# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=170

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 171

---

## [Delete JndiLookup.class](https://discuss.elastic.co/t/delete-jndilookup-class/291507)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 16\
**Last updated:** [January 4, 2022, 2:49pm UTC](https://discuss.elastic.co/t/delete-jndilookup-class/291507 "2022-01-04T14:49:58Z")

</div>

Dear Team, I am unable to find the file zip -q -d \<LOGSTASH\_HOME\>/logstash-core/lib/jars/log4j-core-2.\* org/apache/logging/log4j/core/lookup/JndiLookup.class Can someone please help me or guide me. Regards

---

## [Hexadecimal to Decimal](https://discuss.elastic.co/t/hexadecimal-to-decimal/293361)

<div class="topic-metadata">

**Author:** [@dayajamal](https://discuss.elastic.co/u/dayajamal)\
**Replies:** 2\
**Last updated:** [January 4, 2022, 8:16am UTC](https://discuss.elastic.co/t/hexadecimal-to-decimal/293361 "2022-01-04T08:16:42Z")

</div>

Hi, I am trying to convert a field in my log from hexadecimal to decimal. I tried with the following log: 2021-07-26T16:49:02.189807+0200 | DEBUG | 910EAB70 | flyscan/core/server.1 | ScanActorTask::handle\_message Usin…

---

## [In Logstash Log I am receiving Elasticsearch unreachable error](https://discuss.elastic.co/t/in-logstash-log-i-am-receiving-elasticsearch-unreachable-error/293199)

<div class="topic-metadata">

**Author:** [@d6036de2b54af16665f4](https://discuss.elastic.co/u/d6036de2b54af16665f4)\
**Replies:** 11\
**Last updated:** [January 4, 2022, 7:42am UTC](https://discuss.elastic.co/t/in-logstash-log-i-am-receiving-elasticsearch-unreachable-error/293199 "2022-01-04T07:42:15Z")

</div>

I am not able to view data in kibana and grafana as well . And also i am getting {:message=\>"Elasticsearch Unreachable: error in logstash log

---

## [\_dateparsefailure in ISO8601 date strings](https://discuss.elastic.co/t/dateparsefailure-in-iso8601-date-strings/292799)

<div class="topic-metadata">

**Author:** [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Replies:** 7\
**Last updated:** [January 3, 2022, 11:40am UTC](https://discuss.elastic.co/t/dateparsefailure-in-iso8601-date-strings/292799 "2022-01-03T11:40:01Z")

</div>

I want to pull logs from an mssql server and parse their date strings. unfortunately I can not figure out why it can not parse the date. My filter looks like this: filter { date { match =\> \[ "evtime", "ISO8601" \] tim…

---

## [How to send process Data from Logstash to RabbitMQ?](https://discuss.elastic.co/t/how-to-send-process-data-from-logstash-to-rabbitmq/293336)

<div class="topic-metadata">

**Author:** [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Replies:** 2\
**Last updated:** [January 3, 2022, 10:31am UTC](https://discuss.elastic.co/t/how-to-send-process-data-from-logstash-to-rabbitmq/293336 "2022-01-03T10:31:13Z")

</div>

How to send json format data from logstash to Rabbitmq. I have tried but getting error. Currently I am using local Rabbitmq My config output file, if "\_grokparsefailure" in \[tags\]{ rabbitmq{ host =\> …

---

## [Logstash wont work after upgrading](https://discuss.elastic.co/t/logstash-wont-work-after-upgrading/293273)

<div class="topic-metadata">

**Author:** [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Replies:** 1\
**Last updated:** [January 3, 2022, 7:48am UTC](https://discuss.elastic.co/t/logstash-wont-work-after-upgrading/293273 "2022-01-03T07:48:32Z")

</div>

Hi dears I have 3 instances of Logstash in my cluster. (version 7.6.2) I upgraded to 7.16.2 one by one But one of the Logstash instance wont work after upgrading: \[FATAL\] 2022-01-01 10:36:04.983 \[main\] Logstash - Log…

---

## [Cannot send logs from Logstash to Elastic Search](https://discuss.elastic.co/t/cannot-send-logs-from-logstash-to-elastic-search/291188)

