# Logstash

**URL:** https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=97

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 98

---

## [Winlogbeat unable to communicate with logstash](https://discuss.elastic.co/t/winlogbeat-unable-to-communicate-with-logstash/321862)

<div class="topic-metadata">

**Author:** [@doudou](https://discuss.elastic.co/u/doudou)\
**Replies:** 25\
**Last updated:** [January 5, 2023, 2:32pm UTC](https://discuss.elastic.co/t/winlogbeat-unable-to-communicate-with-logstash/321862 "2023-01-05T14:32:37Z")

</div>

doudou@elkserver101:~$ doudou@elkserver101:~$ sudo /usr/share/logstash/bin/logstash -f /home/doudou/elk/pipeline.conf Using bundled JDK: /usr/share/logstash/jdk WARNING: Could not find logstash.yml which is typically loc…

---

## [Logstash variables in the output plugin for ADX/Log Analytics in Azure](https://discuss.elastic.co/t/logstash-variables-in-the-output-plugin-for-adx-log-analytics-in-azure/322461)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 4\
**Last updated:** [January 5, 2023, 12:04pm UTC](https://discuss.elastic.co/t/logstash-variables-in-the-output-plugin-for-adx-log-analytics-in-azure/322461 "2023-01-05T12:04:26Z")

</div>

Hello All, I have a question. I have a Logstash configuration with an output plugin for Log Analytics/Azure Data explorer in Azure. In my configuration (the output plugin part) instead of using the workspace ID and key…

---

## [Logging to logstash gets timeout from laravel application once the logstash instance(EC2) goes down](https://discuss.elastic.co/t/logging-to-logstash-gets-timeout-from-laravel-application-once-the-logstash-instance-ec2-goes-down/322456)

<div class="topic-metadata">

**Author:** [@yuguerthen](https://discuss.elastic.co/u/yuguerthen)\
**Replies:** 3\
**Last updated:** [January 4, 2023, 6:04pm UTC](https://discuss.elastic.co/t/logging-to-logstash-gets-timeout-from-laravel-application-once-the-logstash-instance-ec2-goes-down/322456 "2023-01-04T18:04:55Z")

</div>

Hello, I have a Laravel application that sends log data to Logstash on an AWS EC2 instance. Recently, the EC2 instance went down, and I noticed that the Laravel application started prompting timeouts when I tried to log …

---

## [Logstash service keep on restarting](https://discuss.elastic.co/t/logstash-service-keep-on-restarting/322370)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 12\
**Last updated:** [January 4, 2023, 3:27pm UTC](https://discuss.elastic.co/t/logstash-service-keep-on-restarting/322370 "2023-01-04T15:27:28Z")

</div>

Hi Team , Logstash service keeps on restarting and this is the message found in logs . Tried doing pqcheck and pqrepair, removed the problematic queue etc.. No issues related to user access , memory, disk Any suggest…

---

## [JSON parse error, original data now in message field {:message=\>"Unexpected character ('\<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')\\n at \[Source: (String)](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-unexpected-character-code-60-expected-a-valid-value-number-string-array-object-true-false-or-null-n-at-source-string/322015)

<div class="topic-metadata">

**Author:** [@shafiwebsphere](https://discuss.elastic.co/u/shafiwebsphere)\
**Replies:** 11\
**Last updated:** [January 4, 2023, 2:26pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-unexpected-character-code-60-expected-a-valid-value-number-string-array-object-true-false-or-null-n-at-source-string/322015 "2023-01-04T14:26:44Z")

</div>

Same code worked in previous version 7 but i have updated to latest version Elasticsearch logstash and kibana 7.17 , the logstash code is not working and getting error, i have been trying this from 15 days , When i have …

---

## [Sending logs from splunk forward to logstash](https://discuss.elastic.co/t/sending-logs-from-splunk-forward-to-logstash/322454)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [January 4, 2023, 11:37am UTC](https://discuss.elastic.co/t/sending-logs-from-splunk-forward-to-logstash/322454 "2023-01-04T11:37:17Z")

