DirectorySecurity AdvisoriesPricing
Sign in
Directory
filebeat logoHELM

filebeat

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
daemonset:
2
# Annotations to apply to the daemonset
3
annotations: {}
4
# additionals labels
5
labels: {}
6
affinity: {}
7
# Include the daemonset
8
enabled: true
9
# Extra environment variables for Filebeat container.
10
envFrom: []
11
# - configMapRef:
12
# name: config-secret
13
extraEnvs:
14
- name: "ELASTICSEARCH_USERNAME"
15
valueFrom:
16
secretKeyRef:
17
name: elasticsearch-master-credentials
18
key: username
19
- name: "ELASTICSEARCH_PASSWORD"
20
valueFrom:
21
secretKeyRef:
22
name: elasticsearch-master-credentials
23
key: password
24
# Allows you to add any config files in /usr/share/filebeat
25
extraVolumes: []
26
# - name: extras
27
# emptyDir: {}
28
extraVolumeMounts: []
29
# - name: extras
30
# mountPath: /usr/share/extras
31
# readOnly: true
32
hostNetworking: false
33
# Allows you to add any config files in /usr/share/filebeat
34
# such as filebeat.yml for daemonset
35
filebeatConfig:
36
filebeat.yml: |
37
filebeat.inputs:
38
- type: container
39
paths:
40
- /var/log/containers/*.log
41
processors:
42
- add_kubernetes_metadata:
43
host: ${NODE_NAME}
44
matchers:
45
- logs_path:
46
logs_path: "/var/log/containers/"
47
48
output.elasticsearch:
49
host: '${NODE_NAME}'
50
hosts: '["https://${ELASTICSEARCH_HOSTS:elasticsearch-master:9200}"]'
51
username: '${ELASTICSEARCH_USERNAME}'
52
password: '${ELASTICSEARCH_PASSWORD}'
53
protocol: https
54
ssl.certificate_authorities: ["/usr/share/filebeat/certs/ca.crt"]
55
# Only used when updateStrategy is set to "RollingUpdate"
56
maxUnavailable: 1
57
nodeSelector: {}
58
# A list of secrets and their paths to mount inside the pod
59
# This is useful for mounting certificates for security other sensitive values
60
secretMounts:
61
- name: elasticsearch-master-certs
62
secretName: elasticsearch-master-certs
63
path: /usr/share/filebeat/certs/
64
# - name: filebeat-certificates
65
# secretName: filebeat-certificates
66
# path: /usr/share/filebeat/certs
67
# Various pod security context settings. Bear in mind that many of these have an impact on Filebeat functioning properly.
68
#
69
# - User that the container will execute as. Typically necessary to run as root (0) in order to properly collect host container logs.
70
# - Whether to execute the Filebeat containers as privileged containers. Typically not necessarily unless running within environments such as OpenShift.
71
securityContext:
72
runAsUser: 0
73
privileged: false
74
resources:
75
requests:
76
cpu: "100m"
77
memory: "100Mi"
78
limits:
79
cpu: "1000m"
80
memory: "200Mi"
81
tolerations: []
82
deployment:
83
# Annotations to apply to the deployment
84
annotations: {}
85
# additionals labels
86
labels: {}
87
affinity: {}
88
# Include the deployment
89
enabled: false
90
# Extra environment variables for Filebeat container.
91
envFrom: []
92
# - configMapRef:
93
# name: config-secret
94
extraEnvs:
95
- name: "ELASTICSEARCH_USERNAME"
96
valueFrom:
97
secretKeyRef:
98
name: elasticsearch-master-credentials
99
key: username
100
- name: "ELASTICSEARCH_PASSWORD"
101
valueFrom:
102
secretKeyRef:
103
name: elasticsearch-master-credentials
104
key: password
105
# Allows you to add any config files in /usr/share/filebeat
106
extraVolumes: []
107
# - name: extras
108
# emptyDir: {}
109
extraVolumeMounts: []
110
# - name: extras
111
# mountPath: /usr/share/extras
112
# readOnly: true
113
# such as filebeat.yml for deployment
114
filebeatConfig:
115
filebeat.yml: |
116
filebeat.inputs:
117
- type: log
118
paths:
119
- /usr/share/filebeat/logs/filebeat
120
121
output.elasticsearch:
