# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=9

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 10

---

## [Logstash - Garbage Collection Issue](https://discuss.elastic.co/t/logstash-garbage-collection-issue/376219)

<div class="topic-metadata">

**Author:** [@sujesh\_js](https://discuss.elastic.co/u/sujesh_js)\
**Replies:** 1\
**Last updated:** [March 21, 2025, 3:33pm UTC](https://discuss.elastic.co/t/logstash-garbage-collection-issue/376219 "2025-03-21T15:33:02Z")

</div>

I need help. My code retrieves data from an external API, converts the response to JSON, and then iterates over it n times. The entire process takes approximately 30 minutes to complete, and the final output is sent to …

---

## [Create a Custom Log not import in logstash](https://discuss.elastic.co/t/create-a-custom-log-not-import-in-logstash/376222)

<div class="topic-metadata">

**Author:** [@brunopsitech](https://discuss.elastic.co/u/brunopsitech)\
**Replies:** 2\
**Last updated:** [March 21, 2025, 2:18pm UTC](https://discuss.elastic.co/t/create-a-custom-log-not-import-in-logstash/376222 "2025-03-21T14:18:06Z")

</div>

Hi, i have a log customized, and when i try read and input in elastic, nothing happens. The logstash dont generate any error or message. File INPUT: /var/log/link.log 2025-03-21T07:43:22-03:00 Link2 ON 2025-03-21T07:4…

---

## [Logstash and pipelines](https://discuss.elastic.co/t/logstash-and-pipelines/374287)

<div class="topic-metadata">

**Author:** [@Trent-alex](https://discuss.elastic.co/u/Trent-alex)\
**Replies:** 15\
**Last updated:** [March 21, 2025, 2:13pm UTC](https://discuss.elastic.co/t/logstash-and-pipelines/374287 "2025-03-21T14:13:31Z")

</div>

Hello, I am attempting my first pipeline from a csv to logstash. I am running elasticsearch and kibana on a single alma linux machine. I downloaded elasticsearch, logstash and kibana from the 8.17 webpage and after extr…

---

## [How to merge selected http headers into the doc fields](https://discuss.elastic.co/t/how-to-merge-selected-http-headers-into-the-doc-fields/376210)

<div class="topic-metadata">

**Author:** [@tmcarrara](https://discuss.elastic.co/u/tmcarrara)\
**Replies:** 1\
**Last updated:** [March 21, 2025, 8:03am UTC](https://discuss.elastic.co/t/how-to-merge-selected-http-headers-into-the-doc-fields/376210 "2025-03-21T08:03:15Z")

</div>

hello im trying to extract some headers from http request input and put into the document, but i dont know how to do that. this is what i tried: my environment: version: '3.8' services: elasticsearch: image: doc…

---

## [Cisco not sending clean syslog message](https://discuss.elastic.co/t/cisco-not-sending-clean-syslog-message/376195)

<div class="topic-metadata">

**Author:** [@justin3](https://discuss.elastic.co/u/justin3)\
**Replies:** 1\
**Last updated:** [March 20, 2025, 6:27pm UTC](https://discuss.elastic.co/t/cisco-not-sending-clean-syslog-message/376195 "2025-03-20T18:27:54Z")

</div>

I have a cisco WLC that is sending syslog to my logstash server but isn't sending clean syslog messages. It is adding extra stuff before the hostname, special characters before other parts of the message. I've found on…

---

## [Error 499 when using http\_poller](https://discuss.elastic.co/t/error-499-when-using-http-poller/376142)

<div class="topic-metadata">

**Author:** [@O\_O\_O](https://discuss.elastic.co/u/O_O_O)\
**Replies:** 2\
**Last updated:** [March 20, 2025, 2:45pm UTC](https://discuss.elastic.co/t/error-499-when-using-http-poller/376142 "2025-03-20T14:45:44Z")

</div>

I'm using http\_poller to get JSON data from an endpoint that runs on nginx in the background, I set the request\_timeout =\> 500 so as to give enough time for the request to be fulfilled. I'm getting persistent HTTP error …

---

## [Storing Open Telemetry metrics from Logstash to Elasticsearch Index](https://discuss.elastic.co/t/storing-open-telemetry-metrics-from-logstash-to-elasticsearch-index/376177)

<div class="topic-metadata">

**Author:** [@Dani\_Matar](https://discuss.elastic.co/u/Dani_Matar)\
**Replies:** 0\
**Last updated:** [March 20, 2025, 10:45am UTC](https://discuss.elastic.co/t/storing-open-telemetry-metrics-from-logstash-to-elasticsearch-index/376177 "2025-03-20T10:45:58Z")