</div>

Hi team, we are trying to send data from splunk to logstash and kibana . we are getting data but data is not in proper format. We have tested below codec but now luck. Every time data changing but no original data is c…

---

## [How to prevent duplicate log](https://discuss.elastic.co/t/how-to-prevent-duplicate-log/322279)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [January 4, 2023, 5:53am UTC](https://discuss.elastic.co/t/how-to-prevent-duplicate-log/322279 "2023-01-04T05:53:04Z")

</div>

Hi there, I have found something odd in my elastic cluster. I found the exact same log showing up twice in the message field as you can see. the logs have the same timestamp, same X-Request-ID all the same. but wh…

---

## [Help with logstash conditional filter](https://discuss.elastic.co/t/help-with-logstash-conditional-filter/322402)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 7:49pm UTC](https://discuss.elastic.co/t/help-with-logstash-conditional-filter/322402 "2023-01-03T19:49:48Z")

</div>

Hello, I'm trying to create a filter to drop events that don't have Lateral attack or Vulnerability exploit attack in the message field. but it is giving error, I would like to know what is wrong and what is the correct …

---

## [Logstash pipeline with input+ filter to one output and other without filter to different output](https://discuss.elastic.co/t/logstash-pipeline-with-input-filter-to-one-output-and-other-without-filter-to-different-output/322350)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 6\
**Last updated:** [January 3, 2023, 4:05pm UTC](https://discuss.elastic.co/t/logstash-pipeline-with-input-filter-to-one-output-and-other-without-filter-to-different-output/322350 "2023-01-03T16:05:08Z")

</div>

Hello Elkan s I wish you a happy new year!! Hope all are doings well. My scenario: collecting logs on port 9600 and adding filter to forward the logs to qradar I need to add one more output of azure sentinel without …

---

## [Question on kv filter](https://discuss.elastic.co/t/question-on-kv-filter/322388)

<div class="topic-metadata">

**Author:** [@moberreiter](https://discuss.elastic.co/u/moberreiter)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 3:09pm UTC](https://discuss.elastic.co/t/question-on-kv-filter/322388 "2023-01-03T15:09:05Z")

</div>

Hello everyone! I have a log from syslog which logstash should parse: Source: Jan 3 10:14:40 123.123.123.123 {"zone\_src":"SRC","zone\_dst":"DST","reason":"rule","rule\_id":12345,"rule\_description":"Rule Description","a…

---

## [\_jsonparsefailure with filebeat and logstash](https://discuss.elastic.co/t/jsonparsefailure-with-filebeat-and-logstash/322356)

<div class="topic-metadata">

**Author:** [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Replies:** 10\
**Last updated:** [January 3, 2023, 1:43pm UTC](https://discuss.elastic.co/t/jsonparsefailure-with-filebeat-and-logstash/322356 "2023-01-03T13:43:08Z")

</div>

Hello, I use Filebeat to fetch data from Wazuh (HIDS) and send alerts to Logstash. Then Logstash sends its data to ES and everything usually works fine. However, sometimes after being away for a few days, I look on Ki…

---

## [Logstash conditional check if filed exist then replace timestamp value with another fileds timestamp](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [January 3, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311 "2023-01-03T12:45:14Z")

</div>

Hello All, I'm stuck in how to implement conditional check in logstash and how would it be implemented correctly. Usecase:I have data coming in my index with multiple fields value,I'd like to send data to elastic wher…

---

## [IS it possible to use "nested else if" in logstash.conf](https://discuss.elastic.co/t/is-it-possible-to-use-nested-else-if-in-logstash-conf/322342)

<div class="topic-metadata">

**Author:** [@jjacksonrkk](https://discuss.elastic.co/u/jjacksonrkk)\
**Replies:** 2\
**Last updated:** [January 3, 2023, 10:17am UTC](https://discuss.elastic.co/t/is-it-possible-to-use-nested-else-if-in-logstash-conf/322342 "2023-01-03T10:17:35Z")

