# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=33

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 34

---

## [Is my logstash working?](https://discuss.elastic.co/t/is-my-logstash-working/358087)

<div class="topic-metadata">

**Author:** [@marlonws](https://discuss.elastic.co/u/marlonws)\
**Replies:** 0\
**Last updated:** [April 24, 2024, 6:26am UTC](https://discuss.elastic.co/t/is-my-logstash-working/358087 "2024-04-24T06:26:33Z")

</div>

The input 8080 if I forward its service it responds with an OK on the web page The input 5044 doesn't return anything to me, now I don't know if it's really working or there really isn't a response page for the 5044.

---

## [Logstash stopped processing because of an error](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error/357956)

<div class="topic-metadata">

**Author:** [@cariinaar](https://discuss.elastic.co/u/cariinaar)\
**Replies:** 3\
**Last updated:** [April 24, 2024, 3:27am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error/357956 "2024-04-24T03:27:06Z")

</div>

I have followed solutions to similar topics, but none of the solutions seem to be working for my case. I have tried numerous solutions but the results when i tail logstash-plain.log is always the same which is like below…

---

## [Is this logic right?](https://discuss.elastic.co/t/is-this-logic-right/358063)

<div class="topic-metadata">

**Author:** [@Marlon\_Westphol](https://discuss.elastic.co/u/Marlon_Westphol)\
**Replies:** 1\
**Last updated:** [April 24, 2024, 12:56am UTC](https://discuss.elastic.co/t/is-this-logic-right/358063 "2024-04-24T00:56:17Z")

</div>

In short: I have an elastic agent on a remote host A Logstash with elasticsearch on the same kubernetes host on a remote host B Will the logstash input plugin for elastic agent or beats always be 5044? Will I have to d…

---

## [Trying to install the IMAP input plugin to logstash on windows](https://discuss.elastic.co/t/trying-to-install-the-imap-input-plugin-to-logstash-on-windows/358060)

<div class="topic-metadata">

**Author:** [@Mike\_Yates](https://discuss.elastic.co/u/Mike_Yates)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 9:18pm UTC](https://discuss.elastic.co/t/trying-to-install-the-imap-input-plugin-to-logstash-on-windows/358060 "2024-04-23T21:18:14Z")

</div>

I have not had any success and the documentation seems somewhat lacking. Does anyone have an idiots guide on how to download, install and run the IMAP plugin. I'm new to playing with additional plugins .. Thanks in adv…

---

## [Dynamically bring nested fields to root level](https://discuss.elastic.co/t/dynamically-bring-nested-fields-to-root-level/357948)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 5\
**Last updated:** [April 23, 2024, 2:53pm UTC](https://discuss.elastic.co/t/dynamically-bring-nested-fields-to-root-level/357948 "2024-04-23T14:53:14Z")

</div>

I need to extract fields, full\_name, roles, email and username from below output "Mika.singh" =\> { "metadata" =\> {}, "full\_name" =\> "mika singh", "roles" =\> \[ \[0\] "teaml", …

---

## [Parsing a syslog message before sending to elastic with empty fields](https://discuss.elastic.co/t/parsing-a-syslog-message-before-sending-to-elastic-with-empty-fields/357795)

<div class="topic-metadata">

**Author:** [@devdem13](https://discuss.elastic.co/u/devdem13)\
**Replies:** 7\
**Last updated:** [April 23, 2024, 2:45pm UTC](https://discuss.elastic.co/t/parsing-a-syslog-message-before-sending-to-elastic-with-empty-fields/357795 "2024-04-23T14:45:54Z")

</div>

Hi, I am sending syslog data to logstash in the form of attribute=value separated by spaces. Sometime some fields might be empty. For example in the syslog message you might have: JOBNAME=ABCD SOURCE= CLASS=CLASS1 E…

---

## [Mapping error for rollover](https://discuss.elastic.co/t/mapping-error-for-rollover/358035)

<div class="topic-metadata">

**Author:** [@h.d.intodata](https://discuss.elastic.co/u/h.d.intodata)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 1:51pm UTC](https://discuss.elastic.co/t/mapping-error-for-rollover/358035 "2024-04-23T13:51:46Z")

