# \[Elastic Log Driver\] Structured JSON logs breaks when Docker splits large log lines

**URL:** <https://discuss.elastic.co/t/elastic-log-driver-structured-json-logs-breaks-when-docker-splits-large-log-lines/385448>\
**Category:** Beats\
**Tags:** docker, beats-module\
**Created:** [March 14, 2026, 2:10am UTC](https://discuss.elastic.co/t/elastic-log-driver-structured-json-logs-breaks-when-docker-splits-large-log-lines/385448 "2026-03-14T02:10:11Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![empee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/empee/32/147123_2.png) [@empee](https://discuss.elastic.co/u/empee)\
**Post date:** [March 14, 2026, 2:10am UTC](https://discuss.elastic.co/t/elastic-log-driver-structured-json-logs-breaks-when-docker-splits-large-log-lines/385448/1 "2026-03-14T02:10:11Z")

</div>

## Summary

When using the Elastic Docker Logging Plugin, applications that already emit structured JSON logs cannot reliably ingest them into Elasticsearch because Docker may split large log lines before they reach the logging plugin. The plugin then wraps each fragment in a separate event under the `message` field, which makes the JSON impossible to parse downstream.

This breaks a common use case: applications emitting structured JSON logs to stdout.

## Logging configuration:

```yaml
logging:
  driver: "elastic/elastic-logging-plugin:9.3.1"
  options:
    hosts: "http://localhost:9200"
    index: "docker-logs"

```

Application logs are already JSON.

Example application log:

```json
{
  "@timestamp": "2026-03-13T18:10:23.326Z",
  "log.level": "ERROR",
  "message": "Request generated INTERNAL error",
  "trace_id": "b24846d3-8b73-4b91-b695-8c4cc9e92b20",
  "error.stack_trace": "... large stacktrace ..."
}

```

## Problem

The Docker logging driver may split large stdout lines. When that happens, the elastic logging plugin receives fragments instead of a full log line. Because the original JSON is split across multiple events, downstream ingest pipelines cannot parse the structured log.

## Expected behavior

The plugin should detect large splitted JSON logs and merge them with the ECS envelope instead of wrapping them as a string in `message`.

## Actual behavior

Large structured JSON logs become fragmented events and structured logging is effectively broken.

## Impact

- rely on fragile ingest pipelines
- accept partial JSON parsing
- switch to alternative architectures
