# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=173

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 174

---

## [How to create configure date filter data nested](https://discuss.elastic.co/t/how-to-create-configure-date-filter-data-nested/292273)

<div class="topic-metadata">

**Author:** [@Rizky\_Hudha](https://discuss.elastic.co/u/Rizky_Hudha)\
**Replies:** 1\
**Last updated:** [December 17, 2021, 11:27am UTC](https://discuss.elastic.co/t/how-to-create-configure-date-filter-data-nested/292273 "2021-12-17T11:27:19Z")

</div>

I have some nested data in my log in the form of unix time, and I am trying to convert it to a time stamp, this is an example of the data I want to convert into a time stamp, { "upstream\_uri": "\\/request", "route":…

---

## [Logstash is not starting.. i have installed a new version of Logstash 7.16.1 , it crashes saying fatal error](https://discuss.elastic.co/t/logstash-is-not-starting-i-have-installed-a-new-version-of-logstash-7-16-1-it-crashes-saying-fatal-error/292026)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 6\
**Last updated:** [December 17, 2021, 5:05am UTC](https://discuss.elastic.co/t/logstash-is-not-starting-i-have-installed-a-new-version-of-logstash-7-16-1-it-crashes-saying-fatal-error/292026 "2021-12-17T05:05:27Z")

</div>

Logstash is not starting, I have installed Logstash 7.16.1, this is the error i am getting in logstash \[2021-12-15T17:28:43,113\]\[ERROR\]\[logstash.config.sourceloader\] No configuration found in the configured sources. \[2…

---

## [Need to bind logstash to eth0](https://discuss.elastic.co/t/need-to-bind-logstash-to-eth0/292236)

<div class="topic-metadata">

**Author:** [@Nie](https://discuss.elastic.co/u/Nie)\
**Replies:** 11\
**Last updated:** [December 17, 2021, 3:03am UTC](https://discuss.elastic.co/t/need-to-bind-logstash-to-eth0/292236 "2021-12-17T03:03:09Z")

</div>

I'm wondering why I am not seeing 5044 listener on the logstash server. I am seeing tcp port listeners on 9200 and 9600 when I execute "netstat -na". However, it's bound to loopback ip which is 127.0.0.1. Also, I can't…

---

## [Updating Logstash from an older version](https://discuss.elastic.co/t/updating-logstash-from-an-older-version/292245)

<div class="topic-metadata">

**Author:** [@b3owu1f](https://discuss.elastic.co/u/b3owu1f)\
**Replies:** 1\
**Last updated:** [December 17, 2021, 2:43am UTC](https://discuss.elastic.co/t/updating-logstash-from-an-older-version/292245 "2021-12-17T02:43:44Z")

</div>

Greetings I have an unsupported operational Logstash I was required to update due to the Log4j2 vulnerability. The service was implemented long ago without documentation by crew already out of the company. Looking aroun…

---

## [Sending data to TCP socket server on connect using logstash](https://discuss.elastic.co/t/sending-data-to-tcp-socket-server-on-connect-using-logstash/292221)

<div class="topic-metadata">

**Author:** [@Bobby\_Maine](https://discuss.elastic.co/u/Bobby_Maine)\
**Replies:** 0\
**Last updated:** [December 16, 2021, 8:40pm UTC](https://discuss.elastic.co/t/sending-data-to-tcp-socket-server-on-connect-using-logstash/292221 "2021-12-16T20:40:05Z")

</div>

Hi - I have a question that are two parts I am trying to configure logstash as a tcp socket client and have to send a message to the socket server each time the the socket client connects All messages sent and rece…

---

## [Problem witch characters "ãˆ°ãˆ±â´±ãˆ­ã„¶ã„¶ã„°" in field Message](https://discuss.elastic.co/t/problem-witch-characters-a-a-a-a-a-a-a-in-field-message/292214)

