# Logs are missing kubernetes metadata when using filebeat \>= 8.9.0

**URL:** <https://discuss.elastic.co/t/logs-are-missing-kubernetes-metadata-when-using-filebeat-8-9-0/344693>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 10, 2023, 12:17am UTC](https://discuss.elastic.co/t/logs-are-missing-kubernetes-metadata-when-using-filebeat-8-9-0/344693 "2023-10-10T00:17:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gparks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gparks/32/50204_2.png) [@gparks](https://discuss.elastic.co/u/gparks)\
**Post date:** [October 10, 2023, 12:17am UTC](https://discuss.elastic.co/t/logs-are-missing-kubernetes-metadata-when-using-filebeat-8-9-0/344693/1 "2023-10-10T00:17:15Z")

</div>

I'm running filebeat as a daemonset in kubernetes, it was previously on 8.8.2 but when upgraded to 8.9.0 logs from the first input stop including the kubernetes metadata but logs from the ingress-nginx input continue to include the metadata.

I confirmed by downgrading back to 8.8.2 that the metadata returns. I've tested all versions up to 8.10.1 (this being the version I initially upgraded to) and they all exhibit the same problem.

I've read the [release notes](https://www.elastic.co/guide/en/beats/libbeat/8.10/release-notes-8.9.0.html) for 8.9.0 and can't find anything obviously related to it

```auto
filebeat.inputs:
- type: container
  paths:
    - /var/log/containers/*.log
  processors:
  - add_kubernetes_metadata:
      host: ${NODE_NAME}
      matchers:
      - logs_path:
          logs_path: "/var/log/containers/"
  fields_under_root: true
  exclude_files:
   - "/var/log/containers/nginx-ingress.*log"
   - "/var/log/containers/ingress-nginx.*log"
  fields:
    log_type: system
- type: container
  paths:
    - /var/log/containers/nginx-ingress*.log
    - /var/log/containers/ingress-nginx*.log
  processors:
  - add_kubernetes_metadata:
      host: ${NODE_NAME}
      matchers:
      - logs_path:
          logs_path: "/var/log/containers/"
  fields_under_root: true
  fields:
    log_type: nginx
    kubernetes_namespace: ${POD_NAMESPACE}
    role: ingress-nginx
  close_renamed: true

```

---

<div class="post-metadata">

**Author:** ![GauravBhinda](https://avatars.discourse-cdn.com/v4/letter/g/91b2a8/32.png) [@GauravBhinda](https://discuss.elastic.co/u/GauravBhinda)\
**Post date:** [October 31, 2023, 6:07am UTC](https://discuss.elastic.co/t/logs-are-missing-kubernetes-metadata-when-using-filebeat-8-9-0/344693/2 "2023-10-31T06:07:41Z")

</div>

hey @gparks , I'm encountering the same problem. Are you able to solve it yet?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2023, 8:07am UTC](https://discuss.elastic.co/t/logs-are-missing-kubernetes-metadata-when-using-filebeat-8-9-0/344693/3 "2023-11-28T08:07:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
