# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=274

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 275

---

## [Nested key-values parsed with KV](https://discuss.elastic.co/t/nested-key-values-parsed-with-kv/257625)

<div class="topic-metadata">

**Author:** [@Elitlogik](https://discuss.elastic.co/u/Elitlogik)\
**Replies:** 5\
**Last updated:** [December 5, 2020, 11:21pm UTC](https://discuss.elastic.co/t/nested-key-values-parsed-with-kv/257625 "2020-12-05T23:21:36Z")

</div>

KV works great for parsing my input. One key-value, however, looks like this: waninfo="name=wan1,bytes=35911872068/568034814778,packets=135560453/438026267;name=wan2,bytes=0/0,packets=0/0;" I would like to KV-parse th…

---

## [Set all nested fields value into master field](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676)

<div class="topic-metadata">

**Author:** [@Raynald](https://discuss.elastic.co/u/Raynald)\
**Replies:** 3\
**Last updated:** [December 4, 2020, 6:01pm UTC](https://discuss.elastic.co/t/set-all-nested-fields-value-into-master-field/257676 "2020-12-04T18:01:42Z")

</div>

Hi everyone, I have an index that can growth with many nested fileds, and we want to limit nested field to one sub-level for identified fields. But we want to keep value of this nested fields into the master field Exam…

---

## [Cannot display Logstash pipeline in Monitoring UI](https://discuss.elastic.co/t/cannot-display-logstash-pipeline-in-monitoring-ui/256894)

<div class="topic-metadata">

**Author:** [@glenacota](https://discuss.elastic.co/u/glenacota)\
**Replies:** 1\
**Last updated:** [December 4, 2020, 7:01pm UTC](https://discuss.elastic.co/t/cannot-display-logstash-pipeline-in-monitoring-ui/256894 "2020-12-04T19:01:07Z")

</div>

Hi, I've enabled monitoring of my Logstash instance by following the instructions here: Collect Logstash monitoring data with Metricbeatedit. I can see all the collected metrics in the Kibana Stack Monitoring UI, except …

---

## [Duplicates in ES Index](https://discuss.elastic.co/t/duplicates-in-es-index/256736)

<div class="topic-metadata">

**Author:** [@jafri6](https://discuss.elastic.co/u/jafri6)\
**Replies:** 1\
**Last updated:** [December 4, 2020, 5:28pm UTC](https://discuss.elastic.co/t/duplicates-in-es-index/256736 "2020-12-04T17:28:55Z")

</div>

My ELK Stack is running a process which collects logs from 5-6 different PCs. The only issue I am facing at the moment is, my ES index is logging multiple entries for the same timestamp. Any suggestions on how I can fi…

---

## [Logstash](https://discuss.elastic.co/t/logstash/257661)

<div class="topic-metadata">

**Author:** [@bhuvaneswari](https://discuss.elastic.co/u/bhuvaneswari)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 2:12pm UTC](https://discuss.elastic.co/t/logstash/257661 "2020-12-04T14:12:52Z")

</div>

Is there any possibility to add logstash configuration to uberagent configuration file?

---

## [How to filter empty objects in Logstash?](https://discuss.elastic.co/t/how-to-filter-empty-objects-in-logstash/257456)

<div class="topic-metadata">

**Author:** [@ppuschmann](https://discuss.elastic.co/u/ppuschmann)\
**Replies:** 1\
**Last updated:** [December 4, 2020, 4:27pm UTC](https://discuss.elastic.co/t/how-to-filter-empty-objects-in-logstash/257456 "2020-12-04T16:27:30Z")

</div>

Hi, given you get the following access-log: { "container\_id": "b62946591d90f24", "service": "slash", "bytes\_received": 0, "input": {}, "type": "filebeat", "protocol": "HTTP/1.1", "bytes\_sent": 8236, "ho…

---

## [Logstash elasticsearch filter plugin authentication issues](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-authentication-issues/257233)

<div class="topic-metadata">

**Author:** [@Dede\_Pessu](https://discuss.elastic.co/u/Dede_Pessu)\
**Replies:** 2\
**Last updated:** [December 4, 2020, 4:21pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-plugin-authentication-issues/257233 "2020-12-04T16:21:28Z")

