# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=2

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 3

---

## [Json file input to and viewing in logstash console](https://discuss.elastic.co/t/json-file-input-to-and-viewing-in-logstash-console/383608)

<div class="topic-metadata">

**Author:** [@dashelastic](https://discuss.elastic.co/u/dashelastic)\
**Replies:** 7\
**Last updated:** [November 27, 2025, 5:33am UTC](https://discuss.elastic.co/t/json-file-input-to-and-viewing-in-logstash-console/383608 "2025-11-27T05:33:08Z")

</div>

logstash version : 8.17.2, installed on windows machine. Requirement : ingest json file into logstash json file (its bigger but for testing purpose, trimmed it to one entry only) {{"id":"ocid1.clem.oc1.iad.","compartm…

---

## [Unable to install Syslog Output Plugin](https://discuss.elastic.co/t/unable-to-install-syslog-output-plugin/383679)

<div class="topic-metadata">

**Author:** [@swarali\_vartak](https://discuss.elastic.co/u/swarali_vartak)\
**Replies:** 2\
**Last updated:** [November 27, 2025, 5:24am UTC](https://discuss.elastic.co/t/unable-to-install-syslog-output-plugin/383679 "2025-11-27T05:24:19Z")

</div>

Hi Team, Could you please guide me on installing the Syslog output plugin on our Logstash server? We tried installing it using the method mentioned on ruby.org, but it didn't work. Kindly share the correct steps or pro…

---

## [Strange Grok with message](https://discuss.elastic.co/t/strange-grok-with-message/383686)

<div class="topic-metadata">

**Author:** [@Andex](https://discuss.elastic.co/u/Andex)\
**Replies:** 4\
**Last updated:** [November 26, 2025, 8:27pm UTC](https://discuss.elastic.co/t/strange-grok-with-message/383686 "2025-11-26T20:27:20Z")

</div>

Hello guys I have this logstash filter filter { if \[log\]\[file\]\[path\] == "/dwdwdosw/Top/log/services/uds-default-pippo.it" or \[log\]\[file\]\[path\] == "/aledwgosw/Top/log/services/uds-default-pluto.it" { mutate { …

---

## [Export Elasticsearch Data](https://discuss.elastic.co/t/export-elasticsearch-data/383692)

<div class="topic-metadata">

**Author:** [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Replies:** 0\
**Last updated:** [November 26, 2025, 4:17pm UTC](https://discuss.elastic.co/t/export-elasticsearch-data/383692 "2025-11-26T16:17:34Z")

</div>

Hello guys, i’m working on a solution which use Elasticsearch as DataLake and export data on an external SIEM. As first requirement I want leverage elasticsearch capabilities as integration and enrichment, so I cannot …

---

## [Grok doesn't work on Elastic but on dubugger yes](https://discuss.elastic.co/t/grok-doesnt-work-on-elastic-but-on-dubugger-yes/383641)

<div class="topic-metadata">

**Author:** [@Andex](https://discuss.elastic.co/u/Andex)\
**Replies:** 5\
**Last updated:** [November 25, 2025, 8:09pm UTC](https://discuss.elastic.co/t/grok-doesnt-work-on-elastic-but-on-dubugger-yes/383641 "2025-11-25T20:09:01Z")

</div>

Hi, i’m running a pipeline with Grok filter and date filter. The date filter is running good. Even if my grok matches the logs, on elastic I don't see them parsed, it's like it ignores my grok filter. This is the pipeli…

---

## [Elasticsearch not creating required output as expected with logstash and filebeat](https://discuss.elastic.co/t/elasticsearch-not-creating-required-output-as-expected-with-logstash-and-filebeat/383551)

<div class="topic-metadata">

**Author:** [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Replies:** 7\
**Last updated:** [November 20, 2025, 4:53pm UTC](https://discuss.elastic.co/t/elasticsearch-not-creating-required-output-as-expected-with-logstash-and-filebeat/383551 "2025-11-20T16:53:04Z")

</div>

Good morning , I have installed filebeat , logstash,kibana and elasticsearch on the same server I want filebeat to push a particular json file to logstash and then appear in kibana i have configured the filebeat.yml …

---

## [Handle batching just like Persistent Queue using the In-Memory Queue](https://discuss.elastic.co/t/handle-batching-just-like-persistent-queue-using-the-in-memory-queue/383453)

