# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=216

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 217

---

## [Logstash does not read 1st line of file which the header](https://discuss.elastic.co/t/logstash-does-not-read-1st-line-of-file-which-the-header/277035)

<div class="topic-metadata">

**Author:** [@Julius\_Gamboa](https://discuss.elastic.co/u/Julius_Gamboa)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 9:58am UTC](https://discuss.elastic.co/t/logstash-does-not-read-1st-line-of-file-which-the-header/277035 "2021-06-25T09:58:05Z")

</div>

Hi, I am using logstash to ingest a pipe delimited file into elasticsearch. I am using the autodetect\_column\_names in the csv filter. Noticed when I run logstash, I get the following warnings below: \[2021-06-25T16:48:3…

---

## [Logstash "Received fatal alert : bad\_certificate"](https://discuss.elastic.co/t/logstash-received-fatal-alert-bad-certificate/277032)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 8:51am UTC](https://discuss.elastic.co/t/logstash-received-fatal-alert-bad-certificate/277032 "2021-06-25T08:51:50Z")

</div>

Hello, I setup TLS on Elasticsearch, kibana, logstash and filebeat. I don't know if it comes from the configuration of logstash or filebeat. I have a cluster of 3 elastic nodes, logstash and filebeat are on node1. Th…

---

## [How can i replace multiple special characters in all fields?](https://discuss.elastic.co/t/how-can-i-replace-multiple-special-characters-in-all-fields/276922)

<div class="topic-metadata">

**Author:** [@alprde](https://discuss.elastic.co/u/alprde)\
**Replies:** 2\
**Last updated:** [June 25, 2021, 7:58am UTC](https://discuss.elastic.co/t/how-can-i-replace-multiple-special-characters-in-all-fields/276922 "2021-06-25T07:58:24Z")

</div>

&Ccedil; =\> Ç &ccedil; =\> ç &#350; =\> Ş &#351; =\> ş &#304; =\> İ &#305; =\> ı &Uuml; =\> Ü &uuml; =\> ü &Ouml; =\> Ö &ouml; =\> ö &#286; =\> Ğ &#287; =\> ğ I want to replace these characters in all fields. how can I …

---

## [Elasticsearch not saving all fields from logstash](https://discuss.elastic.co/t/elasticsearch-not-saving-all-fields-from-logstash/276957)

<div class="topic-metadata">

**Author:** [@mlassnig\_no](https://discuss.elastic.co/u/mlassnig_no)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 7:50am UTC](https://discuss.elastic.co/t/elasticsearch-not-saving-all-fields-from-logstash/276957 "2021-06-25T07:50:14Z")

</div>

I got following situation: Im sending logs from my servers to logstash using filebeat. Im running a logstash pipeline that looks like this: input { beats { port =\> 5003 } } filter { grok { match =\> …

---

## [How can I start logstash from a script](https://discuss.elastic.co/t/how-can-i-start-logstash-from-a-script/277010)

<div class="topic-metadata">

**Author:** [@Mbartlett413](https://discuss.elastic.co/u/Mbartlett413)\
**Replies:** 2\
**Last updated:** [June 25, 2021, 5:30am UTC](https://discuss.elastic.co/t/how-can-i-start-logstash-from-a-script/277010 "2021-06-25T05:30:51Z")

</div>

Background: I have logstash and elasticsearch running on a server. I have a rails application which uploads a CSV to the server and logstash then processes. It works if I manually execute the generated script. If I try t…

---

## [Elasticsearch \_update\_by\_query in logstash error \[HTTP Output Failure\] Encountered non-2xx HTTP code 400](https://discuss.elastic.co/t/elasticsearch-update-by-query-in-logstash-error-http-output-failure-encountered-non-2xx-http-code-400/274405)

