# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=4

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 5

---

## [Doubts about how exclude events by the process name with filebeat](https://discuss.elastic.co/t/doubts-about-how-exclude-events-by-the-process-name-with-filebeat/290988)

<div class="topic-metadata">

**Author:** [@rdinis](https://discuss.elastic.co/u/rdinis)\
**Replies:** 2\
**Last updated:** [December 10, 2021, 2:00pm UTC](https://discuss.elastic.co/t/doubts-about-how-exclude-events-by-the-process-name-with-filebeat/290988 "2021-12-10T14:00:22Z")

</div>

Hi, I'm trying to send logs to elastic from the file /var/logs/messages\* and i have a lot of logs from another agents of elastic. The file messages\* looks like this: Dec 1 16:50:03 machine\_name heartbeat: "status": "u…

---

## [Subheadings in Elasticsearch/clean up system logs](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943)

<div class="topic-metadata">

**Author:** [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Replies:** 12\
**Last updated:** [December 1, 2021, 2:39pm UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943 "2021-12-01T14:39:57Z")

</div>

Hi, I'm brand new to the whole ELK stack, I've setup one in my company. I just wanted to know how best to clean up the logs, I'm getting a lot of system logs from the server and I don't want them. I just want the logs fr…

---

## [How to turn off the color marking in the log?](https://discuss.elastic.co/t/how-to-turn-off-the-color-marking-in-the-log/288897)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 2\
**Last updated:** [November 25, 2021, 1:06am UTC](https://discuss.elastic.co/t/how-to-turn-off-the-color-marking-in-the-log/288897 "2021-11-25T01:06:29Z")

</div>

There are many color marks in the logs collected from filebeat, which greatly affects the structure of the log. Is there any way to close it? Can I only change the log level from INFO to WARN?

---

## [Collapsing / Hiding stack traces in the log stream view?](https://discuss.elastic.co/t/collapsing-hiding-stack-traces-in-the-log-stream-view/288767)

<div class="topic-metadata">

**Author:** [@Matthias\_W](https://discuss.elastic.co/u/Matthias_W)\
**Replies:** 1\
**Last updated:** [November 10, 2021, 11:29am UTC](https://discuss.elastic.co/t/collapsing-hiding-stack-traces-in-the-log-stream-view/288767 "2021-11-10T11:29:42Z")

</div>

Hi, is there any way to collapse / hide stack traces in the "Observability - Logs - Stream" view? Large stack traces make scrolling quite unpleasant and usability really suffers (even when using small text and having a…

---

## [Applying settings /app/logs/settings via an API](https://discuss.elastic.co/t/applying-settings-app-logs-settings-via-an-api/288771)

<div class="topic-metadata">

**Author:** [@angelom888](https://discuss.elastic.co/u/angelom888)\
**Replies:** 3\
**Last updated:** [November 9, 2021, 4:52pm UTC](https://discuss.elastic.co/t/applying-settings-app-logs-settings-via-an-api/288771 "2021-11-09T16:52:25Z")

</div>

I am able to manually configure the setting for logs streams from https:/kibanahost:5601/app/logs/settings I want to do this programmatically but cannot seem to find the API to do this. Can anyone help point me in the…

---

## [Http fields: inbound or outbound](https://discuss.elastic.co/t/http-fields-inbound-or-outbound/287723)

<div class="topic-metadata">

**Author:** [@Bert\_Vanpeteghem](https://discuss.elastic.co/u/Bert_Vanpeteghem)\
**Replies:** 2\
**Last updated:** [November 9, 2021, 12:28pm UTC](https://discuss.elastic.co/t/http-fields-inbound-or-outbound/287723 "2021-11-09T12:28:18Z")

</div>

Hi, in elastic ECS there's the http section. Is this section reserved for incoming or outgoing http activity?

