# Logstash output to Kibana

**URL:** <https://discuss.elastic.co/t/logstash-output-to-kibana/300919>\
**Category:** Logstash\
**Created:** [March 29, 2022, 7:57am UTC](https://discuss.elastic.co/t/logstash-output-to-kibana/300919 "2022-03-29T07:57:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RomanKau](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@RomanKau](https://discuss.elastic.co/u/RomanKau)\
**Post date:** [March 29, 2022, 7:57am UTC](https://discuss.elastic.co/t/logstash-output-to-kibana/300919/1 "2022-03-29T07:57:23Z")

</div>

Running Windows 10, Logstash 8.1.0, Elasticsearch, kibana and filebeat 8.0.0 all on the same machine.

Getting the data from filebeat to kibana works great but the problem is that the whole log is in the field message and we want to have a field for every value in this log.

here is the pipeline which is in C:\Program Files\logstash-8.1.0\first-pipeline.conf:

```auto
 input {
	 beats {
        port => "5044"
    }
}
filter {
		grok {
        patterns_dir => ["./patterns"]
        match => { "message" => "%{DATESTAMP:DateTime},%{PName:Program},%{POSINT:ProcessID},%{POSINT:UsageCPU}" }
      }
    }
output {
	elasticsearch { hosts => ["localhost:9200"]
		user => "elastic"
		password => "my password" 
		ssl => true
		ssl_certificate_verification => false
		
        # The name of the Index 
        index => "<logstash_filelog>" 
        ilm_enabled => false
	}
}

```

Following this guide I have also created the pattern directory where the PName comes from: [Grok filter plugin | Logstash Reference [8.0] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)

C:\Program Files\logstash-8.1.0\patterns\filebeatpattern.txt

> #regex for program name logfilebeat ex: kibana  
> PName [A-Za-z]\w+

Here is the structure of the log file:

> DateTime, Program, PID, CPU Usage  
> 08.03.2022 14:53:41,Chrome,1715,58

Under Management -\> Stack Management I now have this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/b/0be67ea3c3ed233dfaab8a1118bfdb0e91613974.png)

The pipeline seems to be working but how do I get to visualize the pipeline in Kibana?

Any help would be appreciated.

Thanks in Advance

---

<div class="post-metadata">

**Author:** ![RomanKau](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@RomanKau](https://discuss.elastic.co/u/RomanKau)\
**Post date:** [March 31, 2022, 8:28am UTC](https://discuss.elastic.co/t/logstash-output-to-kibana/300919/2 "2022-03-31T08:28:02Z")

</div>

I realized what the issue was. I was missing the Data View. When creating a Data View the index showed up and now the data is visualized.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2022, 8:28am UTC](https://discuss.elastic.co/t/logstash-output-to-kibana/300919/3 "2022-04-28T08:28:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
