# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=57

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 58

---

## [Mariadb-java-client-3.2.0.jar never found](https://discuss.elastic.co/t/mariadb-java-client-3-2-0-jar-never-found/344350)

<div class="topic-metadata">

**Author:** [@loekvankooten](https://discuss.elastic.co/u/loekvankooten)\
**Replies:** 2\
**Last updated:** [October 3, 2023, 10:00pm UTC](https://discuss.elastic.co/t/mariadb-java-client-3-2-0-jar-never-found/344350 "2023-10-03T22:00:39Z")

</div>

I'm on Windows 11. Elastic Search is in D:\\ES. Logstash is in D:\\LS. In D:\\LS is ls.conf: input { jdbc { jdbc\_driver\_library =\> "D:/LS/mariadb-java-client-3.2.0.jar" jdbc\_driver\_class =\> "org.mariadb.jdbc.Dri…

---

## [Port configured for logstash does not turn up (5044)](https://discuss.elastic.co/t/port-configured-for-logstash-does-not-turn-up-5044/344213)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 13\
**Last updated:** [October 3, 2023, 8:11am UTC](https://discuss.elastic.co/t/port-configured-for-logstash-does-not-turn-up-5044/344213 "2023-10-03T08:11:14Z")

</div>

I have configured a logstash on my server and the configurations in /etc/logstash/conf.d/beats.conf file are as follows. input { beats { port =\> 5044 host =\> "192.168.14.189" } } filter { if \[type\] =="sy…

---

## [Logstash Upgrade and 8.10.1 net snmp error](https://discuss.elastic.co/t/logstash-upgrade-and-8-10-1-net-snmp-error/343307)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 6\
**Last updated:** [October 3, 2023, 1:39am UTC](https://discuss.elastic.co/t/logstash-upgrade-and-8-10-1-net-snmp-error/343307 "2023-10-03T01:39:51Z")

</div>

After the upgrade logstash doesn't start Any else experience this? Thank you! org.jruby.exceptions.LoadError: (LoadError) no such file to load -- net/smtp at org.jruby.RubyKernel.require(org/jruby/RubyKernel.java:1057)…

---

## [Multiple TCP output plugins in Logstash](https://discuss.elastic.co/t/multiple-tcp-output-plugins-in-logstash/344204)

<div class="topic-metadata">

**Author:** [@Mano](https://discuss.elastic.co/u/Mano)\
**Replies:** 2\
**Last updated:** [October 2, 2023, 3:37pm UTC](https://discuss.elastic.co/t/multiple-tcp-output-plugins-in-logstash/344204 "2023-10-02T15:37:07Z")

</div>

Hi, I am planning to send logs to 2 different servers over TCP. My output section looks looks something like, output { tcp { host =\> "XX.X.XXX.XXX" #ip address of server 1 m…

---

## [Error escaping slash](https://discuss.elastic.co/t/error-escaping-slash/344169)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 4\
**Last updated:** [October 2, 2023, 7:02am UTC](https://discuss.elastic.co/t/error-escaping-slash/344169 "2023-10-02T07:02:37Z")

</div>

I'm using, logstash 8.9.1 or version 7.14.1, with pipelines managed by kibana in version 8, and 7 with local configuration, having the same result I have this config to remove \\ from the message: mutate { gsub …

---

## [Still facing an issue with Json multiline](https://discuss.elastic.co/t/still-facing-an-issue-with-json-multiline/344168)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 4\
**Last updated:** [October 1, 2023, 7:37pm UTC](https://discuss.elastic.co/t/still-facing-an-issue-with-json-multiline/344168 "2023-10-01T19:37:06Z")

</div>

Hi Team, I am still having a difficulty parse json multiline and not getting any clue about it. Can someone please help with it? Here are the original message \[ { "post\_title": "Windemuller", "grou…

---

## [Pipeline not able to connect to MySQL Aurora Database usine useSSL=True](https://discuss.elastic.co/t/pipeline-not-able-to-connect-to-mysql-aurora-database-usine-usessl-true/344152)

<div class="topic-metadata">

**Author:** [@Ritesh\_Uniyal](https://discuss.elastic.co/u/Ritesh_Uniyal)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 4:58pm UTC](https://discuss.elastic.co/t/pipeline-not-able-to-connect-to-mysql-aurora-database-usine-usessl-true/344152 "2023-09-29T16:58:11Z")

