- Home
- Skills
- DevOps & Cloud
- ECS Logging Retrofit
Works with the AI tools you already use
ECS Logging Retrofit
Retrofit applications with ECS-compliant structured JSON logging and Filebeat configs for seamless ELK integration.
$9
ECS Logging Retrofit
Example session with this skill installed
make this app ELK-ready
- Read your context and instructions
- Compiled the ecs logging retrofit
- Generated the document
I have audited the codebase and identified 14 logging statements. The application currently uses Winston with three different formats. I will convert these to @elastic/ecs-winston-format and provide a Docker-ready Filebeat configuration.
Log Audit and Proposal
| File:line | Current call | Level | Proposed ECS message | Extra fields |
|---|---|---|---|---|
| auth.js:12 | logger.info("User " + id + " logged in") | info | "user logged in" | labels.user_id, event.outcome: success |
| db.js:45 | logger.error("Query failed: " + err) | error | "database query failed" | error.message, error.stack_trace |
| middleware.js:8 | console.log("Request received") | debug | drop | N/A (high volume) |
Implementation: Winston ECS Formatter
const winston = require('winston');
const { ecsFormat } = require('@elastic/ecs-winston-format');
const logger = winston.createLogger({
level: 'info',
format: ecsFormat({ serviceName: process.env.SERVICE_NAME || 'auth-service' }),
transports: [
new winston.transports.Console()
]
});
// Example Rewrite:
// Old: logger.info("User " + user.id + " logged in");
logger.info("user logged in", { labels: { user_id: user.id }, event: { outcome: 'success', action: 'login' } });
Filebeat Configuration (filebeat.ecs.yml)
filebeat.inputs:
- type: container
id: auth-service-logs
paths:
- /var/lib/docker/containers/*/*.log
parsers:
- ndjson:
target: ""
overwrite_keys: true
add_error_key: true
processors:
- drop_event:
when:
equals:
log.level: "debug"
output.elasticsearch:
hosts: ["${ELASTIC_HOST}"]
indices:
- index: "logs-auth-service-%{+yyyy.MM.dd}"
setup.ilm.enabled: true
Next steps
- Run
npm install @elastic/ecs-winston-formatto add the formatter. - Replace the Winston configuration in
logger.jswith the block above. - Deploy the Filebeat sidecar using the provided YAML.
ecs-logging-retrofit.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Getting an existing app's logs into ELK properly is a half-day chore: read the ECS field reference, hunt down every print and console.log, wire the right formatter, rewrite calls so variables become fields, then hand-write a Filebeat config and debug the lines that don't parse.
This skill does that work in one command.
What it does
- Audits every log call in the codebase and shows a keep / enrich / drop table you approve before anything changes
- Flags secrets and personal data being written to logs, a real finding on most codebases
- Converts to the official ECS formatter for the logger you already have: Python logging, winston, pino, logback, log4j2, monolog, zap and more
- Rewrites calls so variables become queryable fields like labels.order_id, event.duration, and error.stack_trace
- Generates a working filebeat.ecs.yml for your runtime (bare metal, Docker, or k8s)
- Verifies real output lines are valid ECS JSON before declaring done
You never write grok patterns, ingest pipelines, or custom index mappings.
Proven on a real service
The included examples come from a run on a production NestJS API. That audit also caught the app's only error log being dead code: NestJS's default abortOnError exits the process before bootstrap().catch ever fires. The retrofit fixes it.
What's in the zip
SKILL.md, install guide, real example output (examples/*.ndjson), and a license for you and your team. Setup is copying one folder. Works with Elastic Stack 8.x.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 3 days ago
- Passed all security checks, Safe to install