# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=77

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 78

---

## [Install and run Logstash tar file](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 9:56am UTC](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899 "2023-05-10T09:56:13Z")

</div>

Hi, Good day! Does anyone know how to install and run logstash in a tar format binary? Thank you! Best regards, Hasmine Joyce Roldan

---

## [JDBC plugin - issue getting binary data](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:25am UTC](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537 "2023-05-10T09:25:26Z")

</div>

I use the JDBC plugin to get data from a MSSQL database. Generally this is working but my query output includes MD5 hashes saved as binary, and then the output looks something like this in stdout (and even more gibberish…

---

## [Grok debugger works, on logstash not](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930)

<div class="topic-metadata">

**Author:** [@psyskeletor](https://discuss.elastic.co/u/psyskeletor)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 8:23am UTC](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930 "2023-05-10T08:23:54Z")

</div>

Hi there. Super new to logstash. I wanted to extract exit code from logs, so i came with this solution using grok debugger filter { grok { match =\> { "message" =\> "(?\<exit\_code\>\\b\[exit code \]\\d+ \\b)" } …

---

## [Remove all backslash from fields in logstash](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041)

<div class="topic-metadata">

**Author:** [@SmoZyNS](https://discuss.elastic.co/u/SmoZyNS)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:08am UTC](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041 "2023-05-10T08:08:08Z")

</div>

Hello, what I am trying to do is to remove backslash as well as double quotes from fields after parsing them with kv. Here is the original input sent to logstash: \<14\>1 2023-05-09T15:06:23+02:00 NAS WinFileService - -…

---

## [Issue with logsatsh](https://discuss.elastic.co/t/issue-with-logsatsh/330227)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 38\
**Last updated:** [May 10, 2023, 6:34am UTC](https://discuss.elastic.co/t/issue-with-logsatsh/330227 "2023-05-10T06:34:23Z")

</div>

Hello, I am currently working on a subject. I am trying to parse my data in JSON format to store it in Elasticsearch, but Logstash is unable to parse my data and is generating errors. Can you help me?

---

## [Field in MSSQL as ID and the use of versioning](https://discuss.elastic.co/t/field-in-mssql-as-id-and-the-use-of-versioning/332414)

<div class="topic-metadata">

**Author:** [@Ric1](https://discuss.elastic.co/u/Ric1)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 7:34pm UTC](https://discuss.elastic.co/t/field-in-mssql-as-id-and-the-use-of-versioning/332414 "2023-05-09T19:34:01Z")

</div>

Hello, I hope I've put this in the correct place. My scenario is: I have data accessible via the JDBC input on MSSQL. The JDBC input plugin runs a command to find records that match a certain query. The output is an …

---

## [Form data in body for Logstash HTTP filter](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574)

<div class="topic-metadata">

**Author:** [@analog\_memories](https://discuss.elastic.co/u/analog_memories)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 7:18pm UTC](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574 "2023-05-09T19:18:37Z")

</div>

Hello, I was wondering if anyone has had the syntax for using form data in the body of HTTP filter. I have tried all manor of ways to make it work, and searched the forums, but have not found anything. This post is pr…

---

## [Getting ENOSPC error when using file output plugin in Logstash](https://discuss.elastic.co/t/getting-enospc-error-when-using-file-output-plugin-in-logstash/332985)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 6:26pm UTC](https://discuss.elastic.co/t/getting-enospc-error-when-using-file-output-plugin-in-logstash/332985 "2023-05-09T18:26:39Z")

</div>

Hi Team, I have the following logstash pipeline config. input { tcp { port =\> "${TCP\_PORT}" codec =\> line } } filter { grok { match =\> {"message" =\> "%{SYSLOGTIMESTAMP:time} %{DATA:s…

---

## [Manage several data stream(s) in the elasitcsearch output with interpolation](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981)

<div class="topic-metadata">

**Author:** [@Pascal\_Nuccio](https://discuss.elastic.co/u/Pascal_Nuccio)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 6:23pm UTC](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981 "2023-05-09T18:23:51Z")

</div>

If you need to manage several data streams for one LOGSTASH instance, you can configure the elasticsearch output like this in your logstash configuration: We must use a filter to configure the data\_stream parameters (ty…

---

## [Will the elasticsearch input plugin of logstash ensure no repeat reading after restart?](https://discuss.elastic.co/t/will-the-elasticsearch-input-plugin-of-logstash-ensure-no-repeat-reading-after-restart/332962)

<div class="topic-metadata">

**Author:** [@liusanyong](https://discuss.elastic.co/u/liusanyong)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 3:14pm UTC](https://discuss.elastic.co/t/will-the-elasticsearch-input-plugin-of-logstash-ensure-no-repeat-reading-after-restart/332962 "2023-05-09T15:14:19Z")

</div>

Hello, If use elasticsearch input plugin of logstash to read data from a elasticsearch index and do some processing. How to ensure it will not read repeated data after the logstash restarted ?

