# Logstash to kibana index pattern fields

**URL:** <https://discuss.elastic.co/t/logstash-to-kibana-index-pattern-fields/146418>\
**Category:** Kibana\
**Created:** [August 28, 2018, 8:32pm UTC](https://discuss.elastic.co/t/logstash-to-kibana-index-pattern-fields/146418 "2018-08-28T20:32:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jlim0930](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@jlim0930](https://discuss.elastic.co/u/jlim0930)\
**Post date:** [August 28, 2018, 8:32pm UTC](https://discuss.elastic.co/t/logstash-to-kibana-index-pattern-fields/146418/1 "2018-08-28T20:32:35Z")

</div>

Hello,

new to the whole ELK scene.. I had my environment stood up with multiple nodes and when I installed filebeat it installed the filebeat-\* index pattern with a lot of fields that it used for various visualizations and dashboards.

I have my logstash setup so that its taking in syslogs from remote servers and it is reporting it into ES and I can see it in kibana but now I am trying to create some meaningful visualizations and dashboards and noticed that the filebeat-\* index pattern has so many more fields than my logstash-\* index pattern. I am mainly just starting so I wanted to concentrate on ssh login/failed login/sudo and create dashboard/visualization like the ones that filebeat provided.

I looked on the discussion and google but and the only thing I found close to what I am looking for was [https://www.elastic.co/blog/grokking-the-linux-authorization-logs](https://www.elastic.co/blog/grokking-the-linux-authorization-logs) however it does not tie things into logstash/kibana much or how to get there...

any help on my next steps?

I am on 6.4

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 29, 2018, 6:24am UTC](https://discuss.elastic.co/t/logstash-to-kibana-index-pattern-fields/146418/2 "2018-08-29T06:24:38Z")

</div>

You probably need to parse out fields in your Logstash config. Have a look at [this blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash) for an introduction how to go about this.

---

<div class="post-metadata">

**Author:** ![jlim0930](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@jlim0930](https://discuss.elastic.co/u/jlim0930)\
**Post date:** [August 29, 2018, 12:42pm UTC](https://discuss.elastic.co/t/logstash-to-kibana-index-pattern-fields/146418/3 "2018-08-29T12:42:44Z")

</div>

thank you will check it out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2018, 12:42pm UTC](https://discuss.elastic.co/t/logstash-to-kibana-index-pattern-fields/146418/4 "2018-09-26T12:42:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
