# Easily parseable log format (ideally, CEF format) in ELS / Kibana / Fluentd

**URL:** <https://discuss.elastic.co/t/easily-parseable-log-format-ideally-cef-format-in-els-kibana-fluentd/89779>\
**Category:** Elasticsearch\
**Created:** [June 16, 2017, 9:38pm UTC](https://discuss.elastic.co/t/easily-parseable-log-format-ideally-cef-format-in-els-kibana-fluentd/89779 "2017-06-16T21:38:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![afcooper](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@afcooper](https://discuss.elastic.co/u/afcooper)\
**Post date:** [June 16, 2017, 9:38pm UTC](https://discuss.elastic.co/t/easily-parseable-log-format-ideally-cef-format-in-els-kibana-fluentd/89779/1 "2017-06-16T21:38:18Z")

</div>

Hi there, I'm new to this stack and trying to evaluate it as an option for my app's log collection and visualization. I've got Kibana/ELS/Fluentd setup on Kubernetes. Extracting useful information from my logs on Kibana has proven difficult -- all non-Kubernetes/Docker fields are dumped into a "log" field, which isn't parsed/is hard to split apart for visualization purposes. Ideally, I'd like to be able to have my log fields parsed, such that I can, for example, easily search by log level, e.g. INFO, WARN, ERROR, FATAL. With the current setup, that isn't very easy to do in a Lucene-like way. I'm investigating using a standard logging format, like CEF, with the hopes that I can use a plug in to get my logs parsed appropriately. Logstash and fluentd both seem to have CEF plugins, but I'm having trouble finding documentation that links all of these disparate pieces together. Any help would be appreciated. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2017, 9:38pm UTC](https://discuss.elastic.co/t/easily-parseable-log-format-ideally-cef-format-in-els-kibana-fluentd/89779/2 "2017-07-14T21:38:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
