# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=152

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 153

---

## [Event severity cisco for logstash](https://discuss.elastic.co/t/event-severity-cisco-for-logstash/300312)

<div class="topic-metadata">

**Author:** [@jojodd](https://discuss.elastic.co/u/jojodd)\
**Replies:** 2\
**Last updated:** [March 24, 2022, 10:20am UTC](https://discuss.elastic.co/t/event-severity-cisco-for-logstash/300312 "2022-03-24T10:20:56Z")

</div>

hello, if \[event\]\[severity\] == 7 - \> does not work in a pipeline to create a new index with do you have any idea how to make it work? infra with filebeat -\> logstash -\> Elasticsearch

---

## [Kafka with ELK](https://discuss.elastic.co/t/kafka-with-elk/300477)

<div class="topic-metadata">

**Author:** [@jojodd](https://discuss.elastic.co/u/jojodd)\
**Replies:** 2\
**Last updated:** [March 24, 2022, 10:17am UTC](https://discuss.elastic.co/t/kafka-with-elk/300477 "2022-03-24T10:17:08Z")

</div>

When installing kafka with the ELK suite, is it mandatory to install zookeeper if you take the latest version? help

---

## [Logstash Metricbeat field calculation](https://discuss.elastic.co/t/logstash-metricbeat-field-calculation/300242)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [March 24, 2022, 9:58am UTC](https://discuss.elastic.co/t/logstash-metricbeat-field-calculation/300242 "2022-03-24T09:58:54Z")

</div>

I'm implementing ruby code through logstash pipeline,Unable to get desired fields created in kibana,what would be right approach to code in order to get desired result? Want to get CPU % by adding two fileds and divide …

---

## [Logstash set up issue](https://discuss.elastic.co/t/logstash-set-up-issue/300160)

<div class="topic-metadata">

**Author:** [@ashiqab](https://discuss.elastic.co/u/ashiqab)\
**Replies:** 4\
**Last updated:** [March 24, 2022, 6:06am UTC](https://discuss.elastic.co/t/logstash-set-up-issue/300160 "2022-03-24T06:06:33Z")

</div>

Hello, I am struggling with my logstash set up, which doesn't seem to be connected to the ELK stack. I cannot see Logstash under Stack Monitoring: However, I can see my custom log data which is ingested using logst…

---

## [Can max document size for Json plugin be increased? Seems to be 32768 now](https://discuss.elastic.co/t/can-max-document-size-for-json-plugin-be-increased-seems-to-be-32768-now/300227)

<div class="topic-metadata">

**Author:** [@paulov](https://discuss.elastic.co/u/paulov)\
**Replies:** 2\
**Last updated:** [March 23, 2022, 8:44pm UTC](https://discuss.elastic.co/t/can-max-document-size-for-json-plugin-be-increased-seems-to-be-32768-now/300227 "2022-03-23T20:44:26Z")

</div>

When using a Json filter in a logstash pipeline, I run into a size problem. I get an error indicating a max size of 32769 (2^15): :exception=\>#\<LogStash::Json::ParserError: Unexpected end-of-input in VALUE\_STRING at \[S…

---

## [Logstash not sending logs to Elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-logs-to-elasticsearch/300037)

<div class="topic-metadata">

**Author:** [@wallace84](https://discuss.elastic.co/u/wallace84)\
**Replies:** 11\
**Last updated:** [March 23, 2022, 5:46pm UTC](https://discuss.elastic.co/t/logstash-not-sending-logs-to-elasticsearch/300037 "2022-03-23T17:46:32Z")

</div>

Hello, I have been trying for some time to send a simple log to Elasticsearch and after trying a very simple example, the logs are not been sent to Elasticsearch from logstash. Services: In same server for this test O…

---

## [Warning 'Relying on default value of \`pipeline.ecs\_compatibility' after updating to logstash 7.16.1](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018)

