Unique File Identifier in Filebeat

https://www.elastic.co/guide/en/beats/filebeat/current/how-filebeat-works.html#_how_does_filebeat_keep_the_state_of_files

The above link tells that "For each file, Filebeat stores unique identifiers to detect whether a file was harvested previously."

Now, my questions are :

  1. What is the name of unique identifier which filebeat uses to keep track of previously harvested files.

  2. Where can we find the value of this unique identifier?

Well, I assume this is internal implementation of harvesters, you need to take a look at the source code.

Why exactly do you need this information? Are you struggling with log rotation?

I am struggling with Filebeat processing all logs again for every Pod Restart in Kubernetes.

I have shared my problem here : Duplicate Entries in Filebeat Registry File For Kubernetes Pod Restart

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.