---

## [Logstash TCP and Syslog Plugin Error](https://discuss.elastic.co/t/logstash-tcp-and-syslog-plugin-error/330722)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 1:26pm UTC](https://discuss.elastic.co/t/logstash-tcp-and-syslog-plugin-error/330722 "2023-05-09T13:26:55Z")

</div>

Hello, I'm experiencing a Logstash error with the syslog input plugin. The input plugin for my pipeline keeps crashing with the message Force-closing a channel whose registration task was not accepted by an event loop …

---

## [Logstash logging](https://discuss.elastic.co/t/logstash-logging/332887)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 12:53pm UTC](https://discuss.elastic.co/t/logstash-logging/332887 "2023-05-09T12:53:34Z")

</div>

Hi! I was wondering if there is any location that stores the logs in Logstash before sending it to any destination? and if there, where and how can I find it? Thanks.

---

## [Queue.drain: true not working for logstash as K8s setup](https://discuss.elastic.co/t/queue-drain-true-not-working-for-logstash-as-k8s-setup/329236)

<div class="topic-metadata">

**Author:** [@Karthik\_N](https://discuss.elastic.co/u/Karthik_N)\
**Replies:** 18\
**Last updated:** [May 9, 2023, 12:21pm UTC](https://discuss.elastic.co/t/queue-drain-true-not-working-for-logstash-as-k8s-setup/329236 "2023-05-09T12:21:47Z")

</div>

Hi Team, We have issues in draining the logstash queue, this config is queue.drain: true not working. Our Current logstash setup in K8s and persistence queue setup in EBS volume, after killing our one of the logstash po…

---

## [Logstash - Convert JSON array and delete whitespaces from key fields](https://discuss.elastic.co/t/logstash-convert-json-array-and-delete-whitespaces-from-key-fields/332419)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 11:55am UTC](https://discuss.elastic.co/t/logstash-convert-json-array-and-delete-whitespaces-from-key-fields/332419 "2023-05-09T11:55:33Z")

</div>

Hi there, I'm using Logstash to receive events from winlogbeat and send them to Kafka which will ultimately send them further. To be able to correctly process those events at the end of the pipe, I need to : Convert t…

---

## [Logstash long nested messgage field in json format not getting parsed](https://discuss.elastic.co/t/logstash-long-nested-messgage-field-in-json-format-not-getting-parsed/332893)

<div class="topic-metadata">

**Author:** [@Alok\_ojha](https://discuss.elastic.co/u/Alok_ojha)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 8:57am UTC](https://discuss.elastic.co/t/logstash-long-nested-messgage-field-in-json-format-not-getting-parsed/332893 "2023-05-09T08:57:45Z")

</div>

Please Help!! I had data in kafka, I used logstash config file to upload it to elasticsearch, data is coming to elasticsearch but the message field is very long and logstash is unable to parse it in key value pair. Is t…

---

## [Is it possible to control the interval logstash send data to elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-control-the-interval-logstash-send-data-to-elasticsearch/332839)

<div class="topic-metadata">

**Author:** [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 8:13am UTC](https://discuss.elastic.co/t/is-it-possible-to-control-the-interval-logstash-send-data-to-elasticsearch/332839 "2023-05-09T08:13:13Z")

</div>

I'm very new to ELK, I'd like to know is it possible to control the interval logstash send data to elasticsearch? For example, I have a simple logstash config file running in /etc/logstash/conf.d folder: input { file…

---

## [Logstash file input](https://discuss.elastic.co/t/logstash-file-input/332802)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 0\
**Last updated:** [May 8, 2023, 10:00am UTC](https://discuss.elastic.co/t/logstash-file-input/332802 "2023-05-08T10:00:15Z")

