# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=164

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 165

---

## [Getting separate values from single variable value in logstash](https://discuss.elastic.co/t/getting-separate-values-from-single-variable-value-in-logstash/295806)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 4\
**Last updated:** [January 31, 2022, 11:50am UTC](https://discuss.elastic.co/t/getting-separate-values-from-single-variable-value-in-logstash/295806 "2022-01-31T11:50:16Z")

</div>

I have log line as follows file\_name,file\_id,size,file\_owner,folder\_id,folder\_name,path\_ids,folder\_owner,deleted,date\_modified,date\_uploaded,folder\_paths nash+animal models.docx,884054786846,20068,xyz@123.com,1499863948…

---

## [How to convert String into JSon format?](https://discuss.elastic.co/t/how-to-convert-string-into-json-format/295703)

<div class="topic-metadata">

**Author:** [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Replies:** 3\
**Last updated:** [January 31, 2022, 10:17am UTC](https://discuss.elastic.co/t/how-to-convert-string-into-json-format/295703 "2022-01-31T10:17:20Z")

</div>

Hello Friends, Need your help to parse string into Json format in logstash. { "id":"xxx", "MessageCreateDate":"2022-01-20", "Response":"{'Cardholder':{'cards':\[{'isPrimaryCard':'N','cardNumber':'xxxxxxxxxx','r…

---

## [Copy complete event to a field of a new event](https://discuss.elastic.co/t/copy-complete-event-to-a-field-of-a-new-event/295583)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 7\
**Last updated:** [January 31, 2022, 9:26am UTC](https://discuss.elastic.co/t/copy-complete-event-to-a-field-of-a-new-event/295583 "2022-01-31T09:26:52Z")

</div>

Hi, I want to copy all fields of an event to a field of a new event in a logstash filter This { " agent ": " Mozilla / 5.0(compatible; MSIE 9.0)", " ip ": " 192.168.24.44 ", " request ": " / in…

---

## [Docker logstash keeps heapdumping](https://discuss.elastic.co/t/docker-logstash-keeps-heapdumping/295801)

<div class="topic-metadata">

**Author:** [@RandomRobbie](https://discuss.elastic.co/u/RandomRobbie)\
**Replies:** 3\
**Last updated:** [January 31, 2022, 7:12am UTC](https://discuss.elastic.co/t/docker-logstash-keeps-heapdumping/295801 "2022-01-31T07:12:43Z")

</div>

Hey, I am using logstash to load a Elasticsearch full of data from text files that i wish to keep the files afterwards as well. Current Logstash Config. input { beats { port =\> 5044 } tcp { port =\> 5001 } …

---

## [How to use Grok for JSON parsing](https://discuss.elastic.co/t/how-to-use-grok-for-json-parsing/295794)

<div class="topic-metadata">

**Author:** [@Adabi\_Raihan](https://discuss.elastic.co/u/Adabi_Raihan)\
**Replies:** 2\
**Last updated:** [January 31, 2022, 4:58am UTC](https://discuss.elastic.co/t/how-to-use-grok-for-json-parsing/295794 "2022-01-31T04:58:59Z")

</div>

Hi, I want to parse this JSON object to ELK { "Format": "IDEA0", "ID": "2b03eb1f-fc4c-4f67-94e5-31c9fb32dccc", "DetectTime": "2022-01-31T08:16:12.600470+07:00", "EventTime": "2022-01-31T01:23:01.637438+00:00", "Categor…

---

## [Cef message split](https://discuss.elastic.co/t/cef-message-split/295797)

<div class="topic-metadata">

**Author:** [@Rohit\_Mangotra](https://discuss.elastic.co/u/Rohit_Mangotra)\
**Replies:** 5\
**Last updated:** [January 31, 2022, 4:08am UTC](https://discuss.elastic.co/t/cef-message-split/295797 "2022-01-31T04:08:46Z")

</div>

Hi, I am new to ELK and learning it now as part of my job. I am getting .cef logs from imperva waf that needs to be split in to fields so that it can be uploaded to the Elastic. Please let me know how I can achieve thi…

---

## [Issues with apply filters](https://discuss.elastic.co/t/issues-with-apply-filters/295761)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 0\
**Last updated:** [January 29, 2022, 7:51pm UTC](https://discuss.elastic.co/t/issues-with-apply-filters/295761 "2022-01-29T19:51:11Z")

