# Help with a grok filter for Docker

**URL:** <https://discuss.elastic.co/t/help-with-a-grok-filter-for-docker/103932>\
**Category:** Logstash\
**Created:** [October 13, 2017, 4:38pm UTC](https://discuss.elastic.co/t/help-with-a-grok-filter-for-docker/103932 "2017-10-13T16:38:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DannielWhatever](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dannielwhatever/32/23040_2.png) [@DannielWhatever](https://discuss.elastic.co/u/DannielWhatever)\
**Post date:** [October 13, 2017, 4:38pm UTC](https://discuss.elastic.co/t/help-with-a-grok-filter-for-docker/103932/1 "2017-10-13T16:38:49Z")

</div>

Hello guys,

I pretty noob in Elastic, and I trying to implement a filter, for the messages of a SpringBoot application running on docker, that is sending the logs to Logstash using the syslog driver.  
The messages seems like:

```
"message": "<30>Oct 13 13:29:51 container-name[10039]: 2017-10-13 16:29:51.551 INFO 1 --- [ost-startStop-1] o.s.b.w.servlet.FilterRegistrationBean : Mapping filter: 'requestContextFilter' to: [/*]"

```

The most important for me, is extracting the container-name to a new field.  
Im using the next pattern , bit is not working.

```
match => { "message" => "<%{NUMBER:whatever}>%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}" }

```

Thank u in advance 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 17, 2017, 5:34am UTC](https://discuss.elastic.co/t/help-with-a-grok-filter-for-docker/103932/2 "2017-10-17T05:34:07Z")

</div>

You're trying to use `SYSLOGHOST` to match `container-name[10039]:` but that won't work. You can use the grok constructor web site to find a better expression.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2017, 5:34am UTC](https://discuss.elastic.co/t/help-with-a-grok-filter-for-docker/103932/3 "2017-11-14T05:34:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
