# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=146

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 147

---

## [Attempted to resurrect connection to dead ES instance, but got an error. {:url=\>"https://elastic:xxxxxx@xxx.xxx.xx.xx:9200/", :error\_type=\>LogStash:error=\>"Elasticsearch Unreachable: \[https://elastic:xxxxxx@xxx.xxx.xx.xx:9200/\]](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-url-https-elastic-xxxxxx-xxx-xxx-xx-xx-9200-error-type-logstash-error-elasticsearch-unreachable-https-elastic-xxxxxx-xxx-xxx-xx-xx-9200/302676)

<div class="topic-metadata">

**Author:** [@sahir](https://discuss.elastic.co/u/sahir)\
**Replies:** 2\
**Last updated:** [April 20, 2022, 11:32am UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error-url-https-elastic-xxxxxx-xxx-xxx-xx-xx-9200-error-type-logstash-error-elasticsearch-unreachable-https-elastic-xxxxxx-xxx-xxx-xx-xx-9200/302676 "2022-04-20T11:32:23Z")

</div>

Hi Team, I tried to connect Elasticsearch from Logstash i'm facing this error. I deployed Elasticsearch using HTTPS and check without passing a certificate its shows an error Elastic hosts is unreachable and again ill te…

---

## [Configuration error in logstash pipeline for multiline sql statements](https://discuss.elastic.co/t/configuration-error-in-logstash-pipeline-for-multiline-sql-statements/302599)

<div class="topic-metadata">

**Author:** [@Vijay\_Balagopal](https://discuss.elastic.co/u/Vijay_Balagopal)\
**Replies:** 2\
**Last updated:** [April 20, 2022, 6:15am UTC](https://discuss.elastic.co/t/configuration-error-in-logstash-pipeline-for-multiline-sql-statements/302599 "2022-04-20T06:15:05Z")

</div>

We have configured centralized pipeline feature for logstash. When we are using a multi line SQL statement we are getting error as below. \[2022-04-18T08:19:05,193\]\[ERROR\]\[logstash.agent \] Failed to execute ac…

---

## [Source ip not getting reflected](https://discuss.elastic.co/t/source-ip-not-getting-reflected/302769)

<div class="topic-metadata">

**Author:** [@ashisharyan](https://discuss.elastic.co/u/ashisharyan)\
**Replies:** 0\
**Last updated:** [April 20, 2022, 6:05am UTC](https://discuss.elastic.co/t/source-ip-not-getting-reflected/302769 "2022-04-20T06:05:41Z")

</div>

We are presently using Elk stack for receiving syslog through file beat. We are receiving logs in logstash and also in Elasticsearch but we are not getting source ip in our dashboard Below is the config file of logsta…

---

## [Metrics not working when using Logstash](https://discuss.elastic.co/t/metrics-not-working-when-using-logstash/302705)

<div class="topic-metadata">

**Author:** [@quim.gomez](https://discuss.elastic.co/u/quim.gomez)\
**Replies:** 13\
**Last updated:** [April 19, 2022, 8:02pm UTC](https://discuss.elastic.co/t/metrics-not-working-when-using-logstash/302705 "2022-04-19T20:02:34Z")

</div>

Hello, I'm using Metricbeats with Logstash. I figured out that when I set Metricbeat to send the output directly to Elasticsearch, I can see all the metrics information in the tab Observability -\> Metrics. But when I se…

---

## [Logstash out put to SQL Server](https://discuss.elastic.co/t/logstash-out-put-to-sql-server/302460)

<div class="topic-metadata">

**Author:** [@Srini12](https://discuss.elastic.co/u/Srini12)\
**Replies:** 3\
**Last updated:** [April 19, 2022, 8:15pm UTC](https://discuss.elastic.co/t/logstash-out-put-to-sql-server/302460 "2022-04-19T20:15:26Z")

</div>

@Badger Hi I am using log stash to output to csv -- it is working fine. However I am trying to write from Elasticsearch to sql server using jdbc driver which is giving error. Can you please try to pick what I am doin…

---

## [Does the Logstash output plugin for RabbitMQ supports RabbitMQ support?](https://discuss.elastic.co/t/does-the-logstash-output-plugin-for-rabbitmq-supports-rabbitmq-support/302741)

