On Windows, my filebeat.yml is set to ignore older than 24h, yet when I am running filebeat today, it is actually showing IIS logs from back in May. The IIS logs are configured to rollover each day, so I'm not sure what is causing this. Any thoughts?
To further clarify, Kibana only shows entries for 5/26, although I just opened the IIS website from the server in question moments ago. A new IIS log file was created today, and several other IIS log files exist from different days, dating back to 2014. I am unsure why it chose to display log files from 5/24 only.
Screenshot attached of the IIS log directory, highlighting the file that some logs are pulling from. Note that not all log entries within the log file are showing in Kibana, only select ones. I do not see any logs pulled from previous days, or anything from today's log.
This is running filebeat 1.2.3, and IIS has been restarted.
So as of now (2:00 PM UTC), I the newest logs that I see are from 2016-06-14 at 00:00:00. Strangely when I sort by log_timestamp they are out of order.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.