# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=21

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 22

---

## [Logstash csv filter unable to handle newline in CSV](https://discuss.elastic.co/t/logstash-csv-filter-unable-to-handle-newline-in-csv/366328)

<div class="topic-metadata">

**Author:** [@Lee\_Li\_Xiong](https://discuss.elastic.co/u/Lee_Li_Xiong)\
**Replies:** 5\
**Last updated:** [September 10, 2024, 4:31pm UTC](https://discuss.elastic.co/t/logstash-csv-filter-unable-to-handle-newline-in-csv/366328 "2024-09-10T16:31:45Z")

</div>

Hello, i have a csv data with newline in some of the column data. Whenever the data start with ", it contain newline. testing2.csv date,name,address 5/23/2024,"Lee123 Hello3",Tanjung789 5/24/2024,Lee124,Tanjung790 5/…

---

## [Can’t collect Check Point FW Logs, via TCP over TLS](https://discuss.elastic.co/t/can-t-collect-check-point-fw-logs-via-tcp-over-tls/366294)

<div class="topic-metadata">

**Author:** [@lga1](https://discuss.elastic.co/u/lga1)\
**Replies:** 8\
**Last updated:** [September 10, 2024, 2:53pm UTC](https://discuss.elastic.co/t/can-t-collect-check-point-fw-logs-via-tcp-over-tls/366294 "2024-09-10T14:53:36Z")

</div>

Hello, I’m new in the elastic community. I’d like to collect logs from a Check Point firewall, with Logstash. I use Elasticsearch, Kibana and Logstash. The infrastructure is running, communications are working between …

---

## [Logstash Keystore not working when running logstash as a service](https://discuss.elastic.co/t/logstash-keystore-not-working-when-running-logstash-as-a-service/366230)

<div class="topic-metadata">

**Author:** [@Raven\_Music](https://discuss.elastic.co/u/Raven_Music)\
**Replies:** 2\
**Last updated:** [September 10, 2024, 1:43pm UTC](https://discuss.elastic.co/t/logstash-keystore-not-working-when-running-logstash-as-a-service/366230 "2024-09-10T13:43:56Z")

</div>

Hi, I'm trying to store the hosts and the logstash\_user password in a keystore in my logstash conf.d output. I have a Ubuntu 22 system. The keystore works perfectly fine with my testconfig when I run logstash like this, …

---

## [Cannot get started with development of a Logstash plugin: README incorrect?](https://discuss.elastic.co/t/cannot-get-started-with-development-of-a-logstash-plugin-readme-incorrect/365771)

<div class="topic-metadata">

**Author:** [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Replies:** 4\
**Last updated:** [September 9, 2024, 6:10pm UTC](https://discuss.elastic.co/t/cannot-get-started-with-development-of-a-logstash-plugin-readme-incorrect/365771 "2024-09-09T18:10:00Z")

</div>

I'm new to Ruby and Rails, so go easy on me :slight\_smile: Maybe I'm missing something that's completely obvious to an experienced Ruby developer but not to this guy with 20 years on Java :man\_shrugging: The README info…

---

## [Logstash deployment in scale to check readiness and liveness probe](https://discuss.elastic.co/t/logstash-deployment-in-scale-to-check-readiness-and-liveness-probe/366213)

<div class="topic-metadata">

**Author:** [@aws.learning](https://discuss.elastic.co/u/aws.learning)\
**Replies:** 2\
**Last updated:** [September 8, 2024, 8:04pm UTC](https://discuss.elastic.co/t/logstash-deployment-in-scale-to-check-readiness-and-liveness-probe/366213 "2024-09-08T20:04:14Z")

</div>

We need to tweak the liveness and readiness probe checks For this I deploy one pod and tweak the readiness and liveness probe values ..But filebeat and syslogs are not flowing

---

## [ElasticSearch Cluster: Logstash works, but does not show up on kibana dashboard](https://discuss.elastic.co/t/elasticsearch-cluster-logstash-works-but-does-not-show-up-on-kibana-dashboard/366205)

<div class="topic-metadata">

**Author:** [@tripoli](https://discuss.elastic.co/u/tripoli)\
**Replies:** 0\
**Last updated:** [September 8, 2024, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-logstash-works-but-does-not-show-up-on-kibana-dashboard/366205 "2024-09-08T13:41:35Z")

</div>

Hi, I'm creating a cluster with elasticsearch (2 elastic nodes and a kibana/logstash/filebeat node). Logstash "apparently" seems to work because filebeat sends the data to logstash and consequently logstash sends them …