<div class="topic-metadata">

**Author:** [@AMBUJ\_DUBEY](https://discuss.elastic.co/u/AMBUJ_DUBEY)\
**Replies:** 0\
**Last updated:** [April 19, 2022, 6:20pm UTC](https://discuss.elastic.co/t/does-the-logstash-output-plugin-for-rabbitmq-supports-rabbitmq-support/302741 "2022-04-19T18:20:41Z")

</div>

Does the Logstash output plugin for RabbitMQ (Rabbitmq output plugin | Logstash Reference \[8.1\] | Elastic) have support for Streams — RabbitMQ

---

## [Logstash Monitoring not available in Kibana](https://discuss.elastic.co/t/logstash-monitoring-not-available-in-kibana/302572)

<div class="topic-metadata">

**Author:** [@mazahir.nazmi](https://discuss.elastic.co/u/mazahir.nazmi)\
**Replies:** 1\
**Last updated:** [April 19, 2022, 7:21am UTC](https://discuss.elastic.co/t/logstash-monitoring-not-available-in-kibana/302572 "2022-04-19T07:21:47Z")

</div>

Hi Guys! i have 2 logstash servers installed. i have enabled the xpack.monitoring for each one of the servers, when i use Kibana and go to "Monitoring" tab, i am not seeing any instance. Please advise Regards, Mazah…

---

## [Logstash is not listening port 5044](https://discuss.elastic.co/t/logstash-is-not-listening-port-5044/302621)

<div class="topic-metadata">

**Author:** [@Meda\_Akshay](https://discuss.elastic.co/u/Meda_Akshay)\
**Replies:** 18\
**Last updated:** [April 18, 2022, 3:34pm UTC](https://discuss.elastic.co/t/logstash-is-not-listening-port-5044/302621 "2022-04-18T15:34:55Z")

</div>

Hi, Am new to Logstash, here my issue is logstash is not listening at port 5044, here is my filebeat configuration output.logstash configured as following # ------------------------------ Logstash Output -------------…

---

## [Unable to retrieve license information from license server {:message=\>"No Available connections"}](https://discuss.elastic.co/t/unable-to-retrieve-license-information-from-license-server-message-no-available-connections/302175)

<div class="topic-metadata">

**Author:** [@sahir](https://discuss.elastic.co/u/sahir)\
**Replies:** 7\
**Last updated:** [April 18, 2022, 7:07am UTC](https://discuss.elastic.co/t/unable-to-retrieve-license-information-from-license-server-message-no-available-connections/302175 "2022-04-18T07:07:00Z")

</div>

Hello team, I'm new to Logstash when im trying to run a logstash i getting the error like this anyone can you please look on it. \[2022-04-11T19:19:07,223\]\[ERROR\]\[logstash.licensechecker.licensereader\] Unable to retriev…

---

## [Multiple logstash indexes to be created from multiple application log files](https://discuss.elastic.co/t/multiple-logstash-indexes-to-be-created-from-multiple-application-log-files/302399)

<div class="topic-metadata">

**Author:** [@ashiqab](https://discuss.elastic.co/u/ashiqab)\
**Replies:** 2\
**Last updated:** [April 18, 2022, 4:01am UTC](https://discuss.elastic.co/t/multiple-logstash-indexes-to-be-created-from-multiple-application-log-files/302399 "2022-04-18T04:01:13Z")

</div>

Hello, Still considerably new to ELK, I have successfully set up Logstash index for one of my application log files as below conf file: server1:/etc/logstash/conf.d # cat /etc/logstash/conf.d/accessinfologs.conf input …

---

## [How to change field types in xml filter](https://discuss.elastic.co/t/how-to-change-field-types-in-xml-filter/302583)

<div class="topic-metadata">

**Author:** [@hagaluly](https://discuss.elastic.co/u/hagaluly)\
**Replies:** 1\
**Last updated:** [April 17, 2022, 11:13pm UTC](https://discuss.elastic.co/t/how-to-change-field-types-in-xml-filter/302583 "2022-04-17T23:13:57Z")

</div>

i have this xml as an example \<testsuites tests="4409" failures="0" errors="0" time="23302.14700000004"\> \<testsuite errors="0" failures="0" hostname="localhost" name="pytest" skipped="1" tests="1" time="0.002" timestamp…

