# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=218

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 219

---

## [How to dispay hostname and host ip on my elastic search output?](https://discuss.elastic.co/t/how-to-dispay-hostname-and-host-ip-on-my-elastic-search-output/275928)

<div class="topic-metadata">

**Author:** [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Replies:** 2\
**Last updated:** [June 17, 2021, 7:49pm UTC](https://discuss.elastic.co/t/how-to-dispay-hostname-and-host-ip-on-my-elastic-search-output/275928 "2021-06-17T19:49:14Z")

</div>

Hi, Can help me please extract the host name from the message output (devname) in elasticsearch. In my current config on the host portion only ip is displayed. Current config: input { syslog { port =\> 5000 host =\> …

---

## [Logstash ElasticSearch Output not using special characters (!)](https://discuss.elastic.co/t/logstash-elasticsearch-output-not-using-special-characters/276282)

<div class="topic-metadata">

**Author:** [@Mahdj](https://discuss.elastic.co/u/Mahdj)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 3:01pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-not-using-special-characters/276282 "2021-06-17T15:01:45Z")

</div>

Hello everyone, I have my logstash and want to connect to my ElasticSearch instance with OpenDistro installed. I've created an user logstash with password "logstash!" but logstash have an error saying "Got response cod…

---

## [Http output plugin is not working in logstash, Please help](https://discuss.elastic.co/t/http-output-plugin-is-not-working-in-logstash-please-help/275889)

<div class="topic-metadata">

**Author:** [@rajkumar.m](https://discuss.elastic.co/u/rajkumar.m)\
**Replies:** 7\
**Last updated:** [June 17, 2021, 2:53pm UTC](https://discuss.elastic.co/t/http-output-plugin-is-not-working-in-logstash-please-help/275889 "2021-06-17T14:53:17Z")

</div>

Hi, I am trying to send json message to kibana api using http plugin, I found the below error, Please help and appreciated. \[2021-06-14T14:45:26,361\]\[ERROR\]\[logstash.outputs.http \] \[HTTP Output Failure\] Encountered n…

---

## [Logstash Helm deploy pattern error](https://discuss.elastic.co/t/logstash-helm-deploy-pattern-error/276276)

<div class="topic-metadata">

**Author:** [@emergrin](https://discuss.elastic.co/u/emergrin)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 2:04pm UTC](https://discuss.elastic.co/t/logstash-helm-deploy-pattern-error/276276 "2021-06-17T14:04:21Z")

</div>

Hi all, I have some problems with my value.yaml from my helm deploy of logstash 7.9 and I need some help. This it's an example of my file: logstashPipeline: logstash.conf: | input { beats { port =\> …

---

## [Logstash file input performance](https://discuss.elastic.co/t/logstash-file-input-performance/276050)

<div class="topic-metadata">

**Author:** [@seadub](https://discuss.elastic.co/u/seadub)\
**Replies:** 4\
**Last updated:** [June 17, 2021, 2:03pm UTC](https://discuss.elastic.co/t/logstash-file-input-performance/276050 "2021-06-17T14:03:55Z")

</div>

Continuing the discussion from Tuning to handle extreme initial ingestion conditions (with logstash): @Christian\_Dahlqvist - I know I'm resurrecting an old thread here but I'd love to confirm a point you'd raised. I hop…

---

## [Field search using Logstash configuration](https://discuss.elastic.co/t/field-search-using-logstash-configuration/276259)

<div class="topic-metadata">

**Author:** [@Pallavibhushan](https://discuss.elastic.co/u/Pallavibhushan)\
**Replies:** 0\
**Last updated:** [June 17, 2021, 11:41am UTC](https://discuss.elastic.co/t/field-search-using-logstash-configuration/276259 "2021-06-17T11:41:10Z")

</div>

Hi , Below is my requirement. I have two indexes Index : Client\_one \[fields : employee\_no1,salary, exp\] Index: client\_two. \[fields " employee\_no2, total\_exp\] Both index have one common field employee\_no. I want to …

