# Docker gelf and logstash to logstash

**URL:** <https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740>\
**Category:** Logstash\
**Created:** [June 14, 2016, 12:54pm UTC](https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740 "2016-06-14T12:54:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![elmamazo](https://avatars.discourse-cdn.com/v4/letter/e/db5fbb/32.png) [@elmamazo](https://discuss.elastic.co/u/elmamazo)\
**Post date:** [June 14, 2016, 12:54pm UTC](https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740/1 "2016-06-14T12:54:28Z")

</div>

Hello guys  
Im using the dock gelf logging driver and I have the gelf input plugin and elastic search as output this works fine.

What I want to is is  
docker -\> gelf\_input -\> lumberjack\_out -\> lunberjack\_in -\> es

the problem is that all the goodies like container name and image id and so are lost in the logstash to logstash.

This is the proxy sending the logs to the other logstash machine (here I can access container\_name field for example)

```
input {
  gelf {
    type => docker
    port => 12201
  }
}
output {
  lumberjack {
    hosts => ["someremotehost.com"]
    port => 5000
    ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
  }
}

```

The receiving machine has this (here I only get the message field (I could merge and split but maybe there is better solution)

```
input {
  lumberjack {
    port => 5000
    type => "docker"
    ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
    ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }
}

```

Any ideas about how to persist the docker fields?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 19, 2016, 10:16am UTC](https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740/2 "2016-06-19T10:16:29Z")

</div>

What do the original events look like? What do they look like after the lumberjack back and forth? I suspect you'll want to use the json codec for both lumberjack plugins.

---

<div class="post-metadata">

**Author:** ![elmamazo](https://avatars.discourse-cdn.com/v4/letter/e/db5fbb/32.png) [@elmamazo](https://discuss.elastic.co/u/elmamazo)\
**Post date:** [June 20, 2016, 10:18am UTC](https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740/3 "2016-06-20T10:18:33Z")

</div>

Original  
`{ "_index": "logstash-2016.06.14", "_type": "docker", "_id": "AVVOP87XaNgHqqvkRf_V", "_score": null, "_source": { "version": "1.1", "host": "hamakabi", "level": 6, "@version": "1", "@timestamp": "2016-06-14T09:30:51.854Z", "source_host": "172.17.0.1", "message": "2016-06-14 09:30:50 UTC LOG: incomplete startup packet", "command": "/bin/sh -c rm -f /var/log/postgresql/postgresql-9.3-main.log \t&& service postgresql start \t&& tail -f /var/log/postgresql/postgresql-9.3-main.log", "container_id": "2397fda5076279766a84950b0760844b5470259cae", "container_name": "dbgelf", "created": "2016-06-14T09:30:47.481540705Z", "image_id": "sha256:b4dc0e3d48524c6908170394e", "image_name": "pgsql:dev", "tag": "", "type": "docker" }, "fields": { "created": [1465896647481], "@timestamp": [1465896651854] }, "sort": [1465896651854] }`

Here as you can see all the docker information is gone (I removed some sensitive fields) but I think you get the idea.  
`{ "_index": "logstash-2016.06.20", "_id": "AVVtS1kxrHGcnCLe_BTu", "_score": null, "_source": { "message": "a message", "@version": "1", "@timestamp": "2016-06-20T10:11:42.389Z", "host": "staging", "offset": "158221" }, "fields": { "@timestamp": [1466417502389] }, "sort": [1466417502389] }`

So your idea is to pack the message in json and then unpack it? can this be done in a quick WAY? right now I just did a merge off docker fields in the message and the I do a split in the other side. I think that json would be more elegant.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 20, 2016, 12:34pm UTC](https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740/4 "2016-06-20T12:34:07Z")

</div>

Add `codec => json` to the lumberjack input and output plugins.

---

<div class="post-metadata">

**Author:** ![elmamazo](https://avatars.discourse-cdn.com/v4/letter/e/db5fbb/32.png) [@elmamazo](https://discuss.elastic.co/u/elmamazo)\
**Post date:** [June 20, 2016, 4:01pm UTC](https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740/5 "2016-06-20T16:01:41Z")

</div>

this totally did the trick!  
thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:51am UTC](https://discuss.elastic.co/t/docker-gelf-and-logstash-to-logstash/52740/6 "2017-07-06T04:51:49Z")

</div>


