Regarding Filebeat Modules and Docker Logs

We will be running filebeat in kubernetes where apps will be logging to stdout and filebeat will be scanning for container logs output by docker.

Does this mean that filebeat modules cannot be used?


Is this question unclear? I was hoping to have got a response by now.


They can be used, I would refer you to the doc, make sure to read the entire autodiscover section with both of its sub-section.

After that I don't think there is any secret sauce, this is highly dependent on your specifics. Spin up a test env and iterate on the configs to see if the modules can be used correctly in your context, etc.

Also, some relevant bookmark and elastic ON content.

I hope this helps,


This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.