# Short\_message and host must be set

**URL:** <https://discuss.elastic.co/t/short-message-and-host-must-be-set/216709>\
**Category:** Logstash\
**Created:** [January 27, 2020, 5:54pm UTC](https://discuss.elastic.co/t/short-message-and-host-must-be-set/216709 "2020-01-27T17:54:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sblancocr](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@sblancocr](https://discuss.elastic.co/u/sblancocr)\
**Post date:** [January 27, 2020, 5:55pm UTC](https://discuss.elastic.co/t/short-message-and-host-must-be-set/216709/1 "2020-01-27T17:55:00Z")

</div>

Hi..

I have a logstash and i try to connect to graylog2.

The logstash configuration is:

input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/XXXX.crt"  
ssl\_key =\> "/etc/pki/tls/private/YYYY.key"  
client\_inactivity\_timeout =\> 0  
}  
udp {  
port =\> 10514  
codec =\> "json"  
type =\> "rsyslog"  
}  
}

output {

gelf {  
host =\> "x.x.x.x"  
short\_message =\> "test"  
port =\> 12201  
}  
}

but, logstash show this error:

[2020-01-27T11:39:47,576][WARN][logstash.outputs.gelf] Trouble sending GELF event {:gelf\_event=\>{"short\_message"=\>nil, "full\_message"=\>"%{message}", "host"=\>"{"name":"idm-fva-01.ucr.ac.cr","id":"9e2a96b31f7ba3ebad15a056c85382d2","os":{"name":"CentOS Linux","family":"redhat","version":"7 (Core)","platform":"centos","codename":"Core"},"architecture":"x86\_64","containerized":false}", "\_tags"=\>"beats\_input\_raw\_event", "\_nginx\_stubstatus"=\>{"dropped"=\>0, "current"=\>1, "requests"=\>706420, "reading"=\>0, "active"=\>1, "writing"=\>1, "hostname"=\>"127.0.0.1", "waiting"=\>0, "handled"=\>167106, "accepts"=\>167106}, "\_beat\_hostname"=\>"idm-fva-01.ucr.ac.cr", "\_beat\_version"=\>"6.8.1", "\_beat\_name"=\>"idm-fva-01.ucr.ac.cr", "\_event\_dataset"=\>"nginx.stubstatus", "\_event\_duration"=\>829344, "\_metricset\_host"=\>"127.0.0.1", "\_metricset\_rtt"=\>829, "\_metricset\_name"=\>"stubstatus", "\_metricset\_module"=\>"nginx", "level"=\>6}, :event=\>#LogStash::Event:0x70a5e5d8, :error=\>#\<ArgumentError: short\_message is missing. Options version, short\_message and host must be set.\>}

Can any help me.

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 27, 2020, 6:10pm UTC](https://discuss.elastic.co/t/short-message-and-host-must-be-set/216709/2 "2020-01-27T18:10:35Z")

</div>

I think you would get that if the message has neither a [message] field (which you will not have with a json codec) nor a [test] field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2020, 6:11pm UTC](https://discuss.elastic.co/t/short-message-and-host-must-be-set/216709/3 "2020-02-24T18:11:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