---

## [Last\_run\_metadata\_path not updated with sql\_last\_value](https://discuss.elastic.co/t/last-run-metadata-path-not-updated-with-sql-last-value/276143)

<div class="topic-metadata">

**Author:** [@Alesora](https://discuss.elastic.co/u/Alesora)\
**Replies:** 2\
**Last updated:** [June 17, 2021, 8:06am UTC](https://discuss.elastic.co/t/last-run-metadata-path-not-updated-with-sql-last-value/276143 "2021-06-17T08:06:14Z")

</div>

Hi, I m new to ELK and I'm having an issue with the jdbc sql\_last\_value. So I'm trying to update my Elastic database from a SQL database using the jdbc driver, I want to update records that are modified (dhm is the row t…

---

## [Logstash How to read only name of the file](https://discuss.elastic.co/t/logstash-how-to-read-only-name-of-the-file/276096)

<div class="topic-metadata">

**Author:** [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Replies:** 2\
**Last updated:** [June 17, 2021, 6:27am UTC](https://discuss.elastic.co/t/logstash-how-to-read-only-name-of-the-file/276096 "2021-06-17T06:27:27Z")

</div>

Hi I'am new to elasticsearch. I wanted to know if there was a possible way to read only the names of the files and ignore the contents inside (I must ignore it to prevent error. I saw this posts but it didn't work for m…

---

## [Split field in elastic](https://discuss.elastic.co/t/split-field-in-elastic/276069)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 6\
**Last updated:** [June 17, 2021, 1:46am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069 "2021-06-17T01:46:50Z")

</div>

Hi all, I have a little problems that needed solving. I have a field dns domain dns.question.name has value like this: a.b.c.d Now i want to split this domain into many other domain like tld, sld ..... dynamically wit…

---

## [JDBC Input last value overlap](https://discuss.elastic.co/t/jdbc-input-last-value-overlap/276188)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 4\
**Last updated:** [June 16, 2021, 9:23pm UTC](https://discuss.elastic.co/t/jdbc-input-last-value-overlap/276188 "2021-06-16T21:23:24Z")

</div>

Is it possible to set the sql\_last\_value parameter to go back a set amount of time. So something like :sql\_last\_value(-10s) or something like that. I'm querying a db and getting anything that's been updated since the l…

---

## [How to parse dir command output from txt file and append filenames to directory](https://discuss.elastic.co/t/how-to-parse-dir-command-output-from-txt-file-and-append-filenames-to-directory/276185)

<div class="topic-metadata">

**Author:** [@baileys20055](https://discuss.elastic.co/u/baileys20055)\
**Replies:** 4\
**Last updated:** [June 16, 2021, 8:33pm UTC](https://discuss.elastic.co/t/how-to-parse-dir-command-output-from-txt-file-and-append-filenames-to-directory/276185 "2021-06-16T20:33:46Z")

</div>

Hello, I am trying to parse dir command txt files that are formatted as follows: Directory of C:\\Windows\\addins 09/15/2018 02:33 AM \<DIR\> . 09/15/2018 02:33 AM \<DIR\> .. 09/15/2018 02:29 AM…

---

## [Establish connection to Filebeat from Logstash](https://discuss.elastic.co/t/establish-connection-to-filebeat-from-logstash/275547)

<div class="topic-metadata">

**Author:** [@cwiechmann](https://discuss.elastic.co/u/cwiechmann)\
**Replies:** 5\
**Last updated:** [June 16, 2021, 8:29pm UTC](https://discuss.elastic.co/t/establish-connection-to-filebeat-from-logstash/275547 "2021-06-16T20:29:18Z")

</div>

Hi All, Let's assume an application I would like to monitor is running in a Security-Network-Zone (e.g. DMZ). It should be integrated via Filebeat into the Logstash & Elasticsearch platform running in the internal netwo…

---

## [How to update index in Elasticsearch](https://discuss.elastic.co/t/how-to-update-index-in-elasticsearch/275773)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 6\
**Last updated:** [June 16, 2021, 7:14pm UTC](https://discuss.elastic.co/t/how-to-update-index-in-elasticsearch/275773 "2021-06-16T19:14:37Z")

