# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=224

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 225

---

## [Convert the @timestamp field](https://discuss.elastic.co/t/convert-the-timestamp-field/273902)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 6\
**Last updated:** [June 1, 2021, 5:26am UTC](https://discuss.elastic.co/t/convert-the-timestamp-field/273902 "2021-06-01T05:26:18Z")

</div>

Hello All , I am trying to convert the @timestamp field to the required format. @timestamp shows the field as : 2021-05-25T07:34:08.137Z and I want the value to be converted in to this format : 05/25/2021 07:34:08 . I …

---

## [Mutate rename issue after upgrade](https://discuss.elastic.co/t/mutate-rename-issue-after-upgrade/274558)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [June 1, 2021, 2:27am UTC](https://discuss.elastic.co/t/mutate-rename-issue-after-upgrade/274558 "2021-06-01T02:27:50Z")

</div>

Hello, I have a pipeline where that receives data from a F5 load balancer and parses it with the cef codec, in the filters I have a series of mutate using rename to change the name of some fields to their ecs correspond…

---

## [Logstash aggregation overwrite](https://discuss.elastic.co/t/logstash-aggregation-overwrite/274556)

<div class="topic-metadata">

**Author:** [@fuzes](https://discuss.elastic.co/u/fuzes)\
**Replies:** 1\
**Last updated:** [June 1, 2021, 1:13am UTC](https://discuss.elastic.co/t/logstash-aggregation-overwrite/274556 "2021-06-01T01:13:42Z")

</div>

I don't know why aggregation is overwritten by last one following is my logstash code filter { aggregate { task\_id =\> "%{code}" code =\> " map\['code'\] = event.get('code') map\[event.get('langu…

---

## [Text Files received by Logstash from Filebeat is not same as Source Files](https://discuss.elastic.co/t/text-files-received-by-logstash-from-filebeat-is-not-same-as-source-files/274512)

<div class="topic-metadata">

**Author:** [@Resington\_R](https://discuss.elastic.co/u/Resington_R)\
**Replies:** 2\
**Last updated:** [May 31, 2021, 7:32pm UTC](https://discuss.elastic.co/t/text-files-received-by-logstash-from-filebeat-is-not-same-as-source-files/274512 "2021-05-31T19:32:04Z")

</div>

Hi everyone... I am transferring text files from my Application Server to Logstash Server using below logstash config file. The files transmitted are received perfectly, but some of the lines in the received text files …

---

## [Logstash don't execute my two Pipelines file](https://discuss.elastic.co/t/logstash-dont-execute-my-two-pipelines-file/274400)

<div class="topic-metadata">

**Author:** [@Denilson-Semedo](https://discuss.elastic.co/u/Denilson-Semedo)\
**Replies:** 4\
**Last updated:** [May 31, 2021, 5:49pm UTC](https://discuss.elastic.co/t/logstash-dont-execute-my-two-pipelines-file/274400 "2021-05-31T17:49:59Z")

</div>

i thease have two pipeline in the logstash pipeline folder logstash.conf : input { beats { port =\> 5066 } } filter { if \[cloud\]\[account\]\[id\] == "941682856883" { mutate { add\_field =\> { "ambiente" =\> "d…

---

## [Show udp source port](https://discuss.elastic.co/t/show-udp-source-port/274539)

<div class="topic-metadata">

**Author:** [@Alex\_Der](https://discuss.elastic.co/u/Alex_Der)\
**Replies:** 1\
**Last updated:** [May 31, 2021, 5:49pm UTC](https://discuss.elastic.co/t/show-udp-source-port/274539 "2021-05-31T17:49:28Z")

</div>

I'm using Logstash to ingest the logs sent (via udp) by 5 different applications running on another machine. Each aplication sends its log to Logstash from a different port (e.g. application\_1 from port 1760, applicatio…

---

## [How to change "type" keyword in clone plugin](https://discuss.elastic.co/t/how-to-change-type-keyword-in-clone-plugin/274499)

