I have different source log and I would like to know the performance, if it is better to have a single logstash process to load the log into elasticsearch for all log type or it is better to have a single logstash process for a single log type.What is your experience?
Please ask questions in English.
sorry for the inconvenient. I modified the message
It's hard to give a universal answer since it depends on so many factors. You should measure it yourself as it's likely to depend on your specific workload and machine performance.
How can I measure it? There is a tool to calculate it or I have to measure it manually?
Have a look at Logstash's HTTP monitoring API.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.