Hi, I'm fairly new to Elastic Search, and I'm experiencing strange behaviour when re-deploying an application that sends its logs to ELK. The application is a Java app and using Filebeat to send the logs (both running in docker containers) to logstash, elastic search and kibana on a separate server, again all running in docker containers.
If I start with a clean setup, everything work as I would expect it to. If I then make changes to the java application, stop and restart the docker containers (including filebeat), then I can see no further logs in the ELK stack. Note, if I make no changes to the app and simply stop and restart the containers, everything continues to work.
If I now delete the image in the index management part of the web portal and restart everything, it starts to see the new application, but obviously I've now lost all existing data.
Is this expected behaviour? Is there any way I can fix this issue?
I have tried checking the logs in filebeat, logstash and elastic search, switching all to debug mode. I'm seeing lots of logging, but no relevant errors being reported by any of the applications.
If anyone knows what I'm doing wrong, please let me know.