# Filebeat stop working after upgrade from 7.6.0 to 7.7.1 (kubernetes)

**URL:** <https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 23, 2020, 5:39am UTC](https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190 "2020-06-23T05:39:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johanes\_Anggara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johanes_anggara/32/63084_2.png) [@Johanes\_Anggara](https://discuss.elastic.co/u/Johanes_Anggara)\
**Post date:** [June 23, 2020, 5:39am UTC](https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190/1 "2020-06-23T05:39:03Z")

</div>

I have filebeat running as daemonset in k8s cluster, while apps storing file which mounted in host disk, this path also mounted by filebeat containers.  
Previously on 7.6 its working but after upgrading to 7.7.1 its stop. Rolling back to 7.6.0 make it working again.  
after upgrading to 7.7.1, the only obvious error in Filebeat container is:

```auto
ERROR	[kubernetes]	add_kubernetes_metadata/matchers.go:91	Error extracting container id - source value does not contain matcher's logs_path '/var/lib/docker/containers/'.

```

This error not occur on filebeat 7.6.0

this is my filebeat yaml:

```auto
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          node: ${NODE_NAME}
          templates:
            - condition:
                equals:
                  kubernetes.pod.labels.logtype: filebeat
              config:
                - type: log
                  enabled: true
                  paths:
                    - /var/lib/kubelet/pods/${data.kubernetes.pod.uid}/volumes/kubernetes.io~empty-dir/filebeat-volume/*.json
                  json:
                    keys_under_root: false
                    add_error_key: true
                  fields:
                    logtype: filebeat

```

while filebeat mounting /var/lib/kubelet/pods/ and my pods have labels logtype=filebeat  
Any help is appreciated

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [June 23, 2020, 8:46am UTC](https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190/2 "2020-06-23T08:46:57Z")

</div>

See: [Problem to update to filebeat 7.7.0 and parser nginx-ingress-controller on Kubernetes](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461)

---

<div class="post-metadata">

**Author:** ![Johanes\_Anggara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johanes_anggara/32/63084_2.png) [@Johanes\_Anggara](https://discuss.elastic.co/u/Johanes_Anggara)\
**Post date:** [June 23, 2020, 9:23am UTC](https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190/3 "2020-06-23T09:23:42Z")

</div>

I already read it, but it didn't explain why it worked in 7.6.0 but not in 7.7.1  
Furthermore the java apps log is already pick up by filebeat (/var/log/containers/), but since the other log (/var/lib/kubelet/pods/) is for json logs, we need to change our code to combine both and print it on stdout (/var/log/containers/) to make it work with 7.7.1?

Note: /var/lib/kubelet/pods/ is the default directory of kubernetes to store emptyDir volumes, and we use in to put all json logs, so diminished the need of logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2020, 11:23am UTC](https://discuss.elastic.co/t/filebeat-stop-working-after-upgrade-from-7-6-0-to-7-7-1-kubernetes/238190/4 "2020-07-21T11:23:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