<div class="topic-metadata">

**Author:** [@nevincansel](https://discuss.elastic.co/u/nevincansel)\
**Replies:** 12\
**Last updated:** [January 3, 2022, 6:28am UTC](https://discuss.elastic.co/t/cannot-send-logs-from-logstash-to-elastic-search/291188 "2022-01-03T06:28:07Z")

</div>

Hello, I deployed ELK Stack to k8s by using helm. In the cluster, Elasticsearch, Kibana and Filebeat are running. I also configured Logstash to send Filebeat logs and logs from external resource. My external resource i…

---

## [Sending data from Logstash to Elasticsearch running on two different server](https://discuss.elastic.co/t/sending-data-from-logstash-to-elasticsearch-running-on-two-different-server/293311)

<div class="topic-metadata">

**Author:** [@mangesh\_shinde](https://discuss.elastic.co/u/mangesh_shinde)\
**Replies:** 1\
**Last updated:** [January 3, 2022, 5:59am UTC](https://discuss.elastic.co/t/sending-data-from-logstash-to-elasticsearch-running-on-two-different-server/293311 "2022-01-03T05:59:40Z")

</div>

I have log files on one server and elastic on different. I want to use Logstash only not any beat for that. so mentioning elastic ip:port output in logstash. Is it possible to have logstash and Elasticsearch on differ…

---

## [Want to check connection duration](https://discuss.elastic.co/t/want-to-check-connection-duration/293235)

<div class="topic-metadata">

**Author:** [@root\_linux](https://discuss.elastic.co/u/root_linux)\
**Replies:** 6\
**Last updated:** [January 2, 2022, 5:17pm UTC](https://discuss.elastic.co/t/want-to-check-connection-duration/293235 "2022-01-02T17:17:11Z")

</div>

hi all, I have configured Elasticsearch, kibana and logstash on a server. Sending logs from different filebeat clients to logstash. I have logs in which connection esatablish and connection reset time present. My requir…

---

## [Could not find gem mimemagic 0.3.3](https://discuss.elastic.co/t/could-not-find-gem-mimemagic-0-3-3/293288)

<div class="topic-metadata">

**Author:** [@shrikantgulia](https://discuss.elastic.co/u/shrikantgulia)\
**Replies:** 1\
**Last updated:** [January 2, 2022, 3:37pm UTC](https://discuss.elastic.co/t/could-not-find-gem-mimemagic-0-3-3/293288 "2022-01-02T15:37:05Z")

</div>

Dears, happy new year i upgraded logstash from 7.3 to 7.14.2 and i took the backup of the plugins when i am installing the backuo of the plugin i faced the error "Using bundled JDK: /usr/share/logstash/jdk OpenJDK 64…

---

## [Stuck at “Successfully started Logstash API endpoint {:port=\>9600}”](https://discuss.elastic.co/t/stuck-at-successfully-started-logstash-api-endpoint-port-9600/293279)

<div class="topic-metadata">

**Author:** [@adkyushu](https://discuss.elastic.co/u/adkyushu)\
**Replies:** 3\
**Last updated:** [January 1, 2022, 7:16pm UTC](https://discuss.elastic.co/t/stuck-at-successfully-started-logstash-api-endpoint-port-9600/293279 "2022-01-01T19:16:37Z")

</div>

Stuck at “Successfully started Logstash API endpoint {:port=\>9600}” When I turn on --debug, it keeps looping the following information:

---

## [ElasticSearch Input Plugin has no log output](https://discuss.elastic.co/t/elasticsearch-input-plugin-has-no-log-output/292906)

<div class="topic-metadata">

**Author:** [@l0ady](https://discuss.elastic.co/u/l0ady)\
**Replies:** 2\
**Last updated:** [December 31, 2021, 2:26pm UTC](https://discuss.elastic.co/t/elasticsearch-input-plugin-has-no-log-output/292906 "2021-12-31T14:26:40Z")

</div>

I want to extract one ES from another es periodically through logstash, but only the startup log, no other log information。。。THX config: input { #beats { # port =\> 5044 #} elasticsearch { hosts =\> \["10.1.2…

