# Search logs of a specific application

**URL:** <https://community.graylog.org/t/search-logs-of-a-specific-application/21814>\
**Category:** Graylog Tech Challenges\
**Created:** [November 21, 2021, 1:15pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814 "2021-11-21T13:15:51Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 21, 2021, 1:15pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/1 "2021-11-21T13:15:51Z")

</div>

How to search for the logs of a specific application?

Logs of this specific application (can be a DB table, OS logs or else) are coming to Graylog from multiple sources using GELF TCP Input.

The idea is to search for these application logs only and not to mix the result with logs of other applications that may come to Graylog.

In other SIEMSs this is usually done by making a dedicated index for each application (log type). As far as I have seen to ingest logs to a specific Graylog index a stream is needed, whose rules require the presence of a field inside GELF content to distinguish between different applications (log types).

Does this mean that the best solution is to add an application dedicated field in GELF, kind of:  
\_application\_brand\_name=“my\_app\_name”  
?

any other idea?

best regards  
Altin

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 23, 2021, 12:21am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/2 "2021-11-23T00:21:10Z")

</div>

Hello,

I might be able to help. As for your first question.

> [@altink](#):
>
> How to search for the logs of a specific application?

Depends on how you setup your environment for searching a particular application.

> [@altink](#):
>
> Logs of this specific application (can be a DB table, OS logs or else) are coming to Graylog from multiple sources using GELF TCP Input.

This can be done either with a unique field or tag to sort through the ingest logs. This can be done through a pipeline, extractor or from the source (log Shipper).

Example from the source. This is a remote server in my environment. I was extracting logs from a application call NextCloud using NXlog. I created a input called the same name as my application  
“nextcloud”.

```auto
<Input nextcloud>
   Module im_file
   FILE "/mnt/nextcloud-data1/nextcloud.log"
   SavePos TRUE
   ReadFromLast TRUE
   PollInterval 1
   Exec $Message = $raw_event;
</Input>

```

Now here is what I receive on my GL server.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/3b34d3ec5c544e4afc34ba57bb94561513f4e1db.png)

I just use the field called **SourceModuleName** to route my messages to stream. Therefor, I do not need to create a extractor/pipeline for a new field.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/22ef677edbedcaf3dbe1ac37a4101759d0a0bf95.png)

As you can see I can have multiple ones. As shown on my widget below.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/3/31ecc5a3eb706dcec796bca6cdcb20608cfc27e2.png)  
Depending on what type of log shipper your using this is possible.  
You could use a pipeline to grab what you need and **route-to-stream** that way also. I guess the main subject here is you may need the correct field first.

Hope that helps  
EDIT: is this the same post?

> [@GELF TCP Input Data to specific index](https://community.graylog.org/t/gelf-tcp-input-data-to-specific-index/21810):
>
> I need to put all data ingested by a specific TCP Input entry into a specific index user made. For this in the UI of Graylog I created a Stream on this index. Checked “Remove matches from ‘All messages’ stream”. When create/edit the TCP Input I cannot find any place for Stream binding. I created a single stream rule “Rule always matches” for the stream created above. Question: How do I connect my specific TCP Input to this Stream (and thus index)? I want other TCP Inputs to keep storing rec…

---

<div class="post-metadata">

**Author:** ![tellistone](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tellistone/32/10200_2.png) [@tellistone](https://community.graylog.org/u/tellistone)\
**Post date:** [November 23, 2021, 12:35pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/3 "2021-11-23T12:35:37Z")

</div>

The default application\_name field should contain the source application name.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/601e8511819ba44b3e0f6611bdd0736ff643554b.jpeg)

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 23, 2021, 10:11pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/4 "2021-11-23T22:11:02Z")

</div>

thank you @tellistone

I would like it this way, but in the GELF documentation field application\_name is not mentioned anywhere. I have Graylog 3.3.2

[https://docs.graylog.org/docs/gelf](https://docs.graylog.org/docs/gelf)

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 23, 2021, 10:15pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/5 "2021-11-23T22:15:37Z")

</div>

thank you @gsmith

Are you are saying that in my case the best thing to do is to add a new user-created field to the GELF, kind of dataplus\_app=my\_app, and then have every search start with dataplus\_app:my\_app?  
If yes, yours is the answer.

ps. GELF docs says nothing about field SourceModuleName. I have Graylog 3.3.2

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 23, 2021, 10:53pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/6 "2021-11-23T22:53:51Z")

</div>

> [@altink](#):
>
> Are you are saying that in my case the best thing to do is to add a new user-created field to the GELF,

No, this would be created using GELF input and the source is sending GELF format. So no need to add that field it will be created for you. This depend on what type of log shipper and/or type of logs that are being ingested. Can you give us the configuration you have for you INPUT and log shipper and what kind of fields generated already that you have. Maybe we can give you some suggestion on a HowTo for you.  
This will give mea idea for a mockup in my lab.

