# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=38

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 39

---

## [How do you know how fast Logstash processing a csv file?](https://discuss.elastic.co/t/how-do-you-know-how-fast-logstash-processing-a-csv-file/354875)

<div class="topic-metadata">

**Author:** [@Benjamin\_Lin](https://discuss.elastic.co/u/Benjamin_Lin)\
**Replies:** 2\
**Last updated:** [March 6, 2024, 9:57pm UTC](https://discuss.elastic.co/t/how-do-you-know-how-fast-logstash-processing-a-csv-file/354875 "2024-03-06T21:57:49Z")

</div>

I am testing a processing performance of Logstash and Elasticsearch injection, does anyone know is there any log or measurement data you can check to see how fast Logstash processing one single CSV file and how fast the …

---

## [@timestamp value for syslog input not in UTC](https://discuss.elastic.co/t/timestamp-value-for-syslog-input-not-in-utc/354840)

<div class="topic-metadata">

**Author:** [@d14](https://discuss.elastic.co/u/d14)\
**Replies:** 1\
**Last updated:** [March 6, 2024, 1:07pm UTC](https://discuss.elastic.co/t/timestamp-value-for-syslog-input-not-in-utc/354840 "2024-03-06T13:07:08Z")

</div>

I'm using the syslog input to parse data from a syslog producer like this: input { syslog { port =\> 5000 } } The output of stdout { codec =\> rubydebug } shows that @timestamp is NOT in UTC but rather ES…

---

## [Logstash collecting logs from the switch](https://discuss.elastic.co/t/logstash-collecting-logs-from-the-switch/354788)

<div class="topic-metadata">

**Author:** [@Yogesh\_AS](https://discuss.elastic.co/u/Yogesh_AS)\
**Replies:** 0\
**Last updated:** [March 6, 2024, 3:17am UTC](https://discuss.elastic.co/t/logstash-collecting-logs-from-the-switch/354788 "2024-03-06T03:17:00Z")

</div>

Hi , I am not getting any logs from the switch tough it is currently configured in switch level also and please find my below code input { udp { port =\> 5145 type =\> syslog } } filter { if \[type\] == "syslog" and…

---

## [Trouble with string interpolation in datastream naming](https://discuss.elastic.co/t/trouble-with-string-interpolation-in-datastream-naming/354770)

<div class="topic-metadata">

**Author:** [@Magister-Machinis](https://discuss.elastic.co/u/Magister-Machinis)\
**Replies:** 3\
**Last updated:** [March 5, 2024, 8:37pm UTC](https://discuss.elastic.co/t/trouble-with-string-interpolation-in-datastream-naming/354770 "2024-03-05T20:37:22Z")

</div>

Hello all, Hoping someone more knowledgeable than I can suggest what I am missing. Attempting to use the below conf file to ingest results and am getting the (also) below error. Is this something that can only be done w…

---

## [Logstash-input-imap SSL Error for Logstash 8.12](https://discuss.elastic.co/t/logstash-input-imap-ssl-error-for-logstash-8-12/354712)

<div class="topic-metadata">

**Author:** [@krissemmy](https://discuss.elastic.co/u/krissemmy)\
**Replies:** 3\
**Last updated:** [March 5, 2024, 7:59pm UTC](https://discuss.elastic.co/t/logstash-input-imap-ssl-error-for-logstash-8-12/354712 "2024-03-05T19:59:10Z")

</div>

Hello there, i have a logstash v8.12 and Imap input plugin v3.2.1. And I use Ubuntu 22.04 Below is my Logstash file: input{ imap { type =\> mail host =\> "imap.gmail.com" user =\> "forgcp24@gma…

---

## [Error while starting logstash](https://discuss.elastic.co/t/error-while-starting-logstash/354631)

<div class="topic-metadata">

**Author:** [@Dhia\_Said](https://discuss.elastic.co/u/Dhia_Said)\
**Replies:** 7\
**Last updated:** [March 5, 2024, 12:03pm UTC](https://discuss.elastic.co/t/error-while-starting-logstash/354631 "2024-03-05T12:03:26Z")

