# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=3

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 4

---

## [Moving applications logs to Elastic Observability](https://discuss.elastic.co/t/moving-applications-logs-to-elastic-observability/305409)

<div class="topic-metadata">

**Author:** [@michael\_kot](https://discuss.elastic.co/u/michael_kot)\
**Replies:** 15\
**Last updated:** [August 17, 2022, 9:00am UTC](https://discuss.elastic.co/t/moving-applications-logs-to-elastic-observability/305409 "2022-08-17T09:00:13Z")

</div>

Hello, Our team is developing a product - an application for e-commerce. This application has logs that are stored in the file system and displayed in the admin panel of this application. So any admin user can go to th…

---

## [Failed to parse field \[msg.RequestPort\] of type \[long\]](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080)

<div class="topic-metadata">

**Author:** [@ayarosh](https://discuss.elastic.co/u/ayarosh)\
**Replies:** 4\
**Last updated:** [August 15, 2022, 12:14pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080 "2022-08-15T12:14:41Z")

</div>

Filebeat cannot parse and drop the logs when receives the different type of input. "RequestPort":"-" (it usually contains the long type number) Error: {\\"type\\":\\"mapper\_parsing\_exception\\",\\"reason\\":\\"failed to pars…

---

## [Elastic APM log4j2 EcsLayout](https://discuss.elastic.co/t/elastic-apm-log4j2-ecslayout/309649)

<div class="topic-metadata">

**Author:** [@tbglazer](https://discuss.elastic.co/u/tbglazer)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 1:04pm UTC](https://discuss.elastic.co/t/elastic-apm-log4j2-ecslayout/309649 "2022-07-14T13:04:52Z")

</div>

We want to log messages using the EcsLayout in a Java app and when we add a KeyValuePair like where branch is a log4j is a field in \[org\](eclipse-javadoc:%E2%98%82=MatafC the Ecs layout builds incorrectly in the log r…

---

## [Masking ecs logs](https://discuss.elastic.co/t/masking-ecs-logs/309324)

<div class="topic-metadata">

**Author:** [@chiragnighut](https://discuss.elastic.co/u/chiragnighut)\
**Replies:** 0\
**Last updated:** [July 11, 2022, 1:24pm UTC](https://discuss.elastic.co/t/masking-ecs-logs/309324 "2022-07-11T13:24:28Z")

</div>

How do I mask Ecslayout based logs based on regex based logic? I am using log4j2 for logging purposes and the layout I am using is EcsLayout. Consider following JSON object which I would be logging using log4j2 ecslayou…

---

## [I am not getting mutiple Controller log in Kibana Dashboard ? any one have idea about this... Log Override \[Result display last controller log\]](https://discuss.elastic.co/t/i-am-not-getting-mutiple-controller-log-in-kibana-dashboard-any-one-have-idea-about-this-log-override-result-display-last-controller-log/308825)

<div class="topic-metadata">

**Author:** [@jignesh7559](https://discuss.elastic.co/u/jignesh7559)\
**Replies:** 3\
**Last updated:** [July 6, 2022, 1:19am UTC](https://discuss.elastic.co/t/i-am-not-getting-mutiple-controller-log-in-kibana-dashboard-any-one-have-idea-about-this-log-override-result-display-last-controller-log/308825 "2022-07-06T01:19:39Z")

</div>

SecondController public class SecondController : Controller { private readonly ILogger \_logger; public SecondController(ILogger\<SecondController\> logger) { \_logger = logger; \_logger.LogInforma…

---

## [How to put indice index rate by documents and by size on a Dashboard](https://discuss.elastic.co/t/how-to-put-indice-index-rate-by-documents-and-by-size-on-a-dashboard/308694)

<div class="topic-metadata">

**Author:** [@Rodolfo\_Albuquerque](https://discuss.elastic.co/u/Rodolfo_Albuquerque)\
**Replies:** 1\
**Last updated:** [July 4, 2022, 6:47am UTC](https://discuss.elastic.co/t/how-to-put-indice-index-rate-by-documents-and-by-size-on-a-dashboard/308694 "2022-07-04T06:47:05Z")

</div>

Hello folks, I'm trying to create a dashboard with some information about my indices. I see these metrics on Stack Monitoring \> Indices but I would like to put those on a Dashboard. So I see there is an indice .monitor…

