# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=40

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 41

---

## [Logstash.service unable to access Keystore](https://discuss.elastic.co/t/logstash-service-unable-to-access-keystore/353628)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 7\
**Last updated:** [February 20, 2024, 11:48am UTC](https://discuss.elastic.co/t/logstash-service-unable-to-access-keystore/353628 "2024-02-20T11:48:06Z")

</div>

Hello everyone, while trying to setup a test Logstash instance, i struggle to get it running. The following error appears, viewable via journalctl: ERROR: Failed to load settings file from "path.settings". Aborting...…

---

## [Issue with Character Encoding When Receiving Data from RSYSLOG in Logstash 8.4.3](https://discuss.elastic.co/t/issue-with-character-encoding-when-receiving-data-from-rsyslog-in-logstash-8-4-3/353609)

<div class="topic-metadata">

**Author:** [@nw-engineer](https://discuss.elastic.co/u/nw-engineer)\
**Replies:** 4\
**Last updated:** [February 20, 2024, 5:41am UTC](https://discuss.elastic.co/t/issue-with-character-encoding-when-receiving-data-from-rsyslog-in-logstash-8-4-3/353609 "2024-02-20T05:41:19Z")

</div>

Hello, I'm currently using Logstash version 8.4.3 and encountering an issue when processing data received from RSYSLOG. The error message I'm seeing is as follows: \[WARN \]\[logstash.codecs.plain\]\[main\]\[b162f9e29529bc018…

---

## [Having trouble parsing my JSON apache log using Logstash](https://discuss.elastic.co/t/having-trouble-parsing-my-json-apache-log-using-logstash/353488)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 3:17pm UTC](https://discuss.elastic.co/t/having-trouble-parsing-my-json-apache-log-using-logstash/353488 "2024-02-19T15:17:28Z")

</div>

Hello. I have an existing Elastic stack that is pulling in app and web server logs. For the web site, I have 2 software stacks - 1 is using an older apache format (comma separated values) and 1 is using a newer JSON fo…

---

## [Transfer log events as files between Logstash instances](https://discuss.elastic.co/t/transfer-log-events-as-files-between-logstash-instances/353503)

<div class="topic-metadata">

**Author:** [@olavur](https://discuss.elastic.co/u/olavur)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 11:34am UTC](https://discuss.elastic.co/t/transfer-log-events-as-files-between-logstash-instances/353503 "2024-02-19T11:34:15Z")

</div>

Hi, I have two logstash instances. One instance A receives events from elastic agents. The second, instance B, inputs the events and outputs them further downstream. But my only option is to transfer files from instanc…

---

## [Missing log file](https://discuss.elastic.co/t/missing-log-file/353554)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 9:46am UTC](https://discuss.elastic.co/t/missing-log-file/353554 "2024-02-19T09:46:38Z")

</div>

Hello. I start logstash with in official container logstash:8.12.1: logstash -f logstash.conf --path.logs /var/log/logstash/ I see logs in the console but path is empty. How can I get logs in the file? Thanks in adva…

---

## [SQL data upload using JDBC-logstash](https://discuss.elastic.co/t/sql-data-upload-using-jdbc-logstash/353435)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 8\
**Last updated:** [February 18, 2024, 10:04am UTC](https://discuss.elastic.co/t/sql-data-upload-using-jdbc-logstash/353435 "2024-02-18T10:04:22Z")

</div>

Hi, I'm uploading data using jdbc-logstash script but when i run ths script it adds allover data again and again so index is showing count of duplicate data too. This is the script which i am using input { jdbc { …

---

## [Logstash TCP encoder](https://discuss.elastic.co/t/logstash-tcp-encoder/353469)

<div class="topic-metadata">

**Author:** [@kypdk](https://discuss.elastic.co/u/kypdk)\
**Replies:** 3\
**Last updated:** [February 17, 2024, 3:54pm UTC](https://discuss.elastic.co/t/logstash-tcp-encoder/353469 "2024-02-17T15:54:41Z")

</div>

The logs go to the logstash server, but they are not indexed because they are not in the format I want. How should I configure it? output { elasticsearch { hosts =\> "elasticsearch:9200" …

---

## [First time user - Unable to get Filebeat \> logstash](https://discuss.elastic.co/t/first-time-user-unable-to-get-filebeat-logstash/352451)

<div class="topic-metadata">

**Author:** [@eezeetee](https://discuss.elastic.co/u/eezeetee)\
**Replies:** 18\
**Last updated:** [February 17, 2024, 5:24am UTC](https://discuss.elastic.co/t/first-time-user-unable-to-get-filebeat-logstash/352451 "2024-02-17T05:24:46Z")

