# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=1

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 2

---

## [Elasticsearch version 7.17 - reindex with important nested documents](https://discuss.elastic.co/t/elasticsearch-version-7-17-reindex-with-important-nested-documents/366301)

<div class="topic-metadata">

**Author:** [@Ulyss](https://discuss.elastic.co/u/Ulyss)\
**Replies:** 1\
**Last updated:** [September 10, 2024, 12:25pm UTC](https://discuss.elastic.co/t/elasticsearch-version-7-17-reindex-with-important-nested-documents/366301 "2024-09-10T12:25:11Z")

</div>

The aim is to reindex an index (from a backup of an ES6.8 version) with important nested documents. The max\_result\_window parameter was increased, but without success. I still get the error: The number of nested docum…

---

## [Spotting Anamolies from Log Data](https://discuss.elastic.co/t/spotting-anamolies-from-log-data/363727)

<div class="topic-metadata">

**Author:** [@robin2](https://discuss.elastic.co/u/robin2)\
**Replies:** 16\
**Last updated:** [August 12, 2024, 9:13am UTC](https://discuss.elastic.co/t/spotting-anamolies-from-log-data/363727 "2024-08-12T09:13:59Z")

</div>

I have the Elk framework setup on my local system with Kibana running on my localhost. I am able to view the logs on Kibana dashboard with the time range. Then I activated a trial license for a month to use the Machine L…

---

## [Handling multiline that spans log files](https://discuss.elastic.co/t/handling-multiline-that-spans-log-files/363603)

<div class="topic-metadata">

**Author:** [@kelvins](https://discuss.elastic.co/u/kelvins)\
**Replies:** 0\
**Last updated:** [July 23, 2024, 5:40am UTC](https://discuss.elastic.co/t/handling-multiline-that-spans-log-files/363603 "2024-07-23T05:40:13Z")

</div>

So, I have an issue with JDE logs. They rotate whenever the log file gets to ~5 Megabytes. The issue that I am having, is that I am using multiline to gather the log files. What is happening however, is that the multi…

---

## [How elastic stack monitoring \> node \> advanced request rate works](https://discuss.elastic.co/t/how-elastic-stack-monitoring-node-advanced-request-rate-works/361282)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 2\
**Last updated:** [June 13, 2024, 5:03pm UTC](https://discuss.elastic.co/t/how-elastic-stack-monitoring-node-advanced-request-rate-works/361282 "2024-06-13T17:03:42Z")

</div>

I have tried to test the load with JMeter using the following configuration: Thread Group: Threads (users): 100 Ramp-up time: 1 second Loop: Infinity Duration: 300 seconds Additionally, I have added to that Prec…

---

## [Kibana - Resize columns on tail logs](https://discuss.elastic.co/t/kibana-resize-columns-on-tail-logs/358853)

<div class="topic-metadata">

**Author:** [@Raul\_Valdoleiros](https://discuss.elastic.co/u/Raul_Valdoleiros)\
**Replies:** 3\
**Last updated:** [May 31, 2024, 11:47am UTC](https://discuss.elastic.co/t/kibana-resize-columns-on-tail-logs/358853 "2024-05-31T11:47:21Z")

</div>

How to resize columns using kibana tail log? It is a basic crucial feature but I can't find a way to do it. Thanks.

---

## [Analyzing log files in a static directory](https://discuss.elastic.co/t/analyzing-log-files-in-a-static-directory/360071)

<div class="topic-metadata">

**Author:** [@Muhammad\_Adil\_Talay](https://discuss.elastic.co/u/Muhammad_Adil_Talay)\
**Replies:** 1\
**Last updated:** [May 23, 2024, 11:42am UTC](https://discuss.elastic.co/t/analyzing-log-files-in-a-static-directory/360071 "2024-05-23T11:42:50Z")

</div>

Introduction Hi, I'm a newbie to Elastic stack, training in the area of Observability. Background I have log files of an application saved in a folder or directory of my computer, not connected to the app. Goal I wo…

---

## [Filebeat 7.6.2 runtime/cgo: pthread\_create failed: Operation not permitted](https://discuss.elastic.co/t/filebeat-7-6-2-runtime-cgo-pthread-create-failed-operation-not-permitted/359223)

<div class="topic-metadata">

**Author:** [@poo0054](https://discuss.elastic.co/u/poo0054)\
**Replies:** 7\
**Last updated:** [May 10, 2024, 5:51am UTC](https://discuss.elastic.co/t/filebeat-7-6-2-runtime-cgo-pthread-create-failed-operation-not-permitted/359223 "2024-05-10T05:51:42Z")

