Best Practice for different log files with multi line Grok patterns

Hi and Respect to all the ELK Gigs !

scenario :
i have several log files (my app logs, application server logs and...) that each of them contains several different of log patterns in their lines.
i'm new in ES and i just want to know what is the best practice for my scenario! to collect and parse them ?
should i parse them only by using one block of multi line Grok pattern ? or use multi Grok pattern block for each individual file ?
is it necessary to make different elastic nodes for each log file ?

thanks for your help
tags: #elasticsearch #logstash #grok #multiline_grok #ELK

I don't think there's a single best practice here. There are several valid ways of doing it and the best solution depends on the context.

is it necessary to make different elastic nodes for each log file ?

No, absolutely not.

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.