<div class="topic-metadata">

**Author:** [@Oscar\_Moyeda](https://discuss.elastic.co/u/Oscar_Moyeda)\
**Replies:** 6\
**Last updated:** [November 18, 2025, 7:14pm UTC](https://discuss.elastic.co/t/handle-batching-just-like-persistent-queue-using-the-in-memory-queue/383453 "2025-11-18T19:14:27Z")

</div>

Hi everyone. I am using Logstash Version: 9.1.0 I was debugging my output plugin and I found out that when using the default In-memory queue, Logstash would batch the events into smaller chunks of events. I have script…

---

## [TLS handshake failure between Logstash-LB and log drops in Logstash server](https://discuss.elastic.co/t/tls-handshake-failure-between-logstash-lb-and-log-drops-in-logstash-server/383469)

<div class="topic-metadata">

**Author:** [@Subhanwita\_Mullick](https://discuss.elastic.co/u/Subhanwita_Mullick)\
**Replies:** 0\
**Last updated:** [November 16, 2025, 5:24pm UTC](https://discuss.elastic.co/t/tls-handshake-failure-between-logstash-lb-and-log-drops-in-logstash-server/383469 "2025-11-16T17:24:26Z")

</div>

My architecture is Sources –\> Load balancer –\> Logstash server (8 CPU, 16 GB) –\> Azure Sentinel. For the store logs, we just did an extensive traffic analysis as well. In the connectivity between LB and Logstash cluster…

---

## [Logstash TCP input SSL connection failing without closing due reason](https://discuss.elastic.co/t/logstash-tcp-input-ssl-connection-failing-without-closing-due-reason/382927)

<div class="topic-metadata">

**Author:** [@ThorNicolai](https://discuss.elastic.co/u/ThorNicolai)\
**Replies:** 1\
**Last updated:** [November 12, 2025, 8:46am UTC](https://discuss.elastic.co/t/logstash-tcp-input-ssl-connection-failing-without-closing-due-reason/382927 "2025-11-12T08:46:27Z")

</div>

Dear members of the forum, I have been struggling to get a connection working regarding incoming TCP SSL data. We are running an Ubuntu server with Logstash, we have multiple pipelines running, but this specific one wo…

---

## [Logstash and Elasticsearch v9 – Compatibility Issue and Windows Support Removal](https://discuss.elastic.co/t/logstash-and-elasticsearch-v9-compatibility-issue-and-windows-support-removal/383331)

<div class="topic-metadata">

**Author:** [@Mahesh\_Kumar1](https://discuss.elastic.co/u/Mahesh_Kumar1)\
**Replies:** 3\
**Last updated:** [November 11, 2025, 10:30am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch-v9-compatibility-issue-and-windows-support-removal/383331 "2025-11-11T10:30:00Z")

</div>

Why was Windows Server 2016/2019 support removed in Elastic v9 even though they’re still supported by Microsoft? Hello Elastic Team, I’m trying to understand the reasoning behind the removal of Windows Server 2016 and W…

---

## [How to connect to cassandra mTLS from logstash to source the data using keystore and truststore files?](https://discuss.elastic.co/t/how-to-connect-to-cassandra-mtls-from-logstash-to-source-the-data-using-keystore-and-truststore-files/383347)

<div class="topic-metadata">

**Author:** [@Venkata9](https://discuss.elastic.co/u/Venkata9)\
**Replies:** 2\
**Last updated:** [November 11, 2025, 7:24am UTC](https://discuss.elastic.co/t/how-to-connect-to-cassandra-mtls-from-logstash-to-source-the-data-using-keystore-and-truststore-files/383347 "2025-11-11T07:24:37Z")

</div>

Hi Team, Need help with connecting to Cassandra with mTLS connectivity using keystore and truststore certificates to source the data from Cassandra.