</div>

hello~ Is it possible to use "nested else if" in filter section inside logstash.conf logstash 7.10.2 example else if ... { if ...{ else if .... { .... } } }

---

## [Logstash - Collecting SNMP data from network devices](https://discuss.elastic.co/t/logstash-collecting-snmp-data-from-network-devices/321814)

<div class="topic-metadata">

**Author:** [@muhammad-murad.nagoo](https://discuss.elastic.co/u/muhammad-murad.nagoo)\
**Replies:** 25\
**Last updated:** [January 3, 2023, 9:41am UTC](https://discuss.elastic.co/t/logstash-collecting-snmp-data-from-network-devices/321814 "2023-01-03T09:41:33Z")

</div>

Hello Gentlemen, Installed the logstash agent in on prem Windows server. Configure to collect the SNMP from network devices. However i found error "\[2022-12-20T09:05:57,307\]\[FATAL\]\[org.logstash.Logstash \] Logstash st…

---

## [Logstash Grok Pattern Not Working(Regex)](https://discuss.elastic.co/t/logstash-grok-pattern-not-working-regex/322199)

<div class="topic-metadata">

**Author:** [@Prakash111](https://discuss.elastic.co/u/Prakash111)\
**Replies:** 4\
**Last updated:** [January 3, 2023, 6:14am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-not-working-regex/322199 "2023-01-03T06:14:58Z")

</div>

Hi Team, I have few logs which is having same pattern DATE LOGLEVEL textData JSONDATA i want to write grok pattern, it should pass all these 3 logs my grok pattern %{TIMESTAMP\_ISO8601:time}\\s\*\\\[%{LOGLEVEL:logleve}\\\]\\…

---

## [Could not index event to Elasticsearch. status: 404](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-status-404/322312)

<div class="topic-metadata">

**Author:** [@shubham.s](https://discuss.elastic.co/u/shubham.s)\
**Replies:** 3\
**Last updated:** [January 3, 2023, 4:34am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-status-404/322312 "2023-01-03T04:34:45Z")

</div>

refer to /etc/logstash/conf.d/pipeline.conf input { file { path =\> "/var/log/secure" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" } } filter { grok { match =\> { "message" =\> ""%{IPV4:i…

---

## [Variable in HTTP plugin](https://discuss.elastic.co/t/variable-in-http-plugin/322308)

<div class="topic-metadata">

**Author:** [@Anu14](https://discuss.elastic.co/u/Anu14)\
**Replies:** 3\
**Last updated:** [January 2, 2023, 6:28pm UTC](https://discuss.elastic.co/t/variable-in-http-plugin/322308 "2023-01-02T18:28:56Z")

</div>

Hello, I have a pretty basic use case for which I am unable to use log stash as intended and would appreciate community's help. There are 'n' keys that are part of a URL. These keys keep changing on daily basis and I w…

---

## [Not using Elasticsearch, Logstash keeps asking for a license](https://discuss.elastic.co/t/not-using-elasticsearch-logstash-keeps-asking-for-a-license/322318)

<div class="topic-metadata">

**Author:** [@camilovietnam](https://discuss.elastic.co/u/camilovietnam)\
**Replies:** 3\
**Last updated:** [January 2, 2023, 4:53pm UTC](https://discuss.elastic.co/t/not-using-elasticsearch-logstash-keeps-asking-for-a-license/322318 "2023-01-02T16:53:38Z")

</div>

Hello! I am running Logstash with Opensearch, and I keep seeing the following message in the logs of my Logstash container: logstash | \[2023-01-02T14:17:52,107\]\[ERROR\]\[logstash.licensechecker.licensereader\] Unable to r…

---

## [BitDefender Integration](https://discuss.elastic.co/t/bitdefender-integration/322327)

<div class="topic-metadata">

**Author:** [@xzapata](https://discuss.elastic.co/u/xzapata)\
**Replies:** 0\
**Last updated:** [January 2, 2023, 4:20pm UTC](https://discuss.elastic.co/t/bitdefender-integration/322327 "2023-01-02T16:20:43Z")