<div class="topic-metadata">

**Author:** [@d71247](https://discuss.elastic.co/u/d71247)\
**Replies:** 22\
**Last updated:** [March 23, 2022, 2:52pm UTC](https://discuss.elastic.co/t/warning-relying-on-default-value-of-pipeline-ecs-compatibility-after-updating-to-logstash-7-16-1/292018 "2022-03-23T14:52:31Z")

</div>

Hello, I just updated my Logstash to 7.16.1... but I noticed errors in my conf when starting Logstash.\* the same conf of Logstash works well in version 7.9.1 How do to fix this warning ? Anyone else experienced this? …

---

## [Parsing array of elements](https://discuss.elastic.co/t/parsing-array-of-elements/300462)

<div class="topic-metadata">

**Author:** [@eliz](https://discuss.elastic.co/u/eliz)\
**Replies:** 3\
**Last updated:** [March 23, 2022, 3:01pm UTC](https://discuss.elastic.co/t/parsing-array-of-elements/300462 "2022-03-23T15:01:01Z")

</div>

Hello, I am looking for a way to go from this message { "parent\_field": \[ "Key 1:red", "Key 1:blue", "Key 2:this is green" \] } to: { "key#1": \["red", "blue"\], "key#2": "this is green" } Tried …

---

## [Logstash Not Loading Config Files Running as Service](https://discuss.elastic.co/t/logstash-not-loading-config-files-running-as-service/300430)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 0\
**Last updated:** [March 23, 2022, 9:35am UTC](https://discuss.elastic.co/t/logstash-not-loading-config-files-running-as-service/300430 "2022-03-23T09:35:22Z")

</div>

Dear all, My Logstash is not reading config files I have specified in pipelines.yml. pipelines.yml # This file is where you define your pipelines. You can define multiple. # For more information on multiple pipelines,…

---

## [Beats input plugin to support TLS 1.3](https://discuss.elastic.co/t/beats-input-plugin-to-support-tls-1-3/299042)

<div class="topic-metadata">

**Author:** [@Nikhitha](https://discuss.elastic.co/u/Nikhitha)\
**Replies:** 1\
**Last updated:** [March 23, 2022, 9:07am UTC](https://discuss.elastic.co/t/beats-input-plugin-to-support-tls-1-3/299042 "2022-03-23T09:07:24Z")

</div>

Currently tls\_min\_version and tls\_max\_version maximum supported version is 1.2 only. Does logstash beats plugin support TLS 1.3?

---

## [Logstash SNMP input error](https://discuss.elastic.co/t/logstash-snmp-input-error/298106)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 1\
**Last updated:** [March 23, 2022, 4:02am UTC](https://discuss.elastic.co/t/logstash-snmp-input-error/298106 "2022-03-23T04:02:11Z")

</div>

I am getting some error when running logstash config as below input { snmp { get =\> \[".1.3.6.1.2.1.5.1.0", ".1.3.6.1.2.1.5.2.0", ".1.3.6.1.2.1.5.3.0", ".1.3.6.1.2.1.5.4.0", ".1.3.6.1.2.1.5.5.0", ".1.3.6.1.…

---

## [\[Agent thread\] sourceloader - No configuration found in the configured sources](https://discuss.elastic.co/t/agent-thread-sourceloader-no-configuration-found-in-the-configured-sources/300394)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 1\
**Last updated:** [March 23, 2022, 3:35am UTC](https://discuss.elastic.co/t/agent-thread-sourceloader-no-configuration-found-in-the-configured-sources/300394 "2022-03-23T03:35:44Z")

</div>

good day I reinstalled logstash and when I try to test a snmp file I get the following error: \[2022-03-22T23:56:52,421\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Failed to install template {:message=\>"Got response …

---

## [Filter with more than one possible match?](https://discuss.elastic.co/t/filter-with-more-than-one-possible-match/300292)

<div class="topic-metadata">

**Author:** [@andre22](https://discuss.elastic.co/u/andre22)\
**Replies:** 2\
**Last updated:** [March 22, 2022, 3:21pm UTC](https://discuss.elastic.co/t/filter-with-more-than-one-possible-match/300292 "2022-03-22T15:21:57Z")

