# Filebeat Kubernetes Autodiscovery Template Problem (6.5.4)

**URL:** <https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 11, 2019, 3:10pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916 "2019-01-11T15:10:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Namik\_Mesic](https://avatars.discourse-cdn.com/v4/letter/n/9e8a1a/32.png) [@Namik\_Mesic](https://discuss.elastic.co/u/Namik_Mesic)\
**Post date:** [January 11, 2019, 3:10pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916/1 "2019-01-11T15:10:23Z")

</div>

I am trying to use filebeat kubernetes with autodiscovery and templates just as shown in the documentation, however I am unable to make the templates work.

What I am trying to achieve:

1. Send logs only when ceartain annotation is present in the pods.
2. Add log filtering (exclude\_lines and include\_lines) based on the kubernetes.container.image value.

Here is my daemonset:

```auto
spec:
  tolerations:
    - key: "node-role.kubernetes.io/master"
      effect: "NoSchedule"
      operator: "Exists"
  serviceAccountName: svc-logging
  terminationGracePeriodSeconds: 30
  containers:
  - name: filebeat
    image: docker.elastic.co/beats/filebeat:{{ .Values.filebeat.version }}
    args: [
      "-c", "/etc/filebeat.yml",
      "-e",
    ]
    env:
      - name: LOGSTASH_HOSTS
        value: "logstash:5044"
    securityContext:
      runAsUser: 0
    resources:
      limits:
        cpu: {{ .Values.filebeat.resources.limits.cpu }}
        memory: {{ .Values.filebeat.resources.limits.memory }}
      requests:
        cpu: {{ .Values.filebeat.resources.requests.cpu }}
        memory: {{ .Values.filebeat.resources.requests.memory }}
    volumeMounts:
    - name: config
      mountPath: /etc/filebeat.yml
      readOnly: true
      subPath: filebeat.yml
      readOnly: true
    - name: data
      mountPath: /usr/share/filebeat/data
    - name: varlibdockercontainers
      mountPath: /var/lib/docker/containers
      readOnly: true
  volumes:
  - name: config
    configMap:
      defaultMode: 0600
      name: filebeat-config
  - name: varlibdockercontainers
    hostPath:
      path: /var/lib/docker/containers
  # data folder stores a registry of read status for all files, so we don't send everything again on a Filebeat pod restart
  - name: data
    hostPath:
      path: /var/lib/filebeat-data
      type: DirectoryOrCreate

```

Here is the configuration I am using:

```auto
apiVersion: v1
kind: ConfigMap
metadata:
    name: filebeat-config
    labels:
        app: "{{ .Values.appName }}"
        component: filebeat
        chart: {{ .Chart.Name }}-{{ .Chart.Version | replace "+" "_" }}
        release: {{ .Release.Name }}
data:
    filebeat.yml: |-
      filebeat.registry_flush: 1s

      filebeat.autodiscover:
        providers:
         - type: kubernetes
           hints.enabled: true
           include_annotations: ['logging']
           templates:
             - condition:
                contains:
                  kubernetes.container.image: "quay.io/hippo/user-worker"
               config:
                 - type: docker
                   container.ids:
                      - "${data.kubernetes.container.id}"
                   exclude_lines: ['^I0111']
      processors:
      - drop_event:
          when:
            not:
              equals:
                kubernetes.annotations.logging: 'true'

      output.logstash:
          hosts: '${LOGSTASH_HOSTS}'

```

Error I am getting is:  
`[filebeat-j5fbt] 2019-01-11T15:08:06.005Z	ERROR	[autodiscover]	cfgfile/list.go:96	Error creating runner from config: Docker input requires at least one entry under 'containers.ids'`

Can someone help me out , is there something I am doing wrong? I followed the documentation, or at least what I could find on the official website, and the forums and github.

I am using filebeats version 6.5.4

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [January 11, 2019, 5:34pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916/2 "2019-01-11T17:34:08Z")

</div>

Hi @Namic\_Mesic,

There is a typo in the config, it says `container.ids` where it should be `containers.ids`.

---

<div class="post-metadata">

**Author:** ![Namik\_Mesic](https://avatars.discourse-cdn.com/v4/letter/n/9e8a1a/32.png) [@Namik\_Mesic](https://discuss.elastic.co/u/Namik_Mesic)\
**Post date:** [January 14, 2019, 11:21am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916/3 "2019-01-14T11:21:31Z")

</div>

@exekias Thanks a lot, I don't know how I missed that. Anyway, works like a charm now!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2019, 11:21am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-template-problem-6-5-4/163916/4 "2019-02-11T11:21:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
