# Beat autodiscover docker.sock permission denied on AWS ECS

**URL:** <https://discuss.elastic.co/t/beat-autodiscover-docker-sock-permission-denied-on-aws-ecs/114597>\
**Category:** Beats\
**Created:** [January 8, 2018, 6:42pm UTC](https://discuss.elastic.co/t/beat-autodiscover-docker-sock-permission-denied-on-aws-ecs/114597 "2018-01-08T18:42:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![iseyer\_alx](https://avatars.discourse-cdn.com/v4/letter/i/ac91a4/32.png) [@iseyer\_alx](https://discuss.elastic.co/u/iseyer_alx)\
**Post date:** [January 8, 2018, 6:42pm UTC](https://discuss.elastic.co/t/beat-autodiscover-docker-sock-permission-denied-on-aws-ecs/114597/1 "2018-01-08T18:42:55Z")

</div>

Trying to use Autodiscover for both filebeat and metricbeat on AWS ECS cluster.

However, I am getting `/var/run/docker.sock/ Operation not committed` when attempting to run both manually and with a task definition. I **have** mounted /var/run/docker.sock to /var/run/docker.sock in the task definition, from host to container.

Here is the relevant portion of my filebeat:

```auto
filebeat.autodiscover:
  providers:
    - type: docker
      templates:
        - condition:
            contains.docker.container.image: ["image1", "image2", "image3"]

```

And the output (when running `./metricbeat` or `./filebeat` in a container with docker.sock mounted:

```auto
sh-4.2$ ./metricbeat
metricbeat2018/01/08 18:31:23.302787 cloudid.go:42: INFO Setting Elasticsearch and Kibana URLs based on the cloud id: output.elasticsearch.hosts=https://host and setup.kibana.host=https:/host
Exiting: Got permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock: Get http://%2Fvar%2Frun%2Fdocker.sock/v1.22/containers/json?limit=0: dial unix /var/run/docker.sock: connect: permission denied

```

Is this impossible on AWS?

I have tried running privileged as root, and get a `docker.sock` not found.

Note: it should not be relevant I don't think, but I am using [elastic.co](http://elastic.co)'s hosted elasticsearch solution.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [January 9, 2018, 2:42pm UTC](https://discuss.elastic.co/t/beat-autodiscover-docker-sock-permission-denied-on-aws-ecs/114597/2 "2018-01-09T14:42:25Z")

</div>

Hi @iseyer_alx,

Our docker integration should work on ECS, we have reports from the community using it ([example](https://discuss.elastic.co/t/filebeat-and-metricbeat-produce-different-docker-metadata-for-same-container/107449)).

Could you share the full log output? Also, could you please detail how did you configure the container? The mount looks correct, did you keep it as writable, that's needed?, I'm also interested in how you configured the "run as root" part.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 29, 2018, 6:43pm UTC](https://discuss.elastic.co/t/beat-autodiscover-docker-sock-permission-denied-on-aws-ecs/114597/3 "2018-01-29T18:43:15Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