</div>

We have a pipeline that connects to db Mysql aurora. We have enabled ssl on db and its failing to connect. We have tried using both verifyServerCertificate=true&useSSL=true&requireSSL=true and useSSL=true&requireSSL=true&…

---

## [Logstash wrapping the data with document](https://discuss.elastic.co/t/logstash-wrapping-the-data-with-document/344135)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 4\
**Last updated:** [September 29, 2023, 1:25pm UTC](https://discuss.elastic.co/t/logstash-wrapping-the-data-with-document/344135 "2023-09-29T13:25:13Z")

</div>

I'm sending data with python on both kafka and http request however kafka pipeline wraps the data with "document". the data on the top is coming from kafka pipeline and the below from http pipeline And these are my…

---

## [Failed to parse field \[document.error\] of type \[text\] in document](https://discuss.elastic.co/t/failed-to-parse-field-document-error-of-type-text-in-document/344108)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 5\
**Last updated:** [September 29, 2023, 12:19pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-document-error-of-type-text-in-document/344108 "2023-09-29T12:19:35Z")

</div>

I'm sending data to logstash through kafka python client. this is the object i send {"user\_id":"kafka12","service\_name":"kafka12","activity\_type":"kafka","error":{"message":"Invalid username","component\_id":"Y456"},"add…

---

## [Could not find logstash.yml](https://discuss.elastic.co/t/could-not-find-logstash-yml/343776)

<div class="topic-metadata">

**Author:** [@atulrana20](https://discuss.elastic.co/u/atulrana20)\
**Replies:** 16\
**Last updated:** [September 29, 2023, 7:29am UTC](https://discuss.elastic.co/t/could-not-find-logstash-yml/343776 "2023-09-29T07:29:50Z")

</div>

WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults Could not find log4j2 configuration at p…

---

## [Having trouble adding muliple tables using logstash](https://discuss.elastic.co/t/having-trouble-adding-muliple-tables-using-logstash/344020)

<div class="topic-metadata">

**Author:** [@Mustapha\_Hadj](https://discuss.elastic.co/u/Mustapha_Hadj)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 11:30pm UTC](https://discuss.elastic.co/t/having-trouble-adding-muliple-tables-using-logstash/344020 "2023-09-28T23:30:01Z")

</div>

so i have 7 tables in my sql database and i'v been trying to add all of them to an index trough logstash jdbc using a query file , the query goes somthing like SELECT \* FROM \[TABLE\]; SELECT \* FROM \[TABLE\]; SELECT \* FR…

---

## [Logstash never picked up any logs. I mean it never parse any logs except 2 log lines for the entire day](https://discuss.elastic.co/t/logstash-never-picked-up-any-logs-i-mean-it-never-parse-any-logs-except-2-log-lines-for-the-entire-day/344063)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [September 28, 2023, 3:55pm UTC](https://discuss.elastic.co/t/logstash-never-picked-up-any-logs-i-mean-it-never-parse-any-logs-except-2-log-lines-for-the-entire-day/344063 "2023-09-28T15:55:40Z")

</div>

I have using logstash 8.10.0 for windows and linux downloaded from elastic.co downloads. I could hardly see 2 events ingested by logstash. logstash-plain.log does not have any error after pipeline\_running. configura…

---

## [Logstash OSS distribution containing EULA](https://discuss.elastic.co/t/logstash-oss-distribution-containing-eula/341230)

<div class="topic-metadata">

**Author:** [@MkGitRepo](https://discuss.elastic.co/u/MkGitRepo)\
**Replies:** 4\
**Last updated:** [September 28, 2023, 1:07pm UTC](https://discuss.elastic.co/t/logstash-oss-distribution-containing-eula/341230 "2023-09-28T13:07:20Z")

</div>

Hi, I was checking the license for logstash-oss and found a notice.txt file containing licenses of few dependencies. One among them is the END USER LICENSE AGREEMENT RED HAT UNIVERSAL BASE IMAGE which is a notice adde…

---

## [Mapper\_parsing\_exception", "reason"=\>"object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete value"}}}}](https://discuss.elastic.co/t/mapper-parsing-exception-reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/344000)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 12:27pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/344000 "2023-09-28T12:27:48Z")

