# \[Filebeat\] HAProxy module in combination with autodiscover

**URL:** <https://discuss.elastic.co/t/filebeat-haproxy-module-in-combination-with-autodiscover/257539>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [December 3, 2020, 3:51pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-in-combination-with-autodiscover/257539 "2020-12-03T15:51:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dacamposol](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dacamposol/32/80191_2.png) [@dacamposol](https://discuss.elastic.co/u/dacamposol)\
**Post date:** [December 3, 2020, 3:51pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-in-combination-with-autodiscover/257539/1 "2020-12-03T15:51:20Z")

</div>

Good afternoon everyone,

I have a server where are running one instance of `haproxy` and one instance of `filebeat` in different containers.

In order to have the output of `haproxy` accesible by `docker logs`, I have configured the output in **stdout** as recommended in the [HAProxy blog](https://www.haproxy.com/blog/introduction-to-haproxy-logging/#:~:text=HAProxy%20Log%20Format,TCP%20mode%20is%20the%20default.).

```auto
defaults
    log stdout format raw local0 info
    mode http
    option httplog

```

This generates the following output when I execute the `docker logs` command:

```auto
XX.XX.XX.XXX:YYYYY [03/Dec/2020:15:29:08.146] http-in backend/appserver 0/0/0/1/1 200 217 - - ---- 3/3/0/0/0 0/0 "HEAD /inf/test.html HTTP/1.1"

```

My problem comes, because I have configured my `filebeat.yml` to work with autodiscovery and the `haproxy` module:

```auto
filebeat:
  autodiscover.providers:
    - type: docker
      templates:
        - condition:
            contains:
              docker.container.image: haproxy
          config:
            - module: haproxy
              log:
                input:
                  type: container
                  paths:
                    - /var/lib/docker/containers/${data.docker.container.id}/*.log

```

But the previous configuration doesn't seem to work, since once I check for the data in Kibana, the entire line is under the `message` field, and the `haproxy` fields aren't present.

When I checked the **grok** in the `haproxy`-module, I saw that it was expecting the process name and the pid at the beginning of the `message` field, so I tried modifying the log-format to a custom one following the **grok** expectations, but it doesn't work neither.

```auto
defaults
    log stdout format raw local0 info
    log-format "haproxy[%pid]: %ci:%cp [%tr] %ft %b/%s %TR/%Tw/%Tc/%Tr/%Ta %ST %B %CC %CS %tsc %ac/%fc/%bc/%sc/%rc %sq/%bq %hr %hs %{+Q}r"
    mode http

```

Does someone know how to configure it properly or if is it a bug from the combination of **autodiscover + haproxy module**?

**UPDATE:**

In order to check the reason, I also tried to include the apache module as follows, but it doesn't seem either to work.

```auto
filebeat:
  inputs:
    - type: log
      enabled: true
      paths:
      - /var/lib/docker/volumes/monitor_logs/_data/*
  autodiscover.providers:
    - type: docker
      templates:
        - condition:
            contains:
              docker.container.image: haproxy
          config:
            - module: haproxy
              log:
                input:
                  type: container
                  paths:
                    - /var/lib/docker/containers/${data.docker.container.id}/*.log
        - condition:
            contains:
              docker.container.image: httpd
          config:
            - module: apache
              access:
                input:
                  type: container
                  paths:
                    - /var/lib/docker/containers/${data.docker.container.id}/*.log

```

I was expecting something like the fields shown in [https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-apache.html](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-apache.html) but it still just adds the whole log line under the `message` field:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e26dfd6528f2116d53095e843e8637857e38ab07.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2020, 5:51pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-in-combination-with-autodiscover/257539/2 "2020-12-31T17:51:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
