# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=270

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 271

---

## [Logstash Pipeline issue (I'm an idiot or something)](https://discuss.elastic.co/t/logstash-pipeline-issue-im-an-idiot-or-something/259042)

<div class="topic-metadata">

**Author:** [@SigmazGFX](https://discuss.elastic.co/u/SigmazGFX)\
**Replies:** 4\
**Last updated:** [December 18, 2020, 1:15am UTC](https://discuss.elastic.co/t/logstash-pipeline-issue-im-an-idiot-or-something/259042 "2020-12-18T01:15:15Z")

</div>

Hey gang. I am working with our dev team and they are dumping custom logging into the windows events Using winlogbeat to ship the log entries into logstash i am trying to set up a central pipeline to handle the differen…

---

## [Convert String to date format](https://discuss.elastic.co/t/convert-string-to-date-format/258899)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 25\
**Last updated:** [December 17, 2020, 9:29pm UTC](https://discuss.elastic.co/t/convert-string-to-date-format/258899 "2020-12-17T21:29:12Z")

</div>

Hi All, I am using ELK7.6.2 Trying to convert "createdTime" field from String to date format. Added following filter in my logstash config file: date { match =\> \["createdTime", "YYYY-MM-dd HH:mm:ss.SSS"\] target =\> "cr…

---

## [Logstash 7.10 Error](https://discuss.elastic.co/t/logstash-7-10-error/259022)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 2\
**Last updated:** [December 17, 2020, 7:23pm UTC](https://discuss.elastic.co/t/logstash-7-10-error/259022 "2020-12-17T19:23:46Z")

</div>

I' ve installed last version of Logstash and gives me this error for ingested pipelines: \[ERROR\]\[logstash.outputs.elasticsearch\]\[main\]\[....\] Encountered a retryable error. Will Retry with exponential backoff {:code=\>40…

---

## [Adding new field based on AND Condition](https://discuss.elastic.co/t/adding-new-field-based-on-and-condition/259010)

<div class="topic-metadata">

**Author:** [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Replies:** 3\
**Last updated:** [December 17, 2020, 6:19pm UTC](https://discuss.elastic.co/t/adding-new-field-based-on-and-condition/259010 "2020-12-17T18:19:19Z")

</div>

Hi have below coloumns columns =\> \[ "Order Key","Cust #","Doc Type","Doc #","Order #","Order Type","Order Complete?","Order Date","Total Order Value","Total Dollar Value","TotalOrderReceivedToday","Inv #","Inv Date","Ex…

---

## [Split Json, transform result](https://discuss.elastic.co/t/split-json-transform-result/259019)

<div class="topic-metadata">

**Author:** [@Jose92](https://discuss.elastic.co/u/Jose92)\
**Replies:** 1\
**Last updated:** [December 17, 2020, 6:13pm UTC](https://discuss.elastic.co/t/split-json-transform-result/259019 "2020-12-17T18:13:27Z")

</div>

Bonjour, je me permets de vous contacter pour avoir de l'aide sur une configuration avec logstash. Je tourne en rond depuis plusieurs jours.... Mon json ressemble à ça : ... "inventaire": { "Applicatio…

---

## [Logstash to Ingest nodes](https://discuss.elastic.co/t/logstash-to-ingest-nodes/258925)

<div class="topic-metadata">

**Author:** [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Replies:** 7\
**Last updated:** [December 17, 2020, 6:02pm UTC](https://discuss.elastic.co/t/logstash-to-ingest-nodes/258925 "2020-12-17T18:02:33Z")

</div>

In Logstash under the pipeline directory there will be multiple .conf files that set specific grok filters. The format of the files are as follows: Input Grok Filter Output \[list of nodes\] For that Output section do …

