# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=133

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 134

---

## [Import all table from sqlserver to elasticsearch](https://discuss.elastic.co/t/import-all-table-from-sqlserver-to-elasticsearch/307516)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR](https://discuss.elastic.co/u/Khadija_BOUDINAR)\
**Replies:** 1\
**Last updated:** [June 20, 2022, 5:41am UTC](https://discuss.elastic.co/t/import-all-table-from-sqlserver-to-elasticsearch/307516 "2022-06-20T05:41:54Z")

</div>

Can i imported my database with all tables sqlserver to Elasticsearch ?

---

## [Merge data neflow and snmp, see description ports in neflow](https://discuss.elastic.co/t/merge-data-neflow-and-snmp-see-description-ports-in-neflow/305580)

<div class="topic-metadata">

**Author:** [@dreshme](https://discuss.elastic.co/u/dreshme)\
**Replies:** 1\
**Last updated:** [June 19, 2022, 11:26am UTC](https://discuss.elastic.co/t/merge-data-neflow-and-snmp-see-description-ports-in-neflow/305580 "2022-06-19T11:26:57Z")

</div>

Hello I use ELK 7.17. I get data from filebeat netflow and snmp plugin. I don't know, how i can combine information about interfaces.ifAlias and interfaces.index received from snmp plugin and netflow.egress\_interface…

---

## [Logsstash and apache kafka](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559)

<div class="topic-metadata">

**Author:** [@Henk\_Stobbe](https://discuss.elastic.co/u/Henk_Stobbe)\
**Replies:** 3\
**Last updated:** [June 18, 2022, 3:53pm UTC](https://discuss.elastic.co/t/logsstash-and-apache-kafka/307559 "2022-06-18T15:53:03Z")

</div>

hello, Newbee so maybe strange question. In my enviroments Kafka is used and the main reason for this is the ability to temporaly queue data. This functionality is (now) available in logstash. So simple question, can …

---

## [JDBC Streaming with list parameter](https://discuss.elastic.co/t/jdbc-streaming-with-list-parameter/307546)

<div class="topic-metadata">

**Author:** [@gaurav\_vivek](https://discuss.elastic.co/u/gaurav_vivek)\
**Replies:** 0\
**Last updated:** [June 17, 2022, 8:43pm UTC](https://discuss.elastic.co/t/jdbc-streaming-with-list-parameter/307546 "2022-06-17T20:43:44Z")

</div>

I have to pass a list in JDBC steaming query for Oracle, since the list can have more than 1000 record so i cannot use in query .i.e. select name from table where id in (..) I tried two option use tuple : Create tup…

---

## [How to split a single line message, into parts](https://discuss.elastic.co/t/how-to-split-a-single-line-message-into-parts/306982)

<div class="topic-metadata">

**Author:** [@Zerra\_Triani](https://discuss.elastic.co/u/Zerra_Triani)\
**Replies:** 8\
**Last updated:** [June 17, 2022, 5:36pm UTC](https://discuss.elastic.co/t/how-to-split-a-single-line-message-into-parts/306982 "2022-06-17T17:36:32Z")

</div>

Hi, I've created a logstash to filter a log and output a single message. Then I want to split that message into several fields. What filter plugin should I use? I try to use split filter and it doesn't work The example…

---

## [Logstash parse mixed json text](https://discuss.elastic.co/t/logstash-parse-mixed-json-text/307362)

<div class="topic-metadata">

**Author:** [@Saathvi](https://discuss.elastic.co/u/Saathvi)\
**Replies:** 3\
**Last updated:** [June 17, 2022, 5:21pm UTC](https://discuss.elastic.co/t/logstash-parse-mixed-json-text/307362 "2022-06-17T17:21:31Z")

</div>

please can any one help me to parse below mixed json txt from below logentry. need to extract request json fields & response json fields 2020-01-06 01:02:10.869 +01:00 \[Information\] WIN HTTP Response at 2020-01-06T01:0…

