# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=221

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 222

---

## [Automatically start logstash configuration file](https://discuss.elastic.co/t/automatically-start-logstash-configuration-file/275427)

<div class="topic-metadata">

**Author:** [@tarekilani](https://discuss.elastic.co/u/tarekilani)\
**Replies:** 1\
**Last updated:** [June 9, 2021, 3:58pm UTC](https://discuss.elastic.co/t/automatically-start-logstash-configuration-file/275427 "2021-06-09T15:58:51Z")

</div>

Hello, Please i would like to know if there is any method to set a logstash.conf file start automatically with the OS. I'm currently using a logstash.conf file using this command : # /usr/share/logstash/bin/logstash -f…

---

## [Syslog kills process in logstash](https://discuss.elastic.co/t/syslog-kills-process-in-logstash/275319)

<div class="topic-metadata">

**Author:** [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Replies:** 9\
**Last updated:** [June 9, 2021, 3:58pm UTC](https://discuss.elastic.co/t/syslog-kills-process-in-logstash/275319 "2021-06-09T15:58:33Z")

</div>

Hi Guy's! I need your help with this problem, please. Means that, syslog is killing the process in logstash, this means that it stops listening to syslog, I don't know why this is happening, the process stops working f…

---

## [Logstash configuration to globally mutate sub index patterns](https://discuss.elastic.co/t/logstash-configuration-to-globally-mutate-sub-index-patterns/275468)

<div class="topic-metadata">

**Author:** [@es-gabriele](https://discuss.elastic.co/u/es-gabriele)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 3:40pm UTC](https://discuss.elastic.co/t/logstash-configuration-to-globally-mutate-sub-index-patterns/275468 "2021-06-09T15:40:50Z")

</div>

Hello, I have an ELK stack, with some configured index patterns. As part of internal requirements, I need to edit a json object (which is part of that index pattern), globally to "string". As of now, such json object i…

---

## [Error while sending oracle data from logstash - elastic](https://discuss.elastic.co/t/error-while-sending-oracle-data-from-logstash-elastic/275447)

<div class="topic-metadata">

**Author:** [@Rahul\_Choubey](https://discuss.elastic.co/u/Rahul_Choubey)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 1:51pm UTC](https://discuss.elastic.co/t/error-while-sending-oracle-data-from-logstash-elastic/275447 "2021-06-09T13:51:07Z")

</div>

I am facing below issue while streaming message from logstash to kiabana: \[2021-06-09T10:15:01,047\]\[INFO \]\[logstash.inputs.jdbc\]\[main\] (0.067667s) SELECT \* FROM GV$ACTIVE\_SESSION\_HISTORY WHERE SAMPLE\_TIME \> TIMESTAMP '2…

---

## [Automatic data ingestion in logstash](https://discuss.elastic.co/t/automatic-data-ingestion-in-logstash/275071)

<div class="topic-metadata">

**Author:** [@Kanishk\_Madan](https://discuss.elastic.co/u/Kanishk_Madan)\
**Replies:** 5\
**Last updated:** [June 9, 2021, 8:44am UTC](https://discuss.elastic.co/t/automatic-data-ingestion-in-logstash/275071 "2021-06-09T08:44:00Z")

</div>

Hello community, This thread is regarding the automate of ingestion of data in logstash. I have created a python script in which I have written the command for the logstash data ingestion. The python script is also auto…

---

## [Logstash not able to connect to Elasticsearch deployed through Kubernetes pod](https://discuss.elastic.co/t/logstash-not-able-to-connect-to-elasticsearch-deployed-through-kubernetes-pod/275400)

<div class="topic-metadata">

**Author:** [@Shubham\_Dhote](https://discuss.elastic.co/u/Shubham_Dhote)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 8:34am UTC](https://discuss.elastic.co/t/logstash-not-able-to-connect-to-elasticsearch-deployed-through-kubernetes-pod/275400 "2021-06-09T08:34:59Z")

</div>

Hi, I have deployed Logstash and elasticsearch pod on EKS cluster. When I am checking the logs for logstash pod it is showing unreachable elasticserach server. Though my elasticsearch is up and running. Please find below…