</div>

I've been trying to get a home monitoring system up and running and i've fallen flat. My goal was to get MQTT and other messages into filebeat, thru logstash and into Kibana to build a dashboard. I've followed a few gu…

---

## [Windows install : jruby not found](https://discuss.elastic.co/t/windows-install-jruby-not-found/353487)

<div class="topic-metadata">

**Author:** [@jim.patterson](https://discuss.elastic.co/u/jim.patterson)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 7:17pm UTC](https://discuss.elastic.co/t/windows-install-jruby-not-found/353487 "2024-02-16T19:17:55Z")

</div>

The error message I am getting: "could not find jruby in D:\\elastic\_stack\\logstash-8.12.0\\vendor\\jruby" I've opened and extracted the logstash-8.12.0-windows-x86\_64 file with 7zip, I didn't use windows default zip file…

---

## [Logstash-filter-fingerprint failing intermittently](https://discuss.elastic.co/t/logstash-filter-fingerprint-failing-intermittently/353317)

<div class="topic-metadata">

**Author:** [@ellje](https://discuss.elastic.co/u/ellje)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 5:51pm UTC](https://discuss.elastic.co/t/logstash-filter-fingerprint-failing-intermittently/353317 "2024-02-16T17:51:27Z")

</div>

My pipeline starts up fine and eventually fails for this error, and has only happened twice in a long period of time, but I would like to understand what is the issue. Getting the following error: Pipeline worker error…

---

## [Multipipeline Sending data to wrong index](https://discuss.elastic.co/t/multipipeline-sending-data-to-wrong-index/353428)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 5:22pm UTC](https://discuss.elastic.co/t/multipipeline-sending-data-to-wrong-index/353428 "2024-02-16T17:22:29Z")

</div>

Hello all, I am trying to implement multiple pipelines, but it appears the output of one is being sent to two indices; its own and the other pipelines. $logstash --version Using bundled JDK: /usr/share/logstash/jdk logs…

---

## [Syslog output plugin message parameter ignored](https://discuss.elastic.co/t/syslog-output-plugin-message-parameter-ignored/352560)

<div class="topic-metadata">

**Author:** [@mutt13y](https://discuss.elastic.co/u/mutt13y)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 5:22pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-message-parameter-ignored/352560 "2024-02-16T17:22:14Z")

</div>

the message parameter for the syslog output plugin is documented as used to set the syslog message (default "%{message}") The parameter is defined here logstash-output-syslog/lib/logstash/outputs/syslog.rb at main · log…

---

## [503 Error encountered during the upgrade of Logstash from version 8.10.4 to 8.12.1](https://discuss.elastic.co/t/503-error-encountered-during-the-upgrade-of-logstash-from-version-8-10-4-to-8-12-1/353442)

<div class="topic-metadata">

**Author:** [@Ramya\_Sababathi](https://discuss.elastic.co/u/Ramya_Sababathi)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 10:15am UTC](https://discuss.elastic.co/t/503-error-encountered-during-the-upgrade-of-logstash-from-version-8-10-4-to-8-12-1/353442 "2024-02-16T10:15:57Z")

</div>

Hi, I recently performed the first upgrade of Logstash from version 8.10.4 to 8.12.1 and encountered an error during the process. It's important to note that this error only occurs during the initial upgrade and not dur…

---

## [AMQP Metadata from RabbitMQ input plugin](https://discuss.elastic.co/t/amqp-metadata-from-rabbitmq-input-plugin/352711)

<div class="topic-metadata">

**Author:** [@Big-Edd](https://discuss.elastic.co/u/Big-Edd)\
**Replies:** 5\
**Last updated:** [February 16, 2024, 1:46am UTC](https://discuss.elastic.co/t/amqp-metadata-from-rabbitmq-input-plugin/352711 "2024-02-16T01:46:37Z")

</div>

Hello Everyone, We are inputting AMQP messages from RabbitMQ. These come to RabbitMQ via SMTP utilizing the rabbitmq-email plugin, so the AMQP headers contain some SMTP information we need. By default it seems that onl…

---

## [Logstash S3 output plugin fails to upload txt files in S3](https://discuss.elastic.co/t/logstash-s3-output-plugin-fails-to-upload-txt-files-in-s3/353352)

<div class="topic-metadata">

**Author:** [@Aniket\_Chakrabarty](https://discuss.elastic.co/u/Aniket_Chakrabarty)\
**Replies:** 6\
**Last updated:** [February 15, 2024, 5:38pm UTC](https://discuss.elastic.co/t/logstash-s3-output-plugin-fails-to-upload-txt-files-in-s3/353352 "2024-02-15T17:38:25Z")