---

## [Invalid Field Reference Logstash Grok](https://discuss.elastic.co/t/invalid-field-reference-logstash-grok/307512)

<div class="topic-metadata">

**Author:** [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Replies:** 4\
**Last updated:** [June 17, 2022, 2:08pm UTC](https://discuss.elastic.co/t/invalid-field-reference-logstash-grok/307512 "2022-06-17T14:08:25Z")

</div>

I'm receiving the error below but it doesn't offer a lot of information that I am able to tell. Anyone seen this before? 2022-06-17T07:45:19,655\]\[WARN \]\[logstash.filters.grok \]\[Cisco\_ASA\]\[694b9ac8fb3e2aae9d4c91962e71…

---

## [Passing Array and a Variable from Json output to a http request in Ruby](https://discuss.elastic.co/t/passing-array-and-a-variable-from-json-output-to-a-http-request-in-ruby/307515)

<div class="topic-metadata">

**Author:** [@santhoshi.p](https://discuss.elastic.co/u/santhoshi.p)\
**Replies:** 0\
**Last updated:** [June 17, 2022, 1:32pm UTC](https://discuss.elastic.co/t/passing-array-and-a-variable-from-json-output-to-a-http-request-in-ruby/307515 "2022-06-17T13:32:43Z")

</div>

Hi, I have above output coming from one API and I need to pass this to another API where URL will have variable componets of datasource array and nodeID. And I need to store this data an ingest it to elastic as document…

---

## [Logstash-output-syslog-3.0.5 not sending UDP over IPv6](https://discuss.elastic.co/t/logstash-output-syslog-3-0-5-not-sending-udp-over-ipv6/307279)

<div class="topic-metadata">

**Author:** [@ben2015](https://discuss.elastic.co/u/ben2015)\
**Replies:** 3\
**Last updated:** [June 17, 2022, 12:25pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-3-0-5-not-sending-udp-over-ipv6/307279 "2022-06-17T12:25:56Z")

</div>

I'm trying to use logstash-output-syslog-3.0.5 with protocol UDP and an IPv6 address. It fails in connect, at line 209 of logstash/vendor/bundle/jruby/2.5.0/gems/logstash-output-syslog-3.0.5/lib/logstash/outputs/syslog.…

---

## [Ruby code to generate fields dynamically based on csv](https://discuss.elastic.co/t/ruby-code-to-generate-fields-dynamically-based-on-csv/307276)

<div class="topic-metadata">

**Author:** [@SreelekhaKovuri](https://discuss.elastic.co/u/SreelekhaKovuri)\
**Replies:** 2\
**Last updated:** [June 17, 2022, 11:12am UTC](https://discuss.elastic.co/t/ruby-code-to-generate-fields-dynamically-based-on-csv/307276 "2022-06-17T11:12:19Z")

</div>

I need dynamically generated fields based on the CSV in the logs. In this case my csv format can be in any of the following ways: CSV = CSV = 0 CSV = 1111;2222;3333;4444444;5555 CSV = 1;2;3;4;5;6;7;8;9;10 So, I wan…

---

## [Block in start-input (file not readable) sqlserver logstash](https://discuss.elastic.co/t/block-in-start-input-file-not-readable-sqlserver-logstash/307391)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 11:04am UTC](https://discuss.elastic.co/t/block-in-start-input-file-not-readable-sqlserver-logstash/307391 "2022-06-16T11:04:25Z")

</div>

Hi all, I plan to load data from SQL Server database to Elastic. While trying to load this data using the Logstash JDBC plugin I am facing a problem. I found in the community errors like this but no solution, Test: Cop…

---

## [Return fields format when retrieving more than one documents using Elasticsearch Filter plugin in Logstash](https://discuss.elastic.co/t/return-fields-format-when-retrieving-more-than-one-documents-using-elasticsearch-filter-plugin-in-logstash/307467)

