# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=67

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 68

---

## [Logstash output by condition](https://discuss.elastic.co/t/logstash-output-by-condition/338376)

<div class="topic-metadata">

**Author:** [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 2:19am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376 "2023-07-17T02:19:05Z")

</div>

Hi Guys, I setup logstash with influxdb plugin, and can send metric to influxdb successfully. But now I meet question with output by condition. run two filebeat instance onto two pc to capture two different log files, …

---

## [Own Output for SNMP Get Values in Logstash](https://discuss.elastic.co/t/own-output-for-snmp-get-values-in-logstash/338440)

<div class="topic-metadata">

**Author:** [@hitman22](https://discuss.elastic.co/u/hitman22)\
**Replies:** 2\
**Last updated:** [July 16, 2023, 10:33pm UTC](https://discuss.elastic.co/t/own-output-for-snmp-get-values-in-logstash/338440 "2023-07-16T22:33:56Z")

</div>

Hello, I have the following Logstash config input { snmp { tags =\> \[ "snmp" \] get =\> \[".1.3.6.1.4.1.9.9.48.1.1.1.5.2",".1.3.6.1.4.1.9.9.109.1.1.1.1.5.1",".1.3.6.1.4.1.9.9.48.1.1.1.5.1"\] hosts =\> \[{host =\> …

---

## [Logstash 8.8.2 not sending filebeat 8.8.2 logs to eleasticsearch 8.8.2 database](https://discuss.elastic.co/t/logstash-8-8-2-not-sending-filebeat-8-8-2-logs-to-eleasticsearch-8-8-2-database/338459)

<div class="topic-metadata">

**Author:** [@Kiran\_K](https://discuss.elastic.co/u/Kiran_K)\
**Replies:** 2\
**Last updated:** [July 16, 2023, 12:40am UTC](https://discuss.elastic.co/t/logstash-8-8-2-not-sending-filebeat-8-8-2-logs-to-eleasticsearch-8-8-2-database/338459 "2023-07-16T00:40:12Z")

</div>

Dear Team, Our scenario is network devices send logs to filebeat. Filebeat send those logs to logstash and logstash send logs to elasticsearch database but we are receive below warning in logstash logs and we didn't rec…

---

## [Filebeat and Logstash not connecting](https://discuss.elastic.co/t/filebeat-and-logstash-not-connecting/338302)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 4\
**Last updated:** [July 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-and-logstash-not-connecting/338302 "2023-07-15T13:55:09Z")

</div>

I am reaching out to seek your expertise and guidance regarding an issue I am facing with transferring logs from Filebeat to Logstash. I have a setup where Filebeat is installed on 'Server1', which sends logs to Logstash…

---

## [Logstash gets stuck in pipelines](https://discuss.elastic.co/t/logstash-gets-stuck-in-pipelines/337247)

<div class="topic-metadata">

**Author:** [@Tony\_K](https://discuss.elastic.co/u/Tony_K)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 9:00pm UTC](https://discuss.elastic.co/t/logstash-gets-stuck-in-pipelines/337247 "2023-07-14T21:00:16Z")

</div>

I have a simple csv file where i like to upload to elasticsearch. My sample csv file contains 2 records. it gets stuck at pipelines. Please see below. I am running this on windows 11 Thank you for your helo. uploa…

---

## [Kafka logstash logs are showing into filebeat logstash index](https://discuss.elastic.co/t/kafka-logstash-logs-are-showing-into-filebeat-logstash-index/337419)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 10\
**Last updated:** [July 14, 2023, 2:27pm UTC](https://discuss.elastic.co/t/kafka-logstash-logs-are-showing-into-filebeat-logstash-index/337419 "2023-07-14T14:27:36Z")

</div>

Hello, I have kafka-logstash conf and logstash reciveing the logs from kafka. here is the config. input { kafka { topics =\> \["sitlogtopic","locallogtopic"\] bootstrap\_servers =\> "ddr-kafkadev.pvt.cci…

---

## [Parsing firewall logs in logstash](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 1:31pm UTC](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405 "2023-07-14T13:31:25Z")

