# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=74

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 75

---

## [What is timezone that schedule (configuration option in elasticsearch input logstash) is based on?](https://discuss.elastic.co/t/what-is-timezone-that-schedule-configuration-option-in-elasticsearch-input-logstash-is-based-on/334223)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 2\
**Last updated:** [May 28, 2023, 4:15pm UTC](https://discuss.elastic.co/t/what-is-timezone-that-schedule-configuration-option-in-elasticsearch-input-logstash-is-based-on/334223 "2023-05-28T16:15:04Z")

</div>

I have following configuration in my logstash pipeline, I want to schedule to run the query for specific hour every day (schedule =\> "\*/5 \* \* \* \*" already working) , but it doesn't work. I have a distributed environment …

---

## [How to pass variable from Logstash filter into ruby parameter](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 4\
**Last updated:** [May 28, 2023, 3:59pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438 "2023-05-28T15:59:27Z")

</div>

Hi I'm trying to create a variable which holds information from input file path. I'm able to do so for example for creating index in Kibana but I'm unable to pass this variable into ruby /plugin/ code. Anyone knows what…

---

## [Most minimal logstash.yml possible?](https://discuss.elastic.co/t/most-minimal-logstash-yml-possible/334512)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [May 27, 2023, 9:37pm UTC](https://discuss.elastic.co/t/most-minimal-logstash-yml-possible/334512 "2023-05-27T21:37:20Z")

</div>

I would like to load all my inputs via the conf.d folder. What is most minimal logstash.yml fle I can have that will allow logstash to start and then load all the yml files in the conf.d folder? Current logstash.yml fi…

---

## [Logstash Split Message with Multiple Messages](https://discuss.elastic.co/t/logstash-split-message-with-multiple-messages/334466)

<div class="topic-metadata">

**Author:** [@balogan](https://discuss.elastic.co/u/balogan)\
**Replies:** 3\
**Last updated:** [May 27, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-split-message-with-multiple-messages/334466 "2023-05-27T14:36:39Z")

</div>

Logfile I need to ingest. You can see there are 3 separate messages under alerts. We need to split that up into 3 separate messages. { "@timestamp": "2023-05-23T18:15:30.537972Z", "alerts": \[ { "s…

---

## [Logstash aggregate and calculate the sum of counts](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [May 27, 2023, 10:20am UTC](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495 "2023-05-27T10:20:07Z")

</div>

Hello All, I have a scenario, I need the expertise to support this, and thanks in advanced I have a statement running by the JDBC input plugin every 1 minute, so the results returned every 1 minute until if the result…

---

## [Configpathloader no config files found in path= /etc/logstash/conf.d/\*.conf](https://discuss.elastic.co/t/configpathloader-no-config-files-found-in-path-etc-logstash-conf-d-conf/334465)

<div class="topic-metadata">

**Author:** [@Saud555](https://discuss.elastic.co/u/Saud555)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 6:03pm UTC](https://discuss.elastic.co/t/configpathloader-no-config-files-found-in-path-etc-logstash-conf-d-conf/334465 "2023-05-26T18:03:54Z")

</div>

I am getting an error while running the logstash Error configpathloader no config files found in path= /etc/logstash/conf.d/\* I have logstash.yml and pipelines.yml in place and cross checked all the configuration. but…

---

## [Failed to install microsoft-sentinel-logstash-output-plugin , error execution expired](https://discuss.elastic.co/t/failed-to-install-microsoft-sentinel-logstash-output-plugin-error-execution-expired/331085)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 5:54pm UTC](https://discuss.elastic.co/t/failed-to-install-microsoft-sentinel-logstash-output-plugin-error-execution-expired/331085 "2023-05-26T17:54:47Z")

</div>

Hi, I am unable to install the microsoft-sentinel-logstash-output-plugin on logstash server. I am running rhel7.9. I get the following error : ERROR: Something went wrong when installing install, microsoft-sentinel-lo…

---

## [Request for Updated Blog Post: Elastic Stack Monitoring with ES 8.7](https://discuss.elastic.co/t/request-for-updated-blog-post-elastic-stack-monitoring-with-es-8-7/333673)

