# How to use the log tail feature in Kibana 6.5.4

**URL:** <https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658>\
**Category:** Logs\
**Created:** [January 10, 2019, 5:30am UTC](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658 "2019-01-10T05:30:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![akhisar](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@akhisar](https://discuss.elastic.co/u/akhisar)\
**Post date:** [January 10, 2019, 5:30am UTC](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658/1 "2019-01-10T05:30:45Z")

</div>

Hello All,

I am using fluentd as my log shipper for kubernetes microservices. I have read that the new kibana version have the log tailing feature for viewing the changes in the logs. Can someone guide me how it can work with a fluentd shipper!!

Currently I am using the logtrail pluggin for this purpose.

Rgds,  
-Akhil

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 10, 2019, 6:44am UTC](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658/2 "2019-01-10T06:44:37Z")

</div>

You just need to use the Logs app, see [https://www.elastic.co/guide/en/kibana/6.5/xpack-logs.html](https://www.elastic.co/guide/en/kibana/6.5/xpack-logs.html)

---

<div class="post-metadata">

**Author:** ![akhisar](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@akhisar](https://discuss.elastic.co/u/akhisar)\
**Post date:** [January 17, 2019, 7:16am UTC](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658/3 "2019-01-17T07:16:39Z")

</div>

Hello,

But it seem to only work with the filebeat indices. Should I do some workaround for the fluentd log(which is shipped as logstash format) for it to work?

Rgds,  
-Akhil

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 29, 2019, 11:40am UTC](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658/4 "2019-01-29T11:40:58Z")

</div>

Hi @akhisar,

the Logs UI by default indeed looks at the `filebeat-*` indices and requires at the very least a `@timestamp` and a `message` or `@message` field on the documents.

The index pattern and the timestamp field can currently be changed via the Kibana config file using the settings

```auto
xpack.infra.sources.default:
  logAlias: 'my-log-indices-*'
  fields:
    timestamp: 'my-timestamp-field'

```

This configuration will be made available via the UI very soon (see [Kibana PR #26786](https://github.com/elastic/kibana/pull/26786) for the progress).

Using these settings it should be possible for you to make the fluentd indices available in the Logs UI.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2019, 11:40am UTC](https://discuss.elastic.co/t/how-to-use-the-log-tail-feature-in-kibana-6-5-4/163658/5 "2019-02-26T11:40:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
