# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=244

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 245

---

## [Logstash cannot run one of the pipelines](https://discuss.elastic.co/t/logstash-cannot-run-one-of-the-pipelines/268369)

<div class="topic-metadata">

**Author:** [@Ishaan](https://discuss.elastic.co/u/Ishaan)\
**Replies:** 0\
**Last updated:** [March 25, 2021, 3:04pm UTC](https://discuss.elastic.co/t/logstash-cannot-run-one-of-the-pipelines/268369 "2021-03-25T15:04:01Z")

</div>

Hello, One of the logstash pipelines is not working and I can run the pipeline in the debug mode because it is centrally managed in kibana UI. How can debug the config? How can I look for errors?

---

## [Logstash filter "if" condition to check if field exist or not](https://discuss.elastic.co/t/logstash-filter-if-condition-to-check-if-field-exist-or-not/268336)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 1\
**Last updated:** [March 25, 2021, 2:20pm UTC](https://discuss.elastic.co/t/logstash-filter-if-condition-to-check-if-field-exist-or-not/268336 "2021-03-25T14:20:14Z")

</div>

Is there any way in Logstash to check if a certain field exists or not? My use-case: I want to add a field "status: missing" when the field "httpStatus" doesn't come in the log document.

---

## [Filter for each output in multiple outputs](https://discuss.elastic.co/t/filter-for-each-output-in-multiple-outputs/268358)

<div class="topic-metadata">

**Author:** [@Charith\_sattiva](https://discuss.elastic.co/u/Charith_sattiva)\
**Replies:** 0\
**Last updated:** [March 25, 2021, 2:04pm UTC](https://discuss.elastic.co/t/filter-for-each-output-in-multiple-outputs/268358 "2021-03-25T14:04:12Z")

</div>

Hello, I would like to send logs to multiple hosts in the output plugin of logstash. Is there a way I can filter logs for each output separately using the filter plugin? Thanks in advance

---

## [Logstash input file plugin feature proposal - possibility to disable file truncation detection](https://discuss.elastic.co/t/logstash-input-file-plugin-feature-proposal-possibility-to-disable-file-truncation-detection/268339)

<div class="topic-metadata">

**Author:** [@maciejfranek](https://discuss.elastic.co/u/maciejfranek)\
**Replies:** 0\
**Last updated:** [March 25, 2021, 12:34pm UTC](https://discuss.elastic.co/t/logstash-input-file-plugin-feature-proposal-possibility-to-disable-file-truncation-detection/268339 "2021-03-25T12:34:20Z")

</div>

Hello everyone, I've been using logstash with azure files, but I reached nasty problem with it - logstash produced a lot of duplicated log events in the output due to file truncation detection. I've already created iss…

---

## [How to insert date type column of a csv file in the format "dd:MM:YYYY HH:mm:ss" into elasticsearch through logstash config](https://discuss.elastic.co/t/how-to-insert-date-type-column-of-a-csv-file-in-the-format-ddyyyy-hhss-into-elasticsearch-through-logstash-config/268189)

<div class="topic-metadata">

**Author:** [@DEEPTHI\_SONA\_G](https://discuss.elastic.co/u/DEEPTHI_SONA_G)\
**Replies:** 4\
**Last updated:** [March 25, 2021, 11:30am UTC](https://discuss.elastic.co/t/how-to-insert-date-type-column-of-a-csv-file-in-the-format-ddyyyy-hhss-into-elasticsearch-through-logstash-config/268189 "2021-03-25T11:30:11Z")

</div>

I'm trying to insert data from a csv file into elasticsearch using logstash. I have tried adding date { match =\> \["SIGHTING\_TIME", "dd-MM-YYYY HH:mm:ss"\] target =\>"SIGHTING\_TIME" } in …

---

## [ECS fields not applied from index template](https://discuss.elastic.co/t/ecs-fields-not-applied-from-index-template/267056)

<div class="topic-metadata">

**Author:** [@jfs1](https://discuss.elastic.co/u/jfs1)\
**Replies:** 6\
**Last updated:** [March 25, 2021, 10:01am UTC](https://discuss.elastic.co/t/ecs-fields-not-applied-from-index-template/267056 "2021-03-25T10:01:02Z")

