# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=134

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 135

---

## [Parsing mixed: plain-text and json log files in logstash](https://discuss.elastic.co/t/parsing-mixed-plain-text-and-json-log-files-in-logstash/307024)

<div class="topic-metadata">

**Author:** [@xyz3](https://discuss.elastic.co/u/xyz3)\
**Replies:** 14\
**Last updated:** [June 15, 2022, 5:46am UTC](https://discuss.elastic.co/t/parsing-mixed-plain-text-and-json-log-files-in-logstash/307024 "2022-06-15T05:46:31Z")

</div>

Hello I have log lines containing of two parts - plain-text and json. Example line below: Jun 13 07:58:00 c4e-gen1 c4edlog\[555007\]: {"level":"info","commit":"436F6D6D697449447B5B3135362031303720362036362032353120323331…

---

## [Json filter fails on negative numbers](https://discuss.elastic.co/t/json-filter-fails-on-negative-numbers/307185)

<div class="topic-metadata">

**Author:** [@stefanoste.ml](https://discuss.elastic.co/u/stefanoste.ml)\
**Replies:** 4\
**Last updated:** [June 14, 2022, 5:08pm UTC](https://discuss.elastic.co/t/json-filter-fails-on-negative-numbers/307185 "2022-06-14T17:08:43Z")

</div>

Hello, given the following input {'Time': 1655214909, 'AAA': '\[00AAA0AAA000A0\]', 'Longitude': 12.368, 'Latitude': 41.9331, 'AltitudeGPS': 216.2, 'AltitudeMSL': 216.2, 'SpeedLat': -3.9, 'SpeedLon': 1.88, 'SpeedH': -6.98…

---

## [Jdbc input sql\_last\_value from another source?](https://discuss.elastic.co/t/jdbc-input-sql-last-value-from-another-source/307090)

<div class="topic-metadata">

**Author:** [@Chris\_Kessel](https://discuss.elastic.co/u/Chris_Kessel)\
**Replies:** 9\
**Last updated:** [June 14, 2022, 4:48pm UTC](https://discuss.elastic.co/t/jdbc-input-sql-last-value-from-another-source/307090 "2022-06-14T16:48:31Z")

</div>

I've been struggling for a couple days on this. I'm using the jdbc input plugin, but I need to source the sql\_last\_value from a DB query against another DB rather than having it pull from last\_run\_metadata\_path . So: f…

---

## [Pass an array data as a variable to URL of http logstash plugin](https://discuss.elastic.co/t/pass-an-array-data-as-a-variable-to-url-of-http-logstash-plugin/307186)

<div class="topic-metadata">

**Author:** [@santhoshi.p](https://discuss.elastic.co/u/santhoshi.p)\
**Replies:** 3\
**Last updated:** [June 14, 2022, 4:45pm UTC](https://discuss.elastic.co/t/pass-an-array-data-as-a-variable-to-url-of-http-logstash-plugin/307186 "2022-06-14T16:45:56Z")

</div>

Hi, I am trying to pass an array to a URL as a loop could you please help me to acheive this in logstash pipeline. Any suggestions that is provided is helpful . My response is below: nodeId: 9 "datasource" =\> \[ \[ …

---

## [Unable to parse XML through Logstash](https://discuss.elastic.co/t/unable-to-parse-xml-through-logstash/307144)

<div class="topic-metadata">

**Author:** [@Bineeta\_Das\_IN](https://discuss.elastic.co/u/Bineeta_Das_IN)\
**Replies:** 5\
**Last updated:** [June 14, 2022, 3:56pm UTC](https://discuss.elastic.co/t/unable-to-parse-xml-through-logstash/307144 "2022-06-14T15:56:29Z")

</div>

I am new to ELK stack. Trying to parse below XML code snippet through Logstash: \<?xml version="1.0"?\> Gambardella, Matthew XML Developer's Guide Computer 44.95 2000-10-01 An in-…

---

## [Failed to create monitoring event {:message=\>"For path: events. Map keys:](https://discuss.elastic.co/t/failed-to-create-monitoring-event-message-for-path-events-map-keys/307184)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 0\
**Last updated:** [June 14, 2022, 3:29pm UTC](https://discuss.elastic.co/t/failed-to-create-monitoring-event-message-for-path-events-map-keys/307184 "2022-06-14T15:29:31Z")

