# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=165

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 166

---

## [Logstash LogStash::Error: Don’t know how to handle \`Java::JavaLang::IllegalArgumentException\` for \`PipelineAction::Create\<main\>\`](https://discuss.elastic.co/t/logstash-logstash-don-t-know-how-to-handle-java-illegalargumentexception-for-pipelineaction-create-main/295468)

<div class="topic-metadata">

**Author:** [@Faisal\_Malik](https://discuss.elastic.co/u/Faisal_Malik)\
**Replies:** 0\
**Last updated:** [January 26, 2022, 2:44pm UTC](https://discuss.elastic.co/t/logstash-logstash-don-t-know-how-to-handle-java-illegalargumentexception-for-pipelineaction-create-main/295468 "2022-01-26T14:44:43Z")

</div>

My logstash was working fine through the Helm chart in Kubernetes stateful set. I updated the logstash version from 7.9 to 7.16.2 but its don't work so I revert to the previous version 7.9 After reverting it also gives …

---

## [Broken Grok filter since V7.10.0](https://discuss.elastic.co/t/broken-grok-filter-since-v7-10-0/295379)

<div class="topic-metadata">

**Author:** [@Landong.Zuo](https://discuss.elastic.co/u/Landong.Zuo)\
**Replies:** 2\
**Last updated:** [January 26, 2022, 2:09pm UTC](https://discuss.elastic.co/t/broken-grok-filter-since-v7-10-0/295379 "2022-01-26T14:09:22Z")

</div>

Hi , I've recently upgraded logstash from V7.6.0 to V7.16.3. and have seen some odd behaviors of Grok filter since then. filter { grok { patterns\_dir =\> "C:\\software\\ELK\\config\\patterns" …

---

## [Extracting key pair Values using nested Json Paths](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419)

<div class="topic-metadata">

**Author:** [@vaseemQA](https://discuss.elastic.co/u/vaseemQA)\
**Replies:** 4\
**Last updated:** [January 26, 2022, 1:35pm UTC](https://discuss.elastic.co/t/extracting-key-pair-values-using-nested-json-paths/295419 "2022-01-26T13:35:26Z")

</div>

Hi Guys, I'm Using Json plugin in filter and trying to fetch a value which resides in below json path. parsedJson.query.bool.filter\[0\].bool.must\[0\].bool.must\[2\].term\["list\_attributes.orderId.long"\].value and actually …

---

## [Logstash-plugin.bat fails to find bundled Java in 7.16.1](https://discuss.elastic.co/t/logstash-plugin-bat-fails-to-find-bundled-java-in-7-16-1/295358)

<div class="topic-metadata">

**Author:** [@stevedearl](https://discuss.elastic.co/u/stevedearl)\
**Replies:** 3\
**Last updated:** [January 26, 2022, 9:54am UTC](https://discuss.elastic.co/t/logstash-plugin-bat-fails-to-find-bundled-java-in-7-16-1/295358 "2022-01-26T09:54:07Z")

</div>

Hi All, I upgraded to 7.16.1 a little while back and noticed today that when I try to list the installed plugins I get the following error: C:\\APPS\\ELASTIC\\logstash-7.16.1\\bin\>logstash-plugin.bat list "Using bundled JD…

---

## [Calculate time difference between two different time values excluding weekends](https://discuss.elastic.co/t/calculate-time-difference-between-two-different-time-values-excluding-weekends/295413)

<div class="topic-metadata">

**Author:** [@ryann](https://discuss.elastic.co/u/ryann)\
**Replies:** 2\
**Last updated:** [January 26, 2022, 5:10am UTC](https://discuss.elastic.co/t/calculate-time-difference-between-two-different-time-values-excluding-weekends/295413 "2022-01-26T05:10:53Z")

</div>

Currently have a logstash conf file that is gathering events with two time fields, createdDate and closedDate. Have a ruby code that calculates the time difference which is working as intended but looking for a way to ex…

---

## [Logstash error info : A plugin had an unrecoverable error. Will restart this plugin](https://discuss.elastic.co/t/logstash-error-info-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/295414)

<div class="topic-metadata">

**Author:** [@seth\_qiang](https://discuss.elastic.co/u/seth_qiang)\
**Replies:** 0\
**Last updated:** [January 26, 2022, 2:52am UTC](https://discuss.elastic.co/t/logstash-error-info-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/295414 "2022-01-26T02:52:40Z")