</div>

I'm trying to reformat my index template to migrate to ECS. I think I'm missing something because the field format for the multi-level keys is not taken into account. My index template looks like this : { "te…

---

## [Combine windows registry and log file](https://discuss.elastic.co/t/combine-windows-registry-and-log-file/268236)

<div class="topic-metadata">

**Author:** [@ahmetnash](https://discuss.elastic.co/u/ahmetnash)\
**Replies:** 1\
**Last updated:** [March 25, 2021, 2:46am UTC](https://discuss.elastic.co/t/combine-windows-registry-and-log-file/268236 "2021-03-25T02:46:39Z")

</div>

In my windows computer, i am using filebeat to read the content of the application server logs. On the same machine, In the registry field i have also store the version of the application. I want to combine these two da…

---

## [Logstash MongoDB Output Plugin - command insert requires authentication](https://discuss.elastic.co/t/logstash-mongodb-output-plugin-command-insert-requires-authentication/268265)

<div class="topic-metadata">

**Author:** [@christiancj](https://discuss.elastic.co/u/christiancj)\
**Replies:** 1\
**Last updated:** [March 24, 2021, 9:29pm UTC](https://discuss.elastic.co/t/logstash-mongodb-output-plugin-command-insert-requires-authentication/268265 "2021-03-24T21:29:32Z")

</div>

I'm using logstash 7.10.2 with MongoDB logstash-output plugin (tested 2 diff versions), I'm trying to write documents from elastic to mongodb, however I'm getting the following errors for each version, plugin version l…

---

## [Ingesting large number of files in a directory using logstash](https://discuss.elastic.co/t/ingesting-large-number-of-files-in-a-directory-using-logstash/268168)

<div class="topic-metadata">

**Author:** [@Razeen](https://discuss.elastic.co/u/Razeen)\
**Replies:** 3\
**Last updated:** [March 24, 2021, 8:24pm UTC](https://discuss.elastic.co/t/ingesting-large-number-of-files-in-a-directory-using-logstash/268168 "2021-03-24T20:24:31Z")

</div>

Hi, I have a logstash configuration to ingest large number of json files from a directory. The ingestion works perfectly fine, But for a particular number of json files. For example i pointed the input for a folder wi…

---

## [Splunk data ingestion into Elasticsearch via Logstash behind NLB](https://discuss.elastic.co/t/splunk-data-ingestion-into-elasticsearch-via-logstash-behind-nlb/267654)

<div class="topic-metadata">

**Author:** [@vijay.gvg](https://discuss.elastic.co/u/vijay.gvg)\
**Replies:** 3\
**Last updated:** [March 24, 2021, 6:41pm UTC](https://discuss.elastic.co/t/splunk-data-ingestion-into-elasticsearch-via-logstash-behind-nlb/267654 "2021-03-24T18:41:24Z")

</div>

Hi, We wanted to integrate logs from Splunk system into Elasticsearch via Logstash. Following are the steps we used to do the same: Create a Network Load Balancer (NLB) URL with Logstash as backend Configure Splunk for…

---

## [Logstash shipping issue](https://discuss.elastic.co/t/logstash-shipping-issue/268227)

<div class="topic-metadata">

**Author:** [@jcor](https://discuss.elastic.co/u/jcor)\
**Replies:** 1\
**Last updated:** [March 24, 2021, 4:18pm UTC](https://discuss.elastic.co/t/logstash-shipping-issue/268227 "2021-03-24T16:18:53Z")

</div>

Hey folks, I'm having a weird issue that I cant seem to solve. I have multiple winlogbeats shipping event logs to a logstash server which then forwards it to an elastic ingestion node which servers the cluster. Recentl…

---

## [Data source Not Sending Data](https://discuss.elastic.co/t/data-source-not-sending-data/267787)

<div class="topic-metadata">

**Author:** [@Bigranawab](https://discuss.elastic.co/u/Bigranawab)\
**Replies:** 3\
**Last updated:** [March 24, 2021, 11:41am UTC](https://discuss.elastic.co/t/data-source-not-sending-data/267787 "2021-03-24T11:41:31Z")

