# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=217

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 218

---

## [Logstash error and MetricBeat stopped](https://discuss.elastic.co/t/logstash-error-and-metricbeat-stopped/276398)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 1\
**Last updated:** [June 22, 2021, 4:49pm UTC](https://discuss.elastic.co/t/logstash-error-and-metricbeat-stopped/276398 "2021-06-22T16:49:15Z")

</div>

I noticed yesterday that my Metricbeat service had stopped running on the Windows test box I have. When I start Logstash I receive the below information. \[2021-06-18T10:28:12,009\]\[WARN \]\[logstash.outputs.elasticsearch\]…

---

## [Getting an error while installing logstash websocket plugin](https://discuss.elastic.co/t/getting-an-error-while-installing-logstash-websocket-plugin/276618)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 1\
**Last updated:** [June 22, 2021, 4:37pm UTC](https://discuss.elastic.co/t/getting-an-error-while-installing-logstash-websocket-plugin/276618 "2021-06-22T16:37:10Z")

</div>

i want to install logstash websocket pluginto make a real-time communication between Elasticsearch and Logstash, through a websocket.\`this is the error that i get while installing ERROR: Installation Aborted, message: B…

---

## [Logstash\_7.5.2\_ Encountered a retryable error. Will Retry with exponential backoff {:code=\>400, :url=\>"https://host:9200/\_bulk"}](https://discuss.elastic.co/t/logstash-7-5-2-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-400-url-https-host-9200-bulk/276635)

<div class="topic-metadata">

**Author:** [@anburethy](https://discuss.elastic.co/u/anburethy)\
**Replies:** 2\
**Last updated:** [June 22, 2021, 1:16pm UTC](https://discuss.elastic.co/t/logstash-7-5-2-encountered-a-retryable-error-will-retry-with-exponential-backoff-code-400-url-https-host-9200-bulk/276635 "2021-06-22T13:16:25Z")

</div>

Hi Team, We use an ELK stack and I actually ran into login issue for which I deleted some existing indexes which are old and the login issue sorted but I ran into another issue. I wasnt able to reindex not the new index…

---

## [Transfer logs from rsyslog to logstash and view those logs in browser](https://discuss.elastic.co/t/transfer-logs-from-rsyslog-to-logstash-and-view-those-logs-in-browser/276140)

<div class="topic-metadata">

**Author:** [@vatsal](https://discuss.elastic.co/u/vatsal)\
**Replies:** 4\
**Last updated:** [June 22, 2021, 1:02pm UTC](https://discuss.elastic.co/t/transfer-logs-from-rsyslog-to-logstash-and-view-those-logs-in-browser/276140 "2021-06-22T13:02:05Z")

</div>

Hi , I want to send syslogs from rsyslog to logstash and view those in browser. I want to do this with TLS enabled. I have tried following ways: a. configured all corresponding files. b. configured pipeline for logst…

---

## [File input plugin - Delimiter property not working](https://discuss.elastic.co/t/file-input-plugin-delimiter-property-not-working/276650)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 0\
**Last updated:** [June 22, 2021, 12:30pm UTC](https://discuss.elastic.co/t/file-input-plugin-delimiter-property-not-working/276650 "2021-06-22T12:30:30Z")

</div>

Hello, I have logstash \[6.7\] complaining when I set "\\r\\n" as delimiter for the file input plugin. The file I'd like logstash to handle is file incident\_sample.csv incident\_sample.csv: ASCII text, with very long lines…

---

## [Figure out which pipeline works the most?](https://discuss.elastic.co/t/figure-out-which-pipeline-works-the-most/276645)

<div class="topic-metadata">

**Author:** [@McElroy](https://discuss.elastic.co/u/McElroy)\
**Replies:** 1\
**Last updated:** [June 22, 2021, 12:42pm UTC](https://discuss.elastic.co/t/figure-out-which-pipeline-works-the-most/276645 "2021-06-22T12:42:21Z")

</div>

Hi, we have a pretty old ELK-stack (5.5) and since a few weeks our Logstash CPU usage is through the roof. Is there a way to check which pipeline or grok pattern is causing that?

