One or more logstash process?

I have different source log and I would like to know the performance, if it is better to have a single logstash process to load the log into elasticsearch for all log type or it is better to have a single logstash process for a single log type.What is your experience?

Please ask questions in English.

sorry for the inconvenient. I modified the message

It's hard to give a universal answer since it depends on so many factors. You should measure it yourself as it's likely to depend on your specific workload and machine performance.

How can I measure it? There is a tool to calculate it or I have to measure it manually?

Have a look at Logstash's HTTP monitoring API.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.