# Azure Logs Integration with ECS logs

**URL:** https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041
**Category:** Elastic Agent
**Tags:** ecs-elastic-common-schema, filebeat
**Created:** [April 28, 2023, 10:03am UTC](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041 "2023-04-28T10:03:24Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![CrystalDesignDR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crystaldesigndr/32/114545_2.png) [@CrystalDesignDR](https://discuss.elastic.co/u/CrystalDesignDR)
#### Post date: [April 28, 2023, 10:03am UTC](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041/1 "2023-04-28T10:03:24Z")

</div>

Hi,

we are running Elastic Cloud and want to add Application Logs to it with Elastic Agent, these logs need to be correlated with out APM traces.  
We are running the Elastic Azure Logs Integration with the Elastic Agent running on a vm.

Our applications log in the ECS format and the data is sent do an Event Hub and also shows up in Elastic and is correlated accordingly.

However, the message in Elastic consists of the whole event-hub JSON and fields like `service.name` and `log.level` are empty.

Am I missing something on how this can be added the correct way to elastic (`message` -\> `message` filed ecc.) Or is this not possible at the moment?  
I did try around with some custom pipelines, but this seems cumbersome.

 ![2023-04-28 12_00_16-Clipboard](https://us1.discourse-cdn.com/elastic/original/3X/9/7/9726b9fa32310807c8877a68cae38fb0b6854c53.png)

The message in elastic:  
Note that `resultDescription` is our ECS logged message

```json
{
	"EventIpAddress": "10.81.0.18",
	"EventPrimaryStampName": "waws-prod-fra-013",
	"EventStampName": "waws-prod-fra-013",
	"EventStampType": "Stamp",
	"Host": "zzz",
	"category": "AppServiceConsoleLogs",
	"containerId": "yyy",
	"level": "Informational",
	"location": "Germany West Central",
	"operationName": "Microsoft.Web/sites/log",
	"resourceId": "/SUBSCRIPTIONS/xxx",
	"resultDescription": " {\"@timestamp\":\"2023-04-28T09:15:17.317Z\",\"log.level\":\"warn\",\"message\":\"ApplicationError: [409] Entity exist already\",\"ecs\":{\"version\":\"1.6.0\"},\"event\":{\"dataset\":\"service-name.log\"},\"trace\":{\"id\":\"702702a79eaadb6ec76bc5b9c84a288a\"},\"transaction\":{\"id\":\"eac23a691b53e73d\"},\"service\":{\"name\":\"service-name\"}}\n\n",
	"time": "2023-04-28T09:15:17.317964487Z"
}

```

An example log generated by our app in ECS format:

```json
{
	"@timestamp": "2023-04-28T09:08:33.060Z",
	"log.level": "warn",
	"message": "ApplicationError: [409] Entity exist already",
	"ecs": {
		"version": "1.6.0"
	},
	"event": {
		"dataset": "service-name.log"
	},
	"trace": {
		"id": "17eeb484574b0075a9607c69f07c42bd"
	},
	"transaction": {
		"id": "b38a1d4d39f1f8ba"
	},
	"service": {
		"name": "service-name"
	}
}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 26, 2023, 10:04am UTC](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041/2 "2023-05-26T10:04:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
