# Segregate filebeat log from kubernetes

**URL:** <https://discuss.elastic.co/t/segregate-filebeat-log-from-kubernetes/353855>\
**Category:** Beats\
**Tags:** docker, kql-kibana-query-language, filebeat\
**Created:** [February 22, 2024, 7:50am UTC](https://discuss.elastic.co/t/segregate-filebeat-log-from-kubernetes/353855 "2024-02-22T07:50:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![srinikar87](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srinikar87/32/131645_2.png) [@srinikar87](https://discuss.elastic.co/u/srinikar87)\
**Post date:** [February 22, 2024, 7:50am UTC](https://discuss.elastic.co/t/segregate-filebeat-log-from-kubernetes/353855/1 "2024-02-22T07:50:39Z")

</div>

How to segregate log stream messages with kubernetes pod name and namespace and container name

 ![Elasticstack](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8e29600d3a5128bb8fc6f6d9dbaf8e895ff54b8d.jpeg)

Filebeat configuration

```
    dnsPolicy: ClusterFirstWithHostNet
    hostNetwork: true
    securityContext:
      runAsUser: 0
    containers:
    - name: filebeat
      volumeMounts:
      - name: varlogcontainers
        mountPath: /var/log/containers
      - name: varlogpods
        mountPath: /var/log/pods
      - name: varlibdockercontainers
        mountPath: /var/lib/docker/containers
    volumes:
    - name: varlogcontainers
      hostPath:
        path: /var/log/containers
    - name: varlogpods
      hostPath:
        path: /var/log/pods
    - name: varlibdockercontainers
      hostPath:
        path: /var/lib/docker/containers

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2024, 9:51am UTC](https://discuss.elastic.co/t/segregate-filebeat-log-from-kubernetes/353855/2 "2024-03-21T09:51:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
