# Configure Filebeat on Kubenetes

**URL:** <https://discuss.elastic.co/t/configure-filebeat-on-kubenetes/127531>\
**Category:** Beats\
**Created:** [April 10, 2018, 6:04pm UTC](https://discuss.elastic.co/t/configure-filebeat-on-kubenetes/127531 "2018-04-10T18:04:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefano\_Pirrello](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Stefano\_Pirrello](https://discuss.elastic.co/u/Stefano_Pirrello)\
**Post date:** [April 10, 2018, 6:04pm UTC](https://discuss.elastic.co/t/configure-filebeat-on-kubenetes/127531/1 "2018-04-10T18:04:51Z")

</div>

Hi,

I'm trying to follow this guide for setting up Filebeats on our K8s cluster (v1.5.4) and the daemonset starts successfully but we never see logs shipped to Logstash. I checked the logs on one of the filebeats daemonset pods and saw these messages. Is there a way we can reference our kubeconfig file (includes our CA cert) to address this problem? Or reference our CA cert at a minimum?

[https://www.elastic.co/guide/en/beats/filebeat/6.0/running-on-kubernetes.html](https://www.elastic.co/guide/en/beats/filebeat/6.0/running-on-kubernetes.html)

2018-04-10T16:53:16.572Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.581Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.582Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.608Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.609Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.617Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.618Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.629Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.629Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.639Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.639Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.670Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.671Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.682Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.682Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.697Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs  
2018-04-10T16:53:16.697Z INFO kubernetes/watcher.go:140 kubernetes: Watching API for pod events  
2018-04-10T16:53:16.715Z ERROR kubernetes/watcher.go:145 kubernetes: Watching API error Get [https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:](https://10.157.0.1:443/api/v1/pods?fieldSelector=spec.nodeName%3Dlocalhost&resourceVersion=0&watch=true:) x509: cannot validate certificate for 10.157.0.1 because it doesn't contain any IP SANs

---

<div class="post-metadata">

**Author:** ![\_flo](https://avatars.discourse-cdn.com/v4/letter/_/f17d59/32.png) [@\_flo](https://discuss.elastic.co/u/_flo)\
**Post date:** [April 10, 2018, 7:08pm UTC](https://discuss.elastic.co/t/configure-filebeat-on-kubenetes/127531/2 "2018-04-10T19:08:31Z")

</div>

are the default serviceaccont certs mounted? i don't know 1.5.x but with 1.8 its mounted per default, if not you always can do a hostPath mount

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2018, 9:08pm UTC](https://discuss.elastic.co/t/configure-filebeat-on-kubenetes/127531/3 "2018-05-08T21:08:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