---

## [Deploying Logstash on ECK returns "Your settings are invalid. Reason: Setting "logstash.yml" doesn't exist. Please check if you haven't made a typo."](https://discuss.elastic.co/t/deploying-logstash-on-eck-returns-your-settings-are-invalid-reason-setting-logstash-yml-doesnt-exist-please-check-if-you-havent-made-a-typo/366203)

<div class="topic-metadata">

**Author:** [@Iftachby](https://discuss.elastic.co/u/Iftachby)\
**Replies:** 0\
**Last updated:** [September 8, 2024, 11:31am UTC](https://discuss.elastic.co/t/deploying-logstash-on-eck-returns-your-settings-are-invalid-reason-setting-logstash-yml-doesnt-exist-please-check-if-you-havent-made-a-typo/366203 "2024-09-08T11:31:26Z")

</div>

Hey Im new to Logstash/ECK Ive tried deploying an ECK cluster and then deploying Logstash, using ArgoCD. The ECK works well, for the Logstash I'm having issues with the statefulset. it returns the error; Your setting…

---

## [Logstash JDBC Inputs SQL Connections are never closed](https://discuss.elastic.co/t/logstash-jdbc-inputs-sql-connections-are-never-closed/366160)

<div class="topic-metadata">

**Author:** [@lkouts](https://discuss.elastic.co/u/lkouts)\
**Replies:** 3\
**Last updated:** [September 6, 2024, 7:20pm UTC](https://discuss.elastic.co/t/logstash-jdbc-inputs-sql-connections-are-never-closed/366160 "2024-09-06T19:20:05Z")

</div>

Hey Folks, I have a logstash configuration that has 10 jdbc inputs connecting to the same SQL Server but to diffrent databases. Scheduler is set to run every 2 minutes. All works correctly however the SQL Connections ar…

---

## [Logstash won't start due to memory heap issue](https://discuss.elastic.co/t/logstash-wont-start-due-to-memory-heap-issue/366069)

<div class="topic-metadata">

**Author:** [@Carolina\_Molina](https://discuss.elastic.co/u/Carolina_Molina)\
**Replies:** 10\
**Last updated:** [September 6, 2024, 11:35am UTC](https://discuss.elastic.co/t/logstash-wont-start-due-to-memory-heap-issue/366069 "2024-09-06T11:35:23Z")

</div>

Hello, I have a instance running logstsh 6.8.2 with Java 11.0.19 and JDK of 64Bits, I changed the filter file do add conditions and terraform logstash to the correct environment. After that logstash refused to start giv…

---

## [Help with filter to create Latitude and Longitude fields](https://discuss.elastic.co/t/help-with-filter-to-create-latitude-and-longitude-fields/366075)

<div class="topic-metadata">

**Author:** [@Big-Edd](https://discuss.elastic.co/u/Big-Edd)\
**Replies:** 1\
**Last updated:** [September 5, 2024, 4:04am UTC](https://discuss.elastic.co/t/help-with-filter-to-create-latitude-and-longitude-fields/366075 "2024-09-05T04:04:17Z")

</div>

Hello, Can I please have some help with a filter for this sample data? { "took": 319, "timed\_out": false, "\_shards": { "total": 1, "successful": 1, "skipped": 0, "failed": 0 …

---

## [Logstash radius decoder](https://discuss.elastic.co/t/logstash-radius-decoder/366063)

<div class="topic-metadata">

**Author:** [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Replies:** 0\
**Last updated:** [September 4, 2024, 6:25pm UTC](https://discuss.elastic.co/t/logstash-radius-decoder/366063 "2024-09-04T18:25:13Z")

</div>

hi guys, im trying to decode radius udp packets, using udp input with plain codec i just see gibberish, y found this ruby gem can anyone tell me if it would be possible to decode packets using that ruby gem? or any other…

---

## [S3-plugin logstash “Exception: Aws::S3::Errors::NotFound plugin had an unrecoverable error. Will restart this plugin](https://discuss.elastic.co/t/s3-plugin-logstash-exception-aws-notfound-plugin-had-an-unrecoverable-error-will-restart-this-plugin/366045)

<div class="topic-metadata">

**Author:** [@vincentm](https://discuss.elastic.co/u/vincentm)\
**Replies:** 0\
**Last updated:** [September 4, 2024, 3:23pm UTC](https://discuss.elastic.co/t/s3-plugin-logstash-exception-aws-notfound-plugin-had-an-unrecoverable-error-will-restart-this-plugin/366045 "2024-09-04T15:23:09Z")

