# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=75

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 76

---

## [\_geoip\_lookup\_failure in Logstash pipeline using GeoLite2-City.mmdb](https://discuss.elastic.co/t/geoip-lookup-failure-in-logstash-pipeline-using-geolite2-city-mmdb/333802)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 4\
**Last updated:** [May 19, 2023, 11:51pm UTC](https://discuss.elastic.co/t/geoip-lookup-failure-in-logstash-pipeline-using-geolite2-city-mmdb/333802 "2023-05-19T23:51:35Z")

</div>

Hi all When trying to enrich the following pipeline of my Logstash 8.4.3 with GeoIP info: input { file { path =\> "/var/log/apache2/\*.log" start\_position =\> "beginning" } http { } } fi…

---

## [Error wen put pipeline line on conf file (version 8.7)](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887)

<div class="topic-metadata">

**Author:** [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 8:49pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887 "2023-05-19T20:49:55Z")

</div>

Hello, i cant start service, because the logstash bring me this error when i put this lines in conf file. The given configuration is invalid. Reason: Expected one of \[ \\t\\r\\n\], "#", "input", "filter", "output" at line 1…

---

## [Logstash ConfigurationError - Failed to execute action](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874 "2023-05-19T14:25:51Z")

</div>

I'm getting a configuration error when try to start logstash: at line 13, column 28 (byte 213) after filter {\\n grok {\\n match =\> { \\"message\\" =\> \\"%{COMBINEDAPACHELOG}\\" }\\n }\\n date {\\n match =\> \[ \\"times…

---

## [Logstash w/ s3 output plugin - slow/delay](https://discuss.elastic.co/t/logstash-w-s3-output-plugin-slow-delay/333836)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-w-s3-output-plugin-slow-delay/333836 "2023-05-19T12:32:12Z")

</div>

Hello, I'm using Logstash 7.17.10 with S3 output plugin, and getting poor performance (possibly not related to performance) my pipeline: input { elasticsearch { docinfo =\> true docinfo\_fields =\> \[ …

---

## [Logstash is not working properly. \_grokparsefailure](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 9:07am UTC](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851 "2023-05-19T09:07:16Z")

</div>

strange behavior of the logstash, everything is parsed in the debugger, but not in the config - gives an error - \_grokparsefailure my logs 10.10.10.10.1680263940261.385400.G\_B2C\_BETA,03/31/2023 15:02:05.465,sf\_sap\_put\_…

---

## [Logstash JDBC input plugin: Java::OrgPostgresqlUtil::PSQLException: An I/O error occurred while sending to the backend](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848)

<div class="topic-metadata">

**Author:** [@Captain](https://discuss.elastic.co/u/Captain)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 7:46am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848 "2023-05-19T07:46:32Z")

</div>

I encountered this problem some time ago and have not been able to find a good solution. Finally, after I modified the configuration in the jvm.options file, the problem did not occur again. The original configuration "-…

---

## [Expected behavior of tcp/input/ssl\_verify=true?](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835)

<div class="topic-metadata">

**Author:** [@bennbrian65](https://discuss.elastic.co/u/bennbrian65)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 3:48am UTC](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835 "2023-05-19T03:48:38Z")

</div>

logstash 8.7.1, tcp input w/ssl\_verify=true. I expect that a sender using a cert w/no SANS and the sender’s host name does not match the cert’s CN would be rejected, but it is accepted. What does ssl\_verify=true govern?

