# Can we monitor IBM webSphere event logs using elasticsearch?

**URL:** <https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543>\
**Category:** Logstash\
**Created:** [July 30, 2015, 5:26am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543 "2015-07-30T05:26:25Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ashok](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Ashok](https://discuss.elastic.co/u/Ashok)\
**Post date:** [July 30, 2015, 5:26am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/1 "2015-07-30T05:26:26Z")

</div>

Hi,

I want to monitor the near real time logs of IBM webSphere.

How can we do with elasticsearch?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 30, 2015, 7:36am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/2 "2015-07-30T07:36:48Z")

</div>

Use Logstash to read and parse the logs and post them into Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Ashok](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Ashok](https://discuss.elastic.co/u/Ashok)\
**Post date:** [July 30, 2015, 9:05am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/3 "2015-07-30T09:05:23Z")

</div>

Can we read real time websphere logs using Logstash? i mean how do connect to IBM server?  
Can i have any sample logsatsh conf file to connect IBM?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 30, 2015, 1:12pm UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/4 "2015-07-30T13:12:53Z")

</div>

If WebSphere writes its logs to text files in the file system you can use Logstash and its standard plugins to read them (in real time). If WebSphere produces logs in some other format it will probably take more work.

Unless you can find something in the forum archives (or be general googling) you'll probably have to make up the Logstash yourself. We can help but we need additional details about the logs.

Since this is a Logstash question, please move it to the Logstash group.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 30, 2015, 11:12pm UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/5 "2015-07-30T23:12:00Z")

</div>

> [@magnusbaeck](#):
>
> Since this is a Logstash question, please move it to the Logstash group.

Done.

---

<div class="post-metadata">

**Author:** ![Ashok](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Ashok](https://discuss.elastic.co/u/Ashok)\
**Post date:** [July 31, 2015, 6:17am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/6 "2015-07-31T06:17:30Z")

</div>

Logs are text format only.How to connect IBM remote application servers using Logstash.  
Is there any standard format?

---

<div class="post-metadata">

**Author:** ![Ashok](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Ashok](https://discuss.elastic.co/u/Ashok)\
**Post date:** [July 31, 2015, 7:03am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/7 "2015-07-31T07:03:28Z")

</div>

Do we need to purchase Logstash Integration Toolkit for monitor IBM application server logs?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 31, 2015, 7:08am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/8 "2015-07-31T07:08:05Z")

</div>

Why? Just point LS at the files and let it read them.

---

<div class="post-metadata">

**Author:** ![Ashok](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Ashok](https://discuss.elastic.co/u/Ashok)\
**Post date:** [July 31, 2015, 7:11am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/9 "2015-07-31T07:11:26Z")

</div>

First we need to connect the servers right?  
Can i have sample logstash conf file? or any reference url?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 31, 2015, 7:12am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/10 "2015-07-31T07:12:20Z")

</div>

Take a look at [https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html](https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html)

---

<div class="post-metadata">

**Author:** ![Ashok](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Ashok](https://discuss.elastic.co/u/Ashok)\
**Post date:** [July 31, 2015, 7:15am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/11 "2015-07-31T07:15:28Z")

</div>

I didn't see any info in this to connect server.  
Already am able to load the static text log file using kibana.But i want monitor and analyze remote server logs.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 31, 2015, 7:17am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/12 "2015-07-31T07:17:18Z")

</div>

Use the file input and then ship them via TCP or similar to another LS instance, then into ES.

---

<div class="post-metadata">

**Author:** ![Ashok](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@Ashok](https://discuss.elastic.co/u/Ashok)\
**Post date:** [July 31, 2015, 7:26am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/13 "2015-07-31T07:26:41Z")

</div>

Logs are located in specified path at unix server.So what we need to give in logstash input?  
First we need to connect server by giving credentials ,then go to the specified path and grep with the string with particular date.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 31, 2015, 7:28am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/14 "2015-07-31T07:28:35Z")

</div>

You will need to install an agent on each application server node that will read the local log files and send them to Logstash and Elasticsearch for further processing. Logstash itself can be used for this using the file input, but often a more light weight shipper, e.g. [Logstash-forwarder](https://github.com/elastic/logstash-forwarder), is used instead.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:33am UTC](https://discuss.elastic.co/t/can-we-monitor-ibm-websphere-event-logs-using-elasticsearch/26543/15 "2017-07-06T05:33:15Z")

</div>


