# Getting K8s annotations in Filebeat logs

**URL:** <https://discuss.elastic.co/t/getting-k8s-annotations-in-filebeat-logs/321671>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [December 20, 2022, 4:06pm UTC](https://discuss.elastic.co/t/getting-k8s-annotations-in-filebeat-logs/321671 "2022-12-20T16:06:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![RudyStolds](https://avatars.discourse-cdn.com/v4/letter/r/c57346/32.png) [@RudyStolds](https://discuss.elastic.co/u/RudyStolds)\
**Post date:** [December 20, 2022, 4:06pm UTC](https://discuss.elastic.co/t/getting-k8s-annotations-in-filebeat-logs/321671/1 "2022-12-20T16:06:20Z")

</div>

Hi,

I'm trying to get additional annotations from my K8s deployment into Elasticsearch.  
I'm currently on filebeat 7.18.8.  
My filebeat imputs in the filebeat.yml file look like the code below

```auto
filebeat.inputs:
- type: log
  enabled: true
  exclude_lines:
    # RI-813 OMSAgent is too noisy:
    - '^[A-Z][a-z][a-z] [0-9][0-9] [0-2][0-9]:[0-5][0-9]:[0-5][0-9] [a-zA-Z0-9]* sudo: omsagent : TTY=unknown'
  paths:
  {% for path in filebeat_paths %}
  - {{ path }}
  {% endfor -%}
  exclude_files:
  {% for exclusion in filebeat_exclude_files %}
  - "{{ exclusion }}"
  {% endfor %}
- type: docker
  containers.ids:
  {% if filebeat_kubelet_container_id is defined %}
  - {{ filebeat_kubelet_container_id }}
  {% else %}
  - '*'
  {% endif %}

  # containers.ids: '*'
  containers.path: "{{ filebeat_docker_root_dir }}/containers"
  processors:
    - add_docker_metadata:
        match_source_index: {{ filebeat_match_source_index }}
    - add_kubernetes_metadata:
        in_cluster: false
        host: "{{ ansible_fqdn }}"

```

my deployment.yml is similar to

```auto
apiVersion: apps/v1
kind: Deployment
metadata:
  annotations:
    test: abc
    test/slash: def
  name: somethingforjoey
spec:
  replicas: 1
  selector:
    matchLabels:
      app: somethingforjoey
  template:
    metadata:
      labels:
        app: somethingforjoey
    spec:
      containers:
      - env:

```

I would like to get the test or test/slash annotations inside my logs but I can't find out how to do it.  
The "- add\_kubernetes\_metadata:" part works as this gives me a uui, name etc as extra fields.  
I did already try

```auto
    - add_kubernetes_metadata:
        in_cluster: false
        include_annotations: ['*'] also ['test','test/slash']
        host: "{{ ansible_fqdn }}"

```

Any help in pointing me into the right direction would be much appreciated.

PS This is a self hosted stack.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2023, 6:06pm UTC](https://discuss.elastic.co/t/getting-k8s-annotations-in-filebeat-logs/321671/2 "2023-01-17T18:06:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
