I'm doing an internship at a hosting company and I got a question about what gives us the best performance. The endgoal is to pipe all apache and php logfiles into Logstash.
The options are:
- Push all apache files to one file (localy) and read it from there with Filebeat.
- Let Filebeat check every location (150+) and push them to Logstash.
Is there any difference?
Is there any advantage if I use a module like "apache module" on Filebeat to send the the logs to Logstash, or do I send them directly to Elasticsearch?