</div>

hi, everyone my logstash have some errors in my logstash. as follows keywords A plugin had an unrecoverable error. Will restart this plugin. Pipeline\_id:main Error: event executor terminated Exception: Java::JavaUt…

---

## [Logstash TCP Zero Window - Palo Alto logs](https://discuss.elastic.co/t/logstash-tcp-zero-window-palo-alto-logs/295396)

<div class="topic-metadata">

**Author:** [@groth](https://discuss.elastic.co/u/groth)\
**Replies:** 3\
**Last updated:** [January 25, 2022, 10:36pm UTC](https://discuss.elastic.co/t/logstash-tcp-zero-window-palo-alto-logs/295396 "2022-01-25T22:36:06Z")

</div>

New to troubleshooting Logstash performance issues. I have a cluster of 3 load balanced virtual servers running Logstash that forward on to Elasticsearch in the cloud. We've noticed that we're not getting all of our logs…

---

## [Could not determine ID for filter/useragent](https://discuss.elastic.co/t/could-not-determine-id-for-filter-useragent/294270)

<div class="topic-metadata">

**Author:** [@Chris\_Andrews](https://discuss.elastic.co/u/Chris_Andrews)\
**Replies:** 4\
**Last updated:** [January 25, 2022, 8:39pm UTC](https://discuss.elastic.co/t/could-not-determine-id-for-filter-useragent/294270 "2022-01-25T20:39:21Z")

</div>

We have upgraded logstash from 7.5.2 to 7.16.2 on three separate instances. The first two upgraded with no issues whatsoever, however the final upgrade encountered this problem and now logstash crashes: Stack trace: \[2…

---

## [LogStash V7.16.3 file plugin failed to load](https://discuss.elastic.co/t/logstash-v7-16-3-file-plugin-failed-to-load/295332)

<div class="topic-metadata">

**Author:** [@Landong.Zuo](https://discuss.elastic.co/u/Landong.Zuo)\
**Replies:** 2\
**Last updated:** [January 25, 2022, 5:13pm UTC](https://discuss.elastic.co/t/logstash-v7-16-3-file-plugin-failed-to-load/295332 "2022-01-25T17:13:35Z")

</div>

Hi , I've installed Logstash V7.16.3 on Windows 10, and I am struggling to load log files using the following configuration even after deleting the sinceDB input { file { path =\> "C:\\software\\EL…

---

## [Facing problem to break this log in grok pattern](https://discuss.elastic.co/t/facing-problem-to-break-this-log-in-grok-pattern/295305)

<div class="topic-metadata">

**Author:** [@jannatnishat](https://discuss.elastic.co/u/jannatnishat)\
**Replies:** 1\
**Last updated:** [January 25, 2022, 5:02pm UTC](https://discuss.elastic.co/t/facing-problem-to-break-this-log-in-grok-pattern/295305 "2022-01-25T17:02:29Z")

</div>

=================== Start: 2022-01-23-16:44:04 ====================== URL:https://www.siikoytto.com/siikoytto/api/v5/selfcare/dpdp/get\_subscriptions Request:{"msisdn":"880139919"} Response:{"status":true,"message":"Su…

---

## [Logstash on prem - Kubernetes or not](https://discuss.elastic.co/t/logstash-on-prem-kubernetes-or-not/295372)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 0\
**Last updated:** [January 25, 2022, 4:15pm UTC](https://discuss.elastic.co/t/logstash-on-prem-kubernetes-or-not/295372 "2022-01-25T16:15:47Z")

</div>

Hi, I'm checking for the advantages/disadvantages to install logstash on openshift (On Prem) or VMWare. Someone has some tips/advice/.. ? thanks in advance.

