# Filebeat Autodiscover Configuration

**URL:** <https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 15, 2020, 9:16pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740 "2020-09-15T21:16:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_b/32/48977_2.png) [@Paul\_B](https://discuss.elastic.co/u/Paul_B)\
**Post date:** [September 15, 2020, 9:16pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740/1 "2020-09-15T21:16:33Z")

</div>

Can anyone shed some light on where exactly in the YAML config the configuration property "cleanup\_timeout" is supposed to sit?

We're using Filebeat Autodiscover for Kubernetes and unfortunately the documentation around exactly what options can sit at what level in the YAML is patchy at best. The only mention of it in the filebeat.reference.yaml file is here:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/6/866c4fb6aae5a32d3f419bedcd45d76d3f7d7663.png)

However, in the documentation here - [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html) - it states that this item is a property of the Provider, does that mean that the config I have is correct?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/a/bacbc834e744aa0f51d7532d774e6615e1bbcd35.png)

Please help!

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [September 16, 2020, 9:48am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740/2 "2020-09-16T09:48:09Z")

</div>

`cleanup_timeout` is used in kubernetes autodiscover to wait some time before the  
configurations associated to stopped containers are removed. As it states in [https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html) the property is defined in the provider configuration.

There is a similar option for `add_docker_metadata` (hence the same name).

---

<div class="post-metadata">

**Author:** ![Paul\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_b/32/48977_2.png) [@Paul\_B](https://discuss.elastic.co/u/Paul_B)\
**Post date:** [September 16, 2020, 9:51am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740/3 "2020-09-16T09:51:13Z")

</div>

So, have I configured it correctly then?

Also, are you guys going to update the filebeat.reference.yaml so that it explicitly shows the two places where you can use that property?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 11:51am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-configuration/248740/4 "2020-10-14T11:51:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
