# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=35

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 36

---

## [Logstash terminating with java.lang.ArrayIndexOutOfBoundsException: Index -1 out of bounds for length 80](https://discuss.elastic.co/t/logstash-terminating-with-java-lang-arrayindexoutofboundsexception-index-1-out-of-bounds-for-length-80/356739)

<div class="topic-metadata">

**Author:** [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Replies:** 1\
**Last updated:** [April 4, 2024, 8:14am UTC](https://discuss.elastic.co/t/logstash-terminating-with-java-lang-arrayindexoutofboundsexception-index-1-out-of-bounds-for-length-80/356739 "2024-04-04T08:14:44Z")

</div>

logstash getting terminated with below error 2024-03-27T15:10:25.063631230+01:00 warning: thread "Converge PipelineAction::Create\<logstash\>" terminated with exception (report\_on\_exception is true): 2024-03-27T15:10:25.0…

---

## [Sync Data Mongo](https://discuss.elastic.co/t/sync-data-mongo/356698)

<div class="topic-metadata">

**Author:** [@hoang\_van\_th\_ng](https://discuss.elastic.co/u/hoang_van_th_ng)\
**Replies:** 1\
**Last updated:** [April 3, 2024, 6:14pm UTC](https://discuss.elastic.co/t/sync-data-mongo/356698 "2024-04-03T18:14:15Z")

</div>

I have that error in logstash logs when logstash starting. Here my config file for logstash: input { mongodb { uri =\> 'mongodb://shardsvr1:27017,shardsvr2:27017,shardsvr3:27017/db\_mongo?replicaSet=RplS' placeholde…

---

## [Setting to read from S3 with request\_payer enabled?](https://discuss.elastic.co/t/setting-to-read-from-s3-with-request-payer-enabled/356682)

<div class="topic-metadata">

**Author:** [@Ritesh\_Uniyal](https://discuss.elastic.co/u/Ritesh_Uniyal)\
**Replies:** 0\
**Last updated:** [April 3, 2024, 12:53pm UTC](https://discuss.elastic.co/t/setting-to-read-from-s3-with-request-payer-enabled/356682 "2024-04-03T12:53:50Z")

</div>

how to read data from an s3 bucket which has request\_payer enabled? Thanks

---

## [How to correctly parse a RSS feed/XML file with Logstash](https://discuss.elastic.co/t/how-to-correctly-parse-a-rss-feed-xml-file-with-logstash/356613)

<div class="topic-metadata">

**Author:** [@ThomasWILHEM](https://discuss.elastic.co/u/ThomasWILHEM)\
**Replies:** 8\
**Last updated:** [April 3, 2024, 12:34pm UTC](https://discuss.elastic.co/t/how-to-correctly-parse-a-rss-feed-xml-file-with-logstash/356613 "2024-04-03T12:34:33Z")

</div>

Hello everyone, I am currently learning Elasticsearch and Logstash, and I have a job to do. I want to parse a Google News RSS Feed (ex : google news feed) and put the data (from every items) in an indice. The RSS feed…

---

## [Logstash 8.13.0-1 Ubuntu/Debian Package Missing](https://discuss.elastic.co/t/logstash-8-13-0-1-ubuntu-debian-package-missing/356429)

<div class="topic-metadata">

**Author:** [@gt2847c](https://discuss.elastic.co/u/gt2847c)\
**Replies:** 1\
**Last updated:** [April 2, 2024, 6:29pm UTC](https://discuss.elastic.co/t/logstash-8-13-0-1-ubuntu-debian-package-missing/356429 "2024-04-02T18:29:54Z")

</div>

Tried to do a package upgrade and while the rest of the elastic packages upgraded to 8.13 just fine, getting a 404 failure on the 8.13 Logstash package download. Apt shows the latest Logstash version avail as 8.13.0-1 w…

---

## [Parsing IRC Logs](https://discuss.elastic.co/t/parsing-irc-logs/356574)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 2\
**Last updated:** [April 2, 2024, 1:17pm UTC](https://discuss.elastic.co/t/parsing-irc-logs/356574 "2024-04-02T13:17:12Z")

</div>

Im running an ELK-Stack in Docker and my goal is, to parse and filter my IRC logs, for learning. 2024-04-01 20:25:02 me foo 2024-04-01 20:25:46 me bar I found some logstash related stuff on Github. I guess the …

