# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=5

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 6

---

## [Monitoring.ui.logs.index not working on docker?](https://discuss.elastic.co/t/monitoring-ui-logs-index-not-working-on-docker/273186)

<div class="topic-metadata">

**Author:** [@Flavio\_Pompermaier](https://discuss.elastic.co/u/Flavio_Pompermaier)\
**Replies:** 2\
**Last updated:** [May 24, 2021, 8:17am UTC](https://discuss.elastic.co/t/monitoring-ui-logs-index-not-working-on-docker/273186 "2021-05-24T08:17:07Z")

</div>

Hi to all, I've setup a working Kibana using docker-compose and I use journalbeat to collect elasticsearch logs of my docker container (that use journald as logging option). I've tried to change monitoring.ui.logs.index …

---

## ["Unknown" logs in observability overview](https://discuss.elastic.co/t/unknown-logs-in-observability-overview/273240)

<div class="topic-metadata">

**Author:** [@mar-ro](https://discuss.elastic.co/u/mar-ro)\
**Replies:** 3\
**Last updated:** [May 20, 2021, 8:29am UTC](https://discuss.elastic.co/t/unknown-logs-in-observability-overview/273240 "2021-05-20T08:29:58Z")

</div>

Good morning. When I click on the menu called "Observability Overview" it shows me an image with "Logs per minute rate" but all the bars in this image appear as "Unknown". I was searching in this forum and I could find a…

---

## [Field for http response times](https://discuss.elastic.co/t/field-for-http-response-times/272742)

<div class="topic-metadata">

**Author:** [@Sergii\_Ovcharenko](https://discuss.elastic.co/u/Sergii_Ovcharenko)\
**Replies:** 2\
**Last updated:** [May 12, 2021, 5:04pm UTC](https://discuss.elastic.co/t/field-for-http-response-times/272742 "2021-05-12T17:04:44Z")

</div>

Hey, Our app logs HTTP response times for the APIs we provide. What would be the best standard field to put this data in to follow ECS standard and best practices? There is no http.response.latency or similar field and e…

---

## [Ingest mixed container logs with text and JSON \[filebeat\]\[docker\]](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-filebeat-docker/271139)

<div class="topic-metadata">

**Author:** [@bluepuma77](https://discuss.elastic.co/u/bluepuma77)\
**Replies:** 4\
**Last updated:** [May 12, 2021, 1:22pm UTC](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-filebeat-docker/271139 "2021-05-12T13:22:05Z")

</div>

Hi all, we are currently using plain text logging and import container output with filebeat into elastic and kibana. We would like to migrate to structured logging with JSON. Is a bit-by-bit migration possible, can I h…

---

## [Anomaly detection / ML Setup](https://discuss.elastic.co/t/anomaly-detection-ml-setup/272378)

<div class="topic-metadata">

**Author:** [@tsp](https://discuss.elastic.co/u/tsp)\
**Replies:** 2\
**Last updated:** [May 11, 2021, 7:14am UTC](https://discuss.elastic.co/t/anomaly-detection-ml-setup/272378 "2021-05-11T07:14:12Z")

</div>

When setting up the ML within the Anomaly detection (Stack 11.1.2) , it says the following: At least one index matching logs-pattern-\* has a field called event.dataset without the correct type. Here is a sample record: …

---

## [ECS in avro format](https://discuss.elastic.co/t/ecs-in-avro-format/272170)

<div class="topic-metadata">

**Author:** [@birko](https://discuss.elastic.co/u/birko)\
**Replies:** 2\
**Last updated:** [May 6, 2021, 2:22pm UTC](https://discuss.elastic.co/t/ecs-in-avro-format/272170 "2021-05-06T14:22:47Z")

</div>

I'm looking for avro schema representation of ecs. It is necessary in Apache NiFi, when you're trying to transform data with record-oriented processors. Workaround is to use InferAvroSchema processor, but there is necess…

---

## [How to configure datastream and ILM to keep logs for specific time](https://discuss.elastic.co/t/how-to-configure-datastream-and-ilm-to-keep-logs-for-specific-time/272154)

