# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=95

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 96

---

## [Logstash conf script language](https://discuss.elastic.co/t/logstash-conf-script-language/323305)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 9:30am UTC](https://discuss.elastic.co/t/logstash-conf-script-language/323305 "2023-01-17T09:30:56Z")

</div>

Hi all, I have installed logstash 8.4.0. with my ES. I have created logstash .conf file to create data pipelines. I use below .conf format input { ... } filter{ .... } output{ ... } I just want to know is above sc…

---

## [Logstash Mutate Convert Not Working](https://discuss.elastic.co/t/logstash-mutate-convert-not-working/323289)

<div class="topic-metadata">

**Author:** [@Johanes\_Mistrialdo](https://discuss.elastic.co/u/Johanes_Mistrialdo)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 6:18am UTC](https://discuss.elastic.co/t/logstash-mutate-convert-not-working/323289 "2023-01-17T06:18:41Z")

</div>

Hi All, I've created logstash ruby filter like this (ignore my val.each loop, I'm tring to convert all field to string): However, I still cannot convert my field to string (the field is showed as date field): My …

---

## [Logstash with stomp plugin](https://discuss.elastic.co/t/logstash-with-stomp-plugin/323279)

<div class="topic-metadata">

**Author:** [@bulaklak](https://discuss.elastic.co/u/bulaklak)\
**Replies:** 5\
**Last updated:** [January 16, 2023, 11:34pm UTC](https://discuss.elastic.co/t/logstash-with-stomp-plugin/323279 "2023-01-16T23:34:51Z")

</div>

Hi all, I'm looking into connecting Logstash with ActiveMQ. However, the stomp plugin I need isn't included with default Logstash. I have tried to install the logstash-input-stomp plugin, but it isn't working. Any direc…

---

## [Import CSV file into nested fields](https://discuss.elastic.co/t/import-csv-file-into-nested-fields/323278)

<div class="topic-metadata">

**Author:** [@markedperf](https://discuss.elastic.co/u/markedperf)\
**Replies:** 4\
**Last updated:** [January 16, 2023, 10:00pm UTC](https://discuss.elastic.co/t/import-csv-file-into-nested-fields/323278 "2023-01-16T22:00:41Z")

</div>

I'm trying to import a CSV file into nested fields. Trying to follow the aggregate example #4, is coming up short for me. This partially works, but not really what I'm looking for. I'd just like the values grouped in …

---

## [Logstash doesn't work in Windows correctly Please help!](https://discuss.elastic.co/t/logstash-doesnt-work-in-windows-correctly-please-help/323161)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 4:07pm UTC](https://discuss.elastic.co/t/logstash-doesnt-work-in-windows-correctly-please-help/323161 "2023-01-16T16:07:14Z")

</div>

Hi, I try to run logstash in windows with the command: .\\bin\\logstash.bat -f D:\\Elastic\\logstash-8.6.0\\config\\conf.d\\bo\_firmas\_electronicas.conf But I have this message: \[2023-01-13T16:01:57,544\]\[ERROR\]\[logstash.agent…

---

## [Logstash horizontal autoscaling](https://discuss.elastic.co/t/logstash-horizontal-autoscaling/323256)

<div class="topic-metadata">

**Author:** [@yuvalweber](https://discuss.elastic.co/u/yuvalweber)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 2:10pm UTC](https://discuss.elastic.co/t/logstash-horizontal-autoscaling/323256 "2023-01-16T14:10:50Z")

</div>

I want to create autoscaling for our logstash based on prometheus queries we have from the api of logstash. I am using Persistent Queue has a way for backing up our messages in case of disaster and I thought that based …

---

## [Winlogbeat to Logstash over SSL](https://discuss.elastic.co/t/winlogbeat-to-logstash-over-ssl/322705)

<div class="topic-metadata">

**Author:** [@Mark\_Marais](https://discuss.elastic.co/u/Mark_Marais)\
**Replies:** 11\
**Last updated:** [January 16, 2023, 1:56pm UTC](https://discuss.elastic.co/t/winlogbeat-to-logstash-over-ssl/322705 "2023-01-16T13:56:11Z")

</div>

Good day, Can someone assist me with a secure connection from my beats to my logstash instances. Thanks.