</div>

Hi All, I have an ELK 7.6.2 stack running in the environment. In my setup logstash is set to ingest file as an input and performs certain operations on it and creates an index in ES. First few lines of the logstash co…

---

## [Index variable substitution not working](https://discuss.elastic.co/t/index-variable-substitution-not-working/276169)

<div class="topic-metadata">

**Author:** [@devopscanada](https://discuss.elastic.co/u/devopscanada)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 4:51pm UTC](https://discuss.elastic.co/t/index-variable-substitution-not-working/276169 "2021-06-16T16:51:13Z")

</div>

I'm trying in Logstash to write different indices (see documentation) but Logtash wont' substitute the variables. My Logstash configuraiton: output { elasticsearch { hosts =\> \["http://elasticsearch-ma…

---

## [From FileBeat to Logstash](https://discuss.elastic.co/t/from-filebeat-to-logstash/276095)

<div class="topic-metadata">

**Author:** [@Michael\_Dylan\_McAloo](https://discuss.elastic.co/u/Michael_Dylan_McAloo)\
**Replies:** 1\
**Last updated:** [June 16, 2021, 4:44pm UTC](https://discuss.elastic.co/t/from-filebeat-to-logstash/276095 "2021-06-16T16:44:46Z")

</div>

I have a dissect with filebeat, functional, but I need to pass it to logstash and I don't know how to use that same function in Logstash. Code: processors: - dissect: tokenizer: '%{timestamp} \[%{trash}\] \[…

---

## [Logstash Extract Elasticsearch Nested Fields](https://discuss.elastic.co/t/logstash-extract-elasticsearch-nested-fields/275451)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 28\
**Last updated:** [June 16, 2021, 2:13pm UTC](https://discuss.elastic.co/t/logstash-extract-elasticsearch-nested-fields/275451 "2021-06-16T14:13:37Z")

</div>

Hello Team I am using Elasticsearch version 7.8.0 and Logstash version 7.8.0 I am having ES Index having following mappings : "mappings" : { "properties" : { "appEvents" : { "properties" : …

---

## [Date Logstash](https://discuss.elastic.co/t/date-logstash/275816)

<div class="topic-metadata">

**Author:** [@Krunal](https://discuss.elastic.co/u/Krunal)\
**Replies:** 1\
**Last updated:** [June 16, 2021, 12:07pm UTC](https://discuss.elastic.co/t/date-logstash/275816 "2021-06-16T12:07:21Z")

</div>

Hello Expert, I would like convert date into timestamp which is mention below.. I dont have any column with reference to date but I have just 1 line in which date is mention. what changes I can do in config file of logs…

---

## [Problem with data merging](https://discuss.elastic.co/t/problem-with-data-merging/274425)

<div class="topic-metadata">

**Author:** [@ravi-shanker](https://discuss.elastic.co/u/ravi-shanker)\
**Replies:** 14\
**Last updated:** [June 16, 2021, 12:02pm UTC](https://discuss.elastic.co/t/problem-with-data-merging/274425 "2021-06-16T12:02:05Z")

</div>

Hello All, I am using jdbc input and jdbc\_streaming section in my logstash config to bring data from two different table into the same index. My logstash config is below. input { jdbc { jdbc\_connection\_str…

---

## [Concatenate log](https://discuss.elastic.co/t/concatenate-log/275968)

<div class="topic-metadata">

**Author:** [@cassiopee](https://discuss.elastic.co/u/cassiopee)\
**Replies:** 4\
**Last updated:** [June 16, 2021, 9:18am UTC](https://discuss.elastic.co/t/concatenate-log/275968 "2021-06-16T09:18:07Z")

</div>

hello, I have a beats log, who are concatenate and special characters. I wanted request one of this field but I supposed my request is blocked because a bad syntax. { "user" =\> { "name" =\> "AD-WSUS…

