# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=7

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 8

---

## [Logstash monitoring with eck-operator](https://discuss.elastic.co/t/logstash-monitoring-with-eck-operator/377665)

<div class="topic-metadata">

**Author:** [@Jo\_De\_Troy](https://discuss.elastic.co/u/Jo_De_Troy)\
**Replies:** 0\
**Last updated:** [April 30, 2025, 11:53am UTC](https://discuss.elastic.co/t/logstash-monitoring-with-eck-operator/377665 "2025-04-30T11:53:00Z")

</div>

Hello all, has anyone tried specifying requests/limits for the metricbeat sidecar used for monitoring a logstash resource? Is there a supported way to specify these? My logstash fails with the message "... forbidden: …

---

## [SQLRecoverableException: ORA-17008: Closed connection](https://discuss.elastic.co/t/sqlrecoverableexception-ora-17008-closed-connection/377428)

<div class="topic-metadata">

**Author:** [@Witcherek](https://discuss.elastic.co/u/Witcherek)\
**Replies:** 3\
**Last updated:** [April 29, 2025, 2:35pm UTC](https://discuss.elastic.co/t/sqlrecoverableexception-ora-17008-closed-connection/377428 "2025-04-29T14:35:08Z")

</div>

Hello, Since two weeks we have problem that from time to time our logstash pipeline which is connecting to oracle databse with jdbc\_streaming filter is throwing, exception=\>#\<Sequel::DatabaseDisconnectError: Java::Java…

---

## [Extract a specific field from a string](https://discuss.elastic.co/t/extract-a-specific-field-from-a-string/377618)

<div class="topic-metadata">

**Author:** [@stanislavcik](https://discuss.elastic.co/u/stanislavcik)\
**Replies:** 2\
**Last updated:** [April 29, 2025, 1:19pm UTC](https://discuss.elastic.co/t/extract-a-specific-field-from-a-string/377618 "2025-04-29T13:19:58Z")

</div>

How to extract a specific field from a string if the string length varies?

---

## [ Ignoring the 'pipelines.yml' file because modules or command line options are specified](https://discuss.elastic.co/t/ignoring-the-pipelines-yml-file-because-modules-or-command-line-options-are-specified/377587)

<div class="topic-metadata">

**Author:** [@somiii\_AB](https://discuss.elastic.co/u/somiii_AB)\
**Replies:** 2\
**Last updated:** [April 28, 2025, 9:22pm UTC](https://discuss.elastic.co/t/ignoring-the-pipelines-yml-file-because-modules-or-command-line-options-are-specified/377587 "2025-04-28T21:22:52Z")

</div>

Is it possible to run multiple pipelines on the Windows version of Logstash? I can’t seem to get this to work for my files. I have installed Logstash on Windows and placed a pipelines.yml file in C:\\Program Files\\Logsta…

---

## [Logstash JMS Input Plugin Failing to Connect to Broker URL (tcp://localhost:7222)](https://discuss.elastic.co/t/logstash-jms-input-plugin-failing-to-connect-to-broker-url-tcp-localhost-7222/371771)

<div class="topic-metadata">

**Author:** [@Loredana](https://discuss.elastic.co/u/Loredana)\
**Replies:** 1\
**Last updated:** [April 28, 2025, 1:00pm UTC](https://discuss.elastic.co/t/logstash-jms-input-plugin-failing-to-connect-to-broker-url-tcp-localhost-7222/371771 "2025-04-28T13:00:32Z")

</div>

Hi, We are using the Logstash JMS input plugin to read events from a JMS Queue and send them to Elasticsearch. However, we are encountering a strange issue where Logstash tries to connect to a default URL (tcp://localho…

---

## [Logstash does not see a field](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 4\
**Last updated:** [April 28, 2025, 12:31pm UTC](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570 "2025-04-28T12:31:17Z")

</div>

I can't reprocess any field in Logstash which is ingested from Jdbc. All Fields are properly inserted into Elastic, they have proper name and data, however I can't transform them anyhow. Here is the configuration: input…

