thanks for trying out version 6.5 of the Elastic Stack!
You're right that the documentation for the Logs UI leaves a lot to be desired.
It is currently designed to work with filebeat out-of-the box. That said, there is some flexibility if you're willing to change the Kibana configuration file (there will be a UI for that soon as well).
- The index pattern used to read log events can be changed via the
xpack.infra.sources.default.logAlias setting, which can contain any index pattern supported by Elasticsearch.
- The timestamp and sorting tiebreaker fields can be changed via the
- The logic to read the message from the individual documents looks at several fields specific to filebeat modules first, but then falls back to the
That means no matter what the ingestion pipeline is, as long as it is possible to formulate an index pattern and structure the documents therein such that they contain timestamp and
@message fields, the Log UI should pick them up, e.g.:
We would be very interested in hearing whether this worked for you and what other improvements you would wish for.