# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=159

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 160

---

## [Logstash stopped](https://discuss.elastic.co/t/logstash-stopped/297853)

<div class="topic-metadata">

**Author:** [@Bhanuji\_paluri](https://discuss.elastic.co/u/Bhanuji_paluri)\
**Replies:** 0\
**Last updated:** [February 22, 2022, 7:51am UTC](https://discuss.elastic.co/t/logstash-stopped/297853 "2022-02-22T07:51:35Z")

</div>

\[2022-02-22T08:29:17,828\]\[ERROR\]\[logstash.javapipeline \]\[mylogs5001\]\[e7635b2b0a223a267b10d8697a123f9520147502f99c0c0faadfac0d8bcf3960\] A plugin had an unrecoverable error. Will restart this plugin. Pipeline\_id:mylogs…

---

## [Why does the jdbc\_pool\_timeout parameter not work?](https://discuss.elastic.co/t/why-does-the-jdbc-pool-timeout-parameter-not-work/297714)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 3\
**Last updated:** [February 22, 2022, 5:45am UTC](https://discuss.elastic.co/t/why-does-the-jdbc-pool-timeout-parameter-not-work/297714 "2022-02-22T05:45:28Z")

</div>

First of all I can't be sure that the jdbc\_pool\_timeout parameter has no effect. I use logstash 7.16 to sync data from mysql 8.0 to elasitcsearch 7.16 cluster. Because this database is a production environment, there …

---

## [Can't install logstash-output-mongodb](https://discuss.elastic.co/t/cant-install-logstash-output-mongodb/297822)

<div class="topic-metadata">

**Author:** [@tamina](https://discuss.elastic.co/u/tamina)\
**Replies:** 0\
**Last updated:** [February 22, 2022, 1:29am UTC](https://discuss.elastic.co/t/cant-install-logstash-output-mongodb/297822 "2022-02-22T01:29:50Z")

</div>

I'm using windows server 2016. I'm using logstash ver 7.17. I'm using install command "bin/logstash-plugin install logstash-output-mongodb". When I try to install logstash-output-mongodb ,I get response only "Using …

---

## [Logstash - org.jruby.exceptions.SystemExit: (SystemExit) exit](https://discuss.elastic.co/t/logstash-org-jruby-exceptions-systemexit-systemexit-exit/297801)

<div class="topic-metadata">

**Author:** [@dontusk1980](https://discuss.elastic.co/u/dontusk1980)\
**Replies:** 1\
**Last updated:** [February 21, 2022, 6:16pm UTC](https://discuss.elastic.co/t/logstash-org-jruby-exceptions-systemexit-systemexit-exit/297801 "2022-02-21T18:16:02Z")

</div>

Hi Team, tried to create one logstash instance from the existing ( with same user data like the other one) but weird message when starting the logstash, details are as below, Could you please help me out with the fix …

---

## [Logstash - REGEX to change a field](https://discuss.elastic.co/t/logstash-regex-to-change-a-field/297769)

<div class="topic-metadata">

**Author:** [@Sylvain\_Renard](https://discuss.elastic.co/u/Sylvain_Renard)\
**Replies:** 1\
**Last updated:** [February 21, 2022, 5:00pm UTC](https://discuss.elastic.co/t/logstash-regex-to-change-a-field/297769 "2022-02-21T17:00:42Z")

</div>

Hello, I'm receiving snmptraps from an equipement with a sequence ID at the end. The sequence ID increase at every new trap. This is normaly considered as a new field and after a while the max of field is reached and I …

---

## [Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/297790)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 4:35pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/297790 "2022-02-21T16:35:33Z")

</div>

Hello all, I am using ELK version 7.16.2 and my Elasticsearch cluster is healthy. when I tried to ingest data through Logstash, it gave me the following error. Am I missing any bundles from setup? "Using bundled JDK: …

---

## [Logstash Running Error](https://discuss.elastic.co/t/logstash-running-error/297601)

<div class="topic-metadata">

**Author:** [@Simone1](https://discuss.elastic.co/u/Simone1)\
**Replies:** 4\
**Last updated:** [February 21, 2022, 4:29pm UTC](https://discuss.elastic.co/t/logstash-running-error/297601 "2022-02-21T16:29:28Z")

