# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=190

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 191

---

## [CEF plugin is not working as expected](https://discuss.elastic.co/t/cef-plugin-is-not-working-as-expected/286024)

<div class="topic-metadata">

**Author:** [@Sunflower](https://discuss.elastic.co/u/Sunflower)\
**Replies:** 12\
**Last updated:** [October 7, 2021, 1:11pm UTC](https://discuss.elastic.co/t/cef-plugin-is-not-working-as-expected/286024 "2021-10-07T13:11:35Z")

</div>

Hi, I'm trying to configure Logstash to work with SentinelOne logs, but it is not working as expected, it looks like it is not separating the fields correctly. I configured the input to be CEF and the output to be json…

---

## [Logstash date filter don't parse time](https://discuss.elastic.co/t/logstash-date-filter-dont-parse-time/286064)

<div class="topic-metadata">

**Author:** [@AlexG](https://discuss.elastic.co/u/AlexG)\
**Replies:** 2\
**Last updated:** [October 7, 2021, 10:17am UTC](https://discuss.elastic.co/t/logstash-date-filter-dont-parse-time/286064 "2021-10-07T10:17:19Z")

</div>

I have a log in msi installer format (time only, without date): MSI (c) (F0:8C) \[09:00:05:007\]: Client-side and UI is none or basic: Running entire install on the server. MSI (c) (F0:8C) \[09:00:05:007\]: Grabbed executio…

---

## [Logstash json messages on tcp-input truncated under high load](https://discuss.elastic.co/t/logstash-json-messages-on-tcp-input-truncated-under-high-load/286102)

<div class="topic-metadata">

**Author:** [@hajeve](https://discuss.elastic.co/u/hajeve)\
**Replies:** 0\
**Last updated:** [October 7, 2021, 7:41am UTC](https://discuss.elastic.co/t/logstash-json-messages-on-tcp-input-truncated-under-high-load/286102 "2021-10-07T07:41:20Z")

</div>

We are receiving BIG IP F5 request-logs in Logstash on a tcp-input (with codec =\> "json\_lines") in our production environment. We see that a lot of messages (json) are truncated and result in many (thousands per hour) js…

---

## [Error: Cannot invoke "java.lang.CharSequence.length()" because "this.wrapped" is null](https://discuss.elastic.co/t/error-cannot-invoke-java-lang-charsequence-length-because-this-wrapped-is-null/286076)

<div class="topic-metadata">

**Author:** [@Thanura\_Kannangara](https://discuss.elastic.co/u/Thanura_Kannangara)\
**Replies:** 1\
**Last updated:** [October 6, 2021, 11:14pm UTC](https://discuss.elastic.co/t/error-cannot-invoke-java-lang-charsequence-length-because-this-wrapped-is-null/286076 "2021-10-06T23:14:22Z")

</div>

Hey Folks, I ran into this error when I tried to run my logstash pipeline \[2021-10-06T21:41:34,176\]\[WARN \]\[logstash.outputs.elasticsearch\]\[logstash\_pipeline\_2\]\[e957447bf4995516c816dfcbd573d1dabd794c31f242e6642bc68deb57…

---

## [Remove from json](https://discuss.elastic.co/t/remove-from-json/286047)

<div class="topic-metadata">

**Author:** [@ANISH\_VERMA](https://discuss.elastic.co/u/ANISH_VERMA)\
**Replies:** 4\
**Last updated:** [October 6, 2021, 4:04pm UTC](https://discuss.elastic.co/t/remove-from-json/286047 "2021-10-06T16:04:25Z")

</div>

Hi I am using logstash so when I am doing the multi-line thing I am getting \\n \\t \\r like character in json is there away to remove these in Json message without compromising with the message layout . And even if it is h…

---

## [Ruby Filter for Compressed Binary OID Table](https://discuss.elastic.co/t/ruby-filter-for-compressed-binary-oid-table/285691)

<div class="topic-metadata">

**Author:** [@bennrtc](https://discuss.elastic.co/u/bennrtc)\
**Replies:** 1\
**Last updated:** [October 6, 2021, 3:40pm UTC](https://discuss.elastic.co/t/ruby-filter-for-compressed-binary-oid-table/285691 "2021-10-06T15:40:16Z")

