we are using an Fleet Server, including Custom UDP logs integration. We observed an issue with data are not ingested with a load about 500 EPS. About 30% to 50 % messages are not ingested.
Also netstat -ulpn shows that the receive queue is quite high:
udp 116480 0 127.0.0.1:1514 0.0.0.0:* 726338/filebeat
CPU and Memory usage is low, also no IO issues detected. Does somebody uses this integration successfull in production environments ? With an acceptable processing rate ?
We switched back to some more mature implementation, logstash directly to elasticsearch. We reached about 5000 eps without any issues.
Would be great that somebody can share his experience as well.