# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=252

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 253

---

## [Convert string in strict\_date\_time (yyyy-MM-dd'T'HH:mm:ss.SSSZZ) to @timestamp](https://discuss.elastic.co/t/convert-string-in-strict-date-time-yyyy-mm-ddthhss-ssszz-to-timestamp/265150)

<div class="topic-metadata">

**Author:** [@manulearns](https://discuss.elastic.co/u/manulearns)\
**Replies:** 10\
**Last updated:** [February 24, 2021, 4:02pm UTC](https://discuss.elastic.co/t/convert-string-in-strict-date-time-yyyy-mm-ddthhss-ssszz-to-timestamp/265150 "2021-02-24T16:02:12Z")

</div>

Hi, I'am trying to convert a string in strict\_date\_time format 2021-02-19T23:02:57.277+05:30 to @timestamp. date { match =\> \[ "timeStampString" , "yyyy-MM-dd'T'HH:mm:ss.SSSZZ" \] target =\> "logTimestamp3" } Throwin…

---

## [Let Logstash handle multi-pipeline performance?](https://discuss.elastic.co/t/let-logstash-handle-multi-pipeline-performance/265177)

<div class="topic-metadata">

**Author:** [@nico127](https://discuss.elastic.co/u/nico127)\
**Replies:** 3\
**Last updated:** [February 24, 2021, 3:08pm UTC](https://discuss.elastic.co/t/let-logstash-handle-multi-pipeline-performance/265177 "2021-02-24T15:08:00Z")

</div>

In the case of multi-pipeline, I understand that the canonical way to handle performance is to manually configure each pipeline, e.g. to use N pipeline workers, or to have a batch size of M. is it possible to let Logsta…

---

## [Logstash configuration | Elimination of if loops in checking values at nested JSON keys](https://discuss.elastic.co/t/logstash-configuration-elimination-of-if-loops-in-checking-values-at-nested-json-keys/265139)

<div class="topic-metadata">

**Author:** [@pkrahul236](https://discuss.elastic.co/u/pkrahul236)\
**Replies:** 3\
**Last updated:** [February 24, 2021, 2:38pm UTC](https://discuss.elastic.co/t/logstash-configuration-elimination-of-if-loops-in-checking-values-at-nested-json-keys/265139 "2021-02-24T14:38:29Z")

</div>

Hello Community Users, I am seeking help regarding writing a better logstash configuration file. I am dealing with nested array JSON which looks something like this. { "data": { "content": { "payload": \[ …

---

## [How to automatically stop logstash process instance after its read the doc](https://discuss.elastic.co/t/how-to-automatically-stop-logstash-process-instance-after-its-read-the-doc/265343)

<div class="topic-metadata">

**Author:** [@rknd](https://discuss.elastic.co/u/rknd)\
**Replies:** 1\
**Last updated:** [February 24, 2021, 2:33pm UTC](https://discuss.elastic.co/t/how-to-automatically-stop-logstash-process-instance-after-its-read-the-doc/265343 "2021-02-24T14:33:47Z")

</div>

I want to ask that, below is my code. With the below code logstash reads the file until its end. Then it is stops reading but process is still alive. I want that process stops when it finishes the reading. How can i do t…

---

## [Logstash doesn't parse logs if i don't define start\_position](https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329)

<div class="topic-metadata">

**Author:** [@rknd](https://discuss.elastic.co/u/rknd)\
**Replies:** 2\
**Last updated:** [February 24, 2021, 1:22pm UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-logs-if-i-dont-define-start-position/265329 "2021-02-24T13:22:06Z")

</div>

Below is my code. When I try to run this pipeline. Pipeline is starting but not parsing the logs. I have deleted .sincedb files at (data/plugins/inputs/file). input { file { path =\> ".../directory/\*.log" …

