# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=262

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 263

---

## [Logstash Output Plugin for Hbase](https://discuss.elastic.co/t/logstash-output-plugin-for-hbase/261726)

<div class="topic-metadata">

**Author:** [@arpit1305](https://discuss.elastic.co/u/arpit1305)\
**Replies:** 0\
**Last updated:** [January 21, 2021, 6:02am UTC](https://discuss.elastic.co/t/logstash-output-plugin-for-hbase/261726 "2021-01-21T06:02:51Z")

</div>

Hi, I am looking for logstash output to be stored in Hbase. Any guidance or inputs please? Regards, Arpit

---

## [Why isn't the template working inside logstash?](https://discuss.elastic.co/t/why-isnt-the-template-working-inside-logstash/261723)

<div class="topic-metadata">

**Author:** [@chb1828](https://discuss.elastic.co/u/chb1828)\
**Replies:** 0\
**Last updated:** [January 21, 2021, 5:47am UTC](https://discuss.elastic.co/t/why-isnt-the-template-working-inside-logstash/261723 "2021-01-21T05:47:41Z")

</div>

I'm using logstash 7.0.0. I install my template but it doesn't apply. Logs in logstash are print like this. Attempting to install template {:manage\_template=\>{"template"=\>"news\*", "settings"=\>{"index.refresh\_interval"…

---

## [Logstash Centralized management pipeline](https://discuss.elastic.co/t/logstash-centralized-management-pipeline/261691)

<div class="topic-metadata">

**Author:** [@esijati](https://discuss.elastic.co/u/esijati)\
**Replies:** 7\
**Last updated:** [January 21, 2021, 12:09am UTC](https://discuss.elastic.co/t/logstash-centralized-management-pipeline/261691 "2021-01-21T00:09:03Z")

</div>

Hi, I am trying to enable the logstash centralized pipeline management with X-Pack security enabled, but with limited documentation from ELK I am unable to proceed further on how it will look at Kibana side. Regards J…

---

## [\[Logstash\] Can't update document for status (entity-centric)](https://discuss.elastic.co/t/logstash-cant-update-document-for-status-entity-centric/261692)

<div class="topic-metadata">

**Author:** [@Joao\_Palma](https://discuss.elastic.co/u/Joao_Palma)\
**Replies:** 0\
**Last updated:** [January 20, 2021, 7:17pm UTC](https://discuss.elastic.co/t/logstash-cant-update-document-for-status-entity-centric/261692 "2021-01-20T19:17:26Z")

</div>

Hello, I have this logs: {"process": "123", "status:red", "@timestamp":"2020-12-31T16:14:13.886+0000" } {"process": "122", "status:red", "@timestamp":"2020-12-31T16:14:14.886+0000" } {"process": "123", "status:green", …

---

## [Dissector mapping, pattern not found in Logstash](https://discuss.elastic.co/t/dissector-mapping-pattern-not-found-in-logstash/261210)

<div class="topic-metadata">

**Author:** [@Sharma3007](https://discuss.elastic.co/u/Sharma3007)\
**Replies:** 0\
**Last updated:** [January 15, 2021, 5:50am UTC](https://discuss.elastic.co/t/dissector-mapping-pattern-not-found-in-logstash/261210 "2021-01-15T05:50:25Z")

</div>

Hi Team, After a long time I am getting below error in my logstash config. \["beats\_input\_codec\_plain\_applied", "\_dissectfailure"\], "input"=\>{"type"=\>"log"}}} \[2021-01-15T04:02:07,055\]\[WARN \]\[org.logstash.dissect.Disse…

---

## [Dissector mapping, pattern not found in Logstash](https://discuss.elastic.co/t/dissector-mapping-pattern-not-found-in-logstash/261444)

<div class="topic-metadata">

**Author:** [@Sharma3007](https://discuss.elastic.co/u/Sharma3007)\
**Replies:** 7\
**Last updated:** [January 20, 2021, 12:29pm UTC](https://discuss.elastic.co/t/dissector-mapping-pattern-not-found-in-logstash/261444 "2021-01-20T12:29:32Z")

</div>

Hi Team, I am getting Dissector mapping, pattern not found in Logstash while start logstash.