<div class="topic-metadata">

**Author:** [@Adixon\_Diaz](https://discuss.elastic.co/u/Adixon_Diaz)\
**Replies:** 2\
**Last updated:** [December 16, 2021, 8:17pm UTC](https://discuss.elastic.co/t/problem-witch-characters-a-a-a-a-a-a-a-in-field-message/292214 "2021-12-16T20:17:45Z")

</div>

Hi Elastic team, I have problem with some insertion in my logstash. I recieve a lot of row by second and some event give me "\_dateparsefailure" i could see in debug mode that this issue es when the field message come th…

---

## [Only title/first row get inserted in in elasticsearch](https://discuss.elastic.co/t/only-title-first-row-get-inserted-in-in-elasticsearch/292119)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 4\
**Last updated:** [December 16, 2021, 6:10pm UTC](https://discuss.elastic.co/t/only-title-first-row-get-inserted-in-in-elasticsearch/292119 "2021-12-16T18:10:26Z")

</div>

Hello team, I am sending data to Elasticsearch , I have .log files which containes below data. But Only title/first row get inserted in in Elasticsearch Sample log: Server Started Timestamp SeverityID EventID Severity…

---

## [Extract domain with grok](https://discuss.elastic.co/t/extract-domain-with-grok/292172)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 1\
**Last updated:** [December 16, 2021, 5:31pm UTC](https://discuss.elastic.co/t/extract-domain-with-grok/292172 "2021-12-16T17:31:17Z")

</div>

Hello! I have the following logs, with field "destination" looks like one of those: s03.amazon.com a63.google.com ayndex.cc s23.a4.test.com test.google.co.uk Is it possible by Grok filter in Logstash, or maybe other w…

---

## [Optional text + field RegEx with filters in Logstash](https://discuss.elastic.co/t/optional-text-field-regex-with-filters-in-logstash/292151)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 2\
**Last updated:** [December 16, 2021, 5:17pm UTC](https://discuss.elastic.co/t/optional-text-field-regex-with-filters-in-logstash/292151 "2021-12-16T17:17:54Z")

</div>

Hello! how can i set a text I use as locator as optioanal with regular expresions or grok ?? For example : 2021-12-15 13:50:34,589 INFO Parámetros enviados a XXXXXX: accion : YYYYYYYYYYY mesNacimiento : YYYYYYYYYY…

---

## [Multiple values in field json parser](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530)

<div class="topic-metadata">

**Author:** [@svenvg93](https://discuss.elastic.co/u/svenvg93)\
**Replies:** 3\
**Last updated:** [December 16, 2021, 4:12pm UTC](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530 "2021-12-16T16:12:17Z")

</div>

In order to learn more about ELK, I try to combine it with fun stuff to build :slight\_smile: . On of the things I try to make is dashboard with Formula 1 data. Im able to get the data in Elasticsearch by curl an json a…

---

## [Logstash substring a field using position getting error](https://discuss.elastic.co/t/logstash-substring-a-field-using-position-getting-error/292157)

<div class="topic-metadata">

**Author:** [@aeoker](https://discuss.elastic.co/u/aeoker)\
**Replies:** 1\
**Last updated:** [December 16, 2021, 4:10pm UTC](https://discuss.elastic.co/t/logstash-substring-a-field-using-position-getting-error/292157 "2021-12-16T16:10:13Z")

</div>

Hello Everyone, I am getting below error while trying to produce new event from existing one as follows, any help? ruby { code =\> "event\['new\_field'\] = event.get\['dummy'\]\[1..4\]" } Error: Ruby exception occurred:…

---

## [Log4j security vulnerability and plugins which bundle / vendor dependencies](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537)

<div class="topic-metadata">

**Author:** [@Kami](https://discuss.elastic.co/u/Kami)\
**Replies:** 4\
**Last updated:** [December 16, 2021, 4:02pm UTC](https://discuss.elastic.co/t/log4j-security-vulnerability-and-plugins-which-bundle-vendor-dependencies/291537 "2021-12-16T16:02:59Z")