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 23, 2021, 11:34pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/7 "2021-11-23T23:34:42Z")

</div>

I am sending the records of an Oracle table using an Oracle job Scheduler calling a procedure. The later uses UTL\_TCP to send data to Graylog. I guess I have no “log shipper”

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 23, 2021, 11:49pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/8 "2021-11-23T23:49:55Z")

</div>

> [@altink](#):
>
> Oracle job Scheduler

I’m unfamiliar with that type of application.  
Can _Oracle job Scheduler_ send logs in GELF format? if so how did you configure it?

If Oracle job Scheduler cant then I would suggest using something like Syslog TCP/UDP for an input. You would then need to create a pipeline or extractors to create the needed field.

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 23, 2021, 11:56pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/9 "2021-11-23T23:56:18Z")

</div>

What does the work is the Oracle package UTL\_TCP - which send data through TCP, and as such event to Graylog TCP Input. Scheduler is just to automate the procedure that iterates through table records and sends them to Graylog using UTL\_TCP.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 24, 2021, 5:43am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/10 "2021-11-24T05:43:25Z")

</div>

Ummmm. Correct me if I’m wrong but you stated your using GELF/TCP INPUT and your sending logs using Oracle package UTL\_TCP.  
I didn’t know that Oracle formatted there log files in a GELF format. Looking at the UTL\_TCP documentation, it’s clearly a plain-text “raw” connection.

---

<div class="post-metadata">

**Author:** ![tellistone](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tellistone/32/10200_2.png) [@tellistone](https://community.graylog.org/u/tellistone)\
**Post date:** [November 24, 2021, 10:04am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/11 "2021-11-24T10:04:07Z")

</div>

Hi Altink,

May I ask which software are you using to collect logs and send them to Graylog in GELF format (Filebeats? NxLog?) so I can attempt to reproduce?

It seems desirable that your GELF format uses the same field name for application name as all other inputs eg. application\_name , so you can sort by this field within the Graylog UI.

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 24, 2021, 8:17pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/12 "2021-11-24T20:17:52Z")

</div>

I am using no software. I am sending the events (table records) straight from Oracle, using UTL\_TCP on Oracle side and GELF TC P Input on Graylog side.

[https://docs.oracle.com/en/database/oracle/oracle-database/12.2/arpls/UTL\_TCP.html](https://docs.oracle.com/en/database/oracle/oracle-database/12.2/arpls/UTL_TCP.html)

The operational logic is embedded inside an Oracle procedure, which its is called by an Oracle Scheduler Job.

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 24, 2021, 8:24pm UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/13 "2021-11-24T20:24:09Z")

</div>

I see many people talking about this field - application\_name - but I cannot find it in the Graylog documentation.

Do I risk something going wrong if I use it on Graylog 3.3.2 (my version)? What about later versions?

best regards  
Altin

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 25, 2021, 12:13am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/14 "2021-11-25T00:13:11Z")

</div>

> [@altink](#):
>
> I see many people talking about this field - application\_name - but I cannot find it in the Graylog documentation.

If you have a field /w your application name, then you would use that field.

**Example** , I created a field called **application\_name** and under that field I have the name of my application.  
This means you either have this field or you need to create it. From your [other post](https://community.graylog.org/t/gelf-tcp-input-data-to-specific-index/21810) was explained on how to go about doing that.

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 25, 2021, 12:17am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/15 "2021-11-25T00:17:09Z")

</div>

thank you very much @gsmith

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [November 25, 2021, 12:17am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/16 "2021-11-25T00:17:48Z")

</div>

Of course, and I apologies for misunderstand you post.

---

<div class="post-metadata">

**Author:** ![altink](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/altink/32/3446_2.png) [@altink](https://community.graylog.org/u/altink)\
**Post date:** [November 25, 2021, 12:36am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/17 "2021-11-25T00:36:15Z")

</div>

no problem at all @gsmith  
I didn’t clarified in the main post that (1) I was not using any log shipper and (2) that I was aiming for a content pack. furthermore this topic is very similar (but not equal) to topic 21810, which adds more confusion.  
I will go for adding application\_name=“my\_app” to my Oracle-sent GELF, and that first search I will use to filter only my events in my content pack, or any related search.  
All rest - index, strean, pipeline … can wait.

thank you very much for your support @gsmith

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [December 9, 2021, 12:36am UTC](https://community.graylog.org/t/search-logs-of-a-specific-application/21814/18 "2021-12-09T00:36:49Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