</div>

Good evening, I am trying to integrate BitDefender Gravity Zone. As you many may know is a cloud service. There are 2 steps 2 this: 1.- Generate a token authentication 2.-Enable the modules/log types with a CURL instr…

---

## [Filter input data from Filebeat using logstash?](https://discuss.elastic.co/t/filter-input-data-from-filebeat-using-logstash/322078)

<div class="topic-metadata">

**Author:** [@camilovietnam](https://discuss.elastic.co/u/camilovietnam)\
**Replies:** 9\
**Last updated:** [January 2, 2023, 12:26pm UTC](https://discuss.elastic.co/t/filter-input-data-from-filebeat-using-logstash/322078 "2023-01-02T12:26:30Z")

</div>

Hello! I managed to set up the stack Filebeat-\>Logstash-\>Elasticsearch, but I am using journald as an input for my filebeat logs, which means that a lot of unnecessary data appears to be saved in the ES index. I thought …

---

## [Using logstash to connect to Azure Datalake Storage Account from elasticsearch](https://discuss.elastic.co/t/using-logstash-to-connect-to-azure-datalake-storage-account-from-elasticsearch/322296)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 0\
**Last updated:** [January 2, 2023, 9:54am UTC](https://discuss.elastic.co/t/using-logstash-to-connect-to-azure-datalake-storage-account-from-elasticsearch/322296 "2023-01-02T09:54:56Z")

</div>

Hi all, Using jdbc driver in logstash, I'm able to connect elasticsearch with different databases like mysql , etc & get data to elasticsearch. But I'm not able to connect elasticsearch with Azure Data Lake Storage Gen…

---

## [How to fetch data from Elasticseach and display in React using APIs](https://discuss.elastic.co/t/how-to-fetch-data-from-elasticseach-and-display-in-react-using-apis/322197)

<div class="topic-metadata">

**Author:** [@khlinten\_demelash](https://discuss.elastic.co/u/khlinten_demelash)\
**Replies:** 8\
**Last updated:** [January 2, 2023, 8:03am UTC](https://discuss.elastic.co/t/how-to-fetch-data-from-elasticseach-and-display-in-react-using-apis/322197 "2023-01-02T08:03:47Z")

</div>

Hello, I'm from Ethiopia, and I'm working in Front-end Website Development. am using ReactJS and Elasticsearch. I'm getting trouble fetching data from Elasticsearch(https://192.168.1.3:9200/clientesafewindows-logstash/\_…

---

## [Rsyslog is not forwarding logs to elasticsearch](https://discuss.elastic.co/t/rsyslog-is-not-forwarding-logs-to-elasticsearch/322266)

<div class="topic-metadata">

**Author:** [@Aksel](https://discuss.elastic.co/u/Aksel)\
**Replies:** 6\
**Last updated:** [January 1, 2023, 6:37pm UTC](https://discuss.elastic.co/t/rsyslog-is-not-forwarding-logs-to-elasticsearch/322266 "2023-01-01T18:37:25Z")

</div>

I'm trying to configure rsyslog to send logs to logstash and then forward them to elasticsearch. I have create a config file /etc/rsyslog.d/60-output.conf with the following content: \*.\* @localhost:10514;json-template …

---

## [Elasticsearch output plugin ssl verification](https://discuss.elastic.co/t/elasticsearch-output-plugin-ssl-verification/322264)

<div class="topic-metadata">

**Author:** [@Mahdi\_Moazami](https://discuss.elastic.co/u/Mahdi_Moazami)\
**Replies:** 2\
**Last updated:** [January 1, 2023, 2:51pm UTC](https://discuss.elastic.co/t/elasticsearch-output-plugin-ssl-verification/322264 "2023-01-01T14:51:13Z")

