# Sending nginx logs from other pods to an ECK elasticsearch via Beats

**URL:** <https://discuss.elastic.co/t/sending-nginx-logs-from-other-pods-to-an-eck-elasticsearch-via-beats/375265>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 1, 2025, 1:23pm UTC](https://discuss.elastic.co/t/sending-nginx-logs-from-other-pods-to-an-eck-elasticsearch-via-beats/375265 "2025-03-01T13:23:52Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [March 1, 2025, 2:01pm UTC](https://discuss.elastic.co/t/sending-nginx-logs-from-other-pods-to-an-eck-elasticsearch-via-beats/375265/2 "2025-03-01T14:01:24Z")

</div>

Filebeat is running under its own isolated namespace under Linux. This means that it has its own file system. Almost like it's running in it's own virtual machine.

Just like you cannot see filebeat from your nginx pods, you cannot see your nginx from your filebeat pod.

So how do you monitor logs on kubernetes with Filebeat?

How would you do it if they were two different VMS?

Well, you'd have to set up some access point where you expose the nginx logs to the filebeat container. Then you'd have to set up filebeat to read logs from that access point.

The typical way to do this is to have your nginx containers log to stdout, so that all logs get written to something like /var/lib/docker/containers on the k8s node, and then mount that dir from the host into the Filebeat container.

Then use Auto discover to monitor for nginx containers, grab their id, and start reading their log files [Autodiscover | Filebeat Reference [8.17] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-autodiscover.html)

There's a previous post here with an example [Docker filebeat autodiscover not detecting nginx logs - #2 by shaunak](https://discuss.elastic.co/t/docker-filebeat-autodiscover-not-detecting-nginx-logs/239849/2)

As an alternative to this, you could create a volume in kubernetes that you mount to all of your nginx pods, have your nginx containers log into this shared volume, and then mount the shared volume into your filebeat pods and setup monitoring of that shared location. This is the less preferred option for sure.

---

_[View the full topic](https://discuss.elastic.co/t/sending-nginx-logs-from-other-pods-to-an-eck-elasticsearch-via-beats/375265)._