---

## [IIS logs showing as a string](https://discuss.elastic.co/t/iis-logs-showing-as-a-string/288470)

<div class="topic-metadata">

**Author:** [@Venu1](https://discuss.elastic.co/u/Venu1)\
**Replies:** 3\
**Last updated:** [November 9, 2021, 3:21am UTC](https://discuss.elastic.co/t/iis-logs-showing-as-a-string/288470 "2021-11-09T03:21:24Z")

</div>

Hello all, I'm a newbie to ELK, I'm able to send the IIS logs and other application logs to the Elastic Kibana from the servers directly without logstash, IIS logs are showing up one string in the Elastic Kibana, I woul…

---

## [Avoid duplicates via node ingest pipelines](https://discuss.elastic.co/t/avoid-duplicates-via-node-ingest-pipelines/288408)

<div class="topic-metadata">

**Author:** [@omartinez](https://discuss.elastic.co/u/omartinez)\
**Replies:** 9\
**Last updated:** [November 5, 2021, 2:30pm UTC](https://discuss.elastic.co/t/avoid-duplicates-via-node-ingest-pipelines/288408 "2021-11-05T14:30:06Z")

</div>

Hi all, I need a solution on the elastic side to handle duplicate logs. I need to develop an elastic ingest node pipeline that can manage duplicates by replacing \_id with uuid, any other suggestions are welcome, but I d…

---

## [How to get Log Patterns similar to what Logz.io does?](https://discuss.elastic.co/t/how-to-get-log-patterns-similar-to-what-logz-io-does/287449)

<div class="topic-metadata">

**Author:** [@Urbano\_Freitas](https://discuss.elastic.co/u/Urbano_Freitas)\
**Replies:** 3\
**Last updated:** [October 28, 2021, 6:56pm UTC](https://discuss.elastic.co/t/how-to-get-log-patterns-similar-to-what-logz-io-does/287449 "2021-10-28T18:56:08Z")

</div>

Hi everyone, One thing I really would love to have in Elastic is a easy way to find patterns in logs like Logz.io does: https://logz.io/platform/features/log-patterns/ I have been playing with Elastic Machine Learning …

---

## [Resources for modeling application log data?](https://discuss.elastic.co/t/resources-for-modeling-application-log-data/285849)

<div class="topic-metadata">

**Author:** [@swainstead](https://discuss.elastic.co/u/swainstead)\
**Replies:** 3\
**Last updated:** [October 27, 2021, 12:58pm UTC](https://discuss.elastic.co/t/resources-for-modeling-application-log-data/285849 "2021-10-27T12:58:21Z")

</div>

I've been working with our application logging and creating Kibana dashboards for a little while now. I wonder though if I'm missing some best practices or techniques for designing the log messages themselves to get the…

---

## [Using Filebeat to send different logs and differentiating in Kibana](https://discuss.elastic.co/t/using-filebeat-to-send-different-logs-and-differentiating-in-kibana/287580)

<div class="topic-metadata">

**Author:** [@Maduranga](https://discuss.elastic.co/u/Maduranga)\
**Replies:** 1\
**Last updated:** [October 25, 2021, 4:54pm UTC](https://discuss.elastic.co/t/using-filebeat-to-send-different-logs-and-differentiating-in-kibana/287580 "2021-10-25T16:54:06Z")

</div>

Hello, I am looking for guidance to get started with ELK stack with Filebeat. I am using Elastic cloud with my servers using Filebeat to send logs directly to the Elastic cloud. I can get the log stream and see the st…

---

## [Elastic Search by Date Range](https://discuss.elastic.co/t/elastic-search-by-date-range/285869)

<div class="topic-metadata">

**Author:** [@Raghavendra\_B](https://discuss.elastic.co/u/Raghavendra_B)\
**Replies:** 1\
**Last updated:** [October 26, 2021, 11:28am UTC](https://discuss.elastic.co/t/elastic-search-by-date-range/285869 "2021-10-26T11:28:35Z")

