# Logs

**URL:** https://discuss.elastic.co/c/observability/logs/69.md?page=8

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 9

---

## [How to use the log tail feature in Kibana 6.5.4](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658)

<div class="topic-metadata">

**Author:** [@akhisar](https://discuss.elastic.co/u/akhisar)\
**Replies:** 3\
**Last updated:** [January 29, 2019, 11:40am UTC](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658 "2019-01-29T11:40:58Z")

</div>

Hello All, I am using fluentd as my log shipper for kubernetes microservices. I have read that the new kibana version have the log tailing feature for viewing the changes in the logs. Can someone guide me how it can wor…

---

## [Failed to format message from \*](https://discuss.elastic.co/t/failed-to-format-message-from/165728)

<div class="topic-metadata">

**Author:** [@Code](https://discuss.elastic.co/u/Code)\
**Replies:** 4\
**Last updated:** [January 28, 2019, 11:28am UTC](https://discuss.elastic.co/t/failed-to-format-message-from/165728 "2019-01-28T11:28:13Z")

</div>

I want to see the detail from my server's IIS logs , and I found that kibana cannot format the information of IIS logs. Pls tell what measure should i do ,so I can see the logs' detail. thank you

---

## [Filebeat fails to process kibana json logs "failed to format message from \*json-.log "in a kubernetes enviroment](https://discuss.elastic.co/t/filebeat-fails-to-process-kibana-json-logs-failed-to-format-message-from-json-log-in-a-kubernetes-enviroment/163558)

<div class="topic-metadata">

**Author:** [@paltaa](https://discuss.elastic.co/u/paltaa)\
**Replies:** 16\
**Last updated:** [January 24, 2019, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-fails-to-process-kibana-json-logs-failed-to-format-message-from-json-log-in-a-kubernetes-enviroment/163558 "2019-01-24T14:21:57Z")

</div>

So ive mounted ELK stack with filebeat in a kubernetes enviroment, im parsing all the logs correctly, only problem is the kibana json-logs format that get error failed to format message from /var/lib/docker/containers/…

---

## [How to charge for three elk software](https://discuss.elastic.co/t/how-to-charge-for-three-elk-software/165507)

<div class="topic-metadata">

**Author:** [@wcfCode](https://discuss.elastic.co/u/wcfCode)\
**Replies:** 4\
**Last updated:** [January 24, 2019, 1:37am UTC](https://discuss.elastic.co/t/how-to-charge-for-three-elk-software/165507 "2019-01-24T01:37:58Z")

</div>

How to charge for three elk software

---

## [How to set a range in Logs UI](https://discuss.elastic.co/t/how-to-set-a-range-in-logs-ui/164244)

<div class="topic-metadata">

**Author:** [@makefriend7](https://discuss.elastic.co/u/makefriend7)\
**Replies:** 3\
**Last updated:** [January 18, 2019, 8:41am UTC](https://discuss.elastic.co/t/how-to-set-a-range-in-logs-ui/164244 "2019-01-18T08:41:41Z")

</div>

In es we can do this GET \_search { "\_source":\["message"\], "query": { "range" : { "my.time": { "gte" : "20190113-09:15:57", "lte" : "20190114-10:15:57" } } } } Is it possible in Logs UI?

---

## [ELK 6.5.4](https://discuss.elastic.co/t/elk-6-5-4/163920)

<div class="topic-metadata">

**Author:** [@Denisboud](https://discuss.elastic.co/u/Denisboud)\
**Replies:** 2\
**Last updated:** [January 16, 2019, 6:48pm UTC](https://discuss.elastic.co/t/elk-6-5-4/163920 "2019-01-16T18:48:28Z")

</div>

Hello everybody, My objective is to facilitate and customize the display of alerts (format date, recover the real PID of the log before transformation, etc...) Early January 2019, installation Docker ELK 6.5.4 (Wazuh, …

---

## [Stream live not updating](https://discuss.elastic.co/t/stream-live-not-updating/163734)

<div class="topic-metadata">

**Author:** [@aviator](https://discuss.elastic.co/u/aviator)\
**Replies:** 5\
**Last updated:** [January 10, 2019, 3:53pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734 "2019-01-10T15:53:02Z")

</div>

Hi When using the Stream Live feature the logs do not get updated in realtime, the logs are there because a page refresh displays them. I think the key is that each time I load up the Logs app the newest/latest entry i…

---

## [Log UI failed to format message from](https://discuss.elastic.co/t/log-ui-failed-to-format-message-from/163196)

<div class="topic-metadata">

**Author:** [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Replies:** 4\
**Last updated:** [January 7, 2019, 6:30pm UTC](https://discuss.elastic.co/t/log-ui-failed-to-format-message-from/163196 "2019-01-07T18:30:51Z")

</div>

Hi, I was looking in to Logs UI and I have setup filebeat to send the logs over to ES. However all I see in the Logs UI is an error message saying Failed to format message from /opt/logstash/logs/logstash-plain.log Do…

---

## [Differences between Discover and Logs?](https://discuss.elastic.co/t/differences-between-discover-and-logs/161184)

<div class="topic-metadata">

**Author:** [@phr0gz](https://discuss.elastic.co/u/phr0gz)\
**Replies:** 4\
**Last updated:** [January 7, 2019, 4:15pm UTC](https://discuss.elastic.co/t/differences-between-discover-and-logs/161184 "2019-01-07T16:15:11Z")

</div>

Hello, The live stream feature seems really nice! But I'm a little bit confused about this functionality: It looks like the same as the "Discover" view...isn't it? We are already using the Elastic stack as a "big" far…