---

## [XML Filter example](https://discuss.elastic.co/t/xml-filter-example/264698)

<div class="topic-metadata">

**Author:** [@Rabin\_Bhattacharya](https://discuss.elastic.co/u/Rabin_Bhattacharya)\
**Replies:** 4\
**Last updated:** [February 24, 2021, 1:20pm UTC](https://discuss.elastic.co/t/xml-filter-example/264698 "2021-02-24T13:20:23Z")

</div>

Hi, I have a requirement where in the a XML message is picked up from TIBCO EMS with the help of logstash and then is viewed in Kibana. I want to parse this message element individually for example conversationid,eventi…

---

## [Can not restart logstash service after configured syslog.conf](https://discuss.elastic.co/t/can-not-restart-logstash-service-after-configured-syslog-conf/265335)

<div class="topic-metadata">

**Author:** [@testsemd\_email](https://discuss.elastic.co/u/testsemd_email)\
**Replies:** 0\
**Last updated:** [February 24, 2021, 12:03pm UTC](https://discuss.elastic.co/t/can-not-restart-logstash-service-after-configured-syslog-conf/265335 "2021-02-24T12:03:28Z")

</div>

I was able to install logstash on the ubuntu server. Then I configued the syslog.conf file to get the traffic to elasticsearch(installed in same server). Then tried to restart the logstash service, but unable to restar…

---

## [How can i read logs event in logstash from siem system?](https://discuss.elastic.co/t/how-can-i-read-logs-event-in-logstash-from-siem-system/265151)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 1\
**Last updated:** [February 24, 2021, 11:20am UTC](https://discuss.elastic.co/t/how-can-i-read-logs-event-in-logstash-from-siem-system/265151 "2021-02-24T11:20:30Z")

</div>

How can i read logs from siem system in logstash?

---

## [How to uninstall Logstash](https://discuss.elastic.co/t/how-to-uninstall-logstash/265280)

<div class="topic-metadata">

**Author:** [@testsemd\_email](https://discuss.elastic.co/u/testsemd_email)\
**Replies:** 1\
**Last updated:** [February 24, 2021, 10:20am UTC](https://discuss.elastic.co/t/how-to-uninstall-logstash/265280 "2021-02-24T10:20:10Z")

</div>

I want to know how to uninstall Logstash in the Ubuntu server?

---

## [How to make a field hold an array, and how to put values in there, and how to loop through an array?](https://discuss.elastic.co/t/how-to-make-a-field-hold-an-array-and-how-to-put-values-in-there-and-how-to-loop-through-an-array/265311)

<div class="topic-metadata">

**Author:** [@Khalil\_SLEIMI](https://discuss.elastic.co/u/Khalil_SLEIMI)\
**Replies:** 0\
**Last updated:** [February 24, 2021, 9:46am UTC](https://discuss.elastic.co/t/how-to-make-a-field-hold-an-array-and-how-to-put-values-in-there-and-how-to-loop-through-an-array/265311 "2021-02-24T09:46:39Z")

</div>

Hi there, I'm new to the elk stack, and want some advice concerning how to manipulate json objects. long story short, I have a json that I extracted from an xml, and now, want to change the json of the output, that's why…

---

## [Filebeat Logstash Module](https://discuss.elastic.co/t/filebeat-logstash-module/265297)

<div class="topic-metadata">

**Author:** [@radu990](https://discuss.elastic.co/u/radu990)\
**Replies:** 0\
**Last updated:** [February 24, 2021, 9:13am UTC](https://discuss.elastic.co/t/filebeat-logstash-module/265297 "2021-02-24T09:13:54Z")

</div>

Hi guys, I'm trying to add a log to Logstash module in Filebeat, but can't succeed. Can anybody please give me some hint what's wrong in my config? Example of Log Entry 2021-02-23T12:44:49.000Z,Warning,1 2021-02-23T1…

---

## [Unable to index with below error](https://discuss.elastic.co/t/unable-to-index-with-below-error/265277)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 0\
**Last updated:** [February 24, 2021, 5:21am UTC](https://discuss.elastic.co/t/unable-to-index-with-below-error/265277 "2021-02-24T05:21:42Z")

