# Docker swarm container log monitoring - require help

**URL:** <https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 27, 2018, 5:12am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115 "2018-09-27T05:12:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sl1729](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@sl1729](https://discuss.elastic.co/u/sl1729)\
**Post date:** [September 27, 2018, 5:12am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115/1 "2018-09-27T05:12:04Z")

</div>

Hello All,

We got filebeat monitoring setup for the VM hosted apps and now trying to monitor logs of containers of docker swarm setup which uses json-file as a logging driver.

I have a filebeat (docker worker node) --\> logstash --\> elasticsearch configured,

Got the raw event passed to elasticsearch but it has only the container id of the docker as metadata, I am looking for more attributes like image, service and labels to be sent along with the event to make the dashboard more meaningful/useful.

My file beat config looks like,

```auto
- type: log
  paths:
    - '/mnt/docker/logs/containers/*/*.log'
  json.message_key: log
  json.keys_under_root: true
  processors:
    - add_docker_metadata: ~
  fields:
    app_id: docker
    env: dev
  fields_under_root: true
```

Any pointer or help is appreciated.

Note: Elastic version : **6.3.2**

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [September 27, 2018, 8:02am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115/2 "2018-09-27T08:02:32Z")

</div>

Hi 🙂

Please, can you provide us with a couple of lines of actual _input_ and the _output_ JSON which is going to Elasticsearch?

I don't see anything wrong in your config. I'm just wondering if the logs that you're fetching are the containers stderr / stdout and that maybe it's not mixed with logs of Swarm itself.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [September 27, 2018, 8:22am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115/3 "2018-09-27T08:22:53Z")

</div>

Ah, no wait, I think that your configuration isn't correct in the key `add_docker_metadata`. Refer here to double check [https://www.elastic.co/guide/en/beats/filebeat/6.0/add-docker-metadata.html](https://www.elastic.co/guide/en/beats/filebeat/6.0/add-docker-metadata.html)

---

<div class="post-metadata">

**Author:** ![sl1729](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@sl1729](https://discuss.elastic.co/u/sl1729)\
**Post date:** [September 28, 2018, 4:22am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115/4 "2018-09-28T04:22:57Z")

</div>

Thanks it is working now, and I am able to get the metadata added to the event.

```
- add_docker_metadata:
    host: "unix:///var/run/docker.sock"
    match_source_index: 4

```

And now trying to monitor how to filter(drop events) based on image names as we want to monitor specific application. Any pointers.

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [October 1, 2018, 7:20am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115/5 "2018-10-01T07:20:38Z")

</div>

Well, you should filter your queries in Elasticsearch and this is the preferred method (you never know if you'll need that "filtered" data later).

If you really don't want that data to arrive to Elasticsearch, then you can filter it using Logstash [https://www.elastic.co/guide/en/logstash/current/filter-plugins.html](https://www.elastic.co/guide/en/logstash/current/filter-plugins.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2018, 7:20am UTC](https://discuss.elastic.co/t/docker-swarm-container-log-monitoring-require-help/150115/6 "2018-10-29T07:20:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
