# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=79

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 80

---

## [Logstash "Connection Refused"](https://discuss.elastic.co/t/logstash-connection-refused/330748)

<div class="topic-metadata">

**Author:** [@baba72210](https://discuss.elastic.co/u/baba72210)\
**Replies:** 11\
**Last updated:** [April 26, 2023, 12:02pm UTC](https://discuss.elastic.co/t/logstash-connection-refused/330748 "2023-04-26T12:02:12Z")

</div>

Hello, I'm using a docker-compose to start my whole stack and I have a problem with my logstash. I have two errors on my logstash logs. elasticsearch - Failed to perform request {:message=\>"Connect to localhost:9200 \[l…

---

## [Logstash : Codec multiline problem](https://discuss.elastic.co/t/logstash-codec-multiline-problem/330812)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 9:20am UTC](https://discuss.elastic.co/t/logstash-codec-multiline-problem/330812 "2023-04-26T09:20:11Z")

</div>

Each time logstash try to parse a log like this : 09-Mar-2023 16:45:40.861 SEVERE \[main\] org.apache.catalina.core.StandardContext.listenerStart Exception sending context initialized event to listener instance of class \[…

---

## [Module s3 input does not work error](https://discuss.elastic.co/t/module-s3-input-does-not-work-error/329522)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 8:11am UTC](https://discuss.elastic.co/t/module-s3-input-does-not-work-error/329522 "2023-04-26T08:11:58Z")

</div>

Hi all, ran into this problem. At some point after upgrading from version 7 to 8, my S3 input module stopped working correctly. I see in the logs that the module connects to S3 and that it tries to deduct the content, …

---

## [Use logstash as a central logging server for log files exported from various devices](https://discuss.elastic.co/t/use-logstash-as-a-central-logging-server-for-log-files-exported-from-various-devices/330689)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 6:21pm UTC](https://discuss.elastic.co/t/use-logstash-as-a-central-logging-server-for-log-files-exported-from-various-devices/330689 "2023-04-25T18:21:55Z")

</div>

Hi All, I want to use logstash as a central logging server for storing log files exported from various devices. The log files can contain structured as well as un-structured data. Also I would like to store binary files…

---

## [Connecting logstash to remote elasticsearch running on https with no port specified](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/330587)

<div class="topic-metadata">

**Author:** [@Yahia-M](https://discuss.elastic.co/u/Yahia-M)\
**Replies:** 4\
**Last updated:** [April 25, 2023, 3:31pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/330587 "2023-04-25T15:31:29Z")

</div>

Hello , i am running Elasticsearch on a website called Cloud IDE gitpod. Once i start the docker image on the gitpod, docker-compose up --build Elasticsearch will start successfully i get a full https public url to ac…

---

## [ELK stack lifecycle management](https://discuss.elastic.co/t/elk-stack-lifecycle-management/330663)

<div class="topic-metadata">

**Author:** [@mphilip9](https://discuss.elastic.co/u/mphilip9)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elk-stack-lifecycle-management/330663 "2023-04-25T13:28:27Z")

</div>

I just took over an ELK stack app and I want to set up some proper index lifecycle management policies. From my understanding, I create an index lifecycle policy, and then I add/associate that policy with an index templa…

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/330741)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 12:57pm UTC](https://discuss.elastic.co/t/issue-with-logstash/330741 "2023-04-25T12:57:52Z")

</div>

Hello, I am trying to parse this JSON with Logstash. {"creation\_date": "2023/01/04", "vulnerabilities": \[{"count": 1, "score": null, "vuln\_index": 414, "plugin\_name": "WordPad History", "severity": 0, "vpr\_score": null,…

---

## [How to send subject field data from logstash to syslog server](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642)

<div class="topic-metadata">

**Author:** [@Thumati](https://discuss.elastic.co/u/Thumati)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642 "2023-04-25T06:25:52Z")

</div>

I would like to know if is it possible to send subject field to rsyslog server. Eg: subject : " username " should be sent.

