# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=23

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 24

---

## [Logstash tcp output plugin](https://discuss.elastic.co/t/logstash-tcp-output-plugin/364933)

<div class="topic-metadata">

**Author:** [@pradeep-logstashuser](https://discuss.elastic.co/u/pradeep-logstashuser)\
**Replies:** 2\
**Last updated:** [August 16, 2024, 6:09am UTC](https://discuss.elastic.co/t/logstash-tcp-output-plugin/364933 "2024-08-16T06:09:39Z")

</div>

Hi, I am using the Logstash TCP output plugin, and even though I removed the host field from my event, I still receive the %host string at the beginning of the event string. Is there any option to remove that? When I pr…

---

## [Logstash fails 409 conflict unknown column: 'type'\\"](https://discuss.elastic.co/t/logstash-fails-409-conflict-unknown-column-type/364886)

<div class="topic-metadata">

**Author:** [@ridish](https://discuss.elastic.co/u/ridish)\
**Replies:** 5\
**Last updated:** [August 16, 2024, 12:10am UTC](https://discuss.elastic.co/t/logstash-fails-409-conflict-unknown-column-type/364886 "2024-08-16T00:10:29Z")

</div>

Hello Everyone, I'm a newbie to logstash and i'm trying to configure logstash with manticore which is based on elasticsearch 6.3.2. And i have the following config input { # Input for the first log file file { …

---

## [Http\_poller and ignore SSL Validation](https://discuss.elastic.co/t/http-poller-and-ignore-ssl-validation/364986)

<div class="topic-metadata">

**Author:** [@rmoss25](https://discuss.elastic.co/u/rmoss25)\
**Replies:** 0\
**Last updated:** [August 15, 2024, 9:18pm UTC](https://discuss.elastic.co/t/http-poller-and-ignore-ssl-validation/364986 "2024-08-15T21:18:32Z")

</div>

Hi, How do you ignore the SSL validation when using the http\_poller plugin? I get the following error when I try to pull API events from a reputable sites REST API. The site is using a valid certificate as its a well …

---

## [How to count empty fields zero](https://discuss.elastic.co/t/how-to-count-empty-fields-zero/364945)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 2\
**Last updated:** [August 15, 2024, 11:08am UTC](https://discuss.elastic.co/t/how-to-count-empty-fields-zero/364945 "2024-08-15T11:08:06Z")

</div>

I have a dataset like this: As shown, there are some empty fields on the dataset. While indexing that file onto ES, I want to fill these empty fields with "0" automatically. How could I do that on Logstash?

---

## [How to load emails into ES instance](https://discuss.elastic.co/t/how-to-load-emails-into-es-instance/364730)

<div class="topic-metadata">

**Author:** [@jaime\_solas](https://discuss.elastic.co/u/jaime_solas)\
**Replies:** 21\
**Last updated:** [August 15, 2024, 8:40am UTC](https://discuss.elastic.co/t/how-to-load-emails-into-es-instance/364730 "2024-08-15T08:40:11Z")

</div>

Hello, I am trying to upload emails in xml format, these xml files were obtained using apache tika to convert the .eml files to .xml I'm trying to load the data into ES with logstash but it's not working and I think it'…

---

## [Fleet Logstash resets back to default setting](https://discuss.elastic.co/t/fleet-logstash-resets-back-to-default-setting/364911)

<div class="topic-metadata">

**Author:** [@Matthew\_Wilhelm](https://discuss.elastic.co/u/Matthew_Wilhelm)\
**Replies:** 5\
**Last updated:** [August 14, 2024, 2:45pm UTC](https://discuss.elastic.co/t/fleet-logstash-resets-back-to-default-setting/364911 "2024-08-14T14:45:28Z")

</div>

Hello everyone, When I either try to add a row to logstash hosts in the grid-logstash or create my own object with it being the default for agent integrations and agent monitoring. After about 5 minutes it resets to the…

