- Remove the journalbeat 5.5.0 service configuration
- override the service configuration to run in a dedicated user
- deploy the elasticsearch packages (journalbeat and filebeat)
- cleanup the temporary configuration
- update the logstash configuration to support the messages
from the old journalbeat version and the new version in parallel
The mappings of the new systemlogs-7.15.1-* and swh_worker-7.15.1-*
index need to be manually declared on elasticsearch before.
Related to T3705
Depends on D6634