# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=39

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 40

---

## [Elastic Stack Agentless Installation](https://discuss.elastic.co/t/elastic-stack-agentless-installation/354218)

<div class="topic-metadata">

**Author:** [@spazzrabbit](https://discuss.elastic.co/u/spazzrabbit)\
**Replies:** 7\
**Last updated:** [February 27, 2024, 1:02pm UTC](https://discuss.elastic.co/t/elastic-stack-agentless-installation/354218 "2024-02-27T13:02:58Z")

</div>

Hello everyone ! Is there any way to monitor windows machines without agent/script on target machine ? ForExample: Tool/Script on logstash to login and read logs from the target machine via SSH etc. Then process in the…

---

## [Request for Retry Limit Feature in Logstash OpenSearch Output Plugin](https://discuss.elastic.co/t/request-for-retry-limit-feature-in-logstash-opensearch-output-plugin/354195)

<div class="topic-metadata">

**Author:** [@nw-engineer](https://discuss.elastic.co/u/nw-engineer)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 12:27pm UTC](https://discuss.elastic.co/t/request-for-retry-limit-feature-in-logstash-opensearch-output-plugin/354195 "2024-02-27T12:27:20Z")

</div>

Dear LogstashTeam, I hope this message finds you well. I am currently using Logstash version 8.4.3 with OpenSearch and have come across a behavior in the OpenSearch output plugin that I believe could be improved for bet…

---

## [Kafka output. How to set a key from message value?](https://discuss.elastic.co/t/kafka-output-how-to-set-a-key-from-message-value/353185)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 10:14am UTC](https://discuss.elastic.co/t/kafka-output-how-to-set-a-key-from-message-value/353185 "2024-02-27T10:14:40Z")

</div>

I'm using logstash to ingest data from Redshift table and put into Kafka. It works great. But how to use input field as Kafka's key?

---

## [Logs dont' show up when trying to use filter](https://discuss.elastic.co/t/logs-dont-show-up-when-trying-to-use-filter/354120)

<div class="topic-metadata">

**Author:** [@haktoggle](https://discuss.elastic.co/u/haktoggle)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 8:47pm UTC](https://discuss.elastic.co/t/logs-dont-show-up-when-trying-to-use-filter/354120 "2024-02-26T20:47:24Z")

</div>

Hi, I'm attempting to utilize the filter with the accessible logs that are displayed on one of my dashboards; however, those available logs do not appear when using a filter. For example, the logs are displaying, and I…

---

## [Trying to visulaize the working of a dead letter queue but getting error while creating index](https://discuss.elastic.co/t/trying-to-visulaize-the-working-of-a-dead-letter-queue-but-getting-error-while-creating-index/354078)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 5:46am UTC](https://discuss.elastic.co/t/trying-to-visulaize-the-working-of-a-dead-letter-queue-but-getting-error-while-creating-index/354078 "2024-02-26T05:46:23Z")

</div>

This is my logstash configuration input { file{ path =\> "C:\\Elastic Stack\\logstash-8.12.0\\config\\sample-data-dlq.json" start\_position =\> "beginning" sincedb\_path =\> "NUL" codec =\> "json" } } filter{ …

---

## [GeoIP issue on logstash conf file](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/354047)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 19\
**Last updated:** [February 25, 2024, 2:49pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/354047 "2024-02-25T14:49:04Z")

</div>

\[ERROR\]\[logstash.filters.geoip \] Invalid setting for geoip filter plugin: filter { geoip { # This setting must be a path # File does not exist or cannot be opened ./usr/share/logstash/GeoLite2-City.m…

---

## [Logstash input imap plugin 3.2.1 No server greeting](https://discuss.elastic.co/t/logstash-input-imap-plugin-3-2-1-no-server-greeting/354027)

