# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=145

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 146

---

## [Logstash-CIDR Plugin](https://discuss.elastic.co/t/logstash-cidr-plugin/301990)

<div class="topic-metadata">

**Author:** [@leela](https://discuss.elastic.co/u/leela)\
**Replies:** 12\
**Last updated:** [April 24, 2022, 4:57pm UTC](https://discuss.elastic.co/t/logstash-cidr-plugin/301990 "2022-04-24T16:57:31Z")

</div>

How can we pass multiple IP's and Location names in Logstash config file with CIDR plugin for Source and Destination

---

## [Logstash multiple output blocking: output blocking with multiple output using the isolation pattern](https://discuss.elastic.co/t/logstash-multiple-output-blocking-output-blocking-with-multiple-output-using-the-isolation-pattern/303078)

<div class="topic-metadata">

**Author:** [@yeppazu](https://discuss.elastic.co/u/yeppazu)\
**Replies:** 4\
**Last updated:** [April 23, 2022, 9:37pm UTC](https://discuss.elastic.co/t/logstash-multiple-output-blocking-output-blocking-with-multiple-output-using-the-isolation-pattern/303078 "2022-04-23T21:37:49Z")

</div>

Hello everyone, we have a trouble with a pipeline in logstash (7.17), with multiple output and isolator pattern. We have adopted the solution suggested in: In our case, input is Winlogbeat and the two outputs are: El…

---

## [Logstash CSV mutate, split and filter](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 5\
**Last updated:** [April 23, 2022, 9:44am UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084 "2022-04-23T09:44:15Z")

</div>

Hello, I hope my message finds the Elastic community safe and healthy. I am trying to import CSV files wherein I want to create a new field - tld using data from one of the columns being imported. Source Column name…

---

## [Extract data from Elastic search using pem cert](https://discuss.elastic.co/t/extract-data-from-elastic-search-using-pem-cert/302849)

<div class="topic-metadata">

**Author:** [@newelastic](https://discuss.elastic.co/u/newelastic)\
**Replies:** 8\
**Last updated:** [April 22, 2022, 7:59pm UTC](https://discuss.elastic.co/t/extract-data-from-elastic-search-using-pem-cert/302849 "2022-04-22T19:59:32Z")

</div>

Hello, I'm new to ELK stack and we are trying to extract data from ES via logstash pipeline from existing system. Below is the logstash input pipeline being used for extracting data and my output pipeline targeted to K…

---

## [How to use the value from kubernetes metadata in S3 output](https://discuss.elastic.co/t/how-to-use-the-value-from-kubernetes-metadata-in-s3-output/302975)

<div class="topic-metadata">

**Author:** [@user2416](https://discuss.elastic.co/u/user2416)\
**Replies:** 1\
**Last updated:** [April 22, 2022, 4:38pm UTC](https://discuss.elastic.co/t/how-to-use-the-value-from-kubernetes-metadata-in-s3-output/302975 "2022-04-22T16:38:22Z")

</div>

Hi, I am trying to use the service name which will get from kubernetes metadata to use in S3 output to construct prefix, how can I use that field value in output?

---

## [Date conversion with Logstash](https://discuss.elastic.co/t/date-conversion-with-logstash/302947)

<div class="topic-metadata">

**Author:** [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Replies:** 4\
**Last updated:** [April 22, 2022, 2:04pm UTC](https://discuss.elastic.co/t/date-conversion-with-logstash/302947 "2022-04-22T14:04:33Z")

</div>

Hello, I currently have a problem for date conversion with Logstash. I receive logs including dates in epoche format (UNIX), so I added the following filters to modify them. Namely, I have multiple date fields, as you c…

---

## [Aggregate similar Logs](https://discuss.elastic.co/t/aggregate-similar-logs/302630)

<div class="topic-metadata">

**Author:** [@Bo-Wyatt](https://discuss.elastic.co/u/Bo-Wyatt)\
**Replies:** 2\
**Last updated:** [April 22, 2022, 11:39am UTC](https://discuss.elastic.co/t/aggregate-similar-logs/302630 "2022-04-22T11:39:32Z")

</div>

Hello, I have SIEM-like logs (with a unique identifier field) in a log flow (two or more logs, in every update/log there's extra info or updaded info). I need to preserve the last log or aggregate all the logs into one w…

---

## [Logstash to elasticsearch ssl connection issue](https://discuss.elastic.co/t/logstash-to-elasticsearch-ssl-connection-issue/302842)

<div class="topic-metadata">

**Author:** [@fabek.75](https://discuss.elastic.co/u/fabek.75)\
**Replies:** 1\
**Last updated:** [April 22, 2022, 8:56am UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-ssl-connection-issue/302842 "2022-04-22T08:56:33Z")

