# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=144

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 145

---

## [Logstash-forwarder-java gives SSL handshake error with Logstash v7.16.1 and higher](https://discuss.elastic.co/t/logstash-forwarder-java-gives-ssl-handshake-error-with-logstash-v7-16-1-and-higher/303510)

<div class="topic-metadata">

**Author:** [@preetish\_P](https://discuss.elastic.co/u/preetish_P)\
**Replies:** 2\
**Last updated:** [April 28, 2022, 5:11pm UTC](https://discuss.elastic.co/t/logstash-forwarder-java-gives-ssl-handshake-error-with-logstash-v7-16-1-and-higher/303510 "2022-04-28T17:11:53Z")

</div>

Hi folks, We are in the process of upgrading ELK stack from v7.11.2 to v7.17.2 to fix the log4j2 vulnerability due to JNDI lookup. Most of the our servers are on AIX so we use logstash-forwarder-java utility. We observ…

---

## [Parsing multiple json in a file](https://discuss.elastic.co/t/parsing-multiple-json-in-a-file/303446)

<div class="topic-metadata">

**Author:** [@stemons](https://discuss.elastic.co/u/stemons)\
**Replies:** 3\
**Last updated:** [April 28, 2022, 4:35pm UTC](https://discuss.elastic.co/t/parsing-multiple-json-in-a-file/303446 "2022-04-28T16:35:06Z")

</div>

Hello! I'm trying to parse a file that contains multiple json. Each json is not delimited by a new line or comma separated. e.g. {"version":"0",....}{"version":"0",...}{"version":"0",...} parsing with the following cod…

---

## [Helm logstash elasticSearch plugin does not work with custom user except if supersuer](https://discuss.elastic.co/t/helm-logstash-elasticsearch-plugin-does-not-work-with-custom-user-except-if-supersuer/303520)

<div class="topic-metadata">

**Author:** [@stoza](https://discuss.elastic.co/u/stoza)\
**Replies:** 0\
**Last updated:** [April 28, 2022, 1:35pm UTC](https://discuss.elastic.co/t/helm-logstash-elasticsearch-plugin-does-not-work-with-custom-user-except-if-supersuer/303520 "2022-04-28T13:35:11Z")

</div>

Hi, I'm testing the to install logstash with helm from https://github.com/elastic/helm-charts. Everything works fine except that logstash is not able to query index and get a 403 forbidden when another user than elasti…

---

## [Need to parse xml by logstash and create an event only if a field value is non zero](https://discuss.elastic.co/t/need-to-parse-xml-by-logstash-and-create-an-event-only-if-a-field-value-is-non-zero/303306)

<div class="topic-metadata">

**Author:** [@Rohit\_Goel1](https://discuss.elastic.co/u/Rohit_Goel1)\
**Replies:** 1\
**Last updated:** [April 28, 2022, 1:03pm UTC](https://discuss.elastic.co/t/need-to-parse-xml-by-logstash-and-create-an-event-only-if-a-field-value-is-non-zero/303306 "2022-04-28T13:03:58Z")

</div>

Hi Team , I have few Jenkins build xml files generated when jenkins jobs are triggered. I have to read few tags from the xml and create new fields from them by parsing it through logstash. The xml has one tag \<duration\>…

---

## [Ruby Script to rename fields base on a dictionary](https://discuss.elastic.co/t/ruby-script-to-rename-fields-base-on-a-dictionary/303413)

<div class="topic-metadata">

**Author:** [@frank\_esg](https://discuss.elastic.co/u/frank_esg)\
**Replies:** 4\
**Last updated:** [April 28, 2022, 8:23am UTC](https://discuss.elastic.co/t/ruby-script-to-rename-fields-base-on-a-dictionary/303413 "2022-04-28T08:23:27Z")

</div>

Hello, we use in a logstash pipeline an external ruby script which contains several methods to process logfiles. now we want to add a new method to rename all top level fields of a document based on a hashtable. I hav…

---

## [How to send data Weblogic exporter data to logstash](https://discuss.elastic.co/t/how-to-send-data-weblogic-exporter-data-to-logstash/303399)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 1\
**Last updated:** [April 27, 2022, 10:28pm UTC](https://discuss.elastic.co/t/how-to-send-data-weblogic-exporter-data-to-logstash/303399 "2022-04-27T22:28:43Z")

</div>

Hello team, We need to send data from Weblogic exporter to logstash is there any wat to send data to logstash. We don't want to send data directly to Elasticsearch.

