# Filebeat Monitor app (Visualize or Tail)

**URL:** <https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 19, 2021, 7:54am UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920 "2021-08-19T07:54:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saleem](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@Saleem](https://discuss.elastic.co/u/Saleem)\
**Post date:** [August 19, 2021, 7:54am UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920/1 "2021-08-19T07:54:26Z")

</div>

Sorry i'm new to the elasticstack, but bear with me

I'm trying to setup ES-Kibana-Filebeat for Java application logs processing

The specific log files i'm trying to visualize aren't one of the log types with modules

They look like this(This is just an example):

```auto
2021-8-19 18:20:43.124 L Starting JMX Shell Server
Thread: localhost-startStop-1:

2021-8-19 18:20:43.124 L Starting Thread system
Thread: localhost-startStop-1:

2021-8-19 18:23:12.135 U [.APPNAME] added driver <etc...>
Thread: "APPNAME" startup:

```

Now what i've done is use Filebeat's mutliline patttern and indexed them in ES, but when i try to visualize the messages i can't

How do i monitor these kinds of logs using ES-Kibana-Filebeat?  
Can they be visualized or tailed? and how?

Is using filestream a good way to tail them? As these logs will be written by the app constantly and i need to visualize them or tail them for monitoring

Any help is appreciated, i would be happy to provide any other details

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 20, 2021, 1:50am UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920/2 "2021-08-20T01:50:25Z")

</div>

Welcome to our community! 😃

> [@Saleem](#):
>
> Now what i've done is use Filebeat's mutliline patttern and indexed them in ES, but when i try to visualize the messages i can't

Can you provide more information about this, you can't why exactly?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 20, 2021, 3:34am UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920/3 "2021-08-20T03:34:35Z")

</div>

@Saleem

I suggest you look at this

> **[Log monitoring | Observability Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/observability/current/monitor-logs.html)**

And here's our equivalent of tailing a log file it's log streaming and it's pretty cool

> **[Tail log files | Observability Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/observability/current/tail-logs.html)**

---

<div class="post-metadata">

**Author:** ![Saleem](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@Saleem](https://discuss.elastic.co/u/Saleem)\
**Post date:** [August 21, 2021, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920/4 "2021-08-21T12:42:49Z")

</div>

Thank you!

Well when i got to kibana and try to create a visualization, the message field is not there so i can't pick it.

I read about it and apparently it's not aggregatable , what i want is just to monitor this specific kind of logfiles, and display them or tail them to monitor the application. It might be a simple solution but i haven't figure it out yet.

---

<div class="post-metadata">

**Author:** ![Saleem](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@Saleem](https://discuss.elastic.co/u/Saleem)\
**Post date:** [August 21, 2021, 12:43pm UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920/5 "2021-08-21T12:43:27Z")

</div>

Alright i'll check them out thank you so much

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 21, 2021, 2:32pm UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920/6 "2021-08-21T14:32:18Z")

</div>

If you go under the log streaming settings you can pick the fields that you want to show.

 ![Screen Shot 2021-08-21 at 7.42.23 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da6b86ea4201602a43effdebfe1d1fe5384415ec.png)

Here I added a field I wanted to see

 ![Screen Shot 2021-08-21 at 7.42.43 AM](https://us1.discourse-cdn.com/elastic/original/3X/6/7/67f0e57b6e9f89a60590715dd9670042bbcfb148.png)

Then in the actual log stream app you can filter using a KQL. So then you'll only see logs that meet that criteria I it display the fields you want

 ![Screen Shot 2021-08-21 at 7.43.28 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06fd9f536f7f8c51a3be6b5a6e610a6f47e65086.jpeg)

Also you can basically do the same thing and Discover and just set a refresh rate of 10 seconds.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2021, 4:33pm UTC](https://discuss.elastic.co/t/filebeat-monitor-app-visualize-or-tail/281920/7 "2021-09-18T16:33:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
