# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=41

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 42

---

## [Logstash service outputs only a few logs from input file](https://discuss.elastic.co/t/logstash-service-outputs-only-a-few-logs-from-input-file/353183)

<div class="topic-metadata">

**Author:** [@vuvu](https://discuss.elastic.co/u/vuvu)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 7:14pm UTC](https://discuss.elastic.co/t/logstash-service-outputs-only-a-few-logs-from-input-file/353183 "2024-02-13T19:14:58Z")

</div>

hi! Since now, I have started Logstash by running the command: /usr/share/logstash/bin/logstash --path.settings /etc/logstash/ --path.data sensor39 -f /etc/logstash/conf.d/logstash-config.conf and it successfully sent…

---

## [Xml parse in logstash](https://discuss.elastic.co/t/xml-parse-in-logstash/352853)

<div class="topic-metadata">

**Author:** [@Ayaan\_Shaik](https://discuss.elastic.co/u/Ayaan_Shaik)\
**Replies:** 9\
**Last updated:** [February 13, 2024, 4:12pm UTC](https://discuss.elastic.co/t/xml-parse-in-logstash/352853 "2024-02-13T16:12:16Z")

</div>

Hi @Badger I'm Trying to parse the log file with below xml \<imm:IMM-contents xmlns:imm="http://www.saforum.org/IMMSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="SAI-AIS-IMM-…

---

## [Logstash as a Statefulset in Kubernetes - File Input and duplicated logs](https://discuss.elastic.co/t/logstash-as-a-statefulset-in-kubernetes-file-input-and-duplicated-logs/353162)

<div class="topic-metadata">

**Author:** [@veramendi](https://discuss.elastic.co/u/veramendi)\
**Replies:** 6\
**Last updated:** [February 13, 2024, 1:52pm UTC](https://discuss.elastic.co/t/logstash-as-a-statefulset-in-kubernetes-file-input-and-duplicated-logs/353162 "2024-02-13T13:52:06Z")

</div>

Hello, I am trying to deploy a multiple pod logstash Statefulset on a kubernetes cluster using the Input File type. It looks like each pod is reading the same logs from the logfile placed on a PVC, and therefore we are…

---

## [ELK configuration for OpenShift](https://discuss.elastic.co/t/elk-configuration-for-openshift/353149)

<div class="topic-metadata">

**Author:** [@ayoub\_souihel](https://discuss.elastic.co/u/ayoub_souihel)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 10:27am UTC](https://discuss.elastic.co/t/elk-configuration-for-openshift/353149 "2024-02-13T10:27:00Z")

</div>

Hello , i am a very new to ELK , i have set up a single node cluster ( Elasticsearch , kibana , logstash ) , i have configured the logforwarder on openshift correctly ( i see elasticsearch logs showing logs recieved fro…

---

## [Useruuid,tracingId and correlationId field is not comming in logstash](https://discuss.elastic.co/t/useruuid-tracingid-and-correlationid-field-is-not-comming-in-logstash/351537)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 4\
**Last updated:** [February 13, 2024, 5:32am UTC](https://discuss.elastic.co/t/useruuid-tracingid-and-correlationid-field-is-not-comming-in-logstash/351537 "2024-02-13T05:32:15Z")

</div>

Not able to see Useruuid,tracingId and correlationId field in logs in logstash which is comming from mule but it is comming in message field in logstash.Below is my logstash.conf file and I have attached the screenshot a…

---

## [Oracle Data to ES using Logstash](https://discuss.elastic.co/t/oracle-data-to-es-using-logstash/352900)

<div class="topic-metadata">

**Author:** [@elkeng](https://discuss.elastic.co/u/elkeng)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 2:19pm UTC](https://discuss.elastic.co/t/oracle-data-to-es-using-logstash/352900 "2024-02-12T14:19:25Z")

</div>

Hello everyone, I am trying to ingest Oracle data to ES using Logstash. But I got some errors in different conditions. Is there a procedure or best practice to do this? Thanks

---

## [Logstash pipeline indexing error](https://discuss.elastic.co/t/logstash-pipeline-indexing-error/352388)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 7:26am UTC](https://discuss.elastic.co/t/logstash-pipeline-indexing-error/352388 "2024-02-12T07:26:42Z")

</div>

Hi team, I am using ELK stack 8.12 for observability. I am collecting input data from SNMP plugin and filtering the data as per my requirement but while doing that i have multiple index for multiple events that I am col…

---

## [XML into JSON value](https://discuss.elastic.co/t/xml-into-json-value/352933)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 5\
**Last updated:** [February 11, 2024, 8:09am UTC](https://discuss.elastic.co/t/xml-into-json-value/352933 "2024-02-11T08:09:09Z")

