I am planning on using Filebeat for log rotation on a server. From my understanding, Filebeat tails the inode so log rotation shouldn't be an issue when it comes to reading new log data. However, I have a question regarding how information is indexed. If I would like a new index everyday in elasticsearch, how would I configure that information in Logstash? Would I have to specify a date within the index name?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.