I found that my busiest index was a logs-elastic_agent.filebeat-default index, so I looked into what was being sent. I found a simple custom logs (filebeat) agent that was sending at debug level. Over 8 million events to the cloud that I don't really need...
I found "Collect agent logs" in settings, but no way to change the log level?
Is there a way to change it? Why did it get set to debug on a single system?
It could be info, maybe not debug, I was using the log viewer in Fleet and selecting the level filters, I had never used it before
IMHO, info is too chatty to send to the cloud. I found a second host, so over 24 hours, I ingested 16 million lines of basically "end of file reached".
If info is the default, is there a way in Fleet to change it?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.