---

## [Imap input plugin download attachment](https://discuss.elastic.co/t/imap-input-plugin-download-attachment/258966)

<div class="topic-metadata">

**Author:** [@Aditya\_Srivastava1](https://discuss.elastic.co/u/Aditya_Srivastava1)\
**Replies:** 8\
**Last updated:** [December 17, 2020, 5:30pm UTC](https://discuss.elastic.co/t/imap-input-plugin-download-attachment/258966 "2020-12-17T17:30:51Z")

</div>

Hi, I am using imap input plugin to fetch email along with attachments. Below configuration gets me multiple fields but does not get the attachment content. Can anyone help here how to download attachments while connec…

---

## [Logstash crash with FATAL error](https://discuss.elastic.co/t/logstash-crash-with-fatal-error/258919)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 7\
**Last updated:** [December 17, 2020, 4:50pm UTC](https://discuss.elastic.co/t/logstash-crash-with-fatal-error/258919 "2020-12-17T16:50:08Z")

</div>

something in either my data or my logstash is killing logstash with following error. I have try this multiple time but I can't figure out what record does it gets kill on. how do I do the debug on this one? I am runni…

---

## [Parsing issue in Logstash grok](https://discuss.elastic.co/t/parsing-issue-in-logstash-grok/258717)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 4\
**Last updated:** [December 17, 2020, 2:27pm UTC](https://discuss.elastic.co/t/parsing-issue-in-logstash-grok/258717 "2020-12-17T14:27:06Z")

</div>

I am having a grok issue. I have a log like below Login Success \[user: jsaver\] \[Source: 10.110.20.58\] How can I parse the this log with grok filter ?

---

## [Can hour and minute be appended to index name?](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830)

<div class="topic-metadata">

**Author:** [@danibe](https://discuss.elastic.co/u/danibe)\
**Replies:** 4\
**Last updated:** [December 17, 2020, 2:16pm UTC](https://discuss.elastic.co/t/can-hour-and-minute-be-appended-to-index-name/258830 "2020-12-17T14:16:39Z")

</div>

I am trying to create index names with minute resolution since I am still experimenting with ELK and would like to see the effect of various changes in my logstash filter, without having to delete an existing filter (and…

---

## [Logstash translate doesn't work](https://discuss.elastic.co/t/logstash-translate-doesnt-work/258249)

<div class="topic-metadata">

**Author:** [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Replies:** 3\
**Last updated:** [December 17, 2020, 12:33pm UTC](https://discuss.elastic.co/t/logstash-translate-doesnt-work/258249 "2020-12-17T12:33:56Z")

</div>

Hello, I have the following code: input { file { path =\> "/home/path/files/\*.csv" start\_position =\> "beginning" } } filter { csv { columns =\> \[ "xx1","xx2","xx3","xx4","Response","TimeStamp",…

---

## [Logstash not working when started via systemctl, however it work when manually starting](https://discuss.elastic.co/t/logstash-not-working-when-started-via-systemctl-however-it-work-when-manually-starting/258973)

<div class="topic-metadata">

**Author:** [@baljka](https://discuss.elastic.co/u/baljka)\
**Replies:** 0\
**Last updated:** [December 17, 2020, 10:20am UTC](https://discuss.elastic.co/t/logstash-not-working-when-started-via-systemctl-however-it-work-when-manually-starting/258973 "2020-12-17T10:20:39Z")

</div>

Hello, Everything was working fine. However it suddenly stopped working. Now when I try running command "/usr/share/logstash/bin/logstash --path.settings /etc/logstash" manually, it works fine When I run command "syst…

---

## [Autogenerating field names from csv headers](https://discuss.elastic.co/t/autogenerating-field-names-from-csv-headers/258638)

<div class="topic-metadata">

**Author:** [@toucan](https://discuss.elastic.co/u/toucan)\
**Replies:** 4\
**Last updated:** [December 17, 2020, 9:27am UTC](https://discuss.elastic.co/t/autogenerating-field-names-from-csv-headers/258638 "2020-12-17T09:27:07Z")

</div>

Hi, I'm trying to parse CSV files with Logstash. Some of the files have a column called time, others have two columns called time\_from and time\_to (and they have several other columns). Ideally I'd like to have one pipe…