<div class="topic-metadata">

**Author:** [@fatdragon](https://discuss.elastic.co/u/fatdragon)\
**Replies:** 1\
**Last updated:** [February 24, 2024, 3:33pm UTC](https://discuss.elastic.co/t/logstash-input-imap-plugin-3-2-1-no-server-greeting/354027 "2024-02-24T15:33:07Z")

</div>

Installed version 3.2.1 logstash-input-imap on Elastic/logstash 8.11.1 and I get this error: ERROR\]\[logstash.inputs.imap \]\[main\]\[b9cf826e6bcb4a03aae915640362d7e31ff45aa3980afc12c3cca2a437c6e280\] Encountered error Ne…

---

## [How to send heartbeats to Elasticsearch in a secured network?](https://discuss.elastic.co/t/how-to-send-heartbeats-to-elasticsearch-in-a-secured-network/353484)

<div class="topic-metadata">

**Author:** [@jschreud](https://discuss.elastic.co/u/jschreud)\
**Replies:** 13\
**Last updated:** [February 23, 2024, 7:16pm UTC](https://discuss.elastic.co/t/how-to-send-heartbeats-to-elasticsearch-in-a-secured-network/353484 "2024-02-23T19:16:56Z")

</div>

Hey there everyone,.. really hoping I can find some help here. I am working in an environment where Elasticsearch, Kibana and Logstash is running on machine A. Machine B has a Heartbeat installed and is collecting heart…

---

## ["certificate" verification mode for Logstash's output plugin for Elasticsearch](https://discuss.elastic.co/t/certificate-verification-mode-for-logstashs-output-plugin-for-elasticsearch/353956)

<div class="topic-metadata">

**Author:** [@Dhiwakar\_Ravikumar](https://discuss.elastic.co/u/Dhiwakar_Ravikumar)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 6:35pm UTC](https://discuss.elastic.co/t/certificate-verification-mode-for-logstashs-output-plugin-for-elasticsearch/353956 "2024-02-23T18:35:25Z")

</div>

In the following page valid values for SSL verification mode are "full" , "none" I want Logstash to only verify the certificate provided by Elasticsearch is from a trusted authority and not the hostname itself , is th…

---

## [Ingest data from a relational database - STDOUT Duplicates](https://discuss.elastic.co/t/ingest-data-from-a-relational-database-stdout-duplicates/353984)

<div class="topic-metadata">

**Author:** [@MaikLinnemann](https://discuss.elastic.co/u/MaikLinnemann)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 12:50pm UTC](https://discuss.elastic.co/t/ingest-data-from-a-relational-database-stdout-duplicates/353984 "2024-02-23T12:50:29Z")

</div>

Dear all, when i follow the article to ingest data from a relational database (MSSQL), which is that one: Klick and i stdout the results to console, i receive duplicates. Exactly i use: stdout { codec =\> json } for th…

---

## [Rovided Grok patterns do not match data in the input, create array for each field while it's a string](https://discuss.elastic.co/t/rovided-grok-patterns-do-not-match-data-in-the-input-create-array-for-each-field-while-its-a-string/353963)

<div class="topic-metadata">

**Author:** [@hsam](https://discuss.elastic.co/u/hsam)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 10:29am UTC](https://discuss.elastic.co/t/rovided-grok-patterns-do-not-match-data-in-the-input-create-array-for-each-field-while-its-a-string/353963 "2024-02-23T10:29:46Z")

</div>

\-csv exemple: A;B;C as991m;tr;lbr-expl/trd/jcl/as991m as991mb;tr;lbr-expl/trd/jcl/as991mb as991t;tr;lbr-expl/trd/jcl/as991t as991tb;tr;lbr-expl/trd/jcl/as991tb as991w;tr;lbr-expl/trd/jcl/as991w as991wb;tr;lbr-expl/trd/j…

---

## [Which connector to use to establish connection via logstash 8.11?](https://discuss.elastic.co/t/which-connector-to-use-to-establish-connection-via-logstash-8-11/352333)