---

## [Github package Integration with Elastic](https://discuss.elastic.co/t/github-package-integration-with-elastic/307442)

<div class="topic-metadata">

**Author:** [@LauraSlusher](https://discuss.elastic.co/u/LauraSlusher)\
**Replies:** 1\
**Last updated:** [June 21, 2022, 8:33am UTC](https://discuss.elastic.co/t/github-package-integration-with-elastic/307442 "2022-06-21T08:33:38Z")

</div>

Hello Folks, I want to add The GitHub integration package to collect audit logs and visualize it on Kibana. I already integrated the GitHub workplace search successfully. But I want to visualize more audit data on Kib…

---

## [AWS fleet integration fails with API key error on ingest](https://discuss.elastic.co/t/aws-fleet-integration-fails-with-api-key-error-on-ingest/304846)

<div class="topic-metadata">

**Author:** [@diogof](https://discuss.elastic.co/u/diogof)\
**Replies:** 10\
**Last updated:** [June 8, 2022, 10:42am UTC](https://discuss.elastic.co/t/aws-fleet-integration-fails-with-api-key-error-on-ingest/304846 "2022-06-08T10:42:40Z")

</div>

Hi I'm in the process of trying to set AWS log ingestion into Elastic Cloud via a Fleet elastic cloud managed elastic agent. I followed the instructions on Install Fleet-managed Elastic Agents | Fleet and Elastic Agent …

---

## [Filebeat on raspberry pi 3](https://discuss.elastic.co/t/filebeat-on-raspberry-pi-3/303671)

<div class="topic-metadata">

**Author:** [@Dhia\_Saibi](https://discuss.elastic.co/u/Dhia_Saibi)\
**Replies:** 5\
**Last updated:** [May 24, 2022, 4:59am UTC](https://discuss.elastic.co/t/filebeat-on-raspberry-pi-3/303671 "2022-05-24T04:59:26Z")

</div>

I wanna know if is it possible to install filebeat from elasticstack (I need it to get logs file from an indoor camera) on raspberry pi 3 and if yes does anyone have a tutorial or can teach me the process?

---

## [Log ingestion to Elastic Cloud not working with ECS Fargate](https://discuss.elastic.co/t/log-ingestion-to-elastic-cloud-not-working-with-ecs-fargate/300762)

<div class="topic-metadata">

**Author:** [@Gabriel\_Carvalho](https://discuss.elastic.co/u/Gabriel_Carvalho)\
**Replies:** 2\
**Last updated:** [April 4, 2022, 6:23pm UTC](https://discuss.elastic.co/t/log-ingestion-to-elastic-cloud-not-working-with-ecs-fargate/300762 "2022-04-04T18:23:48Z")

</div>

Hi everyone! I am trying to send logs of my apps running on an ECS Fargate Cluster to Elastic Cloud. I am using aws firelens logging driver and fluentbit as log router, I followed Elastic Cloud's documentation and every…

---

## [I have a problem when I want to send logs of clamav-0.104.2.linux.x86\_64 to EK version 7.14.2 , ubuntu 20.04](https://discuss.elastic.co/t/i-have-a-problem-when-i-want-to-send-logs-of-clamav-0-104-2-linux-x86-64-to-ek-version-7-14-2-ubuntu-20-04/297611)

<div class="topic-metadata">

**Author:** [@khouloud1](https://discuss.elastic.co/u/khouloud1)\
**Replies:** 9\
**Last updated:** [April 4, 2022, 2:31pm UTC](https://discuss.elastic.co/t/i-have-a-problem-when-i-want-to-send-logs-of-clamav-0-104-2-linux-x86-64-to-ek-version-7-14-2-ubuntu-20-04/297611 "2022-04-04T14:31:12Z")

</div>

I have a problem when I want to send logs of clamav-0.104.2.linux.x86\_64 to EK version 7.14.2 I did configure PFSense to send logsto EK but I did not find the best procedure to configure Elasticsearch and Kibana (7.14.2…

---

## [Elastic Query for Windows user accounts, excluding computer accounts](https://discuss.elastic.co/t/elastic-query-for-windows-user-accounts-excluding-computer-accounts/299750)