</div>

Hi, I'm running the Elastic stack 8.1 I want to create a filter that has more than one condition and therefore avoid creating the same filter for all possibilities again and again. An example: I want the IF condition t…

---

## [Configure Let's Encrypt with Nginx to act as Reverse Proxy for Logstash](https://discuss.elastic.co/t/configure-lets-encrypt-with-nginx-to-act-as-reverse-proxy-for-logstash/300277)

<div class="topic-metadata">

**Author:** [@scottfred](https://discuss.elastic.co/u/scottfred)\
**Replies:** 0\
**Last updated:** [March 22, 2022, 6:51am UTC](https://discuss.elastic.co/t/configure-lets-encrypt-with-nginx-to-act-as-reverse-proxy-for-logstash/300277 "2022-03-22T06:51:55Z")

</div>

I have Logstash running in a Docker container in a private subnet on AWS. We are able to use Logstash's HTTP Plugin to read and process Multi-line ASCII data before sending it on to Elasticsearch for storage. All of th…

---

## [Logstatsh Conditional Filter is not working](https://discuss.elastic.co/t/logstatsh-conditional-filter-is-not-working/300248)

<div class="topic-metadata">

**Author:** [@John\_snow](https://discuss.elastic.co/u/John_snow)\
**Replies:** 2\
**Last updated:** [March 22, 2022, 1:23pm UTC](https://discuss.elastic.co/t/logstatsh-conditional-filter-is-not-working/300248 "2022-03-22T13:23:47Z")

</div>

I'm trying to apply condional filtering in logstash but it is not working. My log looks like "record": { "field1": "abc", "field2": "/value" } Filter Condition if \[re…

---

## [LogStash::Outputs::ElasticSearch::HttpClient::Pool::BadResponseCodeError, :message=\>"Got response code '401'](https://discuss.elastic.co/t/logstash-badresponsecodeerror-message-got-response-code-401/299780)

<div class="topic-metadata">

**Author:** [@Diego\_T](https://discuss.elastic.co/u/Diego_T)\
**Replies:** 2\
**Last updated:** [March 22, 2022, 1:20pm UTC](https://discuss.elastic.co/t/logstash-badresponsecodeerror-message-got-response-code-401/299780 "2022-03-22T13:20:15Z")

</div>

when I run logstash on my local windows pointing to my remote elastic account I get the following error Using LS\_JAVA\_HOME defined java: C:\\Program Files\\Java\\jdk-17.0.2 WARNING: Using LS\_JAVA\_HOME while Logstash distri…

---

## [Config pipeline logstash with module cisco](https://discuss.elastic.co/t/config-pipeline-logstash-with-module-cisco/300044)

<div class="topic-metadata">

**Author:** [@jojodd](https://discuss.elastic.co/u/jojodd)\
**Replies:** 6\
**Last updated:** [March 22, 2022, 1:08pm UTC](https://discuss.elastic.co/t/config-pipeline-logstash-with-module-cisco/300044 "2022-03-22T13:08:53Z")

</div>

Hello, I would like to know if it is possible to use at the same time cisco-asa and cisco-ios in a single pipeline? Is there a method to create several indexes with one for cisco-ios and the other for cisco-asa?

---

## [Environment variable from secrets empty in pipeline](https://discuss.elastic.co/t/environment-variable-from-secrets-empty-in-pipeline/300340)

<div class="topic-metadata">

**Author:** [@pfennema](https://discuss.elastic.co/u/pfennema)\
**Replies:** 0\
**Last updated:** [March 22, 2022, 1:07pm UTC](https://discuss.elastic.co/t/environment-variable-from-secrets-empty-in-pipeline/300340 "2022-03-22T13:07:05Z")

</div>

Hi All, I'm trying to use an environment variable in one of my pipeline configs which is defined in a secrets file in kubernetes. When I login into the container and do an 'env' commend, the environment variable is def…