</div>

Hi, We have tried to upload a txt file through logstash s3 output plugin but having issues it says: Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which l…

---

## [How to split one line document into several documents using logstash?](https://discuss.elastic.co/t/how-to-split-one-line-document-into-several-documents-using-logstash/353394)

<div class="topic-metadata">

**Author:** [@jimmyb](https://discuss.elastic.co/u/jimmyb)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 5:04pm UTC](https://discuss.elastic.co/t/how-to-split-one-line-document-into-several-documents-using-logstash/353394 "2024-02-15T17:04:35Z")

</div>

Hello All, First time poster here. I have a document coming into logstash which is just one field that references different logs however it has come into elastic as just one line. For example the string within the "me…

---

## [How to handle special characters (hex encoded) in logstash mutate or grok](https://discuss.elastic.co/t/how-to-handle-special-characters-hex-encoded-in-logstash-mutate-or-grok/352437)

<div class="topic-metadata">

**Author:** [@Johnson\_will](https://discuss.elastic.co/u/Johnson_will)\
**Replies:** 6\
**Last updated:** [February 15, 2024, 4:59pm UTC](https://discuss.elastic.co/t/how-to-handle-special-characters-hex-encoded-in-logstash-mutate-or-grok/352437 "2024-02-15T16:59:11Z")

</div>

� This is the special character, I am on logstash7.17.10, It seems like it is able to parse on the greater version of logstash I am using mutate to remove the special character from message filter{ # mutate { gsub…

---

## [NOT ABLE TO INDEX DATA USING HTTP POLLER](https://discuss.elastic.co/t/not-able-to-index-data-using-http-poller/353251)

<div class="topic-metadata">

**Author:** [@rajatbhardwaj1393](https://discuss.elastic.co/u/rajatbhardwaj1393)\
**Replies:** 12\
**Last updated:** [February 15, 2024, 10:37am UTC](https://discuss.elastic.co/t/not-able-to-index-data-using-http-poller/353251 "2024-02-15T10:37:10Z")

</div>

want to index data from the third party api. trying to index data from response but the data is coming as array of results and ruby code below is not storing it as individual event. Can someone suggest what i am doing w…

---

## [Is LSCL documented?](https://discuss.elastic.co/t/is-lscl-documented/353178)

<div class="topic-metadata">

**Author:** [@joostdecock](https://discuss.elastic.co/u/joostdecock)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:36am UTC](https://discuss.elastic.co/t/is-lscl-documented/353178 "2024-02-15T08:36:53Z")

</div>

Hi all, I am looking for documentation on LSCL, the logstash configuration language. The one that inputs and pipelines are written in and looks like this: input { kafka { id =\> "whatever" } } I'm in a situatio…

---

## [Sending logs in a my pattern to Logstash via TCP](https://discuss.elastic.co/t/sending-logs-in-a-my-pattern-to-logstash-via-tcp/353336)

<div class="topic-metadata">

**Author:** [@kypdk](https://discuss.elastic.co/u/kypdk)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 7:43am UTC](https://discuss.elastic.co/t/sending-logs-in-a-my-pattern-to-logstash-via-tcp/353336 "2024-02-15T07:43:15Z")

</div>

%d{yyyy-MM-dd HH:mm:ss.SSS} \[%t\] %-5level %logger{36} - %X{requestId} %msg%n%exception{full} in this pattern Can I send to logstash over TCP in json format? I don't want to do xml configuration. I will make all the ad…

---

## [Increase in container memory with logstash 8.11.3 version](https://discuss.elastic.co/t/increase-in-container-memory-with-logstash-8-11-3-version/353225)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 4:48am UTC](https://discuss.elastic.co/t/increase-in-container-memory-with-logstash-8-11-3-version/353225 "2024-02-15T04:48:39Z")

</div>

Hi, There is gradual increase in container memory in our service which uses logstash 8.11.3. Due to this the container may go to OOM kill within a few days and our service may crash.Can anyone suggest if there is any b…

---

## [Date Variable on index name](https://discuss.elastic.co/t/date-variable-on-index-name/353321)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 4:35am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321 "2024-02-15T04:35:23Z")

</div>

Hello there, I'm curious when there's a pipeline with configured output like this: index =\> "log-%{+YYYY.MM.dd}" where is the date variable referring to? the timestamp on the log, or the timestamp of the logstash se…

---

## [Unresolved or ambiguous specs during Gem::Specification.reset: date (\>= 0), but cannot run gem command to resolve](https://discuss.elastic.co/t/unresolved-or-ambiguous-specs-during-gem-specification-reset-date-0-but-cannot-run-gem-command-to-resolve/351931)

