# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=6

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 7

---

## [HTTP Output errors - failed to response when sending to Splunk HF](https://discuss.elastic.co/t/http-output-errors-failed-to-response-when-sending-to-splunk-hf/378811)

<div class="topic-metadata">

**Author:** [@bonecruizer](https://discuss.elastic.co/u/bonecruizer)\
**Replies:** 0\
**Last updated:** [June 3, 2025, 7:04am UTC](https://discuss.elastic.co/t/http-output-errors-failed-to-response-when-sending-to-splunk-hf/378811 "2025-06-03T07:04:16Z")

</div>

We have a setup where a Logstash machine (v7.17.28) sends to a Splunk Heavy Forwarder using HTTP. We see a lot of HTTP Output errors and I am unable to find the cause. All data seems to arrive correctly. The error is (…

---

## [Need to aggregate data in a CSV file based on a key](https://discuss.elastic.co/t/need-to-aggregate-data-in-a-csv-file-based-on-a-key/378642)

<div class="topic-metadata">

**Author:** [@venkatkumar229](https://discuss.elastic.co/u/venkatkumar229)\
**Replies:** 2\
**Last updated:** [May 29, 2025, 6:09am UTC](https://discuss.elastic.co/t/need-to-aggregate-data-in-a-csv-file-based-on-a-key/378642 "2025-05-29T06:09:26Z")

</div>

Hi Everyone, I have an use case where i need to aggregate the lines in a CSV file to get the sum of amount, quantity of an order based on the ordernumber. I have tried to use "aggregate" filter but i am end up getting o…

---

## [Slow down Logstash output to Elasticsearch](https://discuss.elastic.co/t/slow-down-logstash-output-to-elasticsearch/378633)

<div class="topic-metadata">

**Author:** [@natharran](https://discuss.elastic.co/u/natharran)\
**Replies:** 3\
**Last updated:** [May 28, 2025, 1:45pm UTC](https://discuss.elastic.co/t/slow-down-logstash-output-to-elasticsearch/378633 "2025-05-28T13:45:32Z")

</div>

Hello all. This might seem a bit strange but I need to slow down the Logstash output rate to Elasticsearch. The thing is that Logstash reads data from Kafka topic and after processing sends them to Elasticsearch. That's…

---

## [Cannot restart(Stop and start) Logstash](https://discuss.elastic.co/t/cannot-restart-stop-and-start-logstash/378550)

<div class="topic-metadata">

**Author:** [@Clinton\_Pillay](https://discuss.elastic.co/u/Clinton_Pillay)\
**Replies:** 9\
**Last updated:** [May 27, 2025, 6:58pm UTC](https://discuss.elastic.co/t/cannot-restart-stop-and-start-logstash/378550 "2025-05-27T18:58:30Z")

</div>

So I start my logstash conf file, which works great and does exactly what I want it to do. I run iy by manually running: logstash -f csvedit.conf which runs logstash using my .conf file. I stop this script by pressing …

---

## [Logstash - Error at startup - Cannot determine timezone from nil](https://discuss.elastic.co/t/logstash-error-at-startup-cannot-determine-timezone-from-nil/378533)

<div class="topic-metadata">

**Author:** [@markus](https://discuss.elastic.co/u/markus)\
**Replies:** 3\
**Last updated:** [May 27, 2025, 2:57pm UTC](https://discuss.elastic.co/t/logstash-error-at-startup-cannot-determine-timezone-from-nil/378533 "2025-05-27T14:57:16Z")

</div>

Hi, I've stumbled upon a problem with my Logstash config. As soon as I use the translate filter Logstash refuses to start. I use the following minimal config to reproduce the issue: input { stdin { } } filter {…

---

## [Recv-Q with \> 380K segments waiting to be processed by logstash](https://discuss.elastic.co/t/recv-q-with-380k-segments-waiting-to-be-processed-by-logstash/378579)

<div class="topic-metadata">

**Author:** [@pepitogrillo](https://discuss.elastic.co/u/pepitogrillo)\
**Replies:** 0\
**Last updated:** [May 27, 2025, 10:14am UTC](https://discuss.elastic.co/t/recv-q-with-380k-segments-waiting-to-be-processed-by-logstash/378579 "2025-05-27T10:14:21Z")

