elastic / elastic/elastic-agent

[Elastic Agent] [Standalone Mode] [Kubernetes] How to monitor filebeat, when filebeat is down but elastic-agent is up and running

Open
#779 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
275
Forks
264
Avg merge
1d 20h
Merged PRs (30d)
303

Description

The elastic agent is running in standalone mode in Kubernetes as a pod. We have okta as input and send logs to the logstash, which is running as another pod. Once the elastic agent starts, it starts the filebeat as an application.
[elastic-agent-status]
![image](https://user-images.githubusercontent.com/103553949/181174685-bd93dd7a-275a-46fe-98d9-6b75bc3033b6.png)

When the filebeat application goes down, and the elastic agent is still in Healthy status, How can we monitor the filebeat as the pod will be still up and running?
[elastic-agent-status-without-application]
![image](https://user-images.githubusercontent.com/103553949/181173575-bf19b608-e7de-41e5-b29a-804235c04475.png)

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by tracing standalone mode’s Kubernetes health and status reporting, then examine how the Filebeat application state can be surfaced. Done should make Filebeat being down observable even while the Elastic Agent pod remains running.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, kubernetes
Domain
infrastructure, observability
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.