# Using ElasticSearch and Packetbeat to understand a Docker cluster

**URL:** <https://discuss.elastic.co/t/using-elasticsearch-and-packetbeat-to-understand-a-docker-cluster/57695>\
**Category:** Elastic Community and Ecosystem\
**Created:** [August 10, 2016, 11:38am UTC](https://discuss.elastic.co/t/using-elasticsearch-and-packetbeat-to-understand-a-docker-cluster/57695 "2016-08-10T11:38:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghoranyi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghoranyi/32/11309_2.png) [@ghoranyi](https://discuss.elastic.co/u/ghoranyi)\
**Post date:** [August 10, 2016, 11:38am UTC](https://discuss.elastic.co/t/using-elasticsearch-and-packetbeat-to-understand-a-docker-cluster/57695/1 "2016-08-10T11:38:46Z")

</div>

Hey all,

We are building a cool tool visualize what's happening in real-time on a Docker cluster based on the Intuition Engineering concept from Netflix. We are using Packetbeat to observe network traffic and ES aggregations to get the data to visualize. Any kind of feedback is appreciated.

> **[Intuition Engineering with Docker – Gergo Horanyi – Medium](https://medium.com/@ghoranyi/our-take-on-intuition-engineering-with-docker-6cd6740b1045)**
>
> This post presents a suggestion for a docker monitoring solution combining two awesome tools already at your disposal: Netflix Vizceral…

Cheers,  
Gergo

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 10, 2016, 9:13pm UTC](https://discuss.elastic.co/t/using-elasticsearch-and-packetbeat-to-understand-a-docker-cluster/57695/2 "2016-08-10T21:13:44Z")

</div>

Nice, thanks for sharing this!

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 11, 2016, 10:40am UTC](https://discuss.elastic.co/t/using-elasticsearch-and-packetbeat-to-understand-a-docker-cluster/57695/3 "2016-08-11T10:40:40Z")

</div>

That's pretty cool.

Talking about beats, it would be great to access application logs by selecting the services. Logs could be collected with filebeat for example.

There's some work in progress for running metricbeat inside of docker (and metricbeat to custom mounted /proc dir), plus adding support for cgroups: [https://github.com/elastic/beats/issues/2137](https://github.com/elastic/beats/issues/2137) . Some docker-module might be added to metricbeat too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/using-elasticsearch-and-packetbeat-to-understand-a-docker-cluster/57695/4 "2017-07-06T13:43:47Z")

</div>


