HI Team,
I have a ELK stack setup on one single server for my my Non prodcution setup, i will upgrade it to 3 node cluster in future,but for the moment i am working on single node.
Everything seems to working fine, except that my logstash is dumping its parsing messages in the /var/log folder "messages" file.
My /var/log/ is 4GB, I would like to change this path to another mount, is there simplest way to achieve without disturbing my setup!!