# See full log file in ELK?

**URL:** <https://discuss.elastic.co/t/see-full-log-file-in-elk/188139>\
**Category:** Elasticsearch\
**Created:** [June 29, 2019, 1:45pm UTC](https://discuss.elastic.co/t/see-full-log-file-in-elk/188139 "2019-06-29T13:45:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shay\_Berman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shay_berman/32/49072_2.png) [@Shay\_Berman](https://discuss.elastic.co/u/Shay_Berman)\
**Post date:** [June 29, 2019, 1:45pm UTC](https://discuss.elastic.co/t/see-full-log-file-in-elk/188139/1 "2019-06-29T13:45:36Z")

</div>

I setup ELK and it works great. you can see all the logs of the containers that running in the k8s cluster.

But how can I see in kubana or with logstash query all the record that related to specific container? and i want to see it as a whole file.

Idea?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 29, 2019, 2:44pm UTC](https://discuss.elastic.co/t/see-full-log-file-in-elk/188139/2 "2019-06-29T14:44:02Z")

</div>

Do you mean that you want to extract all data that have been indexed in elasticsearch to a local file?  
What for?

---

<div class="post-metadata">

**Author:** ![abcarroll](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abcarroll/32/32885_2.png) [@abcarroll](https://discuss.elastic.co/u/abcarroll)\
**Post date:** [June 29, 2019, 3:46pm UTC](https://discuss.elastic.co/t/see-full-log-file-in-elk/188139/3 "2019-06-29T15:46:21Z")

</div>

Depending on how you ingested, you can query with kibana using 'path', this should be possible with both the file and s3 inputs, both supply a path by default (although s3's is in `[@metadata`], from my recollection)

For example just do a query such as "`path: "my-files/some-log-dir/some-file.log.gz"`"

However, I agree with @dadoonet, unless you are using this for a pretty narrow use case of manually verifying specific files are being ingested the way you expect, this is a weird use case.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2019, 3:46pm UTC](https://discuss.elastic.co/t/see-full-log-file-in-elk/188139/4 "2019-07-27T15:46:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
