# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=34

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 35

---

## [Logstash V7.17.16 and JDK Version Compatibility](https://discuss.elastic.co/t/logstash-v7-17-16-and-jdk-version-compatibility/357221)

<div class="topic-metadata">

**Author:** [@DJorgensen](https://discuss.elastic.co/u/DJorgensen)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 2:16pm UTC](https://discuss.elastic.co/t/logstash-v7-17-16-and-jdk-version-compatibility/357221 "2024-04-11T14:16:37Z")

</div>

We are currently running Logstash 7.17.16 and we are being asked to update JDK to version 11.0.21 the current version installed by logstash is 11.0.20+8. Does Logstash 7.17.16 support JDK version 11.0.21 If so how do y…

---

## [Logstash - JDBC input timeout error](https://discuss.elastic.co/t/logstash-jdbc-input-timeout-error/357206)

<div class="topic-metadata">

**Author:** [@baskarcyber](https://discuss.elastic.co/u/baskarcyber)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 12:46pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-timeout-error/357206 "2024-04-11T12:46:53Z")

</div>

Hi, Logstash -version-7.6.1 I am tring to move 10 million rows from Azure SQL to Elasticsearch using logstash JDBC plugin. I haven't set the querytimeout in the connectionstring. it should be infinitie. But after 10 t…

---

## [Logstash with Docker ( Unable to connect to database )](https://discuss.elastic.co/t/logstash-with-docker-unable-to-connect-to-database/357072)

<div class="topic-metadata">

**Author:** [@Kaique292](https://discuss.elastic.co/u/Kaique292)\
**Replies:** 12\
**Last updated:** [April 10, 2024, 5:04pm UTC](https://discuss.elastic.co/t/logstash-with-docker-unable-to-connect-to-database/357072 "2024-04-10T17:04:39Z")

</div>

I've already changed the driver, I've already checked the connection string for a possible error, but apparently everything is fine. I am trying to remotely connect to a SQL Server database through JDBC via Logstash runn…

---

## [Parsing array of json objects](https://discuss.elastic.co/t/parsing-array-of-json-objects/357138)

<div class="topic-metadata">

**Author:** [@sonukowlwar](https://discuss.elastic.co/u/sonukowlwar)\
**Replies:** 1\
**Last updated:** [April 10, 2024, 4:42pm UTC](https://discuss.elastic.co/t/parsing-array-of-json-objects/357138 "2024-04-10T16:42:40Z")

</div>

Hello , I am new to logstash and would like to parse the below json file and add three seperate fields header1 and header2 and header3. Any suggestion on how to do it { "name": "abc", "headers": \[ { "header1": "val…

---

## [Ruby filter to modify nested json field failing](https://discuss.elastic.co/t/ruby-filter-to-modify-nested-json-field-failing/357128)

<div class="topic-metadata">

**Author:** [@elastico12](https://discuss.elastic.co/u/elastico12)\
**Replies:** 1\
**Last updated:** [April 10, 2024, 4:37pm UTC](https://discuss.elastic.co/t/ruby-filter-to-modify-nested-json-field-failing/357128 "2024-04-10T16:37:49Z")

</div>

Hi, I have never used ruby before, or logstash. i have been trying to modify nested JSON field using ruby. JSON looks like below. { "a" : { "b" : "c=d; e=f; g=h" } My end goal is to remove e=f from the nested key b. …

---

## [Logstash error "out of range for an integer"](https://discuss.elastic.co/t/logstash-error-out-of-range-for-an-integer/357152)

<div class="topic-metadata">

**Author:** [@Karthick\_D](https://discuss.elastic.co/u/Karthick_D)\
**Replies:** 1\
**Last updated:** [April 10, 2024, 4:03pm UTC](https://discuss.elastic.co/t/logstash-error-out-of-range-for-an-integer/357152 "2024-04-10T16:03:48Z")

</div>

Getting this error on logatsh-plain.log \[2024-04-10T13:22:24,797\]\[WARN \]\[logstash.outputs.elasticsearch\]\[geoip\]\[2a0f384086e1f5f8eba88bc1849f4a5149188de0fdacb6e00d827adfb445e001\] Could not index event to Elasticsearch. {…

