# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=131

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 132

---

## [Logstash shuts down in Remote Windows](https://discuss.elastic.co/t/logstash-shuts-down-in-remote-windows/308332)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 4\
**Last updated:** [June 28, 2022, 10:49am UTC](https://discuss.elastic.co/t/logstash-shuts-down-in-remote-windows/308332 "2022-06-28T10:49:36Z")

</div>

Hi Team, I am using Logstash tool to sync(transfer) Oracle DB data to ElasticSearch index. I am running Logstash as a windows service in a Remote Windows server machine. I have run Logstash on Friday(24-6-2022 around …

---

## [Ecs compatibiliy warning in logstash](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263)

<div class="topic-metadata">

**Author:** [@NomanLatif](https://discuss.elastic.co/u/NomanLatif)\
**Replies:** 3\
**Last updated:** [June 28, 2022, 7:53am UTC](https://discuss.elastic.co/t/ecs-compatibiliy-warning-in-logstash/308263 "2022-06-28T07:53:14Z")

</div>

We see the following warning in logstash logs \[2022-06-27T12:23:27,848\]\[WARN \]\[deprecation.logstash.codecs.json\]\[my\_pipeline\] Relying on default value of pipeline.ecs\_compatibility, which may change in a future major re…

---

## [Logstash shutdown alert](https://discuss.elastic.co/t/logstash-shutdown-alert/308232)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 2\
**Last updated:** [June 28, 2022, 2:55am UTC](https://discuss.elastic.co/t/logstash-shutdown-alert/308232 "2022-06-28T02:55:40Z")

</div>

Hi Team, I am using Logstash 7.17.4 for transferring Oracle DB data to ElasticSearch index. Logstash is running perfectly as a windows service(Running on Remote Windows machine) and syncing also happening perfectly. M…

---

## [How multiple logstash nodes read the same file without duplicate data?](https://discuss.elastic.co/t/how-multiple-logstash-nodes-read-the-same-file-without-duplicate-data/308285)

<div class="topic-metadata">

**Author:** [@Thuy\_Le1](https://discuss.elastic.co/u/Thuy_Le1)\
**Replies:** 1\
**Last updated:** [June 27, 2022, 6:41pm UTC](https://discuss.elastic.co/t/how-multiple-logstash-nodes-read-the-same-file-without-duplicate-data/308285 "2022-06-27T18:41:07Z")

</div>

I have multiple files, and multiple logstash nodes. how to setup multiple logstash nodes read the same file without duplicate data

---

## [How to change the value of environment variable in logstash?](https://discuss.elastic.co/t/how-to-change-the-value-of-environment-variable-in-logstash/308283)

<div class="topic-metadata">

**Author:** [@Thuy\_Le1](https://discuss.elastic.co/u/Thuy_Le1)\
**Replies:** 1\
**Last updated:** [June 27, 2022, 6:38pm UTC](https://discuss.elastic.co/t/how-to-change-the-value-of-environment-variable-in-logstash/308283 "2022-06-27T18:38:27Z")

</div>

How to change the value of environment variable in logstash? ruby { code =\> "ENV\[test\] = 1000" } =\> doesnot work

---

## [Logstash HA](https://discuss.elastic.co/t/logstash-ha/307946)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 3\
**Last updated:** [June 27, 2022, 3:58pm UTC](https://discuss.elastic.co/t/logstash-ha/307946 "2022-06-27T15:58:29Z")

</div>

Hi Team, I am using logstash component for collecting/transforming data and then send to pubsubLite. Now there are cases to collect data using push mechanism (other sources are pushing data to logstash component) as wel…

---

## [Single execution of logstash pipeline on demand](https://discuss.elastic.co/t/single-execution-of-logstash-pipeline-on-demand/306769)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 5\
**Last updated:** [June 27, 2022, 3:57pm UTC](https://discuss.elastic.co/t/single-execution-of-logstash-pipeline-on-demand/306769 "2022-06-27T15:57:01Z")

</div>

Hello, i have a logstash 8.2 instance running with multiple scheduled pipelines. What is the best way to start another logstash pipeline on demand for a single execution on the same logstash instance without restarting…

---

## [How to invoke oracle DB Package and store the cursor in the Elastic cache](https://discuss.elastic.co/t/how-to-invoke-oracle-db-package-and-store-the-cursor-in-the-elastic-cache/308257)

<div class="topic-metadata">

**Author:** [@umesh\_choudary](https://discuss.elastic.co/u/umesh_choudary)\
**Replies:** 0\
**Last updated:** [June 27, 2022, 1:24pm UTC](https://discuss.elastic.co/t/how-to-invoke-oracle-db-package-and-store-the-cursor-in-the-elastic-cache/308257 "2022-06-27T13:24:39Z")

