# Logstash with docker logs and tags

**URL:** <https://discuss.elastic.co/t/logstash-with-docker-logs-and-tags/294278>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [January 13, 2022, 1:33pm UTC](https://discuss.elastic.co/t/logstash-with-docker-logs-and-tags/294278 "2022-01-13T13:33:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Spyros\_Agriopoulos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spyros_agriopoulos/32/99497_2.png) [@Spyros\_Agriopoulos](https://discuss.elastic.co/u/Spyros_Agriopoulos)\
**Post date:** [January 13, 2022, 1:33pm UTC](https://discuss.elastic.co/t/logstash-with-docker-logs-and-tags/294278/1 "2022-01-13T13:33:57Z")

</div>

Hello, I am trying to send a docker log from one machine with filebeat and add a tag to it, and when it reaches logstash it should mutate it and the give it an ilm\_rollover\_alias. The log appears in kibana, but with the original name instead of the mutated ilm\_rollover\_alias. It has worked for all the other logs that I have sent, but none of them is a docker log, so I'm guessing I am missing something

logstash.conf

```auto
input {
    beats {
        port => "5044"
    }
}

filter {
  if [tag] == "logs-docker"{
        mutate{
        add_tag=> ["logs-docker"]
                }
        }
}

output {

if "logs-docker" in [tags]{
    elasticsearch {
        hosts => ["https://localhost:9200"]
        user => "username"
        password => "pass"
        ssl => true
        cacert => "/home/ubuntu/elk/ca/ca.crt"
        ilm_rollover_alias => "logs-docker"
        ilm_pattern => "000001"
        ilm_policy => "logstash-policy"
        }
    }

}

```

filebeat.yml

```auto
# ============================== Filebeat modules ==============================

filebeat.config.modules:
  # Glob pattern for configuration loading
  path: ${path.config}/modules.d/*.yml

  # Set to true to enable config reloading
  reload.enabled: false

  # Period on which files under path should be checked for changes
  #reload.period: 10s

filebeat.inputs:
- type: docker
  combine_partial: true
  containers:
    ids:
      - "*"
  tags: ["logs-docker"]
  exclude_files: ['\.gz$']
  ignore_older: 3000m

processors:
  # decode the log field (sub JSON document) if JSON encoded, then maps it's fields to elasticsearch fields
  #- decode_json_fields:
  # fields: ["log", "message"]
  # target: ""
    # overwrite existing target elasticsearch fields while decoding json fields    
    # overwrite_keys: true
- add_docker_metadata:
    host: "unix:///var/run/docker.sock"

output.logstash:
        hosts: ["my_ip:5044"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2022, 1:34pm UTC](https://discuss.elastic.co/t/logstash-with-docker-logs-and-tags/294278/2 "2022-02-10T13:34:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
