# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=83

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 84

---

## [How to grok catalina log file](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895 "2023-03-30T07:24:33Z")

</div>

I have context my config logstash for tomcat filtertomcat filter { if \[fileset\]\[module\] == "tomcat" { if \[fileset\]\[name\] == "tomcatcatalina" { grok { match =\> \[ "message", "(?m)%{TOMCAT\_DATESTAMP:timestamp} %{LOG…

---

## [Is logstash necessarily](https://discuss.elastic.co/t/is-logstash-necessarily/328833)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 8\
**Last updated:** [March 30, 2023, 8:30pm UTC](https://discuss.elastic.co/t/is-logstash-necessarily/328833 "2023-03-30T20:30:36Z")

</div>

Hi everyone I'm testing ELK in a virtual environment (WinServer AD + DNS, Ubuntu Server 22.04, Ubuntu Client 22.04 and Win 10 Client) I've installed ELK stack on an Ubuntu Server 22.04 (I've been helped by a youtube vi…

---

## [Logstash not reading my config](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 5:13pm UTC](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958 "2023-03-30T17:13:32Z")

</div>

I have my config under /etc/logstash/conf.d/myconfig.conf. Below is my simple config input { file { path =\> "/home/foo/logs/\*.log" start\_position =\> "beginning" # stat\_interval =\> 1 # discover\_interval =\>…

---

## [Elastic document\_id](https://discuss.elastic.co/t/elastic-document-id/328738)

<div class="topic-metadata">

**Author:** [@bmagistro1](https://discuss.elastic.co/u/bmagistro1)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-document-id/328738 "2023-03-30T16:08:51Z")

</div>

Is there any defined behavior for document\_id (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic) similar to pipeline (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic)? We have at least o…

---

## [Why the "exec" input in logstash does not work?](https://discuss.elastic.co/t/why-the-exec-input-in-logstash-does-not-work/328808)

<div class="topic-metadata">

**Author:** [@JohnnyLee](https://discuss.elastic.co/u/JohnnyLee)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 10:02am UTC](https://discuss.elastic.co/t/why-the-exec-input-in-logstash-does-not-work/328808 "2023-03-29T10:02:24Z")

</div>

Hi, I failed to load shell script output to ELK with "exec" input plugin in logstash. Is there anything misconfigured in my configure file? Below is my logstash configuraitons. input { exec { command =\> "bash /r…

---

## [Logstash autorelaod even the config file not changed](https://discuss.elastic.co/t/logstash-autorelaod-even-the-config-file-not-changed/328881)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 4:35am UTC](https://discuss.elastic.co/t/logstash-autorelaod-even-the-config-file-not-changed/328881 "2023-03-30T04:35:16Z")

</div>

Hello Team, We use the logstash to consume the messages from Kafka and indexing into Elasticsearch and we use the vault to drop the cert and keys to connect to Kafka and Elasticsearch. vault rotates the cert and key dep…

---

## [Logstash License](https://discuss.elastic.co/t/logstash-license/327869)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 9:26pm UTC](https://discuss.elastic.co/t/logstash-license/327869 "2023-03-29T21:26:54Z")

</div>

Hi, Logstash is still covered by Elastic License v1 (ELv1) which has more restrictions than Elastic License v2 (ELv2): But Elasticsearch and Kibana are already migrated to ELv2. Is there any plan for migrating Logst…

---

## [Problem with my logstash file '.conf' for analyse syslog from my switchs](https://discuss.elastic.co/t/problem-with-my-logstash-file-conf-for-analyse-syslog-from-my-switchs/328750)

<div class="topic-metadata">

**Author:** [@Son\_Goku](https://discuss.elastic.co/u/Son_Goku)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 3:29pm UTC](https://discuss.elastic.co/t/problem-with-my-logstash-file-conf-for-analyse-syslog-from-my-switchs/328750 "2023-03-29T15:29:43Z")

</div>

Hello, I have install ELK stack 8.6 with elasticsearch, Logstash, Kibana, Filebeat and Metricbeats; Well ! I tested my server with a Logstash file "syslog.conf" with a beats input, who listen on 5044 port. It works, I …