---

## [Logstash Stops Very Frequently](https://discuss.elastic.co/t/logstash-stops-very-frequently/364843)

<div class="topic-metadata">

**Author:** [@awesomeparam](https://discuss.elastic.co/u/awesomeparam)\
**Replies:** 2\
**Last updated:** [August 13, 2024, 5:49pm UTC](https://discuss.elastic.co/t/logstash-stops-very-frequently/364843 "2024-08-13T17:49:45Z")

</div>

Using the version 5.6.2 of Logstash, and I see lot of times the following message in the logstash-json.log file {"level":"ERROR","loggerName":"logstash.shutdownwatcher","timeMillis":1723464009728,"thread":"Ruby-0-Thread…

---

## [Password of the Encrypted Key for HTTP Output](https://discuss.elastic.co/t/password-of-the-encrypted-key-for-http-output/364836)

<div class="topic-metadata">

**Author:** [@tepus](https://discuss.elastic.co/u/tepus)\
**Replies:** 2\
**Last updated:** [August 13, 2024, 4:15pm UTC](https://discuss.elastic.co/t/password-of-the-encrypted-key-for-http-output/364836 "2024-08-13T16:15:49Z")

</div>

Dear Elastic Community, The version of the Logstash client is 8.5.3. We're trying to set a Logstash-to-Logstash connection with the following settings in the pipeline of the client: output { http { format =\> jso…

---

## [Logstash Unable to Output Data to Elasticsearch](https://discuss.elastic.co/t/logstash-unable-to-output-data-to-elasticsearch/364758)

<div class="topic-metadata">

**Author:** [@tom\_ding](https://discuss.elastic.co/u/tom_ding)\
**Replies:** 2\
**Last updated:** [August 13, 2024, 8:04am UTC](https://discuss.elastic.co/t/logstash-unable-to-output-data-to-elasticsearch/364758 "2024-08-13T08:04:20Z")

</div>

I am using Elasticsearch 8.13.4, Logstash 8.13.4, and Filebeat 8.13.4. I followed the steps in the documentation here to get familiar with Logstash, but I am unable to sync data to Elasticsearch. I am encountering the fo…

---

## [Memcached filter can't find host when using tls](https://discuss.elastic.co/t/memcached-filter-cant-find-host-when-using-tls/364803)

<div class="topic-metadata">

**Author:** [@JayAskrenPureStorage](https://discuss.elastic.co/u/JayAskrenPureStorage)\
**Replies:** 1\
**Last updated:** [August 13, 2024, 1:10am UTC](https://discuss.elastic.co/t/memcached-filter-cant-find-host-when-using-tls/364803 "2024-08-13T01:10:38Z")

</div>

How do we connect the memecached filter for logstash to AWS Elasticache with tls? We are using the memcached filter for logstash to augment our logs using AWS Elasticache and the filter looks something like this: m…

---

## [Logstash Vulnerability scanner, High CPU utilization](https://discuss.elastic.co/t/logstash-vulnerability-scanner-high-cpu-utilization/363042)

<div class="topic-metadata">

**Author:** [@amaljoy](https://discuss.elastic.co/u/amaljoy)\
**Replies:** 4\
**Last updated:** [August 12, 2024, 6:44am UTC](https://discuss.elastic.co/t/logstash-vulnerability-scanner-high-cpu-utilization/363042 "2024-08-12T06:44:42Z")

</div>

There is a vulnerability scan and penetration testing done from tenable.io / nessus server in our logstash server. This is my input plugin config in logstash. input { syslog { id =\> "idsyslog" host =\> "0.0.0.0" …

---

## [Received an event that has a different character encoding than you configured - Logstash CPU](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-than-you-configured-logstash-cpu/361297)

<div class="topic-metadata">

**Author:** [@amaljoy](https://discuss.elastic.co/u/amaljoy)\
**Replies:** 9\
**Last updated:** [August 12, 2024, 6:42am UTC](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-than-you-configured-logstash-cpu/361297 "2024-08-12T06:42:35Z")

