# Logtrail : Kibana plugin to view, search and tail logs in realtime

**URL:** <https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489>\
**Category:** Kibana\
**Created:** [September 14, 2016, 11:00am UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489 "2016-09-14T11:00:21Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![sivasamyk](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@sivasamyk](https://discuss.elastic.co/u/sivasamyk)\
**Post date:** [September 14, 2016, 11:00am UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/1 "2016-09-14T11:00:21Z")

</div>

All,

Good day!

I have written a Kibana plugin to view, search and tail logs in developer/sysadmin friendly interface ( inspired by [Papertrailapp](https://papertrailapp.com/)).

Installation and configuration instructions is at [[https://github.com/sivasamyk/logtrail](https://github.com/sivasamyk/logtrail)] ([https://github.com/sivasamyk/logtrail](https://github.com/sivasamyk/logtrail)). Currently it is supported for Kibana 4.x version. Following are the features supported:

- View, analyze and search log events from a centralized, developer and sysadmin friendly interface
- Live tail
- Filter aggregated logs by hosts and program
- Quickly seek to logs based on specific time

Checkout the plugin and let me know your feedback.

You can install the plugin by executing following command (requires restart of kibana after installation and config changes)

`./bin/kibana plugin -i logtrail -u https://github.com/sivasamyk/logtrail/releases/download/v4.x-0.1.0/logtrail-4.x-0.1.0.tar.gz`

Screenshot:

[![](https://raw.githubusercontent.com/sivasamyk/logtrail/master/screenshot.png) ](https://raw.githubusercontent.com/sivasamyk/logtrail/master/screenshot.png)

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 14, 2016, 11:18am UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/2 "2016-09-14T11:18:31Z")

</div>

Thanks for sharing this!

---

<div class="post-metadata">

**Author:** ![Ranvijay\_Jamwal](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@Ranvijay\_Jamwal](https://discuss.elastic.co/u/Ranvijay_Jamwal)\
**Post date:** [December 8, 2016, 12:07pm UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/3 "2016-12-08T12:07:39Z")

</div>

Normal Kibana is working.  
This doesn't work. Do I need to change the logtrail.json file?  
I can go to the dark log trail console but can't see any logs there. Help ASAP.

---

<div class="post-metadata">

**Author:** ![sivasamyk](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@sivasamyk](https://discuss.elastic.co/u/sivasamyk)\
**Post date:** [December 8, 2016, 4:37pm UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/4 "2016-12-08T16:37:07Z")

</div>

Yes you need to customize logtrail.json to specify the index to query and  
map the fields accordingly.

---

<div class="post-metadata">

**Author:** ![Ranvijay\_Jamwal](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@Ranvijay\_Jamwal](https://discuss.elastic.co/u/Ranvijay_Jamwal)\
**Post date:** [December 8, 2016, 4:57pm UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/5 "2016-12-08T16:57:54Z")

</div>

This is the conf I am using

"es": {  
"default\_index": "logstash-\*",  
"allow\_url\_parameter": false,  
"timezone": "UTC"  
},  
"tail\_interval\_in\_seconds": 10,  
"max\_buckets": 500,  
"nested\_objects" : false,  
"default\_time\_range\_in\_days" : 0,  
"fields" : {  
"mapping" : {  
"timestamp" : "@timestamp",  
"display\_timestamp" : "syslog\_timestamp",  
"hostname" : "hostname",  
"program": "program",  
"message": "syslog\_message"  
}  
}  
}

What do I change? Elasticsearch is on the same host. Data is already coming into from Logstash Elasticsearch. I installed the plugin, I can switch between kibana and logtrail on the browser, but logtrail does not have data. Indexes are made like logstash-\* only. Please help.

This is if the above ever works for me: Also, is it possible that I can search something specific like a particular log file and show only that on logtrail console?

---

<div class="post-metadata">

**Author:** ![sivasamyk](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@sivasamyk](https://discuss.elastic.co/u/sivasamyk)\
**Post date:** [December 8, 2016, 5:12pm UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/6 "2016-12-08T17:12:42Z")

</div>

Your logtrail.json looks good. Do you have any errors in kibana logs? Are  
you able to see the logs from kibana view?

---

<div class="post-metadata">

**Author:** ![Ranvijay\_Jamwal](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@Ranvijay\_Jamwal](https://discuss.elastic.co/u/Ranvijay_Jamwal)\
**Post date:** [December 9, 2016, 6:16am UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/7 "2016-12-09T06:16:01Z")

</div>

Yes. All the logs. I can see everything properly on kibana. But logtrail says no events. I tried changing the time as well. It should trail all the logs as they are coming right?

---

<div class="post-metadata">

**Author:** ![Ranvijay\_Jamwal](https://avatars.discourse-cdn.com/v4/letter/r/b9e5f3/32.png) [@Ranvijay\_Jamwal](https://discuss.elastic.co/u/Ranvijay_Jamwal)\
**Post date:** [December 12, 2016, 1:45pm UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/8 "2016-12-12T13:45:51Z")

</div>

I made these changes from above:

{  
"es": {  
"default\_index": "logstash-_",  
"allow\_url\_parameter": false,  
"timezone": "UTC"  
},  
"tail\_interval\_in\_seconds": 10,  
"max\_buckets": 500,  
"nested\_objects" : false,  
"default\_time\_range\_in\_days" : 0,  
"fields" : {  
"mapping" : {  
"timestamp" : "@timestamp",  
"display\_timestamp" : "syslog\_timestamp",  
"hostname" : "localhost",  
"program": "program",  
"message": "_"  
}  
}  
}

It says program.raw undefined.

PFA

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1b580a8ad97e51f4558d29ec1c0044fdcc27c419.png)Screen Shot

---

<div class="post-metadata">

**Author:** ![sivasamyk](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@sivasamyk](https://discuss.elastic.co/u/sivasamyk)\
**Post date:** [December 12, 2016, 3:28pm UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/9 "2016-12-12T15:28:14Z")

</div>

Hi,

If you are using logstash for ingesting logs into ES, can you paste your  
logstash config file? Looks like the fields specified in logtrail.json are  
not present in ES.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/logtrail-kibana-plugin-to-view-search-and-tail-logs-in-realtime/60489/10 "2017-07-06T13:33:48Z")

</div>


