# Can filebeat autodiscover collect logs from k8s emptydir volume?

**URL:** <https://discuss.elastic.co/t/can-filebeat-autodiscover-collect-logs-from-k8s-emptydir-volume/290071>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 24, 2021, 1:17pm UTC](https://discuss.elastic.co/t/can-filebeat-autodiscover-collect-logs-from-k8s-emptydir-volume/290071 "2021-11-24T13:17:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ydy](https://avatars.discourse-cdn.com/v4/letter/y/8baadc/32.png) [@ydy](https://discuss.elastic.co/u/ydy)\
**Post date:** [November 24, 2021, 1:17pm UTC](https://discuss.elastic.co/t/can-filebeat-autodiscover-collect-logs-from-k8s-emptydir-volume/290071/1 "2021-11-24T13:17:27Z")

</div>

Here is my filebeat config yaml, downloaded from [Run Filebeat on Kubernetes | Filebeat Reference [7.15] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/running-on-kubernetes.html)

I can't get log when the `templates.config.type` is `log` (yaml below), But when I set this to `container` I can get the filebeat output ( it's parsing my logs mounted from pod emptydir, reporting unable to parse nginx access log as json, which means it can retrive my nginx log ), but when I change type to `log`, nothing output.

```auto
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: filebeat-config
  namespace: kube-system
  labels:
    k8s-app: filebeat
data:
  filebeat.yml: |-
    # filebeat.inputs:
    # - type: container
    # paths:
    # - /var/log/containers/*.log
    # processors:
    # - add_kubernetes_metadata:
    # host: ${NODE_NAME}
    # matchers:
    # - logs_path:
    # logs_path: "/var/log/containers/"

    # To enable hints based autodiscover, remove `filebeat.inputs` configuration and uncomment this:
    filebeat.autodiscover:
     providers:
       - type: kubernetes
         hints.enabled: true
         hints.default_config.enabled: false
         templates:
         - config:
            - type: log 
              paths:
                - /var/lib/kubelet/pods/${data.kubernetes.pod.uid}/volumes/kubernetes.io~empty-dir/logs/*.log
                - /var/lib/kubelet/pods/${data.kubernetes.pod.uid}/volumes/kubernetes.io~empty-dir/logs/*.txt

    processors:
      - add_cloud_metadata:
      - add_host_metadata:

    cloud.id: ${ELASTIC_CLOUD_ID}
    cloud.auth: ${ELASTIC_CLOUD_AUTH}

    output.elasticsearch:
      hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
      username: ${ELASTICSEARCH_USERNAME}
      password: ${ELASTICSEARCH_PASSWORD}
---

```

I 've added annotation to my pod

```auto
annotations:
        co.elastic.logs/enabled: "true"
        co.elastic.logs/multiline.pattern: '^\['
        co.elastic.logs/multiline.negate: true
        co.elastic.logs/multiline.match: after
        co.elastic.logs.sidecar/exclude_lines: '^DBG'

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2021, 3:17pm UTC](https://discuss.elastic.co/t/can-filebeat-autodiscover-collect-logs-from-k8s-emptydir-volume/290071/2 "2021-12-22T15:17:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
