# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=185

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 186

---

## [Logstash pipeline stalling without any error](https://discuss.elastic.co/t/logstash-pipeline-stalling-without-any-error/287274)

<div class="topic-metadata">

**Author:** [@Stephy](https://discuss.elastic.co/u/Stephy)\
**Replies:** 8\
**Last updated:** [October 27, 2021, 4:27pm UTC](https://discuss.elastic.co/t/logstash-pipeline-stalling-without-any-error/287274 "2021-10-27T16:27:47Z")

</div>

Hello, We have a Logstash pipeline (using the official elastic.co Docker Image v7.9.3) running with a JDBC input plugin and Elasticsearch output. Pipeline is set to run with a schedule every 1 minute (\* \* \* \* \*). The in…

---

## [No config files found in path {:path=\>"C:/logstash-7.15.1/bin/logstash.conf"}](https://discuss.elastic.co/t/no-config-files-found-in-path-path-c-logstash-7-15-1-bin-logstash-conf/287770)

<div class="topic-metadata">

**Author:** [@lalatenduswain](https://discuss.elastic.co/u/lalatenduswain)\
**Replies:** 2\
**Last updated:** [October 27, 2021, 4:15pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path-path-c-logstash-7-15-1-bin-logstash-conf/287770 "2021-10-27T16:15:35Z")

</div>

\[2021-10-27T11:13:19,509\]\[INFO \]\[logstash.config.source.local.configpathloader\] No config files found in path {:path=\>"C:/logstash-7.15.1/bin/logstash.conf"} \[2021-10-27T11:13:19,521\]\[DEBUG\]\[logstash.api.service \] \[…

---

## [Logstash to Splunk](https://discuss.elastic.co/t/logstash-to-splunk/287825)

<div class="topic-metadata">

**Author:** [@pbernard](https://discuss.elastic.co/u/pbernard)\
**Replies:** 0\
**Last updated:** [October 27, 2021, 4:10pm UTC](https://discuss.elastic.co/t/logstash-to-splunk/287825 "2021-10-27T16:10:06Z")

</div>

I'm seeing the following error when using "output http" plugin with Logstash V 7.9.1 \[ERROR\]\[logstash.outputs.http \]\[main\]\[fd6763aa601b7a0319bbdad4f501b0901a4f4da752d9fcbf8f841e9fbf9e676c\] \[HTTP Output Failure\] Could…

---

## [How to target City Name as GEOIP Location?](https://discuss.elastic.co/t/how-to-target-city-name-as-geoip-location/287752)

<div class="topic-metadata">

**Author:** [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Replies:** 1\
**Last updated:** [October 27, 2021, 4:09pm UTC](https://discuss.elastic.co/t/how-to-target-city-name-as-geoip-location/287752 "2021-10-27T16:09:51Z")

</div>

I have a city name field and I want to visualize it on the map. I am wondering How I can achieve this because the GEOIP filter takes IP but I don't have an IP address. geoip{ source =\> "\[NotifyEventAdvanceRequestMo…

---

## [Need help to create loglevel field](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665)

<div class="topic-metadata">

**Author:** [@sushant12](https://discuss.elastic.co/u/sushant12)\
**Replies:** 3\
**Last updated:** [October 27, 2021, 2:51pm UTC](https://discuss.elastic.co/t/need-help-to-create-loglevel-field/287665 "2021-10-27T14:51:35Z")

</div>

filter{ if "ERROR" in \[LEVEl\]{ grok{ match =\> {· "message" =\> "%{TIME:timestamp} %{LOGLEVEL:LEVEL} %{GREEDYDATA:errormsg}"· } } } if "DEBUG" in \[LEVEl\]{ grok{····· match =\>…

---

## [SNMP timeout when run from a docker container](https://discuss.elastic.co/t/snmp-timeout-when-run-from-a-docker-container/287805)

<div class="topic-metadata">

**Author:** [@davegreen](https://discuss.elastic.co/u/davegreen)\
**Replies:** 2\
**Last updated:** [October 27, 2021, 2:06pm UTC](https://discuss.elastic.co/t/snmp-timeout-when-run-from-a-docker-container/287805 "2021-10-27T14:06:58Z")

