I am testing the filebeat app and I have encounter that after a while reading a syslog file it stops reading, I suspect is something related to the type of log, it is configured to rotate once a day at 10 AM, but when start reading the file it stops around 12 o'clock, I have checked the logs of filebeat and don't show any errors, here is my filebeat configuration:
- input_type: log
Paths that should be crawled and fetched. Glob based paths.
Array of hosts to connect to.
Optional ingest node pipeline. By default no pipeline will be used.
The number of times a particular Elasticsearch index operation is attempted. If
the indexing operation doesn't succeed after this many retries, the events are
dropped. The default is 3.
Template name. By default the template name is filebeat.
Path to template file
Overwrite existing template
filebeat version 5.4.
Elasticsearch version 5.4
I am missing something?