<div class="topic-metadata">

**Author:** [@davidkov](https://discuss.elastic.co/u/davidkov)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 12:39pm UTC](https://discuss.elastic.co/t/request-for-updated-blog-post-elastic-stack-monitoring-with-es-8-7/333673 "2023-05-26T12:39:14Z")

</div>

Dear Sir, @shaunak I would like to express my gratitude for your insightful blog post titled 'Elastic Stack monitoring with Metricbeat via Logstash or Kafka' It has been instrumental in helping me set up a centralized …

---

## [Ruby error found during Logstash start with IBM Semeru Java](https://discuss.elastic.co/t/ruby-error-found-during-logstash-start-with-ibm-semeru-java/334431)

<div class="topic-metadata">

**Author:** [@KevinT1](https://discuss.elastic.co/u/KevinT1)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 12:35pm UTC](https://discuss.elastic.co/t/ruby-error-found-during-logstash-start-with-ibm-semeru-java/334431 "2023-05-26T12:35:53Z")

</div>

Logstash version: logstash-8.7.1 JDK: \> $ ./java -version \> java version "11.0.18" 2023-01-17 \> IBM Semeru Runtime Certified Edition 11.0.18.0 (build 11.0.18+10) \> Eclipse OpenJ9 VM 11.0.18.0 (build openj9-0.36.1, JRE …

---

## [How we can create two index in logstash](https://discuss.elastic.co/t/how-we-can-create-two-index-in-logstash/334082)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 12:10pm UTC](https://discuss.elastic.co/t/how-we-can-create-two-index-in-logstash/334082 "2023-05-26T12:10:38Z")

</div>

Hello, Anyone came across below scenario, I have a json as input and am filtering the data later creating index in output block to push it into elastic Here i want to split the data into two set and want them to send…

---

## [Logstash pipeline for aws cloudfront fixing timestamp issue](https://discuss.elastic.co/t/logstash-pipeline-for-aws-cloudfront-fixing-timestamp-issue/334411)

<div class="topic-metadata">

**Author:** [@miiimooo](https://discuss.elastic.co/u/miiimooo)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 9:38am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-aws-cloudfront-fixing-timestamp-issue/334411 "2023-05-26T09:38:52Z")

</div>

This took me ages to figure out so I thought it might be helpful for someone else. I'm parsing AWS CloudFront standard logs in logstash (v8.x) The included grok pattern worked fine for me apart from the timestamp, sinc…

---

## [Scale out logstash server and configure the output in the Fleet UI](https://discuss.elastic.co/t/scale-out-logstash-server-and-configure-the-output-in-the-fleet-ui/333383)

<div class="topic-metadata">

**Author:** [@A113n](https://discuss.elastic.co/u/A113n)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 5:29pm UTC](https://discuss.elastic.co/t/scale-out-logstash-server-and-configure-the-output-in-the-fleet-ui/333383 "2023-05-25T17:29:31Z")

</div>

Hi I have 1 logstash server configured and 1 fleet server. I now want to scale out logstash by 1 more server. The Elastic Agent have client side support for loadbalancing between multiple logstash servers: output.log…

---

## [Error starting Logstash pipeline after upgrading to Java 17](https://discuss.elastic.co/t/error-starting-logstash-pipeline-after-upgrading-to-java-17/334346)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:19pm UTC](https://discuss.elastic.co/t/error-starting-logstash-pipeline-after-upgrading-to-java-17/334346 "2023-05-25T16:19:21Z")

</div>

I have bundled Logstash within my Java application and launch it using JRuby. It worked fine until upgrading to Java 17. After upgrading, the pipeline fails to start with following exception : java.lang.IllegalAcce…

---

## [\[Logstash\] How to drop message if field is not a number](https://discuss.elastic.co/t/logstash-how-to-drop-message-if-field-is-not-a-number/333324)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 4\
**Last updated:** [May 25, 2023, 3:59pm UTC](https://discuss.elastic.co/t/logstash-how-to-drop-message-if-field-is-not-a-number/333324 "2023-05-25T15:59:49Z")