</div>

Hi, I am getting this below error suddenly when I tried to start the logstash. \[2022-06-14T16:06:48,964\]\[ERROR\]\[logstash.inputs.metrics \] Failed to create monitoring event {:message=\>"For path: events. Map keys: \[:pip…

---

## [Logstash-plugin logstash-output-clickhouse](https://discuss.elastic.co/t/logstash-plugin-logstash-output-clickhouse/307181)

<div class="topic-metadata">

**Author:** [@FARIDUN\_ISMAILOV](https://discuss.elastic.co/u/FARIDUN_ISMAILOV)\
**Replies:** 0\
**Last updated:** [June 14, 2022, 3:11pm UTC](https://discuss.elastic.co/t/logstash-plugin-logstash-output-clickhouse/307181 "2022-06-14T15:11:03Z")

</div>

Hey guys! Can someone pls create logstash-output-clickhouse zip file for installing offlane. all you need to do: /usr/share/logstash/bin/logstash-plugin prepare-offlane-pack logstash-output-clickhouse and share zi…

---

## [Logstash to Redis user authentication](https://discuss.elastic.co/t/logstash-to-redis-user-authentication/307166)

<div class="topic-metadata">

**Author:** [@broughs](https://discuss.elastic.co/u/broughs)\
**Replies:** 0\
**Last updated:** [June 14, 2022, 1:35pm UTC](https://discuss.elastic.co/t/logstash-to-redis-user-authentication/307166 "2022-06-14T13:35:18Z")

</div>

Hi, We are currently using redis 6.0.6 to sit between logstash and Elasticsearch. Is there a way to create a keystore for user authentication between logstash and redis? At the moment we currently have the password se…

---

## [Query time in input-jdbc database](https://discuss.elastic.co/t/query-time-in-input-jdbc-database/307154)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 0\
**Last updated:** [June 14, 2022, 12:32pm UTC](https://discuss.elastic.co/t/query-time-in-input-jdbc-database/307154 "2022-06-14T12:32:05Z")

</div>

is it possible to create an input-jdbc that executes a query every 3 seconds? this query is small and takes milliseconds to return, but looking at the tail -f you can see that it takes a long time for a new query. can …

---

## [Logstash 8.2.2 on Windows 10 failed to start](https://discuss.elastic.co/t/logstash-8-2-2-on-windows-10-failed-to-start/307118)

<div class="topic-metadata">

**Author:** [@Airborn](https://discuss.elastic.co/u/Airborn)\
**Replies:** 1\
**Last updated:** [June 14, 2022, 12:19pm UTC](https://discuss.elastic.co/t/logstash-8-2-2-on-windows-10-failed-to-start/307118 "2022-06-14T12:19:09Z")

</div>

Hello, Logstash 8.2.2 for windows failed to run, i have the following output. Could someone please help Regards C:\\WINDOWS\\system32\>logstash -f logstash.conf "Using bundled JDK: D:\\Technical-Docs\\Audits\\Audit-Secur…

---

## [Logstash 8.2.2 on windows 10](https://discuss.elastic.co/t/logstash-8-2-2-on-windows-10/307116)

<div class="topic-metadata">

**Author:** [@Airborn](https://discuss.elastic.co/u/Airborn)\
**Replies:** 15\
**Last updated:** [June 14, 2022, 12:15pm UTC](https://discuss.elastic.co/t/logstash-8-2-2-on-windows-10/307116 "2022-06-14T12:15:11Z")

</div>

Hello, logstash 8.2.2Preformatted text for windows failed to run, i have the following output. Could someone please help Regards C:\\WINDOWS\\system32\>logstash -f logstash.conf "Using bundled JDK: D:\\Technical-Docs\\Audi…

---

## [Logstash multiline CSV](https://discuss.elastic.co/t/logstash-multiline-csv/307114)

<div class="topic-metadata">

**Author:** [@tartaarsap](https://discuss.elastic.co/u/tartaarsap)\
**Replies:** 0\
**Last updated:** [June 14, 2022, 8:24am UTC](https://discuss.elastic.co/t/logstash-multiline-csv/307114 "2022-06-14T08:24:43Z")