---

## [Failed to parse date field with format strict\_date\_optional\_time||epoch\_millis](https://discuss.elastic.co/t/failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis/333734)

<div class="topic-metadata">

**Author:** [@Sachinda](https://discuss.elastic.co/u/Sachinda)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 9:08am UTC](https://discuss.elastic.co/t/failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis/333734 "2023-05-18T09:08:02Z")

</div>

Hi All, We are observing the following error in the Logstash serves only for the 2023.05.09 logs. This issue is not occurring in other date indexes. so we can see the 2023.05.08 and 2023.05.10 logs are available on the …

---

## [Java - not able to load FFI provider: How to start the logstash without the error?](https://discuss.elastic.co/t/java-not-able-to-load-ffi-provider-how-to-start-the-logstash-without-the-error/332788)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 7:33am UTC](https://discuss.elastic.co/t/java-not-able-to-load-ffi-provider-how-to-start-the-logstash-without-the-error/332788 "2023-05-18T07:33:35Z")

</div>

Tried to load logstash in a Centos environment \[INFO \]\[logstash.runner \] JVM bootstrap flags: \[-Xms1g, -Xmx1g, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djruby.compile.invokedynamic=true, -XX:+HeapDumpOnOutOfMem…

---

## [Logstash date parse failure - ruby exception](https://discuss.elastic.co/t/logstash-date-parse-failure-ruby-exception/333710)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 2\
**Last updated:** [May 18, 2023, 6:11am UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-ruby-exception/333710 "2023-05-18T06:11:49Z")

</div>

Hi, I am trying to use timestamp for each document by the value present in file name but i am getting Ruby exception occurred: wrong argument type DateTime (expected LogStash::Timestamp) when i run ruby code. it is wo…

---

## [Help with dissect in filter for logstash.conf to dynamically append filename to index patternNotFound Error](https://discuss.elastic.co/t/help-with-dissect-in-filter-for-logstash-conf-to-dynamically-append-filename-to-index-patternnotfound-error/333692)

<div class="topic-metadata">

**Author:** [@fsaa](https://discuss.elastic.co/u/fsaa)\
**Replies:** 2\
**Last updated:** [May 18, 2023, 1:43am UTC](https://discuss.elastic.co/t/help-with-dissect-in-filter-for-logstash-conf-to-dynamically-append-filename-to-index-patternnotfound-error/333692 "2023-05-18T01:43:40Z")

</div>

My folder structure is as follows: main\_directory. | .env | docker-compose.yml | +---elasticsearch | \\---config | elasticsearch.yml | \\---logstash +---config | | logstash.yml | | pipe…

---

## [Logstash - Syslog Output - Custom message](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333588)

<div class="topic-metadata">

**Author:** [@Nandhini\_Viswanathan](https://discuss.elastic.co/u/Nandhini_Viswanathan)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 4:18pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333588 "2023-05-16T16:18:03Z")

</div>

Logstash - Syslog Output - Custom message Hi, I'm I working with Logstash - Syslog Output and I've found out problem with setting custom field message. I'm using Elasticstack 7.8.0. I've installed logstash syslog-outp…

---

## [How logstash jdbc plugin fetch data from database](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 14\
**Last updated:** [May 17, 2023, 9:09pm UTC](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103 "2023-05-17T21:09:51Z")

</div>

Hi I have informix database that contain tons of tables and records that need to join some of them and send to elasticsearch. Result of this join are 70 columns and 100M records. Here is the requirements: 1-For first …

---

## [Issue with Beats forwarding to logstash](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689)

<div class="topic-metadata">

**Author:** [@vhaispdeaded](https://discuss.elastic.co/u/vhaispdeaded)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 6:49pm UTC](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689 "2023-05-17T18:49:16Z")

</div>

Our enterprise configures our AWS EC2 instances with Auditbeat, Filebeat, Journalbeat, Metricbeat, and Packetbeat to forward to a set of logstash servers. Our /var/log/messages, and /var/log/secure files are filled with …

---

## [Check if field from XML is object or array of objects?](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 5:50pm UTC](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686 "2023-05-17T17:50:19Z")

</div>

I have the following case happening. I have an application that is configured to send data via a webhook like push method via HTTP rest api whenever data is inserted in the application database. Im using this functionali…

---

## [Logstash config - Kafka and CEF](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669)

<div class="topic-metadata">

**Author:** [@elizZ](https://discuss.elastic.co/u/elizZ)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:18pm UTC](https://discuss.elastic.co/t/logstash-config-kafka-and-cef/333669 "2023-05-17T14:18:23Z")

