# APM .net agent see the Service Name in the logs for correlated transactions

**URL:** <https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137>\
**Category:** APM\
**Tags:** docker, dotnet, language-clients\
**Created:** [August 1, 2022, 3:39pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137 "2022-08-01T15:39:55Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [August 1, 2022, 3:39pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/1 "2022-08-01T15:39:55Z")

</div>

**Kibana version** :  
7.16.3 (Docker)

**Elasticsearch version** :  
7.16.3 (Docker)

**APM Server version** :  
7.16.3 (Docker)

**APM Agent language and version** :  
.net

```auto
    <PackageReference Include="Elastic.Apm.NetCoreAll" Version="1.16.1" />
    <PackageReference Include="Elastic.Apm.SerilogEnricher" Version="1.5.3" />
    <PackageReference Include="Elastic.Apm.StackExchange.Redis" Version="1.16.1" />

```

**Description of the problem including expected versus actual behavior. Please include screenshots (if relevant)**:  
Hi,  
I use correlated transactions across multiple microservices (.net 6) using the .net APM agent, it works pretty well.  
My problem is about logs, I don't know why the Service Name does not appear, so that I'm not able to distinguish which log belongs to which microservice.

Example here is an example of a correlated transaction

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/0/7071199d560dae9a137f2efb234ba1eb94a44733.png)

and the corresponding logs, but with an empty Service Name column

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3d3e97b8de60f329d9846d6d8d3ffd2816204132.png)

My Serilog logger instance is built this way :

```auto
        public static Logger GetELKLogger(IConfiguration config, string varEnv = "ElasticSearchLog")
        {
            var configuration = config.Get<Configuration>(varEnv);

            return new LoggerConfiguration()
            .ReadFrom.Configuration(config)
            .Enrich.WithElasticApmCorrelationInfo()
            .WriteTo.Elasticsearch(new ElasticsearchSinkOptions(new Uri(configuration.ElasticSearchLog))
            {
                AutoRegisterTemplate = true,
                IndexFormat = "mslogs-{0:yyyy.MM.dd}",
                DetectElasticsearchVersion = true,
                RegisterTemplateFailure = RegisterTemplateRecovery.IndexAnyway,
                AutoRegisterTemplateVersion = AutoRegisterTemplateVersion.ESv7,
                FailureCallback = e => Console.WriteLine($"Unable to submit event {e?.RenderMessage()} to ElasticSearch. Exception : " + e?.Exception?.ToString()),
                EmitEventFailure = EmitEventFailureHandling.WriteToSelfLog |
                                        EmitEventFailureHandling.WriteToFailureSink |
                                        EmitEventFailureHandling.RaiseCallback,
                BufferCleanPayload = (failingEvent, statuscode, exception) =>
                {
                    dynamic e = JObject.Parse(failingEvent);
                    return JsonConvert.SerializeObject(new Dictionary<string, object>()
                        {
                            { "action", "DeniedByElasticSearch"},
                            { "@timestamp",e["@timestamp"]},
                            { "level","Error"},
                            { "message","Error: "+e.message},
                            { "messageTemplate",e.messageTemplate},
                            { "failingStatusCode", statuscode},
                            { "failingException", exception}
                        });
                },
                CustomFormatter = new EcsTextFormatter()
            })
            .CreateLogger();
        }

```

My minimal appsettings.json for each Microservice is

```auto
  "Serilog": {
    "Using": [],
    "MinimumLevel": {
      "Default": "Information",
      "Override": {
        "Microsoft": "Warning",
        "System": "Information",
        "Elastic": "Warning",
        "Apm": "Warning"
      }
    },
    "WriteTo": [
      {
        "Name": "Console"
      }
    ],
    "Enrich": [
      "FromLogContext",
      "WithMachineName",
      "WithProcessId",
      "WithThreadId"
    ],
    "Properties": {
      "ApplicationName": "IT.Microservices.AbandonedCartEmailSender"
    }
  },
  "ElasticApm": {
    "ServerUrl":"http://apm:8200",
    "Enabled": true,
    "TransactionSampleRate": 1,
    "CaptureBody": "all",
    "CaptureHeaders": true,
    "SpanFramesMinDuration": 0, // no stacktrace except for exception
    "CloudProvider": "none"
  },
  "ElasticSearchLog": {
    "ElasticSearchLog": "http://elasticsearch:9200/"
  }

```

What did I miss to have the Service Name in APM ?

---

<div class="post-metadata">

**Author:** ![GregKalapos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregkalapos/32/37205_2.png) [@GregKalapos](https://discuss.elastic.co/u/GregKalapos)\
**Post date:** [August 8, 2022, 1:47pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/2 "2022-08-08T13:47:02Z")

</div>

Hi @Nicolas_Rey,

the service name is not yet automatically added by the .NET APM Agent to the log line. This is something we already discuss to implement (not timeline at this point).

