I'm a complete n00b at Logstash, so please excuse my ignorance.
I have multple tables that I'd like to read using the JDBC input. They have different schemas, different purposes, etc.
Consuming these data as an end-user, they probably will end up with different visualisations, albeit on the same dashboard on Kibana.
Therefore, I'm thinking that I will put them in different indices in elasticsearch - my first question is, am I on the right track thinking this way?
If I do do that, although I'm sure I can configure it using one config file, I think each config file will be simpler and more maintainable if I split them into multiple pipelines...
Are there any best practices guide relating to this? What do you guys do in such cases?