# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=94

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 95

---

## [Logstash Module](https://discuss.elastic.co/t/logstash-module/323715)

<div class="topic-metadata">

**Author:** [@Adedolapo\_Okunsanmi](https://discuss.elastic.co/u/Adedolapo_Okunsanmi)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 7:44am UTC](https://discuss.elastic.co/t/logstash-module/323715 "2023-01-24T07:44:50Z")

</div>

Hi Guys, I use the Cloud-Based Elastic/Kibana. I would like to know if there is a difference between Logstash module in Filebeats and Logstash installed directly on server,

---

## [GCLocker too often allocating 256 words](https://discuss.elastic.co/t/gclocker-too-often-allocating-256-words/323769)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 12:33am UTC](https://discuss.elastic.co/t/gclocker-too-often-allocating-256-words/323769 "2023-01-24T00:33:00Z")

</div>

How I can tune up config due to warning \[1154.233s\]\[warning\]\[gc,alloc\] \[npdb\_dns\]\>worker20: Retried waiting for GCLocker too often allocating 256 words \[1154.233s\]\[warning\]\[gc,alloc\] \[npdb\_network\]\>worker7: Retried wai…

---

## [Illegal reflective access errors](https://discuss.elastic.co/t/illegal-reflective-access-errors/323020)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 6\
**Last updated:** [January 23, 2023, 9:58am UTC](https://discuss.elastic.co/t/illegal-reflective-access-errors/323020 "2023-01-23T09:58:24Z")

</div>

Getting Illegal reflective access errors along with these warnings: WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by org.jruby.ext.openssl.SecurityHelper (file:/{...}…

---

## [ElasticSearch - logstash ( 8.2.0 )](https://discuss.elastic.co/t/elasticsearch-logstash-8-2-0/323710)

<div class="topic-metadata">

**Author:** [@Nalin\_Kumar](https://discuss.elastic.co/u/Nalin_Kumar)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-8-2-0/323710 "2023-01-23T08:56:49Z")

</div>

Hi, all. I'am new to Elasticsearch and finding the best way to store data in elastic-search engine using log stash. Reading tables from input JDBC and output to elastic-search. Currently i have create single index but…

---

## [Help to create new field from message](https://discuss.elastic.co/t/help-to-create-new-field-from-message/323698)

<div class="topic-metadata">

**Author:** [@Sam\_1995](https://discuss.elastic.co/u/Sam_1995)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 8:27am UTC](https://discuss.elastic.co/t/help-to-create-new-field-from-message/323698 "2023-01-23T08:27:50Z")

</div>

Hello, I m looking for a way (maybe with grok), to create new field by extracting some specified pattern but with keeping the field message without modification after operation Example Pattern 2023-01-23 10:33:25 \[ALB…

---

## [Paginantion in logstash](https://discuss.elastic.co/t/paginantion-in-logstash/323385)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 6:34am UTC](https://discuss.elastic.co/t/paginantion-in-logstash/323385 "2023-01-23T06:34:07Z")

</div>

Hello there ! I am fetching data from vRops api using http\_poller. Is there any way to achieve pagination in logstash ?

---

## [Filter data based on dates and days](https://discuss.elastic.co/t/filter-data-based-on-dates-and-days/323681)

<div class="topic-metadata">

**Author:** [@stella\_raj](https://discuss.elastic.co/u/stella_raj)\
**Replies:** 2\
**Last updated:** [January 23, 2023, 3:50am UTC](https://discuss.elastic.co/t/filter-data-based-on-dates-and-days/323681 "2023-01-23T03:50:31Z")

</div>

Hi, Need to filter data based on specific dates and days. Suggest any filter plugin that will fulfil my requirement. Thanks

---

## [Ruby Filter : difference between init option and path option in terms of performance](https://discuss.elastic.co/t/ruby-filter-difference-between-init-option-and-path-option-in-terms-of-performance/323677)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 1:27pm UTC](https://discuss.elastic.co/t/ruby-filter-difference-between-init-option-and-path-option-in-terms-of-performance/323677 "2023-01-22T13:27:07Z")

</div>

Hello All, while I am reading on Ruby filter plugin, I found that the "init" option is used to execute any code at startup time. so, is there any 'performance' difference between path option and init option used like t…

