# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Logs category](https://discuss.elastic.co/t/about-the-logs-category/156755)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 0

</div>

Open source log monitoring The Elastic Stack (sometimes known as the ELK Stack) is the most popular free and open logging platform. This is the place for any questions you may have on log monitoring.

---

## [Not all logs from strongswan available](https://discuss.elastic.co/t/not-all-logs-from-strongswan-available/387402)

<div class="topic-metadata">

**Author:** [@leprovokateur](https://discuss.elastic.co/u/leprovokateur)\
**Replies:** 11\
**Last updated:** [July 1, 2026, 9:58am UTC](https://discuss.elastic.co/t/not-all-logs-from-strongswan-available/387402 "2026-07-01T09:58:49Z")

</div>

Hi, I have StrongSwan installed on a debian 13 machine. The logs are written to the journal. I use elastic-agent in version 9.3.3 trying to read this logs, the stack is in version 9.3.3, too. journalctl -u strongswan sh…

---

## [Reroute logs in different dataset/datastreams/data\_namespaces](https://discuss.elastic.co/t/reroute-logs-in-different-dataset-datastreams-data-namespaces/386282)

<div class="topic-metadata">

**Author:** [@proclick](https://discuss.elastic.co/u/proclick)\
**Replies:** 2\
**Last updated:** [May 11, 2026, 3:08pm UTC](https://discuss.elastic.co/t/reroute-logs-in-different-dataset-datastreams-data-namespaces/386282 "2026-05-11T15:08:34Z")

</div>

Hello guys, I ingest logs from one SaaS solution though the pre-built elastic agent integration. The logs are pretty noisy and I want to reroute them in different namespaces (data streams) to apply different ILM policie…

---

## [Salesforce Integration - Resolving Salesforce instance URL Error](https://discuss.elastic.co/t/salesforce-integration-resolving-salesforce-instance-url-error/383693)

<div class="topic-metadata">

**Author:** [@BKgingersnap](https://discuss.elastic.co/u/BKgingersnap)\
**Replies:** 8\
**Last updated:** [December 15, 2025, 2:47pm UTC](https://discuss.elastic.co/t/salesforce-integration-resolving-salesforce-instance-url-error/383693 "2025-12-15T14:47:07Z")

</div>

I’m configuring the Salesforce Integration as described here: Salesforce Integration | Elastic integrations I am able to authenticate and generate an Salesforce Access Token using the test script in the document but whe…

---

## [Parsing a logstash file](https://discuss.elastic.co/t/parsing-a-logstash-file/383788)

<div class="topic-metadata">

**Author:** [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Replies:** 2\
**Last updated:** [December 1, 2025, 6:08pm UTC](https://discuss.elastic.co/t/parsing-a-logstash-file/383788 "2025-12-01T18:08:53Z")

</div>

I want to parse my logstash file to be able to delete some unnecessary fields that appear in kibana This is the input file from filebeat { "source": "10.200.226.62:57500", "subscription-name": "default-1764331045"…

---

## [Filebeat 8.17.10 disable template data\_stream](https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429)

<div class="topic-metadata">

**Author:** [@almteref](https://discuss.elastic.co/u/almteref)\
**Replies:** 3\
**Last updated:** [November 18, 2025, 3:55am UTC](https://discuss.elastic.co/t/filebeat-8-17-10-disable-template-data-stream/383429 "2025-11-18T03:55:08Z")

</div>

Hi I have filebae version 8.17.10 running on k8s And send logs to elasticsearch with the same version This is my configuration filebeat: inputs: type: filestream id: vouchers-logs-stream paths: /path/to/logs/\*.…

---

## [Alerting on field value change](https://discuss.elastic.co/t/alerting-on-field-value-change/383451)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 12\
**Last updated:** [November 16, 2025, 1:10pm UTC](https://discuss.elastic.co/t/alerting-on-field-value-change/383451 "2025-11-16T13:10:12Z")