</div>

Hi, I recently switched from Filebeat to Logstash, but my multiline config pattern is not working anymore. My config file: input { file { path =\> \[ "D:/temp/\*test\*.csv" \] start\_position =\> "beginning" c…

---

## [Logstash vs filebeat](https://discuss.elastic.co/t/logstash-vs-filebeat/307030)

<div class="topic-metadata">

**Author:** [@GARVIT\_KUMAR\_GUPTA](https://discuss.elastic.co/u/GARVIT_KUMAR_GUPTA)\
**Replies:** 3\
**Last updated:** [June 14, 2022, 6:31am UTC](https://discuss.elastic.co/t/logstash-vs-filebeat/307030 "2022-06-14T06:31:35Z")

</div>

Can Anybody tell me difference between Logstash and filebeat with their pros and cons Thanks in advance

---

## [\[LogStash\] how to intentionally slow down JDBC Input Plugin](https://discuss.elastic.co/t/logstash-how-to-intentionally-slow-down-jdbc-input-plugin/306979)

<div class="topic-metadata">

**Author:** [@JooHyukKim](https://discuss.elastic.co/u/JooHyukKim)\
**Replies:** 3\
**Last updated:** [June 14, 2022, 5:53am UTC](https://discuss.elastic.co/t/logstash-how-to-intentionally-slow-down-jdbc-input-plugin/306979 "2022-06-14T05:53:55Z")

</div>

Table Of Contents My situation What I want How I can help 1. my situation I have to run logstash jdbc input against Database running in production. I use pagination options to limit amount of data per query but since …

---

## [Sending data from old version of es(7.17) to newest version(8.1.1)](https://discuss.elastic.co/t/sending-data-from-old-version-of-es-7-17-to-newest-version-8-1-1/306882)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Replies:** 1\
**Last updated:** [June 14, 2022, 5:44am UTC](https://discuss.elastic.co/t/sending-data-from-old-version-of-es-7-17-to-newest-version-8-1-1/306882 "2022-06-14T05:44:08Z")

</div>

Hi all We have a elastic cluster 8.1.1 with 4 nodes, everything working fine. But we also have a single node 7.17. Some .net applications can only send data to 7.17 becasue of plugin compability issues( I've tried but n…

---

## [Is there a way to print the SQL with the jdbc\_streaming filter?](https://discuss.elastic.co/t/is-there-a-way-to-print-the-sql-with-the-jdbc-streaming-filter/307083)

<div class="topic-metadata">

**Author:** [@Chris\_Kessel](https://discuss.elastic.co/u/Chris_Kessel)\
**Replies:** 1\
**Last updated:** [June 13, 2022, 11:50pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-print-the-sql-with-the-jdbc-streaming-filter/307083 "2022-06-13T23:50:43Z")

</div>

The jdbc input plugin conveniently prints the SQL that's being executed. Is there a way to do that with the jdbc\_streaming filter?

---

## [Logstash restarts every 13 seconds](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955)

<div class="topic-metadata">

**Author:** [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Replies:** 4\
**Last updated:** [June 13, 2022, 10:12pm UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955 "2022-06-13T22:12:14Z")

</div>

Hi, I'm new to ELK, I noticed that the Logstash (version: 8.2.2) restarted every 13 seconds, the log I found in /var/log/logstash/logstash-plain.log suggested that there are some syntax error at line 26 of a certain fi…

---

## [Logstash Elasticsearch Fail to Respond](https://discuss.elastic.co/t/logstash-elasticsearch-fail-to-respond/307040)

<div class="topic-metadata">

**Author:** [@tepus](https://discuss.elastic.co/u/tepus)\
**Replies:** 8\
**Last updated:** [June 13, 2022, 5:39pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-fail-to-respond/307040 "2022-06-13T17:39:29Z")

</div>

Hello Everyone, I'm trying to connect Logstash to Elasticsearch. However, it fails with the message Failed to perform request {:message=\>"10.10.145.124:9200 failed to respond", :exception=\>Manticore::ClientProtocolExcep…

---

## [Manage pipeline launch order](https://discuss.elastic.co/t/manage-pipeline-launch-order/307052)

<div class="topic-metadata">

**Author:** [@Laetitia\_RICHARD](https://discuss.elastic.co/u/Laetitia_RICHARD)\
**Replies:** 4\
**Last updated:** [June 13, 2022, 4:19pm UTC](https://discuss.elastic.co/t/manage-pipeline-launch-order/307052 "2022-06-13T16:19:55Z")

