# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=148

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 149

---

## [Join two csv files](https://discuss.elastic.co/t/join-two-csv-files/301949)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 1\
**Last updated:** [April 8, 2022, 2:25pm UTC](https://discuss.elastic.co/t/join-two-csv-files/301949 "2022-04-08T14:25:55Z")

</div>

Hello! I have 2 csv files that share a common field and I would like to pass 2 fields from one of the files to the other. The functionality that I want is the same that I usually have with the Elasticsearch filter obta…

---

## [Impossible to rename a field](https://discuss.elastic.co/t/impossible-to-rename-a-field/301956)

<div class="topic-metadata">

**Author:** [@mehdielfi](https://discuss.elastic.co/u/mehdielfi)\
**Replies:** 0\
**Last updated:** [April 8, 2022, 11:06am UTC](https://discuss.elastic.co/t/impossible-to-rename-a-field/301956 "2022-04-08T11:06:48Z")

</div>

Hi i struggle to find the solution i try to rename a JSON field from X-Global-Transaction-Id to X-Global-Transaction-ID Here is the filter logstash filter { mutate { rename =\> {"\[response\_http\_head…

---

## [Logstash Filter, is there a better way than mine](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879)

<div class="topic-metadata">

**Author:** [@cRaZyT](https://discuss.elastic.co/u/cRaZyT)\
**Replies:** 3\
**Last updated:** [April 8, 2022, 7:57am UTC](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879 "2022-04-08T07:57:40Z")

</div>

Hi, I have the following Logstash filter, which works, but I find it anything but good, that should work better, right? Input: "The container group started for TEST" if "The container group started for" in \[messa…

---

## [Schedule salesforce plugin Logstash](https://discuss.elastic.co/t/schedule-salesforce-plugin-logstash/301873)

<div class="topic-metadata">

**Author:** [@Simone1](https://discuss.elastic.co/u/Simone1)\
**Replies:** 2\
**Last updated:** [April 8, 2022, 7:06am UTC](https://discuss.elastic.co/t/schedule-salesforce-plugin-logstash/301873 "2022-04-08T07:06:07Z")

</div>

Hi, i'm trying to pull data from salesforce to Elasticsearch through Logstash but i didn't find something similar to the schedule parameter of the JDBC plugin. Any idea on how can i schedule the input? I can't run it m…

---

## [Logstash pipeline configuration. Can someone please hep me? Thank you](https://discuss.elastic.co/t/logstash-pipeline-configuration-can-someone-please-hep-me-thank-you/301891)

<div class="topic-metadata">

**Author:** [@sazeens1](https://discuss.elastic.co/u/sazeens1)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 3:33pm UTC](https://discuss.elastic.co/t/logstash-pipeline-configuration-can-someone-please-hep-me-thank-you/301891 "2022-04-07T15:33:05Z")

</div>

Hello Everyone, Can someone please help me on this one? data in the kafka topic test sample: { "id": "2001", "name": "XYZ", "address" : "safwq", "phone": "1656161" } Sample Logstash configuration for creating a s…

---

## [JSON Parse Failure](https://discuss.elastic.co/t/json-parse-failure/301892)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 1\
**Last updated:** [April 7, 2022, 4:37pm UTC](https://discuss.elastic.co/t/json-parse-failure/301892 "2022-04-07T16:37:40Z")

</div>

I have the following pipeline config: input { file { type =\> "json" path =\> \[ C:/temp/\*.json" \] start\_position =\> "beginnning" codec =\> multiline { pattern =\> "^ZsExDrC" what =\> "previous" …

---

## [Logstash doesn't send events to Elasticsearch](https://discuss.elastic.co/t/logstash-doesnt-send-events-to-elasticsearch/301887)

<div class="topic-metadata">

**Author:** [@Denis\_Abreu](https://discuss.elastic.co/u/Denis_Abreu)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 3:13pm UTC](https://discuss.elastic.co/t/logstash-doesnt-send-events-to-elasticsearch/301887 "2022-04-07T15:13:32Z")