</div>

Hi All, I am currently in a Docker swarm setup with 7 nodes ingesting 20K 200 bytes TPS . Recv-Q is at almost 4.000.000 segments waiting to be processed by logstash right now I have 80 workers, batch\_size=1000 and poo…

---

## [Palo Alto Firewall Log Collection Issue with Elasticsearch](https://discuss.elastic.co/t/palo-alto-firewall-log-collection-issue-with-elasticsearch/377296)

<div class="topic-metadata">

**Author:** [@zakaria2](https://discuss.elastic.co/u/zakaria2)\
**Replies:** 13\
**Last updated:** [May 26, 2025, 10:21pm UTC](https://discuss.elastic.co/t/palo-alto-firewall-log-collection-issue-with-elasticsearch/377296 "2025-05-26T22:21:55Z")

</div>

Hello everyone, I'm having a problem collecting logs from my Palo Alto firewall to my Elastic stack (Elasticsearch, Logstash, Kibana). I configured the Palo Alto firewall to send logs in Syslog format to Logstash (see …

---

## [Receive Elasticsearch API connection with Logstash](https://discuss.elastic.co/t/receive-elasticsearch-api-connection-with-logstash/378541)

<div class="topic-metadata">

**Author:** [@widhalmt](https://discuss.elastic.co/u/widhalmt)\
**Replies:** 4\
**Last updated:** [May 26, 2025, 2:04pm UTC](https://discuss.elastic.co/t/receive-elasticsearch-api-connection-with-logstash/378541 "2025-05-26T14:04:07Z")

</div>

Hi, I have a tool (Icinga 2) that can write data into Elasticsearch. For a special project I need to reroute some of the data to Kafka. Can I use Logstash to receive and reroute the data? I mean is there an input that …

---

## [GROK Help with timestamp](https://discuss.elastic.co/t/grok-help-with-timestamp/378433)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 7\
**Last updated:** [May 23, 2025, 11:29pm UTC](https://discuss.elastic.co/t/grok-help-with-timestamp/378433 "2025-05-23T23:29:15Z")

</div>

Hello, I have below sample data: 10.10.0.1 - - \[20/May/2025:13:02:52 +0000\] "GET /website/redirect/2df4e11a-7e8f-4927-938b-7adfcc40f566 HTTP/1.1" 302 - I cannot set any know be me timestamps for such date/time Can so…

---

## [Is Logstash able to inline correct invalid JSON?](https://discuss.elastic.co/t/is-logstash-able-to-inline-correct-invalid-json/378473)

<div class="topic-metadata">

**Author:** [@Marcos\_Mondragon](https://discuss.elastic.co/u/Marcos_Mondragon)\
**Replies:** 3\
**Last updated:** [May 23, 2025, 4:43pm UTC](https://discuss.elastic.co/t/is-logstash-able-to-inline-correct-invalid-json/378473 "2025-05-23T16:43:44Z")

</div>

I'm trying to determine if there is a way within a Logstash conf file to correct an invalid JSON field being passed in? Here is the data: { "trace": "ID-in":"83455E37DD688327", "ID-out":"83455E37DD688327", "reply-to-in…

---

## [Logstash is not fully using index template](https://discuss.elastic.co/t/logstash-is-not-fully-using-index-template/376042)

<div class="topic-metadata">

**Author:** [@Jesselastic](https://discuss.elastic.co/u/Jesselastic)\
**Replies:** 1\
**Last updated:** [May 22, 2025, 10:56pm UTC](https://discuss.elastic.co/t/logstash-is-not-fully-using-index-template/376042 "2025-05-22T22:56:41Z")

</div>

I have syslog docs coming through logstash and everything is mapping to the correct field names. The index template that has a pattern matching the logs from logstash correctly creates datastreams and ilm is working gre…

---

## [Logstash snmp integration plugin doesn't work](https://discuss.elastic.co/t/logstash-snmp-integration-plugin-doesnt-work/377181)