---

## [Logstash error: Java::JavaLang::NoClassDefFoundError: javax/xml/bind/DatatypeConverter](https://discuss.elastic.co/t/logstash-error-java-javax-xml-bind-datatypeconverter/258920)

<div class="topic-metadata">

**Author:** [@streible](https://discuss.elastic.co/u/streible)\
**Replies:** 0\
**Last updated:** [December 16, 2020, 10:24pm UTC](https://discuss.elastic.co/t/logstash-error-java-javax-xml-bind-datatypeconverter/258920 "2020-12-16T22:24:50Z")

</div>

Hi everyone, I'm hoping someone can lend a hand or give some guidance. I have recently installed Elasticsearch on Ubuntu 20.04 and have most everything up and running. I am working with SQL Server 2019 on a remote mac…

---

## [Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create\<main\>, action\_result: false", :backtrace=\>nil}](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/258909)

<div class="topic-metadata">

**Author:** [@velu](https://discuss.elastic.co/u/velu)\
**Replies:** 1\
**Last updated:** [December 16, 2020, 10:01pm UTC](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/258909 "2020-12-16T22:01:49Z")

</div>

Hi , Please help me how to resolve the below issue. 2020-12-16 18:47:47 ERROR agent:123 - Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action:…

---

## [Can you have multiple actions in one single mutate block?](https://discuss.elastic.co/t/can-you-have-multiple-actions-in-one-single-mutate-block/258913)

<div class="topic-metadata">

**Author:** [@nnet](https://discuss.elastic.co/u/nnet)\
**Replies:** 2\
**Last updated:** [December 16, 2020, 9:10pm UTC](https://discuss.elastic.co/t/can-you-have-multiple-actions-in-one-single-mutate-block/258913 "2020-12-16T21:10:15Z")

</div>

Can you have multiple actions in one single mutate block or do you need a mutate block for each: mutate { copy =\> { "server\_name" =\> "syslog\_hostname" } replace =\> { "syslog\_program" =\> "\_geoip\_lookup\_failure" } } o…

---

## [Logstash configuration](https://discuss.elastic.co/t/logstash-configuration/258914)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 0\
**Last updated:** [December 16, 2020, 8:51pm UTC](https://discuss.elastic.co/t/logstash-configuration/258914 "2020-12-16T20:51:00Z")

</div>

Hi! I've installed Logstash on my Kali platform and, as it says on official site, path.settings value should be "/etc/logstash/", but when I want to use keystores I receive an error which says that I need to put my file…

---

## [Logstash - configuring pipeline.workers for input stage](https://discuss.elastic.co/t/logstash-configuring-pipeline-workers-for-input-stage/258900)

<div class="topic-metadata">

**Author:** [@nages](https://discuss.elastic.co/u/nages)\
**Replies:** 1\
**Last updated:** [December 16, 2020, 7:47pm UTC](https://discuss.elastic.co/t/logstash-configuring-pipeline-workers-for-input-stage/258900 "2020-12-16T19:47:47Z")

</div>

It seems that pipeline.workers allows to configure worker threads for filter and output stage. -w, --pipeline.workers COUNT Sets the number of pipeline workers to run. This option sets the number of workers that will,…

---

## [Logstash is periodically hanging (unresponsive) and not sending anything to ES. How to recognize and fix?](https://discuss.elastic.co/t/logstash-is-periodically-hanging-unresponsive-and-not-sending-anything-to-es-how-to-recognize-and-fix/258896)

<div class="topic-metadata">

**Author:** [@user2416](https://discuss.elastic.co/u/user2416)\
**Replies:** 0\
**Last updated:** [December 16, 2020, 5:10pm UTC](https://discuss.elastic.co/t/logstash-is-periodically-hanging-unresponsive-and-not-sending-anything-to-es-how-to-recognize-and-fix/258896 "2020-12-16T17:10:06Z")

