# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=49

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 50

---

## [Connection reset when ingesting data from Filebeat to Logstash](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681)

<div class="topic-metadata">

**Author:** [@epronetlc](https://discuss.elastic.co/u/epronetlc)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:55pm UTC](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681 "2023-12-05T20:55:06Z")

</div>

I have Filebeat 8.11.1 configured on a server running Windows Server 2019 with an output to Logstash. I have Logstash 8.11.1 configured on a server running Windows Server 2022 with an input from beats and an output to JD…

---

## [Grok\_timeout coming in logstash logs](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623)

<div class="topic-metadata">

**Author:** [@Biswajit\_naik](https://discuss.elastic.co/u/Biswajit_naik)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 5:25pm UTC](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623 "2023-12-05T17:25:00Z")

</div>

when i process multiple type of logs by grok parser ,if the one of logline is not matched with the filter parser ,then i am excepting that it should be come grok parser faliure ,but it comes grok timeout warning in Logst…

---

## [Drop logstash logs not containing certain field](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626)

<div class="topic-metadata">

**Author:** [@e.vedelaar](https://discuss.elastic.co/u/e.vedelaar)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 5:23pm UTC](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626 "2023-12-05T17:23:13Z")

</div>

I want to drop all logs who don't contain the dns.question.name field (or if the field is empty) how would i do this?

---

## [Critical vulns in logstash docker: CVE-2022-46337, CVE-2021-26291](https://discuss.elastic.co/t/critical-vulns-in-logstash-docker-cve-2022-46337-cve-2021-26291/348637)

<div class="topic-metadata">

**Author:** [@AdrianTT](https://discuss.elastic.co/u/AdrianTT)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 5:11pm UTC](https://discuss.elastic.co/t/critical-vulns-in-logstash-docker-cve-2022-46337-cve-2021-26291/348637 "2023-12-05T17:11:36Z")

</div>

trivy reports in the logstash:8.11 docker image the following critical vulns: CVE-2022-46337 in org.apache.derby:derby (derby-10.14.1.0.jar) CVE-2021-26291 in org.apache.maven:maven-compat (maven-compat-3.3.9.jar), org…

---

## [How to connect to \`elasticsearch\` version \`8.x\` using \`API Key\` from \`logstash\`?](https://discuss.elastic.co/t/how-to-connect-to-elasticsearch-version-8-x-using-api-key-from-logstash/348612)

<div class="topic-metadata">

**Author:** [@pushanbhattacharya](https://discuss.elastic.co/u/pushanbhattacharya)\
**Replies:** 4\
**Last updated:** [December 5, 2023, 4:21pm UTC](https://discuss.elastic.co/t/how-to-connect-to-elasticsearch-version-8-x-using-api-key-from-logstash/348612 "2023-12-05T16:21:34Z")

</div>

Hi, I have been using ELK since last 5 years. My codebase is mostly for logstash where the input is a JDBC connection (DB) and after filtering output is the Elasticsearch cluster (for most of the cases). So far I was u…

---

## [A question about Logstash S3 output plugin behaviour](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651)

<div class="topic-metadata">

**Author:** [@milon.james](https://discuss.elastic.co/u/milon.james)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:33pm UTC](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651 "2023-12-05T14:33:35Z")

</div>

Hello, Would like to know what is the default behaviour of Logstash S3 output plugin if we stop the process. Can we configure the plugin to close all the open temporary files and push them to S3 before the process shuts…

---

## [Remove N leading bytes from TCP input](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650)

<div class="topic-metadata">

**Author:** [@rcz](https://discuss.elastic.co/u/rcz)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:29pm UTC](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650 "2023-12-05T14:29:03Z")

</div>

Hi, We are receiving some dubious Protobuf-encoded messages on our TCP input. The sender is leading with a custom length-header of 4 bytes. If we manually dissect the messages, remove the first 4 bytes, and then give …

---

## [Logstash config](https://discuss.elastic.co/t/logstash-config/348644)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 1:16pm UTC](https://discuss.elastic.co/t/logstash-config/348644 "2023-12-05T13:16:17Z")

</div>

I have installed 7.15.0 version of Logstash. I have the following config file: input { file { path =\> "C:/Users/ELK Stack/data/sample.csv" start\_position =\> "beginning" sincedb\_path =\> "NUL" } } filter { csv {…

