# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=6

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 7

---

## [Filebeat send json data to Elastiksearch isuue](https://discuss.elastic.co/t/filebeat-send-json-data-to-elastiksearch-isuue/244860)

<div class="topic-metadata">

**Author:** [@Partha\_Biswas](https://discuss.elastic.co/u/Partha_Biswas)\
**Replies:** 5\
**Last updated:** [August 21, 2020, 9:32am UTC](https://discuss.elastic.co/t/filebeat-send-json-data-to-elastiksearch-isuue/244860 "2020-08-21T09:32:01Z")

</div>

I am using filebeat to send log data in ELK kibana. Log example:- error\_log.log {"type":"ERROR","errorType":"ERROR","message":"Error in add","others":{"error": "something went wrong","source":"/public/new/user"}} {"typ…

---

## [Actions trace log will cause logs setting to reset](https://discuss.elastic.co/t/actions-trace-log-will-cause-logs-setting-to-reset/245074)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 1\
**Last updated:** [August 17, 2020, 9:32am UTC](https://discuss.elastic.co/t/actions-trace-log-will-cause-logs-setting-to-reset/245074 "2020-08-17T09:32:06Z")

</div>

ELK :7.8.1 After clicking trace log, the page to jump to is empty. This is an error. (link http://192.168.10.145:5601/app/logs/link-to/logs?time=1597469807703&filter=trace.id:"4e41234389a5a38eb16827a5ad9eaeb6"%20OR%2…

---

## [Alerting on log data](https://discuss.elastic.co/t/alerting-on-log-data/242932)

<div class="topic-metadata">

**Author:** [@DanRoscigno](https://discuss.elastic.co/u/DanRoscigno)\
**Replies:** 3\
**Last updated:** [August 3, 2020, 10:10am UTC](https://discuss.elastic.co/t/alerting-on-log-data/242932 "2020-08-03T10:10:59Z")

</div>

Here is some information that is in my logs: I would like to be able to create alerts any time a log entry includes the word ERROR, and the kubernetes.pod.name includes the string redis-leader. I have removed the ma…

---

## [Kibana log error message "event.dataset cisco.asa failed to find message"](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034)

<div class="topic-metadata">

**Author:** [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Replies:** 4\
**Last updated:** [July 17, 2020, 1:34pm UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034 "2020-07-17T13:34:34Z")

</div>

Dear people, I have an ELK 7.8.0 server running OK. I've setup the Cisco ASA module in filebeat and all the ASA logs are coming OK to my ELK server on port UDP/514. I can see the ASA lohgs in Discover and SIEM Netwotk t…

---

## [Mulitple terms highlight in the Kibana Logs App](https://discuss.elastic.co/t/mulitple-terms-highlight-in-the-kibana-logs-app/240803)

<div class="topic-metadata">

**Author:** [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Replies:** 1\
**Last updated:** [July 14, 2020, 9:26pm UTC](https://discuss.elastic.co/t/mulitple-terms-highlight-in-the-kibana-logs-app/240803 "2020-07-14T21:26:01Z")

</div>

I was trying to use the "highlight" feature in the Kibana Logs app. I am not able to highlight multiple terms using this feature, when I enter like this I was expecting both the "app-01", and "logging" would get hig…

---

## [Using Elastic Cloud Private with multiple AWS accounts](https://discuss.elastic.co/t/using-elastic-cloud-private-with-multiple-aws-accounts/232275)

<div class="topic-metadata">

**Author:** [@scottcowan](https://discuss.elastic.co/u/scottcowan)\
**Replies:** 1\
**Last updated:** [May 13, 2020, 8:58am UTC](https://discuss.elastic.co/t/using-elastic-cloud-private-with-multiple-aws-accounts/232275 "2020-05-13T08:58:59Z")

</div>

Hi we're looking at breaking up our AWS accounts and I'd still like to have centralised logs. Are we able to use Elastic Cloud Private were we setup Elastic VPCs in multiple accounts to retrieve logs onto a central accou…

---

## [SMTP logs from Windows Server can't be parsed](https://discuss.elastic.co/t/smtp-logs-from-windows-server-cant-be-parsed/229916)

