I am using filebeat-5.6
My config filebeat -> logstash -> elasticsearch -> kibana
I have hundreds of log files with 1KB - 2KB data in the path "c:\programdata\AICdameon\ "
All the files get created when the background jobs start's and the files get updated at regular intervals.
How to make file beat send the whole log file as a single message to elasticsearch only when the log file is finished updating??.
All log file's start with the line "starting jobid 247HQD51" and ends with the line "end job 247HQD51".
My below filebeat config is not working as expected, my filebeat sends logs as soon as they get updated in the log file.
- input_type: log