</div>

I’m currently logging on-change data in ES, and I’m running a latest transform to store the most updated data into a separate index. I was advised that an ingest pipeline will help me compare any value coming in with th…

---

## [.NET W3C format webserver access logs on Linux](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178)

<div class="topic-metadata">

**Author:** [@taprove](https://discuss.elastic.co/u/taprove)\
**Replies:** 9\
**Last updated:** [October 30, 2025, 1:34pm UTC](https://discuss.elastic.co/t/net-w3c-format-webserver-access-logs-on-linux/382178 "2025-10-30T13:34:00Z")

</div>

Before I go down the path of creating something custom to bring in W3C format access logs generated from .NET https server apps on Linux, I wanted to make sure there wasn’t some easier way to do it with an existing integ…

---

## [Structured Logging with Serilog & Elasticsearch – How to Avoid Mapping Explosion?](https://discuss.elastic.co/t/structured-logging-with-serilog-elasticsearch-how-to-avoid-mapping-explosion/378266)

<div class="topic-metadata">

**Author:** [@a\_mandel](https://discuss.elastic.co/u/a_mandel)\
**Replies:** 6\
**Last updated:** [June 5, 2025, 12:35pm UTC](https://discuss.elastic.co/t/structured-logging-with-serilog-elasticsearch-how-to-avoid-mapping-explosion/378266 "2025-06-05T12:35:08Z")

</div>

Hi, I'm using Serilog with Elasticsearch in a .NET application, and I'm writing logs to Elasticsearch data streams using a basic setup like this: Log.Logger = new LoggerConfiguration() .MinimumLevel.Information …

---

## [Best Practice for Using Multiple ILM Policies with Serilog and Elasticsearch Based on Log Levels in a .NET Application?](https://discuss.elastic.co/t/best-practice-for-using-multiple-ilm-policies-with-serilog-and-elasticsearch-based-on-log-levels-in-a-net-application/378265)

<div class="topic-metadata">

**Author:** [@a\_mandel](https://discuss.elastic.co/u/a_mandel)\
**Replies:** 3\
**Last updated:** [June 4, 2025, 4:37pm UTC](https://discuss.elastic.co/t/best-practice-for-using-multiple-ilm-policies-with-serilog-and-elasticsearch-based-on-log-levels-in-a-net-application/378265 "2025-06-04T16:37:51Z")

</div>

Hello, I’m working on a .NET application where I’m using Serilog to send logs to Elasticsearch. I want to apply different Index Lifecycle Management (ILM) policies based on the log level — for example, separate ILM poli…

---

## [Failed to fetch frequent\_item\_sets in log rate analysis](https://discuss.elastic.co/t/failed-to-fetch-frequent-item-sets-in-log-rate-analysis/378492)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [May 24, 2025, 9:00pm UTC](https://discuss.elastic.co/t/failed-to-fetch-frequent-item-sets-in-log-rate-analysis/378492 "2025-05-24T21:00:26Z")

</div>

Good evening, When I add log rate analysis to a dashboard in Elastic Security serverless, I see the following error: The following error occurred running the analysis. Failed to fetch frequent\_item\_sets. Anyone wi…

---

## [Observability field composition of Stream Logs message](https://discuss.elastic.co/t/observability-field-composition-of-stream-logs-message/378048)

<div class="topic-metadata">

**Author:** [@b790718](https://discuss.elastic.co/u/b790718)\
**Replies:** 1\
**Last updated:** [May 12, 2025, 3:03pm UTC](https://discuss.elastic.co/t/observability-field-composition-of-stream-logs-message/378048 "2025-05-12T15:03:35Z")

</div>

Elasticsearch: v8.11.0 Kibana: v8.11.0 Filebeat: v8.11.0 APM Agent: nodejs v8.10.0 I use winston logger with ecs-winston-format. I am so confused about what field composition of Stream Message is ? When I set ecsFo…