122
host: "${NODE_NAME}"
123
hosts: '["https://${ELASTICSEARCH_HOSTS:elasticsearch-master:9200}"]'
124
username: "${ELASTICSEARCH_USERNAME}"
125
password: "${ELASTICSEARCH_PASSWORD}"
126
protocol: https
127
ssl.certificate_authorities: ["/usr/share/filebeat/certs/ca.crt"]
128
nodeSelector: {}
129
# A list of secrets and their paths to mount inside the pod
130
# This is useful for mounting certificates for security other sensitive values
131
secretMounts:
132
- name: elasticsearch-master-certs
133
secretName: elasticsearch-master-certs
134
path: /usr/share/filebeat/certs/
135
# - name: filebeat-certificates
136
# secretName: filebeat-certificates
137
# path: /usr/share/filebeat/certs
138
#
139
# - User that the container will execute as.
140
# Not necessary to run as root (0) as the Filebeat Deployment use cases do not need access to Kubernetes Node internals
141
# - Typically not necessarily unless running within environments such as OpenShift.
142
securityContext:
143
runAsUser: 0
144
privileged: false
145
resources:
146
requests:
147
cpu: "100m"
148
memory: "100Mi"
149
limits:
150
cpu: "1000m"
151
memory: "200Mi"
152
tolerations: []
153
# Replicas being used for the filebeat deployment
154
replicas: 1
155
extraContainers: ""
156
# - name: dummy-init
157
# image: busybox
158
# command: ['echo', 'hey']
159
160
extraInitContainers: []
161
# - name: dummy-init
162
163
# Root directory where Filebeat will write data to in order to persist registry data across pod restarts (file position and other metadata).
164
hostPathRoot: /var/lib
165
dnsConfig: {}
166
# options:
167
# - name: ndots
168
# value: "2"
169
hostAliases: []
170
#- ip: "127.0.0.1"
171
# hostnames:
172
# - "foo.local"
173
# - "bar.local"
174
image: chainreg.biz/chainguard-private/filebeat
175
imageTag: 8.19.21-r3@sha256:fc5ac21da47f88977019d8551485aaa0b85a315f8080923a8bf1439142663761
176
imagePullPolicy: "IfNotPresent"
177
imagePullSecrets: []
178
livenessProbe:
179
exec:
180
command:
181
- sh
182
- -c
183
- |
184
#!/usr/bin/env bash -e
185
curl --fail 127.0.0.1:5066
186
failureThreshold: 3
187
initialDelaySeconds: 10
188
periodSeconds: 10
189
timeoutSeconds: 5
190
readinessProbe:
191
exec:
192
command:
193
- sh
194
- -c
195
- |
196
#!/usr/bin/env bash -e
197
filebeat test output
198
failureThreshold: 3
199
initialDelaySeconds: 10
200
periodSeconds: 10
201
timeoutSeconds: 5
202
# Whether this chart should self-manage its service account, role, and associated role binding.
203
managedServiceAccount: true
204
clusterRoleRules:
205
- apiGroups:
206
- ""
207
resources:
208
- namespaces
209
- nodes
210
- pods
211
verbs:
212
- get
213
- list
214
- watch
215
- apiGroups:
216
- "apps"
217
resources:
218
- replicasets
219
verbs:
220
- get
221
- list
222
- watch
223
podAnnotations: {}
224
# iam.amazonaws.com/role: es-cluster
225
226
# Custom service account override that the pod will use
227
serviceAccount: ""
228
# Annotations to add to the ServiceAccount that is created if the serviceAccount value isn't set.
229
serviceAccountAnnotations: {}
230
# eks.amazonaws.com/role-arn: arn:aws:iam::111111111111:role/k8s.clustername.namespace.serviceaccount
231
232
# How long to wait for Filebeat pods to stop gracefully
233
terminationGracePeriod: 30
234
# This is the PriorityClass settings as defined in
235
# https://kubernetes.io/docs/concepts/configuration/pod-priority-preemption/#priorityclass
236
priorityClassName: ""
237
updateStrategy: RollingUpdate
238
# Override various naming aspects of this chart
239
# Only edit these if you know what you're doing
240
nameOverride: ""
241
fullnameOverride: ""
242

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.