# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=24

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 25

---

## [Multiple events all end up with the same result from an http filter query](https://discuss.elastic.co/t/multiple-events-all-end-up-with-the-same-result-from-an-http-filter-query/364071)

<div class="topic-metadata">

**Author:** [@Maeris](https://discuss.elastic.co/u/Maeris)\
**Replies:** 9\
**Last updated:** [August 1, 2024, 1:08pm UTC](https://discuss.elastic.co/t/multiple-events-all-end-up-with-the-same-result-from-an-http-filter-query/364071 "2024-08-01T13:08:16Z")

</div>

Hi, I'm having trouble with checking for a new IP for a user login with an HTTP filter query against my OpenSearch node. My filter code looks like: if \[event\_type\] == "user\_logged\_in" { http { url =\> "https:…

---

## [Unable to retrieve data from Oracle sample table using Logstash](https://discuss.elastic.co/t/unable-to-retrieve-data-from-oracle-sample-table-using-logstash/363811)

<div class="topic-metadata">

**Author:** [@sundarcdm1](https://discuss.elastic.co/u/sundarcdm1)\
**Replies:** 1\
**Last updated:** [August 1, 2024, 7:34am UTC](https://discuss.elastic.co/t/unable-to-retrieve-data-from-oracle-sample-table-using-logstash/363811 "2024-08-01T07:34:42Z")

</div>

Hi All, I am very new to Elastic . i was following a blog and video which describes step by step of how to configure create a simple db table and to retrieve values from table using logstash and to display in kibana por…

---

## [Not able to push the data to nested directories in Google Cloud Storage](https://discuss.elastic.co/t/not-able-to-push-the-data-to-nested-directories-in-google-cloud-storage/364189)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 0\
**Last updated:** [August 1, 2024, 7:25am UTC](https://discuss.elastic.co/t/not-able-to-push-the-data-to-nested-directories-in-google-cloud-storage/364189 "2024-08-01T07:25:48Z")

</div>

Hi Team, We are trying to push the data to GCS from Logstash. Logstash is specifying it is pushing, but the data is not there in the GCS bucket. When we had a close look at it, we understood that there is no option in …

---

## [How to reload certs periodically for input with TLS](https://discuss.elastic.co/t/how-to-reload-certs-periodically-for-input-with-tls/364167)

<div class="topic-metadata">

**Author:** [@pewpew](https://discuss.elastic.co/u/pewpew)\
**Replies:** 4\
**Last updated:** [July 31, 2024, 10:46pm UTC](https://discuss.elastic.co/t/how-to-reload-certs-periodically-for-input-with-tls/364167 "2024-07-31T22:46:04Z")

</div>

I have a pipeline which is configured to receive input as below: input { tcp { port =\> 12345 codec =\> json\_lines ssl\_enabled =\> true ssl\_client\_authentication =\> "required" ssl\_certificate =\> "/etc…

---

## [Parsing Windows Event Logs in syslog format](https://discuss.elastic.co/t/parsing-windows-event-logs-in-syslog-format/364115)

<div class="topic-metadata">

**Author:** [@miko](https://discuss.elastic.co/u/miko)\
**Replies:** 1\
**Last updated:** [July 31, 2024, 12:17pm UTC](https://discuss.elastic.co/t/parsing-windows-event-logs-in-syslog-format/364115 "2024-07-31T12:17:43Z")

</div>

Hello, I'm looking for a way to parse Windows logs that are send via SYSLOG format. I don't want to change the format to an other format (like json) but when my logs are received in Elastic, the timestamp and sysloghost…

---

## [How to find the Reason and Event of a warning](https://discuss.elastic.co/t/how-to-find-the-reason-and-event-of-a-warning/364055)

<div class="topic-metadata">

**Author:** [@t.h](https://discuss.elastic.co/u/t.h)\
**Replies:** 3\
**Last updated:** [July 31, 2024, 7:14am UTC](https://discuss.elastic.co/t/how-to-find-the-reason-and-event-of-a-warning/364055 "2024-07-31T07:14:22Z")

</div>

Hello, I got often this logstash warning. \[2024-07-30T13:39:05,486\]\[WARN \]\[logstash.filters.throttle\]\[main\]\[34074a72c3b9ba7bd86762d4ae78ed3b6314e6bcc23a9a4cf6c5707484cc7c58\] filters/LogStash::Filters::Throttle: timeslo…