</div>

Hello all, I'm working within an OID that returns values in compressed binary. I've been able to successfully come up with a config (below) that polls a single SNMP OID with compressed binary value using 'get' and then…

---

## [Config files](https://discuss.elastic.co/t/config-files/286045)

<div class="topic-metadata">

**Author:** [@tractor\_boy](https://discuss.elastic.co/u/tractor_boy)\
**Replies:** 2\
**Last updated:** [October 6, 2021, 3:34pm UTC](https://discuss.elastic.co/t/config-files/286045 "2021-10-06T15:34:44Z")

</div>

I am trying to understand how to set up logstash .conf files to see what is required. I am considering a separate .conf files for each index/type of metric being captured. On the web it suggests that even if they are s…

---

## [Logstash JDBC\_last \_ not updating](https://discuss.elastic.co/t/logstash-jdbc-last-not-updating/285993)

<div class="topic-metadata">

**Author:** [@Akshaya](https://discuss.elastic.co/u/Akshaya)\
**Replies:** 2\
**Last updated:** [October 6, 2021, 3:11pm UTC](https://discuss.elastic.co/t/logstash-jdbc-last-not-updating/285993 "2021-10-06T15:11:01Z")

</div>

Hi , I'm new to Elasticsearch and Logstash, trying to implement JDBC plugin. I'm not sure why .logstash\_last\_run file is not getting updated. The values inside the file remains the same even after several runs. value …

---

## [Persistent Queues with multiple logstash processes in 2021](https://discuss.elastic.co/t/persistent-queues-with-multiple-logstash-processes-in-2021/286044)

<div class="topic-metadata">

**Author:** [@ab017i0](https://discuss.elastic.co/u/ab017i0)\
**Replies:** 0\
**Last updated:** [October 6, 2021, 2:45pm UTC](https://discuss.elastic.co/t/persistent-queues-with-multiple-logstash-processes-in-2021/286044 "2021-10-06T14:45:14Z")

</div>

Hello, our team is solving same problem. Persistent Queues with multiple logstash processes The output is "Logstash persistent queues are not shared. Nd configured per instance." as for 2019. Is the answer is still va…

---

## [How can I make my Grok filter match a file extension or blank (if no extension)?](https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011)

<div class="topic-metadata">

**Author:** [@nsouth](https://discuss.elastic.co/u/nsouth)\
**Replies:** 2\
**Last updated:** [October 6, 2021, 1:30pm UTC](https://discuss.elastic.co/t/how-can-i-make-my-grok-filter-match-a-file-extension-or-blank-if-no-extension/286011 "2021-10-06T13:30:01Z")

</div>

I have the following grok filter which extracts the file\_extension from a field. It works except fine for files which have no extension, which generate a \_grokparsefailure tag. For files with no extension, I would like t…

---

## [Updating config file](https://discuss.elastic.co/t/updating-config-file/286021)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 5\
**Last updated:** [October 6, 2021, 1:23pm UTC](https://discuss.elastic.co/t/updating-config-file/286021 "2021-10-06T13:23:33Z")

</div>

I have been trial and error technique to solve problems with the logstash I have been updating the config file input filter and output settings time to time. so I want to index already present files but at first time i…

---

## [Logstash input JDBC - Oracle wallet support](https://discuss.elastic.co/t/logstash-input-jdbc-oracle-wallet-support/286023)

<div class="topic-metadata">

**Author:** [@Prashant\_Achari](https://discuss.elastic.co/u/Prashant_Achari)\
**Replies:** 0\
**Last updated:** [October 6, 2021, 12:20pm UTC](https://discuss.elastic.co/t/logstash-input-jdbc-oracle-wallet-support/286023 "2021-10-06T12:20:10Z")

</div>

I am trying to setup Logstah to work with Oracle wallet. I am unable get any configuration that supports wallet. I cannot keep open passwords in config files that is against the security policy. I am getting below error …

---

## [Detect when a Logstash pipeline is ready for input?](https://discuss.elastic.co/t/detect-when-a-logstash-pipeline-is-ready-for-input/285813)

