- Logstash Reference: other versions:
- Logstash Introduction
- Getting Started with Logstash
- How Logstash Works
- Setting Up and Running Logstash
- Logstash Directory Layout
- Logstash Configuration Files
- logstash.yml
- Secrets keystore for secure settings
- Running Logstash from the Command Line
- Running Logstash as a Service on Debian or RPM
- Running Logstash on Docker
- Configuring Logstash for Docker
- Running Logstash on Windows
- Logging
- Shutting Down Logstash
- Upgrading Logstash
- Creating a Logstash pipeline
- Secure your connection
- Advanced Logstash Configurations
- Logstash-to-Logstash communication
- Managing Logstash
- Working with Logstash Modules
- Working with Filebeat Modules
- Working with Winlogbeat Modules
- Queues and data resiliency
- Transforming Data
- Deploying and Scaling Logstash
- Performance Tuning
- Monitoring Logstash
- Monitoring Logstash with APIs
- Working with plugins
- Integration plugins
- Input plugins
- azure_event_hubs
- beats
- cloudwatch
- couchdb_changes
- dead_letter_queue
- elastic_agent
- elastic_serverless_forwarder
- elasticsearch
- exec
- file
- ganglia
- gelf
- generator
- github
- google_cloud_storage
- google_pubsub
- graphite
- heartbeat
- http
- http_poller
- imap
- irc
- java_generator
- java_stdin
- jdbc
- jms
- jmx
- kafka
- kinesis
- log4j
- lumberjack
- meetup
- pipe
- puppet_facter
- rabbitmq
- redis
- relp
- rss
- s3
- s3-sns-sqs
- salesforce
- snmp
- snmptrap
- sqlite
- sqs
- stdin
- stomp
- syslog
- tcp
- udp
- unix
- varnishlog
- websocket
- wmi
- xmpp
- Output plugins
- boundary
- circonus
- cloudwatch
- csv
- datadog
- datadog_metrics
- dynatrace
- elastic_app_search
- elastic_workplace_search
- elasticsearch
- exec
- file
- ganglia
- gelf
- google_bigquery
- google_cloud_storage
- google_pubsub
- graphite
- graphtastic
- http
- influxdb
- irc
- java_stdout
- juggernaut
- kafka
- librato
- loggly
- lumberjack
- metriccatcher
- mongodb
- nagios
- nagios_nsca
- opentsdb
- pagerduty
- pipe
- rabbitmq
- redis
- redmine
- riak
- riemann
- s3
- sink
- sns
- solr_http
- sqs
- statsd
- stdout
- stomp
- syslog
- tcp
- timber
- udp
- webhdfs
- websocket
- xmpp
- zabbix
- Filter plugins
- age
- aggregate
- alter
- bytes
- cidr
- cipher
- clone
- csv
- date
- de_dot
- dissect
- dns
- drop
- elapsed
- elasticsearch
- environment
- extractnumbers
- fingerprint
- geoip
- grok
- http
- i18n
- java_uuid
- jdbc_static
- jdbc_streaming
- json
- json_encode
- kv
- memcached
- metricize
- metrics
- mutate
- prune
- range
- ruby
- sleep
- split
- syslog_pri
- threats_classifier
- throttle
- tld
- translate
- truncate
- urldecode
- useragent
- uuid
- wurfl_device_detection
- xml
- Codec plugins
- Tips and best practices
- Troubleshooting
- Contributing to Logstash
- How to write a Logstash input plugin
- How to write a Logstash codec plugin
- How to write a Logstash filter plugin
- How to write a Logstash output plugin
- Logstash Plugins Community Maintainer Guide
- Document your plugin
- Publish your plugin to RubyGems.org
- List your plugin
- Contributing a patch to a Logstash plugin
- Extending Logstash core
- Contributing a Java Plugin
- Breaking changes
- Release Notes
- Logstash 8.8.2 Release Notes
- Logstash 8.8.1 Release Notes
- Logstash 8.8.0 Release Notes
- Logstash 8.7.1 Release Notes
- Logstash 8.7.0 Release Notes
- Logstash 8.6.2 Release Notes
- Logstash 8.6.1 Release Notes
- Logstash 8.6.0 Release Notes
- Logstash 8.5.3 Release Notes
- Logstash 8.5.2 Release Notes
- Logstash 8.5.1 Release Notes
- Logstash 8.5.0 Release Notes
