# Kubernetes labels are missing in pod and container metricsets

**URL:** <https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [August 16, 2019, 1:45pm UTC](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505 "2019-08-16T13:45:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 16, 2019, 1:45pm UTC](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505/1 "2019-08-16T13:45:00Z")

</div>

Hi,

I am currently evaluating different approaches to filter filter for deployments / statefulsets and show the child pods and containers including their metrics.

I noticed that in all metricsets having the prefix state\_ the kubernetes labels are shown like this:

```
kubernetes.labels.appl:	redis
kubernetes.labels.cluster: poc
kubernetes.labels.part-of: elasticStack

```

In container and pod events (without stat\_ prefix, these labels are stored in a different manner:

```
kubernetes.container._module.labels.appl: redis
kubernetes.container._module.labels.cluster: poc
kubernetes.container._module.labels.part-of: elasticStack

```

For pods they are stored below `kubernetes.pod._module.labels.*`.

Could you please tell me:

1. why did you choose different fields for storing the same logical data?
2. Is there any method available in kibana to filter for joining / combining both fields to a container? Creating a manual filter with an ES-Query where I query both fields with or condition is not an option. That is unable to be used by normal users with dynamically changing filter queries.
3. Is there any option in metricbeat NOT to add .\_module to the labels? I would like to see all kubernetes labels in kubernetes.labels - regardless of the module which captured it / which kubernetes resource is affected.
4. If currently no solution is available my only idea is writing a logstash ruby filter which will dynamically clone the the field `kubernetes.<module>._module.labels.*` to `kubernetes.labels.*`

I am open for any solutions. So hopefully I have just missed some easy option, because I don't think that my usecase is so special.

thanks and regards, Andreas

---

<div class="post-metadata">

**Author:** ![pmercado](https://avatars.discourse-cdn.com/v4/letter/p/59ef9b/32.png) [@pmercado](https://discuss.elastic.co/u/pmercado)\
**Post date:** [August 19, 2019, 2:41pm UTC](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505/2 "2019-08-19T14:41:37Z")

</div>

Hi @asp,

unfortunately I'm unable to tell you why this is designed as is, I'm leaving that question open so some of the beats/metricbeats members can clarify. I also wonder why `_module` is there and if underscore has any special meaning.

I opened an issue I hope will be working if soon if I get no comments preventing it, that would do a more homogeneous use of labels reporting path and some pre-processing filtering: [https://github.com/elastic/beats/issues/12938](https://github.com/elastic/beats/issues/12938)

In the mean time, I only can point you to the drop fields processor to solve `3.`: [https://www.elastic.co/guide/en/beats/metricbeat/current/drop-fields.html](https://www.elastic.co/guide/en/beats/metricbeat/current/drop-fields.html)

I haven't tested it, and the documentation doesn't indicate if the fields need to be exact path, can be partials, or if wildcards are allowed ... hope that helps anyway

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 20, 2019, 6:38am UTC](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505/3 "2019-08-20T06:38:23Z")

</div>

@pmercado thanks for your reply.

I am using following workaround now:  
ship all metricbeat probes to logstash and copy all fields below \_module to kubernetes root.

Details can be found here. It is not as generic as it should, but it is the fastest workaround which works for me.

> [@Which ways to copy subfields of kubernetes.container.\_module.labels.\* to kubernetes.lables.\*?](https://discuss.elastic.co/t/which-ways-to-copy-subfields-of-kubernetes-container-module-labels-to-kubernetes-lables/195546/5):
>
> mutate+copy is a no-op if a field does not exist, so you can compress this down to mutate { copy =\> { "[kubernetes][container][\_module][labels]" =\> "[kubernetes][labels]" "[kubernetes][container][\_module][namespace]" =\> "[kubernetes][namespace]" "[kubernetes][container][\_module][node]" =\> "[kubernetes][node]" "[kubernetes][container][\_module][pod]" =\> "[kubernetes][pod]" "[kubernetes][pod][\_module][labels]" =\> "[kubern…

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [August 30, 2019, 1:41pm UTC](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505/4 "2019-08-30T13:41:36Z")

</div>

This is bug introduced earlier and just got fixed with [https://github.com/elastic/beats/pull/13433](https://github.com/elastic/beats/pull/13433)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 1:41pm UTC](https://discuss.elastic.co/t/kubernetes-labels-are-missing-in-pod-and-container-metricsets/195505/5 "2019-09-27T13:41:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