</div>

Hi! Could anyone tell me what could be wrong? I'm using ELK in Docker and trying to send Elastic log to itself via Filebeat \> Logstash filebeat.yml filebeat.config: modules: path: ${path.config}/modules.d/\*.yml…

---

## [Logstash Filter issue](https://discuss.elastic.co/t/logstash-filter-issue/300950)

<div class="topic-metadata">

**Author:** [@cRaZyT](https://discuss.elastic.co/u/cRaZyT)\
**Replies:** 5\
**Last updated:** [April 7, 2022, 1:49pm UTC](https://discuss.elastic.co/t/logstash-filter-issue/300950 "2022-04-07T13:49:11Z")

</div>

Hi, I have a problem with a logstash filter. The message which has to be filtered looks like: Imported data: {"total":10,"valid":7,"violations":{"missing":\["359072065634251","359072065633741"\],"Data":\["35907206563425…

---

## [Logstash is stopping becuase SystemExit Error](https://discuss.elastic.co/t/logstash-is-stopping-becuase-systemexit-error/299746)

<div class="topic-metadata">

**Author:** [@goutham\_eai](https://discuss.elastic.co/u/goutham_eai)\
**Replies:** 1\
**Last updated:** [April 7, 2022, 8:28am UTC](https://discuss.elastic.co/t/logstash-is-stopping-becuase-systemexit-error/299746 "2022-04-07T08:28:47Z")

</div>

Hi All, I have upgraded the log stash from 7.8.0 to 7.16.2,After upgrading i am getting below error. \[2022-03-15T13:51:28,568\]\[DEBUG\]\[logstash.modules.scaffold\] Found module {:module\_name=\>"fb\_apache", :directory=\>"/us…

---

## [Logstash-plugin command does not work as expected](https://discuss.elastic.co/t/logstash-plugin-command-does-not-work-as-expected/300857)

<div class="topic-metadata">

**Author:** [@mpride63](https://discuss.elastic.co/u/mpride63)\
**Replies:** 1\
**Last updated:** [April 7, 2022, 7:51am UTC](https://discuss.elastic.co/t/logstash-plugin-command-does-not-work-as-expected/300857 "2022-04-07T07:51:49Z")

</div>

I have Logstash working in a basic test scenario on a Windows server but I need to install a plugin. The problem is that the plugin command doesn't seem to work. No matter what option I run the logstash-plugin.bat with…

---

## [Logstash-input-file scans non latin character file name cause InvalidPathException and stopped working](https://discuss.elastic.co/t/logstash-input-file-scans-non-latin-character-file-name-cause-invalidpathexception-and-stopped-working/301818)

<div class="topic-metadata">

**Author:** [@lixplor](https://discuss.elastic.co/u/lixplor)\
**Replies:** 1\
**Last updated:** [April 7, 2022, 3:37am UTC](https://discuss.elastic.co/t/logstash-input-file-scans-non-latin-character-file-name-cause-invalidpathexception-and-stopped-working/301818 "2022-04-07T03:37:14Z")

</div>

Hi, I'm using Logstash 6.8.23 with file input plugin 4.1.18 on a JRE 8 env. OS is suse11 and system default locale is zh\_CN.gbk. When Logstash collecting logs, it reached a file with non-latin name. eg. 你好.xml. Then Lo…

---

## [Close/flush/reset syslog input connection on logstash](https://discuss.elastic.co/t/close-flush-reset-syslog-input-connection-on-logstash/301813)

<div class="topic-metadata">

**Author:** [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Replies:** 2\
**Last updated:** [April 7, 2022, 2:07am UTC](https://discuss.elastic.co/t/close-flush-reset-syslog-input-connection-on-logstash/301813 "2022-04-07T02:07:42Z")

</div>

Hello, I'm handling logstash syslog input from pcf, the log can be ingested, and there is no problem with that, but when I check the file descriptor and open connection on the specific port, they kept increasing is th…

---

## [Elastic Search Logstash how to query all fields and get all fields into pipeline?](https://discuss.elastic.co/t/elastic-search-logstash-how-to-query-all-fields-and-get-all-fields-into-pipeline/301810)

