Simplified log ingestion

edit

Running Elastic Agent in standalone mode is an advanced use case. The documentation is incomplete and not yet mature. When possible, we recommend using Fleet-managed agents instead of standalone mode.

There is a simplified option for ingesting log files with Elastic Agent. The simplest input configuration to ingest the file /var/log/my-application/log-file.log is:

inputs:
  - type: filestream 
    id: unique-id-per-input 
    paths: 
      - /var/log/my-application/log-file.log

The input type must be filestream.

A unique ID for the input.

An array containing all log file paths.

For other custom options to configure the input, refer to the filestream input in the Filebeat documentation.