---

## [Getting error while connecting logstash to elastic](https://discuss.elastic.co/t/getting-error-while-connecting-logstash-to-elastic/363830)

<div class="topic-metadata">

**Author:** [@Amol\_Nagotkar](https://discuss.elastic.co/u/Amol_Nagotkar)\
**Replies:** 17\
**Last updated:** [July 31, 2024, 4:01am UTC](https://discuss.elastic.co/t/getting-error-while-connecting-logstash-to-elastic/363830 "2024-07-31T04:01:41Z")

</div>

Hi all, elastic -\> sudo docker run -d --name es01 --net elastic -p 9200:9200 -e "discovery.type=single-node" -it -m 2GB docker.elastic.co/elasticsearch/elasticsearch:8.14.3 kibana-\> sudo docker run -d --name kib01 --net…

---

## [Customize \`value\_serializerer \` for the](https://discuss.elastic.co/t/customize-value-serializerer-for-the/364095)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 3\
**Last updated:** [July 31, 2024, 12:55am UTC](https://discuss.elastic.co/t/customize-value-serializerer-for-the/364095 "2024-07-31T00:55:36Z")

</div>

Hi all, I am currently trying to leverage the Kafka output plugin and one of the options it exposes is the value\_serializerer field Sadly, the docs do not specify how to customize this value with a custom JAR (ie: com.…

---

## [Logstash--Using ruby to convert json to fields. Data going to elastic as text. How to set to long?](https://discuss.elastic.co/t/logstash-using-ruby-to-convert-json-to-fields-data-going-to-elastic-as-text-how-to-set-to-long/364075)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 1\
**Last updated:** [July 30, 2024, 4:46pm UTC](https://discuss.elastic.co/t/logstash-using-ruby-to-convert-json-to-fields-data-going-to-elastic-as-text-how-to-set-to-long/364075 "2024-07-30T16:46:47Z")

</div>

Logstash--Using ruby to convert JSON to fields. Data going to elastic as text. Pls let me know how to set to long type? Below is my json log string: { "traceId": "o0uyveRU/8BkjL+lbpDlnQ==", "spanId": "73rmqIRmo34=", …

---

## [There are about 800000 log files in my environment, and now logstash is stuck after starting. Is there any solution? You can collect the latest files](https://discuss.elastic.co/t/there-are-about-800000-log-files-in-my-environment-and-now-logstash-is-stuck-after-starting-is-there-any-solution-you-can-collect-the-latest-files/363963)

<div class="topic-metadata">

**Author:** [@Alexis-cmyk-a11y](https://discuss.elastic.co/u/Alexis-cmyk-a11y)\
**Replies:** 0\
**Last updated:** [July 29, 2024, 10:08am UTC](https://discuss.elastic.co/t/there-are-about-800000-log-files-in-my-environment-and-now-logstash-is-stuck-after-starting-is-there-any-solution-you-can-collect-the-latest-files/363963 "2024-07-29T10:08:27Z")

</div>

There are about 800000 log files in my environment, and now logstash is stuck after starting. Is there any solution? You can collect the latest files

---

## [How to send wazuh logs to elastic trough logstash](https://discuss.elastic.co/t/how-to-send-wazuh-logs-to-elastic-trough-logstash/363750)

<div class="topic-metadata">

**Author:** [@Felipe\_Medina](https://discuss.elastic.co/u/Felipe_Medina)\
**Replies:** 2\
**Last updated:** [July 28, 2024, 11:17pm UTC](https://discuss.elastic.co/t/how-to-send-wazuh-logs-to-elastic-trough-logstash/363750 "2024-07-28T23:17:40Z")

</div>

Hi I want to sent wazug logs to elastic I found this documentation: But, when I execute the following command to verify my logstash configuration, I obtain errors: Can someone help me? Thank you

---

## [Logstash--Ruby exception occurred: no implicit conversion of nil into String](https://discuss.elastic.co/t/logstash-ruby-exception-occurred-no-implicit-conversion-of-nil-into-string/363889)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 4\
**Last updated:** [July 28, 2024, 12:47pm UTC](https://discuss.elastic.co/t/logstash-ruby-exception-occurred-no-implicit-conversion-of-nil-into-string/363889 "2024-07-28T12:47:06Z")