---

## [Replacing @timestamp with logs having custom timestamp](https://discuss.elastic.co/t/replacing-timestamp-with-logs-having-custom-timestamp/323656)

<div class="topic-metadata">

**Author:** [@sahoo35](https://discuss.elastic.co/u/sahoo35)\
**Replies:** 7\
**Last updated:** [January 22, 2023, 10:22am UTC](https://discuss.elastic.co/t/replacing-timestamp-with-logs-having-custom-timestamp/323656 "2023-01-22T10:22:39Z")

</div>

Hello Everyone, I am newbie in ELK stack and i am still learning the logstash, kibana and its further uses . Currently i am stuck at a point where i want to extract the time stamp from my logs and replace it with @times…

---

## [Adding new fields from timestamp nvarchar(max) with grok filter in logstash](https://discuss.elastic.co/t/adding-new-fields-from-timestamp-nvarchar-max-with-grok-filter-in-logstash/323645)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 12\
**Last updated:** [January 22, 2023, 9:57am UTC](https://discuss.elastic.co/t/adding-new-fields-from-timestamp-nvarchar-max-with-grok-filter-in-logstash/323645 "2023-01-22T09:57:40Z")

</div>

hey everyone, i want to create 2 new fields (as month, year) from an existing timestamp field that comes from a json filter (payload) when the timestamp field type is nvarchar(max) I tried going in several directions …

---

## [Logstash unable to write records to existing elasticsearch index](https://discuss.elastic.co/t/logstash-unable-to-write-records-to-existing-elasticsearch-index/323659)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [January 21, 2023, 9:46pm UTC](https://discuss.elastic.co/t/logstash-unable-to-write-records-to-existing-elasticsearch-index/323659 "2023-01-21T21:46:13Z")

</div>

I can successfully get logstash to write records to an elasticsearch index if the index doesn't exist in the first place. But I can't seem to get logstash to write records to an index if it already exists. For example,…

---

## [ELK Active Active Setup with Failure Recovery](https://discuss.elastic.co/t/elk-active-active-setup-with-failure-recovery/323621)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 2\
**Last updated:** [January 21, 2023, 6:34pm UTC](https://discuss.elastic.co/t/elk-active-active-setup-with-failure-recovery/323621 "2023-01-21T18:34:31Z")

</div>

Hello All The use case is that we want to setup Active Active architecture in ELK using two clusters in two different regions. We will index the event to both the local elasticsearch cluster and remote elasticsearch clu…

---

## [Loading large table from Mysql to ES via Logstash](https://discuss.elastic.co/t/loading-large-table-from-mysql-to-es-via-logstash/323442)

<div class="topic-metadata">

**Author:** [@Het\_Desai](https://discuss.elastic.co/u/Het_Desai)\
**Replies:** 7\
**Last updated:** [January 20, 2023, 7:07pm UTC](https://discuss.elastic.co/t/loading-large-table-from-mysql-to-es-via-logstash/323442 "2023-01-20T19:07:53Z")

</div>

Hello, I have multiple large tables (each table contains ~15M records and consumes ~70GB of data). My logstash configuration is as given below. input { jdbc { jdbc\_connection\_string =\> "jdbc:mysql:…

---

## [Différence entre le Grok Debugger et le grok dans le filter](https://discuss.elastic.co/t/difference-entre-le-grok-debugger-et-le-grok-dans-le-filter/323507)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 3\
**Last updated:** [January 20, 2023, 9:30am UTC](https://discuss.elastic.co/t/difference-entre-le-grok-debugger-et-le-grok-dans-le-filter/323507 "2023-01-20T09:30:15Z")

</div>

Bonjour, Je ne trouve pas la bonne manière de faire remplacer ce @timestamp par celui qui se trouve dans mon message. Le principe est simple 1 log = 1 ligne, c'est au format JSON {"startTime":"2023-01-17 14:17:50.238"…

---

## [Data loss without my consent](https://discuss.elastic.co/t/data-loss-without-my-consent/323319)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/data-loss-without-my-consent/323319 "2023-01-20T08:52:41Z")

</div>

Hello, I have a logstash script that takes files as input and sends them to an according elasticsearch index. Said script is run at 1am every night as a scheduled task, which worked in the beginning.But now, every time …

---

## [Custom code for pagination in Logstash](https://discuss.elastic.co/t/custom-code-for-pagination-in-logstash/323474)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 11:00pm UTC](https://discuss.elastic.co/t/custom-code-for-pagination-in-logstash/323474 "2023-01-19T23:00:08Z")

</div>

Hello there ! I am fetching some data using the vRealize api, I want to add pagination using the custom code. which programming language can I use and how can I achieve this ? Can someone please help me with this !

