# Filebeats on ECK

**URL:** <https://discuss.elastic.co/t/filebeats-on-eck/248849>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [September 16, 2020, 3:08pm UTC](https://discuss.elastic.co/t/filebeats-on-eck/248849 "2020-09-16T15:08:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssurenr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssurenr/32/72641_2.png) [@ssurenr](https://discuss.elastic.co/u/ssurenr)\
**Post date:** [September 16, 2020, 3:08pm UTC](https://discuss.elastic.co/t/filebeats-on-eck/248849/1 "2020-09-16T15:08:20Z")

</div>

While collecting logs from all pods using a filebeat daemonset in an ECK cluster, is there a way to use filebeat modules in this setup?  
Most filebeat modules expect a path value typically `var.paths`. In kubernetes environment, this value is ever-changing. Take, for example, you have a Redis deployment and you want to apply the Redis Filebeat module only to the logs coming from Redis server pods. I am looking for a solution to achieve this.

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [September 17, 2020, 12:04pm UTC](https://discuss.elastic.co/t/filebeats-on-eck/248849/2 "2020-09-17T12:04:13Z")

</div>

Hi,

If you redis deployments has some specific labels (for example `app: "redis"`) I think that you can use the autodiscover feature and use the `condition.contains` to match them. Then you should be able to configure the redis module accordingly. For example something along those lines should work:

```auto
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: filebeat
spec:
  type: filebeat
  version: 7.9.1
  elasticsearchRef:
    name: elasticsearch
  kibanaRef:
    name: kibana
  config:
    filebeat.autodiscover.providers:
    - node: ${NODE_NAME}
      type: kubernetes
      hints.default_config.enabled: "false"
      templates:
      - condition.contains:
          kubernetes.labels.app: "redis"
        config:
        - module: redis
          log:
            enabled: true
            var.paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
            input:
              type: container
              containers.ids:
                - ${data.kubernetes.container.id}
    processors:
    - add_cloud_metadata: {}
    - add_host_metadata: {}
  daemonSet:
    podTemplate:
      spec:
        serviceAccountName: filebeat
        automountServiceAccountToken: true
        terminationGracePeriodSeconds: 30
        dnsPolicy: ClusterFirstWithHostNet
        hostNetwork: true # Allows to provide richer host metadata
        containers:
        - name: filebeat
          securityContext:
            runAsUser: 0
            # If using Red Hat OpenShift uncomment this:
            #privileged: true
          volumeMounts:
          - name: varlogcontainers
            mountPath: /var/log/containers
          - name: varlogpods
            mountPath: /var/log/pods
          - name: varlibdockercontainers
            mountPath: /var/lib/docker/containers
          env:
            - name: NODE_NAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
        volumes:
        - name: varlogcontainers
          hostPath:
            path: /var/log/containers
        - name: varlogpods
          hostPath:
            path: /var/log/pods
        - name: varlibdockercontainers
          hostPath:
            path: /var/lib/docker/containers

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:13am UTC](https://discuss.elastic.co/t/filebeats-on-eck/248849/3 "2022-11-04T08:13:17Z")

</div>


