# Logs nicely parsed but not showing in dashboards for nginx module in kubernetes

**URL:** <https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443>\
**Category:** Beats\
**Created:** [November 15, 2020, 5:40pm UTC](https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443 "2020-11-15T17:40:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 15, 2020, 5:40pm UTC](https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443/1 "2020-11-15T17:40:01Z")

</div>

Hello,  
I am running my nginx container in kubernetes and using nginx module I am able to parse logs and show them nicely in kibana discover. I also see ingest pipelines for nginx in kibana. My setup is:  
Filebeat daemonset -\> Elasticsearch -\> Kibana.  
From the documentation I can see that nginx module should bring with its functionality also some dashboards but when I open them I see no data errors.

can someone advise what is the problem here ? Why are the data not showed in dashboards created by nginx module when the data is parsed by nginx module ?

I have basically 3 containers:

1. nginx-ingress-controller - this is parsed using nginx module
2. app-p-backend - this is parsed using custom ingest pipeline (see pipeline call call\_pipelines)
3. app-p-frontend - this is parsed using custom ingest pipeline (see pipeline call call\_pipelines)

Regarding parsing everything is great, only problem I have that I dont have nginx data in dashboards for nginx module.

Here is my kubernetes configmap yaml:

```auto
---
apiVersion: v1
kind: ConfigMap
metadata:
  name: filebeat-config
  namespace: kube-logging
  labels:
    k8s-app: filebeat
data:
  filebeat.yml: |-
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          node: ${NODE_NAME}
          templates:
            - condition:
                contains:
                  kubernetes.container.name: "nginx-ingress-controller"
              config:
                - module: nginx
                  access:
                    input:
                      type: container
                      paths:
                        - /var/log/containers/*-${data.kubernetes.container.id}.log
            - condition:
                contains:
                  kubernetes.container.name: "app-p-backend"
              config:
                - type: container
                  paths:
                    - /var/log/containers/*-${data.kubernetes.container.id}.log
            - condition:
                contains:
                  kubernetes.container.name: "app-p-frontend"
              config:
                - type: container
                  paths:
                    - /var/log/containers/*-${data.kubernetes.container.id}.log

    filebeat.modules:
    - module: nginx
    fields:
      logtype: kubernetes
      kubernetes.cluster.name: xyz-p-aks-cluster
      environment: develop
    fields_under_root: true

    setup.template.name: "logs_xyz_filebeat"
    setup.template.pattern: "logs_xyz_filebeat-%{[agent.version]}-*"
    setup.ilm.enabled: false

    processors:
      - add_cloud_metadata:
      - add_host_metadata:
      - add_kubernetes_metadata:
          host: ${NODE_NAME}
          in_cluster: true

    output.elasticsearch:
      pipeline: call_pipelines
      hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
      username: ${ELASTICSEARCH_USERNAME}
      password: ${ELASTICSEARCH_PASSWORD}
      index: "logs_skv_filebeat-%{[agent.version]}-%{+yyyy.MM.dd}"

    setup.kibana:
      host: "https://kibana_host:443"
      username: "elastic"
      password: ${ELASTICSEARCH_PASSWORD

```

---

<div class="post-metadata">

**Author:** ![dkow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkow/32/47340_2.png) [@dkow](https://discuss.elastic.co/u/dkow)\
**Post date:** [November 16, 2020, 6:03am UTC](https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443/2 "2020-11-16T06:03:47Z")

</div>

Hey @Palino1611, thanks for your question.

I've moved your question to dedicated Beats forum as it seems you are not using [ECK Operator](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-overview.html) for orchestration.

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 16, 2020, 8:48pm UTC](https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443/3 "2020-11-16T20:48:42Z")

</div>

anybody any idea what could be wrong here ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2020, 10:48pm UTC](https://discuss.elastic.co/t/logs-nicely-parsed-but-not-showing-in-dashboards-for-nginx-module-in-kubernetes/255443/4 "2020-12-14T22:48:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
