# Filebeat hints-based autodiscover for JSON encoded logs

**URL:** <https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-for-json-encoded-logs/175571>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 5, 2019, 10:36am UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-for-json-encoded-logs/175571 "2019-04-05T10:36:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmetzler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rmetzler/32/43555_2.png) [@rmetzler](https://discuss.elastic.co/u/rmetzler)\
**Post date:** [April 5, 2019, 10:36am UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-for-json-encoded-logs/175571/1 "2019-04-05T10:36:24Z")

</div>

Hi,

I'm trying to set up autodiscovery in Kubernetes for Filebeat. There is a DaemonSet running Filebeat on each node, logging into ElasticSearch.  
Hints based autodiscovery works well for HAProxy and nginx Containers/Pods, but I'm running into problems with JSON-encoded logs. Several of my containers run SpringBoot+LogBack.

The problem I have is that I can't figure out how I can configure the parsing.

This is the autodiscover part from `filebeat.yml`:

```auto
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          hints.enabled: true
          json.message_key: log
      templates:
        - config:
            - type: docker
              containers.ids:
                - "${data.kubernetes.container.id}"
              json.keys_under_root: true
              json.add_error_key: true
              exclude_lines: ["^\\s+[\\-`('.|_]"] # drop asciiart lines

```

I can see the following in the `message` in Kibana.

```auto
{ "@timestamp": "2019-04-05T10:18:58.057+00:00","@version": 1,"message": "Longer than usual backend-request detected. ","logger_name": "com.example.package.MyClass","thread_name": "http-nio-0.0.0.0-8080-exec-5", "level": "WARN","level_value": 30000}

```

But it's just a string and I would like to have it parsed and be able to filter based on the keys.

I tried to add annotations to the pods, but I wasn't sure what to put there.

When I tried the following, I got Grok error messages:

```auto
  annotations:
    co.elastic.logs/module: logstash
    co.elastic.logs/format: json

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2019, 10:36am UTC](https://discuss.elastic.co/t/filebeat-hints-based-autodiscover-for-json-encoded-logs/175571/2 "2019-05-03T10:36:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
