# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=93

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 94

---

## [Error while connecting logstash to elasticsearch : Attempted to resurrect connection to dead ES instance, but got an error](https://discuss.elastic.co/t/error-while-connecting-logstash-to-elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/324106)

<div class="topic-metadata">

**Author:** [@abhay14](https://discuss.elastic.co/u/abhay14)\
**Replies:** 8\
**Last updated:** [January 30, 2023, 7:33am UTC](https://discuss.elastic.co/t/error-while-connecting-logstash-to-elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/324106 "2023-01-30T07:33:40Z")

</div>

logstash | \[2023-01-27T11:56:05,943\]\[INFO \]\[logstash.javapipeline \]\[.monitoring-logstash\] Pipeline started {"pipeline.id"=\>".monitoring-logstash"} logstash | \[2023-01-27T11:56:05,956\]\[…

---

## [Monitor SAP on azure](https://discuss.elastic.co/t/monitor-sap-on-azure/324072)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 5:12am UTC](https://discuss.elastic.co/t/monitor-sap-on-azure/324072 "2023-01-30T05:12:37Z")

</div>

It is posible to monitor SAP on azure with beats or extract metrics with logstash? Thanks!

---

## [Logstash & JSON array split](https://discuss.elastic.co/t/logstash-json-array-split/324180)

<div class="topic-metadata">

**Author:** [@Jalpesh1689](https://discuss.elastic.co/u/Jalpesh1689)\
**Replies:** 1\
**Last updated:** [January 29, 2023, 6:16pm UTC](https://discuss.elastic.co/t/logstash-json-array-split/324180 "2023-01-29T18:16:56Z")

</div>

Hi Team, We have below array of JSON & want to ingest these JSON into Elasticsearch. We want split this & ingest into 2 rows : \[{ "RequestEventList":\[ { "Instant":"2015-09-28T12:46:50.713Z", "RequestKey":"11bcf87b…

---

## [Replace one value with another logstash](https://discuss.elastic.co/t/replace-one-value-with-another-logstash/324130)

<div class="topic-metadata">

**Author:** [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 8:44pm UTC](https://discuss.elastic.co/t/replace-one-value-with-another-logstash/324130 "2023-01-27T20:44:05Z")

</div>

Hi, I was trying to convert the value of one field with another, for example: I currently have a field called "priority" and the value of that field is = 1, priority=1. What I want to do is change that value 1 to critic…

---

## [Mutate a specific JSON field but not another](https://discuss.elastic.co/t/mutate-a-specific-json-field-but-not-another/324079)

<div class="topic-metadata">

**Author:** [@hexoffender](https://discuss.elastic.co/u/hexoffender)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 8:18pm UTC](https://discuss.elastic.co/t/mutate-a-specific-json-field-but-not-another/324079 "2023-01-27T20:18:40Z")

</div>

Hello, I have data that looks like this. { "remote\_addr": "127.0.0.1", "time\_local": "26/Jan/2023:17:07:18 -0800", "request": "POST /abcd HTTP/1.1", "request\_method": "POST", "status": "200", "us…

---

## [How to detect incorrect OID in SNMP input plugin?](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 4:56pm UTC](https://discuss.elastic.co/t/how-to-detect-incorrect-oid-in-snmp-input-plugin/324062 "2023-01-27T16:56:28Z")

</div>

When using the SNMP input plugin, I am trying to detect when an OID does not work on the given host. For instance, when using snmpget in the command line with an OID that does not correspond to the given host, it would r…

---

## [Work with multiples inputs/outputs in microsoft-logstash-output-azure-loganalytics plugin](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068)

<div class="topic-metadata">

**Author:** [@Rafael\_Oliveira](https://discuss.elastic.co/u/Rafael_Oliveira)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 4:08pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068 "2023-01-27T16:08:19Z")

</div>

I'm working with microsoft-logstash-output-azure-loganalytics plugin and have to receive different inputs and send to different output based on tags or port. Is is possible? Let's my config file: input { tcp { …

---

## [Logstash starting error with JSON codec plugin](https://discuss.elastic.co/t/logstash-starting-error-with-json-codec-plugin/324100)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 1:43pm UTC](https://discuss.elastic.co/t/logstash-starting-error-with-json-codec-plugin/324100 "2023-01-27T13:43:49Z")

</div>

Hi, I'm trying to send some logs with rsyslog in JSON format to my logstash v8.6 server, but it seems that there is a problem with my JSON codec. Here is the error log : \[2023-01-27T11:31:47,917\]\[INFO \]\[logstash.runne…

