# Parse rancher logs with logstash

**URL:** <https://discuss.elastic.co/t/parse-rancher-logs-with-logstash/207242>\
**Category:** Logstash\
**Created:** [November 10, 2019, 2:04pm UTC](https://discuss.elastic.co/t/parse-rancher-logs-with-logstash/207242 "2019-11-10T14:04:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tru64gurus](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@tru64gurus](https://discuss.elastic.co/u/tru64gurus)\
**Post date:** [November 10, 2019, 2:04pm UTC](https://discuss.elastic.co/t/parse-rancher-logs-with-logstash/207242/1 "2019-11-10T14:04:56Z")

</div>

Hi,

I have serveral k8s clusters running on rancher 2.3.1 sending several GB of logs per second and causing disk pressure on source side .

To solve source bottlneck , logs are being sent to syslog server and get written to text files, configure syslog program variable to be cluster name , so each cluster logs get written to separate files on syslog side .

I would like to use logstash on syslog server to parse logs and send them to elasticsearch 7.x . I can't get grok to capture k8s meta data like pod name , cluster name , deployment and any other relevant information which requires extraction of variable number of key/value pairs.. Also I would like to create separate index per cluster ( log file)

Any feed back on rancher logs parsing is appreciated

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2019, 2:04pm UTC](https://discuss.elastic.co/t/parse-rancher-logs-with-logstash/207242/2 "2019-12-08T14:04:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
