# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=155

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 156

---

## [Help with Oracle JDBC connection issue](https://discuss.elastic.co/t/help-with-oracle-jdbc-connection-issue/299254)

<div class="topic-metadata">

**Author:** [@WHenry](https://discuss.elastic.co/u/WHenry)\
**Replies:** 1\
**Last updated:** [March 9, 2022, 8:57pm UTC](https://discuss.elastic.co/t/help-with-oracle-jdbc-connection-issue/299254 "2022-03-09T20:57:29Z")

</div>

Hi, I'm trying to setup jdbc to an oracle db and i'm getting this error: \[2022-03-09T18:34:00,464\]\[ERROR\]\[logstash.inputs.jdbc \]\[main\]\[d8b8d7fe74757907ee914a1d4234f10bc8889d0c39bd99e2b0b0929f51efafab\] Unable to con…

---

## [Error sending data from logstash to elasticsearch](https://discuss.elastic.co/t/error-sending-data-from-logstash-to-elasticsearch/299238)

<div class="topic-metadata">

**Author:** [@Rithik\_greendeck](https://discuss.elastic.co/u/Rithik_greendeck)\
**Replies:** 1\
**Last updated:** [March 9, 2022, 5:58pm UTC](https://discuss.elastic.co/t/error-sending-data-from-logstash-to-elasticsearch/299238 "2022-03-09T17:58:20Z")

</div>

\[2022-03-09T14:40:58,425\]\[ERROR\]\[logstash.outputs.Elasticsearch\]\[main\]\[6c4be64292281ece43eb3c0a90ef5aa3634da5f79c62d74a63d7a5637e24049b\] Encountered an unexpected error submitting a bulk request! Will retry. {:error\_mess…

---

## [Windows event classification mapping - is there a source for this?](https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248)

<div class="topic-metadata">

**Author:** [@mistrhanky](https://discuss.elastic.co/u/mistrhanky)\
**Replies:** 2\
**Last updated:** [March 9, 2022, 5:35pm UTC](https://discuss.elastic.co/t/windows-event-classification-mapping-is-there-a-source-for-this/299248 "2022-03-09T17:35:09Z")

</div>

I am writing(re-writing) a logstash parser for windows and I want to ensure that all of my events get categorized as closely as possible to the ECS definitions. The mappings I am directly referring to are event.type, eve…

---

## [How can i ingest static key value log file to elastic and dynamically choose string or int](https://discuss.elastic.co/t/how-can-i-ingest-static-key-value-log-file-to-elastic-and-dynamically-choose-string-or-int/299229)

<div class="topic-metadata">

**Author:** [@hagaluly](https://discuss.elastic.co/u/hagaluly)\
**Replies:** 0\
**Last updated:** [March 9, 2022, 2:19pm UTC](https://discuss.elastic.co/t/how-can-i-ingest-static-key-value-log-file-to-elastic-and-dynamically-choose-string-or-int/299229 "2022-03-09T14:19:58Z")

</div>

server=server.com ip=192.168.1.2 role=webserver up=1 I am looking for a logstash configuration to do the following thanks! ingest the file and delete after go row by row and decide if value is string or integer deploy…

---

## [Copy content from one field of another record if certain condition matches](https://discuss.elastic.co/t/copy-content-from-one-field-of-another-record-if-certain-condition-matches/298605)

<div class="topic-metadata">

**Author:** [@Ashutosh\_Vaidya](https://discuss.elastic.co/u/Ashutosh_Vaidya)\
**Replies:** 12\
**Last updated:** [March 9, 2022, 1:08pm UTC](https://discuss.elastic.co/t/copy-content-from-one-field-of-another-record-if-certain-condition-matches/298605 "2022-03-09T13:08:12Z")

</div>

Hi I need to copy contents of :path field from No. 15256 into the :path field of No.15257 if Stream\_Identifier of both lines in 15256 and 15257 are matching. Kindly suggest how to get this done in the conf file of logs…

---

## [Logstash-Twitter plugin - AND logical operator between keywords](https://discuss.elastic.co/t/logstash-twitter-plugin-and-logical-operator-between-keywords/299211)

