# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=7

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 8

---

## [Log parsing in logstash](https://discuss.elastic.co/t/log-parsing-in-logstash/201313)

<div class="topic-metadata">

**Author:** [@sk545](https://discuss.elastic.co/u/sk545)\
**Replies:** 3\
**Last updated:** [September 27, 2019, 10:31pm UTC](https://discuss.elastic.co/t/log-parsing-in-logstash/201313 "2019-09-27T22:31:44Z")

</div>

I am wondering , how can i parse below sample event into relevant fields in logstash ?currently i am not seeing any fields from this log in Kibana UI {"COMPILATION\_TIME":40,"DATABASE\_ID":19,"DATABASE\_NAME":"EEERD","END…

---

## [Parse syslog-ng log to elasticsearch](https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830)

<div class="topic-metadata">

**Author:** [@ravipemmasani](https://discuss.elastic.co/u/ravipemmasani)\
**Replies:** 2\
**Last updated:** [September 4, 2019, 8:48am UTC](https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830 "2019-09-04T08:48:52Z")

</div>

Hi All, Iam glad to join this group. Basically i'm in the midst of setting up POC for centralize log collection and analyse the log. Following is my setup on RHEL 7.6. Syslog-ng-collect log from remote clients Elast…

---

## [Filebeats not working in 7.x, and front end app logging](https://discuss.elastic.co/t/filebeats-not-working-in-7-x-and-front-end-app-logging/197240)

<div class="topic-metadata">

**Author:** [@ngg971](https://discuss.elastic.co/u/ngg971)\
**Replies:** 1\
**Last updated:** [August 30, 2019, 9:22am UTC](https://discuss.elastic.co/t/filebeats-not-working-in-7-x-and-front-end-app-logging/197240 "2019-08-30T09:22:13Z")

</div>

Hi, I’ve been using the ELK stack to capture our logs from our Kubernetes cluster. I had filebeats setup on the cluster and everything was working fine until I updated from 6.7 to 7.3 (I also updated the docker image th…

---

## [How I can send logs from filebeat to Elasticsearch in another GKE](https://discuss.elastic.co/t/how-i-can-send-logs-from-filebeat-to-elasticsearch-in-another-gke/193372)

<div class="topic-metadata">

**Author:** [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Replies:** 1\
**Last updated:** [August 8, 2019, 11:27am UTC](https://discuss.elastic.co/t/how-i-can-send-logs-from-filebeat-to-elasticsearch-in-another-gke/193372 "2019-08-08T11:27:42Z")

</div>

Hi! I have two GKE clusters in different GCP projects. GKE clusters: 1) GKE-ELASTIC (with kibana and elastic) 2) GKE-APPS (with my microservices) In the GKE-APPs I disabled the gke logging, because I want to redirec…

---

## [Multiple custom grok patterns not matching, but they successfully match alone?](https://discuss.elastic.co/t/multiple-custom-grok-patterns-not-matching-but-they-successfully-match-alone/193175)

<div class="topic-metadata">

**Author:** [@kmiklas](https://discuss.elastic.co/u/kmiklas)\
**Replies:** 2\
**Last updated:** [August 6, 2019, 1:28pm UTC](https://discuss.elastic.co/t/multiple-custom-grok-patterns-not-matching-but-they-successfully-match-alone/193175 "2019-08-06T13:28:20Z")

</div>

Grok matches single custom patterns, but does match when custom patterns are combined. Complete, working, an verifiable example Sample data: OK 05/20 20:12:10:067 ABC\_02~~DE\_02 FGH\_IJK jsmith \_A0011 Custom patterns: …

---

## [Filebeat docker input](https://discuss.elastic.co/t/filebeat-docker-input/192657)

<div class="topic-metadata">

**Author:** [@mihaijulien](https://discuss.elastic.co/u/mihaijulien)\
**Replies:** 4\
**Last updated:** [August 1, 2019, 8:21am UTC](https://discuss.elastic.co/t/filebeat-docker-input/192657 "2019-08-01T08:21:43Z")

