# Java-ecs-logging

**URL:** <https://discuss.elastic.co/t/java-ecs-logging/201266>\
**Category:** Logs\
**Created:** [September 26, 2019, 4:06pm UTC](https://discuss.elastic.co/t/java-ecs-logging/201266 "2019-09-26T16:06:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rem](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@Rem](https://discuss.elastic.co/u/Rem)\
**Post date:** [September 26, 2019, 4:06pm UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/1 "2019-09-26T16:06:35Z")

</div>

Hi,  
Hope there is someone that can help me.

Config.xml for Log4j2 :

```auto
<Console name="LogToConsole" target="SYSTEM_OUT">
	<Appenders>
		<Console name="LogToConsole" target="SYSTEM_OUT">
			<EcsLayout>
				<KeyValuePair key="additionalField1" value="constant value"/>
				<KeyValuePair key="typeFromStructMsg" value="${sd:msg}"/>
				<KeyValuePair key="nameFromMapMsg" value="${map:name}"/>
                                <KeyValuePair key="nameFromContext" value="${ctx:test}"/>
				<KeyValuePair key="mySysProperty" value="${sys:mySysProperty}"/>
			</EcsLayout>
		</Console>
	</Appenders>
	<Loggers>
		<Root>
			<AppenderRef ref="LogToConsole" />
		</Root>
	</Loggers>
</Configuration>

```

When I add value in a Map or in the ThreadContext, I always get "labels.name" or "labels.test" but I need the fields to be at the base of my Elastic Common Schema (ECS).

How can I do it and is it thread safe?

Thank you!

Example of code :

```auto
StringMapMessage mapMsg = new StringMapMessage();
        mapMsg.put("name", "arun");
		logger.warn(mapMsg);

```

or

```auto
ThreadContext.put("test", "test");
logger.info("any message");

```

using this open source project : [https://github.com/elastic/java-ecs-logging](https://github.com/elastic/java-ecs-logging)

---

<div class="post-metadata">

**Author:** ![Kerry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kerry/32/40330_2.png) [@Kerry](https://discuss.elastic.co/u/Kerry)\
**Post date:** [September 26, 2019, 5:06pm UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/2 "2019-09-26T17:06:52Z")

</div>

Hi @Rem, I've reached out to someone who knows about the [java-ecs-logging](https://github.com/elastic/java-ecs-logging) project, as this is unfortunately not something I can help you with directly myself.

---

<div class="post-metadata">

**Author:** ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)\
**Post date:** [September 27, 2019, 8:26am UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/3 "2019-09-27T08:26:01Z")

</div>

Thanks for checking out the `EcsLayout`!

As you have noticed, by default the `MDC` values are nested under `labels` as this is the most natural place from the ECS perspective. However, there is a configuration setting for the log4j2 `EcsLayout` where you can define specific fields which should be serialized at the top level: [https://github.com/elastic/java-ecs-logging/blob/master/log4j2-ecs-layout/README.md#layout-parameters](https://github.com/elastic/java-ecs-logging/blob/master/log4j2-ecs-layout/README.md#layout-parameters).

Also make sure to have a look at the tips and gotchas listed here: [https://github.com/elastic/java-ecs-logging/blob/master/log4j2-ecs-layout/README.md#structured-logging](https://github.com/elastic/java-ecs-logging/blob/master/log4j2-ecs-layout/README.md#structured-logging).