<div class="topic-metadata">

**Author:** [@GrahamHannington](https://discuss.elastic.co/u/GrahamHannington)\
**Replies:** 5\
**Last updated:** [October 6, 2021, 11:57am UTC](https://discuss.elastic.co/t/detect-when-a-logstash-pipeline-is-ready-for-input/285813 "2021-10-06T11:57:52Z")

</div>

Until recently, using Elastic 7.11.2, I've been using the following curl command line, in a Linux shell script, to detect whether Logstash is ready to ingest data: curl localhost:9600 2\> /dev/null (In a previous edit o…

---

## [Logstash-output-zabbix does not send to zabbix](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912)

<div class="topic-metadata">

**Author:** [@Paveltest](https://discuss.elastic.co/u/Paveltest)\
**Replies:** 3\
**Last updated:** [October 6, 2021, 5:12am UTC](https://discuss.elastic.co/t/logstash-output-zabbix-does-not-send-to-zabbix/285912 "2021-10-06T05:12:42Z")

</div>

When sending logs to zabbix, it gives an error. \[WARN \] 2021-10-05 \[\[main\]\>worker1\] zabbix - Field referenced by message is missing \[WARN \] 2021-10-05 \[\[main\]\>worker1\] zabbix - Zabbix server at monitoring-server.com …

---

## [How to parse the following nested json](https://discuss.elastic.co/t/how-to-parse-the-following-nested-json/285959)

<div class="topic-metadata">

**Author:** [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Replies:** 1\
**Last updated:** [October 5, 2021, 6:53pm UTC](https://discuss.elastic.co/t/how-to-parse-the-following-nested-json/285959 "2021-10-05T18:53:35Z")

</div>

Hello, I would like to know how to parse the list of nested json "documents" inside a json list field. Thank you in advance, There is that list of name and value pairs in the following format: { "list": \[ { …

---

## [Parsing mongodb input fully via logstash =\> elasticsearch](https://discuss.elastic.co/t/parsing-mongodb-input-fully-via-logstash-elasticsearch/285843)

<div class="topic-metadata">

**Author:** [@diaztech](https://discuss.elastic.co/u/diaztech)\
**Replies:** 6\
**Last updated:** [October 5, 2021, 6:28pm UTC](https://discuss.elastic.co/t/parsing-mongodb-input-fully-via-logstash-elasticsearch/285843 "2021-10-05T18:28:23Z")

</div>

I'm parsing a mongodb input into logstash, the config file is as follows: input { mongodb { uri =\> "\<mongouri\>" placeholder\_db\_dir =\> "\<path\>" collection =\> "modules" batch\_size =\> 50…

---

## [Grok pattern for this syslog message for Logstash?](https://discuss.elastic.co/t/grok-pattern-for-this-syslog-message-for-logstash/285896)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 8\
**Last updated:** [October 5, 2021, 2:35pm UTC](https://discuss.elastic.co/t/grok-pattern-for-this-syslog-message-for-logstash/285896 "2021-10-05T14:35:18Z")

</div>

Hello I have this syslog message which is ALMOST like the standard RFC3164 so the default syslog plugin should pick it up: \<134\>1 2021-10-05T08:48:18Z MYSERVER iLO5 - - - XML logout: SomeUser - 1.2.3.4(DNS name not fou…

---

## [Date from DB is changed when inserted in ES](https://discuss.elastic.co/t/date-from-db-is-changed-when-inserted-in-es/285904)

<div class="topic-metadata">

**Author:** [@Blazkowicz](https://discuss.elastic.co/u/Blazkowicz)\
**Replies:** 1\
**Last updated:** [October 5, 2021, 2:27pm UTC](https://discuss.elastic.co/t/date-from-db-is-changed-when-inserted-in-es/285904 "2021-10-05T14:27:01Z")

</div>

Hi all, Having an issue with a date field when trying to insert it in ES. Searched and tried multiple modes but to no avail. Short story, my date field from Postgres ends up in ES with a timezone attached/offset, even …

---

## [Message "Invalid JSON" when inserting a Grok pattern in a Processor for an Ingest Node Pipeline](https://discuss.elastic.co/t/message-invalid-json-when-inserting-a-grok-pattern-in-a-processor-for-an-ingest-node-pipeline/285884)

