# Filebeat kubernets api metadata isnt optional

**URL:** <https://discuss.elastic.co/t/filebeat-kubernets-api-metadata-isnt-optional/134273>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 1, 2018, 9:03pm UTC](https://discuss.elastic.co/t/filebeat-kubernets-api-metadata-isnt-optional/134273 "2018-06-01T21:03:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![shane99a](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@shane99a](https://discuss.elastic.co/u/shane99a)\
**Post date:** [June 1, 2018, 9:03pm UTC](https://discuss.elastic.co/t/filebeat-kubernets-api-metadata-isnt-optional/134273/1 "2018-06-01T21:03:53Z")

</div>

So I decided to test out what happens if filebeat could not access the k8s API, by giving it no reading access to the API, hoping that filebeat will send the logs without kubernetes metadata. But I observed that it will not send the logs unless it has the metadata. Is this intended? I figured it would make more sense to carry on sending the logs without this enhancement.

```
{"time":"2018-06-01T16:32:04.950783-04:00","log":"2018-06-01T20:32:04.950Z#011INFO#011kubernetes\/watcher.go:140#011kubernetes: Watching API for pod events"}
{"time":"2018-06-01T16:32:04.951133-04:00","log":"2018-06-01T20:32:04.950Z#011ERROR#011kubernetes\/watcher.go:145#011kubernetes: Watching API error kubernetes api: Failure 403 pods is forbidden: Ubeat-user\" cannot watch pods at the cluster scope"}
{"time":"2018-06-01T16:32:04.951374-04:00","log":"2018-06-01T20:32:04.950Z#011INFO#011kubernetes\/watcher.go:140#011kubernetes: Watching API for pod events"}
{"time":"2018-06-01T16:32:04.952057-04:00","log":"2018-06-01T20:32:04.951Z#011ERROR#011kubernetes\/watcher.go:145#011kubernetes: Watching API error kubernetes api: Failure 403 pods is forbidden: Ubeat-user\" cannot watch pods at the cluster scope"}

```

I managed to do this, by making a service account that doesn't have appropriate access that filebeat requires.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 4, 2018, 8:04am UTC](https://discuss.elastic.co/t/filebeat-kubernets-api-metadata-isnt-optional/134273/2 "2018-06-04T08:04:58Z")

</div>

Hi @shane99a,

If this is the case, that should be considered a bug, the expected behavior is what you describe (send them without the metadata). Could you please provide all the steps to test this? Perhaps you can do that in a new issue in github: [https://github.com/elastic/beats/issues/new](https://github.com/elastic/beats/issues/new)

Thank you for taking the time to test and provide feedback!

Best regards

---

<div class="post-metadata">

**Author:** ![shane99a](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@shane99a](https://discuss.elastic.co/u/shane99a)\
**Post date:** [June 4, 2018, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-kubernets-api-metadata-isnt-optional/134273/3 "2018-06-04T14:47:16Z")

</div>

Thanks, I logged a ticket: [https://github.com/elastic/beats/issues/7252](https://github.com/elastic/beats/issues/7252). I am using Filebeat 6.2.3 if that makes a difference.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2018, 2:47pm UTC](https://discuss.elastic.co/t/filebeat-kubernets-api-metadata-isnt-optional/134273/4 "2018-07-02T14:47:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
