# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=19

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 20

---

## [How to send 75 percentile of one field(duration) value to kafka servers](https://discuss.elastic.co/t/how-to-send-75-percentile-of-one-field-duration-value-to-kafka-servers/368235)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 0\
**Last updated:** [October 4, 2024, 6:31am UTC](https://discuss.elastic.co/t/how-to-send-75-percentile-of-one-field-duration-value-to-kafka-servers/368235 "2024-10-04T06:31:14Z")

</div>

Hi, I am trying to send 75 percentile of "duration" field(type is number) value to kafka servers by using logstash pipeline. But i did not get idea how to write aggregate filter in logstash. Could you please help me how…

---

## [No cipher suites in common](https://discuss.elastic.co/t/no-cipher-suites-in-common/368108)

<div class="topic-metadata">

**Author:** [@Mahesh\_Kumar\_S](https://discuss.elastic.co/u/Mahesh_Kumar_S)\
**Replies:** 3\
**Last updated:** [October 4, 2024, 2:48am UTC](https://discuss.elastic.co/t/no-cipher-suites-in-common/368108 "2024-10-04T02:48:25Z")

</div>

Hello Elastic Community, I am facing an issue after configuring custom cipher suites for the TCP input plugin in Logstash. Below is my configuration: tcp{ port =\> 6515 type =\> syslog dns\_reverse\_lookup\_ena…

---

## [Translate filter with yml file](https://discuss.elastic.co/t/translate-filter-with-yml-file/367264)

<div class="topic-metadata">

**Author:** [@Honestabe](https://discuss.elastic.co/u/Honestabe)\
**Replies:** 17\
**Last updated:** [September 30, 2024, 11:28pm UTC](https://discuss.elastic.co/t/translate-filter-with-yml-file/367264 "2024-09-30T23:28:36Z")

</div>

I made trying to use translate filter with a yml file to add geo\_point this is the yml file configuration JP.558-0045:\[135.4949, 34.6134\] \` yet when I run the pipeline with this config translate { field =\> …

---

## [Logbeat error when sending data to logstash service in AKS cluster](https://discuss.elastic.co/t/logbeat-error-when-sending-data-to-logstash-service-in-aks-cluster/368206)

<div class="topic-metadata">

**Author:** [@sajid.ali](https://discuss.elastic.co/u/sajid.ali)\
**Replies:** 0\
**Last updated:** [October 3, 2024, 3:45pm UTC](https://discuss.elastic.co/t/logbeat-error-when-sending-data-to-logstash-service-in-aks-cluster/368206 "2024-10-03T15:45:42Z")

</div>

I have setup a logstash service in AKS cluster. The service has a external IP address with port 443. I am sending logs from windows machine using filebeat. It works when i am running filebeat on my local machine. I can s…

---

## [SNMP input, table index becomes separated](https://discuss.elastic.co/t/snmp-input-table-index-becomes-separated/368081)

<div class="topic-metadata">

**Author:** [@Billiam](https://discuss.elastic.co/u/Billiam)\
**Replies:** 1\
**Last updated:** [October 3, 2024, 9:00am UTC](https://discuss.elastic.co/t/snmp-input-table-index-becomes-separated/368081 "2024-10-03T09:00:19Z")

</div>

I've got the SNMP input configured to poll a number of Cisco devices pulling back interfaces stats from the following OIDs: "1.3.6.1.2.1.2.2.1.1", "1.3.6.1.2.1.2.2.1.2", "1.3.6.…

---

## [How back pressure works in pipeline to pipeline communication](https://discuss.elastic.co/t/how-back-pressure-works-in-pipeline-to-pipeline-communication/368120)

<div class="topic-metadata">

**Author:** [@gwa99a9](https://discuss.elastic.co/u/gwa99a9)\
**Replies:** 1\
**Last updated:** [October 2, 2024, 2:34pm UTC](https://discuss.elastic.co/t/how-back-pressure-works-in-pipeline-to-pipeline-communication/368120 "2024-10-02T14:34:50Z")

</div>

Hello, I have question about pipeline to pipeline communication when handling back pressure. My setup is - from the microservices we send api calls as logs via tcp to (codec json) logstash and we have one input pipeline…

