Docker logs
Docker Logs Source
The Docker Logs source collects stdout and stderr logs from containers managed by the Docker daemon. It continuously streams container logs and emits them as log events into the telemetry pipeline for further processing, filtering, and routing.
This source is commonly used in on-prem, self-managed, and containerized environments where Docker is the primary container runtime.
Alias and Compatibility
This source was previously named docker. Existing configurations must be updated to use the new source type name.
Failing to update the source type may result in configuration errors during startup.
Requirements
The Docker Logs source requires access to the Docker daemon.
The user running worker must:
- Have permission to access the Docker socket
- Be a member of the docker group (or equivalent)
Without sufficient permissions, the source will fail to initialize.
Self-Logging Prevention
When worker itself is deployed as a Docker container, the source automatically attempts to avoid collecting its own logs.
This is done by comparing the container hostname with container IDs. If a match is detected, that container is excluded from log collection.
If the container hostname is manually changed, this automatic exclusion may no longer work. In such cases, the worker container should be explicitly excluded using container filtering options.
Collection Model
The source connects to the Docker daemon and streams logs from running containers in real time.
Logs are:
- Collected without maintaining state
- Emitted immediately as they are received
- Delivered using best-effort semantics
Because acknowledgements are not supported, delivery guarantees depend on downstream pipeline components.
Docker Daemon Connection
docker_host (optional, string)
Defines the Docker daemon endpoint to connect to.
If not explicitly configured:
- The DOCKER_HOST environment variable is used
- If unset, the default local Docker socket is used
Using an HTTPS endpoint enables encrypted communication with the Docker daemon.
Container Filtering
include_containers (optional, [string])
Restricts log collection to a specific set of containers identified by container ID or name.
Prefix matching is applied, meaning partial names or IDs may match multiple containers.
exclude_containers (optional, [string])
Excludes specific containers from log collection based on container ID or name.
Exclusions always take precedence over inclusions. If a container matches both include and exclude rules, it is excluded.
Care should be taken when using prefix-based exclusions, as they cannot be overridden.
include_images (optional, [string])
Limits log collection to containers created from specific Docker images.
If not configured, logs from all images are collected.
include_labels (optional, [string])
Filters containers based on Docker object labels.
Only containers matching the specified label selectors are included in log collection.
Host Metadata
host_key (optional, string)
Overrides the field name used to attach the host name to each log event.
If not set, the globally configured log schema host key is used.
Partial Log Handling
auto_partial_merge (optional, bool)
Controls automatic merging of partial log events produced by Docker.
When enabled:
- Split log lines are merged before emission
When disabled:
- Partial log events are emitted as-is and explicitly marked
partial_event_marker_field (optional, string)
Defines the log field used to mark an event as partial when automatic merging is disabled.
This field allows downstream systems to identify incomplete log messages.
Multiline Log Aggregation
multiline (optional, object)
Enables aggregation of multiple log lines into a single logical event.
This is commonly required for:
- Stack traces
- Multiline error messages
- Structured application logs spanning multiple lines
Multiline aggregation is disabled by default.
Multiline Matching and Modes
Multiline behavior is controlled through pattern matching and aggregation modes, determining:
- When a new log message starts
- Which lines belong to the same event
- When buffered logs are flushed
Timeouts ensure that incomplete messages are eventually emitted even if no new lines arrive.
Retry Behavior
retry_backoff_secs (optional, uint)
Defines how long the source waits before retrying after encountering a connection or read error when communicating with the Docker daemon.
TLS Configuration
tls (optional, object)
Configures TLS settings when connecting to the Docker daemon over HTTPS.
If TLS settings are not explicitly provided, Docker’s standard certificate resolution mechanism is used via environment variables and default paths.
TLS configuration ensures secure communication when accessing remote Docker daemons.
Reliability Considerations
- Logs are delivered using best-effort semantics
- No acknowledgements are supported
- Temporary failures may result in log loss
- Reliability should be enforced at downstream sinks or storage layers
Common Deployment Scenarios
- Host-level daemon collecting logs from all containers
- Centralized log collection node with Docker socket access
- On-prem environments without Kubernetes
- Lightweight alternatives to Kubernetes-native logging