6, 2022, 4:35pm UTC](https://discuss.elastic.co/t/read-the-value-from-a-file-for-a-variable-being-used-in-elasticsearch-plugin-in-input-of-logstash-config-file/309033 "2022-07-06T16:35:15Z")

</div>

Hello! We are working on a use case where we are trying to read delta load from an elasticsearch index using the elasticsearch plugin in the logstash configuration file. We are using this elasticsearch plugin in the in…

---

## [Insert epoch time as "date" field, without converting to ISO8601 format](https://discuss.elastic.co/t/insert-epoch-time-as-date-field-without-converting-to-iso8601-format/309029)

<div class="topic-metadata">

**Author:** [@Elie](https://discuss.elastic.co/u/Elie)\
**Replies:** 1\
**Last updated:** [July 6, 2022, 4:32pm UTC](https://discuss.elastic.co/t/insert-epoch-time-as-date-field-without-converting-to-iso8601-format/309029 "2022-07-06T16:32:09Z")

</div>

Hello, I have an epoch time in the data that I am trying to parse via Logstash that I am trying to insert in a field in ES that represents the type "date". However, if i try to insert it just as it is, ES will assume th…

---

## [Problem with the stream log filebeat to logstash](https://discuss.elastic.co/t/problem-with-the-stream-log-filebeat-to-logstash/309007)

<div class="topic-metadata">

**Author:** [@AnotherGuy](https://discuss.elastic.co/u/AnotherGuy)\
**Replies:** 1\
**Last updated:** [July 6, 2022, 12:30pm UTC](https://discuss.elastic.co/t/problem-with-the-stream-log-filebeat-to-logstash/309007 "2022-07-06T12:30:09Z")

</div>

Okay ... I'm done i don't know how to resolv my problem with the stream log. I do the all step on the i modif my filebeat.yml like that: filebeat.inputs: - type: log enabled: true paths: - /home/epnp/epnp-d…

---

## [Nested json field mutate string to number](https://discuss.elastic.co/t/nested-json-field-mutate-string-to-number/308991)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [July 6, 2022, 8:32am UTC](https://discuss.elastic.co/t/nested-json-field-mutate-string-to-number/308991 "2022-07-06T08:32:03Z")

</div>

Hello, I'm trying to convert a nested json field from a string to an integer. But i am not getting field into Integer. field Name: events.data.custom\_attributes.txn\_total\_time\_to\_complete\_in\_sec Code: mutate {con…

---

## [Tweaking pipeline performance](https://discuss.elastic.co/t/tweaking-pipeline-performance/308801)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 1\
**Last updated:** [July 6, 2022, 4:48am UTC](https://discuss.elastic.co/t/tweaking-pipeline-performance/308801 "2022-07-06T04:48:52Z")

</div>

Hello, I'm trying to get the hang off tweaking logstashs performance. I searched the net but unfortunately, I can't seem to find a good guide on how to tweak and actually measure the performance of a pipeline. I can't …

---

## [Compound DSL Querys on Logstash template](https://discuss.elastic.co/t/compound-dsl-querys-on-logstash-template/308965)

<div class="topic-metadata">

**Author:** [@jubilla073](https://discuss.elastic.co/u/jubilla073)\
**Replies:** 0\
**Last updated:** [July 6, 2022, 1:31am UTC](https://discuss.elastic.co/t/compound-dsl-querys-on-logstash-template/308965 "2022-07-06T01:31:14Z")

</div>

Hi guys, Today, i working to include query's templates into my logstash pipelines. In this use case, i need search by two factors, an especific field and only get last X hours (around 6 hours). For this, i wrote a Compo…

---

## [Test field type with ruby filter and rename the field](https://discuss.elastic.co/t/test-field-type-with-ruby-filter-and-rename-the-field/308831)

<div class="topic-metadata">

**Author:** [@austin0918](https://discuss.elastic.co/u/austin0918)\
**Replies:** 4\
**Last updated:** [July 6, 2022, 1:03am UTC](https://discuss.elastic.co/t/test-field-type-with-ruby-filter-and-rename-the-field/308831 "2022-07-06T01:03:10Z")

</div>

I have a field "identity" that is mapped as a keyword, but some logs received have the field as an object. How do I rename the field? I tried the below config but got a syntax error, unexpected tCONSTANT. Please advise. …

