# How to configure filebeat to store logs in elasticsearch correctly

**URL:** <https://discuss.elastic.co/t/how-to-configure-filebeat-to-store-logs-in-elasticsearch-correctly/374865>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 21, 2025, 6:42pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-store-logs-in-elasticsearch-correctly/374865 "2025-02-21T18:42:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mirali\_Rafiyev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mirali_rafiyev/32/141548_2.png) [@Mirali\_Rafiyev](https://discuss.elastic.co/u/Mirali_Rafiyev)\
**Post date:** [February 21, 2025, 6:42pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-store-logs-in-elasticsearch-correctly/374865/1 "2025-02-21T18:42:04Z")

</div>

Hi there , i am newbie in this stack sorry for dummy questions , in my backend i store logs like this

```auto
{"context":{"userId":"66ffe5e929e84af79a89dde8"},"level":"info","message":"getProfile: user found","timestamp":"2025-02-20T13:50:41.502Z"}
{"context":{"userId":"66ffe5e929e84af79a89dde8"},"level":"info","message":"getById: user found","timestamp":"2025-02-20T13:50:44.148Z"}
{"context":{"userId":"66ffe5e929e84af79a89dde8"},"level":"info","message":"getProfile: user found","timestamp":"2025-02-20T13:50:44.149Z"}

```

I see here timestamp is different for all but when filebeat sends this and stores in elasticsearch ( i dont use logstash , filebeat direct to elasticsearch ) , the kibana web page shows all logs in single field ( screeshot attached )

![Screenshot 2025-02-21 at 22.38.42](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e0e5b106d99ff6c9d5c4cf863f68207bd3389cc.png)

here is my filebeat config file ( chatgpt generated )

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/www/api/logs/*.log
  multiline: # Important if you have stack traces
    pattern: '^\[\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}\]' # Adjust if your timestamp format is different
    negate: true
    match: after
  close_inactive: 5m # Keep this to prevent Filebeat from closing if log is not actively written
  close_renamed: false
  close_removed: false

output.elasticsearch:
  hosts: ["localhost:9200"]
  index: "nestjs-logs-%{+yyyy.MM.dd}"

setup.template:
  name: "nestjs-logs"
  pattern: "nestjs-logs-*"

```

I will be very thankfull to get some clear explonation how to config it correctly or what i do wrong . Thank you.

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [February 21, 2025, 8:25pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-store-logs-in-elasticsearch-correctly/374865/2 "2025-02-21T20:25:25Z")

</div>

Hi @Mirali_Rafiyev, welcome to our community!

This link might give you a broader perspective:

[Dec 4th 2022: [EN] Ingesting JSON logs with Elastic-Agent (and/or Filebeat)](https://discuss.elastic.co/t/dec-4th-2022-en-ingesting-json-logs-with-elastic-agent-and-or-filebeat/319536))

It primarily covers JSON parsing in the initial steps.
