# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=18

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 19

---

## [OpenShift deploy Logstash display Association backend for elasticsearch is not configured](https://discuss.elastic.co/t/openshift-deploy-logstash-display-association-backend-for-elasticsearch-is-not-configured/360380)

<div class="topic-metadata">

**Author:** [@kyocoolcool](https://discuss.elastic.co/u/kyocoolcool)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 11:44am UTC](https://discuss.elastic.co/t/openshift-deploy-logstash-display-association-backend-for-elasticsearch-is-not-configured/360380 "2024-10-16T11:44:05Z")

</div>

display Association backend for elasticsearch is not configured Elasticsearch and kibana have been deployed, I've been looking for a long time and I don't know which side of the configuration is wrong. Could you…

---

## [Problem to store syslog](https://discuss.elastic.co/t/problem-to-store-syslog/368678)

<div class="topic-metadata">

**Author:** [@mmurgas](https://discuss.elastic.co/u/mmurgas)\
**Replies:** 1\
**Last updated:** [October 16, 2024, 11:34am UTC](https://discuss.elastic.co/t/problem-to-store-syslog/368678 "2024-10-16T11:34:44Z")

</div>

Hi, I am facing problem with processing of rsyslog messages by logstash. The goal is to receive syslogs from various devices, perform some filtration on base of Ip address/tags and so on and then send to different outpu…

---

## [Logstash(8.15 version, running in local) not able to connect to elastic search(running in local-8.15version)](https://discuss.elastic.co/t/logstash-8-15-version-running-in-local-not-able-to-connect-to-elastic-search-running-in-local-8-15version/368736)

<div class="topic-metadata">

**Author:** [@pranchalm](https://discuss.elastic.co/u/pranchalm)\
**Replies:** 17\
**Last updated:** [October 15, 2024, 8:20pm UTC](https://discuss.elastic.co/t/logstash-8-15-version-running-in-local-not-able-to-connect-to-elastic-search-running-in-local-8-15version/368736 "2024-10-15T20:20:46Z")

</div>

I am running logstash in local and Elasticsearch too, trying to run an alreay configured pipeline on Elasticsearch, but when i m running my logstash.bat file it starts to read the pipelines.yml but the expectancy is that…

---

## [Import as nested type](https://discuss.elastic.co/t/import-as-nested-type/368733)

<div class="topic-metadata">

**Author:** [@os17](https://discuss.elastic.co/u/os17)\
**Replies:** 1\
**Last updated:** [October 15, 2024, 3:04pm UTC](https://discuss.elastic.co/t/import-as-nested-type/368733 "2024-10-15T15:04:35Z")

</div>

Hello, I'm trying to import parent-child data. Here is my config file: input{ jdbc{ jdbc\_driver\_library =\> "/usr/library/postgresql-42.7.4.jar" jdbc\_connection\_string =\> "jdbc:postgresql://185.\*\*.\*…

---

## [Logstash JSON codec fails to parse special characters](https://discuss.elastic.co/t/logstash-json-codec-fails-to-parse-special-characters/368811)

<div class="topic-metadata">

**Author:** [@rookuu](https://discuss.elastic.co/u/rookuu)\
**Replies:** 0\
**Last updated:** [October 14, 2024, 10:52pm UTC](https://discuss.elastic.co/t/logstash-json-codec-fails-to-parse-special-characters/368811 "2024-10-14T22:52:53Z")

</div>

Not sure if I'm missing something here... I'm loading JSON into logstash using the Kafka input plugin with the JSON codec. I'm getting errors only when my input includes unicode characters (like ≤). JSON parse error, …

---

## [How to get percentile value of number field by using logstash pipeline](https://discuss.elastic.co/t/how-to-get-percentile-value-of-number-field-by-using-logstash-pipeline/368582)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 4\
**Last updated:** [October 14, 2024, 1:17pm UTC](https://discuss.elastic.co/t/how-to-get-percentile-value-of-number-field-by-using-logstash-pipeline/368582 "2024-10-14T13:17:02Z")

</div>

Hi Team, I am trying to get percentile value of number field from Elasticsearch by using logstash pipeline filter . Could you please help me how to get percentile value of number field from logsatsh pipeline.

