Your understanding of how all this works looks good to me . Docker will write to files, and that's your buffer as of today. Filebeat is able to pick logs from there and keep a registry of reading offsets, so it can recover from restarts.
The overall architecture looks good to me, would love to hear about your experience if you go live with it
The fix didn't go out yet, you will have to wait for 6.2.3 or build your own image. Also take into account that dotted labels are an issue, we are working on a new fix for those.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.