</div>

I'm using Logstash 7.15.1 on both Centos 7.7 and a docker container with the same configuration (below). When running from Centos, everything works as expected, but on a docker container (in Kubernetes), the SNMP plugin…

---

## [Attempted to send a bulk request to Elasticsearch failed ClientProtocolException](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720)

<div class="topic-metadata">

**Author:** [@makinda](https://discuss.elastic.co/u/makinda)\
**Replies:** 3\
**Last updated:** [October 27, 2021, 1:43pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-failed-clientprotocolexception/287720 "2021-10-27T13:43:05Z")

</div>

I am using Elasticsearch-2.3.1 and logstash-2.3.4 since quite long. Today I found a following warning in Elastic Search. I was trying to copy the logs but I think I press Ctrl+C and then an option appear to stop a job, I…

---

## [Suricata logs logstash filter](https://discuss.elastic.co/t/suricata-logs-logstash-filter/287779)

<div class="topic-metadata">

**Author:** [@algira37](https://discuss.elastic.co/u/algira37)\
**Replies:** 0\
**Last updated:** [October 27, 2021, 9:29am UTC](https://discuss.elastic.co/t/suricata-logs-logstash-filter/287779 "2021-10-27T09:29:55Z")

</div>

Hello guys, Filbeat shipping eve.json to logstash and logstash dynamically maps fields and sends to Elasticsearch. Unfortunately, these logs are too much, lots of useless information for my project so I would like to c…

---

## [Elasticsearch output pipeline error with api\_key](https://discuss.elastic.co/t/elasticsearch-output-pipeline-error-with-api-key/287618)

<div class="topic-metadata">

**Author:** [@Wonder\_Garance](https://discuss.elastic.co/u/Wonder_Garance)\
**Replies:** 3\
**Last updated:** [October 27, 2021, 8:49am UTC](https://discuss.elastic.co/t/elasticsearch-output-pipeline-error-with-api-key/287618 "2021-10-27T08:49:09Z")

</div>

Hello, I created a Logstash config to send files on index of Elasticsearch 7.15.1, on the same server. I got this error \[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<Mant…

---

## [How to add a timestamp from the previous line to the current line](https://discuss.elastic.co/t/how-to-add-a-timestamp-from-the-previous-line-to-the-current-line/287600)

<div class="topic-metadata">

**Author:** [@anoopahamad](https://discuss.elastic.co/u/anoopahamad)\
**Replies:** 6\
**Last updated:** [October 27, 2021, 5:18am UTC](https://discuss.elastic.co/t/how-to-add-a-timestamp-from-the-previous-line-to-the-current-line/287600 "2021-10-27T05:18:32Z")

</div>

In my log file, some of the lines don't have a timestamp. I want to assign the previous line's timestamp to the lines that don't have the timestamp. I tried "memorize" but that's giving some errors. Is there a way we…

---

## [Tomcat logs are seeing appearing in order in discover section in kibana](https://discuss.elastic.co/t/tomcat-logs-are-seeing-appearing-in-order-in-discover-section-in-kibana/286969)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 31\
**Last updated:** [October 26, 2021, 10:03pm UTC](https://discuss.elastic.co/t/tomcat-logs-are-seeing-appearing-in-order-in-discover-section-in-kibana/286969 "2021-10-26T22:03:55Z")

</div>

Hi Team, I have tomcat application running on two servers and sending logs to logstash through filebeat, when checking logs in discover section of kibana, I am not seeing exact sequence of logs in kibana as in server. f…

---

## [Handle event if http output finally fails](https://discuss.elastic.co/t/handle-event-if-http-output-finally-fails/287727)

<div class="topic-metadata">

**Author:** [@jporzelt](https://discuss.elastic.co/u/jporzelt)\
**Replies:** 1\
**Last updated:** [October 26, 2021, 9:50pm UTC](https://discuss.elastic.co/t/handle-event-if-http-output-finally-fails/287727 "2021-10-26T21:50:11Z")

