# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=132

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 133

---

## [Received an event that has a different character encoding from DLP software](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-from-dlp-software/308004)

<div class="topic-metadata">

**Author:** [@Stevenpoot](https://discuss.elastic.co/u/Stevenpoot)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 12:11pm UTC](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-from-dlp-software/308004 "2022-06-23T12:11:08Z")

</div>

{:text=\>"\\u0000\\x FF\\u0001\\u0000\\u0000$\\u0000\\r\\u0000 \\u0000\\u001E\\u0006\\u0001\\u0006\\ u0002\\u0006\\u0003\\u0005\\u0001\\u0005\\u0002\\u0005\\u0003\\u0004\\u0001\\u0 004\\u0002\\u0004\\u0003\\u0003\\u0001\\u0003\\u0002\\u0003\\u0003\\u0002\\u…

---

## [Snmptrap for v3](https://discuss.elastic.co/t/snmptrap-for-v3/307610)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 8:32am UTC](https://discuss.elastic.co/t/snmptrap-for-v3/307610 "2022-06-23T08:32:20Z")

</div>

Hi Team, how can I enable snmptrap plugins for v3. The configuration I am going through applicable only for snmpv1 and v2. But my requirement is for v3 also. please guide me. Below is my configuration: input{ snmptra…

---

## [When outputting from logstash to elasticsearch, some data is missing](https://discuss.elastic.co/t/when-outputting-from-logstash-to-elasticsearch-some-data-is-missing/307820)

<div class="topic-metadata">

**Author:** [@sbyunnn](https://discuss.elastic.co/u/sbyunnn)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 4:59am UTC](https://discuss.elastic.co/t/when-outputting-from-logstash-to-elasticsearch-some-data-is-missing/307820 "2022-06-23T04:59:21Z")

</div>

Hi, I am building ELK Stack The output of my logstash is Elasticsearch but, some data is missing in ES However, some data is missing from ES. After removing all indexes, I can see missed data. but, the other data mis…

---

## [Sprintf on xml filter xpath](https://discuss.elastic.co/t/sprintf-on-xml-filter-xpath/307925)

<div class="topic-metadata">

**Author:** [@Factor3](https://discuss.elastic.co/u/Factor3)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 12:38am UTC](https://discuss.elastic.co/t/sprintf-on-xml-filter-xpath/307925 "2022-06-23T00:38:54Z")

</div>

Hi. Is there a way to use sprintf on the xml xpath string? I have to get the node where the value is equal to a field of the event like this but I am getting no results: xml { source =\> "\[@metadata\]\[body\]" store\_xm…

---

## [Upsert into nested field](https://discuss.elastic.co/t/upsert-into-nested-field/307289)

<div class="topic-metadata">

**Author:** [@elwdipath](https://discuss.elastic.co/u/elwdipath)\
**Replies:** 1\
**Last updated:** [June 22, 2022, 8:21pm UTC](https://discuss.elastic.co/t/upsert-into-nested-field/307289 "2022-06-22T20:21:23Z")

</div>

I'm trying to upsert (push) and object into a nested field. We have data in xml that comes in like this: \<Person\> \<id\>1234\</id\> \<name\>John Smith\</name\> \<age/\> \<position/\> \</Person\> \<addressInfo\> \<AddressID\>3424\</Addres…

---

## [Logstash tcp input CPU perfomance](https://discuss.elastic.co/t/logstash-tcp-input-cpu-perfomance/307759)

<div class="topic-metadata">

**Author:** [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Replies:** 9\
**Last updated:** [June 22, 2022, 1:49pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-cpu-perfomance/307759 "2022-06-22T13:49:26Z")

</div>

Hello, I have configured logstash using one tcp input as follows: input { #logs01 tcp { type =\> "logs" codec =\> "line" port =\> 9916 add\_field =\> { "event\_dataset" =\> "logs\_01" } } } With this co…

---

## [Grok error filter json](https://discuss.elastic.co/t/grok-error-filter-json/307352)

<div class="topic-metadata">

**Author:** [@Roshan1](https://discuss.elastic.co/u/Roshan1)\
**Replies:** 7\
**Last updated:** [June 22, 2022, 8:16am UTC](https://discuss.elastic.co/t/grok-error-filter-json/307352 "2022-06-22T08:16:58Z")

</div>

Hello Team, can you please help me with error below? Error: \[WARN \] 2022-06-16 11:02:33.814 \[\[main\]-pipeline-manager\] grok - ECS v8 support is a preview of the unreleased ECS v8, and uses the v1 patterns. When Version…

---

## [Remove\_field not working](https://discuss.elastic.co/t/remove-field-not-working/307716)

<div class="topic-metadata">

**Author:** [@Naman1](https://discuss.elastic.co/u/Naman1)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 7:59am UTC](https://discuss.elastic.co/t/remove-field-not-working/307716 "2022-06-22T07:59:01Z")

