We are looking into the possibility of using metricbeat to monitor our Windows hosts. We would have about 15 servers going into elasticsearch directly.
What do you recommend? is this the best way to do it or is it better to direct it to redis and then use logstash to feed it to elasticsearch.
As this would be a production environment we need minimise the data loss risk
Any advice would be appreciated.