# Filebeat and monitoring

**URL:** <https://discuss.elastic.co/t/filebeat-and-monitoring/319274>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** docker\
**Created:** [November 18, 2022, 8:29am UTC](https://discuss.elastic.co/t/filebeat-and-monitoring/319274 "2022-11-18T08:29:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ccaillet](https://avatars.discourse-cdn.com/v4/letter/c/ba9def/32.png) [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Post date:** [November 18, 2022, 8:29am UTC](https://discuss.elastic.co/t/filebeat-and-monitoring/319274/1 "2022-11-18T08:29:43Z")

</div>

HI all,

Another question and maybe an issue ...

WIth my cluster ES "preprod" and his monitoring dedicated ES "monitor" when I create a beat called filebeat (what a surprise !) I've the following behaviour: my filebeat appears in monitoring but on a "Standalone Cluster" and not on one of my exstant cluster here is the manifest used for the beat creation :

```auto
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: filebeat
  namespace: elastic-system
spec:
  type: filebeat
  version: 8.5.0
  monitoring:
    metrics:
      elasticsearchRefs:
      - name: monitor
        namespace: elastic-system
    logs:
      elasticsearchRefs:
      - name: monitor
        namespace: elastic-system
  elasticsearchRef:
    name: preprod
    namespace: elastic-system
  kibanaRef:
    name: preprod
    namespace: elastic-system
  config:
    filebeat:
      autodiscover:
        providers:
        - type: kubernetes
          node: ${NODE_NAME}
          hints:
            enabled: true
            default_config:
              type: container
              paths:
              - /var/log/containers/*${data.container.id}.log
              processors:
              - add_cloud_metadata: {}
              - add_host_metadata: {}
  daemonSet:
    podTemplate:
      spec:
        serviceAccountName: filebeat
        automountServiceAccountToken: true
        terminationGracePeriodSeconds: 30
        dnsPolicy: ClusterFirstWithHostNet
        hostNetwork: true # Allows to provide richer host metadata
        containers:
        - name: filebeat
          securityContext:
            runAsUser: 0
            # If using Red Hat OpenShift uncomment this:
            #privileged: true
          volumeMounts:
          - name: varlogcontainers
            mountPath: /var/log/containers
          - name: varlogpods
            mountPath: /var/log/pods
          - name: varlibdockercontainers
            mountPath: /var/lib/docker/containers
          env:
            - name: NODE_NAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
        volumes:
        - name: varlogcontainers
          hostPath:
            path: /var/log/containers
        - name: varlogpods
          hostPath:
            path: /var/log/pods
        - name: varlibdockercontainers
          hostPath:
            path: /var/lib/docker/containers
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: filebeat
rules:
- apiGroups: [""] # "" indicates the core API group
  resources:
  - namespaces
  - pods
  - nodes
  verbs:
  - get
  - watch
  - list
---
apiVersion: v1
kind: ServiceAccount
metadata:
  name: filebeat
  namespace: elastic-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: filebeat
subjects:
- kind: ServiceAccount
  name: filebeat
  namespace: elastic-system
roleRef:
  kind: ClusterRole
  name: filebeat
  apiGroup: rbac.authorization.k8s.io

```

Is there something wrong on my manifest ?

Thanks for your time to answer me 🙂

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 16, 2022, 8:30am UTC](https://discuss.elastic.co/t/filebeat-and-monitoring/319274/2 "2022-12-16T08:30:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
