# Can't get Filebeat to ship Nginx Ingress Controller logs using ECK

**URL:** <https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [September 20, 2023, 3:12pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472 "2023-09-20T15:12:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![krische](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krische/32/112302_2.png) [@krische](https://discuss.elastic.co/u/krische)\
**Post date:** [September 20, 2023, 3:12pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472/1 "2023-09-20T15:12:50Z")

</div>

I have ECK setup and running on my kubernetes cluster. I followed the [Configuration Examples](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-configuration-examples.html) to setup filebeat ship all container logs to Elasticsearch. That is working fine.

However, now I am trying to parse the logs of my Nginx Ingress Controller using the nginx filebeat module so that I can better search the ingress logs. But I just can't seem to get it to work, no matter how many different examples I see online. This is what my Beat resource looks like:

```yaml
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: container-logs
  namespace: elasticsearch
spec:
  config:
    filebeat:
      autodiscover:
        providers:
          - hints:
              default_config:
                enabled: false
            node: ${NODE_NAME}
            templates:
              - config:
                  - paths:
                      - /var/log/containers/*${data.kubernetes.container.id}.log
                    type: container
              - condition:
                  equals:
                    kuberentes.container.name: controller
                config:
                  - ingress_controller:
                      enabled: true
                      vars:
                        paths:
                          - /var/log/containers/*${data.kubernetes.container.id}.log
                    module: nginx
            type: kubernetes
    processors:
      - add_cloud_metadata: {}
      - add_host_metadata: {}
    setup:
      dashboards:
        enabled: false
  daemonSet:
    podTemplate:
      spec:
        automountServiceAccountToken: true
        containers:
          - env:
              - name: NODE_NAME
                valueFrom:
                  fieldRef:
                    fieldPath: spec.nodeName
            name: filebeat
            volumeMounts:
              - mountPath: /var/log/containers
                name: varlogcontainers
              - mountPath: /var/log/pods
                name: varlogpods
              - mountPath: /var/lib/docker/containers
                name: varlibdockercontainers
        dnsPolicy: ClusterFirstWithHostNet
        hostNetwork: true
        securityContext:
          runAsUser: 0
        serviceAccountName: filebeat
        volumes:
          - hostPath:
              path: /var/log/containers
            name: varlogcontainers
          - hostPath:
              path: /var/log/pods
            name: varlogpods
          - hostPath:
              path: /var/lib/docker/containers
            name: varlibdockercontainers
  elasticsearchRef:
    name: elasticsearch
  kibanaRef:
    name: kibana
  monitoring:
    logs: {}
    metrics:
      elasticsearchRefs:
        - name: elasticsearch
          namespace: elasticsearch
  type: filebeat
  version: 8.10.1

```

Has anyone else gotten this to work on their setup? I feel like I've tried everything.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 20, 2023, 5:38pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472/2 "2023-09-20T17:38:44Z")

</div>

Hi @krische

Hmm just a quick look are you missing the provider `type`

```auto
  config:
    filebeat.autodiscover.providers:
    - node: ${NODE_NAME}
      type: kubernetes <!--- Looks like you are missing this? 
      hints.default_config.enabled: "false"
      templates:
      - condition.equals.kubernetes.namespace: log-namespace
        config:
        - paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
          type: container
      - condition.equals.kubernetes.labels.log-label: "true"
        config:
        - paths: ["/var/log/c

```

Also you can read more about filebeat autodiscover [here](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html)...

---

<div class="post-metadata">

**Author:** ![krische](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krische/32/112302_2.png) [@krische](https://discuss.elastic.co/u/krische)\
**Post date:** [September 20, 2023, 7:54pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472/3 "2023-09-20T19:54:06Z")

</div>

It looks like part of my issue was a typo in the condition, I had "kuber **en** tes" instead of "kuber **ne** tes".

And I don't know if it was necessary, but I also overrode some of the input stuff. So this is what ended up working for me:

```yaml
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: container-logs
  namespace: elasticsearch
spec:
  config:
    filebeat:
      autodiscover:
        providers:
          - hints:
              default_config:
                enabled: false
            node: ${NODE_NAME}
            templates:
              - config:
                  - paths:
                      - /var/log/containers/*${data.kubernetes.container.id}.log
                    type: container
              - condition:
                  equals:
                    kubernetes.container.name: controller
                config:
                  - ingress_controller:
                      enabled: true
                      input:
                        paths:
                          - /var/log/containers/*${data.kubernetes.container.id}.log
                        type: container
                      vars:
                        paths:
                          - /var/log/containers/*${data.kubernetes.container.id}.log
                    module: nginx
            type: kubernetes
    processors:
      - add_cloud_metadata: {}
      - add_host_metadata: {}
    setup:
      dashboards:
        enabled: false
  daemonSet:
    podTemplate:
      spec:
        automountServiceAccountToken: true
        containers:
          - env:
              - name: NODE_NAME
                valueFrom:
                  fieldRef:
                    fieldPath: spec.nodeName
            name: filebeat
            volumeMounts:
              - mountPath: /var/log/containers
                name: varlogcontainers
              - mountPath: /var/log/pods
                name: varlogpods
              - mountPath: /var/lib/docker/containers
                name: varlibdockercontainers
        dnsPolicy: ClusterFirstWithHostNet
        hostNetwork: true
        securityContext:
          runAsUser: 0
        serviceAccountName: filebeat
        volumes:
          - hostPath:
              path: /var/log/containers
            name: varlogcontainers
          - hostPath:
              path: /var/log/pods
            name: varlogpods
          - hostPath:
              path: /var/lib/docker/containers
            name: varlibdockercontainers
  elasticsearchRef:
    name: elasticsearch
  kibanaRef:
    name: kibana
  monitoring:
    logs: {}
    metrics:
      elasticsearchRefs:
        - name: elasticsearch
          namespace: elasticsearch
  type: filebeat
  version: 8.10.1

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2023, 9:55pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472/4 "2023-10-18T21:55:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