---

## [Error generating a logstash image](https://discuss.elastic.co/t/error-generating-a-logstash-image/377549)

<div class="topic-metadata">

**Author:** [@bertuz](https://discuss.elastic.co/u/bertuz)\
**Replies:** 3\
**Last updated:** [April 27, 2025, 4:30pm UTC](https://discuss.elastic.co/t/error-generating-a-logstash-image/377549 "2025-04-27T16:30:30Z")

</div>

Freshman on elastic stack here. I'm trying to generate a logstash image with the following Dockerfile: FROM docker.elastic.co/logstash/logstash:8.1.0 RUN rm -f /usr/share/logstash/pipeline/logstash.conf && \\ bin/lo…

---

## [Logstash error](https://discuss.elastic.co/t/logstash-error/377282)

<div class="topic-metadata">

**Author:** [@sreya\_14](https://discuss.elastic.co/u/sreya_14)\
**Replies:** 3\
**Last updated:** [April 25, 2025, 10:01am UTC](https://discuss.elastic.co/t/logstash-error/377282 "2025-04-25T10:01:39Z")

</div>

I am getting below error in logstash log Apr 18 12:24:19 pldevelk03 logstash\[12013\]: ERROR: Failed to parse YAML file "/etc/logstash/logstash.yml". Please confirm if the YAML structure is valid (e.g. look for Apr 18 12:…

---

## [ Help Integrating Wazuh, MISP, and Logstash into a Preventive Security Analysis Module](https://discuss.elastic.co/t/help-integrating-wazuh-misp-and-logstash-into-a-preventive-security-analysis-module/377493)

<div class="topic-metadata">

**Author:** [@Nouaman\_Ahmamcha](https://discuss.elastic.co/u/Nouaman_Ahmamcha)\
**Replies:** 0\
**Last updated:** [April 24, 2025, 2:34pm UTC](https://discuss.elastic.co/t/help-integrating-wazuh-misp-and-logstash-into-a-preventive-security-analysis-module/377493 "2025-04-24T14:34:57Z")

</div>

Hi everyone, I'm currently working on a preventive security analysis module as part of a project, and I'm integrating the following components: Wazuh for SIEM and endpoint monitoring (running via Docker) MISP for thre…

---

## [Logstash preserve source ip](https://discuss.elastic.co/t/logstash-preserve-source-ip/377463)

<div class="topic-metadata">

**Author:** [@omoroka](https://discuss.elastic.co/u/omoroka)\
**Replies:** 6\
**Last updated:** [April 24, 2025, 12:17pm UTC](https://discuss.elastic.co/t/logstash-preserve-source-ip/377463 "2025-04-24T12:17:29Z")

</div>

Hi, I have a logstash server running on linux and this server is collecting logs from various devices like storages, switches, firewalls etc. All device send logs to the logstash servers 514 port, most of them is fine …

---

## [Logstash Troubleshooting: ERROR - (EACCES) Permission denied to output-file-path](https://discuss.elastic.co/t/logstash-troubleshooting-error-eacces-permission-denied-to-output-file-path/377407)

<div class="topic-metadata">

**Author:** [@MonkeyDono](https://discuss.elastic.co/u/MonkeyDono)\
**Replies:** 5\
**Last updated:** [April 23, 2025, 6:01pm UTC](https://discuss.elastic.co/t/logstash-troubleshooting-error-eacces-permission-denied-to-output-file-path/377407 "2025-04-23T18:01:01Z")

</div>

Hello I've been using Logstash for integration with Wazuh. Usually I hadn't have any issues by this since the pipeline it's pretty straight forward. My usuall config is the next one: input { syslog { port =\> …

---

## [Logstash: Client requested protocol TLSv1 is not enabled or supported in server context](https://discuss.elastic.co/t/logstash-client-requested-protocol-tlsv1-is-not-enabled-or-supported-in-server-context/377451)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 0\
**Last updated:** [April 23, 2025, 3:23pm UTC](https://discuss.elastic.co/t/logstash-client-requested-protocol-tlsv1-is-not-enabled-or-supported-in-server-context/377451 "2025-04-23T15:23:27Z")

</div>

Logstash version 7.17. Can advise on why this error incessantly appears in the Logstash log, or any steps to figure out why? \[2025-04-22T14:00:00,158\]\[ERROR\]\[logstash.inputs.tcp \] null: closing due: io.netty.handl…

