# Filebeat not logging hints.enabled container logs

**URL:** <https://discuss.elastic.co/t/filebeat-not-logging-hints-enabled-container-logs/310574>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [July 25, 2022, 8:50pm UTC](https://discuss.elastic.co/t/filebeat-not-logging-hints-enabled-container-logs/310574 "2022-07-25T20:50:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dev4elasticapm](https://avatars.discourse-cdn.com/v4/letter/d/3ec8ea/32.png) [@dev4elasticapm](https://discuss.elastic.co/u/dev4elasticapm)\
**Post date:** [July 25, 2022, 8:50pm UTC](https://discuss.elastic.co/t/filebeat-not-logging-hints-enabled-container-logs/310574/1 "2022-07-25T20:50:23Z")

</div>

Hi, I am using ECK, I have configured filebeat with two options

1. `hints.enabled: true`, which looks for all the containers with `co.elastic.logs/enabled: "true"`
2. Checks the container containing name `ingress`.

#2 is working fine for me but I can't figure out how to get #1 working. Below is my **filebeat.yaml** file.

```auto
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: filebeat
  namespace: search
spec:
  type: filebeat
  version: 7.12.1
  elasticsearchRef:
    name: elastic-search
  kibanaRef:
    name: kibana-web
  config:
    filebeat.autodiscover.providers:
    - node: ${NODE_NAME}
      type: kubernetes
      hints.enabled: true
      #add_resource_metadata.namespace.enabled: true
      hints.default_config.enabled: "false"
    - node: ${NODE_NAME}
      type: kubernetes
      #add_resource_metadata.namespace.enabled: true
      hints.default_config.enabled: "false"
      templates:
      - condition:
          contains: 
            kubernetes.pod.name: ingress
        config:
        - paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
          type: container
          exclude_lines: ["^\\s+[\\-`('.|_]"]
    processors:
    - add_cloud_metadata: {}
    - add_host_metadata: {}
  daemonSet:
    podTemplate:
      spec:
        serviceAccountName: filebeat
        automountServiceAccountToken: true
        terminationGracePeriodSeconds: 30
        dnsPolicy: ClusterFirstWithHostNet
        #hostNetwork: true # Allows to provide richer host metadata
        containers:
        - name: filebeat
          securityContext:
            runAsUser: 0
            # If using Red Hat OpenShift uncomment this:
            #privileged: true
          volumeMounts:
          - name: varlogcontainers
            mountPath: /var/log/containers
          - name: varlogpods
            mountPath: /var/log/pods
          - name: varlibdockercontainers
            mountPath: /var/lib/docker/containers
          env:
            - name: NODE_NAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
          resources:
            requests:
              memory: 200Mi
              cpu: 0.2
            limits:
              memory: 300Mi
              cpu: 0.4
              
        volumes:
        - name: varlogcontainers
          hostPath:
            path: /var/log/containers
        - name: varlogpods
          hostPath:
            path: /var/log/pods
        - name: varlibdockercontainers
          hostPath:
            path: /var/lib/docker/containers

```

This is how my spring boot app deployment is configured

```auto
spec:
  replicas: 1
  selector:
    matchLabels:
      app: app
  template:
    metadata:
      labels:
        app: app
      annotations:
        co.elastic.logs/enabled: "true" # enable the logs collection for filebeat
        co.elastic.logs/multiline.pattern: '^([0-9]{4}-[0-9]{2}-[0-9]{2})'
        co.elastic.logs/multiline.negate: true
        co.elastic.logs/multiline.match: after

```

I can confirm that the spring app is logging the error logs but it's not being send to ECK Discover filebeat stream.I also confirmed that the Filebeat is running in both of the nodes where spring app is installled.

I think I'm missing a simple configuration in the file. I have tried adding (but didn't work!)

```auto
templates:
      - condition:
          contains: 
            co.elastic.logs/enabled: "true"
        config:
        - paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
          type: container
          exclude_lines: ["^\\s+[\\-`('.|_]"]

```

right after

```auto
- node: ${NODE_NAME}
      type: kubernetes
      hints.enabled: true
      #add_resource_metadata.namespace.enabled: true
      hints.default_config.enabled: "false"

```

---

<div class="post-metadata">

**Author:** ![hendry.lim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendry.lim/32/71328_2.png) [@hendry.lim](https://discuss.elastic.co/u/hendry.lim)\
**Post date:** [July 26, 2022, 1:19am UTC](https://discuss.elastic.co/t/filebeat-not-logging-hints-enabled-container-logs/310574/2 "2022-07-26T01:19:31Z")

