# Kubernetes module vs add\_kubernetes\_metadata

**URL:** <https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489>\
**Category:** Beats\
**Tags:** beats-module\
**Created:** [June 17, 2020, 2:54pm UTC](https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489 "2020-06-17T14:54:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![akrzos](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@akrzos](https://discuss.elastic.co/u/akrzos)\
**Post date:** [June 17, 2020, 2:54pm UTC](https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489/1 "2020-06-17T14:54:01Z")

</div>

If you are using the kubernetes module is there any reason to use the add\_kubernetes\_metadata processor? What is the difference between these two (module vs processor) and the use cases for each.

Thanks

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [June 18, 2020, 6:15pm UTC](https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489/2 "2020-06-18T18:15:21Z")

</div>

Hey @akrzos,

In general is not needed to use `add_kubernetes_metadata` when generating configuration using autodiscover, or when using the `kubernetes` module. Autodiscover and the `kubernetes` module include their own Kubernetes metadata.

`add_kubernetes_metadata` is useful to enrich events collected by static configurations, some examples:

- Enrich events from filebeat collecting kubernetes logs with an static `container` input: [https://github.com/elastic/beats/blob/v7.8.0/deploy/kubernetes/filebeat-kubernetes.yaml#L16](https://github.com/elastic/beats/blob/v7.8.0/deploy/kubernetes/filebeat-kubernetes.yaml#L16)
- Enrich Auditbeat events from processes running inside kubernetes containers: [https://github.com/elastic/beats/blob/v7.8.0/deploy/kubernetes/auditbeat-kubernetes.yaml#L37](https://github.com/elastic/beats/blob/v7.8.0/deploy/kubernetes/auditbeat-kubernetes.yaml#L37)
- In Metricbeat it could be also used to enrich events from the system process metricset.

---

<div class="post-metadata">

**Author:** ![akrzos](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@akrzos](https://discuss.elastic.co/u/akrzos)\
**Post date:** [June 22, 2020, 3:53pm UTC](https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489/3 "2020-06-22T15:53:35Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2020, 5:54pm UTC](https://discuss.elastic.co/t/kubernetes-module-vs-add-kubernetes-metadata/237489/4 "2020-07-20T17:54:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