<div class="topic-metadata">

**Author:** [@priyaankaa](https://discuss.elastic.co/u/priyaankaa)\
**Replies:** 1\
**Last updated:** [June 25, 2021, 5:40am UTC](https://discuss.elastic.co/t/elasticsearch-update-by-query-in-logstash-error-http-output-failure-encountered-non-2xx-http-code-400/274405 "2021-06-25T05:40:42Z")

</div>

Properly working \_update\_by\_query call - POST /s1test-demo7/\_update\_by\_query { "script": { "source": "ctx.\_source.externaldata = params.externaldata", "lang": "painless", "params": { "externa…

---

## [Lost All Indices After Adding Additional Pipelines](https://discuss.elastic.co/t/lost-all-indices-after-adding-additional-pipelines/276858)

<div class="topic-metadata">

**Author:** [@Steve\_K](https://discuss.elastic.co/u/Steve_K)\
**Replies:** 2\
**Last updated:** [June 24, 2021, 1:58pm UTC](https://discuss.elastic.co/t/lost-all-indices-after-adding-additional-pipelines/276858 "2021-06-24T13:58:08Z")

</div>

So after I cleared all of the indices and added an additional method to my pipeline configuration, my indices will not repopulate. I have added my code below for the original configuration and then reconfiguration. Ori…

---

## [Grok parser on amount of characters](https://discuss.elastic.co/t/grok-parser-on-amount-of-characters/276924)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 1\
**Last updated:** [June 24, 2021, 2:40pm UTC](https://discuss.elastic.co/t/grok-parser-on-amount-of-characters/276924 "2021-06-24T14:40:33Z")

</div>

Hi, I want to grok match on a sting where the first part contains 3 letters. For example: BUR-TEST-TEST-TEST I want to check that the first part contains 3 charachters (in this case BUR). is that possible with grok m…

---

## [Unokowns characters](https://discuss.elastic.co/t/unokowns-characters/276932)

<div class="topic-metadata">

**Author:** [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Replies:** 0\
**Last updated:** [June 24, 2021, 1:29pm UTC](https://discuss.elastic.co/t/unokowns-characters/276932 "2021-06-24T13:29:54Z")

</div>

Hi everyone. The file I'm reading with filebeat has special character that create problem with logstash Here an example (I know that the image are annoying but is the only way to show you the problem) There is a wa…

---

## [Logstash-plugin-s3 Error: Net::OpenTimeout](https://discuss.elastic.co/t/logstash-plugin-s3-error-net-opentimeout/276890)

<div class="topic-metadata">

**Author:** [@xiaoloutingfengyu](https://discuss.elastic.co/u/xiaoloutingfengyu)\
**Replies:** 0\
**Last updated:** [June 24, 2021, 8:27am UTC](https://discuss.elastic.co/t/logstash-plugin-s3-error-net-opentimeout/276890 "2021-06-24T08:27:23Z")

</div>

\[2021-05-26T10:19:43,686\]\[ERROR\]\[logstash.javapipeline \]\[main\]\[9a2225c4d3e20a639cd009e56ba032fdbc47fc0df0134b087544ef4ed11a3aea\] A plugin had an unrecoverable error. Will restart this plugin. Pipeline\_id:main Plugin…

---

## [Logstash problem with images](https://discuss.elastic.co/t/logstash-problem-with-images/276011)

<div class="topic-metadata">

**Author:** [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Replies:** 11\
**Last updated:** [June 24, 2021, 7:29am UTC](https://discuss.elastic.co/t/logstash-problem-with-images/276011 "2021-06-24T07:29:30Z")

</div>

Hi evrey one, I'am new with elasticsearch and logstash. The problem: I want to use logstash to obtain all image of a file system structure, (I don't need the immage i only need the informetion (Like: path, name)) but w…

---

## [Insert GeoIP processor code in Logstash Filtering](https://discuss.elastic.co/t/insert-geoip-processor-code-in-logstash-filtering/276884)

