# Autodiscover - docker - catch all others

**URL:** <https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 12, 2018, 8:00pm UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868 "2018-04-12T20:00:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![setiseta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/setiseta/32/29949_2.png) [@setiseta](https://discuss.elastic.co/u/setiseta)\
**Post date:** [April 12, 2018, 8:00pm UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868/1 "2018-04-12T20:00:16Z")

</div>

Hello,

I want to setup autodiscover of type docker, do some special configs for some images and at the end I want to catch all other containers to log as is.  
But i haven't found how to configure the 'catch all others'.  
Can someone give me some hints?

i just found the condition - not - contains / equals - docker.container.image  
is this the only way?

when i do a condition - regex - '.\*' at the end, i get double configured prospectors & logs  
maybe it would be nice to only configure one prospector on autodisover and don't go to other condition if a match is found?

thank you for help.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 13, 2018, 3:18pm UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868/2 "2018-04-13T15:18:45Z")

</div>

Please share the autodiscover config that you are using. It sounds like you are doing it correctly by implementing your "catch all" as the negation of your other condition.

---

<div class="post-metadata">

**Author:** ![setiseta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/setiseta/32/29949_2.png) [@setiseta](https://discuss.elastic.co/u/setiseta)\
**Post date:** [April 13, 2018, 6:27pm UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868/3 "2018-04-13T18:27:16Z")

</div>

Yes for now it works, cause i only have one special configuration.

```auto
filebeat.autodiscover:
  providers:
    - type: docker
      templates:
        - condition:
            contains:
              docker.container.image: tomcat
          config:
            - type: docker
              containers.ids:
                - "${data.docker.container.id}"
              multiline.pattern: '^([0-9]{4}-[0-9]{2}-[0-9]{2}|(Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) \d\d)'
              multiline.negate: true
              multiline.match: after
              fields:
                autodiscover: 'image-tomcat'
              pipeline: tomcat_level
        - condition:
            not:
              contains:
                docker.container.image: tomcat
          config:
            - type: docker
              containers.ids:
                - "${data.docker.container.id}"
              fields:
                autodiscover: 'default'

```

but if i add some more container / image specific config it can get confusing fast. or am i wrong?  
so i thought it would be nicier if it stops on first condition match, cause you never want to mach more than one.  
or are there cases where more than one match is needed in the autodiscover pipe?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 13, 2018, 6:44pm UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868/4 "2018-04-13T18:44:43Z")

</div>

The person who has probably spent the most time thinking about auto-discover config is @exekias.

@exekias, is there a better way to handle this "catch all" case?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [April 13, 2018, 8:16pm UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868/5 "2018-04-13T20:16:30Z")

</div>

Hi,

I'm afraid we don't have one yet, this is the open issue to implement this: [https://github.com/elastic/beats/issues/6084](https://github.com/elastic/beats/issues/6084)

Best regards

---

<div class="post-metadata">

**Author:** ![setiseta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/setiseta/32/29949_2.png) [@setiseta](https://discuss.elastic.co/u/setiseta)\
**Post date:** [April 14, 2018, 10:00am UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868/6 "2018-04-14T10:00:38Z")

</div>

Thank you for the information.  
Nice to hear this is already addressed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2018, 10:00am UTC](https://discuss.elastic.co/t/autodiscover-docker-catch-all-others/127868/7 "2018-05-12T10:00:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