---

## [Help me with logstash config (Feature Request)](https://discuss.elastic.co/t/help-me-with-logstash-config-feature-request/322992)

<div class="topic-metadata">

**Author:** [@Md\_Shariful\_Islam](https://discuss.elastic.co/u/Md_Shariful_Islam)\
**Replies:** 4\
**Last updated:** [January 15, 2023, 5:30am UTC](https://discuss.elastic.co/t/help-me-with-logstash-config-feature-request/322992 "2023-01-15T05:30:36Z")

</div>

I am using logstash aggregate filter and I want timeout value for infinite time. How to do that? Current config for aggregate filter given below if \[src\_ip\] { aggregate { task\_id =\> "%{src\_ip}" …

---

## [Logstash Elasticsearch filter Bad URI Exception](https://discuss.elastic.co/t/logstash-elasticsearch-filter-bad-uri-exception/323176)

<div class="topic-metadata">

**Author:** [@eraste](https://discuss.elastic.co/u/eraste)\
**Replies:** 9\
**Last updated:** [January 14, 2023, 7:02pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-bad-uri-exception/323176 "2023-01-14T19:02:12Z")

</div>

Hello Everyone. I have an exception in Logstash with Elasticsearch filter in the hosts parameter. When i give manually the hosts parameter like this, all thing is good, i don't get error : filter { elasticsearch {…

---

## [Print logs into a file before parsing with GROK](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145)

<div class="topic-metadata">

**Author:** [@danishbit09](https://discuss.elastic.co/u/danishbit09)\
**Replies:** 3\
**Last updated:** [January 14, 2023, 5:52pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145 "2023-01-14T17:52:15Z")

</div>

Is there any option to store logs into a file before parsing it in GROK. Please suggest. Can I use logger.info() in Filter plugin.

---

## [Logstash Plugin](https://discuss.elastic.co/t/logstash-plugin/323120)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 8\
**Last updated:** [January 13, 2023, 5:25pm UTC](https://discuss.elastic.co/t/logstash-plugin/323120 "2023-01-13T17:25:38Z")

</div>

Hello friends, Is this possible to write a Logstash plugin for fetching data in Javascript just as we can do with Java ?

---

## [Related to Logstash](https://discuss.elastic.co/t/related-to-logstash/323137)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 1:51pm UTC](https://discuss.elastic.co/t/related-to-logstash/323137 "2023-01-13T13:51:19Z")

</div>

Hello friends I want to fetch some metrics data from the Vrops(VMware) api that includes following steps - Make a post request with login credentials to get the authentication token Use that authentication token with …

---

## [Filebeat-\>Kafka-\>Logstash-\>Elasticsearch fails for system.auth: "Provided Grok expressions do not match field value"](https://discuss.elastic.co/t/filebeat-kafka-logstash-elasticsearch-fails-for-system-auth-provided-grok-expressions-do-not-match-field-value/323068)

<div class="topic-metadata">

**Author:** [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Replies:** 11\
**Last updated:** [January 13, 2023, 11:46am UTC](https://discuss.elastic.co/t/filebeat-kafka-logstash-elasticsearch-fails-for-system-auth-provided-grok-expressions-do-not-match-field-value/323068 "2023-01-13T11:46:31Z")

</div>

The ingest scenario below perplexingly fails for the Filebeat system module with the auth fileset with Provided Grok expressions do not match field value. It doesn't matter what the event is from /var/log/secure; every s…

---

## [Logstash input imap plugin with attachment not decoding](https://discuss.elastic.co/t/logstash-input-imap-plugin-with-attachment-not-decoding/323113)

<div class="topic-metadata">

**Author:** [@anjuls](https://discuss.elastic.co/u/anjuls)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 9:58am UTC](https://discuss.elastic.co/t/logstash-input-imap-plugin-with-attachment-not-decoding/323113 "2023-01-13T09:58:03Z")

</div>

Hi, I am trying to fetch emails with attachments from Office 365 using logstash and putting them on Kafka topic. During the process, I got to understand the logstash-imap-input plugin is unable to process it. When the a…

---

## [Logstash are not running properly](https://discuss.elastic.co/t/logstash-are-not-running-properly/323002)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 7\
**Last updated:** [January 13, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-are-not-running-properly/323002 "2023-01-13T04:26:42Z")

</div>

Hi team, We are trying to get the live logs from DEV Environment for testing.. But after started the Logstash (7.16.1) service, it through a error. Please check the below error. at RUBY.\<module:LibC\>(/usr/shar…

