# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=138

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 139

---

## [Logstash not running own username](https://discuss.elastic.co/t/logstash-not-running-own-username/305703)

<div class="topic-metadata">

**Author:** [@bekk777](https://discuss.elastic.co/u/bekk777)\
**Replies:** 3\
**Last updated:** [May 27, 2022, 7:58am UTC](https://discuss.elastic.co/t/logstash-not-running-own-username/305703 "2022-05-27T07:58:20Z")

</div>

Hello, I am running this command: /usr/share/logstash/bin/logstash --debug --config.test\_and\_exit -f /etc/logstash/filebeat-test.conf I know many times published this kind of issue, but I'm getting errors yet. I tried…

---

## [Logstash Pipeline for Nested data from sql](https://discuss.elastic.co/t/logstash-pipeline-for-nested-data-from-sql/305688)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 2\
**Last updated:** [May 27, 2022, 4:57am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-nested-data-from-sql/305688 "2022-05-27T04:57:05Z")

</div>

Hi, I am trying to insert nested data from sqldb to Elasticsearch index. I create a query with joins and insert data into Elasticsearch index. I used aggregate, but it is not giving correct result. Mapping PUT testi…

---

## [TLS Logstash](https://discuss.elastic.co/t/tls-logstash/305735)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 5\
**Last updated:** [May 26, 2022, 7:06pm UTC](https://discuss.elastic.co/t/tls-logstash/305735 "2022-05-26T19:06:23Z")

</div>

Hello guys, I have a beats input on a logstash pipeline using SSL /TLS: input { beats { port =\> 5044 ssl =\> true ssl\_certificate =\> "/etc/../mycert.pem" ssl\_key =\> "/etc/.../mycert.p…

---

## [Connecting logstash on elastic with security enabled](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636)

<div class="topic-metadata">

**Author:** [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Replies:** 6\
**Last updated:** [May 26, 2022, 5:32pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636 "2022-05-26T17:32:46Z")

</div>

Hi I am trying to connect a plugin on elasticsearch with security enabled. The plugin is having an unrecoverable error and is restarting portion of logs of logstash \[2022-05-25T18:53:15,071\]\[INFO \]\[logstash.inputs.tc…

---

## [Different Timezones in syslog for some hosts](https://discuss.elastic.co/t/different-timezones-in-syslog-for-some-hosts/305737)

<div class="topic-metadata">

**Author:** [@syedabdullah](https://discuss.elastic.co/u/syedabdullah)\
**Replies:** 0\
**Last updated:** [May 26, 2022, 5:18pm UTC](https://discuss.elastic.co/t/different-timezones-in-syslog-for-some-hosts/305737 "2022-05-26T17:18:47Z")

</div>

Hi Everyone, I am relatively new to ELK stack I added a new source of syslog but that source is in UTC, When I forward the syslogs, I have its sources (hosts) in UTC and everything else in EST and once they go into Elas…

---

## [Influx Plugin: Data loss during Output server down-time](https://discuss.elastic.co/t/influx-plugin-data-loss-during-output-server-down-time/305624)

<div class="topic-metadata">

**Author:** [@AurelioAranzana](https://discuss.elastic.co/u/AurelioAranzana)\
**Replies:** 5\
**Last updated:** [May 26, 2022, 5:06pm UTC](https://discuss.elastic.co/t/influx-plugin-data-loss-during-output-server-down-time/305624 "2022-05-26T17:06:17Z")

</div>

Hi everyone! I would like to know how Logstash handles when your output server is down. In my case, I'm using the Influxdb output plugin. From what I'm seeing it will keep trying according to the max\_retries parameter…

---

## [HTTP filter logstash error](https://discuss.elastic.co/t/http-filter-logstash-error/305714)

<div class="topic-metadata">

**Author:** [@vishnuhngama](https://discuss.elastic.co/u/vishnuhngama)\
**Replies:** 1\
**Last updated:** [May 26, 2022, 4:50pm UTC](https://discuss.elastic.co/t/http-filter-logstash-error/305714 "2022-05-26T16:50:07Z")

