# Configuration issue Logstash or Kibana

**URL:** <https://discuss.elastic.co/t/configuration-issue-logstash-or-kibana/232129>\
**Category:** Logstash\
**Created:** [May 12, 2020, 4:24am UTC](https://discuss.elastic.co/t/configuration-issue-logstash-or-kibana/232129 "2020-05-12T04:24:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anmohamed](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@anmohamed](https://discuss.elastic.co/u/anmohamed)\
**Post date:** [May 12, 2020, 4:24am UTC](https://discuss.elastic.co/t/configuration-issue-logstash-or-kibana/232129/1 "2020-05-12T04:24:20Z")

</div>

I have like this log format. but I am not sure i have to config filebeat or Logstash to get the after message to get the logs number to the same log. Can you help me to do this?

I have given 2 sample logs.

I, [2020-05-06T19:01:54.156085 #2714] INFO -- : amazonaccount: 5d817aefb5e24777d400422c. submit\_feed feed\_content: sku price minimum-seller-allowed-price maximum-seller-allowed-price quantity leadtime-to-ship fulfillment-channel  
15893 30   
24636 242   
3214509 228   
6003169 247

I, [2020-05-08T11:01:57.467075 #31370] INFO -- : amazonaccount: 5d817aefb5e24777d400422c. submit\_feed feed\_content: sku price minimum-seller-allowed-price maximum-seller-allowed-price quantity leadtime-to-ship fulfillment-channel  
2421782 x1 74   
41141 X 12 20   
6294946 0   
7011638 93   
85001 52

When I check kibana it's showing

I, [2020-05-06T19:01:54.156085 #2714] INFO -- : amazonaccount: 5d817asawas24777dw400422c. submit\_feed feed\_content: sku price minimum-seller-allowed-price maximum-seller-allowed-price quantity leadtime-to-ship fulfillment-channel

I, [2020-05-08T11:01:57.467075 #31370] INFO -- : amazonaccount: 5d817asawas24777dw400422c. submit\_feed feed\_content: sku price minimum-seller-allowed-price maximum-seller-allowed-price quantity leadtime-to-ship fulfillment-channel

---

<div class="post-metadata">

**Author:** ![anmohamed](https://avatars.discourse-cdn.com/v4/letter/a/f17d59/32.png) [@anmohamed](https://discuss.elastic.co/u/anmohamed)\
**Post date:** [May 12, 2020, 5:22am UTC](https://discuss.elastic.co/t/configuration-issue-logstash-or-kibana/232129/2 "2020-05-12T05:22:37Z")

</div>

Logstash config

if "SUCCESS" not in [RUBY]{  
grok {  
match =\> { "message" =\> "[%{DATA:firstl}%{TIMESTAMP\_ISO8601:timestamp} #%{POSINT:pid}] \*%{RUBY\_LOGLEVEL:loglevel} -- +%{DATA:progname}: %{GREEDYDATA:message}"}  
add\_tag =\> ["SUCCESS"]  
remove\_tag =\> ["\_grokparsefailure"]  
}  
}

Kibana config

filebeat.inputs:

- type: log  
enabled: true  
paths:

output.logstash:

# The Logstash hosts

hosts: ["IPaddress:5044"]

xpack.monitoring:  
enabled: true  
elasticsearch:  
hosts: ["[http://IPaddress:9200](http://IPaddress:9200)"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2020, 5:22am UTC](https://discuss.elastic.co/t/configuration-issue-logstash-or-kibana/232129/3 "2020-06-09T05:22:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