</div>

Hello, our sophos firewall are sending logs to filebeat, then filebeat send to logstash. In logstash im trying to separate field called "action" to be able to filter it under elasticsearch. So far no luck. I managed to …

---

## [Filebeat Syslog no listening port](https://discuss.elastic.co/t/filebeat-syslog-no-listening-port/336969)

<div class="topic-metadata">

**Author:** [@mc.gyver.reboot](https://discuss.elastic.co/u/mc.gyver.reboot)\
**Replies:** 15\
**Last updated:** [July 13, 2023, 2:35pm UTC](https://discuss.elastic.co/t/filebeat-syslog-no-listening-port/336969 "2023-07-13T14:35:45Z")

</div>

Good morning, Configuration: Ubuntu version 22 Filebeat version 8.8.1 Aucun message d'erreur au lancement de Filebeat After hours of searching and testing, I can't find why Filebeat isn't listening on the ports I te…

---

## [Problem to add new date field in filter logstash](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107)

<div class="topic-metadata">

**Author:** [@shayn](https://discuss.elastic.co/u/shayn)\
**Replies:** 3\
**Last updated:** [July 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107 "2023-07-13T12:27:22Z")

</div>

i have date field called case\_start\_time in format of date and time . i am trying to add new field called case\_day which will cut the date without the time from case\_start\_time . case\_start\_time: 09/07/23 23:54:26 ca…

---

## [Logstash forwarding connection refused](https://discuss.elastic.co/t/logstash-forwarding-connection-refused/338293)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 11:29am UTC](https://discuss.elastic.co/t/logstash-forwarding-connection-refused/338293 "2023-07-13T11:29:53Z")

</div>

Hello, I am trying to forward logs to any other location for the moment however i have the following error when trying to forward any data what so ever. I have a netcat listener on the opposite end and can see the incom…

---

## [Logstash pipeline Http output plugin error "\[HTTP Output Failure\] Encountered non-2xx HTTP code 400"](https://discuss.elastic.co/t/logstash-pipeline-http-output-plugin-error-http-output-failure-encountered-non-2xx-http-code-400/338116)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 9:55am UTC](https://discuss.elastic.co/t/logstash-pipeline-http-output-plugin-error-http-output-failure-encountered-non-2xx-http-code-400/338116 "2023-07-13T09:55:29Z")

</div>

Hi all, I have a logstash output http plugin: output { if \[@metadata\]\[index\_to\_delete\] == "first\_index" or \[@metadata\]\[index\_to\_delete\] == "second\_index" { http { id =\> "http\_index\_delete" …

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/338290)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:15am UTC](https://discuss.elastic.co/t/issue-with-logstash/338290 "2023-07-13T08:15:05Z")

</div>

Hello, I have a question: when you have two different configuration files in the logstash conf.d directory, does this cause a problem when importing them into elasticsearch?

---

## [Sometimes I fail to start up and the error message is as follows.](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174)

<div class="topic-metadata">

**Author:** [@pl02206984](https://discuss.elastic.co/u/pl02206984)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 9:46pm UTC](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174 "2023-07-12T21:46:54Z")

</div>

Sometimes I fail to start up and the error message is as follows. \[2023-07-12T10:50:36,815\]\[ERROR\]\[logstash.config.sourceloader\] No configuration found in the configured sources. \[2023-07-12T10:50:36,932\]\[INFO \]\[logstas…

---

## [Another mysterious work logstash with errors \_grokparsefailure](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 18\
**Last updated:** [July 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327 "2023-07-12T14:51:43Z")

</div>

again I encounter a problem in the work of logstash, and specifically with grock. Everything is fine in the debugger, the messages are parsed, but as soon as I apply this configuration to the production, then these messa…

---

## [Log Stash Sql Server](https://discuss.elastic.co/t/log-stash-sql-server/338233)

<div class="topic-metadata">

**Author:** [@balupad14](https://discuss.elastic.co/u/balupad14)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:49pm UTC](https://discuss.elastic.co/t/log-stash-sql-server/338233 "2023-07-12T14:49:07Z")

