# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=5

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 6

---

## [Translate filter is not working](https://discuss.elastic.co/t/translate-filter-is-not-working/379980)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 3\
**Last updated:** [July 11, 2025, 11:47am UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/379980 "2025-07-11T11:47:56Z")

</div>

input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/logstash-core/lib/jars/postgresql-42.7.3.jar" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_connection\_string =\> "jdbc:postgresql://db\_ip:5432/…

---

## [TCP input is not starting for logstash](https://discuss.elastic.co/t/tcp-input-is-not-starting-for-logstash/380002)

<div class="topic-metadata">

**Author:** [@Eshwar\_K](https://discuss.elastic.co/u/Eshwar_K)\
**Replies:** 7\
**Last updated:** [July 10, 2025, 5:16pm UTC](https://discuss.elastic.co/t/tcp-input-is-not-starting-for-logstash/380002 "2025-07-10T17:16:13Z")

</div>

Hi Elastic experts, I am configuring logstash configuration file with tcp input as per below. Since, I haven't configure ssl certificate. So, I have disabled secure ssl mode. tcp { port =\> 5244 tags =\> \["proxy…

---

## [Logstash “bad\_certificate” Handshake Failure on port 5055](https://discuss.elastic.co/t/logstash-bad-certificate-handshake-failure-on-port-5055/379950)

<div class="topic-metadata">

**Author:** [@RyanW](https://discuss.elastic.co/u/RyanW)\
**Replies:** 13\
**Last updated:** [July 9, 2025, 7:00pm UTC](https://discuss.elastic.co/t/logstash-bad-certificate-handshake-failure-on-port-5055/379950 "2025-07-09T19:00:39Z")

</div>

Environment Item Version / Detail Security Onion 2.4.160 Host role so-manager (10.10.0.13) Standalone Network install on Rocky Linux 9 Elastic Agent endpoint Windows host winwork01 (10.10.0.4) Beats/Elastic…

---

## [Reg issue while connecting to kafka using kafka input plugin](https://discuss.elastic.co/t/reg-issue-while-connecting-to-kafka-using-kafka-input-plugin/379937)

<div class="topic-metadata">

**Author:** [@pradeep-logstashuser](https://discuss.elastic.co/u/pradeep-logstashuser)\
**Replies:** 0\
**Last updated:** [July 9, 2025, 9:22am UTC](https://discuss.elastic.co/t/reg-issue-while-connecting-to-kafka-using-kafka-input-plugin/379937 "2025-07-09T09:22:29Z")

</div>

I am using logstash-9.0 version and I try to consume records from kafka using kafka input plugin using sasl\_jaas OAUTHBAREEER method I got an issue in below and I have given logstash kafka-input plugin config also Log …

---

## [Snowflake RSA Key for jdbc auth in Logstash](https://discuss.elastic.co/t/snowflake-rsa-key-for-jdbc-auth-in-logstash/379920)

<div class="topic-metadata">

**Author:** [@random\_cauliflower](https://discuss.elastic.co/u/random_cauliflower)\
**Replies:** 1\
**Last updated:** [July 8, 2025, 2:46pm UTC](https://discuss.elastic.co/t/snowflake-rsa-key-for-jdbc-auth-in-logstash/379920 "2025-07-08T14:46:55Z")

</div>

Hello! I'm trying to use jdbc input plugin to connect to snowflake. The snowflake jdbc driver has a private\_key\_file parameter to specify an RSA key. This seems to be missing from the jdbc input configuration options at …

---

## [New logstash installation is not working](https://discuss.elastic.co/t/new-logstash-installation-is-not-working/379824)

<div class="topic-metadata">

**Author:** [@Luis\_Moy](https://discuss.elastic.co/u/Luis_Moy)\
**Replies:** 11\
**Last updated:** [July 6, 2025, 7:29pm UTC](https://discuss.elastic.co/t/new-logstash-installation-is-not-working/379824 "2025-07-06T19:29:50Z")

</div>

Hello I want to install logstash in red hat linux 9. according with this documentation, because i need this specific version. I followed the instructions. downloaded from the github the version, and using jdk 11 from…