</div>

Hi all, i have exactly the same error than this topic : Then i want to have some information about this problem and how to resolve it. Because, even if my logstash process restart alone, the problem is that just after…

---

## [Sending multiple events using a single POST with http output codec](https://discuss.elastic.co/t/sending-multiple-events-using-a-single-post-with-http-output-codec/365857)

<div class="topic-metadata">

**Author:** [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Replies:** 11\
**Last updated:** [September 3, 2024, 5:12pm UTC](https://discuss.elastic.co/t/sending-multiple-events-using-a-single-post-with-http-output-codec/365857 "2024-09-03T17:12:56Z")

</div>

Good Day, How do you send multiple events in a single POST using the http output codec? I can send the below events but they are sent as 2 individual POSTS and I need to send them as a single post due to restrictions o…

---

## [Fetch logs from MSSQL using logstash input plugin](https://discuss.elastic.co/t/fetch-logs-from-mssql-using-logstash-input-plugin/365807)

<div class="topic-metadata">

**Author:** [@Shivam\_Goyal](https://discuss.elastic.co/u/Shivam_Goyal)\
**Replies:** 2\
**Last updated:** [September 3, 2024, 3:19pm UTC](https://discuss.elastic.co/t/fetch-logs-from-mssql-using-logstash-input-plugin/365807 "2024-09-03T15:19:59Z")

</div>

Hello, I am using Logstash to fetch logs from MSSQL. We need to use domain account which can be used for authentication and to fetch the logs. Can anyone please help how we can use it in input plugin?

---

## [Sincedb and rsync - it's not a solution](https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [September 3, 2024, 12:55pm UTC](https://discuss.elastic.co/t/sincedb-and-rsync-its-not-a-solution/365822 "2024-09-03T12:55:36Z")

</div>

Hi Is there any chance to config some parameters for sincedb for read file only for name, I have updated folder with the second server over rsync and after synchronization data structure are overwrite like inode and etc…

---

## [Logstash doesnt send logs to elasticsearch OR filebeat doesnt send logs to logstash](https://discuss.elastic.co/t/logstash-doesnt-send-logs-to-elasticsearch-or-filebeat-doesnt-send-logs-to-logstash/365931)

<div class="topic-metadata">

**Author:** [@jakub0011](https://discuss.elastic.co/u/jakub0011)\
**Replies:** 1\
**Last updated:** [September 3, 2024, 9:37am UTC](https://discuss.elastic.co/t/logstash-doesnt-send-logs-to-elasticsearch-or-filebeat-doesnt-send-logs-to-logstash/365931 "2024-09-03T09:37:58Z")

</div>

Hi, i have elasticsearch cluster with: logstash 7.17.18 kibana 7.17.18 elasticsearch 7.17.18 filebeat 7.10 Everything worked fine for a month, but for the past 2 days not all logs are being sent to Elasticsearch fro…

---

## [Logstash Access Denied Error Encountered with AWS S3](https://discuss.elastic.co/t/logstash-access-denied-error-encountered-with-aws-s3/365929)

<div class="topic-metadata">

**Author:** [@rui\_1](https://discuss.elastic.co/u/rui_1)\
**Replies:** 0\
**Last updated:** [September 3, 2024, 6:56am UTC](https://discuss.elastic.co/t/logstash-access-denied-error-encountered-with-aws-s3/365929 "2024-09-03T06:56:58Z")

</div>

Hi can anyone please help to see what is possibly causing this error? I have not changed any of my AWS user or role policy, neither is there any explicit deny nor changes to logstash config. The error suddenly came aft…

---

## [Logstash input Salesforce still alive? Process for abandoned plugin projects?](https://discuss.elastic.co/t/logstash-input-salesforce-still-alive-process-for-abandoned-plugin-projects/361928)

<div class="topic-metadata">

**Author:** [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Replies:** 6\
**Last updated:** [September 3, 2024, 6:55am UTC](https://discuss.elastic.co/t/logstash-input-salesforce-still-alive-process-for-abandoned-plugin-projects/361928 "2024-09-03T06:55:27Z")

</div>

Hi all, There's a PR on the logstash-input-salesforce plugin that I would really love to be merged and included into the main release of that plugin, but the project seems to have been abandoned: no changes have happene…

---

## [Parse stringified json from syslog 3164 events](https://discuss.elastic.co/t/parse-stringified-json-from-syslog-3164-events/365877)

