It was strange , there was no log rotation at those servers where log was missed .
also my architecture is something like this -
But for general information what will be impact of log rotation we generally use logrotate feature of linux and how to overcome from these kind of failures
If you use the general log rotation there shouldn't be an issue. Filebeat finishes reading the old file and picks up the new one.
I assume shipper and index above are both LS instances. Any chance to share the log files of filebeat around the time the events went missing? Does it happen every day or it happened only once? Which version of the following are you using?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.