</div>

Hi Team, I am facing an error while ingesting logs in elasticsearch. \[2021-02-24T10:44:15,640\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\]\[69d9e547a776f45c4f2e9d8533dceb1247bd41e30f7abf5602145295741669ba\] Could not in…

---

## [Converting Duration Field From Text To Number](https://discuss.elastic.co/t/converting-duration-field-from-text-to-number/265255)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [February 23, 2021, 10:35pm UTC](https://discuss.elastic.co/t/converting-duration-field-from-text-to-number/265255 "2021-02-23T22:35:49Z")

</div>

I have a field that displays connection duration as a string that looks like 3h:49m:57s. Any ideas on how to convert this to an aggregateable format such as epoch time or something?

---

## [Grok Timestamp](https://discuss.elastic.co/t/grok-timestamp/265236)

<div class="topic-metadata">

**Author:** [@Alex\_Leong](https://discuss.elastic.co/u/Alex_Leong)\
**Replies:** 1\
**Last updated:** [February 23, 2021, 7:13pm UTC](https://discuss.elastic.co/t/grok-timestamp/265236 "2021-02-23T19:13:17Z")

</div>

I have sample log as follows, and trying to grok it so that the timestamp is in the format YYYY-MM-DD HH:MI:SS.ssssss. Hence the timestamp "0204 14:29:42.248281" becomes "2021-02-04 14:29:42.24828" Sample log : E0204…

---

## [JSON Parsing Issue](https://discuss.elastic.co/t/json-parsing-issue/265219)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 4\
**Last updated:** [February 23, 2021, 6:54pm UTC](https://discuss.elastic.co/t/json-parsing-issue/265219 "2021-02-23T18:54:13Z")

</div>

Running Logstash 7.10 and having an issue with parsing a JSON-ish field. Here's my filter config: if \[vpn\]\[tunnel\_type\] { mutate { gsub =\> \[ "\[vpn\]\[tunnel\_type\]", '\\=\\\>', ':' \] …

---

## [Logstash output to Elasticsearch name index based on field?](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-name-index-based-on-field/264584)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 11\
**Last updated:** [February 23, 2021, 4:18pm UTC](https://discuss.elastic.co/t/logstash-output-to-elasticsearch-name-index-based-on-field/264584 "2021-02-23T16:18:24Z")

</div>

Hello. Im trying to name a index based on a field but it doesnt seem to work: output { elasticsearch { hosts =\> \["localhost"\] user =\> \["elastic"\] password =\> \["pass"\] index =\> "winlogbeat-server-winapplication-%{…

---

## [Wildfly grok date not extracted](https://discuss.elastic.co/t/wildfly-grok-date-not-extracted/264441)

<div class="topic-metadata">

**Author:** [@jsec](https://discuss.elastic.co/u/jsec)\
**Replies:** 4\
**Last updated:** [February 23, 2021, 4:17pm UTC](https://discuss.elastic.co/t/wildfly-grok-date-not-extracted/264441 "2021-02-23T16:17:25Z")

</div>

Hello, I'm trying to parse the following wildfly log format: 2021-02-16 00:01:34,505 ERROR \[org.springframework.boot.cttt.web.ErrorPageFilter\] (default task-48) Forwarding to error page from request \[/user/history\] due…

---

## [Regarding Metric Filter](https://discuss.elastic.co/t/regarding-metric-filter/265211)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [February 23, 2021, 3:50pm UTC](https://discuss.elastic.co/t/regarding-metric-filter/265211 "2021-02-23T15:50:44Z")

</div>

Hi, I'm trying to dynamically add fields to a metric filter. Can you tell me why this is failing interpolation? metrics { meter =\> \[ "events" \] add\_field =\> { "agent" =\> "%{\[agen…

---

## [Syslog Preserve host](https://discuss.elastic.co/t/syslog-preserve-host/265216)

<div class="topic-metadata">

**Author:** [@petegriggs](https://discuss.elastic.co/u/petegriggs)\
**Replies:** 0\
**Last updated:** [February 23, 2021, 3:10pm UTC](https://discuss.elastic.co/t/syslog-preserve-host/265216 "2021-02-23T15:10:55Z")