</div>

hello i am new to logstash and i had this error while launching logstash , i didn't know the cause of it, btw i am using it on windows : \[2024-03-04T12:04:49,450\]\[ERROR\]\[logstash.agent \] Failed to execute ac…

---

## [No service found for solr in logstash](https://discuss.elastic.co/t/no-service-found-for-solr-in-logstash/354720)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 2\
**Last updated:** [March 5, 2024, 11:17am UTC](https://discuss.elastic.co/t/no-service-found-for-solr-in-logstash/354720 "2024-03-05T11:17:23Z")

</div>

I am trying to index some logs to Elasticsearch and Solr by using output plugin but giving error while starting it 1709560467682,"\[2024-03-04T13:54:27,680\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline aborted due to…

---

## [Logstash not sending data to ELK](https://discuss.elastic.co/t/logstash-not-sending-data-to-elk/354561)

<div class="topic-metadata">

**Author:** [@bigelkman](https://discuss.elastic.co/u/bigelkman)\
**Replies:** 8\
**Last updated:** [March 4, 2024, 11:39pm UTC](https://discuss.elastic.co/t/logstash-not-sending-data-to-elk/354561 "2024-03-04T23:39:08Z")

</div>

Hello all, I am struggling to get logstash setup and sending data over to ES. I am trying to have logstash act a syslog server and send that data over to ES. I do not see any logstash-\* on the indices or data streams. I …

---

## [Geoip expired\_database error](https://discuss.elastic.co/t/geoip-expired-database-error/354643)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 2\
**Last updated:** [March 4, 2024, 1:14pm UTC](https://discuss.elastic.co/t/geoip-expired-database-error/354643 "2024-03-04T13:14:16Z")

</div>

Hello, I get the following error on logstash logs; \[2024-03-04T13:38:54,437\]\[ERROR\]\[logstash.filters.geoip.downloadmanager\] Permission denied - /var/lib/logstash/plugins/filters/geoip/1709555933 {:cause=\>nil} \[2024-03-…

---

## [Add an ASA to ELK](https://discuss.elastic.co/t/add-an-asa-to-elk/354656)

<div class="topic-metadata">

**Author:** [@Ash78](https://discuss.elastic.co/u/Ash78)\
**Replies:** 0\
**Last updated:** [March 4, 2024, 1:54pm UTC](https://discuss.elastic.co/t/add-an-asa-to-elk/354656 "2024-03-04T13:54:30Z")

</div>

Hi I'm trying to add a Cisco ASA to ELK log monitor and start collecting logs. The ASA is located at the remote site with no direct connection to where the ELK is located. I have a site-to-site VPN between sites. I'm lo…

---

## [Logstash with docker compose - Logstash not reading file input plugin - path](https://discuss.elastic.co/t/logstash-with-docker-compose-logstash-not-reading-file-input-plugin-path/354652)

<div class="topic-metadata">

**Author:** [@Fawwaz\_Hosein](https://discuss.elastic.co/u/Fawwaz_Hosein)\
**Replies:** 0\
**Last updated:** [March 4, 2024, 1:42pm UTC](https://discuss.elastic.co/t/logstash-with-docker-compose-logstash-not-reading-file-input-plugin-path/354652 "2024-03-04T13:42:20Z")

</div>

Pleasant good day, for my docker compose ELK set up I have created a custom image for Logstash for the purposes of creating a directory to bind mount the logs into as well as writing my own logstash.conf pipeline. The lo…

---

## [Hi All, I am facing the issue, Not eligible for data streams because config contains one or more settings that are not compatible with data streams: {"index"=\>"info\_apim\_event"}](https://discuss.elastic.co/t/hi-all-i-am-facing-the-issue-not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-info-apim-event/354424)

