The Elastic Agent collects Filebeat logs. Within 'Fleet' I have the system-1 default. This module collects the logs form usual logfiles like /var/log/syslog* etc.
But also the logs from /var/lib/elastic-agent/logs/default/filebeat-json.log. Now I have all events duplicated. The latter ones are not parsed, the logs from /var/log are correctly parsed.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.