We have 3 filebeat instances running with a s3/sqs input. From what I can tell each instance will only pull 10 sqs messages at one time. We are not bottlenecked on cpu or ram, so what do I need to configure for it to process more simultaneously?
My elastic output is:
output.elasticsearch: compression_level: 5 worker: 30 bulk_max_size: 500