</div>

Hi team, I have a working ilm policy and template which rollsover the index. However, I cannot get the mappings to work in the policy, i a large list of errors such as: index\_template \[my-alias\] invalid, cause \[Validat…

---

## [Data doesn't transfer](https://discuss.elastic.co/t/data-doesnt-transfer/357972)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)\
**Replies:** 1\
**Last updated:** [April 23, 2024, 7:18am UTC](https://discuss.elastic.co/t/data-doesnt-transfer/357972 "2024-04-23T07:18:24Z")

</div>

I have two machine: 1. Fortigate appliance and 2. ELK machine In my ELK I have the following services : filebeat with the following input and output: filebeat.input: -type: udp host: "172.16.57.222:5044" ## thi…

---

## [Inquiry on Logstash Performance Metrics](https://discuss.elastic.co/t/inquiry-on-logstash-performance-metrics/357969)

<div class="topic-metadata">

**Author:** [@Suvidha\_Malaviya](https://discuss.elastic.co/u/Suvidha_Malaviya)\
**Replies:** 0\
**Last updated:** [April 23, 2024, 5:29am UTC](https://discuss.elastic.co/t/inquiry-on-logstash-performance-metrics/357969 "2024-04-23T05:29:03Z")

</div>

Hi Logstash Community, I'm currently working on optimizing our Logstash deployment and would like to gather some insights on the performance metrics of Logstash. Transfer Time for Data Transmission: I'm interested in …

---

## [I'm trying to install logstash as part of an requirement for wazuh](https://discuss.elastic.co/t/im-trying-to-install-logstash-as-part-of-an-requirement-for-wazuh/357892)

<div class="topic-metadata">

**Author:** [@satiswaran](https://discuss.elastic.co/u/satiswaran)\
**Replies:** 3\
**Last updated:** [April 23, 2024, 5:17am UTC](https://discuss.elastic.co/t/im-trying-to-install-logstash-as-part-of-an-requirement-for-wazuh/357892 "2024-04-23T05:17:34Z")

</div>

I'm trying to install logstash to forward logs to my wazuh server from the wazuh agent for windows, i followed the guide given here: -documentation.wazuh.com/current/cloud-service/your-environment/send-syslog-data After…

---

## [How to extract log from .BZ2 input file? Logstash](https://discuss.elastic.co/t/how-to-extract-log-from-bz2-input-file-logstash/357402)

<div class="topic-metadata">

**Author:** [@Leo23](https://discuss.elastic.co/u/Leo23)\
**Replies:** 1\
**Last updated:** [April 21, 2024, 3:58pm UTC](https://discuss.elastic.co/t/how-to-extract-log-from-bz2-input-file-logstash/357402 "2024-04-21T15:58:25Z")

</div>

Hello, I want to extract logs from compress file in .bz2 do there is a way to do that ? I do it from .gz but seems to don't work with bz2 files.

---

## [Fortigate appliance and ELK syslog server](https://discuss.elastic.co/t/fortigate-appliance-and-elk-syslog-server/357855)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://discuss.elastic.co/u/m_pahlevanzadeh)\
**Replies:** 0\
**Last updated:** [April 21, 2024, 11:22am UTC](https://discuss.elastic.co/t/fortigate-appliance-and-elk-syslog-server/357855 "2024-04-21T11:22:30Z")

</div>

Scenario: I want to create a syslog server for CISCO‌ SW and Fortigate Firewall, I configured my FG to send log to ELK server. I tested with tcpdump and data recieved on the given port. I found two way and I don't know…

---

## [The SHA1 fingerprints generated by Logstash differ from those generated using the API](https://discuss.elastic.co/t/the-sha1-fingerprints-generated-by-logstash-differ-from-those-generated-using-the-api/357577)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 6\
**Last updated:** [April 19, 2024, 11:13am UTC](https://discuss.elastic.co/t/the-sha1-fingerprints-generated-by-logstash-differ-from-those-generated-using-the-api/357577 "2024-04-19T11:13:37Z")