</div>

Hi Logstash gurus, I need to drop the messages that contain specific fields that are not a number. The filter I have is: filter { csv { separator =\> "," skip\_header =\> "true" columns =\> \["process-n…

---

## [Logstash plugin is installed and not listed and found by logstash](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595 "2023-05-23T21:24:34Z")

</div>

Hi Team, Microsoft-sentinel-logstash-output-plugin is installed on logstash (7.15.1) server Linux but is not listed and found by logstash : /usr/share/logstash/bin #./logstash-plugin list Plugin successfully install…

---

## [Corrupt index in Logstash causing primary shard is not active](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Aher](https://discuss.elastic.co/u/Vaibhav_Aher)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 2:34pm UTC](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229 "2023-05-24T14:34:19Z")

</div>

Elasticsearch Version- opendistroforelasticsearch-1.4.0 Logstash Version - logstash-7.4.2 Error on Logstash: retrying failed action with response code: 503 ({"type"=\>"unavailable\_shards\_exception", "reason"=\>"\[ABC-20…

---

## [Sending all elasticsearch logs to a diode](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 10:49am UTC](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207 "2023-05-24T10:49:57Z")

</div>

Hi there, I am completing some dev work and trying to input all of the ingested elasticsearch data from my system, into logstash (on the same server as elasticsearch) and output this to a one way data diode to allow the…

---

## [Sending logs from Filebeat(windows) to Logstash(Linux)](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112 "2023-05-24T06:18:57Z")

</div>

Hi, I have installed filebeat on windows machine and configured it to send logs to logstash. Here is my filebeat config filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can …

---

## [Write a RegEx to match the event pattern in log file](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048)

<div class="topic-metadata">

**Author:** [@hamzeha](https://discuss.elastic.co/u/hamzeha)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 9:31pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048 "2023-05-23T21:31:33Z")

</div>

Hi Everyone, I have application log file which contains the application requests and responses, the complete request and response looks like the below, I tried different patterns using RegEx but unfortunately without an…

---

## [Pipeline is running but index is not created at elasticsearch](https://discuss.elastic.co/t/pipeline-is-running-but-index-is-not-created-at-elasticsearch/333940)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 30\
**Last updated:** [May 23, 2023, 7:49pm UTC](https://discuss.elastic.co/t/pipeline-is-running-but-index-is-not-created-at-elasticsearch/333940 "2023-05-23T19:49:21Z")

</div>

I'm trying to create an index and loading one log file to Elasticsearch using logstash using below config: input { file { path =\> \["/mnt/c/databalanceInfo\_0.log"\] start\_position =\> "beginning" sincedb\_path =\> "…

---

## [Ruby API call when parser hit specific field](https://discuss.elastic.co/t/ruby-api-call-when-parser-hit-specific-field/334107)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 8\
**Last updated:** [May 23, 2023, 5:42pm UTC](https://discuss.elastic.co/t/ruby-api-call-when-parser-hit-specific-field/334107 "2023-05-23T17:42:03Z")

</div>

Hi, I'm trying to have Logstash make API call when it hits specific field using Ruby code but I'm unable to do so. Could someone smarter than me check what I'm doing wrong please? Ruby code: require 'uri' require 'net…

---

## [Duplication in logstash pipeline (input elasticsearch and output sql database)](https://discuss.elastic.co/t/duplication-in-logstash-pipeline-input-elasticsearch-and-output-sql-database/333982)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 2\
**Last updated:** [May 23, 2023, 8:27am UTC](https://discuss.elastic.co/t/duplication-in-logstash-pipeline-input-elasticsearch-and-output-sql-database/333982 "2023-05-23T08:27:35Z")

</div>

Hi , I am using elasicsearch index as my input in my logstash config and the output is jdbc-output plugin logstash that send logs to sql database table columns , and the problem is I have duplication in sql database , I…

---

## [Possability to use ELK-Stack for SNMP Monitoring like PRTG, CheckMK](https://discuss.elastic.co/t/possability-to-use-elk-stack-for-snmp-monitoring-like-prtg-checkmk/334073)

