# Filebeat regexp metadata variables

**URL:** <https://discuss.elastic.co/t/filebeat-regexp-metadata-variables/242172>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 22, 2020, 11:01am UTC](https://discuss.elastic.co/t/filebeat-regexp-metadata-variables/242172 "2020-07-22T11:01:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![gladsheim](https://avatars.discourse-cdn.com/v4/letter/g/e8c25b/32.png) [@gladsheim](https://discuss.elastic.co/u/gladsheim)\
**Post date:** [July 22, 2020, 11:01am UTC](https://discuss.elastic.co/t/filebeat-regexp-metadata-variables/242172/1 "2020-07-22T11:01:49Z")

</div>

Hi  
i run filebeat on Kubernetes cluster. We use them for send logs to Kafka.  
Sorry, but I'm rookie on Filebeat :).  
In our Kubernetes cluster we have a namespace naming convention:  
-  
, for example:  
dev-deathstar.  
On Kafka topic is created only by the application name.

In configuration file for Filebeat we use:  
a) processors: add\_kubenetes\_metadata, add\_host\_metadata  
b) ouput:

```auto
output.kafka:
  topic: '%{[kubenetes.namespace]}-k8s.log

```

in logs I see metadata for example:

```auto
"kubernetes": {
  "namespace": "dev-deathstar", 

```

Now is the questions:  
is there possibility to create a new variables that we can use regular expression to get only data that we need, for example:  
variable name: k8snamespace  
value: deathstar

After successfully use regexp we should set our topic name as following:

`topic: %{[k8snamespace]}-k8s.log`

Thankful for any help.

Regards  
tom

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2020, 1:02pm UTC](https://discuss.elastic.co/t/filebeat-regexp-metadata-variables/242172/2 "2020-08-19T13:02:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