<div class="topic-metadata">

**Author:** [@valhalla](https://discuss.elastic.co/u/valhalla)\
**Replies:** 0\
**Last updated:** [June 24, 2021, 7:14am UTC](https://discuss.elastic.co/t/insert-geoip-processor-code-in-logstash-filtering/276884 "2021-06-24T07:14:30Z")

</div>

Hi team, How can I add this geoip processor within Logstash's filtering? I.e Filter { Mutate{ ... }} In general you need first to mannualy add this pipeline to Kibana, I want to skip this mannualy adding …

---

## [Logstash file: how to read first line only](https://discuss.elastic.co/t/logstash-file-how-to-read-first-line-only/276122)

<div class="topic-metadata">

**Author:** [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Replies:** 5\
**Last updated:** [June 24, 2021, 7:25am UTC](https://discuss.elastic.co/t/logstash-file-how-to-read-first-line-only/276122 "2021-06-24T07:25:53Z")

</div>

Hi evreyone. I wanted to know if it's possible to read only the first line of a file and exit (after send information to elastisearch) Thanks in advance

---

## [Logstash problem with \\](https://discuss.elastic.co/t/logstash-problem-with/276775)

<div class="topic-metadata">

**Author:** [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Replies:** 2\
**Last updated:** [June 24, 2021, 6:47am UTC](https://discuss.elastic.co/t/logstash-problem-with/276775 "2021-06-24T06:47:38Z")

</div>

Hi every one, I want to put the values inside a path in some field. I want to split the path so i can take every value inside it but i can't split with \\ because is a special character. I tried to replace \\ with / but …

---

## [Logstash 7.10.x version does not start](https://discuss.elastic.co/t/logstash-7-10-x-version-does-not-start/275178)

<div class="topic-metadata">

**Author:** [@Ramya\_Ramamurthy1](https://discuss.elastic.co/u/Ramya_Ramamurthy1)\
**Replies:** 3\
**Last updated:** [June 24, 2021, 6:06am UTC](https://discuss.elastic.co/t/logstash-7-10-x-version-does-not-start/275178 "2021-06-24T06:06:51Z")

</div>

I have downloaded the .tar.gz file and tried bringing up logstash through the logstash script. I am unable to bring up any of the 7.10.2 versions of logstash with the below error. I see posts about the permissions of th…

---

## [Logstash error on new install](https://discuss.elastic.co/t/logstash-error-on-new-install/276819)

<div class="topic-metadata">

**Author:** [@scott2](https://discuss.elastic.co/u/scott2)\
**Replies:** 4\
**Last updated:** [June 23, 2021, 7:47pm UTC](https://discuss.elastic.co/t/logstash-error-on-new-install/276819 "2021-06-23T19:47:02Z")

</div>

I installed logstash 7.13.2 and i'm getting a couple configuration errors that I cannot seem to find the cause. \</\> Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"Log…

---

## [Solved: Logstash Is Receiving Data From Winlogbeat But Isn't Showing In Kibana](https://discuss.elastic.co/t/solved-logstash-is-receiving-data-from-winlogbeat-but-isnt-showing-in-kibana/276827)

<div class="topic-metadata">

**Author:** [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Replies:** 0\
**Last updated:** [June 23, 2021, 5:18pm UTC](https://discuss.elastic.co/t/solved-logstash-is-receiving-data-from-winlogbeat-but-isnt-showing-in-kibana/276827 "2021-06-23T17:18:01Z")

</div>

EDIT: I have found a solution to the problem so I am going to post it here just in case anyone else runs into the same issue. The thing that was missing from my config file was a way to specify the index. I don't underst…

---

## [Ruby exceptions logstash](https://discuss.elastic.co/t/ruby-exceptions-logstash/276829)

<div class="topic-metadata">

**Author:** [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Replies:** 1\
**Last updated:** [June 23, 2021, 6:19pm UTC](https://discuss.elastic.co/t/ruby-exceptions-logstash/276829 "2021-06-23T18:19:24Z")

