# How to configure Filebeat to recognize ECS data

**URL:** https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550
**Category:** Beats
**Tags:** ecs-elastic-common-schema, filebeat
**Created:** [June 10, 2020, 4:41pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550 "2020-06-10T16:41:13Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Noxis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noxis/32/70075_2.png) [@Noxis](https://discuss.elastic.co/u/Noxis)
#### Post date: [June 10, 2020, 4:41pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550/1 "2020-06-10T16:41:13Z")

</div>

Hello

I have an Kibana Elastic Filebeat docker stack and I want to monitor the logs of some NodeJS microservices (that run in docker too). I discovered yesterday [ecs-morgan-format](https://github.com/elastic/ecs-logging-js/blob/master/loggers/morgan/README.md) and it seems to work well with morgan.

I don't really know how to config my filebeat.yml to recognize the ECS format that are in the logs.

Actually I tried that :

```auto
  providers:
    # Disabling monitoring of containers that have a label "filebeat.disable" set to true
    - type: docker
      #hints.enabled: true
      templates:
        - condition.and:
            - not.contains:
                docker.container.labels.filebeat.disable: "true"
            #Disabling also frontend monitoring so we don't have the logs twice with the nginx module
            - not.contains:
                docker.container.name: frontend
            - not.contains:
                docker.container.name: traefik
          config:
            - type: docker
              containers.ids:
                - "${data.docker.container.id}"
              exclude_lines: ['^[[:space:]]*$']
              fields_under_root: true
          # processors:
          # - decode_json_fields:

```

And the logs I see in kibana are ECS in a 'message' field as it seems Filebeat isn't configured to analyze the ECS and send it to Elasticsearch.

Edit: Here is an example of what I see in Kibana/Elastic (the second entry is good, I enabled a second output)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/1/b/1bfc82d70a4c1ddc40804fd97715b57249bb3f0d.png)

Thanks for your help 🙂

---

<div class="post-metadata">

### Author: ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)
#### Post date: [June 11, 2020, 3:19pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550/2 "2020-06-11T15:19:38Z")

</div>

Hi @Noxis, welcome to the community!

Reviewing and testing with the `filebeat` configuration snippet you provided, I saw the same results. The `docker` input configuration will need to be updated for your node containers to support the JSON decoding of the log lines:

```auto
json.keys_under_root: true
json.overwrite_keys: true

```

---

<div class="post-metadata">

### Author: ![Noxis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/noxis/32/70075_2.png) [@Noxis](https://discuss.elastic.co/u/Noxis)
#### Post date: [June 11, 2020, 9:55pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550/3 "2020-06-11T21:55:47Z")

</div>

Thanks a lot for your answer. It's working now ! 🙂

Here is my final config in case someone needs some help in the future :

```auto
filebeat.autodiscover:
  providers:
    # Disabling monitoring of containers that have a label "filebeat.disable" set to true
    - type: docker
      #hints.enabled: true
      templates:
        - condition.and:
            - not.contains:
                docker.container.labels.filebeat.disable: "true"
            #Disabling also frontend monitoring so we don't have the logs twice with the nginx module
            - not.contains:
                docker.container.name: frontend
            - not.contains:
                docker.container.name: traefik
          config:
            - type: docker
              containers.ids:
                - "${data.docker.container.id}"
              exclude_lines: ['^[[:space:]]*$']
              fields_under_root: true
              json:
                keys_under_root: true
                message_key: message
                overwrite_keys: true

```

---

<div class="post-metadata">

### Author: ![Djiit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djiit/32/70077_2.png) [@Djiit](https://discuss.elastic.co/u/Djiit)
#### Post date: [June 12, 2020, 8:57am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550/4 "2020-06-12T08:57:44Z")

</div>

Just wanted to throw another round of thanks!

I think it should be clearer on the docs what annotations we need to put for services using ECS format.

Cheers

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 10, 2020, 10:57am UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-to-recognize-ecs-data/236550/5 "2020-07-10T10:57:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