</div>

Hey Everyone, I am currently trying to use the elasticsearch filter plugin for logstash to do some calculations/aggregations and it seems to be having issues connecting to our elasticsearch node. based on the documenta…

---

## [Not able to start to logstash due could not find main class Xmx1024m](https://discuss.elastic.co/t/not-able-to-start-to-logstash-due-could-not-find-main-class-xmx1024m/257638)

<div class="topic-metadata">

**Author:** [@Siva\_Munnaluri](https://discuss.elastic.co/u/Siva_Munnaluri)\
**Replies:** 1\
**Last updated:** [December 4, 2020, 2:47pm UTC](https://discuss.elastic.co/t/not-able-to-start-to-logstash-due-could-not-find-main-class-xmx1024m/257638 "2020-12-04T14:47:59Z")

</div>

Getting error as "Error: Could not find or load main class Xmx1024m" when we command "logstash.bat -e 'input {stdin{}} output {stdout{}}'" Logstash version : 7.6.2 Java version : Java 8.0 Please help me on this .

---

## [Ingest-convert.sh getting exception while running the tool](https://discuss.elastic.co/t/ingest-convert-sh-getting-exception-while-running-the-tool/257659)

<div class="topic-metadata">

**Author:** [@anilreddyd](https://discuss.elastic.co/u/anilreddyd)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 2:09pm UTC](https://discuss.elastic.co/t/ingest-convert-sh-getting-exception-while-running-the-tool/257659 "2020-12-04T14:09:21Z")

</div>

I am getting exception while running the ingest-convert tool that converts elastic search parsing json to logstash configuration. Exception in thread "main" javax.script.ScriptException: TypeError: Cannot read property …

---

## [Ingest-convert.sh TypeError](https://discuss.elastic.co/t/ingest-convert-sh-typeerror/256152)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 2\
**Last updated:** [December 4, 2020, 12:55pm UTC](https://discuss.elastic.co/t/ingest-convert-sh-typeerror/256152 "2020-12-04T12:55:33Z")

</div>

I'm trying to convert filebeat-7.10.0-iis-error-pipeline to logstash config with ./ingest-convert.sh --input file:///root/error.json --output file:///root/iss-access.conf I tried with java bundled with logstash 7.10.0 …

---

## [\[ERROR\]\[logstashoutputselasticsearch\] Attempted to send a bulk request to elasticsearch but Elasticsearch appears to be unreachable or down](https://discuss.elastic.co/t/error-logstashoutputselasticsearch-attempted-to-send-a-bulk-request-to-elasticsearch-but-elasticsearch-appears-to-be-unreachable-or-down/257646)

<div class="topic-metadata">

**Author:** [@Cristiane\_Marcarini](https://discuss.elastic.co/u/Cristiane_Marcarini)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 10:25am UTC](https://discuss.elastic.co/t/error-logstashoutputselasticsearch-attempted-to-send-a-bulk-request-to-elasticsearch-but-elasticsearch-appears-to-be-unreachable-or-down/257646 "2020-12-04T10:25:35Z")

</div>

What to do when this appears in the logstash log? \[2020-12-04T09:46:50,568\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Marking url as dead. Last error: \[LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreacha…

---

## [Logstash / Enrich processor event sample rate](https://discuss.elastic.co/t/logstash-enrich-processor-event-sample-rate/257635)

<div class="topic-metadata">

**Author:** [@fran6ssl](https://discuss.elastic.co/u/fran6ssl)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 9:18am UTC](https://discuss.elastic.co/t/logstash-enrich-processor-event-sample-rate/257635 "2020-12-04T09:18:14Z")

</div>

Hi, I have multiple CSVs files with sensors data. Each data file holds the timestamp and the numeric value of the sensor at that time. Each sensor has a different sample rate. For a exemple we have a temperature sensor…

---

## [Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line 1, column 1 (byte 1)](https://discuss.elastic.co/t/expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/257612)