---

## [Logback ECS Encoder vs Logstash](https://discuss.elastic.co/t/logback-ecs-encoder-vs-logstash/383307)

<div class="topic-metadata">

**Author:** [@haider665](https://discuss.elastic.co/u/haider665)\
**Replies:** 0\
**Last updated:** [November 9, 2025, 8:39am UTC](https://discuss.elastic.co/t/logback-ecs-encoder-vs-logstash/383307 "2025-11-09T08:39:09Z")

</div>

I was doing some study on ELK stack and how to implement it with our spring boot microservices. I have seen two approaches to get logs from my application to kibana dashboard. Using logstash: File beat reads the log fr…

---

## [Logstash geoip download/update](https://discuss.elastic.co/t/logstash-geoip-download-update/383241)

<div class="topic-metadata">

**Author:** [@murali\_vraman](https://discuss.elastic.co/u/murali_vraman)\
**Replies:** 4\
**Last updated:** [November 6, 2025, 3:20pm UTC](https://discuss.elastic.co/t/logstash-geoip-download-update/383241 "2025-11-06T15:20:57Z")

</div>

I have enabled the following settings in logstash.yml file. When it does detect changes, does it do a full download of the database? xpack.geoip.downloader.endpoint: "https://geoip.elastic.co/v1/database" xpack.geoip.d…

---

## [Logstash Output to Elastic Severless via API Issues](https://discuss.elastic.co/t/logstash-output-to-elastic-severless-via-api-issues/364620)

<div class="topic-metadata">

**Author:** [@teamomni](https://discuss.elastic.co/u/teamomni)\
**Replies:** 2\
**Last updated:** [November 4, 2025, 2:55pm UTC](https://discuss.elastic.co/t/logstash-output-to-elastic-severless-via-api-issues/364620 "2025-11-04T14:55:10Z")

</div>

Hello, We are currently moving our Elastic Cloud stack to Elastic Serverless on AWS and having issues trying to output Logstash data up the new to Elastic Serverless. Following documentation, we are providing hosts URL…

---

## [Sql\_last\_value is updated only once](https://discuss.elastic.co/t/sql-last-value-is-updated-only-once/383194)

<div class="topic-metadata">

**Author:** [@chiel](https://discuss.elastic.co/u/chiel)\
**Replies:** 0\
**Last updated:** [November 4, 2025, 8:40am UTC](https://discuss.elastic.co/t/sql-last-value-is-updated-only-once/383194 "2025-11-04T08:40:29Z")

</div>

Hi, I’m using sql\_last\_value, last\_run\_metadata\_path, tracking\_column etc. for tracking the most recent value of a given column of my query. When I restart logstash, the value is updated correct in the tracking file (la…

---

## [Logstash output to Azure blobstorage](https://discuss.elastic.co/t/logstash-output-to-azure-blobstorage/383117)

<div class="topic-metadata">

**Author:** [@Kumar\_6](https://discuss.elastic.co/u/Kumar_6)\
**Replies:** 4\
**Last updated:** [October 31, 2025, 8:00am UTC](https://discuss.elastic.co/t/logstash-output-to-azure-blobstorage/383117 "2025-10-31T08:00:30Z")

</div>

Hi, everyone I have been looking over Internet in order to find a plugin for Logstash or FIlebeat in order to send data to azure blobstorage. i haven’t find it. as i see only s3 output is available. is azure blobstor…

---

## [Known Issue: Logstash 9.2.0 will not start with a Persistent Queue greater than 2GiB](https://discuss.elastic.co/t/known-issue-logstash-9-2-0-will-not-start-with-a-persistent-queue-greater-than-2gib/383079)

<div class="topic-metadata">

**Author:** [@RobBavey](https://discuss.elastic.co/u/RobBavey)\
**Replies:** 0\
**Last updated:** [October 29, 2025, 4:57pm UTC](https://discuss.elastic.co/t/known-issue-logstash-9-2-0-will-not-start-with-a-persistent-queue-greater-than-2gib/383079 "2025-10-29T16:57:59Z")

</div>

Logstash 9.2.0 has a known issue where Logstash will not start if a Persistent Queue has been defined with a size greater than 2 GiB. If you attempt to start Logstash 9.2.0 with any PQs where queue.max\_bytes has been se…

---

## [Logstash - Translate Use custom MIBS (OEM - Oracle Enterprise Manager)](https://discuss.elastic.co/t/logstash-translate-use-custom-mibs-oem-oracle-enterprise-manager/382915)

<div class="topic-metadata">

**Author:** [@Tal1](https://discuss.elastic.co/u/Tal1)\
**Replies:** 8\
**Last updated:** [October 23, 2025, 4:18pm UTC](https://discuss.elastic.co/t/logstash-translate-use-custom-mibs-oem-oracle-enterprise-manager/382915 "2025-10-23T16:18:41Z")