---

## [Cannot connect logstash in filebeat in my Spring Boot ELK](https://discuss.elastic.co/t/cannot-connect-logstash-in-filebeat-in-my-spring-boot-elk/302578)

<div class="topic-metadata">

**Author:** [@jolpol\_9090](https://discuss.elastic.co/u/jolpol_9090)\
**Replies:** 0\
**Last updated:** [April 17, 2022, 6:38pm UTC](https://discuss.elastic.co/t/cannot-connect-logstash-in-filebeat-in-my-spring-boot-elk/302578 "2022-04-17T18:38:04Z")

</div>

I've tried to implement a Spring Boot Elk running with Docker. The reason I've tried is to check logs in Kibana but I have a problem which I couldn't fix it. I cannot see any logs when I work with Docker. I think ther…

---

## [Mantain source IP TCP Output](https://discuss.elastic.co/t/mantain-source-ip-tcp-output/302556)

<div class="topic-metadata">

**Author:** [@SecRobe](https://discuss.elastic.co/u/SecRobe)\
**Replies:** 6\
**Last updated:** [April 17, 2022, 3:26pm UTC](https://discuss.elastic.co/t/mantain-source-ip-tcp-output/302556 "2022-04-17T15:26:45Z")

</div>

Hello, I'm absolutely newbie in Logstash. I'm using Logstash 6.2.3 with a simple input filter (TCP and UDP) and Syslog output, the problem with syslog output (as we know) it's it adds the "logstash" header, I'm trying t…

---

## [Value too large to output (9971 bytes)! First 255 chars are](https://discuss.elastic.co/t/value-too-large-to-output-9971-bytes-first-255-chars-are/302449)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 2\
**Last updated:** [April 17, 2022, 1:56pm UTC](https://discuss.elastic.co/t/value-too-large-to-output-9971-bytes-first-255-chars-are/302449 "2022-04-17T13:56:50Z")

</div>

Hello All, I got the error below while parsing through logstash. \[2022-04-14T16:46:53,545\]\[WARN \]\[logstash.filters.grok \]\[main\]\[71f87e3c7ed04afa020468f007ac1a64411b0298a6452730ffc54f56f8121e61\] Timeout executing gro…

---

## [Logstash Http poller plugin for JIRA](https://discuss.elastic.co/t/logstash-http-poller-plugin-for-jira/302568)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 0\
**Last updated:** [April 17, 2022, 5:39am UTC](https://discuss.elastic.co/t/logstash-http-poller-plugin-for-jira/302568 "2022-04-17T05:39:25Z")

</div>

Hello Guys I want one solution I want JIRA Issue Tickete all record create update delete exapand comment etc. all thing I want to add into Elasticsearch using via http\_poller plugin how can I achive that and what filt…

---

## [Losgtash Ruby split nested fields as new field](https://discuss.elastic.co/t/losgtash-ruby-split-nested-fields-as-new-field/302539)

<div class="topic-metadata">

**Author:** [@Akshay\_Kulkarni](https://discuss.elastic.co/u/Akshay_Kulkarni)\
**Replies:** 2\
**Last updated:** [April 16, 2022, 2:35pm UTC](https://discuss.elastic.co/t/losgtash-ruby-split-nested-fields-as-new-field/302539 "2022-04-16T14:35:25Z")

</div>

Hi, I have below type of events. I m looking to split nested field (group\_kpi\_value) and trying to store in new field. kpi\_name=E & kpi\_value=511871 per chunk. Im able to split single event in to multiple events wi…

---

## [Cacert can not access credentials logstash](https://discuss.elastic.co/t/cacert-can-not-access-credentials-logstash/302536)

<div class="topic-metadata">

**Author:** [@darguello](https://discuss.elastic.co/u/darguello)\
**Replies:** 0\
**Last updated:** [April 16, 2022, 7:07am UTC](https://discuss.elastic.co/t/cacert-can-not-access-credentials-logstash/302536 "2022-04-16T07:07:19Z")

</div>

Hi! I am trying to deploy a cluster with 3 Elasticsearch nodes and both Kibana and Logstash. Moreover, the communication between them must be protected. In order to do so, I have followed the tutorial where it is descri…

