# Docker Swarm + Filebeat

**URL:** <https://discuss.elastic.co/t/docker-swarm-filebeat/112002>\
**Category:** Beats\
**Created:** [December 15, 2017, 2:55pm UTC](https://discuss.elastic.co/t/docker-swarm-filebeat/112002 "2017-12-15T14:55:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ZaphordB](https://avatars.discourse-cdn.com/v4/letter/z/e9bcb4/32.png) [@ZaphordB](https://discuss.elastic.co/u/ZaphordB)\
**Post date:** [December 15, 2017, 2:55pm UTC](https://discuss.elastic.co/t/docker-swarm-filebeat/112002/1 "2017-12-15T14:55:42Z")

</div>

Hi!  
There is a server with ELK 5.6 stack and now I need to analyze logs from Docker Swarm hosts. Is it possible to config Filebeat (or any other Beat) inside Swarm to send logs to the ELK server?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [December 17, 2017, 10:59pm UTC](https://discuss.elastic.co/t/docker-swarm-filebeat/112002/2 "2017-12-17T22:59:35Z")

</div>

Hi @ZaphordB,

You should be able to use something like this to get your logs: [https://www.elastic.co/blog/enrich-docker-logs-with-filebeat](https://www.elastic.co/blog/enrich-docker-logs-with-filebeat). Just take into account it requires Filebeat \>= 6.0.0 (`6.1` is the latest one at the moment)

---

<div class="post-metadata">

**Author:** ![ZaphordB](https://avatars.discourse-cdn.com/v4/letter/z/e9bcb4/32.png) [@ZaphordB](https://discuss.elastic.co/u/ZaphordB)\
**Post date:** [December 19, 2017, 3:49pm UTC](https://discuss.elastic.co/t/docker-swarm-filebeat/112002/3 "2017-12-19T15:49:35Z")

</div>

Thank you! It's working!  
But I have logs only from one swarm-worker but not from swarm-manager and other nods. Is it OK?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [December 19, 2017, 4:33pm UTC](https://discuss.elastic.co/t/docker-swarm-filebeat/112002/4 "2017-12-19T16:33:17Z")

</div>

Awesome!

In order to get logs from all nodes you need to have one Filebeat container per node. I'm not too familiar with Swarm but I think you can achieve that using a global service?

---

<div class="post-metadata">

**Author:** ![ZaphordB](https://avatars.discourse-cdn.com/v4/letter/z/e9bcb4/32.png) [@ZaphordB](https://discuss.elastic.co/u/ZaphordB)\
**Post date:** [December 21, 2017, 1:35pm UTC](https://discuss.elastic.co/t/docker-swarm-filebeat/112002/5 "2017-12-21T13:35:40Z")

</div>

Again thank you very much! Everything works perfect. Other nods just needed time to start send logs to Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2018, 3:05pm UTC](https://discuss.elastic.co/t/docker-swarm-filebeat/112002/6 "2018-01-05T15:05:18Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