<div class="topic-metadata">

**Author:** [@ZoolYe](https://discuss.elastic.co/u/ZoolYe)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 6:09am UTC](https://discuss.elastic.co/t/expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/257612 "2020-12-04T06:09:10Z")

</div>

docker pull docker.elastic.co/logstash/logstash:7.10.0 docker run --name=logstash-7.10 -v /xxx/logstash.yml:/usr/share/logstash/config/logstash.yml -v /xxx/logstash.conf:/usr/share/logstash/pipeline/logstash.conf -d doc…

---

## [Logstash websocket input](https://discuss.elastic.co/t/logstash-websocket-input/257610)

<div class="topic-metadata">

**Author:** [@wpitt13](https://discuss.elastic.co/u/wpitt13)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 5:27am UTC](https://discuss.elastic.co/t/logstash-websocket-input/257610 "2020-12-04T05:27:10Z")

</div>

Does the Logstash 'websocket' input plugin support authorization using Bearer tokens? I've tried multiple different syntaxes with no luck.

---

## [Duplicate events even after introducing fingerprint](https://discuss.elastic.co/t/duplicate-events-even-after-introducing-fingerprint/256355)

<div class="topic-metadata">

**Author:** [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Replies:** 4\
**Last updated:** [December 4, 2020, 4:53am UTC](https://discuss.elastic.co/t/duplicate-events-even-after-introducing-fingerprint/256355 "2020-12-04T04:53:33Z")

</div>

Hello All , We have a weird issue in ELK . We have introduced fingerprint in logstash , But still we can see the duplicates in Kibana. Kindly help how can we improve this . input { beats { port =\> 5044 tags =\> \["…

---

## [Achieving resilience for logstash database pipeline](https://discuss.elastic.co/t/achieving-resilience-for-logstash-database-pipeline/257607)

<div class="topic-metadata">

**Author:** [@adityaPsl](https://discuss.elastic.co/u/adityaPsl)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 4:41am UTC](https://discuss.elastic.co/t/achieving-resilience-for-logstash-database-pipeline/257607 "2020-12-04T04:41:13Z")

</div>

Hello Team, I am new to docker and just wanted to understand if i can achieve this, I have 3 node cluster and i am running logstash on one node , if that node goes down i want to start logstash on second node with last…

---

## [Accessing the logstash\_sqlite in logstash-input-mongodb plugin](https://discuss.elastic.co/t/accessing-the-logstash-sqlite-in-logstash-input-mongodb-plugin/257606)

<div class="topic-metadata">

**Author:** [@Durga\_AK](https://discuss.elastic.co/u/Durga_AK)\
**Replies:** 0\
**Last updated:** [December 4, 2020, 4:41am UTC](https://discuss.elastic.co/t/accessing-the-logstash-sqlite-in-logstash-input-mongodb-plugin/257606 "2020-12-04T04:41:06Z")

</div>

Hello, Im using the logstash-input-mongodb plugin to ingest data into Elastic Search from MongoDB, using logstash. I would like to know if the logstash\_sqlite can be accessed to know what in the latest \_id and also if t…

---

## [How to Disable SSL Certificate Verification for Logstash-Plugin (installing plugins)](https://discuss.elastic.co/t/how-to-disable-ssl-certificate-verification-for-logstash-plugin-installing-plugins/257590)

<div class="topic-metadata">

**Author:** [@Jeremy\_A](https://discuss.elastic.co/u/Jeremy_A)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 9:44pm UTC](https://discuss.elastic.co/t/how-to-disable-ssl-certificate-verification-for-logstash-plugin-installing-plugins/257590 "2020-12-03T21:44:34Z")

</div>

This is more of an information post than a question, because I noticed several unanswered questions along these lines while searching for a solution myself. The problem occurs when trying to use bin/logstash-plugin to i…

---

## [Upgraded beats (7.10) still writing to old version indices](https://discuss.elastic.co/t/upgraded-beats-7-10-still-writing-to-old-version-indices/257405)

