On Windows, my filebeat.yml is set to ignore older than 24h, yet when I am running filebeat today, it is actually showing IIS logs from back in May. The IIS logs are configured to rollover each day, so I'm not sure what is causing this. Any thoughts?
To further clarify, Kibana only shows entries for 5/26, although I just opened the IIS website from the server in question moments ago. A new IIS log file was created today, and several other IIS log files exist from different days, dating back to 2014. I am unsure why it chose to display log files from 5/24 only.