---

## [Jdbc\_streaming parameters on From](https://discuss.elastic.co/t/jdbc-streaming-parameters-on-from/276104)

<div class="topic-metadata">

**Author:** [@charles97](https://discuss.elastic.co/u/charles97)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 8:29am UTC](https://discuss.elastic.co/t/jdbc-streaming-parameters-on-from/276104 "2021-06-16T08:29:37Z")

</div>

I've seen documentation about using parameters as statement =\> "select \* from WORLD.COUNTRY WHERE Code = :code" parameters =\> { "code" =\> "country\_code"} But I'm in situation where I have 9 different cases and …

---

## [Logstash filter jdbc\_streaming : JDBC:AdapterNotFound: Could not load jdbc/mssql adapter: adapter class not registered in ADAPTER\_MAP\>](https://discuss.elastic.co/t/logstash-filter-jdbc-streaming-jdbc-could-not-load-jdbc-mssql-adapter-adapter-class-not-registered-in-adapter-map/275546)

<div class="topic-metadata">

**Author:** [@charles97](https://discuss.elastic.co/u/charles97)\
**Replies:** 7\
**Last updated:** [June 16, 2021, 8:00am UTC](https://discuss.elastic.co/t/logstash-filter-jdbc-streaming-jdbc-could-not-load-jdbc-mssql-adapter-adapter-class-not-registered-in-adapter-map/275546 "2021-06-16T08:00:13Z")

</div>

I'm trying to use logstash filter plugin jdbc\_streaming, my logstash version is 7.13 OS centos 7 openjdk 11.0.11 2021-04-20 LTS jdbc 6.0 : "/home/jdbc/sqljdbc\_6.0/enu/jre7/sqljdbc41.jar" my logstash config input {…

---

## [How to export a scripted field in the elasticsearch-output-plugin](https://discuss.elastic.co/t/how-to-export-a-scripted-field-in-the-elasticsearch-output-plugin/276091)

<div class="topic-metadata">

**Author:** [@fidsamurai](https://discuss.elastic.co/u/fidsamurai)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 7:12am UTC](https://discuss.elastic.co/t/how-to-export-a-scripted-field-in-the-elasticsearch-output-plugin/276091 "2021-06-16T07:12:42Z")

</div>

I've written a scripted field to standardise and create a shorthand for URLs. However from what I understood in the docs we can't use it as a keyword field, also it works only on Kibana and not if I try and get data dir…

---

## [Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {:pipeline\_id=\>"main", "exception"=\>"no implicit conversion to rational from nil"](https://discuss.elastic.co/t/exception-in-pipelineworker-the-pipeline-stopped-processing-new-events-please-check-your-filter-configuration-and-restart-logstash-pipeline-id-main-exception-no-implicit-conversion-to-rational-from-nil/275370)

<div class="topic-metadata">

**Author:** [@AmitC](https://discuss.elastic.co/u/AmitC)\
**Replies:** 6\
**Last updated:** [June 16, 2021, 6:00am UTC](https://discuss.elastic.co/t/exception-in-pipelineworker-the-pipeline-stopped-processing-new-events-please-check-your-filter-configuration-and-restart-logstash-pipeline-id-main-exception-no-implicit-conversion-to-rational-from-nil/275370 "2021-06-16T06:00:14Z")

</div>

Logstash Version : 6.1.1 Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {:pipeline\_id=\>"main", "exception"=\>"no implicit conversion…

---

## [One configuration file (single pipeline) or mutiple configuration files (various pipelines)?](https://discuss.elastic.co/t/one-configuration-file-single-pipeline-or-mutiple-configuration-files-various-pipelines/276080)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 0\
**Last updated:** [June 16, 2021, 5:40am UTC](https://discuss.elastic.co/t/one-configuration-file-single-pipeline-or-mutiple-configuration-files-various-pipelines/276080 "2021-06-16T05:40:06Z")

</div>

Hello Currently I have multiple configuration files, each listening on their own port and with their filters. Would it be better to merge it all in one and using conditionals, filter out, do transformations needed and …

---

## [When I set up the template file and used logstash to create the index, I got an error](https://discuss.elastic.co/t/when-i-set-up-the-template-file-and-used-logstash-to-create-the-index-i-got-an-error/275913)