---

## [Logstash 8.1 configuration with elasticsearch](https://discuss.elastic.co/t/logstash-8-1-configuration-with-elasticsearch/302533)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 0\
**Last updated:** [April 16, 2022, 2:53am UTC](https://discuss.elastic.co/t/logstash-8-1-configuration-with-elasticsearch/302533 "2022-04-16T02:53:43Z")

</div>

Hello every body, This is my first configuraton of an elk stack 8.1 with autoconfiguration enabled. My cluster is composed of 3 Elasticsearch nodes and a kibana master. I want to configure logstash to index logs to E…

---

## [How to import syslog data into logstash](https://discuss.elastic.co/t/how-to-import-syslog-data-into-logstash/302521)

<div class="topic-metadata">

**Author:** [@trubeat\_elk](https://discuss.elastic.co/u/trubeat_elk)\
**Replies:** 0\
**Last updated:** [April 15, 2022, 8:19pm UTC](https://discuss.elastic.co/t/how-to-import-syslog-data-into-logstash/302521 "2022-04-15T20:19:04Z")

</div>

Hello , I am newbie in ELK.This is the first time I am working on ELK .I want to know how to import syslog data into Logtash and then see that data in Kibana. Sample events looks like below. date/time host…

---

## [Logstash Queues Management](https://discuss.elastic.co/t/logstash-queues-management/302493)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 0\
**Last updated:** [April 15, 2022, 9:14am UTC](https://discuss.elastic.co/t/logstash-queues-management/302493 "2022-04-15T09:14:50Z")

</div>

Hi, I'm wondering if there is a way to gracefully purge all events in either DLQ (Dead Letter Queue) / PQ (Persistent Queue)? By purging, I mean to drop all those pending events so that I could bring up a dead Logstash A…

---

## [Logstash Http poller plugin for JIRA](https://discuss.elastic.co/t/logstash-http-poller-plugin-for-jira/302486)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 0\
**Last updated:** [April 15, 2022, 7:09am UTC](https://discuss.elastic.co/t/logstash-http-poller-plugin-for-jira/302486 "2022-04-15T07:09:51Z")

</div>

Hello Guys I want All Jira Issue Action Report to Elasticsearch my requirement is for full issue traking in to Elasticsearch please help me ASAP.

---

## [How to extract fields from "message" field in logstash?](https://discuss.elastic.co/t/how-to-extract-fields-from-message-field-in-logstash/302470)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 1\
**Last updated:** [April 14, 2022, 9:15pm UTC](https://discuss.elastic.co/t/how-to-extract-fields-from-message-field-in-logstash/302470 "2022-04-14T21:15:44Z")

</div>

hello, I need help in extracting the fields that come in the "message" field, in case all the fields need to be extracted, can anyone help? here's the field: "message": "Apr 14 16:11:36 tutorial2022-1 sshd\[8454\]: PAM 2…

---

## [Advice to get different unstrctured log data into structured format](https://discuss.elastic.co/t/advice-to-get-different-unstrctured-log-data-into-structured-format/302433)

<div class="topic-metadata">

**Author:** [@Bavaria](https://discuss.elastic.co/u/Bavaria)\
**Replies:** 0\
**Last updated:** [April 14, 2022, 1:08pm UTC](https://discuss.elastic.co/t/advice-to-get-different-unstrctured-log-data-into-structured-format/302433 "2022-04-14T13:08:17Z")

</div>

I am new to Logstash. I have a processing question. I am getting these kind of logs with Filebeat on the "mmesage" field, from the same host. Sometimes different Files. How would I process to make those Messages I am get…

---

## [Slow handling of documents when large text in a field](https://discuss.elastic.co/t/slow-handling-of-documents-when-large-text-in-a-field/302431)

<div class="topic-metadata">

**Author:** [@lubosvr](https://discuss.elastic.co/u/lubosvr)\
**Replies:** 0\
**Last updated:** [April 14, 2022, 12:34pm UTC](https://discuss.elastic.co/t/slow-handling-of-documents-when-large-text-in-a-field/302431 "2022-04-14T12:34:54Z")

</div>

Hi, We have problems when handling for documents with large content in a single field. We have index with mapping like this: "mappings" : { "dynamic" : "false",... "properties" : { "created" : …