---

## [Http output in logstash with additional body requirements](https://discuss.elastic.co/t/http-output-in-logstash-with-additional-body-requirements/357098)

<div class="topic-metadata">

**Author:** [@Mike\_Yates](https://discuss.elastic.co/u/Mike_Yates)\
**Replies:** 3\
**Last updated:** [April 10, 2024, 3:41pm UTC](https://discuss.elastic.co/t/http-output-in-logstash-with-additional-body-requirements/357098 "2024-04-10T15:41:06Z")

</div>

I have a logstash config file below but the api I'm using requires a body that looks like this, how can i pass that information to the http output configuration. \[ { "class":"stuff", "details":"more stuff" } \] inp…

---

## [Create a new event from some fields](https://discuss.elastic.co/t/create-a-new-event-from-some-fields/357082)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 2\
**Last updated:** [April 10, 2024, 2:10pm UTC](https://discuss.elastic.co/t/create-a-new-event-from-some-fields/357082 "2024-04-10T14:10:10Z")

</div>

Hi, I have a log record which looks like { @timestamp: some\_timestamp, metadata\_field: metadata\_value, other\_field: other\_value, message: some\_message } Is it possible to make new event from this log record w…

---

## [Logstash - Kafka input handshake fails](https://discuss.elastic.co/t/logstash-kafka-input-handshake-fails/357154)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 0\
**Last updated:** [April 10, 2024, 1:55pm UTC](https://discuss.elastic.co/t/logstash-kafka-input-handshake-fails/357154 "2024-04-10T13:55:01Z")

</div>

Hi, I try to configure a Kafka input in Logstash, but the handshake fails and I don't have a lot of logs to find a solution. \[2024-04-10T13:40:11,511\]\[ERROR\]\[logstash.inputs.kafka \]\[main\]\[kafka\] Unable to poll Kafka…

---

## [Filter mutate add\_field to create a nested field](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091)

<div class="topic-metadata">

**Author:** [@Armalyca](https://discuss.elastic.co/u/Armalyca)\
**Replies:** 2\
**Last updated:** [April 10, 2024, 12:43pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-to-create-a-nested-field/357091 "2024-04-10T12:43:50Z")

</div>

Hello, I am new to logstash and I have a question about creating nested field with the add\_field filter I use logstash 7.17. I want to create a nested field from a string, but it doesn't work. The other way around (cr…

---

## [PostgreSQL Extraction with Logstash for Postgresql](https://discuss.elastic.co/t/postgresql-extraction-with-logstash-for-postgresql/357105)

<div class="topic-metadata">

**Author:** [@JOPBI\_Digital](https://discuss.elastic.co/u/JOPBI_Digital)\
**Replies:** 0\
**Last updated:** [April 9, 2024, 9:18pm UTC](https://discuss.elastic.co/t/postgresql-extraction-with-logstash-for-postgresql/357105 "2024-04-09T21:18:24Z")

</div>

input { jdbc { jdbc\_connection\_string =\> "jdbc:postgresql://db.coa.interno.trans.com.br:7432/trans" jdbc\_user =\> "ana" jdbc\_password =\> "Hbt" jdbc\_driver\_library =\> "/usr/share/logstash/vendor/jar/jdbc/postgresql-42…

---

## [Don't override elasticsearch index with null values from logstash pipeline](https://discuss.elastic.co/t/dont-override-elasticsearch-index-with-null-values-from-logstash-pipeline/357069)

<div class="topic-metadata">

**Author:** [@Pedro\_Lopez\_Gonzalez](https://discuss.elastic.co/u/Pedro_Lopez_Gonzalez)\
**Replies:** 1\
**Last updated:** [April 9, 2024, 3:34pm UTC](https://discuss.elastic.co/t/dont-override-elasticsearch-index-with-null-values-from-logstash-pipeline/357069 "2024-04-09T15:34:04Z")

</div>

Hi All Im updating an index in logstash pipeline, it's working right, but I need not override the fields with null values. how can i do this? That is my config elasticsearch { hosts =\> \["HOST"\] index =\> "ind…