---

## [Out of Memory at Beats Input](https://discuss.elastic.co/t/out-of-memory-at-beats-input/376135)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 4\
**Last updated:** [July 4, 2025, 7:54am UTC](https://discuss.elastic.co/t/out-of-memory-at-beats-input/376135 "2025-07-04T07:54:49Z")

</div>

Hi, From time to time we get this error with our logstashes: 2025-03-19T16:13:36,640\]\[INFO \]\[org.logstash.beats.BeatsHandler\]\[beats-input\] \[local: 192.168.16.76:6044, remote: 192.168.15.127:52442\] Handling exception:ja…

---

## [Starting Point to Tune Logstash](https://discuss.elastic.co/t/starting-point-to-tune-logstash/379301)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 9\
**Last updated:** [July 4, 2025, 7:10am UTC](https://discuss.elastic.co/t/starting-point-to-tune-logstash/379301 "2025-07-04T07:10:25Z")

</div>

Hi there i have a dedicated logstash machine with 16 cores and 32 Gb RAM and multiple pipelines inside it. There are 3 heavy pipelines(complex filters and high event rate). what is a good starting point to make a globa…

---

## [Logstash stops inputs after update](https://discuss.elastic.co/t/logstash-stops-inputs-after-update/379757)

<div class="topic-metadata">

**Author:** [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Replies:** 3\
**Last updated:** [July 4, 2025, 7:03am UTC](https://discuss.elastic.co/t/logstash-stops-inputs-after-update/379757 "2025-07-04T07:03:08Z")

</div>

We currently try to update our logstash servers from 8.2.0 to 8.18.x (and later 9.x). In Version 8.18.x we face an issue with logstash. I tried to find the exact version which is failing and found that with 8.11.4 every…

---

## [Convert data from UTC to localtime "Europe/Warsaw"](https://discuss.elastic.co/t/convert-data-from-utc-to-localtime-europe-warsaw/379664)

<div class="topic-metadata">

**Author:** [@Nevov21](https://discuss.elastic.co/u/Nevov21)\
**Replies:** 2\
**Last updated:** [July 3, 2025, 7:44am UTC](https://discuss.elastic.co/t/convert-data-from-utc-to-localtime-europe-warsaw/379664 "2025-07-03T07:44:28Z")

</div>

Hello, I'm trying to convert UTC time to my timezone "Europe/Warsaw" in logstash pipeline but it didnt work. This is my filter in pipeline: filter { date { match =\> \["\[fields\]\[timestamp\]", "ISO8601", "UNIX\_MS"\] …

---

## [Logstash Kafka Input Plugin Fails to Load OAUTHBEARER strimzi CallbackHandler Class](https://discuss.elastic.co/t/logstash-kafka-input-plugin-fails-to-load-oauthbearer-strimzi-callbackhandler-class/379464)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 1\
**Last updated:** [July 1, 2025, 12:16pm UTC](https://discuss.elastic.co/t/logstash-kafka-input-plugin-fails-to-load-oauthbearer-strimzi-callbackhandler-class/379464 "2025-07-01T12:16:53Z")

</div>

Hi Experts, I'm encountering a Kafka OAuth setup issue in Logstash where it fails to load the JaasClientOauthLoginCallbackHandler class from the Strimzi libraries. Error Message: ConfigException: Invalid value io.stri…

---

## [Logstash-output-elasticsearch Connection reset while trying to send bulk request to elasticsearch](https://discuss.elastic.co/t/logstash-output-elasticsearch-connection-reset-while-trying-to-send-bulk-request-to-elasticsearch/379398)

<div class="topic-metadata">

**Author:** [@Advay](https://discuss.elastic.co/u/Advay)\
**Replies:** 21\
**Last updated:** [June 30, 2025, 12:46pm UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-connection-reset-while-trying-to-send-bulk-request-to-elasticsearch/379398 "2025-06-30T12:46:14Z")

</div>

We are encountering an issue in our Logstash cluster and would appreciate your assistance in investigating and resolving it. Upon starting the Logstash cluster, we are consistently observing the following warning messag…