<div class="topic-metadata">

**Author:** [@lancer\_enkor](https://discuss.elastic.co/u/lancer_enkor)\
**Replies:** 2\
**Last updated:** [May 5, 2021, 11:58am UTC](https://discuss.elastic.co/t/how-to-configure-datastream-and-ilm-to-keep-logs-for-specific-time/272154 "2021-05-05T11:58:53Z")

</div>

I want to configure datastream for gathering my application logs. And I want to keep the data from the app for a specific time, let say for one week. I will not use hot-warm-cold architecture, I just want to have logs fo…

---

## [Structured logging with Filebeat](https://discuss.elastic.co/t/structured-logging-with-filebeat/269383)

<div class="topic-metadata">

**Author:** [@vharabor](https://discuss.elastic.co/u/vharabor)\
**Replies:** 11\
**Last updated:** [April 29, 2021, 6:42am UTC](https://discuss.elastic.co/t/structured-logging-with-filebeat/269383 "2021-04-29T06:42:59Z")

</div>

Signed up for the elastic trial and quickly got the Filebeat up and running and getting docker statistics to Elasticsearch. I'm really stuck in trying to add any kind of structured logging to kibana. I've tried to add…

---

## [Missing certain log entries (json from k8s using filebeat)](https://discuss.elastic.co/t/missing-certain-log-entries-json-from-k8s-using-filebeat/269948)

<div class="topic-metadata">

**Author:** [@geoaxis](https://discuss.elastic.co/u/geoaxis)\
**Replies:** 2\
**Last updated:** [April 13, 2021, 3:18pm UTC](https://discuss.elastic.co/t/missing-certain-log-entries-json-from-k8s-using-filebeat/269948 "2021-04-13T15:18:42Z")

</div>

I am a consumer of an elastic stack (filebeat, es, kibana) that gets structured json logs from a kubernetes cluster (writing to stdout). The stack is slef hosted by a group at my workplace and unfortunately it does not …

---

## [ERROR StatusLogger Unrecognized conversion specifier log4j2](https://discuss.elastic.co/t/error-statuslogger-unrecognized-conversion-specifier-log4j2/268800)

<div class="topic-metadata">

**Author:** [@pippobaudo](https://discuss.elastic.co/u/pippobaudo)\
**Replies:** 1\
**Last updated:** [March 30, 2021, 3:12pm UTC](https://discuss.elastic.co/t/error-statuslogger-unrecognized-conversion-specifier-log4j2/268800 "2021-03-30T15:12:03Z")

</div>

Hi, I've been strugling with the setting of a small project using elastik e log4j. I'm using IntelliJ and when running everything works fine, but when I create the jar and try to execute it I always get: ERROR StatusLog…

---

## [Elastic Common Schema Fields for Reverse Proxies](https://discuss.elastic.co/t/elastic-common-schema-fields-for-reverse-proxies/267074)

<div class="topic-metadata">

**Author:** [@learnerbyheart](https://discuss.elastic.co/u/learnerbyheart)\
**Replies:** 2\
**Last updated:** [March 15, 2021, 9:10pm UTC](https://discuss.elastic.co/t/elastic-common-schema-fields-for-reverse-proxies/267074 "2021-03-15T21:10:46Z")

</div>

Hello, we are currently migrating our NGINX logging format to the Elastic Common Schema. For some NGINX logging values I cannot find any fitting fields. In our case we use NGINX as a reverse proxy in Kubernetes. Most of…

---

## [Alert When - system\_fails\_to\_provide\_data - dynamic group of sending hosts](https://discuss.elastic.co/t/alert-when-system-fails-to-provide-data-dynamic-group-of-sending-hosts/265094)

<div class="topic-metadata">

**Author:** [@bbek](https://discuss.elastic.co/u/bbek)\
**Replies:** 5\
**Last updated:** [March 9, 2021, 9:08am UTC](https://discuss.elastic.co/t/alert-when-system-fails-to-provide-data-dynamic-group-of-sending-hosts/265094 "2021-03-09T09:08:48Z")