---

## [Follow-up from "Unable to avoid JSON parsing errors in logstash log-file"](https://discuss.elastic.co/t/follow-up-from-unable-to-avoid-json-parsing-errors-in-logstash-log-file/276641)

<div class="topic-metadata">

**Author:** [@es-gabriele](https://discuss.elastic.co/u/es-gabriele)\
**Replies:** 0\
**Last updated:** [June 22, 2021, 11:02am UTC](https://discuss.elastic.co/t/follow-up-from-unable-to-avoid-json-parsing-errors-in-logstash-log-file/276641 "2021-06-22T11:02:13Z")

</div>

Hi everyone, I am using ELK 7.2. I did read from a past answer here and I found it useful, as what I need to do is to make logstash correctly parse json data, and also an array of nested json objects. However, if I ne…

---

## [Logstash 'compile\_imperative' error](https://discuss.elastic.co/t/logstash-compile-imperative-error/276625)

<div class="topic-metadata">

**Author:** [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)\
**Replies:** 2\
**Last updated:** [June 22, 2021, 9:33am UTC](https://discuss.elastic.co/t/logstash-compile-imperative-error/276625 "2021-06-22T09:33:32Z")

</div>

Hi, I have Logstash to pick up Snort Alerts, but i have had this error and i don't know why. Error: logstash | \[2021-06-22T08:55:53,809\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>Log…

---

## [Logstash input plugin bad uri](https://discuss.elastic.co/t/logstash-input-plugin-bad-uri/276592)

<div class="topic-metadata">

**Author:** [@IsAa](https://discuss.elastic.co/u/IsAa)\
**Replies:** 2\
**Last updated:** [June 22, 2021, 2:53am UTC](https://discuss.elastic.co/t/logstash-input-plugin-bad-uri/276592 "2021-06-22T02:53:03Z")

</div>

Hi, I am trying to install plugin for logstash. But whenever I execute .\\logstash-plugin list to see a list of available plugins. I keep getting bad uri error Using JAVA\_HOME defined java: C:\\Program Files\\Java\\jdk-14…

---

## [Logstash -\> array field -\> subquery](https://discuss.elastic.co/t/logstash-array-field-subquery/276584)

<div class="topic-metadata">

**Author:** [@seboraid](https://discuss.elastic.co/u/seboraid)\
**Replies:** 1\
**Last updated:** [June 22, 2021, 12:06am UTC](https://discuss.elastic.co/t/logstash-array-field-subquery/276584 "2021-06-22T00:06:42Z")

</div>

Hi! Im looking to add data from a subquery (i dont jnow if this is possible) to an array field in a elastic index. I have the following tables in MySQL: transactions and applied\_rules where applied\_rules has the follo…

---

## [Logstash-output-syslog incorrect time](https://discuss.elastic.co/t/logstash-output-syslog-incorrect-time/276554)

<div class="topic-metadata">

**Author:** [@bambam](https://discuss.elastic.co/u/bambam)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 2:57pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-incorrect-time/276554 "2021-06-21T14:57:46Z")

</div>

I'm having an issue with using the logstash-output-syslog plugin. The syslog message header is showing a timestamp for UTC and not the timezone for where I'm located. Can someone provide some input on how to change the t…

---

## [I get error with Logstash: IllegalStateException](https://discuss.elastic.co/t/i-get-error-with-logstash-illegalstateexception/276486)

<div class="topic-metadata">

**Author:** [@an\_dinh](https://discuss.elastic.co/u/an_dinh)\
**Replies:** 1\
**Last updated:** [June 21, 2021, 12:09pm UTC](https://discuss.elastic.co/t/i-get-error-with-logstash-illegalstateexception/276486 "2021-06-21T12:09:02Z")

</div>

Here is my logstash.conf: input { mongodb{ uri =\> 'mongodb://localhost:27017/vnExpressCrawler?authSource=vnExpressCrawler' placeholder\_db\_dir =\> '/opt/logstash-mongodb/' placeholder\_db\_name =\> 'logstash\_s…