<div class="topic-metadata">

**Author:** [@Vadym\_Mykolaichuk](https://discuss.elastic.co/u/Vadym_Mykolaichuk)\
**Replies:** 3\
**Last updated:** [April 27, 2020, 3:39pm UTC](https://discuss.elastic.co/t/smtp-logs-from-windows-server-cant-be-parsed/229916 "2020-04-27T15:39:20Z")

</div>

Hi! I'm using filebeat to send IIS log files from Windows Server machine. It parses logs from IIS (web logs) just fine, but it can't parse SMTP logs which have the same format. On Kibana I see this error: Provided Gro…

---

## [Parsing the filebeat logs](https://discuss.elastic.co/t/parsing-the-filebeat-logs/229876)

<div class="topic-metadata">

**Author:** [@priyanka\_j](https://discuss.elastic.co/u/priyanka_j)\
**Replies:** 1\
**Last updated:** [April 27, 2020, 4:16am UTC](https://discuss.elastic.co/t/parsing-the-filebeat-logs/229876 "2020-04-27T04:16:13Z")

</div>

Hi , I am using the filebeat to ship all my logs to the kibana using elasticsearch.I want to parse the log and create some fields from the logs .How can i do that. Thanks

---

## [AIX or Solaris logs to Kafka](https://discuss.elastic.co/t/aix-or-solaris-logs-to-kafka/228725)

<div class="topic-metadata">

**Author:** [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Replies:** 1\
**Last updated:** [April 19, 2020, 11:17pm UTC](https://discuss.elastic.co/t/aix-or-solaris-logs-to-kafka/228725 "2020-04-19T23:17:02Z")

</div>

Hi, I want to ship logs to kafka from AIX/Solaris clients? Any good beat/shipper apart from logstash or LSF ? I need something which can send logs to Kafka brokers in load balancing, over SSL. Please help in this rega…

---

## [Logs REST API](https://discuss.elastic.co/t/logs-rest-api/226068)

<div class="topic-metadata">

**Author:** [@Dawood](https://discuss.elastic.co/u/Dawood)\
**Replies:** 7\
**Last updated:** [April 15, 2020, 10:02am UTC](https://discuss.elastic.co/t/logs-rest-api/226068 "2020-04-15T10:02:07Z")

</div>

Hi, Is there a REST API to retrieve all logs(hits) by specific search ? Is there any examples? In elastic section i can not see that!! Thanks, Dawood

---

## [Kibana infra/logs displaying "undefined" for ECS-formatted events](https://discuss.elastic.co/t/kibana-infra-logs-displaying-undefined-for-ecs-formatted-events/226137)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 5\
**Last updated:** [April 14, 2020, 4:01pm UTC](https://discuss.elastic.co/t/kibana-infra-logs-displaying-undefined-for-ecs-formatted-events/226137 "2020-04-14T16:01:40Z")

</div>

I've spent quite a while reworking my apache/nginx Logstash filter to be ECS-compliant, mostly using the url and http field sets. The newly-formated events are indexing correctly and look fine in Kibana Discover, but in …

---

## [Error has occured trying to edit kibana-logs-ui-default-default-log-entry-categories-count ml job model memory limit](https://discuss.elastic.co/t/error-has-occured-trying-to-edit-kibana-logs-ui-default-default-log-entry-categories-count-ml-job-model-memory-limit/224264)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 18\
**Last updated:** [April 9, 2020, 6:45am UTC](https://discuss.elastic.co/t/error-has-occured-trying-to-edit-kibana-logs-ui-default-default-log-entry-categories-count-ml-job-model-memory-limit/224264 "2020-04-09T06:45:35Z")

</div>

Hello, It seems I hit hard limit for the memory ml model of 'kibana-logs-ui-default-default-log-entry-categories-count' So I stopped the datafeed, closed the job, edit the job and try to edit the Model memory limit f…