---

## [Send Logs from Filebeat on my local machine to Logstash having a private ip](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:13pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352 "2023-04-24T19:13:10Z")

</div>

Hi i have installed filebeat on my local windows machine. I want to send logs to Logstash which has a private IP only and is in a different VPC. How can i set a connection between these two machines? Is it possible?

---

## [Creation of multiple logstash pipelines using API](https://discuss.elastic.co/t/creation-of-multiple-logstash-pipelines-using-api/330612)

<div class="topic-metadata">

**Author:** [@anjali\_roy](https://discuss.elastic.co/u/anjali_roy)\
**Replies:** 9\
**Last updated:** [April 24, 2023, 7:08pm UTC](https://discuss.elastic.co/t/creation-of-multiple-logstash-pipelines-using-api/330612 "2023-04-24T19:08:11Z")

</div>

I have a use case to create multiple Logstash pipelines inside a running Logstash container, Is it possible to use Logstash APIs as I do not have Elasticsearch and Kibana host. Just a Logstash running inside a cluster. I…

---

## [Geo\_Point field for mapping](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 5:53pm UTC](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363 "2023-04-24T17:53:27Z")

</div>

hey , im tryin g to create and have and geo\_point field to create a map visualisation , but im finding difficulties , my Lat and Long fields that i extracted previously from Geoip filter on My configuration file are flo…

---

## [Logstash show error "undefined method \`length' for nil:NilClass"](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373)

<div class="topic-metadata">

**Author:** [@C\_Wesley](https://discuss.elastic.co/u/C_Wesley)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 1:20pm UTC](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373 "2023-04-24T13:20:09Z")

</div>

Hi there, I have an issue with the title. When I send the JSON log to Filebeat and send it ti my logstash, sometimes it passes the filter, but sometimes it fails. Would you please help me check my configuration to see w…

---

## [Logstash Opensearch Configuration havin codec json](https://discuss.elastic.co/t/logstash-opensearch-configuration-havin-codec-json/330607)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 12:17pm UTC](https://discuss.elastic.co/t/logstash-opensearch-configuration-havin-codec-json/330607 "2023-04-24T12:17:04Z")

</div>

I am using opensearch with logstash, I wanted to use codec =\> json in output section of opensearch configuration. How can I achieve that? opensearch { hosts =\> \["${OPENSEARCH\_HOSTS}"\] index =\> "%{logplan…

---

## [Filter message log in logstash](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 2:37am UTC](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524 "2023-04-24T02:37:04Z")

</div>

i want to add filter to logstash to convert message to json format this is my example API response \< HTTP 200 - body: {"result": \[{"status": {"code": -18, "message": "No permission for the resource"}, "url": "/os/hi"}\]…

---

## [Not able to see index log file in elastic search](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 23, 2023, 8:06pm UTC](https://discuss.elastic.co/t/not-able-to-see-index-log-file-in-elastic-search/330571 "2023-04-23T20:06:46Z")

</div>

I am sending this log file web\_access.log 54.36.149.41 - - \[22/Jan/2019:03:56:14 +0330\] "GET /filter/27|13%20%D9%85%DA%AF%D8%A7%D9%BE%DB%8C%DA%A9%D8%B3%D9%84,27|%DA%A9%D9%85%D8%AA%D8%B1%20%D8%A7%D8%B2%205%20%D9%85%DA%A…

---

## [Logstash is not able to connect to workplace search](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 5:27pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-connect-to-workplace-search/330585 "2023-04-23T17:27:44Z")

</div>

Hi Team, I have added workplace search as a output plugin. output { elastic\_workplace\_search { source =\> "6555639ee4f75566c32f4298" access\_token =\> "efzq36opkajivo13judz65n9" url =\> "https://153.1.16.10:3…

