# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=17

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 18

---

## [Failed to parse field \[data\] of type \[text\]](https://discuss.elastic.co/t/failed-to-parse-field-data-of-type-text/369325)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 2\
**Last updated:** [October 28, 2024, 4:19pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-data-of-type-text/369325 "2024-10-28T16:19:00Z")

</div>

Hi i have some issue, i find this error in logstash-plain.log how to solve it? "error"=\>{"type"=\>"document\_parsing\_exception", "reason"=\>"\[1:2532\] failed to parse field \[data\] of type \[text\] in document with id 'f-6ZvJI…

---

## [Syslog\\UDP\\TCP as inputs and files as output](https://discuss.elastic.co/t/syslog-udp-tcp-as-inputs-and-files-as-output/369422)

<div class="topic-metadata">

**Author:** [@Po-temkin](https://discuss.elastic.co/u/Po-temkin)\
**Replies:** 4\
**Last updated:** [October 28, 2024, 7:47am UTC](https://discuss.elastic.co/t/syslog-udp-tcp-as-inputs-and-files-as-output/369422 "2024-10-28T07:47:24Z")

</div>

Hello to everyone! First of all, I'm an infant in using logstash and just briefly read some parts of logstash docs. So do not blame me for stupid questions, please! =) Now, let's look into my question. Preface: My f…

---

## [Failed to parse field \[host\] of type \[text\]](https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text/369320)

<div class="topic-metadata">

**Author:** [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Replies:** 4\
**Last updated:** [October 28, 2024, 5:35am UTC](https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text/369320 "2024-10-28T05:35:23Z")

</div>

Hello team, I'm using the Elasticsearch, Logstash, and Kibana stack version 8.15.3, which is configured using Docker. By using Logstash, I tried to insert a CSV file data into Elasticsearch. However, I encounter an err…

---

## [Are \`Auditbeat\` and \`Logstash - OSS only\` equivalent?](https://discuss.elastic.co/t/are-auditbeat-and-logstash-oss-only-equivalent/369488)

<div class="topic-metadata">

**Author:** [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Replies:** 1\
**Last updated:** [October 27, 2024, 5:54am UTC](https://discuss.elastic.co/t/are-auditbeat-and-logstash-oss-only-equivalent/369488 "2024-10-27T05:54:18Z")

</div>

At Download Logstash Free | Get Started Now | Elastic , I noticed there was a hyperlink that took me to Download Logstash Free | Get Started Now | Elastic . I tried clicking on Docker at Download Logstash Free | Get St…

---

## [How to sync only updated data from mysql table with logstash is it possible?](https://discuss.elastic.co/t/how-to-sync-only-updated-data-from-mysql-table-with-logstash-is-it-possible/369397)

<div class="topic-metadata">

**Author:** [@Hardik\_Patel1](https://discuss.elastic.co/u/Hardik_Patel1)\
**Replies:** 1\
**Last updated:** [October 25, 2024, 7:01am UTC](https://discuss.elastic.co/t/how-to-sync-only-updated-data-from-mysql-table-with-logstash-is-it-possible/369397 "2024-10-25T07:01:24Z")

</div>

how to sync only updated data from mysql table with logstash is it possible with logstash configuration

---

## [Logstash config reload not working](https://discuss.elastic.co/t/logstash-config-reload-not-working/369362)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 5\
**Last updated:** [October 24, 2024, 6:09pm UTC](https://discuss.elastic.co/t/logstash-config-reload-not-working/369362 "2024-10-24T18:09:52Z")

</div>

Hi All, We are having issues in our logstash were the config changes are not getting picked up untill the service is restarted. Tried the solutins given in:Reloading the Config File | Logstash Reference \[8.15\] | Elasti…

---

## [XML some similare tags generate row for each](https://discuss.elastic.co/t/xml-some-similare-tags-generate-row-for-each/369339)

<div class="topic-metadata">

**Author:** [@Spiralium](https://discuss.elastic.co/u/Spiralium)\
**Replies:** 4\
**Last updated:** [October 24, 2024, 3:19pm UTC](https://discuss.elastic.co/t/xml-some-similare-tags-generate-row-for-each/369339 "2024-10-24T15:19:04Z")

