# Filebeat kubernetes autodiscover Multiple conditions

**URL:** <https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-multiple-conditions/161145>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 17, 2018, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-multiple-conditions/161145 "2018-12-17T12:42:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![icoolchn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icoolchn/32/45675_2.png) [@icoolchn](https://discuss.elastic.co/u/icoolchn)\
**Post date:** [December 17, 2018, 12:42pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-multiple-conditions/161145/1 "2018-12-17T12:42:56Z")

</div>

The problem is When the condition has “kubernetes.labels.log-index” ，fields:log\_topic: 'labels-{data.kubernetes.labels.log-index}', otherwise fields: log\_topic: 'aip-{data.kubernetes.namespace}-${data.kubernetes.pod.name}'  
The default condition not.equals.kubernetes.container.name: "filebeat" 。

Test 1  
use filebeat processors

- drop\_event of “when” can use multiple conditions ？

Such as

```
 filebeat.autodiscover:
    providers:
      - type: kubernetes
        hints.enabled: true
        templates:
        processors:
        - drop_event:
            when:
              and:
                - not:
                    has_fields: ['kubernetes.labels.log-index']
                - equals:
                    kubernetes.container.name: "filebeat"
            config:
              - type: docker
                containers.ids:
                  - "${data.kubernetes.container.id}"
                exclude_lines: ["^\\s+[\\-`('.|_]"] # drop asciiart lines
                fields:
                  log_topic: 'labels-${data.kubernetes.labels.log-index}'
            when:                       
              and:
                - has_fields: ['kubernetes.labels.log-index']
                - equals:
                    kubernetes.container.name: "filebeat"          
            config:
              - type: docker
                containers.ids:
                  - "${data.kubernetes.container.id}"
                exclude_lines: ["^\\s+[\\-`('.|_]"] # drop asciiart lines
                fields:
                  log_topic: 'aip-${data.kubernetes.namespace}-${data.kubernetes.pod.name}'

```

Test2  
use condition

Such as

```
  filebeat.autodiscover:
    providers:
      - type: kubernetes
        hints.enabled: true
        templates:
        - condition:
            and:
              has_fields: ['kubernetes.labels.log-index']
              not:
                equals:
                  kubernetes.container.name: "filebeat"
          config:
            - type: docker
              containers.ids:
                - "${data.kubernetes.container.id}"
              exclude_lines: ["^\\s+[\\-`('.|_]"] # drop asciiart lines
                fields:
                  log_topic: 'labels-${data.kubernetes.labels.log-index}'
        - condition:                       
            and:
              not:
                has_fields: ['kubernetes.labels.log-index']
              not:
                equals:
                  kubernetes.container.name: "filebeat"         
          config:
            - type: docker
              containers.ids:
                - "${data.kubernetes.container.id}"
              exclude_lines: ["^\\s+[\\-`('.|_]"] # drop asciiart lines
              fields:
                log_topic: 'aip-${data.kubernetes.namespace}-${data.kubernetes.pod.name}'

```

Test 3  
Multiple type: kubernetes

Such as

```
 filebeat.autodiscover:
    providers:
      - type: kubernetes
        hints.enabled: true
        templates:
        - condition.and:
            - has_fields: ['kubernetes.labels.log-index']
            - not.equals.kubernetes.container.name: "filebeat"                 
          config:
            - type: docker
              containers.ids:
                - "${data.kubernetes.container.id}"
              exclude_lines: ["^\\s+[\\-`('.|_]"] # drop asciiart lines
                fields:
                  log_topic: 'labels-${data.kubernetes.labels.log-index}'
      - type: kubernetes
        hints.enabled: true
        templates:
        - condition.and:                  
            - not.has_fields: ['kubernetes.labels.log-index']
            - not.equals.kubernetes.container.name: "filebeat"          
          config:
            - type: docker
              containers.ids:
                - "${data.kubernetes.container.id}"
              exclude_lines: ["^\\s+[\\-`('.|_]"] # drop asciiart lines
              fields:
                log_topic: 'aip-${data.kubernetes.namespace}-${data.kubernetes.pod.name}'

```

But can't succeed, could you tell me whether there is something wrong with the grammar, thank you

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [December 17, 2018, 1:58pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-multiple-conditions/161145/2 "2018-12-17T13:58:54Z")

</div>

Hello @icoolchn Could you edit your post and use the ``` or **Preformatted test** with your YAML configuration, badly indented YAML can make Filebeat not correctly applies your configuration.

Since you just copied the test without preformatting I cannot very if you have an error in your indentation.

---

<div class="post-metadata">

**Author:** ![icoolchn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/icoolchn/32/45675_2.png) [@icoolchn](https://discuss.elastic.co/u/icoolchn)\
**Post date:** [December 19, 2018, 3:06am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-multiple-conditions/161145/4 "2018-12-19T03:06:07Z")

</div>

Please help to see if the problem, thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2019, 3:06am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscover-multiple-conditions/161145/5 "2019-01-16T03:06:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
