Hello,
I changed my log architecture for this one, because I wanted to be able to handle more messages per second, I placed REDIS in one server and another server is taken the messages from there.
Every message has it own timestamp when the user is sending it, and in the second logstash instance I put another tag with a second timestamp. The difference between both of them is always exactly 2.3333 minutes (140 seconds).
In my previous version (without using REDIS and ELK stack in only one machine) I used to have a 10 ms of difference, which was OK, but I used to lose messages when I have a high rate of data.
I have tried it with several configuration of workers, and I obtain the same results.
Here is a graph with the difference between tags.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.