# Filebeat re-ingesting old logs after pod restart (ECK on GKE) - ignore\_older not working

**URL:** https://discuss.elastic.co/t/filebeat-re-ingesting-old-logs-after-pod-restart-eck-on-gke-ignore-older-not-working/384328
**Category:** Elastic Cloud on Kubernetes (ECK)
**Tags:** ilm-index-lifecycle-management
**Created:** [January 1, 2026, 12:48am UTC](https://discuss.elastic.co/t/filebeat-re-ingesting-old-logs-after-pod-restart-eck-on-gke-ignore-older-not-working/384328 "2026-01-01T00:48:09Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Marwan\_Ghonem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marwan_ghonem/32/146533_2.png) [@Marwan\_Ghonem](https://discuss.elastic.co/u/Marwan_Ghonem)
#### Post date: [January 1, 2026, 12:48am UTC](https://discuss.elastic.co/t/filebeat-re-ingesting-old-logs-after-pod-restart-eck-on-gke-ignore-older-not-working/384328/1 "2026-01-01T00:48:09Z")

</div>

Problem

Filebeat is repeatedly re-ingesting old logs (4-15 days old) causing previously deleted indices to be recreated.  
Environment

- **Filebeat version:** 7.10.1

- **ADeployment:** ECK (Elastic Cloud on Kubernetes) DaemonSet

- **Platform:** Google Kubernetes Engine (GKE)

- **Number of pods:** 42 DaemonSet pods

- **Elasticsearch version:** 7.10.1s happens periodically, and we need to configure

## What's Happening

1. Idelete old filebeat indices (e.g., `filebeat-7.10.1-2025.12.10` through date `2025.12.16`)

2. Within hours, these indices are **recreated** with old log data

3. The recreated indices contain logs with:

---

<div class="post-metadata">

### Author: ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)
#### Post date: [January 2, 2026, 6:56am UTC](https://discuss.elastic.co/t/filebeat-re-ingesting-old-logs-after-pod-restart-eck-on-gke-ignore-older-not-working/384328/2 "2026-01-02T06:56:45Z")

</div>

Hello @Marwan_Ghonem

Welcome to the Community!!

Could you please share the filebeat.yml in order to understand why the older indices are created again?

It can be related to the registry path :

> **[Configure general settings | Beats](https://www.elastic.co/docs/reference/beats/filebeat/configuration-general-options)**
>
> You can specify settings in the filebeat.yml config file to control the general behavior of Filebeat. This includes: Global options that control things...

Similar older issue :

> [@Filebeats(5.40) keeps on recreating the indices after deletion](https://discuss.elastic.co/t/filebeats-5-40-keeps-on-recreating-the-indices-after-deletion/121986):
>
> I have filebeats reading the log files on a remote server and shipping it to logstash on the same server. I have tried deleting the last 6 months old indices but I have noticed that indices are recreated on the elastic search. Can you correct me where i'm doing wrong I went with the default configuration. Thanks paths: #- /var/log/\*.log - \\webserver10\iislogs\*.log output.logstash: # Boolean flag to enable or disable the output module. #enabled: true # The Logstash hosts ho…

Thanks!!

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [January 2, 2026, 3:27pm UTC](https://discuss.elastic.co/t/filebeat-re-ingesting-old-logs-after-pod-restart-eck-on-gke-ignore-older-not-working/384328/3 "2026-01-02T15:27:52Z")

</div>

Hi @Marwan_Ghonem

In addition 7.10.is 5+ years old and that you should upgrade with a matter of urgency.

Many improvements have been made on filebeat, including many improvements directly targeted at K8s container logs.
