# Log Path for ECK Agent Daemonset

**URL:** <https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [May 27, 2022, 5:39pm UTC](https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825 "2022-05-27T17:39:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rstasiunas1](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@rstasiunas1](https://discuss.elastic.co/u/rstasiunas1)\
**Post date:** [May 27, 2022, 5:39pm UTC](https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825/1 "2022-05-27T17:39:02Z")

</div>

I deployed the Kubernetes integration to an ECK daemonset deployment version 8.2.2 in Amazon EKS running on Bottlerocket hosts. I’m not getting any container or audit logs. When I exec into one of the agent pods, there is no path for /var/log/kubernetes`or`/var/log/containers` . Is this expected or do I need to update the paths to something else?

---

<div class="post-metadata">

**Author:** ![framsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/framsouza/32/95958_2.png) [@framsouza](https://discuss.elastic.co/u/framsouza)\
**Post date:** [May 30, 2022, 9:28am UTC](https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825/2 "2022-05-30T09:28:07Z")

</div>

Hello,

By default, Kubernetes integration collect logs using the **/var/log/containers/\*${kubernetes.container.id}.log** path and the audit logs on **/var/log/kubernetes/kube-apiserver-audit.log** , if you are sending logs to another path you should adjust it accordingly,

You can read more about it here, [Kubernetes | Elastic Documentation](https://docs.elastic.co/integrations/kubernetes)

---

<div class="post-metadata">

**Author:** ![rstasiunas1](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@rstasiunas1](https://discuss.elastic.co/u/rstasiunas1)\
**Post date:** [June 9, 2022, 7:45pm UTC](https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825/3 "2022-06-09T19:45:41Z")

</div>

Correct, however it appears that the problem is the default deployment of the agent via the operator does not include the volume mount/claims to be able to read those paths. I'm validating this now, but it appears that the following needs to be manually added for any ECK managed agents that will be configured to use the Kubernetes integration package:

```auto
        containers:
        - name: agent
          volumeMounts:
          - mountPath: /var/lib/docker/containers
            name: varlibdockercontainers
          - mountPath: /var/log/containers
            name: varlogcontainers
          - mountPath: /var/log/pods
            name: varlogpods
        volumes:
        - name: varlibdockercontainers
          hostPath:
            path: /var/lib/docker/containers
        - name: varlogcontainers
          hostPath:
            path: /var/log/containers
        - name: varlogpods
          hostPath:
            path: /var/log/pods

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2022, 7:46pm UTC](https://discuss.elastic.co/t/log-path-for-eck-agent-daemonset/305825/4 "2022-07-07T19:46:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
