I have a setup with lots of SNMP Traps coming in which I started with Logstash 1.5 . So I set up a "Logstash Shipper" (just inputs and one output to two Redis servers, no filters) and "Logstash Indexer" another instance with inputs to get data from the Redis servers, all filters and an elasticsearch output.
This works even during bursts of traps because the first Logstash instance is tremendously fast and Redis can take whatever they are sending.
Can I replace this setup with a single Logstash 6 instance with 2 pipelines? One with all the configuration of the shipper, the other one of the indexer? According to the documentation they should not interfere with each other. So I think it would theoretically work as expected. What I'm asking here is if I forget something or if experience tells that it doesn't work out as expected.