</div>

Hello, I upgraded logstash to the latest version 7.16.3 and I have issues with apply required filters, Maybe this is related with specific ports closed, As output I'm receiving below: ./logstash-plugin install logsta…

---

## [Write data that have failed in Logstash filter transforms to file](https://discuss.elastic.co/t/write-data-that-have-failed-in-logstash-filter-transforms-to-file/295649)

<div class="topic-metadata">

**Author:** [@GitSpree23](https://discuss.elastic.co/u/GitSpree23)\
**Replies:** 4\
**Last updated:** [January 29, 2022, 12:38pm UTC](https://discuss.elastic.co/t/write-data-that-have-failed-in-logstash-filter-transforms-to-file/295649 "2022-01-29T12:38:33Z")

</div>

My logstash config has a filter performing several transformations. But I see many records failing to get processed because of incorrect format/encoding in source data. I want Logstash to write these failed inputs to a …

---

## [Configure Filebeat to input a specific logs of my app pods in AKS](https://discuss.elastic.co/t/configure-filebeat-to-input-a-specific-logs-of-my-app-pods-in-aks/295737)

<div class="topic-metadata">

**Author:** [@amgmdz](https://discuss.elastic.co/u/amgmdz)\
**Replies:** 0\
**Last updated:** [January 29, 2022, 12:37am UTC](https://discuss.elastic.co/t/configure-filebeat-to-input-a-specific-logs-of-my-app-pods-in-aks/295737 "2022-01-29T00:37:52Z")

</div>

I have an application in a kubernetes (AKS) this app generates logs in /logs/\*.log, my problem is that I do not know what configuration to do in Filebeat (this is deployed on AKS nodes) to recognize the logs and send the…

---

## [LogStash::Json::ParserError: Unexpected end-of-input within/between Object entries for curly brace inside string](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-within-between-object-entries-for-curly-brace-inside-string/295659)

<div class="topic-metadata">

**Author:** [@truptir](https://discuss.elastic.co/u/truptir)\
**Replies:** 1\
**Last updated:** [January 28, 2022, 4:05pm UTC](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-within-between-object-entries-for-curly-brace-inside-string/295659 "2022-01-28T16:05:28Z")

</div>

When String contains opening curly braces '{' logstash failed to parse that JSON. As per JSON doc, we don't need to escape curly brace. then how can I parse this type of JSON through logstash? JSON file: { "DESCRIPTIO…

---

## [Set “ssl” parameter for jdbc input plugin for cassandra](https://discuss.elastic.co/t/set-ssl-parameter-for-jdbc-input-plugin-for-cassandra/295711)

<div class="topic-metadata">

**Author:** [@Akshay\_Kulkarni](https://discuss.elastic.co/u/Akshay_Kulkarni)\
**Replies:** 0\
**Last updated:** [January 28, 2022, 1:46pm UTC](https://discuss.elastic.co/t/set-ssl-parameter-for-jdbc-input-plugin-for-cassandra/295711 "2022-01-28T13:46:10Z")

</div>

Hi, Im trying to connect to ssl cassandra with dbschema jdbc drivers. but failing to connect. where as successful to connect to non ssl cassandra db. Also with cdata drivers im able to connect both ssl & non ssl cassa…

---

## [Filter to send only system shortnames](https://discuss.elastic.co/t/filter-to-send-only-system-shortnames/295704)

<div class="topic-metadata">

**Author:** [@StuWhitby](https://discuss.elastic.co/u/StuWhitby)\
**Replies:** 1\
**Last updated:** [January 28, 2022, 1:17pm UTC](https://discuss.elastic.co/t/filter-to-send-only-system-shortnames/295704 "2022-01-28T13:17:27Z")

</div>

Hi, I'm new to Logstash, and attempting to update our company's configuration which currently sends syslog data to Splunk. I've searched on how to standardise the system naming, which may have the shortname or the long…

---

## [Error registering plugin Beats input](https://discuss.elastic.co/t/error-registering-plugin-beats-input/295596)

<div class="topic-metadata">

**Author:** [@florinb](https://discuss.elastic.co/u/florinb)\
**Replies:** 2\
**Last updated:** [January 28, 2022, 11:04am UTC](https://discuss.elastic.co/t/error-registering-plugin-beats-input/295596 "2022-01-28T11:04:28Z")