---

## [Join two indices (many-to-many relationships)](https://discuss.elastic.co/t/join-two-indices-many-to-many-relationships/363867)

<div class="topic-metadata">

**Author:** [@bianca\_s](https://discuss.elastic.co/u/bianca_s)\
**Replies:** 2\
**Last updated:** [October 14, 2024, 7:48am UTC](https://discuss.elastic.co/t/join-two-indices-many-to-many-relationships/363867 "2024-10-14T07:48:23Z")

</div>

Hi all, we have the following use case: We want to create an index that holds the relationships of producer - topic - consumer. Basically all relationships here are many-to-many: Multiple producers can write to the s…

---

## [Logstash pipeline creation is behaving differently for different outputs](https://discuss.elastic.co/t/logstash-pipeline-creation-is-behaving-differently-for-different-outputs/368351)

<div class="topic-metadata">

**Author:** [@sasikiranvaddi](https://discuss.elastic.co/u/sasikiranvaddi)\
**Replies:** 3\
**Last updated:** [October 14, 2024, 7:19am UTC](https://discuss.elastic.co/t/logstash-pipeline-creation-is-behaving-differently-for-different-outputs/368351 "2024-10-14T07:19:46Z")

</div>

We have two deployments where lumberjack is configured as output for one of the deployment and syslog is configured as output for another deployment. In both the deployments the outputs are down when Logstash is initiat…

---

## [Keep getting \_jsonparsefailures](https://discuss.elastic.co/t/keep-getting-jsonparsefailures/367005)

<div class="topic-metadata">

**Author:** [@Mike\_Reprogle](https://discuss.elastic.co/u/Mike_Reprogle)\
**Replies:** 3\
**Last updated:** [October 11, 2024, 2:28pm UTC](https://discuss.elastic.co/t/keep-getting-jsonparsefailures/367005 "2024-10-11T14:28:49Z")

</div>

I am still relatively new to logstash, so I have been trying to run through a bit of a crash course in using it and getting logs to filter correctly. I finally have logs hitting like they should, but I cannot for the lif…

---

## [Trying to Stop an already running logstash pipeline via DELETE Api, getting 404 not found](https://discuss.elastic.co/t/trying-to-stop-an-already-running-logstash-pipeline-via-delete-api-getting-404-not-found/368641)

<div class="topic-metadata">

**Author:** [@pranchalm](https://discuss.elastic.co/u/pranchalm)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 8:39pm UTC](https://discuss.elastic.co/t/trying-to-stop-an-already-running-logstash-pipeline-via-delete-api-getting-404-not-found/368641 "2024-10-10T20:39:31Z")

</div>

http://localhost:9600/\_node/pipelines/test123 this works and gives back the details of the running pipeline test123, but when trying to DELETE it using this same endpoint with a DELETE http method, it gives 404 not found…

---

## ["PKIX path validation failed: java.security.cert.CertPathValidatorException: validity check failed"](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360)

<div class="topic-metadata">

**Author:** [@apal](https://discuss.elastic.co/u/apal)\
**Replies:** 4\
**Last updated:** [October 10, 2024, 8:10pm UTC](https://discuss.elastic.co/t/pkix-path-validation-failed-java-security-cert-certpathvalidatorexception-validity-check-failed/368360 "2024-10-10T20:10:57Z")

</div>

Here's the full error: Oct 07 11:57:38 elk.example.com logstash\[3697608\]: \[2024-10-07T11:57:38,571\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Attempted to resurrect connection to dead ES instance, but got an error {:…

---

## [Error in logstash-plain-logs in /applog/logstash](https://discuss.elastic.co/t/error-in-logstash-plain-logs-in-applog-logstash/368260)

<div class="topic-metadata">

**Author:** [@rohit\_dhiman](https://discuss.elastic.co/u/rohit_dhiman)\
**Replies:** 2\
**Last updated:** [October 10, 2024, 11:30am UTC](https://discuss.elastic.co/t/error-in-logstash-plain-logs-in-applog-logstash/368260 "2024-10-10T11:30:17Z")