</div>

Hello, I have the following filebeat.yml file: filebeat.config: modules: path: ${path.config}/modules.d/\*.yml reload.enabled: false #================================ Logging =================================…

---

## [Log4net implemenation with elastic stack 7.2](https://discuss.elastic.co/t/log4net-implemenation-with-elastic-stack-7-2/191508)

<div class="topic-metadata">

**Author:** [@herzel](https://discuss.elastic.co/u/herzel)\
**Replies:** 2\
**Last updated:** [July 23, 2019, 11:10am UTC](https://discuss.elastic.co/t/log4net-implemenation-with-elastic-stack-7-2/191508 "2019-07-23T11:10:26Z")

</div>

Hi. Thanks a lot in advance for any reply. I have mission from my boss to apply elastic stack 7.2 with log4net. can not find any howto in the web. can anyone help with this issue. I need howto that will explain how…

---

## [Grok pattern / content management](https://discuss.elastic.co/t/grok-pattern-content-management/188162)

<div class="topic-metadata">

**Author:** [@anon15412260](https://discuss.elastic.co/u/anon15412260)\
**Replies:** 1\
**Last updated:** [June 30, 2019, 1:46am UTC](https://discuss.elastic.co/t/grok-pattern-content-management/188162 "2019-06-30T01:46:59Z")

</div>

Is there any ability in the platform today to build out grok patterns within the UI and distribute them to filebeats agents or push these into updated logstash pipelines? If not, could this be a feature request? Would be…

---

## [Upload my logs from node to ElasticSearch](https://discuss.elastic.co/t/upload-my-logs-from-node-to-elasticsearch/187003)

<div class="topic-metadata">

**Author:** [@Shahar-Y](https://discuss.elastic.co/u/Shahar-Y)\
**Replies:** 3\
**Last updated:** [June 24, 2019, 5:55pm UTC](https://discuss.elastic.co/t/upload-my-logs-from-node-to-elasticsearch/187003 "2019-06-24T17:55:58Z")

</div>

Hi, I'm new to ElasticSearch. I want my application to upload its logs while it's running - to my ElasticSearch server. My application is using node (typescript), and I can't understand how to upload a JSON log I creat…

---

## [Support multiple sources](https://discuss.elastic.co/t/support-multiple-sources/184117)

<div class="topic-metadata">

**Author:** [@tomeri](https://discuss.elastic.co/u/tomeri)\
**Replies:** 1\
**Last updated:** [June 4, 2019, 9:00am UTC](https://discuss.elastic.co/t/support-multiple-sources/184117 "2019-06-04T09:00:25Z")

</div>

Hi, I don't know if this already implemented, but I think it'll be helpful to add an option for configuring multiple sources then display them as a dropdown for quick navigation between the different sources without th…

---

## [Kibana logs are not in order 6.7 version](https://discuss.elastic.co/t/kibana-logs-are-not-in-order-6-7-version/181887)

<div class="topic-metadata">

**Author:** [@Rampsrr](https://discuss.elastic.co/u/Rampsrr)\
**Replies:** 1\
**Last updated:** [May 28, 2019, 12:57pm UTC](https://discuss.elastic.co/t/kibana-logs-are-not-in-order-6-7-version/181887 "2019-05-28T12:57:20Z")

</div>

Filebeat-- logstash - - elastic search - - kibana Version all 6.7 It is not working both scenario #10005 ticket, since in real time i have more log lines of 10 to 15 have same @timestamp with respective to seconds but…

---

## [Configure multiple servers logs into single kibana dashboard](https://discuss.elastic.co/t/configure-multiple-servers-logs-into-single-kibana-dashboard/180931)

<div class="topic-metadata">

**Author:** [@pavansai](https://discuss.elastic.co/u/pavansai)\
**Replies:** 15\
**Last updated:** [May 21, 2019, 8:23am UTC](https://discuss.elastic.co/t/configure-multiple-servers-logs-into-single-kibana-dashboard/180931 "2019-05-21T08:23:41Z")

