# Filebeat in Kubernetes - How to push logs for a specific k8s namespace

**URL:** <https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 31, 2018, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868 "2018-10-31T14:44:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anuranjit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuranjit/32/37165_2.png) [@anuranjit](https://discuss.elastic.co/u/anuranjit)\
**Post date:** [October 31, 2018, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868/1 "2018-10-31T14:44:48Z")

</div>

We are using filebeat configuration as in [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-docker.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-docker.html) . We are able to successfully push the logs from kubernetes to Elasticsearch for **containers.ids: '\*'** , but we have a need for specifying a different logic (multiline configuration) for different k8s namespace. We cannot use container ids for a k8s namespace since they keep on changing . Is there a way to specify a k8s namespace in the filebeat configuration.

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 31, 2018, 4:28pm UTC](https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868/2 "2018-10-31T16:28:51Z")

</div>

Hi @anuranjit and welcome 🙂

Filebeat supports [hints-based autodiscovery](https://www.elastic.co/guide/en/beats/filebeat/6.4/configuration-autodiscover-hints.html). Translated to the kubernetes world that means that you can add configuration to filebeat from annotations, this way you can for example add an specific multiline configuration to an specific pod or container using annotations. You can read more about this, including an example with multiline, in [this blogpost](https://www.elastic.co/blog/docker-and-kubernetes-hints-based-autodiscover-with-beats).

---

<div class="post-metadata">

**Author:** ![anuranjit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anuranjit/32/37165_2.png) [@anuranjit](https://discuss.elastic.co/u/anuranjit)\
**Post date:** [November 13, 2018, 1:15pm UTC](https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868/3 "2018-11-13T13:15:51Z")

</div>

@jsoriano Thanks for this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2018, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-in-kubernetes-how-to-push-logs-for-a-specific-k8s-namespace/154868/4 "2018-12-11T13:16:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
