# How do I send logs to elastic search which is set up on a VM , from a docker filebeat

**URL:** <https://discuss.elastic.co/t/how-do-i-send-logs-to-elastic-search-which-is-set-up-on-a-vm-from-a-docker-filebeat/147722>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 7, 2018, 1:34pm UTC](https://discuss.elastic.co/t/how-do-i-send-logs-to-elastic-search-which-is-set-up-on-a-vm-from-a-docker-filebeat/147722 "2018-09-07T13:34:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohit84](https://avatars.discourse-cdn.com/v4/letter/r/439d5e/32.png) [@rohit84](https://discuss.elastic.co/u/rohit84)\
**Post date:** [September 7, 2018, 1:34pm UTC](https://discuss.elastic.co/t/how-do-i-send-logs-to-elastic-search-which-is-set-up-on-a-vm-from-a-docker-filebeat/147722/1 "2018-09-07T13:34:43Z")

</div>

Thhis is my filebeat.yml -

_output:_  
_elasticsearch:_  
_enabled: true_  
_hosts:_  
_- http://\<my\_external\_host\_having\_elasticsearch\_instance\>:9200_

_# ssl_  
_# certificate\_authorities:_  
\_ # - /etc/pki/tls/certs/logstash-beats.crt\_  
_timeout: 15_

_filebeat:_  
_prospectors:_  
_-_  
_paths:_  
_- /var/log/vmware-vmsvc.log_  
_- /var/log/auth.log_  
_document\_type: syslog_  
_-_  
_paths:_  
_- "/var/log/nginx/\*.log"_  
_document\_type: nginx-access_

---

<div class="post-metadata">

**Author:** ![shazChaudhry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shazchaudhry/32/25027_2.png) [@shazChaudhry](https://discuss.elastic.co/u/shazChaudhry)\
**Post date:** [September 9, 2018, 1:31pm UTC](https://discuss.elastic.co/t/how-do-i-send-logs-to-elastic-search-which-is-set-up-on-a-vm-from-a-docker-filebeat/147722/2 "2018-09-09T13:31:08Z")

</div>

For a starter, it will be dependant on the version of Elastic Stack you are using. For example, looking at your config file, in the latest version of Elastic Stack "prospectors" are deprecated in favor of "inputs". Secondly, under "output", you will need to provide Eleasticsearch username & password.

Here are a few suggestions:

1. In non-swarm mode, here is an example on how to run Filebeat docker container: [https://www.elastic.co/guide/en/beats/filebeat/current/running-on-docker.html](https://www.elastic.co/guide/en/beats/filebeat/current/running-on-docker.html)
2. Ensure you bind mount volumes _(locations of logs that are to be shipped to Elasticsearch)_ as part of your docker run command
3. You will need to look at the config reference file at [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-reference-yml.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-reference-yml.html) and configure filebeat as per your scenario

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2018, 1:37pm UTC](https://discuss.elastic.co/t/how-do-i-send-logs-to-elastic-search-which-is-set-up-on-a-vm-from-a-docker-filebeat/147722/3 "2018-10-07T13:37:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
