# Metadata missing on startup

**URL:** <https://discuss.elastic.co/t/metadata-missing-on-startup/324886>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 7, 2023, 10:33am UTC](https://discuss.elastic.co/t/metadata-missing-on-startup/324886 "2023-02-07T10:33:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hdost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hdost/32/116858_2.png) [@hdost](https://discuss.elastic.co/u/hdost)\
**Post date:** [February 7, 2023, 10:33am UTC](https://discuss.elastic.co/t/metadata-missing-on-startup/324886/1 "2023-02-07T10:33:25Z")

</div>

This question seems to be in a similar vein to a different application, but I have more than just "random"

> [@Filebeat missing container k8 metadata](https://discuss.elastic.co/t/filebeat-missing-container-k8-metadata/255530):
>
> When running batch of short-lived containers (which are same docker images), on some (random) occasions k8 metadata tags are missing from some of them Also there are no errors on the Filebeat service itself when filebeat starts watching the files We have following config: filebeat.inputs: - type: docker containers.ids: - '\*' processors: - add\_kubernetes\_metadata: ~ ... ... ... Tested with Filebeat 7.6 and with latest 7.9, same issue persists Ru…

My config is similar to theirs:

```auto
    filebeat.inputs:
    - type: container
      paths:
        - /var/log/containers/*.log
      exclude_files: [<some excludes>]
      processors:
        - add_kubernetes_metadata:
            host: ${NODE_NAME}
            in_cluster: true
            matchers:
            - logs_path:
                logs_path: "/var/log/containers/"

    output.logstash:
        hosts: ["....svc.cluster.local:<SOME_PORT>"]

```

I have tried a couple of variations including adding an in memory buffer, but to no avail. It seems as if the processor is not loading info into the cache before being considered ready and so no information is loaded.  
This seems like almost an antipattern suggestion, but is there a way to force the processor to some sort of initial startup before processing any events. As it stands it seems as though messages are just tossed through without container or pod data, both of which are readily available.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2023, 12:33pm UTC](https://discuss.elastic.co/t/metadata-missing-on-startup/324886/2 "2023-03-07T12:33:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