</div>

In our API, we are concatenating the order id and fingerprint to get the hashed value for orderKey. Given the id/fingerprint of the items: id: '7542b27c-c255-4b18-8321-06c9d65aca7f' fingerprint: '28d68c4f04f487f514db3…

---

## [How to create nested object when transfering data from one index to another via logstash](https://discuss.elastic.co/t/how-to-create-nested-object-when-transfering-data-from-one-index-to-another-via-logstash/357779)

<div class="topic-metadata">

**Author:** [@Kaustub\_Gupta](https://discuss.elastic.co/u/Kaustub_Gupta)\
**Replies:** 0\
**Last updated:** [April 19, 2024, 9:07am UTC](https://discuss.elastic.co/t/how-to-create-nested-object-when-transfering-data-from-one-index-to-another-via-logstash/357779 "2024-04-19T09:07:19Z")

</div>

The original index has a mapping: "GTIN": { "type": "text", "fields": { "keyword": { "type": "keyword", "ignore\_above": 256 } } …

---

## [Replace the @timestamp of the dashboard with the time at which the event get logged in the file](https://discuss.elastic.co/t/replace-the-timestamp-of-the-dashboard-with-the-time-at-which-the-event-get-logged-in-the-file/357729)

<div class="topic-metadata">

**Author:** [@reach](https://discuss.elastic.co/u/reach)\
**Replies:** 4\
**Last updated:** [April 18, 2024, 9:13pm UTC](https://discuss.elastic.co/t/replace-the-timestamp-of-the-dashboard-with-the-time-at-which-the-event-get-logged-in-the-file/357729 "2024-04-18T21:13:12Z")

</div>

Hi there, I wanted to replace the @timestamp value with the log time. I am using logstash as a logs collector. This is not working for me and it still adds my local time stamp to the logs parsed. Here is my configurati…

---

## [Logstash high load and CPU usage](https://discuss.elastic.co/t/logstash-high-load-and-cpu-usage/357079)

<div class="topic-metadata">

**Author:** [@pk92](https://discuss.elastic.co/u/pk92)\
**Replies:** 8\
**Last updated:** [April 18, 2024, 1:42pm UTC](https://discuss.elastic.co/t/logstash-high-load-and-cpu-usage/357079 "2024-04-18T13:42:30Z")

</div>

Hi, I am running an Elastic Stack with multiple Logstash servers in different networks to aggregate, filter and forward the logs. For some time now I have the problem that some of these Logstash nodes regularly have a v…

---

## [Parsing XML attributes](https://discuss.elastic.co/t/parsing-xml-attributes/357665)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [April 18, 2024, 4:09am UTC](https://discuss.elastic.co/t/parsing-xml-attributes/357665 "2024-04-18T04:09:39Z")

</div>

Hi, I'm hoping there's a simple solution to this. I need to parse the attribute name and their associated values from the XML below: \<EventData\> \<Data Name="SubjectIP"\>127.127.127.127\</Data\> \<Data Name="SubjectUse…

---

## [Http\_compression Set 'compression\_level' instead](https://discuss.elastic.co/t/http-compression-set-compression-level-instead/356419)

<div class="topic-metadata">

**Author:** [@mdurvesh](https://discuss.elastic.co/u/mdurvesh)\
**Replies:** 5\
**Last updated:** [April 17, 2024, 9:17pm UTC](https://discuss.elastic.co/t/http-compression-set-compression-level-instead/356419 "2024-04-17T21:17:24Z")

</div>

"http\_compression" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Set 'compression\_level' instead. Getting error after updating compression\_l…

---

## [Update document and concatenate field with Logstash](https://discuss.elastic.co/t/update-document-and-concatenate-field-with-logstash/357642)

<div class="topic-metadata">

**Author:** [@CDBSSG](https://discuss.elastic.co/u/CDBSSG)\
**Replies:** 1\
**Last updated:** [April 17, 2024, 9:02pm UTC](https://discuss.elastic.co/t/update-document-and-concatenate-field-with-logstash/357642 "2024-04-17T21:02:14Z")

</div>

Hello, We would like to update a document using Logstash but one of our field should be concatenante and not replace by the new one. Example, if we have two lines to insert : {"state" =\> "created", "data" =\> "firstDat…

