# "Unknown" logs in observability overview

**URL:** <https://discuss.elastic.co/t/unknown-logs-in-observability-overview/273240>\
**Category:** Logs\
**Created:** [May 18, 2021, 7:04am UTC](https://discuss.elastic.co/t/unknown-logs-in-observability-overview/273240 "2021-05-18T07:04:49Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)\
**Post date:** [May 18, 2021, 10:34am UTC](https://discuss.elastic.co/t/unknown-logs-in-observability-overview/273240/2 "2021-05-18T10:34:58Z")

</div>

As described in the thread you linked, your best bet would be to use ECS loggers and to define the `event.dataset` field. If that's not an option, you can use an [`add_fields` processor](https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html) to manually add this field in your Filebeat configuration.

Example:

```auto
processors:
  - add_fields:
      target: ''
      fields:
        event:
          dataset: my-app.log

```

---

_[View the full topic](https://discuss.elastic.co/t/unknown-logs-in-observability-overview/273240)._
