# Fleet and autodiscovery

**URL:** <https://discuss.elastic.co/t/fleet-and-autodiscovery/317284>\
**Category:** Beats\
**Tags:** docker, fleet\
**Created:** [October 23, 2022, 6:53pm UTC](https://discuss.elastic.co/t/fleet-and-autodiscovery/317284 "2022-10-23T18:53:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [October 23, 2022, 6:53pm UTC](https://discuss.elastic.co/t/fleet-and-autodiscovery/317284/1 "2022-10-23T18:53:01Z")

</div>

Hello All,

I have the following docker containers running with Docker Swarm:

1. Elastic Agent
2. Filebeat
3. Traefik service
4. Spring boot app

We are trying to obtain the spring boot app/traefik logs via Elastic Agent but it is not working , so we had to add a Filebeat Instance to enable the autodiscovery option.

Docker metrics are showing fine via Docker metrics integration, but logs are not coming via Fleet after adding the integrations to the agent so we are using Filebeat + autodiscover:

```auto
​filebeat.config:
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: false

filebeat.autodiscover:
  providers:
    - type: docker
      hints.enabled: true

```

Is there a way to get rid of the Filebeat instance and get this logs via Elastic Agent as well?

Thank you

---

<div class="post-metadata">

**Author:** ![Gustavo\_Llermaly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_llermaly/32/92019_2.png) [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Post date:** [October 23, 2022, 9:15pm UTC](https://discuss.elastic.co/t/fleet-and-autodiscovery/317284/2 "2022-10-23T21:15:55Z")

</div>

My conclusion is right now this is not possible with Fleet Managed Agents, just standalone ones via dynamic inputs.

Found some issues about:

> <https://github.com/elastic/elastic-agent/issues/707>
>
> \### Context
> Picking up context from https://github.com/elastic/beats/issues/238…76
> We want to enable users to monitor Kubernetes workloads through user-provided conditions on the fleet UI 
> 
> \### Problem definition
> Elastic operators need to collect and ingest data from workloads that have a characteristic that is not necessarily aligned with the Kubernetes infrastructure.
> 
> \<img width="498" alt="image" src="https://user-images.githubusercontent.com/39376769/195316666-626fde1d-ebc8-42e8-bb5f-7096d0085d0d.png"\>
> 
> \### User outcome
> Elastic operators can define the conditions that a workload which is to be monitored needs to meet in order for it to be observed. Workloads that meet the conditions defined by the Elastic Operator will have a frictionless experience that will not require further steps from the user side.
> 
> Solution hypothesis
> We believe that providing Elastic operators with a conditions field in the fleet UI will enable them to decide which workloads need to be monitored
> 
> !\[image\](https://user-images.githubusercontent.com/39376769/195317182-43213184-8234-4429-b133-6238e55ca127.png)
> 
> \### Dependency on Fleet UI
> Kibana issue: https://github.com/elastic/kibana/issues/108525

> <https://github.com/elastic/elastic-agent/issues/128>
>
> I'd like to ask for your recommendation for users that prefer to run Elastic Age…nt in the container (let's say due to security reasons).
> 
> Let's discuss the scenario:
> 
> The integrated product is nginx running in a container. It produces logs stored locally in the image and which are rotated. As the agent is running in a different container, it can't simply access produced logs.
> 
> What is your recommendation in this particular case? Should the user expose somehow log files? Mirror them?
> 
> Background -
> I had an interesting talk with @ycombinator about possibilites and testing scenarios and it looks that we will both have to nail this problem (force agent to watch logs produced in a different container).

Would be great if someone from Elastic can validate this.

Gustavo

---

<div class="post-metadata">

**Author:** ![AndersonQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andersonq/32/112214_2.png) [@AndersonQ](https://discuss.elastic.co/u/AndersonQ)\
**Post date:** [October 31, 2022, 4:42pm UTC](https://discuss.elastic.co/t/fleet-and-autodiscovery/317284/3 "2022-10-31T16:42:37Z")

</div>

Hello @Gustavo_Llermaly,

Even though it isn't exactly supported, you can try adding a custom log input reading the container logs. You can set the path in the custom log integration page. You can also use the advanced field if you want to add more configuration that the UI does not allow.

You should end up with something similar to the snippet below in your policy

```auto
 - name: container-log
   type: logfile
   use_output: default
   data_stream:
     namespace: default
   streams:
     - data_stream:
         dataset: generic
       symlinks: true
       paths:
        - /var/lib/docker/containers/${docker.container.id}/${docker.container.id}-json.log
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2022, 6:42pm UTC](https://discuss.elastic.co/t/fleet-and-autodiscovery/317284/4 "2022-11-28T18:42:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