</div>

(this post has been moved from Zero-day-exploit in log4j2 which is part of elasticsearch - #25 by Kami) Dear logstash community, I would like to better understand on how log4j vulnerability affects logstash plugins whi…

---

## [Ask for a help. Does the logstash output s3 plugin support getting data from Kafka?](https://discuss.elastic.co/t/ask-for-a-help-does-the-logstash-output-s3-plugin-support-getting-data-from-kafka/292084)

<div class="topic-metadata">

**Author:** [@shaojielinux](https://discuss.elastic.co/u/shaojielinux)\
**Replies:** 1\
**Last updated:** [December 16, 2021, 3:53pm UTC](https://discuss.elastic.co/t/ask-for-a-help-does-the-logstash-output-s3-plugin-support-getting-data-from-kafka/292084 "2021-12-16T15:53:15Z")

</div>

Ask for a help. Does the logstash output s3 plugin support getting data from Kafka? Below is my configuration input { kafka { bootstrap\_servers =\> "10.88.14.172:9092,10.88.6.9:9092,10.88.10.166:9092" #topics =\> \["k8s…

---

## [Combining two events in one to calculate time difference](https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [December 16, 2021, 3:35pm UTC](https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155 "2021-12-16T15:35:54Z")

</div>

Hello team, I have case where information is being displayed in different lines. These lines are not even consecutive lines. Unique field is log\_processed.companyId. I have to display time difference between entry and e…

---

## [Pipeline.ecs\_compatibility WARN logs](https://discuss.elastic.co/t/pipeline-ecs-compatibility-warn-logs/292164)

<div class="topic-metadata">

**Author:** [@adizalmanovich](https://discuss.elastic.co/u/adizalmanovich)\
**Replies:** 1\
**Last updated:** [December 16, 2021, 3:27pm UTC](https://discuss.elastic.co/t/pipeline-ecs-compatibility-warn-logs/292164 "2021-12-16T15:27:34Z")

</div>

I have some question. I upgraded my ELK to 7.16.1 due to a Log4j2 security issue. In my logstash configuration, we are using to get input from Azure EventHub and Kubernetes cluster. after upgraded my ELK I am getting h…

---

## [Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/291997)

<div class="topic-metadata">

**Author:** [@sama.sowjanya](https://discuss.elastic.co/u/sama.sowjanya)\
**Replies:** 4\
**Last updated:** [December 16, 2021, 3:10pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit/291997 "2021-12-16T15:10:49Z")

</div>

Hi I am getting the error when I run the config file through 'systemctl start logstash' log---- \[2021-12-15T13:49:55,003\]\[INFO \]\[logstash.runner\] Log4j configuration path used is: /etc/logstash/log4j2.properties \[202…

---

## [After restart, logstash doesn't read only new files](https://discuss.elastic.co/t/after-restart-logstash-doesnt-read-only-new-files/292012)

<div class="topic-metadata">

**Author:** [@khouloud](https://discuss.elastic.co/u/khouloud)\
**Replies:** 6\
**Last updated:** [December 16, 2021, 1:12pm UTC](https://discuss.elastic.co/t/after-restart-logstash-doesnt-read-only-new-files/292012 "2021-12-16T13:12:12Z")

</div>

Hello, is it possible when we stop and restart logstash doesn't read all the files that match the path from the beginning and read only new files appended?

