# How to integrate apm trace id with java logs

**URL:** <https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705>\
**Category:** APM\
**Tags:** java\
**Created:** [October 26, 2021, 2:37pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705 "2021-10-26T14:37:17Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![suresh123](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Post date:** [October 26, 2021, 2:37pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/1 "2021-10-26T14:37:17Z")

</div>

`Hi Team,

How to integrate apm trace id or span id with actual java logs to trace the complete java log.`

---

<div class="post-metadata">

**Author:** ![riferrei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/riferrei/32/104867_2.png) [@riferrei](https://discuss.elastic.co/u/riferrei)\
**Post date:** [October 26, 2021, 10:29pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/2 "2021-10-26T22:29:33Z")

</div>

Suppose the logs from the Java application are being sent to Elasticsearch already (via Filebeat or the Elastic agent). In that case, you can enable log correlation in the instrumented JVM using the parameter below:

`-Delastic.apm.enable_log_correlation=true`

More information [here](https://www.elastic.co/guide/en/apm/agent/java/current/log-correlation.html).

— @riferrei

---

<div class="post-metadata">

**Author:** ![suresh123](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Post date:** [October 27, 2021, 11:33am UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/3 "2021-10-27T11:33:57Z")

</div>

`Hi Racardo,

I have added -Delastic.apm.enable\_log\_correlation=true but getting error, please look into below

**Before adding**

java -Xms512M -Xmx2G -javaagent:/services/apm/elastic-apm-agent.jar jar /services/service1/service1\*.jar --server.port=\<port\_num\> --spring.application.name=service1

**After adding**  
java -Xms512M -Xmx2G -javaagent:/services/apm/elastic-apm-agent.jar -Delastic.apm.enable\_log\_correlation=true jar /services/service1/service1\*.jar --server.port=\<port\_num\> --spring.application.name=service1

**Error**  
[main] INFO co.elastic.apm.agent.impl.ElasticApmTracer - Tracer switched to RUNNING state  
Error: Could not find or load main class jar  
Caused by: java.lang.ClassNotFoundException: jar  
[elastic-apm-circuit-breaker] INFO co.elastic.apm.agent.impl.circuitbreaker.CircuitBreaker - Stopping the Circuit Breaker thread `

---

<div class="post-metadata">

**Author:** ![nugusbayevkk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nugusbayevkk/32/126683_2.png) [@nugusbayevkk](https://discuss.elastic.co/u/nugusbayevkk)\
**Post date:** [October 27, 2021, 12:16pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/4 "2021-10-27T12:16:01Z")

</div>

> [@suresh123](#):
>
> java -Xms512M -Xmx2G -javaagent:/services/apm/elastic-apm-agent.jar -Delastic.apm.enable\_log\_correlation=true jar /services/service1/service1\*.jar --server.port=\<port\_num\> --spring.application.name=service1

Hi @suresh123, you make mistake in your command - before jar you need to add `-`

```auto
java -Xms512M -Xmx2G -javaagent:/services/apm/elastic-apm-agent.jar -Delastic.apm.enable_log_correlation=true -jar /services/service1/service1*.jar --server.port=<port_num> --spring.application.name=service1

```

---

<div class="post-metadata">

**Author:** ![suresh123](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Post date:** [October 27, 2021, 12:58pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/5 "2021-10-27T12:58:32Z")

</div>

` I added below, but I think it is not correct, can you please provide correct syntax.

java -Xms512M -Xmx2G -javaagent:-Delastic.apm.enable\_log\_correlation=true /services/apm/elastic-apm-agent.jar -Delastic.apm.enable\_log\_correlation=true -jar /services/service1/service1\*.jar --server.port=\<port\_num\> --spring.application.name=service1

**Error**  
Error opening zip file or JAR manifest missing : -Delastic.apm.enable\_log\_correlation  
Error occurred during initialization of VM  
agent library failed to init: instrument`

---

<div class="post-metadata">

**Author:** ![suresh123](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Post date:** [October 27, 2021, 1:34pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/6 "2021-10-27T13:34:41Z")

</div>

Now it is working -Delastic.apm.enable\_log\_correlation,  
let me check the trace id is pointing to actual logs.

---

<div class="post-metadata">

**Author:** ![suresh123](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Post date:** [October 27, 2021, 1:47pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/7 "2021-10-27T13:47:51Z")

</div>

Can you please guide me how to verify whether apm is integrated with actual java logs. Where can I search with trace id/span id to get complete trace log in application log-index

---

<div class="post-metadata">

**Author:** ![riferrei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/riferrei/32/104867_2.png) [@riferrei](https://discuss.elastic.co/u/riferrei)\
**Post date:** [October 27, 2021, 2:12pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/8 "2021-10-27T14:12:29Z")

</div>

You should be able to jump from a trace to the respective log if it is working correctly. Please note that the flag enabled in the JVM only correlates the traces with the logs, but the logs themselves need to be sent to Elasticsearch separately.

— @riferrei

---

<div class="post-metadata">

**Author:** ![suresh123](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@suresh123](https://discuss.elastic.co/u/suresh123)\
**Post date:** [October 27, 2021, 2:35pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/9 "2021-10-27T14:35:01Z")

</div>

`Hi Ricardo,

We have two indexes, one is for apm-\* and another is for dev1-applogs-be-\*  
In docker, entry point script I added like below which deployed in Kubernetes(pod is the running fine successfully)

java -Xms512M -Xmx2G -javaagent:-/services/apm/elastic-apm-agent.jar -Delastic.apm.enable\_log\_correlation=true -jar /services/service1/service1\*.jar --server.port=\<port\_num\> --spring.application.name=service1

**index1-\>apm-** \*  
These logs contain metrics such as trace id, span id and other fields.

**index2-\> dev1-applogs-be-** \*

These java application logs come from all the pods-containers across the nodes by adding log path in filebeat.yml (filebeat dameonset)

How to check complete trace log by using trace id/ span id in dev1-applogs-be-\*

Please let me know if any details required`

---

<div class="post-metadata">

**Author:** ![riferrei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/riferrei/32/104867_2.png) [@riferrei](https://discuss.elastic.co/u/riferrei)\
**Post date:** [October 27, 2021, 4:47pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/10 "2021-10-27T16:47:28Z")

</div>

You should be able to see the logs from the trace as shown below:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/559ecedd9d1e085feb44f1cf45d9817d3a2ffe8c.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/9/39e3217c5755ec4fe5fd65e6c8a8e5a9614c6147.png)

But that requires the logs to be compliant with the ECS format. Make sure the logs are generated using the [Java ECS Logging](https://www.elastic.co/guide/en/ecs-logging/java/1.x/setup.html) framework, and you will be good to go. Another way without changing your code is creating a ingest pipeline in Elasticsearch and augmenting the log data via a pipeline, which you can plug in your Filebeat configuration. But preferably, aim to generate the ECS format straight from your app.

— @riferrei

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 27, 2021, 7:23pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/11 "2021-10-27T19:23:36Z")

</div>

> [@riferrei](#):
>
> Make sure the logs are generated using the [Java ECS Logging](https://www.elastic.co/guide/en/ecs-logging/java/1.x/setup.html) framework,

This is critical ^^^^

Also you can validate by just looking at the logs and you should see something like this in the logs those 2 fields get injected by the `enable_log_correlation` setting

```auto
trace.id : 048e8431ca04a61d0eed84e98321e122

transaction.id : 1ff61169634559c9

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2021, 7:23pm UTC](https://discuss.elastic.co/t/how-to-integrate-apm-trace-id-with-java-logs/287705/12 "2021-11-24T19:23:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