</div>

Hi, I have a project with 8 pipelines that handle different data, some depend on the end of execution of other pipelines. Is there a way to schedule their execution and wait for some to finish executing before starting o…

---

## [Aggregation query in logstash input](https://discuss.elastic.co/t/aggregation-query-in-logstash-input/307006)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 0\
**Last updated:** [June 13, 2022, 8:59am UTC](https://discuss.elastic.co/t/aggregation-query-in-logstash-input/307006 "2022-06-13T08:59:46Z")

</div>

Hi! I am trying to get the results of an aggregations query with logstash. Via dev tools this query works correctly but when passing it to logstash it ingests metadata but nothing related to max, min etc fields I am exp…

---

## [Can the snmptrap input plugin for logstash receive snmp version 3 traps?](https://discuss.elastic.co/t/can-the-snmptrap-input-plugin-for-logstash-receive-snmp-version-3-traps/306659)

<div class="topic-metadata">

**Author:** [@selflabs](https://discuss.elastic.co/u/selflabs)\
**Replies:** 3\
**Last updated:** [June 13, 2022, 6:32am UTC](https://discuss.elastic.co/t/can-the-snmptrap-input-plugin-for-logstash-receive-snmp-version-3-traps/306659 "2022-06-13T06:32:16Z")

</div>

Hi Team, can we receive snmp v3 traps on logstash-input-smnptrap plugin. I have tried to get but getting errors. Below are my configuration and version details. logstash version : logstash 8.2.2 snmptrap plugin : logst…

---

## [Conditional processing in txt file](https://discuss.elastic.co/t/conditional-processing-in-txt-file/306654)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 4\
**Last updated:** [June 12, 2022, 8:10pm UTC](https://discuss.elastic.co/t/conditional-processing-in-txt-file/306654 "2022-06-12T20:10:31Z")

</div>

Hi I need to make a parsing data through logstash but in the one txt file consists four different pattern How to make logstash for write to another index after encountering a given particular pattern. I am also asking…

---

## ["doc\_as\_upsert" overwrites logs instead of appending the logs](https://discuss.elastic.co/t/doc-as-upsert-overwrites-logs-instead-of-appending-the-logs/306898)

<div class="topic-metadata">

**Author:** [@Marc\_Jacques](https://discuss.elastic.co/u/Marc_Jacques)\
**Replies:** 1\
**Last updated:** [June 11, 2022, 4:19am UTC](https://discuss.elastic.co/t/doc-as-upsert-overwrites-logs-instead-of-appending-the-logs/306898 "2022-06-11T04:19:12Z")

</div>

Hello Elastic, I have a filebeat agent that harvests logs. It sends the logs to Logstash on the same server, which sends it after to Elastic Cloud, the field "message" has the value of the log on Elastic cloud. After a…

---

## [Twitter Logstash issue](https://discuss.elastic.co/t/twitter-logstash-issue/306914)

<div class="topic-metadata">

**Author:** [@Didi\_Sisi](https://discuss.elastic.co/u/Didi_Sisi)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 8:57pm UTC](https://discuss.elastic.co/t/twitter-logstash-issue/306914 "2022-06-10T20:57:11Z")

</div>

Hello; I have an issue with my twitter app and logstash twitter plugin. I have to extract tweets using the logstash twitter plugin. When I was using my old aps, it works perfectly (I have created it in 2020) Now I cre…

---

## [Filebeat not reading logs from subdirectories](https://discuss.elastic.co/t/filebeat-not-reading-logs-from-subdirectories/306905)

<div class="topic-metadata">

**Author:** [@garry12](https://discuss.elastic.co/u/garry12)\
**Replies:** 3\
**Last updated:** [June 10, 2022, 6:42pm UTC](https://discuss.elastic.co/t/filebeat-not-reading-logs-from-subdirectories/306905 "2022-06-10T18:42:03Z")

</div>

Hey team, I am relatively new to ELK stack and I am trying to send logs from a linux servers to Elasticsearch. The path I am choosing is - I have installed the filebeat on linux server where my application logs are gett…