<div class="topic-metadata">

**Author:** [@rknd](https://discuss.elastic.co/u/rknd)\
**Replies:** 2\
**Last updated:** [May 31, 2021, 3:14pm UTC](https://discuss.elastic.co/t/how-to-change-type-keyword-in-clone-plugin/274499 "2021-05-31T15:14:50Z")

</div>

clone plugin default use "type" keyword. In my logstash configuration I use multiple times "type" keyword and now i need to add clone filter plugin in my logstash configuration. How can i use this plugin without using "…

---

## [Update logstash to specific version](https://discuss.elastic.co/t/update-logstash-to-specific-version/274503)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [May 31, 2021, 12:43pm UTC](https://discuss.elastic.co/t/update-logstash-to-specific-version/274503 "2021-05-31T12:43:06Z")

</div>

Hello, I'm upgrading my stack from 7.9.3 to 7.12.1 using yum. For elasticsearch and filebeat I can update for the specific version without any problem using: yum install filebeat-7.12.1 yum install elasticsearch-7.12.…

---

## [Support for PKCS#5 v2.0 in LogStash](https://discuss.elastic.co/t/support-for-pkcs-5-v2-0-in-logstash/274487)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 0\
**Last updated:** [May 31, 2021, 11:03am UTC](https://discuss.elastic.co/t/support-for-pkcs-5-v2-0-in-logstash/274487 "2021-05-31T11:03:00Z")

</div>

Hi all, We are currently migrating our Elastic Stack from RHEL 7 to RHEL 8 which also upgrades openssl from 1.0.2k to 1.1.1g At first we could not figure out why LogStash was not able to start our pipeline containing a…

---

## [Logstash "if" condition not working as expected](https://discuss.elastic.co/t/logstash-if-condition-not-working-as-expected/274483)

<div class="topic-metadata">

**Author:** [@suryarao67](https://discuss.elastic.co/u/suryarao67)\
**Replies:** 1\
**Last updated:** [May 31, 2021, 10:51am UTC](https://discuss.elastic.co/t/logstash-if-condition-not-working-as-expected/274483 "2021-05-31T10:51:35Z")

</div>

Below is my input message to logstash { "object2": "", "headers": { "request\_path": "/", "request\_method": "POST", "http\_accept": "\*/\*", "content\_type": "application/json; charset=utf-8", "http\_version": "HT…

---

## [I want to save all \_grokparsefailure entries in a file to review them later, however](https://discuss.elastic.co/t/i-want-to-save-all-grokparsefailure-entries-in-a-file-to-review-them-later-however/273477)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 5\
**Last updated:** [May 31, 2021, 5:22am UTC](https://discuss.elastic.co/t/i-want-to-save-all-grokparsefailure-entries-in-a-file-to-review-them-later-however/273477 "2021-05-31T05:22:17Z")

</div>

My output configuration portion: if "\_grokparsefailure" in \[tags\] { file { path =\> "/home/myaccount/testfolder/grokfailures" file\_mode =\> 0600 } } else { file { path =\> "/home/myaccount/testfolder/groksuccess" …

---

## [Is there a way to exclude unwanted lines into one event with logstash](https://discuss.elastic.co/t/is-there-a-way-to-exclude-unwanted-lines-into-one-event-with-logstash/274309)

<div class="topic-metadata">

**Author:** [@syrine\_chelly](https://discuss.elastic.co/u/syrine_chelly)\
**Replies:** 3\
**Last updated:** [May 30, 2021, 5:13pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-exclude-unwanted-lines-into-one-event-with-logstash/274309 "2021-05-30T17:13:58Z")

</div>

i want to delete certain lines in the messsage field using logstash .I don't want to drop the field just extra lines in the field. is it possible ?

