# Using AutoDiscover feature for Docker does not work when running in Swarm mode

**URL:** <https://discuss.elastic.co/t/using-autodiscover-feature-for-docker-does-not-work-when-running-in-swarm-mode/120342>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 18, 2018, 10:14am UTC](https://discuss.elastic.co/t/using-autodiscover-feature-for-docker-does-not-work-when-running-in-swarm-mode/120342 "2018-02-18T10:14:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![darkl0rd](https://avatars.discourse-cdn.com/v4/letter/d/e9a140/32.png) [@darkl0rd](https://discuss.elastic.co/u/darkl0rd)\
**Post date:** [February 18, 2018, 10:14am UTC](https://discuss.elastic.co/t/using-autodiscover-feature-for-docker-does-not-work-when-running-in-swarm-mode/120342/1 "2018-02-18T10:14:43Z")

</div>

Running Docker Swarm 18.02 CE + Filebeat 6.2.1.

Filebeat is configured to perform auto-discovery of Docker containers, and ship its logs to logstash. On the logstash side of things however, I see the follow messages for all docker logs:

... "reason"=\>"mapper [docker.container.labels.com.docker.swarm.task] of different type, current\_type [keyword], merged\_type [ObjectMapper]" ...

Looking at the mappings in ElasticSearch:

"docker": {  
"properties": {  
"container": {  
"properties": {  
"name": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"labels": {  
"type": "object"  
},  
"image": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"id": {  
"ignore\_above": 1024,  
"type": "keyword"  
}  
..  
..  
{  
"docker.container.labels": {  
"mapping": {  
"type": "keyword"  
},  
"match\_mapping\_type": "string",  
"path\_match": "docker.container.labels.\*"  
}  
},

docker swarm labels are in the form of:

"com.docker.swarm.service.name": "my\_service\_name"

Is this a bug in the provided filebeat mapping?

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [February 19, 2018, 2:48pm UTC](https://discuss.elastic.co/t/using-autodiscover-feature-for-docker-does-not-work-when-running-in-swarm-mode/120342/2 "2018-02-19T14:48:27Z")

</div>

Hi @darkl0rd,

Thank you for testing Filebeat and providing feedback!

It seems mapping failed due to some of your labels, `com.docker.swarm.task` is currently holding an object, and a single keyword is being indexed (and failing). From what I see you probably have a set of lables like this:

```auto
  "com.docker.swarm.task": "",
  "com.docker.swarm.task.id": "xxxxx",
  "com.docker.swarm.task.name": "xxxxx"

```

This is an issue we have recently fixed (yet to be released), and it's related to the dots in label names and how Elasticsearch stores them.

Something you could do as of today is ignoring the `com.docker.swarm.task` field from Filebeat side, to avoid mapping errors. You can do that by using the drop\_field processor:

```auto
processors:
- drop_fields:
  fields:
    - `docker.container.labels.com.docker.swarm.task`

```

---

<div class="post-metadata">

**Author:** ![darkl0rd](https://avatars.discourse-cdn.com/v4/letter/d/e9a140/32.png) [@darkl0rd](https://discuss.elastic.co/u/darkl0rd)\
**Post date:** [February 19, 2018, 5:52pm UTC](https://discuss.elastic.co/t/using-autodiscover-feature-for-docker-does-not-work-when-running-in-swarm-mode/120342/3 "2018-02-19T17:52:13Z")

</div>

Hi @exekias,

Correct, on the labels; these are the labels as they are added by Docker Swarm.  
Good to hear that this was recently fixed, for the record though - this issue can be reproduced on a single swarm node/single filebeat instance. The value of the label 'com.docker.swarm.task' always triggers this errors.

I have implemented your suggested workaround; which as expected resolves the issue.  
Minor note for others who might read this, it should be:

```auto
processors:
  - drop_fields:
      fields:
        - "docker.containers.labels"

```

(fields should be indented from drop\_fields).

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2018, 5:52pm UTC](https://discuss.elastic.co/t/using-autodiscover-feature-for-docker-does-not-work-when-running-in-swarm-mode/120342/4 "2018-03-19T17:52:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
