I am replacing an existing enterprise logging system by Elastic Stack. I have hundreds of applications currently using the current system. Those applications they are spread across 3 or 4 servers (depending on the environment).
I am planning to use a filebeat forwarding the logs to two logstash instances, that will take care of parsing the logs (grok) and forwarding the log to Elasticsearch.
What would be the best practice in this case, one filebeat with multiple prospectors, or multiple filebeat with one prospector each?
If not enough information, please let me know.
Appreciate your input.