</div>

Please assist how to configure multiple servers logs into single kibana dashboard

---

## [Logs UI along with spaces](https://discuss.elastic.co/t/logs-ui-along-with-spaces/177212)

<div class="topic-metadata">

**Author:** [@sl1729](https://discuss.elastic.co/u/sl1729)\
**Replies:** 5\
**Last updated:** [May 8, 2019, 2:23pm UTC](https://discuss.elastic.co/t/logs-ui-along-with-spaces/177212 "2019-05-08T14:23:03Z")

</div>

I created a space called 'dev' and then created objects like index-pattern, visualization and dashboards etc .. And then a role with read permission to that space and read access to the related indexes. Created a user 'd…

---

## [Roles related to infra UI](https://discuss.elastic.co/t/roles-related-to-infra-ui/176129)

<div class="topic-metadata">

**Author:** [@sl1729](https://discuss.elastic.co/u/sl1729)\
**Replies:** 4\
**Last updated:** [April 17, 2019, 7:21am UTC](https://discuss.elastic.co/t/roles-related-to-infra-ui/176129 "2019-04-17T07:21:43Z")

</div>

We are experimenting infra UI and logs UI. Going good so far, except few known issues which are getting discussed in forum. But when providing access to the users we are having difficulty. We have a scenario where we ne…

---

## [Stream logs to elastic search from Fastly](https://discuss.elastic.co/t/stream-logs-to-elastic-search-from-fastly/176217)

<div class="topic-metadata">

**Author:** [@soerenfrisk](https://discuss.elastic.co/u/soerenfrisk)\
**Replies:** 3\
**Last updated:** [April 12, 2019, 1:38pm UTC](https://discuss.elastic.co/t/stream-logs-to-elastic-search-from-fastly/176217 "2019-04-12T13:38:12Z")

</div>

I'm trying to find a way to stream logs from fastly.com to an elastic cloud service. According to Fastly's docs you are only able to do this through Logstash (which is not included in the cloud service). It seems impract…

---

## [Capturing logs from a browser (SPA)](https://discuss.elastic.co/t/capturing-logs-from-a-browser-spa/175159)

<div class="topic-metadata">

**Author:** [@Matt\_Russell](https://discuss.elastic.co/u/Matt_Russell)\
**Replies:** 1\
**Last updated:** [April 5, 2019, 8:57am UTC](https://discuss.elastic.co/t/capturing-logs-from-a-browser-spa/175159 "2019-04-05T08:57:13Z")

</div>

I wondered if anyone had any good patterns or advice on collecting logs from a single-page application (SPA) running in user browsers and getting them into Elasticsearch? I guess one approach might be to post AJAX to a /…

---

## [Setting up logs functionality with fluentd](https://discuss.elastic.co/t/setting-up-logs-functionality-with-fluentd/169923)

<div class="topic-metadata">

**Author:** [@Erik\_Tribou](https://discuss.elastic.co/u/Erik_Tribou)\
**Replies:** 4\
**Last updated:** [April 3, 2019, 1:07pm UTC](https://discuss.elastic.co/t/setting-up-logs-functionality-with-fluentd/169923 "2019-04-03T13:07:45Z")

</div>

I'm using elasticsearch and kibana 6.5.1 and trying to get the logs functionality working with logs we are inserting via fluentd. Unfortunately all I'm getting is message that no logs can be found and to adjust my filte…

---

## [Sebp/ELK with PFSense](https://discuss.elastic.co/t/sebp-elk-with-pfsense/173576)

<div class="topic-metadata">

**Author:** [@stinkfly](https://discuss.elastic.co/u/stinkfly)\
**Replies:** 4\
**Last updated:** [April 2, 2019, 12:03am UTC](https://discuss.elastic.co/t/sebp-elk-with-pfsense/173576 "2019-04-02T00:03:49Z")

</div>

Hi team, I've setup sebp/ELK (https://elk-docker.readthedocs.io/), GitHub here https://hub.docker.com/r/sebp/elk/ with ELK 6.6.1 Winlogbeat and Metricbeat work ok sending from a Windows 2016 server Syslog from PFSense…