</div>

Hello, I try to extract datas from a XML like : \<?xml version="1.0" encoding="ISO-8859-1" standalone="yes"?\> \<MASTER\> \<CODE\>ABC\</CODE\> \<ENTITE\>FR\</ENTITE\> \<TYPEDEMANDE\>prevision\</TYPEDEMANDE\> \<critere\> \<numero\>fiel…

---

## [Parse date field](https://discuss.elastic.co/t/parse-date-field/369294)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 3\
**Last updated:** [October 24, 2024, 1:04pm UTC](https://discuss.elastic.co/t/parse-date-field/369294 "2024-10-24T13:04:43Z")

</div>

Hi guys, i'm injecting data from an oracle database with jdbc plugin. But i'm having trouble parsing date from a field. Below is a data example, { "data" =\> 2024-10-22T16:07:54Z, "transaction…

---

## [One INPUT and simultaneously stream logs to 2 OUTPUTS](https://discuss.elastic.co/t/one-input-and-simultaneously-stream-logs-to-2-outputs/369304)

<div class="topic-metadata">

**Author:** [@Richard\_LaRoche](https://discuss.elastic.co/u/Richard_LaRoche)\
**Replies:** 1\
**Last updated:** [October 23, 2024, 10:56pm UTC](https://discuss.elastic.co/t/one-input-and-simultaneously-stream-logs-to-2-outputs/369304 "2024-10-23T22:56:01Z")

</div>

Collecting meraki netflow logs on my logstash collectors but would like in the same pipleline to send the logs to 2 different (OUTPUT) destinations. Does logstash OUTPUT support this ? New to the logstash product.

---

## [Logstash: XML recursive split](https://discuss.elastic.co/t/logstash-xml-recursive-split/368554)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 2\
**Last updated:** [October 23, 2024, 3:41pm UTC](https://discuss.elastic.co/t/logstash-xml-recursive-split/368554 "2024-10-23T15:41:00Z")

</div>

Hello, everyone! I am attempting to parse a large XML file that looks like this: \<?xml version="1.0" encoding="UTF-8"?\> \<organisaties\> \<organisatie systeemId="01"\> \<naam\>ORG\_01\</naam\> \</organisatie\> \<organisatie s…

---

## [Logstash-input-file version 4.4.6 sporadically fails to scan files in read mode](https://discuss.elastic.co/t/logstash-input-file-version-4-4-6-sporadically-fails-to-scan-files-in-read-mode/369248)

<div class="topic-metadata">

**Author:** [@Andreas\_Rulle1](https://discuss.elastic.co/u/Andreas_Rulle1)\
**Replies:** 0\
**Last updated:** [October 22, 2024, 11:22pm UTC](https://discuss.elastic.co/t/logstash-input-file-version-4-4-6-sporadically-fails-to-scan-files-in-read-mode/369248 "2024-10-22T23:22:56Z")

</div>

We use the following configuation input { file { sincedb\_path =\> "/usr/share/logstash/sincedb\_details" path =\> "/home/sportal/logstash/details\_3.0/\*.json" start\_po…

---

## [Search pattern in DQL](https://discuss.elastic.co/t/search-pattern-in-dql/368771)

<div class="topic-metadata">

**Author:** [@mika1](https://discuss.elastic.co/u/mika1)\
**Replies:** 4\
**Last updated:** [October 22, 2024, 5:02pm UTC](https://discuss.elastic.co/t/search-pattern-in-dql/368771 "2024-10-22T17:02:22Z")

</div>

i need to find the below pattern from my application logs, when i put the below string in my DQL as provide below . i'm not getting any results. What should be the correct search query. Sting to be searched : "Error -…