</div>

Hi Guys, I received an unknown event from the syslog server. Received an event that has a different character encoding than you configured. {:text=\>"\\\\xC0\\\\u0014\\\\u00009\\\\u00008\\\\u0000\\\\x88\\\\u0000\\\\x87\\\\xC0\\\\u0019\\\\u0…

---

## [Reconcile data in ElasticSearch using logstash filter or output plugin](https://discuss.elastic.co/t/reconcile-data-in-elasticsearch-using-logstash-filter-or-output-plugin/363317)

<div class="topic-metadata">

**Author:** [@vvavad](https://discuss.elastic.co/u/vvavad)\
**Replies:** 4\
**Last updated:** [August 10, 2024, 11:13am UTC](https://discuss.elastic.co/t/reconcile-data-in-elasticsearch-using-logstash-filter-or-output-plugin/363317 "2024-08-10T11:13:27Z")

</div>

I have a Elasticsearch index(index1) with document structure { "id": "id1", "addresses": \[ {"address": "a11","address\_2": "a21","city": "c1","state": "s1","zip": "12345","phone": "9191919191"}, \], "field1": "f1", "fi…

---

## [Kibana doesn't start](https://discuss.elastic.co/t/kibana-doesnt-start/364709)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 2\
**Last updated:** [August 10, 2024, 9:52am UTC](https://discuss.elastic.co/t/kibana-doesnt-start/364709 "2024-08-10T09:52:46Z")

</div>

I got that error when I tried to start the kibana. I reinstalled kibana after i got the error for the first time but it has shown again:

---

## [Logstash 8.14.3 not logging to /var/log/logstash](https://discuss.elastic.co/t/logstash-8-14-3-not-logging-to-var-log-logstash/364721)

<div class="topic-metadata">

**Author:** [@apal](https://discuss.elastic.co/u/apal)\
**Replies:** 2\
**Last updated:** [August 9, 2024, 9:08pm UTC](https://discuss.elastic.co/t/logstash-8-14-3-not-logging-to-var-log-logstash/364721 "2024-08-09T21:08:10Z")

</div>

Hi, This is my log4j2.properties: # status = error status = info name = LogstashPropertiesConfig appender.console.type = Console appender.console.name = plain\_console appender.console.layout.type = PatternLayout appen…

---

## [JDBC input has irregular schedule intervals](https://discuss.elastic.co/t/jdbc-input-has-irregular-schedule-intervals/364252)

<div class="topic-metadata">

**Author:** [@Mahdi\_Moazami](https://discuss.elastic.co/u/Mahdi_Moazami)\
**Replies:** 6\
**Last updated:** [August 9, 2024, 5:21pm UTC](https://discuss.elastic.co/t/jdbc-input-has-irregular-schedule-intervals/364252 "2024-08-09T17:21:47Z")

</div>

Hi Elastic team, We have about 300 pipelines setup which have JDBC inputs that fetches data from different databases landed on a central SQL server. All of the JDBC inputs have a schedule set on \*/5 \* \* \* \* (every 5 mi…

---

## [I controlled my config file tens of times but I got that error anyway](https://discuss.elastic.co/t/i-controlled-my-config-file-tens-of-times-but-i-got-that-error-anyway/364668)

<div class="topic-metadata">

**Author:** [@UMUT\_CAN\_ARGUN](https://discuss.elastic.co/u/UMUT_CAN_ARGUN)\
**Replies:** 2\
**Last updated:** [August 9, 2024, 11:45am UTC](https://discuss.elastic.co/t/i-controlled-my-config-file-tens-of-times-but-i-got-that-error-anyway/364668 "2024-08-09T11:45:59Z")

</div>

Here is my config file: Here is the error:

---

## [Cannot start logstash docker container](https://discuss.elastic.co/t/cannot-start-logstash-docker-container/364525)

<div class="topic-metadata">

**Author:** [@daverodgers](https://discuss.elastic.co/u/daverodgers)\
**Replies:** 2\
**Last updated:** [August 8, 2024, 9:04pm UTC](https://discuss.elastic.co/t/cannot-start-logstash-docker-container/364525 "2024-08-08T21:04:08Z")

