# Room for improvement for log\_sending=true

**URL:** <https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602>\
**Category:** APM\
**Tags:** java\
**Created:** [April 24, 2023, 6:30am UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602 "2023-04-24T06:30:34Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [April 24, 2023, 6:30am UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/1 "2023-04-24T06:30:34Z")

</div>

**Kibana version** : 8.7.0

**Elasticsearch version** : 8.7.0

**APM Server version** : 8.7.0

**APM Agent language and version** : 1.36.0

I just started using `log_sending=true` in the Java agent on one of our Q-Systems. The logs are transferred and stored in Elastic just fine. I can search the logs manually in Discover and everything, it is just that the logs are **NOT** shown in the APM UI.

This seems to be caused by the fact that we do not have microservices - we are running multiple applications in a single tomcat instance. Let's say I have an application called `MyApplication` running, I would expect the `service.name` of all logs to be set to `MyApplication`. In reality, the agent seems to instrument the logback appenders and has no reference to the original application (`event.dataset` is set to `tomcat-application.MyApplicationAppenderDev`, `service.name` is `tomcat-application`). This means, calling `https://my-kibana-host:5601/s/my-team/app/apm/services/MyApplication/logs` does not show the application logs.

I would prefer that the Elastic Agent would send the logs with the correct service name to make correlation easier.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Jack\_Shirazi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_shirazi/32/91641_2.png) [@Jack\_Shirazi](https://discuss.elastic.co/u/Jack_Shirazi)\
**Post date:** [April 24, 2023, 5:46pm UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/2 "2023-04-24T17:46:44Z")

</div>

I haven't had time to reproduce this yet, but have you tried explicitly setting the service.name for the server?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [April 25, 2023, 4:41am UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/3 "2023-04-25T04:41:08Z")

</div>

> have you tried explicitly setting the service.name

Maybe I am missing something, but what good would that do? When I explicitly set the `service.name` on the complete server - wouldn't that single `service.name` be used for all applications on this server instance? Currently, we are relying on the `service.name` autodetection of the agent for all applications on the tomcat (spring webapplications deployed as WAR-files).

---

<div class="post-metadata">

**Author:** ![Jack\_Shirazi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_shirazi/32/91641_2.png) [@Jack\_Shirazi](https://discuss.elastic.co/u/Jack_Shirazi)\
**Post date:** [April 26, 2023, 2:27pm UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/4 "2023-04-26T14:27:04Z")

</div>

Yes, you have it right, I misunderstood. I see you want the application log to be linked to the application transactions. As you note we don't have that correlation working yet. We'll discuss prioritising that

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [April 27, 2023, 4:29am UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/5 "2023-04-27T04:29:11Z")

</div>

Does it make sense to open a Feature request on Github or is there no need for that?

---

<div class="post-metadata">

**Author:** ![Jack\_Shirazi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_shirazi/32/91641_2.png) [@Jack\_Shirazi](https://discuss.elastic.co/u/Jack_Shirazi)\
**Post date:** [April 27, 2023, 8:40am UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/6 "2023-04-27T08:40:59Z")

</div>

please do

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [April 27, 2023, 9:04am UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/7 "2023-04-27T09:04:09Z")

</div>

Done: [make log\_sending=true correlate to the correct service · Issue #3123 · elastic/apm-agent-java · GitHub](https://github.com/elastic/apm-agent-java/issues/3123)

---

<div class="post-metadata">

**Author:** ![Jack\_Shirazi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_shirazi/32/91641_2.png) [@Jack\_Shirazi](https://discuss.elastic.co/u/Jack_Shirazi)\
**Post date:** [May 3, 2023, 12:26pm UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/8 "2023-05-03T12:26:38Z")

</div>

Thanks, we're hoping to get to this next Q

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2023, 8:27am UTC](https://discuss.elastic.co/t/room-for-improvement-for-log-sending-true/330602/9 "2023-05-24T08:27:10Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