<div class="topic-metadata">

**Author:** [@Zhihai\_Xian](https://discuss.elastic.co/u/Zhihai_Xian)\
**Replies:** 0\
**Last updated:** [June 17, 2022, 4:05am UTC](https://discuss.elastic.co/t/return-fields-format-when-retrieving-more-than-one-documents-using-elasticsearch-filter-plugin-in-logstash/307467 "2022-06-17T04:05:48Z")

</div>

Hi, I could not find any topic or documentation about return fields processing when retrieving more than one documents using Elasticsearch filter plugin in Logstash. Is it possible and how to parse the fields format in …

---

## [Subtracting two values of a field](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 8:36pm UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915 "2022-06-16T20:36:41Z")

</div>

Hello All, I have a set up which parses the following line in a log file: \[2022-06-10T19:52:05.017+0000\]\[info\]\[gc \] GC(35959) Pause Full (Diagnostic Command) 1850M-\>1140M(2560M) 506.831ms The resultant get…

---

## [Logstash - .gz files - Error: Unexpected end of ZLIB input stream](https://discuss.elastic.co/t/logstash-gz-files-error-unexpected-end-of-zlib-input-stream/263028)

<div class="topic-metadata">

**Author:** [@sam281](https://discuss.elastic.co/u/sam281)\
**Replies:** 2\
**Last updated:** [June 16, 2022, 6:54pm UTC](https://discuss.elastic.co/t/logstash-gz-files-error-unexpected-end-of-zlib-input-stream/263028 "2022-06-16T18:54:57Z")

</div>

Hi, I am using logstash to read .gz files. The gzip files are around 10 to 15GB for which logstash was unable to process and crashing. So I have split the .gz files using 7zip split based on size of 3GB .gz file chunks.…

---

## [Date conversion adds one microsecond](https://discuss.elastic.co/t/date-conversion-adds-one-microsecond/307418)

<div class="topic-metadata">

**Author:** [@sudden](https://discuss.elastic.co/u/sudden)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 1:49pm UTC](https://discuss.elastic.co/t/date-conversion-adds-one-microsecond/307418 "2022-06-16T13:49:24Z")

</div>

I'm converting date from string but for some strange reason it sometimes add one microsecond in the timestamp field: logstash 8.1.3 String field: 2022-06-16T13:44:04.615 Logstash code: date { match =\> \[ "fluent\_time…

---

## [Confusion around geo.country\_iso\_code vs country\_code2](https://discuss.elastic.co/t/confusion-around-geo-country-iso-code-vs-country-code2/306857)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 2\
**Last updated:** [June 16, 2022, 1:06pm UTC](https://discuss.elastic.co/t/confusion-around-geo-country-iso-code-vs-country-code2/306857 "2022-06-16T13:06:14Z")

</div>

When we parse an IP for geo info using: geoip { source =\> "ip" target =\> "client" fields =\> \["location", "country\_code2", "country\_name"\] } LogStash creates documents with: client: { geo: { country\_iso\_c…

---

## [Grok Pattern for dynamic json](https://discuss.elastic.co/t/grok-pattern-for-dynamic-json/307408)

<div class="topic-metadata">

**Author:** [@Ahmad\_Ahsan\_Saleem](https://discuss.elastic.co/u/Ahmad_Ahsan_Saleem)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 1:01pm UTC](https://discuss.elastic.co/t/grok-pattern-for-dynamic-json/307408 "2022-06-16T13:01:15Z")

</div>

Hi, My data is coming live from spring boot logs and in successful execution the logs show in json format (each json has different input fields).In case of any error the logs show error with a string format Here is a s…

---

## [Query field value to reindex existing indexes](https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367)

<div class="topic-metadata">

**Author:** [@dapmI](https://discuss.elastic.co/u/dapmI)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 9:07am UTC](https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367 "2022-06-16T09:07:52Z")

