The filebeat debugged output does show that most of the input files didn't change, yet it does not show on Kibana as supposed.
Filebeat keeps harvesting the Filebeat+Kibana log files.
My fields.yml should be quite short, I just couldn't figure out its structure.
Can you say how to add just the requested fields to this example load:
"date":"id": "date"
"error.message":"id": "string"
"process.title":"id": "string"
"event.action":"id": "string"
"process.program":"id": "string"
"event.type":"id": "string"
"event.hash":"id": "string"
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.