---

## [Connect Logstash 8.10 to Elasticsearch 8.10](https://discuss.elastic.co/t/connect-logstash-8-10-to-elasticsearch-8-10/348564)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:20pm UTC](https://discuss.elastic.co/t/connect-logstash-8-10-to-elasticsearch-8-10/348564 "2023-12-04T15:20:28Z")

</div>

Can anyone please provide an example to connect Logstash with elasticsearch runing on docker on a debian environement , the connection using SSL "very important" i followed the documentation but i guess im missing somet…

---

## [Need to send data from .log file to AWS opensearch](https://discuss.elastic.co/t/need-to-send-data-from-log-file-to-aws-opensearch/348555)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 5\
**Last updated:** [December 4, 2023, 2:43pm UTC](https://discuss.elastic.co/t/need-to-send-data-from-log-file-to-aws-opensearch/348555 "2023-12-04T14:43:32Z")

</div>

Hello all, Could you please help me on this. I am quite new to the Elasticsearch ocean. My requirement is, I need to send data from .log file to AWS opensearch. Whether the below option will work for me. Download t…

---

## [Logstash log repeated acquisition](https://discuss.elastic.co/t/logstash-log-repeated-acquisition/347821)

<div class="topic-metadata">

**Author:** [@kubo\_Smith](https://discuss.elastic.co/u/kubo_Smith)\
**Replies:** 14\
**Last updated:** [December 4, 2023, 7:34am UTC](https://discuss.elastic.co/t/logstash-log-repeated-acquisition/347821 "2023-12-04T07:34:16Z")

</div>

My log is like this: \[23/Nov/2023:14:12:37 +0800\] | gateway | \[http\] | 195.161.250.29 | POST /gateway/xxx HTTP/1.1 | 9090 | 200 | 182 | sss67jhsd | 0 | gateway | - | - | - | - | Java/1.8.0\_362 Logstash(version: 7.4.2)…

---

## [Logstash CPU Problem](https://discuss.elastic.co/t/logstash-cpu-problem/348239)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 13\
**Last updated:** [December 4, 2023, 3:37am UTC](https://discuss.elastic.co/t/logstash-cpu-problem/348239 "2023-12-04T03:37:54Z")

</div>

Hey guys, I am ingesting firewall logs through logstash via tcp input and am dealing with an issue. Event logs (e.g. vpn) and UTM arrive normally, but when I enable traffic logs (which jumps from 20 eps to 3k eps) logst…

---

## [Logstash pipeline StackOverflowError when using large conf file](https://discuss.elastic.co/t/logstash-pipeline-stackoverflowerror-when-using-large-conf-file/348471)

<div class="topic-metadata">

**Author:** [@blardy](https://discuss.elastic.co/u/blardy)\
**Replies:** 5\
**Last updated:** [December 2, 2023, 5:08pm UTC](https://discuss.elastic.co/t/logstash-pipeline-stackoverflowerror-when-using-large-conf-file/348471 "2023-12-02T17:08:10Z")

</div>

Hey there, Is there a limitation for logstash regarding the size of the configuration file ? I am having StackOverflowError error when logstash starts when using a large conf file (like 400kb) . Below an excerpt of th…

---

## [\[logstash.licensechecker.licensereader\] Unable to retrieve Elasticsearch cluster info. {:message=\>"No Available connections", :exception=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError}](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-unable-to-retrieve-elasticsearch-cluster-info-message-no-available-connections-exception-logstash-noconnectionavailableerror/348421)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [December 2, 2023, 5:37am UTC](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-unable-to-retrieve-elasticsearch-cluster-info-message-no-available-connections-exception-logstash-noconnectionavailableerror/348421 "2023-12-02T05:37:47Z")

</div>

Hey , im using elasticsearch 8.10 on docker , on a debian server , i cannot connect my logstash instance running also on dokcer , on a debian environement . i receive 3 error message WARN \]\[logstash.licensechecker.lice…

---

## [Logstash stuck](https://discuss.elastic.co/t/logstash-stuck/348442)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 5:54pm UTC](https://discuss.elastic.co/t/logstash-stuck/348442 "2023-12-01T17:54:47Z")

