# Weird logs pushed by logstash after going secure

**URL:** <https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179>\
**Category:** Logstash\
**Created:** [September 28, 2020, 12:21pm UTC](https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179 "2020-09-28T12:21:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kwiskas](https://avatars.discourse-cdn.com/v4/letter/k/f04885/32.png) [@Kwiskas](https://discuss.elastic.co/u/Kwiskas)\
**Post date:** [September 28, 2020, 12:21pm UTC](https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179/1 "2020-09-28T12:21:46Z")

</div>

Hello  
Our elk stack is on version 7.6.2  
A few days ago we pushed on our team logstash as secure to enable x-pack  
we dit same for elastic nodes also kibana

Since we did that logstash is sending weird logs and parameters

example:  
parameters.(,dateformat"  
parameters."employeeNumber","employeeName","...

is sending almost everything on a message as a parameter!!

We did not changed the filters

Does anyone know why this is happening?

Thank you

---

<div class="post-metadata">

**Author:** ![Kwiskas](https://avatars.discourse-cdn.com/v4/letter/k/f04885/32.png) [@Kwiskas](https://discuss.elastic.co/u/Kwiskas)\
**Post date:** [September 30, 2020, 8:07am UTC](https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179/2 "2020-09-30T08:07:22Z")

</div>

except that i'm wrong about whats adding those weird fields and it's more an elastic problem?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 30, 2020, 11:48pm UTC](https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179/3 "2020-09-30T23:48:42Z")

</div>

It's not really clear what the issue is here.

Can you show an example event?

---

<div class="post-metadata">

**Author:** ![Kwiskas](https://avatars.discourse-cdn.com/v4/letter/k/f04885/32.png) [@Kwiskas](https://discuss.elastic.co/u/Kwiskas)\
**Post date:** [October 1, 2020, 8:41am UTC](https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179/4 "2020-10-01T08:41:11Z")

</div>

![fields2](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd42a934f2e3e4732c0d57727d56942a51a435a9.jpeg)

have deleted confidential stuff on screen

If this can explain. Since elastic stack upgrade to secure with certificates, a lot of parameters are coming as a field, but they should not

before, i hade basic parameters like:  
parameters.nb\_current\_entry  
parameters.employeeName  
parameters.baseSource

now, i have what you see on screen  
but also:  
parameters.(elskf'.  
parameters.(0elfsg

those kind of things  
almost everything on a message is going up as a parameter and so as a field..

---

<div class="post-metadata">

**Author:** ![Kwiskas](https://avatars.discourse-cdn.com/v4/letter/k/f04885/32.png) [@Kwiskas](https://discuss.elastic.co/u/Kwiskas)\
**Post date:** [October 21, 2020, 10:29am UTC](https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179/5 "2020-10-21T10:29:18Z")

</div>

Maybe someone has an option or idea to exclude those bad parameters using filters on logstash?  
if for example a field start with [,(,,/," just ignore the field creation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2020, 10:29am UTC](https://discuss.elastic.co/t/weird-logs-pushed-by-logstash-after-going-secure/250179/6 "2020-11-18T10:29:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
