# Can filebeats to read lxc container logs?

**URL:** <https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 3, 2019, 7:01am UTC](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625 "2019-07-03T07:01:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuecong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuecong/32/49061_2.png) [@yuecong](https://discuss.elastic.co/u/yuecong)\
**Post date:** [July 3, 2019, 7:01am UTC](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625/1 "2019-07-03T07:01:26Z")

</div>

from the host, I can read the lxc contianers logs using root like  
/var/lib/lxc/_/test/_/logs/\*.log  
but when I put the above path into filebeats as one path for log type of inputs , it can not find it.( A harvester on the above path is not created). I also tried to use the container input type, also it does not work.

How can I debug why filebeats can not read it even the folder is readable from the host using root?

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [July 5, 2019, 8:32pm UTC](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625/2 "2019-07-05T20:32:39Z")

</div>

Hi! Are the double-slashes in your path intentional? It looks like you want `/var/lib/lxc/test/logs/*.log` but instead have `/var/lib/lxc//test//logs/*.log`. Perhaps that's just a typo, though -- if that doesn't fix it, could you share your `filebeat.yml`? What you want should be possible but more information will help troubleshoot where it's going wrong.

---

<div class="post-metadata">

**Author:** ![yuecong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuecong/32/49061_2.png) [@yuecong](https://discuss.elastic.co/u/yuecong)\
**Post date:** [July 5, 2019, 9:32pm UTC](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625/3 "2019-07-05T21:32:49Z")

</div>

## ah. it is a typo. and here is the whole filebeat.yml with redacting some credentials

filebeat.inputs:

- type: log  
paths:
  - /var/log/\*.log
  - /var/lib/lxc/_/test/_/logs/\*.log

processors:

- add\_cloud\_metadata: ~

output.elasticsearch:  
hosts: ["[http://xxxx:9200](http://xxxx:9200)"]  
username: beats\_system  
password: xxx  
monitoring.enabled: true  
monitoring.elasticsearch:  
username: beats\_system  
password: xxxxx

* * *

are the logs below /var/log/_.log can be shipped vi filebeats and I can see one harvester created for each log, bit for /var/lib/lxc/_/test/_/logs/_.log, I can not see any harvester created for the files here.  
Also I can not see any errors on this.  
As I mentioned above, I can access those files using root, and also filebeat are launched using root.

Let me know what info I could provide for your further insights on this.

Thanks

---

<div class="post-metadata">

**Author:** ![yuecong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuecong/32/49061_2.png) [@yuecong](https://discuss.elastic.co/u/yuecong)\
**Post date:** [July 17, 2019, 5:48am UTC](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625/4 "2019-07-17T05:48:23Z")

</div>

@faec any insights on this? Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2019, 5:48am UTC](https://discuss.elastic.co/t/can-filebeats-to-read-lxc-container-logs/188625/5 "2019-08-14T05:48:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
