Hi,
Filebeat is sending whole log every time for addition of even one new line in log file. because of this I'm ending up with lot of duplicate data.
Below is my config file:
filebeat.prospectors:
- type: log
enabled: true
paths:
- /usr/share/filebeat/logs/zuul/log/50lk_1cr_lines.log
encoding: plain
include_lines: ['\d{4}\-\d{2}\-\d{2}']
multiline.pattern: '^\d{4}\-\d{2}\-\d{2}'
multiline.negate: false
multiline.match: after
fields:
document_type: zuul_log
clean_removed: true
registry: /usr/share/filebeat/data/registry
setup.template:
name: "filebeat"
pattern: "filebeat-*"
settings:
index.number_of_shards: 1
index.number_of_replicas: 1
output.elasticsearch:
hosts: ["xxx:9200"]
index: "%{[fields.document_type]}-%{[beat.version]}-%{+yyyy.MM.dd}"