---

## [How to collecting all elasticsearch clusters monitoring data to one elasticsearch using logstash or metricBeat](https://discuss.elastic.co/t/how-to-collecting-all-elasticsearch-clusters-monitoring-data-to-one-elasticsearch-using-logstash-or-metricbeat/174025)

<div class="topic-metadata">

**Author:** [@Kevins\_Si](https://discuss.elastic.co/u/Kevins_Si)\
**Replies:** 2\
**Last updated:** [March 28, 2019, 2:25pm UTC](https://discuss.elastic.co/t/how-to-collecting-all-elasticsearch-clusters-monitoring-data-to-one-elasticsearch-using-logstash-or-metricbeat/174025 "2019-03-28T14:25:37Z")

</div>

is there any info that collecting all elasticsearch clusters monitoring data to one elasticsearch using logstash or metricBeat?? we want to collecting many clusters monitoring log data to one. and keep as normal view as…

---

## [Kibana maps not showing locations](https://discuss.elastic.co/t/kibana-maps-not-showing-locations/172331)

<div class="topic-metadata">

**Author:** [@sc1](https://discuss.elastic.co/u/sc1)\
**Replies:** 10\
**Last updated:** [March 26, 2019, 4:32pm UTC](https://discuss.elastic.co/t/kibana-maps-not-showing-locations/172331 "2019-03-26T16:32:57Z")

</div>

Hello, I have noticed that any map I have on a dashboard isn't showing the geolocations. For example, the sample dashboards from Filebeat showing attempted SSHs loads the dashboards, but it doesn't plot where any of the…

---

## [Need help with parsing json fields](https://discuss.elastic.co/t/need-help-with-parsing-json-fields/172686)

<div class="topic-metadata">

**Author:** [@Adrian\_Hove](https://discuss.elastic.co/u/Adrian_Hove)\
**Replies:** 3\
**Last updated:** [March 18, 2019, 4:47pm UTC](https://discuss.elastic.co/t/need-help-with-parsing-json-fields/172686 "2019-03-18T16:47:17Z")

</div>

I have a sweet log I am trying to parse into JSON. \[2019-03-16 00:00:00\] production.INFO {"timestamp":1552694400,"execution\_time":0.0272369384765625} my default logstash config input { beats { port =\> 5044 } }…

---

## [Create filter](https://discuss.elastic.co/t/create-filter/172282)

<div class="topic-metadata">

**Author:** [@nejmeddine\_ammar](https://discuss.elastic.co/u/nejmeddine_ammar)\
**Replies:** 3\
**Last updated:** [March 18, 2019, 11:56am UTC](https://discuss.elastic.co/t/create-filter/172282 "2019-03-18T11:56:44Z")

</div>

i 'am new in ELK , can you help me to create grok for the data :slight\_smile:

---

## [FileBeat not forwarding My IIS logs to elastic search](https://discuss.elastic.co/t/filebeat-not-forwarding-my-iis-logs-to-elastic-search/170972)

<div class="topic-metadata">

**Author:** [@syedsfayaz](https://discuss.elastic.co/u/syedsfayaz)\
**Replies:** 6\
**Last updated:** [March 7, 2019, 3:34pm UTC](https://discuss.elastic.co/t/filebeat-not-forwarding-my-iis-logs-to-elastic-search/170972 "2019-03-07T15:34:28Z")

</div>

Hi Guys I am very new to Elastic stack. I am trying to setup a dashboard to monitor IIS logs. But the file beats is not working as expected. Here is my configuration. Installed Version:6.6.1 Kibana, Elastic Search, F…

---

## [Error on the Logs page in Kibana on Elastic cloud hosted on AWS](https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261)

<div class="topic-metadata">

**Author:** [@ajazam1](https://discuss.elastic.co/u/ajazam1)\
**Replies:** 2\
**Last updated:** [February 21, 2019, 9:26am UTC](https://discuss.elastic.co/t/error-on-the-logs-page-in-kibana-on-elastic-cloud-hosted-on-aws/169261 "2019-02-21T09:26:06Z")

