# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=250

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 251

---

## [Problems changing @timestamp value](https://discuss.elastic.co/t/problems-changing-timestamp-value/266009)

<div class="topic-metadata">

**Author:** [@tstrul](https://discuss.elastic.co/u/tstrul)\
**Replies:** 2\
**Last updated:** [March 4, 2021, 4:48pm UTC](https://discuss.elastic.co/t/problems-changing-timestamp-value/266009 "2021-03-04T16:48:03Z")

</div>

Hi all, Im working on moving cloudfront real-time logs from kinessis to our ELK stack using functionbeat. I'm trying to convert logs timestamp (unix format) to regular date and use it in @timestemp field. unfortunatel…

---

## [Dealing with multiple number of values from the same input - Logstash](https://discuss.elastic.co/t/dealing-with-multiple-number-of-values-from-the-same-input-logstash/266101)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 4\
**Last updated:** [March 4, 2021, 4:27pm UTC](https://discuss.elastic.co/t/dealing-with-multiple-number-of-values-from-the-same-input-logstash/266101 "2021-03-04T16:27:41Z")

</div>

I have recently started using Logstash so still new at this. The use-case I am working on is that I want to ship a log file with Logstash that has different lengths of lines in it. The length of line (the number of attri…

---

## [Geoip with GeoIP2-Connection-Type](https://discuss.elastic.co/t/geoip-with-geoip2-connection-type/266089)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 0\
**Last updated:** [March 3, 2021, 10:50am UTC](https://discuss.elastic.co/t/geoip-with-geoip2-connection-type/266089 "2021-03-03T10:50:11Z")

</div>

Hello I tried to use this DB for enrichment but it throws "Unsupported database type GeoIP2-Connection-Type" error Is there any chance this will be supported in the future? logstash config geoip { …

---

## [Logstash json filter fail to send to elasticearch when parse json error](https://discuss.elastic.co/t/logstash-json-filter-fail-to-send-to-elasticearch-when-parse-json-error/266190)

<div class="topic-metadata">

**Author:** [@stwang](https://discuss.elastic.co/u/stwang)\
**Replies:** 0\
**Last updated:** [March 4, 2021, 7:48am UTC](https://discuss.elastic.co/t/logstash-json-filter-fail-to-send-to-elasticearch-when-parse-json-error/266190 "2021-03-04T07:48:47Z")

</div>

Hi there, I have a logstash filter to pass my log, my log contain json and non-json log, I want both send to elastic search no matter json parse success or failed. I found from logstash, for the failed parse log, it sh…

---

## [JDBC Input](https://discuss.elastic.co/t/jdbc-input/266028)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 7:26pm UTC](https://discuss.elastic.co/t/jdbc-input/266028 "2021-03-03T19:26:51Z")

</div>

Investigating data ingest using the JDBC input plugin to pull from a SQL database. Is there a way to configure the query to only pull records based on time? The table I'm pulling from has an updated\_on column. As an e…

---

## [Merge multiple fields in document into json array](https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036)

<div class="topic-metadata">

**Author:** [@mussa572](https://discuss.elastic.co/u/mussa572)\
**Replies:** 2\
**Last updated:** [March 3, 2021, 5:09pm UTC](https://discuss.elastic.co/t/merge-multiple-fields-in-document-into-json-array/266036 "2021-03-03T17:09:56Z")

</div>

Hi, I have following document Ingesting into Elasticsearch using the logstash \_source": { "server\_name": "abc", "server\_ip": "0.0.0.0", "server\_location: "us" "type" : "…

---

## [I see timeout excpetion in logstash](https://discuss.elastic.co/t/i-see-timeout-excpetion-in-logstash/266140)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 0\
**Last updated:** [March 3, 2021, 4:20pm UTC](https://discuss.elastic.co/t/i-see-timeout-excpetion-in-logstash/266140 "2021-03-03T16:20:59Z")

