# Filebeat and Docker EE

**URL:** <https://discuss.elastic.co/t/filebeat-and-docker-ee/156698>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 14, 2018, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698 "2018-11-14T14:48:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eric\_Duquesnoy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_duquesnoy/32/37637_2.png) [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Post date:** [November 14, 2018, 2:48pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/1 "2018-11-14T14:48:50Z")

</div>

Hi There,  
We have just installed a Docker EE cluster on 10 nodes (3 UCP , 3 DTR and 6 workers) .  
Filebeat and Metricbeat are installed on each nodes with this configuration :

```
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
setup.template.settings:
  index.number_of_shards: 3
filebeat.autodiscover:
  providers:
    - type: docker
      templates:
        - condition:
            regexp:
              docker.container.name: ".*"
          config:
            - type: docker
              containers.ids:
                - "${data.docker.container.id}"
              processors:
               - add_docker_metadata: ~

```

As you seen docker logs are caught by Filebeat , parsed and send to Elasticsearch.  
Everything works fine but now we would like to activate Kubernetes as Orchestrator (embedded in Docker EE).

Do you ever experienced this configuration with Filebeat ? What is the conf to address Kubernetes api for the autodiscovering ?

Thank you for your help.  
Eric

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 14, 2018, 3:55pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/2 "2018-11-14T15:55:11Z")

</div>

Have you considered the [kubernetes autodiscovery provider](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html#_kubernetes)?

---

<div class="post-metadata">

**Author:** ![Eric\_Duquesnoy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_duquesnoy/32/37637_2.png) [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Post date:** [November 15, 2018, 1:52pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/3 "2018-11-15T13:52:45Z")

</div>

Yes, but Filebeat or Metricbeats need to have some informations about kubernetes (like the hostname and the port). I don't find in the documentation a way to declare them inside my Beats configuration.  
does it need the kubelet in workers or just the Kubernetes API in Masters nodes ?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 15, 2018, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/4 "2018-11-15T16:42:20Z")

</div>

Filebeat/Metricbeat auto discovery does connects to the local kubelet and listens to the local event stream.

Also see:

- [Running Filebeat on Kubernetes docs](https://www.elastic.co/guide/en/beats/filebeat/6.5/running-on-kubernetes.html)
- Default [Kubernetes deployment manifests](https://github.com/elastic/beats/tree/master/deploy/kubernetes) on github.

---

<div class="post-metadata">

**Author:** ![Eric\_Duquesnoy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_duquesnoy/32/37637_2.png) [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Post date:** [November 15, 2018, 5:30pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/5 "2018-11-15T17:30:23Z")

</div>

Fyi , Filebeat does not run in a container , it has been installed by a linux package.  
It's like a unix agent.  
Where can I specify the host and the port of k8s in Filebeat to enable the autodiscover ?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 16, 2018, 1:24pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/6 "2018-11-16T13:24:44Z")

</div>

See [kubernetes provider docs](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html#_kubernetes). The kubernetes providers has the settings `in_cluster`, `host`, and `kube_config`.

Normally `host` is not configured. Beat tries to discover/select the kubernetes host by these rules:

- If `host` is provided in the config use it directly.
- If the Beat is deployed in the k8s cluster, it uses the hostname of the pod. It uses the pod name to query the pod meta in order to read the node name.
- If the Beat is deployed outside the k8s cluster, it use the machine-id to match against k8s nodes for the current node name.

That is, if Filebeat is installed on the same host as as the kubelet, it should still be able to find the correct node. If not you can use the host configuration:

```auto
filebeat.autodiscover:
  providers:
  - type: kubernetes
    host: "<node endpoint>"
    templates:
      - ...

```

---

<div class="post-metadata">

**Author:** ![Eric\_Duquesnoy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eric_duquesnoy/32/37637_2.png) [@Eric\_Duquesnoy](https://discuss.elastic.co/u/Eric_Duquesnoy)\
**Post date:** [November 16, 2018, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/7 "2018-11-16T14:21:45Z")

</div>

Thank you for the example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2018, 2:21pm UTC](https://discuss.elastic.co/t/filebeat-and-docker-ee/156698/8 "2018-12-14T14:21:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
