# PCF (CloudFoundry) Application rename is not being detected

**URL:** <https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 12, 2021, 6:43pm UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460 "2021-07-12T18:43:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![pausebreathefly](https://avatars.discourse-cdn.com/v4/letter/p/ecae2f/32.png) [@pausebreathefly](https://discuss.elastic.co/u/pausebreathefly)\
**Post date:** [July 12, 2021, 6:43pm UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460/1 "2021-07-12T18:43:38Z")

</div>

Hi,

We have configured the below processors in our filebeat application deployed on TAS or PCF but when we rename any application the changes are not being honored. Is there any additional setting that needs to be configured in the filebeat? Also where is the below cache stored ? how do we check the metadata that is being received ?

\</ processors:

- add\_cloudfoundry\_metadata:  
\<\<: \*cloudfoundry  
cache\_duration: 1200s  
cache\_retry\_delay: 60s  
/\>

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 12, 2021, 6:47pm UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460/2 "2021-07-12T18:47:03Z")

</div>

Hi @pausebreathefly Welcome to the community.

First a couple questions

- What version of TAS are you using?
- What version of Filebeat are you using?

I ask this because after a certain versions the `add_cloudfoundry_metadata` is no longer needed as the app names, spaces and org are available in the data stream directly and that is a much better method.

---

<div class="post-metadata">

**Author:** ![pausebreathefly](https://avatars.discourse-cdn.com/v4/letter/p/ecae2f/32.png) [@pausebreathefly](https://discuss.elastic.co/u/pausebreathefly)\
**Post date:** [July 12, 2021, 7:00pm UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460/3 "2021-07-12T19:00:59Z")

</div>

@stephenb - Appreciate your quick reply. we are using TAS version of 2.10 and using Filebeat 7.13 .  
Issue is we have a blue-green deployment on TAS and when the application gets renamed from blue to green. Its still shows old blue name.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 12, 2021, 8:28pm UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460/4 "2021-07-12T20:28:53Z")

</div>

Take out the `add_cloudfoundry_metadata` processor completely, It should be no longer needed.  
Then re-push filebeat.  
The app, org and space names should be realtime.  
let me know what you see.

Here is what mine looks like with no processor

 ![Screen Shot 2021-07-12 at 1.33.04 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f800c8765d0ae89183252c0f245f74b8c1d6460.png)

I renamed / restarted app

 ![Screen Shot 2021-07-12 at 1.44.03 PM](https://us1.discourse-cdn.com/elastic/original/3X/9/d/9d856c769db6a86c8cae48d4e555e6c39876bac4.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 13, 2021, 2:02am UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460/5 "2021-07-13T02:02:21Z")

</div>

@pausebreathefly

Also here are my tuning parameters in the `filebeat.yml` for output if you are sending directly to elasticsearch

```auto
# Approach A : Tuning Parameters
queue.mem:
  events: 4096
  flush.min_events: 2048
  flush.timeout: 1s

output.elasticsearch:
  bulk_max_size: 200
  worker: 4

```

And here is my manifest.yml I found that 1GB filebeats with the above parameters are a good "scaling unit"

```auto
applications:
- name: filebeat
  memory: 1G
  instances: 2
  buildpacks:
  - binary_buildpack
  command: ./filebeat -e -c ~/filebeat.yml
  stack: cflinuxfs3
  health-check-type: process
  no-route: true

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2021, 4:02am UTC](https://discuss.elastic.co/t/pcf-cloudfoundry-application-rename-is-not-being-detected/278460/6 "2021-08-10T04:02:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
