# Check every Fluent Bit collector before enabling pod log-exclusion annotations

> Can a pod annotation intended for Container Insights also stop another log collector?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-445-check-every-fluent-bit-collector-before-enabling-pod-log-exclusion-annotations/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:31+00:00
- Modified: 2026-09-10T02:04:58+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Briefing
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can a pod annotation intended for Container Insights also stop another log collector?

## Potentially affected

Supported ConfigMap-based Container Insights deployments sharing pods with another Fluent Bit collection solution.

## DSE recommendation

Inventory all collectors that honor the pod's exclusion annotations before using them to reduce one pipeline's output.

## Article

## Source facts

Container Insights supports Fluent Bit-based pod annotations that exclude container output after annotation filtering is enabled in its ConfigMap. Microsoft warns that an independent Fluent Bit solution using the Kubernetes plugin filter and annotation-based exclusion also stops collecting the annotated logs. The setting is therefore not necessarily exclusive to Container Insights. AKS Automatic clusters with managed system node pools do not support this ConfigMap configuration path. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-monitor/containers/kubernetes-data-collection-configmap).

## Applicability

Review supported clusters where more than one collector observes the same workload. Identify which solutions actually honor the annotations rather than assuming that every collector does, or that only the intended one does.

## DSE recommendation

Inventory all collectors that honor the pod’s exclusion annotations before using them to reduce one pipeline’s output. Ask each destination owner whether losing those records is acceptable. If one pipeline must retain the data, resolve that requirement with the collector owners before deploying the annotation. Keep the workload manifest and collection configuration in the same review so an application change does not silently remove another team’s evidence.

## Verification

Use a test pod with recognizable benign stdout and stderr messages. Inspect the intended destination and every other relevant destination before and after the approved annotation change. Record each collector’s configuration and observed result. Accept the change only when the resulting exclusions match the agreed collection design; reduced volume in Container Insights alone does not verify the other pipeline’s required continuity.

## Official references

[Microsoft Learn: Container log ConfigMap configuration](https://learn.microsoft.com/en-us/azure/azure-monitor/containers/kubernetes-data-collection-configmap). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure container log collection with ConfigMap - Azure Monitor | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-monitor/containers/kubernetes-data-collection-configmap
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check every Fluent Bit collector before enabling pod log-exclusion annotations,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-445-check-every-fluent-bit-collector-before-enabling-pod-log-exclusion-annotations/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