</div>

I am integrating Open telemetry into my logging platform(elk stack). I have an application sending logs -\> otel collector(docker) -\> logstash(docker) -\> elasticsearch(docker). I am facing an issue when storing the metri…

---

## [Filebeat events are not distributed equally to the logstash pods](https://discuss.elastic.co/t/filebeat-events-are-not-distributed-equally-to-the-logstash-pods/376153)

<div class="topic-metadata">

**Author:** [@Nageswarrao\_Bandi](https://discuss.elastic.co/u/Nageswarrao_Bandi)\
**Replies:** 2\
**Last updated:** [March 20, 2025, 7:55am UTC](https://discuss.elastic.co/t/filebeat-events-are-not-distributed-equally-to-the-logstash-pods/376153 "2025-03-20T07:55:36Z")

</div>

I am using Filebeat, Logstash, Elastic search, Kibana in my Kubernetes cluster to monitor all my application logs. Let me explain the issue and share my configurations. Filebeat collecting the logs and sending the ev…

---

## [Not a valid logstash keystore](https://discuss.elastic.co/t/not-a-valid-logstash-keystore/376130)

<div class="topic-metadata">

**Author:** [@JosephR](https://discuss.elastic.co/u/JosephR)\
**Replies:** 0\
**Last updated:** [March 19, 2025, 2:40pm UTC](https://discuss.elastic.co/t/not-a-valid-logstash-keystore/376130 "2025-03-19T14:40:09Z")

</div>

When I set my keystore using the Elastic steps and add my keys it works fine and will not have any issues listing them or using them for what I need, however as soon as that server or the logstash service restarts I get …

---

## [Logstash pushes duplicate logs to elasticsearch](https://discuss.elastic.co/t/logstash-pushes-duplicate-logs-to-elasticsearch/376137)

<div class="topic-metadata">

**Author:** [@guru\_dev](https://discuss.elastic.co/u/guru_dev)\
**Replies:** 0\
**Last updated:** [March 19, 2025, 5:54pm UTC](https://discuss.elastic.co/t/logstash-pushes-duplicate-logs-to-elasticsearch/376137 "2025-03-19T17:54:18Z")

</div>

\[2025-03-19T00:05:31,618\]\[INFO \]\[logstash.outputs.elastic\]\[main\]\[f5eb5aca1c087bda2220eb216257aea3dd0ce51468b2b1e8aa414d37f871ded2\] Retrying failed action {:status=\>429, :action=\>\["index", {:\_id=\>"ea6cdea2b1e81ed5b4df4eeb…

---

## [Moved from 7.x to 8.x ... Maps stopped working](https://discuss.elastic.co/t/moved-from-7-x-to-8-x-maps-stopped-working/376112)

<div class="topic-metadata">

**Author:** [@alexolivan](https://discuss.elastic.co/u/alexolivan)\
**Replies:** 1\
**Last updated:** [March 19, 2025, 2:29pm UTC](https://discuss.elastic.co/t/moved-from-7-x-to-8-x-maps-stopped-working/376112 "2025-03-19T14:29:19Z")

</div>

Hi! I'm really stuck with this new geo\_point stuff. I have also read about disabling ECS compatibility mode on my pipeline but... I would rather learn the propper way to do thing from now ownwards. So, this is the upda…

---

## [Logstash isn't sending logs to Elastic Cloud Instance](https://discuss.elastic.co/t/logstash-isnt-sending-logs-to-elastic-cloud-instance/376118)

<div class="topic-metadata">

**Author:** [@Mohamad\_AbuZaitoun](https://discuss.elastic.co/u/Mohamad_AbuZaitoun)\
**Replies:** 1\
**Last updated:** [March 19, 2025, 2:16pm UTC](https://discuss.elastic.co/t/logstash-isnt-sending-logs-to-elastic-cloud-instance/376118 "2025-03-19T14:16:24Z")

</div>

NEED HELP! I have logstash installed on my Ubuntu server and there is a test drupal website served by apache2 web server, what I'm trying is to read this website logs which are written to a file inside /var/log/apache2,…

---

## [Logstash using multiple configuration](https://discuss.elastic.co/t/logstash-using-multiple-configuration/376032)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 4\
**Last updated:** [March 18, 2025, 2:33pm UTC](https://discuss.elastic.co/t/logstash-using-multiple-configuration/376032 "2025-03-18T14:33:40Z")

