# How to exclude other namespaces?

**URL:** <https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [August 27, 2020, 4:00am UTC](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544 "2020-08-27T04:00:02Z")\
**Posts on this page:** 5\
**Page:** 2

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [September 5, 2020, 12:23am UTC](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544/21 "2020-09-05T00:23:55Z")

</div>

okay, thank you

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [September 25, 2020, 2:48am UTC](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544/22 "2020-09-25T02:48:09Z")

</div>

hello  
@jsoriano

I found container.id after upgrading filebeat to 7.9.2, but container.id still does not exist in metricbeat version 7.9.2. Will you add container.id next time?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b5d945e06ef08e8f44eb82723cd47abd3b2d6ba9.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c94d229650f4440014413cc7cfdebd4bbd640572.png)

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [September 28, 2020, 11:42am UTC](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544/23 "2020-09-28T11:42:48Z")

</div>

Hey @wajika,

`container.id` field should be also present in events created by Metricbeat 7.9.2.

One thing that might be happening is that your configuration is only matching the pod events, that don't contain information about specific containers (a pod can contain multiple containers, sharing the same network namespace). How is the autodiscover configuration you are using in Metricbeat?

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [October 9, 2020, 2:39am UTC](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544/24 "2020-10-09T02:39:05Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0fe238ea3011989033f422839bee60bd4d421342.png)

Why do other namespace data appear?