---

## [Http\_poller - URL - VAR](https://discuss.elastic.co/t/http-poller-url-var/368123)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 1\
**Last updated:** [October 2, 2024, 2:29pm UTC](https://discuss.elastic.co/t/http-poller-url-var/368123 "2024-10-02T14:29:24Z")

</div>

Can you help me, I'm making a request using HTTP however due to the API limitation I need to insert a date and this date needs to vary. I need the date to always be updated to the current date minus 1 hour. url =\> "htt…

---

## [How to parse stringified json in logstash](https://discuss.elastic.co/t/how-to-parse-stringified-json-in-logstash/367254)

<div class="topic-metadata">

**Author:** [@vijay117](https://discuss.elastic.co/u/vijay117)\
**Replies:** 3\
**Last updated:** [September 29, 2024, 2:12pm UTC](https://discuss.elastic.co/t/how-to-parse-stringified-json-in-logstash/367254 "2024-09-29T14:12:20Z")

</div>

{ "name": "cmg-notification-service App", "hostname": "notify-service-main-8cbfffc56-dq924", "pid": 1, "crn": "XXXXXXXXXXX", "url": "/v2/notify/sms", "requestId": "IJaxVCtAilpjSRODkySgaQ==", "…

---

## [Elk commercial support](https://discuss.elastic.co/t/elk-commercial-support/368114)

<div class="topic-metadata">

**Author:** [@pradeep-logstashuser](https://discuss.elastic.co/u/pradeep-logstashuser)\
**Replies:** 1\
**Last updated:** [October 2, 2024, 6:04am UTC](https://discuss.elastic.co/t/elk-commercial-support/368114 "2024-10-02T06:04:00Z")

</div>

Hi , We are new to ELK, can any one suggest commercial support for on demand basis is available?

---

## [Logstash deduplication with fingerprinting module drops unique data](https://discuss.elastic.co/t/logstash-deduplication-with-fingerprinting-module-drops-unique-data/368101)

<div class="topic-metadata">

**Author:** [@fffasttFGHb3t](https://discuss.elastic.co/u/fffasttFGHb3t)\
**Replies:** 0\
**Last updated:** [October 1, 2024, 5:15pm UTC](https://discuss.elastic.co/t/logstash-deduplication-with-fingerprinting-module-drops-unique-data/368101 "2024-10-01T17:15:45Z")

</div>

Hello all, I have a pipeline with a jdbc connection to a mysql database pulling large documents with many values. I am have added a ruby filter \[1\] to remove padded zeroes from one of the fields and save the unpadded v…

---

## ['source\_ip\_fieldname' is user customized, please check is has an ECS compatible name](https://discuss.elastic.co/t/source-ip-fieldname-is-user-customized-please-check-is-has-an-ecs-compatible-name/368078)

<div class="topic-metadata">

**Author:** [@Mahesh\_Kumar\_S](https://discuss.elastic.co/u/Mahesh_Kumar_S)\
**Replies:** 1\
**Last updated:** [October 1, 2024, 11:24am UTC](https://discuss.elastic.co/t/source-ip-fieldname-is-user-customized-please-check-is-has-an-ecs-compatible-name/368078 "2024-10-01T11:24:07Z")

</div>

Hello Elastic community, After migrating to Logstash 8 i have found a new warning message like \[WARN \]\[logstash.inputs.udp \] 'source\_ip\_fieldname' is user customized, please check is has an ECS compatible name …

---

## [Warning Message in Logstash 8: Redundant Nested Repeat Operator in Regular Expression](https://discuss.elastic.co/t/warning-message-in-logstash-8-redundant-nested-repeat-operator-in-regular-expression/368015)

<div class="topic-metadata">

**Author:** [@Mahesh\_Kumar\_S](https://discuss.elastic.co/u/Mahesh_Kumar_S)\
**Replies:** 2\
**Last updated:** [October 1, 2024, 9:29am UTC](https://discuss.elastic.co/t/warning-message-in-logstash-8-redundant-nested-repeat-operator-in-regular-expression/368015 "2024-10-01T09:29:46Z")

</div>

Hello Elastic community, I've encountered an issue after migrating to Logstash version 8. I'm seeing a new warning message related to a regular expression. Here are the details: Issue: After the migration, I'm receivi…