</div>

Greetings Experts, I hope someone will be able to help me with that issue. I’ve installed Logstash version 9.1.4 on linux redhat machine (version 9.5). logstash is up and running on port 162 receiving snmp trap v3 - e…

---

## [Elastic Agent to Logstash - how to access pipeline metadata](https://discuss.elastic.co/t/elastic-agent-to-logstash-how-to-access-pipeline-metadata/382874)

<div class="topic-metadata">

**Author:** [@username456](https://discuss.elastic.co/u/username456)\
**Replies:** 1\
**Last updated:** [October 22, 2025, 12:27pm UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash-how-to-access-pipeline-metadata/382874 "2025-10-22T12:27:50Z")

</div>

We’re setting up an Elastic Agent → Logstash → Elasticsearch architecture to leverage Logstash’s buffering capabilities, which ingest nodes don’t provide. Our goal is to route all Elastic Agent traffic through Logstash. …

---

## [Problem with quotes in csv filter](https://discuss.elastic.co/t/problem-with-quotes-in-csv-filter/382802)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 6\
**Last updated:** [October 18, 2025, 3:39pm UTC](https://discuss.elastic.co/t/problem-with-quotes-in-csv-filter/382802 "2025-10-18T15:39:46Z")

</div>

Hello, I'm having a problem with the csv plugin (seems the same problem as in this old (2018) article) Quoted strings within fields that do not contain the field separator are interpreted as fields, and this provokes a…

---

## [Elastic Agent: UDP package processing limits](https://discuss.elastic.co/t/elastic-agent-udp-package-processing-limits/382711)

<div class="topic-metadata">

**Author:** [@Phoenix2](https://discuss.elastic.co/u/Phoenix2)\
**Replies:** 5\
**Last updated:** [October 18, 2025, 1:55pm UTC](https://discuss.elastic.co/t/elastic-agent-udp-package-processing-limits/382711 "2025-10-18T13:55:53Z")

</div>

I am using the Elastic Agent with CEF integration, which receives and processes UDP data on a port. In the metrics for the cef integration, I see the value file-beat\_input.system\_packet\_drops . The integration discards …

---

## [Logstash pod failing to create pipeline due to error loading a ruby script](https://discuss.elastic.co/t/logstash-pod-failing-to-create-pipeline-due-to-error-loading-a-ruby-script/382757)

<div class="topic-metadata">

**Author:** [@lester\_slee](https://discuss.elastic.co/u/lester_slee)\
**Replies:** 7\
**Last updated:** [October 17, 2025, 1:47am UTC](https://discuss.elastic.co/t/logstash-pod-failing-to-create-pipeline-due-to-error-loading-a-ruby-script/382757 "2025-10-17T01:47:48Z")

</div>

I am seeing the below error in the logstash log when deploying an eck-logstash pod using Helm. The ruby script is added via a configMap and I have checked that the script has been mounted in the correct directory and has…

---

## [From XML to an index](https://discuss.elastic.co/t/from-xml-to-an-index/382770)

<div class="topic-metadata">

**Author:** [@Cristina\_Marletta\_Li](https://discuss.elastic.co/u/Cristina_Marletta_Li)\
**Replies:** 1\
**Last updated:** [October 16, 2025, 11:34am UTC](https://discuss.elastic.co/t/from-xml-to-an-index/382770 "2025-10-16T11:34:46Z")

</div>

Hi all, what is the simplest and most automatic way to load an index from an XML file containing many entries? The file looks like this: \<Events\> \<Event xmlns="\`\`http://schemas.microsoft.com/win/2004/08/events/event\`\`…

---

## [Logtssh Grok for Cisco ISE](https://discuss.elastic.co/t/logtssh-grok-for-cisco-ise/382057)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 11\
**Last updated:** [October 16, 2025, 10:59am UTC](https://discuss.elastic.co/t/logtssh-grok-for-cisco-ise/382057 "2025-10-16T10:59:32Z")

</div>

I have this Filter and its not parsing correctly , filter { match =\> { "message" =\> "\<%{INT:syslog\_pri}\>%{SYSLOGTIMESTAMP:syslog\_ts} %{HOSTNAME:host} %{WORD:module} %{INT:session\_id} %{INT:severity} %{INT:msg\_i…

