# RKE/Rancker 2.0 and Filebeat not sending logs

**URL:** <https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 2, 2020, 8:41pm UTC](https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406 "2020-06-02T20:41:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wrender](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrender/32/69588_2.png) [@wrender](https://discuss.elastic.co/u/wrender)\
**Post date:** [June 2, 2020, 8:41pm UTC](https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406/1 "2020-06-02T20:41:20Z")

</div>

I have a single server RKE cluster, with Rancher on top for testing. I then deployed elasticsearch and kibana using the helm charts to a namespace called elasticsearch.

I then install filebeat using the official elastic helm charts with something like this: helm install filebeat elastic/filebeat --namespace elasticsearch

Filebeat daemonset starts up, and turns green status, and I can see it is looking for logs in /var/log/containers/, but then when I go into Kibana and click "Index Management" there is no index created, and I would have expected one called filebeat-\* or something like that.

I tried installing metricbeat using the same method, and it seems to work fine, with metric information going into an index called metricbeat-\*

Is there some missing step you need to do if you are on an RKE/Rancher cluster?

---

<div class="post-metadata">

**Author:** ![wrender](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wrender/32/69588_2.png) [@wrender](https://discuss.elastic.co/u/wrender)\
**Post date:** [June 2, 2020, 9:26pm UTC](https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406/2 "2020-06-02T21:26:10Z")

</div>

It looks like it may be related to this issue. I am not running my docker data root in the typical /var/lib/docker location: [https://github.com/rancher/rancher/issues/16456](https://github.com/rancher/rancher/issues/16456)

---

<div class="post-metadata">

**Author:** ![Julien\_MAILLERET](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julien_mailleret/32/45074_2.png) [@Julien\_MAILLERET](https://discuss.elastic.co/u/Julien_MAILLERET)\
**Post date:** [June 10, 2020, 6:57am UTC](https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406/3 "2020-06-10T06:57:08Z")

</div>

Hi @wrender,  
Indeed, Filebeat pod is mounting `/var/lib/docker/containers` (see [daemonset.yaml](https://github.com/elastic/helm-charts/blob/4eceebc18194b816f8439a03c4598d0f8359769b/filebeat/templates/daemonset.yaml#L155-L157)) and is expecting to find your containers here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2020, 6:57am UTC](https://discuss.elastic.co/t/rke-rancker-2-0-and-filebeat-not-sending-logs/235406/4 "2020-07-08T06:57:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