---

## [SSL/TLS connection problem between logstash and Elasticsearch](https://discuss.elastic.co/t/ssl-tls-connection-problem-between-logstash-and-elasticsearch/368071)

<div class="topic-metadata">

**Author:** [@Asmaa\_Oufkir](https://discuss.elastic.co/u/Asmaa_Oufkir)\
**Replies:** 0\
**Last updated:** [October 1, 2024, 8:24am UTC](https://discuss.elastic.co/t/ssl-tls-connection-problem-between-logstash-and-elasticsearch/368071 "2024-10-01T08:24:33Z")

</div>

I have a connection problem between elasticsearch and logstash in fact logstash cannot connect to elasticsearch I tried several solutions but it does not work I can connect to elasticsearch in https by .p12 Kibana also…

---

## [Input as elasticsearch and output to logstash](https://discuss.elastic.co/t/input-as-elasticsearch-and-output-to-logstash/367214)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 7\
**Last updated:** [October 1, 2024, 5:41am UTC](https://discuss.elastic.co/t/input-as-elasticsearch-and-output-to-logstash/367214 "2024-10-01T05:41:46Z")

</div>

Hello All, i have a use case where i need to use my elastic indices to use and dumps to the another logstash clusters (graylog opensearch indices) system is it worthy to use the logstash and get input as my elasticsea…

---

## [Optimizing Logstash Performance: Troubleshooting Instability at 10,000 EPS During Stress Tests](https://discuss.elastic.co/t/optimizing-logstash-performance-troubleshooting-instability-at-10-000-eps-during-stress-tests/368054)

<div class="topic-metadata">

**Author:** [@wangsubo](https://discuss.elastic.co/u/wangsubo)\
**Replies:** 4\
**Last updated:** [October 1, 2024, 4:01am UTC](https://discuss.elastic.co/t/optimizing-logstash-performance-troubleshooting-instability-at-10-000-eps-during-stress-tests/368054 "2024-10-01T04:01:48Z")

</div>

I am currently using an architecture with Elastic-Agent for log collection and Logstash for log forwarding. I am conducting stress testing to evaluate the hardware requirements and costs for my collector setup (Elastic-A…

---

## [Warning: regular expression has redundant nested repeat operator in grok-pure.rb file](https://discuss.elastic.co/t/warning-regular-expression-has-redundant-nested-repeat-operator-in-grok-pure-rb-file/368027)

<div class="topic-metadata">

**Author:** [@Mahesh\_Kumar1](https://discuss.elastic.co/u/Mahesh_Kumar1)\
**Replies:** 0\
**Last updated:** [September 30, 2024, 2:40pm UTC](https://discuss.elastic.co/t/warning-regular-expression-has-redundant-nested-repeat-operator-in-grok-pure-rb-file/368027 "2024-09-30T14:40:44Z")

</div>

After migration to the logstash 8.xx version i have a new warning while running the logstash server. How to fix it?? "/logstash-8.15.1/vendor/bundle/jruby/3.1.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:127: warning: regul…

---

## [Is it a bad idea to push all traffic from logstash into the ingest nodes?](https://discuss.elastic.co/t/is-it-a-bad-idea-to-push-all-traffic-from-logstash-into-the-ingest-nodes/367184)

<div class="topic-metadata">

**Author:** [@calvin1](https://discuss.elastic.co/u/calvin1)\
**Replies:** 2\
**Last updated:** [September 30, 2024, 10:52am UTC](https://discuss.elastic.co/t/is-it-a-bad-idea-to-push-all-traffic-from-logstash-into-the-ingest-nodes/367184 "2024-09-30T10:52:58Z")

</div>

Hi It appears that the normal path is to use either logstash OR ingest nodes for inbound traffic. in these two forms: beats clients -\> ingest -\> hot data nodes or beats clients -\> logstash -\> hot data nodes But is …

---

## [Logstash doesn't deliver input to output](https://discuss.elastic.co/t/logstash-doesnt-deliver-input-to-output/367976)

<div class="topic-metadata">

**Author:** [@evgeniy](https://discuss.elastic.co/u/evgeniy)\
**Replies:** 3\
**Last updated:** [September 30, 2024, 6:13am UTC](https://discuss.elastic.co/t/logstash-doesnt-deliver-input-to-output/367976 "2024-09-30T06:13:15Z")