---

## [\[elastic output\] Differences in SSL between 7.9.1 and 7.16.2](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035)

<div class="topic-metadata">

**Author:** [@rockandska](https://discuss.elastic.co/u/rockandska)\
**Replies:** 4\
**Last updated:** [December 30, 2021, 5:07pm UTC](https://discuss.elastic.co/t/elastic-output-differences-in-ssl-between-7-9-1-and-7-16-2/293035 "2021-12-30T17:07:30Z")

</div>

Hi, Previously, on 7.9.1, I had a configuration like the one bellow for my output : output { elasticsearch { hosts =\> "https://myhost:9200" index =\> "myindex" user =\> "myuser" password =\> "mypassword"…

---

## [Logstash not start after upgrade to new version](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849)

<div class="topic-metadata">

**Author:** [@Alexander\_Popov](https://discuss.elastic.co/u/Alexander_Popov)\
**Replies:** 9\
**Last updated:** [December 30, 2021, 4:48pm UTC](https://discuss.elastic.co/t/logstash-not-start-after-upgrade-to-new-version/291849 "2021-12-30T16:48:35Z")

</div>

was 7.10.2, upgrade to 7.16.1 but it not start: 21-12-14T17:31:17,721\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<LogStash::ConfigurationError: Could not connect to a co…

---

## [Httop Poller Input Plugin - Need help](https://discuss.elastic.co/t/httop-poller-input-plugin-need-help/293107)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 2\
**Last updated:** [December 30, 2021, 10:50am UTC](https://discuss.elastic.co/t/httop-poller-input-plugin-need-help/293107 "2021-12-30T10:50:11Z")

</div>

Hie Everyone, HTTP poller plugin when used fetches only 1000 records from the URL triggered even though the actual response has more than 1000 events. ​ here is the config file : input { http\_poller { urls =\> { …

---

## [Error in parsing Pretty Json Data](https://discuss.elastic.co/t/error-in-parsing-pretty-json-data/293103)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 4\
**Last updated:** [December 30, 2021, 6:51am UTC](https://discuss.elastic.co/t/error-in-parsing-pretty-json-data/293103 "2021-12-30T06:51:43Z")

</div>

Hi team I have file in json format. \[ { "year": 2013, "title": "Rush", "info": { "directors": \["Ron Howard"\], "release\_date": "2013-09-02T00:00:00Z", "rat…

---

## [Assign completion suggest weight with field value in logstash](https://discuss.elastic.co/t/assign-completion-suggest-weight-with-field-value-in-logstash/293155)

<div class="topic-metadata">

**Author:** [@caseydm](https://discuss.elastic.co/u/caseydm)\
**Replies:** 3\
**Last updated:** [December 29, 2021, 11:19pm UTC](https://discuss.elastic.co/t/assign-completion-suggest-weight-with-field-value-in-logstash/293155 "2021-12-29T23:19:09Z")

</div>

I am trying to add a weight to a completion suggest field using logstash, but I'm getting errors. Has anybody done this? The completion suggester field is set up as follows: display\_name": { "type": "text", "fi…

---

## [Under what circumstances can log4j be used to exploit Logstash?](https://discuss.elastic.co/t/under-what-circumstances-can-log4j-be-used-to-exploit-logstash/291886)

<div class="topic-metadata">

**Author:** [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)\
**Replies:** 8\
**Last updated:** [December 29, 2021, 9:54pm UTC](https://discuss.elastic.co/t/under-what-circumstances-can-log4j-be-used-to-exploit-logstash/291886 "2021-12-29T21:54:13Z")

</div>

Hi, Under what circumstances can the log4j bug be exploited in Logstash? Is it as simple as sending the exploit string an open port Logstash is listening on regardless of whatever input is configured in your Logstash co…

---

## [Json parsing problem](https://discuss.elastic.co/t/json-parsing-problem/293110)

<div class="topic-metadata">

**Author:** [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Replies:** 3\
**Last updated:** [December 29, 2021, 6:10pm UTC](https://discuss.elastic.co/t/json-parsing-problem/293110 "2021-12-29T18:10:01Z")