---

## [Logstash parsing @timestamp even before the filter is triggered](https://discuss.elastic.co/t/logstash-parsing-timestamp-even-before-the-filter-is-triggered/308700)

<div class="topic-metadata">

**Author:** [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Replies:** 2\
**Last updated:** [July 5, 2022, 5:09pm UTC](https://discuss.elastic.co/t/logstash-parsing-timestamp-even-before-the-filter-is-triggered/308700 "2022-07-05T17:09:31Z")

</div>

Hi, We are noticing that logstash is parsing the @timestamp field even before the filter{} is triggered and this is causing the warning Error parsing @timestamp string value and spamming our logs We push logs from flue…

---

## [Logstash parsing XML failing on second and subsequent records](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905)

<div class="topic-metadata">

**Author:** [@Gerrard](https://discuss.elastic.co/u/Gerrard)\
**Replies:** 2\
**Last updated:** [July 5, 2022, 2:54pm UTC](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905 "2022-07-05T14:54:55Z")

</div>

Hi, I'm struggling to understand why logstash is unable to process any records beyond the first in my XML log file. The first record is parsed fine, but then any following ones get the "\_xmlparsefailure" tag. My log fil…

---

## [Logstash 'file\_chunk\_size'](https://discuss.elastic.co/t/logstash-file-chunk-size/308659)

<div class="topic-metadata">

**Author:** [@ChinigamiHunter](https://discuss.elastic.co/u/ChinigamiHunter)\
**Replies:** 3\
**Last updated:** [July 5, 2022, 2:23pm UTC](https://discuss.elastic.co/t/logstash-file-chunk-size/308659 "2022-07-05T14:23:06Z")

</div>

hi all, i have some files in a folder and i want to index them in Elasticsearch using logstash. some of the files are indexed, but i get a lot of this error i don't know why : \[2022-06-30T16:15:24,966\]\[INFO \]\[filewatc…

---

## [Send only one field in pipeline to pipeline communication](https://discuss.elastic.co/t/send-only-one-field-in-pipeline-to-pipeline-communication/308002)

<div class="topic-metadata">

**Author:** [@Laetitia\_RICHARD](https://discuss.elastic.co/u/Laetitia_RICHARD)\
**Replies:** 9\
**Last updated:** [July 5, 2022, 2:17pm UTC](https://discuss.elastic.co/t/send-only-one-field-in-pipeline-to-pipeline-communication/308002 "2022-07-05T14:17:08Z")

</div>

Hello, I'd like my 1st pipeline to send the event to an Elasticsearch output and only a field's event to the input of a 2nd pipeline. Is it possible to send only one field in a pipeline and not a complete event?

---

## [Regarding if else condition for grok filter](https://discuss.elastic.co/t/regarding-if-else-condition-for-grok-filter/308863)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 5\
**Last updated:** [July 5, 2022, 2:11pm UTC](https://discuss.elastic.co/t/regarding-if-else-condition-for-grok-filter/308863 "2022-07-05T14:11:39Z")

</div>

Hi @sudhagar\_ramesh @Badger I have 1 date field in my oracle db. If the date field value is empty then I am getting grokparsefailure error as I am doing grok on that value. I need to put 1 condition like if date is nil…

---

## [How to stop logstash using default address when using pipeline](https://discuss.elastic.co/t/how-to-stop-logstash-using-default-address-when-using-pipeline/308922)

<div class="topic-metadata">

**Author:** [@michael.rhys](https://discuss.elastic.co/u/michael.rhys)\
**Replies:** 0\
**Last updated:** [July 5, 2022, 2:00pm UTC](https://discuss.elastic.co/t/how-to-stop-logstash-using-default-address-when-using-pipeline/308922 "2022-07-05T14:00:06Z")

</div>

I am configuring logstash inside kubernetes using the pipeline and it is connecting to my central elk stack fine. However not only is it connecting to the ELK Host I specify it is repeatedly trying to contact http://ela…

---

## [Sending data to Logstash TCP](https://discuss.elastic.co/t/sending-data-to-logstash-tcp/308879)

<div class="topic-metadata">

**Author:** [@Johnnyboi](https://discuss.elastic.co/u/Johnnyboi)\
**Replies:** 0\
**Last updated:** [July 5, 2022, 9:15am UTC](https://discuss.elastic.co/t/sending-data-to-logstash-tcp/308879 "2022-07-05T09:15:51Z")

