I am testing the Filebeat version 5.0 Alpha 5.
I need to read 22 different logs from one server, when Filebeat runs on the same machine, it consumes a lot of CPU (reaches 50%-60%) constantly.
The application server is installed on Windows.
I cannot add more CPU resource to the application servers (Weblogic) due to licensing costs.
We have 5 Application servers.......
So I have set up a server (RHEL) which has filebeat installed and running on it, using CIFS, the filebeat accesses the Application servers and reads logs data.
However, I have encountered multiple events in the Elasticsearch, as it seems, the filebeat reads the files again, although in the registry it is updated regarding the offset and file condition.
This is the configuration I need to use, accessing the log files using some kind of a network share, So I need Filebeat to be able to take the data without re-reading it and duplicate it.
Your help is needed ASAP.