# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=158

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 159

---

## [Logstash error : rejected excution exeption](https://discuss.elastic.co/t/logstash-error-rejected-excution-exeption/298117)

<div class="topic-metadata">

**Author:** [@priyanka\_mundhe](https://discuss.elastic.co/u/priyanka_mundhe)\
**Replies:** 1\
**Last updated:** [February 24, 2022, 8:24am UTC](https://discuss.elastic.co/t/logstash-error-rejected-excution-exeption/298117 "2022-02-24T08:24:39Z")

</div>

cluster is going into red state continously. Please help

---

## [Add fields with same format but different value problem with grok logstash](https://discuss.elastic.co/t/add-fields-with-same-format-but-different-value-problem-with-grok-logstash/298043)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 1\
**Last updated:** [February 23, 2022, 7:51pm UTC](https://discuss.elastic.co/t/add-fields-with-same-format-but-different-value-problem-with-grok-logstash/298043 "2022-02-23T19:51:31Z")

</div>

Hi, log file example: 2021-01-01 11:15:02 - it is a f.... 2021-01-01 11:15:04 - format is =\> 000000: 00 11 22 a5 12 12 23 2a 55 12 00 22 33 44 | ?1451202000 . . . 00114: 00 11 55 77 9a 11 0 2021-12-23 10:14:22 …

---

## [Logstash won't start pipeline after moving to 7.6.13 from 6.5.x](https://discuss.elastic.co/t/logstash-wont-start-pipeline-after-moving-to-7-6-13-from-6-5-x/298035)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 2\
**Last updated:** [February 24, 2022, 6:45am UTC](https://discuss.elastic.co/t/logstash-wont-start-pipeline-after-moving-to-7-6-13-from-6-5-x/298035 "2022-02-24T06:45:09Z")

</div>

Hi All, I've gotten a problem with my old logstash pipeline. My config looks like this (everything is commented out during debugging): \[root@ALPHA00035 pipeline\]# cat logstash.conf input { beats { …

---

## [Whole data from db not updated in elastic index](https://discuss.elastic.co/t/whole-data-from-db-not-updated-in-elastic-index/298030)

<div class="topic-metadata">

**Author:** [@Akhil\_Chandran](https://discuss.elastic.co/u/Akhil_Chandran)\
**Replies:** 3\
**Last updated:** [February 24, 2022, 3:53am UTC](https://discuss.elastic.co/t/whole-data-from-db-not-updated-in-elastic-index/298030 "2022-02-24T03:53:17Z")

</div>

input { jdbc { tags =\> "staff" jdbc\_connection\_string =\> "jdbc:postgresql://${DB\_HOST}:${DB\_PORT}/${DB\_NAME}" jdbc\_user =\> "${DB\_USER}" jdbc\_password =\> "${DB\_PASSWORD}" schedule =\> "\* \* \* \* \*" …

---

## [Large amounts of bulk data sent from Logstash to Elasticsearch after using pipelines](https://discuss.elastic.co/t/large-amounts-of-bulk-data-sent-from-logstash-to-elasticsearch-after-using-pipelines/298092)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 3\
**Last updated:** [February 24, 2022, 1:18am UTC](https://discuss.elastic.co/t/large-amounts-of-bulk-data-sent-from-logstash-to-elasticsearch-after-using-pipelines/298092 "2022-02-24T01:18:41Z")

</div>

I recently changed my configuration from one logstash.config file to pipelines to make it easier. My pipelines.yml (replaced actual names with letters, main re-routes data to correct pipeline based on tag): - pipeline.…

---

## [Logstash 7.x support on Debian 10 or 11](https://discuss.elastic.co/t/logstash-7-x-support-on-debian-10-or-11/298087)

<div class="topic-metadata">

**Author:** [@jeroen.antsec](https://discuss.elastic.co/u/jeroen.antsec)\
**Replies:** 0\
**Last updated:** [February 23, 2022, 9:48pm UTC](https://discuss.elastic.co/t/logstash-7-x-support-on-debian-10-or-11/298087 "2022-02-23T21:48:06Z")