---

## [ES|QL query all types of logs](https://discuss.elastic.co/t/es-ql-query-all-types-of-logs/377086)

<div class="topic-metadata">

**Author:** [@michael005](https://discuss.elastic.co/u/michael005)\
**Replies:** 2\
**Last updated:** [April 16, 2025, 4:33am UTC](https://discuss.elastic.co/t/es-ql-query-all-types-of-logs/377086 "2025-04-16T04:33:34Z")

</div>

Hello- I hope this is the right channel for my ES|QL question. I've setup a centralized log server with 3 IPs sending their logs to that server. I've installed an agent, but now can't figure out the right query to list e…

---

## [Challenges with parsing AWS EKS Logs - Custom Cloudwatch Integration](https://discuss.elastic.co/t/challenges-with-parsing-aws-eks-logs-custom-cloudwatch-integration/374964)

<div class="topic-metadata">

**Author:** [@BKgingersnap](https://discuss.elastic.co/u/BKgingersnap)\
**Replies:** 7\
**Last updated:** [March 13, 2025, 3:06pm UTC](https://discuss.elastic.co/t/challenges-with-parsing-aws-eks-logs-custom-cloudwatch-integration/374964 "2025-03-13T15:06:43Z")

</div>

I'm working on parsing AWS EKS logs that are ingested into Elastic via custom Cloud watch integration + filebeat. The problem though is that right now, the entire Kubernetes audit log is captured in the message field and…

---

## [Clarification on log format used by Elastic's NGINX Integration](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 4\
**Last updated:** [February 18, 2025, 11:42am UTC](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586 "2025-02-18T11:42:44Z")

</div>

Hi, I'm currently utilizing Elastic's NGINX integration to collect and analyze my server logs. Could someone clarify which log format this integration expects by default? Is it compatible with NGINX's default "combined"…

---

## [Preferred way to set the 'final\_pipeline' back to '\_none' for all indices](https://discuss.elastic.co/t/preferred-way-to-set-the-final-pipeline-back-to-none-for-all-indices/374450)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 2\
**Last updated:** [February 13, 2025, 1:44pm UTC](https://discuss.elastic.co/t/preferred-way-to-set-the-final-pipeline-back-to-none-for-all-indices/374450 "2025-02-13T13:44:15Z")

</div>

Hello, Elastic! As the title implies, I was wondering if there's a preferred way to set the 'final\_pipeline' back to '\_none' for all indices. Originally, I set the final pipeline to point at an Ingest Pipeline that use…

---

## [ECS ingest pipeline parsing & help of AI?](https://discuss.elastic.co/t/ecs-ingest-pipeline-parsing-help-of-ai/373974)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [February 2, 2025, 12:24pm UTC](https://discuss.elastic.co/t/ecs-ingest-pipeline-parsing-help-of-ai/373974 "2025-02-02T12:24:19Z")

</div>

Hi there, I have to do some ingest pipeline parsing for cisco proxy syslog logs sent over udp and want to use the ECS standard. Does someone of the staff or the community know, if there is an AI that can help me in that…

---

## [Automatic traces from tracing doesn't match with MDC traces](https://discuss.elastic.co/t/automatic-traces-from-tracing-doesnt-match-with-mdc-traces/373776)

<div class="topic-metadata">

**Author:** [@FranM](https://discuss.elastic.co/u/FranM)\
**Replies:** 1\
**Last updated:** [January 29, 2025, 2:41pm UTC](https://discuss.elastic.co/t/automatic-traces-from-tracing-doesnt-match-with-mdc-traces/373776 "2025-01-29T14:41:26Z")

</div>

Good Morning, I am using ecs structured logging (logging.structured.format.console=ecs) and io.micrometer:micrometer-tracing-bridge-brave with a Spring boot 3.4.2 . My trace from trace.id is coming from MDC and traceId …

---

## [Valid values for service.state](https://discuss.elastic.co/t/valid-values-for-service-state/373766)

<div class="topic-metadata">

**Author:** [@kelunik](https://discuss.elastic.co/u/kelunik)\
**Replies:** 1\
**Last updated:** [January 28, 2025, 5:07pm UTC](https://discuss.elastic.co/t/valid-values-for-service-state/373766 "2025-01-28T17:07:16Z")