</div>

I am using remove\_field , but it is still showing that field in kibana. For eg- tags

---

## [Date time issue while sync up using Logstash from Oracle DB to Elasticsearch](https://discuss.elastic.co/t/date-time-issue-while-sync-up-using-logstash-from-oracle-db-to-elasticsearch/307824)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 4:05am UTC](https://discuss.elastic.co/t/date-time-issue-while-sync-up-using-logstash-from-oracle-db-to-elasticsearch/307824 "2022-06-22T04:05:41Z")

</div>

Hi team, I am using logstash for sync up data from Oracle Db to ElasticSearch index. I am able to sync data but the issue is : In Oracle db, I have 3 date fields. while syncing in ES index, they are storing as UTC. I…

---

## [Memcached not working](https://discuss.elastic.co/t/memcached-not-working/307822)

<div class="topic-metadata">

**Author:** [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 3:57am UTC](https://discuss.elastic.co/t/memcached-not-working/307822 "2022-06-22T03:57:26Z")

</div>

I am trying to create a pipeline using the memcached plugin, however it is not working when I create a key in the cache in dictionary format. Here's my pipeline: input { udp { port =\> 514 type =\> sy…

---

## [Regarding count lookup of newly defined fields with log stash](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814)

<div class="topic-metadata">

**Author:** [@inwoo1](https://discuss.elastic.co/u/inwoo1)\
**Replies:** 3\
**Last updated:** [June 22, 2022, 2:32am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814 "2022-06-22T02:32:04Z")

</div>

I am collecting SNMP through logstash and creating a new field forti\_fw\_sessioncount through mutate-rename function. Looking at the log, 791 cases of forti\_fw\_sessioncount came in, but only 29 cases were shown when I ch…

---

## [Logstash Startup 401 error on Windows 10](https://discuss.elastic.co/t/logstash-startup-401-error-on-windows-10/307806)

<div class="topic-metadata">

**Author:** [@AE2000](https://discuss.elastic.co/u/AE2000)\
**Replies:** 0\
**Last updated:** [June 21, 2022, 9:55pm UTC](https://discuss.elastic.co/t/logstash-startup-401-error-on-windows-10/307806 "2022-06-21T21:55:32Z")

</div>

I'm installing ELK on my windows 10 workstation and I've gone through the steps to install all three; although there was a few issues with authorization during the process, Elasticsearch and Kibana are working perfectly …

---

## [Parse JSON array with nested objects](https://discuss.elastic.co/t/parse-json-array-with-nested-objects/307770)

<div class="topic-metadata">

**Author:** [@eliz](https://discuss.elastic.co/u/eliz)\
**Replies:** 2\
**Last updated:** [June 21, 2022, 6:37pm UTC](https://discuss.elastic.co/t/parse-json-array-with-nested-objects/307770 "2022-06-21T18:37:09Z")

</div>

Hi there! I am receiving an array of nested JSON elements and I would like to build a logic capable of transforming the following input { "devices": \[ { "device": { "device\_name": "printer\_1", …

---

## [Stress testing the Logstash service](https://discuss.elastic.co/t/stress-testing-the-logstash-service/306815)

<div class="topic-metadata">

**Author:** [@olivierots](https://discuss.elastic.co/u/olivierots)\
**Replies:** 13\
**Last updated:** [June 21, 2022, 4:46pm UTC](https://discuss.elastic.co/t/stress-testing-the-logstash-service/306815 "2022-06-21T16:46:09Z")

</div>

Hello there, I wonder whether someone can help me with this I am looking at ways to load stress test the Logstash service that sits on an ec2 instance I am looking at implementing some scaling policies for our ASGs bu…

---

## [Logstash is running on only starts on 127.0.0.1:9600](https://discuss.elastic.co/t/logstash-is-running-on-only-starts-on-127-0-0-1-9600/307710)

<div class="topic-metadata">

**Author:** [@sugriv\_1605](https://discuss.elastic.co/u/sugriv_1605)\
**Replies:** 4\
**Last updated:** [June 21, 2022, 4:38pm UTC](https://discuss.elastic.co/t/logstash-is-running-on-only-starts-on-127-0-0-1-9600/307710 "2022-06-21T16:38:18Z")

</div>

Hi, My Logstash is running but the Port 9600 is not Listening.