- Logstash 8.4.2 Release Notes
- Logstash 8.4.1 Release Notes
- Logstash 8.4.0 Release Notes
- Logstash 8.3.3 Release Notes
- Logstash 8.3.2 Release Notes
- Logstash 8.3.1 Release Notes
- Logstash 8.3.0 Release Notes
- Logstash 8.2.3 Release Notes
- Logstash 8.2.2 Release Notes
- Logstash 8.2.1 Release Notes
- Logstash 8.2.0 Release Notes
- Logstash 8.1.3 Release Notes
- Logstash 8.1.2 Release Notes
- Logstash 8.1.1 Release Notes
- Logstash 8.1.0 Release Notes
- Logstash 8.0.1 Release Notes
- Logstash 8.0.0 Release Notes
- Logstash 8.0.0-rc2 Release Notes
- Logstash 8.0.0-rc1 Release Notes
- Logstash 8.0.0-beta1 Release Notes
- Logstash 8.0.0-alpha2 Release Notes
- Logstash 8.0.0-alpha1 Release Notes
An input plugin enables a specific source of events to be read by Logstash.
The following input plugins are available below. For a list of Elastic supported plugins, please consult the Support Matrix.
Plugin |
Description |
Github repository |
Receives events from Azure Event Hubs |
||
Receives events from the Elastic Beats framework |
||
Pulls events from the Amazon Web Services CloudWatch API |
||
Streams events from CouchDB’s |
||
read events from Logstash’s dead letter queue |
||
Receives events from the Elastic Agent framework |
logstash-input-beats (shared) |
|
Accepts events from Elastic Serverless Forwarder |
||
Reads query results from an Elasticsearch cluster |
||
Captures the output of a shell command as an event |
||
Streams events from files |
||
Reads Ganglia packets over UDP |
||
Reads GELF-format messages from Graylog2 as events |
||
Generates random log events for test purposes |
||
Reads events from a GitHub webhook |
||
Extract events from files in a Google Cloud Storage bucket |
||
Consume events from a Google Cloud PubSub service |
||
Reads metrics from the |
||
Generates heartbeat events for testing |
||
Receives events over HTTP or HTTPS |
||
Decodes the output of an HTTP API into events |
||
Reads mail from an IMAP server |
||
Reads events from an IRC server |
||
Generates synthetic log events |
||
Reads events from standard input |
||
Creates events from JDBC data |
||
Reads events from a Jms Broker |
||
Retrieves metrics from remote Java applications over JMX |
||
Reads events from a Kafka topic |
||
Receives events through an AWS Kinesis stream |
||
Reads events over a TCP socket from a Log4j |
||
Receives events using the Lumberjack protocl |
||
Captures the output of command line tools as an event |
||
Streams events from a long-running command pipe |
||
Receives facts from a Puppet server |
||
Pulls events from a RabbitMQ exchange |
||
Reads events from a Redis instance |
||
Receives RELP events over a TCP socket |
||
Captures the output of command line tools as an event |
||
Streams events from files in a S3 bucket |
||
Reads logs from AWS S3 buckets using sqs |
||
Creates events based on a Salesforce SOQL query |
||
Polls network devices using Simple Network Management Protocol (SNMP) |
||
Creates events based on SNMP trap messages |
||
Creates events based on rows in an SQLite database |
||
Pulls events from an Amazon Web Services Simple Queue Service queue |
||
Reads events from standard input |
||
Creates events received with the STOMP protocol |
||
Reads syslog messages as events |
||
Reads events from a TCP socket |
||
Reads events from the Twitter Streaming API |
||
Reads events over UDP |
||
Reads events over a UNIX socket |
||
Reads from the |
||
Reads events from a websocket |
||
Creates events based on the results of a WMI query |
||
Receives events over the XMPP/Jabber protocol |