# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=176

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 177

---

## [URGENT! Elastic search: Unable to perform jdbc query because of Exception when executing JDBC query](https://discuss.elastic.co/t/urgent-elastic-search-unable-to-perform-jdbc-query-because-of-exception-when-executing-jdbc-query/291181)

<div class="topic-metadata">

**Author:** [@Leo\_Baby\_Jacob](https://discuss.elastic.co/u/Leo_Baby_Jacob)\
**Replies:** 1\
**Last updated:** [December 8, 2021, 2:27pm UTC](https://discuss.elastic.co/t/urgent-elastic-search-unable-to-perform-jdbc-query-because-of-exception-when-executing-jdbc-query/291181 "2021-12-08T14:27:24Z")

</div>

I have a sample logstash conf file, However when I. run it I can see a logstash error caused Error is \[371de1f7cad8c35c02e4a3047ec831da42b9b5048183b45a3916162ab248f3f7\] Exception when executing JDBC query {:excepti…

---

## [Logstash Cannot Listen Port 5044 after fresh install](https://discuss.elastic.co/t/logstash-cannot-listen-port-5044-after-fresh-install/291191)

<div class="topic-metadata">

**Author:** [@bropid](https://discuss.elastic.co/u/bropid)\
**Replies:** 2\
**Last updated:** [December 8, 2021, 12:33pm UTC](https://discuss.elastic.co/t/logstash-cannot-listen-port-5044-after-fresh-install/291191 "2021-12-08T12:33:23Z")

</div>

Hi, i'am freshly installed logstash but when i'm try to test connect with telnet \<logstash ip\> 5044 it says connection refused. Then when i check my network in logstash machine with netstat -plntu | grep 5044 it did…

---

## [Unable to deploy Logstash .. " Unable to configure plugins: Cannot evaluate \`${ELASTIC\_CERTIFICATE}\`. Replacement variable \`ELASTIC\_CERTIFICATE\` is not defined in a Logstash secret store or an environment entry and there is no default value given."](https://discuss.elastic.co/t/unable-to-deploy-logstash-unable-to-configure-plugins-cannot-evaluate-elastic-certificate-replacement-variable-elastic-certificate-is-not-defined-in-a-logstash-secret-store-or-an-environment-entry-and-there-is-no-default-value-given/291216)

<div class="topic-metadata">

**Author:** [@vishnu\_rao](https://discuss.elastic.co/u/vishnu_rao)\
**Replies:** 0\
**Last updated:** [December 8, 2021, 12:29pm UTC](https://discuss.elastic.co/t/unable-to-deploy-logstash-unable-to-configure-plugins-cannot-evaluate-elastic-certificate-replacement-variable-elastic-certificate-is-not-defined-in-a-logstash-secret-store-or-an-environment-entry-and-there-is-no-default-value-given/291216 "2021-12-08T12:29:15Z")

</div>

Hello All I am trying to deploy logstash in our environment and I am seeing below error . I have created the secret with the Elastic Certificate ( .cer ) file .. but sill I am seeing the below error. Using bundled JD…

---

## [Question about permission for file input \[Linux\]](https://discuss.elastic.co/t/question-about-permission-for-file-input-linux/291108)

<div class="topic-metadata">

**Author:** [@Fosco](https://discuss.elastic.co/u/Fosco)\
**Replies:** 4\
**Last updated:** [December 8, 2021, 11:20am UTC](https://discuss.elastic.co/t/question-about-permission-for-file-input-linux/291108 "2021-12-08T11:20:04Z")

</div>

Hi, I have some scripts which download files and need to be read and deleted by logstash afterwards Regarding the permission, the files must be logstash:logstash or only the folder containing the files? Thanks !

