# Create log visualization for my recently created logs

**URL:** <https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261>\
**Category:** Kibana\
**Created:** [January 15, 2021, 1:01pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261 "2021-01-15T13:01:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![leostereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leostereo/32/74891_2.png) [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Post date:** [January 15, 2021, 1:01pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/1 "2021-01-15T13:01:41Z")

</div>

Hy guys.  
Im sending some logs from a custom process using elasticsearch api interface.  
I can see logs at discover section.  
Now , I need to create a visualization for non technical personal.  
I dont need any graphs , just a basic log visualization , similar to graylog , with basic search function.  
Im googling but can not find hot to achieve it.  
Any idea would be wellcome.  
Im using kibana 7.9.  
Regards.  
Leandro.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [January 15, 2021, 5:53pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/2 "2021-01-15T17:53:57Z")

</div>

Hi

You could select the fields you want to have displayed, save the search:

> **[Save a search | Kibana Guide \[7.10\] | Elastic](https://www.elastic.co/guide/en/kibana/current/save-open-search.html)**

Then you can add this search to a dashboard. you could add multiple searches / processes on 1 dashboard, adding a search would then be applied to all widgets containing process data.

Would that cover your use case?

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [January 15, 2021, 6:02pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/3 "2021-01-15T18:02:34Z")

</div>

> Now , I need to create a visualization for non technical personal.  
> I dont need any graphs , just a basic log visualization , similar to graylog , with basic search function.

How are you running Kibana? Are you using Elastic's distribution?

Elastic's kibana distribution contains a [logging application](https://www.elastic.co/guide/en/observability/master/monitor-logs.html) that makes it easy to view and search logs and is exactly what you are looking for.

---

<div class="post-metadata">

**Author:** ![leostereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leostereo/32/74891_2.png) [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Post date:** [January 18, 2021, 5:18pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/4 "2021-01-18T17:18:43Z")

</div>

I worked !! thank!!

---

<div class="post-metadata">

**Author:** ![leostereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leostereo/32/74891_2.png) [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Post date:** [January 18, 2021, 5:19pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/5 "2021-01-18T17:19:08Z")

</div>

I worked , thanks !!!

---

<div class="post-metadata">

**Author:** ![leostereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leostereo/32/74891_2.png) [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Post date:** [January 18, 2021, 5:28pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/6 "2021-01-18T17:28:39Z")

</div>

Hi , It seems a nice tool but can not view my index info there.  
How should I setup it to show my index info ?  
I already set "settings -\> Index pattern for matching indices that contain log data  
and set hotspot , wich is my indes pattern but nothing happend".

Thanks.

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [January 18, 2021, 7:30pm UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/7 "2021-01-18T19:30:38Z")

</div>

Are your logs in [Elastic Common Schema](https://www.elastic.co/guide/en/ecs/current/index.html)?

---

<div class="post-metadata">

**Author:** ![leostereo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leostereo/32/74891_2.png) [@leostereo](https://discuss.elastic.co/u/leostereo)\
**Post date:** [January 19, 2021, 11:37am UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/8 "2021-01-19T11:37:10Z")

</div>

Dear Nathan ... Im not using ECS , , I didnt know about it , now you mentioned I began reading about that.  
In my case , im loggin my hotspot activity , so , when user connects to hotspot I do something like this:

```
 date_default_timezone_set('UTC');
    $today = date("Y-m-d\TH:i:s").".000Z";

    $endpoint = 'http://172.10.100.113:9200/hotspot/_doc/';
    $params = array(
            'name' => $name,
            'mac' => $mac_address,
            'code' => $code,
            'customer' => $customer,
            'dni' => $document,
            'mail' => $mail,
            'phone' => $phone,
            'timestamp' => $today
    );

    #$url = $endpoint . '?' . http_build_query($params);
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, $endpoint);
    curl_setopt($ch, CURLOPT_POST, 1);
    curl_setopt($ch, CURLOPT_HTTPHEADER, array('Content-Type: application/json'));
    curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($params));

    curl_exec($ch);

```

Im not sure how to move my scenario to ECS.  
I have been googling but could not find similar example, can you suggest ?  
BTW , thank you very much for pointing me about ECS , I consider this is a very important piece on elk.  
Leandro.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:21am UTC](https://discuss.elastic.co/t/create-log-visualization-for-my-recently-created-logs/261261/9 "2022-11-04T08:21:45Z")

</div>