</div>

Please suggest me if there is a work around. \[2023-09-27T14:56:22,072\]\[INFO \]\[logstash.javapipeline \]\[main\] Pipeline started {"pipeline.id"=\>"main"}\[2023-09-27T14:56:22,094\]\[INFO \]\[logstash.agent \] Pipeline…

---

## [How catch "user.name" parameter from winlog with logstash](https://discuss.elastic.co/t/how-catch-user-name-parameter-from-winlog-with-logstash/343971)

<div class="topic-metadata">

**Author:** [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Replies:** 5\
**Last updated:** [September 28, 2023, 12:02pm UTC](https://discuss.elastic.co/t/how-catch-user-name-parameter-from-winlog-with-logstash/343971 "2023-09-28T12:02:54Z")

</div>

Hello, i write the following row in pipeline in the filter section: mutate { add\_field =\> {"parameter" =\> "{\[user\]\[name\]}" } } it do not work. the parameter field is fill with "{\[user\]\[name\]}" as text and original va…

---

## [Logstash not pushing logs to loki](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-loki/344007)

<div class="topic-metadata">

**Author:** [@sheldor](https://discuss.elastic.co/u/sheldor)\
**Replies:** 2\
**Last updated:** [September 28, 2023, 6:45am UTC](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-loki/344007 "2023-09-28T06:45:00Z")

</div>

Below is my logstash config input { file { ecs\_compatibility =\> disabled path =\> \[ "/a/logs/project\_apps/\*\*/\*.log" \] start\_position =\> beginning exclude =\> \[ …

---

## [Error The given configuration is invalid. Reason: Unable to configure plugins](https://discuss.elastic.co/t/error-the-given-configuration-is-invalid-reason-unable-to-configure-plugins/344018)

<div class="topic-metadata">

**Author:** [@HectorCy10](https://discuss.elastic.co/u/HectorCy10)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:32pm UTC](https://discuss.elastic.co/t/error-the-given-configuration-is-invalid-reason-unable-to-configure-plugins/344018 "2023-09-27T22:32:18Z")

</div>

Hi everyone, i have the next error but i can not find any topic to solve this issue

---

## [Parse rabbitmq json log](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 5\
**Last updated:** [September 27, 2023, 9:32pm UTC](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009 "2023-09-27T21:32:20Z")

</div>

Hi, got json log message from rabbit as {"timestamp":"2022-12-21 03:14:59.977922+02:00","level":"error","msg":"Error on AMQP connection \<0.32551.1583\>: enotconn (socket is not connected)","domain":"rabbitmq.connection",…

---

## [Shipping access logs logstash to logstash using http plugins](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 12:42pm UTC](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980 "2023-09-27T12:42:38Z")

</div>

Hi We have a setup where we ship logs between systems via logstash to logstash using http plugins. The access logs are in ecs format. The problem is, logstash overwrites http, url and others fields, with it's own transp…

---

## [Json multiline codec is not working and messages are not getting parsed](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 16\
**Last updated:** [September 27, 2023, 10:44am UTC](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172 "2023-09-27T10:44:41Z")

</div>

Hi Team, I an working on logstash json parser and messages are not getting parsed; any clue what could be wrong? Here are original messages \[ { "time": "12/Aug/2023:13:20:52 +0000", "source\_ip": "117.193.217.44",…

---

## [Logstash 8.10.2 fails to start in docker without any log output](https://discuss.elastic.co/t/logstash-8-10-2-fails-to-start-in-docker-without-any-log-output/343973)

<div class="topic-metadata">

**Author:** [@tzfun](https://discuss.elastic.co/u/tzfun)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:36am UTC](https://discuss.elastic.co/t/logstash-8-10-2-fails-to-start-in-docker-without-any-log-output/343973 "2023-09-27T10:36:03Z")

</div>

I pulled image docker.elastic.co/logstash/logstash:8.10.2 to run a container, and it works in docker on mac os but neither works in docker on Debian 11. Docker for mac and debian 11 are both version 24.0.6. There is no…

---

## [Mysql slow log](https://discuss.elastic.co/t/mysql-slow-log/343917)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 8:28pm UTC](https://discuss.elastic.co/t/mysql-slow-log/343917 "2023-09-26T20:28:54Z")

