# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=14

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 15

---

## [Logstash SNMP Interface Monitoring Configuration with Bandwidth Utilization Calculation](https://discuss.elastic.co/t/logstash-snmp-interface-monitoring-configuration-with-bandwidth-utilization-calculation/372068)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 0\
**Last updated:** [December 17, 2024, 12:34pm UTC](https://discuss.elastic.co/t/logstash-snmp-interface-monitoring-configuration-with-bandwidth-utilization-calculation/372068 "2024-12-17T12:34:45Z")

</div>

Hi everyone, I'd like to share my Logstash configuration for monitoring network interfaces via SNMP with bandwidth utilization calculation. This configuration collects interface statistics from network devices (tested w…

---

## [Epoch Time Via Logstash](https://discuss.elastic.co/t/epoch-time-via-logstash/372046)

<div class="topic-metadata">

**Author:** [@DFIR\_Cap](https://discuss.elastic.co/u/DFIR_Cap)\
**Replies:** 4\
**Last updated:** [December 16, 2024, 9:57pm UTC](https://discuss.elastic.co/t/epoch-time-via-logstash/372046 "2024-12-16T21:57:55Z")

</div>

I have a JSON Log file that can ingest properly ALL with the exception of the @timestamp field. Here is the format: "@timestamp":1734103443540 I have tried to add the below in my logstash CONF file but it does not wor…

---

## [Grok pattern](https://discuss.elastic.co/t/grok-pattern/372023)

<div class="topic-metadata">

**Author:** [@inkerinmaa](https://discuss.elastic.co/u/inkerinmaa)\
**Replies:** 1\
**Last updated:** [December 16, 2024, 1:51pm UTC](https://discuss.elastic.co/t/grok-pattern/372023 "2024-12-16T13:51:06Z")

</div>

Hi. I am trying to parse this log message: 2024-12-09 12:33:53,722 ERROR \[Timer-Driven Process Thread-10\] o.a.n.processors.standard.LogAttribute LogAttribute\[id=9b65f63b-0193-1000-ffff-ffffd5fe4484\] logging for flow fil…

---

## [Logstash field is never shown after aggregation](https://discuss.elastic.co/t/logstash-field-is-never-shown-after-aggregation/371963)

<div class="topic-metadata">

**Author:** [@Hannah\_J\_Swystun](https://discuss.elastic.co/u/Hannah_J_Swystun)\
**Replies:** 2\
**Last updated:** [December 16, 2024, 8:49am UTC](https://discuss.elastic.co/t/logstash-field-is-never-shown-after-aggregation/371963 "2024-12-16T08:49:32Z")

</div>

I have logstash version 7.8.0 Can someone tell me why the aggregation below never shown THREAD\_ID field into documents please ? My field : thread\_id is added in the end of aggregation .. 2024-12-14 12:00:01 thread-1 SOA…

---

## [Loading high transactional data to elasticsearch](https://discuss.elastic.co/t/loading-high-transactional-data-to-elasticsearch/371726)

<div class="topic-metadata">

**Author:** [@amirhosseinbi](https://discuss.elastic.co/u/amirhosseinbi)\
**Replies:** 22\
**Last updated:** [December 12, 2024, 10:15pm UTC](https://discuss.elastic.co/t/loading-high-transactional-data-to-elasticsearch/371726 "2024-12-12T22:15:11Z")

</div>

Hi all, I'm ingesting network traffic using tshark and need to load it to elasticsearch for further analysis and troubleshooting. The traffic is transformed to json format and around 1TB daily, my bottleneck is now logs…

---

## [Help pruning fields with "%{\[foo\]\[bar\]}" values](https://discuss.elastic.co/t/help-pruning-fields-with-foo-bar-values/371899)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 6\
**Last updated:** [December 12, 2024, 4:00pm UTC](https://discuss.elastic.co/t/help-pruning-fields-with-foo-bar-values/371899 "2024-12-12T16:00:05Z")

</div>

Hi there! I'm currently testing the latest PFelk with my firewall and I found a very specific situation which has only happened with a couple of log lines, but I would like to make it work. The problem is that due to so…