</div>

5月 10 10:12:30 localhost.localdomain filebeat\[6049\]: /usr/local/go/src/internal/poll/fd\_poll\_runtime.go:96 5月 10 10:12:30 localhost.localdomain filebeat\[6049\]: internal/poll.(\*FD).WaitWrite(...) 5月 10 10:12:30 lo…

---

## [Notify if Index Has 0 Logs in X Minutes](https://discuss.elastic.co/t/notify-if-index-has-0-logs-in-x-minutes/357181)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 1\
**Last updated:** [April 29, 2024, 9:10pm UTC](https://discuss.elastic.co/t/notify-if-index-has-0-logs-in-x-minutes/357181 "2024-04-29T21:10:57Z")

</div>

We have many indexes, and are consistently adding more to our cluster. We need to know when an index doesn't receive any documents in X number of minutes. For instance, if logs-foo hasn't received any documents in 1 hour…

---

## [Log Threshold - Alert Body](https://discuss.elastic.co/t/log-threshold-alert-body/350979)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 32\
**Last updated:** [February 27, 2024, 7:04pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979 "2024-02-27T19:04:19Z")

</div>

Hello, As referenced here: Action variables for a Logs threshold rule I created a log threshold rule. I would like to do is use variables/fields from the documents/logs to appear in the email body. Like how it was men…

---

## [Logstash upgrade issue](https://discuss.elastic.co/t/logstash-upgrade-issue/353154)

<div class="topic-metadata">

**Author:** [@mansoorpn](https://discuss.elastic.co/u/mansoorpn)\
**Replies:** 6\
**Last updated:** [February 14, 2024, 8:33am UTC](https://discuss.elastic.co/t/logstash-upgrade-issue/353154 "2024-02-14T08:33:00Z")

</div>

Hello Team, We have an IOT device and the logs generated from this device are received by a logstash instance as input and sent the same logs to the cloudamqp queue as output. Working condition -- \> Logstash version 6.…

---

## [Unable to create component template updating component template results in invalid composable template after templates are merged](https://discuss.elastic.co/t/unable-to-create-component-template-updating-component-template-results-in-invalid-composable-template-after-templates-are-merged/352271)

<div class="topic-metadata">

**Author:** [@florinsfetea](https://discuss.elastic.co/u/florinsfetea)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 8:32am UTC](https://discuss.elastic.co/t/unable-to-create-component-template-updating-component-template-results-in-invalid-composable-template-after-templates-are-merged/352271 "2024-02-02T08:32:58Z")

</div>

On 8.12.0 I am hitting this again \` Unable to create component template updating component template \[metrics-mysql.performance@custom\] results in invalid composable template \[metrics-mysql.performance\] after templates…

---

## [ES Query Rule : Ability to show previous value?](https://discuss.elastic.co/t/es-query-rule-ability-to-show-previous-value/351215)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 12:04am UTC](https://discuss.elastic.co/t/es-query-rule-ability-to-show-previous-value/351215 "2024-01-17T00:04:42Z")

</div>

Hello, It's me again. I have a interesting use case for ES Query rule but was wondering if its even possible. I was asked to create an alert and be able to show the a field like {{\_source.status}}. This is possible. N…

---

## [Filebeat not getting logs from kubernetes pods](https://discuss.elastic.co/t/filebeat-not-getting-logs-from-kubernetes-pods/350403)

<div class="topic-metadata">

**Author:** [@gustavo\_luigi\_cev](https://discuss.elastic.co/u/gustavo_luigi_cev)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:58pm UTC](https://discuss.elastic.co/t/filebeat-not-getting-logs-from-kubernetes-pods/350403 "2024-01-05T19:58:17Z")

</div>

Hi! I'm trying to use Filebeat on my aws eks to get my containers logs. filebeat-configmap.yaml apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: elk data: filebeat.yml: |- logging.le…

---

## [Apm for django, filter errors by cusotm field](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762)

<div class="topic-metadata">

**Author:** [@k\_cf](https://discuss.elastic.co/u/k_cf)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 8:03am UTC](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762 "2023-12-21T08:03:12Z")

</div>

I have set up elastic apm for a django project with logging (elasticapm.contrib.django.handlers.LoggingHandler). Upon logging a message as follows: logger.exception( custom\_logging\_message, exc\_info=True, ex…

---

## [ELastic ML jobs](https://discuss.elastic.co/t/elastic-ml-jobs/346217)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:50am UTC](https://discuss.elastic.co/t/elastic-ml-jobs/346217 "2023-11-02T03:50:00Z")

