Guide
Filebeat Autodiscover with Docker: Minimal Architecture for Dynamic Log Shipping
A concise architecture note for Filebeat Autodiscover with Docker: requirements, minimal design, trust boundaries, operational checks, failure modes, and triggers for redesign.
Published by Tasadduq Burney
02 Sept 2026, 04:34 UTC
3 min23.3K views0

Requirements
To ship container logs dynamically you need:
- A host with Docker Engine running.
- Filebeat installed (non‑root user) with the
dockerinput enabled. - A reachable Logstash instance that accepts Beats input over TLS (mutual auth).
- Optional: Elasticsearch for storage and indexing.
Smallest Suitable Design
The minimal deployment consists of a single Filebeat process on the Docker host, the Docker input plugin, and a Logstash pipeline. No sidecar containers or extra agents are required.
Filebeat configuration (example)
filebeat.inputs:
- type: docker
containers.ids:
- '${data.docker.container.id}'
processors:
- add_docker_metadata:
host: "unix:///var/run/docker.sock"
match: ids
match_priority: "latest"
output.logstash:
hosts: [":5044"]
ssl.certificate_authorities: [""]
ssl.certificate: ""
ssl.key: ""
Place the file at /etc/filebeat/filebeat.yml and start Filebeat as a non‑root user that belongs to the docker group (or has ACL read access to /var/lib/docker/containers).
Logstash pipeline (example)
input {
beats {
port => 5044
ssl => true
ssl_certificate => ""
ssl_key => ""
}
}
filter {
# parse Docker JSON logs if needed
json {
source => "message"
target => "docker"
}
}
output {
elasticsearch {
hosts => [":9200"]
index => "filebeat-%{+YYYY.MM.dd}"
user => ""
password => ""
}
}
Trust and Data Boundaries
- Docker API trust: Filebeat talks to the Docker daemon via the Unix socket (
/var/run/docker.sock). The socket grants the same privileges as the Docker group; limit Filebeat’s group membership to only what is needed. - Log transport trust: Mutual TLS ensures Filebeat authenticates Logstash and vice‑versa. Certificates must be rotated in sync; a mismatch breaks the connection.
- Data boundary: Filebeat reads only the log files under
/var/lib/docker/containers. It does not access container images or runtime metadata beyond what the Docker API provides via labels.
Operational Checks
- Verify Filebeat health:
curl -s http://localhost:5066/health | jq .– look forstatus: "green"and non‑zeroevents.published. - Check Docker plugin discovery:
curl -s http://localhost:5066/state | jq .module.docker– should list discovered container IDs matching running containers. - Confirm Logstash pipeline status:
curl -s http://localhost:9600/_node/pipelines?pretty– ensurestate: "started"andevents.inmatches Filebeat output. - Inspect Elasticsearch index:
GET filebeat-*/_count– verify document count grows with log traffic.
Failure Modes
- Log rotation before read: If a container rotates its log file faster than Filebeat can harvest, lines may be lost. Mitigate by increasing
close_inactiveor usingignore_oldersettings. - Network partitions: TCP back‑pressure can fill Filebeat’s internal queue; monitor
queue.max_eventsvia the health endpoint. - Permission changes: Altering ACLs on
/var/lib/docker/containersremoves Filebeat’s read access, causing silent drops. Use immutable ACLs or run Filebeat as root only if unavoidable. - Docker API rate limits: Frequent container start/stop can exceed the daemon’s request quota, leading to missed discovery events. Watch Docker daemon metrics (
docker infoAPIRequests) and enabledocker.api.periodthrottling in Filebeat if needed.
When the Design Should Change
- If sustained log volume exceeds ~100 GB per day per host, the Filebeat‑to‑Logstash link may become a bottleneck; consider inserting a Kafka buffer or using Logstash‑only ingestion with persistent queues.
- When compliance requires encryption at rest for logs before they reach Elasticsearch, add an intermediate encrypted storage layer (e.g., encrypted S3 bucket) and adjust the pipeline accordingly.
- If you need to ship logs from multiple Docker hosts with differing security zones, deploy a dedicated Filebeat agent per zone and centralize Logstash behind a load balancer.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.