---

## [No config file found - help me pleaseee](https://discuss.elastic.co/t/no-config-file-found-help-me-pleaseee/323521)

<div class="topic-metadata">

**Author:** [@Jonathan\_Or](https://discuss.elastic.co/u/Jonathan_Or)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 2:33pm UTC](https://discuss.elastic.co/t/no-config-file-found-help-me-pleaseee/323521 "2023-01-19T14:33:01Z")

</div>

hey , i have a problem with my logstash thats running on my ubuntu 18.04 machine. when i run journalctl -u logstash it presents one error that says that no config file found in path etc/log..... but when i go to conf…

---

## [How i can rename dynamical fields](https://discuss.elastic.co/t/how-i-can-rename-dynamical-fields/323321)

<div class="topic-metadata">

**Author:** [@Glad](https://discuss.elastic.co/u/Glad)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-i-can-rename-dynamical-fields/323321 "2023-01-19T13:55:46Z")

</div>

Hello, I would like some help with my little problem. I would like to be able to automatically rename fields that I get with my snmp plugin in input. I obtain this result: "host" =\> \[ \[1\] { "iso...hrProcessorLoa…

---

## [Multiple logstash instances listening to the same redis channel](https://discuss.elastic.co/t/multiple-logstash-instances-listening-to-the-same-redis-channel/323506)

<div class="topic-metadata">

**Author:** [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 12:33pm UTC](https://discuss.elastic.co/t/multiple-logstash-instances-listening-to-the-same-redis-channel/323506 "2023-01-19T12:33:21Z")

</div>

We're using redis to pass data between logstash instances. I have 2 logstash instances currently with the same config: input { redis { data\_type =\> "channel" host =\> "${REDIS\_HOST}" key =\> "l…

---

## [Logstash from multiple beats server](https://discuss.elastic.co/t/logstash-from-multiple-beats-server/323491)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 12:08pm UTC](https://discuss.elastic.co/t/logstash-from-multiple-beats-server/323491 "2023-01-19T12:08:45Z")

</div>

hello every one, i am using logstash to receive data from multiple server using winlogbeats over the port 5044 I want to create an index for each server based on the server name can some one provide me with the logsta…

---

## [Logstash JSON parser error](https://discuss.elastic.co/t/logstash-json-parser-error/323356)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 7:01am UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356 "2023-01-19T07:01:29Z")

</div>

Hi, We are getting json parser warning message as below: \[2023-01-08T13:21:12,936\]\[WARN \]\[logstash.filters.json \] Error parsing json {:source=\>"slmPart", :raw=\>"{"action":UPDATE,"information":"Signing CSR for root …

---

## [Multipipeline configuration](https://discuss.elastic.co/t/multipipeline-configuration/323272)

<div class="topic-metadata">

**Author:** [@SaM9](https://discuss.elastic.co/u/SaM9)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 9:55pm UTC](https://discuss.elastic.co/t/multipipeline-configuration/323272 "2023-01-18T21:55:31Z")

</div>

How can I create a pipeline configuration in Logstash for two different logs that I'm receiving from syslog, the syslog auditd log and the web server log, and separate them to get different outputs? I have tried using an…

---

## [Limitations for Managed Logstash pipelines](https://discuss.elastic.co/t/limitations-for-managed-logstash-pipelines/323450)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 7:29pm UTC](https://discuss.elastic.co/t/limitations-for-managed-logstash-pipelines/323450 "2023-01-18T19:29:04Z")

</div>

Hello, I want to start using the managed pipelines in the Kibana GUI. From the documentation it is not really clear what the limitations are. As an example if you want to include a Ruby script I presume this script must…

---

## [Unable to move the reports from Ansible to logstash](https://discuss.elastic.co/t/unable-to-move-the-reports-from-ansible-to-logstash/322977)