---

## [Delete documents in Elasticsearch from Logstash](https://discuss.elastic.co/t/delete-documents-in-elasticsearch-from-logstash/328679)

<div class="topic-metadata">

**Author:** [@oo\_eyad](https://discuss.elastic.co/u/oo_eyad)\
**Replies:** 1\
**Last updated:** [March 29, 2023, 2:36pm UTC](https://discuss.elastic.co/t/delete-documents-in-elasticsearch-from-logstash/328679 "2023-03-29T14:36:53Z")

</div>

I have an index in Elasticsearch where the UID is automatically generated, I want to delete documents by query but from Logstash. I am trying different ways like http output plugin, is it the correct option to do so? or …

---

## [Convert String to Date field](https://discuss.elastic.co/t/convert-string-to-date-field/328752)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 2:11pm UTC](https://discuss.elastic.co/t/convert-string-to-date-field/328752 "2023-03-29T14:11:10Z")

</div>

I tried converting one of the string field to Date field , I can see in the logs that it could changed to date field because it's without quotes . but it's still showing the field is keyword. Logstash Config # "Submit …

---

## [How to forward index from filebeat to elasticsearch via logstash using http output](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587)

<div class="topic-metadata">

**Author:** [@majan3k](https://discuss.elastic.co/u/majan3k)\
**Replies:** 3\
**Last updated:** [March 29, 2023, 1:54pm UTC](https://discuss.elastic.co/t/how-to-forward-index-from-filebeat-to-elasticsearch-via-logstash-using-http-output/328587 "2023-03-29T13:54:23Z")

</div>

Hello, Hello, I am starting my journey with elasticsearch and I have a couple of questions. I tried to find answers in documentation but some areas are not clear for me and I am confused. If I understood correct, in o…

---

## [Parsing json inside json](https://discuss.elastic.co/t/parsing-json-inside-json/328496)

<div class="topic-metadata">

**Author:** [@eirik](https://discuss.elastic.co/u/eirik)\
**Replies:** 2\
**Last updated:** [March 29, 2023, 1:42pm UTC](https://discuss.elastic.co/t/parsing-json-inside-json/328496 "2023-03-29T13:42:14Z")

</div>

I'm new to logstash and wanted to test using it reading loglines from IBM Cloud and struggling with parsing this log record using logstash. The log line is a json object, and inside this one of the fields starts with pla…

---

## [How to change field name in all events in a list of json objects without splitting/with getting again a list of json objects in logstash?](https://discuss.elastic.co/t/how-to-change-field-name-in-all-events-in-a-list-of-json-objects-without-splitting-with-getting-again-a-list-of-json-objects-in-logstash/328807)

<div class="topic-metadata">

**Author:** [@fosota8](https://discuss.elastic.co/u/fosota8)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-to-change-field-name-in-all-events-in-a-list-of-json-objects-without-splitting-with-getting-again-a-list-of-json-objects-in-logstash/328807 "2023-03-29T09:57:00Z")

</div>

For example if i give logstash the following input: \[{"a": 1, "b": 2}, {"a": 14, "b": 65}\] and I want to change all "b" field names to "c", so I will get the following output: \[{"a": 1, "c": 2}, {"a": 14, "c": 65}\] The …

---

## [How ssl handshake will be happening for logstash output syslog client and syslog server side](https://discuss.elastic.co/t/how-ssl-handshake-will-be-happening-for-logstash-output-syslog-client-and-syslog-server-side/328795)

<div class="topic-metadata">

**Author:** [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 8:50am UTC](https://discuss.elastic.co/t/how-ssl-handshake-will-be-happening-for-logstash-output-syslog-client-and-syslog-server-side/328795 "2023-03-29T08:50:20Z")

</div>

How should we configure Syslog ssl certiificate at logstash(client) and syslog server end. From document what I understood is we will be having ssl\_cacert , ssl\_cert, ssl\_key at client end that is logstash. How about Se…

---

## [Cannot parse empty date](https://discuss.elastic.co/t/cannot-parse-empty-date/328687)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [March 29, 2023, 7:25am UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/328687 "2023-03-29T07:25:25Z")

