# Autodiscover Kubernetes + annotations on pods not working as excepted

**URL:** <https://discuss.elastic.co/t/autodiscover-kubernetes-annotations-on-pods-not-working-as-excepted/199743>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 17, 2019, 1:32am UTC](https://discuss.elastic.co/t/autodiscover-kubernetes-annotations-on-pods-not-working-as-excepted/199743 "2019-09-17T01:32:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roman\_Kournjaev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roman_kournjaev/32/2552_2.png) [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Post date:** [September 17, 2019, 1:32am UTC](https://discuss.elastic.co/t/autodiscover-kubernetes-annotations-on-pods-not-working-as-excepted/199743/1 "2019-09-17T01:32:32Z")

</div>

I am trying to make filebeat work with the official elastic helm chart.  
I would like to parse only the pods that have the "logging" : "json\_log" annotation. As soon as i deploy pods that have that annotation for some reason i am getting all the events parsed , like the logs from filebeats. What exactly i am configuring wrong?

```
   filebeat.autodiscover:
  providers:
    - type: kubernetes
      in_cluster: true
      tags:
        - "kubernetes"
      templates:
        - condition:
            contains:
              kubernetes.annotations.logging: "json_log"
          config:
            - type: container
              json.keys_under_root: true
              json.add_error_key: true
              json.message_key: msg
              paths:
                - '/var/lib/docker/containers/*/*.log'

processors:
  - add_kubernetes_metadata:
      in_cluster: true

output.elasticsearch:
  hosts: ["http://xxxxx:9200"]
```

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [September 17, 2019, 8:08am UTC](https://discuss.elastic.co/t/autodiscover-kubernetes-annotations-on-pods-not-working-as-excepted/199743/2 "2019-09-17T08:08:02Z")

</div>

Hi @Roman_Kournjaev,

when the condition is met the configuration under that condition is triggered. That configuration is reading all logs from the folder, which includes all containers managed by docker.

Maybe using some available variable like `${data.kubernetes.container.id}` would fix it.

Here you can find some info and an explicit warning for that scenario: [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2019, 8:08am UTC](https://discuss.elastic.co/t/autodiscover-kubernetes-annotations-on-pods-not-working-as-excepted/199743/3 "2019-10-15T08:08:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
