# How can I push lttng traces to elastic using filebeat (or otherwise)

**URL:** <https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 19, 2020, 8:37am UTC](https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922 "2020-02-19T08:37:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhaskarsinghal](https://avatars.discourse-cdn.com/v4/letter/b/54ee81/32.png) [@bhaskarsinghal](https://discuss.elastic.co/u/bhaskarsinghal)\
**Post date:** [February 19, 2020, 8:37am UTC](https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922/1 "2020-02-19T08:37:30Z")

</div>

Hello All,

I want to view and query the lttng traces using ELK. What is the best way to do this? I don't see any corresponding input type in filebeat documentation.

Any pointers?

Regards,  
Bhaskar

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [February 19, 2020, 9:05am UTC](https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922/2 "2020-02-19T09:05:00Z")

</div>

Hello,

You can simply use logsatsh if you don't have to deploy it on many VMs. In logstash input, LTTng logs and define a grok pattern to parse these logs.

---

<div class="post-metadata">

**Author:** ![bhaskarsinghal](https://avatars.discourse-cdn.com/v4/letter/b/54ee81/32.png) [@bhaskarsinghal](https://discuss.elastic.co/u/bhaskarsinghal)\
**Post date:** [February 19, 2020, 9:27am UTC](https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922/3 "2020-02-19T09:27:39Z")

</div>

Thank you Ahmed.

There are no logs, only in memory buffer or network stream and the data is encoded (CTF format).  
The traces can be viewed using lttng trace view or babeltrace. But I am looking for a way to ingest the network stream to elastic and query (the decoded traces).

Regards,  
Bhaskar

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2020, 9:27am UTC](https://discuss.elastic.co/t/how-can-i-push-lttng-traces-to-elastic-using-filebeat-or-otherwise/219922/4 "2020-03-18T09:27:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