</div>

Hi all. Do any of you know the reason why Logstash 7.x (all versions up to 7.17) are not officially supported on Debian 10 or 11? Elastic and Kibana are, but Logstash not. Only version 8.0 is supported on Debian 10. Wil…

---

## [Logstash parshing unicode characters](https://discuss.elastic.co/t/logstash-parshing-unicode-characters/296890)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 16\
**Last updated:** [February 23, 2022, 8:46pm UTC](https://discuss.elastic.co/t/logstash-parshing-unicode-characters/296890 "2022-02-23T20:46:48Z")

</div>

hi, we are running into parsing errors when sending data through logstash pipelines. After digging a little, found that the source system has been sending a lot of unicode special characters - something like below: \\u00…

---

## [Can not connect to localhost:9600 for logstash](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687)

<div class="topic-metadata">

**Author:** [@TomYang1993](https://discuss.elastic.co/u/TomYang1993)\
**Replies:** 13\
**Last updated:** [February 23, 2022, 7:23pm UTC](https://discuss.elastic.co/t/can-not-connect-to-localhost-9600-for-logstash/297687 "2022-02-23T19:23:22Z")

</div>

logstash 7.17.0 Elasticsearch 7.17.0 logstash with all default settings, fresh install use sudo systemctl start logstash to start, sudo status shows logstash actively running However, curl -XGET 'localhost:9600/?pret…

---

## [Geoip stopped consolidating coordinates after logstash upgrade to 8.0](https://discuss.elastic.co/t/geoip-stopped-consolidating-coordinates-after-logstash-upgrade-to-8-0/298067)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [February 23, 2022, 6:46pm UTC](https://discuss.elastic.co/t/geoip-stopped-consolidating-coordinates-after-logstash-upgrade-to-8-0/298067 "2022-02-23T18:46:22Z")

</div>

My logstash for geo tagging IPs are failing after logstash upgrade 8.0. Here's a snippet , i get the lat and lon values , but cant seem to get into the "destlocation" field "Dest\_IP" =\> { "geo" =\> { …

---

## [Logstash array how to and filter](https://discuss.elastic.co/t/logstash-array-how-to-and-filter/298054)

<div class="topic-metadata">

**Author:** [@melorium](https://discuss.elastic.co/u/melorium)\
**Replies:** 4\
**Last updated:** [February 23, 2022, 4:11pm UTC](https://discuss.elastic.co/t/logstash-array-how-to-and-filter/298054 "2022-02-23T16:11:26Z")

</div>

Hi. I have a list of user name's with user ID 1-100 each user id case a name that contains to it. Exmaple 01 "user 1" 02 "user2" etc. I my log events I have user id known but not user name. How can I match user id …

---

## [Cannot convert date to string by mutate](https://discuss.elastic.co/t/cannot-convert-date-to-string-by-mutate/298022)

<div class="topic-metadata">

**Author:** [@ivanhoe-dev](https://discuss.elastic.co/u/ivanhoe-dev)\
**Replies:** 4\
**Last updated:** [February 23, 2022, 3:25pm UTC](https://discuss.elastic.co/t/cannot-convert-date-to-string-by-mutate/298022 "2022-02-23T15:25:15Z")

</div>

I want to force my search\_varchar\_1 data type as string, but it always auto detect my data and parse as date type. Is there something I missed? My config filter { split {} csv { separator =\> "," skip\_header =\> "t…

---

## [Parse json data with logstash](https://discuss.elastic.co/t/parse-json-data-with-logstash/297792)

<div class="topic-metadata">

**Author:** [@sylar11](https://discuss.elastic.co/u/sylar11)\
**Replies:** 7\
**Last updated:** [February 23, 2022, 2:54pm UTC](https://discuss.elastic.co/t/parse-json-data-with-logstash/297792 "2022-02-23T14:54:12Z")

</div>

Hi all, I'm a newbie to logstash and I'm trying to parse a JSON data file like the following { "A001": { "X": 503744.7, "Y": 4726339.0, "Z": 458.84, "LON": -2.954286956913572, …