> ```
> apiVersion: v1
> kind: ConfigMap
> metadata:
> name: metricbeat-daemonset-config
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> data:
> metricbeat.yml: |-
> metricbeat.config.modules:
> path: ${path.config}/modules.d/*.yml
> reload.enabled: true
> metricbeat.autodiscover:
> providers:
> - type: kubernetes
> templates:
> - condition:
> or:
> - equals:
> kubernetes.namespace: back
> - equals:
> kubernetes.namespace: front
> processors:
> - add_docker_metadata:
> host: "unix:///var/run/docker.sock"
> - add_kubernetes_metadata:
> in_cluster: true
> host: ${NODE_NAME} 
> output.elasticsearch:
> hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
> ---
> apiVersion: v1
> kind: ConfigMap
> metadata:
> name: metricbeat-fields-config
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> data:
> fields.yml: |-
> - name: service
> type: group
> description: >
> kubernetes service metrics
> release: experimental
> fields:
> - name: name
> type: keyword
> description: Service name.
> - name: cluster_ip
> type: keyword
> description: Internal IP for the service.
> - name: external_name
> type: keyword
> description: Service external DNS name
> - name: external_ip
> type: keyword
> description: Service external IP
> - name: load_balancer_ip
> type: keyword
> description: Load Balancer service IP
> - name: type
> type: keyword
> description: Service type
> - name: ingress_ip
> type: keyword
> description: Ingress IP
> - name: ingress_hostname
> type: keyword
> description: Ingress Hostname
> - name: created
> type: date
> description: Service creation date
> ---
> apiVersion: v1
> kind: ConfigMap
> metadata:
> name: metricbeat-daemonset-config
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> data:
> metricbeat.yml: |-
> metricbeat.config.modules:
> path: ${path.config}/modules.d/*.yml
> reload.enabled: true
> metricbeat.autodiscover:
> providers:
> - type: kubernetes
> templates:
> - condition:
> or:
> - equals:
> kubernetes.namespace: back
> - equals:
> kubernetes.namespace: front
> processors:
> - add_docker_metadata:
> host: "unix:///var/run/docker.sock"
> - add_kubernetes_metadata:
> in_cluster: true
> host: ${NODE_NAME} 
> processors:
> - add_docker_metadata:
> host: "unix:///var/run/docker.sock"
> - add_kubernetes_metadata:
> output.elasticsearch:
> hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
> 
> ---
> apiVersion: v1
> kind: ConfigMap
> metadata:
> name: metricbeat-daemonset-modules
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> data:
> system.yml: |-
> - module: system
> period: 10s
> metricsets:
> - cpu
> - load
> - memory
> - network
> - process
> - process_summary
> #- core
> #- diskio
> #- socket
> processes: ['.*']
> process.include_top_n:
> by_cpu: 5 # include top 5 processes by CPU
> by_memory: 5 # include top 5 processes by memory
> - module: system
> period: 1m
> metricsets:
> - filesystem
> - fsstat
> processors:
> - drop_event.when.regexp:
> system.filesystem.mount_point: '^/(sys|cgroup|proc|dev|etc|host|lib|snap)($|/)'
> kubernetes.yml: |-
> - module: kubernetes
> metricsets:
> - node
> - system
> - pod
> - container
> - volume
> period: 10s
> enabled: true
> host: ${NODE_NAME}
> hosts: ["https://${NODE_NAME}:10250"]
> bearer_token_file: /var/run/secrets/kubernetes.io/serviceaccount/token
> ssl.verification_mode: "none"
> - module: kubernetes
> metricsets:
> - proxy
> period: 10s
> host: ${NODE_NAME}
> hosts: ["localhost:10249"]
> ---
> apiVersion: apps/v1
> kind: DaemonSet
> metadata:
> name: metricbeat
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> spec:
> selector:
> matchLabels:
> k8s-app: metricbeat
> template:
> metadata:
> labels:
> k8s-app: metricbeat
> spec:
> serviceAccountName: metricbeat
> terminationGracePeriodSeconds: 30
> hostNetwork: true
> dnsPolicy: ClusterFirstWithHostNet
> containers:
> - name: metricbeat
> image: metricbeat:master-SNAPSHOT
> args: [
> "-c", "/etc/metricbeat.yml",
> "-e",
> "-system.hostfs=/hostfs",
> ]
> env:
> - name: ELASTICSEARCH_HOST
> value: 192.168.10.145
> - name: ELASTICSEARCH_PORT
> value: "9200"
> - name: ELASTICSEARCH_USERNAME
> value:
> - name: ELASTICSEARCH_PASSWORD
> value:
> - name: ELASTIC_CLOUD_ID
> value:
> - name: ELASTIC_CLOUD_AUTH
> value:
> - name: NODE_NAME
> valueFrom:
> fieldRef:
> fieldPath: status.hostIP
> securityContext:
> runAsUser: 0
> resources:
> limits:
> memory: 200Mi
> requests:
> cpu: 100m
> memory: 100Mi
> volumeMounts:
> - name: config
> mountPath: /etc/metricbeat.yml
> readOnly: true
> subPath: metricbeat.yml
> - name: data
> mountPath: /usr/share/metricbeat/data
> - name: modules
> mountPath: /usr/share/metricbeat/modules.d
> readOnly: true
> - name: dockersock
> mountPath: /var/run/docker.sock
> - name: proc
> mountPath: /hostfs/proc
> readOnly: true
> - name: cgroup
> mountPath: /hostfs/sys/fs/cgroup
> readOnly: true
> volumes:
> - name: proc
> hostPath:
> path: /proc
> - name: cgroup
> hostPath:
> path: /sys/fs/cgroup
> - name: dockersock
> hostPath:
> path: /var/run/docker.sock
> - name: config
> configMap:
> defaultMode: 0600
> name: metricbeat-daemonset-config
> - name: modules
> configMap:
> defaultMode: 0600
> name: metricbeat-daemonset-modules
> - name: data
> hostPath:
> path: /var/lib/metricbeat-data
> type: DirectoryOrCreate
> ---
> apiVersion: v1
> kind: ConfigMap
> metadata:
> name: metricbeat-deployment-config
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> data:
> metricbeat.yml: |-
> metricbeat.config.modules:
> path: ${path.config}/modules.d/*.yml
> reload.enabled: true
> metricbeat.autodiscover:
> providers:
> - type: kubernetes
> templates:
> - condition:
> or:
> - equals:
> kubernetes.namespace: back
> - equals:
> kubernetes.namespace: front
> processors:
> - add_docker_metadata:
> host: "unix:///var/run/docker.sock"
> - add_kubernetes_metadata:
> output.elasticsearch:
> hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
> ---
> apiVersion: v1
> kind: ConfigMap
> metadata:
> name: metricbeat-deployment-modules
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> data:
> kubernetes.yml: |-
> - module: kubernetes
> metricsets:
> - state_node
> - state_deployment
> - state_replicaset
> - state_statefulset
> - state_pod
> - state_container
> - state_cronjob
> - state_resourcequota
> - state_service
> - state_persistentvolume
> - state_persistentvolumeclaim
> - state_storageclass
> # Uncomment this to get k8s events:
> #- event
> period: 10s
> #add_metadata: true
> host: ${NODE_NAME}
> hosts: ["kube-state-metrics:8080"]
> ---
> apiVersion: apps/v1
> kind: Deployment
> metadata:
> name: metricbeat
> namespace: kube-system
> labels:
> k8s-app: metricbeat
> spec:
> selector:
> matchLabels:
> k8s-app: metricbeat
> template:
> metadata:
> labels:
> k8s-app: metricbeat
> spec:
> serviceAccountName: metricbeat
> hostNetwork: true
> dnsPolicy: ClusterFirstWithHostNet
> containers:
> - name: metricbeat
> image: metricbeat:master-SNAPSHOT
> args: [
> "-c", "/etc/metricbeat.yml",
> "-e",
> ]
> env:
> - name: ELASTICSEARCH_HOST
> value: 192.168.10.145
> - name: ELASTICSEARCH_PORT
> value: "9200"
> - name: ELASTICSEARCH_USERNAME
> value:
> - name: ELASTICSEARCH_PASSWORD
> value:
> - name: ELASTIC_CLOUD_ID
> value:
> - name: ELASTIC_CLOUD_AUTH
> value:
> - name: NODE_NAME
> valueFrom:
> fieldRef:
> fieldPath: spec.nodeName
> securityContext:
> runAsUser: 0
> resources:
> limits:
> memory: 200Mi
> requests:
> cpu: 100m
> memory: 100Mi
> volumeMounts:
> - name: config
> mountPath: /etc/metricbeat.yml
> readOnly: true
> subPath: metricbeat.yml
> - name: fields-config
> mountPath: /usr/share/metricbeat/fields.yml
> readOnly: true
> subPath: fields.yml   
> - name: modules
> mountPath: /usr/share/metricbeat/modules.d
> readOnly: true
> volumes:
> - name: config
> configMap:
> defaultMode: 0600
> name: metricbeat-deployment-config
> - name: fields-config
> configMap:
> defaultMode: 0600
> name: metricbeat-fields-config
> - name: modules
> configMap:
> defaultMode: 0600
> name: metricbeat-deployment-modules
> 
> ```

Due to the mapping problem of some fields, I temporarily use the master tag.

about container.id , I can only see it on kibana metric UI, but not on discover.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9de1be6f2ee884441e719958b4f68e0f2d161b6.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/4/b46444ab112a4073f0b64b95785c036d050b283c.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2020, 4:39am UTC](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544/25 "2020-11-06T04:39:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/how-to-exclude-other-namespaces/246544.md?page=1)