<div class="topic-metadata">

**Author:** [@Dth\_Revan](https://discuss.elastic.co/u/Dth_Revan)\
**Replies:** 1\
**Last updated:** [May 22, 2025, 12:36pm UTC](https://discuss.elastic.co/t/logstash-snmp-integration-plugin-doesnt-work/377181 "2025-05-22T12:36:49Z")

</div>

Hello, everybody! I wanted to try a logstash snmp plugin to get metrics from physical devices to migrate completely from zabbix to ELK. I spent very much time, but it doesn't work still... I'm going to describe my env.…

---

## [Eliminate excesive blanks or select fields for position](https://discuss.elastic.co/t/eliminate-excesive-blanks-or-select-fields-for-position/378390)

<div class="topic-metadata">

**Author:** [@fernandosss](https://discuss.elastic.co/u/fernandosss)\
**Replies:** 4\
**Last updated:** [May 22, 2025, 7:23am UTC](https://discuss.elastic.co/t/eliminate-excesive-blanks-or-select-fields-for-position/378390 "2025-05-22T07:23:00Z")

</div>

Hello, I'd like it if someone could help me with the following problem. I'm sending a series of logs to logstash/elastic. The problem is that my logs are separated by blanks, and sometimes after the first field, there…

---

## [Http output "Mapping" setting sends all properties as strings](https://discuss.elastic.co/t/http-output-mapping-setting-sends-all-properties-as-strings/378309)

<div class="topic-metadata">

**Author:** [@skers95](https://discuss.elastic.co/u/skers95)\
**Replies:** 2\
**Last updated:** [May 19, 2025, 8:28pm UTC](https://discuss.elastic.co/t/http-output-mapping-setting-sends-all-properties-as-strings/378309 "2025-05-19T20:28:33Z")

</div>

Hello, I'm on Logstash v7.17, using 'http output' plugin to send logs to third party API. Per third party API spec and hard requirement, "zip" POST property must be a number, otherwise API rejects it. When I use "map…

---

## [Logstash plugin installation created files](https://discuss.elastic.co/t/logstash-plugin-installation-created-files/378269)

<div class="topic-metadata">

**Author:** [@shivani\_aggarwal](https://discuss.elastic.co/u/shivani_aggarwal)\
**Replies:** 1\
**Last updated:** [May 18, 2025, 4:15pm UTC](https://discuss.elastic.co/t/logstash-plugin-installation-created-files/378269 "2025-05-18T16:15:37Z")

</div>

Hi, Background: I build docker images using logstash. After installing the logstash rpm, a few additional logstash plugins are installed. For ex. /usr/share/logstash/bin/logstash-plugin install logstash-output-opense…

---

## [Proper way to extract df -h output](https://discuss.elastic.co/t/proper-way-to-extract-df-h-output/378144)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 7\
**Last updated:** [May 15, 2025, 2:17pm UTC](https://discuss.elastic.co/t/proper-way-to-extract-df-h-output/378144 "2025-05-15T14:17:15Z")

</div>

Hello everyone, i got this data through snmp input plugin. After some mutate filter, I need to extract this data, and I chose to use grok filter. The data looks like this (there is blank space in the first line) Files…

---

## [PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109)

<div class="topic-metadata">

**Author:** [@Ria](https://discuss.elastic.co/u/Ria)\
**Replies:** 4\
**Last updated:** [May 15, 2025, 6:31am UTC](https://discuss.elastic.co/t/pkix-path-building-failed-sun-security-provider-certpath-suncertpathbuilderexception-unable-to-find-valid-certification-path-to-requested-target/378109 "2025-05-15T06:31:16Z")

</div>

I'm using http\_poller input plugin in the logstash pipeline in order to ingest the REST API endpoint call response to feed into the elasticsearch index .This is my current configuration of the pipeline as I'm doing on my…

---

## [Jdbc\_static dealing with parameters from not existing fields](https://discuss.elastic.co/t/jdbc-static-dealing-with-parameters-from-not-existing-fields/377628)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 3\
**Last updated:** [May 12, 2025, 10:09pm UTC](https://discuss.elastic.co/t/jdbc-static-dealing-with-parameters-from-not-existing-fields/377628 "2025-05-12T22:09:37Z")