<div class="topic-metadata">

**Author:** [@dihiaselma](https://discuss.elastic.co/u/dihiaselma)\
**Replies:** 0\
**Last updated:** [March 9, 2022, 12:17pm UTC](https://discuss.elastic.co/t/logstash-twitter-plugin-and-logical-operator-between-keywords/299211 "2022-03-09T12:17:05Z")

</div>

I'm using Twitter logstash plugin to extract data from twitter. I need to specify an AND operator between my keywords. I tried this syntax \["apple samsung"\] i.e. if I find a tweet containing these two words I bring it. …

---

## [Any setting in CSV filter to disable auto datatype conversion and keep everything in string?](https://discuss.elastic.co/t/any-setting-in-csv-filter-to-disable-auto-datatype-conversion-and-keep-everything-in-string/299163)

<div class="topic-metadata">

**Author:** [@pinehk](https://discuss.elastic.co/u/pinehk)\
**Replies:** 6\
**Last updated:** [March 9, 2022, 6:59am UTC](https://discuss.elastic.co/t/any-setting-in-csv-filter-to-disable-auto-datatype-conversion-and-keep-everything-in-string/299163 "2022-03-09T06:59:42Z")

</div>

In both version 7.x and 8, with a very simple csv filter configuration below, for no reason some fields are mapped as "date". In the documentation, there is a switch "convert" that we can customize datatype conversion fr…

---

## [Logstash agent stopped due to error "Don't know how to handle \`Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>\`"](https://discuss.elastic.co/t/logstash-agent-stopped-due-to-error-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/299168)

<div class="topic-metadata">

**Author:** [@ashiqab](https://discuss.elastic.co/u/ashiqab)\
**Replies:** 2\
**Last updated:** [March 9, 2022, 6:43am UTC](https://discuss.elastic.co/t/logstash-agent-stopped-due-to-error-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/299168 "2022-03-09T06:43:41Z")

</div>

Hi, I am new to ELK stack and have installed the three components on my SUSE linux 12 server. Running java 17.0.2. My logstash-plain.log repeats the java error for the agent which stops with below error: \[2022-03-09T0…

---

## [Need to extract specific message from log](https://discuss.elastic.co/t/need-to-extract-specific-message-from-log/299171)

<div class="topic-metadata">

**Author:** [@sushant12](https://discuss.elastic.co/u/sushant12)\
**Replies:** 0\
**Last updated:** [March 9, 2022, 6:29am UTC](https://discuss.elastic.co/t/need-to-extract-specific-message-from-log/299171 "2022-03-09T06:29:13Z")

</div>

address space usage: 1827991552 bytes/1743MB} {rss usage: 389292032 bytes/371MB} \[pid: 19335|app: 0|req: 17171/48113\] 10.195.0.169 () {50 vars in 816 bytes} \[Mon Feb 21 04:06:57 2022\] GET /web/test\_name?name=sush =\> gene…

---

## [Replacing all instances of a string in nested JSON](https://discuss.elastic.co/t/replacing-all-instances-of-a-string-in-nested-json/299152)

<div class="topic-metadata">

**Author:** [@7armyant](https://discuss.elastic.co/u/7armyant)\
**Replies:** 4\
**Last updated:** [March 9, 2022, 4:39am UTC](https://discuss.elastic.co/t/replacing-all-instances-of-a-string-in-nested-json/299152 "2022-03-09T04:39:17Z")

</div>

Hi Gurus, I'm new to logstash and have had little success with the following. I have been trying to relace all instances of a sting in nested JSON. Below is the JSON in question: "{"totalCount": 2, "nextPageKey": n…

---

## [Mutate gsub pattern help for filter](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020)

<div class="topic-metadata">

**Author:** [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Replies:** 6\
**Last updated:** [March 8, 2022, 10:54pm UTC](https://discuss.elastic.co/t/mutate-gsub-pattern-help-for-filter/299020 "2022-03-08T22:54:13Z")

</div>

Hello, still new using regular expressions I currently am working on this to parse in my "message": {"groupByActivity":false,"exampleDevices":\[{"ip":"1.2.3.4","hostname":"example.hostname.com","sid":123456,"subnet":"som…

