# Filebeat autodiscover not working with hints & namespace

**URL:** <https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 5, 2020, 1:51pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876 "2020-08-05T13:51:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mirii1994](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mirii1994/32/77245_2.png) [@mirii1994](https://discuss.elastic.co/u/mirii1994)\
**Post date:** [August 5, 2020, 1:51pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876/1 "2020-08-05T13:51:12Z")

</div>

I'd like to configure filebeat to use autodiscover with hints enabled.  
Problem is, when I set a config for a certain namespace, it cancels the annotations in the pods under that namespace (meaning I get the multiline log split to different logs).

In filebeat's daemonset I configured it to be:

```auto
    filebeat.autodiscover:
          providers:
            - type: kubernetes
              node: ${NODE_NAME}
              hints.enabled: true
              hints.default_config:
                type: container
                paths:
                  - /var/log/containers/*-${data.kubernetes.container.id}.log
              include_annotations: '*'
              templates:
                - condition:
                    contains:
                      kubernetes.namespace: 'my-namespace'
                  config:
                    - type: container
                      paths:
                        - /var/log/containers/*-${data.kubernetes.container.id}.log
                      fields:
                        try: success

```

And in a pod that runs under the namespace 'my-namespace' I added those annotations:

```auto
      annotations:
        co.elastic.logs/multiline.type: 'pattern'
        co.elastic.logs/multiline.pattern: '^\[[0-9]{4}-[0-9]{2}-[0-9]{2}'
        co.elastic.logs/multiline.negate: 'true'
        co.elastic.logs/multiline.match: 'after'
        co.elastic.logs/exclude_lines: '^\n*$'

```

Any ideas on how to configure it so that i'll have a default configuration for that namespace but be able to use the annotations & hints?

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [August 14, 2020, 8:47pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876/2 "2020-08-14T20:47:13Z")

</div>

If you have found the solution (even if it's in the docs), please post it, so if anybody else runs into it, they'll find the answer right away 🙂

---

<div class="post-metadata">

**Author:** ![mirii1994](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mirii1994/32/77245_2.png) [@mirii1994](https://discuss.elastic.co/u/mirii1994)\
**Post date:** [August 18, 2020, 3:25pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876/3 "2020-08-18T15:25:11Z")

</div>

The solution for my problem was to use `appenders` instead of `template`: [https://www.elastic.co/guide/en/beats/filebeat/master/configuration-autodiscover-advanced.html](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-autodiscover-advanced.html)  
Appenders adds further config, where template overrides it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2020, 5:25pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-not-working-with-hints-namespace/243876/4 "2020-09-15T17:25:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
