# Best practice for Log-Analyzing

**URL:** <https://discuss.elastic.co/t/best-practice-for-log-analyzing/155504>\
**Category:** Elasticsearch\
**Created:** [November 6, 2018, 8:25am UTC](https://discuss.elastic.co/t/best-practice-for-log-analyzing/155504 "2018-11-06T08:25:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Illmatic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/illmatic/32/37329_2.png) [@Illmatic](https://discuss.elastic.co/u/Illmatic)\
**Post date:** [November 6, 2018, 8:25am UTC](https://discuss.elastic.co/t/best-practice-for-log-analyzing/155504/1 "2018-11-06T08:25:02Z")

</div>

I need to Analyze the Logs(Exceptions) from a Rest-Application. I have a Log-File with the logged Exceptions and was wondering, what would be best practice to Analyze this Logs and wich Components from the ELK-Stack I should use for that.

Thanks for the Help allready 🙂

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [November 6, 2018, 3:18pm UTC](https://discuss.elastic.co/t/best-practice-for-log-analyzing/155504/2 "2018-11-06T15:18:13Z")

</div>

The first step is to get the data into Elasticsearch.

Take a look at Filebeat [1] (which installs on the same host as your Rest-Application). Pay particular attention to the multi-line support [2] since most exceptions are multi-line.

I would suggest to start with sending data directly to Elasticsearch [3]. If you need any pre-processing of the data prior to indexing, you have a few options [4][5][6].

If you have your own instance of Elasticsearch and Kibana already running, great! If not our cloud offering [7] is really great for getting starting (and production too !). Docker is also great for getting started (and production) [8], and using docker compose with Elasticsearch and Kibana [9] is great for a quick test environment.

Once you have the data in Elasticsearch and Kibana running to view the data, there is a lot available information on this topic via the interwebs. It's a wide topic so specific questions would be needed to properly advise your for your usecase.

[1] [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html)  
[2] [https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)  
[3] [https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html)  
[4] [https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html)  
[5] [https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html)  
[6] [https://www.elastic.co/guide/en/logstash/current/index.html](https://www.elastic.co/guide/en/logstash/current/index.html)  
[7] [https://www.elastic.co/cloud](https://www.elastic.co/cloud)  
[8] [https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html)  
[9] [https://www.elastic.co/guide/en/kibana/current/docker.html](https://www.elastic.co/guide/en/kibana/current/docker.html)

---

<div class="post-metadata">

**Author:** ![Illmatic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/illmatic/32/37329_2.png) [@Illmatic](https://discuss.elastic.co/u/Illmatic)\
**Post date:** [November 21, 2018, 8:35am UTC](https://discuss.elastic.co/t/best-practice-for-log-analyzing/155504/3 "2018-11-21T08:35:19Z")

</div>

Thank you for this detailed answer! You helped me alot!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 19, 2018, 8:35am UTC](https://discuss.elastic.co/t/best-practice-for-log-analyzing/155504/4 "2018-12-19T08:35:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
