What version of the Elasticstack if being run here? Please share the directories under which you have found said hidden files? What OS is this currently running on?
I'm using 5.4.2 version of Elasticsearch under Debian 8.8. The directories under which I've found those hidden files are /etc/logstash/conf.d/ (where I've got the config file for logstash) and /var/log, where I've got the log file I pass to logstash.
Well, I've just figured out this weird issue. The thing was that in logstash.conf I've got "sincedb_path" param at this way:
sincedb_path => ""
This was the only way I found to force logstash to parse from the begining of the document for each execution because start_position => "beginning" didn't work for me.
So, due to sincedb_patch logstash creates a file from each execution.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.