---

## [Rename fields names with logstash](https://discuss.elastic.co/t/rename-fields-names-with-logstash/300321)

<div class="topic-metadata">

**Author:** [@Paf](https://discuss.elastic.co/u/Paf)\
**Replies:** 2\
**Last updated:** [March 22, 2022, 11:53am UTC](https://discuss.elastic.co/t/rename-fields-names-with-logstash/300321 "2022-03-22T11:53:54Z")

</div>

Hello, I want to rename the field name "identity.claims.http://schemas.microsoft.com/claims/authnclassreference" to "identity\_claims\_authnclassreference". For this, i use mutate filter with rename as follwing: filter…

---

## [Logstash working from cli, but not whilst running as a service](https://discuss.elastic.co/t/logstash-working-from-cli-but-not-whilst-running-as-a-service/300309)

<div class="topic-metadata">

**Author:** [@conor\_c](https://discuss.elastic.co/u/conor_c)\
**Replies:** 0\
**Last updated:** [March 22, 2022, 10:02am UTC](https://discuss.elastic.co/t/logstash-working-from-cli-but-not-whilst-running-as-a-service/300309 "2022-03-22T10:02:45Z")

</div>

Hi, I'm running Logstash and Filebeat with what I believe to be simple configurations. I have two syslog listeners, one on UDP 9001 and one on UDP 9002. When running Logstash as a service and when sending logs to 9001,…

---

## [Logstash to process multiple files of large size?](https://discuss.elastic.co/t/logstash-to-process-multiple-files-of-large-size/300299)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 0\
**Last updated:** [March 22, 2022, 8:43am UTC](https://discuss.elastic.co/t/logstash-to-process-multiple-files-of-large-size/300299 "2022-03-22T08:43:14Z")

</div>

Hello, To give a little bit of context, i have 3 VMs , each of 16 CPU cores out of which 2 are of 16GB RAM (they host Elasticsearch and kibana + a flask app, that provides a front end for the user to input the machineip…

---

## [Logstash count events using ruby filter](https://discuss.elastic.co/t/logstash-count-events-using-ruby-filter/300256)

<div class="topic-metadata">

**Author:** [@gnam](https://discuss.elastic.co/u/gnam)\
**Replies:** 4\
**Last updated:** [March 22, 2022, 4:56am UTC](https://discuss.elastic.co/t/logstash-count-events-using-ruby-filter/300256 "2022-03-22T04:56:58Z")

</div>

I have following pipeline (example, not full pipeline) where I need count the number of events for EVERY file I am writing as output. For example, this pipleline creates new file every 30 seconds with the events processe…

---

## [Logstash processing gz file and sending logs to Elasticsearch](https://discuss.elastic.co/t/logstash-processing-gz-file-and-sending-logs-to-elasticsearch/300112)

<div class="topic-metadata">

**Author:** [@wallace84](https://discuss.elastic.co/u/wallace84)\
**Replies:** 1\
**Last updated:** [March 21, 2022, 8:45pm UTC](https://discuss.elastic.co/t/logstash-processing-gz-file-and-sending-logs-to-elasticsearch/300112 "2022-03-21T20:45:23Z")

</div>

Hi, I am trying to do a test sending gz format logs from Logstash to Elasticsearch, do you know about a possible simple config file I could use to process the logs that use time stamps? The filter requires a bit of cus…

---

## [Unable to convert a field from string to integer that is dynamically generated in Logstash filter](https://discuss.elastic.co/t/unable-to-convert-a-field-from-string-to-integer-that-is-dynamically-generated-in-logstash-filter/300224)

<div class="topic-metadata">

**Author:** [@Usman18](https://discuss.elastic.co/u/Usman18)\
**Replies:** 1\
**Last updated:** [March 21, 2022, 6:45pm UTC](https://discuss.elastic.co/t/unable-to-convert-a-field-from-string-to-integer-that-is-dynamically-generated-in-logstash-filter/300224 "2022-03-21T18:45:03Z")

</div>

I am adding a field in my event data point in Logstash filter. The name of the field is created dynamically based on the value of the other field. The code can be seen below which I am using to add this field mutate { …