</div>

I'm trying to use the jdbc\_static filter in my logstash pipeline, but I am getting the following error: \[2025-04-29T10:36:48,983\]\[WARN \]\[logstash.filters.jdbc.lookup\]\[test\]\[udplogstash\] Parameter field not found in even…

---

## [Does file input plugin support backpressure](https://discuss.elastic.co/t/does-file-input-plugin-support-backpressure/378035)

<div class="topic-metadata">

**Author:** [@Anandh\_Kumar](https://discuss.elastic.co/u/Anandh_Kumar)\
**Replies:** 4\
**Last updated:** [May 12, 2025, 1:44pm UTC](https://discuss.elastic.co/t/does-file-input-plugin-support-backpressure/378035 "2025-05-12T13:44:39Z")

</div>

We are using a file input plugin 4.4 latest version with logstash 8.17.0. We have a kafka output plugin using a file input plugin using a persistent queue on a dedicated pipeline. Does file input support backpressure ,…

---

## [Enable logging for rspec on Logstash plugin](https://discuss.elastic.co/t/enable-logging-for-rspec-on-logstash-plugin/378034)

<div class="topic-metadata">

**Author:** [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Replies:** 0\
**Last updated:** [May 12, 2025, 10:28am UTC](https://discuss.elastic.co/t/enable-logging-for-rspec-on-logstash-plugin/378034 "2025-05-12T10:28:25Z")

</div>

I'm making some changes to the logstash-input-salesforce plugin and would like to be able to see the logging generated by @logger.debug statements when running rspec tests. Currently, when rspec starts, it prints Sendin…

---

## [Logstash TCP Input Zero Window Size](https://discuss.elastic.co/t/logstash-tcp-input-zero-window-size/377851)

<div class="topic-metadata">

**Author:** [@5Lights](https://discuss.elastic.co/u/5Lights)\
**Replies:** 6\
**Last updated:** [May 9, 2025, 5:53pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-zero-window-size/377851 "2025-05-09T17:53:00Z")

</div>

We have a Loadbalancer that sends events as a JSON Stream over TCP to Logstash using Persistent Queue. Logstash is configured with a TCP Input. The Sender limits itself to 4 long-lived TCP connections to Logstash, but i…

---

## [Issue with logstash 8.17.4. Sincedb sometimes does not recognise the correct inode. After logstash restart it works](https://discuss.elastic.co/t/issue-with-logstash-8-17-4-sincedb-sometimes-does-not-recognise-the-correct-inode-after-logstash-restart-it-works/377867)

<div class="topic-metadata">

**Author:** [@devops\_training](https://discuss.elastic.co/u/devops_training)\
**Replies:** 9\
**Last updated:** [May 8, 2025, 12:12am UTC](https://discuss.elastic.co/t/issue-with-logstash-8-17-4-sincedb-sometimes-does-not-recognise-the-correct-inode-after-logstash-restart-it-works/377867 "2025-05-08T00:12:13Z")

</div>

db.log rotates to db\_backup.log. input to logstash input { file { path =\> "C:/Program Files (x86)/webserver/db/logs/db.log" exclude =\> "db\_backup.log" type =\> "db" start\_position =\> "beginning" sin…

---

## [File input plugin to process files not newer than X seconds ago](https://discuss.elastic.co/t/file-input-plugin-to-process-files-not-newer-than-x-seconds-ago/377915)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 1\
**Last updated:** [May 7, 2025, 3:43pm UTC](https://discuss.elastic.co/t/file-input-plugin-to-process-files-not-newer-than-x-seconds-ago/377915 "2025-05-07T15:43:16Z")

</div>

Hello again. I am trying to use file input plugin, read mode, delete after completion, but I need to take in charge just files that are not newer than X seconds ago. This because my logger application writes a new file…

---

## [Logstash does not accept SSL connections from beats](https://discuss.elastic.co/t/logstash-does-not-accept-ssl-connections-from-beats/377775)

<div class="topic-metadata">

**Author:** [@Ruslan\_Hafizov](https://discuss.elastic.co/u/Ruslan_Hafizov)\
**Replies:** 11\
**Last updated:** [May 7, 2025, 1:12pm UTC](https://discuss.elastic.co/t/logstash-does-not-accept-ssl-connections-from-beats/377775 "2025-05-07T13:12:04Z")

