# Filebeat breaking up docker log lines

**URL:** <https://discuss.elastic.co/t/filebeat-breaking-up-docker-log-lines/146420>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 28, 2018, 9:13pm UTC](https://discuss.elastic.co/t/filebeat-breaking-up-docker-log-lines/146420 "2018-08-28T21:13:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![btieman](https://avatars.discourse-cdn.com/v4/letter/b/91b2a8/32.png) [@btieman](https://discuss.elastic.co/u/btieman)\
**Post date:** [August 28, 2018, 9:13pm UTC](https://discuss.elastic.co/t/filebeat-breaking-up-docker-log-lines/146420/1 "2018-08-28T21:13:34Z")

</div>

I'm using filebeat 6.3 to read docker log files with the default docker json-file driver. Lines over 16kb in size are being reported by filebeat as 2 seperate log events.

The symptoms look like the situation the combine\_partial[1] option is supposed to address. However, combine\_partial is supposed to be true by default and even if I explicitly set it to true, I see the same behavior.

What I'm trying to do is ingest a docker container log where our application has logged a large chunk of JSON. We are using decode\_json\_fields to parse one of the log fields but since the line gets split, the json doesn't get parsed.

My filebeat configuration is

- type: docker  
combine\_partial: true  
containers:  
ids:
  - '\*'  
path: ${CONTAINER\_LOGS\_DIR}  
stream: 'all'  
json:  
keys\_under\_root: true  
overwrite\_keys: true  
add\_error\_key: true  
message\_key: message  
tags:
  - 'filebeat'  
fields:  
abltools\_application: 'filebeat'  
abltools\_environment: ${ABLTOOLS\_ENVIRONMENT}  
processors:
  - add\_docker\_metadata: ~
  - add\_host\_metadata: ~
  - decode\_json\_fields:  
fields:
    - 'message'  
max\_depth: 1  
target: "json\_message"

Is there something obvious I'm doing wrong? Or is this a bug?

Thanks for the help!

[1] [https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-input-docker.html#\_literal\_combine\_partial\_literal](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-input-docker.html#_literal_combine_partial_literal)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 29, 2018, 10:41am UTC](https://discuss.elastic.co/t/filebeat-breaking-up-docker-log-lines/146420/2 "2018-08-29T10:41:36Z")

</div>

Can you share some failing sample logs?

Is filebeat itself reporting any errors?

---

<div class="post-metadata">

**Author:** ![btieman](https://avatars.discourse-cdn.com/v4/letter/b/91b2a8/32.png) [@btieman](https://discuss.elastic.co/u/btieman)\
**Post date:** [August 29, 2018, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-breaking-up-docker-log-lines/146420/3 "2018-08-29T13:09:02Z")

</div>

I think the issue is me and my ability to use documentation ☹ I thought I had the documentation for 6.3 but it looks like the feature[1] I was hoping to use wasn't released until 6.4.

I'll try uplifting to filebeat 6.4 and see if the issue goes away.

Thanks!

[1] [https://github.com/elastic/beats/pull/6967](https://github.com/elastic/beats/pull/6967)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2018, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-breaking-up-docker-log-lines/146420/4 "2018-09-26T13:09:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