---

## [Multiple inputs to multiple indices](https://discuss.elastic.co/t/multiple-inputs-to-multiple-indices/290171)

<div class="topic-metadata">

**Author:** [@Katgust](https://discuss.elastic.co/u/Katgust)\
**Replies:** 3\
**Last updated:** [December 8, 2021, 10:37am UTC](https://discuss.elastic.co/t/multiple-inputs-to-multiple-indices/290171 "2021-12-08T10:37:17Z")

</div>

Hi! I'm new to the Elastic stack but have tried to learn to use it the last couple of weeks. I have Elasticsearch and Kibana running (I can at least use the DevTools) and I'm using Logstash to retrieve data from an MSSQ…

---

## [Logstash process taking more memory than configured](https://discuss.elastic.co/t/logstash-process-taking-more-memory-than-configured/291064)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 6\
**Last updated:** [December 8, 2021, 8:23am UTC](https://discuss.elastic.co/t/logstash-process-taking-more-memory-than-configured/291064 "2021-12-08T08:23:45Z")

</div>

Hi there. Question in regards to some weird behavior I am noticing on all of our logstash servers. We are running 7.13.4 currently. The problem is related to logstash seemingly taking more memory than I have configured i…

---

## [Remove \_id, \_index, \_score, \_type fields from index by logstash](https://discuss.elastic.co/t/remove-id-index-score-type-fields-from-index-by-logstash/290283)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 3\
**Last updated:** [December 8, 2021, 7:05am UTC](https://discuss.elastic.co/t/remove-id-index-score-type-fields-from-index-by-logstash/290283 "2021-12-08T07:05:11Z")

</div>

I want to delete above fields from event in Elasticsearch from logstash config

---

## [Aggregate fields to an array fields](https://discuss.elastic.co/t/aggregate-fields-to-an-array-fields/291024)

<div class="topic-metadata">

**Author:** [@RichYaNa](https://discuss.elastic.co/u/RichYaNa)\
**Replies:** 7\
**Last updated:** [December 8, 2021, 3:18am UTC](https://discuss.elastic.co/t/aggregate-fields-to-an-array-fields/291024 "2021-12-08T03:18:45Z")

</div>

Hi, I have some output here from my logstash filter: { "taskid" =\> "123", "host" =\> "ubuntu" }, { "taskid" =\> "123", "host" =\> "centos" } is it possible to aggregate that field to be like this: { "taskid"…

---

## [Pipelines running {:count=\>1, :running\_pipelines=\>\[:main\], :non\_running\_pipelines=\>\[\]}](https://discuss.elastic.co/t/pipelines-running-count-1-running-pipelines-main-non-running-pipelines/290811)

<div class="topic-metadata">

**Author:** [@Emanuel\_Fernandez](https://discuss.elastic.co/u/Emanuel_Fernandez)\
**Replies:** 3\
**Last updated:** [December 7, 2021, 8:34pm UTC](https://discuss.elastic.co/t/pipelines-running-count-1-running-pipelines-main-non-running-pipelines/290811 "2021-12-07T20:34:17Z")

</div>

Cuando ejecuto el comando; \\bin\>logstash -f pipeline.config me sale ese error. He realizado muchas modificaciones guiandome en los blogs pero no he dado con el resultado. Muestro como tengo configurado mi pipeline.confi…

---

## [Supported compression algorithms?](https://discuss.elastic.co/t/supported-compression-algorithms/291157)

<div class="topic-metadata">

**Author:** [@tofubeats](https://discuss.elastic.co/u/tofubeats)\
**Replies:** 1\
**Last updated:** [December 7, 2021, 8:16pm UTC](https://discuss.elastic.co/t/supported-compression-algorithms/291157 "2021-12-07T20:16:21Z")

</div>

Hello, I would like to know what compression algorithms logstash pipelines can work with? For example, if i have a pipeline polling a webserver that sends compressed data, will the logstash pipeline only automatically d…

---

## [Unable to get list /load any plugin in logstash](https://discuss.elastic.co/t/unable-to-get-list-load-any-plugin-in-logstash/291155)

<div class="topic-metadata">

**Author:** [@Vipin\_Johar](https://discuss.elastic.co/u/Vipin_Johar)\
**Replies:** 1\
**Last updated:** [December 7, 2021, 8:07pm UTC](https://discuss.elastic.co/t/unable-to-get-list-load-any-plugin-in-logstash/291155 "2021-12-07T20:07:28Z")

</div>

Hi , i am trying to load plugin in logstash but getting the message "Using bundled JDK: "", could you please help here.