---

## [How to use ssl\_certificate\_authorities in Logstash?](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517)

<div class="topic-metadata">

**Author:** [@HarimbolaSantatra](https://discuss.elastic.co/u/HarimbolaSantatra)\
**Replies:** 6\
**Last updated:** [June 30, 2025, 6:56am UTC](https://discuss.elastic.co/t/how-to-use-ssl-certificate-authorities-in-logstash/379517 "2025-06-30T06:56:47Z")

</div>

I have the same issue discussed in this question. The error log is: sept. 12 14:57:47 local logstash\[45016\]: # File does not exist or cannot be opened /etc/logstash/certs/http\_ca.crt sept. 12 14:57:47 local logsta…

---

## [How to Access S3 bucket and list the files using logstash?](https://discuss.elastic.co/t/how-to-access-s3-bucket-and-list-the-files-using-logstash/379562)

<div class="topic-metadata">

**Author:** [@vijay117](https://discuss.elastic.co/u/vijay117)\
**Replies:** 1\
**Last updated:** [June 27, 2025, 6:52pm UTC](https://discuss.elastic.co/t/how-to-access-s3-bucket-and-list-the-files-using-logstash/379562 "2025-06-27T18:52:45Z")

</div>

How to Access S3 bucket and list the files using logstash

---

## [1 pipline not working](https://discuss.elastic.co/t/1-pipline-not-working/379542)

<div class="topic-metadata">

**Author:** [@Himanshu\_Yadav1](https://discuss.elastic.co/u/Himanshu_Yadav1)\
**Replies:** 1\
**Last updated:** [June 26, 2025, 5:18pm UTC](https://discuss.elastic.co/t/1-pipline-not-working/379542 "2025-06-26T17:18:04Z")

</div>

Hi Team, ELK version : I have setup one pipeline in logstash . In input i am using 4 file input for different files ingestion and in output same 4 i am pointing to elasticsearch . In kibana i am getting 4 different in…

---

## [Filebeats (Beats) and Logstash Best Practices Deployment Architecture](https://discuss.elastic.co/t/filebeats-beats-and-logstash-best-practices-deployment-architecture/379511)

<div class="topic-metadata">

**Author:** [@Matthew1](https://discuss.elastic.co/u/Matthew1)\
**Replies:** 0\
**Last updated:** [June 26, 2025, 8:49am UTC](https://discuss.elastic.co/t/filebeats-beats-and-logstash-best-practices-deployment-architecture/379511 "2025-06-26T08:49:53Z")

</div>

Hi Elastics Forum, I am trying to Forward Network Device logs in CEF via syslog into 2 different logstash for HA (High Availabilty) and load balancing. I have check that It can use Filebeats with logstash ouput and load…

---

## [Logstash TLS enabled](https://discuss.elastic.co/t/logstash-tls-enabled/379213)

<div class="topic-metadata">

**Author:** [@devops\_training](https://discuss.elastic.co/u/devops_training)\
**Replies:** 3\
**Last updated:** [June 25, 2025, 6:01am UTC](https://discuss.elastic.co/t/logstash-tls-enabled/379213 "2025-06-25T06:01:33Z")

</div>

I have enabled TLS using the below config. output { if \[type\] == "dba" { elasticsearch { ecs\_compatibility =\> disabled hosts =\> \["https://${\*\*\*\*\*\*\*\*\*\*\*\*\*\*}:443"\] ssl =\> true cacert =\> "${ES…

---

## [Need to upload Files as gz on to S3](https://discuss.elastic.co/t/need-to-upload-files-as-gz-on-to-s3/379436)

<div class="topic-metadata">

**Author:** [@suhassalavathsa782](https://discuss.elastic.co/u/suhassalavathsa782)\
**Replies:** 1\
**Last updated:** [June 24, 2025, 1:06pm UTC](https://discuss.elastic.co/t/need-to-upload-files-as-gz-on-to-s3/379436 "2025-06-24T13:06:39Z")