</div>

i'm running a dockerised Logstash 6.8.23 on java 1.8 image with all dependencies fulfilled: $ java -version openjdk version "1.8.0\_312" OpenJDK Runtime Environment (build 1.8.0\_312-b07) OpenJDK 64-Bit Server VM (build 2…

---

## [Aggregate multiple in logstash](https://discuss.elastic.co/t/aggregate-multiple-in-logstash/295602)

<div class="topic-metadata">

**Author:** [@marc0069urca](https://discuss.elastic.co/u/marc0069urca)\
**Replies:** 3\
**Last updated:** [January 28, 2022, 9:24am UTC](https://discuss.elastic.co/t/aggregate-multiple-in-logstash/295602 "2022-01-28T09:24:00Z")

</div>

Hello I am having trouble merging data from different SQL data tables. I can see that the data is saved in ELK as the different SQL entries are made but when arriving at the aggregation filter, it renames the fields we…

---

## [Logstash scheduling for every 5 mins hour using rss input](https://discuss.elastic.co/t/logstash-scheduling-for-every-5-mins-hour-using-rss-input/295544)

<div class="topic-metadata">

**Author:** [@saik1](https://discuss.elastic.co/u/saik1)\
**Replies:** 2\
**Last updated:** [January 28, 2022, 4:37am UTC](https://discuss.elastic.co/t/logstash-scheduling-for-every-5-mins-hour-using-rss-input/295544 "2022-01-28T04:37:42Z")

</div>

Hi, EveryOne, how can i schedule logstash for every 5mins using rss input? Regads kiran

---

## [Deletion of old output files](https://discuss.elastic.co/t/deletion-of-old-output-files/295622)

<div class="topic-metadata">

**Author:** [@smzd](https://discuss.elastic.co/u/smzd)\
**Replies:** 0\
**Last updated:** [January 27, 2022, 6:45pm UTC](https://discuss.elastic.co/t/deletion-of-old-output-files/295622 "2022-01-27T18:45:15Z")

</div>

Hello, my logstash is outputing logs in files to then be ingested by elastic agent. In order to not have huge amount of disk being consumed by logs, I would like to rotate logs and then delete the old ones (after 3 day…

---

## [Index can not assign to a default ilm policy](https://discuss.elastic.co/t/index-can-not-assign-to-a-default-ilm-policy/295607)

<div class="topic-metadata">

**Author:** [@baalchina](https://discuss.elastic.co/u/baalchina)\
**Replies:** 1\
**Last updated:** [January 27, 2022, 6:27pm UTC](https://discuss.elastic.co/t/index-can-not-assign-to-a-default-ilm-policy/295607 "2022-01-27T18:27:29Z")

</div>

Hi, I am using logstash to collect my switch's syslog. Here is the logstash config like: input{ syslog{ type =\> "syslog-sw-hw-128" host =\> "1.2.3.4" port =\> 580 } } output{ if \[type\]…

---

## [Logstash configuration](https://discuss.elastic.co/t/logstash-configuration/295423)

<div class="topic-metadata">

**Author:** [@puneet\_makhija](https://discuss.elastic.co/u/puneet_makhija)\
**Replies:** 12\
**Last updated:** [January 27, 2022, 4:26pm UTC](https://discuss.elastic.co/t/logstash-configuration/295423 "2022-01-27T16:26:22Z")

</div>

Hello everyone, I am stuck in log stash configuration here below is my configuration please let me know what is wrong in this configuration # Sample Logstash configuration for creating a simple # Beats -\> Logstash -\> …

---

## [Hi all, I am trying to create logstash pipeline to ingest data into elasticsearch but getting this error](https://discuss.elastic.co/t/hi-all-i-am-trying-to-create-logstash-pipeline-to-ingest-data-into-elasticsearch-but-getting-this-error/295576)

<div class="topic-metadata">

**Author:** [@Chinmay\_Bhusate](https://discuss.elastic.co/u/Chinmay_Bhusate)\
**Replies:** 4\
**Last updated:** [January 27, 2022, 12:25pm UTC](https://discuss.elastic.co/t/hi-all-i-am-trying-to-create-logstash-pipeline-to-ingest-data-into-elasticsearch-but-getting-this-error/295576 "2022-01-27T12:25:22Z")

