# Filebeat module for jboss logs

**URL:** <https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521>\
**Category:** Beats\
**Created:** [March 15, 2019, 11:58am UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521 "2019-03-15T11:58:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saloni\_Vithalani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saloni_vithalani/32/42073_2.png) [@Saloni\_Vithalani](https://discuss.elastic.co/u/Saloni_Vithalani)\
**Post date:** [March 15, 2019, 11:58am UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521/1 "2019-03-15T11:58:02Z")

</div>

We are using keycloak 5.0.0 and it gets started on JBOSS wildfly 7.0.0. What will be the recommended way of getting and parsig jboss logs in ELK. We are using filebeat, logstash, elasticsearch and kibana flow.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 25, 2019, 8:31am UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521/2 "2019-03-25T08:31:02Z")

</div>

I would recommend you to use Filebeat to read the log lines and then create an ingest pipeline to parse the logs: [https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html)

Best would be if in the future we have a jboss module that does the magic for you out of the box. If you are interested in this, perhaps file a feature request in the beats repository?

---

<div class="post-metadata">

**Author:** ![Saloni\_Vithalani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saloni_vithalani/32/42073_2.png) [@Saloni\_Vithalani](https://discuss.elastic.co/u/Saloni_Vithalani)\
**Post date:** [March 25, 2019, 9:02am UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521/3 "2019-03-25T09:02:33Z")

</div>

Thanks for the reply @ruflin.

I managed to make jboss log in json format and pick log file location from environment variable. So, I think jboss gives the magic I was looking for. But the configuration of jboss to make it log in json was difficult to find online. Hence, here is the gist of [standalone.xml](https://gist.github.com/skvithalani/c275ce828b9a6c0f33ccdbaf1b335c7d) that does this configuration.

I think If we get logs in json format from any application it makes it version agnostic and we can get rid of regex being maintained in pipeline.

What are your views on this understanding.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 25, 2019, 12:25pm UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521/4 "2019-03-25T12:25:11Z")

</div>

Getting logs in JSON format is definitively an improvement in most cases. But json is not just solving the issue. Often I still see `{"message": "foo"}` which is json, but we still need to process the message field. The other part is the naming of fields and fields explosion. Some json logs have from my perspective too many different fields and they are not standardised. We are trying to solve this with [https://github.com/elastic/ecs](https://github.com/elastic/ecs)

So my guess is with JSON logs at least the input and groking part becomes easier, but we will still need renames and an understanding for the content of the log file.

---

<div class="post-metadata">

**Author:** ![Saloni\_Vithalani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saloni_vithalani/32/42073_2.png) [@Saloni\_Vithalani](https://discuss.elastic.co/u/Saloni_Vithalani)\
**Post date:** [March 27, 2019, 5:17am UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521/5 "2019-03-27T05:17:29Z")

</div>

I looked at Elastic common schema and understood that common schema can give an upper hand to aggregate metrics and APM and logs into a common way of monitoring it.

But we are currently using 6.6.0 basic license and I am only concerned about logs not metric or APM, so is it fair to say that I do not need renames for the time being.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2019, 7:17am UTC](https://discuss.elastic.co/t/filebeat-module-for-jboss-logs/172521/6 "2019-04-24T07:17:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
