# Log source "unknown" in Observability Overview

**URL:** <https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568>\
**Category:** Logs\
**Created:** [January 28, 2021, 9:23pm UTC](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568 "2021-01-28T21:23:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![strophy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strophy/32/83080_2.png) [@strophy](https://discuss.elastic.co/u/strophy)\
**Post date:** [January 28, 2021, 9:23pm UTC](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568/1 "2021-01-28T21:23:10Z")

</div>

I'm new to Elastic Stack and have successfully set up a pipeline with Filebeat, Elasticsearch and Kibana to ingest data from log files. I have set up the display fields in Observability settings, which works for the Logs view, but I can't see where to define the source so it doesn't appear as "Unknown" in the Overview chart:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fcbfd5a192c98cab196734cf84e994d33d1204d5.png)

Can anyone tell me where this is done or point me to the right docs? Thanks!

---

<div class="post-metadata">

**Author:** ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)\
**Post date:** [January 29, 2021, 7:29am UTC](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568/2 "2021-01-29T07:29:39Z")

</div>

Hi and welcome to the forum 👋

You'll have to populate the `event.dataset` field for that which helps you to differ between log streams. The default value our [ECS logging](https://www.elastic.co/guide/en/ecs-logging/overview/master/intro.html) libraries use is `${serviceName}.log`, for example `my-app.log`.

---

<div class="post-metadata">

**Author:** ![strophy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strophy/32/83080_2.png) [@strophy](https://discuss.elastic.co/u/strophy)\
**Post date:** [January 29, 2021, 10:51pm UTC](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568/3 "2021-01-29T22:51:13Z")

</div>

Works great! Thanks for the friendly welcome and quick response 🙂

---

<div class="post-metadata">

**Author:** ![fzyzcjy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fzyzcjy/32/78628_2.png) [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Post date:** [January 30, 2021, 4:20am UTC](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568/4 "2021-01-30T04:20:38Z")

</div>

Hi, how can I set up the serviceName? I have tried the following but only service name is set, and event.dataset is not set.

I guess it is not the best way to set up service name... Is there any suggested approach to **set up service.name for any general services?**

```auto
...
          - rename:
              fields:
                - from: "spring.message"
                  to: "message"
                - from: "spring.application_name"
                  to: "service.name"

```

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2021, 4:20am UTC](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568/5 "2021-02-27T04:20:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