</div>

I've been researching around the different types of ML anamoly detection jobs in Elasticsearch. Would like to get a second opinion as to what might be the best bet for a particular use case am working on: 100's of host…

---

## [Alternative to CLASSPATH for ecs-logging-core.jar and jul-ecs-formatter.jar with Tomcat](https://discuss.elastic.co/t/alternative-to-classpath-for-ecs-logging-core-jar-and-jul-ecs-formatter-jar-with-tomcat/345785)

<div class="topic-metadata">

**Author:** [@AlexanderDyas](https://discuss.elastic.co/u/AlexanderDyas)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 9:00am UTC](https://discuss.elastic.co/t/alternative-to-classpath-for-ecs-logging-core-jar-and-jul-ecs-formatter-jar-with-tomcat/345785 "2023-10-26T09:00:17Z")

</div>

Tomcat 9.0.52 Java openjdk version "1.8.0\_302" Linux As per the suggestion (Get started | ECS Logging Java Reference \[1.x\] | Elastic) I have been successfully using ecs-logging-core.jar and jul-ecs-formatter.jar by ad…

---

## [I receive this error in filebeat can I help me](https://discuss.elastic.co/t/i-receive-this-error-in-filebeat-can-i-help-me/344919)

<div class="topic-metadata">

**Author:** [@alex\_base](https://discuss.elastic.co/u/alex_base)\
**Replies:** 3\
**Last updated:** [October 13, 2023, 9:23am UTC](https://discuss.elastic.co/t/i-receive-this-error-in-filebeat-can-i-help-me/344919 "2023-10-13T09:23:44Z")

</div>

I receive this error in filebeat {"log.level":"error","@timestamp":"2023-10-12T12:30:33.238Z","log.logger":"publisher\_pipeline\_output","log.origin":{"file.name":"pipeline/client\_worker.go","file.line":148},"message":"Fai…

---

## [Parse AWS EC2 logs Error](https://discuss.elastic.co/t/parse-aws-ec2-logs-error/344005)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 6:07pm UTC](https://discuss.elastic.co/t/parse-aws-ec2-logs-error/344005 "2023-09-27T18:07:51Z")

</div>

Hi Engineers, I set up Observability Logs Stream in Kibana for AWS EC2 logs. I have received the aws.ec2\_logs, but Message showed "Fail to find message". When I clicked the "View Details" button, the log contents have b…

---

## [Solution for monitoring](https://discuss.elastic.co/t/solution-for-monitoring/343916)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 9:37am UTC](https://discuss.elastic.co/t/solution-for-monitoring/343916 "2023-09-27T09:37:20Z")

</div>

Hello community I hope you are well. After unpacking the ELK stack I'd like to do some tests to track my local logs and metrics but I don't really know how to go about it. I'm using the latest version of the stack.

---

## [When using log4j AsyncLoggerContextSelector , trace.id and transaction.id is not injected into the MDC context](https://discuss.elastic.co/t/when-using-log4j-asyncloggercontextselector-trace-id-and-transaction-id-is-not-injected-into-the-mdc-context/343796)

<div class="topic-metadata">

**Author:** [@rkg1201](https://discuss.elastic.co/u/rkg1201)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 7:22am UTC](https://discuss.elastic.co/t/when-using-log4j-asyncloggercontextselector-trace-id-and-transaction-id-is-not-injected-into-the-mdc-context/343796 "2023-09-26T07:22:19Z")

</div>

Hi , we are setting -DLog4jContextSelector=org.apache.logging.log4j.core.async.AsyncLoggerContextSelector in our jvm proprties and using elastic agent version 1.42.0 . When using the above mentioned log4j async context…

---

## [Inject more data to MDC, i.e. user.id](https://discuss.elastic.co/t/inject-more-data-to-mdc-i-e-user-id/342465)

<div class="topic-metadata">

**Author:** [@Nadrendion](https://discuss.elastic.co/u/Nadrendion)\
**Replies:** 5\
**Last updated:** [September 22, 2023, 1:30pm UTC](https://discuss.elastic.co/t/inject-more-data-to-mdc-i-e-user-id/342465 "2023-09-22T13:30:02Z")

</div>

Hi, I have a use case where I have a set of microservices deployed. All of them have the Elastic APM agent attached and log correlation is enabled successfully. I can get Logback to log the transaction.id and the other …

---

## [Filebeat to analyze xml logs](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305)

<div class="topic-metadata">

**Author:** [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Replies:** 8\
**Last updated:** [September 6, 2023, 3:53am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305 "2023-09-06T03:53:56Z")

