# Not Getting Kubernetes related filters in Kibana when exporting logs from Logstash

**URL:** <https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [May 15, 2023, 4:15am UTC](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400 "2023-05-15T04:15:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akshay04](https://avatars.discourse-cdn.com/v4/letter/a/bb73d2/32.png) [@Akshay04](https://discuss.elastic.co/u/Akshay04)\
**Post date:** [May 15, 2023, 4:15am UTC](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400/1 "2023-05-15T04:15:51Z")

</div>

Hello,

I have configured Fluentbit in my k8s cluster to send logs to S3 and ELK stack to get logs from S3 and Visualise in Kibana. When I create Dataview in kibana for the Index, the kibana dashboard is not giving filters related to Kubernetes (e.g. kubernetes.namespace\_name).

Following is my configuration of Fluentbit :

```auto
config:
  service: |
    [SERVICE]
        Daemon Off
        Flush {{ .Values.flush }}
        Log_Level {{ .Values.logLevel }}
        Parsers_File parsers.conf
        HTTP_Server On
        HTTP_Listen 0.0.0.0
        HTTP_Port {{ .Values.metricsPort }}
        Health_Check On
        storage.sync normal
        storage.checksum off
        @INCLUDE application-log.conf        

  inputs: |
    [INPUT]
        Name tail
        Tag kube.*
        Path /var/log/containers/*.log
        Parser docker
        Mem_Buf_Limit 50MB
        Skip_Long_Lines On
        Refresh_Interval 10        

  filters: |
    [FILTER]
        Name kubernetes
        Match kube.*
        Kube_URL https://kubernetes.default.svc:443
        Merge_Log On
        Merge_Log_Trim On
        K8S-Logging.Parser On
        K8S-Logging.Exclude On
        Annotations Off
        Labels On

    [FILTER]
        Name modify
        Match *
        Remove kubernetes.container_hash
        Remove kubernetes.docker_id
        Remove kubernetes.pod_id

  outputs: |
    [OUTPUT]
        Name s3
        Match *
        bucket mys3
        region us-east-2
        use_put_object On
        compression gzip
        total_file_size 250M
        upload_timeout 2m
        s3_key_format /$TAG[2]/$TAG[3]/%Y/%m/%d/$TAG[4]__$TAG[5]/$UUID-%M-%S.gz
        s3_key_format_tag_delimiters ._

  customParsers: |
    [PARSER]
        Name docker
        Format json
        Time_Key time
        Time_Format %Y-%m-%dT%H:%M:%S.%L
        Time_Keep On

  upstream: {}

```

Please suggest if any other config needs to done.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2023, 11:44pm UTC](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400/2 "2023-05-17T23:44:02Z")

</div>

Welcome to our community! 😃

What does one of the events look like when you view it in Discover?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2023, 11:44pm UTC](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400/3 "2023-06-14T23:44:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