---

## [Problems in Elasticsearch combining two types of logs using two pipelines (Logstash)](https://discuss.elastic.co/t/problems-in-elasticsearch-combining-two-types-of-logs-using-two-pipelines-logstash/273900)

<div class="topic-metadata">

**Author:** [@francesco96](https://discuss.elastic.co/u/francesco96)\
**Replies:** 1\
**Last updated:** [June 9, 2021, 6:51am UTC](https://discuss.elastic.co/t/problems-in-elasticsearch-combining-two-types-of-logs-using-two-pipelines-logstash/273900 "2021-06-09T06:51:43Z")

</div>

Hi everyone, I need some help. I have configured my ES stack inside a docker. I need to show two types of logs (syslog, log), in an Elastic index. I have created two configuration files logstash.cong logstash-syslog.c…

---

## [Logstash elasticsearch output, expand variables in data stream parameters](https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276)

<div class="topic-metadata">

**Author:** [@ebourlon](https://discuss.elastic.co/u/ebourlon)\
**Replies:** 2\
**Last updated:** [June 9, 2021, 6:13am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-expand-variables-in-data-stream-parameters/275276 "2021-06-09T06:13:01Z")

</div>

Hello, I am using logstash 7.13.1 that has support for datastreams in the elasticsearch output. As far as I looked at it is not possible to specify a variable in one of the datastream related parameter like below: e…

---

## [Send the Ruby Exception message along with the \_rubyException tag](https://discuss.elastic.co/t/send-the-ruby-exception-message-along-with-the-rubyexception-tag/275369)

<div class="topic-metadata">

**Author:** [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Replies:** 0\
**Last updated:** [June 9, 2021, 4:40am UTC](https://discuss.elastic.co/t/send-the-ruby-exception-message-along-with-the-rubyexception-tag/275369 "2021-06-09T04:40:25Z")

</div>

I have ruby filter processing and for some inputs, I do have ruby-exceptions and they are successfully propogated to elastic search with the tag. (expected). However I do not know why this exceptions are caused i.e the s…

---

## [Create event on change of field](https://discuss.elastic.co/t/create-event-on-change-of-field/275363)

<div class="topic-metadata">

**Author:** [@johnwood](https://discuss.elastic.co/u/johnwood)\
**Replies:** 1\
**Last updated:** [June 9, 2021, 3:31am UTC](https://discuss.elastic.co/t/create-event-on-change-of-field/275363 "2021-06-09T03:31:42Z")

</div>

Hi All I need some help getting started in the right direction with a logstash configuration please: We have log events coming into logstash right now. From each of the events we currently parse the name of a computer …

---

## [Copy/Rename multiple field in the same field + adding multiples field to one field](https://discuss.elastic.co/t/copy-rename-multiple-field-in-the-same-field-adding-multiples-field-to-one-field/275264)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 4\
**Last updated:** [June 8, 2021, 10:07pm UTC](https://discuss.elastic.co/t/copy-rename-multiple-field-in-the-same-field-adding-multiples-field-to-one-field/275264 "2021-06-08T22:07:43Z")

</div>

Hello every body, I have two question about the mutate filter: The first one is about adding a0,a1 and a2 fiels that contain the process args to a same field \[process\]\[args\] (process.args=a0,a1,a2) how i can do it ? …

---

## [Help with Split Filter](https://discuss.elastic.co/t/help-with-split-filter/275339)

<div class="topic-metadata">

**Author:** [@pvxchain](https://discuss.elastic.co/u/pvxchain)\
**Replies:** 3\
**Last updated:** [June 8, 2021, 8:59pm UTC](https://discuss.elastic.co/t/help-with-split-filter/275339 "2021-06-08T20:59:08Z")

</div>

Hello I'm trying to create two events out of one so that the subsequent pipeline takes place in both. The event itself, before the split happens here: filter { if \[type\] == "pre-split" { mutate { replac…

---

## [Failed to run logstash with NotImplementedError](https://discuss.elastic.co/t/failed-to-run-logstash-with-notimplementederror/275238)

