# Input logs from Azure BLOB using logstash and output to ES

**URL:** <https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459>\
**Category:** Logstash\
**Created:** [March 8, 2019, 8:59am UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459 "2019-03-08T08:59:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prabhu2430](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhu2430/32/41706_2.png) [@Prabhu2430](https://discuss.elastic.co/u/Prabhu2430)\
**Post date:** [March 8, 2019, 8:59am UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459/1 "2019-03-08T08:59:07Z")

</div>

Hi All,

I have been trying to pull the logs of my webapp which is stored in my azure storage account {BLOB}.

I am using the logstash-input-azureblob plugin which i have already installed.

[root@AZEUSELKVM01 ~]# /usr/share/logstash/bin/logstash-plugin list | grep blob  
logstash-input-azureblob

I am using the below configuration in my logstash.conf

input {  
azureblob {  
storage\_account\_name =\> "testblob"  
storage\_access\_key =\> "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"  
container =\> "test"  
codec =\> "json"  
file\_head\_bytes =\> 12  
file\_tail\_bytes =\> 2  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "blob-%{+YYYY.MM.dd}"  
}  
}

When I start my logstash , its showing the plugin error.

Could you please help on how to pull the logs that are stored in azure blob using logstash.

PFB the error for your reference:

[2019-03-08T08:58:28,535][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::PluginLoadingError", :message=\>"Couldn't find any input plugin named 'azureblob'. Are you sure this is correct? Trying to load the azureblob input plugin resulted in this error: Problems loading the requested plugin named azureblob of type input. Error: TypeError no implicit conversion of nil into String", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:211:in `lookup_pipeline_plugin'", "/usr/share/logstash/logstash-core/lib/logstash/plugin.rb:137:in`lookup'", "org/logstash/plugins/PluginFactoryExt.java:222:in `plugin'", "org/logstash/plugins/PluginFactoryExt.java:181:in`plugin'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:71:in `plugin'", "(eval):8:in`'", "org/jruby/RubyKernel.java:994:in `eval'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:49:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:90:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:43:in`block in execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:94:in `block in exclusive'", "org/jruby/ext/thread/Mutex.java:148:in`synchronize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:94:in `exclusive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:39:in`execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:327:in `block in converge\_state'"]}  
[2019-03-08T08:58:29,089][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![Prabhu2430](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhu2430/32/41706_2.png) [@Prabhu2430](https://discuss.elastic.co/u/Prabhu2430)\
**Post date:** [March 11, 2019, 6:40am UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459/2 "2019-03-11T06:40:17Z")

</div>

Can someone update ?? Still facing issue

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2019, 12:51pm UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459/3 "2019-03-11T12:51:31Z")

</div>

Why not use the [azure\_event\_hubs](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-azure_event_hubs.html) plugin?

---

<div class="post-metadata">

**Author:** ![ec2](https://avatars.discourse-cdn.com/v4/letter/e/e47774/32.png) [@ec2](https://discuss.elastic.co/u/ec2)\
**Post date:** [March 22, 2019, 9:18am UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459/4 "2019-03-22T09:18:39Z")

</div>

I don't believe the [azure\_event\_hubs](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-azure_event_hubs.html) plugin is capable of processing data from an Azure blob storage account? If it can, I'd sure like to know how!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 22, 2019, 12:39pm UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459/5 "2019-03-22T12:39:09Z")

</div>

I haven't tried it, but the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-azure_event_hubs.html) says " [Azure Blob Storage account](https://azure.microsoft.com/en-us/services/storage/blobs) is an essential part of Azure-to-Logstash configuration" and "A Blob Storage account is highly recommended for use with this plugin, and is likely required for production servers". That suggests to me that it can process data from an Azure Blob Storage account. YMMV.

---

<div class="post-metadata">

**Author:** ![ec2](https://avatars.discourse-cdn.com/v4/letter/e/e47774/32.png) [@ec2](https://discuss.elastic.co/u/ec2)\
**Post date:** [March 22, 2019, 12:56pm UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459/6 "2019-03-22T12:56:19Z")

</div>

I've used the Event Hubs plugin quite a bit and am pretty familiar with it but thought maybe I've missed something.

The plugin uses an Azure Blob Storage account only for tracking the progress of processed events from the Event Hub by creating a small file in the blob storage account. This is to avoid duplicate events. It doesn't work as an input unfortunately.

I'm looking for another way to pull logs from an azure blob storrage account as I've also tried the azureblob input plugin but it doesn't seem to be very well supported and has problems with high resource usage.

Thanks anyway!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2019, 12:56pm UTC](https://discuss.elastic.co/t/input-logs-from-azure-blob-using-logstash-and-output-to-es/171459/7 "2019-04-19T12:56:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