---

## [Help parsing ndjson as json using json filter](https://discuss.elastic.co/t/help-parsing-ndjson-as-json-using-json-filter/356560)

<div class="topic-metadata">

**Author:** [@bibbidi](https://discuss.elastic.co/u/bibbidi)\
**Replies:** 8\
**Last updated:** [April 2, 2024, 12:18pm UTC](https://discuss.elastic.co/t/help-parsing-ndjson-as-json-using-json-filter/356560 "2024-04-02T12:18:56Z")

</div>

Hi, I am trying to use Winlogbeat to get a json file with Windows events. Winlogbeat produces ndjson, so I was trying to convert it to json like this: When I run logstash with this configuration file, it does not save a…

---

## [My IIS logs were sent by filebeat and Now I want to pras them with Logstash](https://discuss.elastic.co/t/my-iis-logs-were-sent-by-filebeat-and-now-i-want-to-pras-them-with-logstash/356484)

<div class="topic-metadata">

**Author:** [@Omid\_Mosayebi](https://discuss.elastic.co/u/Omid_Mosayebi)\
**Replies:** 5\
**Last updated:** [April 2, 2024, 7:17am UTC](https://discuss.elastic.co/t/my-iis-logs-were-sent-by-filebeat-and-now-i-want-to-pras-them-with-logstash/356484 "2024-04-02T07:17:53Z")

</div>

I cannot separate my IIS response code in Logstash

---

## [Error: Encountered non-2xx HTTP code 400](https://discuss.elastic.co/t/error-encountered-non-2xx-http-code-400/356378)

<div class="topic-metadata">

**Author:** [@syfwork](https://discuss.elastic.co/u/syfwork)\
**Replies:** 7\
**Last updated:** [April 2, 2024, 2:49am UTC](https://discuss.elastic.co/t/error-encountered-non-2xx-http-code-400/356378 "2024-04-02T02:49:27Z")

</div>

Hi, I'm using the HTTP output plugin to delete some documents by query. Here's my config file: input { jdbc { jdbc\_driver\_library =\> "/root/infr/logstash-8.12.2/connector/mysql-connector-j-8.3.0.jar" jdbc\_dr…

---

## [Dynamic fields in CSV to be pushed to ES](https://discuss.elastic.co/t/dynamic-fields-in-csv-to-be-pushed-to-es/355892)

<div class="topic-metadata">

**Author:** [@Pallavibhushan](https://discuss.elastic.co/u/Pallavibhushan)\
**Replies:** 7\
**Last updated:** [April 1, 2024, 7:07pm UTC](https://discuss.elastic.co/t/dynamic-fields-in-csv-to-be-pushed-to-es/355892 "2024-04-01T19:07:18Z")

</div>

input { file { path =\> "C:/logstash-7.16.2/Outbound/sample\_\*.csv" start\_position =\> "beginning" } } filter { csv { separator =\> "," skip\_empty\_rows=\>true skip\_header=\>true columns =\> \["pr…

---

## [I want to combine all the order that has same type of fingerprint in one doc](https://discuss.elastic.co/t/i-want-to-combine-all-the-order-that-has-same-type-of-fingerprint-in-one-doc/356043)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 1\
**Last updated:** [March 23, 2024, 9:13pm UTC](https://discuss.elastic.co/t/i-want-to-combine-all-the-order-that-has-same-type-of-fingerprint-in-one-doc/356043 "2024-03-23T21:13:15Z")

</div>

Hello everyone i am trying to combine all the same type of fingerprint doc in one doc is it possible with logstash pure no ruby here is my ndjson file {"userId":"33a4-1ff9-d8-a7fb-d1257","id":"48-0d-44e7-bc-b11","key":…

---

## [Cassandra database tls connection issue on logstash](https://discuss.elastic.co/t/cassandra-database-tls-connection-issue-on-logstash/356367)

<div class="topic-metadata">

**Author:** [@gadde36256](https://discuss.elastic.co/u/gadde36256)\
**Replies:** 9\
**Last updated:** [March 31, 2024, 11:28am UTC](https://discuss.elastic.co/t/cassandra-database-tls-connection-issue-on-logstash/356367 "2024-03-31T11:28:02Z")