Currently the agent adds trace id and transaction id to log lines, but not the service name.

One thing you may be able to do is to manually add it (I know, this is less than ideal).

You can query the service name by looking at the currently active transaction:

```auto
Agent.Tracer?.CurrentTransaction?.Context.Service.Name

```

At this point it's probably better to just wait for an implementation of this.

---

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [August 21, 2022, 4:15pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/3 "2022-08-21T16:15:33Z")

</div>

Thank you for you quick answer @GregKalapos  
If I need to set it manually, I'm supposed to set the field you mentioned ?

```auto
Agent.Tracer?.CurrentTransaction?.Context.Service.Name

```

When I try to access to it, it says that Service is not part of Context, using the following APM version

```auto
<PackageReference Include="Elastic.Apm.NetCoreAll" Version="1.16.1" />

```

And could we set it globally, not only for the current span running ?  
Do you have any idea of the roadmap for this implementation ?

Good vacations if you have some 🌴

---

<div class="post-metadata">

**Author:** ![GregKalapos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregkalapos/32/37205_2.png) [@GregKalapos](https://discuss.elastic.co/u/GregKalapos)\
**Post date:** [August 25, 2022, 5:39pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/4 "2022-08-25T17:39:32Z")

</div>

Hi @Nicolas_Rey,

I just realize it's an internal property - sorry about that. My original answer wasn't really any help. Also that property is only set if we want to overwrite the default service name on a transaction level, in default cases it's empty and the agent sends it in the metadata and not on the transaction.

Anyways... second idea: You could use `Agent.Config.ServiceName` - that'll also return the service name. Plus, you can read it always, the other one would have required an active transaction - with this you can set it to all the log lines, also on ones where the agent does not have an active transaction.

> And could we set it globally, not only for the current span running ?

I think this won't be an issue with the new idea.

> Do you have any idea of the roadmap for this implementation ?

Nothing specific, but we are working on the `ecs-dotnet` repo and we really want to make progress on it. But no specific time frame.

> Good vacations if you have some 🌴

Thank you! 🙂

---

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [August 29, 2022, 11:58am UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/5 "2022-08-29T11:58:34Z")

</div>

Thank you @GregKalapos.  
Well I tested the field `Agent.Config.ServiceName` is correctly fed, it is with my MS name.  
Did I misunderstood something ?

Sorry to bother you where you need time to focus on `ecs-dotnet`, if there is a quick win workaround I'd like to apply it but currently I'm not sure of what I'm supposed to do.

---

<div class="post-metadata">

**Author:** ![Wolfgang\_Ziegler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfgang_ziegler/32/109929_2.png) [@Wolfgang\_Ziegler](https://discuss.elastic.co/u/Wolfgang_Ziegler)\
**Post date:** [August 29, 2022, 12:16pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/6 "2022-08-29T12:16:20Z")

</div>

Hi @Nicolas_Rey,  
I'm stepping in for @GregKalapos while he is on vacation.

Did I understand correctly that you see the expected value in `Agent.Config.ServiceName`?  
If yes, I believe that Greg's suggestion was to add this value manually.  
Would that work for you (as a workaround)?

---

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [August 29, 2022, 12:53pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/7 "2022-08-29T12:53:03Z")

</div>

> [@Wolfgang\_Ziegler](#):
>
> , I believe that Greg's suggestion was to add this value manually.

Hi @Wolfgang_Ziegler , well yes `Agent.Config.ServiceName` is filled in with the expected value (my service name), but on APM the Service Name is empty (see my top question).

Greg answered me that it's currently not implemented, but that I can do it manually. So I don't understand the link with `Agent.Config.ServiceName` which is filled in as expected. And btw the `ServiceName` field has only a getter, I would not be able to set it on the fly if it was not already filled in.

---

<div class="post-metadata">

**Author:** ![Wolfgang\_Ziegler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfgang_ziegler/32/109929_2.png) [@Wolfgang\_Ziegler](https://discuss.elastic.co/u/Wolfgang_Ziegler)\
**Post date:** [August 29, 2022, 1:25pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/8 "2022-08-29T13:25:02Z")

</div>

Correct, `Agent.Config.ServiceName` is read-only - that's how it's meant to be.  
The suggestion by Greg, as far as I understood, is to use this property and manually (since this is only a workaround) set up a `SerilogEnricher` (like [here](https://github.com/elastic/ecs-dotnet/blob/main/src/Elastic.Apm.SerilogEnricher/ElasticApmEnricher.cs) e.g.) to report this property as service name so it shows up in the UI where you expected it.

---

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [August 29, 2022, 1:32pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/9 "2022-08-29T13:32:35Z")

</div>

That's perfectly make sense, sorry for the confusion, I focused on APM rather on the log enricher which is the 'root cause' of my concern.  
One last question, any idea of the exact property name/key expected ?