---

## [No output from json line delimited file](https://discuss.elastic.co/t/no-output-from-json-line-delimited-file/299092)

<div class="topic-metadata">

**Author:** [@theflakes](https://discuss.elastic.co/u/theflakes)\
**Replies:** 2\
**Last updated:** [March 8, 2022, 9:33pm UTC](https://discuss.elastic.co/t/no-output-from-json-line-delimited-file/299092 "2022-03-08T21:33:10Z")

</div>

I'm trying to get Logstash 8 working with a config that works in Logstash 7. I'm not getting any output even though it works fine in v7. If I remove all the filters, I still do not get any output. When I run LS in debut …

---

## [Problem overwriting field using json filter plugin](https://discuss.elastic.co/t/problem-overwriting-field-using-json-filter-plugin/299132)

<div class="topic-metadata">

**Author:** [@tstrul](https://discuss.elastic.co/u/tstrul)\
**Replies:** 3\
**Last updated:** [March 8, 2022, 9:17pm UTC](https://discuss.elastic.co/t/problem-overwriting-field-using-json-filter-plugin/299132 "2022-03-08T21:17:10Z")

</div>

Hey, I have a log that i want to parse as json. field is "log" I want to decode json but use the same field as the orig message. when i try: json { source =\> "log" target =\> "log" } Im ge…

---

## [Can't get logstash to work with Elastic 8.01](https://discuss.elastic.co/t/cant-get-logstash-to-work-with-elastic-8-01/298838)

<div class="topic-metadata">

**Author:** [@kim\_frederiksen](https://discuss.elastic.co/u/kim_frederiksen)\
**Replies:** 3\
**Last updated:** [March 8, 2022, 6:37pm UTC](https://discuss.elastic.co/t/cant-get-logstash-to-work-with-elastic-8-01/298838 "2022-03-08T18:37:00Z")

</div>

Hi Everybody, I am extremely new to ELK and have yet to build the first real solution on the platform. We have had version 7.16.1 and we could see the logs from filebeat in kibana. But before we really begin building st…

---

## [Create fields from the objects that are a part of array in Logstash filter](https://discuss.elastic.co/t/create-fields-from-the-objects-that-are-a-part-of-array-in-logstash-filter/299088)

<div class="topic-metadata">

**Author:** [@Usman18](https://discuss.elastic.co/u/Usman18)\
**Replies:** 1\
**Last updated:** [March 8, 2022, 5:14pm UTC](https://discuss.elastic.co/t/create-fields-from-the-objects-that-are-a-part-of-array-in-logstash-filter/299088 "2022-03-08T17:14:43Z")

</div>

In Logstash, in my event object there is a field that is an array. This field contains objects. I have to create or add some new fields in the event object and these fields will be created on the basis of the objects tha…

---

## [Logstash slow in bash script launch by cronjob](https://discuss.elastic.co/t/logstash-slow-in-bash-script-launch-by-cronjob/299103)

<div class="topic-metadata">

**Author:** [@Henri\_L](https://discuss.elastic.co/u/Henri_L)\
**Replies:** 5\
**Last updated:** [March 8, 2022, 4:18pm UTC](https://discuss.elastic.co/t/logstash-slow-in-bash-script-launch-by-cronjob/299103 "2022-03-08T16:18:58Z")

</div>

Hi I have a bash script like that: #!/bin/bash cat /home/xxx/public\_html/datas/zz/file.csv | /usr/share/logstash/bin/logstash -f /home/xxx/public\_html/datas/myconf.conf My conf file is basic like that: input { st…

---

## [Pipeline error : java.lang.OutOfMemoryError: Java heap space](https://discuss.elastic.co/t/pipeline-error-java-lang-outofmemoryerror-java-heap-space/299081)

<div class="topic-metadata">

**Author:** [@Sara\_Chater](https://discuss.elastic.co/u/Sara_Chater)\
**Replies:** 0\
**Last updated:** [March 8, 2022, 11:32am UTC](https://discuss.elastic.co/t/pipeline-error-java-lang-outofmemoryerror-java-heap-space/299081 "2022-03-08T11:32:37Z")

</div>

Dear community, I have a log file that contains multiple entries per transaction id Entries are ordered in file, but not necessary one after each other I tried using logstash aggregate filter as follow : My idea is to…

