device a filebeat server an elk stack server
Fortinet device ---> filebeat with module fortinet on port 9400 --> logstash->elasticsearch->kibana
haproxy server --> filebeat with module haproxy on port 514 -->
apache server --> filebeat with module apache on port 514 -->
Is this possible or not possible?
If this is not possbile. What is the best practice?
Filebeat is a lightweight data shipper, so it's better to configure a few instances close to the monitored device or service. If you want to depend on a single central instance of filebeat, you will have a serious outage if it dies (single point of failure, no logging at all).
Ok, for the device which I can install filebeat, I should install on the device. How about network device which I couldn't install filebeat for example
Fortigate 2 devices
Mikrotik 2 devices
Should I set up 2 vms for install filebeat and receive logs via syslog from separated each branded devices or 4 vms for each device?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.