</div>

Hi Team, We are facing issue while using http filter in logstash . We are using file input plugin to read from a file and then use the message field in http filter please see the code. Please help u actually its a urg…

---

## [Stop filter processing of the event on condition match and jump to output](https://discuss.elastic.co/t/stop-filter-processing-of-the-event-on-condition-match-and-jump-to-output/305673)

<div class="topic-metadata">

**Author:** [@esuser27](https://discuss.elastic.co/u/esuser27)\
**Replies:** 2\
**Last updated:** [May 26, 2022, 4:35pm UTC](https://discuss.elastic.co/t/stop-filter-processing-of-the-event-on-condition-match-and-jump-to-output/305673 "2022-05-26T16:35:16Z")

</div>

Hi Team, I want to know if there is any way to stop my filter processing of the event on condition match and jump to output for ex if \[log\] == "parsed" { stop processing next filter portion and jump to output }

---

## [Update logstash geo\_ip lib file do you need to restart the system?](https://discuss.elastic.co/t/update-logstash-geo-ip-lib-file-do-you-need-to-restart-the-system/305670)

<div class="topic-metadata">

**Author:** [@zhanghao116560](https://discuss.elastic.co/u/zhanghao116560)\
**Replies:** 1\
**Last updated:** [May 26, 2022, 4:13pm UTC](https://discuss.elastic.co/t/update-logstash-geo-ip-lib-file-do-you-need-to-restart-the-system/305670 "2022-05-26T16:13:48Z")

</div>

I covered the logstash file/vendor/bundle/app / 2.3.0 / gems/logstash - filter - geoip - 5.0.3 - Java/vendor/GeoLite2 - City. mmdb, but much more special server, Check whether you need to restart the system to take effec…

---

## [My regExp doesn't work in mutate gsub](https://discuss.elastic.co/t/my-regexp-doesnt-work-in-mutate-gsub/305657)

<div class="topic-metadata">

**Author:** [@playingkim0916](https://discuss.elastic.co/u/playingkim0916)\
**Replies:** 1\
**Last updated:** [May 26, 2022, 4:10pm UTC](https://discuss.elastic.co/t/my-regexp-doesnt-work-in-mutate-gsub/305657 "2022-05-26T16:10:52Z")

</div>

The value value of \[@metadata\]\[test\] is 2022-05-24T08:50:05.000Z , but using the corresponding regular expression causes an error error msg is Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipelin…

---

## [Logstash is not creating index in Elasticsearch](https://discuss.elastic.co/t/logstash-is-not-creating-index-in-elasticsearch/305675)

<div class="topic-metadata">

**Author:** [@ravis85](https://discuss.elastic.co/u/ravis85)\
**Replies:** 1\
**Last updated:** [May 26, 2022, 2:23pm UTC](https://discuss.elastic.co/t/logstash-is-not-creating-index-in-elasticsearch/305675 "2022-05-26T14:23:45Z")

</div>

Hello, I am running ELK stack in docker container. Everything is working fine. However I am having an issue with Logstash, that whenever I use a input type file and provide a path to my logfile, the Logstash is not cre…

---

## [How can i schedule logstash every minute for jdbc input plugin?](https://discuss.elastic.co/t/how-can-i-schedule-logstash-every-minute-for-jdbc-input-plugin/305662)

<div class="topic-metadata">

**Author:** [@Ashok\_Priyadarshi1](https://discuss.elastic.co/u/Ashok_Priyadarshi1)\
**Replies:** 1\
**Last updated:** [May 26, 2022, 6:31am UTC](https://discuss.elastic.co/t/how-can-i-schedule-logstash-every-minute-for-jdbc-input-plugin/305662 "2022-05-26T06:31:11Z")

</div>

Please explain to me the syntax to write the cron jobs for getting jdbc input every 1 minute?

