I use a syslog server which sends log to my cluster (3 servers cluster). Each server has a logstash instance.
The syslog server send only to 2 servers.
I found that my entries are doubled and I think it's because the syslog server send the same logs to the two servers.
So I would like to know if there is a way to send to only one IP which will send to the three logstash servers. I thought about redis but I've nerver used it and don't know how it works.
I only put one logstash instance, every logs will be send to it and the output of the config files will do the loadbalancing (I wrote de name of the different elasticsearch hosts)
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.