<div class="topic-metadata">

**Author:** [@Haribabu](https://discuss.elastic.co/u/Haribabu)\
**Replies:** 8\
**Last updated:** [March 4, 2024, 1:01pm UTC](https://discuss.elastic.co/t/hi-all-i-am-facing-the-issue-not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams-index-info-apim-event/354424 "2024-03-04T13:01:34Z")

</div>

input { beats { port =\> 5044 } } filter { grok { match =\> { "message" =\> "TID: \\\[%{DATA:thread}\\\] \\\[%{DATA:component}\\\] \\\[%{TIMESTAMP\_ISO8601:timestamp}\\\] %{LOGLEVEL:logLevel} \\{%…

---

## [Why does \`--path.settings\` delete events? Why does \`-f\` work perfectly?](https://discuss.elastic.co/t/why-does-path-settings-delete-events-why-does-f-work-perfectly/354592)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 9\
**Last updated:** [March 3, 2024, 7:07pm UTC](https://discuss.elastic.co/t/why-does-path-settings-delete-events-why-does-f-work-perfectly/354592 "2024-03-03T19:07:35Z")

</div>

When I start logstash with -f, everything works perfectly. If I start logstash with --path.settings, logstash deletes events received from the input. Does anyone know why? Here's how to reproduce the issue...i start w…

---

## [Sending data to multiple outputs with different parsing , we are using s3 input plugin](https://discuss.elastic.co/t/sending-data-to-multiple-outputs-with-different-parsing-we-are-using-s3-input-plugin/354566)

<div class="topic-metadata">

**Author:** [@Sumit\_G](https://discuss.elastic.co/u/Sumit_G)\
**Replies:** 1\
**Last updated:** [March 2, 2024, 1:08pm UTC](https://discuss.elastic.co/t/sending-data-to-multiple-outputs-with-different-parsing-we-are-using-s3-input-plugin/354566 "2024-03-02T13:08:51Z")

</div>

This is the setup that we need: Input Plugin - S3 Output plugin: Elastic Search and S3 However, the requirement is that the data that will be going to Elasticsearch won't be the same as that of the data going to S3. T…

---

## [Logstash: Comparison of two variables](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 4\
**Last updated:** [March 1, 2024, 10:36pm UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464 "2024-03-01T22:36:14Z")

</div>

I wrote a logstash config like that, with a lot of if \[message\]. In this example code below, Im filtering logs and have the problem, that a grok named (%{EMAILADDRESS:sender}) (the opposide of (%{EMAILADDRESS:recipient}…

---

## [Logstash shut down and stopped processing because of an error: (SystemExit)](https://discuss.elastic.co/t/logstash-shut-down-and-stopped-processing-because-of-an-error-systemexit/354280)

<div class="topic-metadata">

**Author:** [@Mad\_User](https://discuss.elastic.co/u/Mad_User)\
**Replies:** 7\
**Last updated:** [February 28, 2024, 2:28am UTC](https://discuss.elastic.co/t/logstash-shut-down-and-stopped-processing-because-of-an-error-systemexit/354280 "2024-02-28T02:28:24Z")

</div>

Let me say right away that I am not a professional. I have a problem with Logstash. A few days ago it stopped collecting data and I found an error in the logs. Before it stopped collecting data, changes were made to logs…

---

## [Templating an input plugin?](https://discuss.elastic.co/t/templating-an-input-plugin/354548)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [March 1, 2024, 5:57pm UTC](https://discuss.elastic.co/t/templating-an-input-plugin/354548 "2024-03-01T17:57:17Z")

</div>

I have a question about best practice. Let's say I have two files as follows: File 1. input.template.conf with the content input { elasticsearch { ... several lines of configuration ... } } File 2. start-logst…

---

## [Filebeat not connect with Logstash beat plugin](https://discuss.elastic.co/t/filebeat-not-connect-with-logstash-beat-plugin/354446)

<div class="topic-metadata">

**Author:** [@Pedro\_Lopez\_Gonzalez](https://discuss.elastic.co/u/Pedro_Lopez_Gonzalez)\
**Replies:** 2\
**Last updated:** [February 29, 2024, 6:47pm UTC](https://discuss.elastic.co/t/filebeat-not-connect-with-logstash-beat-plugin/354446 "2024-02-29T18:47:34Z")

