Hi everyone, there is a setting forasticsearch + filebeat. I want to limit the number of logs that come in elasticsearch. There is a set of servers, about 20,000 events from different sets of files that filebeat scans that come every minute. The idea is to get the value not in 20,000, but in 5000-10000 from a set of existing files, or if there are a total of 2,000,000 records, then get them through at least one line. How to implement this? Or are there any other options?
Hi everyone, I solved my question, it is no longer relevant. I used the article for my version. He selects the configuration for himself separately. Configure the internal queue
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.