---

<div class="post-metadata">

**Author:** ![Wolfgang\_Ziegler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfgang_ziegler/32/109929_2.png) [@Wolfgang\_Ziegler](https://discuss.elastic.co/u/Wolfgang_Ziegler)\
**Post date:** [August 29, 2022, 1:49pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/10 "2022-08-29T13:49:42Z")

</div>

No worries, glad we could clear this up 🙂  
As for the attribute name, I would assume `ElasticApmServiceName` - but maybe @Martijn_Laarman can help out here as the ECS expert?

---

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [August 30, 2022, 7:24am UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/11 "2022-08-30T07:24:53Z")

</div>

@Wolfgang_Ziegler anyway I'll test with ElasticApmServiceName and come back to you.

Many thanks for your time, as usual I'm impressed by the reactivity and availability of the Elastic team, especially on the .net driver 🙌

---

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [August 31, 2022, 2:02pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/12 "2022-08-31T14:02:29Z")

</div>

Hello @Wolfgang_Ziegler @Martijn_Laarman , I tested to enrich the log with `ElasticApmServiceName`, it adds the information in the log itself, but still can't see this information in the log panel

The code

```auto
            logEvent.AddPropertyIfAbsent(propertyFactory.CreateProperty(
                "ElasticApmServiceName", "test"));

```

Produces

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/0/10532cf96f15874612d1abecb2c923f96ae7b82a.png)

So the `ElasticApmServiceName` is transformed into `metadata.elastic_apm_service_name` .  
But my logs panel is still empty.

From another stack application (Apollo Graphql), I checked how the logs are filled in, because the service names appears in the logs panel

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/9490c769fbcf645062f3a2a3582b03929fec09e7.png)

so the the expected information seems to be `service.name`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bdede1185fc83fc31dc1fb78f3d702ba09313bf3.png)

When I try to use it in the serilog enricher

```auto
            logEvent.AddPropertyIfAbsent(propertyFactory.CreateProperty(
                "service.name", "test"));

```

The field is enriched

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/1/71ca8d24ab12ec6e0d67064c1c3d3bcb66bbae3e.png)

But the logs panel service name column stays empty.

Do you have insight of the key I'm supposed to fill in the enricher, I'm a bit lost ?  
Thank you for your help

---

<div class="post-metadata">

**Author:** ![Wolfgang\_Ziegler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfgang_ziegler/32/109929_2.png) [@Wolfgang\_Ziegler](https://discuss.elastic.co/u/Wolfgang_Ziegler)\
**Post date:** [August 31, 2022, 3:53pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/13 "2022-08-31T15:53:16Z")

</div>

Hi @Nicolas_Rey ,

I looked into this again and applied the solution I found here: [Outputting service.name instead of / alongside context.service.name](https://discuss.elastic.co/t/outputting-service-name-instead-of-alongside-context-service-name/169088)

With that, you can create an alias for the field you already have `metadata.service.name` to `service.name`.

I tested this with my sample application and it looks promising:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34f1a9b86dfac226026ddc180f7353ece3eff553.png)

(_note_: I aliased from `fields.service.name` to `service.name`)

Maybe @Martijn_Laarman has a better solution but this is the workaround I can suggest at the moment.

Cheers,  
Wolfgang

---

<div class="post-metadata">

**Author:** ![Martijn\_Laarman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martijn_laarman/32/4410_2.png) [@Martijn\_Laarman](https://discuss.elastic.co/u/Martijn_Laarman)\
**Post date:** [August 31, 2022, 6:32pm UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/14 "2022-08-31T18:32:01Z")

</div>

Sadly [[FEATURE] Enrich APM integrations with APM Service name · Issue #134 · elastic/ecs-dotnet · GitHub](https://github.com/elastic/ecs-dotnet/issues/134) still needs addressing so we can do this properly out of the box.

An easier way to do this manually would be:

```auto
var config = new EcsTextFormatterConfiguration()
	.MapCustom((ecsDoc, log) =>
	{
		ecsDoc.Service = new Service { Name = Agent.Config.ServiceName };
		return ecsDoc;
	});
var formatter = new EcsTextFormatter(config);

```

The `MapCustom` callback allows you to manually mutate the ecs document before its written to Elasticsearch.

Then pass that to `ElasticsearchSinkOptions`

```auto
CustomFormatter = formatter

```

---

<div class="post-metadata">

**Author:** ![Nicolas\_Rey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_rey/32/47284_2.png) [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Post date:** [September 1, 2022, 8:17am UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/15 "2022-09-01T08:17:09Z")

</div>

You're awesome @Wolfgang_Ziegler and @Martijn_Laarman , it works like a charm! (I implemented `EcsTextFormatter` solution)

Many thanks guys

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:36am UTC](https://discuss.elastic.co/t/apm-net-agent-see-the-service-name-in-the-logs-for-correlated-transactions/311137/16 "2022-11-04T08:36:27Z")

</div>