</div>

HI, we have requirement to invoke a Oracle DB function which is created in the package. and it returns a cursor object. we need to store the cursor object into Elastic cache. invoking the function using statement filep…

---

## [Separate device in logstash based on the destination port](https://discuss.elastic.co/t/separate-device-in-logstash-based-on-the-destination-port/308235)

<div class="topic-metadata">

**Author:** [@abd\_sh](https://discuss.elastic.co/u/abd_sh)\
**Replies:** 0\
**Last updated:** [June 27, 2022, 10:44am UTC](https://discuss.elastic.co/t/separate-device-in-logstash-based-on-the-destination-port/308235 "2022-06-27T10:44:02Z")

</div>

Hello, i hope you are doing well. i am trying to separate device in logstash based on the destination port. i am using the below config file "input { udp { port =\> 5014} udp { port =\> 5015 } } filter { if port =…

---

## [Logstash Split input and save new event.original](https://discuss.elastic.co/t/logstash-split-input-and-save-new-event-original/308222)

<div class="topic-metadata">

**Author:** [@Gosborne](https://discuss.elastic.co/u/Gosborne)\
**Replies:** 0\
**Last updated:** [June 27, 2022, 9:11am UTC](https://discuss.elastic.co/t/logstash-split-input-and-save-new-event-original/308222 "2022-06-27T09:11:52Z")

</div>

Good Morning, I am trying to split up some JSON logs that are collected from an Eventhub and i'm running into a few issues. My logstash filter below works fine and splits the json based on a field called records, and t…

---

## [Run Python script continuously from Logstash](https://discuss.elastic.co/t/run-python-script-continuously-from-logstash/307656)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 4\
**Last updated:** [June 27, 2022, 5:12am UTC](https://discuss.elastic.co/t/run-python-script-continuously-from-logstash/307656 "2022-06-27T05:12:04Z")

</div>

Hi Team, My requirement is to run python script in background from logstash, and the output I need to take as event in logstash how to achieve that. Note: I am using exec input plugins, which eventually is not sending …

---

## [ERROR: Could not find or load main class](https://discuss.elastic.co/t/error-could-not-find-or-load-main-class/306297)

<div class="topic-metadata">

**Author:** [@Wan\_Nur\_Athirah\_Wan](https://discuss.elastic.co/u/Wan_Nur_Athirah_Wan)\
**Replies:** 13\
**Last updated:** [June 27, 2022, 4:30am UTC](https://discuss.elastic.co/t/error-could-not-find-or-load-main-class/306297 "2022-06-27T04:30:35Z")

</div>

Hai. I have a problem regarding Logstash start. Before this when i use Logstash for ingestion, everything works well. but now, the Logstash seems having problem with java where the error as followed: I already have …

---

## [Got response code '403' contacting Elasticsearch at URL 'http://localhost:9200/](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067)

<div class="topic-metadata">

**Author:** [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Replies:** 2\
**Last updated:** [June 27, 2022, 4:04am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url-http-localhost-9200/308067 "2022-06-27T04:04:38Z")

</div>

Hi, My pipeline not working with ouput elasticsearch, I created user and role like this: root@logserver:/home/g0004830# curl -k -u admin:my\_password -XGET "http://localhost:9200/\_security/user/syslog?pretty" { "sysl…

---

## [How to write remote hostname to output file with logstash](https://discuss.elastic.co/t/how-to-write-remote-hostname-to-output-file-with-logstash/308161)

<div class="topic-metadata">

**Author:** [@Yunus\_Dal](https://discuss.elastic.co/u/Yunus_Dal)\
**Replies:** 2\
**Last updated:** [June 25, 2022, 2:03pm UTC](https://discuss.elastic.co/t/how-to-write-remote-hostname-to-output-file-with-logstash/308161 "2022-06-25T14:03:32Z")

</div>

Hi, I have java application which is running at 2 instance and collect logs from these instances. I want to create output log file so far as remote hostname. my logstash config; input { tcp { codec =\> json …

---

## [How to take input from kafka avro consumer](https://discuss.elastic.co/t/how-to-take-input-from-kafka-avro-consumer/308150)

<div class="topic-metadata">

**Author:** [@saurabhlam](https://discuss.elastic.co/u/saurabhlam)\
**Replies:** 0\
**Last updated:** [June 25, 2022, 5:55am UTC](https://discuss.elastic.co/t/how-to-take-input-from-kafka-avro-consumer/308150 "2022-06-25T05:55:49Z")

</div>

Hi Currently I have defined kafka as input in logstash but I want to take input from kafka avro consumer (avro-console-consumer) . Below is my current config input { kafka { bootstrap\_servers =\> "kafka:9092" topics…

