Atm, most of our traffic is hitting logstash via the beats input. We output to two clusters, one of which is significantly bigger than the other. And periodically, we see congestion reported by beats and it backs off.
My questions is, given this behaviour, do we need to split the output definition for our second elasticsearch cluster to a separate logstash instance? The idea being to avoid issues with one cluster impacting ingestion to the other...