We are using the Elastic Stack for our centralized logging. It works great but there is still a lack of knowledge regarding the spool capabilities of logstash shipping those events to elasticsearch. We are running our Elasticsearch instances on differnt servers than our logstash shippers, so a network outage can be a reason for logstash not to be able to ship an event to elasticsearch successfuly.
I have'nt really found informations on how logstash is acting in this situation. Does it spool those events in memory? Or maybe on disk? Is logstash able to spool at all? As this information is quite important for everyone who is using the Elastic Stack, I'm really wondering why there is so little information about this topic. So thanks for Help!