</div>

Below is the error message in logstash-plain.log \[2021-03-03T16:00:46,719\]\[WARN \]\[io.netty.channel.DefaultChannelPipeline\]\[main\]\[ed5928ede48a4919694eb040ed1411b2d0e6482d5881ff856cc046fe3412681f\] An exceptionCaught() eve…

---

## [How to config Logstash receive and pars logs from port and file path at the same time](https://discuss.elastic.co/t/how-to-config-logstash-receive-and-pars-logs-from-port-and-file-path-at-the-same-time/266112)

<div class="topic-metadata">

**Author:** [@asan](https://discuss.elastic.co/u/asan)\
**Replies:** 0\
**Last updated:** [March 3, 2021, 1:00pm UTC](https://discuss.elastic.co/t/how-to-config-logstash-receive-and-pars-logs-from-port-and-file-path-at-the-same-time/266112 "2021-03-03T13:00:47Z")

</div>

Hi I've been configured my Logstash input to read logs for two of my network devices from "/var/log" path file and it was working correctly but when i installed netflow plugin on logstash it started not reading the pat…

---

## [Logstash-\* in Alert/Action section](https://discuss.elastic.co/t/logstash-in-alert-action-section/266070)

<div class="topic-metadata">

**Author:** [@MABN](https://discuss.elastic.co/u/MABN)\
**Replies:** 1\
**Last updated:** [March 3, 2021, 8:37am UTC](https://discuss.elastic.co/t/logstash-in-alert-action-section/266070 "2021-03-03T08:37:37Z")

</div>

Hi I used rsyslog to send log to ELK, like this guide https://www.elastic.co/blog/how-to-centralize-logs-with-rsyslog-logstash-and-elasticsearch-on-ubuntu-14-04 Then I used grok to pars log's messages in logstash.conf …

---

## [Logstash Helm Deployment](https://discuss.elastic.co/t/logstash-helm-deployment/266060)

<div class="topic-metadata">

**Author:** [@Karl\_Ofeiche](https://discuss.elastic.co/u/Karl_Ofeiche)\
**Replies:** 0\
**Last updated:** [March 3, 2021, 7:14am UTC](https://discuss.elastic.co/t/logstash-helm-deployment/266060 "2021-03-03T07:14:59Z")

</div>

Hey everyone. I've been trying to send logs from an untangle firewall device to my ELK SIEM on Kubernetes. To do so I created a pipeline that I deployed as a ConfigMap and from here I'm stuck. Here's a part of the Helm…

---

## [Logstash- Unable to retrieve license information from license server](https://discuss.elastic.co/t/logstash-unable-to-retrieve-license-information-from-license-server/264979)

<div class="topic-metadata">

**Author:** [@anoopkv](https://discuss.elastic.co/u/anoopkv)\
**Replies:** 4\
**Last updated:** [March 3, 2021, 6:29am UTC](https://discuss.elastic.co/t/logstash-unable-to-retrieve-license-information-from-license-server/264979 "2021-03-03T06:29:36Z")

</div>

Trying to setup ELK stack on my on-premise K8S cluster using helm charts. Have enabled x-pack security and both Elasticsearch and kibana are working fine after enabling transport, http security I have used elasticsearch…

---

## [How to use \_sql (SQL queries) to access Elasticsearch indexes in Logstash input plugin](https://discuss.elastic.co/t/how-to-use-sql-sql-queries-to-access-elasticsearch-indexes-in-logstash-input-plugin/265327)

<div class="topic-metadata">

**Author:** [@Amit\_Singh4](https://discuss.elastic.co/u/Amit_Singh4)\
**Replies:** 4\
**Last updated:** [March 3, 2021, 6:08am UTC](https://discuss.elastic.co/t/how-to-use-sql-sql-queries-to-access-elasticsearch-indexes-in-logstash-input-plugin/265327 "2021-03-03T06:08:07Z")

</div>

Hi I want to use \_sql (SQL queries) to access Elasticsearch indexes in Logstash input plugin. Find my logstash config as below: input { http\_poller { urls =\> { test1 =\> { method =\> "POST" user =\> "abc" password =\>…

---

## [Change in logstash configuration](https://discuss.elastic.co/t/change-in-logstash-configuration/266011)

<div class="topic-metadata">

**Author:** [@sandeep3](https://discuss.elastic.co/u/sandeep3)\
**Replies:** 3\
**Last updated:** [March 3, 2021, 12:14am UTC](https://discuss.elastic.co/t/change-in-logstash-configuration/266011 "2021-03-03T00:14:07Z")

</div>

Hi, Here In our ELK. log stash have the sql query. Suppose if i want to add extra column in the sql query. Is it will impact the index like data lost any. Please help me in this context.