</div>

Hey, If i have a Json message, into has an element "error" : "\<?xml version=\\"1.0\\" encoding=\\"UTF-8\\"?\> zefzefzfzef " how can extract and parse XML for create a sub-doc with all element xml example : "json" : "value…

---

## [Does plugin logstash-input-kinesis support Amazon Kinesis EFO(enhanced fan-out)?](https://discuss.elastic.co/t/does-plugin-logstash-input-kinesis-support-amazon-kinesis-efo-enhanced-fan-out/352988)

<div class="topic-metadata">

**Author:** [@ilove2git](https://discuss.elastic.co/u/ilove2git)\
**Replies:** 0\
**Last updated:** [February 10, 2024, 7:42am UTC](https://discuss.elastic.co/t/does-plugin-logstash-input-kinesis-support-amazon-kinesis-efo-enhanced-fan-out/352988 "2024-02-10T07:42:03Z")

</div>

Hi, I notice that this plugin logstash-input-kinesis \[Kinesis input plugin | Logstash Reference \[8.12\] | Elastic\] supports to receive events through \[AWS Kinesis\]http://docs.aws.amazon.com/kinesis/latest/dev/introductio…

---

## [Logstash Pipeline Error: JSON ParseError](https://discuss.elastic.co/t/logstash-pipeline-error-json-parseerror/352808)

<div class="topic-metadata">

**Author:** [@samuelstephens](https://discuss.elastic.co/u/samuelstephens)\
**Replies:** 7\
**Last updated:** [February 8, 2024, 10:09pm UTC](https://discuss.elastic.co/t/logstash-pipeline-error-json-parseerror/352808 "2024-02-08T22:09:58Z")

</div>

Summary I am collecting asset data for Jira using automations to generate a HTTP POST request to Logstash, the following code then takes the input from the request and filters it and sends it to OpenSearch. I have one y…

---

## [Single logstash config file should send data to mutiple indices](https://discuss.elastic.co/t/single-logstash-config-file-should-send-data-to-mutiple-indices/352506)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 6\
**Last updated:** [February 8, 2024, 7:08pm UTC](https://discuss.elastic.co/t/single-logstash-config-file-should-send-data-to-mutiple-indices/352506 "2024-02-08T19:08:59Z")

</div>

Hello All, Kindly suggest if something wrong I'm doing here. Logstash: 8.8.2 I have two indices: mis-monitoring-webserver and mis-monitoring-webui. I want some additional fileds to be created based on some condition…

---

## [Logs not being sent if multiple fields in grok pattern](https://discuss.elastic.co/t/logs-not-being-sent-if-multiple-fields-in-grok-pattern/352881)

<div class="topic-metadata">

**Author:** [@vuvu](https://discuss.elastic.co/u/vuvu)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 5:26pm UTC](https://discuss.elastic.co/t/logs-not-being-sent-if-multiple-fields-in-grok-pattern/352881 "2024-02-08T17:26:17Z")

</div>

hi! I have the following filter which works fine: filter { grok { match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp}" } } date { match =\> \[ "syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:…

---

## [Process monitor](https://discuss.elastic.co/t/process-monitor/352026)

<div class="topic-metadata">

**Author:** [@Gadapa\_Vasundhara](https://discuss.elastic.co/u/Gadapa_Vasundhara)\
**Replies:** 13\
**Last updated:** [February 8, 2024, 3:59pm UTC](https://discuss.elastic.co/t/process-monitor/352026 "2024-02-08T15:59:25Z")

</div>

Hi Team, I need some help on process monitor ex: datamonitor.exe process from logstash which plugin i need to use. wmi plugin is not working. and more over we are getting the status of process.state as running only.…

---

## [Add volume for each strimzi kafka broker](https://discuss.elastic.co/t/add-volume-for-each-strimzi-kafka-broker/352864)

<div class="topic-metadata">

**Author:** [@jerin](https://discuss.elastic.co/u/jerin)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 1:44pm UTC](https://discuss.elastic.co/t/add-volume-for-each-strimzi-kafka-broker/352864 "2024-02-08T13:44:44Z")

</div>

I am sending logs to Elasticsearch like below beats -- logstash entry -- Kafka -- logstash indexing -- Elasticsearch . We want to remove Kafka in the data flow by replacing with logstash persistent queue .. currently …

---

## [Apparent bug in logstash-output-mongodb plugin v 3.1.7 for logstash logstash-7.17.17](https://discuss.elastic.co/t/apparent-bug-in-logstash-output-mongodb-plugin-v-3-1-7-for-logstash-logstash-7-17-17/352819)

<div class="topic-metadata">

**Author:** [@shaigaut](https://discuss.elastic.co/u/shaigaut)\
**Replies:** 2\
**Last updated:** [February 8, 2024, 9:38am UTC](https://discuss.elastic.co/t/apparent-bug-in-logstash-output-mongodb-plugin-v-3-1-7-for-logstash-logstash-7-17-17/352819 "2024-02-08T09:38:17Z")

