# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=53

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 54

---

## [This error seems to be related to mapping issues in Elasticsearch, below error found in logstash](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414)

<div class="topic-metadata">

**Author:** [@Sreecharanhope](https://discuss.elastic.co/u/Sreecharanhope)\
**Replies:** 4\
**Last updated:** [November 5, 2023, 2:38am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414 "2023-11-05T02:38:14Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [This error seems to be related to mapping issues in Elasticsearch, ](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427)

<div class="topic-metadata">

**Author:** [@jamesjames](https://discuss.elastic.co/u/jamesjames)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 4:06pm UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427 "2023-11-04T16:06:29Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [Extract JSON log from JSON](https://discuss.elastic.co/t/extract-json-log-from-json/346353)

<div class="topic-metadata">

**Author:** [@AlarleCKe](https://discuss.elastic.co/u/AlarleCKe)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 11:33am UTC](https://discuss.elastic.co/t/extract-json-log-from-json/346353 "2023-11-04T11:33:26Z")

</div>

Hi everyone, I´m trying to create an index based on a script output. The script itself creates an NDJSON like: {"packages/current\_version":"3.7.3-2+deb10u5","packages/candidate\_version":"3.7.3-2+deb10u6","packages/prio…

---

## [Logstash http\_pollar Rest API push more than 1000 records](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374)

<div class="topic-metadata">

**Author:** [@puneetsharma2](https://discuss.elastic.co/u/puneetsharma2)\
**Replies:** 12\
**Last updated:** [November 3, 2023, 6:35pm UTC](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374 "2023-11-03T18:35:20Z")

</div>

Logstash http\_pollar Rest API push more than 1000 records As we are using HTTP\_POLLAR to execute the rest API and push the response in elastic index in one go. But default only 1000 records are pushing in elastic. How …

---

## [Logstash + S3 Input plugin with High Availability](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370)

<div class="topic-metadata">

**Author:** [@Pedro\_Baldanta](https://discuss.elastic.co/u/Pedro_Baldanta)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 2:01pm UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370 "2023-11-03T14:01:38Z")

</div>

Hi all: I need to implement high availability of Logstash reading log files from S3. Is there any way to implement HA via scaleout without duplicating the events? Each VM is going to store until which file has read, s…

---

## [Online monitoring log sending devices in logstash machine](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337)

<div class="topic-metadata">

**Author:** [@Mohsen\_R.Marandi](https://discuss.elastic.co/u/Mohsen_R.Marandi)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:24am UTC](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337 "2023-11-03T08:24:36Z")

</div>

Hi every one I have set up logstash on a large scale network. Is there a way to online monitor log sending devices? Tanks

---

## [Logstash Stuck Indexing Pipeline and throwing Error - warning: already initialized constant Manticore::Client::HttpPost](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948)

<div class="topic-metadata">

**Author:** [@mnasim1](https://discuss.elastic.co/u/mnasim1)\
**Replies:** 5\
**Last updated:** [November 3, 2023, 5:52am UTC](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948 "2023-11-03T05:52:57Z")

</div>

Logstash was running fine and successfully reading data from the Postgres Database for indexing. However, it suddenly started throwing the following errors, causing the indexing pipeline to become stuck: logstash-8.6.2…

---

## [Logstash 8.10.4 breaking changes](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [November 3, 2023, 4:55am UTC](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312 "2023-11-03T04:55:19Z")

</div>

"status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[host\] of type \[text\] in document with id 'xxxxxxx'. added this to resolve the above mutate { rename =\> { "\[host\]" =\> …

---

## [Logstash multiline charset =\> "UTF-8"](https://discuss.elastic.co/t/logstash-multiline-charset-utf-8/346146)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 4\
**Last updated:** [November 2, 2023, 5:14pm UTC](https://discuss.elastic.co/t/logstash-multiline-charset-utf-8/346146 "2023-11-02T17:14:56Z")

</div>

\[2023-10-31T12:01:11,534\]\[WARN \]\[logstash.codecs.multiline\]\[main\]\[a029b778777f02de25308ca25697ff60da99dc3bc13beaf4e1c2d010740b27d8\] Received an event that has a different character encoding than you configured. {:text=\>"…

---

## [How can you know that a logstash input query has finished](https://discuss.elastic.co/t/how-can-you-know-that-a-logstash-input-query-has-finished/346173)

<div class="topic-metadata">

**Author:** [@dimitris\_sb](https://discuss.elastic.co/u/dimitris_sb)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-can-you-know-that-a-logstash-input-query-has-finished/346173 "2023-11-02T15:22:31Z")

</div>

Hi All, If you deploy a logstash pipeline using the input plugin with a query, how could you know that ingesting data has been completed to decommission it? Thank you in advance for your insight

---

## [Data not updating on kibana](https://discuss.elastic.co/t/data-not-updating-on-kibana/346297)

<div class="topic-metadata">

**Author:** [@IJ\_Oma](https://discuss.elastic.co/u/IJ_Oma)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:55pm UTC](https://discuss.elastic.co/t/data-not-updating-on-kibana/346297 "2023-11-02T14:55:22Z")

</div>

Hello all, Data stopped flowing from the database jbdc through logstash to kibana across all indices. Is anyone else having same issue? For about more than a week now, data updates on kibana via logstash has been very s…

---

## [What is logstash instance?](https://discuss.elastic.co/t/what-is-logstash-instance/345357)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 10\
**Last updated:** [November 2, 2023, 2:50pm UTC](https://discuss.elastic.co/t/what-is-logstash-instance/345357 "2023-11-02T14:50:49Z")

</div>

I want to know what a logstash instance is? Is it a self-generated .conf file? Which command should I use to check which instances are running?

