Need suggestion for logstash setup


I am having one t2.large ec2 machine with 8 GB RAM and 2 CPU on which I have installed ELK. Now I am parsing 30 GB of logs that I downloaded on that machine with file input plugin. Do you think logstash will process all the data or it will drop some data?


That's really an Elasticsearch question. 30 GB data with a 4 GB Elasticsearch JVM heap should be okay, but you should monitor the JVM heap size.

Since Logstash doesn't store any data is doesn't matter how much you'll index.