# Can filebeat exclude a specific container name from hints-based autodiscover?

**URL:** <https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 6, 2020, 8:25pm UTC](https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577 "2020-11-06T20:25:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [November 6, 2020, 8:25pm UTC](https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577/1 "2020-11-06T20:25:18Z")

</div>

In a hints-based autodiscover configuration, can filebeat exclude all instances of a specific container name from discovery, even if `co.elastic.logs/enabled: 'true'` is set for the pod?

My use case is that I have a `filebeat.autodiscover` provider, which specifically monitors all `istio-proxy` containers and sends their logs to a specific index, so I want to globally exclude them from hints-based autodiscover. It would be easiest if I could do this within the filebeat config, rather than setting it at the pod or namespace level.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [November 9, 2020, 8:21am UTC](https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577/2 "2020-11-09T08:21:26Z")

</div>

Did you look into template conditions?

---

<div class="post-metadata">

**Author:** ![DougR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dougr/32/48095_2.png) [@DougR](https://discuss.elastic.co/u/DougR)\
**Post date:** [November 9, 2020, 1:54pm UTC](https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577/3 "2020-11-09T13:54:20Z")

</div>

> [@mtojek](#):
>
> Did you look into template conditions?

They would be ideal and that was my initial thought, but I couldn't determine whether conditions could be used in a hint-based autodiscover rule or where/how to apply them. Can you point me to a more complete reference regarding hints that might help with this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2020, 3:54pm UTC](https://discuss.elastic.co/t/can-filebeat-exclude-a-specific-container-name-from-hints-based-autodiscover/254577/4 "2020-12-07T15:54:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
