# NGINX Ingress controller + Filebeat with NGINX module

**URL:** <https://discuss.elastic.co/t/nginx-ingress-controller-filebeat-with-nginx-module/291824>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 14, 2021, 3:32pm UTC](https://discuss.elastic.co/t/nginx-ingress-controller-filebeat-with-nginx-module/291824 "2021-12-14T15:32:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anton-johansson](https://avatars.discourse-cdn.com/v4/letter/a/51bf81/32.png) [@anton-johansson](https://discuss.elastic.co/u/anton-johansson)\
**Post date:** [December 14, 2021, 3:32pm UTC](https://discuss.elastic.co/t/nginx-ingress-controller-filebeat-with-nginx-module/291824/1 "2021-12-14T15:32:17Z")

</div>

Hey! We're using the NGINX Ingress Controller ([GitHub - kubernetes/ingress-nginx: NGINX Ingress Controller for Kubernetes](https://github.com/kubernetes/ingress-nginx)), hosted in our Kubernetes cluster. We're using Filebeat deployed as a DaemonSet that parses logs and pushes to our central Elasticsearch.

The Ingress controller logs three different types of logs in the same output stream:

- Access logs
- NGINX error logs
- Ingress Controller logs

I've tried using NGINX module of Filebeat for all three types to read from the same log file, but it does not work very well. Here is my configuration:

```auto
    logging:
      level: info
    filebeat:
      autodiscover:
        providers:
          - type: kubernetes
            labels:
              dedot: true
            annotations:
              dedot: true
            templates:
              - condition:
                  equals:
                    kubernetes.container.name: "nginx-ingress-controller"
                config:
                  - module: nginx
                    access:
                      enabled: true
                      input:
                        type: container
                        format: cri
                        paths:
                          - "/var/log/containers/${data.kubernetes.pod.name}_${data.kubernetes.namespace}_${data.kubernetes.container.name}-${data.kubernetes.container.id}.log"
                        symlinks: true
                    error:
                      enabled: true
                      input:
                        type: container
                        format: cri
                        paths:
                          - "/var/log/containers/${data.kubernetes.pod.name}_${data.kubernetes.namespace}_${data.kubernetes.container.name}-${data.kubernetes.container.id}.log"
                        symlinks: true
                    ingress_controller:
                      enabled: true
                      input:
                        type: container
                        format: cri
                        paths:
                          - "/var/log/containers/${data.kubernetes.pod.name}_${data.kubernetes.namespace}_${data.kubernetes.container.name}-${data.kubernetes.container.id}.log"
                        symlinks: true
    output:
      elasticsearch:
        hosts:
          - 'central-elasticsearch:9200'

```

Each kind gets errors when it reaches a format that it doesn't support. These three types seem to be supported to only look at **different** log files. Does anyone have any suggestions on how we can solve this?

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [December 15, 2021, 5:26am UTC](https://discuss.elastic.co/t/nginx-ingress-controller-filebeat-with-nginx-module/291824/2 "2021-12-15T05:26:33Z")

</div>

Not sure if there is a good solution here hmmm could you try separating the config into three providers?

```auto
    logging:
      level: info
    filebeat:
      autodiscover:
        providers:
          - type: kubernetes
            labels:
              dedot: true
            annotations:
              dedot: true
            templates:
              - condition:
                  equals:
                    kubernetes.container.name: "nginx-ingress-controller"
                config:
                  - module: nginx
                    access:
                      enabled: true
                      input:
                        type: container
                        format: cri
                        paths:
                          - "/var/log/containers/${data.kubernetes.pod.name}_${data.kubernetes.namespace}_${data.kubernetes.container.name}-${data.kubernetes.container.id}.log"
                        symlinks: true
          - type: kubernetes
            labels:
              dedot: true
            annotations:
              dedot: true
            templates:
              - condition:
                  equals:
                    kubernetes.container.name: "nginx-ingress-controller"
                config:
                  - module: nginx
                   error:
                      enabled: true
                      input:
                        type: container
                        format: cri
                        paths:
                          - "/var/log/containers/${data.kubernetes.pod.name}_${data.kubernetes.namespace}_${data.kubernetes.container.name}-${data.kubernetes.container.id}.log"
                        symlinks: true

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 12, 2022, 7:27am UTC](https://discuss.elastic.co/t/nginx-ingress-controller-filebeat-with-nginx-module/291824/3 "2022-01-12T07:27:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