</div>

Hi Guys, I have a problem with ingesting json data. I am guessing that the problem is with the structure. I have tried different configurations (with and without the json codec). Any idea? The json data: \[{"name": …

---

## [Pb mix of indexes, using two or three conf file](https://discuss.elastic.co/t/pb-mix-of-indexes-using-two-or-three-conf-file/292999)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 2\
**Last updated:** [December 29, 2021, 2:08pm UTC](https://discuss.elastic.co/t/pb-mix-of-indexes-using-two-or-three-conf-file/292999 "2021-12-29T14:08:30Z")

</div>

Hello, I have set up two logstach pipelines via two conf files. One is going to look for an rss feed and the other one for tweets. In both, I have a different index type variable to differentiate obviously the data colle…

---

## [Dynamic value substitution for date is NULL](https://discuss.elastic.co/t/dynamic-value-substitution-for-date-is-null/293144)

<div class="topic-metadata">

**Author:** [@4art4](https://discuss.elastic.co/u/4art4)\
**Replies:** 1\
**Last updated:** [December 29, 2021, 5:07pm UTC](https://discuss.elastic.co/t/dynamic-value-substitution-for-date-is-null/293144 "2021-12-29T17:07:36Z")

</div>

To quote the docs: Writing to different indices: best practices You cannot use dynamic variable substitution when ilm\_enabled is true and when using ilm\_rollover\_alias. So what I think I want to do is make each new bat…

---

## [Elastic Search using Message Content Parse with Logstash](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111)

<div class="topic-metadata">

**Author:** [@kiran\_tirumalasetti](https://discuss.elastic.co/u/kiran_tirumalasetti)\
**Replies:** 5\
**Last updated:** [December 29, 2021, 4:07pm UTC](https://discuss.elastic.co/t/elastic-search-using-message-content-parse-with-logstash/293111 "2021-12-29T16:07:25Z")

</div>

Hello, I am trying to push some data into Elasticsearch from an application via logstash and is there anyway to search/filter the json message in Elasticsearch for a particular field in the json message. I am using bel…

---

## [Logstash pipeline error](https://discuss.elastic.co/t/logstash-pipeline-error/293118)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [December 29, 2021, 1:18pm UTC](https://discuss.elastic.co/t/logstash-pipeline-error/293118 "2021-12-29T13:18:54Z")

</div>

Hello team, I am getting following issuw on logstash side. can anyone help me. Error: \[2021-12-29T16:50:48,240\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pip…

---

## [After installing a filter plugin with BouncyCastleFipsProvider, Logstash fails to start](https://discuss.elastic.co/t/after-installing-a-filter-plugin-with-bouncycastlefipsprovider-logstash-fails-to-start/293115)

<div class="topic-metadata">

**Author:** [@yon\_y](https://discuss.elastic.co/u/yon_y)\
**Replies:** 0\
**Last updated:** [December 29, 2021, 12:41pm UTC](https://discuss.elastic.co/t/after-installing-a-filter-plugin-with-bouncycastlefipsprovider-logstash-fails-to-start/293115 "2021-12-29T12:41:46Z")

</div>

I wrote a Java filter plugin, compiled it into a gem (after successfully unit-tests), installed it successfully to Logstash, but then Logstash fails to start. The problem is caused by a single line (when the line is remo…

---

## [Change long field format](https://discuss.elastic.co/t/change-long-field-format/293049)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 3\
**Last updated:** [December 29, 2021, 12:24pm UTC](https://discuss.elastic.co/t/change-long-field-format/293049 "2021-12-29T12:24:18Z")

</div>

I have field called # user\_id\_s: 14,960,923,573 long as above name, value and type I want it should look like 14960923573 I try to change its type to string by mutate convert but not worked. I tried creating new s…

---

## [How to process ResponseTimestamp-ClientIP-ReceivedTimestamp to show ReceivedTimestamp (23/Dec/2021:00:02:53 +0000) as @timestamp](https://discuss.elastic.co/t/how-to-process-responsetimestamp-clientip-receivedtimestamp-to-show-receivedtimestamp-23-dec-202102-53-0000-as-timestamp/293056)