---

## [Date filter can't access nested field from jdbc input](https://discuss.elastic.co/t/date-filter-cant-access-nested-field-from-jdbc-input/371905)

<div class="topic-metadata">

**Author:** [@Ruben\_Laguna](https://discuss.elastic.co/u/Ruben_Laguna)\
**Replies:** 3\
**Last updated:** [December 12, 2024, 1:47pm UTC](https://discuss.elastic.co/t/date-filter-cant-access-nested-field-from-jdbc-input/371905 "2024-12-12T13:47:54Z")

</div>

I have a input { jdbc { target =\> "DataRow" } } filter { mutate { add\_field =\> { "rubentest" =\> "%{\[DataRow\]\[created\_at\]}" } } date { match =\> \[ "rubentest", "ISO8601"\] target =\> "rubentest2"…

---

## [Logstash in docker plugin install error : G1ParScanThreadState::steal\_and\_trim\_queue](https://discuss.elastic.co/t/logstash-in-docker-plugin-install-error-g1parscanthreadstate-steal-and-trim-queue/371898)

<div class="topic-metadata">

**Author:** [@liubin95](https://discuss.elastic.co/u/liubin95)\
**Replies:** 0\
**Last updated:** [December 12, 2024, 8:31am UTC](https://discuss.elastic.co/t/logstash-in-docker-plugin-install-error-g1parscanthreadstate-steal-and-trim-queue/371898 "2024-12-12T08:31:01Z")

</div>

This is Dockerfile # # docker build-t logstash-sts:8.16.0 --platform linux/amd64 . # FROM logstash:8.16.0 ENV LS\_JAVA\_OPT "-Xms4g -Xmx4g" RUN logstash-plugin install logstash-input-sls ADD opt/logstash/config/logstas…

---

## [Logstash not able to consume Kafka input](https://discuss.elastic.co/t/logstash-not-able-to-consume-kafka-input/371823)

<div class="topic-metadata">

**Author:** [@1Z10](https://discuss.elastic.co/u/1Z10)\
**Replies:** 0\
**Last updated:** [December 11, 2024, 9:58am UTC](https://discuss.elastic.co/t/logstash-not-able-to-consume-kafka-input/371823 "2024-12-11T09:58:33Z")

</div>

I'm playing a bit with the latest versions of Logstash and Kafka but I can't get the Kafka input to work. Here a brief summary of my setup: I'm using Docker Compose with apache/kafka:3.9.0 and logstash:8.16.1 Docker i…

---

## [Can't run jruby commands on Logstash 8](https://discuss.elastic.co/t/cant-run-jruby-commands-on-logstash-8/371769)

<div class="topic-metadata">

**Author:** [@mcairney](https://discuss.elastic.co/u/mcairney)\
**Replies:** 0\
**Last updated:** [December 10, 2024, 2:26pm UTC](https://discuss.elastic.co/t/cant-run-jruby-commands-on-logstash-8/371769 "2024-12-10T14:26:19Z")

</div>

Hi, We're looking to upgrade our ELK stack from 7.17 to 8.16 however I've discovered an issue with the jruby command throwing an error on 8.16 which means we can't build and install logstash plugins. e.g. # /usr/share…

---

## [Logstash riddle fingerprint duplicates](https://discuss.elastic.co/t/logstash-riddle-fingerprint-duplicates/371712)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 5\
**Last updated:** [December 10, 2024, 1:47pm UTC](https://discuss.elastic.co/t/logstash-riddle-fingerprint-duplicates/371712 "2024-12-10T13:47:07Z")

</div>

Hi there, Using the logstash fingerprint plugin i came across an issue where it seems i cannot define the \_id as a target from the plugin using the following : fingerprint { source =\> \["\[host\]\[name\]", "\[record\]\[id\]…

---

## [Certificate error in logstash](https://discuss.elastic.co/t/certificate-error-in-logstash/371731)

<div class="topic-metadata">

**Author:** [@vikramaddagulla](https://discuss.elastic.co/u/vikramaddagulla)\
**Replies:** 0\
**Last updated:** [December 10, 2024, 2:02am UTC](https://discuss.elastic.co/t/certificate-error-in-logstash/371731 "2024-12-10T02:02:09Z")

