# Filebeat исключить kubernetes namespace

**URL:** <https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 24, 2020, 12:01pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499 "2020-11-24T12:01:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nurlan199206](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nurlan199206/32/66254_2.png) [@Nurlan199206](https://discuss.elastic.co/u/Nurlan199206)\
**Post date:** [November 24, 2020, 12:01pm UTC](https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499/1 "2020-11-24T12:01:03Z")

</div>

Filebeat работает как DaemonSet в kubernetes. Пытаюсь исключить некоторые namespace, такие как "kube-system" и "calico-system".

ConfigMap: filebeat.yml выглядит следующим образом. Что я делаю не так? С таким конфигом вообще ничего не записывается.

```auto
   - type: container
      paths:
        - /var/log/containers/*.log
      exclude_files:
        - /var/log/containers/java.*
      processors:
        - drop_event:
            when:
              equals:
                  or:
                    - kubernetes.namespace: "kube-system"
        - add_kubernetes_metadata:
            host: ${NODE_NAME}
            matchers:
            - logs_path:
                logs_path: "/var/log/containers/"

```

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [November 25, 2020, 2:49am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499/2 "2020-11-25T02:49:34Z")

</div>

_I can't read or write Russian so I used Google Translate to convert your post to English and have also replied in English. If I misunderstood something, I apologize._

What happens if you comment out the `drop_event` processor from your configuration? Do you record all events? If so, can you post one of the recorded events here please so we can look at the fields in it?

Order of processors is significant. The `kubernetes.*` metadata fields are added by the `add_kubernetes_metadata` processor. So you probably want to swap the order of the processors in your configuration so `add_kubernetes_metadata` comes before `drop_event`.

Shaunak

---

<div class="post-metadata">

**Author:** ![Nurlan199206](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nurlan199206/32/66254_2.png) [@Nurlan199206](https://discuss.elastic.co/u/Nurlan199206)\
**Post date:** [November 25, 2020, 7:54am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499/3 "2020-11-25T07:54:12Z")

</div>

Shaunak i'm trying to exclude some namespaces, because it's takes disk space.

someone have correct config how to exclude namespaces?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2020, 10:29am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-namespace/256499/5 "2020-12-24T10:29:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
