# Ingest mixed container logs with text and JSON \[filebeat\]\[docker\]

**URL:** <https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-filebeat-docker/271139>\
**Category:** Logs\
**Created:** [April 24, 2021, 12:22pm UTC](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-filebeat-docker/271139 "2021-04-24T12:22:05Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![felixbarny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felixbarny/32/27341_2.png) [@felixbarny](https://discuss.elastic.co/u/felixbarny)\
**Post date:** [April 29, 2021, 6:48am UTC](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-filebeat-docker/271139/4 "2021-04-29T06:48:39Z")

</div>

You can either set up your conditions so that they match on a particular label or add multiple conditions to the same template for all of your apps: [Multiple conditions with autodiscover & docker containers - #2 by steffens](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634/2)

There's also a docker-based autodiscover so the k8s-style autodiscover example above would look like this for docker:

```yaml
filebeat.autodiscover:
  providers:
    - type: docker
      templates:
        - condition:
            contains:
              docker.container.labels: "log-format-json-and-text"
          config:
            - type: container
              paths:
                - /var/lib/docker/containers/${data.docker.container.id}/*.log
              include_lines: ['^{']
              json.keys_under_root: true
              json.overwrite_keys: true
              json.add_error_key: true
              json.expand_keys: true
        - condition:
            contains:
              docker.container.labels: "log-format-json-and-text"
          config:
            - type: container
              paths:
                - /var/lib/docker/containers/${data.docker.container.id}/*.log
              exclude_lines: ['^{']
              multiline.pattern: '^[[:blank:]]'
              multiline.negate: false
              multiline.match: after

```

See [Autodiscover | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html#_docker_2) for more info about autodiscover.

> [@bluepuma77](#):
>
> @felixbarny: **Feature request** : new config option `json.add_error_content: key`
> 
> If a line can not be JSON-parsed (error), then it is just added as text under `key` .

What's not working with `json.add_error_key: true`? Is the unparseable JSON under the wrong key or is it completely absent from the indexed document?

---

_[View the full topic](https://discuss.elastic.co/t/ingest-mixed-container-logs-with-text-and-json-filebeat-docker/271139)._