---

## [Logstash install xpack plugin error](https://discuss.elastic.co/t/logstash-install-xpack-plugin-error/305660)

<div class="topic-metadata">

**Author:** [@1065916870](https://discuss.elastic.co/u/1065916870)\
**Replies:** 1\
**Last updated:** [May 26, 2022, 6:24am UTC](https://discuss.elastic.co/t/logstash-install-xpack-plugin-error/305660 "2022-05-26T06:24:58Z")

</div>

I used docker-compose setup with logstash-oss image, but I get an error when I install xpack plugin , I want to monitor my logstash service on kibana You are using the OSS-only distribution of Logstash. As of version 6.…

---

## [Logstash aggregating through different events](https://discuss.elastic.co/t/logstash-aggregating-through-different-events/305492)

<div class="topic-metadata">

**Author:** [@alyafeai](https://discuss.elastic.co/u/alyafeai)\
**Replies:** 1\
**Last updated:** [May 25, 2022, 8:06pm UTC](https://discuss.elastic.co/t/logstash-aggregating-through-different-events/305492 "2022-05-25T20:06:51Z")

</div>

Hello, I have a question regarding aggregating with logstash my usecase is that I a csv file with specific attrbuites but some of the attrbuites come empty then I receive another file that contain these missing attrbu…

---

## [Bug for sincedb with gz file](https://discuss.elastic.co/t/bug-for-sincedb-with-gz-file/305602)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [May 25, 2022, 7:19pm UTC](https://discuss.elastic.co/t/bug-for-sincedb-with-gz-file/305602 "2022-05-25T19:19:16Z")

</div>

Hi I'm facing with issue for \*.xml.gz files generally issue was reproduced on gz compress files. Even on the latest version of logstash 8.2.1 When I recovered logstash service with sincedb configuration it seems that …

---

## [Indices not creating after logstah starting with Systemctl service](https://discuss.elastic.co/t/indices-not-creating-after-logstah-starting-with-systemctl-service/304871)

<div class="topic-metadata">

**Author:** [@Karthik9099](https://discuss.elastic.co/u/Karthik9099)\
**Replies:** 25\
**Last updated:** [May 25, 2022, 1:04pm UTC](https://discuss.elastic.co/t/indices-not-creating-after-logstah-starting-with-systemctl-service/304871 "2022-05-25T13:04:53Z")

</div>

Logstash not creating indices when I use the below command sudo systemctl start logstash.service If I run below command then indices creating successfully and pulling the data bin/logstash -f /etc/logstash/conf.d/logs…

---

## [Logstash Keystore No java.exe executable found on PATH](https://discuss.elastic.co/t/logstash-keystore-no-java-exe-executable-found-on-path/304008)

<div class="topic-metadata">

**Author:** [@Bavaria](https://discuss.elastic.co/u/Bavaria)\
**Replies:** 5\
**Last updated:** [May 25, 2022, 11:31am UTC](https://discuss.elastic.co/t/logstash-keystore-no-java-exe-executable-found-on-path/304008 "2022-05-25T11:31:16Z")

</div>

Hello, I am trying to use the keystore, that the passwords in the pipeline are not in plain text. I did not download any JDK. I used the bundled jdk which is included in the logstash download. I am getting these messag…

---

## [Logstash reads file with multiple lines as "1 hit"](https://discuss.elastic.co/t/logstash-reads-file-with-multiple-lines-as-1-hit/301191)

<div class="topic-metadata">

**Author:** [@RomanKau](https://discuss.elastic.co/u/RomanKau)\
**Replies:** 18\
**Last updated:** [May 24, 2022, 2:02pm UTC](https://discuss.elastic.co/t/logstash-reads-file-with-multiple-lines-as-1-hit/301191 "2022-05-24T14:02:21Z")

</div>

Running Windows 10, Logstash 8.1.0, Elasticsearch, kibana and filebeat 8.0.0 all on the same machine. Getting the data from logstash into elasticsearch and kibana works but when multiple files get read at the same time …