---

## [Rename process of logstash in linux](https://discuss.elastic.co/t/rename-process-of-logstash-in-linux/291156)

<div class="topic-metadata">

**Author:** [@Thuy\_Le1](https://discuss.elastic.co/u/Thuy_Le1)\
**Replies:** 1\
**Last updated:** [December 7, 2021, 8:02pm UTC](https://discuss.elastic.co/t/rename-process-of-logstash-in-linux/291156 "2021-12-07T20:02:18Z")

</div>

at the moment when we run logstash from ./bin/logstash -f logstash\_file.conf the process name is java, how we change to logstash??

---

## [Getting \_dateparsefailure for a log file having two timestamps](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 3\
**Last updated:** [December 7, 2021, 4:10pm UTC](https://discuss.elastic.co/t/getting-dateparsefailure-for-a-log-file-having-two-timestamps/289643 "2021-12-07T16:10:44Z")

</div>

Hello My log file looks like: \[ { "textPayload": "{'testkey': 'testvalue'}", "insertId": "12345-12345", "resource": { "type": "cloud\_function", "labels": { "project\_id": "project-p123",…

---

## [Need help to get only message](https://discuss.elastic.co/t/need-help-to-get-only-message/290123)

<div class="topic-metadata">

**Author:** [@sushant12](https://discuss.elastic.co/u/sushant12)\
**Replies:** 1\
**Last updated:** [December 7, 2021, 3:59pm UTC](https://discuss.elastic.co/t/need-help-to-get-only-message/290123 "2021-12-07T15:59:45Z")

</div>

logs logging messages in following pattern 2021-11-03 05:03:22,773,773 DEBUG \[controllers.requests\] log are logged in to system. i just want to extract following things so i can store in separate variables : Time stam…

---

## [Not able to get see logs until I delete the index](https://discuss.elastic.co/t/not-able-to-get-see-logs-until-i-delete-the-index/290728)

<div class="topic-metadata">

**Author:** [@manavtidhan](https://discuss.elastic.co/u/manavtidhan)\
**Replies:** 1\
**Last updated:** [December 7, 2021, 3:08pm UTC](https://discuss.elastic.co/t/not-able-to-get-see-logs-until-i-delete-the-index/290728 "2021-12-07T15:08:43Z")

</div>

Hi , I am not able to see logs next day , until I delete the index manually from Kibana Below is the status of my logstash and I am not able to see any error logs even I put the debug mode in logstash.yml Below is …

---

## [Logstash service stopped without any specific error](https://discuss.elastic.co/t/logstash-service-stopped-without-any-specific-error/290504)

<div class="topic-metadata">

**Author:** [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Replies:** 15\
**Last updated:** [December 7, 2021, 9:03am UTC](https://discuss.elastic.co/t/logstash-service-stopped-without-any-specific-error/290504 "2021-12-07T09:03:23Z")

</div>

Hello, I've been handling logstash this week, and the service always turned off at night (around 8pm-10pm), so I enabled the debug log, and I can't find any error log that lead to the stopped service here's the last log…

---

## [Grok parsing in logstash for Windows DNS Debug Log](https://discuss.elastic.co/t/grok-parsing-in-logstash-for-windows-dns-debug-log/291085)

<div class="topic-metadata">

**Author:** [@craign30](https://discuss.elastic.co/u/craign30)\
**Replies:** 11\
**Last updated:** [December 7, 2021, 3:53am UTC](https://discuss.elastic.co/t/grok-parsing-in-logstash-for-windows-dns-debug-log/291085 "2021-12-07T03:53:17Z")

</div>

I'm using grok in Logstash (7.8.0) to parse data from a Windows Server (2019) DNS debug log (sent via filebeat) using the statement below. Most of the time, the data gets parsed correctly and fields are populated and vi…

---

## [Syslog filter issue with timestamp](https://discuss.elastic.co/t/syslog-filter-issue-with-timestamp/290468)

<div class="topic-metadata">

**Author:** [@mylvestre](https://discuss.elastic.co/u/mylvestre)\
**Replies:** 12\
**Last updated:** [December 6, 2021, 6:54pm UTC](https://discuss.elastic.co/t/syslog-filter-issue-with-timestamp/290468 "2021-12-06T18:54:22Z")