</div>

\[2022-01-27T17:02:19,895\]\[ERROR\]\[logstash.agent \] An exception happened when converging configuration {:exception=\>LogStash::Error, :message=\>"Don't know how to handle Java::JavaLang::IllegalStateException for P…

---

## [What is wrong with my logstash conf?](https://discuss.elastic.co/t/what-is-wrong-with-my-logstash-conf/295577)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 2\
**Last updated:** [January 27, 2022, 12:10pm UTC](https://discuss.elastic.co/t/what-is-wrong-with-my-logstash-conf/295577 "2022-01-27T12:10:34Z")

</div>

Hello, I installed a new Windows instance that is running parrallel to my Linux Cluster. The Problem: The following .conf file works perfectly on Linux, but not on Windows: input { file { path =\> \[ "C:\\Elas…

---

## [Logstash Cisco ASA logs "grokparsefailure" in logs tag](https://discuss.elastic.co/t/logstash-cisco-asa-logs-grokparsefailure-in-logs-tag/295571)

<div class="topic-metadata">

**Author:** [@zahid4](https://discuss.elastic.co/u/zahid4)\
**Replies:** 0\
**Last updated:** [January 27, 2022, 11:14am UTC](https://discuss.elastic.co/t/logstash-cisco-asa-logs-grokparsefailure-in-logs-tag/295571 "2022-01-27T11:14:36Z")

</div>

Im using the following configuration in the logstash to parse cisco logs and send to ELK: Im getting "grokparsefailure" in logs tag of cisco ASA logs although the format is correct.

---

## [Split a doc to multiple docs](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531)

<div class="topic-metadata">

**Author:** [@cris](https://discuss.elastic.co/u/cris)\
**Replies:** 6\
**Last updated:** [January 27, 2022, 4:41am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531 "2022-01-27T04:41:44Z")

</div>

Hello friends. I am trying to reindex some data to another index but with a little differences. In the first index I have this kind of hit: { "ENVA": { "Login": { "status": "passed" } }, "ENVB": { …

---

## [Logstash 7.16.3 Error： (LoadError) load error: rubygems/text -- java.lang.NoClassDefFoundError: org/jruby/util/Sprintf](https://discuss.elastic.co/t/logstash-7-16-3-error-loaderror-load-error-rubygems-text-java-lang-noclassdeffounderror-org-jruby-util-sprintf/295536)

<div class="topic-metadata">

**Author:** [@seth\_qiang](https://discuss.elastic.co/u/seth_qiang)\
**Replies:** 0\
**Last updated:** [January 27, 2022, 4:21am UTC](https://discuss.elastic.co/t/logstash-7-16-3-error-loaderror-load-error-rubygems-text-java-lang-noclassdeffounderror-org-jruby-util-sprintf/295536 "2022-01-27T04:21:58Z")

</div>

hello, everyone logstash 7.16.3 on docker-compose version: '3.4' services: new-elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:7.16.3 container\_name: new-elasticsearch environment:…

---

## [ERROR COMPILING LOGSTASH CODEBASE TO GENERATE THE .JAR FILE CONTAINING THE JAVA PLUGIN API](https://discuss.elastic.co/t/error-compiling-logstash-codebase-to-generate-the-jar-file-containing-the-java-plugin-api/295528)

<div class="topic-metadata">

**Author:** [@uday22](https://discuss.elastic.co/u/uday22)\
**Replies:** 0\
**Last updated:** [January 27, 2022, 12:34am UTC](https://discuss.elastic.co/t/error-compiling-logstash-codebase-to-generate-the-jar-file-containing-the-java-plugin-api/295528 "2022-01-27T00:34:13Z")

</div>

Error compiling logstash codebase to generate the java plugin API to develop logstash java plugin. running gradlew.bat assemble from root directory of logstash codebase getting below error. Exception in thread "main" …

---

## [JDBC input, kafka output, syntax error, unexpected end-of-file Java:: after pipeline starts](https://discuss.elastic.co/t/jdbc-input-kafka-output-syntax-error-unexpected-end-of-file-java-after-pipeline-starts/294452)