---

## [Error parsing json](https://discuss.elastic.co/t/error-parsing-json/261618)

<div class="topic-metadata">

**Author:** [@shoaib\_akram](https://discuss.elastic.co/u/shoaib_akram)\
**Replies:** 0\
**Last updated:** [January 20, 2021, 7:49am UTC](https://discuss.elastic.co/t/error-parsing-json/261618 "2021-01-20T07:49:03Z")

</div>

Hi i am getting the following errors while ingesting urls into elasticsearch through logstash. Data is ingesting properly but i am getting these errors in log files please help me thanks, Error parsing json {:source=\>"…

---

## [Looks like you either have a bad certificate, an invalid key or your private key was not in PKCS8 format in logstash](https://discuss.elastic.co/t/looks-like-you-either-have-a-bad-certificate-an-invalid-key-or-your-private-key-was-not-in-pkcs8-format-in-logstash/261627)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 0\
**Last updated:** [January 20, 2021, 10:12am UTC](https://discuss.elastic.co/t/looks-like-you-either-have-a-bad-certificate-an-invalid-key-or-your-private-key-was-not-in-pkcs8-format-in-logstash/261627 "2021-01-20T10:12:37Z")

</div>

Hi Team, Im using below configuration in logstash beats and im getting below error, Could anyone help to resolve this issue, input { beats { port =\> 5044 host =\> server" …

---

## [Log stash not loading exact number of records in elasticsearch and on every hit results are changing](https://discuss.elastic.co/t/log-stash-not-loading-exact-number-of-records-in-elasticsearch-and-on-every-hit-results-are-changing/261266)

<div class="topic-metadata">

**Author:** [@ocmvin](https://discuss.elastic.co/u/ocmvin)\
**Replies:** 1\
**Last updated:** [January 20, 2021, 7:07am UTC](https://discuss.elastic.co/t/log-stash-not-loading-exact-number-of-records-in-elasticsearch-and-on-every-hit-results-are-changing/261266 "2021-01-20T07:07:05Z")

</div>

Problem statement : Logstash is not loading all records from Database to elasticsearch correctly and everytime I hit same api gets different results (However sometimes correct but changes on every hit and shows only subs…

---

## [Datestamp to @timestamp](https://discuss.elastic.co/t/datestamp-to-timestamp/261604)

<div class="topic-metadata">

**Author:** [@cyberd](https://discuss.elastic.co/u/cyberd)\
**Replies:** 2\
**Last updated:** [January 19, 2021, 11:21pm UTC](https://discuss.elastic.co/t/datestamp-to-timestamp/261604 "2021-01-19T23:21:34Z")

</div>

Hi, So i need to parse this date format from my log: 01/19/21-15:00:26.308390 to the @timestamp so i can filter it in Kibana. So far it looks like this: match =\> { "message" =\> "%{DATESTAMP:mystamp} date { m…

---

## [Logstash battle scars - metricbeat config and duplicate output](https://discuss.elastic.co/t/logstash-battle-scars-metricbeat-config-and-duplicate-output/261581)

<div class="topic-metadata">

**Author:** [@Declan\_at\_rm](https://discuss.elastic.co/u/Declan_at_rm)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 6:14pm UTC](https://discuss.elastic.co/t/logstash-battle-scars-metricbeat-config-and-duplicate-output/261581 "2021-01-19T18:14:47Z")

</div>

Not so much a question but just wanted to share some things to look out for. I should start by saying that overall by experience of ELK is good and I'm certainly sticking with it. Just wanted to share a few details of …

---

## [Azure instance type for logstash](https://discuss.elastic.co/t/azure-instance-type-for-logstash/261580)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 6:05pm UTC](https://discuss.elastic.co/t/azure-instance-type-for-logstash/261580 "2021-01-19T18:05:21Z")

</div>

Any recommendation of Azure instance type for logstash?