</div>

Hello, I'm trying to achieve a complex action where we currently have a common index filebeat-%{beat version}-%{YY-mm-dd} type of index with multiple log.file.path different. The idea is to have them in other index depe…

---

## [Log stash pipeline not connecting to Elasticsearch](https://discuss.elastic.co/t/log-stash-pipeline-not-connecting-to-elasticsearch/307259)

<div class="topic-metadata">

**Author:** [@harijld](https://discuss.elastic.co/u/harijld)\
**Replies:** 3\
**Last updated:** [June 16, 2022, 7:07am UTC](https://discuss.elastic.co/t/log-stash-pipeline-not-connecting-to-elasticsearch/307259 "2022-06-16T07:07:49Z")

</div>

HI, I am getting below error while establishing connection from logstash pipeline to Elasticsearch. I am able to do the telnet from logstash server to Elasticsearch server but not able to establish the connection. logs…

---

## [Log stash not connecting to Elasticsearch](https://discuss.elastic.co/t/log-stash-not-connecting-to-elasticsearch/307263)

<div class="topic-metadata">

**Author:** [@harijld](https://discuss.elastic.co/u/harijld)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 7:01am UTC](https://discuss.elastic.co/t/log-stash-not-connecting-to-elasticsearch/307263 "2022-06-16T07:01:36Z")

</div>

Hi Team, my log stash is unable to connect Elastic search. Telnet is working fine but log stash pipeline is not able to create connection with Elasticsearch. input { stdin{} } output { elasticsearch { hosts =\> …

---

## [How to put ":" into if statement in filter?](https://discuss.elastic.co/t/how-to-put-into-if-statement-in-filter/307319)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 2\
**Last updated:** [June 15, 2022, 10:59pm UTC](https://discuss.elastic.co/t/how-to-put-into-if-statement-in-filter/307319 "2022-06-15T22:59:32Z")

</div>

I am currently trying this: if ":" in dst { I also have tried ":" and ':' (backslash before the colon) but neither worked. Is it possible to still try this?

---

## [Date Filter - \_dateparsefailure](https://discuss.elastic.co/t/date-filter-dateparsefailure/307199)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 8\
**Last updated:** [June 15, 2022, 6:11pm UTC](https://discuss.elastic.co/t/date-filter-dateparsefailure/307199 "2022-06-15T18:11:46Z")

</div>

Dear all, I'm running into a strange problem converting syslogtimestamp field into @timestamp. After reading the thread: https://discuss.elastic.co/t/date-filter--dateparsefailure-solved/64692, I can't make it to work.…

---

## [Error sql server to elasticsearch TLS10](https://discuss.elastic.co/t/error-sql-server-to-elasticsearch-tls10/307244)

<div class="topic-metadata">

**Author:** [@5k\_pwc](https://discuss.elastic.co/u/5k_pwc)\
**Replies:** 7\
**Last updated:** [June 15, 2022, 5:34pm UTC](https://discuss.elastic.co/t/error-sql-server-to-elasticsearch-tls10/307244 "2022-06-15T17:34:40Z")

</div>

I am trying to communicate with sqlserver with logstash, I used : java version "11.0.14" 2022-01-18 LTS Myfile.conf input { jdbc jdbc\_driver\_library =\> "C:\\Users\\Lenovo\\Desktop\\ELK\\logstash-8.1.0\\logstash-core\\lib…

---

## [Ruby filter to map different array elements into one record](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219)

<div class="topic-metadata">

**Author:** [@santhoshi.p](https://discuss.elastic.co/u/santhoshi.p)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 4:48pm UTC](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219 "2022-06-15T16:48:58Z")

</div>

Hi, I have a response like below I'm unable to figure how i need to proceed further. Kindly provide any solution. Response: { "columns": \[ \[0\] { "label": "ICMP", "ingress": true }, \[1\] { "label": "ICMP", "ingr…

---

## [Logstash file input to file output is not working. No errors seen in the logs](https://discuss.elastic.co/t/logstash-file-input-to-file-output-is-not-working-no-errors-seen-in-the-logs/307273)

