# Filebeat: How to not send logs from kube-system namespace

**URL:** <https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 24, 2021, 11:41pm UTC](https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876 "2021-05-24T23:41:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vrathore18](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vrathore18/32/88411_2.png) [@vrathore18](https://discuss.elastic.co/u/vrathore18)\
**Post date:** [May 24, 2021, 11:41pm UTC](https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876/1 "2021-05-24T23:41:16Z")

</div>

I tried all possible solutions mentioned here and StackOverflow. But not able to exclude logs from kube-system namespaces. Basically, I am getting logs from all the namespaces.

```
data:
  filebeat.yml: |-
    filebeat.inputs:
    - type: container
      paths:
        - /var/log/containers/*.log
      processors:
        - add_kubernetes_metadata:
            host: ${NODE_NAME}
            matchers:
            - logs_path:
                logs_path: "/var/log/containers/"
        - drop_event.when:
            or:
            - equals:
                kubernetes.namespace: "kube-system"
            - equals:
                kubernetes.namespace: "monitoring"

    setup.ilm.enabled: false
    output.elasticsearch:
      hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
      username: ${ELASTICSEARCH_USERNAME}
      password: ${ELASTICSEARCH_PASSWORD}

```

even tried this

```
filebeat.autodiscover:
 providers:
   - type: kubernetes
     node: ${NODE_NAME}
     hints.enabled: true
     hints.default_config:
       type: container
       paths:
         - /var/log/containers/*${data.kubernetes.container.id}.log
processors:
  - drop_event.when:
        or:
        - equals:
            kubernetes.namespace: kube-system
        - equals:
            kubernetes.namespace: monitoring

```

but nothing is working

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 25, 2021, 8:29am UTC](https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876/2 "2021-05-25T08:29:51Z")

</div>

Did you try this solution (with template): [How to exclude other namespaces? - #24 by wajika](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544/24) ?

BTW Which version of filebeat are you using? Maybe there was a bugfix pushed in latter one.

---

<div class="post-metadata">

**Author:** ![vrathore18](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vrathore18/32/88411_2.png) [@vrathore18](https://discuss.elastic.co/u/vrathore18)\
**Post date:** [May 25, 2021, 10:39am UTC](https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876/3 "2021-05-25T10:39:11Z")

</div>

I tried with filebeat version 7.8.0, 7.9.0, 7.12.0, and 8.0.0. But I keep getting all the noise from the kube-system namespace.

For a week I am trying to solve this issue. Almost testing everything on StackOverflow. Could you provide me any working yaml

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2021, 12:39pm UTC](https://discuss.elastic.co/t/filebeat-how-to-not-send-logs-from-kube-system-namespace/273876/4 "2021-06-22T12:39:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