---

## [Undefined method \`accept' for nil:NilClass](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226)

<div class="topic-metadata">

**Author:** [@jsamuel](https://discuss.elastic.co/u/jsamuel)\
**Replies:** 4\
**Last updated:** [November 2, 2023, 1:23pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226 "2023-11-02T13:23:53Z")

</div>

At present, we are operating several instances of Elasticsearch, encompassing both 5.x and 6.x versions, and are in the process of assessing the viability of OpenSearch. However, it is imperative to maintain the current …

---

## [Ingest and Conditional Routing](https://discuss.elastic.co/t/ingest-and-conditional-routing/346231)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 6\
**Last updated:** [November 2, 2023, 1:00pm UTC](https://discuss.elastic.co/t/ingest-and-conditional-routing/346231 "2023-11-02T13:00:40Z")

</div>

I believe this is a Logstash issue, but please correct me if I am wrong. Currently, I have a Kibana instance set up with a lengthy EQL filter to search a description field for keywords. I want to do the filtering as pa…

---

## [Configuring both TLS 1.2 and TLS 1.3 in Logstash 8.8](https://discuss.elastic.co/t/configuring-both-tls-1-2-and-tls-1-3-in-logstash-8-8/346280)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 12:37pm UTC](https://discuss.elastic.co/t/configuring-both-tls-1-2-and-tls-1-3-in-logstash-8-8/346280 "2023-11-02T12:37:10Z")

</div>

In my Logstash8.8 syslog configuration file, I want to configure two TLS versions: TLS 1.2 and TLS 1.3, but it doesn't work. Can you provide the correct way to configure it? Should I create two separate inputs? tcp { i…

---

## [Disable SNI in the TLS session to when connecting to Logstash](https://discuss.elastic.co/t/disable-sni-in-the-tls-session-to-when-connecting-to-logstash/346252)

<div class="topic-metadata">

**Author:** [@jefffriedman](https://discuss.elastic.co/u/jefffriedman)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:41am UTC](https://discuss.elastic.co/t/disable-sni-in-the-tls-session-to-when-connecting-to-logstash/346252 "2023-11-02T02:41:54Z")

</div>

When using Logstash 8.3.x on Linux we can connect via SSL from a server with an IPv6 address. When using Logstash 8.4.0 and higher, we get an error trying to establish a connection. By enabling duebggng in the JVM by ad…

---

## [Logstash Sincedb duplicate entries](https://discuss.elastic.co/t/logstash-sincedb-duplicate-entries/346187)

<div class="topic-metadata">

**Author:** [@justin\_sch](https://discuss.elastic.co/u/justin_sch)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 5:46pm UTC](https://discuss.elastic.co/t/logstash-sincedb-duplicate-entries/346187 "2023-11-01T17:46:45Z")

</div>

Hey, I'm using the ELK-Stack to analyze a Log-File. Right now I clone the Log-File via SSH onto my local machine via a bash script every hour. The Logfile gets data appended every minute. This is my conf: input { …

---

## [Timestamp from log files to @timestamp](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 2:39pm UTC](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199 "2023-11-01T14:39:12Z")

</div>

Hey, !NOTE! i'm new to the elk stack in all its facettes. I have some Problems with displaying my logfiles from an laravel application. I'm running laravel on one server and my elk stack on another i installed logstas…

---

## [Log4j2 Rolling File Strategy Only Rolls Once](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320 "2023-11-01T13:48:40Z")

</div>

I'm having issues with the log4j2 rolling file appender. It only writes the first rollover file. Here's my config: status = error name = LogstashPropertiesConfig appender.console.type = Console appender.console.name =…

---

## [Logstash parse date format AM/PM](https://discuss.elastic.co/t/logstash-parse-date-format-am-pm/346115)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 3:15pm UTC](https://discuss.elastic.co/t/logstash-parse-date-format-am-pm/346115 "2023-10-31T15:15:50Z")

</div>

Hello All, I need to parse below data and send it to elastic index.For some reason index gets created but data dont come in index. I am trying to parse multiple csv file with below data. Here date format field contain A…

---

## [Logstash - Parsing fields with duplicate names](https://discuss.elastic.co/t/logstash-parsing-fields-with-duplicate-names/346131)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 1:19pm UTC](https://discuss.elastic.co/t/logstash-parsing-fields-with-duplicate-names/346131 "2023-10-31T13:19:42Z")

