# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=256

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 257

---

## [Parsing json logs issue](https://discuss.elastic.co/t/parsing-json-logs-issue/263638)

<div class="topic-metadata">

**Author:** [@doogle](https://discuss.elastic.co/u/doogle)\
**Replies:** 2\
**Last updated:** [February 10, 2021, 9:26am UTC](https://discuss.elastic.co/t/parsing-json-logs-issue/263638 "2021-02-10T09:26:52Z")

</div>

Hi All, I am rather new to all of this and I have been tasked to get logging working in our environment. We have a smoothwall firewall that we use for webfiltering. I have manged to get most of the logs parsed, however …

---

## [State tracker file update - JDBC input plugin](https://discuss.elastic.co/t/state-tracker-file-update-jdbc-input-plugin/263268)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 2\
**Last updated:** [February 10, 2021, 7:28am UTC](https://discuss.elastic.co/t/state-tracker-file-update-jdbc-input-plugin/263268 "2021-02-10T07:28:27Z")

</div>

Would like to know when the state tracker file get's updated. We are using the jdbc input plugin and modified date from the table has been used as the state tracker field. Would like to know when the state tracker files…

---

## [Logstash is creating data streams instead of indices in ES](https://discuss.elastic.co/t/logstash-is-creating-data-streams-instead-of-indices-in-es/263824)

<div class="topic-metadata">

**Author:** [@naveenj](https://discuss.elastic.co/u/naveenj)\
**Replies:** 0\
**Last updated:** [February 10, 2021, 4:41am UTC](https://discuss.elastic.co/t/logstash-is-creating-data-streams-instead-of-indices-in-es/263824 "2021-02-10T04:41:31Z")

</div>

elasticsearch { host =\> "localhost" index\_type =\> "logs-%{\[kubernetes\]\[labels\]\[app\]}" } I am using above configuration in logstash Helm chat values.yml file for OKD setup. filebeat -\>logstash -\>ES Some logs …

---

## [Logstash Aggregation and IF/Else](https://discuss.elastic.co/t/logstash-aggregation-and-if-else/263777)

<div class="topic-metadata">

**Author:** [@govind94](https://discuss.elastic.co/u/govind94)\
**Replies:** 0\
**Last updated:** [February 9, 2021, 4:57pm UTC](https://discuss.elastic.co/t/logstash-aggregation-and-if-else/263777 "2021-02-09T16:57:00Z")

</div>

I have SOP named GIS which have 3 jobs and getting 3 events {"jobName":"BIS43683","JobStatus":"COMPLETE","@timestamp":"2020-02-08T23:00:47.958Z","JobSystemStatus":"COMPLETE"} {"jobName":"BIS43595","JobStatus":"COMPLETE…

---

## [Logstash Filter - regez](https://discuss.elastic.co/t/logstash-filter-regez/263806)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 3\
**Last updated:** [February 9, 2021, 9:33pm UTC](https://discuss.elastic.co/t/logstash-filter-regez/263806 "2021-02-09T21:33:06Z")

</div>

Hi, Please help me with the if condition filter in logstash for same KQL querymentioned below. message: \*.url.\* and not \*failover\* Below logstash filter is not working filter{ if (\[message\] != ‘.\\.url\\..’ and \[messa…

---

## [Which is more efficient? KV, Dissect, Split, Grok](https://discuss.elastic.co/t/which-is-more-efficient-kv-dissect-split-grok/263789)

<div class="topic-metadata">

**Author:** [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Replies:** 2\
**Last updated:** [February 9, 2021, 6:55pm UTC](https://discuss.elastic.co/t/which-is-more-efficient-kv-dissect-split-grok/263789 "2021-02-09T18:55:38Z")

</div>

Hi all, As there are many ways to achive similar goal using logstash filters, would like to discuss and compare between KV, Dissect, Split, and Grok, which is a better way of handling data? Scenario 1: Mapping & Parsi…

