# Mixed document types: json and plain text

**URL:** <https://discuss.elastic.co/t/mixed-document-types-json-and-plain-text/143536>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 8, 2018, 2:18pm UTC](https://discuss.elastic.co/t/mixed-document-types-json-and-plain-text/143536 "2018-08-08T14:18:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mimmus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mimmus/32/34273_2.png) [@mimmus](https://discuss.elastic.co/u/mimmus)\
**Post date:** [August 8, 2018, 2:18pm UTC](https://discuss.elastic.co/t/mixed-document-types-json-and-plain-text/143536/1 "2018-08-08T14:18:07Z")

</div>

We are migrating all of our applications to use the JSON encoded format, but until then we have some log files in json and some with normal logs.  
We cannot differentiate them using different paths because all of them are Docker containers logging under:  
`/var/lib/docker/containers/*/*.log`

Is there a solution to parse them or do we need to use two different Filebeat instances?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [August 8, 2018, 2:36pm UTC](https://discuss.elastic.co/t/mixed-document-types-json-and-plain-text/143536/2 "2018-08-08T14:36:05Z")

</div>

> [@mimmus](#):
>
> We are migrating all of our applications to use the JSON encoded format, but until then we have some log files in json and some with normal logs.  
> We cannot differentiate them using different paths because all of them are Docker containers logging under:  
> `/var/lib/docker/containers/*/*.log`

@mimmus You cannot differentiate by filename either?

I am not sure if the following would work, I haven't tried it, but maybe you could use the [decode\_json\_field](https://www.elastic.co/guide/en/beats/filebeat/current/decode-json-fields.html) on the `message` field and a [when conditionals](https://www.elastic.co/guide/en/beats/filebeat/5.3/configuration-processors.html#condition-regexp) to match the begining `{` of a JSON document. I am not sure that will work in all the cases because Docker can split JSON lines.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2018, 2:36pm UTC](https://discuss.elastic.co/t/mixed-document-types-json-and-plain-text/143536/3 "2018-09-05T14:36:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