---

## [Debugging root cause for high Purgatory size in Kafka](https://discuss.elastic.co/t/debugging-root-cause-for-high-purgatory-size-in-kafka/295324)

<div class="topic-metadata">

**Author:** [@LHozzan](https://discuss.elastic.co/u/LHozzan)\
**Replies:** 0\
**Last updated:** [January 25, 2022, 9:54am UTC](https://discuss.elastic.co/t/debugging-root-cause-for-high-purgatory-size-in-kafka/295324 "2022-01-25T09:54:34Z")

</div>

We using ELK stack (7.10.2) in Kubernetes (1.21.5). After several time our service provider Gardener change OS version (318.9.0 -\> 576.1.0) and our troubles with logging stack started. It seems, that Kafka (v 2.8.1, 2 p…

---

## [How to build logstash-input-tcp v6.0.3 plugin?](https://discuss.elastic.co/t/how-to-build-logstash-input-tcp-v6-0-3-plugin/295295)

<div class="topic-metadata">

**Author:** [@SHUBHAM\_JAIN1](https://discuss.elastic.co/u/SHUBHAM_JAIN1)\
**Replies:** 1\
**Last updated:** [January 25, 2022, 9:04am UTC](https://discuss.elastic.co/t/how-to-build-logstash-input-tcp-v6-0-3-plugin/295295 "2022-01-25T09:04:54Z")

</div>

please mention step for making build gem for logstash-input-tcp plugin for version 6.0.3

---

## [DEVELOP JAVA OUTPUT PLUGIN FOR APPLICATION LOG](https://discuss.elastic.co/t/develop-java-output-plugin-for-application-log/295293)

<div class="topic-metadata">

**Author:** [@uday22](https://discuss.elastic.co/u/uday22)\
**Replies:** 0\
**Last updated:** [January 25, 2022, 2:43am UTC](https://discuss.elastic.co/t/develop-java-output-plugin-for-application-log/295293 "2022-01-25T02:43:58Z")

</div>

An application log every line of the message is different from another line. In that, need to extract the IP address and username by using the java output plugin. which method and PluginConfigSpec should use in the plugi…

---

## [Ec2 role based access failing for s3-input-plugin if we upgrade ec2 to use metadata v2](https://discuss.elastic.co/t/ec2-role-based-access-failing-for-s3-input-plugin-if-we-upgrade-ec2-to-use-metadata-v2/295271)

<div class="topic-metadata">

**Author:** [@uma\_rengasamy](https://discuss.elastic.co/u/uma_rengasamy)\
**Replies:** 0\
**Last updated:** [January 24, 2022, 6:56pm UTC](https://discuss.elastic.co/t/ec2-role-based-access-failing-for-s3-input-plugin-if-we-upgrade-ec2-to-use-metadata-v2/295271 "2022-01-24T18:56:29Z")

</div>

Logstash Version : logstash 7.2.0 aws-cli/1.18.157 Python/3.6.8 Linux/4.18.0-305.12.1.el8\_4.x86\_64 botocore/1.18.16 logstash-input-s3 (3.4.1) aws-cli/1.18.157 Python/3.6.8 Linux/4.18.0-305.12.1.el8\_4.x86\_64 botocore/1…

---

## [Error while connecting logstash to kafka](https://discuss.elastic.co/t/error-while-connecting-logstash-to-kafka/295189)

<div class="topic-metadata">

**Author:** [@Avnish\_Singh](https://discuss.elastic.co/u/Avnish_Singh)\
**Replies:** 0\
**Last updated:** [January 24, 2022, 8:16am UTC](https://discuss.elastic.co/t/error-while-connecting-logstash-to-kafka/295189 "2022-01-24T08:16:31Z")

</div>

Hi I'm trying to run logstash with input as Kafka and output to file, here is the pipeline config file: input { kafka { bootstrap\_servers =\> "kafka\_server:9092 topics =\> \["Topic1", "Topic2", "Topic3"\] …

---

## [Logstash throughput ramping up too slowly -- throttle filter?](https://discuss.elastic.co/t/logstash-throughput-ramping-up-too-slowly-throttle-filter/295285)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 0\
**Last updated:** [January 24, 2022, 9:43pm UTC](https://discuss.elastic.co/t/logstash-throughput-ramping-up-too-slowly-throttle-filter/295285 "2022-01-24T21:43:42Z")

</div>

We have a (Windows) logs stream pulled out of Kafka and pushed into ES. During site events our rate can spike to many multiples. When this happens, Logstash appears to delay messages getting in to ES. It's not due to …