---

## [Filebeat logging certificate error even when connection can be established](https://discuss.elastic.co/t/filebeat-logging-certificate-error-even-when-connection-can-be-established/297920)

<div class="topic-metadata">

**Author:** [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Replies:** 1\
**Last updated:** [February 23, 2022, 1:13pm UTC](https://discuss.elastic.co/t/filebeat-logging-certificate-error-even-when-connection-can-be-established/297920 "2022-02-23T13:13:05Z")

</div>

Hi, I searched the board and other sources but all I found didn't match my case or did not receive a reply. So sorry if I missed something but at least I tried. :slight\_smile: I have beats that connect to two Logstash …

---

## [Logstash plugin for Azure storage](https://discuss.elastic.co/t/logstash-plugin-for-azure-storage/297733)

<div class="topic-metadata">

**Author:** [@akpratiek](https://discuss.elastic.co/u/akpratiek)\
**Replies:** 10\
**Last updated:** [February 23, 2022, 12:17pm UTC](https://discuss.elastic.co/t/logstash-plugin-for-azure-storage/297733 "2022-02-23T12:17:12Z")

</div>

Hi Team , I am trying to access and retrieve files from Azure storage. I am getting the following error when I run the config file. Any help is appreciated. \< \[2022-02-21T12:07:37,177\]\[ERROR\]\[logstash.inputs.azureblobst…

---

## [Error when config logstash to connect to elasticsearch with TLS basic security](https://discuss.elastic.co/t/error-when-config-logstash-to-connect-to-elasticsearch-with-tls-basic-security/298020)

<div class="topic-metadata">

**Author:** [@joko](https://discuss.elastic.co/u/joko)\
**Replies:** 0\
**Last updated:** [February 23, 2022, 11:34am UTC](https://discuss.elastic.co/t/error-when-config-logstash-to-connect-to-elasticsearch-with-tls-basic-security/298020 "2022-02-23T11:34:05Z")

</div>

Hi, anyone can help me? I have elasticsearch cluster with basic security enabled, and i want to send some csv data through logstash which i installed it later after elasticsearch. so i followed this instruction Configuri…

---

## [Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<NoMethodError: undefined method \`close' for nil:NilClass\>](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706)

<div class="topic-metadata">

**Author:** [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Replies:** 44\
**Last updated:** [February 23, 2022, 9:50am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706 "2022-02-23T09:50:06Z")

</div>

I have that error in logstash logs when logstash starting. Here my config file for logstash: input { beats { port =\> 5044 } } filter { grok { patterns\_dir =\> \["/etc/logstash/pattern"\] match =\>…

---

## [Correlate log using logstash aggregate plugin](https://discuss.elastic.co/t/correlate-log-using-logstash-aggregate-plugin/297589)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [February 23, 2022, 9:33am UTC](https://discuss.elastic.co/t/correlate-log-using-logstash-aggregate-plugin/297589 "2022-02-23T09:33:34Z")

</div>

Hi all I'm trying to correlate multiple log file into 1 log message send to elastic using aggregate plugin in logstash. 2022-02-18T09:51:25.528Z,mail-srv\\Client mail-srv,08D9DD5FF4988FD5,37,192.168.1.1:587,192.168.2.2:…

---

## [Logstash input from Elasticsearch wrong configuration](https://discuss.elastic.co/t/logstash-input-from-elasticsearch-wrong-configuration/297868)

<div class="topic-metadata">

**Author:** [@Syed\_Saqlain\_Hussain](https://discuss.elastic.co/u/Syed_Saqlain_Hussain)\
**Replies:** 2\
**Last updated:** [February 23, 2022, 6:12am UTC](https://discuss.elastic.co/t/logstash-input-from-elasticsearch-wrong-configuration/297868 "2022-02-23T06:12:11Z")

</div>

I want my logstash to take data from Elasticsearch on some server. This is my logstash configuration for input from Elasticsearch input { elasticsearch{ hosts =\> "127.0.0.1" index =\> "alerts-\*" …