---

## [Append hostname in each index name](https://discuss.elastic.co/t/append-hostname-in-each-index-name/276519)

<div class="topic-metadata">

**Author:** [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Replies:** 1\
**Last updated:** [June 21, 2021, 12:00pm UTC](https://discuss.elastic.co/t/append-hostname-in-each-index-name/276519 "2021-06-21T12:00:49Z")

</div>

I would like to append hostname in each index name for classification of files based on the source hostname. output{ elasticsearch { hosts =\> \["127.0.0.1:9200"\] index =\> "sample-%{\[@metadata\]\[hostname\]}-%{\[@me…

---

## [Parsing a Concatenated Field to Extract Sub-Fields](https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523)

<div class="topic-metadata">

**Author:** [@fmaginga](https://discuss.elastic.co/u/fmaginga)\
**Replies:** 2\
**Last updated:** [June 21, 2021, 11:29am UTC](https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523 "2021-06-21T11:29:23Z")

</div>

Hello, I am trying to write a logstash filter to extract individual sub-fields from on concatenated field. Example: I have a field CGI = 640070003110080 CGI = 640070003110080 I want to split the CGI field in to four…

---

## [How To parse Multiline Message With Grok](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 6\
**Last updated:** [June 21, 2021, 10:47am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500 "2021-06-21T10:47:09Z")

</div>

I am working with AWS Cloudwatchs' GuardDuty finding events, I am getting GuardDuty event in the following format : "message": "\\n\\"AWS MY\_ACCOUNTID has a severity 2 GuardDuty finding type Recon:EC2/PortProbeUnprotected…

---

## [Logstash Application throwing up warning "Connection reset by peer"](https://discuss.elastic.co/t/logstash-application-throwing-up-warning-connection-reset-by-peer/276489)

<div class="topic-metadata">

**Author:** [@theju0805](https://discuss.elastic.co/u/theju0805)\
**Replies:** 0\
**Last updated:** [June 21, 2021, 7:14am UTC](https://discuss.elastic.co/t/logstash-application-throwing-up-warning-connection-reset-by-peer/276489 "2021-06-21T07:14:08Z")

</div>

Logstash application throwing up warning "Connection reset by peer". Logstash is hosted on Azure. This warning doesn't exist or occur on the VM, but after the VM is scaled up(VMSS) I see the warning coming up continuous…

---

## [filter\>jdbc\_streaming\>\[Oracle\] Delete Query return “\[Warn\] ORA-01002”](https://discuss.elastic.co/t/filter-jdbc-streaming-oracle-delete-query-return-warn-ora-01002/273907)

<div class="topic-metadata">

**Author:** [@zeraf29](https://discuss.elastic.co/u/zeraf29)\
**Replies:** 1\
**Last updated:** [June 21, 2021, 6:55am UTC](https://discuss.elastic.co/t/filter-jdbc-streaming-oracle-delete-query-return-warn-ora-01002/273907 "2021-06-21T06:55:28Z")

</div>

Hi. Nice to meet you. I try to make logstash-pipeline which works like below. (1)Input: JDBC plugin-Select data on Oracle DBMS (2)Filter: JDBC\_STREAMING plugin- Delete Data slected by input plugin results (3)Output: …

---

## [Logstash pipeline not inserting all data at first time](https://discuss.elastic.co/t/logstash-pipeline-not-inserting-all-data-at-first-time/276347)

<div class="topic-metadata">

**Author:** [@vikramdayma](https://discuss.elastic.co/u/vikramdayma)\
**Replies:** 4\
**Last updated:** [June 21, 2021, 4:28am UTC](https://discuss.elastic.co/t/logstash-pipeline-not-inserting-all-data-at-first-time/276347 "2021-06-21T04:28:27Z")

</div>

Hi, I setup a logstash conf file for data from sql to elasticsearch index. When I run conf file first time, it insert less data, every time with new index. Inserted data is less than from total data, randomly. But sec…