</div>

Hello All, Recently we made changes on Cassandra database to connect with tls, I don't find much details to configuring tls on logstash. Can you pls share the any help link for configuring the ssl with logstash. Thanks…

---

## [Logstash Jdbc connection error](https://discuss.elastic.co/t/logstash-jdbc-connection-error/356358)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 4\
**Last updated:** [March 30, 2024, 9:36am UTC](https://discuss.elastic.co/t/logstash-jdbc-connection-error/356358 "2024-03-30T09:36:52Z")

</div>

Hi, We are running a 3 node elastic cluster to index logs from a firewall. Filebeat and Redis Queue are used to forward the logs to Logstash for necessary parsing, after which it is indexed in to the Elastic cluster. D…

---

## [Unpivot Causing Logstash Pipeline to Halt](https://discuss.elastic.co/t/unpivot-causing-logstash-pipeline-to-halt/354690)

<div class="topic-metadata">

**Author:** [@Rushil\_Dewaskar](https://discuss.elastic.co/u/Rushil_Dewaskar)\
**Replies:** 1\
**Last updated:** [March 30, 2024, 8:01am UTC](https://discuss.elastic.co/t/unpivot-causing-logstash-pipeline-to-halt/354690 "2024-03-30T08:01:50Z")

</div>

I am trying to create an Elasticsearch index from an SQL database. However, whenever our SQL query contains an unpivot operation, the process halts after processing a certain number of records. It then resumes after 30-4…

---

## [Filter HTTP or filter ruby](https://discuss.elastic.co/t/filter-http-or-filter-ruby/356477)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 0\
**Last updated:** [March 29, 2024, 8:55pm UTC](https://discuss.elastic.co/t/filter-http-or-filter-ruby/356477 "2024-03-29T20:55:29Z")

</div>

I need to make a new query in an api after INPUT, however the filter is giving an error. ´´´ \[ERROR\] 2024-03-29 17:46:12.286 \[\[main\]\>worker0\] http - error during HTTP request {:url=\>"teste.net", :code=\>500, :headers=\>{…

---

## [Logstash elastic\_integration plugin for on-prem basic license?](https://discuss.elastic.co/t/logstash-elastic-integration-plugin-for-on-prem-basic-license/356424)

<div class="topic-metadata">

**Author:** [@tdanno](https://discuss.elastic.co/u/tdanno)\
**Replies:** 1\
**Last updated:** [March 28, 2024, 9:34pm UTC](https://discuss.elastic.co/t/logstash-elastic-integration-plugin-for-on-prem-basic-license/356424 "2024-03-28T21:34:14Z")

</div>

I see in the plugin documentation that you need an enterprise license... is that because of the cloud functionality aspect of it? Is it possible to use this with a basic license anyway if outputting to an on-premise ES …

---

## [Logstash JMS plugin extremly slow](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210)

<div class="topic-metadata">

**Author:** [@Oussama\_seif\_eddine](https://discuss.elastic.co/u/Oussama_seif_eddine)\
**Replies:** 7\
**Last updated:** [March 28, 2024, 9:23pm UTC](https://discuss.elastic.co/t/logstash-jms-plugin-extremly-slow/356210 "2024-03-28T21:23:14Z")

</div>

Hello, I'm using Logstash JMS plugin to connect to an EMS server and fetch data from a queue. I output then to my elastic cluster (2 nodes). The issue is that even i have a lot of consumers (300 thread/logstach server…

---

## [Is it possible to use multiple pipeline.yml files?](https://discuss.elastic.co/t/is-it-possible-to-use-multiple-pipeline-yml-files/356006)

<div class="topic-metadata">

**Author:** [@Aroque\_R](https://discuss.elastic.co/u/Aroque_R)\
**Replies:** 2\
**Last updated:** [March 28, 2024, 8:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-multiple-pipeline-yml-files/356006 "2024-03-28T20:24:22Z")

</div>

I was thinking if i can set multiple pipeline.yml for multiple instances in the same machine like one in /etc/logstash/team\_x other in /etc/logstash/team\_y

---

## [Logstash cannot connect to Elasticsearch](https://discuss.elastic.co/t/logstash-cannot-connect-to-elasticsearch/356307)

