# Filebeat on AWS EKS worker node

**URL:** <https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 21, 2019, 4:09pm UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347 "2019-03-21T16:09:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![reenrik](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@reenrik](https://discuss.elastic.co/u/reenrik)\
**Post date:** [March 21, 2019, 4:09pm UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347/1 "2019-03-21T16:09:30Z")

</div>

I'm an Elastic Cloud subscriber. We are standing up an EKS cluster on AWS, but would like to have filebeat exist outside of Kubernetes, directly on the worker node.

I'm having some trouble understanding what to put in the `kube_config` setting as there isn't a `kube_config` on the worker node that I know of and certainly not at `${HOME}/.kube/config`

Here is my filebeat.inputs

```auto
filebeat.inputs:

- type: log
  enabled: true
  paths:
    - /var/log/*.log

- type: docker
  combine_partial: true
  containers:
    path: "/var/lib/docker/containers"
    ids:
      - "*"
  json.keys_under_root: true
  json.add_error_key: true
  tags:
      - "container_logs_nonprod"
      - "eks_services"
  processors:
  - add_kubernetes_metadata:
      in_cluster: false
      host: i-[REDACTED]
      kube_config: ${HOME}/.kube/config

```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 29, 2019, 11:53am UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347/2 "2019-03-29T11:53:31Z")

</div>

Is there any reason you are setting `json.*` in the Docker input? Filebeat takes care of parsing the messages from the JSON coming from Docker. You only need that option if your logs are JSON under the key `log`. Is that the case?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 29, 2019, 11:54am UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347/3 "2019-03-29T11:54:15Z")

</div>

Also, if you are a customer, you can submit a support ticket to get an answer.

---

<div class="post-metadata">

**Author:** ![reenrik](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@reenrik](https://discuss.elastic.co/u/reenrik)\
**Post date:** [April 3, 2019, 7:44pm UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347/5 "2019-04-03T19:44:22Z")

</div>

The JSON configuration was not really the issue I was asking about, but in any case. I added that configuration assuming that I had to. Are you saying that if the logs are one JSON object per line with no root key, then it needs no further configuration?

---

<div class="post-metadata">

**Author:** ![reenrik](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@reenrik](https://discuss.elastic.co/u/reenrik)\
**Post date:** [April 3, 2019, 7:45pm UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347/6 "2019-04-03T19:45:50Z")

</div>

Also, what about the kubeconfig? Do I have to deploy a kubeconfig with RBAC permissions for a filebeat service account to use or something?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2019, 7:45pm UTC](https://discuss.elastic.co/t/filebeat-on-aws-eks-worker-node/173347/7 "2019-05-01T19:45:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