---

## [Logstash Ruby : Find Matching Value From Two Different Array](https://discuss.elastic.co/t/logstash-ruby-find-matching-value-from-two-different-array/276460)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 1\
**Last updated:** [June 20, 2021, 5:51pm UTC](https://discuss.elastic.co/t/logstash-ruby-find-matching-value-from-two-different-array/276460 "2021-06-20T17:51:30Z")

</div>

I have two different arrays outputs and info.policy.rules coming in the same log document and I would like to run a ruby loop to find if there is any matching value available for adderss field in the array of outputs aga…

---

## [Logstash error when converting field \[http\]\[response\]\[status\_code\] into integer](https://discuss.elastic.co/t/logstash-error-when-converting-field-http-response-status-code-into-integer/276456)

<div class="topic-metadata">

**Author:** [@bertr](https://discuss.elastic.co/u/bertr)\
**Replies:** 0\
**Last updated:** [June 20, 2021, 7:55am UTC](https://discuss.elastic.co/t/logstash-error-when-converting-field-http-response-status-code-into-integer/276456 "2021-06-20T07:55:48Z")

</div>

Tried this with logtsash 7.10.2 and 7.12.1: The following code results in "(TypeError) no implicit conversion of nil into Integer": mutate { add\_field =\> { "\[http\]\[response\]\[status\_code\]" =\> "200" } } \<== this sta…

---

## [Logstash mapping not working correctly](https://discuss.elastic.co/t/logstash-mapping-not-working-correctly/276446)

<div class="topic-metadata">

**Author:** [@Jeremy\_D](https://discuss.elastic.co/u/Jeremy_D)\
**Replies:** 1\
**Last updated:** [June 20, 2021, 2:47am UTC](https://discuss.elastic.co/t/logstash-mapping-not-working-correctly/276446 "2021-06-20T02:47:26Z")

</div>

Really unclear as to what I need to do to make this work right. My logs coming from my Python application are nested within "message" rather than being mapped to the proper fields. Notice how "message" has all the co…

---

## [Using Ruby to rename and flatten dynamic json input](https://discuss.elastic.co/t/using-ruby-to-rename-and-flatten-dynamic-json-input/276438)

<div class="topic-metadata">

**Author:** [@blackberrySherbet](https://discuss.elastic.co/u/blackberrySherbet)\
**Replies:** 1\
**Last updated:** [June 19, 2021, 4:31pm UTC](https://discuss.elastic.co/t/using-ruby-to-rename-and-flatten-dynamic-json-input/276438 "2021-06-19T16:31:00Z")

</div>

I have a variable in Logstash that holds some nested JSON. I do not know the structure or name of the keys (they are dynamic). I need to flatten this JSON into a single level and append a "nested\_" to all the keys that …

---

## [How to present table, based on multiline xml fields](https://discuss.elastic.co/t/how-to-present-table-based-on-multiline-xml-fields/276357)

<div class="topic-metadata">

**Author:** [@rubic](https://discuss.elastic.co/u/rubic)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 9:16am UTC](https://discuss.elastic.co/t/how-to-present-table-based-on-multiline-xml-fields/276357 "2021-06-18T09:16:40Z")

</div>

Hi, I'm struggling with creating simple table in lens, which could present my data from ingested, multiline xml file. Basically I don't need to apply any aggregations. I'm wondering if there is any kind of solution? My…

---

## [Cloudwatch-output-plugin multiple metrics in same pipeline](https://discuss.elastic.co/t/cloudwatch-output-plugin-multiple-metrics-in-same-pipeline/276419)

<div class="topic-metadata">

**Author:** [@Ahmed\_ElHaw](https://discuss.elastic.co/u/Ahmed_ElHaw)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 7:48pm UTC](https://discuss.elastic.co/t/cloudwatch-output-plugin-multiple-metrics-in-same-pipeline/276419 "2021-06-18T19:48:28Z")

</div>

I have managed to get my head around sending one metric to Cloudwatch using output plugin. Now while I understand it aggregates, I am using it to send 1 minute metrics and matching that on CloudWatch so I'm good. The qu…

