# Requirements(ElasticSearch+Kibana)

**URL:** <https://discuss.elastic.co/t/requirements-elasticsearch-kibana/12868>\
**Category:** Elasticsearch\
**Created:** [July 20, 2013, 5:51am UTC](https://discuss.elastic.co/t/requirements-elasticsearch-kibana/12868 "2013-07-20T05:51:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![signin\_vasanth](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@signin\_vasanth](https://discuss.elastic.co/u/signin_vasanth)\
**Post date:** [July 20, 2013, 5:51am UTC](https://discuss.elastic.co/t/requirements-elasticsearch-kibana/12868/1 "2013-07-20T05:51:21Z")

</div>

Hi to All,

I am working on _ElasticSearch+Kibana_ combination it means i am trying to  
feed my elastic search log data into kibana ....

I got the result i.e elastic search is working well and tested the same  
with the URL\* [http://localhost:9200/\_plugin/head/\*](http://localhost:9200/_plugin/head/*) (head front end  
controller)...It fetching my database table every 1 minutes..

Now i have to implement the same with _kibana_....What are the things i  
have to perform to act my search in kibana ?...

So for i tried in many ways i could in get clear vision in any of the  
site..I hope this group will help me out..

Awaiting your response....

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [July 20, 2013, 4:47pm UTC](https://discuss.elastic.co/t/requirements-elasticsearch-kibana/12868/2 "2013-07-20T16:47:49Z")

</div>

Kibana is highly configurable but for best OOTB experience it is aligned  
with Logstash.

There are many examples on Google... for example here

> **[Logstash.pdf](https://indico.cern.ch/event/220443/contributions/454391/attachments/358034/498566/Logstash.pdf)**

For your log data, you could try the logstash "timestamped metadata  
mapping" which has the following fields

@source: The source of the event which includes the plugin that generated  
it and the hostname that produced it.  
@tags: An array of tags on the event.  
@fields: A set of fields, for example "user": "james" for the event.  
@timestamp: An ISO8601 timestamp.  
@source\_host: The source host of the event.  
@source\_path: The path, if any, of a source, for example /var/log/messages.  
@message: The event's message. In our case it is what we put into STDIN.  
@type: The value of the type configuration option we set.

A sample

{  
"@source":"syslog",  
"@tags":,"@fields":{},  
"@timestamp":"2013-03-26T06:40:36.692Z",  
"@source\_host":"lxb009",  
"@source\_path":"/var/log/rsyslog.d/lxb007/messages",  
"@message":"Mar 26 07:40:35 lxb007 chef: [2013-03-26T07:  
40:32+01:00] INFO: Starting Chef Run for  
lxb007.devops.test","@type":"linux-syslog"  
}

A mapping template can be found at

> <https://gist.github.com/deverton/2970285>

and I used this

{  
"_default_": {  
"properties" : {  
"@fields": { "type": "object", "dynamic": true,  
"path": "full" },  
"@message" : { "type" : "string", "index" : "analyzed" },  
"@source" : { "type" : "string", "index" : "not\_analyzed" },  
"@source\_host" : { "type" : "string", "index" :  
"not\_analyzed" },  
"@source\_path" : { "type" : "string", "index" :  
"not\_analyzed" },  
"@tags": { "type": "string", "index" : "not\_analyzed" },  
"@timestamp" : { "type" : "date", "index" : "not\_analyzed" },  
"@type" : { "type" : "string", "index" : "not\_analyzed" }  
}  
}  
}

I switched recently to this mapping when indexing highly structured  
bibliographic data (many hundred fields) in @fields to get them visualized  
in Kibana. Works like a charm!

Jörg

On Sat, Jul 20, 2013 at 7:51 AM, Vasanthakumar Rajendran \<  
[signin.vasanth@gmail.com](mailto:signin.vasanth@gmail.com)\> wrote:

> Hi to All,
> 
> I am working on _Elasticsearch+Kibana_ combination it means i am trying  
> to feed my Elasticsearch log data into kibana ....
> 
> I got the result i.e Elasticsearch is working well and tested the same  
> with the URL\* [http://localhost:9200/\_plugin/head/](http://localhost:9200/_plugin/head/)\* (head front end  
> controller)...It fetching my database table every 1 minutes..
> 
> Now i have to implement the same with _kibana_....What are the things i  
> have to perform to act my search in kibana ?...
> 
> So for i tried in many ways i could in get clear vision in any of the  
> site..I hope this group will help me out..
> 
> Awaiting your response....
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:25am UTC](https://discuss.elastic.co/t/requirements-elasticsearch-kibana/12868/3 "2017-07-06T02:25:23Z")

</div>


