# Problem to update to filebeat 7.7.0 and parser nginx-ingress-controller on Kubernetes

**URL:** <https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 13, 2020, 2:44pm UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461 "2020-05-13T14:44:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [May 13, 2020, 2:44pm UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461/1 "2020-05-13T14:44:24Z")

</div>

Hi!

I was using Kubernetes with this version of Filebeat: **[docker.elastic.co/beats/filebeat:7.3.2](http://docker.elastic.co/beats/filebeat:7.3.2)**

In order to use the new functionalities to parser **nginx-ingress-controller** I've update to **[docker.elastic.co/beats/filebeat:7.7.0](http://docker.elastic.co/beats/filebeat:7.7.0)**

But with my configuration, only changing the image I have some errors.

```auto
2020-05-13T14:26:25.084Z	ERROR	[kubernetes]	add_kubernetes_metadata/matchers.go:91	Error extracting container id - source value does not contain matcher's logs_path '/var/lib/docker/containers/'.

```

I read that was removing the support for **`add_kubernetes_metadata`**  
[https://www.elastic.co/guide/en/beats/libbeat/current/release-notes-7.7.0.html](https://www.elastic.co/guide/en/beats/libbeat/current/release-notes-7.7.0.html)

So... I don't know how I should configure my filebeat. I'm using this configuration, I should replace by another thing?

```auto
    filebeat.inputs:
    - type: container
      paths:
        - /var/log/containers/*.log
      multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
      multiline.negate: false
      multiline.match: after
      processors:
        - add_kubernetes_metadata:
            in_cluster: true
            host: ${NODE_NAME}
            matchers:
            - logs_path:
                logs_path: "/var/log/containers/"

```

Thank you very much

---

<div class="post-metadata">

**Author:** ![David\_Oceans](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/david_oceans/32/51452_2.png) [@David\_Oceans](https://discuss.elastic.co/u/David_Oceans)\
**Post date:** [May 13, 2020, 3:08pm UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461/2 "2020-05-13T15:08:51Z")

</div>

Hi,

I tried updating 7.7.0 and removing this part an the errors disappear but I'm not sure if I have to change it instead of removing.

By the other hand, to parser nginx-ingress-controller I don't have the logs in files

```auto
kubectl exec -ti nginx-ingress-controller-5c64888b48-h5mxp -n ingress-controller bash
bash-5.0$ ls -l /var/log/nginx/
total 0
lrwxrwxrwx 1 www-data www-data 11 Feb 24 12:47 access.log -> /dev/stdout
lrwxrwxrwx 1 www-data www-data 11 Feb 24 12:47 error.log -> /dev/stderr

```

I've tried with and without path, but doesn't log nothing in Kibana

```auto
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          hints.enabled: true
          templates:
            - condition:
                equals:
                  kubernetes.labels.app: nginx-ingress
              config:
                - module: nginx
                  ingress_controller:
                    enabled: true
                    var.paths: ["/var/log//nginx/*.log"]

```

The condition I think is correct, right?

```auto
Name: nginx-ingress-controller-5c64888b48-h5mxp
Namespace: ingress-controller
Priority: 0
Node: gke-apps-stage-default-node-pool-d001bfd8-tfpq/10.31.0.21
Start Time: Mon, 23 Mar 2020 12:38:08 +0100
Labels: app=nginx-ingress
                app.kubernetes.io/component=controller
                pod-template-hash=5c64888b48
                release=nginx-ingress

```

I don't know where is the error, I think is about the path, but what do you think?

Thank you very much

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [May 14, 2020, 2:57pm UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461/3 "2020-05-14T14:57:13Z")

</div>

Hey @David_Oceans,

Take into account that filebeat runs in the host, so it may not have access to the files in the container (like these `/var/log/nginx/*.log`). What one usually does is to use a container input, that collects logs from stdout/stderr.  
You have some examples in the documentation: [https://www.elastic.co/guide/en/beats/filebeat/7.7/configuration-autodiscover.html](https://www.elastic.co/guide/en/beats/filebeat/7.7/configuration-autodiscover.html)

In your case it would be something like this:

```auto
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          hints.enabled: true
          templates:
            - condition:
                equals:
                  kubernetes.labels.app: nginx-ingress
              config:
                - module: nginx
                  ingress_controller:
                    enabled: true
                    input:
                      type: container
                      paths:
                        - /var/log/containers/*-${data.kubernetes.container.id}.log

```

Alternativelly you can use [hints-based autodiscover](https://www.elastic.co/guide/en/beats/filebeat/7.7/configuration-autodiscover-hints.html), without templates:

```auto
    filebeat.autodiscover:
      providers:
        - type: kubernetes
          hints.enabled: true

```

And add annotations like these ones to your ingress controller pods:

```auto
  co.elastic.logs/module: nginx
  co.elastic.logs/fileset.stdout: ingress_controller
  co.elastic.logs/fileset.stderr: error

```

---

<div class="post-metadata">

**Author:** ![tolausson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tolausson/32/69741_2.png) [@tolausson](https://discuss.elastic.co/u/tolausson)\
**Post date:** [June 4, 2020, 10:25pm UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461/4 "2020-06-04T22:25:52Z")

</div>

I'm having a similar issue. It seems that the error is coming from that the default logs\_path is picked up (rather than the configured one).

Notice how the error mentions /var/lib/docker/containers,  
but the matcher's logs\_path is /var/log/containers  
This default can be found in the [code here](https://github.com/elastic/beats/blob/v7.7.1/filebeat/processor/add_kubernetes_metadata/matchers.go#L141)

I have not been able to solve it myself.

---

<div class="post-metadata">

**Author:** ![rhallier](https://avatars.discourse-cdn.com/v4/letter/r/edb3f5/32.png) [@rhallier](https://discuss.elastic.co/u/rhallier)\
**Post date:** [June 15, 2020, 2:52pm UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461/5 "2020-06-15T14:52:44Z")

</div>

Well, I'm running into the same problem. It seems that the matcher logs\_path is not picked up, only the default value (/var/lib/docker/containers)  
My version of Filebeat is 7.7.1  
Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2020, 2:52pm UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461/6 "2020-07-13T14:52:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [July 14, 2020, 8:33am UTC](https://discuss.elastic.co/t/problem-to-update-to-filebeat-7-7-0-and-parser-nginx-ingress-controller-on-kubernetes/232461/7 "2020-07-14T08:33:42Z")

</div>

Hi everyone!

I would suggest upgrading to `7.8` since this seems to be a regression until `7.7.1`.

C.
