# Add\_kubernetes\_metadata with elatsicsearch on kubernetes, elasticsearch-operator does not add k8s field in kibana

**URL:** <https://discuss.elastic.co/t/add-kubernetes-metadata-with-elatsicsearch-on-kubernetes-elasticsearch-operator-does-not-add-k8s-field-in-kibana/304646>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [May 13, 2022, 7:38am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-with-elatsicsearch-on-kubernetes-elasticsearch-operator-does-not-add-k8s-field-in-kibana/304646 "2022-05-13T07:38:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ryuseongryong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryuseongryong/32/98889_2.png) [@ryuseongryong](https://discuss.elastic.co/u/ryuseongryong)\
**Post date:** [May 13, 2022, 7:38am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-with-elatsicsearch-on-kubernetes-elasticsearch-operator-does-not-add-k8s-field-in-kibana/304646/1 "2022-05-13T07:38:05Z")

</div>

hi, I've got a problem with add\_kubernetes\_metadata setting in my filebeat.yaml

set-up with Elasticsearch-operator and Elasticsearch, metricbeat and filebeat, kibana as [elasticsearch.k8s.elastic.co/v1](http://elasticsearch.k8s.elastic.co/v1), [beat.k8s.elastic.co/v1beta1](http://beat.k8s.elastic.co/v1beta1), [kibana.k8s.elastic.co/v1](http://kibana.k8s.elastic.co/v1).

problem is finding kubernetes metadata in filebeat.

```auto
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: filebeat
spec:
  type: filebeat
  version: 8.2.0
  elasticsearchRef:
    name: elasticsearch
  kibanaRef:
    name: kibana
  config:
    filebeat.inputs:
      - type: container
        paths:
          - /var/log/containers/*.log
    processors:
      - add_kubernetes_metadata:
          default_matchers.enabled: false
          host: ${NODE_NAME}
          matchers:
            - logs_path:
                logs_path: /var/log/containers/
  daemonSet:
    podTemplate:
      spec:
        dnsPolicy: ClusterFirstWithHostNet
        hostNetwork: true
        securityContext:
          runAsUser: 0
        containers:
          - name: filebeat
            env:
              - name: NODE_NAME
                valueFrom:
                  fieldRef:
                    fieldPath: spec.nodeName
            volumeMounts:
              - name: varlogcontainers
                mountPath: /var/log/containers
              - name: varlogpods
                mountPath: /var/log/pods
              - name: varlibdockercontainers
                mountPath: /var/lib/docker/containers
        volumes:
          - name: varlogcontainers
            hostPath:
              path: /var/log/containers
          - name: varlogpods
            hostPath:
              path: /var/log/pods
          - name: varlibdockercontainers
            hostPath:
              path: /var/lib/docker/containers

```

but kibana still shows 17 original fields.  
how to fix it?

---

<div class="post-metadata">

**Author:** ![ryuseongryong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryuseongryong/32/98889_2.png) [@ryuseongryong](https://discuss.elastic.co/u/ryuseongryong)\
**Post date:** [May 18, 2022, 8:15am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-with-elatsicsearch-on-kubernetes-elasticsearch-operator-does-not-add-k8s-field-in-kibana/304646/2 "2022-05-18T08:15:56Z")

</div>

sloved! needs clusterRole and serviceAccount.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2022, 10:16am UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-with-elatsicsearch-on-kubernetes-elasticsearch-operator-does-not-add-k8s-field-in-kibana/304646/3 "2022-06-15T10:16:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