---

## [I am Trying to use logstash oss 7.9.1 to push csv files into Open Distro Elasticsearch 1.13.2](https://discuss.elastic.co/t/i-am-trying-to-use-logstash-oss-7-9-1-to-push-csv-files-into-open-distro-elasticsearch-1-13-2/274411)

<div class="topic-metadata">

**Author:** [@aswanth\_jabba](https://discuss.elastic.co/u/aswanth_jabba)\
**Replies:** 1\
**Last updated:** [May 30, 2021, 4:06am UTC](https://discuss.elastic.co/t/i-am-trying-to-use-logstash-oss-7-9-1-to-push-csv-files-into-open-distro-elasticsearch-1-13-2/274411 "2021-05-30T04:06:06Z")

</div>

Please suggest me with version combabilities, I am not sure if thats the case of my errors When I try to run logstash i get these errors \[2021-05-30T03:34:51,112\]\[WARN \]\[logstash.config.source.multilocal\] Ignoring the …

---

## [Qradar Logs to Logstash/Elastic?](https://discuss.elastic.co/t/qradar-logs-to-logstash-elastic/274385)

<div class="topic-metadata">

**Author:** [@mohamed\_el\_mannouti](https://discuss.elastic.co/u/mohamed_el_mannouti)\
**Replies:** 3\
**Last updated:** [May 30, 2021, 12:58am UTC](https://discuss.elastic.co/t/qradar-logs-to-logstash-elastic/274385 "2021-05-30T00:58:02Z")

</div>

we have a Qradar SIEM which we plan to extend to Elastic for threat hunting(Log Forwarding from Qradar to Elastic) Has anyone found any success with it. Any known shortcomings/pitfalls from the setup.

---

## [Duplication of data due to logstash configuration](https://discuss.elastic.co/t/duplication-of-data-due-to-logstash-configuration/274382)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 6\
**Last updated:** [May 29, 2021, 4:15pm UTC](https://discuss.elastic.co/t/duplication-of-data-due-to-logstash-configuration/274382 "2021-05-29T16:15:49Z")

</div>

Hello, I hope you and your loved ones are safe and healthy. I am suspecting multiple copies of the same data being created due to faulty logstash configuration. Here is the ingestion pipeline: Log files in JSON file …

---

## [Logstash not starting with the error "error: jvm options parser failed; exiting"](https://discuss.elastic.co/t/logstash-not-starting-with-the-error-error-jvm-options-parser-failed-exiting/274393)

<div class="topic-metadata">

**Author:** [@Swaroop\_S](https://discuss.elastic.co/u/Swaroop_S)\
**Replies:** 1\
**Last updated:** [May 29, 2021, 8:44am UTC](https://discuss.elastic.co/t/logstash-not-starting-with-the-error-error-jvm-options-parser-failed-exiting/274393 "2021-05-29T08:44:51Z")

</div>

Hi All, I downloaded the logstash file and created the config file and I am trying to start the logstash with the command "logstash -f simple-config.conf" after navigating to bin folder in logstash. But I am getting err…

---

## [Logstash filter based on reference set or database](https://discuss.elastic.co/t/logstash-filter-based-on-reference-set-or-database/274302)

<div class="topic-metadata">

**Author:** [@redfish462](https://discuss.elastic.co/u/redfish462)\
**Replies:** 3\
**Last updated:** [May 28, 2021, 8:07pm UTC](https://discuss.elastic.co/t/logstash-filter-based-on-reference-set-or-database/274302 "2021-05-28T20:07:16Z")

</div>

Hello, I have to redirect some logs based on their username (the usernames are contains in the logs) to different outputs. This list has 80 entry, so it's a lot to write this in the configuration file. I would like to …

---

## [Calculating fields in logstash on upsert](https://discuss.elastic.co/t/calculating-fields-in-logstash-on-upsert/274371)

<div class="topic-metadata">

**Author:** [@tumbledwyer](https://discuss.elastic.co/u/tumbledwyer)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 7:59pm UTC](https://discuss.elastic.co/t/calculating-fields-in-logstash-on-upsert/274371 "2021-05-28T19:59:01Z")