---

## [Netscout arbor legacy syslog parsing - Audit log issue](https://discuss.elastic.co/t/netscout-arbor-legacy-syslog-parsing-audit-log-issue/302340)

<div class="topic-metadata">

**Author:** [@Xor44](https://discuss.elastic.co/u/Xor44)\
**Replies:** 5\
**Last updated:** [April 14, 2022, 12:40pm UTC](https://discuss.elastic.co/t/netscout-arbor-legacy-syslog-parsing-audit-log-issue/302340 "2022-04-14T12:40:58Z")

</div>

Hi Folks , I need your help to resolve the issue below . I'm trying since many days to parse some audit logs .You will find some sample below . Idea is to simply extract these field . Field Need to be extracted …

---

## [Twitter Logstash pipeline stops after a certain period](https://discuss.elastic.co/t/twitter-logstash-pipeline-stops-after-a-certain-period/302425)

<div class="topic-metadata">

**Author:** [@dihiaselma](https://discuss.elastic.co/u/dihiaselma)\
**Replies:** 2\
**Last updated:** [April 14, 2022, 12:31pm UTC](https://discuss.elastic.co/t/twitter-logstash-pipeline-stops-after-a-certain-period/302425 "2022-04-14T12:31:21Z")

</div>

Hello; I have created a pipeline logstash to retrieve data from twitter, then insert these data into Elasticsearch. It works fine for a certain period then, it stops without any error in logs. I have just to restart i…

---

## [Logstash UDP input losing messages](https://discuss.elastic.co/t/logstash-udp-input-losing-messages/302411)

<div class="topic-metadata">

**Author:** [@dwjvaughan](https://discuss.elastic.co/u/dwjvaughan)\
**Replies:** 0\
**Last updated:** [April 14, 2022, 9:23am UTC](https://discuss.elastic.co/t/logstash-udp-input-losing-messages/302411 "2022-04-14T09:23:54Z")

</div>

I'm using the official logstash container (7.17.0) to ingest some logs over UDP (~8k a minute, with spikes probably around 30k a minute). This is running in AWS Fargate (at the moment 2 containers running, with a load ba…

---

## [Send all data to one index and specific fields to another at same time](https://discuss.elastic.co/t/send-all-data-to-one-index-and-specific-fields-to-another-at-same-time/302381)

<div class="topic-metadata">

**Author:** [@adrianfusco](https://discuss.elastic.co/u/adrianfusco)\
**Replies:** 2\
**Last updated:** [April 14, 2022, 8:50am UTC](https://discuss.elastic.co/t/send-all-data-to-one-index-and-specific-fields-to-another-at-same-time/302381 "2022-04-14T08:50:24Z")

</div>

Hello, I've been reading for a long time in different sources if it's possible to send all data processed by logstash to one index and at the same time send just some specific fields of this data to another different in…

---

## [Use field name in datastream namespace or dataset](https://discuss.elastic.co/t/use-field-name-in-datastream-namespace-or-dataset/302188)

<div class="topic-metadata">

**Author:** [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Replies:** 5\
**Last updated:** [April 14, 2022, 8:17am UTC](https://discuss.elastic.co/t/use-field-name-in-datastream-namespace-or-dataset/302188 "2022-04-14T08:17:11Z")

</div>

I'm trying to use a field with logstash output to Elasticsearch but I can't seem to get this to work. My configuration is as below: output { elasticsearch { hosts =\> "es01" data\_stream =\> "true" data…

---

## [Elastic Search Logstash input -\>output AWS s3](https://discuss.elastic.co/t/elastic-search-logstash-input-output-aws-s3/302376)

<div class="topic-metadata">

**Author:** [@MLsuper](https://discuss.elastic.co/u/MLsuper)\
**Replies:** 0\
**Last updated:** [April 13, 2022, 7:35pm UTC](https://discuss.elastic.co/t/elastic-search-logstash-input-output-aws-s3/302376 "2022-04-13T19:35:14Z")

</div>

Is it possible not to query all the data(duplication) when we ingest data from Elasticsearch input -\>aws s3 output? I want to ingest the data daily but it would duplicate it querying all the data from the start again bu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=145)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=147)
