# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=3

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 4

---

## [Regarding Logstash file output settings](https://discuss.elastic.co/t/regarding-logstash-file-output-settings/382428)

<div class="topic-metadata">

**Author:** [@sysrq\_1231](https://discuss.elastic.co/u/sysrq_1231)\
**Replies:** 5\
**Last updated:** [October 7, 2025, 9:20am UTC](https://discuss.elastic.co/t/regarding-logstash-file-output-settings/382428 "2025-10-07T09:20:16Z")

</div>

Hi Can you tell me about file archiving settings in Logstash? I'm creating a pipeline configuration file as shown below. With this configuration, no file (~.log) is output. What could be the cause? Also, what should …

---

## [Logstash Question - Change snmp trap default port (1062 -\> 162)](https://discuss.elastic.co/t/logstash-question-change-snmp-trap-default-port-1062-162/382423)

<div class="topic-metadata">

**Author:** [@Tal1](https://discuss.elastic.co/u/Tal1)\
**Replies:** 4\
**Last updated:** [October 5, 2025, 10:06pm UTC](https://discuss.elastic.co/t/logstash-question-change-snmp-trap-default-port-1062-162/382423 "2025-10-05T22:06:17Z")

</div>

Hello, I’m new here, and i hope the solution will come from here :slight\_smile: I’ve installed logstash 9.1.4 on my linux server (redhat 9.5) and i’m trying to change the logstash snmptrap listener from 1062 to 162 (wh…

---

## [Reading files from ZIP folder using logstash](https://discuss.elastic.co/t/reading-files-from-zip-folder-using-logstash/382345)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 5\
**Last updated:** [October 3, 2025, 12:23pm UTC](https://discuss.elastic.co/t/reading-files-from-zip-folder-using-logstash/382345 "2025-10-03T12:23:30Z")

</div>

Hi Team, I wanted to read the files from a zipped folder on the server is it possible to read them using logstash. If yes could you please let me know the procedure. Logstash version: 8.18.1

---

## [Repeating the Same Directive inside mutate](https://discuss.elastic.co/t/repeating-the-same-directive-inside-mutate/382385)

<div class="topic-metadata">

**Author:** [@Evan2](https://discuss.elastic.co/u/Evan2)\
**Replies:** 1\
**Last updated:** [October 3, 2025, 12:37am UTC](https://discuss.elastic.co/t/repeating-the-same-directive-inside-mutate/382385 "2025-10-03T00:37:57Z")

</div>

I’ve been given the below advice from our Copilot instance. Can you please confirm its authenticity? I have a few Logstash pipelines using multiple remove\_field directives and need to know if I should instead be using m…

---

## [CEF codec unable to set dynamic fields](https://discuss.elastic.co/t/cef-codec-unable-to-set-dynamic-fields/382182)

<div class="topic-metadata">

**Author:** [@wanglin](https://discuss.elastic.co/u/wanglin)\
**Replies:** 1\
**Last updated:** [September 24, 2025, 2:00pm UTC](https://discuss.elastic.co/t/cef-codec-unable-to-set-dynamic-fields/382182 "2025-09-24T14:00:51Z")

</div>

I am using the Logstash CEF Output plugin and wish to add fields dyanmically. Below is my sample code: output { udp { port =\> 514 codec =\> cef { ... fields =\> \["cef\_fields"\] } } } I populate…

---

## [Logstash error after upgrade (of ElasticSearch, Kibana and Logstash) from 7.16.3 to 7.17.29](https://discuss.elastic.co/t/logstash-error-after-upgrade-of-elasticsearch-kibana-and-logstash-from-7-16-3-to-7-17-29/382158)

<div class="topic-metadata">

**Author:** [@milligal\_capita](https://discuss.elastic.co/u/milligal_capita)\
**Replies:** 3\
**Last updated:** [September 24, 2025, 9:29am UTC](https://discuss.elastic.co/t/logstash-error-after-upgrade-of-elasticsearch-kibana-and-logstash-from-7-16-3-to-7-17-29/382158 "2025-09-24T09:29:00Z")

</div>

No log ingestion. Logstash wont stay up. Error in logs: \[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<Grok::PatternError: pattern %{DATAINBRACKETS:log\_date} not defined\>, …

