# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=174

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 175

---

## [Mutate rename using field value](https://discuss.elastic.co/t/mutate-rename-using-field-value/292014)

<div class="topic-metadata">

**Author:** [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Replies:** 2\
**Last updated:** [December 15, 2021, 6:27pm UTC](https://discuss.elastic.co/t/mutate-rename-using-field-value/292014 "2021-12-15T18:27:13Z")

</div>

Hello, I'm trying to rename a field using the value of another metadata field, here is what I have tried: filter { grok { match =\> { "path" =\> "%{GREEDYDATA}/%{GREEDYDATA:\[@metadata\]\[metric\_name\]}\\.csv" …

---

## [Create new records from old one](https://discuss.elastic.co/t/create-new-records-from-old-one/291989)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 7\
**Last updated:** [December 15, 2021, 3:42pm UTC](https://discuss.elastic.co/t/create-new-records-from-old-one/291989 "2021-12-15T15:42:25Z")

</div>

Hello! I have JSON at input { "data:{ "id":"123" }, "message":\[ "event1", "event2", "event3" \], "source":"abc" } Is it possible to make three different events based on "event1", "event2" and "…

---

## [Parse XML nessus config to logstash](https://discuss.elastic.co/t/parse-xml-nessus-config-to-logstash/290887)

<div class="topic-metadata">

**Author:** [@k1mson13](https://discuss.elastic.co/u/k1mson13)\
**Replies:** 12\
**Last updated:** [December 15, 2021, 3:21pm UTC](https://discuss.elastic.co/t/parse-xml-nessus-config-to-logstash/290887 "2021-12-15T15:21:20Z")

</div>

I have a nessus file that looks like this : \<ReportHost name="192.168.2.65"\>\<HostProperties\> \<tag name="traceroute-hop-1"\>192.168.2.65\</tag\> \<tag name="HOST\_START"\>Wed Nov 10 12:48:53 2021\</tag\> \<tag name="HOST\_START\_TI…

---

## [Mongodb jdbc using in logstash](https://discuss.elastic.co/t/mongodb-jdbc-using-in-logstash/291311)

<div class="topic-metadata">

**Author:** [@peledev](https://discuss.elastic.co/u/peledev)\
**Replies:** 4\
**Last updated:** [December 15, 2021, 8:03am UTC](https://discuss.elastic.co/t/mongodb-jdbc-using-in-logstash/291311 "2021-12-15T08:03:58Z")

</div>

trying to write log from mongodb using jdbc see configuration file: input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/logstash-core/lib/jars/mongodb-driver-core-3.4.2.jar" jdbc\_driver\_class =\>…

---

## [Could not index event to Elasticsearch](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291777)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [December 15, 2021, 12:59pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291777 "2021-12-15T12:59:54Z")

</div>

Hello everyone. i have a trouble with elastic. the logs stop come in since 16:40 and here is the log of logstash \` \> \[2021-12-14T16:57:20,948\]\[WARN \]\[logstash.outputs.elasticsearch\]\[pipeline\_ocp4\] Could not index event…

---

## [CVE-2021-44228 aka log4shell is logstash and/or elasticsearch affected?](https://discuss.elastic.co/t/cve-2021-44228-aka-log4shell-is-logstash-and-or-elasticsearch-affected/291415)

<div class="topic-metadata">

**Author:** [@jzandbergen](https://discuss.elastic.co/u/jzandbergen)\
**Replies:** 14\
**Last updated:** [December 15, 2021, 6:22am UTC](https://discuss.elastic.co/t/cve-2021-44228-aka-log4shell-is-logstash-and-or-elasticsearch-affected/291415 "2021-12-15T06:22:09Z")

</div>

Hi All, I was wondering if logstash and/or Elasticsearch is affected by this CVE? More information about this zeroday can be found here: Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package | L…

---

## [Multiple Pipelines throwing errors when enabled](https://discuss.elastic.co/t/multiple-pipelines-throwing-errors-when-enabled/291858)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 9\
**Last updated:** [December 14, 2021, 8:28pm UTC](https://discuss.elastic.co/t/multiple-pipelines-throwing-errors-when-enabled/291858 "2021-12-14T20:28:15Z")

</div>

Good Afternoon Elastic Peeps; I have been working with configuring and employing multiple pipelines in my ELK stack. I have implemented ELK 7.13.4 and when I use a simple syslog pipeline I am able to gather the informa…

---

## [Logstash Date filter plugin doesn't work with Java 8 after 7.16.1 upgrade](https://discuss.elastic.co/t/logstash-date-filter-plugin-doesnt-work-with-java-8-after-7-16-1-upgrade/291811)