</div>

We are using the Elastic Cloud hosted solution on AWS at version 6.6.1. We are using filebeats 6.6.0 and the IIS module to parse IIS 10 logs into Elastic Search. When we look at the logs page we are seeing many failed …

---

## [Fluent Bit Filter for by PODs (calico-pod) in kubernetes?](https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975)

<div class="topic-metadata">

**Author:** [@JDev](https://discuss.elastic.co/u/JDev)\
**Replies:** 2\
**Last updated:** [February 19, 2019, 10:31am UTC](https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975 "2019-02-19T10:31:09Z")

</div>

Hi, I installed fluentbit with default settings. I like that the fluent bit adds additional information (the name of the container). But he writes in the index everything. How do I do better? How to add a filter so that…

---

## [Automated log search and reporting](https://discuss.elastic.co/t/automated-log-search-and-reporting/168447)

<div class="topic-metadata">

**Author:** [@kladizkov](https://discuss.elastic.co/u/kladizkov)\
**Replies:** 2\
**Last updated:** [February 14, 2019, 6:18pm UTC](https://discuss.elastic.co/t/automated-log-search-and-reporting/168447 "2019-02-14T18:18:41Z")

</div>

Hi, I'm new to ELK. I have completed setting up ElasticSearch, Logstash and Kibana. I have 20+ servers to manage. As it is not easy to manually look for errors and warning in the logs, I think there should be something …

---

## [Does Logs UI / Infrastructure UI supported under Cross Cluster Search?](https://discuss.elastic.co/t/does-logs-ui-infrastructure-ui-supported-under-cross-cluster-search/167749)

<div class="topic-metadata">

**Author:** [@tomeri](https://discuss.elastic.co/u/tomeri)\
**Replies:** 1\
**Last updated:** [February 11, 2019, 10:25am UTC](https://discuss.elastic.co/t/does-logs-ui-infrastructure-ui-supported-under-cross-cluster-search/167749 "2019-02-11T10:25:09Z")

</div>

I tried to set xpack.infra.sources.default.logAlias within the Kibana configuration to something like MyClusterA:MyIndexAlias, in order to point the Logs UI to a remote index, but nothing showing under the Logs/Infrastru…

---

## [Logs module](https://discuss.elastic.co/t/logs-module/167449)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [February 8, 2019, 8:49pm UTC](https://discuss.elastic.co/t/logs-module/167449 "2019-02-08T20:49:09Z")

</div>

Hi all, We have a lot of long multiline logs which are outputting a lot of information like stacktraces, error hints, request body, response body, return codes, etc. So way to much to be really readable in a single mes…

---

## [Can we add syntax color to Logs module?](https://discuss.elastic.co/t/can-we-add-syntax-color-to-logs-module/163753)

<div class="topic-metadata">

**Author:** [@Gael\_RICHIER](https://discuss.elastic.co/u/Gael_RICHIER)\
**Replies:** 4\
**Last updated:** [January 31, 2019, 6:16am UTC](https://discuss.elastic.co/t/can-we-add-syntax-color-to-logs-module/163753 "2019-01-31T06:16:43Z")

</div>

Hello everybody ! I'll like to know if we can set color syntax for log through logs module ? Example for syslog or auth log. (Error =\> RED / WARNING =\> ORANGE ....) Thanks

---

## [Logs UI - Selectable message fields?](https://discuss.elastic.co/t/logs-ui-selectable-message-fields/166051)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 2\
**Last updated:** [January 29, 2019, 11:22pm UTC](https://discuss.elastic.co/t/logs-ui-selectable-message-fields/166051 "2019-01-29T23:22:13Z")

</div>

I'd like to use the Logs UI for a bit more than plain syslog (e.g., Apache all the logs) however I can't get it to display anything other than a plain message field. This is not ideal when displaying non-syslog logs for…

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md?page=6)

[Next page](https://discuss.elastic.co/c/observability/logs/69.md?page=8)
