1

I have experienced something a bit weird for me. I have filebeat monitoring my rsyslog (syslog.log) file and sending it to my logstash.

I have noticed that after restarting filebeat where syslog is running, syslogs creates a new file user.log under /var/log/user.log where my logging is going to. However, filebeat expects that syslog.log is the one updated, since that file is not updated nothing is shipped by filebeat towards my logstash...

So my question is that, why does rsyslog daemon create this other file user.log?

Any hint is appreciated!

Thanks in advance!

regards

ndarkness
  • 193
  • 1
  • 7

0 Answers0