# Ingest mixed container logs with text and JSON \[ECK\]\[filebeat\]

**URL:** <https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-eck-filebeat/289464>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 17, 2021, 2:45pm UTC](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-eck-filebeat/289464 "2021-11-17T14:45:30Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![matschaffer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matschaffer/32/95396_2.png) [@matschaffer](https://discuss.elastic.co/u/matschaffer)\
**Post date:** [November 18, 2021, 2:54am UTC](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-eck-filebeat/289464/3 "2021-11-18T02:54:06Z")

</div>

I found [Ingest mixed container logs with text and JSON [filebeat][docker] - #2 by felixbarny](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-filebeat-docker/271139/2) which has a config that might work in your case that's closer to what you were trying with include/exclude but at the autodiscover-level.

@felixbarny generally knows his stuff so maybe try that before my processor idea 🙂

---

_[View the full topic](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-eck-filebeat/289464)._
