# Filebeat how to autodiscover kubernetes service and fetch pod log?

**URL:** <https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 22, 2020, 4:36am UTC](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997 "2020-06-22T04:36:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![chanjarster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chanjarster/32/70773_2.png) [@chanjarster](https://discuss.elastic.co/u/chanjarster)\
**Post date:** [June 22, 2020, 4:36am UTC](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997/1 "2020-06-22T04:36:14Z")

</div>

I've deploy filebeat on kubernetes cluster following the [doc](https://www.elastic.co/guide/en/beats/filebeat/current/running-on-kubernetes.html). And set `resource: service` in the config file:

```auto
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          resource: service
          node: ${NODE_NAME}
          include_annotations: []
          include_labels: []
          hints.enabled: true
          hints.default_config:
            enabled: false
            type: container
            paths:
              - /var/log/containers/*-${data.kubernetes.container.id}.log
    output.console:
      pretty: true

```

And then I add `co.elastic.logs/enabled: "true"` on a Service.

Filebeats discovered that service but print a error:

```auto
2020-06-22T03:27:25.307Z ERROR [autodiscover] autodiscover/autodiscover.go:210 Auto discover config check failed for config '{
"docker-json": {
"cri_flags": true,
"format": "auto",
"partial": true,
"stream": "all"
},
"symlinks": true,
"type": "container"
}', won't start runner: each input must have at least one path defined

```

So, did I missing something?

---

<div class="post-metadata">

**Author:** ![chanjarster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chanjarster/32/70773_2.png) [@chanjarster](https://discuss.elastic.co/u/chanjarster)\
**Post date:** [June 22, 2020, 6:50am UTC](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997/2 "2020-06-22T06:50:09Z")

</div>

Solved. I use config template solve this.

---

<div class="post-metadata">

**Author:** ![rhallier](https://avatars.discourse-cdn.com/v4/letter/r/edb3f5/32.png) [@rhallier](https://discuss.elastic.co/u/rhallier)\
**Post date:** [June 22, 2020, 7:34am UTC](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997/3 "2020-06-22T07:34:59Z")

</div>

Hi Daniel,  
I would be very interested if you could post the solution, I've got the same pb  
Regards  
R.

---

<div class="post-metadata">

**Author:** ![chanjarster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chanjarster/32/70773_2.png) [@chanjarster](https://discuss.elastic.co/u/chanjarster)\
**Post date:** [June 22, 2020, 8:18am UTC](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997/4 "2020-06-22T08:18:21Z")

</div>

Something like this, but you cannot specify the log file name, because kubernetes log file name is `{pod.name}-{pod.namespace}-{container.name}-{container.id}.log`

```auto
filebeat.autodiscover:
  providers:
    - type: kubernetes
      templates:
        - condition:
            equals:
              kubernetes.container.image: "redis"
          config:
            - module: redis
              log:
                input:
                  type: container
                  paths:
                    - /var/log/containers/*-${data.kubernetes.container.id}.log

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2020, 10:18am UTC](https://discuss.elastic.co/t/filebeat-how-to-autodiscover-kubernetes-service-and-fetch-pod-log/237997/5 "2020-07-20T10:18:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