---

## [Logstash index pattern error](https://discuss.elastic.co/t/logstash-index-pattern-error/307721)

<div class="topic-metadata">

**Author:** [@Roshan1](https://discuss.elastic.co/u/Roshan1)\
**Replies:** 1\
**Last updated:** [June 21, 2022, 4:32pm UTC](https://discuss.elastic.co/t/logstash-index-pattern-error/307721 "2022-06-21T16:32:55Z")

</div>

Hello Team, could you please advise why data view cannot be created? conf entry input { file { start\_position =\> "beginning" path =\> "/data/KONG1/mm\_bl.log" sincedb\_path =\> "/dev/null" } } filter { json { …

---

## [Logstash setting LS\_JAVA\_HOME](https://discuss.elastic.co/t/logstash-setting-ls-java-home/307538)

<div class="topic-metadata">

**Author:** [@BRosenberg](https://discuss.elastic.co/u/BRosenberg)\
**Replies:** 6\
**Last updated:** [June 21, 2022, 1:30pm UTC](https://discuss.elastic.co/t/logstash-setting-ls-java-home/307538 "2022-06-21T13:30:48Z")

</div>

Hello again! Before installing Logstash from the apt repo, I made sure java was installed and have set JAVA\_HOME and LS\_JAVA\_HOME to /usr/bin/java as well as added /usr/bin/java to my path and verified java is installed…

---

## [My array of objects has different keys, How can I chenged them to the same name?](https://discuss.elastic.co/t/my-array-of-objects-has-different-keys-how-can-i-chenged-them-to-the-same-name/307683)

<div class="topic-metadata">

**Author:** [@jvinacio](https://discuss.elastic.co/u/jvinacio)\
**Replies:** 2\
**Last updated:** [June 21, 2022, 10:53am UTC](https://discuss.elastic.co/t/my-array-of-objects-has-different-keys-how-can-i-chenged-them-to-the-same-name/307683 "2022-06-21T10:53:33Z")

</div>

Hello, I have the following array: { "by\_hour" : \[ { "hour06" : "06", "nr\_artigos06" : 0, "caixa\_aberta06" : 0, "nr\_taloes06" : 1, "vendas\_liquidas06" : 0, "service\_time06" : null }, { "nr\_taloes10" : 6, "s…

---

## [Logstash-output-azure\_event\_hub](https://discuss.elastic.co/t/logstash-output-azure-event-hub/307726)

<div class="topic-metadata">

**Author:** [@kirankatkar](https://discuss.elastic.co/u/kirankatkar)\
**Replies:** 0\
**Last updated:** [June 21, 2022, 7:22am UTC](https://discuss.elastic.co/t/logstash-output-azure-event-hub/307726 "2022-06-21T07:22:13Z")

</div>

Hello All, Here is high-level structure of our environment: Metricbeat, Winlogbeat, Syslog -\> Logstash (on-prem) -\> Azure Event Hub -\> Logstash (Azure Cloud) -\> Elasticsearch Recently I upgraded logstash to 8.2 versio…

---

## [Logstash pipeline for error logs?](https://discuss.elastic.co/t/logstash-pipeline-for-error-logs/307681)

<div class="topic-metadata">

**Author:** [@MLsuper](https://discuss.elastic.co/u/MLsuper)\
**Replies:** 5\
**Last updated:** [June 20, 2022, 6:39pm UTC](https://discuss.elastic.co/t/logstash-pipeline-for-error-logs/307681 "2022-06-20T18:39:01Z")

</div>

How can I create a logstash pipeline for logstash error logs and put it in Elasticsearch?(So I can see it in discover and see the logs from kibana/discover and analytics?

---

## [Logstash Startup issue](https://discuss.elastic.co/t/logstash-startup-issue/307639)

<div class="topic-metadata">

**Author:** [@shivani\_chittauri](https://discuss.elastic.co/u/shivani_chittauri)\
**Replies:** 7\
**Last updated:** [June 20, 2022, 5:50pm UTC](https://discuss.elastic.co/t/logstash-startup-issue/307639 "2022-06-20T17:50:32Z")

</div>

unable to start logstash, while Elasticsearch and kibana both are up and running. logtstash.conf looks like no change on any other file logstash.yml has everything commented except "pipeline.ordered: auto"

---

## [Connecting logstash to remote elasticsearch running on https with no port specified](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/307671)

<div class="topic-metadata">

**Author:** [@rajivraghu](https://discuss.elastic.co/u/rajivraghu)\
**Replies:** 2\
**Last updated:** [June 20, 2022, 5:42pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/307671 "2022-06-20T17:42:56Z")

</div>

Hello , i am running Elasticsearch on a website called Cloud IDE gitpod. Once i start the docker image on the gitpod, docker run \\ --name elasticsearch \\ --net elastic \\ -p 9200:9200 \\ -e disco…

---

## [Set IP address as index](https://discuss.elastic.co/t/set-ip-address-as-index/307642)

<div class="topic-metadata">

**Author:** [@fropa](https://discuss.elastic.co/u/fropa)\
**Replies:** 1\
**Last updated:** [June 20, 2022, 3:39pm UTC](https://discuss.elastic.co/t/set-ip-address-as-index/307642 "2022-06-20T15:39:07Z")

</div>

Hi, Can I configure logstash to set "source IP address" as index ? Is there any variable for that?

