# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=2

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 3

---

## [Kibana logs are not getting triggered to Opsgenie](https://discuss.elastic.co/t/kibana-logs-are-not-getting-triggered-to-opsgenie/337413)

<div class="topic-metadata">

**Author:** [@Shyam\_Kumar](https://discuss.elastic.co/u/Shyam_Kumar)\
**Replies:** 1\
**Last updated:** [July 3, 2023, 4:46am UTC](https://discuss.elastic.co/t/kibana-logs-are-not-getting-triggered-to-opsgenie/337413 "2023-07-03T04:46:40Z")

</div>

The alert rule in Kibana is satisfying and giving 2 documents. But, the alert is not triggering to Opsgenie. The integration was done perfectly. Previously for the other alert rule which is same, the alert got trigge…

---

## [Cant' find an example of how Elastic.Serilog.Sinks works with json configuration file](https://discuss.elastic.co/t/cant-find-an-example-of-how-elastic-serilog-sinks-works-with-json-configuration-file/337078)

<div class="topic-metadata">

**Author:** [@pantonis](https://discuss.elastic.co/u/pantonis)\
**Replies:** 0\
**Last updated:** [June 28, 2023, 12:27pm UTC](https://discuss.elastic.co/t/cant-find-an-example-of-how-elastic-serilog-sinks-works-with-json-configuration-file/337078 "2023-06-28T12:27:48Z")

</div>

I cannot find an example of how Elastic.Serilog.Sinks works with a json configuration file. It seems that serilog json configuration file does not work with this library. any example of how a json file looks like would…

---

## [Unable to see the spring boot application logs in ElasticCloud APM ](https://discuss.elastic.co/t/unable-to-see-the-spring-boot-application-logs-in-elasticcloud-apm/334473)

<div class="topic-metadata">

**Author:** [@ramakrr77](https://discuss.elastic.co/u/ramakrr77)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 9:26am UTC](https://discuss.elastic.co/t/unable-to-see-the-spring-boot-application-logs-in-elasticcloud-apm/334473 "2023-06-02T09:26:56Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Logs of java APM agent in the Host](https://discuss.elastic.co/t/logs-of-java-apm-agent-in-the-host/334403)

<div class="topic-metadata">

**Author:** [@Anand\_Hitachi](https://discuss.elastic.co/u/Anand_Hitachi)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 8:36am UTC](https://discuss.elastic.co/t/logs-of-java-apm-agent-in-the-host/334403 "2023-05-26T08:36:16Z")

</div>

I'm not getting the logs of java APM agent which is running on Linux host. It looks like agent is connected to the apm server as , We are able to see some metrics and details in kibana UI but couldn't see the agent logs. …

---

## [I am not getting the latest logs for few services in kibana dashboard](https://discuss.elastic.co/t/i-am-not-getting-the-latest-logs-for-few-services-in-kibana-dashboard/333440)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 10:49am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-latest-logs-for-few-services-in-kibana-dashboard/333440 "2023-05-15T10:49:59Z")

</div>

In discover panel, I am not getting latest logs for few services and getting latest logs for few services. Filebeat service is up and running Please help on this

---

## [Duration time between logs](https://discuss.elastic.co/t/duration-time-between-logs/329757)

<div class="topic-metadata">

**Author:** [@justme123](https://discuss.elastic.co/u/justme123)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:54am UTC](https://discuss.elastic.co/t/duration-time-between-logs/329757 "2023-04-12T05:54:21Z")

</div>

Hi Everyone ! I'm new to elastic and kibana and I have some troubles with duration time between log event. I have 2 logs that i get via SNMP Trap : referenceNumber : 123456 alarmType: 2 @timestamp : 2023-04-11T09:…

---

## [Options for log collection from client applications](https://discuss.elastic.co/t/options-for-log-collection-from-client-applications/328288)