<div class="topic-metadata">

**Author:** [@rschmerb](https://discuss.elastic.co/u/rschmerb)\
**Replies:** 6\
**Last updated:** [January 26, 2022, 7:09pm UTC](https://discuss.elastic.co/t/jdbc-input-kafka-output-syntax-error-unexpected-end-of-file-java-after-pipeline-starts/294452 "2022-01-26T19:09:32Z")

</div>

We are seeing the following error messages after starting our pipeline: \[2022-01-13T19:48:06,009\]\[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (SyntaxError) (eval):1: syntax error, un…

---

## [Logstash http poller](https://discuss.elastic.co/t/logstash-http-poller/295441)

<div class="topic-metadata">

**Author:** [@Ingram\_Gultom](https://discuss.elastic.co/u/Ingram_Gultom)\
**Replies:** 3\
**Last updated:** [January 26, 2022, 6:03pm UTC](https://discuss.elastic.co/t/logstash-http-poller/295441 "2022-01-26T18:03:04Z")

</div>

Hi, I am using logstash 7.13.4 and I want to use http poller for this url http://10.10.10.10:8080/dbonequerydata/?username=user/password=password/encrypted=false/conversion=true/DT=csv -H "Content-Type: application/xml…

---

## [Creating a new pipeline in Logstash](https://discuss.elastic.co/t/creating-a-new-pipeline-in-logstash/295478)

<div class="topic-metadata">

**Author:** [@goncalobsantos](https://discuss.elastic.co/u/goncalobsantos)\
**Replies:** 1\
**Last updated:** [January 26, 2022, 4:16pm UTC](https://discuss.elastic.co/t/creating-a-new-pipeline-in-logstash/295478 "2022-01-26T16:16:58Z")

</div>

Step 1. I have edited the pipelines.yml file, adding a third pipeline to the two already existing. Step 2. The corresponding configuration file is placed in the /conf.d folder. Step 3. I stoped and started logstash, ex…

---

## [Logstash with many config files vs one config with many files](https://discuss.elastic.co/t/logstash-with-many-config-files-vs-one-config-with-many-files/295473)

<div class="topic-metadata">

**Author:** [@nikssssss](https://discuss.elastic.co/u/nikssssss)\
**Replies:** 2\
**Last updated:** [January 26, 2022, 3:44pm UTC](https://discuss.elastic.co/t/logstash-with-many-config-files-vs-one-config-with-many-files/295473 "2022-01-26T15:44:46Z")

</div>

hello everybody, i have not understand what is the best solution if you have many input files. Should you use one config file with the configuration of input files or create one config file per input file. (ex. 5-10 fil…

---

## [The logstash container crashes the network of the host machine and then exit with OOM killer](https://discuss.elastic.co/t/the-logstash-container-crashes-the-network-of-the-host-machine-and-then-exit-with-oom-killer/295477)

<div class="topic-metadata">

**Author:** [@Ahmad\_BenMaallem](https://discuss.elastic.co/u/Ahmad_BenMaallem)\
**Replies:** 0\
**Last updated:** [January 26, 2022, 3:36pm UTC](https://discuss.elastic.co/t/the-logstash-container-crashes-the-network-of-the-host-machine-and-then-exit-with-oom-killer/295477 "2022-01-26T15:36:51Z")

</div>

Hello, I am trying to run a logstash 7.14.1 with docker-compose to collect logs from multiple files and write them to a remote Elasticsearch. After starting, logstash manages to send my logs to Elasticsearch without pr…

---

## [Pipe to pipe with multiline codec on the second pipe](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456)

<div class="topic-metadata">

**Author:** [@John\_Smith1](https://discuss.elastic.co/u/John_Smith1)\
**Replies:** 4\
**Last updated:** [January 26, 2022, 2:51pm UTC](https://discuss.elastic.co/t/pipe-to-pipe-with-multiline-codec-on-the-second-pipe/295456 "2022-01-26T14:51:33Z")

</div>

It's seems impossible, but just in case want to ask, is there some way to apply multiline code plugin in the second pipe, that receive logs from first pipe. first pipe pipe\_01.conf output: pipeline { send\_to =\>…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=163)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=165)