</div>

Hi, I am working on ELK stack and was wondering if a data source has stopped sending data to ELK due to any reason, how can we identify or alert team that this particular network device or server has stopped sending eve…

---

## [Extract day, month and year from a date field. Changing Timezone](https://discuss.elastic.co/t/extract-day-month-and-year-from-a-date-field-changing-timezone/267646)

<div class="topic-metadata">

**Author:** [@Ernesto\_Guerra](https://discuss.elastic.co/u/Ernesto_Guerra)\
**Replies:** 4\
**Last updated:** [March 24, 2021, 11:30am UTC](https://discuss.elastic.co/t/extract-day-month-and-year-from-a-date-field-changing-timezone/267646 "2021-03-24T11:30:50Z")

</div>

Hi, I would like to add some fields extracting data from "\[layers\]\[frame\]\[frame\_frame\_time\]" field. My code is: date { match =\> \[ "\[layers\]\[frame\]\[frame\_frame\_time\]","ISO8601" \] target =\> "\[layers\]\[frame\]\[fr…

---

## [Logstash 1.5.4 Output to Elasticsearch with https](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065)

<div class="topic-metadata">

**Author:** [@Dan4](https://discuss.elastic.co/u/Dan4)\
**Replies:** 12\
**Last updated:** [March 24, 2021, 9:02am UTC](https://discuss.elastic.co/t/logstash-1-5-4-output-to-elasticsearch-with-https/268065 "2021-03-24T09:02:22Z")

</div>

Hello together, I am new to the elastic stack and have no further experience than just google a solution. In my environment I have to use Logstash on a remote server. I can not change it. I have no control over the vers…

---

## [Datetime parsing errors when including locale de-AT](https://discuss.elastic.co/t/datetime-parsing-errors-when-including-locale-de-at/268091)

<div class="topic-metadata">

**Author:** [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 12:21pm UTC](https://discuss.elastic.co/t/datetime-parsing-errors-when-including-locale-de-at/268091 "2021-03-23T12:21:13Z")

</div>

Hi, I am at a loss, we have to deal with german encodings of month such as Dezember instead of December, or März instead of March, which also impacts the MMM notation instead of Mar it is Mär. This is an example message…

---

## [Create debian package from source](https://discuss.elastic.co/t/create-debian-package-from-source/268097)

<div class="topic-metadata">

**Author:** [@maxlavr](https://discuss.elastic.co/u/maxlavr)\
**Replies:** 2\
**Last updated:** [March 24, 2021, 5:04am UTC](https://discuss.elastic.co/t/create-debian-package-from-source/268097 "2021-03-24T05:04:28Z")

</div>

Hello everyone. My name is Max and my profession is DevOps. I'm working in company which use Elastic Stack. New security standards for our product require building your software from source code and creating deb packages…

---

## [Issue with date field in CSV plugin](https://discuss.elastic.co/t/issue-with-date-field-in-csv-plugin/268047)

<div class="topic-metadata">

**Author:** [@Gauti](https://discuss.elastic.co/u/Gauti)\
**Replies:** 7\
**Last updated:** [March 24, 2021, 4:26am UTC](https://discuss.elastic.co/t/issue-with-date-field-in-csv-plugin/268047 "2021-03-24T04:26:41Z")

</div>

Hi All, I'm trying to ingest data into elasticsearch using csv plugin, data is going smooth for one or two days then all of a sudden there is a wired entry which will get updated with some random date and year. I'm …

---

## [Filter for When Log changes Slightly](https://discuss.elastic.co/t/filter-for-when-log-changes-slightly/268152)

<div class="topic-metadata">

**Author:** [@rmoss25](https://discuss.elastic.co/u/rmoss25)\
**Replies:** 1\
**Last updated:** [March 24, 2021, 2:40am UTC](https://discuss.elastic.co/t/filter-for-when-log-changes-slightly/268152 "2021-03-24T02:40:27Z")

</div>

HI, How do you create a grok pattern that can handle the log changing every now and then so I have a filter written that works but every so often the last field of an almost identical log is empty and the existing filt…