---

## [Encountered a retryable error. Will Retry with exponential backoff code=\>403](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-403/276382)

<div class="topic-metadata">

**Author:** [@vaclav1](https://discuss.elastic.co/u/vaclav1)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 11:27am UTC](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-403/276382 "2021-06-18T11:27:46Z")

</div>

Hello, we have recently swapped to use api keys and created api key for logstash monitoring. As written here: Configuring Security in Logstash | Logstash Reference \[7.9\] | Elastic POST /\_security/api\_key { "name": "…

---

## [Logstash Infinite Loop while indexing](https://discuss.elastic.co/t/logstash-infinite-loop-while-indexing/276380)

<div class="topic-metadata">

**Author:** [@Adabi\_Raihan](https://discuss.elastic.co/u/Adabi_Raihan)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 11:17am UTC](https://discuss.elastic.co/t/logstash-infinite-loop-while-indexing/276380 "2021-06-18T11:17:40Z")

</div>

Hi Everyone !, So what I'm going to do is indexing .log data with grok using logstash, but in the middle of indexing, it's suddenly stopped. I am already using --debug flag to see what's going on, and it keeps loop this…

---

## [LS not reading jdbc input for large dataset. Order By Clause is a Issue in Microsoft SQL](https://discuss.elastic.co/t/ls-not-reading-jdbc-input-for-large-dataset-order-by-clause-is-a-issue-in-microsoft-sql/276352)

<div class="topic-metadata">

**Author:** [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 8:27am UTC](https://discuss.elastic.co/t/ls-not-reading-jdbc-input-for-large-dataset-order-by-clause-is-a-issue-in-microsoft-sql/276352 "2021-06-18T08:27:19Z")

</div>

Hi All I know this question has been asked earlier as well, but this issue is still there. But there was no clear statement on the solution, so i am asking again. input : jdbc-input-plugin jdbc driver: MSSQL Underne…

---

## [How to make Logstash plugin to BCFIPS compliant?](https://discuss.elastic.co/t/how-to-make-logstash-plugin-to-bcfips-compliant/276338)

<div class="topic-metadata">

**Author:** [@sivatejaperam](https://discuss.elastic.co/u/sivatejaperam)\
**Replies:** 0\
**Last updated:** [June 18, 2021, 6:57am UTC](https://discuss.elastic.co/t/how-to-make-logstash-plugin-to-bcfips-compliant/276338 "2021-06-18T06:57:31Z")

</div>

I am trying to make my log stash input plugin to BCFIPS complaint. I have added bc-fips.jar in my plugin dependency list and also registered the fips provider using Security.addProvider(new BouncyCastleFipsProvider()); . …

---

## [Ruby Code to split key value pair in Logstash 6.8.0](https://discuss.elastic.co/t/ruby-code-to-split-key-value-pair-in-logstash-6-8-0/275933)

<div class="topic-metadata">

**Author:** [@Santy](https://discuss.elastic.co/u/Santy)\
**Replies:** 4\
**Last updated:** [June 18, 2021, 5:13am UTC](https://discuss.elastic.co/t/ruby-code-to-split-key-value-pair-in-logstash-6-8-0/275933 "2021-06-18T05:13:16Z")

</div>

json { source =\> "message" } split { field =\> "data" } date { match =\> \["\[data\]\[currentDate\]", "yyyy-MM-dd HH:mm:ss"\] target =\> "@timestamp" } ruby { code =\> " event\['data'\].each {|k, v| …

---

## [Logstash is losing connection to Elastic search](https://discuss.elastic.co/t/logstash-is-losing-connection-to-elastic-search/276319)

<div class="topic-metadata">

**Author:** [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 10:26pm UTC](https://discuss.elastic.co/t/logstash-is-losing-connection-to-elastic-search/276319 "2021-06-17T22:26:35Z")

</div>

Hi, My logstash is disconnecting to elasticsearch after 20 mins, elasticsearch is running and no error. Here is the logs I have: \[WARN \]\[logstash.outputs.elasticsearch\] Marking url as dead. Last error: \[LogStash::Outp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=216)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=218)