<div class="topic-metadata">

**Author:** [@ArieTwigt](https://discuss.elastic.co/u/ArieTwigt)\
**Replies:** 0\
**Last updated:** [October 5, 2021, 6:22am UTC](https://discuss.elastic.co/t/message-invalid-json-when-inserting-a-grok-pattern-in-a-processor-for-an-ingest-node-pipeline/285884 "2021-10-05T06:22:56Z")

</div>

With the Grok Debugger I managed to create the right Grok pattern for the message I would like to parse. When trying to add the following Grok pattern in the Processor for the Ingest Node Pipeline, I get an error message…

---

## [Manually add geo point to server logs](https://discuss.elastic.co/t/manually-add-geo-point-to-server-logs/285793)

<div class="topic-metadata">

**Author:** [@maltewhiite](https://discuss.elastic.co/u/maltewhiite)\
**Replies:** 5\
**Last updated:** [October 5, 2021, 11:46am UTC](https://discuss.elastic.co/t/manually-add-geo-point-to-server-logs/285793 "2021-10-05T11:46:55Z")

</div>

How do I add the location of our servers as a geo-point that can be used with Kibana Maps to the logs of that server? For example: Let's say a log has agent.name "AgentExample01", then I would match on that, and add la…

---

## [How to fingerprint with a removed field?](https://discuss.elastic.co/t/how-to-fingerprint-with-a-removed-field/284282)

<div class="topic-metadata">

**Author:** [@Busra\_Duygu](https://discuss.elastic.co/u/Busra_Duygu)\
**Replies:** 6\
**Last updated:** [October 5, 2021, 8:02am UTC](https://discuss.elastic.co/t/how-to-fingerprint-with-a-removed-field/284282 "2021-10-05T08:02:56Z")

</div>

Hello friends, I want to put a field in a @metadata variable and use this field for fingerprinting later in logstash conf file. Is it possible for me to do this?Does anyone have an idea? I made some attempts but no resu…

---

## [Logstash did not show any log/message](https://discuss.elastic.co/t/logstash-did-not-show-any-log-message/285888)

<div class="topic-metadata">

**Author:** [@vikramdayma](https://discuss.elastic.co/u/vikramdayma)\
**Replies:** 0\
**Last updated:** [October 5, 2021, 7:22am UTC](https://discuss.elastic.co/t/logstash-did-not-show-any-log-message/285888 "2021-10-05T07:22:13Z")

</div>

Hi, I am making a logstash connection to mariadb. Earlier it was working pefectly. But now when I run a .conf file manually, is start and nothing happen after it, neither close nor execute. And also did not give any …

---

## [Split a json array and then split on each object](https://discuss.elastic.co/t/split-a-json-array-and-then-split-on-each-object/285846)

<div class="topic-metadata">

**Author:** [@devtough](https://discuss.elastic.co/u/devtough)\
**Replies:** 7\
**Last updated:** [October 4, 2021, 10:20pm UTC](https://discuss.elastic.co/t/split-a-json-array-and-then-split-on-each-object/285846 "2021-10-04T22:20:21Z")

</div>

I would like to configure Logstash so that given a JSON input of \[ { "record": "a", "actions": \[ { "id": 1 }, { "id": 2 } \] }, { "record": "b", "actions": \[ { "id": 3 }, { "id": 4 } \] } \] it outputs {record: "a"…

---

## [Contains an unknown parameter \[\_routing\]](https://discuss.elastic.co/t/contains-an-unknown-parameter-routing/285856)

<div class="topic-metadata">

**Author:** [@manjurgani](https://discuss.elastic.co/u/manjurgani)\
**Replies:** 0\
**Last updated:** [October 4, 2021, 9:49pm UTC](https://discuss.elastic.co/t/contains-an-unknown-parameter-routing/285856 "2021-10-04T21:49:56Z")

</div>

Here is my config file for logstash to connect aws Elasticsearch. It works correctly without "routing" input { file { path =\> "C:/Users/manjur.gani/Desktop/ES/test45.csv" start\_position=\>"beginning" } } filte…

---

## [How to replace logstash read time with log timing?](https://discuss.elastic.co/t/how-to-replace-logstash-read-time-with-log-timing/285834)

