# Trouble running metricbeat:5.3.0 with docker module

**URL:** <https://discuss.elastic.co/t/trouble-running-metricbeat-5-3-0-with-docker-module/82204>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [April 12, 2017, 5:23pm UTC](https://discuss.elastic.co/t/trouble-running-metricbeat-5-3-0-with-docker-module/82204 "2017-04-12T17:23:40Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![jarpy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jarpy/32/51290_2.png) [@jarpy](https://discuss.elastic.co/u/jarpy)\
**Post date:** [April 24, 2017, 2:48am UTC](https://discuss.elastic.co/t/trouble-running-metricbeat-5-3-0-with-docker-module/82204/7 "2017-04-24T02:48:04Z")

</div>

> [@andrewkroh](#):
>
> Another option would be to customize the container by adding the beats user that metricbeat runs as to the docker group. But I'm guessing this isn't portable since the docker GID could differ across hosts.

This is probably the best option without running Metricbeat as root, but you're absolutely right about the GID. On my system, the docker group is GID 999, so I can create a custom image with:

```auto
FROM docker.elastic.co/beats/metricbeat:5.3.1
USER root
RUN addgroup docker --gid 999 && \
    usermod --append --group docker metricbeat
USER metricbeat

```

That magic number is a problem, though.

I also tried making the Docker socket world-readable, but that wasn't sufficient. I think that the library used by Metricbeat to do HTTP over Unix sockets is trying to open the socket read/write, even though you would expect read-only to be sufficient for Metricbeat's purposes.

---

_[View the full topic](https://discuss.elastic.co/t/trouble-running-metricbeat-5-3-0-with-docker-module/82204)._