---

## [Port 5044 is not opening](https://discuss.elastic.co/t/port-5044-is-not-opening/357067)

<div class="topic-metadata">

**Author:** [@kachavan](https://discuss.elastic.co/u/kachavan)\
**Replies:** 0\
**Last updated:** [April 9, 2024, 12:36pm UTC](https://discuss.elastic.co/t/port-5044-is-not-opening/357067 "2024-04-09T12:36:56Z")

</div>

Hi, I have installed elasticsearch, kibana and logstach, and when I have checked the open port list on my server I found all the required ports are open like 9200, 5601 etc except this port 5044. Firewall is also disabl…

---

## [Logstash is updating sincedb but indices are not creating](https://discuss.elastic.co/t/logstash-is-updating-sincedb-but-indices-are-not-creating/356516)

<div class="topic-metadata">

**Author:** [@Theivendram\_Athavan](https://discuss.elastic.co/u/Theivendram_Athavan)\
**Replies:** 12\
**Last updated:** [April 9, 2024, 12:01pm UTC](https://discuss.elastic.co/t/logstash-is-updating-sincedb-but-indices-are-not-creating/356516 "2024-04-09T12:01:08Z")

</div>

I am collecting ALB logs from S3 into elasticsearch using logstash. For now I wanted to collect more than one year of data from S3 and ingest into elasticsearch. I am creating indices for everyday with the name of index-…

---

## [Client request timeout - Sync Elasticsearch with MySQL](https://discuss.elastic.co/t/client-request-timeout-sync-elasticsearch-with-mysql/357057)

<div class="topic-metadata">

**Author:** [@abhinavtyagi](https://discuss.elastic.co/u/abhinavtyagi)\
**Replies:** 0\
**Last updated:** [April 9, 2024, 11:16am UTC](https://discuss.elastic.co/t/client-request-timeout-sync-elasticsearch-with-mysql/357057 "2024-04-09T11:16:29Z")

</div>

Hello, I am getting below error while executing the get query on kibana console: Also, if I am executing for another index that one is also taking around 30s. Why it's behaving like this ? docker.yml file: elasti…

---

## [ElasticSearch With Logstash SSL communication error](https://discuss.elastic.co/t/elasticsearch-with-logstash-ssl-communication-error/356856)

<div class="topic-metadata">

**Author:** [@Blaj\_Dragos](https://discuss.elastic.co/u/Blaj_Dragos)\
**Replies:** 4\
**Last updated:** [April 9, 2024, 10:19am UTC](https://discuss.elastic.co/t/elasticsearch-with-logstash-ssl-communication-error/356856 "2024-04-09T10:19:29Z")

</div>

Hi! (version 8.11.1) I keep hitting a problem with my ELK stack configuration and I need some help with it. I needed to enable Kibana login page and I found out that I need to set the ssl on for the elasticsearch conf…

---

## [Triggering Logstash Input](https://discuss.elastic.co/t/triggering-logstash-input/356889)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [April 8, 2024, 5:57pm UTC](https://discuss.elastic.co/t/triggering-logstash-input/356889 "2024-04-08T17:57:53Z")

</div>

Hello I am wondering, if there can be a way to allow Logstash input to be triggered by user? Like for example, I am polling SNMP or HTTP API, and the pollers are set up at their own schedule but if a user wants to inita…

---

## [Increasing load on indices without any change in the database records](https://discuss.elastic.co/t/increasing-load-on-indices-without-any-change-in-the-database-records/356960)

<div class="topic-metadata">

**Author:** [@abhinavtyagi](https://discuss.elastic.co/u/abhinavtyagi)\
**Replies:** 0\
**Last updated:** [April 8, 2024, 10:59am UTC](https://discuss.elastic.co/t/increasing-load-on-indices-without-any-change-in-the-database-records/356960 "2024-04-08T10:59:53Z")

</div>

Hello, I am a newbie and I tried syncing Elasticsearch with MySQL database (two tables from my database). Even they are synced I am facing some issues as described below: Code: base.conf: input { jdbc { jdbc\_dri…

