I am taking logs from journalctl and giving input in logstash, then logstash sent it to kibana.
The main concern is the last log is repeating in an infinite loop and journalbeat-7.2 is publishing event in about some seconds.
I will be able to see my last log in
journalctl -t <syslog.identifier> --recursive (latest) have a single entry that is repeating again and again.
$ journalctl -t XXXXXX --reverse -- Logs begin at Wed 2019-04-17 12:56:46 UTC, end at Fri 2019-08-23 11:41:01 UTC. -- Aug 23 10:42:56 APPLICATION XXXXXXX : username:XXXX.XXXXX|userId:39|ip:XXXXXX|user_agent:XXXX.6.1 (Windows NT X.XX; WOW64
journalbeat.inputs: - paths: ["/var/log/journal/ec2fchrdeb7e4bd5"] seek: cursor cursor_seek_fallback: head include_matches: - "syslog.identifier=XXXXXXX" setup.template.settings: index.number_of_shards: 1 setup.kibana: output.logstash: hosts: ["xxx.xxx.xxx.xx:XXXX"] processors: - add_host_metadata: ~ - add_cloud_metadata: ~ - drop_event: when: equals: process.name: "journalbeat"