We have been working with rsyslog trying to get it to send data to our remote Logstash service.
Our architecture is this:
Application server running on AIX machine, the ELK stack running on RHEL server running remotely.
We can get some logs to the ELK server, but our application produces log files with dynamic names (including order number), so we need to setup a log file monitoring in rsyslog with wildcard in the file name. This introduces additional requirements for rsyslog: specific version of rsyslog that has to be compiled from the source code and the enablement of the inotify feature at the kernel level - we are not sure we can have that turned on.
Just in case we run into a roadblock here - is there another option out there for sending logs to ELK?!
Is Beats supported on AIX?!