<div class="topic-metadata">

**Author:** [@malliaridis](https://discuss.elastic.co/u/malliaridis)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:10pm UTC](https://discuss.elastic.co/t/options-for-log-collection-from-client-applications/328288 "2023-03-23T20:10:14Z")

</div>

tl;dr If I have generated logs on mobile applications / mobile devices and desktop PCs (owned by users) and stored them in files or embedded databases, what options are available and recommended to collect these logs in…

---

## [Logs definition](https://discuss.elastic.co/t/logs-definition/327211)

<div class="topic-metadata">

**Author:** [@Stefan7](https://discuss.elastic.co/u/Stefan7)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 8:01pm UTC](https://discuss.elastic.co/t/logs-definition/327211 "2023-03-07T20:01:45Z")

</div>

Greetings, Can someone please direct me to a location where I can find a definition of logs? Here's a preliminary list that I am trying to clarify: 'logs-elastic\_agent' 'metrics-elastic\_agent.elastic\_agent ' 'logs-e…

---

## [Container logs are not injesting properly to elastic fleet agents](https://discuss.elastic.co/t/container-logs-are-not-injesting-properly-to-elastic-fleet-agents/321547)

<div class="topic-metadata">

**Author:** [@krishnaabylle](https://discuss.elastic.co/u/krishnaabylle)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 4:08pm UTC](https://discuss.elastic.co/t/container-logs-are-not-injesting-properly-to-elastic-fleet-agents/321547 "2023-02-13T16:08:40Z")

</div>

HI, As we rolled out our elastic agents in new clusters through fleets, all logs are coming to Metrics-\* and Logs-\* from Kubernetes containers. As per documentation all the logs should come to Logs-\* and Metrics-\*. We …

---

## [GROK pattern](https://discuss.elastic.co/t/grok-pattern/322443)

<div class="topic-metadata">

**Author:** [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Replies:** 9\
**Last updated:** [January 13, 2023, 11:39am UTC](https://discuss.elastic.co/t/grok-pattern/322443 "2023-01-13T11:39:49Z")

</div>

Hello, I have trouble with writing GROK pattern for system logs. My goal is to parse logs in form "systemctl -o verbose" which looks like this Wed 2022-10-12 09:08:42.759756 \_TRANSPORT=kernel SYSLOG\_IDENTIFIER=…

---

## [Looking to create multiple schedule for a Logstash input plugin](https://discuss.elastic.co/t/looking-to-create-multiple-schedule-for-a-logstash-input-plugin/321806)

<div class="topic-metadata">

**Author:** [@Iseyin](https://discuss.elastic.co/u/Iseyin)\
**Replies:** 0\
**Last updated:** [December 22, 2022, 4:17am UTC](https://discuss.elastic.co/t/looking-to-create-multiple-schedule-for-a-logstash-input-plugin/321806 "2022-12-22T04:17:25Z")

</div>

Hello, I'm looking to create multiple schedule for an input plugin in logstash. Is there a way to do this currently is there a workaround? The schedule parameter is of string type, so it would not accept and array of s…

---

## [Container logs not ingesting properly to elastic fleet agents](https://discuss.elastic.co/t/container-logs-not-ingesting-properly-to-elastic-fleet-agents/321377)

<div class="topic-metadata">

**Author:** [@krishnaabylle](https://discuss.elastic.co/u/krishnaabylle)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 6:54am UTC](https://discuss.elastic.co/t/container-logs-not-ingesting-properly-to-elastic-fleet-agents/321377 "2022-12-16T06:54:40Z")

</div>

Hi, As we rolled out our elastic agents in new clusters through fleets, all logs are coming to Metrics-\* and Logs-\* from Kubernetes containers. As per documentation all the logs should come to Logs-\* and Metrics-\*. We …

---

## [Cant parse logs with - in bytes field](https://discuss.elastic.co/t/cant-parse-logs-with-in-bytes-field/321281)

<div class="topic-metadata">

**Author:** [@bill210kouk](https://discuss.elastic.co/u/bill210kouk)\
**Replies:** 4\
**Last updated:** [December 15, 2022, 1:43pm UTC](https://discuss.elastic.co/t/cant-parse-logs-with-in-bytes-field/321281 "2022-12-15T13:43:30Z")