</div>

Hello, I want to see the logs for last 5 minutes from particular timestamp. I am constructing elastic log url dynamically for alert message (with timestamp i.e the alert triggered time). For specifying date range for l…

---

## [Confusion, dot-notation vs. sub-objects](https://discuss.elastic.co/t/confusion-dot-notation-vs-sub-objects/286199)

<div class="topic-metadata">

**Author:** [@anton-johansson](https://discuss.elastic.co/u/anton-johansson)\
**Replies:** 2\
**Last updated:** [October 11, 2021, 3:15pm UTC](https://discuss.elastic.co/t/confusion-dot-notation-vs-sub-objects/286199 "2021-10-11T15:15:40Z")

</div>

We're a bit confused about the specification regarding dot-notation vs. sub-objects. If you look in the documentation, it is specified as dot-notation, see here: This is implemented as dot-notation in the Java/Log4j2-i…

---

## [Grok pattern issue](https://discuss.elastic.co/t/grok-pattern-issue/284247)

<div class="topic-metadata">

**Author:** [@Divya\_Bansal](https://discuss.elastic.co/u/Divya_Bansal)\
**Replies:** 1\
**Last updated:** [October 4, 2021, 3:24pm UTC](https://discuss.elastic.co/t/grok-pattern-issue/284247 "2021-10-04T15:24:51Z")

</div>

I have two logs: one with loglevel field and one without it as mentioned below. can anyone help me with thescript processing both type of logs from single pattern. the sample logs are:- 2021-09-13T23:58:22.676 \[\] loca…

---

## [Vercel Integration](https://discuss.elastic.co/t/vercel-integration/285092)

<div class="topic-metadata">

**Author:** [@jasonkuhrt](https://discuss.elastic.co/u/jasonkuhrt)\
**Replies:** 1\
**Last updated:** [September 28, 2021, 4:20pm UTC](https://discuss.elastic.co/t/vercel-integration/285092 "2021-09-28T16:20:55Z")

</div>

I am exploring if it is possible to send logs from our functions hosted on Vercel to our ELK trial. My first hurdle is trying to understand how to ship logs from the function to ELK. Currently I am willing to do this wi…

---

## [.Net ECSLayout 1.6.0 Release Date?](https://discuss.elastic.co/t/net-ecslayout-1-6-0-release-date/284246)

<div class="topic-metadata">

**Author:** [@Bingu\_Shim](https://discuss.elastic.co/u/Bingu_Shim)\
**Replies:** 1\
**Last updated:** [September 20, 2021, 5:00am UTC](https://discuss.elastic.co/t/net-ecslayout-1-6-0-release-date/284246 "2021-09-20T05:00:05Z")

</div>

Hello, Is it possible to let me know, when are you planning to release .Net ECS Layout 1.6.0? We really need this fix. Since, we take ECS as standards for our structured logging format. So many teams in our company(w…

---

## [Kibana Duplicate data](https://discuss.elastic.co/t/kibana-duplicate-data/283299)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 1\
**Last updated:** [September 6, 2021, 4:07pm UTC](https://discuss.elastic.co/t/kibana-duplicate-data/283299 "2021-09-06T16:07:34Z")

</div>

I have ELSK Steup to aggregate Kubernetes logs. But in Kibana I see all logs appearing twice, here is the sample 10:43:02.416 \[2021-09-03 14:43:02,414\] \[INFO\] - Encoding password to hash! 10:43:02.416 \[2021-09-03 14:43:…

---

## [Applying Elastic Common Scheman(ECS) in multi language environments](https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431)

<div class="topic-metadata">

**Author:** [@Bingu\_Shim](https://discuss.elastic.co/u/Bingu_Shim)\
**Replies:** 2\
**Last updated:** [August 26, 2021, 1:31am UTC](https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431 "2021-08-26T01:31:08Z")

</div>

Hello, We are operating Filebeat on about 2,000 Machines and 2~30 K8S Clusters. Also we accept ECS as the structured logging format standard for our company. Currently, we applied ECS layout to services that are writt…

