# Kubernetes - Multiple cluster on same Elastic installation

**URL:** <https://discuss.elastic.co/t/kubernetes-multiple-cluster-on-same-elastic-installation/265423>\
**Category:** Elastic Observability\
**Created:** [February 25, 2021, 2:28am UTC](https://discuss.elastic.co/t/kubernetes-multiple-cluster-on-same-elastic-installation/265423 "2021-02-25T02:28:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dekim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dekim/32/68690_2.png) [@dekim](https://discuss.elastic.co/u/dekim)\
**Post date:** [February 25, 2021, 2:28am UTC](https://discuss.elastic.co/t/kubernetes-multiple-cluster-on-same-elastic-installation/265423/1 "2021-02-25T02:28:41Z")

</div>

Hello guys!

We are currently using Elastic to monitor our stack.

We do have multiple GKE (Google Kubernetes Engine) cluster, and I would like to have their logs sent to the same Elastic Instance.

Is there a recommended way to create something like a "namespace" or something similar?

Our goal is to be able to query by "cluster"

Thanks!

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 10, 2021, 7:15pm UTC](https://discuss.elastic.co/t/kubernetes-multiple-cluster-on-same-elastic-installation/265423/2 "2021-03-10T19:15:58Z")

</div>

Hi @dekim,

that's not an uncommon scenario. What worked for me so far is to encode the cluster identifier in the index names (such as `logs-cluster-${cluster_id}`) as well as add a field upon ingestion that contains the cluster identifier. If you're using Filebeat or Elastic Agent you could achieve the latter using the [`add_kubernetes_metadata` processor](https://www.elastic.co/guide/en/beats/filebeat/current/add-kubernetes-metadata.html), which can add labels of the monitored resource to each document.

This then provides the flexibility to limit the queried indices to a cluster or query all of `logs-*` but filter or aggregate over the cluster identifier in the labels.

---

<div class="post-metadata">

**Author:** ![dekim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dekim/32/68690_2.png) [@dekim](https://discuss.elastic.co/u/dekim)\
**Post date:** [March 20, 2021, 1:25pm UTC](https://discuss.elastic.co/t/kubernetes-multiple-cluster-on-same-elastic-installation/265423/3 "2021-03-20T13:25:49Z")

</div>

Awesome!

I will try this out 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:25am UTC](https://discuss.elastic.co/t/kubernetes-multiple-cluster-on-same-elastic-installation/265423/4 "2022-11-04T08:25:00Z")

</div>