---

## [Logtrail performance](https://discuss.elastic.co/t/logtrail-performance/225989)

<div class="topic-metadata">

**Author:** [@Dawood](https://discuss.elastic.co/u/Dawood)\
**Replies:** 2\
**Last updated:** [April 1, 2020, 11:35am UTC](https://discuss.elastic.co/t/logtrail-performance/225989 "2020-04-01T11:35:53Z")

</div>

I have a question regarding Logtrail plugin in kibana. I am sending structured data from python using AsynchronousLogstashHandler: handler = AsynchronousLogstashHandler(host=self.logstash\_host, port=5045, database\_path=…

---

## [Configuring the default columns to appear in the log stream view](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497)

<div class="topic-metadata">

**Author:** [@Yomain](https://discuss.elastic.co/u/Yomain)\
**Replies:** 4\
**Last updated:** [March 30, 2020, 10:40am UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497 "2020-03-30T10:40:39Z")

</div>

Hi, I'm using the elk stack in docker and I am looking for a way to configure the default columns displayed in the log stream. Right now those default columns are timestamp, event.dataset and message. I can change them…

---

## [When are you planning to release v0.1.4?](https://discuss.elastic.co/t/when-are-you-planning-to-release-v0-1-4/224225)

<div class="topic-metadata">

**Author:** [@Bingu\_Shim](https://discuss.elastic.co/u/Bingu_Shim)\
**Replies:** 1\
**Last updated:** [March 19, 2020, 2:30pm UTC](https://discuss.elastic.co/t/when-are-you-planning-to-release-v0-1-4/224225 "2020-03-19T14:30:23Z")

</div>

Hello, I'm trying to apply ECS formatted logging using ECS Logging Java Libary to Spring Boot project with logback. It works well, but I want to add few custom fields, in order to filter out and make trend graph. I c…

---

## [Create Curator in Elastic Cloud](https://discuss.elastic.co/t/create-curator-in-elastic-cloud/221768)

<div class="topic-metadata">

**Author:** [@bmbrit](https://discuss.elastic.co/u/bmbrit)\
**Replies:** 9\
**Last updated:** [March 4, 2020, 10:38pm UTC](https://discuss.elastic.co/t/create-curator-in-elastic-cloud/221768 "2020-03-04T22:38:09Z")

</div>

Hi, Our team has a deployment in the elastic-cloud and we have purchased a standard cloud package. Now, I have a requirement to clear the indices older than 30 days due to storage issues. I tried to connect the cloud-se…

---

## [Pushing partly JSON log to ES with filebeat](https://discuss.elastic.co/t/pushing-partly-json-log-to-es-with-filebeat/221208)

<div class="topic-metadata">

**Author:** [@tuudik](https://discuss.elastic.co/u/tuudik)\
**Replies:** 2\
**Last updated:** [February 28, 2020, 10:58am UTC](https://discuss.elastic.co/t/pushing-partly-json-log-to-es-with-filebeat/221208 "2020-02-28T10:58:45Z")

</div>

Hi! Could someone give me some guidance, how to push audit.log which looks like below to ES? In Elasticsearch I would like to have timestamp which is the first one on the line and then information from JSON part: event…

---

## [GUID is not a configured index pattern ID Showing the default index pattern](https://discuss.elastic.co/t/guid-is-not-a-configured-index-pattern-id-showing-the-default-index-pattern/217405)

<div class="topic-metadata">

**Author:** [@daz1761](https://discuss.elastic.co/u/daz1761)\
**Replies:** 3\
**Last updated:** [February 3, 2020, 8:28am UTC](https://discuss.elastic.co/t/guid-is-not-a-configured-index-pattern-id-showing-the-default-index-pattern/217405 "2020-02-03T08:28:58Z")

</div>

I am new to ELK, and I have just spun up the containers including Filebeat via Docker Compose to read some dummy logs from a file (see https://github.com/moryachok/elasticstack-lab). When I go to the Discovery tab in Ki…

---

## [Sending Log4J logs (in XML) again](https://discuss.elastic.co/t/sending-log4j-logs-in-xml-again/215739)

<div class="topic-metadata">

**Author:** [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Replies:** 13\
**Last updated:** [January 30, 2020, 12:16pm UTC](https://discuss.elastic.co/t/sending-log4j-logs-in-xml-again/215739 "2020-01-30T12:16:03Z")