<div class="topic-metadata">

**Author:** [@MLsuper](https://discuss.elastic.co/u/MLsuper)\
**Replies:** 0\
**Last updated:** [April 7, 2022, 12:19am UTC](https://discuss.elastic.co/t/elastic-search-logstash-how-to-query-all-fields-and-get-all-fields-into-pipeline/301810 "2022-04-07T00:19:22Z")

</div>

So I have a logstash pipeline that is currently setup with this: for a query input { hosts =\> ... query =\> '{ "query": { "match\_all": {} }}' target =\> "\[@metasource\]\[\_source\]" index…

---

## [Logstash input for oracle database](https://discuss.elastic.co/t/logstash-input-for-oracle-database/301683)

<div class="topic-metadata">

**Author:** [@altink](https://discuss.elastic.co/u/altink)\
**Replies:** 2\
**Last updated:** [April 6, 2022, 9:46pm UTC](https://discuss.elastic.co/t/logstash-input-for-oracle-database/301683 "2022-04-06T21:46:29Z")

</div>

I have an Bitnami virtual ova distribution, ELK 7.17 on Debian 10. Elastic, Kibana and Logstash run as services (daemons). I have put the logstash config file logstash-ora-01.conf under /opt/bitnami/logstash/config in…

---

## [How to get logstash to read/process multiple log files at the same time?](https://discuss.elastic.co/t/how-to-get-logstash-to-read-process-multiple-log-files-at-the-same-time/301710)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [April 6, 2022, 7:34pm UTC](https://discuss.elastic.co/t/how-to-get-logstash-to-read-process-multiple-log-files-at-the-same-time/301710 "2022-04-06T19:34:33Z")

</div>

It seems that logstash doesnt read multiple files in the directory at the same time , what am i missing ? how do i get logstash to read all three files here ? root@dev-elk-app02:/app/input# lsof \* COMMAND PID USER FD…

---

## [Logstash fail while running with opensearch](https://discuss.elastic.co/t/logstash-fail-while-running-with-opensearch/301768)

<div class="topic-metadata">

**Author:** [@abhaypersistent](https://discuss.elastic.co/u/abhaypersistent)\
**Replies:** 2\
**Last updated:** [April 6, 2022, 2:05pm UTC](https://discuss.elastic.co/t/logstash-fail-while-running-with-opensearch/301768 "2022-04-06T14:05:29Z")

</div>

I am getting this error. "Using bundled JDK: C:\\Users\\abhay\_pandey\\Documents\\GitHub\\logsdash\\logstash-8.1.2-windows-x86\_64\\logstash-8.1.2\\jdk\\bin\\java.exe" OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC wa…

---

## [Hi, I am trying to join Kibana and Nagios](https://discuss.elastic.co/t/hi-i-am-trying-to-join-kibana-and-nagios/301426)

<div class="topic-metadata">

**Author:** [@nour41\_nour41](https://discuss.elastic.co/u/nour41_nour41)\
**Replies:** 7\
**Last updated:** [April 6, 2022, 1:35pm UTC](https://discuss.elastic.co/t/hi-i-am-trying-to-join-kibana-and-nagios/301426 "2022-04-06T13:35:07Z")

</div>

Hi, I am trying to join Kibana and Nagios, following this link: https://www.elastic.co/es/blog/integrating-nagios-checks-with-logstash But I get some errors which I cant resolve it, any ideas? Thanks. root@nagios:/ho…

---

## [Logstash output is not generating file with current date when timestamp field not available](https://discuss.elastic.co/t/logstash-output-is-not-generating-file-with-current-date-when-timestamp-field-not-available/301752)

<div class="topic-metadata">

**Author:** [@sagarpatel](https://discuss.elastic.co/u/sagarpatel)\
**Replies:** 2\
**Last updated:** [April 6, 2022, 1:03pm UTC](https://discuss.elastic.co/t/logstash-output-is-not-generating-file-with-current-date-when-timestamp-field-not-available/301752 "2022-04-06T13:03:04Z")

