It's my first time here,
Reading logstash book I bought, it recommends using redis as a broker and several other sources recommend the same scenario in a production environment.
Searching I saw that a good solution was to use the filebeat to forward the logs, but the redis output is deprecated by searching here in the community are recommending use fb scenario -> ls -> s <-> Kibana, actually this is not for sure lose the logs?
Another question, I have no idea of the volume of logs generated per day in my environment, I believe that a 5GB per day, with 2 logstash with filters and 2 ElasticSearch, which would be the ideal hardware capability over a vmware environment?
I've several doubts to apply elk stack in a production enviroment , and excuse anything my english is not so good