</div>

I'm trying to run logstash with a new .conf file and i riceve this error: \[ERROR\] 2022-02-18 12:40:51.495 \[Converge PipelineAction::Create\] agent - Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeR…

---

## [Logstash JDBC input using wrong timezone](https://discuss.elastic.co/t/logstash-jdbc-input-using-wrong-timezone/297621)

<div class="topic-metadata">

**Author:** [@ELK\_ftw](https://discuss.elastic.co/u/ELK_ftw)\
**Replies:** 2\
**Last updated:** [February 21, 2022, 4:11pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-using-wrong-timezone/297621 "2022-02-21T16:11:32Z")

</div>

Hi all, At the client we have a setup lets say elk\_server\_DEV (elk version 7.16.2), here we have a logstash config that uses the jdbc input plugin. We noticed that the lastValues are always in UTC, so one hour of for w…

---

## [Calculate timestamp duration to next document](https://discuss.elastic.co/t/calculate-timestamp-duration-to-next-document/297244)

<div class="topic-metadata">

**Author:** [@jannik.b](https://discuss.elastic.co/u/jannik.b)\
**Replies:** 21\
**Last updated:** [February 21, 2022, 4:08pm UTC](https://discuss.elastic.co/t/calculate-timestamp-duration-to-next-document/297244 "2022-02-21T16:08:39Z")

</div>

Hi, this is my expected result: A new field "time\_taken" which in best case calculates in "ms" the used time between the timestamp in the documents. I would like to sort them later in a table so that I can analyze w…

---

## [Logstash - \_jsonparsefailure on valid json in udp input](https://discuss.elastic.co/t/logstash-jsonparsefailure-on-valid-json-in-udp-input/297753)

<div class="topic-metadata">

**Author:** [@mybyte](https://discuss.elastic.co/u/mybyte)\
**Replies:** 6\
**Last updated:** [February 21, 2022, 3:22pm UTC](https://discuss.elastic.co/t/logstash-jsonparsefailure-on-valid-json-in-udp-input/297753 "2022-02-21T15:22:30Z")

</div>

I'm using Logstash 8.0.0 with a fairly straightforward udp pipeline: input { udp { codec =\> json { charset =\> "UTF-8" } port =\> 12200 } } output { stdout {} } The data is being sent from a custo…

---

## [Add\_field with value from message](https://discuss.elastic.co/t/add-field-with-value-from-message/297777)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 3:37pm UTC](https://discuss.elastic.co/t/add-field-with-value-from-message/297777 "2022-02-21T15:37:36Z")

</div>

Hi, filebeat.yml: multiline.type: pattern multiline.pattern: '^\\d{4}-\\d{2}-\\d{2}\\s\\d{2}:\\d{2}:\\d{2}\\s{3}-\\sStarting' multiline.negate: true multiline.match: after multiline.max\_lines: 140 So in my message fi…

---

## [S3 output plugin](https://discuss.elastic.co/t/s3-output-plugin/297675)

<div class="topic-metadata">

**Author:** [@brunoof1](https://discuss.elastic.co/u/brunoof1)\
**Replies:** 3\
**Last updated:** [February 21, 2022, 12:59pm UTC](https://discuss.elastic.co/t/s3-output-plugin/297675 "2022-02-21T12:59:28Z")

</div>

Hello everyone, everything good ? I have 2 doubts. What are all the file formats supported by the s3 output plugin? I'm using Oracle, kafka and file input and writing to s3 with s3 output. I would like to create Parqu…

---

## [HTTP Filter Assistance](https://discuss.elastic.co/t/http-filter-assistance/297655)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 2\
**Last updated:** [February 21, 2022, 2:21pm UTC](https://discuss.elastic.co/t/http-filter-assistance/297655 "2022-02-21T14:21:06Z")

</div>

Hello, I have a situation where an API I'm trying to leverage which requires multiple API HTTP calls to generate the right document. I have the following document with multiple "id" in an array which I get from a http\_…

