# Parsing specific files with Kubernetes autodiscover (hints)

**URL:** <https://discuss.elastic.co/t/parsing-specific-files-with-kubernetes-autodiscover-hints/154344>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 28, 2018, 2:38pm UTC](https://discuss.elastic.co/t/parsing-specific-files-with-kubernetes-autodiscover-hints/154344 "2018-10-28T14:38:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![havlan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/havlan/32/32379_2.png) [@havlan](https://discuss.elastic.co/u/havlan)\
**Post date:** [October 28, 2018, 2:38pm UTC](https://discuss.elastic.co/t/parsing-specific-files-with-kubernetes-autodiscover-hints/154344/1 "2018-10-28T14:38:01Z")

</div>

Is it possible to log or tail specific files specified with Kuberneres filebeat hints or something? Say a service is logging specific events to a file, is it possible to extract these with filebeat? Is hint modules the way to go to achieve this?

Thanks

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [October 28, 2018, 11:04pm UTC](https://discuss.elastic.co/t/parsing-specific-files-with-kubernetes-autodiscover-hints/154344/2 "2018-10-28T23:04:50Z")

</div>

Hi @havlan,

By default (when using our manifests) Filebeat is configured to retrieve logs from containers stdout/stderr. If you are referring to a container writing to a log file (instead of stdout/stderr), I would recommend using the streaming sidecar approach: [https://kubernetes.io/docs/concepts/cluster-administration/logging/#streaming-sidecar-container](https://kubernetes.io/docs/concepts/cluster-administration/logging/#streaming-sidecar-container)

Filebeat doesn't have access to files inside your containers, but you can just create another container in the same pod, and make it tail the log file so it hits stdout. This way Filebeat will collect it in the common way.

Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2018, 11:04pm UTC](https://discuss.elastic.co/t/parsing-specific-files-with-kubernetes-autodiscover-hints/154344/3 "2018-11-25T23:04:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
