# How to read my spring-boot application logs from APM logs menu?

**URL:** <https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635>\
**Category:** APM\
**Tags:** docker, java\
**Created:** [February 3, 2023, 10:06am UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635 "2023-02-03T10:06:09Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vincentLG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincentlg/32/116734_2.png) [@vincentLG](https://discuss.elastic.co/u/vincentLG)\
**Post date:** [February 3, 2023, 10:06am UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/1 "2023-02-03T10:06:09Z")

</div>

Hello,

I have a spring-boot application running into a docker container. I have set up Filebeat, and I can read my dockerized spring-boot application logs from Kibana Stream logs menu:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37f12db6227781d5fa481bf7c344ee4d4647a76a.png)

I have set up an APM server enrolled by Fleet, and my APM Agent enrolled in my spring boot application sends data to my APM server:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c6f6d6da911ef33560777ae78e525481037f0d4.png)

How can I see logs of my spring-boot application into the APM logs menu?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a649ca33769942bebfa13fad5a742143f7638e55.png)

---

<div class="post-metadata">

**Author:** ![rishikeshr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rishikeshr/32/100457_2.png) [@rishikeshr](https://discuss.elastic.co/u/rishikeshr)\
**Post date:** [February 3, 2023, 4:39pm UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/2 "2023-02-03T16:39:16Z")

</div>

Hello @vincentLG ,

If you haven't checked this before, perhaps you could try the steps in the document below:

> **[Get started | ECS Logging Java Reference \[master\] | Elastic](https://www.elastic.co/guide/en/ecs-logging/java/master/setup.html)**

Thanks,  
Rishikesh R

---

<div class="post-metadata">

**Author:** ![Eyal\_Koren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eyal_koren/32/36830_2.png) [@Eyal\_Koren](https://discuss.elastic.co/u/Eyal_Koren)\
**Post date:** [February 5, 2023, 7:55am UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/3 "2023-02-05T07:55:23Z")

</div>

More useful info on the matter can be found in [our application logs guide](https://www.elastic.co/guide/en/observability/master/application-logs.html) and at the [agent's docs](https://www.elastic.co/guide/en/apm/agent/java/current/logs.html).  
In short, you can now get your logs to be automatically [reformatted](https://www.elastic.co/guide/en/apm/agent/java/current/config-logging.html#config-log-ecs-reformatting) to Elastic Common Schema and as of the APM agent [latest version](https://www.elastic.co/guide/en/apm/agent/java/current/release-notes-1.x.html#release-notes-1.36.0), you can even get your logs indexed without Filebeat, although you may need to wait for 8.7 for the full log sending capability.  
@Sylvain_Juge does this intake endpoint already exist in 8.6, or would it be added only in 8.7?

---

<div class="post-metadata">

**Author:** ![vincentLG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincentlg/32/116734_2.png) [@vincentLG](https://discuss.elastic.co/u/vincentLG)\
**Post date:** [February 6, 2023, 8:36am UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/4 "2023-02-06T08:36:14Z")

</div>

Hey, thanks for your answer.

I've seen this option before. The Dockerfile for my Spring Boot application is something like this:

```auto
COPY target/*.jar /app.jar
COPY apm-agent/elastic-apm-agent-1.36.0.jar /agent.jar

ENTRYPOINT ["java","-javaagent:/agent.jar","-Delastic.apm.log_sending=true","-Delastic.apm.service_name=report","-Delastic.apm.secret_token=...","-Delastic.apm.server_urls=http://...:8200","-jar","/app.jar"]

```

So I already use the `log_sending` parameter, but I don't see any log in Kibana... I prefer to use your solution, so if you have any idea why it doesn't work with the `log_sending` parameter, please tell me.  
In the meantime, I will try the solution described in the document sent by @rishikeshr.

---

<div class="post-metadata">

**Author:** ![Sylvain\_Juge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain_juge/32/55521_2.png) [@Sylvain\_Juge](https://discuss.elastic.co/u/Sylvain_Juge)\
**Post date:** [February 6, 2023, 1:40pm UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/5 "2023-02-06T13:40:12Z")

</div>

Log sending endpoint is available in 8.6.0, prior to that filebeat was the only option to capture the logs.

For Java, we now have the most common log ingestion workflows examples in [our contrib repo](https://github.com/elastic/apm-contrib/tree/main/apm-agent-java/log-ingest).

If you want to keep filebeat for logs ingestion, I would suggest to just use [`elastic.apm.log_ecs_reformatting=override`](https://www.elastic.co/guide/en/apm/agent/java/current/config-logging.html#config-log-ecs-reformatting) and let filebeat capture the standard output from the container (which I am assuming you are currently using).

If you want to use `log_sending`, then we need to investigate a bit here, do you have anything visible in the general log stream (not the one per-service in your screenshot) ? Also do you see any log documents in discover ?

---

<div class="post-metadata">

**Author:** ![Eyal\_Koren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eyal_koren/32/36830_2.png) [@Eyal\_Koren](https://discuss.elastic.co/u/Eyal_Koren)\
**Post date:** [February 6, 2023, 1:54pm UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/6 "2023-02-06T13:54:25Z")

</div>

I missed it in the original comment - logs do seem to be sent and stored in ECS format, with proper `service.name` and those that were captured within transactions also contain `transaction.id` and `trace.id`.  
So what we need to understand is why this correlation doesn't show up in UI.  
Let me check

---

<div class="post-metadata">

**Author:** ![vincentLG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vincentlg/32/116734_2.png) [@vincentLG](https://discuss.elastic.co/u/vincentLG)\
**Post date:** [February 6, 2023, 3:14pm UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/7 "2023-02-06T15:14:36Z")

</div>

Okay thank you so much for your help! I was using the wrong version of apm-server (8.3.2 instead of 8.6.1). I can now see my logs in the APM menu.

---

<div class="post-metadata">

**Author:** ![Eyal\_Koren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eyal_koren/32/36830_2.png) [@Eyal\_Koren](https://discuss.elastic.co/u/Eyal_Koren)\
**Post date:** [February 6, 2023, 3:23pm UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/8 "2023-02-06T15:23:10Z")

</div>

Glad to hear, thanks for letting us know! 🎉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2023, 11:23am UTC](https://discuss.elastic.co/t/how-to-read-my-spring-boot-application-logs-from-apm-logs-menu/324635/9 "2023-02-27T11:23:40Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
