# Parse docker logs with logstash

**URL:** <https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972>\
**Category:** Logstash\
**Created:** [July 13, 2017, 9:18am UTC](https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972 "2017-07-13T09:18:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DevOpsRoot](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@DevOpsRoot](https://discuss.elastic.co/u/DevOpsRoot)\
**Post date:** [July 13, 2017, 9:18am UTC](https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972/1 "2017-07-13T09:18:01Z")

</div>

Hello all,

I want to parse logs lines like this one :

**2017-07-12T12:50:37.944779015Z [2017-07-12T12:50:37,944][INFO][logstash.pipeline] Pipeline main started**

How can i do that ? with grok ? wich plug-in better match with my type of log ?

**_[DETAIL OF THE LOGSTASH.CONF FILE]_**\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*

input {  
syslog {  
port =\> "5000"  
type =\> "docker"  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
elasticsearch {  
hosts =\> "elasticsearch:9200"  
}  
}

* * *

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2017, 9:28am UTC](https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972/2 "2017-07-13T09:28:07Z")

</div>

I don't think there's a pre-cooked grok pattern for this kind of log. You may have to construct a custom one. The grok constructor web site can be quite helpful with that.

---

<div class="post-metadata">

**Author:** ![DevOpsRoot](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@DevOpsRoot](https://discuss.elastic.co/u/DevOpsRoot)\
**Post date:** [July 13, 2017, 9:33am UTC](https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972/3 "2017-07-13T09:33:40Z")

</div>

Thanks for your response !! I try with [http://grokconstructor.appspot.com](http://grokconstructor.appspot.com) !  
But grok plug-in accept regular expresion ? if not how can i use regular expression to parse the lines ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2017, 9:38am UTC](https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972/4 "2017-07-13T09:38:14Z")

</div>

Quoting [the docs](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html):

> Grok sits on top of regular expressions, so any regular expressions are valid in grok as well. The regular expression library is Oniguruma, and you can see the full supported regexp syntax on the Oniguruma site.

---

<div class="post-metadata">

**Author:** ![DevOpsRoot](https://avatars.discourse-cdn.com/v4/letter/d/ecccb3/32.png) [@DevOpsRoot](https://discuss.elastic.co/u/DevOpsRoot)\
**Post date:** [July 13, 2017, 9:43am UTC](https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972/5 "2017-07-13T09:43:58Z")

</div>

My bad ... Thanks for all

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 9:44am UTC](https://discuss.elastic.co/t/parse-docker-logs-with-logstash/92972/6 "2017-08-10T09:44:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
