# Filebeat add\_kubernetes\_metadata and IPv6

**URL:** <https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018>\
**Category:** Beats\
**Created:** [October 25, 2018, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018 "2018-10-25T14:25:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hhoover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hhoover/32/36931_2.png) [@hhoover](https://discuss.elastic.co/u/hhoover)\
**Post date:** [October 25, 2018, 2:25pm UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018/1 "2018-10-25T14:25:33Z")

</div>

When using filebeat in a Kubernetes cluster as a pod, using the add\_kubernetes\_metadata processor, the processor can't handle IPv6 addresses if an IPv6 address resolves from [https://kubernetes.default.svc.cluster.local](https://kubernetes.default.svc.cluster.local). The parser freaks out on the colons in the address. I don't know if this is an issue in an underlying library or Filebeat itself.

Secondary to this issue, it would be nice to provide a custom Kubernetes API endpoint to use, so I could try something like https://[2001:0db8:85a3:0000:0000:8a2e:0370:7334]:443 (and force the use of brackets). It looks like I can only do this if I set in\_cluster to "false" and provide a kubeconfig file.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [October 25, 2018, 2:42pm UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018/2 "2018-10-25T14:42:59Z")

</div>

> [@hhoover](#):
>
> When using filebeat in a Kubernetes cluster as a pod, using the add\_kubernetes\_metadata processor, the processor can't handle IPv6 addresses if an IPv6 address resolves from [https://kubernetes.default.svc.cluster.local](https://kubernetes.default.svc.cluster.local). The parser freaks out on the colons in the address. I don't know if this is an issue in an underlying library or Filebeat itself.

Can you create a specific issue on our bug tracker at [GitHub - elastic/beats: 🐠 Beats - Lightweight shippers for Elasticsearch & Logstash](https://github.com/elastic/beats/),  
When you say the _parser freak out_ I presume it actually panic? Adding the trace to the issue would be really useful and we would be able to narrow it down to either beats or the library.

---

<div class="post-metadata">

**Author:** ![hhoover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hhoover/32/36931_2.png) [@hhoover](https://discuss.elastic.co/u/hhoover)\
**Post date:** [October 25, 2018, 2:54pm UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018/3 "2018-10-25T14:54:08Z")

</div>

[https://github.com/elastic/beats/issues/8749](https://github.com/elastic/beats/issues/8749)

Done, with the error included.

---

<div class="post-metadata">

**Author:** ![hhoover](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hhoover/32/36931_2.png) [@hhoover](https://discuss.elastic.co/u/hhoover)\
**Post date:** [November 1, 2018, 3:09pm UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018/4 "2018-11-01T15:09:06Z")

</div>

Is there any container pushed with the fix in it before 6.5's release that I can use in the meantime? I can even test it for you! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2018, 5:09pm UTC](https://discuss.elastic.co/t/filebeat-add-kubernetes-metadata-and-ipv6/154018/5 "2018-11-29T17:09:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