<div class="topic-metadata">

**Author:** [@secprentice](https://discuss.elastic.co/u/secprentice)\
**Replies:** 1\
**Last updated:** [April 1, 2022, 12:53pm UTC](https://discuss.elastic.co/t/elastic-query-for-windows-user-accounts-excluding-computer-accounts/299750 "2022-04-01T12:53:42Z")

</div>

I am trying to write a query for a machine learning rule which filters for Windows Event Log 4625 but excludes all logs where the username contains a $ symbol (excluding computer accounts) I have gotten this far but can…

---

## [Kibana 8.0.1: Can't set logAlias on the configuration file](https://discuss.elastic.co/t/kibana-8-0-1-cant-set-logalias-on-the-configuration-file/300541)

<div class="topic-metadata">

**Author:** [@panos-indev](https://discuss.elastic.co/u/panos-indev)\
**Replies:** 2\
**Last updated:** [March 29, 2022, 8:50am UTC](https://discuss.elastic.co/t/kibana-8-0-1-cant-set-logalias-on-the-configuration-file/300541 "2022-03-29T08:50:45Z")

</div>

Hello, I've been trying to configure logAlias to my config file and I get the following message: \[xpack.infra\].sources.default.logAlias\]: definition for this key is missing I used the 2 below configurations on kibana.…

---

## [Filebeat is not collecting logs from pods/kubernetes](https://discuss.elastic.co/t/filebeat-is-not-collecting-logs-from-pods-kubernetes/299980)

<div class="topic-metadata">

**Author:** [@marone](https://discuss.elastic.co/u/marone)\
**Replies:** 1\
**Last updated:** [March 21, 2022, 6:43pm UTC](https://discuss.elastic.co/t/filebeat-is-not-collecting-logs-from-pods-kubernetes/299980 "2022-03-21T18:43:01Z")

</div>

Hey, I am using Docker-desktop 4.6.0 (75818) on windows 10 \[version 10.0.19042.1526\], trying to set up Observability in a Kubernetes context, I have two application running (spring boot application + react app) I set up …

---

## [Fleet agent](https://discuss.elastic.co/t/fleet-agent/296349)

<div class="topic-metadata">

**Author:** [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Replies:** 6\
**Last updated:** [March 16, 2022, 8:36pm UTC](https://discuss.elastic.co/t/fleet-agent/296349 "2022-03-16T20:36:36Z")

</div>

Hello, I have a question about the fleet agent once it is deployed to a device. I have a self signed cert so I use this command to enroll .\\elastic-agent.exe install --url=https://192.168.131.155:8220 --enrollment-tok…

---

## [Unable to visualize Restored APM data from snapshot](https://discuss.elastic.co/t/unable-to-visualize-restored-apm-data-from-snapshot/299665)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 0\
**Last updated:** [March 14, 2022, 8:27pm UTC](https://discuss.elastic.co/t/unable-to-visualize-restored-apm-data-from-snapshot/299665 "2022-03-14T20:27:56Z")

</div>

Hi, I'm trying to restore a snapshsot that contains data from a fleet managed apm server, the indices I have are hidden and use the patterns : .ds-logs-apm\* is there any procedure to do in order to restore .ds-logs a…

---

## [My integration's data stream does not exists](https://discuss.elastic.co/t/my-integrations-data-stream-does-not-exists/299225)

<div class="topic-metadata">

**Author:** [@Teckinfor](https://discuss.elastic.co/u/Teckinfor)\
**Replies:** 0\
**Last updated:** [March 9, 2022, 1:37pm UTC](https://discuss.elastic.co/t/my-integrations-data-stream-does-not-exists/299225 "2022-03-09T13:37:27Z")

</div>

Hello, I am trying to use the Azure Logs integration (with the event hub) from my fleet. Everything seems fine but I am not getting any logs from this integration. I already have other integrations on this same agent, e…

---

## [How to deploy and setup a Fleet cluster?](https://discuss.elastic.co/t/how-to-deploy-and-setup-a-fleet-cluster/298285)

<div class="topic-metadata">

**Author:** [@Danny\_Dumenigo](https://discuss.elastic.co/u/Danny_Dumenigo)\
**Replies:** 2\
**Last updated:** [March 1, 2022, 3:07pm UTC](https://discuss.elastic.co/t/how-to-deploy-and-setup-a-fleet-cluster/298285 "2022-03-01T15:07:07Z")

