# Parsing docker container logs

**URL:** <https://discuss.elastic.co/t/parsing-docker-container-logs/123184>\
**Category:** Logstash\
**Created:** [March 9, 2018, 4:22am UTC](https://discuss.elastic.co/t/parsing-docker-container-logs/123184 "2018-03-09T04:22:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![aysala](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@aysala](https://discuss.elastic.co/u/aysala)\
**Post date:** [March 9, 2018, 4:22am UTC](https://discuss.elastic.co/t/parsing-docker-container-logs/123184/1 "2018-03-09T04:22:17Z")

</div>

Hi @magnusbaeck ,

I'm using filebeat to ship my logs to Logstash and I need help with parsing docker container logs along with few other logs.

My Filebeat configuration:

```
       filebeat.prospectors:
        - input_type: log
          paths:
            - /var/log/mesos/*.log
            - /var/log/dcos/dcos.log
            - /var/lib/docker/containers/*/*.log
        tail_files: true
        #output.elasticsearch:
        # hosts: ["http://coordinator.elastic.l4lb.thisdcos.directory:9200"]
        output.logstash:
          hosts: logstash.marathon.mesos:5044
          timeout: 90
          bulk_max_size: 1024

```

My Logstash config:

```
input { 
 beats { port=> 5044 }
}

filter {
 grok {
  match => { 'message' => ['%{SYSLOGLINE}', '%{CISCO_REASON}:%{ISO8601_SECOND}'] }
 }
}

output {
 if '_grokparsefailure' in [tags] {
  elasticsearch {
   hosts => 'http://coordinator.elastic.l4lb.thisdcos.directory:9200'
   manage_template => false
   index => 'containers-%{+YYYY.MM.dd}'
  }
}
 else {
  elasticsearch {
   hosts => 'http://coordinator.elastic.l4lb.thisdcos.directory:9200'
   manage_template => false
   index => 'dcos-%{+YYYY.MM.dd}'
  }
 } 
}

```

By using the above configuration, I was expecting to parse the dcos and mesos logs with dcos-\* index and container logs with containers-\* index as it fails the grok pattern match. I have used the Online Grok debugger to find the patterns, but no luck in finding a unique pattern that parses only the container logs.

How do i define a pattern that is unique to container log such as below.

`{"log": - - [08/Mar/2018:21:39:27 +0000] \"GET / HTTP/1.1\" 200 612 \"-\" \"curl/7.29.0\" \"-\"\n","stream":"stdout","time":"2018-03-08T21:39:27.310958603Z"}`

Is there a way to parse the logs based on the source path ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2018, 4:22am UTC](https://discuss.elastic.co/t/parsing-docker-container-logs/123184/2 "2018-04-06T04:22:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
