# Regarding Container Input

**URL:** <https://discuss.elastic.co/t/regarding-container-input/339707>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [July 31, 2023, 3:13pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707 "2023-07-31T15:13:43Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [July 31, 2023, 3:13pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707/1 "2023-07-31T15:13:43Z")

</div>

Hi,  
I see that `combine_partial` is not a parameter for the container input. Does the input now automatically handle docker's 16kb message limit?

Thx  
D

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 1, 2023, 7:33am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/2 "2023-08-01T07:33:53Z")

</div>

Is there anyone that can provide clarification on this?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 1, 2023, 8:28am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/3 "2023-08-01T08:28:48Z")

</div>

Hey @dawiro,

Yes, it seems this feature slipped during the refactors for the container and filestream inputs. Are you finding issues with this?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 1, 2023, 8:32am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/4 "2023-08-01T08:32:44Z")

</div>

I mean, the logic is there, and this behaviour is in theory maintained by default, but there doesn't seem to be any setting to disable it.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 1, 2023, 9:37am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/5 "2023-08-01T09:37:15Z")

</div>

We're making changes to our multiline config and devs are claiming that separate log events are being combined, ie. that the multiline config isn't working. My answer is that, unknown to them, they're emitting newlines which are getting merged instead of being split out as they had been before.

I'm asking this question as due diligence to assess if something else could be wrong. Note: a complicating factor for us is that we don't have access to the raw container logs.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 1, 2023, 9:38am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/6 "2023-08-01T09:38:08Z")

</div>

We do have fat messages that exceed the 16kb limit. So we do need the combine\_partial functionality.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 1, 2023, 9:45am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/7 "2023-08-01T09:45:06Z")

</div>

> [@dawiro](#):
>
> they're emitting newlines which are getting merged instead of being split out as they had been before.

Indeed if the messages contain new lines at the end they are likely going to be merged by the logic to combine partial lines.

How are you defining the multiline configuration? Maybe you can give a try to the [`filestream` input](https://www.elastic.co/guide/en/beats/filebeat/8.9/filebeat-input-filestream.html), that has container and multiline parsers and gives a bit more of control on when each one is executed.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707/8 "2023-08-01T14:02:40Z")

</div>

Atm, we''re using the container input with a separate multiline and json handling spec. If we use filestream will we still get docker/container metadata for log enrichment?

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 2, 2023, 9:58am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/9 "2023-08-02T09:58:00Z")

</div>

@jsoriano ⬆

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 2, 2023, 2:29pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707/10 "2023-08-02T14:29:59Z")

</div>

You can have enrichment if you use an autodiscover provider, or the `add_docker_metadata` processor.

How are you enriching now?

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 2, 2023, 2:54pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707/11 "2023-08-02T14:54:38Z")

</div>

We're using `add_docker_metadata`. If we were to switch to filestream what would we lose relative to the continer input? Also, I presume the filestream input won't handle logs chopped up by docker.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 2, 2023, 3:07pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707/12 "2023-08-02T15:07:10Z")

</div>

> [@dawiro](#):
>
> I presume the filestream input won't handle logs chopped up by docker.

Umm, not sure, I am afraid that it will do the same. If you could confirm that it neither work for your use case we can open an issue to recover this setting.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 3, 2023, 9:14am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/13 "2023-08-03T09:14:12Z")

</div>

Is the handling of the 16kb limit part of the container input or part of beats itself in a general sense?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [August 3, 2023, 10:19am UTC](https://discuss.elastic.co/t/regarding-container-input/339707/14 "2023-08-03T10:19:53Z")

</div>

The 16kb limit is part of Docker. The container input joins lines that end up with newline, independently of their size.

---

<div class="post-metadata">

**Author:** ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Post date:** [August 3, 2023, 1:06pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707/15 "2023-08-03T13:06:17Z")

</div>

So, the filestream input would not recombine messages chopped up by docker. That would create a different problem for us.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2023, 3:06pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707/16 "2023-08-31T15:06:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
