# Multiple conditions with autodiscover & docker containers

**URL:** <https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 23, 2018, 3:01pm UTC](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634 "2018-10-23T15:01:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vieskees](https://avatars.discourse-cdn.com/v4/letter/v/74df32/32.png) [@vieskees](https://discuss.elastic.co/u/vieskees)\
**Post date:** [October 23, 2018, 3:01pm UTC](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634/1 "2018-10-23T15:01:24Z")

</div>

Hi!

I've just set up our ELK stack and I'm struggling with selecting the right containers for the autodiscover setting. I have a application consisting of around 20+ different containers. And around 10 of these containers have interesting logs I'd like to forward to Logstash.

This works;

```
   filebeat.autodiscover:
      providers:
      - type: docker
        templates:
        - condition:
            contains:
              docker.container.image: **SOMETHING**

```

But, unfortunately, 'SOMETHING' covers a lot of containers. And I wanted to exclude some Docker containers. For example exclude container with the name ' **SOMETHING** / **SOMETHING\_ELSE**'

I thought (and kinda hoped) this would work.

```
    filebeat.autodiscover:
       providers:
       - type: docker
         templates:
         - condition:
             contains:
               docker.container.image: **SOMETHING**
               and.not.contains:
                 docker.container.image: **SOMETHING_ELSE**

```

What is the correct syntax to exclude/include container images? Just being able to include more then 1 containername would be sufficient for now. Like;

```
   contains:
      docker.container.image: **A** , **B** , **C**

```

Fyi; this is my first post here, I tried to use the right markdown and such, but please do correct me if I missed something 🙂

Kind regards!

Filebeat version 6.4.1

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [October 24, 2018, 6:05pm UTC](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634/2 "2018-10-24T18:05:59Z")

</div>

conditions syntax is more 'lisp-style', due to the YAML config file format.

E.g. your condition with 'and.not' must look like:

```auto
- condition.and:
  - contains: 
      docker.container.image: **SOMETHING**
  - not.contains:
      docker.container.image: **SOMETHING_ELSE**

```

The `and` operator gets a list of conditionals that must match. It's similar to "ALL".

P.S.: Thank you for taking the time and properly formatting your question on your first try 😉

---

<div class="post-metadata">

**Author:** ![vieskees](https://avatars.discourse-cdn.com/v4/letter/v/74df32/32.png) [@vieskees](https://discuss.elastic.co/u/vieskees)\
**Post date:** [October 25, 2018, 8:09am UTC](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634/3 "2018-10-25T08:09:59Z")

</div>

Awesome, it works!

Thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2018, 8:10am UTC](https://discuss.elastic.co/t/multiple-conditions-with-autodiscover-docker-containers/153634/4 "2018-11-22T08:10:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