---

## [Iterating over the same grok filter](https://discuss.elastic.co/t/iterating-over-the-same-grok-filter/295089)

<div class="topic-metadata">

**Author:** [@tfinan](https://discuss.elastic.co/u/tfinan)\
**Replies:** 4\
**Last updated:** [January 24, 2022, 7:09pm UTC](https://discuss.elastic.co/t/iterating-over-the-same-grok-filter/295089 "2022-01-24T19:09:23Z")

</div>

I am a new user here, and don't know if this is a trivial question or not (it certainly is not for me). What I want to do is create a filter that creates fields with names based on the data itself. I think I can do this…

---

## [How to improve below Logstash grok filters?](https://discuss.elastic.co/t/how-to-improve-below-logstash-grok-filters/295212)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 3\
**Last updated:** [January 24, 2022, 5:55pm UTC](https://discuss.elastic.co/t/how-to-improve-below-logstash-grok-filters/295212 "2022-01-24T17:55:59Z")

</div>

Hi there. I have a problem with Logstash consuming most of the CPU resources all the time and events not being parsed in real time. Through Stack Monitoring in Kibana, I found that for one set of filters for a certain so…

---

## [Ruby script for deleting some elements recursively \[Q&A\]](https://discuss.elastic.co/t/ruby-script-for-deleting-some-elements-recursively-q-a/295253)

<div class="topic-metadata">

**Author:** [@SudoNova](https://discuss.elastic.co/u/SudoNova)\
**Replies:** 0\
**Last updated:** [January 24, 2022, 4:31pm UTC](https://discuss.elastic.co/t/ruby-script-for-deleting-some-elements-recursively-q-a/295253 "2022-01-24T16:31:24Z")

</div>

Hi Just because I had troubles to make it work,I decided to share it maybe some other folks can use it some time. Requirement: Delete all elements in a parsed json log where they are empty Note: Haproxy sends empty fi…

---

## [Mongodb jdbc logstash no data output in my console](https://discuss.elastic.co/t/mongodb-jdbc-logstash-no-data-output-in-my-console/295245)

<div class="topic-metadata">

**Author:** [@Kermit\_Liu](https://discuss.elastic.co/u/Kermit_Liu)\
**Replies:** 0\
**Last updated:** [January 24, 2022, 3:23pm UTC](https://discuss.elastic.co/t/mongodb-jdbc-logstash-no-data-output-in-my-console/295245 "2022-01-24T15:23:37Z")

</div>

input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/pipeline/driver/mongojdbc4.0.jar" jdbc\_driver\_class =\> "com.dbschema.MongoJdbcDriver" jdbc\_connection\_string =\> "jdbc:mongodb://172.17.0.1…

---

## [Install filter-plugin failed](https://discuss.elastic.co/t/install-filter-plugin-failed/295237)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 0\
**Last updated:** [January 24, 2022, 2:04pm UTC](https://discuss.elastic.co/t/install-filter-plugin-failed/295237 "2022-01-24T14:04:16Z")

</div>

Hello, Today I upgraded logstash to the latest version and needs to install logstash-filter-elapsed plugin. I'm receiving below error: ./logstash-plugin install logstash-filter-elapsed Using bundled JDK: /usr/share/lo…

---

## [LogStash Special Character Split Error](https://discuss.elastic.co/t/logstash-special-character-split-error/295137)

<div class="topic-metadata">

**Author:** [@eagles40cnuh](https://discuss.elastic.co/u/eagles40cnuh)\
**Replies:** 6\
**Last updated:** [January 24, 2022, 9:10am UTC](https://discuss.elastic.co/t/logstash-special-character-split-error/295137 "2022-01-24T09:10:40Z")

</div>

Hi! I have some problem with Logstash Filter Filebeat collect -\> "aaa.log" file and then message field -\> "ID∮NAME∮TELNO" And Logstash.conf is input { beats { port =\> xxxx } filter { mutate { split =\> { "message"…

---

## [Fingerprint option in logstash filter not working properly?](https://discuss.elastic.co/t/fingerprint-option-in-logstash-filter-not-working-properly/295115)

<div class="topic-metadata">

**Author:** [@Anjali\_Kushwaha](https://discuss.elastic.co/u/Anjali_Kushwaha)\
**Replies:** 9\
**Last updated:** [January 24, 2022, 5:39am UTC](https://discuss.elastic.co/t/fingerprint-option-in-logstash-filter-not-working-properly/295115 "2022-01-24T05:39:37Z")