</div>

Hello All, We are getting below error in the logstash-plain-logs in /applog/logstash Below are the complete logs. \[logstash.outputs.opensearch\] \[main\] \[2cd0b680af9b49acc4d5ae414a3665aabb9aa76a58d0430b62230cc5c2e971bc\]…

---

## [Need help reducing the volume of data](https://discuss.elastic.co/t/need-help-reducing-the-volume-of-data/368488)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [October 10, 2024, 11:09am UTC](https://discuss.elastic.co/t/need-help-reducing-the-volume-of-data/368488 "2024-10-10T11:09:22Z")

</div>

Hi there! I am trying to reduce the volume of my data in metrics monitoring. Currently, I filter out fields using Logstash and retain only the fields that I need for my dashboards. I have 7 servers, and each server gen…

---

## [Trying to Stop Logstash(version-8.15) process via its API call, not able to stop it via http://localhost:9600/\_node/shutdown, it results in 404 not found but call to \_node/stats works](https://discuss.elastic.co/t/trying-to-stop-logstash-version-8-15-process-via-its-api-call-not-able-to-stop-it-via-http-localhost-9600-node-shutdown-it-results-in-404-not-found-but-call-to-node-stats-works/368571)

<div class="topic-metadata">

**Author:** [@pranchalm](https://discuss.elastic.co/u/pranchalm)\
**Replies:** 2\
**Last updated:** [October 10, 2024, 10:16am UTC](https://discuss.elastic.co/t/trying-to-stop-logstash-version-8-15-process-via-its-api-call-not-able-to-stop-it-via-http-localhost-9600-node-shutdown-it-results-in-404-not-found-but-call-to-node-stats-works/368571 "2024-10-10T10:16:55Z")

</div>

I have written a spring boot application which starts the Logstash process internally by forming a command to get the conf file and trigger the command, similarly when i am trying to stop it via my application code the s…

---

## [Logstash compressed data](https://discuss.elastic.co/t/logstash-compressed-data/368614)

<div class="topic-metadata">

**Author:** [@pradeep-logstashuser](https://discuss.elastic.co/u/pradeep-logstashuser)\
**Replies:** 0\
**Last updated:** [October 10, 2024, 9:36am UTC](https://discuss.elastic.co/t/logstash-compressed-data/368614 "2024-10-10T09:36:45Z")

</div>

Hi Sir, I have used the HTTP input plugin and the OpenSearch output plugin. I am receiving compressed data from the app to the HTTP input. Can I send the compressed data directly to OpenSearch, or should I handle decomp…

---

## [Logstash not getting complete msg from filebeats, might be due to length](https://discuss.elastic.co/t/logstash-not-getting-complete-msg-from-filebeats-might-be-due-to-length/368552)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 5:55pm UTC](https://discuss.elastic.co/t/logstash-not-getting-complete-msg-from-filebeats-might-be-due-to-length/368552 "2024-10-09T17:55:43Z")

</div>

Hello, Below is the multiline log msg coming into logstash\[Not able to post the whole log here also due to max char issue\], but some lines are missing in Msg field, pls let me know the issue for fix \[2024-10-09T07:04:4…

---

## [Logstash config advise](https://discuss.elastic.co/t/logstash-config-advise/368415)

<div class="topic-metadata">

**Author:** [@Athen](https://discuss.elastic.co/u/Athen)\
**Replies:** 22\
**Last updated:** [October 9, 2024, 5:48pm UTC](https://discuss.elastic.co/t/logstash-config-advise/368415 "2024-10-09T17:48:10Z")

</div>

Hi Team, I'm new to ELK and have deployed the ELK stack (Elasticsearch, Logstash, and Kibana) in Kubernetes and exposed Logstash via a Traefik ingress route to allow external servers to send logs. However, I am encounte…

---

## [Splitting a field that looks like an array](https://discuss.elastic.co/t/splitting-a-field-that-looks-like-an-array/368540)

<div class="topic-metadata">

**Author:** [@cdy5159](https://discuss.elastic.co/u/cdy5159)\
**Replies:** 7\
**Last updated:** [October 9, 2024, 4:45pm UTC](https://discuss.elastic.co/t/splitting-a-field-that-looks-like-an-array/368540 "2024-10-09T16:45:30Z")