</div>

Hi. I am trying to create a new ELK stack using docker compose. My ES and Kibana containers are running fine. However i am having issues with logstash. Originally it was starting using the docker compose file. But the …

---

## [Help with filter to create field from substring](https://discuss.elastic.co/t/help-with-filter-to-create-field-from-substring/364568)

<div class="topic-metadata">

**Author:** [@Big-Edd](https://discuss.elastic.co/u/Big-Edd)\
**Replies:** 2\
**Last updated:** [August 8, 2024, 11:05am UTC](https://discuss.elastic.co/t/help-with-filter-to-create-field-from-substring/364568 "2024-08-08T11:05:42Z")

</div>

Hello Everyone, We are inputting RabbitMQ messages that originates via SMTP, so the messages contain some SMTP information we need. The logstash.conf file I have so far looks something like this. input { rabbitmq { …

---

## [Logstash ARM64 Docker Image issue](https://discuss.elastic.co/t/logstash-arm64-docker-image-issue/364544)

<div class="topic-metadata">

**Author:** [@kfarr](https://discuss.elastic.co/u/kfarr)\
**Replies:** 0\
**Last updated:** [August 7, 2024, 2:43pm UTC](https://discuss.elastic.co/t/logstash-arm64-docker-image-issue/364544 "2024-08-07T14:43:15Z")

</div>

Pulling down version 7.17.23, 7.17.22,7.17.21 docker images for Logstash noticing the container will fail on ARM64 due to env2yaml being not being built for arm64. Checking Elastic Git, I pull down the env2yaml and runni…

---

## [Arabic and special characters](https://discuss.elastic.co/t/arabic-and-special-characters/363613)

<div class="topic-metadata">

**Author:** [@abdullah144](https://discuss.elastic.co/u/abdullah144)\
**Replies:** 4\
**Last updated:** [August 7, 2024, 10:28am UTC](https://discuss.elastic.co/t/arabic-and-special-characters/363613 "2024-08-07T10:28:34Z")

</div>

Dear Team, kindly note that when we stashing to Logstash with data contains Arabic or Special characters , it showing to HTML encoded text , Example : Ma’aden (original text) ----\>Ma&#8217;aden (elastic log) الرياض …

---

## [How to use input plugins with multiple Logstash hosts?](https://discuss.elastic.co/t/how-to-use-input-plugins-with-multiple-logstash-hosts/364486)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 4\
**Last updated:** [August 7, 2024, 9:54am UTC](https://discuss.elastic.co/t/how-to-use-input-plugins-with-multiple-logstash-hosts/364486 "2024-08-07T09:54:57Z")

</div>

Hi, I mainly use Logstash with Kafka input without any issue. But now I want to read some logs from elastic and write them to Kafka. So I used the elasticsearch input plugin. But what a surprise to see many logs in my…

---

## [WHERE condition in logstash](https://discuss.elastic.co/t/where-condition-in-logstash/364516)

<div class="topic-metadata">

**Author:** [@Danyal\_Danish](https://discuss.elastic.co/u/Danyal_Danish)\
**Replies:** 0\
**Last updated:** [August 7, 2024, 7:29am UTC](https://discuss.elastic.co/t/where-condition-in-logstash/364516 "2024-08-07T07:29:28Z")

</div>

Hi, I'm trying to run this query in the logstash jdbc but I'm facing this syntax error everytime. I tried multiple variations of single and double quotations but each time I'm getting the same error. Query: jdbc\_stre…

---

## [Output after a health check for destination?](https://discuss.elastic.co/t/output-after-a-health-check-for-destination/364445)

<div class="topic-metadata">

**Author:** [@Big-Edd](https://discuss.elastic.co/u/Big-Edd)\
**Replies:** 4\
**Last updated:** [August 7, 2024, 5:35am UTC](https://discuss.elastic.co/t/output-after-a-health-check-for-destination/364445 "2024-08-07T05:35:53Z")