</div>

Hi, This is a follow up to an earlier post on a similar topic. I'm trying to send Log4j logs in XML format to Elasticsearch using Logstash. My XML file is: \<log4j:event logger="Common.Core.Sessions.SessionManager…

---

## [Unable to output elastalert.log](https://discuss.elastic.co/t/unable-to-output-elastalert-log/215477)

<div class="topic-metadata">

**Author:** [@Sansao](https://discuss.elastic.co/u/Sansao)\
**Replies:** 1\
**Last updated:** [January 27, 2020, 11:03am UTC](https://discuss.elastic.co/t/unable-to-output-elastalert-log/215477 "2020-01-27T11:03:23Z")

</div>

I need to remove elastalert information from /var/log/messages, and I'm having trouble creating a log file for elastalert. the default configuration in config.yaml doesn't work and i'm not getting it through the /etc/rs…

---

## [Detecting and Alerting on Log Loss from Logstash or beats](https://discuss.elastic.co/t/detecting-and-alerting-on-log-loss-from-logstash-or-beats/214482)

<div class="topic-metadata">

**Author:** [@ciphee](https://discuss.elastic.co/u/ciphee)\
**Replies:** 3\
**Last updated:** [January 16, 2020, 5:04pm UTC](https://discuss.elastic.co/t/detecting-and-alerting-on-log-loss-from-logstash-or-beats/214482 "2020-01-16T17:04:22Z")

</div>

Hello, I was trying to be able to detect/alert when either logstash or a beats product stops sendings logs. The problem in the past we have had is when a specific logstash server goes down, or is up but not sending any…

---

## [Sending Log4j logs ( in XML format) to Elasticsearch](https://discuss.elastic.co/t/sending-log4j-logs-in-xml-format-to-elasticsearch/214387)

<div class="topic-metadata">

**Author:** [@JY\_DT](https://discuss.elastic.co/u/JY_DT)\
**Replies:** 5\
**Last updated:** [January 16, 2020, 1:34pm UTC](https://discuss.elastic.co/t/sending-log4j-logs-in-xml-format-to-elasticsearch/214387 "2020-01-16T13:34:43Z")

</div>

Hello, I need to send log files generated using Log4j on client machines to Elasticsearch installed on a server. The logs are in XML format. Is there any other plugin, etc required, or can it just be done using Filebea…

---

## [Message: "failed to find message" in Kibana Logs](https://discuss.elastic.co/t/message-failed-to-find-message-in-kibana-logs/210522)

<div class="topic-metadata">

**Author:** [@jmteba](https://discuss.elastic.co/u/jmteba)\
**Replies:** 2\
**Last updated:** [December 10, 2019, 11:08am UTC](https://discuss.elastic.co/t/message-failed-to-find-message-in-kibana-logs/210522 "2019-12-10T11:08:06Z")

</div>

Hello, We have a problem when we try to see logs from Kibana "Logs", so we get this message: "failed to find message", failed\_to\_find\_message|690x424 but in this path there are multiple log's files. failed\_to\_find\_m…

---

## [How to see the surrounding documents in kibana v7.4.2 log tab](https://discuss.elastic.co/t/how-to-see-the-surrounding-documents-in-kibana-v7-4-2-log-tab/208834)

<div class="topic-metadata">

**Author:** [@111244](https://discuss.elastic.co/u/111244)\
**Replies:** 2\
**Last updated:** [November 25, 2019, 8:37am UTC](https://discuss.elastic.co/t/how-to-see-the-surrounding-documents-in-kibana-v7-4-2-log-tab/208834 "2019-11-25T08:37:13Z")

</div>

how to see the surrounding documents in kibana v7.4.2 log tab? i can't find this link

---

## [Apache/nginx logs wrapped in syslog format](https://discuss.elastic.co/t/apache-nginx-logs-wrapped-in-syslog-format/207211)

