# Filebeat autodiscover namespace\_defaults not work

**URL:** <https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [May 4, 2022, 5:32am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901 "2022-05-04T05:32:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lcc3108](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcc3108/32/105207_2.png) [@lcc3108](https://discuss.elastic.co/u/lcc3108)\
**Post date:** [May 4, 2022, 5:32am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901/1 "2022-05-04T05:32:26Z")

</div>

Hello.  
I'm using Elasticsearch filebeat 7.17.

According to the document, filebeat can use namespace's annotation when pod's annotation does not exist.

> **[Hints based autodiscover | Filebeat Reference \[7.17\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.17/configuration-autodiscover-hints.html#_namespace_defaults)**

But it seems to be working against my expectations.

The following cases operate normally.

```nohighlight
...
apiVersion: v1
kind: Pod
metadata:
  annotations:
    log-topic: service
...

```

However, it does not work when you delete the comment from pod and put the same annotation in namespace.

This is my filebeat setting file.

```nohighlight
filebeat.autodiscover:
  providers:
  - type: kubernetes
    hint.enabled: true
    add_resource_metadata:
      namespace:
        include_annotations: ["log-topic"]
    templates:
    - condition.contains:
        kubernetes.annotations.log-topic: service
      config:
      - type: docker
        containers.ids:
          - ${data.kubernetes.container.id}
        fields:
          log_topic: k8s.logging.filebeat.service
output.kafka:
  hosts: ["kafka_fqdn:port"]
  topic: '%{[fields.log_topic]}'
  partition.round_robin:
    reachable_only: false
  required_acks: 1
  compression: gzip
  max_message_bytes: 1000000
  worker: 6

```

---

<div class="post-metadata">

**Author:** ![Tetiana\_Kravchenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tetiana_kravchenko/32/102683_2.png) [@Tetiana\_Kravchenko](https://discuss.elastic.co/u/Tetiana_Kravchenko)\
**Post date:** [May 5, 2022, 1:10pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901/2 "2022-05-05T13:10:18Z")

</div>

Hi @lcc3108,

Seems here is an issue with documentation - here is an original [PR](https://github.com/elastic/beats/pull/16321) for this feature, this [comment](https://github.com/elastic/beats/pull/16321#issuecomment-604475934) as well as [tests](https://github.com/elastic/beats/pull/16321/files#diff-9f24ba274864b933a726842c2b9fb8ee487a13545579938f9e373d0463611142R153-R320) explains what should be expected.  
I will create an issue to adjust documentation.

---

<div class="post-metadata">

**Author:** ![lcc3108](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcc3108/32/105207_2.png) [@lcc3108](https://discuss.elastic.co/u/lcc3108)\
**Post date:** [May 6, 2022, 1:41am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901/3 "2022-05-06T01:41:33Z")

</div>

I will try the contents of the link.  
And I hope the issue is created and the document is updated.

Thank you.

---

<div class="post-metadata">

**Author:** ![lcc3108](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcc3108/32/105207_2.png) [@lcc3108](https://discuss.elastic.co/u/lcc3108)\
**Post date:** [May 10, 2022, 4:49am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901/4 "2022-05-10T04:49:09Z")

</div>

It still doesn't work.

```nohighlight
filebeat.autodiscover:
  providers:
  - type: kubernetes
    hint.enabled: true
    add_resource_metadata:
      namespace:
        enabled: true
        include_annotations: ["log-topic"] # comment or not comment tested

    templates:
    - condition.contains:
        kubernetes.annotations.log-topic: service
      config:
      - type: docker
        containers.ids:
          - ${data.kubernetes.container.id}
        fields:
          log_topic: k8s.logging.filebeat.service
output.kafka:
  hosts: ["kafka-confluent-1-cp-kafka-headless.kafka.svc.cluster.local:9092"]
  topic: '%{[fields.log_topic]}'
  partition.round_robin:
    reachable_only: false
  required_acks: 1
  compression: gzip
  max_message_bytes: 1000000
  worker: 6

```

```bash
$ kubectl describe ns default
Name: default
Labels: log-type=service
Annotations: log-topic: service
Status: Active

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2022, 6:49am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-namespace-defaults-not-work/303901/5 "2022-06-07T06:49:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