<div class="topic-metadata">

**Author:** [@ALTAMASH80](https://discuss.elastic.co/u/ALTAMASH80)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 6:38am UTC](https://discuss.elastic.co/t/which-connector-to-use-to-establish-connection-via-logstash-8-11/352333 "2024-02-23T06:38:14Z")

</div>

Hi, I've installed Kibana and Elasticsearch and I wanted to insert data in an index via logstash from MySQL. But, the documentation uses JDBC connectors. You guys have an official connector repository which has Mysql an…

---

## [Unknown error occurred sending a bulk request to Elasticsearch](https://discuss.elastic.co/t/unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/353920)

<div class="topic-metadata">

**Author:** [@JRicha](https://discuss.elastic.co/u/JRicha)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 10:41pm UTC](https://discuss.elastic.co/t/unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/353920 "2024-02-22T22:41:19Z")

</div>

Hello community, I have found other posts here to be helpful in solving my previous issues so I am hoping that someone can help me resolve this issue. I researched my problem in the community pages and have not found an…

---

## [Logstash input with Ruby filter to Opensearch output](https://discuss.elastic.co/t/logstash-input-with-ruby-filter-to-opensearch-output/353635)

<div class="topic-metadata">

**Author:** [@samuelstephens](https://discuss.elastic.co/u/samuelstephens)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 12:15am UTC](https://discuss.elastic.co/t/logstash-input-with-ruby-filter-to-opensearch-output/353635 "2024-02-20T00:15:52Z")

</div>

I have rewritten the Ruby filter mentioned here: The filter now reads as such and I am able to at minimum pass the event to OpenSearch: input: |- http { port =\> 8080 codec =\> "json" filter: |- json { source …

---

## [Logstash automatic config reload and config.reload.interval (high CPU usage)](https://discuss.elastic.co/t/logstash-automatic-config-reload-and-config-reload-interval-high-cpu-usage/353805)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 5:35pm UTC](https://discuss.elastic.co/t/logstash-automatic-config-reload-and-config-reload-interval-high-cpu-usage/353805 "2024-02-22T17:35:24Z")

</div>

Hi, I've upgraded my logstash deployments multiple times over the years (starting way back in the 1.x days), and I had set Logstash to check once a minute for config changes (auto-reload) in the logstash.yml file. I re…

---

## [Salesforce Plugin](https://discuss.elastic.co/t/salesforce-plugin/353804)

<div class="topic-metadata">

**Author:** [@kkalwaysok](https://discuss.elastic.co/u/kkalwaysok)\
**Replies:** 3\
**Last updated:** [February 22, 2024, 5:26pm UTC](https://discuss.elastic.co/t/salesforce-plugin/353804 "2024-02-22T17:26:54Z")

</div>

Hi, I'm using salesforce plugin to pull the logs, and it is downloading 6months worth data that is available in Salesforce. Is there a setting that I can use to download logs from specific date? Thanks in advance.

---

## [Logstash http poller input not able to dynamically update the current date](https://discuss.elastic.co/t/logstash-http-poller-input-not-able-to-dynamically-update-the-current-date/353890)

<div class="topic-metadata">

**Author:** [@rajatbhardwaj1393](https://discuss.elastic.co/u/rajatbhardwaj1393)\
**Replies:** 2\
**Last updated:** [February 22, 2024, 1:56pm UTC](https://discuss.elastic.co/t/logstash-http-poller-input-not-able-to-dynamically-update-the-current-date/353890 "2024-02-22T13:56:02Z")

</div>

trying to update dynamically date in post request in http\_poller. Its not updating. Using below code "range": { "ProjectHistories.ProjectHistoryModified": { "gte": "%{+yyyy-MM-dd'T'00:00:00}", "lte": "%{+yyyy-MM-dd'…

---

## [How to save "total hits" results from a query, in a field](https://discuss.elastic.co/t/how-to-save-total-hits-results-from-a-query-in-a-field/353807)