</div>

I have a use case to alert when a host fails to send logs. There is a watcher configured here, which is similar to what I'm trying to achieve: I like the logic, aggregate hosts on last 24 hours, then check for last 5 …

---

## [Using my own time field instead of the @timestamp automatically added by Filebeat](https://discuss.elastic.co/t/using-my-own-time-field-instead-of-the-timestamp-automatically-added-by-filebeat/265709)

<div class="topic-metadata">

**Author:** [@snowfrogdev](https://discuss.elastic.co/u/snowfrogdev)\
**Replies:** 1\
**Last updated:** [February 28, 2021, 3:52am UTC](https://discuss.elastic.co/t/using-my-own-time-field-instead-of-the-timestamp-automatically-added-by-filebeat/265709 "2021-02-28T03:52:02Z")

</div>

I'm using the http\_endpoint input with Filebeat. I wanna use the timestamp field from my JSON payload instead of the @timestamp that Filebeat seems to add automatically. filebeat.inputs: - type: http\_endpoint ena…

---

## [Filebeat http endpoint message doesn't show up in Log](https://discuss.elastic.co/t/filebeat-http-endpoint-message-doesnt-show-up-in-log/265704)

<div class="topic-metadata">

**Author:** [@snowfrogdev](https://discuss.elastic.co/u/snowfrogdev)\
**Replies:** 1\
**Last updated:** [February 28, 2021, 12:40am UTC](https://discuss.elastic.co/t/filebeat-http-endpoint-message-doesnt-show-up-in-log/265704 "2021-02-28T00:40:33Z")

</div>

This is what I get: This is my request: This is my config file: filebeat.inputs: - type: http\_endpoint enabled: true listen\_address: filebeat listen\_port: 8088 response\_code: 200 output.elastics…

---

## [Kibana in logs view shows the paths to they log files, but no content](https://discuss.elastic.co/t/kibana-in-logs-view-shows-the-paths-to-they-log-files-but-no-content/264759)

<div class="topic-metadata">

**Author:** [@jacob1375](https://discuss.elastic.co/u/jacob1375)\
**Replies:** 3\
**Last updated:** [February 23, 2021, 2:17pm UTC](https://discuss.elastic.co/t/kibana-in-logs-view-shows-the-paths-to-they-log-files-but-no-content/264759 "2021-02-23T14:17:17Z")

</div>

I created elk project(elasticsearch, logstash, kibana and filebeat) for production environment. It’s contained 1 server and 5 filebeat clients. Our developers would like to see some log files from they applications. I us…

---

## [Serilog EcsTextFormatter: Not what I expected](https://discuss.elastic.co/t/serilog-ecstextformatter-not-what-i-expected/263781)

<div class="topic-metadata">

**Author:** [@sgtobin](https://discuss.elastic.co/u/sgtobin)\
**Replies:** 1\
**Last updated:** [February 15, 2021, 10:42am UTC](https://discuss.elastic.co/t/serilog-ecstextformatter-not-what-i-expected/263781 "2021-02-15T10:42:52Z")

</div>

This c# code... class Program { static void Main(string\[\] args) { Log.Logger = new LoggerConfiguration() .MinimumLevel.Debug() .WriteTo.Console(new EcsTextFormatter()) …

---

## [Showing \`error.log\` field in Observability Logs? (Currently it just shows \`message\` field, so it is very inconvenient to look at errors!)](https://discuss.elastic.co/t/showing-error-log-field-in-observability-logs-currently-it-just-shows-message-field-so-it-is-very-inconvenient-to-look-at-errors/263319)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 4\
**Last updated:** [February 10, 2021, 12:14pm UTC](https://discuss.elastic.co/t/showing-error-log-field-in-observability-logs-currently-it-just-shows-message-field-so-it-is-very-inconvenient-to-look-at-errors/263319 "2021-02-10T12:14:41Z")

</div>

Hi thanks for elastic stack! I wonder how can I show error.log field in Observability Logs? Currently it just shows message field, so it is very inconvenient to look at errors! When doing tail -f mylogfile, of course we …