---

## [Kibana logstash Snapshot Storage Size continuously growing its size](https://discuss.elastic.co/t/kibana-logstash-snapshot-storage-size-continuously-growing-its-size/299023)

<div class="topic-metadata">

**Author:** [@renatoa12](https://discuss.elastic.co/u/renatoa12)\
**Replies:** 3\
**Last updated:** [March 8, 2022, 2:08am UTC](https://discuss.elastic.co/t/kibana-logstash-snapshot-storage-size-continuously-growing-its-size/299023 "2022-03-08T02:08:24Z")

</div>

Hi Community, Does anyone here experience that their Snapshot storage size continuously growing, currently i have 200gb snapshot size and still growing for march 3 logs, normally the size per day of snapshot ranging 50-…

---

## [Certificate doesn't match any of the subject alternative names](https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 2\
**Last updated:** [March 8, 2022, 1:20am UTC](https://discuss.elastic.co/t/certificate-doesnt-match-any-of-the-subject-alternative-names/298091 "2022-03-08T01:20:38Z")

</div>

Since update to ELK 8 there is following problem: \[2022-02-23T23:18:41,619\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Failed to perform request {:message=\>"Certificate for \<elasticsearch\> doesn't match any of the sub…

---

## [Cannot convert created field to integer](https://discuss.elastic.co/t/cannot-convert-created-field-to-integer/299005)

<div class="topic-metadata">

**Author:** [@aerodynamic](https://discuss.elastic.co/u/aerodynamic)\
**Replies:** 6\
**Last updated:** [March 7, 2022, 10:00pm UTC](https://discuss.elastic.co/t/cannot-convert-created-field-to-integer/299005 "2022-03-07T22:00:25Z")

</div>

Currently I'm dealing with a situation where a field name is dynamically created and needs to be set to an integer like so mutate { add\_field =\> { "%{fieldName}" =\> "%{dataInteger}" } convert …

---

## [Logstash pipeline processing](https://discuss.elastic.co/t/logstash-pipeline-processing/298921)

<div class="topic-metadata">

**Author:** [@KarlWolf](https://discuss.elastic.co/u/KarlWolf)\
**Replies:** 5\
**Last updated:** [March 7, 2022, 9:52pm UTC](https://discuss.elastic.co/t/logstash-pipeline-processing/298921 "2022-03-07T21:52:43Z")

</div>

Hello, I am having a problem with Logstash configuration. I can't get rid with pipelines configuraton. My scenario: logstash.yml - only lines which are uncommented/changed path.data: /usr/share/logstash pipeline.worke…

---

## [Multiline grok filter not working with specific log](https://discuss.elastic.co/t/multiline-grok-filter-not-working-with-specific-log/298923)

<div class="topic-metadata">

**Author:** [@Mihailo\_Stanarevic](https://discuss.elastic.co/u/Mihailo_Stanarevic)\
**Replies:** 2\
**Last updated:** [March 7, 2022, 8:42pm UTC](https://discuss.elastic.co/t/multiline-grok-filter-not-working-with-specific-log/298923 "2022-03-07T20:42:49Z")

</div>

Hello, I have logs that i have to process that look something like this As far as my knowledge goes I have to set up logstash to support multiline logs so I created the following configuration input { file { pat…

---

## [How to transfer data from mongoDB to elasticsearch using mongodb-plugin-input](https://discuss.elastic.co/t/how-to-transfer-data-from-mongodb-to-elasticsearch-using-mongodb-plugin-input/299001)

<div class="topic-metadata">

**Author:** [@Douglas\_Andrade](https://discuss.elastic.co/u/Douglas_Andrade)\
**Replies:** 1\
**Last updated:** [March 7, 2022, 6:42pm UTC](https://discuss.elastic.co/t/how-to-transfer-data-from-mongodb-to-elasticsearch-using-mongodb-plugin-input/299001 "2022-03-07T18:42:35Z")

</div>

I would like to know if it is possible to transfer a complete database from mongoDB to Elasticsearch, not just new data, using mongoDB-plugin-input

