Hi! We're trying to better manage our Kubernetes logs. I have Filebeat running in the cluster using autodiscover and shipping off to Logstash.
Say in the K8s cluster, I have the Docker logging driver set to max-size of 10MB. When that file size is reached - Docker rolls the log.
Filebeat will pick up the new log, correct?
In Docker, if I set max-file to like 2, this will help ensure that Filebeat will still be able to finish reading from the old log file and then go on to the new. And so forth and so forth as logs are rotated.
That sound about right?