# Filebeat query EKS worker node /var/log

**URL:** <https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [September 11, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745 "2023-09-11T14:23:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xUmaRix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xumarix/32/125516_2.png) [@xUmaRix](https://discuss.elastic.co/u/xUmaRix)\
**Post date:** [September 11, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745/1 "2023-09-11T14:23:08Z")

</div>

Hi,

I'm trying to ship EKS worker node `auth.log`, `syslog` and `audit.log` files which located under `/var/log`.  
I've deploy filebeat and logstash in EKS cluster however I saw under filebeat pods there's a lot of error log stated

```auto
{"log.level":"error","@timestamp":"2023-09-11T14:01:23.876Z","log.logger":"kubernetes","log.origin":{"file.name":"add_kubernetes_metadata/matchers.go","file.line":155},"message":"Error extracting container id - source value contains matcher's logs_path, however it is too short to contain a Docker container ID.","service.name":"filebeat","ecs.version":"1.6.0"}

```

This is my filebeat config

```auto
- type: log
  paths:
    - '/var/log/auth.log'
  processors:
  - add_kubernetes_metadata:
      host: ${NODE_NAME}
      matchers:
      - logs_path:
          logs_path: "/var/log/"
  - add_tags:
      tags: [authlog]
      target: "log_category"

```

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [September 12, 2023, 9:06am UTC](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745/2 "2023-09-12T09:06:13Z")

</div>

Hi @xUmaRix,

Welcome back! Have you checked the health of your Kubernetes pod [as recommended in the troubleshooting guide](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-kubernetes-metadata-error-extracting-container-id.html)?

---

<div class="post-metadata">

**Author:** ![Sunile\_Manjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunile_manjee/32/111461_2.png) [@Sunile\_Manjee](https://discuss.elastic.co/u/Sunile_Manjee)\
**Post date:** [September 17, 2023, 3:38am UTC](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745/3 "2023-09-17T03:38:12Z")

</div>

Can you elaborate on why you are using the `add_kubernetes_metadata` processor when collecting system-level logs? The `add_kubernetes_metadata` processor annotates each event with relevant metadata based on the Kubernetes pod from which the event originated. It seems you are collecting logs at a different level (system) in the hierarchy but want to enrich with pod level metadata.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2023, 5:39am UTC](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745/4 "2023-10-15T05:39:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
