# \[Kubernetes Integration\] Custom ingest pipeline for subset of k8s cluster's container's logs

**URL:** <https://discuss.elastic.co/t/kubernetes-integration-custom-ingest-pipeline-for-subset-of-k8s-clusters-containers-logs/314601>\
**Category:** Elastic Agent\
**Tags:** filebeat\
**Created:** [September 16, 2022, 8:55pm UTC](https://discuss.elastic.co/t/kubernetes-integration-custom-ingest-pipeline-for-subset-of-k8s-clusters-containers-logs/314601 "2022-09-16T20:55:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![woodywoodsta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/woodywoodsta/32/107962_2.png) [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Post date:** [September 16, 2022, 8:55pm UTC](https://discuss.elastic.co/t/kubernetes-integration-custom-ingest-pipeline-for-subset-of-k8s-clusters-containers-logs/314601/1 "2022-09-16T20:55:11Z")

</div>

I'm using the Kubernetes Integration managed via fleet to collect container logs from my k8s cluster. At the moment, logs from all containers are passed through the same pipeline by means of the integration.

I have a new ingest pipeline that I would like to use for only some of my containers' logs, and I would like to exclude these logs from the default pipeline - is there a way that this can be achieved?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 16, 2022, 10:19pm UTC](https://discuss.elastic.co/t/kubernetes-integration-custom-ingest-pipeline-for-subset-of-k8s-clusters-containers-logs/314601/2 "2022-09-16T22:19:32Z")

</div>

Which integration?

Is it your custom pipeline or one of the OOTB integrations?

If it a pipeline you wrote you can create a top level pipeline which call the other pipelines based on condition, see [here](https://discuss.elastic.co/t/making-docker-container-logs-go-through-the-right-beats-module-for-processing/312126/9) for an example

---

<div class="post-metadata">

**Author:** ![woodywoodsta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/woodywoodsta/32/107962_2.png) [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Post date:** [September 17, 2022, 12:44pm UTC](https://discuss.elastic.co/t/kubernetes-integration-custom-ingest-pipeline-for-subset-of-k8s-clusters-containers-logs/314601/3 "2022-09-17T12:44:50Z")

</div>

The Kubernetes integration -\> [Kubernetes | Elastic docs](https://docs.elastic.co/en/integrations/kubernetes)

I think conditional pipeline references might be exactly what I'm looking for, thank you! Will try it first and mark as solution if it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2022, 12:45pm UTC](https://discuss.elastic.co/t/kubernetes-integration-custom-ingest-pipeline-for-subset-of-k8s-clusters-containers-logs/314601/4 "2022-10-15T12:45:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