---

## [Grok Parsing numeric field as "NUMBER:field\_name:float" , still Kibana showing string field](https://discuss.elastic.co/t/grok-parsing-numeric-field-as-numberfloat-still-kibana-showing-string-field/297970)

<div class="topic-metadata">

**Author:** [@mrunalini](https://discuss.elastic.co/u/mrunalini)\
**Replies:** 0\
**Last updated:** [February 23, 2022, 5:29am UTC](https://discuss.elastic.co/t/grok-parsing-numeric-field-as-numberfloat-still-kibana-showing-string-field/297970 "2022-02-23T05:29:01Z")

</div>

HI Team , In my logstash conf file i am parsing fields with grok , and numeric field with - "NUMBER:field\_name:float". But Kibana is still showing this field as string in my index . Value coming in this field will be …

---

## [Json { source =\> "message" } not parsing all of it](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430)

<div class="topic-metadata">

**Author:** [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Replies:** 20\
**Last updated:** [February 22, 2022, 8:47pm UTC](https://discuss.elastic.co/t/json-source-message-not-parsing-all-of-it/297430 "2022-02-22T20:47:34Z")

</div>

Hello, I'm new to Logstash and was wondering if someone could help with my filter and how can I parse the rest of my json fields the intent is to bring out the other fields in "message" such that I can map them to ECS: h…

---

## [Login Failed error . giving : A plugin had an unrecoverable error. Will restart this plugin](https://discuss.elastic.co/t/login-failed-error-giving-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/297937)

<div class="topic-metadata">

**Author:** [@d6036de2b54af16665f4](https://discuss.elastic.co/u/d6036de2b54af16665f4)\
**Replies:** 1\
**Last updated:** [February 22, 2022, 7:56pm UTC](https://discuss.elastic.co/t/login-failed-error-giving-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/297937 "2022-02-22T19:56:55Z")

</div>

Hi ALL, Inside my logs of logstash i am receiving the error as such : \[2022-02-22T17:00:11,265\]\[ERROR\]\[logstash.javapipeline \] A plugin had an unrecoverable error. Will restart this plugin. Pipeline\_id:doordash\_aut…

---

## [\[Logstash\] Grok Filter does not work \_grokparsefailure](https://discuss.elastic.co/t/logstash-grok-filter-does-not-work-grokparsefailure/297823)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 15\
**Last updated:** [February 22, 2022, 5:54pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-does-not-work-grokparsefailure/297823 "2022-02-22T17:54:26Z")

</div>

Hi, I am trying to parse this: # Time: 2022-02-21T21:06:30.359422Z\\n# User@Host: backoffice\[backoffice\] @ \[0.0.0.0\] Id: 5373\\n# Query\_time: 13.690075 Lock\_time: 0.000000 Rows\_sent: 0 Rows\_examined: 189879\\nSET tim…

---

## [ELK upgrade to 6.8.23](https://discuss.elastic.co/t/elk-upgrade-to-6-8-23/297892)

<div class="topic-metadata">

**Author:** [@arun.kumar92](https://discuss.elastic.co/u/arun.kumar92)\
**Replies:** 1\
**Last updated:** [February 22, 2022, 5:24pm UTC](https://discuss.elastic.co/t/elk-upgrade-to-6-8-23/297892 "2022-02-22T17:24:32Z")

</div>

Hi Team Currently I'm working on ELK upgrade. When I upgrade lostash from 5.X to 6.8.23.I got below error ----------------------------------------------------------------------------------------------------------------…

---

## [Logstash seems to copy the index indefinitely](https://discuss.elastic.co/t/logstash-seems-to-copy-the-index-indefinitely/297698)

<div class="topic-metadata">

**Author:** [@pain368](https://discuss.elastic.co/u/pain368)\
**Replies:** 3\
**Last updated:** [February 22, 2022, 2:23pm UTC](https://discuss.elastic.co/t/logstash-seems-to-copy-the-index-indefinitely/297698 "2022-02-22T14:23:00Z")

</div>

Hello ELK team, This is my first thread so i hope will be good enough to solve my problem. I have One primary cluster(A), and today i created second cluster(B) only for Machine Learning purpose ( i don;t want to connec…