---

## [Question about pipelines.workers](https://discuss.elastic.co/t/question-about-pipelines-workers/297759)

<div class="topic-metadata">

**Author:** [@Ioxxy](https://discuss.elastic.co/u/Ioxxy)\
**Replies:** 2\
**Last updated:** [February 21, 2022, 1:22pm UTC](https://discuss.elastic.co/t/question-about-pipelines-workers/297759 "2022-02-21T13:22:06Z")

</div>

Hello, I'm wondering, when a pipeline.workers is define either in logstash.yml and in pipelines.yml, which configuration is applied ? I found out this setting was different in those 2 files. My guess would be that the…

---

## [Logstash elasticsearch output - data\_stream\_auto\_routing](https://discuss.elastic.co/t/logstash-elasticsearch-output-data-stream-auto-routing/297624)

<div class="topic-metadata">

**Author:** [@mybyte](https://discuss.elastic.co/u/mybyte)\
**Replies:** 1\
**Last updated:** [February 21, 2022, 10:58am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-data-stream-auto-routing/297624 "2022-02-21T10:58:42Z")

</div>

I'm a bit confused about the data\_stream\_auto\_routing option when using elasticsearch output to data streams in logstash. According to documentation: Automatically routes events by deriving the data stream name using …

---

## [Grok Expression "match anything until you find a number"](https://discuss.elastic.co/t/grok-expression-match-anything-until-you-find-a-number/297612)

<div class="topic-metadata">

**Author:** [@Andrea\_Bozzano](https://discuss.elastic.co/u/Andrea_Bozzano)\
**Replies:** 2\
**Last updated:** [February 21, 2022, 9:56am UTC](https://discuss.elastic.co/t/grok-expression-match-anything-until-you-find-a-number/297612 "2022-02-21T09:56:34Z")

</div>

Hi everyone, and thank you for your help. I'm struggling a bit because I can't write a correctly matching for Grok for this kind of pattern. The logs I'm trying to process are structured like this (they're IP addresses…

---

## [How to run docker container without any defined pipelines](https://discuss.elastic.co/t/how-to-run-docker-container-without-any-defined-pipelines/297736)

<div class="topic-metadata">

**Author:** [@DazDotOne](https://discuss.elastic.co/u/DazDotOne)\
**Replies:** 0\
**Last updated:** [February 21, 2022, 9:11am UTC](https://discuss.elastic.co/t/how-to-run-docker-container-without-any-defined-pipelines/297736 "2022-02-21T09:11:02Z")

</div>

Is it possible to start logstash within it's docker container (docker.elastic.co/logstash/logstash:7.16.2) without any defined pipelines. Or is there a simple pipeline I can use that will prevent docker from shutting do…

---

## [Logstash stops producing data to RabbitMQ, but service running with no errors](https://discuss.elastic.co/t/logstash-stops-producing-data-to-rabbitmq-but-service-running-with-no-errors/297397)

<div class="topic-metadata">

**Author:** [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Replies:** 1\
**Last updated:** [February 21, 2022, 7:08am UTC](https://discuss.elastic.co/t/logstash-stops-producing-data-to-rabbitmq-but-service-running-with-no-errors/297397 "2022-02-21T07:08:59Z")

</div>

I'm using Filebeat to read from a file & push data to Logstash. Logstash is, in turn, publishing the data to RabbitMQ. But at times we stop receiving data in RabbitMQ. But the logstash service would be running and produ…

---

## [How do I copy field from one input to another?](https://discuss.elastic.co/t/how-do-i-copy-field-from-one-input-to-another/297709)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 2\
**Last updated:** [February 21, 2022, 4:25am UTC](https://discuss.elastic.co/t/how-do-i-copy-field-from-one-input-to-another/297709 "2022-02-21T04:25:39Z")

</div>

Hi Team, I have server where messages are being parsed from file using grok expression and I have also messages coming from packetbeat shipper. I wanted to copy one field if certain criteria met into the one which is be…

