I’m using the elastic agent to load pod logs from kubernetes:
- id: container-log-${kubernetes.pod.name}-${kubernetes.container.id}
type: filestream
use_output: default
meta:
package:
name: kubernetes
version: 1.80.2
data_stream:
namespace: default
streams:
- id: container-log-${kubernetes.pod.name}-${kubernetes.container.id}
data_stream:
dataset: kubernetes.container
type: logs
prospector.scanner.symlinks: true
paths: ["/var/log/containers/*${kubernetes.container.id}.log"]
The above input creates a new data stream: logs-kubernetes.container-default which is based on the “logs” index lifecycle policy. Why is this policy deprecated? Should I create a new policy?