</div>

We are running logstash on Kubernetes. And some logstash Pods stops inserting data into ES for some unknown reason periodically (once in 2-7 days) And logstash does not indicate there's something wrong with it. I mean t…

---

## [Not able to connect to DB2 using JDBC\_Static Pluginwith securityMechanism=13](https://discuss.elastic.co/t/not-able-to-connect-to-db2-using-jdbc-static-pluginwith-securitymechanism-13/258807)

<div class="topic-metadata">

**Author:** [@tgkumarmca](https://discuss.elastic.co/u/tgkumarmca)\
**Replies:** 1\
**Last updated:** [December 16, 2020, 4:27pm UTC](https://discuss.elastic.co/t/not-able-to-connect-to-db2-using-jdbc-static-pluginwith-securitymechanism-13/258807 "2020-12-16T16:27:11Z")

</div>

Hi All, I'm trying to connect to the DB2 database where the security mechanism was configured as 13 using the JDBC\_Static plugin. I have tried passing the JDBC Connection as following ways. However, I don't have any luc…

---

## [Positive lookahead not working](https://discuss.elastic.co/t/positive-lookahead-not-working/258752)

<div class="topic-metadata">

**Author:** [@Muhammad\_Faisal](https://discuss.elastic.co/u/Muhammad_Faisal)\
**Replies:** 3\
**Last updated:** [December 16, 2020, 4:10pm UTC](https://discuss.elastic.co/t/positive-lookahead-not-working/258752 "2020-12-16T16:10:15Z")

</div>

hi guys, i want to return or get output 40:123 , whereas input is 40$:123 ---- want to use lookahead , but it always return in output if i use below...any idea, need to used lookahead $ is must in named capture. inpu…

---

## [Runing 2 different logstash config at the same time](https://discuss.elastic.co/t/runing-2-different-logstash-config-at-the-same-time/258889)

<div class="topic-metadata">

**Author:** [@Arezki76](https://discuss.elastic.co/u/Arezki76)\
**Replies:** 0\
**Last updated:** [December 16, 2020, 3:50pm UTC](https://discuss.elastic.co/t/runing-2-different-logstash-config-at-the-same-time/258889 "2020-12-16T15:50:26Z")

</div>

Hi, I have 2 different config files, one to track logs files, and another to interact with DB to build a dashboard. I want to start logstash for these 2 config files, to generates 2 differents indices. Can someone tel…

---

## [How to parse the mod security log.. plz help](https://discuss.elastic.co/t/how-to-parse-the-mod-security-log-plz-help/258869)

<div class="topic-metadata">

**Author:** [@sujeetjha](https://discuss.elastic.co/u/sujeetjha)\
**Replies:** 0\
**Last updated:** [December 16, 2020, 1:58pm UTC](https://discuss.elastic.co/t/how-to-parse-the-mod-security-log-plz-help/258869 "2020-12-16T13:58:38Z")

</div>

hey i want to parse mod\_security log using logstash. when i have checked the logstash it is working fine. logstash.service - logstash Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: en…

---

## [Unable to convert string/text fields to integer](https://discuss.elastic.co/t/unable-to-convert-string-text-fields-to-integer/258788)

<div class="topic-metadata">

**Author:** [@Mauro\_Tridici](https://discuss.elastic.co/u/Mauro_Tridici)\
**Replies:** 0\
**Last updated:** [December 15, 2020, 10:25pm UTC](https://discuss.elastic.co/t/unable-to-convert-string-text-fields-to-integer/258788 "2020-12-15T22:25:17Z")

</div>

Dear All, two days ago I started using "Logstash exec plugin" to launch a bash script and save provided information in elasticsearch. At this moment, it seems working as expected, but I'm not able to convert "quota" an…

---

## [Logstash pipelines taking longer duration to start](https://discuss.elastic.co/t/logstash-pipelines-taking-longer-duration-to-start/258776)