---

## [The use of if ... in \[array\]](https://discuss.elastic.co/t/the-use-of-if-in-array/369112)

<div class="topic-metadata">

**Author:** [@NgDinhNamEtiis](https://discuss.elastic.co/u/NgDinhNamEtiis)\
**Replies:** 2\
**Last updated:** [October 22, 2024, 6:13am UTC](https://discuss.elastic.co/t/the-use-of-if-in-array/369112 "2024-10-22T06:13:48Z")

</div>

Hi When using if ... in \[array\] for Logstash with version 8.15.0: input { generator { count =\> 1 } } filter { if "a" in \["a","b"\] { mutate { add\_field =\> { "test\_field" =\> "1" } } } } output { st…

---

## [Why can't this match successfully?](https://discuss.elastic.co/t/why-cant-this-match-successfully/369146)

<div class="topic-metadata">

**Author:** [@WeirdorPersist](https://discuss.elastic.co/u/WeirdorPersist)\
**Replies:** 4\
**Last updated:** [October 22, 2024, 2:34am UTC](https://discuss.elastic.co/t/why-cant-this-match-successfully/369146 "2024-10-22T02:34:06Z")

</div>

I am trying to mark missing fields in the logs, but some log entries with missing fields cannot match successfully, which prevents them from being marked. What should I do? Is there something wrong with my configurati…

---

## [Error while upgrading Logstash to version 8.15.3](https://discuss.elastic.co/t/error-while-upgrading-logstash-to-version-8-15-3/369027)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 4\
**Last updated:** [October 21, 2024, 6:39pm UTC](https://discuss.elastic.co/t/error-while-upgrading-logstash-to-version-8-15-3/369027 "2024-10-21T18:39:42Z")

</div>

Hello to all After noticing that there is a new version of ELK 8.15.13 I set out to perform the upgrade initially on the elasticsearch cluster servers and all normal, kibana all normal. I started to have problems when …

---

## [Assistance with Logstash Sizing and Kafka Integration](https://discuss.elastic.co/t/assistance-with-logstash-sizing-and-kafka-integration/369076)

<div class="topic-metadata">

**Author:** [@Will3703](https://discuss.elastic.co/u/Will3703)\
**Replies:** 4\
**Last updated:** [October 19, 2024, 3:14pm UTC](https://discuss.elastic.co/t/assistance-with-logstash-sizing-and-kafka-integration/369076 "2024-10-19T15:14:16Z")

</div>

I am new to Elastic and would like to understand the sizing requirements for Logstash based on the following: • Data to process: 7TB over 10 hours • Average event size: 70% of events are 1KB, and 30% are 500 bytes How…

---

## [Separate Documents from log (JSON)](https://discuss.elastic.co/t/separate-documents-from-log-json/369116)

<div class="topic-metadata">

**Author:** [@Naveenchand\_R\_B](https://discuss.elastic.co/u/Naveenchand_R_B)\
**Replies:** 0\
**Last updated:** [October 21, 2024, 5:55am UTC](https://discuss.elastic.co/t/separate-documents-from-log-json/369116 "2024-10-21T05:55:10Z")

</div>

Hi, I have a json which has array of json objects. I want to create seperate documents for each item inside the array Example JSON: { "MainID": "12345", "MainDocs": \[ { "PositionId": "p1", "PositionName"…

---

## [Logstash 0f 8.15.2 is not connecting with elasticsearch of 8.15.2](https://discuss.elastic.co/t/logstash-0f-8-15-2-is-not-connecting-with-elasticsearch-of-8-15-2/369034)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 3\
**Last updated:** [October 21, 2024, 4:19am UTC](https://discuss.elastic.co/t/logstash-0f-8-15-2-is-not-connecting-with-elasticsearch-of-8-15-2/369034 "2024-10-21T04:19:01Z")

</div>

Hi, I am facing an issue with lntegration of logstash 8.15.2 with elasticsearch8.15.2. Logstash is failing to connect to Elasticsearch. The logs show the following errors: EDITED By MOD. Please Format your Code in the…

---

## [Sending Wazuh alerts to Elasticsearch using logstash integration with Wazuh Indexer](https://discuss.elastic.co/t/sending-wazuh-alerts-to-elasticsearch-using-logstash-integration-with-wazuh-indexer/369096)

