# ES K8s (AKS) auditlogs via filebeat

**URL:** <https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 1, 2020, 11:38am UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036 "2020-04-01T11:38:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![VishalBhalla](https://avatars.discourse-cdn.com/v4/letter/v/ad7895/32.png) [@VishalBhalla](https://discuss.elastic.co/u/VishalBhalla)\
**Post date:** [April 1, 2020, 11:38am UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036/1 "2020-04-01T11:38:20Z")

</div>

Hi all. I just wanted to confirm my thinking with what I'm trying to achieve.

We currently have an version 7.6.2 ES stack running on kubernetes in Azure AKS.

The ES audit logs are currently being sent to stdout (so available as pod logs).

I was thinking I could create a filebeat pod to collect those logs, but it seems the wrong way to go about it? I was taking this route because we already have metricbeat setup in this fashion to collect system stats.

Am I right in thinking we should have the audit logs written to disk in the pods, and then install filebeat in each ES pod to hoover them up?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [April 2, 2020, 8:56am UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036/2 "2020-04-02T08:56:16Z")

</div>

Hi @VishalBhalla!

I would say that you can do this yes! Actually what you need is to deploy Filebeat as Daemonset in your k8s nodes and have it collecting the logs of the containers that you want to. See [https://www.elastic.co/guide/en/beats/filebeat/master/running-on-kubernetes.html](https://www.elastic.co/guide/en/beats/filebeat/master/running-on-kubernetes.html)

Regards!

---

<div class="post-metadata">

**Author:** ![VishalBhalla](https://avatars.discourse-cdn.com/v4/letter/v/ad7895/32.png) [@VishalBhalla](https://discuss.elastic.co/u/VishalBhalla)\
**Post date:** [April 2, 2020, 10:54am UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036/3 "2020-04-02T10:54:18Z")

</div>

Yes, I've followed that guide now, and have the daemonset up in our k8s cluster.  
Now just figuring out the logic to collect the correct logs.

Currently looks to collecting ALL kubernetes pod logs, as there seems to be no way to filter on selected pod names.

Am I correct in thinking I could use the [add\_kubernetes\_metedata](https://www.elastic.co/guide/en/beats/filebeat/current/add-kubernetes-metadata.html) processor to filter on namespace? So my filebeat would only be looking at logs in say the `elastic` namespace?

---

<div class="post-metadata">

**Author:** ![VishalBhalla](https://avatars.discourse-cdn.com/v4/letter/v/ad7895/32.png) [@VishalBhalla](https://discuss.elastic.co/u/VishalBhalla)\
**Post date:** [April 2, 2020, 5:41pm UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036/4 "2020-04-02T17:41:09Z")

</div>

So I've got filebeat up and running on kubernetes. But It seems to be hoovering up it's own logs. and therefore just looping round creating messy logs which eventually just end up with loads of `/////`s

My filebeat yaml so far:

```auto
filebeat.modules:
  - module: elasticsearch

filebeat.inputs:
  - type: container
    paths: '/var/lib/docker/containers/*/*.log'
    processors:
    - add_kubernetes_metadata:
        namespace: "elastic"

output.console:
  #pretty: true

```

I just simply want to hoover up the audit logs that the elasticsearch, logstash and kibana pods create.

Help please? Thanks 🙂

---

<div class="post-metadata">

**Author:** ![VishalBhalla](https://avatars.discourse-cdn.com/v4/letter/v/ad7895/32.png) [@VishalBhalla](https://discuss.elastic.co/u/VishalBhalla)\
**Post date:** [April 2, 2020, 6:55pm UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036/5 "2020-04-02T18:55:51Z")

</div>

Right. Got this so far, and it kinda does what I need...I think:

```auto
filebeat.modules:
  - module: elasticsearch

filebeat.inputs:
  - type: container
    paths: '/var/lib/docker/containers/*/*.log'
    processors:
    - add_kubernetes_metadata:
        namespace: "elastic"

processors:
- copy_fields:
    fields:
      - from: agent.type
        to: type
    fail_on_error: true
    ignore_missing: false

- decode_json_fields:
    fields: ["message"]

- drop_event.when.or:
  - contains.kubernetes.pod.name: "filebeat"
  - not.equals.kubernetes.namespace: "elastic"
  - not.equals.message.type: "audit"

output.console:
  #pretty: true

```

If i'm doing anything silly, or if this can be improved in anyway, I'd appreciate the feedback, cheers.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [April 3, 2020, 8:54am UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036/6 "2020-04-03T08:54:46Z")

</div>

Hi!

What you have is looking good. Also have a look in autodiscover ([https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html)) which I think can fit your case and help you to only collect logs from the services that you actually want.

Regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2020, 8:54am UTC](https://discuss.elastic.co/t/es-k8s-aks-auditlogs-via-filebeat/226036/7 "2020-05-01T08:54:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