---

## [Booting up logstash for the first time](https://discuss.elastic.co/t/booting-up-logstash-for-the-first-time/382581)

<div class="topic-metadata">

**Author:** [@hayatve](https://discuss.elastic.co/u/hayatve)\
**Replies:** 3\
**Last updated:** [October 10, 2025, 2:30pm UTC](https://discuss.elastic.co/t/booting-up-logstash-for-the-first-time/382581 "2025-10-10T14:30:50Z")

</div>

Hello, I’m trying to setup the ELK-Stack on my laptop. Elasticsearch and Kibana is running through the browser. I can’t figure out to setup logstash properly tho.I run into the same error, which is: "Using bundled JDK: …

---

## [Logstash s3-input using a VPC accesspoint](https://discuss.elastic.co/t/logstash-s3-input-using-a-vpc-accesspoint/382555)

<div class="topic-metadata">

**Author:** [@dazoakley](https://discuss.elastic.co/u/dazoakley)\
**Replies:** 0\
**Last updated:** [October 9, 2025, 1:16pm UTC](https://discuss.elastic.co/t/logstash-s3-input-using-a-vpc-accesspoint/382555 "2025-10-09T13:16:17Z")

</div>

Hi folks, I’m trying to configure logstash to watch some files in an S3 bucket, but the restriction I have is that we’re only allowed access via VPC AccessPoints. Is there a way to configure logstash to do this? I’ve t…

---

## [Getting a eror to maintain the log order](https://discuss.elastic.co/t/getting-a-eror-to-maintain-the-log-order/382536)

<div class="topic-metadata">

**Author:** [@Waris\_Amir](https://discuss.elastic.co/u/Waris_Amir)\
**Replies:** 0\
**Last updated:** [October 9, 2025, 5:50am UTC](https://discuss.elastic.co/t/getting-a-eror-to-maintain-the-log-order/382536 "2025-10-09T05:50:33Z")

</div>

I’m trying to ingest the logs in the filebeat , by Default it support millisecond precision so I try to add another field in my logs then explicity passing it into filebeats At the server, i m having the logstash which …

---

## [Getting Connection timed out error in logstash](https://discuss.elastic.co/t/getting-connection-timed-out-error-in-logstash/382218)

<div class="topic-metadata">

**Author:** [@upreddy253](https://discuss.elastic.co/u/upreddy253)\
**Replies:** 4\
**Last updated:** [October 9, 2025, 4:03am UTC](https://discuss.elastic.co/t/getting-connection-timed-out-error-in-logstash/382218 "2025-10-09T04:03:06Z")

</div>

Hi All, I have created one logstash pipeline using rabbitmq input plugin. But i am getting below error. \[ERROR\] 2025-09-25 09:35:08.167 \[\[prabbitmq\]\<rabbitmq\] rabbitmq - RabbitMQ connection error, will retry {:exceptio…

---

## [Getting rabbitmq connection error](https://discuss.elastic.co/t/getting-rabbitmq-connection-error/382517)

<div class="topic-metadata">

**Author:** [@upreddy253](https://discuss.elastic.co/u/upreddy253)\
**Replies:** 1\
**Last updated:** [October 8, 2025, 10:05am UTC](https://discuss.elastic.co/t/getting-rabbitmq-connection-error/382517 "2025-10-08T10:05:06Z")

</div>

Hi, We are using logstash version 9.1.2 and we are trying to connect with rabbitmq server using rabbitmq logstash input plugin but we are getting below error in logstash. \[ERROR\] 2025-10-07 06:20:57.286 \[\[prabbitmq\]\<ra…

---

## [Sending logs from SAP HANA to logstash using JJDBC](https://discuss.elastic.co/t/sending-logs-from-sap-hana-to-logstash-using-jjdbc/382475)

<div class="topic-metadata">

**Author:** [@Saad\_khattak](https://discuss.elastic.co/u/Saad_khattak)\
**Replies:** 1\
**Last updated:** [October 7, 2025, 3:01pm UTC](https://discuss.elastic.co/t/sending-logs-from-sap-hana-to-logstash-using-jjdbc/382475 "2025-10-07T15:01:22Z")

</div>

So i want to get security logs from SAP HANA database for that as of my research i am going to use JDBC with logstach the jdbc will query the HANA database and store logs in the logstash from logstash it will be sent to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=1)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=3)
