# Configuration in Logstash don't match logging of docker container

**URL:** <https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205>\
**Category:** Logstash\
**Created:** [May 25, 2020, 8:09pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205 "2020-05-25T20:09:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![hhwvg7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hhwvg7/32/69027_2.png) [@hhwvg7](https://discuss.elastic.co/u/hhwvg7)\
**Post date:** [May 25, 2020, 8:09pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205/1 "2020-05-25T20:09:52Z")

</div>

I run the next container:  
docker run -d --log-driver=syslog --log-opt syslog-address=tcp://:5000 --log-opt syslog-facility=daemon --name piet -p 8080:80 httpd

But In Kibana I see a \_grokparsefailure.  
Please help: How can I modify my Grok statement that it match the logging coming from the container "piet" ?

Thank you for your reply!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 25, 2020, 9:31pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205/2 "2020-05-25T21:31:09Z")

</div>

Well, you would need to show us the value of the field you are trying to grok and also the configuration of your grok filter.

---

<div class="post-metadata">

**Author:** ![hhwvg7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hhwvg7/32/69027_2.png) [@hhwvg7](https://discuss.elastic.co/u/hhwvg7)\
**Post date:** [May 26, 2020, 4:07pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205/3 "2020-05-26T16:07:36Z")

</div>

Thanks for helping me.  
I started the Logstash container as follow:

#### 

sudo docker run --rm -it --network mynetwork --name logstash -p 5000:5000 -v ~/pipeline/:/usr/share/logstash/pipeline/ [docker.elastic.co/logstash/logstash:7.7.0](http://docker.elastic.co/logstash/logstash:7.7.0)

### 

The configuration of the Logstash is as follow:  
input {  
syslog {  
port =\> 5000  
#type =\> "docker"  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{SYSLOG5424PRI}%{NONNEGINT:ver} +(?:%{TIMESTAMP\_ISO8601:ts}|-) +(?:%{HOSTNAME:service}|-) +(?:%{NOTSPACE:containerName}|-) +(?:%{NOTSPACE:proc}|-) +(?:%{WORD:msgid}|-)  
+(?:%{SYSLOG5424SD:sd}|-|) +%{GREEDYDATA:msg}" }  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
mutate {  
remove\_field =\> [ "message", "priority", "ts", "severity", "facility", "facility\_label", "severity\_label", "syslog5424\_pri", "proc", "syslog\_severity\_code", "syslog\_facility\_code", "syslog\_faci  
lity", "syslog\_severity", "syslog\_hostname", "syslog\_message", "syslog\_timestamp", "ver" ]  
}  
mutate {  
remove\_tag =\> ["\_grokparsefailure\_sysloginput"]  
}  
mutate {  
gsub =\> [  
"service", "[0123456789-]", ""  
]  
}  
if [msg] =~ "^ \*{" {  
json {  
source =\> "msg"  
}  
if "\_jsonparsefailure" in [tags] {  
drop {}  
}  
mutate {  
remove\_field =\> ["msg"]  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["elasticsearch:9200"]  
}  
stdout { codec =\> rubydebug }  
}

The container that I start to get the logs, I have started as follow:

#### 

sudo docker run -d --name piet --log-driver=syslog --log-opt syslog-address=tcp://:5000 --log-opt syslog-facility=daemon -p 8080:80 httpd

#### 

#### 

sudo docker run --name telegraf -d --log-driver=syslog --log-opt syslog-address=tcp://:5000 --log-opt syslog-facility=local5 -p 8092:8092/udp telegraf

#### 

The output that I see on Logstash is as follow:  
{  
"host" =\> "172.18.0.1",  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"@timestamp" =\> 2020-05-26T16:04:20.002Z,  
"@version" =\> "1"  
}  
{  
"host" =\> "172.18.0.1",  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"@timestamp" =\> 2020-05-26T16:04:20.003Z,  
"@version" =\> "1"  
}  
Note: Also this is what I see in Kibana

---

<div class="post-metadata">

**Author:** ![hhwvg7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hhwvg7/32/69027_2.png) [@hhwvg7](https://discuss.elastic.co/u/hhwvg7)\
**Post date:** [May 26, 2020, 4:08pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205/4 "2020-05-26T16:08:55Z")

</div>

Sorry, I see that the indentation in the logstash configuration has been deleted by the system.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 26, 2020, 4:10pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205/5 "2020-05-26T16:10:56Z")

</div>

Edit the post, select the configuration and click on \</\> in the toolbar above the edit pane. Then do the same for the output.

Also, please add an example of the message you are trying to parse.

---

<div class="post-metadata">

**Author:** ![hhwvg7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hhwvg7/32/69027_2.png) [@hhwvg7](https://discuss.elastic.co/u/hhwvg7)\
**Post date:** [June 6, 2020, 6:28pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205/7 "2020-06-06T18:28:28Z")

</div>

Badger,  
I saw the problem and update the Grok statement. Thanks for trying helping me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2020, 6:28pm UTC](https://discuss.elastic.co/t/configuration-in-logstash-dont-match-logging-of-docker-container/234205/8 "2020-07-04T18:28:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