---

## [Getting less hits in elasticsearch](https://discuss.elastic.co/t/getting-less-hits-in-elasticsearch/292095)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [December 16, 2021, 10:39am UTC](https://discuss.elastic.co/t/getting-less-hits-in-elasticsearch/292095 "2021-12-16T10:39:10Z")

</div>

I have 1000 records but i am just getting 997 records. csv-input.conf input { file { path =\> "/usr/share/logstash/user\_details.csv" start\_position =\> "beginning" #sincedb\_path =\> "/usr/share/logstash/dbteste" } } f…

---

## [Logstash and logical or](https://discuss.elastic.co/t/logstash-and-logical-or/291582)

<div class="topic-metadata">

**Author:** [@KaPBaJIOJI](https://discuss.elastic.co/u/KaPBaJIOJI)\
**Replies:** 3\
**Last updated:** [December 16, 2021, 3:43am UTC](https://discuss.elastic.co/t/logstash-and-logical-or/291582 "2021-12-16T03:43:29Z")

</div>

Hello everyone I try to started config logstash Work config filter { # grok log lines by program name (listed alpabetically) if \[program\] =~ /^postfix.\*\\/anvil$/ { grok { patterns\_dir =\> …

---

## [Logstash calls flush method multiple times per filter plugin](https://discuss.elastic.co/t/logstash-calls-flush-method-multiple-times-per-filter-plugin/292062)

<div class="topic-metadata">

**Author:** [@vbohata](https://discuss.elastic.co/u/vbohata)\
**Replies:** 0\
**Last updated:** [December 16, 2021, 12:28am UTC](https://discuss.elastic.co/t/logstash-calls-flush-method-multiple-times-per-filter-plugin/292062 "2021-12-16T00:28:29Z")

</div>

I am writing some logstash filter plugin and found one weird behaviour. It seems the LS somehow calls flush method multiple times even if I use 1 worker and 1 pipeline called "def". I did some tests and here are parts of…

---

## [Search for unused fields](https://discuss.elastic.co/t/search-for-unused-fields/292060)

<div class="topic-metadata">

**Author:** [@hamzahda](https://discuss.elastic.co/u/hamzahda)\
**Replies:** 3\
**Last updated:** [December 16, 2021, 2:04am UTC](https://discuss.elastic.co/t/search-for-unused-fields/292060 "2021-12-16T02:04:10Z")

</div>

I have an index pttern that has a huge number of fields and I want to clean it up by removing the unused fields. The way that I'm using to find out if a field is used or not is by searching for the field in the available…

---

## [Mitigation for Log4j2 vulnerability](https://discuss.elastic.co/t/mitigation-for-log4j2-vulnerability/291938)

<div class="topic-metadata">

**Author:** [@Programmer](https://discuss.elastic.co/u/Programmer)\
**Replies:** 4\
**Last updated:** [December 16, 2021, 1:21am UTC](https://discuss.elastic.co/t/mitigation-for-log4j2-vulnerability/291938 "2021-12-16T01:21:08Z")

</div>

Hi, I am using the below ELK stack versions. Might be old version. I would like to know whether these versions of ELK are vulnerable due to the log4j2 issue. Elasticsearch-2.3.3 logstash-2.3.1 kibana-4.5.1 I couldn'…

---

## [Logstash json parse error](https://discuss.elastic.co/t/logstash-json-parse-error/291557)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 11:01pm UTC](https://discuss.elastic.co/t/logstash-json-parse-error/291557 "2021-12-15T23:01:31Z")

</div>

hello, Last time I'm receiving a log of logstash json parse errors, from the error logs I cannot read anything about to what files it is about to, \[ WARN \] 2021-12-12 13:28:20.845 \[\[main\]\>worker6\] json - Error parsing…

---

## [Logstash : Elasticsearch input plugin not working with a remote server](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-not-working-with-a-remote-server/291685)

<div class="topic-metadata">

**Author:** [@Bassem\_Wadie](https://discuss.elastic.co/u/Bassem_Wadie)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 9:37pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-not-working-with-a-remote-server/291685 "2021-12-15T21:37:03Z")

</div>

Hello, I have logstash installed on my PC and there is a Amazon Linux 2 AMI machine contains Kubernetes ( Elasticsearch and Ngnix) There is ssl installed on the server but i can make queries from postman on my pc usi…

---

## [Logstash.instrument.periodicpoller.jvm remove from log](https://discuss.elastic.co/t/logstash-instrument-periodicpoller-jvm-remove-from-log/291932)

