# Logstash elasticsearch input error

**URL:** <https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172>\
**Category:** Logstash\
**Created:** [February 3, 2022, 10:05am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172 "2022-02-03T10:05:30Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 3, 2022, 10:05am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/1 "2022-02-03T10:05:30Z")

</div>

Hello

I am extracting data from an http server through the apace pipeline, indicating the pipeline to use in the logstash output and it indexes correctly. On the other hand, I want to enrich the data already obtained and I have decided to make an Elasticsearch input collecting the data every 2 minutes. My input currently looks like this:

```auto
input {
     # saca todo de los indices que pertenezcan al formato index entre las fechas introducidas
  elasticsearch {
        hosts => ["elk1:9200","elk2:9200","elk3:9200"]
        ssl => true
        user => elastic
        password => "xxxx"
        ca_file => '/path/cert.pem'
        index => "filebeat-7.16.3-mmmmm-http-server-2022*"
        schedule => "*/2 * * * *"
        size => 10000
        query => '{
          "query":{
            "range":{
              "@timestamp":{
                "gte": "now-2m",
                "lte": "now"
              }
            }
          }
        }'
  }
}

```

But there are some small differences. Is there any method to be able to use the pipeline and enrich in the same etl?

otherwise what would be the best config for the input ??

It would be a great help. Thanks!!!

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [February 3, 2022, 8:32pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/2 "2022-02-03T20:32:14Z")

</div>

If you are going through logstash in the first ingest yes, it should be possible to do so in one go.  
What exactly are you trying to enrich/do?

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 3, 2022, 9:28pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/3 "2022-02-03T21:28:52Z")

</div>

thanks for answering!

the first etl consists of an input and an output with the parameter pipeline =\> apache-access.

the second has an Elasticsearch input to get the data parsed by etl 1.8

With the data already parsed by the Apache module, I want to extract words from the [url][original] field or digits from the [source][address] field.

My question is if I could put a filter after the output or if i can put something similar as :sql\_last\_value of jdbc plugin or if there is a more efficient method to do this.

Thank you in advance!

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 3, 2022, 10:09pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/4 "2022-02-03T22:09:04Z")

</div>

Is there any reason you need such two staged pipeline? Filter plugins between HTTP input and some output seems enough to extract some words or digits from some field.

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 3, 2022, 10:24pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/5 "2022-02-03T22:24:31Z")

</div>

Because i dont know how to tell logstash to use the filebeat-apache-access pipeline before the indexing. So i need a second pipeline to parse all the fields that i want with the data previously indexed at Elasticsearch

Can i download the pipeline in a correct format to paste it in the logstash config pipeline? Can i put a filter after an output? How can i use the module pipeline and extract all the info that i want in the same pipeline?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 3, 2022, 10:40pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/6 "2022-02-03T22:40:22Z")

</div>

So you are using probably as the first pipeline.

Sorry I'm not familiar with filebeat and don't understand filebeat-apache-access pipeline. But I suppose there are some similar logstash input plugin to access your HTTP server.

Or using logstash beat input could be more simple.

> **[Configure the Logstash output | Filebeat Reference \[7.17\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html)**

What did you mean "some small differences"?

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 3, 2022, 11:12pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/7 "2022-02-03T23:12:59Z")

</div>

Yes im using filebeat input via the 5044 logstash port and at the output i set the pipeline parameter to use the pipeline preconfigured by the elastic team at the first pipeline.  
When this parsed fields are indexed to elastic i use another pipeline with Elasticsearch input to keep this data and parse it again.

Yes , there is small differences. For example in my first index i could have a count 101 of status code = 200 and at the new one the count is 97.. is an example.

I tried to correct that difference with the fingerprint plugin, creating an id for all the documents concatenating 3 fields( [event][created] , [source][address] and [original][url] ) and using it as the document\_id =\> %{fingerprint\_id} and it reduce the difference but not at all

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 3, 2022, 11:59pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/8 "2022-02-03T23:59:32Z")

</div>

Part of the reason is that you use 2 minutes span every 2 minutes. There could be some gaps and overlaps when some delay has occurred somewhere. Even if the pipeline runs strictly every 2 minutes, there are about up to one second delay for documents to be able to be searched in Elasticsearch after indexed, some documents should be dropped.

You have to run the 2 minutes span pipeline more frequently or prolonged span pipeline every 2 minutes. And deduplicate the documents by using fingerprint as you said.

Use update action reduce the indexing load of the Elasticsearch cluster.

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 4, 2022, 8:29am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/9 "2022-02-04T08:29:43Z")

</div>

> [@Tomo\_M](#):
>
> Part of the reason is that you use 2 minutes span every 2 minutes. There could be some gaps and overlaps when some delay has occurred somewhere. Even if the pipeline runs strictly every 2 minutes, there are about up to one second delay for documents to be able to be searched in Elasticsearch after indexed, some documents should be dropped.
> 
> You have to run the 2 minutes span pipeline more frequently or prolonged span pipeline every 2 minutes. And deduplicate the documents by using fingerprint as you said.
> 
> Use update action reduce the indexing load of the Elasticsearch cluster.

I have it set 2 by 2 because if the time increases I exceed the elastic limitation of 10,000 documents...

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 4, 2022, 8:33am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/10 "2022-02-04T08:33:38Z")

</div>

Then do the pipeline more frequently, or connect filebeat direct to logstash and output to two indices from logstash.

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 4, 2022, 8:43am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/11 "2022-02-04T08:43:52Z")

</div>

can not increase the 10.000 limit , can i ?

i dont know well how to do it because if i increase i excedeed the limit but if i decrease i think i will not get all the documents. Mi workflow is generating 5.000 documents per minute.  
How can i set 1 pipeline to two index and set it to balance the outputs?

sorry for the inconvenience and thank you very much for the help

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 4, 2022, 8:54am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/12 "2022-02-04T08:54:28Z")

</div>

It's a possible solution to raise the limit.

just use two output plugin as [this example](https://www.elastic.co/guide/en/logstash/current/multiple-input-output-plugins.html#testing-second-pipeline).

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 4, 2022, 9:00am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/13 "2022-02-04T09:00:40Z")

</div>

and how can i increase?

i see that but i dont understad how to divide the data equitably in two indexs.

Now i am targeting 3 different data nodes .

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 4, 2022, 9:04am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/14 "2022-02-04T09:04:10Z")

</div>

Have you searched by yourself?

---

<div class="post-metadata">

**Author:** ![rodri.gz](https://avatars.discourse-cdn.com/v4/letter/r/aca169/32.png) [@rodri.gz](https://discuss.elastic.co/u/rodri.gz)\
**Post date:** [February 4, 2022, 9:06am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/15 "2022-02-04T09:06:31Z")

</div>

Yes, I have been trying things like the ones we mentioned for several days but there are always some limitations or problems, I will continue investigating, thanks for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 4, 2022, 9:07am UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-error/296172/16 "2022-03-04T09:07:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
