# Docker container custom logs - how to process them into kibana

**URL:** <https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 17, 2018, 6:20pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188 "2018-11-17T18:20:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 17, 2018, 6:20pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/1 "2018-11-17T18:20:17Z")

</div>

I have many containers running on server. One of them is nginx - I enabled filebeat module nginx, I have also created /etc/logstash/conf.d/nginx.conf -taken from website [https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html).

And logs from my nginx are shown in kibana just fine. But this is only 1 container out of 10.

And from other containers logs are not shown in kibana. But what modules should I enable for them if those are just custom applications running as containers - hence producing random logs?

Please help me here, please advise which configs should I change for filebeat/logstash/elasticsearch.

How I user ELK:  
one server running containers - running filebeat on the server  
second server - running logstash, elasticsearch, kibana

Example of custom logs generated by other containers:  
[pid: 23072|app: 0|req: 11278/21512] 127.0.0.1 () {32 vars in 367 bytes} [Sat Nov 17 18:59:09 2018] GET /ht/ =\> generated 261 bytes in 95 msecs (HTTP/1.1 200) 6 headers in 254 bytes (1 switches on core 0)  
[pid: 23072|app: 0|req: 11279/21513] 127.0.0.1 () {32 vars in 367 bytes} [Sat Nov 17 19:01:09 2018] GET /ht/ =\> generated 261 bytes in 516 msecs (HTTP/1.1 200) 6 headers in 254 bytes (1 switches on core 0)  
[pid: 23072|app: 0|req: 11280/21514] 127.0.0.1 () {32 vars in 367 bytes} [Sat Nov 17 19:03:09 2018] GET /ht/ =\> generated 261 bytes in 517 msecs (HTTP/1.1 200) 6 headers in 254 bytes (1 switches on core 0)

my filebeat.yml inputs looks like this

#=========================== Filebeat inputs =============================

filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so

# you can use different inputs for various configurations.

# Below are the input specific configurations.

- type: docker  
combine\_partial: true  
containers:  
path: "/var/lib/docker/containers/"  
stream: "stdout"  
ids:  
- "\*"  
tags: ["json"]
# Change to true to enable this input configuration.
enabled: true

Please help me

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 21, 2018, 8:04pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/2 "2018-11-21T20:04:28Z")

</div>

Thats exaclty how I setup my filebeat. But the logs for conainters (except container where nginx is running) are not sent to logstash. And even if they were, do I need to setup something specific in logstash or eleasticsearch to process it and send it to kibana? Nginx logs from container are send to kibana, only logs from other containers are not. Thank you

---

<div class="post-metadata">

**Author:** ![jarpy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jarpy/32/51290_2.png) [@jarpy](https://discuss.elastic.co/u/jarpy)\
**Post date:** [November 22, 2018, 10:49pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/3 "2018-11-22T22:49:42Z")

</div>

Yes. If your architecture looks like:

```nohighlight
Filebeat -> Logstash -> Elasticsearch

```

Then you will need to write a Logstash pipeline that includes the Beats input and Elasticsearch output in order for events to flow through Logstash.

Alternatively, if you don't need to do any complex processing in Logstash, you could use this architecture instead:

```nohighlight
Filebeat -> Elasticsearch

```

since Beats can talk directly to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 23, 2018, 2:05pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/4 "2018-11-23T14:05:36Z")

</div>

Thank you very much for your answer, I am considering to switch to the second model which you mentioned:

Filebeat -\> Elasticsearch

If I switched to that model, should I do some config changes / pipelines changes so that data are processed in elasticsearch?

As I posted in my first post here, I believe the logs which i need to process are quite simple.

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 23, 2018, 2:49pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/5 "2018-11-23T14:49:47Z")

</div>

It looks like logs are not even send to logstash, I found this errors for many containers

| 2018-11-23T15:47:27.742+0100 | INFO | log/harvester.go:251 | Harvester started for file: /var/lib/docker/containers/73c7e9a159df3cfd60fc844ee0cc2e360a0d4018eb3e2b768553d453090aa357/73c7e9a159df3cfd60fc844ee0cc2e360a0d4018eb3e2b768553d453090aa357-json.log |
| --- | --- | --- | --- |
| 2018-11-23T15:47:27.742+0100 | ERROR | log/harvester.go:278 | Read line error: invalid CRI log format; File: /var/lib/docker/containers/73c7e9a159df3cfd60fc844ee0cc2e360a0d4018eb3e2b768553d453090aa357/73c7e9a159df3cfd60fc844ee0cc2e360a0d4018eb3e2b768553d453090aa357-json.log |

What do you think could be the cause? Could it be that I dont have configured pipelines in logstash?

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 23, 2018, 3:21pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/6 "2018-11-23T15:21:35Z")

</div>

I stopped filebeat, removed /var/lib/filebeat/registry and then started filebeat. But I still get this error. Any help with that??

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 23, 2018, 4:07pm UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/7 "2018-11-23T16:07:38Z")

</div>

I have noticted that the logs which are not send via filebeat start with "[". Do you think it could cause the errors?

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 24, 2018, 9:56am UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/8 "2018-11-24T09:56:25Z")

</div>

it looks like the issue with CRI has been resolved by adding following lines to /etc/filebeat/filebeat.yml

cri.parse\_flags: true  
combine\_partial: true  
close\_inactive: 48h

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2018, 9:56am UTC](https://discuss.elastic.co/t/docker-container-custom-logs-how-to-process-them-into-kibana/157188/9 "2018-12-22T09:56:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
