Right no i try to evaluate elk for Windows eventlogs using winlogbeat. no matter what i put in the "ignore_older"-Var, winlogbeat seems always to start from the oldest available eventlog-entry. So it takes very long to come up in elasticsearch.
is this the expected behaviour?
I would expect the shipping to start from the oldest entry specified by the "ignore_older"-var.