</div>

Hi all, I am not able to successfully parse Mysql's slow log using logstash. The log file: # Time: 2018-02-27T09:20:14.122543Z # User@Host: user\[user\] @ \[nnn.nnn.nnn.nn\] Id: 148 # Query\_time: 10.275441 Lock\_time: …

---

## [Error when querying Elasticsearch from Logstash](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:19pm UTC](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907 "2023-09-26T15:19:17Z")

</div>

I'm using Elasticsearch input plugin in logstash to query the Elastic data. But I'm getting the below error Ignoring clear\_scroll exception {:message=\>"\[404\] {\\"succeeded\\":true,\\"num\_freed\\":0}", :exception=\>Elasticsea…

---

## [Can't connect to autonomoous oracledb cloud](https://discuss.elastic.co/t/cant-connect-to-autonomoous-oracledb-cloud/343081)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 2:54pm UTC](https://discuss.elastic.co/t/cant-connect-to-autonomoous-oracledb-cloud/343081 "2023-09-26T14:54:13Z")

</div>

Hi I can't connect to an oracle db in oracle cloud, it gives me an error Got minus one from a read call. I've been trying many things in the discussions but nothing seems to work for me: this is my input: input{ j…

---

## [How to parse values as key value not array](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896)

<div class="topic-metadata">

**Author:** [@dreambeam](https://discuss.elastic.co/u/dreambeam)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896 "2023-09-26T14:02:17Z")

</div>

Hi there. I am trying parse a text file containing values below. 15, 3241 16, 800 17, 1 Below if my logstash configuration. When I checked in Kibana , I have the field document displayed as a array. "hcount": \[ 800 \] …

---

## [Logstash google pubsub output plugin](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791)

<div class="topic-metadata">

**Author:** [@Bala\_Joshi](https://discuss.elastic.co/u/Bala_Joshi)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:21am UTC](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791 "2023-09-26T10:21:32Z")

</div>

hello All, I am trying to injest to google pubsub topic from logstash server. Below are the configuration google\_pubsub { project\_id =\> "xx" topic =\> "xx" json\_key\_file =\> "xx" #Options for configuring the upload …

---

## [Encounter error "Saved field "timeStamp" of data view "index-name" is invalid for use with the "Date Histogram" aggregation. Please select a new field](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798)

<div class="topic-metadata">

**Author:** [@Long\_Nguyen](https://discuss.elastic.co/u/Long_Nguyen)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:20pm UTC](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798 "2023-09-25T18:20:16Z")

</div>

Hello everyone, I'm running Elastic Stack 8.3.0. I encounter the following error in Kibana "Discover" with an index: The index is indexed from the following csv file (some fields have been redacted): timeStamp…

---

## [.JSON Conf File for Logstash](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638)

<div class="topic-metadata">

**Author:** [@Google-Cloud-DFIR](https://discuss.elastic.co/u/Google-Cloud-DFIR)\
**Replies:** 19\
**Last updated:** [September 25, 2023, 4:17pm UTC](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638 "2023-09-25T16:17:01Z")

</div>

Hello, I've been trying to configure this .conf file to help parse out .json files correctly. This script is able to ingest Google Cloud Audit Logs (in .json), but fails to parse it correctly: input { # stdin {} …

---

## [How does logstash handle multiline logs in a load balancing configuration](https://discuss.elastic.co/t/how-does-logstash-handle-multiline-logs-in-a-load-balancing-configuration/343780)

<div class="topic-metadata">

**Author:** [@Ror](https://discuss.elastic.co/u/Ror)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 3:18pm UTC](https://discuss.elastic.co/t/how-does-logstash-handle-multiline-logs-in-a-load-balancing-configuration/343780 "2023-09-25T15:18:17Z")

</div>

Hi all, We collect our infrastructure logs with filebeat on elastic cloud. We'd like to add a logstash cluster (multiple logstash instances load-balanced) between our filebeat agents and our elastic cloud cluster. The …

---

## [GROK pattern help for Audit Log](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 2:48pm UTC](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761 "2023-09-25T14:48:14Z")

</div>

I am struggling to find an appropriate GROK pattern to appropriately dissect my log that is being generated by the xpack Audit. My Logs currently look like {"type":"audit", "timestamp":"2023-09-07T14:34:58,359+0100", "…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=56)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=58)