</div>

Hi all, i'm in trouble with Ruby exceptions i get 2 types of exceptions: \[ERROR\]\[logstash.filters.ruby \]\[windows-patching\]\[7da18e5397d31e1f8d249dc2ef273bcbcc32d26e064f064c3138ef1bcbc3c2a0\] Ruby exception occurred: …

---

## [Adding prefex to the field extracted via KV plugin](https://discuss.elastic.co/t/adding-prefex-to-the-field-extracted-via-kv-plugin/276621)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 3\
**Last updated:** [June 23, 2021, 5:18pm UTC](https://discuss.elastic.co/t/adding-prefex-to-the-field-extracted-via-kv-plugin/276621 "2021-06-23T17:18:55Z")

</div>

Hello every body, Apr 1 15:00:01 pc-tst cft: 21/04/20 00:00:00 CFTC12I IDTU=A0007GK PART=LKOR STATE=Y PHASE=Y PHASESTEP=C DIRECT=S TYPE=F SENTINEL\_STATE=POST\_PROC Deleted Is there a method to rename the fields extr…

---

## [Logstash Per Pipeline logs update?](https://discuss.elastic.co/t/logstash-per-pipeline-logs-update/276751)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 2\
**Last updated:** [June 23, 2021, 4:58pm UTC](https://discuss.elastic.co/t/logstash-per-pipeline-logs-update/276751 "2021-06-23T16:58:19Z")

</div>

Hi everyone! Saw this thread. Now I'd like to know if do we have any update on logstash's per pipeline logfiles?

---

## [Most visited domains (IPs)](https://discuss.elastic.co/t/most-visited-domains-ips/276761)

<div class="topic-metadata">

**Author:** [@\_codex](https://discuss.elastic.co/u/_codex)\
**Replies:** 1\
**Last updated:** [June 23, 2021, 4:50pm UTC](https://discuss.elastic.co/t/most-visited-domains-ips/276761 "2021-06-23T16:50:17Z")

</div>

Hello good people of the internet, Firstly I know how FRUSTRATING it is to answer stupid questions regarding technical stuff however I am in charge of SOC for our company and we have just changed from SPLUNK to Kibana 7…

---

## [Logstash GeoIP Kibana point-to-point maps problems](https://discuss.elastic.co/t/logstash-geoip-kibana-point-to-point-maps-problems/276783)

<div class="topic-metadata">

**Author:** [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)\
**Replies:** 0\
**Last updated:** [June 23, 2021, 11:32am UTC](https://discuss.elastic.co/t/logstash-geoip-kibana-point-to-point-maps-problems/276783 "2021-06-23T11:32:01Z")

</div>

I have Logstash with Geoip enabled and even having everything correctly it tells me that I don't have the correct index selected for the creation of map Point to point, as you can see: Code: input { file { …

---

## [Configure Logstash stdout](https://discuss.elastic.co/t/configure-logstash-stdout/276774)

<div class="topic-metadata">

**Author:** [@Atesrin](https://discuss.elastic.co/u/Atesrin)\
**Replies:** 0\
**Last updated:** [June 23, 2021, 10:42am UTC](https://discuss.elastic.co/t/configure-logstash-stdout/276774 "2021-06-23T10:42:39Z")

</div>

Hi, I use Logstash to synchronize a MariaDB to a ES index. But my problem is that I got all the queries, the data in my logstash logs, it becomes quite as big as the index. How can I configure the stdout of Logstash to…

---

## [No logstash pipeline](https://discuss.elastic.co/t/no-logstash-pipeline/276620)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 4\
**Last updated:** [June 23, 2021, 9:55am UTC](https://discuss.elastic.co/t/no-logstash-pipeline/276620 "2021-06-23T09:55:33Z")