---

## [Apache Access logs not appearing in Elasticsearch/Kibana](https://discuss.elastic.co/t/apache-access-logs-not-appearing-in-elasticsearch-kibana/382089)

<div class="topic-metadata">

**Author:** [@mcairney](https://discuss.elastic.co/u/mcairney)\
**Replies:** 7\
**Last updated:** [September 23, 2025, 9:30am UTC](https://discuss.elastic.co/t/apache-access-logs-not-appearing-in-elasticsearch-kibana/382089 "2025-09-23T09:30:20Z")

</div>

Hi, We’ve been successfully ingesting our Apache logs however as of around 2 weeks ago the access logs have stopped appearing however the error logs are still showing up in ES/Kibana. We did upgrade from 8.19.2 to 8.19.…

---

## [Logstash is failing with syntax error](https://discuss.elastic.co/t/logstash-is-failing-with-syntax-error/382073)

<div class="topic-metadata">

**Author:** [@piyush\_hn](https://discuss.elastic.co/u/piyush_hn)\
**Replies:** 3\
**Last updated:** [September 19, 2025, 5:18pm UTC](https://discuss.elastic.co/t/logstash-is-failing-with-syntax-error/382073 "2025-09-19T17:18:36Z")

</div>

Hi All, Please advise on the below error, w.r.t the .conf file. \[2025-09-19T07:11:21,135\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :except…

---

## [Syslog filters](https://discuss.elastic.co/t/syslog-filters/382067)

<div class="topic-metadata">

**Author:** [@Contact](https://discuss.elastic.co/u/Contact)\
**Replies:** 2\
**Last updated:** [September 19, 2025, 2:22pm UTC](https://discuss.elastic.co/t/syslog-filters/382067 "2025-09-19T14:22:45Z")

</div>

Hi there, I want to capture Server: IPv4 information for log corellation. I’m receiving syslog messages from(cisco) in the below format: @timestamp: "2025-09-18T00:49:35.275360534Z" dataSource: "89.115.123.60" dataType…

---

## [High-Speed Log Events Not Fully Captured by Logstash File Input](https://discuss.elastic.co/t/high-speed-log-events-not-fully-captured-by-logstash-file-input/381987)

<div class="topic-metadata">

**Author:** [@jeanpierremq](https://discuss.elastic.co/u/jeanpierremq)\
**Replies:** 1\
**Last updated:** [September 16, 2025, 4:18pm UTC](https://discuss.elastic.co/t/high-speed-log-events-not-fully-captured-by-logstash-file-input/381987 "2025-09-16T16:18:44Z")

</div>

file { path =\> "/mnt/efs-logstash/application-logs/log\_workers/production\_\*.log" start\_position =\> "beginning" sincedb\_path =\> "/var/lib/logstash/sincedb\_logger" type =\> "json" stat\_interval =\> "200…

---

## [Logstash.yml file shows syntax error](https://discuss.elastic.co/t/logstash-yml-file-shows-syntax-error/381971)

<div class="topic-metadata">

**Author:** [@piyush\_hn](https://discuss.elastic.co/u/piyush_hn)\
**Replies:** 2\
**Last updated:** [September 16, 2025, 1:34pm UTC](https://discuss.elastic.co/t/logstash-yml-file-shows-syntax-error/381971 "2025-09-16T13:34:09Z")

</div>

Hi All, I am trying to setup logstash in a container but getting an error like below, can someone please help what is wrong here ?. Older version of logstash was not having any issues for “http.host”, something changed …

---

## [Sentinelone parsing Issue](https://discuss.elastic.co/t/sentinelone-parsing-issue/381897)

<div class="topic-metadata">

**Author:** [@Mahesh\_Loke](https://discuss.elastic.co/u/Mahesh_Loke)\
**Replies:** 2\
**Last updated:** [September 15, 2025, 12:20pm UTC](https://discuss.elastic.co/t/sentinelone-parsing-issue/381897 "2025-09-15T12:20:02Z")

</div>

I have integrated sentinelone with elk via logstash, logs are coming but unparsed

---

## [The incoming data is intermittent](https://discuss.elastic.co/t/the-incoming-data-is-intermittent/381898)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 4\
**Last updated:** [September 14, 2025, 2:38pm UTC](https://discuss.elastic.co/t/the-incoming-data-is-intermittent/381898 "2025-09-14T14:38:22Z")

