Does graylog have a limit on the number of lines it can ingest into 1 log file in the message section of the log file in graylog?
I added the multi line options in my filebeat config so that it can ingest all my log file in 1 log file in filebeat. The log file on my server is an active log file so that means data gets appended to that file. While it is being appended that log file is sent via filebeat to graylog.
I did a test and copied over the same file but this time it was not active and had all the data in the log file. But then it only copied over certain amount of data not the whole file in 1 log file in graylog.
- CentOS 7.9
- Graylog 4.1.
- MongoDB 4.2.14
- Elasticsearch 7.10.2-1
- Filebeat 7.14.0-1
My multi line added to logfile
``` multiline.type: pattern multiline.pattern: '-*.TRANSFER START' multiline.negate: true multiline.match: after ```