# Want to enable NGINX module in our filebeat to get the kubernetes nginx/ingress\_controller logs

**URL:** <https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945>\
**Category:** Beats\
**Tags:** docker, beats-module, filebeat\
**Created:** [September 17, 2020, 8:55am UTC](https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945 "2020-09-17T08:55:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulsrivastava71](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahulsrivastava71/32/75741_2.png) [@rahulsrivastava71](https://discuss.elastic.co/u/rahulsrivastava71)\
**Post date:** [September 17, 2020, 8:55am UTC](https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945/1 "2020-09-17T08:55:38Z")

</div>

we are using filebeat as our log shipper and running it as a docker image , we want to enable the NGINX module so that we can get the logs in proper format as currently we get the logs in the form as a bunch of lines, and we can only perform full text search, but we want to make ingress controller dashboard for which we need proper filters and for that we need to enable the Nginx module in our filebeat.

for ref filebeat :

```
apiVersion: apps/v1
kind: DaemonSet
metadata:
  name: filebeat
  namespace: logging
  labels:
    k8s-app: filebeat
spec:
  selector:
    matchLabels:
      k8s-app: filebeat
  updateStrategy:
    type: RollingUpdate
  template:
metadata:
          labels:
            k8s-app: filebeat
        spec:
          serviceAccountName: filebeat
          terminationGracePeriodSeconds: 30
          containers:
          - name: filebeat
            imagePullPolicy: IfNotPresent
            image: xxx repo
            args: [
              "-c", "/aaa/filebeat.yml",
              "-e",
            ]
            env:
            - name: NODENAME
              valueFrom:
                fieldRef:
                  fieldPath: spec.nodeName
```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [September 21, 2020, 1:31pm UTC](https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945/2 "2020-09-21T13:31:44Z")

</div>

You can find instructions about running Filebeat on Kubernetes here: [https://www.elastic.co/guide/en/beats/filebeat/master/running-on-kubernetes.html](https://www.elastic.co/guide/en/beats/filebeat/master/running-on-kubernetes.html)  
Also, guides about enabling the NGINX module: [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-nginx.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-nginx.html)

Let me know if you have a specific question or something is missing from the docs.

---

<div class="post-metadata">

**Author:** ![rahulsrivastava71](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rahulsrivastava71/32/75741_2.png) [@rahulsrivastava71](https://discuss.elastic.co/u/rahulsrivastava71)\
**Post date:** [September 23, 2020, 8:04am UTC](https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945/3 "2020-09-23T08:04:21Z")

</div>

Hey @kvch thanks for you promt reply, but with us problem is that we are running the filebeat ina docker and the path of the logs files as mentioned in your document is what we are looking for which we are not able to get the logs, our filebeat.yaml looks like

> filebeat.yml: |-  
> name: ${NODENAME}  
> filebeat.inputs:  
> - type: docker  
> containers.ids:  
> - "\*"  
> processors:  
> - add\_kubernetes\_metadata:  
> in\_cluster: true  
> logging.to\_files: false  
> setup.template.enabled: false  
> setup.ilm.enabled: false  
> #proxy\_url: [http://www-url:80](http://www-url:80)  
> output.elasticsearch:  
> hosts: ${ES\_URL}  
> username: ${ES\_USER}  
> password: ${ES\_PASSWORD}  
> index: ${INDEX\_NAME}  
> bulk\_max\_size: 200

problem is in you solution

> ```
> - module: nginx
> ingress_controller:
> enabled: true
> var.paths: ["what will be the path ? -----> /path/to/log/nginx/ingress.log"]
> 
> ```

what will be the path here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2020, 10:04am UTC](https://discuss.elastic.co/t/want-to-enable-nginx-module-in-our-filebeat-to-get-the-kubernetes-nginx-ingress-controller-logs/248945/4 "2020-10-21T10:04:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