</div>

I have a Logstash setup with 4 nodes that collects logs from several OpenShift (OCP) clusters. However, all of the logs from these OCP clusters use the same pipeline. Lately, the logs have been coming in intermittently (…

---

## [Logstash unable to reach Elasticsearch](https://discuss.elastic.co/t/logstash-unable-to-reach-elasticsearch/381852)

<div class="topic-metadata">

**Author:** [@piyush\_hn](https://discuss.elastic.co/u/piyush_hn)\
**Replies:** 5\
**Last updated:** [September 13, 2025, 5:35pm UTC](https://discuss.elastic.co/t/logstash-unable-to-reach-elasticsearch/381852 "2025-09-13T17:35:56Z")

</div>

Hi All, I am new to elastic stack and set it up on two instances on AWS. My main objective of this demonstration is to show that we can forward the application/machine logs to kibana dashboard. One EC2 instance is ru…

---

## [Filebeat logs reaching Logstash but failing to create visible indices in Kibana](https://discuss.elastic.co/t/filebeat-logs-reaching-logstash-but-failing-to-create-visible-indices-in-kibana/381801)

<div class="topic-metadata">

**Author:** [@Jasser\_Hach](https://discuss.elastic.co/u/Jasser_Hach)\
**Replies:** 0\
**Last updated:** [September 9, 2025, 1:30pm UTC](https://discuss.elastic.co/t/filebeat-logs-reaching-logstash-but-failing-to-create-visible-indices-in-kibana/381801 "2025-09-09T13:30:47Z")

</div>

Logstash successfully receives logs from Filebeat. However, no index is visible in Kibana when using the custom index + pipeline block. If I remove this block: index =\> "%{\[@metadata\]\[beat\]}-%{\[@metadata\]\[version\]}-%{+…

---

## [Warning in Logstash log after fresh start](https://discuss.elastic.co/t/warning-in-logstash-log-after-fresh-start/381764)

<div class="topic-metadata">

**Author:** [@LHozzan](https://discuss.elastic.co/u/LHozzan)\
**Replies:** 2\
**Last updated:** [September 9, 2025, 9:28am UTC](https://discuss.elastic.co/t/warning-in-logstash-log-after-fresh-start/381764 "2025-09-09T09:28:27Z")

</div>

Hi there. I working on upgrade to newer Logstash version (9.1.3) from oldest used one (8.9.0). It seems, that now it is working correctly, but I am struggling with some warning messages: \[2025-09-08T13:33:55,354\]\[WARN …

---

## [Logstash Kafka output - Event Hub Namespace limit results in "UNKNOWN\_TOPIC\_OR\_PARTITION" errors](https://discuss.elastic.co/t/logstash-kafka-output-event-hub-namespace-limit-results-in-unknown-topic-or-partition-errors/381562)

<div class="topic-metadata">

**Author:** [@ncallens](https://discuss.elastic.co/u/ncallens)\
**Replies:** 4\
**Last updated:** [September 8, 2025, 1:31pm UTC](https://discuss.elastic.co/t/logstash-kafka-output-event-hub-namespace-limit-results-in-unknown-topic-or-partition-errors/381562 "2025-09-08T13:31:06Z")

</div>

Dear Logstash enthousiasts, I run a cluster of 4 Logstash servers (v8.14) with about 10 Logstash pipelines per node. I use keepalived as VIP failover method. So all 4 nodes have the same 10 Logstash pipelines configured…

---

## [I need some help to parse the attached xml in Logstash using a ruby filter](https://discuss.elastic.co/t/i-need-some-help-to-parse-the-attached-xml-in-logstash-using-a-ruby-filter/381620)

<div class="topic-metadata">

**Author:** [@lester\_slee](https://discuss.elastic.co/u/lester_slee)\
**Replies:** 2\
**Last updated:** [September 8, 2025, 2:51am UTC](https://discuss.elastic.co/t/i-need-some-help-to-parse-the-attached-xml-in-logstash-using-a-ruby-filter/381620 "2025-09-08T02:51:34Z")

</div>

I have xml being received in to logstash via an http input and the message can contain one or more documents that need to be indexed separately which is ok. The part I need help with is the within each document there are…

---

## [Logstash Pod JVM Usage is almost 100% after 7.17.x to 8.18.x upgrade](https://discuss.elastic.co/t/logstash-pod-jvm-usage-is-almost-100-after-7-17-x-to-8-18-x-upgrade/381566)

