I'm new to Elastic Stack and have successfully set up a pipeline with Filebeat, Elasticsearch and Kibana to ingest data from log files. I have set up the display fields in Observability settings, which works for the Logs view, but I can't see where to define the source so it doesn't appear as "Unknown" in the Overview chart:
You'll have to populate the event.dataset field for that which helps you to differ between log streams. The default value our ECS logging libraries use is ${serviceName}.log, for example my-app.log.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.