# Configuring the default columns to appear in the log stream view

**URL:** <https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497>\
**Category:** Logs\
**Tags:** docker\
**Created:** [March 28, 2020, 3:37pm UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497 "2020-03-28T15:37:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yomain](https://avatars.discourse-cdn.com/v4/letter/y/a88e4f/32.png) [@Yomain](https://discuss.elastic.co/u/Yomain)\
**Post date:** [March 28, 2020, 3:37pm UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497/1 "2020-03-28T15:37:59Z")

</div>

Hi,

I'm using the elk stack in docker and I am looking for a way to configure the default columns displayed in the log stream. Right now those default columns are timestamp, event.dataset and message.

I can change them from the setting menu, but I haven't been able to reproduce this from the kibana config file.

Is there a way to do it ?

Thanks in advance !

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 30, 2020, 9:21am UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497/2 "2020-03-30T09:21:31Z")

</div>

Hi @Yomain,

unfortunately there's no mechanism to change the columns via the configuration file at the moment. What makes using the settings UI impractical for you?

---

<div class="post-metadata">

**Author:** ![Yomain](https://avatars.discourse-cdn.com/v4/letter/y/a88e4f/32.png) [@Yomain](https://discuss.elastic.co/u/Yomain)\
**Post date:** [March 30, 2020, 9:55am UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497/3 "2020-03-30T09:55:57Z")

</div>

Hi,

I am running my whole stack in a docker-compoe file and my main issue was about loosing Kibana settings when doing a docker-compose down.

I am only using the elastic stack to parse a single application log file for now so I don't have that many needs.

Anyway to solve that issue I have made a volume of elasticsearch data folder (as Kibana settings are saved there).

But logs are also saved there and initially I wanted to avoid this as I wanted elastic/filebeat to start from 0 and reparse the totally of my log file. Now it's on tail mode in order to avoid duplicate.

But thank you for your answer !

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 30, 2020, 10:35am UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497/4 "2020-03-30T10:35:41Z")

</div>

Thanks for providing the insights. I can empathize - automatically restoring Kibana settings after a redeployment is not trivial. Maybe I can help by providing some insights into how the log source settings are stored:

Upon saving the settings in the Logs UI a space-specific saved object is stored in the Kibana system index. You should be able to query such saved objects using the saved object [`_find` API](https://www.elastic.co/guide/en/kibana/current/saved-objects-api-find.html) as in

```auto
curl -u "${USERNAME}:${PASSWORD}" -X GET '${KIBANA_URL}/api/saved_objects/_find?type=infrastructure-ui-source' -H 'kbn-xsrf: true'

```

and restore them using the [`_bulk_create` API](https://www.elastic.co/guide/en/kibana/current/saved-objects-api-bulk-create.html) after container startup. A one-shot sidecar container is a common pattern for that.

Let me know if that makes sense.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 30, 2020, 10:40am UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497/5 "2020-03-30T10:40:39Z")

</div>

In the meantime I have created [https://github.com/elastic/kibana/issues/61773](https://github.com/elastic/kibana/issues/61773) to put more convenient export/import mechanisms on the roadmap. Please feel free to chime in with your use-case details there to provide some weight to the request.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2020, 10:55am UTC](https://discuss.elastic.co/t/configuring-the-default-columns-to-appear-in-the-log-stream-view/225497/6 "2020-04-27T10:55:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