</div>

Hi, I am trying to create output file using logstash file output plugin but when @timestamp field is not available then it is not genearting file with current date. Below is working example where i have added date fil…

---

## [The day of date is always one in kibana and different that elastic search](https://discuss.elastic.co/t/the-day-of-date-is-always-one-in-kibana-and-different-that-elastic-search/300478)

<div class="topic-metadata">

**Author:** [@tarek0811](https://discuss.elastic.co/u/tarek0811)\
**Replies:** 3\
**Last updated:** [April 6, 2022, 9:52am UTC](https://discuss.elastic.co/t/the-day-of-date-is-always-one-in-kibana-and-different-that-elastic-search/300478 "2022-04-06T09:52:10Z")

</div>

Hi, the day of date in kibana is showing always 1 , regardless of the date in my log or in Elasticsearch. i am using elk docker-compose with the latest version. my logstash config: grok { match =\> { "message" =\> \[ …

---

## [Logstash Read and Write from 2 Different Kafka](https://discuss.elastic.co/t/logstash-read-and-write-from-2-different-kafka/301731)

<div class="topic-metadata">

**Author:** [@osy](https://discuss.elastic.co/u/osy)\
**Replies:** 0\
**Last updated:** [April 6, 2022, 9:43am UTC](https://discuss.elastic.co/t/logstash-read-and-write-from-2-different-kafka/301731 "2022-04-06T09:43:36Z")

</div>

Can logstash read from 2 different kafka which has same topic&tag name? Can logstash write these 2 kafka logs to same Elasticsearch? Example: input { kafka { codec =\> “json” bootstrap\_servers =\> “172.16.1.15:9092” to…

---

## [Grok pattern construction](https://discuss.elastic.co/t/grok-pattern-construction/301610)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 2\
**Last updated:** [April 6, 2022, 9:16am UTC](https://discuss.elastic.co/t/grok-pattern-construction/301610 "2022-04-06T09:16:47Z")

</div>

Hi, I need help constructing the grok pattern for the following log messages Fri Mar 18 17:43:27 2022 : Info: Debugger not attached Fri Mar 18 17:43:27 2022 : Info: Loaded virtual server inner-tunnel Fri Mar 18 17:43:27…

---

## [Problem starting nagioscheckbeat on nagios server](https://discuss.elastic.co/t/problem-starting-nagioscheckbeat-on-nagios-server/301720)

<div class="topic-metadata">

**Author:** [@nour41\_nour41](https://discuss.elastic.co/u/nour41_nour41)\
**Replies:** 0\
**Last updated:** [April 6, 2022, 8:21am UTC](https://discuss.elastic.co/t/problem-starting-nagioscheckbeat-on-nagios-server/301720 "2022-04-06T08:21:37Z")

</div>

nagioscheckbeat.service - One sentence description of the Beat. Loaded: loaded (/usr/lib/systemd/system/nagioscheckbeat.service; enabled; vendor preset: disabled) Active: failed (Result: start-limit) since mer. 2022-04…

---

## [Multiple pipelines with Fileabeat and Logstash](https://discuss.elastic.co/t/multiple-pipelines-with-fileabeat-and-logstash/301652)

<div class="topic-metadata">

**Author:** [@bianca6](https://discuss.elastic.co/u/bianca6)\
**Replies:** 2\
**Last updated:** [April 6, 2022, 7:38am UTC](https://discuss.elastic.co/t/multiple-pipelines-with-fileabeat-and-logstash/301652 "2022-04-06T07:38:38Z")

</div>

Hi, I know this is a known topic, I read different discussions but.. I'm still stuck, if someone could help me I will be grateful. What I'm trying to achieve is this: https://www.elastic.co/guide/en/logstash/current/p…

---

## [Integration of elastic with a service desk app](https://discuss.elastic.co/t/integration-of-elastic-with-a-service-desk-app/301195)

<div class="topic-metadata">

**Author:** [@Vinay\_Menon1](https://discuss.elastic.co/u/Vinay_Menon1)\
**Replies:** 1\
**Last updated:** [April 6, 2022, 4:42am UTC](https://discuss.elastic.co/t/integration-of-elastic-with-a-service-desk-app/301195 "2022-04-06T04:42:49Z")

