# How do you set the orchestrator.cluster.name in Filebeat?

**URL:** <https://discuss.elastic.co/t/how-do-you-set-the-orchestrator-cluster-name-in-filebeat/373656>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [January 25, 2025, 4:00am UTC](https://discuss.elastic.co/t/how-do-you-set-the-orchestrator-cluster-name-in-filebeat/373656 "2025-01-25T04:00:59Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![mridang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mridang/32/140944_2.png) [@mridang](https://discuss.elastic.co/u/mridang)\
**Post date:** [January 25, 2025, 4:00am UTC](https://discuss.elastic.co/t/how-do-you-set-the-orchestrator-cluster-name-in-filebeat/373656/1 "2025-01-25T04:00:59Z")

</div>

I'm using Filebeat in Kubernetes to ship the logs to Elasticsearch. I've noticed that the log messages are missing the `orchestrator.cluster.name` fields. None of the orchestrator fields are being set. [Orchestrator Fields | Elastic Common Schema (ECS) Reference [8.16] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-orchestrator.html) I am using the add\_host\_metadata and the add\_kubernetes\_metadata processors

This is the information about the cluster.

```auto
$ kubectl config view 

apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: DATA+OMITTED
    server: https://127.0.0.1:6443
  name: docker-desktop
contexts:
- context:
    cluster: docker-desktop
    user: docker-desktop
  name: docker-desktop
current-context: docker-desktop
kind: Config
preferences: {}
users:
- name: docker-desktop
  user:
    client-certificate-data: DATA+OMITTED
    client-key-data: DATA+OMITTED

```

I cannot seem to understand where these fields are set from. I'm running ELK via the ECK operator version 8.16.0.