<div class="topic-metadata">

**Author:** [@tweak19](https://discuss.elastic.co/u/tweak19)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 5:49am UTC](https://discuss.elastic.co/t/possability-to-use-elk-stack-for-snmp-monitoring-like-prtg-checkmk/334073 "2023-05-23T05:49:21Z")

</div>

Hi, I would like to ask if there is a way to use ELK stack for SNMP polling of a large number of different devices with different SNMP v3 settings and different OIDs. The idea behind this is that I would have a system …

---

## [Unable to parse "message"](https://discuss.elastic.co/t/unable-to-parse-message/333635)

<div class="topic-metadata">

**Author:** [@bsauvage1](https://discuss.elastic.co/u/bsauvage1)\
**Replies:** 9\
**Last updated:** [May 23, 2023, 3:41am UTC](https://discuss.elastic.co/t/unable-to-parse-message/333635 "2023-05-23T03:41:55Z")

</div>

Hello. New user of logstash here so please bear with me! Sending over TCP from python using logstash\_async, I receive the item in logstash (see bottom of message). How can I parse the "message" into fields? I have tri…

---

## [I want to remove nested elements from logs](https://discuss.elastic.co/t/i-want-to-remove-nested-elements-from-logs/333979)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [May 22, 2023, 5:49pm UTC](https://discuss.elastic.co/t/i-want-to-remove-nested-elements-from-logs/333979 "2023-05-22T17:49:11Z")

</div>

i want to remove nested elements from logs "x": { "test": { "rulesetname": "eq", "operation": { "name": "diagnosticresult", "version": "235" }, "device": "string…

---

## [Logstash and AWS Cloudtrail](https://discuss.elastic.co/t/logstash-and-aws-cloudtrail/333927)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 3\
**Last updated:** [May 22, 2023, 5:33pm UTC](https://discuss.elastic.co/t/logstash-and-aws-cloudtrail/333927 "2023-05-22T17:33:57Z")

</div>

Help please. It appears that AWS cloudtrail puts multiple log records under one top level field, like this: "Records": \[ { "eventName": "AssumeRole", "requestParameters": { "durationSeconds": 1500, "role…

---

## [Logstash config](https://discuss.elastic.co/t/logstash-config/333631)

<div class="topic-metadata">

**Author:** [@A1i](https://discuss.elastic.co/u/A1i)\
**Replies:** 9\
**Last updated:** [May 22, 2023, 4:28am UTC](https://discuss.elastic.co/t/logstash-config/333631 "2023-05-22T04:28:57Z")

</div>

how can I config logstash to read two log files from local then pass them into two indies

---

## [Converting timezones in Logstash - HOWTO](https://discuss.elastic.co/t/converting-timezones-in-logstash-howto/333821)

<div class="topic-metadata">

**Author:** [@nbertram](https://discuss.elastic.co/u/nbertram)\
**Replies:** 2\
**Last updated:** [May 21, 2023, 9:12pm UTC](https://discuss.elastic.co/t/converting-timezones-in-logstash-howto/333821 "2023-05-21T21:12:27Z")

</div>

Hi, After trawling a lot of the internet asking how to convert a timestamp from UTC to local time in Logstash I came up blank, and against a whole bunch of answers on here saying "don't - leave that to the presentation …

---

## [2 conf sending data to the same index](https://discuss.elastic.co/t/2-conf-sending-data-to-the-same-index/333888)

<div class="topic-metadata">

**Author:** [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)\
**Replies:** 7\
**Last updated:** [May 20, 2023, 10:41pm UTC](https://discuss.elastic.co/t/2-conf-sending-data-to-the-same-index/333888 "2023-05-20T22:41:47Z")

</div>

Hello, I have 2 conf files and they are sending data at the same time to the 2 index (when I would like each conf to send the information to the specific index) If you can help me, I can provide more information if nee…

---

## [Weird Bug, Field name is blocked, cant use the same name of field it in other pipelines](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 5\
**Last updated:** [May 20, 2023, 2:25am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890 "2023-05-20T02:25:50Z")

</div>

Hi, I have a pipeline that stores the fields memory\_memused\_per and memory\_swapused\_per in an index , in another pipeline that stores data in another index I have tried to use the same name but nothing is indexed. after …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=73)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=75)