</div>

I'm getting audit data from my linux hosts that will sometimes repeat a field name, so I get what looks like an array of data in that field. I've tried various forms of 'split' to see if I can separate the data into two…

---

## [Dynamically create fields from another field with json input file](https://discuss.elastic.co/t/dynamically-create-fields-from-another-field-with-json-input-file/368508)

<div class="topic-metadata">

**Author:** [@remich](https://discuss.elastic.co/u/remich)\
**Replies:** 8\
**Last updated:** [October 9, 2024, 4:11pm UTC](https://discuss.elastic.co/t/dynamically-create-fields-from-another-field-with-json-input-file/368508 "2024-10-09T16:11:58Z")

</div>

Hi, I have json input that contains appname with their version and other field with standard string like : { "app1": "1.2.3", "app2": "3.2.1", "arch": "virtual" } I would like to be able to use filter versions i…

---

## [Umbrella S3 logs weird format when using CSV filter](https://discuss.elastic.co/t/umbrella-s3-logs-weird-format-when-using-csv-filter/368502)

<div class="topic-metadata">

**Author:** [@danielpaiva](https://discuss.elastic.co/u/danielpaiva)\
**Replies:** 0\
**Last updated:** [October 9, 2024, 7:39am UTC](https://discuss.elastic.co/t/umbrella-s3-logs-weird-format-when-using-csv-filter/368502 "2024-10-09T07:39:07Z")

</div>

Hello ! I'm currently working on pulling Cisco Umbrella logs from S3 buckets with Logstash and s3 input and I'm dealing with a weird behavior. When using only the s3 input and sending the logs to Elastic, it works like…

---

## [Logstash not parsing eventhub logs](https://discuss.elastic.co/t/logstash-not-parsing-eventhub-logs/366816)

<div class="topic-metadata">

**Author:** [@vaibhavu](https://discuss.elastic.co/u/vaibhavu)\
**Replies:** 10\
**Last updated:** [October 9, 2024, 6:16am UTC](https://discuss.elastic.co/t/logstash-not-parsing-eventhub-logs/366816 "2024-10-09T06:16:59Z")

</div>

Hi Everyone , I am working on parsing the logs from Azure eventhub to Elasticsearch and trying to use logstash filter for this but getting \_jsonparsing error for the logs. the logs structure is someting like below: {"…

---

## [How to retain the time zone and nanoseconds in timestamp when migrating es through logstash](https://discuss.elastic.co/t/how-to-retain-the-time-zone-and-nanoseconds-in-timestamp-when-migrating-es-through-logstash/368002)

<div class="topic-metadata">

**Author:** [@baobaoda](https://discuss.elastic.co/u/baobaoda)\
**Replies:** 3\
**Last updated:** [October 8, 2024, 9:52am UTC](https://discuss.elastic.co/t/how-to-retain-the-time-zone-and-nanoseconds-in-timestamp-when-migrating-es-through-logstash/368002 "2024-10-08T09:52:32Z")

</div>

In the old cluster, the timestamp is "@timestamp": "2024-08-12T17:40:31.098422413+08:00". For stability reasons, I still want to keep it after migrating to the new cluster. I have tried many filters like behind, but none…

---

## [OAuth2 Support in Logstash http input plugin](https://discuss.elastic.co/t/oauth2-support-in-logstash-http-input-plugin/368413)

<div class="topic-metadata">

**Author:** [@Marcin\_Miklasz](https://discuss.elastic.co/u/Marcin_Miklasz)\
**Replies:** 0\
**Last updated:** [October 8, 2024, 7:47am UTC](https://discuss.elastic.co/t/oauth2-support-in-logstash-http-input-plugin/368413 "2024-10-08T07:47:38Z")

</div>

As per Logstash reference docs 8.15 and http input \* Plugin version: v3.8.1 only http basic authentication is supported. Please add support for OAuth2 Bearer tokens, otherwise http input plugin is little/no use with any…

---

## [Logstash Pipeline Erro](https://discuss.elastic.co/t/logstash-pipeline-erro/368388)

<div class="topic-metadata">

**Author:** [@vitor\_soprano](https://discuss.elastic.co/u/vitor_soprano)\
**Replies:** 3\
**Last updated:** [October 7, 2024, 11:00pm UTC](https://discuss.elastic.co/t/logstash-pipeline-erro/368388 "2024-10-07T23:00:55Z")

