HI Team,
I am using filebeat-7.3.2-1.x86_64 for application log reading.
but all the time filebeat read log from starting, hence duplicate data is present in elastic
please suggest what configuration required?
HI Team,
I am using filebeat-7.3.2-1.x86_64 for application log reading.
but all the time filebeat read log from starting, hence duplicate data is present in elastic
please suggest what configuration required?
Hello @rguptarg,
Few parameters like clean_inactive , scan_frequency has to be tweaked. Also kindly check if there is any log rotation enabled or any cron for logFile renaming which might also cause these issues. Kindly do check the below link for more details of many attributes such as clean_inactive , scan_frequency, etc.
https://www.elastic.co/guide/en/beats/filebeat/7.3/configuration-filebeat-options.html
Cheers,
Maadavan
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.