---

## [Logstash ('No configuration found in the configured sources')](https://discuss.elastic.co/t/logstash-no-configuration-found-in-the-configured-sources/265765)

<div class="topic-metadata">

**Author:** [@matteo001](https://discuss.elastic.co/u/matteo001)\
**Replies:** 9\
**Last updated:** [March 2, 2021, 5:48pm UTC](https://discuss.elastic.co/t/logstash-no-configuration-found-in-the-configured-sources/265765 "2021-03-02T17:48:26Z")

</div>

Hi everyone, I tried to load the JSON file in elastic search through Logstash in windows10. I show you my "MATTEOLOGSTASHCONF.conf" file: input { file { start\_position =\> "beginning" path =\> "C:/Users/matte/Desktop/…

---

## [Help importing text file split by |](https://discuss.elastic.co/t/help-importing-text-file-split-by/265951)

<div class="topic-metadata">

**Author:** [@randomrobbiebf](https://discuss.elastic.co/u/randomrobbiebf)\
**Replies:** 1\
**Last updated:** [March 2, 2021, 5:45pm UTC](https://discuss.elastic.co/t/help-importing-text-file-split-by/265951 "2021-03-02T17:45:32Z")

</div>

Hey all, I have multiple text files i am trying to import what i currently have imports the text files but ideally i need to split each line. the lines of the text files i am importing look like aXsdA|http://someurl W…

---

## [S3 output configuration failing constantly](https://discuss.elastic.co/t/s3-output-configuration-failing-constantly/265812)

<div class="topic-metadata">

**Author:** [@qubusp](https://discuss.elastic.co/u/qubusp)\
**Replies:** 3\
**Last updated:** [March 2, 2021, 5:19pm UTC](https://discuss.elastic.co/t/s3-output-configuration-failing-constantly/265812 "2021-03-02T17:19:46Z")

</div>

input { java\_generator{ } } filter{ csv{ } } output { s3 { validate\_credentials\_on\_root\_bucket =\> false, endpoint =\> "http://nginx:9000", bucket =\> "rawdata", codec =\> "csv", addi…

---

## [Logstash filebeat json payload problem](https://discuss.elastic.co/t/logstash-filebeat-json-payload-problem/265237)

<div class="topic-metadata">

**Author:** [@MMerel](https://discuss.elastic.co/u/MMerel)\
**Replies:** 2\
**Last updated:** [March 2, 2021, 4:15pm UTC](https://discuss.elastic.co/t/logstash-filebeat-json-payload-problem/265237 "2021-03-02T16:15:21Z")

</div>

Hello everyone, I´m having trouble trying to parse simple json data from logstash to elasticsearch . My config is : filebeat suscribed to some mosquitto topic \> logstash mqqt input \> elasticsearch \> kibana. @timestamp …

---

## [Ignore ssl\_certificate\_validation in Http filter plugin](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379)

<div class="topic-metadata">

**Author:** [@d71247](https://discuss.elastic.co/u/d71247)\
**Replies:** 3\
**Last updated:** [March 2, 2021, 8:53am UTC](https://discuss.elastic.co/t/ignore-ssl-certificate-validation-in-http-filter-plugin/265379 "2021-03-02T08:53:29Z")

</div>

Hi Team, I have installed logstash7.9.2 in the Linux server. I have created a configuration which will connect to the Ansible-tower rest API using http filter plugin. My question is there a way to disable ssl/tls verif…