</div>

Hi all Im trying to send messages from filebeat to logstash, but the messages dont arrive. The ports is open. this is the config input { beats { client\_inactivity\_timeout =\> 3000 port =\> 5049 } } output.logs…

---

## [Logstash client authentication issue](https://discuss.elastic.co/t/logstash-client-authentication-issue/354452)

<div class="topic-metadata">

**Author:** [@mamoon2024](https://discuss.elastic.co/u/mamoon2024)\
**Replies:** 0\
**Last updated:** [February 29, 2024, 2:22pm UTC](https://discuss.elastic.co/t/logstash-client-authentication-issue/354452 "2024-02-29T14:22:45Z")

</div>

Hi I am trying to Collect logs from OCI Logging into Logstash using OCI Streaming as a Kafka server, I am getting an authentication error, this is log for your reference, please advise about this issue as I am new to log…

---

## [Filebeat error](https://discuss.elastic.co/t/filebeat-error/354434)

<div class="topic-metadata">

**Author:** [@Mrudula](https://discuss.elastic.co/u/Mrudula)\
**Replies:** 0\
**Last updated:** [February 29, 2024, 11:12am UTC](https://discuss.elastic.co/t/filebeat-error/354434 "2024-02-29T11:12:37Z")

</div>

We are seeing error in filebeat "ERROR \[publisher\_pipeline\_output\] pipeline/output.go:180 failed to publish events: write tcp xxx.xx.xx:36240-\>xxx.xx.xx:5045: write: connection reset by peer" in openshift filebeat pod an…

---

## [Deprecated settings for logstash](https://discuss.elastic.co/t/deprecated-settings-for-logstash/353320)

<div class="topic-metadata">

**Author:** [@mdurvesh](https://discuss.elastic.co/u/mdurvesh)\
**Replies:** 3\
**Last updated:** [February 29, 2024, 12:42am UTC](https://discuss.elastic.co/t/deprecated-settings-for-logstash/353320 "2024-02-29T00:42:30Z")

</div>

getting msg \[logstash.outputs.elasticsearch\] You are using a deprecated config setting "truststore\_password" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash i…

---

## [Logstash-input-snmp-1.3.2 modify max\_repetitions](https://discuss.elastic.co/t/logstash-input-snmp-1-3-2-modify-max-repetitions/354392)

<div class="topic-metadata">

**Author:** [@KikeI](https://discuss.elastic.co/u/KikeI)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 10:28pm UTC](https://discuss.elastic.co/t/logstash-input-snmp-1-3-2-modify-max-repetitions/354392 "2024-02-28T22:28:58Z")

</div>

Hi, I am migrating services from prometheus snmp\_exporter to logstash-input-snmp-1.3.2. In snmp\_exporter the value of max\_repetitions is default "25" and gives the option to modify it. In logstash-input-snmp-1.3.2 the d…

---

## [Save search results as a file. Which is continually updated](https://discuss.elastic.co/t/save-search-results-as-a-file-which-is-continually-updated/354261)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 8\
**Last updated:** [February 28, 2024, 8:16pm UTC](https://discuss.elastic.co/t/save-search-results-as-a-file-which-is-continually-updated/354261 "2024-02-28T20:16:13Z")

</div>

Hello, i capture logs from a Docker container according to the following pattern. routes: - multiline+logstash+tcp://logstash.intern.example.com:50000 env: - name: SYSLOG\_HOSTNAME value: homeassistant - name:…

---

## [Dont see any logs in logstash-json.log](https://discuss.elastic.co/t/dont-see-any-logs-in-logstash-json-log/354377)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 6:17pm UTC](https://discuss.elastic.co/t/dont-see-any-logs-in-logstash-json-log/354377 "2024-02-28T18:17:05Z")