---

## [Getting permission denied error after changing data directory for logstash](https://discuss.elastic.co/t/getting-permission-denied-error-after-changing-data-directory-for-logstash/303426)

<div class="topic-metadata">

**Author:** [@cool999](https://discuss.elastic.co/u/cool999)\
**Replies:** 8\
**Last updated:** [April 27, 2022, 6:43pm UTC](https://discuss.elastic.co/t/getting-permission-denied-error-after-changing-data-directory-for-logstash/303426 "2022-04-27T18:43:29Z")

</div>

Hi Team, I am getting permission denied error after changing path.data and path.logs in logstash to new path. Same issue is happening for kibana. However for Elasticsearch it is working, i can see elasticsearch folder…

---

## [Parse xml entry with logstash and create a new field with the data](https://discuss.elastic.co/t/parse-xml-entry-with-logstash-and-create-a-new-field-with-the-data/302262)

<div class="topic-metadata">

**Author:** [@Rohit\_Goel1](https://discuss.elastic.co/u/Rohit_Goel1)\
**Replies:** 32\
**Last updated:** [April 27, 2022, 5:52pm UTC](https://discuss.elastic.co/t/parse-xml-entry-with-logstash-and-create-a-new-field-with-the-data/302262 "2022-04-27T17:52:13Z")

</div>

I need to parse below xml file with logstash and filter out status and create a new field with its value. below is the sample xml file: \<?xml version="1.1" encoding="UTF-8"?\> \<flow="abc"\> \<tag\>SUCCESS\</tag\> \</flow\> I…

---

## [Logstash Deprecation log JSON Format](https://discuss.elastic.co/t/logstash-deprecation-log-json-format/303155)

<div class="topic-metadata">

**Author:** [@hunsw](https://discuss.elastic.co/u/hunsw)\
**Replies:** 2\
**Last updated:** [April 27, 2022, 4:14pm UTC](https://discuss.elastic.co/t/logstash-deprecation-log-json-format/303155 "2022-04-27T16:14:08Z")

</div>

Is it possible to configure the deprecation logs of Logstash as JSON entries? log.format: json works fine for the 'normal' logs, but not for deprecation ones. I've checked log4j2.properties and it seems that some kind …

---

## [Split document into multiple documents](https://discuss.elastic.co/t/split-document-into-multiple-documents/303305)

<div class="topic-metadata">

**Author:** [@ciavam](https://discuss.elastic.co/u/ciavam)\
**Replies:** 12\
**Last updated:** [April 27, 2022, 3:47pm UTC](https://discuss.elastic.co/t/split-document-into-multiple-documents/303305 "2022-04-27T15:47:16Z")

</div>

Hello, Through the logstash code I was able to get a result like: {field0 = value field1 = \[value1\_field1; value1\_field1\] field2 = \[value1\_field2; value2\_field2\] } Is it possible through logstash to go to what is w…

---

## [Logstash split filter does not work with match\_only\_text type](https://discuss.elastic.co/t/logstash-split-filter-does-not-work-with-match-only-text-type/303357)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 2\
**Last updated:** [April 27, 2022, 2:56pm UTC](https://discuss.elastic.co/t/logstash-split-filter-does-not-work-with-match-only-text-type/303357 "2022-04-27T14:56:18Z")

</div>

Dear Community, We use heartbeat to collect http response from some services. The response format is a JSON array and the array is returned in the http.request.body.content field and http.request.body.content.text field…

---

## [Parse Mcafee audit log file with Logstash](https://discuss.elastic.co/t/parse-mcafee-audit-log-file-with-logstash/302946)

<div class="topic-metadata">

**Author:** [@Xor44](https://discuss.elastic.co/u/Xor44)\
**Replies:** 4\
**Last updated:** [April 27, 2022, 12:46pm UTC](https://discuss.elastic.co/t/parse-mcafee-audit-log-file-with-logstash/302946 "2022-04-27T12:46:59Z")

</div>

Hi Folks , I need your help to find a right way to parse this non-structured file \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ Timestamp : 19/Apr/2022:05:50:02.771 +0200 User …

---

## [Logstash cipher plugin w/ KMS](https://discuss.elastic.co/t/logstash-cipher-plugin-w-kms/303374)

<div class="topic-metadata">

**Author:** [@MrAtheist](https://discuss.elastic.co/u/MrAtheist)\
**Replies:** 0\
**Last updated:** [April 27, 2022, 9:33am UTC](https://discuss.elastic.co/t/logstash-cipher-plugin-w-kms/303374 "2022-04-27T09:33:19Z")

</div>

Hello, Not sure if anyone has got the cipher filter plugin to work with kms? would love some assistance on it if there is any hack for this...