</div>

Hello, Below is my json log string: { "traceId": "o0uyveRU/8BkjL+lbpDlnQ==", "spanId": "73rmqIRmo34=", "operationName": "ProcessWorkItem", "startTime": "2024-07-22T06:07:12.650881409Z", "duration": "0.256620153s",…

---

## [ElasticSearch query not working](https://discuss.elastic.co/t/elasticsearch-query-not-working/363913)

<div class="topic-metadata">

**Author:** [@Liam\_Young](https://discuss.elastic.co/u/Liam_Young)\
**Replies:** 0\
**Last updated:** [July 27, 2024, 10:00pm UTC](https://discuss.elastic.co/t/elasticsearch-query-not-working/363913 "2024-07-27T22:00:51Z")

</div>

Hi, I am trying to use logstash to make a 1 minute aggregation, when I run the query I've made in postman, I get expected result: { "took": 14, "timed\_out": false, "\_shards": { "total": 1, "s…

---

## [Logstash holds/locks onto files during files rotation](https://discuss.elastic.co/t/logstash-holds-locks-onto-files-during-files-rotation/363723)

<div class="topic-metadata">

**Author:** [@ELKuser24](https://discuss.elastic.co/u/ELKuser24)\
**Replies:** 4\
**Last updated:** [July 27, 2024, 9:53am UTC](https://discuss.elastic.co/t/logstash-holds-locks-onto-files-during-files-rotation/363723 "2024-07-27T09:53:15Z")

</div>

I'm running Logstash 7.17.0 on my Windows server to ship data into my Elasticsearch 8.11.0 instance, running on a Linux server. The Logstash instance is set to ingest log files from a folder, which is actively being writ…

---

## [Logstash plugin error with Tibero DB](https://discuss.elastic.co/t/logstash-plugin-error-with-tibero-db/363832)

<div class="topic-metadata">

**Author:** [@jimmy\_park](https://discuss.elastic.co/u/jimmy_park)\
**Replies:** 2\
**Last updated:** [July 26, 2024, 12:21pm UTC](https://discuss.elastic.co/t/logstash-plugin-error-with-tibero-db/363832 "2024-07-26T12:21:53Z")

</div>

I have a problem about using Logstash with Tibero DB I want to extract data using Logstash at Tibero DB But the plugin error is occured My test.conf is: input { jdbc { jdbc\_driver\_library =\> "/home/elastic/tibero6…

---

## [Logstash Fail to Index Events due to field type](https://discuss.elastic.co/t/logstash-fail-to-index-events-due-to-field-type/363799)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [July 25, 2024, 4:33pm UTC](https://discuss.elastic.co/t/logstash-fail-to-index-events-due-to-field-type/363799 "2024-07-25T16:33:42Z")

</div>

Hello, I have events not indexing into elastic when passing through logstash. The reason is because sometimes a field like "remoteAddress" (of type ip) contains no values. \]\>worker18","logEvent":{"message":"Could not i…

---

## [Create field with condition while looping through an array in ruby](https://discuss.elastic.co/t/create-field-with-condition-while-looping-through-an-array-in-ruby/363444)

<div class="topic-metadata">

**Author:** [@Armalyca](https://discuss.elastic.co/u/Armalyca)\
**Replies:** 4\
**Last updated:** [July 25, 2024, 1:59pm UTC](https://discuss.elastic.co/t/create-field-with-condition-while-looping-through-an-array-in-ruby/363444 "2024-07-25T13:59:59Z")

</div>

Hello, I use logstash 7.17. I want to create a field while looping through an array in ruby from my data. Here is a snippet of my code which doesn't work : items\_contact = event.get("\[contactMedium\]") if items\_con…

---

## [Logstash as service not reading log files](https://discuss.elastic.co/t/logstash-as-service-not-reading-log-files/363774)

<div class="topic-metadata">

**Author:** [@Glen\_Elkins](https://discuss.elastic.co/u/Glen_Elkins)\
**Replies:** 2\
**Last updated:** [July 25, 2024, 11:21am UTC](https://discuss.elastic.co/t/logstash-as-service-not-reading-log-files/363774 "2024-07-25T11:21:13Z")