</div>

Hello again, From the previous threads that I have solved, now I have two Logstash configurations, one that output to Http pluging and one to elasticsearch plugin. I am configuring my D:\\logstash-7.17.28\\config\\pipelin…

---

## [Logstash \[ERROR\]\[logstash.licensechecker.licensereader\]](https://discuss.elastic.co/t/logstash-error-logstash-licensechecker-licensereader/376073)

<div class="topic-metadata">

**Author:** [@dev\_morphheus](https://discuss.elastic.co/u/dev_morphheus)\
**Replies:** 0\
**Last updated:** [March 18, 2025, 1:07pm UTC](https://discuss.elastic.co/t/logstash-error-logstash-licensechecker-licensereader/376073 "2025-03-18T13:07:26Z")

</div>

Hi, I just created a Logstash instance, and it returns the following error: log:\[2025-03-18T07:22:11,331\]\[ERROR\]\[logstash.licensechecker.licensereader\] Unable to retrieve license information from license server {:messa…

---

## [Aggregation Rule](https://discuss.elastic.co/t/aggregation-rule/375990)

<div class="topic-metadata">

**Author:** [@cybersc\_1](https://discuss.elastic.co/u/cybersc_1)\
**Replies:** 2\
**Last updated:** [March 18, 2025, 9:12am UTC](https://discuss.elastic.co/t/aggregation-rule/375990 "2025-03-18T09:12:44Z")

</div>

Hi there. I have plenty of logs on my logstash, and they look like this: Mar 17 10:43:04 xfirewall CEF:0|infotecs|xf|5.4|62|Non-encrypted forwarded IP packet passed|5|start=1742190120000 end=1742190120000 src=\*\*\*\* dst=\*…

---

## [Logstash error - Unable to retrieve Elasticsearch version](https://discuss.elastic.co/t/logstash-error-unable-to-retrieve-elasticsearch-version/375620)

<div class="topic-metadata">

**Author:** [@kawalkarhemant](https://discuss.elastic.co/u/kawalkarhemant)\
**Replies:** 22\
**Last updated:** [March 18, 2025, 6:07am UTC](https://discuss.elastic.co/t/logstash-error-unable-to-retrieve-elasticsearch-version/375620 "2025-03-18T06:07:38Z")

</div>

I am trying to trasanfer data from MSSQL to Elasticsearch using Logstash config file. But keep getting error message. \[2025-03-10T00:13:43,950\]\[WARN \]\[logstash.runner \] NOTICE: Running Logstash as a superuser …

---

## [Forwarding my bulk records from Http Input Plugin to Elasticsearch Output Plugin - Discuss the Elastic Stack](https://discuss.elastic.co/t/forwarding-my-bulk-records-from-http-input-plugin-to-elasticsearch-output-plugin-discuss-the-elastic-stack/375866)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 23\
**Last updated:** [March 17, 2025, 6:39pm UTC](https://discuss.elastic.co/t/forwarding-my-bulk-records-from-http-input-plugin-to-elasticsearch-output-plugin-discuss-the-elastic-stack/375866 "2025-03-17T18:39:15Z")

</div>

Hello there. Passing from Elastic On-Prem to Elastic Cloud, I am trying to use Logstash to create a "store and forward" implementation for creating documents in elastic. So, practically, before I was directly writing to…

---

## [Logstash duplicate](https://discuss.elastic.co/t/logstash-duplicate/375381)

<div class="topic-metadata">

**Author:** [@AVMOps](https://discuss.elastic.co/u/AVMOps)\
**Replies:** 12\
**Last updated:** [March 17, 2025, 12:30pm UTC](https://discuss.elastic.co/t/logstash-duplicate/375381 "2025-03-17T12:30:48Z")

</div>

Hello, I'm facing a duplicate data issue with Elasticsearch (3 nodes v8.5.2 - green state), coupled with Logstash (1 node v 8.5.2). So basically we have multiple apps servers sending logs with NLog to Logstash on port …

---

## [Calling a function / store procedure from jdbc input pluging](https://discuss.elastic.co/t/calling-a-function-store-procedure-from-jdbc-input-pluging/375562)

<div class="topic-metadata">

**Author:** [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Replies:** 2\
**Last updated:** [March 16, 2025, 6:55pm UTC](https://discuss.elastic.co/t/calling-a-function-store-procedure-from-jdbc-input-pluging/375562 "2025-03-16T18:55:38Z")

