# How to remove a Metricbeat daemonset?

**URL:** <https://discuss.elastic.co/t/how-to-remove-a-metricbeat-daemonset/262244>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [January 26, 2021, 3:21pm UTC](https://discuss.elastic.co/t/how-to-remove-a-metricbeat-daemonset/262244 "2021-01-26T15:21:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mchudinov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mchudinov/32/82618_2.png) [@mchudinov](https://discuss.elastic.co/u/mchudinov)\
**Post date:** [January 26, 2021, 3:21pm UTC](https://discuss.elastic.co/t/how-to-remove-a-metricbeat-daemonset/262244/1 "2021-01-26T15:21:32Z")

</div>

How to remove a Metricbeat daemonset created with yaml:

```
apiVersion: beat.k8s.elastic.co/v1beta1
kind: Beat
metadata:
  name: metricbeat
  namespace: myspace 
spec:
  type: metricbeat
  version: 7.10.2
  elasticsearchRef:
    name: elasticsearch
  kibanaRef:
    name: kibana

```

A simple command does not help  
` kubectl delete -n myspace daemonset metricbeat-beat-metricbeat --force`

Pods of this beat are in **CrashLoopBackOff** state because they do not recognize Kibana SSL which is configured for public domain, not for Kubernetes.

Btw, it would be good to have an option for Beats.  
`ssl.verification_mode: "none"`

---

<div class="post-metadata">

**Author:** ![mchudinov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mchudinov/32/82618_2.png) [@mchudinov](https://discuss.elastic.co/u/mchudinov)\
**Post date:** [January 26, 2021, 11:40pm UTC](https://discuss.elastic.co/t/how-to-remove-a-metricbeat-daemonset/262244/2 "2021-01-26T23:40:43Z")

</div>

I have just started a Filebeat daemonset. It works, all pods are green.  
But how to delete it?

The standard command can't delete it.  
`kubectl delete -n myspace daemonset filebeat-beat-filebeat `

Damonset with Filebeat pods is automatically recreated!

```auto
    apiVersion: beat.k8s.elastic.co/v1beta1
    kind: Beat
    metadata:
      name: filebeat
      namespace: myspace 
    spec:
      type: filebeat
      version: 7.10.2
      elasticsearchRef:
        name: elasticsearch
      config:
        filebeat.autodiscover.providers:
        - node: ${NODE_NAME}
          type: kubernetes
          hints.default_config.enabled: "false"
          templates:
          - condition.equals.kubernetes.namespace: log-namespace
            config:
            - paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
              type: container
          - condition.equals.kubernetes.labels.log-label: "true"
            config:
            - paths: ["/var/log/containers/*${data.kubernetes.container.id}.log"]
              type: container
        processors:
        - add_cloud_metadata: {}
        - add_host_metadata: {}
      daemonSet:
        podTemplate:
          spec:
            serviceAccountName: filebeat
            automountServiceAccountToken: true
            terminationGracePeriodSeconds: 30
            dnsPolicy: ClusterFirstWithHostNet
            hostNetwork: true # Allows to provide richer host metadata
            containers:
            - name: filebeat
              securityContext:
                runAsUser: 0
              resources:
                limits:
                  memory: 200Mi
                  cpu: 200m
                requests:
                  cpu: 100m
                  memory: 100Mi
              volumeMounts:
              - name: varlogcontainers
                mountPath: /var/log/containers
              - name: varlogpods
                mountPath: /var/log/pods
              - name: varlibdockercontainers
                mountPath: /var/lib/docker/containers
              env:
                - name: NODE_NAME
                  valueFrom:
                    fieldRef:
                      fieldPath: spec.nodeName
            volumes:
            - name: varlogcontainers
              hostPath:
                path: /var/log/containers
            - name: varlogpods
              hostPath:
                path: /var/log/pods
            - name: varlibdockercontainers
              hostPath:
                path: /var/lib/docker/containers

```

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [January 27, 2021, 7:06am UTC](https://discuss.elastic.co/t/how-to-remove-a-metricbeat-daemonset/262244/3 "2021-01-27T07:06:11Z")

</div>

Hi,

The DaemonSet is managed by the Beat you created. If you want to delete the DaemonSet you must delete the Beat: `kubectl delete beat/filebeat -n myspace `

---

<div class="post-metadata">

**Author:** ![mchudinov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mchudinov/32/82618_2.png) [@mchudinov](https://discuss.elastic.co/u/mchudinov)\
**Post date:** [January 27, 2021, 12:01pm UTC](https://discuss.elastic.co/t/how-to-remove-a-metricbeat-daemonset/262244/4 "2021-01-27T12:01:44Z")

</div>

Thank you! It works.  
It should be noticed in the documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:22am UTC](https://discuss.elastic.co/t/how-to-remove-a-metricbeat-daemonset/262244/5 "2022-11-04T08:22:32Z")

</div>


