# Logs definition

**URL:** <https://discuss.elastic.co/t/logs-definition/327211>\
**Category:** Logs\
**Created:** [March 7, 2023, 4:36pm UTC](https://discuss.elastic.co/t/logs-definition/327211 "2023-03-07T16:36:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefan7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefan7/32/118171_2.png) [@Stefan7](https://discuss.elastic.co/u/Stefan7)\
**Post date:** [March 7, 2023, 4:36pm UTC](https://discuss.elastic.co/t/logs-definition/327211/1 "2023-03-07T16:36:07Z")

</div>

Greetings,  
Can someone please direct me to a location where I can find a definition of logs?  
Here's a preliminary list that I am trying to clarify:  
'logs-elastic\_agent'  
'metrics-elastic\_agent.elastic\_agent '  
'logs-elastic\_agent.filebeat\_input '  
'metrics-elastic\_agent.filebeat\_input '  
'logs-elastic\_agent.filebeat '  
'metrics-elastic\_agent.filebeat '  
'logs-elastic\_agent.metricbeat '  
'metrics-elastic\_agent.metricbeat '  
'metrics-system.cpu '  
'metrics-system.diskio '  
'metrics-system.filesystem '  
'metrics-system.fsstat '  
'metrics-system.load '  
'metrics-system.memory '  
'metrics-system.network '  
'metrics-system.process '  
'metrics-system.process.summary '  
'metrics-system.socket\_summary '  
'metrics-system.uptime '  
'logs-windows.powershell '  
'logs-windows.powershell\_operational '  
'logs-windows.sysmon\_operational '  
'metrics-windows.perfmon '  
'metrics-windows.service '  
'logs-winlog.winlog'

Thank you!

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [March 7, 2023, 6:04pm UTC](https://discuss.elastic.co/t/logs-definition/327211/2 "2023-03-07T18:04:51Z")

</div>

These all look like data streams coming from either Filebeat or Metricbeat. I'm assuming you're looking for the schema for each "module". Anything with the prefix of `logs-` you can assume is a Filebeat module and anything with the prefix of `metrics-` is a Metricbeat module.

Let's look at `metrics-system.cpu` first:

- `metrics-` denotes that it's part of Metricbeat
- `system.` denotes it's the `system` module
- `cpu` is the dataset.

To find out the schema, take a look at the Metricbeat documentation [here](https://www.elastic.co/guide/en/beats/metricbeat/current/metricbeat-overview.html) and click on "Exported Fields" to expand it in left hand navigation and pick "[System fields](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-system.html)" then scroll down to the "[CPU](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-system.html#_cpu_11)" section.

There should also be coresponding documentation for anything with `logs-` prefix located under the [Filebeat documentation.](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields.html)

---

<div class="post-metadata">

**Author:** ![Stefan7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefan7/32/118171_2.png) [@Stefan7](https://discuss.elastic.co/u/Stefan7)\
**Post date:** [March 7, 2023, 6:34pm UTC](https://discuss.elastic.co/t/logs-definition/327211/3 "2023-03-07T18:34:06Z")

</div>

Many thanks, Chris! I will follow up on the tracks you outlined.

---

<div class="post-metadata">

**Author:** ![Stefan7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefan7/32/118171_2.png) [@Stefan7](https://discuss.elastic.co/u/Stefan7)\
**Post date:** [March 7, 2023, 7:24pm UTC](https://discuss.elastic.co/t/logs-definition/327211/4 "2023-03-07T19:24:08Z")

</div>

Hi again Chris,

I was able to find the proper exported fields in the Metricbeat documentation (CPU was a good example), but cannot find the same with the logs- prefix in the Filebeat documentation. I was looking for a module elastic-agent and can't find any. Do you have any additional suggestion?  
Many thanks!

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [March 7, 2023, 8:01pm UTC](https://discuss.elastic.co/t/logs-definition/327211/5 "2023-03-07T20:01:45Z")

</div>

All I can find is this doc for the Elastic Agent logs and metrics: [Monitor Elastic Agents | Fleet and Elastic Agent Guide [8.6] | Elastic](https://www.elastic.co/guide/en/fleet/current/monitor-elastic-agent.html#view-agent-logs)

It might be easier to look at those feeds in Kibana via Discover and look at a sample document.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2023, 8:02pm UTC](https://discuss.elastic.co/t/logs-definition/327211/6 "2023-04-04T20:02:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
