# Filebeat Autodiscovery for coredns in docker, what labels to use?

**URL:** <https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [September 29, 2019, 11:08am UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530 "2019-09-29T11:08:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Masta\_Boombastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/masta_boombastic/32/36025_2.png) [@Masta\_Boombastic](https://discuss.elastic.co/u/Masta_Boombastic)\
**Post date:** [September 29, 2019, 11:08am UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530/1 "2019-09-29T11:08:34Z")

</div>

I'm running elk and coredns in docker.

I am having difficulty getting any log data from coredns docker container using the autodiscovery.

The sample apache auto discovery works a treat for me, I get data in ES and nice apache fields, [https://www.elastic.co/guide/en/beats/filebeat/current/running-on-docker.html](https://www.elastic.co/guide/en/beats/filebeat/current/running-on-docker.html)

For coredns I've tried -

```
--label co.elastic.logs/module=coredns \

```

and using labels from the apache example -

```
--label co.elastic.logs/module=coredns \
--label co.elastic.logs/fileset.stdout=access \
--label co.elastic.logs/fileset.stderr=error \
--label co.elastic.metrics/module=coredns \
--label co.elastic.metrics/metricsets=status \
--label co.elastic.metrics/hosts='${data.host}:${data.port}' \

```

Is there a list of what labels are needed for coredns module?

How do I go about debugging this? Does filebeat output an error somewhere?

Thanks!

---

<div class="post-metadata">

**Author:** ![MangledDeutz](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@MangledDeutz](https://discuss.elastic.co/u/MangledDeutz)\
**Post date:** [October 4, 2019, 9:21pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530/2 "2019-10-04T21:21:15Z")

</div>

Same problem here.

After much exploration, it seems that the coredns ingester will not work by default, because it is expecting a leading timestamp that is not there with the default coredns / docker logging.

Here is how I solved it:

```auto
sed -i'' -e "s,%{timestamp} ,,g" module/coredns/log/ingest/pipeline-plaintext.json
sed -i'' -e "s,%{timestamp} ,,g" module/coredns/log/ingest/pipeline-json.json
sed -i'' -e 's,"ignore_failure" : true,"if": "ctx.timestamp != null",g' module/coredns/log/ingest/pipeline-entry.json

```

This removes the timestamp entry from the ingester (must be applied in your logbeat config / image).

Also, your labels seem wrong. Coredns does not have "access" and "error", just "log".

Here are working labels for me (assuming the above patch as well):

```auto
    co.elastic.logs/module=coredns
    co.elastic.logs/fileset=log

```

---

<div class="post-metadata">

**Author:** ![MangledDeutz](https://avatars.discourse-cdn.com/v4/letter/m/c0e974/32.png) [@MangledDeutz](https://discuss.elastic.co/u/MangledDeutz)\
**Post date:** [October 5, 2019, 12:19am UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530/3 "2019-10-05T00:19:11Z")

</div>

@Masta_Boombastic Here is a docker image for filebeat that contains the fixes above (and does work as expected for the coredns module).

[https://hub.docker.com/r/dubodubonduponey/filebeat](https://hub.docker.com/r/dubodubonduponey/filebeat)

Source:

> **[dubo-dubon-duponey/docker-elastic-filebeat](https://github.com/dubo-dubon-duponey/docker-elastic-filebeat)**
>
> Contribute to dubo-dubon-duponey/docker-elastic-filebeat development by creating an account on GitHub.

_!!!USE AT YOUR OWN RISK!!!_ as I don't intend on maintaining this, beyond my own needs.

Hope that helps.

~~Note that the dashboard still doesn't work (getting exceptions).~~  
I wonder if this module is even maintained.

Latest version of the image also includes fixes for the dashboard & viz.

---

<div class="post-metadata">

**Author:** ![Masta\_Boombastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/masta_boombastic/32/36025_2.png) [@Masta\_Boombastic](https://discuss.elastic.co/u/Masta_Boombastic)\
**Post date:** [October 5, 2019, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530/4 "2019-10-05T12:56:02Z")

</div>

Excellent! Worked a treat.

Thanks for this. You should get a double bonus for a reply using sed. I hadn't seen sed used with commas before, so that's another bonus point.

While investigating this I found a comment on coredns forum that removed the timestamp due to it being displayed doublely when using some logging mechanism. I guess this is all a moving target and difficult to keep everthing up to date.

In the end I copied the coredns module config from the current filebeat image docker container, made your changes to my local config, and then mount those files again into filebeat container.

For those in similar situation, useful commands to run. (where coredns is your container name, or use its id) :

```
docker logs coredns
docker logs -t coredns

```

Thanks Again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2019, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-autodiscovery-for-coredns-in-docker-what-labels-to-use/201530/5 "2019-11-02T12:56:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
