S
S
someday82018-07-11 22:12:39
linux
someday8, 2018-07-11 22:12:39

ELK indexing from a specific date?

There is ELK and filebeat, it was spinning for half a year and a lot of rubbish has accumulated.
It was decided to bang the entire index and start from the beginning, but after deleting the entire
DELETE _all date, logstash pulls all the same old six-month-old logs into elastic.
If you use curator, won't it also upload old logs, index them and delete them?
How to set the date from which the collection of logs will start?
Where to dig?

Answer the question

In order to leave comments, you need to log in

1 answer(s)
S
someday8, 2018-07-24
@someday8

Manually deleting the old filebeat files on each machine solves this problem.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question