# Unable to see trace id or transaction info in logs

**URL:** <https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375>\
**Category:** Logstash\
**Created:** [February 23, 2023, 9:59pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375 "2023-02-23T21:59:18Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pocketcolin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pocketcolin/32/117585_2.png) [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Post date:** [February 23, 2023, 9:59pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/1 "2023-02-23T21:59:18Z")

</div>

I currently have a NodeJS server passing logs to a Logstash server with a TCP tunnel using a Winston transport. Logs make it through all the way to my Elastic Cloud hosted Elasticsearch and pretty much everything looks good except the logs are missing the trace id and transaction information. When I use a stdout transport with Winston to check the logs I can see the trace and transaction info. Here's an example log:

```auto
{"@timestamp":"2023-02-23T21:41:51.479Z","log.level":"info","message":"END: [POST] /api/functions/example-endpoint","ecs":{"version":"1.6.0"},"event":{"dataset":"render-server.log"},"trace":{"id":"35f2bd0ade620fe6613938094020834f"},"transaction":{"id":"074126be6d79359d"},"service":{"name":"render-server"},"path":"/api/functions/example-endpoint"}

```

I am using the `elastic-apm-node` package to run APM on the node server and decorate the logs with the transaction data. I then use [this Winston Logstash package](https://github.com/jaakkos/winston-logstash) to transport the data to Logstash. In the Logstash logs, I also don't see the trace id or transaction info. Example Logstash log:

```auto
Feb 23 05:09:57 PM {
Feb 23 05:09:57 PM "event" => {
Feb 23 05:09:57 PM "original" => "{\"path\":\"/api/functions/example-endpoint\",\"level\":\"info\",\"message\":\"END: [POST] /api/functions/example-endpoint\"}"
Feb 23 05:09:57 PM },
Feb 23 05:09:57 PM "path" => "/api/functions/example-endpoint",
Feb 23 05:09:57 PM "@timestamp" => 2023-02-23T22:09:57.455923359Z,
Feb 23 05:09:57 PM "level" => "info",
Feb 23 05:09:57 PM "message" => "END: [POST] /api/functions/example-endpoint",
Feb 23 05:09:57 PM "@version" => "1"
Feb 23 05:09:57 PM }

```

Any thoughts on what I can test? What might be the issue here?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 23, 2023, 10:30pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/2 "2023-02-23T22:30:26Z")

</div>

What does your logstash configuration looks like?

---

<div class="post-metadata">

**Author:** ![pocketcolin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pocketcolin/32/117585_2.png) [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Post date:** [February 23, 2023, 10:46pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/3 "2023-02-23T22:46:51Z")

</div>

```auto
input {
    tcp {
        port => "10000"
    }
}

filter {
    json {
        source => "message"
    }
}

output {
    elasticsearch {
        cloud_id => "${CLOUD_ID}"
        cloud_auth => "${CLOUD_AUTH}"
        data_stream => "true"
    }
}
```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 24, 2023, 12:08am UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/4 "2023-02-24T00:08:31Z")

</div>

> [@pocketcolin](#):
>
> `{"@timestamp":"2023-02-23T21:41:51.479Z","log.level":"info","message":"END: [POST] /api/functions/example-endpoint","ecs":{"version":"1.6.0"},"event":{"dataset":"render-server.log"},"trace":{"id":"35f2bd0ade620fe6613938094020834f"},"transaction":{"id":"074126be6d79359d"},"service":{"name":"render-server"},"path":"/api/functions/example-endpoint"}`

Where is this message from? Is this the input for Logstash?

---

<div class="post-metadata">

**Author:** ![pocketcolin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pocketcolin/32/117585_2.png) [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Post date:** [February 24, 2023, 3:48am UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/5 "2023-02-24T03:48:57Z")

</div>

Correct. That should be the input for Logstash. I mean I guess the Winston transport that is sending it via TCP could be mutating it but unlikely.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 24, 2023, 4:13am UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/6 "2023-02-24T04:13:39Z")

</div>

> [@pocketcolin](#):
>
> ```auto
> Feb 23 05:09:57 PM "event" => {
> Feb 23 05:09:57 PM "original" => "{\"path\":\"/api/functions/example-endpoint\",\"level\":\"info\",\"message\":\"END: [POST] /api/functions/example-endpoint\"}"
> 
> ```

The event that arrives at logstash does not contain the

```auto
"ecs":{"version":"1.6.0"},"event":{"dataset":"render-server.log"},"trace":{"id":"35f2bd0ade620fe6613938094020834f"},"transaction":{"id":"074126be6d79359d"},"service":{"name":"render-server"},

```

that you expect.

---

<div class="post-metadata">

**Author:** ![pocketcolin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pocketcolin/32/117585_2.png) [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Post date:** [February 24, 2023, 4:01pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/7 "2023-02-24T16:01:44Z")

</div>

So it seems like you were right Badger. Unfortunately, it looks like that Winston transport package was doing some sort of mutation to the object being sent over and removing the transaction information. I swapped it out for the Pino logger and socket transport and everything is working now. Thanks for your time!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2023, 4:01pm UTC](https://discuss.elastic.co/t/unable-to-see-trace-id-or-transaction-info-in-logs/326375/8 "2023-03-24T16:01:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
