Posting the second two in a new reply because of char limit:
nginx error, parsed as access
{
"_index" : "filebeat-7.2.0-2019.08.02-000001",
"_type" : "_doc",
"_id" : "IHZiYWwBZ0VBttQVDUmj",
"_version" : 1,
"_seq_no" : 11347862,
"_primary_term" : 1,
"found" : true,
"_source" : {
"container" : {
"image" : {
"name" : "nginx"
},
"name" : "xxx_nginx_1",
"id" : "38e4520147bb1a9fe4be6891e4232adafd239cd092394fcc764b422b709db19a"
},
"agent" : {
"hostname" : "e1d921b6cf0c",
"id" : "025bd4ea-a9ef-4fd2-a68a-546877603ea7",
"type" : "filebeat",
"ephemeral_id" : "acaa2421-fa0b-4873-b231-6c94bbeddf31",
"version" : "7.2.0"
},
"log" : {
"file" : {
"path" : "/var/lib/docker/containers/38e4520147bb1a9fe4be6891e4232adafd239cd092394fcc764b422b709db19a/38e4520147bb1a9fe4be6891e4232adafd239cd092394fcc764b422b709db19a-json.log"
},
"offset" : 699649
},
"message" : """2019/08/05 10:45:06 [error] 6#6: *2182 open() "/srv/http/blog.xxx.de/robots.txt" failed (2: No such file or directory), client: 172.29.0.13, server: blog.martinwagner.co, request: "GET /robots.txt HTTP/1.1", host: "blog.martinwagner.co"""",
"fileset" : {
"name" : "access"
},
"error" : {
"message" : """Provided Grok expressions do not match field value: [2019/08/05 10:45:06 [error] 6#6: *2182 open() \"/srv/http/blog.xxx.de/robots.txt\" failed (2: No such file or directory), client: 172.29.0.13, server: blog.martinwagner.co, request: \"GET /robots.txt HTTP/1.1\", host: \"blog.martinwagner.co\"]"""
},
"docker" : {
"container" : {
"labels" : {
"co_elastic_logs/module" : "nginx",
"co_elastic_logs/fileset_stdout" : "access",
"com_docker_compose_config-hash" : "60b056dcd4f08eccbf94cf0c73f6b1f1439a3306d46a4c63f29bfee82f88a539",
"com_docker_compose_oneoff" : "False",
"com_docker_compose_project" : "xxx",
"co_elastic_logs/fileset_stderr" : "error",
"com_docker_compose_service" : "nginx",
"com_docker_compose_container-number" : "1",
"com_docker_compose_version" : "1.24.1",
"maintainer" : "NGINX Docker Maintainers <docker-maint@nginx.com>"
}
}
},
"input" : {
"type" : "container"
},
"@timestamp" : "2019-08-05T10:45:06.877Z",
"ecs" : {
"version" : "1.0.0"
},
"stream" : "stderr",
"service" : {
"type" : "nginx"
},
"host" : {
"name" : "e1d921b6cf0c"
},
"event" : {
"module" : "nginx",
"dataset" : "nginx.access"
}
}
}
nginx error, parsed as error
{
"_index" : "filebeat-7.2.0-2019.08.02-000001",
"_type" : "_doc",
"_id" : "F3ZiYWwBZ0VBttQVCEku",
"_version" : 1,
"_seq_no" : 11347854,
"_primary_term" : 1,
"found" : true,
"_source" : {
"container" : {
"image" : {
"name" : "nginx"
},
"name" : "xxx_nginx_1",
"id" : "38e4520147bb1a9fe4be6891e4232adafd239cd092394fcc764b422b709db19a"
},
"agent" : {
"hostname" : "e1d921b6cf0c",
"id" : "025bd4ea-a9ef-4fd2-a68a-546877603ea7",
"type" : "filebeat",
"ephemeral_id" : "acaa2421-fa0b-4873-b231-6c94bbeddf31",
"version" : "7.2.0"
},
"process" : {
"pid" : 6,
"thread" : {
"id" : 6
}
},
"nginx" : {
"error" : {
"connection_id" : 2182
}
},
"log" : {
"file" : {
"path" : "/var/lib/docker/containers/38e4520147bb1a9fe4be6891e4232adafd239cd092394fcc764b422b709db19a/38e4520147bb1a9fe4be6891e4232adafd239cd092394fcc764b422b709db19a-json.log"
},
"offset" : 699649,
"level" : "error"
},
"message" : """open() "/srv/http/blog.xxx.de/robots.txt" failed (2: No such file or directory), client: 172.29.0.13, server: blog.xxx.co, request: "GET /robots.txt HTTP/1.1", host: "blog.xxx.co"""",
"fileset" : {
"name" : "error"
},
"docker" : {
"container" : {
"labels" : {
"co_elastic_logs/module" : "nginx",
"com_docker_compose_config-hash" : "60b056dcd4f08eccbf94cf0c73f6b1f1439a3306d46a4c63f29bfee82f88a539",
"co_elastic_logs/fileset_stdout" : "access",
"com_docker_compose_oneoff" : "False",
"com_docker_compose_project" : "xxx",
"com_docker_compose_service" : "nginx",
"co_elastic_logs/fileset_stderr" : "error",
"com_docker_compose_container-number" : "1",
"com_docker_compose_version" : "1.24.1",
"maintainer" : "NGINX Docker Maintainers <docker-maint@nginx.com>"
}
}
},
"input" : {
"type" : "container"
},
"@timestamp" : "2019-08-05T10:45:06.000Z",
"ecs" : {
"version" : "1.0.0"
},
"stream" : "stderr",
"service" : {
"type" : "nginx"
},
"host" : {
"name" : "e1d921b6cf0c"
},
"event" : {
"created" : "2019-08-05T10:45:06.877Z",
"module" : "nginx",
"dataset" : "nginx.error"
}
}
}