</div>

Hi Team, I have a query not sure if anyone can help in this We have an in house created ticketing system which one of the developers created this we plan to integrate with elastic. We have multiple client regions & on…

---

## [Logstash package version convention in Debian](https://discuss.elastic.co/t/logstash-package-version-convention-in-debian/301607)

<div class="topic-metadata">

**Author:** [@flavono123](https://discuss.elastic.co/u/flavono123)\
**Replies:** 0\
**Last updated:** [April 5, 2022, 9:12am UTC](https://discuss.elastic.co/t/logstash-package-version-convention-in-debian/301607 "2022-04-05T09:12:51Z")

</div>

Hi all, I just noticed that versions of the logstash in debian packages are different from others: $ lsb\_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 20.04.3 LTS Release: …

---

## [Logstash log4j2.properties logfiles are not deleting](https://discuss.elastic.co/t/logstash-log4j2-properties-logfiles-are-not-deleting/301549)

<div class="topic-metadata">

**Author:** [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Replies:** 9\
**Last updated:** [April 5, 2022, 7:25pm UTC](https://discuss.elastic.co/t/logstash-log4j2-properties-logfiles-are-not-deleting/301549 "2022-04-05T19:25:09Z")

</div>

Looking at the log4j2.properties documentation it says to make the following changes to the log4j2.properties files. I've made them but also made changes for being logstash instead of elastic but I do not see any logfil…

---

## [Logstash RSS Input Plugin SSL Support](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 3\
**Last updated:** [April 5, 2022, 6:17pm UTC](https://discuss.elastic.co/t/logstash-rss-input-plugin-ssl-support/301624 "2022-04-05T18:17:34Z")

</div>

Hello, Does the Logstash RSS Input plugin have the ability to use a specific CA certificate to validate an SSL enabled website? There are no "ca\_cert" settings in the docs that I can find. The specific error I'm getti…

---

## [Logstash 7.17.2 and Elastic 7.10.2 (latest repo version) error: could not connect to compatible elastic version](https://discuss.elastic.co/t/logstash-7-17-2-and-elastic-7-10-2-latest-repo-version-error-could-not-connect-to-compatible-elastic-version/301611)

<div class="topic-metadata">

**Author:** [@Julynell](https://discuss.elastic.co/u/Julynell)\
**Replies:** 1\
**Last updated:** [April 5, 2022, 5:48pm UTC](https://discuss.elastic.co/t/logstash-7-17-2-and-elastic-7-10-2-latest-repo-version-error-could-not-connect-to-compatible-elastic-version/301611 "2022-04-05T17:48:43Z")

</div>

Hi all, So yesterday we installed logstash and Elasticsearch via yum from repo: name=Elasticsearch repository for 7.x packages baseurl=https://artifacts.elastic.co/packages/oss-7.x (forgive me if a misuse terms, I am …

---

## [Logstash-output-syslog plugin with different timezone](https://discuss.elastic.co/t/logstash-output-syslog-plugin-with-different-timezone/301650)

<div class="topic-metadata">

**Author:** [@MatthiasLenhardt](https://discuss.elastic.co/u/MatthiasLenhardt)\
**Replies:** 1\
**Last updated:** [April 5, 2022, 5:17pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-plugin-with-different-timezone/301650 "2022-04-05T17:17:30Z")

</div>

Hi, we are sending events via logstash-output-syslog plugin to a syslog server. The timestamp of the messages at the syslog server are with timezone UTC. Is it possible to change the timestamp only for these events to d…

---

## [Error creating new field with the valu of a nested field](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 3\
**Last updated:** [April 5, 2022, 5:13pm UTC](https://discuss.elastic.co/t/error-creating-new-field-with-the-valu-of-a-nested-field/301505 "2022-04-05T17:13:26Z")

</div>

Hello! im reciving a json with the next format: "field": \[ { "context": "CONTEXTLESS", "value": "x", "key": "subfield1" }, { "context": "CONTEXTLESS", "valu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=147)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=149)