<div class="topic-metadata">

**Author:** [@srinivas974](https://discuss.elastic.co/u/srinivas974)\
**Replies:** 0\
**Last updated:** [September 3, 2025, 12:04pm UTC](https://discuss.elastic.co/t/logstash-pod-jvm-usage-is-almost-100-after-7-17-x-to-8-18-x-upgrade/381566 "2025-09-03T12:04:32Z")

</div>

Using logstash 8.18.14 We are running logstash on Dev and QA environments with the same version and we observed JVM usage of almost 100%. We process approximately 3000 logs/sec and of size ~1.5KB. Here are the logstash…

---

## [Array field doesn't get split](https://discuss.elastic.co/t/array-field-doesnt-get-split/381332)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 3\
**Last updated:** [September 2, 2025, 7:19am UTC](https://discuss.elastic.co/t/array-field-doesnt-get-split/381332 "2025-09-02T07:19:08Z")

</div>

hi there, i’m facing a strange issue right now. In my Logstash pipeline, I applied a Grok filter to the raw message and generated a field named responseBody from it. the second filter, I use a JSON filter to parse resp…

---

## [Read logfile once, insert two events to elastic](https://discuss.elastic.co/t/read-logfile-once-insert-two-events-to-elastic/381158)

<div class="topic-metadata">

**Author:** [@nilsen](https://discuss.elastic.co/u/nilsen)\
**Replies:** 7\
**Last updated:** [August 28, 2025, 2:39pm UTC](https://discuss.elastic.co/t/read-logfile-once-insert-two-events-to-elastic/381158 "2025-08-28T14:39:08Z")

</div>

Hello, I have a scenario where I read a log file and want to insert two entries to elastic. Basic example: ▶ Dummy log ▶ Example events created I created two Logstash .conf files reading the same log file. But am I corre…

---

## [Split grok-pattern into multiple lines](https://discuss.elastic.co/t/split-grok-pattern-into-multiple-lines/381366)

<div class="topic-metadata">

**Author:** [@sthorn](https://discuss.elastic.co/u/sthorn)\
**Replies:** 11\
**Last updated:** [August 28, 2025, 12:47pm UTC](https://discuss.elastic.co/t/split-grok-pattern-into-multiple-lines/381366 "2025-08-28T12:47:18Z")

</div>

Hi, Is it possible to split a grok-pattern into multiple lines instead of have one big? grok { pattern\_definitions =\> { "CM" =\> "\[/.\\-\\w\\s\]\*" } match =\> {"syslog\_message" =\> "%{CM:unknown\_id} %{IP:this\_ip},%{…

---

## [Logstash 8.15.2 Imap Input plugin SSL Error](https://discuss.elastic.co/t/logstash-8-15-2-imap-input-plugin-ssl-error/381315)

<div class="topic-metadata">

**Author:** [@carellevbt](https://discuss.elastic.co/u/carellevbt)\
**Replies:** 3\
**Last updated:** [August 25, 2025, 3:50pm UTC](https://discuss.elastic.co/t/logstash-8-15-2-imap-input-plugin-ssl-error/381315 "2025-08-25T15:50:11Z")

</div>

Hello, I’m running logstash 8.15.2 and running into the below IMAP input plugin error. Encountered error Java::JavaLang::NullPointerException {:message=\>"Cannot invoke "org.jruby.ext.openssl.SSLContext$InternalContext…

---

## [Imap plugin not loading](https://discuss.elastic.co/t/imap-plugin-not-loading/375572)

<div class="topic-metadata">

**Author:** [@nkknkk](https://discuss.elastic.co/u/nkknkk)\
**Replies:** 1\
**Last updated:** [August 25, 2025, 2:51pm UTC](https://discuss.elastic.co/t/imap-plugin-not-loading/375572 "2025-08-25T14:51:29Z")

</div>

I installed the imap plugin. logstash-plugin list --verbose | grep imap logstash-input-imap (3.2.1) this is my logstash config file input { imap { host =\> "imap.gmail.com" user =\> "nkknkk@gmail.com" pass…

---

## [Logstash dont do anything but received lines](https://discuss.elastic.co/t/logstash-dont-do-anything-but-received-lines/381258)