</div>

Hi, I am working on a functionality with logstash where it reads logs from AWS MSK Kafka and sends it to S3. I use the S3 output plugin and it sends in its default format as a .txt file. My requirement was to send logs b…

---

## [Unable to Analyze Invalid Beats Protocol Frame](https://discuss.elastic.co/t/unable-to-analyze-invalid-beats-protocol-frame/379399)

<div class="topic-metadata">

**Author:** [@Advay](https://discuss.elastic.co/u/Advay)\
**Replies:** 2\
**Last updated:** [June 22, 2025, 8:26pm UTC](https://discuss.elastic.co/t/unable-to-analyze-invalid-beats-protocol-frame/379399 "2025-06-22T20:26:08Z")

</div>

Dears, I’m currently troubleshooting an issue with my Logstash cluster and would appreciate some guidance. I’m consistently seeing the following warning in the Logstash logs: org.logstash.beats.InvalidFrameProtocolExc…

---

## [Logstash not sends all data to ES](https://discuss.elastic.co/t/logstash-not-sends-all-data-to-es/379380)

<div class="topic-metadata">

**Author:** [@Mercato\_Dev](https://discuss.elastic.co/u/Mercato_Dev)\
**Replies:** 1\
**Last updated:** [June 21, 2025, 11:33am UTC](https://discuss.elastic.co/t/logstash-not-sends-all-data-to-es/379380 "2025-06-21T11:33:45Z")

</div>

I have 262K item in DB but logstash send only 228K to ES this is the logstash query input { jdbc { jdbc\_default\_timezone =\> "UTC" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_driver\_library =\> "/usr/share/logs…

---

## [Could not load FFI Provider: (NotImplementedError) FFI not available: null](https://discuss.elastic.co/t/could-not-load-ffi-provider-notimplementederror-ffi-not-available-null/363551)

<div class="topic-metadata">

**Author:** [@rohit\_dhiman](https://discuss.elastic.co/u/rohit_dhiman)\
**Replies:** 12\
**Last updated:** [June 18, 2025, 5:02pm UTC](https://discuss.elastic.co/t/could-not-load-ffi-provider-notimplementederror-ffi-not-available-null/363551 "2025-06-18T17:02:21Z")

</div>

1. Logstash version: 8.3.2 2. Logstash installation source: RPM 3. Running logstash by executing below command inside directory /usr/share/logstash/bin ./logstash -f /etc/logstash/conf.d/app-uat-vl…

---

## [Jdbc\_stating trowing raise\_pool\_timeout exception](https://discuss.elastic.co/t/jdbc-stating-trowing-raise-pool-timeout-exception/379144)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 5\
**Last updated:** [June 17, 2025, 10:44pm UTC](https://discuss.elastic.co/t/jdbc-stating-trowing-raise-pool-timeout-exception/379144 "2025-06-17T22:44:45Z")

</div>

Hello everyone, I am using jdbc\_static to populate my lookup table and, when I have increased my pipeline workers from 8 to 32, I am starting receiving this error: Exception when executing Jdbc query {:lookup\_id=\>"talo…

---

## [Pipelines are not loading](https://discuss.elastic.co/t/pipelines-are-not-loading/378936)

<div class="topic-metadata">

**Author:** [@shailendra.rastogi](https://discuss.elastic.co/u/shailendra.rastogi)\
**Replies:** 6\
**Last updated:** [June 17, 2025, 5:57am UTC](https://discuss.elastic.co/t/pipelines-are-not-loading/378936 "2025-06-17T05:57:23Z")

</div>

HI , logstash version 9.0.1 The logstash is running fine however the pipelines are not loading getting \[ERROR\]\[logstash.config.sourceloader\] No configuration found in the configured sources. List of pipelines to be lo…

---

## [Ticket SNOW form Kibana](https://discuss.elastic.co/t/ticket-snow-form-kibana/379166)

<div class="topic-metadata">

**Author:** [@Dariia\_Hrebenichenko](https://discuss.elastic.co/u/Dariia_Hrebenichenko)\
**Replies:** 2\
**Last updated:** [June 13, 2025, 4:03pm UTC](https://discuss.elastic.co/t/ticket-snow-form-kibana/379166 "2025-06-13T16:03:03Z")

