# Nginx module on k8s - access and error from the same path?

**URL:** <https://discuss.elastic.co/t/nginx-module-on-k8s-access-and-error-from-the-same-path/321126>\
**Category:** Beats\
**Tags:** docker, beats-module, filebeat\
**Created:** [December 13, 2022, 12:57pm UTC](https://discuss.elastic.co/t/nginx-module-on-k8s-access-and-error-from-the-same-path/321126 "2022-12-13T12:57:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![amir\_Bialek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amir_bialek/32/109973_2.png) [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Post date:** [December 13, 2022, 12:57pm UTC](https://discuss.elastic.co/t/nginx-module-on-k8s-access-and-error-from-the-same-path/321126/1 "2022-12-13T12:57:27Z")

</div>

Hey,

So I have a micro service with nginx, I am using filebeat nginx module to read the logs:

```auto
      filebeat.autodiscover:
        providers:
          - type: kubernetes
            hints.enabled: true
            templates:
              - condition.or:
                  - equals:
                      kubernetes.deployment.name: service1
                  - equals:
                      kubernetes.deployment.name: service2
                config:
                  - module: nginx
                    access:
                      input:
                        type: container
                        containers.ids:
                          - "${data.kubernetes.container.id}"
                        paths:
                        - /var/lib/docker/containers/${data.kubernetes.container.id}/*.log
                    error:
                      input:
                        type: container
                        containers.ids:
                          - "${data.kubernetes.container.id}"
                        paths:
                        - /var/lib/docker/containers/${data.kubernetes.container.id}/*.log
                    ingress_controller:
                      input:
                        type: container
                        containers.ids:
                          - "${data.kubernetes.container.id}"
                        paths:
                        - /var/lib/docker/containers/${data.kubernetes.container.id}/*.log

```

Now the issue is that I get 3 logs in kibana for every log on service1 & 2.  
Anyone have solution for this one?  
I can simply use filter on kibana saying error.message does not exists in filter, but any way to drop the message before it arrive to ES?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2023, 2:58pm UTC](https://discuss.elastic.co/t/nginx-module-on-k8s-access-and-error-from-the-same-path/321126/2 "2023-01-10T14:58:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
