# Does filebeat support fetching logfiles from defined kubernetes pods?

**URL:** <https://discuss.elastic.co/t/does-filebeat-support-fetching-logfiles-from-defined-kubernetes-pods/171076>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 6, 2019, 10:10am UTC](https://discuss.elastic.co/t/does-filebeat-support-fetching-logfiles-from-defined-kubernetes-pods/171076 "2019-03-06T10:10:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Crusader](https://avatars.discourse-cdn.com/v4/letter/c/f04885/32.png) [@Crusader](https://discuss.elastic.co/u/Crusader)\
**Post date:** [March 6, 2019, 10:10am UTC](https://discuss.elastic.co/t/does-filebeat-support-fetching-logfiles-from-defined-kubernetes-pods/171076/1 "2019-03-06T10:10:43Z")

</div>

Out of the box filebeat fetches each container in k8s environment.  
However i have some pods which belong to plugins or controllers which i dont want to process.

I already had a look into:  
[https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-reference-yml.html](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-reference-yml.html)  
...

# Use this to read from all containers, replace \* with a container id to read from one:

#containers:

# stream: all # can be all, stdout or stderr

# ids:

# - '\*'

This would help me restrict on container level. But there is no option which would help me to restrict to pod name level ?

Any ideas if my usecase is supported somehow ?

Thank you for your time !

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [March 6, 2019, 3:02pm UTC](https://discuss.elastic.co/t/does-filebeat-support-fetching-logfiles-from-defined-kubernetes-pods/171076/2 "2019-03-06T15:02:19Z")

</div>

@Crusader I think you could achieve what you want using [Filebeat's autodiscover for k8s](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html) and with template conditions to start or skip log monitoring.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2019, 3:02pm UTC](https://discuss.elastic.co/t/does-filebeat-support-fetching-logfiles-from-defined-kubernetes-pods/171076/3 "2019-04-03T15:02:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
