# Log Annotation

**URL:** <https://discuss.elastic.co/t/log-annotation/107138>\
**Category:** Logstash\
**Created:** [November 10, 2017, 6:15am UTC](https://discuss.elastic.co/t/log-annotation/107138 "2017-11-10T06:15:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sanjeev\_Routray](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@Sanjeev\_Routray](https://discuss.elastic.co/u/Sanjeev_Routray)\
**Post date:** [November 10, 2017, 6:15am UTC](https://discuss.elastic.co/t/log-annotation/107138/1 "2017-11-10T06:15:38Z")

</div>

So we have log files from SQL and Oracle logs. I want to know what the typical fields are that we need to extract (annotate) through logstash before sending it for indexing. Not sure if Filebeat has that domain intelligence.

The idea is to go behind very specific business use casess through these annotations. Any help would be highly appreciated

Thanks  
Sanjeev

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 10, 2017, 6:35am UTC](https://discuss.elastic.co/t/log-annotation/107138/2 "2017-11-10T06:35:21Z")

</div>

You either need Filebeat with an Elasticsearch ingest pipeline or Filebeat with Logstash.

What fields can and should be extracted depends on what's available and what you want to do with the logs. Most log formats offer a timestamp, a level, possibly a source (like a logger name), and a free-form message, so that's a starting point.

---

<div class="post-metadata">

**Author:** ![Sanjeev\_Routray](https://avatars.discourse-cdn.com/v4/letter/s/34f0e0/32.png) [@Sanjeev\_Routray](https://discuss.elastic.co/u/Sanjeev_Routray)\
**Post date:** [November 10, 2017, 6:45am UTC](https://discuss.elastic.co/t/log-annotation/107138/3 "2017-11-10T06:45:58Z")

</div>

Thanks Magnus,

I am looking beyond timestamp, level, source etc. For example, process IDs, State information etc. Things which an SME looks into while investigating an issue. I understand the "how" to extract part. what I am struggling with is "What" :). I am wondering if Microsoft (For SQL) has documented these "fields" somewhere. I will keep looking.  
Thanks  
Sanjeev

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2017, 6:46am UTC](https://discuss.elastic.co/t/log-annotation/107138/4 "2017-12-08T06:46:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