---

## [Received an event that has a different character encoding than you configured](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-than-you-configured/263792)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 1\
**Last updated:** [February 9, 2021, 6:32pm UTC](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-than-you-configured/263792 "2021-02-09T18:32:01Z")

</div>

I have seen several threads related to the same error, but none of them seem to address the issue as we are experiencing it. The messages I get this error for are from ADAudit+ reading logs from an Isilon storage applian…

---

## [Same logstash config file give different result for the same input on different machines](https://discuss.elastic.co/t/same-logstash-config-file-give-different-result-for-the-same-input-on-different-machines/263774)

<div class="topic-metadata">

**Author:** [@Aryaman\_Gupta](https://discuss.elastic.co/u/Aryaman_Gupta)\
**Replies:** 4\
**Last updated:** [February 9, 2021, 6:13pm UTC](https://discuss.elastic.co/t/same-logstash-config-file-give-different-result-for-the-same-input-on-different-machines/263774 "2021-02-09T18:13:57Z")

</div>

Hi I have created one logstash conf file but I am running the same config file on two machine, one is mac and other is ubbuntu. For the same input data on my mac I am getting the correct output where as in ubuntu I am g…

---

## [Logastash container went down - we did not monitor it](https://discuss.elastic.co/t/logastash-container-went-down-we-did-not-monitor-it/263771)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [February 9, 2021, 5:48pm UTC](https://discuss.elastic.co/t/logastash-container-went-down-we-did-not-monitor-it/263771 "2021-02-09T17:48:44Z")

</div>

Hi there, I had the case that the logstash container (7.8.1) just stopped working and we did not nominitor it. What I would have liked: in the momen it crashed docker should have restarted it from the scratch. Question…

---

## [Do not update sql\_last\_value when an Elastic error is encountered](https://discuss.elastic.co/t/do-not-update-sql-last-value-when-an-elastic-error-is-encountered/263788)

<div class="topic-metadata">

**Author:** [@KSmith](https://discuss.elastic.co/u/KSmith)\
**Replies:** 1\
**Last updated:** [February 9, 2021, 5:46pm UTC](https://discuss.elastic.co/t/do-not-update-sql-last-value-when-an-elastic-error-is-encountered/263788 "2021-02-09T17:46:26Z")

</div>

input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/drivers/jdbc/${PG\_DRIVER}" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_connection\_string =\> "jdbc:postgresql://${DATABASE\_HOST}…

---

## [Logstash/Filebeat is periodically hanging (unresponsive)](https://discuss.elastic.co/t/logstash-filebeat-is-periodically-hanging-unresponsive/263199)

<div class="topic-metadata">

**Author:** [@user2416](https://discuss.elastic.co/u/user2416)\
**Replies:** 3\
**Last updated:** [February 9, 2021, 5:39pm UTC](https://discuss.elastic.co/t/logstash-filebeat-is-periodically-hanging-unresponsive/263199 "2021-02-09T17:39:17Z")

</div>

Hi, We are using filebeat as a deamonset on kubernetes nodes to collect all application logs and sending them to logstash and then to elasticsearch. we observe that logs stops working/hangs periodically from some speci…

---

## [Time Duration difference calculation in Logstash](https://discuss.elastic.co/t/time-duration-difference-calculation-in-logstash/263599)

<div class="topic-metadata">

**Author:** [@Rebin](https://discuss.elastic.co/u/Rebin)\
**Replies:** 7\
**Last updated:** [February 9, 2021, 5:01pm UTC](https://discuss.elastic.co/t/time-duration-difference-calculation-in-logstash/263599 "2021-02-09T17:01:43Z")

</div>

Hi All, i'm trying to calculate the time difference between 2 dates. I'm capturing the data through jdbc Input "opentime" : "2020-11-01T11:42:59.000Z", "resolvedtime" : "2020-11-02T22:38:37.000Z", Code filter { date…

---

## [Not able to use insert sql query in jdbc\_streaming filter](https://discuss.elastic.co/t/not-able-to-use-insert-sql-query-in-jdbc-streaming-filter/263725)