---

## [\[2018-05-27T08:46:23,536\]\[ERROR\]\[logstash.outputs.elasticsearch\] Encountered a retryable error. Will Retry with exponential backoff {:code=\>413, :url=\>"http://elasticsearch\_address:9200/\_bulk"}](https://discuss.elastic.co/t/2018-05-27t0823-536-error-logstash-outputs-elasticsearch-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413-url-http-elasticsearch-address-9200-bulk/306876)

<div class="topic-metadata">

**Author:** [@Manohar22](https://discuss.elastic.co/u/Manohar22)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 11:37am UTC](https://discuss.elastic.co/t/2018-05-27t0823-536-error-logstash-outputs-elasticsearch-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413-url-http-elasticsearch-address-9200-bulk/306876 "2022-06-10T11:37:44Z")

</div>

Continuing the discussion from Logstash stuck on "Will Retry with exponential backoff": we are seeing below error in logstash logs \[2022-06-10T04:59:38,367\]\[ERROR\]\[logstash.filters.ruby \] Ruby exception occurred: \[…

---

## [\[WARN \]\[o.e.x.s.t.n.SecurityNetty4HttpServerTransport\] \[crud\_node\] http client did not trust this server's certificate, closing connection Netty4HttpChannel{localAddress=/127.0.0.1:9200](https://discuss.elastic.co/t/warn-o-e-x-s-t-n-securitynetty4httpservertransport-crud-node-http-client-did-not-trust-this-servers-certificate-closing-connection-netty4httpchannel-localaddress-127-0-0-1-9200/306859)

<div class="topic-metadata">

**Author:** [@Axel\_Ekenberg](https://discuss.elastic.co/u/Axel_Ekenberg)\
**Replies:** 0\
**Last updated:** [June 10, 2022, 9:05am UTC](https://discuss.elastic.co/t/warn-o-e-x-s-t-n-securitynetty4httpservertransport-crud-node-http-client-did-not-trust-this-servers-certificate-closing-connection-netty4httpchannel-localaddress-127-0-0-1-9200/306859 "2022-06-10T09:05:14Z")

</div>

Hi! I just started with the ELK stack and i have downloaded kibana, logstash, Elasticsearch, made a config file in my logstash folder and i start Elasticsearch and it works well and then when i run logstash with "logstas…

---

## [Custom jar deployment](https://discuss.elastic.co/t/custom-jar-deployment/306832)

<div class="topic-metadata">

**Author:** [@igladyshev](https://discuss.elastic.co/u/igladyshev)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 9:35pm UTC](https://discuss.elastic.co/t/custom-jar-deployment/306832 "2022-06-09T21:35:16Z")

</div>

Hello. I am trying to consume kafka topics and output them to s3. All works when we consume topics published in Avro, but we are struggling to make it working for JSON topics. I understood there is an option of using spe…

---

## [Modify values in json array with Ruby](https://discuss.elastic.co/t/modify-values-in-json-array-with-ruby/306756)

<div class="topic-metadata">

**Author:** [@Long\_Nguyen](https://discuss.elastic.co/u/Long_Nguyen)\
**Replies:** 4\
**Last updated:** [June 9, 2022, 6:42pm UTC](https://discuss.elastic.co/t/modify-values-in-json-array-with-ruby/306756 "2022-06-09T18:42:30Z")

</div>

Hello everyone, I have a json structure as follows: { "server":\[ { "active":true, "objID":1 }, { "active":true, "objID":2 }, { "active":false, …

---

## [Logstash runs out of memory as soon pipelines are triggered](https://discuss.elastic.co/t/logstash-runs-out-of-memory-as-soon-pipelines-are-triggered/306821)

<div class="topic-metadata">

**Author:** [@charvi23](https://discuss.elastic.co/u/charvi23)\
**Replies:** 1\
**Last updated:** [June 9, 2022, 5:19pm UTC](https://discuss.elastic.co/t/logstash-runs-out-of-memory-as-soon-pipelines-are-triggered/306821 "2022-06-09T17:19:13Z")

</div>

My logstash has started suddenly running out of memory, though no changes have been made to the pipeline. Following is the error log. My server has 14-15 GB of memory free. Tried allocating different memory in jvm.optio…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=133)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=135)
