# Processing fields with Filebeat via Kubernetes annotations

**URL:** <https://discuss.elastic.co/t/processing-fields-with-filebeat-via-kubernetes-annotations/222965>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 10, 2020, 3:28pm UTC](https://discuss.elastic.co/t/processing-fields-with-filebeat-via-kubernetes-annotations/222965 "2020-03-10T15:28:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vicmarbev](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@vicmarbev](https://discuss.elastic.co/u/vicmarbev)\
**Post date:** [March 10, 2020, 3:28pm UTC](https://discuss.elastic.co/t/processing-fields-with-filebeat-via-kubernetes-annotations/222965/1 "2020-03-10T15:28:05Z")

</div>

Hi, we've been looking into bypassing logstash and send logs directly from filebeat to elasticsearch. As we have a kubernetes deployment, as seen in [here](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-autodiscover-hints.html) we can add annotations to handle things like multiline, excluded lines and modules. My question is: how would I go about handling applying a grok to a log line and extracting fields like timestamp, log level, etc? Is "co.elastic.logs/processors" the annotation for this? If so, how would I define one processor?

Right now in logstash we have (among other things) the following grok:

```
grok {
match => [ "message",
          "(?<timestamp>%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME})\s+%{LOGLEVEL:level} %{NUMBER:pid} --- .+? :\s+(?<logmessage>.*)"
        ]}

```

What is the equivalent in kubernetes annotation?

---

<div class="post-metadata">

**Author:** ![dkow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkow/32/47340_2.png) [@dkow](https://discuss.elastic.co/u/dkow)\
**Post date:** [March 11, 2020, 7:54am UTC](https://discuss.elastic.co/t/processing-fields-with-filebeat-via-kubernetes-annotations/222965/2 "2020-03-11T07:54:45Z")

</div>

Hi @vicmarbev, thanks for your question. We've moved your post to Beats/Filebeat part of Discuss as it's mostly about Filebeat configuration in Kubernetes and not specific to ECK ([https://github.com/elastic/cloud-on-k8s](https://github.com/elastic/cloud-on-k8s)).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2020, 7:54am UTC](https://discuss.elastic.co/t/processing-fields-with-filebeat-via-kubernetes-annotations/222965/3 "2020-04-08T07:54:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