<div class="topic-metadata">

**Author:** [@Muhammadh\_Zakir\_Huss](https://discuss.elastic.co/u/Muhammadh_Zakir_Huss)\
**Replies:** 1\
**Last updated:** [October 20, 2024, 11:56am UTC](https://discuss.elastic.co/t/sending-wazuh-alerts-to-elasticsearch-using-logstash-integration-with-wazuh-indexer/369096 "2024-10-20T11:56:01Z")

</div>

root@wazuhsiem:~# sudo -E /usr/share/logstash/bin/logstash -f /etc/logstash/conf .d/wazuh-elasticsearch.conf --p…

---

## [Ingestion Rate decreases over time](https://discuss.elastic.co/t/ingestion-rate-decreases-over-time/369102)

<div class="topic-metadata">

**Author:** [@NikoCosmico01](https://discuss.elastic.co/u/NikoCosmico01)\
**Replies:** 0\
**Last updated:** [October 20, 2024, 10:19am UTC](https://discuss.elastic.co/t/ingestion-rate-decreases-over-time/369102 "2024-10-20T10:19:53Z")

</div>

Hi everyone, I've created a Logstash ingestion pipeline that takes the logs from OpenSearch (about 30M logs per day) and forwards them into elasticSearch. My goal is to be able to load into ELK the last day of logs (as o…

---

## [Logstash Action](https://discuss.elastic.co/t/logstash-action/369054)

<div class="topic-metadata">

**Author:** [@Tam2](https://discuss.elastic.co/u/Tam2)\
**Replies:** 2\
**Last updated:** [October 18, 2024, 1:43pm UTC](https://discuss.elastic.co/t/logstash-action/369054 "2024-10-18T13:43:36Z")

</div>

I'm currently upgrading logstash + elasticsearch from 7.x to 8.x but am getting this error within the logstash pipeline \[WARN \]\[logstash.outputs.elasticsearch\]\[main\]\[790066835755a2e9e8ffb361aa7273a3b82493ee370893269ac96…

---

## [Help me I am new to ELK. I want to ingest mysql logs(error logs, slow query logs and also a general logs)](https://discuss.elastic.co/t/help-me-i-am-new-to-elk-i-want-to-ingest-mysql-logs-error-logs-slow-query-logs-and-also-a-general-logs/368883)

<div class="topic-metadata">

**Author:** [@FJT](https://discuss.elastic.co/u/FJT)\
**Replies:** 6\
**Last updated:** [October 17, 2024, 3:30am UTC](https://discuss.elastic.co/t/help-me-i-am-new-to-elk-i-want-to-ingest-mysql-logs-error-logs-slow-query-logs-and-also-a-general-logs/368883 "2024-10-17T03:30:43Z")

</div>

I want to ingest mysql logs(error logs, slow query logs and also a general logs) Can you like help me what is the most appropriate approach?

---

## [Logstash fails after upgrading to version - 8.15.1](https://discuss.elastic.co/t/logstash-fails-after-upgrading-to-version-8-15-1/366333)

<div class="topic-metadata">

**Author:** [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Replies:** 18\
**Last updated:** [October 18, 2024, 4:35am UTC](https://discuss.elastic.co/t/logstash-fails-after-upgrading-to-version-8-15-1/366333 "2024-10-18T04:35:07Z")

</div>

Hi Team, Today i upgraded my Elasticsearch, Logstash, and Kibana stack from version 8.6.2 to 8.15.1. My setup is based on Docker Compose. After the upgrade, the Logstash container fails to start and throws the following…

---

## [Logstash Pipeline crash](https://discuss.elastic.co/t/logstash-pipeline-crash/369001)

<div class="topic-metadata">

**Author:** [@hunter32](https://discuss.elastic.co/u/hunter32)\
**Replies:** 5\
**Last updated:** [October 17, 2024, 10:20pm UTC](https://discuss.elastic.co/t/logstash-pipeline-crash/369001 "2024-10-17T22:20:23Z")

