# Help with Docker prospector and dissect processor on filebeat

**URL:** <https://discuss.elastic.co/t/help-with-docker-prospector-and-dissect-processor-on-filebeat/174569>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 29, 2019, 4:10pm UTC](https://discuss.elastic.co/t/help-with-docker-prospector-and-dissect-processor-on-filebeat/174569 "2019-03-29T16:10:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbgobie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbgobie/32/43112_2.png) [@bbgobie](https://discuss.elastic.co/u/bbgobie)\
**Post date:** [March 29, 2019, 4:10pm UTC](https://discuss.elastic.co/t/help-with-docker-prospector-and-dissect-processor-on-filebeat/174569/1 "2019-03-29T16:10:53Z")

</div>

Hi,  
I'm trying to use filebeat to parse my docker logs, and dissect them to send to Elasticsearch.

My filebeat.yml looks like this  
filebeat.prospectors:  
- type: docker  
document\_type: docker  
containers:  
ids: "\*"  
path: '/var/lib/docker/containers'  
combine\_partial: true  
processors:  
- add\_cloud\_metadata: ~  
- add\_docker\_metadata: ~  
- dissect:  
field: log  
tokenizer: "[%{log\_stream}] [%{log\_level}] [%{log\_thread}] [%{@timestamp}] - "%{log\_message}"\n"

A sample log line from my docker logs looks like this  
{"@timestamp":"2019-03-29T16:01:19.316Z","@metadata":{"beat":"filebeat","type":"doc","version":"6.6.2"},"offset":409357,"log":{"file":{"path":"/var/lib/docker/containers/d2ada679e60d1f88be90689eaf8be3aaf062dd76b42fc8af951b9b5c52a9b7b6/d2ada679e60d1f88be90689eaf8be3aaf062dd76b42fc8af951b9b5c52a9b7b6-json.log"}},"stream":"stdout","prospector":{"type":"docker"},"input":{"type":"docker"},"meta":{"cloud":{"region":"us-east-1","availability\_zone":"us-east-1c","instance\_id":"i-0ddd0540e506d573e","machine\_type":"t3.large","provider":"ec2"}},"message":"[logger1] [ERROR] [tomcat-http--48] [29/03/2019 12:01:19,315] - " (writeError) [some\_data]Some 'error message. [somepackage/someclass(someObject.java:1354)]","source":"/var/lib/docker/containers/d2ada679e60d1f88be90689eaf8be3aaf062dd76b42fc8af951b9b5c52a9b7b6/d2ada679e60d1f88be90689eaf8be3aaf062dd76b42fc8af951b9b5c52a9b7b6-json.log","docker":{"container":{"id":"d2ada679e60d1f88be90689eaf8be3aaf062dd76b42fc8af951b9b5c52a9b7b6","labels":{"com":{"docker":{"compose":{"project":"master","service":"web","version":"1.22.0","config-hash":"f02330e2e031990958d061bd36dbc1e1b5f59ca5f356bfb76e4134010e277f96","container-number":"1","oneoff":"False"}}},"PROJECT":"web","PROJECT\_NAME":"Web"},"image":"some-repo/web:master","name":"master\_web\_1"}},"beat":{"name":"filebeat","hostname":"filebeat","version":"6.6.2"},"host":{"name":"filebeat"}}

Nothing seems broken out, I would've thought I would've had some keys created in the JSON output to match the keys from dissect? Instead I get standard message key with everything in it.

Any help would be appricated. Thanks

---

<div class="post-metadata">

**Author:** ![bbgobie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbgobie/32/43112_2.png) [@bbgobie](https://discuss.elastic.co/u/bbgobie)\
**Post date:** [March 29, 2019, 7:02pm UTC](https://discuss.elastic.co/t/help-with-docker-prospector-and-dissect-processor-on-filebeat/174569/2 "2019-03-29T19:02:08Z")

</div>

Really sorry, got this working, with a simplier tokenizer string.  
So the one listed here must be off.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2019, 7:02pm UTC](https://discuss.elastic.co/t/help-with-docker-prospector-and-dissect-processor-on-filebeat/174569/3 "2019-04-26T19:02:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
