# Filebeat missing container k8 metadata

**URL:** <https://discuss.elastic.co/t/filebeat-missing-container-k8-metadata/255530>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 16, 2020, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-missing-container-k8-metadata/255530 "2020-11-16T12:52:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mo\_ct](https://avatars.discourse-cdn.com/v4/letter/m/a87d85/32.png) [@mo\_ct](https://discuss.elastic.co/u/mo_ct)\
**Post date:** [November 16, 2020, 12:52pm UTC](https://discuss.elastic.co/t/filebeat-missing-container-k8-metadata/255530/1 "2020-11-16T12:52:42Z")

</div>

When running batch of short-lived containers (which are same docker images), on some (random) occasions k8 metadata tags are missing from some of them  
Also there are no errors on the Filebeat service itself when filebeat starts watching the files  
We have following config:

```auto
    filebeat.inputs:
    - type: docker
      containers.ids:
      - '*'
      processors:
      - add_kubernetes_metadata: ~
     ...
     ...
     ...

```

Tested with Filebeat 7.6 and with latest 7.9, same issue persists  
Running AKS (Azure) 1.17

Example screenshots:  
Missing k8 metadata tags

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/358a3c6f7c701d7c7e4cd3eeadbd82754b7b82f4.png)

And here are some with k8 metadata tags

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e7379083cbb2f32ccdb59e042c3a0c1728244089.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2020, 2:52pm UTC](https://discuss.elastic.co/t/filebeat-missing-container-k8-metadata/255530/2 "2020-12-14T14:52:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