</div>

I am getting to get started with logstash and simply copy a csv file to another file using the following conf: input { file{ path =\> "/Users/test/Desktop/project/test.csv" start\_position =\> "beginning" } } fi…

---

## [When migrating logstash from Centos to Debian I get the tag "\_grokparsefailure"](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328)

<div class="topic-metadata">

**Author:** [@OptimusPrimary](https://discuss.elastic.co/u/OptimusPrimary)\
**Replies:** 5\
**Last updated:** [December 1, 2023, 8:54am UTC](https://discuss.elastic.co/t/when-migrating-logstash-from-centos-to-debian-i-get-the-tag-grokparsefailure/348328 "2023-12-01T08:54:27Z")

</div>

I need to migrate the ELK stack from Centos to Debian, on the server I installed the same version of logstash and the same settings, rights and configs, but the logs are not parsed. The tag "\_grokparsefailure" is assign…

---

## [Update record in Kafka-Elastic Pipelines through Logstash](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401)

<div class="topic-metadata">

**Author:** [@Alberuni\_Beruni](https://discuss.elastic.co/u/Alberuni_Beruni)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 7:31am UTC](https://discuss.elastic.co/t/update-record-in-kafka-elastic-pipelines-through-logstash/348401 "2023-12-01T07:31:51Z")

</div>

Hi, I am directly ingesting kafka recored from kafka topic to Elasticsearch server, if there is coming records is updated with the existing in Elasticsearch server so how can i handle it with logstash that if creation i…

---

## [I have installed a 7.17.3 metric beat and file beat, both the beats are unable to send data to the logstash](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 13\
**Last updated:** [December 1, 2023, 5:24am UTC](https://discuss.elastic.co/t/i-have-installed-a-7-17-3-metric-beat-and-file-beat-both-the-beats-are-unable-to-send-data-to-the-logstash/346018 "2023-12-01T05:24:15Z")

</div>

Hi Team, I have a 3 node elk cluster 7.17.3 , i have installed metricbeats and file beat on a new server , the logstash ports are opened(5044). i have checked telnet. the connection looks fine. The beats are unable to …

---

## [Overwriting supplied index micro-%{appName}%{+YYYY.MM.dd} with rollover alias vehicle-service](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354)

<div class="topic-metadata">

**Author:** [@Gaurav\_Sharma3](https://discuss.elastic.co/u/Gaurav_Sharma3)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354 "2023-12-01T04:05:04Z")

</div>

input { tcp { port =\> 5000 codec =\> json } } output { if \[appName\] =="user-service"{ elasticsearch { hosts =\> \["http://localhost:9200"\] index =\> "micro-%{appName}%{+YYYY.MM.dd}" # Use date-based index names i…

---

## [Un acknowledged events in PQ](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 2:29am UTC](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379 "2023-12-01T02:29:01Z")

</div>

Hi Team, Is there any way to check the ununacknowledged events from the Persistent Queue method. Unfortunately we are not able to use the metric queue\_persisted\_growth\_events to find the ununacknowledged. Regards Kan…

---

## [MongoDB Output plugin 3.1.7 error](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372)

<div class="topic-metadata">

**Author:** [@Daniela\_Juliana\_Sanc](https://discuss.elastic.co/u/Daniela_Juliana_Sanc)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372 "2023-11-30T23:18:46Z")

</div>

Hi, I am not able to connect to MongoDB Compass Version 7.0.3 with below error.Using plugin version 3.1.7. \[WARN \]\[logstash.outputs.mongodb \]\[main\] MONGODB | Failed to handshake with localhost:27017: ArgumentError: wro…

---

## [Logstash CA error](https://discuss.elastic.co/t/logstash-ca-error/348369)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 8:55pm UTC](https://discuss.elastic.co/t/logstash-ca-error/348369 "2023-11-30T20:55:49Z")

</div>

Hi, I have been sitting with this issue all day! :slight\_smile: and I get the below error (on windows) \[2023-11-30T21:42:08,979\]\[ERROR\]\[logstash.outputs.elasticsearch\] Invalid setting for elasticsearch output plugin: …

---

## [Logstash HTTP\_POLLER issue - PKIX path bulding failed](https://discuss.elastic.co/t/logstash-http-poller-issue-pkix-path-bulding-failed/348356)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 6:09pm UTC](https://discuss.elastic.co/t/logstash-http-poller-issue-pkix-path-bulding-failed/348356 "2023-11-30T18:09:48Z")

</div>

hi, I got this error when I try to extract information of Elasticsearch form logstash: cfg config on logstash Do you know what could be my error?