---

## [Ingesting data from laptop through Logstash: Nothing happens](https://discuss.elastic.co/t/ingesting-data-from-laptop-through-logstash-nothing-happens/357617)

<div class="topic-metadata">

**Author:** [@rvenkat](https://discuss.elastic.co/u/rvenkat)\
**Replies:** 1\
**Last updated:** [April 17, 2024, 1:03pm UTC](https://discuss.elastic.co/t/ingesting-data-from-laptop-through-logstash-nothing-happens/357617 "2024-04-17T13:03:56Z")

</div>

I want to use OpenSearch to analyze data. I have started OpenSearch through docker-compose, and it seems to be running fine as per the messages I see in console. I have configured the logstash.conf file with input point…

---

## [Unable to parse logstash date filter](https://discuss.elastic.co/t/unable-to-parse-logstash-date-filter/357539)

<div class="topic-metadata">

**Author:** [@Johnson\_will](https://discuss.elastic.co/u/Johnson_will)\
**Replies:** 1\
**Last updated:** [April 16, 2024, 7:41pm UTC](https://discuss.elastic.co/t/unable-to-parse-logstash-date-filter/357539 "2024-04-16T19:41:00Z")

</div>

Unable to parse logstash date filter SOURCE = 2024-04-16 18:29:01.178 -0400 LOGSTASH = "start\_time" =\> 2024-04-16T18:29:01.178Z, LOGSTASH DATE FILTER date{ match =\> \["\[start\_time\]" , "yyyy-MM-dd HH:mm:ss.SSSZ"\] …

---

## [Need help to setup filebeat and want to connect with logstash to elasticsearch to kibana for multi indexer for our multiple clients](https://discuss.elastic.co/t/need-help-to-setup-filebeat-and-want-to-connect-with-logstash-to-elasticsearch-to-kibana-for-multi-indexer-for-our-multiple-clients/357506)

<div class="topic-metadata">

**Author:** [@Darshan1](https://discuss.elastic.co/u/Darshan1)\
**Replies:** 1\
**Last updated:** [April 16, 2024, 12:40pm UTC](https://discuss.elastic.co/t/need-help-to-setup-filebeat-and-want-to-connect-with-logstash-to-elasticsearch-to-kibana-for-multi-indexer-for-our-multiple-clients/357506 "2024-04-16T12:40:24Z")

</div>

We are not able to start port on logstash 5044 port and not able to connect from filebeat. as of now our elasticsearch cluster is up and running in green status. and kibana also running and able to reach dashboard fronte…

---

## [Parse Json](https://discuss.elastic.co/t/parse-json/357405)

<div class="topic-metadata">

**Author:** [@AndrewO](https://discuss.elastic.co/u/AndrewO)\
**Replies:** 3\
**Last updated:** [April 16, 2024, 11:34am UTC](https://discuss.elastic.co/t/parse-json/357405 "2024-04-16T11:34:37Z")

</div>

Hello Help me parse the logs, I'm a beginner, I don't understand how to do it. My log: {"bucket":"22-11-2023-test1111111111","time":"2024-04-15T10:01:53.539568Z","time\_local":"2024-04-15T10:01:53.539568+0000","remote\_…

---

## [File input plugin , read file between to date using ignore older](https://discuss.elastic.co/t/file-input-plugin-read-file-between-to-date-using-ignore-older/357485)

<div class="topic-metadata">

**Author:** [@Leo23](https://discuss.elastic.co/u/Leo23)\
**Replies:** 0\
**Last updated:** [April 16, 2024, 8:05am UTC](https://discuss.elastic.co/t/file-input-plugin-read-file-between-to-date-using-ignore-older/357485 "2024-04-16T08:05:29Z")

</div>

Hello, i want to read file in logstash which are been modify between 80 and 50 weeks ago. How can I do that? input { file { path =\> "x./y/\*.log" start\_position =\> "beginning" ignore\_older =\>…

---

## [RabbitMQ output resume after reaching queue limit](https://discuss.elastic.co/t/rabbitmq-output-resume-after-reaching-queue-limit/355754)

