I have a few questions regarding ELK stack.
what is the best option to pull data? Read from a log file or Database? Best option in terms of Performance/latency/data accuracy.
a. If Database, then any drawback like extra overload on Application database? How frequently it reads?
b. If both the cases, what happens if Kibana goes down and need to load older log files or data? Will it be done automatic, in real time?
2) Can single Kibana instance handle multiple apps? Or should i go for separate Kibana instance per app. If single, then any performance degradation and can we control user access to specific application data?