</div>

Hello Its Suman Ghorashine I am new to wazuh and ELK stack. And I wanted to know some certain things. I have a xml log format set to wazuh server for analysis from agent configuration file. But when filtering the logs …

---

## [Elastic to logs management](https://discuss.elastic.co/t/elastic-to-logs-management/341716)

<div class="topic-metadata">

**Author:** [@Flavio\_Alves](https://discuss.elastic.co/u/Flavio_Alves)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 4:44pm UTC](https://discuss.elastic.co/t/elastic-to-logs-management/341716 "2023-08-28T16:44:52Z")

</div>

Hey, guys! I'm new to using elastic What is the best way to build this structure? and what features should i use? at the moment I will only use the stack to centralize the logs

---

## [Rsyslog and syslog-ng direct logging to Elasticsearch, viable replacement for elastic-agent?](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 4:43pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390 "2023-08-22T16:43:26Z")

</div>

rsyslog has a module to send directly to Elasticsearch: syslog-ng also has a module for logging directly to Elasticsearch: https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.22/adminis…

---

## [Using DataDog's vector to ship logs to ElasticSearch instead of elastic-agent?](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 4:29pm UTC](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388 "2023-08-22T16:29:19Z")

</div>

DataDog's vector program has a feature which allows you to ship logs directly to Elasticsearch: This looks like this could be used as an alternative to elastic-agent. Does anyone have any experiences to share on usi…

---

## [Upgrading component template logs-settings failed after update to 8.9](https://discuss.elastic.co/t/upgrading-component-template-logs-settings-failed-after-update-to-8-9/340606)

<div class="topic-metadata">

**Author:** [@jordan](https://discuss.elastic.co/u/jordan)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 4:15am UTC](https://discuss.elastic.co/t/upgrading-component-template-logs-settings-failed-after-update-to-8-9/340606 "2023-08-11T04:15:42Z")

</div>

After updating elasticsearch cloud service from version 8.6 to 8.9.0 I want to share the following issue, that's showing up in logs every 30 minutes: \[instance-0000000005\] upgrading component template \[logs-settings\] fo…

---

## [\[API Logs\] - Pulling Latest Logs to Power BI](https://discuss.elastic.co/t/api-logs-pulling-latest-logs-to-power-bi/339657)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 9:46am UTC](https://discuss.elastic.co/t/api-logs-pulling-latest-logs-to-power-bi/339657 "2023-08-01T09:46:01Z")

</div>

Hi Elastic, I want to ask is there a way we can continuously pulling the Elasticsearch data to Power BI Cloud for dashboard purposes? The team currently using Azure Data Factory to pull the data from our Elastic. Curr…

---

## [Mimecast integration](https://discuss.elastic.co/t/mimecast-integration/339431)

<div class="topic-metadata">

**Author:** [@ElastiRCT](https://discuss.elastic.co/u/ElastiRCT)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 12:24pm UTC](https://discuss.elastic.co/t/mimecast-integration/339431 "2023-07-27T12:24:10Z")

</div>

Hi, I am completely new to Elastic and trying to integrate Mimecast into my cloud deployment to collect logs. I have inserted all of the relevant keys for the API but now I am unsure on what to do next to collect the lo…

---

## [How can i send logs from Elastic to another SIEM?](https://discuss.elastic.co/t/how-can-i-send-logs-from-elastic-to-another-siem/339154)

<div class="topic-metadata">

**Author:** [@Ck1f](https://discuss.elastic.co/u/Ck1f)\
**Replies:** 7\
**Last updated:** [July 26, 2023, 5:39pm UTC](https://discuss.elastic.co/t/how-can-i-send-logs-from-elastic-to-another-siem/339154 "2023-07-26T17:39:54Z")

</div>

Good morning, We have installed elastic-agents throughout our environment with everything setup for filebeat and metricbeat monitoring. And now i'm trying to understand how can i send logs to another SIEM?

---

## [Winlogbeat run as service issues](https://discuss.elastic.co/t/winlogbeat-run-as-service-issues/338029)

<div class="topic-metadata">

**Author:** [@Emorta](https://discuss.elastic.co/u/Emorta)\
**Replies:** 4\
**Last updated:** [July 11, 2023, 10:18am UTC](https://discuss.elastic.co/t/winlogbeat-run-as-service-issues/338029 "2023-07-11T10:18:53Z")

</div>

Hey there, I'm facing a challenge while trying to centralize logging for three servers in Elastic Cloud, and I could really use some help from the community. Here's the issue I'm encountering: When I try to install it …

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md)

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=2)