---

## [Two Http\_poller inputs with access token](https://discuss.elastic.co/t/two-http-poller-inputs-with-access-token/298939)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 7\
**Last updated:** [March 7, 2022, 5:51pm UTC](https://discuss.elastic.co/t/two-http-poller-inputs-with-access-token/298939 "2022-03-07T17:51:03Z")

</div>

Hello! I am trying to get data from an api that needs to be accessed using a token that we get from another api. How can I pass this access token to get the data from the other api? I had thought of doing something si…

---

## [Failed to connect to postgreslq via logsatash](https://discuss.elastic.co/t/failed-to-connect-to-postgreslq-via-logsatash/298772)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 1\
**Last updated:** [March 7, 2022, 4:37pm UTC](https://discuss.elastic.co/t/failed-to-connect-to-postgreslq-via-logsatash/298772 "2022-03-07T16:37:33Z")

</div>

it's the first time I'm trying to access a postgresql database through logstash. however there are dnado errors, can you help me. Below is conf and error. input{ jdbc{ jdbc\_driver\_library =\> "/usr/share/java/pos…

---

## [How to pass variable base parameter in http\_poller logstash input plugin](https://discuss.elastic.co/t/how-to-pass-variable-base-parameter-in-http-poller-logstash-input-plugin/298621)

<div class="topic-metadata">

**Author:** [@Purushottam22](https://discuss.elastic.co/u/Purushottam22)\
**Replies:** 1\
**Last updated:** [March 2, 2022, 8:16pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-base-parameter-in-http-poller-logstash-input-plugin/298621 "2022-03-02T20:16:41Z")

</div>

Hi All, Can you please help me with below issue, I am trying to hit two rest api for below two conditions: First is used for providing the login credentials and it will give an response as session id. I have to use t…

---

## [Logstash Performance](https://discuss.elastic.co/t/logstash-performance/298942)

<div class="topic-metadata">

**Author:** [@mani1](https://discuss.elastic.co/u/mani1)\
**Replies:** 0\
**Last updated:** [March 7, 2022, 8:46am UTC](https://discuss.elastic.co/t/logstash-performance/298942 "2022-03-07T08:46:41Z")

</div>

Hello , We have maximize the Logstash performance in terms of processed events per sec, by tuning vcpus, Heap, pipeline workers, Consumer Threads, N/w bandwidth, Batch size etc. There is no scarcity of resources assigne…

---

## [Getting no error but data not saved in ES](https://discuss.elastic.co/t/getting-no-error-but-data-not-saved-in-es/298905)

<div class="topic-metadata">

**Author:** [@AkAmit](https://discuss.elastic.co/u/AkAmit)\
**Replies:** 0\
**Last updated:** [March 6, 2022, 7:24am UTC](https://discuss.elastic.co/t/getting-no-error-but-data-not-saved-in-es/298905 "2022-03-06T07:24:46Z")

</div>

Using bundled JDK: /usr/share/logstash/jdk OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be removed in a future release. Sending Logstash logs to /var/log/log…

---

## [Logstash 8.1, Protobuf error - add\_file](https://discuss.elastic.co/t/logstash-8-1-protobuf-error-add-file/298894)

<div class="topic-metadata">

**Author:** [@pdoten](https://discuss.elastic.co/u/pdoten)\
**Replies:** 2\
**Last updated:** [March 6, 2022, 4:06am UTC](https://discuss.elastic.co/t/logstash-8-1-protobuf-error-add-file/298894 "2022-03-06T04:06:57Z")

</div>

Long time user here, love Elasticstack but cant get over this problem. Trying to create input for protobuf. Input stanza below. LS stops after throwing java exception, cant get pass this -tried to get this to work in 7.…

---

## [\[logstash.outputs.elasticsearch\]\[main\] Failed to install template](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-main-failed-to-install-template/298835)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 1\
**Last updated:** [March 4, 2022, 10:36pm UTC](https://discuss.elastic.co/t/logstash-outputs-elasticsearch-main-failed-to-install-template/298835 "2022-03-04T22:36:05Z")

</div>

Hi everyone, After enabling SSL communication on my Elasticsearch server (v7.14.0), i noticed an error in my logstash logs: \[ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Failed to install template {:message=\>"Got respo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=154)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=156)
