# Filebeat 8.2.1 kubernetes autodiscover template with multiple conditions doesn't work

**URL:** <https://discuss.elastic.co/t/filebeat-8-2-1-kubernetes-autodiscover-template-with-multiple-conditions-doesnt-work/305693>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 26, 2022, 9:22am UTC](https://discuss.elastic.co/t/filebeat-8-2-1-kubernetes-autodiscover-template-with-multiple-conditions-doesnt-work/305693 "2022-05-26T09:22:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![codrut\_alexandru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/codrut_alexandru/32/106193_2.png) [@codrut\_alexandru](https://discuss.elastic.co/u/codrut_alexandru)\
**Post date:** [May 26, 2022, 9:22am UTC](https://discuss.elastic.co/t/filebeat-8-2-1-kubernetes-autodiscover-template-with-multiple-conditions-doesnt-work/305693/1 "2022-05-26T09:22:30Z")

</div>

Hi,

Configuring filebeat version 8.2.1 autodiscover template with multiple conditions doesn't work:  
This works:

```nohighlight
            templates:
              - condition.or:
                  - not.equals:
                      kubernetes.namespace: "longhorn-system"

```

This doesn't:

```nohighlight
            templates:
              - condition.or:
                  - not.equals:
                      kubernetes.namespace: "elastic-system"
                  - not.equals:
                      kubernetes.namespace: "longhorn-system"

```

When adding multiple conditions none of them is respected.  
I'm getting crazy over here after spending one full day on this.

Full config:

```nohighlight
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: filebeat
  namespace: elastic-system
spec:
  type: filebeat
  version: 8.2.1
  elasticsearchRef:
    name: elasticsearch
  kibanaRef:
    name: kibana
  config:
    filebeat:
      autodiscover:
        providers:
          - type: kubernetes
            node: ${NODE_NAME}
            templates:
              - condition.or:
                  # - not.equals:
                  # kubernetes.namespace: "elastic-system"
                  - not.equals:
                      kubernetes.namespace: "longhorn-system"
                config:
                  - type: container
                    paths:
                      - /var/log/containers/*-${data.kubernetes.container.id}.log
...

```

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 30, 2022, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-8-2-1-kubernetes-autodiscover-template-with-multiple-conditions-doesnt-work/305693/2 "2022-05-30T15:16:12Z")

</div>

Hi,

does it make sense?

`namespace != elastic-system` or `namespace != longhorn-system` = always true?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2022, 5:17pm UTC](https://discuss.elastic.co/t/filebeat-8-2-1-kubernetes-autodiscover-template-with-multiple-conditions-doesnt-work/305693/3 "2022-06-27T17:17:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