---

## [Parse JSON input file, extract fields and write them in output file](https://discuss.elastic.co/t/parse-json-input-file-extract-fields-and-write-them-in-output-file/261543)

<div class="topic-metadata">

**Author:** [@fantonio](https://discuss.elastic.co/u/fantonio)\
**Replies:** 1\
**Last updated:** [January 19, 2021, 4:29pm UTC](https://discuss.elastic.co/t/parse-json-input-file-extract-fields-and-write-them-in-output-file/261543 "2021-01-19T16:29:34Z")

</div>

I have an input file where each line is a JSON object like the following: { "status\_code" =\> "200", "method" =\> "GET", "country" =\> "US", "field" =\> "something", } T…

---

## [Logstash text to array conversion](https://discuss.elastic.co/t/logstash-text-to-array-conversion/261393)

<div class="topic-metadata">

**Author:** [@thotakura2](https://discuss.elastic.co/u/thotakura2)\
**Replies:** 1\
**Last updated:** [January 19, 2021, 3:30pm UTC](https://discuss.elastic.co/t/logstash-text-to-array-conversion/261393 "2021-01-19T15:30:38Z")

</div>

Hi all, I am trying to index data from MySQL and one of the fields is delimited by ; and ,. I want to convert it into array by delimiting it with both the characters. Currently i am using the following filter: filt…

---

## [Logstash fails to start](https://discuss.elastic.co/t/logstash-fails-to-start/261558)

<div class="topic-metadata">

**Author:** [@karthik\_s2](https://discuss.elastic.co/u/karthik_s2)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 2:32pm UTC](https://discuss.elastic.co/t/logstash-fails-to-start/261558 "2021-01-19T14:32:34Z")

</div>

When i tired to start with the command (logstash.bat -f logstash.conf) in the prompt. The below output is written and logstash doesn't start. Using JAVA\_HOME defined java: C:\\Program Files\\Java\\jdk1.8.0\_221; WARNING, …

---

## [Redundancy in logstash for syslog devices](https://discuss.elastic.co/t/redundancy-in-logstash-for-syslog-devices/261557)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 2:32pm UTC](https://discuss.elastic.co/t/redundancy-in-logstash-for-syslog-devices/261557 "2021-01-19T14:32:10Z")

</div>

We are in process of upgrading our ELK stack to 7.6 and i need suggestions on configuration for network devices ( Big IP LTM ) for example. The current config has one logstash IP as syslog server , in an event of failur…

---

## [Custom Plugin in restricted network](https://discuss.elastic.co/t/custom-plugin-in-restricted-network/261556)

<div class="topic-metadata">

**Author:** [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 2:17pm UTC](https://discuss.elastic.co/t/custom-plugin-in-restricted-network/261556 "2021-01-19T14:17:52Z")

</div>

I was trying to write a custom plugin, however when i am trying to build bundle install it is saying unable to connect to online ruby gems. Is there a way to avoid going to the official source of ruby gems, as downloadi…

---

## [Logstash - replace @timestamp](https://discuss.elastic.co/t/logstash-replace-timestamp/261553)

<div class="topic-metadata">

**Author:** [@iccMe](https://discuss.elastic.co/u/iccMe)\
**Replies:** 2\
**Last updated:** [January 19, 2021, 2:16pm UTC](https://discuss.elastic.co/t/logstash-replace-timestamp/261553 "2021-01-19T14:16:49Z")

</div>

Hi, Looking for help with a date and time filter in logstash. I created a new Time field putting together a previous date and time field that I subsequently drop. The new Time field looks like the below in my output: "…

---

## [Logstash doesn't index to elasticsearch properly/delay in indexing](https://discuss.elastic.co/t/logstash-doesnt-index-to-elasticsearch-properly-delay-in-indexing/261536)

