# ECS-Kibana issue: is it possible to combine dynamic filter for kubernetes.pod.name or kubernetes.container.\_module.pod.name

**URL:** <https://discuss.elastic.co/t/ecs-kibana-issue-is-it-possible-to-combine-dynamic-filter-for-kubernetes-pod-name-or-kubernetes-container-module-pod-name/195449>\
**Category:** Metrics\
**Created:** [August 16, 2019, 8:01am UTC](https://discuss.elastic.co/t/ecs-kibana-issue-is-it-possible-to-combine-dynamic-filter-for-kubernetes-pod-name-or-kubernetes-container-module-pod-name/195449 "2019-08-16T08:01:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 16, 2019, 8:01am UTC](https://discuss.elastic.co/t/ecs-kibana-issue-is-it-possible-to-combine-dynamic-filter-for-kubernetes-pod-name-or-kubernetes-container-module-pod-name/195449/1 "2019-08-16T08:01:39Z")

</div>

Hi,

I am using metricbeat to gather information about my kubernetes cluster. I want to build my own status dashboard to see if my deployments / statefulsets in kubernetes are healthy and I want to be able to dig deeper and show performance values of containers and pods.

Currently my dashboard is looking like this. (created with enhanced-table plugin)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b58241182f29e5202aa140ef2c697c856dd3e4e5.png)

**First question:**  
Is it possible to achieve the same in TSVB (except for the filter panel)? Doing grouping on **multiple** levels and coloring a text cell based on a status (calculation between two fields).

**Second question**  
I want to add pod and container usage statistics. When I check the events in elasticsearch I have following to offer:

My table on the bottom is gathering information from metricset.nae: **state\_pod** :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1da27ce086187267abb4e5518b38870c3441953.png)

Overall pod metrics can be found in metricset.name: **pod** :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06d113be6ad473a742c298b99305c7411e9d649e.png)

And detailed container metrics can be found in metricset.name: **contianer**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a78701e675c690b695230fffceb1bae3e21d2eea.png)

Marked in green are metrics / values I would like to show.  
I want to be able to filter for example for a **logical** pod name by clicking on a table entry or in an object of tsvb.  
By clicking there I want to see every event which has the pod name value in the fields: `kubernetes.container._module.pod.name`or `kubernetes.pod.name` or at best `kubernetes.*.pod_name`.  
At very best I want to also show events where field `kubernetes.*.pod_name` is not existing.

Can this somehow be achieved with kibana?

In my opinion it would be much, much easier if same information is always stored in the same field. Store the kubernetes.pod.name always in this field, regardless my event is state\_pod, container, pod or whatever.

Same issue I am encountering if i filter for kubernetes.node.name. If I set this filter no pod or container will be shown, because the field (with same meaning) is named differently.

Thanks,  
Andreas

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [August 19, 2019, 3:44pm UTC](https://discuss.elastic.co/t/ecs-kibana-issue-is-it-possible-to-combine-dynamic-filter-for-kubernetes-pod-name-or-kubernetes-container-module-pod-name/195449/2 "2019-08-19T15:44:53Z")

</div>

> [@asp](#):
>
> **First question:**  
> Is it possible to achieve the same in TSVB (except for the filter panel)? Doing grouping on **multiple** levels and coloring a text cell based on a status (calculation between two fields).

Multi-level grouping is not possible in TSVB. It's an idea I've toyed around with but it just hasn't found its way into the the product because it would require refactor to how we do our group by functionality.

> [@asp](#):
>
> **Second question**  
> I want to add pod and container usage statistics. When I check the events in elasticsearch I have following to offer:

I'm not sure I'm interpreting you question correctly, let's see if I understand what you're asking. Are you looking for a filter expression that would return all the events if `kubernetes.pod.name` appeared in `kubernetes.container._module.pod.name OR kubernetes.pod.name OR kubernetes.*.pod.name`?

If that's the question then you could do something like `(kubernetes.container._module.pod.name: "<podName>" OR kubernetes.pod.name: "<podName>")` but unfortunately `kubernetes.*.pod.name` won't work because it's not supported by ES. You would need to list each possible field covered by the wildcard manually as another condition in group of `OR`s.

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 20, 2019, 6:35am UTC](https://discuss.elastic.co/t/ecs-kibana-issue-is-it-possible-to-combine-dynamic-filter-for-kubernetes-pod-name-or-kubernetes-container-module-pod-name/195449/3 "2019-08-20T06:35:26Z")

</div>

@simianhacker thanks for your reply.  
I am using following workaround now:

I ship metricbeat probes to logstash, where I copy lables, namespace, pod.name, etc. from the \_module object to kubernetes root. Then I am able to filter on the fields like kubernetes.labels.appl or kubernetes.namespace over all events which have this information.

Details can be found here:

> [@Which ways to copy subfields of kubernetes.container.\_module.labels.\* to kubernetes.lables.\*?](https://discuss.elastic.co/t/which-ways-to-copy-subfields-of-kubernetes-container-module-labels-to-kubernetes-lables/195546/5):
>
> mutate+copy is a no-op if a field does not exist, so you can compress this down to mutate { copy =\> { "[kubernetes][container][\_module][labels]" =\> "[kubernetes][labels]" "[kubernetes][container][\_module][namespace]" =\> "[kubernetes][namespace]" "[kubernetes][container][\_module][node]" =\> "[kubernetes][node]" "[kubernetes][container][\_module][pod]" =\> "[kubernetes][pod]" "[kubernetes][pod][\_module][labels]" =\> "[kubern…

Regards, Andreas

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2019, 6:41am UTC](https://discuss.elastic.co/t/ecs-kibana-issue-is-it-possible-to-combine-dynamic-filter-for-kubernetes-pod-name-or-kubernetes-container-module-pod-name/195449/4 "2019-09-17T06:41:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