</div>

Hi all, I am trying to insert the data into the Elasticsearch from SQL Server. When I run the logstash, I am getting this error. Not eligible for data streams because config contains one or more settings that are not c…

---

## [To get message field for json filter](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968 "2023-07-12T12:44:48Z")

</div>

Hi Team, I use json filter to parse my json data but my json data has "message" value. that's why ı'm not able to get standard message field which have all parsed log. I just have "message" field which come from json l…

---

## [Start logstash error](https://discuss.elastic.co/t/start-logstash-error/338146)

<div class="topic-metadata">

**Author:** [@liqiu](https://discuss.elastic.co/u/liqiu)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 8:05pm UTC](https://discuss.elastic.co/t/start-logstash-error/338146 "2023-07-11T20:05:01Z")

</div>

I have configured the logstash.yml configuration file logstash.yml： input {stdin{}} output {stdout{}} But when I enter ./logstash to start, the following error occurs \[2023-07-12T01:16:59,926\]\[INFO \]\[logstash.runner …

---

## [Each log line is split into a different document in Elastic](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144)

<div class="topic-metadata">

**Author:** [@Merav\_Yaacov](https://discuss.elastic.co/u/Merav_Yaacov)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 5:37am UTC](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144 "2023-07-12T05:37:53Z")

</div>

Hi, What can be the reason that each line of log file is split into single document in Elastic? That's how Logstash is configured: input { file { type =\> "log" path =\> \["/etc/logstash/conf.d/files/\*.…

---

## [Parsing the message field in security event.code 4624](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 11:19pm UTC](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046 "2023-07-11T23:19:14Z")

</div>

The information that I want is located under the first sub-header "Subject" and "Network Information". My basic question is this, how do I pull this information out of the Message field and display it along with the Time…

---

## [How to convert the Logstash message to fileds](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 15\
**Last updated:** [July 11, 2023, 9:17pm UTC](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910 "2023-07-11T21:17:00Z")

</div>

Hi, I am using Logstash as a syslog server which sends data to elastic. here is the output. @timestampJul 7, 2023 @ 11:30:12.520@version1 hostname10.11.12.13 message {"proxyname":"test-123-abc","revision":"8","latency…

---

## [Invalid FieldReference: \`\_Domain\_Labels\[0\]\_ULabel\`](https://discuss.elastic.co/t/invalid-fieldreference-domain-labels-0-ulabel/337016)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 5\
**Last updated:** [July 11, 2023, 3:50pm UTC](https://discuss.elastic.co/t/invalid-fieldreference-domain-labels-0-ulabel/337016 "2023-07-11T15:50:13Z")

</div>

Logstash version - 7.17.8 Currently we are seeing invalid FieldReference errors on our Logstash nodes dealing with \_Domain\_Labels\[0\]\_ULabel onf.d/mulesoft/get\_cloudhub\_app\_logs.conf"\], :thread=\>"#\<Thread:0x1475cac0 run\>…

---

## [Logstash automatic shutdown normal](https://discuss.elastic.co/t/logstash-automatic-shutdown-normal/337946)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 2:44am UTC](https://discuss.elastic.co/t/logstash-automatic-shutdown-normal/337946 "2023-07-11T02:44:48Z")

</div>

logstash: 7.17.9 cfg file: input { elasticsearch { hosts =\> \["10.251.0.11:39202"\] index =\> "new\_index\_001" docinfo =\> true scroll =\> "30s" size =\> 500 } } filter { mutate { remove\_field =\> \["…

---

## [Running Logstash on multiple servers, avoiding double processing](https://discuss.elastic.co/t/running-logstash-on-multiple-servers-avoiding-double-processing/337780)

<div class="topic-metadata">

**Author:** [@BenSeb](https://discuss.elastic.co/u/BenSeb)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 3:00pm UTC](https://discuss.elastic.co/t/running-logstash-on-multiple-servers-avoiding-double-processing/337780 "2023-07-10T15:00:20Z")