---

## [Ecs compatilibity](https://discuss.elastic.co/t/ecs-compatilibity/296732)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 1\
**Last updated:** [February 20, 2022, 9:04pm UTC](https://discuss.elastic.co/t/ecs-compatilibity/296732 "2022-02-20T21:04:51Z")

</div>

hello, I'm receiving a lot of logs regarding pipeline.ecs\_compatibility. The one way is to disable it, but if I would like to enable, which version should I choose ? I have ES and Logstash in latest version 7.16.3

---

## [Creating Index pattern](https://discuss.elastic.co/t/creating-index-pattern/297679)

<div class="topic-metadata">

**Author:** [@Hamdi\_Hassan](https://discuss.elastic.co/u/Hamdi_Hassan)\
**Replies:** 3\
**Last updated:** [February 20, 2022, 2:25pm UTC](https://discuss.elastic.co/t/creating-index-pattern/297679 "2022-02-20T14:25:15Z")

</div>

Problems to create an index pattern I have a problem when I'm trying to create an index pattern in Kibana. I have a system configured in the Elasticsearch cloud for my company, and I access it with a user with superuse…

---

## [Logstash.filters.elasticsearch "Read timed out"](https://discuss.elastic.co/t/logstash-filters-elasticsearch-read-timed-out/297537)

<div class="topic-metadata">

**Author:** [@gregorys](https://discuss.elastic.co/u/gregorys)\
**Replies:** 1\
**Last updated:** [February 20, 2022, 12:45pm UTC](https://discuss.elastic.co/t/logstash-filters-elasticsearch-read-timed-out/297537 "2022-02-20T12:45:37Z")

</div>

Hi, I'm using Logstash 7.17 against Elasticsearch 7.16 cluster. The filter is working for about 9/10 events, but sometimes it fails with this error: "Failed to query Elasticsearch for previous event", "Read timed out" …

---

## [Randomly missing events](https://discuss.elastic.co/t/randomly-missing-events/297377)

<div class="topic-metadata">

**Author:** [@Nasser](https://discuss.elastic.co/u/Nasser)\
**Replies:** 5\
**Last updated:** [February 20, 2022, 11:07am UTC](https://discuss.elastic.co/t/randomly-missing-events/297377 "2022-02-20T11:07:04Z")

</div>

Hi i have one pipeline processing 16 .conf file in each file i have 2 jdbc the issue is sometimes randomly i see logstash miss some jdbc ! i check the logstash-plain.log but nothing abnormal ! i tired to update logs…

---

## [How to log JDBC connection activity?](https://discuss.elastic.co/t/how-to-log-jdbc-connection-activity/297690)

<div class="topic-metadata">

**Author:** [@Nasser](https://discuss.elastic.co/u/Nasser)\
**Replies:** 0\
**Last updated:** [February 20, 2022, 9:20am UTC](https://discuss.elastic.co/t/how-to-log-jdbc-connection-activity/297690 "2022-02-20T09:20:06Z")

</div>

Hi How to log JDBC connection activity? what should i add to log4j.properties ? thanks

---

## [Fixnum is deprecated](https://discuss.elastic.co/t/fixnum-is-deprecated/297669)

<div class="topic-metadata">

**Author:** [@Nasser](https://discuss.elastic.co/u/Nasser)\
**Replies:** 1\
**Last updated:** [February 19, 2022, 6:49pm UTC](https://discuss.elastic.co/t/fixnum-is-deprecated/297669 "2022-02-19T18:49:22Z")

</div>

Hi i got this error when i run logstash \[2022-02-17T16:37:37,651\]\[INFO \]\[logstash.javapipeline \]\[main\] Pipeline started {"pipeline.id"=\>"main"} \[2022-02-17T16:37:37,728\]\[INFO \]\[logstash.agent \] Pipelines r…

---

## [SSL Subject Missing on TCP Input Plugin](https://discuss.elastic.co/t/ssl-subject-missing-on-tcp-input-plugin/297632)

