# Metricbeat in container - missing docker logs

**URL:** <https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 17, 2018, 9:08pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890 "2018-09-17T21:08:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ncasaux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ncasaux/32/46950_2.png) [@ncasaux](https://discuss.elastic.co/u/ncasaux)\
**Post date:** [September 17, 2018, 9:08pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/1 "2018-09-17T21:08:12Z")

</div>

Hello,

I followed the steps described in the documentation [https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-docker.html](https://www.elastic.co/guide/en/beats/metricbeat/current/running-on-docker.html) and it works great!

The only issue I have is that the command "docker logs " does not show any log. It seems that this appears because of the -system.hostfs=/hostfs parameter.

Is it a normal behaviour ? Sorry if it's an obvious topic...  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [September 18, 2018, 4:35pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/2 "2018-09-18T16:35:43Z")

</div>

Hi @ncasaux and welcome 🙂

I don't think this has any relationship with `-system.hostfs` parameter.  
`docker logs` only shows the logs printed to standard output/error, metricbeat logs to file by default, this is something that can be changed by [config](https://www.elastic.co/guide/en/beats/metricbeat/6.4/configuration-logging.html), but in your case you probably have enough with using the `-e` parameter (after `-system.hostfs=/hostfs`) that makes metricbeat to log to standard error ignoring other logging outputs.

---

<div class="post-metadata">

**Author:** ![ncasaux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ncasaux/32/46950_2.png) [@ncasaux](https://discuss.elastic.co/u/ncasaux)\
**Post date:** [September 18, 2018, 7:00pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/3 "2018-09-18T19:00:20Z")

</div>

Hi @jsoriano,

Thanks for your reply. Let me elaborate why I mentionned this parameter:

When I run :  
`docker run --mount type=bind,source=/proc,target=/hostfs/proc,readonly --mount type=bind,source=/sys/fs/cgroup,target=/hostfs/sys/fs/cgroup,readonly --mount type=bind,source=/,target=/hostfs,readonly --net=host docker.elastic.co/beats/metricbeat:6.4.0`  
I have the logs in the console.

When I run:  
`docker run --mount type=bind,source=/proc,target=/hostfs/proc,readonly --mount type=bind,source=/sys/fs/cgroup,target=/hostfs/sys/fs/cgroup,readonly --mount type=bind,source=/,target=/hostfs,readonly --net=host docker.elastic.co/beats/metricbeat:6.4.0 -system.hostfs=/hostfs`  
I do NOT have the logs in the console.

As you can see, the `system.hostfs=/hostfs` is the only difference in the command.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [September 19, 2018, 7:58am UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/4 "2018-09-19T07:58:50Z")

</div>

Oh, I see. The thing is that `-e` parameter is passed to metricbeat [by default](https://github.com/elastic/beats-docker/blob/c3fd96370e2e173f9d492838bf1a7df970a6ba0e/templates/Dockerfile.j2#L62). If you set other parameters they are used instead, so if you want to keep the logs this way you need to add `-e` too:

```auto
docker run \
  --mount type=bind,source=/proc,target=/hostfs/proc,readonly \
  --mount type=bind,source=/sys/fs/cgroup,target=/hostfs/sys/fs/cgroup,readonly \
  --mount type=bind,source=/,target=/hostfs,readonly --net=host \
  docker.elastic.co/beats/metricbeat:6.4.0 -e -system.hostfs=/hostfs

```

---

<div class="post-metadata">

**Author:** ![ncasaux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ncasaux/32/46950_2.png) [@ncasaux](https://discuss.elastic.co/u/ncasaux)\
**Post date:** [September 19, 2018, 4:28pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/5 "2018-09-19T16:28:04Z")

</div>

Thanks @jsoriano,I see what you mean.

Do you know how to combine `-e` and `-system.hostfs=/hostfs` in a compose file V3?  
I tried many combinations, with no success so far:

So far the `command` part looks like this, and the container starts successfully:  
`command:`  
`- "--system.hostfs=/hostfs"`

This does not work:  
`command:`  
`- "-e --system.hostfs=/hostfs"`

It says: `Error: unknown flag: --e --system.hostfs`

Any idea on what's wrong with this "command" field in my yml ?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [September 19, 2018, 4:49pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/6 "2018-09-19T16:49:32Z")

</div>

In compose, the command is a list of arguments, and each argument has to be declared as a different item, one per line, i.e:

```auto
command:
- '-e'
- '--system.hostfs=/hostfs'

```

Or:

```auto
command: ['-e', '--system.hostfs=/hostfs']

```

---

<div class="post-metadata">

**Author:** ![ncasaux](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ncasaux/32/46950_2.png) [@ncasaux](https://discuss.elastic.co/u/ncasaux)\
**Post date:** [September 20, 2018, 7:39pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/7 "2018-09-20T19:39:07Z")

</div>

Thanks a lot @jsoriano, it works as expected! 😀

I was doing... 🤦‍♂️

```auto
command:
- ['-e', '--system.hostfs=/hostfs']

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2018, 7:39pm UTC](https://discuss.elastic.co/t/metricbeat-in-container-missing-docker-logs/148890/8 "2018-10-18T19:39:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