</div>

Greetings, I'm having an issue where my syslog is parsing the wrong date format. I get the following in Elastic: yyyy-11-Mo 11:37:17, while I get the following error in logstash: \[2021-11-29T11:34:43,644\]\[WARN \]\[logsta…

---

## [Filter basic file with Logstash](https://discuss.elastic.co/t/filter-basic-file-with-logstash/290991)

<div class="topic-metadata">

**Author:** [@algira37](https://discuss.elastic.co/u/algira37)\
**Replies:** 3\
**Last updated:** [December 6, 2021, 6:21pm UTC](https://discuss.elastic.co/t/filter-basic-file-with-logstash/290991 "2021-12-06T18:21:16Z")

</div>

Hello, I have a blocklist.txt which contains IP address in the following structure: 192.168.100.77 192.168.100.66 How can I create JSON with Logstash with a similar output: { IP: 192.168.100.77, IP: 192.168.100.66 …

---

## [Day of the week with non UTC timestamps](https://discuss.elastic.co/t/day-of-the-week-with-non-utc-timestamps/291066)

<div class="topic-metadata">

**Author:** [@Malec](https://discuss.elastic.co/u/Malec)\
**Replies:** 1\
**Last updated:** [December 6, 2021, 5:51pm UTC](https://discuss.elastic.co/t/day-of-the-week-with-non-utc-timestamps/291066 "2021-12-06T17:51:46Z")

</div>

Hi everyone, I have logs in a dd/MM/YYYY HH:mm:ss format using the CET timezone, and I am trying to extract the Day of the week for CET and not UTC. We used this at first date { match =\> \[ "date", "dd/MM/YYYY HH:mm:…

---

## [How to parse timestamp windows event log](https://discuss.elastic.co/t/how-to-parse-timestamp-windows-event-log/291043)

<div class="topic-metadata">

**Author:** [@Roccof97](https://discuss.elastic.co/u/Roccof97)\
**Replies:** 3\
**Last updated:** [December 6, 2021, 2:07pm UTC](https://discuss.elastic.co/t/how-to-parse-timestamp-windows-event-log/291043 "2021-12-06T14:07:23Z")

</div>

Hello to all, I have a problem with parsing this field(event.created) with the timestamp, here is the screen: this is the filter I created: thanks

---

## [Logstash output plugin for azure eventhub](https://discuss.elastic.co/t/logstash-output-plugin-for-azure-eventhub/291035)

<div class="topic-metadata">

**Author:** [@Mye1988](https://discuss.elastic.co/u/Mye1988)\
**Replies:** 0\
**Last updated:** [December 6, 2021, 11:59am UTC](https://discuss.elastic.co/t/logstash-output-plugin-for-azure-eventhub/291035 "2021-12-06T11:59:12Z")

</div>

Hello Everyone, I need to use logstash for sending data to Azure Event Hub.As much as I found, there is only an input plugin for reading data from Azure Hub. Is there a logstash output plugin for sending data to Azure …

---

## [How to remove fields with - values in logstash filter?](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 4\
**Last updated:** [December 6, 2021, 9:58am UTC](https://discuss.elastic.co/t/how-to-remove-fields-with-values-in-logstash-filter/290879 "2021-12-06T09:58:35Z")

</div>

I have a patterns like : 2021-10-15 20:00:13 2396 tstur1 /ftp/workspace/ this is message 2020-10-15 18:00:13 - - this is the second message The fields are Date, Time, SessionId, path and message. The grok pattern use…

---

## [Try to Parsing Postfix Log Using Logstash](https://discuss.elastic.co/t/try-to-parsing-postfix-log-using-logstash/288397)

<div class="topic-metadata">

**Author:** [@RichYaNa](https://discuss.elastic.co/u/RichYaNa)\
**Replies:** 6\
**Last updated:** [December 6, 2021, 9:48am UTC](https://discuss.elastic.co/t/try-to-parsing-postfix-log-using-logstash/288397 "2021-12-06T09:48:12Z")

</div>

Hi, I'm currently parsing postfix logs using Logstash, you can check my config file here. and here is a sample log that I will parse: Nov 4 08:51:20 mail /postfix-script\[XPIDX\]: the Postfix mail system is running: PI…