---

## [Handle Json file](https://discuss.elastic.co/t/handle-json-file/330562)

<div class="topic-metadata">

**Author:** [@Ashraf123](https://discuss.elastic.co/u/Ashraf123)\
**Replies:** 2\
**Last updated:** [April 23, 2023, 3:35pm UTC](https://discuss.elastic.co/t/handle-json-file/330562 "2023-04-23T15:35:54Z")

</div>

Hello All, I have the following Json file collected by logstash. The problem I'm facing is with Item ID as it add json nested object with for each item. The problem I can't build dashboards for these items with this str…

---

## [How to implement data stream splitting for multiple types in Logstash's Java plugin?](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569)

<div class="topic-metadata">

**Author:** [@woxinfeishi](https://discuss.elastic.co/u/woxinfeishi)\
**Replies:** 0\
**Last updated:** [April 23, 2023, 2:32am UTC](https://discuss.elastic.co/t/how-to-implement-data-stream-splitting-for-multiple-types-in-logstashs-java-plugin/330569 "2023-04-23T02:32:42Z")

</div>

When using the logstash-input-rabbitmq plugin, multiple service logs can be collected by specifying different types in the same Logstash configuration file. Now I want to implement a Java version of the Logstash-input-ro…

---

## [How to handle default value for logstash pipeline efficiently?](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 2\
**Last updated:** [April 22, 2023, 8:19am UTC](https://discuss.elastic.co/t/how-to-handle-default-value-for-logstash-pipeline-efficiently/330335 "2023-04-22T08:19:22Z")

</div>

I have a logstash pipeline that its filter part looks like this: filter { if condition { prune { blacklist\_names =\> \["^cat\[1-8\]$","^classifier.version$","^accessory\_check$"\] …

---

## [Can I move my sysmon service to another folder](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:55pm UTC](https://discuss.elastic.co/t/can-i-move-my-sysmon-service-to-another-folder/330542 "2023-04-21T20:55:11Z")

</div>

When I install sysmon, I can put it in the sysmon folder that I choose. But why does the service reside in C:\\WINDOWS\\Sysmon.exe instead of where I would rather have it? thanks again for any advice or suggestions

---

## [Logstash JDBC input v5.4.1 crash pipeline when configured server is unreachable or if the server is not listening on db-port](https://discuss.elastic.co/t/logstash-jdbc-input-v5-4-1-crash-pipeline-when-configured-server-is-unreachable-or-if-the-server-is-not-listening-on-db-port/330530)

<div class="topic-metadata">

**Author:** [@VoP](https://discuss.elastic.co/u/VoP)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 3:45pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-v5-4-1-crash-pipeline-when-configured-server-is-unreachable-or-if-the-server-is-not-listening-on-db-port/330530 "2023-04-21T15:45:32Z")

</div>

Hello, Got some JDBC inputs configured in logstash, and after upgrade from logstash 7.16.2 and logstash-integration-jdbc (5.1.8) to logstash 8.6.2 and logstash-integration-jdbc (5.4.1), the pipeline crashes when the con…

---

## [Connect packetbeat to logstash](https://discuss.elastic.co/t/connect-packetbeat-to-logstash/330515)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 11:30am UTC](https://discuss.elastic.co/t/connect-packetbeat-to-logstash/330515 "2023-04-21T11:30:25Z")

</div>

I'm trying to pass data from packetbeat to logstash and I get this error "packetbeat setup output Exiting: index management requested but the Elasticsearch output is not configured/enabled " These are my settings. #…

---

## [LoLogs are not coming from filebeat to logstash to elasticsearch](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [April 21, 2023, 10:17am UTC](https://discuss.elastic.co/t/lologs-are-not-coming-from-filebeat-to-logstash-to-elasticsearch/330509 "2023-04-21T10:17:23Z")

</div>

Hi, I have installed filebeat on my windows machine. I've enabled the systema nd logstash module. Here is the filebeat.yml - type: filestream # Unique ID among all inputs, an ID is required. id: my-filestream-id …