<div class="topic-metadata">

**Author:** [@Mark\_V](https://discuss.elastic.co/u/Mark_V)\
**Replies:** 3\
**Last updated:** [September 2, 2024, 8:38am UTC](https://discuss.elastic.co/t/parse-stringified-json-from-syslog-3164-events/365877 "2024-09-02T08:38:38Z")

</div>

Hi, I'm pretty new to the elastic stack so please excuse any newbie-level ignorance. Im shipping data from my splunk environment to logstash using the methods detailed in the Splunk Forward data to third-party systems.…

---

## [Grok The correct syntax to match against multiple patterns](https://discuss.elastic.co/t/grok-the-correct-syntax-to-match-against-multiple-patterns/365854)

<div class="topic-metadata">

**Author:** [@Dhiwakar\_Ravikumar](https://discuss.elastic.co/u/Dhiwakar_Ravikumar)\
**Replies:** 1\
**Last updated:** [August 31, 2024, 2:57pm UTC](https://discuss.elastic.co/t/grok-the-correct-syntax-to-match-against-multiple-patterns/365854 "2024-08-31T14:57:13Z")

</div>

I have an event whose message field I want to match against multiple patterns, if the message matches any of the patterns, then simply stop searching the remaining patterns in the list/array and write to output. For ref…

---

## [How to convert hex to ascii in logstash?](https://discuss.elastic.co/t/how-to-convert-hex-to-ascii-in-logstash/365803)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [August 30, 2024, 12:17pm UTC](https://discuss.elastic.co/t/how-to-convert-hex-to-ascii-in-logstash/365803 "2024-08-30T12:17:21Z")

</div>

Hello. I want to convert hex data to ascii so I tried several ways on the logstash.config file. My reference document is here. But it doesn't work for me. There's a error likes 'undefined method pack' . My source data…

---

## [Parser fails when it encounters a newline / Parser falla cuando encuentra un salto de linea](https://discuss.elastic.co/t/parser-fails-when-it-encounters-a-newline-parser-falla-cuando-encuentra-un-salto-de-linea/365718)

<div class="topic-metadata">

**Author:** [@Roberto\_Soto](https://discuss.elastic.co/u/Roberto_Soto)\
**Replies:** 2\
**Last updated:** [August 30, 2024, 3:05am UTC](https://discuss.elastic.co/t/parser-fails-when-it-encounters-a-newline-parser-falla-cuando-encuentra-un-salto-de-linea/365718 "2024-08-30T03:05:44Z")

</div>

hi, i have a problem when a ln or \\n exist in message text. my filter grok is match=\>{"message" =\> "\<%{DATA:timestamp}\> \<%{WORD:Severity}\> \<%{WORD:Subsystem}\> \<%{HOSTNAME:ServerName}\> \<%{HOSTNAME:Instancia}\> \<%{DATA:Thr…

---

## [Invalid FieldReference: \`\[\]\` for CSV somehow persists even after using mutate gsub](https://discuss.elastic.co/t/invalid-fieldreference-for-csv-somehow-persists-even-after-using-mutate-gsub/365763)

<div class="topic-metadata">

**Author:** [@canifer](https://discuss.elastic.co/u/canifer)\
**Replies:** 4\
**Last updated:** [August 29, 2024, 11:02pm UTC](https://discuss.elastic.co/t/invalid-fieldreference-for-csv-somehow-persists-even-after-using-mutate-gsub/365763 "2024-08-29T23:02:28Z")

</div>

Hello, I need help about sending CSV from filebeat into logstash. The error is "Invalid FieldReference: \[\]" I tried this solution but it doesn't work. (the thread is closed so I ma sorry for opening new topic) This is…

---

## [Logstash-input-azureblob Fails to Install with Error](https://discuss.elastic.co/t/logstash-input-azureblob-fails-to-install-with-error/364854)

<div class="topic-metadata">

**Author:** [@nickcat](https://discuss.elastic.co/u/nickcat)\
**Replies:** 6\
**Last updated:** [August 29, 2024, 3:01pm UTC](https://discuss.elastic.co/t/logstash-input-azureblob-fails-to-install-with-error/364854 "2024-08-29T15:01:11Z")

</div>

$ sudo /usr/share/logstash/bin/logstash-plugin install logstash-input-azureblob Using bundled JDK: /usr/share/logstash/jdk Validating logstash-input-azureblob Resolving mixin dependencies WARN: Unresolved or ambiguou…

