# Kubernetes filebeat config map for pod events

**URL:** <https://discuss.elastic.co/t/kubernetes-filebeat-config-map-for-pod-events/360304>\
**Category:** Elasticsearch\
**Created:** [May 27, 2024, 2:17pm UTC](https://discuss.elastic.co/t/kubernetes-filebeat-config-map-for-pod-events/360304 "2024-05-27T14:17:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahan.d](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sahan.d/32/121815_2.png) [@sahan.d](https://discuss.elastic.co/u/sahan.d)\
**Post date:** [May 27, 2024, 2:17pm UTC](https://discuss.elastic.co/t/kubernetes-filebeat-config-map-for-pod-events/360304/1 "2024-05-27T14:17:08Z")

</div>

We have a pod that restarts randomly and we can't find the reason because Kubernetes only keeps event logs only for a short time. Even if we increase it, the logs will be lost when the pod is deleted.

Can someone help me out with the filebeat ConfigMap to log Kubernetes pod events in to Elasticsearch? I've tried different avenues but none of it worked.

I've tried with filebeat.inputs and filebeat.auto-discover but couldn't get it to work. I could get pod logs to be sent but that's not exactly what we need. We want to only send pod state events so that we can figure out what caused the restart and in the meantime to not flood elasticsearch with

---

<div class="post-metadata">

**Author:** ![MYK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/myk/32/134816_2.png) [@MYK](https://discuss.elastic.co/u/MYK)\
**Post date:** [May 27, 2024, 5:31pm UTC](https://discuss.elastic.co/t/kubernetes-filebeat-config-map-for-pod-events/360304/2 "2024-05-27T17:31:27Z")

</div>

easy way i think is to use elasticagent and add integration with kubernetes. you can find more details in Kibana integration section. look for "kubernetes"
