# Subheadings in Elasticsearch/clean up system logs

**URL:** <https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943>\
**Category:** Logs\
**Created:** [November 23, 2021, 11:34am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943 "2021-11-23T11:34:36Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![eprop-marc](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Post date:** [November 23, 2021, 11:34am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/1 "2021-11-23T11:34:36Z")

</div>

Hi, I'm brand new to the whole ELK stack, I've setup one in my company. I just wanted to know how best to clean up the logs, I'm getting a lot of system logs from the server and I don't want them. I just want the logs from our application. Is it possible to set headings and subheadings that point to those app logs, because at the moment, I've added logs into filebeat.yml and I've just added in tags and then saved those searches, would be nice to have the app logs subheadings down the side of Elasticsearch. Apologies for my question, I know I'm asking quite a lot and not sure if its even possible in Elasticsearch. Thanks.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [November 23, 2021, 12:19pm UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/2 "2021-11-23T12:19:19Z")

</div>

Hi @eprop-marc,

glad to hear you're trying it out. The logs app at this point doesn't have a way to store sets of filters, but it's something we're thinking about. In the meantime a workaround could be to bookmark the logs app with the filters applied. They are stored in the URL and would be restored when you open the bookmark.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [November 23, 2021, 12:20pm UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/3 "2021-11-23T12:20:48Z")

</div>

I just found the enhancement issue [[Metrics & Logs UI] Saved Queries and Universal Kuery Bar · Issue #48290 · elastic/kibana · GitHub](https://github.com/elastic/kibana/issues/48290), which seem to be related to your question.

---

<div class="post-metadata">

**Author:** ![eprop-marc](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Post date:** [November 23, 2021, 3:09pm UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/4 "2021-11-23T15:09:39Z")

</div>

Hi Felix, thanks for your quick reply. With regards to the system logs Im getting from the server Elastic is hosted on, is there a way to disable those metrics please? My Kibana output gets spammed with them.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [November 23, 2021, 3:42pm UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/5 "2021-11-23T15:42:13Z")

</div>

Yes, you should be able to tune the filebeat configuration to only pick up the logs you want. Could you provide more details about the filebeat configuration and the enabled modules? Which paths are you harvesting?

---

<div class="post-metadata">

**Author:** ![eprop-marc](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Post date:** [November 26, 2021, 11:37am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/6 "2021-11-26T11:37:35Z")

</div>

This is what I have so far in the filebeats.yml file. Our logs are mounted on AWS EFS, so we get them from /mnt/general which is mounted to EFS. It would be nice if these logs could be headings in Elastic instead of me tagging them, and then saving those searches. I haven't enabled any modules yet, however, I am looking to enabling the AWS module. Is it in the filebeats.yml file where I can take a lot of the system metrics out? Thanks

```auto
# ============================== Filebeat inputs ===============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

####Worker Logs####
#
- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /mnt/general/logs/worker/laravel*.log

  tags: ["Laravel Worker Logs"]

- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /mnt/general/logs/worker/horizon*.log

  tags: ["Horizon Worker Logs"]

- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /mnt/general/logs/worker/feeds*.log

  tags: ["Feeds Worker Logs"]

####Member Logs####
#
- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /mnt/general/logs/member/laravel*.log

  tags: ["Horizon Member Logs"]

####Web Logs#####
#
- type: log

  # Change to true to enable this input configuration.
  enabled: true
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /mnt/general/logs/web/laravel*.log

  tags: ["Horizon Web Logs"]

####Cron Logs####
#
- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /mnt/general/logs/cron/cron.log

  tags: ["Cron Logs"]
    #- c:\programdata\elasticsearch\logs\*

```

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [November 29, 2021, 11:33am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/7 "2021-11-29T11:33:10Z")

</div>

Thanks for providing these details. The `system` log might be enabled by default. Can you check what `metricbeat modules list` shows as "enabled"? Alternatively, could you check in the `modules.d` directory in the metricbeat directory which modules' configs don't have a `.disabled` suffix?

---

<div class="post-metadata">

**Author:** ![eprop-marc](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Post date:** [December 1, 2021, 10:04am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/8 "2021-12-01T10:04:43Z")

</div>

Ahh I have disabled the system module, thanks. Just having some issues with enabling the Nginx module. Do I configure the nginx module in the modules.d direcotry, or in the filebeat.yml file?

---

<div class="post-metadata">

**Author:** ![eprop-marc](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Post date:** [December 1, 2021, 10:09am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/9 "2021-12-01T10:09:17Z")

</div>

Also, is there a way to just add` log path` and the `message` instead of `Document` at the top near `Time` please?

 ![2021-12-01_10h07_47](https://us1.discourse-cdn.com/elastic/original/3X/9/2/922d12d62b38bfc9a0b19d029d9f359e76328a70.png)

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 1, 2021, 10:37am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/10 "2021-12-01T10:37:50Z")

</div>

> [@eprop-marc](#):
>
> Do I configure the nginx module in the modules.d direcotry, or in the filebeat.yml file?

That's up to you, but it would probably be cleaner to configure it in its separate file.

> [@eprop-marc](#):
>
> Also, is there a way to just add ` log path` and the `message` instead of `Document` at the top near `Time` please?

The screenshot looks like it's taken in Kibana's "Discover" app? If so, you can add the specific columns via the sidebar on the left or by expanding a document and clicking the corresponding icon in the matching row of the field table: [Discover | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/discover.html#explore-fields-in-your-data)

---

<div class="post-metadata">

**Author:** ![eprop-marc](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Post date:** [December 1, 2021, 11:44am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/11 "2021-12-01T11:44:17Z")

</div>

Ahh its the available fields on the left, thanks. Is there a way to clean up and delete the other available fields?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [December 1, 2021, 11:46am UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/12 "2021-12-01T11:46:46Z")

</div>

I don't think there is. You can only collapse the sidebar, I think. But you can also prepare your set of desired columns and store it as a "saved search" in Discover if that helps.

---

<div class="post-metadata">

**Author:** ![eprop-marc](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@eprop-marc](https://discuss.elastic.co/u/eprop-marc)\
**Post date:** [December 1, 2021, 2:39pm UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/13 "2021-12-01T14:39:57Z")

</div>

Ahh great thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2021, 2:45pm UTC](https://discuss.elastic.co/t/subheadings-in-elasticsearch-clean-up-system-logs/289943/15 "2021-12-29T14:45:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