<div class="topic-metadata">

**Author:** [@rgeisman](https://discuss.elastic.co/u/rgeisman)\
**Replies:** 9\
**Last updated:** [December 3, 2020, 6:12pm UTC](https://discuss.elastic.co/t/upgraded-beats-7-10-still-writing-to-old-version-indices/257405 "2020-12-03T18:12:03Z")

</div>

Hello all. A maddening problem. We upgraded our cluster to 7.10 (ES, Logstash, Metricbeat, Auditbeat, Filebeat). Since we use Logstash I manually loaded each index template for the beats and default dashboards, then I …

---

## [Indexing error "Index -1 out of bounds for length 0"](https://discuss.elastic.co/t/indexing-error-index-1-out-of-bounds-for-length-0/257379)

<div class="topic-metadata">

**Author:** [@hKerma](https://discuss.elastic.co/u/hKerma)\
**Replies:** 9\
**Last updated:** [December 3, 2020, 5:51pm UTC](https://discuss.elastic.co/t/indexing-error-index-1-out-of-bounds-for-length-0/257379 "2020-12-03T17:51:55Z")

</div>

Hi everyone, I want to use ELK stack to analyze some Kubernetes audit logs. They're sent to the Logstash webhook as JSON. Here's my config file : input{ http { port =\> 8888 codec =\> "json" type =\> "json" } }…

---

## [Add value to blank field](https://discuss.elastic.co/t/add-value-to-blank-field/257286)

<div class="topic-metadata">

**Author:** [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Replies:** 6\
**Last updated:** [December 3, 2020, 4:56pm UTC](https://discuss.elastic.co/t/add-value-to-blank-field/257286 "2020-12-03T16:56:44Z")

</div>

Hi, I am running with an issue, I have a shipment date column which is having a blank value until your order is not shipped, so if the order is not shipped (you can say it's pending now) i want to add a value to that f…

---

## [Getting aws internal ip when using dns plugin i want to see actual dns name like abc.test.com](https://discuss.elastic.co/t/getting-aws-internal-ip-when-using-dns-plugin-i-want-to-see-actual-dns-name-like-abc-test-com/257455)

<div class="topic-metadata">

**Author:** [@sujeetjha](https://discuss.elastic.co/u/sujeetjha)\
**Replies:** 1\
**Last updated:** [December 3, 2020, 4:35pm UTC](https://discuss.elastic.co/t/getting-aws-internal-ip-when-using-dns-plugin-i-want-to-see-actual-dns-name-like-abc-test-com/257455 "2020-12-03T16:35:46Z")

</div>

Getting AWS internal IP (ip-11-11-11-11-amazon.com) when using DNS plugin I want to see actual DNS name like abc.test.com.. what should I do plz suggest... here is my code below # Beats -\> Logstash -\> Elasticsearch pip…

---

## [How to change date format in logstash?](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/257532)

<div class="topic-metadata">

**Author:** [@reillye](https://discuss.elastic.co/u/reillye)\
**Replies:** 1\
**Last updated:** [December 3, 2020, 4:16pm UTC](https://discuss.elastic.co/t/how-to-change-date-format-in-logstash/257532 "2020-12-03T16:16:29Z")

</div>

My raw data comes in epoch format e.g. 430201865. I can parse this to UNIX using the date filter in logstash like so date { match =\> \["time", "UNIX"\] target =\> "timestamp" remove\_field =\> \["time"\] } This produces…

---

## [Logstash Input Plugin Development with File Input Plugin](https://discuss.elastic.co/t/logstash-input-plugin-development-with-file-input-plugin/257486)

<div class="topic-metadata">

**Author:** [@rknd](https://discuss.elastic.co/u/rknd)\
**Replies:** 1\
**Last updated:** [December 3, 2020, 4:07pm UTC](https://discuss.elastic.co/t/logstash-input-plugin-development-with-file-input-plugin/257486 "2020-12-03T16:07:20Z")

</div>

Hello, I would like to ask, if its possible to pass file input plugin output in a new\_input\_plugin. I mean like output of the file input plugin, will be the input of another input plugin. As an example, Read logs from…

---

## [Logstah reading from elastic daily based index name](https://discuss.elastic.co/t/logstah-reading-from-elastic-daily-based-index-name/257278)