<div class="topic-metadata">

**Author:** [@fclmkz](https://discuss.elastic.co/u/fclmkz)\
**Replies:** 13\
**Last updated:** [March 28, 2024, 6:51am UTC](https://discuss.elastic.co/t/logstash-cannot-connect-to-elasticsearch/356307 "2024-03-28T06:51:42Z")

</div>

Logstash cannot connect to Elasticsearch Logstash version is 8.12.2. Elasticsearch version the same. JVM: 21.0.2 when I launch logstash i get this message: Mar 27 16:42:07 elk.kaztoll.kz logstash\[9567\]: \[2024-03-27T1…

---

## [Please provide official logstash-output-jdbc plugin](https://discuss.elastic.co/t/please-provide-official-logstash-output-jdbc-plugin/356259)

<div class="topic-metadata">

**Author:** [@Jasmine\_Blooms](https://discuss.elastic.co/u/Jasmine_Blooms)\
**Replies:** 3\
**Last updated:** [March 27, 2024, 1:56pm UTC](https://discuss.elastic.co/t/please-provide-official-logstash-output-jdbc-plugin/356259 "2024-03-27T13:56:20Z")

</div>

Hi, My use case is to transfer data from Elasticsearch to Postgres. While exploring, I could find logstash-ouput-jdbc plugin(GitHub - theangryangel/logstash-output-jdbc: JDBC output for Logstash) but it does not seem to…

---

## [Bash syslog\_history --\> rsyslog --\> Elastic](https://discuss.elastic.co/t/bash-syslog-history-rsyslog-elastic/354854)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 2\
**Last updated:** [March 27, 2024, 12:31pm UTC](https://discuss.elastic.co/t/bash-syslog-history-rsyslog-elastic/354854 "2024-03-27T12:31:26Z")

</div>

I want to do the following. I want to enable the native Bash history logging with syslog: shopt -s syslog\_history. Then I want rsyslog to relay the logs to a central server over TLS and then from that central server rela…

---

## [Docker container logs via fleet on Windows Docker Host using WSL2](https://discuss.elastic.co/t/docker-container-logs-via-fleet-on-windows-docker-host-using-wsl2/355395)

<div class="topic-metadata">

**Author:** [@Ian\_Core](https://discuss.elastic.co/u/Ian_Core)\
**Replies:** 1\
**Last updated:** [March 27, 2024, 8:57am UTC](https://discuss.elastic.co/t/docker-container-logs-via-fleet-on-windows-docker-host-using-wsl2/355395 "2024-03-27T08:57:51Z")

</div>

Hi All, I am trying to ingest docker container logs using fleet. My agent policy has docker and docker metrics are successfully being sent using the npipe:////./pipe/docker\_engine configuration for host. The docs su…

---

## [Logstash with multi port nad multi file not work properly](https://discuss.elastic.co/t/logstash-with-multi-port-nad-multi-file-not-work-properly/356144)

<div class="topic-metadata">

**Author:** [@shahrestanaki](https://discuss.elastic.co/u/shahrestanaki)\
**Replies:** 3\
**Last updated:** [March 26, 2024, 11:17am UTC](https://discuss.elastic.co/t/logstash-with-multi-port-nad-multi-file-not-work-properly/356144 "2024-03-26T11:17:06Z")

</div>

hello. i start used ELK with: spring boot 3.1.0 logstash-logback-encoder 7.4 janino 3.1.12 setup elk 8.12.1-1 in linux server centos 7 (ELK server) my senario is: i used 2 project (base and auth). and setup logback…

---

## [Metricbeat Cloudwatch 지표 수집 문의](https://discuss.elastic.co/t/metricbeat-cloudwatch/356154)

<div class="topic-metadata">

**Author:** [@kukjisu](https://discuss.elastic.co/u/kukjisu)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 8:35am UTC](https://discuss.elastic.co/t/metricbeat-cloudwatch/356154 "2024-03-26T08:35:59Z")

</div>

안녕하세요 ELK 8.12 Ver으로 구성하여 테스트 중에 있습니다. 구성: Metricbeat -\> Logstash -\> Elasticsearch -\> Kibana aws.yml을 활용하여 metricsets(Cloudwatch)으로 설정 후 period '5m'으로 설정하고 $metricbeat -e 로 실행하여 Kibana에 표시된 지표를 보면 현재 시점 데이터가 아닌 최소 5분 …

