I am wanting to move from "scribe" to ElasticStack for processing apache httpd 2.4 access logs.
I have identified the following approaches:
Option 1
CustomLog with pipe configuration for FileBeat processing stdin.
Option 2
CustomLog with pipe configuration to "rotatelog". FileBeat processing on disk logs
Option 3
Standard logging to file FileBeat processing on disk logs.
Typically we are processing 4,000 transactions per second.
Does anyone have experience with these options and transaction rates they could share?