</div>

I have (long-running) processes that have a starting, running and shutdown phase. I want to filter logs to only show the running phase. I looked at ECS and found service.state as a field that might be suitable, however, …

---

## [Logging fields with type long using logback-ecs-encoder](https://discuss.elastic.co/t/logging-fields-with-type-long-using-logback-ecs-encoder/372031)

<div class="topic-metadata">

**Author:** [@softarn](https://discuss.elastic.co/u/softarn)\
**Replies:** 1\
**Last updated:** [December 18, 2024, 1:20pm UTC](https://discuss.elastic.co/t/logging-fields-with-type-long-using-logback-ecs-encoder/372031 "2024-12-18T13:20:39Z")

</div>

I'm adding request/response logging to my Spring Boot application and I want to add, for example, the field http.request.body.bytes which is of type long. Currently we are adding the values we want to in MDC, logging an…

---

## [Elastic Serverless Forwarder Cannot Connect to my Elastic Cloud Deployment](https://discuss.elastic.co/t/elastic-serverless-forwarder-cannot-connect-to-my-elastic-cloud-deployment/371959)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 3\
**Last updated:** [December 13, 2024, 3:41pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-cannot-connect-to-my-elastic-cloud-deployment/371959 "2024-12-13T15:41:06Z")

</div>

Hello, I'm having trouble sending CloudWatch logs to Elastic Cloud via Elastic Serverless Forwarder (ESF). I've configured my config.yml per the official elastic documentation. I also enabled the DEBUG logs to add verbo…

---

## [Elastic Serverless Forwarder Field Extraction Issue](https://discuss.elastic.co/t/elastic-serverless-forwarder-field-extraction-issue/371779)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 3\
**Last updated:** [December 11, 2024, 3:20am UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-field-extraction-issue/371779 "2024-12-11T03:20:05Z")

</div>

Hello, I'm currently ingesting CloudWatch logs via Kinesis \> Elastic Serverless Forwarder, but I'm having issues with injecting existing "root" fields after expanding events from JSON object lists. I've attached my conf…

---

## [ECK deploy es cluster，slowlog cannot write to file](https://discuss.elastic.co/t/eck-deploy-es-cluster-slowlog-cannot-write-to-file/369412)

<div class="topic-metadata">

**Author:** [@goodboyryan008](https://discuss.elastic.co/u/goodboyryan008)\
**Replies:** 1\
**Last updated:** [December 2, 2024, 7:24am UTC](https://discuss.elastic.co/t/eck-deploy-es-cluster-slowlog-cannot-write-to-file/369412 "2024-12-02T07:24:04Z")

</div>

I deploy 7.10.1 ES cluster with ECK mode，when set slowlog but found the log not appear, then I found in log4j2.properties appender.index\_search\_slowlog\_rolling.type = Console appender.index\_search\_slowlog\_rolling.name…

---

## [Issue while parsing the kubernetes container logs message to individual fields to root document](https://discuss.elastic.co/t/issue-while-parsing-the-kubernetes-container-logs-message-to-individual-fields-to-root-document/371009)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 1\
**Last updated:** [November 26, 2024, 4:29pm UTC](https://discuss.elastic.co/t/issue-while-parsing-the-kubernetes-container-logs-message-to-individual-fields-to-root-document/371009 "2024-11-26T16:29:07Z")

</div>

Sir, below is the message field for the kubernetes container log. {"level":"info","service":"go-treasury","request-id":"1b24ca3b-3ae6-43e6-8700-d7009ca38662","time":"2024-11-25T13:52:38+05:30","caller":"/app/handler/ro…

---

## [How to structure logging to get the most out of built in ML](https://discuss.elastic.co/t/how-to-structure-logging-to-get-the-most-out-of-built-in-ml/370009)