---

## [Logstash upgrade crashing (6.4.2--\> 6.8.20)](https://discuss.elastic.co/t/logstash-upgrade-crashing-6-4-2-6-8-20/290360)

<div class="topic-metadata">

**Author:** [@arunpatchaivy](https://discuss.elastic.co/u/arunpatchaivy)\
**Replies:** 1\
**Last updated:** [December 6, 2021, 5:30am UTC](https://discuss.elastic.co/t/logstash-upgrade-crashing-6-4-2-6-8-20/290360 "2021-12-06T05:30:48Z")

</div>

we are trying to upgrade logstash to new version we doing 2 step upgrade 6.4.2 --\> 6.8.2 --\> 7.15.2 we have downloaded rpm based installer and performed upgrade. Currently we are stuck at logstash version 6.8.2 . we are…

---

## [Logstash cannot Index Log Files into Elasticsearch](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408)

<div class="topic-metadata">

**Author:** [@Amol](https://discuss.elastic.co/u/Amol)\
**Replies:** 3\
**Last updated:** [December 5, 2021, 12:20pm UTC](https://discuss.elastic.co/t/logstash-cannot-index-log-files-into-elasticsearch/290408 "2021-12-05T12:20:06Z")

</div>

Could anyone please help, as i have a logstash config file which need to pick log file when it is updated with new logs. once logstash is started it is working fine, but next day the log file is updated but the data is n…

---

## [How to add country name field based on mobile number using Mobile\_Number using logstash](https://discuss.elastic.co/t/how-to-add-country-name-field-based-on-mobile-number-using-mobile-number-using-logstash/289588)

<div class="topic-metadata">

**Author:** [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)\
**Replies:** 2\
**Last updated:** [December 4, 2021, 3:08pm UTC](https://discuss.elastic.co/t/how-to-add-country-name-field-based-on-mobile-number-using-mobile-number-using-logstash/289588 "2021-12-04T15:08:51Z")

</div>

Hi, I am having logs in txt file contains fields below. I want to extract country code from mobile number and create (translate) into new field called country. I checked with translate filter but not getting how to ext…

---

## [Logstash bytes plugin behaving weirdly](https://discuss.elastic.co/t/logstash-bytes-plugin-behaving-weirdly/290947)

<div class="topic-metadata">

**Author:** [@tkauffmann](https://discuss.elastic.co/u/tkauffmann)\
**Replies:** 0\
**Last updated:** [December 4, 2021, 9:39am UTC](https://discuss.elastic.co/t/logstash-bytes-plugin-behaving-weirdly/290947 "2021-12-04T09:39:44Z")

</div>

Hi, I am trying to use the "Bytes" plugin (Bytes filter plugin | Logstash Reference \[8.0\] | Elastic) to transform fields in the form "1 GB" to their bytes value. I use the following syntax : bytes { sour…

---

## [Push logstash aggregate map as fields in final event](https://discuss.elastic.co/t/push-logstash-aggregate-map-as-fields-in-final-event/290929)

<div class="topic-metadata">

**Author:** [@Joe\_Martin](https://discuss.elastic.co/u/Joe_Martin)\
**Replies:** 3\
**Last updated:** [December 3, 2021, 8:39pm UTC](https://discuss.elastic.co/t/push-logstash-aggregate-map-as-fields-in-final-event/290929 "2021-12-03T20:39:54Z")

</div>

I am trying to use an aggregate filter to pull fields from several different but related logs into one "summary" log. There is a clear end\_of\_task event and I would like to "push"/add all of the fields in the map into t…

---

## [Suggested pipline for rsyslog](https://discuss.elastic.co/t/suggested-pipline-for-rsyslog/290919)

<div class="topic-metadata">

**Author:** [@aqwserf](https://discuss.elastic.co/u/aqwserf)\
**Replies:** 0\
**Last updated:** [December 3, 2021, 5:03pm UTC](https://discuss.elastic.co/t/suggested-pipline-for-rsyslog/290919 "2021-12-03T17:03:40Z")

</div>

Hi everyone ! Quite new user to the ELK stack, and after reading a lot of docs/threads, I'd like some suggestions about my current situation. I have a couple of SOHO router running Openwrt, a Proxmox server and a VPS. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=175)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=177)
