# Filebeat is not collecting logs from pods/kubernetes

**URL:** <https://discuss.elastic.co/t/filebeat-is-not-collecting-logs-from-pods-kubernetes/299980>\
**Category:** Logs\
**Created:** [March 17, 2022, 5:19pm UTC](https://discuss.elastic.co/t/filebeat-is-not-collecting-logs-from-pods-kubernetes/299980 "2022-03-17T17:19:18Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![marone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marone/32/87145_2.png) [@marone](https://discuss.elastic.co/u/marone)\
**Post date:** [March 21, 2022, 6:43pm UTC](https://discuss.elastic.co/t/filebeat-is-not-collecting-logs-from-pods-kubernetes/299980/2 "2022-03-21T18:43:01Z")

</div>

Well based on the two issues: [issue1](https://discuss.elastic.co/t/unknown-logs-in-observability-overview/273240) and [issue2](https://discuss.elastic.co/t/log-source-unknown-in-observability-overview/262568), it appears that filebeat only collect raw logs but doesn't assign from which source it was collected, thus you have to add `event.dataset`, see [ECS: event.dataset](https://www.elastic.co/guide/en/ecs/8.1/ecs-event.html#field-event-dataset) field using `processors`, like this:

```auto
# ....
  processors:
      - add_cloud_metadata:
      - add_host_metadata:
      - add_kubernetes_metadata:
      - add_fields:
          when:
            contains:
              kubernetes.pod.name: "my-app1"
          target: ''
          fields:
            event:
              dataset: my-app1.log
      - add_fields:
          when:
            contains:
              kubernetes.pod.name: "my-app2"
          target: ''
          fields:
            event:
              dataset: my-app2.log
      #- add_field for more pods, etc.
#...

```

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-is-not-collecting-logs-from-pods-kubernetes/299980)._