<div class="topic-metadata">

**Author:** [@Melvin](https://discuss.elastic.co/u/Melvin)\
**Replies:** 4\
**Last updated:** [December 29, 2021, 10:36am UTC](https://discuss.elastic.co/t/how-to-process-responsetimestamp-clientip-receivedtimestamp-to-show-receivedtimestamp-23-dec-202102-53-0000-as-timestamp/293056 "2021-12-29T10:36:06Z")

</div>

Input example line in log: 2021-12-23T00:02:54.126Z 10.173.7.76 - - \[23/Dec/2021:00:02:53 +0000\] "POST /uri1/uri2?queryp=00-0A-12-34-56-78 HTTP/1.1" 403 2001 "-" "useragent" 0 \[500456\] Grok filter expression: filter {…

---

## [After deleting an index, a new one is created with invalid naming scheme](https://discuss.elastic.co/t/after-deleting-an-index-a-new-one-is-created-with-invalid-naming-scheme/292747)

<div class="topic-metadata">

**Author:** [@mdebord](https://discuss.elastic.co/u/mdebord)\
**Replies:** 6\
**Last updated:** [December 28, 2021, 9:21pm UTC](https://discuss.elastic.co/t/after-deleting-an-index-a-new-one-is-created-with-invalid-naming-scheme/292747 "2021-12-28T21:21:39Z")

</div>

Logstash 7.16.2 Elasticsearch 7.16.2 Summary In a scenario that beat processors are sending to logstash, and logstash has ilm configured, if the working index is deleted, a new one is created (as expected), but the n…

---

## [\[ERROR\] logstash.filters.ruby](https://discuss.elastic.co/t/error-logstash-filters-ruby/291841)

<div class="topic-metadata">

**Author:** [@kyk](https://discuss.elastic.co/u/kyk)\
**Replies:** 4\
**Last updated:** [December 29, 2021, 3:14am UTC](https://discuss.elastic.co/t/error-logstash-filters-ruby/291841 "2021-12-29T03:14:16Z")

</div>

I have the next ruby code ruby { code =\> ' m = event.get("ip\_port").scan(/(\\d+.\\d+.\\d+.\\d+):(\\d+)-\>(\\d+.\\d+.\\d+.\\d+):(\\d+)/) w = ; x = ; y = ; z = m.each { |a| w \<\< a\[0\].to\_fo x \<\< a\[1\].to\_fo y \<\< a\[2\].to\_fo z \<…

---

## [How to send Custom Logs Agent to Logstash?](https://discuss.elastic.co/t/how-to-send-custom-logs-agent-to-logstash/293065)

<div class="topic-metadata">

**Author:** [@dannie-ml](https://discuss.elastic.co/u/dannie-ml)\
**Replies:** 8\
**Last updated:** [December 28, 2021, 7:59pm UTC](https://discuss.elastic.co/t/how-to-send-custom-logs-agent-to-logstash/293065 "2021-12-28T19:59:32Z")

</div>

Hi, i integrate it an elastics agent 'custom logs' and in the logs section this is the stream Now i want to parse some information in logstash, ¿how i can send that data to logstash? Please provide me a detail expla…

---

## [Read \*.json.gz from AWS S3 bucket](https://discuss.elastic.co/t/read-json-gz-from-aws-s3-bucket/292822)

<div class="topic-metadata">

**Author:** [@Vidya\_Sagar](https://discuss.elastic.co/u/Vidya_Sagar)\
**Replies:** 2\
**Last updated:** [December 28, 2021, 7:24pm UTC](https://discuss.elastic.co/t/read-json-gz-from-aws-s3-bucket/292822 "2021-12-28T19:24:45Z")

</div>

Hi All, I am new to ELK Stack and trying to read data from S3 buckets. The json data is in compressed format and the folder structure in the S3 bucket is like YYYY-MM-DD/.json.gz 2021-12-01/A.json.gz 2021-12-02/B.jso…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=169)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=171)
