I use winston logger with ecs-winston-format.
I am so confused about what field composition of Stream Message is ?
When I set ecsFomat config > convertReqRes : true, Stream Logs message first "" is always empty.
I can't find the field composition of message in document
I agree this doesn't look perfect. What the UI attempts to do here is to interpolate the event.dataset field. This is part of the message reconstruction heuristics, which go astray sometimes.
If you're on a recent version of the Elastic Stack, you might want to try out Discover in a Kibana space configured for Observability: Explore logs in Discover | Elastic Docs
Nowadays Discover adapts its rendering to suit the use-case better when the data viewed are log entries.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.