<div class="topic-metadata">

**Author:** [@flalar](https://discuss.elastic.co/u/flalar)\
**Replies:** 0\
**Last updated:** [November 4, 2024, 1:13pm UTC](https://discuss.elastic.co/t/how-to-structure-logging-to-get-the-most-out-of-built-in-ml/370009 "2024-11-04T13:13:36Z")

</div>

We’re looking for best practices for structuring our application log streams to utilize the built in ML capacities in Observabilty. Today we log everything from 30 different services with Serilog to the same datastream i…

---

## [Log Categorization in Dashboard?](https://discuss.elastic.co/t/log-categorization-in-dashboard/368063)

<div class="topic-metadata">

**Author:** [@Overl0rd](https://discuss.elastic.co/u/Overl0rd)\
**Replies:** 1\
**Last updated:** [October 3, 2024, 12:23pm UTC](https://discuss.elastic.co/t/log-categorization-in-dashboard/368063 "2024-10-03T12:23:34Z")

</div>

Hi, we are working with Log Categorziation and we were hoping there to be a way to get the Log Categorization interface on a dashboard. Is this a possibility? Best regards, Guido

---

## [Filebeat: \`Active: active (exiting) is coming code=exited status=1](https://discuss.elastic.co/t/filebeat-active-active-exiting-is-coming-code-exited-status-1/366809)

<div class="topic-metadata">

**Author:** [@BINDUN26](https://discuss.elastic.co/u/BINDUN26)\
**Replies:** 4\
**Last updated:** [September 25, 2024, 9:28am UTC](https://discuss.elastic.co/t/filebeat-active-active-exiting-is-coming-code-exited-status-1/366809 "2024-09-25T09:28:33Z")

</div>

filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; vendor preset: enabled) Drop-In: /etc/systemd/system/filebeat.service…

---

## [Trace id and span id is not getting appeneded to the logs when using elastic apm Java agent](https://discuss.elastic.co/t/trace-id-and-span-id-is-not-getting-appeneded-to-the-logs-when-using-elastic-apm-java-agent/366727)

<div class="topic-metadata">

**Author:** [@apurva12](https://discuss.elastic.co/u/apurva12)\
**Replies:** 4\
**Last updated:** [September 23, 2024, 10:32am UTC](https://discuss.elastic.co/t/trace-id-and-span-id-is-not-getting-appeneded-to-the-logs-when-using-elastic-apm-java-agent/366727 "2024-09-23T10:32:04Z")

</div>

We have springboot application which uses micrometer tracing bridge otel library to get traces and span. This is working as expected with plain springboot application. When adding elastic apm Java agent trace id, span id…

---

## [Duplicated Document Not Updating using Fingerprint In Ingest Pipeline](https://discuss.elastic.co/t/duplicated-document-not-updating-using-fingerprint-in-ingest-pipeline/366478)

<div class="topic-metadata">

**Author:** [@Sohaib\_Khan](https://discuss.elastic.co/u/Sohaib_Khan)\
**Replies:** 0\
**Last updated:** [September 12, 2024, 1:20pm UTC](https://discuss.elastic.co/t/duplicated-document-not-updating-using-fingerprint-in-ingest-pipeline/366478 "2024-09-12T13:20:38Z")

</div>

Hi, I am using filebeat to fetch logs into Elasticsearch. I am using ingest pipeline. I am trying to update duplicated document using fingerprint but it is not working. Thanks.

---

## [Create and alert based on a GROUP BY](https://discuss.elastic.co/t/create-and-alert-based-on-a-group-by/360706)

<div class="topic-metadata">

**Author:** [@Matteo\_Mariotti](https://discuss.elastic.co/u/Matteo_Mariotti)\
**Replies:** 9\
**Last updated:** [September 11, 2024, 8:39pm UTC](https://discuss.elastic.co/t/create-and-alert-based-on-a-group-by/360706 "2024-09-11T20:39:51Z")

</div>

Hi Community, I have a system that logs a JSON object containing a user\_id field into a document, and I need to create an alert that notifies me if a user makes more than a certain number of accesses within a certain ti…

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=1)