</div>

Hey! I have some devices pointing at logstash and in turn this is forwarding on to a SIEM via syslog - however when we output to syslog the messages appear to come from logstash - is there a way to preserve the sysloggi…

---

## [Error: A plugin had an unrecoverable error. Will restart this plugin](https://discuss.elastic.co/t/error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/265101)

<div class="topic-metadata">

**Author:** [@jaispirit](https://discuss.elastic.co/u/jaispirit)\
**Replies:** 2\
**Last updated:** [February 23, 2021, 9:37am UTC](https://discuss.elastic.co/t/error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/265101 "2021-02-23T09:37:49Z")

</div>

I am running Elastick-Stack with Security on a single node successfully. I am trying to send logs from another instance with Filebeat to Logstash (Elastic-Stack) without success and receive following 2 errors: \[ERROR\]…

---

## [Filter issue with Logstash](https://discuss.elastic.co/t/filter-issue-with-logstash/265171)

<div class="topic-metadata">

**Author:** [@nyquillus](https://discuss.elastic.co/u/nyquillus)\
**Replies:** 0\
**Last updated:** [February 23, 2021, 7:31am UTC](https://discuss.elastic.co/t/filter-issue-with-logstash/265171 "2021-02-23T07:31:54Z")

</div>

Hi, I recently added a filter to my logstash to change indexing for spesific indices(weekly, monthly etc.) The filter is this: filter { if \[retention\] == "weekly" { mutate { add\_field =\> { "\[@metadata\]…

---

## [Problem With parsing mikrotik log](https://discuss.elastic.co/t/problem-with-parsing-mikrotik-log/264977)

<div class="topic-metadata">

**Author:** [@asan](https://discuss.elastic.co/u/asan)\
**Replies:** 2\
**Last updated:** [February 23, 2021, 5:17am UTC](https://discuss.elastic.co/t/problem-with-parsing-mikrotik-log/264977 "2021-02-23T05:17:08Z")

</div>

Hi i've been trying to normalize mikrotik log with grok in logstash and my sample log is : Feb 20 04:38:02 192.168.202.101 id=firewall sn=C0EAE45CA55 time="2021-02-20 12:54:43" fw=188.126.145.3 pri=6 c=1 m=911 msg="A…

---

## [Logstash iterate through loop](https://discuss.elastic.co/t/logstash-iterate-through-loop/265092)

<div class="topic-metadata">

**Author:** [@bdn](https://discuss.elastic.co/u/bdn)\
**Replies:** 4\
**Last updated:** [February 23, 2021, 2:12am UTC](https://discuss.elastic.co/t/logstash-iterate-through-loop/265092 "2021-02-23T02:12:16Z")

</div>

if \[field2\] == 10 { mutate { replace =\> { "field2" =\> "1" } } } if \[field2\] == 11 { mutate { replace =\> { "field2" =\> "2" } } } if \[field2\] == 12 { mutate { replace =\> { "field2" =\> "3" } } } I h…

---

## [Logstash](https://discuss.elastic.co/t/logstash/265052)

<div class="topic-metadata">

**Author:** [@ranju](https://discuss.elastic.co/u/ranju)\
**Replies:** 1\
**Last updated:** [February 23, 2021, 12:58am UTC](https://discuss.elastic.co/t/logstash/265052 "2021-02-23T00:58:49Z")

</div>

Hi All {"log":"abc","system":"ABC","country":"India","ids":\["111222","22233344"\]} logtag= event.get('system') --\> value getting as ABC itemIds = event.get('ids') --\> Not getting How can we take a String array value?