---

## [Logstash oracle db jdbc plugin eeror](https://discuss.elastic.co/t/logstash-oracle-db-jdbc-plugin-eeror/300225)

<div class="topic-metadata">

**Author:** [@Hamza\_Shakeel](https://discuss.elastic.co/u/Hamza_Shakeel)\
**Replies:** 1\
**Last updated:** [March 21, 2022, 5:16pm UTC](https://discuss.elastic.co/t/logstash-oracle-db-jdbc-plugin-eeror/300225 "2022-03-21T17:16:44Z")

</div>

I am getting the following error : Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\t\\r\\n\], "#", \[A-Za-z0-9\_…

---

## [How to specifiy proxy with websoket input plugin](https://discuss.elastic.co/t/how-to-specifiy-proxy-with-websoket-input-plugin/300174)

<div class="topic-metadata">

**Author:** [@zid57](https://discuss.elastic.co/u/zid57)\
**Replies:** 1\
**Last updated:** [March 21, 2022, 5:12pm UTC](https://discuss.elastic.co/t/how-to-specifiy-proxy-with-websoket-input-plugin/300174 "2022-03-21T17:12:30Z")

</div>

Hello all, I would need to use the logstash websocket as input plugin. I installed it and it works. However, I'm not able to retrieve data from the websocket URL. The case is simple. In order to reach internet, my l…

---

## [How to process json logs from docker container](https://discuss.elastic.co/t/how-to-process-json-logs-from-docker-container/300207)

<div class="topic-metadata">

**Author:** [@paulov](https://discuss.elastic.co/u/paulov)\
**Replies:** 1\
**Last updated:** [March 21, 2022, 3:20pm UTC](https://discuss.elastic.co/t/how-to-process-json-logs-from-docker-container/300207 "2022-03-21T15:20:05Z")

</div>

Hi, I receive logs from docker containers, these have a field 'log' that is in itself a json message and that contains a subfield 'message' which I'm interested in. Example: "log"=\>"{"fields":{},"level":"info","@times…

---

## [Sincedb\_path file type](https://discuss.elastic.co/t/sincedb-path-file-type/300182)

<div class="topic-metadata">

**Author:** [@Greninja\_San](https://discuss.elastic.co/u/Greninja_San)\
**Replies:** 3\
**Last updated:** [March 21, 2022, 10:05am UTC](https://discuss.elastic.co/t/sincedb-path-file-type/300182 "2022-03-21T10:05:50Z")

</div>

Hello! I have to set a sincedb\_path file for logstash. However, I have to create one and I cannot find the file type required. What should it be? (CSV, TXT, JSON...) Thank you :slight\_smile:

---

## [Two distinct elasticsearch outputs in logstash (https,http)](https://discuss.elastic.co/t/two-distinct-elasticsearch-outputs-in-logstash-https-http/300138)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [March 20, 2022, 10:58pm UTC](https://discuss.elastic.co/t/two-distinct-elasticsearch-outputs-in-logstash-https-http/300138 "2022-03-20T22:58:58Z")

</div>

Hi I'm wondering if I can setup multi-output for the two endpoint (one of this address is corresponding to http and the second one works through https) How I can use different Elasticsearch output for https and http? f…

---

## [How do I map fields with ECS if I am using my own grok filters](https://discuss.elastic.co/t/how-do-i-map-fields-with-ecs-if-i-am-using-my-own-grok-filters/300147)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 0\
**Last updated:** [March 21, 2022, 3:46am UTC](https://discuss.elastic.co/t/how-do-i-map-fields-with-ecs-if-i-am-using-my-own-grok-filters/300147 "2022-03-21T03:46:36Z")

</div>

Hi Team, Here is my grok parser match =\> { "message" =\> "(?\<timestamp\>%{MONTHDAY}-%{MONTH}-%{YEAR} %{TIME}) rpz: info: client @%{WORD:data} %{IPV4:clientipaddr}#%{INT:sport} \\(%{NOTSPA CE:qdomain}\\): rpz QNAME Local-Da…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=151)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=153)
