I am using Logstash 6.8 and i intend to use dlq for this purpose:
If an event is not entered the Elastic cluster because of mapping conflict or something else,
i want to show that log in a specific index that tells why, I am able to get the reason and show it in Kibana. So this is great.
What i am struggling about is the retention of those dlq logs in the logstash server. It does not clear itself, and only got a limit on the size of it.
Is there any option to do retention or rotate to those logs so that the dlq can accept events and not limit it and ignore them?