</div>

So I have logstash configured like this: input: tcp { port =\> 5401 } output: stdout { codec =\> rubydebug } When I try to connect to the port via browser, I can see the connection incoming in logstash lo…

---

## [Index not appearing in kibana via logstash](https://discuss.elastic.co/t/index-not-appearing-in-kibana-via-logstash/308178)

<div class="topic-metadata">

**Author:** [@bhatiac](https://discuss.elastic.co/u/bhatiac)\
**Replies:** 7\
**Last updated:** [July 5, 2022, 6:27am UTC](https://discuss.elastic.co/t/index-not-appearing-in-kibana-via-logstash/308178 "2022-07-05T06:27:31Z")

</div>

Hello, I am new to ELK, trying to read my application logs and wishing to show it on kibana dashboard for analysis purposes. Elasticsearch, kibana and logstash instances are up and running. While trying to see the newly…

---

## [Remove Special character from message before sending to json filter](https://discuss.elastic.co/t/remove-special-character-from-message-before-sending-to-json-filter/308434)

<div class="topic-metadata">

**Author:** [@Basel](https://discuss.elastic.co/u/Basel)\
**Replies:** 4\
**Last updated:** [July 5, 2022, 8:10am UTC](https://discuss.elastic.co/t/remove-special-character-from-message-before-sending-to-json-filter/308434 "2022-07-05T08:10:46Z")

</div>

Hi, we are using ELK with Apigee to send the transaction logs, the logstash configuration is as recommended by the community as below: input { tcp { port =\> 8080 type =\> syslog } } filter { m…

---

## [Logstash include filter](https://discuss.elastic.co/t/logstash-include-filter/308853)

<div class="topic-metadata">

**Author:** [@tharunkumar](https://discuss.elastic.co/u/tharunkumar)\
**Replies:** 2\
**Last updated:** [July 5, 2022, 7:02am UTC](https://discuss.elastic.co/t/logstash-include-filter/308853 "2022-07-05T07:02:34Z")

</div>

Hi i need to send the logs of particular lines to logstash .i have tried by using include filter is not working .can u provide me the solution Eg: 2022-06-30 00:00:07 10.32.13.12 POST /maruvayaparpaidhee-cug/MF/Mfajax…

---

## [My Logstash Docker container cannot start normally, please help me analyze it](https://discuss.elastic.co/t/my-logstash-docker-container-cannot-start-normally-please-help-me-analyze-it/308778)

<div class="topic-metadata">

**Author:** [@ahong](https://discuss.elastic.co/u/ahong)\
**Replies:** 5\
**Last updated:** [July 5, 2022, 12:35am UTC](https://discuss.elastic.co/t/my-logstash-docker-container-cannot-start-normally-please-help-me-analyze-it/308778 "2022-07-05T00:35:24Z")

</div>

I deployed ELK in the Docker container (version 8.2.3), but the Docker container wouldn't start when logStash was configured. The log error is as follows: {"log":"\[2022-07-04T03:29:27,007\]\[INFO \]\[logstash.javapipeline …

---

## [Curl command as streaming](https://discuss.elastic.co/t/curl-command-as-streaming/308838)

<div class="topic-metadata">

**Author:** [@Didi\_Sisi](https://discuss.elastic.co/u/Didi_Sisi)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 11:38pm UTC](https://discuss.elastic.co/t/curl-command-as-streaming/308838 "2022-07-04T23:38:46Z")

</div>

Hello ; I want to use twitter streaming api V2. because the twitter plugin of logstash is not working with twitter api 2. I decided to use curl commands. I defined the rules. like this: curl --location --request POST …

---

## [Logstash MySQL pakcet too large exception](https://discuss.elastic.co/t/logstash-mysql-pakcet-too-large-exception/308541)

<div class="topic-metadata">

**Author:** [@Simone1](https://discuss.elastic.co/u/Simone1)\
**Replies:** 3\
**Last updated:** [July 4, 2022, 7:41pm UTC](https://discuss.elastic.co/t/logstash-mysql-pakcet-too-large-exception/308541 "2022-07-04T19:41:50Z")