</div>

Hi We have logstash running on our worker servers, and they run with an identical config, to ensure if one hosts goes down, we are still processing events. The source data is Mysql, then logstash pushes the latest reco…

---

## [Logstash issues when writing from s3 to elastic](https://discuss.elastic.co/t/logstash-issues-when-writing-from-s3-to-elastic/338014)

<div class="topic-metadata">

**Author:** [@Keren\_Cohen](https://discuss.elastic.co/u/Keren_Cohen)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 1:09pm UTC](https://discuss.elastic.co/t/logstash-issues-when-writing-from-s3-to-elastic/338014 "2023-07-10T13:09:53Z")

</div>

Hi, I am trying to write logs from AWS s3 bucket and write them to elastic. I'm using logstash 7.17 and get the following error: /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/aws-sdk-core-2.11.632/lib/seahorse/cl…

---

## [Logstash using codec line is not working](https://discuss.elastic.co/t/logstash-using-codec-line-is-not-working/337816)

<div class="topic-metadata">

**Author:** [@cressprm](https://discuss.elastic.co/u/cressprm)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 9:29pm UTC](https://discuss.elastic.co/t/logstash-using-codec-line-is-not-working/337816 "2023-07-07T21:29:17Z")

</div>

I am new to ELK and having trouble configuring a simple Logstash pipeline. Despite enabling debug logging(--log.level=debug), I can only find a message that says 'Received line' in the logs, and nothing else. Not sure wh…

---

## [Codec Avro Plugin Forward Compatibility](https://discuss.elastic.co/t/codec-avro-plugin-forward-compatibility/337911)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 5:59pm UTC](https://discuss.elastic.co/t/codec-avro-plugin-forward-compatibility/337911 "2023-07-07T17:59:55Z")

</div>

I am processing serialized messages from SQS using Logstash. The messages have been serialized using a FORWARD TRANSITIVE schema. The schema may change in the future. To deserialize these messages, I'd like to use the Co…

---

## [How to setup logstash workers or batch size](https://discuss.elastic.co/t/how-to-setup-logstash-workers-or-batch-size/337903)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-workers-or-batch-size/337903 "2023-07-07T15:22:50Z")

</div>

i have es cluster 6.1.3 i want migrate data to es 7.17.9 i used logstash 7.17.9 to make it my index count has only 1200 doc my logstash config file: input { elasticsearch { hosts =\> \["10.251.0.11:39202","10.25…

---

## [What is this error?](https://discuss.elastic.co/t/what-is-this-error/337869)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 12:29pm UTC](https://discuss.elastic.co/t/what-is-this-error/337869 "2023-07-07T12:29:39Z")

</div>

hi all my logstash jvm config is Xms 2g Xmx 2g and 3 server and each server has 2conf file conf file is 1workers config and content is input { jdbc {oracle} } output { jdbc { postgresql} } logstash no proble…

---

## [Comments field not display for some Affected Services values in Nabled Alert](https://discuss.elastic.co/t/comments-field-not-display-for-some-affected-services-values-in-nabled-alert/337879)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 9:55am UTC](https://discuss.elastic.co/t/comments-field-not-display-for-some-affected-services-values-in-nabled-alert/337879 "2023-07-07T09:55:23Z")

</div>

Hello everyone, I have a dashboard (consists of Client, Hostname, AffectedService and Comments) to check the performance of Affected Services. But the Comments values are not being displayed in the dashboard for Affecte…

---

## [How work many output jdbc at same time?](https://discuss.elastic.co/t/how-work-many-output-jdbc-at-same-time/337746)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 12:10am UTC](https://discuss.elastic.co/t/how-work-many-output-jdbc-at-same-time/337746 "2023-07-07T00:10:47Z")

</div>

hi all, my pipelines.yml - pipeline.id: test1 pipeline.workers: 1 path.config: "/app/logstash/config/conf.d/test1.conf" - pipeline.id: test2 pipeline.workers: 1 path.config: "/app/logstash/config/conf.d/test2.c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=66)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=68)