---

## [Auto\_flush\_interval in multiline codec plugin errors out](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/303376)

<div class="topic-metadata">

**Author:** [@ritesh811](https://discuss.elastic.co/u/ritesh811)\
**Replies:** 0\
**Last updated:** [April 27, 2022, 9:40am UTC](https://discuss.elastic.co/t/auto-flush-interval-in-multiline-codec-plugin-errors-out/303376 "2022-04-27T09:40:55Z")

</div>

Hi, I am using auto\_flush\_interval in the multiline codec plugin. It works fine for all the events but when it reaches the end of file, it is throwing grokparsefailure error. And when I remove auto\_flush\_interval, there…

---

## [Logstash UDP input keeps losing data](https://discuss.elastic.co/t/logstash-udp-input-keeps-losing-data/303215)

<div class="topic-metadata">

**Author:** [@co88liwan](https://discuss.elastic.co/u/co88liwan)\
**Replies:** 2\
**Last updated:** [April 27, 2022, 12:24am UTC](https://discuss.elastic.co/t/logstash-udp-input-keeps-losing-data/303215 "2022-04-27T00:24:41Z")

</div>

Hi there, We encountered an issue that Logstash input UDP plugin consistently losing data. From tcpdump analysis we know the data indeed reached the VM, I also tested with Logstash file output plugin and I saw the data…

---

## [Failing to index geo\_shape data into Elasticsearch from Logstash (nil values)](https://discuss.elastic.co/t/failing-to-index-geo-shape-data-into-elasticsearch-from-logstash-nil-values/303193)

<div class="topic-metadata">

**Author:** [@scottfred](https://discuss.elastic.co/u/scottfred)\
**Replies:** 2\
**Last updated:** [April 26, 2022, 9:22pm UTC](https://discuss.elastic.co/t/failing-to-index-geo-shape-data-into-elasticsearch-from-logstash-nil-values/303193 "2022-04-26T21:22:50Z")

</div>

I have Ruby code in Logstash that parses a CSV file and reads the data. Some fields of the data can be empty (e.g. ,,,). When the data is empty, Ruby's CSV parse converts the data to an empty string, (e.g. ""). I also…

---

## [How to break down a multiline entry with nested json - File input plugin](https://discuss.elastic.co/t/how-to-break-down-a-multiline-entry-with-nested-json-file-input-plugin/303245)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 4\
**Last updated:** [April 26, 2022, 6:28pm UTC](https://discuss.elastic.co/t/how-to-break-down-a-multiline-entry-with-nested-json-file-input-plugin/303245 "2022-04-26T18:28:03Z")

</div>

Hi All, I have the following multiline log in json. My setup is that I read from a file (where my events are in embedded json) and the events gets broken down (each row is a treated as a single entry) wrongly. How can…

---

## [Jdbc streaming no records returned even when there are records](https://discuss.elastic.co/t/jdbc-streaming-no-records-returned-even-when-there-are-records/303222)

<div class="topic-metadata">

**Author:** [@James\_Valan](https://discuss.elastic.co/u/James_Valan)\
**Replies:** 0\
**Last updated:** [April 26, 2022, 6:41am UTC](https://discuss.elastic.co/t/jdbc-streaming-no-records-returned-even-when-there-are-records/303222 "2022-04-26T06:41:39Z")

</div>

I am getting no records sometimes but the db has records. (using JDBC Streaming) is there a timeout issue?