<div class="topic-metadata">

**Author:** [@Masanori\_Mishima](https://discuss.elastic.co/u/Masanori_Mishima)\
**Replies:** 6\
**Last updated:** [June 16, 2021, 4:25am UTC](https://discuss.elastic.co/t/when-i-set-up-the-template-file-and-used-logstash-to-create-the-index-i-got-an-error/275913 "2021-06-16T04:25:11Z")

</div>

The execution environment is shown below. I would like to create an index by specifying mapping in a json file with index template set from logstash. How can I do this? logstash-7.13.0 Settings in the conf file inpu…

---

## [Logstash does not parse all logs with file as input](https://discuss.elastic.co/t/logstash-does-not-parse-all-logs-with-file-as-input/276044)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [June 15, 2021, 7:22pm UTC](https://discuss.elastic.co/t/logstash-does-not-parse-all-logs-with-file-as-input/276044 "2021-06-15T19:22:20Z")

</div>

Hi All. I am using file input plugin to read logs. My config looks like below: input { file { path =\> "/opt/gtal/iptal/elasticsearch/app/logstash/stage/CVMQA\_UAT\_STATS-\*.txt" codec =\> multiline { pattern =\> "…

---

## [Rename strings field to nested field](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 6\
**Last updated:** [June 15, 2021, 4:48pm UTC](https://discuss.elastic.co/t/rename-strings-field-to-nested-field/275912 "2021-06-15T16:48:00Z")

</div>

Hello every body, I want to parse the logs bellow Apr 20 01:10:04 hostname sshproxy\[150\]: \[SSH Session\] session\_id="56454646eaeazjajflen" client\_ip="X.X.X.X" target\_ip="X.X.X.X" user="X.X.X.X" device="X.X.X.X" service…

---

## [Overwrite @timestamp with log timestamp](https://discuss.elastic.co/t/overwrite-timestamp-with-log-timestamp/275713)

<div class="topic-metadata">

**Author:** [@Evan\_W](https://discuss.elastic.co/u/Evan_W)\
**Replies:** 5\
**Last updated:** [June 15, 2021, 3:28pm UTC](https://discuss.elastic.co/t/overwrite-timestamp-with-log-timestamp/275713 "2021-06-15T15:28:47Z")

</div>

As the title says, I'm looking to overwrite ingest timestamp to reflect the actual timestamp pulled from log data. I've already got a custom regex that can pull this timestamp out of my logs as its own unique field, but …

---

## [How would I parse further the syslog5424\_msg in a syslog event in logstash conf?](https://discuss.elastic.co/t/how-would-i-parse-further-the-syslog5424-msg-in-a-syslog-event-in-logstash-conf/275964)

<div class="topic-metadata">

**Author:** [@devashishsingh](https://discuss.elastic.co/u/devashishsingh)\
**Replies:** 4\
**Last updated:** [June 15, 2021, 2:47pm UTC](https://discuss.elastic.co/t/how-would-i-parse-further-the-syslog5424-msg-in-a-syslog-event-in-logstash-conf/275964 "2021-06-15T14:47:54Z")

</div>

Hello, I have parsed the XML log format coming from a syslog source as defined in logstash config file. What shall be done further to parse the syslog message field within the XML? Below is the config: input { tcp …

---

## [I would like to concatenate date and time fields with logstash](https://discuss.elastic.co/t/i-would-like-to-concatenate-date-and-time-fields-with-logstash/275992)

<div class="topic-metadata">

**Author:** [@sudo-ranjith](https://discuss.elastic.co/u/sudo-ranjith)\
**Replies:** 2\
**Last updated:** [June 15, 2021, 2:05pm UTC](https://discuss.elastic.co/t/i-would-like-to-concatenate-date-and-time-fields-with-logstash/275992 "2021-06-15T14:05:52Z")

</div>

Hi There, I have two fields date and time("10/26/20","09:30:53"). My Grok patterns are "%{DATA:date}","%{DATA:time}" I would like to concatenate these two fields as datetime, Could you please help me on the same.

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=217)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=219)
