Filebeat log entries for this inode (For last many days) - it seems same inode tracked the much heavier conn.log
and dns.log
files at some point.
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-05T20:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T03:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T04:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T05:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T09:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T11:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T12:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T13:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/capture_loss.log'","service.name":"filebeat","id":"captureloss","source_file":"filestream::captureloss::native::1296539577-64544","path":"/zeeklog/logs/current/capture_loss.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T14:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T15:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-06T23:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-07T00:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-07T02:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-07T03:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-07T04:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-07T05:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-07T14:00:13.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-07T15:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-08T01:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240205.ndjson:{"log.level":"info","@timestamp":"2024-02-08T02:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T05:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T06:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T07:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T08:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T08:00:23.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T09:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T18:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T19:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T22:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-08T23:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T00:02:53.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/capture_loss.log","service.name":"filebeat","id":"captureloss","source_file":"filestream::captureloss::native::1296539577-64544","path":"/zeeklog/logs/current/capture_loss.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T01:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/capture_loss.log'","service.name":"filebeat","id":"captureloss","source_file":"filestream::captureloss::native::1296539577-64544","path":"/zeeklog/logs/current/capture_loss.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T02:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T03:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T07:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T08:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T13:00:03.653+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T14:00:03.654+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T15:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T16:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T17:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T20:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T21:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T22:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-09T23:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T00:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T01:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T06:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T07:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T08:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T09:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T16:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240208.ndjson:{"log.level":"info","@timestamp":"2024-02-10T17:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-10T20:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-10T21:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-10T22:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-10T23:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T01:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T02:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T07:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T08:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T14:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T15:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T17:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T18:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T19:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-11T20:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T01:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T02:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T03:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T04:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T05:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T06:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T07:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T08:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T13:00:13.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-12T13:50:47.930+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-13T11:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/dns.log","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240210.ndjson:{"log.level":"info","@timestamp":"2024-02-13T12:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/dns.log'","service.name":"filebeat","id":"dns","source_file":"filestream::dns::native::1296539577-64544","path":"/zeeklog/logs/current/dns.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240213.ndjson:{"log.level":"info","@timestamp":"2024-02-13T19:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240213.ndjson:{"log.level":"info","@timestamp":"2024-02-13T20:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240213.ndjson:{"log.level":"info","@timestamp":"2024-02-13T23:00:03.648+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240213.ndjson:{"log.level":"info","@timestamp":"2024-02-14T00:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240213.ndjson:{"log.level":"info","@timestamp":"2024-02-14T07:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/conn.log","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240213.ndjson:{"log.level":"info","@timestamp":"2024-02-14T08:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/conn.log'","service.name":"filebeat","id":"conn","source_file":"filestream::conn::native::1296539577-64544","path":"/zeeklog/logs/current/conn.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240213.ndjson:{"log.level":"info","@timestamp":"2024-02-14T18:00:03.647+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240215-1.ndjson:{"log.level":"info","@timestamp":"2024-02-15T10:51:18.342+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240215-1.ndjson:{"log.level":"info","@timestamp":"2024-02-15T11:00:03.846+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240215-1.ndjson:{"log.level":"info","@timestamp":"2024-02-15T13:00:08.342+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240215.ndjson:{"log.level":"info","@timestamp":"2024-02-15T10:17:27.004+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).openFile","file.name":"filestream/input.go","file.line":274},"message":"File was truncated. Reading file from offset 0. Path=/zeeklog/logs/current/smtp.log","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}
/var/log/filebeat/filebeat_instance_dns.log-20240215.ndjson:{"log.level":"info","@timestamp":"2024-02-15T10:51:10.929+0530","log.logger":"input.filestream","log.origin":{"function":"github.com/elastic/beats/v7/filebeat/input/filestream.(*filestream).readFromSource","file.name":"filestream/input.go","file.line":336},"message":"Reader was closed. Closing. Path='/zeeklog/logs/current/smtp.log'","service.name":"filebeat","id":"smtp","source_file":"filestream::smtp::native::1296539577-64544","path":"/zeeklog/logs/current/smtp.log","state-id":"native::1296539577-64544","ecs.version":"1.6.0"}