---

## [How to implement Keep alive in logstash using JDBC input](https://discuss.elastic.co/t/how-to-implement-keep-alive-in-logstash-using-jdbc-input/308140)

<div class="topic-metadata">

**Author:** [@Oskr](https://discuss.elastic.co/u/Oskr)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 7:30pm UTC](https://discuss.elastic.co/t/how-to-implement-keep-alive-in-logstash-using-jdbc-input/308140 "2022-06-24T19:30:26Z")

</div>

Hello Team, I have a question about a bug in my environment, I am using logstash to extract data from the oracle database, our logstash is running on AWS the sql takes 100 sec to run on average, but at some times of the…

---

## [SunCertPathBuilderException in Logstash Running Elasticsearch in Docker](https://discuss.elastic.co/t/suncertpathbuilderexception-in-logstash-running-elasticsearch-in-docker/308054)

<div class="topic-metadata">

**Author:** [@jhop](https://discuss.elastic.co/u/jhop)\
**Replies:** 7\
**Last updated:** [June 24, 2022, 7:00pm UTC](https://discuss.elastic.co/t/suncertpathbuilderexception-in-logstash-running-elasticsearch-in-docker/308054 "2022-06-24T19:00:02Z")

</div>

I am running Elasticsearch in docker. I am trying to hit port 5044 from my browser (or from anywhere). My error is as follows: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certificat…

---

## [SNMP Input - Stop Table Polling at Specific Table OID](https://discuss.elastic.co/t/snmp-input-stop-table-polling-at-specific-table-oid/308134)

<div class="topic-metadata">

**Author:** [@bennrtc](https://discuss.elastic.co/u/bennrtc)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 4:54pm UTC](https://discuss.elastic.co/t/snmp-input-stop-table-polling-at-specific-table-oid/308134 "2022-06-24T16:54:54Z")

</div>

I'm using Logstash to query a network device that has a large number of interfaces (nearly 1500). I'm interested in a variety of interface metrics that are stored in different tables. I only need the metrics from the f…

---

## [How to add a 0 before a field, with a condicion?](https://discuss.elastic.co/t/how-to-add-a-0-before-a-field-with-a-condicion/308106)

<div class="topic-metadata">

**Author:** [@jvinacio](https://discuss.elastic.co/u/jvinacio)\
**Replies:** 1\
**Last updated:** [June 24, 2022, 3:52pm UTC](https://discuss.elastic.co/t/how-to-add-a-0-before-a-field-with-a-condicion/308106 "2022-06-24T15:52:34Z")

</div>

Hello! I have different docs with different hours from 0 to 23 like the following { "date" : "2022-06-23", "eventDate" : "2022", "StoreID" : 190, "hour" : 0, "PosID" : 12, "tempo" : 0.0 } { "date" : "2022-06-2…

---

## [Logstash filter for filtering out specific words from message](https://discuss.elastic.co/t/logstash-filter-for-filtering-out-specific-words-from-message/307853)

<div class="topic-metadata">

**Author:** [@Muhammed\_Danish](https://discuss.elastic.co/u/Muhammed_Danish)\
**Replies:** 6\
**Last updated:** [June 24, 2022, 3:42pm UTC](https://discuss.elastic.co/t/logstash-filter-for-filtering-out-specific-words-from-message/307853 "2022-06-24T15:42:10Z")

</div>

Hello team, I am looking for a filter to filter out based on the words in a log message. For example, Log messages - This is a test message from server hosted in AWS and This is a test message coming from server hoste…

---

## [Grok filter some entries have additional fields](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092)

<div class="topic-metadata">

**Author:** [@tartaarsap](https://discuss.elastic.co/u/tartaarsap)\
**Replies:** 2\
**Last updated:** [June 24, 2022, 1:55pm UTC](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092 "2022-06-24T13:55:46Z")

</div>

I have the following dataset: 1613766382 FILE %computerName% MACB \[4096\] c:/$MFTMirr 1613766382 FILE %computerName% MACB \[4096\] c:/$MFTMirr ($FILE\_NAME) I am trying to build a GROK filter to match on both lines. Howe…

---

## [Logstash JSON File input](https://discuss.elastic.co/t/logstash-json-file-input/308108)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 11:39am UTC](https://discuss.elastic.co/t/logstash-json-file-input/308108 "2022-06-24T11:39:47Z")

</div>

Hi Team, Please help me to set logstash config from nested json input file. My json file look like below: \[ { "billing\_account\_id": "loma", "InvoiceMonth": "123456", "credits": \[ { "name": "abc", "amount": ,0.0…

---

## [Mutate - Geopoint - Copy Field](https://discuss.elastic.co/t/mutate-geopoint-copy-field/308095)

<div class="topic-metadata">

**Author:** [@shubham184](https://discuss.elastic.co/u/shubham184)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 9:37am UTC](https://discuss.elastic.co/t/mutate-geopoint-copy-field/308095 "2022-06-24T09:37:21Z")