---

## [Logstash : Codec multi line problem | failed to parse field \[time\] of type \[date\] in document](https://discuss.elastic.co/t/logstash-codec-multi-line-problem-failed-to-parse-field-time-of-type-date-in-document/330394)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [April 21, 2023, 9:21am UTC](https://discuss.elastic.co/t/logstash-codec-multi-line-problem-failed-to-parse-field-time-of-type-date-in-document/330394 "2023-04-21T09:21:05Z")

</div>

I think that there is a problem in my multi line pattern but I don't understand where :frowning: Here is my codec : file { path =\> "/var/log/all\_logs/\*\*/serverlogs/localhost.\*.log" start\_position =\> "beginnin…

---

## [Logstash JDBC input plugin: Stopped execution without any error log](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-stopped-execution-without-any-error-log/330186)

<div class="topic-metadata">

**Author:** [@adityasinghal26](https://discuss.elastic.co/u/adityasinghal26)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 8:40am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-stopped-execution-without-any-error-log/330186 "2023-04-21T08:40:41Z")

</div>

Hi Team, I am using Logstash 7.17 as a Kubernetes Deployment (replicas - 2). This logstash has only single pipeline which takes JDBC input from Oracle Database and indexes the records into Elasticsearch 7.17 (running on…

---

## [Logstash timestamp shift](https://discuss.elastic.co/t/logstash-timestamp-shift/330397)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 7\
**Last updated:** [April 21, 2023, 7:51am UTC](https://discuss.elastic.co/t/logstash-timestamp-shift/330397 "2023-04-21T07:51:56Z")

</div>

Hi ! I came across a strange behavior while parsing a timestamp epoch style date { match =\> \[ "eventtime\_ms","UNIX" \] target =\> "\[event\]\[created\]" timezone =\> "Etc/GMT+2" } date { match…

---

## [Logstash MYSQL jdbc](https://discuss.elastic.co/t/logstash-mysql-jdbc/330410)

<div class="topic-metadata">

**Author:** [@gabrile\_jaime\_gomez](https://discuss.elastic.co/u/gabrile_jaime_gomez)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 6:00am UTC](https://discuss.elastic.co/t/logstash-mysql-jdbc/330410 "2023-04-21T06:00:28Z")

</div>

H i, I'm trying to integrate with mysql and I get the following error. \[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"Java::JavaLang…

---

## [Multiline json data into logstash](https://discuss.elastic.co/t/multiline-json-data-into-logstash/330484)

<div class="topic-metadata">

**Author:** [@andrew0087b](https://discuss.elastic.co/u/andrew0087b)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 9:56pm UTC](https://discuss.elastic.co/t/multiline-json-data-into-logstash/330484 "2023-04-20T21:56:45Z")

</div>

Hello, I have the following JSON structure that I want to parse with Logstash: { "messages" : \[ { "remoteReferenceId" : "133883", "sender" : { "name" : "User1" } }, { "remoteReferenceId" : "13…

---

## [Logstash can't connect to elasticsearch](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch/330041)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 7:50pm UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch/330041 "2023-04-20T19:50:41Z")

</div>

Hi friends, please your help, we have this message: in log from logstash \[2023-04-14T20:49:18,951\]\[INFO \]\[logstash.outputs.elasticsearch\]\[rpa\_centria\_test\] Failed to perform request {:message=\>"PKIX path building failed…

---

## [About Beats Input](https://discuss.elastic.co/t/about-beats-input/330322)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 5\
**Last updated:** [April 20, 2023, 2:40pm UTC](https://discuss.elastic.co/t/about-beats-input/330322 "2023-04-20T14:40:54Z")

</div>

Hi, We occasionally receive log lines like this at the beats input: {"level":"info","ts":1681833658.6787357,"caller":"filterprocessor@v0.75.0/traces.go:74","msg":"Span filter configured","env":"","hostname":"tst","tags…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=78)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=80)
