# How does the filebeat elasticsearch module know where the elasticsearch server is?

**URL:** <https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 18, 2019, 5:55pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066 "2019-09-18T17:55:11Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 18, 2019, 5:55pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/1 "2019-09-18T17:55:11Z")

</div>

How do I tell the filebeat elasticsearch module where my elasticsearch cluster is? I am running in kubernetes and elasticsearch is installed in a different namespace.

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [September 19, 2019, 7:54am UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/2 "2019-09-19T07:54:31Z")

</div>

Hi @ceastman-ibm,

You need to configure the output section:  
[Configure filebeat to target elasticsearch](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html)

If you are using a service that resides at a different namespace, usually `servicename.namespace` will succeed:  
[Kubernetes Services - DNS](https://kubernetes.io/docs/concepts/services-networking/service/#dns)

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 1:17pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/3 "2019-09-19T13:17:13Z")

</div>

@pmercado the output is working fine, i thought the filebeat elasticsearch module would capture logs from my elasticsearch pods. do i need to install filebeat inside my elasticsearch kubernetes pods themselves?

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 1:20pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/4 "2019-09-19T13:20:41Z")

</div>

I guess a better question would be whats the purpose of installing filebeat into kubernetes?

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [September 19, 2019, 1:47pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/5 "2019-09-19T13:47:21Z")

</div>

Since logs are located at `/var/log/containers` deploying a filebeat agent as a daemonset should make sense.

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 2:04pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/6 "2019-09-19T14:04:41Z")

</div>

@pmercado i dont see that the filebeat daemonset is mounting /var/log thou. do i need to manually do something so that it does mount it?

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 2:12pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/7 "2019-09-19T14:12:00Z")

</div>

ah this might be due to kube versions. i believe with later versions of kube that is not the correct directory any more. i am on kube version 1.14

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [September 19, 2019, 3:06pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/8 "2019-09-19T15:06:15Z")

</div>

afaik kubelet is bind mounting to /var/log/pods and /var/log/containers, but you can always use the mapping that works for your installation.

Yes please, use:

- volume that includes path to log files
- mount the volume at the filebeat container, usually RO
- point the `logs_path` option at filebeat's container input configuration to the folder where the logs are to be found

You can base your manifests on ours:  
[https://raw.githubusercontent.com/elastic/beats/master/deploy/kubernetes/filebeat-kubernetes.yaml](https://raw.githubusercontent.com/elastic/beats/master/deploy/kubernetes/filebeat-kubernetes.yaml)

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 3:10pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/9 "2019-09-19T15:10:56Z")

</div>

looks like /var/log/pods is a soft link to /var/data/kubeletlogs that doesn't exist.

 ![28%20AM](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7d3aebaa58fcf7adb42cfb666d693f00ff36c87.png)

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 3:49pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/10 "2019-09-19T15:49:41Z")

</div>

maybe its a clusterrole permission thing that filebeat cant see the /var/data/kubeletlogs. i checked out ibm fluentd pod and it has access to the logs in those directories.

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 4:11pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/11 "2019-09-19T16:11:30Z")

</div>

not a cluster role permissions, looks like /var/data has to be mounted

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 4:32pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/12 "2019-09-19T16:32:12Z")

</div>

that was it, i added the two missing volumes/volumemounts to the daemonset and filebeat is parsing the kube logs now.

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 4:42pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/13 "2019-09-19T16:42:06Z")

</div>

ill make a pr to the helm charts for filebeat. [https://github.com/elastic/helm-charts/pull/294](https://github.com/elastic/helm-charts/pull/294)

---

<div class="post-metadata">

**Author:** ![ceastman-ibm](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@ceastman-ibm](https://discuss.elastic.co/u/ceastman-ibm)\
**Post date:** [September 19, 2019, 4:58pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/14 "2019-09-19T16:58:15Z")

</div>

@pmercado so back to the original question - how does this work: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-elasticsearch.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-elasticsearch.html) ? i logged into my filebeat kube pod and there is no /var/log/elasticsearch ? should this be changed to something like /var/log/containers/\*elasticsearch\*.log

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2019, 4:58pm UTC](https://discuss.elastic.co/t/how-does-the-filebeat-elasticsearch-module-know-where-the-elasticsearch-server-is/200066/15 "2019-10-17T16:58:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