</div>

I don't understand why logstash doesn't deliver input data to output. logstash is running in docker, alongside kibana and elastic. logstash.conf input { file { mode =\> "read" codec =\> "json\_lines" add\_fi…

---

## [How to do batched fetching with jdbc\_streaming?](https://discuss.elastic.co/t/how-to-do-batched-fetching-with-jdbc-streaming/367265)

<div class="topic-metadata">

**Author:** [@mxu](https://discuss.elastic.co/u/mxu)\
**Replies:** 2\
**Last updated:** [September 29, 2024, 12:14am UTC](https://discuss.elastic.co/t/how-to-do-batched-fetching-with-jdbc-streaming/367265 "2024-09-29T00:14:00Z")

</div>

I have to use jdbc\_streaming to get data from postgres database. With large number of records, logstash runs OOM. Instead of increasing heap size, I'd like to batched read as jdbc input would do. have been trying differ…

---

## [String Field contains duration/conversion](https://discuss.elastic.co/t/string-field-contains-duration-conversion/367262)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [September 27, 2024, 7:06pm UTC](https://discuss.elastic.co/t/string-field-contains-duration-conversion/367262 "2024-09-27T19:06:39Z")

</div>

Hello, I have this string field "time.connected" Examples: How do I make this field in a duration field? is there a way to convert this?

---

## [Logstash javapipeline error=\> (OpenTimeout) execution expired](https://discuss.elastic.co/t/logstash-javapipeline-error-opentimeout-execution-expired/365660)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 8\
**Last updated:** [September 27, 2024, 11:15am UTC](https://discuss.elastic.co/t/logstash-javapipeline-error-opentimeout-execution-expired/365660 "2024-09-27T11:15:20Z")

</div>

Hi Teams. The problem is in the pipeline. I noticed that data periodically stops flowing for one index. I checked and after a certain time the port stops "listening". At the input, TCP is listening, I saw this message …

---

## [Unable to configure Elasticsearch to collect log from Openshift cluser](https://discuss.elastic.co/t/unable-to-configure-elasticsearch-to-collect-log-from-openshift-cluser/367212)

<div class="topic-metadata">

**Author:** [@mbalel](https://discuss.elastic.co/u/mbalel)\
**Replies:** 0\
**Last updated:** [September 27, 2024, 6:27am UTC](https://discuss.elastic.co/t/unable-to-configure-elasticsearch-to-collect-log-from-openshift-cluser/367212 "2024-09-27T06:27:41Z")

</div>

Hello, I have a problem connection our Openshift cluster to the Elasticsearch. I have tried with elasticsearch as an Input configuration option but failed to configure it I guess. The error from elastic side is: 2024-09-…

---

## [Elasticsearch Index Field Deletion Issue with Logstash](https://discuss.elastic.co/t/elasticsearch-index-field-deletion-issue-with-logstash/367191)

<div class="topic-metadata">

**Author:** [@Md\_Habibullah\_Howlad](https://discuss.elastic.co/u/Md_Habibullah_Howlad)\
**Replies:** 0\
**Last updated:** [September 26, 2024, 2:19pm UTC](https://discuss.elastic.co/t/elasticsearch-index-field-deletion-issue-with-logstash/367191 "2024-09-26T14:19:38Z")

</div>

Hello everyone, I’m new to the ELK stack and need help with an issue regarding field deletion in Elasticsearch. I have a source table with 10 records that I want to reflect in Elasticsearch. I'm using Logstash to pull …

---

## [Failure upon install local java plugins in logstash-wolfi](https://discuss.elastic.co/t/failure-upon-install-local-java-plugins-in-logstash-wolfi/365367)

<div class="topic-metadata">

**Author:** [@ahmadabulaban1993](https://discuss.elastic.co/u/ahmadabulaban1993)\
**Replies:** 1\
**Last updated:** [September 27, 2024, 1:24am UTC](https://discuss.elastic.co/t/failure-upon-install-local-java-plugins-in-logstash-wolfi/365367 "2024-09-27T01:24:31Z")