<div class="topic-metadata">

**Author:** [@YuryShupletsov](https://discuss.elastic.co/u/YuryShupletsov)\
**Replies:** 1\
**Last updated:** [December 14, 2021, 7:40pm UTC](https://discuss.elastic.co/t/logstash-date-filter-plugin-doesnt-work-with-java-8-after-7-16-1-upgrade/291811 "2021-12-14T19:40:15Z")

</div>

Hello, We have updated Logstash from 7.10.1 to 7.16.1 and cannot start it with the error: \[2021-12-14T15:35:05,385\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/…

---

## [Multiline pattern not matching in fluentbit](https://discuss.elastic.co/t/multiline-pattern-not-matching-in-fluentbit/291853)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 3\
**Last updated:** [December 14, 2021, 6:55pm UTC](https://discuss.elastic.co/t/multiline-pattern-not-matching-in-fluentbit/291853 "2021-12-14T18:55:32Z")

</div>

Hello team, I am ingesting data through fluent bit. we are facing some multiline pattern issu. can any one help me on this. In the message field it is displaying only 1 line. Pattern: (?m-ix)^(?\<time\>\\d{4}\\-\\d{2}\\…

---

## [How to re-name field names in logstash](https://discuss.elastic.co/t/how-to-re-name-field-names-in-logstash/291803)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 3\
**Last updated:** [December 14, 2021, 6:19pm UTC](https://discuss.elastic.co/t/how-to-re-name-field-names-in-logstash/291803 "2021-12-14T18:19:06Z")

</div>

Hi all, We have field names like client.geo.name and event.category , how can we re-name the names to this client geo name and event category. "\[event\]\[category\]" =\> "Event category" "\[client\]\[geo\]\[name\]" =\> "client g…

---

## [Logstash sending data to kafka topic at same time which disturbs ordering of log transactions](https://discuss.elastic.co/t/logstash-sending-data-to-kafka-topic-at-same-time-which-disturbs-ordering-of-log-transactions/291848)

<div class="topic-metadata">

**Author:** [@venkataraman](https://discuss.elastic.co/u/venkataraman)\
**Replies:** 1\
**Last updated:** [December 14, 2021, 5:58pm UTC](https://discuss.elastic.co/t/logstash-sending-data-to-kafka-topic-at-same-time-which-disturbs-ordering-of-log-transactions/291848 "2021-12-14T17:58:02Z")

</div>

Hello Everyone, My log file transactions look like this as shown below My log file looks like this: start time: 2021-10-11T13:54:34Z category: commercial status: started end time: start time: 2021-10-11T13:54:34Z c…

---

## [Problem with "\\n" character with tcp output plugin](https://discuss.elastic.co/t/problem-with-n-character-with-tcp-output-plugin/291822)

<div class="topic-metadata">

**Author:** [@lemahdois](https://discuss.elastic.co/u/lemahdois)\
**Replies:** 1\
**Last updated:** [December 14, 2021, 5:55pm UTC](https://discuss.elastic.co/t/problem-with-n-character-with-tcp-output-plugin/291822 "2021-12-14T17:55:59Z")

</div>

Hello, on my logstash pipeline I receive logs that contain "\\n" character as follows "message" : "aaaa\\nbbbbb" When sending this log using tcp output plugin, the destination receives the log on two lines aaaa bb…

---

## [How to update log4j jar in logstash installed in ubuntu VM](https://discuss.elastic.co/t/how-to-update-log4j-jar-in-logstash-installed-in-ubuntu-vm/291830)

<div class="topic-metadata">

**Author:** [@Rughma\_Sussan\_Renji](https://discuss.elastic.co/u/Rughma_Sussan_Renji)\
**Replies:** 2\
**Last updated:** [December 14, 2021, 5:47pm UTC](https://discuss.elastic.co/t/how-to-update-log4j-jar-in-logstash-installed-in-ubuntu-vm/291830 "2021-12-14T17:47:38Z")

</div>

how will I upgrade my logstash version in ubuntu to 2.15.0, currently it is 2.14.0, but due to the vulnerability issue I need to update it to 2.15.0. can anyone tell me the command to update it to the latest version

---

## [Create tab delimited string for output](https://discuss.elastic.co/t/create-tab-delimited-string-for-output/291840)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [December 14, 2021, 5:40pm UTC](https://discuss.elastic.co/t/create-tab-delimited-string-for-output/291840 "2021-12-14T17:40:52Z")

</div>

I need to construct a string with tab as delimiters for downstream consumption. I don't want to create a csv file because I am sending it over the network somewhere else. example input: field1: timestamp field2: host…

---

## [Logstash starts but doesn’t do anything](https://discuss.elastic.co/t/logstash-starts-but-doesn-t-do-anything/291637)

<div class="topic-metadata">

**Author:** [@sama.sowjanya](https://discuss.elastic.co/u/sama.sowjanya)\
**Replies:** 4\
**Last updated:** [December 14, 2021, 2:06pm UTC](https://discuss.elastic.co/t/logstash-starts-but-doesn-t-do-anything/291637 "2021-12-14T14:06:51Z")