</div>

Hi all, we are using Logstash for first time in a project and we are using it to process e-mails (imap input), transform some fields and send the event to an http output (Http output plugin | Logstash Reference \[7.15\] |…

---

## [Output When Data in Field is a Specific Value](https://discuss.elastic.co/t/output-when-data-in-field-is-a-specific-value/287733)

<div class="topic-metadata">

**Author:** [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Replies:** 1\
**Last updated:** [October 26, 2021, 9:43pm UTC](https://discuss.elastic.co/t/output-when-data-in-field-is-a-specific-value/287733 "2021-10-26T21:43:49Z")

</div>

Hi, I want to know only output a field called network.application when it contains the value ALPHA but I am getting an error that Expected one of \[ \\t\\r\\n\], "#", "{" at line 152, column 7 (byte 3941) after output { if…

---

## [Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down!](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-but-elasticsearch-appears-to-be-unreachable-or-down/287640)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 2\
**Last updated:** [October 26, 2021, 4:31pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-but-elasticsearch-appears-to-be-unreachable-or-down/287640 "2021-10-26T16:31:17Z")

</div>

Hi, I have configured logstash conf file to get data from filebeat. Logstash input port 5044 and output to elasticseach as multiple index output. Elasticsearch service is up and running. But logstash can't reach the E…

---

## [Logstash azure blob plugin error](https://discuss.elastic.co/t/logstash-azure-blob-plugin-error/287709)

<div class="topic-metadata">

**Author:** [@RS\_D](https://discuss.elastic.co/u/RS_D)\
**Replies:** 0\
**Last updated:** [October 26, 2021, 3:24pm UTC](https://discuss.elastic.co/t/logstash-azure-blob-plugin-error/287709 "2021-10-26T15:24:52Z")

</div>

I am trying to install "logstash-input-azureblob" plugin with command as below using docker compose. I am getting the below error. command: bash -c "bin/logstash-plugin install logstash-input-azureblob && logstash -f …

---

## [Parse JSON array](https://discuss.elastic.co/t/parse-json-array/287682)

<div class="topic-metadata">

**Author:** [@khouloud](https://discuss.elastic.co/u/khouloud)\
**Replies:** 0\
**Last updated:** [October 26, 2021, 10:50am UTC](https://discuss.elastic.co/t/parse-json-array/287682 "2021-10-26T10:50:04Z")

</div>

Hello, In my log file I have json array, when I parse it with json filtre logstash only the first object display in Elasticsearch. How can I display all the object in Elasticsearch Table ? Thank you.

---

## [Ruby filter to get data for performance alerting](https://discuss.elastic.co/t/ruby-filter-to-get-data-for-performance-alerting/286990)

<div class="topic-metadata">

**Author:** [@Sebastian\_Rodak](https://discuss.elastic.co/u/Sebastian_Rodak)\
**Replies:** 6\
**Last updated:** [October 26, 2021, 10:33am UTC](https://discuss.elastic.co/t/ruby-filter-to-get-data-for-performance-alerting/286990 "2021-10-26T10:33:36Z")

</div>

Hi ! I'm working with json below to configure trigger when "free" will be near to 0, { "@timestamp" =\> 2021-10-13T08:51:00.395Z, "type" =\> "metric", "@version" =\> "1", …

---

## [Creating a map with Latitude and logitude fields - ERROR](https://discuss.elastic.co/t/creating-a-map-with-latitude-and-logitude-fields-error/287633)

<div class="topic-metadata">

**Author:** [@Robson\_Gomes](https://discuss.elastic.co/u/Robson_Gomes)\
**Replies:** 2\
**Last updated:** [October 26, 2021, 3:21am UTC](https://discuss.elastic.co/t/creating-a-map-with-latitude-and-logitude-fields-error/287633 "2021-10-26T03:21:13Z")

</div>

I'm trying to create a map with all my latitude and longitude fields but when I try to create a map on Elastic, they don't show nothing, someone could help me? my logstash conf: input { # I sent via http JSON files to…