---

## [Dynamic query in jdbc plugin](https://discuss.elastic.co/t/dynamic-query-in-jdbc-plugin/264806)

<div class="topic-metadata">

**Author:** [@niki1](https://discuss.elastic.co/u/niki1)\
**Replies:** 3\
**Last updated:** [February 22, 2021, 6:57pm UTC](https://discuss.elastic.co/t/dynamic-query-in-jdbc-plugin/264806 "2021-02-22T18:57:29Z")

</div>

I got a mysql(or any other relational database) with a table like this: id,name,prod 11,alex,car 22,alice,ship 33,bob,airplane and I have messages going through logstash pipeline like this: 11,20210215,ford,.... 2…

---

## [Rsyslog to send logs to logstash](https://discuss.elastic.co/t/rsyslog-to-send-logs-to-logstash/264973)

<div class="topic-metadata">

**Author:** [@Prabhath\_samarasingh](https://discuss.elastic.co/u/Prabhath_samarasingh)\
**Replies:** 11\
**Last updated:** [February 22, 2021, 2:41pm UTC](https://discuss.elastic.co/t/rsyslog-to-send-logs-to-logstash/264973 "2021-02-22T14:41:57Z")

</div>

Hi, Configured rsyslog to send logs to logstash. But kibana dosen't receive. Please help. OS : Ubuntu 20.04 \</\> cat /etc/elasticsearch/elasticsearch.yml Elasticsearch performs poorly when the system is swapping t…

---

## [Grok matching multi-lines saving first and last value to separate fields](https://discuss.elastic.co/t/grok-matching-multi-lines-saving-first-and-last-value-to-separate-fields/264958)

<div class="topic-metadata">

**Author:** [@Daniel\_Jankech](https://discuss.elastic.co/u/Daniel_Jankech)\
**Replies:** 11\
**Last updated:** [February 22, 2021, 3:08pm UTC](https://discuss.elastic.co/t/grok-matching-multi-lines-saving-first-and-last-value-to-separate-fields/264958 "2021-02-22T15:08:30Z")

</div>

Hello everyone, as the caption indicates I am trying to match multiple-lines of logs of which I would like to save first occurence of timestamp to separate field than last occurence of the timestamp. I am using codec mu…

---

## [Logstash mutate rename](https://discuss.elastic.co/t/logstash-mutate-rename/265043)

<div class="topic-metadata">

**Author:** [@Jokie74](https://discuss.elastic.co/u/Jokie74)\
**Replies:** 1\
**Last updated:** [February 22, 2021, 2:25pm UTC](https://discuss.elastic.co/t/logstash-mutate-rename/265043 "2021-02-22T14:25:08Z")

</div>

hello dear community, I have a question about the "mutate rename" filter option. In my logstash filter I have this: mutate { rename =\> { "\[fields\]\[host\]\[name\]" =\> "\[host\]\[name\]" …

---

## [Get Akamai SIEM logs to ELK](https://discuss.elastic.co/t/get-akamai-siem-logs-to-elk/265075)

<div class="topic-metadata">

**Author:** [@Shubhangi](https://discuss.elastic.co/u/Shubhangi)\
**Replies:** 0\
**Last updated:** [February 22, 2021, 2:11pm UTC](https://discuss.elastic.co/t/get-akamai-siem-logs-to-elk/265075 "2021-02-22T14:11:54Z")

</div>

Hi, We want to ingest SIEM logs from akamai to Logstash, then Elasticsearch. To access SIEM logs, we have created akamai API credentials and have gotten SIEM connector details. They include: client\_secret = host = xy…

---

## [Can I add dynamic index mapping from Logstash](https://discuss.elastic.co/t/can-i-add-dynamic-index-mapping-from-logstash/264674)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 2\
**Last updated:** [February 22, 2021, 11:51am UTC](https://discuss.elastic.co/t/can-i-add-dynamic-index-mapping-from-logstash/264674 "2021-02-22T11:51:03Z")

</div>

I am creating index dynamically(e.g wallet-tx-customer-%{+YYYY.MM}) from Logstash. For some field I am getting an error mapper \[usd\] cannot be changed from type \[long\] to \[float\] and that event doesn't get indexed. I wa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=251)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=253)
