Docker image for Elastic Filebeat
500K+
This Docker image contains Elastic Filebeat, a lightweight, open source shipper for log file data. As the next-generation Logstash Forwarder, Filebeat tails logs and quickly sends this information to Logstash for further parsing and enrichment or to Elasticsearch for centralized storage and analysis.
The image is available on Docker Hub and can be pulled with:
docker pull olinicola/filebeat
The container can be executed with:
docker run -d olinicola/filebeat
This will simply run Filebeat using the default filebeat.yml configuration file that comes with the Linux 64-bit distribution.
The Filebeat container can be configured passing a custom filebeat.yml configuration file as a Docker volume:
docker run -d -v "/path/to/your/filebeat.yml:/etc/filebeat/filebeat.yml" olinicola/filebeat
Check the official Filebeat guide for more detailed info regarding the filebeat.yml available options.
Suppose you have an Nginx container named nginx that defines /var/log/nginx folder as a Docker volume. The Filebeat container can be instructed to fetch the log files from that volume with:
docker run -d --volumes-from nginx -v "/path/to/your/filebeat.yml:/etc/filebeat/filebeat.yml" olinicola/filebeat
The filebeat.yml configuration file can be something like this:
filebeat:
prospectors:
-
paths:
- "/var/log/nginx/access.log"
document_type: nginx-access
-
paths:
- "/var/log/nginx/error.log"
document_type: nginx-error
output:
logstash:
enabled: true
hosts: ["your-logstash-host:5000"]
index: logstash
Content type
Image
Digest
Size
59.4 MB
Last updated
over 10 years ago
docker pull olinicola/filebeat:1.2.3