# Can Elasticsearch extract fields from multiple log files? Can we write this code in a single file?

**URL:** <https://discuss.elastic.co/t/can-elasticsearch-extract-fields-from-multiple-log-files-can-we-write-this-code-in-a-single-file/40190>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 27, 2016, 5:56am UTC](https://discuss.elastic.co/t/can-elasticsearch-extract-fields-from-multiple-log-files-can-we-write-this-code-in-a-single-file/40190 "2016-01-27T05:56:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![usahitya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/usahitya/32/6180_2.png) [@usahitya](https://discuss.elastic.co/u/usahitya)\
**Post date:** [January 27, 2016, 5:56am UTC](https://discuss.elastic.co/t/can-elasticsearch-extract-fields-from-multiple-log-files-can-we-write-this-code-in-a-single-file/40190/1 "2016-01-27T05:56:39Z")

</div>

Hi Friends,

I am monitoring /var/log/\* in my linux box through Filebeat. Every log file have it's own style. I am getting the event like below (sample log file)  
"message:b8tTpts/0��3T(:a� pts/0ts/0SAHISD+jocktramen10.33.111.11f\>Te @version:1 @timestamp:January 19th 2016, 16:38:32.732 beat.hostname:NSAH-PC1169-1 [beat.name](http://beat.name):NSAH-PC1169-1 count:1 fields: - input\_type:log offset:109,405 \*\* source:/var/log/wtmp\*\* type:syslog host:NHCLT-PC1169-1 \_id:AVJZkgL5augbAVuIOsWM \_type:syslog \_index:filebeat-2016.01.19 \_score:"

From above event I couldn't able to make a meaningful dashboard in Kibana. I cannot Extract new fields as every log file have it's own style of logging. Can I write code in Logstash , that extract from multiple log files?

In Elasticsearch document there i found /var/log/syslog. But I didn't found in my Linux box.

Is Syslog is a software? will it take all the logfiles, and convert it into Single format i.e., Syslog format?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 27, 2016, 7:26am UTC](https://discuss.elastic.co/t/can-elasticsearch-extract-fields-from-multiple-log-files-can-we-write-this-code-in-a-single-file/40190/2 "2016-01-27T07:26:18Z")

</div>

> From above event I couldn't able to make a meaningful dashboard in Kibana.

/var/log/wtmp is a binary file that you won't be able to read in a meaningful way with Filebeat. Another reason not to tell Filebeat to read /var/log/\* is that some events are logged in multiple files so if you read them all you'll get duplicates. Check your syslog configuration to see how things are set up. Chances are _all_ events will go to /var/log/syslog and then there's no point in reading any other files.

> I cannot Extract new fields as every log file have it's own style of logging. Can I write code in Logstash , that extract from multiple log files?

Yes. For example, grok filters can be configured to try multiple patterns until it gets a match.

> Is Syslog is a software? will it take all the logfiles, and convert it into Single format i.e., Syslog format?

I'm not sure what you're asking here.

---

<div class="post-metadata">

**Author:** ![Sai\_Birada](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_birada/32/142367_2.png) [@Sai\_Birada](https://discuss.elastic.co/u/Sai_Birada)\
**Post date:** [April 12, 2016, 4:18am UTC](https://discuss.elastic.co/t/can-elasticsearch-extract-fields-from-multiple-log-files-can-we-write-this-code-in-a-single-file/40190/3 "2016-04-12T04:18:28Z")

</div>

How to read wtmp files through filebeat and send to logstash instance?.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 12, 2016, 5:29am UTC](https://discuss.elastic.co/t/can-elasticsearch-extract-fields-from-multiple-log-files-can-we-write-this-code-in-a-single-file/40190/4 "2016-04-12T05:29:04Z")

</div>

> How to read wtmp files through filebeat and send to logstash instance?.

As I said earlier: /var/log/wtmp is a binary file that you won't be able to read in a meaningful way with Filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 9:53pm UTC](https://discuss.elastic.co/t/can-elasticsearch-extract-fields-from-multiple-log-files-can-we-write-this-code-in-a-single-file/40190/5 "2017-07-05T21:53:28Z")

</div>