<div class="topic-metadata">

**Author:** [@rajivraghu](https://discuss.elastic.co/u/rajivraghu)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 3:53pm UTC](https://discuss.elastic.co/t/logstash-file-input-to-file-output-is-not-working-no-errors-seen-in-the-logs/307273 "2022-06-15T15:53:55Z")

</div>

Hello, I am new to logstash. I am using 8.2.3. I dont have Elasticsearch running. I wanted to see if logstash is able to take log file as input and convert into json and store it in a file . This is my code below . in…

---

## [IDE/editor for logstash .conf files](https://discuss.elastic.co/t/ide-editor-for-logstash-conf-files/307303)

<div class="topic-metadata">

**Author:** [@hsalim](https://discuss.elastic.co/u/hsalim)\
**Replies:** 0\
**Last updated:** [June 15, 2022, 3:50pm UTC](https://discuss.elastic.co/t/ide-editor-for-logstash-conf-files/307303 "2022-06-15T15:50:37Z")

</div>

Hello, Is there a IDE or an editor for logstash pipeline development? i am currently using visual studio and was wondering if there is something else out there? i found this so far \[Logstash Editor - Visual Studio Mark…

---

## [Add new calculated field when processing file in logstash](https://discuss.elastic.co/t/add-new-calculated-field-when-processing-file-in-logstash/307014)

<div class="topic-metadata">

**Author:** [@eduhernandezm](https://discuss.elastic.co/u/eduhernandezm)\
**Replies:** 4\
**Last updated:** [June 15, 2022, 1:54pm UTC](https://discuss.elastic.co/t/add-new-calculated-field-when-processing-file-in-logstash/307014 "2022-06-15T13:54:46Z")

</div>

Hello, I have the following configuration in Logstash to read data from a CSV file that I pass every day. I have it working correctly. My doubt is that I need to add a new field based on a mathematical function against …

---

## [Logstash configuration not working on read csv file](https://discuss.elastic.co/t/logstash-configuration-not-working-on-read-csv-file/306515)

<div class="topic-metadata">

**Author:** [@selflabs](https://discuss.elastic.co/u/selflabs)\
**Replies:** 11\
**Last updated:** [June 15, 2022, 12:24pm UTC](https://discuss.elastic.co/t/logstash-configuration-not-working-on-read-csv-file/306515 "2022-06-15T12:24:49Z")

</div>

Hello Everyone, Logstash not reading csv file, i have tried all possible case but unable to pick data from the csv file. my ultimate goal is read data from REST API and mapping with CSV file. Please suggest, Configuratio…

---

## [Logstash pipeline issues with flowfile attributes](https://discuss.elastic.co/t/logstash-pipeline-issues-with-flowfile-attributes/307260)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 12:07pm UTC](https://discuss.elastic.co/t/logstash-pipeline-issues-with-flowfile-attributes/307260 "2022-06-15T12:07:34Z")

</div>

We get json files from a Nifi and when I checked in Kibana They have a \_jsonparsefailure. When I looked at the logs I see inside "message" "flowfile.attributes0000644 0000 000 000 000 and other garbage about ECDS and at …

---

## [Does ELK support indexing emails from Microsoft Exchange?](https://discuss.elastic.co/t/does-elk-support-indexing-emails-from-microsoft-exchange/307223)

<div class="topic-metadata">

**Author:** [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Replies:** 0\
**Last updated:** [June 15, 2022, 6:32am UTC](https://discuss.elastic.co/t/does-elk-support-indexing-emails-from-microsoft-exchange/307223 "2022-06-15T06:32:39Z")

</div>

Hi, I did some research and found that logstash does support indexing emails from IMAP https://qbox.io/blog/indexing-emails-to-elasticsearch-logstash-imap/ But I'm not sure if there's any similar plugin available in L…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=132)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=134)