</div>

Hello! I facing an issue with my grok format pattern even though i managed to change the type of the bytes log field to numbers (this type will be used for better Kibana visualizations) some of logs have the bytes field…

---

## [Can I create Alert considering field value of the index?](https://discuss.elastic.co/t/can-i-create-alert-considering-field-value-of-the-index/320794)

<div class="topic-metadata">

**Author:** [@Vijaykumar\_Deshmukh1](https://discuss.elastic.co/u/Vijaykumar_Deshmukh1)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 5:51am UTC](https://discuss.elastic.co/t/can-i-create-alert-considering-field-value-of-the-index/320794 "2022-12-09T05:51:37Z")

</div>

Hello Here, simple situation here is i have one index named hat Mapping is herePUT hat { "mappings": { "properties": { "@timestamp": { "type": "date" }, "jay": { "type": "intege…

---

## [Elastalert is not triggering the email notifications](https://discuss.elastic.co/t/elastalert-is-not-triggering-the-email-notifications/320735)

<div class="topic-metadata">

**Author:** [@vikash\_bugata](https://discuss.elastic.co/u/vikash_bugata)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 6:17am UTC](https://discuss.elastic.co/t/elastalert-is-not-triggering-the-email-notifications/320735 "2022-12-08T06:17:14Z")

</div>

I have defined the rules under the rules folder but my rules were not triggering email alerts even the matching expression is found on the logs. I am running the elastalert on the Linux OS and our elasticsearch version …

---

## [Connect Render.com Log Stream to Elastic Cloud](https://discuss.elastic.co/t/connect-render-com-log-stream-to-elastic-cloud/319704)

<div class="topic-metadata">

**Author:** [@Mike\_Cann](https://discuss.elastic.co/u/Mike_Cann)\
**Replies:** 5\
**Last updated:** [December 1, 2022, 11:59pm UTC](https://discuss.elastic.co/t/connect-render-com-log-stream-to-elastic-cloud/319704 "2022-12-01T23:59:26Z")

</div>

Hi I would like to push my logs from Render.com so that they are viewable / tailable etc in Elastic Cloud. Render.com sends to a syslog drain (Log Streams | Render · Cloud Hosting for Developers) in a standard (RFC5424)…

---

## [Filebeat logs not sent on a server for which chocolatey installed](https://discuss.elastic.co/t/filebeat-logs-not-sent-on-a-server-for-which-chocolatey-installed/318569)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 11:43am UTC](https://discuss.elastic.co/t/filebeat-logs-not-sent-on-a-server-for-which-chocolatey-installed/318569 "2022-11-29T11:43:55Z")

</div>

Hi , We are configuring a server whith filebeat agent to send costum logs , however no logs are received on Kibana . Just to mention that the server for which we don't receive logs , we have chocolatey installed but it …

---

## [Fleet Managed Elastic Agent - add parameter to filebeat.yml](https://discuss.elastic.co/t/fleet-managed-elastic-agent-add-parameter-to-filebeat-yml/317521)

<div class="topic-metadata">

**Author:** [@lnx](https://discuss.elastic.co/u/lnx)\
**Replies:** 3\
**Last updated:** [November 12, 2022, 7:31pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-add-parameter-to-filebeat-yml/317521 "2022-11-12T19:31:12Z")

</div>

I need to set the scan\_frequency config parameter for the Filebeat subprocess of Elastic Agent running on Windows managed by Fleet. I'm using the IIS integration. I would like to try to reduce CPU usage. How do I do th…

---

## [How to ingest a log file from source system to Kibana through Filebeat](https://discuss.elastic.co/t/how-to-ingest-a-log-file-from-source-system-to-kibana-through-filebeat/315544)