</div>

Im trying to get some data in my logstash but my service doesn't seem to work properly. When I check my logstash status I get the following: ● logstash.service - logstash Loaded: loaded (/etc/systemd/system/logstash.se…

---

## [Help with Grok pattern with space in field?](https://discuss.elastic.co/t/help-with-grok-pattern-with-space-in-field/291695)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 5\
**Last updated:** [December 14, 2021, 1:03pm UTC](https://discuss.elastic.co/t/help-with-grok-pattern-with-space-in-field/291695 "2021-12-14T13:03:56Z")

</div>

I have the following logs looks like: query: s03.amazon.com IN A + (21.12.21.21) query: s2.tabtest.com IN AAAA +++ (213.12.21.21) query: t4.asaptest.com OUT TD OP- (21.124.21.21) I need output to look like this: hos…

---

## [Logstash - comparison 2 fields](https://discuss.elastic.co/t/logstash-comparison-2-fields/291692)

<div class="topic-metadata">

**Author:** [@Christophe\_Journel](https://discuss.elastic.co/u/Christophe_Journel)\
**Replies:** 2\
**Last updated:** [December 14, 2021, 11:47am UTC](https://discuss.elastic.co/t/logstash-comparison-2-fields/291692 "2021-12-14T11:47:48Z")

</div>

Hello. I would like to compare 2 fields using logstash. To be more precise, i would like to know id the content of one field is included into the other one, using ( regex) i tried this configuration if ( \[test\]\[fi…

---

## [Translate Filter Error, Not Getting file Path?](https://discuss.elastic.co/t/translate-filter-error-not-getting-file-path/291590)

<div class="topic-metadata">

**Author:** [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Replies:** 2\
**Last updated:** [December 14, 2021, 6:25am UTC](https://discuss.elastic.co/t/translate-filter-error-not-getting-file-path/291590 "2021-12-14T06:25:08Z")

</div>

I am working on 7.14.1 Elasticsearch version. I am running it using docker-compose file. I have different files in json format. I am trying to read all those files in logstash config file but I am getting error. I think …

---

## [Extracting fields from existing message field in windows logs](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705)

<div class="topic-metadata">

**Author:** [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Replies:** 3\
**Last updated:** [December 14, 2021, 4:55am UTC](https://discuss.elastic.co/t/extracting-fields-from-existing-message-field-in-windows-logs/291705 "2021-12-14T04:55:32Z")

</div>

Hi, I have winlogbeat that sends evtx files to logstash and than the output of logstash goes to elastic. In the windows event logs, there is a field named "message". the problem is that the field type is text, so i ca…

---

## [Logstash - OutOfMemoryError from TCP input](https://discuss.elastic.co/t/logstash-outofmemoryerror-from-tcp-input/291702)

<div class="topic-metadata">

**Author:** [@vishnug](https://discuss.elastic.co/u/vishnug)\
**Replies:** 1\
**Last updated:** [December 13, 2021, 6:38pm UTC](https://discuss.elastic.co/t/logstash-outofmemoryerror-from-tcp-input/291702 "2021-12-13T18:38:38Z")

</div>

Hi, I have a logstash pipeline that uses TCP as input. The pipeline handles around 150k to 200k events per day. I was getting the below errors. An exception was thrown by org.logstash.tcp.InputLoop$InputHandler$FlushOn…

---

## [How to re-name multiple field names at once in logstash](https://discuss.elastic.co/t/how-to-re-name-multiple-field-names-at-once-in-logstash/291599)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 1\
**Last updated:** [December 13, 2021, 5:45pm UTC](https://discuss.elastic.co/t/how-to-re-name-multiple-field-names-at-once-in-logstash/291599 "2021-12-13T17:45:14Z")

</div>

Hie All, I want to rename fields names from this : "\[url\]\[path\]" =\> to "url path" and "\[server\]\[domain\]" =\> "Server domain" We can use mutate filter plugin (as mutate uses lot of cpu) ,but I have nearly 50 fields name…

---

## [CSV MalformedCSVError: Illegal quoting in line](https://discuss.elastic.co/t/csv-malformedcsverror-illegal-quoting-in-line/291639)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 1\
**Last updated:** [December 13, 2021, 4:59pm UTC](https://discuss.elastic.co/t/csv-malformedcsverror-illegal-quoting-in-line/291639 "2021-12-13T16:59:45Z")

</div>

I have used CSV filter to log the events my sample data is 2021-12-09 12:12:09,155 INFO com.tdg.box.incrindex.service.PastEventProcessor \[Thread-14\] Captured Event false dbf5b71c-faa1-4e73-b8db-bf057002e3f5 UPLOAD 1747…