</div>

Hi Team, Need some advice regarding configuration options for file input. If we have multiple patterns for files to watch for, what are pros and cons for below options Configuring each file path pattern as a dedicated…

---

## [Grok pattern](https://discuss.elastic.co/t/grok-pattern/332618)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 4\
**Last updated:** [May 5, 2023, 9:36am UTC](https://discuss.elastic.co/t/grok-pattern/332618 "2023-05-05T09:36:17Z")

</div>

Hi i am new to logstash can i get help on creating a grok pattern for following log line \[20/Apr/2023:11:25:44.389 +0530\] 200 | 38 ms | 2 B | 172.31.40.179 | 172.31.40.179 | 8DCE7CA611DB96B7B6767151C08E79B6 | - |…

---

## [Elasticsearch data indices is not creating when start\_position = beginning in logstash input file plugin?](https://discuss.elastic.co/t/elasticsearch-data-indices-is-not-creating-when-start-position-beginning-in-logstash-input-file-plugin/332286)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 2\
**Last updated:** [May 5, 2023, 7:46am UTC](https://discuss.elastic.co/t/elasticsearch-data-indices-is-not-creating-when-start-position-beginning-in-logstash-input-file-plugin/332286 "2023-05-05T07:46:45Z")

</div>

input { file { path =\> "/home/logs/info.log" type =\> "accesslog" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" stat\_interval =\> 5 ignore\_older =\> 0 }

---

## [\_source field in jdbc output](https://discuss.elastic.co/t/source-field-in-jdbc-output/332583)

<div class="topic-metadata">

**Author:** [@Valeriy\_Dzhura](https://discuss.elastic.co/u/Valeriy_Dzhura)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 4:34pm UTC](https://discuss.elastic.co/t/source-field-in-jdbc-output/332583 "2023-05-04T16:34:26Z")

</div>

Hello guys, I'm new in logstash. I have a question how I can return \_source field from elastic input to jdbc output. This is necessary for getting main fields and \_source should be stored like varchar(max) For example:…

---

## [How to upload json.file via logstash into elasticserch? What I did wrong?](https://discuss.elastic.co/t/how-to-upload-json-file-via-logstash-into-elasticserch-what-i-did-wrong/331377)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 4:26pm UTC](https://discuss.elastic.co/t/how-to-upload-json-file-via-logstash-into-elasticserch-what-i-did-wrong/331377 "2023-05-04T16:26:56Z")

</div>

json.file \[ { "sku":"00000290", "categories":"1\_brands,1\_restaurant\_equipment,2\_brand\_rm\_gastro,2\_food\_holding\_and\_warming\_equipment,3\_steam\_heaters\_and\_buffets,4\_bain\_marie\_heaters,categoryE7E7163", "family":"TV…

---

## [Error connecting Logstash to PostgresSQL Database](https://discuss.elastic.co/t/error-connecting-logstash-to-postgressql-database/331059)

<div class="topic-metadata">

**Author:** [@vineasouza](https://discuss.elastic.co/u/vineasouza)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 4:14pm UTC](https://discuss.elastic.co/t/error-connecting-logstash-to-postgressql-database/331059 "2023-05-04T16:14:50Z")

</div>

Hello guys, I'm trying to connect Logstash to a PostgresSQL database, but every time I run the pipeline, I'm getting the error Unable to configure plugins: (ArgumentError) Cannot determine timezone from nil . I've trie…

---

## [Logstash Service is active but still data is not passing to Elastic search](https://discuss.elastic.co/t/logstash-service-is-active-but-still-data-is-not-passing-to-elastic-search/332423)

<div class="topic-metadata">

**Author:** [@Sharath\_Subhash](https://discuss.elastic.co/u/Sharath_Subhash)\
**Replies:** 3\
**Last updated:** [May 4, 2023, 1:07pm UTC](https://discuss.elastic.co/t/logstash-service-is-active-but-still-data-is-not-passing-to-elastic-search/332423 "2023-05-04T13:07:40Z")

</div>

Hi, I am new to Logstash and Elastic search. I am currently going through documents and trying to fix a issue. Our logstash service is running active but data is not passing to Elasticsearch. "logstash.version"=\>"7.17.7…

---

## [Logstash not sending all data to elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-all-data-to-elasticsearch/330025)