---

## [Profile file cannot be null Logstash error](https://discuss.elastic.co/t/profile-file-cannot-be-null-logstash-error/348224)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 6\
**Last updated:** [November 30, 2023, 10:50am UTC](https://discuss.elastic.co/t/profile-file-cannot-be-null-logstash-error/348224 "2023-11-30T10:50:20Z")

</div>

Hello Community I have an issue in Logstash kinesis input plugin, when I run /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/kinesis.conf I can see logs are coming from AWS and ingested into my Elasticsear…

---

## [Reg: Logstash JVM OOM](https://discuss.elastic.co/t/reg-logstash-jvm-oom/348041)

<div class="topic-metadata">

**Author:** [@Thumati](https://discuss.elastic.co/u/Thumati)\
**Replies:** 5\
**Last updated:** [November 30, 2023, 7:36am UTC](https://discuss.elastic.co/t/reg-logstash-jvm-oom/348041 "2023-11-30T07:36:46Z")

</div>

Hi Logstash version is 8.4.3 . Logstash settings are done in below way cpu - 1000m, limits - 7 gi, request - 6 gi ,JVM is 67 %. From the metrics of CPU and memory we can see the memory is not even reaching the 3.5 GI …

---

## [Delete indices after 180 days](https://discuss.elastic.co/t/delete-indices-after-180-days/348148)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 3:25pm UTC](https://discuss.elastic.co/t/delete-indices-after-180-days/348148 "2023-11-29T15:25:11Z")

</div>

Hello, i have create new ILM policy PUT \_ilm/policy/delete-logs-after-6months { "policy": { "phases": { "delete": { "min\_age": "180d", "actions": { "delete": {} } } …

---

## [LogStash returns an error in connection with VMWare](https://discuss.elastic.co/t/logstash-returns-an-error-in-connection-with-vmware/347340)

<div class="topic-metadata">

**Author:** [@heisenberg93](https://discuss.elastic.co/u/heisenberg93)\
**Replies:** 3\
**Last updated:** [November 29, 2023, 2:09pm UTC](https://discuss.elastic.co/t/logstash-returns-an-error-in-connection-with-vmware/347340 "2023-11-29T14:09:14Z")

</div>

Hi, I set the forwarding configuration in a vCenter server to the port of my Elastic server where Logstash is running and set port 9300. Now my Logstash config for this looks like this: input { tcp { …

---

## [Json filter not parsing AWS WAF Logs](https://discuss.elastic.co/t/json-filter-not-parsing-aws-waf-logs/347639)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 5\
**Last updated:** [November 29, 2023, 11:45am UTC](https://discuss.elastic.co/t/json-filter-not-parsing-aws-waf-logs/347639 "2023-11-29T11:45:34Z")

</div>

Hello Community, I having issue with parsing AWS Waf logs using Logstash filter plugin, here is the breakdown I'm pulling logs from AWS using kinesis input and the I'm filtering the log message using :- filter { jso…

---

## [JDBC streaming array as parameter](https://discuss.elastic.co/t/jdbc-streaming-array-as-parameter/348159)

<div class="topic-metadata">

**Author:** [@Rodrigo\_Martins](https://discuss.elastic.co/u/Rodrigo_Martins)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/jdbc-streaming-array-as-parameter/348159 "2023-11-28T15:19:33Z")

</div>

Hello everyone, We are trying to execute a jdbc\_streaming query that takes as parameter a array of values. Our statement looks like this: statement =\> "SELECT \`table\_name\`,\`column\_name\`,\`classification\` FROM \`tableEx\`…

---

## [Logstash freezes during initialization](https://discuss.elastic.co/t/logstash-freezes-during-initialization/348145)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 1:26pm UTC](https://discuss.elastic.co/t/logstash-freezes-during-initialization/348145 "2023-11-28T13:26:16Z")

</div>

Hi, I got a Logstash who work well on local docker. When i use docker on Azure, Logstash freezes during initialization. I just got these logs : Using bundled JDK: /usr/share/logstash/jdk OpenJDK 64-Bit Server VM war…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=48)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=50)