</div>

Hello everyone, I followed this tutorial to enable tls on elasticsearch, kibana, logstash and filebeat : I think logstash don't send logs to kibana but I don't know where to find the information Thank you in advance …

---

## [Index document with double nested property using Logstash](https://discuss.elastic.co/t/index-document-with-double-nested-property-using-logstash/276755)

<div class="topic-metadata">

**Author:** [@joe100](https://discuss.elastic.co/u/joe100)\
**Replies:** 0\
**Last updated:** [June 23, 2021, 9:10am UTC](https://discuss.elastic.co/t/index-document-with-double-nested-property-using-logstash/276755 "2021-06-23T09:10:30Z")

</div>

I have my\_index with a double nested property (nested of nested) and i'm looking for the right logshash configuration to correctly index documents with the following mappings: "mappings": { "properties": { "id": {…

---

## [Multiple split](https://discuss.elastic.co/t/multiple-split/276533)

<div class="topic-metadata">

**Author:** [@graaooor](https://discuss.elastic.co/u/graaooor)\
**Replies:** 3\
**Last updated:** [June 23, 2021, 7:55am UTC](https://discuss.elastic.co/t/multiple-split/276533 "2021-06-23T07:55:08Z")

</div>

Hello, I Have a csv file which have 3 fields field1 : ID field2 : Company Name field3 : Array of contacts (separator : | ) Theis field can be : null (no contact) one or more contacts But each contact is also an a…

---

## [logstashとpostgresDBを同期して取得する日付データが9時間ずれる](https://discuss.elastic.co/t/logstash-postgresdb-9/276254)

<div class="topic-metadata">

**Author:** [@lee0745](https://discuss.elastic.co/u/lee0745)\
**Replies:** 2\
**Last updated:** [June 23, 2021, 7:29am UTC](https://discuss.elastic.co/t/logstash-postgresdb-9/276254 "2021-06-23T07:29:29Z")

</div>

logstashとpostgresDBを同期して取得する日付データが9時間ずれます。 postgres（sample\_date)：2021/06/17 11:45:59.740 logstash同期後：2021-06-17T02:45:59.740Z 私のconfファイルです。 input { jdbc { jdbc\_driver\_library =\> "../logstash/logstash-core/lib/…

---

## [Drop field based on pattern](https://discuss.elastic.co/t/drop-field-based-on-pattern/276443)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 3\
**Last updated:** [June 22, 2021, 9:49pm UTC](https://discuss.elastic.co/t/drop-field-based-on-pattern/276443 "2021-06-22T21:49:51Z")

</div>

Hi, I have some field names that begin with the string "sub" that I want Logstash to drop. Can I do something like: if \[sub\*\] { drop {} }

---

## [Logstash error : no implicit conversion of nil into Integer](https://discuss.elastic.co/t/logstash-error-no-implicit-conversion-of-nil-into-integer/276688)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 4\
**Last updated:** [June 22, 2021, 8:40pm UTC](https://discuss.elastic.co/t/logstash-error-no-implicit-conversion-of-nil-into-integer/276688 "2021-06-22T20:40:14Z")

</div>

Hello, elastic people, I have been making a filter in logstash of a conditional to analyze the status of a team according to the metrics, I tried it, but I get the following error, I need help with this please: \[ERROR\] …

---

## [Unble to convert to date string field](https://discuss.elastic.co/t/unble-to-convert-to-date-string-field/276661)

<div class="topic-metadata">

**Author:** [@casquero](https://discuss.elastic.co/u/casquero)\
**Replies:** 10\
**Last updated:** [June 22, 2021, 6:30pm UTC](https://discuss.elastic.co/t/unble-to-convert-to-date-string-field/276661 "2021-06-22T18:30:09Z")

</div>

I've tried to create a new field as date but always appears as string in Kibana, I've done the following: mutate { add\_field =\> { "timestampTest" =\> "%{localisodate}" } } date { match =\> \["timest…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=215)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=217)