<div class="topic-metadata">

**Author:** [@Sreekanth3](https://discuss.elastic.co/u/Sreekanth3)\
**Replies:** 2\
**Last updated:** [December 16, 2020, 11:38am UTC](https://discuss.elastic.co/t/logstash-pipelines-taking-longer-duration-to-start/258776 "2020-12-16T11:38:03Z")

</div>

Hi all, I am using a logstash with 8 pipelines and if restart the logstash it is taking around 45 minutes to get started and bound to 9600 port. The logstash version is 7.7.0 . I'm looking to optimize the logstash to …

---

## [Logstash is not working - mutate,remove\_field](https://discuss.elastic.co/t/logstash-is-not-working-mutate-remove-field/258852)

<div class="topic-metadata">

**Author:** [@KyungJin\_Joo](https://discuss.elastic.co/u/KyungJin_Joo)\
**Replies:** 0\
**Last updated:** [December 16, 2020, 11:10am UTC](https://discuss.elastic.co/t/logstash-is-not-working-mutate-remove-field/258852 "2020-12-16T11:10:59Z")

</div>

winlogbeat-my computer logstash-(GCP Compute Engine) Winlogbeat sends sysmon field from logstash. Filtering is as follows, It was written in a format that maps the ProcessCreate event. However, writing this way work…

---

## [Logstash: regex to get part of file name](https://discuss.elastic.co/t/logstash-regex-to-get-part-of-file-name/258673)

<div class="topic-metadata">

**Author:** [@nameisnotimportant](https://discuss.elastic.co/u/nameisnotimportant)\
**Replies:** 2\
**Last updated:** [December 16, 2020, 12:39am UTC](https://discuss.elastic.co/t/logstash-regex-to-get-part-of-file-name/258673 "2020-12-16T00:39:52Z")

</div>

Hi, I am trying to get the date in the file name using following regex, but it still return a-zA-Z character: Path: /home/appadmin/Documents/ML/data/pocket\_pmo/activityLogs20201211.csv grok { match =\> { "path" =\> "(…

---

## [Date parse error](https://discuss.elastic.co/t/date-parse-error/258106)

<div class="topic-metadata">

**Author:** [@Muhammad\_Faisal](https://discuss.elastic.co/u/Muhammad_Faisal)\
**Replies:** 4\
**Last updated:** [December 15, 2020, 6:37pm UTC](https://discuss.elastic.co/t/date-parse-error/258106 "2020-12-15T18:37:13Z")

</div>

hi guys, can you assist why below does not parse input data coming as Wed Dec 02 11:11:03 Asia/Riyadh 2020 date { match =\> \[ "Timestamp", "EEE MMM dd HH:mm:ss ZZZ yyyy"\] target =\> "@timestamp" }

---

## [Want to try my logstash Pipeline Testing UI?](https://discuss.elastic.co/t/want-to-try-my-logstash-pipeline-testing-ui/258640)

<div class="topic-metadata">

**Author:** [@epacke](https://discuss.elastic.co/u/epacke)\
**Replies:** 2\
**Last updated:** [December 15, 2020, 5:23pm UTC](https://discuss.elastic.co/t/want-to-try-my-logstash-pipeline-testing-ui/258640 "2020-12-15T17:23:17Z")

</div>

Hi there! Rewritten the pipeline testing tool using React and typescript to improve the UX and usability and would appreciate some feedback. It's a tool using NodeJs, Logstash and docker-compose for my colleagues that …

---

## [Logstash aggregate function](https://discuss.elastic.co/t/logstash-aggregate-function/258738)

<div class="topic-metadata">

**Author:** [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Replies:** 0\
**Last updated:** [December 15, 2020, 4:09pm UTC](https://discuss.elastic.co/t/logstash-aggregate-function/258738 "2020-12-15T16:09:54Z")

</div>

I am looking for aggregate function to get sum of field(TotalOrderReceivedToday) in a new field (sum). but i think it's aggregating everything based on TotalOrderReceivedToday field, I need sum of one field only to { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=269)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=271)