---

## [Output Plugin for Azure LAW or EventHub](https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360)

<div class="topic-metadata">

**Author:** [@ricki1234](https://discuss.elastic.co/u/ricki1234)\
**Replies:** 3\
**Last updated:** [April 23, 2025, 5:17am UTC](https://discuss.elastic.co/t/output-plugin-for-azure-law-or-eventhub/377360 "2025-04-23T05:17:12Z")

</div>

Hello I'm trying to get data from an elasticsearch cluster to an Azure log-analytics-workspace or to an azure eventhub. Are there any output-plugins (I've read about the microsoft-logstash-output-azure-loganalytics - do…

---

## [JDBC - This driver is not configured for integrated authentication](https://discuss.elastic.co/t/jdbc-this-driver-is-not-configured-for-integrated-authentication/377225)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 2\
**Last updated:** [April 17, 2025, 2:03pm UTC](https://discuss.elastic.co/t/jdbc-this-driver-is-not-configured-for-integrated-authentication/377225 "2025-04-17T14:03:21Z")

</div>

Trying to connect to my Sql Server Instance thru Windows Authentication using the following configuration: input { udp { port =\> 517 } } filter { mutate { gsub =\> \[ "message", "\\u0000", "\[0x00\]" \] } mutate { gsub …

---

## [What's the difference between UDP workers and Pipeline Workers](https://discuss.elastic.co/t/whats-the-difference-between-udp-workers-and-pipeline-workers/377220)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 0\
**Last updated:** [April 16, 2025, 8:04pm UTC](https://discuss.elastic.co/t/whats-the-difference-between-udp-workers-and-pipeline-workers/377220 "2025-04-16T20:04:02Z")

</div>

As the question says, I am curious to understand the different impacts of having multiple Pipeline Workers and multiple UDP input plugin Workers. No much information can be found in the documentation. How would you siz…

---

## [logstash is issue](https://discuss.elastic.co/t/logstash-is-issue/377176)

<div class="topic-metadata">

**Author:** [@yunguo](https://discuss.elastic.co/u/yunguo)\
**Replies:** 2\
**Last updated:** [April 16, 2025, 8:57am UTC](https://discuss.elastic.co/t/logstash-is-issue/377176 "2025-04-16T08:57:10Z")

</div>

/usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/concurrent-ruby-1.1.9/lib/concurrent-ruby/concurrent/executor/java\_thread\_pool\_executor.rb:13: warning: method redefined; discarding old to\_int /usr/share/logstash/vend…

---

## [Why do errors occur when running in a kubernetes cluster?](https://discuss.elastic.co/t/why-do-errors-occur-when-running-in-a-kubernetes-cluster/376737)

<div class="topic-metadata">

**Author:** [@Vladimir\_Fomin1](https://discuss.elastic.co/u/Vladimir_Fomin1)\
**Replies:** 1\
**Last updated:** [April 3, 2025, 11:51am UTC](https://discuss.elastic.co/t/why-do-errors-occur-when-running-in-a-kubernetes-cluster/376737 "2025-04-03T11:51:56Z")

</div>

After I run Logstash in a Kubernetes cluster with the settings of input { gelf { port =\> 7003 type =\> "some-type-1" } gelf { port =\> 7004 type =\> "some-type-2" …

---

## [Elastic-agent + Logstash (for enrichment) + Elasticsearch](https://discuss.elastic.co/t/elastic-agent-logstash-for-enrichment-elasticsearch/377104)

<div class="topic-metadata">

**Author:** [@francesco.amato](https://discuss.elastic.co/u/francesco.amato)\
**Replies:** 5\
**Last updated:** [April 16, 2025, 7:03am UTC](https://discuss.elastic.co/t/elastic-agent-logstash-for-enrichment-elasticsearch/377104 "2025-04-16T07:03:38Z")

</div>

Hello to everyone We have this structure: 1 Elasticsearch Cluster 1 Elastic-agent managed by our Fleet server 1 Logstash instance installed on the elastic-agent We have already configured the elastic-agent to send UD…