---

## [Checking client cert subject in Logstash](https://discuss.elastic.co/t/checking-client-cert-subject-in-logstash/287625)

<div class="topic-metadata">

**Author:** [@jceddy](https://discuss.elastic.co/u/jceddy)\
**Replies:** 0\
**Last updated:** [October 25, 2021, 8:49pm UTC](https://discuss.elastic.co/t/checking-client-cert-subject-in-logstash/287625 "2021-10-25T20:49:11Z")

</div>

I have Logstash set up receiving data from Filebeat on external servers, with SSL mutual authentication. I would like to add one more layer and only allow through when Filebeat's client certificate subject matches a str…

---

## [How to extract data from multiline(codec)](https://discuss.elastic.co/t/how-to-extract-data-from-multiline-codec/287575)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [October 25, 2021, 7:34pm UTC](https://discuss.elastic.co/t/how-to-extract-data-from-multiline-codec/287575 "2021-10-25T19:34:26Z")

</div>

Hi Does anyone know how to extract data from under the codec multiline. After parse xml data I need to avoid the header (prefix of name measData ) for whole of ingested rows... it makes also some keyword field and mul…

---

## [What is the grok expression that can match variable length documents from a single log file?](https://discuss.elastic.co/t/what-is-the-grok-expression-that-can-match-variable-length-documents-from-a-single-log-file/285320)

<div class="topic-metadata">

**Author:** [@shi](https://discuss.elastic.co/u/shi)\
**Replies:** 1\
**Last updated:** [October 25, 2021, 7:32pm UTC](https://discuss.elastic.co/t/what-is-the-grok-expression-that-can-match-variable-length-documents-from-a-single-log-file/285320 "2021-10-25T19:32:41Z")

</div>

A log file is having records of different leighths, say 3 different types of records? what is the grok expression that can match variable length documents from a single log file? This will be very useful for creating i…

---

## [Installation aborted, plugin 'logstash-input-jdbc' is already provided by 'logstash-integration-jdbc'](https://discuss.elastic.co/t/installation-aborted-plugin-logstash-input-jdbc-is-already-provided-by-logstash-integration-jdbc/287562)

<div class="topic-metadata">

**Author:** [@Kumar\_Reddy](https://discuss.elastic.co/u/Kumar_Reddy)\
**Replies:** 4\
**Last updated:** [October 25, 2021, 6:17pm UTC](https://discuss.elastic.co/t/installation-aborted-plugin-logstash-input-jdbc-is-already-provided-by-logstash-integration-jdbc/287562 "2021-10-25T18:17:45Z")

</div>

I am facing this issue when i try to run command from docker-compose.yml file. version: '3.7' services: Elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:7.15.1 ports: - '9200:9200' environment: …

---

## [Authentication issue between kafka(OpenShift Operator deployed) and Logstash](https://discuss.elastic.co/t/authentication-issue-between-kafka-openshift-operator-deployed-and-logstash/287614)

<div class="topic-metadata">

**Author:** [@karanjit.rai](https://discuss.elastic.co/u/karanjit.rai)\
**Replies:** 0\
**Last updated:** [October 25, 2021, 6:02pm UTC](https://discuss.elastic.co/t/authentication-issue-between-kafka-openshift-operator-deployed-and-logstash/287614 "2021-10-25T18:02:47Z")

</div>

Hello, I have installed Kafka through the OpenShift operator and now I am trying to connect it to Logstash (running in a OpenShift cluster). I do not see anyway to connect through authentication between the two or where…

---

## [Logstash JDBC output](https://discuss.elastic.co/t/logstash-jdbc-output/287605)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [October 25, 2021, 5:44pm UTC](https://discuss.elastic.co/t/logstash-jdbc-output/287605 "2021-10-25T17:44:32Z")

</div>

Do we have the JDBC output plugin in logstash to write to the database?