---

## [Best way of setting up \`service.name\` && any other fields that I should set up?](https://discuss.elastic.co/t/best-way-of-setting-up-service-name-any-other-fields-that-i-should-set-up/262700)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 2\
**Last updated:** [February 10, 2021, 12:12pm UTC](https://discuss.elastic.co/t/best-way-of-setting-up-service-name-any-other-fields-that-i-should-set-up/262700 "2021-02-10T12:12:29Z")

</div>

Hi thanks for this product! I wonder how should I set up the service.name? What is the most recommended way to setup it for any kubernetes pod (e.g. a Spring java app, a Nginx, a Kafka...) (Because I see here saying tha…

---

## [Logs only showing time in UTC, regardless of setting](https://discuss.elastic.co/t/logs-only-showing-time-in-utc-regardless-of-setting/262761)

<div class="topic-metadata">

**Author:** [@doyelese](https://discuss.elastic.co/u/doyelese)\
**Replies:** 1\
**Last updated:** [February 4, 2021, 9:38am UTC](https://discuss.elastic.co/t/logs-only-showing-time-in-utc-regardless-of-setting/262761 "2021-02-04T09:38:45Z")

</div>

Hi there, Maybe I'm missing the setting, but my logs in the Observability window are always being shown in UTC, despite the fact that I'm saving these logs as MST. Where can I change this setting or determine how the da…

---

## [Log source "unknown" in Observability Overview](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568)

<div class="topic-metadata">

**Author:** [@strophy](https://discuss.elastic.co/u/strophy)\
**Replies:** 3\
**Last updated:** [January 30, 2021, 4:20am UTC](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568 "2021-01-30T04:20:38Z")

</div>

I'm new to Elastic Stack and have successfully set up a pipeline with Filebeat, Elasticsearch and Kibana to ingest data from log files. I have set up the display fields in Observability settings, which works for the Logs…

---

## [Loading Incremental data into Elastic Search](https://discuss.elastic.co/t/loading-incremental-data-into-elastic-search/262180)

<div class="topic-metadata">

**Author:** [@gaurav1](https://discuss.elastic.co/u/gaurav1)\
**Replies:** 3\
**Last updated:** [January 26, 2021, 3:12pm UTC](https://discuss.elastic.co/t/loading-incremental-data-into-elastic-search/262180 "2021-01-26T15:12:34Z")

</div>

I am getting Json response from JIRA using Api containing issue details and loading those as logs in Elasticsearch. This activity we are doing continuously. So every time we need to provide an incremental data. In data w…

---

## [Nanosecond support in Logs UI](https://discuss.elastic.co/t/nanosecond-support-in-logs-ui/261048)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 2\
**Last updated:** [January 24, 2021, 12:58pm UTC](https://discuss.elastic.co/t/nanosecond-support-in-logs-ui/261048 "2021-01-24T12:58:02Z")

</div>

Does anyone know if the Logs UI supports timetamps in data\_nanos format? If not, is this feature coming in the future? I couldn't get it to work with nanoseconds.

---

## [Alerting based on the keyword in logs](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295)

<div class="topic-metadata">

**Author:** [@v\_anil](https://discuss.elastic.co/u/v_anil)\
**Replies:** 3\
**Last updated:** [January 6, 2021, 5:16pm UTC](https://discuss.elastic.co/t/alerting-based-on-the-keyword-in-logs/260295 "2021-01-06T17:16:25Z")

</div>

Hi , Is there anyway we can configure an alert based on the keyword in the logs, and alert them if we found more than threshould. for ex: If the logs contain "Exception or ERROR" more than 10 times in last 2 min , i …

---

## [Sorting by something other than timestamp in Logs app](https://discuss.elastic.co/t/sorting-by-something-other-than-timestamp-in-logs-app/257897)

<div class="topic-metadata">

**Author:** [@ippolito](https://discuss.elastic.co/u/ippolito)\
**Replies:** 3\
**Last updated:** [December 8, 2020, 7:13pm UTC](https://discuss.elastic.co/t/sorting-by-something-other-than-timestamp-in-logs-app/257897 "2020-12-08T19:13:23Z")