</div>

Hi I have a pipeline used to enrich some json data from different sources to build up an index for a report. I would like to do a calculation based on 2 fields from the different sources, but since the sources are diffe…

---

## [Multiline: flush downstream error java.io.IOException since upgrading from 6.8 to 7.12](https://discuss.elastic.co/t/multiline-flush-downstream-error-java-io-ioexception-since-upgrading-from-6-8-to-7-12/274236)

<div class="topic-metadata">

**Author:** [@soulless](https://discuss.elastic.co/u/soulless)\
**Replies:** 3\
**Last updated:** [May 28, 2021, 5:51pm UTC](https://discuss.elastic.co/t/multiline-flush-downstream-error-java-io-ioexception-since-upgrading-from-6-8-to-7-12/274236 "2021-05-28T17:51:49Z")

</div>

We have a multiline config that we use for capturing exceptions. codec =\> multiline { pattern =\> "^%{TIMESTAMP\_ISO8601}" negate =\> true what =\> "previous" } It appears to still be working, but since upgradi…

---

## [Using already provided time period](https://discuss.elastic.co/t/using-already-provided-time-period/274299)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 5:03pm UTC](https://discuss.elastic.co/t/using-already-provided-time-period/274299 "2021-05-28T17:03:35Z")

</div>

Hello. I have a bit of a problem here - i'm reseiving via syslog some data including uptime/downtime periods in format "HHhr:MMmin:SSsec". There's no problem parsing it in an object like "downtime.\<hr/min/sec\>", but ho…

---

## [Get the name of the log file and create a tag or a custom field with that value](https://discuss.elastic.co/t/get-the-name-of-the-log-file-and-create-a-tag-or-a-custom-field-with-that-value/274344)

<div class="topic-metadata">

**Author:** [@mar-ro](https://discuss.elastic.co/u/mar-ro)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 4:58pm UTC](https://discuss.elastic.co/t/get-the-name-of-the-log-file-and-create-a-tag-or-a-custom-field-with-that-value/274344 "2021-05-28T16:58:12Z")

</div>

Good afternoon. I would like to know how I could in logstash create a tag (or a custom field) with a part of the value of the log.file.path.keyword field. Considering that this field stores the absolute path, I would be…

---

## [Filebeat to logstash encoding error](https://discuss.elastic.co/t/filebeat-to-logstash-encoding-error/274314)

<div class="topic-metadata">

**Author:** [@jezemery](https://discuss.elastic.co/u/jezemery)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 4:39pm UTC](https://discuss.elastic.co/t/filebeat-to-logstash-encoding-error/274314 "2021-05-28T16:39:54Z")

</div>

Hey, I'm attempting to use docker-elk from GitHub to set up a local ELK stack for testing purposes. I have the containers running fine. I also configured filebeat on my local machine to monitor nginx logs. For some rea…

---

## [Postgresql -\> Jdbc input plugin -\> logstash - ERROR: relation does not exist](https://discuss.elastic.co/t/postgresql-jdbc-input-plugin-logstash-error-relation-does-not-exist/274296)

<div class="topic-metadata">

**Author:** [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 3:03pm UTC](https://discuss.elastic.co/t/postgresql-jdbc-input-plugin-logstash-error-relation-does-not-exist/274296 "2021-05-28T15:03:06Z")

</div>

Hello everyone, It seems im missing something, but couldn't found anything related to this. Im using jdbc input plugin to collect some data from postgresql db. \[2021-05-28T03:24:12,032\]\[ERROR\]\[logstash.inputs.jdbc …

---

## [Tagging errors parsing json messages](https://discuss.elastic.co/t/tagging-errors-parsing-json-messages/274326)

<div class="topic-metadata">

**Author:** [@alfredo.deluca](https://discuss.elastic.co/u/alfredo.deluca)\
**Replies:** 2\
**Last updated:** [May 28, 2021, 2:10pm UTC](https://discuss.elastic.co/t/tagging-errors-parsing-json-messages/274326 "2021-05-28T14:10:46Z")