<div class="topic-metadata">

**Author:** [@thrower](https://discuss.elastic.co/u/thrower)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 12:02pm UTC](https://discuss.elastic.co/t/logstash-doesnt-index-to-elasticsearch-properly-delay-in-indexing/261536 "2021-01-19T12:02:43Z")

</div>

There is quite a significant delay occurring when there is updation in the database. It takes up to one to half an hour for the change to be reflected in the elasticsearch index. However if I change another product or ch…

---

## [Timezone in UTC causes wrong filename](https://discuss.elastic.co/t/timezone-in-utc-causes-wrong-filename/261480)

<div class="topic-metadata">

**Author:** [@yodog](https://discuss.elastic.co/u/yodog)\
**Replies:** 3\
**Last updated:** [January 19, 2021, 10:23am UTC](https://discuss.elastic.co/t/timezone-in-utc-causes-wrong-filename/261480 "2021-01-19T10:23:23Z")

</div>

i have a logserver with logstash only. no elasticsearch nor kibana. all other servers are using filebeat to send log to the logserver. logstash writes to /var/log/logstash/appname.txt.%{+YYYY-MM-dd} after some processi…

---

## [Select only one field to output](https://discuss.elastic.co/t/select-only-one-field-to-output/261451)

<div class="topic-metadata">

**Author:** [@Finley](https://discuss.elastic.co/u/Finley)\
**Replies:** 0\
**Last updated:** [January 18, 2021, 4:40pm UTC](https://discuss.elastic.co/t/select-only-one-field-to-output/261451 "2021-01-18T16:40:50Z")

</div>

Hello, I'm trying to setup a logstash configuration. I want to forward the event.original field only on the udp output. I have a filebeat input, and elasticsearch/udp output. I tried the "codec line" option with "forma…

---

## [Logstash translate filter](https://discuss.elastic.co/t/logstash-translate-filter/261518)

<div class="topic-metadata">

**Author:** [@vinu89](https://discuss.elastic.co/u/vinu89)\
**Replies:** 0\
**Last updated:** [January 19, 2021, 9:31am UTC](https://discuss.elastic.co/t/logstash-translate-filter/261518 "2021-01-19T09:31:02Z")

</div>

hi, i have a csv file containing malicious domains and category,i want to check whether those domains are comings in my logs and i achieved that using translate field..but i want to extract the particular category also…

---

## [Add tag if SNMP poll reaches its timeout](https://discuss.elastic.co/t/add-tag-if-snmp-poll-reaches-its-timeout/261447)

<div class="topic-metadata">

**Author:** [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Replies:** 1\
**Last updated:** [January 18, 2021, 6:05pm UTC](https://discuss.elastic.co/t/add-tag-if-snmp-poll-reaches-its-timeout/261447 "2021-01-18T18:05:01Z")

</div>

Hello, I have recently started to use the SNMP plugin to poll a few devices and its great the only issue I am having is if the device reaches its timeout Logstash just logs it in its log file and I would like to have it…

---

## [Avoid loggin on a pipeline output](https://discuss.elastic.co/t/avoid-loggin-on-a-pipeline-output/261438)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [January 18, 2021, 2:34pm UTC](https://discuss.elastic.co/t/avoid-loggin-on-a-pipeline-output/261438 "2021-01-18T14:34:39Z")

</div>

Hi, Im getting an error on a pipeline, the error doesnt affect the indexing of the data, but is filling the docker logs, is there a way to avoid this error from being shown? -the output plugin is elasticsearch -I dont …

---

## [Logstash drop unnecessary fields ( ip2location plugin )](https://discuss.elastic.co/t/logstash-drop-unnecessary-fields-ip2location-plugin/259694)

<div class="topic-metadata">

**Author:** [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Replies:** 6\
**Last updated:** [January 18, 2021, 11:42am UTC](https://discuss.elastic.co/t/logstash-drop-unnecessary-fields-ip2location-plugin/259694 "2021-01-18T11:42:46Z")