<div class="topic-metadata">

**Author:** [@Andex](https://discuss.elastic.co/u/Andex)\
**Replies:** 3\
**Last updated:** [February 22, 2024, 8:26am UTC](https://discuss.elastic.co/t/how-to-save-total-hits-results-from-a-query-in-a-field/353807 "2024-02-22T08:26:00Z")

</div>

Hi, i 'm trying to using Logstash to send email. I configure the input pipeline filter witha a query, i need to find all the document that contain ERROR in the message. I do that. in the output i want to user the tota…

---

## [Changing the precision of the @timestamp field](https://discuss.elastic.co/t/changing-the-precision-of-the-timestamp-field/353728)

<div class="topic-metadata">

**Author:** [@ankh](https://discuss.elastic.co/u/ankh)\
**Replies:** 8\
**Last updated:** [February 22, 2024, 8:23am UTC](https://discuss.elastic.co/t/changing-the-precision-of-the-timestamp-field/353728 "2024-02-22T08:23:50Z")

</div>

I have been using the generated @timestamp field in our documents as a record of when a document was sent to Elastic. I have been renaming the field in Logstash to suit our document structure. rename =\> { "@timestamp" =\>…

---

## [\[Kafka Input\] Error using Custom Java Assignor class](https://discuss.elastic.co/t/kafka-input-error-using-custom-java-assignor-class/353853)

<div class="topic-metadata">

**Author:** [@samde](https://discuss.elastic.co/u/samde)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 7:42am UTC](https://discuss.elastic.co/t/kafka-input-error-using-custom-java-assignor-class/353853 "2024-02-22T07:42:57Z")

</div>

Trying to use a custom assignor in partition\_assignment\_strategy but getting the following error. Expectation: Logstash is able to run without issues as partition\_assignment\_strategy field still seems to support java c…

---

## [Heartbeat giving data to Logstash but Logstash's data not going to Elasticsearch](https://discuss.elastic.co/t/heartbeat-giving-data-to-logstash-but-logstashs-data-not-going-to-elasticsearch/353271)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 8\
**Last updated:** [February 22, 2024, 5:26am UTC](https://discuss.elastic.co/t/heartbeat-giving-data-to-logstash-but-logstashs-data-not-going-to-elasticsearch/353271 "2024-02-22T05:26:39Z")

</div>

this is my logstash configuration input { beats { port =\> 5044 codec =\> "json\_lines" } } output { if \[type\] == "heartbeat" { elasticsearch { hosts =\> \["https://127.0.0.1:9200"\] index =\> "he…

---

## [Seeking Advice on Handling Non-UTF-8 Characters in Logs from F5 BIG-IP ASM to Logstash](https://discuss.elastic.co/t/seeking-advice-on-handling-non-utf-8-characters-in-logs-from-f5-big-ip-asm-to-logstash/353827)

<div class="topic-metadata">

**Author:** [@nw-engineer](https://discuss.elastic.co/u/nw-engineer)\
**Replies:** 0\
**Last updated:** [February 22, 2024, 12:55am UTC](https://discuss.elastic.co/t/seeking-advice-on-handling-non-utf-8-characters-in-logs-from-f5-big-ip-asm-to-logstash/353827 "2024-02-22T00:55:01Z")

</div>

Hello everyone, I hope this message finds you well. I am currently using Logstash to process logs from F5 BIG-IP ASM. Initially, I had the input codec set to the default (UTF-8). However, I've encountered an issue wher…

---

## [Logstash plugin issue](https://discuss.elastic.co/t/logstash-plugin-issue/353392)

<div class="topic-metadata">

**Author:** [@derekorr](https://discuss.elastic.co/u/derekorr)\
**Replies:** 1\
**Last updated:** [February 21, 2024, 1:51am UTC](https://discuss.elastic.co/t/logstash-plugin-issue/353392 "2024-02-21T01:51:40Z")

</div>

Hi all, I'm having an issue with any logstash plugin deployment. I tried logstash-plugin install logstash-output-google\_cloud\_storage several times and I was met with several different error messages that seemed to be …