<div class="topic-metadata">

**Author:** [@janaka8](https://discuss.elastic.co/u/janaka8)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 6:03pm UTC](https://discuss.elastic.co/t/unable-to-move-the-reports-from-ansible-to-logstash/322977 "2023-01-18T18:03:46Z")

</div>

Team, We have a ansible setup in our environment and even are using a Kibana Dashboard for resporting purpose. We are getting below attached error while pushing the reports from ansible logs to kibana dashboard. { "co…

---

## [Ingestion of data to Elasticsearch using lostash with incremental data](https://discuss.elastic.co/t/ingestion-of-data-to-elasticsearch-using-lostash-with-incremental-data/323416)

<div class="topic-metadata">

**Author:** [@sriteja\_chebrolu](https://discuss.elastic.co/u/sriteja_chebrolu)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 2:02pm UTC](https://discuss.elastic.co/t/ingestion-of-data-to-elasticsearch-using-lostash-with-incremental-data/323416 "2023-01-18T14:02:52Z")

</div>

Hi All, I am ingesting data from SQL to Elastic cloud If i ingest a SQL table twice it is ingesting two times but I want to ingest only the new data Suppose if a table has 10 records at first ingestion after that 2 re…

---

## [Logstash Pipeline terminate after one output plugin error](https://discuss.elastic.co/t/logstash-pipeline-terminate-after-one-output-plugin-error/323386)

<div class="topic-metadata">

**Author:** [@Bert\_Van\_der\_Heyden](https://discuss.elastic.co/u/Bert_Van_der_Heyden)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 7:59am UTC](https://discuss.elastic.co/t/logstash-pipeline-terminate-after-one-output-plugin-error/323386 "2023-01-18T07:59:16Z")

</div>

Context: Logstash 8.6.0 \[2023-01-18T08:07:30,522\]\[ERROR\]\[logstash.javapipeline \]\[test\_pipeline\] Pipeline worker error, the pipeline will be stopped {:pipeline\_id=\>"test\_pipeline", :error=\>"(IOError) An established co…

---

## [Unable to convert date to specified timezone](https://discuss.elastic.co/t/unable-to-convert-date-to-specified-timezone/322398)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 10\
**Last updated:** [January 18, 2023, 6:46am UTC](https://discuss.elastic.co/t/unable-to-convert-date-to-specified-timezone/322398 "2023-01-18T06:46:18Z")

</div>

Hi All, I am trying to convert the date UTC time to different timezone (Asia/Tokyo) in logstash and below is the configuration I have tried, input { stdin { id =\> "logstash-rae" add\_field =\> { "log\_or…

---

## [Got response code '403' contacting Elasticsearch at URL](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 4\
**Last updated:** [January 18, 2023, 2:27am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368 "2023-01-18T02:27:40Z")

</div>

Hello World! I'm trying to follow Configuring Security in Logstash | Logstash Reference \[7.17\] | Elastic, specifically these: Configuring Logstash to use Basic Authentication Granting Users Access to the Logstash Indi…

---

## [GROK pattern issue](https://discuss.elastic.co/t/grok-pattern-issue/323330)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 4\
**Last updated:** [January 17, 2023, 4:00pm UTC](https://discuss.elastic.co/t/grok-pattern-issue/323330 "2023-01-17T16:00:54Z")

</div>

Hello, I am using filebeat to send logs from a DNS server to logstash before being ingested in Elasticsearch. The same pattern is repeated with two spaces and one space due to the variation in logs over updates which is…

---

## [How to send logs to logstash outside the kubernetes cluster](https://discuss.elastic.co/t/how-to-send-logs-to-logstash-outside-the-kubernetes-cluster/323322)

<div class="topic-metadata">

**Author:** [@sulfred](https://discuss.elastic.co/u/sulfred)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 12:38pm UTC](https://discuss.elastic.co/t/how-to-send-logs-to-logstash-outside-the-kubernetes-cluster/323322 "2023-01-17T12:38:50Z")

</div>

Hi all, I followed this page to set up a logstash with k8s. I can send logs to this logstash within the k8s cluster from other pods. But, I cannot send logs to the logstash outside the cluster. Here is my settings: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=93)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=95)