<div class="topic-metadata">

**Author:** [@lecko](https://discuss.elastic.co/u/lecko)\
**Replies:** 4\
**Last updated:** [December 3, 2020, 3:45pm UTC](https://discuss.elastic.co/t/logstah-reading-from-elastic-daily-based-index-name/257278 "2020-12-03T15:45:47Z")

</div>

Hello, I am new to logstash.I I want to get data out of elasticsearch and filter it and send it to some third party sw. With help of examples and docs the first draft seems to work. But the elasticsearch index name i…

---

## [Logstash with multiple input and output](https://discuss.elastic.co/t/logstash-with-multiple-input-and-output/257524)

<div class="topic-metadata">

**Author:** [@ck\_7](https://discuss.elastic.co/u/ck_7)\
**Replies:** 4\
**Last updated:** [December 3, 2020, 3:18pm UTC](https://discuss.elastic.co/t/logstash-with-multiple-input-and-output/257524 "2020-12-03T15:18:56Z")

</div>

Help me to understand the below logstash config. Trying to configure multiples input and output but index shows only one. Here my config: There is no Error: logstash runs but no index name for the storage. only network…

---

## [Receive Authorization Header Logstash Http Input Plugin](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407)

<div class="topic-metadata">

**Author:** [@sai\_kiran1](https://discuss.elastic.co/u/sai_kiran1)\
**Replies:** 4\
**Last updated:** [December 3, 2020, 2:18pm UTC](https://discuss.elastic.co/t/receive-authorization-header-logstash-http-input-plugin/257407 "2020-12-03T14:18:43Z")

</div>

Hi, I am using the HTTP input plugin to receive data from the postman with Basic Auth enabled, "Authorization" header is available in the postman response but when I print the data in logstash I don't see the Authorizat…

---

## [Logstash: error when use date filter](https://discuss.elastic.co/t/logstash-error-when-use-date-filter/257517)

<div class="topic-metadata">

**Author:** [@raistlin2912](https://discuss.elastic.co/u/raistlin2912)\
**Replies:** 1\
**Last updated:** [December 3, 2020, 1:46pm UTC](https://discuss.elastic.co/t/logstash-error-when-use-date-filter/257517 "2020-12-03T13:46:01Z")

</div>

Hi, I'm setting up an ELK Stack to process some logs that are sent to us from AKAMAI. An example line: 2020-11-18 14:58:27 2.17.200.11 - - - - GET /unaurl.es/N3X3QDOPYNHGPO5R6ZYCEOWCNM.png - 200 1 36513 848 1 80 HTTP/1…

---

## [Logstash mutate error for hostname](https://discuss.elastic.co/t/logstash-mutate-error-for-hostname/257474)

<div class="topic-metadata">

**Author:** [@aaron111com](https://discuss.elastic.co/u/aaron111com)\
**Replies:** 3\
**Last updated:** [December 3, 2020, 10:02am UTC](https://discuss.elastic.co/t/logstash-mutate-error-for-hostname/257474 "2020-12-03T10:02:15Z")

</div>

hi I meet a weird problem, I want to parse my hostname is "alexworkstation-alex", I wanna get the string "alexworkstation" , so I split the hostname by "-" . but I can't add\_field . this is follow with official do…

---

## [Logstash got error message "no implicit conversion of nil into String"](https://discuss.elastic.co/t/logstash-got-error-message-no-implicit-conversion-of-nil-into-string/257440)

<div class="topic-metadata">

**Author:** [@algo\_msh](https://discuss.elastic.co/u/algo_msh)\
**Replies:** 0\
**Last updated:** [December 3, 2020, 3:11am UTC](https://discuss.elastic.co/t/logstash-got-error-message-no-implicit-conversion-of-nil-into-string/257440 "2020-12-03T03:11:21Z")

</div>

\[2020-12-03T01:22:03,474\]\[ERROR\]\[logstash.outputs.elasticsearch\] An unknown error occurred sending a bulk request to Elasticsearch. We will retry indefinitely {:error\_message=\>"no implicit conversion of nil into String",…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=273)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=275)
