Today I was trying to get FileBeat up and running. I have logstash, elasticsearch and kibana all setup but i'm new to FileBeat.
Previously I had logstash running on an ubuntu VM, smb mounting windows shares, and correctly tailing log files from multiple servers. These log files roll over whenever they hit 50mb. Logstash was handling this fine.
I've now got filebeat running on a windows2012r2 server pickup up files from the same windows shares. all is good until the files roll over.
They way the files are rolled over is somelog.log will be renamed somelog.1.log and a new file will be created somelog.log.
Should filebeat be able to handle this, I read through the doco, played with force_close_files and tailfiles but no luck.
The windows share thing is because i'll trailing ELK for our log analytics and can't get approval to run filebeat on the actual servers just yet.
Sorry no config atm, at home with beer. but has anyone seen this issue and got the magic bullet?