</div>

I have configured elastic and logstash couple of years ago and now I am getting certificate expired error. This is happening when logstash is trying to connect to elastic. The error seen in logsatsh is as below : \[202…

---

## [Logstash File Naming Issue with Timezone (Attempting with Other Timezone)](https://discuss.elastic.co/t/logstash-file-naming-issue-with-timezone-attempting-with-other-timezone/371645)

<div class="topic-metadata">

**Author:** [@blitzkrieg330](https://discuss.elastic.co/u/blitzkrieg330)\
**Replies:** 3\
**Last updated:** [December 9, 2024, 11:34am UTC](https://discuss.elastic.co/t/logstash-file-naming-issue-with-timezone-attempting-with-other-timezone/371645 "2024-12-09T11:34:15Z")

</div>

Hello, I am using Logstash to process PAN-OS syslog data and I'm facing an issue with the file name timestamp. I want the output file names to be in the format YYYY-MM-DD with the time zone set to "Europe/Berlin" (Germa…

---

## [Http output and curl eqvalent](https://discuss.elastic.co/t/http-output-and-curl-eqvalent/371547)

<div class="topic-metadata">

**Author:** [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Replies:** 6\
**Last updated:** [December 6, 2024, 2:05pm UTC](https://discuss.elastic.co/t/http-output-and-curl-eqvalent/371547 "2024-12-06T14:05:07Z")

</div>

Good Day, I am trying to use the logstash http output command to replicate the following curl command? curl -k PATCH https://etp.us.example.com/api/v1/policies/123455/deny -H "Content-Type: application/json" -H "x-exam…

---

## [Sflow Codec Plugin is not being installed locally](https://discuss.elastic.co/t/sflow-codec-plugin-is-not-being-installed-locally/371593)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [December 6, 2024, 10:59am UTC](https://discuss.elastic.co/t/sflow-codec-plugin-is-not-being-installed-locally/371593 "2024-12-06T10:59:47Z")

</div>

We have logstash logstash-8.15.2 locally but on production its not 8.7 and we don't have internet access, so i have dowloaded the gem file from \[logstash-codec-sflow | RubyGems.org | your community gem host\] (logstash…

---

## [ESET Protect CLOUD logs send to Logstash](https://discuss.elastic.co/t/eset-protect-cloud-logs-send-to-logstash/369803)

<div class="topic-metadata">

**Author:** [@Roverboy](https://discuss.elastic.co/u/Roverboy)\
**Replies:** 7\
**Last updated:** [December 6, 2024, 9:55am UTC](https://discuss.elastic.co/t/eset-protect-cloud-logs-send-to-logstash/369803 "2024-12-06T09:55:04Z")

</div>

Hi All, I have a problem with the logs received by my ESET POTECT CLOUD Console. This is what i received : "\\u0000\\u0000\\u0011\\u0000\\u000F\\u0000\\u0000\\f82.64.237.88\\u0000\\v\\u0000\\u0004\\u0003\\u0000\\u0001\\u0002\\u0000\\n" …

---

## [Receive syslog logs and forward copy to another server](https://discuss.elastic.co/t/receive-syslog-logs-and-forward-copy-to-another-server/371480)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 2\
**Last updated:** [December 5, 2024, 12:54pm UTC](https://discuss.elastic.co/t/receive-syslog-logs-and-forward-copy-to-another-server/371480 "2024-12-05T12:54:43Z")

</div>

Hello, I need to receive them via syslog through logstash, process them and send them to the elasticsearch cluster, but I also need the original logs to go a copy to another server to another SIEM that I have. I would …

---

## [Logstash ramping up RAM usage change in behaviour](https://discuss.elastic.co/t/logstash-ramping-up-ram-usage-change-in-behaviour/370599)

<div class="topic-metadata">

**Author:** [@carlosmg1](https://discuss.elastic.co/u/carlosmg1)\
**Replies:** 5\
**Last updated:** [December 4, 2024, 1:06pm UTC](https://discuss.elastic.co/t/logstash-ramping-up-ram-usage-change-in-behaviour/370599 "2024-12-04T13:06:50Z")