</div>

I am running logstash as a service by modifying /etc/systemd/system/logstash.service with: ExecStart=/usr/share/logstash/bin/logstash -f /usr/share/logstash/config/logstash.conf --config.reload.automatic Nothing is bei…

---

## [Logstash not able to get nested json in desired output using ruby](https://discuss.elastic.co/t/logstash-not-able-to-get-nested-json-in-desired-output-using-ruby/363751)

<div class="topic-metadata">

**Author:** [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Replies:** 3\
**Last updated:** [July 25, 2024, 10:55am UTC](https://discuss.elastic.co/t/logstash-not-able-to-get-nested-json-in-desired-output-using-ruby/363751 "2024-07-25T10:55:25Z")

</div>

Below is my sample output log { "traceId": "o0uyveRU/8BkjL+lbpDlnQ==", "spanId": "73rmqIRmo34=", "tags": \[ { "key": "otel.library.name", "vStr": "com.mdi.core.workmgmt.TypedC…

---

## [Logstash and fingerprint](https://discuss.elastic.co/t/logstash-and-fingerprint/363683)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 2\
**Last updated:** [July 24, 2024, 12:51pm UTC](https://discuss.elastic.co/t/logstash-and-fingerprint/363683 "2024-07-24T12:51:27Z")

</div>

Hi there! I would like to use the fingerprint plugin to manage the authenticity of a document. When I try to use the the fingerprint on the field agent, it works well : fingerprint { source =\> \["agent"\] concatenat…

---

## [Send fortiweb syslog to elasticsearch](https://discuss.elastic.co/t/send-fortiweb-syslog-to-elasticsearch/363605)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 3\
**Last updated:** [July 23, 2024, 12:55pm UTC](https://discuss.elastic.co/t/send-fortiweb-syslog-to-elasticsearch/363605 "2024-07-23T12:55:25Z")

</div>

hi all, we have a fortieweb 2000 s device and we want to send its log to elaticearch. in the first step, we wrote a logstash config file which is listening on udp with type "json", meanwhile the fortiweb log type is c…

---

## [Logstash (TypeError) no implicit conversion of Hash into String](https://discuss.elastic.co/t/logstash-typeerror-no-implicit-conversion-of-hash-into-string/363616)

<div class="topic-metadata">

**Author:** [@Gimi\_Sedi](https://discuss.elastic.co/u/Gimi_Sedi)\
**Replies:** 0\
**Last updated:** [July 23, 2024, 8:58am UTC](https://discuss.elastic.co/t/logstash-typeerror-no-implicit-conversion-of-hash-into-string/363616 "2024-07-23T08:58:47Z")

</div>

For a couple of days, logstash stops ingesting logs (while the service is up and running). The error thrown on the logs is shown below: 2024-07-22 12:10:36,103 pool-84-thread-1 ERROR An exception occurred processing App…

---

## [I am getting Malformed Escape Escape at Index error in logstash logs for http url. How to resolve it?](https://discuss.elastic.co/t/i-am-getting-malformed-escape-escape-at-index-error-in-logstash-logs-for-http-url-how-to-resolve-it/363440)

<div class="topic-metadata">

**Author:** [@Shalu\_Bisht](https://discuss.elastic.co/u/Shalu_Bisht)\
**Replies:** 4\
**Last updated:** [July 23, 2024, 2:44am UTC](https://discuss.elastic.co/t/i-am-getting-malformed-escape-escape-at-index-error-in-logstash-logs-for-http-url-how-to-resolve-it/363440 "2024-07-23T02:44:53Z")

</div>

I am getting Malformed Escape Escape at Index error in logstash logs for http url. How to resolve it ?