---

## [I tried to upgrade the Elasticsearch to 7.16.2 and it’s working fine but Logstash upgrade to 7.16.2 still not working with upgraded elastic. I am getting below error with it, I tried to troubleshoot the issue but it’s still the same](https://discuss.elastic.co/t/i-tried-to-upgrade-the-elasticsearch-to-7-16-2-and-it-s-working-fine-but-logstash-upgrade-to-7-16-2-still-not-working-with-upgraded-elastic-i-am-getting-below-error-with-it-i-tried-to-troubleshoot-the-issue-but-it-s-still-the-same/303216)

<div class="topic-metadata">

**Author:** [@rutika\_kamble](https://discuss.elastic.co/u/rutika_kamble)\
**Replies:** 0\
**Last updated:** [April 26, 2022, 6:15am UTC](https://discuss.elastic.co/t/i-tried-to-upgrade-the-elasticsearch-to-7-16-2-and-it-s-working-fine-but-logstash-upgrade-to-7-16-2-still-not-working-with-upgraded-elastic-i-am-getting-below-error-with-it-i-tried-to-troubleshoot-the-issue-but-it-s-still-the-same/303216 "2022-04-26T06:15:08Z")

</div>

\[2022-04-22T04:24:45,425\]\[WARN \]\[deprecation.logstash.filters.json\] Relying on default value of pipeline.ecs\_compatibility, which may change in a future major release of Logstash. To avoid unexpected changes when upgradi…

---

## [How to pull AZURE APP SERVICE logs to ELK](https://discuss.elastic.co/t/how-to-pull-azure-app-service-logs-to-elk/303115)

<div class="topic-metadata">

**Author:** [@vinayborra](https://discuss.elastic.co/u/vinayborra)\
**Replies:** 1\
**Last updated:** [April 26, 2022, 5:18am UTC](https://discuss.elastic.co/t/how-to-pull-azure-app-service-logs-to-elk/303115 "2022-04-26T05:18:40Z")

</div>

Hi, From last two days, I am facing to find out how to pull azure app service logs to local server ELK. I didn't find any supported links. Can you please help on this. Thanks in advance.

---

## [Logstash configuration from elk cloud](https://discuss.elastic.co/t/logstash-configuration-from-elk-cloud/302961)

<div class="topic-metadata">

**Author:** [@Jesus\_Leguizamon](https://discuss.elastic.co/u/Jesus_Leguizamon)\
**Replies:** 1\
**Last updated:** [April 26, 2022, 1:15am UTC](https://discuss.elastic.co/t/logstash-configuration-from-elk-cloud/302961 "2022-04-26T01:15:29Z")

</div>

How can download agent logstash from my elk cloud, like Elasticsearch for easy setup, regards

---

## [Logstash / Elastic CVE-2022-21449](https://discuss.elastic.co/t/logstash-elastic-cve-2022-21449/302962)

<div class="topic-metadata">

**Author:** [@saberph](https://discuss.elastic.co/u/saberph)\
**Replies:** 0\
**Last updated:** [April 21, 2022, 7:52pm UTC](https://discuss.elastic.co/t/logstash-elastic-cve-2022-21449/302962 "2022-04-21T19:52:14Z")

</div>

Hi, Are Elasticsearch or Logstash affected by CVE-2022-21449 ? The bundle jdk v16 seems vulnerable. /usr/share/Elasticsearch/jdk/bin/java is not yet updated to fix the CVE. Thanks.

---

## [Could not connect to SQL DB using JDBC in Logstash](https://discuss.elastic.co/t/could-not-connect-to-sql-db-using-jdbc-in-logstash/302990)

<div class="topic-metadata">

**Author:** [@Sakshi.Clover](https://discuss.elastic.co/u/Sakshi.Clover)\
**Replies:** 0\
**Last updated:** [April 22, 2022, 7:33am UTC](https://discuss.elastic.co/t/could-not-connect-to-sql-db-using-jdbc-in-logstash/302990 "2022-04-22T07:33:12Z")

</div>

Hi All, I am trying to connect SQL DB with Logstash. Getting exception please refer attachment Below is the Logstash code input { jdbc { jdbc\_connection\_string =\> "jdbc:sqlserver://server;databaseName=…

---

## [Unable to access elastic search without SSL](https://discuss.elastic.co/t/unable-to-access-elastic-search-without-ssl/303201)

<div class="topic-metadata">

**Author:** [@newelastic](https://discuss.elastic.co/u/newelastic)\
**Replies:** 1\
**Last updated:** [April 26, 2022, 12:12am UTC](https://discuss.elastic.co/t/unable-to-access-elastic-search-without-ssl/303201 "2022-04-26T00:12:20Z")

