Oct Index contains data :
Oct 1st UTC - Oct 31 UTC
But my apache logs are in PST and are rotated daily. So I need to put log files from "Sep 30 5 PM PST - Oct 30 4:59 PM PST" for Oct ELK Index (UTC).
Is there a way to make logstash to parse only portion of log file instead of complete file, so that I can pass Sep 30 PST and Oct 30 PST log files and can ask logstatsh to pick from/till time specified.
Is there a way to monitor how much of a log file is parsed by logstash. As during downtimes of systems, where we have to stop logstash and es running processes, are they re-runnable. I mean they will start again where they left. Please suggest how to handle ELK processing during/post downtimes.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.