---

## [Multiple Inputs going to different Log Analytics tables](https://discuss.elastic.co/t/multiple-inputs-going-to-different-log-analytics-tables/356135)

<div class="topic-metadata">

**Author:** [@Mike\_Reprogle](https://discuss.elastic.co/u/Mike_Reprogle)\
**Replies:** 0\
**Last updated:** [March 26, 2024, 2:31am UTC](https://discuss.elastic.co/t/multiple-inputs-going-to-different-log-analytics-tables/356135 "2024-03-26T02:31:58Z")

</div>

This is my first time setting up Logstash as opposed to just using a standard syslog server to throw data at Log Analytics. I basically have an Azure VM set up with port 514 open to specific IPs. I am hoping to use port …

---

## [Help need to find the best approach and logic to combine the all orders of same fingerprint](https://discuss.elastic.co/t/help-need-to-find-the-best-approach-and-logic-to-combine-the-all-orders-of-same-fingerprint/356124)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 0\
**Last updated:** [March 25, 2024, 7:16pm UTC](https://discuss.elastic.co/t/help-need-to-find-the-best-approach-and-logic-to-combine-the-all-orders-of-same-fingerprint/356124 "2024-03-25T19:16:39Z")

</div>

Can you help me this , i have orders data , in ndjson on which i use split to separate the docs and create a unique fingerprint on the basis of the items upc + displayName . code and dataset is given below now i want t…

---

## [Logstash not able to parse logs with spaces between key value pair in json object](https://discuss.elastic.co/t/logstash-not-able-to-parse-logs-with-spaces-between-key-value-pair-in-json-object/356011)

<div class="topic-metadata">

**Author:** [@Dhruvi\_Shah](https://discuss.elastic.co/u/Dhruvi_Shah)\
**Replies:** 10\
**Last updated:** [March 25, 2024, 5:27pm UTC](https://discuss.elastic.co/t/logstash-not-able-to-parse-logs-with-spaces-between-key-value-pair-in-json-object/356011 "2024-03-25T17:27:55Z")

</div>

I have a log containing json object. The log gets parsed if json object has no spaces. If it has spaces between key value pair, it is not getting parsed. Configuration file used input { syslog { port =\> 3011 } } filte…

---

## [Logstash and Filebeat not showing in stack monitoring](https://discuss.elastic.co/t/logstash-and-filebeat-not-showing-in-stack-monitoring/356060)

<div class="topic-metadata">

**Author:** [@athul\_prasad](https://discuss.elastic.co/u/athul_prasad)\
**Replies:** 3\
**Last updated:** [March 25, 2024, 10:49am UTC](https://discuss.elastic.co/t/logstash-and-filebeat-not-showing-in-stack-monitoring/356060 "2024-03-25T10:49:05Z")

</div>

Hii Iam new to elk, I can't see logstash nodes and filebeat nodes in kibana stack monitoring . I can see both kibana's and elasticsearches node, could you please help me here to setup that by giving a proper doc or some …

---

## [Logstash pipeline did not handle exception](https://discuss.elastic.co/t/logstash-pipeline-did-not-handle-exception/356070)

<div class="topic-metadata">

**Author:** [@ThELocal\_GUiDE](https://discuss.elastic.co/u/ThELocal_GUiDE)\
**Replies:** 0\
**Last updated:** [March 25, 2024, 4:59am UTC](https://discuss.elastic.co/t/logstash-pipeline-did-not-handle-exception/356070 "2024-03-25T04:59:31Z")

</div>

Hello i am new to logstash. I was trying to send logs from filebeats to logstash then to my indexer. But after running the stack for sometime i ran into an error which im not sure of how to handle. I have used docker to …

---

## [Logstash 8.12.2 rubyTests are failing](https://discuss.elastic.co/t/logstash-8-12-2-rubytests-are-failing/356059)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 1\
**Last updated:** [March 25, 2024, 4:55am UTC](https://discuss.elastic.co/t/logstash-8-12-2-rubytests-are-failing/356059 "2024-03-25T04:55:52Z")

</div>

Hi all, LOgstash 8.12.2 rubyTests are failing with the following error: org.logstash.RSpecTests \> rspecTests\[core tests\] FAILED java.lang.AssertionError: RSpec test suite \`core tests\` saw at least one failure. -…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=34)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=36)