---

## [Logstash Log4j Update](https://discuss.elastic.co/t/logstash-log4j-update/307604)

<div class="topic-metadata">

**Author:** [@rishabjain1012](https://discuss.elastic.co/u/rishabjain1012)\
**Replies:** 2\
**Last updated:** [June 20, 2022, 3:35pm UTC](https://discuss.elastic.co/t/logstash-log4j-update/307604 "2022-06-20T15:35:59Z")

</div>

Hi, We are using opensource versions of logstash docker Images. Our security team found that these images contain log4j-core-2.17.0.jar which is found to be vulnerable. Can someone provide us an update as of when will…

---

## [Logstash giving error while creating template - Failed to install template Got response code '400' contacting Elasticsearch at URL](https://discuss.elastic.co/t/logstash-giving-error-while-creating-template-failed-to-install-template-got-response-code-400-contacting-elasticsearch-at-url/307677)

<div class="topic-metadata">

**Author:** [@anand\_tripathi](https://discuss.elastic.co/u/anand_tripathi)\
**Replies:** 0\
**Last updated:** [June 20, 2022, 3:14pm UTC](https://discuss.elastic.co/t/logstash-giving-error-while-creating-template-failed-to-install-template-got-response-code-400-contacting-elasticsearch-at-url/307677 "2022-06-20T15:14:10Z")

</div>

I am getting this error failed to install when specifying the template file in the logstash configuration. But the same template json is working if I create it using the Elasticsearch API. I actually don't want to create…

---

## [Use sns message value for Elasticsearch input query](https://discuss.elastic.co/t/use-sns-message-value-for-elasticsearch-input-query/307488)

<div class="topic-metadata">

**Author:** [@Laetitia\_RICHARD](https://discuss.elastic.co/u/Laetitia_RICHARD)\
**Replies:** 2\
**Last updated:** [June 20, 2022, 2:47pm UTC](https://discuss.elastic.co/t/use-sns-message-value-for-elasticsearch-input-query/307488 "2022-06-20T14:47:57Z")

</div>

Hello, Is there a way to retrieve a value from an SNS message (via an input) and pass that same value to an Elastic input ?

---

## [Unable to retrieve license information from license server](https://discuss.elastic.co/t/unable-to-retrieve-license-information-from-license-server/304766)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 5\
**Last updated:** [June 20, 2022, 2:13pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-license-information-from-license-server/304766 "2022-06-20T14:13:18Z")

</div>

Setting up a multi-node ELK 8.2 stack and hitting an issue I've not been able to sort out. The basics of Elasticsearch and Kibana are working, but Logstash doesn't want to connect to the one Elasticsearch machine I have.…

---

## [Logstash 8.x ecs.compatibility mode adds event.original](https://discuss.elastic.co/t/logstash-8-x-ecs-compatibility-mode-adds-event-original/307654)

<div class="topic-metadata">

**Author:** [@bernhard.fluehmann](https://discuss.elastic.co/u/bernhard.fluehmann)\
**Replies:** 0\
**Last updated:** [June 20, 2022, 1:05pm UTC](https://discuss.elastic.co/t/logstash-8-x-ecs-compatibility-mode-adds-event-original/307654 "2022-06-20T13:05:42Z")

</div>

As already discussed in a previous thread, logstash in ecs.compatibility mode adds the event.original field to all events. The proposed solution was to turn off ecs.compatibility. The problem is that disabling ecs.compa…

---

## [Split filter in Logstash gives NilClass error](https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498)

<div class="topic-metadata">

**Author:** [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Replies:** 2\
**Last updated:** [June 20, 2022, 7:41am UTC](https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498 "2022-06-20T07:41:25Z")

</div>

Hello, I'm trying to split JSON using the split filter in Logstash, but with no success. This data is coming straight from an API and then forwarded to the filter in Logstash. The structure of the JSON is the followi…

---

## [Send different event to multiple output plugins in same config](https://discuss.elastic.co/t/send-different-event-to-multiple-output-plugins-in-same-config/307390)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 2\
**Last updated:** [June 20, 2022, 6:45am UTC](https://discuss.elastic.co/t/send-different-event-to-multiple-output-plugins-in-same-config/307390 "2022-06-20T06:45:33Z")

</div>

Hi Team, I have one pipeline with multiple output, elasticsearch and kafka. Now, the requirement is to sent a field to elasticsearch, but while sending to kafka that field needs to drop. Here my config says input is f…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=131)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=133)