</div>

Hi everybody, We're having some issue with one of our logstash clusters. There are 6 machines with 32 Gb of RAM + 16 Core AWS instances running logstash docker container. Those are only logstsh servers. We've had an sta…

---

## [Logstash remains in running state](https://discuss.elastic.co/t/logstash-remains-in-running-state/371323)

<div class="topic-metadata">

**Author:** [@Ritik\_Loomba](https://discuss.elastic.co/u/Ritik_Loomba)\
**Replies:** 13\
**Last updated:** [December 4, 2024, 12:25pm UTC](https://discuss.elastic.co/t/logstash-remains-in-running-state/371323 "2024-12-04T12:25:11Z")

</div>

Hi , I want to setup a logstash pipeline which will read data from Elasticsearch and load it to s3. For time being i am creating a test pipeline which reads data from one file and create a output file from it (creating …

---

## [Logstash 8.16.0 Java::JavaSql::SQLException: Java heap space](https://discuss.elastic.co/t/logstash-8-16-0-java-java-heap-space/371288)

<div class="topic-metadata">

**Author:** [@nickbarry](https://discuss.elastic.co/u/nickbarry)\
**Replies:** 2\
**Last updated:** [December 3, 2024, 10:19pm UTC](https://discuss.elastic.co/t/logstash-8-16-0-java-java-heap-space/371288 "2024-12-03T22:19:42Z")

</div>

Recently upgraded to Elastic 8.16.0, Kibana 8.16.0 and logstash 8.16.0. And things were running smoothly until Friday morning at 1am. Here in the States it was Thanksgiving so I did not change anything recently. Syste…

---

## [Logstash - Slow data processing](https://discuss.elastic.co/t/logstash-slow-data-processing/371115)

<div class="topic-metadata">

**Author:** [@Harsh08](https://discuss.elastic.co/u/Harsh08)\
**Replies:** 19\
**Last updated:** [December 3, 2024, 3:02pm UTC](https://discuss.elastic.co/t/logstash-slow-data-processing/371115 "2024-12-03T15:02:52Z")

</div>

I am using Filebeat and Logstash to set up a logging system for handling logs from around 35 servers. Currently, I have large volume of logs, and Logstash is not able to process the data quickly enough. As a result, the…

---

## [Getting error while parsing logs from one server to another](https://discuss.elastic.co/t/getting-error-while-parsing-logs-from-one-server-to-another/371300)

<div class="topic-metadata">

**Author:** [@Monica\_D](https://discuss.elastic.co/u/Monica_D)\
**Replies:** 0\
**Last updated:** [December 2, 2024, 8:24am UTC](https://discuss.elastic.co/t/getting-error-while-parsing-logs-from-one-server-to-another/371300 "2024-12-02T08:24:27Z")

</div>

I have a setup with two Logstash servers, where the sender Logstash server takes input from a Python script and sends it to the receiving Logstash server. The port connectivity is fine, but I am still facing issues while…

---

## [Logstash preventing system shutdown](https://discuss.elastic.co/t/logstash-preventing-system-shutdown/371129)

<div class="topic-metadata">

**Author:** [@ahsan0331](https://discuss.elastic.co/u/ahsan0331)\
**Replies:** 8\
**Last updated:** [November 29, 2024, 11:37pm UTC](https://discuss.elastic.co/t/logstash-preventing-system-shutdown/371129 "2024-11-29T23:37:10Z")

</div>

hi whenever i reboot or shut my machine it hangs at this message job logstash.service/stop running it takes forever .. its a test lab and hardly one device is sending a netflow and winlog beat to it. last time i left…

---

## [Error syslog5424\_sd](https://discuss.elastic.co/t/error-syslog5424-sd/371221)

<div class="topic-metadata">

**Author:** [@Virtual\_Box](https://discuss.elastic.co/u/Virtual_Box)\
**Replies:** 0\
**Last updated:** [November 29, 2024, 6:15am UTC](https://discuss.elastic.co/t/error-syslog5424-sd/371221 "2024-11-29T06:15:10Z")