---

## [Mapping Strategies For Survey Data](https://discuss.elastic.co/t/mapping-strategies-for-survey-data/291481)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [December 13, 2021, 4:58pm UTC](https://discuss.elastic.co/t/mapping-strategies-for-survey-data/291481 "2021-12-13T16:58:55Z")

</div>

I am ingesting data and looking for opinions on better ways of indexing the data for later aggregation analytics. The data is currently pulled and stored in Elasticsearch as numbered q&a fields. { "question1": { …

---

## [Error running Logstash 7.16.1 OSS](https://discuss.elastic.co/t/error-running-logstash-7-16-1-oss/291677)

<div class="topic-metadata">

**Author:** [@BenSeb](https://discuss.elastic.co/u/BenSeb)\
**Replies:** 2\
**Last updated:** [December 13, 2021, 4:54pm UTC](https://discuss.elastic.co/t/error-running-logstash-7-16-1-oss/291677 "2021-12-13T16:54:53Z")

</div>

We're getting the following errors when trying to run 7.16.1 OSS \[2021-12-13T14:53:22,775\]\[INFO \]\[logstash.runner \] Log4j configuration path used is: /etc/logstash/log4j2.properties \[2021-12-13T14:53:22,790\]\[I…

---

## [exception=\>#\<CSV::MalformedCSVError: Illegal quoting in line 1.\>](https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 2\
**Last updated:** [December 13, 2021, 4:06pm UTC](https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437 "2021-12-13T16:06:49Z")

</div>

My config file is: { stdin{} } filter { if "box\_Firewall" not in \[program\] { if \[message\] =~ /{".\*":\\s".\*",/ { json { source =\> "message" } …

---

## [Logstash.conf not building pipeline.yml file](https://discuss.elastic.co/t/logstash-conf-not-building-pipeline-yml-file/291259)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 12\
**Last updated:** [December 13, 2021, 3:36pm UTC](https://discuss.elastic.co/t/logstash-conf-not-building-pipeline-yml-file/291259 "2021-12-13T15:36:58Z")

</div>

Good Afternoon Elastic Peeps; I am in the process of creating a second logstash.conf file on my server. It is intended to pull data from a microsoft database. To that end I downloaded and extracted the sqljdbc9.4.jar …

---

## [Convert IP string to Integer](https://discuss.elastic.co/t/convert-ip-string-to-integer/290351)

<div class="topic-metadata">

**Author:** [@rojin](https://discuss.elastic.co/u/rojin)\
**Replies:** 3\
**Last updated:** [December 13, 2021, 2:48pm UTC](https://discuss.elastic.co/t/convert-ip-string-to-integer/290351 "2021-12-13T14:48:18Z")

</div>

Hi!, Is there a way to convert an IP address to an integer in logstash filters? Suppose I have the grok pattern: %{IPv4: clientip} - %{DATA:name}.... I want to have the equivalent byte-like integer of the IP address t…

---

## [Parsing a date and timestamp to default Elasticsearch](https://discuss.elastic.co/t/parsing-a-date-and-timestamp-to-default-elasticsearch/291667)

<div class="topic-metadata">

**Author:** [@mangesh\_shinde](https://discuss.elastic.co/u/mangesh_shinde)\
**Replies:** 2\
**Last updated:** [December 13, 2021, 2:43pm UTC](https://discuss.elastic.co/t/parsing-a-date-and-timestamp-to-default-elasticsearch/291667 "2021-12-13T14:43:44Z")

</div>

I have a field called event\_timestamp with format Thu Dec 09 15:02:66 IST 2021 I want to parse this format to default elastic acceptable format I use date filter as below date{ match =\> \["event\_timestamp","EEE MMM dd…

---

## [Logstash input Kafka error](https://discuss.elastic.co/t/logstash-input-kafka-error/291345)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 1\
**Last updated:** [December 13, 2021, 1:27pm UTC](https://discuss.elastic.co/t/logstash-input-kafka-error/291345 "2021-12-13T13:27:04Z")

</div>

Hi evrery one, i'm facing an issue while using kafka as my logstash input. when i started logstash i have this error : Unable to poll Kafka consumer {:kafka\_error\_message=\>org.apache.kafka.common.KafkaException: Recei…

---

## [The grok works very strangely in logstash](https://discuss.elastic.co/t/the-grok-works-very-strangely-in-logstash/291427)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 5\
**Last updated:** [December 13, 2021, 10:13am UTC](https://discuss.elastic.co/t/the-grok-works-very-strangely-in-logstash/291427 "2021-12-13T10:13:42Z")

</div>

To all lovers of this hello! In some excellent one noticed that my messages in logstash stopped parsing, an error appeared - \_grokparsefailure. but no configuration changes were made. Original messages 1.2.3.4 0 - Tes…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=173)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=175)
