# When I restart the pod and move the worker node, filebeat does not start collecting logs

**URL:** <https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [February 6, 2021, 8:54am UTC](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490 "2021-02-06T08:54:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Negi700](https://avatars.discourse-cdn.com/v4/letter/n/e9bcb4/32.png) [@Negi700](https://discuss.elastic.co/u/Negi700)\
**Post date:** [February 6, 2021, 8:54am UTC](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490/1 "2021-02-06T08:54:11Z")

</div>

The log of the pod of azure kubernetes system is collected from the worker node.  
Log collection does not start when the pod reboots and moves the worker node.  
Is there any good workaround?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 8, 2021, 10:13am UTC](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490/2 "2021-02-08T10:13:45Z")

</div>

Hi!

Can you please provide more information about your case?  
I cannot understand how the Pod's restart is related with the node removal. What do you exactly mean by `move the worker node`?

C.

---

<div class="post-metadata">

**Author:** ![Negi700](https://avatars.discourse-cdn.com/v4/letter/n/e9bcb4/32.png) [@Negi700](https://discuss.elastic.co/u/Negi700)\
**Post date:** [February 10, 2021, 10:02am UTC](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490/3 "2021-02-10T10:02:35Z")

</div>

Hi!  
I'm using filebeat 6.8.  
Three worker nodes on the azure kubernetes system are running in a cluster.  
There is a filebeat for each worker.  
The pod for which you want to collect logs went down and started on another worker node.  
After that, the collection of log files stopped.  
When I looked it up, the log of the log collection pod started on a different node is inside the filebeat pod.  
It doesn't seem to be logged because it's not mounted.

Is there a setting to collect logs even if it is started on a different worker node?  
I set file\_identey but it didn't work.

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 10, 2021, 11:17am UTC](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490/4 "2021-02-10T11:17:53Z")

</div>

Hey!

How you deploy Filebeat on k8s nodes? Could you share your k8s manifests?  
You should figure out why log file is not mounted inside Filebeat's Pod. This is the first thing we need to resolve.

C.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2021, 1:18pm UTC](https://discuss.elastic.co/t/when-i-restart-the-pod-and-move-the-worker-node-filebeat-does-not-start-collecting-logs/263490/5 "2021-03-10T13:18:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
