# Unable to send input log to Elastic search via filebeat docker installation

**URL:** <https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 21, 2020, 4:52pm UTC](https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973 "2020-06-21T16:52:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bhanu\_Praveen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhanu_praveen/32/60395_2.png) [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Post date:** [June 21, 2020, 4:52pm UTC](https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973/1 "2020-06-21T16:52:59Z")

</div>

Hello,

I have installed ELK in 3 different containers. All are working fine. Pulled docker image and Installed Filebeat in docker container with below command:

docker run -d   
--name=filebeat   
--user=root   
--volume="/opt/filebeat.docker.yml:/usr/share/filebeat/filebeat.yml:ro"   
--volume="/var/lib/docker/containers:/var/lib/docker/containers:ro"   
--volume="/var/run/docker.sock:/var/run/docker.sock:ro"   
[docker.elastic.co/beats/filebeat:7.7.1](http://docker.elastic.co/beats/filebeat:7.7.1) filebeat -e -strict.perms=false   
-E output.elasticsearch.hosts=["myhost:9200"]

My filebeat.docker.yml content as below:

filebeat.inputs:

- type: log  
enabled: true  
close\_inactive: 1m  
close\_removed: true  
clean\_inactive: 5h  
clean\_removed: true  
ignore\_older: 4h  
paths:
  - "/opt/test/\*.json"  
json.keys\_under\_root: true  
json.add\_error\_key: true  
fields:  
index: hc-work  
hc\_type: work

filebeat.config:  
modules:  
path: ${path.config}/modules.d/\*.yml  
reload.enabled: false

filebeat.autodiscover:  
providers:  
- type: docker  
hints.enabled: true

processors:

- add\_docker\_metadata: ~

output.elasticsearch:  
hosts: '{ELASTICSEARCH\_HOSTS:myhost:9200}' username: '{ELASTICSEARCH\_USERNAME:elasticsearch}'  
password: '${ELASTICSEARCH\_PASSWORD:password}'

Now not sure where to check the Filebeat output? Not able to send logs from input path. Kindly let me know is it correct way to do and what am i missing?

Thanks

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [June 23, 2020, 9:05am UTC](https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973/2 "2020-06-23T09:05:08Z")

</div>

Could you please format you post using code tags?

---

<div class="post-metadata">

**Author:** ![Bhanu\_Praveen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhanu_praveen/32/60395_2.png) [@Bhanu\_Praveen](https://discuss.elastic.co/u/Bhanu_Praveen)\
**Post date:** [June 30, 2020, 4:50pm UTC](https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973/3 "2020-06-30T16:50:37Z")

</div>

Thanks, I got this fixed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2020, 6:50pm UTC](https://discuss.elastic.co/t/unable-to-send-input-log-to-elastic-search-via-filebeat-docker-installation/237973/4 "2020-07-28T18:50:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
