# Getting other pods nginx log to Beats in ECK

**URL:** <https://discuss.elastic.co/t/getting-other-pods-nginx-log-to-beats-in-eck/375259>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 1, 2025, 10:36am UTC](https://discuss.elastic.co/t/getting-other-pods-nginx-log-to-beats-in-eck/375259 "2025-03-01T10:36:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cedric\_Rochefolle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cedric_rochefolle/32/141729_2.png) [@Cedric\_Rochefolle](https://discuss.elastic.co/u/Cedric_Rochefolle)\
**Post date:** [March 1, 2025, 10:36am UTC](https://discuss.elastic.co/t/getting-other-pods-nginx-log-to-beats-in-eck/375259/1 "2025-03-01T10:36:47Z")

</div>

I have followed the ECK documents to configure Elasticsearch, Kibana, logstash and filebeat on my kubernetes cluster (it's a k3s home cluster)  
The Filebeat configuration I followed from [here](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-quickstart.html)  
then I create the following version:

```auto
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: jsc-filebeat
  namespace: jsc-ns
spec:
  type: filebeat
  version: 8.17.2
  config:
    filebeat.inputs:
      - type: filestream
        id: nginx-filestream-id
        enabled: true
        paths:
          - /var/log/nginx/access.log
        fields:
          nginx: true
    output.logstash:
      hosts: ["jsc-logstash-ls-beats:5044"]
  daemonSet:
    podTemplate:
      spec:
        dnsPolicy: ClusterFirstWithHostNet
        hostNetwork: true
        securityContext:
          runAsUser: 0
        containers:
          - name: filebeat
            volumeMounts:
              - name: varlognginx
                mountPath: /var/log/nginx
        volumes:
          - name: varlognginx
            hostPath:
              path: /var/log/nginx

```

If I create a `/var/log/nginx/access.log` file on a filebeat pod, I can see the index created and the data showing in Kibana. That confirms that the overall setup is ok.  
What I am missing is how to get the nginx logs from a different pods (I have a small website on a pod in the same k8s cluster and namespace) to be seen by the `daemonSet`  
Is it a permission that I am missing? It might be more of a k8s question but I would think more people have tried this too.

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [March 1, 2025, 2:52pm UTC](https://discuss.elastic.co/t/getting-other-pods-nginx-log-to-beats-in-eck/375259/2 "2025-03-01T14:52:48Z")

</div>

It looks like you've posted this question twice, I've replied to your other post here [Sending nginx logs from other pods to an ECK elasticsearch via Beats - #2 by strawgate](https://discuss.elastic.co/t/sending-nginx-logs-from-other-pods-to-an-eck-elasticsearch-via-beats/375265/2)

---

<div class="post-metadata">

**Author:** ![Cedric\_Rochefolle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cedric_rochefolle/32/141729_2.png) [@Cedric\_Rochefolle](https://discuss.elastic.co/u/Cedric_Rochefolle)\
**Post date:** [March 1, 2025, 2:57pm UTC](https://discuss.elastic.co/t/getting-other-pods-nginx-log-to-beats-in-eck/375259/3 "2025-03-01T14:57:31Z")

</div>

Thank you. Apologies, it's my first time using this forum, my other post appeared as draft and when I edited it posted a new one. I'll mark this as closed.
