# How to stop and remove filebeat from kubernetes? (eks)

**URL:** <https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 31, 2020, 12:49pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957 "2020-12-31T12:49:10Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [December 31, 2020, 12:49pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/1 "2020-12-31T12:49:10Z")

</div>

Hello  
i installed filebeat from this link :

> **[Quickstart | Elastic Cloud on Kubernetes \[1.3\] | Elastic](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-quickstart.html)**

  
and its working.  
now i like to remove it from the eks cluster.  
how can i stop it and remove it ?  
no info in documents  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 5, 2021, 12:42am UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/2 "2021-01-05T00:42:38Z")

</div>

Did any of the answers here help - [https://www.reddit.com/r/elasticsearch/comments/kpneeb/how\_to\_uninstall\_elk\_filebeat\_from\_kubernetes/](https://www.reddit.com/r/elasticsearch/comments/kpneeb/how_to_uninstall_elk_filebeat_from_kubernetes/)?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2021, 1:07am UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/3 "2021-01-05T01:07:07Z")

</div>

Lets see

Been a while but take a look at this.... **but use at your own risk... do NOT try on production first!!!**

```
# Cleanup
#### List the pods
kubectl get pods -n kube-system --no-headers=true | awk '/filebeat/{print $1}'
### CAREFUL THIS DELETES 
kubectl get pods -n kube-system --no-headers=true | awk '/filebeat/{print $1}' | xargs kubectl delete -nkube-system pod
kubectl --namespace=kube-system delete ds/filebeat
kubectl --namespace=kube-system delete configmap/filebeat-config
kubectl --namespace=kube-system delete clusterrolebinding.rbac.authorization.k8s.io/filebeat
kubectl --namespace=kube-system delete clusterrole.rbac.authorization.k8s.io/filebeat
kubectl --namespace=kube-system delete serviceaccount/filebeat

kubectl --namespace=kube-system delete configmap/filebeat-setup-config
kubectl --namespace=kube-system delete job/filebeat-setup
```

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 5, 2021, 5:39am UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/4 "2021-01-05T05:39:34Z")

</div>

in fact the solution is much simpler if you using yml file to install it  
you just do  
kubectl delete -f filebeat.yml  
Thanks!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2021, 5:47am UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/5 "2021-01-05T05:47:44Z")

</div>

Does that clear out all the configmaps etc?

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 5, 2021, 6:14am UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/6 "2021-01-05T06:14:40Z")

</div>

clear all , then i can install again

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 5, 2021, 10:55am UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/7 "2021-01-05T10:55:47Z")

</div>

@stephenb  
you know what i m not sure as from when i used the delete  
I'm keep getting :

```auto
f2021-01-05T10:52:03.776Z INFO instance/beat.go:392 filebeat stopped.
2021-01-05T10:52:03.776Z ERROR instance/beat.go:956 Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).
Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2021, 3:26pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/8 "2021-01-05T15:26:22Z")

</div>

That means it is not completely cleaned up... Try my steps see what happens.

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 5, 2021, 5:30pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/9 "2021-01-05T17:30:08Z")

</div>

> [@stephenb](#):
>
> `kubectl get pods -n kube-system --no-headers=true | awk '/filebeat/{print $1}'`

this command gives me nothing i guess it do erase everything.  
but installing it in a complex system is not straightforward and has allot of problems  
i still struggle to make it work

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 5, 2021, 6:06pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/10 "2021-01-05T18:06:37Z")

</div>

That command would have just _ **listed** _ the filebeat pods that are present.  
If nothing returns then there are not filebeat pods.  
It looks like the data path is not cleaned up, did you put the data on a persitent disk?  
I have not looked at this in a while apologies for not being able to directly answer.

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 6, 2021, 6:13am UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/11 "2021-01-06T06:13:09Z")

</div>

@stephenb  
i checked nad they Are written to the disc on the hosting nodes under /var/containers/\*  
so you suggest to :  
kubectl delete -f filbeats.yml  
ssh to the nodes and rm -rf to every thing under /var/containers /\* ?

But i noticed that when i delete the filebeat , the filebeat log also deleted from the node disk  
And when created again it is created , so i dont think its the problem

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 6, 2021, 1:19pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/12 "2021-01-06T13:19:08Z")

</div>

@stephenb  
this is what helped in the end see my last reply

> [@Filebeat not collection logs of elastic pods](https://discuss.elastic.co/t/filebeat-not-collection-logs-of-elastic-pods/259719/4):
>
> Hi @umen any update on your side regarding that issue?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 6, 2021, 3:01pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/13 "2021-01-06T15:01:11Z")

</div>

> [@umen](#):
>
> ssh to the nodes and rm -rf to every thing under /var/containers /\* ?

I would be careful with that as you may delete other containers data, I would only delete the containers related to filebeat if / when I get a chance I will check, but I did not have this problem on a vanilla GKS (google) env.

Thanks for the update.

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 6, 2021, 3:03pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/14 "2021-01-06T15:03:16Z")

</div>

i didn't do this ... ( i alomst did )  
the link i sent was the solution  
by the way ...  
is there way just to restart elasticsearch and all its process ( beats ) without uninstalling ?  
just doing simple restart in EKS ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2021, 5:03pm UTC](https://discuss.elastic.co/t/how-to-stop-and-remove-filebeat-from-kubernetes-eks/259957/15 "2021-02-03T17:03:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