</div>

Can you try the following Autodiscover config?

```auto
filebeat.autodiscover.providers:
  - type: kubernetes
    node: ${NODE_NAME}
    hints.enabled: true
    hints.default_config.enabled: false
    templates:
      - condition:
          contains: 
            kubernetes.pod.name: ingress
        config:
          - type: container
            paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
            exclude_lines: ["^\\s+[\\-`('.|_]"]

```

---

<div class="post-metadata">

**Author:** ![dev4elasticapm](https://avatars.discourse-cdn.com/v4/letter/d/3ec8ea/32.png) [@dev4elasticapm](https://discuss.elastic.co/u/dev4elasticapm)\
**Post date:** [July 26, 2022, 7:29pm UTC](https://discuss.elastic.co/t/filebeat-not-logging-hints-enabled-container-logs/310574/3 "2022-07-26T19:29:52Z")

</div>

Hi @hendry.lim Thank you for sharing this. I tried this config but it didn't work. I got the ingress logs but nothing from my web application [spring boot java app]

This is how my filebeat.yaml file looks right now [based on your suggested changes]

```auto
spec:
  type: filebeat
  version: 7.12.1
  elasticsearchRef:
    name: elastic-search
  kibanaRef:
    name: kibana-web
  config:
    filebeat.autodiscover.providers:
    - type: kubernetes
      node: ${NODE_NAME}
      hints.enabled: true
      #add_resource_metadata.namespace.enabled: true
      hints.default_config.enabled: false
      templates:
      - condition:
          contains: 
            kubernetes.pod.name: ingress
        config:
        - paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
          type: container
          exclude_lines: ["^\\s+[\\-`('.|_]"]

```

---

<div class="post-metadata">

**Author:** ![dev4elasticapm](https://avatars.discourse-cdn.com/v4/letter/d/3ec8ea/32.png) [@dev4elasticapm](https://discuss.elastic.co/u/dev4elasticapm)\
**Post date:** [July 30, 2022, 1:19am UTC](https://discuss.elastic.co/t/filebeat-not-logging-hints-enabled-container-logs/310574/4 "2022-07-30T01:19:06Z")

</div>

Alright! I finally got the configuration working 🙂 Below is fully functional filebeat.yaml file. It does following:

1. Checks if **co.elastic.logs/enabled: "true"** annotation is enabled in any of the container, if it does, then the logs are sent to elasticsearch.

2. Checks if any of the pod name contains **nginx**. If it does, then the logs are sent to elasticsearch.

Working filebeat.yaml file:

```auto
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: filebeat
  namespace: search
spec:
  type: filebeat
  version: 7.12.1
  elasticsearchRef:
    name: elastic-search
  kibanaRef:
    name: kibana-web
  config:
    filebeat.autodiscover.providers:
    - type: kubernetes
      node: ${NODE_NAME}
      hints: 
        enabled: true
        #add_resource_metadata.namespace.enabled: true
        default_config: 
          enabled: false
          type: container
          paths:
              - /var/log/containers/*${data.kubernetes.container.id}.log
      templates:
      - condition:
          contains: 
            kubernetes.pod.name: ingress
        config:
        - paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
          type: container
          
    processors:
    - add_cloud_metadata: {}
    - add_host_metadata: {}
  daemonSet:
    podTemplate:
      spec:
        serviceAccountName: filebeat
        automountServiceAccountToken: true
        terminationGracePeriodSeconds: 30
        dnsPolicy: ClusterFirstWithHostNet
        #hostNetwork: true # Allows to provide richer host metadata
        containers:
        - name: filebeat
          securityContext:
            runAsUser: 0
            # If using Red Hat OpenShift uncomment this:
            #privileged: true
          volumeMounts:
          - name: varlogcontainers
            mountPath: /var/log/containers
          - name: varlogpods
            mountPath: /var/log/pods
          - name: varlibdockercontainers
            mountPath: /var/lib/docker/containers
          env:
            - name: NODE_NAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
          resources:
            requests:
              memory: 200Mi
              cpu: 0.2
            limits:
              memory: 300Mi
              cpu: 0.4
              
        volumes:
        - name: varlogcontainers
          hostPath:
            path: /var/log/containers
        - name: varlogpods
          hostPath:
            path: /var/log/pods
        - name: varlibdockercontainers
          hostPath:
            path: /var/lib/docker/containers

```

The key is where you specify the annotation in your application's yaml file. In my case [java app], if I specify the annotation at the top level (i.e. deployment yaml's **metadata.annotations** level, the logs are not sent. When I set the annotations for the pod (i.e. at **spec.template.metadata.annotations** ), the logs started coming in.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2022, 3:19am UTC](https://discuss.elastic.co/t/filebeat-not-logging-hints-enabled-container-logs/310574/5 "2022-08-27T03:19:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