---

## [Why does my aggregation apply to only some of my tasks?](https://discuss.elastic.co/t/why-does-my-aggregation-apply-to-only-some-of-my-tasks/356825)

<div class="topic-metadata">

**Author:** [@Mack1](https://discuss.elastic.co/u/Mack1)\
**Replies:** 1\
**Last updated:** [April 5, 2024, 5:55pm UTC](https://discuss.elastic.co/t/why-does-my-aggregation-apply-to-only-some-of-my-tasks/356825 "2024-04-05T17:55:10Z")

</div>

Hello. Learning Logstash here. I am using logstash to apply aggregation formatting so that data arrives to elasticsearch in a specific format. It seems to work most of the time, but some data seems to get no aggregation …

---

## [Fingerprint plugin not working properly](https://discuss.elastic.co/t/fingerprint-plugin-not-working-properly/356845)

<div class="topic-metadata">

**Author:** [@Amer\_Uljic](https://discuss.elastic.co/u/Amer_Uljic)\
**Replies:** 5\
**Last updated:** [April 5, 2024, 11:59am UTC](https://discuss.elastic.co/t/fingerprint-plugin-not-working-properly/356845 "2024-04-05T11:59:18Z")

</div>

I have logs that I receive daily in a JSON form and most of them contain unique identifiers such as ip addresses and ports. A lot of them repeat daily so I want to filter them out but their timestamp changes and elastic …

---

## [Airgapped install of plugin fails trying to access artifacts.elastic.co](https://discuss.elastic.co/t/airgapped-install-of-plugin-fails-trying-to-access-artifacts-elastic-co/356781)

<div class="topic-metadata">

**Author:** [@SebastianThorn](https://discuss.elastic.co/u/SebastianThorn)\
**Replies:** 5\
**Last updated:** [April 5, 2024, 10:25am UTC](https://discuss.elastic.co/t/airgapped-install-of-plugin-fails-trying-to-access-artifacts-elastic-co/356781 "2024-04-05T10:25:56Z")

</div>

Hello, I'm trying to install a plugin behind an airgapped environment. The environment has access to a private RubyGems-repository located in Artifactory. I'm getting this error: \> \[config 4/5\] RUN logstash-plugin i…

---

## [Attempted to resurrect connection to dead ES instance](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/356816)

<div class="topic-metadata">

**Author:** [@yjavvaji](https://discuss.elastic.co/u/yjavvaji)\
**Replies:** 2\
**Last updated:** [April 4, 2024, 9:52pm UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/356816 "2024-04-04T21:52:32Z")

</div>

Hi, I am trying to setup logstash pipeline from kafka to Elasticsearch. The logstash logs show Attempted to resurrect connection to dead ES instance error. \[logstash.outputs.elasticsearch\]\[main\] Attempted to resurrect …

---

## [Can Logstash convert a string into a version field type?](https://discuss.elastic.co/t/can-logstash-convert-a-string-into-a-version-field-type/356810)

<div class="topic-metadata">

**Author:** [@Michael\_Cook](https://discuss.elastic.co/u/Michael_Cook)\
**Replies:** 2\
**Last updated:** [April 4, 2024, 7:15pm UTC](https://discuss.elastic.co/t/can-logstash-convert-a-string-into-a-version-field-type/356810 "2024-04-04T19:15:56Z")

</div>

I've come across Version field type | Elasticsearch Guide \[8.12\] | Elastic which describes exactly what I want to do with a semver text field I'm ingesting via Logstash. However, is it possible in the Logstash filter pi…

---

## [Logstash UDP input ingest big payloads](https://discuss.elastic.co/t/logstash-udp-input-ingest-big-payloads/356790)

<div class="topic-metadata">

**Author:** [@vivere-dally](https://discuss.elastic.co/u/vivere-dally)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 5:09pm UTC](https://discuss.elastic.co/t/logstash-udp-input-ingest-big-payloads/356790 "2024-04-04T17:09:12Z")

</div>

Hi. I have a simple Logstash pipeline: input { udp { port =\> 50001 codec =\> "json" } } output { elasticsearch { // elastic data } } I observed that when I submit a bigger payload it does not get ingested. Is…