</div>

I was trying to set up SSL/TLS between beats and input beats in logstash. To create the certificates, I used the following commands: ### creating logstash.p12 elasticsearch-certutil crl --ca /usr/share/elasticsearch/con…

---

## [Using xml filter plugin](https://discuss.elastic.co/t/using-xml-filter-plugin/377823)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 5\
**Last updated:** [May 6, 2025, 3:53pm UTC](https://discuss.elastic.co/t/using-xml-filter-plugin/377823 "2025-05-06T15:53:52Z")

</div>

Hello again, I am trying to parse an XML string received on UDP input plugin with the XML filter plugin. The structure of the XML is: \<ROOT\> \<LEVEL1a\>string \<LEVEL2a\> \<LEVEL3a\>string\</LEVEL3a\> \<LEVEL3b\>string\</…

---

## [Logstash locks the file during the file rotation in windows server](https://discuss.elastic.co/t/logstash-locks-the-file-during-the-file-rotation-in-windows-server/377793)

<div class="topic-metadata">

**Author:** [@guru\_dev](https://discuss.elastic.co/u/guru_dev)\
**Replies:** 9\
**Last updated:** [May 6, 2025, 3:48pm UTC](https://discuss.elastic.co/t/logstash-locks-the-file-during-the-file-rotation-in-windows-server/377793 "2025-05-06T15:48:24Z")

</div>

Below is the error from logstash-plain.logstash \[2025-05-05T05:04:45,597\]\[WARN \]\[filewatch.tailmode.handlers.create\]\[main\]\[c1077e68a0985da91e9d9117b4ed7833cd278b44745ff7a8664043bc8322aec5\] failed to open file {:path=\>"C…

---

## [Is SNMP PDU varbinds order preserved by the snmptrap plugin?](https://discuss.elastic.co/t/is-snmp-pdu-varbinds-order-preserved-by-the-snmptrap-plugin/377649)

<div class="topic-metadata">

**Author:** [@NickyJohn](https://discuss.elastic.co/u/NickyJohn)\
**Replies:** 2\
**Last updated:** [May 1, 2025, 2:01am UTC](https://discuss.elastic.co/t/is-snmp-pdu-varbinds-order-preserved-by-the-snmptrap-plugin/377649 "2025-05-01T02:01:03Z")

</div>

Doesn't seem to... eg v 2c linkUp rubydebug output shown here... https://www.rfc-editor.org/rfc/rfc3416#page-21 4.2.6. The SNMPv2-Trap-PDU ... The first \*\* two variable bindings\*\* in the variable binding list of …

---

## [Loading a json file to enrich data](https://discuss.elastic.co/t/loading-a-json-file-to-enrich-data/377683)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 4\
**Last updated:** [April 30, 2025, 9:21pm UTC](https://discuss.elastic.co/t/loading-a-json-file-to-enrich-data/377683 "2025-04-30T21:21:44Z")

</div>

Hello everyone, I am working with Logstash UDP Input Plugin and Elasticsearch output plugin. I need to load a json file containing information that I need to enrich the data sent to elastic matching same criteria. Wha…

---

## [Timestamp of last attemp of ingestion](https://discuss.elastic.co/t/timestamp-of-last-attemp-of-ingestion/377681)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 4\
**Last updated:** [April 30, 2025, 4:44pm UTC](https://discuss.elastic.co/t/timestamp-of-last-attemp-of-ingestion/377681 "2025-04-30T16:44:57Z")

</div>

Hello everyone, I am working with Logstash UDP Input Plugin and Elasticsearch output plugin and using Persisted Queues. I noticed that the @timestamp I receive from Logstash into Elasticsearch, even in the event of int…

---

## [Management of illegal characters](https://discuss.elastic.co/t/management-of-illegal-characters/377159)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 9\
**Last updated:** [April 30, 2025, 2:56pm UTC](https://discuss.elastic.co/t/management-of-illegal-characters/377159 "2025-04-30T14:56:40Z")

</div>

Hello Everyone, I am in the process of converting a "in-house" Delphi application that receives an XML string over udp port and send it to an elasticsearch instance, doing a conversion from XML to JSON and sending it th…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=5)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=7)