<div class="topic-metadata">

**Author:** [@tod-yangyd](https://discuss.elastic.co/u/tod-yangyd)\
**Replies:** 1\
**Last updated:** [June 8, 2021, 8:08pm UTC](https://discuss.elastic.co/t/failed-to-run-logstash-with-notimplementederror/275238 "2021-06-08T20:08:41Z")

</div>

Errors when running logstash (solaris10 SPARCS version) java\_version : oracle jdk 1.8 I noticed that there was a reference to ubuntu's add "libc6-dev" on the Internet, but this does not apply to solaris. warning: thre…

---

## [Error to set custom date pattern and change value of @timestamp](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170)

<div class="topic-metadata">

**Author:** [@mar-ro](https://discuss.elastic.co/u/mar-ro)\
**Replies:** 3\
**Last updated:** [June 8, 2021, 7:52pm UTC](https://discuss.elastic.co/t/error-to-set-custom-date-pattern-and-change-value-of-timestamp/275170 "2021-06-08T19:52:11Z")

</div>

Hello! I've tried to use the following code to change the value of @timestamp but I couldn't do it.. input { pipeline { address =\> crontab } } filter { grok { match =\> { "message" =\> "(?\<fecha\>%{MONTH} %{MO…

---

## [Filtering logs in logstash](https://discuss.elastic.co/t/filtering-logs-in-logstash/275245)

<div class="topic-metadata">

**Author:** [@Zubaer\_Ahmad](https://discuss.elastic.co/u/Zubaer_Ahmad)\
**Replies:** 1\
**Last updated:** [June 8, 2021, 5:02pm UTC](https://discuss.elastic.co/t/filtering-logs-in-logstash/275245 "2021-06-08T17:02:38Z")

</div>

I am trying to filter the following log in logstash but couldn't make it work. Can anyone help me on this. thanks debug | 2021-06-08 12:02:50 | +3ms | SCHEDULER | REQUEST\_ID: ff23e465-7d36-42ea-9a2b-2ba734dde41b | IP\_AD…

---

## [Logstash clone filter use event field as clones parameter](https://discuss.elastic.co/t/logstash-clone-filter-use-event-field-as-clones-parameter/275250)

<div class="topic-metadata">

**Author:** [@ebourlon](https://discuss.elastic.co/u/ebourlon)\
**Replies:** 1\
**Last updated:** [June 8, 2021, 5:02pm UTC](https://discuss.elastic.co/t/logstash-clone-filter-use-event-field-as-clones-parameter/275250 "2021-06-08T17:02:01Z")

</div>

Hello, I made some tests with the clone filter in logstash. In my opinion there is no way to make the "clones" parameter dynamic. Does someone know how this can be done? Looking at the filter code I think it might be c…

---

## [Split JSON into several events](https://discuss.elastic.co/t/split-json-into-several-events/275212)

<div class="topic-metadata">

**Author:** [@rmartinez.rv](https://discuss.elastic.co/u/rmartinez.rv)\
**Replies:** 4\
**Last updated:** [June 8, 2021, 4:17pm UTC](https://discuss.elastic.co/t/split-json-into-several-events/275212 "2021-06-08T16:17:12Z")

</div>

Hi. I'm trying to split into several events a JSON input. I have something like this: { "Domains": \[ { "name": "location", "hash\_size": 4096, "AORs": \[ {…

---

## [Maintaining Multiple Logstash Servers](https://discuss.elastic.co/t/maintaining-multiple-logstash-servers/275315)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 2\
**Last updated:** [June 8, 2021, 3:54pm UTC](https://discuss.elastic.co/t/maintaining-multiple-logstash-servers/275315 "2021-06-08T15:54:07Z")

</div>

I would like to set up multiple logstash servers for load balancing as mentioned here. Is there a best practice for maintaining the multiple pipeline files (one for each instance of logstash) besides just configuring one…

---

## [Logstash ERROR \`block in controlled\_read'](https://discuss.elastic.co/t/logstash-error-block-in-controlled-read/275269)

<div class="topic-metadata">

**Author:** [@oduvancheg666](https://discuss.elastic.co/u/oduvancheg666)\
**Replies:** 0\
**Last updated:** [June 8, 2021, 9:01am UTC](https://discuss.elastic.co/t/logstash-error-block-in-controlled-read/275269 "2021-06-08T09:01:53Z")

