# Applying Elastic Common Scheman(ECS) in multi language environments

**URL:** https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431
**Category:** Logs
**Tags:** ecs-elastic-common-schema
**Created:** [August 25, 2021, 4:24am UTC](https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431 "2021-08-25T04:24:56Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Bingu\_Shim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bingu_shim/32/57949_2.png) [@Bingu\_Shim](https://discuss.elastic.co/u/Bingu_Shim)
#### Post date: [August 25, 2021, 4:24am UTC](https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431/1 "2021-08-25T04:24:56Z")

</div>

Hello,

We are operating Filebeat on about 2,000 Machines and 2~30 K8S Clusters.  
Also we accept ECS as the structured logging format standard for our company.  
Currently, we applied ECS layout to services that are written in Java, Node.JS.

We want to apply ECS Loging layout to services that are wirtten in .Net and C++.  
Each case have issue for applying ECS.

1. **C++ : No library on this language on [Github](https://github.com/elastic/ecs-logging)**  
**Question** : Do you have any plan to support C++ log layout?

2. **.Net** : Value of log.level filed is different from each language.  
**Question** : Do you have any recommendation on this environment

```auto
// Request
POST filebeat-*/_search
{
  "size": 0,
  "query": {
    "bool": {
      "filter": [
        {
          "query_string": {
            "analyze_wildcard": true,
            "query": "*"
          }
        }
      ]
    }
  },
  "aggs": {
    "3": {
      "terms": {
        "field": "log.level",
        "size": 10,
        "order": {
          "_key": "asc"
        },
        "min_doc_count": 1
      }
    }
  }
}

// Response
{
  "took" : 31,
  "timed_out" : false,
  "_shards" : {
    "total" : 60,
    "successful" : 60,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 77,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  },
  "aggregations" : {
    "3" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "INFO",
          "doc_count" : 72
        },
        {
          "key" : "WARN",
          "doc_count" : 2
        },
        {
          "key" : "warn",
          "doc_count" : 3
        }
      ]
    }
  }
}

```

---

<div class="post-metadata">

### Author: ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)
#### Post date: [August 25, 2021, 8:59am UTC](https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431/2 "2021-08-25T08:59:04Z")

</div>

Hi and thanks for your question!

> [@Bingu\_Shim](#):
>
> Do you have any plan to support C++ log layout?

We currently don't have plans for that.  
Which C++ logging frameworks are you using?

> [@Bingu\_Shim](#):
>
> Value of log.level filed is different from each language.  
> **Question** : Do you have any recommendation on this environment

The lowercase normalizer sounds like the way to go for your use case.

Aggregations should return the normalized value, see [normalizer | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/normalizer.html).

Maybe you have aggregated over the wrong field or the mapping has not been applied for the index you're aggregating over. Remember: you can't change the mapping of existing indices, only new ones.

It can get a bit more complex if not only the casing differs, such as `WARN` vs `WARNING`. In that case, you may want to use an ingest node pipeline to normalize the values.

---

<div class="post-metadata">

### Author: ![Bingu\_Shim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bingu_shim/32/57949_2.png) [@Bingu\_Shim](https://discuss.elastic.co/u/Bingu_Shim)
#### Post date: [August 26, 2021, 1:31am UTC](https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431/3 "2021-08-26T01:31:08Z")

</div>

Hi,

Thank you for the quick answer.

1. We are using Log4Cpp([http://log4cpp.sourceforge.net/](http://log4cpp.sourceforge.net/))

2. Yor are right about the aggregation with normalizated value.  
The problem is that i was using wildcard index whan search.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 23, 2021, 1:31am UTC](https://discuss.elastic.co/t/applying-elastic-common-scheman-ecs-in-multi-language-environments/282431/4 "2021-09-23T01:31:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