</div>

Hi, We use ip2locaion database and plugin to detect client's ISP. There are multiple versions of this database with different information but we bought the basic version with only ISP info. How can I prevent logstash t…

---

## [Translate: Unquoted fields do not allow \\r or \\n (line 1)](https://discuss.elastic.co/t/translate-unquoted-fields-do-not-allow-r-or-n-line-1/260904)

<div class="topic-metadata">

**Author:** [@EHE](https://discuss.elastic.co/u/EHE)\
**Replies:** 2\
**Last updated:** [January 18, 2021, 8:31am UTC](https://discuss.elastic.co/t/translate-unquoted-fields-do-not-allow-r-or-n-line-1/260904 "2021-01-18T08:31:01Z")

</div>

Hello, I am struggling with a translation dilemma, I have been researching for hrs for answers, but i havent found the right one for my issue, and i do not know why i am getting this error: Translate: Unquoted fields d…

---

## [Logstash-7.10.0 repositories available for APT doesn't have release file](https://discuss.elastic.co/t/logstash-7-10-0-repositories-available-for-apt-doesnt-have-release-file/261392)

<div class="topic-metadata">

**Author:** [@saroja](https://discuss.elastic.co/u/saroja)\
**Replies:** 0\
**Last updated:** [January 18, 2021, 7:50am UTC](https://discuss.elastic.co/t/logstash-7-10-0-repositories-available-for-apt-doesnt-have-release-file/261392 "2021-01-18T07:50:24Z")

</div>

Hi All, i am unable to install logstash-7.10.0 package from APT repository. To download and install logstash-7.10.0, used the following steps for APT distributions. Download and install the Public Signing Key: $ wg…

---

## [Overwrite an index in logstash](https://discuss.elastic.co/t/overwrite-an-index-in-logstash/261345)

<div class="topic-metadata">

**Author:** [@hallaoui](https://discuss.elastic.co/u/hallaoui)\
**Replies:** 4\
**Last updated:** [January 18, 2021, 7:33am UTC](https://discuss.elastic.co/t/overwrite-an-index-in-logstash/261345 "2021-01-18T07:33:45Z")

</div>

Hi All, I am collecting alarms status from an oracle database every 5 minutes using logstash and load them into an index, the thing is that the remote DB will contain alarms only if the alarms are still open and I would…

---

## [How to print the values or grok expression and the line it is working on and file name and path](https://discuss.elastic.co/t/how-to-print-the-values-or-grok-expression-and-the-line-it-is-working-on-and-file-name-and-path/261385)

<div class="topic-metadata">

**Author:** [@umen](https://discuss.elastic.co/u/umen)\
**Replies:** 0\
**Last updated:** [January 18, 2021, 6:49am UTC](https://discuss.elastic.co/t/how-to-print-the-values-or-grok-expression-and-the-line-it-is-working-on-and-file-name-and-path/261385 "2021-01-18T06:49:39Z")

</div>

i try to find how to print to log the name of the log file and the line the grok expretion is working on right now . here the logstash config : input { s3 { "access\_key\_id" =\> "xxxx" "secret\_acces…

---

## [How to use nginx's host overwrite logstash's host information when send it by filebeat?](https://discuss.elastic.co/t/how-to-use-nginxs-host-overwrite-logstashs-host-information-when-send-it-by-filebeat/261369)

<div class="topic-metadata">

**Author:** [@iooi](https://discuss.elastic.co/u/iooi)\
**Replies:** 0\
**Last updated:** [January 18, 2021, 2:04am UTC](https://discuss.elastic.co/t/how-to-use-nginxs-host-overwrite-logstashs-host-information-when-send-it-by-filebeat/261369 "2021-01-18T02:04:09Z")

</div>

Now using filebeat and logstash sending nginx's json log on k8s. The nginx's configuration likes nginx.conf http { log\_format bucket escape=json '{' '"request\_id": "$request\_id",' '"method": "$…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=261)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=263)