</div>

Hi elastic team I've configured a pipeline containing a file input, some filters and elasticsearch output. the target es server is secured by ssl and the certificates are generated using the the way explained in docs. n…

---

## [Integrate Fortigate with Logstash](https://discuss.elastic.co/t/integrate-fortigate-with-logstash/322262)

<div class="topic-metadata">

**Author:** [@khaled7](https://discuss.elastic.co/u/khaled7)\
**Replies:** 0\
**Last updated:** [January 1, 2023, 12:51pm UTC](https://discuss.elastic.co/t/integrate-fortigate-with-logstash/322262 "2023-01-01T12:51:56Z")

</div>

Hello Team can anyone tell me a way or video explain how to integrate fortigate logs with logstash and elasticsearch and a way to make it appear in kibana i have elasticsearch 7.17.6 Kibana 7.17.6 Logstash 7.17.6 T…

---

## [Logstash pipeline High avliliblity](https://discuss.elastic.co/t/logstash-pipeline-high-avliliblity/321965)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 13\
**Last updated:** [December 31, 2022, 1:30am UTC](https://discuss.elastic.co/t/logstash-pipeline-high-avliliblity/321965 "2022-12-31T01:30:02Z")

</div>

hello Everyone, How to achieve The Logstash Pipeline HA? I have 3 Nodes if any node opening count of pipeline after that the node is down what happen? what is the solutions to achieve the HA?

---

## [Failed to install template](https://discuss.elastic.co/t/failed-to-install-template/322210)

<div class="topic-metadata">

**Author:** [@camilovietnam](https://discuss.elastic.co/u/camilovietnam)\
**Replies:** 2\
**Last updated:** [December 30, 2022, 1:15pm UTC](https://discuss.elastic.co/t/failed-to-install-template/322210 "2022-12-30T13:15:43Z")

</div>

Trying to demo the Elasticsearch stack, but having trouble figuring out why aren't things working. To start with, I have the following docker-compose file for mongo, logstash and elasticsearch. version: '3' # referenc…

---

## [Not able to get Source filename in the logstash output](https://discuss.elastic.co/t/not-able-to-get-source-filename-in-the-logstash-output/322130)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 2\
**Last updated:** [December 30, 2022, 10:57am UTC](https://discuss.elastic.co/t/not-able-to-get-source-filename-in-the-logstash-output/322130 "2022-12-30T10:57:43Z")

</div>

Hi, We are using filebeat 7.10.2 and logstash 8.10.4. Filebeat transfer the files from Machine A (Filebeat) to Machine B (Logstash) and Logstash writes the same in machine B's path (/va/pm/sfile/%{hostname}/%{\[log\]\[file…

---

## [Trying to understand a previous setup/pipeline](https://discuss.elastic.co/t/trying-to-understand-a-previous-setup-pipeline/322175)

<div class="topic-metadata">

**Author:** [@jason3](https://discuss.elastic.co/u/jason3)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 9:52pm UTC](https://discuss.elastic.co/t/trying-to-understand-a-previous-setup-pipeline/322175 "2022-12-29T21:52:07Z")

</div>

Hello all, Im trying to understand and learn Elastic while working though and improving some bad setups of my predecessors. I was hoping you could help with confirming my understanding after what I have been reading. …

---

## [Ruby Code Exception](https://discuss.elastic.co/t/ruby-code-exception/322155)

<div class="topic-metadata">

**Author:** [@Rohit\_Kumbhar](https://discuss.elastic.co/u/Rohit_Kumbhar)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 12:26pm UTC](https://discuss.elastic.co/t/ruby-code-exception/322155 "2022-12-29T12:26:01Z")

</div>

Hi Team, I am getting Ruby exception occurred: undefined method \`length' for nil error while using the following Ruby Code ruby { code =\> ' names = event.get("\[message\]").split(".") event.set("number\_…

[Previous page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=96)

[Next page](https://discuss.elastic.co/c/elastic-stack/logstash/14.md?page=98)