<div class="topic-metadata">

**Author:** [@Melvin\_Shaju](https://discuss.elastic.co/u/Melvin_Shaju)\
**Replies:** 3\
**Last updated:** [February 9, 2021, 4:57pm UTC](https://discuss.elastic.co/t/not-able-to-use-insert-sql-query-in-jdbc-streaming-filter/263725 "2021-02-09T16:57:37Z")

</div>

When I tried to insert some in local mysql using jdbc\_streaming filter, it is showing following error. But no error is shown for select statements. Ruby-0-Thread-12@\[main\]\>worker6: :1\] jdbcstreaming - Exception when exe…

---

## [Split FQDN](https://discuss.elastic.co/t/split-fqdn/263773)

<div class="topic-metadata">

**Author:** [@Dan\_L](https://discuss.elastic.co/u/Dan_L)\
**Replies:** 2\
**Last updated:** [February 9, 2021, 4:54pm UTC](https://discuss.elastic.co/t/split-fqdn/263773 "2021-02-09T16:54:53Z")

</div>

I'm trying to split an FQDN to get the base server name. Currently, the FQDN is stored in "server", so I'd like to split "server" on "." and get the name. Additionally, sometimes the server may not be the FQDN, so it'd …

---

## [Parsing Json object array](https://discuss.elastic.co/t/parsing-json-object-array/262487)

<div class="topic-metadata">

**Author:** [@jolaniya](https://discuss.elastic.co/u/jolaniya)\
**Replies:** 6\
**Last updated:** [February 9, 2021, 3:19pm UTC](https://discuss.elastic.co/t/parsing-json-object-array/262487 "2021-02-09T15:19:31Z")

</div>

Hi, I have trouble with a xml file. I have applied xml filter on that and after that i am getting 2 outputs. message.GeneralInfo message.ReportNode I guess these are json outputs but json filter is not working on th…

---

## [Problem to get xml response with http\_poller plugin](https://discuss.elastic.co/t/problem-to-get-xml-response-with-http-poller-plugin/263749)

<div class="topic-metadata">

**Author:** [@hiba](https://discuss.elastic.co/u/hiba)\
**Replies:** 0\
**Last updated:** [February 9, 2021, 2:32pm UTC](https://discuss.elastic.co/t/problem-to-get-xml-response-with-http-poller-plugin/263749 "2021-02-09T14:32:39Z")

</div>

Hi all, I want to load data from an api rest (response xml) using logstash 7.9.0 this is my config file: input { http\_poller { urls =\> { method =\> get url1 =\> "https://\*\*\*\*\*\*\*/rest/1.0/geography"…

---

## [Logstash - Elastichsearch Output - ILM](https://discuss.elastic.co/t/logstash-elastichsearch-output-ilm/263700)

<div class="topic-metadata">

**Author:** [@Jurilz](https://discuss.elastic.co/u/Jurilz)\
**Replies:** 0\
**Last updated:** [February 9, 2021, 9:15am UTC](https://discuss.elastic.co/t/logstash-elastichsearch-output-ilm/263700 "2021-02-09T09:15:26Z")

</div>

Good day, I'm trying to establish an Index Lifecycle Management for my indices by using the elasticsearch output in Logstash. This is the elasticsearch output plugin config: output { if "tomcat" in \[type\] { elas…

---

## [Logstash filter with separator " \_"](https://discuss.elastic.co/t/logstash-filter-with-separator/263675)

<div class="topic-metadata">

**Author:** [@vik1](https://discuss.elastic.co/u/vik1)\
**Replies:** 3\
**Last updated:** [February 9, 2021, 12:47pm UTC](https://discuss.elastic.co/t/logstash-filter-with-separator/263675 "2021-02-09T12:47:45Z")

</div>

Hello, I am using logstash to collect data from FortiGate. I have one special field to check the number of connections per day. This "vpn" field looks like sz\_forti, szec\_forti. I need to take the first characters before…

