# Fluent Bit Filter for by PODs (calico-pod) in kubernetes?

**URL:** <https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975>\
**Category:** Logs\
**Created:** [February 19, 2019, 9:25am UTC](https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975 "2019-02-19T09:25:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JDev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jdev/32/40795_2.png) [@JDev](https://discuss.elastic.co/u/JDev)\
**Post date:** [February 19, 2019, 9:25am UTC](https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975/1 "2019-02-19T09:25:54Z")

</div>

Hi, I installed fluentbit with default settings. I like that the fluent bit adds additional information (the name of the container).  
But he writes in the index everything. How do I do better? How to add a filter so that it takes all the logs, except for example the logs from the calico pod.

Here is the default Filter.

```
fluent-bit-filter.conf:
[FILTER]
    Name kubernetes
    Match kube.*
    Kube_URL https://kubernetes.default.svc:443
    Kube_CA_File /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
    Kube_Token_File /var/run/secrets/kubernetes.io/serviceaccount/token
    Merge_Log On
    K8S-Logging.Parser On
    K8S-Logging.Exclude On

```

Thanks.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [February 19, 2019, 9:32am UTC](https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975/2 "2019-02-19T09:32:58Z")

</div>

Hi @JDev,

these are the support forums for the Elastic Stack. Unfortunately we can't offer support for other products. The [Fluent Bit community](https://fluentbit.io/community/) might be a better place to ask for support regarding Fluent Bit filter plugin configuration.

If you are looking for advice about the index mapping when writing to Elasticsearch in order for the log entries to show up in the Logs UI, I'd be happy to assist.

---

<div class="post-metadata">

**Author:** ![JDev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jdev/32/40795_2.png) [@JDev](https://discuss.elastic.co/u/JDev)\
**Post date:** [February 19, 2019, 10:31am UTC](https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975/3 "2019-02-19T10:31:09Z")

</div>

I understood you. Thanks for the link.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2019, 10:31am UTC](https://discuss.elastic.co/t/fluent-bit-filter-for-by-pods-calico-pod-in-kubernetes/168975/4 "2019-03-19T10:31:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
