# Filebeat autodiscover for Kubernetes uses incorrect log path

**URL:** <https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-incorrect-log-path/317635>\
**Category:** Elastic Observability\
**Created:** [October 27, 2022, 6:11pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-incorrect-log-path/317635 "2022-10-27T18:11:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nlang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nlang/32/112610_2.png) [@nlang](https://discuss.elastic.co/u/nlang)\
**Post date:** [October 27, 2022, 6:11pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-incorrect-log-path/317635/1 "2022-10-27T18:11:04Z")

</div>

I'm trying to configure filebeat and my pods in kubernetes to use auto disscover and hints. I found this previous topic: [Filebeat autodiscover for Kubernetes uses inconsistent log files path by default](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-inconsistent-log-files-path-by-default/279834) but it's now closed.

At this point in time I'm unable to upgrade past 7.17, so I was curious what the proper workaround should be.

Thanks

---

<div class="post-metadata">

**Author:** ![Honken77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/honken77/32/117036_2.png) [@Honken77](https://discuss.elastic.co/u/Honken77)\
**Post date:** [May 29, 2023, 6:58am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-incorrect-log-path/317635/2 "2023-05-29T06:58:52Z")

</div>

Did you get this working?

```auto
filebeat.autodiscover:
      providers:
        - type: kubernetes
          host: ${NODE_NAME}
          hints:
            enabled: true
            default_config:
              enabled: true
              paths:
                - /var/log/pods/*${data.kubernetes.pod.uid}/${data.kubernetes.container.name}/*.log
          add_resource_metadata:
            namespace:
              enabled: true

```

If I use this config, I get all logs no matter if the namespace or deployment is annotated or not

```auto
annotations:
  co.elastic.logs/enabled: 'true'

```

I feel like I had this working at some point. Are you saying it works in 7.17? And then I should disable config? I am on OpenShift 4.10 by the way.

---

<div class="post-metadata">

**Author:** ![Honken77](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/honken77/32/117036_2.png) [@Honken77](https://discuss.elastic.co/u/Honken77)\
**Post date:** [May 29, 2023, 8:05am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-incorrect-log-path/317635/3 "2023-05-29T08:05:04Z")

</div>

I think I got it working by disabling default\_config. This is my config now:

```auto
filebeat.autodiscover:
      providers:
        - type: kubernetes
          hints:
            enabled: true
            default_config:
              enabled: false
              paths:
                - /var/log/pods/*${data.kubernetes.pod.uid}/${data.kubernetes.container.name}/*.log
          add_resource_metadata:
            namespace:
              enabled: true
output.logstash:
      hosts: [" ***** :5044"] 
      ssl.enabled: true

```

Why it reads paths when default\_config is disabled, I don't know, but changing path was required for it to find the logs. Note that this is for OpenShift, so the path might be a bit different for Kubernetes running containerd or cri-o (I had to add the \* before pod uid variable).

I also have no idea what "host: ${NODE\_NAME}" is supposed to do...
