We have an ELK 5.5.2 environment where we have 3 master enable nodes, 3 coordinating nodes and 8 data nodes. The servers in this environment have 8 cores, 64gb ram and 200gb of storage on the data nodes.
We are sending the syslogs for ELK servers to a remote rsyslog receiving linux server where we have file beat installed. This server is not part of the ELK environment - it is a specialized server for collecting syslogs from other linux servers. File beat is forwarding the syslogs and it own logs to the ELK environment directly. FB -> ES.
When we query the data in Kibana we are seeing a few minute lag. In other words we have no data for the last x minutes from the server where we have filebeat installed.
How do we tell if filebeat is not keeping up. If it is falling behind while reading the logs. Is there a way to have filebeat print out the position that it currently reading from and the position of the EOF?