</div>

Hello, I'm trying to invoke a function from the jdbc input plugin. I've read this But I get the following error \[2025-03-07T14:43:00,004\]\[WARN \]\[logstash.inputs.jdbc \]\[main\]\[335bb609b009b4900e39c184c3e0c418f819…

---

## [Parse either json or non json logs in logstash](https://discuss.elastic.co/t/parse-either-json-or-non-json-logs-in-logstash/375771)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 2\
**Last updated:** [March 16, 2025, 8:36am UTC](https://discuss.elastic.co/t/parse-either-json-or-non-json-logs-in-logstash/375771 "2025-03-16T08:36:49Z")

</div>

here is my log messages with two farmats in response section : this one non json in response 2025-03-12 10:52:19,645 INFO REQUEST:/auth/authorize?response\_type=code RESPONSE:APPROVED amount:1000 this one json in rep…

---

## [Logstash memory queue events lost](https://discuss.elastic.co/t/logstash-memory-queue-events-lost/375962)

<div class="topic-metadata">

**Author:** [@Mahdi\_Moazami](https://discuss.elastic.co/u/Mahdi_Moazami)\
**Replies:** 1\
**Last updated:** [March 15, 2025, 12:49pm UTC](https://discuss.elastic.co/t/logstash-memory-queue-events-lost/375962 "2025-03-15T12:49:05Z")

</div>

Hi there, we are using logstash as data pipeline to transfer data from a SQL Server database to Elasticsearch. the pipelines are configured as memory queued and sometimes after the data transfer completes, it's incomple…

---

## [Logstash ERROR: (NameError) cannot initialize Java class org.logstash.plugins.AliasRegistry (java.lang.ExceptionInInitializerError)](https://discuss.elastic.co/t/logstash-error-nameerror-cannot-initialize-java-class-org-logstash-plugins-aliasregistry-java-lang-exceptionininitializererror/375965)

<div class="topic-metadata">

**Author:** [@horemheb](https://discuss.elastic.co/u/horemheb)\
**Replies:** 0\
**Last updated:** [March 15, 2025, 9:13am UTC](https://discuss.elastic.co/t/logstash-error-nameerror-cannot-initialize-java-class-org-logstash-plugins-aliasregistry-java-lang-exceptionininitializererror/375965 "2025-03-15T09:13:25Z")

</div>

Logstash ERROR: (NameError) cannot initialize Java class org.logstash.plugins.AliasRegistry (java.lang.ExceptionInInitializerError) For this exception on windows machines I'd changed jvm.options file for parameters #-Du…

---

## [\[2025-03-14T09:00:37,853\]\[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (SystemExit) exit org.jruby.exceptions.SystemExit: (SystemExit) exit at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:747) ~\[jruby-c](https://discuss.elastic.co/t/2025-03-14t0937-853-fatal-org-logstash-logstash-logstash-stopped-processing-because-of-an-error-systemexit-exit-org-jruby-exceptions-systemexit-systemexit-exit-at-org-jruby-rubykernel-exit-org-jruby-rubykernel-java-747-jruby-c/375949)

<div class="topic-metadata">

**Author:** [@praveen.jain](https://discuss.elastic.co/u/praveen.jain)\
**Replies:** 0\
**Last updated:** [March 14, 2025, 5:41pm UTC](https://discuss.elastic.co/t/2025-03-14t0937-853-fatal-org-logstash-logstash-logstash-stopped-processing-because-of-an-error-systemexit-exit-org-jruby-exceptions-systemexit-systemexit-exit-at-org-jruby-rubykernel-exit-org-jruby-rubykernel-java-747-jruby-c/375949 "2025-03-14T17:41:06Z")

</div>

I am getting this below error in my environment where I am using logstash to collect and transfer logs to syslog server and also storing it locally. \[2025-03-14T09:00:37,853\]\[FATAL\]\[org.logstash.Logstash \] Logstash s…

---

## [Forwarding the http input data to http output data](https://discuss.elastic.co/t/forwarding-the-http-input-data-to-http-output-data/375567)

<div class="topic-metadata">

**Author:** [@Francesco\_Esposito](https://discuss.elastic.co/u/Francesco_Esposito)\
**Replies:** 32\
**Last updated:** [March 14, 2025, 3:24pm UTC](https://discuss.elastic.co/t/forwarding-the-http-input-data-to-http-output-data/375567 "2025-03-14T15:24:47Z")

</div>

Hello there. Passing from Elastic On-Prem to Elastic Cloud, I am trying to use Logstash to create a "store and forward" implementation for creating documents in elastic. So, practically, before I was directly writing to…