---

## [Documentation Suggestion | Secure communication with Logstash](https://discuss.elastic.co/t/documentation-suggestion-secure-communication-with-logstash/268146)

<div class="topic-metadata">

**Author:** [@lorenzop](https://discuss.elastic.co/u/lorenzop)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 10:11pm UTC](https://discuss.elastic.co/t/documentation-suggestion-secure-communication-with-logstash/268146 "2021-03-23T22:11:39Z")

</div>

In this guide, specifically the section for configuring Logstash to receive secure communications using an SSL certificate, we experienced difficulty getting this setup and were actually only able to get the server to …

---

## [Logstash Beats Input remote: undefined on SSL Errors](https://discuss.elastic.co/t/logstash-beats-input-remote-undefined-on-ssl-errors/268144)

<div class="topic-metadata">

**Author:** [@lorenzop](https://discuss.elastic.co/u/lorenzop)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 10:05pm UTC](https://discuss.elastic.co/t/logstash-beats-input-remote-undefined-on-ssl-errors/268144 "2021-03-23T22:05:50Z")

</div>

Wanted to bring conversation over to the discussion forum and see if anyone here might have experience with solving this problem.

---

## [Pipeline error in logstash on windows 10](https://discuss.elastic.co/t/pipeline-error-in-logstash-on-windows-10/266072)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 1\
**Last updated:** [March 23, 2021, 9:13pm UTC](https://discuss.elastic.co/t/pipeline-error-in-logstash-on-windows-10/266072 "2021-03-23T21:13:20Z")

</div>

Hi, I setup logstash 7.11.1 pipeline on windows 10 but it is showing No configuration found in the configured sources I am running logstash by logstash --debug command with administrator in cmd. Below is my complete l…

---

## [Logstash an suricata](https://discuss.elastic.co/t/logstash-an-suricata/268133)

<div class="topic-metadata">

**Author:** [@lumi](https://discuss.elastic.co/u/lumi)\
**Replies:** 2\
**Last updated:** [March 23, 2021, 9:05pm UTC](https://discuss.elastic.co/t/logstash-an-suricata/268133 "2021-03-23T21:05:01Z")

</div>

Hello I am getting Suricata Messages from Qradar which i need so save in a file. The suricata module on filebeat will add it to the elasticsearch. i have the following problem: This is what logstash writes into the f…

---

## [Logstash - do not starts when jdbc filter fails connection](https://discuss.elastic.co/t/logstash-do-not-starts-when-jdbc-filter-fails-connection/267545)

<div class="topic-metadata">

**Author:** [@cesar.hernandez.a3se](https://discuss.elastic.co/u/cesar.hernandez.a3se)\
**Replies:** 6\
**Last updated:** [March 23, 2021, 8:59pm UTC](https://discuss.elastic.co/t/logstash-do-not-starts-when-jdbc-filter-fails-connection/267545 "2021-03-23T20:59:04Z")

</div>

Hi I've created a logstash input filter: filter { jdbc\_static { loaders =\> \[ { id =\> "remote-ipsservers" query =\> "select address, display\_name from host\_list'" …

---

## [Parse a comma separate value that contains a comma in it](https://discuss.elastic.co/t/parse-a-comma-separate-value-that-contains-a-comma-in-it/268026)

<div class="topic-metadata">

**Author:** [@d-ring](https://discuss.elastic.co/u/d-ring)\
**Replies:** 5\
**Last updated:** [March 23, 2021, 4:52pm UTC](https://discuss.elastic.co/t/parse-a-comma-separate-value-that-contains-a-comma-in-it/268026 "2021-03-23T16:52:53Z")

</div>

Evening All, I am trying to parse out a log entry that is comma separated, but if the SOMEUSER field exists will have a comma in it as well that should be ignored. The fields that exist in some fashion are SOMEUSER, SO…

---

## [After switching Elasticsearch Output - Logstash says it cannot reach old Elasticsearch Output Host](https://discuss.elastic.co/t/after-switching-elasticsearch-output-logstash-says-it-cannot-reach-old-elasticsearch-output-host/268116)