<div class="topic-metadata">

**Author:** [@gharryg](https://discuss.elastic.co/u/gharryg)\
**Replies:** 1\
**Last updated:** [February 18, 2022, 10:31pm UTC](https://discuss.elastic.co/t/ssl-subject-missing-on-tcp-input-plugin/297632 "2022-02-18T22:31:18Z")

</div>

I am working with Logstash (8.0.0) and using the TCP input plugin with SSL enabled. According the documentation, there should be a field that contains the subject of the certificate for the connecting client. However, it…

---

## [Logstash thread using high CPU usage](https://discuss.elastic.co/t/logstash-thread-using-high-cpu-usage/297634)

<div class="topic-metadata">

**Author:** [@jestin.varghese](https://discuss.elastic.co/u/jestin.varghese)\
**Replies:** 1\
**Last updated:** [February 18, 2022, 8:32pm UTC](https://discuss.elastic.co/t/logstash-thread-using-high-cpu-usage/297634 "2022-02-18T20:32:33Z")

</div>

Hi, Following threads in our logstash is using high CPU usage ====================== bash-4.2$ curl -XGET 'localhost:9600/\_node/hot\_threads?human=true' ::: {} Hot threads at 2022-02-18T19:50:45+01:00, busiestThreads…

---

## [Issue with logstash then elasticsearch : message (from grok) not creating fields?](https://discuss.elastic.co/t/issue-with-logstash-then-elasticsearch-message-from-grok-not-creating-fields/297555)

<div class="topic-metadata">

**Author:** [@ledufakademy](https://discuss.elastic.co/u/ledufakademy)\
**Replies:** 8\
**Last updated:** [February 18, 2022, 6:24pm UTC](https://discuss.elastic.co/t/issue-with-logstash-then-elasticsearch-message-from-grok-not-creating-fields/297555 "2022-02-18T18:24:56Z")

</div>

First i 'm trying to add my HAPROXY ALOHA 13.5 LTS (we cannot install nothing on this appliance, so FileBeat ... not for us , but perhaps i'm wrong ?) syslog to Elasticsearch (Kiban gui). So i decide to send syslog dat…

---

## [Error : \[LogStash::Runner\] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified \[FATAL\] 2022-02-18 16:47:25.987 \[LogStash::Runner\] runner - The given configuration is invalid](https://discuss.elastic.co/t/error-logstash-runner-multilocal-ignoring-the-pipelines-yml-file-because-modules-or-command-line-options-are-specified-fatal-2022-02-18-1625-987-logstash-runner-runner-the-given-configuration-is-invalid/297628)

<div class="topic-metadata">

**Author:** [@d6036de2b54af16665f4](https://discuss.elastic.co/u/d6036de2b54af16665f4)\
**Replies:** 0\
**Last updated:** [February 18, 2022, 4:53pm UTC](https://discuss.elastic.co/t/error-logstash-runner-multilocal-ignoring-the-pipelines-yml-file-because-modules-or-command-line-options-are-specified-fatal-2022-02-18-1625-987-logstash-runner-runner-the-given-configuration-is-invalid/297628 "2022-02-18T16:53:19Z")

</div>

I am getting this error Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console \[WARN \] 2022-02-18 16:47:25.536 \[LogStash::Runner\]…

---

## [S3 connection with logstash file |||||I get a input from S3 bucket in my Logstash .conf files](https://discuss.elastic.co/t/s3-connection-with-logstash-file-i-get-a-input-from-s3-bucket-in-my-logstash-conf-files/297626)

<div class="topic-metadata">

**Author:** [@d6036de2b54af16665f4](https://discuss.elastic.co/u/d6036de2b54af16665f4)\
**Replies:** 2\
**Last updated:** [February 18, 2022, 4:45pm UTC](https://discuss.elastic.co/t/s3-connection-with-logstash-file-i-get-a-input-from-s3-bucket-in-my-logstash-conf-files/297626 "2022-02-18T16:45:55Z")

</div>

In one of .conf file i received No files found is s3 bucket . So is this is error of my connection with S3 bucket is wrong. How i can check this that is problem is their or not ? var/log/logstash Logs \[2022-02-18T16:…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=158)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=160)