<div class="topic-metadata">

**Author:** [@cadrija](https://discuss.elastic.co/u/cadrija)\
**Replies:** 15\
**Last updated:** [November 10, 2022, 5:50am UTC](https://discuss.elastic.co/t/how-to-ingest-a-log-file-from-source-system-to-kibana-through-filebeat/315544 "2022-11-10T05:50:26Z")

</div>

Hi experts! I am new to elastic. I have installed ELK (7.17.6) on a Ubuntu system (suppose u.u.u.u). Now I am trying to fetch/ingest a log file from a windows system (suppose w.w.w.w). Steps I followed leaning from tut…

---

## [Every log line sent to ES create new index](https://discuss.elastic.co/t/every-log-line-sent-to-es-create-new-index/318340)

<div class="topic-metadata">

**Author:** [@florind](https://discuss.elastic.co/u/florind)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 2:59pm UTC](https://discuss.elastic.co/t/every-log-line-sent-to-es-create-new-index/318340 "2022-11-07T14:59:58Z")

</div>

Hello, I'm using fluentd to send pod logs to ES 8.5 My problem is that each log sent is creating a new index, so i end up having a very large number of indices. What I'd like to have is one index per day, and keep the…

---

## [While ingesting a log file from source system to Kibana through Filebeat, getting "End Of File reached" message in Filebeat logs](https://discuss.elastic.co/t/while-ingesting-a-log-file-from-source-system-to-kibana-through-filebeat-getting-end-of-file-reached-message-in-filebeat-logs/317777)

<div class="topic-metadata">

**Author:** [@cadrija](https://discuss.elastic.co/u/cadrija)\
**Replies:** 0\
**Last updated:** [October 31, 2022, 5:55am UTC](https://discuss.elastic.co/t/while-ingesting-a-log-file-from-source-system-to-kibana-through-filebeat-getting-end-of-file-reached-message-in-filebeat-logs/317777 "2022-10-31T05:55:37Z")

</div>

Hi experts! I am new to elastic. I have installed ELK (8.4) on a Ubuntu system (suppose u.u.u.u). Now I am trying to fetch/ingest a log file from a windows system (suppose w.w.w.w). Steps I followed leaning from tutori…

---

## [Azure Vnet / NSG Flow Logs](https://discuss.elastic.co/t/azure-vnet-nsg-flow-logs/315957)

<div class="topic-metadata">

**Author:** [@Chandrapaul](https://discuss.elastic.co/u/Chandrapaul)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 12:21pm UTC](https://discuss.elastic.co/t/azure-vnet-nsg-flow-logs/315957 "2022-10-06T12:21:45Z")

</div>

How to ingest Azure VNet / NSG flow logs into elasticsearch ?

---

## [Visualizing aggregated logs](https://discuss.elastic.co/t/visualizing-aggregated-logs/314966)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 4\
**Last updated:** [September 30, 2022, 12:09pm UTC](https://discuss.elastic.co/t/visualizing-aggregated-logs/314966 "2022-09-30T12:09:00Z")

</div>

Anyone aggregating duplicate log messages? That is, are you counting up identical messages in your logging library or in Logstash, then emitting a single message saying (original message) ... This message was repeate…

---

## [Dealing with log messages about source \_and\_ target](https://discuss.elastic.co/t/dealing-with-log-messages-about-source-and-target/313895)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 6\
**Last updated:** [September 21, 2022, 4:26am UTC](https://discuss.elastic.co/t/dealing-with-log-messages-about-source-and-target/313895 "2022-09-21T04:26:31Z")

</div>

Okay, so… We’ve got a field that could be used to indicate whether a whole message is related to client or server activity, whether communication is inbound or outbound: network.direction But in some situations we’re l…

---

## [Aggregation in Ingest Pipeline of Elastic Agent - Custom Logs integration](https://discuss.elastic.co/t/aggregation-in-ingest-pipeline-of-elastic-agent-custom-logs-integration/313910)