---

## [Logs UI disable "failed to find message" line](https://discuss.elastic.co/t/logs-ui-disable-failed-to-find-message-line/162958)

<div class="topic-metadata">

**Author:** [@Eilyre](https://discuss.elastic.co/u/Eilyre)\
**Replies:** 2\
**Last updated:** [January 4, 2019, 1:06pm UTC](https://discuss.elastic.co/t/logs-ui-disable-failed-to-find-message-line/162958 "2019-01-04T13:06:55Z")

</div>

Hello! Loving the new Logs UI functionality. Makes checking the logs of distributed systems much quicker and more pleasant to use. While it works well, there's one pet peeve I have - when a document does not have the "…

---

## [Logs UI beta, how it works !?](https://discuss.elastic.co/t/logs-ui-beta-how-it-works/157430)

<div class="topic-metadata">

**Author:** [@dimuskin](https://discuss.elastic.co/u/dimuskin)\
**Replies:** 7\
**Last updated:** [January 3, 2019, 10:22am UTC](https://discuss.elastic.co/t/logs-ui-beta-how-it-works/157430 "2019-01-03T10:22:02Z")

</div>

Hello, I finally upgraded to ES 6.5 and was pleasantly surprised by the innovations. Really liked the feature Logs UI (watching logs in real time), but unfortunately I did not find a description of her work. Documenta…

---

## [Multiple fields instead of message](https://discuss.elastic.co/t/multiple-fields-instead-of-message/161301)

<div class="topic-metadata">

**Author:** [@phr0gz](https://discuss.elastic.co/u/phr0gz)\
**Replies:** 1\
**Last updated:** [December 21, 2018, 9:47am UTC](https://discuss.elastic.co/t/multiple-fields-instead-of-message/161301 "2018-12-21T09:47:54Z")

</div>

Hello, is there any plan to add multiple fields instead of @message/message ? Because in my case to avoid redundant fields we drop the message field when the message is parsed.

---

## [Show hostname or source path](https://discuss.elastic.co/t/show-hostname-or-source-path/158229)

<div class="topic-metadata">

**Author:** [@benpolzin](https://discuss.elastic.co/u/benpolzin)\
**Replies:** 1\
**Last updated:** [November 28, 2018, 6:30pm UTC](https://discuss.elastic.co/t/show-hostname-or-source-path/158229 "2018-11-28T18:30:39Z")

</div>

The new infinite scroll feature of the Logs UI is fantastic! Thanks! I'm finding that I really miss the context of my logs, though. In the Discover view I frequently add hostname or the source path as columns because I …

---

## [Which indexes does the new Infrastructure / Logs feature use?](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920)

<div class="topic-metadata">

**Author:** [@Matin\_Nayob](https://discuss.elastic.co/u/Matin_Nayob)\
**Replies:** 3\
**Last updated:** [November 28, 2018, 6:26pm UTC](https://discuss.elastic.co/t/which-indexes-does-the-new-infrastructure-logs-feature-use/157920 "2018-11-28T18:26:21Z")

</div>

The new logs feature in Kibana 6.5.0 only seems to display live logs from a subset of my indexes. Is there a way to configure this yet? I've tried adding specific indexes to the filter, but it doesnt display any data. T…

---

## [Catenate two fields as message](https://discuss.elastic.co/t/catenate-two-fields-as-message/157243)

<div class="topic-metadata">

**Author:** [@Anton1](https://discuss.elastic.co/u/Anton1)\
**Replies:** 3\
**Last updated:** [November 19, 2018, 10:57am UTC](https://discuss.elastic.co/t/catenate-two-fields-as-message/157243 "2018-11-19T10:57:35Z")

</div>

I got the logs ui working with my own index. However, message and loglevel are two different fields. Is it possible to catenate level and message so that both are shown in logs ui?

---

## [Does the same filtering that works for Discover also work for Logs? So far it's not for me](https://discuss.elastic.co/t/does-the-same-filtering-that-works-for-discover-also-work-for-logs-so-far-its-not-for-me/157123)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 3\
**Last updated:** [November 16, 2018, 10:26pm UTC](https://discuss.elastic.co/t/does-the-same-filtering-that-works-for-discover-also-work-for-logs-so-far-its-not-for-me/157123 "2018-11-16T22:26:55Z")

</div>

I've got Logs working, I think it's going to be a really helpful feature. I do have one question though. Here's an example of a query that works in Discovery but if I try it in Logs it says " There are no log messages …

---

## ["Looks like you don't have any logging indices"](https://discuss.elastic.co/t/looks-like-you-dont-have-any-logging-indices/156915)

<div class="topic-metadata">

**Author:** [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Replies:** 7\
**Last updated:** [November 16, 2018, 10:18am UTC](https://discuss.elastic.co/t/looks-like-you-dont-have-any-logging-indices/156915 "2018-11-16T10:18:30Z")

</div>

I'm trying to figure out what constitutes a "logging index" - I'm getting the message " Looks like you don't have any logging indices" when testing the new "Logs" app in Kibana, but I can't find any documentation around …

---

## [Elastic stack 6.5 Logs UI](https://discuss.elastic.co/t/elastic-stack-6-5-logs-ui/156960)

<div class="topic-metadata">

**Author:** [@shradhatx](https://discuss.elastic.co/u/shradhatx)\
**Replies:** 2\
**Last updated:** [November 16, 2018, 9:49am UTC](https://discuss.elastic.co/t/elastic-stack-6-5-logs-ui/156960 "2018-11-16T09:49:09Z")

</div>

Where can I get more information on it? Is it a consolidated dashboard of MetricBeat and APM?

[Previous page](https://discuss.elastic.co/c/observability/logs/69.md?page=7)