---

## [Retry on failure mechanism in logstash-bigquery filter plugin](https://discuss.elastic.co/t/retry-on-failure-mechanism-in-logstash-bigquery-filter-plugin/365719)

<div class="topic-metadata">

**Author:** [@Deena\_Dayalan](https://discuss.elastic.co/u/Deena_Dayalan)\
**Replies:** 4\
**Last updated:** [August 29, 2024, 12:45pm UTC](https://discuss.elastic.co/t/retry-on-failure-mechanism-in-logstash-bigquery-filter-plugin/365719 "2024-08-29T12:45:35Z")

</div>

Recently, I encountered an issue where events uploads to BigQuery from Logstash failed with a BigQueryException: The service is currently unavailable error. My concern is that valid events might fail due to BigQuery ser…

---

## [Logstash config parameter to handle large messages from rsyslog server](https://discuss.elastic.co/t/logstash-config-parameter-to-handle-large-messages-from-rsyslog-server/365757)

<div class="topic-metadata">

**Author:** [@mansoorpn](https://discuss.elastic.co/u/mansoorpn)\
**Replies:** 6\
**Last updated:** [August 29, 2024, 12:29pm UTC](https://discuss.elastic.co/t/logstash-config-parameter-to-handle-large-messages-from-rsyslog-server/365757 "2024-08-29T12:29:26Z")

</div>

Hello Team Developers use on the device a conf with a max size of 65MB because of bigger core dumps. $MaxMessageSize 65536k What will be the logstash configuration parameter to handle these big-size messages? our curr…

---

## [Multiple file inputs cause re-reading of file](https://discuss.elastic.co/t/multiple-file-inputs-cause-re-reading-of-file/365276)

<div class="topic-metadata">

**Author:** [@henning\_l](https://discuss.elastic.co/u/henning_l)\
**Replies:** 6\
**Last updated:** [August 29, 2024, 11:18am UTC](https://discuss.elastic.co/t/multiple-file-inputs-cause-re-reading-of-file/365276 "2024-08-29T11:18:21Z")

</div>

I am running an ELK stack and tailoring the Logstash configurations to elicit data from several different logs. Because the logs are formatted differently I need to create multiple file inputs. The following is the curre…

---

## [Elastic agent input gives bad\_certificate in Logstash](https://discuss.elastic.co/t/elastic-agent-input-gives-bad-certificate-in-logstash/365748)

<div class="topic-metadata">

**Author:** [@Alessio\_Creo](https://discuss.elastic.co/u/Alessio_Creo)\
**Replies:** 0\
**Last updated:** [August 29, 2024, 9:13am UTC](https://discuss.elastic.co/t/elastic-agent-input-gives-bad-certificate-in-logstash/365748 "2024-08-29T09:13:47Z")

</div>

Hi, following step-by-step the following guide We can't connect the elastic agent to Logstash because of a bad\_certificate error. We have basic License but we set the Logstash output as default. Please let me know w…

---

## [Error with multiple values in ssl\_certificate\_authorities for elasticsearch output](https://discuss.elastic.co/t/error-with-multiple-values-in-ssl-certificate-authorities-for-elasticsearch-output/365708)

<div class="topic-metadata">

**Author:** [@pk92](https://discuss.elastic.co/u/pk92)\
**Replies:** 2\
**Last updated:** [August 29, 2024, 7:23am UTC](https://discuss.elastic.co/t/error-with-multiple-values-in-ssl-certificate-authorities-for-elasticsearch-output/365708 "2024-08-29T07:23:16Z")

</div>

Hi, when I put a list with multiple elements in "ssl\_certificate\_authorities" for the Elasticsearch output of the Logstash pipeline, like this: output { elasticsearch { hosts =\> \["htt…

---

## [How to use Logstash to perform multi-attribute missing tagging on log data?](https://discuss.elastic.co/t/how-to-use-logstash-to-perform-multi-attribute-missing-tagging-on-log-data/365651)

<div class="topic-metadata">

**Author:** [@WeirdorPersist](https://discuss.elastic.co/u/WeirdorPersist)\
**Replies:** 2\
**Last updated:** [August 29, 2024, 2:00am UTC](https://discuss.elastic.co/t/how-to-use-logstash-to-perform-multi-attribute-missing-tagging-on-log-data/365651 "2024-08-29T02:00:51Z")

</div>

I want to mark log data with missing attributes, but the results always do not match my expectations. The following is an example of normal log data： 14.49.42.25 - - \[12/May/2019:01:24:44 +0000\] "GET /articles/ppp-over…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=20)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=22)
