And also sample doument (too lengt post):
{
"_index": "filebeat-7.3.0-2019.08.03-000001",
"_type": "_doc",
"_id": "XuCyYGwBHJ227QPYFYO_",
"_version": 1,
"_score": null,
"_source": {
"@timestamp": "2019-08-05T07:32:55.857Z",
"stream": "stdout",
"logstash": {
"OriginStatusLine": "200 OK",
"RequestAddr": "automaton-mt.mitus-test.teta.net",
"origin_X-Xss-Protection": "1 ; mode=block",
"BackendName": "backend-gateway-mt",
"Duration": 10862475,
"OriginDuration": 10776795,
"OriginStatus": 200,
"downstream_Date": "Mon, 05 Aug 2019 07:32:55 GMT",
"request_Accept-Language": "pl-PL,pl;q=0.9,en-US;q=0.8,en;q=0.7",
"request_Authorization": "Bearer eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJraWtvbCIsInNjb3BlIjoiYXBpIiwiaXNzIjoia2lrb2wiLCJpYXQiOjE1NjQ5OTAzNTQsImV4cCI6MTU2NTA3Njc1NH0.t4pD5nuedDeZhbUYBtNvYGcUW5VwgyfqhP9iE20d6F9h_s-v3m-SDjyQX2ByEDKPjMx4JHGUdzgmSUvgnQKaqQ",
"Overhead": 85680,
"downstream_Referrer-Policy": "no-referrer",
"level": "info",
"ClientUsername": "-",
"StartUTC": "2019-08-05T07:32:55.846776227Z",
"downstream_Content-Type": "application/json;charset=UTF-8",
"downstream_X-Content-Type-Options": "nosniff",
"origin_Pragma": "no-cache",
"request_User-Agent": "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36",
"origin_Expires": "0",
"ClientAddr": "10.48.92.178:62941",
"FrontendName": "Host-automaton-mt-mitus-test-teta-net-automaton-review-mitus-test-teta-net-PathPrefixStrip-api-61",
"RequestHost": "automaton-mt.mitus-test.teta.net",
"RetryAttempts": 0,
"downstream_Vary": "Accept-Encoding",
"downstream_X-Xss-Protection": "1 ; mode=block",
"origin_Referrer-Policy": "no-referrer",
"origin_X-Content-Type-Options": "nosniff",
"request_Accept": "application/json, text/plain, */*",
"request_X-Forwarded-Proto": "http",
"DownstreamStatus": 200,
"RequestPath": "/api/taskmanagement/tasks/statistic/",
"StartLocal": "2019-08-05T09:32:55.846776227+02:00",
"time": "2019-08-05T09:32:55+02:00",
"RequestCount": 6939,
"DownstreamStatusLine": "200 OK",
"RequestProtocol": "HTTP/1.1",
"origin_X-Frame-Options": "DENY",
"request_X-Forwarded-For": "127.0.0.1",
"request_X-Forwarded-Prefix": "/api",
"ClientPort": "62941",
"origin_Content-Type": "application/json;charset=UTF-8",
"request_Referer": "http://localhost:8080/tasks/user",
"request_X-Forwarded-Host": "localhost:8080",
"request_X-Forwarded-Port": "8080",
"RequestLine": "GET /api/taskmanagement/tasks/statistic/ HTTP/1.1",
"downstream_Cache-Control": "no-cache, no-store, max-age=0, must-revalidate",
"msg": "",
"request_Connection": "close",
"BackendURL": {
"Scheme": "http",
"Path": "",
"Fragment": "",
"ForceQuery": false,
"RawQuery": "",
"Opaque": "",
"User": null,
"Host": "10.0.26.111:8080",
"RawPath": ""
}
},
"host": {
"name": "1516ac37019c"
},
"log": {
"file": {
"path": "/var/lib/docker/containers/8d932184e0af1dc988db75de02981fc39de388aa940fc2dc4f53ed5c2713e0b8/8d932184e0af1dc988db75de02981fc39de388aa940fc2dc4f53ed5c2713e0b8-json.log"
},
"offset": 1388535
},
"ecs": {
"version": "1.0.1"
},
"input": {
"type": "container"
},
"docker": {
"container": {
"labels": {
"org_opencontainers_image_url": "https://traefik.io",
"com_docker_swarm_node_id": "vjpbn32i27e2l3xhw098iug65",
"com_docker_swarm_task": "",
"com_docker_swarm_service_id": "pg1nc3phr2wd7wpkexo6pijb7",
"org_opencontainers_image_vendor": "Containous",
"org_opencontainers_image_documentation": "https://docs.traefik.io",
"proxy": "true",
"com_docker_stack_namespace": "infrastructure",
"com_docker_swarm_service_name": "infrastructure_traefik",
"org_opencontainers_image_title": "Traefik",
"org_opencontainers_image_description": "A modern reverse-proxy",
"com_docker_swarm_task_name": "infrastructure_traefik.1.cdz042qgr260paryvqkgue8vn",
"logstash": "false",
"com_docker_swarm_task_id": "cdz042qgr260paryvqkgue8vn",
"org_opencontainers_image_version": "v1.7.11",
"traefik": "false"
}
}
},
"container": {
"name": "infrastructure_traefik.1.cdz042qgr260paryvqkgue8vn",
"image": {
"name": "traefik:1.7.11@sha256:d590b5ef1278809b8809025eba2bd67afc2fdfe1926d87e67fcada14deb38652"
},
"id": "8d932184e0af1dc988db75de02981fc39de388aa940fc2dc4f53ed5c2713e0b8",
"labels": {
"org_opencontainers_image_vendor": "Containous",
"org_opencontainers_image_version": "v1.7.11",
"traefik": "false",
"logstash": "false",
"com_docker_swarm_task_id": "cdz042qgr260paryvqkgue8vn",
"com_docker_swarm_service_id": "pg1nc3phr2wd7wpkexo6pijb7",
"com_docker_swarm_service_name": "infrastructure_traefik",
"org_opencontainers_image_description": "A modern reverse-proxy",
"org_opencontainers_image_title": "Traefik",
"org_opencontainers_image_url": "https://traefik.io",
"com_docker_swarm_task_name": "infrastructure_traefik.1.cdz042qgr260paryvqkgue8vn",
"org_opencontainers_image_documentation": "https://docs.traefik.io",
"com_docker_stack_namespace": "infrastructure",
"proxy": "true",
"com_docker_swarm_node_id": "vjpbn32i27e2l3xhw098iug65",
"com_docker_swarm_task": ""
}
},
"agent": {
"version": "7.3.0",
"type": "filebeat",
"ephemeral_id": "bea05f1b-0ea3-48df-84e8-6843ffa92ac4",
"hostname": "1516ac37019c",
"id": "0f6a83c3-6d32-4229-91e3-5a706a9244f9"
}
},
"fields": {
"@timestamp": [
"2019-08-05T07:32:55.857Z"
],
"suricata.eve.timestamp": [
"2019-08-05T07:32:55.857Z"
]
},
"sort": [
1564990375857
]
}