# Filebeat harvest only currently running docker containers

**URL:** <https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924>\
**Category:** Beats\
**Created:** [November 8, 2017, 7:31pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924 "2017-11-08T19:31:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![kwojcicki](https://avatars.discourse-cdn.com/v4/letter/k/57b2e6/32.png) [@kwojcicki](https://discuss.elastic.co/u/kwojcicki)\
**Post date:** [November 8, 2017, 7:31pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/1 "2017-11-08T19:31:03Z")

</div>

I am currently running filebeat to harvest all logs in /var/lib/docker/containers/_/_-json.log however this harvests all logs even if a container isn't running anymore. Is there a way to get around this or perhaps a different approach should be used?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 8, 2017, 9:54pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/2 "2017-11-08T21:54:31Z")

</div>

Hi @kwojcicki,

This is something that should not worry you if you plan to ship all logs, initial sync may be an issue though.

You can consider pruning your previous state, have a look to `docker system prune` command.

Also, we are already working on new features that will help with this [https://github.com/elastic/beats/pull/5245](https://github.com/elastic/beats/pull/5245)

---

<div class="post-metadata">

**Author:** ![kwojcicki](https://avatars.discourse-cdn.com/v4/letter/k/57b2e6/32.png) [@kwojcicki](https://discuss.elastic.co/u/kwojcicki)\
**Post date:** [November 9, 2017, 3:48pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/3 "2017-11-09T15:48:15Z")

</div>

Hey @exekias thanks for the quick reply. The auto discover feature looks great however until that is out I am worried about dev's running filebeat locally. Asking them to constantly `docker container prune` seems annoying when they are starting/stopping many containers constantly. I saw your comment about using drop\_event to whitelist/blacklist containers on this github issue [https://github.com/elastic/beats/issues/918#issuecomment-335999673](https://github.com/elastic/beats/issues/918#issuecomment-335999673) . Is this a viable solution if so how would it work?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 10, 2017, 10:21am UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/4 "2017-11-10T10:21:54Z")

</div>

Understood, There are several things you can do:

1- Put the docker id of the container you are interested in into filebeat.yml, you can probably script this

2- Whitelist containers by name, image or labels:

For example, you can do something like this to drop any event not matching any of the images you want

```auto
filebeat.prospectors:
- type: log
  paths:
   - '/var/lib/docker/containers/*/*.log'
  json.message_key: log
  json.keys_under_root: true
  processors:
  - add_docker_metadata: ~
  - drop_event.when.not.or:
      - equals:
          docker.contaner.image: busybox
      - equals:
          docker.contaner.image: alpine

```

---

<div class="post-metadata">

**Author:** ![kwojcicki](https://avatars.discourse-cdn.com/v4/letter/k/57b2e6/32.png) [@kwojcicki](https://discuss.elastic.co/u/kwojcicki)\
**Post date:** [November 13, 2017, 7:01pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/5 "2017-11-13T19:01:54Z")

</div>

We decided to go for option #1 as mentioned was a fairly simple script 😀. The auto discover feature is there an ETA for when it will be merged and generally available?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [November 15, 2017, 4:24pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/6 "2017-11-15T16:24:54Z")

</div>

I don't have an ETA on when it will merged, although it's pretty advanced 🙂 Once that happens it should make it to the next release in the 6.X line.

---

<div class="post-metadata">

**Author:** ![kwojcicki](https://avatars.discourse-cdn.com/v4/letter/k/57b2e6/32.png) [@kwojcicki](https://discuss.elastic.co/u/kwojcicki)\
**Post date:** [November 15, 2017, 4:50pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/7 "2017-11-15T16:50:09Z")

</div>

Sounds good I will follow the github PR to see when its merged. Thanks for the help this can be closed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2017, 7:31pm UTC](https://discuss.elastic.co/t/filebeat-harvest-only-currently-running-docker-containers/106924/8 "2017-11-29T19:31:14Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