</div>

Hello community! I have two environments of ELK v7.17 deployed on-prem (test and prod), so I decided to try Fleet. Im still testing things, so, In my test env I was able to setup a Fleet server (with certificates genera…

---

## [Logstash - any best practices for reusing elasitcsearch outputs across pipelines?](https://discuss.elastic.co/t/logstash-any-best-practices-for-reusing-elasitcsearch-outputs-across-pipelines/297155)

<div class="topic-metadata">

**Author:** [@mybyte](https://discuss.elastic.co/u/mybyte)\
**Replies:** 2\
**Last updated:** [February 18, 2022, 9:48am UTC](https://discuss.elastic.co/t/logstash-any-best-practices-for-reusing-elasitcsearch-outputs-across-pipelines/297155 "2022-02-18T09:48:40Z")

</div>

We have a set-up with sort of a hierarchical flow in the pipelines. Depending on application/format they're being routed to a different pipeline. All pipelines use the same Elasticsearch cluster for output, but in some c…

---

## [X-pack logs index template](https://discuss.elastic.co/t/x-pack-logs-index-template/296916)

<div class="topic-metadata">

**Author:** [@icey7z](https://discuss.elastic.co/u/icey7z)\
**Replies:** 1\
**Last updated:** [February 12, 2022, 4:25pm UTC](https://discuss.elastic.co/t/x-pack-logs-index-template/296916 "2022-02-12T16:25:03Z")

</div>

I'm trying to get my cluster to work with x-pack, and my data is stored in indexes under the namespace logs-\*-\*. This is a problem because x-pack creates an index template named logs as { "index\_patterns": \[ …

---

## [Integration Azure Metrics - No storaged used capacity](https://discuss.elastic.co/t/integration-azure-metrics-no-storaged-used-capacity/296190)

<div class="topic-metadata">

**Author:** [@Teckinfor](https://discuss.elastic.co/u/Teckinfor)\
**Replies:** 1\
**Last updated:** [February 10, 2022, 3:29pm UTC](https://discuss.elastic.co/t/integration-azure-metrics-no-storaged-used-capacity/296190 "2022-02-10T15:29:30Z")

</div>

Hello, I can't see some data such as "storage used capacity", can you help me please? Thanks in advance

---

## [Help with collecting Custom Windows Event Logs with Elastic Agent](https://discuss.elastic.co/t/help-with-collecting-custom-windows-event-logs-with-elastic-agent/295053)

<div class="topic-metadata">

**Author:** [@Josh\_G](https://discuss.elastic.co/u/Josh_G)\
**Replies:** 0\
**Last updated:** [January 21, 2022, 11:29am UTC](https://discuss.elastic.co/t/help-with-collecting-custom-windows-event-logs-with-elastic-agent/295053 "2022-01-21T11:29:11Z")

</div>

Hello everyone! A very rudimentary question I think, but haven't been able to find clarification myself. I am still very much getting to grips with the platform, and logging itself, so apologies if it is a really obviou…

---

## [How do you manage large filebeat installations?](https://discuss.elastic.co/t/how-do-you-manage-large-filebeat-installations/293755)

<div class="topic-metadata">

**Author:** [@mybyte](https://discuss.elastic.co/u/mybyte)\
**Replies:** 11\
**Last updated:** [January 18, 2022, 2:00pm UTC](https://discuss.elastic.co/t/how-do-you-manage-large-filebeat-installations/293755 "2022-01-18T14:00:17Z")

</div>

Elastic has made huge leaps in the direction of centralized management recently. Fleet and agent seem to be coming along. But while they seem to work well for metrics, syslog etc. I'm still struggling a bit with a useabl…

---

## [Do people use the Log viewer in Kibana?](https://discuss.elastic.co/t/do-people-use-the-log-viewer-in-kibana/294152)

<div class="topic-metadata">

**Author:** [@mybyte](https://discuss.elastic.co/u/mybyte)\
**Replies:** 3\
**Last updated:** [January 12, 2022, 3:17pm UTC](https://discuss.elastic.co/t/do-people-use-the-log-viewer-in-kibana/294152 "2022-01-12T15:17:39Z")

</div>

We're currently setting up a POC where we - among other things - collect a whole bunch of logs from many different machines. The idea was to centralize logs so we don't have to go rummage around multiple machines to find…