---

## [Esitmate Logstash Requirement on Centerlized Managed](https://discuss.elastic.co/t/esitmate-logstash-requirement-on-centerlized-managed/377127)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 1\
**Last updated:** [April 15, 2025, 7:59pm UTC](https://discuss.elastic.co/t/esitmate-logstash-requirement-on-centerlized-managed/377127 "2025-04-15T19:59:32Z")

</div>

I’m currently using centralized Logstash management from Kibana, with a single pipeline in place. Logstash Version: 8.11 Elasticsearch Version: 8.11 Here’s my pipeline configuration: input { elasticsearch { hos…

---

## [\[Solved\] Error in logstash elasticsearch:9200](https://discuss.elastic.co/t/solved-error-in-logstash-elasticsearch-9200/376927)

<div class="topic-metadata">

**Author:** [@GabrielMunumel](https://discuss.elastic.co/u/GabrielMunumel)\
**Replies:** 1\
**Last updated:** [April 15, 2025, 5:21pm UTC](https://discuss.elastic.co/t/solved-error-in-logstash-elasticsearch-9200/376927 "2025-04-15T17:21:13Z")

</div>

Hello, I'm running a ElasticStack using a docker compose. The errors in logstash are: \[2025-04-08T17:04:18,301\]\[WARN \]\[logstash.licensechecker.licensereader\] Attempted to resurrect connection to dead ES instance, but g…

---

## [Ingesting XML data from UDP input plugin thru elasticsearch output plugin](https://discuss.elastic.co/t/ingesting-xml-data-from-udp-input-plugin-thru-elasticsearch-output-plugin/377125)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 1\
**Last updated:** [April 14, 2025, 11:51pm UTC](https://discuss.elastic.co/t/ingesting-xml-data-from-udp-input-plugin-thru-elasticsearch-output-plugin/377125 "2025-04-14T23:51:21Z")

</div>

Hello everyone, I need to ingest an XML received over UDP input plugin. The output plugin needs to be "elasticsearch". This is an example of XML: \<EVENT\> \<HOST\>FRANCESCOE-RMT\</HOST\> \<INSTANCEID\>3C38C41D-9F66-47AB-AF8D…

---

## [Conexion de elastic con orracle database](https://discuss.elastic.co/t/conexion-de-elastic-con-orracle-database/377116)

<div class="topic-metadata">

**Author:** [@angeles\_martinez\_dom](https://discuss.elastic.co/u/angeles_martinez_dom)\
**Replies:** 3\
**Last updated:** [April 14, 2025, 8:13pm UTC](https://discuss.elastic.co/t/conexion-de-elastic-con-orracle-database/377116 "2025-04-14T20:13:40Z")

</div>

hola estoy tratando de conectarme a una base de datos pero al momento de correr mi archivo de configuracion sale lo sig. a alguien le pasa lo mismo?

---

## [Elastic search cluster x-pack security](https://discuss.elastic.co/t/elastic-search-cluster-x-pack-security/377103)

<div class="topic-metadata">

**Author:** [@Akash\_More](https://discuss.elastic.co/u/Akash_More)\
**Replies:** 0\
**Last updated:** [April 14, 2025, 10:23am UTC](https://discuss.elastic.co/t/elastic-search-cluster-x-pack-security/377103 "2025-04-14T10:23:30Z")

</div>

Hello sir, I am using two IPs: 92 and 93. On IP 92, node-1 is installed, and on IP 93, node-2 is installed. After that, I added two extra nodes using the tar file on each IP, so now on IP 92, nodes 1, 3, and 4 are instal…

---

## [Understanding Logstash pipeline to pipeline communication](https://discuss.elastic.co/t/understanding-logstash-pipeline-to-pipeline-communication/377064)

<div class="topic-metadata">

**Author:** [@LogstashQuestions](https://discuss.elastic.co/u/LogstashQuestions)\
**Replies:** 2\
**Last updated:** [April 12, 2025, 5:44am UTC](https://discuss.elastic.co/t/understanding-logstash-pipeline-to-pipeline-communication/377064 "2025-04-12T05:44:37Z")

</div>

I'm trying to fix some performance issues in a Logstash pipeline that was set up using pipeline to pipeline communication but I'm not sure if the way it was set up makes sense. There are 2 pipelines defined, with the fir…

