elastic / elastic/elastic-agent
[Elastic Agent] [Standalone Mode] [Kubernetes] How to monitor filebeat, when filebeat is down but elastic-agent is up and running
- Dominant language
- Go
- Stars
- 275
- Forks
- 264
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 303
Description
The elastic agent is running in standalone mode in Kubernetes as a pod. We have okta as input and send logs to the logstash, which is running as another pod. Once the elastic agent starts, it starts the filebeat as an application.
[elastic-agent-status]

When the filebeat application goes down, and the elastic agent is still in Healthy status, How can we monitor the filebeat as the pod will be still up and running?
[elastic-agent-status-without-application]

Contributor guide
Research direction
No files, tests, or entry points are named. Start by tracing standalone mode’s Kubernetes health and status reporting, then examine how the Filebeat application state can be surfaced. Done should make Filebeat being down observable even while the Elastic Agent pod remains running.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, kubernetes
- Domain
- infrastructure, observability
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100