<div class="topic-metadata">

**Author:** [@IvanRibakov](https://discuss.elastic.co/u/IvanRibakov)\
**Replies:** 3\
**Last updated:** [April 16, 2024, 7:43am UTC](https://discuss.elastic.co/t/rabbitmq-output-resume-after-reaching-queue-limit/355754 "2024-04-16T07:43:09Z")

</div>

I'm trying to generate backpressure from RabbitMQ to Logstash. The behaviour that I'm after is for Logstash to stop publishing if the queue is full and resume publishing once it freed up some slots. I've configured Rabb…

---

## [I have configuration of logstash for syslog , it is collecting from multiple devices, how can i create separate indices for each device](https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339)

<div class="topic-metadata">

**Author:** [@Sandeep\_Baljepally](https://discuss.elastic.co/u/Sandeep_Baljepally)\
**Replies:** 3\
**Last updated:** [April 13, 2024, 2:20pm UTC](https://discuss.elastic.co/t/i-have-configuration-of-logstash-for-syslog-it-is-collecting-from-multiple-devices-how-can-i-create-separate-indices-for-each-device/357339 "2024-04-13T14:20:49Z")

</div>

here is my snippet: syslog { port =\> 9111 syslog\_field =\> "syslog" grok\_pattern =\> "\<%{POSINT:priority}\>%{SYSLOGTIMESTAMP:timestamp} %{SYSLOGHOST:host} %{DATA:loglevel}: %{GREEDYDATA:messag…

---

## [Create a new indices for each random directory](https://discuss.elastic.co/t/create-a-new-indices-for-each-random-directory/357329)

<div class="topic-metadata">

**Author:** [@Sandeep\_Baljepally](https://discuss.elastic.co/u/Sandeep_Baljepally)\
**Replies:** 3\
**Last updated:** [April 13, 2024, 7:22am UTC](https://discuss.elastic.co/t/create-a-new-indices-for-each-random-directory/357329 "2024-04-13T07:22:45Z")

</div>

Hi Team, I have a requirement to create randomly generated directories from scripts to create separate indices i.e /mnt/data/logger/xyz/xyz-1.1.1.1 and /mnt/data/logger/xyz/xyz-1.2.1.1 here xyz-x.x.x.x these are gen…

---

## [Problem using logstash-input-google\_pubsub with an https proxy](https://discuss.elastic.co/t/problem-using-logstash-input-google-pubsub-with-an-https-proxy/357295)

<div class="topic-metadata">

**Author:** [@Pedro\_Baldanta](https://discuss.elastic.co/u/Pedro_Baldanta)\
**Replies:** 1\
**Last updated:** [April 13, 2024, 6:48am UTC](https://discuss.elastic.co/t/problem-using-logstash-input-google-pubsub-with-an-https-proxy/357295 "2024-04-13T06:48:39Z")

</div>

Hi all, I'm using this plugin locally with direct internet connection without problem, but when I try to use in my prod env that use a http/https proxy, it does not work, it does not work. With debug I cannot see any er…

---

## [TCP traffic limited - Zero windows](https://discuss.elastic.co/t/tcp-traffic-limited-zero-windows/357293)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 0\
**Last updated:** [April 12, 2024, 1:14pm UTC](https://discuss.elastic.co/t/tcp-traffic-limited-zero-windows/357293 "2024-04-12T13:14:45Z")

</div>

Hi everyone, I had a scenario that I've segmented endpoint traffic in multiple TCP ports. Whether I use only one port I receive zerowin error and delay to input log at elasticsearch. When occour high traffic happening …

---

## [How to use logstash to send longs in real time](https://discuss.elastic.co/t/how-to-use-logstash-to-send-longs-in-real-time/357073)

<div class="topic-metadata">

**Author:** [@saywhat](https://discuss.elastic.co/u/saywhat)\
**Replies:** 14\
**Last updated:** [April 12, 2024, 12:56pm UTC](https://discuss.elastic.co/t/how-to-use-logstash-to-send-longs-in-real-time/357073 "2024-04-12T12:56:38Z")

</div>

Instead of running logstash manually and specify the configuration file and path with: /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/logstash.conf, how can I instruct logstash to run in the background and coll…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=32)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=34)