---

## [Logstash 8.5.2 how to parse special character in a string value](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107)

<div class="topic-metadata">

**Author:** [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 1:14pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107 "2023-01-27T13:14:10Z")

</div>

Parsing a value of string field http://127.0.0.1:27336/notify logstash maps in Elastic search index many values for the original string. In this case values are http, 127.0.0.1, 27336 and notify. When it encounters t…

---

## [Logstash Value too large to output](https://discuss.elastic.co/t/logstash-value-too-large-to-output/323495)

<div class="topic-metadata">

**Author:** [@Doremanilka](https://discuss.elastic.co/u/Doremanilka)\
**Replies:** 10\
**Last updated:** [January 27, 2023, 11:43am UTC](https://discuss.elastic.co/t/logstash-value-too-large-to-output/323495 "2023-01-27T11:43:09Z")

</div>

Hello, I have new core app that I need to parse. This app has strange big message output field and I need somehow add it to ELK. Log pattern: grok { match =\> \[ "message", "%{DATA:\[event\]\[ti…

---

## [FilestreamWhen updating log files, updated logs and old logs display in graylog](https://discuss.elastic.co/t/filestreamwhen-updating-log-files-updated-logs-and-old-logs-display-in-graylog/324089)

<div class="topic-metadata">

**Author:** [@leesy9610](https://discuss.elastic.co/u/leesy9610)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 7:31am UTC](https://discuss.elastic.co/t/filestreamwhen-updating-log-files-updated-logs-and-old-logs-display-in-graylog/324089 "2023-01-27T07:31:00Z")

</div>

Hi, I used graylog, logtash, filebeat When updating log files, updated logs and old logs display in graylog. I only want the updated log to come out. help me please...

---

## [Can't install logstash-output-influxdb plugin](https://discuss.elastic.co/t/cant-install-logstash-output-influxdb-plugin/323890)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 19\
**Last updated:** [January 27, 2023, 6:23am UTC](https://discuss.elastic.co/t/cant-install-logstash-output-influxdb-plugin/323890 "2023-01-27T06:23:37Z")

</div>

Hi, I'm using Logstash (8.6.0) and want to send data to influxdb2 (2.6.1). But I find that logstash-output-infludb isn't installed by default, so I'm trying to install it. Some errors happen but no details are shown. C…

---

## [Docker logstash 8.6.0 + logstash-input-cloudwatch\_logs does not build](https://discuss.elastic.co/t/docker-logstash-8-6-0-logstash-input-cloudwatch-logs-does-not-build/324077)

<div class="topic-metadata">

**Author:** [@francisco\_eguiguren](https://discuss.elastic.co/u/francisco_eguiguren)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 12:18am UTC](https://discuss.elastic.co/t/docker-logstash-8-6-0-logstash-input-cloudwatch-logs-does-not-build/324077 "2023-01-27T00:18:44Z")

</div>

Hi Folks, I'm trying to build a Docker image that includes logstash-input-cloudwatch\_logs plugin as I need to insert logs from Cloudwatch into my pipeline. I've tried multiple combinations of commands and JAVA\_OPTS, on…

---

## [Logstash plugins still displaying ECS v8 warnings](https://discuss.elastic.co/t/logstash-plugins-still-displaying-ecs-v8-warnings/324030)

<div class="topic-metadata">

**Author:** [@Oddly](https://discuss.elastic.co/u/Oddly)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 10:18pm UTC](https://discuss.elastic.co/t/logstash-plugins-still-displaying-ecs-v8-warnings/324030 "2023-01-26T22:18:20Z")

</div>

I noticed that several plugins (grok and outputs.elasticsearchmonitoring to name a few) are still displaying warning messages like the following: \[WARN\]\[logstash.filters.grok\]\[\<pipeline\_redacted\] ECS v8 support is a pre…

---

## [Failed to perform request](https://discuss.elastic.co/t/failed-to-perform-request/324071)

<div class="topic-metadata">

**Author:** [@test\_qweqwe](https://discuss.elastic.co/u/test_qweqwe)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 10:15pm UTC](https://discuss.elastic.co/t/failed-to-perform-request/324071 "2023-01-26T22:15:18Z")

</div>

\[2023-01-26T19:51:43,271\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\] Failed to perform request {:message=\>"192.168.0.108:9200 failed to respond", :exception=\>Manticore::ClientProtocolException, :cause=\>#\<Java::OrgApach…