</div>

Hi, I have setup an on-prem dev environment with Elasticsearch 8.x and from a client I'm trying to push some data through a Logstash pipeline (version is 8.1.2-1). It seems, however, Logstash wants absolutely that some …

---

## [Winlogbeat message not parsed](https://discuss.elastic.co/t/winlogbeat-message-not-parsed/302979)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 7\
**Last updated:** [April 22, 2022, 8:25am UTC](https://discuss.elastic.co/t/winlogbeat-message-not-parsed/302979 "2022-04-22T08:25:03Z")

</div>

Hello, I am using elasticstack v8. The messages are sent from winlogbeat -\> kafka - \> logstash -\> elastic. The message is arrived unparsed. Logstash config: input { kafka{ bootstrap\_servers =\> …

---

## [Grok Parsing for multiple patterns in single log file](https://discuss.elastic.co/t/grok-parsing-for-multiple-patterns-in-single-log-file/302948)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 2\
**Last updated:** [April 22, 2022, 5:18am UTC](https://discuss.elastic.co/t/grok-parsing-for-multiple-patterns-in-single-log-file/302948 "2022-04-22T05:18:15Z")

</div>

Hi Everyone, I am writing a grok pattern to parse a log file where i have two types of log lines. 2022-04-13 06:38:24.472 DBG Microsoft.AspNet.server --- Connection Id "Xxxxxxxx" accepted 2022-04-13 06:38:19.330 d…

---

## [S3 input: Unable to list objects. Access Denied](https://discuss.elastic.co/t/s3-input-unable-to-list-objects-access-denied/302380)

<div class="topic-metadata">

**Author:** [@elker](https://discuss.elastic.co/u/elker)\
**Replies:** 1\
**Last updated:** [April 22, 2022, 3:01am UTC](https://discuss.elastic.co/t/s3-input-unable-to-list-objects-access-denied/302380 "2022-04-22T03:01:00Z")

</div>

I am using the s3 input plugin to use assume a role using an aws\_access\_key/secret key and read from a bucket using a date based key. The Logstash role allows AssumeRole, and the bucket allows the role to ListBucket an…

---

## [How to attach Index Lifecycle Policy to indices created by Logstash?](https://discuss.elastic.co/t/how-to-attach-index-lifecycle-policy-to-indices-created-by-logstash/301657)

<div class="topic-metadata">

**Author:** [@pritster5](https://discuss.elastic.co/u/pritster5)\
**Replies:** 5\
**Last updated:** [April 21, 2022, 9:40pm UTC](https://discuss.elastic.co/t/how-to-attach-index-lifecycle-policy-to-indices-created-by-logstash/301657 "2022-04-21T21:40:05Z")

</div>

I have a Logstash Config file that looks like this: input { s3 { bucket =\> "testbucket" region =\> "us-east-1" codec =\> "json" additional\_settings =\> { force\_path\_style =\> …

---

## [Logstash fail to rewrite json files](https://discuss.elastic.co/t/logstash-fail-to-rewrite-json-files/302942)

<div class="topic-metadata">

**Author:** [@Math](https://discuss.elastic.co/u/Math)\
**Replies:** 1\
**Last updated:** [April 21, 2022, 4:41pm UTC](https://discuss.elastic.co/t/logstash-fail-to-rewrite-json-files/302942 "2022-04-21T16:41:16Z")

</div>

Hi, I want to send json files with filebeat to logstash and then logstash rewrite these json files locally. Filebeat version: 8.1.2 Logstash version: 8.1.2 There is my filebeat conf: filebeat.inputs: - type: filest…

---

## [Logstash is not reading some files from filebeat](https://discuss.elastic.co/t/logstash-is-not-reading-some-files-from-filebeat/302570)

<div class="topic-metadata">

**Author:** [@Rohini\_Gadge28](https://discuss.elastic.co/u/Rohini_Gadge28)\
**Replies:** 5\
**Last updated:** [April 21, 2022, 4:38pm UTC](https://discuss.elastic.co/t/logstash-is-not-reading-some-files-from-filebeat/302570 "2022-04-21T16:38:35Z")

</div>

There is data in a folder which is read by filebeat and forwarded to Logstash . So we write to logs file everyday and based on date multiple files(eg. : 2022-03-29-1.log , 2022-03-30-1.log, etc) get created. But somehow…

---

## [Windows Environment Variables not accessible when Logstash is run as a service](https://discuss.elastic.co/t/windows-environment-variables-not-accessible-when-logstash-is-run-as-a-service/302901)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 0\
**Last updated:** [April 21, 2022, 11:14am UTC](https://discuss.elastic.co/t/windows-environment-variables-not-accessible-when-logstash-is-run-as-a-service/302901 "2022-04-21T11:14:32Z")