---

## [Logstash RabbitMQ Input Plugin Consumes Messages Despite ack =\> false Setting](https://discuss.elastic.co/t/logstash-rabbitmq-input-plugin-consumes-messages-despite-ack-false-setting/377002)

<div class="topic-metadata">

**Author:** [@fakman0](https://discuss.elastic.co/u/fakman0)\
**Replies:** 7\
**Last updated:** [April 11, 2025, 4:33pm UTC](https://discuss.elastic.co/t/logstash-rabbitmq-input-plugin-consumes-messages-despite-ack-false-setting/377002 "2025-04-11T16:33:17Z")

</div>

Description: I'm using Logstash with RabbitMQ input plugin to read messages from a queue and write them to Elasticsearch. I want Logstash to only read the messages without consuming them (like a logger), but it's still …

---

## [HTTP end point to call Logstash API](https://discuss.elastic.co/t/http-end-point-to-call-logstash-api/376980)

<div class="topic-metadata">

**Author:** [@rmeemanage](https://discuss.elastic.co/u/rmeemanage)\
**Replies:** 1\
**Last updated:** [April 10, 2025, 4:14pm UTC](https://discuss.elastic.co/t/http-end-point-to-call-logstash-api/376980 "2025-04-10T16:14:10Z")

</div>

I want to call Logstash API in Elastic Cloud. How can I find HTTP endpoint url?

---

## [Skipping Integrations Server in favor of Logstash](https://discuss.elastic.co/t/skipping-integrations-server-in-favor-of-logstash/376960)

<div class="topic-metadata">

**Author:** [@H\_TS](https://discuss.elastic.co/u/H_TS)\
**Replies:** 5\
**Last updated:** [April 10, 2025, 2:52pm UTC](https://discuss.elastic.co/t/skipping-integrations-server-in-favor-of-logstash/376960 "2025-04-10T14:52:11Z")

</div>

Hello everyone, I am new to the Elastic Stack and have learned a lot about it in the past weeks. I am currently looking into the Elastic Cloud as it got me exited after researching the Elastic Stack. One thing I notice…

---

## [Unable to use env variable with multiple hosts, for ES hosts output](https://discuss.elastic.co/t/unable-to-use-env-variable-with-multiple-hosts-for-es-hosts-output/372982)

<div class="topic-metadata">

**Author:** [@Maeris](https://discuss.elastic.co/u/Maeris)\
**Replies:** 3\
**Last updated:** [April 10, 2025, 8:47am UTC](https://discuss.elastic.co/t/unable-to-use-env-variable-with-multiple-hosts-for-es-hosts-output/372982 "2025-04-10T08:47:35Z")

</div>

Hi, I'm running logstash in a k8s cluster using the logstash helm chart. I have a .env file from which I create a k8s secret, which is used within logstash. in my .env, I have my hosts defined like: ES\_NODES="elk1.ho…

---

## [Field Enrichment](https://discuss.elastic.co/t/field-enrichment/376958)

<div class="topic-metadata">

**Author:** [@Gowtham1](https://discuss.elastic.co/u/Gowtham1)\
**Replies:** 0\
**Last updated:** [April 9, 2025, 1:16pm UTC](https://discuss.elastic.co/t/field-enrichment/376958 "2025-04-09T13:16:06Z")

</div>

Hi, How to enrich the field from one kafka topic/index to another kafka topic/index? (eg) Field name "device.model.class". I want to enrich the field device.model.class from one kafka topic/index to another kafka topic…

---

## [Receiving elasticsearch bulks in Logstash input](https://discuss.elastic.co/t/receiving-elasticsearch-bulks-in-logstash-input/376867)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 2\
**Last updated:** [April 8, 2025, 8:58am UTC](https://discuss.elastic.co/t/receiving-elasticsearch-bulks-in-logstash-input/376867 "2025-04-08T08:58:34Z")

</div>

Hi, Now, we use direct integration, application (es\_output) to elasticsearch (using ingest pipeline) But we would like to add logstash to our architecture. Is it possible to don't change output in the application, so e…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=6)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=8)
