# Unable to get logs in Kibana on Red Hat Enterprise Linux 7

**URL:** <https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382>\
**Category:** Elasticsearch\
**Created:** [May 9, 2019, 2:16pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382 "2019-05-09T14:16:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![krajapraveen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krajapraveen/32/45708_2.png) [@krajapraveen](https://discuss.elastic.co/u/krajapraveen)\
**Post date:** [May 9, 2019, 2:16pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382/1 "2019-05-09T14:16:38Z")

</div>

Hi

I want t display logs in Kibana on Red Hat Enterprise Linux 7.

I have elasticsearch-6.4.0.rpm, kibana-6.4.0-x86\_64.rpm and logstash-6.4.1 installed.

My logstash file is as follows:

input {  
file {  
type =\> "java"  
path =\> "/var/log/sample.log"  
codec =\> multiline {  
pattern =\> "^%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME}.\*"  
#negate =\> "true"  
#what =\> "previous"  
}  
}  
}  
output {

```
elasticsearch {
hosts => ["localhost:9200"]
index => "abc-%{+YYYY.MM.dd}"

```

}  
}

## I have un-commented some content in kibana.yml file which is as follows:

elasticsearch.url: "[http://localhost:9200](http://localhost:9200)"

## logging.dest: stdout

In /usr/share I have kibana folder in which I have the files/folders as below:  
bin LICENSE.txt node node\_modules NOTICE.txt optimize package.json plugins README.txt src webpackShims yarn.lock

In /etc I have kibana file/folder in which I have one file as below:  
kibana.yml

In /usr/share I have elasticsearch folder in which I have the files/folders as below:  
bin lib LICENSE.txt modules NOTICE.txt plugins README.textile

In /etc I have elasticsearch folder in which I have files/folders as below:  
elasticsearch.keystore elasticsearch.yml jvm.options log4j2.properties role\_mapping.yml roles.yml users users\_roles

To run:

I am running elasticsearch by giving the following command:  
sudo /etc/init.d/elasticsearch start

I am running kibana by giving the following command:  
sudo /etc/init.d/kibana start

I am running the logstash by giving the following command:  
/opt/logstash/bin/logstash -f /etc/logstash/logstash.conf

On doing the above things, I am not getting the logs in Kibana in stdout and stderr files.

Can you please help me on this.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 9, 2019, 3:46pm UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382/2 "2019-05-09T15:46:23Z")

</div>

Not exactly the answer you are looking for but why are you using Logstash for this? filebeat would be more efficient IMO just to read log lines and send them to elasticsearch.

---

<div class="post-metadata">

**Author:** ![krajapraveen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krajapraveen/32/45708_2.png) [@krajapraveen](https://discuss.elastic.co/u/krajapraveen)\
**Post date:** [May 10, 2019, 2:15am UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382/3 "2019-05-10T02:15:36Z")

</div>

Hi David

Thank you so much for your reply. Can you please tell me how to configure filebeat so that I can get logs in Kibana.

Regards

K. Raja Praveen.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 10, 2019, 5:51am UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382/4 "2019-05-10T05:51:33Z")

</div>

Start here: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html)

---

<div class="post-metadata">

**Author:** ![krajapraveen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krajapraveen/32/45708_2.png) [@krajapraveen](https://discuss.elastic.co/u/krajapraveen)\
**Post date:** [May 10, 2019, 6:13am UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382/5 "2019-05-10T06:13:40Z")

</div>

Thank you David. I will refer to the link which you have provided. If any doubts further , I will contact you here.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 10, 2019, 6:40am UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382/6 "2019-05-10T06:40:24Z")

</div>

If you have trouble with filebeat then I'd suggest you ask in #beats:filebeat instead. 🤗

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2019, 6:40am UTC](https://discuss.elastic.co/t/unable-to-get-logs-in-kibana-on-red-hat-enterprise-linux-7/180382/7 "2019-06-07T06:40:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