</div>

Hi, I have a Logstash input of Kafka(codec cef), that consumes arcsight CEF format events from a kafka topic and writes it to elastic with 'elasticsearch' output I have an issue when some of the events have multiline f…

---

## [Logstash - Syslog Output - Custom message](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668)

<div class="topic-metadata">

**Author:** [@Nandhini\_Viswanathan](https://discuss.elastic.co/u/Nandhini_Viswanathan)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 2:07pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333668 "2023-05-17T14:07:31Z")

</div>

Hi, Reopening for Discussion. I'm working with Logstash - Syslog Output and I've found problem with custom field message. I'm using Elasticstack 7.10.2 I've installed logstash syslog-output plugin version 3.0.5. /usr…

---

## [Logstash JDBC insert after select completes](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 1:06pm UTC](https://discuss.elastic.co/t/logstash-jdbc-insert-after-select-completes/333660 "2023-05-17T13:06:51Z")

</div>

Hey All Just looking to understand if there is some way that I can run a SQL INSERT before and after a SELECT statement in the filter section to update a tracking table in the DB to say that the select query has started…

---

## [I want to put my grok inside if else block of logstash I want the fields to be displayed in kibana it's executing but not displaying the actual fields](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 8:48am UTC](https://discuss.elastic.co/t/i-want-to-put-my-grok-inside-if-else-block-of-logstash-i-want-the-fields-to-be-displayed-in-kibana-its-executing-but-not-displaying-the-actual-fields/333637 "2023-05-17T08:48:56Z")

</div>

filter { if \[IgmpSnooping\] == "%IGMPSNOOPING-6-NO\_IGMP\_QUERIER" { grok { match =\> { "message" =\> "\<%{INT:priority:int}\>%{SYSLOGTIMESTAMP:timestamp}\\s+%{HOSTNAME:device\_name}\\s+\\IgmpSnooping:\\s+%{DATA:IgmpSnooping}\\…

---

## [Grok filter working in online debuggers but not in actual implementation](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 8:35am UTC](https://discuss.elastic.co/t/grok-filter-working-in-online-debuggers-but-not-in-actual-implementation/333428 "2023-05-17T08:35:10Z")

</div>

This seems to give \_grokparsefailure a hundred percent of the time: if \[event\]\[action\]=="Process Creation" { grok { match =\> { "winlog.event\_data.NewProcessName" =\> "(?\<directory\>.\*)\\\\(?\<exe…

---

## [Logstash new record](https://discuss.elastic.co/t/logstash-new-record/333629)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 6:53am UTC](https://discuss.elastic.co/t/logstash-new-record/333629 "2023-05-17T06:53:52Z")

</div>

How to handle the logstash configuration in the case when I run the JDBC query and then there are no results through 1 to 10 minutes, if there is no result I need to generate a new record to store it in as document in th…

---

## [GeoIP filter missing some ECS fields](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 7\
**Last updated:** [May 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/geoip-filter-missing-some-ecs-fields/333339 "2023-05-17T05:18:00Z")

</div>

I am using the GeoIP Logstash filter and it seems to not have some desired fields for example \[mmdb\]\[isp\]. Overall it has no as or mmdb fields, as well as some other random fields. It does have all the geo fields however…

---

## [Logstash Syslog Input - Capture the Connecting Host's IP Address](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602)

<div class="topic-metadata">

**Author:** [@m52](https://discuss.elastic.co/u/m52)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 4:16am UTC](https://discuss.elastic.co/t/logstash-syslog-input-capture-the-connecting-hosts-ip-address/333602 "2023-05-17T04:16:35Z")

</div>

Hi, Newbie to Logstash here and could use some assistance regarding the Syslog input connector. I currently have the Syslog connector working successfully, but noticed the JSON output has a host.ip element that always…