---

## [Elasticsearch server logs not visible in Kibana Stack monitoring](https://discuss.elastic.co/t/elasticsearch-server-logs-not-visible-in-kibana-stack-monitoring/287672)

<div class="topic-metadata">

**Author:** [@kalev](https://discuss.elastic.co/u/kalev)\
**Replies:** 5\
**Last updated:** [January 12, 2022, 1:01am UTC](https://discuss.elastic.co/t/elasticsearch-server-logs-not-visible-in-kibana-stack-monitoring/287672 "2022-01-12T01:01:09Z")

</div>

Hi, I do collect elsticsearch server (7.10.2) logs with filebeat (7.10.2) and they do exist in filebeat-\* index. These logs do NOT appear in Kibana Stack monitoring page as illustrated in https://www.elastic.co/guide/e…

---

## [.NET Core API Log correlation not showing in transactions](https://discuss.elastic.co/t/net-core-api-log-correlation-not-showing-in-transactions/293747)

<div class="topic-metadata">

**Author:** [@gonzaloluna](https://discuss.elastic.co/u/gonzaloluna)\
**Replies:** 0\
**Last updated:** [January 7, 2022, 1:21pm UTC](https://discuss.elastic.co/t/net-core-api-log-correlation-not-showing-in-transactions/293747 "2022-01-07T13:21:48Z")

</div>

Hi I'm trying to make log correlation work on my NET Core API. I'm using NLog following the documentation. I'm getting the traceID and transactionID in the logs in my console and logfile but I have zero logs in any APM …

---

## [Load a log file in fleet to read the file or logs in the elastic agent](https://discuss.elastic.co/t/load-a-log-file-in-fleet-to-read-the-file-or-logs-in-the-elastic-agent/292949)

<div class="topic-metadata">

**Author:** [@dannie-ml](https://discuss.elastic.co/u/dannie-ml)\
**Replies:** 1\
**Last updated:** [January 5, 2022, 10:10am UTC](https://discuss.elastic.co/t/load-a-log-file-in-fleet-to-read-the-file-or-logs-in-the-elastic-agent/292949 "2022-01-05T10:10:50Z")

</div>

Hi im exploring the elastic technology and im using fleet and i want to configure it an elastic agent to read my .log file, can any one please tell me how to read my .log file or can you tell me the steps to achieve this…

---

## [Shared views in Inventory Observability \[7.15.2\]](https://discuss.elastic.co/t/shared-views-in-inventory-observability-7-15-2/291991)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 1\
**Last updated:** [January 5, 2022, 10:08am UTC](https://discuss.elastic.co/t/shared-views-in-inventory-observability-7-15-2/291991 "2022-01-05T10:08:17Z")

</div>

Hi, everyone I have created a view in Inventory called Infraestructure in Default space. Does this view only can used by my user? I would like to create a global view, is it possible? is there any way to share it? …

---

## [ECSEncoder - Add the possibility to process or transform the messages](https://discuss.elastic.co/t/ecsencoder-add-the-possibility-to-process-or-transform-the-messages/293204)

<div class="topic-metadata">

**Author:** [@fpena](https://discuss.elastic.co/u/fpena)\
**Replies:** 0\
**Last updated:** [December 30, 2021, 1:25pm UTC](https://discuss.elastic.co/t/ecsencoder-add-the-possibility-to-process-or-transform-the-messages/293204 "2021-12-30T13:25:33Z")

</div>

I need to be able to transform some messages. For example obfuscate some information. I want to be able to do that at the encoder level and not before on several components. Now a days, the encode method add the message…

---

## [Logs ML event.dataset type error](https://discuss.elastic.co/t/logs-ml-event-dataset-type-error/292510)

<div class="topic-metadata">

**Author:** [@Travis\_Marble](https://discuss.elastic.co/u/Travis_Marble)\
**Replies:** 2\
**Last updated:** [December 22, 2021, 12:08am UTC](https://discuss.elastic.co/t/logs-ml-event-dataset-type-error/292510 "2021-12-22T00:08:02Z")

</div>

I am trying to setup Logs ML anomaly detection and getting the following error at least one index has a field event.dataset without the correct type Here is the typings for my index, I have seen various questions abo…

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md?page=2)

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=4)