</div>

We are getting some infrequent crashes with logstash. They seem to always be NoMethodFound errors on test\_for\_inclusion. When it failed no of my error logging is happen so I can not find the location in my pipeline that …

---

## [Logstash Fortinet Grok Pattern](https://discuss.elastic.co/t/logstash-fortinet-grok-pattern/369019)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 5\
**Last updated:** [October 17, 2024, 8:05pm UTC](https://discuss.elastic.co/t/logstash-fortinet-grok-pattern/369019 "2024-10-17T20:05:55Z")

</div>

HI All: I am working on another GROK pattern and hitting some snags. Here are the details: Sample Log Line: logver=0702071577 idseq=237867271677022888 itime=1723855010 devid="FGT60E4Q17040542" devname="central-il-cu"…

---

## [Logstash Java Errors](https://discuss.elastic.co/t/logstash-java-errors/368038)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 12\
**Last updated:** [October 17, 2024, 5:20pm UTC](https://discuss.elastic.co/t/logstash-java-errors/368038 "2024-10-17T17:20:46Z")

</div>

HI All: Is anyone familiar with the below logstash error? I am trying to run a basic Combined apache log GROK Filter. match =\> { "message" =\> "%{COMBINEDAPACHELOG}" } \[2024-09-30T20:13:10,962\]\[WARN \]\[filewatch.readmo…

---

## [Problem in the operation of the snmp module in logstash](https://discuss.elastic.co/t/problem-in-the-operation-of-the-snmp-module-in-logstash/367222)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 2\
**Last updated:** [October 17, 2024, 8:27am UTC](https://discuss.elastic.co/t/problem-in-the-operation-of-the-snmp-module-in-logstash/367222 "2024-10-17T08:27:37Z")

</div>

After updating logstash to the latest version 8.15.1. the problems with the snmp module have been fixed. logs: Sep 27 08:39:17 lst01 logstash\[898\]: Error: Task java.util.concurrent.CompletableFuture$AsyncSupply@615d2…

---

## [Any information on creating a logstash plugin offline](https://discuss.elastic.co/t/any-information-on-creating-a-logstash-plugin-offline/368979)

<div class="topic-metadata">

**Author:** [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 8:07am UTC](https://discuss.elastic.co/t/any-information-on-creating-a-logstash-plugin-offline/368979 "2024-10-17T08:07:20Z")

</div>

Hello, I want to create a logstash plugin in my lab that has no internet or actually has anyone created an offline logstash plugin (input,filter and output ) for grpc Thanks

---

## [Stability Issues at 10k EPS in Elastic-Agent + Logstash – Elasticsearch Bottleneck?](https://discuss.elastic.co/t/stability-issues-at-10k-eps-in-elastic-agent-logstash-elasticsearch-bottleneck/368960)

<div class="topic-metadata">

**Author:** [@wangsubo](https://discuss.elastic.co/u/wangsubo)\
**Replies:** 0\
**Last updated:** [October 17, 2024, 3:31am UTC](https://discuss.elastic.co/t/stability-issues-at-10k-eps-in-elastic-agent-logstash-elasticsearch-bottleneck/368960 "2024-10-17T03:31:49Z")

</div>

I am currently using Elastic-Agent for log collection and Logstash for log forwarding. I am conducting a stress test to evaluate the hardware requirements and costs of the collector setup (Elastic-Agent + Logstash). I…

---

## [Using Logstash aggregate filter with only start and continuation events](https://discuss.elastic.co/t/using-logstash-aggregate-filter-with-only-start-and-continuation-events/368933)

<div class="topic-metadata">

**Author:** [@jeffkirk1](https://discuss.elastic.co/u/jeffkirk1)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 6:48pm UTC](https://discuss.elastic.co/t/using-logstash-aggregate-filter-with-only-start-and-continuation-events/368933 "2024-10-16T18:48:00Z")

</div>

Hey there, I am attempting to merge the "message" field for syslog logs using the aggregate pipeline, and have been beating my head against a wall trying to get this scenario to work. I'm on the verge of giving up and i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=16)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=18)