</div>

I recently migrated from mongodb 3.0 to mongodb 6.0 and logstash plugin 3.1.5 was no longer working, I upgraded the plugin to 3.1.7 and I keep getting this error in logstash logs: n\] MONGODB | Error checking 127.0.0.1:2…

---

## [Logstash : parse json input from http poller failing](https://discuss.elastic.co/t/logstash-parse-json-input-from-http-poller-failing/352787)

<div class="topic-metadata">

**Author:** [@Rasheed](https://discuss.elastic.co/u/Rasheed)\
**Replies:** 8\
**Last updated:** [February 8, 2024, 5:46am UTC](https://discuss.elastic.co/t/logstash-parse-json-input-from-http-poller-failing/352787 "2024-02-08T05:46:53Z")

</div>

I have a logstash configuration of http poller input, and elastic output, but i am struggling to store the json input from poller to index as documents. it stores the entire json as a single field but i need to store eac…

---

## [Running Pipeline Manually](https://discuss.elastic.co/t/running-pipeline-manually/352777)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 10\
**Last updated:** [February 7, 2024, 10:14pm UTC](https://discuss.elastic.co/t/running-pipeline-manually/352777 "2024-02-07T22:14:34Z")

</div>

Quick Question for all: When I am trying to run my pipeline for logstash do I execute pipelines.yml, or just start up logstash? Based on this Documentation I believe I should be starting up logstash " This file is for…

---

## [Patterns defined under patterns\_dir are not valid](https://discuss.elastic.co/t/patterns-defined-under-patterns-dir-are-not-valid/352498)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 23\
**Last updated:** [February 7, 2024, 8:29pm UTC](https://discuss.elastic.co/t/patterns-defined-under-patterns-dir-are-not-valid/352498 "2024-02-07T20:29:39Z")

</div>

I would like to write a grok pattern for logstash using patterns\_dir for maillog based on the following document. There is a postfix-grok-patterns file in patterns\_dir with all the following patterns. I have added th…

---

## [Fortigate 30E not sending any logs to ubuntu/logstash](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270)

<div class="topic-metadata">

**Author:** [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Replies:** 14\
**Last updated:** [February 7, 2024, 7:49pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270 "2024-02-07T19:49:14Z")

</div>

Hi! I have a problem that I need help with. I am using a Fortigate 30e firewall and a log server on a virtual machine with ELK stack and Logstash installed. The goal is to send logs from the Fortigate 30e to the log ser…

---

## [Help requested to iterate and join sub-arrays](https://discuss.elastic.co/t/help-requested-to-iterate-and-join-sub-arrays/352408)

<div class="topic-metadata">

**Author:** [@lmw](https://discuss.elastic.co/u/lmw)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 6:25pm UTC](https://discuss.elastic.co/t/help-requested-to-iterate-and-join-sub-arrays/352408 "2024-02-07T18:25:09Z")

</div>

Hi everyone, Please forgive me for my noob question, of it it has already been answered, but I have not been able to find it by myself. Let's consider that I have this datasource, with an arrays of vars, which may cont…

---

## [Error with datetime field in Kibana](https://discuss.elastic.co/t/error-with-datetime-field-in-kibana/352759)

<div class="topic-metadata">

**Author:** [@ehmontesinos](https://discuss.elastic.co/u/ehmontesinos)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 6:10pm UTC](https://discuss.elastic.co/t/error-with-datetime-field-in-kibana/352759 "2024-02-07T18:10:14Z")

</div>

Hi to everyone I have the following problem. I am exporting from a csv file to generate a dashboard with data that is read daily from that file, which is also generated daily. One of the fields that I include in the csv…

---

## [Replace @timestamp with SYSLOGTIMESTAMP](https://discuss.elastic.co/t/replace-timestamp-with-syslogtimestamp/352725)

<div class="topic-metadata">

**Author:** [@vuvu](https://discuss.elastic.co/u/vuvu)\
**Replies:** 8\
**Last updated:** [February 7, 2024, 3:52pm UTC](https://discuss.elastic.co/t/replace-timestamp-with-syslogtimestamp/352725 "2024-02-07T15:52:26Z")

</div>

hi! I want to replace the @timestamp from the Dashboard with the timestamp from the logs that I get from some servers. The thing is that these logs have the SYSLOGTIMESTAMP format and just by using the date filter, it di…

---

## [Help - Logstash multiple logs in single output](https://discuss.elastic.co/t/help-logstash-multiple-logs-in-single-output/352746)

<div class="topic-metadata">

**Author:** [@CDY1911](https://discuss.elastic.co/u/CDY1911)\
**Replies:** 2\
**Last updated:** [February 7, 2024, 1:39pm UTC](https://discuss.elastic.co/t/help-logstash-multiple-logs-in-single-output/352746 "2024-02-07T13:39:41Z")