---

## [Which port is my logstash using?](https://discuss.elastic.co/t/which-port-is-my-logstash-using/323021)

<div class="topic-metadata">

**Author:** [@waitangi](https://discuss.elastic.co/u/waitangi)\
**Replies:** 3\
**Last updated:** [January 12, 2023, 1:41pm UTC](https://discuss.elastic.co/t/which-port-is-my-logstash-using/323021 "2023-01-12T13:41:15Z")

</div>

Hello all I have a running server where logstash is working. In my pipelines.yml there's a line path.config: "/etc/logstash/conf.d/\*.conf" - this points to a directory where my configuration is. The directory contains …

---

## [Fixing late logs into elastic](https://discuss.elastic.co/t/fixing-late-logs-into-elastic/322888)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [January 12, 2023, 10:54am UTC](https://discuss.elastic.co/t/fixing-late-logs-into-elastic/322888 "2023-01-12T10:54:18Z")

</div>

Hello there, i would like to ask about my problem here. so here is the situation. my elastic, receive log from OCP. the problem is when the log is viewed from elastic, it doesn't appear to have updated. as in the image …

---

## [The Plan to support SNMP Traps version 3 as input plugin?](https://discuss.elastic.co/t/the-plan-to-support-snmp-traps-version-3-as-input-plugin/322907)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 8:50am UTC](https://discuss.elastic.co/t/the-plan-to-support-snmp-traps-version-3-as-input-plugin/322907 "2023-01-12T08:50:00Z")

</div>

Plant to support SNMP Traps version 3 as input plugin? So far V3 not supported if there is plan and info you can everyone to add me, please don't hesitate. thank you

---

## [\_dateparseerror for timestamp in this format: 2023-01-11T05:07:30.648881Z,](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959)

<div class="topic-metadata">

**Author:** [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Replies:** 10\
**Last updated:** [January 11, 2023, 8:54pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959 "2023-01-11T20:54:45Z")

</div>

I am trying to parse a field called create\_ts with a value of 2023-01-11T05:07:30.648881Z and then add fields for year, month and day. I have scoured everything to figure out the correct timestamp pattern and cannot see…

---

## [Logstash Issue](https://discuss.elastic.co/t/logstash-issue/322960)

<div class="topic-metadata">

**Author:** [@amulya](https://discuss.elastic.co/u/amulya)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 6:00pm UTC](https://discuss.elastic.co/t/logstash-issue/322960 "2023-01-11T18:00:53Z")

</div>

Starting Logstash for the first time in linux machine There was an error while loading \`logstash-core-plugin-api.gemspec\`: load error: psych -- java.lang.RuntimeException: BUG: we can not copy embedded jar to temp direc…

---

## [How to configure filebeat if we are getting log files from different Linux servers?](https://discuss.elastic.co/t/how-to-configure-filebeat-if-we-are-getting-log-files-from-different-linux-servers/322954)

<div class="topic-metadata">

**Author:** [@SP003](https://discuss.elastic.co/u/SP003)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 4:03pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-if-we-are-getting-log-files-from-different-linux-servers/322954 "2023-01-11T16:03:57Z")

</div>

Hi Experts, As of now, I am able configure filebeat , logstash and get the index created with logs successfully in Elastic Search in the same server where log files are available, now I want to access log files which is…

---

## [Logstash http output plugin times out](https://discuss.elastic.co/t/logstash-http-output-plugin-times-out/322953)

<div class="topic-metadata">

**Author:** [@sarabande](https://discuss.elastic.co/u/sarabande)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 4:03pm UTC](https://discuss.elastic.co/t/logstash-http-output-plugin-times-out/322953 "2023-01-11T16:03:01Z")

</div>

I'm using logstash http output plugin to send log events to an URL. This is how my output section looks like: output { if \[logger\_name\] != 'xxx' and \[type\] != "xxx" and \[logger\_name\] != 'xxx' { elasticsearch {…

---

## [\[ERROR\]\[logstash.agent\] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"and\\", \\"or\\", \\"xor\\", \\"nand\\",](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599)

<div class="topic-metadata">

**Author:** [@SP003](https://discuss.elastic.co/u/SP003)\
**Replies:** 6\
**Last updated:** [January 11, 2023, 3:50pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599 "2023-01-11T15:50:28Z")