<div class="topic-metadata">

**Author:** [@Pradeep\_Kumar2](https://discuss.elastic.co/u/Pradeep_Kumar2)\
**Replies:** 9\
**Last updated:** [October 4, 2021, 6:25pm UTC](https://discuss.elastic.co/t/how-to-replace-logstash-read-time-with-log-timing/285834 "2021-10-04T18:25:56Z")

</div>

Hi, I am trying to configure logstash file which will replace the logstash read timestamp or system time with actual log time. In the kibana discover dashboard logs are displayed with logstash read time. How to replace …

---

## [Parsing data from multiple application servers through logstash](https://discuss.elastic.co/t/parsing-data-from-multiple-application-servers-through-logstash/285069)

<div class="topic-metadata">

**Author:** [@prat](https://discuss.elastic.co/u/prat)\
**Replies:** 10\
**Last updated:** [October 4, 2021, 3:27pm UTC](https://discuss.elastic.co/t/parsing-data-from-multiple-application-servers-through-logstash/285069 "2021-10-04T15:27:56Z")

</div>

Hi Team, I have application running on 2 servers and application logs are getting logged on both the servers, so i want to parse logs from both servers. filebeat is installed on two application servers, logstash is in…

---

## [Work with nested fields in logstash elasticsearch filter](https://discuss.elastic.co/t/work-with-nested-fields-in-logstash-elasticsearch-filter/285828)

<div class="topic-metadata">

**Author:** [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Replies:** 1\
**Last updated:** [October 4, 2021, 2:35pm UTC](https://discuss.elastic.co/t/work-with-nested-fields-in-logstash-elasticsearch-filter/285828 "2021-10-04T14:35:42Z")

</div>

hello! i want to enrich my data with the elastic filter . i tried to keep de host.hostname fields of metricbeat without success with this: elasticsearch { hosts =\> "https://xxxx:9200" index =\> "metricbeat" …

---

## [Logstash does not send few log events generally the last ones](https://discuss.elastic.co/t/logstash-does-not-send-few-log-events-generally-the-last-ones/285802)

<div class="topic-metadata">

**Author:** [@Pratyush\_Rath](https://discuss.elastic.co/u/Pratyush_Rath)\
**Replies:** 6\
**Last updated:** [October 4, 2021, 1:44pm UTC](https://discuss.elastic.co/t/logstash-does-not-send-few-log-events-generally-the-last-ones/285802 "2021-10-04T13:44:28Z")

</div>

I am using an ELK stack in my local machine . I have tested sending log events from variety of inputs like file, stdin, filebeat and outputs like Elasticsearch, stdout and tried variety of combinations but the Outputs al…

---

## [Multiple pipelines mixing records in indexes](https://discuss.elastic.co/t/multiple-pipelines-mixing-records-in-indexes/285705)

<div class="topic-metadata">

**Author:** [@Danny\_Dumenigo](https://discuss.elastic.co/u/Danny_Dumenigo)\
**Replies:** 2\
**Last updated:** [October 4, 2021, 12:35pm UTC](https://discuss.elastic.co/t/multiple-pipelines-mixing-records-in-indexes/285705 "2021-10-04T12:35:13Z")

</div>

Hello Community: Im a new user at ELK. I have deployed an ELK stack and everything works fine except for my Logstash pipelines. I explain myself: I have a Logstash server with 3 pipelines defined: Pipeline 1: Manage a…

---

## [Logstash output to elasic with a pretty print JSON field, but as string (not scattered to fields)](https://discuss.elastic.co/t/logstash-output-to-elasic-with-a-pretty-print-json-field-but-as-string-not-scattered-to-fields/285804)

<div class="topic-metadata">

**Author:** [@dotaneli](https://discuss.elastic.co/u/dotaneli)\
**Replies:** 0\
**Last updated:** [October 4, 2021, 10:28am UTC](https://discuss.elastic.co/t/logstash-output-to-elasic-with-a-pretty-print-json-field-but-as-string-not-scattered-to-fields/285804 "2021-10-04T10:28:30Z")

</div>

Hi all. I have a pipline that take a JSON from filebeat. That json has fields that hold json themselvers. Escaped. I want to see in discover the json field as a pretty printed json, but think that I first need to send…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=189)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=191)
