Docs
  • Guides
  • APIs (opens in a new tab)
  • Products
    Elasticsearch Observability Security Elastic Cloud
  • Reference
  • Troubleshoot
  • Release notes
  1. Docs /
  2. Reference /
  3. Ingestion tools /
  4. Logstash

Transforming data

With over 200 plugins in the Logstash plugin ecosystem, it’s sometimes challenging to choose the best plugin to meet your data processing needs. In this section, we’ve collected a list of popular plugins and organized them according to their processing capabilities:

  • Performing Core Operations
  • Deserializing Data
  • Extracting Fields and Wrangling Data
  • Enriching Data with Lookups

Also see Filter plugins and Codec plugins for the full list of available data processing plugins.

Previous
Dead letter queues (DLQ)
Next
Performing Core Operations
  • View as Markdown
  • Report a docs issue
  • Edit this page
  • Learn how to contribute
Get started free
  • 14-day free trial
  • All features included
  • No setup required
Section
Reference
Docs Guides APIs (opens in a new tab)
Products
Elasticsearch Observability Security Elastic Cloud
Reference Troubleshoot Release notes
Version
Reference Ingestion tools
  • Logstash
    • Getting started with Logstash
      • Installing Logstash
      • Stashing Your First Event
      • Parsing Logs with Logstash
      • Stitching Together Multiple Input and Output Plugins
    • How Logstash Works
      • Execution Model
      • ECS in Logstash
      • Processing Details
    • Setting up and running Logstash
      • Logstash Directory Layout
      • Logstash Configuration Files
      • logstash.yml
      • Secrets keystore for secure settings
      • Running Logstash from the Command Line
      • Running Logstash as a Service on Debian or RPM
      • Running Logstash on Docker
      • Configuring Logstash for Docker
      • Running Logstash on Kubernetes
      • Running Logstash on Windows
      • Logging
      • Shutting Down Logstash
    • Upgrading Logstash
      • Upgrading using package managers
      • Upgrading using a direct download
      • Upgrading between minor versions
    • Creating a Logstash Pipeline
      • Structure of a pipeline
      • Accessing event data and fields
      • Using environment variables
      • Sending data to Elastic Cloud Hosted
      • Sending data to Elasticsearch Serverless
      • Logstash configuration examples
    • Secure your connection
    • Advanced Logstash configurations
      • Multiple Pipelines
      • Pipeline-to-pipeline communication
      • Reloading the Config File
      • Managing Multiline Events
      • Glob Pattern Support
    • Logstash-to-Logstash communications
      • Logstash-to-Logstash: Lumberjack output to Beats input
      • Logstash-to-Logstash: HTTP output to HTTP input
      • Logstash-to-Logstash: Output to Input
    • Managing Logstash
      • Centralized Pipeline Management
      • Configure Centralized Pipeline Management
    • Using Logstash with Elastic integrations
      • Tutorial to extend Elastic Integrations
    • Working with Filebeat modules
      • Use ingest pipelines for parsing
      • Example: Set up Filebeat modules to work with Kafka and Logstash
    • Working with Winlogbeat modules
    • Queues and data resiliency
      • Memory queue
      • Persistent queues (PQ)
      • Dead letter queues (DLQ)
    • Transforming data
      • Performing Core Operations
      • Deserializing Data
      • Extracting Fields and Wrangling Data
      • Enriching Data with Lookups
    • Deploying and scaling Logstash
    • Managing GeoIP databases
      • GeoIP Database Management
      • Configure GeoIP Database Management
    • Performance tuning
      • Performance troubleshooting
      • Tuning and profiling logstash pipeline performance
    • Monitoring Logstash with Elastic Agent
      • Collect monitoring data for dashboards
      • Collect monitoring data for dashboards (Serverless )
      • Collect monitoring data for stack monitoring
    • Monitoring Logstash (Legacy)
      • Metricbeat collection
      • Legacy collection (deprecated)
      • Monitoring UI
      • Pipeline Viewer UI
      • Troubleshooting
    • Monitoring Logstash with APIs
    • Monitoring Logstash with OpenTelemetry
    • Working with plugins
      • Cross-plugin concepts and features
      • Generating plugins
      • Offline Plugin Management
      • Private Gem Repositories
      • Event API
    • Tips and best practices
      • JVM settings
      • File descriptors
Elastic logo
  • Trademarks
  • Terms of Use
  • Privacy
  • Sitemap

© 2026 Elasticsearch B.V. All Rights Reserved.

This content is available in different formats for convenience only. All original licensing terms apply.

Elasticsearch is a trademark of Elasticsearch B.V., registered in the U.S. and in other countries. Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.