---

## [Is there a way to configure Multiple Log Streams by distinct Index Name?](https://discuss.elastic.co/t/is-there-a-way-to-configure-multiple-log-streams-by-distinct-index-name/281823)

<div class="topic-metadata">

**Author:** [@vijay.sangha](https://discuss.elastic.co/u/vijay.sangha)\
**Replies:** 3\
**Last updated:** [August 20, 2021, 7:48am UTC](https://discuss.elastic.co/t/is-there-a-way-to-configure-multiple-log-streams-by-distinct-index-name/281823 "2021-08-20T07:48:16Z")

</div>

I have been using logtrail till version 7.9.0, but the plugin provider didn't re-wrote the code to comply with the latest version. As there is a streams availabe within Kibana now, is there a way to define multiple stre…

---

## [Observability logs - Alert log stoppage](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414)

<div class="topic-metadata">

**Author:** [@jancodenew](https://discuss.elastic.co/u/jancodenew)\
**Replies:** 7\
**Last updated:** [August 18, 2021, 9:09am UTC](https://discuss.elastic.co/t/observability-logs-alert-log-stoppage/281414 "2021-08-18T09:09:33Z")

</div>

Hello, I am able to create log stoppage alert using threshold alert type in logs-ovservability. Is there any way to add multiple index names in this observalibilty-logs settings?, so that I can create multiple alerts f…

---

## [Elastisearch query rule type hits contains only one document](https://discuss.elastic.co/t/elastisearch-query-rule-type-hits-contains-only-one-document/277688)

<div class="topic-metadata">

**Author:** [@bravo](https://discuss.elastic.co/u/bravo)\
**Replies:** 15\
**Last updated:** [August 2, 2021, 12:50pm UTC](https://discuss.elastic.co/t/elastisearch-query-rule-type-hits-contains-only-one-document/277688 "2021-08-02T12:50:23Z")

</div>

Rule type: Elastisearch query Connector: Index context.hits always contain only one document, evethough there are multiple documents that match the query at that point in time. Context.value is always 1. Test query (i…

---

## [Delete Documents Index](https://discuss.elastic.co/t/delete-documents-index/277777)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 1\
**Last updated:** [July 5, 2021, 2:13pm UTC](https://discuss.elastic.co/t/delete-documents-index/277777 "2021-07-05T14:13:14Z")

</div>

Hi all!! I have read the documentation about the lifecicle but I have a simple question about it. Is possible delete the documents after X days? I don't want to keep the docs because they are only to debug. Thanks for…

---

## [Mapping multiple properties to a single one](https://discuss.elastic.co/t/mapping-multiple-properties-to-a-single-one/275966)

<div class="topic-metadata">

**Author:** [@mats990](https://discuss.elastic.co/u/mats990)\
**Replies:** 3\
**Last updated:** [June 28, 2021, 11:21am UTC](https://discuss.elastic.co/t/mapping-multiple-properties-to-a-single-one/275966 "2021-06-28T11:21:18Z")

</div>

Hi, Let's say you have a cluster with application logs. And since multiple applications are sending data to the cluster they have different properties. For example, one application will send a log message in the "messag…

---

## [ECS Logger Mapping Logs to ECS Fields](https://discuss.elastic.co/t/ecs-logger-mapping-logs-to-ecs-fields/274932)

<div class="topic-metadata">

**Author:** [@mertayd](https://discuss.elastic.co/u/mertayd)\
**Replies:** 7\
**Last updated:** [June 16, 2021, 5:48pm UTC](https://discuss.elastic.co/t/ecs-logger-mapping-logs-to-ecs-fields/274932 "2021-06-16T17:48:03Z")

</div>

I am quite new using Elastic and I have log data from AWS CloudWatch that I have shipped into Elastic Cluster using filebeats however I couldn't understand how I can map my logs into ECS fields. I read a lot of documenta…