</div>

Hello. Logstash version 7.3.0 gets the error: \[2021-06-08T10:13:48,304\]\[ERROR\]\[filewatch.tailmode.handlers.grow\] read\_to\_eof: general error reading //PC/C$/inetpub/logs/LogFiles/W3SVC2/u\_ex210608.log {"error"=\>"#\<System…

---

## [Grok pattern(s) working in debugger but not used in logstash?](https://discuss.elastic.co/t/grok-pattern-s-working-in-debugger-but-not-used-in-logstash/274602)

<div class="topic-metadata">

**Author:** [@3lastic](https://discuss.elastic.co/u/3lastic)\
**Replies:** 14\
**Last updated:** [June 8, 2021, 8:04am UTC](https://discuss.elastic.co/t/grok-pattern-s-working-in-debugger-but-not-used-in-logstash/274602 "2021-06-08T08:04:07Z")

</div>

Hello, I try to get Sophos Firewall logs into logstash (which is working) but my grok filter to get the logline separated into fields is not working. The test via grok debugger is working... Here are my logstash conf f…

---

## [How to install logstash-integration-jdbc plugin](https://discuss.elastic.co/t/how-to-install-logstash-integration-jdbc-plugin/275241)

<div class="topic-metadata">

**Author:** [@charles97](https://discuss.elastic.co/u/charles97)\
**Replies:** 0\
**Last updated:** [June 8, 2021, 7:33am UTC](https://discuss.elastic.co/t/how-to-install-logstash-integration-jdbc-plugin/275241 "2021-06-08T07:33:04Z")

</div>

I'm trying to install logstash-integration-jdbc following this git logstash-integration-jdbc running logstash 7.12.1 I've installed jruby $ jruby --version jruby 9.1.17.0 (2.3.3) 2020-02-29 fffffff OpenJDK 64-Bit Ser…

---

## [Logstash is not listening on the port from .conf file](https://discuss.elastic.co/t/logstash-is-not-listening-on-the-port-from-conf-file/275023)

<div class="topic-metadata">

**Author:** [@devashishsingh](https://discuss.elastic.co/u/devashishsingh)\
**Replies:** 2\
**Last updated:** [June 8, 2021, 6:29am UTC](https://discuss.elastic.co/t/logstash-is-not-listening-on-the-port-from-conf-file/275023 "2021-06-08T06:29:50Z")

</div>

I am trying to get TCP 6514 for SSL enabled logs to Logstash. I created a simple .conf file with no filters and then restarted Logstash. Still the localhost doesn't seems to listen on 6514. In addition to this, when I …

---

## [Filter and ouput is skipped when apply a tag conditional statement](https://discuss.elastic.co/t/filter-and-ouput-is-skipped-when-apply-a-tag-conditional-statement/275228)

<div class="topic-metadata">

**Author:** [@ivanhoe-dev](https://discuss.elastic.co/u/ivanhoe-dev)\
**Replies:** 1\
**Last updated:** [June 8, 2021, 6:16am UTC](https://discuss.elastic.co/t/filter-and-ouput-is-skipped-when-apply-a-tag-conditional-statement/275228 "2021-06-08T06:16:05Z")

</div>

In my use case, I have around 20 csv to upload, so I prepare 20 logstash config files and add an unique tag for each of them to filter and output conditionally. However, when I run logstash in the directory, only one of …

---

## [Logstash Elasticsearch input plugin mTLS](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098)

<div class="topic-metadata">

**Author:** [@Armen\_Petrosyan](https://discuss.elastic.co/u/Armen_Petrosyan)\
**Replies:** 2\
**Last updated:** [June 8, 2021, 6:14am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin-mtls/275098 "2021-06-08T06:14:14Z")

</div>

I have question related to mutual TLS authentication in case of using logstash Elasticsearch input plugin. I have Elasticsearch cluster installed and configured to work over tls using mutual authentication. Now I want t…

---

## [Logstash DLQ not starting up (Dockerized LS)](https://discuss.elastic.co/t/logstash-dlq-not-starting-up-dockerized-ls/275220)

