# K8 logging with ECK

**URL:** <https://discuss.elastic.co/t/k8-logging-with-eck/241686>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [July 17, 2020, 3:16pm UTC](https://discuss.elastic.co/t/k8-logging-with-eck/241686 "2020-07-17T15:16:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kay\_Khan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kay_khan/32/45028_2.png) [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Post date:** [July 17, 2020, 3:16pm UTC](https://discuss.elastic.co/t/k8-logging-with-eck/241686/1 "2020-07-17T15:16:36Z")

</div>

Hi,

Im interested in pushing logs from kubernetes containers to my elastic cluster are there any guides on how to implement logstash and/or filebeat with ECK?

---

<div class="post-metadata">

**Author:** ![pebrc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pebrc/32/101790_2.png) [@pebrc](https://discuss.elastic.co/u/pebrc)\
**Post date:** [July 22, 2020, 6:20am UTC](https://discuss.elastic.co/t/k8-logging-with-eck/241686/2 "2020-07-22T06:20:02Z")

</div>

ECK 1.2. now supports Beats. Take a look here [https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-quickstart.html](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-beat-quickstart.html)

---

<div class="post-metadata">

**Author:** ![Kay\_Khan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kay_khan/32/45028_2.png) [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Post date:** [August 6, 2020, 9:19am UTC](https://discuss.elastic.co/t/k8-logging-with-eck/241686/3 "2020-08-06T09:19:49Z")

</div>

Cool, however i managed to setup filebeats before ECK 1.2 was released as stand alone. I setup filbeats using the following recipies you have on github which have been super helpful [https://github.com/elastic/cloud-on-k8s/blob/1.1/config/recipes/beats/2\_filebeat-kubernetes.yaml](https://github.com/elastic/cloud-on-k8s/blob/1.1/config/recipes/beats/2_filebeat-kubernetes.yaml)

1. Im curious should i move to the ECK version since im using ECK api general elasticsearch and kibana.

2. Looking at the new version [https://github.com/elastic/cloud-on-k8s/blob/1.2/config/recipes/beats/filebeat\_autodiscover.yaml](https://github.com/elastic/cloud-on-k8s/blob/1.2/config/recipes/beats/filebeat_autodiscover.yaml) im not sure where i can define my templates and modules.

for example i have this section in my current filebeat.yml it allows me to use filebeat haproxy module. How would i set this in the ECK version. Is this feature missing to configure filebeat templates/modules?

```
data:
  filebeat.yml: |-
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          host: ${NODE_NAME}
          hints.enabled: true
          hints.default_config:
            type: container
            paths:
              - /var/log/containers/*${data.kubernetes.container.id}.log
          templates:
            - condition.or:
                - equals.kubernetes.labels.app: "cgg-haproxy"
                - equals.kubernetes.labels.app: "haproxy-test"
              config:
                - module: haproxy
                  log:
                    enabled: true
                    input:
                      type: container
                      paths:
                        - /var/log/containers/*-${data.kubernetes.container.id}.log
    processors:
      - add_cloud_metadata:
      - add_host_metadata:

    setup.dashboards.enabled: true

    setup.kibana:
      host: "https://${KIBANA_HOST:kibana}:${KIBANA_PORT:5601}"
      ssl.enabled: true
      ssl.certificate_authorities:
      - /mnt/kibana/ca.crt

    output.elasticsearch:
      hosts: ['https://${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
      username: ${ELASTICSEARCH_USERNAME}
      password: ${ELASTICSEARCH_PASSWORD}
      ssl.certificate_authorities:
      - /mnt/elastic/tls.crt
---
```

---

<div class="post-metadata">

**Author:** ![michael.morello](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael.morello/32/47448_2.png) [@michael.morello](https://discuss.elastic.co/u/michael.morello)\
**Post date:** [August 6, 2020, 2:40pm UTC](https://discuss.elastic.co/t/k8-logging-with-eck/241686/4 "2020-08-06T14:40:24Z")

</div>

Regarding your first question the main benefits about managing Beats with ECK is that all the Beats output configuration is managed for you: the certificate trust relationship between Beats, Elasticsearch and Kibana is automatically established and the output configuration (url, user, password) is also automatically set.

This way you can focus on the most meaningful Beats configuration settings.

Regarding your second question you can set this configuration right below the `config` element of the example you mentioned: [https://github.com/elastic/cloud-on-k8s/blob/1.2/config/recipes/beats/filebeat\_autodiscover.yaml#L14](https://github.com/elastic/cloud-on-k8s/blob/1.2/config/recipes/beats/filebeat_autodiscover.yaml#L14)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:06am UTC](https://discuss.elastic.co/t/k8-logging-with-eck/241686/5 "2022-11-04T08:06:45Z")

</div>