</div>

If I receive a log in that looks like this, how do I deal with the fact that the subfields under "records" are identical? Is there a concept of \[records\]\[operationName\]\[0\] and \[1\], for example? { "records": \[ { …

---

## [How to join two stream data sources and find matches](https://discuss.elastic.co/t/how-to-join-two-stream-data-sources-and-find-matches/346097)

<div class="topic-metadata">

**Author:** [@fim01](https://discuss.elastic.co/u/fim01)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 8:22am UTC](https://discuss.elastic.co/t/how-to-join-two-stream-data-sources-and-find-matches/346097 "2023-10-31T08:22:08Z")

</div>

I'm asking for an idea or approach to solve the following business problem: Two stream data sources (A and B) continuously ingesting events into two separate indices (A and B) in Elasticsearch. Each of them has a unique…

---

## [Syslog severity and facility not set when upgrading version](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695)

<div class="topic-metadata">

**Author:** [@Andrea\_De\_Pinto](https://discuss.elastic.co/u/Andrea_De_Pinto)\
**Replies:** 3\
**Last updated:** [October 30, 2023, 3:13pm UTC](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695 "2023-10-30T15:13:31Z")

</div>

Hi, I did the migration from the version 6.8 to the 8.9 and I have a logstash pipeline that use the syslog to feed my elasticsearch. This is the configuration I have on the 6.8 : input { syslog { type =\> "sy…

---

## [Logstash RSS plugin failed to load after fresh install](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988)

<div class="topic-metadata">

**Author:** [@developerx](https://discuss.elastic.co/u/developerx)\
**Replies:** 2\
**Last updated:** [October 30, 2023, 9:15am UTC](https://discuss.elastic.co/t/logstash-rss-plugin-failed-to-load-after-fresh-install/345988 "2023-10-30T09:15:35Z")

</div>

Hello, i've an issue with a fresh logstash installation and logstash-input-rss plugin. when trying to test the configuration for a simple RSS reader for just 1 URL i got this error: \[DEBUG\] 2023-10-29 19:57:25.354 \[Con…

---

## [Problem with Template File Not Applying Correctly in Logstash](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 7:09am UTC](https://discuss.elastic.co/t/problem-with-template-file-not-applying-correctly-in-logstash/346006 "2023-10-30T07:09:06Z")

</div>

We are experiencing an issue with Logstash where the user\_dictionary\_rules, stopwords, and synonyms data are not being properly indexed based on the template file in an EC2 environment. When these data sets, specificall…

---

## [Why is the ssl\_key\_passphrase missing in the plugins-outputs-elasticsearch?](https://discuss.elastic.co/t/why-is-the-ssl-key-passphrase-missing-in-the-plugins-outputs-elasticsearch/345999)

<div class="topic-metadata">

**Author:** [@hengya\_liu](https://discuss.elastic.co/u/hengya_liu)\
**Replies:** 6\
**Last updated:** [October 30, 2023, 6:27am UTC](https://discuss.elastic.co/t/why-is-the-ssl-key-passphrase-missing-in-the-plugins-outputs-elasticsearch/345999 "2023-10-30T06:27:43Z")

</div>

Logstash 8.10 ssl\_key\_passphrase is Missing. If we set the SSL certificate, do we have to use the unencrypted key or use a keystore?

---

## [Index Created but No Document got written](https://discuss.elastic.co/t/index-created-but-no-document-got-written/346004)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 4:57am UTC](https://discuss.elastic.co/t/index-created-but-no-document-got-written/346004 "2023-10-30T04:57:40Z")

</div>

Just set a more specific index template with a higher priority value than the more general one, and looking to apply this template instead of the general one. Then I removed related data stream (which wipes off all the r…

---

## [Logstash create many zero document indexes](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522)

<div class="topic-metadata">

**Author:** [@Amzath\_Khan](https://discuss.elastic.co/u/Amzath_Khan)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 12:28pm UTC](https://discuss.elastic.co/t/logstash-create-many-zero-document-indexes/345522 "2023-10-29T12:28:25Z")

</div>

I'm sending data from a Microsoft SQL Server database into elasticsearch using logstash 8.x. It functions well. However, logstash multiplies indexes with no documents and raises the shared. It takes over an hour to reach…

---

## [Logstash cvs plugin not sending data to index](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [October 29, 2023, 7:36am UTC](https://discuss.elastic.co/t/logstash-cvs-plugin-not-sending-data-to-index/345924 "2023-10-29T07:36:29Z")

</div>

Hello All, I have csv files under one folder in windows system and need to send the data in elastic index using logstash. I'm not sure why data is not showing in index,though index getting created. Need key and value a…

---

## [LogStash::Error: Don't know how to handle \`Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>\`](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882)

<div class="topic-metadata">

**Author:** [@fae](https://discuss.elastic.co/u/fae)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-dont-know-how-to-handle-java-illegalstateexception-for-pipelineaction-create-main/345882 "2023-10-29T06:53:11Z")

</div>

Need help troubleshooting logstash java issue, it was working fine until a while ago when it started throwing up this error below: systemctl status logstash -l ● logstash.service - Logstash service (ELK stack). Loade…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=52)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=54)
