Hi and Respect to all the ELK Gigs !
scenario :
i have several log files (my app logs, application server logs and...) that each of them contains several different of log patterns in their lines.
i'm new in ES and i just want to know what is the best practice for my scenario! to collect and parse them ?
should i parse them only by using one block of multi line Grok pattern ? or use multi Grok pattern block for each individual file ?
is it necessary to make different elastic nodes for each log file ?
thanks for your help
tags: #elasticsearch #logstash #grok #multiline_grok #ELK