Is there a configuration option to restrict the initial ingestion of Winlogbeat to something less than the entirety of the logs, perhaps by date?
For example, I am trying to onboard about 350 Windows servers, and when I add the Winlogbeat service to a single system, I get all of the logs which are stored on that server. In my example, I have a server whose logs go back to 2012, but I have a curator job which purges logs older than 180 days.
Can I limit Winlogbeat to only look at log entries newer than 180 days, in my case?
As this stands, I have quadrupled my indices for the day until my purge happens, leading to delays as my data nodes work to keep up with replicating shards. These delays keep the cluster in a yellow or green status for dozens of minutes.