<div class="topic-metadata">

**Author:** [@rowra](https://discuss.elastic.co/u/rowra)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 4:56pm UTC](https://discuss.elastic.co/t/aggregation-in-ingest-pipeline-of-elastic-agent-custom-logs-integration/313910 "2022-09-07T16:56:29Z")

</div>

Hey, Currently I have a Logstash pipeline parsing, aggregating and finally delivering Postfix logs to the Elasticsearch. I want to retire Logstash completely and use Fleet to deploy a policy with Custom Logs integration…

---

## [Multiple Nested JSON Formats parsing with Logstash](https://discuss.elastic.co/t/multiple-nested-json-formats-parsing-with-logstash/313414)

<div class="topic-metadata">

**Author:** [@Prateek\_Kumar\_Saini](https://discuss.elastic.co/u/Prateek_Kumar_Saini)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 6:59am UTC](https://discuss.elastic.co/t/multiple-nested-json-formats-parsing-with-logstash/313414 "2022-09-01T06:59:14Z")

</div>

Hello everyone, I am trying to ingest multiple logs into my logstash. The input type is a JSON (Nested Jsons), but the formats are varying. For example, JSON 1) 1|2|3|4|{"event-ts":"07-07-2022 17:42:55.294","event-na…

---

## [Duplicate log on message field with springboot java](https://discuss.elastic.co/t/duplicate-log-on-message-field-with-springboot-java/312941)

<div class="topic-metadata">

**Author:** [@jluisv98](https://discuss.elastic.co/u/jluisv98)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 3:26pm UTC](https://discuss.elastic.co/t/duplicate-log-on-message-field-with-springboot-java/312941 "2022-08-25T15:26:35Z")

</div>

I'm new to the ELK stack, I'm trying to send the logs of a web application in springboot to logstash. This is the stream log I send: {"@timestamp":"2022-08-24T17:25:09.346-05:00","@version":"1"," message":"Starting \*\*\*…

---

## [How can I get CloudWatchLogs to Elastic as JSON?](https://discuss.elastic.co/t/how-can-i-get-cloudwatchlogs-to-elastic-as-json/312101)

<div class="topic-metadata">

**Author:** [@DanielInacio](https://discuss.elastic.co/u/DanielInacio)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 7:08am UTC](https://discuss.elastic.co/t/how-can-i-get-cloudwatchlogs-to-elastic-as-json/312101 "2022-08-22T07:08:18Z")

</div>

Hi everyone Basically, I have a CloudFormation Stack in AWS, which currently uses the AWS Lambda ElasticForwarder to POST CloudFormation logs into an Elasticsearch stream. The messages are JSON dictionaries but they ar…

---

## [Timestamp is not correct](https://discuss.elastic.co/t/timestamp-is-not-correct/310278)

<div class="topic-metadata">

**Author:** [@BaseSL](https://discuss.elastic.co/u/BaseSL)\
**Replies:** 4\
**Last updated:** [August 22, 2022, 5:32am UTC](https://discuss.elastic.co/t/timestamp-is-not-correct/310278 "2022-08-22T05:32:53Z")

</div>

I have the problem that the time does not match the one in the log file. What can I do about it ? It only occurs with this log file (filebeat). On another system, where Logstash is running, this does not occur. Unfo…

---

## [Log4j2-ecs-layout serialize MDC](https://discuss.elastic.co/t/log4j2-ecs-layout-serialize-mdc/311623)

<div class="topic-metadata">

**Author:** [@tbglazer](https://discuss.elastic.co/u/tbglazer)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 5:28am UTC](https://discuss.elastic.co/t/log4j2-ecs-layout-serialize-mdc/311623 "2022-08-22T05:28:44Z")

</div>

Is there any option not to serialize MDC fields by default ? I am using additional fields to serialize under different name like \<KeyValuePair name="labels.X" value="%X(Y)" and as result I get two fields labels.X=value …

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md?page=1)

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=3)
