# Logs not in sequence as in console output

**URL:** <https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437>\
**Category:** Logstash\
**Created:** [July 2, 2019, 6:08am UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437 "2019-07-02T06:08:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [July 2, 2019, 6:08am UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/1 "2019-07-02T06:08:31Z")

</div>

I am sending logs from Jenkins to ELK. Because of the jade timestamp and not having enough precision to nano or milli seconds , I have introduced a sequence number against every line of log that enters logstash . Even after introducing the sequence number , the problem persists. If the logs are not in sequence in Kibana , its misleading to the users.

**Below is the sample of console logs in jenkins :**

 ![Capture2](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f686027bdf533339ca515e8f955d5581821b3b54.png)

**Below is a sample of how logs are in my kibana : The number on extreme right is the sequence number.**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0b9624e47b6a7f2c9aeb0a2f0332604c1d92a1b.png)

As can be seen , the log line "Finished :Success " is at the bottom in actual jenkins logs . but in my kibana UI it appears in the middle.

Will any change in the pipeline work ?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 2, 2019, 6:10am UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/2 "2019-07-02T06:10:40Z")

</div>

How are you assigning the sequence number? If done in a filter it is possible the logs are not processed in order. I believe Filebeat provides an offset value that you can use to order data within a file, so I would recommend using that over the Logstash file input plugin.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [July 2, 2019, 6:22am UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/3 "2019-07-02T06:22:38Z")

</div>

Offset is the number of bytes read. If I sort by offset , the sequence will not be maintained. I tried doing that as I can see a filed by name "offset" in kibana.

I am using input filter , and ruby code to introduce the sequence number to every line of log. As can be seen below , the sequence starts from 100 and increases by one to every line of log , it encounters.

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa0b75b2b7c74d745b17968890873c17e2c5b4e7.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 2, 2019, 7:11am UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/4 "2019-07-02T07:11:14Z")

</div>

The offset will give you the order although not sequential values. I am not sure if the ordering of events is guaranteed once you get to the filter stage so you may need to implement a custom codec.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 2, 2019, 12:44pm UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/5 "2019-07-02T12:44:00Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> I am not sure if the ordering of events is guaranteed once you get to the filter stage

With the java execution engine (the default in v7) both filters and outputs [can](https://discuss.elastic.co/t/elpased-filter-works-differently-6-8-1-vs-7-1-possible-bug/187400/2) re-order events, even with '--pipeline.workers 1'.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [July 2, 2019, 1:04pm UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/6 "2019-07-02T13:04:00Z")

</div>

Thanks for responding back . Glad to know about the issue with V7. Even though I am not using V7 , if the order is not maintained , its misleading. There must be a fix for this.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [July 2, 2019, 1:08pm UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/7 "2019-07-02T13:08:49Z")

</div>

Right now I have reduced 'pipeline.batch.size' to 1 . After this the order is maintained in Kibana , how ever only time will tell how effective a solution this is . I have not changed the default pipeline workers , which is 1 by default. I am not able to figure out how to use '-w 1'. my ELK version is 6.3.2

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2019, 1:08pm UTC](https://discuss.elastic.co/t/logs-not-in-sequence-as-in-console-output/188437/8 "2019-07-30T13:08:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