</div>

Hi there, i'm facing an issue about empty date field. so my data is ingested from csv file. and some row has a empty date field. i already made a condition like this but i keep getting error like this response=\>{"in…

---

## [ELK - 8.6 (Filebeat to logstash) - only write ops with an op\_type of create are allowed in data streams](https://discuss.elastic.co/t/elk-8-6-filebeat-to-logstash-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/328401)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 12\
**Last updated:** [March 29, 2023, 1:54am UTC](https://discuss.elastic.co/t/elk-8-6-filebeat-to-logstash-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/328401 "2023-03-29T01:54:53Z")

</div>

Hello everyone: I got 2 physical server - one got elastic and 2nd one got Logstash & Kibana. I got filebeat running on our customer server from where I am harvesting data from the application log. Below is the error w…

---

## [Logstash runs but shows no output on server](https://discuss.elastic.co/t/logstash-runs-but-shows-no-output-on-server/328754)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 9:50pm UTC](https://discuss.elastic.co/t/logstash-runs-but-shows-no-output-on-server/328754 "2023-03-28T21:50:46Z")

</div>

I'm new to the Elastic Stack. I have a logstash config which parses and filters csv files and it looks like this: input { file { path =\> "/path/to/file" start\_position =\> "beginning" sincedb\_path =\>…

---

## [Lack of proper SSL credentials is crashing logstash](https://discuss.elastic.co/t/lack-of-proper-ssl-credentials-is-crashing-logstash/328728)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 3:30pm UTC](https://discuss.elastic.co/t/lack-of-proper-ssl-credentials-is-crashing-logstash/328728 "2023-03-28T15:30:25Z")

</div>

Is it possible to handle SSL exceptions gracefully in Logstash and prevent it from crashing out? At the moment I have SSL enabled on Filebeat side of things, as well as in Logstash. Everything is working fine if these SS…

---

## [JDBC driver library error](https://discuss.elastic.co/t/jdbc-driver-library-error/328705)

<div class="topic-metadata">

**Author:** [@Rakesh\_Mukherjee](https://discuss.elastic.co/u/Rakesh_Mukherjee)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 10:35am UTC](https://discuss.elastic.co/t/jdbc-driver-library-error/328705 "2023-03-28T10:35:50Z")

</div>

I am using Azure MySql server and trying to ingest logs to logstash using jdbc input plug-in. While running logstash, it is giving me error that Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<LogStash::PluginLoadin…

---

## [Get timestamp from your field](https://discuss.elastic.co/t/get-timestamp-from-your-field/328666)

<div class="topic-metadata">

**Author:** [@akeelow](https://discuss.elastic.co/u/akeelow)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 4:56am UTC](https://discuss.elastic.co/t/get-timestamp-from-your-field/328666 "2023-03-28T04:56:39Z")

</div>

The service writes logs in a special way. Part of the time is specified in the file name 23032807.log (yyMMddHHH). Minutes, seconds and microseconds are written inside the log 03:42.370003 (mm:ss.SSS). I created such a …

---

## [Several configuration files for one pipeline](https://discuss.elastic.co/t/several-configuration-files-for-one-pipeline/328640)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 6:34pm UTC](https://discuss.elastic.co/t/several-configuration-files-for-one-pipeline/328640 "2023-03-27T18:34:23Z")

</div>

I'm trying to reduce high cpu consumption in our logstash, so i decide to join several pipelines in one and run these configuration files as only one pipeline I'm testing with only two files without filter, only input a…

---

## [Logstash could not index event, how to view what server send the event](https://discuss.elastic.co/t/logstash-could-not-index-event-how-to-view-what-server-send-the-event/328619)

<div class="topic-metadata">

**Author:** [@ginokok1996](https://discuss.elastic.co/u/ginokok1996)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 1:28pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-how-to-view-what-server-send-the-event/328619 "2023-03-27T13:28:27Z")

</div>

Hi, We are currently receiving quite some errors relating to the same issue: \[2023-03-27T15:13:43,994\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:…

---

## [Best way to count documents in index](https://discuss.elastic.co/t/best-way-to-count-documents-in-index/328610)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 12:37pm UTC](https://discuss.elastic.co/t/best-way-to-count-documents-in-index/328610 "2023-03-27T12:37:33Z")