<div class="topic-metadata">

**Author:** [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 4:01pm UTC](https://discuss.elastic.co/t/after-switching-elasticsearch-output-logstash-says-it-cannot-reach-old-elasticsearch-output-host/268116 "2021-03-23T16:01:10Z")

</div>

Hello Community, we've recently added a Node to our Cluster - which is supposed to handle the all the Logs which are processed by Logstash. Information: Elasticsearch 7.10 Logstash 7.10 OS: CentOS 7 So i reconfigur…

---

## [Logstash Kusto - No timestamp getting generated automatically as earlier](https://discuss.elastic.co/t/logstash-kusto-no-timestamp-getting-generated-automatically-as-earlier/268084)

<div class="topic-metadata">

**Author:** [@omkarg81](https://discuss.elastic.co/u/omkarg81)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 11:16am UTC](https://discuss.elastic.co/t/logstash-kusto-no-timestamp-getting-generated-automatically-as-earlier/268084 "2021-03-23T11:16:28Z")

</div>

I have a Winlogbeat --\> Logstash --\> Azure Data Explorer logging system, but somehow, since last few days, the debug logs that I have activated on logstash is showing that the tmp file written by ADX before the logs are …

---

## [Mongodb - MongoDB Input threw an exception, restarting {:exception=\>#\<BSON::ObjectId::Invalid: '003cd541-2dd3-4a8e-89b0-595c74a9e4f9' is an invalid ObjectID](https://discuss.elastic.co/t/mongodb-mongodb-input-threw-an-exception-restarting-exception-bson-003cd541-2dd3-4a8e-89b0-595c74a9e4f9-is-an-invalid-objectid/268045)

<div class="topic-metadata">

**Author:** [@deepakELKB](https://discuss.elastic.co/u/deepakELKB)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 6:11am UTC](https://discuss.elastic.co/t/mongodb-mongodb-input-threw-an-exception-restarting-exception-bson-003cd541-2dd3-4a8e-89b0-595c74a9e4f9-is-an-invalid-objectid/268045 "2021-03-23T06:11:21Z")

</div>

Hi I am getting this error during creation of index from mongodb input plugin. I have also integrate filter and remove \_id filed but still getting same error. input { mongodb{ uri =\> "mongodb+srv://localhost:2…

---

## [Logstash does not work under win10](https://discuss.elastic.co/t/logstash-does-not-work-under-win10/268034)

<div class="topic-metadata">

**Author:** [@George\_Lee](https://discuss.elastic.co/u/George_Lee)\
**Replies:** 2\
**Last updated:** [March 23, 2021, 6:00am UTC](https://discuss.elastic.co/t/logstash-does-not-work-under-win10/268034 "2021-03-23T06:00:01Z")

</div>

Can someone help me solve it, thank you very much

---

## [Logstash and Lumberjack giving Error](https://discuss.elastic.co/t/logstash-and-lumberjack-giving-error/268044)

<div class="topic-metadata">

**Author:** [@jhanvi](https://discuss.elastic.co/u/jhanvi)\
**Replies:** 0\
**Last updated:** [March 23, 2021, 5:59am UTC](https://discuss.elastic.co/t/logstash-and-lumberjack-giving-error/268044 "2021-03-23T05:59:52Z")

</div>

Hello, I am facing this error quite often and it happens randomly too. My logs seem to be flowing fine and then suddenly it stops and I get the below error. \[ERROR\]\[logstash.outputs.lumberjack\]\[main\] All hosts unavaila…

---

## [Parsing json object](https://discuss.elastic.co/t/parsing-json-object/267446)

<div class="topic-metadata">

**Author:** [@hackercat](https://discuss.elastic.co/u/hackercat)\
**Replies:** 1\
**Last updated:** [March 17, 2021, 4:45pm UTC](https://discuss.elastic.co/t/parsing-json-object/267446 "2021-03-17T16:45:33Z")

</div>

Hi there, If someone can help me with this I would be very appreciated. It's so complicated for me. So I have an event like this { "time":"2021-03-12T00:40:57.016Z", "severity":"INFO", "duration\_s":0.02124, …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=243)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=245)