</div>

Hi. Is there a way to sort by a different field in the Observability/Logs app? Since we have multiple logging servers feeding a kafka queue, our logs don't necessarily arrive in the same order they're generated. We'd lik…

---

## [ElasticSearch usage for logs with big size of entries](https://discuss.elastic.co/t/elasticsearch-usage-for-logs-with-big-size-of-entries/255197)

<div class="topic-metadata">

**Author:** [@andsm](https://discuss.elastic.co/u/andsm)\
**Replies:** 1\
**Last updated:** [November 17, 2020, 2:24pm UTC](https://discuss.elastic.co/t/elasticsearch-usage-for-logs-with-big-size-of-entries/255197 "2020-11-17T14:24:10Z")

</div>

Hello, I think about usage of ElasticSearch for logging. System generates about 5-10k log entries per second, average, total size is about 500 Mb per second. Most of log entries are small, but some log entries have siz…

---

## [Detect CreditCard numbers in Logs](https://discuss.elastic.co/t/detect-creditcard-numbers-in-logs/255381)

<div class="topic-metadata">

**Author:** [@vishakh](https://discuss.elastic.co/u/vishakh)\
**Replies:** 1\
**Last updated:** [November 13, 2020, 10:12pm UTC](https://discuss.elastic.co/t/detect-creditcard-numbers-in-logs/255381 "2020-11-13T22:12:28Z")

</div>

Currently, we're running ELK-Stack and I would like to setup-configure detection & alerts for logs containing CreditCard numbers. I did skim through certain ELK-modules, but couldn't find any suitable that can achieve t…

---

## [Configure Kibana Log UI settings per space using API](https://discuss.elastic.co/t/configure-kibana-log-ui-settings-per-space-using-api/251704)

<div class="topic-metadata">

**Author:** [@leon.seng](https://discuss.elastic.co/u/leon.seng)\
**Replies:** 4\
**Last updated:** [October 15, 2020, 10:11pm UTC](https://discuss.elastic.co/t/configure-kibana-log-ui-settings-per-space-using-api/251704 "2020-10-15T22:11:13Z")

</div>

Hi, I am currently running Kibanamultiple spaces - each monitoring for different index patterns, in order the trigger alerts and actions on different indices. This page on Logs UI settings shows how we can configure th…

---

## [Filebeat output to logstash and elasticsearch both](https://discuss.elastic.co/t/filebeat-output-to-logstash-and-elasticsearch-both/250064)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 3\
**Last updated:** [September 27, 2020, 9:57am UTC](https://discuss.elastic.co/t/filebeat-output-to-logstash-and-elasticsearch-both/250064 "2020-09-27T09:57:32Z")

</div>

Hi I am using Elasticstack 7.9 on-prem - I am wondering about a scenario if it's possible I have 2 services on 1 VM - one is an haproxy service and the other is an nginx service Both services generate log files on dis…

---

## [Logstash process stops abruptly](https://discuss.elastic.co/t/logstash-process-stops-abruptly/245895)

<div class="topic-metadata">

**Author:** [@tarund](https://discuss.elastic.co/u/tarund)\
**Replies:** 4\
**Last updated:** [September 3, 2020, 7:37pm UTC](https://discuss.elastic.co/t/logstash-process-stops-abruptly/245895 "2020-09-03T19:37:09Z")

</div>

I am using Logstash version 7.7.1 to parse some log files located on the same server. Using file input filter, grok filter & Elasticsearch output The process stops abruptly after some time, with nothing in the logs, ev…

---

## [Settings Log traceId](https://discuss.elastic.co/t/settings-log-traceid/246665)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 4\
**Last updated:** [September 2, 2020, 6:50am UTC](https://discuss.elastic.co/t/settings-log-traceid/246665 "2020-09-02T06:50:21Z")

</div>

Good morning, I don't know if it is a bug but I would like confirm it. I have a configuration of Logs where I added one pattern more. With this change I can see all the logs, but if i want see the trace of a transact…

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md?page=4)

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=6)