</div>

I have used Windows environment variables in Logstash config file. Following command was used to create env variable: $env:MW\_Index = 'mw-test-index-temp' In my config file, I have called this index. mutate { add\_fie…

---

## [Logstash Elasticsearch Filter Lookup 99% not finding if End to close to Start?](https://discuss.elastic.co/t/logstash-elasticsearch-filter-lookup-99-not-finding-if-end-to-close-to-start/302695)

<div class="topic-metadata">

**Author:** [@Dan\_M](https://discuss.elastic.co/u/Dan_M)\
**Replies:** 2\
**Last updated:** [April 21, 2022, 11:01am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-lookup-99-not-finding-if-end-to-close-to-start/302695 "2022-04-21T11:01:32Z")

</div>

Hi, I am trying to do the standard End items enrichment with the Start item details. filter{ if \[benchmarkType\] == "End" { elasticsearch { hosts =\> \["MY-IP:9200"\] index =\> "prod-\*" …

---

## [Logstash Unable to Retrieve License Info](https://discuss.elastic.co/t/logstash-unable-to-retrieve-license-info/302900)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 0\
**Last updated:** [April 21, 2022, 11:02am UTC](https://discuss.elastic.co/t/logstash-unable-to-retrieve-license-info/302900 "2022-04-21T11:02:42Z")

</div>

I have enabled SSL security with the password security as well on my Elasticsearch and Kibana. Whole cluster is behaving correctly as I have done this on ELK stack 7.13 as well. But Now while I am doing the same thing on…

---

## [Add\_field not working](https://discuss.elastic.co/t/add-field-not-working/302887)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 2\
**Last updated:** [April 21, 2022, 10:31am UTC](https://discuss.elastic.co/t/add-field-not-working/302887 "2022-04-21T10:31:10Z")

</div>

Hi, the following is my logstash conf file for passing a few sample audit log messages sample messages: type=SYSCALL msg=audit(1547800652.003:103): arch=c00000b7 syscall=200 success=no exit=-13 a0=c a1=ffffe65a3648 a2=…

---

## [Break down unknown number of iteration with same pattern](https://discuss.elastic.co/t/break-down-unknown-number-of-iteration-with-same-pattern/302878)

<div class="topic-metadata">

**Author:** [@julien34](https://discuss.elastic.co/u/julien34)\
**Replies:** 2\
**Last updated:** [April 21, 2022, 9:48am UTC](https://discuss.elastic.co/t/break-down-unknown-number-of-iteration-with-same-pattern/302878 "2022-04-21T09:48:52Z")

</div>

Hello there ! I'm new to ELK and GROK filter, I look for a long time but cannot find a proper way to achieve what I want to do, so I'm asking here. I have log coming via filebeat, the "message" field containing my orig…

---

## [Using Windows ENV variables in Logstash](https://discuss.elastic.co/t/using-windows-env-variables-in-logstash/302883)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 1\
**Last updated:** [April 21, 2022, 9:23am UTC](https://discuss.elastic.co/t/using-windows-env-variables-in-logstash/302883 "2022-04-21T09:23:43Z")

</div>

I have set an environment variable in windows using Powershell with following command: $env:MW\_Index = 'mw-test-index' In my logstash.config file, I am trying to use this variable in the following way: mutate { add\_fi…

---

## [Delete file logstash](https://discuss.elastic.co/t/delete-file-logstash/302314)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 5\
**Last updated:** [April 21, 2022, 8:47am UTC](https://discuss.elastic.co/t/delete-file-logstash/302314 "2022-04-21T08:47:57Z")

</div>

Hi, I have a small problem i have logs and i read it with filebeat filebeat.yml - type: log enabled: true paths: - D:\\elastic\_stack\\LOGS\\CMS\_LOGS\\\* fields: kafka\_topic: "kafka-topic-cms-test1" mult…

---

## [Logstash - java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/302879)

<div class="topic-metadata">

**Author:** [@sahir](https://discuss.elastic.co/u/sahir)\
**Replies:** 0\
**Last updated:** [April 21, 2022, 7:38am UTC](https://discuss.elastic.co/t/logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/302879 "2022-04-21T07:38:46Z")

</div>

Hello team, I try to run the logstash.conf file im facing the error like WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.headius.backport9.modules.Modules (file:/us…

---

## [Jira logs not getting every events using http poller](https://discuss.elastic.co/t/jira-logs-not-getting-every-events-using-http-poller/302671)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 1\
**Last updated:** [April 21, 2022, 5:28am UTC](https://discuss.elastic.co/t/jira-logs-not-getting-every-events-using-http-poller/302671 "2022-04-21T05:28:24Z")