---

## [Logshash filter plugin ruby code to remove duplicates from a json array of json address objects](https://discuss.elastic.co/t/logshash-filter-plugin-ruby-code-to-remove-duplicates-from-a-json-array-of-json-address-objects/363501)

<div class="topic-metadata">

**Author:** [@vvavad](https://discuss.elastic.co/u/vvavad)\
**Replies:** 2\
**Last updated:** [July 22, 2024, 12:19pm UTC](https://discuss.elastic.co/t/logshash-filter-plugin-ruby-code-to-remove-duplicates-from-a-json-array-of-json-address-objects/363501 "2024-07-22T12:19:33Z")

</div>

I am writing a logstash job/pipeline which takes input from Elasticsearch index(index 1), in filter plugin reads another elasticSearch index(index2). Both of these idices have json data with array of address objects. I w…

---

## [Calculating sum using the aggregate filter](https://discuss.elastic.co/t/calculating-sum-using-the-aggregate-filter/363519)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 0\
**Last updated:** [July 22, 2024, 5:40am UTC](https://discuss.elastic.co/t/calculating-sum-using-the-aggregate-filter/363519 "2024-07-22T05:40:52Z")

</div>

Hi Team, We have sample data like this log 1 { "commonid": "test\_567", "Key": "test1234", "amount": 0, "information2": "test\_567" } log 2 { "commonid": "test\_567", "reconKey…

---

## [Logstash geoip failure | IP was not found in the database](https://discuss.elastic.co/t/logstash-geoip-failure-ip-was-not-found-in-the-database/363231)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 7\
**Last updated:** [July 21, 2024, 2:18pm UTC](https://discuss.elastic.co/t/logstash-geoip-failure-ip-was-not-found-in-the-database/363231 "2024-07-21T14:18:52Z")

</div>

Hi Community, Below is the logstash config . My objective is to get city,country,state based on geolocation. In input file i am putting geolocation. input { beats { port=\> 5044 #codec =\> json } } filter { geoip { …

---

## [Bletcherous Logstash Elasticsearch filter ConfigurationError](https://discuss.elastic.co/t/bletcherous-logstash-elasticsearch-filter-configurationerror/363443)

<div class="topic-metadata">

**Author:** [@Gary\_Brooks](https://discuss.elastic.co/u/Gary_Brooks)\
**Replies:** 3\
**Last updated:** [July 21, 2024, 11:23am UTC](https://discuss.elastic.co/t/bletcherous-logstash-elasticsearch-filter-configurationerror/363443 "2024-07-21T11:23:18Z")

</div>

I'm receiving the "Unable to configure plugins: (ConfigurationError) Something is wrong with your configuration." error message from a Logstash Elasticsearch filter. The filter is: filter { ruby { # code to defi…

---

## [LogStash 403 error to Elastic](https://discuss.elastic.co/t/logstash-403-error-to-elastic/362897)

<div class="topic-metadata">

**Author:** [@NikoCosmico01](https://discuss.elastic.co/u/NikoCosmico01)\
**Replies:** 9\
**Last updated:** [July 21, 2024, 7:13am UTC](https://discuss.elastic.co/t/logstash-403-error-to-elastic/362897 "2024-07-21T07:13:34Z")

</div>

I am trying to ingest data from wazuh to elastic using this .config file inside logstash input { opensearch { hosts =\> \["\[IP:PORT\]"\] user =\> "\[USER\]" password =\> "\[PW\]" index =\> "wazuh-alerts-\*" s…

---

## [Ingest json file containing several json objects (one per line) sent from java (over http) to logstash to elasticsearch](https://discuss.elastic.co/t/ingest-json-file-containing-several-json-objects-one-per-line-sent-from-java-over-http-to-logstash-to-elasticsearch/363478)

<div class="topic-metadata">

**Author:** [@taykara](https://discuss.elastic.co/u/taykara)\
**Replies:** 11\
**Last updated:** [July 20, 2024, 6:35pm UTC](https://discuss.elastic.co/t/ingest-json-file-containing-several-json-objects-one-per-line-sent-from-java-over-http-to-logstash-to-elasticsearch/363478 "2024-07-20T18:35:42Z")

</div>

Hi there, I'm very very new to ELK and I am facing an issue. I try to send a json file containing several json object (one per line) from a Java application to logstash. Here is the file I send over http post request …

---

## [Calculating the Sum of a field by grouping](https://discuss.elastic.co/t/calculating-the-sum-of-a-field-by-grouping/363411)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 0\
**Last updated:** [July 19, 2024, 10:06am UTC](https://discuss.elastic.co/t/calculating-the-sum-of-a-field-by-grouping/363411 "2024-07-19T10:06:15Z")

</div>

Hi Team, I am trying to merge two documents based on a common key in logstash and i am able to achieve this by using a elastic input filter and elastic filter in filter section for the lookup data. Now i wanted to calcu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=23)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=25)
