Minimising number of ingest nodes/filebeat instances


I need to analyse different log files which all have different patterns.

Is it possible to have either:

  1. One filebeat instance which will send the log lines to different ingest nodes depending on the filename.

  2. One ingest node which can match different patterns according to the filename without going through all patterns sequentially.

Or must I have one ingest node and one filebeat instance for every different type of log?

(system) #2

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.