# How to solve in Kibana: Visualization of specific log entries with additional information?

**URL:** <https://discuss.elastic.co/t/how-to-solve-in-kibana-visualization-of-specific-log-entries-with-additional-information/79184>\
**Category:** Kibana\
**Created:** [March 19, 2017, 6:40pm UTC](https://discuss.elastic.co/t/how-to-solve-in-kibana-visualization-of-specific-log-entries-with-additional-information/79184 "2017-03-19T18:40:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![test\_user](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@test\_user](https://discuss.elastic.co/u/test_user)\
**Post date:** [March 19, 2017, 6:40pm UTC](https://discuss.elastic.co/t/how-to-solve-in-kibana-visualization-of-specific-log-entries-with-additional-information/79184/1 "2017-03-19T18:40:23Z")

</div>

Hi all,

We want to migrate existing script based solution into Kibana, with following features:

- handling multiple specific(fetching with regular expressions) text log entries.  
Should be not peformant has to run only several times each day.
- on each fetched log entry we should show specific additional related configuration information.
- We want to visualize in a table view with customized header row and column.

How i achieve this in Kibana. Please give me a hint regarding:

- which is in this situation the best way to process log entries?
- How can I visualize it as described in the beginning?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [March 21, 2017, 7:40pm UTC](https://discuss.elastic.co/t/how-to-solve-in-kibana-visualization-of-specific-log-entries-with-additional-information/79184/2 "2017-03-21T19:40:27Z")

</div>

Hi there,

Are you currently indexing your log data into Elasticsearch? If so, can you provide a sample log and the Elasticsearch mapping you're using?

Thanks!

---

<div class="post-metadata">

**Author:** ![test\_user](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@test\_user](https://discuss.elastic.co/u/test_user)\
**Post date:** [March 22, 2017, 1:41pm UTC](https://discuss.elastic.co/t/how-to-solve-in-kibana-visualization-of-specific-log-entries-with-additional-information/79184/3 "2017-03-22T13:41:38Z")

</div>

Hello Lukas,

yes, we are indexing it but at this stage the important text part(position right after loglevel column information) on each line is not indexed (GREEDYDATA).  
Below are some sample log rows, highlighted text parts (number and string) are entries for fetching related row. Numbers are also keys for additional Info in order to show later on in a view somewhere

ltimestamp threadid loglevel textpart  
2017-03-22 T04:28:04.280 [0x7f6d92b67700] INFO - [SFE- **00342**]: SFE-00342 **market housekeeping starts**  
2017-03-22 T05:57:05.271 [0x7f6d92b67700] INFO - [SFE- **01350**]: SFE-01350 **market housekeeping starts**  
2017-03-22 T07:27:01.285 [0x7f70a4287700] WARN - No tick denominator available for listing: 933984583,113,0 Prov: 152  
2017-03-22 T04:28:12.021 [0x7f6d92b67700] ALERT - [SFE- **00342**]: updateSodHKStatus SFE-00342 SODHK for market 342 **terminates after**  
2017-03-22 T05:57:06.404 [0x7f6d92b67700] ALERT - [SFE- **01350**]: updateSodHKStatus SFE-01350 SODHK for market 1350 **terminates after**

Below is current mapping visible

Thanks in advance!

"filebeat-2017.03.21" : {  
"mappings" : {  
"log" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date"  
},  
"@version" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"beat" : {  
"properties" : {  
"hostname" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"name" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"version" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
}  
}  
},  
"debugtimestamp" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"host" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"input\_type" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"loglevel" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"ltimestamp" : {  
"type" : "date"  
},  
"message" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"offset" : {  
"type" : "long"  
},  
"source" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"tags" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"threadid" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"type" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
}  
}  
}  
}  
},

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [March 28, 2017, 6:28pm UTC](https://discuss.elastic.co/t/how-to-solve-in-kibana-visualization-of-specific-log-entries-with-additional-information/79184/4 "2017-03-28T18:28:14Z")

</div>

It looks like you're using Filebeat. Have you tried using the [sample Filebeat Kibana dashboards](https://www.elastic.co/guide/en/beats/libbeat/current/import-dashboards.html)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2017, 6:28pm UTC](https://discuss.elastic.co/t/how-to-solve-in-kibana-visualization-of-specific-log-entries-with-additional-information/79184/5 "2017-04-25T18:28:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