</div>

Versions 8.15.0 based on wolfi (docker.elastic.co/logstash/logstash-wolfi:8.15.0) Describe the issue : I've some custom plugins built using java and currently using logstash v8.14.3. Noticed that logstash 8.15.0 is re…

---

## [Logstash helm chart for copying data from elasticsearch to opensearch](https://discuss.elastic.co/t/logstash-helm-chart-for-copying-data-from-elasticsearch-to-opensearch/367143)

<div class="topic-metadata">

**Author:** [@Deepa\_Karthika](https://discuss.elastic.co/u/Deepa_Karthika)\
**Replies:** 3\
**Last updated:** [September 26, 2024, 8:49am UTC](https://discuss.elastic.co/t/logstash-helm-chart-for-copying-data-from-elasticsearch-to-opensearch/367143 "2024-09-26T08:49:07Z")

</div>

0 We were using ELK cluster for observability log monitoring in our current project and now we are moving that to opensearch tool. So we need to copy data from current ECK cluster( indices data ) to Opensearch indices. …

---

## [Cassandra jdbc drive issue with logstash in docker](https://discuss.elastic.co/t/cassandra-jdbc-drive-issue-with-logstash-in-docker/367105)

<div class="topic-metadata">

**Author:** [@AmritMatti](https://discuss.elastic.co/u/AmritMatti)\
**Replies:** 2\
**Last updated:** [September 25, 2024, 1:33pm UTC](https://discuss.elastic.co/t/cassandra-jdbc-drive-issue-with-logstash-in-docker/367105 "2024-09-25T13:33:13Z")

</div>

Hi, I am running logsstash, elasticsearch, kibana in docker 8.15.0 and cassandra 5.0. I want to setup logstash input from cassandra with jdbc. I have downloaded jdbc drivers from Cassandra JDBC Driver Download & Connec…

---

## [Logstash installation getting failed](https://discuss.elastic.co/t/logstash-installation-getting-failed/366889)

<div class="topic-metadata">

**Author:** [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Replies:** 1\
**Last updated:** [September 25, 2024, 12:48pm UTC](https://discuss.elastic.co/t/logstash-installation-getting-failed/366889 "2024-09-25T12:48:23Z")

</div>

Hi , I have logstash 7.16.3 installed in my machine. If I try to remove this and install 8.x versions of logstash using the RPM files, the installation is getting failed with the below error. Could anyone please help…

---

## [Parsing logs with a value\_split](https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059)

<div class="topic-metadata">

**Author:** [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Replies:** 3\
**Last updated:** [September 25, 2024, 12:30pm UTC](https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059 "2024-09-25T12:30:29Z")

</div>

"processors" : \[ { "grok": { "field": "log", "patterns": \["%{TIME\_STAMP:ts} %{GREEDYDATA:logtail}"\], "pattern\_definitions" : { "TIME\_STAMP" : "%{YEAR}-%{MONTHNUM…

---

## [Sql\_last\_value wrong timestamp](https://discuss.elastic.co/t/sql-last-value-wrong-timestamp/367075)

<div class="topic-metadata">

**Author:** [@thien.nguyen](https://discuss.elastic.co/u/thien.nguyen)\
**Replies:** 0\
**Last updated:** [September 25, 2024, 2:24am UTC](https://discuss.elastic.co/t/sql-last-value-wrong-timestamp/367075 "2024-09-25T02:24:28Z")

</div>

Hi, I used logstash jbdc to get data from oracle db for a year. Last week, my company change db server and my jdbc pipeline does not work correctly anymore. As you see, I set my pipeline start at 8 a.m and run every 5 m…

---

## [Unable to start logstash](https://discuss.elastic.co/t/unable-to-start-logstash/366705)

<div class="topic-metadata">

**Author:** [@Mike\_Reprogle](https://discuss.elastic.co/u/Mike_Reprogle)\
**Replies:** 4\
**Last updated:** [September 24, 2024, 2:35am UTC](https://discuss.elastic.co/t/unable-to-start-logstash/366705 "2024-09-24T02:35:24Z")

</div>

I have seen many other posts that seem similar, but come down to not having a config file set. I have a couple of .conf files located in /etc/logstash/conf.d, as I am trying to set up an Azure VM with logstash for SaaS l…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=18)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=20)