---

## [Cannot view logs in Observability log app](https://discuss.elastic.co/t/cannot-view-logs-in-observability-log-app/274257)

<div class="topic-metadata">

**Author:** [@NoviceESCoder](https://discuss.elastic.co/u/NoviceESCoder)\
**Replies:** 5\
**Last updated:** [June 3, 2021, 12:15pm UTC](https://discuss.elastic.co/t/cannot-view-logs-in-observability-log-app/274257 "2021-06-03T12:15:55Z")

</div>

I have a asp.net core web app (mvc) project that will write the logs using Serilog to Elasticsearch. I created the index pattern in Kibana and I can view the logs that was written to elasticsearch under Discover. But whe…

---

## [Best Practices / Recommendations for Custom Objects](https://discuss.elastic.co/t/best-practices-recommendations-for-custom-objects/274081)

<div class="topic-metadata">

**Author:** [@Jeff\_Stevens](https://discuss.elastic.co/u/Jeff_Stevens)\
**Replies:** 2\
**Last updated:** [June 1, 2021, 6:16am UTC](https://discuss.elastic.co/t/best-practices-recommendations-for-custom-objects/274081 "2021-06-01T06:16:24Z")

</div>

We are evaluating ECS as a common transport schema for our events, logging, and messaging needs. Tags are not enough as we want to have sharable serialized compound objects. We initially started with the .NET NLog mapp…

---

## [KubeEdge and monitoring](https://discuss.elastic.co/t/kubeedge-and-monitoring/274067)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 2\
**Last updated:** [May 27, 2021, 4:58pm UTC](https://discuss.elastic.co/t/kubeedge-and-monitoring/274067 "2021-05-27T16:58:36Z")

</div>

Any support from Elastic for monitoring within KubeEdge? ( KubeEdge, a Kubernetes Native Edge Computing Framework | Kubernetes

---

## [Monitoring log sources status](https://discuss.elastic.co/t/monitoring-log-sources-status/273492)

<div class="topic-metadata">

**Author:** [@ima](https://discuss.elastic.co/u/ima)\
**Replies:** 1\
**Last updated:** [May 27, 2021, 1:21pm UTC](https://discuss.elastic.co/t/monitoring-log-sources-status/273492 "2021-05-27T13:21:05Z")

</div>

Hello, does anybody have an idea on how to create a dashboard to monitor all log sources status observability and know those who stopped sending logs

---

## [Trace.id and transaction.id not being added to log entry](https://discuss.elastic.co/t/trace-id-and-transaction-id-not-being-added-to-log-entry/268838)

<div class="topic-metadata">

**Author:** [@pculebras](https://discuss.elastic.co/u/pculebras)\
**Replies:** 13\
**Last updated:** [May 26, 2021, 4:21pm UTC](https://discuss.elastic.co/t/trace-id-and-transaction-id-not-being-added-to-log-entry/268838 "2021-05-26T16:21:51Z")

</div>

Good evening everyone, I was able to set up the APM Java Agent and activated the log\_correlation option without further issues. Next, I got the tool to log into a file by using the ECS Java Logging tool and its standar…

---

## [Need update on tiebreaker fields for Kibana logs (event.sequence ?)](https://discuss.elastic.co/t/need-update-on-tiebreaker-fields-for-kibana-logs-event-sequence/273295)

<div class="topic-metadata">

**Author:** [@cotjoey](https://discuss.elastic.co/u/cotjoey)\
**Replies:** 2\
**Last updated:** [May 25, 2021, 4:23pm UTC](https://discuss.elastic.co/t/need-update-on-tiebreaker-fields-for-kibana-logs-event-sequence/273295 "2021-05-25T16:23:51Z")

</div>

Good morning, Following up from another post I made a while ago, I want to know if in version 7.10.0 of Kibana, the event.sequence field is used automatically by the Kibana Logs application to sort the events that have …

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md?page=3)

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=5)