</div>

Hello experts, I am setting up filebeat, logstash for my log monitoring work. (Linux system) Getting below error on filebeat. --\> systemctl status filebeat - getting error --\> systemctl status logstash - Running fine…

---

## [Logstash - Converting input from JDBC to json for an HTTP request](https://discuss.elastic.co/t/logstash-converting-input-from-jdbc-to-json-for-an-http-request/322949)

<div class="topic-metadata">

**Author:** [@L\_C](https://discuss.elastic.co/u/L_C)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 3:32pm UTC](https://discuss.elastic.co/t/logstash-converting-input-from-jdbc-to-json-for-an-http-request/322949 "2023-01-11T15:32:47Z")

</div>

Hello, I am looking for some pointers regarding how to convert input data from a JBDC plugin into json to send the content to an API. Here is the logstash.conf: input { jdbc { jdbc\_driver\_library =\> "/logstash-c…

---

## [Pipeline: copy unique value to a new index](https://discuss.elastic.co/t/pipeline-copy-unique-value-to-a-new-index/322946)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 3:19pm UTC](https://discuss.elastic.co/t/pipeline-copy-unique-value-to-a-new-index/322946 "2023-01-11T15:19:27Z")

</div>

I guys, I need an help! I have an index called s1v6\_new\_cleaninq2 with more then 1 million of documents. Inside each documents I have a field called "num\_pratica" and this field could be repeated for a couple of documen…

---

## [Optional match for a grok pattern](https://discuss.elastic.co/t/optional-match-for-a-grok-pattern/322904)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 3:05pm UTC](https://discuss.elastic.co/t/optional-match-for-a-grok-pattern/322904 "2023-01-11T15:05:46Z")

</div>

Hey community, I would like to build an optional match for the following logline: 2023-01-11 00:00:11 1pEoP9-000LLu-Gz \<= noreply@domain.de H=fqdn.domain.de (FQDN) \[10.1.1.1\] P=esmtpa A=login\_virtual\_exim:mtaspooler@do…

---

## [Change logstash default @timestamp format](https://discuss.elastic.co/t/change-logstash-default-timestamp-format/322857)

<div class="topic-metadata">

**Author:** [@markedperf](https://discuss.elastic.co/u/markedperf)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 1:41pm UTC](https://discuss.elastic.co/t/change-logstash-default-timestamp-format/322857 "2023-01-11T13:41:29Z")

</div>

I am looking to change the default @timestamp format from nano seconds ("@timestamp" : "2023-01-07T17:26:16.969990782Z") to just milliseconds ("@timestamp" : "2023-01-07T17:26:16.969" or "@timestamp" : "2023-01-07T17:26:…

---

## [TCP/UDP VS syslog](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 1:31pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927 "2023-01-11T13:31:40Z")

</div>

What is differences between the below. input { tcp { port =\> 514 type =\> syslog } udp { port =\> 514 type =\> syslog } } VS input { syslog { port =\> 514 } } If I need to receive syslog m…

---

## [Logstash Input plugin for Elasticsearch to query once based on scedule instead of scrolling](https://discuss.elastic.co/t/logstash-input-plugin-for-elasticsearch-to-query-once-based-on-scedule-instead-of-scrolling/322931)

<div class="topic-metadata">

**Author:** [@sahil\_sawhney](https://discuss.elastic.co/u/sahil_sawhney)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/logstash-input-plugin-for-elasticsearch-to-query-once-based-on-scedule-instead-of-scrolling/322931 "2023-01-11T13:21:39Z")

</div>

As visible in the screenshot for 1-minute duration, the data is queried multiple times. I wish to disable this and for a schedule "\* \* \* \* \*" collect data only once in 1 minute. My current config for logstash input pl…

---

## [Logstash Elasticsearch output plugin fails to establish a connection](https://discuss.elastic.co/t/logstash-elasticsearch-output-plugin-fails-to-establish-a-connection/322922)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 12:59pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-plugin-fails-to-establish-a-connection/322922 "2023-01-11T12:59:37Z")

</div>

Hi all, I am facing an error with Logstash which is not able to connect to Elasticsearch. I am getting the following error: \[2023-01-11T12:10:15,365\]\[WARN \]\[logstash.outputs.elasticsearch\]\[continuous\] Attempted to resu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=94)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=96)