</div>

Hello everyone! I would be very grateful for your help! Now I am trying to integrate the Checkpoint firewall with ELK. I receive logs, but they are not parsed. I get the following error when parsing logs from the Checkp…

---

## [Log stash parsing invalid json string issue](https://discuss.elastic.co/t/log-stash-parsing-invalid-json-string-issue/370431)

<div class="topic-metadata">

**Author:** [@Awais\_Jilani](https://discuss.elastic.co/u/Awais_Jilani)\
**Replies:** 1\
**Last updated:** [November 28, 2024, 4:05pm UTC](https://discuss.elastic.co/t/log-stash-parsing-invalid-json-string-issue/370431 "2024-11-28T16:05:11Z")

</div>

I am facing issue in logstash 7.6.1 while reading a mesages which is json but nested map is in json string which cause it invalid json and logstash gives json parsing error. I tried to remove that tag from message but i…

---

## [Issues with Gsub moving from Logstash 7 to 8](https://discuss.elastic.co/t/issues-with-gsub-moving-from-logstash-7-to-8/371189)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 2\
**Last updated:** [November 28, 2024, 3:12pm UTC](https://discuss.elastic.co/t/issues-with-gsub-moving-from-logstash-7-to-8/371189 "2024-11-28T15:12:29Z")

</div>

Hi all, as the title says, I'm experiencing some issues with GSUB, moving from logstash 7 to logstash 8. I discarded a problem with ECS compatibility (I didn't think it was involved here, but just in case), so it must be…

---

## [Logstash 8 grok is resolving host.name as host.hostname](https://discuss.elastic.co/t/logstash-8-grok-is-resolving-host-name-as-host-hostname/371149)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 7\
**Last updated:** [November 27, 2024, 5:13pm UTC](https://discuss.elastic.co/t/logstash-8-grok-is-resolving-host-name-as-host-hostname/371149 "2024-11-27T17:13:01Z")

</div>

Hi all, I'm currently working on migrating from Logstash 7.x to logstash 8.x and it's being a bit trippy. We already used ECS so supposedly it should be straight forward, but I'm experiencing some weird errors with grok.…

---

## [ERROR: logstash.licensechecker.licensereader](https://discuss.elastic.co/t/error-logstash-licensechecker-licensereader/371013)

<div class="topic-metadata">

**Author:** [@XiaoYu\_Zhang](https://discuss.elastic.co/u/XiaoYu_Zhang)\
**Replies:** 2\
**Last updated:** [November 25, 2024, 11:38am UTC](https://discuss.elastic.co/t/error-logstash-licensechecker-licensereader/371013 "2024-11-25T11:38:02Z")

</div>

\[2024-11-25T09:31:58,481\]\[ERROR\]\[logstash.licensechecker.licensereader\] Unable to retrieve license information from license server {:message=\>"No Available connections"} :cause=\>java.net.UnknownHostException: elasticsea…

---

## [Custom pipeline settings with Centralised Pipeline Management](https://discuss.elastic.co/t/custom-pipeline-settings-with-centralised-pipeline-management/371001)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 0\
**Last updated:** [November 25, 2024, 1:58am UTC](https://discuss.elastic.co/t/custom-pipeline-settings-with-centralised-pipeline-management/371001 "2024-11-25T01:58:30Z")

</div>

Hi, We're looking at moving our existing pipelines from git to to Kibana, using "Centralised Pipeline Management". I tried replicating them in Kibana, but only very basic settings were present - I couldn't set any of o…

---

## [Elastic search look up filter is not working when the fields has special characters](https://discuss.elastic.co/t/elastic-search-look-up-filter-is-not-working-when-the-fields-has-special-characters/370960)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 3\
**Last updated:** [November 22, 2024, 6:40pm UTC](https://discuss.elastic.co/t/elastic-search-look-up-filter-is-not-working-when-the-fields-has-special-characters/370960 "2024-11-22T18:40:51Z")

</div>

Hi Team, I am trying to compare data in two indexes using a common key which has special character "/" in the value. For example: Common\_key: pr/01/1235678 When i use Elasticsearch filter in logstash to look up using …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=13)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=15)