</div>

I'm trying to retreive data from a remote MySQL Server through the 22 port and i receive this error: \[ERROR\] 2022-06-29 15:21:37.081 \[\[main\]\<jdbc\] jdbc - Unable to connect to database. Tried 0 times {:error\_message=\>"Ja…

---

## [Regarding grok Date Time](https://discuss.elastic.co/t/regarding-grok-date-time/308636)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 2\
**Last updated:** [July 4, 2022, 3:54pm UTC](https://discuss.elastic.co/t/regarding-grok-date-time/308636 "2022-07-04T15:54:30Z")

</div>

In my oracle DB, I have with timestamp like this: "createdDate" =\> 2022-04-02T17:00:44.339Z But in my elasticsearch index, having createdDate as "createdDate": "2022-04-02T17:00:44Z" How can we change the format in Log…

---

## [Could not index event to Elasticsearch - no write index is defined for alias](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-no-write-index-is-defined-for-alias/308783)

<div class="topic-metadata">

**Author:** [@teesr5](https://discuss.elastic.co/u/teesr5)\
**Replies:** 1\
**Last updated:** [July 4, 2022, 1:15pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-no-write-index-is-defined-for-alias/308783 "2022-07-04T13:15:31Z")

</div>

Hi guys, we are facing an issue on our ELK infrastructure: \[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"logstash-rollover…

---

## [Help with "\_grokparsefailure" and "\_geoip\_lookup\_failure"](https://discuss.elastic.co/t/help-with-grokparsefailure-and-geoip-lookup-failure/308702)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 5\
**Last updated:** [July 4, 2022, 3:22am UTC](https://discuss.elastic.co/t/help-with-grokparsefailure-and-geoip-lookup-failure/308702 "2022-07-04T03:22:31Z")

</div>

I am getting those error tags. Here is my filter section from my logstash section (Note that I started to get the \_grokparsefailure after adding the second grok with the src match, it was working fine with just the top g…

---

## [Does auto reload cause Logstash to restart ingestion from beginning](https://discuss.elastic.co/t/does-auto-reload-cause-logstash-to-restart-ingestion-from-beginning/308756)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 1\
**Last updated:** [July 3, 2022, 6:19pm UTC](https://discuss.elastic.co/t/does-auto-reload-cause-logstash-to-restart-ingestion-from-beginning/308756 "2022-07-03T18:19:33Z")

</div>

I am using the Elasticsearch input plugin to move a very large number of logs from one cluster to another. Logstash has been running for about 72 hours now and is pretty sluggish. I was thinking of adding a 2nd Elasti…

---

## ["Your settings are invalid. Setting "" doesnt exist" error during setup](https://discuss.elastic.co/t/your-settings-are-invalid-setting-doesnt-exist-error-during-setup/308751)

<div class="topic-metadata">

**Author:** [@dsilvera](https://discuss.elastic.co/u/dsilvera)\
**Replies:** 2\
**Last updated:** [July 3, 2022, 6:04pm UTC](https://discuss.elastic.co/t/your-settings-are-invalid-setting-doesnt-exist-error-during-setup/308751 "2022-07-03T18:04:00Z")

</div>

Setting up ELK 8.3.1 on Windows 10 PC and got Elastic Search and Kabana up and running. Reached to setting up logstash, entered the following command: .\\bin\\logstash.bat -e "input { stdin { } } output { stdout {} }" f…

---

## [Logstash XML xpath function like PHP $father-\>children()](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 3\
**Last updated:** [July 3, 2022, 7:28am UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719 "2022-07-03T07:28:08Z")

</div>

I'm searching if in logstash exist a xpath function like the one in PHP to get the child of a node without knowing the name. Thanks to everyone

---

## [I am having problem with logstash](https://discuss.elastic.co/t/i-am-having-problem-with-logstash/308712)

<div class="topic-metadata">

**Author:** [@CodeRed](https://discuss.elastic.co/u/CodeRed)\
**Replies:** 1\
**Last updated:** [July 2, 2022, 12:09pm UTC](https://discuss.elastic.co/t/i-am-having-problem-with-logstash/308712 "2022-07-02T12:09:44Z")

</div>

after i did add xpack.security.enabled :true to elasticserach.yml file then i set password but i was not able to restart logstash anymore this is what i see in logstash's log file Attempted to resurrect connection to d…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=128)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=130)