</div>

Hi all we have elastic cloud 7.12 with logstash 7.12 parsing json messages and send them to elasticsearch, but as we are having issues with mismatch type I d like to tag the error when that happen. Do you have any idea…

---

## [Elasticsearch filter plugin and winlogbeat](https://discuss.elastic.co/t/elasticsearch-filter-plugin-and-winlogbeat/273794)

<div class="topic-metadata">

**Author:** [@fabryx87](https://discuss.elastic.co/u/fabryx87)\
**Replies:** 1\
**Last updated:** [May 28, 2021, 7:43am UTC](https://discuss.elastic.co/t/elasticsearch-filter-plugin-and-winlogbeat/273794 "2021-05-28T07:43:00Z")

</div>

Goodmorning everyone, I am trying to use for the firts time the elasticsearch filter plugin for logstash. I am trying to searching the login event whenever you the log off event and enrich the log off event with necess…

---

## [Logstash pipeline stopped inserting data into elasticsearch](https://discuss.elastic.co/t/logstash-pipeline-stopped-inserting-data-into-elasticsearch/274285)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 0\
**Last updated:** [May 28, 2021, 5:40am UTC](https://discuss.elastic.co/t/logstash-pipeline-stopped-inserting-data-into-elasticsearch/274285 "2021-05-28T05:40:56Z")

</div>

Logstash pipeline is not ingesting data into the elasticsearch index though the pipeline was running. This pipeline was deployed one year back and it was running well since then. But on 24th May 2021, it stopped ingesti…

---

## [How to create multiple index in logstash?](https://discuss.elastic.co/t/how-to-create-multiple-index-in-logstash/274212)

<div class="topic-metadata">

**Author:** [@Guhan\_S](https://discuss.elastic.co/u/Guhan_S)\
**Replies:** 1\
**Last updated:** [May 27, 2021, 11:16pm UTC](https://discuss.elastic.co/t/how-to-create-multiple-index-in-logstash/274212 "2021-05-27T23:16:49Z")

</div>

Am running 2 applications in same AWS ec2 instance as docker-containers.. now I want to create separate index for both application. Filebeat is running on application server. And elk is running on another instance. fi…

---

## [Logstash stopped processing because of an error: (SystemExit)](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit/274267)

<div class="topic-metadata">

**Author:** [@soldider1621](https://discuss.elastic.co/u/soldider1621)\
**Replies:** 0\
**Last updated:** [May 27, 2021, 9:35pm UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit/274267 "2021-05-27T21:35:31Z")

</div>

Hi, I am trying to run the logstash service but it always stops due to error, below I share the log. I can't find the reason for the error, has it happened to you? If I use the program directly from command, it works w…

---

## [Mutate Lowercase Issue](https://discuss.elastic.co/t/mutate-lowercase-issue/274247)

<div class="topic-metadata">

**Author:** [@Alexandre.Bernier](https://discuss.elastic.co/u/Alexandre.Bernier)\
**Replies:** 4\
**Last updated:** [May 27, 2021, 7:46pm UTC](https://discuss.elastic.co/t/mutate-lowercase-issue/274247 "2021-05-27T19:46:09Z")

</div>

Hi, I'm running Logstash 7.3 and I actually face an issue (or maybe I didn't write the filter correctly) when I apply a lowercase to a new field. The base field is always lowered too. First, I tried this: filter { …

---

## [Force insert double quotes in a field value](https://discuss.elastic.co/t/force-insert-double-quotes-in-a-field-value/274144)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 2\
**Last updated:** [May 27, 2021, 6:41pm UTC](https://discuss.elastic.co/t/force-insert-double-quotes-in-a-field-value/274144 "2021-05-27T18:41:40Z")

</div>

Hi all, I have been trying to force wrap double quotes around a field value so it can be used in the query statements of the elasticsearch plugin. the field in question is the network.community\_id which includes a colo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=223)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=225)