<div class="topic-metadata">

**Author:** [@Koi\_Kin](https://discuss.elastic.co/u/Koi_Kin)\
**Replies:** 7\
**Last updated:** [May 4, 2023, 11:18am UTC](https://discuss.elastic.co/t/logstash-not-sending-all-data-to-elasticsearch/330025 "2023-05-04T11:18:13Z")

</div>

I have a simple jdbc connector without filter to fetch data from database to feed the elasticsearch with. input { jdbc { jdbc\_connection\_string =\> "#connectionstring" jdbc\_user =\> "#username" jdb…

---

## [Incremental data from oracle DB to elastic search using Logstash jdbc plugin](https://discuss.elastic.co/t/incremental-data-from-oracle-db-to-elastic-search-using-logstash-jdbc-plugin/332524)

<div class="topic-metadata">

**Author:** [@Jayasurya](https://discuss.elastic.co/u/Jayasurya)\
**Replies:** 0\
**Last updated:** [May 4, 2023, 9:23am UTC](https://discuss.elastic.co/t/incremental-data-from-oracle-db-to-elastic-search-using-logstash-jdbc-plugin/332524 "2023-05-04T09:23:23Z")

</div>

Hi, I am using Logstash jdbc plugin to ingest my data from oracle Database to Elasticsearch ,so this activity I can able to do. and the problem is while I need to take a incremental data and modified data to Elasticsear…

---

## [Ingestion not consistent, data loss](https://discuss.elastic.co/t/ingestion-not-consistent-data-loss/330512)

<div class="topic-metadata">

**Author:** [@Rui\_Goncalves](https://discuss.elastic.co/u/Rui_Goncalves)\
**Replies:** 6\
**Last updated:** [May 4, 2023, 6:44am UTC](https://discuss.elastic.co/t/ingestion-not-consistent-data-loss/330512 "2023-05-04T06:44:06Z")

</div>

Hi, We're ingesting a big amount of data from an oracle database into elastic through logstash. We import some oracle table information into different arrays in elastic. Each table corresponding to an array, and each r…

---

## [How to change the path of Jruby jar files in Logstash](https://discuss.elastic.co/t/how-to-change-the-path-of-jruby-jar-files-in-logstash/330909)

<div class="topic-metadata">

**Author:** [@sriteja\_chebrolu](https://discuss.elastic.co/u/sriteja_chebrolu)\
**Replies:** 1\
**Last updated:** [May 4, 2023, 6:30am UTC](https://discuss.elastic.co/t/how-to-change-the-path-of-jruby-jar-files-in-logstash/330909 "2023-05-04T06:30:32Z")

</div>

Large number of Jruby jar files are generating in Windows temp folder that filling up the C drive space. I want to change the path of those Jruby jar files. Can anyone please help me on this.

---

## [Logstash not able to pull multiple beats data (ELK 8.6)](https://discuss.elastic.co/t/logstash-not-able-to-pull-multiple-beats-data-elk-8-6/332424)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 4\
**Last updated:** [May 4, 2023, 3:54am UTC](https://discuss.elastic.co/t/logstash-not-able-to-pull-multiple-beats-data-elk-8-6/332424 "2023-05-04T03:54:44Z")

</div>

Hello all: I am trying to get my filebeat and metricbeat data from another server into logstash . I am using below command line at the logstash bin folder. And I got separate conf file for filebeat and metricbeat on my …

---

## [Logstash file input plugin](https://discuss.elastic.co/t/logstash-file-input-plugin/332259)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 3, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-file-input-plugin/332259 "2023-05-03T12:32:48Z")

</div>

Hi, I am trying to use logstash file input plugin. I want to pick files from multiple locations and send them to different indices. Here is my config nput { file { type =\> "TomEE-logs-passport" …

---

## [Logstash file input plugin picks different files other than specified path](https://discuss.elastic.co/t/logstash-file-input-plugin-picks-different-files-other-than-specified-path/332380)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [May 3, 2023, 6:42am UTC](https://discuss.elastic.co/t/logstash-file-input-plugin-picks-different-files-other-than-specified-path/332380 "2023-05-03T06:42:15Z")

</div>

Hi , I am using the file input plugin , here is my config nput { file { type =\> "tomeeaccess\_passport" path =\> "/etc/logstash/logs/localhost\_access\_log..2023-04-20.txt" start\_posi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=76)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=78)