---

## [Logstash exits after successfully installing plugin with docker-compose exited with code 0](https://discuss.elastic.co/t/logstash-exits-after-successfully-installing-plugin-with-docker-compose-exited-with-code-0/287607)

<div class="topic-metadata">

**Author:** [@Kumar\_Reddy](https://discuss.elastic.co/u/Kumar_Reddy)\
**Replies:** 0\
**Last updated:** [October 25, 2021, 4:43pm UTC](https://discuss.elastic.co/t/logstash-exits-after-successfully-installing-plugin-with-docker-compose-exited-with-code-0/287607 "2021-10-25T16:43:43Z")

</div>

I am trying to run an Elastic stack and I am trying to install a logstash plugin within the docker compose file. I am getting the message that the plugin is installed successful and right after that the container exits w…

---

## [Stack trace parsing issue](https://discuss.elastic.co/t/stack-trace-parsing-issue/287573)

<div class="topic-metadata">

**Author:** [@Divya\_Bansal](https://discuss.elastic.co/u/Divya_Bansal)\
**Replies:** 9\
**Last updated:** [October 25, 2021, 2:15pm UTC](https://discuss.elastic.co/t/stack-trace-parsing-issue/287573 "2021-10-25T14:15:57Z")

</div>

I am having a json data in the following manne:- {"@timestamp":"2021-06-04T09:57:25.141Z","@metadata":{"beat":"filebeat","type":"\_doc","version":"7.6.3"},"log":{"offset":10413931,"file":{"path":""}},"message":"\[ERROR\] 2…

---

## [Logstash file input plugin: missing first lines after log rotation](https://discuss.elastic.co/t/logstash-file-input-plugin-missing-first-lines-after-log-rotation/287112)

<div class="topic-metadata">

**Author:** [@adminunix](https://discuss.elastic.co/u/adminunix)\
**Replies:** 2\
**Last updated:** [October 25, 2021, 1:56pm UTC](https://discuss.elastic.co/t/logstash-file-input-plugin-missing-first-lines-after-log-rotation/287112 "2021-10-25T13:56:26Z")

</div>

Hello, I´m using logstash with a pipeline that collects logs with the file input plugin. Everything works fine, but when log files are rotated, logstash doesn´t collect some of the first few lines of the new log file. T…

---

## [Calculate transaction duration](https://discuss.elastic.co/t/calculate-transaction-duration/287210)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [October 25, 2021, 12:22pm UTC](https://discuss.elastic.co/t/calculate-transaction-duration/287210 "2021-10-25T12:22:51Z")

</div>

Hi I'm struggling with one interesting case: we have some data within some patterns. But we don't have any tags: start or end in these documents. How I can calculate transaction duration? I'm also see great article Ca…

---

## [Suddenly pipeline got stuck with error couldn't find any output plugin named http](https://discuss.elastic.co/t/suddenly-pipeline-got-stuck-with-error-couldnt-find-any-output-plugin-named-http/287376)

<div class="topic-metadata">

**Author:** [@michael.l](https://discuss.elastic.co/u/michael.l)\
**Replies:** 3\
**Last updated:** [October 25, 2021, 11:55am UTC](https://discuss.elastic.co/t/suddenly-pipeline-got-stuck-with-error-couldnt-find-any-output-plugin-named-http/287376 "2021-10-25T11:55:41Z")

</div>

We have a simple pipeline that has been running fine for weeks without any errors, and then suddenly stopped outputting events while repeatedly printing this error: {"level":"ERROR","loggerName":"logstash.agent","timeMi…

---

## [Logstash Error](https://discuss.elastic.co/t/logstash-error/287404)

<div class="topic-metadata">

**Author:** [@Mudit\_Tripathi](https://discuss.elastic.co/u/Mudit_Tripathi)\
**Replies:** 5\
**Last updated:** [October 25, 2021, 9:22am UTC](https://discuss.elastic.co/t/logstash-error/287404 "2021-10-25T09:22:27Z")

</div>

Hi Guys, I have created a sample csv file with 3 columns and I am using to log the csv file into Elasticsearch using logstash. This is my logstash.conf input { file { path =\> "/Users/mudit.tripathi/Downloads/samplel…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=184)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=186)