<div class="topic-metadata">

**Author:** [@peledev](https://discuss.elastic.co/u/peledev)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 9:20pm UTC](https://discuss.elastic.co/t/logstash-instrument-periodicpoller-jvm-remove-from-log/291932 "2021-12-15T21:20:11Z")

</div>

how do i disable all the logs debug of logstash.instrument.periodicpoller.jvm it is filling my log with junk please assist thanks claudia

---

## [Warning \[org.logstash.instrument.metrics.gauge.LazyDelegatingGauge\] after updating to 7.16.1](https://discuss.elastic.co/t/warning-org-logstash-instrument-metrics-gauge-lazydelegatinggauge-after-updating-to-7-16-1/292049)

<div class="topic-metadata">

**Author:** [@d71247](https://discuss.elastic.co/u/d71247)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 9:07pm UTC](https://discuss.elastic.co/t/warning-org-logstash-instrument-metrics-gauge-lazydelegatinggauge-after-updating-to-7-16-1/292049 "2021-12-15T21:07:37Z")

</div>

Hello, I just updated my Logstash to 7.16.1... but I noticed warning in my conf when starting Logstash. the same conf of Logstash works well in version 7.9.1 How do to fix this warning ? I am using a Logstash docker …

---

## [Is it possible to update an index by importing an updated .csv file?](https://discuss.elastic.co/t/is-it-possible-to-update-an-index-by-importing-an-updated-csv-file/292029)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 1\
**Last updated:** [December 15, 2021, 8:35pm UTC](https://discuss.elastic.co/t/is-it-possible-to-update-an-index-by-importing-an-updated-csv-file/292029 "2021-12-15T20:35:24Z")

</div>

I want to update my index by importing a .csv file via Logstash. Currently, the plan is to delete all the records from the index and then reimport the new .csv file from scratch. But I was wondering if it's possible to j…

---

## [CVE-2021-44228 Alternative Mitigation](https://discuss.elastic.co/t/cve-2021-44228-alternative-mitigation/291877)

<div class="topic-metadata">

**Author:** [@boris111](https://discuss.elastic.co/u/boris111)\
**Replies:** 2\
**Last updated:** [December 15, 2021, 7:55pm UTC](https://discuss.elastic.co/t/cve-2021-44228-alternative-mitigation/291877 "2021-12-15T19:55:02Z")

</div>

Is it possible to drop the new log4j-core-2.15.0.jar for logstash as an alternative mitigation for the 5.x logstash version? The recommended mitigation step to remove the JndiLookup.class would not be desirable for dep…

---

## [Need to split comma delimited string where one of the fields contains a backslash](https://discuss.elastic.co/t/need-to-split-comma-delimited-string-where-one-of-the-fields-contains-a-backslash/289962)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 2\
**Last updated:** [November 23, 2021, 7:00pm UTC](https://discuss.elastic.co/t/need-to-split-comma-delimited-string-where-one-of-the-fields-contains-a-backslash/289962 "2021-11-23T19:00:48Z")

</div>

I have this message string: "foo,bar,domain\\name,blah I need to split it into fields so it looks like this: field\[0\]: foo field\[1\]: bar field\[2\]: domain\\user field\[3\]: blah but the split filter splits the message u…

---

## [Failing to load conf file](https://discuss.elastic.co/t/failing-to-load-conf-file/289811)

<div class="topic-metadata">

**Author:** [@kainan](https://discuss.elastic.co/u/kainan)\
**Replies:** 4\
**Last updated:** [November 23, 2021, 3:28pm UTC](https://discuss.elastic.co/t/failing-to-load-conf-file/289811 "2021-11-23T15:28:02Z")

</div>

Hey all, First time poster. I have been struggling for over a week to get the below conf file to compile. I have read through the forums and it always seems to be missing a } however that does not seem to be the case he…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=172)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=174)
