-
Notifications
You must be signed in to change notification settings - Fork 8.3k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch '7.x' into backport/7.x/pr-49390
- Loading branch information
Showing
263 changed files
with
4,260 additions
and
1,982 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,50 +1,46 @@ | ||
[role="xpack"] | ||
[[xpack-logs-configuring]] | ||
|
||
:ecs-link: {ecs-ref}[Elastic Common Schema (ECS)] | ||
:ecs-base-link: {ecs-ref}/ecs-base.html[base] | ||
|
||
== Configuring the Logs data | ||
|
||
The default source configuration for logs is specified in the {kibana-ref}/logs-ui-settings-kb.html[Logs app settings] in the {kibana-ref}/settings.html[Kibana configuration file]. | ||
The default configuration uses the `filebeat-*` index pattern to query the data. | ||
The default configuration also defines field settings for things like timestamps and container names, and the default columns to show in the logs pane. | ||
The default configuration also defines field settings for things like timestamps and container names, and the default columns to show in the logs stream. | ||
|
||
If your logs have custom index patterns, or use non-default field settings, or contain parsed fields which you want to expose as individual columns, you can override the default settings. | ||
Click *Configuration* to change the settings. | ||
This opens the *Configure source* fly-out dialog. | ||
If your logs have custom index patterns, use non-default field settings, or contain parsed fields which you want to expose as individual columns, you can override the default configuration settings. | ||
|
||
NOTE: These settings are shared with metrics. Changes you make here may also affect the settings used by the *Metrics* app. | ||
|
||
TIP: If <<xpack-spaces>> are enabled in your Kibana instance, any configuration changes you make here are specific to the current space. | ||
You can make different subsets of data available by creating multiple spaces with different data source configurations. | ||
To change the configuration settings, click the *Settings* tab. | ||
|
||
TIP: If you don't see the *Configuration* option, you may not have sufficient privileges to change the source configuration. | ||
For more information see <<xpack-security-authorization>>. | ||
|
||
[float] | ||
=== Indices and fields tab | ||
NOTE: These settings are shared with metrics. Changes you make here may also affect the settings used by the *Metrics* app. | ||
|
||
In the *Indices and fields* tab, you can change the following values: | ||
In the *Settings* tab, you can change the values in these sections: | ||
|
||
* *Name*: the name of the source configuration | ||
* *Indices*: the index pattern or patterns in the Elasticsearch indices to read metrics data and log data from | ||
* *Fields*: the names of specific fields in the indices that are used to query and interpret the data correctly | ||
* *Log columns*: the columns that are shown in the logs stream | ||
|
||
[float] | ||
==== Log columns configuration | ||
|
||
In the *Log columns* tab you can change the columns that are displayed in the Logs app. | ||
By default the following columns are shown: | ||
By default the logs stream shows following columns: | ||
|
||
* *Timestamp*: The timestamp of the log entry from the `timestamp` field. | ||
* *Message*: The message extracted from the document. | ||
The content of this field depends on the type of log message. | ||
If no special log message type is detected, the {ecs-link} field `message` is used. | ||
// ++ add a better link. The actual page location is ecs-base | ||
If no special log message type is detected, the Elastic Common Schema (ECS) {ecs-base-link} field, `message`, is used. | ||
|
||
To add a new column, click *Add column*. | ||
To add a new column to the logs stream, in the *Settings* tab, click *Add column*. | ||
In the list of available fields, select the field you want to add. | ||
You can start typing a field name in the search box to filter the field list by that name. | ||
|
||
To remove an existing column, click the *Remove this column* icon | ||
image:logs/images/logs-configure-source-dialog-remove-column-button.png[Remove column]. | ||
image:logs/images/logs-configure-source-dialog-remove-column-button.png[Remove column]. | ||
|
||
When you have completed your changes, click *Apply*. | ||
|
||
If the fields are greyed out and cannot be edited, you may not have sufficient privileges to change the source configuration. | ||
For more information see <<xpack-security-authorization>>. | ||
|
||
TIP: If <<xpack-spaces>> are enabled in your Kibana instance, any configuration changes you make here are specific to the current space. | ||
You can make different subsets of data available by creating multiple spaces with different data source configurations. | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.