</div>

I need to convert 2 Fields (doc.geoLat and doc.geoLong) to geopoint datatype. I tried the following but it dosen't work Could you please show me where I might be making a mistake if \[type\] == \\"xxxxx\\" { …

---

## [Parse json in the filed message](https://discuss.elastic.co/t/parse-json-in-the-filed-message/308079)

<div class="topic-metadata">

**Author:** [@Rustam\_Kulnazarov](https://discuss.elastic.co/u/Rustam_Kulnazarov)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 6:44am UTC](https://discuss.elastic.co/t/parse-json-in-the-filed-message/308079 "2022-06-24T06:44:24Z")

</div>

Hello everyone! Tell me please, how can I parse json in the field message, if the message has: 2022-06-24 12:35:53 # {json structure}\\n text text\\n text

---

## [Struggling to replace a string in a syslog message with sub](https://discuss.elastic.co/t/struggling-to-replace-a-string-in-a-syslog-message-with-sub/307809)

<div class="topic-metadata">

**Author:** [@ddaloia](https://discuss.elastic.co/u/ddaloia)\
**Replies:** 4\
**Last updated:** [June 23, 2022, 10:36pm UTC](https://discuss.elastic.co/t/struggling-to-replace-a-string-in-a-syslog-message-with-sub/307809 "2022-06-23T22:36:45Z")

</div>

Hi Friends. I am taking in cef syslog messages from an application called Secret Server. The messages are not parsing correctly because some of the fields usernames have a slash in the username. The format is domain\\user…

---

## [How can I create new field inside an array of obejcts?](https://discuss.elastic.co/t/how-can-i-create-new-field-inside-an-array-of-obejcts/308036)

<div class="topic-metadata">

**Author:** [@jvinacio](https://discuss.elastic.co/u/jvinacio)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 5:42pm UTC](https://discuss.elastic.co/t/how-can-i-create-new-field-inside-an-array-of-obejcts/308036 "2022-06-23T17:42:28Z")

</div>

Hello! I have the following array: { "tempoTotalDayEvents" : \[ { "tempo7" : 25.0 }, { "tempo8" : 0.0 }, { "tempo11" : 0.0 }, { "tempo12" : 6.0 }, { "tempo13" : 0.0 }, { "tempo14" : 3.0 }, { "tempo1…

---

## [Codec in gelf input plugin not working](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017)

<div class="topic-metadata">

**Author:** [@smtp\_server](https://discuss.elastic.co/u/smtp_server)\
**Replies:** 5\
**Last updated:** [June 23, 2022, 3:37pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017 "2022-06-23T15:37:03Z")

</div>

I'm trying to use codec for logs coming from gelf driver of another container to aggregate multiline logs but they are turning into events for each line in message, So multiline is not working at all. input{ gelf{ …

---

## [Logstash http\_poller input body](https://discuss.elastic.co/t/logstash-http-poller-input-body/308034)

<div class="topic-metadata">

**Author:** [@mfrg85](https://discuss.elastic.co/u/mfrg85)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 3:15pm UTC](https://discuss.elastic.co/t/logstash-http-poller-input-body/308034 "2022-06-23T15:15:15Z")

</div>

I'm trying to POST to an external API that requires authorization headers and a query. Here is the configuration that I have so far and the error that I am receiving. I'm not sure if the body portion of the config is for…

---

## [Deprecation.logstash.codecs.plain](https://discuss.elastic.co/t/deprecation-logstash-codecs-plain/308005)

<div class="topic-metadata">

**Author:** [@Stevenpoot](https://discuss.elastic.co/u/Stevenpoot)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 1:59pm UTC](https://discuss.elastic.co/t/deprecation-logstash-codecs-plain/308005 "2022-06-23T13:59:23Z")

</div>

How do I solve this. Logstash is working but the message is repeating all the time \[deprecation.logstash.codecs.plain\] Relying on default value of pipeline.ecs\_compatibility, which may change in a future maj or release …

---

## [Logstash parse multiline logging](https://discuss.elastic.co/t/logstash-parse-multiline-logging/307995)

<div class="topic-metadata">

**Author:** [@Ceesz](https://discuss.elastic.co/u/Ceesz)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 12:36pm UTC](https://discuss.elastic.co/t/logstash-parse-multiline-logging/307995 "2022-06-23T12:36:43Z")

</div>

Hi all, I am trying to parse the following log file with multi-log lines: Benutzerkennung: test1 Uhrzeit: 20:53:54 14.05.2022 Version: Microsoft Dynamics AX 6.2 (Erstellungsnummer 3000.5768) Datenbank: Microsoft SQL Se…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=130)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=132)
