# Filebeat Hints based not grabbing logs

**URL:** <https://discuss.elastic.co/t/filebeat-hints-based-not-grabbing-logs/283634>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [September 8, 2021, 9:02am UTC](https://discuss.elastic.co/t/filebeat-hints-based-not-grabbing-logs/283634 "2021-09-08T09:02:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![WookWook](https://avatars.discourse-cdn.com/v4/letter/w/54ee81/32.png) [@WookWook](https://discuss.elastic.co/u/WookWook)\
**Post date:** [September 8, 2021, 9:02am UTC](https://discuss.elastic.co/t/filebeat-hints-based-not-grabbing-logs/283634/1 "2021-09-08T09:02:13Z")

</div>

Hello

I set up Elastic Cloud on Kubernetes on a Managed Azure Redhat Openshift Cluster 4.6

My initial configuration with hints based autodiscover and a default config was working fine. It grabbed all logs and I could discover the logs via Kibana.  
But I dont want to get all logs from the Cluster. So I disabled the default config and only set an annotation in a specific namespace. I also tried to set the annotation for a single pod.

I guess I am just missing something very simple...I hope you can help me.

Thanks in advance!

```auto
oc annotate namespace namespacename co.elastic.logs/enabled='true'

```

```auto
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: filebeat
spec:
  type: filebeat
  version: 7.13.0
  elasticsearchRef:
    name: elasticsearch
  kibanaRef:
    name: kibana
  config:
    filebeat:
      autodiscover:
        providers:
        - type: kubernetes
          node: ${NODE_NAME}
          hints:
            enabled: true
            default_config.enabled: false
    processors:
    - add_cloud_metadata: {}
    - add_host_metadata: {}
  daemonSet:
    podTemplate:
      spec:
        serviceAccountName: filebeat
        automountServiceAccountToken: true
        terminationGracePeriodSeconds: 30
        dnsPolicy: ClusterFirstWithHostNet
        hostNetwork: true # Allows to provide richer host metadata
        containers:
        - name: filebeat
          securityContext:
            runAsUser: 0
            # If using Red Hat OpenShift uncomment this:
            privileged: true
          volumeMounts:
          - name: varlogcontainers
            mountPath: /var/log/containers
          - name: varlogpods
            mountPath: /var/log/pods
          - name: varlibdockercontainers
            mountPath: /var/lib/docker/containers
          env:
            - name: NODE_NAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
        volumes:
        - name: varlogcontainers
          hostPath:
            path: /var/log/containers
        - name: varlogpods
          hostPath:
            path: /var/log/pods
        - name: varlibdockercontainers
          hostPath:
            path: /var/lib/docker/containers

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2021, 11:02am UTC](https://discuss.elastic.co/t/filebeat-hints-based-not-grabbing-logs/283634/2 "2021-10-06T11:02:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