---

## [Logstash service started but no input](https://discuss.elastic.co/t/logstash-service-started-but-no-input/305472)

<div class="topic-metadata">

**Author:** [@CemG](https://discuss.elastic.co/u/CemG)\
**Replies:** 2\
**Last updated:** [May 24, 2022, 1:54pm UTC](https://discuss.elastic.co/t/logstash-service-started-but-no-input/305472 "2022-05-24T13:54:54Z")

</div>

Hello, I have tested Logstash with debug, every thing worked fine. Also tried to start logstash with /usr/share/logstash/bin/logstash and it worked. I have changed the logstash.service file to use pipeline because it wo…

---

## [Logstash azure log analytics output - Failed to flush outgoing items - block in start\_workers](https://discuss.elastic.co/t/logstash-azure-log-analytics-output-failed-to-flush-outgoing-items-block-in-start-workers/305078)

<div class="topic-metadata">

**Author:** [@pavank](https://discuss.elastic.co/u/pavank)\
**Replies:** 6\
**Last updated:** [May 24, 2022, 12:29pm UTC](https://discuss.elastic.co/t/logstash-azure-log-analytics-output-failed-to-flush-outgoing-items-block-in-start-workers/305078 "2022-05-24T12:29:11Z")

</div>

Hi, I am using the redhat openshift logging operator provided fluentd forward to forward my logs to a Logstash instance, and using the azure log analytics output plugin to forward the logs to an Azure Log Analytics Work…

---

## [Use KV filter in logstash can not filter?](https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446)

<div class="topic-metadata">

**Author:** [@GhostRaven](https://discuss.elastic.co/u/GhostRaven)\
**Replies:** 2\
**Last updated:** [May 24, 2022, 10:29am UTC](https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446 "2022-05-24T10:29:45Z")

</div>

Use KV filter in logstash. I can get the value, but can not filter ? why ? Does the key can not be uppercase? if \[host\] == "10.9.10.10" { kv { include\_keys =\> \[ "ACMAC", "ACNAME", "AP…

---

## [Failed to execute action](https://discuss.elastic.co/t/failed-to-execute-action/305479)

<div class="topic-metadata">

**Author:** [@Palaibada](https://discuss.elastic.co/u/Palaibada)\
**Replies:** 0\
**Last updated:** [May 24, 2022, 9:40am UTC](https://discuss.elastic.co/t/failed-to-execute-action/305479 "2022-05-24T09:40:30Z")

</div>

what is solution for this error "message=\>"java.io.IOException: Page file size is too small to hold elements" ?

---

## [Parse specific field when JSON filter failed](https://discuss.elastic.co/t/parse-specific-field-when-json-filter-failed/305439)

<div class="topic-metadata">

**Author:** [@austin0918](https://discuss.elastic.co/u/austin0918)\
**Replies:** 1\
**Last updated:** [May 24, 2022, 2:53am UTC](https://discuss.elastic.co/t/parse-specific-field-when-json-filter-failed/305439 "2022-05-24T02:53:53Z")

</div>

I have some logs in JSON format with some offending key-value pairs that cause \_jsonparsefailure. I wanted to leave the log as is and just parse the timestamp. I tried the below config but failed to parse the timestamp f…

---

## [\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Encountered a retryable error (will retry with exponential backoff) {:code=\>400, :url=\>"http://127.0.0.1:9200/\_bulk", :content\_length=\>137306}](https://discuss.elastic.co/t/error-logstash-outputs-elasticsearch-main-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-400-url-http-127-0-0-1-9200-bulk-content-length-137306/305436)

<div class="topic-metadata">

**Author:** [@sunpasup](https://discuss.elastic.co/u/sunpasup)\
**Replies:** 4\
**Last updated:** [May 24, 2022, 2:03am UTC](https://discuss.elastic.co/t/error-logstash-outputs-elasticsearch-main-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-400-url-http-127-0-0-1-9200-bulk-content-length-137306/305436 "2022-05-24T02:03:29Z")