---

## [Search a string using logstash](https://discuss.elastic.co/t/search-a-string-using-logstash/265607)

<div class="topic-metadata">

**Author:** [@Rabin\_Bhattacharya](https://discuss.elastic.co/u/Rabin_Bhattacharya)\
**Replies:** 9\
**Last updated:** [March 2, 2021, 6:29am UTC](https://discuss.elastic.co/t/search-a-string-using-logstash/265607 "2021-03-02T06:29:04Z")

</div>

Hi, We have a requirement to parse a XML ( XML2) which is available as a string within a XML( XML1) document. I was able to parse the XML1 using xml filter in logstash. Please help to parse /search a particular string w…

---

## [How to parse fields from multiline text log file?](https://discuss.elastic.co/t/how-to-parse-fields-from-multiline-text-log-file/265752)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 4\
**Last updated:** [March 2, 2021, 4:27am UTC](https://discuss.elastic.co/t/how-to-parse-fields-from-multiline-text-log-file/265752 "2021-03-02T04:27:45Z")

</div>

Dears, I need your advise in case of parsing fields from text log file. This is sample of text file: ---- got a mess at: 11:21:51 ctrl\_mess\_handler::control\_message\_handler @333.333 got new timer id: 11111, to be fired…

---

## [Extract multiline log with not id field present](https://discuss.elastic.co/t/extract-multiline-log-with-not-id-field-present/265848)

<div class="topic-metadata">

**Author:** [@E\_T\_N](https://discuss.elastic.co/u/E_T_N)\
**Replies:** 5\
**Last updated:** [March 2, 2021, 12:11am UTC](https://discuss.elastic.co/t/extract-multiline-log-with-not-id-field-present/265848 "2021-03-02T00:11:17Z")

</div>

Hello. I need to build a record composed of multiple lines where there is no clear identifier There is a word that tells me where the task starts in this case "select" There is a word that tells me where the task ends…

---

## [Mikrotik sending IPFIX to Logstarsh](https://discuss.elastic.co/t/mikrotik-sending-ipfix-to-logstarsh/265830)

<div class="topic-metadata">

**Author:** [@Roberto\_Williams\_Bat](https://discuss.elastic.co/u/Roberto_Williams_Bat)\
**Replies:** 0\
**Last updated:** [March 1, 2021, 4:13pm UTC](https://discuss.elastic.co/t/mikrotik-sending-ipfix-to-logstarsh/265830 "2021-03-01T16:13:26Z")

</div>

Hello, I need to ingest IPFIX data from Mikrotik, which arrives in my ELK server in port 9880. How should I configure the Logstash to receive it and have elastcsearching ingesting it? Note: I can change IPFIX to NetFlo…

---

## [Kibana and logstash](https://discuss.elastic.co/t/kibana-and-logstash/265781)

<div class="topic-metadata">

**Author:** [@Gharsa\_Khouloud](https://discuss.elastic.co/u/Gharsa_Khouloud)\
**Replies:** 0\
**Last updated:** [March 1, 2021, 10:42am UTC](https://discuss.elastic.co/t/kibana-and-logstash/265781 "2021-03-01T10:42:59Z")

</div>

What is the best way to integrate more than one collection of mongodb into Kibana via Logstash and Elasticsearch . i want to join two or 3 collection from my database and index it in one index to elasticsearch ?

---

## [Logstash has stopped processing logs suddenly](https://discuss.elastic.co/t/logstash-has-stopped-processing-logs-suddenly/264273)

<div class="topic-metadata">

**Author:** [@amanpradhan](https://discuss.elastic.co/u/amanpradhan)\
**Replies:** 1\
**Last updated:** [March 1, 2021, 10:33am UTC](https://discuss.elastic.co/t/logstash-has-stopped-processing-logs-suddenly/264273 "2021-03-01T10:33:12Z")

</div>

Hi Everyone, My logstash stopped processing logs all of sudden when i checked in kibana one day. I did not make any changes in any config and it was working earlier from past one year. Now it is giving below error At…