</div>

Hello Everyone, When the output destination container is slower to start or unavailable, the message dequeued from RabbitMQ input is lost by Logstash. Is it possible to have the Logstash wait for a health check to be O…

---

## [Assistance with pruning Syslog plugin output](https://discuss.elastic.co/t/assistance-with-pruning-syslog-plugin-output/364497)

<div class="topic-metadata">

**Author:** [@L0rdV0ld3m0rt](https://discuss.elastic.co/u/L0rdV0ld3m0rt)\
**Replies:** 0\
**Last updated:** [August 6, 2024, 8:25pm UTC](https://discuss.elastic.co/t/assistance-with-pruning-syslog-plugin-output/364497 "2024-08-06T20:25:43Z")

</div>

First time trying to configure a Security Onion server to forward alerts on to a SIEM using the logstash syslog plugin. Have spent the better part of a day reading documentation and still at a loss. The config below is r…

---

## [Logstash--Exception caught in json filter](https://discuss.elastic.co/t/logstash-exception-caught-in-json-filter/364174)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 9\
**Last updated:** [August 6, 2024, 3:35pm UTC](https://discuss.elastic.co/t/logstash-exception-caught-in-json-filter/364174 "2024-08-06T15:35:05Z")

</div>

Logstash--Exception caught in json filter Below is my json log string: { "traceId": "o0uyveRU/8BkjL+lbpDlnQ==", "spanId": "73rmqIRmo34=", "operationName": "ProcessWorkItem", "startTime": "2024-07-22T06:07:12.650881…

---

## [Http\_poller input fails authentication](https://discuss.elastic.co/t/http-poller-input-fails-authentication/364429)

<div class="topic-metadata">

**Author:** [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Replies:** 1\
**Last updated:** [August 6, 2024, 1:56am UTC](https://discuss.elastic.co/t/http-poller-input-fails-authentication/364429 "2024-08-06T01:56:15Z")

</div>

Hi, I am trying to get logstash to produce the same output as the following curl command that connects to a test server's REST API but it is always failing authentication. curl -H "X-API-KEY: api\_key\_id" -H "X-SECRET: …

---

## [Struggling to Upsert only one field of a document](https://discuss.elastic.co/t/struggling-to-upsert-only-one-field-of-a-document/364351)

<div class="topic-metadata">

**Author:** [@sicarius\_noidea](https://discuss.elastic.co/u/sicarius_noidea)\
**Replies:** 0\
**Last updated:** [August 5, 2024, 7:16am UTC](https://discuss.elastic.co/t/struggling-to-upsert-only-one-field-of-a-document/364351 "2024-08-05T07:16:24Z")

</div>

Hello, I'm using Elasticsearch to store billions of data points, each with four key fields: value type date\_first\_seen date\_last\_seen I use Logstash to calculate an mmh3 ID for each document based on the type and val…

---

## [Logstash elastic\_agent input connection reset](https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-reset/364258)

<div class="topic-metadata">

**Author:** [@BlueNick](https://discuss.elastic.co/u/BlueNick)\
**Replies:** 0\
**Last updated:** [August 2, 2024, 9:38am UTC](https://discuss.elastic.co/t/logstash-elastic-agent-input-connection-reset/364258 "2024-08-02T09:38:24Z")

</div>

Hello, I'm trying to set up logstash to receive logs from elastic agents with output to elasticsearch. Everything goes well, elasticsearch receives correctly the logs but on logstash side I'm flooded of this type of wa…

---

## [Logstash port 514 input error](https://discuss.elastic.co/t/logstash-port-514-input-error/364215)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 6\
**Last updated:** [August 1, 2024, 5:18pm UTC](https://discuss.elastic.co/t/logstash-port-514-input-error/364215 "2024-08-01T17:18:09Z")

</div>

New RHEL 9 box trying to get logstash to listen on 514 but it fails out \[2024-08-01T10:45:37,012\]\[ERROR\]\[logstash.javapipeline \]\[main\]\[input-tcp-514\] A plugin had an unrecoverable error. Will restart this plugin. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=22)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=24)