---

## [Logstash send logs to monitoring cluster](https://discuss.elastic.co/t/logstash-send-logs-to-monitoring-cluster/297798)

<div class="topic-metadata">

**Author:** [@caseydm](https://discuss.elastic.co/u/caseydm)\
**Replies:** 4\
**Last updated:** [February 22, 2022, 2:19pm UTC](https://discuss.elastic.co/t/logstash-send-logs-to-monitoring-cluster/297798 "2022-02-22T14:19:34Z")

</div>

Hi all. I'm using logstash to send data from redshift to Elasticsearch. I monitor my pipelines with metricbeats, and am able to see general statistics about logstash within my monitoring cluster. What I can't see is logs…

---

## [Rebooting Logstash VM](https://discuss.elastic.co/t/rebooting-logstash-vm/297904)

<div class="topic-metadata">

**Author:** [@Cosmus\_Wright](https://discuss.elastic.co/u/Cosmus_Wright)\
**Replies:** 2\
**Last updated:** [February 22, 2022, 2:11pm UTC](https://discuss.elastic.co/t/rebooting-logstash-vm/297904 "2022-02-22T14:11:30Z")

</div>

Hello! If I stop the Logstash service and reboot the the VM, will any incoming events during that time be lost? Currently we have an Azure EventHub that sends the events to Logstash and then onwards to Elasticsearch. I…

---

## [Logstash Oracle 19c - IO Error: Got minus one from a read call](https://discuss.elastic.co/t/logstash-oracle-19c-io-error-got-minus-one-from-a-read-call/297902)

<div class="topic-metadata">

**Author:** [@tmihaldinec](https://discuss.elastic.co/u/tmihaldinec)\
**Replies:** 0\
**Last updated:** [February 22, 2022, 1:38pm UTC](https://discuss.elastic.co/t/logstash-oracle-19c-io-error-got-minus-one-from-a-read-call/297902 "2022-02-22T13:38:18Z")

</div>

Hi can you please help what i am doing wrong.. this same config works fine with ver 12 input { jdbc { statement\_filepath =\> "/usr/share/logstash/pipelines/sql/database\_query.sql" #important the driver library must be…

---

## [Add field multiline under multiline filebeat/logstash](https://discuss.elastic.co/t/add-field-multiline-under-multiline-filebeat-logstash/297765)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 1\
**Last updated:** [February 22, 2022, 1:53pm UTC](https://discuss.elastic.co/t/add-field-multiline-under-multiline-filebeat-logstash/297765 "2022-02-22T13:53:15Z")

</div>

Hi, I would like to know if I can add a field if I find a word in the message but with just a block of lines. log file example: 2022-01-01 17:27:56 - Starting d........ 2022-12-22 17:27:59 - Run..... . . 2022-01-0…

---

## [Logstash Filter ordering fields](https://discuss.elastic.co/t/logstash-filter-ordering-fields/297877)

<div class="topic-metadata">

**Author:** [@Simone1](https://discuss.elastic.co/u/Simone1)\
**Replies:** 0\
**Last updated:** [February 22, 2022, 10:57am UTC](https://discuss.elastic.co/t/logstash-filter-ordering-fields/297877 "2022-02-22T10:57:52Z")

</div>

I pull data from a remote MySQL DB from different columns and tables, i need to reorder the fields, how can i do? Example with stdout it doesn't print in a fixed order but it change every time, i want to see something l…

---

## [Add field problem logstash](https://discuss.elastic.co/t/add-field-problem-logstash/297858)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 1\
**Last updated:** [February 22, 2022, 10:18am UTC](https://discuss.elastic.co/t/add-field-problem-logstash/297858 "2022-02-22T10:18:52Z")

</div>

Hi, I would like to know if I can add field if I find a word in the message but under a block of lines. filebeat.yml: multiline.type: pattern multiline.pattern: '^\\d{4}-\\d{2}-\\d{2}\\s\\d{2}:\\d{2}:\\d{2}\\s{3}-\\sStarti…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=157)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=159)