</div>

we are facing above issue while uploading large sets of data from postgres table. based on basic research it looks like, its because of malfunctioned data. how to fix this ? how to identify what data is causing this is…

---

## [Parsing whole phrase](https://discuss.elastic.co/t/parsing-whole-phrase/305420)

<div class="topic-metadata">

**Author:** [@Orest\_Gulman](https://discuss.elastic.co/u/Orest_Gulman)\
**Replies:** 3\
**Last updated:** [May 23, 2022, 7:58pm UTC](https://discuss.elastic.co/t/parsing-whole-phrase/305420 "2022-05-23T19:58:01Z")

</div>

I'm collecting Windows Applications Event Logs, all of them are multiline and can have a variety of formats. My message field which I would like to match has such format: \[Message: An error occurred while trying to ch…

---

## [How not to duplicate data in Elasticserch](https://discuss.elastic.co/t/how-not-to-duplicate-data-in-elasticserch/305428)

<div class="topic-metadata">

**Author:** [@Daniel\_Oliveira](https://discuss.elastic.co/u/Daniel_Oliveira)\
**Replies:** 1\
**Last updated:** [May 23, 2022, 7:45pm UTC](https://discuss.elastic.co/t/how-not-to-duplicate-data-in-elasticserch/305428 "2022-05-23T19:45:03Z")

</div>

Hello gentlemen. I have a logstash pipeline that processes data from a .csv file this file has a column called id how do i not duplicate the data with the same id in case i reprocessed the file or another file that co…

---

## [Recover connection vs logstash further processing](https://discuss.elastic.co/t/recover-connection-vs-logstash-further-processing/305429)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [May 23, 2022, 7:36pm UTC](https://discuss.elastic.co/t/recover-connection-vs-logstash-further-processing/305429 "2022-05-23T19:36:12Z")

</div>

Hi I observe in my production environment such suspicious behavior. Under in spike period of shooting data to ELK cluster a few of master nodes are occupying and in that time I got it that connection is Unreachable. T…

---

## [Using variables/constants in input](https://discuss.elastic.co/t/using-variables-constants-in-input/305402)

<div class="topic-metadata">

**Author:** [@msl09](https://discuss.elastic.co/u/msl09)\
**Replies:** 0\
**Last updated:** [May 23, 2022, 12:54pm UTC](https://discuss.elastic.co/t/using-variables-constants-in-input/305402 "2022-05-23T12:54:10Z")

</div>

Consider the following code: input { http\_poller { urls =\> { myurl1 =\> { ... password =\> 123456 } myurl2 =\> { ... password =\> 123456 } ... } ..…

---

## [Reindex "host" to "host.ip"](https://discuss.elastic.co/t/reindex-host-to-host-ip/305102)

<div class="topic-metadata">

**Author:** [@teamomni](https://discuss.elastic.co/u/teamomni)\
**Replies:** 6\
**Last updated:** [May 23, 2022, 12:52pm UTC](https://discuss.elastic.co/t/reindex-host-to-host-ip/305102 "2022-05-23T12:52:56Z")

</div>

Hello, we recently moved our Logstash that was receiving SNMP to the data stream. All of the current data has worked fine, but when I went to reindex the past several months it failed due to the old files had placed the…

---

## [How to store unstructured data](https://discuss.elastic.co/t/how-to-store-unstructured-data/305373)

<div class="topic-metadata">

**Author:** [@Naga\_Prudhvi](https://discuss.elastic.co/u/Naga_Prudhvi)\
**Replies:** 1\
**Last updated:** [May 23, 2022, 12:45pm UTC](https://discuss.elastic.co/t/how-to-store-unstructured-data/305373 "2022-05-23T12:45:53Z")

</div>

how to store a novel book (text) data into Elasticsearch

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=137)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=139)
