# LogLevel field in kibana

**URL:** <https://discuss.elastic.co/t/loglevel-field-in-kibana/164524>\
**Category:** Logstash\
**Created:** [January 16, 2019, 7:05pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524 "2019-01-16T19:05:54Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![shiv94](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Post date:** [January 16, 2019, 7:05pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/1 "2019-01-16T19:05:54Z")

</div>

Hello,

I want to get the log level field in kibana for all the logs

For example,

2019-01-16 13:54:55,833 INFO [org.apache.cxf.wsdl.service.factory.ReflectionServiceFactoryBean] (default task-29) Creating Service {[http://www.GETWPWS.WBS2PRMI.com](http://www.GETWPWS.WBS2PRMI.com)}GETWPWSService from WSDL: file:/var/acweb/properties/GtWp.wsdl  
2019-01-16 13:54:55,929 ERROR [io.undertow.request] (default task-29) UT005023: Exception handling request to /agent/agentweb/tertiary\_template.jsp: javax.servlet.ServletException: javax.servlet.ServletException: javax.servlet.ServletExc  
eption: javax.servlet.jsp.JspException: No bean found under attribute key policyCorrespondenceDocumentList  
at org.apache.struts.chain.ComposableRequestProcessor.process(ComposableRequestProcessor.java:286)  
at org.apache.struts.action.ActionServlet.process(ActionServlet.java:1913)  
at org.apache.struts.action.ActionServlet.doGet(ActionServlet.java:449)  
at javax.servlet.http.HttpServlet.service(HttpServlet.java:687)  
at javax.servlet.http.HttpServlet.service(HttpServlet.java:790)  
at io.undertow.servlet.handlers.ServletHandler.handleRequest(ServletHandler.java:85)  
at io.undertow.servlet.handlers.FilterHandler$FilterChainImpl.doFilter(FilterHandler.java:129)  
at org.springframework.security.web.FilterChainProxy$VirtualFilterChain.doFilter(FilterChainProxy.java:320)

I need to get log level as INFO, ERROR, WARN, DEBUG ... In the above I have two entries one is INFO and other is ERROR. Is there any option to get these values for log level field?  
I tried using grok filter but didn't work

grok {  
match =\> { "message" =\> ["%{TIMESTAMP\_ISO8601:timestamp} %{LOGLEVEL:loglevel} (?(?:[a-zA-Z0-9]+.)\*[-A-Za-z0-9$]+) %{GREEDYDATA:message}"]  
}  
mutate {  
add\_field =\> {"loglevel" =\> %{LOGLEVEL:level}}  
}  
}`Preformatted text`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 7:15pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/2 "2019-01-16T19:15:32Z")

</div>

As displayed, that is not a valid grok pattern. If you are posting a configuration please select it in the edit pane and click on \</\> in the toolbar above the pane.

What are you trying to achieve using the mutate filter?

---

<div class="post-metadata">

**Author:** ![shiv94](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Post date:** [January 16, 2019, 7:18pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/3 "2019-01-16T19:18:56Z")

</div>

I am trying to pull the LOGLEVEL value. Can you suggest me better option?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 7:22pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/4 "2019-01-16T19:22:54Z")

</div>

```
match => { "message" => ["^%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:loglevel}"]

```

will get you a field on the event called loglevel. But I get a feeling you actually want more than that. You still need to fix your original post.

---

<div class="post-metadata">

**Author:** ![shiv94](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Post date:** [January 16, 2019, 7:29pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/5 "2019-01-16T19:29:10Z")

</div>

Will loglevel will be displayed in the kibana? Like in the below image. `Preformatted text`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/1/91eff4b23b2672d1888708325666fe8086490026.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 7:31pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/6 "2019-01-16T19:31:13Z")

</div>

Well, it will add a field called loglevel to the event. If you ingest that into elasticsearch then if kibana queries elasticsearch the field will be there.

---

<div class="post-metadata">

**Author:** ![shiv94](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Post date:** [January 16, 2019, 7:59pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/7 "2019-01-16T19:59:07Z")

</div>

Hi Badger ,  
I tried this and got the below error

```
        filter {
         if "abcd" in [tags] {
         match => { "message" => ["^%{TIMESTAMP_ISO8601:timestamp1} %{LOGLEVEL:loglevel}"] }
         }
        }

```

[2019-01-16T14:57:37,361][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.4.1"}  
[2019-01-16T14:57:37,623][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, { at line 68, column 8 (byte 1092) after filter {\n if "abcd" in [tags] {\n match ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:90:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:38:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:309:in`block in converge\_state'"]}

timestamp1 and loglevel field should be displayed like in the below image

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f565d0f434c0ff7ba05440e2f13da291e7a92680.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 8:07pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/8 "2019-01-16T20:07:39Z")

</div>

You are missing 'grok {' and the matching }

---

<div class="post-metadata">

**Author:** ![shiv94](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Post date:** [January 16, 2019, 8:10pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/9 "2019-01-16T20:10:43Z")

</div>

Thanks and sorry for the wrong post

---

<div class="post-metadata">

**Author:** ![shiv94](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Post date:** [January 16, 2019, 8:22pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/10 "2019-01-16T20:22:38Z")

</div>

Got it but I can see for only few events, even other contains the same format

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c52ec7959558863898068c7089ae99efd271ae31.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2019, 8:26pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/11 "2019-01-16T20:26:02Z")

</div>

OK, so what does the message field look like on one of those events that does not have loglevel?

---

<div class="post-metadata">

**Author:** ![shiv94](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@shiv94](https://discuss.elastic.co/u/shiv94)\
**Post date:** [January 16, 2019, 8:32pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/12 "2019-01-16T20:32:15Z")

</div>

I did the changes only in one server not the entire cluster. Now, it works

Thanks a lot for you immediate response helped me alot 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2019, 8:32pm UTC](https://discuss.elastic.co/t/loglevel-field-in-kibana/164524/13 "2019-02-13T20:32:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