---

## [Two types under one filter](https://discuss.elastic.co/t/two-types-under-one-filter/323978)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 9:54pm UTC](https://discuss.elastic.co/t/two-types-under-one-filter/323978 "2023-01-26T21:54:30Z")

</div>

Can I have two types (plain txt log & json )under one filter in the logstash.yml file? input { beats { port =\> "5044" } } filter { if \[fields=='access'\] { grok { remove\_field =\> "message" } …

---

## [Logstash configuration to IBM MQ using TLS and Cipher](https://discuss.elastic.co/t/logstash-configuration-to-ibm-mq-using-tls-and-cipher/323995)

<div class="topic-metadata">

**Author:** [@JHE](https://discuss.elastic.co/u/JHE)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 7:43am UTC](https://discuss.elastic.co/t/logstash-configuration-to-ibm-mq-using-tls-and-cipher/323995 "2023-01-26T07:43:45Z")

</div>

Hi, I'm trying to connect logstash to IBM MQ using jms input. It's OK for an non secured connection. However I didn't find any example to configure a TLS connection and to specify a cipher suites. Here bellow my confi…

---

## [Is the logstash-plugins artifacts link correct?](https://discuss.elastic.co/t/is-the-logstash-plugins-artifacts-link-correct/323999)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 8:16am UTC](https://discuss.elastic.co/t/is-the-logstash-plugins-artifacts-link-correct/323999 "2023-01-26T08:16:13Z")

</div>

Looking if package named: logstash-output-influxdb exists at https://artifacts.elastic.co/downloads/logstash-plugins/logstash-output-influxdb/logstash-output-influxdb-7.6.2.zip Net::OpenTimeout: execution expired …

---

## [Support of IAM for Elasticsearch Input plugin](https://discuss.elastic.co/t/support-of-iam-for-elasticsearch-input-plugin/323982)

<div class="topic-metadata">

**Author:** [@vijayalakshmi\_chanum](https://discuss.elastic.co/u/vijayalakshmi_chanum)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:49am UTC](https://discuss.elastic.co/t/support-of-iam-for-elasticsearch-input-plugin/323982 "2023-01-26T07:49:04Z")

</div>

Do we have support for passing IAM credentials for logstash using Elasticsearch input plugin?

---

## [Is logstash-output-influxdb plugin InfluxDB V2 support?](https://discuss.elastic.co/t/is-logstash-output-influxdb-plugin-influxdb-v2-support/323985)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 2:22am UTC](https://discuss.elastic.co/t/is-logstash-output-influxdb-plugin-influxdb-v2-support/323985 "2023-01-26T02:22:00Z")

</div>

Hi guys I notice that it seems no available output plugin for InfluxDB V2. Is logstash-output-influxdb plugin really being maintained? If the plugin isn't maintained actively, who can I contact to request to update th…

---

## [Elastic Agent elastic-agent-pipeline.conf](https://discuss.elastic.co/t/elastic-agent-elastic-agent-pipeline-conf/323969)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 8:27pm UTC](https://discuss.elastic.co/t/elastic-agent-elastic-agent-pipeline-conf/323969 "2023-01-25T20:27:29Z")

</div>

Where is this file located? I'm testing an integration, created an Agent Policy and then enrolled the Elastic-Agent through Fleet. I need to setup Logstash to accept logs from the Elastic Agent but I need to edit step …

---

## [Issue with running Logstash in docker](https://discuss.elastic.co/t/issue-with-running-logstash-in-docker/323931)

<div class="topic-metadata">

**Author:** [@SimonIv](https://discuss.elastic.co/u/SimonIv)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:34pm UTC](https://discuss.elastic.co/t/issue-with-running-logstash-in-docker/323931 "2023-01-25T14:34:07Z")

</div>

I'm trying to run Logstash in docker with Elasticsearch as output, however there are some warnings and errors like: elasticsearch:9200 failed to respond Unable to retrieve license information from license server {:mess…

---

## [Logstash $HOME/.logstash\_jdbc\_last\_run not created](https://discuss.elastic.co/t/logstash-home-logstash-jdbc-last-run-not-created/323936)

<div class="topic-metadata">

**Author:** [@duffel](https://discuss.elastic.co/u/duffel)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 2:56pm UTC](https://discuss.elastic.co/t/logstash-home-logstash-jdbc-last-run-not-created/323936 "2023-01-25T14:56:03Z")