---

## [Filter username or email address within space delimited string](https://discuss.elastic.co/t/filter-username-or-email-address-within-space-delimited-string/263479)

<div class="topic-metadata">

**Author:** [@earlsanchez](https://discuss.elastic.co/u/earlsanchez)\
**Replies:** 3\
**Last updated:** [February 9, 2021, 8:13am UTC](https://discuss.elastic.co/t/filter-username-or-email-address-within-space-delimited-string/263479 "2021-02-09T08:13:20Z")

</div>

Hello, I'm trying to create a Logstash filter using Grok for the following log event: 2021-01-15 15:36:08.081 ERROR t:44 com.ixiasoft.physicalModel.TextmlSession.loginWithServerConnection:321 Unable to authentica…

---

## [Simple Logstash Event in Docker](https://discuss.elastic.co/t/simple-logstash-event-in-docker/263672)

<div class="topic-metadata">

**Author:** [@manideep](https://discuss.elastic.co/u/manideep)\
**Replies:** 0\
**Last updated:** [February 9, 2021, 4:57am UTC](https://discuss.elastic.co/t/simple-logstash-event-in-docker/263672 "2021-02-09T04:57:33Z")

</div>

Hi All, I just pulled a Logstash Docker image and trying to run a simple event. here is the command I use. docker run --rm -it -v ~/pipleine/simpleevent.conf:/usr/share/logstash/pipeline/ docker.elastic.co/logstash/lo…

---

## [Filebeat modules via Logstash](https://discuss.elastic.co/t/filebeat-modules-via-logstash/263612)

<div class="topic-metadata">

**Author:** [@st1988](https://discuss.elastic.co/u/st1988)\
**Replies:** 6\
**Last updated:** [February 8, 2021, 9:19pm UTC](https://discuss.elastic.co/t/filebeat-modules-via-logstash/263612 "2021-02-08T21:19:01Z")

</div>

Hi everyone, I have an issue where when I try and integrate Filebeat PANOS module with Elasticsearch via Logstash it fails to bring across the pre-built dashboards that is does when integrating Filebeat directly with El…

---

## [ArubaOS](https://discuss.elastic.co/t/arubaos/263655)

<div class="topic-metadata">

**Author:** [@javig12](https://discuss.elastic.co/u/javig12)\
**Replies:** 0\
**Last updated:** [February 8, 2021, 9:00pm UTC](https://discuss.elastic.co/t/arubaos/263655 "2021-02-08T21:00:32Z")

</div>

Hello community? Has anyone could ship logs to Logstash from Aruba Networks? any .conf file example? hope your comments. Regards

---

## [Logstash won't run, openJDK 64-bit Server](https://discuss.elastic.co/t/logstash-wont-run-openjdk-64-bit-server/263072)

<div class="topic-metadata">

**Author:** [@Minx](https://discuss.elastic.co/u/Minx)\
**Replies:** 3\
**Last updated:** [February 8, 2021, 5:04pm UTC](https://discuss.elastic.co/t/logstash-wont-run-openjdk-64-bit-server/263072 "2021-02-08T17:04:07Z")

</div>

I try to run log stash and this happens, does anyone know what is wrong please? PS C:\\logstash-7.10.1\\bin\> .\\logstash.bat -f .\\config\\logstash.conf "Using bundled JDK: "" OpenJDK 64-Bit Server VM warning: Option UseCo…

---

## [Logstash Events forward](https://discuss.elastic.co/t/logstash-events-forward/263614)

<div class="topic-metadata">

**Author:** [@suraj.ghorp](https://discuss.elastic.co/u/suraj.ghorp)\
**Replies:** 0\
**Last updated:** [February 8, 2021, 2:30pm UTC](https://discuss.elastic.co/t/logstash-events-forward/263614 "2021-02-08T14:30:46Z")

</div>

Hi Team, Logastash pulling logs from cloud based WAF on windows system and we wanted to forward the logs towards Linux based SIEM forwarder. please hep to configure the config file.

