In the beginning our ELK stack filebeat monitoring worked perfectly with X-Pack but recently I tried adding some new hosts to it and although the data is correctly parsed by Logstash the monitoring data that get's send directly to ElasticSearch does something weird.
Instead of creating a new filebeat instance in the Beats monitoring it overwrites an old one which causes us to not be able to monitor all the filebeats. When I then restart the previous filebeat the hostname of the filebeat instance get's changed back and the new one isn't monitored anymore.
First I tried to fix this by adding the 'name' tag to the filebeat configuration file but that doesn't really do anything. I know the issue is probably caused because these servers were cloned and at that time filebeat was running but I don't get why I can't fix it.
Is there anything I am missing, perhaps a configuration option?
Or do you require more data to situate the problem?
Thank you for your help