---

## [Grok pattern](https://discuss.elastic.co/t/grok-pattern/375613)

<div class="topic-metadata">

**Author:** [@arcsons](https://discuss.elastic.co/u/arcsons)\
**Replies:** 9\
**Last updated:** [March 14, 2025, 8:17am UTC](https://discuss.elastic.co/t/grok-pattern/375613 "2025-03-14T08:17:46Z")

</div>

Hello everyone, I have an error in my logs. I have created a grok pattern and added it to the agent policy, but it still doesn't work. I have tested the grok pattern with just a few fields \<%{NUMBER:syslog\_pri}\>%…

---

## [Logstash file input for log rotation files](https://discuss.elastic.co/t/logstash-file-input-for-log-rotation-files/375815)

<div class="topic-metadata">

**Author:** [@devops\_training](https://discuss.elastic.co/u/devops_training)\
**Replies:** 0\
**Last updated:** [March 13, 2025, 9:23am UTC](https://discuss.elastic.co/t/logstash-file-input-for-log-rotation-files/375815 "2025-03-13T09:23:54Z")

</div>

\[2025-03-12T23:41:09,844\]\[INFO \]\[logstash.outputs.elsticsearch\]\[main\]\[fb620d57153c1bad1d3ce0fa625d11e35cc5c8b4b14994fd6f9c6cba50debda9\] Retrying failed action {:status=\>429, :action=\>\["index", {:\_id=\>nil, :\_index=\>"examp…

---

## [Parsing Json fields Cisco ESA Iron Port](https://discuss.elastic.co/t/parsing-json-fields-cisco-esa-iron-port/375714)

<div class="topic-metadata">

**Author:** [@odo24](https://discuss.elastic.co/u/odo24)\
**Replies:** 6\
**Last updated:** [March 13, 2025, 8:38am UTC](https://discuss.elastic.co/t/parsing-json-fields-cisco-esa-iron-port/375714 "2025-03-13T08:38:53Z")

</div>

I use this Logstash filter below to parse Cisco ESA logs filter { if "cef" in \[tags\] { mutate { # CEF:0 is pipe delimited, split into individual fields split =\> \["cef\_message", "|"\] add\_…

---

## [Logstash file output can't fetch data from filebeat as input, input source is journald logs](https://discuss.elastic.co/t/logstash-file-output-cant-fetch-data-from-filebeat-as-input-input-source-is-journald-logs/375751)

<div class="topic-metadata">

**Author:** [@huanghaiqing1](https://discuss.elastic.co/u/huanghaiqing1)\
**Replies:** 0\
**Last updated:** [March 12, 2025, 12:59am UTC](https://discuss.elastic.co/t/logstash-file-output-cant-fetch-data-from-filebeat-as-input-input-source-is-journald-logs/375751 "2025-03-12T00:59:56Z")

</div>

Here, here we choose filebeat as input in logstash, because the source is "journald" binary logs. And choose file as output in logstash. Logstash service and configure seem ok. Filebeat input port is working also. But j…

---

## [Ingest Azure Siginin logs array of json object using http\_poller](https://discuss.elastic.co/t/ingest-azure-siginin-logs-array-of-json-object-using-http-poller/375720)

<div class="topic-metadata">

**Author:** [@O\_O\_O](https://discuss.elastic.co/u/O_O_O)\
**Replies:** 10\
**Last updated:** [March 11, 2025, 8:30pm UTC](https://discuss.elastic.co/t/ingest-azure-siginin-logs-array-of-json-object-using-http-poller/375720 "2025-03-11T20:30:48Z")

</div>

I am trying to use the logstash http\_poller input plugin to ingest Azure Signin Logs (without an eventhub), then pass each document to logs-azure.signinlogs-1.22.0 ingest pipeline for proper parsing. My current logstash…

---

## [Experiencing Error trying to Launch Logstash](https://discuss.elastic.co/t/experiencing-error-trying-to-launch-logstash/375227)

<div class="topic-metadata">

**Author:** [@abbyode](https://discuss.elastic.co/u/abbyode)\
**Replies:** 26\
**Last updated:** [March 11, 2025, 7:20pm UTC](https://discuss.elastic.co/t/experiencing-error-trying-to-launch-logstash/375227 "2025-03-11T19:20:18Z")

</div>

I am experiencing some errors trying to launch logstash. I am using logstash plug-in to send json data to Sentinel Log Analytics Workspace. Below is the error i'm getting. \[ERROR\] 2025-02-28 15:45:10.466 \[Agent thread\] …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=8)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=10)