---

## [API Connect offloading to ElasticSearch Error](https://discuss.elastic.co/t/api-connect-offloading-to-elasticsearch-error/356719)

<div class="topic-metadata">

**Author:** [@m2web1](https://discuss.elastic.co/u/m2web1)\
**Replies:** 3\
**Last updated:** [April 4, 2024, 4:21pm UTC](https://discuss.elastic.co/t/api-connect-offloading-to-elasticsearch-error/356719 "2024-04-04T16:21:11Z")

</div>

When attempting to offload to our ElasticSerach instance, we are seeing the following error: \[2024-04-03T20:00:32,154\]\[INFO \]\[logstash.outputs.elasticsearch\] Failed to perform request {:message=\>"PKIX path building fail…

---

## [Auditbeat log to syslog without information](https://discuss.elastic.co/t/auditbeat-log-to-syslog-without-information/356748)

<div class="topic-metadata">

**Author:** [@Roberto3](https://discuss.elastic.co/u/Roberto3)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 4:20pm UTC](https://discuss.elastic.co/t/auditbeat-log-to-syslog-without-information/356748 "2024-04-04T16:20:21Z")

</div>

Hi, I have a problem to send the audibeat log to my syslog. If I send the log to the file inside the file I can show some useful information such as the modified file etc, but If I send the same information to the sysl…

---

## [Logstash truncate messages with more than 30 kb](https://discuss.elastic.co/t/logstash-truncate-messages-with-more-than-30-kb/356755)

<div class="topic-metadata">

**Author:** [@Pedro\_Lopez\_Gonzalez](https://discuss.elastic.co/u/Pedro_Lopez_Gonzalez)\
**Replies:** 2\
**Last updated:** [April 4, 2024, 3:16pm UTC](https://discuss.elastic.co/t/logstash-truncate-messages-with-more-than-30-kb/356755 "2024-04-04T15:16:00Z")

</div>

Hi all Im sending messages from filebeat to logstash, but the messages are more longers than 30 kb. Logstash is truncating the messages and I can't process complete. It's possible to increase this limit? beats { po…

---

## [Cannot install logstash plugin](https://discuss.elastic.co/t/cannot-install-logstash-plugin/356665)

<div class="topic-metadata">

**Author:** [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Replies:** 2\
**Last updated:** [April 4, 2024, 1:51pm UTC](https://discuss.elastic.co/t/cannot-install-logstash-plugin/356665 "2024-04-04T13:51:54Z")

</div>

cannot install logstash plugin on redhat linux 8 get error message ./logstash-plugin install --version 0.1.0-beta5 lostash-input-snmp Using bundled JDK: /usr/share/logstash/jdk ERROR: Something went wrong when instal…

---

## [Logs from different ports issue](https://discuss.elastic.co/t/logs-from-different-ports-issue/356763)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 2\
**Last updated:** [April 4, 2024, 12:03pm UTC](https://discuss.elastic.co/t/logs-from-different-ports-issue/356763 "2024-04-04T12:03:59Z")

</div>

Hello, I have the following setup: system logs are sent to logstash using filebeat on port 5044, Apache logs being sent to logstash (same logstash instance as above) using filebeat on port 5047 I then pull these logs…

---

## [Logstash input TCP with TLS connection in a CLOSE\_WAIT state](https://discuss.elastic.co/t/logstash-input-tcp-with-tls-connection-in-a-close-wait-state/356761)

<div class="topic-metadata">

**Author:** [@RifwanJ](https://discuss.elastic.co/u/RifwanJ)\
**Replies:** 0\
**Last updated:** [April 4, 2024, 10:50am UTC](https://discuss.elastic.co/t/logstash-input-tcp-with-tls-connection-in-a-close-wait-state/356761 "2024-04-04T10:50:30Z")

</div>

Hi There, I'm using logstash 8.12.2 version and trying to use input tcp plugging with ssl\_enabled to receive logs from palo alto panorama (client) to logstash.service (server) on port 5400. below is the input tcp confi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=33)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=35)