Cheers,  
Felix

---

<div class="post-metadata">

**Author:** ![Rem](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@Rem](https://discuss.elastic.co/u/Rem)\
**Post date:** [September 27, 2019, 3:35pm UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/4 "2019-09-27T15:35:40Z")

</div>

Hi,  
Here is my Config.xml file for Log4j2. Notice that event.action is an official field that I took from the Elastic Common Scheman (ECS).  
Therefore, I expect the fields to be at the base of the the json output (no labels prefix).

```auto
<Console name="LogToConsole" target="SYSTEM_OUT">
	<Appenders>
		<Console name="LogToConsole" target="SYSTEM_OUT">
			<EcsLayout>
				<KeyValuePair key="event.action" value="$${ctx:event.action}" />
			</EcsLayout>
		</Console>
	</Appenders>
	<Loggers>
		<Root>
			<AppenderRef ref="LogToConsole" />
		</Root>
	</Loggers>
</Configuration>

```

Here's my code from my JUnit test :

```auto
package com.myapplication.logs

import org.apache.logging.log4j.LogManager;
import org.apache.logging.log4j.Logger;
import org.apache.logging.log4j.ThreadContext;

import junit.framework.TestCase;

public class ECSLayoutJUnit extends TestCase{
	private Logger logger = LogManager.getLogger(ECSLayoutJUnit.class);
    
	public void testLogConsole() throws Exception {
		ThreadContext.put("event.action", "Processing");
		logger.info("I am a simple test.");
		ThreadContext.clearMap();
	}
}

```

And here is the output :

```auto
{
    "@timestamp": "2019-09-27T15:33:50.745Z",
    "log.level": "INFO",
    "message": "I am a simple test.",
    "process.thread.name": "main",
    "log.logger": "com.myapplication.logs.ECSLayoutJUnit",
    "event.action": "Processing",
    "labels.event.action": "Processing"
}

```

Expected behavior :

```auto
{
    "@timestamp": "2019-09-27T15:33:50.745Z",
    "log.level": "INFO",
    "message": "I am a simple test.",
    "process.thread.name": "main",
    "log.logger": "com.myapplication.logs.ECSLayoutJUnit",
    "event.action": "Processing"
}

```

Why am I having the field "labels.event.action" if this is an official ECS field?  
What am I doing wrong?  
Note that the field "event.action" is duplicated by "labels.event.action".  
Note that I need to fill the ECS field "event.action" at the runtime and I need some java code to do so.

Thank you!

---

<div class="post-metadata">

**Author:** ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)\
**Post date:** [September 27, 2019, 3:55pm UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/5 "2019-09-27T15:55:39Z")

</div>

Try with this configuration:

```auto
<Console name="LogToConsole" target="SYSTEM_OUT">
	<Appenders>
		<Console name="LogToConsole" target="SYSTEM_OUT">
			<EcsLayout topLevelLabels="event.action"/>
		</Console>
	</Appenders>
	<Loggers>
		<Root>
			<AppenderRef ref="LogToConsole" />
		</Root>
	</Loggers>
</Configuration>

```

Then you can do this:

```java
ThreadContext.put("event.action", "Processing");
logger.info("I am a simple test.");
ThreadContext.clearMap();

```

However, I would recommend using `StringMapMessage`. No special configuration is required then:

```java
logger.info(new StringMapMessage()
    .with("message", "I am a simple test.")
    .with("event.action", "Processing"));

```

---

<div class="post-metadata">

**Author:** ![Rem](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@Rem](https://discuss.elastic.co/u/Rem)\
**Post date:** [September 30, 2019, 4:30pm UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/6 "2019-09-30T16:30:34Z")

</div>

The configurations work from version 0.1.1 of the project.

Thank you so much!

Thought, we do not need anymore to add the topLevelLabels="event.action" with this version.

So, I guess I will have add it manually if necessary.

The configuration topLevelLabels is now necessary only if I use the ThreadContext at runtime to add a JSON parameter to the logs.

If the field is add at runtime via StringMapMessage, it is at the top level.  
If the field is add at runtime with ThreadContext. Then, the prefix label is add.

---

<div class="post-metadata">

**Author:** ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)\
**Post date:** [October 1, 2019, 10:21am UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/7 "2019-10-01T10:21:39Z")

</div>

I've just released 0.1.1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2019, 10:21am UTC](https://discuss.elastic.co/t/java-ecs-logging/201266/8 "2019-10-29T10:21:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