---

## [Logstash cannot identify config file, it stops after starting , i am using docker desktop](https://discuss.elastic.co/t/logstash-cannot-identify-config-file-it-stops-after-starting-i-am-using-docker-desktop/333613)

<div class="topic-metadata">

**Author:** [@sakshi1](https://discuss.elastic.co/u/sakshi1)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:45pm UTC](https://discuss.elastic.co/t/logstash-cannot-identify-config-file-it-stops-after-starting-i-am-using-docker-desktop/333613 "2023-05-16T22:45:14Z")

</div>

so , i wrote an elasticsearch.yaml , which contains the configuration of elasticsearch, kibana and logstash. i will just attach the text version: '3.3' services: elasticsearch: image: docker.elastic.co/elasticsear…

---

## [Csv parse failure](https://discuss.elastic.co/t/csv-parse-failure/333049)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 2:45pm UTC](https://discuss.elastic.co/t/csv-parse-failure/333049 "2023-05-16T14:45:10Z")

</div>

Hello, I'm trying to parse a CSV file with Logstash, but I'm encountering a CSV parse failure. Can you please help me?

---

## [Mutate -\> Copy is not working as expected](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541)

<div class="topic-metadata">

**Author:** [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 2:42pm UTC](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541 "2023-05-16T14:42:54Z")

</div>

Im working on some json data, transforming and remapping fields add\_field, rename plugins are working as expected But whenever im using copy, output does not include these \[events\]\[date\], \[env\]\[app\] fields. But does in…

---

## [Java errors when running Logstash with database configuration](https://discuss.elastic.co/t/java-errors-when-running-logstash-with-database-configuration/333557)

<div class="topic-metadata">

**Author:** [@runnerpaul](https://discuss.elastic.co/u/runnerpaul)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:47am UTC](https://discuss.elastic.co/t/java-errors-when-running-logstash-with-database-configuration/333557 "2023-05-16T10:47:12Z")

</div>

I added the below jdbc config to my conf.d/logstash-simple.conf file. jdbc { add\_field =\> { "\[index\_name\]" =\> "pglogdb" } add\_field =\> { "\[@metadata\]\[beat\]" =\> "jdbc" } add\_field =\> { "\[@metadata\]\[version\]" …

---

## [Logstash Mapping - Duplicate values in nested properties](https://discuss.elastic.co/t/logstash-mapping-duplicate-values-in-nested-properties/333554)

<div class="topic-metadata">

**Author:** [@kgazula](https://discuss.elastic.co/u/kgazula)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:05am UTC](https://discuss.elastic.co/t/logstash-mapping-duplicate-values-in-nested-properties/333554 "2023-05-16T10:05:58Z")

</div>

Hello, can someone please help with mapping when there are more than 1 nested type properties in the mapping? We are using the 8.0 version and using Logstash we are synching the data from our Database to the ES index. P…

---

## [Logstash errors](https://discuss.elastic.co/t/logstash-errors/333531)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 6:48am UTC](https://discuss.elastic.co/t/logstash-errors/333531 "2023-05-16T06:48:32Z")

</div>

In some moment after i try to restart logstash i start to get errors like this, so everithing stoped to work. \[2023-05-16T16:43:06,516\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline worker error, the pipeline will be…

---

## [Logstash and/or Kibana config wrong](https://discuss.elastic.co/t/logstash-and-or-kibana-config-wrong/333317)

<div class="topic-metadata">

**Author:** [@mariolanno](https://discuss.elastic.co/u/mariolanno)\
**Replies:** 3\
**Last updated:** [May 15, 2023, 9:50pm UTC](https://discuss.elastic.co/t/logstash-and-or-kibana-config-wrong/333317 "2023-05-15T21:50:26Z")

</div>

Hi, I cannot understand why I create two indexes on logstash to grab syslogs from two devices and then send to EL. input { udp { host =\> "192.168.0.73" port =\> "5515" } } filter {} output { ela…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=74)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=76)