</div>

My log4j2.properties setup: appender.rolling.type = RollingFile appender.rolling.name = plain\_rolling appender.rolling.fileName = ${sys:ls.logs}/logstash-plain.log appender.rolling.filePattern = ${sys:ls.logs}/logstash-…

---

## [How to see what logstash version a plugin version supports](https://discuss.elastic.co/t/how-to-see-what-logstash-version-a-plugin-version-supports/354362)

<div class="topic-metadata">

**Author:** [@tylersiemers](https://discuss.elastic.co/u/tylersiemers)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 5:58pm UTC](https://discuss.elastic.co/t/how-to-see-what-logstash-version-a-plugin-version-supports/354362 "2024-02-28T17:58:07Z")

</div>

logstash 7.17.2 I am looking to update the logstash-integration-kafka logstash-integration-kafka (10.9.0) to a newer version that supports Kafka 3.X Where do I see in the README or docs what version logstash I need f…

---

## [I want to migrate an index from a cluster to another index in the another cluster but I get error](https://discuss.elastic.co/t/i-want-to-migrate-an-index-from-a-cluster-to-another-index-in-the-another-cluster-but-i-get-error/354314)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 9\
**Last updated:** [February 28, 2024, 4:11pm UTC](https://discuss.elastic.co/t/i-want-to-migrate-an-index-from-a-cluster-to-another-index-in-the-another-cluster-but-i-get-error/354314 "2024-02-28T16:11:46Z")

</div>

Hi, I want to migrate an index to another cluster. I can't use reindex because source IP is not whitelisted. also I can't use snapshot I decided to do this task by writing a logstash pipeline you can see my pipeline be…

---

## [Badly formatted index, after interpolation still contains placeholder](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231 "2024-02-28T12:38:17Z")

</div>

Hello, after migration to the 8.12.1 I've started getting error "Badly formatted index, after interpolation still contains placeholder". When I'm trying to process report with Filebeat. More interesting is I get this mes…

---

## [No implicit conversion of Pathname into String when logstash plugin installed](https://discuss.elastic.co/t/no-implicit-conversion-of-pathname-into-string-when-logstash-plugin-installed/354328)

<div class="topic-metadata">

**Author:** [@rindarapu](https://discuss.elastic.co/u/rindarapu)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 11:04am UTC](https://discuss.elastic.co/t/no-implicit-conversion-of-pathname-into-string-when-logstash-plugin-installed/354328 "2024-02-28T11:04:15Z")

</div>

getting "no implicit conversion of Pathname into String" when installing offline plugin. Downloaded logstash 8.12.2 and installed logstash-output-mongodb plugin created offline pack and trying to install on the server…

---

## [Parsing file containing sectional metadata and data](https://discuss.elastic.co/t/parsing-file-containing-sectional-metadata-and-data/354020)

<div class="topic-metadata">

**Author:** [@Diamond\_Mohanty](https://discuss.elastic.co/u/Diamond_Mohanty)\
**Replies:** 5\
**Last updated:** [February 28, 2024, 6:38am UTC](https://discuss.elastic.co/t/parsing-file-containing-sectional-metadata-and-data/354020 "2024-02-28T06:38:04Z")

</div>

I have a file with a structure where the actual events follow their meta. For example, the file has contents like below Columns = Name|Age|Gender Delimiter = | John|23|M Jane|25|F Columns = Country,State Delimiter…

---

## [How to setup a proxy in logstash using Windows?](https://discuss.elastic.co/t/how-to-setup-a-proxy-in-logstash-using-windows/354259)

<div class="topic-metadata">

**Author:** [@tcalvillo](https://discuss.elastic.co/u/tcalvillo)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 5:08pm UTC](https://discuss.elastic.co/t/how-to-setup-a-proxy-in-logstash-using-windows/354259 "2024-02-27T17:08:50Z")

</div>

Hello Logstash team, I successfully installed and started Logstash on Windows server 2016. My issue is that I use a proxy and, when I try to see a list of plugins in bin using the below command: C:\\Logstash\\logstash-8.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=37)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=39)
