# Filebeat 7.6 Kubernetes \[ Openshift \] - Missing labels

**URL:** <https://discuss.elastic.co/t/filebeat-7-6-kubernetes-openshift-missing-labels/227912>\
**Category:** Beats\
**Created:** [April 14, 2020, 12:45pm UTC](https://discuss.elastic.co/t/filebeat-7-6-kubernetes-openshift-missing-labels/227912 "2020-04-14T12:45:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zerobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zerobot/32/48977_2.png) [@Zerobot](https://discuss.elastic.co/u/Zerobot)\
**Post date:** [April 14, 2020, 12:45pm UTC](https://discuss.elastic.co/t/filebeat-7-6-kubernetes-openshift-missing-labels/227912/1 "2020-04-14T12:45:34Z")

</div>

Hi!

We're trying to run Filebeat on Openshift. We want to create indices based on project-labels. Let's say we have a project label called "system-name". Multiple projects could have the same "system-name" because they are a part of the same system and We don't want to have separate indices for every single project.

Reading trough docs I understood that Filebeat kubernetes providers should get these labels in **"data.kubernetes.labels"**  
Reading trough docs [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html)

```
{
   "host": "172.17.0.21",
   "port": 9090,
  "kubernetes": {
     "container": {
       "id": "bb3a50625c01b16a88aa224779c39262a9ad14264c3034669a50cd9a90af1527",
       "image": "prom/prometheus",
       "name": "prometheus"
     },
     "labels": {
        "project": "prometheus",
       ...
     },
     "namespace": "default",
     "node": {
       "name": "minikube"
     },
     "pod": {
       "name": "prometheus-2657348378-k1pnh"
     }
   },
}

```

Sadly, after sending whole **"data.kubernetes"** JSON field, it seems We even got **"data.kubernetes.pod.labels"** but not **"data.kubernetes.labels"**.  
Is that a known error on Openshift?

Also, we are using Hints based autodiscover, config looks like this:

```
 filebeat.autodiscover:
   providers:
     - type: kubernetes
       node: ${NODE_NAME}
       hints.enabled: true
       hints.default_config:
         type: container
         paths:
           - /var/log/containers/*${data.kubernetes.container.id}.log
         processors:
           - drop_event:
               when:
                  equals:
                    kubernetes.namespace: kube-system
           - add_labels:
               labels:
                 osh_cluster: test
                 namespace_all: '${data.kubernetes}'
                 # sadly, no "data.kubernetes.labels" are received by Elasticsearch
 filebeat.modules:
 - module: haproxy
   log:
     enabled: true
     var.paths: ["/var/log/haproxy.log"]
     var.input: "file"
 
 processors:
   - add_cloud_metadata:
   - add_host_metadata:
   
 cloud.id: ${ELASTIC_CLOUD_ID}
 cloud.auth: ${ELASTIC_CLOUD_AUTH}
 
 output.logstash:
   hosts: ["#"]
   loadbalance: true
```

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [April 14, 2020, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-7-6-kubernetes-openshift-missing-labels/227912/2 "2020-04-14T13:11:19Z")

</div>

Try to enable debug logging for all selectors and see if Kubernetes doesn't report any problems.

---

<div class="post-metadata">

**Author:** ![Zerobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zerobot/32/48977_2.png) [@Zerobot](https://discuss.elastic.co/u/Zerobot)\
**Post date:** [April 15, 2020, 6:35am UTC](https://discuss.elastic.co/t/filebeat-7-6-kubernetes-openshift-missing-labels/227912/3 "2020-04-15T06:35:32Z")

</div>

Sadly, no errors were recorde and Filebeat is showing only things we already know like: lists of labels it is going to add to the event. Those lists of course do not contain labels we are looking for (project/namespace labels).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2020, 8:35am UTC](https://discuss.elastic.co/t/filebeat-7-6-kubernetes-openshift-missing-labels/227912/4 "2020-05-13T08:35:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