</div>

I have used below code but its only inserting one record to ES . filter { fingerprint { target =\> "document\_id" method =\> "SHA256" key =\> "9ced3827c6a1c9dafac6da9abac41386ba1038ac95b3a865a0951bc2e948c58c" …

---

## [Xpath Functions in Logstash](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 4\
**Last updated:** [January 23, 2022, 6:43pm UTC](https://discuss.elastic.co/t/xpath-functions-in-logstash/295119 "2022-01-23T18:43:31Z")

</div>

I am needing to use xpath functions like string-join() and concat() to extract what I need from my XML file, however whenever I use these functions I get the following warning in my logstash-plain.log: \[2022-01-21T20:4…

---

## [How to different syslog in the same port?](https://discuss.elastic.co/t/how-to-different-syslog-in-the-same-port/295134)

<div class="topic-metadata">

**Author:** [@baalchina](https://discuss.elastic.co/u/baalchina)\
**Replies:** 6\
**Last updated:** [January 23, 2022, 3:22pm UTC](https://discuss.elastic.co/t/how-to-different-syslog-in-the-same-port/295134 "2022-01-23T15:22:24Z")

</div>

Hi all, I have many network devices, I forward their syslog to a logstash server, and then to elastisearch. In logstash, I start many ports, such 514,515,516... and each port to different log types, and when output to e…

---

## [Logstash Aggregate Problem tag in subdirectories Please Help](https://discuss.elastic.co/t/logstash-aggregate-problem-tag-in-subdirectories-please-help/295116)

<div class="topic-metadata">

**Author:** [@melorium](https://discuss.elastic.co/u/melorium)\
**Replies:** 7\
**Last updated:** [January 23, 2022, 3:20pm UTC](https://discuss.elastic.co/t/logstash-aggregate-problem-tag-in-subdirectories-please-help/295116 "2022-01-23T15:20:04Z")

</div>

Hi i trying to use logstash aggregate to tag all log events i main and sub folders. I want all logs in APP1 folders and subfolders to have tag "APP1" and all logs in app2 folders to have APP2 etc. My friend did some ki…

---

## [Filter to remember field accross lines with between start and stop tag](https://discuss.elastic.co/t/filter-to-remember-field-accross-lines-with-between-start-and-stop-tag/295147)

<div class="topic-metadata">

**Author:** [@melorium](https://discuss.elastic.co/u/melorium)\
**Replies:** 3\
**Last updated:** [January 23, 2022, 2:41pm UTC](https://discuss.elastic.co/t/filter-to-remember-field-accross-lines-with-between-start-and-stop-tag/295147 "2022-01-23T14:41:07Z")

</div>

Hi. I have a log with a s tart and stop tag. 2021-12-30 13:15:08.614 +0100 \[AWT-EventQueue-0\] 51818 INFO com.nuix.data.keystore.b - Read 0 passwords from C:\\CASE\\Test Log 1-1\\Stores\\DecryptionKeys\\pgpkeylist.dat This…

---

## [About Comments within Logstash Plugin Config](https://discuss.elastic.co/t/about-comments-within-logstash-plugin-config/295120)

<div class="topic-metadata">

**Author:** [@usb](https://discuss.elastic.co/u/usb)\
**Replies:** 2\
**Last updated:** [January 23, 2022, 4:34am UTC](https://discuss.elastic.co/t/about-comments-within-logstash-plugin-config/295120 "2022-01-23T04:34:53Z")

</div>

Hi everyone. Recently, I am trying to add more comments to my Logstash pipeline config so that it is more understandable. However, I found that it seems comments cannot be added in-between lines of a plugin config. For …

---

## [\_dateparsefailure](https://discuss.elastic.co/t/dateparsefailure/294997)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 9\
**Last updated:** [January 22, 2022, 10:22am UTC](https://discuss.elastic.co/t/dateparsefailure/294997 "2022-01-22T10:22:20Z")

</div>

So I don't know why I got the so kind error : \_dateparsefailure below You can find one of data input |date|time|millisecond| |18.11.2021|09:29:15|257| code: ruby { code =\> " event\_millisecond = ('000' + eve…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=164)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=166)