---

## [Logstash parsing json](https://discuss.elastic.co/t/logstash-parsing-json/265163)

<div class="topic-metadata">

**Author:** [@ali\_ghorbani](https://discuss.elastic.co/u/ali_ghorbani)\
**Replies:** 8\
**Last updated:** [March 1, 2021, 10:23am UTC](https://discuss.elastic.co/t/logstash-parsing-json/265163 "2021-03-01T10:23:51Z")

</div>

I am trying to use log-stash to read input file 1.log in JSON format and write on elasticsearch. This is my log file: {"key":"value00"} {"key":"value01"} {"key1":\[{"key2":"value02"},{"key3":"value03"},{"key4":\[{"key5":"…

---

## [Selecting "file" in logstash input does not send to elasticsearch](https://discuss.elastic.co/t/selecting-file-in-logstash-input-does-not-send-to-elasticsearch/265602)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 8\
**Last updated:** [March 1, 2021, 8:04am UTC](https://discuss.elastic.co/t/selecting-file-in-logstash-input-does-not-send-to-elasticsearch/265602 "2021-03-01T08:04:24Z")

</div>

I am trying to send log files from logstash to elasticsearch. I have completed the whole setup and the test to send the standard input to elasticsearch has passed. Now, I want to send the file to elasticsearch by speci…

---

## [How to stop logstash to not creating multiple conf.save file](https://discuss.elastic.co/t/how-to-stop-logstash-to-not-creating-multiple-conf-save-file/265747)

<div class="topic-metadata">

**Author:** [@asan](https://discuss.elastic.co/u/asan)\
**Replies:** 1\
**Last updated:** [March 1, 2021, 4:55am UTC](https://discuss.elastic.co/t/how-to-stop-logstash-to-not-creating-multiple-conf-save-file/265747 "2021-03-01T04:55:13Z")

</div>

Hi Recently i configured logstsh for parsing my mikrotik and fortigate log and they are working correctly but in conf.d logstsh started to create multiple conf.save like : mikrotik.conf.save.1, mikrotik.conf.save.2, m…

---

## [Parse "message" field on Syslog](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729)

<div class="topic-metadata">

**Author:** [@Santiago\_Fernandez](https://discuss.elastic.co/u/Santiago_Fernandez)\
**Replies:** 3\
**Last updated:** [February 28, 2021, 6:53pm UTC](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729 "2021-02-28T18:53:17Z")

</div>

Hi Guys! I m new in ELK. have managed to get the Stack up and send my syslogs from my API Manager. I would like to be able to transform a Syslog field into JSON. The "message" field. This is my logstash.conf input { …

---

## [Configure metricbeat to use logstash--tutorial error?](https://discuss.elastic.co/t/configure-metricbeat-to-use-logstash-tutorial-error/265143)

<div class="topic-metadata">

**Author:** [@John\_McDonnell](https://discuss.elastic.co/u/John_McDonnell)\
**Replies:** 3\
**Last updated:** [February 27, 2021, 11:59pm UTC](https://discuss.elastic.co/t/configure-metricbeat-to-use-logstash-tutorial-error/265143 "2021-02-27T23:59:39Z")

</div>

I've set up a 7.11 Kibana-Elastisearch-Logstash-Beats stack more-or-less successfully, but I am unable to configure metricbeat to use logstash. (I am able to see metricbeat data sending it directly to elastisearch.) F…

---

## [Log stash schema less input fields](https://discuss.elastic.co/t/log-stash-schema-less-input-fields/265681)

<div class="topic-metadata">

**Author:** [@ali\_ghorbani](https://discuss.elastic.co/u/ali_ghorbani)\
**Replies:** 1\
**Last updated:** [February 27, 2021, 4:41pm UTC](https://discuss.elastic.co/t/log-stash-schema-less-input-fields/265681 "2021-02-27T16:41:49Z")

</div>

Hi, I'm new in log-stash what I trying to do is to store my request and response JSON of my web app into the elastic search using log-stash with no change in their JSON format. the problem is a field named start\_time i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=249)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=251)