<div class="topic-metadata">

**Author:** [@hughjarse](https://discuss.elastic.co/u/hughjarse)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 1:17am UTC](https://discuss.elastic.co/t/unresolved-or-ambiguous-specs-during-gem-specification-reset-date-0-but-cannot-run-gem-command-to-resolve/351931 "2024-02-15T01:17:52Z")

</div>

Running the logstash-plugin list or logstash-plugin install commands cause the following error. How can I troubleshoot and resolve this problem with the gem command that is built into Logstash? WARN: Unresolved or ambig…

---

## [Query Regarding Warning Messages in Logstash Version 8.12.0](https://discuss.elastic.co/t/query-regarding-warning-messages-in-logstash-version-8-12-0/353242)

<div class="topic-metadata">

**Author:** [@Ramya\_Sababathi](https://discuss.elastic.co/u/Ramya_Sababathi)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 6:44pm UTC](https://discuss.elastic.co/t/query-regarding-warning-messages-in-logstash-version-8-12-0/353242 "2024-02-14T18:44:32Z")

</div>

Issue Description: Upon upgrading to Logstash version 8.12.0, I have noticed the following warning messages appearing in the logs: /usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/concurrent-ruby-1.1.9/lib/concurrent…

---

## [How to mask the content which will be available in persistence queue file](https://discuss.elastic.co/t/how-to-mask-the-content-which-will-be-available-in-persistence-queue-file/353075)

<div class="topic-metadata">

**Author:** [@siva0030](https://discuss.elastic.co/u/siva0030)\
**Replies:** 6\
**Last updated:** [February 14, 2024, 3:03pm UTC](https://discuss.elastic.co/t/how-to-mask-the-content-which-will-be-available-in-persistence-queue-file/353075 "2024-02-14T15:03:54Z")

</div>

Hello Team, We are using Logstash (8.11.3) in our monitoring to receive data from different source systems (via Filebeat, Metricbeat, and Winlogbeat). On the Logstash side, we are using a persistence queue. Since, Logs…

---

## [Windows Event Log connector with Logstash](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274)

<div class="topic-metadata">

**Author:** [@RemyB](https://discuss.elastic.co/u/RemyB)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 1:07pm UTC](https://discuss.elastic.co/t/windows-event-log-connector-with-logstash/353274 "2024-02-14T13:07:05Z")

</div>

Hello all, I would like to thank you in advance for your time reading my following issue : In order to install the windows integrations (Windows Event Logs/Windows) and benefit from the provided visualisations and the …

---

## [Postfix monitoring using ELK](https://discuss.elastic.co/t/postfix-monitoring-using-elk/353125)

<div class="topic-metadata">

**Author:** [@uzzaldas](https://discuss.elastic.co/u/uzzaldas)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 12:20pm UTC](https://discuss.elastic.co/t/postfix-monitoring-using-elk/353125 "2024-02-14T12:20:39Z")

</div>

I want to monitor Postfix logs using ELK stack. I tried postfix filter and grok pattern as below. But I am getting following errors from logstash. ELK Version: 8.9.2 Logstash Error: logstash\_1 | \[2024-02-13T05:3…

---

## [Logstash script adding duplicate data](https://discuss.elastic.co/t/logstash-script-adding-duplicate-data/353223)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 5:05am UTC](https://discuss.elastic.co/t/logstash-script-adding-duplicate-data/353223 "2024-02-14T05:05:58Z")

</div>

Hi, I'm uploading php\_error.logs using logstash script but when i run ths script it adds allover data again and again so index is showing count of duplicate data too. how i can avoid that? This is the script which i am…

---

## [Logstash configurations for v8.12](https://discuss.elastic.co/t/logstash-configurations-for-v8-12/353210)

<div class="topic-metadata">

**Author:** [@prajeet](https://discuss.elastic.co/u/prajeet)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 9:34pm UTC](https://discuss.elastic.co/t/logstash-configurations-for-v8-12/353210 "2024-02-13T21:34:12Z")

</div>

I have installed Elastic, Kibana and Logstash of different linux servers and configured Elastic and kibana with my organization trusted ca. Now, I'm trying to configure logstash to ship from logs from filebeat installed …

---

## [Running logstash](https://discuss.elastic.co/t/running-logstash/352616)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 9:15pm UTC](https://discuss.elastic.co/t/running-logstash/352616 "2024-02-13T21:15:51Z")

</div>

hi I want to create a project that visualize my data in mysql to kibana but when I run the logstash with this cmd : .\\bin\\logstash -f logstash.conf I find only 81 fields in kibana and some fields are empty …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=39)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=41)
