My question is related to the correct way to configure the output, for Elasticsearch.
Right now my Elasticsearch cluster is one master node, 2 ingest nodes and 1 data node.
My Logstash output configuration is linked to the ingest nodes, the data is routed in base some conditions, so the data can be sent to the ingest_node_1 or to ingest_node_2 but never to both of them. This works quite fine until now.
But after check the stack, review forums and, in general, make some research, I'm starting to doubt if I must link the output to the master node instead of the ingest nodes.