</div>

Hello, I'm trying to pull data from Elasticsearch using logstash pipeline and seeing some issues. I'm able to connect to ES using username and pwd through API (No certificate is provided in the request). However, when t…

---

## [Making a grok filed optional in grok pattern](https://discuss.elastic.co/t/making-a-grok-filed-optional-in-grok-pattern/303159)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 2\
**Last updated:** [April 25, 2022, 5:29pm UTC](https://discuss.elastic.co/t/making-a-grok-filed-optional-in-grok-pattern/303159 "2022-04-25T17:29:38Z")

</div>

Hi, I am trying to make my field optional. Let me give you the scenario below: let suppose my log patterns are: pattern 1: \[2022-04-25T12:51:27.967+02:00\] \[d03-c02-s02\] \[NOTIFICATION\] \[oracle.wsm.msg.logging\] \[tid: …

---

## [Setting the number of replicas in Index Creation](https://discuss.elastic.co/t/setting-the-number-of-replicas-in-index-creation/303166)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [April 25, 2022, 5:22pm UTC](https://discuss.elastic.co/t/setting-the-number-of-replicas-in-index-creation/303166 "2022-04-25T17:22:34Z")

</div>

Hello everyone, when I create a new Index via Logstash they always go with 1 replica and that turns the Index yellow. So I edit it in Index Management to set replicas to 0 the Index turns green; It might be silly but I …

---

## [Audit log fields](https://discuss.elastic.co/t/audit-log-fields/302874)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 2\
**Last updated:** [April 25, 2022, 10:46am UTC](https://discuss.elastic.co/t/audit-log-fields/302874 "2022-04-25T10:46:06Z")

</div>

Hi, I have a set of audit call events, Example: type=SYSCALL msg=audit(1647800652.003:104): arch=c00000b7 syscall=221 success=yes exit=0 a0=ffff96c3a518 a1=ffffe65a32e8 a2=ffffe65a3c78 a3=8 items=0 ppid=5916 pid=7997 au…

---

## [Grok Match but not include](https://discuss.elastic.co/t/grok-match-but-not-include/303046)

<div class="topic-metadata">

**Author:** [@sukur55](https://discuss.elastic.co/u/sukur55)\
**Replies:** 2\
**Last updated:** [April 25, 2022, 6:42am UTC](https://discuss.elastic.co/t/grok-match-but-not-include/303046 "2022-04-25T06:42:27Z")

</div>

Hello, I am trying to parse a custom date&time field like: date=2022-04-22 time=09:38:04, currently I have filter like: (?\<timestamp\>%{YEAR}-%{MONTHNUM}-%{MONTHDAY} time=%{TIME}) and result of timestamp is: 2022-04…

---

## [How to persist data after logstash pod restart?](https://discuss.elastic.co/t/how-to-persist-data-after-logstash-pod-restart/303108)

<div class="topic-metadata">

**Author:** [@amruth](https://discuss.elastic.co/u/amruth)\
**Replies:** 0\
**Last updated:** [April 25, 2022, 1:35am UTC](https://discuss.elastic.co/t/how-to-persist-data-after-logstash-pod-restart/303108 "2022-04-25T01:35:27Z")

</div>

Hello All, I am using Logstash helm chart. I want to persist a file after logstash pod restart. For that I can see an option persistence: enabled: true But there is no much documentation on it on how to pass variabl…

---

## [Logstash Kafka SASL\_PLAIN input plugin config](https://discuss.elastic.co/t/logstash-kafka-sasl-plain-input-plugin-config/303107)

<div class="topic-metadata">

**Author:** [@Prateek\_Tiwari](https://discuss.elastic.co/u/Prateek_Tiwari)\
**Replies:** 0\
**Last updated:** [April 24, 2022, 10:04pm UTC](https://discuss.elastic.co/t/logstash-kafka-sasl-plain-input-plugin-config/303107 "2022-04-24T22:04:49Z")

</div>

Hi, I have been trying to connect logstash to my remote kafka instance, which has SASL\_PLAIN authentication method, but still not able establish the connection and getting the following error : org.apache.kafka.clients…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=143)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=145)