---

## [\[Logstash\] Aggregate Filter Plugin with Nested Fields](https://discuss.elastic.co/t/logstash-aggregate-filter-plugin-with-nested-fields/263591)

<div class="topic-metadata">

**Author:** [@jeduguim](https://discuss.elastic.co/u/jeduguim)\
**Replies:** 0\
**Last updated:** [February 8, 2021, 11:45am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-plugin-with-nested-fields/263591 "2021-02-08T11:45:48Z")

</div>

Hi, I'm trying to use aggregate filter plugin with nested fields on a logstash config file. But I have a nested field inside other nested field. Is it possible to do in logstash? Maybe with multiple aggregate filters? My…

---

## [Help please.. to acchive json format](https://discuss.elastic.co/t/help-please-to-acchive-json-format/263330)

<div class="topic-metadata">

**Author:** [@onkarborade](https://discuss.elastic.co/u/onkarborade)\
**Replies:** 2\
**Last updated:** [February 8, 2021, 5:06am UTC](https://discuss.elastic.co/t/help-please-to-acchive-json-format/263330 "2021-02-08T05:06:05Z")

</div>

I have rosterentry field as bellow rosterentry = "100,01-JUL-20,01-AUG-22|100,02-JUL-20,02-AUG-22|101,03-JUL-19,03-AUG-19" I have converted to : rosterentry = \[ "100,01-JUL-20,01-AUG-22", …

---

## [Syslog filter for IP](https://discuss.elastic.co/t/syslog-filter-for-ip/263512)

<div class="topic-metadata">

**Author:** [@dandotwalker](https://discuss.elastic.co/u/dandotwalker)\
**Replies:** 3\
**Last updated:** [February 7, 2021, 9:57am UTC](https://discuss.elastic.co/t/syslog-filter-for-ip/263512 "2021-02-07T09:57:01Z")

</div>

Hi, I am learning Elastic so I have set it up in my home to prepare for when we start designing it at work. I have a simple set up where logstash is listening for syslog messages. It works great with most hosts but my …

---

## [Logstash SPLIT plugin help](https://discuss.elastic.co/t/logstash-split-plugin-help/263462)

<div class="topic-metadata">

**Author:** [@Zdeno\_Liska](https://discuss.elastic.co/u/Zdeno_Liska)\
**Replies:** 5\
**Last updated:** [February 7, 2021, 12:51am UTC](https://discuss.elastic.co/t/logstash-split-plugin-help/263462 "2021-02-07T00:51:11Z")

</div>

Hi, I would like to ask thing about Split plugin. I have event like: {"name":"JASON", "phones":\[{ "mark":"Nokia", "model":"3310"},{"mark":"Apple","model":"12 Pro"}\]} I use clone, and want object like: {"name":"JAS…

---

## [Linux auditd to ECS mapping](https://discuss.elastic.co/t/linux-auditd-to-ecs-mapping/263150)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 0\
**Last updated:** [February 3, 2021, 4:48pm UTC](https://discuss.elastic.co/t/linux-auditd-to-ecs-mapping/263150 "2021-02-03T16:48:22Z")

</div>

hi We got data coming via syslog-\> logstash from certain Linux devices and don't have auditbeats. Is there a logstash pattern, where I can map the auditd fields to ECS (common schema) format?

---

## [Logstash HTTP input plugin](https://discuss.elastic.co/t/logstash-http-input-plugin/263456)

<div class="topic-metadata">

**Author:** [@TrentB2000](https://discuss.elastic.co/u/TrentB2000)\
**Replies:** 0\
**Last updated:** [February 5, 2021, 6:57pm UTC](https://discuss.elastic.co/t/logstash-http-input-plugin/263456 "2021-02-05T18:57:01Z")

</div>

I am attempting to use the logstash HTTP input plugin with my Docker container that I am running Elk in. I am currently using Docker Compose to run my stack and in trying to follow this page (below) I have been unsuc…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=255)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=257)
