# Logstash parse docker container log

**URL:** <https://discuss.elastic.co/t/logstash-parse-docker-container-log/168816>\
**Category:** Logstash\
**Created:** [February 18, 2019, 11:30am UTC](https://discuss.elastic.co/t/logstash-parse-docker-container-log/168816 "2019-02-18T11:30:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![messi655](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/messi655/32/47596_2.png) [@messi655](https://discuss.elastic.co/u/messi655)\
**Post date:** [February 18, 2019, 11:30am UTC](https://discuss.elastic.co/t/logstash-parse-docker-container-log/168816/1 "2019-02-18T11:30:47Z")

</div>

Hi,

Our API is running by container and the log of our API inside container have format like this:

> {"log":"{"fields.time":"2019-02-16T02:53:00.606890428Z","ip":"xx.xxx.xxx.xxx","latency":303805427,"level":"info","method":"POST","msg":"","path":"/v1/contacts","status":200,"time":"2019-02-16T02:53:00Z","user-agent":"okhttp/3.11.0"}\n","stream":"stderr","time":"2019-02-16T02:53:00.607869346Z"}

I used filebeat to send these log to our logstash to parse to separate fields like: logtime = fields.time , ip, latency, status, .... (all of nested in log object)

here is my filebeat config:

> - type: log  
> paths:  
> # Docker  
> - /var/lib/docker/containers/_/_-json.log  
> json.message\_key: log  
> json.keys\_under\_root: true  
> fields:  
> log\_type: "docker"

Here is my logstash

input {  
beats {  
port =\> 5044  
}  
}

filter {

```
if [fields][log_type] == "docker" {
    grok {
        match => { "message" => "%{GREEDYDATA}" }
        add_field => ["received_at", "%{@timestamp}"]
        add_field => ["received_from", "%{host}"]
    }

 mutate {
    add_field => {"logtime" => "%{[log][fields.time]}"}
    add_field => {"logtime" => "%{[log][ip]}"}
 }
}

```

}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
hosts =\> ["es\_host:9200"]  
manage\_template =\> false  
index =\> "test-%{+YYYY.MM.dd}"  
}  
}

But I did not work as I expect.  
I want from Kibana I can see separate fields: logtime, ip, status,...

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 18, 2019, 1:16pm UTC](https://discuss.elastic.co/t/logstash-parse-docker-container-log/168816/2 "2019-02-18T13:16:38Z")

</div>

The grok filter does not make any sense. It tries to match message to GREEDYDATA, which will always match, but does not extract any fields.

If the input is json then you should use a json filter to parse it.

```
json { source => "message" }

```

This will cause logtime to be an array with those two entries. Probably not what you want.

```
add_field => {"logtime" => "%{[log][fields.time]}"}
add_field => {"logtime" => "%{[log][ip]}"}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2019, 1:16pm UTC](https://discuss.elastic.co/t/logstash-parse-docker-container-log/168816/3 "2019-03-18T13:16:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