</div>

I am using logstash 7.14 and the jdbc plugin with the following settings jdbc { type =\> "jdbc-audit" id =\> "dev-jdbc-audit" jdbc\_driver\_library =\> "/opt/appl/lib/postgresql-42.5.1.jar" jdbc\_driver\_clas…

---

## [Filebeat regex in windows path](https://discuss.elastic.co/t/filebeat-regex-in-windows-path/323927)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 1\
**Last updated:** [January 25, 2023, 2:06pm UTC](https://discuss.elastic.co/t/filebeat-regex-in-windows-path/323927 "2023-01-25T14:06:48Z")

</div>

Hi, I'm trying to collect logs from a windows path with filebeat with filestream as input like so: --- # vim:ft=yaml - type: filestream paths: - 'C:\\Users\\\*\\some\\other\\folders\\\*.json' fields\_under\_root: true …

---

## [How to set a value in timestamp](https://discuss.elastic.co/t/how-to-set-a-value-in-timestamp/323762)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 6\
**Last updated:** [January 24, 2023, 5:22pm UTC](https://discuss.elastic.co/t/how-to-set-a-value-in-timestamp/323762 "2023-01-24T17:22:13Z")

</div>

I have two values as my date and hour data and i want them to be my timestamp: "F-MESSAGE-CAB": "20221018","H-MESSAGE-CAB": "601006" "F-MESSAGE-CAB": "20221018","H-MESSAGE-CAB": "1338311" What i'm trying to do is putt…

---

## [Logstash log](https://discuss.elastic.co/t/logstash-log/323775)

<div class="topic-metadata">

**Author:** [@kadamik](https://discuss.elastic.co/u/kadamik)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 5:02pm UTC](https://discuss.elastic.co/t/logstash-log/323775 "2023-01-24T17:02:35Z")

</div>

I have having trouble getting logstash and elasticsearch setup. I have my rsyslog server sending my logs from my Unifi UDM device. I have it setup for the most-part but the problem is how logstash is trasforming the l…

---

## [How to create file that contain tracking\_column date](https://discuss.elastic.co/t/how-to-create-file-that-contain-tracking-column-date/323846)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 3:01pm UTC](https://discuss.elastic.co/t/how-to-create-file-that-contain-tracking-column-date/323846 "2023-01-24T15:01:42Z")

</div>

Hi, please your help, I have a pipeline with input JDBC so I work with tracking\_colum, I have a file .sql\_last\_value\_date with this format: --- !ruby/object:DateTime '2022-07-01 05:00:00.000000000 Z' this the date that …

---

## [Logstash, query not executing inside of the elasticsearch input plugin](https://discuss.elastic.co/t/logstash-query-not-executing-inside-of-the-elasticsearch-input-plugin/323655)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 1:41pm UTC](https://discuss.elastic.co/t/logstash-query-not-executing-inside-of-the-elasticsearch-input-plugin/323655 "2023-01-24T13:41:08Z")

</div>

Hi, I have a logstash pipeline where I'm reading data in from Kafka and then inside of the filter plugin I have a conditional to call the elasticsearch input plugin if a certain condition is met. The condition: If ser…

---

## [\[Logstash OSS\] Invalid UTF-8 start byte issue](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772)

<div class="topic-metadata">

**Author:** [@dstepanov25](https://discuss.elastic.co/u/dstepanov25)\
**Replies:** 7\
**Last updated:** [January 24, 2023, 11:32am UTC](https://discuss.elastic.co/t/logstash-oss-invalid-utf-8-start-byte-issue/323772 "2023-01-24T11:32:03Z")

</div>

Describe the bug It's not possible to save item with non-ASCII characters into OpenSearch To Reproduce Steps to reproduce the behavior: Run OpenSearch in a Docker container: docker run -d -p 9200:9200 -p 9600:9600…

---

## [Not able to parse logs while parsing mix json objects](https://discuss.elastic.co/t/not-able-to-parse-logs-while-parsing-mix-json-objects/323494)

<div class="topic-metadata">

**Author:** [@abhishek1111](https://discuss.elastic.co/u/abhishek1111)\
**Replies:** 8\
**Last updated:** [January 24, 2023, 8:17am UTC](https://discuss.elastic.co/t/not-able-to-parse-logs-while-parsing-mix-json-objects/323494 "2023-01-24T08:17:08Z")

</div>

Could someone please help me with parsing below mix json logs tried multiple ways of parsing it, but nothing has helped. Logs {"log":"\[GIN\] 2023/01/19 - 08:14:32 | 200 | 5.595393ms | 10.164.30.231 | POST "/api…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=92)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=94)