<div class="topic-metadata">

**Author:** [@trenhard](https://discuss.elastic.co/u/trenhard)\
**Replies:** 8\
**Last updated:** [August 23, 2025, 8:42pm UTC](https://discuss.elastic.co/t/logstash-dont-do-anything-but-received-lines/381258 "2025-08-23T20:42:38Z")

</div>

Hello cyberbrothers. I came across the fact that the logtash successfully reads the lines, but does nothing further. I've spent two sleepless days on this, please take a look at it with a clear eye. My logstash conf in…

---

## [Logstash dont do anything after received lines](https://discuss.elastic.co/t/logstash-dont-do-anything-after-received-lines/381260)

<div class="topic-metadata">

**Author:** [@trenhard](https://discuss.elastic.co/u/trenhard)\
**Replies:** 1\
**Last updated:** [August 22, 2025, 5:01pm UTC](https://discuss.elastic.co/t/logstash-dont-do-anything-after-received-lines/381260 "2025-08-22T17:01:44Z")

</div>

Hello everyone. My logstash conf input { file { path =\> \["/usr/local/airflow/logs/\*/\*/\*/\*.log"\] codec =\> "line" } } filter { grok { match =\> { "path" =\> "/usr/local/airflow/logs/(?\<dag\_id\>.\*?)/(?\<run\_i…

---

## [Is Logstash 7.4.2 supported on AIX server](https://discuss.elastic.co/t/is-logstash-7-4-2-supported-on-aix-server/381207)

<div class="topic-metadata">

**Author:** [@Shubham.Kumar](https://discuss.elastic.co/u/Shubham.Kumar)\
**Replies:** 1\
**Last updated:** [August 21, 2025, 12:53pm UTC](https://discuss.elastic.co/t/is-logstash-7-4-2-supported-on-aix-server/381207 "2025-08-21T12:53:13Z")

</div>

Hi, I'm trying to deploy Logstash version 7.4.2 on an AIX server and wanted to check if this setup is officially supported or if anyone has experience running it in a similar environment. The server runs AIX 7.0.0, and …

---

## [Logstash bulk request failures: Connection reset by peer / NO\_VALID\_CONNECTION\_AVAILABLE](https://discuss.elastic.co/t/logstash-bulk-request-failures-connection-reset-by-peer-no-valid-connection-available/381133)

<div class="topic-metadata">

**Author:** [@Aswin.r](https://discuss.elastic.co/u/Aswin.r)\
**Replies:** 2\
**Last updated:** [August 21, 2025, 5:42am UTC](https://discuss.elastic.co/t/logstash-bulk-request-failures-connection-reset-by-peer-no-valid-connection-available/381133 "2025-08-21T05:42:48Z")

</div>

Hi Team, I am facing repeated bulk request failures in Logstash while sending data to Elasticsearch. Error: Connection reset by peer error.type: Manticore::SocketException error.class: LogStash::Outputs::Elasticsearch…

---

## [Logstash file input does not deduct the new file after log rotation](https://discuss.elastic.co/t/logstash-file-input-does-not-deduct-the-new-file-after-log-rotation/378543)

<div class="topic-metadata">

**Author:** [@guru\_dev](https://discuss.elastic.co/u/guru_dev)\
**Replies:** 3\
**Last updated:** [August 20, 2025, 7:47am UTC](https://discuss.elastic.co/t/logstash-file-input-does-not-deduct-the-new-file-after-log-rotation/378543 "2025-08-20T07:47:36Z")

</div>

parser\_\*.log once this file is 10mb this gets renamed to parser\_appserver\_backup.log and then creates a new file called parser\_appserver.log.later parser\_appserver\_backup.log is deleted logstash completely reads parser…

---

## [Character encoding problem in output](https://discuss.elastic.co/t/character-encoding-problem-in-output/381072)

<div class="topic-metadata">

**Author:** [@elainesoucy](https://discuss.elastic.co/u/elainesoucy)\
**Replies:** 3\
**Last updated:** [August 19, 2025, 8:05pm UTC](https://discuss.elastic.co/t/character-encoding-problem-in-output/381072 "2025-08-19T20:05:20Z")

</div>

Hello, I'm having a character encoding problem. I have a .ndjson file in UTF-8 encoding. For some reason I can't understand, even though I explicitly specify UTF-8 encoding in the input file, the output contains misinte…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=2)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=4)
