My Current setup is
- File Beat --> Log Stash ---> Elastic Search
The expected log volume is say 10 GB per hour to LS (as current version of FB doesn't have regexp feature and ships all logs).
Hence would like to know if FB and Log Stash would be able to handle this log without loss of any messages or network over head !!
What is the best practice !!
Should we implement FB-->Any Queue (Redis) --> Log Stash. If so does File beat support integrating with Fedis.