---

## [Can I filter a separate set of logs through logstash rather than straight to Elasticsearch?](https://discuss.elastic.co/t/can-i-filter-a-separate-set-of-logs-through-logstash-rather-than-straight-to-elasticsearch/353726)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 2\
**Last updated:** [February 21, 2024, 12:07am UTC](https://discuss.elastic.co/t/can-i-filter-a-separate-set-of-logs-through-logstash-rather-than-straight-to-elasticsearch/353726 "2024-02-21T00:07:59Z")

</div>

Hello, I currently have Elasticsearch and Kibana installed and configured. I installed fleet-server to manage my elastic-agents and installed elastic-agents to all my hosts and everything is working as should. My elast…

---

## [Logstash - Syslog Timestamp](https://discuss.elastic.co/t/logstash-syslog-timestamp/353719)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 9:38pm UTC](https://discuss.elastic.co/t/logstash-syslog-timestamp/353719 "2024-02-20T21:38:10Z")

</div>

Hello, I am attempting to parse out a timestamp from syslog. The timestamp comes out to 2024-02-04 02:04:03+00:00 Using the date filter how would I be able to take into account the suffix "+00:00"

---

## [Logstash TCP Zero Windows](https://discuss.elastic.co/t/logstash-tcp-zero-windows/351178)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 17\
**Last updated:** [February 20, 2024, 6:22pm UTC](https://discuss.elastic.co/t/logstash-tcp-zero-windows/351178 "2024-02-20T18:22:21Z")

</div>

Hi everyone, I am receiving TCP Zero Windowns in my tcpdumps. I saw in other topics that problem is resolved change pipeline.workes in pipeline file. I am using tcp input in logstash and this input doesn't accepted thi…

---

## [Issue to run logstash](https://discuss.elastic.co/t/issue-to-run-logstash/353717)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 5:07pm UTC](https://discuss.elastic.co/t/issue-to-run-logstash/353717 "2024-02-20T17:07:43Z")

</div>

Hello everyone, I am using Redhat and logstash8.2.0. I want to start my logstash instance, so I execute the following command: bin/logstash -f /bin/logstash-8.2.0/config/logstash.yml Here's the error I get: \[2024-02-…

---

## [How can i restrict only http post api requests to logstash](https://discuss.elastic.co/t/how-can-i-restrict-only-http-post-api-requests-to-logstash/353685)

<div class="topic-metadata">

**Author:** [@kashyap\_kapadia](https://discuss.elastic.co/u/kashyap_kapadia)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 3:28pm UTC](https://discuss.elastic.co/t/how-can-i-restrict-only-http-post-api-requests-to-logstash/353685 "2024-02-20T15:28:14Z")

</div>

Hi All, i want to restrict only https POST call to be accepted by logstash for which i did multiple options in http input section as shown below: input { http { port =\> 5400 ssl\_enabled =\> true s…

---

## [Scale testing logstash beat input](https://discuss.elastic.co/t/scale-testing-logstash-beat-input/353705)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 2:35pm UTC](https://discuss.elastic.co/t/scale-testing-logstash-beat-input/353705 "2024-02-20T14:35:43Z")

</div>

Hi - Any suggestions to test the logstash beat input under load, e.g like simulating metricbeat data for thousands of the machines.

---

## [Logstash - The default timestamp field does not match my log field](https://discuss.elastic.co/t/logstash-the-default-timestamp-field-does-not-match-my-log-field/353622)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 5\
**Last updated:** [February 20, 2024, 1:16pm UTC](https://discuss.elastic.co/t/logstash-the-default-timestamp-field-does-not-match-my-log-field/353622 "2024-02-20T13:16:36Z")

</div>

Hello. I have an existing Elastic stack that is pulling in app and web server logs. For the web site, I have 2 software stacks - 1 is using an older apache format (comma separated values) and 1 is using a newer JSON form…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=38)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=40)