<div class="topic-metadata">

**Author:** [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Replies:** 2\
**Last updated:** [June 8, 2021, 3:28am UTC](https://discuss.elastic.co/t/logstash-dlq-not-starting-up-dockerized-ls/275220 "2021-06-08T03:28:34Z")

</div>

Hi, I have a Dockerized LS setup working on a pipeline (Logstash Docker 7.13) I added the DLQ settings via environment variables to the LS container and run another pipeline in the same container (named as "dlq-mypipel…

---

## [Could not execute action: PipelineAction::Create](https://discuss.elastic.co/t/could-not-execute-action-pipelineaction-create/275196)

<div class="topic-metadata">

**Author:** [@jeroen.antsec](https://discuss.elastic.co/u/jeroen.antsec)\
**Replies:** 0\
**Last updated:** [June 7, 2021, 8:02pm UTC](https://discuss.elastic.co/t/could-not-execute-action-pipelineaction-create/275196 "2021-06-07T20:02:26Z")

</div>

Hi guys, I have a question. I have a nice running logstash and elastic cluster. When i create a large pipeline of over 4000 lines logstash crashes with the following error: \[2021-06-07T19:27:23,511\]\[INFO \]\[logstash.jav…

---

## [Logstash stops getting events once in 3 days](https://discuss.elastic.co/t/logstash-stops-getting-events-once-in-3-days/274490)

<div class="topic-metadata">

**Author:** [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)\
**Replies:** 10\
**Last updated:** [June 7, 2021, 5:11pm UTC](https://discuss.elastic.co/t/logstash-stops-getting-events-once-in-3-days/274490 "2021-06-07T17:11:40Z")

</div>

We are using Logstash 7.4.2. Once in 3-4 days, Logstash stops processing events and its not parsing new events till we restart the service. We see only below error in log , :body=\>"{"error":{"root\_cause":\[{"type":"actio…

---

## [Cannot get original timestamp from WSo2 logs coming from Source -\> filebeat -\> logstash -\> Elasticsearch](https://discuss.elastic.co/t/cannot-get-original-timestamp-from-wso2-logs-coming-from-source-filebeat-logstash-elasticsearch/275148)

<div class="topic-metadata">

**Author:** [@Jefledge](https://discuss.elastic.co/u/Jefledge)\
**Replies:** 1\
**Last updated:** [June 7, 2021, 4:59pm UTC](https://discuss.elastic.co/t/cannot-get-original-timestamp-from-wso2-logs-coming-from-source-filebeat-logstash-elasticsearch/275148 "2021-06-07T16:59:19Z")

</div>

I currently have logstash and filebeat running on the same AWS EC2 as a proof of concept to get logs from efs and push to Elastic for us to view on Kibana. It is all set up and working nicely, there is just one issue I c…

---

## [How Logstash works for 10,000 lines of log file](https://discuss.elastic.co/t/how-logstash-works-for-10-000-lines-of-log-file/275118)

<div class="topic-metadata">

**Author:** [@sudo-ranjith](https://discuss.elastic.co/u/sudo-ranjith)\
**Replies:** 3\
**Last updated:** [June 7, 2021, 4:58pm UTC](https://discuss.elastic.co/t/how-logstash-works-for-10-000-lines-of-log-file/275118 "2021-06-07T16:58:00Z")

</div>

I have log file that has 10,000 lines of logs, every hour 10 lines of logs will be added in the log file. at 3 AM I have 10,000 line of logs at 4 AM 10,010 lines of logs at 5 AM 10,020 lines of logs.... I would like …

---

## [Elastic App Search -- Importing Json files](https://discuss.elastic.co/t/elastic-app-search-importing-json-files/274992)

<div class="topic-metadata">

**Author:** [@NiklasSpira](https://discuss.elastic.co/u/NiklasSpira)\
**Replies:** 3\
**Last updated:** [June 7, 2021, 4:51pm UTC](https://discuss.elastic.co/t/elastic-app-search-importing-json-files/274992 "2021-06-07T16:51:35Z")

</div>

Hello Guys, I have a problem with importing Jsons into my Elastic App Search. I've gone through nearly all the existing threads, here and everywhere else but I couldn't get my problem fixed. I'm currently trying to imp…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=220)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=222)
