# Journalbeat on Kubernetes

**URL:** <https://discuss.elastic.co/t/journalbeat-on-kubernetes/160603>\
**Category:** Beats\
**Tags:** journalbeat\
**Created:** [December 12, 2018, 6:41pm UTC](https://discuss.elastic.co/t/journalbeat-on-kubernetes/160603 "2018-12-12T18:41:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![przemek\_danysz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/przemek_danysz/32/18030_2.png) [@przemek\_danysz](https://discuss.elastic.co/u/przemek_danysz)\
**Post date:** [December 12, 2018, 6:41pm UTC](https://discuss.elastic.co/t/journalbeat-on-kubernetes/160603/1 "2018-12-12T18:41:01Z")

</div>

Dears,

I'm trying to run Journalbeat on Kubernetes cluster and almost all works fine 🙂  
I run pod with Privileges and access to /var/log/journal directory, so Journalbeat is reading it correctly, but....

But I want to also use Processor plugin "add\_kubernetes\_metadata" and journalbeat ends with error each time:

> Exiting: error initializing publisher: error initializing processors: Can not initialize kubernetes plugin with zero matcher plugins

But here a config for K8s:

```
  processors:
      - drop_event:
          when:
            not:
              has_fields: ['container.name']

      - add_kubernetes_metadata:
          in_cluster: true

      - add_host_metadata:
          netinfo.enabled: false
          cache.ttl: 5m

```

Pod is run under kubernetes system namespace. I also tried to run it in "default" namespace, but always end with this error.

Any ideas? I'm doing something wrong ?

Thanks!

---

<div class="post-metadata">

**Author:** ![przemek\_danysz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/przemek_danysz/32/18030_2.png) [@przemek\_danysz](https://discuss.elastic.co/u/przemek_danysz)\
**Post date:** [December 17, 2018, 12:55pm UTC](https://discuss.elastic.co/t/journalbeat-on-kubernetes/160603/2 "2018-12-17T12:55:54Z")

</div>

Nobody try use this ?  
Anyone ?

---

<div class="post-metadata">

**Author:** ![kvaps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvaps/32/41830_2.png) [@kvaps](https://discuss.elastic.co/u/kvaps)\
**Post date:** [March 12, 2019, 4:21pm UTC](https://discuss.elastic.co/t/journalbeat-on-kubernetes/160603/3 "2019-03-12T16:21:31Z")

</div>

Hi @przemek_danysz I had similar issue:

I made it working with the next settings:

```auto
    processors:
    - add_kubernetes_metadata:
        in_cluster: true
        default_indexers.enabled: false
        default_matchers.enabled: false
        indexers:
          - container:
        matchers:
          - fields:
              lookup_fields: ["container.id"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 6:47am UTC](https://discuss.elastic.co/t/journalbeat-on-kubernetes/160603/4 "2022-11-04T06:47:22Z")

</div>


