# How to find missing logs

**URL:** <https://discuss.elastic.co/t/how-to-find-missing-logs/299823>\
**Category:** Logstash\
**Created:** [March 16, 2022, 7:01am UTC](https://discuss.elastic.co/t/how-to-find-missing-logs/299823 "2022-03-16T07:01:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dginfi](https://avatars.discourse-cdn.com/v4/letter/d/3da27b/32.png) [@dginfi](https://discuss.elastic.co/u/dginfi)\
**Post date:** [March 16, 2022, 7:01am UTC](https://discuss.elastic.co/t/how-to-find-missing-logs/299823/1 "2022-03-16T07:01:12Z")

</div>

I have logs being forwarding from Panorama to ELK.  
On ELK server I have filebeats setup with panw module enabled which receives the logs and forwards to logstash.  
In logstash filter I am using jdbc\_streaming filter for certain database lookups.  
I don't see any parse errors, however when a capture is taken for the specific port and I try to compare the wireshark data with Kibana data, I see that certain logs are missed.  
I do not see any interface drops but I do see many udpbuffer receive errors so this could also be one of the issue.

Any suggestions to determine where the logs get leaked or dropped are welcome.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2022, 7:01am UTC](https://discuss.elastic.co/t/how-to-find-missing-logs/299823/2 "2022-04-13T07:01:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