</div>

Hi there, first time trying to use logstash to capture logs from PfSense. This is what im using in the pipeline: input { syslog { port =\> 5514 type =\> "syslog" } } filter { if \[type\] == "sy…

---

## [Logstash-output-mongodb not work](https://discuss.elastic.co/t/logstash-output-mongodb-not-work/368363)

<div class="topic-metadata">

**Author:** [@yi.xin](https://discuss.elastic.co/u/yi.xin)\
**Replies:** 2\
**Last updated:** [October 7, 2024, 6:28pm UTC](https://discuss.elastic.co/t/logstash-output-mongodb-not-work/368363 "2024-10-07T18:28:40Z")

</div>

I'm having trouble with the logstash-output-mongodb plugin; it’s not working at all. I need to know if this plugin is still being maintained. If not, please confirm so I can look for alternatives.

---

## [Unable configure ELK stack on Single Node](https://discuss.elastic.co/t/unable-configure-elk-stack-on-single-node/368329)

<div class="topic-metadata">

**Author:** [@PJ111288](https://discuss.elastic.co/u/PJ111288)\
**Replies:** 1\
**Last updated:** [October 7, 2024, 11:56am UTC](https://discuss.elastic.co/t/unable-configure-elk-stack-on-single-node/368329 "2024-10-07T11:56:06Z")

</div>

Caused by: org.logstash.beats.InvalidFrameProtocolException: Invalid version of beats protocol: 3 -Config : No xpack secuirty enabled cd /etc/logstash/conf.d/ output { elasticsearch { hosts =\> \["localhost:9200"\] s…

---

## [Logstash Json Data processing issue](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 6\
**Last updated:** [October 7, 2024, 10:55am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309 "2024-10-07T10:55:01Z")

</div>

Hi ELK Community, I need your help with an issue I'm encountering. In my JSON data processing pipeline, some fields are coming in two formats: as an array and as a keyword. When I set the mapping for "field\_name" as a…

---

## [Warning: already initialized constant Manticore::Client::HttpPost](https://discuss.elastic.co/t/warning-already-initialized-constant-manticore-httppost/368327)

<div class="topic-metadata">

**Author:** [@Jone132231](https://discuss.elastic.co/u/Jone132231)\
**Replies:** 0\
**Last updated:** [October 7, 2024, 7:31am UTC](https://discuss.elastic.co/t/warning-already-initialized-constant-manticore-httppost/368327 "2024-10-07T07:31:46Z")

</div>

its shows this Issue When I Try to Upload index its show this : I clear the cash and still not fixed client.rb:284: warning: already initialized constant Manticore::Client::HttpPost client.rb:284: warning: already in…

---

## [How to use ingest pipelines with logstash](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-with-logstash/368281)

<div class="topic-metadata">

**Author:** [@Magnificeent](https://discuss.elastic.co/u/Magnificeent)\
**Replies:** 1\
**Last updated:** [October 5, 2024, 2:58pm UTC](https://discuss.elastic.co/t/how-to-use-ingest-pipelines-with-logstash/368281 "2024-10-05T14:58:52Z")

</div>

I want to use the Apache access ingest pipeline with Filebeat and with Logstash (not directly to Elasticsearch). When I put direct output to Elasticsearch in the filebeat file (filebeat.yml) everything is fine, I can se…

---

## [Load json text in oracle table to elastic search via logstash](https://discuss.elastic.co/t/load-json-text-in-oracle-table-to-elastic-search-via-logstash/367208)

<div class="topic-metadata">

**Author:** [@karthikeyanc2003](https://discuss.elastic.co/u/karthikeyanc2003)\
**Replies:** 7\
**Last updated:** [October 5, 2024, 4:32am UTC](https://discuss.elastic.co/t/load-json-text-in-oracle-table-to-elastic-search-via-logstash/367208 "2024-10-05T04:32:16Z")

</div>

Dear Team, I have data in Oracle table Tbl\_user in the below table format. JSON column has the value in the JSON format. I want to insert this data into the Elastic search index with userid as a document ID via logstas…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=17)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=19)
