I have close to 1000 log files which produces 10000 events per sec, out of which i have to extract 1000 events per sec and parse it to elasticsearch.
Currently i have a machine (bare metal) which has 32 CPU cores, 47 gig RAM.
What would be the better machine capacity or number of machines for ELK to work ?
Well, my groks are taking too much time to process. Thus resulting in a huge latency of processing files.
I have around 5 logstash config files, and around 1000 files passing to it with /*.log.
Each config file has 4 to 6 grok filters.
Well i really spent lot of time in analysing this without any luck.
Looks like ES is working fine without much load.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.