</div>

Hello everybody! I need to create tickets in ServiceNow what based on information in Kibana. I already have alerting system what takes information from kibana.log and uses logstash to send different emails. Now I need…

---

## [Integrating rsyslog to logstash to include only fortinet syslog](https://discuss.elastic.co/t/integrating-rsyslog-to-logstash-to-include-only-fortinet-syslog/378912)

<div class="topic-metadata">

**Author:** [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Replies:** 3\
**Last updated:** [June 10, 2025, 2:24pm UTC](https://discuss.elastic.co/t/integrating-rsyslog-to-logstash-to-include-only-fortinet-syslog/378912 "2025-06-10T14:24:33Z")

</div>

I have integrated rsyslog with logstash but cannot see the output in a standard output there are no error logs This is the logstash conf t input { udp { host =\> "10.200.253.122" port =\> 5140 type =\> "for…

---

## [Why does Logstash close idle TCP connections with RST instead of FIN?](https://discuss.elastic.co/t/why-does-logstash-close-idle-tcp-connections-with-rst-instead-of-fin/379000)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 0\
**Last updated:** [June 9, 2025, 12:03pm UTC](https://discuss.elastic.co/t/why-does-logstash-close-idle-tcp-connections-with-rst-instead-of-fin/379000 "2025-06-09T12:03:44Z")

</div>

Hi Elastic team, I’m trying to better understand how client\_inactivity\_timeout works in Logstash, specifically in relation to how it closes idle TCP connections. Context: We have Winlogbeat agents sending logs over TCP…

---

## [Logstash output traffic significantly higher than input (minimal transformations) + TCP RST](https://discuss.elastic.co/t/logstash-output-traffic-significantly-higher-than-input-minimal-transformations-tcp-rst/378868)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 23\
**Last updated:** [June 9, 2025, 1:38pm UTC](https://discuss.elastic.co/t/logstash-output-traffic-significantly-higher-than-input-minimal-transformations-tcp-rst/378868 "2025-06-09T13:38:56Z")

</div>

Hi, I'm investigating a situation where Logstash receives a certain amount of data, but the traffic sent from Logstash to Elasticsearch is significantly larger, even though I perform minimal transformations. Setup Inp…

---

## [Logstash Filters not functioning](https://discuss.elastic.co/t/logstash-filters-not-functioning/378992)

<div class="topic-metadata">

**Author:** [@JJ192](https://discuss.elastic.co/u/JJ192)\
**Replies:** 1\
**Last updated:** [June 9, 2025, 8:58am UTC](https://discuss.elastic.co/t/logstash-filters-not-functioning/378992 "2025-06-09T08:58:20Z")

</div>

Hello, it seems that my filters are not working. I am not getting any errors and all data is available in the dashboard, but not with my filters applied. Is there any obvious issues that can be seen? Thanks!

---

## [Conditional if not working as expected](https://discuss.elastic.co/t/conditional-if-not-working-as-expected/378984)

<div class="topic-metadata">

**Author:** [@JJ192](https://discuss.elastic.co/u/JJ192)\
**Replies:** 1\
**Last updated:** [June 8, 2025, 8:30pm UTC](https://discuss.elastic.co/t/conditional-if-not-working-as-expected/378984 "2025-06-08T20:30:43Z")

</div>

Hello, I am attempting to add a tag to certain lines imported from a CSV file, depending on "10" being present in the "state\_id" field. I am not getting any error messages but the output is creating two indexes with all…

---

## [\[ERROR\]\[logstash.agent \] Failed to execute action](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action/378805)

<div class="topic-metadata">

**Author:** [@Reyhan](https://discuss.elastic.co/u/Reyhan)\
**Replies:** 2\
**Last updated:** [June 3, 2025, 8:41am UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action/378805 "2025-06-03T08:41:58Z")

</div>

Was working on logstash and got stuck with this error: \< \[2025-05-28T06:57:49,669\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"Lo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=4)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=6)
