# How to extract trivy logs from a docker container?

**URL:** <https://discuss.elastic.co/t/how-to-extract-trivy-logs-from-a-docker-container/368145>\
**Category:** Elastic Observability\
**Tags:** docker\
**Created:** [October 2, 2024, 7:30pm UTC](https://discuss.elastic.co/t/how-to-extract-trivy-logs-from-a-docker-container/368145 "2024-10-02T19:30:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![SamuelSMendes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuelsmendes/32/104246_2.png) [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Post date:** [October 2, 2024, 7:30pm UTC](https://discuss.elastic.co/t/how-to-extract-trivy-logs-from-a-docker-container/368145/1 "2024-10-02T19:30:08Z")

</div>

Basically, I have a docker container which contains a few services that I check on the vulnerabilities ocasionally using the program trivy. The result comes in many ways, json included.

I thought of using Logstash to approach the output and sending over to Elasticsearch. But so far I haven't grasp yet on how I would make it work. Does Logstash has something like that?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 2, 2024, 10:11pm UTC](https://discuss.elastic.co/t/how-to-extract-trivy-logs-from-a-docker-container/368145/2 "2024-10-02T22:11:49Z")

</div>

Hi @SamuelSMendes  
How about Filebeat with container input

> **[Container input | Filebeat Reference \[8.15\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/8.15/filebeat-input-container.html)**
