I am still getting data in elasticsearch index after killing logstash and filebeat and when i am checking the PID of logsatsh and filebeat its showing that both are not working but i am still getting the data
Can someone suggest me why is it so.
Hello @dadoonet
Thanks for the response I created a config file in logstash and also created a script to run logstash in the backend
In the logstash I am getting data from 3 different instances and I am seprating data output to 3 different indices.
I applied a loop.
Due to certain reasons I had to kill the filebeat and logstash and even I after deleting the registry file in filebeat and I am getting the data and data is getting Indexed in my indices.
Not sure about what you are meaning.
But could you run again the same cat command I pasted before and after stopping. And again after 1 minute.
And share all the 3 outputs here.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.