# Filebeat doesn't log anythign with kubernetes autodiscover

**URL:** <https://discuss.elastic.co/t/filebeat-doesnt-log-anythign-with-kubernetes-autodiscover/144933>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 17, 2018, 4:30pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-log-anythign-with-kubernetes-autodiscover/144933 "2018-08-17T16:30:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lassizci](https://avatars.discourse-cdn.com/v4/letter/l/5daacb/32.png) [@lassizci](https://discuss.elastic.co/u/lassizci)\
**Post date:** [August 17, 2018, 4:30pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-log-anythign-with-kubernetes-autodiscover/144933/1 "2018-08-17T16:30:14Z")

</div>

Hi, I've been trying to set up kubernetes logging with filebeat from outside our kubernetes cluster. Here is my config:

```
filebeat:
  autodiscover:
    providers:
      - type: kubernetes
        kube_config: /etc/kubernetes/kubelet-kubeconfig.yml
        in_cluster: false
        templates:
          - condition:
              regexp:
                kubernetes.namespace: ".*"
            config:
              - type: docker
                include_annotations: true
                containers.ids:
                  - "${data.kubernetes.container.id}"
logging:
  files:
    keepfiles: 7
    name: filebeat.log
    path: /var/log/filebeat
    permissions: '0644'
    rotateeverybytes: 104857600
  level: debug
  to_files: true
output:
  file:
    path: /tmp/filebeat

```

Filebeat doesn't seem to even create the output file.

Logs here (due to body size limit..): [https://pastebin.com/ry0bvA6f](https://pastebin.com/ry0bvA6f)

To me it looks like it does find at least some pods, even though only for kube-system namespace while I have others running there too. But no output from those produced either.

I've tried previously without the autodiscover:

```
filebeat:
  prospectors:
  - fields:
      kubeenv: dev1
      type: kubelog
    fields_under_root: true
    json:
      keys_under_root: true
      message_key: log
    paths:
    - /var/lib/docker/containers/*/*.log
    processors:
    - add_kubernetes_metadata:
        in_cluster: false
        kube_config: /etc/kubernetes/kubelet-kubeconfig.yml
    type: log

```

and that seems to be working though, but there's an issue with that: [https://github.com/elastic/beats/issues/5377](https://github.com/elastic/beats/issues/5377)

Any ideas what possibly could be wrong?

---

<div class="post-metadata">

**Author:** ![lassizci](https://avatars.discourse-cdn.com/v4/letter/l/5daacb/32.png) [@lassizci](https://discuss.elastic.co/u/lassizci)\
**Post date:** [August 20, 2018, 9:13am UTC](https://discuss.elastic.co/t/filebeat-doesnt-log-anythign-with-kubernetes-autodiscover/144933/2 "2018-08-20T09:13:29Z")

</div>

Turned out to be an issue with machine-id. Added `host` to provider config and started to see logs, so the detection went wrong because provisioning hadn't generated a unique one. Kubelet credentials don't apparently have `watch` permission by default, but didn't seem to be a part of the issue. Better practice anyway is to create a separate read-only credentials for filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 17, 2018, 9:13am UTC](https://discuss.elastic.co/t/filebeat-doesnt-log-anythign-with-kubernetes-autodiscover/144933/3 "2018-09-17T09:13:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