</div>

Hello Every one I am using http poller to get issue event from jira but i am not getting every event like update create delete logs off issue any one please help .. please follow my configuration input { http\_poller { …

---

## [Logstash Postgresql error](https://discuss.elastic.co/t/logstash-postgresql-error/302864)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 2\
**Last updated:** [April 21, 2022, 4:44am UTC](https://discuss.elastic.co/t/logstash-postgresql-error/302864 "2022-04-21T04:44:29Z")

</div>

Dear Team, I faced the below error while fetching logs from postgresql DB ERROR\] 2022-04-20 10:26:51.485 \[Converge PipelineAction::Create\] jdbc - Missing a required setting for the jdbc input plugin: input { jdbc { …

---

## [Unable to install logstash kusto plugin using 6.4.2 version](https://discuss.elastic.co/t/unable-to-install-logstash-kusto-plugin-using-6-4-2-version/302857)

<div class="topic-metadata">

**Author:** [@newelastic](https://discuss.elastic.co/u/newelastic)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 11:19pm UTC](https://discuss.elastic.co/t/unable-to-install-logstash-kusto-plugin-using-6-4-2-version/302857 "2022-04-20T23:19:19Z")

</div>

Hello, I'm using logstash 6.4.2 version and trying to install kusto plugin. Logstash is throwing an error bin/logstash-plugin install logstash-output-kusto Cannot find Java 1.5 or higher. But, my machine has Java 8. …

---

## [Logstash pipeline date filter doesn't work](https://discuss.elastic.co/t/logstash-pipeline-date-filter-doesnt-work/302386)

<div class="topic-metadata">

**Author:** [@zerojin63](https://discuss.elastic.co/u/zerojin63)\
**Replies:** 0\
**Last updated:** [April 14, 2022, 2:23am UTC](https://discuss.elastic.co/t/logstash-pipeline-date-filter-doesnt-work/302386 "2022-04-14T02:23:21Z")

</div>

Hi, I wanted to display timestamp of a certain index in two ways, one in my local timezone (in evt\_time field) and the other in Los Angeles timezone (in evt\_time\_america field). So I added 'date' filter to my logstash …

---

## [How can use patterns\_files\_glob in grok？](https://discuss.elastic.co/t/how-can-use-patterns-files-glob-in-grok/302792)

<div class="topic-metadata">

**Author:** [@lingminzeng](https://discuss.elastic.co/u/lingminzeng)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 4:47pm UTC](https://discuss.elastic.co/t/how-can-use-patterns-files-glob-in-grok/302792 "2022-04-20T16:47:28Z")

</div>

My config: patterns\_files\_glob =\> "test.txt" But it not working and output error

---

## [Error when building logstash-filter-elasticsearch plugin](https://discuss.elastic.co/t/error-when-building-logstash-filter-elasticsearch-plugin/302838)

<div class="topic-metadata">

**Author:** [@jong99](https://discuss.elastic.co/u/jong99)\
**Replies:** 0\
**Last updated:** [April 20, 2022, 4:29pm UTC](https://discuss.elastic.co/t/error-when-building-logstash-filter-elasticsearch-plugin/302838 "2022-04-20T16:29:48Z")

</div>

I'm trying to track down an issue I'm having with the logstash-filter-elasticsearch plugin so I've checked out the code and am trying to build from source. Running inside a ruby:9.2 docker container I'm checking out the…

---

## [Logstash does not open Port for Data-Input](https://discuss.elastic.co/t/logstash-does-not-open-port-for-data-input/302305)

<div class="topic-metadata">

**Author:** [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Replies:** 1\
**Last updated:** [April 20, 2022, 1:06pm UTC](https://discuss.elastic.co/t/logstash-does-not-open-port-for-data-input/302305 "2022-04-20T13:06:39Z")

</div>

Hi there, soo i'm trying to get a new cluster to work - everythings setup fine. We're using CentOS 7, Elasticsearch 7.15, Logstash 7.15. The service is running fine - no errors when running it in debug mode. There's…

---

## [Reparsing / processing old indexes with new separation files in Logstash depending on path logs](https://discuss.elastic.co/t/reparsing-processing-old-indexes-with-new-separation-files-in-logstash-depending-on-path-logs/302807)

<div class="topic-metadata">

**Author:** [@dapmI](https://discuss.elastic.co/u/dapmI)\
**Replies:** 0\
**Last updated:** [April 20, 2022, 12:01pm UTC](https://discuss.elastic.co/t/reparsing-processing-old-indexes-with-new-separation-files-in-logstash-depending-on-path-logs/302807 "2022-04-20T12:01:23Z")

</div>

Hello, I'm currently in the process to separate indexes depending on the path logs. Here we had to separate logs depending on the source files to better apply lifecycle policy. Currently we have one common index with lo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=144)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=146)