<div class="topic-metadata">

**Author:** [@w\_o\_j\_t\_e\_k](https://discuss.elastic.co/u/w_o_j_t_e_k)\
**Replies:** 2\
**Last updated:** [November 11, 2019, 10:40am UTC](https://discuss.elastic.co/t/apache-nginx-logs-wrapped-in-syslog-format/207211 "2019-11-11T10:40:33Z")

</div>

Hi, I've got a centralized log server that receives apache + nginx logs. I would like to use filebeat on this box to forward these logs into elastic. The logs are wrapped in the syslog format, e.q: 2019-11-09T11:50:5…

---

## [Logs in Logstash / archive](https://discuss.elastic.co/t/logs-in-logstash-archive/205640)

<div class="topic-metadata">

**Author:** [@juuuhuuu](https://discuss.elastic.co/u/juuuhuuu)\
**Replies:** 5\
**Last updated:** [October 30, 2019, 12:24pm UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640 "2019-10-30T12:24:00Z")

</div>

Hello, Im new in elastic. I would like to know, for how long the logs are "active " in logstash. Can I archive them, if yes how? Thank you

---

## [LogsUI in kibana 7.4.0 getting error when trying to look at the logs with date\_nanos](https://discuss.elastic.co/t/logsui-in-kibana-7-4-0-getting-error-when-trying-to-look-at-the-logs-with-date-nanos/204335)

<div class="topic-metadata">

**Author:** [@Alex-St](https://discuss.elastic.co/u/Alex-St)\
**Replies:** 3\
**Last updated:** [October 23, 2019, 9:55pm UTC](https://discuss.elastic.co/t/logsui-in-kibana-7-4-0-getting-error-when-trying-to-look-at-the-logs-with-date-nanos/204335 "2019-10-23T21:55:25Z")

</div>

open logs UI - configure to use SourceTime which is in date\_nanos instead of @timestamp field, logsUI tries to load data for several seconds, then displays graphics on the left side (timeline), and briefly shows the logs…

---

## [Unifying Log4j 2 layouts and EcsLayout](https://discuss.elastic.co/t/unifying-log4j-2-layouts-and-ecslayout/197698)

<div class="topic-metadata">

**Author:** [@vyazici](https://discuss.elastic.co/u/vyazici)\
**Replies:** 8\
**Last updated:** [October 10, 2019, 11:07am UTC](https://discuss.elastic.co/t/unifying-log4j-2-layouts-and-ecslayout/197698 "2019-10-10T11:07:29Z")

</div>

Dear fellow Elastic developers, I am the maintainer of the log4j2-logstash-layout project, the fastest and the only fully customizable JSON layout plugin for Log4j 2: LogstashLayout. A couple of days ago (2019-08-30) Fe…

---

## [How to esclude from filebeat this log](https://discuss.elastic.co/t/how-to-esclude-from-filebeat-this-log/202303)

<div class="topic-metadata">

**Author:** [@mirketto82](https://discuss.elastic.co/u/mirketto82)\
**Replies:** 3\
**Last updated:** [October 7, 2019, 11:08am UTC](https://discuss.elastic.co/t/how-to-esclude-from-filebeat-this-log/202303 "2019-10-07T11:08:47Z")

</div>

hi all i want to exclude from filebeat this logs? at org.apache.camel.spring.spi.TransactionErrorHandler.process(TransactionErrorHandler.java:101) Oct 4, 2019 @ 10:27:45 at org.apache.camel.spring.spi.TransactionErro…

---

## [Java-ecs-logging](https://discuss.elastic.co/t/java-ecs-logging/201266)

<div class="topic-metadata">

**Author:** [@Rem](https://discuss.elastic.co/u/Rem)\
**Replies:** 6\
**Last updated:** [October 1, 2019, 10:21am UTC](https://discuss.elastic.co/t/java-ecs-logging/201266 "2019-10-01T10:21:39Z")

</div>

Hi, Hope there is someone that can help me. Config.xml for Log4j2 : \<Console name="LogToConsole" target="SYSTEM\_OUT"\> \<Appenders\> \<Console name="LogToConsole" target="SYSTEM\_OUT"\> \<EcsLayout\> \<KeyValuePair k…

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md?page=5)

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=7)
