Elastic Agent System Integration

The Elastic Agent collects Filebeat logs. Within 'Fleet' I have the system-1 default. This module collects the logs form usual logfiles like /var/log/syslog* etc.
But also the logs from /var/lib/elastic-agent/logs/default/filebeat-json.log. Now I have all events duplicated. The latter ones are not parsed, the logs from /var/log are correctly parsed.

Why are there logs also collected?


We definitively should not ship the logs twice. @blaker Could you comment on this?

That is because of elastic/beats#19179. We need to fix the logging we start filebeat and metricbeat with so that every published event is not logged.