</div>

Hi, Im currently stuck surrounding why my testfile is not outputting both types of logs (flow\_logs and URL\_logs). I've ran these both separately and they work fine However once i run the following code below. Im only o…

---

## [Parsing logs with logstash](https://discuss.elastic.co/t/parsing-logs-with-logstash/352655)

<div class="topic-metadata">

**Author:** [@Nejmeddine\_Saidane](https://discuss.elastic.co/u/Nejmeddine_Saidane)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 8:01am UTC](https://discuss.elastic.co/t/parsing-logs-with-logstash/352655 "2024-02-07T08:01:50Z")

</div>

I have this log {"data" =\> "\<Event xmlns='link'\>\<System\>\<Provider Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service Control Manager'/\>\<EventID Qualifiers='16384'\>7036\</…

---

## [Grok Filter](https://discuss.elastic.co/t/grok-filter/352525)

<div class="topic-metadata">

**Author:** [@Emilie\_Carlier](https://discuss.elastic.co/u/Emilie_Carlier)\
**Replies:** 3\
**Last updated:** [February 6, 2024, 10:19pm UTC](https://discuss.elastic.co/t/grok-filter/352525 "2024-02-06T22:19:29Z")

</div>

Hello, I have event from Acces Point Dlink. I can parse some events but for this type I need your help: \<6\>1707130951,Src\_MAC="9E:98:48:98:8E:81",Dst\_MAC="EC:AD:E0:7D:5A:98",Src\_IP="10.229.64.250",Dst\_IP="17.57.146.17…

---

## [Can Logstash detect updates to TLS certificates?](https://discuss.elastic.co/t/can-logstash-detect-updates-to-tls-certificates/352684)

<div class="topic-metadata">

**Author:** [@jpelletier](https://discuss.elastic.co/u/jpelletier)\
**Replies:** 0\
**Last updated:** [February 6, 2024, 9:46pm UTC](https://discuss.elastic.co/t/can-logstash-detect-updates-to-tls-certificates/352684 "2024-02-06T21:46:10Z")

</div>

We run Logstash in a Kubernetes environment using Docker containers. We are looking to integrate cert-manager service to handle automatic updates to TLS certificates within the environment. Is Logstash setup in a way t…

---

## [Rabbitmq output plugin](https://discuss.elastic.co/t/rabbitmq-output-plugin/352639)

<div class="topic-metadata">

**Author:** [@milousel](https://discuss.elastic.co/u/milousel)\
**Replies:** 2\
**Last updated:** [February 6, 2024, 7:07pm UTC](https://discuss.elastic.co/t/rabbitmq-output-plugin/352639 "2024-02-06T19:07:39Z")

</div>

Hello, I want to send data from elasticsearch via logstash to rabbitMQ. All components are in separately docker containers. I am new in ELK, so can you tell me what I doing wrong? Logstash.conf input { stdin {…

---

## [\_csvparsing failure in logstash with delimeters](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 5\
**Last updated:** [February 6, 2024, 2:51pm UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499 "2024-02-06T14:51:57Z")

</div>

Hi all, i am testing a logstash pipelines with the csv data which have approx 20 headers but i am trying with the 3 fields and csv delimeter tab is giving me parsing failures . i also tried with the quote\_char but it is…

---

## [Ubuntu VMware logserver + Fortigate 30E firewall](https://discuss.elastic.co/t/ubuntu-vmware-logserver-fortigate-30e-firewall/352537)

<div class="topic-metadata">

**Author:** [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Replies:** 3\
**Last updated:** [February 6, 2024, 12:46pm UTC](https://discuss.elastic.co/t/ubuntu-vmware-logserver-fortigate-30e-firewall/352537 "2024-02-06T12:46:33Z")

</div>

Hi, I need a bit of help from those wiser. I've built a virtual machine log server that runs on Ubuntu. The log server has an ELK stack installed through which logs from other virtual machines (normal Ubuntu and Windows…

---

## [Logstash Email Output Plugin not using environmental variables](https://discuss.elastic.co/t/logstash-email-output-plugin-not-using-environmental-variables/352579)

<div class="topic-metadata">

**Author:** [@mattk202](https://discuss.elastic.co/u/mattk202)\
**Replies:** 2\
**Last updated:** [February 6, 2024, 2:07am UTC](https://discuss.elastic.co/t/logstash-email-output-plugin-not-using-environmental-variables/352579 "2024-02-06T02:07:14Z")

</div>

Hi All, I'm very new to Elastic and Logstash and am having some issues outputting environmental variables to my email output plugin. I have installed my stack through Selks (Suricata, Logstash, evebox etc etc) and all …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=40)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=42)
