This is my first post. I have 10GB/day centralized syslog from CentOS systems. Log files can be accessed from local or NFS mount. Need at least two fields(timestamp and host) to filter logs. Total users are less than five.
What kind of setup you would recommend?
Minimum hardware requirement. Multiple ingest/data nodes?
Will logstash be the bottleneck?
How do I scale up if I have more log in the future.
Since I need to filter data using host and timestamp, I assume filebeat cannot be used.
Do I have to use logstash? If so, is grok the only way to add timestamp and host fields?