</div>

Hi Guys, I'm creating a pipeline to calculate a price. I need to multiply the number of documents of my index (with a filter like room = red) with a constant 1.27€. Could you please help me about the best way in order…

---

## [Is cloudfront codec for logstash working?](https://discuss.elastic.co/t/is-cloudfront-codec-for-logstash-working/328614)

<div class="topic-metadata">

**Author:** [@soumyajk](https://discuss.elastic.co/u/soumyajk)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 11:55am UTC](https://discuss.elastic.co/t/is-cloudfront-codec-for-logstash-working/328614 "2023-03-27T11:55:48Z")

</div>

Hello, Is Cloudfront codec working? logstash\[575080\]: \[2023-03-27T11:50:05,811\]\[ERROR\]\[logstash.inputs.s3 \]\[main\]\[cloudfront\] Failed to read file, processing skipped {:exception=\>Java::JavaLang::IllegalArgumentExc…

---

## [Logstash: replacement of the Coralogix/Ruby output plugin with http output plugin requires x2 resources](https://discuss.elastic.co/t/logstash-replacement-of-the-coralogix-ruby-output-plugin-with-http-output-plugin-requires-x2-resources/327558)

<div class="topic-metadata">

**Author:** [@AlexKonkin](https://discuss.elastic.co/u/AlexKonkin)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 6:56am UTC](https://discuss.elastic.co/t/logstash-replacement-of-the-coralogix-ruby-output-plugin-with-http-output-plugin-requires-x2-resources/327558 "2023-03-27T06:56:31Z")

</div>

According to the Coralogix they are going to drop support of their Coralogix/Ruby based plugin. As the replacement it is proposed to use http output plugin. You can find the relevant details by navigating the URL below:…

---

## [LRU cache in the Jdbc streaming filter plugin](https://discuss.elastic.co/t/lru-cache-in-the-jdbc-streaming-filter-plugin/328538)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 7:05am UTC](https://discuss.elastic.co/t/lru-cache-in-the-jdbc-streaming-filter-plugin/328538 "2023-03-26T07:05:08Z")

</div>

Hi All, when I parse the value to Jdbc streaming filter plugin to run the query for extract the results in the target, this values existing in the other input plugin, but the amount of values more than the time of quer…

---

## [Logstash - rabbitmq config to get multiple queues data to multiple elastic indeces](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520)

<div class="topic-metadata">

**Author:** [@qrshat](https://discuss.elastic.co/u/qrshat)\
**Replies:** 5\
**Last updated:** [March 25, 2023, 10:20pm UTC](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520 "2023-03-25T22:20:13Z")

</div>

scenario: rabbitmq have different queues more than three. I want to make logstash configuration to get data from the rabbitmq queue and index this data to Elasticsearch. In order to that I have created logstash conf fi…

---

## [Condicional if with Regex](https://discuss.elastic.co/t/condicional-if-with-regex/328417)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 4\
**Last updated:** [March 25, 2023, 1:21am UTC](https://discuss.elastic.co/t/condicional-if-with-regex/328417 "2023-03-25T01:21:46Z")

</div>

Hi everybody, Does anyone know how can I build a "if" condicional that logstash change de number "1" to string "Worked" ? As example, the input are lines like: hello,ola,1hi,1 1,red1,1,green 1 ... and the output…

---

## [Parsing JSON Array In Event](https://discuss.elastic.co/t/parsing-json-array-in-event/328393)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 9\
**Last updated:** [March 24, 2023, 9:54pm UTC](https://discuss.elastic.co/t/parsing-json-array-in-event/328393 "2023-03-24T21:54:24Z")

</div>

I am using the jdbc\_streaming filter to pull additional data for an event from a database, the result looks like below. Any ideas on how I could have this parsed out so that I don't lose any of the data and keep it all …

---

## [Change Nil values to set default value](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 7:29pm UTC](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369 "2023-03-24T19:29:14Z")

</div>

Logstash is dropping fields which has "nil" values, but I don't want those fields to be drop, but at least we can set it to default values if the field is nil, else it has it's original value. I tried with this code fou…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=82)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=84)
