The subject of my post probably isn't clear; here's what I'd like to at least try:
I have a logstash-* and filebeat-* index. In Kibana, depending on which I choose to view, of course, I'll set either logs from hosts forwarding via syslog, or those forwarding via filebeat. I was wondering if I could create a third index which contains both logstash- and filebeat-derived logs, and display that in Kibana.
Hoping you understand what I'm trying to accomplish. And, apologies if I've posted in the wrong forum.
However, every night at 10:00, output stops. I then have to remove and add back the alias, and am good again until 10:00 that night. I don't see anything that might cause this behavior. Does anyone have any ideas?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.